diff --git a/.gitattributes b/.gitattributes new file mode 100644 index 0000000..7f73f44 --- /dev/null +++ b/.gitattributes @@ -0,0 +1,19 @@ +# Normalize text files to LF in the repository. +* text=auto eol=lf + +# Keep the repository's source and data formats explicitly textual. +*.md text +*.py text +*.json text +*.jsonl text +*.yml text +*.yaml text +*.sh text +*.txt text + +# These files are intended for direct viewing, not diffing as source. +*.png binary +*.jpg binary +*.jpeg binary +*.gif binary +*.pdf binary \ No newline at end of file diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml new file mode 100644 index 0000000..17e588f --- /dev/null +++ b/.github/workflows/ci.yml @@ -0,0 +1,78 @@ +name: Repository +on: + pull_request: + push: + branches: [main, 'dev*', 'dev**/**', 'release*', 'release**/**', 'codex/**'] + workflow_dispatch: +permissions: + contents: read +concurrency: + group: repository-${{ github.ref }} + cancel-in-progress: true +jobs: + verify: + name: Repository / verify + runs-on: ubuntu-24.04 + timeout-minutes: 30 + steps: + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 + with: + path: product + persist-credentials: false + submodules: false + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 + with: + node-version: '22.23.2' + - name: Read fixed shared-tool source + id: tooling + working-directory: product + run: | + node --input-type=module -e 'import fs from "node:fs"; const t=JSON.parse(fs.readFileSync("release/tooling.json")); for(const k of ["workspace","core"]) if(t[k]) {if(!/^[a-f0-9]{40}$/.test(t[k].commit)) throw Error("Unpinned tools"); fs.appendFileSync(process.env.GITHUB_OUTPUT, k+"="+t[k].commit+"\n");}' + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 + with: + repository: shendeguize/AgentOrganon + ref: ${{ steps.tooling.outputs.workspace }} + path: tools + persist-credentials: false + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 + with: + repository: shendeguize/OrganonCore + ref: ${{ steps.tooling.outputs.core }} + path: core + persist-credentials: false + - name: Install pinned Lean toolchain in temporary runner storage + env: + ELAN_HOME: ${{ runner.temp }}/organon-elan + run: | + mkdir -p "$RUNNER_TEMP/organon-elan-bootstrap" + curl --proto '=https' --tlsv1.2 --fail --location https://github.com/leanprover/elan/releases/download/v4.2.4/elan-x86_64-unknown-linux-gnu.tar.gz --output "$RUNNER_TEMP/organon-elan-bootstrap/elan.tar.gz" + echo "42b94d4244e8353142c456ec0e4ca6528fd898a6c604d4059f494e706e431f63 $RUNNER_TEMP/organon-elan-bootstrap/elan.tar.gz" | sha256sum --check --strict + tar -xzf "$RUNNER_TEMP/organon-elan-bootstrap/elan.tar.gz" -C "$RUNNER_TEMP/organon-elan-bootstrap" + "$RUNNER_TEMP/organon-elan-bootstrap/elan-init" -y --no-modify-path --default-toolchain leanprover/lean4:v4.33.1 + "$ELAN_HOME/bin/elan" toolchain install leanprover/lean4:v4.33.1 + echo "ELAN_HOME=$ELAN_HOME" >> "$GITHUB_ENV" + echo "$ELAN_HOME/bin" >> "$GITHUB_PATH" + - name: Source tests and human-document links + working-directory: product + env: + ORGANON_WORKSPACE_ROOT: ${{ github.workspace }}/tools + ORGANON_CORE_ROOT: ${{ github.workspace }}/core + run: | + npm test + npm run check:content + - name: Install locked site build dependencies + working-directory: core/tools/site + run: npm ci --ignore-scripts + - name: Build and validate released-site paths + working-directory: product + env: + ORGANON_CORE_ROOT: ${{ github.workspace }}/core + run: npm run check:site + - name: Check current Lean evidence and four reader editions + run: node core/skills/organon-core-leanify-prove/scripts/check.js product/SoftwareEngineering/lean/philosophy --manuscript manuscript.json + - name: Keep development site preview + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 + with: + name: development-site-AdvisedOrganons-${{ github.run_attempt }} + path: product/dist/site/ + if-no-files-found: error diff --git a/.github/workflows/pages.yml b/.github/workflows/pages.yml new file mode 100644 index 0000000..ebb557c --- /dev/null +++ b/.github/workflows/pages.yml @@ -0,0 +1,77 @@ +name: Verified release Pages +on: + workflow_dispatch: + inputs: + version: + description: Published product version + required: true + type: string + manifest_sha256: + description: Canonical digest of the fully published release manifest + required: true + type: string +permissions: {} +concurrency: + group: site-data-${{ github.repository }} + cancel-in-progress: false +jobs: + prepare: + if: github.repository == 'shendeguize/AdvisedOrganons' && (github.ref == 'refs/heads/main' || github.ref == 'refs/heads/release/1.0.0') + runs-on: ubuntu-24.04 + timeout-minutes: 45 + permissions: + contents: write + outputs: + deploy: ${{ steps.state.outputs.deploy }} + steps: + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 + with: + persist-credentials: false + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 + with: + node-version: '22.23.2' + - name: Read fixed workspace tooling + id: tooling + run: | + node --input-type=module - <<'NODE' + import fs from 'node:fs'; + const tooling = JSON.parse(fs.readFileSync('release/tooling.json', 'utf8')); + if (tooling.schema_version !== 1 || tooling.workspace?.repository !== 'shendeguize/AgentOrganon' || !/^[a-f0-9]{40}$/.test(tooling.workspace.commit)) throw new Error('Invalid fixed workspace tooling'); + fs.appendFileSync(process.env.GITHUB_OUTPUT, `commit=${tooling.workspace.commit}\n`); + NODE + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 + with: + repository: shendeguize/AgentOrganon + ref: ${{ steps.tooling.outputs.commit }} + path: .tooling/workspace + persist-credentials: false + - name: Verify all channels and build fixed released sources + id: state + env: + GITHUB_TOKEN: ${{ github.token }} + GH_TOKEN: ${{ github.token }} + GOVERNANCE_AUDIT_TOKEN: ${{ secrets.GOVERNANCE_AUDIT_TOKEN }} + RELEASE_VERSION: ${{ inputs.version }} + MANIFEST_SHA256: ${{ inputs.manifest_sha256 }} + run: node .tooling/workspace/scripts/release/site-data.mjs pages --version "$RELEASE_VERSION" --manifest-sha256 "$MANIFEST_SHA256" + - uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa + if: steps.state.outputs.deploy == 'true' + with: + name: github-pages-${{ github.run_attempt }} + path: ${{ steps.state.outputs.public_dir }} + deploy: + needs: prepare + if: needs.prepare.outputs.deploy == 'true' + runs-on: ubuntu-24.04 + timeout-minutes: 10 + permissions: + pages: write + id-token: write + environment: + name: github-pages + url: ${{ steps.deployment.outputs.page_url }} + steps: + - uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e + id: deployment + with: + artifact_name: github-pages-${{ github.run_attempt }} diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml new file mode 100644 index 0000000..ea1ed83 --- /dev/null +++ b/.github/workflows/publish.yml @@ -0,0 +1,90 @@ +name: Publish verified product +on: + workflow_dispatch: + inputs: + version: + description: Exact validated product version + required: true + manifest_sha256: + description: Canonical sealed manifest digest + required: true + operation: + description: Controlled publication step + required: true + type: choice + options: [publish, promote] + bootstrap_npm: + description: Use the short-lived first-publication credential + type: boolean + default: false +permissions: + contents: read +concurrency: + group: publish-${{ inputs.version }} + cancel-in-progress: false +jobs: + publish: + if: github.ref == 'refs/heads/release/1.0.0' + environment: ${{ startsWith(inputs.version, '1.0.0-rc.') && 'npm-rc' || 'npm-stable' }} + runs-on: ubuntu-24.04 + permissions: + contents: write + actions: read + id-token: write + env: + RELEASE_VERSION: ${{ inputs.version }} + RELEASE_MANIFEST_SHA256: ${{ inputs.manifest_sha256 }} + APPROVED_RC_MANIFEST_SHA256: ${{ vars.APPROVED_RC_MANIFEST_SHA256 }} + NPM_CHANNEL_STRATEGY: ${{ vars.NPM_CHANNEL_STRATEGY }} + RELEASE_OPERATION: ${{ inputs.operation }} + GH_TOKEN: ${{ github.token }} + steps: + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 + with: + ref: ${{ github.sha }} + path: product + persist-credentials: false + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 + with: + node-version: '22.23.2' + registry-url: https://registry.npmjs.org + - name: Read fixed release tooling + id: tooling + working-directory: product + run: | + node --input-type=module -e 'import fs from "node:fs"; const t=JSON.parse(fs.readFileSync("release/tooling.json")); if(t.workspace.repository!=="shendeguize/AgentOrganon" || !/^[a-f0-9]{40}$/.test(t.workspace.commit)) throw Error("Unpinned tools"); fs.appendFileSync(process.env.GITHUB_OUTPUT,"workspace="+t.workspace.commit+"\n")' + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 + with: + repository: shendeguize/AgentOrganon + ref: ${{ steps.tooling.outputs.workspace }} + path: tools + persist-credentials: false + - name: Install exact npm with OIDC support in the temporary runner + run: npm install --global npm@12.0.2 --ignore-scripts + - name: Fetch exact public validated bundle + + run: node tools/scripts/release/publish.mjs fetch --version "$RELEASE_VERSION" --manifest-sha256 "$RELEASE_MANIFEST_SHA256" --out candidate + - name: Verify identity and every gate before credentials are exposed + run: | + node tools/scripts/release/manifest.mjs check --manifest candidate/release-manifest.json + node --input-type=module -e 'import {readJSON} from "./tools/scripts/release/lib.mjs"; import {assertDispatch} from "./tools/scripts/release/manifest.mjs"; assertDispatch(readJSON("candidate/release-manifest.json"),process.env,"advised")' + - name: Verify approved RC to stable source transition + if: inputs.version == '1.0.0' + run: node tools/scripts/release/stable.mjs --manifest candidate/release-manifest.json + - name: First npm publication with short-lived bootstrap credential + if: inputs.operation == 'publish' && inputs.bootstrap_npm + env: + NODE_AUTH_TOKEN: ${{ secrets.NPM_BOOTSTRAP_TOKEN }} + GOVERNANCE_AUDIT_TOKEN: ${{ secrets.GOVERNANCE_AUDIT_TOKEN }} + run: node tools/scripts/release/publish.mjs publish --manifest candidate/release-manifest.json --product advised + - name: OIDC publication or verified bundle operation + if: inputs.operation != 'promote' && !(inputs.operation == 'publish' && inputs.bootstrap_npm) + env: + GOVERNANCE_AUDIT_TOKEN: ${{ secrets.GOVERNANCE_AUDIT_TOKEN }} + run: node tools/scripts/release/publish.mjs "$RELEASE_OPERATION" --manifest candidate/release-manifest.json --product advised + - name: Complete channel recommendation only after all three products match + if: inputs.operation == 'promote' + env: + NODE_AUTH_TOKEN: ${{ secrets.NPM_TAG_TOKEN }} + GOVERNANCE_AUDIT_TOKEN: ${{ secrets.GOVERNANCE_AUDIT_TOKEN }} + run: node tools/scripts/release/publish.mjs promote --manifest candidate/release-manifest.json --product advised diff --git a/.github/workflows/stars.yml b/.github/workflows/stars.yml new file mode 100644 index 0000000..dc20bee --- /dev/null +++ b/.github/workflows/stars.yml @@ -0,0 +1,67 @@ +name: Observed stars +on: + workflow_dispatch: + schedule: + - cron: '17 2 * * *' +permissions: {} +concurrency: + group: site-data-${{ github.repository }} + cancel-in-progress: false +jobs: + prepare: + if: github.repository == 'shendeguize/AdvisedOrganons' && (github.ref == 'refs/heads/main' || github.ref == 'refs/heads/release/1.0.0') + runs-on: ubuntu-24.04 + timeout-minutes: 45 + permissions: + contents: write + outputs: + deploy: ${{ steps.state.outputs.deploy }} + steps: + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 + with: + persist-credentials: false + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 + with: + node-version: '22.23.2' + - name: Read fixed workspace tooling + id: tooling + run: | + node --input-type=module - <<'NODE' + import fs from 'node:fs'; + const tooling = JSON.parse(fs.readFileSync('release/tooling.json', 'utf8')); + if (tooling.schema_version !== 1 || tooling.workspace?.repository !== 'shendeguize/AgentOrganon' || !/^[a-f0-9]{40}$/.test(tooling.workspace.commit)) throw new Error('Invalid fixed workspace tooling'); + fs.appendFileSync(process.env.GITHUB_OUTPUT, `commit=${tooling.workspace.commit}\n`); + NODE + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 + with: + repository: shendeguize/AgentOrganon + ref: ${{ steps.tooling.outputs.commit }} + path: .tooling/workspace + persist-credentials: false + - name: Sample actual total and retain released HTML + id: state + env: + GITHUB_TOKEN: ${{ github.token }} + GH_TOKEN: ${{ github.token }} + run: node .tooling/workspace/scripts/release/site-data.mjs stars + - uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa + if: steps.state.outputs.deploy == 'true' + with: + name: github-pages-${{ github.run_attempt }} + path: ${{ steps.state.outputs.public_dir }} + deploy: + needs: prepare + if: needs.prepare.outputs.deploy == 'true' + runs-on: ubuntu-24.04 + timeout-minutes: 10 + permissions: + pages: write + id-token: write + environment: + name: github-pages + url: ${{ steps.deployment.outputs.page_url }} + steps: + - uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e + id: deployment + with: + artifact_name: github-pages-${{ github.run_attempt }} diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..f2c6b27 --- /dev/null +++ b/.gitignore @@ -0,0 +1,51 @@ +# Local project state +/.local/ + +# Python +__pycache__/ +*.py[cod] +*$py.class +.Python +*.so +.venv/ +venv/ +env/ +ENV/ +pip-wheel-metadata/ +*.egg-info/ +build/ +dist/ + +# Python tooling +.pytest_cache/ +.mypy_cache/ +.ruff_cache/ +.tox/ +.nox/ +.coverage +.coverage.* +htmlcov/ + +# Operating system +.DS_Store +.AppleDouble +.LSOverride + +# Editor and IDE +.idea/ +.vscode/ + +node_modules/ + +*.log + +# Lean compiler outputs +*.olean + +# Public immutable review evidence required by the manuscript closure +!/SoftwareEngineering/lean/philosophy/reviews/r3-actual-audit.log +!/SoftwareEngineering/lean/philosophy/reviews/r3-build.log +!/SoftwareEngineering/lean/philosophy/reviews/r3-probes.log +!/SoftwareEngineering/lean/philosophy/reviews/r3-stability-probe.log +!/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r1-probes-attempt1.log +!/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r1-probes.log diff --git a/README.md b/README.md new file mode 100644 index 0000000..bba466f --- /dev/null +++ b/README.md @@ -0,0 +1,57 @@ +![AdvisedOrganons](assets/banner.svg) + +[English](README.md) · [简体中文](zh/README.md) · [Website](https://shendeguize.github.io/AdvisedOrganons/) · [Releases](https://github.com/shendeguize/AdvisedOrganons/releases) + +# AdvisedOrganons + +Domain philosophies with explicit boundaries. + +## Design Aim · Ground agent judgments and improvements + +Make commitments, reasons and boundaries readable, assessable and revisable. Organon supplies philosophy and methods; it does not promise correct judgments or automatic improvement. Philosophical adoption retains an explicit human decision. + +The current domain is **SoftwareEngineering**. Philosophy **0.2.1** adds a defeasible priority for credible software evolution and retains the considered Core **0.1.2** checkpoint. That priority is an additional commitment, not a deduction from the Core. Selecting this domain remains explicit. + +## Start here + +```sh +npx --yes @shendeguize/agent-organon@1.0.0-rc.1 install --product advised --agent codex --scope project --project /path/to/workspace --version 1.0.0-rc.1 --domain SoftwareEngineering +``` + +Release candidate **1.0.0-rc.1** awaits review. Run this command once the public package is available; before publication use a local candidate archive. Requires Node.js 22+. Project and global installation are available; the release matrix records actual validation for the six agent adapters. + +[Complete quick start: install → check → select philosophy → read-only assessment](https://shendeguize.github.io/AdvisedOrganons/quick-start) + +## Read and navigate + +| Entry | Content | +| --- | --- | +| [AgentOrganon](https://github.com/shendeguize/AgentOrganon) | Workspace skills and management of adopted copies. | +| [OrganonCore](https://github.com/shendeguize/OrganonCore) | Core philosophy, review methods and Lean evidence. | +| [AdvisedOrganons](https://github.com/shendeguize/AdvisedOrganons) | Domain philosophy collection; select a domain explicitly. | +| [Docs](https://shendeguize.github.io/AdvisedOrganons/understand) | Concepts, operations and capability boundaries for readers. | +| [Philosophy](https://shendeguize.github.io/AdvisedOrganons/philosophy) | Adopted commitments with their meanings and conditions. | +| [Lean](https://shendeguize.github.io/AdvisedOrganons/lean) | Claim overviews and paired code with line explanations. | + +Release packages contain philosophy, non-Lean skills and required runtime files. Websites, tutorials, Lean projects and evidence remain in source. Rationale is separate from reader documentation and adds no philosophical obligations; maintenance protocols live in maintenance. + + +## Choose a method + +| Discovered entrypoint | Purpose | +| --- | --- | +| `organon-software-engineering` | Route assessment under a selected philosophy; also support wording-only review. | + +Before assessment, explicitly select the domain and adopted philosophy path, then use this domain entrypoint to reach the bundled workspace and Core review methods. The package includes the required implementations but does not separately register the four Core method names as discoverable skills. Installing the domain entrypoint does not adopt its philosophy; a wording-only request does not require a philosophy selection. + +## Star history + +![Observed total stars for this repository](https://shendeguize.github.io/AdvisedOrganons/assets/stars.svg) + +Daily observations begin when collection is enabled. Zero totals, unstars and missing samples are retained; the chart reports its update time. + +## Contribute + +Read the repository’s agent guidance and maintenance protocols before contributing. Mechanical checks, independent review and human adoption decisions have distinct responsibilities. + +MIT · [License](LICENSE) diff --git a/SoftwareEngineering/AGENTS.md b/SoftwareEngineering/AGENTS.md new file mode 100644 index 0000000..f839a9c --- /dev/null +++ b/SoftwareEngineering/AGENTS.md @@ -0,0 +1,11 @@ +# Working with Software Engineering Organon + +Read [PHILOSOPHY.md](PHILOSOPHY.md), including its meanings and limits, as this Organon's adopted baseline. [Rationale](rationale/README.md) and [cases](docs/cases.md) explain and illustrate it without adding philosophical obligations. + +For an Organon philosophical operation that has selected this Organon as its adopted baseline, explicitly pass this directory's English philosophy path and its real reference directory through delegation. Preserve the operation caller separately. The collection root does not select a domain on the caller's behalf. Keep a proposed replacement distinct from the adopted baseline and the review method's own constraints. + +Use AgentOrganon's applicable maintenance and adoption workflow for changes. Preserve existing user work; a change in philosophical meaning or applicability and its semantic version require the user's specific decision. English is authoritative for the corresponding Chinese text; preserve IDs, conditions and force, and do not maintain a separate Chinese adoption state. + +Keep private review and execution evidence under the owning workspace's ignored `.local/`. For example changes, run the relevant checks described in [cases](docs/cases.md); their results support the declared behavior, not philosophical correctness. [README](README.md) explains reading order, explicit baseline selection and document/lock checks. + +Maintain the [Lean delivery](lean/README.md) with the two Core Lean skills and an explicitly selected independent Core runtime. Preserve the complete preceding evidence and reader closure before replacement, review affected source/code objects, and synchronize both English and Chinese reader granularities. Tool execution does not change this Organon’s adopted baseline or establish philosophical correctness. diff --git a/SoftwareEngineering/PHILOSOPHY.lock.json b/SoftwareEngineering/PHILOSOPHY.lock.json new file mode 100644 index 0000000..3b04653 --- /dev/null +++ b/SoftwareEngineering/PHILOSOPHY.lock.json @@ -0,0 +1,176 @@ +{ + "format_version": "0.1.0", + "document_id": "urn:uuid:4dea4124-d1c4-411f-b052-bb4590d5e077", + "document_filename": "PHILOSOPHY.md", + "core_version": "0.1.2", + "core_source_id": "https://github.com/shendeguize/OrganonCore", + "sources": { + "https://github.com/shendeguize/OrganonCore": { + "kind": "core", + "format_version": "0.1.0", + "philosophy_version": "0.1.2", + "core_version": "0.1.2", + "content_hash": "cb23f8a44d6b877ff9b5385961ff8e5fa788f8021ae267cdc8e305870ec20ca7", + "sections": { + "organon.preamble": "450b06d19fd0e8d4975923efa2d02c47ee1faeafad89f5dd5a4a3ce76828dd5f", + "organon.charter": "01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b", + "organon.charter.overview": "75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c", + "organon.charter.self-transcendence": "f4ca590e2ae15e3882f70c7b2bc46a8911c97cee547c8b137b5493fbf862c8c0", + "organon.charter.self-transcendence.orientation": "7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf", + "organon.charter.self-transcendence.non-finality": "4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8", + "organon.charter.self-transcendence.limits": "6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d", + "organon.charter.consistency": "c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42", + "organon.charter.consistency.meaning": "81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa", + "organon.charter.consistency.limits": "4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75", + "organon.charter.reflexivity": "13293b45c2fa89068c68ae7ef3c5df38f0efadb3ef3873d78a5ba67d9691a757", + "organon.charter.reflexivity.meaning": "8a2caede01a43d8b6c60b54c78ac089c51868e9956f316948077ccee2e45c9cc", + "organon.charter.reflexivity.limits": "ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc", + "organon.grounds": "4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6", + "organon.grounds.assessment": "ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d", + "organon.grounds.scope": "4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693", + "organon.grounds.capabilities": "7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0", + "organon.grounds.implementations": "bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c", + "organon.grounds.implementations.limits": "db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870", + "organon.relationships": "01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b", + "organon.relationships.roles": "24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e", + "organon.relationships.terms": "0d22f818e4466a5ab4272607ac0ab26997270cf05c64ce9ac547e866068907d1" + }, + "structure": [ + { + "id": "organon.preamble", + "title": "Organon Philosophy: Charter and Grounds", + "level": 1, + "parent": null + }, + { + "id": "organon.charter", + "title": "1. Charter", + "level": 2, + "parent": "organon.preamble" + }, + { + "id": "organon.charter.overview", + "title": "1.1 Overview", + "level": 3, + "parent": "organon.charter" + }, + { + "id": "organon.charter.self-transcendence", + "title": "1.2 Self-Transcendence", + "level": 3, + "parent": "organon.charter" + }, + { + "id": "organon.charter.self-transcendence.orientation", + "title": "1.2.1 Generative Orientation", + "level": 4, + "parent": "organon.charter.self-transcendence" + }, + { + "id": "organon.charter.self-transcendence.non-finality", + "title": "1.2.2 Non-finality", + "level": 4, + "parent": "organon.charter.self-transcendence" + }, + { + "id": "organon.charter.self-transcendence.limits", + "title": "1.2.3 Grounds for Achievement and Limits", + "level": 4, + "parent": "organon.charter.self-transcendence" + }, + { + "id": "organon.charter.consistency", + "title": "1.3 Internal Consistency", + "level": 3, + "parent": "organon.charter" + }, + { + "id": "organon.charter.consistency.meaning", + "title": "1.3.1 Meaning", + "level": 4, + "parent": "organon.charter.consistency" + }, + { + "id": "organon.charter.consistency.limits", + "title": "1.3.2 Conditions and Limits", + "level": 4, + "parent": "organon.charter.consistency" + }, + { + "id": "organon.charter.reflexivity", + "title": "1.4 Reflexivity", + "level": 3, + "parent": "organon.charter" + }, + { + "id": "organon.charter.reflexivity.meaning", + "title": "1.4.1 Meaning", + "level": 4, + "parent": "organon.charter.reflexivity" + }, + { + "id": "organon.charter.reflexivity.limits", + "title": "1.4.2 Conditions and Limits", + "level": 4, + "parent": "organon.charter.reflexivity" + }, + { + "id": "organon.grounds", + "title": "2. Grounds", + "level": 2, + "parent": "organon.preamble" + }, + { + "id": "organon.grounds.assessment", + "title": "2.1 Articulation and Responsibilities of Assessment", + "level": 3, + "parent": "organon.grounds" + }, + { + "id": "organon.grounds.scope", + "title": "2.2 Relations, Scope, and the Limits of Measurement", + "level": 3, + "parent": "organon.grounds" + }, + { + "id": "organon.grounds.capabilities", + "title": "2.3 Capability Claims", + "level": 3, + "parent": "organon.grounds" + }, + { + "id": "organon.grounds.implementations", + "title": "2.4 Implementation Choices: Openness to Alternatives", + "level": 3, + "parent": "organon.grounds" + }, + { + "id": "organon.grounds.implementations.limits", + "title": "2.4.1 Conditions and Limits", + "level": 4, + "parent": "organon.grounds.implementations" + }, + { + "id": "organon.relationships", + "title": "3. Relationships and Necessary Terms", + "level": 2, + "parent": "organon.preamble" + }, + { + "id": "organon.relationships.roles", + "title": "3.1 Roles and Mutual Constraints", + "level": 3, + "parent": "organon.relationships" + }, + { + "id": "organon.relationships.terms", + "title": "3.2 Necessary Terms", + "level": 3, + "parent": "organon.relationships" + } + ], + "structure_hash": "f33bd82a1c16ea108e4b5114396165a9740691b22d1dfb503a8c86652e7e4005" + } + }, + "declined": [] +} diff --git a/SoftwareEngineering/PHILOSOPHY.md b/SoftwareEngineering/PHILOSOPHY.md new file mode 100644 index 0000000..dc76a0f --- /dev/null +++ b/SoftwareEngineering/PHILOSOPHY.md @@ -0,0 +1,202 @@ +--- +format_version: 0.1.0 +philosophy_version: 0.2.1 +core_version: 0.1.2 +derived_from: + source_id: "https://github.com/shendeguize/OrganonCore" + philosophy_version: "0.1.2" + content_hash: "cb23f8a44d6b877ff9b5385961ff8e5fa788f8021ae267cdc8e305870ec20ca7" +--- +# Software Engineering Organon: Charter and Grounds + + +This is a statement of Software Engineering Organon’s adopted philosophy. It expresses commitments, not factual assertions about every system or a proof of universal correctness. + +The quoted provisions, their meanings, and their conditions of application form the core. The charter and Grounds constrain one another; their grouping establishes neither a deductive hierarchy nor an order of priority. [Rationale](rationale/README.md) supplies arguments and cases without adding obligations to this core. Skills are revisable applications under the repository’s stated objectives and constraints, not part of the philosophical commitments themselves. + +## 1. Charter + + +### 1.1 Overview + + +**Self-Transcendence · Internal Consistency · Reflexivity** + +> A system is intrinsically oriented toward expanding what it can understand and construct. It brings itself and its principles within the scope of generation and assessment, with internal consistency constraining this process. + +The overview connects three distinct requirements: self-transcendence establishes a generative orientation and refuses to treat existing forms as final, internal consistency constrains judgments held simultaneously, and reflexivity brings the system and its principles within the scope of their own generation and assessment. The provisions below specify the conditions for each. + +### 1.2 Self-Transcendence + + +> A system is intrinsically oriented toward expanding what it can understand and construct. It does not regard any existing form as the endpoint of generation. + +#### 1.2.1 Generative Orientation + + +A commitment to keeping generative possibilities open is distinct from valuing their expansion. A system has an intrinsic orientation when it regards that expansion as worth pursuing. Merely permitting change does not fully express this orientation. + +#### 1.2.2 Non-finality + + +Refusing to regard an existing form as an endpoint keeps it open to being surpassed. “Existing form” includes a system’s current organization, methods, and principles, not only its appearance or artifacts. These remain within the scope of possible change; their revisability does not guarantee actual progress. + +#### 1.2.3 Grounds for Achievement and Limits + + +Whether progress has actually occurred remains a separate judgment. Having the orientation does not guarantee progress. Progress cannot be established merely by an increase in the number of artifacts, levels of abstraction, or terms. + +- “Intrinsic orientation” expresses Organon’s philosophical commitment; it does not assert that all systems in fact develop autonomously. +- Self-transcendence does not imply independence from external experience, knowledge, or collaboration, nor does it guarantee autonomous execution or self-improvement. +- Refusing to regard an existing form as an endpoint does not require every action to produce change. Justified stability can coexist with a generative orientation. +- Whether transcendence expands what can be understood and constructed requires discernible grounds; a system’s own claim of generation does not establish actual achievement. + +### 1.3 Internal Consistency + + +> The principles and judgments a system holds simultaneously, together with their implications, must not yield contradictory judgments on the same question under the same assumptions, meanings of terms, and scope of application. + +#### 1.3.1 Meaning + + +“Held simultaneously” specifies which principles, judgments, and implications must hold together. Revision may withdraw an earlier judgment; old and new principles need not remain compatible forever. When a change has occurred, that change cannot be represented as though it had not occurred. + +“The same assumptions, meanings of terms, and scope of application” specifies the basis for comparing judgments. Divergent judgments under different conditions do not automatically constitute contradictions. Nor can unacknowledged changes in assumptions, meanings, or scope be used to conceal an existing contradiction. + +#### 1.3.2 Conditions and Limits + + +- Tension between different assessments or values does not directly constitute a contradiction. Revision or qualification is needed when they require incompatible conclusions under the same conditions. +- Internal consistency is not correctness or sufficiency. A set of principles may be internally consistent while relying on false assumptions or neglecting important questions. + +### 1.4 Reflexivity + + +> A system’s principles of generation and assessment also apply to the system itself and to the formation, application, and revision of those principles. + +#### 1.4.1 Meaning + + +Reflexivity encompasses both the system itself and its principles. Assessment concerns not only whether the system conforms to its principles, but also how those principles are formed, where they apply, and why they may need revision. The formation and revision of principles thus also become objects of generation and assessment. + +#### 1.4.2 Conditions and Limits + + +- Applying principles equally retains their conditions of application. When the relevant conditions hold, being the system itself is not a basis for exemption. Nor does the requirement of reflexivity establish that every principle can be applied to itself without examining its applicability. +- Self-application does not constitute self-proof. Subjecting a principle to its own assessment does not thereby establish its correctness. +- That a revision is produced by the system itself does not give it sufficient grounds. + +## 2. Grounds + + +> The grounds of principles and judgments must be articulable and subject to assessment appropriate to the nature of the claim. The strength and scope of a claim must be proportionate to the support provided by its grounds. + +### 2.1 Articulation and Responsibilities of Assessment + + +Articulation and assessment have distinct responsibilities. Articulability requires that concepts, assumptions, reasons, and limits can be identified. Assessment requires examining whether those grounds support the corresponding claim. Clearly expressed grounds are not thereby sufficiently established. + +| Type of claim | Responsibility of assessment | What cannot substitute for that responsibility | +| --- | --- | --- | +| Empirical claim | Examine observations, evidence, and performance, together with the conditions, scope, and uncertainty of their support for the claim. | Treating measurability or repeatability itself as proof of relevance, correctness, or value. | +| Inferential claim | Examine whether the conclusion is supported by the stated assumptions and inferential relations. | Treating the absence of conflict between a conclusion and its assumptions as sufficient to establish that the conclusion follows from them. | +| Value commitment | State the position taken, its reasons, limits of application, and consequences, and remain open to relevant criticism. | Presenting a commitment as an empirical fact or a necessary inference, or substituting self-assertion for reasons. | + +Initial value commitments may be stated explicitly as commitments; they need not prove all their own starting assumptions. The strength and scope of a claim do not require conversion to a common numerical scale. Different types of claims specify their support and limits in accordance with their nature. + +### 2.2 Relations, Scope, and the Limits of Measurement + + +Performance is discerned within particular relations, conditions, and scopes of observation. A boundary helps specify what a comparison concerns, but local examples do not automatically support unconditional universal conclusions. A judgment cannot establish that relevant differences do not exist merely because its chosen scope omits them. + +Measurement can make some differences comparable. Repeated assessment can help examine the stability of corresponding conclusions. Their roles, and the role of any assessment framework, must be explained relative to the claim and its context. Measurement, repeatability, and an assessment framework do not form a universally necessary chain on which all judgments must depend. + +An observation that has not been reproduced may still offer limited support, and random outcomes need not be identical on every occasion. The verifiability of observations, reproducibility of conditions, and stability of conclusions must be distinguished. + +### 2.3 Capability Claims + + +Capability claims are subject to Grounds: the capability claimed, its conditions, and the support for it must be identifiable. The core does not prescribe uniform definitions of method mastery, method generation, or capability levels. Applications specify the capabilities they assess and may require understanding, explanation, or performance under relevant variations. + +Grounds for a capability claim may be supplied by an external assessor. Their articulability does not by itself require the assessed system to understand or explain its internal generation process. Evidence of reliable output must be assessed against the capability actually claimed; it does not automatically establish understanding of that process. Nor can the number of method documents, terms, tools, or artifacts alone establish a capability beyond what that evidence supports. + +### 2.4 Implementation Choices: Openness to Alternatives + + +> The choice of an implementation must be supported by reasons connected to the objectives and values pursued and to the relevant constraints. Its name, conventional use, or established status alone does not provide sufficient grounds for giving it priority. + +This choice provision adds an additional evaluative commitment: name, conventional use, or established status alone is insufficient to establish priority. Grouping it under Grounds does not mean that it follows from the general requirement to assess reasons, or merely from the discernibility of performance. Conventions and existing arrangements may have practical significance, but that significance must be connected to the objectives and values pursued and to the relevant constraints. + +#### 2.4.1 Conditions and Limits + + +- Openness does not make all implementations equivalent, nor does it guarantee multiple feasible implementations for the same objective. +- A method’s explanatory power, limits of application, simplicity, and explicit process requirements may all provide grounded reasons for assessment. They cannot be excluded merely because they concern methods internal to the implementation. +- Identical local performance does not establish overall equivalence. Relations, conditions, and the scope of comparison are constrained by the provisions of Grounds. +- Openness does not reject an implementation merely because it already exists or is conventionally used. Relevant reasons may still give it priority. + +## 3. Relationships and Necessary Terms + + +### 3.1 Roles and Mutual Constraints + + +The charter states the generative orientation, the consistency constraint, and reflexive application. Grounds specifies support requirements for judgments and includes an additional commitment concerning implementation choices. Both parts belong to the core and constrain one another. Their placement neither makes Grounds a deduction from the charter nor gives the charter priority over it. Each commitment needs its own reasons. + +Internal Consistency concerns whether simultaneously held judgments can hold together; Grounds concerns whether and how far a claim is supported. A conclusion may fail to conflict with its assumptions without being supported by them. Self-Transcendence specifies a generative orientation and non-finality; neither establishes actual capability. Applications may supply objectives, values, and capability definitions; claims made under those objectives, values, and definitions remain subject to the relevant core provisions. + +Self-Transcendence does not substitute for Reflexivity: keeping existing forms open to being surpassed differs from applying relevant principles to the system and to their own formation, application, and revision. Reflexivity extends these requirements to the system and to the formation, application, and revision of its principles. The grounds and limits of the Grounds provisions must themselves be articulable. The system’s own capability claims remain subject to assessment, and this philosophy’s existing form cannot gain priority merely from its established status. Such mutual application provides no self-proof and does not remove conditions of application. + +### 3.2 Necessary Terms + + +| Term | Meaning in this philosophy | +| --- | --- | +| Existing form | The system’s current organization, methods, and principles, not only its appearance or artifacts. | +| Assessment | Examination of reasons, applicability, and observed performance; not limited to executable tests. | + +## 4. Software Engineering + + +This chapter adds a software engineering commitment and specifies its meaning and limits. It does not claim that this commitment follows from the Charter or Grounds. Those provisions remain adopted and constrain its application. + +### 4.1 Purpose, Subjects, and Lifecycle + + +Software engineering concerns the construction, operation, understanding, and revision of software within its relevant human and technical conditions. This philosophy guides decisions by people and agents; it does not attribute an intrinsic orientation to every software artifact. + +The evolution capability considered here belongs to the continuing engineering activity: maintainers, including successor maintainers and agents, working with software, tools, and available knowledge. Code that its original author can modify is not on that ground alone shown to support that continuing activity. + +Apply the following priority according to the software's credible lifecycle and maintenance expectations. A genuinely temporary script, bounded prototype, or retiring system may have little reason to support further evolution. Calling a continuing system temporary does not establish that condition. + +### 4.2 Priority for Credible Evolution + + +> When relevant behavioral, safety, performance, and other necessary requirements are satisfied, give priority to continuing maintainers' ability to make credible future changes, including changes to the design itself, over present abstraction simplicity. Accept additional present abstraction complexity for that purpose, while allowing this preference to yield when the added costs threaten concrete engineering objectives. + +Credible directions of change have articulable grounds, such as a committed plan, relevant domain knowledge, or an applicable history of change. They need not already have multiple implementations. Their credibility remains open to revision; a conceivable change alone does not establish that it warrants accommodation now. + +This is a default priority, not an obligation to maximize extensibility or retain every possibility. Costs include relevant burdens of understanding, construction, diagnosis, verification, coordination, operation, and eventual migration. A departure from the priority identifies the objective threatened and why the costs matter. No universal numerical exchange rate between these considerations is prescribed. + +### 4.3 Meaning of Evolution + + +Evolution includes adding capabilities, replacing implementations, deleting mechanisms, withdrawing abstractions, redrawing boundaries, and migrating away from an existing technology or model. Making additions within a fixed scheme does not establish equal ability to revise or leave that scheme. Not every such change can or should be made inexpensive. + +An evolution claim identifies the relevant changes and the maintainers' conditions. Independent changes, coordinated changes, preservation of existing obligations, and deliberate revision of those obligations can require different structures. A design's advantage on one dimension does not establish an advantage on every dimension. + +### 4.4 Structural Judgments and Their Support + + +Apply the preceding commitment to engineering consequences as a whole, including the relations among components, their observable contracts, and the work needed to understand and verify a change. An interface's shape, the number of modules or extension points, or the use of a named principle is not sufficient evidence of the claimed capability. + +The relevant comparison may examine how a change propagates, which knowledge and obligations cross a boundary, which assumptions become fixed, and what a later withdrawal would require. A proposed boundary needs support for the changes it is meant to accommodate; introducing it does not by itself show that those changes became easier. + +Distinguish a transformation that preserves an identified observable contract from one that deliberately revises that contract. The latter needs a corresponding account of changed obligations and affected parties. This distinction does not require preserving every historical behavior or using a particular testing or migration procedure. + +### 4.5 Revision and Justified Stability + + +Changed evidence about likely changes, maintenance conditions, costs, or objectives may justify revising a design or this priority's application. A revised judgment acknowledges material changes in its grounds; it does not make a failed prediction successful retrospectively. + +Retaining a design can be justified when the relevant alternatives have no supported contribution or impose costs that defeat the objective. Reflexivity also keeps this engineering commitment and the methods used to assess evolution within the scope of criticism and revision. Continued change, agreement, or successful examples do not establish its universal correctness. diff --git a/SoftwareEngineering/README.md b/SoftwareEngineering/README.md new file mode 100644 index 0000000..63cc561 --- /dev/null +++ b/SoftwareEngineering/README.md @@ -0,0 +1,35 @@ +# Software Engineering Organon + +This directory contains the adopted Software Engineering Organon, its rationale and cases. Its managed philosophy retains the reviewed Core 0.1.2 source. A successful format check does not itself authorize philosophical adoption. + +[PHILOSOPHY.md](PHILOSOPHY.md) retains Core's commitments and adds a defeasible priority for credible software evolution. [Rationale](rationale/README.md) examines reasons, sources, alternatives and objections. [Constructed cases](docs/cases.md) provide executable examples; the [AgentOrganon architecture case](rationale/architecture-case.md) separately examines actual repository responsibilities. [Chinese text](zh/README.md) corresponds to the English authority. + +The philosophy version is **0.2.0**: a new domain commitment is added while the existing Core commitments retain their meaning, force and applicability. `core_version` remains **0.1.2**, identifying the Core worktree text fully considered; `format_version` remains **0.1.0**. The version records the adopted whole; later changes to its meaning or applicability require a specific decision. + +The domain priority is an additional value commitment, not a deduction from Self-Transcendence. Its subject is continuing human and agent maintenance, its scope follows credible lifecycle conditions, and it includes withdrawal and migration as well as extension. It gives no technical paradigm automatic priority. + +## Read and use + +Read the philosophy first for its commitments and limits, then the rationale for their grounds and the cases for bounded executable illustrations. The rationale and cases add no philosophical obligations. The 4.2 priority is conditional on relevant necessary requirements, credible change directions and actual lifecycle expectations; a pattern name does not settle a design choice. + +For an operation that selects this Organon as its adopted baseline, explicitly supply this directory's English `PHILOSOPHY.md` and preserve its real directory when delegating. When reviewing a proposed replacement, retain the caller's selected adopted baseline and pass the proposal separately as the review object. The collection root is not a substitute for selecting a domain. A proposed replacement remains an object of review until specifically adopted. Use assess for the relationship to the selected philosophy, principled-review for structural analysis, absorb for proposed philosophical adoption, and wording-review for wording alone. Philosophy management handles document and lock operations. + +With the AgentOrganon checkout as the current directory, the managed destination can be checked with: + +```sh +rtk proxy node scripts/check.js AdvisedOrganons/SoftwareEngineering/PHILOSOPHY.md +``` + +That command checks the managed English philosophy and its lock. It does not establish philosophical correctness or authorize adoption. Source checking a separate candidate uses `scripts/check.js --source` with its actual path. The adjacent lock belongs to the managed English document; translated text follows the English metadata and IDs and has no independent adoption state. + +Run the isolated examples from this directory: + +```sh +rtk proxy node examples/run.mjs +``` + +This needs Node.js and a C++20 compiler as described in [Cases](docs/cases.md). The runner checks declared example behavior and expected counterexamples; it does not validate the philosophy or establish production maintenance gains. Generated files and execution evidence remain under ignored `examples/.local/`. + +## Lean implementation and readers + +[Lean delivery](lean/README.md) provides the maintained Lean project, frozen targets, source review, selected evidence, and English and Chinese overviews and line-by-line readers. It keeps this Organon’s adopted Core 0.1.2 baseline. Checking uses an explicitly selected independent OrganonCore runtime; the child contains no duplicate checker. diff --git a/SoftwareEngineering/docs/cases.md b/SoftwareEngineering/docs/cases.md new file mode 100644 index 0000000..d85827d --- /dev/null +++ b/SoftwareEngineering/docs/cases.md @@ -0,0 +1,144 @@ +# Constructed software engineering cases + +These original, isolated examples compare concrete implementation choices under +declared requirements. They are not observations of a production repository, an +independent assessment of the philosophy, or evidence that a philosophy +is correct. Each example explicitly identifies its contract and known +counterexample. They do not use the formal independent case set or held-out material. +The separate [AgentOrganon architecture case](../rationale/architecture-case.md) examines +actual repository responsibilities with its own sources and limits. + +The examples need Node.js and a C++20 compiler, with no third-party packages. +The combined runner defaults to `/usr/bin/clang++`; `CXX` can select another +compiler whose constraint diagnostics contain `constraints not satisfied`. +Run from the directory containing `examples/` and `docs/`: + +```sh +rtk proxy node examples/run.mjs +``` + +The runner records the exact argument vectors, tool versions, stdout, stderr, +exit status, and termination signals in +`examples/.local/verification.log`. Generated binaries and logs stay under +`examples/.local/`, covered by `examples/.gitignore`. A run replaces that log; +preserve it separately before rerunning if comparison between runs is needed. +An unexpected command result makes the runner fail. Intentional compile +rejections count as success only when the compiler exits nonzero and reports an +unsatisfied constraint. A valid instantiation of the same probe must compile +and run first. + +## 1. JavaScript: observable contracts across a refactor + +**Objective and constraints.** A caller needs duplicate strings removed while +preserving first occurrence order. The accepted domain is ordinary dense arrays +of strings, including frozen arrays; equality is exact, with no case folding or +Unicode normalization. The result is a fresh caller-owned array, and the input +is unchanged. Invalid input throws `TypeError`, without a specified message. +Proxies, accessors, hostile modifications of built-ins, and resource exhaustion +are outside this example. + +**Variants.** `stableUniqueLoop` uses iteration and a local `Set`; +`stableUniqueReduce` uses reduction and array operations. They expose the same +declared behavior. `sortedUnique` deliberately preserves the surface shape +`string[] -> string[]` while sorting the output. Its known counterexample is +`['b', 'a', 'b']`: the required result is `['b', 'a']`, and the bad replacement +returns `['a', 'b']`. + +**Checks and observations.** The shared suite checks empty inputs, duplicates, +ordering, exact string distinctions, frozen inputs, result ownership, and invalid +inputs including a sparse array. Both correct implementations pass. A separate +negative test confirms that the bad result meets the surface shape and that the +same equality assertion rejects it. This expected rejection is caught by the +test: a green suite means the counterexample was detected, not that the bad +replacement satisfies the contract. + +The maintained source is [stable-unique.mjs](../examples/js/stable-unique.mjs); +the predeclared examples and checks are in +[contract.test.mjs](../examples/js/contract.test.mjs). Rerun this case alone from +the directory containing `examples/`: + +```sh +rtk proxy node --test examples/js/contract.test.mjs +``` + +**Limits and maintenance decision.** Passing these finite examples supports a +bounded refactoring claim; it does not prove equivalence for every JavaScript +interaction. Input validation is deliberately shared, so common defects could +escape a comparison of the two implementations. Expected results and rejection +checks provide additional, still incomplete evidence. + +The reduction variant repeatedly searches and copies its growing accumulator; +that source-level observation warrants checking relevant workload costs before +choosing it. No latency, memory, or throughput advantage was measured. Where +such costs threaten a specific service objective, behavior agreement alone is +insufficient reason to adopt it. A human or agent maintainer can retain the loop, +revert a proposed replacement, or remove a redundant variant after choosing an +implementation. Keeping both forever is not an acceptance condition. Retain the +observable contract and its regression checks across that decision. + +## 2. C++20: static configuration, generic shape, and runtime change + +**Objective and constraints.** A batch counter accepts record counts in +`[0, 1,000,000]` and capacities in `[1, 1024]`, returning the ceiling of count +divided by capacity. A partial final batch counts as one. Invalid runtime +arguments throw `std::invalid_argument`; message text is unspecified. A separate +requirement asks for capacity to change within the same process, without +recompilation. These are explicitly different requirements: fixed deployment +configuration and live changes should not be silently treated as interchangeable. + +**Variants.** `StaticBatches` constrains configuration using a C++20 +`requires` clause. `RuntimeBatches` validates capacity at construction and on +updates. Both validate record counts at runtime. The `BatchPolicy` concept +requires a const-callable expression returning `int`; `count_batches` accepts +either policy through that generic interface. `DropsPartialBatch` satisfies the +concept but deliberately truncates `9 / 8` to `1`, violating the required `2`. + +**Checks and observations.** The executable checks empty, exact, partial, and +domain-boundary counts; valid static capacity boundaries; invalid counts for +both variants; invalid runtime configurations; and update behavior. Changing +runtime capacity from `8` to `4` changes the result for `9` records from `2` to +`3`. Rejected updates preserve the preceding valid capacity. The static +specialization remains at `2`. The concept accepts the deliberately bad policy, +and an explicit semantic check observes its known violation. + +The runner also compiles the same configuration probe with capacity `8`, then +checks compiler rejection for `0` and `1025`. Compile rejection here establishes +that these invalid static configurations are excluded. It does not establish +the semantic contract for every accepted policy: the counterexample compiles. +The checks and implementation are in [case.cpp](../examples/cpp/case.cpp), +[batches.hpp](../examples/cpp/batches.hpp), and +[config-probe.cpp](../examples/cpp/config-probe.cpp). Use the combined runner +above to reproduce both positive execution and expected negative compilation. + +**Limits and maintenance decision.** A `requires` expression and a successful +compilation check a specified set of language constraints. They do not prove +semantic substitutability or eliminate validation of dynamic inputs. A fixed +specialization alone cannot satisfy the live-change requirement. Selecting among +compiled specializations would add runtime selection and a supported set of +configurations; it does not supply live changes at no cost. This case measures +neither optimization benefits nor dispatch costs and ranks no paradigm by name. + +For a deployment whose capacity really is fixed, either implementation remains +a candidate under its actual objectives. For the live-change requirement, the +runtime variant meets the demonstrated change behavior. A migration from runtime +configuration to a fixed specialization should stop or be withdrawn if live +changes remain required and no acceptable replacement is established. Removing +the runtime path is defensible only after its concrete obligations have been +retired or transferred. That is an illustrative decision boundary, not a report +of a completed production migration or an authorization to perform one. + +## Local execution record and scope of support + +On 2026-09-12, the combined runner completed all 9 commands: tool version reads, +5 passing JavaScript tests, C++ compilation and execution, compilation and +execution of the valid configuration probe, and 2 expected static constraint +rejections. The raw versions and diagnostic output are retained in +`examples/.local/verification.log`. + +The cases show specific consequences of declared requirements and implementation +choices. They do not establish universal superiority of functional, imperative, +generic, compile-time, or runtime techniques. They also do not demonstrate +production scalability, migration safety, or the quality of any philosophical +adoption process. The contract, examples, expected counterexamples, and rerun +commands give future human and agent maintainers an inspectable starting point +for revising or removing these examples when their stated purpose changes. diff --git a/SoftwareEngineering/examples/.gitignore b/SoftwareEngineering/examples/.gitignore new file mode 100644 index 0000000..a47f082 --- /dev/null +++ b/SoftwareEngineering/examples/.gitignore @@ -0,0 +1 @@ +.local/ diff --git a/SoftwareEngineering/examples/cpp/batches.hpp b/SoftwareEngineering/examples/cpp/batches.hpp new file mode 100644 index 0000000..925764a --- /dev/null +++ b/SoftwareEngineering/examples/cpp/batches.hpp @@ -0,0 +1,55 @@ +#pragma once +#include +#include + +// Observable contract: counts in [0, 1,000,000], capacity in [1, 1024]; +// return ceiling(count / capacity), counting a partial final batch. +// Invalid runtime arguments throw invalid_argument; no message contract. +inline void validate_count(int count) { + if (count < 0 || count > 1'000'000) + throw std::invalid_argument("record count outside declared domain"); +} + +inline int ceiling_batches(int count, int capacity) { + return count / capacity + (count % capacity != 0); +} + +template +requires (Capacity >= 1 && Capacity <= 1024) +struct StaticBatches { + int operator()(int count) const { + validate_count(count); + return ceiling_batches(count, Capacity); + } +}; + +class RuntimeBatches { + int capacity_; +public: + explicit RuntimeBatches(int capacity) { set_capacity(capacity); } + void set_capacity(int capacity) { + if (capacity < 1 || capacity > 1024) + throw std::invalid_argument("capacity outside declared domain"); + capacity_ = capacity; + } + int operator()(int count) const { + validate_count(count); + return ceiling_batches(count, capacity_); + } +}; + +// This concept checks an expression and return type, not the semantic contract. +template +concept BatchPolicy = requires(const Policy& policy, int count) { + { policy(count) } -> std::same_as; +}; + +template +int count_batches(const Policy& policy, int count) { return policy(count); } + +struct DropsPartialBatch { + int operator()(int count) const { + validate_count(count); + return count / 8; // Deliberate, documented counterexample. + } +}; diff --git a/SoftwareEngineering/examples/cpp/case.cpp b/SoftwareEngineering/examples/cpp/case.cpp new file mode 100644 index 0000000..a467987 --- /dev/null +++ b/SoftwareEngineering/examples/cpp/case.cpp @@ -0,0 +1,43 @@ +#include "batches.hpp" +#include +#include + +void check(bool condition, const char* message) { + if (!condition) throw std::runtime_error(message); +} + +template +void rejects(Operation operation) { + try { operation(); } + catch (const std::invalid_argument&) { return; } + throw std::runtime_error("expected invalid_argument"); +} + +int main() { + StaticBatches<8> fixed; + RuntimeBatches changing(8); + check(count_batches(fixed, 0) == 0, "empty batch count"); + check(count_batches(fixed, 8) == 1, "exact batch count"); + check(count_batches(fixed, 9) == 2, "partial final batch counts"); + check(count_batches(changing, 9) == 2, "initial runtime capacity"); + check(count_batches(StaticBatches<1>{}, 1'000'000) == 1'000'000, + "capacity and record-count boundary"); + check(count_batches(StaticBatches<1024>{}, 1025) == 2, "upper capacity boundary"); + rejects([&] { count_batches(fixed, -1); }); + rejects([&] { count_batches(fixed, 1'000'001); }); + rejects([&] { count_batches(changing, -1); }); + rejects([&] { count_batches(changing, 1'000'001); }); + rejects([] { RuntimeBatches invalid(0); }); + rejects([] { RuntimeBatches invalid(1025); }); + changing.set_capacity(4); // A requirement to vary without recompilation. + check(count_batches(changing, 9) == 3, "runtime capacity change"); + rejects([&] { changing.set_capacity(0); }); + rejects([&] { changing.set_capacity(1025); }); + check(count_batches(changing, 9) == 3, "invalid update preserves old capacity"); + check(count_batches(fixed, 9) == 2, "static specialization remains fixed"); + static_assert(BatchPolicy); + check(count_batches(DropsPartialBatch{}, 9) == 1, "known bad policy observed"); + check(count_batches(DropsPartialBatch{}, 9) != 2, "known semantic violation exposed"); + std::cout << "PASS: static and runtime boundaries; runtime update; " + "concept-compatible semantic counterexample (9 / 8: 1, required 2)\n"; +} diff --git a/SoftwareEngineering/examples/cpp/config-probe.cpp b/SoftwareEngineering/examples/cpp/config-probe.cpp new file mode 100644 index 0000000..0edc0e9 --- /dev/null +++ b/SoftwareEngineering/examples/cpp/config-probe.cpp @@ -0,0 +1,7 @@ +#include "batches.hpp" + +// Runner first compiles with capacity 8, then expects constraint rejection for +// 0 and 1025. These are intentional negative tests, not broken deliverables. +int main() { + return StaticBatches{}(0); +} diff --git a/SoftwareEngineering/examples/js/contract.test.mjs b/SoftwareEngineering/examples/js/contract.test.mjs new file mode 100644 index 0000000..e560c65 --- /dev/null +++ b/SoftwareEngineering/examples/js/contract.test.mjs @@ -0,0 +1,41 @@ +import assert from 'node:assert/strict'; +import test from 'node:test'; +import { stableUniqueLoop, stableUniqueReduce, sortedUnique } from './stable-unique.mjs'; + +// Declared observable contract: ordinary dense arrays of strings (including +// frozen arrays), exact string equality, first occurrence order, a fresh array, +// no input mutation. Invalid arrays/elements throw TypeError; message unspecified. +// Proxies, accessors and hostile built-in modification are outside this case. +const cases = [ + [[], []], + [['b', 'a', 'b'], ['b', 'a']], // Known counterexample to sorting, fixed in advance. + [['', 'A', 'a', ''], ['', 'A', 'a']], + [['é', 'e\u0301', 'é'], ['é', 'e\u0301']], +]; + +for (const implementation of [stableUniqueLoop, stableUniqueReduce]) { + test(`${implementation.name}: declared examples and input ownership`, () => { + for (const [source, expected] of cases) { + const input = Object.freeze([...source]); + const actual = implementation(input); + assert.deepEqual(actual, expected); + assert.notEqual(actual, input); + assert.deepEqual(input, source); + actual.push('caller-owned'); + assert.deepEqual(input, source); + } + }); + test(`${implementation.name}: rejects invalid input`, () => { + for (const input of [null, 'a', {}, ['a', 1], new Array(1)]) { + assert.throws(() => implementation(input), TypeError); + } + }); +} + +test('known bad replacement has the surface shape but violates order', () => { + const input = Object.freeze(['b', 'a', 'b']); + const actual = sortedUnique(input); + assert.ok(Array.isArray(actual) && actual.every(x => typeof x === 'string')); + assert.deepEqual(actual, ['a', 'b']); + assert.throws(() => assert.deepEqual(actual, ['b', 'a']), assert.AssertionError); +}); diff --git a/SoftwareEngineering/examples/js/stable-unique.mjs b/SoftwareEngineering/examples/js/stable-unique.mjs new file mode 100644 index 0000000..46720ba --- /dev/null +++ b/SoftwareEngineering/examples/js/stable-unique.mjs @@ -0,0 +1,31 @@ +function validate(items) { + if (!Array.isArray(items)) throw new TypeError('expected an array of strings'); + for (const item of items) { + if (typeof item !== 'string') throw new TypeError('expected a string'); + } +} + +// Both implementations keep their state local; callers own the returned array. +export function stableUniqueLoop(items) { + validate(items); + const seen = new Set(); + const result = []; + for (const item of items) { + if (!seen.has(item)) { + seen.add(item); + result.push(item); + } + } + return result; +} + +export function stableUniqueReduce(items) { + validate(items); + return items.reduce((result, item) => + result.includes(item) ? result : [...result, item], []); +} + +// Deliberately wrong replacement: string[] -> string[] does not encode order. +export function sortedUnique(items) { + return stableUniqueLoop(items).sort(); +} diff --git a/SoftwareEngineering/examples/run.mjs b/SoftwareEngineering/examples/run.mjs new file mode 100644 index 0000000..9bede68 --- /dev/null +++ b/SoftwareEngineering/examples/run.mjs @@ -0,0 +1,39 @@ +import { spawnSync } from 'node:child_process'; +import { mkdirSync, writeFileSync } from 'node:fs'; +import { fileURLToPath } from 'node:url'; +import { join } from 'node:path'; + +const root = fileURLToPath(new URL('.', import.meta.url)); +const output = join(root, '.local'); +mkdirSync(output, { recursive: true }); +const log = []; +let checks = 0; +const compiler = process.env.CXX || '/usr/bin/clang++'; +function run(command, args, expectedFailure = false) { + const result = spawnSync(command, args, { cwd: root, encoding: 'utf8' }); + log.push(`$ ${[command, ...args].map(x => JSON.stringify(x)).join(' ')}`, + result.stdout || '', result.stderr || '', + `exit=${result.status}; signal=${result.signal}; error=${result.error?.message || 'none'}`); + writeFileSync(join(output, 'verification.log'), log.join('\n') + '\n'); + if (result.error || result.signal || result.status === null || + (expectedFailure ? result.status === 0 : result.status !== 0)) { + throw new Error(`unexpected result; inspect ${join(output, 'verification.log')}`); + } + if (expectedFailure && !/constraints not satisfied/.test(result.stderr)) { + throw new Error('negative compile failed for an unexpected reason; inspect verification.log'); + } + checks++; +} + +run(process.execPath, ['--version']); +run(compiler, ['--version']); +run(process.execPath, ['--test', 'js/contract.test.mjs']); +const flags = ['-std=c++20', '-Wall', '-Wextra', '-Werror', '-pedantic']; +run(compiler, [...flags, 'cpp/case.cpp', '-o', join(output, 'cpp-case')]); +run(join(output, 'cpp-case'), []); +run(compiler, [...flags, '-DCASE_CAPACITY=8', 'cpp/config-probe.cpp', '-o', join(output, 'config-probe')]); +run(join(output, 'config-probe'), []); +for (const capacity of [0, 1025]) { + run(compiler, [...flags, `-DCASE_CAPACITY=${capacity}`, '-fsyntax-only', 'cpp/config-probe.cpp'], true); +} +console.log(`PASS: ${checks} commands, including 2 expected constraint rejections. Raw output: ${join(output, 'verification.log')}`); diff --git a/SoftwareEngineering/lean/.gitignore b/SoftwareEngineering/lean/.gitignore new file mode 100644 index 0000000..46e0410 --- /dev/null +++ b/SoftwareEngineering/lean/.gitignore @@ -0,0 +1,6 @@ +**/evidence/checks/ +**/leanified/.lake/ +**/leanified/*.olean +**/leanified/*.ilean +!**/evidence/lean-audit.log +!**/evidence/lake-build.log diff --git a/SoftwareEngineering/lean/README.md b/SoftwareEngineering/lean/README.md new file mode 100644 index 0000000..ccdf364 --- /dev/null +++ b/SoftwareEngineering/lean/README.md @@ -0,0 +1,36 @@ +# Software Engineering Lean implementation and readers + +The English [philosophy](../PHILOSOPHY.md) is authoritative. This delivery uses SoftwareEngineering **0.2.1**, which retains the adopted Core **0.1.2** text. The current OrganonCore checking runtime does not change that adoption. + +| Reader | English | Chinese | +| --- | --- | --- | +| Claims, premises and limits | [Overview](philosophy/overview.md) | [速览](../zh/lean/philosophy/overview.md) | +| Complete code and every nonblank line | [Details](philosophy/details.md) | [逐行详解](../zh/lean/philosophy/details.md) | + +The [frozen catalog](philosophy/targets.json) retains 40 targets and 175 prescribed semantic cases, covering all 47 substantive source paragraphs. Two empty headings remain structural entries. The 59 registered declarations include normative interfaces, conditional results and checked cases. Specifications express duties; checking their definitions does not establish fulfillment. The joint witness fulfills the complete represented inherited and domain interfaces in one concrete context. The strong countermodel fulfills the complete represented inherited interface while the additional domain priority genuinely applies but is not adopted; temporary lifecycle and cost exceptions do not discharge that target. + +These are bounded mathematical results and reviewed source correspondences. They do not prove universal philosophical correctness, empirical engineering outcomes or the merits of every value choice. [Review records](philosophy/reviews/README.md) retain independent initial judgments, failures, corrections and later comparisons. [Validation](VALIDATION.md) identifies checks and their limits. + +## Explicit runtime dependency + +This directory owns its [Lean sources](philosophy/leanified/CoreReader.lean), manifests, readers and selected evidence. It contains no duplicate checker. Use an independently obtained OrganonCore checkout with its two Lean skills and runtime. No outer AgentOrganon checkout is needed for Lean checking or the local examples. + +With Node >=22, RTK and installed Lean `v4.33.1`, supply the actual paths to both directories: + +```sh +organon_core=/absolute/path/to/OrganonCore +software_engineering=/absolute/path/to/SoftwareEngineering +rtk proxy node "$organon_core/skills/organon-core-leanify-prove/scripts/check.js" "$software_engineering/lean/philosophy" --manuscript manuscript.json +``` + +Omit `--manuscript manuscript.json` to check the frozen source, build, declarations, full types and dependencies alone. Manuscript checking also binds the current source and adopted baseline, four views, exact excerpts and code, source review, target inventory and reported states. Its `semantic_status: not_evaluated` is intentional: the checker checks evidence consistency, not semantic correctness or reviewer independence. `proof_targets.complete` means the frozen target completion conditions were met for the reported reviewed objects; it does not mean complete formalization of every source sentence. + +The code uses Lean's installed standard library, without Mathlib or automatic downloads. Dependencies such as `propext`, `Classical.choice` and `Quot.sound` are disclosed in the [actual audit](philosophy/evidence/lean-audit.log); there are no project-declared axioms or `sorry` proofs. + +## Maintenance + +The stable `philosophy/` location names the current object, not an immutable approval. Before replacement, preserve the full reference closure, including the Chinese readers outside the run directory, and replay the old object from a separate copy. Source hashes, code, complete declaration types, reviews and manuscripts must continue to identify the same objects. A source or interpretation change requires a newly reviewed object; unchanged version metadata is insufficient. + +Retain failed, limited, incomplete, inapplicable and stale judgments with their reasons. Reuse exact unchanged material only after checking its identity and disclosing that reuse. Synchronize English and Chinese at both granularities after affected changes. Private iteration records and historical objects stay in the owning workspace's ignored `.local/`; public checking and ordinary copies do not depend on them. + +New execution receipts under ignored `philosophy/evidence/checks/` record loaded tool bytes and observed runtime versions. They do not approve the tool or retroactively add execution identity to earlier records. [Source context](philosophy/SOURCE-CONTEXT.md) explains the frozen source's relative links. diff --git a/SoftwareEngineering/lean/VALIDATION.md b/SoftwareEngineering/lean/VALIDATION.md new file mode 100644 index 0000000..e725397 --- /dev/null +++ b/SoftwareEngineering/lean/VALIDATION.md @@ -0,0 +1,27 @@ +# Validation and limits + +Use the explicit independent Core command in [README](README.md). It builds the actual Lean project, checks all 59 registered declarations, records complete types and axiom dependencies, and checks all four manuscript views against the unchanged 40-target catalog and exact source bytes. + +| Evidence | Role | +| --- | --- | +| [Kernel](philosophy/evidence/kernel.json) | Build and registered declaration results | +| [Complete declaration types](philosophy/evidence/declaration-types.json) | Actual Lean `Expr` values and hashes | +| [Audit](philosophy/evidence/lean-audit.log) | Declarations and axiom dependencies | +| [Execution identity](philosophy/evidence/execution-identity.json) | Loaded tools, inputs and observed runtime | +| [Manuscript check](philosophy/evidence/manuscript-check.json) | Current-source/baseline, exact four-view content and reviewed target bindings | +| [Review history](philosophy/reviews/README.md) | Independent source-first and code-only initial work, later informed judgments and corrections | +| [175 semantic cases](philosophy/reviews/semantic-cases.json) | Reviewed links to actual declarations and bounded interpretations | + +The independently audited source review covers all project declarations in addition to the required 59. Reader acceptance requires actual retrieval and explanation of complete conditions and proof steps; nonempty line markers alone do not establish translation accuracy. + +The [executable examples](../docs/cases.md) have their own checks: + +```sh +rtk proxy node examples/run.mjs +``` + +Run this from SoftwareEngineering with Node and a C++20 compiler. The runner includes positive executions and expected static-constraint rejections. These demonstrate the declared JavaScript/C++ behavior; the Lean models separately represent specified behavior, requirements, maintenance paths, costs, contracts and revision history. Neither substitutes for measurement in a production system. + +A portable acceptance copy contains only SoftwareEngineering and the explicitly selected independent Core runtime, excluding outer management files, private records, previous build caches and compiled Lean objects. It reruns the build, manuscript check and executable examples. The outer managed document/lock check is a separate source-format check and does not become a dependency of that portable Lean delivery. + +Selected public evidence remains attached to the current object; rerunning checks writes fresh records without silently replacing it. Historical failures and previous review judgments retain their original scope. Structural integrity, reported acceptance and philosophical correctness are distinct. diff --git a/SoftwareEngineering/lean/philosophy/PREREGISTERED.md b/SoftwareEngineering/lean/philosophy/PREREGISTERED.md new file mode 100644 index 0000000..9129160 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/PREREGISTERED.md @@ -0,0 +1,17 @@ +# Frozen proof objectives + +The selected source is the complete SoftwareEngineering 0.2.0 philosophy, adopted from Core 0.1.2. Its exact bytes have SHA256 `6c6ae78a23f2726c5c370434e808d76c206647fe7793245e88cae52c076abe34`. Rationale and executable examples supply context and cases; they are not additional whole-document proof obligations. The source, version and adoption lock remain unchanged. + +The independent source inventory and the author's inventory were compared before candidate Lean was written. Source references and one added bounded non-entailment statement were corrected before freezing. The accepted catalog is [targets.json](targets.json), SHA256 `c0939df35dad148a0543ba92a1ac7b7d3b2eb4946f92ac4be251ec51b6481d13`. It fixes the complete statements, premises, case meanings and acceptance conditions. This document is the delivery copy of those recorded objectives; its file creation time does not authenticate their earlier registration. + +All frozen provable targets and necessary independent reviews must finish. A failed target cannot be removed, weakened or reclassified to claim completion. Definitions express obligations; conditional theorems, finite examples, empirical grounds and value commitments retain distinct states. A finite successful model does not prove the philosophy universally correct. + +The composition checks use one nonempty engineering context. T38 requires all represented inherited and domain commitments jointly, with a continuing lifecycle and actual evolution priority. T39 requires every represented inherited commitment while the domain priority genuinely applies and is not adopted. Necessary requirements, a supported advantage for credible changes including design revision, and the absence of a defeating cost threat must hold. A temporary lifecycle, an exception, or merely completing assessment cannot substitute for this countermodel. + +The cases cover actual and mislabeled temporary lifecycles, credible and merely conceivable changes, every represented necessary-requirement failure, default priority and explained departure, addition and exit, successor and agent maintenance, preservation and deliberate revision of observable contracts, failed predictions and subsequent judgments. Each semantic case in the catalog needs an actual proposition and content explanation, even when a theorem groups several cases. + +Lean 4.33.1 and its core libraries check the registered declarations, full types and axiom dependencies. Project axioms and admitted proofs are forbidden. Independent code-only backtranslation is preserved before source comparison. English and Chinese overviews and detailed readers bind to the same source, code, target and review objects. Every nonblank Lean line receives an explanation in each detailed reader. + +The existing JavaScript and C++ examples are executed separately from the mathematical models. Their observed results do not establish future empirical maintainability. Portable verification uses only this child philosophy and the explicitly designated independent Core runtime, excluding the outer management repository, private records and build caches. The child carries no separately maintained copy of the checker. + +Method changes require an observed deficiency, preservation of the preceding objects, relevant preregistered variations, actual checks and independent review. Philosophical absorption remains an analysis of candidates; it does not change the source commitments or adoption baseline. diff --git a/SoftwareEngineering/lean/philosophy/SOURCE-CONTEXT.md b/SoftwareEngineering/lean/philosophy/SOURCE-CONTEXT.md new file mode 100644 index 0000000..20819d1 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/SOURCE-CONTEXT.md @@ -0,0 +1,9 @@ +# Frozen source context + +[snapshots/PHILOSOPHY.md](snapshots/PHILOSOPHY.md) preserves the exact English source bytes. Its relative links were written for the SoftwareEngineering root, not the snapshots directory. Read them through the unchanged [current philosophy](../../PHILOSOPHY.md), [rationale](../../rationale/README.md) and [cases](../../docs/cases.md). + +The adopted baseline is SoftwareEngineering 0.2.1, retaining Core 0.1.2. The source and selected baseline both bind that whole adopted English document. Current OrganonCore tools are an explicit runtime dependency, with no authority to upgrade the adopted source to Core 0.1.3. Rationale and executable cases support interpretation and validation but do not receive separate whole-text proof obligations in this run. + +The detailed readers quote all source paragraphs exactly and retain both empty structural headings. Frozen target descriptions, formal claims, application premises and reported source correspondence remain distinct. The supplementary helper modules retain their mathematical scope; their earlier Core provenance does not add duties to this source. + +The original preregistration retains its historical source/catalog identity. The current metadata and rationale path were separately compared in [source migration review](reviews/source-migration-2026-09-15.md); unchanged Lean code, target bodies and bounded judgments are reused with that scope disclosed. diff --git a/SoftwareEngineering/lean/philosophy/details.md b/SoftwareEngineering/lean/philosophy/details.md new file mode 100644 index 0000000..9cc19a7 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/details.md @@ -0,0 +1,24858 @@ +# Software Engineering Philosophy and Lean: detailed reader + +This reader follows 40 frozen targets. Target acceptance, Lean checking and source fidelity are separate judgments. Defining a duty does not establish its fulfillment; a finite model does not establish universal real-world correctness. The tracing appendix retains all 47 source paragraphs and two empty headings. + +The adopted baseline is SoftwareEngineering 0.2.1, inheriting Core 0.1.2. Current Core tools provide only the checking runtime. + +`accepted` records acceptance of a target within its stated scope; `limited` retains a bounded formal correspondence for a source paragraph; `incomplete` retains material without a complete source proof. Lean `passed` reports checking of registered declarations; checking a normative interface is not fulfillment of its duty. + +[Other granularity](overview.md) · [Frozen targets](targets.json) · [Review and exposure record](reviews/README.md) · [Actual declaration types](evidence/declaration-types.json) + +| Target | Claim | Kind | Target review | +| --- | --- | --- | --- | +| [T01](#t01) | Authority and the adopted baseline | boundary | accepted | +| [T02](#t02) | Valued expansion and revisable forms | specification | accepted | +| [T03](#t03) | Orientation is not achievement | nonentailment | accepted | +| [T04](#t04) | Consistency of the whole held theory | specification | accepted | +| [T05](#t05) | Contradiction and explicit revision | theorem | accepted | +| [T06](#t06) | Consistency, truth and support differ | nonentailment | accepted | +| [T07](#t07) | Applicable self-application | specification | accepted | +| [T08](#t08) | Self-application supplies no self-proof | nonentailment | accepted | +| [T09](#t09) | Grounds for the original assessment task | specification | accepted | +| [T10](#t10) | Empirical support and uncertainty | specification | accepted | +| [T11](#t11) | Inference and negative examination | specification | accepted | +| [T12](#t12) | Value positions and reasons | specification | accepted | +| [T13](#t13) | Articulation and proportionality limits | nonentailment | accepted | +| [T14](#t14) | Relations, comparison scope and method roles | specification | accepted | +| [T15](#t15) | Local evidence does not erase differences | nonentailment | accepted | +| [T16](#t16) | Application-specific capability and understanding | specification | accepted | +| [T17](#t17) | Output evidence does not imply introspection | nonentailment | accepted | +| [T18](#t18) | Grounded implementation choice | specification | accepted | +| [T19](#t19) | Openness and the additional choice commitment | nonentailment | accepted | +| [T20](#t20) | Mutual application in one engineering system | theorem | accepted | +| [T21](#t21) | Existing forms and assessment | boundary | accepted | +| [T22](#t22) | The continuing engineering activity | specification | accepted | +| [T23](#t23) | Private editability and shared capability | nonentailment | accepted | +| [T24](#t24) | Conditions of evolution priority | specification | accepted | +| [T25](#t25) | The applicable priority theorem | theorem | accepted | +| [T26](#t26) | Grounded credible directions | specification | accepted | +| [T27](#t27) | Credibility is not unlimited accommodation | nonentailment | accepted | +| [T28](#t28) | Concrete costs and justified departure | specification | accepted | +| [T29](#t29) | Kinds of evolution and changed obligations | specification | accepted | +| [T30](#t30) | One evolution advantage is not every advantage | nonentailment | accepted | +| [T31](#t31) | Structural consequences and crossing obligations | specification | accepted | +| [T32](#t32) | Structure names do not prove capability | nonentailment | accepted | +| [T33](#t33) | Preservation versus deliberate contract revision | specification | accepted | +| [T34](#t34) | The contract-preservation theorem | theorem | accepted | +| [T35](#t35) | Revision and preserved historical evidence | specification | accepted | +| [T36](#t36) | Revision cannot rewrite failure | nonentailment | accepted | +| [T37](#t37) | The priority remains open to its own assessment | theorem | accepted | +| [T38](#t38) | One joint witness for all represented duties | satisfiability | accepted | +| [T39](#t39) | Inherited duties do not force the added priority | nonentailment | accepted | +| [T40](#t40) | What the formal evidence cannot establish | boundary | accepted | + + +## T01 · Authority and the adopted baseline + +SoftwareEngineering 0.2.1 adopts the inherited Core 0.1.2 text and an additional engineering priority. This edition does not advance the adopted Core 0.1.2 checkpoint. + +**Premises and representation:** The complete quoted provisions, meanings and application limits are authoritative. Rationale and cases supply interpretation; the current Core checker is a separate runtime dependency. + +**Proof or check:** Source bytes, metadata and paragraph excerpts are frozen and traced. No Lean theorem is assigned to documentary authority. + +**Limits:** Neither the chapter order nor a successful checker establishes deductive hierarchy, universal philosophical correctness or adoption by every system. + +**State:** accepted (boundary). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.preamble#p1](#source-organon-preamble-p1), [organon.preamble#p2](#source-organon-preamble-p2), [organon.charter.overview#p1](#source-organon-charter-overview-p1), [organon.charter.overview#p2](#source-organon-charter-overview-p2), [organon.charter.overview#p3](#source-organon-charter-overview-p3), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [extensions#p1](#source-extensions-p1) + +This boundary target has no Lean declaration. + + + +## T02 · Valued expansion and revisable forms + +generationSpecification requires valuing expansion and keeping every current organization, method and principle form revisable. A justified stable action can satisfy this orientation. + +**Premises and representation:** Policy supplies the value position, current forms and revisability relation. The concrete policy has current forms; the requirement is not discharged by an empty inventory. + +**Proof or check:** The positive case constructs valuation and revisability. A neutral policy permits version changes but fails valuation; stable and collaborative examples check actual state transitions and resources. + +**Limits:** The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.charter.overview#p2](#source-organon-charter-overview-p2), [organon.charter.overview#p3](#source-organon-charter-overview-p3), [organon.charter.self-transcendence#p1](#source-organon-charter-self-transcendence-p1), [organon.charter.self-transcendence.orientation#p1](#source-organon-charter-self-transcendence-orientation-p1), [organon.charter.self-transcendence.non-finality#p1](#source-organon-charter-self-transcendence-non-finality-p1), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.relationships.terms#p1](#source-organon-relationships-terms-p1) + +### `CoreReader.Adopted.generationSpecification` + +[leanified/CoreReader/Adopted.lean:80](#line-code-leanified-corereader-adopted-lean-80) · definition + +Core dependencies: none. + +```lean +def generationSpecification (policy : Policy) : Prop := Generative policy +``` + +### `CoreReader.Adopted.generationCases` + +[leanified/CoreReader/Adopted.lean:862](#line-code-leanified-corereader-adopted-lean-862) · case + +Core dependencies: `propext`, `Quot.sound`. + +```lean +theorem generationCases : + (Generative openPolicy ∧ + (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧ + (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1)))) ∧ + (neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy) ∧ + (Generative generatingSystem.policy ∧ + generatingSystem.policy.permitsVersion 0 0 ∧ + ¬ Expanded generatingSystem.current inflatedState ∧ + generatingSystem.current.inventory.length < inflatedState.inventory.length ∧ + generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧ + generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧ + generatingSystem.execute availableResources = some 6 ∧ + generatingSystem.execute { availableResources with experience := none } = none ∧ +``` + + + +## T03 · Orientation is not achievement + +Permission, valuation, revisability and increased inventories do not by themselves establish expanded capability or actual execution. + +**Premises and representation:** States contain actual available operations; resource removal changes execution. Achievement evidence fixes the same transition, operation, input and output claim. + +**Proof or check:** The inflated state adds counts without a successor operation. The collaborative case gains that operation only with the relevant resource. A performance record supports the identified achievement, while an announcement admits a counterworld. + +**Limits:** These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.charter.self-transcendence.orientation#p1](#source-organon-charter-self-transcendence-orientation-p1), [organon.charter.self-transcendence.non-finality#p1](#source-organon-charter-self-transcendence-non-finality-p1), [organon.charter.self-transcendence.limits#p1](#source-organon-charter-self-transcendence-limits-p1), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2) + +### `CoreReader.Adopted.generationLimits012` + +[leanified/CoreReader/Adopted.lean:904](#line-code-leanified-corereader-adopted-lean-904) · case + +Core dependencies: `propext`, `Quot.sound`. + +```lean +theorem generationLimits012 : + (neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy) ∧ + (Generative openPolicy ∧ + (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧ + (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1)))) ∧ + (Generative generatingSystem.policy ∧ + generatingSystem.policy.permitsVersion 0 0 ∧ + ¬ Expanded generatingSystem.current inflatedState ∧ + generatingSystem.current.inventory.length < inflatedState.inventory.length ∧ + generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧ + generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧ + generatingSystem.execute availableResources = some 6 ∧ + generatingSystem.execute { availableResources with experience := none } = none ∧ +``` + + + +## T04 · Consistency of the whole held theory + +Consistency constrains joint consequences of all held claims under one set of assumptions, meanings and scope. Truthful revision reporting is a separate condition. + +**Premises and representation:** A Theory selects proposition-valued claims; Context fixes assumptions, question meanings and scope. Both positive and negative consequences quantify over the same admissible worlds. + +**Proof or check:** The cases exhibit a contradiction produced only by the union, genuine changes of context, separately consistent time slices, and truthful Boolean change reports. + +**Limits:** A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.charter.consistency#p1](#source-organon-charter-consistency-p1), [organon.charter.consistency.meaning#p1](#source-organon-charter-consistency-meaning-p1), [organon.charter.consistency.meaning#p2](#source-organon-charter-consistency-meaning-p2), [organon.charter.consistency.limits#p1](#source-organon-charter-consistency-limits-p1) + +### `CoreReader.Adopted.consistencySpecification` + +[leanified/CoreReader/Adopted.lean:90](#line-code-leanified-corereader-adopted-lean-90) · definition + +Core dependencies: none. + +```lean +def consistencySpecification {W Q : Type} (before after : Snapshot W Q) + (reported : Bool) : Prop := +``` + +### `CoreReader.Adopted.consistencyCases` + +[leanified/CoreReader/Adopted.lean:952](#line-code-leanified-corereader-adopted-lean-952) · case + +Core dependencies: none. + +```lean +theorem consistencyCases : + (Satisfiable (singleton premiseP) ∧ Satisfiable (singleton premiseRule) ∧ + Satisfiable (singleton premiseNotQ) ∧ ¬ Satisfiable jointTheory) ∧ + ((Consequence emptyTheory (assumptionContext true) () true ∧ + Consequence emptyTheory (assumptionContext false) () false) ∧ + (Consequence emptyTheory (meaningContext true) () true ∧ + Consequence emptyTheory (meaningContext false) () false) ∧ + (Consequence emptyTheory (scopeContext true) () true ∧ + Consequence emptyTheory (scopeContext false) () false) ∧ + (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w)) ∧ + (¬ TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (meaningContext true)) (contextSnapshot (meaningContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (scopeContext true)) (contextSnapshot (scopeContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (scopeContext true) 0) (contextSnapshot (scopeContext true) 1) false ∧ + (TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) true ∧ + ¬ Models (assumptionContext false).assumptions true)) ∧ + (Satisfiable (revisionSlice 0) ∧ Satisfiable (revisionSlice 1) ∧ + ¬ Satisfiable (union (revisionSlice 0) (revisionSlice 1))) ∧ + ((∀ time, Consistent (revisionSlice time) broadBoolContext) ∧ + ¬ Consistent (union (revisionSlice 0) (revisionSlice 1)) broadBoolContext) ∧ + (∀ p q : Claim Bool, + ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r) ∧ + (Consequence jointTheory jointContext012 () true ∧ + Consequence jointTheory jointContext012 () false ∧ + ¬ Consistent jointTheory jointContext012) := +``` + + + +## T05 · Contradiction and explicit revision + +Opposite consequences on the same question violate consistency. Withdrawing an earlier judgment can leave each revised time slice consistent. + +**Premises and representation:** The conditional theorem receives both signed consequences and their common context. It does not derive either premise. + +**Proof or check:** consistencyConsequences applies conflictRequiresChange. The slice examples construct a model at each time and derive conflict for the union. Reordering a union preserves its selected claims. + +**Limits:** The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. + +**State:** accepted (theorem). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.charter.consistency#p1](#source-organon-charter-consistency-p1), [organon.charter.consistency.meaning#p1](#source-organon-charter-consistency-meaning-p1), [organon.charter.consistency.meaning#p2](#source-organon-charter-consistency-meaning-p2), [organon.charter.consistency.limits#p1](#source-organon-charter-consistency-limits-p1) + +### `CoreReader.Adopted.consistencyConsequences` + +[leanified/CoreReader/Adopted.lean:241](#line-code-leanified-corereader-adopted-lean-241) · theorem + +Core dependencies: none. + +```lean +theorem consistencyConsequences {W Q : Type} (t : Theory W) (c : Context W Q) (q : Q) + (positive : Consequence t c q true) (negative : Consequence t c q false) : + ¬ Consistent t c := conflictRequiresChange t c q positive negative +``` + +### `CoreReader.Adopted.consistencyCases` + +[leanified/CoreReader/Adopted.lean:952](#line-code-leanified-corereader-adopted-lean-952) · case + +Core dependencies: none. + +```lean +theorem consistencyCases : + (Satisfiable (singleton premiseP) ∧ Satisfiable (singleton premiseRule) ∧ + Satisfiable (singleton premiseNotQ) ∧ ¬ Satisfiable jointTheory) ∧ + ((Consequence emptyTheory (assumptionContext true) () true ∧ + Consequence emptyTheory (assumptionContext false) () false) ∧ + (Consequence emptyTheory (meaningContext true) () true ∧ + Consequence emptyTheory (meaningContext false) () false) ∧ + (Consequence emptyTheory (scopeContext true) () true ∧ + Consequence emptyTheory (scopeContext false) () false) ∧ + (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w)) ∧ + (¬ TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (meaningContext true)) (contextSnapshot (meaningContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (scopeContext true)) (contextSnapshot (scopeContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (scopeContext true) 0) (contextSnapshot (scopeContext true) 1) false ∧ + (TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) true ∧ + ¬ Models (assumptionContext false).assumptions true)) ∧ + (Satisfiable (revisionSlice 0) ∧ Satisfiable (revisionSlice 1) ∧ + ¬ Satisfiable (union (revisionSlice 0) (revisionSlice 1))) ∧ + ((∀ time, Consistent (revisionSlice time) broadBoolContext) ∧ + ¬ Consistent (union (revisionSlice 0) (revisionSlice 1)) broadBoolContext) ∧ + (∀ p q : Claim Bool, + ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r) ∧ + (Consequence jointTheory jointContext012 () true ∧ + Consequence jointTheory jointContext012 () false ∧ + ¬ Consistent jointTheory jointContext012) := +``` + + + +## T06 · Consistency, truth and support differ + +Different conditions and compatible value tensions need not conflict. A consistent set can still be false at a particular world or fail to entail a conclusion. + +**Premises and representation:** The examples use explicit Boolean worlds, scoped contexts and simultaneous inequalities rather than a free correctness flag. + +**Proof or check:** A witness proves consistency; an outside countervaluation falsifies the claim or refutes the alleged entailment. Changing assumptions or scope changes the comparison object explicitly. + +**Limits:** Consistency is not sufficient empirical or value support; the counterexamples concern the disclosed mathematical representation. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.charter.consistency.meaning#p2](#source-organon-charter-consistency-meaning-p2), [organon.charter.consistency.limits#p1](#source-organon-charter-consistency-limits-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2) + +### `CoreReader.Adopted.consistencyLimits012` + +[leanified/CoreReader/Adopted.lean:987](#line-code-leanified-corereader-adopted-lean-987) · case + +Core dependencies: none. + +```lean +theorem consistencyLimits012 : + ((Consequence emptyTheory (assumptionContext true) () true ∧ + Consequence emptyTheory (assumptionContext false) () false) ∧ + (Consequence emptyTheory (meaningContext true) () true ∧ + Consequence emptyTheory (meaningContext false) () false) ∧ + (Consequence emptyTheory (scopeContext true) () true ∧ + Consequence emptyTheory (scopeContext false) () false) ∧ + (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w)) ∧ + ((∃ budget : Nat, 4 ≤ budget ∧ budget ≤ 6) ∧ + ¬ ((fun n : Nat => 4 ≤ n) = (fun n : Nat => n ≤ 6))) ∧ + (Consistent (singleton (fun w : Bool => w = true)) broadBoolContext ∧ + ¬ Models (singleton (fun w : Bool => w = true)) false ∧ + Consistent (emptyTheory : Theory Bool) broadBoolContext ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧ + (Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧ + (Consistent (union (singleton (fun n : Nat => 4 ≤ n)) (singleton (fun n => n ≤ 6))) tensionContext012) := +``` + + + +## T07 · Applicable self-application + +Relevant generation and assessment rules apply to the system and to principle formation, application and revision. Self-status supplies no exemption. + +**Premises and representation:** Each rule has an owner/key, applicability condition, actual input and outcome meaning. Matching keys must identify the same rule. + +**Proof or check:** Concrete records discharge applicable self targets. An application-only rule supplies an explicit inapplicable system case. Grounds-on-Grounds uses a real unsupported-scope counterworld and stated value rationale. + +**Limits:** Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.charter.reflexivity#p1](#source-organon-charter-reflexivity-p1), [organon.charter.reflexivity.meaning#p1](#source-organon-charter-reflexivity-meaning-p1), [organon.charter.reflexivity.limits#p1](#source-organon-charter-reflexivity-limits-p1), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3) + +### `CoreReader.Adopted.reflexivitySpecification` + +[leanified/CoreReader/Adopted.lean:110](#line-code-leanified-corereader-adopted-lean-110) · definition + +Core dependencies: none. + +```lean +def reflexivitySpecification {T I O : Type} (rules : List (ReflexiveRule T I O)) + (isSelf : T → Prop) (performed : PrincipleKey → T → I → O → Prop) : Prop := +``` + +### `CoreReader.Adopted.reflexivityCases012` + +[leanified/CoreReader/Adopted.lean:1015](#line-code-leanified-corereader-adopted-lean-1015) · case + +Core dependencies: `propext`, `Classical.choice`, `Quot.sound`. + +```lean +theorem reflexivityCases012 : + (reflexivitySpecification ((ownRules 0).map legacyRule) (fun s => s.owner = 0) + (legacyPerformed (ownRules 0) (completeOwnWork 0)) ∧ + (∀ phase, Performed (completeOwnWork 0) (.process 0 0 phase) .assessment) ∧ + Performed (completeOwnWork 0) (.system 0) .assessment ∧ + reflexivitySpecification ([applicationRule].map legacyRule) (fun s => s.owner = 0) + (legacyPerformed [applicationRule] applicationWork) ∧ + ¬ Performed applicationWork (.system 0) .assessment) ∧ + (Grounds012 (fun enabled => GroundsProvision012 enabled) canonicalArticulation [.value groundsPosition012] (.value groundsPosition012) ∧ + groundsPosition012.limits true ∧ groundsPosition012.relevantCriticism true) ∧ + (Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0) ∧ + groundsExperiment012 true = false ∧ groundsExperiment012 false = true ∧ + groundsPosition012.outcome true true = groundsExperiment012 true ∧ + groundsPosition012.outcome true false = groundsExperiment012 false) := +``` + + + +## T08 · Self-application supplies no self-proof + +A self-assessed or self-generated proposal may lack support. In one shared finite context, the complete represented Charter holds while a concrete general Grounds task fails. + +**Premises and representation:** CompleteCharter012 includes valuation, revisability, whole-set consistency, truthful reporting and actual applicable self-work for the same system. + +**Proof or check:** charterWithoutGrounds012 constructs that Charter witness. The budget observation admits a world that fails the claimed output capability, so it cannot discharge the identified capability facet. + +**Limits:** This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.charter.reflexivity.limits#p1](#source-organon-charter-reflexivity-limits-p1), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.grounds#p1](#source-organon-grounds-p1) + +### `CoreReader.Adopted.reflexivityLimits012` + +[leanified/CoreReader/Adopted.lean:1038](#line-code-leanified-corereader-adopted-lean-1038) · case + +Core dependencies: `propext`, `Quot.sound`. + +```lean +theorem reflexivityLimits012 : + (selfTest [1] = true ∧ ownArithmeticPrinciple 0 = false ∧ + ¬ (∀ n, ownArithmeticPrinciple n = true)) ∧ + (localGenerator 0 0 = true ∧ localGenerator 0 1 = false ∧ + Compatible [zeroRecord] (localGenerator 0) ∧ + ¬ Supports [zeroRecord] allTrue ∧ OwnedRevisionExample) ∧ + (Generative openPolicy ∧ ¬ Reflexive 0 (ownRules 0) []) ∧ + (CompleteCharter012 CoreReader.Integration.actualSystem CoreReader.Integration.actual ∧ + Admissible CoreReader.Integration.held CoreReader.Integration.context CoreReader.Integration.actual ∧ + Compatible [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.actual ∧ + Articulated (canonicalArticulation CoreReader.Integration.unsupportedCapabilityFacet) ∧ + ¬ Supports [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.capability ∧ + ¬ Grounds012 CoreReader.Integration.capability canonicalArticulation + [CoreReader.Integration.unsupportedCapabilityFacet] + (taskOfFacet CoreReader.Integration.unsupportedCapabilityFacet)) ∧ + (generationSpecification openPolicy ∧ openPolicy.revisable ⟨.principle,0⟩ ∧ + selfExemptPerformed012 ⟨0,1⟩ 1 1 true ∧ + selfExemptRule012.applicable 0 ∧ + ¬ reflexivitySpecification [selfExemptRule012] (fun target => target = 0) selfExemptPerformed012) := +``` + + + +## T09 · Grounds for the original assessment task + +Grounds012 requires a nonempty set of articulated, discharged facets appropriate to the original claim task. Clear articulation alone is insufficient. + +**Premises and representation:** AssessmentTask fixes original observations/scope/claim/uncertainty, original inference premises, or the actual value position. NatureAppropriate compares contents, not type labels alone. + +**Proof or check:** Input-zero evidence supports input zero but admits a failing input-one counterworld. Replacing the original empirical task by a new premise that assumes its conclusion is rejected; the legitimate inference adapter retains the original observation/scope premises and uncertainty. + +**Limits:** This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.grounds#p1](#source-organon-grounds-p1), [organon.grounds.assessment#p1](#source-organon-grounds-assessment-p1), [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3) + +### `CoreReader.Adopted.Grounds012` + +[leanified/CoreReader/Adopted.lean:54](#line-code-leanified-corereader-adopted-lean-54) · definition + +Core dependencies: `propext`. + +```lean +def Grounds012 {W : Type} (claim : Claim W) + (articulations : Facet W → Articulation W) (facets : List (Facet W)) + (task : AssessmentTask W) : Prop := +``` + +### `CoreReader.Adopted.groundsCases012` + +[leanified/CoreReader/Adopted.lean:1066](#line-code-leanified-corereader-adopted-lean-1066) · case + +Core dependencies: `propext`. + +```lean +theorem groundsCases012 : + (Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧ + Articulated (canonicalArticulation globalFacet012) ∧ + ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧ + ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012)) ∧ + (Articulated uninformativeArgument ∧ + ¬ Entails uninformativeArgument.assumptions (fun w : Bool => w = true)) ∧ + (Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] (taskOfFacet circularGlobalFacet012) ∧ + ¬ NatureAppropriate originalGlobalTask012 circularGlobalFacet012 ∧ + ¬ Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] originalGlobalTask012) := +``` + + + +## T10 · Empirical support and uncertainty + +The empirical adapter checks compatible observations, an inhabited application scope, support for the stated claim and its stated uncertainty. + +**Premises and representation:** Records are mathematical observation functions and recorded values. Their relation to real measurements requires an external interpretation. + +**Proof or check:** A relevant input-zero record supports a local claim. Repeated irrelevant observations do not support another object; two compatible worlds retain different unobserved outcomes in the uncertainty case. + +**Limits:** Repeatability or measurability alone does not establish relevance, correctness or value; varying unobserved outcomes need not contradict limited support. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2) + +### `CoreReader.Adopted.empiricalSpecification` + +[leanified/CoreReader/Adopted.lean:152](#line-code-leanified-corereader-adopted-lean-152) · definition + +Core dependencies: `propext`. + +```lean +def empiricalSpecification {W : Type} (records : List (Record W)) + (scope claim uncertainty : Claim W) : Prop := +``` + +### `CoreReader.Adopted.empiricalCases012` + +[leanified/CoreReader/Adopted.lean:1082](#line-code-leanified-corereader-adopted-lean-1082) · case + +Core dependencies: `propext`. + +```lean +theorem empiricalCases012 : + (Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧ + Articulated (canonicalArticulation globalFacet012) ∧ + ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧ + ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012)) ∧ + (temperatureRecord.test (true,false) = true ∧ + Compatible [temperatureRecord,temperatureRecord] (true,false) ∧ + Compatible [temperatureRecord,temperatureRecord] (true,true) ∧ + ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + Compatible [actionRecord,actionRecord] (true,0) ∧ + Compatible [actionRecord,actionRecord] (true,3) ∧ + ¬ Supports [actionRecord] announcementPosition.consequence ∧ + ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧ + ¬ ValueProcedure announcementPosition) ∧ + (empiricalSpecification [temperatureRecord, temperatureRecord] (fun _ => True) + (fun w => w.1 = true) (fun w => w.2 = true ∨ w.2 = false) ∧ + Compatible [temperatureRecord, temperatureRecord] (true,true) ∧ + Compatible [temperatureRecord, temperatureRecord] (true,false)) ∧ + (Grounds012 (fun f => f 0 = true) canonicalArticulation [localFacet012] originalLocalTask012 ∧ + Grounds012 (fun f => f 0 = true) canonicalArticulation [observedInferenceFacet012] originalLocalTask012) ∧ + (FacetDischarged uncertaintyBypassFacet012 ∧ + ¬ NatureAppropriate originalUncertaintyTask012 uncertaintyBypassFacet012 ∧ + ¬ Grounds012 (fun w : Bool × Bool => w.1 = true) canonicalArticulation + [uncertaintyBypassFacet012] originalUncertaintyTask012) := +``` + + + +## T11 · Inference and negative examination + +Inferential support requires entailment from satisfiable stated assumptions. A correctly completed examination may instead reject a conclusion. + +**Premises and representation:** Entails quantifies over all models of the supplied theory. InferenceExamined records whether acceptance matches actual entailment. + +**Proof or check:** The arithmetic case derives n + 1 = 3 from n = 2. The Boolean counterworld satisfies the same empty theory but falsifies the conclusion, validating a negative examination. + +**Limits:** Failure of support is not failure to assess correctly; consistency with assumptions is weaker than entailment. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2) + +### `CoreReader.Adopted.inferentialSpecification` + +[leanified/CoreReader/Adopted.lean:161](#line-code-leanified-corereader-adopted-lean-161) · definition + +Core dependencies: `propext`. + +```lean +def inferentialSpecification {W : Type} (assumptions : Theory W) (claim : Claim W) : Prop := +``` + +### `CoreReader.Adopted.inferentialCases012` + +[leanified/CoreReader/Adopted.lean:1114](#line-code-leanified-corereader-adopted-lean-1114) · case + +Core dependencies: `propext`. + +```lean +theorem inferentialCases012 : + (inferentialSpecification (singleton (fun n : Nat => n = 2)) (fun n => n + 1 = 3) ∧ + InferenceExamined (emptyTheory : Theory Bool) (fun w => w = true) false ∧ + Models (emptyTheory : Theory Bool) false ∧ ¬ ((fun w : Bool => w = true) false)) ∧ + (Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧ + (FacetDischarged (Facet.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) ∧ + ¬ Grounds012 (fun w : Bool => w = true) canonicalArticulation + [.inferential (singleton (fun w => w = true)) (fun w => w = true)] + (.inferential emptyTheory (fun w => w = true))) := +``` + + + +## T12 · Value positions and reasons + +A value position states adoption, reasons, limits, consequences and responses to relevant criticism. Initial adoption is not inferred from observation alone. + +**Premises and representation:** ValueProcedure uses supplied objectives and constraints, a joint adoption/reasons witness, conditional adequacy, and a response where criticism applies. + +**Proof or check:** The switch example has real budget/benefit consequences. Removing the relevant response fails the procedure; a neutral observation does not force adoption. + +**Limits:** The application supplies a sufficient value assessment, not a universal requirement to prove every starting assumption or a proof that one value is universally best. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3) + +### `CoreReader.Adopted.valueSpecification` + +[leanified/CoreReader/Adopted.lean:168](#line-code-leanified-corereader-adopted-lean-168) · definition + +Core dependencies: `propext`. + +```lean +def valueSpecification {W : Type} (position : ValuePosition W) : Prop := +``` + +### `CoreReader.Adopted.valueCases012` + +[leanified/CoreReader/Adopted.lean:1131](#line-code-leanified-corereader-adopted-lean-1131) · case + +Core dependencies: `propext`, `Classical.choice`, `Quot.sound`. + +```lean +theorem valueCases012 : + (valueSpecification switchPosition) ∧ + (announcementPosition.reasons ≠ [] ∧ announcementPosition.commitment (true,0) ∧ + (∀ reason, reason ∈ announcementPosition.reasons → reason (true,0) announcementPosition.adopted) ∧ + ¬ announcementPosition.consequence (true,0) ∧ ¬ ValueProcedure announcementPosition) ∧ + (¬ ValueProcedure closedPosition012) ∧ + (ValueProcedure switchPosition ∧ + Satisfiable switchPosition.starting ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧ + (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧ + (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition)) ∧ + (FacetDischarged selectedFactFacet012 ∧ valueSpecification switchPosition ∧ + ¬ Grounds012 switchPosition.commitment canonicalArticulation [selectedFactFacet012] (.value switchPosition)) := +``` + + + +## T13 · Articulation and proportionality limits + +Clear reasons can be false or irrelevant. Qualitative implication can compare claim strength without a common numerical scale. + +**Premises and representation:** The examples fix actual counterworlds, neutral records and explicit starting value assumptions. + +**Proof or check:** A false-world witness rejects the clear factual argument. allTrue entails truth at input zero, while the converse fails at input one. Neither neutral evidence nor an empty theory entails the value commitment. + +**Limits:** These distinctions do not require values, empirical evidence and inference to be reduced to one score. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.grounds.assessment#p1](#source-organon-grounds-assessment-p1), [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3) + +### `CoreReader.Adopted.groundsLimits012` + +[leanified/CoreReader/Adopted.lean:1152](#line-code-leanified-corereader-adopted-lean-1152) · case + +Core dependencies: `propext`, `Classical.choice`, `Quot.sound`. + +```lean +theorem groundsLimits012 : + (Articulated clearFalseArgument012 ∧ ¬ Models clearFalseArgument012.assumptions false) ∧ + (temperatureRecord.test (true,false) = true ∧ + Compatible [temperatureRecord,temperatureRecord] (true,false) ∧ + Compatible [temperatureRecord,temperatureRecord] (true,true) ∧ + ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + Compatible [actionRecord,actionRecord] (true,0) ∧ + Compatible [actionRecord,actionRecord] (true,3) ∧ + ¬ Supports [actionRecord] announcementPosition.consequence ∧ + ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧ + ¬ ValueProcedure announcementPosition) ∧ + (valueSpecification switchPosition ∧ + Compatible [valueNeutralRecord012] false ∧ + ¬ Supports [valueNeutralRecord012] switchPosition.commitment ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment) ∧ + (ValueProcedure switchPosition ∧ + Satisfiable switchPosition.starting ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧ + (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧ + (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition)) ∧ + (ClaimNoStronger (fun f : Nat → Bool => f 0 = true) allTrue ∧ + ¬ ClaimNoStronger allTrue (fun f : Nat → Bool => f 0 = true) ∧ + valueSpecification switchPosition) := +``` + + + +## T14 · Relations, comparison scope and method roles + +Compared objects must lie in the stated conditions and observation scope, and satisfy the stated relevance relation. Each used assessment method needs a claim-specific role. + +**Premises and representation:** ScopeAccount supplies compared/relevant relations and an explains predicate. The concrete account additionally binds exact claim, conditions, role text and support facts. + +**Proof or check:** The local account restricts both inputs to zero. Measurement and repetition support that local output; the framework role explicitly retains the failed universal extrapolation. + +**Limits:** A nonempty role string alone is not sufficient interpretation, and an unused method does not become compulsory. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.grounds.scope#p1](#source-organon-grounds-scope-p1), [organon.grounds.scope#p2](#source-organon-grounds-scope-p2), [organon.grounds.scope#p3](#source-organon-grounds-scope-p3) + +### `CoreReader.Adopted.scopeSpecification` + +[leanified/CoreReader/Adopted.lean:191](#line-code-leanified-corereader-adopted-lean-191) · definition + +Core dependencies: none. + +```lean +def scopeSpecification {W : Type} (account : ScopeAccount W) : Prop := +``` + +### `CoreReader.Adopted.scopeCases012` + +[leanified/CoreReader/Adopted.lean:1184](#line-code-leanified-corereader-adopted-lean-1184) · case + +Core dependencies: `propext`. + +```lean +theorem scopeCases012 : + (scopeSpecification localScopeAccount012) ∧ + ((∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧ + (fun _ : Nat => true) 1 ≠ localGenerator 0 1) := +``` + + + +## T15 · Local evidence does not erase differences + +Equal local behavior can coexist with a relevant difference elsewhere. Limited observations can support a limited claim without a universal methodological chain. + +**Premises and representation:** Claims and observation scopes remain explicit. Random-output examples distinguish event observation, reproducible conditions and stability of a bounded conclusion. + +**Proof or check:** Concrete functions agree at zero and differ at one; one observation supports only its local claim. A mathematical inference and a value procedure provide examples using no obligatory observation chain. + +**Limits:** Omitting an input from comparison is not evidence that no relevant difference exists there. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.grounds.scope#p1](#source-organon-grounds-scope-p1), [organon.grounds.scope#p2](#source-organon-grounds-scope-p2), [organon.grounds.scope#p3](#source-organon-grounds-scope-p3), [organon.grounds.implementations.limits#p1](#source-organon-grounds-implementations-limits-p1) + +### `CoreReader.Adopted.scopeLimits012` + +[leanified/CoreReader/Adopted.lean:1197](#line-code-leanified-corereader-adopted-lean-1197) · case + +Core dependencies: `propext`, `Quot.sound`. + +```lean +theorem scopeLimits012 : + ((∃ outside : Nat, outside ≠ 0) ∧ + Compatible [zeroRecord] (fun _ => true) ∧ + Compatible [zeroRecord] (localGenerator 0) ∧ + allTrue (fun _ => true) ∧ ¬ allTrue (localGenerator 0) ∧ + ¬ Supports [zeroRecord] allTrue) ∧ + ((∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧ + (fun _ : Nat => true) 1 ≠ localGenerator 0 1) ∧ + ([zeroRecord].length = 1 ∧ + (∃ f, Compatible [zeroRecord] f) ∧ + Supports [zeroRecord] (fun f => f 0 = true) ∧ + ¬ Supports [zeroRecord] allTrue) ∧ + (let a : Trial := ⟨0,1,1⟩ +``` + + + +## T16 · Application-specific capability and understanding + +Capability claims retain their actual object, contract and grounds. An application may require more than reliable output or an output-equivalent explanation. + +**Premises and representation:** The output contract ranges over all natural inputs. A separate mechanism application defines operational understanding as explaining the same process and answering every input/multiplier variation; this is its selected criterion. + +**Proof or check:** ExternalCertificate checks output without introspection. Two mechanism objects share the same explainedProcess; the fixed-double responder fails at (3,1), while the mechanism responder proves the stronger contract and same-object Grounds012. The failing object also fails those same grounds. + +**Limits:** This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3) + +### `CoreReader.Adopted.capabilitySpecification` + +[leanified/CoreReader/Adopted.lean:205](#line-code-leanified-corereader-adopted-lean-205) · definition + +Core dependencies: `propext`. + +```lean +def capabilitySpecification (assessed : Process) (contract : Claim Process) : Prop := +``` + +### `CoreReader.Adopted.capabilityCases012` + +[leanified/CoreReader/Adopted.lean:1232](#line-code-leanified-corereader-adopted-lean-1232) · case + +Core dependencies: `propext`. + +```lean +theorem capabilityCases012 : + (capabilitySpecification outputOnlyProcess OutputContract ∧ + capabilitySpecification explainedProcess FullProcessContract ∧ + (∃ certificate : ExternalCertificate outputOnlyProcess, + certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧ + ¬ ExplanationContract outputOnlyProcess) ∧ + (OwnCapability012 7 7 outputOnlyProcess OutputContract) ∧ + (explainedWithoutVariation012.process = mechanismResponder012.process ∧ + FullProcessContract explainedWithoutVariation012.process ∧ + ¬ UnderstandingApplication012 explainedWithoutVariation012 ∧ + UnderstandingApplication012 mechanismResponder012 ∧ + Grounds012 UnderstandingApplication012 canonicalArticulation + [understandingFacet012 mechanismResponder012] (understandingTask012 mechanismResponder012) ∧ + ¬ Grounds012 UnderstandingApplication012 canonicalArticulation + [understandingFacet012 explainedWithoutVariation012] (understandingTask012 explainedWithoutVariation012)) := +``` + + + +## T17 · Output evidence does not imply introspection + +Reliable output, external articulation and increased inventory do not automatically establish process explanation or stronger capability. + +**Premises and representation:** The opaque process actually returns no explanatory certificate, while its output proof still covers all natural inputs. + +**Proof or check:** The proof combines correct output with absence of explanation. Duplicating copy artifacts across inventory kinds never supplies a successor operation; resource and inflated-state cases preserve that distinction. + +**Limits:** An external assessor can ground the selected output claim without establishing how the assessed system understands its generation process. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2) + +### `CoreReader.Adopted.capabilityLimits012` + +[leanified/CoreReader/Adopted.lean:1254](#line-code-leanified-corereader-adopted-lean-1254) · case + +Core dependencies: `propext`, `Quot.sound`. + +```lean +theorem capabilityLimits012 : + (capabilitySpecification outputOnlyProcess OutputContract ∧ + capabilitySpecification explainedProcess FullProcessContract ∧ + (∃ certificate : ExternalCertificate outputOnlyProcess, + certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧ + ¬ ExplanationContract outputOnlyProcess) ∧ + (∀ kind : InventoryKind, + Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .copy ∧ + ¬ Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .successor) ∧ + (Generative generatingSystem.policy ∧ + generatingSystem.policy.permitsVersion 0 0 ∧ + ¬ Expanded generatingSystem.current inflatedState ∧ + generatingSystem.current.inventory.length < inflatedState.inventory.length ∧ + generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧ + generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧ + generatingSystem.execute availableResources = some 6 ∧ + generatingSystem.execute { availableResources with experience := none } = none ∧ +``` + + + +## T18 · Grounded implementation choice + +Implementation priority requires reasons linked to objectives and constraints. Convention may contribute practically, but status alone is insufficient. + +**Premises and representation:** JustifiedChoice includes actual requirement satisfaction and at least one relevant method reason. Explanation, applicability, simplicity and process can be relevant within the chosen requirements. + +**Proof or check:** The conventional identity implementation satisfies its contract and budget. A cheap successor fails the required output despite its cost advantage; a status-only choice fails the reason condition. + +**Limits:** These are application reasons, not a universal cost function or a rule that conventional implementations must lose. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.grounds.implementations#p1](#source-organon-grounds-implementations-p1), [organon.grounds.implementations#p2](#source-organon-grounds-implementations-p2), [organon.grounds.implementations.limits#p1](#source-organon-grounds-implementations-limits-p1), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3) + +### `CoreReader.Adopted.choiceSpecification` + +[leanified/CoreReader/Adopted.lean:215](#line-code-leanified-corereader-adopted-lean-215) · definition + +Core dependencies: none. + +```lean +def choiceSpecification (requirements : Requirements) (implementation : Implementation) + (reasons : List Reason) : Prop := JustifiedChoice requirements implementation reasons +``` + +### `CoreReader.Adopted.choiceCases012` + +[leanified/CoreReader/Adopted.lean:1295](#line-code-leanified-corereader-adopted-lean-1295) · case + +Core dependencies: `propext`, `Classical.choice`, `Quot.sound`. + +```lean +theorem choiceCases012 : + (identityImpl.conventional = true ∧ identityImpl.established = true ∧ + JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output]) ∧ + (Relevant identityRequirements identityImpl (.method .explanation) ∧ + Relevant identityRequirements identityImpl (.method .applicability) ∧ + Relevant identityRequirements identityImpl (.method .simplicity) ∧ + Relevant identityRequirements identityImpl (.method .procedure) ∧ + (Relevant identityRequirements cheapSuccessor (.method .simplicity) ∧ + ¬ JustifiedChoice identityRequirements cheapSuccessor [.method .simplicity])) ∧ + (Articulated priorityArticulation ∧ AssessmentAccurate false ∧ + (∀ selected, Models statusFacts selected) ∧ + priorityClaim .identity ∧ ¬ priorityClaim .successor ∧ + ¬ Entails statusFacts priorityClaim ∧ + ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧ + ((∀ n, identityImpl.run n = wrongExplanation012.run n) ∧ + Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧ + Relevant identityRequirements identityImpl (.method .explanation) ∧ + ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation)) ∧ + (¬ choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation + [.status .standing] ∧ + choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation + [.method .output]) ∧ + (∀ kind : StatusKind, + ¬ choiceSpecification identityRequirements identityImpl [.status kind]) := +``` + + + +## T19 · Openness and the additional choice commitment + +Openness allows distinct alternatives and can coexist with only one feasible conventional option. The added choice rule is not obtained merely by completing a general assessment. + +**Premises and representation:** The limited general-assessment model and the stronger engineering non-entailment in T39 are different objects and results. + +**Proof or check:** Concrete requirement scopes distinguish alternatives that agree locally. The general-assessment case retains its stated assessment while the status-only priority lacks a relevant reason. + +**Limits:** No result asserts all implementations equivalent, multiple feasible implementations guaranteed, or the choice commitment derivable from chapter placement. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.grounds.implementations#p1](#source-organon-grounds-implementations-p1), [organon.grounds.implementations#p2](#source-organon-grounds-implementations-p2), [organon.grounds.implementations.limits#p1](#source-organon-grounds-implementations-limits-p1) + +### `CoreReader.Adopted.choiceLimits012` + +[leanified/CoreReader/Adopted.lean:1329](#line-code-leanified-corereader-adopted-lean-1329) · case + +Core dependencies: `propext`, `Classical.choice`, `Quot.sound`. + +```lean +theorem choiceLimits012 : + ((∀ candidate, Feasible identityRequirements (implementation candidate) ↔ candidate = .identity) ∧ + JustifiedChoice identityRequirements identityImpl objectiveReason) ∧ + (identityImpl.conventional = true ∧ identityImpl.established = true ∧ + JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output]) ∧ + ((∀ n, identityImpl.run n = wrongExplanation012.run n) ∧ + Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧ + Relevant identityRequirements identityImpl (.method .explanation) ∧ + ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation)) ∧ + (JustifiedChoice identityRequirements identityImpl objectiveReason ∧ + identityImpl.run 0 ≠ successorImpl.run 0) ∧ + ((∀ x, x = 0 → identityImpl.run x = changedOutsideZero.run x) ∧ + identityImpl.run 1 ≠ changedOutsideZero.run 1) ∧ + ((Articulated priorityArticulation ∧ AssessmentAccurate false ∧ + (∀ selected, Models statusFacts selected) ∧ + priorityClaim .identity ∧ ¬ priorityClaim .successor ∧ + ¬ Entails statusFacts priorityClaim ∧ + ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧ + PolicyIndependenceExample) := +``` + + + +## T20 · Mutual application in one engineering system + +The inherited duties apply to this system’s own principles, methods, value positions, capability reports and implementation choice. Actual normative contents enter its whole consistency theory. + +**Premises and representation:** Inherited fixes sharedContext and carries fulfilled generation, reflection, original empirical/inferential/value tasks, scope, capability and choice. ownTheory joins actual facts with every applicable OwnNorm content; consistency constrains this whole union. + +**Proof or check:** inheritedMutualApplication projects these actual fields and the full-content/support bridges; inheritedCurrent constructs them separately. Both actual reflection rules are self objects, and the evaluator’s revision test reports its local empty-sample defect. + +**Limits:** Projection does not derive all duties from one principle. Adoption markers are separate facts; they do not substitute for normative content. The sample-aware criticism is an application criterion, not a universal requirement for observations. + +**State:** accepted (theorem). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3) + +### `CoreReader.Engineering.inheritedMutualApplication` + +[leanified/CoreReader/Engineering/Integration.lean:420](#line-code-leanified-corereader-engineering-integration-lean-420) · theorem + +Core dependencies: `propext`. + +```lean +theorem inheritedMutualApplication (ctx : Context) (chosen : Candidate) + (inherited : Inherited ctx chosen) : + generationSpecification engineeringPolicy ∧ + reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self + (selfModel chosen).performed ∧ + (∀ principle, valueSpecification (governancePosition principle)) ∧ + capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen) ∧ + choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons ∧ + (∀ fact, inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact)) ∧ + (∀ norm, normApplies chosen norm → ownTheory chosen (ownNormClaim chosen norm)) ∧ + (∀ claim, ownTheory chosen claim → inferentialSpecification (ownFactPremises chosen) claim) ∧ + consistencySpecification (engineeringSnapshot .evolvable 0) + (engineeringSnapshot chosen 1) true := +``` + +### `CoreReader.Engineering.inheritedMutualCases` + +[leanified/CoreReader/Engineering/Integration.lean:442](#line-code-leanified-corereader-engineering-integration-lean-442) · case + +Core dependencies: `propext`, `Classical.choice`, `Quot.sound`. + +```lean +theorem inheritedMutualCases : + Inherited sharedContext .evolvable ∧ + valueSpecification (governancePosition .grounds) ∧ + capabilitySpecification (engineeringProcess .evolvable) (engineeringCapability .evolvable) ∧ + choiceSpecification chosenRequirements (chosenImplementation .evolvable) chosenReasons ∧ + Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧ + (.generationRule : ReviewObject) ∈ (selfModel .evolvable).objects ∧ + (.assessmentRule : ReviewObject) ∈ (selfModel .evolvable).objects ∧ + Reflection.evaluate ((selfModel .evolvable).input ⟨0, .assessmentRule, .revision⟩) = .counterexample := +``` + + + +## T21 · Existing forms and assessment + +Existing forms include organization, methods and principles. Assessment includes examination of reasons and applicability, not only executable tests. + +**Premises and representation:** These terms constrain interpretation throughout the source and the other targets. + +**Proof or check:** The source tracing preserves the exact terms. Form kinds and both inferential/value examples illustrate their use without assigning a new theorem to the glossary. + +**Limits:** The finite test machinery used here does not redefine all assessment as testing. + +**State:** accepted (boundary). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.relationships.terms#p1](#source-organon-relationships-terms-p1) + +This boundary target has no Lean declaration. + + + +## T22 · The continuing engineering activity + +The subject is an activity involving maintainers, software, tools and accessible knowledge across its actual lifecycle. A temporary label does not establish a bounded lifecycle. + +**Premises and representation:** ActivityScope requires nonempty participants, software and tools, with knowledge for the participants. Continuing and BoundedLifecycle inspect releases, maintenance and bounded runs. + +**Proof or check:** The continuing example has three releases and six maintenance periods despite its label. Separate temporary, prototype and retiring activities have genuinely bounded execution and no scheduled continuation. + +**Limits:** These numerical schedules are finite model data, not project time estimates. Scope alone does not prove every participant can perform every change. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.purpose#p1](#source-software-engineering-purpose-p1), [software-engineering.purpose#p2](#source-software-engineering-purpose-p2), [software-engineering.purpose#p3](#source-software-engineering-purpose-p3) + +### `CoreReader.Engineering.ActivityScope` + +[leanified/CoreReader/Engineering/Domain.lean:49](#line-code-leanified-corereader-engineering-domain-lean-49) · definition + +Core dependencies: none. + +```lean +abbrev ActivityScope (a : Activity) : Prop := +``` + +### `CoreReader.Engineering.subjectLifecycleCases` + +[leanified/CoreReader/Engineering/Domain.lean:146](#line-code-leanified-corereader-engineering-domain-lean-146) · case + +Core dependencies: `propext`. + +```lean +theorem subjectLifecycleCases : + ActivityScope continuingActivity ∧ + CanChange continuingActivity .evolvable .successor .designRevision ∧ + CanChange continuingActivity .evolvable .agent .designRevision ∧ + continuingActivity.label = "temporary" ∧ Continuing continuingActivity ∧ + ¬ BoundedLifecycle continuingActivity ∧ BoundedLifecycle temporaryActivity ∧ + BoundedLifecycle prototypeActivity ∧ BoundedLifecycle retiringActivity := by decide +``` + + + +## T23 · Private editability and shared capability + +The original author’s ability to edit does not establish successor or agent capability. A passive artifact does not itself inherit the activity’s intentions. + +**Premises and representation:** CanChange checks a nonempty actual edit/verification path, participant identity, tools and the knowledge required by every step. + +**Proof or check:** The simple design requires privateLayout. The original author has it; successor and agent do not. The documented path uses their available public knowledge and tools. Artifact execution remains distinct from maintainer proposals. + +**Limits:** The result concerns the represented paths; lack of one documented path is not a universal impossibility theorem about all maintenance. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.purpose#p1](#source-software-engineering-purpose-p1), [software-engineering.purpose#p2](#source-software-engineering-purpose-p2), [software-engineering.purpose#p3](#source-software-engineering-purpose-p3) + +### `CoreReader.Engineering.subjectLimits` + +[leanified/CoreReader/Engineering/Domain.lean:159](#line-code-leanified-corereader-engineering-domain-lean-159) · case + +Core dependencies: `propext`. + +```lean +theorem subjectLimits : + CanChange continuingActivity .presentSimple .original .designRevision ∧ + ¬ CanChange continuingActivity .presentSimple .successor .designRevision ∧ + ¬ ContinuingCapability continuingActivity .presentSimple .designRevision ∧ + continuingActivity.label = "temporary" ∧ ¬ BoundedLifecycle continuingActivity ∧ + orientation .agent ≠ [] ∧ passiveArtifact [2, 1] = [2, 1] ∧ + EngineeringAction.propose .designRevision ∈ maintainerActions .agent ∧ + EngineeringAction.propose .designRevision ∉ artifactActions [2, 1] := by decide +``` + + + +## T24 · Conditions of evolution priority + +EvolutionPriority is a conditional adopted preference: when all PriorityConditions hold, choose evolvable or supply a justified departure. + +**Premises and representation:** Conditions require ongoing releases and maintenance; nonempty participants, software identity and tools; some available knowledge for every participant; both candidates meeting behavior/safety/latency/retention requirements; credible design revision; and a nonempty evolvable revision path whose required knowledge and tools are available to every listed participant. That path must have lower work than the simple option, while the evolvable option has greater present complexity. + +**Proof or check:** Each necessary-requirement failure blocks applicability. The ordinary context has work 6 versus 17 and complexity 3 versus 1. A concrete cost threat can justify departure; an unexplained excuse cannot. The maximal candidate adds a real CSV path but exceeds the budget. + +**Limits:** This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.purpose#p3](#source-software-engineering-purpose-p3), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3) + +### `CoreReader.Engineering.EvolutionPriority` + +[leanified/CoreReader/Engineering/Domain.lean:321](#line-code-leanified-corereader-engineering-domain-lean-321) · definition + +Core dependencies: none. + +```lean +abbrev EvolutionPriority (ctx : Context) (chosen : Candidate) : Prop := +``` + +### `CoreReader.Engineering.priorityConditionsCases` + +[leanified/CoreReader/Engineering/Domain.lean:367](#line-code-leanified-corereader-engineering-domain-lean-367) · case + +Core dependencies: `propext`. + +```lean +theorem priorityConditionsCases : + EvolutionPriority currentContinuing .evolvable ∧ + ¬ Meets normalRequirements { profile .evolvable with orderOutput := [1, 2] } ∧ +``` + + + +## T25 · The applicable priority theorem + +With the adopted priority rule, all applicability conditions and no justified departure, the choice must be evolvable and accept its greater present complexity. + +**Premises and representation:** priorityWhenApplicable receives EvolutionPriority, PriorityConditions and the absence of JustifiedDeparture. These are premises of the theorem. + +**Proof or check:** Apply the rule to the supplied conditions, eliminate the departure branch, and project the strict complexity comparison. Concrete cases check the evolvable selection, the violating simple selection and a threat-supported departure. + +**Limits:** The theorem neither proves the value rule from facts nor establishes that every apparently complex design has the relevant advantage. + +**State:** accepted (theorem). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3) + +### `CoreReader.Engineering.priorityWhenApplicable` + +[leanified/CoreReader/Engineering/Domain.lean:337](#line-code-leanified-corereader-engineering-domain-lean-337) · theorem + +Core dependencies: none. + +```lean +theorem priorityWhenApplicable (ctx : Context) (chosen : Candidate) + (rule : EvolutionPriority ctx chosen) (applicable : PriorityConditions ctx) + (noDeparture : ¬ JustifiedDeparture ctx .evolvable) : + chosen = .evolvable ∧ + abstractionComplexity .presentSimple < abstractionComplexity chosen := by +``` + +### `CoreReader.Engineering.priorityChoices` + +[leanified/CoreReader/Engineering/Domain.lean:384](#line-code-leanified-corereader-engineering-domain-lean-384) · case + +Core dependencies: `propext`. + +```lean +theorem priorityChoices : + EvolutionPriority currentContinuing .evolvable ∧ + ¬ EvolutionPriority currentContinuing .presentSimple ∧ + EvolutionPriority (threatened .verification) .presentSimple := by +``` + + + +## T26 · Grounded credible directions + +Credible directions have articulated supporting grounds. An existing plurality of implementations is unnecessary, while mere imagination is insufficient. + +**Premises and representation:** The adapter examines plan, domain-knowledge and history contents, with an additional extensible evidence form. These are application constructors, not an exhaustive philosophical checklist. + +**Proof or check:** The registered plan identifies release 2 and design revision. Knowledge/history cases check their concrete relevance. An imagined-only entry fails, and changed evidence can produce a changed forecast. + +**Limits:** The proof checks stipulated evidence contents, not the real-world credibility or predictive calibration of arbitrary plans. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3) + +### `CoreReader.Engineering.CredibleDirection` + +[leanified/CoreReader/Engineering/Domain.lean:174](#line-code-leanified-corereader-engineering-domain-lean-174) · definition + +Core dependencies: none. + +```lean +abbrev CredibleDirection {Ground : Type} (grounds : List Ground) + (articulated : Ground → Bool) (supports : Ground → Change → Bool) + (d : Change) : Prop := +``` + +### `CoreReader.Engineering.credibilityCases` + +[leanified/CoreReader/Engineering/Domain.lean:212](#line-code-leanified-corereader-engineering-domain-lean-212) · case + +Core dependencies: none. + +```lean +theorem credibilityCases : + credible initialGrounds .designRevision ∧ + credible [.knowledge "queue" [.designRevision] "tenant-config-reload"] .designRevision ∧ + credible [.history "queue" [.migration, .migration]] .migration ∧ + ¬ credible [] (.other "quantum backend") ∧ + credible forecastGrounds .deletion ∧ ¬ credible forecastGrounds .designRevision := by decide +``` + + + +## T27 · Credibility is not unlimited accommodation + +Credible change can warrant selective accommodation without multiple current implementations or maximal expansion. Conceivability alone supplies no such support. + +**Premises and representation:** The case retains one existing implementation, a supported particular direction and explicit cost dimensions. + +**Proof or check:** The credible plan case remains valid with one implementation. Imagined evidence fails support. The actual selective design and separate cost coordinates avoid requiring every possibility or a common exchange rate. + +**Limits:** No finite list of directions proves all future changes predictable or all omitted possibilities irrelevant. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3) + +### `CoreReader.Engineering.credibilityLimits` + +[leanified/CoreReader/Engineering/Domain.lean:394](#line-code-leanified-corereader-engineering-domain-lean-394) · case + +Core dependencies: `propext`. + +```lean +theorem credibilityLimits : + credible initialGrounds .designRevision ∧ implementedVariants.length = 1 ∧ + ¬ WarrantedAccommodation [] (.other "quantum backend") 0 5 ∧ + ¬ credible initialGrounds (.other "quantum backend") ∧ + EvolutionPriority currentContinuing .evolvable ∧ + abstractionComplexity .evolvable < abstractionComplexity .maximal ∧ + cost .evolvable .construction < cost .evolvable .migration ∧ + ¬ MaximumRegisteredCapability continuingActivity .evolvable ∧ + MaximumRegisteredCapability continuingActivity .maximal ∧ + (supportedDirections continuingActivity .evolvable).length = 9 ∧ + (supportedDirections continuingActivity .maximal).length = 10 ∧ + ¬ credible initialGrounds (.other "csv export") := by decide +``` + + + +## T28 · Concrete costs and justified departure + +Departure identifies which concrete objective is threatened by added cost. The model admits seven distinct burdens without summing them into one universal score. + +**Premises and representation:** ConcreteThreat connects actual candidate cost, the simpler comparison cost and the capacity of the named burden. JustifiedDeparture binds the recorded burden and objective to that threat. + +**Proof or check:** Separate cases lower the relevant capacity for understanding, construction, diagnosis, verification, coordination, operation and migration. An arbitrary recorded excuse with no actual threatened capacity fails. + +**Limits:** The finite costs are modeled work/budget data. The source does not require every category to apply or provide a universal numerical tradeoff. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3) + +### `CoreReader.Engineering.JustifiedDeparture` + +[leanified/CoreReader/Engineering/Domain.lean:298](#line-code-leanified-corereader-engineering-domain-lean-298) · definition + +Core dependencies: none. + +```lean +abbrev JustifiedDeparture (ctx : Context) (c : Candidate) : Prop := +``` + +### `CoreReader.Engineering.costCases` + +[leanified/CoreReader/Engineering/Domain.lean:410](#line-code-leanified-corereader-engineering-domain-lean-410) · case + +Core dependencies: `propext`. + +```lean +theorem costCases : + JustifiedDeparture (threatened .understanding) .evolvable ∧ + JustifiedDeparture (threatened .construction) .evolvable ∧ + JustifiedDeparture (threatened .diagnosis) .evolvable ∧ + JustifiedDeparture (threatened .verification) .evolvable ∧ + JustifiedDeparture (threatened .coordination) .evolvable ∧ + JustifiedDeparture (threatened .operation) .evolvable ∧ + JustifiedDeparture (threatened .migration) .evolvable ∧ + ¬ JustifiedDeparture { currentContinuing with departure := some .migration } .evolvable := by decide +``` + + + +## T29 · Kinds of evolution and changed obligations + +Evolution includes adding, replacing, deleting, withdrawing abstractions, redrawing boundaries and migrating, with distinct independent/coordinated paths and contract treatment. + +**Premises and representation:** EvolutionClaim connects the identified request and maintainer capability to the corresponding contract account, an actual contractRunner step, and preserve/revise treatment of the specified observation. SoftwareState transformations are separate conjuncts of evolutionKindsCases, not fields of this predicate. + +**Proof or check:** The cases compute addition, replacement, deletion, withdrawal, boundary and migration state changes as separate conjuncts. They also verify successor paths, preservation for the replacement request, explicit contract revision for redrawing, and different independent/coordinated work. The revision account concerns the changed observable behavior; the state-transform conjuncts are separately checked. + +**Limits:** The enumerated constructors illustrate source dimensions and allow an other direction; they do not claim every possible evolution is represented or cheap. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.evolution-meaning#p1](#source-software-engineering-evolution-meaning-p1), [software-engineering.evolution-meaning#p2](#source-software-engineering-evolution-meaning-p2) + +### `CoreReader.Engineering.EvolutionClaim` + +[leanified/CoreReader/Engineering/Domain.lean:556](#line-code-leanified-corereader-engineering-domain-lean-556) · definition + +Core dependencies: none. + +```lean +abbrev EvolutionClaim (a : Activity) (c : Candidate) (claim : ChangeClaim) : Prop := +``` + +### `CoreReader.Engineering.evolutionKindsCases` + +[leanified/CoreReader/Engineering/Domain.lean:569](#line-code-leanified-corereader-engineering-domain-lean-569) · case + +Core dependencies: `propext`. + +```lean +theorem evolutionKindsCases : + (transform .addition originalSoftware).capabilities = ["deduplicate", "tenant batching"] ∧ + (transform .replacement originalSoftware).implementation = 1 ∧ + (transform .deletion originalSoftware).mechanisms = ["queue"] ∧ + (transform .withdrawal originalSoftware).abstractions = [] ∧ + (transform .redrawing originalSoftware).boundary = 1 ∧ + (transform .migration originalSoftware).technology = "portable store" ∧ + changes.all (fun d => decide (CanChange continuingActivity .evolvable .successor d)) = true ∧ + EvolutionClaim continuingActivity .evolvable ⟨.replacement, .successor, .preserve⟩ ∧ + EvolutionClaim continuingActivity .evolvable ⟨.redrawing, .agent, .revise⟩ ∧ + changeWork .evolvable .independent < changeWork .evolvable .coordinated := by decide +``` + + + +## T30 · One evolution advantage is not every advantage + +Easy additions within a scheme do not imply easy exit from it, and an advantage in design revision does not imply a strict advantage in every dimension. + +**Premises and representation:** Work is computed from the actual edit/verification paths for the same designs and change kinds. + +**Proof or check:** The simple design has a short addition path and a 17-unit withdrawal path. The evolvable design improves design revision from 17 to 6, while addition remains 2 for both; coordinated work can exceed independent work. + +**Limits:** These counterexamples reject unjustified cross-dimension inference without adding a duty that every change be inexpensive. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.evolution-meaning#p1](#source-software-engineering-evolution-meaning-p1), [software-engineering.evolution-meaning#p2](#source-software-engineering-evolution-meaning-p2) + +### `CoreReader.Engineering.evolutionDimensionsLimits` + +[leanified/CoreReader/Engineering/Domain.lean:585](#line-code-leanified-corereader-engineering-domain-lean-585) · case + +Core dependencies: `propext`. + +```lean +theorem evolutionDimensionsLimits : + changeWork .presentSimple .addition = 2 ∧ + changeWork .presentSimple .withdrawal = 17 ∧ + changeWork .evolvable .independent < changeWork .evolvable .coordinated ∧ + EvolutionPriority currentContinuing .evolvable ∧ + 9 < changeWork .evolvable .migration ∧ + CanChange continuingActivity .presentSimple .original .addition ∧ + CanChange continuingActivity .evolvable .original .addition ∧ + CanChange continuingActivity .presentSimple .original .designRevision ∧ + CanChange continuingActivity .evolvable .original .designRevision ∧ + changeWork .evolvable .designRevision < changeWork .presentSimple .designRevision ∧ + changeWork .evolvable .addition = changeWork .presentSimple .addition ∧ + (transform (.other "csv export") originalSoftware).capabilities = ["deduplicate", "csv export"] ∧ + CanChange continuingActivity .maximal .successor (.other "csv export") ∧ + ¬ CanChange continuingActivity .evolvable .successor (.other "csv export") := by +``` + + + +## T31 · Structural consequences and crossing obligations + +Structural assessment connects intended changes to propagation, actual observable contracts, knowledge and verification work. A boundary label alone cannot establish the crossing obligation is handled. + +**Premises and representation:** StructuralAccount binds recorded touched components, observations and work to actual paths. The boundary case has caller 2, callee 1 and an explicit order-preserving obligation. + +**Proof or check:** The coordinated change edits callee 1 and checks the contract at caller 2. Deleting that caller check keeps the crossing but fails boundaryObligationChecked; moving the callee to untouched 7 changes applicability; sorting the output fails the same observable contract. + +**Limits:** These are relevant finite inquiries, not a mandatory universal checklist or a real-world estimate of all boundary costs. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2) + +### `CoreReader.Engineering.StructuralAccount` + +[leanified/CoreReader/Engineering/Domain.lean:641](#line-code-leanified-corereader-engineering-domain-lean-641) · definition + +Core dependencies: none. + +```lean +abbrev StructuralAccount (a : Activity) (c : Candidate) (e : StructuralEvidence) : Prop := +``` + +### `CoreReader.Engineering.structuralCases` + +[leanified/CoreReader/Engineering/Domain.lean:733](#line-code-leanified-corereader-engineering-domain-lean-733) · case + +Core dependencies: `propext`. + +```lean +theorem structuralCases : + StructuralAccount continuingActivity .evolvable (structuralEvidence .evolvable .designRevision) ∧ + (propagation .presentSimple .designRevision).length = 3 ∧ + (propagation .evolvable .designRevision).length = 2 ∧ + (changePath .evolvable .coordinated).any (fun s => s.component == 2 && s.requires == .publicContract) = true ∧ + PreservesFinite orderedUnique orderedRefactor ∧ + (structuralEvidence .evolvable .designRevision).observedBefore ≠ + (structuralEvidence .evolvable .designRevision).observedAfter ∧ + staticBatch 21 10 = liveBatch 21 10 ∧ staticBatch 21 5 ≠ liveBatch 21 5 ∧ + changeWork .presentSimple .withdrawal = 17 ∧ + (crossesBoundary boundaryDesign .coordinated coordinatedBoundary = true ∧ + boundaryObligationChecked boundaryDesign .coordinated coordinatedBoundary = true ∧ + crossesBoundary omittedCallerCheck .coordinated coordinatedBoundary = true ∧ + boundaryObligationChecked omittedCallerCheck .coordinated coordinatedBoundary = false ∧ + crossesBoundary otherCalleeDesign .coordinated otherCalleeBoundary = false ∧ + boundaryObligationChecked { boundaryDesign with run := sortedUnique } +``` + + + +## T32 · Structure names do not prove capability + +The same signature, module count or named principle can hide different behavior or change capability. Introducing a real boundary need not reduce change work. + +**Premises and representation:** EngineeringDesign contains actual behavior, component paths, boundaries and fixed batch assumptions; metadata is kept separate. + +**Proof or check:** Same signatures produce ordered versus sorted output. Eight modules all require the size change. Private and documented paths share metadata but differ for the successor. A new boundary relocates existing verification steps, retaining work 17 and missing private knowledge; a separate added-check variant costs 18. + +**Limits:** The equal-work case preserves step units through an actual path transformation; these units are a disclosed model measure, not observed engineering effort. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2) + +### `CoreReader.Engineering.structureNotCapability` + +[leanified/CoreReader/Engineering/Domain.lean:793](#line-code-leanified-corereader-engineering-domain-lean-793) · case + +Core dependencies: `propext`. + +```lean +theorem structureNotCapability : + (privateDesign.metadata.signature = sortedDesign.metadata.signature ∧ + privateDesign.run [2, 1, 2] = [2, 1] ∧ sortedDesign.run [2, 1, 2] ≠ [2, 1]) ∧ + (privateDesign.metadata.modules = privateDesign.components.length ∧ + privateDesign.batchAssumptions.length = 8 ∧ + (designModulesNeedingRevision privateDesign 5).length = 8) ∧ + (privateDesign.metadata.principle = "dependency inversion" ∧ + privateDesign.metadata = documentedDesign.metadata ∧ + ¬ DesignCanChange continuingActivity privateDesign .successor .designRevision ∧ + DesignCanChange continuingActivity documentedDesign .successor .designRevision) ∧ + (privateDesign.boundaries.length = 0 ∧ wrappedDesign.boundaries.length = 1 ∧ + wrappedDesign.components.length = 9 ∧ + wrappedDesign.boundaries = [⟨8, 0, "List Nat → List Nat"⟩] ∧ + wrappedDesign.run [2, 1, 2] = privateDesign.run [2, 1, 2] ∧ + designWork privateDesign .designRevision = 17 ∧ + designWork wrappedDesign .designRevision = 18 ∧ + ¬ designWork wrappedDesign .designRevision < designWork privateDesign .designRevision) ∧ + (sameWorkDesign.boundaries = [⟨8, 0, "List Nat → List Nat"⟩] ∧ + sameWorkDesign.components.length = 9 ∧ + sameWorkDesign.paths .designRevision ≠ privateDesign.paths .designRevision ∧ + sameWorkDesign.run [2, 1, 2] = privateDesign.run [2, 1, 2] ∧ + designWork sameWorkDesign .designRevision = designWork privateDesign .designRevision ∧ + designWork sameWorkDesign .designRevision = 17 ∧ + ¬ DesignCanChange continuingActivity sameWorkDesign .successor .designRevision) := by +``` + + + +## T33 · Preservation versus deliberate contract revision + +An identified contract can be preserved or deliberately revised. Revision accounts identify changed obligations and affected parties instead of silently relabeling changed behavior as preservation. + +**Premises and representation:** ObservableContract includes order behavior and retry limits. Actual party dependencies determine which consumers/operators are affected; a report cannot define them away. + +**Proof or check:** Order-preserving refactoring passes. Sorted order and changed retry limits need a revision account. Omitting the actual operator fails; a behavior retired outside the selected finite suite demonstrates that local preservation is limited. + +**Limits:** The model does not require retaining every historical behavior, a particular test procedure, or an added universal notification obligation. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3) + +### `CoreReader.Engineering.ContractChangeAccount` + +[leanified/CoreReader/Engineering/Domain.lean:549](#line-code-leanified-corereader-engineering-domain-lean-549) · definition + +Core dependencies: none. + +```lean +abbrev ContractChangeAccount (old new : ObservableContract) (r : ContractRevision) : Prop := +``` + +### `CoreReader.Engineering.contractCases` + +[leanified/CoreReader/Engineering/Domain.lean:843](#line-code-leanified-corereader-engineering-domain-lean-843) · case + +Core dependencies: none. + +```lean +theorem contractCases : + ContractChangeAccount originalContract refactoredContract normalRevision ∧ + ContractChangeAccount originalContract revisedContract normalRevision ∧ + ¬ ContractChangeAccount originalContract revisedContract { normalRevision with affected := [] } ∧ +``` + + + +## T34 · The contract-preservation theorem + +If all identified in-scope observations are equal, the identified contract is preserved. A changed in-scope observation refutes preservation of that same contract. + +**Premises and representation:** contractPreservation receives a universal in-scope equality. The finite order/retry examples are separate checks and do not supply that universal premise automatically. + +**Proof or check:** The theorem returns the supplied equality as PreservesOn. changedObservationNotPreserved applies it to a differing input. The examples compute order changes, retry at 3, affected parties and a difference at the excluded input [99]. + +**Limits:** A passing finite test suite is not a universal equality proof; preservation always retains its identified scope. + +**State:** accepted (theorem). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3) + +### `CoreReader.Engineering.contractPreservation` + +[leanified/CoreReader/Engineering/Domain.lean:822](#line-code-leanified-corereader-engineering-domain-lean-822) · theorem + +Core dependencies: none. + +```lean +theorem contractPreservation {Input Output : Type} (scope : Input → Prop) + (old new : Input → Output) (observations : ∀ x, scope x → new x = old x) : + PreservesOn scope old new := observations +``` + +### `CoreReader.Engineering.contractDistinctions` + +[leanified/CoreReader/Engineering/Domain.lean:853](#line-code-leanified-corereader-engineering-domain-lean-853) · case + +Core dependencies: none. + +```lean +theorem contractDistinctions : + PreservesFinite orderedUnique orderedRefactor ∧ + ¬ PreservesFinite orderedUnique sortedUnique ∧ + retry originalContract 3 = false ∧ retry revisedContract 3 = true ∧ + ¬ PreservesContractFinite originalContract revisedContract ∧ + affectedParties originalContract revisedContract = ["queue consumer", "queue operator"] ∧ + ¬ ContractChangeAccount originalContract revisedContract + { normalRevision with affected := ["queue consumer"] } ∧ +``` + + + +## T35 · Revision and preserved historical evidence + +Changed forecasts, maintainers, costs or objectives can justify changed judgments. A new record must retain the earlier prediction and its observed failure. + +**Premises and representation:** RevisionAccount compares the revision with independently fixed observedHistory, including software identity, old prediction and actual observed result. revisionFor uses the current context and selected candidate. MaterialGroundsChanged is a disjunction of five recorded differences; it does not prove that each difference alone adequately justifies the new choice. + +**Proof or check:** The same old/new state pair changes forecast, maintenance, maintainers, migration cost and objective capacity together; the theorem lists all five differences. Tampering with both old and recordedOld cannot change the independent history. Separate retention cases use an unsupported alternative or a justified migration-cost departure. + +**Limits:** The recorded history is fixed model evidence; the theorem does not authenticate arbitrary real-world logs or prove every criticism response adequate. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.revision#p2](#source-software-engineering-revision-p2), [software-engineering.revision#p1](#source-software-engineering-revision-p1) + +### `CoreReader.Engineering.RevisionAccount` + +[leanified/CoreReader/Engineering/Domain.lean:922](#line-code-leanified-corereader-engineering-domain-lean-922) · definition + +Core dependencies: none. + +```lean +abbrev RevisionAccount (r : RevisionRecord) : Prop := RevisionAccountAgainst observedHistory r +``` + +### `CoreReader.Engineering.revisionCases` + +[leanified/CoreReader/Engineering/Domain.lean:951](#line-code-leanified-corereader-engineering-domain-lean-951) · case + +Core dependencies: `propext`. + +```lean +theorem revisionCases : + RevisionAccount revisionRecord ∧ + revisionRecord.old.forecast ≠ revisionRecord.current.forecast ∧ + revisionRecord.old.maintenance ≠ revisionRecord.current.maintenance ∧ + revisionRecord.old.maintainers ≠ revisionRecord.current.maintainers ∧ + revisionRecord.old.migrationCost ≠ revisionRecord.current.migrationCost ∧ + revisionRecord.old.objectiveCapacity ≠ revisionRecord.current.objectiveCapacity ∧ + revisionRecord.predictedBatchCount ≠ revisionRecord.actualBatchCount ∧ + RetentionJustified currentContinuing [.other "quantum backend"] ∧ + RetentionJustified (threatened .migration) [.migration] := by decide +``` + + + +## T36 · Revision cannot rewrite failure + +A new judgment cannot make the old failed forecast true. Agreement and local success do not establish universal correctness; justified stability remains possible. + +**Premises and representation:** The old static prediction and changed live batch result remain fixed independently of the revision report. + +**Proof or check:** The 21-item case agrees at size 10 but differs at size 5. Relabeling cannot repair that arithmetic. The stable record retains a valid historical account and criticism-direction coverage while leaving the choice unchanged; the named unsupported alternative satisfies the bounded retention criterion. This case does not prove the design’s actual revisability. + +**Limits:** The result permits bounded retention, not permanent immunity from later grounds or criticism. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.revision#p2](#source-software-engineering-revision-p2), [software-engineering.revision#p1](#source-software-engineering-revision-p1) + +### `CoreReader.Engineering.revisionLimits` + +[leanified/CoreReader/Engineering/Domain.lean:993](#line-code-leanified-corereader-engineering-domain-lean-993) · case + +Core dependencies: `propext`. + +```lean +theorem revisionLimits : + RevisionAccount revisionRecord ∧ + ¬ RevisionAccount { revisionRecord with reportedPredictionSucceeded := true } ∧ +``` + + + +## T37 · The priority remains open to its own assessment + +For the same adopter and applicable context, the priority and actual assessment methods remain under Grounds, whole-theory consistency and reflexive scrutiny. + +**Premises and representation:** The theorem retains full Inherited and DomainSatisfied premises, PriorityConditions and no justified departure. It identifies the actual priority object and connects the evolution value commitment to EvolutionPriority by equality of their meanings in sharedContext. + +**Proof or check:** Eliminate the departure branch, retain reflection, and supply priorityGrounds plus the domain content’s membership in the whole consistent theory. The own forecast and evaluator revision cases retain their actual counterexamples. + +**Limits:** Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. + +**State:** accepted (theorem). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.revision#p2](#source-software-engineering-revision-p2) + +### `CoreReader.Engineering.priorityRemainsReflexive` + +[leanified/CoreReader/Engineering/Integration.lean:467](#line-code-leanified-corereader-engineering-integration-lean-467) · theorem + +Core dependencies: `propext`, `Classical.choice`, `Quot.sound`. + +```lean +theorem priorityRemainsReflexive (ctx : Context) (chosen : Candidate) + (inherited : Inherited ctx chosen) (domain : DomainSatisfied ctx chosen) + (applicable : PriorityConditions ctx) (noDeparture : ¬ JustifiedDeparture ctx .evolvable) : + chosen = .evolvable ∧ + (.priority : ReviewObject) ∈ (selfModel chosen).objects ∧ + reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self + (selfModel chosen).performed ∧ + (∀ principle, valueSpecification (governancePosition principle)) ∧ + Grounds012 (EvolutionPriority ctx) canonicalArticulation + [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) ∧ + ownTheory chosen (ownNormClaim chosen .domain) ∧ + consistencySpecification (engineeringSnapshot .evolvable 0) + (engineeringSnapshot chosen 1) true := by +``` + +### `CoreReader.Engineering.priorityReflexiveCases` + +[leanified/CoreReader/Engineering/Integration.lean:493](#line-code-leanified-corereader-engineering-integration-lean-493) · case + +Core dependencies: `propext`, `Classical.choice`, `Quot.sound`. + +```lean +theorem priorityReflexiveCases : + (.priority : ReviewObject) ∈ (selfModel .evolvable).objects ∧ + objectTest .priority (.evolvable, 10) = true ∧ + (selfModel .evolvable).performed ⟨0, 1⟩ ⟨0, .priority, .revision⟩ + ((selfModel .evolvable).input ⟨0, .priority, .revision⟩) + (.assessed .supportedWithinScope) ∧ + Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧ + objectTest .evolutionMethod (.evolvable, 10) = true ∧ + objectTest .evolutionMethod (.evolvable, 5) = false ∧ + Grounds012 (EvolutionPriority sharedContext) canonicalArticulation + [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) ∧ + Reflection.evaluate ((selfModel .evolvable).input ⟨0, .assessmentRule, .revision⟩) = .counterexample := by +``` + + + +## T38 · One joint witness for all represented duties + +One nonempty continuing context and its evolvable selection satisfy the full represented inherited and domain bundles together, with genuine applicable priority and extra present complexity. + +**Premises and representation:** The witness fixes sharedContext, all original assessment tasks and values, the whole facts/norms theory, successor and agent paths, satisfied requirements, credible design revision and no concrete cost threat. + +**Proof or check:** inheritedCurrent constructs every inherited field for evolvable; currentDomainSatisfied supplies the domain bundle. Explicit values check complexity 3 versus 1 and work 6 versus 17, nonempty own objects and admissibility of that same chosen candidate. + +**Limits:** This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +**State:** accepted (satisfiability). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.charter.overview#p2](#source-organon-charter-overview-p2), [organon.charter.overview#p3](#source-organon-charter-overview-p3), [organon.charter.self-transcendence#p1](#source-organon-charter-self-transcendence-p1), [organon.charter.self-transcendence.orientation#p1](#source-organon-charter-self-transcendence-orientation-p1), [organon.charter.self-transcendence.non-finality#p1](#source-organon-charter-self-transcendence-non-finality-p1), [organon.charter.self-transcendence.limits#p1](#source-organon-charter-self-transcendence-limits-p1), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.charter.consistency#p1](#source-organon-charter-consistency-p1), [organon.charter.consistency.meaning#p1](#source-organon-charter-consistency-meaning-p1), [organon.charter.consistency.meaning#p2](#source-organon-charter-consistency-meaning-p2), [organon.charter.consistency.limits#p1](#source-organon-charter-consistency-limits-p1), [organon.charter.reflexivity#p1](#source-organon-charter-reflexivity-p1), [organon.charter.reflexivity.meaning#p1](#source-organon-charter-reflexivity-meaning-p1), [organon.charter.reflexivity.limits#p1](#source-organon-charter-reflexivity-limits-p1), [organon.grounds#p1](#source-organon-grounds-p1), [organon.grounds.assessment#p1](#source-organon-grounds-assessment-p1), [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3), [organon.grounds.scope#p1](#source-organon-grounds-scope-p1), [organon.grounds.scope#p2](#source-organon-grounds-scope-p2), [organon.grounds.scope#p3](#source-organon-grounds-scope-p3), [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2), [organon.grounds.implementations#p1](#source-organon-grounds-implementations-p1), [organon.grounds.implementations#p2](#source-organon-grounds-implementations-p2), [organon.grounds.implementations.limits#p1](#source-organon-grounds-implementations-limits-p1), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.purpose#p1](#source-software-engineering-purpose-p1), [software-engineering.purpose#p2](#source-software-engineering-purpose-p2), [software-engineering.purpose#p3](#source-software-engineering-purpose-p3), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3), [software-engineering.evolution-meaning#p1](#source-software-engineering-evolution-meaning-p1), [software-engineering.evolution-meaning#p2](#source-software-engineering-evolution-meaning-p2), [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2), [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3), [software-engineering.revision#p1](#source-software-engineering-revision-p1), [software-engineering.revision#p2](#source-software-engineering-revision-p2) + +### `CoreReader.Engineering.jointWitness` + +[leanified/CoreReader/Engineering/Integration.lean:557](#line-code-leanified-corereader-engineering-integration-lean-557) · case + +Core dependencies: `propext`, `Classical.choice`, `Quot.sound`. + +```lean +theorem jointWitness : + ∃ ctx : Context, ∃ chosen : Candidate, + ctx = sharedContext ∧ chosen = .evolvable ∧ + Inherited ctx chosen ∧ DomainSatisfied ctx chosen ∧ + PriorityConditions ctx ∧ ¬ HasThreat ctx .evolvable ∧ + abstractionComplexity .presentSimple < abstractionComplexity chosen ∧ + CanChange ctx.activity chosen .successor .designRevision ∧ + CanChange ctx.activity chosen .agent .designRevision ∧ + ownTheory chosen (ownFactClaim chosen .selected) ∧ + (.commitment .grounds : ReviewObject) ∈ (selfModel chosen).objects ∧ + Admissible (ownTheory chosen) (comparisonContext chosen) chosen := by +``` + + + +## T39 · Inherited duties do not force the added priority + +In that same applicable continuing context, a presentSimple selection satisfies every represented inherited duty but does not adopt the additional evolution priority. + +**Premises and representation:** Both options meet necessary requirements; the evolution advantage, credible design revision, successor/agent paths and complexity tradeoff are real within the model. There is no temporary-lifecycle or cost-departure escape. + +**Proof or check:** inheritedCurrent constructs the whole inherited bundle for presentSimple. Its actually adopted simplicity value has cost/work reasons and criticism limits. Applying the domain rule would require evolvable or a departure; both are excluded, so EvolutionPriority is false. + +**Limits:** The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3) + +### `CoreReader.Engineering.inheritedDoesNotEntailPriority` + +[leanified/CoreReader/Engineering/Integration.lean:586](#line-code-leanified-corereader-engineering-integration-lean-586) · case + +Core dependencies: `propext`, `Classical.choice`, `Quot.sound`. + +```lean +theorem inheritedDoesNotEntailPriority : + ∃ ctx : Context, ∃ chosen : Candidate, + ctx = sharedContext ∧ chosen = .presentSimple ∧ + Inherited ctx chosen ∧ PriorityConditions ctx ∧ + Continuing ctx.activity ∧ ¬ BoundedLifecycle ctx.activity ∧ + ¬ HasThreat ctx .evolvable ∧ ¬ JustifiedDeparture ctx .evolvable ∧ + Meets ctx.required (ctx.profiles .presentSimple) ∧ + Meets ctx.required (ctx.profiles .evolvable) ∧ + credible ctx.evidence .designRevision ∧ + CanChange ctx.activity .evolvable .successor .designRevision ∧ + CanChange ctx.activity .evolvable .agent .designRevision ∧ + changeWork .evolvable .designRevision < changeWork chosen .designRevision ∧ + abstractionComplexity chosen < abstractionComplexity .evolvable ∧ + valueSpecification (selectionPosition chosen) ∧ + (selectionPosition chosen).commitment chosen ∧ + ¬ EvolutionPriority ctx chosen := by +``` + + + +## T40 · What the formal evidence cannot establish + +Checked specifications, conditional proofs and concrete witnesses remain distinct from empirical adequacy, sufficient real-world grounds and philosophical adoption. + +**Premises and representation:** Source fidelity is a separately recorded, bounded judgment. Costs, plans, histories, operational understanding and finite contracts retain their disclosed application interpretations. + +**Proof or check:** The edition binds actual source/code/type/dependency objects, independent initial records and later repairs. Prior failed or incomplete objects are not relabeled as successful historical executions. + +**Limits:** Build success, source tracing, agent agreement and self-application do not prove philosophical correctness. No frozen provable target has been deleted or recast as a boundary to obtain completion. + +**State:** accepted (boundary). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.preamble#p1](#source-organon-preamble-p1), [organon.preamble#p2](#source-organon-preamble-p2), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.grounds#p1](#source-organon-grounds-p1), [organon.grounds.assessment#p1](#source-organon-grounds-assessment-p1), [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3), [organon.grounds.scope#p2](#source-organon-grounds-scope-p2), [organon.grounds.scope#p3](#source-organon-grounds-scope-p3), [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2), [organon.grounds.implementations#p1](#source-organon-grounds-implementations-p1), [organon.grounds.implementations#p2](#source-organon-grounds-implementations-p2), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.purpose#p1](#source-software-engineering-purpose-p1), [software-engineering.purpose#p2](#source-software-engineering-purpose-p2), [software-engineering.purpose#p3](#source-software-engineering-purpose-p3), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3), [software-engineering.evolution-meaning#p1](#source-software-engineering-evolution-meaning-p1), [software-engineering.evolution-meaning#p2](#source-software-engineering-evolution-meaning-p2), [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2), [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3), [software-engineering.revision#p1](#source-software-engineering-revision-p1), [software-engineering.revision#p2](#source-software-engineering-revision-p2) + +This boundary target has no Lean declaration. + + +## Source tracing appendix + + + + +### `organon.preamble#p1` + +```text +This is a statement of Software Engineering Organon’s adopted philosophy. It expresses commitments, not factual assertions about every system or a proof of universal correctness. +``` + +State: **not_applicable**; Lean: not_checked; fidelity: not_applicable. + +Documentary authority, interpretive role or disclosed boundary. No formal proof is assigned. + +Related targets: [T01](#t01), [T40](#t40). + + + + + + +### `organon.preamble#p2` + +```text +The quoted provisions, their meanings, and their conditions of application form the core. The charter and Grounds constrain one another; their grouping establishes neither a deductive hierarchy nor an order of priority. [Rationale](rationale/README.md) supplies arguments and cases without adding obligations to this core. Skills are revisable applications under the repository’s stated objectives and constraints, not part of the philosophical commitments themselves. +``` + +State: **not_applicable**; Lean: not_checked; fidelity: not_applicable. + +Documentary authority, interpretive role or disclosed boundary. No formal proof is assigned. + +Related targets: [T01](#t01), [T40](#t40). + + + + + + +### `organon.charter` + +```text + + +``` + +State: **not_applicable**; Lean: not_checked; fidelity: not_applicable. + +Structural heading without substantive direct-body content; no theorem is assigned. + + + + + + +### `organon.charter.overview#p1` + +```text +**Self-Transcendence · Internal Consistency · Reflexivity** +``` + +State: **not_applicable**; Lean: not_checked; fidelity: not_applicable. + +Documentary authority, interpretive role or disclosed boundary. No formal proof is assigned. + +Related targets: [T01](#t01). + + + + + + +### `organon.charter.overview#p2` + +```text +> A system is intrinsically oriented toward expanding what it can understand and construct. It brings itself and its principles within the scope of generation and assessment, with internal consistency constraining this process. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T02, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T01](#t01), [T02](#t02), [T38](#t38). + + + + + + +### `organon.charter.overview#p3` + +```text +The overview connects three distinct requirements: self-transcendence establishes a generative orientation and refuses to treat existing forms as final, internal consistency constrains judgments held simultaneously, and reflexivity brings the system and its principles within the scope of their own generation and assessment. The provisions below specify the conditions for each. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T02, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T01](#t01), [T02](#t02), [T38](#t38). + + + + + + +### `organon.charter.self-transcendence#p1` + +```text +> A system is intrinsically oriented toward expanding what it can understand and construct. It does not regard any existing form as the endpoint of generation. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T02, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T02](#t02), [T38](#t38). + + + + + + +### `organon.charter.self-transcendence.orientation#p1` + +```text +A commitment to keeping generative possibilities open is distinct from valuing their expansion. A system has an intrinsic orientation when it regards that expansion as worth pursuing. Merely permitting change does not fully express this orientation. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T02, T03, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T02](#t02), [T03](#t03), [T38](#t38). + + + + + + +### `organon.charter.self-transcendence.non-finality#p1` + +```text +Refusing to regard an existing form as an endpoint keeps it open to being surpassed. “Existing form” includes a system’s current organization, methods, and principles, not only its appearance or artifacts. These remain within the scope of possible change; their revisability does not guarantee actual progress. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T02, T03, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T02](#t02), [T03](#t03), [T38](#t38). + + + + + + +### `organon.charter.self-transcendence.limits#p1` + +```text +Whether progress has actually occurred remains a separate judgment. Having the orientation does not guarantee progress. Progress cannot be established merely by an increase in the number of artifacts, levels of abstraction, or terms. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T03, T38. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T03](#t03), [T38](#t38). + + + + + + +### `organon.charter.self-transcendence.limits#p2` + +```text +- “Intrinsic orientation” expresses Organon’s philosophical commitment; it does not assert that all systems in fact develop autonomously. +- Self-transcendence does not imply independence from external experience, knowledge, or collaboration, nor does it guarantee autonomous execution or self-improvement. +- Refusing to regard an existing form as an endpoint does not require every action to produce change. Justified stability can coexist with a generative orientation. +- Whether transcendence expands what can be understood and constructed requires discernible grounds; a system’s own claim of generation does not establish actual achievement. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T02, T03, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T02](#t02), [T03](#t03), [T38](#t38), [T40](#t40). + + + + + + +### `organon.charter.consistency#p1` + +```text +> The principles and judgments a system holds simultaneously, together with their implications, must not yield contradictory judgments on the same question under the same assumptions, meanings of terms, and scope of application. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T04, T05, T38. A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T04](#t04), [T05](#t05), [T38](#t38). + + + + + + +### `organon.charter.consistency.meaning#p1` + +```text +“Held simultaneously” specifies which principles, judgments, and implications must hold together. Revision may withdraw an earlier judgment; old and new principles need not remain compatible forever. When a change has occurred, that change cannot be represented as though it had not occurred. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T04, T05, T38. A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T04](#t04), [T05](#t05), [T38](#t38). + + + + + + +### `organon.charter.consistency.meaning#p2` + +```text +“The same assumptions, meanings of terms, and scope of application” specifies the basis for comparing judgments. Divergent judgments under different conditions do not automatically constitute contradictions. Nor can unacknowledged changes in assumptions, meanings, or scope be used to conceal an existing contradiction. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T04, T05, T06, T38. A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. Consistency is not sufficient empirical or value support; the counterexamples concern the disclosed mathematical representation. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T04](#t04), [T05](#t05), [T06](#t06), [T38](#t38). + + + + + + +### `organon.charter.consistency.limits#p1` + +```text +- Tension between different assessments or values does not directly constitute a contradiction. Revision or qualification is needed when they require incompatible conclusions under the same conditions. +- Internal consistency is not correctness or sufficiency. A set of principles may be internally consistent while relying on false assumptions or neglecting important questions. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T04, T05, T06, T38. A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. Consistency is not sufficient empirical or value support; the counterexamples concern the disclosed mathematical representation. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T04](#t04), [T05](#t05), [T06](#t06), [T38](#t38). + + + + + + +### `organon.charter.reflexivity#p1` + +```text +> A system’s principles of generation and assessment also apply to the system itself and to the formation, application, and revision of those principles. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T07, T38. Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T07](#t07), [T38](#t38). + + + + + + +### `organon.charter.reflexivity.meaning#p1` + +```text +Reflexivity encompasses both the system itself and its principles. Assessment concerns not only whether the system conforms to its principles, but also how those principles are formed, where they apply, and why they may need revision. The formation and revision of principles thus also become objects of generation and assessment. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T07, T38. Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T07](#t07), [T38](#t38). + + + + + + +### `organon.charter.reflexivity.limits#p1` + +```text +- Applying principles equally retains their conditions of application. When the relevant conditions hold, being the system itself is not a basis for exemption. Nor does the requirement of reflexivity establish that every principle can be applied to itself without examining its applicability. +- Self-application does not constitute self-proof. Subjecting a principle to its own assessment does not thereby establish its correctness. +- That a revision is produced by the system itself does not give it sufficient grounds. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T07, T08, T38. Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T07](#t07), [T08](#t08), [T38](#t38). + + + + + + +### `organon.grounds#p1` + +```text +> The grounds of principles and judgments must be articulable and subject to assessment appropriate to the nature of the claim. The strength and scope of a claim must be proportionate to the support provided by its grounds. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T08, T09, T38. This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T08](#t08), [T09](#t09), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.assessment#p1` + +```text +Articulation and assessment have distinct responsibilities. Articulability requires that concepts, assumptions, reasons, and limits can be identified. Assessment requires examining whether those grounds support the corresponding claim. Clearly expressed grounds are not thereby sufficiently established. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T09, T13, T38. This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. These distinctions do not require values, empirical evidence and inference to be reduced to one score. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T09](#t09), [T13](#t13), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.assessment#p2` + +```text +| Type of claim | Responsibility of assessment | What cannot substitute for that responsibility | +| --- | --- | --- | +| Empirical claim | Examine observations, evidence, and performance, together with the conditions, scope, and uncertainty of their support for the claim. | Treating measurability or repeatability itself as proof of relevance, correctness, or value. | +| Inferential claim | Examine whether the conclusion is supported by the stated assumptions and inferential relations. | Treating the absence of conflict between a conclusion and its assumptions as sufficient to establish that the conclusion follows from them. | +| Value commitment | State the position taken, its reasons, limits of application, and consequences, and remain open to relevant criticism. | Presenting a commitment as an empirical fact or a necessary inference, or substituting self-assertion for reasons. | +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T09, T10, T11, T12, T13, T38. This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. Repeatability or measurability alone does not establish relevance, correctness or value; varying unobserved outcomes need not contradict limited support. Failure of support is not failure to assess correctly; consistency with assumptions is weaker than entailment. The application supplies a sufficient value assessment, not a universal requirement to prove every starting assumption or a proof that one value is universally best. These distinctions do not require values, empirical evidence and inference to be reduced to one score. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T09](#t09), [T10](#t10), [T11](#t11), [T12](#t12), [T13](#t13), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.assessment#p3` + +```text +Initial value commitments may be stated explicitly as commitments; they need not prove all their own starting assumptions. The strength and scope of a claim do not require conversion to a common numerical scale. Different types of claims specify their support and limits in accordance with their nature. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T09, T12, T13, T38. This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. The application supplies a sufficient value assessment, not a universal requirement to prove every starting assumption or a proof that one value is universally best. These distinctions do not require values, empirical evidence and inference to be reduced to one score. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T09](#t09), [T12](#t12), [T13](#t13), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.scope#p1` + +```text +Performance is discerned within particular relations, conditions, and scopes of observation. A boundary helps specify what a comparison concerns, but local examples do not automatically support unconditional universal conclusions. A judgment cannot establish that relevant differences do not exist merely because its chosen scope omits them. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T14, T15, T38. A nonempty role string alone is not sufficient interpretation, and an unused method does not become compulsory. Omitting an input from comparison is not evidence that no relevant difference exists there. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T14](#t14), [T15](#t15), [T38](#t38). + + + + + + +### `organon.grounds.scope#p2` + +```text +Measurement can make some differences comparable. Repeated assessment can help examine the stability of corresponding conclusions. Their roles, and the role of any assessment framework, must be explained relative to the claim and its context. Measurement, repeatability, and an assessment framework do not form a universally necessary chain on which all judgments must depend. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T14, T15, T38. A nonempty role string alone is not sufficient interpretation, and an unused method does not become compulsory. Omitting an input from comparison is not evidence that no relevant difference exists there. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T14](#t14), [T15](#t15), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.scope#p3` + +```text +An observation that has not been reproduced may still offer limited support, and random outcomes need not be identical on every occasion. The verifiability of observations, reproducibility of conditions, and stability of conclusions must be distinguished. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T14, T15, T38. A nonempty role string alone is not sufficient interpretation, and an unused method does not become compulsory. Omitting an input from comparison is not evidence that no relevant difference exists there. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T14](#t14), [T15](#t15), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.capabilities#p1` + +```text +Capability claims are subject to Grounds: the capability claimed, its conditions, and the support for it must be identifiable. The core does not prescribe uniform definitions of method mastery, method generation, or capability levels. Applications specify the capabilities they assess and may require understanding, explanation, or performance under relevant variations. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T16, T17, T38. This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. An external assessor can ground the selected output claim without establishing how the assessed system understands its generation process. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T16](#t16), [T17](#t17), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.capabilities#p2` + +```text +Grounds for a capability claim may be supplied by an external assessor. Their articulability does not by itself require the assessed system to understand or explain its internal generation process. Evidence of reliable output must be assessed against the capability actually claimed; it does not automatically establish understanding of that process. Nor can the number of method documents, terms, tools, or artifacts alone establish a capability beyond what that evidence supports. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T16, T17, T38. This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. An external assessor can ground the selected output claim without establishing how the assessed system understands its generation process. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T16](#t16), [T17](#t17), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.implementations#p1` + +```text +> The choice of an implementation must be supported by reasons connected to the objectives and values pursued and to the relevant constraints. Its name, conventional use, or established status alone does not provide sufficient grounds for giving it priority. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T18, T19, T38. These are application reasons, not a universal cost function or a rule that conventional implementations must lose. No result asserts all implementations equivalent, multiple feasible implementations guaranteed, or the choice commitment derivable from chapter placement. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T18](#t18), [T19](#t19), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.implementations#p2` + +```text +This choice provision adds an additional evaluative commitment: name, conventional use, or established status alone is insufficient to establish priority. Grouping it under Grounds does not mean that it follows from the general requirement to assess reasons, or merely from the discernibility of performance. Conventions and existing arrangements may have practical significance, but that significance must be connected to the objectives and values pursued and to the relevant constraints. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T18, T19, T38. These are application reasons, not a universal cost function or a rule that conventional implementations must lose. No result asserts all implementations equivalent, multiple feasible implementations guaranteed, or the choice commitment derivable from chapter placement. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T18](#t18), [T19](#t19), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.implementations.limits#p1` + +```text +- Openness does not make all implementations equivalent, nor does it guarantee multiple feasible implementations for the same objective. +- A method’s explanatory power, limits of application, simplicity, and explicit process requirements may all provide grounded reasons for assessment. They cannot be excluded merely because they concern methods internal to the implementation. +- Identical local performance does not establish overall equivalence. Relations, conditions, and the scope of comparison are constrained by the provisions of Grounds. +- Openness does not reject an implementation merely because it already exists or is conventionally used. Relevant reasons may still give it priority. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T15, T18, T19, T38. Omitting an input from comparison is not evidence that no relevant difference exists there. These are application reasons, not a universal cost function or a rule that conventional implementations must lose. No result asserts all implementations equivalent, multiple feasible implementations guaranteed, or the choice commitment derivable from chapter placement. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T15](#t15), [T18](#t18), [T19](#t19), [T38](#t38). + + + + + + +### `organon.relationships` + +```text + + +``` + +State: **not_applicable**; Lean: not_checked; fidelity: not_applicable. + +Structural heading without substantive direct-body content; no theorem is assigned. + + + + + + +### `organon.relationships.roles#p1` + +```text +The charter states the generative orientation, the consistency constraint, and reflexive application. Grounds specifies support requirements for judgments and includes an additional commitment concerning implementation choices. Both parts belong to the core and constrain one another. Their placement neither makes Grounds a deduction from the charter nor gives the charter priority over it. Each commitment needs its own reasons. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T08, T20, T38, T39. This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. Projection does not derive all duties from one principle. Adoption markers are separate facts; they do not substitute for normative content. The sample-aware criticism is an application criterion, not a universal requirement for observations. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance. + +Related targets: [T01](#t01), [T08](#t08), [T20](#t20), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `organon.relationships.roles#p2` + +```text +Internal Consistency concerns whether simultaneously held judgments can hold together; Grounds concerns whether and how far a claim is supported. A conclusion may fail to conflict with its assumptions without being supported by them. Self-Transcendence specifies a generative orientation and non-finality; neither establishes actual capability. Applications may supply objectives, values, and capability definitions; claims made under those objectives, values, and definitions remain subject to the relevant core provisions. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T03, T06, T11, T16, T20, T38, T39. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. Consistency is not sufficient empirical or value support; the counterexamples concern the disclosed mathematical representation. Failure of support is not failure to assess correctly; consistency with assumptions is weaker than entailment. This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. Projection does not derive all duties from one principle. Adoption markers are separate facts; they do not substitute for normative content. The sample-aware criticism is an application criterion, not a universal requirement for observations. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance. + +Related targets: [T03](#t03), [T06](#t06), [T11](#t11), [T16](#t16), [T20](#t20), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `organon.relationships.roles#p3` + +```text +Self-Transcendence does not substitute for Reflexivity: keeping existing forms open to being surpassed differs from applying relevant principles to the system and to their own formation, application, and revision. Reflexivity extends these requirements to the system and to the formation, application, and revision of its principles. The grounds and limits of the Grounds provisions must themselves be articulable. The system’s own capability claims remain subject to assessment, and this philosophy’s existing form cannot gain priority merely from its established status. Such mutual application provides no self-proof and does not remove conditions of application. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T07, T08, T16, T18, T20, T37, T38, T39. Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. These are application reasons, not a universal cost function or a rule that conventional implementations must lose. Projection does not derive all duties from one principle. Adoption markers are separate facts; they do not substitute for normative content. The sample-aware criticism is an application criterion, not a universal requirement for observations. Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance. + +Related targets: [T07](#t07), [T08](#t08), [T16](#t16), [T18](#t18), [T20](#t20), [T37](#t37), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `organon.relationships.terms#p1` + +```text +| Term | Meaning in this philosophy | +| --- | --- | +| Existing form | The system’s current organization, methods, and principles, not only its appearance or artifacts. | +| Assessment | Examination of reasons, applicability, and observed performance; not limited to executable tests. | +``` + +State: **incomplete**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T02. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. + +Related targets: [T02](#t02), [T21](#t21). + + + + + + +### `extensions#p1` + +```text +This chapter adds a software engineering commitment and specifies its meaning and limits. It does not claim that this commitment follows from the Charter or Grounds. Those provisions remain adopted and constrain its application. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T37, T38, T39. Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance. + +Related targets: [T01](#t01), [T37](#t37), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `software-engineering.purpose#p1` + +```text +Software engineering concerns the construction, operation, understanding, and revision of software within its relevant human and technical conditions. This philosophy guides decisions by people and agents; it does not attribute an intrinsic orientation to every software artifact. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T22, T23, T38. These numerical schedules are finite model data, not project time estimates. Scope alone does not prove every participant can perform every change. The result concerns the represented paths; lack of one documented path is not a universal impossibility theorem about all maintenance. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T22](#t22), [T23](#t23), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.purpose#p2` + +```text +The evolution capability considered here belongs to the continuing engineering activity: maintainers, including successor maintainers and agents, working with software, tools, and available knowledge. Code that its original author can modify is not on that ground alone shown to support that continuing activity. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T22, T23, T38. These numerical schedules are finite model data, not project time estimates. Scope alone does not prove every participant can perform every change. The result concerns the represented paths; lack of one documented path is not a universal impossibility theorem about all maintenance. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T22](#t22), [T23](#t23), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.purpose#p3` + +```text +Apply the following priority according to the software's credible lifecycle and maintenance expectations. A genuinely temporary script, bounded prototype, or retiring system may have little reason to support further evolution. Calling a continuing system temporary does not establish that condition. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T22, T23, T24, T38. These numerical schedules are finite model data, not project time estimates. Scope alone does not prove every participant can perform every change. The result concerns the represented paths; lack of one documented path is not a universal impossibility theorem about all maintenance. This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T22](#t22), [T23](#t23), [T24](#t24), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.evolution-priority#p1` + +```text +> When relevant behavioral, safety, performance, and other necessary requirements are satisfied, give priority to continuing maintainers' ability to make credible future changes, including changes to the design itself, over present abstraction simplicity. Accept additional present abstraction complexity for that purpose, while allowing this preference to yield when the added costs threaten concrete engineering objectives. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T24, T25, T38, T39. This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. The theorem neither proves the value rule from facts nor establishes that every apparently complex design has the relevant advantage. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance. + +Related targets: [T24](#t24), [T25](#t25), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `software-engineering.evolution-priority#p2` + +```text +Credible directions of change have articulable grounds, such as a committed plan, relevant domain knowledge, or an applicable history of change. They need not already have multiple implementations. Their credibility remains open to revision; a conceivable change alone does not establish that it warrants accommodation now. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T24, T25, T26, T27, T38, T39. This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. The theorem neither proves the value rule from facts nor establishes that every apparently complex design has the relevant advantage. The proof checks stipulated evidence contents, not the real-world credibility or predictive calibration of arbitrary plans. No finite list of directions proves all future changes predictable or all omitted possibilities irrelevant. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance. + +Related targets: [T24](#t24), [T25](#t25), [T26](#t26), [T27](#t27), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `software-engineering.evolution-priority#p3` + +```text +This is a default priority, not an obligation to maximize extensibility or retain every possibility. Costs include relevant burdens of understanding, construction, diagnosis, verification, coordination, operation, and eventual migration. A departure from the priority identifies the objective threatened and why the costs matter. No universal numerical exchange rate between these considerations is prescribed. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T24, T25, T26, T27, T28, T38, T39. This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. The theorem neither proves the value rule from facts nor establishes that every apparently complex design has the relevant advantage. The proof checks stipulated evidence contents, not the real-world credibility or predictive calibration of arbitrary plans. No finite list of directions proves all future changes predictable or all omitted possibilities irrelevant. The finite costs are modeled work/budget data. The source does not require every category to apply or provide a universal numerical tradeoff. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance. + +Related targets: [T24](#t24), [T25](#t25), [T26](#t26), [T27](#t27), [T28](#t28), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `software-engineering.evolution-meaning#p1` + +```text +Evolution includes adding capabilities, replacing implementations, deleting mechanisms, withdrawing abstractions, redrawing boundaries, and migrating away from an existing technology or model. Making additions within a fixed scheme does not establish equal ability to revise or leave that scheme. Not every such change can or should be made inexpensive. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T29, T30, T38. The enumerated constructors illustrate source dimensions and allow an other direction; they do not claim every possible evolution is represented or cheap. These counterexamples reject unjustified cross-dimension inference without adding a duty that every change be inexpensive. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T29](#t29), [T30](#t30), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.evolution-meaning#p2` + +```text +An evolution claim identifies the relevant changes and the maintainers' conditions. Independent changes, coordinated changes, preservation of existing obligations, and deliberate revision of those obligations can require different structures. A design's advantage on one dimension does not establish an advantage on every dimension. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T29, T30, T38. The enumerated constructors illustrate source dimensions and allow an other direction; they do not claim every possible evolution is represented or cheap. These counterexamples reject unjustified cross-dimension inference without adding a duty that every change be inexpensive. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T29](#t29), [T30](#t30), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.structural-judgment#p1` + +```text +Apply the preceding commitment to engineering consequences as a whole, including the relations among components, their observable contracts, and the work needed to understand and verify a change. An interface's shape, the number of modules or extension points, or the use of a named principle is not sufficient evidence of the claimed capability. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T31, T32, T37, T38. These are relevant finite inquiries, not a mandatory universal checklist or a real-world estimate of all boundary costs. The equal-work case preserves step units through an actual path transformation; these units are a disclosed model measure, not observed engineering effort. Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T31](#t31), [T32](#t32), [T37](#t37), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.structural-judgment#p2` + +```text +The relevant comparison may examine how a change propagates, which knowledge and obligations cross a boundary, which assumptions become fixed, and what a later withdrawal would require. A proposed boundary needs support for the changes it is meant to accommodate; introducing it does not by itself show that those changes became easier. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T31, T32, T38. These are relevant finite inquiries, not a mandatory universal checklist or a real-world estimate of all boundary costs. The equal-work case preserves step units through an actual path transformation; these units are a disclosed model measure, not observed engineering effort. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T31](#t31), [T32](#t32), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.structural-judgment#p3` + +```text +Distinguish a transformation that preserves an identified observable contract from one that deliberately revises that contract. The latter needs a corresponding account of changed obligations and affected parties. This distinction does not require preserving every historical behavior or using a particular testing or migration procedure. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T33, T34, T38. The model does not require retaining every historical behavior, a particular test procedure, or an added universal notification obligation. A passing finite test suite is not a universal equality proof; preservation always retains its identified scope. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T33](#t33), [T34](#t34), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.revision#p1` + +```text +Changed evidence about likely changes, maintenance conditions, costs, or objectives may justify revising a design or this priority's application. A revised judgment acknowledges material changes in its grounds; it does not make a failed prediction successful retrospectively. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T35, T36, T38. The recorded history is fixed model evidence; the theorem does not authenticate arbitrary real-world logs or prove every criticism response adequate. The result permits bounded retention, not permanent immunity from later grounds or criticism. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T35](#t35), [T36](#t36), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.revision#p2` + +```text +Retaining a design can be justified when the relevant alternatives have no supported contribution or impose costs that defeat the objective. Reflexivity also keeps this engineering commitment and the methods used to assess evolution within the scope of criticism and revision. Continued change, agreement, or successful examples do not establish its universal correctness. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T35, T36, T37, T38. The recorded history is fixed model evidence; the theorem does not authenticate arbitrary real-world logs or prove every criticism response adequate. The result permits bounded retention, not permanent immunity from later grounds or criticism. Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T35](#t35), [T36](#t36), [T37](#t37), [T38](#t38), [T40](#t40). + + + +## Complete code and line explanations + +Each file retains its exact checked contents. These line explanations are informed translations of the revised object; the initial blind account and rejected earlier judgments are retained separately. + + +### `leanified/CoreReader/Adopted.lean` + + +```lean +import CoreReader.Integration + +namespace CoreReader.Adopted +open CoreReader.Logic CoreReader.Agency CoreReader.Evidence CoreReader.Choice + +/- These are three explicit mathematical assessment tasks, not an exhaustive or +exclusive taxonomy of claim natures. A task fixes the original claim and support +context before any candidate assessment is proposed. Its identity must be retained +when comparing alternative assessments; taskOfFacet declares a new task and does +not authorize replacing a previously identified task. -/ +inductive AssessmentTask (W : Type) where + | empirical (records : List (Record W)) (scope claim uncertainty : Claim W) + | inferential (assumptions : Theory W) (claim : Claim W) + | value (position : ValuePosition W) + +def taskOfFacet {W : Type} : Facet W → AssessmentTask W + | .empirical records scope claim uncertainty => .empirical records scope claim uncertainty + | .inferential assumptions claim => .inferential assumptions claim + | .value position => .value position + +/- This is a content-based sufficient adapter for the declared task, not a +philosophical rule requiring one unique assessment form. The empirical task may +also be assessed inferentially from exactly its observation/scope premises; its +original uncertainty obligation is still checked. In particular, adding the +conclusion as a new premise cannot replace the original empirical grounds. +The finite adapter need not accept every semantically equivalent presentation. -/ +def NatureAppropriate {W : Type} : AssessmentTask W → Facet W → Prop + | .empirical records scope claim uncertainty, .empirical actualRecords actualScope conclusion actualUncertainty => + actualRecords = records ∧ actualScope = scope ∧ conclusion = claim ∧ actualUncertainty = uncertainty + | .empirical records scope claim uncertainty, .inferential assumptions conclusion => + assumptions = singleton (fun w => Compatible records w ∧ scope w) ∧ + conclusion = claim ∧ Supports records uncertainty + | .inferential assumptions claim, .inferential actualAssumptions conclusion => + actualAssumptions = assumptions ∧ conclusion = claim + | .value position, .value actualPosition => actualPosition = position + | _, _ => False + +theorem taskOfFacetAppropriate {W : Type} (f : Facet W) : NatureAppropriate (taskOfFacet f) f := by + cases f with + | empirical _ _ _ _ => exact ⟨rfl, rfl, rfl, rfl⟩ + | inferential _ _ => exact ⟨rfl, rfl⟩ + | value _ => rfl + +/- Core 0.1.2 requires appropriateness to the original claim task. Supplied facets +are an explicit assessment scope, without importing Core 0.1.3's all-applicable +coverage requirement. No claim-kind label or freely assigned success flag proves +appropriateness: NatureAppropriate compares the actual task and facet contents. -/ +/-- organon-map CoreReader.Adopted.Grounds012 +organon.grounds#p1 sha256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6 +organon.grounds.assessment#p1 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +-/ +def Grounds012 {W : Type} (claim : Claim W) + (articulations : Facet W → Articulation W) (facets : List (Facet W)) + (task : AssessmentTask W) : Prop := + facets ≠ [] ∧ ∀ facet ∈ facets, + facet.claim = claim ∧ Articulated (articulations facet) ∧ + FacetArticulated (articulations facet) facet ∧ FacetDischarged facet ∧ + NatureAppropriate task facet + +/- This helper proves the newly declared taskOfFacet f only. It supplies no +appropriateness proof for another, previously fixed task with the same claim. -/ +theorem grounds012Singleton {W : Type} (f : Facet W) (h : FacetDischarged f) : + Grounds012 f.claim canonicalArticulation [f] (taskOfFacet f) := by + refine ⟨by simp, ?_⟩ + intro facet hf + cases List.mem_singleton.mp hf + exact ⟨rfl, canonicalArticulated f h, canonicalFacetArticulated f, h, taskOfFacetAppropriate f⟩ + +/-- organon-map CoreReader.Adopted.generationSpecification +organon.charter.overview#p2 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c +organon.charter.overview#p3 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c +organon.charter.self-transcendence#p1 sha256 f4ca590e2ae15e3882f70c7b2bc46a8911c97cee547c8b137b5493fbf862c8c0 +organon.charter.self-transcendence.orientation#p1 sha256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf +organon.charter.self-transcendence.non-finality#p1 sha256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8 +organon.charter.self-transcendence.limits#p2 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d +organon.relationships.terms#p1 sha256 61cb7ce4f2920f1aa6771502b87a66536ae0504acccfebd9dd23bcc62756eddf +-/ +def generationSpecification (policy : Policy) : Prop := Generative policy + +/- All consequences use the whole currently held set. Historical reporting is +separate and does not require simultaneous compatibility with withdrawn claims. -/ +/-- organon-map CoreReader.Adopted.consistencySpecification +organon.charter.consistency#p1 sha256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42 +organon.charter.consistency.meaning#p1 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75 +-/ +def consistencySpecification {W Q : Type} (before after : Snapshot W Q) + (reported : Bool) : Prop := + Consistent after.held after.context ∧ TruthfulReport before after reported + +/- A method's actual input and interpretation are parameters, permitting domain +methods as well as the small arithmetic adapter. Key coherence prevents records +for another method from silently satisfying the duty. -/ +structure ReflexiveRule (T I O : Type) where + key : PrincipleKey + activity : Activity + applicable : T → Prop + input : T → I + meaning : I → O → Prop + +/-- organon-map CoreReader.Adopted.reflexivitySpecification +organon.charter.reflexivity#p1 sha256 13293b45c2fa89068c68ae7ef3c5df38f0efadb3ef3873d78a5ba67d9691a757 +organon.charter.reflexivity.meaning#p1 sha256 8a2caede01a43d8b6c60b54c78ac089c51868e9956f316948077ccee2e45c9cc +organon.charter.reflexivity.limits#p1 sha256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +def reflexivitySpecification {T I O : Type} (rules : List (ReflexiveRule T I O)) + (isSelf : T → Prop) (performed : PrincipleKey → T → I → O → Prop) : Prop := + (∀ p ∈ rules, ∀ q ∈ rules, p.key = q.key → p = q) ∧ + ∀ rule ∈ rules, ∀ target, isSelf target → rule.applicable target → + ∃ outcome, performed rule.key target (rule.input target) outcome ∧ + rule.meaning (rule.input target) outcome + +def legacyRule (p : Principle) : ReflexiveRule Subject Inquiry WorkOutcome := + ⟨p.key, p.activity, p.applicable, p.inquiry, + fun inquiry outcome => p.meaning inquiry (p.reasons inquiry.target) (p.limits inquiry.target) outcome⟩ + +def legacyPerformed (rules : List Principle) (records : List WorkRecord) + (key : PrincipleKey) (target : Subject) (input : Inquiry) (outcome : WorkOutcome) : Prop := + ∃ p ∈ rules, ∃ record ∈ records, + p.key = key ∧ ValidApplication rules p target record ∧ + record.inquiry = input ∧ record.outcome = outcome + +theorem legacyReflexivity (owner : Nat) (rules : List Principle) (records : List WorkRecord) + (h : Reflexive owner rules records) : + reflexivitySpecification (rules.map legacyRule) (fun s => s.owner = owner) + (legacyPerformed rules records) := by + constructor + · intro p hp q hq he + obtain ⟨a, ha, rfl⟩ := List.mem_map.mp hp + obtain ⟨b, hb, rfl⟩ := List.mem_map.mp hq + exact congrArg legacyRule (h.1 a ha b hb he) + · intro rule hr target ht happ + obtain ⟨p, hp, rfl⟩ := List.mem_map.mp hr + obtain ⟨record, hm, hv⟩ := h.2 p hp target ht happ + refine ⟨record.outcome, ⟨p, hp, record, hm, rfl, hv, hv.inquiryIdentity, rfl⟩, ?_⟩ + change p.meaning (p.inquiry target) (p.reasons (p.inquiry target).target) + (p.limits (p.inquiry target).target) record.outcome + have ti : (p.inquiry target).target = target := hv.inquiryIdentity ▸ hv.inquiryTarget + rw [ti] + rw [← hv.inquiryIdentity, ← hv.reasonsIdentity, ← hv.limitsIdentity] + exact hv.followsMeaning + +/- These are fulfillment interfaces for the named mathematical adapters, not +universal empirical adequacy claims or definitions of all possible claim kinds. -/ +/-- organon-map CoreReader.Adopted.empiricalSpecification +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +-/ +def empiricalSpecification {W : Type} (records : List (Record W)) + (scope claim uncertainty : Claim W) : Prop := + Grounds012 claim canonicalArticulation [.empirical records scope claim uncertainty] + (.empirical records scope claim uncertainty) + +/-- organon-map CoreReader.Adopted.inferentialSpecification +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +def inferentialSpecification {W : Type} (assumptions : Theory W) (claim : Claim W) : Prop := + Grounds012 claim canonicalArticulation [.inferential assumptions claim] (.inferential assumptions claim) + +/-- organon-map CoreReader.Adopted.valueSpecification +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +-/ +def valueSpecification {W : Type} (position : ValuePosition W) : Prop := + Grounds012 position.commitment canonicalArticulation [.value position] (.value position) + +/- Scope and roles are explicitly identified relative to a claim. An actually +used method needs an explanation; unused methods are not required. The input +relation can encode contextual relevance without a universal numeric scale. -/ +inductive AssessmentMethod | measurement | repetition | framework + deriving DecidableEq +structure ScopeAccount (W : Type) where + claim : Claim W + conditions : Claim W + observationScope : Claim W + relevant : W → W → Prop + compared : W → W → Prop + used : AssessmentMethod → Prop + role : AssessmentMethod → String + explains : AssessmentMethod → String → Claim W → Claim W → Prop + +/-- organon-map CoreReader.Adopted.scopeSpecification +organon.grounds.scope#p1 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.scope#p2 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.scope#p3 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +-/ +def scopeSpecification {W : Type} (account : ScopeAccount W) : Prop := + (∀ a b, account.compared a b → account.conditions a ∧ account.conditions b ∧ + account.observationScope a ∧ account.observationScope b ∧ account.relevant a b) ∧ + ∀ method, account.used method → account.role method ≠ "" ∧ + account.explains method (account.role method) account.claim account.conditions + +/- A capability is selected by the application as an exact object-scoped +contract; whether explanation is part of it remains an application choice. -/ +/-- organon-map CoreReader.Adopted.capabilitySpecification +organon.grounds.capabilities#p1 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0 +organon.grounds.capabilities#p2 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0 +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +def capabilitySpecification (assessed : Process) (contract : Claim Process) : Prop := + Grounds012 contract canonicalArticulation [processContractFacet assessed contract] + (.inferential (processScope assessed) contract) + +/-- organon-map CoreReader.Adopted.choiceSpecification +organon.grounds.implementations#p1 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c +organon.grounds.implementations#p2 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c +organon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870 +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +def choiceSpecification (requirements : Requirements) (implementation : Implementation) + (reasons : List Reason) : Prop := JustifiedChoice requirements implementation reasons + +/- A collaborator supplies the successor operation. Removing that resource +leaves the initial state; progress is tested on actual added operation content. -/ +def collaborativeRevision (resources : ExternalResources) : State := + if resources.collaborator.isSome then extendedState else baseState + +theorem collaborativeProgress : + generationSpecification openPolicy ∧ + Expanded baseState (collaborativeRevision availableResources) ∧ + ¬ Expanded baseState (collaborativeRevision { availableResources with collaborator := none }) ∧ + assistedExecution ⟨none, none, none⟩ = none := by + refine ⟨⟨Or.inl rfl, fun _ _ => trivial⟩, ?_, ?_, rfl⟩ + · exact Or.inr ⟨.successor, by simp [collaborativeRevision, availableResources, extendedState], + by simp [baseState]⟩ + · simp [collaborativeRevision, Expanded, baseState] + +/- A truth-preserving current slice need not retain an earlier incompatible +slice. Context changes and presentation order have separate semantics. -/ +/-- organon-map CoreReader.Adopted.consistencyConsequences +organon.charter.consistency#p1 sha256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42 +organon.charter.consistency.meaning#p1 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75 +-/ +theorem consistencyConsequences {W Q : Type} (t : Theory W) (c : Context W Q) (q : Q) + (positive : Consequence t c q true) (negative : Consequence t c q false) : + ¬ Consistent t c := conflictRequiresChange t c q positive negative + +def broadBoolContext : Context Bool Unit := ⟨emptyTheory, onQuestion, fun _ => True⟩ + +theorem sliceConsistency : + (∀ time, Consistent (revisionSlice time) broadBoolContext) ∧ + ¬ Consistent (union (revisionSlice 0) (revisionSlice 1)) broadBoolContext := by + constructor + · intro time + apply consequenceConsistency + exact ⟨time == 0, (modelsSingleton _ _).2 rfl, (by intro p hp; cases hp), trivial⟩ + · apply conflictRequiresChange _ _ () + · intro w h + change w = true + exact (modelsSingleton (fun w : Bool => w = true) w).1 ((modelsUnion _ _ _).1 h.1).1 + · intro w h ht + have hn := (modelsSingleton _ _).1 ((modelsUnion _ _ _).1 h.1).2 + cases ht.symm.trans hn + +theorem explicitlyConsistentLimits : + Consistent (singleton (fun w : Bool => w = true)) broadBoolContext ∧ + ¬ Models (singleton (fun w : Bool => w = true)) false ∧ + Consistent (emptyTheory : Theory Bool) broadBoolContext ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true) := by + refine ⟨?_, consistentFalse.2, ?_, consistentIncomplete.2.1⟩ + · exact consequenceConsistency _ _ ⟨true, (modelsSingleton _ _).2 rfl, + (by intro p hp; cases hp), trivial⟩ + · exact consequenceConsistency _ _ ⟨true, (by intro p hp; cases hp), + (by intro p hp; cases hp), trivial⟩ + +/- One observed input supports the local claim. The identical records cannot +support all inputs, nor the stronger claim that both Boolean outputs are true. -/ +def localFacet012 : Facet (Nat → Bool) := + .empirical [zeroRecord] (fun _ => True) (fun f => f 0 = true) (fun _ => True) +def globalFacet012 : Facet (Nat → Bool) := + .empirical [zeroRecord] (fun _ => True) allTrue (fun _ => True) +def strongFacet012 : Facet (Nat → Bool) := + .empirical [zeroRecord] (fun _ => True) (fun f => f 0 = true ∧ f 1 = true) (fun _ => True) + +theorem localFacetChecked012 : FacetDischarged localFacet012 := + ⟨⟨localGenerator 0, (zeroCompatible _).2 rfl, trivial⟩, + (fun f hf _ => (zeroCompatible f).1 hf), fun _ _ => trivial⟩ + +theorem scopeStrength012 : + Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧ + Articulated (canonicalArticulation globalFacet012) ∧ + ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧ + ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012) := by + refine ⟨grounds012Singleton _ localFacetChecked012, ⟨by simp [canonicalArticulation, globalFacet012], + by simp [canonicalArticulation, globalFacet012]⟩, ?_, ?_⟩ + · intro h + have checked := (h.2 globalFacet012 (by simp)).2.2.2.1 + have bad := checked.2.1 (localGenerator 0) ((zeroCompatible _).2 rfl) trivial 1 + cases bad + · intro h + have checked := (h.2 strongFacet012 (by simp)).2.2.2.1 + have bad := (checked.2.1 (localGenerator 0) ((zeroCompatible _).2 rfl) trivial).2 + cases bad + +/- A bounded outcome statement can leave another observable entirely unknown. +This represents uncertainty by a range of compatible worlds, not a probability. -/ +def uncertainFacet012 : Facet (Bool × Bool) := + .empirical [temperatureRecord, temperatureRecord] (fun _ => True) + (fun w => w.1 = true) (fun w => w.2 = true ∨ w.2 = false) + +theorem uncertainSupported012 : + empiricalSpecification [temperatureRecord, temperatureRecord] (fun _ => True) + (fun w => w.1 = true) (fun w => w.2 = true ∨ w.2 = false) ∧ + Compatible [temperatureRecord, temperatureRecord] (true,true) ∧ + Compatible [temperatureRecord, temperatureRecord] (true,false) := by + refine ⟨grounds012Singleton uncertainFacet012 ?_, temperatureCompatible true, temperatureCompatible false⟩ + refine ⟨⟨(true,false), temperatureCompatible false, trivial⟩, ?_, ?_⟩ + · intro w hw _; exact hw temperatureRecord (by simp) + · intro w _; cases w.2 <;> simp + +/- Correctly completed negative examination is distinct from a supported +conclusion. The countervaluation satisfies the same premises. -/ +def InferenceExamined {W : Type} (premises : Theory W) (conclusion : Claim W) + (accepted : Bool) : Prop := accepted = true ↔ Entails premises conclusion + +theorem inferenceChecked012 : + inferentialSpecification (singleton (fun n : Nat => n = 2)) (fun n => n + 1 = 3) ∧ + InferenceExamined (emptyTheory : Theory Bool) (fun w => w = true) false ∧ + Models (emptyTheory : Theory Bool) false ∧ ¬ ((fun w : Bool => w = true) false) := by + refine ⟨grounds012Singleton arithmeticFacet noUniversalChain.1, ?_, (by intro p hp; cases hp), by decide⟩ + constructor + · intro h; cases h + · intro h; exact False.elim (consistentIncomplete.2.1 h) + +/- Closing a response to an actually relevant criticism fails the value +procedure even when its budget/benefit reasons and joint adoption are unchanged. -/ +def closedPosition012 : ValuePosition Bool := { switchPosition with response := fun _ => none } + +theorem closedCriticism012 : ¬ ValueProcedure closedPosition012 := by + intro h + obtain ⟨answer, ha, _⟩ := h.2.2.2 false trivial rfl + cases ha + +theorem valueFulfilled012 : valueSpecification switchPosition := + grounds012Singleton _ switchValueProcedure + +/- Qualitative entailment orders claims by implication, without conversion of +value and empirical/inferential reasons to a common numeric scale. -/ +def ClaimNoStronger {W : Type} (weaker stronger : Claim W) : Prop := ∀ w, stronger w → weaker w + +theorem qualitativeProportionality012 : + ClaimNoStronger (fun f : Nat → Bool => f 0 = true) allTrue ∧ + ¬ ClaimNoStronger allTrue (fun f : Nat → Bool => f 0 = true) ∧ + valueSpecification switchPosition := by + refine ⟨fun _ h => h 0, ?_, valueFulfilled012⟩ + intro h + have bad := h (localGenerator 0) rfl 1 + cases bad + +def scopeRole012 : AssessmentMethod → String + | .measurement => "identify the output at the observed input zero" + | .repetition => "check the same local conclusion against repeated input-zero observations" + | .framework => "compare only the declared input; keep broader claims separate" + +def scopeRoleContent012 : AssessmentMethod → Prop + | .measurement => Supports [zeroRecord] (fun f => f 0 = true) + | .repetition => Supports [zeroRecord, zeroRecord] (fun f => f 0 = true) + | .framework => ¬ Supports [zeroRecord] allTrue + +def localScopeAccount012 : ScopeAccount Nat where + claim n := (localGenerator 0) n = true + conditions _ := True + observationScope n := n = 0 + relevant a b := a = b + compared a b := a = 0 ∧ b = 0 + used _ := True + role := scopeRole012 + explains method text claim conditions := + text = scopeRole012 method ∧ claim = (fun n => localGenerator 0 n = true) ∧ + conditions = (fun _ => True) ∧ scopeRoleContent012 method + +theorem scopeFulfilled012 : scopeSpecification localScopeAccount012 := by + constructor + · intro a b h + exact ⟨trivial, trivial, h.1, h.2, h.1.trans h.2.symm⟩ + · intro method _ + refine ⟨?_, rfl, rfl, rfl, ?_⟩ + · cases method <;> decide + · cases method with + | measurement => exact singleObservation.2.2.1 + | repetition => intro f hf; exact hf zeroRecord (by simp) + | framework => exact singleObservation.2.2.2 + +theorem capabilityFulfilled012 : + capabilitySpecification outputOnlyProcess OutputContract ∧ + capabilitySpecification explainedProcess FullProcessContract ∧ + (∃ certificate : ExternalCertificate outputOnlyProcess, + certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧ + ¬ ExplanationContract outputOnlyProcess := by + refine ⟨grounds012Singleton _ (processContractDischarged _ _ outputCorrectByEvaluation), + grounds012Singleton _ (processContractDischarged _ _ ?_), + ⟨externalOutputCertificate, externalOutputCertificate.distinctParticipants, + externalOutputCertificate.outputCorrect⟩, outputOnlyNoExplanation⟩ + exact ⟨fun _ => rfl, .doubleInput, rfl, fun _ => rfl⟩ + +/- This application asks the assessed object to predict a multiplier mechanism +at changed inputs and multiplier values. This is one operational understanding +criterion selected by an application, not a definition of psychological understanding. +The original output and explanation alone do not answer the additional questions. -/ +structure MechanismApplication012 where + process : Process + answer : Nat → Nat → Nat + +def mechanism012 (multiplier input : Nat) : Nat := multiplier * input + +def UnderstandingApplication012 (assessed : MechanismApplication012) : Prop := + FullProcessContract assessed.process ∧ + (∀ input, assessed.process.output input = mechanism012 2 input) ∧ + ∀ multiplier input, assessed.answer multiplier input = mechanism012 multiplier input + +def explainedWithoutVariation012 : MechanismApplication012 := + ⟨explainedProcess, fun _ input => input + input⟩ + +def mechanismResponder012 : MechanismApplication012 := + ⟨explainedProcess, mechanism012⟩ + +/- The assessment task is fixed by this very application object and the stronger +contract. Identity is a scope premise; the positive case still proves the contract. -/ +def understandingScope012 (assessed : MechanismApplication012) : Theory MechanismApplication012 := + singleton (fun candidate => candidate = assessed) + +def understandingTask012 (assessed : MechanismApplication012) : AssessmentTask MechanismApplication012 := + .inferential (understandingScope012 assessed) UnderstandingApplication012 + +def understandingFacet012 (assessed : MechanismApplication012) : Facet MechanismApplication012 := + .inferential (understandingScope012 assessed) UnderstandingApplication012 + +theorem mechanismResponderUnderstands012 : UnderstandingApplication012 mechanismResponder012 := by + refine ⟨⟨(fun _ => rfl), .doubleInput, rfl, (fun _ => rfl)⟩, ?_, fun _ _ => rfl⟩ + intro input + simp [mechanismResponder012, explainedProcess, mechanism012, Nat.two_mul] + +theorem explainedWithoutVariationFails012 : + ¬ UnderstandingApplication012 explainedWithoutVariation012 := by + intro h + have wrong := h.2.2 3 1 + change 2 = 3 at wrong + cases wrong + +theorem understandingApplicationCases012 : + explainedWithoutVariation012.process = mechanismResponder012.process ∧ + FullProcessContract explainedWithoutVariation012.process ∧ + ¬ UnderstandingApplication012 explainedWithoutVariation012 ∧ + UnderstandingApplication012 mechanismResponder012 ∧ + Grounds012 UnderstandingApplication012 canonicalArticulation + [understandingFacet012 mechanismResponder012] (understandingTask012 mechanismResponder012) ∧ + ¬ Grounds012 UnderstandingApplication012 canonicalArticulation + [understandingFacet012 explainedWithoutVariation012] (understandingTask012 explainedWithoutVariation012) := by + refine ⟨rfl, ⟨(fun _ => rfl), .doubleInput, rfl, (fun _ => rfl)⟩, + explainedWithoutVariationFails012, mechanismResponderUnderstands012, ?_, ?_⟩ + · apply grounds012Singleton + refine ⟨⟨mechanismResponder012, (modelsSingleton _ _).2 rfl⟩, ?_⟩ + intro candidate hc + have same := (modelsSingleton _ _).1 hc + subst candidate + exact mechanismResponderUnderstands012 + · intro h + have discharged := (h.2 (understandingFacet012 explainedWithoutVariation012) (by simp)).2.2.2.1 + exact explainedWithoutVariationFails012 + (discharged.2 explainedWithoutVariation012 ((modelsSingleton _ _).2 rfl)) + +/- The same exact application contract receives Grounds when its owner asserts +it; external certificates change who supplies reasons, not the asserted object. -/ +def OwnCapability012 (owner claimant : Nat) (process : Process) (contract : Claim Process) : Prop := + owner = claimant ∧ capabilitySpecification process contract + +theorem ownCapability012 : OwnCapability012 7 7 outputOnlyProcess OutputContract := + ⟨rfl, capabilityFulfilled012.1⟩ + +/- A complete represented Charter includes generation, whole-set consistency, +truthful revision reporting and applicable contentful self-work on the same +system. The world type is the finite Candidate × Mode type. -/ +def CompleteCharter012 (system : CoreReader.Integration.System) + (world : CoreReader.Integration.World) : Prop := + generationSpecification (system.policy world) ∧ + consistencySpecification + ⟨CoreReader.Integration.systemHeld system, CoreReader.Integration.systemContext system, 0⟩ + ⟨CoreReader.Integration.systemHeld system, CoreReader.Integration.systemContext system, 0⟩ false ∧ + reflexivitySpecification ((system.rules world).map legacyRule) (fun s => s.owner = system.owner) + (legacyPerformed (system.rules world) (system.work world)) ∧ + (system.policy world).current system.method.form ∧ + (system.policy world).current system.principleForm + +theorem completeCharter012 : CompleteCharter012 CoreReader.Integration.actualSystem CoreReader.Integration.actual := by + refine ⟨CoreReader.Integration.charterChecked.1, + ⟨CoreReader.Integration.jointConsistent, ?_⟩, + legacyReflexivity 0 _ _ (completeOwnWork_reflexive 0), rfl, rfl⟩ + rintro (h | h) + · exact False.elim (h ⟨fun _ => Iff.rfl, fun _ => Iff.rfl, fun _ _ => Iff.rfl, fun _ => Iff.rfl⟩) + · exact False.elim (h rfl) + +theorem charterWithoutGrounds012 : + CompleteCharter012 CoreReader.Integration.actualSystem CoreReader.Integration.actual ∧ + Admissible CoreReader.Integration.held CoreReader.Integration.context CoreReader.Integration.actual ∧ + Compatible [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.actual ∧ + Articulated (canonicalArticulation CoreReader.Integration.unsupportedCapabilityFacet) ∧ + ¬ Supports [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.capability ∧ + ¬ Grounds012 CoreReader.Integration.capability canonicalArticulation + [CoreReader.Integration.unsupportedCapabilityFacet] + (taskOfFacet CoreReader.Integration.unsupportedCapabilityFacet) := by + refine ⟨completeCharter012, CoreReader.Integration.actualAdmissible, + (by intro r hr; cases List.mem_singleton.mp hr; rfl), + ⟨by simp [canonicalArticulation, CoreReader.Integration.unsupportedCapabilityFacet], + by simp [canonicalArticulation, CoreReader.Integration.unsupportedCapabilityFacet]⟩, + CoreReader.Integration.costDoesNotSupportOutput, ?_⟩ + intro h + have checked := (h.2 CoreReader.Integration.unsupportedCapabilityFacet (by simp)).2.2.2.1 + exact CoreReader.Integration.costDoesNotSupportOutput (fun w hw => checked.2.1 w hw trivial) + +/- Permission to assert is evaluated on the same claim, articulation and facets. +The countercase derives inadequacy from the actual unobserved output. -/ +def groundsPermission012 {W : Type} (enabled : Bool) (claim : Claim W) + (a : Facet W → Articulation W) (facets : List (Facet W)) (task : AssessmentTask W) : Prop := + if enabled then Grounds012 claim a facets task else True + +def GroundsProvision012 (enabled : Bool) : Prop := + ∀ (claim : Claim (Nat → Bool)) a facets task, + groundsPermission012 enabled claim a facets task → Grounds012 claim a facets task + +theorem groundsProvision012Meaning (enabled : Bool) : GroundsProvision012 enabled ↔ enabled = true := by + cases enabled with + | true => exact ⟨fun _ => rfl, fun _ _ _ _ _ h => h⟩ + | false => + constructor + · intro h + exact False.elim (scopeStrength012.2.2.1 (h globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) trivial)) + · intro h; cases h + +/- The value rationale concerns this fixed empirical assertion task. The +same task, observed grounds and concrete counterworld are retained when the +permission policy is enabled or disabled. -/ +def groundsExperimentTask012 : AssessmentTask (Nat → Bool) := + .empirical [zeroRecord] (fun _ => True) allTrue (fun _ => True) + +noncomputable def groundsExperiment012 (enabled : Bool) : Bool := + @decide (groundsPermission012 enabled allTrue canonicalArticulation [globalFacet012] + groundsExperimentTask012) (Classical.propDecidable _) + +noncomputable def groundsPosition012 : ValuePosition Bool where + Position := Bool + Outcome := Bool + adopted := true + selected := id + outcome _ enabled := groundsExperiment012 enabled + objective accepted := accepted = false + constraints _ enabled := GroundsProvision012 enabled + starting := singleton (fun enabled => enabled = true) + reasons := [fun _ _ => Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0)] + limits _ := True + relevantCriticism _ := ¬ Supports [zeroRecord] allTrue + response _ := some "retain local support and reject the unsupported universal conclusion" + +theorem groundsPosition012Checked : ValueProcedure groundsPosition012 := by + refine ⟨by simp [groundsPosition012], ?_, ?_, ?_⟩ + · refine ⟨true, (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩ + intro reason hr + cases List.mem_singleton.mp hr + refine ⟨(zeroCompatible _).2 rfl, ?_⟩ + intro h; have bad := h 1; cases bad + · intro w _ _ reasons + have counterworld := reasons _ (List.mem_singleton.mpr rfl) + change Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0) at counterworld + have unsupported : ¬ Grounds012 allTrue canonicalArticulation [globalFacet012] groundsExperimentTask012 := by + intro h + have discharged := (h.2 globalFacet012 (by simp)).2.2.2.1 + exact counterworld.2 (discharged.2.1 (localGenerator 0) counterworld.1 trivial) + refine ⟨?_, (groundsProvision012Meaning true).2 rfl⟩ + exact @decide_eq_false (groundsPermission012 true allTrue canonicalArticulation [globalFacet012] + groundsExperimentTask012) (Classical.propDecidable _) unsupported + · intro w _ _; exact ⟨_, rfl, by decide⟩ + +theorem groundsRationaleExperiment012 : + Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0) ∧ + groundsExperiment012 true = false ∧ groundsExperiment012 false = true ∧ + groundsPosition012.outcome true true = groundsExperiment012 true ∧ + groundsPosition012.outcome true false = groundsExperiment012 false := by + refine ⟨(zeroCompatible _).2 rfl, ?_, ?_, ?_, rfl, rfl⟩ + · intro h; have bad := h 1; cases bad + · have actualReasons : ∀ reason ∈ groundsPosition012.reasons, reason true groundsPosition012.adopted := by + intro reason member + cases List.mem_singleton.mp member + refine ⟨(zeroCompatible _).2 rfl, ?_⟩ + intro h; have bad := h 1; cases bad + exact (groundsPosition012Checked.2.2.1 true ((modelsSingleton _ _).2 rfl) trivial actualReasons).1 + · exact @decide_eq_true (groundsPermission012 false allTrue canonicalArticulation [globalFacet012] + groundsExperimentTask012) (Classical.propDecidable _) trivial + +theorem groundsOnGrounds012 : + Grounds012 (fun enabled => GroundsProvision012 enabled) canonicalArticulation [.value groundsPosition012] (.value groundsPosition012) ∧ + groundsPosition012.limits true ∧ groundsPosition012.relevantCriticism true := by + have same : (Facet.value groundsPosition012).claim = (fun enabled => GroundsProvision012 enabled) := by + funext enabled + exact propext (groundsProvision012Meaning enabled).symm + refine ⟨?_, trivial, singleObservation.2.2.2⟩ + rw [← same] + exact grounds012Singleton _ groundsPosition012Checked + +theorem reflexiveTargets012 : + reflexivitySpecification ((ownRules 0).map legacyRule) (fun s => s.owner = 0) + (legacyPerformed (ownRules 0) (completeOwnWork 0)) ∧ + (∀ phase, Performed (completeOwnWork 0) (.process 0 0 phase) .assessment) ∧ + Performed (completeOwnWork 0) (.system 0) .assessment ∧ + reflexivitySpecification ([applicationRule].map legacyRule) (fun s => s.owner = 0) + (legacyPerformed [applicationRule] applicationWork) ∧ + ¬ Performed applicationWork (.system 0) .assessment := by + refine ⟨legacyReflexivity 0 _ _ (completeOwnWork_reflexive 0), ?_, + ownAssessmentPerformed 0 (.system 0) (by simp [ownSubjects]), + legacyReflexivity 0 _ _ applicationWork_reflexive, (applicabilityRetained 0 [] []).2.2.2⟩ + intro phase + apply ownAssessmentPerformed + cases phase <;> simp [ownSubjects] + +theorem achievementSupported012 : + Grounds012 transitionAchievement canonicalArticulation [transitionFacet] (taskOfFacet transitionFacet) ∧ + Compatible [transitionPerformanceRecord] .extend ∧ + transitionAchievement .extend ∧ ¬ transitionAchievement .inflate ∧ + ¬ Supports [transitionReportRecord] transitionAchievement := by + refine ⟨grounds012Singleton _ transitionFacetDischarged, ?_, ?_, ?_, transitionReportDoesNotSupport.2.2⟩ + · exact (transitionPerformanceCompatible .extend).mpr rfl + · simp [transitionAchievement, transitionBefore, transitionAfter, Expanded, baseState, extendedState] + · simp [transitionAchievement, transitionBefore, transitionAfter, Expanded, baseState, inflatedState] + +theorem semanticOrder012 : ∀ p q : Claim Bool, + ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r := + representationOrderIrrelevant + +def clearFalseArgument012 : Articulation Bool := + ⟨["the actual switch is on"], singleton (fun w => w = true), [fun w => w = true], fun _ => True⟩ + +theorem clearFalseReason012 : + Articulated clearFalseArgument012 ∧ ¬ Models clearFalseArgument012.assumptions false := + ⟨⟨by simp [clearFalseArgument012], by simp [clearFalseArgument012]⟩, consistentFalse.2⟩ + +def valueNeutralRecord012 : Record Bool := ⟨fun _ => true, true⟩ + +theorem valueNotFact012 : + valueSpecification switchPosition ∧ + Compatible [valueNeutralRecord012] false ∧ + ¬ Supports [valueNeutralRecord012] switchPosition.commitment ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment := by + have compatible : Compatible [valueNeutralRecord012] false := by + intro r hr; cases List.mem_singleton.mp hr; rfl + refine ⟨valueFulfilled012, compatible, ?_, valueWithoutSelfProof.2.2.1⟩ + intro h + have bad := h false compatible + cases bad + +def wrongExplanation012 : Implementation := { identityImpl with explanation := fun n => n + 1 } + +theorem internalReasonDistinguishes012 : + (∀ n, identityImpl.run n = wrongExplanation012.run n) ∧ + Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧ + Relevant identityRequirements identityImpl (.method .explanation) ∧ + ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation) := by + refine ⟨fun _ => rfl, identityFeasible, identityFeasible, internalReasons.1, ?_⟩ + intro h + have bad := h.2 0 trivial + cases bad + +theorem inventoryCases012 : ∀ kind : InventoryKind, + Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .copy ∧ + ¬ Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .successor := by + intro kind + simp [Available] + + +def selfExemptRule012 : ReflexiveRule Nat Nat Bool := + ⟨⟨0,1⟩, .assessment, fun _ => True, id, + fun input output => output = ownArithmeticPrinciple input⟩ +def selfExemptPerformed012 (key : PrincipleKey) (target input : Nat) (output : Bool) : Prop := + key = ⟨0,1⟩ ∧ target = 1 ∧ input = target ∧ output = ownArithmeticPrinciple input + +theorem openSelfExempt012 : + generationSpecification openPolicy ∧ openPolicy.revisable ⟨.principle,0⟩ ∧ + selfExemptPerformed012 ⟨0,1⟩ 1 1 true ∧ + selfExemptRule012.applicable 0 ∧ + ¬ reflexivitySpecification [selfExemptRule012] (fun target => target = 0) selfExemptPerformed012 := by + refine ⟨⟨Or.inl rfl, fun _ _ => trivial⟩, trivial, ⟨rfl,rfl,rfl,by decide⟩, trivial, ?_⟩ + intro h + obtain ⟨outcome, performed, _⟩ := h.2 selfExemptRule012 (by simp) 0 rfl trivial + cases performed.2.1 + +theorem ownPhilosophyStatus012 : + ¬ choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation + [.status .standing] ∧ + choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation + [.method .output] := + ⟨CoreReader.Integration.existingPhilosophyNotPrivileged.2.2.1, + CoreReader.Integration.existingPhilosophyNotPrivileged.2.2.2.1⟩ + +def jointContext012 : Context (Bool × Bool) Unit := + ⟨emptyTheory, fun _ w => w.2 = true, fun _ => True⟩ + +theorem jointImplicationConflict012 : + Consequence jointTheory jointContext012 () true ∧ + Consequence jointTheory jointContext012 () false ∧ + ¬ Consistent jointTheory jointContext012 := by + have positive : Consequence jointTheory jointContext012 () true := by + intro w hw + exact (hw.1 premiseRule (Or.inr (Or.inl rfl))) (hw.1 premiseP (Or.inl rfl)) + have negative : Consequence jointTheory jointContext012 () false := by + intro w hw + exact hw.1 premiseNotQ (Or.inr (Or.inr rfl)) + exact ⟨positive, negative, conflictRequiresChange _ _ () positive negative⟩ + +def tensionContext012 : Context Nat Unit := + ⟨emptyTheory, fun _ n => n ≤ 6, fun _ => True⟩ + +theorem tensionConsistent012 : + Consistent (union (singleton (fun n : Nat => 4 ≤ n)) (singleton (fun n => n ≤ 6))) tensionContext012 := by + apply consequenceConsistency + exact ⟨5, (modelsUnion _ _ _).2 ⟨(modelsSingleton _ _).2 (by decide), + (modelsSingleton _ _).2 (by decide)⟩, (by intro p hp; cases hp), trivial⟩ + +theorem qualitativeUnmeasured012 : + inferentialSpecification (singleton (fun on : Bool => on = true)) (fun on => on ≠ false) ∧ + usesObservation (Facet.inferential (singleton (fun on : Bool => on = true)) (fun on => on ≠ false)) = false := by + refine ⟨grounds012Singleton _ ⟨⟨true, (modelsSingleton _ _).2 rfl⟩, ?_⟩, rfl⟩ + intro on hon hf + have ht := (modelsSingleton (fun on : Bool => on = true) on).1 hon + cases ht.symm.trans hf + + +theorem allStatusOnly012 : ∀ kind : StatusKind, + ¬ choiceSpecification identityRequirements identityImpl [.status kind] := + statusOnlyFails identityRequirements identityImpl + +/- A finite two-draw experiment assigns positive equal weights to both possible +outcomes. It models possibility and a stable conclusion, not empirical claims +about any physical random-number source. -/ +def drawWeight012 (_draw : Bool) : Nat := 1 +def randomTrial012 (draw : Bool) : Trial := + ⟨0, if draw then 1 else 2, if draw then 1 else 2⟩ + +theorem randomOutcomes012 : + drawWeight012 true > 0 ∧ drawWeight012 false > 0 ∧ + drawWeight012 true = drawWeight012 false ∧ + Reproduced (randomTrial012 true) (randomTrial012 false) ∧ + (randomTrial012 true).actualOutcome ≠ (randomTrial012 false).actualOutcome ∧ + (∀ draw, Verified (randomTrial012 draw) ∧ Bounded (randomTrial012 draw)) := by + refine ⟨by decide, by decide, rfl, rfl, by decide, ?_⟩ + intro draw + cases draw <;> simp [Verified, Bounded, randomTrial012] + + +/- Original tasks are fixed independently of the candidate substitutions below. -/ +def originalGlobalTask012 : AssessmentTask (Nat → Bool) := + .empirical [zeroRecord] (fun _ => True) allTrue (fun _ => True) +def originalLocalTask012 : AssessmentTask (Nat → Bool) := + .empirical [zeroRecord] (fun _ => True) (fun f => f 0 = true) (fun _ => True) + +def circularGlobalFacet012 : Facet (Nat → Bool) := .inferential (singleton allTrue) allTrue + +theorem circularGlobalConditional012 : FacetDischarged circularGlobalFacet012 := by + refine ⟨⟨fun _ => true, (modelsSingleton _ _).2 (fun _ => rfl)⟩, ?_⟩ + intro f hf + exact (modelsSingleton _ _).1 hf + +theorem circularSubstitutionRejected012 : + Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] (taskOfFacet circularGlobalFacet012) ∧ + ¬ NatureAppropriate originalGlobalTask012 circularGlobalFacet012 ∧ + ¬ Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] originalGlobalTask012 := by + have inappropriate : ¬ NatureAppropriate originalGlobalTask012 circularGlobalFacet012 := by + intro h + have equalPremises := h.1 + have originalMember : singleton (fun f => Compatible [zeroRecord] f ∧ True) allTrue := equalPremises ▸ (show singleton allTrue allTrue from rfl) + have equalClaims : allTrue = (fun f => Compatible [zeroRecord] f ∧ True) := originalMember + have claimedAll := (congrFun equalClaims (localGenerator 0)).mpr ⟨(zeroCompatible _).2 rfl, trivial⟩ + have bad := claimedAll 1 + cases bad + refine ⟨grounds012Singleton _ circularGlobalConditional012, inappropriate, ?_⟩ + intro h + exact inappropriate (h.2 circularGlobalFacet012 (by simp)).2.2.2.2 + +def observedPremises012 : Theory (Nat → Bool) := singleton (fun f => Compatible [zeroRecord] f ∧ True) +def observedInferenceFacet012 : Facet (Nat → Bool) := + .inferential observedPremises012 (fun f => f 0 = true) + +theorem observedInferenceChecked012 : FacetDischarged observedInferenceFacet012 := by + refine ⟨⟨localGenerator 0, (modelsSingleton _ _).2 ⟨(zeroCompatible _).2 rfl, trivial⟩⟩, ?_⟩ + intro f hf + exact (zeroCompatible _).1 ((modelsSingleton _ _).1 hf).1 + +theorem sameEmpiricalTaskTwoMethods012 : + Grounds012 (fun f => f 0 = true) canonicalArticulation [localFacet012] originalLocalTask012 ∧ + Grounds012 (fun f => f 0 = true) canonicalArticulation [observedInferenceFacet012] originalLocalTask012 := by + refine ⟨grounds012Singleton _ localFacetChecked012, ?_⟩ + refine ⟨by simp, ?_⟩ + intro f hf + cases List.mem_singleton.mp hf + exact ⟨rfl, canonicalArticulated _ observedInferenceChecked012, + canonicalFacetArticulated _, observedInferenceChecked012, rfl, rfl, fun _ _ => trivial⟩ + +/- The second coordinate remains unobserved. Switching assessment form cannot +remove that uncertainty responsibility from the original empirical task. -/ +def originalUncertaintyTask012 : AssessmentTask (Bool × Bool) := + .empirical [temperatureRecord, temperatureRecord] (fun _ => True) + (fun w => w.1 = true) (fun w => w.2 = true) +def uncertaintyBypassFacet012 : Facet (Bool × Bool) := + .inferential (singleton (fun w => Compatible [temperatureRecord, temperatureRecord] w ∧ True)) + (fun w => w.1 = true) + +theorem uncertaintyBypassChecked012 : FacetDischarged uncertaintyBypassFacet012 := by + refine ⟨⟨(true,false), (modelsSingleton _ _).2 ⟨temperatureCompatible false, trivial⟩⟩, ?_⟩ + intro w hw + exact ((modelsSingleton _ _).1 hw).1 temperatureRecord (by simp) + +theorem uncertaintySubstitutionRejected012 : + FacetDischarged uncertaintyBypassFacet012 ∧ + ¬ NatureAppropriate originalUncertaintyTask012 uncertaintyBypassFacet012 ∧ + ¬ Grounds012 (fun w : Bool × Bool => w.1 = true) canonicalArticulation + [uncertaintyBypassFacet012] originalUncertaintyTask012 := by + have inappropriate : ¬ NatureAppropriate originalUncertaintyTask012 uncertaintyBypassFacet012 := by + intro h + have bad := h.2.2 (true,false) (temperatureCompatible false) + cases bad + exact ⟨uncertaintyBypassChecked012, inappropriate, + fun h => inappropriate (h.2 uncertaintyBypassFacet012 (by simp)).2.2.2.2⟩ + +def selectedFactFacet012 : Facet Bool := + .empirical [switchRecord] (fun _ => True) switchPosition.commitment (fun _ => True) + +theorem valueFactSubstitutionRejected012 : + FacetDischarged selectedFactFacet012 ∧ valueSpecification switchPosition ∧ + ¬ Grounds012 switchPosition.commitment canonicalArticulation [selectedFactFacet012] (.value switchPosition) := by + refine ⟨switchEmpiricalDischarged, valueFulfilled012, ?_⟩ + intro h + exact (h.2 selectedFactFacet012 (by simp)).2.2.2.2 + +theorem inferentialContextSubstitutionRejected012 : + FacetDischarged (Facet.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) ∧ + ¬ Grounds012 (fun w : Bool => w = true) canonicalArticulation + [.inferential (singleton (fun w => w = true)) (fun w => w = true)] + (.inferential emptyTheory (fun w => w = true)) := by + refine ⟨⟨⟨true, (modelsSingleton _ _).2 rfl⟩, fun w hw => (modelsSingleton (fun w : Bool => w = true) w).1 hw⟩, ?_⟩ + intro h + have appropriate := (h.2 (.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) (by simp)).2.2.2.2 + have same : singleton (fun w : Bool => w = true) = emptyTheory := appropriate.1 + have bad : emptyTheory (fun w : Bool => w = true) := same ▸ (show singleton (fun w : Bool => w = true) (fun w => w = true) from rfl) + exact bad + + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.generationCases +organon.charter.overview#p2 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c +organon.charter.overview#p3 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c +organon.charter.self-transcendence#p1 sha256 f4ca590e2ae15e3882f70c7b2bc46a8911c97cee547c8b137b5493fbf862c8c0 +organon.charter.self-transcendence.orientation#p1 sha256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf +organon.charter.self-transcendence.non-finality#p1 sha256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8 +organon.charter.self-transcendence.limits#p2 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d +organon.relationships.terms#p1 sha256 61cb7ce4f2920f1aa6771502b87a66536ae0504acccfebd9dd23bcc62756eddf +-/ +theorem generationCases : + (Generative openPolicy ∧ + (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧ + (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1)))) ∧ + (neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy) ∧ + (Generative generatingSystem.policy ∧ + generatingSystem.policy.permitsVersion 0 0 ∧ + ¬ Expanded generatingSystem.current inflatedState ∧ + generatingSystem.current.inventory.length < inflatedState.inventory.length ∧ + generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧ + generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧ + generatingSystem.execute availableResources = some 6 ∧ + generatingSystem.execute { availableResources with experience := none } = none ∧ + generatingSystem.execute { availableResources with knowledge := none } = none ∧ + generatingSystem.execute { availableResources with collaborator := none } = none ∧ + generatingSystem.execute ⟨none, none, none⟩ = none ∧ + ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧ + generatingSystem.stableAction = generatingSystem.current ∧ + generatingSystem.requirementsMet generatingSystem.stableAction ∧ + generatingSystem.withinBudget generatingSystem.stableAction ∧ + ¬ generatingSystem.withinBudget inflatedState ∧ + StableReason generatingSystem.current inflatedState ∧ + (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧ + inflatedAnnouncement.owner = generatingSystem.owner ∧ + inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧ + inflatedAnnouncement.reportedNewOperation = .successor ∧ + inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧ + ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after)) ∧ + (generationSpecification openPolicy ∧ + Expanded baseState (collaborativeRevision availableResources) ∧ + ¬ Expanded baseState (collaborativeRevision { availableResources with collaborator := none }) ∧ + assistedExecution ⟨none, none, none⟩ = none) := + ⟨revisionWithoutProgress, permissionNotValuation, generationLimits, collaborativeProgress⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.generationLimits012 +organon.charter.self-transcendence.orientation#p1 sha256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf +organon.charter.self-transcendence.non-finality#p1 sha256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8 +organon.charter.self-transcendence.limits#p1 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d +organon.charter.self-transcendence.limits#p2 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +theorem generationLimits012 : + (neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy) ∧ + (Generative openPolicy ∧ + (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧ + (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1)))) ∧ + (Generative generatingSystem.policy ∧ + generatingSystem.policy.permitsVersion 0 0 ∧ + ¬ Expanded generatingSystem.current inflatedState ∧ + generatingSystem.current.inventory.length < inflatedState.inventory.length ∧ + generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧ + generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧ + generatingSystem.execute availableResources = some 6 ∧ + generatingSystem.execute { availableResources with experience := none } = none ∧ + generatingSystem.execute { availableResources with knowledge := none } = none ∧ + generatingSystem.execute { availableResources with collaborator := none } = none ∧ + generatingSystem.execute ⟨none, none, none⟩ = none ∧ + ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧ + generatingSystem.stableAction = generatingSystem.current ∧ + generatingSystem.requirementsMet generatingSystem.stableAction ∧ + generatingSystem.withinBudget generatingSystem.stableAction ∧ + ¬ generatingSystem.withinBudget inflatedState ∧ + StableReason generatingSystem.current inflatedState ∧ + (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧ + inflatedAnnouncement.owner = generatingSystem.owner ∧ + inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧ + inflatedAnnouncement.reportedNewOperation = .successor ∧ + inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧ + ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after)) ∧ + (generationSpecification openPolicy ∧ + Expanded baseState (collaborativeRevision availableResources) ∧ + ¬ Expanded baseState (collaborativeRevision { availableResources with collaborator := none }) ∧ + assistedExecution ⟨none, none, none⟩ = none) ∧ + (Grounds012 transitionAchievement canonicalArticulation [transitionFacet] (taskOfFacet transitionFacet) ∧ + Compatible [transitionPerformanceRecord] .extend ∧ + transitionAchievement .extend ∧ ¬ transitionAchievement .inflate ∧ + ¬ Supports [transitionReportRecord] transitionAchievement) ∧ + (∀ kind : InventoryKind, + Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .copy ∧ + ¬ Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .successor) := + ⟨permissionNotValuation, revisionWithoutProgress, generationLimits, collaborativeProgress, achievementSupported012, inventoryCases012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.consistencyCases +organon.charter.consistency#p1 sha256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42 +organon.charter.consistency.meaning#p1 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75 +-/ +theorem consistencyCases : + (Satisfiable (singleton premiseP) ∧ Satisfiable (singleton premiseRule) ∧ + Satisfiable (singleton premiseNotQ) ∧ ¬ Satisfiable jointTheory) ∧ + ((Consequence emptyTheory (assumptionContext true) () true ∧ + Consequence emptyTheory (assumptionContext false) () false) ∧ + (Consequence emptyTheory (meaningContext true) () true ∧ + Consequence emptyTheory (meaningContext false) () false) ∧ + (Consequence emptyTheory (scopeContext true) () true ∧ + Consequence emptyTheory (scopeContext false) () false) ∧ + (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w)) ∧ + (¬ TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (meaningContext true)) (contextSnapshot (meaningContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (scopeContext true)) (contextSnapshot (scopeContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (scopeContext true) 0) (contextSnapshot (scopeContext true) 1) false ∧ + (TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) true ∧ + ¬ Models (assumptionContext false).assumptions true)) ∧ + (Satisfiable (revisionSlice 0) ∧ Satisfiable (revisionSlice 1) ∧ + ¬ Satisfiable (union (revisionSlice 0) (revisionSlice 1))) ∧ + ((∀ time, Consistent (revisionSlice time) broadBoolContext) ∧ + ¬ Consistent (union (revisionSlice 0) (revisionSlice 1)) broadBoolContext) ∧ + (∀ p q : Claim Bool, + ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r) ∧ + (Consequence jointTheory jointContext012 () true ∧ + Consequence jointTheory jointContext012 () false ∧ + ¬ Consistent jointTheory jointContext012) := + ⟨jointConflict, contextDifferences, hiddenContextChangeRejected, revisionCanReverse, sliceConsistency, semanticOrder012, jointImplicationConflict012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.consistencyLimits012 +organon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75 +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +theorem consistencyLimits012 : + ((Consequence emptyTheory (assumptionContext true) () true ∧ + Consequence emptyTheory (assumptionContext false) () false) ∧ + (Consequence emptyTheory (meaningContext true) () true ∧ + Consequence emptyTheory (meaningContext false) () false) ∧ + (Consequence emptyTheory (scopeContext true) () true ∧ + Consequence emptyTheory (scopeContext false) () false) ∧ + (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w)) ∧ + ((∃ budget : Nat, 4 ≤ budget ∧ budget ≤ 6) ∧ + ¬ ((fun n : Nat => 4 ≤ n) = (fun n : Nat => n ≤ 6))) ∧ + (Consistent (singleton (fun w : Bool => w = true)) broadBoolContext ∧ + ¬ Models (singleton (fun w : Bool => w = true)) false ∧ + Consistent (emptyTheory : Theory Bool) broadBoolContext ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧ + (Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧ + (Consistent (union (singleton (fun n : Nat => 4 ≤ n)) (singleton (fun n => n ≤ 6))) tensionContext012) := + ⟨contextDifferences, tensionWithoutContradiction, explicitlyConsistentLimits, compatibilityNotEntailment, tensionConsistent012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.reflexivityCases012 +organon.charter.reflexivity#p1 sha256 13293b45c2fa89068c68ae7ef3c5df38f0efadb3ef3873d78a5ba67d9691a757 +organon.charter.reflexivity.meaning#p1 sha256 8a2caede01a43d8b6c60b54c78ac089c51868e9956f316948077ccee2e45c9cc +organon.charter.reflexivity.limits#p1 sha256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +theorem reflexivityCases012 : + (reflexivitySpecification ((ownRules 0).map legacyRule) (fun s => s.owner = 0) + (legacyPerformed (ownRules 0) (completeOwnWork 0)) ∧ + (∀ phase, Performed (completeOwnWork 0) (.process 0 0 phase) .assessment) ∧ + Performed (completeOwnWork 0) (.system 0) .assessment ∧ + reflexivitySpecification ([applicationRule].map legacyRule) (fun s => s.owner = 0) + (legacyPerformed [applicationRule] applicationWork) ∧ + ¬ Performed applicationWork (.system 0) .assessment) ∧ + (Grounds012 (fun enabled => GroundsProvision012 enabled) canonicalArticulation [.value groundsPosition012] (.value groundsPosition012) ∧ + groundsPosition012.limits true ∧ groundsPosition012.relevantCriticism true) ∧ + (Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0) ∧ + groundsExperiment012 true = false ∧ groundsExperiment012 false = true ∧ + groundsPosition012.outcome true true = groundsExperiment012 true ∧ + groundsPosition012.outcome true false = groundsExperiment012 false) := + ⟨reflexiveTargets012, groundsOnGrounds012, groundsRationaleExperiment012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.reflexivityLimits012 +organon.charter.reflexivity.limits#p1 sha256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.grounds#p1 sha256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6 +-/ +theorem reflexivityLimits012 : + (selfTest [1] = true ∧ ownArithmeticPrinciple 0 = false ∧ + ¬ (∀ n, ownArithmeticPrinciple n = true)) ∧ + (localGenerator 0 0 = true ∧ localGenerator 0 1 = false ∧ + Compatible [zeroRecord] (localGenerator 0) ∧ + ¬ Supports [zeroRecord] allTrue ∧ OwnedRevisionExample) ∧ + (Generative openPolicy ∧ ¬ Reflexive 0 (ownRules 0) []) ∧ + (CompleteCharter012 CoreReader.Integration.actualSystem CoreReader.Integration.actual ∧ + Admissible CoreReader.Integration.held CoreReader.Integration.context CoreReader.Integration.actual ∧ + Compatible [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.actual ∧ + Articulated (canonicalArticulation CoreReader.Integration.unsupportedCapabilityFacet) ∧ + ¬ Supports [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.capability ∧ + ¬ Grounds012 CoreReader.Integration.capability canonicalArticulation + [CoreReader.Integration.unsupportedCapabilityFacet] + (taskOfFacet CoreReader.Integration.unsupportedCapabilityFacet)) ∧ + (generationSpecification openPolicy ∧ openPolicy.revisable ⟨.principle,0⟩ ∧ + selfExemptPerformed012 ⟨0,1⟩ 1 1 true ∧ + selfExemptRule012.applicable 0 ∧ + ¬ reflexivitySpecification [selfExemptRule012] (fun target => target = 0) selfExemptPerformed012) := + ⟨selfTestDoesNotProve, selfOriginDoesNotSupport, generationNotReflexivity, charterWithoutGrounds012, openSelfExempt012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.groundsCases012 +organon.grounds#p1 sha256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6 +organon.grounds.assessment#p1 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +-/ +theorem groundsCases012 : + (Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧ + Articulated (canonicalArticulation globalFacet012) ∧ + ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧ + ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012)) ∧ + (Articulated uninformativeArgument ∧ + ¬ Entails uninformativeArgument.assumptions (fun w : Bool => w = true)) ∧ + (Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] (taskOfFacet circularGlobalFacet012) ∧ + ¬ NatureAppropriate originalGlobalTask012 circularGlobalFacet012 ∧ + ¬ Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] originalGlobalTask012) := + ⟨scopeStrength012, articulationNotSupport, circularSubstitutionRejected012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.empiricalCases012 +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +-/ +theorem empiricalCases012 : + (Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧ + Articulated (canonicalArticulation globalFacet012) ∧ + ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧ + ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012)) ∧ + (temperatureRecord.test (true,false) = true ∧ + Compatible [temperatureRecord,temperatureRecord] (true,false) ∧ + Compatible [temperatureRecord,temperatureRecord] (true,true) ∧ + ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + Compatible [actionRecord,actionRecord] (true,0) ∧ + Compatible [actionRecord,actionRecord] (true,3) ∧ + ¬ Supports [actionRecord] announcementPosition.consequence ∧ + ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧ + ¬ ValueProcedure announcementPosition) ∧ + (empiricalSpecification [temperatureRecord, temperatureRecord] (fun _ => True) + (fun w => w.1 = true) (fun w => w.2 = true ∨ w.2 = false) ∧ + Compatible [temperatureRecord, temperatureRecord] (true,true) ∧ + Compatible [temperatureRecord, temperatureRecord] (true,false)) ∧ + (Grounds012 (fun f => f 0 = true) canonicalArticulation [localFacet012] originalLocalTask012 ∧ + Grounds012 (fun f => f 0 = true) canonicalArticulation [observedInferenceFacet012] originalLocalTask012) ∧ + (FacetDischarged uncertaintyBypassFacet012 ∧ + ¬ NatureAppropriate originalUncertaintyTask012 uncertaintyBypassFacet012 ∧ + ¬ Grounds012 (fun w : Bool × Bool => w.1 = true) canonicalArticulation + [uncertaintyBypassFacet012] originalUncertaintyTask012) := + ⟨scopeStrength012, measurementRepeatNotSupport, uncertainSupported012, sameEmpiricalTaskTwoMethods012, uncertaintySubstitutionRejected012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.inferentialCases012 +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +theorem inferentialCases012 : + (inferentialSpecification (singleton (fun n : Nat => n = 2)) (fun n => n + 1 = 3) ∧ + InferenceExamined (emptyTheory : Theory Bool) (fun w => w = true) false ∧ + Models (emptyTheory : Theory Bool) false ∧ ¬ ((fun w : Bool => w = true) false)) ∧ + (Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧ + (FacetDischarged (Facet.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) ∧ + ¬ Grounds012 (fun w : Bool => w = true) canonicalArticulation + [.inferential (singleton (fun w => w = true)) (fun w => w = true)] + (.inferential emptyTheory (fun w => w = true))) := + ⟨inferenceChecked012, compatibilityNotEntailment, inferentialContextSubstitutionRejected012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.valueCases012 +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +-/ +theorem valueCases012 : + (valueSpecification switchPosition) ∧ + (announcementPosition.reasons ≠ [] ∧ announcementPosition.commitment (true,0) ∧ + (∀ reason, reason ∈ announcementPosition.reasons → reason (true,0) announcementPosition.adopted) ∧ + ¬ announcementPosition.consequence (true,0) ∧ ¬ ValueProcedure announcementPosition) ∧ + (¬ ValueProcedure closedPosition012) ∧ + (ValueProcedure switchPosition ∧ + Satisfiable switchPosition.starting ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧ + (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧ + (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition)) ∧ + (FacetDischarged selectedFactFacet012 ∧ valueSpecification switchPosition ∧ + ¬ Grounds012 switchPosition.commitment canonicalArticulation [selectedFactFacet012] (.value switchPosition)) := + ⟨valueFulfilled012, announcementNotBudgetReason, closedCriticism012, valueWithoutSelfProof, valueFactSubstitutionRejected012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.groundsLimits012 +organon.grounds.assessment#p1 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +-/ +theorem groundsLimits012 : + (Articulated clearFalseArgument012 ∧ ¬ Models clearFalseArgument012.assumptions false) ∧ + (temperatureRecord.test (true,false) = true ∧ + Compatible [temperatureRecord,temperatureRecord] (true,false) ∧ + Compatible [temperatureRecord,temperatureRecord] (true,true) ∧ + ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + Compatible [actionRecord,actionRecord] (true,0) ∧ + Compatible [actionRecord,actionRecord] (true,3) ∧ + ¬ Supports [actionRecord] announcementPosition.consequence ∧ + ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧ + ¬ ValueProcedure announcementPosition) ∧ + (valueSpecification switchPosition ∧ + Compatible [valueNeutralRecord012] false ∧ + ¬ Supports [valueNeutralRecord012] switchPosition.commitment ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment) ∧ + (ValueProcedure switchPosition ∧ + Satisfiable switchPosition.starting ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧ + (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧ + (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition)) ∧ + (ClaimNoStronger (fun f : Nat → Bool => f 0 = true) allTrue ∧ + ¬ ClaimNoStronger allTrue (fun f : Nat → Bool => f 0 = true) ∧ + valueSpecification switchPosition) := + ⟨clearFalseReason012, measurementRepeatNotSupport, valueNotFact012, valueWithoutSelfProof, qualitativeProportionality012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.scopeCases012 +organon.grounds.scope#p1 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.scope#p2 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.scope#p3 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +-/ +theorem scopeCases012 : + (scopeSpecification localScopeAccount012) ∧ + ((∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧ + (fun _ : Nat => true) 1 ≠ localGenerator 0 1) := + ⟨scopeFulfilled012, hiddenDifference⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.scopeLimits012 +organon.grounds.scope#p1 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.scope#p2 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.scope#p3 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870 +-/ +theorem scopeLimits012 : + ((∃ outside : Nat, outside ≠ 0) ∧ + Compatible [zeroRecord] (fun _ => true) ∧ + Compatible [zeroRecord] (localGenerator 0) ∧ + allTrue (fun _ => true) ∧ ¬ allTrue (localGenerator 0) ∧ + ¬ Supports [zeroRecord] allTrue) ∧ + ((∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧ + (fun _ : Nat => true) 1 ≠ localGenerator 0 1) ∧ + ([zeroRecord].length = 1 ∧ + (∃ f, Compatible [zeroRecord] f) ∧ + Supports [zeroRecord] (fun f => f 0 = true) ∧ + ¬ Supports [zeroRecord] allTrue) ∧ + (let a : Trial := ⟨0,1,1⟩ + let b : Trial := ⟨0,2,2⟩ + Reproduced a b ∧ a.actualOutcome ≠ b.actualOutcome ∧ Bounded a ∧ Bounded b) ∧ + ((Verified ⟨0,1,1⟩ ∧ Verified ⟨1,1,1⟩ ∧ ¬ Reproduced ⟨0,1,1⟩ ⟨1,1,1⟩) ∧ + (Reproduced ⟨0,1,1⟩ ⟨0,3,2⟩ ∧ ¬ Verified ⟨0,3,2⟩ ∧ ¬ Bounded ⟨0,3,2⟩) ∧ + (Bounded ⟨0,1,1⟩ ∧ Bounded ⟨0,2,0⟩ ∧ ¬ Verified ⟨0,2,0⟩)) ∧ + (FacetDischarged arithmeticFacet ∧ usesObservation arithmeticFacet = false) ∧ + (inferentialSpecification (singleton (fun on : Bool => on = true)) (fun on => on ≠ false) ∧ + usesObservation (Facet.inferential (singleton (fun on : Bool => on = true)) (fun on => on ≠ false)) = false) ∧ + (drawWeight012 true > 0 ∧ drawWeight012 false > 0 ∧ + drawWeight012 true = drawWeight012 false ∧ + Reproduced (randomTrial012 true) (randomTrial012 false) ∧ + (randomTrial012 true).actualOutcome ≠ (randomTrial012 false).actualOutcome ∧ + (∀ draw, Verified (randomTrial012 draw) ∧ Bounded (randomTrial012 draw))) := + ⟨localNotUniversal, hiddenDifference, singleObservation, variableOutcomesStableBound, verificationReproductionStability, noUniversalChain, qualitativeUnmeasured012, randomOutcomes012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.capabilityCases012 +organon.grounds.capabilities#p1 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0 +organon.grounds.capabilities#p2 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0 +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +theorem capabilityCases012 : + (capabilitySpecification outputOnlyProcess OutputContract ∧ + capabilitySpecification explainedProcess FullProcessContract ∧ + (∃ certificate : ExternalCertificate outputOnlyProcess, + certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧ + ¬ ExplanationContract outputOnlyProcess) ∧ + (OwnCapability012 7 7 outputOnlyProcess OutputContract) ∧ + (explainedWithoutVariation012.process = mechanismResponder012.process ∧ + FullProcessContract explainedWithoutVariation012.process ∧ + ¬ UnderstandingApplication012 explainedWithoutVariation012 ∧ + UnderstandingApplication012 mechanismResponder012 ∧ + Grounds012 UnderstandingApplication012 canonicalArticulation + [understandingFacet012 mechanismResponder012] (understandingTask012 mechanismResponder012) ∧ + ¬ Grounds012 UnderstandingApplication012 canonicalArticulation + [understandingFacet012 explainedWithoutVariation012] (understandingTask012 explainedWithoutVariation012)) := + ⟨capabilityFulfilled012, ownCapability012, understandingApplicationCases012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.capabilityLimits012 +organon.grounds.capabilities#p1 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0 +organon.grounds.capabilities#p2 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0 +-/ +theorem capabilityLimits012 : + (capabilitySpecification outputOnlyProcess OutputContract ∧ + capabilitySpecification explainedProcess FullProcessContract ∧ + (∃ certificate : ExternalCertificate outputOnlyProcess, + certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧ + ¬ ExplanationContract outputOnlyProcess) ∧ + (∀ kind : InventoryKind, + Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .copy ∧ + ¬ Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .successor) ∧ + (Generative generatingSystem.policy ∧ + generatingSystem.policy.permitsVersion 0 0 ∧ + ¬ Expanded generatingSystem.current inflatedState ∧ + generatingSystem.current.inventory.length < inflatedState.inventory.length ∧ + generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧ + generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧ + generatingSystem.execute availableResources = some 6 ∧ + generatingSystem.execute { availableResources with experience := none } = none ∧ + generatingSystem.execute { availableResources with knowledge := none } = none ∧ + generatingSystem.execute { availableResources with collaborator := none } = none ∧ + generatingSystem.execute ⟨none, none, none⟩ = none ∧ + ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧ + generatingSystem.stableAction = generatingSystem.current ∧ + generatingSystem.requirementsMet generatingSystem.stableAction ∧ + generatingSystem.withinBudget generatingSystem.stableAction ∧ + ¬ generatingSystem.withinBudget inflatedState ∧ + StableReason generatingSystem.current inflatedState ∧ + (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧ + inflatedAnnouncement.owner = generatingSystem.owner ∧ + inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧ + inflatedAnnouncement.reportedNewOperation = .successor ∧ + inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧ + ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after)) := + ⟨capabilityFulfilled012, inventoryCases012, generationLimits⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.choiceCases012 +organon.grounds.implementations#p1 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c +organon.grounds.implementations#p2 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c +organon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870 +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +theorem choiceCases012 : + (identityImpl.conventional = true ∧ identityImpl.established = true ∧ + JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output]) ∧ + (Relevant identityRequirements identityImpl (.method .explanation) ∧ + Relevant identityRequirements identityImpl (.method .applicability) ∧ + Relevant identityRequirements identityImpl (.method .simplicity) ∧ + Relevant identityRequirements identityImpl (.method .procedure) ∧ + (Relevant identityRequirements cheapSuccessor (.method .simplicity) ∧ + ¬ JustifiedChoice identityRequirements cheapSuccessor [.method .simplicity])) ∧ + (Articulated priorityArticulation ∧ AssessmentAccurate false ∧ + (∀ selected, Models statusFacts selected) ∧ + priorityClaim .identity ∧ ¬ priorityClaim .successor ∧ + ¬ Entails statusFacts priorityClaim ∧ + ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧ + ((∀ n, identityImpl.run n = wrongExplanation012.run n) ∧ + Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧ + Relevant identityRequirements identityImpl (.method .explanation) ∧ + ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation)) ∧ + (¬ choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation + [.status .standing] ∧ + choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation + [.method .output]) ∧ + (∀ kind : StatusKind, + ¬ choiceSpecification identityRequirements identityImpl [.status kind]) := + ⟨conventionWithReason, internalReasons, statusAssessmentNonEntailment, internalReasonDistinguishes012, ownPhilosophyStatus012, allStatusOnly012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.choiceLimits012 +organon.grounds.implementations#p1 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c +organon.grounds.implementations#p2 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c +organon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870 +-/ +theorem choiceLimits012 : + ((∀ candidate, Feasible identityRequirements (implementation candidate) ↔ candidate = .identity) ∧ + JustifiedChoice identityRequirements identityImpl objectiveReason) ∧ + (identityImpl.conventional = true ∧ identityImpl.established = true ∧ + JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output]) ∧ + ((∀ n, identityImpl.run n = wrongExplanation012.run n) ∧ + Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧ + Relevant identityRequirements identityImpl (.method .explanation) ∧ + ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation)) ∧ + (JustifiedChoice identityRequirements identityImpl objectiveReason ∧ + identityImpl.run 0 ≠ successorImpl.run 0) ∧ + ((∀ x, x = 0 → identityImpl.run x = changedOutsideZero.run x) ∧ + identityImpl.run 1 ≠ changedOutsideZero.run 1) ∧ + ((Articulated priorityArticulation ∧ AssessmentAccurate false ∧ + (∀ selected, Models statusFacts selected) ∧ + priorityClaim .identity ∧ ¬ priorityClaim .successor ∧ + ¬ Entails statusFacts priorityClaim ∧ + ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧ + PolicyIndependenceExample) := + ⟨singleFeasible, conventionWithReason, internalReasonDistinguishes012, openNotEquivalent, localNotGlobal, generalGroundsNotChoice⟩ + +end CoreReader.Adopted +``` + + + + **L1** Import the checked Logic, Evidence, Choice and Agency examples through Integration. + + + **L3** Place the following declarations in CoreReader.Adopted. + + + **L4** Make the four helper namespaces available without qualification. + + + **L6** The comment limits the encoding to three explicit mathematical task forms. + + + **L7** These forms are not an exhaustive or exclusive taxonomy; original claims and support must be fixed. + + + **L8** The support context is fixed before proposing a candidate assessment. + + + **L9** Alternative assessments must retain task identity; taskOfFacet instead declares a new task. + + + **L10** Declaring a new task does not authorize replacing an existing one. + + + **L11** Define task data over an arbitrary world type W; constructing data proves no fulfillment. + + + **L12** An empirical task stores the original records, scope, claim and uncertainty predicate. + + + **L13** An inferential task stores the original assumptions and conclusion. + + + **L14** A value task stores the complete position, including its reasons, limits and consequences. + + + **L16** Convert a facet into the new assessment task it itself declares. + + + **L17** Copy every empirical field into the newly declared task. + + + **L18** Copy the inference's assumptions and conclusion without adding support. + + + **L19** Preserve the complete value position in the new task. + + + **L21** Describe a content-based sufficient adapter for a declared task. + + + **L22** This finite adapter is not a philosophical demand for one unique assessment form. + + + **L23** An empirical task may use inference based on exactly its original observation and scope premises. + + + **L24** Changing assessment form still retains the original uncertainty duty. + + + **L25** Assuming the desired conclusion cannot replace the original empirical grounds. + + + **L26** The finite adapter does not promise to accept every equivalent presentation. + + + **L27** Define appropriateness as a relation between an independently fixed task and a candidate facet. + + + **L28** Compare an original empirical task with a candidate empirical assessment. + + + **L29** Require exact equality of records, scope, conclusion and uncertainty content. + + + **L30** Handle an inference proposed for the same original empirical task. + + + **L31** Require its assumptions to be exactly original record compatibility together with original scope. + + + **L32** Retain the original conclusion and require the original records to support the original uncertainty predicate. + + + **L33** Compare original and candidate inferential tasks. + + + **L34** Require the same assumptions and conclusion; a new conclusion-assumption is not admitted. + + + **L35** For a value task require equality of the entire position, not just its selected option. + + + **L36** Reject all other task/facet pairings in this disclosed finite adapter. + + + **L38** Prove that a facet matches the new task declared from itself; this says nothing about another original task. + + + **L39** Split the proof over the three facet constructors. + + + **L40** The empirical case supplies four reflexive content equalities. + + + **L41** The inferential case supplies reflexive assumption and conclusion equalities. + + + **L42** The value case uses reflexive equality of the complete position. + + + **L44** Explain that the adopted Core 0.1.2 task needs appropriate assessment. + + + **L45** The supplied facet list is the explicit represented scope of assessment. + + + **L46** No Core 0.1.3 all-applicable coverage rule or self-validating kind label is introduced. + + + **L47** Appropriateness depends on actual task and facet contents. + + + **L48** Begin source-tracing metadata for CoreReader.Adopted.Grounds012; this mapping is not a proof premise. + + + **L49** Record source clause organon.grounds#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L50** Record source clause organon.grounds.assessment#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L51** Record source clause organon.grounds.assessment#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L52** Record source clause organon.grounds.assessment#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L53** Close the preceding source-mapping comment without adding a logical condition. + + + **L54** Define Grounds012 for an explicit claim over W. + + + **L55** Parameterize it by the actual articulation function and proposed facet list. + + + **L56** Also require the independently fixed original task as an explicit parameter. + + + **L57** Require a nonempty list and examine every listed facet. + + + **L58** Bind each facet to the same claim and require identifiable articulation. + + + **L59** Require articulation to match the facet's contents and require its represented assessment to be discharged. + + + **L60** Also require appropriateness to the original task; same conclusion alone is insufficient. + + + **L62** The helper's conclusion concerns only its newly declared taskOfFacet f. + + + **L63** It cannot supply appropriateness to a different existing task sharing the conclusion. + + + **L64** Assume the supplied facet f is already discharged; the helper does not prove that premise. + + + **L65** Conclude Grounds for its canonical articulation and its own newly declared task. + + + **L66** Prove the singleton list nonempty, leaving its universal facet obligation. + + + **L67** Introduce an arbitrary listed facet and its membership proof. + + + **L68** Singleton membership identifies that facet with f. + + + **L69** Combine claim identity, canonical articulation, the assumed discharge h, and task-content identity. + + + **L71** Begin source-tracing metadata for CoreReader.Adopted.generationSpecification; this mapping is not a proof premise. + + + **L72** Record source clause organon.charter.overview#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L73** Record source clause organon.charter.overview#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L74** Record source clause organon.charter.self-transcendence#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L75** Record source clause organon.charter.self-transcendence.orientation#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L76** Record source clause organon.charter.self-transcendence.non-finality#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L77** Record source clause organon.charter.self-transcendence.limits#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L78** Record source clause organon.relationships.terms#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L79** Close the preceding source-mapping comment without adding a logical condition. + + + **L80** Generation satisfaction means valuing expansion and keeping every current form revisable. + + + **L82** The consistency comment concerns joint consequences of the whole currently held set. + + + **L83** Reporting historical change is separate from retaining withdrawn claims simultaneously. + + + **L84** Begin source-tracing metadata for CoreReader.Adopted.consistencySpecification; this mapping is not a proof premise. + + + **L85** Record source clause organon.charter.consistency#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L86** Record source clause organon.charter.consistency.meaning#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L87** Record source clause organon.charter.consistency.meaning#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L88** Record source clause organon.charter.consistency.limits#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L89** Close the preceding source-mapping comment without adding a logical condition. + + + **L90** Define consistency and reporting for before/after snapshots over worlds and questions. + + + **L91** The Boolean report records whether a change was acknowledged. + + + **L92** Require the current whole theory to be consistent and the transition report truthful. + + + **L94** The reflexive-rule comment allows domain-specific input and interpretation types. + + + **L95** The rule key must coherently identify one method. + + + **L96** Work for another method cannot silently discharge this rule's duty. + + + **L97** Package a reflexive rule over targets T, inputs I and outcomes O. + + + **L98** Store the rule's owner/local principle identity. + + + **L99** Store whether the rule concerns generation or assessment. + + + **L100** Store the condition under which the rule applies to each target. + + + **L101** Specify the actual input for each target. + + + **L102** Specify which outcomes follow the method's meaning for each input. + + + **L104** Begin source-tracing metadata for CoreReader.Adopted.reflexivitySpecification; this mapping is not a proof premise. + + + **L105** Record source clause organon.charter.reflexivity#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L106** Record source clause organon.charter.reflexivity.meaning#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L107** Record source clause organon.charter.reflexivity.limits#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L108** Record source clause organon.relationships.roles#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L109** Close the preceding source-mapping comment without adding a logical condition. + + + **L110** Define the obligation over a supplied list of generic reflexive rules. + + + **L111** Supply self-target identification and an actual performed-work relation indexed by key, target, input and result. + + + **L112** Equal keys among registered rules must identify equal complete rules. + + + **L113** For every listed rule and self-target, retain that rule's actual applicability condition. + + + **L114** Require an actual result performed on precisely that target and its prescribed input. + + + **L115** Require the same result to satisfy the rule's meaning relation. + + + **L117** Adapt an existing concrete principle to the generic reflexive interface. + + + **L118** Preserve its key, activity, applicability and inquiry function. + + + **L119** Evaluate meaning using the reasons and limits attached to this inquiry's actual target. + + + **L121** Define the concrete work relation over existing rules and records. + + + **L122** Identify the exact key, target, inquiry and outcome being requested. + + + **L123** Require a registered principle and an actual record in the supplied lists. + + + **L124** Require the matching key and the contentful ValidApplication predicate. + + + **L125** Bind the record's inquiry and outcome to the requested ones. + + + **L127** State a conditional bridge from existing concrete reflexivity to the generic interface. + + + **L128** Assume concrete Reflexive satisfaction h; this is not established merely by the interface. + + + **L129** The conclusion maps all original rules and preserves the owner's self-target predicate. + + + **L130** Use actual original records through legacyPerformed; begin the proof. + + + **L131** Separate registry coherence from the per-target work obligation. + + + **L132** Take two mapped rules with memberships and an equal-key premise. + + + **L133** Recover the first original rule a from its mapped membership. + + + **L134** Recover the second original rule b likewise. + + + **L135** Use original registry coherence to identify a and b, then map that equality. + + + **L136** Introduce a listed rule, its self-target and its actual applicability proof. + + + **L137** Recover the original principle underlying the mapped rule. + + + **L138** Apply assumed concrete reflexivity h to obtain a recorded valid application at this target. + + + **L139** Choose that record's outcome and preserve its key, membership and inquiry identity. + + + **L140** Expose the original principle's meaning on its own inquiry and target-specific reasons. + + + **L141** Retain the limits of that same target and this record's outcome. + + + **L142** Derive that the inquiry's embedded target is the target actually being assessed. + + + **L143** Rewrite the embedded target using that identity. + + + **L144** Rewrite inquiry, reasons and limits back to the exact recorded fields. + + + **L145** Finish with the record's already supplied followsMeaning proof. + + + **L147** The specification comment limits fulfillment to the named mathematical adapters. + + + **L148** It asserts neither universal empirical adequacy nor a complete taxonomy. + + + **L149** Begin source-tracing metadata for CoreReader.Adopted.empiricalSpecification; this mapping is not a proof premise. + + + **L150** Record source clause organon.grounds.assessment#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L151** Close the preceding source-mapping comment without adding a logical condition. + + + **L152** Define the empirical obligation with explicit original observations. + + + **L153** Keep its scope, asserted claim and uncertainty predicate as separate inputs. + + + **L154** Require canonical Grounds for the given empirical candidate facet. + + + **L155** Fix the original task to these same records, scope, claim and uncertainty. + + + **L157** Begin source-tracing metadata for CoreReader.Adopted.inferentialSpecification; this mapping is not a proof premise. + + + **L158** Record source clause organon.grounds.assessment#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L159** Record source clause organon.relationships.roles#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L160** Close the preceding source-mapping comment without adding a logical condition. + + + **L161** Define inference satisfaction relative to explicit original assumptions and claim. + + + **L162** Require the inference facet to fulfill the task with those same original assumptions. + + + **L164** Begin source-tracing metadata for CoreReader.Adopted.valueSpecification; this mapping is not a proof premise. + + + **L165** Record source clause organon.grounds.assessment#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L166** Record source clause organon.grounds.assessment#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L167** Close the preceding source-mapping comment without adding a logical condition. + + + **L168** Define value satisfaction for the complete supplied position. + + + **L169** Require Grounds for its commitment under that very value-position task. + + + **L171** Explain that comparison scope and method roles concern a particular claim. + + + **L172** Only a method actually used incurs the represented role-explanation duty. + + + **L173** The relevance relation does not require a universal numerical scale. + + + **L174** Introduce three represented method kinds: measurement, repetition and framework. + + + **L175** Derive decidable equality for this finite method type. + + + **L176** Package the claim-specific comparison and method-role account over W. + + + **L177** Store the claim being assessed. + + + **L178** Store relevant conditions independently of observation scope. + + + **L179** Store which worlds or inputs are included in observation scope. + + + **L180** Store contextual relevance between compared objects. + + + **L181** Store which object pairs are actually compared. + + + **L182** Store which assessment methods are actually used. + + + **L183** Assign a stated role text to each method. + + + **L184** Store the semantic relation connecting a method and its role text to the claim and conditions. + + + **L186** Begin source-tracing metadata for CoreReader.Adopted.scopeSpecification; this mapping is not a proof premise. + + + **L187** Record source clause organon.grounds.scope#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L188** Record source clause organon.grounds.scope#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L189** Record source clause organon.grounds.scope#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L190** Close the preceding source-mapping comment without adding a logical condition. + + + **L191** Define scope satisfaction for a supplied comparison account. + + + **L192** Every actual compared pair must satisfy the account's conditions on both sides. + + + **L193** Both sides must also lie in scope and satisfy the stated relevance relation. + + + **L194** Every used method needs a nonempty role description. + + + **L195** That exact role must explain this method relative to this claim and its conditions. + + + **L197** Capability is modeled by an application-selected contract for one exact process. + + + **L198** Requiring an explanation certificate remains an application decision. + + + **L199** Begin source-tracing metadata for CoreReader.Adopted.capabilitySpecification; this mapping is not a proof premise. + + + **L200** Record source clause organon.grounds.capabilities#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L201** Record source clause organon.grounds.capabilities#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L202** Record source clause organon.relationships.roles#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L203** Record source clause organon.relationships.roles#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L204** Close the preceding source-mapping comment without adding a logical condition. + + + **L205** Define a capability obligation for the assessed process and selected contract. + + + **L206** Require Grounds for the exact process-contract facet. + + + **L207** The original inferential task fixes the process-identity assumptions and that contract. + + + **L209** Begin source-tracing metadata for CoreReader.Adopted.choiceSpecification; this mapping is not a proof premise. + + + **L210** Record source clause organon.grounds.implementations#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L211** Record source clause organon.grounds.implementations#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L212** Record source clause organon.grounds.implementations.limits#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L213** Record source clause organon.relationships.roles#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L214** Close the preceding source-mapping comment without adding a logical condition. + + + **L215** Define choice satisfaction for actual requirements and implementation. + + + **L216** The reasons must satisfy the helper's feasibility and relevant-content conditions. + + + **L218** The comment identifies a collaborator as the source of the additional operation. + + + **L219** Without that resource, the transition retains the initial operation content. + + + **L220** Define the collaboration-dependent state revision. + + + **L221** Return extendedState when a collaborator exists, otherwise baseState. + + + **L223** Prove actual collaborative expansion can coexist with failure of unaided execution. + + + **L224** The open policy satisfies the represented generation commitment. + + + **L225** The available collaborator yields a newly constructed or understood operation. + + + **L226** Removing that same collaborator removes the represented expansion. + + + **L227** With no experience, knowledge or collaborator, assisted execution returns no result. + + + **L228** Supply the policy proof and unaided failure by evaluation, leaving both transition claims. + + + **L229** Choose successor as the newly constructed operation in the extended state. + + + **L230** Verify that successor was absent from the base state. + + + **L231** Expand the no-collaborator branch and show unchanged content cannot count as expansion. + + + **L233** The comment separates current consistency from old incompatible judgments. + + + **L234** Semantic context changes and presentation ordering have different roles. + + + **L235** Begin source-tracing metadata for CoreReader.Adopted.consistencyConsequences; this mapping is not a proof premise. + + + **L236** Record source clause organon.charter.consistency#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L237** Record source clause organon.charter.consistency.meaning#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L238** Record source clause organon.charter.consistency.meaning#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L239** Record source clause organon.charter.consistency.limits#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L240** Close the preceding source-mapping comment without adding a logical condition. + + + **L241** State a conditional inconsistency theorem for one theory, context and question. + + + **L242** Assume positive and negative consequences of that same question in that same context. + + + **L243** Those two premises directly violate Consistent; no factual correctness is inferred. + + + **L245** Use Boolean worlds, the on-question, no extra assumptions and unrestricted scope. + + + **L247** Prove each revision slice consistent while the old/new union is inconsistent. + + + **L248** Quantify consistency over every current time slice. + + + **L249** Reject simultaneous retention of the opposing slices zero and one. + + + **L250** Prove individual-slice consistency and union inconsistency separately. + + + **L251** Fix an arbitrary time for the positive branch. + + + **L252** Use an actual admissible world to establish consistency. + + + **L253** Choose the Boolean time==0; it models the slice, empty assumptions and unrestricted scope. + + + **L254** Reduce union inconsistency to opposite consequences of the on-question. + + + **L255** Take an arbitrary admissible world for the positive consequence. + + + **L256** Expose the required positive meaning as w=true. + + + **L257** Read w=true from the zero-time component of the union's model. + + + **L258** For the negative consequence, additionally assume the world is on. + + + **L259** Read w=false from the one-time component of the same union model. + + + **L260** Compose the equalities to contradict true=false. + + + **L262** Prove explicit consistent examples with false assumptions or an undecided question. + + + **L263** The singleton on-theory is consistent in the broad context. + + + **L264** Deny that actual false models the theory whose sole claim is world=true. + + + **L265** The empty held theory is also consistent in that context. + + + **L266** The inhabited empty theory does not entail the positive true-world answer. + + + **L267** Reuse the checked false-world and non-entailment results, leaving consistency witnesses. + + + **L268** For the on-theory choose the true world as its model. + + + **L269** Its additional assumptions are empty and its scope is unrestricted. + + + **L270** For the empty theory again choose true; no held premises must be checked. + + + **L271** The empty contextual assumptions and unrestricted scope complete admissibility. + + + **L273** The comment distinguishes support at input zero from stronger assertions. + + + **L274** Neither all-input truth nor an extra input-one conjunct follows from that record. + + + **L275** Define the empirical facet asserting output true only at input zero. + + + **L276** Use zeroRecord, unrestricted world scope, the local claim and trivial uncertainty. + + + **L277** Define the stronger all-input empirical assertion with the same record. + + + **L278** The claim is allTrue; neither scope nor uncertainty adds evidence. + + + **L279** Define the strengthened two-output empirical assertion. + + + **L280** Require both f0=true and f1=true from the unchanged input-zero record. + + + **L282** Prove the local empirical facet discharged in its represented scope. + + + **L283** Give localGenerator0 as a real evidence-compatible world in scope. + + + **L284** Compatibility yields its observed zero output; the uncertainty predicate is True. + + + **L286** Bundle local support with failures of global scope and stronger claim content. + + + **L287** The local claim fulfills its explicitly declared local task. + + + **L288** The global candidate is nevertheless clearly articulated. + + + **L289** The all-input task fails Grounds despite that articulation. + + + **L290** The two-output task also fails with the same records. + + + **L291** Reuse checked local support and begin verifying the global articulation fields. + + + **L292** Show its reasons are identifiable; leave both substantive failures to prove. + + + **L293** Assume global Grounds in order to refute it. + + + **L294** Extract the global facet's required discharge from that hypothesis. + + + **L295** Apply its supposed support to localGenerator0 at input one, where the output is false. + + + **L296** Eliminate the resulting impossible Boolean equality. + + + **L297** Assume Grounds for the stronger two-output claim, for contradiction. + + + **L298** Extract that candidate's empirical discharge obligation. + + + **L299** Its second conjunct wrongly requires localGenerator0's input-one output to be true. + + + **L300** Contradict the actual false output. + + + **L302** The comment permits one observed result while another observable remains unknown. + + + **L303** Uncertainty here is a set of possible worlds, not a probability distribution. + + + **L304** Define an uncertain empirical facet over pairs of Booleans. + + + **L305** Use repeated first-coordinate observations without restricting worlds further. + + + **L306** Assert the first coordinate true while allowing either value of the second. + + + **L308** Prove this limited empirical assertion and both remaining possibilities. + + + **L309** The empirical task uses the same repeated temperature records. + + + **L310** The claim fixes only coordinate one; uncertainty explicitly allows coordinate two to vary. + + + **L311** The true/true world matches the repeated records. + + + **L312** The true/false world matches them as well. + + + **L313** Use canonical singleton Grounds and provide both compatible worlds. + + + **L314** Choose true/false as the nonempty empirical witness and separate the support duties. + + + **L315** Read the actual first-coordinate observation from the record membership. + + + **L316** Exhaust the two second-coordinate values to prove the stated uncertainty range. + + + **L318** The comment separates accurate negative examination from supported positive assertion. + + + **L319** The countervaluation must satisfy the same original premises. + + + **L320** Define an examination report for explicit premises and conclusion. + + + **L321** A report accepts exactly when the original premises entail the conclusion; this defines accuracy, not a positive result. + + + **L323** Prove a valid arithmetic inference alongside an accurate negative Boolean examination. + + + **L324** From the stated assumption n=2 the scoped inference establishes n+1=3. + + + **L325** The empty Boolean theory accurately receives a negative report for the on-claim. + + + **L326** The false world satisfies the same empty premises while falsifying that conclusion. + + + **L327** Use checked arithmetic discharge and the concrete counterworld, leaving report accuracy. + + + **L328** Prove both directions of the report's equivalence with entailment. + + + **L329** A false report equaling true is impossible. + + + **L330** Supposed entailment contradicts the already checked empty-theory countervaluation. + + + **L332** The comment identifies relevant criticism as an actual responsibility. + + + **L333** Unchanged budget reasons and adoption do not excuse closing the response. + + + **L334** Keep switchPosition unchanged except that every response becomes none. + + + **L336** Prove that the response-free position fails the represented value procedure. + + + **L337** Assume that value procedure for contradiction. + + + **L338** Apply its response duty to the actually relevant false-world criticism. + + + **L339** The required some answer contradicts the defined none response. + + + **L341** State fulfillment of the fixed switch value-position task. + + + **L342** Use the checked switch value procedure in the canonical singleton helper. + + + **L344** The comment compares claim strength through logical implication. + + + **L345** No common numerical conversion of value and other reasons is required. + + + **L346** Define weaker as holding in every world in which stronger holds. + + + **L348** Prove the asymmetric implication ordering while retaining a reasoned value task. + + + **L349** Truth at every input implies truth at input zero. + + + **L350** Truth at zero does not imply truth at every input. + + + **L351** The switch value task remains independently fulfilled. + + + **L352** Specialize universal truth to zero and reuse value fulfillment; leave the converse to refute. + + + **L353** Assume the stronger all-input claim follows from the local one. + + + **L354** Apply that assumption to localGenerator0 and test input one. + + + **L355** The false input-one output contradicts the supposed implication. + + + **L357** Assign concrete explanatory text to each represented assessment method. + + + **L358** Measurement identifies the output at the observed input zero. + + + **L359** Repetition checks the same local conclusion against repeated zero-input records. + + + **L360** The framework separates the declared input from broader unsupported claims. + + + **L362** Give each stated method role a proposition describing its actual contribution. + + + **L363** Measurement's contribution is support for the observed zero output. + + + **L364** Repetition's contribution is support for that same output from duplicate records. + + + **L365** The framework records that those local observations do not support allTrue. + + + **L367** Instantiate a complete local scope account over natural-number inputs. + + + **L368** The account concerns whether localGenerator0 succeeds at the input. + + + **L369** There are no additional input conditions. + + + **L370** Only input zero belongs to the observation scope. + + + **L371** The represented relevance relation requires equal inputs. + + + **L372** Actual comparison occurs only when both inputs equal zero. + + + **L373** All three represented methods are used in this particular example. + + + **L374** Use the previously specified method-role text. + + + **L375** Define what counts as an explanation for this account. + + + **L376** Require the exact role text and the exact local-generator claim. + + + **L377** Also require the actual conditions and the method's substantive contribution. + + + **L379** Prove that the instantiated scope account fulfills its stated duties. + + + **L380** Separate pair-comparison validity from used-method explanations. + + + **L381** Take any pair that the account says is compared. + + + **L382** Use both zero identities to establish conditions, scope and equal-input relevance. + + + **L383** Fix an arbitrary method used by this account. + + + **L384** Supply exact role/claim/condition identities, leaving nonempty text and semantic contribution. + + + **L385** Check each of the three literal role texts is nonempty. + + + **L386** Split the substantive contribution by method kind. + + + **L387** Reuse the single observation's proved local support. + + + **L388** Read the zero record from repeated-record compatibility. + + + **L389** Reuse the same observation's proved failure to support allTrue. + + + **L391** Prove two distinct process-contract fulfillments and an external certificate without internal explanation. + + + **L392** The output-only process has Grounds for its output contract. + + + **L393** The explained process has Grounds for the stronger output-plus-explanation contract. + + + **L394** Exhibit an external certificate for the very output-only process. + + + **L395** Its assessor and assessed identifiers differ, and its output contract holds. + + + **L396** Nevertheless this process does not supply the explanation contract. + + + **L397** Use evaluated output correctness to discharge the exact process-scoped inference. + + + **L398** Reduce the explained process's Grounds to proving its stronger contract. + + + **L399** Choose the actual external certificate and its proved participant distinction. + + + **L400** Use its output proof and the established absence of an internal explanation. + + + **L401** Prove all outputs by evaluation and supply the faithful doubleInput certificate. + + + **L403** The application asks this assessed object to predict the behavior of a multiplier mechanism. + + + **L404** The questions vary both inputs and multiplier values, giving an operational understanding task. + + + **L405** The criterion belongs to this application and does not define psychological understanding in general. + + + **L406** Original outputs and their faithful explanation do not by themselves supply answers to the extra questions. + + + **L407** Define an application object containing its process and its responses to mechanism variations. + + + **L408** The process field contains the object's original output function and explanation response. + + + **L409** The answer function takes a multiplier and an input and returns the object's predicted natural-number output. + + + **L411** Define the mechanism's predicted result as the product of the multiplier and input. + + + **L413** Define this application's stronger understanding contract for one assessed object. + + + **L414** Require the same object's original process to satisfy both output correctness and faithful explanation. + + + **L415** Require every original output to agree with the multiplier mechanism at its original multiplier of two. + + + **L416** Require correct mechanism answers for every natural-number multiplier and input, including changed values. + + + **L418** Define an object with a faithful explanation but a response that ignores multiplier changes. + + + **L419** Use explainedProcess while always answering twice the input regardless of the requested multiplier. + + + **L421** Define the object that answers mechanism-variation questions using the multiplication rule. + + + **L422** Keep the same explainedProcess and supply mechanism012 as the actual answer function. + + + **L424** Fix the assessment task using this application object and its stronger contract. + + + **L425** Object identity restricts scope; it does not assume the contract that the positive proof must establish. + + + **L426** Define the inferential scope for a specified application object. + + + **L427** Its sole scope premise says that the candidate equals the assessed object. + + + **L429** Define the original understanding assessment task for the specified object. + + + **L430** The task uses exact object-identity assumptions and the stronger understanding claim. + + + **L432** Define the candidate inferential assessment facet for that same specified object. + + + **L433** The facet retains the original task's exact identity assumptions and understanding claim. + + + **L435** Prove that the mechanism responder actually satisfies the selected understanding contract. + + + **L436** Construct original output and explanation correctness and all variation answers by reduction, leaving the original multiplier agreement to prove. + + + **L437** Take an arbitrary input for the remaining original-mechanism agreement obligation. + + + **L438** Expand the concrete definitions and use two times an input equals its sum with itself. + + + **L440** State the failure theorem for the object that ignores multiplier variation. + + + **L441** The conclusion denies the stronger understanding contract for that concrete object. + + + **L442** Assume the stronger contract temporarily to derive a contradiction. + + + **L443** Specialize its required variation correctness to multiplier three and input one. + + + **L444** Compute the object's answer and mechanism result, turning the assumed equality into two equals three. + + + **L445** Eliminate the impossible equality of these distinct natural numbers. + + + **L447** Bundle the concrete positive and negative understanding cases together with their object-scoped Grounds results. + + + **L448** Both application objects contain exactly the same original process, so their outputs and explanation are identical. + + + **L449** The object with wrong variation answers still satisfies the original output-and-explanation contract. + + + **L450** That object fails the stronger application understanding task. + + + **L451** The mechanism responder satisfies that stronger task. + + + **L452** Assert Grounds for the exact stronger understanding claim using canonical articulation. + + + **L453** The positive facet and the fixed original task both identify the mechanism responder. + + + **L454** Deny Grounds for the same stronger understanding claim in the negative object case. + + + **L455** The negative assessment retains that object's own fixed task and identity scope, then begins the bundled proof. + + + **L456** Construct identical-process and faithful original-contract evidence directly from the shared concrete process. + + + **L457** Use the proved failure and success of the two understanding tasks, leaving their Grounds claims to prove. + + + **L458** Apply the singleton Grounds helper to the positive facet; its declared task is exactly the fixed understanding task here. + + + **L459** Use the responder itself as a model of its identity assumptions, then leave the semantic consequence to prove. + + + **L460** Take an arbitrary candidate satisfying the fixed identity assumptions. + + + **L461** Extract equality with the assessed responder from the singleton scope model. + + + **L462** Replace the candidate with that very responder using the proved identity. + + + **L463** Supply the already established concrete stronger contract, rather than assuming it in the scope. + + + **L464** Assume Grounds for the negative object temporarily to derive a contradiction. + + + **L465** Extract discharge of the actual negative object's singleton facet from the assumed Grounds. + + + **L466** Apply the proved failure of the stronger understanding task for this object. + + + **L467** The supposed entailment applied to this same object's identity model would prove the failed contract, giving the contradiction. + + + **L469** Self-assertion retains the same exact application contract. + + + **L470** Changing the reason-provider does not change the object being asserted about. + + + **L471** Define own-capability duty for owner, claimant, process and contract. + + + **L472** Require identical owner/claimant identities and the ordinary scoped capability duty. + + + **L474** Prove owner 7 can assert its own output-only contract with these Grounds. + + + **L475** Combine identity equality with the already checked output capability. + + + **L477** The complete represented Charter contains generation and whole-theory consistency. + + + **L478** It also contains truthful reporting and applicable contentful self-work. + + + **L479** These duties share one system over a finite Candidate×Mode world type. + + + **L480** Define the complete represented Charter for a supplied integration system. + + + **L481** Evaluate its duties at one common finite world. + + + **L482** Require that system's own world-indexed policy to be generative. + + + **L483** Also require the coupled consistency/reporting specification. + + + **L484** Use the system's whole held theory and context as the before snapshot. + + + **L485** Use the identical after snapshot with a false change report; no change is hidden. + + + **L486** Apply the generic reflexivity specification to this same system's mapped rules and owner. + + + **L487** Use this system's actual rules and work records in the performed relation. + + + **L488** Require its method form to be among its current forms. + + + **L489** Require its principle form to be current as well. + + + **L491** Prove the concrete integration system satisfies this complete represented Charter. + + + **L492** Reuse the concrete system's checked generative policy. + + + **L493** Reuse its joint consistency, leaving truthful unchanged reporting. + + + **L494** Bridge actual completed self-work and verify the two current-form identities. + + + **L495** Split any alleged change into semantic change or revision-identity change. + + + **L496** The identical snapshots have equal held theory, assumptions, meanings and scope, contradicting semantic change. + + + **L497** The identical revision identifiers contradict the other change alternative. + + + **L499** Prove complete Charter fulfillment does not entail this concrete unsupported Grounds task. + + + **L500** The very concrete system/world fulfills every represented Charter component. + + + **L501** It also supplies an actual admissible world for the held theory and context. + + + **L502** The concrete cost-allowance record is true in that world. + + + **L503** The proposed capability facet has identifiable canonical articulation. + + + **L504** That true cost record cannot support the actual output capability. + + + **L505** Consequently the same capability fails Grounds with these proposed grounds. + + + **L506** The candidate list contains the identified unsupported capability facet. + + + **L507** Its original task retains that facet's empirical claim and support context. + + + **L508** Reuse the complete Charter proof and the common admissible world. + + + **L509** Check the singleton cost record directly against this actual world. + + + **L510** Unfold the facet's canonical articulation to verify its concepts. + + + **L511** Also verify its nonempty identifiable reasons. + + + **L512** Reuse the substantive cost/output countermodel; leave full Grounds rejection. + + + **L513** Assume this task satisfies Grounds, for contradiction. + + + **L514** Extract the required empirical discharge for that very capability facet. + + + **L515** It would imply the disproved cost-to-output support relation in the same scope. + + + **L517** Permission must refer to the same claim, articulation and facets. + + + **L518** Insufficiency comes from an actual outside-observation failure. + + + **L519** Define a permission policy with an explicit enable flag and claim. + + + **L520** Retain the actual articulation, candidate facets and original task in the policy inputs. + + + **L521** Enabled permission requires Grounds; disabling it permits every package. + + + **L523** Define whether the permission policy enforces represented Grounds obligations. + + + **L524** Quantify over all claims, articulations, candidate lists and original tasks in this world type. + + + **L525** Require every permitted package to satisfy Grounds for that same original task. + + + **L527** Prove this enforcing-policy property holds exactly in enabled mode. + + + **L528** Consider the two enable-flag values. + + + **L529** Enabled permission is Grounds itself, so the implication returns its premise. + + + **L530** Handle the disabled mode, which allows unsupported packages. + + + **L531** Prove each direction of the proposed equivalence in that mode. + + + **L532** Assume disabled permission nevertheless enforces all Grounds duties. + + + **L533** Apply it to the concrete unsupported global task, contradicting scopeStrength012. + + + **L534** The converse premise false=true is impossible. + + + **L536** The value rationale concerns one fixed empirical assertion task. + + + **L537** Its records and actual counterworld remain identical across modes. + + + **L538** Only the permission policy changes between enabled and disabled modes. + + + **L539** Declare the original empirical task used by the policy comparison. + + + **L540** It asserts allTrue from the input-zero record with unrestricted scope and trivial uncertainty. + + + **L542** Define a noncomputable logical decision of actual task permission, not a runtime experiment. + + + **L543** Ask whether this exact allTrue claim and global candidate are permitted. + + + **L544** Keep the fixed original task and use classical propositional decidability. + + + **L546** Define the value position about that actual task-permission policy. + + + **L547** The alternatives are enabling or disabling the policy. + + + **L548** The outcome is the Boolean permission decision. + + + **L549** Explicitly adopt the enabled alternative; no factual derivation of adoption is asserted. + + + **L550** The represented world itself identifies the selected alternative. + + + **L551** Evaluate the actual fixed-task permission for that alternative. + + + **L552** The stated objective is rejection of the unsupported assertion. + + + **L553** Also require that the chosen policy enforces the represented Grounds provision. + + + **L554** The starting assumption explicitly records adoption of enabled mode. + + + **L555** The reason is a concrete record-compatible program that falsifies allTrue, not enabled=true. + + + **L556** The represented value position has unrestricted world scope. + + + **L557** The actual lack of allTrue support is a relevant criticism. + + + **L558** Provide a nonempty response retaining local support and rejecting overreach. + + + **L560** Prove the finite value procedure for this concrete permission rationale. + + + **L561** Verify nonempty reasons and separate joint adoption, consequences and criticism response. + + + **L562** Choose the enabled world, satisfying its starts, scope and adopted selection. + + + **L563** Take an arbitrary member of the position's reason list. + + + **L564** Identify it with the singleton concrete counterworld reason. + + + **L565** Supply record compatibility and leave falsity of the global claim. + + + **L566** At input one the program outputs false, refuting allTrue. + + + **L567** For the consequence branch assume the supplied reason facts at the current world. + + + **L568** Extract the actual counterworld fact from those passed reasons. + + + **L569** Expose its two contents: record compatibility and failure of allTrue. + + + **L570** Derive lack of Grounds for the same fixed original global task. + + + **L571** Assume that exact Grounds package for contradiction. + + + **L572** Extract its empirical discharge for globalFacet012. + + + **L573** Use the passed counterworld's compatibility to contradict its passed global falsity. + + + **L574** Separate actual rejection from enabled enforcement of the general provision. + + + **L575** Turn the derived lack of permission into a false logical decision. + + + **L576** The decision still concerns the same original task; classical decidability adds no empirical test. + + + **L577** Supply the fixed nonempty response for any relevant criticism in scope. + + + **L579** Prove the finite permission-policy comparison retains actual counterexample content. + + + **L580** The same program matches the observed record and fails the global claim. + + + **L581** Enabled permission rejects that task; disabled permission accepts it. + + + **L582** The value position's enabled outcome is the actual enabled permission decision. + + + **L583** Its disabled outcome likewise is the actual disabled permission decision. + + + **L584** Provide compatibility and outcome identities, leaving falsity and both decisions. + + + **L585** Refute allTrue by the actual failure at input one. + + + **L586** Construct every required reason explicitly at the enabled world. + + + **L587** Take a reason together with its membership proof. + + + **L588** Identify it with the actual singleton counterworld reason. + + + **L589** Supply its observed-record compatibility. + + + **L590** Supply its actual allTrue counterexample at input one. + + + **L591** Apply the checked value procedure with those actual reasons and extract its rejection consequence. + + + **L592** For disabled mode, the permission proposition is True. + + + **L593** Convert that trivial permission for the unchanged task into a true decision. + + + **L595** Prove a scoped value-based Grounds assessment of the represented Grounds provision itself. + + + **L596** The assessed claim is enforcement of Grounds, with the exact groundsPosition012 value task. + + + **L597** The adopted world lies in scope and has a live support-limit criticism. + + + **L598** Relate the position's adopted-selection claim to the enforcement proposition. + + + **L599** Compare these claim functions at an arbitrary enabled flag. + + + **L600** Use the proved equivalence of enforcement and enabled selection, via propositional extensionality. + + + **L601** Supply scope and actual criticism, leaving Grounds for the provision. + + + **L602** Rewrite the claim using the established exact function identity. + + + **L603** Apply singleton Grounds to the actually checked value procedure. + + + **L605** Prove concrete applicable self-target coverage without universalizing applicability. + + + **L606** The full registered own rules satisfy the generic reflexivity interface. + + + **L607** Their actual completed work supplies the performed applications. + + + **L608** Assessment records exist for formation, application and revision phases. + + + **L609** There is also an actual system-self assessment. + + + **L610** A narrower application-only rule separately satisfies generic reflexivity. + + + **L611** Its actual applicationWork is the source of performed work. + + + **L612** That narrower rule need not produce an inapplicable system assessment. + + + **L613** Bridge complete own-work reflexivity, leaving the phase quantifier. + + + **L614** Use the concrete system target's membership to obtain its assessment record. + + + **L615** Bridge the application-only example and retain the proved absent system work. + + + **L616** Fix an arbitrary formation/application/revision phase. + + + **L617** Reduce its required record to the existing ownAssessmentPerformed theorem. + + + **L618** Check the target list contains the process in each of the three phases. + + + **L620** Prove achievement support for the exact actual transition and reject support from mere reporting. + + + **L621** The transition's performance facet fulfills the exact achievement task it declares. + + + **L622** The extending transition matches the actual performance record. + + + **L623** Extension adds capability; inventory inflation does not. + + + **L624** A report alone fails to support the same transition-achievement claim. + + + **L625** Reuse the checked transition facet and report counterexample, leaving actual transition facts. + + + **L626** Use the equivalence between performance compatibility and the extend transition. + + + **L627** Expand the actual before/after states and verify the new operation in extension. + + + **L628** Expand inflation and verify that neither understood nor constructed operations grow. + + + **L630** State order independence for any two Boolean-world claims. + + + **L631** Each member belongs to one singleton union exactly when it belongs to the reversed union. + + + **L632** Apply the general representation-order theorem. + + + **L634** Define a clearly stated but possibly false argument about the switch. + + + **L635** Its concepts, sole on-assumption, on-reason and unrestricted limit are all explicit. + + + **L637** Prove clear articulation does not make that argument true in the actual off-world. + + + **L638** Its fields are identifiable, but the false world does not model its assumptions. + + + **L639** Check nonempty articulation and reuse the concrete false-assumption result. + + + **L641** Define a record whose test always returns true and says nothing about selection. + + + **L643** Prove a reasoned value commitment need not follow from neutral recorded facts. + + + **L644** The switch value task has its own fulfilled reasons and responsibilities. + + + **L645** The opposite selection false is compatible with the neutral record. + + + **L646** Thus those records do not establish adoption of the switch commitment. + + + **L647** Nor is that adoption entailed by an empty factual theory. + + + **L648** Construct the neutral record's actual false-selection counterworld. + + + **L649** The singleton constant-true test matches its recorded result by evaluation. + + + **L650** Reuse value fulfillment and no-selfproof, leaving the observation-support failure. + + + **L651** Assume that neutral record supports the adoption claim. + + + **L652** Apply it to the compatible opposite-selection world. + + + **L653** The claimed true selection conflicts with the actual false selection. + + + **L655** Keep identity implementation behavior and costs, but replace its explanation by successor. + + + **L657** Prove internal explanation fidelity distinguishes otherwise feasible equal-output implementations. + + + **L658** Both implementations return identical actual outputs at every input. + + + **L659** Both meet the same output and budget feasibility requirements. + + + **L660** The identity implementation's explanation is a relevant faithful reason. + + + **L661** The altered explanation fails that same relevance/content test. + + + **L662** Supply equal outputs, both feasibility proofs and the valid explanation reason. + + + **L663** Assume the altered explanation were a relevant faithful reason. + + + **L664** Specialize its required explanation/output equality to input zero. + + + **L665** Successor's one output contradicts identity's zero output. + + + **L667** Quantify the duplication example over every inventory category. + + + **L668** Two copies of a copy item still provide the copy operation. + + + **L669** They do not provide the distinct successor operation. + + + **L670** Fix any document, term, tool or artifact category. + + + **L671** Unfold actual item membership to check the operation content. + + + **L674** Define an assessment rule applicable to every natural-number target. + + + **L675** Give it key (0,1), universal applicability and the target itself as input. + + + **L676** Its outcome must equal actual evaluation of ownArithmeticPrinciple at that input. + + + **L677** Define the actual work relation for this deliberately self-exempt rule. + + + **L678** Work exists only for target one, with matching key/input and an evaluated arithmetic result. + + + **L680** Prove open revisability plus real work on another target does not satisfy self-application. + + + **L681** The policy values expansion and keeps the principle form revisable. + + + **L682** An actual assessment of target one returns true. + + + **L683** Nevertheless the same rule is applicable to self-target zero. + + + **L684** It fails reflexivity because that applicable self-target receives no work. + + + **L685** Supply actual policy/revisability and other-target work, leaving self-duty failure. + + + **L686** Assume reflexivity for this self-exempt relation. + + + **L687** Obtain its supposedly performed outcome at applicable self-target zero. + + + **L688** Performed requires target zero to equal one, a contradiction. + + + **L690** Prove the system's current philosophy method receives no status-only privilege. + + + **L691** Begin the status-only rejection under the actual proposal-review requirements. + + + **L692** Use exactly the same current philosophy implementation in this status-only negative branch. + + + **L693** The rejected reason list contains standing alone. + + + **L694** State the contrasting justified choice under the same proposal-review requirements. + + + **L695** Use exactly the same current philosophy implementation in the positive case. + + + **L696** Its actual output performance supplies the positive reason. + + + **L697** Reuse the checked status-only rejection for the actual current method. + + + **L698** Reuse its separate checked output-based justification. + + + **L700** Define one joint context over two Boolean coordinates. + + + **L701** Use no extra assumptions; the question asks whether coordinate two is true, at unrestricted scope. + + + **L703** Derive both question signs from the jointly held premises and prove inconsistency. + + + **L704** The joint theory implies the positive second-coordinate question. + + + **L705** It also implies that same question's negation in the same context. + + + **L706** Therefore it violates the defined consistency condition. + + + **L707** First derive the positive consequence from the actual combined premises. + + + **L708** Take an arbitrary admissible world for the whole joint theory. + + + **L709** Extract P→Q and P from the same held set and apply the former to the latter. + + + **L710** Then derive the negative consequence from the same theory. + + + **L711** Use the same whole-theory admissibility condition. + + + **L712** Read the held ¬Q premise through its exact nested-union membership. + + + **L713** Combine both signs and apply the general contradiction criterion; no explosion rule is used. + + + **L715** Define a numerical budget context for simultaneous-value tension. + + + **L716** The question is n≤6 with no extra assumptions and unrestricted scope. + + + **L718** Prove the two different budget demands are jointly consistent. + + + **L719** The whole held set requires 4≤n and n≤6 simultaneously. + + + **L720** Establish consistency by an explicit admissible allocation. + + + **L721** Choose five, satisfying the first budget demand in the union. + + + **L722** Also satisfy the second demand, empty assumptions and unrestricted scope. + + + **L724** Prove a qualitative inference without an observation method. + + + **L725** Under the explicit premise on=true, infer on≠false. + + + **L726** The actual inferential facet reports that it does not use observation. + + + **L727** Provide the true-world premise model and leave the required inference. + + + **L728** Take a premise-satisfying Boolean and suppose it equals false. + + + **L729** Read its equality to true from the singleton premise theory. + + + **L730** The two equalities would identify true with false. + + + **L733** Quantify status-only rejection over every represented status kind. + + + **L734** Neither name, convention nor standing alone justifies the identity implementation. + + + **L735** Apply the helper's all-kind status-only theorem to these exact requirements and implementation. + + + **L737** The comment states that both finite possible draws receive positive equal weights. + + + **L738** The model concerns possible varying outcomes and a stable bound. + + + **L739** It makes no empirical assertion about a physical randomness source. + + + **L740** Assign weight one to each Boolean draw. + + + **L741** Define the actual and recorded outcome for each draw. + + + **L742** Both draws use setting zero; true gives outcome one and false gives two, recorded accurately. + + + **L744** Prove the finite draws vary without losing setting reproducibility or their bound. + + + **L745** Both possible draw weights are positive. + + + **L746** The two weights are equal. + + + **L747** Both trials reproduce the same setting. + + + **L748** Their actual outcomes nevertheless differ. + + + **L749** For every draw the record is accurate and the actual outcome is at most two. + + + **L750** Evaluate positive weights, equality, settings and different outcomes; leave the universal verification/bound. + + + **L751** Fix an arbitrary draw. + + + **L752** Check both draws by unfolding actual records and bounds. + + + **L755** Original assessment tasks are declared before and independently of the proposed substitutions. + + + **L756** Define the fixed original all-input empirical task. + + + **L757** Its only observation is zeroRecord; its claim is allTrue. + + + **L758** Define the different original local empirical task. + + + **L759** With the same record it asserts only f0=true. + + + **L761** Define a circular but mathematically valid conditional inference: assume allTrue and conclude allTrue. + + + **L763** Prove that separately stated conditional inference is satisfiable and valid. + + + **L764** The constant-true function satisfies its allTrue assumption. + + + **L765** Take an arbitrary function modeling that singleton assumption. + + + **L766** Return the allTrue fact already present in the premise model. + + + **L768** Distinguish valid fulfillment of the new conditional task from an invalid substitution into the original empirical task. + + + **L769** The circular facet has Grounds for its own explicitly new conditional task. + + + **L770** It is not appropriate to the previously fixed global empirical task. + + + **L771** Thus it cannot fulfill that original task merely by sharing its conclusion. + + + **L772** First prove the candidate violates original-task appropriateness. + + + **L773** Assume appropriateness for contradiction. + + + **L774** Extract its demanded equality of original and candidate premise theories. + + + **L775** That equality would make allTrue a member of the observation-and-scope singleton theory. + + + **L776** Singleton membership then equates allTrue itself with mere record compatibility and scope. + + + **L777** Apply that false identification to localGenerator0, which really matches the original record. + + + **L778** The identification incorrectly yields true output at input one. + + + **L779** Contradict the actual false output. + + + **L780** Retain the valid separate conditional task and the proved inappropriateness. + + + **L781** Assume the candidate nonetheless fulfills original-task Grounds. + + + **L782** Extract its required appropriateness, contradicting the preceding counterexample. + + + **L784** Fix inference premises to exactly original zero-record compatibility and scope. + + + **L785** Define a candidate inference using those unchanged original premises. + + + **L786** Conclude only the actual zero-input observation. + + + **L788** Prove this observation-based inference satisfiable and valid. + + + **L789** Use localGenerator0 as a model of the original record/scope premises. + + + **L790** Take any function satisfying those exact premises. + + + **L791** Extract compatibility and hence the observed zero output. + + + **L793** Prove two assessment forms can fulfill one unchanged empirical task. + + + **L794** The original empirical facet fulfills the fixed local task. + + + **L795** The legitimate observation-based inference fulfills that very same task. + + + **L796** Reuse the original empirical proof and leave the alternative inference adapter. + + + **L797** Show the alternative candidate list nonempty and check its sole member. + + + **L798** Take any candidate in that list. + + + **L799** Identify it with the observation-based inference facet. + + + **L800** Supply exact conclusion and canonical articulation for the checked inference. + + + **L801** Retain original premises, conclusion and the original trivial uncertainty support. + + + **L803** The second coordinate is not observed by these records. + + + **L804** Changing to inference cannot erase that original uncertainty obligation. + + + **L805** Define an original task demanding more uncertainty support than the records provide. + + + **L806** Use repeated first-coordinate records with unrestricted scope. + + + **L807** Assert the first coordinate true but also demand that uncertainty establish the unobserved second as true. + + + **L808** Define an inference candidate that omits this extra uncertainty duty from its own discharge. + + + **L809** Its premises preserve the original record compatibility and scope. + + + **L810** Its conclusion asserts only coordinate one. + + + **L812** Prove that this candidate's conditional inference is itself valid. + + + **L813** The true/false world models the exact inference premises. + + + **L814** Take an arbitrary model of those premises. + + + **L815** Read the recorded first-coordinate result, establishing the local conclusion. + + + **L817** Prove that this valid inference cannot bypass the original uncertainty responsibility. + + + **L818** Retain the valid candidate's own discharge. + + + **L819** Reject its appropriateness to the full original uncertainty task. + + + **L820** Reject Grounds for this original first-coordinate assertion and its unchanged articulation. + + + **L821** The candidate must still be checked against the full original uncertainty task. + + + **L822** First establish substantive inappropriateness. + + + **L823** Assume the original uncertainty duty was retained and fulfilled. + + + **L824** Apply its required second-coordinate support to the record-compatible true/false world. + + + **L825** The false second coordinate contradicts that supposed support. + + + **L826** Combine valid conditional inference with its original-task inappropriateness. + + + **L827** Any claimed Grounds would supply precisely the disproved appropriateness. + + + **L829** Define an empirical observation of which value option was actually selected. + + + **L830** The switch record supports the selection fact, with trivial uncertainty. + + + **L832** Separate supported selection facts from fulfillment of the original value-reason task. + + + **L833** The empirical selection facet is discharged and the reasoned value position independently fulfills its task. + + + **L834** The empirical fact alone nevertheless cannot fulfill the fixed value-position task. + + + **L835** Reuse empirical and value proofs, leaving rejection of substitution. + + + **L836** Assume empirical facts fulfilled that original value task. + + + **L837** The required value-task/empirical-facet pairing is False in the finite adapter. + + + **L839** Prove that changing original inference assumptions also invalidates task substitution. + + + **L840** The conditional inference from on=true to itself is valid in its own right. + + + **L841** Reject Grounds for the original on-claim when the inference context has been substituted. + + + **L842** The proposed candidate assumes the conclusion itself as its premise. + + + **L843** The fixed original task instead contains an empty assumption theory. + + + **L844** Give the valid conditional its true-world model and return its own premise; leave substitution failure. + + + **L845** Assume original-task Grounds for the altered-premise candidate. + + + **L846** Extract appropriateness for the exact candidate in its singleton list. + + + **L847** It would equate the nonempty on-assumption singleton with the empty theory. + + + **L848** Transport singleton membership to obtain membership in the empty theory. + + + **L849** Such membership is False by definition, completing the contradiction. + + + **L852** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction. + + + **L853** Begin source-tracing metadata for CoreReader.Adopted.generationCases; this mapping is not a proof premise. + + + **L854** Record source clause organon.charter.overview#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L855** Record source clause organon.charter.overview#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L856** Record source clause organon.charter.self-transcendence#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L857** Record source clause organon.charter.self-transcendence.orientation#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L858** Record source clause organon.charter.self-transcendence.non-finality#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L859** Record source clause organon.charter.self-transcendence.limits#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L860** Record source clause organon.relationships.terms#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L861** Close the preceding source-mapping comment without adding a logical condition. + + + **L862** Bundle checked generative valuation, permission-only failure, justified stability and real collaboration cases. + + + **L863** The explicitly open policy satisfies Generative. + + + **L864** Additionally exposes revision permission for version zero of every form category. + + + **L865** Every adjacent pair in the constant trace lacks a newly understood or constructed operation. + + + **L866** States that neutralPolicy permits 0→1, the versions differ, and its missing valuation defeats Generative. + + + **L867** The concrete generating system's own policy satisfies Generative. + + + **L868** Its policy allows keeping version zero, so generativity does not require every action to change versions. + + + **L869** Inflating this system's inventory does not expand its represented capabilities. + + + **L870** The inflated state has strictly more inventory entries than this system's current state. + + + **L871** Its abstraction-layer count also strictly increases without capability expansion. + + + **L872** Its vocabulary count strictly increases under the same unchanged capability content. + + + **L873** With resources 1,2,3, this system's execution actually returns some 6. + + + **L874** Removing experience from that same resource bundle makes the system's execution fail. + + + **L875** Removing knowledge alone likewise makes its execution return none. + + + **L876** Removing the collaborator input alone also makes execution fail. + + + **L877** With all three external inputs absent, this same execution interface returns none. + + + **L878** The system's stable action yields no represented capability expansion. + + + **L879** That stable action is exactly retention of the system's current state. + + + **L880** Retention preserves the workload's required copy operation. + + + **L881** The retained one-item state fits this system's one-item application budget. + + + **L882** The duplicated inventory has two entries and exceeds this same system's one-item budget. + + + **L883** Stability has the stated reason: construction is unchanged, but only the current state fits the budget. + + + **L884** Identifies the report as this system's announcement about inflatedState, successor, input zero and output one. + + + **L885** The report's owner equals this generating system's owner. + + + **L886** The report uses this system's current state as baseline and inflatedState as result. + + + **L887** Confirms the alleged new operation is successor. + + + **L888** Confirms the announced test is input zero with expected output one. + + + **L889** States both that the announcement's substantive claim fails and that its own state pair has no expansion. + + + **L890** The open policy satisfies the represented generation commitment. + + + **L891** The available collaborator yields a newly constructed or understood operation. + + + **L892** Removing that same collaborator removes the represented expansion. + + + **L893** With no experience, knowledge or collaborator, assisted execution returns no result. + + + **L894** Assemble the four actual component proofs into the full stated conjunction; their names alone are not evidence. + + + **L896** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction. + + + **L897** Begin source-tracing metadata for CoreReader.Adopted.generationLimits012; this mapping is not a proof premise. + + + **L898** Record source clause organon.charter.self-transcendence.orientation#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L899** Record source clause organon.charter.self-transcendence.non-finality#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L900** Record source clause organon.charter.self-transcendence.limits#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L901** Record source clause organon.charter.self-transcendence.limits#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L902** Record source clause organon.relationships.roles#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L903** Close the preceding source-mapping comment without adding a logical condition. + + + **L904** Bundle generation's non-entailments: permission is not valuation, openness is not achievement, and content matters more than counts. + + + **L905** States that neutralPolicy permits 0→1, the versions differ, and its missing valuation defeats Generative. + + + **L906** The open policy itself fulfills the valuation-and-revisability condition. + + + **L907** Additionally exposes revision permission for version zero of every form category. + + + **L908** Every adjacent pair in the constant trace lacks a newly understood or constructed operation. + + + **L909** The system is generative even in the following non-progress examples. + + + **L910** Its policy allows keeping version zero, so generativity does not require every action to change versions. + + + **L911** Inflating this system's inventory does not expand its represented capabilities. + + + **L912** The inflated state has strictly more inventory entries than this system's current state. + + + **L913** Its abstraction-layer count also strictly increases without capability expansion. + + + **L914** Its vocabulary count strictly increases under the same unchanged capability content. + + + **L915** With resources 1,2,3, this system's execution actually returns some 6. + + + **L916** Removing experience from that same resource bundle makes the system's execution fail. + + + **L917** Removing knowledge alone likewise makes its execution return none. + + + **L918** Removing the collaborator input alone also makes execution fail. + + + **L919** With all three external inputs absent, this same execution interface returns none. + + + **L920** The system's stable action yields no represented capability expansion. + + + **L921** That stable action is exactly retention of the system's current state. + + + **L922** Retention preserves the workload's required copy operation. + + + **L923** The retained one-item state fits this system's one-item application budget. + + + **L924** The duplicated inventory has two entries and exceeds this same system's one-item budget. + + + **L925** Stability has the stated reason: construction is unchanged, but only the current state fits the budget. + + + **L926** Identifies the report as this system's announcement about inflatedState, successor, input zero and output one. + + + **L927** The report's owner equals this generating system's owner. + + + **L928** The report uses this system's current state as baseline and inflatedState as result. + + + **L929** Confirms the alleged new operation is successor. + + + **L930** Confirms the announced test is input zero with expected output one. + + + **L931** States both that the announcement's substantive claim fails and that its own state pair has no expansion. + + + **L932** The open policy satisfies the represented generation commitment. + + + **L933** The available collaborator yields a newly constructed or understood operation. + + + **L934** Removing that same collaborator removes the represented expansion. + + + **L935** With no experience, knowledge or collaborator, assisted execution returns no result. + + + **L936** The transition's performance facet fulfills the exact achievement task it declares. + + + **L937** Require extend to satisfy the actual performance observation. + + + **L938** Extension adds capability; inventory inflation does not. + + + **L939** Conclude that the positive report records therefore do not support the achievement over all compatible transitions. + + + **L940** Quantify the inventory-content result over every represented item category. + + + **L941** Two copies of a copy item still provide the copy operation. + + + **L942** They do not provide the distinct successor operation. + + + **L943** Combine six proofs, including actual collaborative progress, same-transition support and all-category duplication limits. + + + **L945** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction. + + + **L946** Begin source-tracing metadata for CoreReader.Adopted.consistencyCases; this mapping is not a proof premise. + + + **L947** Record source clause organon.charter.consistency#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L948** Record source clause organon.charter.consistency.meaning#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L949** Record source clause organon.charter.consistency.meaning#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L950** Record source clause organon.charter.consistency.limits#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L951** Close the preceding source-mapping comment without adding a logical condition. + + + **L952** Bundle whole-set conflict, context distinctions, honest reporting, withdrawal and presentation-order cases. + + + **L953** The first two conclusions provide separate models for P and its implication rule. + + + **L954** Also require a separate model for not Q, but deny any model of the entire joint theory. + + + **L955** Require a positive answer under true-valued assumptions. + + + **L956** Require the negative answer under false-valued assumptions; the contexts differ. + + + **L957** Require a positive answer for the question meaning equality to true. + + + **L958** Require the negative answer when that question instead means equality to false. + + + **L959** Require the positive answer in the scope restricted to true. + + + **L960** Require the negative answer in the different scope restricted to false. + + + **L961** For either assumption selector, require an actual admissible world. + + + **L962** For either question meaning, require an actual admissible world. + + + **L963** For either scope selector, the conclusion includes an actual admissible world. + + + **L964** Reject a false report when actual contextual assumptions change from true to false. + + + **L965** Reject a false report when the question’s actual meaning changes. + + + **L966** Reject a false report when the actual application scope changes. + + + **L967** Reject a false report when revision identity changes from 0 to 1 despite unchanged context. + + + **L968** Permit truthful acknowledgement of the changed assumptions with a true report. + + + **L969** Nevertheless deny that those revised false-world assumptions hold at actual true. + + + **L970** Require time slices 0 and 1 to have separate model witnesses. + + + **L971** Deny a model of their simultaneous union; this does not deny either separate witness. + + + **L972** Quantify consistency over every current time slice. + + + **L973** Reject simultaneous retention of the opposing slices zero and one. + + + **L974** The ordering claim applies to arbitrary Boolean-world claims p and q. + + + **L975** Each member belongs to one singleton union exactly when it belongs to the reversed union. + + + **L976** The joint theory implies the positive second-coordinate question. + + + **L977** It also implies that same question's negation in the same context. + + + **L978** Therefore it violates the defined consistency condition. + + + **L979** Combine the seven checked components, retaining joint-implication conflict and separate-time consistency. + + + **L981** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction. + + + **L982** Begin source-tracing metadata for CoreReader.Adopted.consistencyLimits012; this mapping is not a proof premise. + + + **L983** Record source clause organon.charter.consistency.meaning#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L984** Record source clause organon.charter.consistency.limits#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L985** Record source clause organon.relationships.roles#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L986** Close the preceding source-mapping comment without adding a logical condition. + + + **L987** Bundle consistency limits with actual context models, budget tension, false assumptions and lack of entailment. + + + **L988** Require a positive answer under true-valued assumptions. + + + **L989** Require the negative answer under false-valued assumptions; the contexts differ. + + + **L990** Require a positive answer for the question meaning equality to true. + + + **L991** Require the negative answer when that question instead means equality to false. + + + **L992** Require the positive answer in the scope restricted to true. + + + **L993** Require the negative answer in the different scope restricted to false. + + + **L994** For either assumption selector, require an actual admissible world. + + + **L995** For either question meaning, require an actual admissible world. + + + **L996** For either scope selector, the conclusion includes an actual admissible world. + + + **L997** Ask for a natural-number budget satisfying both lower bound 4 and upper bound 6. + + + **L998** Also assert that the two bound predicates are not identical, even though jointly satisfiable. + + + **L999** The singleton on-theory is consistent in the broad context. + + + **L1000** Deny that actual false models the theory whose sole claim is world=true. + + + **L1001** The empty held theory is also consistent in that context. + + + **L1002** The inhabited empty theory does not entail the positive true-world answer. + + + **L1003** Require a model where emptyTheory and the positive singleton claim hold together. + + + **L1004** The inhabited empty theory does not entail the positive true-world answer. + + + **L1005** The whole held set requires 4≤n and n≤6 simultaneously. + + + **L1006** Use all five component proofs; the last supplies a genuinely shared consistent allocation for both demands. + + + **L1008** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction. + + + **L1009** Begin source-tracing metadata for CoreReader.Adopted.reflexivityCases012; this mapping is not a proof premise. + + + **L1010** Record source clause organon.charter.reflexivity#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1011** Record source clause organon.charter.reflexivity.meaning#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1012** Record source clause organon.charter.reflexivity.limits#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1013** Record source clause organon.relationships.roles#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1014** Close the preceding source-mapping comment without adding a logical condition. + + + **L1015** Bundle applicable self-target work, Grounds self-assessment and its actual permission consequence. + + + **L1016** The full registered own rules satisfy the generic reflexivity interface. + + + **L1017** Their actual completed work supplies the performed applications. + + + **L1018** Assessment records exist for formation, application and revision phases. + + + **L1019** There is also an actual system-self assessment. + + + **L1020** A narrower application-only rule separately satisfies generic reflexivity. + + + **L1021** Its actual applicationWork is the source of performed work. + + + **L1022** Yet that same log contains no assessment of the system itself, where this rule is not applicable. + + + **L1023** The assessed claim is enforcement of Grounds, with the exact groundsPosition012 value task. + + + **L1024** The adopted world lies in scope and has a live support-limit criticism. + + + **L1025** The same program matches the observed record and fails the global claim. + + + **L1026** Enabled permission rejects that task; disabled permission accepts it. + + + **L1027** The value position's enabled outcome is the actual enabled permission decision. + + + **L1028** Its disabled outcome likewise is the actual disabled permission decision. + + + **L1029** Combine actual records with the checked value procedure and same-task enabled/disabled permission comparison. + + + **L1031** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction. + + + **L1032** Begin source-tracing metadata for CoreReader.Adopted.reflexivityLimits012; this mapping is not a proof premise. + + + **L1033** Record source clause organon.charter.reflexivity.limits#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1034** Record source clause organon.relationships.roles#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1035** Record source clause organon.relationships.roles#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1036** Record source clause organon.grounds#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1037** Close the preceding source-mapping comment without adding a logical condition. + + + **L1038** Bundle concrete failures of self-proof, self-origin support and self-exempt openness, including full Charter without the selected Grounds. + + + **L1039** The same arithmetic principle passes sample 1 but evaluates false at 0. + + + **L1040** Therefore that principle does not return true for every natural-number input. + + + **L1041** Compute localGenerator 0 as true at 0 and false at 1. + + + **L1042** Require this generated function to match the same input-0 record. + + + **L1043** State failure of all-input support and include the concrete owner/prior/revision relationship example. + + + **L1044** Combines a generative openPolicy with failure of owned reflexivity when the work log is empty. + + + **L1045** The very concrete system/world fulfills every represented Charter component. + + + **L1046** It also supplies an actual admissible world for the held theory and context. + + + **L1047** The concrete cost-allowance record is true in that world. + + + **L1048** The proposed capability facet has identifiable canonical articulation. + + + **L1049** That true cost record cannot support the actual output capability. + + + **L1050** Consequently the same capability fails Grounds with these proposed grounds. + + + **L1051** The candidate list contains the identified unsupported capability facet. + + + **L1052** Its original task retains that facet's empirical claim and support context. + + + **L1053** The policy values expansion and keeps the principle form revisable. + + + **L1054** An actual assessment of target one returns true. + + + **L1055** Nevertheless the same rule is applicable to self-target zero. + + + **L1056** It fails reflexivity because that applicable self-target receives no work. + + + **L1057** Use five concrete component proofs rather than inferring correctness from self-application. + + + **L1059** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction. + + + **L1060** Begin source-tracing metadata for CoreReader.Adopted.groundsCases012; this mapping is not a proof premise. + + + **L1061** Record source clause organon.grounds#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1062** Record source clause organon.grounds.assessment#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1063** Record source clause organon.grounds.assessment#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1064** Record source clause organon.grounds.assessment#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1065** Close the preceding source-mapping comment without adding a logical condition. + + + **L1066** Bundle same-task Grounds examples and the rejected circular-assumption substitution. + + + **L1067** The local claim fulfills its explicitly declared local task. + + + **L1068** The global candidate is nevertheless clearly articulated. + + + **L1069** The all-input task fails Grounds despite that articulation. + + + **L1070** The two-output task also fails with the same records. + + + **L1071** The uninformative argument still has identifiable concepts and reasons. + + + **L1072** The uninformative articulation’s actual assumptions do not entail that the world is true. + + + **L1073** The circular facet has Grounds for its own explicitly new conditional task. + + + **L1074** It is not appropriate to the previously fixed global empirical task. + + + **L1075** Thus it cannot fulfill that original task merely by sharing its conclusion. + + + **L1076** Combine scope/strength countermodels, articulation without support, and preserved-original-task rejection. + + + **L1078** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction. + + + **L1079** Begin source-tracing metadata for CoreReader.Adopted.empiricalCases012; this mapping is not a proof premise. + + + **L1080** Record source clause organon.grounds.assessment#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1081** Close the preceding source-mapping comment without adding a logical condition. + + + **L1082** Bundle empirical relevance, scope, uncertainty and alternative-assessment cases with original tasks preserved. + + + **L1083** The local claim fulfills its explicitly declared local task. + + + **L1084** The global candidate is nevertheless clearly articulated. + + + **L1085** The all-input task fails Grounds despite that articulation. + + + **L1086** The two-output task also fails with the same records. + + + **L1087** The actual temperature test returns true even when the independent output coordinate is false. + + + **L1088** Retain this false-output world under repeated temperature observations. + + + **L1089** Also retain a true-output world under those same repeated observations. + + + **L1090** A single temperature record does not support the other output being true. + + + **L1091** Repeating that temperature record still does not support the other output being true. + + + **L1092** Repeated observed activation is compatible with selected-on and budget 0. + + + **L1093** The same repeated records are also compatible with budget 3. + + + **L1094** A single activation record does not support the option’s actual objective-and-budget consequence. + + + **L1095** Repeating activation records does not repair that lack of consequence support. + + + **L1096** The announcement-based value procedure also fails for that actual option and constraint. + + + **L1097** The empirical task uses the same repeated temperature records. + + + **L1098** The claim fixes only coordinate one; uncertainty explicitly allows coordinate two to vary. + + + **L1099** The true/true world matches the repeated records. + + + **L1100** The true/false world matches them as well. + + + **L1101** The original empirical facet fulfills the fixed local task. + + + **L1102** The legitimate observation-based inference fulfills that very same task. + + + **L1103** Retain the valid candidate's own discharge. + + + **L1104** Reject its appropriateness to the full original uncertainty task. + + + **L1105** Reject Grounds for this original first-coordinate assertion and its unchanged articulation. + + + **L1106** The candidate must still be checked against the full original uncertainty task. + + + **L1107** Use all five component proofs, including legitimate empirical-to-inference assessment and the rejected uncertainty bypass. + + + **L1109** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction. + + + **L1110** Begin source-tracing metadata for CoreReader.Adopted.inferentialCases012; this mapping is not a proof premise. + + + **L1111** Record source clause organon.grounds.assessment#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1112** Record source clause organon.relationships.roles#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1113** Close the preceding source-mapping comment without adding a logical condition. + + + **L1114** Bundle valid inference, compatible-but-unentailed conclusions and rejected changes of original premises. + + + **L1115** From the stated assumption n=2 the scoped inference establishes n+1=3. + + + **L1116** The empty Boolean theory accurately receives a negative report for the on-claim. + + + **L1117** The false world satisfies the same empty premises while falsifying that conclusion. + + + **L1118** Require a model where emptyTheory and the positive singleton claim hold together. + + + **L1119** The inhabited empty theory does not entail the positive true-world answer. + + + **L1120** Include an inferential facet whose satisfiable true-world premise entails the same true-world claim. + + + **L1121** Reject Grounds for the original on-claim when the inference context has been substituted. + + + **L1122** The proposed candidate assumes the conclusion itself as its premise. + + + **L1123** The fixed original task instead contains an empty assumption theory. + + + **L1124** Combine the arithmetic/negative-report proof, actual countervaluation and original-context substitution rejection. + + + **L1126** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction. + + + **L1127** Begin source-tracing metadata for CoreReader.Adopted.valueCases012; this mapping is not a proof premise. + + + **L1128** Record source clause organon.grounds.assessment#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1129** Record source clause organon.grounds.assessment#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1130** Close the preceding source-mapping comment without adding a logical condition. + + + **L1131** Bundle reasoned value adoption, insufficient self-announcement, live criticism, initial commitments and fact/value distinction. + + + **L1132** The switch value task has its own fulfilled reasons and responsibilities. + + + **L1133** Require nonempty announcement reasons and actual adoption at selected-on with budget 0. + + + **L1134** At that same zero-budget world, all actual announcement reasons hold. + + + **L1135** Nevertheless reject the actual consequence and the whole value procedure. + + + **L1136** Closing every criticism response makes closedPosition012 fail the value procedure. + + + **L1137** The original switch position does satisfy the represented value procedure. + + + **L1138** Its explicitly adopted starting assumptions have a real model. + + + **L1139** Deny derivation of its adopted commitment from the empty Boolean theory. + + + **L1140** The opposite position has a joint witness but fails consequence assessment. + + + **L1141** Reject the procedures for contradictory starting assumptions and impossible actual adoption separately. + + + **L1142** The empirical selection facet is discharged and the reasoned value position independently fulfills its task. + + + **L1143** The empirical fact alone nevertheless cannot fulfill the fixed value-position task. + + + **L1144** Assemble the five value proofs while retaining assumptions, limits and actual negative cases. + + + **L1146** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction. + + + **L1147** Begin source-tracing metadata for CoreReader.Adopted.groundsLimits012; this mapping is not a proof premise. + + + **L1148** Record source clause organon.grounds.assessment#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1149** Record source clause organon.grounds.assessment#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1150** Record source clause organon.grounds.assessment#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1151** Close the preceding source-mapping comment without adding a logical condition. + + + **L1152** Bundle limits on clear reasons, repeated irrelevant facts, self-proof demands and numerical commensurability. + + + **L1153** Its fields are identifiable, but the false world does not model its assumptions. + + + **L1154** The actual temperature test returns true even when the independent output coordinate is false. + + + **L1155** Retain this false-output world under repeated temperature observations. + + + **L1156** Also retain a true-output world under those same repeated observations. + + + **L1157** A single temperature record does not support the other output being true. + + + **L1158** Repeating that temperature record still does not support the other output being true. + + + **L1159** Repeated observed activation is compatible with selected-on and budget 0. + + + **L1160** The same repeated records are also compatible with budget 3. + + + **L1161** A single activation record does not support the option’s actual objective-and-budget consequence. + + + **L1162** Repeating activation records does not repair that lack of consequence support. + + + **L1163** The announcement-based value procedure also fails for that actual option and constraint. + + + **L1164** The switch value task has its own fulfilled reasons and responsibilities. + + + **L1165** The opposite selection false is compatible with the neutral record. + + + **L1166** Thus those records do not establish adoption of the switch commitment. + + + **L1167** Deny derivation of its adopted commitment from the empty Boolean theory. + + + **L1168** The finite switch value procedure is fulfilled in its stated interpretation. + + + **L1169** The adopted starting theory is satisfiable, without claiming it follows from empty facts. + + + **L1170** Deny derivation of its adopted commitment from the empty Boolean theory. + + + **L1171** The opposite position has a joint witness but fails consequence assessment. + + + **L1172** Reject the procedures for contradictory starting assumptions and impossible actual adoption separately. + + + **L1173** Truth at every input implies truth at input zero. + + + **L1174** Truth at zero does not imply truth at every input. + + + **L1175** The switch value task has its own fulfilled reasons and responsibilities. + + + **L1176** Combine concrete false-reason and wrong-object counterexamples with the value and qualitative-strength results. + + + **L1178** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction. + + + **L1179** Begin source-tracing metadata for CoreReader.Adopted.scopeCases012; this mapping is not a proof premise. + + + **L1180** Record source clause organon.grounds.scope#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1181** Record source clause organon.grounds.scope#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1182** Record source clause organon.grounds.scope#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1183** Close the preceding source-mapping comment without adding a logical condition. + + + **L1184** Bundle a fulfilled local scope account with an actual omitted difference. + + + **L1185** The defined local account satisfies every represented comparison and method-role duty. + + + **L1186** State equality of both functions only for inputs satisfying n=0. + + + **L1187** State their concrete output inequality at input 1. + + + **L1188** Use the actual scope-account proof and the input-one difference witness. + + + **L1190** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction. + + + **L1191** Begin source-tracing metadata for CoreReader.Adopted.scopeLimits012; this mapping is not a proof premise. + + + **L1192** Record source clause organon.grounds.scope#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1193** Record source clause organon.grounds.scope#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1194** Record source clause organon.grounds.scope#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1195** Record source clause organon.grounds.implementations.limits#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1196** Close the preceding source-mapping comment without adding a logical condition. + + + **L1197** Bundle limited local support, broader differences, trial distinctions and nonobservational assessment. + + + **L1198** There is an actual natural input outside the observed zero input. + + + **L1199** The constant-true function matches the zero observation. + + + **L1200** Require this generated function to match the same input-0 record. + + + **L1201** The first function is universally true while the second is not. + + + **L1202** The original zero record does not support all-input truth. + + + **L1203** State equality of both functions only for inputs satisfying n=0. + + + **L1204** State their concrete output inequality at input 1. + + + **L1205** The evidence list contains exactly one observation. + + + **L1206** That single observation has a real compatible function, so the support example is nonempty. + + + **L1207** That single record supports its actual input-0 claim. + + + **L1208** Its limited support still does not establish allTrue. + + + **L1209** Define trial a with setting zero and an accurately recorded actual outcome one. + + + **L1210** Define trial b at the same setting with accurately recorded actual outcome two. + + + **L1211** Require the two explicitly fixed trials to share settings, differ in actual outcomes and both satisfy actualOutcome ≤ 2. + + + **L1212** Require two accurately recorded trials whose settings nevertheless differ. + + + **L1213** Require repeated settings alongside an inaccurate second record and an actual result exceeding the bound. + + + **L1214** Require preserved bounds even though one recorded outcome is inaccurate. + + + **L1215** The arithmetic facet is discharged although its method uses no observation. + + + **L1216** Under the explicit premise on=true, infer on≠false. + + + **L1217** The actual inferential facet reports that it does not use observation. + + + **L1218** Both possible draw weights are positive. + + + **L1219** The two weights are equal. + + + **L1220** Both trials reproduce the same setting. + + + **L1221** Their actual outcomes nevertheless differ. + + + **L1222** For every draw the record is accurate and the actual outcome is at most two. + + + **L1223** Combine eight proofs; finite weighted draws and logical decisions are not claimed as empirical universal guarantees. + + + **L1225** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction. + + + **L1226** Begin source-tracing metadata for CoreReader.Adopted.capabilityCases012; this mapping is not a proof premise. + + + **L1227** Record source clause organon.grounds.capabilities#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1228** Record source clause organon.grounds.capabilities#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1229** Record source clause organon.relationships.roles#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1230** Record source clause organon.relationships.roles#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1231** Close the preceding source-mapping comment without adding a logical condition. + + + **L1232** Bundle exact-object output and explanation contracts with the same duty for an owner's own claim. + + + **L1233** The output-only process has Grounds for its output contract. + + + **L1234** The explained process has Grounds for the stronger output-plus-explanation contract. + + + **L1235** Require an actual external certificate indexed by outputOnlyProcess. + + + **L1236** Require their distinction and actual output correctness of the same process. + + + **L1237** Still deny an internal explanation contract for that actual process. + + + **L1238** Retain the existing own-capability case and conjoin the additional understanding cases. + + + **L1239** Both application objects contain exactly the same original process, so their outputs and explanation are identical. + + + **L1240** The object with wrong variation answers still satisfies the original output-and-explanation contract. + + + **L1241** That object fails the stronger application understanding task. + + + **L1242** The mechanism responder satisfies that stronger task. + + + **L1243** Assert Grounds for the exact stronger understanding claim using canonical articulation. + + + **L1244** The positive facet and the fixed original task both identify the mechanism responder. + + + **L1245** Deny Grounds for the same stronger understanding claim in the negative object case. + + + **L1246** The negative assessment retains that object's own fixed task and identity scope, closing the additional understanding cases. + + + **L1247** Construct the bundle from the preserved capability and own-capability proofs and the new understanding-case proof. + + + **L1249** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction. + + + **L1250** Begin source-tracing metadata for CoreReader.Adopted.capabilityLimits012; this mapping is not a proof premise. + + + **L1251** Record source clause organon.grounds.capabilities#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1252** Record source clause organon.grounds.capabilities#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1253** Close the preceding source-mapping comment without adding a logical condition. + + + **L1254** Bundle reliable output without explanation and inventory/resource limits on stronger capability claims. + + + **L1255** The output-only process has Grounds for its output contract. + + + **L1256** The explained process has Grounds for the stronger output-plus-explanation contract. + + + **L1257** Require an actual external certificate indexed by outputOnlyProcess. + + + **L1258** Require their distinction and actual output correctness of the same process. + + + **L1259** Still deny an internal explanation contract for that actual process. + + + **L1260** The duplication claim applies to each represented inventory kind. + + + **L1261** Two copies of a copy item still provide the copy operation. + + + **L1262** They do not provide the distinct successor operation. + + + **L1263** The same concrete generating system has a generative policy. + + + **L1264** Its policy allows keeping version zero, so generativity does not require every action to change versions. + + + **L1265** Inflating this system's inventory does not expand its represented capabilities. + + + **L1266** The inflated state has strictly more inventory entries than this system's current state. + + + **L1267** Its abstraction-layer count also strictly increases without capability expansion. + + + **L1268** Its vocabulary count strictly increases under the same unchanged capability content. + + + **L1269** With resources 1,2,3, this system's execution actually returns some 6. + + + **L1270** Removing experience from that same resource bundle makes the system's execution fail. + + + **L1271** Removing knowledge alone likewise makes its execution return none. + + + **L1272** Removing the collaborator input alone also makes execution fail. + + + **L1273** With all three external inputs absent, this same execution interface returns none. + + + **L1274** The system's stable action yields no represented capability expansion. + + + **L1275** That stable action is exactly retention of the system's current state. + + + **L1276** Retention preserves the workload's required copy operation. + + + **L1277** The retained one-item state fits this system's one-item application budget. + + + **L1278** The duplicated inventory has two entries and exceeds this same system's one-item budget. + + + **L1279** Stability has the stated reason: construction is unchanged, but only the current state fits the budget. + + + **L1280** Identifies the report as this system's announcement about inflatedState, successor, input zero and output one. + + + **L1281** The report's owner equals this generating system's owner. + + + **L1282** The report uses this system's current state as baseline and inflatedState as result. + + + **L1283** Confirms the alleged new operation is successor. + + + **L1284** Confirms the announced test is input zero with expected output one. + + + **L1285** States both that the announcement's substantive claim fails and that its own state pair has no expansion. + + + **L1286** Combine scoped capability proofs, all-category content checks and actual generation/resource limits. + + + **L1288** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction. + + + **L1289** Begin source-tracing metadata for CoreReader.Adopted.choiceCases012; this mapping is not a proof premise. + + + **L1290** Record source clause organon.grounds.implementations#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1291** Record source clause organon.grounds.implementations#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1292** Record source clause organon.grounds.implementations.limits#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1293** Record source clause organon.relationships.roles#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1294** Close the preceding source-mapping comment without adding a logical condition. + + + **L1295** Bundle grounded conventional choices, internal-method reasons and status-only rejection, including the current philosophy. + + + **L1296** Keep both actual status facts true for identity. + + + **L1297** Claim justified selection using a list containing convention and an actual output reason; the output reason supplies relevance. + + + **L1298** Require a faithful explanation reason for the same actual identity implementation. + + + **L1299** Require its actual applicability to cover the required inputs. + + + **L1300** Require its actual cost to meet the valued simplicity/budget condition. + + + **L1301** Require its actual trace content to meet the valued procedure condition. + + + **L1302** Require that cheapSuccessor’s cost reason is actually relevant under the chosen requirements. + + + **L1303** Nevertheless reject its justified choice with that reason alone because feasibility includes correct outputs. + + + **L1304** Require procedural articulation and a correctly negative report for the same status-priority assessment. + + + **L1305** Keep all candidate interpretations as models of the same actual status facts. + + + **L1306** The priority predicate holds at identity and fails at successor. + + + **L1307** True name/convention/standing facts do not entail the particular priority claim. + + + **L1308** Also reject selecting identity with standing as the only actual reason. + + + **L1309** Both implementations return identical actual outputs at every input. + + + **L1310** Both meet the same output and budget feasibility requirements. + + + **L1311** Require a faithful explanation reason for the same actual identity implementation. + + + **L1312** The altered explanation fails that same relevance/content test. + + + **L1313** Begin the status-only rejection under the actual proposal-review requirements. + + + **L1314** Use exactly the same current philosophy implementation in this status-only negative branch. + + + **L1315** The rejected reason list contains standing alone. + + + **L1316** State the contrasting justified choice under the same proposal-review requirements. + + + **L1317** Use exactly the same current philosophy implementation in the positive case. + + + **L1318** Its actual output performance supplies the positive reason. + + + **L1319** Quantify status-only insufficiency over names, conventional use and standing. + + + **L1320** Neither name, convention nor standing alone justifies the identity implementation. + + + **L1321** Combine six choice proofs, retaining real content comparisons and rejecting privilege for the current philosophy. + + + **L1323** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction. + + + **L1324** Begin source-tracing metadata for CoreReader.Adopted.choiceLimits012; this mapping is not a proof premise. + + + **L1325** Record source clause organon.grounds.implementations#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1326** Record source clause organon.grounds.implementations#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1327** Record source clause organon.grounds.implementations.limits#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation. + + + **L1328** Close the preceding source-mapping comment without adding a logical condition. + + + **L1329** Bundle limits of openness: one feasible conventional option, unequal internal reasons, broader differences and limited assessment-policy independence. + + + **L1330** Over the explicitly two-valued candidate type, require feasibility exactly for identity. + + + **L1331** Also retain identity’s actual output-reason justification. + + + **L1332** Keep both actual status facts true for identity. + + + **L1333** Claim justified selection using a list containing convention and an actual output reason; the output reason supplies relevance. + + + **L1334** Both implementations return identical actual outputs at every input. + + + **L1335** Both meet the same output and budget feasibility requirements. + + + **L1336** Require a faithful explanation reason for the same actual identity implementation. + + + **L1337** The altered explanation fails that same relevance/content test. + + + **L1338** Also retain identity’s actual output-reason justification. + + + **L1339** Also require that identity and successor actually produce different outputs at input 0. + + + **L1340** Compare actual outputs only under the input-0 scope. + + + **L1341** Separately require a real output difference at input 1. + + + **L1342** Require procedural articulation and a correctly negative report for the same status-priority assessment. + + + **L1343** Keep all candidate interpretations as models of the same actual status facts. + + + **L1344** The priority predicate holds at identity and fails at successor. + + + **L1345** The status premises alone still do not entail the priority claim. + + + **L1346** Also reject selecting identity with standing as the only actual reason. + + + **L1347** The two policies share the same accurate assessment but differ in their actual priority reasons; this is not full Grounds independence. + + + **L1348** Use six checked components; generalGroundsNotChoice proves only the disclosed general-assessment/choice-policy separation. + + + **L1350** Close CoreReader.Adopted; subsequent declarations are outside this namespace. + + +### `leanified/CoreReader/Agency.lean` + + +```lean +import CoreReader.Reflexivity + +namespace CoreReader.Agency + +inductive FormKind | organization | method | principle | appearance | artifact + deriving DecidableEq, Repr + +structure Form where + kind : FormKind + version : Nat + deriving DecidableEq, Repr + +inductive Aim | expandUnderstandingAndConstruction | preserveSafeOperation + deriving DecidableEq, Repr + +/- A policy records an adopted valuation, current forms, and permission. It does not assert that valuation is correct or enacted. -/ +structure Policy where + worthPursuing : Aim → Prop + current : Form → Prop + revisable : Form → Prop + permitsVersion : Nat → Nat → Prop + +/- The normative specification keeps valuation and revisability separate from realized transitions. -/ +def Generative (p : Policy) : Prop := + p.worthPursuing .expandUnderstandingAndConstruction ∧ + ∀ f, p.current f → p.revisable f + +def openPolicy : Policy where + worthPursuing a := a = .expandUnderstandingAndConstruction ∨ a = .preserveSafeOperation + current f := f.version = 0 + revisable _ := True + permitsVersion _ _ := True + +def neutralPolicy : Policy := { openPolicy with worthPursuing := fun _ => False } + +/- Permitting a real version change does not supply an adopted value position. -/ +theorem permissionNotValuation : + neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy := by + simp [neutralPolicy, openPolicy, Generative] + +/- This is an explicit consequence of the adopted specification, not evidence of actual revision. -/ +theorem revisabilityCovers (p : Policy) (h : Generative p) (k : FormKind) (v : Nat) + (hc : p.current ⟨k, v⟩) : p.revisable ⟨k, v⟩ := h.2 _ hc + +inductive Operation | copy | successor + deriving DecidableEq, Repr + +def Operation.run : Operation → Nat → Nat + | .copy, n => n + | .successor, n => n + 1 + +inductive InventoryKind | document | term | tool | artifact + deriving DecidableEq, Repr + +structure Item where + kind : InventoryKind + content : Operation + deriving DecidableEq, Repr + +/- Available represented operations are the contents present, not their number of occurrences. -/ +def Available (xs : List Item) (op : Operation) : Prop := + ∃ item ∈ xs, item.content = op + +/- Duplicating any inventory category preserves exactly the represented operation content. -/ +theorem inventoryNotCapability (kind : InventoryKind) (ops : List Operation) (op : Operation) : + Available ((ops.map fun x => Item.mk kind x) ++ (ops.map fun x => Item.mk kind x)) op ↔ + Available (ops.map fun x => Item.mk kind x) op := by + simp only [Available, List.mem_append] + constructor + · rintro ⟨x, hx | hx, hop⟩ <;> exact ⟨x, hx, hop⟩ + · rintro ⟨x, hx, hop⟩ + exact ⟨x, Or.inl hx, hop⟩ + +structure State where + understood : List Operation + constructed : List Operation + inventory : List Item + abstractionLayers : List Operation + vocabulary : List Operation + deriving DecidableEq, Repr + +/- A gain must identify an operation newly understood or constructed; this is a disclosed finite capability representation. -/ +def Expanded (before after : State) : Prop := + (∃ op, op ∈ after.understood ∧ op ∉ before.understood) ∨ + (∃ op, op ∈ after.constructed ∧ op ∉ before.constructed) + +def baseState : State := + ⟨[.copy], [.copy], [⟨.artifact, .copy⟩], [.copy], [.copy]⟩ + +def inflatedState : State := + { baseState with + inventory := baseState.inventory ++ baseState.inventory + abstractionLayers := [.copy, .copy] + vocabulary := [.copy, .copy] } + +def stableTrace (_time : Nat) : State := baseState + +/- A revisable policy can govern an unchanged trace; no improvement is hidden in revisability. -/ +theorem revisionWithoutProgress : + Generative openPolicy ∧ + (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧ + (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1))) := by + simp [Generative, openPolicy, stableTrace, Expanded] + +structure ExternalResources where + experience : Option Nat + knowledge : Option Nat + collaborator : Option Nat + deriving DecidableEq, Repr + +/- This interpreter actually needs all three external inputs to produce the modeled result. -/ +def assistedExecution (r : ExternalResources) : Option Nat := do + let e ← r.experience + let k ← r.knowledge + let c ← r.collaborator + pure (Operation.copy.run (e + k + c)) + +def availableResources : ExternalResources := ⟨some 1, some 2, some 3⟩ + +/- Stability has a concrete stated reason in this workload: preserve its operation while staying within the one-item budget. -/ +def StableReason (before proposed : State) : Prop := + before.constructed = proposed.constructed ∧ + before.inventory.length ≤ 1 ∧ ¬ proposed.inventory.length ≤ 1 + +/- The policy, current capabilities, execution interface and workload constraints belong to one generating system. -/ +structure GeneratingSystem where + owner : Nat + policy : Policy + current : State + execute : ExternalResources → Option Nat + applicationBudget : Nat + requiredOperations : List Operation +/- The modeled system uses the assisted interpreter under a one-item budget and a copy-operation requirement. -/ +def generatingSystem : GeneratingSystem where + owner := 0 + policy := openPolicy + current := baseState + execute := assistedExecution + applicationBudget := 1 + requiredOperations := [.copy] +/- A stable action retains this system's own current state. -/ +def GeneratingSystem.stableAction (system : GeneratingSystem) : State := system.current +def GeneratingSystem.requirementsMet (system : GeneratingSystem) (state : State) : Prop := + ∀ operation, operation ∈ system.requiredOperations → operation ∈ state.constructed +def GeneratingSystem.withinBudget (system : GeneratingSystem) (state : State) : Prop := + state.inventory.length ≤ system.applicationBudget +/- An expansion report identifies the actual before/after states and the operation/performance it asserts was added. -/ +structure Announcement where + owner : Nat + before : State + after : State + reportedNewOperation : Operation + input : Nat + expectedOutput : Nat + deriving DecidableEq, Repr +/- Reports are generated by this system and identify its actual current state as their baseline. -/ +def GeneratingSystem.report (system : GeneratingSystem) (after : State) + (operation : Operation) (input expectedOutput : Nat) : Announcement := + ⟨system.owner, system.current, after, operation, input, expectedOutput⟩ +/- Report content is interpreted against those very states and the named operation's actual behavior. -/ +def Announcement.claim (report : Announcement) : Prop := + report.reportedNewOperation ∈ report.after.constructed ∧ + report.reportedNewOperation ∉ report.before.constructed ∧ + report.reportedNewOperation.run report.input = report.expectedOutput +/- A true report of this form entails a represented construction expansion. -/ +theorem announcementClaimImpliesExpansion (report : Announcement) (h : report.claim) : + Expanded report.before report.after := Or.inr ⟨report.reportedNewOperation, h.1, h.2.1⟩ +/- This concrete self-report asserts a successor operation for the actual inventory-only inflation. -/ +def inflatedAnnouncement : Announcement := generatingSystem.report inflatedState .successor 0 1 +/- The report asserts a real successor result but its named operation is absent from its own after-state. -/ +theorem inflatedAnnouncementRefuted : + inflatedAnnouncement.before = baseState ∧ inflatedAnnouncement.after = inflatedState ∧ + inflatedAnnouncement.reportedNewOperation = .successor ∧ + inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧ + ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after := by + simp [inflatedAnnouncement, GeneratingSystem.report, generatingSystem, Announcement.claim, Expanded, baseState, inflatedState] + +/- These transitions share one initial state; only extension adds an actual new operation. -/ +inductive TransitionCase | inflate | extend + deriving DecidableEq, Repr + +def extendedState : State := + { baseState with understood := [.copy, .successor], constructed := [.copy, .successor] } +def transitionBefore (_transition : TransitionCase) : State := baseState +def transitionAfter : TransitionCase → State + | .inflate => inflatedState + | .extend => extendedState +/- Both alternatives are assessed under the same concrete input condition. -/ +def transitionInput (_transition : TransitionCase) : Nat := 0 +def transitionAnnouncement (transition : TransitionCase) : Announcement := + generatingSystem.report (transitionAfter transition) .successor (transitionInput transition) 1 + +/- Eleven boundary branches share a content-bearing trace and executable dependency model. They do not assert a universal law of human capability. -/ +theorem generationLimits : + Generative generatingSystem.policy ∧ + generatingSystem.policy.permitsVersion 0 0 ∧ + ¬ Expanded generatingSystem.current inflatedState ∧ + generatingSystem.current.inventory.length < inflatedState.inventory.length ∧ + generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧ + generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧ + generatingSystem.execute availableResources = some 6 ∧ + generatingSystem.execute { availableResources with experience := none } = none ∧ + generatingSystem.execute { availableResources with knowledge := none } = none ∧ + generatingSystem.execute { availableResources with collaborator := none } = none ∧ + generatingSystem.execute ⟨none, none, none⟩ = none ∧ + ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧ + generatingSystem.stableAction = generatingSystem.current ∧ + generatingSystem.requirementsMet generatingSystem.stableAction ∧ + generatingSystem.withinBudget generatingSystem.stableAction ∧ + ¬ generatingSystem.withinBudget inflatedState ∧ + StableReason generatingSystem.current inflatedState ∧ + (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧ + inflatedAnnouncement.owner = generatingSystem.owner ∧ + inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧ + inflatedAnnouncement.reportedNewOperation = .successor ∧ + inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧ + ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after) := by + simp [generatingSystem, GeneratingSystem.stableAction, GeneratingSystem.requirementsMet, + GeneratingSystem.withinBudget, GeneratingSystem.report, Generative, openPolicy, Expanded, + baseState, inflatedState, assistedExecution, availableResources, Operation.run, + StableReason, inflatedAnnouncement, Announcement.claim] + +/- The empty work log omits an actually applicable system assessment despite an open generative policy. -/ +theorem generationNotReflexivity : + Generative openPolicy ∧ ¬ Reflexive 0 (ownRules 0) [] := by + constructor + · simp [Generative, openPolicy] + · intro h + have bad := noSelfExemption 0 (ownRules 0) [] h (assessingRule 0) (by simp [ownRules]) + (.system 0) rfl (by simp [assessingRule, ownSubjects]) + simp [Performed] at bad + +/- The same proposed arithmetic principle is used in the self-test and in the universal correctness claim. -/ +def ownArithmeticPrinciple (n : Nat) : Bool := decide (n + 1 = 2 * n) + +def selfTest (samples : List Nat) : Bool := samples.all ownArithmeticPrinciple + +/- A genuine evaluation on the selected sample succeeds, while the same principle fails at zero. -/ +theorem selfTestDoesNotProve : + selfTest [1] = true ∧ ownArithmeticPrinciple 0 = false ∧ + ¬ (∀ n, ownArithmeticPrinciple n = true) := by + constructor + · decide + constructor + · decide + · intro h + have bad := h 0 + contradiction + +end CoreReader.Agency +``` + + + + **L1** Imports CoreReader.Reflexivity and its dependencies into this module. + + + **L3** Opens namespace CoreReader.Agency; file boundaries do not change declaration identity. + + + **L5** Defines exactly five form tags; their names carry no additional semantics. + + + **L6** Generates decidable equality and display instances for the preceding datatype. + + + **L8** A form is a kind tag and a natural-number version. + + + **L9** Stores whether this form is an organization, method, principle, appearance or artifact. + + + **L10** Stores a natural-number form version; it does not prove any change occurred. + + + **L11** Generates decidable equality and display instances for the preceding datatype. + + + **L13** Defines two aim tags: expanding understanding/construction and preserving safe operation; the datatype alone does not value either aim. + + + **L14** Generates decidable equality and display instances for the preceding datatype. + + + **L16** Documents the following definition or result: A policy supplies four unrelated predicate fields; no law ties version permission to valuation or revisability. + + + **L17** A policy supplies four unrelated predicate fields; no law ties version permission to valuation or revisability. + + + **L18** Specifies which of the two represented aims this policy regards as worth pursuing. + + + **L19** Specifies the form kind/version pairs currently held by this policy. + + + **L20** Specifies which form kind/version pairs this policy leaves revisable. + + + **L21** Specifies permission between version numbers independently of actual execution. + + + **L23** Documents the following definition or result: A policy satisfies this predicate when it values the designated expansion aim and declares every current form revisable. This states no actual progress condition. + + + **L24** A policy satisfies this predicate when it values the designated expansion aim and declares every current form revisable. This states no actual progress condition. + + + **L25** Requires this policy to value expanding understanding and construction. + + + **L26** Requires every form currently held by this policy to remain revisable. + + + **L28** Constructs a policy valuing both aims, selecting version zero, and permitting every revision and version pair. + + + **L29** Values both expansion and preserving safe operation in openPolicy. + + + **L30** Treats precisely version-zero forms as current, regardless of kind. + + + **L31** Allows revision of every form, including forms not currently held. + + + **L32** Permits every pair of version numbers; this does not execute a change. + + + **L34** Copies the open policy but makes every aim unworthy of pursuit; the permission fields are unchanged. + + + **L36** Documents the following definition or result: Shows permission for version 0 to 1 and distinct versions coexist with failure of the generation predicate. + + + **L37** Shows permission for version 0 to 1 and distinct versions coexist with failure of the generation predicate. + + + **L38** States that neutralPolicy permits 0→1, the versions differ, and its missing valuation defeats Generative. + + + **L39** Unfolds the two policies: permission is true, 0≠1 computes true, and the required valuation is false. + + + **L41** Documents the following definition or result: Extracts revisability of a specified current kind/version from an assumed generation predicate; it does not revise that form. + + + **L42** Extracts revisability of a specified current kind/version from an assumed generation predicate; it does not revise that form. + + + **L43** Uses h's revisability clause on the same kind/version form that hc identifies as current. + + + **L45** Defines the only two encoded operations: identity and successor on natural numbers. + + + **L46** Generates decidable equality and display instances for the preceding datatype. + + + **L48** Interprets an operation as a function on natural numbers. + + + **L49** Executing copy returns its input unchanged. + + + **L50** Executing successor returns the input plus one. + + + **L52** Defines four inventory tags whose operational content is stored separately. + + + **L53** Generates decidable equality and display instances for the preceding datatype. + + + **L55** An inventory item consists of a tag and one of the two operations. + + + **L56** Classifies this inventory item as a document, term, tool or artifact. + + + **L57** Records the operation represented by this item, independently of its category. + + + **L58** Generates decidable equality and display instances for the preceding datatype. + + + **L60** Documents the following definition or result: Availability means that some item in the supplied list has exactly the requested operation as its content. + + + **L61** Availability means that some item in the supplied list has exactly the requested operation as its content. + + + **L62** An operation is available exactly when some listed item contains that operation. + + + **L64** Documents the following definition or result: Proves that duplicating a uniformly tagged list of operations does not change which operations are available. + + + **L65** Proves that duplicating a uniformly tagged list of operations does not change which operations are available. + + + **L66** Tests availability after duplicating the list of items built from ops and the fixed category. + + + **L67** Compares it with availability in the original single copy of that same list. + + + **L68** Expands availability and turns membership in the duplicated list into membership in either copy. + + + **L69** Proves both directions: duplication neither adds nor removes represented operations. + + + **L70** An item found in either copy is already an original-list witness for the same operation. + + + **L71** For the reverse direction, take an original item x with membership hx and matching content hop. + + + **L72** Places that same item in the first copy, preserving its matching operation. + + + **L74** A state is five lists; understanding and construction are represented only by membership in the two-operation datatype. + + + **L75** Lists operations represented as understood in this state. + + + **L76** Lists operations represented as constructed in this state. + + + **L77** Stores inventory items; their multiplicity is distinct from capability membership. + + + **L78** Stores abstraction-layer entries without identifying their count with understanding. + + + **L79** Stores vocabulary entries without identifying their count with constructed capability. + + + **L80** Generates decidable equality and display instances for the preceding datatype. + + + **L82** Documents the following definition or result: Expansion is the appearance of at least one previously absent operation in either understanding or construction. It allows losing other operations. + + + **L83** Expansion is the appearance of at least one previously absent operation in either understanding or construction. It allows losing other operations. + + + **L84** Expansion may be witnessed by an operation understood after the change but not before. + + + **L85** Alternatively, a newly constructed operation witnesses expansion. + + + **L87** Constructs a state with only copy in every operation list and one copy artifact. + + + **L88** The baseline understands and constructs copy, with one copy artifact, layer and vocabulary entry. + + + **L90** Constructs a larger inventory/layer/vocabulary state with unchanged understanding and construction. + + + **L91** Starts from baseState, retaining fields unless explicitly overwritten below. + + + **L92** Duplicates the one-item inventory while leaving understood and constructed operations unchanged. + + + **L93** Replaces one abstraction-layer entry with two copies of copy. + + + **L94** Similarly doubles the vocabulary list; no new operation is introduced. + + + **L96** Returns the same base state at every natural-number time. + + + **L98** Documents the following definition or result: Exhibits a policy meeting the generation interface and universal revisability while its independently chosen constant trace never expands. + + + **L99** Exhibits a policy meeting the generation interface and universal revisability while its independently chosen constant trace never expands. + + + **L100** Asserts openPolicy meets the adopted valuation-and-revisability specification. + + + **L101** Additionally exposes revision permission for version zero of every form category. + + + **L102** Every adjacent pair in the constant trace lacks a newly understood or constructed operation. + + + **L103** Reduces the policy clauses to true and every expansion claim to impossible new membership in an unchanged list. + + + **L105** Stores three optional natural numbers representing external-resource slots. + + + **L106** An optional external experience value; none makes assistedExecution fail at its first read. + + + **L107** An optional knowledge value required after the experience input. + + + **L108** An optional collaborator value required before producing the result. + + + **L109** Generates decidable equality and display instances for the preceding datatype. + + + **L111** Documents the following definition or result: An Option computation succeeds only when all three slots are present, then returns their sum through identity. This dependency is programmed into the example. + + + **L112** An Option computation succeeds only when all three slots are present, then returns their sum through identity. This dependency is programmed into the example. + + + **L113** Reads experience into e, immediately returning none when that resource is absent. + + + **L114** Reads knowledge into k; absence aborts the same Option computation. + + + **L115** Reads the collaborator's value into c, also propagating absence. + + + **L116** Returns the sum e+k+c through the copy operation inside some. + + + **L118** Provides resource values 1, 2 and 3 for the concrete success case. + + + **L120** Documents the following definition or result: Defines a particular non-growth reason: construction lists match, the old inventory has length at most one, and the proposed one exceeds one. + + + **L121** Defines a particular non-growth reason: construction lists match, the old inventory has length at most one, and the proposed one exceeds one. + + + **L122** A reason to retain the old state requires both states to have exactly the same constructed operations. + + + **L123** The old inventory must fit the one-item limit while the proposed inventory exceeds it. + + + **L125** Documents the following definition or result: Binds one owner's policy, current state, resource-dependent executor, budget and required operations. + + + **L126** Binds one owner's policy, current state, resource-dependent executor, budget and required operations. + + + **L127** Identifies the owner of this generating system. + + + **L128** Attaches the valuation and revisability policy to this same system. + + + **L129** Stores the system's current represented capability and inventory state. + + + **L130** Stores this system's actual resource-consuming execution function. + + + **L131** Specifies the inventory-size budget used to evaluate stable and proposed states. + + + **L132** Specifies operations that the workload requires to remain constructed. + + + **L133** Documents the following definition or result: Instantiates owner zero with the open policy, base state, three-slot executor, budget one and required copy operation. + + + **L134** Instantiates owner zero with the open policy, base state, three-slot executor, budget one and required copy operation. + + + **L135** Assigns owner identifier zero to the concrete generating system. + + + **L136** Installs openPolicy in that same concrete system. + + + **L137** Sets its current capabilities and inventory to baseState. + + + **L138** Uses the three-resource assisted interpreter as this system's execution interface. + + + **L139** Sets this workload's inventory budget to exactly one item. + + + **L140** Requires the concrete workload to preserve the copy operation. + + + **L141** Documents the following definition or result: Returns this system's current state as its stability-preserving action. + + + **L142** Returns this system's current state as its stability-preserving action. + + + **L143** Checks every operation required by this same system is constructed in the assessed state. + + + **L144** For this system and proposed state, every required operation must occur in the state's constructed list. + + + **L145** Compares the assessed state's inventory length against this system's declared budget. + + + **L146** Checks the state's inventory count against this same system's declared application budget. + + + **L147** Documents the following definition or result: Stores reporting owner, exact before/after states, claimed new operation, tested input and expected output. + + + **L148** Stores reporting owner, exact before/after states, claimed new operation, tested input and expected output. + + + **L149** Records whose expansion announcement this is. + + + **L150** Stores the exact baseline state named by the announcement. + + + **L151** Stores the exact resulting state named by the announcement. + + + **L152** Names the operation alleged to be newly constructed. + + + **L153** Fixes the input at which the announced operation's behavior is claimed. + + + **L154** Stores the claimed output of that operation at the stated input. + + + **L155** Generates decidable equality and display instances for the preceding datatype. + + + **L156** Documents the following definition or result: Builds a report from this system's owner/current state and the supplied proposal and operation contract. + + + **L157** Builds a report from this system's owner/current state and the supplied proposal and operation contract. + + + **L158** Receives the allegedly new operation and the concrete input/output pair for this report. + + + **L159** Builds a report tied to the system's owner and current baseline, using the supplied after-state and claim data. + + + **L160** Documents the following definition or result: Requires the reported operation to be newly constructed and to produce the stated output at the stated input. + + + **L161** Requires the reported operation to be newly constructed and to produce the stated output at the stated input. + + + **L162** The reported new operation must actually occur in the announcement's after-state. + + + **L163** The same operation must be absent from the announcement's baseline constructed list. + + + **L164** Its actual run at the reported input must equal the announced expected output. + + + **L165** Documents the following definition or result: Uses the genuinely new constructed operation from an assumed report claim as the expansion witness. + + + **L166** Uses the genuinely new constructed operation from an assumed report claim as the expansion witness. + + + **L167** Uses the claim's after-membership and before-absence to construct Expanded's construction branch. + + + **L168** Documents the following definition or result: This system reports successor at input zero for an inventory-only inflation proposal. + + + **L169** This system reports successor at input zero for an inventory-only inflation proposal. + + + **L170** Documents the following definition or result: Computes the exact report objects and shows its claimed new operation and actual expansion both fail. + + + **L171** Computes the exact report objects and shows its claimed new operation and actual expansion both fail. + + + **L172** Confirms the concrete announcement refers to baseState and inflatedState themselves. + + + **L173** Confirms the alleged new operation is successor. + + + **L174** Confirms the announced test is input zero with expected output one. + + + **L175** States both that the announcement's substantive claim fails and that its own state pair has no expansion. + + + **L176** Computes the report fields and unchanged capability lists; successor is absent from the after-state despite its correct 0→1 behavior. + + + **L178** Documents the following definition or result: Restricts the achievement model to inventory inflation and genuine operation extension. + + + **L179** Restricts the achievement model to inventory inflation and genuine operation extension. + + + **L180** Generates decidable equality and display instances for the preceding datatype. + + + **L182** Adds successor to the base state's understanding and construction lists. + + + **L183** Adds successor to both understood and constructed lists while retaining the baseline's other fields. + + + **L184** Both modeled transitions share the same base-state baseline. + + + **L185** Chooses inflatedState or extendedState according to the transition constructor. + + + **L186** The inflate transition ends at the inventory-only inflated state. + + + **L187** The extend transition ends at the state with newly understood and constructed successor. + + + **L188** Documents the following definition or result: Uses zero as the explicit tested input for both transition cases. + + + **L189** Uses zero as the explicit tested input for both transition cases. + + + **L190** Reports successor output one at input zero for this same system and selected after-state. + + + **L191** Both alternatives announce successor at the shared input zero, but name their own actual after-state. + + + **L193** Documents the following definition or result: Checks all concrete branches on the bound system: unchanged capability despite list inflation, resource dependence, justified stable action and an untrue same-object achievement report. + + + **L194** Checks all concrete branches on the bound system: unchanged capability despite list inflation, resource dependence, justified stable action and an untrue same-object achievement report. + + + **L195** The concrete system retains the adopted generative policy. + + + **L196** Its policy allows keeping version zero, so generativity does not require every action to change versions. + + + **L197** Inflating this system's inventory does not expand its represented capabilities. + + + **L198** The inflated state has strictly more inventory entries than this system's current state. + + + **L199** Its abstraction-layer count also strictly increases without capability expansion. + + + **L200** Its vocabulary count strictly increases under the same unchanged capability content. + + + **L201** With resources 1,2,3, this system's execution actually returns some 6. + + + **L202** Removing experience from that same resource bundle makes the system's execution fail. + + + **L203** Removing knowledge alone likewise makes its execution return none. + + + **L204** Removing the collaborator input alone also makes execution fail. + + + **L205** With all three external inputs absent, this same execution interface returns none. + + + **L206** The system's stable action yields no represented capability expansion. + + + **L207** That stable action is exactly retention of the system's current state. + + + **L208** Retention preserves the workload's required copy operation. + + + **L209** The retained one-item state fits this system's one-item application budget. + + + **L210** The duplicated inventory has two entries and exceeds this same system's one-item budget. + + + **L211** Stability has the stated reason: construction is unchanged, but only the current state fits the budget. + + + **L212** Identifies the report as this system's announcement about inflatedState, successor, input zero and output one. + + + **L213** The report's owner equals this generating system's owner. + + + **L214** The report uses this system's current state as baseline and inflatedState as result. + + + **L215** The operation this actual report calls new is successor. + + + **L216** The report's claimed performance remains the concrete pair 0→1. + + + **L217** Despite that report, its claim is false and its own before/after pair has no capability expansion. + + + **L218** Begins computing all generationLimits clauses by exposing the concrete system, retention action and required-operation check. + + + **L219** Also exposes the one-item budget, report constructor and policy/expansion predicates so their claims reduce to concrete data. + + + **L220** Uses the actual baseline/inflated lists and three-resource interpreter to decide the size, membership and execution results. + + + **L221** Finally unfolds the stability reason and owned announcement claim, completing all conjunction branches by computation. + + + **L223** Documents the following definition or result: Exhibits a policy meeting generation while empty records fail the nonempty concrete reflexivity requirements. + + + **L224** Exhibits a policy meeting generation while empty records fail the nonempty concrete reflexivity requirements. + + + **L225** Combines a generative openPolicy with failure of owned reflexivity when the work log is empty. + + + **L226** Separates establishing Generative from refuting the empty-log Reflexive claim. + + + **L227** Computes openPolicy's expansion valuation and unconditional revisability. + + + **L228** Assumes, for contradiction, that the empty log satisfies the owned reflexivity contract. + + + **L229** Applies noSelfExemption to the registered assessingRule, forcing a performed assessment from the assumed empty-log compliance. + + + **L230** Chooses the very system subject with matching owner and proves that assessment is applicable to it. + + + **L231** Unfolding Performed reveals an impossible member of the empty work list. + + + **L233** Documents the following definition or result: Decides the arithmetic equation n+1=2*n for each natural number. + + + **L234** Decides the arithmetic equation n+1=2*n for each natural number. + + + **L236** Returns true precisely when the equation holds at every listed sample; no unlisted input is tested. + + + **L238** Documents the following definition or result: Computes success on sample 1 and failure at 0, refuting universal success. This concerns the particular arithmetic predicate, not a universal impossibility theorem about all self-tests. + + + **L239** Computes success on sample 1 and failure at 0, refuting universal success. This concerns the particular arithmetic predicate, not a universal impossibility theorem about all self-tests. + + + **L240** The same arithmetic principle passes sample 1 but evaluates false at 0. + + + **L241** Therefore that principle does not return true for every natural-number input. + + + **L242** Separates the passing sample computation from the two failure claims. + + + **L243** Evaluates the singleton sample: 1+1 equals 2×1, so selfTest [1] is true. + + + **L244** Separates the concrete failure at zero from refuting universal success. + + + **L245** Computes 0+1≠2×0, making ownArithmeticPrinciple 0 false. + + + **L246** Assumes the same principle succeeds for every input. + + + **L247** Specializes that universal assumption to input zero. + + + **L248** Contradicts the computed false result at zero, refuting universal correctness. + + + **L250** Closes the current namespace. + + +### `leanified/CoreReader/Choice.lean` + + +```lean +import CoreReader.Evidence + +namespace CoreReader.Choice +open CoreReader.Logic CoreReader.Evidence + +inductive StatusKind | name | convention | standing + deriving DecidableEq, Repr + +inductive MethodReason | output | explanation | applicability | simplicity | procedure + deriving DecidableEq, Repr + +inductive Reason | status (kind : StatusKind) | method (kind : MethodReason) + deriving DecidableEq, Repr + +/- An implementation has observable behavior, a stated domain, an explanation formula and an execution trace. -/ +structure Implementation where + name : String + conventional : Bool + established : Bool + run : Nat → Nat + cost : Nat + domain : Nat → Prop + explanation : Nat → Nat + trace : Nat → List Nat + +/- An application selects relevant objectives and constraints; no universal ranking or score is prescribed. -/ +structure Requirements where + inputs : Nat → Prop + expected : Nat → Nat + budget : Nat + values : MethodReason → Prop + +/- These are explicit, content-based interpretations of possible method reasons in this application. -/ +def MethodContent (req : Requirements) (i : Implementation) : MethodReason → Prop + | .output => ∀ x, req.inputs x → i.run x = req.expected x + | .explanation => ∀ x, req.inputs x → i.explanation x = i.run x + | .applicability => ∀ x, req.inputs x → i.domain x + | .simplicity => i.cost ≤ req.budget + | .procedure => ∀ x, req.inputs x → (i.trace x).getLast? = some (i.run x) + +/- The extra choice commitment requires both selected relevance and actual reason content; pure status supplies neither. -/ +def Relevant (req : Requirements) (i : Implementation) : Reason → Prop + | .status _ => False + | .method kind => req.values kind ∧ MethodContent req i kind + +def Feasible (req : Requirements) (i : Implementation) : Prop := + (∀ x, req.inputs x → i.run x = req.expected x) ∧ i.cost ≤ req.budget + +/- In this application, a relevant reason is eligible only after its stated output and budget requirements hold. -/ +def JustifiedChoice (req : Requirements) (i : Implementation) (reasons : List Reason) : Prop := + Feasible req i ∧ ∃ reason ∈ reasons, Relevant req i reason + +/- This proves the structural effect of the adopted choice commitment for each of its three status-only cases. -/ +theorem statusOnlyFails (req : Requirements) (i : Implementation) (k : StatusKind) : + ¬ JustifiedChoice req i [.status k] := by + rintro ⟨_, reason, hr, hv⟩ + simp only [List.mem_singleton] at hr + subst reason + exact hv + +def identityImpl : Implementation where + name := "Existing identity implementation" + conventional := true + established := true + run n := n + cost := 1 + domain _ := True + explanation n := n + trace n := [n] + +def successorImpl : Implementation where + name := "Successor implementation" + conventional := false + established := false + run n := n + 1 + cost := 2 + domain _ := True + explanation n := n + 1 + trace n := [n, n + 1] + +def changedOutsideZero : Implementation := + { identityImpl with + name := "Changed outside zero" + conventional := false + established := false + run := fun n => if n = 0 then 0 else n + 1 + explanation := fun n => if n = 0 then 0 else n + 1 + trace := fun n => [if n = 0 then 0 else n + 1] } + +def identityRequirements : Requirements where + inputs _ := True + expected n := n + budget := 1 + values _ := True + +def objectiveReason : List Reason := [.method .output] + +theorem identityOutputReason : Relevant identityRequirements identityImpl (.method .output) := by + exact ⟨trivial, fun _ _ => rfl⟩ + +theorem identityFeasible : Feasible identityRequirements identityImpl := + ⟨fun _ _ => rfl, by decide⟩ + +theorem identityJustified : JustifiedChoice identityRequirements identityImpl objectiveReason := + ⟨identityFeasible, .method .output, by simp [objectiveReason], identityOutputReason⟩ + +/- A conventional existing implementation can be selected for an actual requirement, not for status alone. -/ +theorem conventionWithReason : + identityImpl.conventional = true ∧ identityImpl.established = true ∧ + JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output] := by + exact ⟨rfl, rfl, identityFeasible, .method .output, by simp, identityOutputReason⟩ + +inductive Candidate | identity | successor + deriving DecidableEq, Repr + +def implementation : Candidate → Implementation + | .identity => identityImpl + | .successor => successorImpl + +/- Feasibility is decided by the same stated behavior and resource requirement for either candidate. -/ +theorem singleFeasible : + (∀ candidate, Feasible identityRequirements (implementation candidate) ↔ candidate = .identity) ∧ + JustifiedChoice identityRequirements identityImpl objectiveReason := by + constructor + · intro candidate + cases candidate + · simp [Feasible, identityRequirements, implementation, identityImpl] + · simp [Feasible, identityRequirements, implementation, successorImpl] + · exact identityJustified + +/- The same observed input can conceal a relevant difference at another input. -/ +theorem localNotGlobal : + (∀ x, x = 0 → identityImpl.run x = changedOutsideZero.run x) ∧ + identityImpl.run 1 ≠ changedOutsideZero.run 1 := by + constructor + · intro x hx; subst x; rfl + · decide + +/- This candidate is cheap enough but misses the required identity output. -/ +def cheapSuccessor : Implementation := { successorImpl with cost := 1 } + +theorem eligibleInternalReasonNotSufficient : + Relevant identityRequirements cheapSuccessor (.method .simplicity) ∧ + ¬ JustifiedChoice identityRequirements cheapSuccessor [.method .simplicity] := by + refine ⟨⟨trivial, by change 1 ≤ 1; decide⟩, ?_⟩ + intro h + have bad := h.1.1 0 trivial + cases bad + +/- Each of the four internal-method reasons is eligible because of its actual selected requirement and content. -/ +theorem internalReasons : + Relevant identityRequirements identityImpl (.method .explanation) ∧ + Relevant identityRequirements identityImpl (.method .applicability) ∧ + Relevant identityRequirements identityImpl (.method .simplicity) ∧ + Relevant identityRequirements identityImpl (.method .procedure) ∧ + (Relevant identityRequirements cheapSuccessor (.method .simplicity) ∧ + ¬ JustifiedChoice identityRequirements cheapSuccessor [.method .simplicity]) := by + exact ⟨⟨trivial, fun _ _ => rfl⟩, ⟨trivial, fun _ _ => trivial⟩, + ⟨trivial, by change 1 ≤ 1; decide⟩, ⟨trivial, fun _ _ => rfl⟩, eligibleInternalReasonNotSufficient⟩ + +/- Openness about reasons does not make two actual behaviors identical or reject the existing implementation. -/ +theorem openNotEquivalent : + JustifiedChoice identityRequirements identityImpl objectiveReason ∧ + identityImpl.run 0 ≠ successorImpl.run 0 := by + exact ⟨identityJustified, by decide⟩ + +/- A priority interpretation chooses one of the same two actual implementations. -/ +def priorityClaim : Claim Candidate := fun selected => selected = .identity + +def statusFacts : Theory Candidate := union + (singleton (fun _ => identityImpl.conventional = true)) + (singleton (fun _ => identityImpl.established = true)) + +/- Both interpretations have exactly the same true conventional and established status facts. -/ +theorem statusFactsModel (selected : Candidate) : Models statusFacts selected := by + exact (modelsUnion _ _ _).2 ⟨(modelsSingleton _ _).2 rfl, (modelsSingleton _ _).2 rfl⟩ + +def priorityArticulation : Articulation Candidate := + ⟨["priority", "conventional use", "established status"], statusFacts, + [fun _ => identityImpl.conventional = true, fun _ => identityImpl.established = true], + fun _ => True⟩ + +/- This procedure reports whether the actual status premises entail that very priority claim over its stated two-candidate scope. -/ +def AssessmentAccurate (report : Bool) : Prop := + report = true ↔ Entails statusFacts priorityClaim + +theorem statusDoesNotEntailPriority : ¬ Entails statusFacts priorityClaim := by + intro h + have bad := h .successor (statusFactsModel .successor) + cases bad + +theorem statusAssessmentNonEntailment : + Articulated priorityArticulation ∧ AssessmentAccurate false ∧ + (∀ selected, Models statusFacts selected) ∧ + priorityClaim .identity ∧ ¬ priorityClaim .successor ∧ + ¬ Entails statusFacts priorityClaim ∧ + ¬ JustifiedChoice identityRequirements identityImpl [.status .standing] := by + refine ⟨⟨by simp [priorityArticulation], by simp [priorityArticulation]⟩, + ⟨(by intro h; cases h), (fun h => False.elim (statusDoesNotEntailPriority h))⟩, + statusFactsModel, rfl, (by intro h; cases h), statusDoesNotEntailPriority, + statusOnlyFails _ _ _⟩ + +/- An assessment identifies the exact premises and priority question whose entailment it reports. -/ +structure PriorityAssessment where + premises : Theory Candidate + question : Claim Candidate + report : Bool +/- Accuracy concerns the actual reported entailment question, independently of a later choice policy. -/ +def PriorityAssessment.accurate (assessment : PriorityAssessment) : Prop := + assessment.report = true ↔ Entails assessment.premises assessment.question +/- Both policies receive this same correctly negative status-only priority audit. -/ +def statusPriorityAudit : PriorityAssessment := ⟨statusFacts, priorityClaim, false⟩ +/- Priority reasons are a policy component independent of the assessment's report and objects. -/ +structure ChoicePolicy where + selected : Candidate + priorityReasons : List Reason + assessment : PriorityAssessment +/- This is completion of the specified assessment procedure only, not full compliance with philosophical Grounds. -/ +def GeneralAssessmentFulfilled (policy : ChoicePolicy) : Prop := + Articulated priorityArticulation ∧ policy.assessment = statusPriorityAudit ∧ policy.assessment.accurate +/- The additional choice norm separately tests the reasons actually used to prioritize the selected implementation. -/ +def AdditionalChoiceNorm (policy : ChoicePolicy) : Prop := + JustifiedChoice identityRequirements (implementation policy.selected) policy.priorityReasons +/- This policy retains status alone as its priority reason despite receiving the correctly negative status audit. -/ +def statusPriorityPolicy : ChoicePolicy := ⟨.identity, [.status .standing], statusPriorityAudit⟩ +/- This policy selects the same implementation using its actual relevant output reason after the same audit. -/ +def outputPriorityPolicy : ChoicePolicy := ⟨.identity, objectiveReason, statusPriorityAudit⟩ +/- The shared negative result is mathematically accurate for its actual status premises and question. -/ +theorem statusPriorityAuditAccurate : statusPriorityAudit.accurate := by + constructor + · intro h; cases h + · intro h; exact False.elim (statusDoesNotEntailPriority h) +/- These independently variable policies share facts, selected implementation and completed audit, but differ on the extra choice norm. -/ +def PolicyIndependenceExample : Prop := + statusPriorityPolicy.selected = outputPriorityPolicy.selected ∧ + statusPriorityPolicy.assessment = outputPriorityPolicy.assessment ∧ + statusPriorityPolicy.assessment.premises = statusFacts ∧ + statusPriorityPolicy.assessment.question = priorityClaim ∧ + statusPriorityPolicy.assessment.report = false ∧ + (∀ selected, Models statusPriorityPolicy.assessment.premises selected) ∧ + statusPriorityPolicy.priorityReasons ≠ outputPriorityPolicy.priorityReasons ∧ + GeneralAssessmentFulfilled statusPriorityPolicy ∧ GeneralAssessmentFulfilled outputPriorityPolicy ∧ + ¬ AdditionalChoiceNorm statusPriorityPolicy ∧ AdditionalChoiceNorm outputPriorityPolicy +/- Changing the actual priority reasons changes choice compliance while the accurate audit remains identical. -/ +theorem policyIndependenceExample : PolicyIndependenceExample := by + have articulated : Articulated priorityArticulation := + ⟨by simp [priorityArticulation], by simp [priorityArticulation]⟩ + refine ⟨rfl,rfl,rfl,rfl,rfl,statusFactsModel,?_, + ⟨articulated,rfl,statusPriorityAuditAccurate⟩, + ⟨articulated,rfl,statusPriorityAuditAccurate⟩,?_,?_⟩ + · decide + · exact statusOnlyFails identityRequirements identityImpl .standing + · exact identityJustified + +/- A correctly articulated, completed negative assessment does not enforce the additional selection rule. +This is only independence from represented assessment procedures: keeping this unsupported priority would fail general support proportionality too. -/ +theorem generalGroundsNotChoice : + (Articulated priorityArticulation ∧ AssessmentAccurate false ∧ + (∀ selected, Models statusFacts selected) ∧ + priorityClaim .identity ∧ ¬ priorityClaim .successor ∧ + ¬ Entails statusFacts priorityClaim ∧ + ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧ + PolicyIndependenceExample := + ⟨statusAssessmentNonEntailment, policyIndependenceExample⟩ + +end CoreReader.Choice +``` + + + + **L1** Import CoreReader.Evidence, making its checked declarations available to this module; this line states no new philosophical result. + + + **L3** Open namespace CoreReader.Choice so subsequent declarations receive this module-qualified name. + + + **L4** Make names from CoreReader.Logic CoreReader.Evidence available without qualification; this changes name resolution, not assumptions. + + + **L6** Declare the alternatives StatusKind. Defines three status tags; no ranking or evidential meaning is attached by the datatype alone. + + + **L7** Derive decidable equality and printable representations for these finite constructors; these are computational conveniences, not choice criteria. + + + **L9** Declare the alternatives MethodReason. Defines five method-reason tags whose actual content is supplied by MethodContent. + + + **L10** Derive decidable equality and printable representations for these finite constructors; these are computational conveniences, not choice criteria. + + + **L12** Declare the alternatives Reason. Separates tagged status reasons from tagged method reasons. + + + **L13** Derive decidable equality and printable representations for these finite constructors; these are computational conveniences, not choice criteria. + + + **L15** Document the intended scope of Implementation. The corresponding declaration concerns: Packages an implementation's metadata, behavior, cost, domain, explanation function and trace function as independently supplied fields. This comment is explanatory, not a proof premise. + + + **L16** Declare the data interface Implementation. Packages an implementation's metadata, behavior, cost, domain, explanation function and trace function as independently supplied fields. + + + **L17** Store the implementation’s descriptive name; it does not confer priority. + + + **L18** Record whether the implementation is conventional as a Boolean status fact. + + + **L19** Record whether the implementation is established, independently of its actual behavior. + + + **L20** Store the actual natural-number input/output function. + + + **L21** Store the cost checked against an application’s budget. + + + **L22** Store the implementation’s claimed domain as a predicate on inputs. + + + **L23** Store explanatory output content to be compared with actual run results. + + + **L24** Store an input-indexed execution trace whose last element can be compared with actual output. + + + **L26** Document the intended scope of Requirements. The corresponding declaration concerns: Packages the input scope, expected output, fixed budget and valued reason kinds. This comment is explanatory, not a proof premise. + + + **L27** Declare the data interface Requirements. Packages the input scope, expected output, fixed budget and valued reason kinds. + + + **L28** Specify which inputs the application actually requires. + + + **L29** Specify the expected output at each input. + + + **L30** Specify the application’s budget constraint. + + + **L31** Specify which method-reason categories this application values; this choice is an adopted input. + + + **L33** Document the intended scope of MethodContent. The corresponding declaration concerns: Assigns a proposition to each method tag, using these particular behavioral and cost proxies. This comment is explanatory, not a proof premise. + + + **L34** Define MethodContent. Assigns a proposition to each method tag, using these particular behavioral and cost proxies. + + + **L35** An output reason requires this implementation’s actual output to equal the application’s expected output at every required input. + + + **L36** An explanation reason requires explanatory output to match this very implementation’s actual run at every required input. + + + **L37** An applicability reason requires every application-required input to belong to this implementation’s domain. + + + **L38** The simplicity reason is the selected application’s actual cost-within-budget condition. + + + **L39** A procedure reason requires the actual trace’s last element to equal this implementation’s real output at every required input. + + + **L41** Document the intended scope of Relevant. The corresponding declaration concerns: A reason is relevant when it is an allowed method kind whose content holds; status kinds are excluded outright. This comment is explanatory, not a proof premise. + + + **L42** Define Relevant. A reason is relevant when it is an allowed method kind whose content holds; status kinds are excluded outright. + + + **L43** Status reasons are defined as irrelevant under this adopted choice norm, regardless of their status subtype. + + + **L44** A method reason must both belong to a category valued by these requirements and satisfy that category’s actual MethodContent. + + + **L46** Define Feasible. Feasibility requires universal requested-input output correctness and fixed cost within budget; it does not include explanation, domain or trace checks. + + + **L47** Feasibility requires correct actual output at every required input and actual cost within this application’s budget. + + + **L49** Document the intended scope of JustifiedChoice. The corresponding declaration concerns: Requires both output/budget feasibility and at least one listed valued method reason with its concrete content satisfied. This comment is explanatory, not a proof premise. + + + **L50** Define JustifiedChoice. Requires both output/budget feasibility and at least one listed valued method reason with its concrete content satisfied. + + + **L51** Require feasibility and at least one actually listed relevant reason; a relevant reason alone does not establish feasibility. + + + **L53** Document the intended scope of statusOnlyFails. The corresponding declaration concerns: For any requirements and implementation, a singleton status reason cannot justify choice because its relevance is defined as false. This comment is explanatory, not a proof premise. + + + **L54** State the checked result statusOnlyFails. For any requirements and implementation, a singleton status reason cannot justify choice because its relevance is defined as false. + + + **L55** Deny justified selection when the only listed reason is status, for the supplied arbitrary requirements and implementation. + + + **L56** Unpack an alleged status-only justified choice, extracting its listed reason and proof of relevance; feasibility alone cannot supply the missing relevance. + + + **L57** Simplify singleton membership to show that the extracted reason is exactly the given status reason. + + + **L58** Substitute the identified status reason into its alleged relevance proof. + + + **L59** Relevance of a status reason is defined as False, so the extracted hv is already a contradiction. + + + **L61** Define identityImpl. Builds an identity implementation with both status flags true, cost one, unrestricted domain, matching explanation and singleton output trace. + + + **L62** Name the concrete existing identity implementation without using its name as a proof of quality. + + + **L63** Mark the identity implementation’s conventional and established status as true; these facts remain distinct from its actual method reasons. + + + **L64** Mark the identity implementation’s conventional and established status as true; these facts remain distinct from its actual method reasons. + + + **L65** Define actual identity output as the unchanged input n. + + + **L66** Set identity’s actual cost to 1. + + + **L67** Let identity’s applicability domain contain all natural inputs. + + + **L68** Provide an explanatory result equal to the input, matching identity’s actual output. + + + **L69** Use the singleton input as the actual trace, whose last element equals identity’s output. + + + **L71** Define successorImpl. Builds a successor implementation with false status flags, cost two, unrestricted domain, matching explanation and a two-entry trace. + + + **L72** Name the alternative successor implementation. + + + **L73** Mark successor as neither conventional nor established in this example; this status alone does not determine feasibility. + + + **L74** Mark successor as neither conventional nor established in this example; this status alone does not determine feasibility. + + + **L75** Define successor’s actual output as n+1. + + + **L76** Set its original cost to 2, above the identity application’s budget 1. + + + **L77** Let successor’s applicability domain also include every natural input. + + + **L78** Provide its explanatory result n+1, faithful to its own actual output. + + + **L79** Record input and then actual successor output in its trace. + + + **L81** Define changedOutsideZero. Copies identity metadata/fields except the explicitly replaced ones, producing an implementation equal at zero but different elsewhere. + + + **L82** Start from identityImpl’s fields and explicitly override the following components. + + + **L83** Name the modified implementation by its change outside input zero. + + + **L84** Change this modified implementation’s conventional/established flags to false. + + + **L85** Change this modified implementation’s conventional/established flags to false. + + + **L86** Keep output 0 at input 0 but return n+1 at every other input. + + + **L87** Make its explanation follow the same actual piecewise output function. + + + **L88** Use that same piecewise result as its singleton trace; finish the implementation override. + + + **L90** Define identityRequirements. Requires identity behavior at all natural inputs, budget one, and values every method-reason kind. + + + **L91** Require every natural-number input in the identity application. + + + **L92** Set the desired output to the unchanged input. + + + **L93** Adopt budget 1 for the application. + + + **L94** Admit all represented method-reason categories; their actual content must still be checked. + + + **L96** Define objectiveReason. Defines a reason list containing only the output-correctness method tag. + + + **L98** State the checked result identityOutputReason. Proves the identity implementation has a relevant output reason under universal identity requirements by definitional output equality. The following tactic block proves this explicit type. + + + **L99** The output reason is admitted by these requirements, and identityImpl’s actual output equals the expected output at every allowed input by reflexivity. + + + **L101** State the checked result identityFeasible. Proves universal identity output and cost one within budget one. The supplied proof term uses the displayed constructed witnesses or earlier lemmas, rather than adding an axiom. + + + **L102** For identity, every required output is correct by reflexivity; compute cost 1 within budget 1. + + + **L104** State the checked result identityJustified. Uses the output reason as the existential witness justifying identity under the given requirements. The supplied proof term uses the displayed constructed witnesses or earlier lemmas, rather than adding an axiom. + + + **L105** Combine identity’s feasibility with the actual output reason, prove it belongs to objectiveReason and supply its content-based relevance. + + + **L107** Document the intended scope of conventionWithReason. The corresponding declaration concerns: Shows conventional and established metadata can coexist with justified choice when the list also contains a valid output reason; status does not provide the witness. This comment is explanatory, not a proof premise. + + + **L108** State the checked result conventionWithReason. Shows conventional and established metadata can coexist with justified choice when the list also contains a valid output reason; status does not provide the witness. + + + **L109** Keep both actual status facts true for identity. + + + **L110** Claim justified selection using a list containing convention and an actual output reason; the output reason supplies relevance. + + + **L111** Compute the conventional/established status facts, retain actual feasibility, and select the listed output reason with its separately proved relevance. + + + **L113** Declare the alternatives Candidate. Closes the candidate universe to exactly identity and successor. + + + **L114** Derive decidable equality and printable representations for these finite constructors; these are computational conveniences, not choice criteria. + + + **L116** Define implementation. Maps each of the two candidate constructors to its concrete implementation. + + + **L117** Interpret the identity candidate as the actual identityImpl object. + + + **L118** Interpret the successor candidate as the actual successorImpl object. + + + **L120** Document the intended scope of singleFeasible. The corresponding declaration concerns: Proves identity is the sole feasible member of the two-constructor candidate type under identity requirements, and separately supplies its output justification. This comment is explanatory, not a proof premise. + + + **L121** State the checked result singleFeasible. Proves identity is the sole feasible member of the two-constructor candidate type under identity requirements, and separately supplies its output justification. + + + **L122** Over the explicitly two-valued candidate type, require feasibility exactly for identity. + + + **L123** Also retain identity’s actual output-reason justification. + + + **L124** Separate the exact feasible-candidate characterization from the existing proof of identity’s justified selection. + + + **L125** Fix any candidate in the explicit identity/successor type before checking its feasibility equivalence. + + + **L126** Exhaust the actual two-candidate type: identity or successor; no unlisted implementation is considered. + + + **L127** For identity, unfold actual outputs and cost; the identity-output and budget conditions are satisfied. + + + **L128** For successor, unfold the same requirements; the candidate cannot meet identity outputs and its original cost also exceeds the budget. + + + **L129** Reuse identityJustified to finish the concrete selected-candidate obligation. + + + **L131** Document the intended scope of localNotGlobal. The corresponding declaration concerns: Shows identity and the piecewise implementation agree when input is zero but disagree at input one; this refutes inference from local agreement to global equality. This comment is explanatory, not a proof premise. + + + **L132** State the checked result localNotGlobal. Shows identity and the piecewise implementation agree when input is zero but disagree at input one; this refutes inference from local agreement to global equality. + + + **L133** Compare actual outputs only under the input-0 scope. + + + **L134** Separately require a real output difference at input 1. + + + **L135** Separate equality under the input-0 scope from actual inequality at input 1. + + + **L136** Substitute the local-scope assumption x=0; the two implementations then have definitionally equal outputs. + + + **L137** Compute their actual outputs at input 1 to verify the claimed inequality. + + + **L139** Document the intended scope of cheapSuccessor. The corresponding declaration concerns: Lowers successor's fixed cost to one without fixing its identity-output failure. This comment is explanatory, not a proof premise. + + + **L140** Define cheapSuccessor. Lowers successor's fixed cost to one without fixing its identity-output failure. + + + **L142** State the checked result eligibleInternalReasonNotSufficient. Shows cost simplicity is relevant for cheap successor, yet output infeasibility prevents justified choice. + + + **L143** Require that cheapSuccessor’s cost reason is actually relevant under the chosen requirements. + + + **L144** Nevertheless reject its justified choice with that reason alone because feasibility includes correct outputs. + + + **L145** Show the cheap successor has an admitted cost reason with cost 1 ≤ budget 1, then separately refute justified choice. + + + **L146** Assume cheapSuccessor is justified using its cost reason, in order to extract and refute its required output feasibility. + + + **L147** An alleged justified choice includes feasible outputs; apply that requirement at input 0, where successor returns 1 instead of expected 0. + + + **L148** Eliminate the resulting impossible output equality; a relevant cost reason did not repair the wrong output. + + + **L150** Document the intended scope of internalReasons. The corresponding declaration concerns: Provides four valid internal reasons for identity and a cost-relevant successor counterexample to automatic sufficiency. This comment is explanatory, not a proof premise. + + + **L151** State the checked result internalReasons. Provides four valid internal reasons for identity and a cost-relevant successor counterexample to automatic sufficiency. + + + **L152** Require a faithful explanation reason for the same actual identity implementation. + + + **L153** Require its actual applicability to cover the required inputs. + + + **L154** Require its actual cost to meet the valued simplicity/budget condition. + + + **L155** Require its actual trace content to meet the valued procedure condition. + + + **L156** Include a separate cheap-successor case where its cost reason is eligible. + + + **L157** That cheap candidate still fails justified selection; the combined theorem begins its proof here. + + + **L158** Provide admitted, actually faithful explanation and applicability reasons for identity, checking their content at every required input. + + + **L159** Provide the actual budget and trace reasons, then include the cheap-but-wrong example showing relevance alone is insufficient. + + + **L161** Document the intended scope of openNotEquivalent. The corresponding declaration concerns: Combines identity's justification with differing identity/successor outputs at zero. It proves behavioral distinction between these examples, not a general openness property. This comment is explanatory, not a proof premise. + + + **L162** State the checked result openNotEquivalent. Combines identity's justification with differing identity/successor outputs at zero. It proves behavioral distinction between these examples, not a general openness property. + + + **L163** Retain justified selection of the existing identity implementation based on its actual output reason. + + + **L164** Also require that identity and successor actually produce different outputs at input 0. + + + **L165** Retain the existing identity justification and compute the distinct actual outputs of identity and successor at 0. + + + **L167** Document the intended scope of priorityClaim. The corresponding declaration concerns: Defines the priority claim as selection of the identity constructor. This comment is explanatory, not a proof premise. + + + **L168** Define priorityClaim. Defines the priority claim as selection of the identity constructor. + + + **L170** Define statusFacts. Forms a theory containing two status facts about identity that are constant across candidate worlds. + + + **L171** The first status premise records actual conventional status of identity, regardless of the candidate interpretation. + + + **L172** The second status premise records actual established status of that same implementation. + + + **L174** Document the intended scope of statusFactsModel. The corresponding declaration concerns: Proves every candidate world models these status facts because both concern fixed metadata, independent of selection. This comment is explanatory, not a proof premise. + + + **L175** State the checked result statusFactsModel. Proves every candidate world models these status facts because both concern fixed metadata, independent of selection. The following tactic block proves this explicit type. + + + **L176** Both status predicates concern the same actual identity implementation and are true independently of which candidate interpretation is selected; combine their singleton models. + + + **L178** Define priorityArticulation. Constructs a nonempty articulation of the constant status theory, with the same two status predicates as reasons and unrestricted limits. + + + **L179** Articulate priority and actual status concepts using statusFacts as the premise theory. + + + **L180** List the same actual conventional and established facts as articulated reasons. + + + **L181** Use unrestricted candidate scope for this status-priority articulation. + + + **L183** Document the intended scope of AssessmentAccurate. The corresponding declaration concerns: Defines report accuracy as equivalence between report=true and semantic entailment of the priority claim by status facts. This comment is explanatory, not a proof premise. + + + **L184** Define AssessmentAccurate. Defines report accuracy as equivalence between report=true and semantic entailment of the priority claim by status facts. + + + **L185** Define report accuracy by equivalence between report=true and semantic entailment of this exact priority question from these status facts. + + + **L187** State the checked result statusDoesNotEntailPriority. Refutes priority entailment using successor, which models all fixed identity-status facts but is not identity. The following tactic block proves this explicit type. + + + **L188** Assume the actual status facts entail identity priority across all candidate interpretations. + + + **L189** Apply alleged status-to-priority entailment to successor, which satisfies all the same true status facts but is not identity. + + + **L190** Distinct candidate constructors refute the priority equality derived at successor. + + + **L192** State the checked result statusAssessmentNonEntailment. Retains the original factual countermodel: status facts are articulated and accurately assessed but do not entail identity priority. + + + **L193** Require procedural articulation and a correctly negative report for the same status-priority assessment. + + + **L194** Keep all candidate interpretations as models of the same actual status facts. + + + **L195** The priority predicate holds at identity and fails at successor. + + + **L196** Deny entailment of that priority predicate from status facts alone. + + + **L197** Also reject selecting identity with standing as the only actual reason. + + + **L198** Check that priorityArticulation has nonempty concepts and actual status reasons. + + + **L199** Prove report=false is accurate: it cannot equal true, and any entailment assumption contradicts the actual successor countermodel. + + + **L200** Retain models of the same facts for both candidates, priority at identity but not successor, and the established failed entailment. + + + **L201** Reuse the general status-only failure theorem for the explicit identity choice with standing as its sole reason. + + + **L203** Document the intended scope of PriorityAssessment. The corresponding declaration concerns: Stores the actual premise theory, question and Boolean assessment report independently of a choice policy. This comment is explanatory, not a proof premise. + + + **L204** Declare the data interface PriorityAssessment. Stores the actual premise theory, question and Boolean assessment report independently of a choice policy. + + + **L205** Store the actual premise theory audited by this assessment. + + + **L206** Store the exact priority claim whose entailment is assessed. + + + **L207** Store the reported Boolean answer separately from facts and question. + + + **L208** Document the intended scope of PriorityAssessment.accurate. The corresponding declaration concerns: Matches the report to semantic entailment for this exact premise/question pair. This comment is explanatory, not a proof premise. + + + **L209** Define PriorityAssessment.accurate. Matches the report to semantic entailment for this exact premise/question pair. + + + **L210** Require this assessment’s actual report to agree exactly with entailment from its own premises to its own question. + + + **L211** Document the intended scope of statusPriorityAudit. The corresponding declaration concerns: Records a false entailment report for the actual fixed status facts and priority question. This comment is explanatory, not a proof premise. + + + **L212** Define statusPriorityAudit. Records a false entailment report for the actual fixed status facts and priority question. + + + **L213** Document the intended scope of ChoicePolicy. The corresponding declaration concerns: Separates chosen candidate, priority reasons and the independently stored assessment. This comment is explanatory, not a proof premise. + + + **L214** Declare the data interface ChoicePolicy. Separates chosen candidate, priority reasons and the independently stored assessment. + + + **L215** Store the candidate this policy actually selects. + + + **L216** Store the policy’s actual priority reasons independently of its assessment record. + + + **L217** Store the actual assessment whose procedure the policy completed. + + + **L218** Document the intended scope of GeneralAssessmentFulfilled. The corresponding declaration concerns: Requires nonempty actual articulation and the exact accurate status audit, without imposing the additional choice criterion. This comment is explanatory, not a proof premise. + + + **L219** Define GeneralAssessmentFulfilled. Requires nonempty actual articulation and the exact accurate status audit, without imposing the additional choice criterion. + + + **L220** Require nonempty articulation, exactly the shared statusPriorityAudit, and its accuracy; this is specified procedure fulfillment, not full philosophical Grounds. + + + **L221** Document the intended scope of AdditionalChoiceNorm. The corresponding declaration concerns: Applies the separate feasibility-and-relevance choice norm to this policy's selected implementation and reasons. This comment is explanatory, not a proof premise. + + + **L222** Define AdditionalChoiceNorm. Applies the separate feasibility-and-relevance choice norm to this policy's selected implementation and reasons. + + + **L223** Separately apply JustifiedChoice to the policy’s actual selected implementation and its actual reason list. + + + **L224** Document the intended scope of statusPriorityPolicy. The corresponding declaration concerns: Selects identity solely on standing while retaining the accurate non-entailment audit. This comment is explanatory, not a proof premise. + + + **L225** Define statusPriorityPolicy. Selects identity solely on standing while retaining the accurate non-entailment audit. + + + **L226** Document the intended scope of outputPriorityPolicy. The corresponding declaration concerns: Keeps the same choice and audit but uses the actual output reason. This comment is explanatory, not a proof premise. + + + **L227** Define outputPriorityPolicy. Keeps the same choice and audit but uses the actual output reason. + + + **L228** Document the intended scope of statusPriorityAuditAccurate. The corresponding declaration concerns: Uses the successor countermodel to establish the recorded false entailment report is accurate. This comment is explanatory, not a proof premise. + + + **L229** State the checked result statusPriorityAuditAccurate. Uses the successor countermodel to establish the recorded false entailment report is accurate. The following tactic block proves this explicit type. + + + **L230** Split accuracy of the negative audit into the two directions of its equivalence with entailment. + + + **L231** The audit’s actual false report cannot equal true, so this direction has an impossible premise. + + + **L232** Any asserted entailment contradicts statusDoesNotEntailPriority; this establishes the reverse accuracy direction for the false report. + + + **L233** Document the intended scope of PolicyIndependenceExample. The corresponding declaration concerns: Requires two policies with the same actual selection/audit but different reasons, both satisfying represented assessment duties and only the output policy satisfying the extra norm. This comment is explanatory, not a proof premise. + + + **L234** Define PolicyIndependenceExample. Requires two policies with the same actual selection/audit but different reasons, both satisfying represented assessment duties and only the output policy satisfying the extra norm. + + + **L235** Fix identical selected candidates in both policies. + + + **L236** Fix the same actual assessment in both policies. + + + **L237** Bind that assessment’s premises to the actual shared statusFacts. + + + **L238** Bind its question to the same priorityClaim. + + + **L239** Fix the common report to false, rather than allowing policy changes to alter the audit answer. + + + **L240** Retain models of these same assessment premises for every candidate interpretation. + + + **L241** Require the actual priority reason lists to differ despite the shared candidate and audit. + + + **L242** Require both policies to complete the same specified assessment procedure accurately. + + + **L243** Require opposite results under the additional choice norm: status fails, output passes. + + + **L244** Document the intended scope of policyIndependenceExample. The corresponding declaration concerns: Constructs both independent policy objects and combines actual audit accuracy with status rejection and output justification. This comment is explanatory, not a proof premise. + + + **L245** State the checked result policyIndependenceExample. Constructs both independent policy objects and combines actual audit accuracy with status rejection and output justification. The following tactic block proves this explicit type. + + + **L246** Construct one shared nonempty articulation of the actual status-priority question for both policies. + + + **L247** Construct one shared nonempty articulation of the actual status-priority question for both policies. + + + **L248** Fix identical selected candidate, audit, premises, question and false report; retain actual fact models and leave the difference in reason lists. + + + **L249** Show the status-only policy completed that exact articulated audit with its mathematically accurate report. + + + **L250** Supply the identical fulfilled audit for the output policy, leaving the two separate additional-choice-norm results. + + + **L251** Compute that status-only and output-based priority reason lists are distinct despite their shared selected candidate and audit. + + + **L252** Apply statusOnlyFails to the actual status policy’s priority reason, proving failure of AdditionalChoiceNorm. + + + **L253** Use identityJustified for the output policy’s actual relevant output reason, proving its AdditionalChoiceNorm. + + + **L255** Document the intended scope of generalGroundsNotChoice. The corresponding declaration concerns: Combines the factual non-entailment case with a separate policy-level countermodel to deriving the added choice norm from represented general assessment duties. This comment is explanatory, not a proof premise. + + + **L256** Document the intended scope of generalGroundsNotChoice. The corresponding declaration concerns: Combines the factual non-entailment case with a separate policy-level countermodel to deriving the added choice norm from represented general assessment duties. This comment is explanatory, not a proof premise. + + + **L257** State the checked result generalGroundsNotChoice. Combines the factual non-entailment case with a separate policy-level countermodel to deriving the added choice norm from represented general assessment duties. + + + **L258** Retain the original articulated, accurately negative status assessment as part of the registered result. + + + **L259** Keep the same actual status premises modeled by every candidate. + + + **L260** Keep priority true for identity and false for successor. + + + **L261** Keep the demonstrated status-to-priority non-entailment. + + + **L262** Keep status-only choice failure, then join it to the stronger policy-independence example. + + + **L263** Include actual policy variation through PolicyIndependenceExample, rather than ending at status non-entailment. + + + **L264** Pair the preserved status non-entailment proof with policyIndependenceExample, thereby including actual independent priority-reason variation in the registered theorem. + + + **L266** Close namespace CoreReader.Choice; this adds no proof or premise. + + +### `leanified/CoreReader/Engineering/Domain.lean` + + +```lean +import Std + +namespace CoreReader.Engineering + +/- This is a bounded engineering application model. Work units count explicit +operations; they are not a universal exchange rate or empirical forecast. -/ +inductive Maintainer where + | original | successor | agent + deriving DecidableEq, Repr +inductive Tool where + | editor | compiler | contractRunner | migrationRunner + deriving DecidableEq, Repr +inductive Knowledge where + | privateLayout | publicContract | changeGuide | migrationGuide + deriving DecidableEq, Repr +inductive Change where + | addition | replacement | deletion | withdrawal | redrawing | migration + | independent | coordinated | designRevision | other (name : String) + deriving DecidableEq, Repr +inductive Candidate where + | presentSimple | evolvable | maximal + deriving DecidableEq, Repr +inductive Burden where + | understanding | construction | diagnosis | verification | coordination + | operation | migration + deriving DecidableEq, Repr + +def maintainers : List Maintainer := [.original, .successor, .agent] +def changes : List Change := [.addition, .replacement, .deletion, .withdrawal, + .redrawing, .migration, .independent, .coordinated, .designRevision] +def burdens : List Burden := [.understanding, .construction, .diagnosis, + .verification, .coordination, .operation, .migration] + +structure Activity where + participants : List Maintainer + software : String + tools : List Tool + available : Maintainer → List Knowledge + scheduledReleases : Nat + scheduledMaintenance : Nat + boundedRuns : Option Nat + label : String + +/-- organon-map CoreReader.Engineering.ActivityScope +software-engineering.purpose#p1 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.purpose#p2 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +-/ +abbrev ActivityScope (a : Activity) : Prop := + a.participants ≠ [] ∧ a.software ≠ "" ∧ a.tools ≠ [] ∧ + a.participants.all (fun m => !(a.available m).isEmpty) = true + +abbrev Continuing (a : Activity) : Prop := + 0 < a.scheduledReleases ∧ 0 < a.scheduledMaintenance + +abbrev BoundedLifecycle (a : Activity) : Prop := + a.boundedRuns.isSome = true ∧ a.scheduledReleases = 0 ∧ + a.scheduledMaintenance = 0 + +def continuingActivity : Activity := { + participants := maintainers, software := "order-preserving queue", + tools := [.editor, .compiler, .contractRunner, .migrationRunner], + available := fun m => match m with + | .original => [.privateLayout, .publicContract, .changeGuide, .migrationGuide] + | _ => [.publicContract, .changeGuide, .migrationGuide], + scheduledReleases := 3, scheduledMaintenance := 6, + boundedRuns := none, label := "temporary" } + +def temporaryActivity : Activity := { continuingActivity with + scheduledReleases := 0, scheduledMaintenance := 0, boundedRuns := some 1, + label := "one-shot import" } +def prototypeActivity : Activity := { temporaryActivity with + boundedRuns := some 4, label := "bounded prototype" } +def retiringActivity : Activity := { temporaryActivity with + boundedRuns := some 2, label := "retiring service" } + +structure EditStep where + component : Nat + requires : Knowledge + tool : Tool + units : Nat + deriving DecidableEq, Repr + +def changePath (c : Candidate) (d : Change) : List EditStep := + let guide := if c = .presentSimple then Knowledge.privateLayout else .changeGuide + let base : List EditStep := [⟨0, guide, .editor, 1⟩, + ⟨0, .publicContract, .contractRunner, 1⟩] + match d with + | .addition | .independent => base + | .replacement | .deletion => base ++ [⟨1, guide, .compiler, 1⟩] + | .coordinated => base ++ [⟨1, guide, .compiler, 3⟩, ⟨2, .publicContract, .contractRunner, 3⟩] + | .migration => base ++ [⟨1, .migrationGuide, .migrationRunner, 8⟩] + | .withdrawal | .redrawing | .designRevision => + if c = .presentSimple then base ++ + [⟨1, guide, .editor, 5⟩, ⟨2, guide, .compiler, 5⟩, + ⟨2, .publicContract, .contractRunner, 5⟩] + else base ++ [⟨1, guide, .editor, 2⟩, ⟨1, .publicContract, .contractRunner, 2⟩] + | .other name => + if name = "csv export" then + if c = .maximal then base ++ [⟨3, .migrationGuide, .compiler, 2⟩] + else base ++ [⟨3, .privateLayout, .compiler, 20⟩] + else [] + +def changeWork (c : Candidate) (d : Change) : Nat := + ((changePath c d).map EditStep.units).sum + +abbrev CanChange (a : Activity) (c : Candidate) (m : Maintainer) (d : Change) : Prop := + (changePath c d) ≠ [] ∧ m ∈ a.participants ∧ (changePath c d).all + (fun step => (a.available m).contains step.requires && a.tools.contains step.tool) = true + +abbrev ContinuingCapability (a : Activity) (c : Candidate) (d : Change) : Prop := + (changePath c d) ≠ [] ∧ a.participants.all (fun m => (changePath c d).all + (fun step => (a.available m).contains step.requires && a.tools.contains step.tool)) = true + +/- Maximal is maximal only on this explicitly registered finite set. The +extra CSV direction has an actual documented compilation path and later state +transformation; unsupported names do not gain a capability from an empty path. -/ +def registeredDirections : List Change := changes ++ [.other "csv export"] +def supportedDirections (a : Activity) (c : Candidate) : List Change := + registeredDirections.filter (fun d => decide (ContinuingCapability a c d)) +abbrev MaximumRegisteredCapability (a : Activity) (c : Candidate) : Prop := + registeredDirections.all (fun d => decide (ContinuingCapability a c d)) = true + +/- A software value here is a passive function: no intention is stored in it. +An engineering intention is an agent's selected set of changes. -/ +def passiveArtifact (xs : List Nat) : List Nat := xs + +def orientation : Maintainer → List Change := fun _ => [.designRevision, .migration] + +inductive EngineeringAction where + | propose (direction : Change) + | execute (result : List Nat) + deriving DecidableEq, Repr + +def maintainerActions (m : Maintainer) : List EngineeringAction := + (orientation m).map EngineeringAction.propose + +def artifactActions (input : List Nat) : List EngineeringAction := + [.execute (passiveArtifact input)] + +/-- organon-map CoreReader.Engineering.subjectLifecycleCases +software-engineering.purpose#p1 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.purpose#p2 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +-/ +theorem subjectLifecycleCases : + ActivityScope continuingActivity ∧ + CanChange continuingActivity .evolvable .successor .designRevision ∧ + CanChange continuingActivity .evolvable .agent .designRevision ∧ + continuingActivity.label = "temporary" ∧ Continuing continuingActivity ∧ + ¬ BoundedLifecycle continuingActivity ∧ BoundedLifecycle temporaryActivity ∧ + BoundedLifecycle prototypeActivity ∧ BoundedLifecycle retiringActivity := by decide + +/-- organon-map CoreReader.Engineering.subjectLimits +software-engineering.purpose#p1 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.purpose#p2 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +-/ +theorem subjectLimits : + CanChange continuingActivity .presentSimple .original .designRevision ∧ + ¬ CanChange continuingActivity .presentSimple .successor .designRevision ∧ + ¬ ContinuingCapability continuingActivity .presentSimple .designRevision ∧ + continuingActivity.label = "temporary" ∧ ¬ BoundedLifecycle continuingActivity ∧ + orientation .agent ≠ [] ∧ passiveArtifact [2, 1] = [2, 1] ∧ + EngineeringAction.propose .designRevision ∈ maintainerActions .agent ∧ + EngineeringAction.propose .designRevision ∉ artifactActions [2, 1] := by decide + +/- Ground is intentionally parameterized: the examples below do not exhaust +possible sources of credibility. The supplied support relation needs review. -/ +/-- organon-map CoreReader.Engineering.CredibleDirection +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +abbrev CredibleDirection {Ground : Type} (grounds : List Ground) + (articulated : Ground → Bool) (supports : Ground → Change → Bool) + (d : Change) : Prop := + grounds.any (fun g => articulated g && supports g d) = true + +inductive DirectionGround where + | plan (release : Nat) (committed : List Change) + | knowledge (service : String) (affected : List Change) (mechanism : String) + | history (service : String) (observed : List Change) + | other (account : String) (supported : List Change) + deriving DecidableEq, Repr + +def articulateGround : DirectionGround → Bool + | .plan release ds => release > 0 && !ds.isEmpty + | .knowledge service ds mechanism => service != "" && !ds.isEmpty && mechanism != "" + | .history service ds => service != "" && !ds.isEmpty + | .other account ds => account != "" && !ds.isEmpty + +def supportGround : DirectionGround → Change → Bool + | .plan release ds, d => release > 0 && ds.contains d + | .knowledge service ds mechanism, d => + service == "queue" && mechanism == "tenant-config-reload" && ds.contains d + | .history service ds, d => service == "queue" && (ds.filter (· == d)).length >= 2 + | .other account ds, d => account == "reviewed customer migration requirement" && ds.contains d + +abbrev initialGrounds : List DirectionGround := [.plan 2 [.designRevision, .migration]] +def forecastGrounds : List DirectionGround := [.plan 3 [.deletion]] +abbrev credible (gs : List DirectionGround) (d : Change) : Prop := + CredibleDirection gs articulateGround supportGround d + +abbrev WarrantedAccommodation (gs : List DirectionGround) (d : Change) + (objectiveGain investment : Nat) : Prop := + credible gs d ∧ 0 < objectiveGain ∧ investment ≤ objectiveGain + +/-- organon-map CoreReader.Engineering.credibilityCases +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +theorem credibilityCases : + credible initialGrounds .designRevision ∧ + credible [.knowledge "queue" [.designRevision] "tenant-config-reload"] .designRevision ∧ + credible [.history "queue" [.migration, .migration]] .migration ∧ + ¬ credible [] (.other "quantum backend") ∧ + credible forecastGrounds .deletion ∧ ¬ credible forecastGrounds .designRevision := by decide + +def abstractionComplexity : Candidate → Nat + | .presentSimple => 1 | .evolvable => 3 | .maximal => 30 + +def implementedVariants : List Candidate := [.presentSimple] + +/- No scalar conversion across burden dimensions is used by the priority rule. -/ +structure CostVector where + amount : Burden → Nat +structure CostLimits where + capacity : Burden → Nat + objective : Burden → String + +def cost : Candidate → Burden → Nat + | .presentSimple, _ => 1 + | .evolvable, .understanding => 3 + | .evolvable, .construction => 4 + | .evolvable, .diagnosis => 2 + | .evolvable, .verification => 4 + | .evolvable, .coordination => 2 + | .evolvable, .operation => 2 + | .evolvable, .migration => 8 + | .maximal, _ => 40 + +def normalLimits : CostLimits := { + capacity := fun _ => 12, + objective := fun b => match b with + | .understanding => "successor onboarding capacity" + | .construction => "release construction capacity" + | .diagnosis => "incident diagnosis window" + | .verification => "release verification capacity" + | .coordination => "available team coordination" + | .operation => "runtime resource budget" + | .migration => "retirement migration capacity" } + +structure Requirements where + orderRequired : Bool + maxUnsafeOperations : Nat + maxLatency : Nat + minRetention : Nat + +def normalRequirements : Requirements := ⟨true, 0, 10, 30⟩ +def behavior : Candidate → List Nat → List Nat := fun _ xs => xs.eraseDups + +/- Candidate profiles are observations in this bounded scenario. Modified +profiles below test all four independent necessary-requirement gates. -/ +structure CandidateProfile where + orderOutput : List Nat + unsafeOperations : Nat + latency : Nat + retention : Nat + +def profile (c : Candidate) : CandidateProfile := ⟨behavior c [2, 1, 2], 0, 5, 30⟩ +abbrev Meets (r : Requirements) (p : CandidateProfile) : Prop := + (r.orderRequired = true → p.orderOutput = [2, 1]) ∧ + p.unsafeOperations ≤ r.maxUnsafeOperations ∧ p.latency ≤ r.maxLatency ∧ + r.minRetention ≤ p.retention + +structure Context where + activity : Activity + required : Requirements + evidence : List DirectionGround + limits : CostLimits + departure : Option Burden + profiles : Candidate → CandidateProfile := profile + +def currentContinuing : Context := { + activity := continuingActivity, required := normalRequirements, + evidence := initialGrounds, limits := normalLimits, departure := none } + +abbrev ConcreteThreat (ctx : Context) (c : Candidate) (b : Burden) : Prop := + cost .presentSimple b < cost c b ∧ ctx.limits.capacity b < cost c b ∧ + ctx.limits.objective b ≠ "" + +abbrev HasThreat (ctx : Context) (c : Candidate) : Prop := + burdens.any (fun b => decide (ConcreteThreat ctx c b)) = true + +/-- organon-map CoreReader.Engineering.JustifiedDeparture +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +abbrev JustifiedDeparture (ctx : Context) (c : Candidate) : Prop := + match ctx.departure with + | none => False + | some b => ConcreteThreat ctx c b + +instance (ctx : Context) (c : Candidate) : Decidable (JustifiedDeparture ctx c) := by + unfold JustifiedDeparture + split <;> infer_instance + +abbrev PriorityConditions (ctx : Context) : Prop := + Continuing ctx.activity ∧ ActivityScope ctx.activity ∧ + Meets ctx.required (ctx.profiles .presentSimple) ∧ Meets ctx.required (ctx.profiles .evolvable) ∧ + credible ctx.evidence .designRevision ∧ + ContinuingCapability ctx.activity .evolvable .designRevision ∧ + changeWork .evolvable .designRevision < changeWork .presentSimple .designRevision ∧ + abstractionComplexity .presentSimple < abstractionComplexity .evolvable + +/-- organon-map CoreReader.Engineering.EvolutionPriority +software-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +abbrev EvolutionPriority (ctx : Context) (chosen : Candidate) : Prop := + PriorityConditions ctx → chosen = .evolvable ∨ JustifiedDeparture ctx .evolvable + +theorem currentPriorityConditions : PriorityConditions currentContinuing := by decide +theorem currentNoThreat : ¬ HasThreat currentContinuing .evolvable ∧ + ¬ JustifiedDeparture currentContinuing .evolvable := by decide + +def threatened (b : Burden) : Context := { currentContinuing with + limits := { normalLimits with capacity := fun x => if x = b then 1 else 12 }, + departure := some b } + +/-- organon-map CoreReader.Engineering.priorityWhenApplicable +software-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +theorem priorityWhenApplicable (ctx : Context) (chosen : Candidate) + (rule : EvolutionPriority ctx chosen) (applicable : PriorityConditions ctx) + (noDeparture : ¬ JustifiedDeparture ctx .evolvable) : + chosen = .evolvable ∧ + abstractionComplexity .presentSimple < abstractionComplexity chosen := by + have hc := (rule applicable).resolve_right noDeparture + exact ⟨hc, hc ▸ applicable.2.2.2.2.2.2.2⟩ + +theorem currentSimpleViolates : ¬ EvolutionPriority currentContinuing .presentSimple := by + intro h + have bad := (h currentPriorityConditions).resolve_right currentNoThreat.2 + cases bad + +def withEvolvableProfile (p : CandidateProfile) : Context := { currentContinuing with + profiles := fun c => if c = .evolvable then p else profile c } + +theorem unmetRequirementsBlockPriority : + ¬ PriorityConditions (withEvolvableProfile { profile .evolvable with orderOutput := [1, 2] }) ∧ + ¬ PriorityConditions (withEvolvableProfile { profile .evolvable with unsafeOperations := 1 }) ∧ + ¬ PriorityConditions (withEvolvableProfile { profile .evolvable with latency := 11 }) ∧ + ¬ PriorityConditions (withEvolvableProfile { profile .evolvable with retention := 29 }) := by + simp [PriorityConditions, withEvolvableProfile, currentContinuing, Meets, + normalRequirements] + +/-- organon-map CoreReader.Engineering.priorityConditionsCases +software-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +theorem priorityConditionsCases : + EvolutionPriority currentContinuing .evolvable ∧ + ¬ Meets normalRequirements { profile .evolvable with orderOutput := [1, 2] } ∧ + ¬ Meets normalRequirements { profile .evolvable with unsafeOperations := 1 } ∧ + ¬ Meets normalRequirements { profile .evolvable with latency := 11 } ∧ + ¬ Meets normalRequirements { profile .evolvable with retention := 29 } ∧ + EvolutionPriority (threatened .verification) .presentSimple ∧ + ¬ JustifiedDeparture { threatened .verification with departure := none } .evolvable ∧ + abstractionComplexity .evolvable < abstractionComplexity .maximal := by + refine ⟨by decide, by decide, by decide, by decide, by decide, by decide, ?_, by decide⟩ + simp [JustifiedDeparture] + +/-- organon-map CoreReader.Engineering.priorityChoices +software-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +theorem priorityChoices : + EvolutionPriority currentContinuing .evolvable ∧ + ¬ EvolutionPriority currentContinuing .presentSimple ∧ + EvolutionPriority (threatened .verification) .presentSimple := by + exact ⟨by decide, currentSimpleViolates, by decide⟩ + +/-- organon-map CoreReader.Engineering.credibilityLimits +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +theorem credibilityLimits : + credible initialGrounds .designRevision ∧ implementedVariants.length = 1 ∧ + ¬ WarrantedAccommodation [] (.other "quantum backend") 0 5 ∧ + ¬ credible initialGrounds (.other "quantum backend") ∧ + EvolutionPriority currentContinuing .evolvable ∧ + abstractionComplexity .evolvable < abstractionComplexity .maximal ∧ + cost .evolvable .construction < cost .evolvable .migration ∧ + ¬ MaximumRegisteredCapability continuingActivity .evolvable ∧ + MaximumRegisteredCapability continuingActivity .maximal ∧ + (supportedDirections continuingActivity .evolvable).length = 9 ∧ + (supportedDirections continuingActivity .maximal).length = 10 ∧ + ¬ credible initialGrounds (.other "csv export") := by decide + +/-- organon-map CoreReader.Engineering.costCases +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +theorem costCases : + JustifiedDeparture (threatened .understanding) .evolvable ∧ + JustifiedDeparture (threatened .construction) .evolvable ∧ + JustifiedDeparture (threatened .diagnosis) .evolvable ∧ + JustifiedDeparture (threatened .verification) .evolvable ∧ + JustifiedDeparture (threatened .coordination) .evolvable ∧ + JustifiedDeparture (threatened .operation) .evolvable ∧ + JustifiedDeparture (threatened .migration) .evolvable ∧ + ¬ JustifiedDeparture { currentContinuing with departure := some .migration } .evolvable := by decide + +/- Total functions model an identified order-preserving de-duplication API. +The test corpus is explicitly finite; universal preservation is separate. -/ +def orderedUnique (xs : List Nat) : List Nat := xs.eraseDups +def orderedRefactor (xs : List Nat) : List Nat := xs.eraseDups ++ [] +def insertOrdered (n : Nat) : List Nat → List Nat + | [] => [n] + | x :: xs => if n ≤ x then n :: x :: xs else x :: insertOrdered n xs + +def sortValues : List Nat → List Nat + | [] => [] + | x :: xs => insertOrdered x (sortValues xs) + +def sortedUnique (xs : List Nat) : List Nat := (sortValues xs).eraseDups + +structure SoftwareState where + capabilities : List String + implementation : Nat + mechanisms : List String + abstractions : List String + boundary : Nat + technology : String + batchSize : Nat + deriving DecidableEq, Repr + +def originalSoftware : SoftwareState := + ⟨["deduplicate"], 0, ["queue", "legacy cache"], ["fixed batch"], 0, "legacy store", 10⟩ + +def transform (d : Change) (s : SoftwareState) : SoftwareState := match d with + | .addition => { s with capabilities := s.capabilities ++ ["tenant batching"] } + | .replacement => { s with implementation := s.implementation + 1 } + | .deletion => { s with mechanisms := s.mechanisms.filter (· != "legacy cache") } + | .withdrawal => { s with abstractions := s.abstractions.filter (· != "fixed batch") } + | .redrawing => { s with boundary := s.boundary + 1 } + | .migration => { s with technology := "portable store" } + | .independent => { s with batchSize := 5 } + | .coordinated => { s with batchSize := 5, boundary := s.boundary + 1 } + | .designRevision => { s with batchSize := 5, abstractions := ["live configuration"], boundary := s.boundary + 1 } + | .other name => + if name = "csv export" then { s with capabilities := s.capabilities ++ ["csv export"] } + else s + +def evolutionBehavior (d : Change) : List Nat → List Nat := + if d = .redrawing ∨ d = .designRevision then sortedUnique else orderedUnique + +/- Changes include an open other constructor. Work, maintainer knowledge and +obligation treatment are separate dimensions, not one extensibility score. -/ +inductive ObligationTreatment where + | preserve | revise + deriving DecidableEq, Repr +structure ChangeClaim where + direction : Change + byMaintainer : Maintainer + treatment : ObligationTreatment + +abbrev contractInputs : List (List Nat) := [[], [2, 1, 2], [1, 3, 1], [4, 4]] +def PreservesOn {Input Output : Type} (scope : Input → Prop) + (old new : Input → Output) : Prop := ∀ x, scope x → new x = old x + +abbrev PreservesFinite (old new : List Nat → List Nat) : Prop := + contractInputs.all (fun xs => new xs == old xs) = true + +/- The actual contracts and observer dependencies are inputs independent of +any revision report. Reports cannot redefine the affected population or the +old/new retry behavior merely by changing their own fields. -/ +structure ObservableContract where + order : List Nat → List Nat + maxAttempts : Nat + +def retry (contract : ObservableContract) (attempts : Nat) : Bool := + attempts < contract.maxAttempts + +def orderContract (order : List Nat → List Nat) : ObservableContract := ⟨order, 3⟩ +def originalContract : ObservableContract := orderContract orderedUnique +def refactoredContract : ObservableContract := orderContract orderedRefactor +def revisedContract : ObservableContract := ⟨sortedUnique, 5⟩ +def evolutionContract (d : Change) : ObservableContract := + ⟨evolutionBehavior d, if d = .redrawing ∨ d = .designRevision then 5 else 3⟩ + +def failureInputs : List Nat := [0, 1, 2, 3, 4, 5] +abbrev PreservesContractFinite (old new : ObservableContract) : Prop := + PreservesFinite old.order new.order ∧ + failureInputs.all (fun attempts => retry new attempts == retry old attempts) = true + +inductive ContractAspect where + | order | retry + deriving DecidableEq, Repr +structure PartyDependency where + party : String + observes : ContractAspect + deriving DecidableEq, Repr + +def partyDependencies : List PartyDependency := + [⟨"queue consumer", .order⟩, ⟨"queue operator", .retry⟩] + +def aspectChanged (old new : ObservableContract) : ContractAspect → Bool + | .order => contractInputs.any (fun xs => new.order xs != old.order xs) + | .retry => failureInputs.any (fun attempts => retry new attempts != retry old attempts) + +def affectedParties (old new : ObservableContract) : List String := + (partyDependencies.filter (fun dependency => aspectChanged old new dependency.observes)).map + PartyDependency.party + +structure ContractRevision where + deliberate : Bool + revisedOrder : List Nat + affected : List String + oldFailureLimit : Nat + newFailureLimit : Nat + recordedOldFailureLimit : Nat + recordedNewFailureLimit : Nat + procedure : String + +def normalRevision : ContractRevision := { + deliberate := true, revisedOrder := [1, 2], + affected := ["queue consumer", "queue operator"], + oldFailureLimit := 3, newFailureLimit := 5, + recordedOldFailureLimit := 3, recordedNewFailureLimit := 5, + procedure := "contract review" } + +abbrev RevisionDuties (old new : ObservableContract) (r : ContractRevision) : Prop := + r.deliberate = true ∧ r.revisedOrder = new.order [2, 1, 2] ∧ + (affectedParties old new).all (fun p => r.affected.contains p) = true ∧ + r.oldFailureLimit = old.maxAttempts ∧ r.newFailureLimit = new.maxAttempts ∧ + r.recordedOldFailureLimit = old.maxAttempts ∧ + r.recordedNewFailureLimit = new.maxAttempts + +/-- organon-map CoreReader.Engineering.ContractChangeAccount +software-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +-/ +abbrev ContractChangeAccount (old new : ObservableContract) (r : ContractRevision) : Prop := + PreservesContractFinite old new ∨ RevisionDuties old new r + +/-- organon-map CoreReader.Engineering.EvolutionClaim +software-engineering.evolution-meaning#p1 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6 +software-engineering.evolution-meaning#p2 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6 +-/ +abbrev EvolutionClaim (a : Activity) (c : Candidate) (claim : ChangeClaim) : Prop := + CanChange a c claim.byMaintainer claim.direction ∧ + ContractChangeAccount originalContract (evolutionContract claim.direction) normalRevision ∧ + (changePath c claim.direction).any (fun step => step.tool == .contractRunner) = true ∧ + ((claim.treatment = .preserve ∧ + evolutionBehavior claim.direction [2, 1, 2] = orderedUnique [2, 1, 2]) ∨ + (claim.treatment = .revise ∧ + evolutionBehavior claim.direction [2, 1, 2] ≠ orderedUnique [2, 1, 2])) + +/-- organon-map CoreReader.Engineering.evolutionKindsCases +software-engineering.evolution-meaning#p1 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6 +software-engineering.evolution-meaning#p2 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6 +-/ +theorem evolutionKindsCases : + (transform .addition originalSoftware).capabilities = ["deduplicate", "tenant batching"] ∧ + (transform .replacement originalSoftware).implementation = 1 ∧ + (transform .deletion originalSoftware).mechanisms = ["queue"] ∧ + (transform .withdrawal originalSoftware).abstractions = [] ∧ + (transform .redrawing originalSoftware).boundary = 1 ∧ + (transform .migration originalSoftware).technology = "portable store" ∧ + changes.all (fun d => decide (CanChange continuingActivity .evolvable .successor d)) = true ∧ + EvolutionClaim continuingActivity .evolvable ⟨.replacement, .successor, .preserve⟩ ∧ + EvolutionClaim continuingActivity .evolvable ⟨.redrawing, .agent, .revise⟩ ∧ + changeWork .evolvable .independent < changeWork .evolvable .coordinated := by decide + +/-- organon-map CoreReader.Engineering.evolutionDimensionsLimits +software-engineering.evolution-meaning#p1 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6 +software-engineering.evolution-meaning#p2 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6 +-/ +theorem evolutionDimensionsLimits : + changeWork .presentSimple .addition = 2 ∧ + changeWork .presentSimple .withdrawal = 17 ∧ + changeWork .evolvable .independent < changeWork .evolvable .coordinated ∧ + EvolutionPriority currentContinuing .evolvable ∧ + 9 < changeWork .evolvable .migration ∧ + CanChange continuingActivity .presentSimple .original .addition ∧ + CanChange continuingActivity .evolvable .original .addition ∧ + CanChange continuingActivity .presentSimple .original .designRevision ∧ + CanChange continuingActivity .evolvable .original .designRevision ∧ + changeWork .evolvable .designRevision < changeWork .presentSimple .designRevision ∧ + changeWork .evolvable .addition = changeWork .presentSimple .addition ∧ + (transform (.other "csv export") originalSoftware).capabilities = ["deduplicate", "csv export"] ∧ + CanChange continuingActivity .maximal .successor (.other "csv export") ∧ + ¬ CanChange continuingActivity .evolvable .successor (.other "csv export") := by + exact ⟨by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide⟩ + +theorem oneDimensionDoesNotEntailEveryDimension : + changeWork .evolvable .designRevision < changeWork .presentSimple .designRevision ∧ + ¬ (∀ d : Change, changeWork .evolvable d < changeWork .presentSimple d) := by + refine ⟨by decide, ?_⟩ + intro allDirections + exact (by decide : ¬ changeWork .evolvable .addition < changeWork .presentSimple .addition) + (allDirections .addition) + +def propagation (c : Candidate) (d : Change) : List Nat := + ((changePath c d).map EditStep.component).eraseDups + +def batchCount (items size : Nat) : Nat := (items + size - 1) / size +def staticBatch (items _runtimeSize : Nat) : Nat := batchCount items 10 +def liveBatch (items runtimeSize : Nat) : Nat := batchCount items runtimeSize + +structure StructuralEvidence where + intended : Change + participants : List Maintainer + touched : List Nat + contractObservations : List (List Nat) + observedBefore : List (List Nat) + observedAfter : List (List Nat) + understandingWork : Nat + verificationWork : Nat + boundaryGain : Nat + +def structuralEvidence (c : Candidate) (d : Change) : StructuralEvidence := { + intended := d, participants := maintainers, touched := propagation c d, + contractObservations := contractInputs, + observedBefore := contractInputs.map orderedUnique, + observedAfter := contractInputs.map (evolutionBehavior d), + understandingWork := changeWork c d, + verificationWork := ((changePath c d).filter (fun step => step.tool == .contractRunner)).length, + boundaryGain := changeWork .presentSimple d - changeWork c d } + +/-- organon-map CoreReader.Engineering.StructuralAccount +software-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +software-engineering.structural-judgment#p2 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +-/ +abbrev StructuralAccount (a : Activity) (c : Candidate) (e : StructuralEvidence) : Prop := + e.participants = a.participants ∧ e.touched = propagation c e.intended ∧ + e.contractObservations = contractInputs ∧ + e.observedBefore = contractInputs.map orderedUnique ∧ + e.observedAfter = contractInputs.map (evolutionBehavior e.intended) ∧ + e.understandingWork = changeWork c e.intended ∧ + e.verificationWork = ((changePath c e.intended).filter + (fun step => step.tool == .contractRunner)).length ∧ + e.boundaryGain = changeWork .presentSimple e.intended - changeWork c e.intended + +structure InterfaceView where + signature : String + modules : Nat + extensionPoints : Nat + principle : String + deriving DecidableEq, Repr + +def sameShape : InterfaceView := ⟨"List Nat → List Nat", 8, 12, "dependency inversion"⟩ +def moduleAssumptions : List (Nat × Nat) := + (List.range 8).map (fun component => (component, 10)) + +def modulesNeedingRevision (newSize : Nat) : List Nat := + (moduleAssumptions.filter (fun p => p.2 != newSize)).map Prod.fst + +structure Boundary where + caller : Nat + callee : Nat + contract : String + deriving DecidableEq, Repr + +structure EngineeringDesign where + metadata : InterfaceView + run : List Nat → List Nat + paths : Change → List EditStep + components : List Nat + boundaries : List Boundary + batchAssumptions : List (Nat × Nat) + +def privateDesign : EngineeringDesign := { + metadata := sameShape, run := orderedUnique, paths := changePath .presentSimple, + components := List.range 8, boundaries := [], batchAssumptions := moduleAssumptions } + +def documentedDesign : EngineeringDesign := { + privateDesign with paths := changePath .evolvable } + +def sortedDesign : EngineeringDesign := { documentedDesign with run := sortedUnique } + +/- This application has a caller at component 2 and a callee at component 1. +Editing the callee crosses that actual edge. The caller must recheck the +observable order contract in this finite case; the contract name alone is not +evidence that either the verification work or the observable equality holds. -/ +def coordinatedBoundary : Boundary := ⟨2, 1, "order-preserving queue"⟩ + +def boundaryDesign : EngineeringDesign := + { documentedDesign with boundaries := [coordinatedBoundary] } + +def crossesBoundary (design : EngineeringDesign) (direction : Change) (edge : Boundary) : Bool := + design.boundaries.contains edge && design.components.contains edge.caller && + design.components.contains edge.callee && edge.caller != edge.callee && + (design.paths direction).any (fun step => step.component == edge.callee && + (step.tool == .editor || step.tool == .compiler)) + +def boundaryObligationChecked (design : EngineeringDesign) (direction : Change) + (edge : Boundary) : Bool := + crossesBoundary design direction edge && + (design.paths direction).any (fun step => step.component == edge.caller && + step.tool == .contractRunner && step.requires == .publicContract) && + decide (PreservesFinite orderedUnique design.run) + +def omittedCallerCheck : EngineeringDesign := + { boundaryDesign with paths := fun direction => + (boundaryDesign.paths direction).filter (fun step => + !(step.component == coordinatedBoundary.caller && step.tool == .contractRunner)) } + +def otherCalleeBoundary : Boundary := { coordinatedBoundary with callee := 7 } + +def otherCalleeDesign : EngineeringDesign := + { boundaryDesign with boundaries := [otherCalleeBoundary] } + +theorem actualCrossBoundaryObligation : + crossesBoundary boundaryDesign .coordinated coordinatedBoundary = true ∧ + boundaryObligationChecked boundaryDesign .coordinated coordinatedBoundary = true ∧ + crossesBoundary omittedCallerCheck .coordinated coordinatedBoundary = true ∧ + boundaryObligationChecked omittedCallerCheck .coordinated coordinatedBoundary = false ∧ + crossesBoundary otherCalleeDesign .coordinated otherCalleeBoundary = false ∧ + boundaryObligationChecked { boundaryDesign with run := sortedUnique } + .coordinated coordinatedBoundary = false := by decide + +/-- organon-map CoreReader.Engineering.structuralCases +software-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +software-engineering.structural-judgment#p2 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +-/ +theorem structuralCases : + StructuralAccount continuingActivity .evolvable (structuralEvidence .evolvable .designRevision) ∧ + (propagation .presentSimple .designRevision).length = 3 ∧ + (propagation .evolvable .designRevision).length = 2 ∧ + (changePath .evolvable .coordinated).any (fun s => s.component == 2 && s.requires == .publicContract) = true ∧ + PreservesFinite orderedUnique orderedRefactor ∧ + (structuralEvidence .evolvable .designRevision).observedBefore ≠ + (structuralEvidence .evolvable .designRevision).observedAfter ∧ + staticBatch 21 10 = liveBatch 21 10 ∧ staticBatch 21 5 ≠ liveBatch 21 5 ∧ + changeWork .presentSimple .withdrawal = 17 ∧ + (crossesBoundary boundaryDesign .coordinated coordinatedBoundary = true ∧ + boundaryObligationChecked boundaryDesign .coordinated coordinatedBoundary = true ∧ + crossesBoundary omittedCallerCheck .coordinated coordinatedBoundary = true ∧ + boundaryObligationChecked omittedCallerCheck .coordinated coordinatedBoundary = false ∧ + crossesBoundary otherCalleeDesign .coordinated otherCalleeBoundary = false ∧ + boundaryObligationChecked { boundaryDesign with run := sortedUnique } + .coordinated coordinatedBoundary = false) := by decide + +abbrev DesignCanChange (a : Activity) (design : EngineeringDesign) + (m : Maintainer) (d : Change) : Prop := + design.paths d ≠ [] ∧ m ∈ a.participants ∧ + (design.paths d).all (fun step => + (a.available m).contains step.requires && a.tools.contains step.tool) = true + +def designWork (design : EngineeringDesign) (d : Change) : Nat := + ((design.paths d).map EditStep.units).sum + +def designModulesNeedingRevision (design : EngineeringDesign) (newSize : Nat) : List Nat := + (design.batchAssumptions.filter (fun p => p.2 != newSize)).map Prod.fst + +/- In this finite model, a facade adds an actual component, forwarding edge +and contract verification step. It preserves observable order but does not +remove the original edit/compilation work or supply private maintainer knowledge. -/ +def introduceBoundary (design : EngineeringDesign) : EngineeringDesign := { + metadata := { design.metadata with modules := design.metadata.modules + 1, extensionPoints := design.metadata.extensionPoints + 1 }, + run := fun xs => design.run (xs ++ []), + paths := fun d => if (design.paths d).isEmpty then [] else + design.paths d ++ [⟨design.components.length, .publicContract, .contractRunner, 1⟩], + components := design.components ++ [design.components.length], + boundaries := design.boundaries ++ + [⟨design.components.length, 0, design.metadata.signature⟩], + batchAssumptions := design.batchAssumptions } + +def wrappedDesign : EngineeringDesign := introduceBoundary privateDesign + +/- This second facade relocates the existing contract-verification work to +the new component. It changes the actual boundary and step locations without +reducing the work or making the private edit knowledge public. -/ +def relocateVerification (design : EngineeringDesign) : EngineeringDesign := { + introduceBoundary design with + paths := fun d => (design.paths d).map (fun step => + if step.tool = .contractRunner then { step with component := design.components.length } + else step) } + +def sameWorkDesign : EngineeringDesign := relocateVerification privateDesign + +/-- organon-map CoreReader.Engineering.structureNotCapability +software-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +software-engineering.structural-judgment#p2 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +-/ +theorem structureNotCapability : + (privateDesign.metadata.signature = sortedDesign.metadata.signature ∧ + privateDesign.run [2, 1, 2] = [2, 1] ∧ sortedDesign.run [2, 1, 2] ≠ [2, 1]) ∧ + (privateDesign.metadata.modules = privateDesign.components.length ∧ + privateDesign.batchAssumptions.length = 8 ∧ + (designModulesNeedingRevision privateDesign 5).length = 8) ∧ + (privateDesign.metadata.principle = "dependency inversion" ∧ + privateDesign.metadata = documentedDesign.metadata ∧ + ¬ DesignCanChange continuingActivity privateDesign .successor .designRevision ∧ + DesignCanChange continuingActivity documentedDesign .successor .designRevision) ∧ + (privateDesign.boundaries.length = 0 ∧ wrappedDesign.boundaries.length = 1 ∧ + wrappedDesign.components.length = 9 ∧ + wrappedDesign.boundaries = [⟨8, 0, "List Nat → List Nat"⟩] ∧ + wrappedDesign.run [2, 1, 2] = privateDesign.run [2, 1, 2] ∧ + designWork privateDesign .designRevision = 17 ∧ + designWork wrappedDesign .designRevision = 18 ∧ + ¬ designWork wrappedDesign .designRevision < designWork privateDesign .designRevision) ∧ + (sameWorkDesign.boundaries = [⟨8, 0, "List Nat → List Nat"⟩] ∧ + sameWorkDesign.components.length = 9 ∧ + sameWorkDesign.paths .designRevision ≠ privateDesign.paths .designRevision ∧ + sameWorkDesign.run [2, 1, 2] = privateDesign.run [2, 1, 2] ∧ + designWork sameWorkDesign .designRevision = designWork privateDesign .designRevision ∧ + designWork sameWorkDesign .designRevision = 17 ∧ + ¬ DesignCanChange continuingActivity sameWorkDesign .successor .designRevision) := by + exact ⟨by decide, by decide, by decide, by decide, by decide⟩ + +/-- organon-map CoreReader.Engineering.contractPreservation +software-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +-/ +theorem contractPreservation {Input Output : Type} (scope : Input → Prop) + (old new : Input → Output) (observations : ∀ x, scope x → new x = old x) : + PreservesOn scope old new := observations + +theorem changedObservationNotPreserved {Input Output : Type} (scope : Input → Prop) + (old new : Input → Output) (x : Input) (inside : scope x) + (different : new x ≠ old x) : ¬ PreservesOn scope old new := by + intro h + exact different (h x inside) + +theorem contractRevisionObligations (old new : ObservableContract) + (r : ContractRevision) (account : ContractChangeAccount old new r) + (changed : ¬ PreservesContractFinite old new) : + RevisionDuties old new r := account.resolve_left changed + +def retiredBehavior (xs : List Nat) : List Nat := + if xs = [99] then [] else orderedUnique xs + +/-- organon-map CoreReader.Engineering.contractCases +software-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +-/ +theorem contractCases : + ContractChangeAccount originalContract refactoredContract normalRevision ∧ + ContractChangeAccount originalContract revisedContract normalRevision ∧ + ¬ ContractChangeAccount originalContract revisedContract { normalRevision with affected := [] } ∧ + PreservesFinite orderedUnique retiredBehavior ∧ retiredBehavior [99] ≠ orderedUnique [99] ∧ + ContractChangeAccount originalContract revisedContract { normalRevision with procedure := "paired audit" } := by decide + +/-- organon-map CoreReader.Engineering.contractDistinctions +software-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +-/ +theorem contractDistinctions : + PreservesFinite orderedUnique orderedRefactor ∧ + ¬ PreservesFinite orderedUnique sortedUnique ∧ + retry originalContract 3 = false ∧ retry revisedContract 3 = true ∧ + ¬ PreservesContractFinite originalContract revisedContract ∧ + affectedParties originalContract revisedContract = ["queue consumer", "queue operator"] ∧ + ¬ ContractChangeAccount originalContract revisedContract + { normalRevision with affected := ["queue consumer"] } ∧ + ¬ ContractChangeAccount originalContract revisedContract + { normalRevision with oldFailureLimit := 5, recordedOldFailureLimit := 5 } ∧ + ContractChangeAccount originalContract revisedContract normalRevision ∧ + PreservesFinite orderedUnique retiredBehavior ∧ retiredBehavior [99] ≠ orderedUnique [99] := by decide + +/- Revision records time-indexed evidence rather than changing a past event. +Judgment is choice under current evidence; forecast truth is a separate value. -/ +structure RevisionState where + time : Nat + forecast : List Change + maintenance : Nat + maintainers : List Maintainer + migrationCost : Nat + objectiveCapacity : Nat + choice : Candidate + deriving DecidableEq, Repr +structure RevisionRecord where + software : String + old : RevisionState + current : RevisionState + recordedOld : RevisionState + recordedCurrent : RevisionState + predictedBatchCount : Nat + actualBatchCount : Nat + reportedPredictionSucceeded : Bool + consideredChanges : List Change + criticizedDirections : List Change + +abbrev MaterialGroundsChanged (old current : RevisionState) : Prop := + old.forecast ≠ current.forecast ∨ old.maintenance ≠ current.maintenance ∨ + old.maintainers ≠ current.maintainers ∨ + old.migrationCost ≠ current.migrationCost ∨ old.objectiveCapacity ≠ current.objectiveCapacity + +def oldState : RevisionState := ⟨0, [.designRevision], 6, [.original], 8, 12, .evolvable⟩ +def newState : RevisionState := ⟨1, [.deletion], 2, [.successor, .agent], 14, 10, .presentSimple⟩ + +structure HistoricalEvidence where + software : String + state : RevisionState + predictedBatchCount : Nat + actualBatchCount : Nat + +/- Independent event content: the recorded predictor used a fixed batch size +of ten; the actual event had runtime size five and twenty-one queue items. -/ +def observedHistory : HistoricalEvidence := + ⟨"order-preserving queue", oldState, staticBatch 21 5, liveBatch 21 5⟩ + +abbrev RevisionAccountAgainst (history : HistoricalEvidence) (r : RevisionRecord) : Prop := + r.software = history.software ∧ + r.old = history.state ∧ r.recordedOld = history.state ∧ + r.predictedBatchCount = history.predictedBatchCount ∧ + r.actualBatchCount = history.actualBatchCount ∧ + r.old.time < r.current.time ∧ r.recordedCurrent = r.current ∧ + (r.old.choice ≠ r.current.choice → MaterialGroundsChanged r.old r.current) ∧ + r.reportedPredictionSucceeded = decide (history.predictedBatchCount = history.actualBatchCount) ∧ + r.consideredChanges.all (fun d => r.criticizedDirections.contains d) = true + +/-- organon-map CoreReader.Engineering.RevisionAccount +software-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +software-engineering.revision#p1 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +-/ +abbrev RevisionAccount (r : RevisionRecord) : Prop := RevisionAccountAgainst observedHistory r + +theorem failedHistoryNotRewritten (history : HistoricalEvidence) (r : RevisionRecord) + (account : RevisionAccountAgainst history r) + (failed : history.predictedBatchCount ≠ history.actualBatchCount) : + r.reportedPredictionSucceeded = false := by + simpa [failed] using account.2.2.2.2.2.2.2.2.1 + +def revisionRecord : RevisionRecord := { + software := "order-preserving queue", + old := oldState, current := newState, recordedOld := oldState, recordedCurrent := newState, + predictedBatchCount := staticBatch 21 5, actualBatchCount := liveBatch 21 5, + reportedPredictionSucceeded := false, + consideredChanges := changes, criticizedDirections := changes } + +abbrev SupportedAlternative (gs : List DirectionGround) (d : Change) : Prop := credible gs d + +abbrev RetentionJustified (ctx : Context) (alternatives : List Change) : Prop := + alternatives.all (fun d => !decide (SupportedAlternative ctx.evidence d)) = true ∨ + JustifiedDeparture ctx .evolvable + +def stableRecord : RevisionRecord := { revisionRecord with + current := { newState with choice := .evolvable }, + recordedCurrent := { newState with choice := .evolvable } } + +/-- organon-map CoreReader.Engineering.revisionCases +software-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +software-engineering.revision#p1 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +-/ +theorem revisionCases : + RevisionAccount revisionRecord ∧ + revisionRecord.old.forecast ≠ revisionRecord.current.forecast ∧ + revisionRecord.old.maintenance ≠ revisionRecord.current.maintenance ∧ + revisionRecord.old.maintainers ≠ revisionRecord.current.maintainers ∧ + revisionRecord.old.migrationCost ≠ revisionRecord.current.migrationCost ∧ + revisionRecord.old.objectiveCapacity ≠ revisionRecord.current.objectiveCapacity ∧ + revisionRecord.predictedBatchCount ≠ revisionRecord.actualBatchCount ∧ + RetentionJustified currentContinuing [.other "quantum backend"] ∧ + RetentionJustified (threatened .migration) [.migration] := by decide + +def observations : List (Nat × Nat) := [(21, 10), (30, 10), (40, 10)] +def revisionsMade : List Nat := [1, 2, 3] +def agreedBatch (reviewers : List Maintainer) (items size : Nat) : List Nat := + reviewers.map (fun _ => staticBatch items size) + +def rewrittenOldRecord : RevisionRecord := { revisionRecord with + old := { oldState with forecast := [.deletion] }, + recordedOld := { oldState with forecast := [.deletion] } } + +def rewrittenPredictionRecord : RevisionRecord := { revisionRecord with + predictedBatchCount := 5, reportedPredictionSucceeded := true } + +def rewrittenObservationRecord : RevisionRecord := { revisionRecord with + actualBatchCount := 3, reportedPredictionSucceeded := true } + +def unrelatedSoftwareRecord : RevisionRecord := { + revisionRecord with software := "unrelated batch processor" } + +theorem historicalTamperingRejected : + RevisionAccount revisionRecord ∧ + ¬ RevisionAccount rewrittenOldRecord ∧ + ¬ RevisionAccount rewrittenPredictionRecord ∧ + ¬ RevisionAccount rewrittenObservationRecord ∧ + observedHistory.predictedBatchCount = 3 ∧ observedHistory.actualBatchCount = 5 ∧ + ¬ RevisionAccount unrelatedSoftwareRecord := by + exact ⟨by decide, by decide, by decide, by decide, by decide, by decide, by decide⟩ + +/-- organon-map CoreReader.Engineering.revisionLimits +software-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +software-engineering.revision#p1 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +-/ +theorem revisionLimits : + RevisionAccount revisionRecord ∧ + ¬ RevisionAccount { revisionRecord with reportedPredictionSucceeded := true } ∧ + revisionsMade.length = 3 ∧ + agreedBatch maintainers 21 5 = [3, 3, 3] ∧ liveBatch 21 5 = 5 ∧ + observations.all (fun p => staticBatch p.1 p.2 == liveBatch p.1 p.2) = true ∧ + staticBatch 21 5 ≠ liveBatch 21 5 ∧ + RevisionAccount stableRecord ∧ stableRecord.current.choice = stableRecord.old.choice ∧ + RetentionJustified currentContinuing [.other "quantum backend"] := by + refine ⟨by decide, ?_, by decide, by decide, by decide, by decide, + by decide, by decide, by decide, by decide⟩ + dsimp [RevisionAccount, RevisionAccountAgainst, observedHistory, MaterialGroundsChanged, revisionRecord, oldState, newState] + decide + +def groundedChanges : DirectionGround → List Change + | .plan _ ds | .knowledge _ ds _ | .history _ ds | .other _ ds => ds + +def currentRevisionState (ctx : Context) (chosen : Candidate) : RevisionState := { + time := 1, forecast := ctx.evidence.flatMap groundedChanges, + maintenance := ctx.activity.scheduledMaintenance, maintainers := ctx.activity.participants, + migrationCost := cost chosen .migration, + objectiveCapacity := ctx.limits.capacity .migration, + choice := chosen } + +def revisionFor (ctx : Context) (chosen : Candidate) : RevisionRecord := { + stableRecord with software := ctx.activity.software, current := currentRevisionState ctx chosen, recordedCurrent := currentRevisionState ctx chosen } + +theorem revisionContextIdentity : + (revisionFor currentContinuing .evolvable).software = currentContinuing.activity.software ∧ + (revisionFor currentContinuing .evolvable).software = observedHistory.software ∧ (revisionFor currentContinuing .evolvable).current.maintenance = + currentContinuing.activity.scheduledMaintenance ∧ + (revisionFor currentContinuing .evolvable).current.maintainers = currentContinuing.activity.participants ∧ + (revisionFor currentContinuing .evolvable).current.migrationCost = cost .evolvable .migration ∧ + (revisionFor currentContinuing .evolvable).current.objectiveCapacity = + currentContinuing.limits.capacity .migration ∧ + (revisionFor currentContinuing .evolvable).current.choice = .evolvable ∧ + RevisionAccount (revisionFor currentContinuing .evolvable) := by decide + +/- Whole domain satisfaction keeps actual subject, credibility, account and +revision duties. The same context is passed to priority and every domain duty. +Application account choices below are finite records, not universal claims. -/ +abbrev DomainSatisfied (ctx : Context) (chosen : Candidate) : Prop := + ActivityScope ctx.activity ∧ EvolutionPriority ctx chosen ∧ + credible ctx.evidence .designRevision ∧ + (ctx.departure ≠ none → JustifiedDeparture ctx .evolvable) ∧ + EvolutionClaim ctx.activity chosen ⟨.designRevision, .successor, .revise⟩ ∧ + StructuralAccount ctx.activity chosen (structuralEvidence chosen .designRevision) ∧ + ContractChangeAccount (orderContract (behavior chosen)) (evolutionContract .designRevision) normalRevision ∧ + RevisionAccount (revisionFor ctx chosen) + +theorem currentDomainSatisfied : DomainSatisfied currentContinuing .evolvable := by + refine ⟨by decide, by decide, by decide, ?_, by decide, by decide, by decide, by decide⟩ + simp [currentContinuing] + +end CoreReader.Engineering +``` + + + + **L1** Loads Lean's standard library for lists, arithmetic, strings and decidable finite checks used throughout the model. + + + **L3** Places the application vocabulary and results in CoreReader.Engineering, keeping them distinct from the inherited Core interfaces. + + + **L5** The work numbers count stipulated edit operations in a bounded scenario; they are neither a universal conversion between burdens nor measurements of future engineering performance. + + + **L6** The work numbers count stipulated edit operations in a bounded scenario; they are neither a universal conversion between burdens nor measurements of future engineering performance. + + + **L7** The three maintainer roles distinguish the original author, a successor and an agent, so original-author editability need not imply continuing maintenance capability. + + + **L8** The three maintainer roles distinguish the original author, a successor and an agent, so original-author editability need not imply continuing maintenance capability. + + + **L9** Automatically provides equality decisions and printable representations for Maintainer; these support concrete case evaluation, not a philosophical claim about that type. + + + **L10** The available operations distinguish editing, compilation, contract checking and migration; a change path must have the required tool available. + + + **L11** The available operations distinguish editing, compilation, contract checking and migration; a change path must have the required tool available. + + + **L12** Automatically provides equality decisions and printable representations for Tool; these support concrete case evaluation, not a philosophical claim about that type. + + + **L13** Knowledge distinguishes private implementation layout from the public contract and documented change/migration guides; these prerequisites will separate maintainer capabilities. + + + **L14** Knowledge distinguishes private implementation layout from the public contract and documented change/migration guides; these prerequisites will separate maintainer capabilities. + + + **L15** Automatically provides equality decisions and printable representations for Knowledge; these support concrete case evaluation, not a philosophical claim about that type. + + + **L16** The change vocabulary includes six major evolution operations, independent/coordinated work, design revision and an open named alternative. The nine-element examples do not exhaust the type. + + + **L17** The change vocabulary includes six major evolution operations, independent/coordinated work, design revision and an open named alternative. The nine-element examples do not exhaust the type. + + + **L18** The change vocabulary includes six major evolution operations, independent/coordinated work, design revision and an open named alternative. The nine-element examples do not exhaust the type. + + + **L19** Automatically provides equality decisions and printable representations for Change; these support concrete case evaluation, not a philosophical claim about that type. + + + **L20** Three candidate designs permit comparison of present simplicity, credible evolution support and extra registered extensibility; their merits are supplied by later behavior and work data. + + + **L21** Three candidate designs permit comparison of present simplicity, credible evolution support and extra registered extensibility; their merits are supplied by later behavior and work data. + + + **L22** Automatically provides equality decisions and printable representations for Candidate; these support concrete case evaluation, not a philosophical claim about that type. + + + **L23** Seven distinct burden dimensions cover understanding, construction, diagnosis, verification, coordination, operation and migration; no sum across them is required. + + + **L24** Seven distinct burden dimensions cover understanding, construction, diagnosis, verification, coordination, operation and migration; no sum across them is required. + + + **L25** Seven distinct burden dimensions cover understanding, construction, diagnosis, verification, coordination, operation and migration; no sum across them is required. + + + **L26** Automatically provides equality decisions and printable representations for Burden; these support concrete case evaluation, not a philosophical claim about that type. + + + **L28** The concrete activity includes all three maintainer roles, making successor and agent claims nonvacuous. + + + **L29** Registers nine ordinary changes for the finite examples; named other changes can still be represented separately. + + + **L30** Registers nine ordinary changes for the finite examples; named other changes can still be represented separately. + + + **L31** Lists every represented cost dimension so threat searches examine each dimension independently. + + + **L32** Lists every represented cost dimension so threat searches examine each dimension independently. + + + **L34** An engineering activity groups the people or agents, software, tools, knowledge and lifecycle expectations relevant to a capability claim. + + + **L35** Records the maintainers participating in this activity; membership is later required for individual change capability. + + + **L36** Identifies the software being maintained; this identity also binds later revision reports to their task. + + + **L37** Records available tools rather than assuming every requested tool exists. + + + **L38** Assigns knowledge separately to each maintainer, allowing an original author to know private details unavailable to successors. + + + **L39** Counts scheduled releases as one concrete indicator of continuing development expectations. + + + **L40** Counts scheduled maintenance work independently of releases. + + + **L41** An optional finite run bound represents genuinely bounded use; absence of a bound alone is not the definition of continuing activity. + + + **L42** Keeps a descriptive label separate from lifecycle facts, allowing the misleading label temporary to be tested. + + + **L44** Begins a provenance comment attaching CoreReader.Engineering.ActivityScope to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence. + + + **L45** Records the source reference software-engineering.purpose/p1 for CoreReader.Engineering.ActivityScope, with direct-body SHA256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b. This is a traceability binding, not a new premise or semantic proof. + + + **L46** Records the source reference software-engineering.purpose/p2 for CoreReader.Engineering.ActivityScope, with direct-body SHA256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b. This is a traceability binding, not a new premise or semantic proof. + + + **L47** Records the source reference software-engineering.purpose/p3 for CoreReader.Engineering.ActivityScope, with direct-body SHA256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b. This is a traceability binding, not a new premise or semantic proof. + + + **L48** Closes the source-mapping comment for CoreReader.Engineering.ActivityScope; executable declarations resume after the comment. + + + **L49** Activity scope is a concrete admissibility condition for the engineering subject, rather than an intrinsic intention attributed to code. + + + **L50** Requires actual participants, a nonempty software identifier and some available tools. + + + **L51** Every listed maintainer must have some available knowledge; this does not yet show the knowledge suffices for every change. + + + **L53** Continuing activity means both planned releases and maintenance are positive in this model; the name of the activity is irrelevant. + + + **L54** Continuing activity means both planned releases and maintenance are positive in this model; the name of the activity is irrelevant. + + + **L56** A bounded lifecycle requires a declared finite run limit and zero planned releases and maintenance; a temporary label alone cannot satisfy it. + + + **L57** A bounded lifecycle requires a declared finite run limit and zero planned releases and maintenance; a temporary label alone cannot satisfy it. + + + **L58** A bounded lifecycle requires a declared finite run limit and zero planned releases and maintenance; a temporary label alone cannot satisfy it. + + + **L60** The continuing queue activity includes all maintainers and all four tools; its software identity is the order-preserving queue. + + + **L61** The continuing queue activity includes all maintainers and all four tools; its software identity is the order-preserving queue. + + + **L62** The continuing queue activity includes all maintainers and all four tools; its software identity is the order-preserving queue. + + + **L63** Only the original maintainer receives privateLayout. Successors and agents have public contracts and guides, creating a real prerequisite difference. + + + **L64** Only the original maintainer receives privateLayout. Successors and agents have public contracts and guides, creating a real prerequisite difference. + + + **L65** Only the original maintainer receives privateLayout. Successors and agents have public contracts and guides, creating a real prerequisite difference. + + + **L66** The activity schedules three releases and six maintenance units, so both continuing-lifecycle indicators are positive. + + + **L67** There is no finite run bound even though the descriptive label says temporary; later cases reject that label as evidence of a bounded lifecycle. + + + **L69** The one-shot variant removes all planned releases and maintenance and sets a single-run limit, creating a genuinely bounded example. + + + **L70** The one-shot variant removes all planned releases and maintenance and sets a single-run limit, creating a genuinely bounded example. + + + **L71** The one-shot variant removes all planned releases and maintenance and sets a single-run limit, creating a genuinely bounded example. + + + **L72** The prototype retains the zero-maintenance bounded setup but allows four runs. + + + **L73** The prototype retains the zero-maintenance bounded setup but allows four runs. + + + **L74** The retiring service uses the same bounded setup with two remaining runs. + + + **L75** The retiring service uses the same bounded setup with two remaining runs. + + + **L77** Each edit step records where work occurs, which knowledge and tool it needs, and its assigned work units. + + + **L78** Identifies the component touched by this work step. + + + **L79** States the knowledge prerequisite that the acting maintainer must possess. + + + **L80** States the tool needed for this step. + + + **L81** Assigns a natural-number cost to this explicit operation; later totals sum these units. + + + **L82** Automatically provides equality decisions and printable representations for EditStep; these support concrete case evaluation, not a philosophical claim about that type. + + + **L84** Builds an explicit work path for a candidate and intended change, rather than assigning capability from a design label. + + + **L85** PresentSimple requires private layout knowledge; the other designs use the change guide, which successors possess. + + + **L86** Every ordinary path starts with one edit at component 0 and one public-contract check there, each costing one unit. + + + **L87** Every ordinary path starts with one edit at component 0 and one public-contract check there, each costing one unit. + + + **L88** Dispatch on the requested Change to choose its corresponding editing path; the following branches distinguish the different directions. + + + **L89** Addition and independent change use only that two-unit base path. + + + **L90** Replacement and deletion add a one-unit compilation at component 1 using the design's selected guide. + + + **L91** Coordinated change adds compilation at component 1 and public-contract verification at component 2, each costing three units. + + + **L92** Migration adds an eight-unit migration-runner step requiring the migration guide. + + + **L93** Withdrawal, boundary redrawing and design revision branch on the selected design; this is where simplicity and evolution have different work paths. + + + **L94** Withdrawal, boundary redrawing and design revision branch on the selected design; this is where simplicity and evolution have different work paths. + + + **L95** The simple design adds private-guide edit and compilation plus a public-contract check, each costing five units, bringing total work to seventeen. + + + **L96** The simple design adds private-guide edit and compilation plus a public-contract check, each costing five units, bringing total work to seventeen. + + + **L97** Other designs instead add a two-unit edit and two-unit public-contract check at component 1, totaling six units with the base. + + + **L98** The open change constructor receives a concrete special case only for csv export. + + + **L99** The open change constructor receives a concrete special case only for csv export. + + + **L100** Maximal handles CSV export with a documented migration-guide compilation at component 3 costing two extra units. + + + **L101** Other designs require privateLayout and twenty extra compilation units for CSV export, so a successor lacks that path's prerequisite. + + + **L102** Unrecognized names receive no path; the nonempty-path requirement prevents vacuous capability from an empty list. + + + **L104** Total work is the sum of the actual path steps' assigned units, not the number of modules or extension points. + + + **L105** Total work is the sum of the actual path steps' assigned units, not the number of modules or extension points. + + + **L107** Individual change capability is indexed by the actual activity, design, maintainer and intended change. + + + **L108** Capability requires a nonempty path, participating maintainer, and every path step's knowledge and tool prerequisites; a failed prerequisite blocks the claim. + + + **L109** Capability requires a nonempty path, participating maintainer, and every path step's knowledge and tool prerequisites; a failed prerequisite blocks the claim. + + + **L111** Continuing capability requires a nonempty path executable with the knowledge and tools of every listed maintainer; activity scope supplies the separate nonempty-participant condition. + + + **L112** Continuing capability requires a nonempty path executable with the knowledge and tools of every listed maintainer; activity scope supplies the separate nonempty-participant condition. + + + **L113** Continuing capability requires a nonempty path executable with the knowledge and tools of every listed maintainer; activity scope supplies the separate nonempty-participant condition. + + + **L115** Maximality will concern only a registered finite direction set. CSV has concrete work and state content; unsupported names cannot acquire capability from an empty path. + + + **L116** Maximality will concern only a registered finite direction set. CSV has concrete work and state content; unsupported names cannot acquire capability from an empty path. + + + **L117** Maximality will concern only a registered finite direction set. CSV has concrete work and state content; unsupported names cannot acquire capability from an empty path. + + + **L118** Adds the named CSV export direction to the nine ordinary changes, producing ten registered directions. + + + **L119** Keeps exactly those registered directions that every continuing maintainer can execute for the chosen design. + + + **L120** Keeps exactly those registered directions that every continuing maintainer can execute for the chosen design. + + + **L121** A candidate has maximum registered capability when it supports every direction in that fixed list; this is not maximality over every conceivable change. + + + **L122** A candidate has maximum registered capability when it supports every direction in that fixed list; this is not maximality over every conceivable change. + + + **L124** The passive software function is separated from maintainers' selected intentions; the example does not attribute generative orientation to every artifact. + + + **L125** The passive software function is separated from maintainers' selected intentions; the example does not attribute generative orientation to every artifact. + + + **L126** The artifact returns its input unchanged and makes no change proposal. + + + **L128** Each represented maintainer intends design revision and migration; this is the activity's explicit selected intention. + + + **L130** Actions distinguish proposing a change from executing software to obtain an output list. + + + **L131** Actions distinguish proposing a change from executing software to obtain an output list. + + + **L132** Actions distinguish proposing a change from executing software to obtain an output list. + + + **L133** Automatically provides equality decisions and printable representations for EngineeringAction; these support concrete case evaluation, not a philosophical claim about that type. + + + **L135** Maintainer intentions become actual propose actions for each selected direction. + + + **L136** Maintainer intentions become actual propose actions for each selected direction. + + + **L138** The artifact's only action executes its passive function; the action list contains no proposal constructor. + + + **L139** The artifact's only action executes its passive function; the action list contains no proposal constructor. + + + **L141** Begins a provenance comment attaching CoreReader.Engineering.subjectLifecycleCases to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence. + + + **L142** Records the source reference software-engineering.purpose/p1 for CoreReader.Engineering.subjectLifecycleCases, with direct-body SHA256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b. This is a traceability binding, not a new premise or semantic proof. + + + **L143** Records the source reference software-engineering.purpose/p2 for CoreReader.Engineering.subjectLifecycleCases, with direct-body SHA256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b. This is a traceability binding, not a new premise or semantic proof. + + + **L144** Records the source reference software-engineering.purpose/p3 for CoreReader.Engineering.subjectLifecycleCases, with direct-body SHA256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b. This is a traceability binding, not a new premise or semantic proof. + + + **L145** Closes the source-mapping comment for CoreReader.Engineering.subjectLifecycleCases; executable declarations resume after the comment. + + + **L146** Collects concrete positive scope, maintainer-capability and lifecycle cases for the shared queue activity. + + + **L147** The continuing activity satisfies the nonempty engineering-subject scope condition. + + + **L148** The successor has the tools and public knowledge needed for evolvable design revision. + + + **L149** The agent also has the prerequisites for that same design revision. + + + **L150** The concrete activity remains continuing even while carrying the temporary label. + + + **L151** The continuing activity is not bounded, while the one-shot, prototype and retiring variants meet their explicit finite lifecycle conditions. + + + **L152** The continuing activity is not bounded, while the one-shot, prototype and retiring variants meet their explicit finite lifecycle conditions. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope. + + + **L154** Begins a provenance comment attaching CoreReader.Engineering.subjectLimits to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence. + + + **L155** Records the source reference software-engineering.purpose/p1 for CoreReader.Engineering.subjectLimits, with direct-body SHA256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b. This is a traceability binding, not a new premise or semantic proof. + + + **L156** Records the source reference software-engineering.purpose/p2 for CoreReader.Engineering.subjectLimits, with direct-body SHA256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b. This is a traceability binding, not a new premise or semantic proof. + + + **L157** Records the source reference software-engineering.purpose/p3 for CoreReader.Engineering.subjectLimits, with direct-body SHA256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b. This is a traceability binding, not a new premise or semantic proof. + + + **L158** Closes the source-mapping comment for CoreReader.Engineering.subjectLimits; executable declarations resume after the comment. + + + **L159** Collects counterexamples to inferring continuing capability or software intention from weaker facts. + + + **L160** The original maintainer can revise the simple design because private layout knowledge is available to that maintainer. + + + **L161** The successor cannot perform that same simple-design revision because the private prerequisite is absent. + + + **L162** Consequently the simple design does not support this revision for every continuing maintainer. + + + **L163** The temporary label coexists with failure of the actual bounded-lifecycle condition. + + + **L164** The agent's intention is nonempty, while the passive artifact still merely returns [2,1]. + + + **L165** A design-revision proposal occurs among agent actions but not among the artifact's execution actions. + + + **L166** A design-revision proposal occurs among agent actions but not among the artifact's execution actions. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope. + + + **L168** Credibility is parameterized by an articulability test and a support relation; the following examples do not validate every possible supplied relation. + + + **L169** Credibility is parameterized by an articulability test and a support relation; the following examples do not validate every possible supplied relation. + + + **L170** Begins a provenance comment attaching CoreReader.Engineering.CredibleDirection to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence. + + + **L171** Records the source reference software-engineering.evolution-priority/p2 for CoreReader.Engineering.CredibleDirection, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof. + + + **L172** Records the source reference software-engineering.evolution-priority/p3 for CoreReader.Engineering.CredibleDirection, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof. + + + **L173** Closes the source-mapping comment for CoreReader.Engineering.CredibleDirection; executable declarations resume after the comment. + + + **L174** Allows any ground type, preserving an open set of possible credibility sources. + + + **L175** The application supplies separate tests for whether a ground is articulated and whether it supports the intended direction. + + + **L176** A direction is credible here when at least one listed ground passes both tests for that same direction. + + + **L177** A direction is credible here when at least one listed ground passes both tests for that same direction. + + + **L179** The concrete examples instantiate ground records without making these constructors an exhaustive philosophical taxonomy. + + + **L180** A plan records a release number and committed changes. + + + **L181** Domain knowledge records the relevant service, affected changes and a mechanism account. + + + **L182** History records a service and observed change directions. + + + **L183** An other constructor keeps room for a separately articulated account and its supported changes. + + + **L184** Automatically provides equality decisions and printable representations for DirectionGround; these support concrete case evaluation, not a philosophical claim about that type. + + + **L186** Checks the concrete ground records for the identifying content required by this application. + + + **L187** A plan must name a positive release and at least one committed direction. + + + **L188** Knowledge must identify a service, some affected directions and a nonempty mechanism account. + + + **L189** A history needs a named service and some observations. + + + **L190** An other ground needs a nonempty account and direction list. + + + **L192** Interprets support according to this bounded application's concrete records, rather than deriving arbitrary real-world relevance from strings. + + + **L193** A positive-release plan supports a direction only when it explicitly contains that direction. + + + **L194** The designated queue knowledge supports listed directions when its mechanism is tenant-config-reload; this named mechanism is an application interpretation. + + + **L195** The designated queue knowledge supports listed directions when its mechanism is tenant-config-reload; this named mechanism is an application interpretation. + + + **L196** A queue history supports a direction when it occurs at least twice in the recorded list; this is a chosen finite support rule. + + + **L197** The particular reviewed customer migration account supports only directions listed in that account. + + + **L199** The initial grounds commit release 2 to design revision and migration. + + + **L200** The revised forecast commits release 3 to deletion instead. + + + **L201** Specializes generic credibility to DirectionGround using the concrete articulation and support interpretations above. + + + **L202** Specializes generic credibility to DirectionGround using the concrete articulation and support interpretations above. + + + **L204** The chosen accommodation test requires credible direction, positive objective gain and investment no greater than that gain; it is a local sufficient criterion, not a universal numerical exchange rule. + + + **L205** The chosen accommodation test requires credible direction, positive objective gain and investment no greater than that gain; it is a local sufficient criterion, not a universal numerical exchange rule. + + + **L206** The chosen accommodation test requires credible direction, positive objective gain and investment no greater than that gain; it is a local sufficient criterion, not a universal numerical exchange rule. + + + **L208** Begins a provenance comment attaching CoreReader.Engineering.credibilityCases to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence. + + + **L209** Records the source reference software-engineering.evolution-priority/p2 for CoreReader.Engineering.credibilityCases, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof. + + + **L210** Records the source reference software-engineering.evolution-priority/p3 for CoreReader.Engineering.credibilityCases, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof. + + + **L211** Closes the source-mapping comment for CoreReader.Engineering.credibilityCases; executable declarations resume after the comment. + + + **L212** Bundles positive plan, knowledge and history support with unsupported-imagination and revised-forecast contrasts. + + + **L213** The actual release-2 plan supports design revision. + + + **L214** The designated queue mechanism provides the declared knowledge support for design revision. + + + **L215** Two recorded queue migrations meet the concrete historical support criterion. + + + **L216** An empty ground list does not support an imagined quantum backend. + + + **L217** The changed forecast supports deletion and no longer supports design revision. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope. + + + **L219** Assigns present abstraction complexity 1, 3 and 30 to simple, evolvable and maximal candidates; these are scenario parameters. + + + **L220** Assigns present abstraction complexity 1, 3 and 30 to simple, evolvable and maximal candidates; these are scenario parameters. + + + **L222** Only the simple candidate is currently implemented, allowing credibility without multiple existing implementations. + + + **L224** The priority rule compares each burden against its own capacity instead of converting them into one score. + + + **L225** A cost vector can assign a separate natural-number amount to each burden; this auxiliary structure does not force aggregation. + + + **L226** A cost vector can assign a separate natural-number amount to each burden; this auxiliary structure does not force aggregation. + + + **L227** Cost limits pair a capacity with an identified objective for each burden, so a claimed threat must concern something concrete. + + + **L228** Cost limits pair a capacity with an identified objective for each burden, so a claimed threat must concern something concrete. + + + **L229** Cost limits pair a capacity with an identified objective for each burden, so a claimed threat must concern something concrete. + + + **L231** Every burden of the simple baseline costs one unit in this scenario. + + + **L232** Every burden of the simple baseline costs one unit in this scenario. + + + **L233** Evolvable understanding cost is three units. + + + **L234** Evolvable construction cost is four units. + + + **L235** Evolvable diagnosis cost is two units. + + + **L236** Evolvable verification cost is four units. + + + **L237** Evolvable coordination cost is two units. + + + **L238** Evolvable operational cost is two units. + + + **L239** Evolvable migration cost is eight units, illustrating a burden that need not be cheap. + + + **L240** The maximal candidate costs forty units in every represented burden. + + + **L242** The ordinary context has capacity twelve for each burden, enough for the evolvable candidate's assigned costs. + + + **L243** The ordinary context has capacity twelve for each burden, enough for the evolvable candidate's assigned costs. + + + **L244** Assign each Burden its objective name by matching on the burden; the following branches supply the distinct engineering objectives. + + + **L245** The understanding limit concerns successor onboarding capacity. + + + **L246** Construction capacity is tied to preparing a release. + + + **L247** Diagnosis capacity concerns the incident diagnosis window. + + + **L248** Verification capacity concerns checking a release. + + + **L249** Coordination capacity concerns available teamwork. + + + **L250** Operational capacity concerns the runtime resource budget. + + + **L251** Migration capacity concerns eventual retirement migration. + + + **L253** Necessary requirements remain separate from the value preference for evolution. + + + **L254** Indicates whether the identified output-order contract is required. + + + **L255** Bounds the permitted number of unsafe operations. + + + **L256** Bounds observed latency. + + + **L257** Sets the required minimum retention. + + + **L259** The ordinary requirements demand order, zero unsafe operations, latency at most ten and retention at least thirty. + + + **L260** All three candidate behaviors remove duplicate list values in the given order; this local equality does not equate their maintenance paths or costs. + + + **L262** Profiles are observations stipulated for this scenario; later variants independently violate each of the four requirement gates. + + + **L263** Profiles are observations stipulated for this scenario; later variants independently violate each of the four requirement gates. + + + **L264** A profile records the four behavior/safety/performance quantities relevant to these requirements. + + + **L265** Stores the output observed on the identified order test. + + + **L266** Stores the number of unsafe operations in this profile. + + + **L267** Stores this profile's latency observation. + + + **L268** Stores this profile's retention observation. + + + **L270** Each original profile observes de-duplication on [2,1,2], zero unsafe operations, latency five and retention thirty. + + + **L271** Meeting requirements checks the order result [2,1] whenever order is required; it does not impose order when the requirement is disabled. + + + **L272** Meeting requirements checks the order result [2,1] whenever order is required; it does not impose order when the requirement is disabled. + + + **L273** Safety and latency must stay at or below their maxima, and retention must reach its minimum. + + + **L274** Safety and latency must stay at or below their maxima, and retention must reach its minimum. + + + **L276** A context binds the activity, requirements, evidence, costs and selected departure account used by the domain norm. + + + **L277** Carries the actual engineering activity and its maintainer conditions. + + + **L278** Carries the relevant necessary requirements. + + + **L279** Carries the grounds for credible future directions. + + + **L280** Carries per-burden objective capacities. + + + **L281** Optionally identifies the burden used to justify departing from evolution priority. + + + **L282** Provides candidate observations, defaulting to the ordinary profiles but allowing explicit test variants. + + + **L284** The shared ordinary context uses the continuing queue, normal requirements, release-2 grounds and capacity-twelve limits, with no claimed departure. + + + **L285** The shared ordinary context uses the continuing queue, normal requirements, release-2 grounds and capacity-twelve limits, with no claimed departure. + + + **L286** The shared ordinary context uses the continuing queue, normal requirements, release-2 grounds and capacity-twelve limits, with no claimed departure. + + + **L288** A concrete threat requires added cost above both the simple baseline and the named objective's capacity; naming a burden without those inequalities is insufficient. + + + **L289** A concrete threat requires added cost above both the simple baseline and the named objective's capacity; naming a burden without those inequalities is insufficient. + + + **L290** A concrete threat requires added cost above both the simple baseline and the named objective's capacity; naming a burden without those inequalities is insufficient. + + + **L292** A threat exists if one of the seven represented burden dimensions meets the concrete-threat condition. + + + **L293** A threat exists if one of the seven represented burden dimensions meets the concrete-threat condition. + + + **L295** Begins a provenance comment attaching CoreReader.Engineering.JustifiedDeparture to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence. + + + **L296** Records the source reference software-engineering.evolution-priority/p3 for CoreReader.Engineering.JustifiedDeparture, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof. + + + **L297** Closes the source-mapping comment for CoreReader.Engineering.JustifiedDeparture; executable declarations resume after the comment. + + + **L298** Define justified departure for this context and candidate through a recorded burden whose concrete cost threat must hold. + + + **L299** Inspect this same context’s departure option to distinguish an absent explanation from a named burden. + + + **L300** With no recorded departure burden, justification is False; absence supplies no exception. + + + **L301** For the recorded burden b, require ConcreteThreat for this exact context, candidate and burden. + + + **L303** Supplies a decision procedure for the departure proposition so finite examples can be checked by computation. + + + **L304** Exposes the match on the optional selected burden in JustifiedDeparture. + + + **L305** Splits none versus some burden and lets Lean obtain decidability of False or the concrete arithmetic/string condition. + + + **L307** Priority applicability is a conjunction of lifecycle, feasibility, credibility and actual comparative capability conditions. + + + **L308** Requires a continuing activity with a valid engineering-subject scope. + + + **L309** Both simple and evolvable alternatives must satisfy the same context's necessary requirements. + + + **L310** The context must contain credible grounds for design revision, not merely an imagined addition. + + + **L311** Every continuing maintainer must be able to perform that design revision with evolvable. + + + **L312** The actual design-revision path must cost less work in evolvable than in simple. + + + **L313** Evolvable must incur more present abstraction complexity, making the intended tradeoff nontrivial. + + + **L315** Begins a provenance comment attaching CoreReader.Engineering.EvolutionPriority to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence. + + + **L316** Records the source reference software-engineering.purpose/p3 for CoreReader.Engineering.EvolutionPriority, with direct-body SHA256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b. This is a traceability binding, not a new premise or semantic proof. + + + **L317** Records the source reference software-engineering.evolution-priority/p1 for CoreReader.Engineering.EvolutionPriority, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof. + + + **L318** Records the source reference software-engineering.evolution-priority/p2 for CoreReader.Engineering.EvolutionPriority, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof. + + + **L319** Records the source reference software-engineering.evolution-priority/p3 for CoreReader.Engineering.EvolutionPriority, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof. + + + **L320** Closes the source-mapping comment for CoreReader.Engineering.EvolutionPriority; executable declarations resume after the comment. + + + **L321** This is the adopted defeasible priority: when all applicability conditions hold, select evolvable unless its added cost has an explicitly justified departure. It is not deduced from those facts alone. + + + **L322** This is the adopted defeasible priority: when all applicability conditions hold, select evolvable unless its added cost has an explicitly justified departure. It is not deduced from those facts alone. + + + **L324** Computes that the ordinary shared context satisfies all priority conditions. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope. + + + **L325** Computes that the ordinary evolvable costs threaten no represented objective and support no claimed departure. + + + **L326** Computes that the ordinary evolvable costs threaten no represented objective and support no claimed departure. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope. + + + **L328** The threatened variant lowers only the selected burden's capacity to one and records that burden as the departure reason; other capacities remain twelve. + + + **L329** The threatened variant lowers only the selected burden's capacity to one and records that burden as the departure reason; other capacities remain twelve. + + + **L330** The threatened variant lowers only the selected burden's capacity to one and records that burden as the departure reason; other capacities remain twelve. + + + **L332** Begins a provenance comment attaching CoreReader.Engineering.priorityWhenApplicable to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence. + + + **L333** Records the source reference software-engineering.evolution-priority/p1 for CoreReader.Engineering.priorityWhenApplicable, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof. + + + **L334** Records the source reference software-engineering.evolution-priority/p2 for CoreReader.Engineering.priorityWhenApplicable, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof. + + + **L335** Records the source reference software-engineering.evolution-priority/p3 for CoreReader.Engineering.priorityWhenApplicable, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof. + + + **L336** Closes the source-mapping comment for CoreReader.Engineering.priorityWhenApplicable; executable declarations resume after the comment. + + + **L337** The conditional result ranges over any context and chosen candidate in this application vocabulary. + + + **L338** Assumes both adoption of the priority rule and actual applicability; neither premise is derived merely from the theorem statement. + + + **L339** Also assumes there is no justified cost departure. + + + **L340** Under those premises, the choice must be evolvable and therefore carry the stated extra abstraction complexity. + + + **L341** Under those premises, the choice must be evolvable and therefore carry the stated extra abstraction complexity. + + + **L342** Applies the adopted implication to actual conditions and eliminates its departure alternative using noDeparture. + + + **L343** Pairs the resulting choice equality with the applicability premise's final complexity inequality, substituting the actual chosen candidate. + + + **L345** Shows that choosing simple in the ordinary applicable, no-threat context violates the adopted evolution priority. + + + **L346** Temporarily assumes the simple choice satisfies the rule in order to derive a contradiction. + + + **L347** Actual applicability activates that rule, and absence of departure forces the impossible simple=evolvable equality. + + + **L348** Eliminates equality between distinct candidate constructors, completing the negative result. + + + **L350** Replaces only evolvable's observed profile while preserving the other candidate profiles and context, isolating a necessary-requirement variation. + + + **L351** Replaces only evolvable's observed profile while preserving the other candidate profiles and context, isolating a necessary-requirement variation. + + + **L353** Check that each of the four displayed requirement failures makes PriorityConditions false. This only disables priority activation: EvolutionPriority and the later DomainSatisfied do not impose an unconditional Meets rejection. + + + **L354** Changing the observed order from [2,1] to [1,2] invalidates priority applicability. + + + **L355** One unsafe operation exceeds the permitted zero and invalidates applicability. + + + **L356** Latency eleven exceeds the limit ten and invalidates applicability. + + + **L357** Retention twenty-nine falls below thirty and invalidates applicability. + + + **L358** Simplifies applicability, the altered profile and requirement predicates; each branch reduces to its explicit failed equality or numerical bound. + + + **L359** Simplifies applicability, the altered profile and requirement predicates; each branch reduces to its explicit failed equality or numerical bound. + + + **L361** Begins a provenance comment attaching CoreReader.Engineering.priorityConditionsCases to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence. + + + **L362** Records the source reference software-engineering.purpose/p3 for CoreReader.Engineering.priorityConditionsCases, with direct-body SHA256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b. This is a traceability binding, not a new premise or semantic proof. + + + **L363** Records the source reference software-engineering.evolution-priority/p1 for CoreReader.Engineering.priorityConditionsCases, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof. + + + **L364** Records the source reference software-engineering.evolution-priority/p2 for CoreReader.Engineering.priorityConditionsCases, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof. + + + **L365** Records the source reference software-engineering.evolution-priority/p3 for CoreReader.Engineering.priorityConditionsCases, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof. + + + **L366** Closes the source-mapping comment for CoreReader.Engineering.priorityConditionsCases; executable declarations resume after the comment. + + + **L367** Bundles ordinary priority, four requirement failures, an accounted cost exception and the nonmaximal chosen design. + + + **L368** Choosing evolvable satisfies the adopted priority in the ordinary context. + + + **L369** Reordered output fails the ordinary order requirement. + + + **L370** One unsafe operation fails the safety requirement. + + + **L371** Latency eleven fails the performance bound. + + + **L372** Retention twenty-nine fails the minimum retention requirement. + + + **L373** With a concrete verification-capacity threat, the rule permits the simple choice through its departure branch. + + + **L374** Removing the departure account leaves no justified departure even when the threatened cost data remain. + + + **L375** The preferred evolvable design has complexity three, below maximal's thirty; the priority is not a duty to maximize complexity. + + + **L376** Builds the conjunction by finite decisions, leaving only the absent-departure branch for simplification. + + + **L377** An absent departure reduces JustifiedDeparture to False, proving that negative branch. + + + **L379** Begins a provenance comment attaching CoreReader.Engineering.priorityChoices to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence. + + + **L380** Records the source reference software-engineering.evolution-priority/p1 for CoreReader.Engineering.priorityChoices, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof. + + + **L381** Records the source reference software-engineering.evolution-priority/p2 for CoreReader.Engineering.priorityChoices, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof. + + + **L382** Records the source reference software-engineering.evolution-priority/p3 for CoreReader.Engineering.priorityChoices, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof. + + + **L383** Closes the source-mapping comment for CoreReader.Engineering.priorityChoices; executable declarations resume after the comment. + + + **L384** Presents the actual ordinary evolution choice, ordinary simple rejection and threatened-context simple allowance together. + + + **L385** The ordinary evolvable choice follows the adopted rule. + + + **L386** The ordinary simple choice fails that same rule. + + + **L387** The verification-threat context gives a justified exception for choosing simple. + + + **L388** Combines computed positive examples with the previously proved no-threat simple-choice contradiction. + + + **L390** Begins a provenance comment attaching CoreReader.Engineering.credibilityLimits to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence. + + + **L391** Records the source reference software-engineering.evolution-priority/p2 for CoreReader.Engineering.credibilityLimits, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof. + + + **L392** Records the source reference software-engineering.evolution-priority/p3 for CoreReader.Engineering.credibilityLimits, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof. + + + **L393** Closes the source-mapping comment for CoreReader.Engineering.credibilityLimits; executable declarations resume after the comment. + + + **L394** Separates credible planned change from existing implementation count, imaginative possibilities and maximum registered capability. + + + **L395** The design-revision plan is credible while only one candidate is implemented. + + + **L396** An imagined quantum backend with no grounds and zero gain does not justify an investment of five. + + + **L397** The initial plan does not support the imagined quantum-backend direction. + + + **L398** The ordinary evolvable choice still satisfies the domain priority. + + + **L399** The preferred design's present complexity is lower than maximal's. + + + **L400** Construction and migration costs differ within evolvable, retaining distinct burdens instead of one universal cost rate. + + + **L401** Evolvable does not support every registered direction for all continuing maintainers. + + + **L402** Maximal does support every direction in the explicitly registered finite set. + + + **L403** Evolvable supports nine registered directions. + + + **L404** Maximal supports ten, making its extra extensibility substantive rather than merely a name. + + + **L405** CSV export is not supported by the current plan, so its technical availability does not itself establish present credibility. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope. + + + **L407** Begins a provenance comment attaching CoreReader.Engineering.costCases to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence. + + + **L408** Records the source reference software-engineering.evolution-priority/p3 for CoreReader.Engineering.costCases, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof. + + + **L409** Closes the source-mapping comment for CoreReader.Engineering.costCases; executable declarations resume after the comment. + + + **L410** Checks each of the seven burdens as a possible concrete reason for departing from priority. + + + **L411** Reducing understanding capacity to one makes the evolvable understanding cost a justified departure. + + + **L412** The analogous construction-capacity threat justifies departure. + + + **L413** The analogous diagnosis-capacity threat justifies departure. + + + **L414** The analogous verification-capacity threat justifies departure. + + + **L415** The analogous coordination-capacity threat justifies departure. + + + **L416** The analogous operational-capacity threat justifies departure. + + + **L417** The analogous migration-capacity threat justifies departure. + + + **L418** Merely naming migration in the ordinary capacity-twelve context does not create a real threat or justified exception. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope. + + + **L420** The following total functions represent an identified de-duplication API. Finite corpus equality is kept distinct from universal contract preservation. + + + **L421** The following total functions represent an identified de-duplication API. Finite corpus equality is kept distinct from universal contract preservation. + + + **L422** Removes duplicate values using the standard library's order-preserving list operation. + + + **L423** The refactor performs the same de-duplication and appends an empty list, preserving output. + + + **L424** Take a natural number and an arbitrary natural-number list; the type has no sorted-input premise. sortValues uses this helper for ordered insertion into its recursively sorted tail. + + + **L425** Inserting into an empty list yields the singleton value. + + + **L426** Places the value before the first no-smaller head; otherwise keeps the head and recursively inserts into the tail. + + + **L428** Sorting recursively uses the insertion operation; this changes ordering rather than only de-duplicating. + + + **L429** The empty list sorts to itself. + + + **L430** Sorts the tail and inserts the original head into that sorted result. + + + **L432** The alternative implementation sorts all values before removing duplicates, so it can violate the original order contract. + + + **L434** Software-state fields allow distinct kinds of evolution to change distinct aspects of the represented design. + + + **L435** Lists the represented capabilities of the software. + + + **L436** Identifies which implementation version is used. + + + **L437** Lists concrete mechanisms that may be added or deleted. + + + **L438** Lists abstractions that may be retained or withdrawn. + + + **L439** Records a boundary revision index, separate from capability and implementation indices. + + + **L440** Identifies the storage technology or model that may be migrated away from. + + + **L441** Records the configured batch size. + + + **L442** Automatically provides equality decisions and printable representations for SoftwareState; these support concrete case evaluation, not a philosophical claim about that type. + + + **L444** The starting software de-duplicates, uses implementation 0, queue plus legacy cache, fixed batching, boundary index 0, legacy storage and batch size ten. + + + **L445** The starting software de-duplicates, uses implementation 0, queue plus legacy cache, fixed batching, boundary index 0, legacy storage and batch size ten. + + + **L447** Each change direction transforms actual selected fields of the software state; this is a stipulated state model, not an executable source-code editor. + + + **L448** Addition retains existing capabilities and adds tenant batching. + + + **L449** Replacement increments the implementation identifier. + + + **L450** Deletion removes legacy cache while retaining other mechanisms. + + + **L451** Withdrawal removes the fixed-batch abstraction. + + + **L452** Redrawing increments the boundary revision index. + + + **L453** Migration replaces legacy technology with portable storage. + + + **L454** Independent change updates only batch size to five. + + + **L455** Coordinated change updates batch size and the boundary index together. + + + **L456** Design revision sets batch size five, replaces the abstraction with live configuration and redraws the boundary. + + + **L457** The named CSV direction adds an actual CSV capability; unrecognized other directions leave the state unchanged. + + + **L458** The named CSV direction adds an actual CSV capability; unrecognized other directions leave the state unchanged. + + + **L459** The named CSV direction adds an actual CSV capability; unrecognized other directions leave the state unchanged. + + + **L461** Redrawing and design revision deliberately use sortedUnique behavior; other changes preserve orderedUnique behavior in this application. + + + **L462** Redrawing and design revision deliberately use sortedUnique behavior; other changes preserve orderedUnique behavior in this application. + + + **L464** Open-ended change kinds, work requirements, maintainer knowledge and obligation treatment remain separate; they are not collapsed into a single extensibility score. + + + **L465** Open-ended change kinds, work requirements, maintainer knowledge and obligation treatment remain separate; they are not collapsed into a single extensibility score. + + + **L466** A change claim explicitly says whether it preserves or deliberately revises obligations. + + + **L467** A change claim explicitly says whether it preserves or deliberately revises obligations. + + + **L468** A change claim explicitly says whether it preserves or deliberately revises obligations. Automatically provides equality decisions and printable representations for ObligationTreatment; these support concrete case evaluation, not a philosophical claim about that type. + + + **L469** Groups the intended direction, acting maintainer and declared obligation treatment in one claim. + + + **L470** Identifies the change whose capability is being claimed. + + + **L471** Identifies the maintainer whose conditions must support that change. + + + **L472** States whether the same identified obligation is preserved or deliberately revised. + + + **L474** The finite order corpus is exactly four lists: empty, [2,1,2], [1,3,1] and [4,4]; later finite preservation claims are limited to these inputs. + + + **L475** Universal scoped preservation requires the new and old functions to agree for every input satisfying the supplied scope predicate. + + + **L476** Universal scoped preservation requires the new and old functions to agree for every input satisfying the supplied scope predicate. + + + **L478** Finite preservation checks only the declared corpus by Boolean equality; it does not infer the preceding all-input property. + + + **L479** Finite preservation checks only the declared corpus by Boolean equality; it does not infer the preceding all-input property. + + + **L481** Contracts and observer dependencies are supplied independently of the report, preventing report edits from redefining the actual old/new behavior or affected population. + + + **L482** Contracts and observer dependencies are supplied independently of the report, preventing report edits from redefining the actual old/new behavior or affected population. + + + **L483** Contracts and observer dependencies are supplied independently of the report, preventing report edits from redefining the actual old/new behavior or affected population. + + + **L484** An observable contract combines order behavior with a retry limit. + + + **L485** The order function is actual observable behavior, not just a contract name. + + + **L486** The retry threshold belongs to the actual contract. + + + **L488** A retry is permitted exactly when the attempt index is below maxAttempts, making changes in that threshold observable. + + + **L489** A retry is permitted exactly when the attempt index is below maxAttempts, making changes in that threshold observable. + + + **L491** An ordinary order contract pairs its function with threshold three. + + + **L492** The original contract uses ordered de-duplication and threshold three. + + + **L493** The refactored contract changes only to the extensionally identical refactor, retaining threshold three. + + + **L494** The deliberate revision uses sorted de-duplication and threshold five, changing both represented contract aspects. + + + **L495** The direction-specific contract uses its actual evolution behavior and raises retry threshold only for redrawing or design revision. + + + **L496** The direction-specific contract uses its actual evolution behavior and raises retry threshold only for redrawing or design revision. + + + **L498** The finite retry corpus contains attempt indices zero through five. + + + **L499** Finite whole-contract preservation requires both order equality on contractInputs and retry equality on failureInputs. + + + **L500** Finite whole-contract preservation requires both order equality on contractInputs and retry equality on failureInputs. + + + **L501** Finite whole-contract preservation requires both order equality on contractInputs and retry equality on failureInputs. + + + **L503** Order and retry are distinct observable contract aspects, allowing different parties to depend on them. + + + **L504** Order and retry are distinct observable contract aspects, allowing different parties to depend on them. + + + **L505** Order and retry are distinct observable contract aspects, allowing different parties to depend on them. Automatically provides equality decisions and printable representations for ContractAspect; these support concrete case evaluation, not a philosophical claim about that type. + + + **L506** A dependency record connects a named party to the contract aspect it observes. + + + **L507** Identifies the party whose obligations may be affected. + + + **L508** Identifies the particular observable aspect that party depends on. + + + **L509** Automatically provides equality decisions and printable representations for PartyDependency; these support concrete case evaluation, not a philosophical claim about that type. + + + **L511** The queue consumer depends on order, while the queue operator depends on retry behavior; these dependencies are fixed outside the revision report. + + + **L512** The queue consumer depends on order, while the queue operator depends on retry behavior; these dependencies are fixed outside the revision report. + + + **L514** Detects changes from actual old/new contracts under the finite observations for each aspect. + + + **L515** Order changes when any declared order input produces a different output. + + + **L516** Retry changes when any declared attempt index produces a different permission result. + + + **L518** The affected-party list is computed from fixed dependencies whose observed aspect actually changes, not taken from the report's own claim. + + + **L519** The affected-party list is computed from fixed dependencies whose observed aspect actually changes, not taken from the report's own claim. + + + **L520** The affected-party list is computed from fixed dependencies whose observed aspect actually changes, not taken from the report's own claim. + + + **L522** The revision account records intention, changed observations, parties, actual-limit claims, recorded limits and a procedure description. + + + **L523** States that a contract change is deliberate. + + + **L524** Records the revised order output on the distinguished sample. + + + **L525** Lists parties acknowledged by the report; duties later compare this to actual affected parties. + + + **L526** States the claimed old retry threshold. + + + **L527** States the claimed new retry threshold. + + + **L528** Retains the report's historical record of the old threshold. + + + **L529** Retains the recorded new threshold. + + + **L530** Names the chosen procedure; the philosophical account does not prescribe one particular procedure. + + + **L532** The ordinary revision is deliberate and records the new sorted result [1,2]. + + + **L533** The ordinary revision is deliberate and records the new sorted result [1,2]. + + + **L534** Acknowledges both the consumer and operator affected by the two actual aspect changes. + + + **L535** States actual retry limits changing from three to five. + + + **L536** The retained records also say three before and five after, rather than rewriting the old limit. + + + **L537** Uses contract review as one possible procedure, without making its name a condition of validity. + + + **L539** Revision duties are evaluated against the independently supplied old/new contracts and the particular report. + + + **L540** Requires deliberate revision and an accurate report of the new output on [2,1,2]. + + + **L541** Every actually affected party must occur in the report; this permits extra listed parties and does not prescribe notification. + + + **L542** Both claimed failure limits must equal the independently supplied actual thresholds. + + + **L543** The recorded old limit must still match the original contract. + + + **L544** The recorded new limit must match the new contract. + + + **L546** Begins a provenance comment attaching CoreReader.Engineering.ContractChangeAccount to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence. + + + **L547** Records the source reference software-engineering.structural-judgment/p3 for CoreReader.Engineering.ContractChangeAccount, with direct-body SHA256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42. This is a traceability binding, not a new premise or semantic proof. + + + **L548** Closes the source-mapping comment for CoreReader.Engineering.ContractChangeAccount; executable declarations resume after the comment. + + + **L549** A contract-change account either preserves all declared finite observations or supplies the deliberate-revision duties; these are distinct alternatives. + + + **L550** A contract-change account either preserves all declared finite observations or supplies the deliberate-revision duties; these are distinct alternatives. + + + **L552** Begins a provenance comment attaching CoreReader.Engineering.EvolutionClaim to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence. + + + **L553** Records the source reference software-engineering.evolution-meaning/p1 for CoreReader.Engineering.EvolutionClaim, with direct-body SHA256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6. This is a traceability binding, not a new premise or semantic proof. + + + **L554** Records the source reference software-engineering.evolution-meaning/p2 for CoreReader.Engineering.EvolutionClaim, with direct-body SHA256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6. This is a traceability binding, not a new premise or semantic proof. + + + **L555** Closes the source-mapping comment for CoreReader.Engineering.EvolutionClaim; executable declarations resume after the comment. + + + **L556** A capability claim concerns a specific maintainer and direction, with an explicit obligation treatment. + + + **L557** The named maintainer must actually be able to execute the intended direction's path. + + + **L558** The same direction's actual old/new contract change must have a valid preservation or revision account. + + + **L559** The direction's path must contain a contract-runner step, tying the claim to represented verification work. + + + **L560** A preserve claim requires the distinguished sample to retain the original ordered output. + + + **L561** A preserve claim requires the distinguished sample to retain the original ordered output. + + + **L562** A revise claim instead requires an actual different output on that sample; the treatment label cannot silently reverse the observed relation. + + + **L563** A revise claim instead requires an actual different output on that sample; the treatment label cannot silently reverse the observed relation. + + + **L565** Begins a provenance comment attaching CoreReader.Engineering.evolutionKindsCases to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence. + + + **L566** Records the source reference software-engineering.evolution-meaning/p1 for CoreReader.Engineering.evolutionKindsCases, with direct-body SHA256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6. This is a traceability binding, not a new premise or semantic proof. + + + **L567** Records the source reference software-engineering.evolution-meaning/p2 for CoreReader.Engineering.evolutionKindsCases, with direct-body SHA256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6. This is a traceability binding, not a new premise or semantic proof. + + + **L568** Closes the source-mapping comment for CoreReader.Engineering.evolutionKindsCases; executable declarations resume after the comment. + + + **L569** Collects actual state changes, successor capability and both preservation/revision claim examples. + + + **L570** Addition retains de-duplication and adds tenant batching. + + + **L571** Replacement changes implementation index zero to one. + + + **L572** Deletion removes legacy cache, leaving the queue mechanism. + + + **L573** Withdrawal removes the only fixed-batch abstraction, leaving the abstraction list empty. + + + **L574** Redrawing changes the boundary index from zero to one. + + + **L575** Migration changes the storage technology to portable store. + + + **L576** The successor can execute all nine ordinary evolvable change paths with the supplied tools and guides. + + + **L577** A successor's replacement is a valid preservation-type EvolutionClaim. + + + **L578** An agent's boundary redrawing is a valid deliberate-revision EvolutionClaim. + + + **L579** Independent work costs two while coordinated work costs eight, so they need not require equal work. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope. + + + **L581** Begins a provenance comment attaching CoreReader.Engineering.evolutionDimensionsLimits to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence. + + + **L582** Records the source reference software-engineering.evolution-meaning/p1 for CoreReader.Engineering.evolutionDimensionsLimits, with direct-body SHA256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6. This is a traceability binding, not a new premise or semantic proof. + + + **L583** Records the source reference software-engineering.evolution-meaning/p2 for CoreReader.Engineering.evolutionDimensionsLimits, with direct-body SHA256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6. This is a traceability binding, not a new premise or semantic proof. + + + **L584** Closes the source-mapping comment for CoreReader.Engineering.evolutionDimensionsLimits; executable declarations resume after the comment. + + + **L585** Shows that different evolution dimensions have different costs and capabilities, including an actual maximum-versus-evolvable contrast. + + + **L586** Simple-design addition costs two units. + + + **L587** Withdrawing its fixed structure costs seventeen units, much more than addition. + + + **L588** Evolvable independent change costs less than its coordinated change. + + + **L589** These uneven costs coexist with satisfaction of evolution priority. + + + **L590** Evolvable migration costs ten, so it exceeds nine despite the priority's satisfaction. + + + **L591** The original maintainer can add to the simple design. + + + **L592** The original maintainer can also add to evolvable. + + + **L593** The original maintainer's private knowledge permits simple-design revision. + + + **L594** The original maintainer can also perform evolvable design revision. + + + **L595** For the same design-revision direction, evolvable uses six work units versus simple's seventeen. + + + **L596** Both designs use two units for addition; an advantage on design revision is not a strict advantage on every dimension. + + + **L597** CSV export changes the actual capability list to include CSV alongside de-duplication. + + + **L598** The successor has the guides and tools for maximal's CSV path. + + + **L599** The successor lacks privateLayout needed by evolvable's CSV path, despite its other advantages. + + + **L600** Constructs every conjunct with Lean's decision procedure over the explicit finite paths, states and arithmetic; no empirical generalization occurs. + + + **L602** States a counterexample to universal strict improvement from a single-direction advantage. + + + **L603** Retains the genuine strict improvement for design revision. + + + **L604** Denies that evolvable requires strictly less work for every Change, including additions and named other directions. + + + **L605** Computes the positive revision inequality and leaves the universal negative to a counterexample argument. + + + **L606** Assumes strict improvement in every direction to derive a contradiction. + + + **L607** Specializes that assumption to addition, where both work totals equal two; the claimed strict inequality is false. + + + **L608** Specializes that assumption to addition, where both work totals equal two; the claimed strict inequality is false. + + + **L610** Change propagation is the distinct list of component identifiers touched by the actual path, retaining relations to the intended change. + + + **L611** Change propagation is the distinct list of component identifiers touched by the actual path, retaining relations to the intended change. + + + **L613** Computes a natural-number batch-count expression (items+size−1)/size. It is intended for positive batch sizes; Lean subtraction and division are total even outside that intended domain. + + + **L614** The static predictor deliberately ignores runtimeSize and always computes with size ten. + + + **L615** The live predictor uses the supplied runtime batch size, allowing the fixed assumption to be tested. + + + **L617** A structural evidence record connects an intended change to participants, propagation, observations and work accounts. + + + **L618** Identifies the change this evidence is supposed to support. + + + **L619** Identifies the relevant maintainers in the evidence account. + + + **L620** Records which components the change touches. + + + **L621** Records the exact input corpus used to observe contracts. + + + **L622** Records outputs before the change on that corpus. + + + **L623** Records outputs after the change on the same corpus. + + + **L624** Stores the represented understanding-work quantity, here instantiated from total path work. + + + **L625** Stores a verification-work quantity, instantiated below as the number of contract-runner steps rather than their unit sum. + + + **L626** Stores a claimed work gain over the simple design for this intended change. + + + **L628** Builds a concrete evidence record from the candidate's path and the same intended direction. + + + **L629** Binds the direction, all maintainers and the actual deduplicated propagation list. + + + **L630** Uses exactly the declared finite contract corpus. + + + **L631** Computes the old observations with orderedUnique. + + + **L632** Computes the new observations with that direction's actual evolutionBehavior. + + + **L633** The understanding-work field equals the intended path's total assigned work. + + + **L634** Verification counts actual contractRunner steps in the same path. + + + **L635** Work gain is simple work minus chosen work using natural subtraction, which truncates at zero rather than recording negative gains. + + + **L637** Begins a provenance comment attaching CoreReader.Engineering.StructuralAccount to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence. + + + **L638** Records the source reference software-engineering.structural-judgment/p1 for CoreReader.Engineering.StructuralAccount, with direct-body SHA256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42. This is a traceability binding, not a new premise or semantic proof. + + + **L639** Records the source reference software-engineering.structural-judgment/p2 for CoreReader.Engineering.StructuralAccount, with direct-body SHA256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42. This is a traceability binding, not a new premise or semantic proof. + + + **L640** Closes the source-mapping comment for CoreReader.Engineering.StructuralAccount; executable declarations resume after the comment. + + + **L641** A valid structural account must match the actual activity, candidate and intended change; merely filling record fields is insufficient. + + + **L642** Recorded participants must equal the activity's, and touched components must equal actual propagation for the claimed direction. + + + **L643** The account must identify the prescribed finite observation inputs exactly. + + + **L644** Its before-results must be the original ordered behavior on those inputs. + + + **L645** Its after-results must come from the same intended direction's behavior. + + + **L646** The claimed understanding work must match the selected path's total work. + + + **L647** The verification field must match the actual number of contract-runner steps; this checks a concrete work relation, not a free assessment flag. + + + **L648** The verification field must match the actual number of contract-runner steps; this checks a concrete work relation, not a free assessment flag. + + + **L649** The claimed gain must equal the actual simple-minus-selected work difference for the same intended change. + + + **L651** Visible interface metadata is separated from executable behavior and edit paths for later insufficiency counterexamples. + + + **L652** Stores the visible function signature text. + + + **L653** Stores a claimed module count, later compared with actual component lists. + + + **L654** Stores the visible extension-point count. + + + **L655** Stores a named design principle; its name alone will not prove capability. + + + **L656** Automatically provides equality decisions and printable representations for InterfaceView; these support concrete case evaluation, not a philosophical claim about that type. + + + **L658** Several designs share the same List Nat→List Nat signature, eight modules, twelve extension points and dependency-inversion label. + + + **L659** All eight components, numbered zero through seven, assume batch size ten. + + + **L660** All eight components, numbered zero through seven, assume batch size ten. + + + **L662** Changing batch size selects the components whose stored assumption differs from the new size; at size five all eight need revision. + + + **L663** Changing batch size selects the components whose stored assumption differs from the new size; at size five all eight need revision. + + + **L665** A boundary carries actual endpoint identifiers and a contract label, allowing relation-sensitive checks. + + + **L666** Identifies the caller endpoint of the edge. + + + **L667** Identifies the callee endpoint of the edge. + + + **L668** Stores the edge's contract label; later checks also require work and actual output equality, so this string is not sufficient evidence. + + + **L669** Automatically provides equality decisions and printable representations for Boundary; these support concrete case evaluation, not a philosophical claim about that type. + + + **L671** A complete represented design combines metadata with its actual function, paths, components, boundaries and assumptions. + + + **L672** Keeps the visible metadata alongside the substantive design fields. + + + **L673** Carries the actual behavior used in contract comparisons. + + + **L674** Supplies concrete edit steps separately for each intended change. + + + **L675** Lists actual component identifiers, allowing endpoint-presence checks. + + + **L676** Lists the design's actual represented edges. + + + **L677** Associates components with their fixed batch-size assumptions. + + + **L679** The private design has the shared metadata, ordered behavior and simple-design paths; it has eight components, no explicit edges and eight fixed-batch assumptions. + + + **L680** The private design has the shared metadata, ordered behavior and simple-design paths; it has eight components, no explicit edges and eight fixed-batch assumptions. + + + **L681** The private design has the shared metadata, ordered behavior and simple-design paths; it has eight components, no explicit edges and eight fixed-batch assumptions. + + + **L683** The documented design changes only the work paths to evolvable's guide-based paths; metadata and observable behavior stay the same. + + + **L684** The documented design changes only the work paths to evolvable's guide-based paths; metadata and observable behavior stay the same. + + + **L686** The sorted variant changes actual behavior while retaining documented design metadata and paths, enabling a same-signature contract counterexample. + + + **L688** This finite application treats editing callee 1 as crossing the actual 2→1 edge and requiring caller-side order verification; neither an edge label nor a named contract proves that verification occurred or output was preserved. + + + **L689** This finite application treats editing callee 1 as crossing the actual 2→1 edge and requiring caller-side order verification; neither an edge label nor a named contract proves that verification occurred or output was preserved. + + + **L690** This finite application treats editing callee 1 as crossing the actual 2→1 edge and requiring caller-side order verification; neither an edge label nor a named contract proves that verification occurred or output was preserved. + + + **L691** This finite application treats editing callee 1 as crossing the actual 2→1 edge and requiring caller-side order verification; neither an edge label nor a named contract proves that verification occurred or output was preserved. + + + **L692** Instantiates the concrete edge from caller 2 to callee 1 with the queue's order-contract label. + + + **L694** Adds that actual edge to documentedDesign's boundary list, tying the later check to a design containing the edge. + + + **L695** Adds that actual edge to documentedDesign's boundary list, tying the later check to a design containing the edge. + + + **L697** Boundary crossing is checked for one actual design, one intended direction and one edge. + + + **L698** The edge must belong to the design and its caller must be an actual component. + + + **L699** Its callee must also exist, and caller and callee must be different components. + + + **L700** The intended path must actually edit or compile the callee component; an unrelated edge does not establish propagation across this boundary. + + + **L701** The intended path must actually edit or compile the callee component; an unrelated edge does not establish propagation across this boundary. + + + **L703** The boundary-obligation test is indexed by the same design, intended change and edge, so results for unrelated boundaries cannot substitute. + + + **L704** The boundary-obligation test is indexed by the same design, intended change and edge, so results for unrelated boundaries cannot substitute. + + + **L705** Requires the actual boundary-crossing relation before treating a caller-side check as a cross-boundary obligation. + + + **L706** The same change path must contain a caller-component contractRunner step requiring publicContract knowledge. + + + **L707** The same change path must contain a caller-component contractRunner step requiring publicContract knowledge. + + + **L708** The actual design behavior must preserve orderedUnique on the declared finite order corpus; a check-step label without output equality fails. + + + **L710** Construct omittedCallerCheck as a design variant whose paths omit caller contract-runner work, for the later boundary-obligation counterexample. + + + **L711** Copy boundaryDesign’s other fields unchanged and replace paths with a function that transforms the path for each requested direction. + + + **L712** Filter the original boundaryDesign path for this same direction, retaining precisely the steps accepted by the following predicate. + + + **L713** Exclude a step exactly when it is at coordinatedBoundary.caller and uses contractRunner; keep all other steps and finish the record update. + + + **L715** Moves the callee endpoint to component 7 while retaining the caller and contract label. + + + **L717** The alternate design actually contains the changed edge, so the negative crossing test is about its endpoint/path mismatch rather than simple absence of the edge. + + + **L718** The alternate design actually contains the changed edge, so the negative crossing test is about its endpoint/path mismatch rather than simple absence of the edge. + + + **L720** Checks positive and negative relations among actual edges, intended work, caller obligations and observable behavior. + + + **L721** Coordinated work in boundaryDesign crosses its actual 2→1 edge. + + + **L722** That work includes the required caller check and retains the finite order contract. + + + **L723** Removing the caller check does not remove the callee edit, so the boundary is still crossed. + + + **L724** Nevertheless the cross-boundary obligation is unmet after the caller check is removed. + + + **L725** The edge to callee 7 is not crossed because the coordinated path does not edit or compile that callee. + + + **L726** Replacing only run with sortedUnique violates the order obligation despite unchanged edge and checking steps; the finite conjunction is proved by computation. + + + **L727** Replacing only run with sortedUnique violates the order obligation despite unchanged edge and checking steps; the finite conjunction is proved by computation. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope. + + + **L729** Begins a provenance comment attaching CoreReader.Engineering.structuralCases to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence. + + + **L730** Records the source reference software-engineering.structural-judgment/p1 for CoreReader.Engineering.structuralCases, with direct-body SHA256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42. This is a traceability binding, not a new premise or semantic proof. + + + **L731** Records the source reference software-engineering.structural-judgment/p2 for CoreReader.Engineering.structuralCases, with direct-body SHA256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42. This is a traceability binding, not a new premise or semantic proof. + + + **L732** Closes the source-mapping comment for CoreReader.Engineering.structuralCases; executable declarations resume after the comment. + + + **L733** The registered structural case bundle includes actual propagation, contract observations, work and the new explicit cross-boundary checks. + + + **L734** The evolvable design-revision evidence matches the actual continuing activity and intended path. + + + **L735** Simple design revision touches three distinct components. + + + **L736** Evolvable design revision touches two distinct components. + + + **L737** Coordinated work contains a component-2 step needing public-contract knowledge; the following new cases additionally bind it to a real edge. + + + **L738** The refactor preserves ordered behavior on the declared finite contract corpus. + + + **L739** The actual before/after observation lists differ for deliberate design revision; the change is not falsely called preservation. + + + **L740** The actual before/after observation lists differ for deliberate design revision; the change is not falsely called preservation. + + + **L741** The static batch assumption agrees at runtime size ten but fails at size five for twenty-one items. + + + **L742** Withdrawing the simple design's structure takes seventeen units, retaining an eventual-exit cost. + + + **L743** The coordinated path crosses the actual caller-2/callee-1 boundary. + + + **L744** That boundary's public-contract verification and finite order obligation are fulfilled. + + + **L745** The callee edit still crosses the boundary when caller verification is omitted. + + + **L746** The omitted caller verification causes the obligation test to fail. + + + **L747** An edge whose callee is component 7 does not match this edit path and is not crossed. + + + **L748** The same edge and steps with sortedUnique behavior fail actual finite order preservation; decide checks all clauses of this concrete structural bundle. + + + **L749** The same edge and steps with sortedUnique behavior fail actual finite order preservation; decide checks all clauses of this concrete structural bundle. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope. + + + **L751** Generalizes individual capability from a candidate tag to an actual EngineeringDesign with its own paths. + + + **L752** Generalizes individual capability from a candidate tag to an actual EngineeringDesign with its own paths. + + + **L753** Requires an actual nonempty design path and a participating maintainer. + + + **L754** Every actual path step must be executable with that maintainer's knowledge and the activity's tools. + + + **L755** Every actual path step must be executable with that maintainer's knowledge and the activity's tools. + + + **L757** Computes work from this design object's actual path units, so path mutations can change or preserve the total explicitly. + + + **L758** Computes work from this design object's actual path units, so path mutations can change or preserve the total explicitly. + + + **L760** Finds components whose own recorded batch assumptions differ from the proposed runtime size. + + + **L761** Finds components whose own recorded batch assumptions differ from the proposed runtime size. + + + **L763** The first facade adds a component, forwarding edge and verification step while preserving output; it supplies neither missing private knowledge nor removal of existing edit work. + + + **L764** The first facade adds a component, forwarding edge and verification step while preserving output; it supplies neither missing private knowledge nor removal of existing edit work. + + + **L765** The first facade adds a component, forwarding edge and verification step while preserving output; it supplies neither missing private knowledge nor removal of existing edit work. + + + **L766** Constructs the first explicit boundary-introduction transformation on a complete design. + + + **L767** The visible module and extension-point counts both increase by one. + + + **L768** The wrapper appends an empty list to input before calling the original behavior, preserving the result. + + + **L769** An absent original path stays absent; merely wrapping cannot create support for an unknown change. + + + **L770** An existing path gains one public-contract verification unit at the new component identifier. + + + **L771** Adds the original component-list length as a new component identifier; it is fresh for the concrete zero-through-seven starting design. + + + **L772** Adds a forwarding edge from that new component to component 0 carrying the original signature label. + + + **L773** Adds a forwarding edge from that new component to component 0 carrying the original signature label. + + + **L774** Leaves all fixed batch assumptions unchanged, so the wrapper does not resolve their coupling. + + + **L776** Applies the first facade transformation to the private design for a concrete increased-work counterexample. + + + **L778** The second facade moves existing verification to the new component instead of adding work; real boundary and path changes still do not supply private knowledge or lower total work. + + + **L779** The second facade moves existing verification to the new component instead of adding work; real boundary and path changes still do not supply private knowledge or lower total work. + + + **L780** The second facade moves existing verification to the new component instead of adding work; real boundary and path changes still do not supply private knowledge or lower total work. + + + **L781** Begins with the same boundary-introducing design, retaining its new component, edge and equivalent behavior. + + + **L782** Begins with the same boundary-introducing design, retaining its new component, edge and equivalent behavior. + + + **L783** Rebuilds the work paths from the original design's steps, removing the extra appended verification step of the first facade. + + + **L784** Moves each original contractRunner step to the new component while preserving its knowledge, tool and units. + + + **L785** Leaves every nonverification step unchanged, completing a relocation without changing work units. + + + **L787** The concrete same-work design is the private design after this verification relocation. + + + **L789** Begins a provenance comment attaching CoreReader.Engineering.structureNotCapability to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence. + + + **L790** Records the source reference software-engineering.structural-judgment/p1 for CoreReader.Engineering.structureNotCapability, with direct-body SHA256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42. This is a traceability binding, not a new premise or semantic proof. + + + **L791** Records the source reference software-engineering.structural-judgment/p2 for CoreReader.Engineering.structureNotCapability, with direct-body SHA256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42. This is a traceability binding, not a new premise or semantic proof. + + + **L792** Closes the source-mapping comment for CoreReader.Engineering.structureNotCapability; executable declarations resume after the comment. + + + **L793** Collects counterexamples showing that signature, module count, principle name and new boundaries do not alone prove the claimed capability or lower work. + + + **L794** Private and sorted designs share a signature but give different order results on [2,1,2]; identical interface shape does not establish contract equivalence. + + + **L795** Private and sorted designs share a signature but give different order results on [2,1,2]; identical interface shape does not establish contract equivalence. + + + **L796** The private design's declared eight modules equal its actual component-list length. + + + **L797** It contains eight actual recorded batch assumptions, not merely a module-count label. + + + **L798** All eight components need assumption revision when runtime batch size changes to five. + + + **L799** The private design carries the dependency-inversion principle name. + + + **L800** Private and documented designs share all visible metadata. + + + **L801** Despite that label, the successor cannot revise the private design because its paths need private layout knowledge. + + + **L802** The successor can revise the documented design with its genuinely different guide-based paths. + + + **L803** The first facade changes the actual boundary count from zero to one. + + + **L804** It also increases actual component count from eight to nine. + + + **L805** The new actual edge is exactly component 8→0 with the original list-function signature. + + + **L806** The first facade retains the original observed output on [2,1,2]. + + + **L807** The original private design needs seventeen units for design revision. + + + **L808** The first facade needs eighteen units after its extra verification step. + + + **L809** Thus this actual boundary introduction does not reduce the intended design-revision work. + + + **L810** The relocation variant also has the concrete edge 8→0. + + + **L811** The relocation variant has nine actual components. + + + **L812** Its design-revision path differs from the original because verification component identifiers moved. + + + **L813** The relocation retains the original observed order result. + + + **L814** Its total assigned work equals the original path's total exactly. + + + **L815** That unchanged total is seventeen units. + + + **L816** The successor still lacks required private knowledge after relocation, so the new boundary does not establish continuing capability. + + + **L817** Proves the five concrete counterexample groups by decision procedures on their actual records, functions and arithmetic. + + + **L819** Begins a provenance comment attaching CoreReader.Engineering.contractPreservation to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence. + + + **L820** Records the source reference software-engineering.structural-judgment/p3 for CoreReader.Engineering.contractPreservation, with direct-body SHA256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42. This is a traceability binding, not a new premise or semantic proof. + + + **L821** Closes the source-mapping comment for CoreReader.Engineering.contractPreservation; executable declarations resume after the comment. + + + **L822** The general preservation theorem is polymorphic in inputs/outputs and keeps an explicitly supplied scope. + + + **L823** Its premise already supplies equality of new and old behavior for every input in that scope. + + + **L824** Returns that same universal scoped equality as PreservesOn; it does not derive universal preservation from finite tests. + + + **L826** A single actual differing observation inside the declared scope refutes scoped preservation. + + + **L827** Fixes the old/new functions, an input and proof that this input lies inside the scope. + + + **L828** Assumes an actual output difference there and concludes that preservation cannot hold. + + + **L829** Temporarily assumes scoped preservation. + + + **L830** Specializes preservation to the in-scope counterexample and contradicts its known output difference. + + + **L832** The revision-obligation theorem compares the same actual old/new observable contracts. + + + **L833** Requires a report already satisfying the preservation-or-revision account. + + + **L834** Also assumes that actual finite contract preservation fails. + + + **L835** Eliminates the preservation alternative, leaving the report's revision duties; it does not manufacture an account from changed behavior alone. + + + **L837** The retired behavior changes only input [99], which is outside the declared finite contract corpus, while retaining orderedUnique elsewhere. + + + **L838** The retired behavior changes only input [99], which is outside the declared finite contract corpus, while retaining orderedUnique elsewhere. + + + **L840** Begins a provenance comment attaching CoreReader.Engineering.contractCases to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence. + + + **L841** Records the source reference software-engineering.structural-judgment/p3 for CoreReader.Engineering.contractCases, with direct-body SHA256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42. This is a traceability binding, not a new premise or semantic proof. + + + **L842** Closes the source-mapping comment for CoreReader.Engineering.contractCases; executable declarations resume after the comment. + + + **L843** Collects preservation, deliberate revision, missing-party rejection and procedure flexibility cases. + + + **L844** The refactored contract has a valid account through finite preservation. + + + **L845** The revised order/retry contract has a valid account through actual revision duties. + + + **L846** An empty acknowledged-party list cannot account for the actual consumer/operator changes. + + + **L847** The retired behavior preserves every declared finite input but differs at [99], demonstrating the scope limit. + + + **L848** Changing the procedure name to paired audit keeps the account valid; no particular procedure is mandated. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope. + + + **L850** Begins a provenance comment attaching CoreReader.Engineering.contractDistinctions to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence. + + + **L851** Records the source reference software-engineering.structural-judgment/p3 for CoreReader.Engineering.contractDistinctions, with direct-body SHA256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42. This is a traceability binding, not a new premise or semantic proof. + + + **L852** Closes the source-mapping comment for CoreReader.Engineering.contractDistinctions; executable declarations resume after the comment. + + + **L853** Separates actual order preservation, retry change, party effects and accurate historical contract reporting. + + + **L854** The append-empty refactor preserves the finite ordered contract. + + + **L855** Sorting before de-duplication does not preserve that same order contract. + + + **L856** At attempt index three the old threshold forbids retry but the new threshold allows it, making failure-policy change concrete. + + + **L857** The combined order/retry contract therefore is not preserved. + + + **L858** The fixed dependency map identifies exactly the consumer and operator as affected in this example. + + + **L859** Acknowledging only the consumer omits the operator affected by retry change, so the revision account fails. + + + **L860** Acknowledging only the consumer omits the operator affected by retry change, so the revision account fails. + + + **L861** Changing both reported old-limit fields to five still fails because the independent actual old contract has threshold three. + + + **L862** Changing both reported old-limit fields to five still fails because the independent actual old contract has threshold three. + + + **L863** The unaltered normalRevision correctly accounts for the deliberate changes. + + + **L864** Finite preservation still allows the intentionally out-of-scope difference at [99]; it is not all-input equivalence. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope. + + + **L866** Revision concerns current choices under time-indexed evidence; it does not alter the truth of an already observed prediction. + + + **L867** Revision concerns current choices under time-indexed evidence; it does not alter the truth of an already observed prediction. + + + **L868** A revision state records the current evidence, maintenance setting, costs, objectives and selected design at one time. + + + **L869** Orders states by a natural-number time index. + + + **L870** Records expected future change directions. + + + **L871** Records the amount of expected maintenance. + + + **L872** Records who is expected to maintain the software. + + + **L873** Records the relevant migration cost. + + + **L874** Records the objective's capacity against that cost. + + + **L875** Records the design chosen under those conditions. + + + **L876** Automatically provides equality decisions and printable representations for RevisionState; these support concrete case evaluation, not a philosophical claim about that type. + + + **L877** A revision record keeps actual and reported states plus a separately checkable prediction outcome and criticism coverage. + + + **L878** Binds the report to a named software task. + + + **L879** Carries the old state claimed by the report. + + + **L880** Carries the current state. + + + **L881** Preserves what the report records about the old state for comparison with independent history. + + + **L882** Preserves what it records about the current state. + + + **L883** States the earlier predicted batch count. + + + **L884** States the actually observed batch count. + + + **L885** Records whether the report declares the prediction successful; later checks bind this Boolean to actual historical equality. + + + **L886** Lists change directions considered by this revision. + + + **L887** Lists directions kept within the declared criticism scope. + + + **L889** Material changes concern substantive grounds rather than a mere later timestamp or relabeled choice. + + + **L890** A change in expected directions or maintenance amount counts as changed grounds. + + + **L891** Changing the maintainers also changes the relevant conditions. + + + **L892** Changed migration cost or objective capacity supplies another material-ground difference. + + + **L894** The old state at time zero expects design revision, six maintenance units, the original maintainer, cost eight/capacity twelve and evolvable. + + + **L895** The new state at time one expects deletion, two maintenance units, successor/agent maintainers, cost fourteen/capacity ten and simple. + + + **L897** HistoricalEvidence is an input separate from the mutable report, anchoring the task, old state and past prediction/observation. + + + **L898** Identifies which software the historical event concerns. + + + **L899** Preserves the actual historical revision state. + + + **L900** Preserves the historical prediction independently of the new report. + + + **L901** Preserves the historical observed result independently of the report. + + + **L903** The recorded event used a predictor fixed at ten while reality used runtime size five for twenty-one items; the mismatch is retained as event content. + + + **L904** The recorded event used a predictor fixed at ten while reality used runtime size five for twenty-one items; the mismatch is retained as event content. + + + **L905** Fixes the queue history to oldState, predicted count three and actual count five computed by the two real functions. + + + **L906** Fixes the queue history to oldState, predicted count three and actual count five computed by the two real functions. + + + **L908** Checks a report against this independently supplied historical object, rather than comparing report fields only with each other. + + + **L909** The report's software identity must match the historical task. + + + **L910** Both its old-state claim and recorded old state must equal the independent historical state. + + + **L911** The report must retain the actual historical predicted count. + + + **L912** It must retain the actual historical observed count. + + + **L913** Time must advance, and the current-state record must accurately reflect the current state. + + + **L914** A changed design choice requires material grounds to have changed; this condition alone is not a proof that every such redesign is substantively justified. + + + **L915** The reported success flag must equal the decision of actual historical prediction/observation equality, preventing retrospective relabeling. + + + **L916** Every considered direction must remain in the listed criticism scope; this finite coverage is not a universal proof of reflexive correctness. + + + **L918** Begins a provenance comment attaching CoreReader.Engineering.RevisionAccount to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence. + + + **L919** Records the source reference software-engineering.revision/p2 for CoreReader.Engineering.RevisionAccount, with direct-body SHA256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99. This is a traceability binding, not a new premise or semantic proof. + + + **L920** Records the source reference software-engineering.revision/p1 for CoreReader.Engineering.RevisionAccount, with direct-body SHA256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99. This is a traceability binding, not a new premise or semantic proof. + + + **L921** Closes the source-mapping comment for CoreReader.Engineering.RevisionAccount; executable declarations resume after the comment. + + + **L922** Specializes the generic history-bound account to the fixed observed queue history. + + + **L924** The anti-rewriting result works for any supplied history and report, not only the queue numbers. + + + **L925** Assumes that the report satisfies the full account against that same historical object. + + + **L926** Assumes the actual historical prediction differs from the observation. + + + **L927** Concludes that an accurate report must mark the prediction unsuccessful. + + + **L928** Extracts the account's success-flag equality and simplifies it using the historical failure premise, yielding false. + + + **L930** Builds the ordinary revision report with accurate old/new states and the preserved failed forecast. + + + **L931** Uses the same order-preserving queue identity as observedHistory. + + + **L932** Actual and recorded states agree with oldState and newState respectively. + + + **L933** Uses the actual static/live counts for twenty-one items at runtime size five. + + + **L934** Truthfully marks that prediction unsuccessful. + + + **L935** Considers all nine ordinary directions and keeps all nine within criticism scope. + + + **L937** For this retention adapter, a supported alternative is a direction credible under the context's ground interpretation. + + + **L939** Retention may be justified by the declared lack-of-contribution or concrete-cost conditions; this is an application criterion. + + + **L940** One branch requires every listed alternative to lack credible support in the context. + + + **L941** The other branch permits retention through an explicitly justified evolvable cost departure. + + + **L943** The stable variant keeps the chosen design evolvable in both actual and recorded current states, while retaining changed evidence, honest failed prediction and criticism coverage. + + + **L944** The stable variant keeps the chosen design evolvable in both actual and recorded current states, while retaining changed evidence, honest failed prediction and criticism coverage. + + + **L945** The stable variant keeps the chosen design evolvable in both actual and recorded current states, while retaining changed evidence, honest failed prediction and criticism coverage. + + + **L947** Begins a provenance comment attaching CoreReader.Engineering.revisionCases to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence. + + + **L948** Records the source reference software-engineering.revision/p2 for CoreReader.Engineering.revisionCases, with direct-body SHA256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99. This is a traceability binding, not a new premise or semantic proof. + + + **L949** Records the source reference software-engineering.revision/p1 for CoreReader.Engineering.revisionCases, with direct-body SHA256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99. This is a traceability binding, not a new premise or semantic proof. + + + **L950** Closes the source-mapping comment for CoreReader.Engineering.revisionCases; executable declarations resume after the comment. + + + **L951** Exhibits a valid revision with all five material-ground differences, a preserved prediction failure and two justifications for retention. + + + **L952** The ordinary report satisfies the account against the fixed independent history. + + + **L953** Its forecast changes from design revision to deletion. + + + **L954** Its maintenance amount changes from six to two. + + + **L955** Its maintainer set changes from the original author to successor and agent. + + + **L956** Its migration cost changes from eight to fourteen. + + + **L957** Its objective capacity changes from twelve to ten. + + + **L958** The prediction three still differs from the actual five; revising the decision does not change this failure. + + + **L959** A quantum-backend alternative lacking credible grounds supplies the no-supported-alternative retention case. + + + **L960** A genuine migration-capacity threat supplies the cost-based retention case. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope. + + + **L962** The successful observation set uses only runtime size ten with item counts twenty-one, thirty and forty. + + + **L963** Records three revision identifiers, whose count alone will not establish correctness. + + + **L964** Every named reviewer reports the same static predictor result, modeling agreement without adding independent support or changing the actual predictor. + + + **L965** Every named reviewer reports the same static predictor result, modeling agreement without adding independent support or changing the actual predictor. + + + **L967** The first tampering variant changes both claimed and recorded old forecasts together, testing that agreement between report fields cannot override independent history. + + + **L968** The first tampering variant changes both claimed and recorded old forecasts together, testing that agreement between report fields cannot override independent history. + + + **L969** The first tampering variant changes both claimed and recorded old forecasts together, testing that agreement between report fields cannot override independent history. + + + **L971** The second variant changes the predicted count to five and calls it successful, attempting to rewrite the old prediction to match observation. + + + **L972** The second variant changes the predicted count to five and calls it successful, attempting to rewrite the old prediction to match observation. + + + **L974** The third variant changes the observed count to three and calls the prediction successful, attempting to rewrite the actual event. + + + **L975** The third variant changes the observed count to three and calls the prediction successful, attempting to rewrite the actual event. + + + **L977** The identity variant assigns the report to unrelated software while keeping its numerical data, testing task binding. + + + **L978** The identity variant assigns the report to unrelated software while keeping its numerical data, testing task binding. + + + **L980** Shows that fixed historical evidence rejects coordinated report-field tampering and software-identity substitution. + + + **L981** The unchanged report remains valid. + + + **L982** Changing both old-state fields cannot satisfy the independently fixed history. + + + **L983** Rewriting the predicted count and success flag is rejected. + + + **L984** Rewriting the observed count and success flag is also rejected. + + + **L985** The independent history retains prediction three and observation five throughout these variants. + + + **L986** A report for unrelated software fails the task-identity requirement. + + + **L987** Computes all seven concrete validity/failure and historical-number clauses without editing the historical object. + + + **L989** Begins a provenance comment attaching CoreReader.Engineering.revisionLimits to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence. + + + **L990** Records the source reference software-engineering.revision/p2 for CoreReader.Engineering.revisionLimits, with direct-body SHA256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99. This is a traceability binding, not a new premise or semantic proof. + + + **L991** Records the source reference software-engineering.revision/p1 for CoreReader.Engineering.revisionLimits, with direct-body SHA256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99. This is a traceability binding, not a new premise or semantic proof. + + + **L992** Closes the source-mapping comment for CoreReader.Engineering.revisionLimits; executable declarations resume after the comment. + + + **L993** Collects limits on retrospective success, revision count, agreement, repeated local success and justified stability. + + + **L994** The ordinary historical account is valid. + + + **L995** Merely flipping reportedPredictionSucceeded to true invalidates the account. + + + **L996** Three revisions have occurred in the explicit list, but their number supplies no correctness theorem. + + + **L997** All three maintainers agree on the static result three, while the live result is five; agreement does not erase the counterexample. + + + **L998** Every listed size-ten observation agrees between static and live predictors. + + + **L999** Those repeated successes coexist with a failure at runtime size five. + + + **L1000** The stable report remains history-valid and keeps the old design choice, showing revision openness need not force every act to change design. + + + **L1001** The unsupported quantum-backend alternative still permits retaining the current design. + + + **L1002** Builds the conjunction with finite decisions, leaving only the falsely reported-success account to an explicit reduction. + + + **L1003** Builds the conjunction with finite decisions, leaving only the falsely reported-success account to an explicit reduction. + + + **L1004** Expands the fixed history, actual report and material-change predicates so the false success claim is exposed as the concrete three-versus-five mismatch. + + + **L1005** The remaining decidable contradiction is checked computationally. + + + **L1007** Extracts each record's listed directions regardless of ground constructor; this extraction records forecast content and does not itself prove credibility. + + + **L1008** Extracts each record's listed directions regardless of ground constructor; this extraction records forecast content and does not itself prove credibility. + + + **L1010** Builds a current revision state from the actual context and selected design rather than independent report placeholders. + + + **L1011** Sets time one and concatenates the directions listed in the actual context evidence into the forecast. + + + **L1012** Copies maintenance amount and participating maintainers from the same activity. + + + **L1013** Uses the selected design's actual assigned migration cost. + + + **L1014** Uses the same context's migration objective capacity. + + + **L1015** Records the actual chosen candidate. + + + **L1017** The report retains historical data from stableRecord but binds software, actual current state and recorded current state to this context and chosen candidate. + + + **L1018** The report retains historical data from stableRecord but binds software, actual current state and recorded current state to this context and chosen candidate. + + + **L1020** Checks that the instantiated revision report really belongs to the shared engineering context and satisfies its fixed-history account. + + + **L1021** Its software identifier equals the activity's actual identifier. + + + **L1022** The same identifier matches historical evidence, and current maintenance equals the activity's schedule. + + + **L1023** The same identifier matches historical evidence, and current maintenance equals the activity's schedule. + + + **L1024** Current maintainers equal the actual participant list. + + + **L1025** Current migration cost equals evolvable's assigned cost. + + + **L1026** Current objective capacity equals the shared context's migration capacity. + + + **L1027** Current objective capacity equals the shared context's migration capacity. + + + **L1028** The recorded current choice is actually evolvable. + + + **L1029** The fully bound report satisfies RevisionAccount; the concrete checks are decided from its actual fields. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope. + + + **L1031** The whole domain bundle retains actual subject, credibility, accounts and revision duties on one context. Its chosen finite application records do not claim universal engineering adequacy. + + + **L1032** The whole domain bundle retains actual subject, credibility, accounts and revision duties on one context. Its chosen finite application records do not claim universal engineering adequacy. + + + **L1033** The whole domain bundle retains actual subject, credibility, accounts and revision duties on one context. Its chosen finite application records do not claim universal engineering adequacy. + + + **L1034** Combine the represented domain duties for one context and selected design. This bundle has no unconditional Meets field; priority applicability is not an overall requirement-rejection test. + + + **L1035** Require ActivityScope and the conditional EvolutionPriority. If PriorityConditions is false, that implication holds vacuously; this conjunct does not reject the choice for unmet requirements, while the remaining domain duties still apply. + + + **L1036** Requires actual credible grounds for the design-revision direction. + + + **L1037** If a departure is recorded, it must be a justified concrete-cost departure; absent departure creates no extra exception. + + + **L1038** Requires the successor's actual design-revision capability with explicit revision of obligations. + + + **L1039** Requires a structural account matching the same activity, chosen candidate and design-revision evidence. + + + **L1040** Requires a preservation-or-revision account comparing the selected design's order contract with the actual design-revision contract. + + + **L1041** Requires the same context/candidate revision report to satisfy the fixed independent historical account. + + + **L1043** Constructs actual whole-domain satisfaction for the shared continuing evolvable example. + + + **L1044** Computes the concrete subject, priority, credibility, change, structural, contract and history obligations; leaves the conditional departure check. + + + **L1045** The ordinary context records departure=none, so the implication requiring justification for a recorded departure is vacuously satisfied; priority itself still has actual applicability and no cost escape. + + + **L1047** Closes the engineering namespace; all declarations above remain available under CoreReader.Engineering. + + +### `leanified/CoreReader/Engineering/Integration.lean` + + +```lean +import CoreReader.Engineering.Domain +import CoreReader.Engineering.Reflection +import CoreReader.Engineering.SelfApplication + +namespace CoreReader.Engineering + +open CoreReader.Logic CoreReader.Evidence CoreReader.Adopted + +/- All interpretations below share this activity, requirements, evidence and +cost limits. Only the selected implementation and its stated value priority vary. -/ +abbrev sharedContext : Context := currentContinuing + +def maintainedOutput (chosen : Candidate) (n : Nat) : Nat := + (behavior chosen [n]).headD 0 + +def chosenImplementation (chosen : Candidate) : CoreReader.Choice.Implementation where + name := "order-preserving queue" + conventional := chosen == .presentSimple + established := chosen == .presentSimple + run := maintainedOutput chosen + cost := abstractionComplexity chosen + domain _ := True + explanation := maintainedOutput chosen + trace n := [maintainedOutput chosen n] + +/- This Core choice projection checks the queue's one-item observable contract +and present understanding budget. Domain retains its additional required checks. -/ +def chosenRequirements : CoreReader.Choice.Requirements where + inputs _ := True + expected n := n + budget := sharedContext.limits.capacity .understanding + values _ := True + +def chosenReasons : List CoreReader.Choice.Reason := + [.method .output, .method .simplicity] + +theorem maintainedOutputCorrect (chosen : Candidate) (n : Nat) : + maintainedOutput chosen n = n := by + rfl + +theorem implementationReasoned (chosen : Candidate) + (budget : abstractionComplexity chosen ≤ chosenRequirements.budget) : + choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons := by + refine ⟨⟨fun n _ => maintainedOutputCorrect chosen n, budget⟩, + .method .output, ?_, ?_⟩ + · simp [chosenReasons] + · exact ⟨trivial, fun n _ => maintainedOutputCorrect chosen n⟩ + +/- This reported capability concerns actual paths for each maintainer. Zero +records the unavailable path, not an assertion that an unsupported path exists. -/ +def capabilityOutput (chosen : Candidate) (input : Nat) : Nat := + let maintainer := if input = 0 then Maintainer.original + else if input = 1 then Maintainer.successor else Maintainer.agent + if decide (CanChange sharedContext.activity chosen maintainer .designRevision) + then changeWork chosen .designRevision else 0 + +def engineeringProcess (chosen : Candidate) : Process := + ⟨capabilityOutput chosen, none⟩ + +def engineeringCapability (chosen : Candidate) : Claim Process := + fun process => ∀ input, process.output input = capabilityOutput chosen input + +theorem engineeringCapabilityGrounded (chosen : Candidate) : + capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen) := by + exact grounds012Singleton _ (processContractDischarged _ _ (fun _ => rfl)) + +theorem actualCapabilityContrast : + (engineeringProcess .presentSimple).output 0 = 17 ∧ + (engineeringProcess .presentSimple).output 1 = 0 ∧ + (engineeringProcess .presentSimple).output 2 = 0 ∧ + (engineeringProcess .evolvable).output 0 = 6 ∧ + (engineeringProcess .evolvable).output 1 = 6 ∧ + (engineeringProcess .evolvable).output 2 = 6 := by decide + +/- A recorded threshold test measures present abstraction complexity in this +finite model. It does not observe future maintainability or establish a value. -/ +def presentBudgetRecord : Record Candidate := + ⟨fun candidate => decide (abstractionComplexity candidate ≤ 3), true⟩ + +abbrev presentBudgetClaim : Claim Candidate := fun candidate => abstractionComplexity candidate ≤ 3 + +theorem budgetObservationMeaning (candidate : Candidate) : + Compatible [presentBudgetRecord] candidate ↔ presentBudgetClaim candidate := by + constructor + · intro observed + have result := observed presentBudgetRecord (List.mem_singleton.mpr rfl) + exact of_decide_eq_true result + · intro enough record member + cases List.mem_singleton.mp member + exact decide_eq_true enough + +def budgetEmpiricalFacet : Facet Candidate := + .empirical [presentBudgetRecord] (fun _ => True) presentBudgetClaim (fun _ => True) + +theorem budgetEmpiricalDischarged : FacetDischarged budgetEmpiricalFacet := by + refine ⟨⟨.evolvable, (budgetObservationMeaning _).2 (by decide), trivial⟩, ?_, ?_⟩ + · intro candidate observed _ + exact (budgetObservationMeaning candidate).1 observed + · intro _ _; trivial + +def capacityClaim : Claim Candidate := + fun candidate => abstractionComplexity candidate ≤ sharedContext.limits.capacity .understanding + +def capacityAssumptions : Theory Candidate := singleton presentBudgetClaim + +def budgetInferentialFacet : Facet Candidate := .inferential capacityAssumptions capacityClaim + +theorem budgetInferentialDischarged : FacetDischarged budgetInferentialFacet := by + refine ⟨⟨.evolvable, (modelsSingleton _ _).2 (by decide)⟩, ?_⟩ + intro candidate premises + have small := (modelsSingleton _ _).1 premises + exact Nat.le_trans small (by decide) + +def budgetScopeAccount : ScopeAccount Candidate where + claim := presentBudgetClaim + conditions := fun _ => True + observationScope := fun _ => True + relevant := fun a b => behavior a [2, 1, 2] = behavior b [2, 1, 2] + compared := fun a b => presentBudgetClaim a ∧ presentBudgetClaim b + used method := method = .measurement + role _ := "threshold observation of present complexity; no future-performance conclusion" + explains method text claim conditions := method = .measurement ∧ + text = "threshold observation of present complexity; no future-performance conclusion" ∧ + claim = presentBudgetClaim ∧ conditions = (fun _ => True) + +theorem budgetScopeExplained : scopeSpecification budgetScopeAccount := by + constructor + · intro a b _; exact ⟨trivial, trivial, trivial, trivial, rfl⟩ + · intro method hm + exact ⟨by change "threshold observation of present complexity; no future-performance conclusion" ≠ ""; decide, + hm, rfl, rfl, rfl⟩ + +/- The unchanged observation cannot justify a stronger complexity bound. -/ +theorem budgetObservationLimit : + Compatible [presentBudgetRecord] .evolvable ∧ + ¬ Supports [presentBudgetRecord] (fun candidate => abstractionComplexity candidate ≤ 1) := by + refine ⟨(budgetObservationMeaning _).2 (by decide), ?_⟩ + intro support + have impossible := support .evolvable ((budgetObservationMeaning _).2 (by decide)) + exact (by decide : ¬ (3 ≤ 1)) impossible + +/- The policy values expansion while keeping every represented organization, +method and principle form revisable. It does not assert that a revision occurs. -/ +def engineeringPolicy : CoreReader.Agency.Policy where + worthPursuing aim := + (aim = .expandUnderstandingAndConstruction ∧ coreAdopted .generation = true) ∨ + aim = .preserveSafeOperation + current form := form.version = 1 + revisable form := ∃ next, form.version < next ∧ coreAdopted .generation = true + permitsVersion old next := old ≤ next + +theorem engineeringGenerative : generationSpecification engineeringPolicy := by + exact ⟨Or.inl ⟨rfl, rfl⟩, fun form _ => ⟨form.version + 1, Nat.lt_succ_self _, rfl⟩⟩ + +/- Own facts are mathematical reports about this model and its recorded state. +Their inferential tasks do not replace the separate empirical or value tasks. -/ +inductive OwnFact + | selected | requirements | capacity | capability | forecast | revision + | generativePolicy | reflection | coreAdoption (principle : CoreCommitment) + deriving DecidableEq, Repr + +abbrev ownFactClaim (adopted : Candidate) : OwnFact → Claim Candidate + | .selected => fun candidate => candidate = adopted + | .requirements => fun candidate => Meets sharedContext.required (sharedContext.profiles candidate) + | .capacity => capacityClaim + | .capability => fun candidate => engineeringCapability candidate (engineeringProcess candidate) + | .forecast => fun _ => staticBatch 21 10 = liveBatch 21 10 ∧ staticBatch 21 5 ≠ liveBatch 21 5 + | .revision => fun candidate => RevisionAccount (revisionFor sharedContext candidate) + | .generativePolicy => fun _ => generationSpecification engineeringPolicy + | .reflection => fun candidate => reflexivitySpecification + (selfModel candidate).rules (selfModel candidate).self (selfModel candidate).performed + | .coreAdoption principle => (governancePosition principle).commitment + +theorem actualOwnFact (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) (fact : OwnFact) : + ownFactClaim chosen fact chosen := by + cases fact with + | selected => rfl + | requirements => cases chosen <;> decide + | capacity => rcases ordinary with rfl | rfl <;> change _ ≤ 12 <;> decide + | capability => intro _; rfl + | forecast => exact ⟨rfl, by decide⟩ + | revision => rcases ordinary with rfl | rfl <;> decide + | generativePolicy => exact engineeringGenerative + | reflection => exact currentSelfApplication chosen ordinary + | coreAdoption _ => rfl + +def ownFactPremises (chosen : Candidate) : Theory Candidate := + singleton (fun candidate => candidate = chosen) + +theorem actualOwnFactGrounded (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) (fact : OwnFact) : + inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact) := by + apply grounds012Singleton + refine ⟨⟨chosen, (modelsSingleton _ _).2 rfl⟩, ?_⟩ + intro candidate same + have identity := (modelsSingleton _ _).1 same + subst candidate + exact actualOwnFact chosen ordinary fact + +/- In this fixed applicable context, the actual priority rule and the adopted +evolution value select exactly the same candidate. This identity connects its +value grounds to the normative rule, not merely to an adoption label. -/ +theorem priorityValueMeaning (candidate : Candidate) : + (selectionPosition .evolvable).commitment candidate ↔ + EvolutionPriority sharedContext candidate := by + constructor + · intro selected + change candidate = .evolvable at selected + subst candidate + exact currentDomainSatisfied.2.1 + · intro priority + exact (priorityWhenApplicable sharedContext candidate priority + currentPriorityConditions currentNoThreat.2).1 + +theorem priorityGrounds : + Grounds012 (EvolutionPriority sharedContext) canonicalArticulation + [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) := by + have same : (selectionPosition .evolvable).commitment = EvolutionPriority sharedContext := + funext (fun candidate => propext (priorityValueMeaning candidate)) + rw [← same] + exact selectionGrounded .evolvable (Or.inr rfl) + +/- Facts of adoption remain distinct from the actual normative contents. Each +constructor below denotes its full represented duty, with its original task, +conditions, reasons and scope. Domain duties enter only for the domain adopter. +Consistency is the constraint on the resulting whole theory below; it is not +encoded as a self-referential proposition in that theory's own definition. -/ +inductive OwnNorm + | generation | reflection | empirical | inferential | principleValue (principle : CoreCommitment) + | selectionValue | scope | capability | choice | ownGrounds (fact : OwnFact) + | domain | priorityValue + deriving DecidableEq, Repr + +def normApplies (adopted : Candidate) : OwnNorm → Prop + | .domain | .priorityValue => adopted = .evolvable + | _ => True + +def ownNormClaim (adopted : Candidate) : OwnNorm → Claim Candidate + | .generation => fun _ => generationSpecification engineeringPolicy + | .reflection => fun candidate => reflexivitySpecification + (selfModel candidate).rules (selfModel candidate).self (selfModel candidate).performed + | .empirical => fun _ => empiricalSpecification [presentBudgetRecord] (fun _ => True) + presentBudgetClaim (fun _ => True) + | .inferential => fun _ => inferentialSpecification capacityAssumptions capacityClaim + | .principleValue principle => fun _ => valueSpecification (governancePosition principle) + | .selectionValue => fun candidate => valueSpecification (selectionPosition adopted) ∧ + (selectionPosition adopted).commitment candidate + | .scope => fun _ => scopeSpecification budgetScopeAccount + | .capability => fun candidate => capabilitySpecification + (engineeringProcess candidate) (engineeringCapability candidate) + | .choice => fun candidate => choiceSpecification + chosenRequirements (chosenImplementation candidate) chosenReasons + | .ownGrounds fact => fun _ => inferentialSpecification + (ownFactPremises adopted) (ownFactClaim adopted fact) + | .domain => fun candidate => DomainSatisfied sharedContext candidate + | .priorityValue => fun _ => Grounds012 (EvolutionPriority sharedContext) canonicalArticulation + [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) + +theorem actualOwnNorm (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) + (norm : OwnNorm) (applicable : normApplies chosen norm) : ownNormClaim chosen norm chosen := by + cases norm with + | generation => exact engineeringGenerative + | reflection => exact currentSelfApplication chosen ordinary + | empirical => exact grounds012Singleton _ budgetEmpiricalDischarged + | inferential => exact grounds012Singleton _ budgetInferentialDischarged + | principleValue principle => exact governanceGrounded principle + | selectionValue => exact ⟨selectionGrounded chosen ordinary, rfl⟩ + | scope => exact budgetScopeExplained + | capability => exact engineeringCapabilityGrounded chosen + | choice => + apply implementationReasoned + rcases ordinary with rfl | rfl <;> change _ ≤ 12 <;> decide + | ownGrounds fact => exact actualOwnFactGrounded chosen ordinary fact + | domain => + change chosen = .evolvable at applicable + subst chosen + exact currentDomainSatisfied + | priorityValue => exact priorityGrounds + +def ownFactTheory (chosen : Candidate) : Theory Candidate := + fun claim => ∃ fact : OwnFact, claim = ownFactClaim chosen fact + +def ownNormTheory (chosen : Candidate) : Theory Candidate := + fun claim => ∃ norm : OwnNorm, normApplies chosen norm ∧ claim = ownNormClaim chosen norm + +/- The consequence relation now acts on all these facts and normative contents +together, including the implications of their union. -/ +def ownTheory (chosen : Candidate) : Theory Candidate := + union (ownFactTheory chosen) (ownNormTheory chosen) + +theorem allNormativeContentHeld (chosen : Candidate) (norm : OwnNorm) + (applicable : normApplies chosen norm) : ownTheory chosen (ownNormClaim chosen norm) := + Or.inr ⟨norm, applicable, rfl⟩ + +theorem nonemptyOwnObjects (chosen : Candidate) : + ownTheory chosen (ownFactClaim chosen .selected) ∧ + ownTheory chosen (ownFactClaim chosen (.coreAdoption .grounds)) ∧ + (.activity : ReviewObject) ∈ (selfModel chosen).objects ∧ + (.commitment .grounds : ReviewObject) ∈ (selfModel chosen).objects := by + refine ⟨Or.inl ⟨.selected, rfl⟩, Or.inl ⟨.coreAdoption .grounds, rfl⟩, ?_, ?_⟩ <;> + simp [selfModel, reviewObjects, coreCommitments] + +def comparisonContext (chosen : Candidate) : CoreReader.Logic.Context Candidate OwnFact where + assumptions := ownFactPremises chosen + meaning := ownFactClaim chosen + scope := valueScope + +def engineeringSnapshot (chosen : Candidate) (revision : Nat) : Snapshot Candidate OwnFact := + ⟨ownTheory chosen, comparisonContext chosen, revision⟩ + +theorem currentAdmissible (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) : + Admissible (ownTheory chosen) (comparisonContext chosen) chosen := by + refine ⟨?_, (modelsSingleton _ _).2 rfl, ?_⟩ + · intro claim held + rcases held with factHeld | normHeld + · obtain ⟨fact, rfl⟩ := factHeld + exact actualOwnFact chosen ordinary fact + · obtain ⟨norm, applicable, rfl⟩ := normHeld + exact actualOwnNorm chosen ordinary norm applicable + · rcases ordinary with rfl | rfl <;> change _ ≤ 3 <;> decide + +theorem currentConsistency (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) : + consistencySpecification (engineeringSnapshot .evolvable 0) + (engineeringSnapshot chosen 1) true := by + exact ⟨consequenceConsistency _ _ ⟨chosen, currentAdmissible chosen ordinary⟩, fun _ => rfl⟩ + +theorem wholeClaimGrounded (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) + (claim : Claim Candidate) (held : ownTheory chosen claim) : + inferentialSpecification (ownFactPremises chosen) claim := by + apply grounds012Singleton + refine ⟨⟨chosen, (modelsSingleton _ _).2 rfl⟩, ?_⟩ + intro candidate same + have identity := (modelsSingleton _ _).1 same + subst candidate + exact (currentAdmissible chosen ordinary).1 claim held + +/- Keeping the same adoption marker does not conceal contradictory normative +contents. Both demands act on the very same candidate, question and scope. -/ +def incompatibleNormTheory : Theory Candidate := + union (singleton (fun candidate => candidate = .presentSimple)) + (singleton (fun candidate => candidate ≠ .presentSimple)) + +def incompatibleNormContext : CoreReader.Logic.Context Candidate Unit := + ⟨emptyTheory, fun _ candidate => candidate = .presentSimple, fun _ => True⟩ + +theorem normativeContentVariation : + coreAdopted .choice = true ∧ + ¬ Consistent incompatibleNormTheory incompatibleNormContext ∧ + normApplies .evolvable .domain ∧ ¬ normApplies .presentSimple .domain ∧ + ownTheory .evolvable (ownNormClaim .evolvable .domain) ∧ + ¬ ownTheory .presentSimple (ownNormClaim .presentSimple .domain) := by + refine ⟨rfl, ?_, rfl, by unfold normApplies; decide, allNormativeContentHeld _ _ rfl, ?_⟩ + · apply conflictRequiresChange _ _ () + · intro candidate admissible + change candidate = .presentSimple + exact (modelsSingleton (fun c : Candidate => c = .presentSimple) candidate).1 + ((modelsUnion _ _ _).1 admissible.1).1 + · intro candidate admissible + change candidate ≠ .presentSimple + exact (modelsSingleton (fun c : Candidate => c ≠ .presentSimple) candidate).1 + ((modelsUnion _ _ _).1 admissible.1).2 + · intro held + have domain := (currentAdmissible .presentSimple (Or.inl rfl)).1 _ held + exact currentSimpleViolates domain.2.1 + +/- Every field is an actual satisfaction or support condition. Value accounts +and assessment completion do not replace the normative fields they explain. +The identity field limits this implementation to its disclosed common context. -/ +structure Inherited (ctx : Context) (chosen : Candidate) : Prop where + sameContext : ctx = sharedContext + generation : generationSpecification engineeringPolicy + consistency : consistencySpecification (engineeringSnapshot .evolvable 0) + (engineeringSnapshot chosen 1) true + reflection : reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self + (selfModel chosen).performed + ownPrincipleGrounds : ∀ principle, valueSpecification (governancePosition principle) + choiceValueGrounds : valueSpecification (selectionPosition chosen) + empiricalGrounds : empiricalSpecification [presentBudgetRecord] (fun _ => True) + presentBudgetClaim (fun _ => True) + inferentialGrounds : inferentialSpecification capacityAssumptions capacityClaim + scopeAccount : scopeSpecification budgetScopeAccount + capabilityGrounds : capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen) + implementationChoice : choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons + ownClaimGrounds : ∀ fact, inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact) + observedHere : Compatible [presentBudgetRecord] chosen + selectionActuallyAdopted : (selectionPosition chosen).commitment chosen + currentOwnClaims : Models (ownTheory chosen) chosen + fullNormativeContents : ∀ norm, normApplies chosen norm → + ownTheory chosen (ownNormClaim chosen norm) + wholeClaimGrounds : ∀ claim, ownTheory chosen claim → + inferentialSpecification (ownFactPremises chosen) claim + +theorem inheritedCurrent (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) : + Inherited sharedContext chosen := by + refine ⟨rfl, engineeringGenerative, currentConsistency chosen ordinary, + currentSelfApplication chosen ordinary, governanceGrounded, + selectionGrounded chosen ordinary, grounds012Singleton _ budgetEmpiricalDischarged, + grounds012Singleton _ budgetInferentialDischarged, budgetScopeExplained, + engineeringCapabilityGrounded chosen, ?_, actualOwnFactGrounded chosen ordinary, + ?_, rfl, (currentAdmissible chosen ordinary).1, + allNormativeContentHeld chosen, wholeClaimGrounded chosen ordinary⟩ + · apply implementationReasoned + rcases ordinary with rfl | rfl <;> change _ ≤ 12 <;> decide + · apply (budgetObservationMeaning _).2 + rcases ordinary with rfl | rfl <;> change _ ≤ 3 <;> decide + +/- Mutual application extracts duties for the same system, principles, claims +and actual chosen implementation. It retains the full Inherited premise. -/ +/-- organon-map CoreReader.Engineering.inheritedMutualApplication +organon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +theorem inheritedMutualApplication (ctx : Context) (chosen : Candidate) + (inherited : Inherited ctx chosen) : + generationSpecification engineeringPolicy ∧ + reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self + (selfModel chosen).performed ∧ + (∀ principle, valueSpecification (governancePosition principle)) ∧ + capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen) ∧ + choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons ∧ + (∀ fact, inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact)) ∧ + (∀ norm, normApplies chosen norm → ownTheory chosen (ownNormClaim chosen norm)) ∧ + (∀ claim, ownTheory chosen claim → inferentialSpecification (ownFactPremises chosen) claim) ∧ + consistencySpecification (engineeringSnapshot .evolvable 0) + (engineeringSnapshot chosen 1) true := + ⟨inherited.generation, inherited.reflection, inherited.ownPrincipleGrounds, + inherited.capabilityGrounds, inherited.implementationChoice, inherited.ownClaimGrounds, + inherited.fullNormativeContents, inherited.wholeClaimGrounds, inherited.consistency⟩ + +/-- organon-map CoreReader.Engineering.inheritedMutualCases +organon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +theorem inheritedMutualCases : + Inherited sharedContext .evolvable ∧ + valueSpecification (governancePosition .grounds) ∧ + capabilitySpecification (engineeringProcess .evolvable) (engineeringCapability .evolvable) ∧ + choiceSpecification chosenRequirements (chosenImplementation .evolvable) chosenReasons ∧ + Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧ + (.generationRule : ReviewObject) ∈ (selfModel .evolvable).objects ∧ + (.assessmentRule : ReviewObject) ∈ (selfModel .evolvable).objects ∧ + Reflection.evaluate ((selfModel .evolvable).input ⟨0, .assessmentRule, .revision⟩) = .counterexample := + ⟨inheritedCurrent .evolvable (Or.inr rfl), governanceGrounded .grounds, + engineeringCapabilityGrounded .evolvable, + (inheritedCurrent .evolvable (Or.inr rfl)).implementationChoice, + (actualSelfCriticism .evolvable).2.2.1, + (ownRuleIdentity .evolvable .generation .revision).1, + (ownRuleIdentity .evolvable .assessment .revision).1, + (ownRuleContentVariation .evolvable).2.2.2.2.1⟩ + +/- In the adopter's same context, the actual priority object and its own +assessment method remain within the inherited criticism/generation contract. -/ +/-- organon-map CoreReader.Engineering.priorityRemainsReflexive +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +extensions#p1 sha256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66 +software-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +software-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +-/ +theorem priorityRemainsReflexive (ctx : Context) (chosen : Candidate) + (inherited : Inherited ctx chosen) (domain : DomainSatisfied ctx chosen) + (applicable : PriorityConditions ctx) (noDeparture : ¬ JustifiedDeparture ctx .evolvable) : + chosen = .evolvable ∧ + (.priority : ReviewObject) ∈ (selfModel chosen).objects ∧ + reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self + (selfModel chosen).performed ∧ + (∀ principle, valueSpecification (governancePosition principle)) ∧ + Grounds012 (EvolutionPriority ctx) canonicalArticulation + [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) ∧ + ownTheory chosen (ownNormClaim chosen .domain) ∧ + consistencySpecification (engineeringSnapshot .evolvable 0) + (engineeringSnapshot chosen 1) true := by + have selected := (priorityWhenApplicable ctx chosen domain.2.1 applicable noDeparture).1 + refine ⟨selected, ?_, inherited.reflection, inherited.ownPrincipleGrounds, + ?_, allNormativeContentHeld chosen .domain selected, inherited.consistency⟩ + · subst chosen; decide + · rw [inherited.sameContext] + exact priorityGrounds + +/-- organon-map CoreReader.Engineering.priorityReflexiveCases +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +extensions#p1 sha256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66 +software-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +software-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +-/ +theorem priorityReflexiveCases : + (.priority : ReviewObject) ∈ (selfModel .evolvable).objects ∧ + objectTest .priority (.evolvable, 10) = true ∧ + (selfModel .evolvable).performed ⟨0, 1⟩ ⟨0, .priority, .revision⟩ + ((selfModel .evolvable).input ⟨0, .priority, .revision⟩) + (.assessed .supportedWithinScope) ∧ + Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧ + objectTest .evolutionMethod (.evolvable, 10) = true ∧ + objectTest .evolutionMethod (.evolvable, 5) = false ∧ + Grounds012 (EvolutionPriority sharedContext) canonicalArticulation + [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) ∧ + Reflection.evaluate ((selfModel .evolvable).input ⟨0, .assessmentRule, .revision⟩) = .counterexample := by + refine ⟨by decide, by decide, ?_, (actualSelfCriticism .evolvable).2.2.1, + (actualSelfCriticism .evolvable).1, (actualSelfCriticism .evolvable).2.1, + priorityGrounds, (ownRuleContentVariation .evolvable).2.2.2.2.1⟩ + exact ⟨⟨rfl, by decide⟩, rfl, .assessment, rfl, rfl⟩ + +/- The witness is nonempty and satisfies the entire represented inherited and +domain bundles in the very same continuing activity, with active priority. -/ +/-- organon-map CoreReader.Engineering.jointWitness +organon.charter.overview#p2 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c +organon.charter.overview#p3 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c +organon.charter.self-transcendence#p1 sha256 f4ca590e2ae15e3882f70c7b2bc46a8911c97cee547c8b137b5493fbf862c8c0 +organon.charter.self-transcendence.orientation#p1 sha256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf +organon.charter.self-transcendence.non-finality#p1 sha256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8 +organon.charter.self-transcendence.limits#p1 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d +organon.charter.self-transcendence.limits#p2 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d +organon.charter.consistency#p1 sha256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42 +organon.charter.consistency.meaning#p1 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75 +organon.charter.reflexivity#p1 sha256 13293b45c2fa89068c68ae7ef3c5df38f0efadb3ef3873d78a5ba67d9691a757 +organon.charter.reflexivity.meaning#p1 sha256 8a2caede01a43d8b6c60b54c78ac089c51868e9956f316948077ccee2e45c9cc +organon.charter.reflexivity.limits#p1 sha256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc +organon.grounds#p1 sha256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6 +organon.grounds.assessment#p1 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.scope#p1 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.scope#p2 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.scope#p3 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.capabilities#p1 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0 +organon.grounds.capabilities#p2 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0 +organon.grounds.implementations#p1 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c +organon.grounds.implementations#p2 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c +organon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870 +organon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +extensions#p1 sha256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66 +software-engineering.purpose#p1 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.purpose#p2 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-meaning#p1 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6 +software-engineering.evolution-meaning#p2 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6 +software-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +software-engineering.structural-judgment#p2 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +software-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +software-engineering.revision#p1 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +software-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +-/ +theorem jointWitness : + ∃ ctx : Context, ∃ chosen : Candidate, + ctx = sharedContext ∧ chosen = .evolvable ∧ + Inherited ctx chosen ∧ DomainSatisfied ctx chosen ∧ + PriorityConditions ctx ∧ ¬ HasThreat ctx .evolvable ∧ + abstractionComplexity .presentSimple < abstractionComplexity chosen ∧ + CanChange ctx.activity chosen .successor .designRevision ∧ + CanChange ctx.activity chosen .agent .designRevision ∧ + ownTheory chosen (ownFactClaim chosen .selected) ∧ + (.commitment .grounds : ReviewObject) ∈ (selfModel chosen).objects ∧ + Admissible (ownTheory chosen) (comparisonContext chosen) chosen := by + exact ⟨sharedContext, .evolvable, rfl, rfl, + inheritedCurrent .evolvable (Or.inr rfl), currentDomainSatisfied, + currentPriorityConditions, currentNoThreat.1, by decide, by decide, by decide, + (nonemptyOwnObjects .evolvable).1, (nonemptyOwnObjects .evolvable).2.2.2, + currentAdmissible .evolvable (Or.inr rfl)⟩ + +/- The countermodel adopts a supported present-simplicity value and actually +chooses that option. Every inherited duty still holds. The domain conditions +are active; neither lifecycle nor threatened costs supplies an escape. -/ +/-- organon-map CoreReader.Engineering.inheritedDoesNotEntailPriority +organon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +extensions#p1 sha256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66 +software-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +theorem inheritedDoesNotEntailPriority : + ∃ ctx : Context, ∃ chosen : Candidate, + ctx = sharedContext ∧ chosen = .presentSimple ∧ + Inherited ctx chosen ∧ PriorityConditions ctx ∧ + Continuing ctx.activity ∧ ¬ BoundedLifecycle ctx.activity ∧ + ¬ HasThreat ctx .evolvable ∧ ¬ JustifiedDeparture ctx .evolvable ∧ + Meets ctx.required (ctx.profiles .presentSimple) ∧ + Meets ctx.required (ctx.profiles .evolvable) ∧ + credible ctx.evidence .designRevision ∧ + CanChange ctx.activity .evolvable .successor .designRevision ∧ + CanChange ctx.activity .evolvable .agent .designRevision ∧ + changeWork .evolvable .designRevision < changeWork chosen .designRevision ∧ + abstractionComplexity chosen < abstractionComplexity .evolvable ∧ + valueSpecification (selectionPosition chosen) ∧ + (selectionPosition chosen).commitment chosen ∧ + ¬ EvolutionPriority ctx chosen := by + exact ⟨sharedContext, .presentSimple, rfl, rfl, + inheritedCurrent .presentSimple (Or.inl rfl), currentPriorityConditions, + by decide, by decide, currentNoThreat.1, currentNoThreat.2, + by decide, by decide, by decide, by decide, by decide, by decide, by decide, + selectionGrounded .presentSimple (Or.inl rfl), rfl, currentSimpleViolates⟩ + +end CoreReader.Engineering +``` + + + + **L1** Import CoreReader.Engineering.Domain, making its declarations and transitive dependencies available; this line adds no new proposition. + + + **L2** Import CoreReader.Engineering.Reflection, making its declarations and transitive dependencies available; this line adds no new proposition. + + + **L3** Import CoreReader.Engineering.SelfApplication, making its declarations and transitive dependencies available; this line adds no new proposition. + + + **L5** Open namespace CoreReader.Engineering for the following declarations. + + + **L7** Allow unqualified references to declarations in CoreReader.Logic CoreReader.Evidence CoreReader.Adopted; their meaning is unchanged. + + + **L9** Comment fixes the activity, requirements and evidence shared by all interpretations here. + + + **L10** Comment also fixes cost limits while permitting the chosen implementation and stated value to vary. + + + **L11** All integrated claims use sharedContext, definitionally the fixed currentContinuing context. + + + **L13** For a chosen design and natural input, maintainedOutput extracts one observable result. + + + **L14** Run behavior on the singleton [n] and take its head, defaulting to 0 if empty. + + + **L16** Project the chosen design into Core's Implementation record. + + + **L17** Use the shared descriptive name order-preserving queue. + + + **L18** Mark conventional exactly when chosen is presentSimple. + + + **L19** Mark established under the same Boolean equality. + + + **L20** Use maintainedOutput as the implementation's actual run function. + + + **L21** Its Core-level cost is the chosen design's abstraction complexity. + + + **L22** The projected domain permits every natural input. + + + **L23** Use the identical maintainedOutput function as its explanation. + + + **L24** The trace is a singleton containing the final output; it is not an internal execution trace. + + + **L26** Comment limits the Core choice projection to the queue's one-item observable contract. + + + **L27** Comment adds present understanding budget and retains separate domain checks outside this projection. + + + **L28** Define the Core choice requirements for this projection. + + + **L29** Every natural number is an admissible input. + + + **L30** The expected result is the input itself. + + + **L31** Use the shared context's understanding capacity as budget. + + + **L32** The additional values predicate is unrestricted True. + + + **L34** The available Core choice reasons form a finite list. + + + **L35** List output and simplicity method reasons; membership alone will not prove a reason adequate. + + + **L37** For every design and natural n, state correctness of the one-item output projection. + + + **L38** The actual maintainedOutput must equal n. + + + **L39** The equality is definitional for singleton input, so reflexivity proves it. + + + **L41** Prove reasoned Core implementation choice for any chosen design under a budget premise. + + + **L42** Assume actual abstraction complexity is within chosenRequirements.budget. + + + **L43** The conclusion uses the actual requirements, projected implementation and listed reasons. + + + **L44** Construct functional correctness for every allowed input and reuse the supplied budget proof. + + + **L45** Choose the output method reason; leave its membership and adequacy obligations. + + + **L46** Unfold chosenReasons to establish membership of the output reason. + + + **L47** Prove the output reason's unrestricted value condition and exact input/output contract. + + + **L49** Comment identifies the capability report as actual maintainer-indexed path availability. + + + **L50** Comment explains 0 as a missing-path marker, not evidence that a path exists. + + + **L51** capabilityOutput reports revision-path work for a maintainer encoded by a natural input. + + + **L52** Input 0 selects the original maintainer. + + + **L53** Input 1 selects the successor; every larger input selects the agent. + + + **L54** Decide actual CanChange for this maintainer, design and designRevision in sharedContext. + + + **L55** Return actual revision work when the path exists, otherwise 0 as an absence marker. + + + **L57** Build a Process reporting the chosen design's capability-output function. + + + **L58** Its output is capabilityOutput; its optional explanation is none. + + + **L60** Define the exact functional claim on a Process for this chosen design. + + + **L61** For all natural inputs, require the process output to equal capabilityOutput for that design. + + + **L63** Ground the functional capability claim for every chosen design. + + + **L64** The process and capability specification share the same chosen parameter. + + + **L65** Use an inferential process-contract facet discharged by pointwise reflexivity, then singleton grounds. + + + **L67** actualCapabilityContrast computes six concrete maintainer/design outputs. + + + **L68** presentSimple reports 17 work units for the original maintainer. + + + **L69** It reports absent-path marker 0 for the successor. + + + **L70** It also reports 0 for the agent. + + + **L71** evolvable reports 6 work units for the original maintainer. + + + **L72** It reports 6 for the successor too. + + + **L73** It reports 6 for the agent; decide computes all six equalities. + + + **L75** Comment introduces a recorded threshold of present abstraction complexity. + + + **L76** Comment confines that observation to this finite model and excludes future maintainability and value establishment. + + + **L77** Create one recorded Boolean threshold observation over Candidate. + + + **L78** The instrument checks abstraction complexity ≤ 3, and the recorded result is true. + + + **L80** presentBudgetClaim is precisely the same complexity-at-most-3 predicate. + + + **L82** For every candidate, relate compatibility with this record to its exact claim. + + + **L83** State an iff; the record constrains only present complexity. + + + **L84** Prove each direction of the equivalence separately. + + + **L85** Assume compatibility with the singleton observation list. + + + **L86** Apply compatibility to its actual record using singleton membership. + + + **L87** Convert the instrument's true Boolean result to the complexity proposition. + + + **L88** Conversely, assume the bound and introduce any listed record. + + + **L89** Singleton membership identifies it as presentBudgetRecord. + + + **L90** Convert the bound into the required Boolean equality to true. + + + **L92** Package the budget observation into an empirical Facet over Candidate. + + + **L93** Use the exact record and budget claim; both empirical scope and uncertainty predicates are True. + + + **L95** Prove actual discharge of that empirical facet. + + + **L96** Use evolvable as a compatible in-scope witness; leave claim support and uncertainty support to prove. + + + **L97** For every compatible candidate, introduce the trivial empirical-scope premise. + + + **L98** Use the forward observation equivalence to prove the exact budget claim. + + + **L99** The remaining uncertainty predicate is True, so every compatible candidate satisfies it trivially. + + + **L101** capacityClaim is a proposition about the actual current understanding capacity. + + + **L102** For each candidate require complexity ≤ sharedContext's understanding limit, which is 12. + + + **L104** The capacity inference assumes only the singleton presentBudgetClaim theory. + + + **L106** Construct the inferential facet from those assumptions to the capacity claim. + + + **L108** Prove this inference has a model and entails its claim. + + + **L109** Use evolvable to witness the complexity-at-most-3 assumptions, leaving entailment. + + + **L110** Introduce any candidate satisfying all inference premises. + + + **L111** Singleton-model equivalence extracts the ≤ 3 bound. + + + **L112** Combine that bound with the computed 3 ≤ 12 inequality. + + + **L114** Build a scope account for the present-budget measurement claim. + + + **L115** The explained claim is exactly presentBudgetClaim. + + + **L116** Application conditions are unrestricted True. + + + **L117** Observation scope is likewise True. + + + **L118** Comparative relevance means equal actual behavior on [2, 1, 2]. + + + **L119** Two candidates are compared only when both satisfy the budget claim. + + + **L120** The only used method is measurement. + + + **L121** The role text limits the observation to current complexity and excludes future-performance conclusions. + + + **L122** The explanation relation first requires the method to be measurement. + + + **L123** Require the exact stored limitation text. + + + **L124** Require identity of the explained claim and condition predicate. + + + **L126** Verify the stated scopeSpecification of this exact account. + + + **L127** Split comparative-scope and method-explanation obligations. + + + **L128** For compared candidates, prove four True conditions/scopes and use definitional equality of their actual behavior on [2,1,2] for relevance. + + + **L129** Introduce any actually used method and its usage proof. + + + **L130** Prove the role string is nonempty by computing its inequality with the empty string. + + + **L131** Reuse usage equality and reflexive identities for text, claim and conditions. + + + **L133** Comment introduces a counterexample to strengthening a claim without changing its observation. + + + **L134** Demonstrate that this observation does not support a stricter complexity bound. + + + **L135** evolvable is compatible with the recorded ≤ 3 result. + + + **L136** Yet the singleton record does not support the universal compatible-world claim complexity ≤ 1. + + + **L137** Prove compatibility via the observation equivalence, leaving failure of support. + + + **L138** Assume the stronger support relation for contradiction. + + + **L139** Apply it to compatible evolvable, obtaining the impossible 3 ≤ 1. + + + **L140** Compute ¬(3 ≤ 1) and apply it to that derived bound. + + + **L142** Comment states that the policy values expansion while retaining revisability of represented forms. + + + **L143** Comment includes organizations, methods and principles, but does not assert an actual revision event. + + + **L144** Instantiate an Agency.Policy for this engineering activity. + + + **L145** Define which aims count as worth pursuing. + + + **L146** Expansion is worthwhile when the generation commitment is explicitly adopted. + + + **L147** Preserving safe operation is also worthwhile unconditionally. + + + **L148** A form is current exactly when its version equals 1. + + + **L149** Revisability requires some greater natural-number version and generation adoption. + + + **L150** Permit any nondecreasing version transition. + + + **L152** Prove the generation specification for this concrete policy. + + + **L153** Witness adopted expansion and, for every current form, choose version + 1 as a strictly greater revisable version. + + + **L155** Comment identifies OwnFact values as mathematical reports of this model's state. + + + **L156** Comment preserves the separate empirical/value tasks despite these reports' inferential grounds. + + + **L157** OwnFact enumerates model reports that will be held in its theory. + + + **L158** Include selection, requirements, capacity, capability, forecast and revision reports. + + + **L159** Also include generation/reflection reports and an adoption report parameterized by principle. + + + **L160** Derive DecidableEq, Repr: decidable equality and printable representations of these constructors. + + + **L162** Interpret each OwnFact as a claim on Candidate, parameterized by the adopted design. + + + **L163** The selection report requires the candidate to equal the adopted design. + + + **L164** The requirements report uses that candidate's actual profile in sharedContext. + + + **L165** The capacity report is the previously defined actual capacity claim. + + + **L166** The capability report applies the candidate-indexed claim to the same candidate's process. + + + **L167** The forecast report states old size-10 agreement and size-5 disagreement, independent of candidate. + + + **L168** The revision report concerns the actual revisionFor sharedContext candidate account. + + + **L169** The policy report states generationSpecification of the actual engineeringPolicy. + + + **L170** The reflection report uses the candidate's actual reflexivity specification. + + + **L171** Rules, self targets and performed records all come from that same selfModel candidate. + + + **L172** The adoption report is the same principle's governance commitment predicate. + + + **L174** Prove each own fact about the actually selected design. + + + **L175** Require an ordinary design, but quantify universally over OwnFact. + + + **L176** Evaluate the adopted-indexed fact at that same chosen candidate. + + + **L177** Split on the fact constructor. + + + **L178** The selection report is chosen = chosen, proved reflexively. + + + **L179** For requirements, enumerate all three candidates and compute their necessary-profile checks. + + + **L180** For capacity, restrict to the two ordinary candidates and compute complexity ≤ 12. + + + **L181** For capability, introduce any input and use the identical output function reflexively. + + + **L182** For forecast, combine definitional old equality with computed new inequality. + + + **L183** For revision, substitute each ordinary design and decide its concrete account. + + + **L184** Reuse engineeringGenerative for the policy report. + + + **L185** Reuse actual currentSelfApplication under the ordinary premise. + + + **L186** The Core adoption flag is true by definitional equality. + + + **L188** Define the exact inference assumptions for facts about the chosen design. + + + **L189** The sole assumption is that the candidate equals chosen; this is an identity-conditioned inference. + + + **L191** Ground every own-fact report inferentially. + + + **L192** Keep the ordinary-design premise and universally selected fact. + + + **L193** Use the identity theory as premises and the actual fact interpretation as conclusion. + + + **L194** Reduce singleton grounds to discharge of its inferential facet. + + + **L195** Supply chosen as a model of its own identity premise; leave entailment. + + + **L196** Introduce an arbitrary candidate satisfying that identity theory. + + + **L197** Extract candidate = chosen using singleton-model equivalence. + + + **L198** Replace candidate by chosen throughout the goal. + + + **L199** Apply the actually proved own-fact theorem for the same chosen design and fact. + + + **L201** Comment restricts the priority/value equivalence to this fixed applicable context. + + + **L202** Comment states that both predicates select exactly the same candidate. + + + **L203** Comment connects value grounds to actual normative content through identity, rather than a mere adoption label. + + + **L204** For every candidate in the fixed shared context, prove value commitment and actual priority select identically. + + + **L205** The left side is the commitment of the explicitly adopted evolvable selection position. + + + **L206** The right side is EvolutionPriority itself, not a label naming priority. + + + **L207** Prove both directions of this same-claim equivalence. + + + **L208** Assume the evolvable selection commitment. + + + **L209** Expose that commitment as candidate = evolvable. + + + **L210** Substitute the actually selected evolvable candidate. + + + **L211** Extract its priority proof from actual currentDomainSatisfied. + + + **L212** Conversely assume actual EvolutionPriority for the candidate. + + + **L213** Apply the priority rule's selected-candidate conclusion in sharedContext. + + + **L214** Supply current applicability and absence of justified departure; these fixed-context facts are essential. + + + **L216** priorityGrounds supplies value grounds for the actual priority proposition in sharedContext. + + + **L217** The claim is EvolutionPriority sharedContext, with canonical articulation. + + + **L218** Use the exact evolvable value facet both as the singleton required task and the supplied facet. + + + **L219** Introduce equality between the value commitment predicate and actual priority predicate. + + + **L220** Use propositional extensionality pointwise and function extensionality to derive that predicate equality. + + + **L221** Rewrite the priority claim back to the identical value commitment claim. + + + **L222** Reuse selectionGrounded for evolvable; no facet or assessed claim is swapped without this equality. + + + **L224** Comment separates adoption facts from actual normative contents. + + + **L225** Comment states that each following constructor retains the full represented duty and original task. + + + **L226** Comment retains conditions/reasons/scope and restricts domain duties to the domain adopter. + + + **L227** Comment places consistency as an external constraint on the complete resulting theory. + + + **L228** Comment avoids defining that theory through a self-referential proposition asserting its own consistency. + + + **L229** OwnNorm enumerates full represented duties separately from adoption reports. + + + **L230** Include generation, reflection, empirical/inferential grounds and principle-indexed value grounds. + + + **L231** Include selection value, scope, capability, choice and fact-indexed inferential grounds. + + + **L232** Include the domain bundle and grounds for actual priority as distinct duties. + + + **L233** Derive DecidableEq, Repr: decidable equality and printable representations of these constructors. + + + **L235** normApplies determines adoption-dependent membership eligibility for each norm. + + + **L236** Only the evolvable adopter includes domain and priority-value duties under this predicate. + + + **L237** Every other norm applies to all adopters. + + + **L239** Interpret every OwnNorm as its full proposition on Candidate, retaining the adopted parameter. + + + **L240** The generation norm is the actual policy's full generationSpecification. + + + **L241** The reflection norm requires the candidate's actual reflexivity specification. + + + **L242** It uses that same candidate model's rules, self relation and performance relation. + + + **L243** The empirical norm retains the actual record and original True empirical-scope predicate. + + + **L244** It also retains the exact budget claim and the original True uncertainty predicate. + + + **L245** The inferential norm retains actual capacity assumptions and capacity conclusion. + + + **L246** Each principle-value norm requires the full grounds of that same governance position. + + + **L247** Selection-value content requires its full value specification, indexed by adopted. + + + **L248** It additionally requires that same value commitment to hold at the candidate. + + + **L249** The scope norm is the exact budgetScopeAccount specification. + + + **L250** The capability norm retains the complete capability specification. + + + **L251** The process and claim both use the same candidate parameter. + + + **L252** The choice norm retains complete reasoned implementation choice. + + + **L253** It uses actual requirements, this candidate's implementation and the original reasons. + + + **L254** Each own-ground norm is the full inferential task for its fact. + + + **L255** Its identity premises and actual fact claim are both indexed by adopted. + + + **L256** The domain norm is actual DomainSatisfied in sharedContext, evaluated at candidate. + + + **L257** The priority-value norm is grounds for the actual priority predicate, with canonical articulation. + + + **L258** Retain the same required and supplied evolvable value facet. + + + **L260** actualOwnNorm proves satisfaction of each applicable full norm at the selected candidate. + + + **L261** The selected candidate must again be one of the two ordinary designs. + + + **L262** Quantify over the norm and assume its actual normApplies condition before concluding its content. + + + **L263** Split on every OwnNorm constructor, retaining its parameters. + + + **L264** Discharge generation with the actual engineering-policy theorem. + + + **L265** Discharge reflection with the checked self-model theorem for this ordinary design. + + + **L266** Use the actually discharged empirical facet inside singleton grounds. + + + **L267** Use the actually discharged capacity inference facet likewise. + + + **L268** Use governanceGrounded for this exact principle parameter. + + + **L269** Pair actual selection grounds with reflexive selected/adopted identity. + + + **L270** Reuse the actual budget scope explanation proof. + + + **L271** Reuse the same candidate's actual functional capability grounds. + + + **L272** Enter the reasoned implementation choice obligation. + + + **L273** Apply implementationReasoned, leaving its actual budget premise. + + + **L274** Substitute either ordinary design and compute its complexity ≤ 12. + + + **L275** Use actualOwnFactGrounded for the very same chosen design and indexed fact. + + + **L276** For the domain norm, use its adoption applicability premise. + + + **L277** Expose applicable as chosen = evolvable. + + + **L278** Substitute evolvable for chosen. + + + **L279** Now use the actual full current domain satisfaction proof. + + + **L280** The fixed priority-value norm is discharged by priorityGrounds. + + + **L282** ownFactTheory holds exactly the represented own-fact claims. + + + **L283** A claim is held if some OwnFact interprets to that exact claim. + + + **L285** ownNormTheory holds applicable full normative contents. + + + **L286** Require an actual norm witness, its normApplies proof and equality with its full interpreted claim. + + + **L288** Comment says the consequence relation applies jointly to facts and full normative contents. + + + **L289** Comment includes implications of their actual union, not just separate checks of each branch. + + + **L290** ownTheory is the combined theory on which later model and consistency predicates operate. + + + **L291** Take the union of factual reports and full applicable normative claims; it is not merely an adoption-marker theory. + + + **L293** For every chosen design and norm, provide a route into the combined theory. + + + **L294** An actual applicability premise suffices to hold that norm's exact full claim. + + + **L295** Use the union's normative branch with norm witness, applicability and reflexive claim identity. + + + **L297** Exhibit nonempty held claims and review objects for every chosen design. + + + **L298** The chosen selection report is actually in ownTheory. + + + **L299** The grounds-principle adoption report is also actually held. + + + **L300** The activity review object belongs to selfModel's list. + + + **L301** The grounds commitment object belongs to that same list. + + + **L302** Supply two factual-branch witnesses and leave the two object membership checks. + + + **L303** Expand actual model and finite commitment lists to prove those memberships. + + + **L305** comparisonContext is a Logic.Context with worlds Candidate and questions OwnFact. + + + **L306** Its assumptions are the exact chosen-identity theory. + + + **L307** Its question meaning is the chosen-indexed factual interpretation. + + + **L308** Its admissible comparison scope requires complexity at most 3. + + + **L310** Build a Snapshot from a chosen design and explicit revision number. + + + **L311** Store the full combined theory, its comparison context and that revision number. + + + **L313** Prove the chosen ordinary design is an actual admissible world of its combined theory. + + + **L314** Keep the ordinary-design premise explicit. + + + **L315** Admissibility includes all held claims, comparison assumptions and scope at the same chosen world. + + + **L316** Supply reflexive identity assumptions; leave full theory satisfaction and scope. + + + **L317** Introduce any claim actually held in the combined theory. + + + **L318** Split union membership into the factual and normative branches. + + + **L319** Extract the OwnFact witness and substitute its exact claim interpretation. + + + **L320** Apply the checked actualOwnFact theorem at chosen. + + + **L321** Extract the OwnNorm witness, applicability proof and exact claim identity. + + + **L322** Apply actualOwnNorm with the same chosen design, norm and applicability proof. + + + **L323** For scope, substitute each ordinary design and compute complexity ≤ 3. + + + **L325** Prove consistency of the new full snapshot plus truthful change reporting against the specified earlier snapshot; this does not merge old and new theories. + + + **L326** The new choice must be ordinary. + + + **L327** The earlier snapshot is evolvable at revision 0. + + + **L328** The current snapshot is chosen at revision 1, with change acknowledged as true. + + + **L329** Use the actual admissible chosen witness to establish consequence consistency, and reflexivity for the change-record obligation. + + + **L331** Ground every claim in the combined theory, including full applicable norm claims. + + + **L332** Require the chosen design to be ordinary. + + + **L333** Quantify over any Candidate claim and assume it is actually held in ownTheory. + + + **L334** The conclusion is identity-conditioned inferential grounds for that exact claim. + + + **L335** Reduce singleton grounds to the inferential task. + + + **L336** Use chosen as the nonempty identity-premise model; leave entailment. + + + **L337** Introduce any candidate satisfying the identity assumptions. + + + **L338** Extract its equality to chosen from singleton-model semantics. + + + **L339** Substitute chosen for that candidate. + + + **L340** Project full theory satisfaction from currentAdmissible and apply it to the exact held claim. + + + **L342** Comment introduces incompatible contents while keeping an adoption marker unchanged. + + + **L343** Comment identifies the same candidate, question and scope on both sides of the conflict. + + + **L344** Define a deliberately incompatible normative theory over the same Candidate worlds. + + + **L345** The first singleton theory requires the candidate to be presentSimple. + + + **L346** The second requires that same candidate not to be presentSimple. + + + **L348** Use one Unit question to compare these opposing claims in a common context. + + + **L349** Assumptions are empty, the question means candidate = presentSimple, and scope is True. + + + **L351** normativeContentVariation shows a true adoption marker cannot conceal incompatible contents. + + + **L352** The choice adoption flag remains true. + + + **L353** The actual incompatible theory is nevertheless inconsistent in its shared context. + + + **L354** Domain adoption applies to evolvable and does not apply to presentSimple. + + + **L355** The actual domain claim is held in evolvable's theory. + + + **L356** That actual domain claim is not held in presentSimple's theory. + + + **L357** Construct the adoption and applicability facts and positive membership; leave inconsistency and negative membership. + + + **L358** Apply conflictRequiresChange to the single shared Unit question. + + + **L359** For any admissible candidate, derive the positive side of the conflict. + + + **L360** Expose the positive question meaning as candidate = presentSimple. + + + **L361** Extract the positive claim via singleton-model equivalence. + + + **L362** Select the first theory from the model of the union inside admissibility. + + + **L363** For the same kind of admissible candidate, derive the negative side. + + + **L364** Expose the negated meaning as candidate ≠ presentSimple. + + + **L365** Extract the negative claim via its singleton-model equivalence. + + + **L366** Select the second theory from the same union model. + + + **L367** For negative membership, assume the actual domain claim is held by presentSimple. + + + **L368** Its checked admissibility then makes that full DomainSatisfied claim true at presentSimple. + + + **L369** Extract priority from that domain bundle and contradict currentSimpleViolates. + + + **L371** Comment describes Inherited fields as actual satisfaction or support conditions. + + + **L372** Comment denies that value accounts or completed assessments replace the normative fields themselves. + + + **L373** Comment explicitly limits this implementation to the shared context through its identity field. + + + **L374** Inherited bundles represented inherited duties at an explicit context and chosen design; its fields are premises for projection theorems. + + + **L375** Restrict ctx to the exact sharedContext; this is stronger than an arbitrary-context implementation. + + + **L376** Require full generationSpecification for the actual engineering policy. + + + **L377** Require consistency of the current snapshot and truthful reporting against the earlier evolvable revision-0 snapshot. + + + **L378** The current snapshot uses this chosen design at revision 1, with change recorded true. + + + **L379** Require reflexivity using this candidate's actual rules and self targets. + + + **L380** The performance relation comes from the same candidate's selfModel. + + + **L381** For every Core principle, require the actual governance-position value grounds. + + + **L382** Require grounds for this chosen design's selection value position. + + + **L383** Require the empirical task with the actual budget record and True empirical scope. + + + **L384** Retain its exact present-budget claim and True uncertainty predicate; no quantitative uncertainty bound is supplied. + + + **L385** Require actual inference from capacityAssumptions to capacityClaim. + + + **L386** Require the actual budget-scope explanation. + + + **L387** Require functional capability grounds for the same chosen process and claim. + + + **L388** Require reasoned choice of this chosen implementation under actual requirements and reasons. + + + **L389** For all own facts, require inference from the chosen-identity premises to the exact fact claim. + + + **L390** Require chosen itself to be compatible with the actual budget observation. + + + **L391** Require the chosen selection commitment to be actually adopted at chosen. + + + **L392** Require chosen to model every held claim of the full combined theory. + + + **L393** For every applicable norm, require actual theory membership of its content. + + + **L394** The held content must be that same norm's complete ownNormClaim. + + + **L395** For every actual held claim, require its inferential grounds. + + + **L396** Those grounds retain the explicit chosen-identity assumptions. + + + **L398** Construct all Inherited fields for a selected design. + + + **L399** Assume it is presentSimple or evolvable. + + + **L400** The resulting bundle is in exactly sharedContext. + + + **L401** Supply context identity, actual generation proof and full current consistency. + + + **L402** Supply actual self-application and grounds for every governance principle. + + + **L403** Supply chosen selection grounds and the discharged empirical singleton task. + + + **L404** Supply discharged capacity inference and the actual scope account. + + + **L405** Supply capability grounds, leave implementation choice open, and supply all own-fact grounds. + + + **L406** Leave observation compatibility open; supply adoption identity and actual full-theory satisfaction. + + + **L407** Supply applicable normative membership and grounds for every held claim. + + + **L408** For the implementation field, apply the actual reasoned-choice theorem. + + + **L409** Split ordinary choices and compute the remaining ≤ 12 budget condition. + + + **L410** For observation compatibility, use the backward budget observation equivalence. + + + **L411** Split ordinary choices and compute their ≤ 3 observation bound. + + + **L413** Comment introduces mutual application to the same system, principles and claims. + + + **L414** Comment includes the actual chosen implementation and retains the complete Inherited premise. + + + **L415** Begin source-trace metadata for CoreReader.Engineering.inheritedMutualApplication; the following source identifiers and hashes are not Lean proof premises. + + + **L416** Record source unit organon.relationships.roles#p1 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L417** Record source unit organon.relationships.roles#p2 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L418** Record source unit organon.relationships.roles#p3 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L419** End the source-trace metadata comment; Lean does not elaborate it as a proof term. + + + **L420** For any ctx and chosen, inheritedMutualApplication extracts same-object obligations from Inherited. + + + **L421** The full inherited bundle is an explicit premise, not the theorem's independently derived conclusion. + + + **L422** Return the actual engineering generation specification. + + + **L423** Return reflexivity on the chosen model's rules and self relation. + + + **L424** Retain that same model's performance relation. + + + **L425** Return value grounds universally over all Core principles. + + + **L426** Return capability grounds for the chosen process and its exact claim. + + + **L427** Return actual reasoned implementation choice. + + + **L428** Return inference grounds for every own fact under chosen-identity premises. + + + **L429** Return theory membership of every norm whose applicability premise holds. + + + **L430** Return inferential grounds for every claim actually held in the combined theory. + + + **L431** Return current full-theory consistency and truthful change reporting against the earlier evolvable snapshot. + + + **L432** Its current side remains chosen revision 1 with change recorded true. + + + **L433** Build the conjunction by projecting generation, reflection and governance grounds from inherited. + + + **L434** Project capability, actual implementation choice and own-fact grounds. + + + **L435** Project full normative membership, all-held-claim grounds and full consistency; no extra proof of their premises occurs here. + + + **L437** Begin source-trace metadata for CoreReader.Engineering.inheritedMutualCases; the following source identifiers and hashes are not Lean proof premises. + + + **L438** Record source unit organon.relationships.roles#p1 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L439** Record source unit organon.relationships.roles#p2 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L440** Record source unit organon.relationships.roles#p3 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L441** End the source-trace metadata comment; Lean does not elaborate it as a proof term. + + + **L442** inheritedMutualCases gives concrete positive duties alongside actual self-criticism results. + + + **L443** The full Inherited bundle holds for evolvable in sharedContext. + + + **L444** The grounds principle's governance value specification holds. + + + **L445** The actual evolvable process has its exact functional capability grounds. + + + **L446** The evolvable implementation has actual reasoned-choice support. + + + **L447** The actual batch-method revision evaluates to counterexample. + + + **L448** The generationRule object actually belongs to the evolvable model. + + + **L449** The assessmentRule object belongs to that same model. + + + **L450** The actual assessment-rule revision also evaluates to counterexample. + + + **L451** Use the full inheritedCurrent witness and actual grounds-principle value theorem. + + + **L452** Use the exact evolvable capability-grounding theorem. + + + **L453** Extract reasoned implementation choice from that same inherited witness. + + + **L454** Extract the batch-method counterexample from actualSelfCriticism. + + + **L455** Extract generation-rule object membership from ownRuleIdentity. + + + **L456** Extract assessment-rule object membership from the corresponding identity theorem. + + + **L457** Extract the current assessment-rule revision counterexample from ownRuleContentVariation. + + + **L459** Comment locates the priority object and its assessment method in the adopter's same context. + + + **L460** Comment retains both objects within the inherited criticism/generation contract. + + + **L461** Begin source-trace metadata for CoreReader.Engineering.priorityRemainsReflexive; the following source identifiers and hashes are not Lean proof premises. + + + **L462** Record source unit organon.relationships.roles#p3 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L463** Record source unit extensions#p1 with SHA-256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L464** Record source unit software-engineering.structural-judgment#p1 with SHA-256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L465** Record source unit software-engineering.revision#p2 with SHA-256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L466** End the source-trace metadata comment; Lean does not elaborate it as a proof term. + + + **L467** priorityRemainsReflexive connects domain priority to inherited self-criticism in an explicit context and choice. + + + **L468** Assume the complete Inherited bundle and actual DomainSatisfied for the same ctx/chosen. + + + **L469** Also assume priority applies and evolvable has no justified departure in that same context. + + + **L470** Conclude the selected candidate must be evolvable. + + + **L471** Its actual priority object belongs to its self-review list. + + + **L472** The chosen self-model still satisfies reflexivity over its actual rules and targets. + + + **L473** Retain its actual performance relation in that specification. + + + **L474** Retain value grounds for every inherited Core principle. + + + **L475** Additionally ground the actual EvolutionPriority ctx claim, with canonical articulation. + + + **L476** Its required and supplied facet are the very same evolvable selection value position. + + + **L477** The full actual domain norm is held in chosen's combined theory. + + + **L478** The full inherited consistency specification is retained. + + + **L479** The current snapshot remains chosen revision 1, with acknowledged change true. + + + **L480** Extract actual priority from domain and apply applicability/noDeparture to derive chosen = evolvable. + + + **L481** Construct the selected identity, leave membership open, and project reflection and Core value grounds. + + + **L482** Leave exact-priority grounds open; use selected as domain norm applicability and project consistency. + + + **L483** Replace chosen with evolvable and compute actual priority-object membership. + + + **L484** Rewrite ctx to sharedContext using the Inherited identity field; this bounds the grounds result's context. + + + **L485** Now apply priorityGrounds for the exact same priority predicate. + + + **L487** Begin source-trace metadata for CoreReader.Engineering.priorityReflexiveCases; the following source identifiers and hashes are not Lean proof premises. + + + **L488** Record source unit organon.relationships.roles#p3 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L489** Record source unit extensions#p1 with SHA-256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L490** Record source unit software-engineering.structural-judgment#p1 with SHA-256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L491** Record source unit software-engineering.revision#p2 with SHA-256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L492** End the source-trace metadata comment; Lean does not elaborate it as a proof term. + + + **L493** priorityReflexiveCases computes actual priority review and retains criticisms of distinct method objects. + + + **L494** The priority object is actually listed for evolvable. + + + **L495** Its finite size-10 object test passes. + + + **L496** The model records actual performance under assessment key (0,1) for priority revision owned by 0. + + + **L497** The performed input is exactly the input built for that same target. + + + **L498** The recorded outcome is assessed supportedWithinScope. + + + **L499** The distinct batch-method revision nevertheless yields counterexample. + + + **L500** The old batch-method size-10 test succeeds. + + + **L501** The challenged size-5 test fails. + + + **L502** Keep grounds for actual priority in sharedContext with canonical articulation. + + + **L503** Use its identical singleton required/supplied evolvable value facet. + + + **L504** The assessment-rule revision's local-contract failure is also retained as a counterexample. + + + **L505** Compute priority membership and test success; leave performed, while extracting batch criticism. + + + **L506** Extract the batch method's old success and challenged failure. + + + **L507** Supply actual priority grounds and the actual rule-revision counterexample. + + + **L508** Construct performed from self membership, exact input and the assessment activity's key/record identities. + + + **L510** Comment introduces a nonempty witness satisfying the entire represented inherited bundle. + + + **L511** Comment also requires the domain bundle in the very same continuing activity with active priority. + + + **L512** Begin source-trace metadata for CoreReader.Engineering.jointWitness; the following source identifiers and hashes are not Lean proof premises. + + + **L513** Record source unit organon.charter.overview#p2 with SHA-256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L514** Record source unit organon.charter.overview#p3 with SHA-256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L515** Record source unit organon.charter.self-transcendence#p1 with SHA-256 f4ca590e2ae15e3882f70c7b2bc46a8911c97cee547c8b137b5493fbf862c8c0; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L516** Record source unit organon.charter.self-transcendence.orientation#p1 with SHA-256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L517** Record source unit organon.charter.self-transcendence.non-finality#p1 with SHA-256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L518** Record source unit organon.charter.self-transcendence.limits#p1 with SHA-256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L519** Record source unit organon.charter.self-transcendence.limits#p2 with SHA-256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L520** Record source unit organon.charter.consistency#p1 with SHA-256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L521** Record source unit organon.charter.consistency.meaning#p1 with SHA-256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L522** Record source unit organon.charter.consistency.meaning#p2 with SHA-256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L523** Record source unit organon.charter.consistency.limits#p1 with SHA-256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L524** Record source unit organon.charter.reflexivity#p1 with SHA-256 13293b45c2fa89068c68ae7ef3c5df38f0efadb3ef3873d78a5ba67d9691a757; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L525** Record source unit organon.charter.reflexivity.meaning#p1 with SHA-256 8a2caede01a43d8b6c60b54c78ac089c51868e9956f316948077ccee2e45c9cc; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L526** Record source unit organon.charter.reflexivity.limits#p1 with SHA-256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L527** Record source unit organon.grounds#p1 with SHA-256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L528** Record source unit organon.grounds.assessment#p1 with SHA-256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L529** Record source unit organon.grounds.assessment#p2 with SHA-256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L530** Record source unit organon.grounds.assessment#p3 with SHA-256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L531** Record source unit organon.grounds.scope#p1 with SHA-256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L532** Record source unit organon.grounds.scope#p2 with SHA-256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L533** Record source unit organon.grounds.scope#p3 with SHA-256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L534** Record source unit organon.grounds.capabilities#p1 with SHA-256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L535** Record source unit organon.grounds.capabilities#p2 with SHA-256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L536** Record source unit organon.grounds.implementations#p1 with SHA-256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L537** Record source unit organon.grounds.implementations#p2 with SHA-256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L538** Record source unit organon.grounds.implementations.limits#p1 with SHA-256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L539** Record source unit organon.relationships.roles#p1 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L540** Record source unit organon.relationships.roles#p2 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L541** Record source unit organon.relationships.roles#p3 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L542** Record source unit extensions#p1 with SHA-256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L543** Record source unit software-engineering.purpose#p1 with SHA-256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L544** Record source unit software-engineering.purpose#p2 with SHA-256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L545** Record source unit software-engineering.purpose#p3 with SHA-256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L546** Record source unit software-engineering.evolution-priority#p1 with SHA-256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L547** Record source unit software-engineering.evolution-priority#p2 with SHA-256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L548** Record source unit software-engineering.evolution-priority#p3 with SHA-256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L549** Record source unit software-engineering.evolution-meaning#p1 with SHA-256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L550** Record source unit software-engineering.evolution-meaning#p2 with SHA-256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L551** Record source unit software-engineering.structural-judgment#p1 with SHA-256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L552** Record source unit software-engineering.structural-judgment#p2 with SHA-256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L553** Record source unit software-engineering.structural-judgment#p3 with SHA-256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L554** Record source unit software-engineering.revision#p1 with SHA-256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L555** Record source unit software-engineering.revision#p2 with SHA-256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L556** End the source-trace metadata comment; Lean does not elaborate it as a proof term. + + + **L557** jointWitness exhibits one nonempty finite model jointly satisfying inherited and domain bundles. + + + **L558** Existentially choose a context and Candidate; this is an existence result, not universal adequacy. + + + **L559** Require the witnesses to be exactly sharedContext and evolvable. + + + **L560** Both complete bundles must hold for these same objects. + + + **L561** Priority applicability is active and evolvable has no represented threat. + + + **L562** The chosen design has greater abstraction complexity than presentSimple. + + + **L563** The successor has an actual designRevision path in that same activity/design. + + + **L564** The agent has an actual designRevision path there too. + + + **L565** The selected-design report is actually held in chosen's theory. + + + **L566** The grounds commitment is actually among chosen's self-review objects. + + + **L567** Chosen is an admissible model of its full combined theory and comparison context. + + + **L568** Choose sharedContext and evolvable as witnesses, proving both identity fields reflexively. + + + **L569** Supply the complete inheritedCurrent bundle and currentDomainSatisfied. + + + **L570** Supply active priority/no threat, then compute complexity ordering and both maintainer paths. + + + **L571** Project held selection and the actual grounds-review object from nonemptyOwnObjects. + + + **L572** Finish with the actual full-theory admissibility proof. + + + **L574** Comment introduces a countermodel adopting the supported present-simplicity value. + + + **L575** Comment states actual selection and full inherited satisfaction while beginning the applicability qualification. + + + **L576** Comment rules out inactive domain conditions, bounded lifecycle and threatened costs as escape explanations. + + + **L577** Begin source-trace metadata for CoreReader.Engineering.inheritedDoesNotEntailPriority; the following source identifiers and hashes are not Lean proof premises. + + + **L578** Record source unit organon.relationships.roles#p1 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L579** Record source unit organon.relationships.roles#p2 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L580** Record source unit organon.relationships.roles#p3 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L581** Record source unit extensions#p1 with SHA-256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L582** Record source unit software-engineering.evolution-priority#p1 with SHA-256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L583** Record source unit software-engineering.evolution-priority#p2 with SHA-256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L584** Record source unit software-engineering.evolution-priority#p3 with SHA-256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04; this comment tracks the reviewed source object, not a logical assumption or correspondence proof. + + + **L585** End the source-trace metadata comment; Lean does not elaborate it as a proof term. + + + **L586** inheritedDoesNotEntailPriority exhibits a finite countermodel separating inherited duties from the additional priority adoption. + + + **L587** Existentially choose a context and candidate satisfying all following conjuncts. + + + **L588** Fix them to sharedContext and presentSimple. + + + **L589** The full inherited bundle holds while the domain priority conditions are active. + + + **L590** The same activity is continuing and has no bounded lifecycle. + + + **L591** There is neither a threat nor a justified departure for evolvable. + + + **L592** presentSimple meets the actual necessary requirements. + + + **L593** evolvable also meets those same requirements. + + + **L594** The same evidence makes designRevision credible. + + + **L595** The successor can revise evolvable in this activity. + + + **L596** The agent can revise evolvable there too. + + + **L597** evolvable requires less actual design-revision work than chosen presentSimple. + + + **L598** Chosen presentSimple has less present abstraction complexity than evolvable. + + + **L599** The chosen simplicity value position has its actual value grounds. + + + **L600** The same value position is actually committed to the chosen design. + + + **L601** Nevertheless the actual EvolutionPriority claim is false for that choice. + + + **L602** Choose sharedContext and presentSimple, discharging their identities reflexively. + + + **L603** Provide complete inherited satisfaction and active priority conditions. + + + **L604** Compute continuation and unboundedness, then use both no-threat/no-departure facts. + + + **L605** Compute both requirements, credible revision, both maintainer paths, and the work/complexity inequalities. + + + **L606** Use actual simple-position grounds, reflexive adoption and currentSimpleViolates to finish the countermodel. + + + **L608** Close namespace CoreReader.Engineering; no further mathematical claim is asserted. + + +### `leanified/CoreReader/Engineering/Reflection.lean` + + +```lean +import CoreReader.Adopted + +namespace CoreReader.Engineering.Reflection + +open CoreReader.Agency CoreReader.Adopted + +/- A target retains the owner, the actual object and the stage being examined. -/ +structure Target (Object : Type) where + owner : Nat + object : Object + phase : Phase + +/- A finite assessment contract has actual tests and a scope it claims to cover. +The scope is an application limit, not a universal definition of assessment. -/ +structure Contract (W : Type) where + test : W → Bool + tested : List W + claimed : List W + +/- Inputs carry the contract belonging to the named target, so another object's +test result cannot silently discharge this target's inquiry. -/ +structure Input (W Object : Type) where + target : Target Object + contract : Contract W + requested : List W + reasons : List String + basis : Prop + +inductive Verdict | supportedWithinScope | counterexample | noSupportingSample + deriving DecidableEq, Repr + +inductive Outcome (W : Type) + | generated (tests scope : List W) + | assessed (verdict : Verdict) + deriving DecidableEq + +/- A successful sample does not license the wider scope: an actual failing +instance there changes the assessment to counterexample. -/ +def evaluate {W Object : Type} (input : Input W Object) : Verdict := + if input.contract.tested.all input.contract.test then + if input.requested.all input.contract.test then .supportedWithinScope + else .counterexample + else .noSupportingSample + +/- Generation proposes an expanded test set. Proposal generation does not prove +that the resulting contract passes those tests or warrants adoption. -/ +def generate {W Object : Type} (input : Input W Object) : Outcome W := + .generated input.requested input.requested + +def interpret {W Object : Type} (activity : Activity) (input : Input W Object) + (outcome : Outcome W) : Prop := + input.reasons ≠ [] ∧ input.basis ∧ match activity with + | .generation => outcome = generate input + | .assessment => outcome = .assessed (evaluate input) + +structure Model (W Object : Type) where + owner : Nat + objects : List Object + contracts : Object → Contract W + requested : Object → Phase → List W + reasons : Object → Phase → List String + basis : Object → Phase → Prop + generationApplies : Object → Phase → Prop + assessmentApplies : Object → Phase → Prop + recorded : Activity → Object → Phase → Outcome W + +def Model.input {W Object : Type} (m : Model W Object) (t : Target Object) : Input W Object := + ⟨t, m.contracts t.object, m.requested t.object t.phase, m.reasons t.object t.phase, + m.basis t.object t.phase⟩ + +def Model.self {W Object : Type} (m : Model W Object) (t : Target Object) : Prop := + t.owner = m.owner ∧ t.object ∈ m.objects + +def Model.rule {W Object : Type} (m : Model W Object) (activity : Activity) : + ReflexiveRule (Target Object) (Input W Object) (Outcome W) where + key := ⟨m.owner, match activity with | .generation => 0 | .assessment => 1⟩ + activity := activity + applicable t := m.self t ∧ match activity with + | .generation => m.generationApplies t.object t.phase + | .assessment => m.assessmentApplies t.object t.phase + input := m.input + meaning := interpret activity + +def Model.rules {W Object : Type} (m : Model W Object) := + [m.rule .generation, m.rule .assessment] + +/- These are the stated records. The separate follows test compares each stated +outcome with the actual input's evaluation, rather than defining success by its name. -/ +def Model.performed {W Object : Type} (m : Model W Object) + (key : PrincipleKey) (t : Target Object) (input : Input W Object) (outcome : Outcome W) : Prop := + m.self t ∧ input = m.input t ∧ + ∃ activity, key = (m.rule activity).key ∧ + outcome = m.recorded activity t.object t.phase + +def Model.follows {W Object : Type} (m : Model W Object) : Prop := + ∀ activity object phase, object ∈ m.objects → + (match activity with + | .generation => m.generationApplies object phase + | .assessment => m.assessmentApplies object phase) → + interpret activity (m.input ⟨m.owner, object, phase⟩) (m.recorded activity object phase) + +/- This generic implication retains the actual evaluation premise. Concrete +engineering instances must discharge follows separately for their own contracts. -/ +theorem recordedReflexivity {W Object : Type} (m : Model W Object) (checked : m.follows) : + reflexivitySpecification m.rules m.self m.performed := by + constructor + · intro p hp q hq equal + simp only [Model.rules, List.mem_cons, List.not_mem_nil, or_false] at hp hq + rcases hp with rfl | rfl <;> rcases hq with rfl | rfl + · rfl + · have bad := congrArg PrincipleKey.localId equal; contradiction + · have bad := congrArg PrincipleKey.localId equal; contradiction + · rfl + · intro rule hr target hs ha + simp only [Model.rules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl + · refine ⟨m.recorded .generation target.object target.phase, + ⟨hs, rfl, .generation, rfl, rfl⟩, ?_⟩ + have actual := checked .generation target.object target.phase hs.2 ha.2 + rcases target with ⟨owner, object, phase⟩ + have ownerEqual : owner = m.owner := hs.1 + subst owner + exact actual + · refine ⟨m.recorded .assessment target.object target.phase, + ⟨hs, rfl, .assessment, rfl, rfl⟩, ?_⟩ + have actual := checked .assessment target.object target.phase hs.2 ha.2 + rcases target with ⟨owner, object, phase⟩ + have ownerEqual : owner = m.owner := hs.1 + subst owner + exact actual + +end CoreReader.Engineering.Reflection +``` + + + + **L1** Import CoreReader.Adopted, making its declarations and transitive dependencies available; this line adds no new proposition. + + + **L3** Open namespace CoreReader.Engineering.Reflection for the following declarations. + + + **L5** Allow unqualified references to declarations in CoreReader.Agency CoreReader.Adopted; their meaning is unchanged. + + + **L7** Comment explains why Target retains owner, actual object and examined stage; these links are encoded by its fields. + + + **L8** For any object type, Target stores an owner, an object of that type, and a lifecycle phase. + + + **L9** The owner's identifier is a natural number; uniqueness is not a field invariant. + + + **L10** This field retains the actual object, rather than just its name. + + + **L11** The target includes the phase being examined. + + + **L13** Comment introduces a finite assessment contract with actual tests and a claimed scope. + + + **L14** Comment limits this scope representation to the application; it is not a universal definition of assessment. + + + **L15** For any sample type W, Contract packages one Boolean test and two finite lists. + + + **L16** The test maps each W value to a Boolean verdict. + + + **L17** This list records the initial tested cases; it may be empty. + + + **L18** This is the contract's claimed list; evaluate does not read it. + + + **L20** Comment introduces target-associated inputs; Model.input later enforces the field selection from that target. + + + **L21** Comment states the purpose of preventing another object's test from replacing this inquiry; raw Input alone does not enforce a provenance invariant. + + + **L22** Input is polymorphic in sample and object types, packaging the target and the data used for its inquiry. + + + **L23** Retain the full owner/object/phase target. + + + **L24** Store the test contract associated by the model with this object. + + + **L25** This requested list is what evaluate checks after the initial list passes. + + + **L26** Reasons are strings; nonemptiness will be checked, not their truth or relevance by string analysis. + + + **L27** The basis is an arbitrary proposition; interpret requires its proof. + + + **L29** Define three verdicts: support within scope, counterexample, and no supporting sample. + + + **L30** Derive DecidableEq, Repr: decidable equality and printable representations of these constructors. + + + **L32** Outcome is indexed by sample type W and records either a generation result or an assessment. + + + **L33** A generated outcome stores separate tests and scope lists, both over W. + + + **L34** An assessed outcome stores a Verdict and no sample list. + + + **L35** Derive decidable equality for Outcome W when [DecidableEq W] is available; the generated instance retains that typeclass premise, satisfied by the concrete ReviewCase model. + + + **L37** Comment warns that success on initial samples does not by itself license a wider requested list. + + + **L38** Comment identifies an actually failing requested case as the counterexample branch after initial success. + + + **L39** With implicit types W and Object and one input, evaluate computes a verdict from two Boolean all-tests. + + + **L40** First require every initially tested case to pass; List.all on an empty list is true. + + + **L41** If initial tests pass and every requested case passes, return supportedWithinScope, even when initial tests are empty. + + + **L42** If initial tests pass but some requested case fails, return counterexample. + + + **L43** A failing initial case returns noSupportingSample; the name does not mean an explicit empty-list check exists. + + + **L45** Comment describes generation as proposing tests and begins the distinction from validating them. + + + **L46** Comment denies that proposal generation proves either test success or warranted adoption. + + + **L47** With implicit sample/object types, generate produces a proposed Outcome from the input. + + + **L48** Copy requested into both generated tests and generated scope; neither list is validated here. + + + **L50** interpret takes an activity and an input, with both types implicit. + + + **L51** The final explicit argument is an outcome; the result is a proposition about that outcome. + + + **L52** Require a nonempty reasons list and the input's basis proposition, then branch on the activity. + + + **L53** Generation means exact equality to this input's actual generator output. + + + **L54** Assessment means exact equality to the verdict computed by evaluate on this input. + + + **L56** A Model over W and Object supplies target membership, contracts, applicability and recorded outcomes. + + + **L57** The model has one natural-number owner identifier. + + + **L58** Only objects in this finite list can satisfy Model.self. + + + **L59** Assign a contract to every Object value, including values outside objects. + + + **L60** Requested cases depend on the object and phase. + + + **L61** Reason strings depend on the same object and phase. + + + **L62** The basis proposition also depends on that object and phase. + + + **L63** A proposition determines generation applicability per object and phase. + + + **L64** A separate proposition determines assessment applicability. + + + **L65** Recorded outcomes depend on activity, object and phase; correctness is not assumed here. + + + **L67** Model.input builds the inquiry for any target; it does not itself check owner or membership. + + + **L68** Use the target itself and select contract, requested cases and reasons by its actual object/phase. + + + **L69** Complete the input with the basis selected at the same object and phase. + + + **L71** Model.self is the membership/ownership predicate on targets. + + + **L72** Both equal owner and membership of the actual object are required; phase is unrestricted here. + + + **L74** For a model and activity, construct the corresponding reflexive rule. + + + **L75** The rule's target/input/output types are exactly Target Object, Input W Object and Outcome W. + + + **L76** Use model owner plus local identifier 0 for generation or 1 for assessment. + + + **L77** Retain the supplied activity in the rule. + + + **L78** Applicability requires a self target and the activity-specific applicability condition. + + + **L79** Generation uses this object's generationApplies at this phase. + + + **L80** Assessment uses this object's assessmentApplies at this phase. + + + **L81** The actual rule input is the model's target-indexed input constructor. + + + **L82** The rule meaning is the actual interpret function for this activity. + + + **L84** Build the list of rules for this model, with both generic types inferred. + + + **L85** The rule list contains generation first and assessment second, with no other rules. + + + **L87** Comment identifies performed data as stated records, with a separate follows check. + + + **L88** Comment specifies comparison with actual input evaluation; success is not inferred from the outcome's name. + + + **L89** Define recorded performance as a relation belonging to this model. + + + **L90** The relation explicitly takes a principle key, target, input and outcome and returns Prop. + + + **L91** Require self membership and exact equality to the input built for that target. + + + **L92** Existentially choose an activity whose rule key equals the supplied key. + + + **L93** The outcome must be exactly the record for that activity and this same object/phase. + + + **L95** Model.follows states that all applicable records satisfy their actual meaning. + + + **L96** Universally quantify activity, object and phase, then assume object membership. + + + **L97** The next premise selects applicability by activity. + + + **L98** For generation, require generationApplies on the quantified object/phase. + + + **L99** For assessment, require assessmentApplies before asserting the interpretation. + + + **L100** Check recorded outcome against actual input, fixing the target owner to m.owner. + + + **L102** Comment emphasizes that the generic implication retains its substantive evaluation premise. + + + **L103** Comment requires concrete instances to prove follows for their own actual contracts. + + + **L104** For arbitrary types and model, the theorem assumes checked : m.follows; it does not derive this premise. + + + **L105** Under that premise, prove rule-key identity and applicable self-performance in reflexivitySpecification. + + + **L106** Split the specification into identity and performance obligations. + + + **L107** Introduce two listed rules and assume their keys are equal. + + + **L108** Expand membership of the two-rule list into generation/assessment alternatives. + + + **L109** Substitute each membership alternative, yielding four rule pairs. + + + **L110** When both rules are the same activity, their required equality is reflexive. + + + **L111** For generation versus assessment, project equal keys to localId and contradict 0 = 1. + + + **L112** For assessment versus generation, the same projection contradicts 1 = 0. + + + **L113** When both rules are the same activity, their required equality is reflexive. + + + **L114** Introduce a listed rule, self target and applicability proof for the performance obligation. + + + **L115** Reduce the rule's list membership to its two possible activities. + + + **L116** Handle generation and assessment separately by substitution. + + + **L117** For generation, choose its recorded outcome at this target's object/phase as witness. + + + **L118** Prove performed using self membership, exact input, and the generation activity; leave meaning to prove. + + + **L119** Apply checked to this generation record, using object membership from hs and applicability from ha. + + + **L120** Destructure the target into owner, object and phase to expose the ownership equality. + + + **L121** Extract owner = m.owner from the self-target premise. + + + **L122** Substitute the model owner so checked and the target refer to identical inputs. + + + **L123** The previously obtained actual interpretation now exactly closes the goal. + + + **L124** For assessment, choose its recorded verdict at the same target as witness. + + + **L125** Construct performed with the assessment activity and exact input/output identities. + + + **L126** Use checked for assessment, retaining this target's membership and applicability premises. + + + **L127** Destructure the target into owner, object and phase to expose the ownership equality. + + + **L128** Extract owner = m.owner from the self-target premise. + + + **L129** Substitute the model owner so checked and the target refer to identical inputs. + + + **L130** The previously obtained actual interpretation now exactly closes the goal. + + + **L132** Close namespace CoreReader.Engineering.Reflection; no further mathematical claim is asserted. + + +### `leanified/CoreReader/Engineering/SelfApplication.lean` + + +```lean +import CoreReader.Engineering.Values +import CoreReader.Engineering.Reflection + +namespace CoreReader.Engineering + +open CoreReader.Adopted + +inductive ReviewObject | activity | commitment (principle : CoreCommitment) | priority | evolutionMethod + | generationRule | assessmentRule + deriving DecidableEq, Repr + +abbrev ReviewCase := Candidate × Nat + +def generationApplies (_ : ReviewObject) (phase : CoreReader.Agency.Phase) : Prop := + phase ≠ .application + +def assessmentApplies (_ : ReviewObject) (_ : CoreReader.Agency.Phase) : Prop := True + +def ruleObject : CoreReader.Agency.Activity → ReviewObject + | .generation => .generationRule + | .assessment => .assessmentRule + +/- These inputs test the current reflection functions themselves. Size 10 has +an actual supporting sample; size 5 removes that sample while retaining the +requested claim. The domain batch predictor is not used in this method test. -/ +def ruleProbe (activity : CoreReader.Agency.Activity) (point : ReviewCase) : + Reflection.Input ReviewCase ReviewObject where + target := ⟨0, ruleObject activity, .revision⟩ + contract := ⟨fun _ => true, if point.2 = 10 then [point] else [], [point]⟩ + requested := [point] + reasons := ["retain the proposed scope and distinguish actual samples from an empty test set"] + basis := True + +def generationRuleTest + (method : Reflection.Input ReviewCase ReviewObject → Reflection.Outcome ReviewCase) + (point : ReviewCase) : Bool := + let input := ruleProbe .generation point + method input == .generated input.requested input.requested + +def assessmentRuleTest + (method : Reflection.Input ReviewCase ReviewObject → Reflection.Verdict) + (point : ReviewCase) : Bool := + method (ruleProbe .assessment point) == + (if point.2 = 10 then .supportedWithinScope else .noSupportingSample) + +/- A candidate revision supplies the previously missing empty-sample check. +It is kept distinct from the current evaluator and is not silently adopted. -/ +def sampleAwareAssessment (input : Reflection.Input ReviewCase ReviewObject) : Reflection.Verdict := + if input.contract.tested.isEmpty then .noSupportingSample else Reflection.evaluate input + +/- The method under criticism is the activity's own static batch forecast. Its +contract is checked at its original size and at the credible runtime change. -/ +def objectTest (object : ReviewObject) (point : ReviewCase) : Bool := + match object with + | .activity => decide (Meets currentContinuing.required (currentContinuing.profiles point.1)) + | .commitment principle => safeguardExperiment principle true point.1 + | .priority => decide (EvolutionPriority currentContinuing point.1) + | .evolutionMethod => staticBatch 21 point.2 == liveBatch 21 point.2 + | .generationRule => generationRuleTest Reflection.generate point + | .assessmentRule => assessmentRuleTest Reflection.evaluate point + +def reviewObjects (chosen : Candidate) : List ReviewObject := + [.activity] ++ coreCommitments.map ReviewObject.commitment ++ + (if chosen = .evolvable then [.priority] else []) ++ + [.evolutionMethod, .generationRule, .assessmentRule] + +def requestedCases (chosen : Candidate) : CoreReader.Agency.Phase → List ReviewCase + | .formation | .application => [(chosen, 10)] + | .revision => [(chosen, 10), (chosen, 5)] + +def reviewReasons (object : ReviewObject) (phase : CoreReader.Agency.Phase) : List String := + let content := match object with + | .activity => "actual order, safety, latency and retention requirements of this activity" + | .commitment principle => criticismFor principle + | .priority => "credible design revision, successor and agent paths, necessary requirements and concrete costs" + | .evolutionMethod => "the same batch forecast at its recorded size and the proposed runtime size" + | .generationRule => "the actual generator must retain its input's requested tests and scope" + | .assessmentRule => "the actual evaluator's acceptance depends on whether its input has supporting samples" + [content, match phase with + | .formation => "identify this object's purpose and the conditions of its initial contract" + | .application => "apply that contract to the currently selected design in this continuing activity" + | .revision => "examine the proposed wider input scope and retain any counterexample"] + +/- The recorded verdict is independent of the evaluator: the revision of the +batch method is explicitly reported as a counterexample; other current checks +are reported supported only in the scope that will be checked below. -/ +def statedReview (chosen : Candidate) (activity : CoreReader.Agency.Activity) + (object : ReviewObject) (phase : CoreReader.Agency.Phase) : Reflection.Outcome ReviewCase := + match activity with + | .generation => .generated (requestedCases chosen phase) (requestedCases chosen phase) + | .assessment => .assessed (match object, phase with + | .evolutionMethod, .revision | .assessmentRule, .revision => .counterexample + | _, _ => .supportedWithinScope) + +/- The basis is not a free approval flag. Each inquiry requires the facts +relevant to its own object; a counterexample can ground criticism rather than +the truth of the original method's broader claim. -/ +def reviewBasis (chosen : Candidate) : ReviewObject → CoreReader.Agency.Phase → Prop + | .activity, _ => ActivityScope currentContinuing.activity ∧ + Meets currentContinuing.required (currentContinuing.profiles chosen) + | .commitment principle, _ => ReasonRelevant principle (reasonFor principle) chosen + | .priority, _ => PriorityConditions currentContinuing ∧ ¬ HasThreat currentContinuing .evolvable + | .evolutionMethod, .revision => + staticBatch 21 10 = liveBatch 21 10 ∧ staticBatch 21 5 ≠ liveBatch 21 5 + | .evolutionMethod, _ => staticBatch 21 10 = liveBatch 21 10 + | .generationRule, _ => + generationRuleTest Reflection.generate (chosen, 10) = true ∧ + generationRuleTest (fun _ => .generated [] []) (chosen, 10) = false + | .assessmentRule, .revision => + assessmentRuleTest Reflection.evaluate (chosen, 10) = true ∧ + assessmentRuleTest Reflection.evaluate (chosen, 5) = false + | .assessmentRule, _ => assessmentRuleTest Reflection.evaluate (chosen, 10) = true + +def selfModel (chosen : Candidate) : Reflection.Model ReviewCase ReviewObject where + owner := 0 + objects := reviewObjects chosen + contracts object := ⟨objectTest object, [(chosen, 10)], [(chosen, 10)]⟩ + requested _ := requestedCases chosen + reasons := reviewReasons + basis := reviewBasis chosen + generationApplies := generationApplies + assessmentApplies := assessmentApplies + recorded := statedReview chosen + +/- The named normative object and its finite rationale test are deliberately +distinct: a supported rationale experiment is not proof of universal correctness. +The same commitment identifier controls adoption, reasons and reflection. -/ +theorem reviewIdentity (chosen : Candidate) (object : ReviewObject) + (phase : CoreReader.Agency.Phase) : + ((selfModel chosen).input ⟨0, object, phase⟩).target.object = object ∧ + ((selfModel chosen).input ⟨0, object, phase⟩).contract.test = objectTest object ∧ + ((selfModel chosen).input ⟨0, object, phase⟩).requested = requestedCases chosen phase ∧ + ((selfModel chosen).input ⟨0, object, phase⟩).reasons = reviewReasons object phase ∧ + ((selfModel chosen).input ⟨0, object, phase⟩).basis = reviewBasis chosen object phase := + ⟨rfl, rfl, rfl, rfl, rfl⟩ + +theorem currentSelfRecords (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) : + (selfModel chosen).follows := by + rcases ordinary with rfl | rfl + all_goals + intro activity object phase member applies + cases activity <;> cases object <;> cases phase + all_goals first + | rename_i principle; cases principle + | skip + all_goals simp_all [Reflection.interpret, Reflection.Model.input, + Reflection.evaluate, selfModel, statedReview, reviewObjects, coreCommitments, + requestedCases, reviewReasons, criticismFor, objectTest, safeguardExperiment, + generationApplies, assessmentApplies, generationRuleTest, assessmentRuleTest, + ruleProbe, Reflection.generate, + reviewBasis, ReasonRelevant, reasonFor, HasThreat, burdens, ConcreteThreat, cost, + EvolutionPriority, PriorityConditions, JustifiedDeparture, currentContinuing, + Continuing, ActivityScope, Meets, profile, normalRequirements, initialGrounds, + ContinuingCapability, continuingActivity, maintainers, changePath, + changeWork, abstractionComplexity, credible, CredibleDirection, articulateGround, + supportGround, normalLimits, staticBatch, liveBatch, batchCount, orderedUnique, + sortedUnique, sortValues, insertOrdered, List.eraseDups] + all_goals decide + +theorem currentSelfApplication (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) : + reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self + (selfModel chosen).performed := + Reflection.recordedReflexivity _ (currentSelfRecords chosen ordinary) + +/- The activity's own assessment method passes its old observation while the +expanded input exposes its actual failed forecast. Neither applying the method +to itself nor generating a broader candidate makes the failed forecast true. -/ +theorem actualSelfCriticism (chosen : Candidate) : + objectTest .evolutionMethod (chosen, 10) = true ∧ + objectTest .evolutionMethod (chosen, 5) = false ∧ + Reflection.evaluate ((selfModel chosen).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧ + statedReview chosen .generation .evolutionMethod .revision = + .generated [(chosen, 10), (chosen, 5)] [(chosen, 10), (chosen, 5)] ∧ + staticBatch 21 5 ≠ liveBatch 21 5 := by + refine ⟨?_, ?_, ?_, rfl, by decide⟩ + · change (staticBatch 21 10 == liveBatch 21 10) = true + decide + · change (staticBatch 21 5 == liveBatch 21 5) = false + decide + · simp [Reflection.evaluate, Reflection.Model.input, selfModel, requestedCases, + objectTest, staticBatch, liveBatch, batchCount] + +/- The objects use the very functions in the adopted rules, and the same +applicability functions. Assessment applies in all three phases; generation +applies to formation and revision, including formation/revision of these rules. -/ +theorem ownRuleIdentity (chosen : Candidate) (activity : CoreReader.Agency.Activity) + (phase : CoreReader.Agency.Phase) : + ruleObject activity ∈ (selfModel chosen).objects ∧ + ((selfModel chosen).rule activity).meaning = Reflection.interpret activity ∧ + ((selfModel chosen).input ⟨0, ruleObject activity, phase⟩).contract.test = + objectTest (ruleObject activity) ∧ + (selfModel chosen).generationApplies (ruleObject activity) phase = + generationApplies (ruleObject activity) phase ∧ + (selfModel chosen).assessmentApplies (ruleObject activity) phase = + assessmentApplies (ruleObject activity) phase := by + refine ⟨?_, rfl, rfl, rfl, rfl⟩ + cases activity <;> simp [ruleObject, selfModel, reviewObjects] + +/- Changing the actual generator changes its object's result despite keeping +the object name. The evaluator really approves an empty initial sample set; +its own revision review reports that bounded defect instead of a self-proof. -/ +theorem ownRuleContentVariation (chosen : Candidate) : + generationRuleTest Reflection.generate (chosen, 10) = true ∧ + generationRuleTest (fun _ => .generated [] []) (chosen, 10) = false ∧ + assessmentRuleTest Reflection.evaluate (chosen, 10) = true ∧ + assessmentRuleTest Reflection.evaluate (chosen, 5) = false ∧ + Reflection.evaluate ((selfModel chosen).input ⟨0, .assessmentRule, .revision⟩) = .counterexample ∧ + generationApplies .generationRule .formation ∧ + generationApplies .generationRule .revision ∧ + ¬ generationApplies .generationRule .application ∧ + (∀ phase, assessmentApplies .assessmentRule phase) := by + simp [generationRuleTest, assessmentRuleTest, ruleProbe, Reflection.generate, + Reflection.evaluate, Reflection.Model.input, selfModel, requestedCases, + objectTest, generationApplies, assessmentApplies] + +theorem proposedRuleRevision (chosen : Candidate) : + assessmentRuleTest Reflection.evaluate (chosen, 5) = false ∧ + assessmentRuleTest sampleAwareAssessment (chosen, 5) = true ∧ + assessmentRuleTest sampleAwareAssessment (chosen, 10) = true ∧ + ((selfModel chosen).rule .generation).applicable ⟨0, .generationRule, .revision⟩ ∧ + ¬ (({ selfModel chosen with generationApplies := fun _ _ => False }).rule .generation).applicable + ⟨0, .generationRule, .revision⟩ := by + simp [assessmentRuleTest, sampleAwareAssessment, ruleProbe, Reflection.evaluate, + Reflection.Model.rule, Reflection.Model.self, selfModel, reviewObjects, + generationApplies] + +end CoreReader.Engineering +``` + + + + **L1** Import CoreReader.Engineering.Values, making its declarations and transitive dependencies available; this line adds no new proposition. + + + **L2** Import CoreReader.Engineering.Reflection, making its declarations and transitive dependencies available; this line adds no new proposition. + + + **L4** Open namespace CoreReader.Engineering for the following declarations. + + + **L6** Allow unqualified references to declarations in CoreReader.Adopted; their meaning is unchanged. + + + **L8** ReviewObject distinguishes the activity, each parameterized Core commitment, priority and evolution method. + + + **L9** Add actual generation-rule and assessment-rule objects to the same object type. + + + **L10** Derive DecidableEq, Repr: decidable equality and printable representations of these constructors. + + + **L12** A review case is a pair of selected Candidate and natural-number size. + + + **L14** Generation applicability ignores object identity and depends only on lifecycle phase. + + + **L15** Generation applies exactly outside application: formation and revision. + + + **L17** Assessment applicability ignores both arguments and is true in all phases for every object. + + + **L19** Map each actual activity to its corresponding method review object. + + + **L20** Generation is represented by generationRule. + + + **L21** Assessment is represented by assessmentRule. + + + **L23** Comment says these probes target current reflection functions themselves and introduces the size-10 case. + + + **L24** Comment contrasts a real initial sample at size 10 with its removal at size 5. + + + **L25** Comment retains the requested claim and distinguishes this actual-rule test from the domain batch predictor. + + + **L26** Build a probe for an actual method, parameterized by activity and Candidate/size pair. + + + **L27** The probe's samples are ReviewCase and its targets are ReviewObject. + + + **L28** Fix owner 0 and revision phase, with object chosen from the activity. + + + **L29** The inner test always passes; only size 10 supplies an initial sample, while claimed always contains the point. + + + **L30** Retain the point as the requested case even when the initial sample list is empty. + + + **L31** Supply a nonempty reason describing scope retention and distinguishing an empty initial list. + + + **L32** The probe basis is True; this field supplies no additional empirical justification. + + + **L34** generationRuleTest tests the function supplied as method, allowing real function replacement. + + + **L35** The method must map this exact reflection input type to the corresponding outcome type. + + + **L36** For a case, return a Boolean contract result. + + + **L37** Construct the generation probe for this same case. + + + **L38** Require exact outcome equality to generated requested tests and requested scope. + + + **L40** assessmentRuleTest checks an explicitly supplied evaluator against a local sample-aware contract. + + + **L41** The evaluated method has this exact input type and returns a Verdict. + + + **L42** Each Candidate/size case receives a Boolean pass/fail result. + + + **L43** Compare the actual method's verdict on the assessment probe with the expected verdict below. + + + **L44** Expect support at size 10 and noSupportingSample otherwise; this is a local contract, not a universal empirical duty. + + + **L46** Comment introduces a candidate revision adding the missing empty-initial-list check. + + + **L47** Comment explicitly keeps the candidate separate from the currently installed evaluator. + + + **L48** Define a distinct candidate evaluator revision over the same input type. + + + **L49** Reject an empty initial tested list before delegating nonempty cases to current evaluate. + + + **L51** Comment introduces the evolutionMethod branch as criticism of this activity's own static batch forecast. + + + **L52** Comment contrasts the original size with the credible changed runtime size. + + + **L53** objectTest selects an operational Boolean test by actual review object. + + + **L54** Pattern-match the object's constructor to choose its specific test. + + + **L55** For activity, decide whether the chosen design profile meets current necessary requirements. + + + **L56** For a commitment, run its enabled safeguard experiment on the chosen design. + + + **L57** For priority, decide the actual EvolutionPriority proposition in currentContinuing. + + + **L58** For evolutionMethod, compare the static and live batch forecasts for 21 items at this size. + + + **L59** For generationRule, pass the actual Reflection.generate function to its test. + + + **L60** For assessmentRule, pass the actual Reflection.evaluate function to its test. + + + **L62** Construct a finite review-object list depending on the chosen design. + + + **L63** Include the activity and all five Core commitments using their original identifiers. + + + **L64** Include the priority object only for the evolvable selection. + + + **L65** Always include the batch method and both actual rule objects. + + + **L67** Requested cases depend on chosen design and lifecycle phase. + + + **L68** Formation and application request only size 10. + + + **L69** Revision expands the requested list to sizes 10 and 5 of the same design. + + + **L71** Construct reason strings specifically for each object and phase. + + + **L72** Choose the first reason by the actual object constructor. + + + **L73** The activity reason names its order, safety, latency and retention requirements. + + + **L74** A commitment reuses the criticism string indexed by the same principle. + + + **L75** The priority reason identifies evidence, maintainer paths, requirements and costs. + + + **L76** The method reason compares the same forecast at recorded and proposed runtime sizes. + + + **L77** The generator reason demands retention of requested tests and scope. + + + **L78** The evaluator reason states this local dependence on the presence of supporting samples. + + + **L79** Return the object-specific reason plus a phase-specific reason. + + + **L80** Formation asks for the object's purpose and initial contract conditions. + + + **L81** Application names the current chosen design and continuing activity. + + + **L82** Revision asks to examine wider inputs and retain counterexamples. + + + **L84** Comment emphasizes that statedReview records are defined independently of evaluate. + + + **L85** Comment identifies the batch-method revision as an explicitly recorded counterexample. + + + **L86** Comment limits other supported records to the finite scopes checked by the subsequent proof. + + + **L87** statedReview independently records an outcome for a chosen design and activity. + + + **L88** The record also depends on object and phase and has the exact reflection outcome type. + + + **L89** Separate generation records from assessment records. + + + **L90** Generation records the phase's requested list in both output fields. + + + **L91** Assessment chooses its recorded verdict by object/phase, rather than calling evaluate. + + + **L92** Revision of the batch method or assessment rule is explicitly recorded as a counterexample. + + + **L93** Every other object/phase assessment is recorded as supportedWithinScope. + + + **L95** Comment introduces basis as object-specific factual content instead of an unrestricted approval flag. + + + **L96** Comment explains that a counterexample can support criticism of the same object. + + + **L97** Comment denies that such critical support establishes the method's broader original claim. + + + **L98** reviewBasis gives object-specific propositions; proofs will be checked for the ordinary designs. + + + **L99** Activity inquiry requires the actual activity's scope condition. + + + **L100** It additionally requires the chosen profile to meet current necessary requirements. + + + **L101** Commitment inquiry requires factual relevance of the reason for that same principle and selection. + + + **L102** Priority inquiry requires current applicability and absence of a threat to evolvable. + + + **L103** The revision branch gives a stronger basis for the batch-method inquiry. + + + **L104** Require success at size 10 and an actual inequality at size 5. + + + **L105** Other batch-method phases require only the size-10 equality. + + + **L106** The generator's basis is a positive and negative test of actual function content. + + + **L107** The real generator must pass at this chosen design and size 10. + + + **L108** An empty-output generator must fail on the same case. + + + **L109** Assessment-rule revision requires a two-case contrast. + + + **L110** The current evaluator must pass its sample-aware test at size 10. + + + **L111** It must fail that contract at size 5, where the initial list is empty. + + + **L112** Other assessment-rule phases require the size-10 positive case only. + + + **L114** selfModel instantiates reflection with these cases and objects for the chosen design. + + + **L115** Set the model owner to 0. The separate self relation requires self-owned targets to match it; raw Model.input still accepts and retains a target with any owner. + + + **L116** Use the choice-dependent actual object list. + + + **L117** Each outer contract uses its objectTest, with initial tested and claimed lists containing size 10. + + + **L118** All objects share the phase-specific requestedCases for the chosen design. + + + **L119** Use actual object/phase reason construction. + + + **L120** Use the substantive object/phase basis predicates. + + + **L121** Install the actual generation applicability function. + + + **L122** Install the actual assessment applicability function. + + + **L123** Use independently stated records, which currentSelfRecords later verifies. + + + **L125** Comment begins the distinction between the actual normative object and its finite rationale experiment. + + + **L126** Comment denies that success of the rationale experiment proves universal normative correctness. + + + **L127** Comment states the intended same-identifier link across adoption, reasons and reflection. + + + **L128** For every chosen design and object, reviewIdentity identifies all input components. + + + **L129** The identity holds for every lifecycle phase. + + + **L130** The input's target object is exactly the supplied object. + + + **L131** Its test is exactly objectTest for that same object. + + + **L132** Its requested list is exactly the chosen design's list at this phase. + + + **L133** Its reasons are exactly those of the same object and phase. + + + **L134** Its basis is exactly the same chosen/object/phase predicate. + + + **L135** All five identities hold by definitional reflexivity, not empirical validation. + + + **L137** currentSelfRecords checks the records of a selected design. + + + **L138** The premise restricts chosen to presentSimple or evolvable; maximal is excluded. + + + **L139** The conclusion is follows, including each applicable record's actual interpretation. + + + **L140** Split the ordinary premise and substitute each of the two designs. + + + **L141** Apply subsequent proof steps to both design goals. + + + **L142** Introduce arbitrary activity, object, phase, membership and applicability premises. + + + **L143** Exhaust all constructors of activity, object and phase. + + + **L144** On every remaining goal, try the following local tactics in order. + + + **L145** When a commitment parameter exists, name it principle and split its five constructors. + + + **L146** Otherwise leave the goal unchanged rather than requiring a principle parameter. + + + **L147** Simplify all goals and hypotheses using the actual interpretation and input construction. + + + **L148** Expand evaluator, model, stated records and finite object lists. + + + **L149** Expand requested cases, reasons, object tests and safeguard experiments. + + + **L150** Expand both applicability predicates and actual rule-test definitions. + + + **L151** Expand the inner method probe and actual generator. + + + **L152** Expand basis, relevance and concrete threat/cost predicates. + + + **L153** Expand priority, applicability, departure and the fixed current context. + + + **L154** Expand activity scope, necessary requirements, profiles and initial evidence. + + + **L155** Expand continuing capability, maintainer list and actual change paths. + + + **L156** Expand work, complexity and credibility of the stated directions. + + + **L157** Expand evidence support, limits, batch arithmetic and ordered output. + + + **L158** Expand the sorting and duplicate-removal helpers needed for finite checks. + + + **L159** Decide any remaining closed finite propositions after the case splits and simplification. + + + **L161** currentSelfApplication derives reflexivity for a selected design. + + + **L162** Retain the explicit two-design ordinary premise. + + + **L163** The specification uses the same selfModel's rules and self-target predicate. + + + **L164** Its performance relation is also taken from that same model. + + + **L165** Apply the generic recordedReflexivity theorem with the actually proved currentSelfRecords premise. + + + **L167** Comment identifies success of the old observation for the activity's batch assessment method. + + + **L168** Comment says expanded input reveals the failed forecast and begins the limit of self-application. + + + **L169** Comment denies that self-application or a broader generated candidate makes the failed forecast true. + + + **L170** actualSelfCriticism holds for every chosen design and exhibits the batch method's finite failure. + + + **L171** The old size-10 batch test passes. + + + **L172** The size-5 batch test fails. + + + **L173** The actual revision evaluator reports counterexample for that same method object. + + + **L174** The separately recorded generation result for that method's revision is specified. + + + **L175** Both generated lists contain size 10 and size 5 for the same chosen design. + + + **L176** The conclusion also retains the underlying arithmetic forecast inequality. + + + **L177** Construct five conjuncts; generation is reflexive and arithmetic inequality decidable, leaving three checks. + + + **L178** Expose the size-10 Boolean equality test as the first proof goal. + + + **L179** Compute that closed size-10 equality. + + + **L180** Expose the size-5 Boolean inequality result as the next goal. + + + **L181** Compute that closed size-5 failure. + + + **L182** Expand the evaluator and actual model input for the counterexample goal. + + + **L183** Reduce object test and batch arithmetic to close that counterexample calculation. + + + **L185** Comment stresses identity between review objects and the functions actually used in adopted rules. + + + **L186** Comment retains identical applicability functions and all-phase assessment. + + + **L187** Comment includes formation/revision of the generation rules themselves in generation's applicable phases. + + + **L188** ownRuleIdentity links every chosen design and activity to the actual rule object and implementation. + + + **L189** The link is stated for every phase, regardless of whether generation applies there. + + + **L190** The activity's method object actually belongs to the model's objects. + + + **L191** The model rule's meaning is exactly the actual interpret activity function. + + + **L192** The input for this same rule object obtains its actual contract test. + + + **L193** That test is objectTest indexed by this identical method object. + + + **L194** Compare the model's generation applicability at this object/phase. + + + **L195** It equals the declared generationApplies function on the same arguments. + + + **L196** Compare the model's assessment applicability at this object/phase. + + + **L197** It equals assessmentApplies on those identical arguments. + + + **L198** Four function/field equalities are reflexive; leave actual object membership as the only goal. + + + **L199** Split activity and compute membership in the actual review-object list. + + + **L201** Comment describes a content-sensitive generator replacement despite unchanged object naming. + + + **L202** Comment records the actual evaluator's acceptance with an empty initial sample list; requested cases are still checked. + + + **L203** Comment characterizes the outer self-review as reporting this bounded local-contract defect, not proving itself universally valid. + + + **L204** ownRuleContentVariation supplies function-sensitive positive and negative cases for every design. + + + **L205** The current generator passes the size-10 retention test. + + + **L206** An empty-output generator fails the identical test. + + + **L207** The current evaluator passes the local sample-aware contract with a size-10 sample. + + + **L208** It fails that contract at size 5 with an empty initial sample list. + + + **L209** The outer revision assessment of the actual assessment-rule object reports counterexample. + + + **L210** Generation applies to formation of its own rule object. + + + **L211** It also applies to revision of its own rule object. + + + **L212** Generation does not apply to application phase of that object. + + + **L213** Assessment applies to its own rule object for every phase. + + + **L214** Unfold actual method tests, probe and generator in all conjuncts. + + + **L215** Expand evaluator, actual input/model and requested cases. + + + **L216** Reduce the object test and both applicability predicates to finish the finite checks. + + + **L218** proposedRuleRevision compares current and candidate evaluators and an applicability mutation. + + + **L219** The current evaluator fails the local empty-initial-sample contract. + + + **L220** The separate sampleAwareAssessment candidate passes that size-5 contract. + + + **L221** The candidate also retains the size-10 positive result. + + + **L222** The current generation rule applies to revision of its own generation-rule object. + + + **L223** A separate model update making generationApplies always False removes that applicability. + + + **L224** The removed applicability concerns exactly owner 0, generationRule and revision. + + + **L225** Expand the local test, candidate evaluator, probe and current evaluator. + + + **L226** Expand actual rule/self-target semantics and model object membership. + + + **L227** Reduce generation applicability to complete the conjunction; neither candidate is installed here. + + + **L229** Close namespace CoreReader.Engineering; no further mathematical claim is asserted. + + +### `leanified/CoreReader/Engineering/Values.lean` + + +```lean +import CoreReader.Adopted +import CoreReader.Engineering.Domain + +namespace CoreReader.Engineering + +open CoreReader.Logic CoreReader.Evidence CoreReader.Adopted + +inductive CoreCommitment | generation | consistency | reflexivity | grounds | choice + deriving DecidableEq, Repr + +def coreCommitments : List CoreCommitment := + [.generation, .consistency, .reflexivity, .grounds, .choice] + +/- Initial adoption is explicit. The following reasons neither infer adoption +from facts nor claim that every alternative value position is untenable. -/ +def coreAdopted (_ : CoreCommitment) : Bool := true + +inductive AdoptionReason + | plannedChange (release : Nat) (direction : Change) + | incompatibleOrders (input : List Nat) + | ownMethodCounterexample (items size : Nat) + | unsupportedScope (items observedSize extendedSize : Nat) + | statusBudgetContrast (statusSelected : Candidate) (capacity : Nat) + deriving DecidableEq, Repr + +def reasonFor : CoreCommitment → AdoptionReason + | .generation => .plannedChange 2 .designRevision + | .consistency => .incompatibleOrders [2, 1, 2] + | .reflexivity => .ownMethodCounterexample 21 5 + | .grounds => .unsupportedScope 21 10 5 + | .choice => .statusBudgetContrast .maximal 12 + +/- Each factual reason has contents specific to the principle's purpose. The +context is the very continuing activity and its current requirements/grounds. +Matching a constructor alone is insufficient: the represented facts must hold. -/ +abbrev ReasonRelevant : CoreCommitment → AdoptionReason → Candidate → Prop + | .generation, .plannedChange release direction, _ => + DirectionGround.plan release [direction, .migration] ∈ currentContinuing.evidence ∧ + credible currentContinuing.evidence direction ∧ Continuing currentContinuing.activity + | .consistency, .incompatibleOrders input, _ => + currentContinuing.required.orderRequired = true ∧ + orderedUnique input ≠ sortedUnique input + | .reflexivity, .ownMethodCounterexample items size, _ => + staticBatch items 10 = liveBatch items 10 ∧ staticBatch items size ≠ liveBatch items size + | .grounds, .unsupportedScope items observedSize extendedSize, _ => + staticBatch items observedSize = liveBatch items observedSize ∧ + staticBatch items extendedSize ≠ liveBatch items extendedSize + | .choice, .statusBudgetContrast candidate capacity, selected => + capacity = currentContinuing.limits.capacity .understanding ∧ + capacity < abstractionComplexity candidate ∧ abstractionComplexity selected ≤ capacity + | _, _, _ => False + +abbrev valueScope (selected : Candidate) : Prop := abstractionComplexity selected ≤ 3 + +/- A small operational experiment explains each adopted safeguard's purpose. +These consequences are limited to the stated experiment, not a total value score. +The disabled branch supplies a real contrast for this application policy. -/ +def safeguardExperiment (principle : CoreCommitment) (enabled : Bool) + (selected : Candidate) : Bool := + match principle with + | .generation => + let allowed : List Change := if enabled then [.designRevision, .migration] else [] + allowed.contains .designRevision && decide (credible currentContinuing.evidence .designRevision) + | .consistency => + let firstDemand := orderedUnique [2, 1, 2] + let secondDemand := sortedUnique [2, 1, 2] + let permitsBoth := if enabled then firstDemand == secondDemand else true + !permitsBoth + | .reflexivity => + let selfTests := if enabled then [(21, 10), (21, 5)] else [(21, 10)] + selfTests.any (fun point => staticBatch point.1 point.2 != liveBatch point.1 point.2) + | .grounds => + let licensed := if enabled then [10] else [10, 5] + licensed.all (fun size => staticBatch 21 size == liveBatch 21 size) + | .choice => + let selectedByRule := if enabled then selected else .maximal + decide (abstractionComplexity selectedByRule ≤ currentContinuing.limits.capacity .understanding) + +def criticismFor : CoreCommitment → String + | .generation => "Reconsider this reason if the committed change or continuing maintenance ends." + | .consistency => "Reconsider the comparison if the parties deliberately revise the observable order contract." + | .reflexivity => "This counterexample concerns the stated batch rule; it does not validate all self-assessment." + | .grounds => "A new input condition requires its own support; success at size ten does not cover size five." + | .choice => "If objectives or budgets change, compare the actual alternatives and reasons again." + +def governancePosition (principle : CoreCommitment) : ValuePosition Candidate where + Position := Bool + Outcome := Bool + adopted := true + selected _ := coreAdopted principle + outcome selected enabled := safeguardExperiment principle enabled selected + objective result := result = true + constraints selected _ := valueScope selected + starting := singleton valueScope + reasons := [fun selected _ => ReasonRelevant principle (reasonFor principle) selected] + limits := valueScope + relevantCriticism _ := True + response _ := some (criticismFor principle) + +theorem adoptionReasonRelevant (principle : CoreCommitment) (selected : Candidate) + (scope : valueScope selected) : ReasonRelevant principle (reasonFor principle) selected := by + cases principle + · dsimp only [ReasonRelevant, reasonFor]; decide + · dsimp only [ReasonRelevant, reasonFor]; decide + · dsimp only [ReasonRelevant, reasonFor]; decide + · dsimp only [ReasonRelevant, reasonFor]; decide + · refine ⟨rfl, by decide, ?_⟩ + exact Nat.le_trans scope (by decide) + +theorem safeguardEnabled (principle : CoreCommitment) (selected : Candidate) + (scope : valueScope selected) : safeguardExperiment principle true selected = true := by + cases principle + · dsimp only [safeguardExperiment]; decide + · dsimp only [safeguardExperiment]; decide + · dsimp only [safeguardExperiment]; decide + · dsimp only [safeguardExperiment]; decide + · apply decide_eq_true + exact Nat.le_trans scope (by change 3 ≤ 12; decide) + +theorem safeguardDisabled (principle : CoreCommitment) (selected : Candidate) : + safeguardExperiment principle false selected = false := by + cases principle <;> simp only [safeguardExperiment, Bool.false_eq_true, ↓reduceIte] <;> decide + +theorem governanceValueProcedure (principle : CoreCommitment) : + ValueProcedure (governancePosition principle) := by + refine ⟨by simp [governancePosition], ?_, ?_, ?_⟩ + · refine ⟨.evolvable, (modelsSingleton _ _).2 (by change 3 ≤ 3; decide), + (by change 3 ≤ 3; decide), rfl, ?_⟩ + intro reason member + cases List.mem_singleton.mp member + exact adoptionReasonRelevant principle .evolvable (by change 3 ≤ 3; decide) + · intro selected _ scope _ + exact ⟨safeguardEnabled principle selected scope, scope⟩ + · intro selected _ _ + exact ⟨criticismFor principle, rfl, by cases principle <;> decide⟩ + +theorem governanceGrounded (principle : CoreCommitment) : + valueSpecification (governancePosition principle) := + grounds012Singleton _ (governanceValueProcedure principle) + +/- Factual relevance, rationale experiments and value adoption are separate. +Swapping a reason or altering the input makes the finite rationale fail. -/ +theorem governanceRationaleLimits : + ¬ ReasonRelevant .consistency (reasonFor .generation) .evolvable ∧ + ¬ ReasonRelevant .reflexivity (.ownMethodCounterexample 21 10) .evolvable ∧ + ¬ ReasonRelevant .generation (.plannedChange 9 .addition) .evolvable ∧ + ¬ valueScope .maximal ∧ + (∀ principle, safeguardExperiment principle false .evolvable = false) ∧ + (∀ principle, (governancePosition principle).commitment .presentSimple) := by + refine ⟨by change ¬ False; decide, by decide, by decide, by change ¬ (30 ≤ 3); decide, + fun principle => safeguardDisabled principle .evolvable, fun _ => rfl⟩ + +/- This additional value priority is a real selection between the same designs. +Both scopes retain all necessary domain conditions and no cost exception. +The present-simple stance values less abstraction now without claiming that it +has the better successor-maintainer capability. The other stance values that capability. -/ +def selectionObjective (adopted : Candidate) (outcome : Nat × Nat) : Prop := + match adopted with + | .presentSimple => outcome.1 ≤ 1 + | .evolvable => outcome.2 ≤ 6 + | .maximal => outcome.1 ≤ 1 + +def selectionPosition (adopted : Candidate) : ValuePosition Candidate where + Position := Candidate + Outcome := Nat × Nat + adopted := adopted + selected := id + outcome _ candidate := (abstractionComplexity candidate, changeWork candidate .designRevision) + objective := selectionObjective adopted + constraints _ candidate := abstractionComplexity candidate ≤ currentContinuing.limits.capacity .understanding + starting := singleton (fun candidate => candidate = adopted) + reasons := [fun _ candidate => + abstractionComplexity candidate = (if adopted = .presentSimple then 1 else 3) ∧ + changeWork candidate .designRevision = (if adopted = .presentSimple then 17 else 6)] + limits _ := Continuing currentContinuing.activity ∧ + credible currentContinuing.evidence .designRevision + relevantCriticism _ := True + response _ := some (if adopted = .presentSimple then + "The successor lacks the private-layout path; this choice does not claim evolution priority and must be reconsidered if that value is adopted." + else "The six-step design-revision path does not establish every change is cheap or every forecast is correct.") + +theorem selectionValueProcedure (adopted : Candidate) + (ordinary : adopted = .presentSimple ∨ adopted = .evolvable) : + ValueProcedure (selectionPosition adopted) := by + rcases ordinary with rfl | rfl + · refine ⟨by simp [selectionPosition], ?_, ?_, ?_⟩ + · refine ⟨.presentSimple, (modelsSingleton _ _).2 rfl, ?_, rfl, ?_⟩ + · change Continuing currentContinuing.activity ∧ credible currentContinuing.evidence .designRevision + decide + · intro reason member + cases List.mem_singleton.mp member + decide + · intro selected _ _ allReasons + have actual := allReasons _ (List.mem_singleton.mpr rfl) + change abstractionComplexity .presentSimple = 1 ∧ changeWork .presentSimple .designRevision = 17 at actual + change abstractionComplexity .presentSimple ≤ 1 ∧ + abstractionComplexity .presentSimple ≤ currentContinuing.limits.capacity .understanding + exact ⟨by rw [actual.1]; exact Nat.le_refl _, by rw [actual.1]; decide⟩ + · intro selected _ _ + refine ⟨_, rfl, ?_⟩ + simp + · refine ⟨by simp [selectionPosition], ?_, ?_, ?_⟩ + · refine ⟨.evolvable, (modelsSingleton _ _).2 rfl, ?_, rfl, ?_⟩ + · change Continuing currentContinuing.activity ∧ credible currentContinuing.evidence .designRevision + decide + · intro reason member + cases List.mem_singleton.mp member + decide + · intro selected _ _ allReasons + have actual := allReasons _ (List.mem_singleton.mpr rfl) + change abstractionComplexity .evolvable = 3 ∧ changeWork .evolvable .designRevision = 6 at actual + change changeWork .evolvable .designRevision ≤ 6 ∧ + abstractionComplexity .evolvable ≤ currentContinuing.limits.capacity .understanding + exact ⟨by rw [actual.2]; exact Nat.le_refl _, by rw [actual.1]; decide⟩ + · intro selected _ _ + refine ⟨_, rfl, ?_⟩ + simp + +theorem selectionGrounded (adopted : Candidate) + (ordinary : adopted = .presentSimple ∨ adopted = .evolvable) : + valueSpecification (selectionPosition adopted) := + grounds012Singleton _ (selectionValueProcedure adopted ordinary) + +end CoreReader.Engineering +``` + + + + **L1** Import CoreReader.Adopted, making its declarations and transitive dependencies available; this line adds no new proposition. + + + **L2** Import CoreReader.Engineering.Domain, making its declarations and transitive dependencies available; this line adds no new proposition. + + + **L4** Open namespace CoreReader.Engineering for the following declarations. + + + **L6** Allow unqualified references to declarations in CoreReader.Logic CoreReader.Evidence CoreReader.Adopted; their meaning is unchanged. + + + **L8** Define five Core commitment identifiers: generation, consistency, reflexivity, grounds and choice. + + + **L9** Derive DecidableEq, Repr: decidable equality and printable representations of these constructors. + + + **L11** coreCommitments is the finite list of all represented commitment identifiers. + + + **L12** List each of the five constructors once, in the displayed order. + + + **L14** Comment identifies adoption as an explicit starting choice; reasons do not infer the adoption itself. + + + **L15** Comment rejects both deriving adoption from facts and claiming all alternative values untenable. + + + **L16** Every commitment is explicitly marked adopted; no factual premise derives this Boolean choice. + + + **L18** AdoptionReason is a typed family of concrete rationale data, not itself a proof. + + + **L19** plannedChange records a natural-number release and a Change direction. + + + **L20** incompatibleOrders stores the actual input list used to compare output orders. + + + **L21** ownMethodCounterexample stores item count and runtime size. + + + **L22** unsupportedScope distinguishes observed and extended sizes for a fixed item count. + + + **L23** statusBudgetContrast records a status-selected alternative and a natural-number capacity. + + + **L24** Derive DecidableEq, Repr: decidable equality and printable representations of these constructors. + + + **L26** Assign one concrete rationale value to every Core commitment. + + + **L27** Generation uses planned release 2 and designRevision. + + + **L28** Consistency uses the order-sensitive input [2, 1, 2]. + + + **L29** Reflexivity uses 21 items at runtime size 5. + + + **L30** Grounds compares observation at size 10 with extension to size 5 for 21 items. + + + **L31** Choice contrasts maximal against understanding capacity 12. + + + **L33** Comment introduces factual reasons specialized to each principle's purpose. + + + **L34** Comment fixes their context to this continuing activity and its actual requirements/evidence. + + + **L35** Comment requires actual reason contents to hold, beyond matching constructor names. + + + **L36** ReasonRelevant is a proposition on principle, structured reason and selected design; it checks actual reason content. + + + **L37** For generation with a planned-change reason, selection is irrelevant to this branch. + + + **L38** The precise release plan containing direction and migration must occur in current evidence. + + + **L39** That direction must be credible and the current activity continuing. + + + **L40** For consistency, use the input carried by the incompatible-orders reason. + + + **L41** The actual current requirements must demand order preservation. + + + **L42** Order-preserving and sorted duplicate removal must differ on that input. + + + **L43** For reflexivity, use the reason's item count and challenged size. + + + **L44** Require agreement at old size 10 and disagreement at the challenged size. + + + **L45** For grounds, compare the reason's observed and extended sizes. + + + **L46** Static and live forecasts must agree at the observed size. + + + **L47** They must disagree at the proposed extended size. + + + **L48** For choice, distinguish the contrasted candidate from the actually selected design. + + + **L49** The stated capacity must equal the current understanding capacity. + + + **L50** The contrasted candidate exceeds that capacity while the actual selection stays within it. + + + **L51** Any mismatched principle/reason constructors yield False. + + + **L53** The value procedure's disclosed scope is designs of abstraction complexity at most 3. + + + **L55** Comment introduces a small operational experiment explaining each safeguard's purpose. + + + **L56** Comment limits consequences to that experiment, excluding a total value score. + + + **L57** Comment identifies the disabled branch as an actual contrast within this application policy. + + + **L58** safeguardExperiment varies a named safeguard's enabled Boolean. + + + **L59** It also takes the actual selected design and returns an operational Boolean result. + + + **L60** Select the experiment by principle; this is no aggregate value metric. + + + **L61** The generation branch measures availability of a credible planned change. + + + **L62** Enable both designRevision and migration, or disable them with an empty allowed list. + + + **L63** Pass only if designRevision is allowed and currently credible. + + + **L64** The consistency branch measures refusal of incompatible simultaneous demands. + + + **L65** Compute the first demand using order-preserving duplicate removal. + + + **L66** Compute the second demand using sorted duplicate removal on the same input. + + + **L67** An enabled check permits both demands only if equal; disabling it permits both unconditionally. + + + **L68** The experiment succeeds when simultaneous permission is rejected. + + + **L69** The reflexivity branch tests the actual batch forecast on itself. + + + **L70** Enable the old and challenged sizes, or retain only the old size when disabled. + + + **L71** Pass when some listed point yields unequal static and live forecasts. + + + **L72** The grounds branch tests the licensed input scope. + + + **L73** Enable licensing only size 10; disabling broadens licensing to 10 and 5. + + + **L74** Require forecast equality for every licensed size, with 21 items fixed. + + + **L75** The choice branch measures conformity to understanding capacity. + + + **L76** Enable the supplied choice, or select maximal when the safeguard is disabled. + + + **L77** Decide whether that actual rule selection fits the current understanding capacity. + + + **L79** Assign a revisability/criticism response string to each principle. + + + **L80** The generation response identifies loss of committed change or ongoing maintenance as a reconsideration condition. + + + **L81** The consistency response allows reconsidering the comparison after deliberate revision of the order contract. + + + **L82** The reflexivity response limits the counterexample to this batch rule, not all self-assessment. + + + **L83** The grounds response denies extending size-10 success to size 5 without its own support. + + + **L84** The choice response calls for renewed comparison if objectives or budgets change. + + + **L86** For one principle, build a ValuePosition over Candidate with explicit adoption and bounded supporting reasons. + + + **L87** The value-position alternatives are Boolean enabled/disabled states. + + + **L88** The experiment's outcome type is Bool. + + + **L89** Adopt the enabled value position explicitly. + + + **L90** For every design, selected position is that principle's adoption flag. + + + **L91** Outcomes run the same principle's experiment using design and enabled position. + + + **L92** The objective is experiment success, represented by true. + + + **L93** Constraints require the design's valueScope regardless of Boolean position. + + + **L94** The starting theory consists solely of the valueScope proposition. + + + **L95** The singleton reason requires actual relevance for the same principle and selected design. + + + **L96** The application limit is again valueScope. + + + **L97** All Candidate values count as relevant criticism; no narrower filter is encoded. + + + **L98** Every criticism receives the principle's fixed response string. + + + **L100** Prove reason relevance for every principle and selected design within scope. + + + **L101** The premise bounds selected complexity by 3; the conclusion uses its exact reasonFor value. + + + **L102** Split the five principle constructors. + + + **L103** For generation, unfold reason content and compute plan membership, credibility and continuation. + + + **L104** For consistency, unfold and compute the order requirement and differing outputs. + + + **L105** For reflexivity, unfold and compute old success and challenged forecast failure. + + + **L106** For grounds, unfold and compute observed equality and extended inequality. + + + **L107** For choice, prove capacity identity and maximal over-budget, leaving the selected-design bound. + + + **L108** Chain selected complexity ≤ 3 with 3 ≤ 12 to obtain the required bound. + + + **L110** Prove the enabled experiment succeeds for every principle within the disclosed scope. + + + **L111** Retain the scope premise and state an actual Boolean equality to true. + + + **L112** Split by the five principles to compute each distinct experiment. + + + **L113** For generation, expand the enabled change list and decide the credibility test. + + + **L114** For consistency, expand the enabled comparison and decide rejection of incompatible demands. + + + **L115** For reflexivity, expand the two tests and decide existence of a failed forecast. + + + **L116** For grounds, expand the licensed size-10 list and decide its test success. + + + **L117** Convert the choice experiment's Boolean result into its underlying capacity proposition. + + + **L118** Use scope and the computed 3 ≤ 12 bound to prove that capacity proposition. + + + **L120** The disabled safeguard fails for every principle and selected design, without a scope premise. + + + **L121** State failure as exact equality of the computed experiment to false. + + + **L122** Split principles, reduce the disabled branches and decide all five finite results. + + + **L124** For each principle, verify the actual governance value procedure. + + + **L125** The target is ValueProcedure for that same governancePosition. + + + **L126** Construct nonempty reasons and leave compatibility, objective/constraints and response obligations. + + + **L127** Choose evolvable as a starting-theory witness, proving its singleton scope membership. + + + **L128** Prove its application limit and selection identity; leave its reason validity. + + + **L129** Introduce any reason belonging to the position's reason list. + + + **L130** Singleton membership identifies it with the actual relevance reason. + + + **L131** Apply the proved relevance theorem at evolvable's complexity bound 3 ≤ 3. + + + **L132** For an arbitrary design under the procedure premises, retain its scope proof. + + + **L133** Supply enabled experiment success and the same scope as objective and constraint satisfaction. + + + **L134** Introduce an arbitrary criticism case under the response premises. + + + **L135** Provide the fixed criticism response, its exact stored identity and nonemptiness by finite case analysis. + + + **L137** governanceGrounded gives grounds for the value commitment of every represented principle. + + + **L138** The conclusion is valueSpecification for the exact governance position. + + + **L139** Wrap its verified ValueProcedure in the singleton adopted Core 0.1.2 grounds construction. + + + **L141** Comment separates factual relevance, rationale experiments and value adoption. + + + **L142** Comment introduces failure cases from swapped reasons or altered inputs. + + + **L143** governanceRationaleLimits exhibits actual failures and distinguishes support from adoption. + + + **L144** A generation reason is irrelevant to consistency because the constructors mismatch. + + + **L145** A claimed self-counterexample at size 10 fails because the old forecast agrees there. + + + **L146** An unsupported release-9 addition plan fails the generation reason requirements. + + + **L147** maximal lies outside the complexity-at-most-3 value scope. + + + **L148** Every disabled safeguard experiment fails at evolvable. + + + **L149** Nevertheless every governance commitment is adopted at presentSimple too. + + + **L150** Compute the three irrelevant-reason cases and maximal's 30 > 3 scope failure. + + + **L151** Use safeguardDisabled for every principle, and reflexive adoption identity for the final universal claim. + + + **L153** Comment frames the additional value priority as a genuine selection between the same designs. + + + **L154** Comment points to the common context's necessary conditions and absence of cost exception; the limits field below explicitly tests continuation and credibility. + + + **L155** Comment says the simple position values lower present abstraction and begins its capability qualification. + + + **L156** Comment denies superior successor capability for the simple stance and assigns that objective to the other stance. + + + **L157** selectionObjective maps an adopted design and complexity/work pair to its chosen objective proposition. + + + **L158** The objective changes with the explicitly adopted candidate. + + + **L159** presentSimple values present abstraction complexity at most 1. + + + **L160** evolvable values design-revision work at most 6. + + + **L161** The maximal branch also uses complexity at most 1; no successful procedure for maximal is proved below. + + + **L163** Build a separate selection ValuePosition parameterized by the adopted candidate. + + + **L164** Its alternative positions are the actual Candidate designs. + + + **L165** Outcomes are natural-number pairs of complexity and revision work. + + + **L166** Store the supplied adopted candidate directly. + + + **L167** A world's selected position is itself, via the identity function. + + + **L168** Measure the chosen position's complexity and actual designRevision work. + + + **L169** Use the objective indexed by the adopted design. + + + **L170** Constrain the position's complexity by the actual understanding capacity. + + + **L171** The starting theory requires the world to equal the adopted design. + + + **L172** There is one reason function; it ignores the world argument and examines the position. + + + **L173** Require complexity 1 for presentSimple adoption, otherwise complexity 3. + + + **L174** Require revision work 17 for presentSimple adoption, otherwise 6. + + + **L175** The procedure's limits require the current activity to continue. + + + **L176** They also require designRevision to be credible in the actual evidence. + + + **L177** Every candidate is treated as relevant criticism. + + + **L178** Every criticism receives a response selected by whether presentSimple was adopted. + + + **L179** The simple response admits the successor's missing private-layout path and denies claiming evolution priority. + + + **L180** The evolvable response limits the six-step result and denies general cheap-change or forecast correctness. + + + **L182** Verify the selection value procedure for an adopted candidate. + + + **L183** Assume adoption is one of the two ordinary designs. + + + **L184** The conclusion is the actual ValueProcedure for that adoption. + + + **L185** Split and substitute presentSimple and evolvable adoptions. + + + **L186** For presentSimple, prove nonempty reasons and leave the three substantive procedure obligations. + + + **L187** Choose presentSimple itself as compatible witness and reduce its selection identity reflexively. + + + **L188** Expose the witness limit as actual continuation and credible designRevision. + + + **L189** Compute those fixed-context facts. + + + **L190** Introduce a reason from the singleton simple-position list. + + + **L191** Replace that reason by its unique member. + + + **L192** Compute simple design complexity 1 and revision work 17. + + + **L193** Introduce arbitrary procedure premises, retaining allReasons for simple adoption. + + + **L194** Extract the actual singleton reason from allReasons. + + + **L195** Expose that reason as the concrete equalities complexity 1 and work 17 at adopted presentSimple. + + + **L196** Expose the simple objective as complexity at most 1. + + + **L197** The second conjunct is the same design's understanding-capacity constraint. + + + **L198** Rewrite with the actual complexity equality, using reflexive ≤ for the objective and computation for capacity. + + + **L199** For arbitrary relevant criticism, enter the simple response obligation. + + + **L200** Choose the stored response and its reflexive equality; leave nonemptiness. + + + **L201** Simplify the fixed response to prove it is nonempty. + + + **L202** For evolvable, prove nonempty reasons and leave the same three procedure obligations. + + + **L203** Choose evolvable itself as compatible witness with reflexive selection identity. + + + **L204** Expose the evolvable witness's continuation and credible-revision limits. + + + **L205** Compute those limits in currentContinuing. + + + **L206** Introduce a reason from evolvable's singleton reason list. + + + **L207** Identify it with the unique actual reason. + + + **L208** Compute evolvable complexity 3 and revision work 6. + + + **L209** Introduce procedure premises for evolvable, retaining allReasons. + + + **L210** Extract the unique substantive reason from that premise. + + + **L211** Expose complexity 3 and designRevision work 6 for the adopted evolvable position. + + + **L212** Expose the evolvable objective as work at most 6. + + + **L213** Retain the actual understanding-capacity constraint on the same design. + + + **L214** Use work equality for the objective and complexity equality for the capacity check. + + + **L215** For any relevant criticism, enter the evolvable response obligation. + + + **L216** Choose the stored evolvable response, leaving its nonemptiness. + + + **L217** Simplify the response string to prove nonemptiness. + + + **L219** selectionGrounded packages value grounds for the adopted selection. + + + **L220** The two-ordinary-design assumption remains explicit. + + + **L221** The conclusion concerns exactly selectionPosition adopted. + + + **L222** Use the proved selection procedure as the discharged singleton value facet. + + + **L224** Close namespace CoreReader.Engineering; no further mathematical claim is asserted. + + +### `leanified/CoreReader/Evidence.lean` + + +```lean +import CoreReader.Logic +import CoreReader.Agency + +namespace CoreReader.Evidence +open CoreReader.Logic +open CoreReader.Agency + +/- An observation records the outcome of a specified test on the represented world. -/ +structure Record (W : Type) where + test : W → Bool + observed : Bool +/- Compatible worlds reproduce the actual contents of every recorded observation. -/ +def Compatible {W : Type} (records : List (Record W)) (w : W) : Prop := + ∀ r, r ∈ records → r.test w = r.observed +/- Inferential support requires the same claim in every evidence-compatible world. -/ +def Supports {W : Type} (records : List (Record W)) (claim : Claim W) : Prop := + ∀ w, Compatible records w → claim w +/- Articulation identifies concepts, premises, reason contents and an application limit. -/ +structure Articulation (W : Type) where + concepts : List String + assumptions : Theory W + reasons : List (Claim W) + limits : Claim W +/- Nonempty identifiable concepts and reasons are procedural articulation requirements. -/ +def Articulated {W : Type} (a : Articulation W) : Prop := + a.concepts ≠ [] ∧ a.reasons ≠ [] +/- This application model interprets an adopted option through its actual outcomes and stated goals/constraints. -/ +structure ValuePosition (W : Type) where + Position : Type + Outcome : Type + adopted : Position + selected : W → Position + outcome : W → Position → Outcome + objective : Outcome → Prop + constraints : W → Position → Prop + starting : Theory W + reasons : List (W → Position → Prop) + limits : Claim W + relevantCriticism : Claim W + response : W → Option String +/- The adopted position's claim is derived from the same selected option used by the outcome interpretation. -/ +def ValuePosition.commitment {W : Type} (v : ValuePosition W) : Claim W := + fun w => v.selected w = v.adopted +/- Assessed consequences concern this adopted option's actual outcome, objective and constraints. -/ +def ValuePosition.consequence {W : Type} (v : ValuePosition W) : Claim W := + fun w => v.objective (v.outcome w v.adopted) ∧ v.constraints w v.adopted +/- Articulated reasons specialize the actual option-indexed premises to the adopted option. -/ +def ValuePosition.activeReasons {W : Type} (v : ValuePosition W) : List (Claim W) := + v.reasons.map (fun reason w => reason w v.adopted) +/- A joint witness excludes inconsistent starts and impossible adoption states. -/ +def JointAdoption {W : Type} (v : ValuePosition W) : Prop := + ∃ w, Models v.starting w ∧ v.limits w ∧ v.commitment w ∧ + ∀ reason, reason ∈ v.reasons → reason w v.adopted +/- This declared option/outcome adapter checks joint reasons for an assessed consequence; it is not a necessary deductive form for all value justification. -/ +def ValueProcedure {W : Type} (v : ValuePosition W) : Prop := + v.reasons ≠ [] ∧ JointAdoption v ∧ + (∀ w, Models v.starting w → v.limits w → + (∀ reason, reason ∈ v.reasons → reason w v.adopted) → v.consequence w) ∧ + (∀ w, v.limits w → v.relevantCriticism w → ∃ answer, v.response w = some answer ∧ answer ≠ "") +/- A facet carries its specific contents; several different facets can have the same conclusion. -/ +inductive Facet (W : Type) where + | empirical (records : List (Record W)) (scope conclusion uncertainty : Claim W) + | inferential (assumptions : Theory W) (conclusion : Claim W) + | value (position : ValuePosition W) +/- The claim referred to by each assessment facet is explicit. -/ +def Facet.claim {W : Type} : Facet W → Claim W + | .empirical _ _ p _ => p + | .inferential _ p => p + | .value v => v.commitment +/- These disclosed semantic adapters implement selected nature-specific checks; passing them does not establish all real empirical or value adequacy. -/ +def FacetDischarged {W : Type} : Facet W → Prop + | .empirical records scope p uncertainty => + (∃ w, Compatible records w ∧ scope w) ∧ + Supports records (fun w => scope w → p w) ∧ Supports records uncertainty + | .inferential assumptions p => Satisfiable assumptions ∧ Entails assumptions p + | .value v => ValueProcedure v +/- This model's semantic adapter identifies the actual assumptions, reason content and limit of a facet. -/ +def FacetArticulated {W : Type} (a : Articulation W) : Facet W → Prop + | .empirical records scope _ _ => + a.assumptions = singleton (Compatible records) ∧ a.reasons = [Compatible records] ∧ a.limits = scope + | .inferential assumptions _ => + a.assumptions = assumptions ∧ a.reasons = [Models assumptions] ∧ a.limits = (fun _ => True) + | .value v => a.assumptions = v.starting ∧ a.reasons = v.activeReasons ∧ a.limits = v.limits +/- A canonical articulation exposes this adapter; the source does not mandate this particular representation of grounds. -/ +def canonicalArticulation {W : Type} : Facet W → Articulation W + | .empirical records scope _ _ => + ⟨["recorded test outcomes", "observation conditions"], singleton (Compatible records), [Compatible records], scope⟩ + | .inferential assumptions _ => + ⟨["stated assumptions", "semantic consequence"], assumptions, [Models assumptions], fun _ => True⟩ + | .value v => + ⟨["adopted position", "reasons and consequences"], v.starting, v.activeReasons, v.limits⟩ +/- Canonical articulation is connected to the very facet whose grounds it identifies. -/ +theorem canonicalFacetArticulated {W : Type} (f : Facet W) : + FacetArticulated (canonicalArticulation f) f := by + cases f <;> exact ⟨rfl, rfl, rfl⟩ +/- A discharged facet has nonempty canonical reason articulation, including the value procedure's reason requirement. -/ +theorem canonicalArticulated {W : Type} (f : Facet W) (h : FacetDischarged f) : + Articulated (canonicalArticulation f) := by + cases f with + | empirical records scope p uncertainty => simp [Articulated, canonicalArticulation] + | inferential assumptions p => simp [Articulated, canonicalArticulation] + | value v => + refine ⟨by simp [canonicalArticulation], ?_⟩ + simpa [canonicalArticulation, ValuePosition.activeReasons] using h.1 +/- This model of the Grounds obligation binds each actual facet to its claim and articulation. Its disclosed FacetDischarged adapters do not replace all source-level assessment responsibilities or prove real adequacy. -/ +def Grounds {W : Type} (claim : Claim W) (articulations : Facet W → Articulation W) + (actualApplicable : Facet W → Prop) (facets : List (Facet W)) : Prop := + facets ≠ [] ∧ (∀ facet, actualApplicable facet → facet ∈ facets) ∧ + ∀ facet, facet ∈ facets → facet.claim = claim ∧ Articulated (articulations facet) ∧ + FacetArticulated (articulations facet) facet ∧ FacetDischarged facet +/- The achievement obligation requires grounds for this very claim, without making observation a universal prerequisite. -/ +def AchievementAccountability {W : Type} (achievement : Claim W) (articulations : Facet W → Articulation W) + (actualApplicable : Facet W → Prop) (facets : List (Facet W)) : Prop := + Grounds achievement articulations actualApplicable facets +/- The concrete achievement claim refers to each transition's own before/after states. -/ +def transitionAchievement : Claim TransitionCase := + fun transition => Expanded (transitionBefore transition) (transitionAfter transition) +/- This observation inspects an actually constructed successor and its output under that transition's input condition. -/ +def transitionPerformanceRecord : Record TransitionCase := + ⟨fun transition => (transitionAfter transition).constructed.any + (fun operation => operation == .successor && decide (operation.run (transitionInput transition) = 1)), true⟩ +/- The positive report test reads its asserted operation, input and output; it does not verify their presence in the after-state. -/ +def transitionReportRecord : Record TransitionCase := + ⟨fun transition => + let report := transitionAnnouncement transition + report.reportedNewOperation == .successor && report.input == 0 && report.expectedOutput == 1, true⟩ +/- Only the genuine extension matches the operation/performance observation in this two-transition model. -/ +theorem transitionPerformanceCompatible : + ∀ transition, Compatible [transitionPerformanceRecord] transition ↔ transition = .extend := by + intro transition + constructor + · intro h + have observed := h transitionPerformanceRecord (List.mem_singleton.mpr rfl) + cases transition + · cases observed + · rfl + · intro h; cases h + intro record hr; have hr' := List.mem_singleton.mp hr; subst record + rfl +/- A compatible performance observation establishes the same transition's report content and hence its represented expansion. -/ +theorem transitionSupported : Supports [transitionPerformanceRecord] transitionAchievement := by + intro transition compatible + have h := (transitionPerformanceCompatible transition).1 compatible + subst transition + have reportTrue : (transitionAnnouncement .extend).claim := by + simp [transitionAnnouncement, transitionAfter, transitionInput, + Announcement.claim, GeneratingSystem.report, generatingSystem, extendedState, baseState, Operation.run] + exact announcementClaimImpliesExpansion _ reportTrue +/- The actual scope is the shared input-zero condition, with no probabilistic inference introduced. -/ +def transitionFacet : Facet TransitionCase := + .empirical [transitionPerformanceRecord] (fun transition => transitionInput transition = 0) + transitionAchievement (fun _ => True) +/- The empirical assessment has a real compatible witness and supports this scoped achievement. -/ +theorem transitionFacetDischarged : FacetDischarged transitionFacet := by + refine ⟨⟨.extend, (transitionPerformanceCompatible _).2 rfl, rfl⟩, ?_, ?_⟩ + · intro transition compatible _; exact transitionSupported transition compatible + · intro _ _; trivial +/- Every applicable facet of this specified achievement has matching articulation and actual discharged evidence. -/ +theorem transitionAccountable : + AchievementAccountability transitionAchievement canonicalArticulation + (fun facet => facet = transitionFacet) [transitionFacet] := by + refine ⟨by simp, ?_, ?_⟩ + · intro facet hf; subst facet; exact List.mem_singleton.mpr rfl + · intro facet hf; have hf' := List.mem_singleton.mp hf; subst facet + exact ⟨rfl, canonicalArticulated _ transitionFacetDischarged, + canonicalFacetArticulated _, transitionFacetDischarged⟩ +/- Both actual transitions issue the same positive report about their own identified state pair. -/ +theorem transitionReportCompatible (transition : TransitionCase) : + Compatible [transitionReportRecord] transition := by + intro record hr; have hr' := List.mem_singleton.mp hr; subst record + rfl +/- Inflation is a concrete report-compatible counterworld, so the positive report alone does not support the same achievement claim. -/ +theorem transitionReportDoesNotSupport : + Compatible [transitionReportRecord] .inflate ∧ ¬ transitionAchievement .inflate ∧ + ¬ Supports [transitionReportRecord] transitionAchievement := by + have noExpansion : ¬ transitionAchievement .inflate := by + simp [transitionAchievement, transitionBefore, transitionAfter, Expanded, baseState, inflatedState] + exact ⟨transitionReportCompatible _, noExpansion, fun h => noExpansion (h _ (transitionReportCompatible _))⟩ +/- These concrete obligations, positive evidence and negative report case all refer to the same state-pair and input semantics. -/ +def ConcreteAchievementExample : Prop := + AchievementAccountability transitionAchievement canonicalArticulation + (fun facet => facet = transitionFacet) [transitionFacet] ∧ + Compatible [transitionPerformanceRecord] .extend ∧ + Supports [transitionPerformanceRecord] transitionAchievement ∧ transitionAchievement .extend ∧ + (Compatible [transitionReportRecord] .inflate ∧ ¬ transitionAchievement .inflate ∧ + ¬ Supports [transitionReportRecord] transitionAchievement) ∧ + (∀ transition, (transitionAnnouncement transition).before = transitionBefore transition ∧ + (transitionAnnouncement transition).after = transitionAfter transition ∧ + (transitionAnnouncement transition).input = transitionInput transition ∧ transitionInput transition = 0) +/- The concrete example jointly inhabits accountability, evidence compatibility, actual gain, and the report-only countermodel. -/ +theorem concreteAchievementExample : ConcreteAchievementExample := by + refine ⟨transitionAccountable, (transitionPerformanceCompatible _).2 rfl, transitionSupported, + transitionSupported .extend ((transitionPerformanceCompatible _).2 rfl), + transitionReportDoesNotSupport, ?_⟩ + intro transition; exact ⟨rfl,rfl,rfl,rfl⟩ +/- Semantic evidence yields truth only at a world that actually satisfies those evidence conditions. -/ +theorem achievementNeedsSupport {W : Type} (achievement : Claim W) (records : List (Record W)) + (actual : W) (reliableHere : Compatible records actual) (support : Supports records achievement) : + achievement actual ∧ ConcreteAchievementExample := + ⟨support actual reliableHere, concreteAchievementExample⟩ +/- Weakening a conclusion preserves support; this makes no claim about weakening the evidence. -/ +theorem supportWeakening {W : Type} (records : List (Record W)) (p q : Claim W) + (support : Supports records p) (weaker : ∀ w, p w → q w) : Supports records q := + fun w hw => weaker w (support w hw) +/- Discarding the only informative observation loses support for the unchanged switch claim. -/ +theorem evidenceWeakeningCanLoseSupport : + Supports ([⟨id, true⟩] : List (Record Bool)) (fun w => w = true) ∧ + ¬ Supports ([] : List (Record Bool)) (fun w => w = true) := by + refine ⟨?_, ?_⟩ + · intro w hw; exact hw ⟨id,true⟩ (by simp) + · intro h; have bad := h false (by intro r hr; cases hr); cases bad +/- Restricting the quantified application domain preserves a supported universal conclusion. -/ +theorem scopeRestriction {W X : Type} (records : List (Record W)) (p : W → X → Prop) + (wide narrow : X → Prop) (included : ∀ x, narrow x → wide x) + (support : Supports records (fun w => ∀ x, wide x → p w x)) : + Supports records (fun w => ∀ x, narrow x → p w x) := + fun w hw x hx => support w hw x (included x hx) +/- Actual applicability, rather than an optional classifier label, determines facet responsibility. -/ +def Duties {W : Type} (applicable : Facet W → Prop) : Prop := + ∀ f, applicable f → FacetDischarged f +def LabeledDuties {W : Type} (_labels : List String) (applicable : Facet W → Prop) : Prop := + Duties applicable +/- Combining applicable facets requires both sets of substantive duties. -/ +theorem assessmentUnion {W : Type} (a b : Facet W → Prop) : + Duties (fun f => a f ∨ b f) ↔ Duties a ∧ Duties b := by + constructor + · intro h; exact ⟨fun f hf => h f (Or.inl hf), fun f hf => h f (Or.inr hf)⟩ + · rintro ⟨ha,hb⟩ f (hf|hf); exact ha f hf; exact hb f hf +/- Omitting or changing labels does not remove an applicable duty. -/ +theorem labelsCannotWaive {W : Type} (xs ys : List String) (a : Facet W → Prop) : + LabeledDuties xs a ↔ LabeledDuties ys a := Iff.rfl +/- The observed switch is the outcome itself, not a record identifier. -/ +def switchRecord : Record Bool := ⟨id, true⟩ +theorem switchCompatible (w : Bool) : Compatible [switchRecord] w ↔ w = true := by + constructor + · intro h; exact h switchRecord (by simp) + · intro hw r hr; simp only [List.mem_singleton] at hr; cases hr; exact hw +theorem switchSupported : Supports [switchRecord] (fun w : Bool => w = true) := + fun w hw => (switchCompatible w).1 hw +/- The candidate action has specific benefit and cost outcomes; its inactive alternative has neither. -/ +def optionBenefit (selected : Bool) : Nat := if selected then 4 else 0 +def optionCost (selected : Bool) : Nat := if selected then 3 else 0 +/- The report describes each option's actual cost and benefit; it does not itself assert which option ought to be selected. -/ +def optionReport (selected : Bool) : Prop := + optionCost selected ≤ 3 ∧ optionBenefit selected = (if selected then 4 else 0) +/- The on position connects its own selected option to that option's benefit/cost outcome. -/ +def switchPosition : ValuePosition Bool where + Position := Bool + Outcome := Nat × Nat + adopted := true + selected := id + outcome := fun _ option => (optionBenefit option, optionCost option) + objective := fun result => result.2 < result.1 + constraints := fun _ option => optionCost option ≤ 3 + starting := singleton (fun w => w = true) + reasons := [fun _ option => optionReport option] + limits := fun _ => True + relevantCriticism := fun w => w = false + response := fun w => if w then some "benefit exceeds cost within budget" else some "reconsider if the budget no longer permits this cost" +theorem switchValueProcedure : ValueProcedure switchPosition := by + refine ⟨by simp [switchPosition], ?_, ?_, ?_⟩ + · refine ⟨true, (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩ + intro reason hr + have hr' : reason = (fun (_ : Bool) (option : Bool) => optionReport option) := List.mem_singleton.mp hr + subst reason + exact ⟨by decide, rfl⟩ + · intro w _ _ allReasons + have evidence := allReasons (fun (_ : Bool) (option : Bool) => optionReport option) (List.mem_singleton.mpr rfl) + change optionReport true at evidence + have benefitAboveBudget : 3 < optionBenefit true := by rw [evidence.2]; decide + exact ⟨Nat.lt_of_le_of_lt evidence.1 benefitAboveBudget, evidence.1⟩ + · intro w _ _; cases w <;> simp [switchPosition] +/- Adopting the other option updates the adopted starting state too, so rejection cannot be blamed on an inconsistent start. -/ +def oppositePosition : ValuePosition Bool := + { switchPosition with adopted := false, starting := singleton (fun w => w = false) } +/- The alternative has a joint adoption witness but its actual zero benefit/cost fails the adopted strict-benefit objective. -/ +theorem oppositePositionRejected : JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition := by + have witness : JointAdoption oppositePosition := by + refine ⟨false, (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩ + intro reason hr + have hr' : reason = (fun (_ : Bool) (option : Bool) => optionReport option) := List.mem_singleton.mp hr + subst reason + exact ⟨by decide, rfl⟩ + refine ⟨witness, ?_⟩ + intro h + have allReasons : ∀ reason, reason ∈ oppositePosition.reasons → reason false oppositePosition.adopted := by + intro reason hr + have hr' : reason = (fun (_ : Bool) (option : Bool) => optionReport option) := List.mem_singleton.mp hr + subst reason + exact ⟨by decide, rfl⟩ + have bad := h.2.2.1 false ((modelsSingleton _ _).2 rfl) trivial allReasons + exact Nat.lt_irrefl 0 bad.1 +/- Contradictory starting assumptions and an impossible selected/adopted equality are separate inadmissible variants. -/ +def contradictoryStartingPosition : ValuePosition Bool := + { switchPosition with starting := singleton (fun _ => False) } +def impossibleAdoptionPosition : ValuePosition Bool := + { switchPosition with selected := fun _ => false } +/- The common-world witness rejects both contradiction and an impossible commitment instead of proving them vacuously. -/ +theorem inadmissibleValuePositionsRejected : + ¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition := by + constructor + · intro h; obtain ⟨w,hw,_,_,_⟩ := h.2.1 + exact (modelsSingleton _ _).1 hw + · intro h; obtain ⟨w,_,_,hw,_⟩ := h.2.1 + cases hw +/- Removing the reasons leaves only a position and assertion, which fails this value procedure. -/ +def unsupportedPosition : ValuePosition Bool := { switchPosition with reasons := [] } +def switchEmpirical : Facet Bool := + .empirical [switchRecord] (fun _ => True) (fun w => w = true) (fun _ => True) +theorem switchEmpiricalDischarged : FacetDischarged switchEmpirical := by + refine ⟨⟨true, (switchCompatible true).2 rfl, trivial⟩, ?_, ?_⟩ + · intro w hw _; exact switchSupported w hw + · intro w _; trivial +/- A mixed empirical/value position has actual empirical evidence but still lacks its value-reason duty. -/ +theorem mixedMissingResponsibility : + FacetDischarged switchEmpirical ∧ + ¬ LabeledDuties [] (fun f : Facet Bool => f = switchEmpirical ∨ f = .value unsupportedPosition) := by + refine ⟨switchEmpiricalDischarged, ?_⟩ + intro h + have bad := (h (.value unsupportedPosition) (Or.inr rfl)).1 + exact bad rfl +/- A fully identified argument may still fail to entail the stated conclusion. -/ +def uninformativeArgument : Articulation Bool := + ⟨["switch state"], emptyTheory, [fun _ => True], fun _ => True⟩ +theorem articulationNotSupport : Articulated uninformativeArgument ∧ + ¬ Entails uninformativeArgument.assumptions (fun w : Bool => w = true) := by + exact ⟨⟨by simp [uninformativeArgument], by simp [uninformativeArgument]⟩, + consistentIncomplete.2.1⟩ +/- Identifiable but unrelated argument fields cannot replace the actual observation grounds under the connected adapter. -/ +theorem unrelatedArticulationRejected : + Articulated uninformativeArgument ∧ FacetDischarged switchEmpirical ∧ + ¬ FacetArticulated uninformativeArgument switchEmpirical := by + refine ⟨articulationNotSupport.1, switchEmpiricalDischarged, ?_⟩ + intro h + have relation := congrFun h.1 (Compatible [switchRecord]) + have bad : False := relation.mpr rfl + exact bad +/- Repetition of the same unrelated temperature observation leaves the switch state undetermined. -/ +def temperatureRecord : Record (Bool × Bool) := ⟨Prod.fst, true⟩ +theorem temperatureCompatible (b : Bool) : + Compatible [temperatureRecord, temperatureRecord] (true,b) := by + intro r hr + simp at hr + cases hr + rfl +/- The world identifies a selected action and its budget; the action costs three units. -/ +abbrev BudgetWorld := Bool × Nat +/- A real issued announcement asserts the selected action, but says nothing about affordability. -/ +def announcement : String := "activate" +def announcementPosition : ValuePosition BudgetWorld where + Position := Bool + Outcome := Nat × Nat + adopted := true + selected := Prod.fst + outcome := fun _ option => (optionBenefit option, optionCost option) + objective := fun result => result.2 < result.1 + constraints := fun w option => optionCost option ≤ w.2 + starting := singleton (fun w => w.1 = true) + reasons := [fun _ option => announcement = (if option then "activate" else "disable")] + limits := fun _ => True + relevantCriticism := fun w => w.2 < 3 + response := fun _ => some "reconsider the action when its cost exceeds budget" +/- The zero-budget counterworld satisfies the stated starts, adoption and all announced reasons jointly. -/ +theorem announcementHasJointAdoption : JointAdoption announcementPosition := by + refine ⟨(true,0), (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩ + intro reason hr + have hr' : reason = (fun (_ : BudgetWorld) (option : Bool) => announcement = (if option then "activate" else "disable")) := + List.mem_singleton.mp hr + subst reason + rfl +/- A nonempty announcement remains true in a jointly admissible zero-budget world but cannot support the action's affordability. -/ +theorem announcementNotBudgetReason : + announcementPosition.reasons ≠ [] ∧ announcementPosition.commitment (true,0) ∧ + (∀ reason, reason ∈ announcementPosition.reasons → reason (true,0) announcementPosition.adopted) ∧ + ¬ announcementPosition.consequence (true,0) ∧ ¬ ValueProcedure announcementPosition := by + refine ⟨by simp [announcementPosition], rfl, ?_, (by intro h; cases h.2), ?_⟩ + · intro reason hr + have hr' : reason = (fun (_ : BudgetWorld) (option : Bool) => announcement = (if option then "activate" else "disable")) := List.mem_singleton.mp hr + subst reason + rfl + · intro h + have allReasons : ∀ reason, reason ∈ announcementPosition.reasons → reason (true,0) announcementPosition.adopted := by + intro reason hr + have hr' : reason = (fun (_ : BudgetWorld) (option : Bool) => announcement = (if option then "activate" else "disable")) := List.mem_singleton.mp hr + subst reason + rfl + have bad := h.2.2.1 (true,0) ((modelsSingleton _ _).2 rfl) trivial allReasons + cases bad.2 +/- A repeated actual selection observation contains no budget information. -/ +def actionRecord : Record BudgetWorld := ⟨Prod.fst, true⟩ +theorem actionCompatible (budget : Nat) : Compatible [actionRecord, actionRecord] (true,budget) := by + intro r hr; simp at hr; cases hr; rfl +/- Single and repeated irrelevant observations cannot establish the other outcome or the same action's budget adequacy. -/ +theorem measurementRepeatNotSupport : + temperatureRecord.test (true,false) = true ∧ + Compatible [temperatureRecord,temperatureRecord] (true,false) ∧ + Compatible [temperatureRecord,temperatureRecord] (true,true) ∧ + ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + Compatible [actionRecord,actionRecord] (true,0) ∧ + Compatible [actionRecord,actionRecord] (true,3) ∧ + ¬ Supports [actionRecord] announcementPosition.consequence ∧ + ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧ + ¬ ValueProcedure announcementPosition := by + refine ⟨rfl, temperatureCompatible false, temperatureCompatible true, ?_, ?_, + actionCompatible 0, actionCompatible 3, ?_, ?_, announcementNotBudgetReason.2.2.2.2⟩ + · intro h + have bad := h (true,false) (by intro r hr; simp only [List.mem_singleton] at hr; cases hr; rfl) + cases bad + · intro h; have bad := h (true,false) (temperatureCompatible false); cases bad + · intro h + have bad := h (true,0) (by intro r hr; simp only [List.mem_singleton] at hr; cases hr; rfl) + cases bad.2 + · intro h; have bad := h (true,0) (actionCompatible 0); cases bad.2 +/- Missing reason records fail a procedure; independently, a present announcement fails the explicit budget-support criterion. -/ +theorem selfAssertionNotReason : + (unsupportedPosition.commitment true ∧ ¬ ValueProcedure unsupportedPosition) ∧ + (announcementPosition.reasons ≠ [] ∧ announcementPosition.commitment (true,0) ∧ + ¬ announcementPosition.consequence (true,0) ∧ ¬ ValueProcedure announcementPosition) ∧ + JointAdoption announcementPosition := + ⟨⟨rfl, fun h => h.1 rfl⟩, + ⟨announcementNotBudgetReason.1, announcementNotBudgetReason.2.1, + announcementNotBudgetReason.2.2.2.1, announcementNotBudgetReason.2.2.2.2⟩, + announcementHasJointAdoption⟩ +/- The value procedure is satisfiable although the adopted starting commitment is not entailed by empty facts. -/ +theorem valueWithoutSelfProof : ValueProcedure switchPosition ∧ + Satisfiable switchPosition.starting ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧ + (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧ + (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition) := + ⟨switchValueProcedure, ⟨true, (modelsSingleton _ _).2 rfl⟩, consistentIncomplete.2.1, + oppositePositionRejected, inadmissibleValuePositionsRejected⟩ +/- The world records the selected option and its actual benefit/cost outcomes. -/ +abbrev BenefitCostWorld := Bool × (Nat × Nat) +def measuredOutcome (world : BenefitCostWorld) (option : Bool) : Nat × Nat := + if option then world.2 else (0,0) +def benefitReason (world : BenefitCostWorld) (option : Bool) : Prop := + (measuredOutcome world option).1 = 4 +def costReason (world : BenefitCostWorld) (option : Bool) : Prop := + (measuredOutcome world option).2 ≤ 3 +/- Neither recorded benefit nor recorded cost alone establishes the selected option's joint consequence. -/ +def jointReasonPosition : ValuePosition BenefitCostWorld where + Position := Bool + Outcome := Nat × Nat + adopted := true + selected := Prod.fst + outcome := measuredOutcome + objective := fun result => result.2 < result.1 + constraints := fun world option => (measuredOutcome world option).2 ≤ 3 + starting := singleton (fun world => world.1 = true) + reasons := [benefitReason, costReason] + limits := fun _ => True + relevantCriticism := fun world => 3 < world.2.2 + response := fun _ => some "reassess the option when its cost exceeds the budget" +/- These two content constraints jointly establish the consequence in a nonempty adopted world. -/ +theorem jointReasonProcedure : ValueProcedure jointReasonPosition := by + refine ⟨by simp [jointReasonPosition], ?_, ?_, ?_⟩ + · refine ⟨(true,(4,3)), (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩ + intro reason hr + change reason ∈ [benefitReason,costReason] at hr + rcases List.mem_cons.mp hr with hr | hr + · subst reason; rfl + · have hr' := List.mem_singleton.mp hr + subst reason + change 3 ≤ 3; exact Nat.le_refl 3 + · intro world _ _ reasons + have benefit := reasons benefitReason (by change benefitReason ∈ [benefitReason,costReason]; simp) + have cost := reasons costReason (by change costReason ∈ [benefitReason,costReason]; simp) + change (measuredOutcome world true).1 = 4 at benefit + change (measuredOutcome world true).2 ≤ 3 at cost + refine ⟨?_, cost⟩ + have bigger : 3 < (measuredOutcome world true).1 := by rw [benefit]; decide + exact Nat.lt_of_le_of_lt cost bigger + · intro world _ _ + exact ⟨"reassess the option when its cost exceeds the budget", rfl, by decide⟩ +/- Each separate reason has a concrete same-start/limit/adoption counterworld; their conjunction is sufficient. -/ +def JointReasonsExample : Prop := + ValueProcedure jointReasonPosition ∧ + (Models jointReasonPosition.starting (true,(4,5)) ∧ jointReasonPosition.limits (true,(4,5)) ∧ + jointReasonPosition.commitment (true,(4,5)) ∧ benefitReason (true,(4,5)) true ∧ + ¬ jointReasonPosition.consequence (true,(4,5))) ∧ + (Models jointReasonPosition.starting (true,(0,3)) ∧ jointReasonPosition.limits (true,(0,3)) ∧ + jointReasonPosition.commitment (true,(0,3)) ∧ costReason (true,(0,3)) true ∧ + ¬ jointReasonPosition.consequence (true,(0,3))) +theorem jointReasonsExample : JointReasonsExample := by + refine ⟨jointReasonProcedure, + ⟨(modelsSingleton _ _).2 rfl, trivial, rfl, rfl, ?_⟩, + ⟨(modelsSingleton _ _).2 rfl, trivial, rfl, Nat.le_refl 3, ?_⟩⟩ + · intro h; have bad : 5 ≤ 3 := h.2; omega + · intro h; have bad : 3 < 0 := h.1; omega +/- Empirical observations, semantic inference and criticism-responsive reasons coexist without a scalar score. -/ +theorem heterogeneousReasons : + FacetDischarged switchEmpirical ∧ + FacetDischarged (Facet.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) ∧ + FacetDischarged (Facet.value switchPosition) ∧ JointReasonsExample := by + refine ⟨switchEmpiricalDischarged, ⟨⟨true, (modelsSingleton _ _).2 rfl⟩, ?_⟩, switchValueProcedure, jointReasonsExample⟩ + intro w hw; exact (modelsSingleton (fun x : Bool => x = true) w).1 hw + +/- This local observation checks the actual output on input zero. -/ +def zeroRecord : Record (Nat → Bool) := ⟨fun f => f 0, true⟩ +def localGenerator (seed : Nat) : Nat → Bool := fun n => n == seed +/- All outputs being true is a stronger, explicitly quantified capability claim. -/ +def allTrue : Claim (Nat → Bool) := fun f => ∀ n, f n = true +theorem zeroCompatible (f : Nat → Bool) : Compatible [zeroRecord] f ↔ f 0 = true := by + constructor + · intro h; exact h zeroRecord (by simp) + · intro hf r hr; simp only [List.mem_singleton] at hr; cases hr; exact hf +/- A generating subject owns an earlier predicate and a seed used to revise that actual predicate. -/ +structure GeneratingProcess where + owner : Nat + prior : Nat → Bool + generateSeed : Nat +/- The revision preserves prior successes and adds the seed-selected case through the actual generator. -/ +def GeneratingProcess.outputRevision (process : GeneratingProcess) : Nat → Bool := + fun input => process.prior input || localGenerator process.generateSeed input +/- A produced revision retains its producer and exact old/new objects. -/ +structure ProducedRevision where + producer : Nat + before : Nat → Bool + after : Nat → Bool +/- The subject itself constructs the owned before/after revision object. -/ +def GeneratingProcess.produce (process : GeneratingProcess) : ProducedRevision := + ⟨process.owner, process.prior, process.outputRevision⟩ +def sampleGeneratingProcess : GeneratingProcess := ⟨17, fun _ => false, 0⟩ +/- This same-owner revision actually changes input zero, while its produced predicate still fails at input one. -/ +def OwnedRevisionExample : Prop := + sampleGeneratingProcess.produce.producer = sampleGeneratingProcess.owner ∧ + sampleGeneratingProcess.produce.before = sampleGeneratingProcess.prior ∧ + sampleGeneratingProcess.produce.after = sampleGeneratingProcess.outputRevision ∧ + sampleGeneratingProcess.produce.before 0 = false ∧ sampleGeneratingProcess.produce.after 0 = true ∧ + sampleGeneratingProcess.produce.after 1 = false ∧ + Compatible [zeroRecord] sampleGeneratingProcess.produce.after ∧ + ¬ Supports [zeroRecord] allTrue +/- Actual producer/old/new links and the compatible failing revision witness the insufficiency of self-origin. -/ +theorem ownedRevisionExample : OwnedRevisionExample := by + refine ⟨rfl,rfl,rfl,rfl,rfl,rfl,(zeroCompatible _).2 rfl, ?_⟩ + intro h + have bad := h sampleGeneratingProcess.produce.after ((zeroCompatible _).2 rfl) 1 + cases bad +/- The generator's own sample succeeds, but its generated revision has a concrete unsupported global claim. -/ +theorem selfOriginDoesNotSupport : + localGenerator 0 0 = true ∧ localGenerator 0 1 = false ∧ + Compatible [zeroRecord] (localGenerator 0) ∧ + ¬ Supports [zeroRecord] allTrue ∧ OwnedRevisionExample := by + refine ⟨rfl, rfl, (zeroCompatible _).2 rfl, ?_, ownedRevisionExample⟩ + intro h + have bad := h (localGenerator 0) ((zeroCompatible _).2 rfl) 1 + cases bad +/- A proper local observation allows both a universally successful and a failing extension. -/ +theorem localNotUniversal : + (∃ outside : Nat, outside ≠ 0) ∧ + Compatible [zeroRecord] (fun _ => true) ∧ + Compatible [zeroRecord] (localGenerator 0) ∧ + allTrue (fun _ => true) ∧ ¬ allTrue (localGenerator 0) ∧ + ¬ Supports [zeroRecord] allTrue := by + refine ⟨⟨1, by decide⟩, (zeroCompatible _).2 rfl, (zeroCompatible _).2 rfl, + (fun _ => rfl), ?_, selfOriginDoesNotSupport.2.2.2.1⟩ + intro h; have bad := h 1; cases bad +/- Two implementations agree on the actual observed input and differ on a specified relevant omitted input. -/ +theorem hiddenDifference : + (∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧ + (fun _ : Nat => true) 1 ≠ localGenerator 0 1 := by + refine ⟨?_, by decide⟩ + intro n hn; cases hn; rfl +/- One observation supplies only its actual input-specific consequence, without repetition. -/ +theorem singleObservation : [zeroRecord].length = 1 ∧ + (∃ f, Compatible [zeroRecord] f) ∧ + Supports [zeroRecord] (fun f => f 0 = true) ∧ + ¬ Supports [zeroRecord] allTrue := + ⟨rfl, ⟨localGenerator 0, (zeroCompatible _).2 rfl⟩, + (fun f hf => (zeroCompatible f).1 hf), selfOriginDoesNotSupport.2.2.2.1⟩ +/- This inferential assessment derives a successor value from its explicit numeric premise without observation. -/ +def arithmeticFacet : Facet Nat := .inferential (singleton (fun n => n = 2)) (fun n => n + 1 = 3) +def usesObservation {W : Type} : Facet W → Bool + | .empirical _ _ _ _ => true + | _ => false +/- An actual valid inferential assessment refutes a mandatory measurement/repetition/framework chain. -/ +theorem noUniversalChain : FacetDischarged arithmeticFacet ∧ usesObservation arithmeticFacet = false := by + refine ⟨⟨⟨2, (modelsSingleton _ _).2 rfl⟩, ?_⟩, rfl⟩ + intro n hn + have premise := (modelsSingleton (fun x : Nat => x = 2) n).1 hn + change n + 1 = 3 + rw [premise] +/- A trial has a reproducible setting, an actual outcome and a separately recorded outcome. -/ +structure Trial where + setting : Nat + actualOutcome : Nat + recordedOutcome : Nat +/- Verifying a record, reproducing settings and retaining a conclusion are separate predicates. -/ +def Verified (t : Trial) : Prop := t.recordedOutcome = t.actualOutcome +def Reproduced (a b : Trial) : Prop := a.setting = b.setting +def Bounded (t : Trial) : Prop := t.actualOutcome ≤ 2 +/- Same-setting possible trials can differ while preserving the chosen bound; no probability semantics is claimed. -/ +theorem variableOutcomesStableBound : + let a : Trial := ⟨0,1,1⟩ + let b : Trial := ⟨0,2,2⟩ + Reproduced a b ∧ a.actualOutcome ≠ b.actualOutcome ∧ Bounded a ∧ Bounded b := by + simp [Reproduced, Bounded] +/- Concrete records distinguish record accuracy, condition reproduction and conclusion stability. -/ +theorem verificationReproductionStability : + (Verified ⟨0,1,1⟩ ∧ Verified ⟨1,1,1⟩ ∧ ¬ Reproduced ⟨0,1,1⟩ ⟨1,1,1⟩) ∧ + (Reproduced ⟨0,1,1⟩ ⟨0,3,2⟩ ∧ ¬ Verified ⟨0,3,2⟩ ∧ ¬ Bounded ⟨0,3,2⟩) ∧ + (Bounded ⟨0,1,1⟩ ∧ Bounded ⟨0,2,0⟩ ∧ ¬ Verified ⟨0,2,0⟩) := by + simp [Verified, Reproduced, Bounded] +/- Explanation certificates are executable syntax for this same arithmetic process. -/ +inductive Program where + | doubleInput + | constant (value : Nat) +def Program.eval : Program → Nat → Nat + | .doubleInput, n => n + n + | .constant value, _ => value +/- A process exposes outputs and an explanation response, whose certificate can be checked against those outputs. -/ +structure Process where + output : Nat → Nat + explanation : Option Program +/- The output-only application contract checks every relevant input. -/ +def OutputContract (p : Process) : Prop := ∀ n, p.output n = n + n +/- The explanation application contract requires a provided certificate faithful to this very process. -/ +def ExplanationContract (p : Process) : Prop := + ∃ program, p.explanation = some program ∧ ∀ n, program.eval n = p.output n +/- This process produces doubled values but returns no explanatory certificate. -/ +def outputOnlyProcess : Process := ⟨fun n => n + n, none⟩ +def explainedProcess : Process := ⟨fun n => n + n, some .doubleInput⟩ +/- Object scope fixes the very process whose contract is assessed; contract inputs themselves still range over all naturals. -/ +def processScope (assessed : Process) : Theory Process := + singleton (fun candidate => candidate = assessed) +/- This inferential facet checks an explicit contract under exact process-identity assumptions. -/ +def processContractFacet (assessed : Process) (contract : Claim Process) : Facet Process := + .inferential (processScope assessed) contract +/- The scope's compatible interpretations are exactly this assessed process, not an unrelated substitute. -/ +theorem processScopeModels (assessed candidate : Process) : + Models (processScope assessed) candidate ↔ candidate = assessed := + modelsSingleton (fun process => process = assessed) candidate +/- A concrete contract proof supplies the facet's consequence for its scoped object. -/ +theorem processContractDischarged (assessed : Process) (contract : Claim Process) (proof : contract assessed) : + FacetDischarged (processContractFacet assessed contract) := by + refine ⟨⟨assessed,(processScopeModels _ _).2 rfl⟩, ?_⟩ + intro candidate hc + have same := (processScopeModels _ _).1 hc + subst candidate + exact proof +/- Scoped capability grounds include exact claim, object-specific assumptions, canonical articulation and actual assessment. -/ +def ProcessGrounds (assessed : Process) (contract : Claim Process) : Prop := + Grounds contract canonicalArticulation (fun facet => facet = processContractFacet assessed contract) + [processContractFacet assessed contract] +theorem processGrounds (assessed : Process) (contract : Claim Process) (proof : contract assessed) : + ProcessGrounds assessed contract := by + have discharged := processContractDischarged assessed contract proof + refine ⟨by simp, ?_, ?_⟩ + · intro facet hf; subst facet; exact List.mem_singleton.mpr rfl + · intro facet hf; have hf' := List.mem_singleton.mp hf; subst facet + exact ⟨rfl,canonicalArticulated _ discharged,canonicalFacetArticulated _,discharged⟩ +/- Universal output correctness here comes from the concrete program definition, not from an assumed capability label. -/ +theorem outputCorrectByEvaluation : OutputContract outputOnlyProcess := fun _ => rfl +/- This same process actually returns no explanation certificate. -/ +theorem outputOnlyNoExplanation : ¬ ExplanationContract outputOnlyProcess := by + rintro ⟨program,h,_⟩; cases h +/- The full application contract requires outputs and an explanation of that same process. -/ +def FullProcessContract (assessed : Process) : Prop := OutputContract assessed ∧ ExplanationContract assessed +/- Output-only grounds have the assessed process itself as a counterworld to the stronger contract. -/ +def OutputContractEvidence : Prop := + ProcessGrounds outputOnlyProcess OutputContract ∧ + Models (processScope outputOnlyProcess) outputOnlyProcess ∧ + ¬ Entails (processScope outputOnlyProcess) FullProcessContract +/- Existing output evidence does not supply the absent explanation for the same object and scope. -/ +theorem outputContractEvidence : OutputContractEvidence := by + refine ⟨processGrounds _ _ outputCorrectByEvaluation, (processScopeModels _ _).2 rfl, ?_⟩ + intro stronger + exact outputOnlyNoExplanation (stronger outputOnlyProcess ((processScopeModels _ _).2 rfl)).2 +/- Both actual application contracts have grounds and explicit object scopes; neither scope is empty. -/ +def ScopedApplicationEvidence : Prop := + ProcessGrounds outputOnlyProcess OutputContract ∧ + ProcessGrounds explainedProcess FullProcessContract ∧ + (∀ candidate, Models (processScope outputOnlyProcess) candidate ↔ candidate = outputOnlyProcess) ∧ + (∀ candidate, Models (processScope explainedProcess) candidate ↔ candidate = explainedProcess) ∧ + Satisfiable (processScope outputOnlyProcess) ∧ Satisfiable (processScope explainedProcess) +/- Concrete evaluation and a faithful double-input certificate establish the two differently scoped contracts. -/ +theorem scopedApplicationEvidence : ScopedApplicationEvidence := by + refine ⟨processGrounds _ _ outputCorrectByEvaluation, processGrounds _ _ ?_, + processScopeModels _,processScopeModels _,⟨_,(processScopeModels _ _).2 rfl⟩, + ⟨_,(processScopeModels _ _).2 rfl⟩⟩ + exact ⟨fun _ => rfl,⟨.doubleInput,rfl,fun _ => rfl⟩⟩ +/- Universal output correctness does not entail the explanation-requiring contract for the same process. -/ +theorem outputNotExplanation : OutputContract outputOnlyProcess ∧ + ¬ ExplanationContract outputOnlyProcess ∧ OutputContractEvidence := + ⟨outputCorrectByEvaluation, outputOnlyNoExplanation, outputContractEvidence⟩ +/- Applications may use distinct contracts, and a faithful certificate can satisfy the stronger one. -/ +theorem applicationContractsDiffer : + (OutputContract outputOnlyProcess ∧ ¬ (OutputContract outputOnlyProcess ∧ ExplanationContract outputOnlyProcess)) ∧ + (OutputContract explainedProcess ∧ ExplanationContract explainedProcess) ∧ + ScopedApplicationEvidence := + ⟨⟨outputCorrectByEvaluation, fun h => outputOnlyNoExplanation h.2⟩, + ⟨(fun _ => rfl), ⟨.doubleInput, rfl, fun _ => rfl⟩⟩, scopedApplicationEvidence⟩ +/- The assessor supplies a mathematical certificate; the process's own explanation response is unnecessary. -/ +structure ExternalCertificate (p : Process) where + assessorId : Nat + assessedId : Nat + distinctParticipants : assessorId ≠ assessedId + outputCorrect : ∀ n, p.output n = n + n +/- The external assessor 42 evaluates the specified process 7; the full output proof is constructed by evaluation. -/ +def externalOutputCertificate : ExternalCertificate outputOnlyProcess := + ⟨42,7,by decide,fun _ => rfl⟩ +/- An external certificate establishes the output contract without producing an internal explanation. -/ +theorem externalAssessment : + (∃ certificate : ExternalCertificate outputOnlyProcess, + certificate.assessorId = 42 ∧ certificate.assessedId = 7 ∧ + certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧ + ProcessGrounds outputOnlyProcess OutputContract ∧ + ¬ ExplanationContract outputOnlyProcess := + ⟨⟨externalOutputCertificate,rfl,rfl,externalOutputCertificate.distinctParticipants, + externalOutputCertificate.outputCorrect⟩, + processGrounds outputOnlyProcess OutputContract externalOutputCertificate.outputCorrect, + outputOnlyNoExplanation⟩ +/- This argument records concepts and actual premises for a semantic inference, separately from executable tests. -/ +def arithmeticArticulation : Articulation Nat := canonicalArticulation arithmeticFacet +/- A reasoned inferential assessment needs no observation method, while applicable empirical assessment retains observations. -/ +theorem nonExecutableAssessment : + Grounds (fun n : Nat => n + 1 = 3) canonicalArticulation (fun f => f = arithmeticFacet) [arithmeticFacet] ∧ + usesObservation arithmeticFacet = false ∧ + FacetDischarged switchEmpirical ∧ usesObservation switchEmpirical = true := by + refine ⟨⟨by simp, (by intro f hf; cases hf; simp), ?_⟩, rfl, switchEmpiricalDischarged, rfl⟩ + intro f hf; simp only [List.mem_singleton] at hf; cases hf + exact ⟨rfl, canonicalArticulated _ noUniversalChain.1, canonicalFacetArticulated _, noUniversalChain.1⟩ + +end CoreReader.Evidence +``` + + + + **L1** Import CoreReader.Logic, making its checked declarations available to this module; this line states no new philosophical result. + + + **L2** Import CoreReader.Agency, making its checked declarations available to this module; this line states no new philosophical result. + + + **L4** Open namespace CoreReader.Evidence so subsequent declarations receive this module-qualified name. + + + **L5** Make names from CoreReader.Logic available without qualification; this changes name resolution, not assumptions. + + + **L6** Make names from CoreReader.Agency available without qualification; this changes name resolution, not assumptions. + + + **L8** Document the intended scope of Record. The corresponding declaration concerns: A record packages a supplied Boolean test and its supplied observed result; provenance and measurement reliability are not fields. This comment is explanatory, not a proof premise. + + + **L9** Declare the data interface Record. A record packages a supplied Boolean test and its supplied observed result; provenance and measurement reliability are not fields. + + + **L10** Store a specified Boolean test that reads the actual represented world. + + + **L11** Store the observed Boolean outcome to which that test will be compared. + + + **L12** Document the intended scope of Compatible. The corresponding declaration concerns: A world is compatible when every listed test yields its recorded result. The empty record list admits every world. This comment is explanatory, not a proof premise. + + + **L13** Define Compatible. A world is compatible when every listed test yields its recorded result. The empty record list admits every world. + + + **L14** Require every listed record’s actual test at w to equal that record’s observed outcome. + + + **L15** Document the intended scope of Supports. The corresponding declaration concerns: Support means that the claim holds in every compatible modeled world. It is semantic entailment from records, not a statistical confidence measure. This comment is explanatory, not a proof premise. + + + **L16** Define Supports. Support means that the claim holds in every compatible modeled world. It is semantic entailment from records, not a statistical confidence measure. + + + **L17** Require the very claim to hold in every world compatible with all records; absent compatible worlds this implication alone can be vacuous. + + + **L18** Document the intended scope of Articulation. The corresponding declaration concerns: Packages concept strings, an assumption theory, a list of reason claims, and a scope/limits claim. This comment is explanatory, not a proof premise. + + + **L19** Declare the data interface Articulation. Packages concept strings, an assumption theory, a list of reason claims, and a scope/limits claim. + + + **L20** Store identifiable concept names; strings alone do not establish semantic adequacy. + + + **L21** Store the actual theory stated as the articulation’s assumptions. + + + **L22** Store reason contents as propositions about the same world type. + + + **L23** Store the actual application-limit predicate for those reasons. + + + **L24** Document the intended scope of Articulated. The corresponding declaration concerns: Checks only that concept and reason lists are nonempty; it does not establish truth, relevance, or a relation to the target claim. This comment is explanatory, not a proof premise. + + + **L25** Define Articulated. Checks only that concept and reason lists are nonempty; it does not establish truth, relevance, or a relation to the target claim. + + + **L26** Require nonempty concept and reason lists only; this procedural condition is weaker than matching, discharged Grounds. + + + **L27** Document the intended scope of ValuePosition. The corresponding declaration concerns: Represents an adopted option, selected option, option-indexed outcomes/reasons, objectives, constraints, starting theory, scope and criticism response; this is a disclosed application adapter. This comment is explanatory, not a proof premise. + + + **L28** Declare the data interface ValuePosition. Represents an adopted option, selected option, option-indexed outcomes/reasons, objectives, constraints, starting theory, scope and criticism response; this is a disclosed application adapter. + + + **L29** Supply the type of options among which this value position adopts one. + + + **L30** Supply the outcome type used to interpret the effects of each option. + + + **L31** Specify which option is adopted, separately from which option a world actually selects. + + + **L32** Read the actually selected option from each world. + + + **L33** Interpret the actual outcome of each option at each world, rather than storing an arbitrary support label. + + + **L34** State the adopted objective as a predicate on outcomes; its value authority is not proved by this field. + + + **L35** State the world- and option-specific constraints checked alongside the objective. + + + **L36** Store the starting theory; JointAdoption will require it to share a real model with adoption and reasons. + + + **L37** Store reasons parameterized by both world and option, so switching the adopted option changes the assessed reasons. + + + **L38** Specify the scope within which this value-assessment procedure claims its conclusions. + + + **L39** Identify which worlds present relevant criticism; this is an explicit application predicate. + + + **L40** Store an optional textual response at each world; its presence does not prove that the criticism is answered adequately. + + + **L41** Document the intended scope of ValuePosition.commitment. The corresponding declaration concerns: The commitment claim says the world selects this position's adopted option; it is no longer a freely relabeled separate claim field. This comment is explanatory, not a proof premise. + + + **L42** Define ValuePosition.commitment. The commitment claim says the world selects this position's adopted option; it is no longer a freely relabeled separate claim field. + + + **L43** Derive the commitment claim by equating actual selection with this very adopted option. + + + **L44** Document the intended scope of ValuePosition.consequence. The corresponding declaration concerns: Checks this adopted option's modeled outcome against its objective and constraints. This comment is explanatory, not a proof premise. + + + **L45** Define ValuePosition.consequence. Checks this adopted option's modeled outcome against its objective and constraints. + + + **L46** Derive the assessed consequence from this adopted option’s actual outcome satisfying the objective and its actual constraints. + + + **L47** Document the intended scope of ValuePosition.activeReasons. The corresponding declaration concerns: Specializes every option-indexed reason to the adopted option for articulation. This comment is explanatory, not a proof premise. + + + **L48** Define ValuePosition.activeReasons. Specializes every option-indexed reason to the adopted option for articulation. + + + **L49** Specialize each option-indexed reason to the adopted option to produce its actual articulated world predicate. + + + **L50** Document the intended scope of JointAdoption. The corresponding declaration concerns: Requires one world jointly modeling the starting theory, scope, actual adoption and all adopted-option reasons. This comment is explanatory, not a proof premise. + + + **L51** Define JointAdoption. Requires one world jointly modeling the starting theory, scope, actual adoption and all adopted-option reasons. + + + **L52** Require one common world for starting assumptions, application limits and actual adoption. + + + **L53** At that same witness, require every listed reason for that adopted option to hold together. + + + **L54** Document the intended scope of ValueProcedure. The corresponding declaration concerns: Requires nonempty reasons, a joint adoption witness, joint reasons supporting the option's consequence within starting assumptions/scope, and nonempty criticism responses. It does not prove ultimate value correctness. This comment is explanatory, not a proof premise. + + + **L55** Define ValueProcedure. Requires nonempty reasons, a joint adoption witness, joint reasons supporting the option's consequence within starting assumptions/scope, and nonempty criticism responses. It does not prove ultimate value correctness. + + + **L56** Begin ValueProcedure with nonempty reasons and the complete joint adoption witness. + + + **L57** For every world satisfying the actual starting theory and limits, impose the following conditional consequence requirement. + + + **L58** Use the conjunction of all reasons for the adopted option to imply its actual consequence; no individual-reason sufficiency requirement is imposed. + + + **L59** Within limits, every relevant criticism must receive a specified nonempty response; this checks recorded response, not persuasiveness. + + + **L60** Document the intended scope of Facet. The corresponding declaration concerns: Defines three distinct facet kinds with different discharge conditions. This comment is explanatory, not a proof premise. + + + **L61** Declare the alternatives Facet. Defines three distinct facet kinds with different discharge conditions. + + + **L62** An empirical facet stores actual test records together with its scope, conclusion and stated uncertainty predicate. + + + **L63** An inferential facet stores its actual premise theory and the conclusion to be entailed from it. + + + **L64** A value facet stores the entire option/outcome position, including its starting theory, reasons, limits and criticism response. + + + **L65** Document the intended scope of Facet.claim. The corresponding declaration concerns: Extracts the target claim of a facet, using the commitment rather than consequence for a value facet. This comment is explanatory, not a proof premise. + + + **L66** Define Facet.claim. Extracts the target claim of a facet, using the commitment rather than consequence for a value facet. + + + **L67** Read the empirical facet’s own conclusion p as its claim; records, scope and uncertainty remain assessment inputs. + + + **L68** Read the inferential facet’s own conclusion p as its claim, separately from its premise theory. + + + **L69** The value facet’s claim is actual selection equaling its own adopted option, derived through v.commitment. + + + **L70** Document the intended scope of FacetDischarged. The corresponding declaration concerns: Dispatches to a different check for each facet kind; these checks have different truth guarantees. This comment is explanatory, not a proof premise. + + + **L71** Define FacetDischarged. Dispatches to a different check for each facet kind; these checks have different truth guarantees. + + + **L72** Enter the empirical discharge case with this facet’s actual records, scope, conclusion p and uncertainty predicate. + + + **L73** For an empirical facet, require a world compatible with its records and inside its scope, excluding an empty empirical domain. + + + **L74** Require the records to support the scoped conclusion and the explicitly stated uncertainty predicate. + + + **L75** Inferential discharge requires a nonempty model of the actual assumptions and semantic entailment of p from those same assumptions. + + + **L76** Value discharge is exactly the declared ValueProcedure for that same position, not a proof of ultimate value adequacy. + + + **L77** Document the intended scope of FacetArticulated. The corresponding declaration concerns: Requires articulation fields to match the facet's own assumptions, reasons and limits; concept strings are not constrained here. This comment is explanatory, not a proof premise. + + + **L78** Define FacetArticulated. Requires articulation fields to match the facet's own assumptions, reasons and limits; concept strings are not constrained here. + + + **L79** In the empirical articulation case, read the actual records and scope whose assumptions/reasons/limits must match. + + + **L80** This empirical adapter equates articulated assumptions and reasons with actual record compatibility, and articulated limits with the empirical scope. + + + **L81** In the inferential case, use this facet’s actual assumption theory as the articulation’s reference. + + + **L82** This inferential adapter retains the exact premise theory, articulates its model condition as the reason, and uses unrestricted additional limits. + + + **L83** Require value articulation to use exactly this position’s starting theory, adopted-option active reasons and limits. + + + **L84** Document the intended scope of canonicalArticulation. The corresponding declaration concerns: Constructs field-aligned articulations by pattern matching; the fixed concept strings are descriptive labels. This comment is explanatory, not a proof premise. + + + **L85** Define canonicalArticulation. Constructs field-aligned articulations by pattern matching; the fixed concept strings are descriptive labels. + + + **L86** Construct the empirical canonical articulation from the actual record list and scope of the selected facet. + + + **L87** Construct empirical articulation naming test outcomes and conditions, using the actual compatibility claim as its premise/reason and the original scope as its limit. + + + **L88** Construct inferential canonical articulation from this facet’s actual premise theory. + + + **L89** Construct inferential articulation from the same theory and its actual model predicate, with no extra limit. + + + **L90** Construct the value articulation using the same complete position v. + + + **L91** Construct value articulation from the actual starting theory, adopted-option reasons and original limits. + + + **L92** Document the intended scope of canonicalFacetArticulated. The corresponding declaration concerns: Proves all canonical articulations have the required field alignment; no discharge hypothesis is needed for equality by construction. This comment is explanatory, not a proof premise. + + + **L93** State the checked result canonicalFacetArticulated. Proves all canonical articulations have the required field alignment; no discharge hypothesis is needed for equality by construction. + + + **L94** Assert that canonical articulation is semantically connected to this very facet; the proof checks each facet constructor. + + + **L95** Split the three facet constructors; each canonical articulation has exactly the assumptions, reasons and limits required by its matching branch, so all three equalities are reflexive. + + + **L96** Document the intended scope of canonicalArticulated. The corresponding declaration concerns: Given a discharged facet, proves its canonical concept/reason lists are nonempty. The value case uses the discharge premise's reason nonemptiness. This comment is explanatory, not a proof premise. + + + **L97** State the checked result canonicalArticulated. Given a discharged facet, proves its canonical concept/reason lists are nonempty. The value case uses the discharge premise's reason nonemptiness. + + + **L98** Given this facet’s discharge, require its canonical concepts and reasons to be nonempty. + + + **L99** Check canonical articulation separately for empirical, inferential and value facets. + + + **L100** In this empirical or inferential branch, the canonical concept and reason lists are explicitly nonempty; simplification verifies both articulation requirements. + + + **L101** In this empirical or inferential branch, the canonical concept and reason lists are explicitly nonempty; simplification verifies both articulation requirements. + + + **L102** For the value branch, the premise h is ValueProcedure v; its nonempty reasons must establish nonempty canonical active reasons. + + + **L103** For a value facet, supply nonempty canonical concepts and leave the nonempty active-reason obligation. + + + **L104** Use the discharged value procedure’s nonempty reasons; specializing them to the adopted option preserves nonemptiness. + + + **L105** Document the intended scope of Grounds. The corresponding declaration concerns: Grounds packages a nonempty facet list, coverage of a supplied applicability predicate, common claim identity, articulation presence/alignment, and every listed facet's discharge. It is not uniformly a truth certificate for the claim. This comment is explanatory, not a proof premise. + + + **L106** Define Grounds. Grounds packages a nonempty facet list, coverage of a supplied applicability predicate, common claim identity, articulation presence/alignment, and every listed facet's discharge. It is not uniformly a truth certificate for the claim. + + + **L107** Take actualApplicable independently of the finite list, so coverage is an explicit obligation rather than inferred from list membership. + + + **L108** Require a nonempty facet list and inclusion of every facet satisfying actualApplicable. + + + **L109** For every listed facet, require the exact claim and a nonempty articulation belonging to that facet. + + + **L110** Also require semantic matching to its actual premises/reasons/limits and discharge by its declared adapter. + + + **L111** Document the intended scope of AchievementAccountability. The corresponding declaration concerns: Defines achievement accountability as exactly the same Grounds predicate, with no additional execution or achievement proof. This comment is explanatory, not a proof premise. + + + **L112** Define AchievementAccountability. Defines achievement accountability as exactly the same Grounds predicate, with no additional execution or achievement proof. + + + **L113** Achievement accountability accepts the same actual-applicability predicate and facet list as Grounds. + + + **L114** Define accountability directly by Grounds for the very achievement claim; no extra universal observation requirement is added. + + + **L115** Document the intended scope of transitionAchievement. The corresponding declaration concerns: Defines achievement as understanding/construction expansion between the same modeled transition's before and after states. This comment is explanatory, not a proof premise. + + + **L116** Define transitionAchievement. Defines achievement as understanding/construction expansion between the same modeled transition's before and after states. + + + **L117** The achievement claim is actual expansion between the selected transition’s own before and after states. + + + **L118** Document the intended scope of transitionPerformanceRecord. The corresponding declaration concerns: Tests whether that after-state contains successor actually returning one at the transition input, within the two-transition model. This comment is explanatory, not a proof premise. + + + **L119** Define transitionPerformanceRecord. Tests whether that after-state contains successor actually returning one at the transition input, within the two-transition model. + + + **L120** The performance test inspects operations actually constructed in this transition’s after-state. + + + **L121** It records true only when successor is present and actually sends the shared transition input to 1. + + + **L122** Document the intended scope of transitionReportRecord. The corresponding declaration concerns: Records only the report's announced operation/input/output, not its actual achievement. This comment is explanatory, not a proof premise. + + + **L123** Define transitionReportRecord. Records only the report's announced operation/input/output, not its actual achievement. + + + **L124** Begin a record whose test reads the actual transition’s announcement. + + + **L125** Bind report to the announcement generated for this same transition. + + + **L126** Test its stated successor, input 0 and expected output 1, recording a positive announcement independently of whether the operation exists. + + + **L127** Document the intended scope of transitionPerformanceCompatible. The corresponding declaration concerns: Exhausts inflate/extend to show the actual performance record identifies extension. This comment is explanatory, not a proof premise. + + + **L128** State the checked result transitionPerformanceCompatible. Exhausts inflate/extend to show the actual performance record identifies extension. + + + **L129** Claim that matching the actual positive performance record is equivalent to selecting extend. + + + **L130** Fix an arbitrary actual transition, either inflate or extend, for the record-compatibility equivalence. + + + **L131** Prove both directions: performance compatibility implies extend, and extend supplies compatibility. + + + **L132** Assume this transition matches the actual positive performance record. + + + **L133** Apply compatibility to the actual singleton performance record to obtain its observed test result for this transition. + + + **L134** Split the actual transition into inflate and extend, whose after-states have different operation content. + + + **L135** The inflate state lacks successor, so its performance test cannot equal the recorded true outcome. + + + **L136** The extend case has the required transition identity by reflexivity. + + + **L137** For the reverse implication, substitute the assumption that the transition is extend. + + + **L138** Membership in the singleton record list identifies the arbitrary record with this exact transition record; substitute it before checking its test. + + + **L139** Evaluate the actual extend performance record; its successor-at-zero test equals the recorded true outcome. + + + **L140** Document the intended scope of transitionSupported. The corresponding declaration concerns: Uses performance identification, the concrete new operation and report claim to establish transition expansion in every compatible case. This comment is explanatory, not a proof premise. + + + **L141** State the checked result transitionSupported. Uses performance identification, the concrete new operation and report claim to establish transition expansion in every compatible case. The following tactic block proves this explicit type. + + + **L142** Take an arbitrary transition and its compatibility with the actual performance record; prove expansion for that same transition. + + + **L143** Use transitionPerformanceCompatible to identify every performance-compatible transition as extend. + + + **L144** Substitute extend for the transition, so the remaining achievement claim concerns its real extended after-state. + + + **L145** Check the same system-generated extend report against its actual before/after states: successor is newly constructed and sends input 0 to output 1. + + + **L146** Check the same system-generated extend report against its actual before/after states: successor is newly constructed and sends input 0 to output 1. + + + **L147** Check the same system-generated extend report against its actual before/after states: successor is newly constructed and sends input 0 to output 1. + + + **L148** Apply announcementClaimImpliesExpansion to the verified report content to obtain the same transition’s Expanded claim. + + + **L149** Document the intended scope of transitionFacet. The corresponding declaration concerns: Packages the performance record, input-zero scope and exact expansion claim as an empirical facet. This comment is explanatory, not a proof premise. + + + **L150** Define transitionFacet. Packages the performance record, input-zero scope and exact expansion claim as an empirical facet. + + + **L151** Build an empirical facet from the performance record with the exact input-0 transition scope. + + + **L152** Its conclusion is the same transition’s achievement; its uncertainty predicate is explicitly True. + + + **L153** Document the intended scope of transitionFacetDischarged. The corresponding declaration concerns: Supplies extension as a nonempty witness, actual support and trivial uncertainty. This comment is explanatory, not a proof premise. + + + **L154** State the checked result transitionFacetDischarged. Supplies extension as a nonempty witness, actual support and trivial uncertainty. The following tactic block proves this explicit type. + + + **L155** Provide extend as the nonempty empirical witness with compatible performance evidence and the shared input-0 scope; leave scoped support and uncertainty checks. + + + **L156** The already proved transition support supplies the achievement at any compatible transition, hence within the chosen scope. + + + **L157** The explicitly unrestricted uncertainty predicate is True, so this adapter component is immediate; no quantitative uncertainty bound is inferred. + + + **L158** Document the intended scope of transitionAccountable. The corresponding declaration concerns: Builds achievement Grounds with matching claim, scope, canonical articulation and discharged facet. This comment is explanatory, not a proof premise. + + + **L159** State the checked result transitionAccountable. Builds achievement Grounds with matching claim, scope, canonical articulation and discharged facet. + + + **L160** State accountability for the actual transition-achievement predicate with canonical articulation. + + + **L161** Declare transitionFacet the only applicable facet and use precisely that singleton evidence package. + + + **L162** Split accountability into nonempty facets, coverage of actual applicability, and matching articulated discharge for each included facet. + + + **L163** The applicability assumption identifies the facet with the one prescribed facet, which belongs to the singleton list. + + + **L164** Singleton membership identifies the current facet with the prescribed one; substitute it to check its exact claim and grounds. + + + **L165** Assemble identical claim, nonempty canonical articulation, its semantic connection to this facet, and transitionFacetDischarged. + + + **L166** Assemble identical claim, nonempty canonical articulation, its semantic connection to this facet, and transitionFacetDischarged. + + + **L167** Document the intended scope of transitionReportCompatible. The corresponding declaration concerns: Shows both transition cases produce the same announced operation/input/output record. This comment is explanatory, not a proof premise. + + + **L168** State the checked result transitionReportCompatible. Shows both transition cases produce the same announced operation/input/output record. + + + **L169** State that this transition’s positive report record is compatible with the transition itself, including inflate. + + + **L170** Membership in the singleton record list identifies the arbitrary record with this exact transition record; substitute it before checking its test. + + + **L171** The report test only checks the actual positive announcement contents, which evaluate identically for either transition. + + + **L172** Document the intended scope of transitionReportDoesNotSupport. The corresponding declaration concerns: Uses the inflated transition as a report-compatible non-achievement countermodel. This comment is explanatory, not a proof premise. + + + **L173** State the checked result transitionReportDoesNotSupport. Uses the inflated transition as a report-compatible non-achievement countermodel. + + + **L174** Require inflate to match the report while failing the same achievement predicate. + + + **L175** Conclude that the positive report records therefore do not support the achievement over all compatible transitions. + + + **L176** Unfold the inflate transition: both understood and constructed operation sets are unchanged, so no new-operation witness for Expanded exists. + + + **L177** Unfold the inflate transition: both understood and constructed operation sets are unchanged, so no new-operation witness for Expanded exists. + + + **L178** Combine positive-report compatibility with the false expansion claim at inflate; any claimed support applied there gives a contradiction. + + + **L179** Document the intended scope of ConcreteAchievementExample. The corresponding declaration concerns: Combines same-object achievement accountability and supported extension with an unsupported inflation report, preserving before/after/input identities. This comment is explanatory, not a proof premise. + + + **L180** Define ConcreteAchievementExample. Combines same-object achievement accountability and supported extension with an unsupported inflation report, preserving before/after/input identities. + + + **L181** The concrete example includes actual accountability for the transition achievement. + + + **L182** Its actual-applicability predicate and list identify the same single transition facet. + + + **L183** Require extend to satisfy the actual performance observation. + + + **L184** Require semantic support for the achievement and its truth at extend. + + + **L185** Also retain the report-compatible inflate world in which this achievement is false. + + + **L186** State the resulting failure of support from reports alone. + + + **L187** For every transition, bind the report’s before state to the actual transition-before state. + + + **L188** Bind its after state to that same transition’s actual after state. + + + **L189** Bind the report input to the actual transition input and explicitly fix that condition to 0. + + + **L190** Document the intended scope of concreteAchievementExample. The corresponding declaration concerns: Assembles the concrete performance support, reporting countermodel and exact state/input links. This comment is explanatory, not a proof premise. + + + **L191** State the checked result concreteAchievementExample. Assembles the concrete performance support, reporting countermodel and exact state/input links. The following tactic block proves this explicit type. + + + **L192** Assemble the actual achievement’s accountability, extend performance compatibility and semantic support in the concrete example. + + + **L193** Apply that same support to the extend witness to establish actual expansion there. + + + **L194** Include the report-compatible inflate counterexample and leave the same-before/after/input relationships. + + + **L195** For either transition, all report-to-state and input-0 links hold by the definitions themselves. + + + **L196** Document the intended scope of achievementNeedsSupport. The corresponding declaration concerns: Applies supplied compatible-world support to the arbitrary actual claim and separately includes the checked concrete transition example. This comment is explanatory, not a proof premise. + + + **L197** State the checked result achievementNeedsSupport. Applies supplied compatible-world support to the arbitrary actual claim and separately includes the checked concrete transition example. + + + **L198** Assume the chosen actual world matches all records and those records already support the achievement. + + + **L199** Conclude truth of the achievement at that actual world, together with the separately constructed concrete achievement example. + + + **L200** Apply the assumed support to the actual evidence-compatible world, and pair that local truth with the separately proved concrete achievement example. + + + **L201** Document the intended scope of supportWeakening. The corresponding declaration concerns: Preserves support when a supported claim implies a weaker claim at every world; it does not weaken the record set. This comment is explanatory, not a proof premise. + + + **L202** State the checked result supportWeakening. Preserves support when a supported claim implies a weaker claim at every world; it does not weaken the record set. + + + **L203** Assume support for p and a world-by-world implication from p to q; conclude support for q using the same records. + + + **L204** At each compatible world w, first derive p using the unchanged records, then apply the supplied implication weaker to obtain q. + + + **L205** Document the intended scope of evidenceWeakeningCanLoseSupport. The corresponding declaration concerns: Provides a true Boolean observation supporting equality to true and shows deleting that record loses this support. This comment is explanatory, not a proof premise. + + + **L206** State the checked result evidenceWeakeningCanLoseSupport. Provides a true Boolean observation supporting equality to true and shows deleting that record loses this support. + + + **L207** The single identity observation supports that the Boolean world is true. + + + **L208** Deleting that observation leaves empty records, which do not support the unchanged claim. + + + **L209** Split the supported one-record claim from the failure of the same claim after deleting that record. + + + **L210** Read the informative identity test from compatibility; it directly states that the Boolean world is true. + + + **L211** With no records, false is compatible; evaluating purported support there refutes the unchanged true-world claim. + + + **L212** Document the intended scope of scopeRestriction. The corresponding declaration concerns: Restricts a universally supported property from a wider input domain to an included narrower domain, for arbitrary world and input types. This comment is explanatory, not a proof premise. + + + **L213** State the checked result scopeRestriction. Restricts a universally supported property from a wider input domain to an included narrower domain, for arbitrary world and input types. + + + **L214** Take broad and narrow application domains and assume every narrow-domain input is in the broad domain. + + + **L215** Assume the same records support p at every input in the broad domain. + + + **L216** Conclude support at every input in the narrower domain; neither the evidence nor predicate p changes. + + + **L217** For a compatible world and narrow-domain input x, included converts narrow membership to broad membership; apply the original broad support there. + + + **L218** Document the intended scope of Duties. The corresponding declaration concerns: Requires every facet satisfying the supplied applicability predicate to be discharged. This comment is explanatory, not a proof premise. + + + **L219** Define Duties. Requires every facet satisfying the supplied applicability predicate to be discharged. + + + **L220** Require every actually applicable facet to pass its own discharge condition. + + + **L221** Define LabeledDuties. Defines labeled duties by ignoring all labels and keeping only the applicability-based duties. + + + **L222** Define labeled duties by exactly the original applicability duties; the labels supply no waiver. + + + **L223** Document the intended scope of assessmentUnion. The corresponding declaration concerns: Proves that discharging the union of two applicability predicates is equivalent to discharging each separately. This comment is explanatory, not a proof premise. + + + **L224** State the checked result assessmentUnion. Proves that discharging the union of two applicability predicates is equivalent to discharging each separately. + + + **L225** Equate duties for the union of two applicability predicates with fulfillment of both sets of duties. + + + **L226** Prove both directions between duty on the union applicability predicate and simultaneous duties on its two components. + + + **L227** Restrict the union duty to each applicable-facet predicate using the matching disjunction injection. + + + **L228** Unpack both duty sets, split actual applicability into its left/right case, and discharge that very facet using the corresponding duty. + + + **L229** Document the intended scope of labelsCannotWaive. The corresponding declaration concerns: Proves changing labels cannot change duties because labels were ignored by definition; no external classification mechanism is analyzed. This comment is explanatory, not a proof premise. + + + **L230** State the checked result labelsCannotWaive. Proves changing labels cannot change duties because labels were ignored by definition; no external classification mechanism is analyzed. + + + **L231** Changing only the label lists leaves the same duty proposition; the equivalence is reflexive. + + + **L232** Document the intended scope of switchRecord. The corresponding declaration concerns: Records the identity Boolean test with observed value true. This comment is explanatory, not a proof premise. + + + **L233** Define switchRecord. Records the identity Boolean test with observed value true. + + + **L234** State the checked result switchCompatible. Proves compatibility with the single switch record is exactly equality of the world with true. The following tactic block proves this explicit type. + + + **L235** Prove that compatibility with the singleton switch record is equivalent to the actual Boolean world being true. + + + **L236** Apply record compatibility to the sole named test to recover its actual observed equality. + + + **L237** Conversely, singleton membership identifies any listed record with this test, whose equality is the supplied observation premise. + + + **L238** State the checked result switchSupported. Supports equality to true by extracting the previously proved compatibility equivalence. The supplied proof term uses the displayed constructed witnesses or earlier lemmas, rather than adding an axiom. + + + **L239** Use switchCompatible’s forward implication to extract world=true from the same world’s actual record compatibility. + + + **L240** Document the intended scope of optionBenefit. The corresponding declaration concerns: Assigns benefit 4 to selected=true and 0 otherwise. This comment is explanatory, not a proof premise. + + + **L241** Define optionBenefit. Assigns benefit 4 to selected=true and 0 otherwise. + + + **L242** Define optionCost. Assigns cost 3 to selected=true and 0 otherwise. + + + **L243** Document the intended scope of optionReport. The corresponding declaration concerns: States option-specific cost and benefit facts rather than an unconnected reason flag. This comment is explanatory, not a proof premise. + + + **L244** Define optionReport. States option-specific cost and benefit facts rather than an unconnected reason flag. + + + **L245** The option report asserts actual cost at most 3 and the option-specific benefit of 4 for on or 0 for off. + + + **L246** Document the intended scope of switchPosition. The corresponding declaration concerns: Adopts true with actual option cost/benefit outcomes, cost-below-benefit objective, budget constraint and a scoped criticism response. This comment is explanatory, not a proof premise. + + + **L247** Define switchPosition. Adopts true with actual option cost/benefit outcomes, cost-below-benefit objective, budget constraint and a scoped criticism response. + + + **L248** Use Boolean options for on/off. + + + **L249** Represent each outcome as actual benefit and cost in a natural-number pair. + + + **L250** Adopt the on option explicitly; adoption itself is not derived from arithmetic. + + + **L251** Read the actual selected option directly from the Boolean world. + + + **L252** Compute benefit and cost from this same actual option. + + + **L253** Adopt the objective that actual benefit strictly exceeds actual cost. + + + **L254** Check the actual option cost against the fixed budget 3. + + + **L255** Assume the actual Boolean selection is on; do not insert the assessed benefit conclusion into the starting theory. + + + **L256** Use the option-indexed actual cost/benefit report as the sole reason. + + + **L257** Use an unrestricted world scope in this example; starting assumptions and reason content still constrain the procedure. + + + **L258** Mark the off-selected world as a relevant criticism case. + + + **L259** Provide distinct nonempty messages for the two worlds, including budget reconsideration in the criticism case. + + + **L260** State the checked result switchValueProcedure. Provides a consistent adoption witness and derives the adopted option's objective/constraint from its actual cost-benefit reason; both Boolean responses are checked. The following tactic block proves this explicit type. + + + **L261** Separate nonempty reasons, a joint adoption witness, consequence support by all reasons, and response to criticism for switchPosition. + + + **L262** Choose world true, satisfying the starting selection, unrestricted limit and adopted option, and leave its actual reason to check. + + + **L263** Take any reason in switchPosition’s list; the next step identifies its actual optionReport content at the adopted on witness. + + + **L264** Singleton membership identifies the arbitrary reason with optionReport specialized to this position’s adopted option; substitute that actual reason. + + + **L265** Singleton membership identifies the arbitrary reason with optionReport specialized to this position’s adopted option; substitute that actual reason. + + + **L266** Check that the adopted on option meets its recorded cost bound and its stated benefit value. + + + **L267** For an arbitrary world in the stated starting/limit conditions, assume the entire active-reason conjunction. + + + **L268** Extract the actual optionReport reason from that conjunction, rather than introducing an independent support label. + + + **L269** Unfold which option is adopted: this evidence concerns the on option. + + + **L270** Use the reported benefit equality to prove the on option’s benefit exceeds 3. + + + **L271** Combine cost ≤ 3 with benefit > 3 to prove cost < benefit, and retain the same cost bound as the constraint. + + + **L272** Check both Boolean worlds to provide the recorded nonempty criticism response where required. + + + **L273** Document the intended scope of oppositePosition. The corresponding declaration concerns: Changes the adopted option to false and updates its starting selection while retaining the same outcome model and objective. This comment is explanatory, not a proof premise. + + + **L274** Define oppositePosition. Changes the adopted option to false and updates its starting selection while retaining the same outcome model and objective. + + + **L275** Change both adopted option and starting selection to off while retaining the same actual outcome/reason interpretation. + + + **L276** Document the intended scope of oppositePositionRejected. The corresponding declaration concerns: Shows false can be jointly adopted but fails the unchanged cost-below-benefit objective, so its value procedure is rejected. This comment is explanatory, not a proof premise. + + + **L277** State the checked result oppositePositionRejected. Shows false can be jointly adopted but fails the unchanged cost-below-benefit objective, so its value procedure is rejected. The following tactic block proves this explicit type. + + + **L278** Construct an actual joint adoption witness for the opposite off position at world false; the rejection will therefore not rely on an empty domain. + + + **L279** Construct an actual joint adoption witness for the opposite off position at world false; the rejection will therefore not rely on an empty domain. + + + **L280** For the opposite position’s false-world witness, take any listed reason before checking that off option’s actual report. + + + **L281** Singleton membership identifies the arbitrary reason with optionReport specialized to this position’s adopted option; substitute that actual reason. + + + **L282** Singleton membership identifies the arbitrary reason with optionReport specialized to this position’s adopted option; substitute that actual reason. + + + **L283** The off option’s own report is true: its zero cost is within the bound and its zero benefit matches the stated report. + + + **L284** Retain the nonempty joint witness and separately refute fulfillment of the opposite value procedure. + + + **L285** Assume the opposite off position satisfies its entire ValueProcedure, to derive a contradiction with its zero-benefit outcome. + + + **L286** Assemble all of the opposite position’s reasons at its actual false-world witness before applying any consequence requirement. + + + **L287** Take any actual reason of the opposite position to assemble all reasons at its inhabited false-world counterexample. + + + **L288** Singleton membership identifies the arbitrary reason with optionReport specialized to this position’s adopted option; substitute that actual reason. + + + **L289** Singleton membership identifies the arbitrary reason with optionReport specialized to this position’s adopted option; substitute that actual reason. + + + **L290** The off option’s own report is true: its zero cost is within the bound and its zero benefit matches the stated report. + + + **L291** Apply the assumed opposite procedure’s joint-reason consequence clause to that same starting/limit witness and all its actual reasons. + + + **L292** Its purported objective would require the off option’s zero cost to be strictly less than its zero benefit, contradicting irreflexivity. + + + **L293** Document the intended scope of contradictoryStartingPosition. The corresponding declaration concerns: Replaces the starting theory with a false singleton, eliminating every joint adoption witness. This comment is explanatory, not a proof premise. + + + **L294** Define contradictoryStartingPosition. Replaces the starting theory with a false singleton, eliminating every joint adoption witness. + + + **L295** Replace the starting theory with the impossible singleton claim False. + + + **L296** Define impossibleAdoptionPosition. Always selects false while retaining adoption of true, making joint adoption impossible. + + + **L297** Keep the adopted on option but make every actual selection off, making joint adoption impossible. + + + **L298** Document the intended scope of inadmissibleValuePositionsRejected. The corresponding declaration concerns: Rejects both inconsistent starting theory and impossible adoption via the required witness. This comment is explanatory, not a proof premise. + + + **L299** State the checked result inadmissibleValuePositionsRejected. Rejects both inconsistent starting theory and impossible adoption via the required witness. + + + **L300** Reject the procedures for contradictory starting assumptions and impossible actual adoption separately. + + + **L301** Separate rejection of the contradictory starting theory from rejection of the impossible selected/adopted combination. + + + **L302** Extract a joint adoption witness from the alleged procedure for the contradictory starting position. + + + **L303** The singleton starting theory requires False at that witness, directly contradicting its model proof. + + + **L304** Extract the adoption equality from the alleged joint witness for the impossible selected/adopted combination. + + + **L305** The required adoption equality equates distinct Boolean options, so this witness cannot exist. + + + **L306** Document the intended scope of unsupportedPosition. The corresponding declaration concerns: Copies the switch value position but deletes its reasons, guaranteeing procedural failure. This comment is explanatory, not a proof premise. + + + **L307** Define unsupportedPosition. Copies the switch value position but deletes its reasons, guaranteeing procedural failure. + + + **L308** Define switchEmpirical. Builds an empirical facet concluding the Boolean world is true from the switch record, with unrestricted scope and trivially true uncertainty. + + + **L309** Use the actual switch observation, unrestricted scope and same selected-on claim; uncertainty is explicitly True. + + + **L310** State the checked result switchEmpiricalDischarged. Discharges that empirical facet with a true-world witness, semantic support, and trivial uncertainty. The following tactic block proves this explicit type. + + + **L311** Use true as a nonempty world compatible with the switch record and unrestricted empirical scope. + + + **L312** The same switch record’s semantic support proves the scoped switch claim at each compatible world. + + + **L313** Discharge the explicitly trivial uncertainty predicate, without adding an empirical confidence claim. + + + **L314** Document the intended scope of mixedMissingResponsibility. The corresponding declaration concerns: Shows a discharged empirical facet does not discharge a union of applicable facets when an included value facet has no reasons. This comment is explanatory, not a proof premise. + + + **L315** State the checked result mixedMissingResponsibility. Shows a discharged empirical facet does not discharge a union of applicable facets when an included value facet has no reasons. + + + **L316** Retain successful discharge of the actual empirical switch facet. + + + **L317** Deny all mixed duties even with empty labels, because the actual value facet also applies and lacks recorded reasons. + + + **L318** Keep the valid empirical switch facet and separately refute completion of all mixed duties. + + + **L319** Assume every actual mixed facet is discharged, including the value facet whose recorded reason list is empty. + + + **L320** Select the value facet from the actual applicability union and extract its required nonempty reason-list condition. + + + **L321** Its reason list is definitionally empty, contradicting only that recorded procedural requirement. + + + **L322** Document the intended scope of uninformativeArgument. The corresponding declaration concerns: Constructs a nonempty articulation with no assumptions and a tautological reason; it carries no information about the switch conclusion. This comment is explanatory, not a proof premise. + + + **L323** Define uninformativeArgument. Constructs a nonempty articulation with no assumptions and a tautological reason; it carries no information about the switch conclusion. + + + **L324** Articulate a switch concept with empty assumptions and a True reason; these nonempty words do not constrain the switch world. + + + **L325** State the checked result articulationNotSupport. Proves this articulation passes the nonemptiness check while its assumptions do not entail that the world is true. + + + **L326** The uninformative articulation’s actual assumptions do not entail that the world is true. + + + **L327** Pair nonempty but uninformative concepts/reasons with the empty theory’s established failure to entail the switch claim. + + + **L328** Pair nonempty but uninformative concepts/reasons with the empty theory’s established failure to entail the switch claim. + + + **L329** Document the intended scope of unrelatedArticulationRejected. The corresponding declaration concerns: Shows that a nonempty unrelated articulation and a discharged empirical facet need not align, and rejects this concrete pairing. This comment is explanatory, not a proof premise. + + + **L330** State the checked result unrelatedArticulationRejected. Shows that a nonempty unrelated articulation and a discharged empirical facet need not align, and rejects this concrete pairing. + + + **L331** Keep the unrelated articulation procedurally present and the switch facet actually discharged. + + + **L332** Still reject semantic matching between that unrelated articulation and this empirical facet. + + + **L333** Retain articulation and valid switch evidence, then separately test whether this unrelated articulation actually matches the facet. + + + **L334** Assume the uninformative articulation semantically matches switchEmpirical, despite its empty premise theory. + + + **L335** Evaluate the alleged equality of articulation assumptions and empirical compatibility assumptions on the compatibility claim itself. + + + **L336** The empirical singleton contains that compatibility claim, while the unrelated empty theory cannot; the alleged equality yields False. + + + **L337** Close this component of unrelatedArticulationRejected using the displayed local evidence or previously proved lemma; the component belongs to the following fixed result: Shows that a nonempty unrelated articulation and a discharged empirical facet need not align, and rejects this concrete pairing. + + + **L338** Document the intended scope of temperatureRecord. The corresponding declaration concerns: Records only the first coordinate of a Boolean pair, observed as true; the second coordinate is unmeasured. This comment is explanatory, not a proof premise. + + + **L339** Define temperatureRecord. Records only the first coordinate of a Boolean pair, observed as true; the second coordinate is unmeasured. + + + **L340** State the checked result temperatureCompatible. Shows duplicating that record remains compatible with either second-coordinate value when the first is true. + + + **L341** For any output coordinate b, repeated temperature records remain compatible with (true,b). + + + **L342** For either output coordinate b, singleton-style membership in the repeated list selects the same temperature test; its observed first coordinate is true and leaves b unconstrained. + + + **L343** For either output coordinate b, singleton-style membership in the repeated list selects the same temperature test; its observed first coordinate is true and leaves b unconstrained. + + + **L344** For either output coordinate b, singleton-style membership in the repeated list selects the same temperature test; its observed first coordinate is true and leaves b unconstrained. + + + **L345** For either output coordinate b, singleton-style membership in the repeated list selects the same temperature test; its observed first coordinate is true and leaves b unconstrained. + + + **L346** Document the intended scope of BudgetWorld. The corresponding declaration concerns: Uses a Boolean action coordinate and natural-number budget as the world type. This comment is explanatory, not a proof premise. + + + **L347** Introduce the type abbreviation BudgetWorld. Uses a Boolean action coordinate and natural-number budget as the world type. + + + **L348** Document the intended scope of announcement. The corresponding declaration concerns: Defines a fixed declaration string; its content is not linked to budget. This comment is explanatory, not a proof premise. + + + **L349** Define announcement. Defines a fixed declaration string; its content is not linked to budget. + + + **L350** Define announcementPosition. Uses an action announcement as the sole option-indexed reason while requiring actual benefit/cost and available budget. + + + **L351** Use Boolean options for on/off. + + + **L352** Represent each outcome as actual benefit and cost in a natural-number pair. + + + **L353** Adopt the on option explicitly; adoption itself is not derived from arithmetic. + + + **L354** Read actual selection from the first coordinate while leaving budget independently variable. + + + **L355** Compute benefit and cost from this same actual option. + + + **L356** Adopt the objective that actual benefit strictly exceeds actual cost. + + + **L357** Compare the adopted option’s actual cost with this world’s independently supplied budget. + + + **L358** Fix selection to on without any affordability or budget assumption. + + + **L359** Use the actual option-specific announcement text as the reason; it says nothing about available budget. + + + **L360** Use an unrestricted world scope in this example; starting assumptions and reason content still constrain the procedure. + + + **L361** Treat budget below 3 as relevant criticism of this cost-3 action. + + + **L362** Record a nonempty message about reconsidering the action when cost exceeds budget. + + + **L363** Document the intended scope of announcementHasJointAdoption. The corresponding declaration concerns: Constructs an action-true budget-zero world where the announcement reason holds; failure later is substantive, not absent adoption. This comment is explanatory, not a proof premise. + + + **L364** State the checked result announcementHasJointAdoption. Constructs an action-true budget-zero world where the announcement reason holds; failure later is substantive, not absent adoption. The following tactic block proves this explicit type. + + + **L365** Choose selected-on with budget 0 as a joint adoption witness; the starting theory fixes selection but does not assume affordability. + + + **L366** Take an arbitrary announcement reason at the selected-on, zero-budget joint witness. + + + **L367** Use membership to identify the actual reason as the option-indexed announcement text, then specialize it to the adopted on option. + + + **L368** Use membership to identify the actual reason as the option-indexed announcement text, then specialize it to the adopted on option. + + + **L369** Use membership to identify the actual reason as the option-indexed announcement text, then specialize it to the adopted on option. + + + **L370** The actual announcement equals the on option’s activation text; this proves the announcement reason, not the budget constraint. + + + **L371** Document the intended scope of announcementNotBudgetReason. The corresponding declaration concerns: At budget zero, the adopted action and true nonempty announcement reasons fail the real budget consequence, refuting the procedure. This comment is explanatory, not a proof premise. + + + **L372** State the checked result announcementNotBudgetReason. At budget zero, the adopted action and true nonempty announcement reasons fail the real budget consequence, refuting the procedure. + + + **L373** Require nonempty announcement reasons and actual adoption at selected-on with budget 0. + + + **L374** At that same zero-budget world, all actual announcement reasons hold. + + + **L375** Nevertheless reject the actual consequence and the whole value procedure. + + + **L376** Assemble nonempty announcement reasons and the true announcement; refute the zero-budget consequence and leave failure of the whole procedure. + + + **L377** For the claimed conjunction of reasons at budget 0, take any member of the actual announcement reason list. + + + **L378** Use membership to identify the actual reason as the option-indexed announcement text, then specialize it to the adopted on option. + + + **L379** Use membership to identify the actual reason as the option-indexed announcement text, then specialize it to the adopted on option. + + + **L380** The actual announcement equals the on option’s activation text; this proves the announcement reason, not the budget constraint. + + + **L381** Assume the announcement position satisfies ValueProcedure, to test its consequence clause at budget 0. + + + **L382** Collect every announcement reason at the same selected-on, zero-budget world. + + + **L383** To supply all reasons to that clause, take any announcement reason at the same zero-budget world. + + + **L384** Use membership to identify the actual reason as the option-indexed announcement text, then specialize it to the adopted on option. + + + **L385** Use membership to identify the actual reason as the option-indexed announcement text, then specialize it to the adopted on option. + + + **L386** The actual announcement equals the on option’s activation text; this proves the announcement reason, not the budget constraint. + + + **L387** Apply a hypothetical procedure to that inhabited zero-budget starting/limit case and its actual announcement reason. + + + **L388** The resulting cost constraint would require cost 3 within budget 0, which is impossible. + + + **L389** Document the intended scope of actionRecord. The corresponding declaration concerns: Records only the action Boolean, leaving budget completely unconstrained. This comment is explanatory, not a proof premise. + + + **L390** Define actionRecord. Records only the action Boolean, leaving budget completely unconstrained. + + + **L391** State the checked result actionCompatible. Shows two copies of the action record accept every budget when action=true. The following tactic block proves this explicit type. + + + **L392** Every action record in the repeated list tests only the actual selected-on coordinate, so any supplied budget remains compatible. + + + **L393** Document the intended scope of measurementRepeatNotSupport. The corresponding declaration concerns: Combines explicit countermodels showing that repeated measurement of one coordinate does not support an unmeasured coordinate or a budget consequence, and does not fix the announcement value procedure. This comment is explanatory, not a proof premise. + + + **L394** State the checked result measurementRepeatNotSupport. Combines explicit countermodels showing that repeated measurement of one coordinate does not support an unmeasured coordinate or a budget consequence, and does not fix the announcement value procedure. + + + **L395** The actual temperature test returns true even when the independent output coordinate is false. + + + **L396** Retain this false-output world under repeated temperature observations. + + + **L397** Also retain a true-output world under those same repeated observations. + + + **L398** A single temperature record does not support the other output being true. + + + **L399** Repeating that temperature record still does not support the other output being true. + + + **L400** Repeated observed activation is compatible with selected-on and budget 0. + + + **L401** The same repeated records are also compatible with budget 3. + + + **L402** A single activation record does not support the option’s actual objective-and-budget consequence. + + + **L403** Repeating activation records does not repair that lack of consequence support. + + + **L404** The announcement-based value procedure also fails for that actual option and constraint. + + + **L405** Record the observation’s actual true value and both temperature-compatible output alternatives; leave the unsupported output claims to refute. + + + **L406** Keep both budget-0 and budget-3 action-compatible worlds and the established announcement-procedure failure; leave affordability support claims to refute. + + + **L407** Assume a single temperature observation supports the independently represented second output being true. + + + **L408** Apply purported one-record output support to (true,false), whose temperature observation is true but whose other output claim is false. + + + **L409** Apply purported one-record output support to (true,false), whose temperature observation is true but whose other output claim is false. + + + **L410** The same (true,false) counterworld remains compatible with repeated temperature records, defeating repeated-data output support. + + + **L411** Assume a single action observation supports the adopted option’s benefit-and-budget consequence. + + + **L412** A single observed activation is compatible with budget 0; purported consequence support there would force the impossible cost constraint. + + + **L413** A single observed activation is compatible with budget 0; purported consequence support there would force the impossible cost constraint. + + + **L414** Repeating activation records retains the same zero-budget counterworld, so it still does not support the actual affordability consequence. + + + **L415** Document the intended scope of selfAssertionNotReason. The corresponding declaration concerns: Combines empty-reason and nonempty-but-budget-irrelevant self-assertion failures, with a joint adoption witness for the latter. This comment is explanatory, not a proof premise. + + + **L416** State the checked result selfAssertionNotReason. Combines empty-reason and nonempty-but-budget-irrelevant self-assertion failures, with a joint adoption witness for the latter. + + + **L417** The missing-reason position can be actually adopted yet fail its recorded procedure. + + + **L418** The stronger announcement example has nonempty reasons and actual adoption at budget 0. + + + **L419** Its actual consequence and its procedure still fail because the same adopted option exceeds budget. + + + **L420** Retain an actual joint adoption witness, excluding an empty-starting-domain explanation of this failure. + + + **L421** Prove unsupportedPosition.commitment true by reduction; a supposed ValueProcedure contradicts its empty reason list through its nonemptiness requirement. + + + **L422** Reuse the nonempty actual announcement reasons and adoption equality from announcementNotBudgetReason. + + + **L423** Also reuse failure of the same zero-budget consequence and of the entire announcement procedure. + + + **L424** Retain announcementHasJointAdoption so this failure is not explained by an empty or inconsistent starting domain. + + + **L425** Document the intended scope of valueWithoutSelfProof. The corresponding declaration concerns: Exhibits a coherent reasoned position not derivable from empty assumptions, and rejects opposite-option, inconsistent-start and impossible-adoption variants. This comment is explanatory, not a proof premise. + + + **L426** State the checked result valueWithoutSelfProof. Exhibits a coherent reasoned position not derivable from empty assumptions, and rejects opposite-option, inconsistent-start and impossible-adoption variants. + + + **L427** Require the switch position’s actual starting theory to have a model. + + + **L428** Deny derivation of its adopted commitment from the empty Boolean theory. + + + **L429** The opposite position has a joint witness but fails consequence assessment. + + + **L430** Also reject contradictory starting and impossible adoption variants, distinguishing non-self-derived from inconsistent starts. + + + **L431** Combine the actual switch procedure, world true as its starting model, and non-entailment of the adopted claim from emptyTheory. + + + **L432** Add rejection of the inhabited opposite option and the separate contradictory-start and impossible-adoption variants. + + + **L433** Document the intended scope of BenefitCostWorld. The corresponding declaration concerns: Stores a selected Boolean option together with variable benefit and cost values. This comment is explanatory, not a proof premise. + + + **L434** Introduce the type abbreviation BenefitCostWorld. Stores a selected Boolean option together with variable benefit and cost values. + + + **L435** Define measuredOutcome. For true, returns the world's benefit/cost pair; false has outcome zero/zero. + + + **L436** The on option reads the world’s actual benefit/cost pair; the off option yields (0,0). + + + **L437** Define benefitReason. Requires the same option's measured benefit to equal four. + + + **L438** The benefit reason requires the actual option’s measured benefit to equal 4. + + + **L439** Define costReason. Requires that option's measured cost to be at most three. + + + **L440** The cost reason requires the same option’s measured cost to be at most 3. + + + **L441** Document the intended scope of jointReasonPosition. The corresponding declaration concerns: Uses two separate option-specific benefit and cost reasons jointly for the adopted option's objective and budget. This comment is explanatory, not a proof premise. + + + **L442** Define jointReasonPosition. Uses two separate option-specific benefit and cost reasons jointly for the adopted option's objective and budget. + + + **L443** Use Boolean options for on/off. + + + **L444** Represent each outcome as actual benefit and cost in a natural-number pair. + + + **L445** Adopt the on option explicitly; adoption itself is not derived from arithmetic. + + + **L446** Read selection from the world’s first coordinate, separately from measured benefit and cost. + + + **L447** Use measuredOutcome so the assessed option’s actual benefit and cost come from this world. + + + **L448** Adopt the objective that actual benefit strictly exceeds actual cost. + + + **L449** Require this option’s measured cost to be at most 3. + + + **L450** Assume the selected option is on, without assuming benefit or cost conclusions. + + + **L451** List benefitReason and costReason together; the procedure will use their conjunction. + + + **L452** Use an unrestricted world scope in this example; starting assumptions and reason content still constrain the procedure. + + + **L453** Identify an actual measured cost above 3 as relevant criticism. + + + **L454** Record the nonempty response to reassess this option when its actual cost exceeds budget. + + + **L455** Document the intended scope of jointReasonProcedure. The corresponding declaration concerns: Builds a joint witness at benefit four/cost three and combines both reasons to prove cost below benefit and within budget. This comment is explanatory, not a proof premise. + + + **L456** State the checked result jointReasonProcedure. Builds a joint witness at benefit four/cost three and combines both reasons to prove cost below benefit and within budget. The following tactic block proves this explicit type. + + + **L457** Separate the joint-reason position’s nonempty reasons, joint witness, conjunction-based consequence and criticism response. + + + **L458** Use selected-on with benefit 4 and cost 3 as the common starting/limit/adoption witness. + + + **L459** Take any of the two reasons at the actual (true,(4,3)) witness, then split membership to check each distinct reason. + + + **L460** Expose the actual two-element reason list: benefitReason and costReason. + + + **L461** Split reason membership into the benefit reason or the remaining singleton cost reason. + + + **L462** Substitute the benefit reason and check that the witness’s measured benefit is exactly 4. + + + **L463** Identify the remaining reason with costReason and substitute it. + + + **L464** Identify the remaining reason with costReason and substitute it. + + + **L465** Check the witness’s cost bound 3 ≤ 3 by reflexivity of the natural-number order. + + + **L466** For an arbitrary admitted world, assume all active reasons together rather than requiring either reason alone to suffice. + + + **L467** Extract the actual benefitReason from the reason conjunction at this world and adopted option. + + + **L468** Extract costReason from the same conjunction at the same world and option. + + + **L469** Unfold benefitReason: the adopted on option’s measured benefit equals 4. + + + **L470** Unfold costReason: that same option’s measured cost is at most 3. + + + **L471** Retain the actual cost constraint and leave only the strict benefit-over-cost objective. + + + **L472** Rewrite the measured benefit to 4 and check that it exceeds 3. + + + **L473** Compose cost ≤ 3 with 3 < benefit to establish cost < benefit using both reasons. + + + **L474** For a world within limits where criticism is relevant, construct the required response about this option’s excessive cost. + + + **L475** Provide the explicit nonempty response about reassessing the option when its cost exceeds the budget; this records a response, not its persuasive adequacy. + + + **L476** Document the intended scope of JointReasonsExample. The corresponding declaration concerns: States that the joint procedure passes while either reason alone can hold at a world failing the consequence. This comment is explanatory, not a proof premise. + + + **L477** Define JointReasonsExample. States that the joint procedure passes while either reason alone can hold at a world failing the consequence. + + + **L478** Require the two-reason position to satisfy its complete ValueProcedure. + + + **L479** Fix a benefit-only counterworld (true,(4,5)) satisfying the same starting assumptions and limits. + + + **L480** At that world, actual adoption and the benefit reason both hold. + + + **L481** Deny the assessed consequence there, because its actual cost is too high. + + + **L482** Fix a cost-only counterworld (true,(0,3)) under the same starting assumptions and limits. + + + **L483** At this world, actual adoption and the cost reason hold. + + + **L484** Deny its assessed consequence because zero benefit does not exceed cost 3. + + + **L485** State the checked result jointReasonsExample. Uses benefit four/cost five and benefit zero/cost three as counterexamples to individual-reason sufficiency. The following tactic block proves this explicit type. + + + **L486** Begin the combined example with the already checked two-reason procedure. + + + **L487** Supply the benefit-only counterworld with benefit 4 and cost 5, satisfying the same starting, limit and adoption conditions. + + + **L488** Supply the cost-only counterworld with benefit 0 and cost 3 under the same conditions. + + + **L489** The benefit-only world violates the cost constraint 5 ≤ 3; natural-number arithmetic closes the contradiction. + + + **L490** The cost-only world cannot satisfy the strict objective 3 < 0; arithmetic closes this counterexample. + + + **L491** Document the intended scope of heterogeneousReasons. The corresponding declaration concerns: Combines empirical, inferential and value examples with a genuine two-reason combination that neither reason alone establishes. This comment is explanatory, not a proof premise. + + + **L492** State the checked result heterogeneousReasons. Combines empirical, inferential and value examples with a genuine two-reason combination that neither reason alone establishes. + + + **L493** Include the actually discharged empirical switch facet. + + + **L494** Include an inferential facet whose satisfiable true-world premise entails the same true-world claim. + + + **L495** Include the actual switch value procedure and the two-joint-reasons example in this registered theorem. + + + **L496** Combine the checked empirical facet, an inhabited inferential singleton, the value procedure and the joint-reason counterexamples. + + + **L497** For the inferential facet, its singleton premise directly yields the same true-world claim at any model. + + + **L499** Document the intended scope of zeroRecord. The corresponding declaration concerns: Records only a function's Boolean output at natural-number input zero. This comment is explanatory, not a proof premise. + + + **L500** Define zeroRecord. Records only a function's Boolean output at natural-number input zero. + + + **L501** Define localGenerator. Produces a function returning true exactly at its natural-number seed. + + + **L502** Document the intended scope of allTrue. The corresponding declaration concerns: Requires a Boolean-valued function to return true at every natural number. This comment is explanatory, not a proof premise. + + + **L503** Define allTrue. Requires a Boolean-valued function to return true at every natural number. + + + **L504** State the checked result zeroCompatible. Proves one zero-input record constrains exactly the function's value at zero. The following tactic block proves this explicit type. + + + **L505** Prove both directions between matching zeroRecord and the actual function returning true at input 0. + + + **L506** Apply record compatibility to the sole named test to recover its actual observed equality. + + + **L507** Conversely, singleton membership identifies any listed record with this test, whose equality is the supplied observation premise. + + + **L508** Document the intended scope of GeneratingProcess. The corresponding declaration concerns: Stores producer identity, the actual earlier predicate and the seed used by its revision algorithm. This comment is explanatory, not a proof premise. + + + **L509** Declare the data interface GeneratingProcess. Stores producer identity, the actual earlier predicate and the seed used by its revision algorithm. + + + **L510** Store the actual generating process owner identifier. + + + **L511** Store the prior Boolean-valued function before this process generates its revision. + + + **L512** Store the seed input used by this process’s actual local generator. + + + **L513** Document the intended scope of GeneratingProcess.outputRevision. The corresponding declaration concerns: Preserves prior successes and adds the seed-selected input through the actual local generator. This comment is explanatory, not a proof premise. + + + **L514** Define GeneratingProcess.outputRevision. Preserves prior successes and adds the seed-selected input through the actual local generator. + + + **L515** The revised function preserves each true prior output or adds truth at the actual generated seed input. + + + **L516** Document the intended scope of ProducedRevision. The corresponding declaration concerns: Stores producer plus exact before and after predicate objects. This comment is explanatory, not a proof premise. + + + **L517** Declare the data interface ProducedRevision. Stores producer plus exact before and after predicate objects. + + + **L518** Identify which owner produced this concrete revision object. + + + **L519** Store the actual before-function of the revision. + + + **L520** Store the actual after-function of the revision. + + + **L521** Document the intended scope of GeneratingProcess.produce. The corresponding declaration concerns: Constructs this process's own revision with its owner and actual prior/output functions. This comment is explanatory, not a proof premise. + + + **L522** Define GeneratingProcess.produce. Constructs this process's own revision with its owner and actual prior/output functions. + + + **L523** Construct the revision directly from this process’s owner, prior function and computed output revision. + + + **L524** Define sampleGeneratingProcess. Uses owner seventeen, an always-false prior predicate and seed zero. + + + **L525** Document the intended scope of OwnedRevisionExample. The corresponding declaration concerns: Binds self-origin and exact before/after functions to a real zero-input change whose global claim lacks support. This comment is explanatory, not a proof premise. + + + **L526** Define OwnedRevisionExample. Binds self-origin and exact before/after functions to a real zero-input change whose global claim lacks support. + + + **L527** Bind the revision’s producer identifier to the actual generating process owner. + + + **L528** Bind its before-function to this process’s actual prior function. + + + **L529** Bind its after-function to this process’s actual outputRevision. + + + **L530** Require actual change at input 0 from false before to true after. + + + **L531** Retain an actual false output at input 1 after that revision. + + + **L532** The actual produced after-function matches the input-0 observation. + + + **L533** That record still does not support the all-input truth claim. + + + **L534** Document the intended scope of ownedRevisionExample. The corresponding declaration concerns: Computes ownership/object links and uses the produced function's failure at one to refute universal support. This comment is explanatory, not a proof premise. + + + **L535** State the checked result ownedRevisionExample. Computes ownership/object links and uses the produced function's failure at one to refute universal support. The following tactic block proves this explicit type. + + + **L536** Check producer identity, prior/output revision relationships and actual sample values by computation; retain zero-record compatibility and leave universal support to refute. + + + **L537** Assume zeroRecord supports allTrue, to refute it using this owner’s actual produced revision. + + + **L538** Apply purported support to this owner’s actual produced after-function at input 1, where its revision still returns false. + + + **L539** Eliminate the resulting false=true equality; the actual revision is an evidence-compatible counterexample. + + + **L540** Document the intended scope of selfOriginDoesNotSupport. The corresponding declaration concerns: Retains the local observation countermodel and adds an actual owned before/after revision with the same unsupported global claim. This comment is explanatory, not a proof premise. + + + **L541** State the checked result selfOriginDoesNotSupport. Retains the local observation countermodel and adds an actual owned before/after revision with the same unsupported global claim. + + + **L542** Compute localGenerator 0 as true at 0 and false at 1. + + + **L543** Require this generated function to match the same input-0 record. + + + **L544** State failure of all-input support and include the concrete owner/prior/revision relationship example. + + + **L545** Compute the generated function’s values at 0 and 1, give its zero-record compatibility, and include the owned revision relationship example. + + + **L546** Assume the local zero observation entails true output at every input of every compatible function. + + + **L547** Instantiate alleged universal support with localGenerator 0 and then input 1; compatibility at 0 did not constrain this failing input. + + + **L548** Eliminate the resulting false=true equality; the actual revision is an evidence-compatible counterexample. + + + **L549** Document the intended scope of localNotUniversal. The corresponding declaration concerns: Exhibits both a universally true function and a zero-only true function compatible with the same observation, with an explicit outside input; therefore the observation does not support universal truth. This comment is explanatory, not a proof premise. + + + **L550** State the checked result localNotUniversal. Exhibits both a universally true function and a zero-only true function compatible with the same observation, with an explicit outside input; therefore the observation does not support universal truth. + + + **L551** Require at least one natural-number input outside the observed singleton scope. + + + **L552** The constant-true function matches the zero observation. + + + **L553** The local generator also matches that same observation. + + + **L554** The first function is universally true while the second is not. + + + **L555** Therefore the shared observation does not support universal truth. + + + **L556** Provide an input outside the observed scope and show both the constant-true function and local generator satisfy the same zero observation. + + + **L557** The constant function is universally true; retain the known support counterexample and leave the local generator’s universal claim to refute. + + + **L558** Evaluate any proposed all-input truth of the local generator at 1, where its actual result is false. + + + **L559** Document the intended scope of hiddenDifference. The corresponding declaration concerns: Shows the two functions agree on the domain restricted to zero and disagree at one; local agreement does not establish global equality. This comment is explanatory, not a proof premise. + + + **L560** State the checked result hiddenDifference. Shows the two functions agree on the domain restricted to zero and disagree at one; local agreement does not establish global equality. + + + **L561** State equality of both functions only for inputs satisfying n=0. + + + **L562** State their concrete output inequality at input 1. + + + **L563** Separate agreement on the input-0 scope from the concrete output difference at input 1. + + + **L564** Substitute n=0 from the scope premise; both functions then compute to true. + + + **L565** Document the intended scope of singleObservation. The corresponding declaration concerns: A single zero-input observation is nonvacuously compatible and supports its local result but does not support the all-input claim. This comment is explanatory, not a proof premise. + + + **L566** State the checked result singleObservation. A single zero-input observation is nonvacuously compatible and supports its local result but does not support the all-input claim. + + + **L567** Require an actual function compatible with the single observation, preventing empty evidence semantics. + + + **L568** That single record supports its actual input-0 claim. + + + **L569** It does not support the stronger all-input claim. + + + **L570** Compute the record count as one and provide localGenerator 0 as an actual compatible witness. + + + **L571** Extract the supported input-0 fact directly from compatibility and reuse the established failure of allTrue support. + + + **L572** Document the intended scope of arithmeticFacet. The corresponding declaration concerns: Defines an inferential facet with assumption n=2 and conclusion n+1=3. This comment is explanatory, not a proof premise. + + + **L573** Define arithmeticFacet. Defines an inferential facet with assumption n=2 and conclusion n+1=3. + + + **L574** Define usesObservation. Returns true only for empirical facet tags; this is a classification test, not an analysis of computational executability. + + + **L575** Classify an empirical facet as using observation because it carries actual test records. + + + **L576** Classify inferential and value facets as not using observation in this represented method classifier. + + + **L577** Document the intended scope of noUniversalChain. The corresponding declaration concerns: Discharges the arithmetic implication with a model n=2 while its observation tag is false. This is an example of nonempirical discharge, not a universal account of knowledge. This comment is explanatory, not a proof premise. + + + **L578** State the checked result noUniversalChain. Discharges the arithmetic implication with a model n=2 while its observation tag is false. This is an example of nonempirical discharge, not a universal account of knowledge. The following tactic block proves this explicit type. + + + **L579** Provide n=2 as the inferential theory’s nonempty witness and note that its facet constructor uses no observation. + + + **L580** Take any natural-number world n satisfying the arithmetic facet’s actual premise theory. + + + **L581** Extract n=2 from the actual singleton premise, rather than assuming the desired successor conclusion. + + + **L582** Expose the arithmetic conclusion n+1=3 as the remaining goal. + + + **L583** Rewrite n to 2 using the premise; the required arithmetic equality reduces by computation. + + + **L584** Document the intended scope of Trial. The corresponding declaration concerns: Stores setting, actual outcome and recorded outcome as independent natural-number fields, with no measurement mechanism. This comment is explanatory, not a proof premise. + + + **L585** Declare the data interface Trial. Stores setting, actual outcome and recorded outcome as independent natural-number fields, with no measurement mechanism. + + + **L586** Store the trial’s setting separately from its outcomes. + + + **L587** Store the trial’s actual outcome, whether accurately recorded or not. + + + **L588** Store the separately recorded outcome to allow accuracy comparisons. + + + **L589** Document the intended scope of Verified. The corresponding declaration concerns: Verification means exact equality of the two supplied outcome fields. This comment is explanatory, not a proof premise. + + + **L590** Define Verified. Verification means exact equality of the two supplied outcome fields. + + + **L591** Define Reproduced. Reproduction means only equality of two setting fields; it does not require matching outcomes or histories. + + + **L592** Define Bounded. The bound property is actualOutcome≤2, a fixed threshold rather than a general stability theory. + + + **L593** Document the intended scope of variableOutcomesStableBound. The corresponding declaration concerns: Exhibits matching settings with different actual outcomes that both satisfy the fixed upper bound. This comment is explanatory, not a proof premise. + + + **L594** State the checked result variableOutcomesStableBound. Exhibits matching settings with different actual outcomes that both satisfy the fixed upper bound. + + + **L595** Fix the first trial at setting 0 with actual and recorded outcome 1. + + + **L596** Fix the second trial at the same setting with actual and recorded outcome 2. + + + **L597** Require the two explicitly fixed trials to share settings, differ in actual outcomes and both satisfy actualOutcome ≤ 2. + + + **L598** Evaluate the two same-setting trials: actual outcomes 1 and 2 differ, but each satisfies actualOutcome ≤ 2. + + + **L599** Document the intended scope of verificationReproductionStability. The corresponding declaration concerns: Uses explicit numeric trials to separate recorded/actual agreement, equal settings, and the fixed outcome bound. This comment is explanatory, not a proof premise. + + + **L600** State the checked result verificationReproductionStability. Uses explicit numeric trials to separate recorded/actual agreement, equal settings, and the fixed outcome bound. + + + **L601** Require two accurately recorded trials whose settings nevertheless differ. + + + **L602** Require repeated settings alongside an inaccurate second record and an actual result exceeding the bound. + + + **L603** Require preserved bounds even though one recorded outcome is inaccurate. + + + **L604** Compute each concrete trial predicate separately, exhibiting changed settings, inaccurate recording and failure or preservation of the bound without conflating them. + + + **L605** Document the intended scope of Program. The corresponding declaration concerns: Defines a tiny program language with doubling and natural-number constants only. This comment is explanatory, not a proof premise. + + + **L606** Declare the alternatives Program. Defines a tiny program language with doubling and natural-number constants only. + + + **L607** Provide syntax for the explanation program that doubles its actual input. + + + **L608** Provide syntax for a constant-output explanation program carrying its returned natural number. + + + **L609** Define Program.eval. Defines the executable meaning of the two program constructors. + + + **L610** Evaluate the doubleInput explanation program at n by actual addition n+n. + + + **L611** Evaluate a constant program by returning its stored value, independently of the input. + + + **L612** Document the intended scope of Process. The corresponding declaration concerns: A process consists of an arbitrary natural-number function and an optional tiny-language explanation program. This comment is explanatory, not a proof premise. + + + **L613** Declare the data interface Process. A process consists of an arbitrary natural-number function and an optional tiny-language explanation program. + + + **L614** Store the same process’s actual output function over natural-number inputs. + + + **L615** Store the process’s optional supplied explanation program, separately from its output function. + + + **L616** Document the intended scope of OutputContract. The corresponding declaration concerns: Requires the output function to double every natural-number input. This comment is explanatory, not a proof premise. + + + **L617** Define OutputContract. Requires the output function to double every natural-number input. + + + **L618** Document the intended scope of ExplanationContract. The corresponding declaration concerns: Requires an attached program whose evaluated outputs equal the process output on every input; this is extensional agreement, not causal or human explanatory adequacy. This comment is explanatory, not a proof premise. + + + **L619** Define ExplanationContract. Requires an attached program whose evaluated outputs equal the process output on every input; this is extensional agreement, not causal or human explanatory adequacy. + + + **L620** Require an actually supplied program whose evaluation equals this process’s output at every natural input. + + + **L621** Document the intended scope of outputOnlyProcess. The corresponding declaration concerns: Constructs the correct doubling function without any attached explanation program. This comment is explanatory, not a proof premise. + + + **L622** Define outputOnlyProcess. Constructs the correct doubling function without any attached explanation program. + + + **L623** Define explainedProcess. Constructs the same output function with the doubling program attached. + + + **L624** Document the intended scope of processScope. The corresponding declaration concerns: Restricts modeled candidates to the exact assessed process, without restricting the contract's input quantifier. This comment is explanatory, not a proof premise. + + + **L625** Define processScope. Restricts modeled candidates to the exact assessed process, without restricting the contract's input quantifier. + + + **L626** Restrict theory models by the actual equality candidate=assessed, not by assuming the desired contract. + + + **L627** Document the intended scope of processContractFacet. The corresponding declaration concerns: Builds an inferential contract facet under the exact assessed-process identity assumption. This comment is explanatory, not a proof premise. + + + **L628** Define processContractFacet. Builds an inferential contract facet under the exact assessed-process identity assumption. + + + **L629** Build an inferential facet with that exact object-identity scope and the supplied contract conclusion. + + + **L630** Document the intended scope of processScopeModels. The corresponding declaration concerns: Proves that modeling the identity scope is exactly equality to the assessed process. This comment is explanatory, not a proof premise. + + + **L631** State the checked result processScopeModels. Proves that modeling the identity scope is exactly equality to the assessed process. + + + **L632** State that modeling this scope is exactly equality to the assessed process. + + + **L633** Instantiate modelsSingleton with equality to the actual assessed Process, proving exactly which candidates satisfy processScope. + + + **L634** Document the intended scope of processContractDischarged. The corresponding declaration concerns: Uses a supplied proof of the actual process contract and scope equality to discharge the corresponding inferential facet. This comment is explanatory, not a proof premise. + + + **L635** State the checked result processContractDischarged. Uses a supplied proof of the actual process contract and scope equality to discharge the corresponding inferential facet. + + + **L636** Conclude discharge for that same object’s contract facet using the explicit contract-proof premise. + + + **L637** Use the assessed process itself as a model of its identity scope; leave semantic entailment of its contract. + + + **L638** Take a candidate and proof hc that it lies in the actual assessed process’s identity scope. + + + **L639** From the scope model hc, recover that the candidate is exactly the assessed process. + + + **L640** Substitute that process identity so the contract goal is about the actual assessed object. + + + **L641** Use the explicit premise proof of this object’s contract; the generic helper does not create contract correctness without that premise. + + + **L642** Document the intended scope of ProcessGrounds. The corresponding declaration concerns: Requires canonical Grounds for this exact process/contract facet and its singleton applicability. This comment is explanatory, not a proof premise. + + + **L643** Define ProcessGrounds. Requires canonical Grounds for this exact process/contract facet and its singleton applicability. + + + **L644** Require Grounds for the supplied contract using canonical articulation and the exact assessed-process facet as applicable. + + + **L645** The listed evidence package contains precisely that same process-contract facet. + + + **L646** State the checked result processGrounds. Constructs matching contract Grounds from an actual proof for that same assessed process. + + + **L647** Conclude these same-object ProcessGrounds from the explicit proof of the contract at the assessed process. + + + **L648** Apply the contract-discharge helper to the explicit proof for this same assessed process. + + + **L649** Separate nonempty facets, exact applicability coverage and each facet’s claim/articulation/discharge obligations. + + + **L650** The applicability assumption identifies the facet with the one prescribed facet, which belongs to the singleton list. + + + **L651** Singleton membership identifies the current facet with the prescribed one; substitute it to check its exact claim and grounds. + + + **L652** Assemble the same contract claim, nonempty canonical articulation, semantic connection to the object scope and the established discharge. + + + **L653** Document the intended scope of outputCorrectByEvaluation. The corresponding declaration concerns: Proves all-input doubling directly from the concrete output function, not an assumed success flag. This comment is explanatory, not a proof premise. + + + **L654** State the checked result outputCorrectByEvaluation. Proves all-input doubling directly from the concrete output function, not an assumed success flag. The supplied proof term uses the displayed constructed witnesses or earlier lemmas, rather than adding an axiom. + + + **L655** Document the intended scope of outputOnlyNoExplanation. The corresponding declaration concerns: Rejects an attached explanation witness because the same process stores none. This comment is explanatory, not a proof premise. + + + **L656** State the checked result outputOnlyNoExplanation. Rejects an attached explanation witness because the same process stores none. The following tactic block proves this explicit type. + + + **L657** Any explanation contract would supply a program whose some value equals the process’s actual none response; distinct option constructors make that impossible. + + + **L658** Document the intended scope of FullProcessContract. The corresponding declaration concerns: Conjoins output correctness with an attached output-faithful explanation for the same process. This comment is explanatory, not a proof premise. + + + **L659** Define FullProcessContract. Conjoins output correctness with an attached output-faithful explanation for the same process. + + + **L660** Document the intended scope of OutputContractEvidence. The corresponding declaration concerns: Combines grounded output and a nonempty exact-process scope whose model refutes the stronger full contract. This comment is explanatory, not a proof premise. + + + **L661** Define OutputContractEvidence. Combines grounded output and a nonempty exact-process scope whose model refutes the stronger full contract. + + + **L662** Require grounded output correctness for the actual output-only process. + + + **L663** Keep that process itself as an inhabitant of the exact assessment scope. + + + **L664** Deny that this same scope entails the stronger output-plus-explanation contract. + + + **L665** Document the intended scope of outputContractEvidence. The corresponding declaration concerns: Builds output Grounds by evaluation and uses the missing explanation at the same process to refute full-contract entailment. This comment is explanatory, not a proof premise. + + + **L666** State the checked result outputContractEvidence. Builds output Grounds by evaluation and uses the missing explanation at the same process to refute full-contract entailment. The following tactic block proves this explicit type. + + + **L667** Supply the actual output contract’s grounds and the process’s own scope witness, then refute the stronger contract under that very scope. + + + **L668** Assume that this exact process scope entails the stronger output-plus-explanation contract. + + + **L669** Instantiate alleged full-contract entailment at outputOnlyProcess itself; its explanation component contradicts the proven absent explanation. + + + **L670** Document the intended scope of ScopedApplicationEvidence. The corresponding declaration concerns: Requires both different application contracts to have Grounds and nonempty exact-process scopes. This comment is explanatory, not a proof premise. + + + **L671** Define ScopedApplicationEvidence. Requires both different application contracts to have Grounds and nonempty exact-process scopes. + + + **L672** Include grounded output correctness for outputOnlyProcess. + + + **L673** Include grounded output and explanation together for explainedProcess. + + + **L674** Make the first scope’s exact identity with outputOnlyProcess explicit for every candidate. + + + **L675** Likewise make the second scope’s exact identity with explainedProcess explicit. + + + **L676** Require both actual process-identity theories to be satisfiable. + + + **L677** Document the intended scope of scopedApplicationEvidence. The corresponding declaration concerns: Supplies actual all-input output proofs and the doubling explanation program for the stronger contract. This comment is explanatory, not a proof premise. + + + **L678** State the checked result scopedApplicationEvidence. Supplies actual all-input output proofs and the doubling explanation program for the stronger contract. The following tactic block proves this explicit type. + + + **L679** Construct output-only grounds by evaluation and reserve the explained process’s stronger contract proof. + + + **L680** Provide exact process-identity scope equivalences and each process itself as a nonempty scope witness. + + + **L681** Provide exact process-identity scope equivalences and each process itself as a nonempty scope witness. + + + **L682** For explainedProcess, prove every doubled output by reflexivity and supply doubleInput as an actual provided, extensionally faithful explanation program. + + + **L683** Document the intended scope of outputNotExplanation. The corresponding declaration concerns: Proves output correctness with no attached explanation and includes the corresponding same-object Grounds/countermodel evidence. This comment is explanatory, not a proof premise. + + + **L684** State the checked result outputNotExplanation. Proves output correctness with no attached explanation and includes the corresponding same-object Grounds/countermodel evidence. + + + **L685** Retain absence of this process’s explanation contract together with its scoped output evidence. + + + **L686** Combine actual output correctness, the same process’s absence of an explanation, and its matched scoped output evidence. + + + **L687** Document the intended scope of applicationContractsDiffer. The corresponding declaration concerns: Shows output-only evidence fails the stronger contract, while the explained process satisfies both; both applications carry their own Grounds. This comment is explanatory, not a proof premise. + + + **L688** State the checked result applicationContractsDiffer. Shows output-only evidence fails the stronger contract, while the explained process satisfies both; both applications carry their own Grounds. + + + **L689** The output-only process meets output correctness but fails the combined output-and-explanation contract. + + + **L690** The explained process meets both actual contracts. + + + **L691** Include the explicit scoped grounds and nonempty witnesses for both application contracts. + + + **L692** For outputOnlyProcess, supply actual output correctness and refute any joint contract by projecting its impossible explanation component. + + + **L693** For explainedProcess, compute all doubled outputs, supply faithful doubleInput syntax, and include both contracts’ matched scoped grounds. + + + **L694** Document the intended scope of ExternalCertificate. The corresponding declaration concerns: Binds output-correctness proof to the exact process and distinct assessor/assessed identifiers; it is a mathematical role model, not authenticated real provenance. This comment is explanatory, not a proof premise. + + + **L695** Declare the data interface ExternalCertificate. Binds output-correctness proof to the exact process and distinct assessor/assessed identifiers; it is a mathematical role model, not authenticated real provenance. + + + **L696** Store the external assessor’s identifier. + + + **L697** Store the assessed participant’s identifier; the certificate type already fixes the assessed Process. + + + **L698** Require distinct participant identifiers as an explicit certificate field. + + + **L699** Require a proof of this very process’s doubled output for every input; a generic certificate assumes this field, while the concrete certificate constructs it. + + + **L700** Document the intended scope of externalOutputCertificate. The corresponding declaration concerns: Constructs assessor forty-two's proof for assessed object seven by actual output evaluation. This comment is explanatory, not a proof premise. + + + **L701** Define externalOutputCertificate. Constructs assessor forty-two's proof for assessed object seven by actual output evaluation. + + + **L702** Construct participants 42 and 7, compute their inequality, and prove every doubled output by reflexivity of the actual program. + + + **L703** Document the intended scope of externalAssessment. The corresponding declaration concerns: Uses a distinct-participant certificate to supply matching output Grounds while the assessed process still returns no explanation. This comment is explanatory, not a proof premise. + + + **L704** State the checked result externalAssessment. Uses a distinct-participant certificate to supply matching output Grounds while the assessed process still returns no explanation. + + + **L705** Require an actual external certificate indexed by outputOnlyProcess. + + + **L706** Identify its assessor as 42 and assessed participant as 7. + + + **L707** Require their distinction and actual output correctness of the same process. + + + **L708** Also retain matched ProcessGrounds for that same output contract. + + + **L709** Still deny an internal explanation contract for that actual process. + + + **L710** Use the actual externalOutputCertificate with fixed participants 42 and 7 and its proved participant distinction. + + + **L711** Take universal output correctness from that concrete certificate, whose proof was constructed from the actual program. + + + **L712** Build matching ProcessGrounds for the very outputOnlyProcess using that same concrete output proof. + + + **L713** Retain outputOnlyNoExplanation, so the external certificate does not assert an internal explanation exists. + + + **L714** Document the intended scope of arithmeticArticulation. The corresponding declaration concerns: Names the canonical articulation of the arithmetic inferential facet. This comment is explanatory, not a proof premise. + + + **L715** Define arithmeticArticulation. Names the canonical articulation of the arithmetic inferential facet. + + + **L716** Document the intended scope of nonExecutableAssessment. The corresponding declaration concerns: Constructs Grounds for the arithmetic conditional facet and distinguishes its nonempirical tag from a discharged empirical switch facet. The tag does not establish noncomputability. This comment is explanatory, not a proof premise. + + + **L717** State the checked result nonExecutableAssessment. Constructs Grounds for the arithmetic conditional facet and distinguishes its nonempirical tag from a discharged empirical switch facet. The tag does not establish noncomputability. + + + **L718** Require matched canonical Grounds for n+1=3 using precisely arithmeticFacet. + + + **L719** Specify that this inferential facet uses no observation. + + + **L720** At the same time, include an actually discharged empirical facet that does use observation. + + + **L721** Build the arithmetic claim’s nonempty, applicability-covered Grounds, retain its no-observation classification, and include the valid observed switch facet. + + + **L722** Singleton membership fixes the assessed facet to arithmeticFacet, so its specific assumptions and conclusion must be checked. + + + **L723** Use the same arithmetic facet’s proven discharge with canonical nonempty articulation and its exact semantic connection. + + + **L725** Close namespace CoreReader.Evidence; this adds no proof or premise. + + +### `leanified/CoreReader/Integration.lean` + + +```lean +import CoreReader.Agency +import CoreReader.Choice + +namespace CoreReader.Integration +open CoreReader.Logic CoreReader.Evidence CoreReader.Agency CoreReader.Choice + +/- Canonical articulation preserves the actual assessment contents of each facet. -/ +theorem canonicalGrounds {W : Type} (claim : Claim W) (facets : List (Facet W)) + (hne : facets ≠ []) (checked : ∀ f ∈ facets, f.claim = claim ∧ FacetDischarged f) : + Grounds claim canonicalArticulation (fun f => f ∈ facets) facets := by + exact ⟨hne, fun _ h => h, fun f hf => + ⟨(checked f hf).1, canonicalArticulated f (checked f hf).2, + canonicalFacetArticulated f, (checked f hf).2⟩⟩ + +theorem canonicalGroundsForSingleton {W : Type} (f : Facet W) (checked : FacetDischarged f) : + Grounds f.claim canonicalArticulation (fun g => g = f) [f] := by + refine ⟨by simp, (by intro g hg; cases hg; simp), ?_⟩ + intro g hg + simp only [List.mem_singleton] at hg + subst g + exact ⟨rfl, canonicalArticulated f checked, canonicalFacetArticulated f, checked⟩ + +/- A mode selects whether a system applies or waives the modeled governance rule. -/ +inductive Mode | apply | waive + deriving DecidableEq, Repr + +/- The four hypotheses vary algorithm and governance independently for the same assessed system. -/ +abbrev World := Candidate × Mode + +def actual : World := (.identity, .apply) + +/- A method's form and its possible executable realizations belong to one object. -/ +structure Method where + form : Form + realize : World → Implementation + +/- System fields identify the owner, its method, its current principle form, policy and work. -/ +structure System where + owner : Nat + method : Method + principleForm : Form + governance : World → Mode + requirements : Requirements + +def policyFor : Mode → Policy + | .apply => openPolicy + | .waive => neutralPolicy + +def workFor (owner : Nat) : Mode → List WorkRecord + | .apply => completeOwnWork owner + | .waive => [] + +def System.policy (s : System) (w : World) : Policy := policyFor (s.governance w) +def System.rules (s : System) (_w : World) : List Principle := ownRules s.owner +def System.work (s : System) (w : World) : List WorkRecord := workFor s.owner (s.governance w) + +def actualSystem : System where + owner := 0 + method := ⟨⟨.method, 0⟩, fun w => implementation w.1⟩ + principleForm := ⟨.principle, 0⟩ + governance := Prod.snd + requirements := identityRequirements + +def systemCapability (s : System) : Claim World := + fun w => ∀ n, s.requirements.inputs n → (s.method.realize w).run n = s.requirements.expected n + +def systemBudget (s : System) : Claim World := + fun w => (s.method.realize w).cost ≤ s.requirements.budget + +def systemObservation (s : System) : Record World := + ⟨fun w => decide ((s.method.realize w).run 0 = s.requirements.expected 0), true⟩ + +def systemHeld (s : System) : Theory World := + union (singleton (systemCapability s)) (singleton (systemBudget s)) + +inductive Question | correctOutput | affordable + deriving DecidableEq, Repr + +def systemContext (s : System) : Context World Question := + ⟨singleton (Compatible [systemObservation s]), + (fun q => match q with | .correctOutput => systemCapability s | .affordable => systemBudget s), + fun w => (s.method.realize w).domain 0 ∧ w.2 = .apply⟩ + +abbrev capability := systemCapability actualSystem +abbrev observation := systemObservation actualSystem +abbrev held := systemHeld actualSystem +abbrev context := systemContext actualSystem + +/- The output observation identifies the algorithm, without identifying its independently varied governance mode. -/ +theorem observationIdentifies (w : World) : Compatible [observation] w ↔ w.1 = .identity := by + rcases w with ⟨candidate, mode⟩ + cases candidate <;> simp [Compatible, observation, systemObservation, actualSystem, + implementation, identityRequirements, identityImpl, successorImpl] + +theorem capabilityActual : capability actual := fun _ _ => rfl + +theorem observedCapability : Supports [observation] capability := by + intro w hw + have hid := (observationIdentifies w).1 hw + rcases w with ⟨candidate, mode⟩ + change candidate = .identity at hid + subst candidate + exact fun _ _ => rfl + +def capabilityFacet : Facet World := .empirical [observation] (fun _ => True) capability (fun _ => True) + +theorem capabilityFacetChecked : FacetDischarged capabilityFacet := by + exact ⟨⟨actual, (observationIdentifies actual).2 rfl, trivial⟩, + (fun w hw _ => observedCapability w hw), fun _ _ => trivial⟩ + +theorem capabilityGrounds : Grounds capability canonicalArticulation + (fun f => f = capabilityFacet) [capabilityFacet] := + canonicalGroundsForSingleton capabilityFacet capabilityFacetChecked + +theorem actualAdmissible : Admissible held context actual := by + refine ⟨(modelsUnion _ _ _).2 ⟨(modelsSingleton _ _).2 capabilityActual, + (modelsSingleton _ _).2 (by change 1 ≤ 1; decide)⟩, + (modelsSingleton _ _).2 ((observationIdentifies actual).2 rfl), trivial, rfl⟩ + +theorem jointConsistent : Consistent held context := + consequenceConsistency held context ⟨actual, actualAdmissible⟩ + +/- The current method/principle forms, judgments, rules and own work are read from this very system and world. -/ +def Charter (s : System) (w : World) : Prop := + Generative (s.policy w) ∧ Consistent (systemHeld s) (systemContext s) ∧ + Reflexive s.owner (s.rules w) (s.work w) ∧ + (s.policy w).current s.method.form ∧ (s.policy w).current s.principleForm + +theorem charterChecked : Charter actualSystem actual := + ⟨⟨Or.inl rfl, fun _ _ => trivial⟩, jointConsistent, completeOwnWork_reflexive 0, rfl, rfl⟩ + +/- Revision adds a supported input-specific assertion about the same system's realized method. -/ +def revisedHeld : Theory World := union held + (singleton (fun w => (actualSystem.method.realize w).run 0 = actualSystem.requirements.expected 0)) + +def initialSnapshot : Snapshot World Question := ⟨held, context, 0⟩ +def revisedSnapshot : Snapshot World Question := ⟨revisedHeld, context, 1⟩ + +theorem revisionKeepsConsistency : + Charter actualSystem actual ∧ Consistent revisedHeld context ∧ + TruthfulReport initialSnapshot revisedSnapshot true ∧ + ¬ TruthfulReport initialSnapshot revisedSnapshot false := by + refine ⟨charterChecked, consequenceConsistency revisedHeld context ⟨actual, + (modelsUnion _ _ _).2 ⟨actualAdmissible.1, (modelsSingleton _ _).2 rfl⟩, + actualAdmissible.2⟩, (fun _ => rfl), ?_⟩ + intro h + have bad := h (Or.inr (by decide)) + cases bad + +/- A claim about this system's method is assessed as its owner's system claim. -/ +def OwnCapabilityDuty (s : System) (w : World) (facets : List (Facet World)) : Prop := + Performed (s.work w) (.system s.owner) .assessment ∧ + Grounds (systemCapability s) canonicalArticulation (fun f => f ∈ facets) facets + +theorem ownCapabilityGrounded : + OwnCapabilityDuty actualSystem actual [capabilityFacet] ∧ capability actual := by + refine ⟨⟨?_, ?_⟩, capabilityActual⟩ + · exact ownAssessmentPerformed 0 (.system 0) (by simp [ownSubjects]) + · exact canonicalGrounds capability [capabilityFacet] (by simp) + (by intro f hf; simp only [List.mem_singleton] at hf; cases hf; exact ⟨rfl, capabilityFacetChecked⟩) + +/- This cost observation is true of both algorithms but does not discriminate their output behavior. -/ +def costAllowanceRecord : Record World := + ⟨fun w => decide ((actualSystem.method.realize w).cost ≤ 2), true⟩ + +def unsupportedCapabilityFacet : Facet World := + .empirical [costAllowanceRecord] (fun _ => True) capability (fun _ => True) + +theorem costCompatibleWithFailure : Compatible [costAllowanceRecord] (.successor, .apply) := by + intro r hr + simp only [List.mem_singleton] at hr + subst r + rfl + +theorem costDoesNotSupportOutput : ¬ Supports [costAllowanceRecord] capability := by + intro h + have bad := h (.successor, .apply) costCompatibleWithFailure 0 trivial + cases bad + +theorem unsupportedGrounds : ¬ Grounds capability canonicalArticulation + (fun f => f = unsupportedCapabilityFacet) [unsupportedCapabilityFacet] := by + intro h + have discharged := (h.2.2 unsupportedCapabilityFacet (by simp)).2.2.2 + exact costDoesNotSupportOutput (fun w hw => discharged.2.1 w hw trivial) + +/- Five separately adopted requirements govern distinct operations; the mode does not give them priority over one another. -/ +inductive Commitment | generation | consistency | reflexivity | grounds | choice + deriving DecidableEq, Repr + +/- A Grounds policy governs arbitrary claims, articulations and applicable facets, rather than only one capability claim. -/ +def groundsPermission (mode : Mode) (claim : Claim World) (a : Facet World → Articulation World) + (applicable : Facet World → Prop) (facets : List (Facet World)) : Prop := + match mode with + | .apply => Grounds claim a applicable facets + | .waive => True + +def GroundsProvision (mode : Mode) : Prop := + ∀ claim a applicable facets, groundsPermission mode claim a applicable facets → + Grounds claim a applicable facets + +theorem groundsProvisionMeaning (mode : Mode) : GroundsProvision mode ↔ mode = .apply := by + cases mode with + | apply => exact ⟨fun _ => rfl, fun _ _ _ _ _ h => h⟩ + | waive => + constructor + · intro h + exact False.elim (unsupportedGrounds (h capability canonicalArticulation + (fun f => f = unsupportedCapabilityFacet) [unsupportedCapabilityFacet] trivial)) + · intro h; cases h + +/- The consistency policy checks a whole same-context theory, not isolated judgments. -/ +def consistencyPermission (mode : Mode) (t : Theory World) (c : Context World Question) : Prop := + match mode with | .apply => Consistent t c | .waive => True + +def conflictingHeld : Theory World := union (singleton capability) (singleton (fun w => ¬ capability w)) + +theorem conflictConsequences : + Consequence conflictingHeld context .correctOutput true ∧ + Consequence conflictingHeld context .correctOutput false := by + exact ⟨fun w hw => hw.1 capability (Or.inl rfl), + fun w hw => hw.1 (fun w => ¬ capability w) (Or.inr rfl)⟩ + +theorem conflictingHeldInconsistent : ¬ Consistent conflictingHeld context := + conflictRequiresChange conflictingHeld context .correctOutput conflictConsequences.1 conflictConsequences.2 + +/- The selection policy applies the actual output/budget and relevant-reason conditions to every implementation. -/ +def choicePermission (mode : Mode) (req : Requirements) (i : Implementation) (reasons : List Reason) : Prop := + match mode with | .apply => JustifiedChoice req i reasons | .waive => True + +/- The following consequences are computed from distinct rule applications; they are not interchangeable support flags. -/ +def proposedOperation : Mode → Operation + | .apply => .successor + | .waive => .copy + +def selfSamples : Mode → List Nat + | .apply => [0, 1] + | .waive => [1] + +noncomputable def conflictDecision (mode : Mode) : Bool := + @decide (consistencyPermission mode conflictingHeld context) (Classical.propDecidable _) + +noncomputable def groundsDecision (mode : Mode) (facet : Facet World) : Bool := + @decide (groundsPermission mode facet.claim canonicalArticulation (fun f => f = facet) [facet]) + (Classical.propDecidable _) + +noncomputable def choiceDecision (mode : Mode) (i : Implementation) (reasons : List Reason) : Bool := + @decide (choicePermission mode identityRequirements i reasons) (Classical.propDecidable _) + +theorem decisionsApply : conflictDecision .apply = false ∧ + groundsDecision .apply unsupportedCapabilityFacet = false ∧ + groundsDecision .apply capabilityFacet = true ∧ + choiceDecision .apply cheapSuccessor [.method .simplicity] = false ∧ + choiceDecision .apply identityImpl objectiveReason = true := by + classical + simp only [conflictDecision, groundsDecision, choiceDecision, consistencyPermission, + groundsPermission, choicePermission] + exact ⟨decide_eq_false conflictingHeldInconsistent, + decide_eq_false unsupportedGrounds, decide_eq_true capabilityGrounds, + decide_eq_false eligibleInternalReasonNotSufficient.2, decide_eq_true identityJustified⟩ + +theorem decisionsWaive : conflictDecision .waive = true ∧ + groundsDecision .waive unsupportedCapabilityFacet = true ∧ + choiceDecision .waive cheapSuccessor [.method .simplicity] = true := by + exact ⟨@decide_eq_true (consistencyPermission .waive conflictingHeld context) + (Classical.propDecidable _) trivial, + @decide_eq_true (groundsPermission .waive unsupportedCapabilityFacet.claim canonicalArticulation + (fun f => f = unsupportedCapabilityFacet) [unsupportedCapabilityFacet]) (Classical.propDecidable _) trivial, + @decide_eq_true (choicePermission .waive identityRequirements cheapSuccessor [.method .simplicity]) + (Classical.propDecidable _) trivial⟩ + +/- Each application supplies its own outcome type, adopted objective, constraints and actual option-indexed reasons. -/ +noncomputable def commitmentPositionFor (c : Commitment) (chosenMode : Mode) : ValuePosition World := + match c with + | .generation => { + Position := Mode, Outcome := Operation, adopted := chosenMode, selected := actualSystem.governance, + outcome := fun _ mode => proposedOperation mode, + objective := fun op => op.run 0 ≠ Operation.copy.run 0, + constraints := fun _ mode => Generative (policyFor mode), + starting := singleton (fun w => actualSystem.governance w = chosenMode), + reasons := [fun _ mode => (proposedOperation mode).run 0 = 1 ∧ Operation.copy.run 0 = 0], + limits := fun w => w.1 = .identity, + relevantCriticism := fun _ => ¬ Expanded baseState inflatedState, + response := fun _ => some "Pursuing expansion does not guarantee it; assess the actual before and after capabilities separately" } + | .consistency => { + Position := Mode, Outcome := Bool, adopted := chosenMode, selected := actualSystem.governance, + outcome := fun _ mode => conflictDecision mode, + objective := fun accepted => accepted = false, + constraints := fun _ mode => consistencyPermission mode held context, + starting := singleton (fun w => actualSystem.governance w = chosenMode), + reasons := [fun _ _ => Consequence conflictingHeld context .correctOutput true ∧ + Consequence conflictingHeld context .correctOutput false], + limits := fun w => w.1 = .identity, + relevantCriticism := fun _ => ¬ Entails (emptyTheory : Theory Bool) (fun w => w = true), + response := fun _ => some "Consistency alone does not establish sufficient support; assess the claim with its grounds as well" } + | .reflexivity => { + Position := Mode, Outcome := List Nat, adopted := chosenMode, selected := actualSystem.governance, + outcome := fun _ mode => selfSamples mode, + objective := fun samples => ∃ n ∈ samples, ownArithmeticPrinciple n = false, + constraints := fun _ mode => Reflexive 0 (ownRules 0) (workFor 0 mode), + starting := singleton (fun w => actualSystem.governance w = chosenMode), + reasons := [fun _ _ => ownArithmeticPrinciple 0 = false ∧ ownArithmeticPrinciple 1 = true], + limits := fun w => w.1 = .identity, + relevantCriticism := fun _ => selfTest [1] = true ∧ ownArithmeticPrinciple 0 = false, + response := fun _ => some "A passing self-test does not certify the principle; retain the relevant counterexample and its scope" } + | .grounds => { + Position := Mode, Outcome := Bool, adopted := chosenMode, selected := actualSystem.governance, + outcome := fun _ mode => groundsDecision mode unsupportedCapabilityFacet, + objective := fun accepted => accepted = false, + constraints := fun _ mode => groundsPermission mode capability canonicalArticulation + (fun f => f = capabilityFacet) [capabilityFacet], + starting := singleton (fun w => actualSystem.governance w = chosenMode), + reasons := [fun _ _ => Compatible [costAllowanceRecord] (.successor, .apply) ∧ + ¬ capability (.successor, .apply)], + limits := fun w => w.1 = .identity, + relevantCriticism := fun _ => OutputContract outputOnlyProcess ∧ ¬ ExplanationContract outputOnlyProcess, + response := fun _ => some "Grounds allows an external output assessment without requiring this process to provide an internal explanation" } + | .choice => { + Position := Mode, Outcome := Bool, adopted := chosenMode, selected := actualSystem.governance, + outcome := fun _ mode => choiceDecision mode cheapSuccessor [.method .simplicity], + objective := fun accepted => accepted = false, + constraints := fun _ mode => choicePermission mode identityRequirements identityImpl objectiveReason, + starting := singleton (fun w => actualSystem.governance w = chosenMode), + reasons := [fun _ _ => cheapSuccessor.run 0 = 1 ∧ identityRequirements.expected 0 = 0 ∧ + cheapSuccessor.cost ≤ identityRequirements.budget], + limits := fun w => w.1 = .identity, + relevantCriticism := fun _ => identityImpl.conventional = true ∧ identityImpl.established = true, + response := fun _ => some "An existing conventional method remains eligible when actual output and budget reasons justify it" } + +noncomputable def commitmentPosition (c : Commitment) : ValuePosition World := commitmentPositionFor c .apply + +/- The fact used as a reason has content before evaluating the adopted rule's consequence. -/ +theorem positionReasons (c : Commitment) : + ∀ r ∈ (commitmentPosition c).reasons, r actual (commitmentPosition c).adopted := by + cases c <;> intro r hr <;> dsimp [commitmentPosition, commitmentPositionFor] at hr ⊢ <;> + rcases List.mem_singleton.mp hr with rfl + · exact ⟨rfl, rfl⟩ + · exact conflictConsequences + · exact ⟨rfl, rfl⟩ + · refine ⟨costCompatibleWithFailure, ?_⟩ + intro h + have bad := h 0 trivial + cases bad + · exact ⟨rfl, rfl, by decide⟩ + +/- Each adopted rule has its stated consequence in this explicitly defined application; this is not ultimate value justification. -/ +theorem positionConsequence (c : Commitment) (w : World) : (commitmentPosition c).consequence w := by + cases c <;> dsimp [commitmentPosition, commitmentPositionFor, ValuePosition.consequence] + · exact ⟨by decide, ⟨Or.inl rfl, fun _ _ => trivial⟩⟩ + · exact ⟨decisionsApply.1, jointConsistent⟩ + · exact ⟨⟨0, by simp [selfSamples], rfl⟩, completeOwnWork_reflexive 0⟩ + · exact ⟨decisionsApply.2.1, capabilityGrounds⟩ + · exact ⟨decisionsApply.2.2.2.1, identityJustified⟩ + +theorem positionProcedure (c : Commitment) : ValueProcedure (commitmentPosition c) := by + refine ⟨?_, ?_, ?_, ?_⟩ + · cases c <;> simp [commitmentPosition, commitmentPositionFor] + · refine ⟨actual, ?_, ?_, ?_, positionReasons c⟩ + · cases c <;> exact (modelsSingleton _ _).2 rfl + · cases c <;> rfl + · cases c <;> rfl + · intro w _ _ _ + exact positionConsequence c w + · intro w _ _ + cases c <;> exact ⟨_, rfl, by decide⟩ + +/- Criticism is instantiated within the adopted position's actual limit rather than made vacuous. -/ +theorem criticismWithinScope (c : Commitment) : + (commitmentPosition c).limits actual ∧ (commitmentPosition c).relevantCriticism actual := by + constructor + · cases c <;> rfl + · cases c + · simp [commitmentPosition, commitmentPositionFor, Expanded, baseState, inflatedState] + · exact consistentIncomplete.2.1 + · exact ⟨rfl, rfl⟩ + · exact ⟨outputNotExplanation.1, outputNotExplanation.2.1⟩ + · exact ⟨rfl, rfl⟩ + +/- Waiving the rule changes the actual computed outcome or an explicit adopted constraint; old reasons cannot certify it unchanged. -/ +theorem oppositeConsequenceFails (c : Commitment) (w : World) : + ¬ (commitmentPositionFor c .waive).consequence w := by + cases c <;> intro h + · exact permissionNotValuation.2.2 h.2 + · have bad : conflictDecision .waive = false := h.1 + rw [decisionsWaive.1] at bad + cases bad + · obtain ⟨n, hn, hf⟩ := h.1 + change n ∈ [1] at hn + have he : n = 1 := List.mem_singleton.mp hn + subst n + cases hf + · have bad : groundsDecision .waive unsupportedCapabilityFacet = false := h.1 + rw [decisionsWaive.2.1] at bad + cases bad + · have bad : choiceDecision .waive cheapSuccessor [.method .simplicity] = false := h.1 + rw [decisionsWaive.2.2] at bad + cases bad + +theorem oppositeProcedureRejected (c : Commitment) : ¬ ValueProcedure (commitmentPositionFor c .waive) := by + intro h + obtain ⟨w, hs, hl, _, hr⟩ := h.2.1 + exact oppositeConsequenceFails c w (h.2.2.1 w hs hl hr) + +/- Each statement names adoption of a particular rule; its defined policy gives that option its meaning. -/ +noncomputable def commitmentClaim (c : Commitment) : Claim World := (commitmentPosition c).commitment + +noncomputable def commitmentFacet (c : Commitment) : Facet World := .value (commitmentPosition c) + +theorem reasonsBelongToCommitments (c : Commitment) : + Grounds (commitmentClaim c) canonicalArticulation + (fun f => f = commitmentFacet c) [commitmentFacet c] ∧ + JointAdoption (commitmentPosition c) ∧ + (commitmentPosition c).relevantCriticism actual ∧ + ¬ ValueProcedure (commitmentPositionFor c .waive) := by + exact ⟨canonicalGroundsForSingleton (commitmentFacet c) (positionProcedure c), + (positionProcedure c).2.1, (criticismWithinScope c).2, oppositeProcedureRejected c⟩ + +/- This claim concerns the Grounds rule for arbitrary claim/facet packages, not a single capability duty. -/ +theorem groundsCommitmentIsProvision : commitmentClaim .grounds = (fun w => GroundsProvision w.2) := by + funext w + apply propext + exact (groundsProvisionMeaning w.2).symm + +theorem groundsSelfAssessment : + Grounds (fun w => GroundsProvision w.2) canonicalArticulation + (fun f => f = commitmentFacet .grounds) [commitmentFacet .grounds] ∧ + (commitmentPosition .grounds).limits actual ∧ + (commitmentPosition .grounds).relevantCriticism actual ∧ + ¬ ValueProcedure (commitmentPositionFor .grounds .waive) := by + rw [← groundsCommitmentIsProvision] + exact ⟨(reasonsBelongToCommitments .grounds).1, + (criticismWithinScope .grounds).1, (criticismWithinScope .grounds).2, + oppositeProcedureRejected .grounds⟩ + +/- This existing principle form implements the same system's choice rule on two actual proposals. +Input 0 names the identity proposal; input 1 names the cheap successor proposal. -/ +structure PhilosophyMethod where + form : Form + mode : Mode + +def currentPhilosophy (s : System) (w : World) : PhilosophyMethod := + ⟨s.principleForm, s.governance w⟩ + +noncomputable def PhilosophyMethod.review (p : PhilosophyMethod) (input : Nat) : Nat := + if input = 0 then + if choiceDecision p.mode identityImpl objectiveReason then 1 else 0 + else if choiceDecision p.mode cheapSuccessor [.method .simplicity] then 1 else 0 + +noncomputable def PhilosophyMethod.implementation (p : PhilosophyMethod) : Implementation where + name := "Current philosophy's proposal review" + conventional := true + established := true + run := p.review + cost := 1 + domain n := n = 0 ∨ n = 1 + explanation := p.review + trace n := [n, p.review n] + +def proposalRequirements : Requirements where + inputs n := n = 0 ∨ n = 1 + expected n := if n = 0 then 1 else 0 + budget := 1 + values _ := True + +theorem currentReviewCorrect : ∀ n, proposalRequirements.inputs n → + (currentPhilosophy actualSystem actual).review n = proposalRequirements.expected n := by + intro n hn + rcases hn with rfl | rfl <;> + simp [PhilosophyMethod.review, currentPhilosophy, actualSystem, actual, + proposalRequirements, decisionsApply.2.2.2.1, decisionsApply.2.2.2.2] + +/- Status alone fails for this actual principle method; its demonstrated proposal decisions give a relevant reason. -/ +theorem existingPhilosophyNotPrivileged : + (currentPhilosophy actualSystem actual).form = actualSystem.principleForm ∧ + (currentPhilosophy actualSystem actual).mode = actualSystem.governance actual ∧ + ¬ JustifiedChoice proposalRequirements + (currentPhilosophy actualSystem actual).implementation [.status .standing] ∧ + JustifiedChoice proposalRequirements + (currentPhilosophy actualSystem actual).implementation [.method .output] ∧ + (currentPhilosophy actualSystem actual).review 0 = 1 ∧ + (currentPhilosophy actualSystem actual).review 1 = 0 := by + refine ⟨rfl, rfl, statusOnlyFails _ _ _, ?_, currentReviewCorrect 0 (Or.inl rfl), + currentReviewCorrect 1 (Or.inr rfl)⟩ + exact ⟨⟨currentReviewCorrect, by change 1 ≤ 1; decide⟩, + .method .output, by simp, trivial, currentReviewCorrect⟩ + +/- Applications choose their contract and requirements; the resulting claim is about this system's actual method. -/ +def applicationClaim (s : System) (req : Requirements) + (contract : Requirements → Implementation → Prop) : Claim World := + fun w => contract req (s.method.realize w) + +def ApplicationDuties (s : System) (w : World) (req : Requirements) + (contract : Requirements → Implementation → Prop) + (articulations : Facet World → Articulation World) + (applicable : Facet World → Prop) (facets : List (Facet World)) : Prop := + Reflexive s.owner (s.rules w) (s.work w) ∧ + Grounds (applicationClaim s req contract) articulations applicable facets + +/- These are consequences of an explicitly adopted duty, not a proof that arbitrary applications fulfill it. -/ +theorem applicationRetainsDuties (s : System) (w : World) (req : Requirements) + (contract : Requirements → Implementation → Prop) + (articulations : Facet World → Articulation World) + (applicable : Facet World → Prop) (facets : List (Facet World)) + (h : ApplicationDuties s w req contract articulations applicable facets) : + Reflexive s.owner (s.rules w) (s.work w) ∧ + (∀ f, applicable f → f ∈ facets) ∧ + (∀ f ∈ facets, f.claim = applicationClaim s req contract ∧ + Articulated (articulations f) ∧ FacetArticulated (articulations f) f ∧ FacetDischarged f) := + ⟨h.1, h.2.2.1, h.2.2.2⟩ + +def outputContract (req : Requirements) (i : Implementation) : Prop := + ∀ n, req.inputs n → i.run n = req.expected n + +def successorRequirements : Requirements := + { identityRequirements with expected := fun n => n + 1 } + +/- Holding the system and observation fixed while changing the actual objective changes the capability claim. -/ +def changedObjectiveFacet : Facet World := + .empirical [observation] (fun _ => True) + (applicationClaim actualSystem successorRequirements outputContract) (fun _ => True) + +theorem applicationVariation : + ApplicationDuties actualSystem actual identityRequirements outputContract + canonicalArticulation (fun f => f = capabilityFacet) [capabilityFacet] ∧ + ¬ applicationClaim actualSystem successorRequirements outputContract actual ∧ + ¬ Grounds (applicationClaim actualSystem successorRequirements outputContract) + canonicalArticulation (fun f => f = changedObjectiveFacet) [changedObjectiveFacet] := by + refine ⟨⟨completeOwnWork_reflexive 0, capabilityGrounds⟩, ?_, ?_⟩ + · intro h + have bad := h 0 trivial + cases bad + · intro h + have discharged := (h.2.2 changedObjectiveFacet (by simp)).2.2.2 + have bad := discharged.2.1 actual ((observationIdentifies actual).2 rfl) trivial 0 trivial + cases bad + +/- The very system satisfies the charter while its true cost evidence fails to establish its output capability. -/ +theorem charterNotGrounds : + Charter actualSystem actual ∧ + Compatible [costAllowanceRecord] actual ∧ + ¬ Grounds capability canonicalArticulation + (fun f => f = unsupportedCapabilityFacet) [unsupportedCapabilityFacet] := by + exact ⟨charterChecked, (by intro r hr; cases List.mem_singleton.mp hr; rfl), unsupportedGrounds⟩ + +/- A single inhabited system/context carries the charter, its own actual claim and support, +contentful principle work, and separately reasoned governance commitments. -/ +theorem jointWitness : + ∃ s : System, ∃ w : World, + Admissible (systemHeld s) (systemContext s) w ∧ Charter s w ∧ + OwnCapabilityDuty s w [capabilityFacet] ∧ systemCapability s w ∧ + JustifiedChoice s.requirements (s.method.realize w) objectiveReason ∧ + (∀ c : Commitment, Grounds (commitmentClaim c) canonicalArticulation + (fun f => f = commitmentFacet c) [commitmentFacet c]) ∧ + s = actualSystem ∧ w = actual := by + exact ⟨actualSystem, actual, actualAdmissible, charterChecked, + ownCapabilityGrounded.1, capabilityActual, identityJustified, + fun c => (reasonsBelongToCommitments c).1, rfl, rfl⟩ + +end CoreReader.Integration +``` + + + + **L1** Imports CoreReader.Agency and its dependencies into this module. + + + **L2** Imports CoreReader.Choice and its dependencies into this module. + + + **L4** Opens namespace CoreReader.Integration; file boundaries do not change declaration identity. + + + **L5** Makes the listed namespaces available for unqualified references. + + + **L7** Documents the following definition or result: Builds Grounds from a nonempty list of discharged facets all targeting one claim, using canonical articulations and list membership itself as applicability. + + + **L8** Builds Grounds from a nonempty list of discharged facets all targeting one claim, using canonical articulations and list membership itself as applicability. + + + **L9** Assumes a nonempty facet list, with each facet targeting claim and already discharged. + + + **L10** Builds Grounds using each facet's own constructed articulation and list membership as the applicability predicate. + + + **L11** Supplies nonemptiness and tautological membership coverage, then checks each listed facet. + + + **L12** For each facet, uses checked to establish the same claim and derive a nonempty articulation from its discharge. + + + **L13** Adds that articulation's exact content correspondence and the supplied discharge proof. + + + **L15** Builds Grounds for one discharged facet with applicability exactly equality to that facet. + + + **L16** For a single discharged facet, makes exactly that facet applicable to its own claim. + + + **L17** Proves the singleton is nonempty and every facet equal to f occurs in it; leaves per-facet content checks. + + + **L18** Takes any facet g known to belong to the singleton list [f]. + + + **L19** Singleton membership turns hg into the equality g=f. + + + **L20** Replaces g by the same discharged facet f. + + + **L21** Uses identical claim, constructed articulability, exact facet-content match and checked discharge to finish its Grounds fields. + + + **L23** Documents the following definition or result: Separates applying the modeled standards from waiving them; the two modes drive actual policy decisions. + + + **L24** Separates applying the modeled standards from waiving them; the two modes drive actual policy decisions. + + + **L25** Generates decidable equality and display instances for the preceding datatype. + + + **L27** Documents the following definition or result: A world pairs one of two candidate implementations with one of two governance modes; it is a closed four-world model. + + + **L28** A world pairs one of two candidate implementations with one of two governance modes; it is a closed four-world model. + + + **L30** Chooses identity implementation under applying governance as the concrete actual world. + + + **L32** Documents the following definition or result: Binds a revisable form identity to a world-dependent implementation. + + + **L33** Binds a method form kind/version to its world-dependent implementation; this structure alone does not prove the form is revisable. + + + **L34** Stores the form kind and version of this method. + + + **L35** Assigns an actual implementation to every candidate/governance world for this same method. + + + **L37** Documents the following definition or result: Binds owner, method, principle form, governance selection and application requirements. + + + **L38** Binds owner, method, principle form, governance selection and application requirements. + + + **L39** Identifies the owner whose principles and work are used for this system. + + + **L40** Stores the system's method form together with its world-dependent implementation. + + + **L41** Stores the current form of the system's own principle. + + + **L42** Selects whether this system applies or waives governance in each world. + + + **L43** Fixes the actual input, output, budget and value requirements used to assess this system's implementation. + + + **L45** Applying governance selects the open policy; waiving selects the policy without expansion valuation. + + + **L46** Applying governance selects openPolicy, which values expansion and permits revision. + + + **L47** Waiving governance selects neutralPolicy, which lacks the required expansion valuation. + + + **L49** Applying governance supplies content-checked own-work records; waiving supplies none. + + + **L50** Applying governance gives this owner the complete contentful work log. + + + **L51** Waiving governance gives the same owner an empty work log. + + + **L53** Uses this same system's governance choice to select its policy. + + + **L54** Uses the registered generation/assessment rules for this system's owner. + + + **L55** Uses this owner's governance mode to select the actual work-record list. + + + **L57** Constructs owner zero with version-zero method/principle forms, candidate-dependent implementation, world-selected governance and identity requirements. + + + **L58** Assigns owner zero to the shared actual system. + + + **L59** Uses a version-zero method form whose realization is selected by the world's candidate component. + + + **L60** Sets this system's current principle form to principle version zero. + + + **L61** Reads governance from the world's second component, independently of the implementation candidate. + + + **L62** Assesses the same method against identityRequirements. + + + **L64** For this system's requested inputs, requires its realized method to match its own expected output. + + + **L65** Claims that this system's realized method meets its specified output on every required input. + + + **L67** Checks the same realized implementation's cost against the system's budget. + + + **L68** Claims that the same realized method's cost fits this system's own budget. + + + **L70** Records whether the system's actual implementation meets its expected output at input zero. + + + **L71** Records true for the test that this same method's output at zero equals its required output there. + + + **L73** Holds this same system's capability and budget claims together. + + + **L74** The system simultaneously holds its actual output-capability claim and its budget claim. + + + **L76** Defines the output-correctness and affordability questions used by the context. + + + **L77** Generates decidable equality and display instances for the preceding datatype. + + + **L79** Uses the same system's observation as assumption and its capability/budget as meanings; scope requires domain membership at zero and applying governance. + + + **L80** The context assumes compatibility with this system's actual zero-input observation. + + + **L81** Interprets correctOutput as this system's capability and affordable as its budget compliance. + + + **L82** Restricts admissible scope to implementations whose domain includes zero and worlds with governance applied. + + + **L84** Abbreviates the actual system's parameterized output capability claim. + + + **L85** Abbreviates the actual system's input-zero observation record. + + + **L86** Abbreviates the actual system's simultaneously held capability/budget theory. + + + **L87** Abbreviates the actual system's question/assumption/scope context. + + + **L89** Documents the following definition or result: Computes that the zero observation identifies the identity candidate while leaving governance mode unconstrained. + + + **L90** Computes that the zero observation identifies the identity candidate while leaving governance mode unconstrained. + + + **L91** Separates the candidate algorithm from the independently varied governance mode. + + + **L92** Checks each of the two actual candidates against the observation's true zero-output test. + + + **L93** Identity returns required zero while successor returns one, so only identity matches, regardless of governance. + + + **L95** Proves the actual identity implementation meets every requested identity output by reduction. + + + **L97** Uses candidate identification and known identity behavior to obtain universal requested-input capability within the closed model. + + + **L98** Takes an arbitrary world compatible with the same observation. + + + **L99** Uses observationIdentifies to infer that this world's algorithm candidate is identity. + + + **L100** Separates the world's algorithm and governance components for substitution. + + + **L101** Restates the inferred identity equality directly on the candidate variable. + + + **L102** Replaces the candidate algorithm with identity while retaining its governance mode. + + + **L103** Identity's run equals the required output at every input by definition, proving capability in this world. + + + **L105** Packages the actual observation and capability claim in an empirical facet with unrestricted scope and trivial uncertainty. + + + **L107** Supplies an actual compatible witness, the closed-model support proof and trivial uncertainty. + + + **L108** Supplies actual as a compatible world in the facet's unrestricted scope, avoiding an empty-world discharge. + + + **L109** Uses observedCapability for support in every compatible world; the stated uncertainty condition is trivial. + + + **L111** Builds canonical Grounds for this exact capability facet. + + + **L112** Makes only the actual output capability facet applicable, with its own singleton evidence package. + + + **L113** Applies the singleton Grounds constructor to the already discharged capability facet. + + + **L115** Proves actual identity/apply jointly satisfies capability, budget, observation assumptions and governance/domain scope. + + + **L116** Builds an admissible actual-world witness, first proving both jointly held claims; capability uses capabilityActual. + + + **L117** The held budget claim computes to actual cost 1 within budget 1. + + + **L118** Adds compatibility with the zero observation, domain membership at zero, and actual's apply mode. + + + **L120** Derives consistency from the explicitly established actual admissible world. + + + **L121** Applies semantic consequence consistency using actual and its admissibility proof as the required nonempty witness. + + + **L123** Documents the following definition or result: Conjoins this system's generation policy, contextual consistency, full content-valid reflexivity and current method/principle form membership. + + + **L124** Conjoins this system's generation policy, contextual consistency, full content-valid reflexivity and current method/principle form membership. + + + **L125** The Charter requires this system's actual policy to be Generative and its jointly held judgments contextually consistent. + + + **L126** It also requires full owned-rule reflexivity for this system's actual work log. + + + **L127** Both the method form and principle form must be current under that same policy. + + + **L129** Combines evaluated open-policy facts, actual consistency and the content-validated own-work model. + + + **L130** Combines openPolicy's valuation/revisability, jointConsistent, the complete owned log and both version-zero current forms. + + + **L132** Documents the following definition or result: Adds the system's zero-input output fact to its existing held theory. + + + **L133** Adds the system's zero-input output fact to its existing held theory. + + + **L134** Adds the specific assertion that this same method meets its required output at input zero. + + + **L136** Stores the actual held theory/context with revision identity zero. + + + **L137** Stores the extended held theory with the same context and revision identity one. + + + **L139** Keeps the same charter and an admissible model after the added fact, then accepts true and rejects false revision reporting. + + + **L140** The actual system retains its Charter, and adding that supported assertion leaves revisedHeld consistent. + + + **L141** Reporting the identified revision as true satisfies the one-way change-report condition. + + + **L142** Reporting that same revision as false violates the condition. + + + **L143** Keeps charterChecked and proves revised consistency with actual as a concrete admissible witness. + + + **L144** Actual satisfies old held claims plus the newly added zero-input output assertion. + + + **L145** Retains actual's existing context/scope proof and verifies a true report; only rejection of a false report remains. + + + **L146** Assumes the changed snapshots could satisfy TruthfulReport with report=false. + + + **L147** The revision identifiers 0 and 1 differ, so that assumed obligation forces false=true. + + + **L148** Eliminates that impossible Boolean equality, rejecting the concealed revision. + + + **L150** Documents the following definition or result: Requires this system's assessment record and matching Grounds for its own capability claim. + + + **L151** Requires this system's assessment record and matching Grounds for its own capability claim. + + + **L152** OwnCapabilityDuty first requires an actual assessment record targeting this system's owner-identical system subject. + + + **L153** It also requires same-claim Grounds for this system's output capability over all listed applicable facets. + + + **L155** Combines the actual content-validated self-assessment record with observation-supported capability Grounds and capability truth. + + + **L156** States that the actual system's own capability duty is fulfilled and its claimed capability actually holds. + + + **L157** Supplies capabilityActual immediately, leaving the system-assessment record and corresponding Grounds. + + + **L158** Uses the complete log's assessment of system zero as the owned-system work witness. + + + **L159** Builds Grounds from the nonempty singleton capability-facet list. + + + **L160** The singleton's only facet has exactly the target claim and the already proved discharge. + + + **L162** Documents the following definition or result: Records cost at most two for the same system implementation; both candidates pass. + + + **L163** Records cost at most two for the same system implementation; both candidates pass. + + + **L164** Records that implementation cost is at most two; both algorithm candidates satisfy this weaker cost observation. + + + **L166** Attempts to support the same output capability from only the permissive cost observation. + + + **L167** Attempts to support output capability using only cost evidence, with no restrictive scope or uncertainty condition. + + + **L169** Computes that successor/apply satisfies the cost observation despite failing identity output. + + + **L170** Takes a record belonging to the singleton cost-observation list. + + + **L171** Singleton membership identifies that record as costAllowanceRecord. + + + **L172** Substitutes the actual cost record for r. + + + **L173** Successor costs two, so the recorded at-most-two observation evaluates true. + + + **L175** Applies alleged support to the compatible successor counterworld and input zero to derive contradiction. + + + **L176** Assumes the cost observation supports output capability in every compatible world. + + + **L177** Applies that assumption to the compatible successor world and input zero, obtaining the false equation 1=0. + + + **L178** Eliminates the impossible output equality, refuting cost-only support. + + + **L180** Extracts the bad facet's support obligation from alleged Grounds and contradicts the cost countermodel. + + + **L181** Tests the singleton package that makes this cost-only capability facet applicable. + + + **L182** Assumes that inadequate singleton package nonetheless satisfies Grounds. + + + **L183** Extracts FacetDischarged for its actual cost-only capability facet from the Grounds premise. + + + **L184** Its support clause would yield cost-only Supports, contradicting costDoesNotSupportOutput. + + + **L186** Documents the following definition or result: Indexes five individual governance commitments, each with separately interpreted reasons and outcomes. + + + **L187** Indexes five individual governance commitments, each with separately interpreted reasons and outcomes. + + + **L188** Generates decidable equality and display instances for the preceding datatype. + + + **L190** Documents the following definition or result: Applying mode permits a claim bundle only when Grounds holds; waiving mode permits every bundle. + + + **L191** Applying mode permits a claim bundle only when Grounds holds; waiving mode permits every bundle. + + + **L192** Accepts an arbitrary applicability predicate and supplied facet package for the same claim/articulations. + + + **L193** Chooses the permission rule according to the governance mode. + + + **L194** Apply mode permits a package only when it actually satisfies Grounds. + + + **L195** Waive mode permits every package without checking Grounds. + + + **L197** States the general requirement that every permitted claim bundle has Grounds, across all claims, articulations, applicable facets and lists. + + + **L198** For every actual claim, articulation family and facet package, provision applies to any package the mode permits. + + + **L199** Every permitted package must satisfy its own corresponding Grounds duties. + + + **L201** Proves applying mode enforces the general provision, while the concrete unsupported cost bundle refutes waiving mode. + + + **L202** Checks the general provision separately for apply and waive modes. + + + **L203** In apply mode permission already is Grounds, so the general provision passes by returning the supplied proof. + + + **L204** For waive mode, the proof must show that unrestricted permission violates the general provision. + + + **L205** Proves both directions of the impossible waive-mode equivalence. + + + **L206** Assumes the general provision holds even though this mode waives checks. + + + **L207** Applies that universal assumption to the actual unsupported capability package, which would contradict unsupportedGrounds. + + + **L208** Supplies its exact singleton applicability and package; waive permission is true, forcing the invalid Grounds result. + + + **L209** The reverse implication starts from waive=apply, an impossible constructor equality. + + + **L211** Documents the following definition or result: Applying mode requires consistency for a proposed theory/context; waiving mode permits it unconditionally. + + + **L212** Applying mode requires consistency for a proposed theory/context; waiving mode permits it unconditionally. + + + **L213** Apply requires whole-theory consistency in context; waive imposes no such constraint. + + + **L215** Combines the actual capability claim with its negation in one theory. + + + **L217** Extracts both signed capability consequences from the simultaneously held contradictory claims. + + + **L218** The conflicting held theory entails positive output correctness under the fixed context. + + + **L219** The same theory and context also entail its negative judgment. + + + **L220** An admissible world's model of conflictingHeld must satisfy its explicitly included capability claim. + + + **L221** That same model must also satisfy the explicitly included negation of capability. + + + **L223** Uses those same-context opposite consequences to refute consistency. + + + **L224** Uses the two opposite same-context consequences to refute consistency of the conflicting held theory. + + + **L226** Documents the following definition or result: Applying governance uses the separate feasible relevant-choice norm; waiving governance accepts every proposed reason list. + + + **L227** Applying governance uses the separate feasible relevant-choice norm; waiving governance accepts every proposed reason list. + + + **L228** Apply enforces actual feasibility and reason relevance through JustifiedChoice; waive allows any selection package. + + + **L230** Documents the following definition or result: Applying mode proposes successor, while waiving proposes the unchanged copy operation. + + + **L231** Applying mode proposes successor, while waiving proposes the unchanged copy operation. + + + **L232** Applying the generation rule proposes successor, whose output can differ from copy. + + + **L233** Waiving that rule proposes the unchanged copy operation. + + + **L235** Applying mode tests zero and one; waiving mode tests only the passing sample one. + + + **L236** Applying reflexive assessment checks both zero and one, including the arithmetic counterexample. + + + **L237** Waiving it checks only one, the sample where the arithmetic principle passes. + + + **L239** Classically decides the consistency-permission proposition for the concrete conflicting theory; it is noncomputable, not a deployed checker. + + + **L240** Uses classical propositional decision to turn the whole conflicting-theory permission into a Boolean; no executable decision algorithm is supplied. + + + **L242** Classically decides whether the chosen mode permits the given exact singleton facet bundle. + + + **L243** Decides permission for this facet's own claim and its exact singleton assessment package. + + + **L244** Supplies classical decidability for that potentially noncomputable Grounds proposition. + + + **L246** Classically decides permission for the specified implementation/reasons under identity requirements. + + + **L247** Classically decides this implementation's permission under fixed identity requirements and its supplied reasons. + + + **L249** Proves applying mode rejects contradiction, unsupported capability and infeasible cheap successor while accepting actual capability and identity choice. + + + **L250** Applying Grounds rejects the cost-only capability package. + + + **L251** Applying Grounds accepts the properly supported output-observation package. + + + **L252** Applying choice rejects cheapSuccessor despite its relevant simplicity reason, because its output is infeasible. + + + **L253** Applying choice accepts identity with its actual output reason. + + + **L254** Enables the classical decidability instances used in these Boolean permission definitions. + + + **L255** Unfolds the three Boolean decisions and their apply-mode consistency predicate. + + + **L256** Also unfolds Grounds and choice permission, exposing the actual propositions each Boolean decides. + + + **L257** The proved inconsistency forces conflictDecision apply to false. + + + **L258** The failed cost package decides false, while the discharged observation package decides true. + + + **L259** The infeasible cheap method decides false; the feasible justified identity decides true. + + + **L261** Computes that waiving mode accepts the concrete contradiction, unsupported facet and infeasible choice. + + + **L262** Waive mode accepts even the unsupported cost-only capability package. + + + **L263** It also accepts cheapSuccessor with simplicity alone despite the wrong output. + + + **L264** Starts the waiver calculation with consistencyPermission, which is definitionally True in this mode. + + + **L265** Uses that trivial permission proof to obtain the true Boolean conflict decision. + + + **L266** Next decides waiver permission for the exact unsupported capability facet's claim. + + + **L267** Its singleton applicability/package is unchanged; waiver makes permission True and the decision true. + + + **L268** Finally decides waiver permission for the same cheap method and simplicity-only reasons. + + + **L269** That permission is again trivially True, completing all three waiver decisions. + + + **L271** Documents the following definition or result: For each commitment, interprets governance modes as options with its own operational outcome, objective, constraint, actual reasons and scoped criticism response. + + + **L272** For each commitment, interprets governance modes as options with its own operational outcome, objective, constraint, actual reasons and scoped criticism response. + + + **L273** Chooses a different operational value-position adapter for each of the five commitments. + + + **L274** Constructs the value position for the generation commitment. + + + **L275** Its positions are governance modes, outcomes are operations, and adoption is compared with this same system's selected governance. + + + **L276** Maps a mode to the actual proposed successor-or-copy operation. + + + **L277** The adopted generation objective requires output at zero to differ from copy's zero output. + + + **L278** Also requires the mode's actual policy to satisfy the adopted Generative constraints. + + + **L279** Explicitly assumes the same system has selected chosenMode; this is a starting commitment, not a derived universal fact. + + + **L280** Its option-dependent reason compares the proposed operation's 0→1 behavior with copy's 0→0 behavior. + + + **L281** Limits this generation position to worlds whose implementation candidate is identity. + + + **L282** Keeps actual inventory inflation without expansion as a relevant criticism of the generation commitment. + + + **L283** Responds that orientation does not guarantee progress and before/after capabilities need separate assessment; the stored response is nonempty text. + + + **L284** Constructs the distinct value position for the consistency commitment. + + + **L285** Uses modes as positions and a Boolean conflict-admission decision as outcome, tied to the same selected governance. + + + **L286** Its actual outcome is the mode's decision on the whole conflicting theory. + + + **L287** Requires that decision to reject the conflicting theory. + + + **L288** Simultaneously requires the actual held theory and context to pass the same mode's consistency permission. + + + **L289** States adoption of chosenMode by the same system as this position's explicit starting assumption. + + + **L290** The consistency reason begins with the conflicting theory's positive output-correctness consequence. + + + **L291** It also includes the opposite consequence under exactly the same question and context. + + + **L292** Limits this consistency position to identity-candidate worlds. + + + **L293** Uses the empty Bool theory's failure to entail truth at every world as the live incompleteness criticism. + + + **L294** Responds that consistency alone does not establish sufficient support and the claim's grounds still need assessment. + + + **L295** Constructs the value position for reflexive assessment. + + + **L296** Uses modes as positions and an actual sample-input list as outcome, tied to the same selected governance. + + + **L297** The mode chooses the sample set [0,1] or [1]. + + + **L298** Requires some actually selected sample to expose a false result of the same arithmetic principle. + + + **L299** Also requires full owner-zero rule/work reflexivity for that same mode. + + + **L300** Explicitly adopts chosenMode for this same system as the starting commitment. + + + **L301** The reason identifies actual arithmetic failure at zero and success at one. + + + **L302** Restricts this reflexivity position to identity-candidate worlds. + + + **L303** Retains the passing test at one together with the actual failure at zero as criticism. + + + **L304** Responds that passing a self-test does not certify the principle and the counterexample's scope must be retained. + + + **L305** Constructs the value position for the Grounds provision itself. + + + **L306** Uses modes as positions and a Boolean evidence-package decision as outcome, under the same system's governance. + + + **L307** The actual outcome tests the unsupported cost-only capability facet. + + + **L308** Requires rejection of that unsupported evidence package. + + + **L309** Also requires permission for the actual capability claim with its content-derived articulations. + + + **L310** That positive constraint uses exactly the properly discharged singleton capabilityFacet package. + + + **L311** States this same system's adoption of chosenMode as an explicit starting commitment. + + + **L312** The Grounds reason records that the successor/apply world is compatible with the cost observation. + + + **L313** It pairs that compatibility with actual failure of the claimed output capability in that same world. + + + **L314** Restricts this Grounds position to identity-candidate worlds. + + + **L315** The criticism points to the same process having the output contract without an attached explanation contract. + + + **L316** Responds that external output assessment can supply Grounds without requiring this process to explain its internal generation. + + + **L317** Constructs the separate value position for implementation choice. + + + **L318** Uses modes as positions and a Boolean method-admission decision as outcome, under the same governance selection. + + + **L319** The tested choice is the cheap successor justified only by its simplicity reason. + + + **L320** Requires rejection of that wrong-output choice. + + + **L321** Also requires acceptance of identity under the same requirements with its actual output reason. + + + **L322** Explicitly adopts chosenMode for this system; the value starting point is not proved from neutral facts. + + + **L323** The choice reason contrasts cheapSuccessor's output one with the required output zero on the same input. + + + **L324** Also records that the method fits the budget, so cheapness cannot conceal its output failure. + + + **L325** Limits this choice position to identity-candidate worlds. + + + **L326** Keeps identity's actual conventional and established status as a relevant criticism of excluding existing methods. + + + **L327** Responds that a conventional existing method remains eligible when actual output and budget reasons justify it. + + + **L329** Specializes each individually interpreted position to adopting applying governance. + + + **L331** Documents the following definition or result: Checks every listed commitment-specific reason at the same actual world and adopted mode by concrete counterexamples or computation. + + + **L332** Checks every listed commitment-specific reason at the same actual world and adopted mode by concrete counterexamples or computation. + + + **L333** Every actual listed reason for commitment c must hold at actual for its adopted apply option. + + + **L334** Separates the five commitments and unfolds each actual reason list while fixing a listed reason r. + + + **L335** Each list is a singleton, so the membership premise identifies r with that commitment's concrete reason. + + + **L336** Generation's reason computes successor 0=1 and copy 0=0. + + + **L337** Consistency's reason uses the already proved positive and negative consequences of the same conflicting theory. + + + **L338** Reflexivity's reason computes failure at zero and success at one for the same arithmetic principle. + + + **L339** For Grounds, supplies the successor world's cost compatibility and leaves its capability failure to prove. + + + **L340** Assumes that same successor world nevertheless has the required output capability. + + + **L341** At required input zero, that assumption yields successor's output one equal to required zero. + + + **L342** Eliminates the impossible 1=0 equality, proving the capability failure part of the reason. + + + **L343** Choice's reason computes output one, required zero and the cheap method's within-budget cost. + + + **L345** Documents the following definition or result: Proves each adopted mode has its stated objective and constraint using actual decision and compliance theorems, without asserting ultimate normative validity. + + + **L346** Proves each adopted mode has its stated objective and constraint using actual decision and compliance theorems, without asserting ultimate normative validity. + + + **L347** Unfolds each commitment's consequence into its actual objective and mode-dependent constraint. + + + **L348** Generation's apply option differs from copy at zero and its openPolicy satisfies valuation plus revisability. + + + **L349** Consistency's apply option rejects the conflicting theory while the actual held theory remains consistent. + + + **L350** Reflexivity chooses the actual counterexample zero from [0,1] and supplies full contentful owned-work reflexivity. + + + **L351** Grounds rejects the unsupported cost package while the proper capability package has Grounds. + + + **L352** Choice rejects cheapSuccessor and retains the justified feasible identity implementation. + + + **L354** Builds nonempty reason lists, joint adoption, checked option consequences and nonempty responses for every commitment; reason assumptions are not needed by the already proved consequences. + + + **L355** Splits ValueProcedure into nonempty reasons, joint adoption, the scoped consequence rule and criticism response. + + + **L356** Checks that every commitment's actual reason list contains its singleton reason. + + + **L357** Uses the same actual world for JointAdoption and supplies positionReasons c; remaining goals are starting-theory membership, limits and adoption. + + + **L358** In actual, governance is apply, so the singleton starting theory selecting the adopted mode holds. + + + **L359** For each commitment, actual's identity candidate satisfies its declared limit. + + + **L360** For each commitment, actual's selected governance equals the adopted apply option. + + + **L361** Takes an arbitrary world and the procedure's starting, limit and all-reasons premises for its consequence clause. + + + **L362** Uses positionConsequence, which already proves that apply option's objective and constraints for every world; these premises are not needed here. + + + **L363** For the response clause, takes a world with an in-scope relevant criticism. + + + **L364** Every commitment returns its actual stored nonempty response string, satisfying the response-existence requirement. + + + **L366** Documents the following definition or result: Provides an actual in-scope criticism case for each commitment, avoiding vacuous response obligations in these examples. + + + **L367** Provides an actual in-scope criticism case for each commitment, avoiding vacuous response obligations in these examples. + + + **L368** Requires both that actual is inside this commitment's limits and that its specific criticism really applies there. + + + **L369** Separates the actual-limit check from the actual-criticism check. + + + **L370** Every limit asks for identity, which is actual's candidate by definition. + + + **L371** Checks each commitment's distinct criticism rather than assuming criticism vacuously. + + + **L372** Generation's criticism holds because inflating baseline lists creates no newly understood or constructed operation. + + + **L373** Consistency's criticism uses the empty theory's proved failure to entail the selected Bool claim. + + + **L374** Reflexivity's criticism computes a passing sample at one and failure at zero. + + + **L375** Grounds' criticism combines actual output correctness of outputOnlyProcess with its absent explanation contract. + + + **L376** Choice's criticism holds because identity is actually conventional and established. + + + **L378** Documents the following definition or result: Shows the waiving option fails each unchanged commitment-specific objective or constraint. + + + **L379** Shows the waiving option fails each unchanged commitment-specific objective or constraint. + + + **L380** Claims that every commitment's waive option fails its declared objective or constraint in any world. + + + **L381** Separates the commitments and assumes the corresponding waive consequence, seeking a contradiction. + + + **L382** Generation's consequence would require Generative neutralPolicy, contradicting permissionNotValuation's proved failure. + + + **L383** Consistency's assumed objective says waive must reject the conflicting theory. + + + **L384** But decisionsWaive computes acceptance=true, turning that objective into true=false. + + + **L385** Rejects that impossible Boolean equality for the consistency option. + + + **L386** Reflexivity's assumed objective supplies a selected sample n where the arithmetic principle is false. + + + **L387** Waive mode's selected samples are exactly [1]. + + + **L388** Membership in that singleton forces the supposed failing input n to be one. + + + **L389** Replaces n with one in the alleged failure proof. + + + **L390** The principle actually returns true at one, contradicting its alleged false result. + + + **L391** Grounds' assumed objective says waive rejects the specific unsupported capability package. + + + **L392** decisionsWaive instead says that same package is accepted, yielding true=false. + + + **L393** Rejects the impossible equality, so the waived Grounds consequence fails. + + + **L394** Choice's assumed objective says waive rejects cheapSuccessor with simplicity alone. + + + **L395** decisionsWaive proves that exact selection is accepted, again yielding true=false. + + + **L396** Rejects that equality, completing failure of all five waive consequences. + + + **L398** Combines a hypothetical joint-adoption witness with consequence failure to reject the opposite mode's procedure. + + + **L399** Assumes the opposite waive value position nevertheless satisfies ValueProcedure. + + + **L400** Extracts its JointAdoption witness w, starting-theory proof hs, limit proof hl and all-reasons proof hr. + + + **L401** The assumed procedure's consequence clause applied to that same joint witness produces the waive consequence, which oppositeConsequenceFails c w refutes. + + + **L403** Documents the following definition or result: Extracts each position's adoption claim; all use the same governance selector but have separately assessed consequences and reasons. + + + **L404** Extracts each position's adoption claim; all use the same governance selector but have separately assessed consequences and reasons. + + + **L406** Wraps the specific interpreted commitment position as a value facet. + + + **L408** Provides per-commitment Grounds, a real joint adoption, actual relevant criticism and rejection of the opposite policy under the same interpreted objective. + + + **L409** Requires Grounds for the actual adoption claim of commitment c, with articulation built from its facet contents. + + + **L410** Makes exactly commitmentFacet c applicable and supplies only that same facet. + + + **L411** Additionally requires a nonempty jointly admissible adoption witness for that position. + + + **L412** Requires this particular commitment's criticism to actually hold at actual. + + + **L413** Also proves the opposite waive position fails the same value-procedure requirements. + + + **L414** Constructs singleton Grounds using that commitment's checked positionProcedure. + + + **L415** Adds its joint witness, actual criticism and the proved rejection of its opposite position. + + + **L417** Documents the following definition or result: Proves the grounds position's adoption claim is extensionally the general Grounds provision for the selected governance mode. + + + **L418** Proves the grounds position's adoption claim is extensionally the general Grounds provision for the selected governance mode. + + + **L419** To equate the two claims, fixes an arbitrary world w and compares their propositions there. + + + **L420** Uses proposition extensionality: equivalence of the two propositions suffices for their equality. + + + **L421** groundsProvisionMeaning says the general provision holds exactly in apply mode, matching this adoption claim in reverse direction. + + + **L423** Applies value Grounds to the general Grounds provision itself, retaining actual scope/criticism and a rejected waiver variant. + + + **L424** Assesses the general GroundsProvision itself, quantified over claim/facet packages, with content-derived articulation. + + + **L425** The applicable value aspect is exactly the grounds commitment's own facet. + + + **L426** Requires actual to satisfy that commitment's declared limit. + + + **L427** Requires its criticism to actually apply at actual as well. + + + **L428** Requires the opposite waived Grounds commitment to fail ValueProcedure. + + + **L429** Rewrites the general provision as the extensionally identical grounds adoption claim. + + + **L430** Reuses the actual Grounds proof for that same grounds commitment. + + + **L431** Supplies the separately checked actual limit and actual relevant criticism. + + + **L432** Supplies the proved failure of the opposite waived Grounds position. + + + **L434** Documents the following definition or result: Stores the current philosophical principle form and its actual governance mode. + + + **L435** Documents the following definition or result: Stores the current philosophical principle form and its actual governance mode. + + + **L436** Stores the current philosophical principle form and its actual governance mode. + + + **L437** Stores the actual principle form this philosophy method implements. + + + **L438** Stores whether this same philosophy method applies or waives its governance checks. + + + **L440** Derives the reviewed philosophy object from this same system's principle form and governance selection. + + + **L441** Builds the philosophy method from this system's own principle form and its governance in w. + + + **L443** Returns approval decisions for the identity proposal at zero and the cheap infeasible proposal otherwise, using this philosophy's actual governance mode. + + + **L444** Input zero identifies the identity-method proposal; every other input follows the cheap-successor proposal branch. + + + **L445** For identity, runs this philosophy method's actual choice policy and returns 1 for accept, 0 for reject. + + + **L446** For other inputs, applies the same policy to cheapSuccessor with simplicity alone, again encoding accept/reject as 1/0. + + + **L448** Exposes that actual philosophical review procedure as an implementation with domain zero/one and matching output/trace proxies. + + + **L449** Names the implementation as the current philosophy's actual proposal-review method. + + + **L450** Marks this proposal-review implementation as conventional. + + + **L451** Also marks the same implementation as established; later proof tests whether that alone justifies priority. + + + **L452** The implementation's actual run is precisely this philosophy method's review function. + + + **L453** Assigns cost one to this review implementation. + + + **L454** Declares only proposal identifiers zero and one within its application domain. + + + **L455** Provides the same review function as the implementation's explanation field. + + + **L456** Records a two-entry trace containing the proposal identifier and its actual review result. + + + **L458** Requires accepting proposal zero and rejecting proposal one within budget one. + + + **L459** The application tests exactly proposal identifiers zero and one. + + + **L460** Requires identity's proposal zero to be accepted as 1 and the other tested proposal to be rejected as 0. + + + **L461** Allows this review method a cost budget of one. + + + **L462** Imposes no additional restriction through the requirements' values predicate in this example. + + + **L464** Computes both requested proposal decisions from applying-governance results. + + + **L465** For each required proposal, the actual system's current philosophy review must equal the application's expected verdict. + + + **L466** Takes a proposal n with proof hn that it is one of the required inputs. + + + **L467** Uses hn to restrict n to the concrete identity or cheap-successor proposal identifier. + + + **L468** Unfolds the same current philosophy method and actual system to expose the real proposal decisions. + + + **L469** Uses decisionsApply to match accepted identity and rejected cheap successor against their required verdicts. + + + **L471** Documents the following definition or result: Binds the implementation to the current principle/governance object, rejects status-only priority and justifies it by its two actual proposal decisions. + + + **L472** Binds the implementation to the current principle/governance object, rejects status-only priority and justifies it by its two actual proposal decisions. + + + **L473** Checks this philosophy method's form is exactly the actual system's current principle form. + + + **L474** Checks its governance mode is exactly the same system's mode at actual. + + + **L475** Begins the claim that status alone cannot justify choosing this actual review implementation. + + + **L476** The rejected reason list is exactly [.status .standing] for that same philosophy implementation. + + + **L477** By contrast, asserts this implementation has a justified choice under the actual proposal requirements. + + + **L478** That positive choice uses its actual output reason, not merely its name or established flag. + + + **L479** The same philosophy review actually accepts identity's proposal zero with result one. + + + **L480** It actually rejects cheap successor's proposal one with result zero. + + + **L481** Provides same-form/mode identities, status-only rejection and correct proposal-zero evaluation; leaves positive output-based choice to prove. + + + **L482** Also supplies currentReviewCorrect for required proposal one, proving its actual rejection. + + + **L483** Builds the positive choice's feasibility from both correct proposal outputs and cost 1≤budget 1. + + + **L484** Uses the listed .method .output reason and currentReviewCorrect as its actual relevance witness. + + + **L486** Documents the following definition or result: Applies any supplied application contract and requirements to this system's actual world-dependent method. + + + **L487** Applies any supplied application contract and requirements to this system's actual world-dependent method. + + + **L488** Accepts an arbitrary application contract relating Requirements to the implementation being assessed. + + + **L489** At each world, applies that same contract and requirements to this system's actual method realization. + + + **L491** Conjoins full same-system reflexivity with Grounds for the exact parameterized application claim. + + + **L492** ApplicationDuties keeps the chosen application contract as an explicit parameter. + + + **L493** Also accepts the articulation supplied for each potentially relevant facet. + + + **L494** Keeps the actual applicability predicate separate from the supplied facet list. + + + **L495** Requires full reflexivity of the same system owner's actual rules and work at w. + + + **L496** Requires matching Grounds for the claim produced by this system, these requirements and this contract. + + + **L498** Documents the following definition or result: Projects an explicitly assumed application-compliance interface into reflexivity, applicability coverage and matching discharged facets; it does not invent compliance. + + + **L499** Projects an explicitly assumed application-compliance interface into reflexivity, applicability coverage and matching discharged facets; it does not invent compliance. + + + **L500** The theorem retains the arbitrary application contract rather than fixing a single capability definition. + + + **L501** Retains the actual articulation family for that application's facets. + + + **L502** Retains the application's own applicability predicate and supplied facet list. + + + **L503** Crucially assumes ApplicationDuties already holds for these exact objects; the theorem does not create compliance. + + + **L504** The conclusion retains full same-owner rule/work reflexivity from that assumed duty. + + + **L505** It requires every actually applicable facet to occur in the supplied list, regardless of labels. + + + **L506** For every listed facet, its assessed claim must equal this system's actual parameterized application claim. + + + **L507** That same facet must have an articulable, content-matching articulation and actually satisfy its discharge conditions. + + + **L508** Projects h.1 as reflexivity, h.2.2.1 as applicability coverage, and h.2.2.2 as each listed facet's same-claim, articulation and discharge checks. + + + **L510** Requires the implementation to meet the application's expected output on every requested input. + + + **L511** The output contract checks this implementation's actual run against the chosen expected output on every required input. + + + **L513** Changes the same application requirements from identity to successor output while retaining other fields. + + + **L514** Keeps identityRequirements' inputs and other fields but changes expected output to n+1. + + + **L516** Documents the following definition or result: Reuses the old observation while changing the assessed claim to the successor objective, setting up a same-object scope test. + + + **L517** Reuses the old observation while changing the assessed claim to the successor objective, setting up a same-object scope test. + + + **L518** Reuses the old actual observation for an empirical facet with unrestricted scope. + + + **L519** Changes its assessed claim to this same system meeting successorRequirements; the uncertainty predicate remains trivial. + + + **L521** In this example, the original identity contract retains its fulfilled duties; the changed successor contract fails for the same actual method, and the specified retained-observation package cannot ground it. + + + **L522** The original identity-output application fulfills ApplicationDuties for the actual system and world. + + + **L523** That positive instance uses the already supported capabilityFacet and its own constructed articulation. + + + **L524** But the same actual system does not meet the changed successor-output contract. + + + **L525** Nor does the changed claim acquire Grounds from the retained observation package. + + + **L526** This failure concerns exactly changedObjectiveFacet's singleton package, not every possible evidence package. + + + **L527** Builds the original duty from full owned reflexivity and capabilityGrounds, then leaves changed behavior and changed evidence failures. + + + **L528** Assumes the actual identity method meets the new successor contract. + + + **L529** At required input zero, this would force actual output zero to equal expected one. + + + **L530** Eliminates the impossible 0=1 equality, refuting the changed actual capability claim. + + + **L531** Assumes the retained observation singleton nevertheless gives Grounds for that changed claim. + + + **L532** Extracts the actual changedObjectiveFacet's discharge from that assumed Grounds package. + + + **L533** Its support rule applied to the compatible actual world and input zero yields the same false output equality 0=1. + + + **L534** Rejects that equality, proving the specified retained-observation package cannot ground the new claim. + + + **L536** Documents the following definition or result: Exhibits this actual charter-compliant system with compatible cost evidence whose specified capability facet is unsupported; other valid grounds can still exist. + + + **L537** Exhibits this actual charter-compliant system with compatible cost evidence whose specified capability facet is unsupported; other valid grounds can still exist. + + + **L538** The same actual system satisfies all represented Charter conditions. + + + **L539** Its actual world is compatible with the true at-most-two cost observation. + + + **L540** Nevertheless, that cost evidence does not provide Grounds for its output capability. + + + **L541** The denied Grounds is the particular unsupportedCapabilityFacet singleton, not every possible assessment bundle. + + + **L542** Combines charterChecked, direct compatibility of actual with the cost record, and the already proved unsupportedGrounds counterexample. + + + **L544** Documents the following definition or result: Constructs one shared system/world satisfying actual judgments, full reflexivity, capability evidence, feasible choice and each interpreted commitment's Grounds; it is a bounded model, not universal philosophical correctness. + + + **L545** Documents the following definition or result: Constructs one shared system/world satisfying actual judgments, full reflexivity, capability evidence, feasible choice and each interpreted commitment's Grounds; it is a bounded model, not universal philosophical correctness. + + + **L546** Constructs one shared system/world satisfying actual judgments, full reflexivity, capability evidence, feasible choice and each interpreted commitment's Grounds; it is a bounded model, not universal philosophical correctness. + + + **L547** Requires an actual system/world pair as the joint witness, so the combined claim is nonempty. + + + **L548** That same pair must be admissible for its jointly held/contextual claims and satisfy its Charter. + + + **L549** It must also have its own capability duty fulfilled by capabilityFacet and possess the claimed capability. + + + **L550** The same realized method must be feasibly chosen under its own requirements using objectiveReason. + + + **L551** For every one of the five commitments, the corresponding actual adoption claim must have Grounds. + + + **L552** Each commitment uses its own exact singleton value facet and corresponding applicability. + + + **L553** Finally identifies the witnesses with actualSystem and actual, preventing unrelated existential substitutions. + + + **L554** Chooses that exact pair and supplies its actual admissibility and checked Charter. + + + **L555** Adds this same system's owned capability duty, actual capability and justified identity choice. + + + **L556** Uses each commitment's existing Grounds proof, then closes the two witness-identity equalities by construction. + + + **L558** Closes the current namespace. + + +### `leanified/CoreReader/Logic.lean` + + +```lean +namespace CoreReader.Logic + +/- A claim denotes the worlds in which its content holds. -/ +abbrev Claim (W : Type) := W → Prop +/- A theory is a collection of simultaneously held claims. -/ +abbrev Theory (W : Type) := Claim W → Prop +/- A model satisfies every member of the whole theory. -/ +def Models {W : Type} (t : Theory W) (w : W) : Prop := ∀ p, t p → p w +/- Semantic entailment quantifies over all models. -/ +def Entails {W : Type} (t : Theory W) (p : Claim W) : Prop := ∀ w, Models t w → p w +/- Satisfiability requires an actual witness. -/ +def Satisfiable {W : Type} (t : Theory W) : Prop := ∃ w, Models t w +/- Assumptions, meanings and scope are distinct components; questions remain explicit. -/ +structure Context (W Q : Type) where + assumptions : Theory W + meaning : Q → Claim W + scope : Claim W +/- Admissible worlds satisfy held claims, assumptions and scope jointly. -/ +def Admissible {W Q : Type} (t : Theory W) (c : Context W Q) (w : W) : Prop := + Models t w ∧ Models c.assumptions w ∧ c.scope w +/- A negative judgment denies the very same question under the same meaning. -/ +def Consequence {W Q : Type} (t : Theory W) (c : Context W Q) (q : Q) (positive : Bool) : Prop := + ∀ w, Admissible t c w → if positive then c.meaning q w else ¬ c.meaning q w +/- The consistency obligation prohibits both consequences at one comparison basis. -/ +def Consistent {W Q : Type} (t : Theory W) (c : Context W Q) : Prop := + ∀ q, ¬ (Consequence t c q true ∧ Consequence t c q false) +/- An inhabited joint interpretation prevents opposite semantic consequences. -/ +theorem consequenceConsistency {W Q : Type} (t : Theory W) (c : Context W Q) + (inhabited : ∃ w, Admissible t c w) : Consistent t c := by + intro q h + obtain ⟨w, hw⟩ := inhabited + exact (h.2 w hw) (h.1 w hw) +/- Empty and singleton theories provide concrete semantic contexts. -/ +def emptyTheory {W : Type} : Theory W := fun _ => False +def singleton {W : Type} (p : Claim W) : Theory W := fun q => q = p +def union {W : Type} (a b : Theory W) : Theory W := fun p => a p ∨ b p +theorem modelsSingleton {W : Type} (p : Claim W) (w : W) : Models (singleton p) w ↔ p w := by + constructor + · intro h; exact h p rfl + · intro h q hq; cases hq; exact h +theorem modelsUnion {W : Type} (a b : Theory W) (w : W) : + Models (union a b) w ↔ Models a w ∧ Models b w := by + constructor + · intro h; exact ⟨fun p hp => h p (Or.inl hp), fun p hp => h p (Or.inr hp)⟩ + · rintro ⟨ha,hb⟩ p (hp|hp); exact ha p hp; exact hb p hp +/- The paired world records independent truth values for two questions. -/ +def premiseP : Claim (Bool × Bool) := fun w => w.1 = true +def premiseRule : Claim (Bool × Bool) := fun w => w.1 = true → w.2 = true +def premiseNotQ : Claim (Bool × Bool) := fun w => w.2 ≠ true +def jointTheory : Theory (Bool × Bool) := + union (singleton premiseP) (union (singleton premiseRule) (singleton premiseNotQ)) +/- Each premise has a model, but their joint implication makes the union unsatisfiable. -/ +theorem jointConflict : + Satisfiable (singleton premiseP) ∧ Satisfiable (singleton premiseRule) ∧ + Satisfiable (singleton premiseNotQ) ∧ ¬ Satisfiable jointTheory := by + refine ⟨⟨(true,true), (modelsSingleton _ _).2 rfl⟩, + ⟨(false,false), (modelsSingleton _ _).2 (by intro h; cases h)⟩, + ⟨(false,false), (modelsSingleton _ _).2 (by intro h; cases h)⟩, ?_⟩ + rintro ⟨w, hw⟩ + have hp := hw premiseP (Or.inl rfl) + have hr := hw premiseRule (Or.inr (Or.inl rfl)) + have hn := hw premiseNotQ (Or.inr (Or.inr rfl)) + exact hn (hr hp) +/- A retraction replaces the old singleton, rather than retaining both at the same time. -/ +def revisionSlice (time : Nat) : Theory Bool := + singleton (fun w => w = (time == 0)) +/- The initial and revised slices have models; keeping both would create a conflict. -/ +theorem revisionCanReverse : + Satisfiable (revisionSlice 0) ∧ Satisfiable (revisionSlice 1) ∧ + ¬ Satisfiable (union (revisionSlice 0) (revisionSlice 1)) := by + refine ⟨⟨true, (modelsSingleton _ _).2 rfl⟩, + ⟨false, (modelsSingleton _ _).2 rfl⟩, ?_⟩ + rintro ⟨w, hw⟩ + have hs := (modelsUnion _ _ _).1 hw + have hp := (modelsSingleton _ _).1 hs.1 + have hn := (modelsSingleton _ _).1 hs.2 + have bad : true = false := hp.symm.trans hn + cases bad +/- This basic question asks whether the represented switch is on. -/ +def onQuestion : Unit → Claim Bool := fun _ w => w = true +def assumptionContext (b : Bool) : Context Bool Unit := + ⟨singleton (fun w => w = b), onQuestion, fun _ => True⟩ +def meaningContext (b : Bool) : Context Bool Unit := + ⟨singleton (fun w => w = true), (fun _ w => w = b), fun _ => True⟩ +def scopeContext (b : Bool) : Context Bool Unit := + ⟨emptyTheory, onQuestion, fun w => w = b⟩ +/- Distinct assumptions, meanings and scopes each admit opposite judgments without same-context conflict. -/ +theorem contextDifferences : + (Consequence emptyTheory (assumptionContext true) () true ∧ + Consequence emptyTheory (assumptionContext false) () false) ∧ + (Consequence emptyTheory (meaningContext true) () true ∧ + Consequence emptyTheory (meaningContext false) () false) ∧ + (Consequence emptyTheory (scopeContext true) () true ∧ + Consequence emptyTheory (scopeContext false) () false) ∧ + (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w) := by + have empty : ∀ w : Bool, Models emptyTheory w := by intro w p hp; cases hp + refine ⟨⟨?_, ?_⟩, ⟨?_, ?_⟩, ⟨?_, ?_⟩, ?_, ?_, ?_⟩ + · intro w h; change w = true; exact (modelsSingleton (fun x : Bool => x = true) w).1 h.2.1 + · intro w h hp; have hn := (modelsSingleton _ _).1 h.2.1; cases hp.symm.trans hn + · intro w h; change w = true; exact (modelsSingleton (fun x : Bool => x = true) w).1 h.2.1 + · intro w h hn; have hp := (modelsSingleton _ _).1 h.2.1; cases hp.symm.trans hn + · intro w h; exact h.2.2 + · intro w h hp; cases hp.symm.trans h.2.2 + · intro b; exact ⟨b, empty b, (modelsSingleton _ _).2 rfl, trivial⟩ + · intro b; exact ⟨true, empty true, (modelsSingleton _ _).2 rfl, trivial⟩ + · intro b; exact ⟨b, empty b, empty b, rfl⟩ +/- Snapshots preserve identifiable adopted-form revisions even when semantic content agrees. -/ +structure Snapshot (W Q : Type) where + held : Theory W + context : Context W Q + revisionIdentity : Nat +/- Semantic equivalence compares represented content, not its list ordering. -/ +def SameContent {W Q : Type} (a b : Snapshot W Q) : Prop := + (∀ p, a.held p ↔ b.held p) ∧ + (∀ p, a.context.assumptions p ↔ b.context.assumptions p) ∧ + (∀ q w, a.context.meaning q w ↔ b.context.meaning q w) ∧ + (∀ w, a.context.scope w ↔ b.context.scope w) +/- The reporting norm covers both semantic change and independently identified revisions. -/ +def TruthfulReport {W Q : Type} (a b : Snapshot W Q) (reported : Bool) : Prop := + (¬ SameContent a b ∨ a.revisionIdentity ≠ b.revisionIdentity) → reported = true +/- A real represented change and compliance entail an acknowledged change. -/ +theorem semanticChangeMustBeReported {W Q : Type} (a b : Snapshot W Q) (reported : Bool) + (changed : ¬ SameContent a b ∨ a.revisionIdentity ≠ b.revisionIdentity) + (h : TruthfulReport a b reported) : reported = true := h changed +/- Reordering a two-claim presentation preserves the held theory extension. -/ +theorem representationOrderIrrelevant {W : Type} (p q : Claim W) : + ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r := by + intro r; exact or_comm +def contextSnapshot (c : Context Bool Unit) (revision : Nat := 0) : Snapshot Bool Unit := + ⟨emptyTheory, c, revision⟩ +/- Hiding each kind of contextual change violates the reporting interface; reporting alone supplies no truth guarantee. -/ +theorem hiddenContextChangeRejected : + ¬ TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (meaningContext true)) (contextSnapshot (meaningContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (scopeContext true)) (contextSnapshot (scopeContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (scopeContext true) 0) (contextSnapshot (scopeContext true) 1) false ∧ + (TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) true ∧ + ¬ Models (assumptionContext false).assumptions true) := by + have neq : (fun w : Bool => w = true) ≠ (fun w : Bool => w = false) := by + intro h; have k := congrFun h true; have z : true = false := k.mp rfl; cases z + refine ⟨?_, ?_, ?_, ?_, ?_⟩ + · intro h + have bad := h (Or.inl (by intro s; exact neq ((s.2.1 _).mp rfl))) + cases bad + · intro h + have bad := h (Or.inl (by intro s; have z := (s.2.2.1 () true).mp rfl; cases z)) + cases bad + · intro h + have bad := h (Or.inl (by intro s; have z := (s.2.2.2 true).mp rfl; cases z)) + cases bad + · intro h; have bad := h (Or.inr (by decide)); cases bad + · refine ⟨fun _ => rfl, ?_⟩ + intro h; have z := (modelsSingleton _ _).1 h; cases z +/- Two nonidentical resource objectives can share a feasible allocation. -/ +theorem tensionWithoutContradiction : + (∃ budget : Nat, 4 ≤ budget ∧ budget ≤ 6) ∧ + ¬ ((fun n : Nat => 4 ≤ n) = (fun n : Nat => n ≤ 6)) := by + refine ⟨⟨5, by decide, by decide⟩, ?_⟩ + intro h; have k := congrFun h 0; have bad : 4 ≤ 0 := k.mpr (by decide); cases bad +/- Conflicting conclusions cannot be retained under the same consistency obligation. -/ +theorem conflictRequiresChange {W Q : Type} (t : Theory W) (c : Context W Q) (q : Q) + (positive : Consequence t c q true) (negative : Consequence t c q false) : + ¬ Consistent t c := fun h => h q ⟨positive,negative⟩ +/- A satisfiable theory can have a false assumption at a specified actual world. -/ +theorem consistentFalse : Satisfiable (singleton (fun w : Bool => w = true)) ∧ + ¬ Models (singleton (fun w : Bool => w = true)) false := by + refine ⟨⟨true, (modelsSingleton _ _).2 rfl⟩, ?_⟩ + intro h; have bad := (modelsSingleton _ _).1 h; cases bad +/- The explicitly asked on/off question is undecided by the empty but inhabited theory. -/ +theorem consistentIncomplete : Satisfiable (emptyTheory : Theory Bool) ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true) ∧ + ¬ Entails emptyTheory (fun w : Bool => w ≠ true) := by + have empty : ∀ w : Bool, Models emptyTheory w := by intro w p hp; cases hp + refine ⟨⟨true, empty true⟩, ?_, ?_⟩ + · intro h; have bad := h false (empty false); cases bad + · intro h; exact h true (empty true) rfl +/- A claim can share a model with a theory without following in every model. -/ +theorem compatibilityNotEntailment : + Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true) := by + refine ⟨⟨true, (modelsUnion _ _ _).2 ⟨?_, (modelsSingleton _ _).2 rfl⟩⟩, + consistentIncomplete.2.1⟩ + intro p hp; cases hp + +end CoreReader.Logic +``` + + + + **L1** Open namespace CoreReader.Logic so subsequent declarations receive this module-qualified name. + + + **L3** Document the intended scope of Claim. The corresponding declaration concerns: A claim is a proposition-valued function on a supplied world type W; the world type is not restricted to a real-world interpretation. This comment is explanatory, not a proof premise. + + + **L4** Introduce the type abbreviation Claim. A claim is a proposition-valued function on a supplied world type W; the world type is not restricted to a real-world interpretation. + + + **L5** Document the intended scope of Theory. The corresponding declaration concerns: A theory is a predicate selecting claims, rather than a finite syntax or executable theory representation. This comment is explanatory, not a proof premise. + + + **L6** Introduce the type abbreviation Theory. A theory is a predicate selecting claims, rather than a finite syntax or executable theory representation. + + + **L7** Document the intended scope of Models. The corresponding declaration concerns: A world models a theory exactly when every selected claim holds at that world. This comment is explanatory, not a proof premise. + + + **L8** Define Models. A world models a theory exactly when every selected claim holds at that world. + + + **L9** Document the intended scope of Entails. The corresponding declaration concerns: Semantic entailment universally quantifies over worlds satisfying the theory. With no model it is vacuous. This comment is explanatory, not a proof premise. + + + **L10** Define Entails. Semantic entailment universally quantifies over worlds satisfying the theory. With no model it is vacuous. + + + **L11** Document the intended scope of Satisfiable. The corresponding declaration concerns: Satisfiability requires an actual witness world together with a proof that it models the theory. This comment is explanatory, not a proof premise. + + + **L12** Define Satisfiable. Satisfiability requires an actual witness world together with a proof that it models the theory. + + + **L13** Document the intended scope of Context. The corresponding declaration concerns: Packages contextual assumptions, question meanings, and a scope predicate; the interface does not validate these choices. This comment is explanatory, not a proof premise. + + + **L14** Declare the data interface Context. Packages contextual assumptions, question meanings, and a scope predicate; the interface does not validate these choices. + + + **L15** Store the actual contextual assumption theory, separately from the held theory. + + + **L16** Interpret each question as a proposition about each world. + + + **L17** Store the predicate selecting the admitted application scope. + + + **L18** Document the intended scope of Admissible. The corresponding declaration concerns: A world is admissible when the held theory, contextual assumptions, and scope all hold simultaneously. This comment is explanatory, not a proof premise. + + + **L19** Define Admissible. A world is admissible when the held theory, contextual assumptions, and scope all hold simultaneously. + + + **L20** Require this same world to model both theories and satisfy the contextual scope simultaneously. + + + **L21** Document the intended scope of Consequence. The corresponding declaration concerns: A signed consequence must hold in every admissible world: positive selects the question meaning and negative selects its negation. This comment is explanatory, not a proof premise. + + + **L22** Define Consequence. A signed consequence must hold in every admissible world: positive selects the question meaning and negative selects its negation. + + + **L23** Quantify over every admissible world; the sign selects either this question’s meaning or its negation. + + + **L24** Document the intended scope of Consistent. The corresponding declaration concerns: Consistency rules out simultaneously entailing a question and its negation for every question in Q. Empty Q makes this condition vacuous. This comment is explanatory, not a proof premise. + + + **L25** Define Consistent. Consistency rules out simultaneously entailing a question and its negation for every question in Q. Empty Q makes this condition vacuous. + + + **L26** For every question, prohibit the conjunction of its positive and negative consequences in this same context. + + + **L27** Document the intended scope of consequenceConsistency. The corresponding declaration concerns: Given an admissible witness, proves that no question can have both signed consequences. The witness is an explicit premise. This comment is explanatory, not a proof premise. + + + **L28** State the checked result consequenceConsistency. Given an admissible witness, proves that no question can have both signed consequences. The witness is an explicit premise. + + + **L29** Assume an admissible witness for the whole context and conclude its consistency; begin the proof. + + + **L30** Introduce an arbitrary question q and the hypothetical pair h of its positive and negative consequences in the same context. + + + **L31** Extract the common admissible world w and its entire theory/assumptions/scope proof hw from the explicit inhabited premise. + + + **L32** Evaluate both halves of h at the same w and hw; the negative consequence contradicts the positive consequence. + + + **L33** Document the intended scope of emptyTheory. The corresponding declaration concerns: Selects no claims, so every world models this theory. This comment is explanatory, not a proof premise. + + + **L34** Define emptyTheory. Selects no claims, so every world models this theory. + + + **L35** Define singleton. Selects exactly the claim equal to p; this uses equality of predicate functions. + + + **L36** Define union. Combines two sets of claims by disjunction of membership. + + + **L37** State the checked result modelsSingleton. Proves that modeling the singleton theory is equivalent to satisfying its sole claim. The following tactic block proves this explicit type. + + + **L38** Split the equivalence between satisfying the singleton theory and satisfying its sole claim into two implications. + + + **L39** Use the assumed singleton model h on p, whose membership follows from reflexive equality. + + + **L40** For any selected claim q, singleton membership identifies q with p; substitute that identity and return the assumed truth h of p. + + + **L41** State the checked result modelsUnion. Proves that modeling the union is equivalent to modeling both constituent theories at the same world. + + + **L42** State that the same world models the theory union exactly when it models both constituent theories. + + + **L43** Prove the model-of-union equivalence in its forward and reverse directions. + + + **L44** Restrict the union model h to each theory by embedding its membership proof into the left or right disjunct. + + + **L45** Unpack both constituent models, split a union membership into its two alternatives, and use the corresponding model on the same claim and world. + + + **L46** Document the intended scope of premiseP. The corresponding declaration concerns: Reads the first Boolean coordinate as true. This comment is explanatory, not a proof premise. + + + **L47** Define premiseP. Reads the first Boolean coordinate as true. + + + **L48** Define premiseRule. Makes truth of the first Boolean imply truth of the second. + + + **L49** Define premiseNotQ. Requires the second Boolean not to be true. + + + **L50** Define jointTheory. Combines the first-coordinate fact, the implication, and the negated second-coordinate fact. + + + **L51** Hold P, the rule P implies Q, and not Q together through nested theory unions. + + + **L52** Document the intended scope of jointConflict. The corresponding declaration concerns: Exhibits individual models of each of three claims, then proves their conjunction has no model. This comment is explanatory, not a proof premise. + + + **L53** State the checked result jointConflict. Exhibits individual models of each of three claims, then proves their conjunction has no model. + + + **L54** The first two conclusions provide separate models for P and its implication rule. + + + **L55** Also require a separate model for not Q, but deny any model of the entire joint theory. + + + **L56** Supply (true,true) as the model of P, using modelsSingleton to turn its first-coordinate equality into the required model proof. + + + **L57** Supply (false,false) for the implication premise: assuming its false first coordinate is true is impossible. + + + **L58** Supply (false,false) for not Q and leave the joint unsatisfiability branch to be proved. + + + **L59** Assume a joint model w with proof hw in order to refute its existence. + + + **L60** Extract the actual first-coordinate fact P from its left membership in the joint theory. + + + **L61** Extract P implies Q from the nested union membership of the rule. + + + **L62** Extract not Q from the other nested union branch at the same world. + + + **L63** Apply the rule to P to derive Q and contradict the extracted not Q. + + + **L64** Document the intended scope of revisionSlice. The corresponding declaration concerns: At time zero requires a true world; at every other natural time requires a false world. This comment is explanatory, not a proof premise. + + + **L65** Define revisionSlice. At time zero requires a true world; at every other natural time requires a false world. + + + **L66** Select the single claim that the world equals the Boolean result of testing time=0. + + + **L67** Document the intended scope of revisionCanReverse. The corresponding declaration concerns: Exhibits satisfiable time-zero and time-one slices whose union is unsatisfiable. No temporal update mechanism is implemented. This comment is explanatory, not a proof premise. + + + **L68** State the checked result revisionCanReverse. Exhibits satisfiable time-zero and time-one slices whose union is unsatisfiable. No temporal update mechanism is implemented. + + + **L69** Require time slices 0 and 1 to have separate model witnesses. + + + **L70** Deny a model of their simultaneous union; this does not deny either separate witness. + + + **L71** Give true as the witness for the time-zero singleton theory. + + + **L72** Give false as the witness for time one, and leave the impossibility of holding both slices together. + + + **L73** Assume a world satisfies both time slices simultaneously. + + + **L74** Split this union model into models of the time-zero and time-one theories at the same world. + + + **L75** Extract that the common world equals true from the time-zero singleton. + + + **L76** Extract that the same world equals false from the time-one singleton. + + + **L77** Compose the two equalities through the same world to derive the impossible equality true = false. + + + **L78** Eliminate the impossible equality between distinct Boolean constructors. + + + **L79** Document the intended scope of onQuestion. The corresponding declaration concerns: The sole Unit question asks whether the Boolean world is true. This comment is explanatory, not a proof premise. + + + **L80** Define onQuestion. The sole Unit question asks whether the Boolean world is true. + + + **L81** Define assumptionContext. Varies the assumption selecting the world while fixing its question meaning and unrestricted scope. + + + **L82** Select world b through assumptions, retain the same on-question, and allow every world in scope. + + + **L83** Define meaningContext. Fixes the world assumption to true but varies whether the question means equality to true or false. + + + **L84** Keep the true-world assumption while changing the question to equality with b; scope remains unrestricted. + + + **L85** Define scopeContext. Keeps assumptions empty and the question fixed while selecting the world through scope. + + + **L86** Leave assumptions empty and the question fixed, but let scope select world b. + + + **L87** Document the intended scope of contextDifferences. The corresponding declaration concerns: Proves that changing any one of assumptions, meaning, or scope can reverse polarity, with explicit admissible witnesses in all displayed contexts. This comment is explanatory, not a proof premise. + + + **L88** State the checked result contextDifferences. Proves that changing any one of assumptions, meaning, or scope can reverse polarity, with explicit admissible witnesses in all displayed contexts. + + + **L89** Require a positive answer under true-valued assumptions. + + + **L90** Require the negative answer under false-valued assumptions; the contexts differ. + + + **L91** Require a positive answer for the question meaning equality to true. + + + **L92** Require the negative answer when that question instead means equality to false. + + + **L93** Require the positive answer in the scope restricted to true. + + + **L94** Require the negative answer in the different scope restricted to false. + + + **L95** For either assumption selector, require an actual admissible world. + + + **L96** For either question meaning, require an actual admissible world. + + + **L97** For either scope selector, require an actual admissible world and begin the combined proof. + + + **L98** Show every Boolean world satisfies emptyTheory because membership in that theory is False. + + + **L99** Separate the positive/negative answer pairs for changed assumptions, meaning and scope, then the three nonempty-context witness obligations. + + + **L100** For the true-assumption context, read w = true from the contextual singleton assumptions. + + + **L101** For the false-assumption context, a proposed positive answer contradicts the singleton assumption w = false. + + + **L102** For the true meaning of the question, use the fixed true-world assumption to establish the positive answer. + + + **L103** For the changed false meaning, its proposed truth conflicts with the unchanged true-world assumption. + + + **L104** In the true-scope context, the scope component itself states the required positive answer. + + + **L105** In the false-scope context, a positive answer contradicts the scope component at the same world. + + + **L106** For either chosen assumption b, witness world b satisfies the empty held theory, that singleton assumption and unrestricted scope. + + + **L107** For either question meaning b, true remains a witness because the assumptions are fixed to true and scope is unrestricted. + + + **L108** For either scope selector b, world b satisfies both empty theories and the selected scope by equality. + + + **L109** Document the intended scope of Snapshot. The corresponding declaration concerns: Packages held claims, context and a natural-number revision identity; there is no history validation. This comment is explanatory, not a proof premise. + + + **L110** Declare the data interface Snapshot. Packages held claims, context and a natural-number revision identity; there is no history validation. + + + **L111** Store the theory of simultaneously held claims in the snapshot. + + + **L112** Store the snapshot’s assumptions, question meanings and scope as one Context. + + + **L113** Store a separate natural-number revision identifier; no history validation is implied. + + + **L114** Document the intended scope of SameContent. The corresponding declaration concerns: Defines sameness using claim-membership equivalence, contextual-assumption membership equivalence, pointwise meaning equivalence, and pointwise scope equivalence. This comment is explanatory, not a proof premise. + + + **L115** Define SameContent. Defines sameness using claim-membership equivalence, contextual-assumption membership equivalence, pointwise meaning equivalence, and pointwise scope equivalence. + + + **L116** Require identical held-claim membership for every claim in both snapshots. + + + **L117** Require identical membership for every contextual assumption. + + + **L118** Require equivalent question meanings for every question at every world. + + + **L119** Require equivalent scope predicates at every world. + + + **L120** Document the intended scope of TruthfulReport. The corresponding declaration concerns: Requires a true report if semantic content or revision identity differs. It allows a true report when neither differs and implements no detector. This comment is explanatory, not a proof premise. + + + **L121** Define TruthfulReport. Requires a true report if semantic content or revision identity differs. It allows a true report when neither differs and implements no detector. + + + **L122** Define truthful reporting as a positive flag whenever content differs or the independent revision identifiers differ. + + + **L123** Document the intended scope of semanticChangeMustBeReported. The corresponding declaration concerns: Instantiates the reporting interface with a supplied change proof; it cannot discover changes on its own. This comment is explanatory, not a proof premise. + + + **L124** State the checked result semanticChangeMustBeReported. Instantiates the reporting interface with a supplied change proof; it cannot discover changes on its own. + + + **L125** Assume an actual change: either content differs or the revision identifiers differ. + + + **L126** Assume the reporting obligation and apply it to the preceding change premise to obtain reported=true. + + + **L127** Document the intended scope of representationOrderIrrelevant. The corresponding declaration concerns: Proves swapping the order of two singleton components leaves theory membership unchanged. This comment is explanatory, not a proof premise. + + + **L128** State the checked result representationOrderIrrelevant. Proves swapping the order of two singleton components leaves theory membership unchanged. + + + **L129** For any claim r, swapping p and q preserves membership in their singleton-theory union. + + + **L130** For an arbitrary candidate claim r, use commutativity of disjunction to preserve union membership after reordering p and q. + + + **L131** Define contextSnapshot. Wraps a Boolean/Unit context in a snapshot with empty held theory and a default revision of zero. + + + **L132** Construct a snapshot with no held claims, the supplied context, and the supplied revision identifier. + + + **L133** Document the intended scope of hiddenContextChangeRejected. The corresponding declaration concerns: Rejects false reports for three concrete context changes and a revision-only change; also shows reporting true does not make an incompatible assumption hold. This comment is explanatory, not a proof premise. + + + **L134** State the checked result hiddenContextChangeRejected. Rejects false reports for three concrete context changes and a revision-only change; also shows reporting true does not make an incompatible assumption hold. + + + **L135** Reject a false report when actual contextual assumptions change from true to false. + + + **L136** Reject a false report when the question’s actual meaning changes. + + + **L137** Reject a false report when the actual application scope changes. + + + **L138** Reject a false report when revision identity changes from 0 to 1 despite unchanged context. + + + **L139** Permit truthful acknowledgement of the changed assumptions with a true report. + + + **L140** Nevertheless deny that those revised false-world assumptions hold at actual true. + + + **L141** Prepare a semantic inequality: the predicates selecting true and selecting false are distinct functions. + + + **L142** Evaluate any alleged predicate equality at true; it would turn reflexive truth into true = false. + + + **L143** Split the four rejected hidden changes from the final acknowledged-but-false-assumption example. + + + **L144** Assume the hidden assumption change with report=false satisfied TruthfulReport, in order to refute that claim. + + + **L145** A claimed SameContent would equate the changed assumption predicates; their established inequality activates TruthfulReport and forces the false flag to be true. + + + **L146** Close this hidden-change branch because the required true report contradicts the specified false flag. + + + **L147** Assume the changed question meaning could be truthfully reported as unchanged. + + + **L148** At the sole question and world true, the changed meaning contradicts SameContent; the reporting obligation then forces a positive report. + + + **L149** Close this hidden-change branch because the required true report contradicts the specified false flag. + + + **L150** Assume the changed application scope could satisfy the reporting rule with a false change flag. + + + **L151** Compare the two scopes at true to refute SameContent, then apply the reporting obligation to this real scope change. + + + **L152** Close this hidden-change branch because the required true report contradicts the specified false flag. + + + **L153** The distinct revision identities alone activate the reporting rule, contradicting the false report even without a content change. + + + **L154** Construct an always-positive truthful report, while leaving the separate truth of the revised assumption to be refuted. + + + **L155** Extract the revised false-world assumption at actual true; its impossible equality shows acknowledgement did not make it true. + + + **L156** Document the intended scope of tensionWithoutContradiction. The corresponding declaration concerns: Exhibits overlapping lower/upper budget bounds while proving that the two predicates differ. This is a concrete compatible-constraints example. This comment is explanatory, not a proof premise. + + + **L157** State the checked result tensionWithoutContradiction. Exhibits overlapping lower/upper budget bounds while proving that the two predicates differ. This is a concrete compatible-constraints example. + + + **L158** Ask for a natural-number budget satisfying both lower bound 4 and upper bound 6. + + + **L159** Also assert that the two bound predicates are not identical, even though jointly satisfiable. + + + **L160** Choose budget 5, check both numeric bounds, and leave the inequality of the two objective predicates. + + + **L161** At budget 0, the upper bound holds but the lower bound cannot; therefore the objective predicates cannot be equal. + + + **L162** Document the intended scope of conflictRequiresChange. The corresponding declaration concerns: Given both signed consequences for one question, proves inconsistency as defined. It does not construct a repair or establish which premise should change. This comment is explanatory, not a proof premise. + + + **L163** State the checked result conflictRequiresChange. Given both signed consequences for one question, proves inconsistency as defined. It does not construct a repair or establish which premise should change. + + + **L164** Assume both opposed consequences for exactly the same theory, context and question. + + + **L165** Any Consistent proof would forbid that given pair; apply it to refute consistency, without constructing a revision. + + + **L166** Document the intended scope of consistentFalse. The corresponding declaration concerns: Exhibits a satisfiable Boolean singleton theory that fails at the separately chosen world false; satisfiability is not truth at every world. This comment is explanatory, not a proof premise. + + + **L167** State the checked result consistentFalse. Exhibits a satisfiable Boolean singleton theory that fails at the separately chosen world false; satisfiability is not truth at every world. + + + **L168** Deny that actual false models the theory whose sole claim is world=true. + + + **L169** Provide true as a model of the singleton theory and separately refute modeling it at actual false. + + + **L170** Singleton modeling at false would force false = true, an impossible Boolean equality. + + + **L171** Document the intended scope of consistentIncomplete. The corresponding declaration concerns: Shows the empty Boolean theory is satisfiable while entailing neither the true-world claim nor its negation. This comment is explanatory, not a proof premise. + + + **L172** State the checked result consistentIncomplete. Shows the empty Boolean theory is satisfiable while entailing neither the true-world claim nor its negation. + + + **L173** The inhabited empty theory does not entail the positive true-world answer. + + + **L174** It also does not entail the negative true-world answer; prove these two failures separately. + + + **L175** Show every Boolean world satisfies emptyTheory because membership in that theory is False. + + + **L176** Provide an inhabited empty theory and leave both positive and negative entailments to be refuted. + + + **L177** A purported entailment of world=true fails at the empty theory model false. + + + **L178** A purported entailment of world≠true fails at the empty theory model true. + + + **L179** Document the intended scope of compatibilityNotEntailment. The corresponding declaration concerns: Shows that adding a claim can remain satisfiable even though the original empty theory did not entail that claim. This comment is explanatory, not a proof premise. + + + **L180** State the checked result compatibilityNotEntailment. Shows that adding a claim can remain satisfiable even though the original empty theory did not entail that claim. + + + **L181** Require a model where emptyTheory and the positive singleton claim hold together. + + + **L182** Still deny that emptyTheory by itself entails that positive claim. + + + **L183** Use world true to witness compatibility of the empty theory with the positive singleton claim. + + + **L184** Reuse the previously proved failure of positive entailment from the empty theory. + + + **L185** Finish the model witness: no claim can actually belong to emptyTheory. + + + **L187** Close namespace CoreReader.Logic; this adds no proof or premise. + + +### `leanified/CoreReader/Reflexivity.lean` + + +```lean +import Std + +namespace CoreReader.Agency + +inductive Phase | formation | application | revision + deriving DecidableEq, Repr + +structure PrincipleKey where + owner : Nat + localId : Nat + deriving DecidableEq, Repr + +inductive Subject + | system (owner : Nat) + | principle (owner id : Nat) + | process (owner id : Nat) (phase : Phase) + deriving DecidableEq, Repr + +def Subject.owner : Subject → Nat + | .system n => n + | .principle n _ => n + | .process n _ _ => n + +inductive Activity | generation | assessment + deriving DecidableEq, Repr + +inductive QuestionKind | conformity | formationBasis | applicability | revisionGrounds + deriving DecidableEq, Repr + +inductive SampleProgram | alwaysTrue | onlyAtZero + deriving DecidableEq, Repr + +def SampleProgram.run : SampleProgram → Nat → Bool + | .alwaysTrue, _ => true + | .onlyAtZero, n => n == 0 + +/- A generated candidate specifies both the inputs it tests and the scope it proposes to license. -/ +structure MethodDraft where + testedInputs : List Nat + claimedScope : List Nat + deriving DecidableEq, Repr + +def MethodDraft.accepts (draft : MethodDraft) (program : SampleProgram) : Bool := + draft.testedInputs.all program.run + +/- This finite application asks whether a proposed rule's observed inputs support its claimed input scope. -/ +structure Inquiry where + target : Subject + kind : QuestionKind + requestedScope : List Nat + currentMethod : MethodDraft + deriving DecidableEq, Repr + +inductive ReasonContent + | purpose (inputs : List Nat) + | declaredScope (inputs : List Nat) + | observation (input : Nat) (output : Bool) + | counterexample (program : SampleProgram) (input : Nat) + deriving DecidableEq, Repr + +def ReasonContent.identifier : ReasonContent → Nat + | .purpose _ => 0 + | .declaredScope _ => 1 + | .observation _ _ => 2 + | .counterexample _ _ => 3 + +/- Reasons have independently supplied contents, a stable local reference and the actual target they concern. -/ +structure ReasonObject where + reference : Nat + target : Subject + content : ReasonContent + deriving DecidableEq, Repr + +inductive AssessmentResult | supportedWithinScope | insufficient | notApplicable | undetermined + deriving DecidableEq, Repr + +inductive WorkOutcome + | assessment (result : AssessmentResult) + | generated (draft : MethodDraft) + deriving DecidableEq, Repr + +/- A method's question, source reasons and limits are determined before looking at its activity records. +The meaning relation describes application of that method, not its universal adequacy. -/ +structure Principle where + key : PrincipleKey + activity : Activity + declaredMethod : MethodDraft + applicable : Subject → Prop + inquiry : Subject → Inquiry + reasons : Subject → List ReasonObject + limits : Subject → List Nat + meaning : Inquiry → List ReasonObject → List Nat → WorkOutcome → Prop + +structure WorkRecord where + usedPrinciple : PrincipleKey + target : Subject + activity : Activity + inquiry : Inquiry + reasons : List ReasonObject + limits : List Nat + outcome : WorkOutcome + deriving DecidableEq, Repr + +def RegistryCoherent (rules : List Principle) : Prop := + ∀ p ∈ rules, ∀ q ∈ rules, p.key = q.key → p = q + +def TargetResolved (rules : List Principle) : Subject → Prop + | .system owner => ∃ p ∈ rules, p.key.owner = owner + | .principle owner id | .process owner id _ => ∃ p ∈ rules, p.key = ⟨owner,id⟩ + +/- The inquiry names the registered target's declared method contract, not an unrelated candidate. +For a system inquiry this finite model uses the registered generation contract as its assessed artifact. -/ +def TargetContentResolved (rules : List Principle) (question : Inquiry) : Prop := + match question.target with + | .system owner => ∃ p ∈ rules, p.key = ⟨owner,0⟩ ∧ question.currentMethod = p.declaredMethod + | .principle owner id | .process owner id _ => + ∃ p ∈ rules, p.key = ⟨owner,id⟩ ∧ question.currentMethod = p.declaredMethod + +def Performed (records : List WorkRecord) (s : Subject) (a : Activity) : Prop := + ∃ record ∈ records, record.target = s ∧ record.activity = a + +/- The old scope condition remains available without conflating scope with content completion. -/ +def ReflexiveScope (owner : Nat) (rules : List Principle) (records : List WorkRecord) : Prop := + ∀ rule ∈ rules, ∀ s, s.owner = owner → rule.applicable s → Performed records s rule.activity + +/- A record uses a registered principle on the same resolvable target, question, reasons and limits, +and its result must actually follow that principle's method. A negative result can satisfy this relation. -/ +structure ValidApplication (rules : List Principle) (rule : Principle) (s : Subject) + (record : WorkRecord) : Prop where + registered : rule ∈ rules + applicable : rule.applicable s + usedIdentity : record.usedPrinciple = rule.key + targetIdentity : record.target = s + targetResolved : TargetResolved rules s + activityIdentity : record.activity = rule.activity + inquiryIdentity : record.inquiry = rule.inquiry s + inquiryTarget : record.inquiry.target = s + targetContent : TargetContentResolved rules record.inquiry + reasonsIdentity : record.reasons = rule.reasons s + reasonsNonempty : record.reasons ≠ [] + reasonTargets : ∀ reason ∈ record.reasons, reason.target = s + limitsIdentity : record.limits = rule.limits s + followsMeaning : rule.meaning record.inquiry record.reasons record.limits record.outcome + +/- The registered normative interface requires contentful application, not just activity labels. -/ +def Reflexive (owner : Nat) (rules : List Principle) (records : List WorkRecord) : Prop := + RegistryCoherent rules ∧ + ∀ rule ∈ rules, ∀ s, s.owner = owner → rule.applicable s → + ∃ record ∈ records, ValidApplication rules rule s record + +theorem Reflexive.toScope {owner : Nat} {rules : List Principle} {records : List WorkRecord} + (h : Reflexive owner rules records) : ReflexiveScope owner rules records := by + intro rule hr s hs ha + obtain ⟨record, hm, hv⟩ := h.2 rule hr s hs ha + exact ⟨record, hm, hv.targetIdentity, hv.activityIdentity⟩ + +theorem noSelfExemption (owner : Nat) (rules : List Principle) (records : List WorkRecord) + (h : Reflexive owner rules records) (rule : Principle) (hr : rule ∈ rules) + (s : Subject) (hs : s.owner = owner) (ha : rule.applicable s) : + Performed records s rule.activity := h.toScope rule hr s hs ha + +def localMethod : MethodDraft := ⟨[0],[0]⟩ + +def inquiryFor (s : Subject) : Inquiry := + match s with + | .process _ _ .formation => ⟨s, .formationBasis, [0], localMethod⟩ + | .process _ _ .application => ⟨s, .applicability, [0], localMethod⟩ + | .process _ _ .revision => ⟨s, .revisionGrounds, [0,1], localMethod⟩ + | _ => ⟨s, .conformity, [0], localMethod⟩ + +/- These original inquiry inputs do not depend on which work records happen to be present. -/ +def sourceReasonContents : QuestionKind → List ReasonContent + | .formationBasis => [.purpose [0], .declaredScope [0], .observation 0 true] + | .applicability | .conformity => [.declaredScope [0], .observation 0 true] + | .revisionGrounds => [.purpose [0,1], .declaredScope [0], .observation 0 true, + .counterexample .onlyAtZero 1] + +def reasonsFor (s : Subject) : List ReasonObject := + (sourceReasonContents (inquiryFor s).kind).map fun content => ⟨content.identifier,s,content⟩ + +/- The application-specific evaluator examines actual scope and sample/counterexample contents. +It is a finite inferential method, not a universal standard for empirical or value claims. -/ +def assessInquiry (question : Inquiry) (reasons : List ReasonObject) (limits : List Nat) : AssessmentResult := + let contents := reasons.map ReasonObject.content + if limits ≠ question.currentMethod.claimedScope then .undetermined else + match question.kind with + | .formationBasis => + if ReasonContent.purpose question.requestedScope ∈ contents ∧ + ReasonContent.declaredScope limits ∈ contents ∧ question.requestedScope = limits + then .supportedWithinScope else .undetermined + | .applicability | .conformity => + if question.requestedScope.all (fun n => limits.contains n) then + if ReasonContent.declaredScope limits ∈ contents ∧ + ReasonContent.observation 0 true ∈ contents ∧ question.requestedScope = [0] + then .supportedWithinScope else .undetermined + else .notApplicable + | .revisionGrounds => + if ReasonContent.purpose question.requestedScope ∈ contents ∧ + ReasonContent.declaredScope limits ∈ contents ∧ + ReasonContent.observation 0 true ∈ contents ∧ + contents.any (fun reason => match reason with + | .counterexample program input => question.requestedScope.contains input && + question.currentMethod.accepts program && + !(program.run input) + | _ => false) + then .insufficient else .undetermined + +def finiteMethodResult (activity : Activity) (question : Inquiry) + (reasons : List ReasonObject) (limits : List Nat) : WorkOutcome := + match activity with + | .generation => .generated ⟨question.currentMethod.testedInputs,question.requestedScope⟩ + | .assessment => .assessment (assessInquiry question reasons limits) + +def finiteMethodMeaning (activity : Activity) (question : Inquiry) + (reasons : List ReasonObject) (limits : List Nat) (outcome : WorkOutcome) : Prop := + outcome = finiteMethodResult activity question reasons limits + +def ownSubjects (owner : Nat) : List Subject := + [.system owner, .principle owner 0, .principle owner 1, + .process owner 0 .formation, .process owner 0 .application, .process owner 0 .revision, + .process owner 1 .formation, .process owner 1 .application, .process owner 1 .revision] + +/- Applying an existing rule is not a generation event in this application. -/ +def generationEligible : Subject → Bool + | .process _ _ .application => false + | _ => true + +def generatingRule (owner : Nat) : Principle where + key := ⟨owner,0⟩ + activity := .generation + declaredMethod := localMethod + applicable s := s ∈ ownSubjects owner ∧ generationEligible s = true + inquiry := inquiryFor + reasons := reasonsFor + limits _ := [0] + meaning := finiteMethodMeaning .generation + +def assessingRule (owner : Nat) : Principle where + key := ⟨owner,1⟩ + activity := .assessment + declaredMethod := localMethod + applicable s := s ∈ ownSubjects owner + inquiry := inquiryFor + reasons := reasonsFor + limits _ := [0] + meaning := finiteMethodMeaning .assessment + +def ownRules (owner : Nat) : List Principle := [generatingRule owner, assessingRule owner] + +/- Recorded verdicts are stated separately from the evaluator, so agreement has to be proved. -/ +def statedOutcome (activity : Activity) (s : Subject) : WorkOutcome := + match activity with + | .generation => .generated ⟨(inquiryFor s).currentMethod.testedInputs,(inquiryFor s).requestedScope⟩ + | .assessment => .assessment (match (inquiryFor s).kind with + | .revisionGrounds => .insufficient + | _ => .supportedWithinScope) + +def recordFor (rule : Principle) (s : Subject) : WorkRecord := + ⟨rule.key,s,rule.activity,rule.inquiry s,rule.reasons s,rule.limits s,statedOutcome rule.activity s⟩ + +theorem reasonsFor_nonempty (s : Subject) : reasonsFor s ≠ [] := by + cases s with + | system owner => simp [reasonsFor, inquiryFor, sourceReasonContents] + | principle owner id => simp [reasonsFor, inquiryFor, sourceReasonContents] + | process owner id phase => cases phase <;> simp [reasonsFor, inquiryFor, sourceReasonContents] + +theorem reasonsFor_target (s : Subject) : ∀ reason ∈ reasonsFor s, reason.target = s := by + intro reason h + obtain ⟨content, _, rfl⟩ := List.mem_map.mp h + rfl + +theorem inquiryFor_target (s : Subject) : (inquiryFor s).target = s := by + cases s with + | system owner => rfl + | principle owner id => rfl + | process owner id phase => cases phase <;> rfl + +/- This proof includes the actual negative revision evaluation for both principle identities. -/ +theorem ownContentEvaluates (activity : Activity) (s : Subject) : + statedOutcome activity s = finiteMethodResult activity (inquiryFor s) (reasonsFor s) [0] := by + cases activity with + | generation => rfl + | assessment => + cases s with + | system owner => rfl + | principle owner id => rfl + | process owner id phase => cases phase <;> rfl + +theorem ownRegistryCoherent (owner : Nat) : RegistryCoherent (ownRules owner) := by + intro p hp q hq hkey + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hp hq + rcases hp with rfl | rfl <;> rcases hq with rfl | rfl + · rfl + · have bad := congrArg PrincipleKey.localId hkey; contradiction + · have bad := congrArg PrincipleKey.localId hkey; contradiction + · rfl + +theorem ownTargetResolved (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) : + TargetResolved (ownRules owner) s := by + simp only [ownSubjects, List.mem_cons, List.not_mem_nil, or_false] at hs + rcases hs with rfl | rfl | rfl | rfl | rfl | rfl | rfl | rfl | rfl <;> + simp [TargetResolved, ownRules, generatingRule, assessingRule] + +theorem ownTargetContent (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) : + TargetContentResolved (ownRules owner) (inquiryFor s) := by + simp only [ownSubjects, List.mem_cons, List.not_mem_nil, or_false] at hs + rcases hs with rfl | rfl | rfl | rfl | rfl | rfl | rfl | rfl | rfl <;> + simp [TargetContentResolved, inquiryFor, ownRules, generatingRule, assessingRule] + +theorem ownRecordValid (owner : Nat) (rule : Principle) (hr : rule ∈ ownRules owner) + (s : Subject) (ha : rule.applicable s) : + ValidApplication (ownRules owner) rule s (recordFor rule s) := by + have hs : s ∈ ownSubjects owner := by + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl + · exact ha.1 + · exact ha + have hq : rule.inquiry = inquiryFor := by + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl <;> rfl + have hg : rule.reasons = reasonsFor := by + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl <;> rfl + have hl : rule.limits s = [0] := by + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl <;> rfl + have hm : rule.meaning = finiteMethodMeaning rule.activity := by + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl <;> rfl + refine ⟨hr, ha, rfl, rfl, ownTargetResolved owner s hs, rfl, rfl, ?_, ?_, rfl, ?_, ?_, rfl, ?_⟩ + · change (rule.inquiry s).target = s + rw [hq]; exact inquiryFor_target s + · change TargetContentResolved (ownRules owner) (rule.inquiry s) + rw [hq]; exact ownTargetContent owner s hs + · change rule.reasons s ≠ [] + rw [hg]; exact reasonsFor_nonempty s + · change ∀ reason ∈ rule.reasons s, reason.target = s + rw [hg]; exact reasonsFor_target s + · change rule.meaning (rule.inquiry s) (rule.reasons s) (rule.limits s) (statedOutcome rule.activity s) + rw [hm, hq, hg, hl] + exact ownContentEvaluates rule.activity s + +def completeOwnWork (owner : Nat) : List WorkRecord := + (ownSubjects owner).flatMap fun s => + if generationEligible s then [recordFor (generatingRule owner) s, recordFor (assessingRule owner) s] + else [recordFor (assessingRule owner) s] + +theorem assessingRecord_member (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) : + recordFor (assessingRule owner) s ∈ completeOwnWork owner := by + apply List.mem_flatMap.mpr + refine ⟨s,hs,?_⟩ + cases generationEligible s <;> simp + +theorem generatingRecord_member (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) + (hg : generationEligible s = true) : recordFor (generatingRule owner) s ∈ completeOwnWork owner := by + exact List.mem_flatMap.mpr ⟨s,hs,by simp [hg]⟩ + +theorem completeOwnWork_reflexive (owner : Nat) : + Reflexive owner (ownRules owner) (completeOwnWork owner) := by + refine ⟨ownRegistryCoherent owner, ?_⟩ + intro rule hr s _ ha + refine ⟨recordFor rule s, ?_, ownRecordValid owner rule hr s ha⟩ + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl + · exact generatingRecord_member owner s ha.1 ha.2 + · exact assessingRecord_member owner s ha + +theorem ownAssessmentPerformed (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) : + Performed (completeOwnWork owner) s .assessment := + ⟨recordFor (assessingRule owner) s, assessingRecord_member owner s hs, rfl, rfl⟩ + +def applicationRule : Principle := + { assessingRule 0 with key := ⟨0,0⟩, applicable := fun s => s = .process 0 0 .application } + +def applicationWork : List WorkRecord := [recordFor applicationRule (.process 0 0 .application)] + +theorem applicationWork_reflexive : Reflexive 0 [applicationRule] applicationWork := by + constructor + · intro p hp q hq _ + simp only [List.mem_singleton] at hp hq + rw [hp,hq] + · intro rule hr s _ ha + simp only [List.mem_singleton] at hr + subst rule + change s = .process 0 0 .application at ha + subst s + refine ⟨recordFor applicationRule (.process 0 0 .application), by simp [applicationWork], ?_⟩ + refine ⟨by simp, rfl, rfl, rfl, ?_, rfl, rfl, rfl, ?_, rfl, ?_, ?_, rfl, ?_⟩ + · exact ⟨applicationRule, by simp, rfl⟩ + · exact ⟨applicationRule, by simp, rfl, rfl⟩ + · exact reasonsFor_nonempty _ + · exact reasonsFor_target _ + · change statedOutcome .assessment (.process 0 0 .application) = finiteMethodResult .assessment (inquiryFor (.process 0 0 .application)) (reasonsFor (.process 0 0 .application)) [0] + exact ownContentEvaluates .assessment _ + +theorem applicabilityRetained (owner : Nat) (rules : List Principle) (records : List WorkRecord) : + (Reflexive owner rules records → ReflexiveScope owner rules records) ∧ + (ReflexiveScope owner rules records ↔ + ∀ rule ∈ rules, ∀ s, s.owner = owner → (¬ rule.applicable s ∨ Performed records s rule.activity)) ∧ + (Reflexive 0 [applicationRule] applicationWork ∧ + ¬ Performed applicationWork (.system 0) .assessment) := by + classical + refine ⟨Reflexive.toScope, ?_, applicationWork_reflexive, ?_⟩ + · constructor + · intro h rule hr s hs + by_cases ha : rule.applicable s + · exact Or.inr (h rule hr s hs ha) + · exact Or.inl ha + · intro h rule hr s hs ha + exact (h rule hr s hs).resolve_left (not_not_intro ha) + · rintro ⟨record, hm, ht, _⟩ + simp only [applicationWork, List.mem_singleton] at hm + subst record + cases ht + +end CoreReader.Agency +``` + + + + **L1** Imports Std and its dependencies into this module. + + + **L3** Opens namespace CoreReader.Agency; file boundaries do not change declaration identity. + + + **L5** Defines formation, application and revision phase tags. + + + **L6** Generates decidable equality and display instances for the preceding datatype. + + + **L8** Identifies a registered principle by owner and local identifier. + + + **L9** Stores the owning subject identifier. + + + **L10** Stores the principle identifier within its owner. + + + **L11** Generates decidable equality and display instances for the preceding datatype. + + + **L13** Distinguishes system, principle and phase-indexed principle-process objects. + + + **L14** Represents the system itself, identified by its owner number. + + + **L15** Represents a particular principle by owner and local principle identifier. + + + **L16** Represents that principle's formation, application or revision process as a separate subject. + + + **L17** Generates decidable equality and display instances for the preceding datatype. + + + **L19** Extracts the owner's identifier from every subject constructor. + + + **L20** Extracts the owner directly from a system subject. + + + **L21** Extracts a principle's owner while ignoring its local identifier. + + + **L22** Extracts a process subject's owner independently of its principle identifier and phase. + + + **L24** Distinguishes generation work from assessment work. + + + **L25** Generates decidable equality and display instances for the preceding datatype. + + + **L27** Separates conformity, formation basis, applicability and revision-ground questions. + + + **L28** Generates decidable equality and display instances for the preceding datatype. + + + **L30** Provides a constant-true program and a program true only at zero. + + + **L31** Generates decidable equality and display instances for the preceding datatype. + + + **L33** Evaluates those two programs on natural inputs. + + + **L34** The alwaysTrue sample program accepts every natural-number input. + + + **L35** The onlyAtZero program returns true precisely at input zero. + + + **L37** Documents the following definition or result: Stores tested inputs separately from the claimed scope, allowing overextended claims. + + + **L38** Stores tested inputs separately from the claimed scope, allowing overextended claims. + + + **L39** Records the inputs on which this method draft actually tests a program. + + + **L40** Separately records the input scope the draft proposes to authorize. + + + **L41** Generates decidable equality and display instances for the preceding datatype. + + + **L43** Accepts a program when it succeeds on all listed test inputs; untested inputs are unchecked. + + + **L44** Accepts a program when every tested input returns true; claimedScope is not checked here. + + + **L46** Documents the following definition or result: Binds a target and question kind to requested scope and the target's current method content. + + + **L47** Binds a target and question kind to requested scope and the target's current method content. + + + **L48** Identifies the exact subject whose method is being examined. + + + **L49** Distinguishes conformity, formation reasons, applicability and revision reasons as inquiry purposes. + + + **L50** Records the input scope this particular inquiry asks the method to cover. + + + **L51** Attaches the actual method draft under examination, including its tested and claimed inputs. + + + **L52** Generates decidable equality and display instances for the preceding datatype. + + + **L54** Represents purposes, declared scopes, observations and concrete program/input counterexamples. + + + **L55** A purpose reason names the inputs the method is intended to address. + + + **L56** A scope reason states the method's declared input limits. + + + **L57** An observation reason records a specific input and Boolean output. + + + **L58** A counterexample reason names an actual sample program and input to check. + + + **L59** Generates decidable equality and display instances for the preceding datatype. + + + **L61** Assigns a small code to each reason constructor; the code alone is not evidential content. + + + **L62** Uses local reference 0 for purpose reasons; this is a category identifier, not a unique global identity. + + + **L63** Uses local reference 1 for declared-scope reasons. + + + **L64** Uses local reference 2 for observation reasons. + + + **L65** Uses local reference 3 for counterexample reasons. + + + **L67** Documents the following definition or result: Attaches a reason's content and reference to the subject it concerns. + + + **L68** Attaches a reason's content and reference to the subject it concerns. + + + **L69** Stores a local reference identifying this reason in the modeled inquiry. + + + **L70** Identifies the subject this reason actually concerns. + + + **L71** Stores the purpose, scope, observation or counterexample contents of the reason. + + + **L72** Generates decidable equality and display instances for the preceding datatype. + + + **L74** Allows scoped support, insufficiency, nonapplicability and undetermined results. + + + **L75** Generates decidable equality and display instances for the preceding datatype. + + + **L77** Separates an assessment result from a generated method draft. + + + **L78** Packages a verdict as an assessment outcome; a negative verdict is still an assessment. + + + **L79** Packages a newly generated method draft, without asserting that the draft is correct. + + + **L80** Generates decidable equality and display instances for the preceding datatype. + + + **L82** Documents the following definition or result: Registers a rule's identity, activity, declared method, applicability, inquiries, reasons, limits and explicit outcome semantics. + + + **L83** Documents the following definition or result: Registers a rule's identity, activity, declared method, applicability, inquiries, reasons, limits and explicit outcome semantics. + + + **L84** Registers a rule's identity, activity, declared method, applicability, inquiries, reasons, limits and explicit outcome semantics. + + + **L85** Gives the principle an owner/local identifier used to resolve its records. + + + **L86** Specifies whether this principle governs generation or assessment activity. + + + **L87** States the method draft belonging to this registered principle. + + + **L88** States the subjects on which this principle is applicable. + + + **L89** Assigns the actual question to examine for each subject. + + + **L90** Assigns the reasons supplied for each subject's question. + + + **L91** Assigns the retained input limits for each subject's application. + + + **L92** Defines when an outcome follows this principle's question, reasons and limits; no adequacy law is imposed by this field alone. + + + **L94** Stores the actual rule identity, target, activity, inquiry, reasons, limits and outcome used by an application. + + + **L95** Records the exact registered principle key claimed to have been used. + + + **L96** Records the subject on which this work was performed. + + + **L97** Records whether this work was generation or assessment. + + + **L98** Stores the concrete inquiry actually recorded for this work. + + + **L99** Stores the concrete reasons used in this work record. + + + **L100** Stores the input limits retained in this work record. + + + **L101** Stores the recorded assessment verdict or generated method draft. + + + **L102** Generates decidable equality and display instances for the preceding datatype. + + + **L104** Requires equal registered keys to identify the same principle, preventing ambiguous duplicate identities. + + + **L105** Two registered principles sharing one key must be the same principle, preventing ambiguous lookup. + + + **L107** Requires each assessed target to resolve to a registered owner or exact principle key. + + + **L108** A system subject is resolved when the registry contains some principle with that owner. + + + **L109** Principle and process subjects require a registry entry with their exact owner and local identifier. + + + **L111** Documents the following definition or result: Connects the inquiry's current method to the registered target principle's declared method. + + + **L112** Documents the following definition or result: Connects the inquiry's current method to the registered target principle's declared method. + + + **L113** Connects the inquiry's current method to the registered target principle's declared method. + + + **L114** Chooses the lookup rule from the inquiry's actual target kind. + + + **L115** A system inquiry examines the declared method of its owner's registered principle zero. + + + **L116** For a principle or its process, retain that target's actual owner and identifier for lookup. + + + **L117** Requires both exact key lookup and equality between the inquiry's method and that registered principle's method. + + + **L119** Requires an actual stored record with the requested target and activity; validity is checked separately. + + + **L120** Performed means a listed record has this exact subject and activity; by itself it checks no reason contents. + + + **L122** Documents the following definition or result: Retains the owner-and-applicability-conditioned record-coverage interface. + + + **L123** Retains the owner-and-applicability-conditioned record-coverage interface. + + + **L124** Every applicable registered rule must have a performed activity on subjects belonging to the specified owner. + + + **L126** Documents the following definition or result: Checks rule registration, applicability, object identities, resolved method content, nonempty targeted reasons, exact limits and agreement with the rule's semantics. + + + **L127** Documents the following definition or result: Checks rule registration, applicability, object identities, resolved method content, nonempty targeted reasons, exact limits and agreement with the rule's semantics. + + + **L128** Checks rule registration, applicability, object identities, resolved method content, nonempty targeted reasons, exact limits and agreement with the rule's semantics. + + + **L129** The following proof fields certify one particular work record as a valid use of rule on s. + + + **L130** Requires the rule used by the record to belong to this registry. + + + **L131** Requires that same rule to be applicable to the assessed subject. + + + **L132** Checks the record's used-principle key against this rule's exact key. + + + **L133** Checks that the work record targets this exact subject s. + + + **L134** Requires the record's subject to resolve within the same rule registry. + + + **L135** Checks that the recorded activity is the activity governed by this rule. + + + **L136** Checks that the recorded inquiry equals the inquiry this rule assigns to s. + + + **L137** Separately checks that the inquiry itself targets s, rather than an unrelated subject. + + + **L138** Checks that the inquiry's method belongs to its resolved registered target. + + + **L139** Checks the recorded reasons equal those specified by this rule for s. + + + **L140** Requires at least one actual reason in this record. + + + **L141** Requires every recorded reason to concern the same subject s. + + + **L142** Checks that recorded limits equal the rule's limits for s. + + + **L143** Requires the record's outcome to satisfy the rule's actual meaning relation on its inquiry, reasons and limits. + + + **L145** Documents the following definition or result: Requires a coherent registry and a valid recorded application for every applicable same-owner subject and registered rule; this remains a model compliance condition. + + + **L146** Requires a coherent registry and a valid recorded application for every applicable same-owner subject and registered rule; this remains a model compliance condition. + + + **L147** Reflexive first requires unambiguous principle registration. + + + **L148** It then ranges over each registered rule and owned subject where that rule is applicable. + + + **L149** For each such application, some listed record must satisfy all ValidApplication content checks. + + + **L151** Forgets content-validity details while extracting target/activity record coverage from full reflexivity. + + + **L152** Assumes full contentful Reflexive compliance and derives its weaker scope-only coverage. + + + **L153** Takes a registered rule, an owned subject and its applicability premise for the scope obligation. + + + **L154** Uses full Reflexive compliance to obtain the actual listed record and its ValidApplication proof. + + + **L155** Keeps that record's membership, target identity and activity identity to prove Performed. + + + **L157** Instantiates full reflexivity at a registered applicable same-owner subject, then extracts its performance record. + + + **L158** Requires full Reflexive compliance and actual membership of the rule in the registry. + + + **L159** Also requires the target's owner to match and the rule to be applicable to it. + + + **L160** Specializes the derived scope obligation to those premises, yielding this target's performed activity. + + + **L162** Tests input zero and declares scope zero. + + + **L164** Maps formation to basis, application to applicability, revision to grounds over zero and one, and other objects to conformity. + + + **L165** Chooses the inquiry from the subject's process phase, retaining the same subject as target. + + + **L166** For formation, asks about the basis for a method covering input zero. + + + **L167** For application, asks whether the local method applies on input zero. + + + **L168** For revision, asks about extending the same local method's scope to inputs zero and one. + + + **L169** For a system or principle itself, asks conformity on the local scope {0}. + + + **L171** Documents the following definition or result: Supplies question-specific purpose/scope/observation data, adding a failing untested-input program for revision review. + + + **L172** Supplies question-specific purpose/scope/observation data, adding a failing untested-input program for revision review. + + + **L173** Formation reasons state the purpose {0}, declared scope {0}, and the observed true result at zero. + + + **L174** Applicability and conformity use the declared local scope plus the same observation at zero. + + + **L175** Revision reasons request {0,1} while acknowledging a declared scope of {0} and only a zero observation. + + + **L176** Adds the concrete onlyAtZero program at input one as a revision counterexample. + + + **L178** Attaches every chosen reason's content to this exact inquiry target. + + + **L179** Wraps each source reason with its category reference and the same subject s, preserving its actual content. + + + **L181** Documents the following definition or result: Computes scoped results from actual reason contents and method scope; a program passing current tests but failing a requested input yields insufficiency for revision. + + + **L182** Documents the following definition or result: Computes scoped results from actual reason contents and method scope; a program passing current tests but failing a requested input yields insufficiency for revision. + + + **L183** Computes scoped results from actual reason contents and method scope; a program passing current tests but failing a requested input yields insufficiency for revision. + + + **L184** Extracts reason contents for checking their substantive purpose, scope, observations and counterexamples. + + + **L185** Returns undetermined if supplied limits differ from the examined method's declared scope. + + + **L186** After checking limits, evaluates the specific kind of question asked. + + + **L187** Selects the formation-basis assessment branch. + + + **L188** Requires a purpose reason covering the inquiry's requested inputs. + + + **L189** Also requires an explicit limit declaration and equality of requested and declared scopes. + + + **L190** Formation is supportedWithinScope only when those content checks pass; otherwise it is undetermined. + + + **L191** Uses the same local checks for applicability and conformity questions. + + + **L192** First tests that every requested input belongs to the supplied limits. + + + **L193** Within those limits, requires a reason explicitly declaring that same scope. + + + **L194** Also requires the true observation at zero and a requested scope exactly equal to [0]. + + + **L195** Passing these local checks yields supportedWithinScope; incomplete evidence yields undetermined. + + + **L196** A requested input outside the supplied limits yields notApplicable. + + + **L197** Selects the revision-grounds branch, which searches for an actual scope counterexample. + + + **L198** Requires a reason stating the revised requested scope as the intended purpose. + + + **L199** Requires the old limits to be explicitly present as a declared-scope reason. + + + **L200** Requires the original successful observation at input zero. + + + **L201** Searches the supplied reason contents for a counterexample satisfying the following concrete checks. + + + **L202** A counterexample's input must be inside the newly requested scope. + + + **L203** Its program must nevertheless pass the current method's tested inputs. + + + **L204** That same program must fail at the counterexample input. + + + **L205** Other reason kinds cannot themselves satisfy this counterexample search. + + + **L206** A witnessed testing/scope gap yields insufficient; without those contents, the result is undetermined. + + + **L208** Generation keeps tested inputs and adopts requested scope; assessment executes the reason-sensitive inquiry evaluator. + + + **L209** Supplies the same reasons and limits to the activity-specific result function. + + + **L210** Chooses between generating a draft and evaluating an inquiry. + + + **L211** Generation keeps the method's tested inputs but proposes the inquiry's requested scope; correctness is not certified. + + + **L212** Assessment computes assessInquiry from this question's actual reasons and limits. + + + **L214** Defines acceptable outcome by equality with the disclosed finite evaluation algorithm, not an assumed successful result. + + + **L215** Receives the specific recorded outcome whose compliance with this activity's method is checked. + + + **L216** An outcome follows the method exactly when it equals the computed finiteMethodResult. + + + **L218** Enumerates the owner system, both registered principles and all three phases of each principle. + + + **L219** Includes the system itself and its two principle identities as owned subjects. + + + **L220** Includes formation, application and revision of principle zero as separate subjects. + + + **L221** Also includes all three phases of principle one, giving nine owned subjects total. + + + **L223** Documents the following definition or result: Excludes application-phase processes from this particular generation rule while retaining the other objects. + + + **L224** Excludes application-phase processes from this particular generation rule while retaining the other objects. + + + **L225** Treats applying an already existing principle as ineligible for generation in this application model. + + + **L226** All other represented subject kinds remain eligible for generation. + + + **L228** Registers principle zero for generation with the local method, explicit inquiries/reasons and restricted applicability. + + + **L229** Registers the generation principle under local key zero for this owner. + + + **L230** Makes this rule govern generation work. + + + **L231** Assigns the local test-and-scope draft [0]/[0] to the generation rule. + + + **L232** Generation requires both membership in this owner's nine subjects and generation eligibility. + + + **L233** Uses inquiryFor to supply the subject's actual phase-sensitive question. + + + **L234** Uses reasonsFor to supply the original target-linked reason contents. + + + **L235** Retains [0] as the generation rule's limit for every subject. + + + **L236** Requires the generated outcome to match finiteMethodResult's generation branch. + + + **L238** Registers principle one for assessment of every enumerated own subject with explicit finite evaluation semantics. + + + **L239** Registers the assessment principle under distinct local key one. + + + **L240** Makes this rule govern assessment work. + + + **L241** The assessment principle declares the same local [0]/[0] method contract. + + + **L242** Assessment applies to all nine subjects belonging to this owner. + + + **L243** Assigns the same phase-sensitive inquiry function to the assessment rule. + + + **L244** Assigns the same original target-linked reasons to its assessments. + + + **L245** Retains [0] as the assessment rule's declared limit. + + + **L246** Requires assessment outcomes to equal the evaluator's actual result. + + + **L248** Returns the two distinct registered generation and assessment principles. + + + **L250** Documents the following definition or result: Constructs expected generated drafts and scoped/insufficient assessment results, which are subsequently checked against evaluation. + + + **L251** Constructs expected generated drafts and scoped/insufficient assessment results, which are subsequently checked against evaluation. + + + **L252** Chooses the independently stated record outcome by activity. + + + **L253** The recorded generated draft retains tested inputs and adopts the inquiry's requested scope. + + + **L254** For assessment records, chooses a stated verdict from the inquiry kind rather than calling assessInquiry here. + + + **L255** Revision inquiries are recorded as insufficient. + + + **L256** The remaining represented inquiries are recorded as supportedWithinScope. + + + **L258** Builds a record from the supplied rule and subject; registry membership and content validity require the later ValidApplication proof. + + + **L259** Builds a record from this rule's identity, inquiry, reasons and limits, but uses the separately stated outcome. + + + **L261** Exhausts subject/phase constructors to prove each concrete inquiry has reasons. + + + **L262** Checks reason-list nonemptiness for each kind of subject. + + + **L263** System inquiries use the conformity reasons, which contain scope and observation entries. + + + **L264** Principle inquiries likewise have the nonempty scope-and-observation list. + + + **L265** Each process phase reduces to its actual nonempty formation, application or revision reason list. + + + **L267** Uses the reason-list map construction to prove every reason targets the same subject. + + + **L268** Takes any reason known to occur in this subject's constructed reason list. + + + **L269** Inverts the map construction to recover the source content and replace the reason with its target-tagged wrapper. + + + **L270** That wrapper's target is s by construction, so target equality is reflexive. + + + **L272** Checks each constructor to prove the generated inquiry retains its subject identity. + + + **L273** Checks the inquiry target for system, principle and process subjects separately. + + + **L274** The system inquiry was constructed with that same system as target. + + + **L275** The principle inquiry likewise retains that same principle target. + + + **L276** Every process phase uses the original process subject as its inquiry target. + + + **L278** Documents the following definition or result: Computes every subject/phase assessment and generation case, showing stored expected outcomes agree with the actual algorithm, including insufficiency. + + + **L279** Computes every subject/phase assessment and generation case, showing stored expected outcomes agree with the actual algorithm, including insufficiency. + + + **L280** Requires the independently stated outcome to equal actual evaluation of this subject's question, reasons and [0] limits. + + + **L281** Splits this equality check between generated drafts and assessment verdicts. + + + **L282** Both generation definitions construct the identical tested-input/requested-scope draft. + + + **L283** For assessment, the stated verdict must now be checked against the actual evaluator. + + + **L284** Separates the finite assessment check by subject kind. + + + **L285** The system's conformity contents compute to the stated supportedWithinScope verdict. + + + **L286** The principle's conformity contents compute to that same supportedWithinScope verdict. + + + **L287** Formation/application compute support; revision computes insufficient from the program passing zero but failing one. + + + **L289** Separates local identifiers zero and one to prove the two-rule registry has no ambiguous key. + + + **L290** Takes two registered principles whose keys are assumed equal. + + + **L291** Restricts both registry memberships to the actual generation or assessment rule. + + + **L292** Examines the four resulting pairs of concrete rules. + + + **L293** When both are the generation rule, principle equality holds directly. + + + **L294** Generation key 0 cannot equal assessment key 1; projecting localId produces a contradiction. + + + **L295** The reverse mixed pair would require localId 1=0, also impossible. + + + **L296** When both are the assessment rule, principle equality holds directly. + + + **L298** Checks all nine enumerated subjects resolve to an actual registered owner/principle. + + + **L299** The subject selected from ownSubjects must resolve to this owner's actual registry. + + + **L300** Expands membership hs into the nine concrete owned subjects. + + + **L301** Handles each of those nine subjects with its original owner and principle identifier fixed. + + + **L302** Finds the generation or assessment registry entry matching each target key. + + + **L304** Checks each inquiry's method matches its registered target's declared local method. + + + **L305** Requires the selected subject's inquiry to examine its own registered declared method. + + + **L306** Again enumerates the nine concrete subjects from the actual membership premise. + + + **L307** Checks target-method correspondence separately for each system, principle and phase subject. + + + **L308** Both registered rules declare localMethod, exactly the method inquiryFor assigns to every enumerated target. + + + **L310** Combines identity, reason-target, scope, registry and actual evaluation facts to validate each applicable generated record. + + + **L311** Assumes the chosen registered rule is applicable to this subject s. + + + **L312** Proves the concrete recordFor rule s satisfies every ValidApplication field. + + + **L313** First derives that applicability places s in this owner's subject list. + + + **L314** Uses registry membership to restrict rule to one of the two owned rules. + + + **L315** Separates the generation and assessment applicability conditions. + + + **L316** Generation applicability includes owned-subject membership as its first conjunct. + + + **L317** Assessment applicability is exactly that owned-subject membership. + + + **L318** Establishes that this actual rule uses inquiryFor as its inquiry function. + + + **L319** Reduces registered-rule membership to generation or assessment to inspect its inquiry field. + + + **L320** Both possible rules define their inquiry field as inquiryFor. + + + **L321** Establishes that the chosen rule uses reasonsFor as its reason provider. + + + **L322** Again restricts the rule to the two actual registry entries before inspecting reasons. + + + **L323** Both entries supply exactly reasonsFor. + + + **L324** Establishes that this rule's limits for s are exactly [0]. + + + **L325** Resolves registry membership before inspecting the selected rule's limits. + + + **L326** Both owned rules retain [0] as their limit. + + + **L327** Establishes that the chosen rule's meaning is the result function for its own activity. + + + **L328** Resolves registry membership to inspect generation versus assessment meaning. + + + **L329** In either case, the rule's meaning is finiteMethodMeaning specialized to that rule's activity. + + + **L330** Builds ValidApplication using registry/applicability premises, record identities and resolved target; leaves inquiry, reasons and computed meaning checks to follow. + + + **L331** The remaining inquiry-target goal is about this rule's actual inquiry on s. + + + **L332** Replaces the rule's inquiry with inquiryFor, whose target-preservation theorem proves it targets s. + + + **L333** The remaining method-identity goal checks the registered target of this rule's inquiry. + + + **L334** Rewrites to inquiryFor and uses the concrete owned-target method-resolution theorem. + + + **L335** Reduces record reason nonemptiness to nonemptiness of this rule's supplied reasons. + + + **L336** Rewrites those reasons to reasonsFor and applies its nonempty-list theorem. + + + **L337** Reduces reason-target consistency to every supplied reason targeting s. + + + **L338** Rewrites to reasonsFor and uses its target-preserving construction theorem. + + + **L339** The final obligation compares the separately stated outcome against this rule's actual inquiry, reasons, limits and meaning. + + + **L340** Substitutes the four established identities for meaning, inquiry, reasons and [0] limits. + + + **L341** Uses ownContentEvaluates to prove the recorded outcome equals the actual method result. + + + **L343** Constructs records for all nine subjects, including generation only where its eligibility condition holds. + + + **L344** Builds the full log by concatenating the records assigned to each owned subject. + + + **L345** Eligible subjects receive both a generation record and an assessment record. + + + **L346** Application-phase subjects receive assessment only, matching generation's explicit applicability restriction. + + + **L348** Places each subject's assessment record in the flat-mapped complete work list. + + + **L349** Claims this owned subject's assessment record occurs in the constructed full log. + + + **L350** Uses flatMap membership: choose a subject whose assigned record list contains the desired record. + + + **L351** Chooses the same s and its supplied owned-subject membership hs. + + + **L352** Whether generation is eligible or not, the assigned list contains s's assessment record. + + + **L354** Places a subject's generation record in the work list under explicit generation eligibility. + + + **L355** Adds generation eligibility to owned membership before claiming a generation record in the full log. + + + **L356** Selects s's flatMap branch; hg makes that branch include the requested generation record. + + + **L358** Combines coherent registry, membership and content-valid applications to establish the concrete nonempty reflexivity model. + + + **L359** States full contentful reflexivity for the actual two-rule registry and constructed work log. + + + **L360** Provides the proved registry coherence and leaves contentful coverage for each applicable subject. + + + **L361** Takes an actual registered rule and applicable subject; applicability itself will supply needed owned membership. + + + **L362** Chooses recordFor rule s and its already proved content validity, leaving only its presence in the full log. + + + **L363** Resolves rule membership to the generation or assessment entry. + + + **L364** Splits record membership by those two actual rule cases. + + + **L365** For generation, ha supplies owned membership and eligibility, which place its record in the full log. + + + **L366** For assessment, ha directly supplies the owned membership needed for its record. + + + **L368** Extracts the constructed assessment record for a listed own subject. + + + **L369** Claims a performed assessment on s in the same complete work log. + + + **L370** Uses s's assessment record, its proved log membership and exact target/activity identities as the Performed witness. + + + **L372** Restricts an assessment rule to one application-phase subject and assigns it a resolvable key. + + + **L373** Restricts the assessment rule to exactly principle-zero's application process, with key (0,0). + + + **L375** Stores the one fully specified application assessment record. + + + **L377** Checks the singleton registry and record satisfy full content-valid reflexivity on their restricted applicability. + + + **L378** Separates singleton-registry coherence from coverage of its sole applicable subject. + + + **L379** Takes any two rules in that singleton registry; key equality is unnecessary because membership already identifies both. + + + **L380** Singleton membership makes both rules equal to applicationRule. + + + **L381** Substituting these identities proves the two rules are equal. + + + **L382** Takes an applicable subject for a rule in the singleton application registry. + + + **L383** Uses singleton membership to identify the rule as applicationRule. + + + **L384** Replaces rule with that exact applicationRule throughout the coverage obligation. + + + **L385** Unfolds applicability to show s is exactly owner-zero principle-zero's application process. + + + **L386** Substitutes that exact process for s, fixing the work target. + + + **L387** Selects the sole record in applicationWork and proves its membership; content validity remains to check. + + + **L388** Fills immediate registry, applicability and record-identity fields; leaves target resolution, reasons and computed outcome checks. + + + **L389** The target key resolves to applicationRule itself in the singleton registry. + + + **L390** That same registered rule supplies the localMethod actually examined by the inquiry. + + + **L391** The application inquiry's reasons are nonempty by reasonsFor_nonempty. + + + **L392** Every application reason targets this exact application-process subject. + + + **L393** The remaining meaning obligation is equality of the stated application assessment and its actual finite evaluation. + + + **L394** Uses ownContentEvaluates to certify that equality for the application-phase assessment. + + + **L396** Derives record scope from full reflexivity, proves its classical conditional/disjunctive equivalence, and gives a valid restricted example with no system assessment. + + + **L397** The first clause retains the implication from full contentful reflexivity to scope coverage. + + + **L398** The second clause restates conditional scope coverage as an either/or obligation. + + + **L399** For each owned subject and registered rule, either the rule is inapplicable or its activity was performed. + + + **L400** The concrete singleton application log satisfies full reflexivity under its restricted rule. + + + **L401** Yet that same log contains no assessment of the system itself, where this rule is not applicable. + + + **L402** Uses classical case splitting on possibly undecidable applicability predicates. + + + **L403** Supplies the general scope projection and concrete restricted witness; leaves the equivalence and missing-system-record proof. + + + **L404** Proves both directions of the applicability-or-performance reformulation. + + + **L405** Assumes conditional scope coverage and fixes a registered rule with an owned subject. + + + **L406** Splits on whether that exact rule is applicable to this subject. + + + **L407** When applicable, coverage supplies the performed activity, satisfying the right disjunct. + + + **L408** When inapplicable, that negative applicability fact satisfies the left disjunct. + + + **L409** For the reverse direction, assumes the disjunction and actual applicability on the owned subject. + + + **L410** Rules out the inapplicable disjunct using ha, leaving the required performed activity. + + + **L411** Assumes a system assessment exists and extracts its listed record plus target identity. + + + **L412** The singleton applicationWork list forces that record to be its application-process record. + + + **L413** Replaces the alleged system-assessment record with that sole process record. + + + **L414** Its process target cannot equal the system target, contradicting the assumed record identity. + + + **L416** Closes the current namespace. + + +### `leanified/CoreReader.lean` + + +```lean +import CoreReader.Engineering.Integration +``` + + + + **L1** Import Engineering.Integration and its transitive modules, making this project’s engineering application, inherited interfaces, joint witness and non-entailment proof available; the import itself asserts no philosophical theorem. + diff --git a/SoftwareEngineering/lean/philosophy/evidence/README.md b/SoftwareEngineering/lean/philosophy/evidence/README.md new file mode 100644 index 0000000..2ba2f10 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/evidence/README.md @@ -0,0 +1,5 @@ +# Selected current checks + +These actual build, declaration/type/dependency and four-view checks were selected from a fresh ordinary-copy execution after the 2026-09-15 source migration. The [independent migration comparison](../reviews/source-migration-2026-09-15.md) supplies the bounded new-source judgment; unchanged code and target bodies retain the disclosed earlier interpretation scope. The preceding complete source/run/readers were preserved and replayed separately before replacement. + +`kernel.json` and `manuscript-check.json` report mechanical checks, not philosophical correctness. `execution-identity.json` records loaded tools and observed runtimes, not tool approval. All partial, nonformal and application-specific limits remain. Reruns write separate ignored `checks/` records rather than changing these selected outputs. diff --git a/SoftwareEngineering/lean/philosophy/evidence/audit.lean b/SoftwareEngineering/lean/philosophy/evidence/audit.lean new file mode 100644 index 0000000..73c9b90 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/evidence/audit.lean @@ -0,0 +1,297 @@ +import Lean +import CoreReader +#check CoreReader.Adopted.generationSpecification +#print axioms CoreReader.Adopted.generationSpecification +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.generationSpecification + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.generationSpecification " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.generationCases +#print axioms CoreReader.Adopted.generationCases +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.generationCases + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.generationCases " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.generationLimits012 +#print axioms CoreReader.Adopted.generationLimits012 +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.generationLimits012 + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.generationLimits012 " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.consistencySpecification +#print axioms CoreReader.Adopted.consistencySpecification +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.consistencySpecification + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.consistencySpecification " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.consistencyCases +#print axioms CoreReader.Adopted.consistencyCases +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.consistencyCases + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.consistencyCases " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.consistencyConsequences +#print axioms CoreReader.Adopted.consistencyConsequences +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.consistencyConsequences + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.consistencyConsequences " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.consistencyLimits012 +#print axioms CoreReader.Adopted.consistencyLimits012 +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.consistencyLimits012 + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.consistencyLimits012 " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.reflexivitySpecification +#print axioms CoreReader.Adopted.reflexivitySpecification +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.reflexivitySpecification + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.reflexivitySpecification " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.reflexivityCases012 +#print axioms CoreReader.Adopted.reflexivityCases012 +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.reflexivityCases012 + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.reflexivityCases012 " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.reflexivityLimits012 +#print axioms CoreReader.Adopted.reflexivityLimits012 +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.reflexivityLimits012 + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.reflexivityLimits012 " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.Grounds012 +#print axioms CoreReader.Adopted.Grounds012 +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.Grounds012 + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.Grounds012 " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.groundsCases012 +#print axioms CoreReader.Adopted.groundsCases012 +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.groundsCases012 + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.groundsCases012 " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.empiricalSpecification +#print axioms CoreReader.Adopted.empiricalSpecification +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.empiricalSpecification + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.empiricalSpecification " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.empiricalCases012 +#print axioms CoreReader.Adopted.empiricalCases012 +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.empiricalCases012 + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.empiricalCases012 " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.inferentialSpecification +#print axioms CoreReader.Adopted.inferentialSpecification +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.inferentialSpecification + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.inferentialSpecification " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.inferentialCases012 +#print axioms CoreReader.Adopted.inferentialCases012 +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.inferentialCases012 + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.inferentialCases012 " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.valueSpecification +#print axioms CoreReader.Adopted.valueSpecification +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.valueSpecification + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.valueSpecification " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.valueCases012 +#print axioms CoreReader.Adopted.valueCases012 +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.valueCases012 + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.valueCases012 " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.groundsLimits012 +#print axioms CoreReader.Adopted.groundsLimits012 +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.groundsLimits012 + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.groundsLimits012 " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.scopeSpecification +#print axioms CoreReader.Adopted.scopeSpecification +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.scopeSpecification + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.scopeSpecification " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.scopeCases012 +#print axioms CoreReader.Adopted.scopeCases012 +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.scopeCases012 + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.scopeCases012 " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.scopeLimits012 +#print axioms CoreReader.Adopted.scopeLimits012 +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.scopeLimits012 + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.scopeLimits012 " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.capabilitySpecification +#print axioms CoreReader.Adopted.capabilitySpecification +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.capabilitySpecification + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.capabilitySpecification " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.capabilityCases012 +#print axioms CoreReader.Adopted.capabilityCases012 +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.capabilityCases012 + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.capabilityCases012 " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.capabilityLimits012 +#print axioms CoreReader.Adopted.capabilityLimits012 +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.capabilityLimits012 + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.capabilityLimits012 " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.choiceSpecification +#print axioms CoreReader.Adopted.choiceSpecification +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.choiceSpecification + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.choiceSpecification " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.choiceCases012 +#print axioms CoreReader.Adopted.choiceCases012 +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.choiceCases012 + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.choiceCases012 " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Adopted.choiceLimits012 +#print axioms CoreReader.Adopted.choiceLimits012 +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Adopted.choiceLimits012 + Lean.logInfo ("ORGANON_TYPE CoreReader.Adopted.choiceLimits012 " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.inheritedMutualApplication +#print axioms CoreReader.Engineering.inheritedMutualApplication +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.inheritedMutualApplication + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.inheritedMutualApplication " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.inheritedMutualCases +#print axioms CoreReader.Engineering.inheritedMutualCases +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.inheritedMutualCases + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.inheritedMutualCases " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.ActivityScope +#print axioms CoreReader.Engineering.ActivityScope +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.ActivityScope + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.ActivityScope " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.subjectLifecycleCases +#print axioms CoreReader.Engineering.subjectLifecycleCases +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.subjectLifecycleCases + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.subjectLifecycleCases " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.subjectLimits +#print axioms CoreReader.Engineering.subjectLimits +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.subjectLimits + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.subjectLimits " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.EvolutionPriority +#print axioms CoreReader.Engineering.EvolutionPriority +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.EvolutionPriority + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.EvolutionPriority " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.priorityConditionsCases +#print axioms CoreReader.Engineering.priorityConditionsCases +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.priorityConditionsCases + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.priorityConditionsCases " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.priorityWhenApplicable +#print axioms CoreReader.Engineering.priorityWhenApplicable +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.priorityWhenApplicable + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.priorityWhenApplicable " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.priorityChoices +#print axioms CoreReader.Engineering.priorityChoices +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.priorityChoices + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.priorityChoices " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.CredibleDirection +#print axioms CoreReader.Engineering.CredibleDirection +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.CredibleDirection + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.CredibleDirection " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.credibilityCases +#print axioms CoreReader.Engineering.credibilityCases +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.credibilityCases + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.credibilityCases " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.credibilityLimits +#print axioms CoreReader.Engineering.credibilityLimits +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.credibilityLimits + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.credibilityLimits " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.JustifiedDeparture +#print axioms CoreReader.Engineering.JustifiedDeparture +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.JustifiedDeparture + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.JustifiedDeparture " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.costCases +#print axioms CoreReader.Engineering.costCases +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.costCases + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.costCases " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.EvolutionClaim +#print axioms CoreReader.Engineering.EvolutionClaim +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.EvolutionClaim + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.EvolutionClaim " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.evolutionKindsCases +#print axioms CoreReader.Engineering.evolutionKindsCases +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.evolutionKindsCases + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.evolutionKindsCases " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.evolutionDimensionsLimits +#print axioms CoreReader.Engineering.evolutionDimensionsLimits +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.evolutionDimensionsLimits + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.evolutionDimensionsLimits " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.StructuralAccount +#print axioms CoreReader.Engineering.StructuralAccount +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.StructuralAccount + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.StructuralAccount " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.structuralCases +#print axioms CoreReader.Engineering.structuralCases +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.structuralCases + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.structuralCases " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.structureNotCapability +#print axioms CoreReader.Engineering.structureNotCapability +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.structureNotCapability + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.structureNotCapability " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.ContractChangeAccount +#print axioms CoreReader.Engineering.ContractChangeAccount +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.ContractChangeAccount + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.ContractChangeAccount " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.contractCases +#print axioms CoreReader.Engineering.contractCases +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.contractCases + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.contractCases " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.contractPreservation +#print axioms CoreReader.Engineering.contractPreservation +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.contractPreservation + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.contractPreservation " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.contractDistinctions +#print axioms CoreReader.Engineering.contractDistinctions +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.contractDistinctions + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.contractDistinctions " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.RevisionAccount +#print axioms CoreReader.Engineering.RevisionAccount +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.RevisionAccount + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.RevisionAccount " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.revisionCases +#print axioms CoreReader.Engineering.revisionCases +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.revisionCases + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.revisionCases " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.revisionLimits +#print axioms CoreReader.Engineering.revisionLimits +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.revisionLimits + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.revisionLimits " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.priorityRemainsReflexive +#print axioms CoreReader.Engineering.priorityRemainsReflexive +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.priorityRemainsReflexive + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.priorityRemainsReflexive " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.priorityReflexiveCases +#print axioms CoreReader.Engineering.priorityReflexiveCases +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.priorityReflexiveCases + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.priorityReflexiveCases " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.jointWitness +#print axioms CoreReader.Engineering.jointWitness +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.jointWitness + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.jointWitness " ++ (Lean.Json.str (reprStr info.type)).compress) +#check CoreReader.Engineering.inheritedDoesNotEntailPriority +#print axioms CoreReader.Engineering.inheritedDoesNotEntailPriority +run_cmd do + let info ← Lean.getConstInfo `CoreReader.Engineering.inheritedDoesNotEntailPriority + Lean.logInfo ("ORGANON_TYPE CoreReader.Engineering.inheritedDoesNotEntailPriority " ++ (Lean.Json.str (reprStr info.type)).compress) diff --git a/SoftwareEngineering/lean/philosophy/evidence/declaration-types.json b/SoftwareEngineering/lean/philosophy/evidence/declaration-types.json new file mode 100644 index 0000000..cd7eb58 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/evidence/declaration-types.json @@ -0,0 +1,238 @@ +{ + "CoreReader.Adopted.generationSpecification": { + "type": "Lean.Expr.forallE\n `policy\n (Lean.Expr.const `CoreReader.Agency.Policy [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default)", + "sha256": "4d07b8deec9112ff5d3e7fe744c159c254580260c78b82be6dd64347e8a9a4eb" + }, + "CoreReader.Adopted.generationCases": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `k\n (Lean.Expr.const `CoreReader.Agency.FormKind [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.revisable [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Form.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.forallE\n `t\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.stableTrace []) (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.stableTrace [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `HAdd.hAdd [Lean.Level.zero, Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `instHAdd [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instAddNat [])))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.permitsVersion [])\n (Lean.Expr.const `CoreReader.Agency.neutralPolicy []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.const `CoreReader.Agency.neutralPolicy []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.permitsVersion [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.availableResources [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Option.some [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 6)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 1780710401) \"_hygCtx\") \"_hyg\") 147)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 1780710401) \"_hygCtx\") \"_hyg\") 166)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `Option [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 1780710401) \"_hygCtx\") \"_hyg\") 185)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n true)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `Option [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.requirementsMet [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.StableReason [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Announcement []))\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.GeneratingSystem.report\n [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.owner [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.owner [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.before [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.after [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.reportedNewOperation\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.input [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const\n `Eq\n [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.expectedOutput\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.claim\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.before\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.after\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))))))))))))))))))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.generationSpecification [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.const `CoreReader.Agency.baseState []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.collaborativeRevision [])\n (Lean.Expr.const `CoreReader.Agency.availableResources []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.const `CoreReader.Agency.baseState []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.collaborativeRevision [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 1780710401) \"_hygCtx\") \"_hyg\") 355)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n true)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.assistedExecution [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))))", + "sha256": "430a91318477db0305b3107b81f9df39652fa27673fdc38705a86f8e158ca138" + }, + "CoreReader.Adopted.generationLimits012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.permitsVersion [])\n (Lean.Expr.const `CoreReader.Agency.neutralPolicy []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.const `CoreReader.Agency.neutralPolicy []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `k\n (Lean.Expr.const `CoreReader.Agency.FormKind [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.revisable [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Form.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.forallE\n `t\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.stableTrace []) (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.stableTrace [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `HAdd.hAdd [Lean.Level.zero, Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `instHAdd [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instAddNat [])))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.permitsVersion [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.availableResources [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Option.some [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 6)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3022720055) \"_hygCtx\") \"_hyg\") 147)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3022720055) \"_hygCtx\") \"_hyg\") 166)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `Option [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3022720055) \"_hygCtx\") \"_hyg\") 185)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n true)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `Option [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.requirementsMet [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.StableReason [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Announcement []))\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.GeneratingSystem.report\n [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.owner [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.owner [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.before [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.after [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.reportedNewOperation\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.input [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const\n `Eq\n [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.expectedOutput\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.claim\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.before\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.after\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))))))))))))))))))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.generationSpecification [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.const `CoreReader.Agency.baseState []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.collaborativeRevision [])\n (Lean.Expr.const `CoreReader.Agency.availableResources []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.const `CoreReader.Agency.baseState []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.collaborativeRevision [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3022720055) \"_hygCtx\") \"_hyg\") 358)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n true)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.assistedExecution [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase []))\n (Lean.Expr.const `CoreReader.Evidence.transitionAchievement []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))\n (Lean.Expr.const `CoreReader.Evidence.transitionFacet []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase []))\n (Lean.Expr.const `CoreReader.Evidence.transitionFacet []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))\n (Lean.Expr.const `CoreReader.Evidence.transitionPerformanceRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))))\n (Lean.Expr.const `CoreReader.Agency.TransitionCase.extend [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.transitionAchievement [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase.extend [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.transitionAchievement [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase.inflate []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))\n (Lean.Expr.const `CoreReader.Evidence.transitionReportRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))))\n (Lean.Expr.const `CoreReader.Evidence.transitionAchievement []))))))))\n (Lean.Expr.forallE\n `kind\n (Lean.Expr.const `CoreReader.Agency.InventoryKind [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Available [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item [])))))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Available [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item [])))))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor []))))\n (Lean.BinderInfo.default))))))", + "sha256": "69058c75db607f675c730d92da7dd1c6ee27d75385f4ac4ff717bd9fc7e925b2" + }, + "CoreReader.Adopted.consistencySpecification": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `Q\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `before\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Snapshot []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `after\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Snapshot []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.forallE\n `reported\n (Lean.Expr.const `Bool [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit))\n (Lean.BinderInfo.implicit)", + "sha256": "cf239ba7292f80875f93e960cd3417c226a8727f57f11e1ec4af4564caef076d" + }, + "CoreReader.Adopted.consistencyCases": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.premiseP []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.premiseRule []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.premiseNotQ []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.jointTheory [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consequence [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.assumptionContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.meaningContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.scopeContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.TruthfulReport []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.TruthfulReport []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.TruthfulReport [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.TruthfulReport [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.TruthfulReport [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Models []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Context.assumptions [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.const `Bool.true [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `time\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.revisionSlice []) (Lean.Expr.bvar 0)))\n (Lean.Expr.const `CoreReader.Adopted.broadBoolContext []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.const `CoreReader.Adopted.broadBoolContext [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `p\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `Bool []))\n (Lean.Expr.forallE\n `q\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `Bool []))\n (Lean.Expr.forallE\n `r\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Iff [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 2)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 2)))\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consequence [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.const `CoreReader.Logic.jointTheory []))\n (Lean.Expr.const `CoreReader.Adopted.jointContext012 []))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consequence [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.const `CoreReader.Logic.jointTheory []))\n (Lean.Expr.const `CoreReader.Adopted.jointContext012 []))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consistent [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.const `CoreReader.Logic.jointTheory []))\n (Lean.Expr.const `CoreReader.Adopted.jointContext012 []))))))))))", + "sha256": "16a20441e5650e4992e046ae4eeb2a1867f573730aa1dc402ca70508bb1802a6" + }, + "CoreReader.Adopted.consistencyConsequences": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `Q\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `t\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Theory []) (Lean.Expr.bvar 1))\n (Lean.Expr.forallE\n `c\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Context []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.forallE\n `q\n (Lean.Expr.bvar 2)\n (Lean.Expr.forallE\n `positive\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.bvar 4))\n (Lean.Expr.bvar 3))\n (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.forallE\n `negative\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.bvar 5))\n (Lean.Expr.bvar 4))\n (Lean.Expr.bvar 3))\n (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `Bool.false []))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.bvar 6))\n (Lean.Expr.bvar 5))\n (Lean.Expr.bvar 4))\n (Lean.Expr.bvar 3)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit))\n (Lean.BinderInfo.implicit)", + "sha256": "4b3231ac25a534c2699cd8f548a59a7d8beb1cb3923456f10c95081a3b6b5be3" + }, + "CoreReader.Adopted.consistencyLimits012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Admissible []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.assumptionContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.meaningContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Admissible []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.scopeContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lam\n `budget\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 4)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 4)))))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 6))))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 4)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 4)))))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 6)))))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.broadBoolContext [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Models []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.broadBoolContext [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Nat []))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 4)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 4)))))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Nat []))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 6)))))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.const `CoreReader.Adopted.tensionContext012 [])))))", + "sha256": "1bb1429eb084c222d9a84341c2d6cae05e8c83c1374bbbab8402a372099649cc" + }, + "CoreReader.Adopted.reflexivitySpecification": { + "type": "Lean.Expr.forallE\n `T\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `I\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `O\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `rules\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.forallE\n `isSelf\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 3)\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `performed\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Agency.PrincipleKey [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 5)\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 5)\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 5)\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit))\n (Lean.BinderInfo.implicit))\n (Lean.BinderInfo.implicit)", + "sha256": "d8084253926a4e9a9b2b9d6ccea7fcba129de72b8412ec4bd30c08a9bdf254bc" + }, + "CoreReader.Adopted.reflexivityCases012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.reflexivitySpecification [])\n (Lean.Expr.const `CoreReader.Agency.Subject []))\n (Lean.Expr.const `CoreReader.Agency.Inquiry []))\n (Lean.Expr.const `CoreReader.Agency.WorkOutcome []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.map [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule [])\n (Lean.Expr.const `CoreReader.Agency.Subject []))\n (Lean.Expr.const `CoreReader.Agency.Inquiry []))\n (Lean.Expr.const `CoreReader.Agency.WorkOutcome [])))\n (Lean.Expr.const `CoreReader.Adopted.legacyRule []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ownRules [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.lam\n `s\n (Lean.Expr.const `CoreReader.Agency.Subject [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Subject.owner []) (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.legacyPerformed [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ownRules [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.completeOwnWork [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `phase\n (Lean.Expr.const `CoreReader.Agency.Phase [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Performed [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.completeOwnWork [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Subject.process [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `CoreReader.Agency.Activity.assessment []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Performed [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.completeOwnWork [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Subject.system [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `CoreReader.Agency.Activity.assessment [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.reflexivitySpecification [])\n (Lean.Expr.const `CoreReader.Agency.Subject []))\n (Lean.Expr.const `CoreReader.Agency.Inquiry []))\n (Lean.Expr.const `CoreReader.Agency.WorkOutcome []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.map [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule [])\n (Lean.Expr.const `CoreReader.Agency.Subject []))\n (Lean.Expr.const `CoreReader.Agency.Inquiry []))\n (Lean.Expr.const `CoreReader.Agency.WorkOutcome [])))\n (Lean.Expr.const `CoreReader.Adopted.legacyRule []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle []))\n (Lean.Expr.const `CoreReader.Agency.applicationRule []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle [])))))\n (Lean.Expr.lam\n `s\n (Lean.Expr.const `CoreReader.Agency.Subject [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Subject.owner []) (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.legacyPerformed [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle []))\n (Lean.Expr.const `CoreReader.Agency.applicationRule []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle []))))\n (Lean.Expr.const `CoreReader.Agency.applicationWork []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Performed [])\n (Lean.Expr.const `CoreReader.Agency.applicationWork []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Subject.system [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `CoreReader.Agency.Activity.assessment []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.Grounds012 []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `enabled\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.GroundsProvision012 []) (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet.value []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.AssessmentTask.value []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.limits [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.relevantCriticism [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 []))\n (Lean.Expr.const `Bool.true [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.groundsExperiment012 [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.groundsExperiment012 [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Outcome [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.outcome [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.groundsExperiment012 [])\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Outcome [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.outcome [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.groundsExperiment012 [])\n (Lean.Expr.const `Bool.false [])))))))))", + "sha256": "55a9d738a39137aeb7cf0ee474c532a636dc2a59451613848747030a756b29e7" + }, + "CoreReader.Adopted.reflexivityLimits012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.selfTest [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ownArithmeticPrinciple [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.ownArithmeticPrinciple []) (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Evidence.allTrue []))))\n (Lean.Expr.const `CoreReader.Evidence.OwnedRevisionExample []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Reflexive [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ownRules [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.WorkRecord []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.CompleteCharter012 [])\n (Lean.Expr.const `CoreReader.Integration.actualSystem []))\n (Lean.Expr.const `CoreReader.Integration.actual [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.const `CoreReader.Integration.Question []))\n (Lean.Expr.const `CoreReader.Integration.held []))\n (Lean.Expr.const `CoreReader.Integration.context []))\n (Lean.Expr.const `CoreReader.Integration.actual [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Integration.World [])))\n (Lean.Expr.const `CoreReader.Integration.costAllowanceRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Integration.World [])))))\n (Lean.Expr.const `CoreReader.Integration.actual [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulated [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.const `CoreReader.Integration.unsupportedCapabilityFacet []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Integration.World [])))\n (Lean.Expr.const `CoreReader.Integration.costAllowanceRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Integration.World [])))))\n (Lean.Expr.const `CoreReader.Integration.capability []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.const `CoreReader.Integration.capability []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Integration.World [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Integration.World [])))\n (Lean.Expr.const `CoreReader.Integration.unsupportedCapabilityFacet []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Integration.World [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.const `CoreReader.Integration.unsupportedCapabilityFacet []))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.generationSpecification [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.revisable [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Form.mk [])\n (Lean.Expr.const `CoreReader.Agency.FormKind.principle []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.selfExemptPerformed012 [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.PrincipleKey.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule.applicable [])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.selfExemptRule012 []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.reflexivitySpecification [])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule [])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.selfExemptRule012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule [])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool [])))))\n (Lean.Expr.lam\n `target\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.selfExemptPerformed012 []))))))))))", + "sha256": "6aaa9a96ab7f8fe3ebe04633ee7e9ae054eafa88e7e8289179d143ee96e46d05" + }, + "CoreReader.Adopted.Grounds012": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `claim\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `articulations\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.bvar 1))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Articulation []) (Lean.Expr.bvar 2))\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `facets\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.bvar 2)))\n (Lean.Expr.forallE\n `task\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.AssessmentTask []) (Lean.Expr.bvar 3))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)", + "sha256": "65ead33e1cc510ec07082dde80dbec28ca36d80391c18e2ca6df7ed3e1353029" + }, + "CoreReader.Adopted.groundsCases012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulated [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Articulated []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.uninformativeArgument [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulation.assumptions [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.uninformativeArgument [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Evidence.allTrue []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.circularGlobalFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.circularGlobalFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.NatureAppropriate [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.originalGlobalTask012 []))\n (Lean.Expr.const `CoreReader.Adopted.circularGlobalFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Evidence.allTrue []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.circularGlobalFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Adopted.originalGlobalTask012 []))))))", + "sha256": "5d659ec603f559d1be5abf4df0466b2daee1633dcfbf70194c0b8ccf9640e40f" + }, + "CoreReader.Adopted.empiricalSpecification": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `records\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Record []) (Lean.Expr.bvar 0)))\n (Lean.Expr.forallE\n `scope\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.bvar 1))\n (Lean.Expr.forallE\n `claim\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.bvar 2))\n (Lean.Expr.forallE\n `uncertainty\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.bvar 3))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)", + "sha256": "9f534ab1f51da3b82f8edf1d35b0dfab34dfe042d10c44582f04b4dce6569ef2" + }, + "CoreReader.Adopted.empiricalCases012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulated [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record.test [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 3)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.consequence [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.consequence [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.empiricalSpecification [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 577346429) \"_hygCtx\") \"_hyg\") 256)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `True [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.fst [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Or [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.false [])))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.bvar 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Adopted.originalLocalTask012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.bvar 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.observedInferenceFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Adopted.originalLocalTask012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.FacetDischarged [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.uncertaintyBypassFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.NatureAppropriate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.originalUncertaintyTask012 []))\n (Lean.Expr.const `CoreReader.Adopted.uncertaintyBypassFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.fst [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Adopted.uncertaintyBypassFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))))\n (Lean.Expr.const `CoreReader.Adopted.originalUncertaintyTask012 []))))))))", + "sha256": "fba89ddcd1cf1f745deec2bbdb86e1434e01d6fc73f99c6bf690331560f736f6" + }, + "CoreReader.Adopted.inferentialSpecification": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `assumptions\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Theory []) (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `claim\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.bvar 1))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)", + "sha256": "d56b013c37bfeb071f171cb3f552b8775a79eee535305a78d2d9551b86c03c16" + }, + "CoreReader.Adopted.inferentialCases012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.inferentialSpecification []) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Nat []))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `HAdd.hAdd [Lean.Level.zero, Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `instHAdd [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instAddNat [])))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.InferenceExamined []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Models []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))\n (Lean.Expr.const `Bool.false [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.FacetDischarged []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet.inferential []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.Grounds012 []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.inferential [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.AssessmentTask.inferential [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))))", + "sha256": "b37768f2ff32da55daf97b29dc027bfa78aa1a1f2456c80937dde7aa64a5c515" + }, + "CoreReader.Adopted.valueSpecification": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `position\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.ValuePosition []) (Lean.Expr.bvar 0))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)", + "sha256": "1f45a163b8b2a0db44eeaeb0910e0af6168e4674ab3a3925dcfe54e3015e3ae6" + }, + "CoreReader.Adopted.valueCases012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.valueSpecification []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.reasons [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `reason\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.reasons [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.bvar 1)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.adopted [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.consequence [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.ValueProcedure []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.closedPosition012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.ValueProcedure []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.starting [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.JointAdoption [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.oppositePosition [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.oppositePosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.contradictoryStartingPosition []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.impossibleAdoptionPosition [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.FacetDischarged []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.selectedFactFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.valueSpecification []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.Grounds012 []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.selectedFactFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.AssessmentTask.value [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))))))))", + "sha256": "ce1dba18fb8bf4611fe703b21270e3b59591f6f1cf1c40f2ee03899fa26c142a" + }, + "CoreReader.Adopted.groundsLimits012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Articulated []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.clearFalseArgument012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Models []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulation.assumptions [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.clearFalseArgument012 [])))\n (Lean.Expr.const `Bool.false [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record.test [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 3)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.consequence [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.consequence [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.valueSpecification []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Compatible []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Record []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.valueNeutralRecord012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Record []) (Lean.Expr.const `Bool [])))))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Supports []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Record []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.valueNeutralRecord012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Record []) (Lean.Expr.const `Bool [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.ValueProcedure []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.starting [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.JointAdoption [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.oppositePosition [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.oppositePosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.contradictoryStartingPosition []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.impossibleAdoptionPosition [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ClaimNoStronger [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.bvar 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ClaimNoStronger [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Evidence.allTrue []))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.bvar 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.valueSpecification []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))))))", + "sha256": "b404dce33c3fbf86c65d3824e2fceaf5f0a1f312ce1edc1f0a9e9251af9ccad3" + }, + "CoreReader.Adopted.scopeSpecification": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `account\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.ScopeAccount []) (Lean.Expr.bvar 0))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)", + "sha256": "01857cd86d39ca8bc2d54d15555ebed9fc9fa6a0bd40196743e5f1fbbcb966b7" + }, + "CoreReader.Adopted.scopeCases012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.scopeSpecification []) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Adopted.localScopeAccount012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 3351349031) \"_hygCtx\") \"_hyg\") 37)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.bvar 1)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 3351349031) \"_hygCtx\") \"_hyg\") 54)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))", + "sha256": "e503dd4f8dacf02303b9bd7e56977a56feee218c1c677d8836c15039e83655a8" + }, + "CoreReader.Adopted.scopeLimits012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lam\n `outside\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 27637535) \"_hygCtx\") \"_hyg\") 38)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 27637535) \"_hygCtx\") \"_hyg\") 62)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 27637535) \"_hygCtx\") \"_hyg\") 117)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.bvar 1)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 27637535) \"_hygCtx\") \"_hyg\") 134)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.bvar 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.letE\n `a\n (Lean.Expr.const `CoreReader.Evidence.Trial [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.letE\n `b\n (Lean.Expr.const `CoreReader.Evidence.Trial [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Reproduced []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.actualOutcome [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Trial.actualOutcome []) (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Bounded []) (Lean.Expr.bvar 1)))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Bounded []) (Lean.Expr.bvar 0)))))\n true)\n true))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Verified [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Verified [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Reproduced [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Reproduced [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Verified [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2))))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Bounded [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Bounded [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Bounded [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Verified [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.FacetDischarged []) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Evidence.arithmeticFacet [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.usesObservation [])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Evidence.arithmeticFacet [])))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.inferentialSpecification [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `on\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.lam\n `on\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.false []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.usesObservation [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.inferential [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `on\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.lam\n `on\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.false []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `GT.gt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.drawWeight012 [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `GT.gt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.drawWeight012 [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.drawWeight012 [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.drawWeight012 [])\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Reproduced [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.actualOutcome [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.actualOutcome [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.const `Bool.false [])))))\n (Lean.Expr.forallE\n `draw\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Verified [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Bounded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.bvar 0))))\n (Lean.BinderInfo.default)))))))))))))", + "sha256": "a286f42a08d68addaec58cb6b0b9656968db614439bd753425f3972b29d8125c" + }, + "CoreReader.Adopted.capabilitySpecification": { + "type": "Lean.Expr.forallE\n `assessed\n (Lean.Expr.const `CoreReader.Evidence.Process [])\n (Lean.Expr.forallE\n `contract\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `CoreReader.Evidence.Process []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "908a244789ebae715ab94703060109000c2369e1c4735c6cdb48a096243f3c04" + }, + "CoreReader.Adopted.capabilityCases012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.const `CoreReader.Evidence.explainedProcess []))\n (Lean.Expr.const `CoreReader.Evidence.FullProcessContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))\n (Lean.Expr.lam\n `certificate\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate.assessorId [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate.assessedId [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExplanationContract [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.OwnCapability012 [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 7)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 7)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 7)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 7)))))\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Evidence.Process []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012.process [])\n (Lean.Expr.const `CoreReader.Adopted.explainedWithoutVariation012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012.process [])\n (Lean.Expr.const `CoreReader.Adopted.mechanismResponder012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.FullProcessContract [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012.process [])\n (Lean.Expr.const `CoreReader.Adopted.explainedWithoutVariation012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.UnderstandingApplication012 [])\n (Lean.Expr.const `CoreReader.Adopted.explainedWithoutVariation012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.UnderstandingApplication012 [])\n (Lean.Expr.const `CoreReader.Adopted.mechanismResponder012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 []))\n (Lean.Expr.const `CoreReader.Adopted.UnderstandingApplication012 []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.understandingFacet012 [])\n (Lean.Expr.const `CoreReader.Adopted.mechanismResponder012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.understandingTask012 [])\n (Lean.Expr.const `CoreReader.Adopted.mechanismResponder012 []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 []))\n (Lean.Expr.const `CoreReader.Adopted.UnderstandingApplication012 []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.understandingFacet012 [])\n (Lean.Expr.const `CoreReader.Adopted.explainedWithoutVariation012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.understandingTask012 [])\n (Lean.Expr.const `CoreReader.Adopted.explainedWithoutVariation012 []))))))))))", + "sha256": "71d33f0d4ef4ccd7b59de8cf61f1e8aa0edae58f02813c4f4f3d79754d592d03" + }, + "CoreReader.Adopted.capabilityLimits012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.const `CoreReader.Evidence.explainedProcess []))\n (Lean.Expr.const `CoreReader.Evidence.FullProcessContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))\n (Lean.Expr.lam\n `certificate\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate.assessorId [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate.assessedId [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExplanationContract [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `kind\n (Lean.Expr.const `CoreReader.Agency.InventoryKind [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Available [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item [])))))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Available [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item [])))))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor []))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.permitsVersion [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.availableResources [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Option.some [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 6)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3023016825) \"_hygCtx\") \"_hyg\") 160)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3023016825) \"_hygCtx\") \"_hyg\") 179)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3023016825) \"_hygCtx\") \"_hyg\") 198)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n true)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.requirementsMet [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.StableReason [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Announcement []))\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.report [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.owner [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.owner [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.before [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.after [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.reportedNewOperation\n [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.input [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.expectedOutput\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.claim [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.before\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.after [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))))))))))))))))))))))))))))", + "sha256": "8efa4107232374dd4f308f0f4c19f39b706da292b2cb4042aba290ade3368d52" + }, + "CoreReader.Adopted.choiceSpecification": { + "type": "Lean.Expr.forallE\n `requirements\n (Lean.Expr.const `CoreReader.Choice.Requirements [])\n (Lean.Expr.forallE\n `implementation\n (Lean.Expr.const `CoreReader.Choice.Implementation [])\n (Lean.Expr.forallE\n `reasons\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "4b2ffafbf066633850901441a4978132cc3d84f95bef9c803f56a17866762054" + }, + "CoreReader.Adopted.choiceCases012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.conventional [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.established [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.status [])\n (Lean.Expr.const `CoreReader.Choice.StatusKind.convention [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.output [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.explanation []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.applicability []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.simplicity []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.procedure []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.cheapSuccessor []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.simplicity []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.cheapSuccessor []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.simplicity [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason [])))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulated [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.priorityArticulation [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.AssessmentAccurate [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `selected\n (Lean.Expr.const `CoreReader.Choice.Candidate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Models [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.statusFacts []))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.priorityClaim [])\n (Lean.Expr.const `CoreReader.Choice.Candidate.identity [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.priorityClaim [])\n (Lean.Expr.const `CoreReader.Choice.Candidate.successor []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Entails [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.statusFacts []))\n (Lean.Expr.const `CoreReader.Choice.priorityClaim []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.status [])\n (Lean.Expr.const `CoreReader.Choice.StatusKind.standing [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 []))\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Feasible [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Feasible [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.explanation []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.explanation [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.choiceSpecification [])\n (Lean.Expr.const `CoreReader.Integration.proposalRequirements []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Integration.PhilosophyMethod.implementation [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Integration.currentPhilosophy [])\n (Lean.Expr.const `CoreReader.Integration.actualSystem []))\n (Lean.Expr.const `CoreReader.Integration.actual []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.status [])\n (Lean.Expr.const `CoreReader.Choice.StatusKind.standing [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.choiceSpecification [])\n (Lean.Expr.const `CoreReader.Integration.proposalRequirements []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Integration.PhilosophyMethod.implementation [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Integration.currentPhilosophy [])\n (Lean.Expr.const `CoreReader.Integration.actualSystem []))\n (Lean.Expr.const `CoreReader.Integration.actual []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.output [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))\n (Lean.Expr.forallE\n `kind\n (Lean.Expr.const `CoreReader.Choice.StatusKind [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.choiceSpecification [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Choice.Reason.status []) (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason [])))))\n (Lean.BinderInfo.default))))))", + "sha256": "36f89bc4962aa87be316945afd3147dd30111dfdca8902a41b0392a2bda28c04" + }, + "CoreReader.Adopted.choiceLimits012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `candidate\n (Lean.Expr.const `CoreReader.Choice.Candidate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Iff [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Feasible [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Choice.implementation []) (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Choice.Candidate.identity [])))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.const `CoreReader.Choice.objectiveReason []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.conventional [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.established [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.status [])\n (Lean.Expr.const `CoreReader.Choice.StatusKind.convention [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.output [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 []))\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Feasible [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Feasible [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.explanation []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.explanation [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.const `CoreReader.Choice.objectiveReason [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.successorImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `x\n (Lean.Expr.const `Nat [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.changedOutsideZero []))\n (Lean.Expr.bvar 1)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.changedOutsideZero []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulated [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.priorityArticulation [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.AssessmentAccurate [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `selected\n (Lean.Expr.const `CoreReader.Choice.Candidate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Models [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.statusFacts []))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.priorityClaim [])\n (Lean.Expr.const `CoreReader.Choice.Candidate.identity [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.priorityClaim [])\n (Lean.Expr.const `CoreReader.Choice.Candidate.successor []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Entails [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.statusFacts []))\n (Lean.Expr.const `CoreReader.Choice.priorityClaim []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.status [])\n (Lean.Expr.const `CoreReader.Choice.StatusKind.standing [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))))))))\n (Lean.Expr.const `CoreReader.Choice.PolicyIndependenceExample []))))))", + "sha256": "84bdf70f43a217d10ccf0d7a8179aea2b586ab845a7c8f3a2f087089c6098874" + }, + "CoreReader.Engineering.inheritedMutualApplication": { + "type": "Lean.Expr.forallE\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.forallE\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.forallE\n `inherited\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.Inherited []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.generationSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.engineeringPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.reflexivitySpecification [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Outcome [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.rules [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 1))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.self [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 1))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.performed [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `principle\n (Lean.Expr.const `CoreReader.Engineering.CoreCommitment [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.valueSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.governancePosition []) (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.engineeringProcess []) (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringCapability [])\n (Lean.Expr.bvar 1))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.choiceSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.chosenRequirements []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.chosenImplementation [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.const `CoreReader.Engineering.chosenReasons [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `fact\n (Lean.Expr.const `CoreReader.Engineering.OwnFact [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.inferentialSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownFactPremises [])\n (Lean.Expr.bvar 2)))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.ownFactClaim []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `norm\n (Lean.Expr.const `CoreReader.Engineering.OwnNorm [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.normApplies []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.ownTheory []) (Lean.Expr.bvar 3))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownNormClaim [])\n (Lean.Expr.bvar 3))\n (Lean.Expr.bvar 1)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `claim\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Claim [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.ownTheory []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.inferentialSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownFactPremises [])\n (Lean.Expr.bvar 3)))\n (Lean.Expr.bvar 1))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.consistencySpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `CoreReader.Engineering.OwnFact []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringSnapshot [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringSnapshot [])\n (Lean.Expr.bvar 1))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.const `Bool.true []))))))))))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "b60496465943a095fdd0772f4002302eb9242ece03be7a2e20ce616f0253ee4a" + }, + "CoreReader.Engineering.inheritedMutualCases": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Inherited [])\n (Lean.Expr.const `CoreReader.Engineering.sharedContext []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.valueSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.governancePosition [])\n (Lean.Expr.const `CoreReader.Engineering.CoreCommitment.grounds []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringProcess [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringCapability [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.choiceSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.chosenRequirements []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.chosenImplementation [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.const `CoreReader.Engineering.chosenReasons [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.evaluate [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.evolutionMethod []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision [])))))\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict.counterexample [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.objects [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.generationRule [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.objects [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.assessmentRule [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.evaluate [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.assessmentRule []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision [])))))\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict.counterexample []))))))))", + "sha256": "e3c73c4f98c7a3fe5bfadc8b2bc7a9a5231473504e047179d6299e3417f2ba4c" + }, + "CoreReader.Engineering.ActivityScope": { + "type": "Lean.Expr.forallE\n `a\n (Lean.Expr.const `CoreReader.Engineering.Activity [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default)", + "sha256": "fdfa84c29643bd37a72d614541ecf59b4b7efdf606ac4b7480cb02fe3e4c8382" + }, + "CoreReader.Engineering.subjectLifecycleCases": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ActivityScope [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `String []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.label [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.lit (Lean.Literal.strVal \"temporary\"))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Continuing [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.const `CoreReader.Engineering.temporaryActivity [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.const `CoreReader.Engineering.prototypeActivity [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.const `CoreReader.Engineering.retiringActivity [])))))))))", + "sha256": "a2d126370b7fef5af4645ef64d85b169467518bfb8f76269b41f47f82e0bd02b" + }, + "CoreReader.Engineering.subjectLimits": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.original []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContinuingCapability [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `String []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.label [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.lit (Lean.Literal.strVal \"temporary\"))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.orientation [])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.passiveArtifact [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.maintainerActions [])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction.propose [])\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.artifactActions [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction.propose [])\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))))))))))", + "sha256": "4d0b23030599912d1ad72613e9956d5dd179d987aa64f0a694f74e85847b2a2b" + }, + "CoreReader.Engineering.EvolutionPriority": { + "type": "Lean.Expr.forallE\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.forallE\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "8609cb39944d272540e985febb940328bc4a85a6e22fe06e652f4c95bd043ddb" + }, + "CoreReader.Engineering.priorityConditionsCases": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.const `CoreReader.Engineering.normalRequirements []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2249646945) \"_hygCtx\") \"_hyg\") 19)\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.profile [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.unsafeOperations [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.latency [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.retention [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.const `CoreReader.Engineering.normalRequirements []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2249646945) \"_hygCtx\") \"_hyg\") 45)\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.profile [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.orderOutput [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.latency [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.retention [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.const `CoreReader.Engineering.normalRequirements []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2249646945) \"_hygCtx\") \"_hyg\") 65)\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.profile [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.orderOutput [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.unsafeOperations [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 11)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 11)))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.retention [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.const `CoreReader.Engineering.normalRequirements []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2249646945) \"_hygCtx\") \"_hyg\") 85)\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.profile [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.orderOutput [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.unsafeOperations [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.latency [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 29)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 29)))))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.verification [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2249646945) \"_hygCtx\") \"_hyg\") 113)\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.verification []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.required [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.evidence [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.limits [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Burden [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.profiles [])\n (Lean.Expr.bvar 0)))\n true))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.maximal [])))))))))", + "sha256": "3206e3bed26ebff1742e044beabbfcca534354e4895936cd6496b4af5a5485e9" + }, + "CoreReader.Engineering.priorityWhenApplicable": { + "type": "Lean.Expr.forallE\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.forallE\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.forallE\n `rule\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `applicable\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.PriorityConditions []) (Lean.Expr.bvar 2))\n (Lean.Expr.forallE\n `noDeparture\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture []) (Lean.Expr.bvar 3))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.bvar 3))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity []) (Lean.Expr.bvar 3))))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "6b1efb7cab71c9b837ce57e666f331112f6416f18a59675e8119416b3d7a39a6" + }, + "CoreReader.Engineering.priorityChoices": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.verification [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple [])))", + "sha256": "d4cbb2cea4f863c0a900531a90fd4e36cd04ad50df57b340871001d6fb01b349" + }, + "CoreReader.Engineering.CredibleDirection": { + "type": "Lean.Expr.forallE\n `Ground\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `grounds\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `articulated\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 1)\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `supports\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 2)\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Engineering.Change [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `d\n (Lean.Expr.const `CoreReader.Engineering.Change [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)", + "sha256": "1906e98dd6d042fc973fb93506c24accc024a7643adaddd05e071030c8b5682b" + }, + "CoreReader.Engineering.credibilityCases": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.initialGrounds []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround.knowledge [])\n (Lean.Expr.lit (Lean.Literal.strVal \"queue\")))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))))\n (Lean.Expr.lit (Lean.Literal.strVal \"tenant-config-reload\"))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround []))))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround.history [])\n (Lean.Expr.lit (Lean.Literal.strVal \"queue\")))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.const `CoreReader.Engineering.Change.migration []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.const `CoreReader.Engineering.Change.migration []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround []))))\n (Lean.Expr.const `CoreReader.Engineering.Change.migration [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"quantum backend\"))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.forecastGrounds []))\n (Lean.Expr.const `CoreReader.Engineering.Change.deletion [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.forecastGrounds []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))))))", + "sha256": "b5d172388be7bcd1bdbeea1f07436b61458bd02c0e714dc83b7d7565adefa6c9" + }, + "CoreReader.Engineering.credibilityLimits": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.initialGrounds []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `CoreReader.Engineering.implementedVariants [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.WarrantedAccommodation [])\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"quantum backend\"))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.initialGrounds []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"quantum backend\"))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.maximal []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.cost [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Burden.construction [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.cost [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Burden.migration []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.MaximumRegisteredCapability [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.MaximumRegisteredCapability [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.maximal [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.supportedDirections [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 9)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 9))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.supportedDirections [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.maximal []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 10))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.initialGrounds []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"csv export\")))))))))))))))", + "sha256": "76415ebe0bbc33c3827da7db33b1e89e3f676b7cf0f4f39df5401beeda5f40c4" + }, + "CoreReader.Engineering.JustifiedDeparture": { + "type": "Lean.Expr.forallE\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.forallE\n `c\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "f6c50ef1eaca65b4a3886bcbc5ccb11393e89a2d7baf8f6980b6a58f9d0719a4" + }, + "CoreReader.Engineering.costCases": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.understanding [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.construction [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.diagnosis [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.verification [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.coordination [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.operation [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.migration [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 797674858) \"_hygCtx\") \"_hyg\") 72)\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.required [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.evidence [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.limits [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Option.some [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Burden []))\n (Lean.Expr.const `CoreReader.Engineering.Burden.migration [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.profiles [])\n (Lean.Expr.bvar 0)))\n true))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))))))))", + "sha256": "0159f38d1da3fe90524ce5a5d2e2b1d3a4fc5a14c6a76a6fbc07a158d16edd90" + }, + "CoreReader.Engineering.EvolutionClaim": { + "type": "Lean.Expr.forallE\n `a\n (Lean.Expr.const `CoreReader.Engineering.Activity [])\n (Lean.Expr.forallE\n `c\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.forallE\n `claim\n (Lean.Expr.const `CoreReader.Engineering.ChangeClaim [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "9c0c528a387fd26adf8c44acbd1e97da3c991c6544f40f31c0a8c3adb2ccd2f7" + }, + "CoreReader.Engineering.evolutionKindsCases": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.capabilities [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.addition []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"deduplicate\")))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"tenant batching\")))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `String []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.implementation [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.replacement []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.mechanisms [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.deletion []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"queue\")))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `String [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.abstractions [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.withdrawal []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `String []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.boundary [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.redrawing []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `String []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.technology [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.migration []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.lit (Lean.Literal.strVal \"portable store\"))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.all [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.const `CoreReader.Engineering.changes []))\n (Lean.Expr.lam\n `d\n (Lean.Expr.const `CoreReader.Engineering.Change [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Decidable.decide [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instDecidableAnd [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.participants [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.all [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.lam\n `step\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Bool.and [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.const\n `CoreReader.Engineering.instDecidableEqKnowledge\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.available [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.requires [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqTool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.tools [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.tool [])\n (Lean.Expr.bvar 0))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instDecidableNot [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.instDecidableEqNil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instDecidableAnd [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.participants [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.all [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.lam\n `step\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Bool.and [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.const\n `CoreReader.Engineering.instDecidableEqKnowledge\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.available [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.requires [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqTool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.tools [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.tool [])\n (Lean.Expr.bvar 0))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.instDecidableMemOfLawfulBEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqMaintainer [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instLawfulBEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqMaintainer [])))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.participants [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instDecidableEqBool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.all [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.lam\n `step\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Bool.and [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.const\n `CoreReader.Engineering.instDecidableEqKnowledge\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.available [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.requires [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqTool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.tools [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.tool [])\n (Lean.Expr.bvar 0))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionClaim [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ChangeClaim.mk [])\n (Lean.Expr.const `CoreReader.Engineering.Change.replacement []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.ObligationTreatment.preserve []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionClaim [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ChangeClaim.mk [])\n (Lean.Expr.const `CoreReader.Engineering.Change.redrawing []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent []))\n (Lean.Expr.const `CoreReader.Engineering.ObligationTreatment.revise []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.independent [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated [])))))))))))", + "sha256": "ccab4c5ed0bb676cef2d8435b8252630c0bc2f32d0ce9023156532deb6b77a1e" + }, + "CoreReader.Engineering.evolutionDimensionsLimits": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.addition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.withdrawal [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 17)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 17))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.independent [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 9)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 9)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.migration []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.original []))\n (Lean.Expr.const `CoreReader.Engineering.Change.addition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.original []))\n (Lean.Expr.const `CoreReader.Engineering.Change.addition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.original []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.original []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.addition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.addition []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.capabilities [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"csv export\"))))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"deduplicate\")))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"csv export\")))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `String []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.maximal []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"csv export\")))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"csv export\")))))))))))))))))", + "sha256": "ba2af856a831323eaa2344e83084a08689b7a287f6a8542edcef6fb0c2e57af7" + }, + "CoreReader.Engineering.StructuralAccount": { + "type": "Lean.Expr.forallE\n `a\n (Lean.Expr.const `CoreReader.Engineering.Activity [])\n (Lean.Expr.forallE\n `c\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.forallE\n `e\n (Lean.Expr.const `CoreReader.Engineering.StructuralEvidence [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "45df6c2c2383df05162c2a265ba6daf5debbdf46847dc9de1801f881eb00db1e" + }, + "CoreReader.Engineering.structuralCases": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.StructuralAccount [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.structuralEvidence [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.propagation [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.propagation [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.any [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated [])))\n (Lean.Expr.lam\n `s\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Bool.and [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `BEq.beq [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instDecidableEqNat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.component [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `BEq.beq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqKnowledge [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.requires [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `CoreReader.Engineering.Knowledge.publicContract [])))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.orderedRefactor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.StructuralEvidence.observedBefore [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.structuralEvidence [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.StructuralEvidence.observedAfter [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.structuralEvidence [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.staticBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 10))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 10)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.staticBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.withdrawal [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 17)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 17))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.crossesBoundary [])\n (Lean.Expr.const `CoreReader.Engineering.boundaryDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.coordinatedBoundary [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.boundaryObligationChecked [])\n (Lean.Expr.const `CoreReader.Engineering.boundaryDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.coordinatedBoundary [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.crossesBoundary [])\n (Lean.Expr.const `CoreReader.Engineering.omittedCallerCheck []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.coordinatedBoundary [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.boundaryObligationChecked [])\n (Lean.Expr.const `CoreReader.Engineering.omittedCallerCheck []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.coordinatedBoundary [])))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.crossesBoundary [])\n (Lean.Expr.const `CoreReader.Engineering.otherCalleeDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.otherCalleeBoundary [])))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.boundaryObligationChecked [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 1550649743) \"_hygCtx\") \"_hyg\") 194)\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign [])\n (Lean.Expr.const `CoreReader.Engineering.boundaryDesign [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.mk [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Engineering.EngineeringDesign.metadata\n [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `CoreReader.Engineering.sortedUnique []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.paths [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Engineering.EngineeringDesign.components\n [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.boundaries [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Engineering.EngineeringDesign.batchAssumptions\n [])\n (Lean.Expr.bvar 0)))\n true))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.coordinatedBoundary [])))\n (Lean.Expr.const `Bool.false [])))))))))))))))", + "sha256": "4fdfb378096465bfe330f655d5cc248745bbfdcb505407595d9d23254428de9e" + }, + "CoreReader.Engineering.structureNotCapability": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `String []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.InterfaceView.signature [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.InterfaceView.signature [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.sortedDesign [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.sortedDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.InterfaceView.modules [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.components [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.batchAssumptions [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 8)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 8))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designModulesNeedingRevision [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 8)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 8))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `String []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.InterfaceView.principle [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))))\n (Lean.Expr.lit (Lean.Literal.strVal \"dependency inversion\"))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.InterfaceView []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.documentedDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.DesignCanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.DesignCanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.documentedDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.boundaries [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.boundaries [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.components [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 9)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 9))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.boundaries [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Boundary.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 8)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 8)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.lit (Lean.Literal.strVal \"List Nat → List Nat\"))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 17)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 17))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 18)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 18))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.boundaries [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Boundary.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 8)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 8)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.lit (Lean.Literal.strVal \"List Nat → List Nat\"))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.components [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 9)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 9))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.paths [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.paths [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 17)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 17))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.DesignCanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))))))))))", + "sha256": "2c09939db7dbc6561ff01284d1187a4272120050885c7743d2227d2a6e133ea9" + }, + "CoreReader.Engineering.ContractChangeAccount": { + "type": "Lean.Expr.forallE\n `old\n (Lean.Expr.const `CoreReader.Engineering.ObservableContract [])\n (Lean.Expr.forallE\n `new\n (Lean.Expr.const `CoreReader.Engineering.ObservableContract [])\n (Lean.Expr.forallE\n `r\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "c58d92d3f41481a1b24941446085e8161c5dcb32cc266487f9734c2c03c8d3fe" + }, + "CoreReader.Engineering.contractCases": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.refactoredContract []))\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 640854215) \"_hygCtx\") \"_hyg\") 28)\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision [])\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.deliberate [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.revisedOrder [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.oldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.newFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedOldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedNewFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.procedure [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.retiredBehavior [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.retiredBehavior [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 99)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 99)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 99)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 99)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 640854215) \"_hygCtx\") \"_hyg\") 68)\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision [])\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.deliberate [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.revisedOrder [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.affected [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.oldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.newFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedOldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedNewFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.lit (Lean.Literal.strVal \"paired audit\")))\n true))))))", + "sha256": "d577c98b03b1349b8acdc20e24a2d1141ea92e5ce49ab73e3518385e0981adeb" + }, + "CoreReader.Engineering.contractPreservation": { + "type": "Lean.Expr.forallE\n `Input\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `Output\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `scope\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 1)\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `old\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 2)\n (Lean.Expr.bvar 2)\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `new\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 3)\n (Lean.Expr.bvar 3)\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `observations\n (Lean.Expr.forallE\n `x\n (Lean.Expr.bvar 4)\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app (Lean.Expr.bvar 3) (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.bvar 5))\n (Lean.Expr.app (Lean.Expr.bvar 2) (Lean.Expr.bvar 1)))\n (Lean.Expr.app (Lean.Expr.bvar 3) (Lean.Expr.bvar 1)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.PreservesOn []) (Lean.Expr.bvar 5))\n (Lean.Expr.bvar 4))\n (Lean.Expr.bvar 3))\n (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit))\n (Lean.BinderInfo.implicit)", + "sha256": "d9078e49c446deddda26e669891464c695136710e6b34620ca8ee4f08bdafbed" + }, + "CoreReader.Engineering.contractDistinctions": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.orderedRefactor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.sortedUnique []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.retry [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3))))))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.retry [])\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesContractFinite [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.affectedParties [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"queue consumer\")))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"queue operator\")))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `String []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2260969961) \"_hygCtx\") \"_hyg\") 73)\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision [])\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.deliberate [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.revisedOrder [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"queue consumer\")))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `String []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.oldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.newFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedOldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedNewFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.procedure [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2260969961) \"_hygCtx\") \"_hyg\") 97)\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision [])\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.deliberate [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.revisedOrder [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.affected [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 5)))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.newFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 5)))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedNewFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.procedure [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.retiredBehavior [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.retiredBehavior [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 99)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 99)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 99)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 99)))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))))))))))))", + "sha256": "bc0f83a82833ba24fc73f01ff24ac513e5ce42fec36a8195c70d516365a07a28" + }, + "CoreReader.Engineering.RevisionAccount": { + "type": "Lean.Expr.forallE\n `r\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default)", + "sha256": "865a4c6c542f07f6b0ce44a67e98175239ef389738b16bc6071ccebffae61c8b" + }, + "CoreReader.Engineering.revisionCases": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionAccount [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.forecast [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.forecast [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.maintenance [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.maintenance [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.maintainers [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.maintainers [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.migrationCost [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.migrationCost [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.objectiveCapacity [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.objectiveCapacity [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.predictedBatchCount [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.actualBatchCount [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RetentionJustified [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"quantum backend\"))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RetentionJustified [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.migration [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.const `CoreReader.Engineering.Change.migration []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change [])))))))))))", + "sha256": "8e2008450f4c7a80eca24630a18e6c77bf570055daee2c75c2577987c06ff629" + }, + "CoreReader.Engineering.revisionLimits": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionAccount [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionAccount [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 3857095740) \"_hygCtx\") \"_hyg\") 17)\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.software [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.recordedOld [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.recordedCurrent [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.predictedBatchCount [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.actualBatchCount [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.consideredChanges [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.criticizedDirections [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Engineering.revisionsMade [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.agreedBatch [])\n (Lean.Expr.const `CoreReader.Engineering.maintainers []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.all [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.const `CoreReader.Engineering.observations []))\n (Lean.Expr.lam\n `p\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `BEq.beq [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instDecidableEqNat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.staticBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.fst [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.fst [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.staticBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionAccount [])\n (Lean.Expr.const `CoreReader.Engineering.stableRecord [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.choice [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.stableRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.choice [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.stableRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RetentionJustified [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"quantum backend\"))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))))))))))))", + "sha256": "071a3e5cddf46166eacbd56285cdb4abb9f11a94e50e8bf00f8bc100f01026d0" + }, + "CoreReader.Engineering.priorityRemainsReflexive": { + "type": "Lean.Expr.forallE\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.forallE\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.forallE\n `inherited\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.Inherited []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `domain\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.DomainSatisfied []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.forallE\n `applicable\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.PriorityConditions []) (Lean.Expr.bvar 3))\n (Lean.Expr.forallE\n `noDeparture\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture []) (Lean.Expr.bvar 4))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.bvar 4))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.objects [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 4))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.priority [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.reflexivitySpecification [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Outcome [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.rules [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 4))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.self [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 4))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.performed [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 4)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `principle\n (Lean.Expr.const `CoreReader.Engineering.CoreCommitment [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.valueSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.governancePosition [])\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.bvar 5)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.value [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.AssessmentTask.value [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.ownTheory []) (Lean.Expr.bvar 4))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownNormClaim [])\n (Lean.Expr.bvar 4))\n (Lean.Expr.const `CoreReader.Engineering.OwnNorm.domain []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.consistencySpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `CoreReader.Engineering.OwnFact []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringSnapshot [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringSnapshot [])\n (Lean.Expr.bvar 4))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.const `Bool.true []))))))))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "285b4edb7397d25ccc631b194a1ff8ebb5204df450d52ec8eaf0685519b289c2" + }, + "CoreReader.Engineering.priorityReflexiveCases": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.objects [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.priority [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.objectTest [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.priority []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 10)))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.performed [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.PrincipleKey.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.priority []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.priority []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Outcome.assessed [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict.supportedWithinScope []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.evaluate [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.evolutionMethod []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision [])))))\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict.counterexample [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.objectTest [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.evolutionMethod []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 10)))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.objectTest [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.evolutionMethod []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.sharedContext [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.value [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.AssessmentTask.value [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.evaluate [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.assessmentRule []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision [])))))\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict.counterexample []))))))))", + "sha256": "2be55699c66ab5ba0f6310f298e19b890de4caef622e0d69676f2d6a7a3b5170" + }, + "CoreReader.Engineering.jointWitness": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Context []))\n (Lean.Expr.lam\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.lam\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Context []))\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.sharedContext [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.Inherited []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.DomainSatisfied []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.PriorityConditions []) (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.HasThreat []) (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownTheory [])\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownFactClaim [])\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.OwnFact.selected []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.objects [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.commitment [])\n (Lean.Expr.const `CoreReader.Engineering.CoreCommitment.grounds []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `CoreReader.Engineering.OwnFact []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownTheory [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.comparisonContext [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.bvar 0)))))))))))))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default))", + "sha256": "56d1bd97b0ac6c069484812a2a975dc185a905a24ee133a780b5f23a7fdc0b59" + }, + "CoreReader.Engineering.inheritedDoesNotEntailPriority": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Context []))\n (Lean.Expr.lam\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.lam\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Context []))\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.sharedContext [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.Inherited []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.PriorityConditions []) (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Continuing [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.Context.activity []) (Lean.Expr.bvar 1))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.HasThreat []) (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.required [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.profiles [])\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.required [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.profiles [])\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.evidence [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `LT.lt [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `LT.lt [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.valueSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))))))))))))))))))))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default))", + "sha256": "ad1b1b45257f57a53567b08bc87eb32bd6d8acf8395e9762a684c1116f270197" + } +} diff --git a/SoftwareEngineering/lean/philosophy/evidence/execution-identity.json b/SoftwareEngineering/lean/philosophy/evidence/execution-identity.json new file mode 100644 index 0000000..2ab482f --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/evidence/execution-identity.json @@ -0,0 +1,23 @@ +{ + "schema_version": 1, + "assessment": "self_reported_not_approval", + "sources_at_module_load": { + "skills/organon-core-leanify-prove/scripts/check.js": "74194794f7b058740255aa0ad8099b2c27bc8b4cf82cbf0f1336fc03f5348240", + "skills/organon-core-leanify-prove/scripts/manuscript.js": "e1aed330b703c2a5901e0cbca4b47b4d75602375646a462ced2e268f1aba4dcc", + "skills/organon-core-leanify-prove/scripts/targets.js": "cab6a7a55b852a2f29ca00ef9f03331a30549b2ba16d32d69138f488fdbc8888", + "scripts/lib/sections.js": "35c8cc81ea851e79af7ef9996e800112efa97c71005abecd59287a52ba8da180", + "scripts/lib/frontmatter.js": "42773238b4a39f6d5d374a814b5e23821340d55aea3e1972e5cac5a6820c354e" + }, + "node": { + "status": "observed", + "version": "v22.23.2" + }, + "lean": { + "status": "observed", + "version": "4.33.1" + }, + "lake": { + "status": "observed", + "version": "5.0.0-src+819816b" + } +} diff --git a/SoftwareEngineering/lean/philosophy/evidence/inputs-sha256.json b/SoftwareEngineering/lean/philosophy/evidence/inputs-sha256.json new file mode 100644 index 0000000..76699d9 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/evidence/inputs-sha256.json @@ -0,0 +1,20 @@ +{ + "run.json": "18a076e48d5b40c97031ddf35a293ef1399c38cc444cf028be21f6d956924b62", + "PREREGISTERED.md": "f39cb0e07ace7d0ea330d90f8102f06f8f623d976ad8e0f3e6df729772bfbfcc", + "snapshots/PHILOSOPHY.md": "adc8cce5ac55a5e3795f8806748603eb69d5695fa37bbe263bee20ac6c14a1a6", + "leanified/lakefile.toml": "05d8ba36975f87aca61e3b0ddcacc42669539f316ba9b8eef5859961e2aa6fdc", + "targets.json": "19184f5f301fb5a2f156d09a1d5b4fee5f9e8e9bbc96fdc5fbbc9ccb426287bb", + "leanified/CoreReader/Adopted.lean": "8de4d364bb3c64e29ab92e81d86cbe4c9e5af49ada3dad262d1378421fb588c2", + "leanified/CoreReader/Agency.lean": "2722c34645f4256f20ce31205738f2f5712ab5dd5cc6fcf9f1180d0be5aa0303", + "leanified/CoreReader/Choice.lean": "b28728df12ed7e73edb5569604cd2541c0ebd815ae3aaa0812e6557dece1d1ba", + "leanified/CoreReader/Engineering/Domain.lean": "ce5653a2950cc7443cefbfe8b9726bd4859228e831ddb7d42601e501ccbfd855", + "leanified/CoreReader/Engineering/Integration.lean": "a2b88062148b3f7ebea7da02d88cb29cb04d8f1b2e9e6b97bb2420ac2c006328", + "leanified/CoreReader/Engineering/Reflection.lean": "c290d8472884d00bedbf945f0fc1866524e758740f40d42088c4ff9678a93fa2", + "leanified/CoreReader/Engineering/SelfApplication.lean": "d69c0d369bd4fd8db4c21ce3b65abb5e9efd07ed5ab9a68d56b4db39bb9d2a21", + "leanified/CoreReader/Engineering/Values.lean": "ccd45bf23d2f47c41d1b2f9955d753e290687d951a0c55af41ab9a63b9a8d9cb", + "leanified/CoreReader/Evidence.lean": "d55f33e44902cef146841cbffb65710bd7c8a3bda79d01d084edc36f019fdc96", + "leanified/CoreReader/Integration.lean": "97e2939c0b6714b78a3ed78358e174619a5028ad5b0b5025c0d4422b4294921b", + "leanified/CoreReader/Logic.lean": "0ec342691766ebd83d251dcd0da3b0ae9840aed677a714bc1b01c45d89392bc0", + "leanified/CoreReader/Reflexivity.lean": "48e2c74e7cbae571db1b990b9f32dd0d701f6881a8b0111d907f8861287d76fa", + "leanified/CoreReader.lean": "c5574fae235419a7d6449b3ebb5d2da29d1e92a3b572c1b759438e3c470caaa9" +} diff --git a/SoftwareEngineering/lean/philosophy/evidence/kernel.json b/SoftwareEngineering/lean/philosophy/evidence/kernel.json new file mode 100644 index 0000000..a32f2a1 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/evidence/kernel.json @@ -0,0 +1,814 @@ +{ + "passed": true, + "semantic_status": "not_evaluated", + "errors": [], + "checked": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases", + "CoreReader.Adopted.generationLimits012", + "CoreReader.Adopted.consistencySpecification", + "CoreReader.Adopted.consistencyCases", + "CoreReader.Adopted.consistencyConsequences", + "CoreReader.Adopted.consistencyLimits012", + "CoreReader.Adopted.reflexivitySpecification", + "CoreReader.Adopted.reflexivityCases012", + "CoreReader.Adopted.reflexivityLimits012", + "CoreReader.Adopted.Grounds012", + "CoreReader.Adopted.groundsCases012", + "CoreReader.Adopted.empiricalSpecification", + "CoreReader.Adopted.empiricalCases012", + "CoreReader.Adopted.inferentialSpecification", + "CoreReader.Adopted.inferentialCases012", + "CoreReader.Adopted.valueSpecification", + "CoreReader.Adopted.valueCases012", + "CoreReader.Adopted.groundsLimits012", + "CoreReader.Adopted.scopeSpecification", + "CoreReader.Adopted.scopeCases012", + "CoreReader.Adopted.scopeLimits012", + "CoreReader.Adopted.capabilitySpecification", + "CoreReader.Adopted.capabilityCases012", + "CoreReader.Adopted.capabilityLimits012", + "CoreReader.Adopted.choiceSpecification", + "CoreReader.Adopted.choiceCases012", + "CoreReader.Adopted.choiceLimits012", + "CoreReader.Engineering.inheritedMutualApplication", + "CoreReader.Engineering.inheritedMutualCases", + "CoreReader.Engineering.ActivityScope", + "CoreReader.Engineering.subjectLifecycleCases", + "CoreReader.Engineering.subjectLimits", + "CoreReader.Engineering.EvolutionPriority", + "CoreReader.Engineering.priorityConditionsCases", + "CoreReader.Engineering.priorityWhenApplicable", + "CoreReader.Engineering.priorityChoices", + "CoreReader.Engineering.CredibleDirection", + "CoreReader.Engineering.credibilityCases", + "CoreReader.Engineering.credibilityLimits", + "CoreReader.Engineering.JustifiedDeparture", + "CoreReader.Engineering.costCases", + "CoreReader.Engineering.EvolutionClaim", + "CoreReader.Engineering.evolutionKindsCases", + "CoreReader.Engineering.evolutionDimensionsLimits", + "CoreReader.Engineering.StructuralAccount", + "CoreReader.Engineering.structuralCases", + "CoreReader.Engineering.structureNotCapability", + "CoreReader.Engineering.ContractChangeAccount", + "CoreReader.Engineering.contractCases", + "CoreReader.Engineering.contractPreservation", + "CoreReader.Engineering.contractDistinctions", + "CoreReader.Engineering.RevisionAccount", + "CoreReader.Engineering.revisionCases", + "CoreReader.Engineering.revisionLimits", + "CoreReader.Engineering.priorityRemainsReflexive", + "CoreReader.Engineering.priorityReflexiveCases", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ], + "dependencies": { + "CoreReader.Adopted.generationSpecification": [], + "CoreReader.Adopted.generationCases": [ + "propext", + "Quot.sound" + ], + "CoreReader.Adopted.generationLimits012": [ + "propext", + "Quot.sound" + ], + "CoreReader.Adopted.consistencySpecification": [], + "CoreReader.Adopted.consistencyCases": [], + "CoreReader.Adopted.consistencyConsequences": [], + "CoreReader.Adopted.consistencyLimits012": [], + "CoreReader.Adopted.reflexivitySpecification": [], + "CoreReader.Adopted.reflexivityCases012": [ + "propext", + "Classical.choice", + "Quot.sound" + ], + "CoreReader.Adopted.reflexivityLimits012": [ + "propext", + "Quot.sound" + ], + "CoreReader.Adopted.Grounds012": [ + "propext" + ], + "CoreReader.Adopted.groundsCases012": [ + "propext" + ], + "CoreReader.Adopted.empiricalSpecification": [ + "propext" + ], + "CoreReader.Adopted.empiricalCases012": [ + "propext" + ], + "CoreReader.Adopted.inferentialSpecification": [ + "propext" + ], + "CoreReader.Adopted.inferentialCases012": [ + "propext" + ], + "CoreReader.Adopted.valueSpecification": [ + "propext" + ], + "CoreReader.Adopted.valueCases012": [ + "propext", + "Classical.choice", + "Quot.sound" + ], + "CoreReader.Adopted.groundsLimits012": [ + "propext", + "Classical.choice", + "Quot.sound" + ], + "CoreReader.Adopted.scopeSpecification": [], + "CoreReader.Adopted.scopeCases012": [ + "propext" + ], + "CoreReader.Adopted.scopeLimits012": [ + "propext", + "Quot.sound" + ], + "CoreReader.Adopted.capabilitySpecification": [ + "propext" + ], + "CoreReader.Adopted.capabilityCases012": [ + "propext" + ], + "CoreReader.Adopted.capabilityLimits012": [ + "propext", + "Quot.sound" + ], + "CoreReader.Adopted.choiceSpecification": [], + "CoreReader.Adopted.choiceCases012": [ + "propext", + "Classical.choice", + "Quot.sound" + ], + "CoreReader.Adopted.choiceLimits012": [ + "propext", + "Classical.choice", + "Quot.sound" + ], + "CoreReader.Engineering.inheritedMutualApplication": [ + "propext" + ], + "CoreReader.Engineering.inheritedMutualCases": [ + "propext", + "Classical.choice", + "Quot.sound" + ], + "CoreReader.Engineering.ActivityScope": [], + "CoreReader.Engineering.subjectLifecycleCases": [ + "propext" + ], + "CoreReader.Engineering.subjectLimits": [ + "propext" + ], + "CoreReader.Engineering.EvolutionPriority": [], + "CoreReader.Engineering.priorityConditionsCases": [ + "propext" + ], + "CoreReader.Engineering.priorityWhenApplicable": [], + "CoreReader.Engineering.priorityChoices": [ + "propext" + ], + "CoreReader.Engineering.CredibleDirection": [], + "CoreReader.Engineering.credibilityCases": [], + "CoreReader.Engineering.credibilityLimits": [ + "propext" + ], + "CoreReader.Engineering.JustifiedDeparture": [], + "CoreReader.Engineering.costCases": [ + "propext" + ], + "CoreReader.Engineering.EvolutionClaim": [], + "CoreReader.Engineering.evolutionKindsCases": [ + "propext" + ], + "CoreReader.Engineering.evolutionDimensionsLimits": [ + "propext" + ], + "CoreReader.Engineering.StructuralAccount": [], + "CoreReader.Engineering.structuralCases": [ + "propext" + ], + "CoreReader.Engineering.structureNotCapability": [ + "propext" + ], + "CoreReader.Engineering.ContractChangeAccount": [], + "CoreReader.Engineering.contractCases": [], + "CoreReader.Engineering.contractPreservation": [], + "CoreReader.Engineering.contractDistinctions": [], + "CoreReader.Engineering.RevisionAccount": [], + "CoreReader.Engineering.revisionCases": [ + "propext" + ], + "CoreReader.Engineering.revisionLimits": [ + "propext" + ], + "CoreReader.Engineering.priorityRemainsReflexive": [ + "propext", + "Classical.choice", + "Quot.sound" + ], + "CoreReader.Engineering.priorityReflexiveCases": [ + "propext", + "Classical.choice", + "Quot.sound" + ], + "CoreReader.Engineering.jointWitness": [ + "propext", + "Classical.choice", + "Quot.sound" + ], + "CoreReader.Engineering.inheritedDoesNotEntailPriority": [ + "propext", + "Classical.choice", + "Quot.sound" + ] + }, + "reported_reviews": [], + "proof_targets": { + "sha256": "19184f5f301fb5a2f156d09a1d5b4fee5f9e8e9bbc96fdc5fbbc9ccb426287bb", + "complete": true, + "semantic_status": "not_evaluated", + "entries": [ + { + "id": "T01", + "kind": "boundary", + "reported_status": "accepted", + "declarations": [] + }, + { + "id": "T02", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases" + ] + }, + { + "id": "T03", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.generationLimits012" + ] + }, + { + "id": "T04", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.consistencySpecification", + "CoreReader.Adopted.consistencyCases" + ] + }, + { + "id": "T05", + "kind": "theorem", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.consistencyConsequences", + "CoreReader.Adopted.consistencyCases" + ] + }, + { + "id": "T06", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.consistencyLimits012" + ] + }, + { + "id": "T07", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.reflexivitySpecification", + "CoreReader.Adopted.reflexivityCases012" + ] + }, + { + "id": "T08", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.reflexivityLimits012" + ] + }, + { + "id": "T09", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.Grounds012", + "CoreReader.Adopted.groundsCases012" + ] + }, + { + "id": "T10", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.empiricalSpecification", + "CoreReader.Adopted.empiricalCases012" + ] + }, + { + "id": "T11", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.inferentialSpecification", + "CoreReader.Adopted.inferentialCases012" + ] + }, + { + "id": "T12", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.valueSpecification", + "CoreReader.Adopted.valueCases012" + ] + }, + { + "id": "T13", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.groundsLimits012" + ] + }, + { + "id": "T14", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.scopeSpecification", + "CoreReader.Adopted.scopeCases012" + ] + }, + { + "id": "T15", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.scopeLimits012" + ] + }, + { + "id": "T16", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.capabilitySpecification", + "CoreReader.Adopted.capabilityCases012" + ] + }, + { + "id": "T17", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.capabilityLimits012" + ] + }, + { + "id": "T18", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.choiceSpecification", + "CoreReader.Adopted.choiceCases012" + ] + }, + { + "id": "T19", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.choiceLimits012" + ] + }, + { + "id": "T20", + "kind": "theorem", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.inheritedMutualApplication", + "CoreReader.Engineering.inheritedMutualCases" + ] + }, + { + "id": "T21", + "kind": "boundary", + "reported_status": "accepted", + "declarations": [] + }, + { + "id": "T22", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.ActivityScope", + "CoreReader.Engineering.subjectLifecycleCases" + ] + }, + { + "id": "T23", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.subjectLimits" + ] + }, + { + "id": "T24", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.EvolutionPriority", + "CoreReader.Engineering.priorityConditionsCases" + ] + }, + { + "id": "T25", + "kind": "theorem", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.priorityWhenApplicable", + "CoreReader.Engineering.priorityChoices" + ] + }, + { + "id": "T26", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.CredibleDirection", + "CoreReader.Engineering.credibilityCases" + ] + }, + { + "id": "T27", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.credibilityLimits" + ] + }, + { + "id": "T28", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.JustifiedDeparture", + "CoreReader.Engineering.costCases" + ] + }, + { + "id": "T29", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.EvolutionClaim", + "CoreReader.Engineering.evolutionKindsCases" + ] + }, + { + "id": "T30", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.evolutionDimensionsLimits" + ] + }, + { + "id": "T31", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.StructuralAccount", + "CoreReader.Engineering.structuralCases" + ] + }, + { + "id": "T32", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.structureNotCapability" + ] + }, + { + "id": "T33", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.ContractChangeAccount", + "CoreReader.Engineering.contractCases" + ] + }, + { + "id": "T34", + "kind": "theorem", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.contractPreservation", + "CoreReader.Engineering.contractDistinctions" + ] + }, + { + "id": "T35", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.RevisionAccount", + "CoreReader.Engineering.revisionCases" + ] + }, + { + "id": "T36", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.revisionLimits" + ] + }, + { + "id": "T37", + "kind": "theorem", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.priorityRemainsReflexive", + "CoreReader.Engineering.priorityReflexiveCases" + ] + }, + { + "id": "T38", + "kind": "satisfiability", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.jointWitness" + ] + }, + { + "id": "T39", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ] + }, + { + "id": "T40", + "kind": "boundary", + "reported_status": "accepted", + "declarations": [] + } + ] + }, + "declaration_types": { + "CoreReader.Adopted.generationSpecification": { + "type": "Lean.Expr.forallE\n `policy\n (Lean.Expr.const `CoreReader.Agency.Policy [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default)", + "sha256": "4d07b8deec9112ff5d3e7fe744c159c254580260c78b82be6dd64347e8a9a4eb" + }, + "CoreReader.Adopted.generationCases": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `k\n (Lean.Expr.const `CoreReader.Agency.FormKind [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.revisable [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Form.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.forallE\n `t\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.stableTrace []) (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.stableTrace [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `HAdd.hAdd [Lean.Level.zero, Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `instHAdd [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instAddNat [])))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.permitsVersion [])\n (Lean.Expr.const `CoreReader.Agency.neutralPolicy []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.const `CoreReader.Agency.neutralPolicy []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.permitsVersion [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.availableResources [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Option.some [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 6)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 1780710401) \"_hygCtx\") \"_hyg\") 147)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 1780710401) \"_hygCtx\") \"_hyg\") 166)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `Option [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 1780710401) \"_hygCtx\") \"_hyg\") 185)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n true)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `Option [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.requirementsMet [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.StableReason [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Announcement []))\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.GeneratingSystem.report\n [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.owner [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.owner [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.before [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.after [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.reportedNewOperation\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.input [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const\n `Eq\n [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.expectedOutput\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.claim\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.before\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.after\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))))))))))))))))))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.generationSpecification [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.const `CoreReader.Agency.baseState []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.collaborativeRevision [])\n (Lean.Expr.const `CoreReader.Agency.availableResources []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.const `CoreReader.Agency.baseState []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.collaborativeRevision [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 1780710401) \"_hygCtx\") \"_hyg\") 355)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n true)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.assistedExecution [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))))", + "sha256": "430a91318477db0305b3107b81f9df39652fa27673fdc38705a86f8e158ca138" + }, + "CoreReader.Adopted.generationLimits012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.permitsVersion [])\n (Lean.Expr.const `CoreReader.Agency.neutralPolicy []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.const `CoreReader.Agency.neutralPolicy []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `k\n (Lean.Expr.const `CoreReader.Agency.FormKind [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.revisable [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Form.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.forallE\n `t\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.stableTrace []) (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.stableTrace [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `HAdd.hAdd [Lean.Level.zero, Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `instHAdd [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instAddNat [])))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.permitsVersion [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.availableResources [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Option.some [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 6)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3022720055) \"_hygCtx\") \"_hyg\") 147)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3022720055) \"_hygCtx\") \"_hyg\") 166)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `Option [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3022720055) \"_hygCtx\") \"_hyg\") 185)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n true)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `Option [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.requirementsMet [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.StableReason [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Announcement []))\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.GeneratingSystem.report\n [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.owner [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.owner [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.before [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.after [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.reportedNewOperation\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.input [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const\n `Eq\n [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.expectedOutput\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.claim\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.before\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.after\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))))))))))))))))))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.generationSpecification [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.const `CoreReader.Agency.baseState []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.collaborativeRevision [])\n (Lean.Expr.const `CoreReader.Agency.availableResources []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.const `CoreReader.Agency.baseState []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.collaborativeRevision [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3022720055) \"_hygCtx\") \"_hyg\") 358)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n true)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.assistedExecution [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase []))\n (Lean.Expr.const `CoreReader.Evidence.transitionAchievement []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))\n (Lean.Expr.const `CoreReader.Evidence.transitionFacet []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase []))\n (Lean.Expr.const `CoreReader.Evidence.transitionFacet []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))\n (Lean.Expr.const `CoreReader.Evidence.transitionPerformanceRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))))\n (Lean.Expr.const `CoreReader.Agency.TransitionCase.extend [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.transitionAchievement [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase.extend [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.transitionAchievement [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase.inflate []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))\n (Lean.Expr.const `CoreReader.Evidence.transitionReportRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))))\n (Lean.Expr.const `CoreReader.Evidence.transitionAchievement []))))))))\n (Lean.Expr.forallE\n `kind\n (Lean.Expr.const `CoreReader.Agency.InventoryKind [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Available [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item [])))))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Available [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item [])))))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor []))))\n (Lean.BinderInfo.default))))))", + "sha256": "69058c75db607f675c730d92da7dd1c6ee27d75385f4ac4ff717bd9fc7e925b2" + }, + "CoreReader.Adopted.consistencySpecification": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `Q\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `before\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Snapshot []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `after\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Snapshot []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.forallE\n `reported\n (Lean.Expr.const `Bool [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit))\n (Lean.BinderInfo.implicit)", + "sha256": "cf239ba7292f80875f93e960cd3417c226a8727f57f11e1ec4af4564caef076d" + }, + "CoreReader.Adopted.consistencyCases": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.premiseP []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.premiseRule []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.premiseNotQ []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.jointTheory [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consequence [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.assumptionContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.meaningContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.scopeContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.TruthfulReport []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.TruthfulReport []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.TruthfulReport [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.TruthfulReport [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.TruthfulReport [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Models []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Context.assumptions [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.const `Bool.true [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `time\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.revisionSlice []) (Lean.Expr.bvar 0)))\n (Lean.Expr.const `CoreReader.Adopted.broadBoolContext []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.const `CoreReader.Adopted.broadBoolContext [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `p\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `Bool []))\n (Lean.Expr.forallE\n `q\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `Bool []))\n (Lean.Expr.forallE\n `r\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Iff [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 2)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 2)))\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consequence [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.const `CoreReader.Logic.jointTheory []))\n (Lean.Expr.const `CoreReader.Adopted.jointContext012 []))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consequence [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.const `CoreReader.Logic.jointTheory []))\n (Lean.Expr.const `CoreReader.Adopted.jointContext012 []))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consistent [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.const `CoreReader.Logic.jointTheory []))\n (Lean.Expr.const `CoreReader.Adopted.jointContext012 []))))))))))", + "sha256": "16a20441e5650e4992e046ae4eeb2a1867f573730aa1dc402ca70508bb1802a6" + }, + "CoreReader.Adopted.consistencyConsequences": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `Q\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `t\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Theory []) (Lean.Expr.bvar 1))\n (Lean.Expr.forallE\n `c\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Context []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.forallE\n `q\n (Lean.Expr.bvar 2)\n (Lean.Expr.forallE\n `positive\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.bvar 4))\n (Lean.Expr.bvar 3))\n (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.forallE\n `negative\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.bvar 5))\n (Lean.Expr.bvar 4))\n (Lean.Expr.bvar 3))\n (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `Bool.false []))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.bvar 6))\n (Lean.Expr.bvar 5))\n (Lean.Expr.bvar 4))\n (Lean.Expr.bvar 3)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit))\n (Lean.BinderInfo.implicit)", + "sha256": "4b3231ac25a534c2699cd8f548a59a7d8beb1cb3923456f10c95081a3b6b5be3" + }, + "CoreReader.Adopted.consistencyLimits012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Admissible []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.assumptionContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.meaningContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Admissible []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.scopeContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lam\n `budget\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 4)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 4)))))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 6))))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 4)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 4)))))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 6)))))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.broadBoolContext [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Models []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.broadBoolContext [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Nat []))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 4)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 4)))))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Nat []))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 6)))))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.const `CoreReader.Adopted.tensionContext012 [])))))", + "sha256": "1bb1429eb084c222d9a84341c2d6cae05e8c83c1374bbbab8402a372099649cc" + }, + "CoreReader.Adopted.reflexivitySpecification": { + "type": "Lean.Expr.forallE\n `T\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `I\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `O\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `rules\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.forallE\n `isSelf\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 3)\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `performed\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Agency.PrincipleKey [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 5)\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 5)\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 5)\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit))\n (Lean.BinderInfo.implicit))\n (Lean.BinderInfo.implicit)", + "sha256": "d8084253926a4e9a9b2b9d6ccea7fcba129de72b8412ec4bd30c08a9bdf254bc" + }, + "CoreReader.Adopted.reflexivityCases012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.reflexivitySpecification [])\n (Lean.Expr.const `CoreReader.Agency.Subject []))\n (Lean.Expr.const `CoreReader.Agency.Inquiry []))\n (Lean.Expr.const `CoreReader.Agency.WorkOutcome []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.map [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule [])\n (Lean.Expr.const `CoreReader.Agency.Subject []))\n (Lean.Expr.const `CoreReader.Agency.Inquiry []))\n (Lean.Expr.const `CoreReader.Agency.WorkOutcome [])))\n (Lean.Expr.const `CoreReader.Adopted.legacyRule []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ownRules [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.lam\n `s\n (Lean.Expr.const `CoreReader.Agency.Subject [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Subject.owner []) (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.legacyPerformed [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ownRules [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.completeOwnWork [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `phase\n (Lean.Expr.const `CoreReader.Agency.Phase [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Performed [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.completeOwnWork [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Subject.process [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `CoreReader.Agency.Activity.assessment []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Performed [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.completeOwnWork [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Subject.system [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `CoreReader.Agency.Activity.assessment [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.reflexivitySpecification [])\n (Lean.Expr.const `CoreReader.Agency.Subject []))\n (Lean.Expr.const `CoreReader.Agency.Inquiry []))\n (Lean.Expr.const `CoreReader.Agency.WorkOutcome []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.map [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule [])\n (Lean.Expr.const `CoreReader.Agency.Subject []))\n (Lean.Expr.const `CoreReader.Agency.Inquiry []))\n (Lean.Expr.const `CoreReader.Agency.WorkOutcome [])))\n (Lean.Expr.const `CoreReader.Adopted.legacyRule []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle []))\n (Lean.Expr.const `CoreReader.Agency.applicationRule []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle [])))))\n (Lean.Expr.lam\n `s\n (Lean.Expr.const `CoreReader.Agency.Subject [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Subject.owner []) (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.legacyPerformed [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle []))\n (Lean.Expr.const `CoreReader.Agency.applicationRule []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle []))))\n (Lean.Expr.const `CoreReader.Agency.applicationWork []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Performed [])\n (Lean.Expr.const `CoreReader.Agency.applicationWork []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Subject.system [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `CoreReader.Agency.Activity.assessment []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.Grounds012 []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `enabled\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.GroundsProvision012 []) (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet.value []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.AssessmentTask.value []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.limits [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.relevantCriticism [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 []))\n (Lean.Expr.const `Bool.true [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.groundsExperiment012 [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.groundsExperiment012 [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Outcome [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.outcome [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.groundsExperiment012 [])\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Outcome [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.outcome [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.groundsExperiment012 [])\n (Lean.Expr.const `Bool.false [])))))))))", + "sha256": "55a9d738a39137aeb7cf0ee474c532a636dc2a59451613848747030a756b29e7" + }, + "CoreReader.Adopted.reflexivityLimits012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.selfTest [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ownArithmeticPrinciple [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.ownArithmeticPrinciple []) (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Evidence.allTrue []))))\n (Lean.Expr.const `CoreReader.Evidence.OwnedRevisionExample []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Reflexive [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ownRules [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.WorkRecord []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.CompleteCharter012 [])\n (Lean.Expr.const `CoreReader.Integration.actualSystem []))\n (Lean.Expr.const `CoreReader.Integration.actual [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.const `CoreReader.Integration.Question []))\n (Lean.Expr.const `CoreReader.Integration.held []))\n (Lean.Expr.const `CoreReader.Integration.context []))\n (Lean.Expr.const `CoreReader.Integration.actual [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Integration.World [])))\n (Lean.Expr.const `CoreReader.Integration.costAllowanceRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Integration.World [])))))\n (Lean.Expr.const `CoreReader.Integration.actual [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulated [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.const `CoreReader.Integration.unsupportedCapabilityFacet []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Integration.World [])))\n (Lean.Expr.const `CoreReader.Integration.costAllowanceRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Integration.World [])))))\n (Lean.Expr.const `CoreReader.Integration.capability []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.const `CoreReader.Integration.capability []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Integration.World [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Integration.World [])))\n (Lean.Expr.const `CoreReader.Integration.unsupportedCapabilityFacet []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Integration.World [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.const `CoreReader.Integration.unsupportedCapabilityFacet []))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.generationSpecification [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.revisable [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Form.mk [])\n (Lean.Expr.const `CoreReader.Agency.FormKind.principle []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.selfExemptPerformed012 [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.PrincipleKey.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule.applicable [])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.selfExemptRule012 []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.reflexivitySpecification [])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule [])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.selfExemptRule012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule [])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool [])))))\n (Lean.Expr.lam\n `target\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.selfExemptPerformed012 []))))))))))", + "sha256": "6aaa9a96ab7f8fe3ebe04633ee7e9ae054eafa88e7e8289179d143ee96e46d05" + }, + "CoreReader.Adopted.Grounds012": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `claim\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `articulations\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.bvar 1))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Articulation []) (Lean.Expr.bvar 2))\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `facets\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.bvar 2)))\n (Lean.Expr.forallE\n `task\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.AssessmentTask []) (Lean.Expr.bvar 3))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)", + "sha256": "65ead33e1cc510ec07082dde80dbec28ca36d80391c18e2ca6df7ed3e1353029" + }, + "CoreReader.Adopted.groundsCases012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulated [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Articulated []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.uninformativeArgument [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulation.assumptions [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.uninformativeArgument [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Evidence.allTrue []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.circularGlobalFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.circularGlobalFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.NatureAppropriate [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.originalGlobalTask012 []))\n (Lean.Expr.const `CoreReader.Adopted.circularGlobalFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Evidence.allTrue []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.circularGlobalFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Adopted.originalGlobalTask012 []))))))", + "sha256": "5d659ec603f559d1be5abf4df0466b2daee1633dcfbf70194c0b8ccf9640e40f" + }, + "CoreReader.Adopted.empiricalSpecification": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `records\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Record []) (Lean.Expr.bvar 0)))\n (Lean.Expr.forallE\n `scope\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.bvar 1))\n (Lean.Expr.forallE\n `claim\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.bvar 2))\n (Lean.Expr.forallE\n `uncertainty\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.bvar 3))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)", + "sha256": "9f534ab1f51da3b82f8edf1d35b0dfab34dfe042d10c44582f04b4dce6569ef2" + }, + "CoreReader.Adopted.empiricalCases012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulated [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record.test [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 3)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.consequence [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.consequence [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.empiricalSpecification [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 577346429) \"_hygCtx\") \"_hyg\") 256)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `True [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.fst [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Or [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.false [])))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.bvar 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Adopted.originalLocalTask012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.bvar 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.observedInferenceFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Adopted.originalLocalTask012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.FacetDischarged [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.uncertaintyBypassFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.NatureAppropriate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.originalUncertaintyTask012 []))\n (Lean.Expr.const `CoreReader.Adopted.uncertaintyBypassFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.fst [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Adopted.uncertaintyBypassFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))))\n (Lean.Expr.const `CoreReader.Adopted.originalUncertaintyTask012 []))))))))", + "sha256": "fba89ddcd1cf1f745deec2bbdb86e1434e01d6fc73f99c6bf690331560f736f6" + }, + "CoreReader.Adopted.inferentialSpecification": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `assumptions\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Theory []) (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `claim\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.bvar 1))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)", + "sha256": "d56b013c37bfeb071f171cb3f552b8775a79eee535305a78d2d9551b86c03c16" + }, + "CoreReader.Adopted.inferentialCases012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.inferentialSpecification []) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Nat []))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `HAdd.hAdd [Lean.Level.zero, Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `instHAdd [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instAddNat [])))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.InferenceExamined []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Models []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))\n (Lean.Expr.const `Bool.false [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.FacetDischarged []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet.inferential []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.Grounds012 []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.inferential [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.AssessmentTask.inferential [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))))", + "sha256": "b37768f2ff32da55daf97b29dc027bfa78aa1a1f2456c80937dde7aa64a5c515" + }, + "CoreReader.Adopted.valueSpecification": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `position\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.ValuePosition []) (Lean.Expr.bvar 0))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)", + "sha256": "1f45a163b8b2a0db44eeaeb0910e0af6168e4674ab3a3925dcfe54e3015e3ae6" + }, + "CoreReader.Adopted.valueCases012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.valueSpecification []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.reasons [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `reason\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.reasons [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.bvar 1)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.adopted [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.consequence [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.ValueProcedure []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.closedPosition012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.ValueProcedure []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.starting [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.JointAdoption [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.oppositePosition [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.oppositePosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.contradictoryStartingPosition []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.impossibleAdoptionPosition [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.FacetDischarged []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.selectedFactFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.valueSpecification []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.Grounds012 []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.selectedFactFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.AssessmentTask.value [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))))))))", + "sha256": "ce1dba18fb8bf4611fe703b21270e3b59591f6f1cf1c40f2ee03899fa26c142a" + }, + "CoreReader.Adopted.groundsLimits012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Articulated []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.clearFalseArgument012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Models []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulation.assumptions [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.clearFalseArgument012 [])))\n (Lean.Expr.const `Bool.false [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record.test [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 3)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.consequence [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.consequence [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.valueSpecification []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Compatible []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Record []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.valueNeutralRecord012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Record []) (Lean.Expr.const `Bool [])))))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Supports []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Record []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.valueNeutralRecord012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Record []) (Lean.Expr.const `Bool [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.ValueProcedure []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.starting [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.JointAdoption [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.oppositePosition [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.oppositePosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.contradictoryStartingPosition []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.impossibleAdoptionPosition [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ClaimNoStronger [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.bvar 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ClaimNoStronger [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Evidence.allTrue []))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.bvar 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.valueSpecification []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))))))", + "sha256": "b404dce33c3fbf86c65d3824e2fceaf5f0a1f312ce1edc1f0a9e9251af9ccad3" + }, + "CoreReader.Adopted.scopeSpecification": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `account\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.ScopeAccount []) (Lean.Expr.bvar 0))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)", + "sha256": "01857cd86d39ca8bc2d54d15555ebed9fc9fa6a0bd40196743e5f1fbbcb966b7" + }, + "CoreReader.Adopted.scopeCases012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.scopeSpecification []) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Adopted.localScopeAccount012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 3351349031) \"_hygCtx\") \"_hyg\") 37)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.bvar 1)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 3351349031) \"_hygCtx\") \"_hyg\") 54)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))", + "sha256": "e503dd4f8dacf02303b9bd7e56977a56feee218c1c677d8836c15039e83655a8" + }, + "CoreReader.Adopted.scopeLimits012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lam\n `outside\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 27637535) \"_hygCtx\") \"_hyg\") 38)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 27637535) \"_hygCtx\") \"_hyg\") 62)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 27637535) \"_hygCtx\") \"_hyg\") 117)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.bvar 1)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 27637535) \"_hygCtx\") \"_hyg\") 134)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.bvar 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.letE\n `a\n (Lean.Expr.const `CoreReader.Evidence.Trial [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.letE\n `b\n (Lean.Expr.const `CoreReader.Evidence.Trial [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Reproduced []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.actualOutcome [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Trial.actualOutcome []) (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Bounded []) (Lean.Expr.bvar 1)))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Bounded []) (Lean.Expr.bvar 0)))))\n true)\n true))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Verified [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Verified [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Reproduced [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Reproduced [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Verified [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2))))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Bounded [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Bounded [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Bounded [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Verified [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.FacetDischarged []) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Evidence.arithmeticFacet [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.usesObservation [])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Evidence.arithmeticFacet [])))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.inferentialSpecification [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `on\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.lam\n `on\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.false []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.usesObservation [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.inferential [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `on\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.lam\n `on\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.false []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `GT.gt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.drawWeight012 [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `GT.gt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.drawWeight012 [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.drawWeight012 [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.drawWeight012 [])\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Reproduced [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.actualOutcome [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.actualOutcome [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.const `Bool.false [])))))\n (Lean.Expr.forallE\n `draw\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Verified [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Bounded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.bvar 0))))\n (Lean.BinderInfo.default)))))))))))))", + "sha256": "a286f42a08d68addaec58cb6b0b9656968db614439bd753425f3972b29d8125c" + }, + "CoreReader.Adopted.capabilitySpecification": { + "type": "Lean.Expr.forallE\n `assessed\n (Lean.Expr.const `CoreReader.Evidence.Process [])\n (Lean.Expr.forallE\n `contract\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `CoreReader.Evidence.Process []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "908a244789ebae715ab94703060109000c2369e1c4735c6cdb48a096243f3c04" + }, + "CoreReader.Adopted.capabilityCases012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.const `CoreReader.Evidence.explainedProcess []))\n (Lean.Expr.const `CoreReader.Evidence.FullProcessContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))\n (Lean.Expr.lam\n `certificate\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate.assessorId [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate.assessedId [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExplanationContract [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.OwnCapability012 [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 7)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 7)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 7)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 7)))))\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Evidence.Process []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012.process [])\n (Lean.Expr.const `CoreReader.Adopted.explainedWithoutVariation012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012.process [])\n (Lean.Expr.const `CoreReader.Adopted.mechanismResponder012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.FullProcessContract [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012.process [])\n (Lean.Expr.const `CoreReader.Adopted.explainedWithoutVariation012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.UnderstandingApplication012 [])\n (Lean.Expr.const `CoreReader.Adopted.explainedWithoutVariation012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.UnderstandingApplication012 [])\n (Lean.Expr.const `CoreReader.Adopted.mechanismResponder012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 []))\n (Lean.Expr.const `CoreReader.Adopted.UnderstandingApplication012 []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.understandingFacet012 [])\n (Lean.Expr.const `CoreReader.Adopted.mechanismResponder012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.understandingTask012 [])\n (Lean.Expr.const `CoreReader.Adopted.mechanismResponder012 []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 []))\n (Lean.Expr.const `CoreReader.Adopted.UnderstandingApplication012 []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.understandingFacet012 [])\n (Lean.Expr.const `CoreReader.Adopted.explainedWithoutVariation012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.understandingTask012 [])\n (Lean.Expr.const `CoreReader.Adopted.explainedWithoutVariation012 []))))))))))", + "sha256": "71d33f0d4ef4ccd7b59de8cf61f1e8aa0edae58f02813c4f4f3d79754d592d03" + }, + "CoreReader.Adopted.capabilityLimits012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.const `CoreReader.Evidence.explainedProcess []))\n (Lean.Expr.const `CoreReader.Evidence.FullProcessContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))\n (Lean.Expr.lam\n `certificate\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate.assessorId [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate.assessedId [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExplanationContract [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `kind\n (Lean.Expr.const `CoreReader.Agency.InventoryKind [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Available [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item [])))))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Available [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item [])))))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor []))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.permitsVersion [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.availableResources [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Option.some [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 6)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3023016825) \"_hygCtx\") \"_hyg\") 160)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3023016825) \"_hygCtx\") \"_hyg\") 179)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3023016825) \"_hygCtx\") \"_hyg\") 198)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n true)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.requirementsMet [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.StableReason [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Announcement []))\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.report [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.owner [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.owner [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.before [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.after [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.reportedNewOperation\n [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.input [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.expectedOutput\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.claim [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.before\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.after [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))))))))))))))))))))))))))))", + "sha256": "8efa4107232374dd4f308f0f4c19f39b706da292b2cb4042aba290ade3368d52" + }, + "CoreReader.Adopted.choiceSpecification": { + "type": "Lean.Expr.forallE\n `requirements\n (Lean.Expr.const `CoreReader.Choice.Requirements [])\n (Lean.Expr.forallE\n `implementation\n (Lean.Expr.const `CoreReader.Choice.Implementation [])\n (Lean.Expr.forallE\n `reasons\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "4b2ffafbf066633850901441a4978132cc3d84f95bef9c803f56a17866762054" + }, + "CoreReader.Adopted.choiceCases012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.conventional [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.established [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.status [])\n (Lean.Expr.const `CoreReader.Choice.StatusKind.convention [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.output [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.explanation []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.applicability []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.simplicity []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.procedure []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.cheapSuccessor []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.simplicity []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.cheapSuccessor []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.simplicity [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason [])))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulated [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.priorityArticulation [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.AssessmentAccurate [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `selected\n (Lean.Expr.const `CoreReader.Choice.Candidate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Models [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.statusFacts []))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.priorityClaim [])\n (Lean.Expr.const `CoreReader.Choice.Candidate.identity [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.priorityClaim [])\n (Lean.Expr.const `CoreReader.Choice.Candidate.successor []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Entails [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.statusFacts []))\n (Lean.Expr.const `CoreReader.Choice.priorityClaim []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.status [])\n (Lean.Expr.const `CoreReader.Choice.StatusKind.standing [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 []))\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Feasible [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Feasible [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.explanation []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.explanation [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.choiceSpecification [])\n (Lean.Expr.const `CoreReader.Integration.proposalRequirements []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Integration.PhilosophyMethod.implementation [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Integration.currentPhilosophy [])\n (Lean.Expr.const `CoreReader.Integration.actualSystem []))\n (Lean.Expr.const `CoreReader.Integration.actual []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.status [])\n (Lean.Expr.const `CoreReader.Choice.StatusKind.standing [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.choiceSpecification [])\n (Lean.Expr.const `CoreReader.Integration.proposalRequirements []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Integration.PhilosophyMethod.implementation [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Integration.currentPhilosophy [])\n (Lean.Expr.const `CoreReader.Integration.actualSystem []))\n (Lean.Expr.const `CoreReader.Integration.actual []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.output [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))\n (Lean.Expr.forallE\n `kind\n (Lean.Expr.const `CoreReader.Choice.StatusKind [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.choiceSpecification [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Choice.Reason.status []) (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason [])))))\n (Lean.BinderInfo.default))))))", + "sha256": "36f89bc4962aa87be316945afd3147dd30111dfdca8902a41b0392a2bda28c04" + }, + "CoreReader.Adopted.choiceLimits012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `candidate\n (Lean.Expr.const `CoreReader.Choice.Candidate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Iff [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Feasible [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Choice.implementation []) (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Choice.Candidate.identity [])))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.const `CoreReader.Choice.objectiveReason []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.conventional [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.established [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.status [])\n (Lean.Expr.const `CoreReader.Choice.StatusKind.convention [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.output [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 []))\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Feasible [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Feasible [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.explanation []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.explanation [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.const `CoreReader.Choice.objectiveReason [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.successorImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `x\n (Lean.Expr.const `Nat [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.changedOutsideZero []))\n (Lean.Expr.bvar 1)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.changedOutsideZero []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulated [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.priorityArticulation [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.AssessmentAccurate [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `selected\n (Lean.Expr.const `CoreReader.Choice.Candidate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Models [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.statusFacts []))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.priorityClaim [])\n (Lean.Expr.const `CoreReader.Choice.Candidate.identity [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.priorityClaim [])\n (Lean.Expr.const `CoreReader.Choice.Candidate.successor []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Entails [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.statusFacts []))\n (Lean.Expr.const `CoreReader.Choice.priorityClaim []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.status [])\n (Lean.Expr.const `CoreReader.Choice.StatusKind.standing [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))))))))\n (Lean.Expr.const `CoreReader.Choice.PolicyIndependenceExample []))))))", + "sha256": "84bdf70f43a217d10ccf0d7a8179aea2b586ab845a7c8f3a2f087089c6098874" + }, + "CoreReader.Engineering.inheritedMutualApplication": { + "type": "Lean.Expr.forallE\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.forallE\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.forallE\n `inherited\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.Inherited []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.generationSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.engineeringPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.reflexivitySpecification [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Outcome [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.rules [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 1))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.self [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 1))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.performed [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `principle\n (Lean.Expr.const `CoreReader.Engineering.CoreCommitment [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.valueSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.governancePosition []) (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.engineeringProcess []) (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringCapability [])\n (Lean.Expr.bvar 1))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.choiceSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.chosenRequirements []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.chosenImplementation [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.const `CoreReader.Engineering.chosenReasons [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `fact\n (Lean.Expr.const `CoreReader.Engineering.OwnFact [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.inferentialSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownFactPremises [])\n (Lean.Expr.bvar 2)))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.ownFactClaim []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `norm\n (Lean.Expr.const `CoreReader.Engineering.OwnNorm [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.normApplies []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.ownTheory []) (Lean.Expr.bvar 3))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownNormClaim [])\n (Lean.Expr.bvar 3))\n (Lean.Expr.bvar 1)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `claim\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Claim [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.ownTheory []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.inferentialSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownFactPremises [])\n (Lean.Expr.bvar 3)))\n (Lean.Expr.bvar 1))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.consistencySpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `CoreReader.Engineering.OwnFact []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringSnapshot [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringSnapshot [])\n (Lean.Expr.bvar 1))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.const `Bool.true []))))))))))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "b60496465943a095fdd0772f4002302eb9242ece03be7a2e20ce616f0253ee4a" + }, + "CoreReader.Engineering.inheritedMutualCases": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Inherited [])\n (Lean.Expr.const `CoreReader.Engineering.sharedContext []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.valueSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.governancePosition [])\n (Lean.Expr.const `CoreReader.Engineering.CoreCommitment.grounds []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringProcess [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringCapability [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.choiceSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.chosenRequirements []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.chosenImplementation [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.const `CoreReader.Engineering.chosenReasons [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.evaluate [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.evolutionMethod []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision [])))))\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict.counterexample [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.objects [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.generationRule [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.objects [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.assessmentRule [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.evaluate [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.assessmentRule []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision [])))))\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict.counterexample []))))))))", + "sha256": "e3c73c4f98c7a3fe5bfadc8b2bc7a9a5231473504e047179d6299e3417f2ba4c" + }, + "CoreReader.Engineering.ActivityScope": { + "type": "Lean.Expr.forallE\n `a\n (Lean.Expr.const `CoreReader.Engineering.Activity [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default)", + "sha256": "fdfa84c29643bd37a72d614541ecf59b4b7efdf606ac4b7480cb02fe3e4c8382" + }, + "CoreReader.Engineering.subjectLifecycleCases": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ActivityScope [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `String []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.label [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.lit (Lean.Literal.strVal \"temporary\"))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Continuing [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.const `CoreReader.Engineering.temporaryActivity [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.const `CoreReader.Engineering.prototypeActivity [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.const `CoreReader.Engineering.retiringActivity [])))))))))", + "sha256": "a2d126370b7fef5af4645ef64d85b169467518bfb8f76269b41f47f82e0bd02b" + }, + "CoreReader.Engineering.subjectLimits": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.original []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContinuingCapability [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `String []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.label [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.lit (Lean.Literal.strVal \"temporary\"))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.orientation [])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.passiveArtifact [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.maintainerActions [])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction.propose [])\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.artifactActions [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction.propose [])\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))))))))))", + "sha256": "4d0b23030599912d1ad72613e9956d5dd179d987aa64f0a694f74e85847b2a2b" + }, + "CoreReader.Engineering.EvolutionPriority": { + "type": "Lean.Expr.forallE\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.forallE\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "8609cb39944d272540e985febb940328bc4a85a6e22fe06e652f4c95bd043ddb" + }, + "CoreReader.Engineering.priorityConditionsCases": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.const `CoreReader.Engineering.normalRequirements []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2249646945) \"_hygCtx\") \"_hyg\") 19)\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.profile [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.unsafeOperations [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.latency [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.retention [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.const `CoreReader.Engineering.normalRequirements []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2249646945) \"_hygCtx\") \"_hyg\") 45)\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.profile [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.orderOutput [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.latency [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.retention [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.const `CoreReader.Engineering.normalRequirements []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2249646945) \"_hygCtx\") \"_hyg\") 65)\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.profile [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.orderOutput [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.unsafeOperations [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 11)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 11)))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.retention [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.const `CoreReader.Engineering.normalRequirements []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2249646945) \"_hygCtx\") \"_hyg\") 85)\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.profile [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.orderOutput [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.unsafeOperations [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.latency [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 29)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 29)))))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.verification [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2249646945) \"_hygCtx\") \"_hyg\") 113)\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.verification []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.required [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.evidence [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.limits [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Burden [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.profiles [])\n (Lean.Expr.bvar 0)))\n true))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.maximal [])))))))))", + "sha256": "3206e3bed26ebff1742e044beabbfcca534354e4895936cd6496b4af5a5485e9" + }, + "CoreReader.Engineering.priorityWhenApplicable": { + "type": "Lean.Expr.forallE\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.forallE\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.forallE\n `rule\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `applicable\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.PriorityConditions []) (Lean.Expr.bvar 2))\n (Lean.Expr.forallE\n `noDeparture\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture []) (Lean.Expr.bvar 3))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.bvar 3))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity []) (Lean.Expr.bvar 3))))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "6b1efb7cab71c9b837ce57e666f331112f6416f18a59675e8119416b3d7a39a6" + }, + "CoreReader.Engineering.priorityChoices": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.verification [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple [])))", + "sha256": "d4cbb2cea4f863c0a900531a90fd4e36cd04ad50df57b340871001d6fb01b349" + }, + "CoreReader.Engineering.CredibleDirection": { + "type": "Lean.Expr.forallE\n `Ground\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `grounds\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `articulated\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 1)\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `supports\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 2)\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Engineering.Change [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `d\n (Lean.Expr.const `CoreReader.Engineering.Change [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)", + "sha256": "1906e98dd6d042fc973fb93506c24accc024a7643adaddd05e071030c8b5682b" + }, + "CoreReader.Engineering.credibilityCases": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.initialGrounds []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround.knowledge [])\n (Lean.Expr.lit (Lean.Literal.strVal \"queue\")))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))))\n (Lean.Expr.lit (Lean.Literal.strVal \"tenant-config-reload\"))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround []))))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround.history [])\n (Lean.Expr.lit (Lean.Literal.strVal \"queue\")))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.const `CoreReader.Engineering.Change.migration []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.const `CoreReader.Engineering.Change.migration []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround []))))\n (Lean.Expr.const `CoreReader.Engineering.Change.migration [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"quantum backend\"))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.forecastGrounds []))\n (Lean.Expr.const `CoreReader.Engineering.Change.deletion [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.forecastGrounds []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))))))", + "sha256": "b5d172388be7bcd1bdbeea1f07436b61458bd02c0e714dc83b7d7565adefa6c9" + }, + "CoreReader.Engineering.credibilityLimits": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.initialGrounds []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `CoreReader.Engineering.implementedVariants [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.WarrantedAccommodation [])\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"quantum backend\"))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.initialGrounds []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"quantum backend\"))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.maximal []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.cost [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Burden.construction [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.cost [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Burden.migration []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.MaximumRegisteredCapability [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.MaximumRegisteredCapability [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.maximal [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.supportedDirections [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 9)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 9))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.supportedDirections [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.maximal []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 10))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.initialGrounds []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"csv export\")))))))))))))))", + "sha256": "76415ebe0bbc33c3827da7db33b1e89e3f676b7cf0f4f39df5401beeda5f40c4" + }, + "CoreReader.Engineering.JustifiedDeparture": { + "type": "Lean.Expr.forallE\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.forallE\n `c\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "f6c50ef1eaca65b4a3886bcbc5ccb11393e89a2d7baf8f6980b6a58f9d0719a4" + }, + "CoreReader.Engineering.costCases": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.understanding [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.construction [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.diagnosis [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.verification [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.coordination [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.operation [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.migration [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 797674858) \"_hygCtx\") \"_hyg\") 72)\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.required [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.evidence [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.limits [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Option.some [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Burden []))\n (Lean.Expr.const `CoreReader.Engineering.Burden.migration [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.profiles [])\n (Lean.Expr.bvar 0)))\n true))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))))))))", + "sha256": "0159f38d1da3fe90524ce5a5d2e2b1d3a4fc5a14c6a76a6fbc07a158d16edd90" + }, + "CoreReader.Engineering.EvolutionClaim": { + "type": "Lean.Expr.forallE\n `a\n (Lean.Expr.const `CoreReader.Engineering.Activity [])\n (Lean.Expr.forallE\n `c\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.forallE\n `claim\n (Lean.Expr.const `CoreReader.Engineering.ChangeClaim [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "9c0c528a387fd26adf8c44acbd1e97da3c991c6544f40f31c0a8c3adb2ccd2f7" + }, + "CoreReader.Engineering.evolutionKindsCases": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.capabilities [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.addition []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"deduplicate\")))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"tenant batching\")))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `String []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.implementation [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.replacement []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.mechanisms [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.deletion []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"queue\")))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `String [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.abstractions [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.withdrawal []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `String []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.boundary [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.redrawing []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `String []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.technology [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.migration []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.lit (Lean.Literal.strVal \"portable store\"))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.all [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.const `CoreReader.Engineering.changes []))\n (Lean.Expr.lam\n `d\n (Lean.Expr.const `CoreReader.Engineering.Change [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Decidable.decide [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instDecidableAnd [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.participants [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.all [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.lam\n `step\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Bool.and [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.const\n `CoreReader.Engineering.instDecidableEqKnowledge\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.available [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.requires [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqTool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.tools [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.tool [])\n (Lean.Expr.bvar 0))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instDecidableNot [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.instDecidableEqNil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instDecidableAnd [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.participants [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.all [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.lam\n `step\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Bool.and [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.const\n `CoreReader.Engineering.instDecidableEqKnowledge\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.available [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.requires [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqTool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.tools [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.tool [])\n (Lean.Expr.bvar 0))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.instDecidableMemOfLawfulBEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqMaintainer [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instLawfulBEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqMaintainer [])))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.participants [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instDecidableEqBool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.all [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.lam\n `step\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Bool.and [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.const\n `CoreReader.Engineering.instDecidableEqKnowledge\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.available [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.requires [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqTool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.tools [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.tool [])\n (Lean.Expr.bvar 0))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionClaim [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ChangeClaim.mk [])\n (Lean.Expr.const `CoreReader.Engineering.Change.replacement []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.ObligationTreatment.preserve []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionClaim [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ChangeClaim.mk [])\n (Lean.Expr.const `CoreReader.Engineering.Change.redrawing []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent []))\n (Lean.Expr.const `CoreReader.Engineering.ObligationTreatment.revise []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.independent [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated [])))))))))))", + "sha256": "ccab4c5ed0bb676cef2d8435b8252630c0bc2f32d0ce9023156532deb6b77a1e" + }, + "CoreReader.Engineering.evolutionDimensionsLimits": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.addition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.withdrawal [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 17)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 17))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.independent [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 9)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 9)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.migration []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.original []))\n (Lean.Expr.const `CoreReader.Engineering.Change.addition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.original []))\n (Lean.Expr.const `CoreReader.Engineering.Change.addition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.original []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.original []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.addition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.addition []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.capabilities [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"csv export\"))))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"deduplicate\")))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"csv export\")))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `String []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.maximal []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"csv export\")))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"csv export\")))))))))))))))))", + "sha256": "ba2af856a831323eaa2344e83084a08689b7a287f6a8542edcef6fb0c2e57af7" + }, + "CoreReader.Engineering.StructuralAccount": { + "type": "Lean.Expr.forallE\n `a\n (Lean.Expr.const `CoreReader.Engineering.Activity [])\n (Lean.Expr.forallE\n `c\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.forallE\n `e\n (Lean.Expr.const `CoreReader.Engineering.StructuralEvidence [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "45df6c2c2383df05162c2a265ba6daf5debbdf46847dc9de1801f881eb00db1e" + }, + "CoreReader.Engineering.structuralCases": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.StructuralAccount [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.structuralEvidence [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.propagation [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.propagation [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.any [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated [])))\n (Lean.Expr.lam\n `s\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Bool.and [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `BEq.beq [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instDecidableEqNat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.component [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `BEq.beq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqKnowledge [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.requires [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `CoreReader.Engineering.Knowledge.publicContract [])))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.orderedRefactor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.StructuralEvidence.observedBefore [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.structuralEvidence [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.StructuralEvidence.observedAfter [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.structuralEvidence [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.staticBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 10))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 10)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.staticBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.withdrawal [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 17)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 17))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.crossesBoundary [])\n (Lean.Expr.const `CoreReader.Engineering.boundaryDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.coordinatedBoundary [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.boundaryObligationChecked [])\n (Lean.Expr.const `CoreReader.Engineering.boundaryDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.coordinatedBoundary [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.crossesBoundary [])\n (Lean.Expr.const `CoreReader.Engineering.omittedCallerCheck []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.coordinatedBoundary [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.boundaryObligationChecked [])\n (Lean.Expr.const `CoreReader.Engineering.omittedCallerCheck []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.coordinatedBoundary [])))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.crossesBoundary [])\n (Lean.Expr.const `CoreReader.Engineering.otherCalleeDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.otherCalleeBoundary [])))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.boundaryObligationChecked [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 1550649743) \"_hygCtx\") \"_hyg\") 194)\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign [])\n (Lean.Expr.const `CoreReader.Engineering.boundaryDesign [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.mk [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Engineering.EngineeringDesign.metadata\n [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `CoreReader.Engineering.sortedUnique []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.paths [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Engineering.EngineeringDesign.components\n [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.boundaries [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Engineering.EngineeringDesign.batchAssumptions\n [])\n (Lean.Expr.bvar 0)))\n true))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.coordinatedBoundary [])))\n (Lean.Expr.const `Bool.false [])))))))))))))))", + "sha256": "4fdfb378096465bfe330f655d5cc248745bbfdcb505407595d9d23254428de9e" + }, + "CoreReader.Engineering.structureNotCapability": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `String []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.InterfaceView.signature [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.InterfaceView.signature [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.sortedDesign [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.sortedDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.InterfaceView.modules [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.components [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.batchAssumptions [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 8)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 8))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designModulesNeedingRevision [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 8)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 8))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `String []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.InterfaceView.principle [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))))\n (Lean.Expr.lit (Lean.Literal.strVal \"dependency inversion\"))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.InterfaceView []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.documentedDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.DesignCanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.DesignCanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.documentedDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.boundaries [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.boundaries [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.components [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 9)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 9))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.boundaries [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Boundary.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 8)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 8)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.lit (Lean.Literal.strVal \"List Nat → List Nat\"))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 17)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 17))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 18)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 18))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.boundaries [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Boundary.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 8)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 8)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.lit (Lean.Literal.strVal \"List Nat → List Nat\"))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.components [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 9)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 9))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.paths [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.paths [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 17)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 17))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.DesignCanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))))))))))", + "sha256": "2c09939db7dbc6561ff01284d1187a4272120050885c7743d2227d2a6e133ea9" + }, + "CoreReader.Engineering.ContractChangeAccount": { + "type": "Lean.Expr.forallE\n `old\n (Lean.Expr.const `CoreReader.Engineering.ObservableContract [])\n (Lean.Expr.forallE\n `new\n (Lean.Expr.const `CoreReader.Engineering.ObservableContract [])\n (Lean.Expr.forallE\n `r\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "c58d92d3f41481a1b24941446085e8161c5dcb32cc266487f9734c2c03c8d3fe" + }, + "CoreReader.Engineering.contractCases": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.refactoredContract []))\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 640854215) \"_hygCtx\") \"_hyg\") 28)\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision [])\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.deliberate [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.revisedOrder [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.oldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.newFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedOldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedNewFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.procedure [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.retiredBehavior [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.retiredBehavior [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 99)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 99)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 99)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 99)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 640854215) \"_hygCtx\") \"_hyg\") 68)\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision [])\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.deliberate [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.revisedOrder [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.affected [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.oldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.newFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedOldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedNewFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.lit (Lean.Literal.strVal \"paired audit\")))\n true))))))", + "sha256": "d577c98b03b1349b8acdc20e24a2d1141ea92e5ce49ab73e3518385e0981adeb" + }, + "CoreReader.Engineering.contractPreservation": { + "type": "Lean.Expr.forallE\n `Input\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `Output\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `scope\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 1)\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `old\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 2)\n (Lean.Expr.bvar 2)\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `new\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 3)\n (Lean.Expr.bvar 3)\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `observations\n (Lean.Expr.forallE\n `x\n (Lean.Expr.bvar 4)\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app (Lean.Expr.bvar 3) (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.bvar 5))\n (Lean.Expr.app (Lean.Expr.bvar 2) (Lean.Expr.bvar 1)))\n (Lean.Expr.app (Lean.Expr.bvar 3) (Lean.Expr.bvar 1)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.PreservesOn []) (Lean.Expr.bvar 5))\n (Lean.Expr.bvar 4))\n (Lean.Expr.bvar 3))\n (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit))\n (Lean.BinderInfo.implicit)", + "sha256": "d9078e49c446deddda26e669891464c695136710e6b34620ca8ee4f08bdafbed" + }, + "CoreReader.Engineering.contractDistinctions": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.orderedRefactor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.sortedUnique []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.retry [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3))))))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.retry [])\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesContractFinite [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.affectedParties [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"queue consumer\")))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"queue operator\")))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `String []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2260969961) \"_hygCtx\") \"_hyg\") 73)\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision [])\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.deliberate [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.revisedOrder [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"queue consumer\")))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `String []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.oldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.newFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedOldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedNewFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.procedure [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2260969961) \"_hygCtx\") \"_hyg\") 97)\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision [])\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.deliberate [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.revisedOrder [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.affected [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 5)))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.newFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 5)))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedNewFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.procedure [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.retiredBehavior [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.retiredBehavior [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 99)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 99)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 99)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 99)))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))))))))))))", + "sha256": "bc0f83a82833ba24fc73f01ff24ac513e5ce42fec36a8195c70d516365a07a28" + }, + "CoreReader.Engineering.RevisionAccount": { + "type": "Lean.Expr.forallE\n `r\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default)", + "sha256": "865a4c6c542f07f6b0ce44a67e98175239ef389738b16bc6071ccebffae61c8b" + }, + "CoreReader.Engineering.revisionCases": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionAccount [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.forecast [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.forecast [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.maintenance [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.maintenance [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.maintainers [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.maintainers [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.migrationCost [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.migrationCost [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.objectiveCapacity [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.objectiveCapacity [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.predictedBatchCount [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.actualBatchCount [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RetentionJustified [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"quantum backend\"))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RetentionJustified [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.migration [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.const `CoreReader.Engineering.Change.migration []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change [])))))))))))", + "sha256": "8e2008450f4c7a80eca24630a18e6c77bf570055daee2c75c2577987c06ff629" + }, + "CoreReader.Engineering.revisionLimits": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionAccount [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionAccount [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 3857095740) \"_hygCtx\") \"_hyg\") 17)\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.software [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.recordedOld [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.recordedCurrent [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.predictedBatchCount [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.actualBatchCount [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.consideredChanges [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.criticizedDirections [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Engineering.revisionsMade [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.agreedBatch [])\n (Lean.Expr.const `CoreReader.Engineering.maintainers []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.all [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.const `CoreReader.Engineering.observations []))\n (Lean.Expr.lam\n `p\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `BEq.beq [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instDecidableEqNat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.staticBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.fst [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.fst [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.staticBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionAccount [])\n (Lean.Expr.const `CoreReader.Engineering.stableRecord [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.choice [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.stableRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.choice [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.stableRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RetentionJustified [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"quantum backend\"))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))))))))))))", + "sha256": "071a3e5cddf46166eacbd56285cdb4abb9f11a94e50e8bf00f8bc100f01026d0" + }, + "CoreReader.Engineering.priorityRemainsReflexive": { + "type": "Lean.Expr.forallE\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.forallE\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.forallE\n `inherited\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.Inherited []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `domain\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.DomainSatisfied []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.forallE\n `applicable\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.PriorityConditions []) (Lean.Expr.bvar 3))\n (Lean.Expr.forallE\n `noDeparture\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture []) (Lean.Expr.bvar 4))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.bvar 4))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.objects [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 4))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.priority [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.reflexivitySpecification [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Outcome [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.rules [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 4))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.self [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 4))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.performed [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 4)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `principle\n (Lean.Expr.const `CoreReader.Engineering.CoreCommitment [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.valueSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.governancePosition [])\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.bvar 5)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.value [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.AssessmentTask.value [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.ownTheory []) (Lean.Expr.bvar 4))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownNormClaim [])\n (Lean.Expr.bvar 4))\n (Lean.Expr.const `CoreReader.Engineering.OwnNorm.domain []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.consistencySpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `CoreReader.Engineering.OwnFact []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringSnapshot [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringSnapshot [])\n (Lean.Expr.bvar 4))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.const `Bool.true []))))))))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "285b4edb7397d25ccc631b194a1ff8ebb5204df450d52ec8eaf0685519b289c2" + }, + "CoreReader.Engineering.priorityReflexiveCases": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.objects [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.priority [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.objectTest [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.priority []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 10)))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.performed [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.PrincipleKey.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.priority []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.priority []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Outcome.assessed [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict.supportedWithinScope []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.evaluate [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.evolutionMethod []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision [])))))\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict.counterexample [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.objectTest [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.evolutionMethod []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 10)))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.objectTest [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.evolutionMethod []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.sharedContext [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.value [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.AssessmentTask.value [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.evaluate [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.assessmentRule []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision [])))))\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict.counterexample []))))))))", + "sha256": "2be55699c66ab5ba0f6310f298e19b890de4caef622e0d69676f2d6a7a3b5170" + }, + "CoreReader.Engineering.jointWitness": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Context []))\n (Lean.Expr.lam\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.lam\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Context []))\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.sharedContext [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.Inherited []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.DomainSatisfied []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.PriorityConditions []) (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.HasThreat []) (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownTheory [])\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownFactClaim [])\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.OwnFact.selected []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.objects [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.commitment [])\n (Lean.Expr.const `CoreReader.Engineering.CoreCommitment.grounds []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `CoreReader.Engineering.OwnFact []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownTheory [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.comparisonContext [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.bvar 0)))))))))))))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default))", + "sha256": "56d1bd97b0ac6c069484812a2a975dc185a905a24ee133a780b5f23a7fdc0b59" + }, + "CoreReader.Engineering.inheritedDoesNotEntailPriority": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Context []))\n (Lean.Expr.lam\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.lam\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Context []))\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.sharedContext [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.Inherited []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.PriorityConditions []) (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Continuing [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.Context.activity []) (Lean.Expr.bvar 1))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.HasThreat []) (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.required [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.profiles [])\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.required [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.profiles [])\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.evidence [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `LT.lt [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `LT.lt [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.valueSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))))))))))))))))))))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default))", + "sha256": "ad1b1b45257f57a53567b08bc87eb32bd6d8acf8395e9762a684c1116f270197" + } + }, + "build_returncode": 0, + "audit_returncode": 0, + "kernel_passed": true +} diff --git a/SoftwareEngineering/lean/philosophy/evidence/lake-build.log b/SoftwareEngineering/lean/philosophy/evidence/lake-build.log new file mode 100644 index 0000000..a85f364 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/evidence/lake-build.log @@ -0,0 +1,16 @@ +✔ [2/15] Built CoreReader.Logic (235ms) +✔ [3/15] Built CoreReader.Reflexivity (639ms) +✔ [4/15] Built CoreReader.Agency (475ms) +✔ [5/15] Built CoreReader.Engineering.Domain (1.3s) +✔ [6/15] Built CoreReader.Evidence (438ms) +✔ [7/15] Built CoreReader.Choice (309ms) +✔ [8/15] Built CoreReader.Integration (464ms) +✔ [9/15] Built CoreReader.Adopted (548ms) +✔ [10/15] Built CoreReader.Engineering.Reflection (332ms) +✔ [11/15] Built CoreReader.Engineering.Values (432ms) +✔ [12/15] Built CoreReader.Engineering.SelfApplication (2.7s) +✔ [13/15] Built CoreReader.Engineering.Integration (470ms) +✔ [14/15] Built CoreReader (206ms) +Build completed successfully (15 jobs). +info: software_engineering: no previous manifest, creating one from scratch +info: toolchain not updated; already up-to-date diff --git a/SoftwareEngineering/lean/philosophy/evidence/lean-audit.log b/SoftwareEngineering/lean/philosophy/evidence/lean-audit.log new file mode 100644 index 0000000..75aac1d --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/evidence/lean-audit.log @@ -0,0 +1,1368 @@ +CoreReader.Adopted.generationSpecification (policy : CoreReader.Agency.Policy) : Prop +'CoreReader.Adopted.generationSpecification' does not depend on any axioms +ORGANON_TYPE CoreReader.Adopted.generationSpecification "Lean.Expr.forallE\n `policy\n (Lean.Expr.const `CoreReader.Agency.Policy [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default)" +CoreReader.Adopted.generationCases : + (CoreReader.Agency.Generative CoreReader.Agency.openPolicy ∧ + (∀ (k : CoreReader.Agency.FormKind), CoreReader.Agency.openPolicy.revisable { kind := k, version := 0 }) ∧ + ∀ (t : Nat), + ¬CoreReader.Agency.Expanded (CoreReader.Agency.stableTrace t) (CoreReader.Agency.stableTrace (t + 1))) ∧ + (CoreReader.Agency.neutralPolicy.permitsVersion 0 1 ∧ + 0 ≠ 1 ∧ ¬CoreReader.Agency.Generative CoreReader.Agency.neutralPolicy) ∧ + (CoreReader.Agency.Generative CoreReader.Agency.generatingSystem.policy ∧ + CoreReader.Agency.generatingSystem.policy.permitsVersion 0 0 ∧ + ¬CoreReader.Agency.Expanded CoreReader.Agency.generatingSystem.current CoreReader.Agency.inflatedState ∧ + CoreReader.Agency.generatingSystem.current.inventory.length < + CoreReader.Agency.inflatedState.inventory.length ∧ + CoreReader.Agency.generatingSystem.current.abstractionLayers.length < + CoreReader.Agency.inflatedState.abstractionLayers.length ∧ + CoreReader.Agency.generatingSystem.current.vocabulary.length < + CoreReader.Agency.inflatedState.vocabulary.length ∧ + CoreReader.Agency.generatingSystem.execute CoreReader.Agency.availableResources = some 6 ∧ + CoreReader.Agency.generatingSystem.execute + (have __src := CoreReader.Agency.availableResources; + { experience := none, knowledge := __src.knowledge, collaborator := __src.collaborator }) = + none ∧ + CoreReader.Agency.generatingSystem.execute + (have __src := CoreReader.Agency.availableResources; + { experience := __src.experience, knowledge := none, + collaborator := __src.collaborator }) = + none ∧ + CoreReader.Agency.generatingSystem.execute + (have __src := CoreReader.Agency.availableResources; + { experience := __src.experience, knowledge := __src.knowledge, + collaborator := none }) = + none ∧ + CoreReader.Agency.generatingSystem.execute + { experience := none, knowledge := none, collaborator := none } = + none ∧ + ¬CoreReader.Agency.Expanded CoreReader.Agency.generatingSystem.current + CoreReader.Agency.generatingSystem.stableAction ∧ + CoreReader.Agency.generatingSystem.stableAction = + CoreReader.Agency.generatingSystem.current ∧ + CoreReader.Agency.generatingSystem.requirementsMet + CoreReader.Agency.generatingSystem.stableAction ∧ + CoreReader.Agency.generatingSystem.withinBudget + CoreReader.Agency.generatingSystem.stableAction ∧ + ¬CoreReader.Agency.generatingSystem.withinBudget CoreReader.Agency.inflatedState ∧ + CoreReader.Agency.StableReason CoreReader.Agency.generatingSystem.current + CoreReader.Agency.inflatedState ∧ + CoreReader.Agency.inflatedAnnouncement = + CoreReader.Agency.generatingSystem.report CoreReader.Agency.inflatedState + CoreReader.Agency.Operation.successor 0 1 ∧ + CoreReader.Agency.inflatedAnnouncement.owner = + CoreReader.Agency.generatingSystem.owner ∧ + CoreReader.Agency.inflatedAnnouncement.before = + CoreReader.Agency.generatingSystem.current ∧ + CoreReader.Agency.inflatedAnnouncement.after = + CoreReader.Agency.inflatedState ∧ + CoreReader.Agency.inflatedAnnouncement.reportedNewOperation = + CoreReader.Agency.Operation.successor ∧ + CoreReader.Agency.inflatedAnnouncement.input = 0 ∧ + CoreReader.Agency.inflatedAnnouncement.expectedOutput = 1 ∧ + ¬CoreReader.Agency.inflatedAnnouncement.claim ∧ + ¬CoreReader.Agency.Expanded + CoreReader.Agency.inflatedAnnouncement.before + CoreReader.Agency.inflatedAnnouncement.after) ∧ + CoreReader.Adopted.generationSpecification CoreReader.Agency.openPolicy ∧ + CoreReader.Agency.Expanded CoreReader.Agency.baseState + (CoreReader.Adopted.collaborativeRevision CoreReader.Agency.availableResources) ∧ + ¬CoreReader.Agency.Expanded CoreReader.Agency.baseState + (CoreReader.Adopted.collaborativeRevision + (have __src := CoreReader.Agency.availableResources; + { experience := __src.experience, knowledge := __src.knowledge, collaborator := none })) ∧ + CoreReader.Agency.assistedExecution { experience := none, knowledge := none, collaborator := none } = none +'CoreReader.Adopted.generationCases' depends on axioms: [propext, Quot.sound] +ORGANON_TYPE CoreReader.Adopted.generationCases "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `k\n (Lean.Expr.const `CoreReader.Agency.FormKind [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.revisable [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Form.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.forallE\n `t\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.stableTrace []) (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.stableTrace [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `HAdd.hAdd [Lean.Level.zero, Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `instHAdd [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instAddNat [])))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.permitsVersion [])\n (Lean.Expr.const `CoreReader.Agency.neutralPolicy []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.const `CoreReader.Agency.neutralPolicy []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.permitsVersion [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.availableResources [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Option.some [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 6)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 1780710401) \"_hygCtx\") \"_hyg\") 147)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 1780710401) \"_hygCtx\") \"_hyg\") 166)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `Option [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 1780710401) \"_hygCtx\") \"_hyg\") 185)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n true)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `Option [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.requirementsMet [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.StableReason [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Announcement []))\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.GeneratingSystem.report\n [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.owner [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.owner [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.before [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.after [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.reportedNewOperation\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.input [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const\n `Eq\n [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.expectedOutput\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.claim\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.before\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.after\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))))))))))))))))))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.generationSpecification [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.const `CoreReader.Agency.baseState []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.collaborativeRevision [])\n (Lean.Expr.const `CoreReader.Agency.availableResources []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.const `CoreReader.Agency.baseState []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.collaborativeRevision [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 1780710401) \"_hygCtx\") \"_hyg\") 355)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n true)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.assistedExecution [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))))" +CoreReader.Adopted.generationLimits012 : + (CoreReader.Agency.neutralPolicy.permitsVersion 0 1 ∧ + 0 ≠ 1 ∧ ¬CoreReader.Agency.Generative CoreReader.Agency.neutralPolicy) ∧ + (CoreReader.Agency.Generative CoreReader.Agency.openPolicy ∧ + (∀ (k : CoreReader.Agency.FormKind), CoreReader.Agency.openPolicy.revisable { kind := k, version := 0 }) ∧ + ∀ (t : Nat), + ¬CoreReader.Agency.Expanded (CoreReader.Agency.stableTrace t) (CoreReader.Agency.stableTrace (t + 1))) ∧ + (CoreReader.Agency.Generative CoreReader.Agency.generatingSystem.policy ∧ + CoreReader.Agency.generatingSystem.policy.permitsVersion 0 0 ∧ + ¬CoreReader.Agency.Expanded CoreReader.Agency.generatingSystem.current CoreReader.Agency.inflatedState ∧ + CoreReader.Agency.generatingSystem.current.inventory.length < + CoreReader.Agency.inflatedState.inventory.length ∧ + CoreReader.Agency.generatingSystem.current.abstractionLayers.length < + CoreReader.Agency.inflatedState.abstractionLayers.length ∧ + CoreReader.Agency.generatingSystem.current.vocabulary.length < + CoreReader.Agency.inflatedState.vocabulary.length ∧ + CoreReader.Agency.generatingSystem.execute CoreReader.Agency.availableResources = some 6 ∧ + CoreReader.Agency.generatingSystem.execute + (have __src := CoreReader.Agency.availableResources; + { experience := none, knowledge := __src.knowledge, collaborator := __src.collaborator }) = + none ∧ + CoreReader.Agency.generatingSystem.execute + (have __src := CoreReader.Agency.availableResources; + { experience := __src.experience, knowledge := none, + collaborator := __src.collaborator }) = + none ∧ + CoreReader.Agency.generatingSystem.execute + (have __src := CoreReader.Agency.availableResources; + { experience := __src.experience, knowledge := __src.knowledge, + collaborator := none }) = + none ∧ + CoreReader.Agency.generatingSystem.execute + { experience := none, knowledge := none, collaborator := none } = + none ∧ + ¬CoreReader.Agency.Expanded CoreReader.Agency.generatingSystem.current + CoreReader.Agency.generatingSystem.stableAction ∧ + CoreReader.Agency.generatingSystem.stableAction = + CoreReader.Agency.generatingSystem.current ∧ + CoreReader.Agency.generatingSystem.requirementsMet + CoreReader.Agency.generatingSystem.stableAction ∧ + CoreReader.Agency.generatingSystem.withinBudget + CoreReader.Agency.generatingSystem.stableAction ∧ + ¬CoreReader.Agency.generatingSystem.withinBudget CoreReader.Agency.inflatedState ∧ + CoreReader.Agency.StableReason CoreReader.Agency.generatingSystem.current + CoreReader.Agency.inflatedState ∧ + CoreReader.Agency.inflatedAnnouncement = + CoreReader.Agency.generatingSystem.report CoreReader.Agency.inflatedState + CoreReader.Agency.Operation.successor 0 1 ∧ + CoreReader.Agency.inflatedAnnouncement.owner = + CoreReader.Agency.generatingSystem.owner ∧ + CoreReader.Agency.inflatedAnnouncement.before = + CoreReader.Agency.generatingSystem.current ∧ + CoreReader.Agency.inflatedAnnouncement.after = + CoreReader.Agency.inflatedState ∧ + CoreReader.Agency.inflatedAnnouncement.reportedNewOperation = + CoreReader.Agency.Operation.successor ∧ + CoreReader.Agency.inflatedAnnouncement.input = 0 ∧ + CoreReader.Agency.inflatedAnnouncement.expectedOutput = 1 ∧ + ¬CoreReader.Agency.inflatedAnnouncement.claim ∧ + ¬CoreReader.Agency.Expanded + CoreReader.Agency.inflatedAnnouncement.before + CoreReader.Agency.inflatedAnnouncement.after) ∧ + (CoreReader.Adopted.generationSpecification CoreReader.Agency.openPolicy ∧ + CoreReader.Agency.Expanded CoreReader.Agency.baseState + (CoreReader.Adopted.collaborativeRevision CoreReader.Agency.availableResources) ∧ + ¬CoreReader.Agency.Expanded CoreReader.Agency.baseState + (CoreReader.Adopted.collaborativeRevision + (have __src := CoreReader.Agency.availableResources; + { experience := __src.experience, knowledge := __src.knowledge, collaborator := none })) ∧ + CoreReader.Agency.assistedExecution { experience := none, knowledge := none, collaborator := none } = + none) ∧ + (CoreReader.Adopted.Grounds012 CoreReader.Evidence.transitionAchievement + CoreReader.Evidence.canonicalArticulation [CoreReader.Evidence.transitionFacet] + (CoreReader.Adopted.taskOfFacet CoreReader.Evidence.transitionFacet) ∧ + CoreReader.Evidence.Compatible [CoreReader.Evidence.transitionPerformanceRecord] + CoreReader.Agency.TransitionCase.extend ∧ + CoreReader.Evidence.transitionAchievement CoreReader.Agency.TransitionCase.extend ∧ + ¬CoreReader.Evidence.transitionAchievement CoreReader.Agency.TransitionCase.inflate ∧ + ¬CoreReader.Evidence.Supports [CoreReader.Evidence.transitionReportRecord] + CoreReader.Evidence.transitionAchievement) ∧ + ∀ (kind : CoreReader.Agency.InventoryKind), + CoreReader.Agency.Available + [{ kind := kind, content := CoreReader.Agency.Operation.copy }, + { kind := kind, content := CoreReader.Agency.Operation.copy }] + CoreReader.Agency.Operation.copy ∧ + ¬CoreReader.Agency.Available + [{ kind := kind, content := CoreReader.Agency.Operation.copy }, + { kind := kind, content := CoreReader.Agency.Operation.copy }] + CoreReader.Agency.Operation.successor +'CoreReader.Adopted.generationLimits012' depends on axioms: [propext, Quot.sound] +ORGANON_TYPE CoreReader.Adopted.generationLimits012 "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.permitsVersion [])\n (Lean.Expr.const `CoreReader.Agency.neutralPolicy []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.const `CoreReader.Agency.neutralPolicy []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `k\n (Lean.Expr.const `CoreReader.Agency.FormKind [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.revisable [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Form.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.forallE\n `t\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.stableTrace []) (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.stableTrace [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `HAdd.hAdd [Lean.Level.zero, Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `instHAdd [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instAddNat [])))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.permitsVersion [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.availableResources [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Option.some [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 6)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3022720055) \"_hygCtx\") \"_hyg\") 147)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3022720055) \"_hygCtx\") \"_hyg\") 166)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `Option [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3022720055) \"_hygCtx\") \"_hyg\") 185)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n true)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `Option [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.requirementsMet [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.StableReason [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Announcement []))\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.GeneratingSystem.report\n [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.owner [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.owner [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.before [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.after [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.reportedNewOperation\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.input [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const\n `Eq\n [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.expectedOutput\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.claim\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.before\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.after\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))))))))))))))))))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.generationSpecification [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.const `CoreReader.Agency.baseState []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.collaborativeRevision [])\n (Lean.Expr.const `CoreReader.Agency.availableResources []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.const `CoreReader.Agency.baseState []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.collaborativeRevision [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3022720055) \"_hygCtx\") \"_hyg\") 358)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n true)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.assistedExecution [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase []))\n (Lean.Expr.const `CoreReader.Evidence.transitionAchievement []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))\n (Lean.Expr.const `CoreReader.Evidence.transitionFacet []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase []))\n (Lean.Expr.const `CoreReader.Evidence.transitionFacet []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))\n (Lean.Expr.const `CoreReader.Evidence.transitionPerformanceRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))))\n (Lean.Expr.const `CoreReader.Agency.TransitionCase.extend [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.transitionAchievement [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase.extend [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.transitionAchievement [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase.inflate []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))\n (Lean.Expr.const `CoreReader.Evidence.transitionReportRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))))\n (Lean.Expr.const `CoreReader.Evidence.transitionAchievement []))))))))\n (Lean.Expr.forallE\n `kind\n (Lean.Expr.const `CoreReader.Agency.InventoryKind [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Available [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item [])))))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Available [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item [])))))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor []))))\n (Lean.BinderInfo.default))))))" +CoreReader.Adopted.consistencySpecification {W Q : Type} (before after : CoreReader.Logic.Snapshot W Q) + (reported : Bool) : Prop +'CoreReader.Adopted.consistencySpecification' does not depend on any axioms +ORGANON_TYPE CoreReader.Adopted.consistencySpecification "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `Q\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `before\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Snapshot []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `after\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Snapshot []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.forallE\n `reported\n (Lean.Expr.const `Bool [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit))\n (Lean.BinderInfo.implicit)" +CoreReader.Adopted.consistencyCases : + (CoreReader.Logic.Satisfiable (CoreReader.Logic.singleton CoreReader.Logic.premiseP) ∧ + CoreReader.Logic.Satisfiable (CoreReader.Logic.singleton CoreReader.Logic.premiseRule) ∧ + CoreReader.Logic.Satisfiable (CoreReader.Logic.singleton CoreReader.Logic.premiseNotQ) ∧ + ¬CoreReader.Logic.Satisfiable CoreReader.Logic.jointTheory) ∧ + ((CoreReader.Logic.Consequence CoreReader.Logic.emptyTheory (CoreReader.Logic.assumptionContext true) () true ∧ + CoreReader.Logic.Consequence CoreReader.Logic.emptyTheory (CoreReader.Logic.assumptionContext false) () + false) ∧ + (CoreReader.Logic.Consequence CoreReader.Logic.emptyTheory (CoreReader.Logic.meaningContext true) () true ∧ + CoreReader.Logic.Consequence CoreReader.Logic.emptyTheory (CoreReader.Logic.meaningContext false) () + false) ∧ + (CoreReader.Logic.Consequence CoreReader.Logic.emptyTheory (CoreReader.Logic.scopeContext true) () true ∧ + CoreReader.Logic.Consequence CoreReader.Logic.emptyTheory (CoreReader.Logic.scopeContext false) () + false) ∧ + (∀ (b : Bool), + ∃ w, + CoreReader.Logic.Admissible CoreReader.Logic.emptyTheory (CoreReader.Logic.assumptionContext b) w) ∧ + (∀ (b : Bool), + ∃ w, CoreReader.Logic.Admissible CoreReader.Logic.emptyTheory (CoreReader.Logic.meaningContext b) w) ∧ + ∀ (b : Bool), + ∃ w, CoreReader.Logic.Admissible CoreReader.Logic.emptyTheory (CoreReader.Logic.scopeContext b) w) ∧ + (¬CoreReader.Logic.TruthfulReport (CoreReader.Logic.contextSnapshot (CoreReader.Logic.assumptionContext true)) + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.assumptionContext false)) false ∧ + ¬CoreReader.Logic.TruthfulReport (CoreReader.Logic.contextSnapshot (CoreReader.Logic.meaningContext true)) + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.meaningContext false)) false ∧ + ¬CoreReader.Logic.TruthfulReport (CoreReader.Logic.contextSnapshot (CoreReader.Logic.scopeContext true)) + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.scopeContext false)) false ∧ + ¬CoreReader.Logic.TruthfulReport (CoreReader.Logic.contextSnapshot (CoreReader.Logic.scopeContext true)) + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.scopeContext true) 1) false ∧ + CoreReader.Logic.TruthfulReport + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.assumptionContext true)) + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.assumptionContext false)) true ∧ + ¬CoreReader.Logic.Models (CoreReader.Logic.assumptionContext false).assumptions true) ∧ + (CoreReader.Logic.Satisfiable (CoreReader.Logic.revisionSlice 0) ∧ + CoreReader.Logic.Satisfiable (CoreReader.Logic.revisionSlice 1) ∧ + ¬CoreReader.Logic.Satisfiable + (CoreReader.Logic.union (CoreReader.Logic.revisionSlice 0) (CoreReader.Logic.revisionSlice 1))) ∧ + ((∀ (time : Nat), + CoreReader.Logic.Consistent (CoreReader.Logic.revisionSlice time) CoreReader.Adopted.broadBoolContext) ∧ + ¬CoreReader.Logic.Consistent + (CoreReader.Logic.union (CoreReader.Logic.revisionSlice 0) (CoreReader.Logic.revisionSlice 1)) + CoreReader.Adopted.broadBoolContext) ∧ + (∀ (p q r : CoreReader.Logic.Claim Bool), + CoreReader.Logic.union (CoreReader.Logic.singleton p) (CoreReader.Logic.singleton q) r ↔ + CoreReader.Logic.union (CoreReader.Logic.singleton q) (CoreReader.Logic.singleton p) r) ∧ + CoreReader.Logic.Consequence CoreReader.Logic.jointTheory CoreReader.Adopted.jointContext012 () true ∧ + CoreReader.Logic.Consequence CoreReader.Logic.jointTheory CoreReader.Adopted.jointContext012 () false ∧ + ¬CoreReader.Logic.Consistent CoreReader.Logic.jointTheory CoreReader.Adopted.jointContext012 +'CoreReader.Adopted.consistencyCases' does not depend on any axioms +ORGANON_TYPE CoreReader.Adopted.consistencyCases "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.premiseP []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.premiseRule []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.premiseNotQ []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.jointTheory [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consequence [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.assumptionContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.meaningContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.scopeContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.TruthfulReport []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.TruthfulReport []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.TruthfulReport [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.TruthfulReport [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.TruthfulReport [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Models []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Context.assumptions [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.const `Bool.true [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `time\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.revisionSlice []) (Lean.Expr.bvar 0)))\n (Lean.Expr.const `CoreReader.Adopted.broadBoolContext []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.const `CoreReader.Adopted.broadBoolContext [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `p\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `Bool []))\n (Lean.Expr.forallE\n `q\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `Bool []))\n (Lean.Expr.forallE\n `r\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Iff [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 2)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 2)))\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consequence [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.const `CoreReader.Logic.jointTheory []))\n (Lean.Expr.const `CoreReader.Adopted.jointContext012 []))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consequence [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.const `CoreReader.Logic.jointTheory []))\n (Lean.Expr.const `CoreReader.Adopted.jointContext012 []))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consistent [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.const `CoreReader.Logic.jointTheory []))\n (Lean.Expr.const `CoreReader.Adopted.jointContext012 []))))))))))" +CoreReader.Adopted.consistencyConsequences {W Q : Type} (t : CoreReader.Logic.Theory W) + (c : CoreReader.Logic.Context W Q) (q : Q) (positive : CoreReader.Logic.Consequence t c q true) + (negative : CoreReader.Logic.Consequence t c q false) : ¬CoreReader.Logic.Consistent t c +'CoreReader.Adopted.consistencyConsequences' does not depend on any axioms +ORGANON_TYPE CoreReader.Adopted.consistencyConsequences "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `Q\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `t\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Theory []) (Lean.Expr.bvar 1))\n (Lean.Expr.forallE\n `c\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Context []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.forallE\n `q\n (Lean.Expr.bvar 2)\n (Lean.Expr.forallE\n `positive\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.bvar 4))\n (Lean.Expr.bvar 3))\n (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.forallE\n `negative\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.bvar 5))\n (Lean.Expr.bvar 4))\n (Lean.Expr.bvar 3))\n (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `Bool.false []))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.bvar 6))\n (Lean.Expr.bvar 5))\n (Lean.Expr.bvar 4))\n (Lean.Expr.bvar 3)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit))\n (Lean.BinderInfo.implicit)" +CoreReader.Adopted.consistencyLimits012 : + ((CoreReader.Logic.Consequence CoreReader.Logic.emptyTheory (CoreReader.Logic.assumptionContext true) () true ∧ + CoreReader.Logic.Consequence CoreReader.Logic.emptyTheory (CoreReader.Logic.assumptionContext false) () false) ∧ + (CoreReader.Logic.Consequence CoreReader.Logic.emptyTheory (CoreReader.Logic.meaningContext true) () true ∧ + CoreReader.Logic.Consequence CoreReader.Logic.emptyTheory (CoreReader.Logic.meaningContext false) () false) ∧ + (CoreReader.Logic.Consequence CoreReader.Logic.emptyTheory (CoreReader.Logic.scopeContext true) () true ∧ + CoreReader.Logic.Consequence CoreReader.Logic.emptyTheory (CoreReader.Logic.scopeContext false) () false) ∧ + (∀ (b : Bool), + ∃ w, CoreReader.Logic.Admissible CoreReader.Logic.emptyTheory (CoreReader.Logic.assumptionContext b) w) ∧ + (∀ (b : Bool), + ∃ w, CoreReader.Logic.Admissible CoreReader.Logic.emptyTheory (CoreReader.Logic.meaningContext b) w) ∧ + ∀ (b : Bool), + ∃ w, CoreReader.Logic.Admissible CoreReader.Logic.emptyTheory (CoreReader.Logic.scopeContext b) w) ∧ + ((∃ budget, 4 ≤ budget ∧ budget ≤ 6) ∧ ¬(fun n => 4 ≤ n) = fun n => n ≤ 6) ∧ + (CoreReader.Logic.Consistent (CoreReader.Logic.singleton fun w => w = true) CoreReader.Adopted.broadBoolContext ∧ + ¬CoreReader.Logic.Models (CoreReader.Logic.singleton fun w => w = true) false ∧ + CoreReader.Logic.Consistent CoreReader.Logic.emptyTheory CoreReader.Adopted.broadBoolContext ∧ + ¬CoreReader.Logic.Entails CoreReader.Logic.emptyTheory fun w => w = true) ∧ + (CoreReader.Logic.Satisfiable + (CoreReader.Logic.union CoreReader.Logic.emptyTheory (CoreReader.Logic.singleton fun w => w = true)) ∧ + ¬CoreReader.Logic.Entails CoreReader.Logic.emptyTheory fun w => w = true) ∧ + CoreReader.Logic.Consistent + (CoreReader.Logic.union (CoreReader.Logic.singleton fun n => 4 ≤ n) + (CoreReader.Logic.singleton fun n => n ≤ 6)) + CoreReader.Adopted.tensionContext012 +'CoreReader.Adopted.consistencyLimits012' does not depend on any axioms +ORGANON_TYPE CoreReader.Adopted.consistencyLimits012 "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Admissible []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.assumptionContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.meaningContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Admissible []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.scopeContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lam\n `budget\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 4)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 4)))))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 6))))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 4)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 4)))))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 6)))))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.broadBoolContext [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Models []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.broadBoolContext [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Nat []))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 4)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 4)))))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Nat []))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 6)))))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.const `CoreReader.Adopted.tensionContext012 [])))))" +CoreReader.Adopted.reflexivitySpecification {T I O : Type} (rules : List (CoreReader.Adopted.ReflexiveRule T I O)) + (isSelf : T → Prop) (performed : CoreReader.Agency.PrincipleKey → T → I → O → Prop) : Prop +'CoreReader.Adopted.reflexivitySpecification' does not depend on any axioms +ORGANON_TYPE CoreReader.Adopted.reflexivitySpecification "Lean.Expr.forallE\n `T\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `I\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `O\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `rules\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.forallE\n `isSelf\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 3)\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `performed\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Agency.PrincipleKey [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 5)\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 5)\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 5)\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit))\n (Lean.BinderInfo.implicit))\n (Lean.BinderInfo.implicit)" +CoreReader.Adopted.reflexivityCases012 : + (CoreReader.Adopted.reflexivitySpecification (List.map CoreReader.Adopted.legacyRule (CoreReader.Agency.ownRules 0)) + (fun s => s.owner = 0) + (CoreReader.Adopted.legacyPerformed (CoreReader.Agency.ownRules 0) (CoreReader.Agency.completeOwnWork 0)) ∧ + (∀ (phase : CoreReader.Agency.Phase), + CoreReader.Agency.Performed (CoreReader.Agency.completeOwnWork 0) + (CoreReader.Agency.Subject.process 0 0 phase) CoreReader.Agency.Activity.assessment) ∧ + CoreReader.Agency.Performed (CoreReader.Agency.completeOwnWork 0) (CoreReader.Agency.Subject.system 0) + CoreReader.Agency.Activity.assessment ∧ + CoreReader.Adopted.reflexivitySpecification + (List.map CoreReader.Adopted.legacyRule [CoreReader.Agency.applicationRule]) (fun s => s.owner = 0) + (CoreReader.Adopted.legacyPerformed [CoreReader.Agency.applicationRule] + CoreReader.Agency.applicationWork) ∧ + ¬CoreReader.Agency.Performed CoreReader.Agency.applicationWork (CoreReader.Agency.Subject.system 0) + CoreReader.Agency.Activity.assessment) ∧ + (CoreReader.Adopted.Grounds012 (fun enabled => CoreReader.Adopted.GroundsProvision012 enabled) + CoreReader.Evidence.canonicalArticulation + [CoreReader.Evidence.Facet.value CoreReader.Adopted.groundsPosition012] + (CoreReader.Adopted.AssessmentTask.value CoreReader.Adopted.groundsPosition012) ∧ + CoreReader.Adopted.groundsPosition012.limits true ∧ + CoreReader.Adopted.groundsPosition012.relevantCriticism true) ∧ + CoreReader.Evidence.Compatible [CoreReader.Evidence.zeroRecord] (CoreReader.Evidence.localGenerator 0) ∧ + ¬CoreReader.Evidence.allTrue (CoreReader.Evidence.localGenerator 0) ∧ + CoreReader.Adopted.groundsExperiment012 true = false ∧ + CoreReader.Adopted.groundsExperiment012 false = true ∧ + CoreReader.Adopted.groundsPosition012.outcome true true = CoreReader.Adopted.groundsExperiment012 true ∧ + CoreReader.Adopted.groundsPosition012.outcome true false = CoreReader.Adopted.groundsExperiment012 false +'CoreReader.Adopted.reflexivityCases012' depends on axioms: [propext, Classical.choice, Quot.sound] +ORGANON_TYPE CoreReader.Adopted.reflexivityCases012 "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.reflexivitySpecification [])\n (Lean.Expr.const `CoreReader.Agency.Subject []))\n (Lean.Expr.const `CoreReader.Agency.Inquiry []))\n (Lean.Expr.const `CoreReader.Agency.WorkOutcome []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.map [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule [])\n (Lean.Expr.const `CoreReader.Agency.Subject []))\n (Lean.Expr.const `CoreReader.Agency.Inquiry []))\n (Lean.Expr.const `CoreReader.Agency.WorkOutcome [])))\n (Lean.Expr.const `CoreReader.Adopted.legacyRule []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ownRules [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.lam\n `s\n (Lean.Expr.const `CoreReader.Agency.Subject [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Subject.owner []) (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.legacyPerformed [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ownRules [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.completeOwnWork [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `phase\n (Lean.Expr.const `CoreReader.Agency.Phase [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Performed [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.completeOwnWork [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Subject.process [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `CoreReader.Agency.Activity.assessment []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Performed [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.completeOwnWork [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Subject.system [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `CoreReader.Agency.Activity.assessment [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.reflexivitySpecification [])\n (Lean.Expr.const `CoreReader.Agency.Subject []))\n (Lean.Expr.const `CoreReader.Agency.Inquiry []))\n (Lean.Expr.const `CoreReader.Agency.WorkOutcome []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.map [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule [])\n (Lean.Expr.const `CoreReader.Agency.Subject []))\n (Lean.Expr.const `CoreReader.Agency.Inquiry []))\n (Lean.Expr.const `CoreReader.Agency.WorkOutcome [])))\n (Lean.Expr.const `CoreReader.Adopted.legacyRule []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle []))\n (Lean.Expr.const `CoreReader.Agency.applicationRule []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle [])))))\n (Lean.Expr.lam\n `s\n (Lean.Expr.const `CoreReader.Agency.Subject [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Subject.owner []) (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.legacyPerformed [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle []))\n (Lean.Expr.const `CoreReader.Agency.applicationRule []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle []))))\n (Lean.Expr.const `CoreReader.Agency.applicationWork []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Performed [])\n (Lean.Expr.const `CoreReader.Agency.applicationWork []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Subject.system [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `CoreReader.Agency.Activity.assessment []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.Grounds012 []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `enabled\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.GroundsProvision012 []) (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet.value []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.AssessmentTask.value []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.limits [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.relevantCriticism [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 []))\n (Lean.Expr.const `Bool.true [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.groundsExperiment012 [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.groundsExperiment012 [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Outcome [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.outcome [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.groundsExperiment012 [])\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Outcome [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.outcome [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.groundsExperiment012 [])\n (Lean.Expr.const `Bool.false [])))))))))" +CoreReader.Adopted.reflexivityLimits012 : + (CoreReader.Agency.selfTest [1] = true ∧ + CoreReader.Agency.ownArithmeticPrinciple 0 = false ∧ + ¬∀ (n : Nat), CoreReader.Agency.ownArithmeticPrinciple n = true) ∧ + (CoreReader.Evidence.localGenerator 0 0 = true ∧ + CoreReader.Evidence.localGenerator 0 1 = false ∧ + CoreReader.Evidence.Compatible [CoreReader.Evidence.zeroRecord] (CoreReader.Evidence.localGenerator 0) ∧ + ¬CoreReader.Evidence.Supports [CoreReader.Evidence.zeroRecord] CoreReader.Evidence.allTrue ∧ + CoreReader.Evidence.OwnedRevisionExample) ∧ + (CoreReader.Agency.Generative CoreReader.Agency.openPolicy ∧ + ¬CoreReader.Agency.Reflexive 0 (CoreReader.Agency.ownRules 0) []) ∧ + (CoreReader.Adopted.CompleteCharter012 CoreReader.Integration.actualSystem CoreReader.Integration.actual ∧ + CoreReader.Logic.Admissible CoreReader.Integration.held CoreReader.Integration.context + CoreReader.Integration.actual ∧ + CoreReader.Evidence.Compatible [CoreReader.Integration.costAllowanceRecord] + CoreReader.Integration.actual ∧ + CoreReader.Evidence.Articulated + (CoreReader.Evidence.canonicalArticulation CoreReader.Integration.unsupportedCapabilityFacet) ∧ + ¬CoreReader.Evidence.Supports [CoreReader.Integration.costAllowanceRecord] + CoreReader.Integration.capability ∧ + ¬CoreReader.Adopted.Grounds012 CoreReader.Integration.capability + CoreReader.Evidence.canonicalArticulation [CoreReader.Integration.unsupportedCapabilityFacet] + (CoreReader.Adopted.taskOfFacet CoreReader.Integration.unsupportedCapabilityFacet)) ∧ + CoreReader.Adopted.generationSpecification CoreReader.Agency.openPolicy ∧ + CoreReader.Agency.openPolicy.revisable { kind := CoreReader.Agency.FormKind.principle, version := 0 } ∧ + CoreReader.Adopted.selfExemptPerformed012 { owner := 0, localId := 1 } 1 1 true ∧ + CoreReader.Adopted.selfExemptRule012.applicable 0 ∧ + ¬CoreReader.Adopted.reflexivitySpecification [CoreReader.Adopted.selfExemptRule012] + (fun target => target = 0) CoreReader.Adopted.selfExemptPerformed012 +'CoreReader.Adopted.reflexivityLimits012' depends on axioms: [propext, Quot.sound] +ORGANON_TYPE CoreReader.Adopted.reflexivityLimits012 "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.selfTest [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ownArithmeticPrinciple [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.ownArithmeticPrinciple []) (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Evidence.allTrue []))))\n (Lean.Expr.const `CoreReader.Evidence.OwnedRevisionExample []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Reflexive [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ownRules [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.WorkRecord []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.CompleteCharter012 [])\n (Lean.Expr.const `CoreReader.Integration.actualSystem []))\n (Lean.Expr.const `CoreReader.Integration.actual [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.const `CoreReader.Integration.Question []))\n (Lean.Expr.const `CoreReader.Integration.held []))\n (Lean.Expr.const `CoreReader.Integration.context []))\n (Lean.Expr.const `CoreReader.Integration.actual [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Integration.World [])))\n (Lean.Expr.const `CoreReader.Integration.costAllowanceRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Integration.World [])))))\n (Lean.Expr.const `CoreReader.Integration.actual [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulated [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.const `CoreReader.Integration.unsupportedCapabilityFacet []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Integration.World [])))\n (Lean.Expr.const `CoreReader.Integration.costAllowanceRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Integration.World [])))))\n (Lean.Expr.const `CoreReader.Integration.capability []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.const `CoreReader.Integration.capability []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Integration.World [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Integration.World [])))\n (Lean.Expr.const `CoreReader.Integration.unsupportedCapabilityFacet []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Integration.World [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.const `CoreReader.Integration.unsupportedCapabilityFacet []))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.generationSpecification [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.revisable [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Form.mk [])\n (Lean.Expr.const `CoreReader.Agency.FormKind.principle []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.selfExemptPerformed012 [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.PrincipleKey.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule.applicable [])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.selfExemptRule012 []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.reflexivitySpecification [])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule [])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.selfExemptRule012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule [])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool [])))))\n (Lean.Expr.lam\n `target\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.selfExemptPerformed012 []))))))))))" +CoreReader.Adopted.Grounds012 {W : Type} (claim : CoreReader.Logic.Claim W) + (articulations : CoreReader.Evidence.Facet W → CoreReader.Evidence.Articulation W) + (facets : List (CoreReader.Evidence.Facet W)) (task : CoreReader.Adopted.AssessmentTask W) : Prop +'CoreReader.Adopted.Grounds012' depends on axioms: [propext] +ORGANON_TYPE CoreReader.Adopted.Grounds012 "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `claim\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `articulations\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.bvar 1))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Articulation []) (Lean.Expr.bvar 2))\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `facets\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.bvar 2)))\n (Lean.Expr.forallE\n `task\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.AssessmentTask []) (Lean.Expr.bvar 3))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)" +CoreReader.Adopted.groundsCases012 : + (CoreReader.Adopted.Grounds012 CoreReader.Adopted.localFacet012.claim CoreReader.Evidence.canonicalArticulation + [CoreReader.Adopted.localFacet012] (CoreReader.Adopted.taskOfFacet CoreReader.Adopted.localFacet012) ∧ + CoreReader.Evidence.Articulated (CoreReader.Evidence.canonicalArticulation CoreReader.Adopted.globalFacet012) ∧ + ¬CoreReader.Adopted.Grounds012 CoreReader.Adopted.globalFacet012.claim CoreReader.Evidence.canonicalArticulation + [CoreReader.Adopted.globalFacet012] (CoreReader.Adopted.taskOfFacet CoreReader.Adopted.globalFacet012) ∧ + ¬CoreReader.Adopted.Grounds012 CoreReader.Adopted.strongFacet012.claim + CoreReader.Evidence.canonicalArticulation [CoreReader.Adopted.strongFacet012] + (CoreReader.Adopted.taskOfFacet CoreReader.Adopted.strongFacet012)) ∧ + (CoreReader.Evidence.Articulated CoreReader.Evidence.uninformativeArgument ∧ + ¬CoreReader.Logic.Entails CoreReader.Evidence.uninformativeArgument.assumptions fun w => w = true) ∧ + CoreReader.Adopted.Grounds012 CoreReader.Evidence.allTrue CoreReader.Evidence.canonicalArticulation + [CoreReader.Adopted.circularGlobalFacet012] + (CoreReader.Adopted.taskOfFacet CoreReader.Adopted.circularGlobalFacet012) ∧ + ¬CoreReader.Adopted.NatureAppropriate CoreReader.Adopted.originalGlobalTask012 + CoreReader.Adopted.circularGlobalFacet012 ∧ + ¬CoreReader.Adopted.Grounds012 CoreReader.Evidence.allTrue CoreReader.Evidence.canonicalArticulation + [CoreReader.Adopted.circularGlobalFacet012] CoreReader.Adopted.originalGlobalTask012 +'CoreReader.Adopted.groundsCases012' depends on axioms: [propext] +ORGANON_TYPE CoreReader.Adopted.groundsCases012 "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulated [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Articulated []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.uninformativeArgument [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulation.assumptions [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.uninformativeArgument [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Evidence.allTrue []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.circularGlobalFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.circularGlobalFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.NatureAppropriate [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.originalGlobalTask012 []))\n (Lean.Expr.const `CoreReader.Adopted.circularGlobalFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Evidence.allTrue []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.circularGlobalFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Adopted.originalGlobalTask012 []))))))" +CoreReader.Adopted.empiricalSpecification {W : Type} (records : List (CoreReader.Evidence.Record W)) + (scope claim uncertainty : CoreReader.Logic.Claim W) : Prop +'CoreReader.Adopted.empiricalSpecification' depends on axioms: [propext] +ORGANON_TYPE CoreReader.Adopted.empiricalSpecification "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `records\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Record []) (Lean.Expr.bvar 0)))\n (Lean.Expr.forallE\n `scope\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.bvar 1))\n (Lean.Expr.forallE\n `claim\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.bvar 2))\n (Lean.Expr.forallE\n `uncertainty\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.bvar 3))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)" +CoreReader.Adopted.empiricalCases012 : + (CoreReader.Adopted.Grounds012 CoreReader.Adopted.localFacet012.claim CoreReader.Evidence.canonicalArticulation + [CoreReader.Adopted.localFacet012] (CoreReader.Adopted.taskOfFacet CoreReader.Adopted.localFacet012) ∧ + CoreReader.Evidence.Articulated (CoreReader.Evidence.canonicalArticulation CoreReader.Adopted.globalFacet012) ∧ + ¬CoreReader.Adopted.Grounds012 CoreReader.Adopted.globalFacet012.claim CoreReader.Evidence.canonicalArticulation + [CoreReader.Adopted.globalFacet012] (CoreReader.Adopted.taskOfFacet CoreReader.Adopted.globalFacet012) ∧ + ¬CoreReader.Adopted.Grounds012 CoreReader.Adopted.strongFacet012.claim + CoreReader.Evidence.canonicalArticulation [CoreReader.Adopted.strongFacet012] + (CoreReader.Adopted.taskOfFacet CoreReader.Adopted.strongFacet012)) ∧ + (CoreReader.Evidence.temperatureRecord.test (true, false) = true ∧ + CoreReader.Evidence.Compatible [CoreReader.Evidence.temperatureRecord, CoreReader.Evidence.temperatureRecord] + (true, false) ∧ + CoreReader.Evidence.Compatible [CoreReader.Evidence.temperatureRecord, CoreReader.Evidence.temperatureRecord] + (true, true) ∧ + (¬CoreReader.Evidence.Supports [CoreReader.Evidence.temperatureRecord] fun w => w.snd = true) ∧ + (¬CoreReader.Evidence.Supports + [CoreReader.Evidence.temperatureRecord, CoreReader.Evidence.temperatureRecord] fun w => + w.snd = true) ∧ + CoreReader.Evidence.Compatible [CoreReader.Evidence.actionRecord, CoreReader.Evidence.actionRecord] + (true, 0) ∧ + CoreReader.Evidence.Compatible [CoreReader.Evidence.actionRecord, CoreReader.Evidence.actionRecord] + (true, 3) ∧ + ¬CoreReader.Evidence.Supports [CoreReader.Evidence.actionRecord] + CoreReader.Evidence.announcementPosition.consequence ∧ + ¬CoreReader.Evidence.Supports [CoreReader.Evidence.actionRecord, CoreReader.Evidence.actionRecord] + CoreReader.Evidence.announcementPosition.consequence ∧ + ¬CoreReader.Evidence.ValueProcedure CoreReader.Evidence.announcementPosition) ∧ + ((CoreReader.Adopted.empiricalSpecification + [CoreReader.Evidence.temperatureRecord, CoreReader.Evidence.temperatureRecord] (fun x => True) + (fun w => w.fst = true) fun w => w.snd = true ∨ w.snd = false) ∧ + CoreReader.Evidence.Compatible [CoreReader.Evidence.temperatureRecord, CoreReader.Evidence.temperatureRecord] + (true, true) ∧ + CoreReader.Evidence.Compatible + [CoreReader.Evidence.temperatureRecord, CoreReader.Evidence.temperatureRecord] (true, false)) ∧ + (CoreReader.Adopted.Grounds012 (fun f => f 0 = true) CoreReader.Evidence.canonicalArticulation + [CoreReader.Adopted.localFacet012] CoreReader.Adopted.originalLocalTask012 ∧ + CoreReader.Adopted.Grounds012 (fun f => f 0 = true) CoreReader.Evidence.canonicalArticulation + [CoreReader.Adopted.observedInferenceFacet012] CoreReader.Adopted.originalLocalTask012) ∧ + CoreReader.Evidence.FacetDischarged CoreReader.Adopted.uncertaintyBypassFacet012 ∧ + ¬CoreReader.Adopted.NatureAppropriate CoreReader.Adopted.originalUncertaintyTask012 + CoreReader.Adopted.uncertaintyBypassFacet012 ∧ + ¬CoreReader.Adopted.Grounds012 (fun w => w.fst = true) CoreReader.Evidence.canonicalArticulation + [CoreReader.Adopted.uncertaintyBypassFacet012] CoreReader.Adopted.originalUncertaintyTask012 +'CoreReader.Adopted.empiricalCases012' depends on axioms: [propext] +ORGANON_TYPE CoreReader.Adopted.empiricalCases012 "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulated [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record.test [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 3)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.consequence [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.consequence [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.empiricalSpecification [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 577346429) \"_hygCtx\") \"_hyg\") 256)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `True [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.fst [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Or [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.false [])))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.bvar 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Adopted.originalLocalTask012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.bvar 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.observedInferenceFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Adopted.originalLocalTask012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.FacetDischarged [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.uncertaintyBypassFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.NatureAppropriate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.originalUncertaintyTask012 []))\n (Lean.Expr.const `CoreReader.Adopted.uncertaintyBypassFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.fst [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Adopted.uncertaintyBypassFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))))\n (Lean.Expr.const `CoreReader.Adopted.originalUncertaintyTask012 []))))))))" +CoreReader.Adopted.inferentialSpecification {W : Type} (assumptions : CoreReader.Logic.Theory W) + (claim : CoreReader.Logic.Claim W) : Prop +'CoreReader.Adopted.inferentialSpecification' depends on axioms: [propext] +ORGANON_TYPE CoreReader.Adopted.inferentialSpecification "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `assumptions\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Theory []) (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `claim\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.bvar 1))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)" +CoreReader.Adopted.inferentialCases012 : + ((CoreReader.Adopted.inferentialSpecification (CoreReader.Logic.singleton fun n => n = 2) fun n => n + 1 = 3) ∧ + CoreReader.Adopted.InferenceExamined CoreReader.Logic.emptyTheory (fun w => w = true) false ∧ + CoreReader.Logic.Models CoreReader.Logic.emptyTheory false ∧ ¬(fun w => w = true) false) ∧ + (CoreReader.Logic.Satisfiable + (CoreReader.Logic.union CoreReader.Logic.emptyTheory (CoreReader.Logic.singleton fun w => w = true)) ∧ + ¬CoreReader.Logic.Entails CoreReader.Logic.emptyTheory fun w => w = true) ∧ + CoreReader.Evidence.FacetDischarged + (CoreReader.Evidence.Facet.inferential (CoreReader.Logic.singleton fun w => w = true) fun w => w = true) ∧ + ¬CoreReader.Adopted.Grounds012 (fun w => w = true) CoreReader.Evidence.canonicalArticulation + [CoreReader.Evidence.Facet.inferential (CoreReader.Logic.singleton fun w => w = true) fun w => w = true] + (CoreReader.Adopted.AssessmentTask.inferential CoreReader.Logic.emptyTheory fun w => w = true) +'CoreReader.Adopted.inferentialCases012' depends on axioms: [propext] +ORGANON_TYPE CoreReader.Adopted.inferentialCases012 "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.inferentialSpecification []) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Nat []))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `HAdd.hAdd [Lean.Level.zero, Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `instHAdd [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instAddNat [])))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.InferenceExamined []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Models []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))\n (Lean.Expr.const `Bool.false [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.FacetDischarged []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet.inferential []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.Grounds012 []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.inferential [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.AssessmentTask.inferential [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))))" +CoreReader.Adopted.valueSpecification {W : Type} (position : CoreReader.Evidence.ValuePosition W) : Prop +'CoreReader.Adopted.valueSpecification' depends on axioms: [propext] +ORGANON_TYPE CoreReader.Adopted.valueSpecification "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `position\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.ValuePosition []) (Lean.Expr.bvar 0))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)" +CoreReader.Adopted.valueCases012 : + CoreReader.Adopted.valueSpecification CoreReader.Evidence.switchPosition ∧ + (CoreReader.Evidence.announcementPosition.reasons ≠ [] ∧ + CoreReader.Evidence.announcementPosition.commitment (true, 0) ∧ + (∀ (reason : CoreReader.Evidence.BudgetWorld → CoreReader.Evidence.announcementPosition.Position → Prop), + reason ∈ CoreReader.Evidence.announcementPosition.reasons → + reason (true, 0) CoreReader.Evidence.announcementPosition.adopted) ∧ + ¬CoreReader.Evidence.announcementPosition.consequence (true, 0) ∧ + ¬CoreReader.Evidence.ValueProcedure CoreReader.Evidence.announcementPosition) ∧ + ¬CoreReader.Evidence.ValueProcedure CoreReader.Adopted.closedPosition012 ∧ + (CoreReader.Evidence.ValueProcedure CoreReader.Evidence.switchPosition ∧ + CoreReader.Logic.Satisfiable CoreReader.Evidence.switchPosition.starting ∧ + ¬CoreReader.Logic.Entails CoreReader.Logic.emptyTheory CoreReader.Evidence.switchPosition.commitment ∧ + (CoreReader.Evidence.JointAdoption CoreReader.Evidence.oppositePosition ∧ + ¬CoreReader.Evidence.ValueProcedure CoreReader.Evidence.oppositePosition) ∧ + ¬CoreReader.Evidence.ValueProcedure CoreReader.Evidence.contradictoryStartingPosition ∧ + ¬CoreReader.Evidence.ValueProcedure CoreReader.Evidence.impossibleAdoptionPosition) ∧ + CoreReader.Evidence.FacetDischarged CoreReader.Adopted.selectedFactFacet012 ∧ + CoreReader.Adopted.valueSpecification CoreReader.Evidence.switchPosition ∧ + ¬CoreReader.Adopted.Grounds012 CoreReader.Evidence.switchPosition.commitment + CoreReader.Evidence.canonicalArticulation [CoreReader.Adopted.selectedFactFacet012] + (CoreReader.Adopted.AssessmentTask.value CoreReader.Evidence.switchPosition) +'CoreReader.Adopted.valueCases012' depends on axioms: [propext, Classical.choice, Quot.sound] +ORGANON_TYPE CoreReader.Adopted.valueCases012 "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.valueSpecification []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.reasons [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `reason\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.reasons [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.bvar 1)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.adopted [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.consequence [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.ValueProcedure []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.closedPosition012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.ValueProcedure []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.starting [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.JointAdoption [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.oppositePosition [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.oppositePosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.contradictoryStartingPosition []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.impossibleAdoptionPosition [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.FacetDischarged []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.selectedFactFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.valueSpecification []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.Grounds012 []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.selectedFactFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.AssessmentTask.value [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))))))))" +CoreReader.Adopted.groundsLimits012 : + (CoreReader.Evidence.Articulated CoreReader.Adopted.clearFalseArgument012 ∧ + ¬CoreReader.Logic.Models CoreReader.Adopted.clearFalseArgument012.assumptions false) ∧ + (CoreReader.Evidence.temperatureRecord.test (true, false) = true ∧ + CoreReader.Evidence.Compatible [CoreReader.Evidence.temperatureRecord, CoreReader.Evidence.temperatureRecord] + (true, false) ∧ + CoreReader.Evidence.Compatible [CoreReader.Evidence.temperatureRecord, CoreReader.Evidence.temperatureRecord] + (true, true) ∧ + (¬CoreReader.Evidence.Supports [CoreReader.Evidence.temperatureRecord] fun w => w.snd = true) ∧ + (¬CoreReader.Evidence.Supports + [CoreReader.Evidence.temperatureRecord, CoreReader.Evidence.temperatureRecord] fun w => + w.snd = true) ∧ + CoreReader.Evidence.Compatible [CoreReader.Evidence.actionRecord, CoreReader.Evidence.actionRecord] + (true, 0) ∧ + CoreReader.Evidence.Compatible [CoreReader.Evidence.actionRecord, CoreReader.Evidence.actionRecord] + (true, 3) ∧ + ¬CoreReader.Evidence.Supports [CoreReader.Evidence.actionRecord] + CoreReader.Evidence.announcementPosition.consequence ∧ + ¬CoreReader.Evidence.Supports [CoreReader.Evidence.actionRecord, CoreReader.Evidence.actionRecord] + CoreReader.Evidence.announcementPosition.consequence ∧ + ¬CoreReader.Evidence.ValueProcedure CoreReader.Evidence.announcementPosition) ∧ + (CoreReader.Adopted.valueSpecification CoreReader.Evidence.switchPosition ∧ + CoreReader.Evidence.Compatible [CoreReader.Adopted.valueNeutralRecord012] false ∧ + ¬CoreReader.Evidence.Supports [CoreReader.Adopted.valueNeutralRecord012] + CoreReader.Evidence.switchPosition.commitment ∧ + ¬CoreReader.Logic.Entails CoreReader.Logic.emptyTheory CoreReader.Evidence.switchPosition.commitment) ∧ + (CoreReader.Evidence.ValueProcedure CoreReader.Evidence.switchPosition ∧ + CoreReader.Logic.Satisfiable CoreReader.Evidence.switchPosition.starting ∧ + ¬CoreReader.Logic.Entails CoreReader.Logic.emptyTheory CoreReader.Evidence.switchPosition.commitment ∧ + (CoreReader.Evidence.JointAdoption CoreReader.Evidence.oppositePosition ∧ + ¬CoreReader.Evidence.ValueProcedure CoreReader.Evidence.oppositePosition) ∧ + ¬CoreReader.Evidence.ValueProcedure CoreReader.Evidence.contradictoryStartingPosition ∧ + ¬CoreReader.Evidence.ValueProcedure CoreReader.Evidence.impossibleAdoptionPosition) ∧ + CoreReader.Adopted.ClaimNoStronger (fun f => f 0 = true) CoreReader.Evidence.allTrue ∧ + (¬CoreReader.Adopted.ClaimNoStronger CoreReader.Evidence.allTrue fun f => f 0 = true) ∧ + CoreReader.Adopted.valueSpecification CoreReader.Evidence.switchPosition +'CoreReader.Adopted.groundsLimits012' depends on axioms: [propext, Classical.choice, Quot.sound] +ORGANON_TYPE CoreReader.Adopted.groundsLimits012 "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Articulated []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.clearFalseArgument012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Models []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulation.assumptions [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.clearFalseArgument012 [])))\n (Lean.Expr.const `Bool.false [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record.test [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 3)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.consequence [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.consequence [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.valueSpecification []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Compatible []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Record []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.valueNeutralRecord012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Record []) (Lean.Expr.const `Bool [])))))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Supports []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Record []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.valueNeutralRecord012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Record []) (Lean.Expr.const `Bool [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.ValueProcedure []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.starting [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.JointAdoption [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.oppositePosition [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.oppositePosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.contradictoryStartingPosition []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.impossibleAdoptionPosition [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ClaimNoStronger [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.bvar 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ClaimNoStronger [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Evidence.allTrue []))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.bvar 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.valueSpecification []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))))))" +CoreReader.Adopted.scopeSpecification {W : Type} (account : CoreReader.Adopted.ScopeAccount W) : Prop +'CoreReader.Adopted.scopeSpecification' does not depend on any axioms +ORGANON_TYPE CoreReader.Adopted.scopeSpecification "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `account\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.ScopeAccount []) (Lean.Expr.bvar 0))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)" +CoreReader.Adopted.scopeCases012 : + CoreReader.Adopted.scopeSpecification CoreReader.Adopted.localScopeAccount012 ∧ + (∀ (n : Nat), n = 0 → (fun x => true) n = CoreReader.Evidence.localGenerator 0 n) ∧ + (fun x => true) 1 ≠ CoreReader.Evidence.localGenerator 0 1 +'CoreReader.Adopted.scopeCases012' depends on axioms: [propext] +ORGANON_TYPE CoreReader.Adopted.scopeCases012 "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.scopeSpecification []) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Adopted.localScopeAccount012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 3351349031) \"_hygCtx\") \"_hyg\") 37)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.bvar 1)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 3351349031) \"_hygCtx\") \"_hyg\") 54)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))" +CoreReader.Adopted.scopeLimits012 : + ((∃ outside, outside ≠ 0) ∧ + (CoreReader.Evidence.Compatible [CoreReader.Evidence.zeroRecord] fun x => true) ∧ + CoreReader.Evidence.Compatible [CoreReader.Evidence.zeroRecord] (CoreReader.Evidence.localGenerator 0) ∧ + (CoreReader.Evidence.allTrue fun x => true) ∧ + ¬CoreReader.Evidence.allTrue (CoreReader.Evidence.localGenerator 0) ∧ + ¬CoreReader.Evidence.Supports [CoreReader.Evidence.zeroRecord] CoreReader.Evidence.allTrue) ∧ + ((∀ (n : Nat), n = 0 → (fun x => true) n = CoreReader.Evidence.localGenerator 0 n) ∧ + (fun x => true) 1 ≠ CoreReader.Evidence.localGenerator 0 1) ∧ + ([CoreReader.Evidence.zeroRecord].length = 1 ∧ + (∃ f, CoreReader.Evidence.Compatible [CoreReader.Evidence.zeroRecord] f) ∧ + (CoreReader.Evidence.Supports [CoreReader.Evidence.zeroRecord] fun f => f 0 = true) ∧ + ¬CoreReader.Evidence.Supports [CoreReader.Evidence.zeroRecord] CoreReader.Evidence.allTrue) ∧ + (have a := { setting := 0, actualOutcome := 1, recordedOutcome := 1 }; + have b := { setting := 0, actualOutcome := 2, recordedOutcome := 2 }; + CoreReader.Evidence.Reproduced a b ∧ + a.actualOutcome ≠ b.actualOutcome ∧ CoreReader.Evidence.Bounded a ∧ CoreReader.Evidence.Bounded b) ∧ + ((CoreReader.Evidence.Verified { setting := 0, actualOutcome := 1, recordedOutcome := 1 } ∧ + CoreReader.Evidence.Verified { setting := 1, actualOutcome := 1, recordedOutcome := 1 } ∧ + ¬CoreReader.Evidence.Reproduced { setting := 0, actualOutcome := 1, recordedOutcome := 1 } + { setting := 1, actualOutcome := 1, recordedOutcome := 1 }) ∧ + (CoreReader.Evidence.Reproduced { setting := 0, actualOutcome := 1, recordedOutcome := 1 } + { setting := 0, actualOutcome := 3, recordedOutcome := 2 } ∧ + ¬CoreReader.Evidence.Verified { setting := 0, actualOutcome := 3, recordedOutcome := 2 } ∧ + ¬CoreReader.Evidence.Bounded { setting := 0, actualOutcome := 3, recordedOutcome := 2 }) ∧ + CoreReader.Evidence.Bounded { setting := 0, actualOutcome := 1, recordedOutcome := 1 } ∧ + CoreReader.Evidence.Bounded { setting := 0, actualOutcome := 2, recordedOutcome := 0 } ∧ + ¬CoreReader.Evidence.Verified { setting := 0, actualOutcome := 2, recordedOutcome := 0 }) ∧ + (CoreReader.Evidence.FacetDischarged CoreReader.Evidence.arithmeticFacet ∧ + CoreReader.Evidence.usesObservation CoreReader.Evidence.arithmeticFacet = false) ∧ + ((CoreReader.Adopted.inferentialSpecification (CoreReader.Logic.singleton fun on => on = true) fun on => + on ≠ false) ∧ + CoreReader.Evidence.usesObservation + (CoreReader.Evidence.Facet.inferential (CoreReader.Logic.singleton fun on => on = true) fun on => + on ≠ false) = + false) ∧ + CoreReader.Adopted.drawWeight012 true > 0 ∧ + CoreReader.Adopted.drawWeight012 false > 0 ∧ + CoreReader.Adopted.drawWeight012 true = CoreReader.Adopted.drawWeight012 false ∧ + CoreReader.Evidence.Reproduced (CoreReader.Adopted.randomTrial012 true) + (CoreReader.Adopted.randomTrial012 false) ∧ + (CoreReader.Adopted.randomTrial012 true).actualOutcome ≠ + (CoreReader.Adopted.randomTrial012 false).actualOutcome ∧ + ∀ (draw : Bool), + CoreReader.Evidence.Verified (CoreReader.Adopted.randomTrial012 draw) ∧ + CoreReader.Evidence.Bounded (CoreReader.Adopted.randomTrial012 draw) +'CoreReader.Adopted.scopeLimits012' depends on axioms: [propext, Quot.sound] +ORGANON_TYPE CoreReader.Adopted.scopeLimits012 "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lam\n `outside\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 27637535) \"_hygCtx\") \"_hyg\") 38)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 27637535) \"_hygCtx\") \"_hyg\") 62)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 27637535) \"_hygCtx\") \"_hyg\") 117)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.bvar 1)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 27637535) \"_hygCtx\") \"_hyg\") 134)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.bvar 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.letE\n `a\n (Lean.Expr.const `CoreReader.Evidence.Trial [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.letE\n `b\n (Lean.Expr.const `CoreReader.Evidence.Trial [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Reproduced []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.actualOutcome [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Trial.actualOutcome []) (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Bounded []) (Lean.Expr.bvar 1)))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Bounded []) (Lean.Expr.bvar 0)))))\n true)\n true))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Verified [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Verified [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Reproduced [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Reproduced [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Verified [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2))))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Bounded [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Bounded [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Bounded [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Verified [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.FacetDischarged []) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Evidence.arithmeticFacet [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.usesObservation [])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Evidence.arithmeticFacet [])))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.inferentialSpecification [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `on\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.lam\n `on\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.false []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.usesObservation [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.inferential [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `on\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.lam\n `on\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.false []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `GT.gt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.drawWeight012 [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `GT.gt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.drawWeight012 [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.drawWeight012 [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.drawWeight012 [])\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Reproduced [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.actualOutcome [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.actualOutcome [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.const `Bool.false [])))))\n (Lean.Expr.forallE\n `draw\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Verified [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Bounded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.bvar 0))))\n (Lean.BinderInfo.default)))))))))))))" +CoreReader.Adopted.capabilitySpecification (assessed : CoreReader.Evidence.Process) + (contract : CoreReader.Logic.Claim CoreReader.Evidence.Process) : Prop +'CoreReader.Adopted.capabilitySpecification' depends on axioms: [propext] +ORGANON_TYPE CoreReader.Adopted.capabilitySpecification "Lean.Expr.forallE\n `assessed\n (Lean.Expr.const `CoreReader.Evidence.Process [])\n (Lean.Expr.forallE\n `contract\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `CoreReader.Evidence.Process []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)" +CoreReader.Adopted.capabilityCases012 : + (CoreReader.Adopted.capabilitySpecification CoreReader.Evidence.outputOnlyProcess CoreReader.Evidence.OutputContract ∧ + CoreReader.Adopted.capabilitySpecification CoreReader.Evidence.explainedProcess + CoreReader.Evidence.FullProcessContract ∧ + (∃ certificate, + certificate.assessorId ≠ certificate.assessedId ∧ + CoreReader.Evidence.OutputContract CoreReader.Evidence.outputOnlyProcess) ∧ + ¬CoreReader.Evidence.ExplanationContract CoreReader.Evidence.outputOnlyProcess) ∧ + CoreReader.Adopted.OwnCapability012 7 7 CoreReader.Evidence.outputOnlyProcess CoreReader.Evidence.OutputContract ∧ + CoreReader.Adopted.explainedWithoutVariation012.process = CoreReader.Adopted.mechanismResponder012.process ∧ + CoreReader.Evidence.FullProcessContract CoreReader.Adopted.explainedWithoutVariation012.process ∧ + ¬CoreReader.Adopted.UnderstandingApplication012 CoreReader.Adopted.explainedWithoutVariation012 ∧ + CoreReader.Adopted.UnderstandingApplication012 CoreReader.Adopted.mechanismResponder012 ∧ + CoreReader.Adopted.Grounds012 CoreReader.Adopted.UnderstandingApplication012 + CoreReader.Evidence.canonicalArticulation + [CoreReader.Adopted.understandingFacet012 CoreReader.Adopted.mechanismResponder012] + (CoreReader.Adopted.understandingTask012 CoreReader.Adopted.mechanismResponder012) ∧ + ¬CoreReader.Adopted.Grounds012 CoreReader.Adopted.UnderstandingApplication012 + CoreReader.Evidence.canonicalArticulation + [CoreReader.Adopted.understandingFacet012 CoreReader.Adopted.explainedWithoutVariation012] + (CoreReader.Adopted.understandingTask012 CoreReader.Adopted.explainedWithoutVariation012) +'CoreReader.Adopted.capabilityCases012' depends on axioms: [propext] +ORGANON_TYPE CoreReader.Adopted.capabilityCases012 "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.const `CoreReader.Evidence.explainedProcess []))\n (Lean.Expr.const `CoreReader.Evidence.FullProcessContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))\n (Lean.Expr.lam\n `certificate\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate.assessorId [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate.assessedId [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExplanationContract [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.OwnCapability012 [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 7)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 7)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 7)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 7)))))\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Evidence.Process []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012.process [])\n (Lean.Expr.const `CoreReader.Adopted.explainedWithoutVariation012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012.process [])\n (Lean.Expr.const `CoreReader.Adopted.mechanismResponder012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.FullProcessContract [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012.process [])\n (Lean.Expr.const `CoreReader.Adopted.explainedWithoutVariation012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.UnderstandingApplication012 [])\n (Lean.Expr.const `CoreReader.Adopted.explainedWithoutVariation012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.UnderstandingApplication012 [])\n (Lean.Expr.const `CoreReader.Adopted.mechanismResponder012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 []))\n (Lean.Expr.const `CoreReader.Adopted.UnderstandingApplication012 []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.understandingFacet012 [])\n (Lean.Expr.const `CoreReader.Adopted.mechanismResponder012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.understandingTask012 [])\n (Lean.Expr.const `CoreReader.Adopted.mechanismResponder012 []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 []))\n (Lean.Expr.const `CoreReader.Adopted.UnderstandingApplication012 []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.understandingFacet012 [])\n (Lean.Expr.const `CoreReader.Adopted.explainedWithoutVariation012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.understandingTask012 [])\n (Lean.Expr.const `CoreReader.Adopted.explainedWithoutVariation012 []))))))))))" +CoreReader.Adopted.capabilityLimits012 : + (CoreReader.Adopted.capabilitySpecification CoreReader.Evidence.outputOnlyProcess CoreReader.Evidence.OutputContract ∧ + CoreReader.Adopted.capabilitySpecification CoreReader.Evidence.explainedProcess + CoreReader.Evidence.FullProcessContract ∧ + (∃ certificate, + certificate.assessorId ≠ certificate.assessedId ∧ + CoreReader.Evidence.OutputContract CoreReader.Evidence.outputOnlyProcess) ∧ + ¬CoreReader.Evidence.ExplanationContract CoreReader.Evidence.outputOnlyProcess) ∧ + (∀ (kind : CoreReader.Agency.InventoryKind), + CoreReader.Agency.Available + [{ kind := kind, content := CoreReader.Agency.Operation.copy }, + { kind := kind, content := CoreReader.Agency.Operation.copy }] + CoreReader.Agency.Operation.copy ∧ + ¬CoreReader.Agency.Available + [{ kind := kind, content := CoreReader.Agency.Operation.copy }, + { kind := kind, content := CoreReader.Agency.Operation.copy }] + CoreReader.Agency.Operation.successor) ∧ + CoreReader.Agency.Generative CoreReader.Agency.generatingSystem.policy ∧ + CoreReader.Agency.generatingSystem.policy.permitsVersion 0 0 ∧ + ¬CoreReader.Agency.Expanded CoreReader.Agency.generatingSystem.current CoreReader.Agency.inflatedState ∧ + CoreReader.Agency.generatingSystem.current.inventory.length < + CoreReader.Agency.inflatedState.inventory.length ∧ + CoreReader.Agency.generatingSystem.current.abstractionLayers.length < + CoreReader.Agency.inflatedState.abstractionLayers.length ∧ + CoreReader.Agency.generatingSystem.current.vocabulary.length < + CoreReader.Agency.inflatedState.vocabulary.length ∧ + CoreReader.Agency.generatingSystem.execute CoreReader.Agency.availableResources = some 6 ∧ + CoreReader.Agency.generatingSystem.execute + (have __src := CoreReader.Agency.availableResources; + { experience := none, knowledge := __src.knowledge, collaborator := __src.collaborator }) = + none ∧ + CoreReader.Agency.generatingSystem.execute + (have __src := CoreReader.Agency.availableResources; + { experience := __src.experience, knowledge := none, collaborator := __src.collaborator }) = + none ∧ + CoreReader.Agency.generatingSystem.execute + (have __src := CoreReader.Agency.availableResources; + { experience := __src.experience, knowledge := __src.knowledge, collaborator := none }) = + none ∧ + CoreReader.Agency.generatingSystem.execute + { experience := none, knowledge := none, collaborator := none } = + none ∧ + ¬CoreReader.Agency.Expanded CoreReader.Agency.generatingSystem.current + CoreReader.Agency.generatingSystem.stableAction ∧ + CoreReader.Agency.generatingSystem.stableAction = + CoreReader.Agency.generatingSystem.current ∧ + CoreReader.Agency.generatingSystem.requirementsMet + CoreReader.Agency.generatingSystem.stableAction ∧ + CoreReader.Agency.generatingSystem.withinBudget + CoreReader.Agency.generatingSystem.stableAction ∧ + ¬CoreReader.Agency.generatingSystem.withinBudget CoreReader.Agency.inflatedState ∧ + CoreReader.Agency.StableReason CoreReader.Agency.generatingSystem.current + CoreReader.Agency.inflatedState ∧ + CoreReader.Agency.inflatedAnnouncement = + CoreReader.Agency.generatingSystem.report CoreReader.Agency.inflatedState + CoreReader.Agency.Operation.successor 0 1 ∧ + CoreReader.Agency.inflatedAnnouncement.owner = + CoreReader.Agency.generatingSystem.owner ∧ + CoreReader.Agency.inflatedAnnouncement.before = + CoreReader.Agency.generatingSystem.current ∧ + CoreReader.Agency.inflatedAnnouncement.after = + CoreReader.Agency.inflatedState ∧ + CoreReader.Agency.inflatedAnnouncement.reportedNewOperation = + CoreReader.Agency.Operation.successor ∧ + CoreReader.Agency.inflatedAnnouncement.input = 0 ∧ + CoreReader.Agency.inflatedAnnouncement.expectedOutput = 1 ∧ + ¬CoreReader.Agency.inflatedAnnouncement.claim ∧ + ¬CoreReader.Agency.Expanded + CoreReader.Agency.inflatedAnnouncement.before + CoreReader.Agency.inflatedAnnouncement.after +'CoreReader.Adopted.capabilityLimits012' depends on axioms: [propext, Quot.sound] +ORGANON_TYPE CoreReader.Adopted.capabilityLimits012 "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.const `CoreReader.Evidence.explainedProcess []))\n (Lean.Expr.const `CoreReader.Evidence.FullProcessContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))\n (Lean.Expr.lam\n `certificate\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate.assessorId [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate.assessedId [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExplanationContract [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `kind\n (Lean.Expr.const `CoreReader.Agency.InventoryKind [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Available [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item [])))))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Available [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item [])))))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor []))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.permitsVersion [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.availableResources [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Option.some [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 6)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3023016825) \"_hygCtx\") \"_hyg\") 160)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3023016825) \"_hygCtx\") \"_hyg\") 179)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3023016825) \"_hygCtx\") \"_hyg\") 198)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n true)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.requirementsMet [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.StableReason [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Announcement []))\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.report [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.owner [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.owner [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.before [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.after [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.reportedNewOperation\n [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.input [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.expectedOutput\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.claim [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.before\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.after [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))))))))))))))))))))))))))))" +CoreReader.Adopted.choiceSpecification (requirements : CoreReader.Choice.Requirements) + (implementation : CoreReader.Choice.Implementation) (reasons : List CoreReader.Choice.Reason) : Prop +'CoreReader.Adopted.choiceSpecification' does not depend on any axioms +ORGANON_TYPE CoreReader.Adopted.choiceSpecification "Lean.Expr.forallE\n `requirements\n (Lean.Expr.const `CoreReader.Choice.Requirements [])\n (Lean.Expr.forallE\n `implementation\n (Lean.Expr.const `CoreReader.Choice.Implementation [])\n (Lean.Expr.forallE\n `reasons\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)" +CoreReader.Adopted.choiceCases012 : + (CoreReader.Choice.identityImpl.conventional = true ∧ + CoreReader.Choice.identityImpl.established = true ∧ + CoreReader.Choice.JustifiedChoice CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + [CoreReader.Choice.Reason.status CoreReader.Choice.StatusKind.convention, + CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.output]) ∧ + (CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.explanation) ∧ + CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.applicability) ∧ + CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.simplicity) ∧ + CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.procedure) ∧ + CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements CoreReader.Choice.cheapSuccessor + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.simplicity) ∧ + ¬CoreReader.Choice.JustifiedChoice CoreReader.Choice.identityRequirements + CoreReader.Choice.cheapSuccessor + [CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.simplicity]) ∧ + (CoreReader.Evidence.Articulated CoreReader.Choice.priorityArticulation ∧ + CoreReader.Choice.AssessmentAccurate false ∧ + (∀ (selected : CoreReader.Choice.Candidate), + CoreReader.Logic.Models CoreReader.Choice.statusFacts selected) ∧ + CoreReader.Choice.priorityClaim CoreReader.Choice.Candidate.identity ∧ + ¬CoreReader.Choice.priorityClaim CoreReader.Choice.Candidate.successor ∧ + ¬CoreReader.Logic.Entails CoreReader.Choice.statusFacts CoreReader.Choice.priorityClaim ∧ + ¬CoreReader.Choice.JustifiedChoice CoreReader.Choice.identityRequirements + CoreReader.Choice.identityImpl + [CoreReader.Choice.Reason.status CoreReader.Choice.StatusKind.standing]) ∧ + ((∀ (n : Nat), CoreReader.Choice.identityImpl.run n = CoreReader.Adopted.wrongExplanation012.run n) ∧ + CoreReader.Choice.Feasible CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl ∧ + CoreReader.Choice.Feasible CoreReader.Choice.identityRequirements CoreReader.Adopted.wrongExplanation012 ∧ + CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.explanation) ∧ + ¬CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements + CoreReader.Adopted.wrongExplanation012 + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.explanation)) ∧ + (¬CoreReader.Adopted.choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem + CoreReader.Integration.actual).implementation + [CoreReader.Choice.Reason.status CoreReader.Choice.StatusKind.standing] ∧ + CoreReader.Adopted.choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem + CoreReader.Integration.actual).implementation + [CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.output]) ∧ + ∀ (kind : CoreReader.Choice.StatusKind), + ¬CoreReader.Adopted.choiceSpecification CoreReader.Choice.identityRequirements + CoreReader.Choice.identityImpl [CoreReader.Choice.Reason.status kind] +'CoreReader.Adopted.choiceCases012' depends on axioms: [propext, Classical.choice, Quot.sound] +ORGANON_TYPE CoreReader.Adopted.choiceCases012 "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.conventional [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.established [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.status [])\n (Lean.Expr.const `CoreReader.Choice.StatusKind.convention [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.output [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.explanation []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.applicability []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.simplicity []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.procedure []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.cheapSuccessor []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.simplicity []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.cheapSuccessor []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.simplicity [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason [])))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulated [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.priorityArticulation [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.AssessmentAccurate [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `selected\n (Lean.Expr.const `CoreReader.Choice.Candidate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Models [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.statusFacts []))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.priorityClaim [])\n (Lean.Expr.const `CoreReader.Choice.Candidate.identity [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.priorityClaim [])\n (Lean.Expr.const `CoreReader.Choice.Candidate.successor []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Entails [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.statusFacts []))\n (Lean.Expr.const `CoreReader.Choice.priorityClaim []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.status [])\n (Lean.Expr.const `CoreReader.Choice.StatusKind.standing [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 []))\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Feasible [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Feasible [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.explanation []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.explanation [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.choiceSpecification [])\n (Lean.Expr.const `CoreReader.Integration.proposalRequirements []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Integration.PhilosophyMethod.implementation [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Integration.currentPhilosophy [])\n (Lean.Expr.const `CoreReader.Integration.actualSystem []))\n (Lean.Expr.const `CoreReader.Integration.actual []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.status [])\n (Lean.Expr.const `CoreReader.Choice.StatusKind.standing [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.choiceSpecification [])\n (Lean.Expr.const `CoreReader.Integration.proposalRequirements []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Integration.PhilosophyMethod.implementation [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Integration.currentPhilosophy [])\n (Lean.Expr.const `CoreReader.Integration.actualSystem []))\n (Lean.Expr.const `CoreReader.Integration.actual []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.output [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))\n (Lean.Expr.forallE\n `kind\n (Lean.Expr.const `CoreReader.Choice.StatusKind [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.choiceSpecification [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Choice.Reason.status []) (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason [])))))\n (Lean.BinderInfo.default))))))" +CoreReader.Adopted.choiceLimits012 : + ((∀ (candidate : CoreReader.Choice.Candidate), + CoreReader.Choice.Feasible CoreReader.Choice.identityRequirements (CoreReader.Choice.implementation candidate) ↔ + candidate = CoreReader.Choice.Candidate.identity) ∧ + CoreReader.Choice.JustifiedChoice CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + CoreReader.Choice.objectiveReason) ∧ + (CoreReader.Choice.identityImpl.conventional = true ∧ + CoreReader.Choice.identityImpl.established = true ∧ + CoreReader.Choice.JustifiedChoice CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + [CoreReader.Choice.Reason.status CoreReader.Choice.StatusKind.convention, + CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.output]) ∧ + ((∀ (n : Nat), CoreReader.Choice.identityImpl.run n = CoreReader.Adopted.wrongExplanation012.run n) ∧ + CoreReader.Choice.Feasible CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl ∧ + CoreReader.Choice.Feasible CoreReader.Choice.identityRequirements CoreReader.Adopted.wrongExplanation012 ∧ + CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.explanation) ∧ + ¬CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements + CoreReader.Adopted.wrongExplanation012 + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.explanation)) ∧ + (CoreReader.Choice.JustifiedChoice CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + CoreReader.Choice.objectiveReason ∧ + CoreReader.Choice.identityImpl.run 0 ≠ CoreReader.Choice.successorImpl.run 0) ∧ + ((∀ (x : Nat), x = 0 → CoreReader.Choice.identityImpl.run x = CoreReader.Choice.changedOutsideZero.run x) ∧ + CoreReader.Choice.identityImpl.run 1 ≠ CoreReader.Choice.changedOutsideZero.run 1) ∧ + (CoreReader.Evidence.Articulated CoreReader.Choice.priorityArticulation ∧ + CoreReader.Choice.AssessmentAccurate false ∧ + (∀ (selected : CoreReader.Choice.Candidate), + CoreReader.Logic.Models CoreReader.Choice.statusFacts selected) ∧ + CoreReader.Choice.priorityClaim CoreReader.Choice.Candidate.identity ∧ + ¬CoreReader.Choice.priorityClaim CoreReader.Choice.Candidate.successor ∧ + ¬CoreReader.Logic.Entails CoreReader.Choice.statusFacts CoreReader.Choice.priorityClaim ∧ + ¬CoreReader.Choice.JustifiedChoice CoreReader.Choice.identityRequirements + CoreReader.Choice.identityImpl + [CoreReader.Choice.Reason.status CoreReader.Choice.StatusKind.standing]) ∧ + CoreReader.Choice.PolicyIndependenceExample +'CoreReader.Adopted.choiceLimits012' depends on axioms: [propext, Classical.choice, Quot.sound] +ORGANON_TYPE CoreReader.Adopted.choiceLimits012 "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `candidate\n (Lean.Expr.const `CoreReader.Choice.Candidate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Iff [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Feasible [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Choice.implementation []) (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Choice.Candidate.identity [])))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.const `CoreReader.Choice.objectiveReason []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.conventional [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.established [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.status [])\n (Lean.Expr.const `CoreReader.Choice.StatusKind.convention [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.output [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 []))\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Feasible [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Feasible [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.explanation []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.explanation [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.const `CoreReader.Choice.objectiveReason [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.successorImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `x\n (Lean.Expr.const `Nat [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.changedOutsideZero []))\n (Lean.Expr.bvar 1)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.changedOutsideZero []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulated [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.priorityArticulation [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.AssessmentAccurate [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `selected\n (Lean.Expr.const `CoreReader.Choice.Candidate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Models [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.statusFacts []))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.priorityClaim [])\n (Lean.Expr.const `CoreReader.Choice.Candidate.identity [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.priorityClaim [])\n (Lean.Expr.const `CoreReader.Choice.Candidate.successor []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Entails [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.statusFacts []))\n (Lean.Expr.const `CoreReader.Choice.priorityClaim []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.status [])\n (Lean.Expr.const `CoreReader.Choice.StatusKind.standing [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))))))))\n (Lean.Expr.const `CoreReader.Choice.PolicyIndependenceExample []))))))" +CoreReader.Engineering.inheritedMutualApplication (ctx : CoreReader.Engineering.Context) + (chosen : CoreReader.Engineering.Candidate) (inherited : CoreReader.Engineering.Inherited ctx chosen) : + CoreReader.Adopted.generationSpecification CoreReader.Engineering.engineeringPolicy ∧ + CoreReader.Adopted.reflexivitySpecification (CoreReader.Engineering.selfModel chosen).rules + (CoreReader.Engineering.selfModel chosen).self (CoreReader.Engineering.selfModel chosen).performed ∧ + (∀ (principle : CoreReader.Engineering.CoreCommitment), + CoreReader.Adopted.valueSpecification (CoreReader.Engineering.governancePosition principle)) ∧ + CoreReader.Adopted.capabilitySpecification (CoreReader.Engineering.engineeringProcess chosen) + (CoreReader.Engineering.engineeringCapability chosen) ∧ + CoreReader.Adopted.choiceSpecification CoreReader.Engineering.chosenRequirements + (CoreReader.Engineering.chosenImplementation chosen) CoreReader.Engineering.chosenReasons ∧ + (∀ (fact : CoreReader.Engineering.OwnFact), + CoreReader.Adopted.inferentialSpecification (CoreReader.Engineering.ownFactPremises chosen) + (CoreReader.Engineering.ownFactClaim chosen fact)) ∧ + (∀ (norm : CoreReader.Engineering.OwnNorm), + CoreReader.Engineering.normApplies chosen norm → + CoreReader.Engineering.ownTheory chosen (CoreReader.Engineering.ownNormClaim chosen norm)) ∧ + (∀ (claim : CoreReader.Logic.Claim CoreReader.Engineering.Candidate), + CoreReader.Engineering.ownTheory chosen claim → + CoreReader.Adopted.inferentialSpecification (CoreReader.Engineering.ownFactPremises chosen) + claim) ∧ + CoreReader.Adopted.consistencySpecification + (CoreReader.Engineering.engineeringSnapshot CoreReader.Engineering.Candidate.evolvable 0) + (CoreReader.Engineering.engineeringSnapshot chosen 1) true +'CoreReader.Engineering.inheritedMutualApplication' depends on axioms: [propext] +ORGANON_TYPE CoreReader.Engineering.inheritedMutualApplication "Lean.Expr.forallE\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.forallE\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.forallE\n `inherited\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.Inherited []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.generationSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.engineeringPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.reflexivitySpecification [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Outcome [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.rules [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 1))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.self [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 1))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.performed [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `principle\n (Lean.Expr.const `CoreReader.Engineering.CoreCommitment [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.valueSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.governancePosition []) (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.engineeringProcess []) (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringCapability [])\n (Lean.Expr.bvar 1))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.choiceSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.chosenRequirements []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.chosenImplementation [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.const `CoreReader.Engineering.chosenReasons [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `fact\n (Lean.Expr.const `CoreReader.Engineering.OwnFact [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.inferentialSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownFactPremises [])\n (Lean.Expr.bvar 2)))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.ownFactClaim []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `norm\n (Lean.Expr.const `CoreReader.Engineering.OwnNorm [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.normApplies []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.ownTheory []) (Lean.Expr.bvar 3))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownNormClaim [])\n (Lean.Expr.bvar 3))\n (Lean.Expr.bvar 1)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `claim\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Claim [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.ownTheory []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.inferentialSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownFactPremises [])\n (Lean.Expr.bvar 3)))\n (Lean.Expr.bvar 1))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.consistencySpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `CoreReader.Engineering.OwnFact []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringSnapshot [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringSnapshot [])\n (Lean.Expr.bvar 1))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.const `Bool.true []))))))))))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)" +CoreReader.Engineering.inheritedMutualCases : + CoreReader.Engineering.Inherited CoreReader.Engineering.sharedContext CoreReader.Engineering.Candidate.evolvable ∧ + CoreReader.Adopted.valueSpecification + (CoreReader.Engineering.governancePosition CoreReader.Engineering.CoreCommitment.grounds) ∧ + CoreReader.Adopted.capabilitySpecification + (CoreReader.Engineering.engineeringProcess CoreReader.Engineering.Candidate.evolvable) + (CoreReader.Engineering.engineeringCapability CoreReader.Engineering.Candidate.evolvable) ∧ + CoreReader.Adopted.choiceSpecification CoreReader.Engineering.chosenRequirements + (CoreReader.Engineering.chosenImplementation CoreReader.Engineering.Candidate.evolvable) + CoreReader.Engineering.chosenReasons ∧ + CoreReader.Engineering.Reflection.evaluate + ((CoreReader.Engineering.selfModel CoreReader.Engineering.Candidate.evolvable).input + { owner := 0, object := CoreReader.Engineering.ReviewObject.evolutionMethod, + phase := CoreReader.Agency.Phase.revision }) = + CoreReader.Engineering.Reflection.Verdict.counterexample ∧ + CoreReader.Engineering.ReviewObject.generationRule ∈ + (CoreReader.Engineering.selfModel CoreReader.Engineering.Candidate.evolvable).objects ∧ + CoreReader.Engineering.ReviewObject.assessmentRule ∈ + (CoreReader.Engineering.selfModel CoreReader.Engineering.Candidate.evolvable).objects ∧ + CoreReader.Engineering.Reflection.evaluate + ((CoreReader.Engineering.selfModel CoreReader.Engineering.Candidate.evolvable).input + { owner := 0, object := CoreReader.Engineering.ReviewObject.assessmentRule, + phase := CoreReader.Agency.Phase.revision }) = + CoreReader.Engineering.Reflection.Verdict.counterexample +'CoreReader.Engineering.inheritedMutualCases' depends on axioms: [propext, Classical.choice, Quot.sound] +ORGANON_TYPE CoreReader.Engineering.inheritedMutualCases "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Inherited [])\n (Lean.Expr.const `CoreReader.Engineering.sharedContext []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.valueSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.governancePosition [])\n (Lean.Expr.const `CoreReader.Engineering.CoreCommitment.grounds []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringProcess [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringCapability [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.choiceSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.chosenRequirements []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.chosenImplementation [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.const `CoreReader.Engineering.chosenReasons [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.evaluate [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.evolutionMethod []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision [])))))\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict.counterexample [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.objects [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.generationRule [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.objects [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.assessmentRule [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.evaluate [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.assessmentRule []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision [])))))\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict.counterexample []))))))))" +CoreReader.Engineering.ActivityScope (a : CoreReader.Engineering.Activity) : Prop +'CoreReader.Engineering.ActivityScope' does not depend on any axioms +ORGANON_TYPE CoreReader.Engineering.ActivityScope "Lean.Expr.forallE\n `a\n (Lean.Expr.const `CoreReader.Engineering.Activity [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default)" +CoreReader.Engineering.subjectLifecycleCases : + CoreReader.Engineering.ActivityScope CoreReader.Engineering.continuingActivity ∧ + CoreReader.Engineering.CanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.evolvable CoreReader.Engineering.Maintainer.successor + CoreReader.Engineering.Change.designRevision ∧ + CoreReader.Engineering.CanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.evolvable CoreReader.Engineering.Maintainer.agent + CoreReader.Engineering.Change.designRevision ∧ + CoreReader.Engineering.continuingActivity.label = "temporary" ∧ + CoreReader.Engineering.Continuing CoreReader.Engineering.continuingActivity ∧ + ¬CoreReader.Engineering.BoundedLifecycle CoreReader.Engineering.continuingActivity ∧ + CoreReader.Engineering.BoundedLifecycle CoreReader.Engineering.temporaryActivity ∧ + CoreReader.Engineering.BoundedLifecycle CoreReader.Engineering.prototypeActivity ∧ + CoreReader.Engineering.BoundedLifecycle CoreReader.Engineering.retiringActivity +'CoreReader.Engineering.subjectLifecycleCases' depends on axioms: [propext] +ORGANON_TYPE CoreReader.Engineering.subjectLifecycleCases "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ActivityScope [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `String []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.label [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.lit (Lean.Literal.strVal \"temporary\"))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Continuing [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.const `CoreReader.Engineering.temporaryActivity [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.const `CoreReader.Engineering.prototypeActivity [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.const `CoreReader.Engineering.retiringActivity [])))))))))" +CoreReader.Engineering.subjectLimits : + CoreReader.Engineering.CanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.presentSimple CoreReader.Engineering.Maintainer.original + CoreReader.Engineering.Change.designRevision ∧ + ¬CoreReader.Engineering.CanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.presentSimple CoreReader.Engineering.Maintainer.successor + CoreReader.Engineering.Change.designRevision ∧ + ¬CoreReader.Engineering.ContinuingCapability CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.presentSimple CoreReader.Engineering.Change.designRevision ∧ + CoreReader.Engineering.continuingActivity.label = "temporary" ∧ + ¬CoreReader.Engineering.BoundedLifecycle CoreReader.Engineering.continuingActivity ∧ + CoreReader.Engineering.orientation CoreReader.Engineering.Maintainer.agent ≠ [] ∧ + CoreReader.Engineering.passiveArtifact [2, 1] = [2, 1] ∧ + CoreReader.Engineering.EngineeringAction.propose CoreReader.Engineering.Change.designRevision ∈ + CoreReader.Engineering.maintainerActions CoreReader.Engineering.Maintainer.agent ∧ + ¬CoreReader.Engineering.EngineeringAction.propose CoreReader.Engineering.Change.designRevision ∈ + CoreReader.Engineering.artifactActions [2, 1] +'CoreReader.Engineering.subjectLimits' depends on axioms: [propext] +ORGANON_TYPE CoreReader.Engineering.subjectLimits "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.original []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContinuingCapability [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `String []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.label [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.lit (Lean.Literal.strVal \"temporary\"))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.orientation [])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.passiveArtifact [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.maintainerActions [])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction.propose [])\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.artifactActions [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction.propose [])\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))))))))))" +CoreReader.Engineering.EvolutionPriority (ctx : CoreReader.Engineering.Context) + (chosen : CoreReader.Engineering.Candidate) : Prop +'CoreReader.Engineering.EvolutionPriority' does not depend on any axioms +ORGANON_TYPE CoreReader.Engineering.EvolutionPriority "Lean.Expr.forallE\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.forallE\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)" +CoreReader.Engineering.priorityConditionsCases : + CoreReader.Engineering.EvolutionPriority CoreReader.Engineering.currentContinuing + CoreReader.Engineering.Candidate.evolvable ∧ + ¬CoreReader.Engineering.Meets CoreReader.Engineering.normalRequirements + (have __src := CoreReader.Engineering.profile CoreReader.Engineering.Candidate.evolvable; + { orderOutput := [1, 2], unsafeOperations := __src.unsafeOperations, latency := __src.latency, + retention := __src.retention }) ∧ + ¬CoreReader.Engineering.Meets CoreReader.Engineering.normalRequirements + (have __src := CoreReader.Engineering.profile CoreReader.Engineering.Candidate.evolvable; + { orderOutput := __src.orderOutput, unsafeOperations := 1, latency := __src.latency, + retention := __src.retention }) ∧ + ¬CoreReader.Engineering.Meets CoreReader.Engineering.normalRequirements + (have __src := CoreReader.Engineering.profile CoreReader.Engineering.Candidate.evolvable; + { orderOutput := __src.orderOutput, unsafeOperations := __src.unsafeOperations, latency := 11, + retention := __src.retention }) ∧ + ¬CoreReader.Engineering.Meets CoreReader.Engineering.normalRequirements + (have __src := CoreReader.Engineering.profile CoreReader.Engineering.Candidate.evolvable; + { orderOutput := __src.orderOutput, unsafeOperations := __src.unsafeOperations, + latency := __src.latency, retention := 29 }) ∧ + CoreReader.Engineering.EvolutionPriority + (CoreReader.Engineering.threatened CoreReader.Engineering.Burden.verification) + CoreReader.Engineering.Candidate.presentSimple ∧ + ¬CoreReader.Engineering.JustifiedDeparture + (have __src := CoreReader.Engineering.threatened CoreReader.Engineering.Burden.verification; + { activity := __src.activity, required := __src.required, evidence := __src.evidence, + limits := __src.limits, departure := none, profiles := __src.profiles }) + CoreReader.Engineering.Candidate.evolvable ∧ + CoreReader.Engineering.abstractionComplexity CoreReader.Engineering.Candidate.evolvable < + CoreReader.Engineering.abstractionComplexity CoreReader.Engineering.Candidate.maximal +'CoreReader.Engineering.priorityConditionsCases' depends on axioms: [propext] +ORGANON_TYPE CoreReader.Engineering.priorityConditionsCases "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.const `CoreReader.Engineering.normalRequirements []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2249646945) \"_hygCtx\") \"_hyg\") 19)\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.profile [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.unsafeOperations [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.latency [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.retention [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.const `CoreReader.Engineering.normalRequirements []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2249646945) \"_hygCtx\") \"_hyg\") 45)\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.profile [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.orderOutput [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.latency [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.retention [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.const `CoreReader.Engineering.normalRequirements []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2249646945) \"_hygCtx\") \"_hyg\") 65)\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.profile [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.orderOutput [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.unsafeOperations [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 11)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 11)))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.retention [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.const `CoreReader.Engineering.normalRequirements []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2249646945) \"_hygCtx\") \"_hyg\") 85)\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.profile [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.orderOutput [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.unsafeOperations [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.latency [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 29)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 29)))))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.verification [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2249646945) \"_hygCtx\") \"_hyg\") 113)\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.verification []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.required [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.evidence [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.limits [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Burden [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.profiles [])\n (Lean.Expr.bvar 0)))\n true))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.maximal [])))))))))" +CoreReader.Engineering.priorityWhenApplicable (ctx : CoreReader.Engineering.Context) + (chosen : CoreReader.Engineering.Candidate) (rule : CoreReader.Engineering.EvolutionPriority ctx chosen) + (applicable : CoreReader.Engineering.PriorityConditions ctx) + (noDeparture : ¬CoreReader.Engineering.JustifiedDeparture ctx CoreReader.Engineering.Candidate.evolvable) : + chosen = CoreReader.Engineering.Candidate.evolvable ∧ + CoreReader.Engineering.abstractionComplexity CoreReader.Engineering.Candidate.presentSimple < + CoreReader.Engineering.abstractionComplexity chosen +'CoreReader.Engineering.priorityWhenApplicable' does not depend on any axioms +ORGANON_TYPE CoreReader.Engineering.priorityWhenApplicable "Lean.Expr.forallE\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.forallE\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.forallE\n `rule\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `applicable\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.PriorityConditions []) (Lean.Expr.bvar 2))\n (Lean.Expr.forallE\n `noDeparture\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture []) (Lean.Expr.bvar 3))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.bvar 3))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity []) (Lean.Expr.bvar 3))))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)" +CoreReader.Engineering.priorityChoices : + CoreReader.Engineering.EvolutionPriority CoreReader.Engineering.currentContinuing + CoreReader.Engineering.Candidate.evolvable ∧ + ¬CoreReader.Engineering.EvolutionPriority CoreReader.Engineering.currentContinuing + CoreReader.Engineering.Candidate.presentSimple ∧ + CoreReader.Engineering.EvolutionPriority + (CoreReader.Engineering.threatened CoreReader.Engineering.Burden.verification) + CoreReader.Engineering.Candidate.presentSimple +'CoreReader.Engineering.priorityChoices' depends on axioms: [propext] +ORGANON_TYPE CoreReader.Engineering.priorityChoices "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.verification [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple [])))" +CoreReader.Engineering.CredibleDirection {Ground : Type} (grounds : List Ground) (articulated : Ground → Bool) + (supports : Ground → CoreReader.Engineering.Change → Bool) (d : CoreReader.Engineering.Change) : Prop +'CoreReader.Engineering.CredibleDirection' does not depend on any axioms +ORGANON_TYPE CoreReader.Engineering.CredibleDirection "Lean.Expr.forallE\n `Ground\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `grounds\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `articulated\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 1)\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `supports\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 2)\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Engineering.Change [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `d\n (Lean.Expr.const `CoreReader.Engineering.Change [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)" +CoreReader.Engineering.credibilityCases : + CoreReader.Engineering.credible CoreReader.Engineering.initialGrounds CoreReader.Engineering.Change.designRevision ∧ + CoreReader.Engineering.credible + [CoreReader.Engineering.DirectionGround.knowledge "queue" [CoreReader.Engineering.Change.designRevision] + "tenant-config-reload"] + CoreReader.Engineering.Change.designRevision ∧ + CoreReader.Engineering.credible + [CoreReader.Engineering.DirectionGround.history "queue" + [CoreReader.Engineering.Change.migration, CoreReader.Engineering.Change.migration]] + CoreReader.Engineering.Change.migration ∧ + ¬CoreReader.Engineering.credible [] (CoreReader.Engineering.Change.other "quantum backend") ∧ + CoreReader.Engineering.credible CoreReader.Engineering.forecastGrounds + CoreReader.Engineering.Change.deletion ∧ + ¬CoreReader.Engineering.credible CoreReader.Engineering.forecastGrounds + CoreReader.Engineering.Change.designRevision +'CoreReader.Engineering.credibilityCases' does not depend on any axioms +ORGANON_TYPE CoreReader.Engineering.credibilityCases "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.initialGrounds []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround.knowledge [])\n (Lean.Expr.lit (Lean.Literal.strVal \"queue\")))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))))\n (Lean.Expr.lit (Lean.Literal.strVal \"tenant-config-reload\"))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround []))))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround.history [])\n (Lean.Expr.lit (Lean.Literal.strVal \"queue\")))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.const `CoreReader.Engineering.Change.migration []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.const `CoreReader.Engineering.Change.migration []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround []))))\n (Lean.Expr.const `CoreReader.Engineering.Change.migration [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"quantum backend\"))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.forecastGrounds []))\n (Lean.Expr.const `CoreReader.Engineering.Change.deletion [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.forecastGrounds []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))))))" +CoreReader.Engineering.credibilityLimits : + CoreReader.Engineering.credible CoreReader.Engineering.initialGrounds CoreReader.Engineering.Change.designRevision ∧ + CoreReader.Engineering.implementedVariants.length = 1 ∧ + ¬CoreReader.Engineering.WarrantedAccommodation [] (CoreReader.Engineering.Change.other "quantum backend") 0 5 ∧ + ¬CoreReader.Engineering.credible CoreReader.Engineering.initialGrounds + (CoreReader.Engineering.Change.other "quantum backend") ∧ + CoreReader.Engineering.EvolutionPriority CoreReader.Engineering.currentContinuing + CoreReader.Engineering.Candidate.evolvable ∧ + CoreReader.Engineering.abstractionComplexity CoreReader.Engineering.Candidate.evolvable < + CoreReader.Engineering.abstractionComplexity CoreReader.Engineering.Candidate.maximal ∧ + CoreReader.Engineering.cost CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Burden.construction < + CoreReader.Engineering.cost CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Burden.migration ∧ + ¬CoreReader.Engineering.MaximumRegisteredCapability CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.evolvable ∧ + CoreReader.Engineering.MaximumRegisteredCapability CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.maximal ∧ + (CoreReader.Engineering.supportedDirections CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.evolvable).length = + 9 ∧ + (CoreReader.Engineering.supportedDirections CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.maximal).length = + 10 ∧ + ¬CoreReader.Engineering.credible CoreReader.Engineering.initialGrounds + (CoreReader.Engineering.Change.other "csv export") +'CoreReader.Engineering.credibilityLimits' depends on axioms: [propext] +ORGANON_TYPE CoreReader.Engineering.credibilityLimits "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.initialGrounds []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `CoreReader.Engineering.implementedVariants [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.WarrantedAccommodation [])\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"quantum backend\"))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.initialGrounds []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"quantum backend\"))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.maximal []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.cost [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Burden.construction [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.cost [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Burden.migration []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.MaximumRegisteredCapability [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.MaximumRegisteredCapability [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.maximal [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.supportedDirections [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 9)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 9))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.supportedDirections [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.maximal []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 10))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.initialGrounds []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"csv export\")))))))))))))))" +CoreReader.Engineering.JustifiedDeparture (ctx : CoreReader.Engineering.Context) + (c : CoreReader.Engineering.Candidate) : Prop +'CoreReader.Engineering.JustifiedDeparture' does not depend on any axioms +ORGANON_TYPE CoreReader.Engineering.JustifiedDeparture "Lean.Expr.forallE\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.forallE\n `c\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)" +CoreReader.Engineering.costCases : + CoreReader.Engineering.JustifiedDeparture + (CoreReader.Engineering.threatened CoreReader.Engineering.Burden.understanding) + CoreReader.Engineering.Candidate.evolvable ∧ + CoreReader.Engineering.JustifiedDeparture + (CoreReader.Engineering.threatened CoreReader.Engineering.Burden.construction) + CoreReader.Engineering.Candidate.evolvable ∧ + CoreReader.Engineering.JustifiedDeparture + (CoreReader.Engineering.threatened CoreReader.Engineering.Burden.diagnosis) + CoreReader.Engineering.Candidate.evolvable ∧ + CoreReader.Engineering.JustifiedDeparture + (CoreReader.Engineering.threatened CoreReader.Engineering.Burden.verification) + CoreReader.Engineering.Candidate.evolvable ∧ + CoreReader.Engineering.JustifiedDeparture + (CoreReader.Engineering.threatened CoreReader.Engineering.Burden.coordination) + CoreReader.Engineering.Candidate.evolvable ∧ + CoreReader.Engineering.JustifiedDeparture + (CoreReader.Engineering.threatened CoreReader.Engineering.Burden.operation) + CoreReader.Engineering.Candidate.evolvable ∧ + CoreReader.Engineering.JustifiedDeparture + (CoreReader.Engineering.threatened CoreReader.Engineering.Burden.migration) + CoreReader.Engineering.Candidate.evolvable ∧ + ¬CoreReader.Engineering.JustifiedDeparture + (have __src := CoreReader.Engineering.currentContinuing; + { activity := __src.activity, required := __src.required, evidence := __src.evidence, + limits := __src.limits, departure := some CoreReader.Engineering.Burden.migration, + profiles := __src.profiles }) + CoreReader.Engineering.Candidate.evolvable +'CoreReader.Engineering.costCases' depends on axioms: [propext] +ORGANON_TYPE CoreReader.Engineering.costCases "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.understanding [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.construction [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.diagnosis [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.verification [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.coordination [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.operation [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.migration [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 797674858) \"_hygCtx\") \"_hyg\") 72)\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.required [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.evidence [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.limits [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Option.some [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Burden []))\n (Lean.Expr.const `CoreReader.Engineering.Burden.migration [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.profiles [])\n (Lean.Expr.bvar 0)))\n true))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))))))))" +CoreReader.Engineering.EvolutionClaim (a : CoreReader.Engineering.Activity) (c : CoreReader.Engineering.Candidate) + (claim : CoreReader.Engineering.ChangeClaim) : Prop +'CoreReader.Engineering.EvolutionClaim' does not depend on any axioms +ORGANON_TYPE CoreReader.Engineering.EvolutionClaim "Lean.Expr.forallE\n `a\n (Lean.Expr.const `CoreReader.Engineering.Activity [])\n (Lean.Expr.forallE\n `c\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.forallE\n `claim\n (Lean.Expr.const `CoreReader.Engineering.ChangeClaim [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)" +CoreReader.Engineering.evolutionKindsCases : + (CoreReader.Engineering.transform CoreReader.Engineering.Change.addition + CoreReader.Engineering.originalSoftware).capabilities = + ["deduplicate", "tenant batching"] ∧ + (CoreReader.Engineering.transform CoreReader.Engineering.Change.replacement + CoreReader.Engineering.originalSoftware).implementation = + 1 ∧ + (CoreReader.Engineering.transform CoreReader.Engineering.Change.deletion + CoreReader.Engineering.originalSoftware).mechanisms = + ["queue"] ∧ + (CoreReader.Engineering.transform CoreReader.Engineering.Change.withdrawal + CoreReader.Engineering.originalSoftware).abstractions = + [] ∧ + (CoreReader.Engineering.transform CoreReader.Engineering.Change.redrawing + CoreReader.Engineering.originalSoftware).boundary = + 1 ∧ + (CoreReader.Engineering.transform CoreReader.Engineering.Change.migration + CoreReader.Engineering.originalSoftware).technology = + "portable store" ∧ + (CoreReader.Engineering.changes.all fun d => + decide + (CoreReader.Engineering.CanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.evolvable CoreReader.Engineering.Maintainer.successor d)) = + true ∧ + CoreReader.Engineering.EvolutionClaim CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.evolvable + { direction := CoreReader.Engineering.Change.replacement, + byMaintainer := CoreReader.Engineering.Maintainer.successor, + treatment := CoreReader.Engineering.ObligationTreatment.preserve } ∧ + CoreReader.Engineering.EvolutionClaim CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.evolvable + { direction := CoreReader.Engineering.Change.redrawing, + byMaintainer := CoreReader.Engineering.Maintainer.agent, + treatment := CoreReader.Engineering.ObligationTreatment.revise } ∧ + CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.independent < + CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.coordinated +'CoreReader.Engineering.evolutionKindsCases' depends on axioms: [propext] +ORGANON_TYPE CoreReader.Engineering.evolutionKindsCases "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.capabilities [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.addition []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"deduplicate\")))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"tenant batching\")))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `String []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.implementation [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.replacement []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.mechanisms [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.deletion []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"queue\")))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `String [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.abstractions [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.withdrawal []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `String []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.boundary [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.redrawing []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `String []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.technology [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.migration []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.lit (Lean.Literal.strVal \"portable store\"))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.all [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.const `CoreReader.Engineering.changes []))\n (Lean.Expr.lam\n `d\n (Lean.Expr.const `CoreReader.Engineering.Change [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Decidable.decide [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instDecidableAnd [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.participants [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.all [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.lam\n `step\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Bool.and [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.const\n `CoreReader.Engineering.instDecidableEqKnowledge\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.available [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.requires [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqTool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.tools [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.tool [])\n (Lean.Expr.bvar 0))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instDecidableNot [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.instDecidableEqNil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instDecidableAnd [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.participants [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.all [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.lam\n `step\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Bool.and [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.const\n `CoreReader.Engineering.instDecidableEqKnowledge\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.available [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.requires [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqTool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.tools [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.tool [])\n (Lean.Expr.bvar 0))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.instDecidableMemOfLawfulBEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqMaintainer [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instLawfulBEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqMaintainer [])))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.participants [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instDecidableEqBool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.all [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.lam\n `step\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Bool.and [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.const\n `CoreReader.Engineering.instDecidableEqKnowledge\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.available [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.requires [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqTool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.tools [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.tool [])\n (Lean.Expr.bvar 0))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionClaim [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ChangeClaim.mk [])\n (Lean.Expr.const `CoreReader.Engineering.Change.replacement []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.ObligationTreatment.preserve []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionClaim [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ChangeClaim.mk [])\n (Lean.Expr.const `CoreReader.Engineering.Change.redrawing []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent []))\n (Lean.Expr.const `CoreReader.Engineering.ObligationTreatment.revise []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.independent [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated [])))))))))))" +CoreReader.Engineering.evolutionDimensionsLimits : + CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.presentSimple + CoreReader.Engineering.Change.addition = + 2 ∧ + CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.presentSimple + CoreReader.Engineering.Change.withdrawal = + 17 ∧ + CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.independent < + CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.coordinated ∧ + CoreReader.Engineering.EvolutionPriority CoreReader.Engineering.currentContinuing + CoreReader.Engineering.Candidate.evolvable ∧ + 9 < + CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.migration ∧ + CoreReader.Engineering.CanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.presentSimple CoreReader.Engineering.Maintainer.original + CoreReader.Engineering.Change.addition ∧ + CoreReader.Engineering.CanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.evolvable CoreReader.Engineering.Maintainer.original + CoreReader.Engineering.Change.addition ∧ + CoreReader.Engineering.CanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.presentSimple CoreReader.Engineering.Maintainer.original + CoreReader.Engineering.Change.designRevision ∧ + CoreReader.Engineering.CanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.evolvable CoreReader.Engineering.Maintainer.original + CoreReader.Engineering.Change.designRevision ∧ + CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.designRevision < + CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.presentSimple + CoreReader.Engineering.Change.designRevision ∧ + CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.addition = + CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.presentSimple + CoreReader.Engineering.Change.addition ∧ + (CoreReader.Engineering.transform (CoreReader.Engineering.Change.other "csv export") + CoreReader.Engineering.originalSoftware).capabilities = + ["deduplicate", "csv export"] ∧ + CoreReader.Engineering.CanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.maximal CoreReader.Engineering.Maintainer.successor + (CoreReader.Engineering.Change.other "csv export") ∧ + ¬CoreReader.Engineering.CanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.evolvable CoreReader.Engineering.Maintainer.successor + (CoreReader.Engineering.Change.other "csv export") +'CoreReader.Engineering.evolutionDimensionsLimits' depends on axioms: [propext] +ORGANON_TYPE CoreReader.Engineering.evolutionDimensionsLimits "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.addition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.withdrawal [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 17)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 17))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.independent [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 9)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 9)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.migration []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.original []))\n (Lean.Expr.const `CoreReader.Engineering.Change.addition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.original []))\n (Lean.Expr.const `CoreReader.Engineering.Change.addition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.original []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.original []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.addition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.addition []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.capabilities [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"csv export\"))))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"deduplicate\")))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"csv export\")))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `String []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.maximal []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"csv export\")))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"csv export\")))))))))))))))))" +CoreReader.Engineering.StructuralAccount (a : CoreReader.Engineering.Activity) (c : CoreReader.Engineering.Candidate) + (e : CoreReader.Engineering.StructuralEvidence) : Prop +'CoreReader.Engineering.StructuralAccount' does not depend on any axioms +ORGANON_TYPE CoreReader.Engineering.StructuralAccount "Lean.Expr.forallE\n `a\n (Lean.Expr.const `CoreReader.Engineering.Activity [])\n (Lean.Expr.forallE\n `c\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.forallE\n `e\n (Lean.Expr.const `CoreReader.Engineering.StructuralEvidence [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)" +CoreReader.Engineering.structuralCases : + CoreReader.Engineering.StructuralAccount CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.evolvable + (CoreReader.Engineering.structuralEvidence CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.designRevision) ∧ + (CoreReader.Engineering.propagation CoreReader.Engineering.Candidate.presentSimple + CoreReader.Engineering.Change.designRevision).length = + 3 ∧ + (CoreReader.Engineering.propagation CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.designRevision).length = + 2 ∧ + ((CoreReader.Engineering.changePath CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.coordinated).any + fun s => s.component == 2 && s.requires == CoreReader.Engineering.Knowledge.publicContract) = + true ∧ + CoreReader.Engineering.PreservesFinite CoreReader.Engineering.orderedUnique + CoreReader.Engineering.orderedRefactor ∧ + (CoreReader.Engineering.structuralEvidence CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.designRevision).observedBefore ≠ + (CoreReader.Engineering.structuralEvidence CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.designRevision).observedAfter ∧ + CoreReader.Engineering.staticBatch 21 10 = CoreReader.Engineering.liveBatch 21 10 ∧ + CoreReader.Engineering.staticBatch 21 5 ≠ CoreReader.Engineering.liveBatch 21 5 ∧ + CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.presentSimple + CoreReader.Engineering.Change.withdrawal = + 17 ∧ + CoreReader.Engineering.crossesBoundary CoreReader.Engineering.boundaryDesign + CoreReader.Engineering.Change.coordinated CoreReader.Engineering.coordinatedBoundary = + true ∧ + CoreReader.Engineering.boundaryObligationChecked CoreReader.Engineering.boundaryDesign + CoreReader.Engineering.Change.coordinated CoreReader.Engineering.coordinatedBoundary = + true ∧ + CoreReader.Engineering.crossesBoundary CoreReader.Engineering.omittedCallerCheck + CoreReader.Engineering.Change.coordinated CoreReader.Engineering.coordinatedBoundary = + true ∧ + CoreReader.Engineering.boundaryObligationChecked CoreReader.Engineering.omittedCallerCheck + CoreReader.Engineering.Change.coordinated CoreReader.Engineering.coordinatedBoundary = + false ∧ + CoreReader.Engineering.crossesBoundary CoreReader.Engineering.otherCalleeDesign + CoreReader.Engineering.Change.coordinated CoreReader.Engineering.otherCalleeBoundary = + false ∧ + CoreReader.Engineering.boundaryObligationChecked + (have __src := CoreReader.Engineering.boundaryDesign; + { metadata := __src.metadata, run := CoreReader.Engineering.sortedUnique, + paths := __src.paths, components := __src.components, + boundaries := __src.boundaries, batchAssumptions := __src.batchAssumptions }) + CoreReader.Engineering.Change.coordinated CoreReader.Engineering.coordinatedBoundary = + false +'CoreReader.Engineering.structuralCases' depends on axioms: [propext] +ORGANON_TYPE CoreReader.Engineering.structuralCases "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.StructuralAccount [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.structuralEvidence [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.propagation [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.propagation [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.any [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated [])))\n (Lean.Expr.lam\n `s\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Bool.and [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `BEq.beq [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instDecidableEqNat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.component [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `BEq.beq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqKnowledge [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.requires [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `CoreReader.Engineering.Knowledge.publicContract [])))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.orderedRefactor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.StructuralEvidence.observedBefore [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.structuralEvidence [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.StructuralEvidence.observedAfter [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.structuralEvidence [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.staticBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 10))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 10)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.staticBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.withdrawal [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 17)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 17))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.crossesBoundary [])\n (Lean.Expr.const `CoreReader.Engineering.boundaryDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.coordinatedBoundary [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.boundaryObligationChecked [])\n (Lean.Expr.const `CoreReader.Engineering.boundaryDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.coordinatedBoundary [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.crossesBoundary [])\n (Lean.Expr.const `CoreReader.Engineering.omittedCallerCheck []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.coordinatedBoundary [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.boundaryObligationChecked [])\n (Lean.Expr.const `CoreReader.Engineering.omittedCallerCheck []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.coordinatedBoundary [])))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.crossesBoundary [])\n (Lean.Expr.const `CoreReader.Engineering.otherCalleeDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.otherCalleeBoundary [])))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.boundaryObligationChecked [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 1550649743) \"_hygCtx\") \"_hyg\") 194)\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign [])\n (Lean.Expr.const `CoreReader.Engineering.boundaryDesign [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.mk [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Engineering.EngineeringDesign.metadata\n [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `CoreReader.Engineering.sortedUnique []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.paths [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Engineering.EngineeringDesign.components\n [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.boundaries [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Engineering.EngineeringDesign.batchAssumptions\n [])\n (Lean.Expr.bvar 0)))\n true))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.coordinatedBoundary [])))\n (Lean.Expr.const `Bool.false [])))))))))))))))" +CoreReader.Engineering.structureNotCapability : + (CoreReader.Engineering.privateDesign.metadata.signature = CoreReader.Engineering.sortedDesign.metadata.signature ∧ + CoreReader.Engineering.privateDesign.run [2, 1, 2] = [2, 1] ∧ + CoreReader.Engineering.sortedDesign.run [2, 1, 2] ≠ [2, 1]) ∧ + (CoreReader.Engineering.privateDesign.metadata.modules = CoreReader.Engineering.privateDesign.components.length ∧ + CoreReader.Engineering.privateDesign.batchAssumptions.length = 8 ∧ + (CoreReader.Engineering.designModulesNeedingRevision CoreReader.Engineering.privateDesign 5).length = 8) ∧ + (CoreReader.Engineering.privateDesign.metadata.principle = "dependency inversion" ∧ + CoreReader.Engineering.privateDesign.metadata = CoreReader.Engineering.documentedDesign.metadata ∧ + ¬CoreReader.Engineering.DesignCanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.privateDesign CoreReader.Engineering.Maintainer.successor + CoreReader.Engineering.Change.designRevision ∧ + CoreReader.Engineering.DesignCanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.documentedDesign CoreReader.Engineering.Maintainer.successor + CoreReader.Engineering.Change.designRevision) ∧ + (CoreReader.Engineering.privateDesign.boundaries.length = 0 ∧ + CoreReader.Engineering.wrappedDesign.boundaries.length = 1 ∧ + CoreReader.Engineering.wrappedDesign.components.length = 9 ∧ + CoreReader.Engineering.wrappedDesign.boundaries = + [{ caller := 8, callee := 0, contract := "List Nat → List Nat" }] ∧ + CoreReader.Engineering.wrappedDesign.run [2, 1, 2] = + CoreReader.Engineering.privateDesign.run [2, 1, 2] ∧ + CoreReader.Engineering.designWork CoreReader.Engineering.privateDesign + CoreReader.Engineering.Change.designRevision = + 17 ∧ + CoreReader.Engineering.designWork CoreReader.Engineering.wrappedDesign + CoreReader.Engineering.Change.designRevision = + 18 ∧ + ¬CoreReader.Engineering.designWork CoreReader.Engineering.wrappedDesign + CoreReader.Engineering.Change.designRevision < + CoreReader.Engineering.designWork CoreReader.Engineering.privateDesign + CoreReader.Engineering.Change.designRevision) ∧ + CoreReader.Engineering.sameWorkDesign.boundaries = + [{ caller := 8, callee := 0, contract := "List Nat → List Nat" }] ∧ + CoreReader.Engineering.sameWorkDesign.components.length = 9 ∧ + CoreReader.Engineering.sameWorkDesign.paths CoreReader.Engineering.Change.designRevision ≠ + CoreReader.Engineering.privateDesign.paths CoreReader.Engineering.Change.designRevision ∧ + CoreReader.Engineering.sameWorkDesign.run [2, 1, 2] = + CoreReader.Engineering.privateDesign.run [2, 1, 2] ∧ + CoreReader.Engineering.designWork CoreReader.Engineering.sameWorkDesign + CoreReader.Engineering.Change.designRevision = + CoreReader.Engineering.designWork CoreReader.Engineering.privateDesign + CoreReader.Engineering.Change.designRevision ∧ + CoreReader.Engineering.designWork CoreReader.Engineering.sameWorkDesign + CoreReader.Engineering.Change.designRevision = + 17 ∧ + ¬CoreReader.Engineering.DesignCanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.sameWorkDesign CoreReader.Engineering.Maintainer.successor + CoreReader.Engineering.Change.designRevision +'CoreReader.Engineering.structureNotCapability' depends on axioms: [propext] +ORGANON_TYPE CoreReader.Engineering.structureNotCapability "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `String []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.InterfaceView.signature [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.InterfaceView.signature [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.sortedDesign [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.sortedDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.InterfaceView.modules [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.components [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.batchAssumptions [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 8)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 8))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designModulesNeedingRevision [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 8)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 8))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `String []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.InterfaceView.principle [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))))\n (Lean.Expr.lit (Lean.Literal.strVal \"dependency inversion\"))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.InterfaceView []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.documentedDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.DesignCanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.DesignCanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.documentedDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.boundaries [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.boundaries [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.components [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 9)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 9))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.boundaries [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Boundary.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 8)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 8)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.lit (Lean.Literal.strVal \"List Nat → List Nat\"))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 17)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 17))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 18)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 18))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.boundaries [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Boundary.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 8)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 8)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.lit (Lean.Literal.strVal \"List Nat → List Nat\"))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.components [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 9)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 9))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.paths [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.paths [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 17)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 17))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.DesignCanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))))))))))" +CoreReader.Engineering.ContractChangeAccount (old new : CoreReader.Engineering.ObservableContract) + (r : CoreReader.Engineering.ContractRevision) : Prop +'CoreReader.Engineering.ContractChangeAccount' does not depend on any axioms +ORGANON_TYPE CoreReader.Engineering.ContractChangeAccount "Lean.Expr.forallE\n `old\n (Lean.Expr.const `CoreReader.Engineering.ObservableContract [])\n (Lean.Expr.forallE\n `new\n (Lean.Expr.const `CoreReader.Engineering.ObservableContract [])\n (Lean.Expr.forallE\n `r\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)" +CoreReader.Engineering.contractCases : + CoreReader.Engineering.ContractChangeAccount CoreReader.Engineering.originalContract + CoreReader.Engineering.refactoredContract CoreReader.Engineering.normalRevision ∧ + CoreReader.Engineering.ContractChangeAccount CoreReader.Engineering.originalContract + CoreReader.Engineering.revisedContract CoreReader.Engineering.normalRevision ∧ + ¬CoreReader.Engineering.ContractChangeAccount CoreReader.Engineering.originalContract + CoreReader.Engineering.revisedContract + (have __src := CoreReader.Engineering.normalRevision; + { deliberate := __src.deliberate, revisedOrder := __src.revisedOrder, affected := [], + oldFailureLimit := __src.oldFailureLimit, newFailureLimit := __src.newFailureLimit, + recordedOldFailureLimit := __src.recordedOldFailureLimit, + recordedNewFailureLimit := __src.recordedNewFailureLimit, procedure := __src.procedure }) ∧ + CoreReader.Engineering.PreservesFinite CoreReader.Engineering.orderedUnique + CoreReader.Engineering.retiredBehavior ∧ + CoreReader.Engineering.retiredBehavior [99] ≠ CoreReader.Engineering.orderedUnique [99] ∧ + CoreReader.Engineering.ContractChangeAccount CoreReader.Engineering.originalContract + CoreReader.Engineering.revisedContract + (have __src := CoreReader.Engineering.normalRevision; + { deliberate := __src.deliberate, revisedOrder := __src.revisedOrder, affected := __src.affected, + oldFailureLimit := __src.oldFailureLimit, newFailureLimit := __src.newFailureLimit, + recordedOldFailureLimit := __src.recordedOldFailureLimit, + recordedNewFailureLimit := __src.recordedNewFailureLimit, procedure := "paired audit" }) +'CoreReader.Engineering.contractCases' does not depend on any axioms +ORGANON_TYPE CoreReader.Engineering.contractCases "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.refactoredContract []))\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 640854215) \"_hygCtx\") \"_hyg\") 28)\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision [])\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.deliberate [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.revisedOrder [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.oldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.newFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedOldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedNewFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.procedure [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.retiredBehavior [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.retiredBehavior [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 99)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 99)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 99)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 99)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 640854215) \"_hygCtx\") \"_hyg\") 68)\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision [])\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.deliberate [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.revisedOrder [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.affected [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.oldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.newFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedOldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedNewFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.lit (Lean.Literal.strVal \"paired audit\")))\n true))))))" +CoreReader.Engineering.contractPreservation {Input Output : Type} (scope : Input → Prop) (old new : Input → Output) + (observations : ∀ (x : Input), scope x → new x = old x) : CoreReader.Engineering.PreservesOn scope old new +'CoreReader.Engineering.contractPreservation' does not depend on any axioms +ORGANON_TYPE CoreReader.Engineering.contractPreservation "Lean.Expr.forallE\n `Input\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `Output\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `scope\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 1)\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `old\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 2)\n (Lean.Expr.bvar 2)\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `new\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 3)\n (Lean.Expr.bvar 3)\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `observations\n (Lean.Expr.forallE\n `x\n (Lean.Expr.bvar 4)\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app (Lean.Expr.bvar 3) (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.bvar 5))\n (Lean.Expr.app (Lean.Expr.bvar 2) (Lean.Expr.bvar 1)))\n (Lean.Expr.app (Lean.Expr.bvar 3) (Lean.Expr.bvar 1)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.PreservesOn []) (Lean.Expr.bvar 5))\n (Lean.Expr.bvar 4))\n (Lean.Expr.bvar 3))\n (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit))\n (Lean.BinderInfo.implicit)" +CoreReader.Engineering.contractDistinctions : + CoreReader.Engineering.PreservesFinite CoreReader.Engineering.orderedUnique CoreReader.Engineering.orderedRefactor ∧ + ¬CoreReader.Engineering.PreservesFinite CoreReader.Engineering.orderedUnique CoreReader.Engineering.sortedUnique ∧ + CoreReader.Engineering.retry CoreReader.Engineering.originalContract 3 = false ∧ + CoreReader.Engineering.retry CoreReader.Engineering.revisedContract 3 = true ∧ + ¬CoreReader.Engineering.PreservesContractFinite CoreReader.Engineering.originalContract + CoreReader.Engineering.revisedContract ∧ + CoreReader.Engineering.affectedParties CoreReader.Engineering.originalContract + CoreReader.Engineering.revisedContract = + ["queue consumer", "queue operator"] ∧ + ¬CoreReader.Engineering.ContractChangeAccount CoreReader.Engineering.originalContract + CoreReader.Engineering.revisedContract + (have __src := CoreReader.Engineering.normalRevision; + { deliberate := __src.deliberate, revisedOrder := __src.revisedOrder, + affected := ["queue consumer"], oldFailureLimit := __src.oldFailureLimit, + newFailureLimit := __src.newFailureLimit, + recordedOldFailureLimit := __src.recordedOldFailureLimit, + recordedNewFailureLimit := __src.recordedNewFailureLimit, procedure := __src.procedure }) ∧ + ¬CoreReader.Engineering.ContractChangeAccount CoreReader.Engineering.originalContract + CoreReader.Engineering.revisedContract + (have __src := CoreReader.Engineering.normalRevision; + { deliberate := __src.deliberate, revisedOrder := __src.revisedOrder, affected := __src.affected, + oldFailureLimit := 5, newFailureLimit := __src.newFailureLimit, recordedOldFailureLimit := 5, + recordedNewFailureLimit := __src.recordedNewFailureLimit, procedure := __src.procedure }) ∧ + CoreReader.Engineering.ContractChangeAccount CoreReader.Engineering.originalContract + CoreReader.Engineering.revisedContract CoreReader.Engineering.normalRevision ∧ + CoreReader.Engineering.PreservesFinite CoreReader.Engineering.orderedUnique + CoreReader.Engineering.retiredBehavior ∧ + CoreReader.Engineering.retiredBehavior [99] ≠ CoreReader.Engineering.orderedUnique [99] +'CoreReader.Engineering.contractDistinctions' does not depend on any axioms +ORGANON_TYPE CoreReader.Engineering.contractDistinctions "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.orderedRefactor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.sortedUnique []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.retry [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3))))))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.retry [])\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesContractFinite [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.affectedParties [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"queue consumer\")))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"queue operator\")))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `String []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2260969961) \"_hygCtx\") \"_hyg\") 73)\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision [])\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.deliberate [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.revisedOrder [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"queue consumer\")))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `String []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.oldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.newFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedOldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedNewFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.procedure [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2260969961) \"_hygCtx\") \"_hyg\") 97)\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision [])\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.deliberate [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.revisedOrder [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.affected [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 5)))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.newFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 5)))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedNewFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.procedure [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.retiredBehavior [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.retiredBehavior [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 99)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 99)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 99)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 99)))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))))))))))))" +CoreReader.Engineering.RevisionAccount (r : CoreReader.Engineering.RevisionRecord) : Prop +'CoreReader.Engineering.RevisionAccount' does not depend on any axioms +ORGANON_TYPE CoreReader.Engineering.RevisionAccount "Lean.Expr.forallE\n `r\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default)" +CoreReader.Engineering.revisionCases : + CoreReader.Engineering.RevisionAccount CoreReader.Engineering.revisionRecord ∧ + CoreReader.Engineering.revisionRecord.old.forecast ≠ CoreReader.Engineering.revisionRecord.current.forecast ∧ + CoreReader.Engineering.revisionRecord.old.maintenance ≠ + CoreReader.Engineering.revisionRecord.current.maintenance ∧ + CoreReader.Engineering.revisionRecord.old.maintainers ≠ + CoreReader.Engineering.revisionRecord.current.maintainers ∧ + CoreReader.Engineering.revisionRecord.old.migrationCost ≠ + CoreReader.Engineering.revisionRecord.current.migrationCost ∧ + CoreReader.Engineering.revisionRecord.old.objectiveCapacity ≠ + CoreReader.Engineering.revisionRecord.current.objectiveCapacity ∧ + CoreReader.Engineering.revisionRecord.predictedBatchCount ≠ + CoreReader.Engineering.revisionRecord.actualBatchCount ∧ + CoreReader.Engineering.RetentionJustified CoreReader.Engineering.currentContinuing + [CoreReader.Engineering.Change.other "quantum backend"] ∧ + CoreReader.Engineering.RetentionJustified + (CoreReader.Engineering.threatened CoreReader.Engineering.Burden.migration) + [CoreReader.Engineering.Change.migration] +'CoreReader.Engineering.revisionCases' depends on axioms: [propext] +ORGANON_TYPE CoreReader.Engineering.revisionCases "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionAccount [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.forecast [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.forecast [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.maintenance [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.maintenance [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.maintainers [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.maintainers [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.migrationCost [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.migrationCost [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.objectiveCapacity [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.objectiveCapacity [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.predictedBatchCount [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.actualBatchCount [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RetentionJustified [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"quantum backend\"))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RetentionJustified [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.migration [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.const `CoreReader.Engineering.Change.migration []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change [])))))))))))" +CoreReader.Engineering.revisionLimits : + CoreReader.Engineering.RevisionAccount CoreReader.Engineering.revisionRecord ∧ + ¬CoreReader.Engineering.RevisionAccount + (have __src := CoreReader.Engineering.revisionRecord; + { software := __src.software, old := __src.old, current := __src.current, recordedOld := __src.recordedOld, + recordedCurrent := __src.recordedCurrent, predictedBatchCount := __src.predictedBatchCount, + actualBatchCount := __src.actualBatchCount, reportedPredictionSucceeded := true, + consideredChanges := __src.consideredChanges, criticizedDirections := __src.criticizedDirections }) ∧ + CoreReader.Engineering.revisionsMade.length = 3 ∧ + CoreReader.Engineering.agreedBatch CoreReader.Engineering.maintainers 21 5 = [3, 3, 3] ∧ + CoreReader.Engineering.liveBatch 21 5 = 5 ∧ + (CoreReader.Engineering.observations.all fun p => + CoreReader.Engineering.staticBatch p.fst p.snd == CoreReader.Engineering.liveBatch p.fst p.snd) = + true ∧ + CoreReader.Engineering.staticBatch 21 5 ≠ CoreReader.Engineering.liveBatch 21 5 ∧ + CoreReader.Engineering.RevisionAccount CoreReader.Engineering.stableRecord ∧ + CoreReader.Engineering.stableRecord.current.choice = CoreReader.Engineering.stableRecord.old.choice ∧ + CoreReader.Engineering.RetentionJustified CoreReader.Engineering.currentContinuing + [CoreReader.Engineering.Change.other "quantum backend"] +'CoreReader.Engineering.revisionLimits' depends on axioms: [propext] +ORGANON_TYPE CoreReader.Engineering.revisionLimits "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionAccount [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionAccount [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 3857095740) \"_hygCtx\") \"_hyg\") 17)\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.software [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.recordedOld [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.recordedCurrent [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.predictedBatchCount [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.actualBatchCount [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.consideredChanges [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.criticizedDirections [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Engineering.revisionsMade [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.agreedBatch [])\n (Lean.Expr.const `CoreReader.Engineering.maintainers []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.all [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.const `CoreReader.Engineering.observations []))\n (Lean.Expr.lam\n `p\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `BEq.beq [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instDecidableEqNat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.staticBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.fst [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.fst [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.staticBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionAccount [])\n (Lean.Expr.const `CoreReader.Engineering.stableRecord [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.choice [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.stableRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.choice [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.stableRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RetentionJustified [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"quantum backend\"))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))))))))))))" +CoreReader.Engineering.priorityRemainsReflexive (ctx : CoreReader.Engineering.Context) + (chosen : CoreReader.Engineering.Candidate) (inherited : CoreReader.Engineering.Inherited ctx chosen) + (domain : CoreReader.Engineering.DomainSatisfied ctx chosen) + (applicable : CoreReader.Engineering.PriorityConditions ctx) + (noDeparture : ¬CoreReader.Engineering.JustifiedDeparture ctx CoreReader.Engineering.Candidate.evolvable) : + chosen = CoreReader.Engineering.Candidate.evolvable ∧ + CoreReader.Engineering.ReviewObject.priority ∈ (CoreReader.Engineering.selfModel chosen).objects ∧ + CoreReader.Adopted.reflexivitySpecification (CoreReader.Engineering.selfModel chosen).rules + (CoreReader.Engineering.selfModel chosen).self (CoreReader.Engineering.selfModel chosen).performed ∧ + (∀ (principle : CoreReader.Engineering.CoreCommitment), + CoreReader.Adopted.valueSpecification (CoreReader.Engineering.governancePosition principle)) ∧ + CoreReader.Adopted.Grounds012 (CoreReader.Engineering.EvolutionPriority ctx) + CoreReader.Evidence.canonicalArticulation + [CoreReader.Evidence.Facet.value + (CoreReader.Engineering.selectionPosition CoreReader.Engineering.Candidate.evolvable)] + (CoreReader.Adopted.AssessmentTask.value + (CoreReader.Engineering.selectionPosition CoreReader.Engineering.Candidate.evolvable)) ∧ + CoreReader.Engineering.ownTheory chosen + (CoreReader.Engineering.ownNormClaim chosen CoreReader.Engineering.OwnNorm.domain) ∧ + CoreReader.Adopted.consistencySpecification + (CoreReader.Engineering.engineeringSnapshot CoreReader.Engineering.Candidate.evolvable 0) + (CoreReader.Engineering.engineeringSnapshot chosen 1) true +'CoreReader.Engineering.priorityRemainsReflexive' depends on axioms: [propext, Classical.choice, Quot.sound] +ORGANON_TYPE CoreReader.Engineering.priorityRemainsReflexive "Lean.Expr.forallE\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.forallE\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.forallE\n `inherited\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.Inherited []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `domain\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.DomainSatisfied []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.forallE\n `applicable\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.PriorityConditions []) (Lean.Expr.bvar 3))\n (Lean.Expr.forallE\n `noDeparture\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture []) (Lean.Expr.bvar 4))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.bvar 4))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.objects [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 4))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.priority [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.reflexivitySpecification [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Outcome [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.rules [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 4))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.self [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 4))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.performed [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 4)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `principle\n (Lean.Expr.const `CoreReader.Engineering.CoreCommitment [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.valueSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.governancePosition [])\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.bvar 5)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.value [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.AssessmentTask.value [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.ownTheory []) (Lean.Expr.bvar 4))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownNormClaim [])\n (Lean.Expr.bvar 4))\n (Lean.Expr.const `CoreReader.Engineering.OwnNorm.domain []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.consistencySpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `CoreReader.Engineering.OwnFact []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringSnapshot [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringSnapshot [])\n (Lean.Expr.bvar 4))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.const `Bool.true []))))))))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)" +CoreReader.Engineering.priorityReflexiveCases : + CoreReader.Engineering.ReviewObject.priority ∈ + (CoreReader.Engineering.selfModel CoreReader.Engineering.Candidate.evolvable).objects ∧ + CoreReader.Engineering.objectTest CoreReader.Engineering.ReviewObject.priority + (CoreReader.Engineering.Candidate.evolvable, 10) = + true ∧ + (CoreReader.Engineering.selfModel CoreReader.Engineering.Candidate.evolvable).performed + { owner := 0, localId := 1 } + { owner := 0, object := CoreReader.Engineering.ReviewObject.priority, + phase := CoreReader.Agency.Phase.revision } + ((CoreReader.Engineering.selfModel CoreReader.Engineering.Candidate.evolvable).input + { owner := 0, object := CoreReader.Engineering.ReviewObject.priority, + phase := CoreReader.Agency.Phase.revision }) + (CoreReader.Engineering.Reflection.Outcome.assessed + CoreReader.Engineering.Reflection.Verdict.supportedWithinScope) ∧ + CoreReader.Engineering.Reflection.evaluate + ((CoreReader.Engineering.selfModel CoreReader.Engineering.Candidate.evolvable).input + { owner := 0, object := CoreReader.Engineering.ReviewObject.evolutionMethod, + phase := CoreReader.Agency.Phase.revision }) = + CoreReader.Engineering.Reflection.Verdict.counterexample ∧ + CoreReader.Engineering.objectTest CoreReader.Engineering.ReviewObject.evolutionMethod + (CoreReader.Engineering.Candidate.evolvable, 10) = + true ∧ + CoreReader.Engineering.objectTest CoreReader.Engineering.ReviewObject.evolutionMethod + (CoreReader.Engineering.Candidate.evolvable, 5) = + false ∧ + CoreReader.Adopted.Grounds012 + (CoreReader.Engineering.EvolutionPriority CoreReader.Engineering.sharedContext) + CoreReader.Evidence.canonicalArticulation + [CoreReader.Evidence.Facet.value + (CoreReader.Engineering.selectionPosition CoreReader.Engineering.Candidate.evolvable)] + (CoreReader.Adopted.AssessmentTask.value + (CoreReader.Engineering.selectionPosition CoreReader.Engineering.Candidate.evolvable)) ∧ + CoreReader.Engineering.Reflection.evaluate + ((CoreReader.Engineering.selfModel CoreReader.Engineering.Candidate.evolvable).input + { owner := 0, object := CoreReader.Engineering.ReviewObject.assessmentRule, + phase := CoreReader.Agency.Phase.revision }) = + CoreReader.Engineering.Reflection.Verdict.counterexample +'CoreReader.Engineering.priorityReflexiveCases' depends on axioms: [propext, Classical.choice, Quot.sound] +ORGANON_TYPE CoreReader.Engineering.priorityReflexiveCases "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.objects [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.priority [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.objectTest [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.priority []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 10)))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.performed [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.PrincipleKey.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.priority []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.priority []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Outcome.assessed [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict.supportedWithinScope []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.evaluate [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.evolutionMethod []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision [])))))\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict.counterexample [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.objectTest [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.evolutionMethod []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 10)))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.objectTest [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.evolutionMethod []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.sharedContext [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.value [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.AssessmentTask.value [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.evaluate [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.assessmentRule []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision [])))))\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict.counterexample []))))))))" +CoreReader.Engineering.jointWitness : + ∃ ctx chosen, + ctx = CoreReader.Engineering.sharedContext ∧ + chosen = CoreReader.Engineering.Candidate.evolvable ∧ + CoreReader.Engineering.Inherited ctx chosen ∧ + CoreReader.Engineering.DomainSatisfied ctx chosen ∧ + CoreReader.Engineering.PriorityConditions ctx ∧ + ¬CoreReader.Engineering.HasThreat ctx CoreReader.Engineering.Candidate.evolvable ∧ + CoreReader.Engineering.abstractionComplexity CoreReader.Engineering.Candidate.presentSimple < + CoreReader.Engineering.abstractionComplexity chosen ∧ + CoreReader.Engineering.CanChange ctx.activity chosen CoreReader.Engineering.Maintainer.successor + CoreReader.Engineering.Change.designRevision ∧ + CoreReader.Engineering.CanChange ctx.activity chosen CoreReader.Engineering.Maintainer.agent + CoreReader.Engineering.Change.designRevision ∧ + CoreReader.Engineering.ownTheory chosen + (CoreReader.Engineering.ownFactClaim chosen CoreReader.Engineering.OwnFact.selected) ∧ + CoreReader.Engineering.ReviewObject.commitment CoreReader.Engineering.CoreCommitment.grounds ∈ + (CoreReader.Engineering.selfModel chosen).objects ∧ + CoreReader.Logic.Admissible (CoreReader.Engineering.ownTheory chosen) + (CoreReader.Engineering.comparisonContext chosen) chosen +'CoreReader.Engineering.jointWitness' depends on axioms: [propext, Classical.choice, Quot.sound] +ORGANON_TYPE CoreReader.Engineering.jointWitness "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Context []))\n (Lean.Expr.lam\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.lam\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Context []))\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.sharedContext [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.Inherited []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.DomainSatisfied []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.PriorityConditions []) (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.HasThreat []) (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownTheory [])\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownFactClaim [])\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.OwnFact.selected []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.objects [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.commitment [])\n (Lean.Expr.const `CoreReader.Engineering.CoreCommitment.grounds []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `CoreReader.Engineering.OwnFact []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownTheory [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.comparisonContext [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.bvar 0)))))))))))))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default))" +CoreReader.Engineering.inheritedDoesNotEntailPriority : + ∃ ctx chosen, + ctx = CoreReader.Engineering.sharedContext ∧ + chosen = CoreReader.Engineering.Candidate.presentSimple ∧ + CoreReader.Engineering.Inherited ctx chosen ∧ + CoreReader.Engineering.PriorityConditions ctx ∧ + CoreReader.Engineering.Continuing ctx.activity ∧ + ¬CoreReader.Engineering.BoundedLifecycle ctx.activity ∧ + ¬CoreReader.Engineering.HasThreat ctx CoreReader.Engineering.Candidate.evolvable ∧ + ¬CoreReader.Engineering.JustifiedDeparture ctx CoreReader.Engineering.Candidate.evolvable ∧ + CoreReader.Engineering.Meets ctx.required + (ctx.profiles CoreReader.Engineering.Candidate.presentSimple) ∧ + CoreReader.Engineering.Meets ctx.required + (ctx.profiles CoreReader.Engineering.Candidate.evolvable) ∧ + CoreReader.Engineering.credible ctx.evidence CoreReader.Engineering.Change.designRevision ∧ + CoreReader.Engineering.CanChange ctx.activity CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Maintainer.successor CoreReader.Engineering.Change.designRevision ∧ + CoreReader.Engineering.CanChange ctx.activity CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Maintainer.agent CoreReader.Engineering.Change.designRevision ∧ + CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.designRevision < + CoreReader.Engineering.changeWork chosen + CoreReader.Engineering.Change.designRevision ∧ + CoreReader.Engineering.abstractionComplexity chosen < + CoreReader.Engineering.abstractionComplexity + CoreReader.Engineering.Candidate.evolvable ∧ + CoreReader.Adopted.valueSpecification + (CoreReader.Engineering.selectionPosition chosen) ∧ + (CoreReader.Engineering.selectionPosition chosen).commitment chosen ∧ + ¬CoreReader.Engineering.EvolutionPriority ctx chosen +'CoreReader.Engineering.inheritedDoesNotEntailPriority' depends on axioms: [propext, Classical.choice, Quot.sound] +ORGANON_TYPE CoreReader.Engineering.inheritedDoesNotEntailPriority "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Context []))\n (Lean.Expr.lam\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.lam\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Context []))\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.sharedContext [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.Inherited []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.PriorityConditions []) (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Continuing [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.Context.activity []) (Lean.Expr.bvar 1))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.HasThreat []) (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.required [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.profiles [])\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.required [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.profiles [])\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.evidence [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `LT.lt [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `LT.lt [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.valueSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))))))))))))))))))))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default))" diff --git a/SoftwareEngineering/lean/philosophy/evidence/manuscript-check.json b/SoftwareEngineering/lean/philosophy/evidence/manuscript-check.json new file mode 100644 index 0000000..dda8a70 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/evidence/manuscript-check.json @@ -0,0 +1,697 @@ +{ + "passed": true, + "semantic_status": "not_evaluated", + "current_source": "current", + "current_baseline": "current", + "errors": [], + "entries": [ + { + "id": "organon.preamble.p1", + "kernel": "not_checked", + "reported_fidelity": "not_applicable", + "reported_status": "not_applicable", + "effective_status": "not_applicable" + }, + { + "id": "organon.preamble.p2", + "kernel": "not_checked", + "reported_fidelity": "not_applicable", + "reported_status": "not_applicable", + "effective_status": "not_applicable" + }, + { + "id": "organon.charter", + "kernel": "not_checked", + "reported_fidelity": "not_applicable", + "reported_status": "not_applicable", + "effective_status": "not_applicable" + }, + { + "id": "organon.charter.overview.p1", + "kernel": "not_checked", + "reported_fidelity": "not_applicable", + "reported_status": "not_applicable", + "effective_status": "not_applicable" + }, + { + "id": "organon.charter.overview.p2", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.charter.overview.p3", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.charter.self-transcendence.p1", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.charter.self-transcendence.orientation.p1", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.charter.self-transcendence.non-finality.p1", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.charter.self-transcendence.limits.p1", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.charter.self-transcendence.limits.p2", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.charter.consistency.p1", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.charter.consistency.meaning.p1", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.charter.consistency.meaning.p2", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.charter.consistency.limits.p1", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.charter.reflexivity.p1", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.charter.reflexivity.meaning.p1", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.charter.reflexivity.limits.p1", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.grounds.p1", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.grounds.assessment.p1", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.grounds.assessment.p2", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.grounds.assessment.p3", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.grounds.scope.p1", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.grounds.scope.p2", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.grounds.scope.p3", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.grounds.capabilities.p1", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.grounds.capabilities.p2", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.grounds.implementations.p1", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.grounds.implementations.p2", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.grounds.implementations.limits.p1", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.relationships", + "kernel": "not_checked", + "reported_fidelity": "not_applicable", + "reported_status": "not_applicable", + "effective_status": "not_applicable" + }, + { + "id": "organon.relationships.roles.p1", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.relationships.roles.p2", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.relationships.roles.p3", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "organon.relationships.terms.p1", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "incomplete", + "effective_status": "incomplete" + }, + { + "id": "extensions.p1", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "software-engineering.purpose.p1", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "software-engineering.purpose.p2", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "software-engineering.purpose.p3", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "software-engineering.evolution-priority.p1", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "software-engineering.evolution-priority.p2", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "software-engineering.evolution-priority.p3", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "software-engineering.evolution-meaning.p1", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "software-engineering.evolution-meaning.p2", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "software-engineering.structural-judgment.p1", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "software-engineering.structural-judgment.p2", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "software-engineering.structural-judgment.p3", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "software-engineering.revision.p1", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + }, + { + "id": "software-engineering.revision.p2", + "kernel": "passed", + "reported_fidelity": "partial", + "reported_status": "limited", + "effective_status": "limited" + } + ], + "manifest_sha256": "8ad14b42a35afa6709255638c23167ffc8b60b5678bfc7e4f88ae657e9bcfec4", + "proof_targets": { + "sha256": "19184f5f301fb5a2f156d09a1d5b4fee5f9e8e9bbc96fdc5fbbc9ccb426287bb", + "complete": true, + "semantic_status": "not_evaluated", + "entries": [ + { + "id": "T01", + "kind": "boundary", + "reported_status": "accepted", + "declarations": [] + }, + { + "id": "T02", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases" + ] + }, + { + "id": "T03", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.generationLimits012" + ] + }, + { + "id": "T04", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.consistencySpecification", + "CoreReader.Adopted.consistencyCases" + ] + }, + { + "id": "T05", + "kind": "theorem", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.consistencyConsequences", + "CoreReader.Adopted.consistencyCases" + ] + }, + { + "id": "T06", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.consistencyLimits012" + ] + }, + { + "id": "T07", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.reflexivitySpecification", + "CoreReader.Adopted.reflexivityCases012" + ] + }, + { + "id": "T08", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.reflexivityLimits012" + ] + }, + { + "id": "T09", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.Grounds012", + "CoreReader.Adopted.groundsCases012" + ] + }, + { + "id": "T10", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.empiricalSpecification", + "CoreReader.Adopted.empiricalCases012" + ] + }, + { + "id": "T11", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.inferentialSpecification", + "CoreReader.Adopted.inferentialCases012" + ] + }, + { + "id": "T12", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.valueSpecification", + "CoreReader.Adopted.valueCases012" + ] + }, + { + "id": "T13", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.groundsLimits012" + ] + }, + { + "id": "T14", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.scopeSpecification", + "CoreReader.Adopted.scopeCases012" + ] + }, + { + "id": "T15", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.scopeLimits012" + ] + }, + { + "id": "T16", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.capabilitySpecification", + "CoreReader.Adopted.capabilityCases012" + ] + }, + { + "id": "T17", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.capabilityLimits012" + ] + }, + { + "id": "T18", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.choiceSpecification", + "CoreReader.Adopted.choiceCases012" + ] + }, + { + "id": "T19", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Adopted.choiceLimits012" + ] + }, + { + "id": "T20", + "kind": "theorem", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.inheritedMutualApplication", + "CoreReader.Engineering.inheritedMutualCases" + ] + }, + { + "id": "T21", + "kind": "boundary", + "reported_status": "accepted", + "declarations": [] + }, + { + "id": "T22", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.ActivityScope", + "CoreReader.Engineering.subjectLifecycleCases" + ] + }, + { + "id": "T23", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.subjectLimits" + ] + }, + { + "id": "T24", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.EvolutionPriority", + "CoreReader.Engineering.priorityConditionsCases" + ] + }, + { + "id": "T25", + "kind": "theorem", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.priorityWhenApplicable", + "CoreReader.Engineering.priorityChoices" + ] + }, + { + "id": "T26", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.CredibleDirection", + "CoreReader.Engineering.credibilityCases" + ] + }, + { + "id": "T27", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.credibilityLimits" + ] + }, + { + "id": "T28", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.JustifiedDeparture", + "CoreReader.Engineering.costCases" + ] + }, + { + "id": "T29", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.EvolutionClaim", + "CoreReader.Engineering.evolutionKindsCases" + ] + }, + { + "id": "T30", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.evolutionDimensionsLimits" + ] + }, + { + "id": "T31", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.StructuralAccount", + "CoreReader.Engineering.structuralCases" + ] + }, + { + "id": "T32", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.structureNotCapability" + ] + }, + { + "id": "T33", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.ContractChangeAccount", + "CoreReader.Engineering.contractCases" + ] + }, + { + "id": "T34", + "kind": "theorem", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.contractPreservation", + "CoreReader.Engineering.contractDistinctions" + ] + }, + { + "id": "T35", + "kind": "specification", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.RevisionAccount", + "CoreReader.Engineering.revisionCases" + ] + }, + { + "id": "T36", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.revisionLimits" + ] + }, + { + "id": "T37", + "kind": "theorem", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.priorityRemainsReflexive", + "CoreReader.Engineering.priorityReflexiveCases" + ] + }, + { + "id": "T38", + "kind": "satisfiability", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.jointWitness" + ] + }, + { + "id": "T39", + "kind": "nonentailment", + "reported_status": "accepted", + "declarations": [ + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ] + }, + { + "id": "T40", + "kind": "boundary", + "reported_status": "accepted", + "declarations": [] + } + ] + } +} diff --git a/SoftwareEngineering/lean/philosophy/leanified/.gitignore b/SoftwareEngineering/lean/philosophy/leanified/.gitignore new file mode 100644 index 0000000..23abe82 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/leanified/.gitignore @@ -0,0 +1,3 @@ +.lake/ +*.olean +*.ilean diff --git a/SoftwareEngineering/lean/philosophy/leanified/CoreReader.lean b/SoftwareEngineering/lean/philosophy/leanified/CoreReader.lean new file mode 100644 index 0000000..dc83110 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/leanified/CoreReader.lean @@ -0,0 +1 @@ +import CoreReader.Engineering.Integration diff --git a/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Adopted.lean b/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Adopted.lean new file mode 100644 index 0000000..dde9dff --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Adopted.lean @@ -0,0 +1,1350 @@ +import CoreReader.Integration + +namespace CoreReader.Adopted +open CoreReader.Logic CoreReader.Agency CoreReader.Evidence CoreReader.Choice + +/- These are three explicit mathematical assessment tasks, not an exhaustive or +exclusive taxonomy of claim natures. A task fixes the original claim and support +context before any candidate assessment is proposed. Its identity must be retained +when comparing alternative assessments; taskOfFacet declares a new task and does +not authorize replacing a previously identified task. -/ +inductive AssessmentTask (W : Type) where + | empirical (records : List (Record W)) (scope claim uncertainty : Claim W) + | inferential (assumptions : Theory W) (claim : Claim W) + | value (position : ValuePosition W) + +def taskOfFacet {W : Type} : Facet W → AssessmentTask W + | .empirical records scope claim uncertainty => .empirical records scope claim uncertainty + | .inferential assumptions claim => .inferential assumptions claim + | .value position => .value position + +/- This is a content-based sufficient adapter for the declared task, not a +philosophical rule requiring one unique assessment form. The empirical task may +also be assessed inferentially from exactly its observation/scope premises; its +original uncertainty obligation is still checked. In particular, adding the +conclusion as a new premise cannot replace the original empirical grounds. +The finite adapter need not accept every semantically equivalent presentation. -/ +def NatureAppropriate {W : Type} : AssessmentTask W → Facet W → Prop + | .empirical records scope claim uncertainty, .empirical actualRecords actualScope conclusion actualUncertainty => + actualRecords = records ∧ actualScope = scope ∧ conclusion = claim ∧ actualUncertainty = uncertainty + | .empirical records scope claim uncertainty, .inferential assumptions conclusion => + assumptions = singleton (fun w => Compatible records w ∧ scope w) ∧ + conclusion = claim ∧ Supports records uncertainty + | .inferential assumptions claim, .inferential actualAssumptions conclusion => + actualAssumptions = assumptions ∧ conclusion = claim + | .value position, .value actualPosition => actualPosition = position + | _, _ => False + +theorem taskOfFacetAppropriate {W : Type} (f : Facet W) : NatureAppropriate (taskOfFacet f) f := by + cases f with + | empirical _ _ _ _ => exact ⟨rfl, rfl, rfl, rfl⟩ + | inferential _ _ => exact ⟨rfl, rfl⟩ + | value _ => rfl + +/- Core 0.1.2 requires appropriateness to the original claim task. Supplied facets +are an explicit assessment scope, without importing Core 0.1.3's all-applicable +coverage requirement. No claim-kind label or freely assigned success flag proves +appropriateness: NatureAppropriate compares the actual task and facet contents. -/ +/-- organon-map CoreReader.Adopted.Grounds012 +organon.grounds#p1 sha256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6 +organon.grounds.assessment#p1 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +-/ +def Grounds012 {W : Type} (claim : Claim W) + (articulations : Facet W → Articulation W) (facets : List (Facet W)) + (task : AssessmentTask W) : Prop := + facets ≠ [] ∧ ∀ facet ∈ facets, + facet.claim = claim ∧ Articulated (articulations facet) ∧ + FacetArticulated (articulations facet) facet ∧ FacetDischarged facet ∧ + NatureAppropriate task facet + +/- This helper proves the newly declared taskOfFacet f only. It supplies no +appropriateness proof for another, previously fixed task with the same claim. -/ +theorem grounds012Singleton {W : Type} (f : Facet W) (h : FacetDischarged f) : + Grounds012 f.claim canonicalArticulation [f] (taskOfFacet f) := by + refine ⟨by simp, ?_⟩ + intro facet hf + cases List.mem_singleton.mp hf + exact ⟨rfl, canonicalArticulated f h, canonicalFacetArticulated f, h, taskOfFacetAppropriate f⟩ + +/-- organon-map CoreReader.Adopted.generationSpecification +organon.charter.overview#p2 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c +organon.charter.overview#p3 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c +organon.charter.self-transcendence#p1 sha256 f4ca590e2ae15e3882f70c7b2bc46a8911c97cee547c8b137b5493fbf862c8c0 +organon.charter.self-transcendence.orientation#p1 sha256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf +organon.charter.self-transcendence.non-finality#p1 sha256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8 +organon.charter.self-transcendence.limits#p2 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d +organon.relationships.terms#p1 sha256 61cb7ce4f2920f1aa6771502b87a66536ae0504acccfebd9dd23bcc62756eddf +-/ +def generationSpecification (policy : Policy) : Prop := Generative policy + +/- All consequences use the whole currently held set. Historical reporting is +separate and does not require simultaneous compatibility with withdrawn claims. -/ +/-- organon-map CoreReader.Adopted.consistencySpecification +organon.charter.consistency#p1 sha256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42 +organon.charter.consistency.meaning#p1 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75 +-/ +def consistencySpecification {W Q : Type} (before after : Snapshot W Q) + (reported : Bool) : Prop := + Consistent after.held after.context ∧ TruthfulReport before after reported + +/- A method's actual input and interpretation are parameters, permitting domain +methods as well as the small arithmetic adapter. Key coherence prevents records +for another method from silently satisfying the duty. -/ +structure ReflexiveRule (T I O : Type) where + key : PrincipleKey + activity : Activity + applicable : T → Prop + input : T → I + meaning : I → O → Prop + +/-- organon-map CoreReader.Adopted.reflexivitySpecification +organon.charter.reflexivity#p1 sha256 13293b45c2fa89068c68ae7ef3c5df38f0efadb3ef3873d78a5ba67d9691a757 +organon.charter.reflexivity.meaning#p1 sha256 8a2caede01a43d8b6c60b54c78ac089c51868e9956f316948077ccee2e45c9cc +organon.charter.reflexivity.limits#p1 sha256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +def reflexivitySpecification {T I O : Type} (rules : List (ReflexiveRule T I O)) + (isSelf : T → Prop) (performed : PrincipleKey → T → I → O → Prop) : Prop := + (∀ p ∈ rules, ∀ q ∈ rules, p.key = q.key → p = q) ∧ + ∀ rule ∈ rules, ∀ target, isSelf target → rule.applicable target → + ∃ outcome, performed rule.key target (rule.input target) outcome ∧ + rule.meaning (rule.input target) outcome + +def legacyRule (p : Principle) : ReflexiveRule Subject Inquiry WorkOutcome := + ⟨p.key, p.activity, p.applicable, p.inquiry, + fun inquiry outcome => p.meaning inquiry (p.reasons inquiry.target) (p.limits inquiry.target) outcome⟩ + +def legacyPerformed (rules : List Principle) (records : List WorkRecord) + (key : PrincipleKey) (target : Subject) (input : Inquiry) (outcome : WorkOutcome) : Prop := + ∃ p ∈ rules, ∃ record ∈ records, + p.key = key ∧ ValidApplication rules p target record ∧ + record.inquiry = input ∧ record.outcome = outcome + +theorem legacyReflexivity (owner : Nat) (rules : List Principle) (records : List WorkRecord) + (h : Reflexive owner rules records) : + reflexivitySpecification (rules.map legacyRule) (fun s => s.owner = owner) + (legacyPerformed rules records) := by + constructor + · intro p hp q hq he + obtain ⟨a, ha, rfl⟩ := List.mem_map.mp hp + obtain ⟨b, hb, rfl⟩ := List.mem_map.mp hq + exact congrArg legacyRule (h.1 a ha b hb he) + · intro rule hr target ht happ + obtain ⟨p, hp, rfl⟩ := List.mem_map.mp hr + obtain ⟨record, hm, hv⟩ := h.2 p hp target ht happ + refine ⟨record.outcome, ⟨p, hp, record, hm, rfl, hv, hv.inquiryIdentity, rfl⟩, ?_⟩ + change p.meaning (p.inquiry target) (p.reasons (p.inquiry target).target) + (p.limits (p.inquiry target).target) record.outcome + have ti : (p.inquiry target).target = target := hv.inquiryIdentity ▸ hv.inquiryTarget + rw [ti] + rw [← hv.inquiryIdentity, ← hv.reasonsIdentity, ← hv.limitsIdentity] + exact hv.followsMeaning + +/- These are fulfillment interfaces for the named mathematical adapters, not +universal empirical adequacy claims or definitions of all possible claim kinds. -/ +/-- organon-map CoreReader.Adopted.empiricalSpecification +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +-/ +def empiricalSpecification {W : Type} (records : List (Record W)) + (scope claim uncertainty : Claim W) : Prop := + Grounds012 claim canonicalArticulation [.empirical records scope claim uncertainty] + (.empirical records scope claim uncertainty) + +/-- organon-map CoreReader.Adopted.inferentialSpecification +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +def inferentialSpecification {W : Type} (assumptions : Theory W) (claim : Claim W) : Prop := + Grounds012 claim canonicalArticulation [.inferential assumptions claim] (.inferential assumptions claim) + +/-- organon-map CoreReader.Adopted.valueSpecification +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +-/ +def valueSpecification {W : Type} (position : ValuePosition W) : Prop := + Grounds012 position.commitment canonicalArticulation [.value position] (.value position) + +/- Scope and roles are explicitly identified relative to a claim. An actually +used method needs an explanation; unused methods are not required. The input +relation can encode contextual relevance without a universal numeric scale. -/ +inductive AssessmentMethod | measurement | repetition | framework + deriving DecidableEq +structure ScopeAccount (W : Type) where + claim : Claim W + conditions : Claim W + observationScope : Claim W + relevant : W → W → Prop + compared : W → W → Prop + used : AssessmentMethod → Prop + role : AssessmentMethod → String + explains : AssessmentMethod → String → Claim W → Claim W → Prop + +/-- organon-map CoreReader.Adopted.scopeSpecification +organon.grounds.scope#p1 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.scope#p2 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.scope#p3 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +-/ +def scopeSpecification {W : Type} (account : ScopeAccount W) : Prop := + (∀ a b, account.compared a b → account.conditions a ∧ account.conditions b ∧ + account.observationScope a ∧ account.observationScope b ∧ account.relevant a b) ∧ + ∀ method, account.used method → account.role method ≠ "" ∧ + account.explains method (account.role method) account.claim account.conditions + +/- A capability is selected by the application as an exact object-scoped +contract; whether explanation is part of it remains an application choice. -/ +/-- organon-map CoreReader.Adopted.capabilitySpecification +organon.grounds.capabilities#p1 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0 +organon.grounds.capabilities#p2 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0 +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +def capabilitySpecification (assessed : Process) (contract : Claim Process) : Prop := + Grounds012 contract canonicalArticulation [processContractFacet assessed contract] + (.inferential (processScope assessed) contract) + +/-- organon-map CoreReader.Adopted.choiceSpecification +organon.grounds.implementations#p1 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c +organon.grounds.implementations#p2 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c +organon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870 +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +def choiceSpecification (requirements : Requirements) (implementation : Implementation) + (reasons : List Reason) : Prop := JustifiedChoice requirements implementation reasons + +/- A collaborator supplies the successor operation. Removing that resource +leaves the initial state; progress is tested on actual added operation content. -/ +def collaborativeRevision (resources : ExternalResources) : State := + if resources.collaborator.isSome then extendedState else baseState + +theorem collaborativeProgress : + generationSpecification openPolicy ∧ + Expanded baseState (collaborativeRevision availableResources) ∧ + ¬ Expanded baseState (collaborativeRevision { availableResources with collaborator := none }) ∧ + assistedExecution ⟨none, none, none⟩ = none := by + refine ⟨⟨Or.inl rfl, fun _ _ => trivial⟩, ?_, ?_, rfl⟩ + · exact Or.inr ⟨.successor, by simp [collaborativeRevision, availableResources, extendedState], + by simp [baseState]⟩ + · simp [collaborativeRevision, Expanded, baseState] + +/- A truth-preserving current slice need not retain an earlier incompatible +slice. Context changes and presentation order have separate semantics. -/ +/-- organon-map CoreReader.Adopted.consistencyConsequences +organon.charter.consistency#p1 sha256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42 +organon.charter.consistency.meaning#p1 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75 +-/ +theorem consistencyConsequences {W Q : Type} (t : Theory W) (c : Context W Q) (q : Q) + (positive : Consequence t c q true) (negative : Consequence t c q false) : + ¬ Consistent t c := conflictRequiresChange t c q positive negative + +def broadBoolContext : Context Bool Unit := ⟨emptyTheory, onQuestion, fun _ => True⟩ + +theorem sliceConsistency : + (∀ time, Consistent (revisionSlice time) broadBoolContext) ∧ + ¬ Consistent (union (revisionSlice 0) (revisionSlice 1)) broadBoolContext := by + constructor + · intro time + apply consequenceConsistency + exact ⟨time == 0, (modelsSingleton _ _).2 rfl, (by intro p hp; cases hp), trivial⟩ + · apply conflictRequiresChange _ _ () + · intro w h + change w = true + exact (modelsSingleton (fun w : Bool => w = true) w).1 ((modelsUnion _ _ _).1 h.1).1 + · intro w h ht + have hn := (modelsSingleton _ _).1 ((modelsUnion _ _ _).1 h.1).2 + cases ht.symm.trans hn + +theorem explicitlyConsistentLimits : + Consistent (singleton (fun w : Bool => w = true)) broadBoolContext ∧ + ¬ Models (singleton (fun w : Bool => w = true)) false ∧ + Consistent (emptyTheory : Theory Bool) broadBoolContext ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true) := by + refine ⟨?_, consistentFalse.2, ?_, consistentIncomplete.2.1⟩ + · exact consequenceConsistency _ _ ⟨true, (modelsSingleton _ _).2 rfl, + (by intro p hp; cases hp), trivial⟩ + · exact consequenceConsistency _ _ ⟨true, (by intro p hp; cases hp), + (by intro p hp; cases hp), trivial⟩ + +/- One observed input supports the local claim. The identical records cannot +support all inputs, nor the stronger claim that both Boolean outputs are true. -/ +def localFacet012 : Facet (Nat → Bool) := + .empirical [zeroRecord] (fun _ => True) (fun f => f 0 = true) (fun _ => True) +def globalFacet012 : Facet (Nat → Bool) := + .empirical [zeroRecord] (fun _ => True) allTrue (fun _ => True) +def strongFacet012 : Facet (Nat → Bool) := + .empirical [zeroRecord] (fun _ => True) (fun f => f 0 = true ∧ f 1 = true) (fun _ => True) + +theorem localFacetChecked012 : FacetDischarged localFacet012 := + ⟨⟨localGenerator 0, (zeroCompatible _).2 rfl, trivial⟩, + (fun f hf _ => (zeroCompatible f).1 hf), fun _ _ => trivial⟩ + +theorem scopeStrength012 : + Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧ + Articulated (canonicalArticulation globalFacet012) ∧ + ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧ + ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012) := by + refine ⟨grounds012Singleton _ localFacetChecked012, ⟨by simp [canonicalArticulation, globalFacet012], + by simp [canonicalArticulation, globalFacet012]⟩, ?_, ?_⟩ + · intro h + have checked := (h.2 globalFacet012 (by simp)).2.2.2.1 + have bad := checked.2.1 (localGenerator 0) ((zeroCompatible _).2 rfl) trivial 1 + cases bad + · intro h + have checked := (h.2 strongFacet012 (by simp)).2.2.2.1 + have bad := (checked.2.1 (localGenerator 0) ((zeroCompatible _).2 rfl) trivial).2 + cases bad + +/- A bounded outcome statement can leave another observable entirely unknown. +This represents uncertainty by a range of compatible worlds, not a probability. -/ +def uncertainFacet012 : Facet (Bool × Bool) := + .empirical [temperatureRecord, temperatureRecord] (fun _ => True) + (fun w => w.1 = true) (fun w => w.2 = true ∨ w.2 = false) + +theorem uncertainSupported012 : + empiricalSpecification [temperatureRecord, temperatureRecord] (fun _ => True) + (fun w => w.1 = true) (fun w => w.2 = true ∨ w.2 = false) ∧ + Compatible [temperatureRecord, temperatureRecord] (true,true) ∧ + Compatible [temperatureRecord, temperatureRecord] (true,false) := by + refine ⟨grounds012Singleton uncertainFacet012 ?_, temperatureCompatible true, temperatureCompatible false⟩ + refine ⟨⟨(true,false), temperatureCompatible false, trivial⟩, ?_, ?_⟩ + · intro w hw _; exact hw temperatureRecord (by simp) + · intro w _; cases w.2 <;> simp + +/- Correctly completed negative examination is distinct from a supported +conclusion. The countervaluation satisfies the same premises. -/ +def InferenceExamined {W : Type} (premises : Theory W) (conclusion : Claim W) + (accepted : Bool) : Prop := accepted = true ↔ Entails premises conclusion + +theorem inferenceChecked012 : + inferentialSpecification (singleton (fun n : Nat => n = 2)) (fun n => n + 1 = 3) ∧ + InferenceExamined (emptyTheory : Theory Bool) (fun w => w = true) false ∧ + Models (emptyTheory : Theory Bool) false ∧ ¬ ((fun w : Bool => w = true) false) := by + refine ⟨grounds012Singleton arithmeticFacet noUniversalChain.1, ?_, (by intro p hp; cases hp), by decide⟩ + constructor + · intro h; cases h + · intro h; exact False.elim (consistentIncomplete.2.1 h) + +/- Closing a response to an actually relevant criticism fails the value +procedure even when its budget/benefit reasons and joint adoption are unchanged. -/ +def closedPosition012 : ValuePosition Bool := { switchPosition with response := fun _ => none } + +theorem closedCriticism012 : ¬ ValueProcedure closedPosition012 := by + intro h + obtain ⟨answer, ha, _⟩ := h.2.2.2 false trivial rfl + cases ha + +theorem valueFulfilled012 : valueSpecification switchPosition := + grounds012Singleton _ switchValueProcedure + +/- Qualitative entailment orders claims by implication, without conversion of +value and empirical/inferential reasons to a common numeric scale. -/ +def ClaimNoStronger {W : Type} (weaker stronger : Claim W) : Prop := ∀ w, stronger w → weaker w + +theorem qualitativeProportionality012 : + ClaimNoStronger (fun f : Nat → Bool => f 0 = true) allTrue ∧ + ¬ ClaimNoStronger allTrue (fun f : Nat → Bool => f 0 = true) ∧ + valueSpecification switchPosition := by + refine ⟨fun _ h => h 0, ?_, valueFulfilled012⟩ + intro h + have bad := h (localGenerator 0) rfl 1 + cases bad + +def scopeRole012 : AssessmentMethod → String + | .measurement => "identify the output at the observed input zero" + | .repetition => "check the same local conclusion against repeated input-zero observations" + | .framework => "compare only the declared input; keep broader claims separate" + +def scopeRoleContent012 : AssessmentMethod → Prop + | .measurement => Supports [zeroRecord] (fun f => f 0 = true) + | .repetition => Supports [zeroRecord, zeroRecord] (fun f => f 0 = true) + | .framework => ¬ Supports [zeroRecord] allTrue + +def localScopeAccount012 : ScopeAccount Nat where + claim n := (localGenerator 0) n = true + conditions _ := True + observationScope n := n = 0 + relevant a b := a = b + compared a b := a = 0 ∧ b = 0 + used _ := True + role := scopeRole012 + explains method text claim conditions := + text = scopeRole012 method ∧ claim = (fun n => localGenerator 0 n = true) ∧ + conditions = (fun _ => True) ∧ scopeRoleContent012 method + +theorem scopeFulfilled012 : scopeSpecification localScopeAccount012 := by + constructor + · intro a b h + exact ⟨trivial, trivial, h.1, h.2, h.1.trans h.2.symm⟩ + · intro method _ + refine ⟨?_, rfl, rfl, rfl, ?_⟩ + · cases method <;> decide + · cases method with + | measurement => exact singleObservation.2.2.1 + | repetition => intro f hf; exact hf zeroRecord (by simp) + | framework => exact singleObservation.2.2.2 + +theorem capabilityFulfilled012 : + capabilitySpecification outputOnlyProcess OutputContract ∧ + capabilitySpecification explainedProcess FullProcessContract ∧ + (∃ certificate : ExternalCertificate outputOnlyProcess, + certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧ + ¬ ExplanationContract outputOnlyProcess := by + refine ⟨grounds012Singleton _ (processContractDischarged _ _ outputCorrectByEvaluation), + grounds012Singleton _ (processContractDischarged _ _ ?_), + ⟨externalOutputCertificate, externalOutputCertificate.distinctParticipants, + externalOutputCertificate.outputCorrect⟩, outputOnlyNoExplanation⟩ + exact ⟨fun _ => rfl, .doubleInput, rfl, fun _ => rfl⟩ + +/- This application asks the assessed object to predict a multiplier mechanism +at changed inputs and multiplier values. This is one operational understanding +criterion selected by an application, not a definition of psychological understanding. +The original output and explanation alone do not answer the additional questions. -/ +structure MechanismApplication012 where + process : Process + answer : Nat → Nat → Nat + +def mechanism012 (multiplier input : Nat) : Nat := multiplier * input + +def UnderstandingApplication012 (assessed : MechanismApplication012) : Prop := + FullProcessContract assessed.process ∧ + (∀ input, assessed.process.output input = mechanism012 2 input) ∧ + ∀ multiplier input, assessed.answer multiplier input = mechanism012 multiplier input + +def explainedWithoutVariation012 : MechanismApplication012 := + ⟨explainedProcess, fun _ input => input + input⟩ + +def mechanismResponder012 : MechanismApplication012 := + ⟨explainedProcess, mechanism012⟩ + +/- The assessment task is fixed by this very application object and the stronger +contract. Identity is a scope premise; the positive case still proves the contract. -/ +def understandingScope012 (assessed : MechanismApplication012) : Theory MechanismApplication012 := + singleton (fun candidate => candidate = assessed) + +def understandingTask012 (assessed : MechanismApplication012) : AssessmentTask MechanismApplication012 := + .inferential (understandingScope012 assessed) UnderstandingApplication012 + +def understandingFacet012 (assessed : MechanismApplication012) : Facet MechanismApplication012 := + .inferential (understandingScope012 assessed) UnderstandingApplication012 + +theorem mechanismResponderUnderstands012 : UnderstandingApplication012 mechanismResponder012 := by + refine ⟨⟨(fun _ => rfl), .doubleInput, rfl, (fun _ => rfl)⟩, ?_, fun _ _ => rfl⟩ + intro input + simp [mechanismResponder012, explainedProcess, mechanism012, Nat.two_mul] + +theorem explainedWithoutVariationFails012 : + ¬ UnderstandingApplication012 explainedWithoutVariation012 := by + intro h + have wrong := h.2.2 3 1 + change 2 = 3 at wrong + cases wrong + +theorem understandingApplicationCases012 : + explainedWithoutVariation012.process = mechanismResponder012.process ∧ + FullProcessContract explainedWithoutVariation012.process ∧ + ¬ UnderstandingApplication012 explainedWithoutVariation012 ∧ + UnderstandingApplication012 mechanismResponder012 ∧ + Grounds012 UnderstandingApplication012 canonicalArticulation + [understandingFacet012 mechanismResponder012] (understandingTask012 mechanismResponder012) ∧ + ¬ Grounds012 UnderstandingApplication012 canonicalArticulation + [understandingFacet012 explainedWithoutVariation012] (understandingTask012 explainedWithoutVariation012) := by + refine ⟨rfl, ⟨(fun _ => rfl), .doubleInput, rfl, (fun _ => rfl)⟩, + explainedWithoutVariationFails012, mechanismResponderUnderstands012, ?_, ?_⟩ + · apply grounds012Singleton + refine ⟨⟨mechanismResponder012, (modelsSingleton _ _).2 rfl⟩, ?_⟩ + intro candidate hc + have same := (modelsSingleton _ _).1 hc + subst candidate + exact mechanismResponderUnderstands012 + · intro h + have discharged := (h.2 (understandingFacet012 explainedWithoutVariation012) (by simp)).2.2.2.1 + exact explainedWithoutVariationFails012 + (discharged.2 explainedWithoutVariation012 ((modelsSingleton _ _).2 rfl)) + +/- The same exact application contract receives Grounds when its owner asserts +it; external certificates change who supplies reasons, not the asserted object. -/ +def OwnCapability012 (owner claimant : Nat) (process : Process) (contract : Claim Process) : Prop := + owner = claimant ∧ capabilitySpecification process contract + +theorem ownCapability012 : OwnCapability012 7 7 outputOnlyProcess OutputContract := + ⟨rfl, capabilityFulfilled012.1⟩ + +/- A complete represented Charter includes generation, whole-set consistency, +truthful revision reporting and applicable contentful self-work on the same +system. The world type is the finite Candidate × Mode type. -/ +def CompleteCharter012 (system : CoreReader.Integration.System) + (world : CoreReader.Integration.World) : Prop := + generationSpecification (system.policy world) ∧ + consistencySpecification + ⟨CoreReader.Integration.systemHeld system, CoreReader.Integration.systemContext system, 0⟩ + ⟨CoreReader.Integration.systemHeld system, CoreReader.Integration.systemContext system, 0⟩ false ∧ + reflexivitySpecification ((system.rules world).map legacyRule) (fun s => s.owner = system.owner) + (legacyPerformed (system.rules world) (system.work world)) ∧ + (system.policy world).current system.method.form ∧ + (system.policy world).current system.principleForm + +theorem completeCharter012 : CompleteCharter012 CoreReader.Integration.actualSystem CoreReader.Integration.actual := by + refine ⟨CoreReader.Integration.charterChecked.1, + ⟨CoreReader.Integration.jointConsistent, ?_⟩, + legacyReflexivity 0 _ _ (completeOwnWork_reflexive 0), rfl, rfl⟩ + rintro (h | h) + · exact False.elim (h ⟨fun _ => Iff.rfl, fun _ => Iff.rfl, fun _ _ => Iff.rfl, fun _ => Iff.rfl⟩) + · exact False.elim (h rfl) + +theorem charterWithoutGrounds012 : + CompleteCharter012 CoreReader.Integration.actualSystem CoreReader.Integration.actual ∧ + Admissible CoreReader.Integration.held CoreReader.Integration.context CoreReader.Integration.actual ∧ + Compatible [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.actual ∧ + Articulated (canonicalArticulation CoreReader.Integration.unsupportedCapabilityFacet) ∧ + ¬ Supports [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.capability ∧ + ¬ Grounds012 CoreReader.Integration.capability canonicalArticulation + [CoreReader.Integration.unsupportedCapabilityFacet] + (taskOfFacet CoreReader.Integration.unsupportedCapabilityFacet) := by + refine ⟨completeCharter012, CoreReader.Integration.actualAdmissible, + (by intro r hr; cases List.mem_singleton.mp hr; rfl), + ⟨by simp [canonicalArticulation, CoreReader.Integration.unsupportedCapabilityFacet], + by simp [canonicalArticulation, CoreReader.Integration.unsupportedCapabilityFacet]⟩, + CoreReader.Integration.costDoesNotSupportOutput, ?_⟩ + intro h + have checked := (h.2 CoreReader.Integration.unsupportedCapabilityFacet (by simp)).2.2.2.1 + exact CoreReader.Integration.costDoesNotSupportOutput (fun w hw => checked.2.1 w hw trivial) + +/- Permission to assert is evaluated on the same claim, articulation and facets. +The countercase derives inadequacy from the actual unobserved output. -/ +def groundsPermission012 {W : Type} (enabled : Bool) (claim : Claim W) + (a : Facet W → Articulation W) (facets : List (Facet W)) (task : AssessmentTask W) : Prop := + if enabled then Grounds012 claim a facets task else True + +def GroundsProvision012 (enabled : Bool) : Prop := + ∀ (claim : Claim (Nat → Bool)) a facets task, + groundsPermission012 enabled claim a facets task → Grounds012 claim a facets task + +theorem groundsProvision012Meaning (enabled : Bool) : GroundsProvision012 enabled ↔ enabled = true := by + cases enabled with + | true => exact ⟨fun _ => rfl, fun _ _ _ _ _ h => h⟩ + | false => + constructor + · intro h + exact False.elim (scopeStrength012.2.2.1 (h globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) trivial)) + · intro h; cases h + +/- The value rationale concerns this fixed empirical assertion task. The +same task, observed grounds and concrete counterworld are retained when the +permission policy is enabled or disabled. -/ +def groundsExperimentTask012 : AssessmentTask (Nat → Bool) := + .empirical [zeroRecord] (fun _ => True) allTrue (fun _ => True) + +noncomputable def groundsExperiment012 (enabled : Bool) : Bool := + @decide (groundsPermission012 enabled allTrue canonicalArticulation [globalFacet012] + groundsExperimentTask012) (Classical.propDecidable _) + +noncomputable def groundsPosition012 : ValuePosition Bool where + Position := Bool + Outcome := Bool + adopted := true + selected := id + outcome _ enabled := groundsExperiment012 enabled + objective accepted := accepted = false + constraints _ enabled := GroundsProvision012 enabled + starting := singleton (fun enabled => enabled = true) + reasons := [fun _ _ => Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0)] + limits _ := True + relevantCriticism _ := ¬ Supports [zeroRecord] allTrue + response _ := some "retain local support and reject the unsupported universal conclusion" + +theorem groundsPosition012Checked : ValueProcedure groundsPosition012 := by + refine ⟨by simp [groundsPosition012], ?_, ?_, ?_⟩ + · refine ⟨true, (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩ + intro reason hr + cases List.mem_singleton.mp hr + refine ⟨(zeroCompatible _).2 rfl, ?_⟩ + intro h; have bad := h 1; cases bad + · intro w _ _ reasons + have counterworld := reasons _ (List.mem_singleton.mpr rfl) + change Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0) at counterworld + have unsupported : ¬ Grounds012 allTrue canonicalArticulation [globalFacet012] groundsExperimentTask012 := by + intro h + have discharged := (h.2 globalFacet012 (by simp)).2.2.2.1 + exact counterworld.2 (discharged.2.1 (localGenerator 0) counterworld.1 trivial) + refine ⟨?_, (groundsProvision012Meaning true).2 rfl⟩ + exact @decide_eq_false (groundsPermission012 true allTrue canonicalArticulation [globalFacet012] + groundsExperimentTask012) (Classical.propDecidable _) unsupported + · intro w _ _; exact ⟨_, rfl, by decide⟩ + +theorem groundsRationaleExperiment012 : + Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0) ∧ + groundsExperiment012 true = false ∧ groundsExperiment012 false = true ∧ + groundsPosition012.outcome true true = groundsExperiment012 true ∧ + groundsPosition012.outcome true false = groundsExperiment012 false := by + refine ⟨(zeroCompatible _).2 rfl, ?_, ?_, ?_, rfl, rfl⟩ + · intro h; have bad := h 1; cases bad + · have actualReasons : ∀ reason ∈ groundsPosition012.reasons, reason true groundsPosition012.adopted := by + intro reason member + cases List.mem_singleton.mp member + refine ⟨(zeroCompatible _).2 rfl, ?_⟩ + intro h; have bad := h 1; cases bad + exact (groundsPosition012Checked.2.2.1 true ((modelsSingleton _ _).2 rfl) trivial actualReasons).1 + · exact @decide_eq_true (groundsPermission012 false allTrue canonicalArticulation [globalFacet012] + groundsExperimentTask012) (Classical.propDecidable _) trivial + +theorem groundsOnGrounds012 : + Grounds012 (fun enabled => GroundsProvision012 enabled) canonicalArticulation [.value groundsPosition012] (.value groundsPosition012) ∧ + groundsPosition012.limits true ∧ groundsPosition012.relevantCriticism true := by + have same : (Facet.value groundsPosition012).claim = (fun enabled => GroundsProvision012 enabled) := by + funext enabled + exact propext (groundsProvision012Meaning enabled).symm + refine ⟨?_, trivial, singleObservation.2.2.2⟩ + rw [← same] + exact grounds012Singleton _ groundsPosition012Checked + +theorem reflexiveTargets012 : + reflexivitySpecification ((ownRules 0).map legacyRule) (fun s => s.owner = 0) + (legacyPerformed (ownRules 0) (completeOwnWork 0)) ∧ + (∀ phase, Performed (completeOwnWork 0) (.process 0 0 phase) .assessment) ∧ + Performed (completeOwnWork 0) (.system 0) .assessment ∧ + reflexivitySpecification ([applicationRule].map legacyRule) (fun s => s.owner = 0) + (legacyPerformed [applicationRule] applicationWork) ∧ + ¬ Performed applicationWork (.system 0) .assessment := by + refine ⟨legacyReflexivity 0 _ _ (completeOwnWork_reflexive 0), ?_, + ownAssessmentPerformed 0 (.system 0) (by simp [ownSubjects]), + legacyReflexivity 0 _ _ applicationWork_reflexive, (applicabilityRetained 0 [] []).2.2.2⟩ + intro phase + apply ownAssessmentPerformed + cases phase <;> simp [ownSubjects] + +theorem achievementSupported012 : + Grounds012 transitionAchievement canonicalArticulation [transitionFacet] (taskOfFacet transitionFacet) ∧ + Compatible [transitionPerformanceRecord] .extend ∧ + transitionAchievement .extend ∧ ¬ transitionAchievement .inflate ∧ + ¬ Supports [transitionReportRecord] transitionAchievement := by + refine ⟨grounds012Singleton _ transitionFacetDischarged, ?_, ?_, ?_, transitionReportDoesNotSupport.2.2⟩ + · exact (transitionPerformanceCompatible .extend).mpr rfl + · simp [transitionAchievement, transitionBefore, transitionAfter, Expanded, baseState, extendedState] + · simp [transitionAchievement, transitionBefore, transitionAfter, Expanded, baseState, inflatedState] + +theorem semanticOrder012 : ∀ p q : Claim Bool, + ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r := + representationOrderIrrelevant + +def clearFalseArgument012 : Articulation Bool := + ⟨["the actual switch is on"], singleton (fun w => w = true), [fun w => w = true], fun _ => True⟩ + +theorem clearFalseReason012 : + Articulated clearFalseArgument012 ∧ ¬ Models clearFalseArgument012.assumptions false := + ⟨⟨by simp [clearFalseArgument012], by simp [clearFalseArgument012]⟩, consistentFalse.2⟩ + +def valueNeutralRecord012 : Record Bool := ⟨fun _ => true, true⟩ + +theorem valueNotFact012 : + valueSpecification switchPosition ∧ + Compatible [valueNeutralRecord012] false ∧ + ¬ Supports [valueNeutralRecord012] switchPosition.commitment ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment := by + have compatible : Compatible [valueNeutralRecord012] false := by + intro r hr; cases List.mem_singleton.mp hr; rfl + refine ⟨valueFulfilled012, compatible, ?_, valueWithoutSelfProof.2.2.1⟩ + intro h + have bad := h false compatible + cases bad + +def wrongExplanation012 : Implementation := { identityImpl with explanation := fun n => n + 1 } + +theorem internalReasonDistinguishes012 : + (∀ n, identityImpl.run n = wrongExplanation012.run n) ∧ + Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧ + Relevant identityRequirements identityImpl (.method .explanation) ∧ + ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation) := by + refine ⟨fun _ => rfl, identityFeasible, identityFeasible, internalReasons.1, ?_⟩ + intro h + have bad := h.2 0 trivial + cases bad + +theorem inventoryCases012 : ∀ kind : InventoryKind, + Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .copy ∧ + ¬ Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .successor := by + intro kind + simp [Available] + + +def selfExemptRule012 : ReflexiveRule Nat Nat Bool := + ⟨⟨0,1⟩, .assessment, fun _ => True, id, + fun input output => output = ownArithmeticPrinciple input⟩ +def selfExemptPerformed012 (key : PrincipleKey) (target input : Nat) (output : Bool) : Prop := + key = ⟨0,1⟩ ∧ target = 1 ∧ input = target ∧ output = ownArithmeticPrinciple input + +theorem openSelfExempt012 : + generationSpecification openPolicy ∧ openPolicy.revisable ⟨.principle,0⟩ ∧ + selfExemptPerformed012 ⟨0,1⟩ 1 1 true ∧ + selfExemptRule012.applicable 0 ∧ + ¬ reflexivitySpecification [selfExemptRule012] (fun target => target = 0) selfExemptPerformed012 := by + refine ⟨⟨Or.inl rfl, fun _ _ => trivial⟩, trivial, ⟨rfl,rfl,rfl,by decide⟩, trivial, ?_⟩ + intro h + obtain ⟨outcome, performed, _⟩ := h.2 selfExemptRule012 (by simp) 0 rfl trivial + cases performed.2.1 + +theorem ownPhilosophyStatus012 : + ¬ choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation + [.status .standing] ∧ + choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation + [.method .output] := + ⟨CoreReader.Integration.existingPhilosophyNotPrivileged.2.2.1, + CoreReader.Integration.existingPhilosophyNotPrivileged.2.2.2.1⟩ + +def jointContext012 : Context (Bool × Bool) Unit := + ⟨emptyTheory, fun _ w => w.2 = true, fun _ => True⟩ + +theorem jointImplicationConflict012 : + Consequence jointTheory jointContext012 () true ∧ + Consequence jointTheory jointContext012 () false ∧ + ¬ Consistent jointTheory jointContext012 := by + have positive : Consequence jointTheory jointContext012 () true := by + intro w hw + exact (hw.1 premiseRule (Or.inr (Or.inl rfl))) (hw.1 premiseP (Or.inl rfl)) + have negative : Consequence jointTheory jointContext012 () false := by + intro w hw + exact hw.1 premiseNotQ (Or.inr (Or.inr rfl)) + exact ⟨positive, negative, conflictRequiresChange _ _ () positive negative⟩ + +def tensionContext012 : Context Nat Unit := + ⟨emptyTheory, fun _ n => n ≤ 6, fun _ => True⟩ + +theorem tensionConsistent012 : + Consistent (union (singleton (fun n : Nat => 4 ≤ n)) (singleton (fun n => n ≤ 6))) tensionContext012 := by + apply consequenceConsistency + exact ⟨5, (modelsUnion _ _ _).2 ⟨(modelsSingleton _ _).2 (by decide), + (modelsSingleton _ _).2 (by decide)⟩, (by intro p hp; cases hp), trivial⟩ + +theorem qualitativeUnmeasured012 : + inferentialSpecification (singleton (fun on : Bool => on = true)) (fun on => on ≠ false) ∧ + usesObservation (Facet.inferential (singleton (fun on : Bool => on = true)) (fun on => on ≠ false)) = false := by + refine ⟨grounds012Singleton _ ⟨⟨true, (modelsSingleton _ _).2 rfl⟩, ?_⟩, rfl⟩ + intro on hon hf + have ht := (modelsSingleton (fun on : Bool => on = true) on).1 hon + cases ht.symm.trans hf + + +theorem allStatusOnly012 : ∀ kind : StatusKind, + ¬ choiceSpecification identityRequirements identityImpl [.status kind] := + statusOnlyFails identityRequirements identityImpl + +/- A finite two-draw experiment assigns positive equal weights to both possible +outcomes. It models possibility and a stable conclusion, not empirical claims +about any physical random-number source. -/ +def drawWeight012 (_draw : Bool) : Nat := 1 +def randomTrial012 (draw : Bool) : Trial := + ⟨0, if draw then 1 else 2, if draw then 1 else 2⟩ + +theorem randomOutcomes012 : + drawWeight012 true > 0 ∧ drawWeight012 false > 0 ∧ + drawWeight012 true = drawWeight012 false ∧ + Reproduced (randomTrial012 true) (randomTrial012 false) ∧ + (randomTrial012 true).actualOutcome ≠ (randomTrial012 false).actualOutcome ∧ + (∀ draw, Verified (randomTrial012 draw) ∧ Bounded (randomTrial012 draw)) := by + refine ⟨by decide, by decide, rfl, rfl, by decide, ?_⟩ + intro draw + cases draw <;> simp [Verified, Bounded, randomTrial012] + + +/- Original tasks are fixed independently of the candidate substitutions below. -/ +def originalGlobalTask012 : AssessmentTask (Nat → Bool) := + .empirical [zeroRecord] (fun _ => True) allTrue (fun _ => True) +def originalLocalTask012 : AssessmentTask (Nat → Bool) := + .empirical [zeroRecord] (fun _ => True) (fun f => f 0 = true) (fun _ => True) + +def circularGlobalFacet012 : Facet (Nat → Bool) := .inferential (singleton allTrue) allTrue + +theorem circularGlobalConditional012 : FacetDischarged circularGlobalFacet012 := by + refine ⟨⟨fun _ => true, (modelsSingleton _ _).2 (fun _ => rfl)⟩, ?_⟩ + intro f hf + exact (modelsSingleton _ _).1 hf + +theorem circularSubstitutionRejected012 : + Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] (taskOfFacet circularGlobalFacet012) ∧ + ¬ NatureAppropriate originalGlobalTask012 circularGlobalFacet012 ∧ + ¬ Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] originalGlobalTask012 := by + have inappropriate : ¬ NatureAppropriate originalGlobalTask012 circularGlobalFacet012 := by + intro h + have equalPremises := h.1 + have originalMember : singleton (fun f => Compatible [zeroRecord] f ∧ True) allTrue := equalPremises ▸ (show singleton allTrue allTrue from rfl) + have equalClaims : allTrue = (fun f => Compatible [zeroRecord] f ∧ True) := originalMember + have claimedAll := (congrFun equalClaims (localGenerator 0)).mpr ⟨(zeroCompatible _).2 rfl, trivial⟩ + have bad := claimedAll 1 + cases bad + refine ⟨grounds012Singleton _ circularGlobalConditional012, inappropriate, ?_⟩ + intro h + exact inappropriate (h.2 circularGlobalFacet012 (by simp)).2.2.2.2 + +def observedPremises012 : Theory (Nat → Bool) := singleton (fun f => Compatible [zeroRecord] f ∧ True) +def observedInferenceFacet012 : Facet (Nat → Bool) := + .inferential observedPremises012 (fun f => f 0 = true) + +theorem observedInferenceChecked012 : FacetDischarged observedInferenceFacet012 := by + refine ⟨⟨localGenerator 0, (modelsSingleton _ _).2 ⟨(zeroCompatible _).2 rfl, trivial⟩⟩, ?_⟩ + intro f hf + exact (zeroCompatible _).1 ((modelsSingleton _ _).1 hf).1 + +theorem sameEmpiricalTaskTwoMethods012 : + Grounds012 (fun f => f 0 = true) canonicalArticulation [localFacet012] originalLocalTask012 ∧ + Grounds012 (fun f => f 0 = true) canonicalArticulation [observedInferenceFacet012] originalLocalTask012 := by + refine ⟨grounds012Singleton _ localFacetChecked012, ?_⟩ + refine ⟨by simp, ?_⟩ + intro f hf + cases List.mem_singleton.mp hf + exact ⟨rfl, canonicalArticulated _ observedInferenceChecked012, + canonicalFacetArticulated _, observedInferenceChecked012, rfl, rfl, fun _ _ => trivial⟩ + +/- The second coordinate remains unobserved. Switching assessment form cannot +remove that uncertainty responsibility from the original empirical task. -/ +def originalUncertaintyTask012 : AssessmentTask (Bool × Bool) := + .empirical [temperatureRecord, temperatureRecord] (fun _ => True) + (fun w => w.1 = true) (fun w => w.2 = true) +def uncertaintyBypassFacet012 : Facet (Bool × Bool) := + .inferential (singleton (fun w => Compatible [temperatureRecord, temperatureRecord] w ∧ True)) + (fun w => w.1 = true) + +theorem uncertaintyBypassChecked012 : FacetDischarged uncertaintyBypassFacet012 := by + refine ⟨⟨(true,false), (modelsSingleton _ _).2 ⟨temperatureCompatible false, trivial⟩⟩, ?_⟩ + intro w hw + exact ((modelsSingleton _ _).1 hw).1 temperatureRecord (by simp) + +theorem uncertaintySubstitutionRejected012 : + FacetDischarged uncertaintyBypassFacet012 ∧ + ¬ NatureAppropriate originalUncertaintyTask012 uncertaintyBypassFacet012 ∧ + ¬ Grounds012 (fun w : Bool × Bool => w.1 = true) canonicalArticulation + [uncertaintyBypassFacet012] originalUncertaintyTask012 := by + have inappropriate : ¬ NatureAppropriate originalUncertaintyTask012 uncertaintyBypassFacet012 := by + intro h + have bad := h.2.2 (true,false) (temperatureCompatible false) + cases bad + exact ⟨uncertaintyBypassChecked012, inappropriate, + fun h => inappropriate (h.2 uncertaintyBypassFacet012 (by simp)).2.2.2.2⟩ + +def selectedFactFacet012 : Facet Bool := + .empirical [switchRecord] (fun _ => True) switchPosition.commitment (fun _ => True) + +theorem valueFactSubstitutionRejected012 : + FacetDischarged selectedFactFacet012 ∧ valueSpecification switchPosition ∧ + ¬ Grounds012 switchPosition.commitment canonicalArticulation [selectedFactFacet012] (.value switchPosition) := by + refine ⟨switchEmpiricalDischarged, valueFulfilled012, ?_⟩ + intro h + exact (h.2 selectedFactFacet012 (by simp)).2.2.2.2 + +theorem inferentialContextSubstitutionRejected012 : + FacetDischarged (Facet.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) ∧ + ¬ Grounds012 (fun w : Bool => w = true) canonicalArticulation + [.inferential (singleton (fun w => w = true)) (fun w => w = true)] + (.inferential emptyTheory (fun w => w = true)) := by + refine ⟨⟨⟨true, (modelsSingleton _ _).2 rfl⟩, fun w hw => (modelsSingleton (fun w : Bool => w = true) w).1 hw⟩, ?_⟩ + intro h + have appropriate := (h.2 (.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) (by simp)).2.2.2.2 + have same : singleton (fun w : Bool => w = true) = emptyTheory := appropriate.1 + have bad : emptyTheory (fun w : Bool => w = true) := same ▸ (show singleton (fun w : Bool => w = true) (fun w => w = true) from rfl) + exact bad + + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.generationCases +organon.charter.overview#p2 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c +organon.charter.overview#p3 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c +organon.charter.self-transcendence#p1 sha256 f4ca590e2ae15e3882f70c7b2bc46a8911c97cee547c8b137b5493fbf862c8c0 +organon.charter.self-transcendence.orientation#p1 sha256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf +organon.charter.self-transcendence.non-finality#p1 sha256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8 +organon.charter.self-transcendence.limits#p2 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d +organon.relationships.terms#p1 sha256 61cb7ce4f2920f1aa6771502b87a66536ae0504acccfebd9dd23bcc62756eddf +-/ +theorem generationCases : + (Generative openPolicy ∧ + (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧ + (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1)))) ∧ + (neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy) ∧ + (Generative generatingSystem.policy ∧ + generatingSystem.policy.permitsVersion 0 0 ∧ + ¬ Expanded generatingSystem.current inflatedState ∧ + generatingSystem.current.inventory.length < inflatedState.inventory.length ∧ + generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧ + generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧ + generatingSystem.execute availableResources = some 6 ∧ + generatingSystem.execute { availableResources with experience := none } = none ∧ + generatingSystem.execute { availableResources with knowledge := none } = none ∧ + generatingSystem.execute { availableResources with collaborator := none } = none ∧ + generatingSystem.execute ⟨none, none, none⟩ = none ∧ + ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧ + generatingSystem.stableAction = generatingSystem.current ∧ + generatingSystem.requirementsMet generatingSystem.stableAction ∧ + generatingSystem.withinBudget generatingSystem.stableAction ∧ + ¬ generatingSystem.withinBudget inflatedState ∧ + StableReason generatingSystem.current inflatedState ∧ + (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧ + inflatedAnnouncement.owner = generatingSystem.owner ∧ + inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧ + inflatedAnnouncement.reportedNewOperation = .successor ∧ + inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧ + ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after)) ∧ + (generationSpecification openPolicy ∧ + Expanded baseState (collaborativeRevision availableResources) ∧ + ¬ Expanded baseState (collaborativeRevision { availableResources with collaborator := none }) ∧ + assistedExecution ⟨none, none, none⟩ = none) := + ⟨revisionWithoutProgress, permissionNotValuation, generationLimits, collaborativeProgress⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.generationLimits012 +organon.charter.self-transcendence.orientation#p1 sha256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf +organon.charter.self-transcendence.non-finality#p1 sha256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8 +organon.charter.self-transcendence.limits#p1 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d +organon.charter.self-transcendence.limits#p2 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +theorem generationLimits012 : + (neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy) ∧ + (Generative openPolicy ∧ + (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧ + (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1)))) ∧ + (Generative generatingSystem.policy ∧ + generatingSystem.policy.permitsVersion 0 0 ∧ + ¬ Expanded generatingSystem.current inflatedState ∧ + generatingSystem.current.inventory.length < inflatedState.inventory.length ∧ + generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧ + generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧ + generatingSystem.execute availableResources = some 6 ∧ + generatingSystem.execute { availableResources with experience := none } = none ∧ + generatingSystem.execute { availableResources with knowledge := none } = none ∧ + generatingSystem.execute { availableResources with collaborator := none } = none ∧ + generatingSystem.execute ⟨none, none, none⟩ = none ∧ + ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧ + generatingSystem.stableAction = generatingSystem.current ∧ + generatingSystem.requirementsMet generatingSystem.stableAction ∧ + generatingSystem.withinBudget generatingSystem.stableAction ∧ + ¬ generatingSystem.withinBudget inflatedState ∧ + StableReason generatingSystem.current inflatedState ∧ + (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧ + inflatedAnnouncement.owner = generatingSystem.owner ∧ + inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧ + inflatedAnnouncement.reportedNewOperation = .successor ∧ + inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧ + ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after)) ∧ + (generationSpecification openPolicy ∧ + Expanded baseState (collaborativeRevision availableResources) ∧ + ¬ Expanded baseState (collaborativeRevision { availableResources with collaborator := none }) ∧ + assistedExecution ⟨none, none, none⟩ = none) ∧ + (Grounds012 transitionAchievement canonicalArticulation [transitionFacet] (taskOfFacet transitionFacet) ∧ + Compatible [transitionPerformanceRecord] .extend ∧ + transitionAchievement .extend ∧ ¬ transitionAchievement .inflate ∧ + ¬ Supports [transitionReportRecord] transitionAchievement) ∧ + (∀ kind : InventoryKind, + Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .copy ∧ + ¬ Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .successor) := + ⟨permissionNotValuation, revisionWithoutProgress, generationLimits, collaborativeProgress, achievementSupported012, inventoryCases012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.consistencyCases +organon.charter.consistency#p1 sha256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42 +organon.charter.consistency.meaning#p1 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75 +-/ +theorem consistencyCases : + (Satisfiable (singleton premiseP) ∧ Satisfiable (singleton premiseRule) ∧ + Satisfiable (singleton premiseNotQ) ∧ ¬ Satisfiable jointTheory) ∧ + ((Consequence emptyTheory (assumptionContext true) () true ∧ + Consequence emptyTheory (assumptionContext false) () false) ∧ + (Consequence emptyTheory (meaningContext true) () true ∧ + Consequence emptyTheory (meaningContext false) () false) ∧ + (Consequence emptyTheory (scopeContext true) () true ∧ + Consequence emptyTheory (scopeContext false) () false) ∧ + (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w)) ∧ + (¬ TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (meaningContext true)) (contextSnapshot (meaningContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (scopeContext true)) (contextSnapshot (scopeContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (scopeContext true) 0) (contextSnapshot (scopeContext true) 1) false ∧ + (TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) true ∧ + ¬ Models (assumptionContext false).assumptions true)) ∧ + (Satisfiable (revisionSlice 0) ∧ Satisfiable (revisionSlice 1) ∧ + ¬ Satisfiable (union (revisionSlice 0) (revisionSlice 1))) ∧ + ((∀ time, Consistent (revisionSlice time) broadBoolContext) ∧ + ¬ Consistent (union (revisionSlice 0) (revisionSlice 1)) broadBoolContext) ∧ + (∀ p q : Claim Bool, + ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r) ∧ + (Consequence jointTheory jointContext012 () true ∧ + Consequence jointTheory jointContext012 () false ∧ + ¬ Consistent jointTheory jointContext012) := + ⟨jointConflict, contextDifferences, hiddenContextChangeRejected, revisionCanReverse, sliceConsistency, semanticOrder012, jointImplicationConflict012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.consistencyLimits012 +organon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75 +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +theorem consistencyLimits012 : + ((Consequence emptyTheory (assumptionContext true) () true ∧ + Consequence emptyTheory (assumptionContext false) () false) ∧ + (Consequence emptyTheory (meaningContext true) () true ∧ + Consequence emptyTheory (meaningContext false) () false) ∧ + (Consequence emptyTheory (scopeContext true) () true ∧ + Consequence emptyTheory (scopeContext false) () false) ∧ + (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w)) ∧ + ((∃ budget : Nat, 4 ≤ budget ∧ budget ≤ 6) ∧ + ¬ ((fun n : Nat => 4 ≤ n) = (fun n : Nat => n ≤ 6))) ∧ + (Consistent (singleton (fun w : Bool => w = true)) broadBoolContext ∧ + ¬ Models (singleton (fun w : Bool => w = true)) false ∧ + Consistent (emptyTheory : Theory Bool) broadBoolContext ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧ + (Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧ + (Consistent (union (singleton (fun n : Nat => 4 ≤ n)) (singleton (fun n => n ≤ 6))) tensionContext012) := + ⟨contextDifferences, tensionWithoutContradiction, explicitlyConsistentLimits, compatibilityNotEntailment, tensionConsistent012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.reflexivityCases012 +organon.charter.reflexivity#p1 sha256 13293b45c2fa89068c68ae7ef3c5df38f0efadb3ef3873d78a5ba67d9691a757 +organon.charter.reflexivity.meaning#p1 sha256 8a2caede01a43d8b6c60b54c78ac089c51868e9956f316948077ccee2e45c9cc +organon.charter.reflexivity.limits#p1 sha256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +theorem reflexivityCases012 : + (reflexivitySpecification ((ownRules 0).map legacyRule) (fun s => s.owner = 0) + (legacyPerformed (ownRules 0) (completeOwnWork 0)) ∧ + (∀ phase, Performed (completeOwnWork 0) (.process 0 0 phase) .assessment) ∧ + Performed (completeOwnWork 0) (.system 0) .assessment ∧ + reflexivitySpecification ([applicationRule].map legacyRule) (fun s => s.owner = 0) + (legacyPerformed [applicationRule] applicationWork) ∧ + ¬ Performed applicationWork (.system 0) .assessment) ∧ + (Grounds012 (fun enabled => GroundsProvision012 enabled) canonicalArticulation [.value groundsPosition012] (.value groundsPosition012) ∧ + groundsPosition012.limits true ∧ groundsPosition012.relevantCriticism true) ∧ + (Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0) ∧ + groundsExperiment012 true = false ∧ groundsExperiment012 false = true ∧ + groundsPosition012.outcome true true = groundsExperiment012 true ∧ + groundsPosition012.outcome true false = groundsExperiment012 false) := + ⟨reflexiveTargets012, groundsOnGrounds012, groundsRationaleExperiment012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.reflexivityLimits012 +organon.charter.reflexivity.limits#p1 sha256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.grounds#p1 sha256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6 +-/ +theorem reflexivityLimits012 : + (selfTest [1] = true ∧ ownArithmeticPrinciple 0 = false ∧ + ¬ (∀ n, ownArithmeticPrinciple n = true)) ∧ + (localGenerator 0 0 = true ∧ localGenerator 0 1 = false ∧ + Compatible [zeroRecord] (localGenerator 0) ∧ + ¬ Supports [zeroRecord] allTrue ∧ OwnedRevisionExample) ∧ + (Generative openPolicy ∧ ¬ Reflexive 0 (ownRules 0) []) ∧ + (CompleteCharter012 CoreReader.Integration.actualSystem CoreReader.Integration.actual ∧ + Admissible CoreReader.Integration.held CoreReader.Integration.context CoreReader.Integration.actual ∧ + Compatible [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.actual ∧ + Articulated (canonicalArticulation CoreReader.Integration.unsupportedCapabilityFacet) ∧ + ¬ Supports [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.capability ∧ + ¬ Grounds012 CoreReader.Integration.capability canonicalArticulation + [CoreReader.Integration.unsupportedCapabilityFacet] + (taskOfFacet CoreReader.Integration.unsupportedCapabilityFacet)) ∧ + (generationSpecification openPolicy ∧ openPolicy.revisable ⟨.principle,0⟩ ∧ + selfExemptPerformed012 ⟨0,1⟩ 1 1 true ∧ + selfExemptRule012.applicable 0 ∧ + ¬ reflexivitySpecification [selfExemptRule012] (fun target => target = 0) selfExemptPerformed012) := + ⟨selfTestDoesNotProve, selfOriginDoesNotSupport, generationNotReflexivity, charterWithoutGrounds012, openSelfExempt012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.groundsCases012 +organon.grounds#p1 sha256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6 +organon.grounds.assessment#p1 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +-/ +theorem groundsCases012 : + (Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧ + Articulated (canonicalArticulation globalFacet012) ∧ + ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧ + ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012)) ∧ + (Articulated uninformativeArgument ∧ + ¬ Entails uninformativeArgument.assumptions (fun w : Bool => w = true)) ∧ + (Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] (taskOfFacet circularGlobalFacet012) ∧ + ¬ NatureAppropriate originalGlobalTask012 circularGlobalFacet012 ∧ + ¬ Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] originalGlobalTask012) := + ⟨scopeStrength012, articulationNotSupport, circularSubstitutionRejected012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.empiricalCases012 +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +-/ +theorem empiricalCases012 : + (Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧ + Articulated (canonicalArticulation globalFacet012) ∧ + ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧ + ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012)) ∧ + (temperatureRecord.test (true,false) = true ∧ + Compatible [temperatureRecord,temperatureRecord] (true,false) ∧ + Compatible [temperatureRecord,temperatureRecord] (true,true) ∧ + ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + Compatible [actionRecord,actionRecord] (true,0) ∧ + Compatible [actionRecord,actionRecord] (true,3) ∧ + ¬ Supports [actionRecord] announcementPosition.consequence ∧ + ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧ + ¬ ValueProcedure announcementPosition) ∧ + (empiricalSpecification [temperatureRecord, temperatureRecord] (fun _ => True) + (fun w => w.1 = true) (fun w => w.2 = true ∨ w.2 = false) ∧ + Compatible [temperatureRecord, temperatureRecord] (true,true) ∧ + Compatible [temperatureRecord, temperatureRecord] (true,false)) ∧ + (Grounds012 (fun f => f 0 = true) canonicalArticulation [localFacet012] originalLocalTask012 ∧ + Grounds012 (fun f => f 0 = true) canonicalArticulation [observedInferenceFacet012] originalLocalTask012) ∧ + (FacetDischarged uncertaintyBypassFacet012 ∧ + ¬ NatureAppropriate originalUncertaintyTask012 uncertaintyBypassFacet012 ∧ + ¬ Grounds012 (fun w : Bool × Bool => w.1 = true) canonicalArticulation + [uncertaintyBypassFacet012] originalUncertaintyTask012) := + ⟨scopeStrength012, measurementRepeatNotSupport, uncertainSupported012, sameEmpiricalTaskTwoMethods012, uncertaintySubstitutionRejected012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.inferentialCases012 +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +theorem inferentialCases012 : + (inferentialSpecification (singleton (fun n : Nat => n = 2)) (fun n => n + 1 = 3) ∧ + InferenceExamined (emptyTheory : Theory Bool) (fun w => w = true) false ∧ + Models (emptyTheory : Theory Bool) false ∧ ¬ ((fun w : Bool => w = true) false)) ∧ + (Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧ + (FacetDischarged (Facet.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) ∧ + ¬ Grounds012 (fun w : Bool => w = true) canonicalArticulation + [.inferential (singleton (fun w => w = true)) (fun w => w = true)] + (.inferential emptyTheory (fun w => w = true))) := + ⟨inferenceChecked012, compatibilityNotEntailment, inferentialContextSubstitutionRejected012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.valueCases012 +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +-/ +theorem valueCases012 : + (valueSpecification switchPosition) ∧ + (announcementPosition.reasons ≠ [] ∧ announcementPosition.commitment (true,0) ∧ + (∀ reason, reason ∈ announcementPosition.reasons → reason (true,0) announcementPosition.adopted) ∧ + ¬ announcementPosition.consequence (true,0) ∧ ¬ ValueProcedure announcementPosition) ∧ + (¬ ValueProcedure closedPosition012) ∧ + (ValueProcedure switchPosition ∧ + Satisfiable switchPosition.starting ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧ + (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧ + (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition)) ∧ + (FacetDischarged selectedFactFacet012 ∧ valueSpecification switchPosition ∧ + ¬ Grounds012 switchPosition.commitment canonicalArticulation [selectedFactFacet012] (.value switchPosition)) := + ⟨valueFulfilled012, announcementNotBudgetReason, closedCriticism012, valueWithoutSelfProof, valueFactSubstitutionRejected012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.groundsLimits012 +organon.grounds.assessment#p1 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +-/ +theorem groundsLimits012 : + (Articulated clearFalseArgument012 ∧ ¬ Models clearFalseArgument012.assumptions false) ∧ + (temperatureRecord.test (true,false) = true ∧ + Compatible [temperatureRecord,temperatureRecord] (true,false) ∧ + Compatible [temperatureRecord,temperatureRecord] (true,true) ∧ + ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + Compatible [actionRecord,actionRecord] (true,0) ∧ + Compatible [actionRecord,actionRecord] (true,3) ∧ + ¬ Supports [actionRecord] announcementPosition.consequence ∧ + ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧ + ¬ ValueProcedure announcementPosition) ∧ + (valueSpecification switchPosition ∧ + Compatible [valueNeutralRecord012] false ∧ + ¬ Supports [valueNeutralRecord012] switchPosition.commitment ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment) ∧ + (ValueProcedure switchPosition ∧ + Satisfiable switchPosition.starting ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧ + (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧ + (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition)) ∧ + (ClaimNoStronger (fun f : Nat → Bool => f 0 = true) allTrue ∧ + ¬ ClaimNoStronger allTrue (fun f : Nat → Bool => f 0 = true) ∧ + valueSpecification switchPosition) := + ⟨clearFalseReason012, measurementRepeatNotSupport, valueNotFact012, valueWithoutSelfProof, qualitativeProportionality012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.scopeCases012 +organon.grounds.scope#p1 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.scope#p2 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.scope#p3 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +-/ +theorem scopeCases012 : + (scopeSpecification localScopeAccount012) ∧ + ((∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧ + (fun _ : Nat => true) 1 ≠ localGenerator 0 1) := + ⟨scopeFulfilled012, hiddenDifference⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.scopeLimits012 +organon.grounds.scope#p1 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.scope#p2 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.scope#p3 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870 +-/ +theorem scopeLimits012 : + ((∃ outside : Nat, outside ≠ 0) ∧ + Compatible [zeroRecord] (fun _ => true) ∧ + Compatible [zeroRecord] (localGenerator 0) ∧ + allTrue (fun _ => true) ∧ ¬ allTrue (localGenerator 0) ∧ + ¬ Supports [zeroRecord] allTrue) ∧ + ((∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧ + (fun _ : Nat => true) 1 ≠ localGenerator 0 1) ∧ + ([zeroRecord].length = 1 ∧ + (∃ f, Compatible [zeroRecord] f) ∧ + Supports [zeroRecord] (fun f => f 0 = true) ∧ + ¬ Supports [zeroRecord] allTrue) ∧ + (let a : Trial := ⟨0,1,1⟩ + let b : Trial := ⟨0,2,2⟩ + Reproduced a b ∧ a.actualOutcome ≠ b.actualOutcome ∧ Bounded a ∧ Bounded b) ∧ + ((Verified ⟨0,1,1⟩ ∧ Verified ⟨1,1,1⟩ ∧ ¬ Reproduced ⟨0,1,1⟩ ⟨1,1,1⟩) ∧ + (Reproduced ⟨0,1,1⟩ ⟨0,3,2⟩ ∧ ¬ Verified ⟨0,3,2⟩ ∧ ¬ Bounded ⟨0,3,2⟩) ∧ + (Bounded ⟨0,1,1⟩ ∧ Bounded ⟨0,2,0⟩ ∧ ¬ Verified ⟨0,2,0⟩)) ∧ + (FacetDischarged arithmeticFacet ∧ usesObservation arithmeticFacet = false) ∧ + (inferentialSpecification (singleton (fun on : Bool => on = true)) (fun on => on ≠ false) ∧ + usesObservation (Facet.inferential (singleton (fun on : Bool => on = true)) (fun on => on ≠ false)) = false) ∧ + (drawWeight012 true > 0 ∧ drawWeight012 false > 0 ∧ + drawWeight012 true = drawWeight012 false ∧ + Reproduced (randomTrial012 true) (randomTrial012 false) ∧ + (randomTrial012 true).actualOutcome ≠ (randomTrial012 false).actualOutcome ∧ + (∀ draw, Verified (randomTrial012 draw) ∧ Bounded (randomTrial012 draw))) := + ⟨localNotUniversal, hiddenDifference, singleObservation, variableOutcomesStableBound, verificationReproductionStability, noUniversalChain, qualitativeUnmeasured012, randomOutcomes012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.capabilityCases012 +organon.grounds.capabilities#p1 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0 +organon.grounds.capabilities#p2 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0 +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +theorem capabilityCases012 : + (capabilitySpecification outputOnlyProcess OutputContract ∧ + capabilitySpecification explainedProcess FullProcessContract ∧ + (∃ certificate : ExternalCertificate outputOnlyProcess, + certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧ + ¬ ExplanationContract outputOnlyProcess) ∧ + (OwnCapability012 7 7 outputOnlyProcess OutputContract) ∧ + (explainedWithoutVariation012.process = mechanismResponder012.process ∧ + FullProcessContract explainedWithoutVariation012.process ∧ + ¬ UnderstandingApplication012 explainedWithoutVariation012 ∧ + UnderstandingApplication012 mechanismResponder012 ∧ + Grounds012 UnderstandingApplication012 canonicalArticulation + [understandingFacet012 mechanismResponder012] (understandingTask012 mechanismResponder012) ∧ + ¬ Grounds012 UnderstandingApplication012 canonicalArticulation + [understandingFacet012 explainedWithoutVariation012] (understandingTask012 explainedWithoutVariation012)) := + ⟨capabilityFulfilled012, ownCapability012, understandingApplicationCases012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.capabilityLimits012 +organon.grounds.capabilities#p1 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0 +organon.grounds.capabilities#p2 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0 +-/ +theorem capabilityLimits012 : + (capabilitySpecification outputOnlyProcess OutputContract ∧ + capabilitySpecification explainedProcess FullProcessContract ∧ + (∃ certificate : ExternalCertificate outputOnlyProcess, + certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧ + ¬ ExplanationContract outputOnlyProcess) ∧ + (∀ kind : InventoryKind, + Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .copy ∧ + ¬ Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .successor) ∧ + (Generative generatingSystem.policy ∧ + generatingSystem.policy.permitsVersion 0 0 ∧ + ¬ Expanded generatingSystem.current inflatedState ∧ + generatingSystem.current.inventory.length < inflatedState.inventory.length ∧ + generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧ + generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧ + generatingSystem.execute availableResources = some 6 ∧ + generatingSystem.execute { availableResources with experience := none } = none ∧ + generatingSystem.execute { availableResources with knowledge := none } = none ∧ + generatingSystem.execute { availableResources with collaborator := none } = none ∧ + generatingSystem.execute ⟨none, none, none⟩ = none ∧ + ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧ + generatingSystem.stableAction = generatingSystem.current ∧ + generatingSystem.requirementsMet generatingSystem.stableAction ∧ + generatingSystem.withinBudget generatingSystem.stableAction ∧ + ¬ generatingSystem.withinBudget inflatedState ∧ + StableReason generatingSystem.current inflatedState ∧ + (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧ + inflatedAnnouncement.owner = generatingSystem.owner ∧ + inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧ + inflatedAnnouncement.reportedNewOperation = .successor ∧ + inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧ + ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after)) := + ⟨capabilityFulfilled012, inventoryCases012, generationLimits⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.choiceCases012 +organon.grounds.implementations#p1 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c +organon.grounds.implementations#p2 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c +organon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870 +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +theorem choiceCases012 : + (identityImpl.conventional = true ∧ identityImpl.established = true ∧ + JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output]) ∧ + (Relevant identityRequirements identityImpl (.method .explanation) ∧ + Relevant identityRequirements identityImpl (.method .applicability) ∧ + Relevant identityRequirements identityImpl (.method .simplicity) ∧ + Relevant identityRequirements identityImpl (.method .procedure) ∧ + (Relevant identityRequirements cheapSuccessor (.method .simplicity) ∧ + ¬ JustifiedChoice identityRequirements cheapSuccessor [.method .simplicity])) ∧ + (Articulated priorityArticulation ∧ AssessmentAccurate false ∧ + (∀ selected, Models statusFacts selected) ∧ + priorityClaim .identity ∧ ¬ priorityClaim .successor ∧ + ¬ Entails statusFacts priorityClaim ∧ + ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧ + ((∀ n, identityImpl.run n = wrongExplanation012.run n) ∧ + Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧ + Relevant identityRequirements identityImpl (.method .explanation) ∧ + ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation)) ∧ + (¬ choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation + [.status .standing] ∧ + choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation + [.method .output]) ∧ + (∀ kind : StatusKind, + ¬ choiceSpecification identityRequirements identityImpl [.status kind]) := + ⟨conventionWithReason, internalReasons, statusAssessmentNonEntailment, internalReasonDistinguishes012, ownPhilosophyStatus012, allStatusOnly012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.choiceLimits012 +organon.grounds.implementations#p1 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c +organon.grounds.implementations#p2 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c +organon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870 +-/ +theorem choiceLimits012 : + ((∀ candidate, Feasible identityRequirements (implementation candidate) ↔ candidate = .identity) ∧ + JustifiedChoice identityRequirements identityImpl objectiveReason) ∧ + (identityImpl.conventional = true ∧ identityImpl.established = true ∧ + JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output]) ∧ + ((∀ n, identityImpl.run n = wrongExplanation012.run n) ∧ + Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧ + Relevant identityRequirements identityImpl (.method .explanation) ∧ + ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation)) ∧ + (JustifiedChoice identityRequirements identityImpl objectiveReason ∧ + identityImpl.run 0 ≠ successorImpl.run 0) ∧ + ((∀ x, x = 0 → identityImpl.run x = changedOutsideZero.run x) ∧ + identityImpl.run 1 ≠ changedOutsideZero.run 1) ∧ + ((Articulated priorityArticulation ∧ AssessmentAccurate false ∧ + (∀ selected, Models statusFacts selected) ∧ + priorityClaim .identity ∧ ¬ priorityClaim .successor ∧ + ¬ Entails statusFacts priorityClaim ∧ + ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧ + PolicyIndependenceExample) := + ⟨singleFeasible, conventionWithReason, internalReasonDistinguishes012, openNotEquivalent, localNotGlobal, generalGroundsNotChoice⟩ + +end CoreReader.Adopted diff --git a/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Agency.lean b/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Agency.lean new file mode 100644 index 0000000..ca509c4 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Agency.lean @@ -0,0 +1,250 @@ +import CoreReader.Reflexivity + +namespace CoreReader.Agency + +inductive FormKind | organization | method | principle | appearance | artifact + deriving DecidableEq, Repr + +structure Form where + kind : FormKind + version : Nat + deriving DecidableEq, Repr + +inductive Aim | expandUnderstandingAndConstruction | preserveSafeOperation + deriving DecidableEq, Repr + +/- A policy records an adopted valuation, current forms, and permission. It does not assert that valuation is correct or enacted. -/ +structure Policy where + worthPursuing : Aim → Prop + current : Form → Prop + revisable : Form → Prop + permitsVersion : Nat → Nat → Prop + +/- The normative specification keeps valuation and revisability separate from realized transitions. -/ +def Generative (p : Policy) : Prop := + p.worthPursuing .expandUnderstandingAndConstruction ∧ + ∀ f, p.current f → p.revisable f + +def openPolicy : Policy where + worthPursuing a := a = .expandUnderstandingAndConstruction ∨ a = .preserveSafeOperation + current f := f.version = 0 + revisable _ := True + permitsVersion _ _ := True + +def neutralPolicy : Policy := { openPolicy with worthPursuing := fun _ => False } + +/- Permitting a real version change does not supply an adopted value position. -/ +theorem permissionNotValuation : + neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy := by + simp [neutralPolicy, openPolicy, Generative] + +/- This is an explicit consequence of the adopted specification, not evidence of actual revision. -/ +theorem revisabilityCovers (p : Policy) (h : Generative p) (k : FormKind) (v : Nat) + (hc : p.current ⟨k, v⟩) : p.revisable ⟨k, v⟩ := h.2 _ hc + +inductive Operation | copy | successor + deriving DecidableEq, Repr + +def Operation.run : Operation → Nat → Nat + | .copy, n => n + | .successor, n => n + 1 + +inductive InventoryKind | document | term | tool | artifact + deriving DecidableEq, Repr + +structure Item where + kind : InventoryKind + content : Operation + deriving DecidableEq, Repr + +/- Available represented operations are the contents present, not their number of occurrences. -/ +def Available (xs : List Item) (op : Operation) : Prop := + ∃ item ∈ xs, item.content = op + +/- Duplicating any inventory category preserves exactly the represented operation content. -/ +theorem inventoryNotCapability (kind : InventoryKind) (ops : List Operation) (op : Operation) : + Available ((ops.map fun x => Item.mk kind x) ++ (ops.map fun x => Item.mk kind x)) op ↔ + Available (ops.map fun x => Item.mk kind x) op := by + simp only [Available, List.mem_append] + constructor + · rintro ⟨x, hx | hx, hop⟩ <;> exact ⟨x, hx, hop⟩ + · rintro ⟨x, hx, hop⟩ + exact ⟨x, Or.inl hx, hop⟩ + +structure State where + understood : List Operation + constructed : List Operation + inventory : List Item + abstractionLayers : List Operation + vocabulary : List Operation + deriving DecidableEq, Repr + +/- A gain must identify an operation newly understood or constructed; this is a disclosed finite capability representation. -/ +def Expanded (before after : State) : Prop := + (∃ op, op ∈ after.understood ∧ op ∉ before.understood) ∨ + (∃ op, op ∈ after.constructed ∧ op ∉ before.constructed) + +def baseState : State := + ⟨[.copy], [.copy], [⟨.artifact, .copy⟩], [.copy], [.copy]⟩ + +def inflatedState : State := + { baseState with + inventory := baseState.inventory ++ baseState.inventory + abstractionLayers := [.copy, .copy] + vocabulary := [.copy, .copy] } + +def stableTrace (_time : Nat) : State := baseState + +/- A revisable policy can govern an unchanged trace; no improvement is hidden in revisability. -/ +theorem revisionWithoutProgress : + Generative openPolicy ∧ + (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧ + (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1))) := by + simp [Generative, openPolicy, stableTrace, Expanded] + +structure ExternalResources where + experience : Option Nat + knowledge : Option Nat + collaborator : Option Nat + deriving DecidableEq, Repr + +/- This interpreter actually needs all three external inputs to produce the modeled result. -/ +def assistedExecution (r : ExternalResources) : Option Nat := do + let e ← r.experience + let k ← r.knowledge + let c ← r.collaborator + pure (Operation.copy.run (e + k + c)) + +def availableResources : ExternalResources := ⟨some 1, some 2, some 3⟩ + +/- Stability has a concrete stated reason in this workload: preserve its operation while staying within the one-item budget. -/ +def StableReason (before proposed : State) : Prop := + before.constructed = proposed.constructed ∧ + before.inventory.length ≤ 1 ∧ ¬ proposed.inventory.length ≤ 1 + +/- The policy, current capabilities, execution interface and workload constraints belong to one generating system. -/ +structure GeneratingSystem where + owner : Nat + policy : Policy + current : State + execute : ExternalResources → Option Nat + applicationBudget : Nat + requiredOperations : List Operation +/- The modeled system uses the assisted interpreter under a one-item budget and a copy-operation requirement. -/ +def generatingSystem : GeneratingSystem where + owner := 0 + policy := openPolicy + current := baseState + execute := assistedExecution + applicationBudget := 1 + requiredOperations := [.copy] +/- A stable action retains this system's own current state. -/ +def GeneratingSystem.stableAction (system : GeneratingSystem) : State := system.current +def GeneratingSystem.requirementsMet (system : GeneratingSystem) (state : State) : Prop := + ∀ operation, operation ∈ system.requiredOperations → operation ∈ state.constructed +def GeneratingSystem.withinBudget (system : GeneratingSystem) (state : State) : Prop := + state.inventory.length ≤ system.applicationBudget +/- An expansion report identifies the actual before/after states and the operation/performance it asserts was added. -/ +structure Announcement where + owner : Nat + before : State + after : State + reportedNewOperation : Operation + input : Nat + expectedOutput : Nat + deriving DecidableEq, Repr +/- Reports are generated by this system and identify its actual current state as their baseline. -/ +def GeneratingSystem.report (system : GeneratingSystem) (after : State) + (operation : Operation) (input expectedOutput : Nat) : Announcement := + ⟨system.owner, system.current, after, operation, input, expectedOutput⟩ +/- Report content is interpreted against those very states and the named operation's actual behavior. -/ +def Announcement.claim (report : Announcement) : Prop := + report.reportedNewOperation ∈ report.after.constructed ∧ + report.reportedNewOperation ∉ report.before.constructed ∧ + report.reportedNewOperation.run report.input = report.expectedOutput +/- A true report of this form entails a represented construction expansion. -/ +theorem announcementClaimImpliesExpansion (report : Announcement) (h : report.claim) : + Expanded report.before report.after := Or.inr ⟨report.reportedNewOperation, h.1, h.2.1⟩ +/- This concrete self-report asserts a successor operation for the actual inventory-only inflation. -/ +def inflatedAnnouncement : Announcement := generatingSystem.report inflatedState .successor 0 1 +/- The report asserts a real successor result but its named operation is absent from its own after-state. -/ +theorem inflatedAnnouncementRefuted : + inflatedAnnouncement.before = baseState ∧ inflatedAnnouncement.after = inflatedState ∧ + inflatedAnnouncement.reportedNewOperation = .successor ∧ + inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧ + ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after := by + simp [inflatedAnnouncement, GeneratingSystem.report, generatingSystem, Announcement.claim, Expanded, baseState, inflatedState] + +/- These transitions share one initial state; only extension adds an actual new operation. -/ +inductive TransitionCase | inflate | extend + deriving DecidableEq, Repr + +def extendedState : State := + { baseState with understood := [.copy, .successor], constructed := [.copy, .successor] } +def transitionBefore (_transition : TransitionCase) : State := baseState +def transitionAfter : TransitionCase → State + | .inflate => inflatedState + | .extend => extendedState +/- Both alternatives are assessed under the same concrete input condition. -/ +def transitionInput (_transition : TransitionCase) : Nat := 0 +def transitionAnnouncement (transition : TransitionCase) : Announcement := + generatingSystem.report (transitionAfter transition) .successor (transitionInput transition) 1 + +/- Eleven boundary branches share a content-bearing trace and executable dependency model. They do not assert a universal law of human capability. -/ +theorem generationLimits : + Generative generatingSystem.policy ∧ + generatingSystem.policy.permitsVersion 0 0 ∧ + ¬ Expanded generatingSystem.current inflatedState ∧ + generatingSystem.current.inventory.length < inflatedState.inventory.length ∧ + generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧ + generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧ + generatingSystem.execute availableResources = some 6 ∧ + generatingSystem.execute { availableResources with experience := none } = none ∧ + generatingSystem.execute { availableResources with knowledge := none } = none ∧ + generatingSystem.execute { availableResources with collaborator := none } = none ∧ + generatingSystem.execute ⟨none, none, none⟩ = none ∧ + ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧ + generatingSystem.stableAction = generatingSystem.current ∧ + generatingSystem.requirementsMet generatingSystem.stableAction ∧ + generatingSystem.withinBudget generatingSystem.stableAction ∧ + ¬ generatingSystem.withinBudget inflatedState ∧ + StableReason generatingSystem.current inflatedState ∧ + (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧ + inflatedAnnouncement.owner = generatingSystem.owner ∧ + inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧ + inflatedAnnouncement.reportedNewOperation = .successor ∧ + inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧ + ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after) := by + simp [generatingSystem, GeneratingSystem.stableAction, GeneratingSystem.requirementsMet, + GeneratingSystem.withinBudget, GeneratingSystem.report, Generative, openPolicy, Expanded, + baseState, inflatedState, assistedExecution, availableResources, Operation.run, + StableReason, inflatedAnnouncement, Announcement.claim] + +/- The empty work log omits an actually applicable system assessment despite an open generative policy. -/ +theorem generationNotReflexivity : + Generative openPolicy ∧ ¬ Reflexive 0 (ownRules 0) [] := by + constructor + · simp [Generative, openPolicy] + · intro h + have bad := noSelfExemption 0 (ownRules 0) [] h (assessingRule 0) (by simp [ownRules]) + (.system 0) rfl (by simp [assessingRule, ownSubjects]) + simp [Performed] at bad + +/- The same proposed arithmetic principle is used in the self-test and in the universal correctness claim. -/ +def ownArithmeticPrinciple (n : Nat) : Bool := decide (n + 1 = 2 * n) + +def selfTest (samples : List Nat) : Bool := samples.all ownArithmeticPrinciple + +/- A genuine evaluation on the selected sample succeeds, while the same principle fails at zero. -/ +theorem selfTestDoesNotProve : + selfTest [1] = true ∧ ownArithmeticPrinciple 0 = false ∧ + ¬ (∀ n, ownArithmeticPrinciple n = true) := by + constructor + · decide + constructor + · decide + · intro h + have bad := h 0 + contradiction + +end CoreReader.Agency diff --git a/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Choice.lean b/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Choice.lean new file mode 100644 index 0000000..07e3817 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Choice.lean @@ -0,0 +1,266 @@ +import CoreReader.Evidence + +namespace CoreReader.Choice +open CoreReader.Logic CoreReader.Evidence + +inductive StatusKind | name | convention | standing + deriving DecidableEq, Repr + +inductive MethodReason | output | explanation | applicability | simplicity | procedure + deriving DecidableEq, Repr + +inductive Reason | status (kind : StatusKind) | method (kind : MethodReason) + deriving DecidableEq, Repr + +/- An implementation has observable behavior, a stated domain, an explanation formula and an execution trace. -/ +structure Implementation where + name : String + conventional : Bool + established : Bool + run : Nat → Nat + cost : Nat + domain : Nat → Prop + explanation : Nat → Nat + trace : Nat → List Nat + +/- An application selects relevant objectives and constraints; no universal ranking or score is prescribed. -/ +structure Requirements where + inputs : Nat → Prop + expected : Nat → Nat + budget : Nat + values : MethodReason → Prop + +/- These are explicit, content-based interpretations of possible method reasons in this application. -/ +def MethodContent (req : Requirements) (i : Implementation) : MethodReason → Prop + | .output => ∀ x, req.inputs x → i.run x = req.expected x + | .explanation => ∀ x, req.inputs x → i.explanation x = i.run x + | .applicability => ∀ x, req.inputs x → i.domain x + | .simplicity => i.cost ≤ req.budget + | .procedure => ∀ x, req.inputs x → (i.trace x).getLast? = some (i.run x) + +/- The extra choice commitment requires both selected relevance and actual reason content; pure status supplies neither. -/ +def Relevant (req : Requirements) (i : Implementation) : Reason → Prop + | .status _ => False + | .method kind => req.values kind ∧ MethodContent req i kind + +def Feasible (req : Requirements) (i : Implementation) : Prop := + (∀ x, req.inputs x → i.run x = req.expected x) ∧ i.cost ≤ req.budget + +/- In this application, a relevant reason is eligible only after its stated output and budget requirements hold. -/ +def JustifiedChoice (req : Requirements) (i : Implementation) (reasons : List Reason) : Prop := + Feasible req i ∧ ∃ reason ∈ reasons, Relevant req i reason + +/- This proves the structural effect of the adopted choice commitment for each of its three status-only cases. -/ +theorem statusOnlyFails (req : Requirements) (i : Implementation) (k : StatusKind) : + ¬ JustifiedChoice req i [.status k] := by + rintro ⟨_, reason, hr, hv⟩ + simp only [List.mem_singleton] at hr + subst reason + exact hv + +def identityImpl : Implementation where + name := "Existing identity implementation" + conventional := true + established := true + run n := n + cost := 1 + domain _ := True + explanation n := n + trace n := [n] + +def successorImpl : Implementation where + name := "Successor implementation" + conventional := false + established := false + run n := n + 1 + cost := 2 + domain _ := True + explanation n := n + 1 + trace n := [n, n + 1] + +def changedOutsideZero : Implementation := + { identityImpl with + name := "Changed outside zero" + conventional := false + established := false + run := fun n => if n = 0 then 0 else n + 1 + explanation := fun n => if n = 0 then 0 else n + 1 + trace := fun n => [if n = 0 then 0 else n + 1] } + +def identityRequirements : Requirements where + inputs _ := True + expected n := n + budget := 1 + values _ := True + +def objectiveReason : List Reason := [.method .output] + +theorem identityOutputReason : Relevant identityRequirements identityImpl (.method .output) := by + exact ⟨trivial, fun _ _ => rfl⟩ + +theorem identityFeasible : Feasible identityRequirements identityImpl := + ⟨fun _ _ => rfl, by decide⟩ + +theorem identityJustified : JustifiedChoice identityRequirements identityImpl objectiveReason := + ⟨identityFeasible, .method .output, by simp [objectiveReason], identityOutputReason⟩ + +/- A conventional existing implementation can be selected for an actual requirement, not for status alone. -/ +theorem conventionWithReason : + identityImpl.conventional = true ∧ identityImpl.established = true ∧ + JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output] := by + exact ⟨rfl, rfl, identityFeasible, .method .output, by simp, identityOutputReason⟩ + +inductive Candidate | identity | successor + deriving DecidableEq, Repr + +def implementation : Candidate → Implementation + | .identity => identityImpl + | .successor => successorImpl + +/- Feasibility is decided by the same stated behavior and resource requirement for either candidate. -/ +theorem singleFeasible : + (∀ candidate, Feasible identityRequirements (implementation candidate) ↔ candidate = .identity) ∧ + JustifiedChoice identityRequirements identityImpl objectiveReason := by + constructor + · intro candidate + cases candidate + · simp [Feasible, identityRequirements, implementation, identityImpl] + · simp [Feasible, identityRequirements, implementation, successorImpl] + · exact identityJustified + +/- The same observed input can conceal a relevant difference at another input. -/ +theorem localNotGlobal : + (∀ x, x = 0 → identityImpl.run x = changedOutsideZero.run x) ∧ + identityImpl.run 1 ≠ changedOutsideZero.run 1 := by + constructor + · intro x hx; subst x; rfl + · decide + +/- This candidate is cheap enough but misses the required identity output. -/ +def cheapSuccessor : Implementation := { successorImpl with cost := 1 } + +theorem eligibleInternalReasonNotSufficient : + Relevant identityRequirements cheapSuccessor (.method .simplicity) ∧ + ¬ JustifiedChoice identityRequirements cheapSuccessor [.method .simplicity] := by + refine ⟨⟨trivial, by change 1 ≤ 1; decide⟩, ?_⟩ + intro h + have bad := h.1.1 0 trivial + cases bad + +/- Each of the four internal-method reasons is eligible because of its actual selected requirement and content. -/ +theorem internalReasons : + Relevant identityRequirements identityImpl (.method .explanation) ∧ + Relevant identityRequirements identityImpl (.method .applicability) ∧ + Relevant identityRequirements identityImpl (.method .simplicity) ∧ + Relevant identityRequirements identityImpl (.method .procedure) ∧ + (Relevant identityRequirements cheapSuccessor (.method .simplicity) ∧ + ¬ JustifiedChoice identityRequirements cheapSuccessor [.method .simplicity]) := by + exact ⟨⟨trivial, fun _ _ => rfl⟩, ⟨trivial, fun _ _ => trivial⟩, + ⟨trivial, by change 1 ≤ 1; decide⟩, ⟨trivial, fun _ _ => rfl⟩, eligibleInternalReasonNotSufficient⟩ + +/- Openness about reasons does not make two actual behaviors identical or reject the existing implementation. -/ +theorem openNotEquivalent : + JustifiedChoice identityRequirements identityImpl objectiveReason ∧ + identityImpl.run 0 ≠ successorImpl.run 0 := by + exact ⟨identityJustified, by decide⟩ + +/- A priority interpretation chooses one of the same two actual implementations. -/ +def priorityClaim : Claim Candidate := fun selected => selected = .identity + +def statusFacts : Theory Candidate := union + (singleton (fun _ => identityImpl.conventional = true)) + (singleton (fun _ => identityImpl.established = true)) + +/- Both interpretations have exactly the same true conventional and established status facts. -/ +theorem statusFactsModel (selected : Candidate) : Models statusFacts selected := by + exact (modelsUnion _ _ _).2 ⟨(modelsSingleton _ _).2 rfl, (modelsSingleton _ _).2 rfl⟩ + +def priorityArticulation : Articulation Candidate := + ⟨["priority", "conventional use", "established status"], statusFacts, + [fun _ => identityImpl.conventional = true, fun _ => identityImpl.established = true], + fun _ => True⟩ + +/- This procedure reports whether the actual status premises entail that very priority claim over its stated two-candidate scope. -/ +def AssessmentAccurate (report : Bool) : Prop := + report = true ↔ Entails statusFacts priorityClaim + +theorem statusDoesNotEntailPriority : ¬ Entails statusFacts priorityClaim := by + intro h + have bad := h .successor (statusFactsModel .successor) + cases bad + +theorem statusAssessmentNonEntailment : + Articulated priorityArticulation ∧ AssessmentAccurate false ∧ + (∀ selected, Models statusFacts selected) ∧ + priorityClaim .identity ∧ ¬ priorityClaim .successor ∧ + ¬ Entails statusFacts priorityClaim ∧ + ¬ JustifiedChoice identityRequirements identityImpl [.status .standing] := by + refine ⟨⟨by simp [priorityArticulation], by simp [priorityArticulation]⟩, + ⟨(by intro h; cases h), (fun h => False.elim (statusDoesNotEntailPriority h))⟩, + statusFactsModel, rfl, (by intro h; cases h), statusDoesNotEntailPriority, + statusOnlyFails _ _ _⟩ + +/- An assessment identifies the exact premises and priority question whose entailment it reports. -/ +structure PriorityAssessment where + premises : Theory Candidate + question : Claim Candidate + report : Bool +/- Accuracy concerns the actual reported entailment question, independently of a later choice policy. -/ +def PriorityAssessment.accurate (assessment : PriorityAssessment) : Prop := + assessment.report = true ↔ Entails assessment.premises assessment.question +/- Both policies receive this same correctly negative status-only priority audit. -/ +def statusPriorityAudit : PriorityAssessment := ⟨statusFacts, priorityClaim, false⟩ +/- Priority reasons are a policy component independent of the assessment's report and objects. -/ +structure ChoicePolicy where + selected : Candidate + priorityReasons : List Reason + assessment : PriorityAssessment +/- This is completion of the specified assessment procedure only, not full compliance with philosophical Grounds. -/ +def GeneralAssessmentFulfilled (policy : ChoicePolicy) : Prop := + Articulated priorityArticulation ∧ policy.assessment = statusPriorityAudit ∧ policy.assessment.accurate +/- The additional choice norm separately tests the reasons actually used to prioritize the selected implementation. -/ +def AdditionalChoiceNorm (policy : ChoicePolicy) : Prop := + JustifiedChoice identityRequirements (implementation policy.selected) policy.priorityReasons +/- This policy retains status alone as its priority reason despite receiving the correctly negative status audit. -/ +def statusPriorityPolicy : ChoicePolicy := ⟨.identity, [.status .standing], statusPriorityAudit⟩ +/- This policy selects the same implementation using its actual relevant output reason after the same audit. -/ +def outputPriorityPolicy : ChoicePolicy := ⟨.identity, objectiveReason, statusPriorityAudit⟩ +/- The shared negative result is mathematically accurate for its actual status premises and question. -/ +theorem statusPriorityAuditAccurate : statusPriorityAudit.accurate := by + constructor + · intro h; cases h + · intro h; exact False.elim (statusDoesNotEntailPriority h) +/- These independently variable policies share facts, selected implementation and completed audit, but differ on the extra choice norm. -/ +def PolicyIndependenceExample : Prop := + statusPriorityPolicy.selected = outputPriorityPolicy.selected ∧ + statusPriorityPolicy.assessment = outputPriorityPolicy.assessment ∧ + statusPriorityPolicy.assessment.premises = statusFacts ∧ + statusPriorityPolicy.assessment.question = priorityClaim ∧ + statusPriorityPolicy.assessment.report = false ∧ + (∀ selected, Models statusPriorityPolicy.assessment.premises selected) ∧ + statusPriorityPolicy.priorityReasons ≠ outputPriorityPolicy.priorityReasons ∧ + GeneralAssessmentFulfilled statusPriorityPolicy ∧ GeneralAssessmentFulfilled outputPriorityPolicy ∧ + ¬ AdditionalChoiceNorm statusPriorityPolicy ∧ AdditionalChoiceNorm outputPriorityPolicy +/- Changing the actual priority reasons changes choice compliance while the accurate audit remains identical. -/ +theorem policyIndependenceExample : PolicyIndependenceExample := by + have articulated : Articulated priorityArticulation := + ⟨by simp [priorityArticulation], by simp [priorityArticulation]⟩ + refine ⟨rfl,rfl,rfl,rfl,rfl,statusFactsModel,?_, + ⟨articulated,rfl,statusPriorityAuditAccurate⟩, + ⟨articulated,rfl,statusPriorityAuditAccurate⟩,?_,?_⟩ + · decide + · exact statusOnlyFails identityRequirements identityImpl .standing + · exact identityJustified + +/- A correctly articulated, completed negative assessment does not enforce the additional selection rule. +This is only independence from represented assessment procedures: keeping this unsupported priority would fail general support proportionality too. -/ +theorem generalGroundsNotChoice : + (Articulated priorityArticulation ∧ AssessmentAccurate false ∧ + (∀ selected, Models statusFacts selected) ∧ + priorityClaim .identity ∧ ¬ priorityClaim .successor ∧ + ¬ Entails statusFacts priorityClaim ∧ + ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧ + PolicyIndependenceExample := + ⟨statusAssessmentNonEntailment, policyIndependenceExample⟩ + +end CoreReader.Choice diff --git a/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Engineering/Domain.lean b/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Engineering/Domain.lean new file mode 100644 index 0000000..e616b00 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Engineering/Domain.lean @@ -0,0 +1,1047 @@ +import Std + +namespace CoreReader.Engineering + +/- This is a bounded engineering application model. Work units count explicit +operations; they are not a universal exchange rate or empirical forecast. -/ +inductive Maintainer where + | original | successor | agent + deriving DecidableEq, Repr +inductive Tool where + | editor | compiler | contractRunner | migrationRunner + deriving DecidableEq, Repr +inductive Knowledge where + | privateLayout | publicContract | changeGuide | migrationGuide + deriving DecidableEq, Repr +inductive Change where + | addition | replacement | deletion | withdrawal | redrawing | migration + | independent | coordinated | designRevision | other (name : String) + deriving DecidableEq, Repr +inductive Candidate where + | presentSimple | evolvable | maximal + deriving DecidableEq, Repr +inductive Burden where + | understanding | construction | diagnosis | verification | coordination + | operation | migration + deriving DecidableEq, Repr + +def maintainers : List Maintainer := [.original, .successor, .agent] +def changes : List Change := [.addition, .replacement, .deletion, .withdrawal, + .redrawing, .migration, .independent, .coordinated, .designRevision] +def burdens : List Burden := [.understanding, .construction, .diagnosis, + .verification, .coordination, .operation, .migration] + +structure Activity where + participants : List Maintainer + software : String + tools : List Tool + available : Maintainer → List Knowledge + scheduledReleases : Nat + scheduledMaintenance : Nat + boundedRuns : Option Nat + label : String + +/-- organon-map CoreReader.Engineering.ActivityScope +software-engineering.purpose#p1 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.purpose#p2 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +-/ +abbrev ActivityScope (a : Activity) : Prop := + a.participants ≠ [] ∧ a.software ≠ "" ∧ a.tools ≠ [] ∧ + a.participants.all (fun m => !(a.available m).isEmpty) = true + +abbrev Continuing (a : Activity) : Prop := + 0 < a.scheduledReleases ∧ 0 < a.scheduledMaintenance + +abbrev BoundedLifecycle (a : Activity) : Prop := + a.boundedRuns.isSome = true ∧ a.scheduledReleases = 0 ∧ + a.scheduledMaintenance = 0 + +def continuingActivity : Activity := { + participants := maintainers, software := "order-preserving queue", + tools := [.editor, .compiler, .contractRunner, .migrationRunner], + available := fun m => match m with + | .original => [.privateLayout, .publicContract, .changeGuide, .migrationGuide] + | _ => [.publicContract, .changeGuide, .migrationGuide], + scheduledReleases := 3, scheduledMaintenance := 6, + boundedRuns := none, label := "temporary" } + +def temporaryActivity : Activity := { continuingActivity with + scheduledReleases := 0, scheduledMaintenance := 0, boundedRuns := some 1, + label := "one-shot import" } +def prototypeActivity : Activity := { temporaryActivity with + boundedRuns := some 4, label := "bounded prototype" } +def retiringActivity : Activity := { temporaryActivity with + boundedRuns := some 2, label := "retiring service" } + +structure EditStep where + component : Nat + requires : Knowledge + tool : Tool + units : Nat + deriving DecidableEq, Repr + +def changePath (c : Candidate) (d : Change) : List EditStep := + let guide := if c = .presentSimple then Knowledge.privateLayout else .changeGuide + let base : List EditStep := [⟨0, guide, .editor, 1⟩, + ⟨0, .publicContract, .contractRunner, 1⟩] + match d with + | .addition | .independent => base + | .replacement | .deletion => base ++ [⟨1, guide, .compiler, 1⟩] + | .coordinated => base ++ [⟨1, guide, .compiler, 3⟩, ⟨2, .publicContract, .contractRunner, 3⟩] + | .migration => base ++ [⟨1, .migrationGuide, .migrationRunner, 8⟩] + | .withdrawal | .redrawing | .designRevision => + if c = .presentSimple then base ++ + [⟨1, guide, .editor, 5⟩, ⟨2, guide, .compiler, 5⟩, + ⟨2, .publicContract, .contractRunner, 5⟩] + else base ++ [⟨1, guide, .editor, 2⟩, ⟨1, .publicContract, .contractRunner, 2⟩] + | .other name => + if name = "csv export" then + if c = .maximal then base ++ [⟨3, .migrationGuide, .compiler, 2⟩] + else base ++ [⟨3, .privateLayout, .compiler, 20⟩] + else [] + +def changeWork (c : Candidate) (d : Change) : Nat := + ((changePath c d).map EditStep.units).sum + +abbrev CanChange (a : Activity) (c : Candidate) (m : Maintainer) (d : Change) : Prop := + (changePath c d) ≠ [] ∧ m ∈ a.participants ∧ (changePath c d).all + (fun step => (a.available m).contains step.requires && a.tools.contains step.tool) = true + +abbrev ContinuingCapability (a : Activity) (c : Candidate) (d : Change) : Prop := + (changePath c d) ≠ [] ∧ a.participants.all (fun m => (changePath c d).all + (fun step => (a.available m).contains step.requires && a.tools.contains step.tool)) = true + +/- Maximal is maximal only on this explicitly registered finite set. The +extra CSV direction has an actual documented compilation path and later state +transformation; unsupported names do not gain a capability from an empty path. -/ +def registeredDirections : List Change := changes ++ [.other "csv export"] +def supportedDirections (a : Activity) (c : Candidate) : List Change := + registeredDirections.filter (fun d => decide (ContinuingCapability a c d)) +abbrev MaximumRegisteredCapability (a : Activity) (c : Candidate) : Prop := + registeredDirections.all (fun d => decide (ContinuingCapability a c d)) = true + +/- A software value here is a passive function: no intention is stored in it. +An engineering intention is an agent's selected set of changes. -/ +def passiveArtifact (xs : List Nat) : List Nat := xs + +def orientation : Maintainer → List Change := fun _ => [.designRevision, .migration] + +inductive EngineeringAction where + | propose (direction : Change) + | execute (result : List Nat) + deriving DecidableEq, Repr + +def maintainerActions (m : Maintainer) : List EngineeringAction := + (orientation m).map EngineeringAction.propose + +def artifactActions (input : List Nat) : List EngineeringAction := + [.execute (passiveArtifact input)] + +/-- organon-map CoreReader.Engineering.subjectLifecycleCases +software-engineering.purpose#p1 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.purpose#p2 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +-/ +theorem subjectLifecycleCases : + ActivityScope continuingActivity ∧ + CanChange continuingActivity .evolvable .successor .designRevision ∧ + CanChange continuingActivity .evolvable .agent .designRevision ∧ + continuingActivity.label = "temporary" ∧ Continuing continuingActivity ∧ + ¬ BoundedLifecycle continuingActivity ∧ BoundedLifecycle temporaryActivity ∧ + BoundedLifecycle prototypeActivity ∧ BoundedLifecycle retiringActivity := by decide + +/-- organon-map CoreReader.Engineering.subjectLimits +software-engineering.purpose#p1 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.purpose#p2 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +-/ +theorem subjectLimits : + CanChange continuingActivity .presentSimple .original .designRevision ∧ + ¬ CanChange continuingActivity .presentSimple .successor .designRevision ∧ + ¬ ContinuingCapability continuingActivity .presentSimple .designRevision ∧ + continuingActivity.label = "temporary" ∧ ¬ BoundedLifecycle continuingActivity ∧ + orientation .agent ≠ [] ∧ passiveArtifact [2, 1] = [2, 1] ∧ + EngineeringAction.propose .designRevision ∈ maintainerActions .agent ∧ + EngineeringAction.propose .designRevision ∉ artifactActions [2, 1] := by decide + +/- Ground is intentionally parameterized: the examples below do not exhaust +possible sources of credibility. The supplied support relation needs review. -/ +/-- organon-map CoreReader.Engineering.CredibleDirection +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +abbrev CredibleDirection {Ground : Type} (grounds : List Ground) + (articulated : Ground → Bool) (supports : Ground → Change → Bool) + (d : Change) : Prop := + grounds.any (fun g => articulated g && supports g d) = true + +inductive DirectionGround where + | plan (release : Nat) (committed : List Change) + | knowledge (service : String) (affected : List Change) (mechanism : String) + | history (service : String) (observed : List Change) + | other (account : String) (supported : List Change) + deriving DecidableEq, Repr + +def articulateGround : DirectionGround → Bool + | .plan release ds => release > 0 && !ds.isEmpty + | .knowledge service ds mechanism => service != "" && !ds.isEmpty && mechanism != "" + | .history service ds => service != "" && !ds.isEmpty + | .other account ds => account != "" && !ds.isEmpty + +def supportGround : DirectionGround → Change → Bool + | .plan release ds, d => release > 0 && ds.contains d + | .knowledge service ds mechanism, d => + service == "queue" && mechanism == "tenant-config-reload" && ds.contains d + | .history service ds, d => service == "queue" && (ds.filter (· == d)).length >= 2 + | .other account ds, d => account == "reviewed customer migration requirement" && ds.contains d + +abbrev initialGrounds : List DirectionGround := [.plan 2 [.designRevision, .migration]] +def forecastGrounds : List DirectionGround := [.plan 3 [.deletion]] +abbrev credible (gs : List DirectionGround) (d : Change) : Prop := + CredibleDirection gs articulateGround supportGround d + +abbrev WarrantedAccommodation (gs : List DirectionGround) (d : Change) + (objectiveGain investment : Nat) : Prop := + credible gs d ∧ 0 < objectiveGain ∧ investment ≤ objectiveGain + +/-- organon-map CoreReader.Engineering.credibilityCases +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +theorem credibilityCases : + credible initialGrounds .designRevision ∧ + credible [.knowledge "queue" [.designRevision] "tenant-config-reload"] .designRevision ∧ + credible [.history "queue" [.migration, .migration]] .migration ∧ + ¬ credible [] (.other "quantum backend") ∧ + credible forecastGrounds .deletion ∧ ¬ credible forecastGrounds .designRevision := by decide + +def abstractionComplexity : Candidate → Nat + | .presentSimple => 1 | .evolvable => 3 | .maximal => 30 + +def implementedVariants : List Candidate := [.presentSimple] + +/- No scalar conversion across burden dimensions is used by the priority rule. -/ +structure CostVector where + amount : Burden → Nat +structure CostLimits where + capacity : Burden → Nat + objective : Burden → String + +def cost : Candidate → Burden → Nat + | .presentSimple, _ => 1 + | .evolvable, .understanding => 3 + | .evolvable, .construction => 4 + | .evolvable, .diagnosis => 2 + | .evolvable, .verification => 4 + | .evolvable, .coordination => 2 + | .evolvable, .operation => 2 + | .evolvable, .migration => 8 + | .maximal, _ => 40 + +def normalLimits : CostLimits := { + capacity := fun _ => 12, + objective := fun b => match b with + | .understanding => "successor onboarding capacity" + | .construction => "release construction capacity" + | .diagnosis => "incident diagnosis window" + | .verification => "release verification capacity" + | .coordination => "available team coordination" + | .operation => "runtime resource budget" + | .migration => "retirement migration capacity" } + +structure Requirements where + orderRequired : Bool + maxUnsafeOperations : Nat + maxLatency : Nat + minRetention : Nat + +def normalRequirements : Requirements := ⟨true, 0, 10, 30⟩ +def behavior : Candidate → List Nat → List Nat := fun _ xs => xs.eraseDups + +/- Candidate profiles are observations in this bounded scenario. Modified +profiles below test all four independent necessary-requirement gates. -/ +structure CandidateProfile where + orderOutput : List Nat + unsafeOperations : Nat + latency : Nat + retention : Nat + +def profile (c : Candidate) : CandidateProfile := ⟨behavior c [2, 1, 2], 0, 5, 30⟩ +abbrev Meets (r : Requirements) (p : CandidateProfile) : Prop := + (r.orderRequired = true → p.orderOutput = [2, 1]) ∧ + p.unsafeOperations ≤ r.maxUnsafeOperations ∧ p.latency ≤ r.maxLatency ∧ + r.minRetention ≤ p.retention + +structure Context where + activity : Activity + required : Requirements + evidence : List DirectionGround + limits : CostLimits + departure : Option Burden + profiles : Candidate → CandidateProfile := profile + +def currentContinuing : Context := { + activity := continuingActivity, required := normalRequirements, + evidence := initialGrounds, limits := normalLimits, departure := none } + +abbrev ConcreteThreat (ctx : Context) (c : Candidate) (b : Burden) : Prop := + cost .presentSimple b < cost c b ∧ ctx.limits.capacity b < cost c b ∧ + ctx.limits.objective b ≠ "" + +abbrev HasThreat (ctx : Context) (c : Candidate) : Prop := + burdens.any (fun b => decide (ConcreteThreat ctx c b)) = true + +/-- organon-map CoreReader.Engineering.JustifiedDeparture +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +abbrev JustifiedDeparture (ctx : Context) (c : Candidate) : Prop := + match ctx.departure with + | none => False + | some b => ConcreteThreat ctx c b + +instance (ctx : Context) (c : Candidate) : Decidable (JustifiedDeparture ctx c) := by + unfold JustifiedDeparture + split <;> infer_instance + +abbrev PriorityConditions (ctx : Context) : Prop := + Continuing ctx.activity ∧ ActivityScope ctx.activity ∧ + Meets ctx.required (ctx.profiles .presentSimple) ∧ Meets ctx.required (ctx.profiles .evolvable) ∧ + credible ctx.evidence .designRevision ∧ + ContinuingCapability ctx.activity .evolvable .designRevision ∧ + changeWork .evolvable .designRevision < changeWork .presentSimple .designRevision ∧ + abstractionComplexity .presentSimple < abstractionComplexity .evolvable + +/-- organon-map CoreReader.Engineering.EvolutionPriority +software-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +abbrev EvolutionPriority (ctx : Context) (chosen : Candidate) : Prop := + PriorityConditions ctx → chosen = .evolvable ∨ JustifiedDeparture ctx .evolvable + +theorem currentPriorityConditions : PriorityConditions currentContinuing := by decide +theorem currentNoThreat : ¬ HasThreat currentContinuing .evolvable ∧ + ¬ JustifiedDeparture currentContinuing .evolvable := by decide + +def threatened (b : Burden) : Context := { currentContinuing with + limits := { normalLimits with capacity := fun x => if x = b then 1 else 12 }, + departure := some b } + +/-- organon-map CoreReader.Engineering.priorityWhenApplicable +software-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +theorem priorityWhenApplicable (ctx : Context) (chosen : Candidate) + (rule : EvolutionPriority ctx chosen) (applicable : PriorityConditions ctx) + (noDeparture : ¬ JustifiedDeparture ctx .evolvable) : + chosen = .evolvable ∧ + abstractionComplexity .presentSimple < abstractionComplexity chosen := by + have hc := (rule applicable).resolve_right noDeparture + exact ⟨hc, hc ▸ applicable.2.2.2.2.2.2.2⟩ + +theorem currentSimpleViolates : ¬ EvolutionPriority currentContinuing .presentSimple := by + intro h + have bad := (h currentPriorityConditions).resolve_right currentNoThreat.2 + cases bad + +def withEvolvableProfile (p : CandidateProfile) : Context := { currentContinuing with + profiles := fun c => if c = .evolvable then p else profile c } + +theorem unmetRequirementsBlockPriority : + ¬ PriorityConditions (withEvolvableProfile { profile .evolvable with orderOutput := [1, 2] }) ∧ + ¬ PriorityConditions (withEvolvableProfile { profile .evolvable with unsafeOperations := 1 }) ∧ + ¬ PriorityConditions (withEvolvableProfile { profile .evolvable with latency := 11 }) ∧ + ¬ PriorityConditions (withEvolvableProfile { profile .evolvable with retention := 29 }) := by + simp [PriorityConditions, withEvolvableProfile, currentContinuing, Meets, + normalRequirements] + +/-- organon-map CoreReader.Engineering.priorityConditionsCases +software-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +theorem priorityConditionsCases : + EvolutionPriority currentContinuing .evolvable ∧ + ¬ Meets normalRequirements { profile .evolvable with orderOutput := [1, 2] } ∧ + ¬ Meets normalRequirements { profile .evolvable with unsafeOperations := 1 } ∧ + ¬ Meets normalRequirements { profile .evolvable with latency := 11 } ∧ + ¬ Meets normalRequirements { profile .evolvable with retention := 29 } ∧ + EvolutionPriority (threatened .verification) .presentSimple ∧ + ¬ JustifiedDeparture { threatened .verification with departure := none } .evolvable ∧ + abstractionComplexity .evolvable < abstractionComplexity .maximal := by + refine ⟨by decide, by decide, by decide, by decide, by decide, by decide, ?_, by decide⟩ + simp [JustifiedDeparture] + +/-- organon-map CoreReader.Engineering.priorityChoices +software-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +theorem priorityChoices : + EvolutionPriority currentContinuing .evolvable ∧ + ¬ EvolutionPriority currentContinuing .presentSimple ∧ + EvolutionPriority (threatened .verification) .presentSimple := by + exact ⟨by decide, currentSimpleViolates, by decide⟩ + +/-- organon-map CoreReader.Engineering.credibilityLimits +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +theorem credibilityLimits : + credible initialGrounds .designRevision ∧ implementedVariants.length = 1 ∧ + ¬ WarrantedAccommodation [] (.other "quantum backend") 0 5 ∧ + ¬ credible initialGrounds (.other "quantum backend") ∧ + EvolutionPriority currentContinuing .evolvable ∧ + abstractionComplexity .evolvable < abstractionComplexity .maximal ∧ + cost .evolvable .construction < cost .evolvable .migration ∧ + ¬ MaximumRegisteredCapability continuingActivity .evolvable ∧ + MaximumRegisteredCapability continuingActivity .maximal ∧ + (supportedDirections continuingActivity .evolvable).length = 9 ∧ + (supportedDirections continuingActivity .maximal).length = 10 ∧ + ¬ credible initialGrounds (.other "csv export") := by decide + +/-- organon-map CoreReader.Engineering.costCases +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +theorem costCases : + JustifiedDeparture (threatened .understanding) .evolvable ∧ + JustifiedDeparture (threatened .construction) .evolvable ∧ + JustifiedDeparture (threatened .diagnosis) .evolvable ∧ + JustifiedDeparture (threatened .verification) .evolvable ∧ + JustifiedDeparture (threatened .coordination) .evolvable ∧ + JustifiedDeparture (threatened .operation) .evolvable ∧ + JustifiedDeparture (threatened .migration) .evolvable ∧ + ¬ JustifiedDeparture { currentContinuing with departure := some .migration } .evolvable := by decide + +/- Total functions model an identified order-preserving de-duplication API. +The test corpus is explicitly finite; universal preservation is separate. -/ +def orderedUnique (xs : List Nat) : List Nat := xs.eraseDups +def orderedRefactor (xs : List Nat) : List Nat := xs.eraseDups ++ [] +def insertOrdered (n : Nat) : List Nat → List Nat + | [] => [n] + | x :: xs => if n ≤ x then n :: x :: xs else x :: insertOrdered n xs + +def sortValues : List Nat → List Nat + | [] => [] + | x :: xs => insertOrdered x (sortValues xs) + +def sortedUnique (xs : List Nat) : List Nat := (sortValues xs).eraseDups + +structure SoftwareState where + capabilities : List String + implementation : Nat + mechanisms : List String + abstractions : List String + boundary : Nat + technology : String + batchSize : Nat + deriving DecidableEq, Repr + +def originalSoftware : SoftwareState := + ⟨["deduplicate"], 0, ["queue", "legacy cache"], ["fixed batch"], 0, "legacy store", 10⟩ + +def transform (d : Change) (s : SoftwareState) : SoftwareState := match d with + | .addition => { s with capabilities := s.capabilities ++ ["tenant batching"] } + | .replacement => { s with implementation := s.implementation + 1 } + | .deletion => { s with mechanisms := s.mechanisms.filter (· != "legacy cache") } + | .withdrawal => { s with abstractions := s.abstractions.filter (· != "fixed batch") } + | .redrawing => { s with boundary := s.boundary + 1 } + | .migration => { s with technology := "portable store" } + | .independent => { s with batchSize := 5 } + | .coordinated => { s with batchSize := 5, boundary := s.boundary + 1 } + | .designRevision => { s with batchSize := 5, abstractions := ["live configuration"], boundary := s.boundary + 1 } + | .other name => + if name = "csv export" then { s with capabilities := s.capabilities ++ ["csv export"] } + else s + +def evolutionBehavior (d : Change) : List Nat → List Nat := + if d = .redrawing ∨ d = .designRevision then sortedUnique else orderedUnique + +/- Changes include an open other constructor. Work, maintainer knowledge and +obligation treatment are separate dimensions, not one extensibility score. -/ +inductive ObligationTreatment where + | preserve | revise + deriving DecidableEq, Repr +structure ChangeClaim where + direction : Change + byMaintainer : Maintainer + treatment : ObligationTreatment + +abbrev contractInputs : List (List Nat) := [[], [2, 1, 2], [1, 3, 1], [4, 4]] +def PreservesOn {Input Output : Type} (scope : Input → Prop) + (old new : Input → Output) : Prop := ∀ x, scope x → new x = old x + +abbrev PreservesFinite (old new : List Nat → List Nat) : Prop := + contractInputs.all (fun xs => new xs == old xs) = true + +/- The actual contracts and observer dependencies are inputs independent of +any revision report. Reports cannot redefine the affected population or the +old/new retry behavior merely by changing their own fields. -/ +structure ObservableContract where + order : List Nat → List Nat + maxAttempts : Nat + +def retry (contract : ObservableContract) (attempts : Nat) : Bool := + attempts < contract.maxAttempts + +def orderContract (order : List Nat → List Nat) : ObservableContract := ⟨order, 3⟩ +def originalContract : ObservableContract := orderContract orderedUnique +def refactoredContract : ObservableContract := orderContract orderedRefactor +def revisedContract : ObservableContract := ⟨sortedUnique, 5⟩ +def evolutionContract (d : Change) : ObservableContract := + ⟨evolutionBehavior d, if d = .redrawing ∨ d = .designRevision then 5 else 3⟩ + +def failureInputs : List Nat := [0, 1, 2, 3, 4, 5] +abbrev PreservesContractFinite (old new : ObservableContract) : Prop := + PreservesFinite old.order new.order ∧ + failureInputs.all (fun attempts => retry new attempts == retry old attempts) = true + +inductive ContractAspect where + | order | retry + deriving DecidableEq, Repr +structure PartyDependency where + party : String + observes : ContractAspect + deriving DecidableEq, Repr + +def partyDependencies : List PartyDependency := + [⟨"queue consumer", .order⟩, ⟨"queue operator", .retry⟩] + +def aspectChanged (old new : ObservableContract) : ContractAspect → Bool + | .order => contractInputs.any (fun xs => new.order xs != old.order xs) + | .retry => failureInputs.any (fun attempts => retry new attempts != retry old attempts) + +def affectedParties (old new : ObservableContract) : List String := + (partyDependencies.filter (fun dependency => aspectChanged old new dependency.observes)).map + PartyDependency.party + +structure ContractRevision where + deliberate : Bool + revisedOrder : List Nat + affected : List String + oldFailureLimit : Nat + newFailureLimit : Nat + recordedOldFailureLimit : Nat + recordedNewFailureLimit : Nat + procedure : String + +def normalRevision : ContractRevision := { + deliberate := true, revisedOrder := [1, 2], + affected := ["queue consumer", "queue operator"], + oldFailureLimit := 3, newFailureLimit := 5, + recordedOldFailureLimit := 3, recordedNewFailureLimit := 5, + procedure := "contract review" } + +abbrev RevisionDuties (old new : ObservableContract) (r : ContractRevision) : Prop := + r.deliberate = true ∧ r.revisedOrder = new.order [2, 1, 2] ∧ + (affectedParties old new).all (fun p => r.affected.contains p) = true ∧ + r.oldFailureLimit = old.maxAttempts ∧ r.newFailureLimit = new.maxAttempts ∧ + r.recordedOldFailureLimit = old.maxAttempts ∧ + r.recordedNewFailureLimit = new.maxAttempts + +/-- organon-map CoreReader.Engineering.ContractChangeAccount +software-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +-/ +abbrev ContractChangeAccount (old new : ObservableContract) (r : ContractRevision) : Prop := + PreservesContractFinite old new ∨ RevisionDuties old new r + +/-- organon-map CoreReader.Engineering.EvolutionClaim +software-engineering.evolution-meaning#p1 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6 +software-engineering.evolution-meaning#p2 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6 +-/ +abbrev EvolutionClaim (a : Activity) (c : Candidate) (claim : ChangeClaim) : Prop := + CanChange a c claim.byMaintainer claim.direction ∧ + ContractChangeAccount originalContract (evolutionContract claim.direction) normalRevision ∧ + (changePath c claim.direction).any (fun step => step.tool == .contractRunner) = true ∧ + ((claim.treatment = .preserve ∧ + evolutionBehavior claim.direction [2, 1, 2] = orderedUnique [2, 1, 2]) ∨ + (claim.treatment = .revise ∧ + evolutionBehavior claim.direction [2, 1, 2] ≠ orderedUnique [2, 1, 2])) + +/-- organon-map CoreReader.Engineering.evolutionKindsCases +software-engineering.evolution-meaning#p1 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6 +software-engineering.evolution-meaning#p2 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6 +-/ +theorem evolutionKindsCases : + (transform .addition originalSoftware).capabilities = ["deduplicate", "tenant batching"] ∧ + (transform .replacement originalSoftware).implementation = 1 ∧ + (transform .deletion originalSoftware).mechanisms = ["queue"] ∧ + (transform .withdrawal originalSoftware).abstractions = [] ∧ + (transform .redrawing originalSoftware).boundary = 1 ∧ + (transform .migration originalSoftware).technology = "portable store" ∧ + changes.all (fun d => decide (CanChange continuingActivity .evolvable .successor d)) = true ∧ + EvolutionClaim continuingActivity .evolvable ⟨.replacement, .successor, .preserve⟩ ∧ + EvolutionClaim continuingActivity .evolvable ⟨.redrawing, .agent, .revise⟩ ∧ + changeWork .evolvable .independent < changeWork .evolvable .coordinated := by decide + +/-- organon-map CoreReader.Engineering.evolutionDimensionsLimits +software-engineering.evolution-meaning#p1 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6 +software-engineering.evolution-meaning#p2 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6 +-/ +theorem evolutionDimensionsLimits : + changeWork .presentSimple .addition = 2 ∧ + changeWork .presentSimple .withdrawal = 17 ∧ + changeWork .evolvable .independent < changeWork .evolvable .coordinated ∧ + EvolutionPriority currentContinuing .evolvable ∧ + 9 < changeWork .evolvable .migration ∧ + CanChange continuingActivity .presentSimple .original .addition ∧ + CanChange continuingActivity .evolvable .original .addition ∧ + CanChange continuingActivity .presentSimple .original .designRevision ∧ + CanChange continuingActivity .evolvable .original .designRevision ∧ + changeWork .evolvable .designRevision < changeWork .presentSimple .designRevision ∧ + changeWork .evolvable .addition = changeWork .presentSimple .addition ∧ + (transform (.other "csv export") originalSoftware).capabilities = ["deduplicate", "csv export"] ∧ + CanChange continuingActivity .maximal .successor (.other "csv export") ∧ + ¬ CanChange continuingActivity .evolvable .successor (.other "csv export") := by + exact ⟨by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide⟩ + +theorem oneDimensionDoesNotEntailEveryDimension : + changeWork .evolvable .designRevision < changeWork .presentSimple .designRevision ∧ + ¬ (∀ d : Change, changeWork .evolvable d < changeWork .presentSimple d) := by + refine ⟨by decide, ?_⟩ + intro allDirections + exact (by decide : ¬ changeWork .evolvable .addition < changeWork .presentSimple .addition) + (allDirections .addition) + +def propagation (c : Candidate) (d : Change) : List Nat := + ((changePath c d).map EditStep.component).eraseDups + +def batchCount (items size : Nat) : Nat := (items + size - 1) / size +def staticBatch (items _runtimeSize : Nat) : Nat := batchCount items 10 +def liveBatch (items runtimeSize : Nat) : Nat := batchCount items runtimeSize + +structure StructuralEvidence where + intended : Change + participants : List Maintainer + touched : List Nat + contractObservations : List (List Nat) + observedBefore : List (List Nat) + observedAfter : List (List Nat) + understandingWork : Nat + verificationWork : Nat + boundaryGain : Nat + +def structuralEvidence (c : Candidate) (d : Change) : StructuralEvidence := { + intended := d, participants := maintainers, touched := propagation c d, + contractObservations := contractInputs, + observedBefore := contractInputs.map orderedUnique, + observedAfter := contractInputs.map (evolutionBehavior d), + understandingWork := changeWork c d, + verificationWork := ((changePath c d).filter (fun step => step.tool == .contractRunner)).length, + boundaryGain := changeWork .presentSimple d - changeWork c d } + +/-- organon-map CoreReader.Engineering.StructuralAccount +software-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +software-engineering.structural-judgment#p2 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +-/ +abbrev StructuralAccount (a : Activity) (c : Candidate) (e : StructuralEvidence) : Prop := + e.participants = a.participants ∧ e.touched = propagation c e.intended ∧ + e.contractObservations = contractInputs ∧ + e.observedBefore = contractInputs.map orderedUnique ∧ + e.observedAfter = contractInputs.map (evolutionBehavior e.intended) ∧ + e.understandingWork = changeWork c e.intended ∧ + e.verificationWork = ((changePath c e.intended).filter + (fun step => step.tool == .contractRunner)).length ∧ + e.boundaryGain = changeWork .presentSimple e.intended - changeWork c e.intended + +structure InterfaceView where + signature : String + modules : Nat + extensionPoints : Nat + principle : String + deriving DecidableEq, Repr + +def sameShape : InterfaceView := ⟨"List Nat → List Nat", 8, 12, "dependency inversion"⟩ +def moduleAssumptions : List (Nat × Nat) := + (List.range 8).map (fun component => (component, 10)) + +def modulesNeedingRevision (newSize : Nat) : List Nat := + (moduleAssumptions.filter (fun p => p.2 != newSize)).map Prod.fst + +structure Boundary where + caller : Nat + callee : Nat + contract : String + deriving DecidableEq, Repr + +structure EngineeringDesign where + metadata : InterfaceView + run : List Nat → List Nat + paths : Change → List EditStep + components : List Nat + boundaries : List Boundary + batchAssumptions : List (Nat × Nat) + +def privateDesign : EngineeringDesign := { + metadata := sameShape, run := orderedUnique, paths := changePath .presentSimple, + components := List.range 8, boundaries := [], batchAssumptions := moduleAssumptions } + +def documentedDesign : EngineeringDesign := { + privateDesign with paths := changePath .evolvable } + +def sortedDesign : EngineeringDesign := { documentedDesign with run := sortedUnique } + +/- This application has a caller at component 2 and a callee at component 1. +Editing the callee crosses that actual edge. The caller must recheck the +observable order contract in this finite case; the contract name alone is not +evidence that either the verification work or the observable equality holds. -/ +def coordinatedBoundary : Boundary := ⟨2, 1, "order-preserving queue"⟩ + +def boundaryDesign : EngineeringDesign := + { documentedDesign with boundaries := [coordinatedBoundary] } + +def crossesBoundary (design : EngineeringDesign) (direction : Change) (edge : Boundary) : Bool := + design.boundaries.contains edge && design.components.contains edge.caller && + design.components.contains edge.callee && edge.caller != edge.callee && + (design.paths direction).any (fun step => step.component == edge.callee && + (step.tool == .editor || step.tool == .compiler)) + +def boundaryObligationChecked (design : EngineeringDesign) (direction : Change) + (edge : Boundary) : Bool := + crossesBoundary design direction edge && + (design.paths direction).any (fun step => step.component == edge.caller && + step.tool == .contractRunner && step.requires == .publicContract) && + decide (PreservesFinite orderedUnique design.run) + +def omittedCallerCheck : EngineeringDesign := + { boundaryDesign with paths := fun direction => + (boundaryDesign.paths direction).filter (fun step => + !(step.component == coordinatedBoundary.caller && step.tool == .contractRunner)) } + +def otherCalleeBoundary : Boundary := { coordinatedBoundary with callee := 7 } + +def otherCalleeDesign : EngineeringDesign := + { boundaryDesign with boundaries := [otherCalleeBoundary] } + +theorem actualCrossBoundaryObligation : + crossesBoundary boundaryDesign .coordinated coordinatedBoundary = true ∧ + boundaryObligationChecked boundaryDesign .coordinated coordinatedBoundary = true ∧ + crossesBoundary omittedCallerCheck .coordinated coordinatedBoundary = true ∧ + boundaryObligationChecked omittedCallerCheck .coordinated coordinatedBoundary = false ∧ + crossesBoundary otherCalleeDesign .coordinated otherCalleeBoundary = false ∧ + boundaryObligationChecked { boundaryDesign with run := sortedUnique } + .coordinated coordinatedBoundary = false := by decide + +/-- organon-map CoreReader.Engineering.structuralCases +software-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +software-engineering.structural-judgment#p2 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +-/ +theorem structuralCases : + StructuralAccount continuingActivity .evolvable (structuralEvidence .evolvable .designRevision) ∧ + (propagation .presentSimple .designRevision).length = 3 ∧ + (propagation .evolvable .designRevision).length = 2 ∧ + (changePath .evolvable .coordinated).any (fun s => s.component == 2 && s.requires == .publicContract) = true ∧ + PreservesFinite orderedUnique orderedRefactor ∧ + (structuralEvidence .evolvable .designRevision).observedBefore ≠ + (structuralEvidence .evolvable .designRevision).observedAfter ∧ + staticBatch 21 10 = liveBatch 21 10 ∧ staticBatch 21 5 ≠ liveBatch 21 5 ∧ + changeWork .presentSimple .withdrawal = 17 ∧ + (crossesBoundary boundaryDesign .coordinated coordinatedBoundary = true ∧ + boundaryObligationChecked boundaryDesign .coordinated coordinatedBoundary = true ∧ + crossesBoundary omittedCallerCheck .coordinated coordinatedBoundary = true ∧ + boundaryObligationChecked omittedCallerCheck .coordinated coordinatedBoundary = false ∧ + crossesBoundary otherCalleeDesign .coordinated otherCalleeBoundary = false ∧ + boundaryObligationChecked { boundaryDesign with run := sortedUnique } + .coordinated coordinatedBoundary = false) := by decide + +abbrev DesignCanChange (a : Activity) (design : EngineeringDesign) + (m : Maintainer) (d : Change) : Prop := + design.paths d ≠ [] ∧ m ∈ a.participants ∧ + (design.paths d).all (fun step => + (a.available m).contains step.requires && a.tools.contains step.tool) = true + +def designWork (design : EngineeringDesign) (d : Change) : Nat := + ((design.paths d).map EditStep.units).sum + +def designModulesNeedingRevision (design : EngineeringDesign) (newSize : Nat) : List Nat := + (design.batchAssumptions.filter (fun p => p.2 != newSize)).map Prod.fst + +/- In this finite model, a facade adds an actual component, forwarding edge +and contract verification step. It preserves observable order but does not +remove the original edit/compilation work or supply private maintainer knowledge. -/ +def introduceBoundary (design : EngineeringDesign) : EngineeringDesign := { + metadata := { design.metadata with modules := design.metadata.modules + 1, extensionPoints := design.metadata.extensionPoints + 1 }, + run := fun xs => design.run (xs ++ []), + paths := fun d => if (design.paths d).isEmpty then [] else + design.paths d ++ [⟨design.components.length, .publicContract, .contractRunner, 1⟩], + components := design.components ++ [design.components.length], + boundaries := design.boundaries ++ + [⟨design.components.length, 0, design.metadata.signature⟩], + batchAssumptions := design.batchAssumptions } + +def wrappedDesign : EngineeringDesign := introduceBoundary privateDesign + +/- This second facade relocates the existing contract-verification work to +the new component. It changes the actual boundary and step locations without +reducing the work or making the private edit knowledge public. -/ +def relocateVerification (design : EngineeringDesign) : EngineeringDesign := { + introduceBoundary design with + paths := fun d => (design.paths d).map (fun step => + if step.tool = .contractRunner then { step with component := design.components.length } + else step) } + +def sameWorkDesign : EngineeringDesign := relocateVerification privateDesign + +/-- organon-map CoreReader.Engineering.structureNotCapability +software-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +software-engineering.structural-judgment#p2 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +-/ +theorem structureNotCapability : + (privateDesign.metadata.signature = sortedDesign.metadata.signature ∧ + privateDesign.run [2, 1, 2] = [2, 1] ∧ sortedDesign.run [2, 1, 2] ≠ [2, 1]) ∧ + (privateDesign.metadata.modules = privateDesign.components.length ∧ + privateDesign.batchAssumptions.length = 8 ∧ + (designModulesNeedingRevision privateDesign 5).length = 8) ∧ + (privateDesign.metadata.principle = "dependency inversion" ∧ + privateDesign.metadata = documentedDesign.metadata ∧ + ¬ DesignCanChange continuingActivity privateDesign .successor .designRevision ∧ + DesignCanChange continuingActivity documentedDesign .successor .designRevision) ∧ + (privateDesign.boundaries.length = 0 ∧ wrappedDesign.boundaries.length = 1 ∧ + wrappedDesign.components.length = 9 ∧ + wrappedDesign.boundaries = [⟨8, 0, "List Nat → List Nat"⟩] ∧ + wrappedDesign.run [2, 1, 2] = privateDesign.run [2, 1, 2] ∧ + designWork privateDesign .designRevision = 17 ∧ + designWork wrappedDesign .designRevision = 18 ∧ + ¬ designWork wrappedDesign .designRevision < designWork privateDesign .designRevision) ∧ + (sameWorkDesign.boundaries = [⟨8, 0, "List Nat → List Nat"⟩] ∧ + sameWorkDesign.components.length = 9 ∧ + sameWorkDesign.paths .designRevision ≠ privateDesign.paths .designRevision ∧ + sameWorkDesign.run [2, 1, 2] = privateDesign.run [2, 1, 2] ∧ + designWork sameWorkDesign .designRevision = designWork privateDesign .designRevision ∧ + designWork sameWorkDesign .designRevision = 17 ∧ + ¬ DesignCanChange continuingActivity sameWorkDesign .successor .designRevision) := by + exact ⟨by decide, by decide, by decide, by decide, by decide⟩ + +/-- organon-map CoreReader.Engineering.contractPreservation +software-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +-/ +theorem contractPreservation {Input Output : Type} (scope : Input → Prop) + (old new : Input → Output) (observations : ∀ x, scope x → new x = old x) : + PreservesOn scope old new := observations + +theorem changedObservationNotPreserved {Input Output : Type} (scope : Input → Prop) + (old new : Input → Output) (x : Input) (inside : scope x) + (different : new x ≠ old x) : ¬ PreservesOn scope old new := by + intro h + exact different (h x inside) + +theorem contractRevisionObligations (old new : ObservableContract) + (r : ContractRevision) (account : ContractChangeAccount old new r) + (changed : ¬ PreservesContractFinite old new) : + RevisionDuties old new r := account.resolve_left changed + +def retiredBehavior (xs : List Nat) : List Nat := + if xs = [99] then [] else orderedUnique xs + +/-- organon-map CoreReader.Engineering.contractCases +software-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +-/ +theorem contractCases : + ContractChangeAccount originalContract refactoredContract normalRevision ∧ + ContractChangeAccount originalContract revisedContract normalRevision ∧ + ¬ ContractChangeAccount originalContract revisedContract { normalRevision with affected := [] } ∧ + PreservesFinite orderedUnique retiredBehavior ∧ retiredBehavior [99] ≠ orderedUnique [99] ∧ + ContractChangeAccount originalContract revisedContract { normalRevision with procedure := "paired audit" } := by decide + +/-- organon-map CoreReader.Engineering.contractDistinctions +software-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +-/ +theorem contractDistinctions : + PreservesFinite orderedUnique orderedRefactor ∧ + ¬ PreservesFinite orderedUnique sortedUnique ∧ + retry originalContract 3 = false ∧ retry revisedContract 3 = true ∧ + ¬ PreservesContractFinite originalContract revisedContract ∧ + affectedParties originalContract revisedContract = ["queue consumer", "queue operator"] ∧ + ¬ ContractChangeAccount originalContract revisedContract + { normalRevision with affected := ["queue consumer"] } ∧ + ¬ ContractChangeAccount originalContract revisedContract + { normalRevision with oldFailureLimit := 5, recordedOldFailureLimit := 5 } ∧ + ContractChangeAccount originalContract revisedContract normalRevision ∧ + PreservesFinite orderedUnique retiredBehavior ∧ retiredBehavior [99] ≠ orderedUnique [99] := by decide + +/- Revision records time-indexed evidence rather than changing a past event. +Judgment is choice under current evidence; forecast truth is a separate value. -/ +structure RevisionState where + time : Nat + forecast : List Change + maintenance : Nat + maintainers : List Maintainer + migrationCost : Nat + objectiveCapacity : Nat + choice : Candidate + deriving DecidableEq, Repr +structure RevisionRecord where + software : String + old : RevisionState + current : RevisionState + recordedOld : RevisionState + recordedCurrent : RevisionState + predictedBatchCount : Nat + actualBatchCount : Nat + reportedPredictionSucceeded : Bool + consideredChanges : List Change + criticizedDirections : List Change + +abbrev MaterialGroundsChanged (old current : RevisionState) : Prop := + old.forecast ≠ current.forecast ∨ old.maintenance ≠ current.maintenance ∨ + old.maintainers ≠ current.maintainers ∨ + old.migrationCost ≠ current.migrationCost ∨ old.objectiveCapacity ≠ current.objectiveCapacity + +def oldState : RevisionState := ⟨0, [.designRevision], 6, [.original], 8, 12, .evolvable⟩ +def newState : RevisionState := ⟨1, [.deletion], 2, [.successor, .agent], 14, 10, .presentSimple⟩ + +structure HistoricalEvidence where + software : String + state : RevisionState + predictedBatchCount : Nat + actualBatchCount : Nat + +/- Independent event content: the recorded predictor used a fixed batch size +of ten; the actual event had runtime size five and twenty-one queue items. -/ +def observedHistory : HistoricalEvidence := + ⟨"order-preserving queue", oldState, staticBatch 21 5, liveBatch 21 5⟩ + +abbrev RevisionAccountAgainst (history : HistoricalEvidence) (r : RevisionRecord) : Prop := + r.software = history.software ∧ + r.old = history.state ∧ r.recordedOld = history.state ∧ + r.predictedBatchCount = history.predictedBatchCount ∧ + r.actualBatchCount = history.actualBatchCount ∧ + r.old.time < r.current.time ∧ r.recordedCurrent = r.current ∧ + (r.old.choice ≠ r.current.choice → MaterialGroundsChanged r.old r.current) ∧ + r.reportedPredictionSucceeded = decide (history.predictedBatchCount = history.actualBatchCount) ∧ + r.consideredChanges.all (fun d => r.criticizedDirections.contains d) = true + +/-- organon-map CoreReader.Engineering.RevisionAccount +software-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +software-engineering.revision#p1 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +-/ +abbrev RevisionAccount (r : RevisionRecord) : Prop := RevisionAccountAgainst observedHistory r + +theorem failedHistoryNotRewritten (history : HistoricalEvidence) (r : RevisionRecord) + (account : RevisionAccountAgainst history r) + (failed : history.predictedBatchCount ≠ history.actualBatchCount) : + r.reportedPredictionSucceeded = false := by + simpa [failed] using account.2.2.2.2.2.2.2.2.1 + +def revisionRecord : RevisionRecord := { + software := "order-preserving queue", + old := oldState, current := newState, recordedOld := oldState, recordedCurrent := newState, + predictedBatchCount := staticBatch 21 5, actualBatchCount := liveBatch 21 5, + reportedPredictionSucceeded := false, + consideredChanges := changes, criticizedDirections := changes } + +abbrev SupportedAlternative (gs : List DirectionGround) (d : Change) : Prop := credible gs d + +abbrev RetentionJustified (ctx : Context) (alternatives : List Change) : Prop := + alternatives.all (fun d => !decide (SupportedAlternative ctx.evidence d)) = true ∨ + JustifiedDeparture ctx .evolvable + +def stableRecord : RevisionRecord := { revisionRecord with + current := { newState with choice := .evolvable }, + recordedCurrent := { newState with choice := .evolvable } } + +/-- organon-map CoreReader.Engineering.revisionCases +software-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +software-engineering.revision#p1 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +-/ +theorem revisionCases : + RevisionAccount revisionRecord ∧ + revisionRecord.old.forecast ≠ revisionRecord.current.forecast ∧ + revisionRecord.old.maintenance ≠ revisionRecord.current.maintenance ∧ + revisionRecord.old.maintainers ≠ revisionRecord.current.maintainers ∧ + revisionRecord.old.migrationCost ≠ revisionRecord.current.migrationCost ∧ + revisionRecord.old.objectiveCapacity ≠ revisionRecord.current.objectiveCapacity ∧ + revisionRecord.predictedBatchCount ≠ revisionRecord.actualBatchCount ∧ + RetentionJustified currentContinuing [.other "quantum backend"] ∧ + RetentionJustified (threatened .migration) [.migration] := by decide + +def observations : List (Nat × Nat) := [(21, 10), (30, 10), (40, 10)] +def revisionsMade : List Nat := [1, 2, 3] +def agreedBatch (reviewers : List Maintainer) (items size : Nat) : List Nat := + reviewers.map (fun _ => staticBatch items size) + +def rewrittenOldRecord : RevisionRecord := { revisionRecord with + old := { oldState with forecast := [.deletion] }, + recordedOld := { oldState with forecast := [.deletion] } } + +def rewrittenPredictionRecord : RevisionRecord := { revisionRecord with + predictedBatchCount := 5, reportedPredictionSucceeded := true } + +def rewrittenObservationRecord : RevisionRecord := { revisionRecord with + actualBatchCount := 3, reportedPredictionSucceeded := true } + +def unrelatedSoftwareRecord : RevisionRecord := { + revisionRecord with software := "unrelated batch processor" } + +theorem historicalTamperingRejected : + RevisionAccount revisionRecord ∧ + ¬ RevisionAccount rewrittenOldRecord ∧ + ¬ RevisionAccount rewrittenPredictionRecord ∧ + ¬ RevisionAccount rewrittenObservationRecord ∧ + observedHistory.predictedBatchCount = 3 ∧ observedHistory.actualBatchCount = 5 ∧ + ¬ RevisionAccount unrelatedSoftwareRecord := by + exact ⟨by decide, by decide, by decide, by decide, by decide, by decide, by decide⟩ + +/-- organon-map CoreReader.Engineering.revisionLimits +software-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +software-engineering.revision#p1 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +-/ +theorem revisionLimits : + RevisionAccount revisionRecord ∧ + ¬ RevisionAccount { revisionRecord with reportedPredictionSucceeded := true } ∧ + revisionsMade.length = 3 ∧ + agreedBatch maintainers 21 5 = [3, 3, 3] ∧ liveBatch 21 5 = 5 ∧ + observations.all (fun p => staticBatch p.1 p.2 == liveBatch p.1 p.2) = true ∧ + staticBatch 21 5 ≠ liveBatch 21 5 ∧ + RevisionAccount stableRecord ∧ stableRecord.current.choice = stableRecord.old.choice ∧ + RetentionJustified currentContinuing [.other "quantum backend"] := by + refine ⟨by decide, ?_, by decide, by decide, by decide, by decide, + by decide, by decide, by decide, by decide⟩ + dsimp [RevisionAccount, RevisionAccountAgainst, observedHistory, MaterialGroundsChanged, revisionRecord, oldState, newState] + decide + +def groundedChanges : DirectionGround → List Change + | .plan _ ds | .knowledge _ ds _ | .history _ ds | .other _ ds => ds + +def currentRevisionState (ctx : Context) (chosen : Candidate) : RevisionState := { + time := 1, forecast := ctx.evidence.flatMap groundedChanges, + maintenance := ctx.activity.scheduledMaintenance, maintainers := ctx.activity.participants, + migrationCost := cost chosen .migration, + objectiveCapacity := ctx.limits.capacity .migration, + choice := chosen } + +def revisionFor (ctx : Context) (chosen : Candidate) : RevisionRecord := { + stableRecord with software := ctx.activity.software, current := currentRevisionState ctx chosen, recordedCurrent := currentRevisionState ctx chosen } + +theorem revisionContextIdentity : + (revisionFor currentContinuing .evolvable).software = currentContinuing.activity.software ∧ + (revisionFor currentContinuing .evolvable).software = observedHistory.software ∧ (revisionFor currentContinuing .evolvable).current.maintenance = + currentContinuing.activity.scheduledMaintenance ∧ + (revisionFor currentContinuing .evolvable).current.maintainers = currentContinuing.activity.participants ∧ + (revisionFor currentContinuing .evolvable).current.migrationCost = cost .evolvable .migration ∧ + (revisionFor currentContinuing .evolvable).current.objectiveCapacity = + currentContinuing.limits.capacity .migration ∧ + (revisionFor currentContinuing .evolvable).current.choice = .evolvable ∧ + RevisionAccount (revisionFor currentContinuing .evolvable) := by decide + +/- Whole domain satisfaction keeps actual subject, credibility, account and +revision duties. The same context is passed to priority and every domain duty. +Application account choices below are finite records, not universal claims. -/ +abbrev DomainSatisfied (ctx : Context) (chosen : Candidate) : Prop := + ActivityScope ctx.activity ∧ EvolutionPriority ctx chosen ∧ + credible ctx.evidence .designRevision ∧ + (ctx.departure ≠ none → JustifiedDeparture ctx .evolvable) ∧ + EvolutionClaim ctx.activity chosen ⟨.designRevision, .successor, .revise⟩ ∧ + StructuralAccount ctx.activity chosen (structuralEvidence chosen .designRevision) ∧ + ContractChangeAccount (orderContract (behavior chosen)) (evolutionContract .designRevision) normalRevision ∧ + RevisionAccount (revisionFor ctx chosen) + +theorem currentDomainSatisfied : DomainSatisfied currentContinuing .evolvable := by + refine ⟨by decide, by decide, by decide, ?_, by decide, by decide, by decide, by decide⟩ + simp [currentContinuing] + +end CoreReader.Engineering diff --git a/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Engineering/Integration.lean b/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Engineering/Integration.lean new file mode 100644 index 0000000..c35d978 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Engineering/Integration.lean @@ -0,0 +1,608 @@ +import CoreReader.Engineering.Domain +import CoreReader.Engineering.Reflection +import CoreReader.Engineering.SelfApplication + +namespace CoreReader.Engineering + +open CoreReader.Logic CoreReader.Evidence CoreReader.Adopted + +/- All interpretations below share this activity, requirements, evidence and +cost limits. Only the selected implementation and its stated value priority vary. -/ +abbrev sharedContext : Context := currentContinuing + +def maintainedOutput (chosen : Candidate) (n : Nat) : Nat := + (behavior chosen [n]).headD 0 + +def chosenImplementation (chosen : Candidate) : CoreReader.Choice.Implementation where + name := "order-preserving queue" + conventional := chosen == .presentSimple + established := chosen == .presentSimple + run := maintainedOutput chosen + cost := abstractionComplexity chosen + domain _ := True + explanation := maintainedOutput chosen + trace n := [maintainedOutput chosen n] + +/- This Core choice projection checks the queue's one-item observable contract +and present understanding budget. Domain retains its additional required checks. -/ +def chosenRequirements : CoreReader.Choice.Requirements where + inputs _ := True + expected n := n + budget := sharedContext.limits.capacity .understanding + values _ := True + +def chosenReasons : List CoreReader.Choice.Reason := + [.method .output, .method .simplicity] + +theorem maintainedOutputCorrect (chosen : Candidate) (n : Nat) : + maintainedOutput chosen n = n := by + rfl + +theorem implementationReasoned (chosen : Candidate) + (budget : abstractionComplexity chosen ≤ chosenRequirements.budget) : + choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons := by + refine ⟨⟨fun n _ => maintainedOutputCorrect chosen n, budget⟩, + .method .output, ?_, ?_⟩ + · simp [chosenReasons] + · exact ⟨trivial, fun n _ => maintainedOutputCorrect chosen n⟩ + +/- This reported capability concerns actual paths for each maintainer. Zero +records the unavailable path, not an assertion that an unsupported path exists. -/ +def capabilityOutput (chosen : Candidate) (input : Nat) : Nat := + let maintainer := if input = 0 then Maintainer.original + else if input = 1 then Maintainer.successor else Maintainer.agent + if decide (CanChange sharedContext.activity chosen maintainer .designRevision) + then changeWork chosen .designRevision else 0 + +def engineeringProcess (chosen : Candidate) : Process := + ⟨capabilityOutput chosen, none⟩ + +def engineeringCapability (chosen : Candidate) : Claim Process := + fun process => ∀ input, process.output input = capabilityOutput chosen input + +theorem engineeringCapabilityGrounded (chosen : Candidate) : + capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen) := by + exact grounds012Singleton _ (processContractDischarged _ _ (fun _ => rfl)) + +theorem actualCapabilityContrast : + (engineeringProcess .presentSimple).output 0 = 17 ∧ + (engineeringProcess .presentSimple).output 1 = 0 ∧ + (engineeringProcess .presentSimple).output 2 = 0 ∧ + (engineeringProcess .evolvable).output 0 = 6 ∧ + (engineeringProcess .evolvable).output 1 = 6 ∧ + (engineeringProcess .evolvable).output 2 = 6 := by decide + +/- A recorded threshold test measures present abstraction complexity in this +finite model. It does not observe future maintainability or establish a value. -/ +def presentBudgetRecord : Record Candidate := + ⟨fun candidate => decide (abstractionComplexity candidate ≤ 3), true⟩ + +abbrev presentBudgetClaim : Claim Candidate := fun candidate => abstractionComplexity candidate ≤ 3 + +theorem budgetObservationMeaning (candidate : Candidate) : + Compatible [presentBudgetRecord] candidate ↔ presentBudgetClaim candidate := by + constructor + · intro observed + have result := observed presentBudgetRecord (List.mem_singleton.mpr rfl) + exact of_decide_eq_true result + · intro enough record member + cases List.mem_singleton.mp member + exact decide_eq_true enough + +def budgetEmpiricalFacet : Facet Candidate := + .empirical [presentBudgetRecord] (fun _ => True) presentBudgetClaim (fun _ => True) + +theorem budgetEmpiricalDischarged : FacetDischarged budgetEmpiricalFacet := by + refine ⟨⟨.evolvable, (budgetObservationMeaning _).2 (by decide), trivial⟩, ?_, ?_⟩ + · intro candidate observed _ + exact (budgetObservationMeaning candidate).1 observed + · intro _ _; trivial + +def capacityClaim : Claim Candidate := + fun candidate => abstractionComplexity candidate ≤ sharedContext.limits.capacity .understanding + +def capacityAssumptions : Theory Candidate := singleton presentBudgetClaim + +def budgetInferentialFacet : Facet Candidate := .inferential capacityAssumptions capacityClaim + +theorem budgetInferentialDischarged : FacetDischarged budgetInferentialFacet := by + refine ⟨⟨.evolvable, (modelsSingleton _ _).2 (by decide)⟩, ?_⟩ + intro candidate premises + have small := (modelsSingleton _ _).1 premises + exact Nat.le_trans small (by decide) + +def budgetScopeAccount : ScopeAccount Candidate where + claim := presentBudgetClaim + conditions := fun _ => True + observationScope := fun _ => True + relevant := fun a b => behavior a [2, 1, 2] = behavior b [2, 1, 2] + compared := fun a b => presentBudgetClaim a ∧ presentBudgetClaim b + used method := method = .measurement + role _ := "threshold observation of present complexity; no future-performance conclusion" + explains method text claim conditions := method = .measurement ∧ + text = "threshold observation of present complexity; no future-performance conclusion" ∧ + claim = presentBudgetClaim ∧ conditions = (fun _ => True) + +theorem budgetScopeExplained : scopeSpecification budgetScopeAccount := by + constructor + · intro a b _; exact ⟨trivial, trivial, trivial, trivial, rfl⟩ + · intro method hm + exact ⟨by change "threshold observation of present complexity; no future-performance conclusion" ≠ ""; decide, + hm, rfl, rfl, rfl⟩ + +/- The unchanged observation cannot justify a stronger complexity bound. -/ +theorem budgetObservationLimit : + Compatible [presentBudgetRecord] .evolvable ∧ + ¬ Supports [presentBudgetRecord] (fun candidate => abstractionComplexity candidate ≤ 1) := by + refine ⟨(budgetObservationMeaning _).2 (by decide), ?_⟩ + intro support + have impossible := support .evolvable ((budgetObservationMeaning _).2 (by decide)) + exact (by decide : ¬ (3 ≤ 1)) impossible + +/- The policy values expansion while keeping every represented organization, +method and principle form revisable. It does not assert that a revision occurs. -/ +def engineeringPolicy : CoreReader.Agency.Policy where + worthPursuing aim := + (aim = .expandUnderstandingAndConstruction ∧ coreAdopted .generation = true) ∨ + aim = .preserveSafeOperation + current form := form.version = 1 + revisable form := ∃ next, form.version < next ∧ coreAdopted .generation = true + permitsVersion old next := old ≤ next + +theorem engineeringGenerative : generationSpecification engineeringPolicy := by + exact ⟨Or.inl ⟨rfl, rfl⟩, fun form _ => ⟨form.version + 1, Nat.lt_succ_self _, rfl⟩⟩ + +/- Own facts are mathematical reports about this model and its recorded state. +Their inferential tasks do not replace the separate empirical or value tasks. -/ +inductive OwnFact + | selected | requirements | capacity | capability | forecast | revision + | generativePolicy | reflection | coreAdoption (principle : CoreCommitment) + deriving DecidableEq, Repr + +abbrev ownFactClaim (adopted : Candidate) : OwnFact → Claim Candidate + | .selected => fun candidate => candidate = adopted + | .requirements => fun candidate => Meets sharedContext.required (sharedContext.profiles candidate) + | .capacity => capacityClaim + | .capability => fun candidate => engineeringCapability candidate (engineeringProcess candidate) + | .forecast => fun _ => staticBatch 21 10 = liveBatch 21 10 ∧ staticBatch 21 5 ≠ liveBatch 21 5 + | .revision => fun candidate => RevisionAccount (revisionFor sharedContext candidate) + | .generativePolicy => fun _ => generationSpecification engineeringPolicy + | .reflection => fun candidate => reflexivitySpecification + (selfModel candidate).rules (selfModel candidate).self (selfModel candidate).performed + | .coreAdoption principle => (governancePosition principle).commitment + +theorem actualOwnFact (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) (fact : OwnFact) : + ownFactClaim chosen fact chosen := by + cases fact with + | selected => rfl + | requirements => cases chosen <;> decide + | capacity => rcases ordinary with rfl | rfl <;> change _ ≤ 12 <;> decide + | capability => intro _; rfl + | forecast => exact ⟨rfl, by decide⟩ + | revision => rcases ordinary with rfl | rfl <;> decide + | generativePolicy => exact engineeringGenerative + | reflection => exact currentSelfApplication chosen ordinary + | coreAdoption _ => rfl + +def ownFactPremises (chosen : Candidate) : Theory Candidate := + singleton (fun candidate => candidate = chosen) + +theorem actualOwnFactGrounded (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) (fact : OwnFact) : + inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact) := by + apply grounds012Singleton + refine ⟨⟨chosen, (modelsSingleton _ _).2 rfl⟩, ?_⟩ + intro candidate same + have identity := (modelsSingleton _ _).1 same + subst candidate + exact actualOwnFact chosen ordinary fact + +/- In this fixed applicable context, the actual priority rule and the adopted +evolution value select exactly the same candidate. This identity connects its +value grounds to the normative rule, not merely to an adoption label. -/ +theorem priorityValueMeaning (candidate : Candidate) : + (selectionPosition .evolvable).commitment candidate ↔ + EvolutionPriority sharedContext candidate := by + constructor + · intro selected + change candidate = .evolvable at selected + subst candidate + exact currentDomainSatisfied.2.1 + · intro priority + exact (priorityWhenApplicable sharedContext candidate priority + currentPriorityConditions currentNoThreat.2).1 + +theorem priorityGrounds : + Grounds012 (EvolutionPriority sharedContext) canonicalArticulation + [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) := by + have same : (selectionPosition .evolvable).commitment = EvolutionPriority sharedContext := + funext (fun candidate => propext (priorityValueMeaning candidate)) + rw [← same] + exact selectionGrounded .evolvable (Or.inr rfl) + +/- Facts of adoption remain distinct from the actual normative contents. Each +constructor below denotes its full represented duty, with its original task, +conditions, reasons and scope. Domain duties enter only for the domain adopter. +Consistency is the constraint on the resulting whole theory below; it is not +encoded as a self-referential proposition in that theory's own definition. -/ +inductive OwnNorm + | generation | reflection | empirical | inferential | principleValue (principle : CoreCommitment) + | selectionValue | scope | capability | choice | ownGrounds (fact : OwnFact) + | domain | priorityValue + deriving DecidableEq, Repr + +def normApplies (adopted : Candidate) : OwnNorm → Prop + | .domain | .priorityValue => adopted = .evolvable + | _ => True + +def ownNormClaim (adopted : Candidate) : OwnNorm → Claim Candidate + | .generation => fun _ => generationSpecification engineeringPolicy + | .reflection => fun candidate => reflexivitySpecification + (selfModel candidate).rules (selfModel candidate).self (selfModel candidate).performed + | .empirical => fun _ => empiricalSpecification [presentBudgetRecord] (fun _ => True) + presentBudgetClaim (fun _ => True) + | .inferential => fun _ => inferentialSpecification capacityAssumptions capacityClaim + | .principleValue principle => fun _ => valueSpecification (governancePosition principle) + | .selectionValue => fun candidate => valueSpecification (selectionPosition adopted) ∧ + (selectionPosition adopted).commitment candidate + | .scope => fun _ => scopeSpecification budgetScopeAccount + | .capability => fun candidate => capabilitySpecification + (engineeringProcess candidate) (engineeringCapability candidate) + | .choice => fun candidate => choiceSpecification + chosenRequirements (chosenImplementation candidate) chosenReasons + | .ownGrounds fact => fun _ => inferentialSpecification + (ownFactPremises adopted) (ownFactClaim adopted fact) + | .domain => fun candidate => DomainSatisfied sharedContext candidate + | .priorityValue => fun _ => Grounds012 (EvolutionPriority sharedContext) canonicalArticulation + [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) + +theorem actualOwnNorm (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) + (norm : OwnNorm) (applicable : normApplies chosen norm) : ownNormClaim chosen norm chosen := by + cases norm with + | generation => exact engineeringGenerative + | reflection => exact currentSelfApplication chosen ordinary + | empirical => exact grounds012Singleton _ budgetEmpiricalDischarged + | inferential => exact grounds012Singleton _ budgetInferentialDischarged + | principleValue principle => exact governanceGrounded principle + | selectionValue => exact ⟨selectionGrounded chosen ordinary, rfl⟩ + | scope => exact budgetScopeExplained + | capability => exact engineeringCapabilityGrounded chosen + | choice => + apply implementationReasoned + rcases ordinary with rfl | rfl <;> change _ ≤ 12 <;> decide + | ownGrounds fact => exact actualOwnFactGrounded chosen ordinary fact + | domain => + change chosen = .evolvable at applicable + subst chosen + exact currentDomainSatisfied + | priorityValue => exact priorityGrounds + +def ownFactTheory (chosen : Candidate) : Theory Candidate := + fun claim => ∃ fact : OwnFact, claim = ownFactClaim chosen fact + +def ownNormTheory (chosen : Candidate) : Theory Candidate := + fun claim => ∃ norm : OwnNorm, normApplies chosen norm ∧ claim = ownNormClaim chosen norm + +/- The consequence relation now acts on all these facts and normative contents +together, including the implications of their union. -/ +def ownTheory (chosen : Candidate) : Theory Candidate := + union (ownFactTheory chosen) (ownNormTheory chosen) + +theorem allNormativeContentHeld (chosen : Candidate) (norm : OwnNorm) + (applicable : normApplies chosen norm) : ownTheory chosen (ownNormClaim chosen norm) := + Or.inr ⟨norm, applicable, rfl⟩ + +theorem nonemptyOwnObjects (chosen : Candidate) : + ownTheory chosen (ownFactClaim chosen .selected) ∧ + ownTheory chosen (ownFactClaim chosen (.coreAdoption .grounds)) ∧ + (.activity : ReviewObject) ∈ (selfModel chosen).objects ∧ + (.commitment .grounds : ReviewObject) ∈ (selfModel chosen).objects := by + refine ⟨Or.inl ⟨.selected, rfl⟩, Or.inl ⟨.coreAdoption .grounds, rfl⟩, ?_, ?_⟩ <;> + simp [selfModel, reviewObjects, coreCommitments] + +def comparisonContext (chosen : Candidate) : CoreReader.Logic.Context Candidate OwnFact where + assumptions := ownFactPremises chosen + meaning := ownFactClaim chosen + scope := valueScope + +def engineeringSnapshot (chosen : Candidate) (revision : Nat) : Snapshot Candidate OwnFact := + ⟨ownTheory chosen, comparisonContext chosen, revision⟩ + +theorem currentAdmissible (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) : + Admissible (ownTheory chosen) (comparisonContext chosen) chosen := by + refine ⟨?_, (modelsSingleton _ _).2 rfl, ?_⟩ + · intro claim held + rcases held with factHeld | normHeld + · obtain ⟨fact, rfl⟩ := factHeld + exact actualOwnFact chosen ordinary fact + · obtain ⟨norm, applicable, rfl⟩ := normHeld + exact actualOwnNorm chosen ordinary norm applicable + · rcases ordinary with rfl | rfl <;> change _ ≤ 3 <;> decide + +theorem currentConsistency (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) : + consistencySpecification (engineeringSnapshot .evolvable 0) + (engineeringSnapshot chosen 1) true := by + exact ⟨consequenceConsistency _ _ ⟨chosen, currentAdmissible chosen ordinary⟩, fun _ => rfl⟩ + +theorem wholeClaimGrounded (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) + (claim : Claim Candidate) (held : ownTheory chosen claim) : + inferentialSpecification (ownFactPremises chosen) claim := by + apply grounds012Singleton + refine ⟨⟨chosen, (modelsSingleton _ _).2 rfl⟩, ?_⟩ + intro candidate same + have identity := (modelsSingleton _ _).1 same + subst candidate + exact (currentAdmissible chosen ordinary).1 claim held + +/- Keeping the same adoption marker does not conceal contradictory normative +contents. Both demands act on the very same candidate, question and scope. -/ +def incompatibleNormTheory : Theory Candidate := + union (singleton (fun candidate => candidate = .presentSimple)) + (singleton (fun candidate => candidate ≠ .presentSimple)) + +def incompatibleNormContext : CoreReader.Logic.Context Candidate Unit := + ⟨emptyTheory, fun _ candidate => candidate = .presentSimple, fun _ => True⟩ + +theorem normativeContentVariation : + coreAdopted .choice = true ∧ + ¬ Consistent incompatibleNormTheory incompatibleNormContext ∧ + normApplies .evolvable .domain ∧ ¬ normApplies .presentSimple .domain ∧ + ownTheory .evolvable (ownNormClaim .evolvable .domain) ∧ + ¬ ownTheory .presentSimple (ownNormClaim .presentSimple .domain) := by + refine ⟨rfl, ?_, rfl, by unfold normApplies; decide, allNormativeContentHeld _ _ rfl, ?_⟩ + · apply conflictRequiresChange _ _ () + · intro candidate admissible + change candidate = .presentSimple + exact (modelsSingleton (fun c : Candidate => c = .presentSimple) candidate).1 + ((modelsUnion _ _ _).1 admissible.1).1 + · intro candidate admissible + change candidate ≠ .presentSimple + exact (modelsSingleton (fun c : Candidate => c ≠ .presentSimple) candidate).1 + ((modelsUnion _ _ _).1 admissible.1).2 + · intro held + have domain := (currentAdmissible .presentSimple (Or.inl rfl)).1 _ held + exact currentSimpleViolates domain.2.1 + +/- Every field is an actual satisfaction or support condition. Value accounts +and assessment completion do not replace the normative fields they explain. +The identity field limits this implementation to its disclosed common context. -/ +structure Inherited (ctx : Context) (chosen : Candidate) : Prop where + sameContext : ctx = sharedContext + generation : generationSpecification engineeringPolicy + consistency : consistencySpecification (engineeringSnapshot .evolvable 0) + (engineeringSnapshot chosen 1) true + reflection : reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self + (selfModel chosen).performed + ownPrincipleGrounds : ∀ principle, valueSpecification (governancePosition principle) + choiceValueGrounds : valueSpecification (selectionPosition chosen) + empiricalGrounds : empiricalSpecification [presentBudgetRecord] (fun _ => True) + presentBudgetClaim (fun _ => True) + inferentialGrounds : inferentialSpecification capacityAssumptions capacityClaim + scopeAccount : scopeSpecification budgetScopeAccount + capabilityGrounds : capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen) + implementationChoice : choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons + ownClaimGrounds : ∀ fact, inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact) + observedHere : Compatible [presentBudgetRecord] chosen + selectionActuallyAdopted : (selectionPosition chosen).commitment chosen + currentOwnClaims : Models (ownTheory chosen) chosen + fullNormativeContents : ∀ norm, normApplies chosen norm → + ownTheory chosen (ownNormClaim chosen norm) + wholeClaimGrounds : ∀ claim, ownTheory chosen claim → + inferentialSpecification (ownFactPremises chosen) claim + +theorem inheritedCurrent (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) : + Inherited sharedContext chosen := by + refine ⟨rfl, engineeringGenerative, currentConsistency chosen ordinary, + currentSelfApplication chosen ordinary, governanceGrounded, + selectionGrounded chosen ordinary, grounds012Singleton _ budgetEmpiricalDischarged, + grounds012Singleton _ budgetInferentialDischarged, budgetScopeExplained, + engineeringCapabilityGrounded chosen, ?_, actualOwnFactGrounded chosen ordinary, + ?_, rfl, (currentAdmissible chosen ordinary).1, + allNormativeContentHeld chosen, wholeClaimGrounded chosen ordinary⟩ + · apply implementationReasoned + rcases ordinary with rfl | rfl <;> change _ ≤ 12 <;> decide + · apply (budgetObservationMeaning _).2 + rcases ordinary with rfl | rfl <;> change _ ≤ 3 <;> decide + +/- Mutual application extracts duties for the same system, principles, claims +and actual chosen implementation. It retains the full Inherited premise. -/ +/-- organon-map CoreReader.Engineering.inheritedMutualApplication +organon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +theorem inheritedMutualApplication (ctx : Context) (chosen : Candidate) + (inherited : Inherited ctx chosen) : + generationSpecification engineeringPolicy ∧ + reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self + (selfModel chosen).performed ∧ + (∀ principle, valueSpecification (governancePosition principle)) ∧ + capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen) ∧ + choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons ∧ + (∀ fact, inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact)) ∧ + (∀ norm, normApplies chosen norm → ownTheory chosen (ownNormClaim chosen norm)) ∧ + (∀ claim, ownTheory chosen claim → inferentialSpecification (ownFactPremises chosen) claim) ∧ + consistencySpecification (engineeringSnapshot .evolvable 0) + (engineeringSnapshot chosen 1) true := + ⟨inherited.generation, inherited.reflection, inherited.ownPrincipleGrounds, + inherited.capabilityGrounds, inherited.implementationChoice, inherited.ownClaimGrounds, + inherited.fullNormativeContents, inherited.wholeClaimGrounds, inherited.consistency⟩ + +/-- organon-map CoreReader.Engineering.inheritedMutualCases +organon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +theorem inheritedMutualCases : + Inherited sharedContext .evolvable ∧ + valueSpecification (governancePosition .grounds) ∧ + capabilitySpecification (engineeringProcess .evolvable) (engineeringCapability .evolvable) ∧ + choiceSpecification chosenRequirements (chosenImplementation .evolvable) chosenReasons ∧ + Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧ + (.generationRule : ReviewObject) ∈ (selfModel .evolvable).objects ∧ + (.assessmentRule : ReviewObject) ∈ (selfModel .evolvable).objects ∧ + Reflection.evaluate ((selfModel .evolvable).input ⟨0, .assessmentRule, .revision⟩) = .counterexample := + ⟨inheritedCurrent .evolvable (Or.inr rfl), governanceGrounded .grounds, + engineeringCapabilityGrounded .evolvable, + (inheritedCurrent .evolvable (Or.inr rfl)).implementationChoice, + (actualSelfCriticism .evolvable).2.2.1, + (ownRuleIdentity .evolvable .generation .revision).1, + (ownRuleIdentity .evolvable .assessment .revision).1, + (ownRuleContentVariation .evolvable).2.2.2.2.1⟩ + +/- In the adopter's same context, the actual priority object and its own +assessment method remain within the inherited criticism/generation contract. -/ +/-- organon-map CoreReader.Engineering.priorityRemainsReflexive +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +extensions#p1 sha256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66 +software-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +software-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +-/ +theorem priorityRemainsReflexive (ctx : Context) (chosen : Candidate) + (inherited : Inherited ctx chosen) (domain : DomainSatisfied ctx chosen) + (applicable : PriorityConditions ctx) (noDeparture : ¬ JustifiedDeparture ctx .evolvable) : + chosen = .evolvable ∧ + (.priority : ReviewObject) ∈ (selfModel chosen).objects ∧ + reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self + (selfModel chosen).performed ∧ + (∀ principle, valueSpecification (governancePosition principle)) ∧ + Grounds012 (EvolutionPriority ctx) canonicalArticulation + [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) ∧ + ownTheory chosen (ownNormClaim chosen .domain) ∧ + consistencySpecification (engineeringSnapshot .evolvable 0) + (engineeringSnapshot chosen 1) true := by + have selected := (priorityWhenApplicable ctx chosen domain.2.1 applicable noDeparture).1 + refine ⟨selected, ?_, inherited.reflection, inherited.ownPrincipleGrounds, + ?_, allNormativeContentHeld chosen .domain selected, inherited.consistency⟩ + · subst chosen; decide + · rw [inherited.sameContext] + exact priorityGrounds + +/-- organon-map CoreReader.Engineering.priorityReflexiveCases +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +extensions#p1 sha256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66 +software-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +software-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +-/ +theorem priorityReflexiveCases : + (.priority : ReviewObject) ∈ (selfModel .evolvable).objects ∧ + objectTest .priority (.evolvable, 10) = true ∧ + (selfModel .evolvable).performed ⟨0, 1⟩ ⟨0, .priority, .revision⟩ + ((selfModel .evolvable).input ⟨0, .priority, .revision⟩) + (.assessed .supportedWithinScope) ∧ + Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧ + objectTest .evolutionMethod (.evolvable, 10) = true ∧ + objectTest .evolutionMethod (.evolvable, 5) = false ∧ + Grounds012 (EvolutionPriority sharedContext) canonicalArticulation + [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) ∧ + Reflection.evaluate ((selfModel .evolvable).input ⟨0, .assessmentRule, .revision⟩) = .counterexample := by + refine ⟨by decide, by decide, ?_, (actualSelfCriticism .evolvable).2.2.1, + (actualSelfCriticism .evolvable).1, (actualSelfCriticism .evolvable).2.1, + priorityGrounds, (ownRuleContentVariation .evolvable).2.2.2.2.1⟩ + exact ⟨⟨rfl, by decide⟩, rfl, .assessment, rfl, rfl⟩ + +/- The witness is nonempty and satisfies the entire represented inherited and +domain bundles in the very same continuing activity, with active priority. -/ +/-- organon-map CoreReader.Engineering.jointWitness +organon.charter.overview#p2 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c +organon.charter.overview#p3 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c +organon.charter.self-transcendence#p1 sha256 f4ca590e2ae15e3882f70c7b2bc46a8911c97cee547c8b137b5493fbf862c8c0 +organon.charter.self-transcendence.orientation#p1 sha256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf +organon.charter.self-transcendence.non-finality#p1 sha256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8 +organon.charter.self-transcendence.limits#p1 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d +organon.charter.self-transcendence.limits#p2 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d +organon.charter.consistency#p1 sha256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42 +organon.charter.consistency.meaning#p1 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75 +organon.charter.reflexivity#p1 sha256 13293b45c2fa89068c68ae7ef3c5df38f0efadb3ef3873d78a5ba67d9691a757 +organon.charter.reflexivity.meaning#p1 sha256 8a2caede01a43d8b6c60b54c78ac089c51868e9956f316948077ccee2e45c9cc +organon.charter.reflexivity.limits#p1 sha256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc +organon.grounds#p1 sha256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6 +organon.grounds.assessment#p1 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.scope#p1 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.scope#p2 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.scope#p3 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.capabilities#p1 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0 +organon.grounds.capabilities#p2 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0 +organon.grounds.implementations#p1 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c +organon.grounds.implementations#p2 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c +organon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870 +organon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +extensions#p1 sha256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66 +software-engineering.purpose#p1 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.purpose#p2 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-meaning#p1 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6 +software-engineering.evolution-meaning#p2 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6 +software-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +software-engineering.structural-judgment#p2 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +software-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +software-engineering.revision#p1 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +software-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +-/ +theorem jointWitness : + ∃ ctx : Context, ∃ chosen : Candidate, + ctx = sharedContext ∧ chosen = .evolvable ∧ + Inherited ctx chosen ∧ DomainSatisfied ctx chosen ∧ + PriorityConditions ctx ∧ ¬ HasThreat ctx .evolvable ∧ + abstractionComplexity .presentSimple < abstractionComplexity chosen ∧ + CanChange ctx.activity chosen .successor .designRevision ∧ + CanChange ctx.activity chosen .agent .designRevision ∧ + ownTheory chosen (ownFactClaim chosen .selected) ∧ + (.commitment .grounds : ReviewObject) ∈ (selfModel chosen).objects ∧ + Admissible (ownTheory chosen) (comparisonContext chosen) chosen := by + exact ⟨sharedContext, .evolvable, rfl, rfl, + inheritedCurrent .evolvable (Or.inr rfl), currentDomainSatisfied, + currentPriorityConditions, currentNoThreat.1, by decide, by decide, by decide, + (nonemptyOwnObjects .evolvable).1, (nonemptyOwnObjects .evolvable).2.2.2, + currentAdmissible .evolvable (Or.inr rfl)⟩ + +/- The countermodel adopts a supported present-simplicity value and actually +chooses that option. Every inherited duty still holds. The domain conditions +are active; neither lifecycle nor threatened costs supplies an escape. -/ +/-- organon-map CoreReader.Engineering.inheritedDoesNotEntailPriority +organon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +extensions#p1 sha256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66 +software-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +theorem inheritedDoesNotEntailPriority : + ∃ ctx : Context, ∃ chosen : Candidate, + ctx = sharedContext ∧ chosen = .presentSimple ∧ + Inherited ctx chosen ∧ PriorityConditions ctx ∧ + Continuing ctx.activity ∧ ¬ BoundedLifecycle ctx.activity ∧ + ¬ HasThreat ctx .evolvable ∧ ¬ JustifiedDeparture ctx .evolvable ∧ + Meets ctx.required (ctx.profiles .presentSimple) ∧ + Meets ctx.required (ctx.profiles .evolvable) ∧ + credible ctx.evidence .designRevision ∧ + CanChange ctx.activity .evolvable .successor .designRevision ∧ + CanChange ctx.activity .evolvable .agent .designRevision ∧ + changeWork .evolvable .designRevision < changeWork chosen .designRevision ∧ + abstractionComplexity chosen < abstractionComplexity .evolvable ∧ + valueSpecification (selectionPosition chosen) ∧ + (selectionPosition chosen).commitment chosen ∧ + ¬ EvolutionPriority ctx chosen := by + exact ⟨sharedContext, .presentSimple, rfl, rfl, + inheritedCurrent .presentSimple (Or.inl rfl), currentPriorityConditions, + by decide, by decide, currentNoThreat.1, currentNoThreat.2, + by decide, by decide, by decide, by decide, by decide, by decide, by decide, + selectionGrounded .presentSimple (Or.inl rfl), rfl, currentSimpleViolates⟩ + +end CoreReader.Engineering diff --git a/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Engineering/Reflection.lean b/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Engineering/Reflection.lean new file mode 100644 index 0000000..a7f1fc7 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Engineering/Reflection.lean @@ -0,0 +1,132 @@ +import CoreReader.Adopted + +namespace CoreReader.Engineering.Reflection + +open CoreReader.Agency CoreReader.Adopted + +/- A target retains the owner, the actual object and the stage being examined. -/ +structure Target (Object : Type) where + owner : Nat + object : Object + phase : Phase + +/- A finite assessment contract has actual tests and a scope it claims to cover. +The scope is an application limit, not a universal definition of assessment. -/ +structure Contract (W : Type) where + test : W → Bool + tested : List W + claimed : List W + +/- Inputs carry the contract belonging to the named target, so another object's +test result cannot silently discharge this target's inquiry. -/ +structure Input (W Object : Type) where + target : Target Object + contract : Contract W + requested : List W + reasons : List String + basis : Prop + +inductive Verdict | supportedWithinScope | counterexample | noSupportingSample + deriving DecidableEq, Repr + +inductive Outcome (W : Type) + | generated (tests scope : List W) + | assessed (verdict : Verdict) + deriving DecidableEq + +/- A successful sample does not license the wider scope: an actual failing +instance there changes the assessment to counterexample. -/ +def evaluate {W Object : Type} (input : Input W Object) : Verdict := + if input.contract.tested.all input.contract.test then + if input.requested.all input.contract.test then .supportedWithinScope + else .counterexample + else .noSupportingSample + +/- Generation proposes an expanded test set. Proposal generation does not prove +that the resulting contract passes those tests or warrants adoption. -/ +def generate {W Object : Type} (input : Input W Object) : Outcome W := + .generated input.requested input.requested + +def interpret {W Object : Type} (activity : Activity) (input : Input W Object) + (outcome : Outcome W) : Prop := + input.reasons ≠ [] ∧ input.basis ∧ match activity with + | .generation => outcome = generate input + | .assessment => outcome = .assessed (evaluate input) + +structure Model (W Object : Type) where + owner : Nat + objects : List Object + contracts : Object → Contract W + requested : Object → Phase → List W + reasons : Object → Phase → List String + basis : Object → Phase → Prop + generationApplies : Object → Phase → Prop + assessmentApplies : Object → Phase → Prop + recorded : Activity → Object → Phase → Outcome W + +def Model.input {W Object : Type} (m : Model W Object) (t : Target Object) : Input W Object := + ⟨t, m.contracts t.object, m.requested t.object t.phase, m.reasons t.object t.phase, + m.basis t.object t.phase⟩ + +def Model.self {W Object : Type} (m : Model W Object) (t : Target Object) : Prop := + t.owner = m.owner ∧ t.object ∈ m.objects + +def Model.rule {W Object : Type} (m : Model W Object) (activity : Activity) : + ReflexiveRule (Target Object) (Input W Object) (Outcome W) where + key := ⟨m.owner, match activity with | .generation => 0 | .assessment => 1⟩ + activity := activity + applicable t := m.self t ∧ match activity with + | .generation => m.generationApplies t.object t.phase + | .assessment => m.assessmentApplies t.object t.phase + input := m.input + meaning := interpret activity + +def Model.rules {W Object : Type} (m : Model W Object) := + [m.rule .generation, m.rule .assessment] + +/- These are the stated records. The separate follows test compares each stated +outcome with the actual input's evaluation, rather than defining success by its name. -/ +def Model.performed {W Object : Type} (m : Model W Object) + (key : PrincipleKey) (t : Target Object) (input : Input W Object) (outcome : Outcome W) : Prop := + m.self t ∧ input = m.input t ∧ + ∃ activity, key = (m.rule activity).key ∧ + outcome = m.recorded activity t.object t.phase + +def Model.follows {W Object : Type} (m : Model W Object) : Prop := + ∀ activity object phase, object ∈ m.objects → + (match activity with + | .generation => m.generationApplies object phase + | .assessment => m.assessmentApplies object phase) → + interpret activity (m.input ⟨m.owner, object, phase⟩) (m.recorded activity object phase) + +/- This generic implication retains the actual evaluation premise. Concrete +engineering instances must discharge follows separately for their own contracts. -/ +theorem recordedReflexivity {W Object : Type} (m : Model W Object) (checked : m.follows) : + reflexivitySpecification m.rules m.self m.performed := by + constructor + · intro p hp q hq equal + simp only [Model.rules, List.mem_cons, List.not_mem_nil, or_false] at hp hq + rcases hp with rfl | rfl <;> rcases hq with rfl | rfl + · rfl + · have bad := congrArg PrincipleKey.localId equal; contradiction + · have bad := congrArg PrincipleKey.localId equal; contradiction + · rfl + · intro rule hr target hs ha + simp only [Model.rules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl + · refine ⟨m.recorded .generation target.object target.phase, + ⟨hs, rfl, .generation, rfl, rfl⟩, ?_⟩ + have actual := checked .generation target.object target.phase hs.2 ha.2 + rcases target with ⟨owner, object, phase⟩ + have ownerEqual : owner = m.owner := hs.1 + subst owner + exact actual + · refine ⟨m.recorded .assessment target.object target.phase, + ⟨hs, rfl, .assessment, rfl, rfl⟩, ?_⟩ + have actual := checked .assessment target.object target.phase hs.2 ha.2 + rcases target with ⟨owner, object, phase⟩ + have ownerEqual : owner = m.owner := hs.1 + subst owner + exact actual + +end CoreReader.Engineering.Reflection diff --git a/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Engineering/SelfApplication.lean b/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Engineering/SelfApplication.lean new file mode 100644 index 0000000..03f51ca --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Engineering/SelfApplication.lean @@ -0,0 +1,229 @@ +import CoreReader.Engineering.Values +import CoreReader.Engineering.Reflection + +namespace CoreReader.Engineering + +open CoreReader.Adopted + +inductive ReviewObject | activity | commitment (principle : CoreCommitment) | priority | evolutionMethod + | generationRule | assessmentRule + deriving DecidableEq, Repr + +abbrev ReviewCase := Candidate × Nat + +def generationApplies (_ : ReviewObject) (phase : CoreReader.Agency.Phase) : Prop := + phase ≠ .application + +def assessmentApplies (_ : ReviewObject) (_ : CoreReader.Agency.Phase) : Prop := True + +def ruleObject : CoreReader.Agency.Activity → ReviewObject + | .generation => .generationRule + | .assessment => .assessmentRule + +/- These inputs test the current reflection functions themselves. Size 10 has +an actual supporting sample; size 5 removes that sample while retaining the +requested claim. The domain batch predictor is not used in this method test. -/ +def ruleProbe (activity : CoreReader.Agency.Activity) (point : ReviewCase) : + Reflection.Input ReviewCase ReviewObject where + target := ⟨0, ruleObject activity, .revision⟩ + contract := ⟨fun _ => true, if point.2 = 10 then [point] else [], [point]⟩ + requested := [point] + reasons := ["retain the proposed scope and distinguish actual samples from an empty test set"] + basis := True + +def generationRuleTest + (method : Reflection.Input ReviewCase ReviewObject → Reflection.Outcome ReviewCase) + (point : ReviewCase) : Bool := + let input := ruleProbe .generation point + method input == .generated input.requested input.requested + +def assessmentRuleTest + (method : Reflection.Input ReviewCase ReviewObject → Reflection.Verdict) + (point : ReviewCase) : Bool := + method (ruleProbe .assessment point) == + (if point.2 = 10 then .supportedWithinScope else .noSupportingSample) + +/- A candidate revision supplies the previously missing empty-sample check. +It is kept distinct from the current evaluator and is not silently adopted. -/ +def sampleAwareAssessment (input : Reflection.Input ReviewCase ReviewObject) : Reflection.Verdict := + if input.contract.tested.isEmpty then .noSupportingSample else Reflection.evaluate input + +/- The method under criticism is the activity's own static batch forecast. Its +contract is checked at its original size and at the credible runtime change. -/ +def objectTest (object : ReviewObject) (point : ReviewCase) : Bool := + match object with + | .activity => decide (Meets currentContinuing.required (currentContinuing.profiles point.1)) + | .commitment principle => safeguardExperiment principle true point.1 + | .priority => decide (EvolutionPriority currentContinuing point.1) + | .evolutionMethod => staticBatch 21 point.2 == liveBatch 21 point.2 + | .generationRule => generationRuleTest Reflection.generate point + | .assessmentRule => assessmentRuleTest Reflection.evaluate point + +def reviewObjects (chosen : Candidate) : List ReviewObject := + [.activity] ++ coreCommitments.map ReviewObject.commitment ++ + (if chosen = .evolvable then [.priority] else []) ++ + [.evolutionMethod, .generationRule, .assessmentRule] + +def requestedCases (chosen : Candidate) : CoreReader.Agency.Phase → List ReviewCase + | .formation | .application => [(chosen, 10)] + | .revision => [(chosen, 10), (chosen, 5)] + +def reviewReasons (object : ReviewObject) (phase : CoreReader.Agency.Phase) : List String := + let content := match object with + | .activity => "actual order, safety, latency and retention requirements of this activity" + | .commitment principle => criticismFor principle + | .priority => "credible design revision, successor and agent paths, necessary requirements and concrete costs" + | .evolutionMethod => "the same batch forecast at its recorded size and the proposed runtime size" + | .generationRule => "the actual generator must retain its input's requested tests and scope" + | .assessmentRule => "the actual evaluator's acceptance depends on whether its input has supporting samples" + [content, match phase with + | .formation => "identify this object's purpose and the conditions of its initial contract" + | .application => "apply that contract to the currently selected design in this continuing activity" + | .revision => "examine the proposed wider input scope and retain any counterexample"] + +/- The recorded verdict is independent of the evaluator: the revision of the +batch method is explicitly reported as a counterexample; other current checks +are reported supported only in the scope that will be checked below. -/ +def statedReview (chosen : Candidate) (activity : CoreReader.Agency.Activity) + (object : ReviewObject) (phase : CoreReader.Agency.Phase) : Reflection.Outcome ReviewCase := + match activity with + | .generation => .generated (requestedCases chosen phase) (requestedCases chosen phase) + | .assessment => .assessed (match object, phase with + | .evolutionMethod, .revision | .assessmentRule, .revision => .counterexample + | _, _ => .supportedWithinScope) + +/- The basis is not a free approval flag. Each inquiry requires the facts +relevant to its own object; a counterexample can ground criticism rather than +the truth of the original method's broader claim. -/ +def reviewBasis (chosen : Candidate) : ReviewObject → CoreReader.Agency.Phase → Prop + | .activity, _ => ActivityScope currentContinuing.activity ∧ + Meets currentContinuing.required (currentContinuing.profiles chosen) + | .commitment principle, _ => ReasonRelevant principle (reasonFor principle) chosen + | .priority, _ => PriorityConditions currentContinuing ∧ ¬ HasThreat currentContinuing .evolvable + | .evolutionMethod, .revision => + staticBatch 21 10 = liveBatch 21 10 ∧ staticBatch 21 5 ≠ liveBatch 21 5 + | .evolutionMethod, _ => staticBatch 21 10 = liveBatch 21 10 + | .generationRule, _ => + generationRuleTest Reflection.generate (chosen, 10) = true ∧ + generationRuleTest (fun _ => .generated [] []) (chosen, 10) = false + | .assessmentRule, .revision => + assessmentRuleTest Reflection.evaluate (chosen, 10) = true ∧ + assessmentRuleTest Reflection.evaluate (chosen, 5) = false + | .assessmentRule, _ => assessmentRuleTest Reflection.evaluate (chosen, 10) = true + +def selfModel (chosen : Candidate) : Reflection.Model ReviewCase ReviewObject where + owner := 0 + objects := reviewObjects chosen + contracts object := ⟨objectTest object, [(chosen, 10)], [(chosen, 10)]⟩ + requested _ := requestedCases chosen + reasons := reviewReasons + basis := reviewBasis chosen + generationApplies := generationApplies + assessmentApplies := assessmentApplies + recorded := statedReview chosen + +/- The named normative object and its finite rationale test are deliberately +distinct: a supported rationale experiment is not proof of universal correctness. +The same commitment identifier controls adoption, reasons and reflection. -/ +theorem reviewIdentity (chosen : Candidate) (object : ReviewObject) + (phase : CoreReader.Agency.Phase) : + ((selfModel chosen).input ⟨0, object, phase⟩).target.object = object ∧ + ((selfModel chosen).input ⟨0, object, phase⟩).contract.test = objectTest object ∧ + ((selfModel chosen).input ⟨0, object, phase⟩).requested = requestedCases chosen phase ∧ + ((selfModel chosen).input ⟨0, object, phase⟩).reasons = reviewReasons object phase ∧ + ((selfModel chosen).input ⟨0, object, phase⟩).basis = reviewBasis chosen object phase := + ⟨rfl, rfl, rfl, rfl, rfl⟩ + +theorem currentSelfRecords (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) : + (selfModel chosen).follows := by + rcases ordinary with rfl | rfl + all_goals + intro activity object phase member applies + cases activity <;> cases object <;> cases phase + all_goals first + | rename_i principle; cases principle + | skip + all_goals simp_all [Reflection.interpret, Reflection.Model.input, + Reflection.evaluate, selfModel, statedReview, reviewObjects, coreCommitments, + requestedCases, reviewReasons, criticismFor, objectTest, safeguardExperiment, + generationApplies, assessmentApplies, generationRuleTest, assessmentRuleTest, + ruleProbe, Reflection.generate, + reviewBasis, ReasonRelevant, reasonFor, HasThreat, burdens, ConcreteThreat, cost, + EvolutionPriority, PriorityConditions, JustifiedDeparture, currentContinuing, + Continuing, ActivityScope, Meets, profile, normalRequirements, initialGrounds, + ContinuingCapability, continuingActivity, maintainers, changePath, + changeWork, abstractionComplexity, credible, CredibleDirection, articulateGround, + supportGround, normalLimits, staticBatch, liveBatch, batchCount, orderedUnique, + sortedUnique, sortValues, insertOrdered, List.eraseDups] + all_goals decide + +theorem currentSelfApplication (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) : + reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self + (selfModel chosen).performed := + Reflection.recordedReflexivity _ (currentSelfRecords chosen ordinary) + +/- The activity's own assessment method passes its old observation while the +expanded input exposes its actual failed forecast. Neither applying the method +to itself nor generating a broader candidate makes the failed forecast true. -/ +theorem actualSelfCriticism (chosen : Candidate) : + objectTest .evolutionMethod (chosen, 10) = true ∧ + objectTest .evolutionMethod (chosen, 5) = false ∧ + Reflection.evaluate ((selfModel chosen).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧ + statedReview chosen .generation .evolutionMethod .revision = + .generated [(chosen, 10), (chosen, 5)] [(chosen, 10), (chosen, 5)] ∧ + staticBatch 21 5 ≠ liveBatch 21 5 := by + refine ⟨?_, ?_, ?_, rfl, by decide⟩ + · change (staticBatch 21 10 == liveBatch 21 10) = true + decide + · change (staticBatch 21 5 == liveBatch 21 5) = false + decide + · simp [Reflection.evaluate, Reflection.Model.input, selfModel, requestedCases, + objectTest, staticBatch, liveBatch, batchCount] + +/- The objects use the very functions in the adopted rules, and the same +applicability functions. Assessment applies in all three phases; generation +applies to formation and revision, including formation/revision of these rules. -/ +theorem ownRuleIdentity (chosen : Candidate) (activity : CoreReader.Agency.Activity) + (phase : CoreReader.Agency.Phase) : + ruleObject activity ∈ (selfModel chosen).objects ∧ + ((selfModel chosen).rule activity).meaning = Reflection.interpret activity ∧ + ((selfModel chosen).input ⟨0, ruleObject activity, phase⟩).contract.test = + objectTest (ruleObject activity) ∧ + (selfModel chosen).generationApplies (ruleObject activity) phase = + generationApplies (ruleObject activity) phase ∧ + (selfModel chosen).assessmentApplies (ruleObject activity) phase = + assessmentApplies (ruleObject activity) phase := by + refine ⟨?_, rfl, rfl, rfl, rfl⟩ + cases activity <;> simp [ruleObject, selfModel, reviewObjects] + +/- Changing the actual generator changes its object's result despite keeping +the object name. The evaluator really approves an empty initial sample set; +its own revision review reports that bounded defect instead of a self-proof. -/ +theorem ownRuleContentVariation (chosen : Candidate) : + generationRuleTest Reflection.generate (chosen, 10) = true ∧ + generationRuleTest (fun _ => .generated [] []) (chosen, 10) = false ∧ + assessmentRuleTest Reflection.evaluate (chosen, 10) = true ∧ + assessmentRuleTest Reflection.evaluate (chosen, 5) = false ∧ + Reflection.evaluate ((selfModel chosen).input ⟨0, .assessmentRule, .revision⟩) = .counterexample ∧ + generationApplies .generationRule .formation ∧ + generationApplies .generationRule .revision ∧ + ¬ generationApplies .generationRule .application ∧ + (∀ phase, assessmentApplies .assessmentRule phase) := by + simp [generationRuleTest, assessmentRuleTest, ruleProbe, Reflection.generate, + Reflection.evaluate, Reflection.Model.input, selfModel, requestedCases, + objectTest, generationApplies, assessmentApplies] + +theorem proposedRuleRevision (chosen : Candidate) : + assessmentRuleTest Reflection.evaluate (chosen, 5) = false ∧ + assessmentRuleTest sampleAwareAssessment (chosen, 5) = true ∧ + assessmentRuleTest sampleAwareAssessment (chosen, 10) = true ∧ + ((selfModel chosen).rule .generation).applicable ⟨0, .generationRule, .revision⟩ ∧ + ¬ (({ selfModel chosen with generationApplies := fun _ _ => False }).rule .generation).applicable + ⟨0, .generationRule, .revision⟩ := by + simp [assessmentRuleTest, sampleAwareAssessment, ruleProbe, Reflection.evaluate, + Reflection.Model.rule, Reflection.Model.self, selfModel, reviewObjects, + generationApplies] + +end CoreReader.Engineering diff --git a/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Engineering/Values.lean b/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Engineering/Values.lean new file mode 100644 index 0000000..2517e93 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Engineering/Values.lean @@ -0,0 +1,224 @@ +import CoreReader.Adopted +import CoreReader.Engineering.Domain + +namespace CoreReader.Engineering + +open CoreReader.Logic CoreReader.Evidence CoreReader.Adopted + +inductive CoreCommitment | generation | consistency | reflexivity | grounds | choice + deriving DecidableEq, Repr + +def coreCommitments : List CoreCommitment := + [.generation, .consistency, .reflexivity, .grounds, .choice] + +/- Initial adoption is explicit. The following reasons neither infer adoption +from facts nor claim that every alternative value position is untenable. -/ +def coreAdopted (_ : CoreCommitment) : Bool := true + +inductive AdoptionReason + | plannedChange (release : Nat) (direction : Change) + | incompatibleOrders (input : List Nat) + | ownMethodCounterexample (items size : Nat) + | unsupportedScope (items observedSize extendedSize : Nat) + | statusBudgetContrast (statusSelected : Candidate) (capacity : Nat) + deriving DecidableEq, Repr + +def reasonFor : CoreCommitment → AdoptionReason + | .generation => .plannedChange 2 .designRevision + | .consistency => .incompatibleOrders [2, 1, 2] + | .reflexivity => .ownMethodCounterexample 21 5 + | .grounds => .unsupportedScope 21 10 5 + | .choice => .statusBudgetContrast .maximal 12 + +/- Each factual reason has contents specific to the principle's purpose. The +context is the very continuing activity and its current requirements/grounds. +Matching a constructor alone is insufficient: the represented facts must hold. -/ +abbrev ReasonRelevant : CoreCommitment → AdoptionReason → Candidate → Prop + | .generation, .plannedChange release direction, _ => + DirectionGround.plan release [direction, .migration] ∈ currentContinuing.evidence ∧ + credible currentContinuing.evidence direction ∧ Continuing currentContinuing.activity + | .consistency, .incompatibleOrders input, _ => + currentContinuing.required.orderRequired = true ∧ + orderedUnique input ≠ sortedUnique input + | .reflexivity, .ownMethodCounterexample items size, _ => + staticBatch items 10 = liveBatch items 10 ∧ staticBatch items size ≠ liveBatch items size + | .grounds, .unsupportedScope items observedSize extendedSize, _ => + staticBatch items observedSize = liveBatch items observedSize ∧ + staticBatch items extendedSize ≠ liveBatch items extendedSize + | .choice, .statusBudgetContrast candidate capacity, selected => + capacity = currentContinuing.limits.capacity .understanding ∧ + capacity < abstractionComplexity candidate ∧ abstractionComplexity selected ≤ capacity + | _, _, _ => False + +abbrev valueScope (selected : Candidate) : Prop := abstractionComplexity selected ≤ 3 + +/- A small operational experiment explains each adopted safeguard's purpose. +These consequences are limited to the stated experiment, not a total value score. +The disabled branch supplies a real contrast for this application policy. -/ +def safeguardExperiment (principle : CoreCommitment) (enabled : Bool) + (selected : Candidate) : Bool := + match principle with + | .generation => + let allowed : List Change := if enabled then [.designRevision, .migration] else [] + allowed.contains .designRevision && decide (credible currentContinuing.evidence .designRevision) + | .consistency => + let firstDemand := orderedUnique [2, 1, 2] + let secondDemand := sortedUnique [2, 1, 2] + let permitsBoth := if enabled then firstDemand == secondDemand else true + !permitsBoth + | .reflexivity => + let selfTests := if enabled then [(21, 10), (21, 5)] else [(21, 10)] + selfTests.any (fun point => staticBatch point.1 point.2 != liveBatch point.1 point.2) + | .grounds => + let licensed := if enabled then [10] else [10, 5] + licensed.all (fun size => staticBatch 21 size == liveBatch 21 size) + | .choice => + let selectedByRule := if enabled then selected else .maximal + decide (abstractionComplexity selectedByRule ≤ currentContinuing.limits.capacity .understanding) + +def criticismFor : CoreCommitment → String + | .generation => "Reconsider this reason if the committed change or continuing maintenance ends." + | .consistency => "Reconsider the comparison if the parties deliberately revise the observable order contract." + | .reflexivity => "This counterexample concerns the stated batch rule; it does not validate all self-assessment." + | .grounds => "A new input condition requires its own support; success at size ten does not cover size five." + | .choice => "If objectives or budgets change, compare the actual alternatives and reasons again." + +def governancePosition (principle : CoreCommitment) : ValuePosition Candidate where + Position := Bool + Outcome := Bool + adopted := true + selected _ := coreAdopted principle + outcome selected enabled := safeguardExperiment principle enabled selected + objective result := result = true + constraints selected _ := valueScope selected + starting := singleton valueScope + reasons := [fun selected _ => ReasonRelevant principle (reasonFor principle) selected] + limits := valueScope + relevantCriticism _ := True + response _ := some (criticismFor principle) + +theorem adoptionReasonRelevant (principle : CoreCommitment) (selected : Candidate) + (scope : valueScope selected) : ReasonRelevant principle (reasonFor principle) selected := by + cases principle + · dsimp only [ReasonRelevant, reasonFor]; decide + · dsimp only [ReasonRelevant, reasonFor]; decide + · dsimp only [ReasonRelevant, reasonFor]; decide + · dsimp only [ReasonRelevant, reasonFor]; decide + · refine ⟨rfl, by decide, ?_⟩ + exact Nat.le_trans scope (by decide) + +theorem safeguardEnabled (principle : CoreCommitment) (selected : Candidate) + (scope : valueScope selected) : safeguardExperiment principle true selected = true := by + cases principle + · dsimp only [safeguardExperiment]; decide + · dsimp only [safeguardExperiment]; decide + · dsimp only [safeguardExperiment]; decide + · dsimp only [safeguardExperiment]; decide + · apply decide_eq_true + exact Nat.le_trans scope (by change 3 ≤ 12; decide) + +theorem safeguardDisabled (principle : CoreCommitment) (selected : Candidate) : + safeguardExperiment principle false selected = false := by + cases principle <;> simp only [safeguardExperiment, Bool.false_eq_true, ↓reduceIte] <;> decide + +theorem governanceValueProcedure (principle : CoreCommitment) : + ValueProcedure (governancePosition principle) := by + refine ⟨by simp [governancePosition], ?_, ?_, ?_⟩ + · refine ⟨.evolvable, (modelsSingleton _ _).2 (by change 3 ≤ 3; decide), + (by change 3 ≤ 3; decide), rfl, ?_⟩ + intro reason member + cases List.mem_singleton.mp member + exact adoptionReasonRelevant principle .evolvable (by change 3 ≤ 3; decide) + · intro selected _ scope _ + exact ⟨safeguardEnabled principle selected scope, scope⟩ + · intro selected _ _ + exact ⟨criticismFor principle, rfl, by cases principle <;> decide⟩ + +theorem governanceGrounded (principle : CoreCommitment) : + valueSpecification (governancePosition principle) := + grounds012Singleton _ (governanceValueProcedure principle) + +/- Factual relevance, rationale experiments and value adoption are separate. +Swapping a reason or altering the input makes the finite rationale fail. -/ +theorem governanceRationaleLimits : + ¬ ReasonRelevant .consistency (reasonFor .generation) .evolvable ∧ + ¬ ReasonRelevant .reflexivity (.ownMethodCounterexample 21 10) .evolvable ∧ + ¬ ReasonRelevant .generation (.plannedChange 9 .addition) .evolvable ∧ + ¬ valueScope .maximal ∧ + (∀ principle, safeguardExperiment principle false .evolvable = false) ∧ + (∀ principle, (governancePosition principle).commitment .presentSimple) := by + refine ⟨by change ¬ False; decide, by decide, by decide, by change ¬ (30 ≤ 3); decide, + fun principle => safeguardDisabled principle .evolvable, fun _ => rfl⟩ + +/- This additional value priority is a real selection between the same designs. +Both scopes retain all necessary domain conditions and no cost exception. +The present-simple stance values less abstraction now without claiming that it +has the better successor-maintainer capability. The other stance values that capability. -/ +def selectionObjective (adopted : Candidate) (outcome : Nat × Nat) : Prop := + match adopted with + | .presentSimple => outcome.1 ≤ 1 + | .evolvable => outcome.2 ≤ 6 + | .maximal => outcome.1 ≤ 1 + +def selectionPosition (adopted : Candidate) : ValuePosition Candidate where + Position := Candidate + Outcome := Nat × Nat + adopted := adopted + selected := id + outcome _ candidate := (abstractionComplexity candidate, changeWork candidate .designRevision) + objective := selectionObjective adopted + constraints _ candidate := abstractionComplexity candidate ≤ currentContinuing.limits.capacity .understanding + starting := singleton (fun candidate => candidate = adopted) + reasons := [fun _ candidate => + abstractionComplexity candidate = (if adopted = .presentSimple then 1 else 3) ∧ + changeWork candidate .designRevision = (if adopted = .presentSimple then 17 else 6)] + limits _ := Continuing currentContinuing.activity ∧ + credible currentContinuing.evidence .designRevision + relevantCriticism _ := True + response _ := some (if adopted = .presentSimple then + "The successor lacks the private-layout path; this choice does not claim evolution priority and must be reconsidered if that value is adopted." + else "The six-step design-revision path does not establish every change is cheap or every forecast is correct.") + +theorem selectionValueProcedure (adopted : Candidate) + (ordinary : adopted = .presentSimple ∨ adopted = .evolvable) : + ValueProcedure (selectionPosition adopted) := by + rcases ordinary with rfl | rfl + · refine ⟨by simp [selectionPosition], ?_, ?_, ?_⟩ + · refine ⟨.presentSimple, (modelsSingleton _ _).2 rfl, ?_, rfl, ?_⟩ + · change Continuing currentContinuing.activity ∧ credible currentContinuing.evidence .designRevision + decide + · intro reason member + cases List.mem_singleton.mp member + decide + · intro selected _ _ allReasons + have actual := allReasons _ (List.mem_singleton.mpr rfl) + change abstractionComplexity .presentSimple = 1 ∧ changeWork .presentSimple .designRevision = 17 at actual + change abstractionComplexity .presentSimple ≤ 1 ∧ + abstractionComplexity .presentSimple ≤ currentContinuing.limits.capacity .understanding + exact ⟨by rw [actual.1]; exact Nat.le_refl _, by rw [actual.1]; decide⟩ + · intro selected _ _ + refine ⟨_, rfl, ?_⟩ + simp + · refine ⟨by simp [selectionPosition], ?_, ?_, ?_⟩ + · refine ⟨.evolvable, (modelsSingleton _ _).2 rfl, ?_, rfl, ?_⟩ + · change Continuing currentContinuing.activity ∧ credible currentContinuing.evidence .designRevision + decide + · intro reason member + cases List.mem_singleton.mp member + decide + · intro selected _ _ allReasons + have actual := allReasons _ (List.mem_singleton.mpr rfl) + change abstractionComplexity .evolvable = 3 ∧ changeWork .evolvable .designRevision = 6 at actual + change changeWork .evolvable .designRevision ≤ 6 ∧ + abstractionComplexity .evolvable ≤ currentContinuing.limits.capacity .understanding + exact ⟨by rw [actual.2]; exact Nat.le_refl _, by rw [actual.1]; decide⟩ + · intro selected _ _ + refine ⟨_, rfl, ?_⟩ + simp + +theorem selectionGrounded (adopted : Candidate) + (ordinary : adopted = .presentSimple ∨ adopted = .evolvable) : + valueSpecification (selectionPosition adopted) := + grounds012Singleton _ (selectionValueProcedure adopted ordinary) + +end CoreReader.Engineering diff --git a/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Evidence.lean b/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Evidence.lean new file mode 100644 index 0000000..d6573bc --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Evidence.lean @@ -0,0 +1,725 @@ +import CoreReader.Logic +import CoreReader.Agency + +namespace CoreReader.Evidence +open CoreReader.Logic +open CoreReader.Agency + +/- An observation records the outcome of a specified test on the represented world. -/ +structure Record (W : Type) where + test : W → Bool + observed : Bool +/- Compatible worlds reproduce the actual contents of every recorded observation. -/ +def Compatible {W : Type} (records : List (Record W)) (w : W) : Prop := + ∀ r, r ∈ records → r.test w = r.observed +/- Inferential support requires the same claim in every evidence-compatible world. -/ +def Supports {W : Type} (records : List (Record W)) (claim : Claim W) : Prop := + ∀ w, Compatible records w → claim w +/- Articulation identifies concepts, premises, reason contents and an application limit. -/ +structure Articulation (W : Type) where + concepts : List String + assumptions : Theory W + reasons : List (Claim W) + limits : Claim W +/- Nonempty identifiable concepts and reasons are procedural articulation requirements. -/ +def Articulated {W : Type} (a : Articulation W) : Prop := + a.concepts ≠ [] ∧ a.reasons ≠ [] +/- This application model interprets an adopted option through its actual outcomes and stated goals/constraints. -/ +structure ValuePosition (W : Type) where + Position : Type + Outcome : Type + adopted : Position + selected : W → Position + outcome : W → Position → Outcome + objective : Outcome → Prop + constraints : W → Position → Prop + starting : Theory W + reasons : List (W → Position → Prop) + limits : Claim W + relevantCriticism : Claim W + response : W → Option String +/- The adopted position's claim is derived from the same selected option used by the outcome interpretation. -/ +def ValuePosition.commitment {W : Type} (v : ValuePosition W) : Claim W := + fun w => v.selected w = v.adopted +/- Assessed consequences concern this adopted option's actual outcome, objective and constraints. -/ +def ValuePosition.consequence {W : Type} (v : ValuePosition W) : Claim W := + fun w => v.objective (v.outcome w v.adopted) ∧ v.constraints w v.adopted +/- Articulated reasons specialize the actual option-indexed premises to the adopted option. -/ +def ValuePosition.activeReasons {W : Type} (v : ValuePosition W) : List (Claim W) := + v.reasons.map (fun reason w => reason w v.adopted) +/- A joint witness excludes inconsistent starts and impossible adoption states. -/ +def JointAdoption {W : Type} (v : ValuePosition W) : Prop := + ∃ w, Models v.starting w ∧ v.limits w ∧ v.commitment w ∧ + ∀ reason, reason ∈ v.reasons → reason w v.adopted +/- This declared option/outcome adapter checks joint reasons for an assessed consequence; it is not a necessary deductive form for all value justification. -/ +def ValueProcedure {W : Type} (v : ValuePosition W) : Prop := + v.reasons ≠ [] ∧ JointAdoption v ∧ + (∀ w, Models v.starting w → v.limits w → + (∀ reason, reason ∈ v.reasons → reason w v.adopted) → v.consequence w) ∧ + (∀ w, v.limits w → v.relevantCriticism w → ∃ answer, v.response w = some answer ∧ answer ≠ "") +/- A facet carries its specific contents; several different facets can have the same conclusion. -/ +inductive Facet (W : Type) where + | empirical (records : List (Record W)) (scope conclusion uncertainty : Claim W) + | inferential (assumptions : Theory W) (conclusion : Claim W) + | value (position : ValuePosition W) +/- The claim referred to by each assessment facet is explicit. -/ +def Facet.claim {W : Type} : Facet W → Claim W + | .empirical _ _ p _ => p + | .inferential _ p => p + | .value v => v.commitment +/- These disclosed semantic adapters implement selected nature-specific checks; passing them does not establish all real empirical or value adequacy. -/ +def FacetDischarged {W : Type} : Facet W → Prop + | .empirical records scope p uncertainty => + (∃ w, Compatible records w ∧ scope w) ∧ + Supports records (fun w => scope w → p w) ∧ Supports records uncertainty + | .inferential assumptions p => Satisfiable assumptions ∧ Entails assumptions p + | .value v => ValueProcedure v +/- This model's semantic adapter identifies the actual assumptions, reason content and limit of a facet. -/ +def FacetArticulated {W : Type} (a : Articulation W) : Facet W → Prop + | .empirical records scope _ _ => + a.assumptions = singleton (Compatible records) ∧ a.reasons = [Compatible records] ∧ a.limits = scope + | .inferential assumptions _ => + a.assumptions = assumptions ∧ a.reasons = [Models assumptions] ∧ a.limits = (fun _ => True) + | .value v => a.assumptions = v.starting ∧ a.reasons = v.activeReasons ∧ a.limits = v.limits +/- A canonical articulation exposes this adapter; the source does not mandate this particular representation of grounds. -/ +def canonicalArticulation {W : Type} : Facet W → Articulation W + | .empirical records scope _ _ => + ⟨["recorded test outcomes", "observation conditions"], singleton (Compatible records), [Compatible records], scope⟩ + | .inferential assumptions _ => + ⟨["stated assumptions", "semantic consequence"], assumptions, [Models assumptions], fun _ => True⟩ + | .value v => + ⟨["adopted position", "reasons and consequences"], v.starting, v.activeReasons, v.limits⟩ +/- Canonical articulation is connected to the very facet whose grounds it identifies. -/ +theorem canonicalFacetArticulated {W : Type} (f : Facet W) : + FacetArticulated (canonicalArticulation f) f := by + cases f <;> exact ⟨rfl, rfl, rfl⟩ +/- A discharged facet has nonempty canonical reason articulation, including the value procedure's reason requirement. -/ +theorem canonicalArticulated {W : Type} (f : Facet W) (h : FacetDischarged f) : + Articulated (canonicalArticulation f) := by + cases f with + | empirical records scope p uncertainty => simp [Articulated, canonicalArticulation] + | inferential assumptions p => simp [Articulated, canonicalArticulation] + | value v => + refine ⟨by simp [canonicalArticulation], ?_⟩ + simpa [canonicalArticulation, ValuePosition.activeReasons] using h.1 +/- This model of the Grounds obligation binds each actual facet to its claim and articulation. Its disclosed FacetDischarged adapters do not replace all source-level assessment responsibilities or prove real adequacy. -/ +def Grounds {W : Type} (claim : Claim W) (articulations : Facet W → Articulation W) + (actualApplicable : Facet W → Prop) (facets : List (Facet W)) : Prop := + facets ≠ [] ∧ (∀ facet, actualApplicable facet → facet ∈ facets) ∧ + ∀ facet, facet ∈ facets → facet.claim = claim ∧ Articulated (articulations facet) ∧ + FacetArticulated (articulations facet) facet ∧ FacetDischarged facet +/- The achievement obligation requires grounds for this very claim, without making observation a universal prerequisite. -/ +def AchievementAccountability {W : Type} (achievement : Claim W) (articulations : Facet W → Articulation W) + (actualApplicable : Facet W → Prop) (facets : List (Facet W)) : Prop := + Grounds achievement articulations actualApplicable facets +/- The concrete achievement claim refers to each transition's own before/after states. -/ +def transitionAchievement : Claim TransitionCase := + fun transition => Expanded (transitionBefore transition) (transitionAfter transition) +/- This observation inspects an actually constructed successor and its output under that transition's input condition. -/ +def transitionPerformanceRecord : Record TransitionCase := + ⟨fun transition => (transitionAfter transition).constructed.any + (fun operation => operation == .successor && decide (operation.run (transitionInput transition) = 1)), true⟩ +/- The positive report test reads its asserted operation, input and output; it does not verify their presence in the after-state. -/ +def transitionReportRecord : Record TransitionCase := + ⟨fun transition => + let report := transitionAnnouncement transition + report.reportedNewOperation == .successor && report.input == 0 && report.expectedOutput == 1, true⟩ +/- Only the genuine extension matches the operation/performance observation in this two-transition model. -/ +theorem transitionPerformanceCompatible : + ∀ transition, Compatible [transitionPerformanceRecord] transition ↔ transition = .extend := by + intro transition + constructor + · intro h + have observed := h transitionPerformanceRecord (List.mem_singleton.mpr rfl) + cases transition + · cases observed + · rfl + · intro h; cases h + intro record hr; have hr' := List.mem_singleton.mp hr; subst record + rfl +/- A compatible performance observation establishes the same transition's report content and hence its represented expansion. -/ +theorem transitionSupported : Supports [transitionPerformanceRecord] transitionAchievement := by + intro transition compatible + have h := (transitionPerformanceCompatible transition).1 compatible + subst transition + have reportTrue : (transitionAnnouncement .extend).claim := by + simp [transitionAnnouncement, transitionAfter, transitionInput, + Announcement.claim, GeneratingSystem.report, generatingSystem, extendedState, baseState, Operation.run] + exact announcementClaimImpliesExpansion _ reportTrue +/- The actual scope is the shared input-zero condition, with no probabilistic inference introduced. -/ +def transitionFacet : Facet TransitionCase := + .empirical [transitionPerformanceRecord] (fun transition => transitionInput transition = 0) + transitionAchievement (fun _ => True) +/- The empirical assessment has a real compatible witness and supports this scoped achievement. -/ +theorem transitionFacetDischarged : FacetDischarged transitionFacet := by + refine ⟨⟨.extend, (transitionPerformanceCompatible _).2 rfl, rfl⟩, ?_, ?_⟩ + · intro transition compatible _; exact transitionSupported transition compatible + · intro _ _; trivial +/- Every applicable facet of this specified achievement has matching articulation and actual discharged evidence. -/ +theorem transitionAccountable : + AchievementAccountability transitionAchievement canonicalArticulation + (fun facet => facet = transitionFacet) [transitionFacet] := by + refine ⟨by simp, ?_, ?_⟩ + · intro facet hf; subst facet; exact List.mem_singleton.mpr rfl + · intro facet hf; have hf' := List.mem_singleton.mp hf; subst facet + exact ⟨rfl, canonicalArticulated _ transitionFacetDischarged, + canonicalFacetArticulated _, transitionFacetDischarged⟩ +/- Both actual transitions issue the same positive report about their own identified state pair. -/ +theorem transitionReportCompatible (transition : TransitionCase) : + Compatible [transitionReportRecord] transition := by + intro record hr; have hr' := List.mem_singleton.mp hr; subst record + rfl +/- Inflation is a concrete report-compatible counterworld, so the positive report alone does not support the same achievement claim. -/ +theorem transitionReportDoesNotSupport : + Compatible [transitionReportRecord] .inflate ∧ ¬ transitionAchievement .inflate ∧ + ¬ Supports [transitionReportRecord] transitionAchievement := by + have noExpansion : ¬ transitionAchievement .inflate := by + simp [transitionAchievement, transitionBefore, transitionAfter, Expanded, baseState, inflatedState] + exact ⟨transitionReportCompatible _, noExpansion, fun h => noExpansion (h _ (transitionReportCompatible _))⟩ +/- These concrete obligations, positive evidence and negative report case all refer to the same state-pair and input semantics. -/ +def ConcreteAchievementExample : Prop := + AchievementAccountability transitionAchievement canonicalArticulation + (fun facet => facet = transitionFacet) [transitionFacet] ∧ + Compatible [transitionPerformanceRecord] .extend ∧ + Supports [transitionPerformanceRecord] transitionAchievement ∧ transitionAchievement .extend ∧ + (Compatible [transitionReportRecord] .inflate ∧ ¬ transitionAchievement .inflate ∧ + ¬ Supports [transitionReportRecord] transitionAchievement) ∧ + (∀ transition, (transitionAnnouncement transition).before = transitionBefore transition ∧ + (transitionAnnouncement transition).after = transitionAfter transition ∧ + (transitionAnnouncement transition).input = transitionInput transition ∧ transitionInput transition = 0) +/- The concrete example jointly inhabits accountability, evidence compatibility, actual gain, and the report-only countermodel. -/ +theorem concreteAchievementExample : ConcreteAchievementExample := by + refine ⟨transitionAccountable, (transitionPerformanceCompatible _).2 rfl, transitionSupported, + transitionSupported .extend ((transitionPerformanceCompatible _).2 rfl), + transitionReportDoesNotSupport, ?_⟩ + intro transition; exact ⟨rfl,rfl,rfl,rfl⟩ +/- Semantic evidence yields truth only at a world that actually satisfies those evidence conditions. -/ +theorem achievementNeedsSupport {W : Type} (achievement : Claim W) (records : List (Record W)) + (actual : W) (reliableHere : Compatible records actual) (support : Supports records achievement) : + achievement actual ∧ ConcreteAchievementExample := + ⟨support actual reliableHere, concreteAchievementExample⟩ +/- Weakening a conclusion preserves support; this makes no claim about weakening the evidence. -/ +theorem supportWeakening {W : Type} (records : List (Record W)) (p q : Claim W) + (support : Supports records p) (weaker : ∀ w, p w → q w) : Supports records q := + fun w hw => weaker w (support w hw) +/- Discarding the only informative observation loses support for the unchanged switch claim. -/ +theorem evidenceWeakeningCanLoseSupport : + Supports ([⟨id, true⟩] : List (Record Bool)) (fun w => w = true) ∧ + ¬ Supports ([] : List (Record Bool)) (fun w => w = true) := by + refine ⟨?_, ?_⟩ + · intro w hw; exact hw ⟨id,true⟩ (by simp) + · intro h; have bad := h false (by intro r hr; cases hr); cases bad +/- Restricting the quantified application domain preserves a supported universal conclusion. -/ +theorem scopeRestriction {W X : Type} (records : List (Record W)) (p : W → X → Prop) + (wide narrow : X → Prop) (included : ∀ x, narrow x → wide x) + (support : Supports records (fun w => ∀ x, wide x → p w x)) : + Supports records (fun w => ∀ x, narrow x → p w x) := + fun w hw x hx => support w hw x (included x hx) +/- Actual applicability, rather than an optional classifier label, determines facet responsibility. -/ +def Duties {W : Type} (applicable : Facet W → Prop) : Prop := + ∀ f, applicable f → FacetDischarged f +def LabeledDuties {W : Type} (_labels : List String) (applicable : Facet W → Prop) : Prop := + Duties applicable +/- Combining applicable facets requires both sets of substantive duties. -/ +theorem assessmentUnion {W : Type} (a b : Facet W → Prop) : + Duties (fun f => a f ∨ b f) ↔ Duties a ∧ Duties b := by + constructor + · intro h; exact ⟨fun f hf => h f (Or.inl hf), fun f hf => h f (Or.inr hf)⟩ + · rintro ⟨ha,hb⟩ f (hf|hf); exact ha f hf; exact hb f hf +/- Omitting or changing labels does not remove an applicable duty. -/ +theorem labelsCannotWaive {W : Type} (xs ys : List String) (a : Facet W → Prop) : + LabeledDuties xs a ↔ LabeledDuties ys a := Iff.rfl +/- The observed switch is the outcome itself, not a record identifier. -/ +def switchRecord : Record Bool := ⟨id, true⟩ +theorem switchCompatible (w : Bool) : Compatible [switchRecord] w ↔ w = true := by + constructor + · intro h; exact h switchRecord (by simp) + · intro hw r hr; simp only [List.mem_singleton] at hr; cases hr; exact hw +theorem switchSupported : Supports [switchRecord] (fun w : Bool => w = true) := + fun w hw => (switchCompatible w).1 hw +/- The candidate action has specific benefit and cost outcomes; its inactive alternative has neither. -/ +def optionBenefit (selected : Bool) : Nat := if selected then 4 else 0 +def optionCost (selected : Bool) : Nat := if selected then 3 else 0 +/- The report describes each option's actual cost and benefit; it does not itself assert which option ought to be selected. -/ +def optionReport (selected : Bool) : Prop := + optionCost selected ≤ 3 ∧ optionBenefit selected = (if selected then 4 else 0) +/- The on position connects its own selected option to that option's benefit/cost outcome. -/ +def switchPosition : ValuePosition Bool where + Position := Bool + Outcome := Nat × Nat + adopted := true + selected := id + outcome := fun _ option => (optionBenefit option, optionCost option) + objective := fun result => result.2 < result.1 + constraints := fun _ option => optionCost option ≤ 3 + starting := singleton (fun w => w = true) + reasons := [fun _ option => optionReport option] + limits := fun _ => True + relevantCriticism := fun w => w = false + response := fun w => if w then some "benefit exceeds cost within budget" else some "reconsider if the budget no longer permits this cost" +theorem switchValueProcedure : ValueProcedure switchPosition := by + refine ⟨by simp [switchPosition], ?_, ?_, ?_⟩ + · refine ⟨true, (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩ + intro reason hr + have hr' : reason = (fun (_ : Bool) (option : Bool) => optionReport option) := List.mem_singleton.mp hr + subst reason + exact ⟨by decide, rfl⟩ + · intro w _ _ allReasons + have evidence := allReasons (fun (_ : Bool) (option : Bool) => optionReport option) (List.mem_singleton.mpr rfl) + change optionReport true at evidence + have benefitAboveBudget : 3 < optionBenefit true := by rw [evidence.2]; decide + exact ⟨Nat.lt_of_le_of_lt evidence.1 benefitAboveBudget, evidence.1⟩ + · intro w _ _; cases w <;> simp [switchPosition] +/- Adopting the other option updates the adopted starting state too, so rejection cannot be blamed on an inconsistent start. -/ +def oppositePosition : ValuePosition Bool := + { switchPosition with adopted := false, starting := singleton (fun w => w = false) } +/- The alternative has a joint adoption witness but its actual zero benefit/cost fails the adopted strict-benefit objective. -/ +theorem oppositePositionRejected : JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition := by + have witness : JointAdoption oppositePosition := by + refine ⟨false, (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩ + intro reason hr + have hr' : reason = (fun (_ : Bool) (option : Bool) => optionReport option) := List.mem_singleton.mp hr + subst reason + exact ⟨by decide, rfl⟩ + refine ⟨witness, ?_⟩ + intro h + have allReasons : ∀ reason, reason ∈ oppositePosition.reasons → reason false oppositePosition.adopted := by + intro reason hr + have hr' : reason = (fun (_ : Bool) (option : Bool) => optionReport option) := List.mem_singleton.mp hr + subst reason + exact ⟨by decide, rfl⟩ + have bad := h.2.2.1 false ((modelsSingleton _ _).2 rfl) trivial allReasons + exact Nat.lt_irrefl 0 bad.1 +/- Contradictory starting assumptions and an impossible selected/adopted equality are separate inadmissible variants. -/ +def contradictoryStartingPosition : ValuePosition Bool := + { switchPosition with starting := singleton (fun _ => False) } +def impossibleAdoptionPosition : ValuePosition Bool := + { switchPosition with selected := fun _ => false } +/- The common-world witness rejects both contradiction and an impossible commitment instead of proving them vacuously. -/ +theorem inadmissibleValuePositionsRejected : + ¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition := by + constructor + · intro h; obtain ⟨w,hw,_,_,_⟩ := h.2.1 + exact (modelsSingleton _ _).1 hw + · intro h; obtain ⟨w,_,_,hw,_⟩ := h.2.1 + cases hw +/- Removing the reasons leaves only a position and assertion, which fails this value procedure. -/ +def unsupportedPosition : ValuePosition Bool := { switchPosition with reasons := [] } +def switchEmpirical : Facet Bool := + .empirical [switchRecord] (fun _ => True) (fun w => w = true) (fun _ => True) +theorem switchEmpiricalDischarged : FacetDischarged switchEmpirical := by + refine ⟨⟨true, (switchCompatible true).2 rfl, trivial⟩, ?_, ?_⟩ + · intro w hw _; exact switchSupported w hw + · intro w _; trivial +/- A mixed empirical/value position has actual empirical evidence but still lacks its value-reason duty. -/ +theorem mixedMissingResponsibility : + FacetDischarged switchEmpirical ∧ + ¬ LabeledDuties [] (fun f : Facet Bool => f = switchEmpirical ∨ f = .value unsupportedPosition) := by + refine ⟨switchEmpiricalDischarged, ?_⟩ + intro h + have bad := (h (.value unsupportedPosition) (Or.inr rfl)).1 + exact bad rfl +/- A fully identified argument may still fail to entail the stated conclusion. -/ +def uninformativeArgument : Articulation Bool := + ⟨["switch state"], emptyTheory, [fun _ => True], fun _ => True⟩ +theorem articulationNotSupport : Articulated uninformativeArgument ∧ + ¬ Entails uninformativeArgument.assumptions (fun w : Bool => w = true) := by + exact ⟨⟨by simp [uninformativeArgument], by simp [uninformativeArgument]⟩, + consistentIncomplete.2.1⟩ +/- Identifiable but unrelated argument fields cannot replace the actual observation grounds under the connected adapter. -/ +theorem unrelatedArticulationRejected : + Articulated uninformativeArgument ∧ FacetDischarged switchEmpirical ∧ + ¬ FacetArticulated uninformativeArgument switchEmpirical := by + refine ⟨articulationNotSupport.1, switchEmpiricalDischarged, ?_⟩ + intro h + have relation := congrFun h.1 (Compatible [switchRecord]) + have bad : False := relation.mpr rfl + exact bad +/- Repetition of the same unrelated temperature observation leaves the switch state undetermined. -/ +def temperatureRecord : Record (Bool × Bool) := ⟨Prod.fst, true⟩ +theorem temperatureCompatible (b : Bool) : + Compatible [temperatureRecord, temperatureRecord] (true,b) := by + intro r hr + simp at hr + cases hr + rfl +/- The world identifies a selected action and its budget; the action costs three units. -/ +abbrev BudgetWorld := Bool × Nat +/- A real issued announcement asserts the selected action, but says nothing about affordability. -/ +def announcement : String := "activate" +def announcementPosition : ValuePosition BudgetWorld where + Position := Bool + Outcome := Nat × Nat + adopted := true + selected := Prod.fst + outcome := fun _ option => (optionBenefit option, optionCost option) + objective := fun result => result.2 < result.1 + constraints := fun w option => optionCost option ≤ w.2 + starting := singleton (fun w => w.1 = true) + reasons := [fun _ option => announcement = (if option then "activate" else "disable")] + limits := fun _ => True + relevantCriticism := fun w => w.2 < 3 + response := fun _ => some "reconsider the action when its cost exceeds budget" +/- The zero-budget counterworld satisfies the stated starts, adoption and all announced reasons jointly. -/ +theorem announcementHasJointAdoption : JointAdoption announcementPosition := by + refine ⟨(true,0), (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩ + intro reason hr + have hr' : reason = (fun (_ : BudgetWorld) (option : Bool) => announcement = (if option then "activate" else "disable")) := + List.mem_singleton.mp hr + subst reason + rfl +/- A nonempty announcement remains true in a jointly admissible zero-budget world but cannot support the action's affordability. -/ +theorem announcementNotBudgetReason : + announcementPosition.reasons ≠ [] ∧ announcementPosition.commitment (true,0) ∧ + (∀ reason, reason ∈ announcementPosition.reasons → reason (true,0) announcementPosition.adopted) ∧ + ¬ announcementPosition.consequence (true,0) ∧ ¬ ValueProcedure announcementPosition := by + refine ⟨by simp [announcementPosition], rfl, ?_, (by intro h; cases h.2), ?_⟩ + · intro reason hr + have hr' : reason = (fun (_ : BudgetWorld) (option : Bool) => announcement = (if option then "activate" else "disable")) := List.mem_singleton.mp hr + subst reason + rfl + · intro h + have allReasons : ∀ reason, reason ∈ announcementPosition.reasons → reason (true,0) announcementPosition.adopted := by + intro reason hr + have hr' : reason = (fun (_ : BudgetWorld) (option : Bool) => announcement = (if option then "activate" else "disable")) := List.mem_singleton.mp hr + subst reason + rfl + have bad := h.2.2.1 (true,0) ((modelsSingleton _ _).2 rfl) trivial allReasons + cases bad.2 +/- A repeated actual selection observation contains no budget information. -/ +def actionRecord : Record BudgetWorld := ⟨Prod.fst, true⟩ +theorem actionCompatible (budget : Nat) : Compatible [actionRecord, actionRecord] (true,budget) := by + intro r hr; simp at hr; cases hr; rfl +/- Single and repeated irrelevant observations cannot establish the other outcome or the same action's budget adequacy. -/ +theorem measurementRepeatNotSupport : + temperatureRecord.test (true,false) = true ∧ + Compatible [temperatureRecord,temperatureRecord] (true,false) ∧ + Compatible [temperatureRecord,temperatureRecord] (true,true) ∧ + ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + Compatible [actionRecord,actionRecord] (true,0) ∧ + Compatible [actionRecord,actionRecord] (true,3) ∧ + ¬ Supports [actionRecord] announcementPosition.consequence ∧ + ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧ + ¬ ValueProcedure announcementPosition := by + refine ⟨rfl, temperatureCompatible false, temperatureCompatible true, ?_, ?_, + actionCompatible 0, actionCompatible 3, ?_, ?_, announcementNotBudgetReason.2.2.2.2⟩ + · intro h + have bad := h (true,false) (by intro r hr; simp only [List.mem_singleton] at hr; cases hr; rfl) + cases bad + · intro h; have bad := h (true,false) (temperatureCompatible false); cases bad + · intro h + have bad := h (true,0) (by intro r hr; simp only [List.mem_singleton] at hr; cases hr; rfl) + cases bad.2 + · intro h; have bad := h (true,0) (actionCompatible 0); cases bad.2 +/- Missing reason records fail a procedure; independently, a present announcement fails the explicit budget-support criterion. -/ +theorem selfAssertionNotReason : + (unsupportedPosition.commitment true ∧ ¬ ValueProcedure unsupportedPosition) ∧ + (announcementPosition.reasons ≠ [] ∧ announcementPosition.commitment (true,0) ∧ + ¬ announcementPosition.consequence (true,0) ∧ ¬ ValueProcedure announcementPosition) ∧ + JointAdoption announcementPosition := + ⟨⟨rfl, fun h => h.1 rfl⟩, + ⟨announcementNotBudgetReason.1, announcementNotBudgetReason.2.1, + announcementNotBudgetReason.2.2.2.1, announcementNotBudgetReason.2.2.2.2⟩, + announcementHasJointAdoption⟩ +/- The value procedure is satisfiable although the adopted starting commitment is not entailed by empty facts. -/ +theorem valueWithoutSelfProof : ValueProcedure switchPosition ∧ + Satisfiable switchPosition.starting ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧ + (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧ + (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition) := + ⟨switchValueProcedure, ⟨true, (modelsSingleton _ _).2 rfl⟩, consistentIncomplete.2.1, + oppositePositionRejected, inadmissibleValuePositionsRejected⟩ +/- The world records the selected option and its actual benefit/cost outcomes. -/ +abbrev BenefitCostWorld := Bool × (Nat × Nat) +def measuredOutcome (world : BenefitCostWorld) (option : Bool) : Nat × Nat := + if option then world.2 else (0,0) +def benefitReason (world : BenefitCostWorld) (option : Bool) : Prop := + (measuredOutcome world option).1 = 4 +def costReason (world : BenefitCostWorld) (option : Bool) : Prop := + (measuredOutcome world option).2 ≤ 3 +/- Neither recorded benefit nor recorded cost alone establishes the selected option's joint consequence. -/ +def jointReasonPosition : ValuePosition BenefitCostWorld where + Position := Bool + Outcome := Nat × Nat + adopted := true + selected := Prod.fst + outcome := measuredOutcome + objective := fun result => result.2 < result.1 + constraints := fun world option => (measuredOutcome world option).2 ≤ 3 + starting := singleton (fun world => world.1 = true) + reasons := [benefitReason, costReason] + limits := fun _ => True + relevantCriticism := fun world => 3 < world.2.2 + response := fun _ => some "reassess the option when its cost exceeds the budget" +/- These two content constraints jointly establish the consequence in a nonempty adopted world. -/ +theorem jointReasonProcedure : ValueProcedure jointReasonPosition := by + refine ⟨by simp [jointReasonPosition], ?_, ?_, ?_⟩ + · refine ⟨(true,(4,3)), (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩ + intro reason hr + change reason ∈ [benefitReason,costReason] at hr + rcases List.mem_cons.mp hr with hr | hr + · subst reason; rfl + · have hr' := List.mem_singleton.mp hr + subst reason + change 3 ≤ 3; exact Nat.le_refl 3 + · intro world _ _ reasons + have benefit := reasons benefitReason (by change benefitReason ∈ [benefitReason,costReason]; simp) + have cost := reasons costReason (by change costReason ∈ [benefitReason,costReason]; simp) + change (measuredOutcome world true).1 = 4 at benefit + change (measuredOutcome world true).2 ≤ 3 at cost + refine ⟨?_, cost⟩ + have bigger : 3 < (measuredOutcome world true).1 := by rw [benefit]; decide + exact Nat.lt_of_le_of_lt cost bigger + · intro world _ _ + exact ⟨"reassess the option when its cost exceeds the budget", rfl, by decide⟩ +/- Each separate reason has a concrete same-start/limit/adoption counterworld; their conjunction is sufficient. -/ +def JointReasonsExample : Prop := + ValueProcedure jointReasonPosition ∧ + (Models jointReasonPosition.starting (true,(4,5)) ∧ jointReasonPosition.limits (true,(4,5)) ∧ + jointReasonPosition.commitment (true,(4,5)) ∧ benefitReason (true,(4,5)) true ∧ + ¬ jointReasonPosition.consequence (true,(4,5))) ∧ + (Models jointReasonPosition.starting (true,(0,3)) ∧ jointReasonPosition.limits (true,(0,3)) ∧ + jointReasonPosition.commitment (true,(0,3)) ∧ costReason (true,(0,3)) true ∧ + ¬ jointReasonPosition.consequence (true,(0,3))) +theorem jointReasonsExample : JointReasonsExample := by + refine ⟨jointReasonProcedure, + ⟨(modelsSingleton _ _).2 rfl, trivial, rfl, rfl, ?_⟩, + ⟨(modelsSingleton _ _).2 rfl, trivial, rfl, Nat.le_refl 3, ?_⟩⟩ + · intro h; have bad : 5 ≤ 3 := h.2; omega + · intro h; have bad : 3 < 0 := h.1; omega +/- Empirical observations, semantic inference and criticism-responsive reasons coexist without a scalar score. -/ +theorem heterogeneousReasons : + FacetDischarged switchEmpirical ∧ + FacetDischarged (Facet.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) ∧ + FacetDischarged (Facet.value switchPosition) ∧ JointReasonsExample := by + refine ⟨switchEmpiricalDischarged, ⟨⟨true, (modelsSingleton _ _).2 rfl⟩, ?_⟩, switchValueProcedure, jointReasonsExample⟩ + intro w hw; exact (modelsSingleton (fun x : Bool => x = true) w).1 hw + +/- This local observation checks the actual output on input zero. -/ +def zeroRecord : Record (Nat → Bool) := ⟨fun f => f 0, true⟩ +def localGenerator (seed : Nat) : Nat → Bool := fun n => n == seed +/- All outputs being true is a stronger, explicitly quantified capability claim. -/ +def allTrue : Claim (Nat → Bool) := fun f => ∀ n, f n = true +theorem zeroCompatible (f : Nat → Bool) : Compatible [zeroRecord] f ↔ f 0 = true := by + constructor + · intro h; exact h zeroRecord (by simp) + · intro hf r hr; simp only [List.mem_singleton] at hr; cases hr; exact hf +/- A generating subject owns an earlier predicate and a seed used to revise that actual predicate. -/ +structure GeneratingProcess where + owner : Nat + prior : Nat → Bool + generateSeed : Nat +/- The revision preserves prior successes and adds the seed-selected case through the actual generator. -/ +def GeneratingProcess.outputRevision (process : GeneratingProcess) : Nat → Bool := + fun input => process.prior input || localGenerator process.generateSeed input +/- A produced revision retains its producer and exact old/new objects. -/ +structure ProducedRevision where + producer : Nat + before : Nat → Bool + after : Nat → Bool +/- The subject itself constructs the owned before/after revision object. -/ +def GeneratingProcess.produce (process : GeneratingProcess) : ProducedRevision := + ⟨process.owner, process.prior, process.outputRevision⟩ +def sampleGeneratingProcess : GeneratingProcess := ⟨17, fun _ => false, 0⟩ +/- This same-owner revision actually changes input zero, while its produced predicate still fails at input one. -/ +def OwnedRevisionExample : Prop := + sampleGeneratingProcess.produce.producer = sampleGeneratingProcess.owner ∧ + sampleGeneratingProcess.produce.before = sampleGeneratingProcess.prior ∧ + sampleGeneratingProcess.produce.after = sampleGeneratingProcess.outputRevision ∧ + sampleGeneratingProcess.produce.before 0 = false ∧ sampleGeneratingProcess.produce.after 0 = true ∧ + sampleGeneratingProcess.produce.after 1 = false ∧ + Compatible [zeroRecord] sampleGeneratingProcess.produce.after ∧ + ¬ Supports [zeroRecord] allTrue +/- Actual producer/old/new links and the compatible failing revision witness the insufficiency of self-origin. -/ +theorem ownedRevisionExample : OwnedRevisionExample := by + refine ⟨rfl,rfl,rfl,rfl,rfl,rfl,(zeroCompatible _).2 rfl, ?_⟩ + intro h + have bad := h sampleGeneratingProcess.produce.after ((zeroCompatible _).2 rfl) 1 + cases bad +/- The generator's own sample succeeds, but its generated revision has a concrete unsupported global claim. -/ +theorem selfOriginDoesNotSupport : + localGenerator 0 0 = true ∧ localGenerator 0 1 = false ∧ + Compatible [zeroRecord] (localGenerator 0) ∧ + ¬ Supports [zeroRecord] allTrue ∧ OwnedRevisionExample := by + refine ⟨rfl, rfl, (zeroCompatible _).2 rfl, ?_, ownedRevisionExample⟩ + intro h + have bad := h (localGenerator 0) ((zeroCompatible _).2 rfl) 1 + cases bad +/- A proper local observation allows both a universally successful and a failing extension. -/ +theorem localNotUniversal : + (∃ outside : Nat, outside ≠ 0) ∧ + Compatible [zeroRecord] (fun _ => true) ∧ + Compatible [zeroRecord] (localGenerator 0) ∧ + allTrue (fun _ => true) ∧ ¬ allTrue (localGenerator 0) ∧ + ¬ Supports [zeroRecord] allTrue := by + refine ⟨⟨1, by decide⟩, (zeroCompatible _).2 rfl, (zeroCompatible _).2 rfl, + (fun _ => rfl), ?_, selfOriginDoesNotSupport.2.2.2.1⟩ + intro h; have bad := h 1; cases bad +/- Two implementations agree on the actual observed input and differ on a specified relevant omitted input. -/ +theorem hiddenDifference : + (∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧ + (fun _ : Nat => true) 1 ≠ localGenerator 0 1 := by + refine ⟨?_, by decide⟩ + intro n hn; cases hn; rfl +/- One observation supplies only its actual input-specific consequence, without repetition. -/ +theorem singleObservation : [zeroRecord].length = 1 ∧ + (∃ f, Compatible [zeroRecord] f) ∧ + Supports [zeroRecord] (fun f => f 0 = true) ∧ + ¬ Supports [zeroRecord] allTrue := + ⟨rfl, ⟨localGenerator 0, (zeroCompatible _).2 rfl⟩, + (fun f hf => (zeroCompatible f).1 hf), selfOriginDoesNotSupport.2.2.2.1⟩ +/- This inferential assessment derives a successor value from its explicit numeric premise without observation. -/ +def arithmeticFacet : Facet Nat := .inferential (singleton (fun n => n = 2)) (fun n => n + 1 = 3) +def usesObservation {W : Type} : Facet W → Bool + | .empirical _ _ _ _ => true + | _ => false +/- An actual valid inferential assessment refutes a mandatory measurement/repetition/framework chain. -/ +theorem noUniversalChain : FacetDischarged arithmeticFacet ∧ usesObservation arithmeticFacet = false := by + refine ⟨⟨⟨2, (modelsSingleton _ _).2 rfl⟩, ?_⟩, rfl⟩ + intro n hn + have premise := (modelsSingleton (fun x : Nat => x = 2) n).1 hn + change n + 1 = 3 + rw [premise] +/- A trial has a reproducible setting, an actual outcome and a separately recorded outcome. -/ +structure Trial where + setting : Nat + actualOutcome : Nat + recordedOutcome : Nat +/- Verifying a record, reproducing settings and retaining a conclusion are separate predicates. -/ +def Verified (t : Trial) : Prop := t.recordedOutcome = t.actualOutcome +def Reproduced (a b : Trial) : Prop := a.setting = b.setting +def Bounded (t : Trial) : Prop := t.actualOutcome ≤ 2 +/- Same-setting possible trials can differ while preserving the chosen bound; no probability semantics is claimed. -/ +theorem variableOutcomesStableBound : + let a : Trial := ⟨0,1,1⟩ + let b : Trial := ⟨0,2,2⟩ + Reproduced a b ∧ a.actualOutcome ≠ b.actualOutcome ∧ Bounded a ∧ Bounded b := by + simp [Reproduced, Bounded] +/- Concrete records distinguish record accuracy, condition reproduction and conclusion stability. -/ +theorem verificationReproductionStability : + (Verified ⟨0,1,1⟩ ∧ Verified ⟨1,1,1⟩ ∧ ¬ Reproduced ⟨0,1,1⟩ ⟨1,1,1⟩) ∧ + (Reproduced ⟨0,1,1⟩ ⟨0,3,2⟩ ∧ ¬ Verified ⟨0,3,2⟩ ∧ ¬ Bounded ⟨0,3,2⟩) ∧ + (Bounded ⟨0,1,1⟩ ∧ Bounded ⟨0,2,0⟩ ∧ ¬ Verified ⟨0,2,0⟩) := by + simp [Verified, Reproduced, Bounded] +/- Explanation certificates are executable syntax for this same arithmetic process. -/ +inductive Program where + | doubleInput + | constant (value : Nat) +def Program.eval : Program → Nat → Nat + | .doubleInput, n => n + n + | .constant value, _ => value +/- A process exposes outputs and an explanation response, whose certificate can be checked against those outputs. -/ +structure Process where + output : Nat → Nat + explanation : Option Program +/- The output-only application contract checks every relevant input. -/ +def OutputContract (p : Process) : Prop := ∀ n, p.output n = n + n +/- The explanation application contract requires a provided certificate faithful to this very process. -/ +def ExplanationContract (p : Process) : Prop := + ∃ program, p.explanation = some program ∧ ∀ n, program.eval n = p.output n +/- This process produces doubled values but returns no explanatory certificate. -/ +def outputOnlyProcess : Process := ⟨fun n => n + n, none⟩ +def explainedProcess : Process := ⟨fun n => n + n, some .doubleInput⟩ +/- Object scope fixes the very process whose contract is assessed; contract inputs themselves still range over all naturals. -/ +def processScope (assessed : Process) : Theory Process := + singleton (fun candidate => candidate = assessed) +/- This inferential facet checks an explicit contract under exact process-identity assumptions. -/ +def processContractFacet (assessed : Process) (contract : Claim Process) : Facet Process := + .inferential (processScope assessed) contract +/- The scope's compatible interpretations are exactly this assessed process, not an unrelated substitute. -/ +theorem processScopeModels (assessed candidate : Process) : + Models (processScope assessed) candidate ↔ candidate = assessed := + modelsSingleton (fun process => process = assessed) candidate +/- A concrete contract proof supplies the facet's consequence for its scoped object. -/ +theorem processContractDischarged (assessed : Process) (contract : Claim Process) (proof : contract assessed) : + FacetDischarged (processContractFacet assessed contract) := by + refine ⟨⟨assessed,(processScopeModels _ _).2 rfl⟩, ?_⟩ + intro candidate hc + have same := (processScopeModels _ _).1 hc + subst candidate + exact proof +/- Scoped capability grounds include exact claim, object-specific assumptions, canonical articulation and actual assessment. -/ +def ProcessGrounds (assessed : Process) (contract : Claim Process) : Prop := + Grounds contract canonicalArticulation (fun facet => facet = processContractFacet assessed contract) + [processContractFacet assessed contract] +theorem processGrounds (assessed : Process) (contract : Claim Process) (proof : contract assessed) : + ProcessGrounds assessed contract := by + have discharged := processContractDischarged assessed contract proof + refine ⟨by simp, ?_, ?_⟩ + · intro facet hf; subst facet; exact List.mem_singleton.mpr rfl + · intro facet hf; have hf' := List.mem_singleton.mp hf; subst facet + exact ⟨rfl,canonicalArticulated _ discharged,canonicalFacetArticulated _,discharged⟩ +/- Universal output correctness here comes from the concrete program definition, not from an assumed capability label. -/ +theorem outputCorrectByEvaluation : OutputContract outputOnlyProcess := fun _ => rfl +/- This same process actually returns no explanation certificate. -/ +theorem outputOnlyNoExplanation : ¬ ExplanationContract outputOnlyProcess := by + rintro ⟨program,h,_⟩; cases h +/- The full application contract requires outputs and an explanation of that same process. -/ +def FullProcessContract (assessed : Process) : Prop := OutputContract assessed ∧ ExplanationContract assessed +/- Output-only grounds have the assessed process itself as a counterworld to the stronger contract. -/ +def OutputContractEvidence : Prop := + ProcessGrounds outputOnlyProcess OutputContract ∧ + Models (processScope outputOnlyProcess) outputOnlyProcess ∧ + ¬ Entails (processScope outputOnlyProcess) FullProcessContract +/- Existing output evidence does not supply the absent explanation for the same object and scope. -/ +theorem outputContractEvidence : OutputContractEvidence := by + refine ⟨processGrounds _ _ outputCorrectByEvaluation, (processScopeModels _ _).2 rfl, ?_⟩ + intro stronger + exact outputOnlyNoExplanation (stronger outputOnlyProcess ((processScopeModels _ _).2 rfl)).2 +/- Both actual application contracts have grounds and explicit object scopes; neither scope is empty. -/ +def ScopedApplicationEvidence : Prop := + ProcessGrounds outputOnlyProcess OutputContract ∧ + ProcessGrounds explainedProcess FullProcessContract ∧ + (∀ candidate, Models (processScope outputOnlyProcess) candidate ↔ candidate = outputOnlyProcess) ∧ + (∀ candidate, Models (processScope explainedProcess) candidate ↔ candidate = explainedProcess) ∧ + Satisfiable (processScope outputOnlyProcess) ∧ Satisfiable (processScope explainedProcess) +/- Concrete evaluation and a faithful double-input certificate establish the two differently scoped contracts. -/ +theorem scopedApplicationEvidence : ScopedApplicationEvidence := by + refine ⟨processGrounds _ _ outputCorrectByEvaluation, processGrounds _ _ ?_, + processScopeModels _,processScopeModels _,⟨_,(processScopeModels _ _).2 rfl⟩, + ⟨_,(processScopeModels _ _).2 rfl⟩⟩ + exact ⟨fun _ => rfl,⟨.doubleInput,rfl,fun _ => rfl⟩⟩ +/- Universal output correctness does not entail the explanation-requiring contract for the same process. -/ +theorem outputNotExplanation : OutputContract outputOnlyProcess ∧ + ¬ ExplanationContract outputOnlyProcess ∧ OutputContractEvidence := + ⟨outputCorrectByEvaluation, outputOnlyNoExplanation, outputContractEvidence⟩ +/- Applications may use distinct contracts, and a faithful certificate can satisfy the stronger one. -/ +theorem applicationContractsDiffer : + (OutputContract outputOnlyProcess ∧ ¬ (OutputContract outputOnlyProcess ∧ ExplanationContract outputOnlyProcess)) ∧ + (OutputContract explainedProcess ∧ ExplanationContract explainedProcess) ∧ + ScopedApplicationEvidence := + ⟨⟨outputCorrectByEvaluation, fun h => outputOnlyNoExplanation h.2⟩, + ⟨(fun _ => rfl), ⟨.doubleInput, rfl, fun _ => rfl⟩⟩, scopedApplicationEvidence⟩ +/- The assessor supplies a mathematical certificate; the process's own explanation response is unnecessary. -/ +structure ExternalCertificate (p : Process) where + assessorId : Nat + assessedId : Nat + distinctParticipants : assessorId ≠ assessedId + outputCorrect : ∀ n, p.output n = n + n +/- The external assessor 42 evaluates the specified process 7; the full output proof is constructed by evaluation. -/ +def externalOutputCertificate : ExternalCertificate outputOnlyProcess := + ⟨42,7,by decide,fun _ => rfl⟩ +/- An external certificate establishes the output contract without producing an internal explanation. -/ +theorem externalAssessment : + (∃ certificate : ExternalCertificate outputOnlyProcess, + certificate.assessorId = 42 ∧ certificate.assessedId = 7 ∧ + certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧ + ProcessGrounds outputOnlyProcess OutputContract ∧ + ¬ ExplanationContract outputOnlyProcess := + ⟨⟨externalOutputCertificate,rfl,rfl,externalOutputCertificate.distinctParticipants, + externalOutputCertificate.outputCorrect⟩, + processGrounds outputOnlyProcess OutputContract externalOutputCertificate.outputCorrect, + outputOnlyNoExplanation⟩ +/- This argument records concepts and actual premises for a semantic inference, separately from executable tests. -/ +def arithmeticArticulation : Articulation Nat := canonicalArticulation arithmeticFacet +/- A reasoned inferential assessment needs no observation method, while applicable empirical assessment retains observations. -/ +theorem nonExecutableAssessment : + Grounds (fun n : Nat => n + 1 = 3) canonicalArticulation (fun f => f = arithmeticFacet) [arithmeticFacet] ∧ + usesObservation arithmeticFacet = false ∧ + FacetDischarged switchEmpirical ∧ usesObservation switchEmpirical = true := by + refine ⟨⟨by simp, (by intro f hf; cases hf; simp), ?_⟩, rfl, switchEmpiricalDischarged, rfl⟩ + intro f hf; simp only [List.mem_singleton] at hf; cases hf + exact ⟨rfl, canonicalArticulated _ noUniversalChain.1, canonicalFacetArticulated _, noUniversalChain.1⟩ + +end CoreReader.Evidence diff --git a/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Integration.lean b/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Integration.lean new file mode 100644 index 0000000..42a54da --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Integration.lean @@ -0,0 +1,558 @@ +import CoreReader.Agency +import CoreReader.Choice + +namespace CoreReader.Integration +open CoreReader.Logic CoreReader.Evidence CoreReader.Agency CoreReader.Choice + +/- Canonical articulation preserves the actual assessment contents of each facet. -/ +theorem canonicalGrounds {W : Type} (claim : Claim W) (facets : List (Facet W)) + (hne : facets ≠ []) (checked : ∀ f ∈ facets, f.claim = claim ∧ FacetDischarged f) : + Grounds claim canonicalArticulation (fun f => f ∈ facets) facets := by + exact ⟨hne, fun _ h => h, fun f hf => + ⟨(checked f hf).1, canonicalArticulated f (checked f hf).2, + canonicalFacetArticulated f, (checked f hf).2⟩⟩ + +theorem canonicalGroundsForSingleton {W : Type} (f : Facet W) (checked : FacetDischarged f) : + Grounds f.claim canonicalArticulation (fun g => g = f) [f] := by + refine ⟨by simp, (by intro g hg; cases hg; simp), ?_⟩ + intro g hg + simp only [List.mem_singleton] at hg + subst g + exact ⟨rfl, canonicalArticulated f checked, canonicalFacetArticulated f, checked⟩ + +/- A mode selects whether a system applies or waives the modeled governance rule. -/ +inductive Mode | apply | waive + deriving DecidableEq, Repr + +/- The four hypotheses vary algorithm and governance independently for the same assessed system. -/ +abbrev World := Candidate × Mode + +def actual : World := (.identity, .apply) + +/- A method's form and its possible executable realizations belong to one object. -/ +structure Method where + form : Form + realize : World → Implementation + +/- System fields identify the owner, its method, its current principle form, policy and work. -/ +structure System where + owner : Nat + method : Method + principleForm : Form + governance : World → Mode + requirements : Requirements + +def policyFor : Mode → Policy + | .apply => openPolicy + | .waive => neutralPolicy + +def workFor (owner : Nat) : Mode → List WorkRecord + | .apply => completeOwnWork owner + | .waive => [] + +def System.policy (s : System) (w : World) : Policy := policyFor (s.governance w) +def System.rules (s : System) (_w : World) : List Principle := ownRules s.owner +def System.work (s : System) (w : World) : List WorkRecord := workFor s.owner (s.governance w) + +def actualSystem : System where + owner := 0 + method := ⟨⟨.method, 0⟩, fun w => implementation w.1⟩ + principleForm := ⟨.principle, 0⟩ + governance := Prod.snd + requirements := identityRequirements + +def systemCapability (s : System) : Claim World := + fun w => ∀ n, s.requirements.inputs n → (s.method.realize w).run n = s.requirements.expected n + +def systemBudget (s : System) : Claim World := + fun w => (s.method.realize w).cost ≤ s.requirements.budget + +def systemObservation (s : System) : Record World := + ⟨fun w => decide ((s.method.realize w).run 0 = s.requirements.expected 0), true⟩ + +def systemHeld (s : System) : Theory World := + union (singleton (systemCapability s)) (singleton (systemBudget s)) + +inductive Question | correctOutput | affordable + deriving DecidableEq, Repr + +def systemContext (s : System) : Context World Question := + ⟨singleton (Compatible [systemObservation s]), + (fun q => match q with | .correctOutput => systemCapability s | .affordable => systemBudget s), + fun w => (s.method.realize w).domain 0 ∧ w.2 = .apply⟩ + +abbrev capability := systemCapability actualSystem +abbrev observation := systemObservation actualSystem +abbrev held := systemHeld actualSystem +abbrev context := systemContext actualSystem + +/- The output observation identifies the algorithm, without identifying its independently varied governance mode. -/ +theorem observationIdentifies (w : World) : Compatible [observation] w ↔ w.1 = .identity := by + rcases w with ⟨candidate, mode⟩ + cases candidate <;> simp [Compatible, observation, systemObservation, actualSystem, + implementation, identityRequirements, identityImpl, successorImpl] + +theorem capabilityActual : capability actual := fun _ _ => rfl + +theorem observedCapability : Supports [observation] capability := by + intro w hw + have hid := (observationIdentifies w).1 hw + rcases w with ⟨candidate, mode⟩ + change candidate = .identity at hid + subst candidate + exact fun _ _ => rfl + +def capabilityFacet : Facet World := .empirical [observation] (fun _ => True) capability (fun _ => True) + +theorem capabilityFacetChecked : FacetDischarged capabilityFacet := by + exact ⟨⟨actual, (observationIdentifies actual).2 rfl, trivial⟩, + (fun w hw _ => observedCapability w hw), fun _ _ => trivial⟩ + +theorem capabilityGrounds : Grounds capability canonicalArticulation + (fun f => f = capabilityFacet) [capabilityFacet] := + canonicalGroundsForSingleton capabilityFacet capabilityFacetChecked + +theorem actualAdmissible : Admissible held context actual := by + refine ⟨(modelsUnion _ _ _).2 ⟨(modelsSingleton _ _).2 capabilityActual, + (modelsSingleton _ _).2 (by change 1 ≤ 1; decide)⟩, + (modelsSingleton _ _).2 ((observationIdentifies actual).2 rfl), trivial, rfl⟩ + +theorem jointConsistent : Consistent held context := + consequenceConsistency held context ⟨actual, actualAdmissible⟩ + +/- The current method/principle forms, judgments, rules and own work are read from this very system and world. -/ +def Charter (s : System) (w : World) : Prop := + Generative (s.policy w) ∧ Consistent (systemHeld s) (systemContext s) ∧ + Reflexive s.owner (s.rules w) (s.work w) ∧ + (s.policy w).current s.method.form ∧ (s.policy w).current s.principleForm + +theorem charterChecked : Charter actualSystem actual := + ⟨⟨Or.inl rfl, fun _ _ => trivial⟩, jointConsistent, completeOwnWork_reflexive 0, rfl, rfl⟩ + +/- Revision adds a supported input-specific assertion about the same system's realized method. -/ +def revisedHeld : Theory World := union held + (singleton (fun w => (actualSystem.method.realize w).run 0 = actualSystem.requirements.expected 0)) + +def initialSnapshot : Snapshot World Question := ⟨held, context, 0⟩ +def revisedSnapshot : Snapshot World Question := ⟨revisedHeld, context, 1⟩ + +theorem revisionKeepsConsistency : + Charter actualSystem actual ∧ Consistent revisedHeld context ∧ + TruthfulReport initialSnapshot revisedSnapshot true ∧ + ¬ TruthfulReport initialSnapshot revisedSnapshot false := by + refine ⟨charterChecked, consequenceConsistency revisedHeld context ⟨actual, + (modelsUnion _ _ _).2 ⟨actualAdmissible.1, (modelsSingleton _ _).2 rfl⟩, + actualAdmissible.2⟩, (fun _ => rfl), ?_⟩ + intro h + have bad := h (Or.inr (by decide)) + cases bad + +/- A claim about this system's method is assessed as its owner's system claim. -/ +def OwnCapabilityDuty (s : System) (w : World) (facets : List (Facet World)) : Prop := + Performed (s.work w) (.system s.owner) .assessment ∧ + Grounds (systemCapability s) canonicalArticulation (fun f => f ∈ facets) facets + +theorem ownCapabilityGrounded : + OwnCapabilityDuty actualSystem actual [capabilityFacet] ∧ capability actual := by + refine ⟨⟨?_, ?_⟩, capabilityActual⟩ + · exact ownAssessmentPerformed 0 (.system 0) (by simp [ownSubjects]) + · exact canonicalGrounds capability [capabilityFacet] (by simp) + (by intro f hf; simp only [List.mem_singleton] at hf; cases hf; exact ⟨rfl, capabilityFacetChecked⟩) + +/- This cost observation is true of both algorithms but does not discriminate their output behavior. -/ +def costAllowanceRecord : Record World := + ⟨fun w => decide ((actualSystem.method.realize w).cost ≤ 2), true⟩ + +def unsupportedCapabilityFacet : Facet World := + .empirical [costAllowanceRecord] (fun _ => True) capability (fun _ => True) + +theorem costCompatibleWithFailure : Compatible [costAllowanceRecord] (.successor, .apply) := by + intro r hr + simp only [List.mem_singleton] at hr + subst r + rfl + +theorem costDoesNotSupportOutput : ¬ Supports [costAllowanceRecord] capability := by + intro h + have bad := h (.successor, .apply) costCompatibleWithFailure 0 trivial + cases bad + +theorem unsupportedGrounds : ¬ Grounds capability canonicalArticulation + (fun f => f = unsupportedCapabilityFacet) [unsupportedCapabilityFacet] := by + intro h + have discharged := (h.2.2 unsupportedCapabilityFacet (by simp)).2.2.2 + exact costDoesNotSupportOutput (fun w hw => discharged.2.1 w hw trivial) + +/- Five separately adopted requirements govern distinct operations; the mode does not give them priority over one another. -/ +inductive Commitment | generation | consistency | reflexivity | grounds | choice + deriving DecidableEq, Repr + +/- A Grounds policy governs arbitrary claims, articulations and applicable facets, rather than only one capability claim. -/ +def groundsPermission (mode : Mode) (claim : Claim World) (a : Facet World → Articulation World) + (applicable : Facet World → Prop) (facets : List (Facet World)) : Prop := + match mode with + | .apply => Grounds claim a applicable facets + | .waive => True + +def GroundsProvision (mode : Mode) : Prop := + ∀ claim a applicable facets, groundsPermission mode claim a applicable facets → + Grounds claim a applicable facets + +theorem groundsProvisionMeaning (mode : Mode) : GroundsProvision mode ↔ mode = .apply := by + cases mode with + | apply => exact ⟨fun _ => rfl, fun _ _ _ _ _ h => h⟩ + | waive => + constructor + · intro h + exact False.elim (unsupportedGrounds (h capability canonicalArticulation + (fun f => f = unsupportedCapabilityFacet) [unsupportedCapabilityFacet] trivial)) + · intro h; cases h + +/- The consistency policy checks a whole same-context theory, not isolated judgments. -/ +def consistencyPermission (mode : Mode) (t : Theory World) (c : Context World Question) : Prop := + match mode with | .apply => Consistent t c | .waive => True + +def conflictingHeld : Theory World := union (singleton capability) (singleton (fun w => ¬ capability w)) + +theorem conflictConsequences : + Consequence conflictingHeld context .correctOutput true ∧ + Consequence conflictingHeld context .correctOutput false := by + exact ⟨fun w hw => hw.1 capability (Or.inl rfl), + fun w hw => hw.1 (fun w => ¬ capability w) (Or.inr rfl)⟩ + +theorem conflictingHeldInconsistent : ¬ Consistent conflictingHeld context := + conflictRequiresChange conflictingHeld context .correctOutput conflictConsequences.1 conflictConsequences.2 + +/- The selection policy applies the actual output/budget and relevant-reason conditions to every implementation. -/ +def choicePermission (mode : Mode) (req : Requirements) (i : Implementation) (reasons : List Reason) : Prop := + match mode with | .apply => JustifiedChoice req i reasons | .waive => True + +/- The following consequences are computed from distinct rule applications; they are not interchangeable support flags. -/ +def proposedOperation : Mode → Operation + | .apply => .successor + | .waive => .copy + +def selfSamples : Mode → List Nat + | .apply => [0, 1] + | .waive => [1] + +noncomputable def conflictDecision (mode : Mode) : Bool := + @decide (consistencyPermission mode conflictingHeld context) (Classical.propDecidable _) + +noncomputable def groundsDecision (mode : Mode) (facet : Facet World) : Bool := + @decide (groundsPermission mode facet.claim canonicalArticulation (fun f => f = facet) [facet]) + (Classical.propDecidable _) + +noncomputable def choiceDecision (mode : Mode) (i : Implementation) (reasons : List Reason) : Bool := + @decide (choicePermission mode identityRequirements i reasons) (Classical.propDecidable _) + +theorem decisionsApply : conflictDecision .apply = false ∧ + groundsDecision .apply unsupportedCapabilityFacet = false ∧ + groundsDecision .apply capabilityFacet = true ∧ + choiceDecision .apply cheapSuccessor [.method .simplicity] = false ∧ + choiceDecision .apply identityImpl objectiveReason = true := by + classical + simp only [conflictDecision, groundsDecision, choiceDecision, consistencyPermission, + groundsPermission, choicePermission] + exact ⟨decide_eq_false conflictingHeldInconsistent, + decide_eq_false unsupportedGrounds, decide_eq_true capabilityGrounds, + decide_eq_false eligibleInternalReasonNotSufficient.2, decide_eq_true identityJustified⟩ + +theorem decisionsWaive : conflictDecision .waive = true ∧ + groundsDecision .waive unsupportedCapabilityFacet = true ∧ + choiceDecision .waive cheapSuccessor [.method .simplicity] = true := by + exact ⟨@decide_eq_true (consistencyPermission .waive conflictingHeld context) + (Classical.propDecidable _) trivial, + @decide_eq_true (groundsPermission .waive unsupportedCapabilityFacet.claim canonicalArticulation + (fun f => f = unsupportedCapabilityFacet) [unsupportedCapabilityFacet]) (Classical.propDecidable _) trivial, + @decide_eq_true (choicePermission .waive identityRequirements cheapSuccessor [.method .simplicity]) + (Classical.propDecidable _) trivial⟩ + +/- Each application supplies its own outcome type, adopted objective, constraints and actual option-indexed reasons. -/ +noncomputable def commitmentPositionFor (c : Commitment) (chosenMode : Mode) : ValuePosition World := + match c with + | .generation => { + Position := Mode, Outcome := Operation, adopted := chosenMode, selected := actualSystem.governance, + outcome := fun _ mode => proposedOperation mode, + objective := fun op => op.run 0 ≠ Operation.copy.run 0, + constraints := fun _ mode => Generative (policyFor mode), + starting := singleton (fun w => actualSystem.governance w = chosenMode), + reasons := [fun _ mode => (proposedOperation mode).run 0 = 1 ∧ Operation.copy.run 0 = 0], + limits := fun w => w.1 = .identity, + relevantCriticism := fun _ => ¬ Expanded baseState inflatedState, + response := fun _ => some "Pursuing expansion does not guarantee it; assess the actual before and after capabilities separately" } + | .consistency => { + Position := Mode, Outcome := Bool, adopted := chosenMode, selected := actualSystem.governance, + outcome := fun _ mode => conflictDecision mode, + objective := fun accepted => accepted = false, + constraints := fun _ mode => consistencyPermission mode held context, + starting := singleton (fun w => actualSystem.governance w = chosenMode), + reasons := [fun _ _ => Consequence conflictingHeld context .correctOutput true ∧ + Consequence conflictingHeld context .correctOutput false], + limits := fun w => w.1 = .identity, + relevantCriticism := fun _ => ¬ Entails (emptyTheory : Theory Bool) (fun w => w = true), + response := fun _ => some "Consistency alone does not establish sufficient support; assess the claim with its grounds as well" } + | .reflexivity => { + Position := Mode, Outcome := List Nat, adopted := chosenMode, selected := actualSystem.governance, + outcome := fun _ mode => selfSamples mode, + objective := fun samples => ∃ n ∈ samples, ownArithmeticPrinciple n = false, + constraints := fun _ mode => Reflexive 0 (ownRules 0) (workFor 0 mode), + starting := singleton (fun w => actualSystem.governance w = chosenMode), + reasons := [fun _ _ => ownArithmeticPrinciple 0 = false ∧ ownArithmeticPrinciple 1 = true], + limits := fun w => w.1 = .identity, + relevantCriticism := fun _ => selfTest [1] = true ∧ ownArithmeticPrinciple 0 = false, + response := fun _ => some "A passing self-test does not certify the principle; retain the relevant counterexample and its scope" } + | .grounds => { + Position := Mode, Outcome := Bool, adopted := chosenMode, selected := actualSystem.governance, + outcome := fun _ mode => groundsDecision mode unsupportedCapabilityFacet, + objective := fun accepted => accepted = false, + constraints := fun _ mode => groundsPermission mode capability canonicalArticulation + (fun f => f = capabilityFacet) [capabilityFacet], + starting := singleton (fun w => actualSystem.governance w = chosenMode), + reasons := [fun _ _ => Compatible [costAllowanceRecord] (.successor, .apply) ∧ + ¬ capability (.successor, .apply)], + limits := fun w => w.1 = .identity, + relevantCriticism := fun _ => OutputContract outputOnlyProcess ∧ ¬ ExplanationContract outputOnlyProcess, + response := fun _ => some "Grounds allows an external output assessment without requiring this process to provide an internal explanation" } + | .choice => { + Position := Mode, Outcome := Bool, adopted := chosenMode, selected := actualSystem.governance, + outcome := fun _ mode => choiceDecision mode cheapSuccessor [.method .simplicity], + objective := fun accepted => accepted = false, + constraints := fun _ mode => choicePermission mode identityRequirements identityImpl objectiveReason, + starting := singleton (fun w => actualSystem.governance w = chosenMode), + reasons := [fun _ _ => cheapSuccessor.run 0 = 1 ∧ identityRequirements.expected 0 = 0 ∧ + cheapSuccessor.cost ≤ identityRequirements.budget], + limits := fun w => w.1 = .identity, + relevantCriticism := fun _ => identityImpl.conventional = true ∧ identityImpl.established = true, + response := fun _ => some "An existing conventional method remains eligible when actual output and budget reasons justify it" } + +noncomputable def commitmentPosition (c : Commitment) : ValuePosition World := commitmentPositionFor c .apply + +/- The fact used as a reason has content before evaluating the adopted rule's consequence. -/ +theorem positionReasons (c : Commitment) : + ∀ r ∈ (commitmentPosition c).reasons, r actual (commitmentPosition c).adopted := by + cases c <;> intro r hr <;> dsimp [commitmentPosition, commitmentPositionFor] at hr ⊢ <;> + rcases List.mem_singleton.mp hr with rfl + · exact ⟨rfl, rfl⟩ + · exact conflictConsequences + · exact ⟨rfl, rfl⟩ + · refine ⟨costCompatibleWithFailure, ?_⟩ + intro h + have bad := h 0 trivial + cases bad + · exact ⟨rfl, rfl, by decide⟩ + +/- Each adopted rule has its stated consequence in this explicitly defined application; this is not ultimate value justification. -/ +theorem positionConsequence (c : Commitment) (w : World) : (commitmentPosition c).consequence w := by + cases c <;> dsimp [commitmentPosition, commitmentPositionFor, ValuePosition.consequence] + · exact ⟨by decide, ⟨Or.inl rfl, fun _ _ => trivial⟩⟩ + · exact ⟨decisionsApply.1, jointConsistent⟩ + · exact ⟨⟨0, by simp [selfSamples], rfl⟩, completeOwnWork_reflexive 0⟩ + · exact ⟨decisionsApply.2.1, capabilityGrounds⟩ + · exact ⟨decisionsApply.2.2.2.1, identityJustified⟩ + +theorem positionProcedure (c : Commitment) : ValueProcedure (commitmentPosition c) := by + refine ⟨?_, ?_, ?_, ?_⟩ + · cases c <;> simp [commitmentPosition, commitmentPositionFor] + · refine ⟨actual, ?_, ?_, ?_, positionReasons c⟩ + · cases c <;> exact (modelsSingleton _ _).2 rfl + · cases c <;> rfl + · cases c <;> rfl + · intro w _ _ _ + exact positionConsequence c w + · intro w _ _ + cases c <;> exact ⟨_, rfl, by decide⟩ + +/- Criticism is instantiated within the adopted position's actual limit rather than made vacuous. -/ +theorem criticismWithinScope (c : Commitment) : + (commitmentPosition c).limits actual ∧ (commitmentPosition c).relevantCriticism actual := by + constructor + · cases c <;> rfl + · cases c + · simp [commitmentPosition, commitmentPositionFor, Expanded, baseState, inflatedState] + · exact consistentIncomplete.2.1 + · exact ⟨rfl, rfl⟩ + · exact ⟨outputNotExplanation.1, outputNotExplanation.2.1⟩ + · exact ⟨rfl, rfl⟩ + +/- Waiving the rule changes the actual computed outcome or an explicit adopted constraint; old reasons cannot certify it unchanged. -/ +theorem oppositeConsequenceFails (c : Commitment) (w : World) : + ¬ (commitmentPositionFor c .waive).consequence w := by + cases c <;> intro h + · exact permissionNotValuation.2.2 h.2 + · have bad : conflictDecision .waive = false := h.1 + rw [decisionsWaive.1] at bad + cases bad + · obtain ⟨n, hn, hf⟩ := h.1 + change n ∈ [1] at hn + have he : n = 1 := List.mem_singleton.mp hn + subst n + cases hf + · have bad : groundsDecision .waive unsupportedCapabilityFacet = false := h.1 + rw [decisionsWaive.2.1] at bad + cases bad + · have bad : choiceDecision .waive cheapSuccessor [.method .simplicity] = false := h.1 + rw [decisionsWaive.2.2] at bad + cases bad + +theorem oppositeProcedureRejected (c : Commitment) : ¬ ValueProcedure (commitmentPositionFor c .waive) := by + intro h + obtain ⟨w, hs, hl, _, hr⟩ := h.2.1 + exact oppositeConsequenceFails c w (h.2.2.1 w hs hl hr) + +/- Each statement names adoption of a particular rule; its defined policy gives that option its meaning. -/ +noncomputable def commitmentClaim (c : Commitment) : Claim World := (commitmentPosition c).commitment + +noncomputable def commitmentFacet (c : Commitment) : Facet World := .value (commitmentPosition c) + +theorem reasonsBelongToCommitments (c : Commitment) : + Grounds (commitmentClaim c) canonicalArticulation + (fun f => f = commitmentFacet c) [commitmentFacet c] ∧ + JointAdoption (commitmentPosition c) ∧ + (commitmentPosition c).relevantCriticism actual ∧ + ¬ ValueProcedure (commitmentPositionFor c .waive) := by + exact ⟨canonicalGroundsForSingleton (commitmentFacet c) (positionProcedure c), + (positionProcedure c).2.1, (criticismWithinScope c).2, oppositeProcedureRejected c⟩ + +/- This claim concerns the Grounds rule for arbitrary claim/facet packages, not a single capability duty. -/ +theorem groundsCommitmentIsProvision : commitmentClaim .grounds = (fun w => GroundsProvision w.2) := by + funext w + apply propext + exact (groundsProvisionMeaning w.2).symm + +theorem groundsSelfAssessment : + Grounds (fun w => GroundsProvision w.2) canonicalArticulation + (fun f => f = commitmentFacet .grounds) [commitmentFacet .grounds] ∧ + (commitmentPosition .grounds).limits actual ∧ + (commitmentPosition .grounds).relevantCriticism actual ∧ + ¬ ValueProcedure (commitmentPositionFor .grounds .waive) := by + rw [← groundsCommitmentIsProvision] + exact ⟨(reasonsBelongToCommitments .grounds).1, + (criticismWithinScope .grounds).1, (criticismWithinScope .grounds).2, + oppositeProcedureRejected .grounds⟩ + +/- This existing principle form implements the same system's choice rule on two actual proposals. +Input 0 names the identity proposal; input 1 names the cheap successor proposal. -/ +structure PhilosophyMethod where + form : Form + mode : Mode + +def currentPhilosophy (s : System) (w : World) : PhilosophyMethod := + ⟨s.principleForm, s.governance w⟩ + +noncomputable def PhilosophyMethod.review (p : PhilosophyMethod) (input : Nat) : Nat := + if input = 0 then + if choiceDecision p.mode identityImpl objectiveReason then 1 else 0 + else if choiceDecision p.mode cheapSuccessor [.method .simplicity] then 1 else 0 + +noncomputable def PhilosophyMethod.implementation (p : PhilosophyMethod) : Implementation where + name := "Current philosophy's proposal review" + conventional := true + established := true + run := p.review + cost := 1 + domain n := n = 0 ∨ n = 1 + explanation := p.review + trace n := [n, p.review n] + +def proposalRequirements : Requirements where + inputs n := n = 0 ∨ n = 1 + expected n := if n = 0 then 1 else 0 + budget := 1 + values _ := True + +theorem currentReviewCorrect : ∀ n, proposalRequirements.inputs n → + (currentPhilosophy actualSystem actual).review n = proposalRequirements.expected n := by + intro n hn + rcases hn with rfl | rfl <;> + simp [PhilosophyMethod.review, currentPhilosophy, actualSystem, actual, + proposalRequirements, decisionsApply.2.2.2.1, decisionsApply.2.2.2.2] + +/- Status alone fails for this actual principle method; its demonstrated proposal decisions give a relevant reason. -/ +theorem existingPhilosophyNotPrivileged : + (currentPhilosophy actualSystem actual).form = actualSystem.principleForm ∧ + (currentPhilosophy actualSystem actual).mode = actualSystem.governance actual ∧ + ¬ JustifiedChoice proposalRequirements + (currentPhilosophy actualSystem actual).implementation [.status .standing] ∧ + JustifiedChoice proposalRequirements + (currentPhilosophy actualSystem actual).implementation [.method .output] ∧ + (currentPhilosophy actualSystem actual).review 0 = 1 ∧ + (currentPhilosophy actualSystem actual).review 1 = 0 := by + refine ⟨rfl, rfl, statusOnlyFails _ _ _, ?_, currentReviewCorrect 0 (Or.inl rfl), + currentReviewCorrect 1 (Or.inr rfl)⟩ + exact ⟨⟨currentReviewCorrect, by change 1 ≤ 1; decide⟩, + .method .output, by simp, trivial, currentReviewCorrect⟩ + +/- Applications choose their contract and requirements; the resulting claim is about this system's actual method. -/ +def applicationClaim (s : System) (req : Requirements) + (contract : Requirements → Implementation → Prop) : Claim World := + fun w => contract req (s.method.realize w) + +def ApplicationDuties (s : System) (w : World) (req : Requirements) + (contract : Requirements → Implementation → Prop) + (articulations : Facet World → Articulation World) + (applicable : Facet World → Prop) (facets : List (Facet World)) : Prop := + Reflexive s.owner (s.rules w) (s.work w) ∧ + Grounds (applicationClaim s req contract) articulations applicable facets + +/- These are consequences of an explicitly adopted duty, not a proof that arbitrary applications fulfill it. -/ +theorem applicationRetainsDuties (s : System) (w : World) (req : Requirements) + (contract : Requirements → Implementation → Prop) + (articulations : Facet World → Articulation World) + (applicable : Facet World → Prop) (facets : List (Facet World)) + (h : ApplicationDuties s w req contract articulations applicable facets) : + Reflexive s.owner (s.rules w) (s.work w) ∧ + (∀ f, applicable f → f ∈ facets) ∧ + (∀ f ∈ facets, f.claim = applicationClaim s req contract ∧ + Articulated (articulations f) ∧ FacetArticulated (articulations f) f ∧ FacetDischarged f) := + ⟨h.1, h.2.2.1, h.2.2.2⟩ + +def outputContract (req : Requirements) (i : Implementation) : Prop := + ∀ n, req.inputs n → i.run n = req.expected n + +def successorRequirements : Requirements := + { identityRequirements with expected := fun n => n + 1 } + +/- Holding the system and observation fixed while changing the actual objective changes the capability claim. -/ +def changedObjectiveFacet : Facet World := + .empirical [observation] (fun _ => True) + (applicationClaim actualSystem successorRequirements outputContract) (fun _ => True) + +theorem applicationVariation : + ApplicationDuties actualSystem actual identityRequirements outputContract + canonicalArticulation (fun f => f = capabilityFacet) [capabilityFacet] ∧ + ¬ applicationClaim actualSystem successorRequirements outputContract actual ∧ + ¬ Grounds (applicationClaim actualSystem successorRequirements outputContract) + canonicalArticulation (fun f => f = changedObjectiveFacet) [changedObjectiveFacet] := by + refine ⟨⟨completeOwnWork_reflexive 0, capabilityGrounds⟩, ?_, ?_⟩ + · intro h + have bad := h 0 trivial + cases bad + · intro h + have discharged := (h.2.2 changedObjectiveFacet (by simp)).2.2.2 + have bad := discharged.2.1 actual ((observationIdentifies actual).2 rfl) trivial 0 trivial + cases bad + +/- The very system satisfies the charter while its true cost evidence fails to establish its output capability. -/ +theorem charterNotGrounds : + Charter actualSystem actual ∧ + Compatible [costAllowanceRecord] actual ∧ + ¬ Grounds capability canonicalArticulation + (fun f => f = unsupportedCapabilityFacet) [unsupportedCapabilityFacet] := by + exact ⟨charterChecked, (by intro r hr; cases List.mem_singleton.mp hr; rfl), unsupportedGrounds⟩ + +/- A single inhabited system/context carries the charter, its own actual claim and support, +contentful principle work, and separately reasoned governance commitments. -/ +theorem jointWitness : + ∃ s : System, ∃ w : World, + Admissible (systemHeld s) (systemContext s) w ∧ Charter s w ∧ + OwnCapabilityDuty s w [capabilityFacet] ∧ systemCapability s w ∧ + JustifiedChoice s.requirements (s.method.realize w) objectiveReason ∧ + (∀ c : Commitment, Grounds (commitmentClaim c) canonicalArticulation + (fun f => f = commitmentFacet c) [commitmentFacet c]) ∧ + s = actualSystem ∧ w = actual := by + exact ⟨actualSystem, actual, actualAdmissible, charterChecked, + ownCapabilityGrounded.1, capabilityActual, identityJustified, + fun c => (reasonsBelongToCommitments c).1, rfl, rfl⟩ + +end CoreReader.Integration diff --git a/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Logic.lean b/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Logic.lean new file mode 100644 index 0000000..4249442 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Logic.lean @@ -0,0 +1,187 @@ +namespace CoreReader.Logic + +/- A claim denotes the worlds in which its content holds. -/ +abbrev Claim (W : Type) := W → Prop +/- A theory is a collection of simultaneously held claims. -/ +abbrev Theory (W : Type) := Claim W → Prop +/- A model satisfies every member of the whole theory. -/ +def Models {W : Type} (t : Theory W) (w : W) : Prop := ∀ p, t p → p w +/- Semantic entailment quantifies over all models. -/ +def Entails {W : Type} (t : Theory W) (p : Claim W) : Prop := ∀ w, Models t w → p w +/- Satisfiability requires an actual witness. -/ +def Satisfiable {W : Type} (t : Theory W) : Prop := ∃ w, Models t w +/- Assumptions, meanings and scope are distinct components; questions remain explicit. -/ +structure Context (W Q : Type) where + assumptions : Theory W + meaning : Q → Claim W + scope : Claim W +/- Admissible worlds satisfy held claims, assumptions and scope jointly. -/ +def Admissible {W Q : Type} (t : Theory W) (c : Context W Q) (w : W) : Prop := + Models t w ∧ Models c.assumptions w ∧ c.scope w +/- A negative judgment denies the very same question under the same meaning. -/ +def Consequence {W Q : Type} (t : Theory W) (c : Context W Q) (q : Q) (positive : Bool) : Prop := + ∀ w, Admissible t c w → if positive then c.meaning q w else ¬ c.meaning q w +/- The consistency obligation prohibits both consequences at one comparison basis. -/ +def Consistent {W Q : Type} (t : Theory W) (c : Context W Q) : Prop := + ∀ q, ¬ (Consequence t c q true ∧ Consequence t c q false) +/- An inhabited joint interpretation prevents opposite semantic consequences. -/ +theorem consequenceConsistency {W Q : Type} (t : Theory W) (c : Context W Q) + (inhabited : ∃ w, Admissible t c w) : Consistent t c := by + intro q h + obtain ⟨w, hw⟩ := inhabited + exact (h.2 w hw) (h.1 w hw) +/- Empty and singleton theories provide concrete semantic contexts. -/ +def emptyTheory {W : Type} : Theory W := fun _ => False +def singleton {W : Type} (p : Claim W) : Theory W := fun q => q = p +def union {W : Type} (a b : Theory W) : Theory W := fun p => a p ∨ b p +theorem modelsSingleton {W : Type} (p : Claim W) (w : W) : Models (singleton p) w ↔ p w := by + constructor + · intro h; exact h p rfl + · intro h q hq; cases hq; exact h +theorem modelsUnion {W : Type} (a b : Theory W) (w : W) : + Models (union a b) w ↔ Models a w ∧ Models b w := by + constructor + · intro h; exact ⟨fun p hp => h p (Or.inl hp), fun p hp => h p (Or.inr hp)⟩ + · rintro ⟨ha,hb⟩ p (hp|hp); exact ha p hp; exact hb p hp +/- The paired world records independent truth values for two questions. -/ +def premiseP : Claim (Bool × Bool) := fun w => w.1 = true +def premiseRule : Claim (Bool × Bool) := fun w => w.1 = true → w.2 = true +def premiseNotQ : Claim (Bool × Bool) := fun w => w.2 ≠ true +def jointTheory : Theory (Bool × Bool) := + union (singleton premiseP) (union (singleton premiseRule) (singleton premiseNotQ)) +/- Each premise has a model, but their joint implication makes the union unsatisfiable. -/ +theorem jointConflict : + Satisfiable (singleton premiseP) ∧ Satisfiable (singleton premiseRule) ∧ + Satisfiable (singleton premiseNotQ) ∧ ¬ Satisfiable jointTheory := by + refine ⟨⟨(true,true), (modelsSingleton _ _).2 rfl⟩, + ⟨(false,false), (modelsSingleton _ _).2 (by intro h; cases h)⟩, + ⟨(false,false), (modelsSingleton _ _).2 (by intro h; cases h)⟩, ?_⟩ + rintro ⟨w, hw⟩ + have hp := hw premiseP (Or.inl rfl) + have hr := hw premiseRule (Or.inr (Or.inl rfl)) + have hn := hw premiseNotQ (Or.inr (Or.inr rfl)) + exact hn (hr hp) +/- A retraction replaces the old singleton, rather than retaining both at the same time. -/ +def revisionSlice (time : Nat) : Theory Bool := + singleton (fun w => w = (time == 0)) +/- The initial and revised slices have models; keeping both would create a conflict. -/ +theorem revisionCanReverse : + Satisfiable (revisionSlice 0) ∧ Satisfiable (revisionSlice 1) ∧ + ¬ Satisfiable (union (revisionSlice 0) (revisionSlice 1)) := by + refine ⟨⟨true, (modelsSingleton _ _).2 rfl⟩, + ⟨false, (modelsSingleton _ _).2 rfl⟩, ?_⟩ + rintro ⟨w, hw⟩ + have hs := (modelsUnion _ _ _).1 hw + have hp := (modelsSingleton _ _).1 hs.1 + have hn := (modelsSingleton _ _).1 hs.2 + have bad : true = false := hp.symm.trans hn + cases bad +/- This basic question asks whether the represented switch is on. -/ +def onQuestion : Unit → Claim Bool := fun _ w => w = true +def assumptionContext (b : Bool) : Context Bool Unit := + ⟨singleton (fun w => w = b), onQuestion, fun _ => True⟩ +def meaningContext (b : Bool) : Context Bool Unit := + ⟨singleton (fun w => w = true), (fun _ w => w = b), fun _ => True⟩ +def scopeContext (b : Bool) : Context Bool Unit := + ⟨emptyTheory, onQuestion, fun w => w = b⟩ +/- Distinct assumptions, meanings and scopes each admit opposite judgments without same-context conflict. -/ +theorem contextDifferences : + (Consequence emptyTheory (assumptionContext true) () true ∧ + Consequence emptyTheory (assumptionContext false) () false) ∧ + (Consequence emptyTheory (meaningContext true) () true ∧ + Consequence emptyTheory (meaningContext false) () false) ∧ + (Consequence emptyTheory (scopeContext true) () true ∧ + Consequence emptyTheory (scopeContext false) () false) ∧ + (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w) := by + have empty : ∀ w : Bool, Models emptyTheory w := by intro w p hp; cases hp + refine ⟨⟨?_, ?_⟩, ⟨?_, ?_⟩, ⟨?_, ?_⟩, ?_, ?_, ?_⟩ + · intro w h; change w = true; exact (modelsSingleton (fun x : Bool => x = true) w).1 h.2.1 + · intro w h hp; have hn := (modelsSingleton _ _).1 h.2.1; cases hp.symm.trans hn + · intro w h; change w = true; exact (modelsSingleton (fun x : Bool => x = true) w).1 h.2.1 + · intro w h hn; have hp := (modelsSingleton _ _).1 h.2.1; cases hp.symm.trans hn + · intro w h; exact h.2.2 + · intro w h hp; cases hp.symm.trans h.2.2 + · intro b; exact ⟨b, empty b, (modelsSingleton _ _).2 rfl, trivial⟩ + · intro b; exact ⟨true, empty true, (modelsSingleton _ _).2 rfl, trivial⟩ + · intro b; exact ⟨b, empty b, empty b, rfl⟩ +/- Snapshots preserve identifiable adopted-form revisions even when semantic content agrees. -/ +structure Snapshot (W Q : Type) where + held : Theory W + context : Context W Q + revisionIdentity : Nat +/- Semantic equivalence compares represented content, not its list ordering. -/ +def SameContent {W Q : Type} (a b : Snapshot W Q) : Prop := + (∀ p, a.held p ↔ b.held p) ∧ + (∀ p, a.context.assumptions p ↔ b.context.assumptions p) ∧ + (∀ q w, a.context.meaning q w ↔ b.context.meaning q w) ∧ + (∀ w, a.context.scope w ↔ b.context.scope w) +/- The reporting norm covers both semantic change and independently identified revisions. -/ +def TruthfulReport {W Q : Type} (a b : Snapshot W Q) (reported : Bool) : Prop := + (¬ SameContent a b ∨ a.revisionIdentity ≠ b.revisionIdentity) → reported = true +/- A real represented change and compliance entail an acknowledged change. -/ +theorem semanticChangeMustBeReported {W Q : Type} (a b : Snapshot W Q) (reported : Bool) + (changed : ¬ SameContent a b ∨ a.revisionIdentity ≠ b.revisionIdentity) + (h : TruthfulReport a b reported) : reported = true := h changed +/- Reordering a two-claim presentation preserves the held theory extension. -/ +theorem representationOrderIrrelevant {W : Type} (p q : Claim W) : + ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r := by + intro r; exact or_comm +def contextSnapshot (c : Context Bool Unit) (revision : Nat := 0) : Snapshot Bool Unit := + ⟨emptyTheory, c, revision⟩ +/- Hiding each kind of contextual change violates the reporting interface; reporting alone supplies no truth guarantee. -/ +theorem hiddenContextChangeRejected : + ¬ TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (meaningContext true)) (contextSnapshot (meaningContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (scopeContext true)) (contextSnapshot (scopeContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (scopeContext true) 0) (contextSnapshot (scopeContext true) 1) false ∧ + (TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) true ∧ + ¬ Models (assumptionContext false).assumptions true) := by + have neq : (fun w : Bool => w = true) ≠ (fun w : Bool => w = false) := by + intro h; have k := congrFun h true; have z : true = false := k.mp rfl; cases z + refine ⟨?_, ?_, ?_, ?_, ?_⟩ + · intro h + have bad := h (Or.inl (by intro s; exact neq ((s.2.1 _).mp rfl))) + cases bad + · intro h + have bad := h (Or.inl (by intro s; have z := (s.2.2.1 () true).mp rfl; cases z)) + cases bad + · intro h + have bad := h (Or.inl (by intro s; have z := (s.2.2.2 true).mp rfl; cases z)) + cases bad + · intro h; have bad := h (Or.inr (by decide)); cases bad + · refine ⟨fun _ => rfl, ?_⟩ + intro h; have z := (modelsSingleton _ _).1 h; cases z +/- Two nonidentical resource objectives can share a feasible allocation. -/ +theorem tensionWithoutContradiction : + (∃ budget : Nat, 4 ≤ budget ∧ budget ≤ 6) ∧ + ¬ ((fun n : Nat => 4 ≤ n) = (fun n : Nat => n ≤ 6)) := by + refine ⟨⟨5, by decide, by decide⟩, ?_⟩ + intro h; have k := congrFun h 0; have bad : 4 ≤ 0 := k.mpr (by decide); cases bad +/- Conflicting conclusions cannot be retained under the same consistency obligation. -/ +theorem conflictRequiresChange {W Q : Type} (t : Theory W) (c : Context W Q) (q : Q) + (positive : Consequence t c q true) (negative : Consequence t c q false) : + ¬ Consistent t c := fun h => h q ⟨positive,negative⟩ +/- A satisfiable theory can have a false assumption at a specified actual world. -/ +theorem consistentFalse : Satisfiable (singleton (fun w : Bool => w = true)) ∧ + ¬ Models (singleton (fun w : Bool => w = true)) false := by + refine ⟨⟨true, (modelsSingleton _ _).2 rfl⟩, ?_⟩ + intro h; have bad := (modelsSingleton _ _).1 h; cases bad +/- The explicitly asked on/off question is undecided by the empty but inhabited theory. -/ +theorem consistentIncomplete : Satisfiable (emptyTheory : Theory Bool) ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true) ∧ + ¬ Entails emptyTheory (fun w : Bool => w ≠ true) := by + have empty : ∀ w : Bool, Models emptyTheory w := by intro w p hp; cases hp + refine ⟨⟨true, empty true⟩, ?_, ?_⟩ + · intro h; have bad := h false (empty false); cases bad + · intro h; exact h true (empty true) rfl +/- A claim can share a model with a theory without following in every model. -/ +theorem compatibilityNotEntailment : + Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true) := by + refine ⟨⟨true, (modelsUnion _ _ _).2 ⟨?_, (modelsSingleton _ _).2 rfl⟩⟩, + consistentIncomplete.2.1⟩ + intro p hp; cases hp + +end CoreReader.Logic diff --git a/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Reflexivity.lean b/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Reflexivity.lean new file mode 100644 index 0000000..3e11efe --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/leanified/CoreReader/Reflexivity.lean @@ -0,0 +1,416 @@ +import Std + +namespace CoreReader.Agency + +inductive Phase | formation | application | revision + deriving DecidableEq, Repr + +structure PrincipleKey where + owner : Nat + localId : Nat + deriving DecidableEq, Repr + +inductive Subject + | system (owner : Nat) + | principle (owner id : Nat) + | process (owner id : Nat) (phase : Phase) + deriving DecidableEq, Repr + +def Subject.owner : Subject → Nat + | .system n => n + | .principle n _ => n + | .process n _ _ => n + +inductive Activity | generation | assessment + deriving DecidableEq, Repr + +inductive QuestionKind | conformity | formationBasis | applicability | revisionGrounds + deriving DecidableEq, Repr + +inductive SampleProgram | alwaysTrue | onlyAtZero + deriving DecidableEq, Repr + +def SampleProgram.run : SampleProgram → Nat → Bool + | .alwaysTrue, _ => true + | .onlyAtZero, n => n == 0 + +/- A generated candidate specifies both the inputs it tests and the scope it proposes to license. -/ +structure MethodDraft where + testedInputs : List Nat + claimedScope : List Nat + deriving DecidableEq, Repr + +def MethodDraft.accepts (draft : MethodDraft) (program : SampleProgram) : Bool := + draft.testedInputs.all program.run + +/- This finite application asks whether a proposed rule's observed inputs support its claimed input scope. -/ +structure Inquiry where + target : Subject + kind : QuestionKind + requestedScope : List Nat + currentMethod : MethodDraft + deriving DecidableEq, Repr + +inductive ReasonContent + | purpose (inputs : List Nat) + | declaredScope (inputs : List Nat) + | observation (input : Nat) (output : Bool) + | counterexample (program : SampleProgram) (input : Nat) + deriving DecidableEq, Repr + +def ReasonContent.identifier : ReasonContent → Nat + | .purpose _ => 0 + | .declaredScope _ => 1 + | .observation _ _ => 2 + | .counterexample _ _ => 3 + +/- Reasons have independently supplied contents, a stable local reference and the actual target they concern. -/ +structure ReasonObject where + reference : Nat + target : Subject + content : ReasonContent + deriving DecidableEq, Repr + +inductive AssessmentResult | supportedWithinScope | insufficient | notApplicable | undetermined + deriving DecidableEq, Repr + +inductive WorkOutcome + | assessment (result : AssessmentResult) + | generated (draft : MethodDraft) + deriving DecidableEq, Repr + +/- A method's question, source reasons and limits are determined before looking at its activity records. +The meaning relation describes application of that method, not its universal adequacy. -/ +structure Principle where + key : PrincipleKey + activity : Activity + declaredMethod : MethodDraft + applicable : Subject → Prop + inquiry : Subject → Inquiry + reasons : Subject → List ReasonObject + limits : Subject → List Nat + meaning : Inquiry → List ReasonObject → List Nat → WorkOutcome → Prop + +structure WorkRecord where + usedPrinciple : PrincipleKey + target : Subject + activity : Activity + inquiry : Inquiry + reasons : List ReasonObject + limits : List Nat + outcome : WorkOutcome + deriving DecidableEq, Repr + +def RegistryCoherent (rules : List Principle) : Prop := + ∀ p ∈ rules, ∀ q ∈ rules, p.key = q.key → p = q + +def TargetResolved (rules : List Principle) : Subject → Prop + | .system owner => ∃ p ∈ rules, p.key.owner = owner + | .principle owner id | .process owner id _ => ∃ p ∈ rules, p.key = ⟨owner,id⟩ + +/- The inquiry names the registered target's declared method contract, not an unrelated candidate. +For a system inquiry this finite model uses the registered generation contract as its assessed artifact. -/ +def TargetContentResolved (rules : List Principle) (question : Inquiry) : Prop := + match question.target with + | .system owner => ∃ p ∈ rules, p.key = ⟨owner,0⟩ ∧ question.currentMethod = p.declaredMethod + | .principle owner id | .process owner id _ => + ∃ p ∈ rules, p.key = ⟨owner,id⟩ ∧ question.currentMethod = p.declaredMethod + +def Performed (records : List WorkRecord) (s : Subject) (a : Activity) : Prop := + ∃ record ∈ records, record.target = s ∧ record.activity = a + +/- The old scope condition remains available without conflating scope with content completion. -/ +def ReflexiveScope (owner : Nat) (rules : List Principle) (records : List WorkRecord) : Prop := + ∀ rule ∈ rules, ∀ s, s.owner = owner → rule.applicable s → Performed records s rule.activity + +/- A record uses a registered principle on the same resolvable target, question, reasons and limits, +and its result must actually follow that principle's method. A negative result can satisfy this relation. -/ +structure ValidApplication (rules : List Principle) (rule : Principle) (s : Subject) + (record : WorkRecord) : Prop where + registered : rule ∈ rules + applicable : rule.applicable s + usedIdentity : record.usedPrinciple = rule.key + targetIdentity : record.target = s + targetResolved : TargetResolved rules s + activityIdentity : record.activity = rule.activity + inquiryIdentity : record.inquiry = rule.inquiry s + inquiryTarget : record.inquiry.target = s + targetContent : TargetContentResolved rules record.inquiry + reasonsIdentity : record.reasons = rule.reasons s + reasonsNonempty : record.reasons ≠ [] + reasonTargets : ∀ reason ∈ record.reasons, reason.target = s + limitsIdentity : record.limits = rule.limits s + followsMeaning : rule.meaning record.inquiry record.reasons record.limits record.outcome + +/- The registered normative interface requires contentful application, not just activity labels. -/ +def Reflexive (owner : Nat) (rules : List Principle) (records : List WorkRecord) : Prop := + RegistryCoherent rules ∧ + ∀ rule ∈ rules, ∀ s, s.owner = owner → rule.applicable s → + ∃ record ∈ records, ValidApplication rules rule s record + +theorem Reflexive.toScope {owner : Nat} {rules : List Principle} {records : List WorkRecord} + (h : Reflexive owner rules records) : ReflexiveScope owner rules records := by + intro rule hr s hs ha + obtain ⟨record, hm, hv⟩ := h.2 rule hr s hs ha + exact ⟨record, hm, hv.targetIdentity, hv.activityIdentity⟩ + +theorem noSelfExemption (owner : Nat) (rules : List Principle) (records : List WorkRecord) + (h : Reflexive owner rules records) (rule : Principle) (hr : rule ∈ rules) + (s : Subject) (hs : s.owner = owner) (ha : rule.applicable s) : + Performed records s rule.activity := h.toScope rule hr s hs ha + +def localMethod : MethodDraft := ⟨[0],[0]⟩ + +def inquiryFor (s : Subject) : Inquiry := + match s with + | .process _ _ .formation => ⟨s, .formationBasis, [0], localMethod⟩ + | .process _ _ .application => ⟨s, .applicability, [0], localMethod⟩ + | .process _ _ .revision => ⟨s, .revisionGrounds, [0,1], localMethod⟩ + | _ => ⟨s, .conformity, [0], localMethod⟩ + +/- These original inquiry inputs do not depend on which work records happen to be present. -/ +def sourceReasonContents : QuestionKind → List ReasonContent + | .formationBasis => [.purpose [0], .declaredScope [0], .observation 0 true] + | .applicability | .conformity => [.declaredScope [0], .observation 0 true] + | .revisionGrounds => [.purpose [0,1], .declaredScope [0], .observation 0 true, + .counterexample .onlyAtZero 1] + +def reasonsFor (s : Subject) : List ReasonObject := + (sourceReasonContents (inquiryFor s).kind).map fun content => ⟨content.identifier,s,content⟩ + +/- The application-specific evaluator examines actual scope and sample/counterexample contents. +It is a finite inferential method, not a universal standard for empirical or value claims. -/ +def assessInquiry (question : Inquiry) (reasons : List ReasonObject) (limits : List Nat) : AssessmentResult := + let contents := reasons.map ReasonObject.content + if limits ≠ question.currentMethod.claimedScope then .undetermined else + match question.kind with + | .formationBasis => + if ReasonContent.purpose question.requestedScope ∈ contents ∧ + ReasonContent.declaredScope limits ∈ contents ∧ question.requestedScope = limits + then .supportedWithinScope else .undetermined + | .applicability | .conformity => + if question.requestedScope.all (fun n => limits.contains n) then + if ReasonContent.declaredScope limits ∈ contents ∧ + ReasonContent.observation 0 true ∈ contents ∧ question.requestedScope = [0] + then .supportedWithinScope else .undetermined + else .notApplicable + | .revisionGrounds => + if ReasonContent.purpose question.requestedScope ∈ contents ∧ + ReasonContent.declaredScope limits ∈ contents ∧ + ReasonContent.observation 0 true ∈ contents ∧ + contents.any (fun reason => match reason with + | .counterexample program input => question.requestedScope.contains input && + question.currentMethod.accepts program && + !(program.run input) + | _ => false) + then .insufficient else .undetermined + +def finiteMethodResult (activity : Activity) (question : Inquiry) + (reasons : List ReasonObject) (limits : List Nat) : WorkOutcome := + match activity with + | .generation => .generated ⟨question.currentMethod.testedInputs,question.requestedScope⟩ + | .assessment => .assessment (assessInquiry question reasons limits) + +def finiteMethodMeaning (activity : Activity) (question : Inquiry) + (reasons : List ReasonObject) (limits : List Nat) (outcome : WorkOutcome) : Prop := + outcome = finiteMethodResult activity question reasons limits + +def ownSubjects (owner : Nat) : List Subject := + [.system owner, .principle owner 0, .principle owner 1, + .process owner 0 .formation, .process owner 0 .application, .process owner 0 .revision, + .process owner 1 .formation, .process owner 1 .application, .process owner 1 .revision] + +/- Applying an existing rule is not a generation event in this application. -/ +def generationEligible : Subject → Bool + | .process _ _ .application => false + | _ => true + +def generatingRule (owner : Nat) : Principle where + key := ⟨owner,0⟩ + activity := .generation + declaredMethod := localMethod + applicable s := s ∈ ownSubjects owner ∧ generationEligible s = true + inquiry := inquiryFor + reasons := reasonsFor + limits _ := [0] + meaning := finiteMethodMeaning .generation + +def assessingRule (owner : Nat) : Principle where + key := ⟨owner,1⟩ + activity := .assessment + declaredMethod := localMethod + applicable s := s ∈ ownSubjects owner + inquiry := inquiryFor + reasons := reasonsFor + limits _ := [0] + meaning := finiteMethodMeaning .assessment + +def ownRules (owner : Nat) : List Principle := [generatingRule owner, assessingRule owner] + +/- Recorded verdicts are stated separately from the evaluator, so agreement has to be proved. -/ +def statedOutcome (activity : Activity) (s : Subject) : WorkOutcome := + match activity with + | .generation => .generated ⟨(inquiryFor s).currentMethod.testedInputs,(inquiryFor s).requestedScope⟩ + | .assessment => .assessment (match (inquiryFor s).kind with + | .revisionGrounds => .insufficient + | _ => .supportedWithinScope) + +def recordFor (rule : Principle) (s : Subject) : WorkRecord := + ⟨rule.key,s,rule.activity,rule.inquiry s,rule.reasons s,rule.limits s,statedOutcome rule.activity s⟩ + +theorem reasonsFor_nonempty (s : Subject) : reasonsFor s ≠ [] := by + cases s with + | system owner => simp [reasonsFor, inquiryFor, sourceReasonContents] + | principle owner id => simp [reasonsFor, inquiryFor, sourceReasonContents] + | process owner id phase => cases phase <;> simp [reasonsFor, inquiryFor, sourceReasonContents] + +theorem reasonsFor_target (s : Subject) : ∀ reason ∈ reasonsFor s, reason.target = s := by + intro reason h + obtain ⟨content, _, rfl⟩ := List.mem_map.mp h + rfl + +theorem inquiryFor_target (s : Subject) : (inquiryFor s).target = s := by + cases s with + | system owner => rfl + | principle owner id => rfl + | process owner id phase => cases phase <;> rfl + +/- This proof includes the actual negative revision evaluation for both principle identities. -/ +theorem ownContentEvaluates (activity : Activity) (s : Subject) : + statedOutcome activity s = finiteMethodResult activity (inquiryFor s) (reasonsFor s) [0] := by + cases activity with + | generation => rfl + | assessment => + cases s with + | system owner => rfl + | principle owner id => rfl + | process owner id phase => cases phase <;> rfl + +theorem ownRegistryCoherent (owner : Nat) : RegistryCoherent (ownRules owner) := by + intro p hp q hq hkey + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hp hq + rcases hp with rfl | rfl <;> rcases hq with rfl | rfl + · rfl + · have bad := congrArg PrincipleKey.localId hkey; contradiction + · have bad := congrArg PrincipleKey.localId hkey; contradiction + · rfl + +theorem ownTargetResolved (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) : + TargetResolved (ownRules owner) s := by + simp only [ownSubjects, List.mem_cons, List.not_mem_nil, or_false] at hs + rcases hs with rfl | rfl | rfl | rfl | rfl | rfl | rfl | rfl | rfl <;> + simp [TargetResolved, ownRules, generatingRule, assessingRule] + +theorem ownTargetContent (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) : + TargetContentResolved (ownRules owner) (inquiryFor s) := by + simp only [ownSubjects, List.mem_cons, List.not_mem_nil, or_false] at hs + rcases hs with rfl | rfl | rfl | rfl | rfl | rfl | rfl | rfl | rfl <;> + simp [TargetContentResolved, inquiryFor, ownRules, generatingRule, assessingRule] + +theorem ownRecordValid (owner : Nat) (rule : Principle) (hr : rule ∈ ownRules owner) + (s : Subject) (ha : rule.applicable s) : + ValidApplication (ownRules owner) rule s (recordFor rule s) := by + have hs : s ∈ ownSubjects owner := by + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl + · exact ha.1 + · exact ha + have hq : rule.inquiry = inquiryFor := by + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl <;> rfl + have hg : rule.reasons = reasonsFor := by + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl <;> rfl + have hl : rule.limits s = [0] := by + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl <;> rfl + have hm : rule.meaning = finiteMethodMeaning rule.activity := by + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl <;> rfl + refine ⟨hr, ha, rfl, rfl, ownTargetResolved owner s hs, rfl, rfl, ?_, ?_, rfl, ?_, ?_, rfl, ?_⟩ + · change (rule.inquiry s).target = s + rw [hq]; exact inquiryFor_target s + · change TargetContentResolved (ownRules owner) (rule.inquiry s) + rw [hq]; exact ownTargetContent owner s hs + · change rule.reasons s ≠ [] + rw [hg]; exact reasonsFor_nonempty s + · change ∀ reason ∈ rule.reasons s, reason.target = s + rw [hg]; exact reasonsFor_target s + · change rule.meaning (rule.inquiry s) (rule.reasons s) (rule.limits s) (statedOutcome rule.activity s) + rw [hm, hq, hg, hl] + exact ownContentEvaluates rule.activity s + +def completeOwnWork (owner : Nat) : List WorkRecord := + (ownSubjects owner).flatMap fun s => + if generationEligible s then [recordFor (generatingRule owner) s, recordFor (assessingRule owner) s] + else [recordFor (assessingRule owner) s] + +theorem assessingRecord_member (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) : + recordFor (assessingRule owner) s ∈ completeOwnWork owner := by + apply List.mem_flatMap.mpr + refine ⟨s,hs,?_⟩ + cases generationEligible s <;> simp + +theorem generatingRecord_member (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) + (hg : generationEligible s = true) : recordFor (generatingRule owner) s ∈ completeOwnWork owner := by + exact List.mem_flatMap.mpr ⟨s,hs,by simp [hg]⟩ + +theorem completeOwnWork_reflexive (owner : Nat) : + Reflexive owner (ownRules owner) (completeOwnWork owner) := by + refine ⟨ownRegistryCoherent owner, ?_⟩ + intro rule hr s _ ha + refine ⟨recordFor rule s, ?_, ownRecordValid owner rule hr s ha⟩ + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl + · exact generatingRecord_member owner s ha.1 ha.2 + · exact assessingRecord_member owner s ha + +theorem ownAssessmentPerformed (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) : + Performed (completeOwnWork owner) s .assessment := + ⟨recordFor (assessingRule owner) s, assessingRecord_member owner s hs, rfl, rfl⟩ + +def applicationRule : Principle := + { assessingRule 0 with key := ⟨0,0⟩, applicable := fun s => s = .process 0 0 .application } + +def applicationWork : List WorkRecord := [recordFor applicationRule (.process 0 0 .application)] + +theorem applicationWork_reflexive : Reflexive 0 [applicationRule] applicationWork := by + constructor + · intro p hp q hq _ + simp only [List.mem_singleton] at hp hq + rw [hp,hq] + · intro rule hr s _ ha + simp only [List.mem_singleton] at hr + subst rule + change s = .process 0 0 .application at ha + subst s + refine ⟨recordFor applicationRule (.process 0 0 .application), by simp [applicationWork], ?_⟩ + refine ⟨by simp, rfl, rfl, rfl, ?_, rfl, rfl, rfl, ?_, rfl, ?_, ?_, rfl, ?_⟩ + · exact ⟨applicationRule, by simp, rfl⟩ + · exact ⟨applicationRule, by simp, rfl, rfl⟩ + · exact reasonsFor_nonempty _ + · exact reasonsFor_target _ + · change statedOutcome .assessment (.process 0 0 .application) = finiteMethodResult .assessment (inquiryFor (.process 0 0 .application)) (reasonsFor (.process 0 0 .application)) [0] + exact ownContentEvaluates .assessment _ + +theorem applicabilityRetained (owner : Nat) (rules : List Principle) (records : List WorkRecord) : + (Reflexive owner rules records → ReflexiveScope owner rules records) ∧ + (ReflexiveScope owner rules records ↔ + ∀ rule ∈ rules, ∀ s, s.owner = owner → (¬ rule.applicable s ∨ Performed records s rule.activity)) ∧ + (Reflexive 0 [applicationRule] applicationWork ∧ + ¬ Performed applicationWork (.system 0) .assessment) := by + classical + refine ⟨Reflexive.toScope, ?_, applicationWork_reflexive, ?_⟩ + · constructor + · intro h rule hr s hs + by_cases ha : rule.applicable s + · exact Or.inr (h rule hr s hs ha) + · exact Or.inl ha + · intro h rule hr s hs ha + exact (h rule hr s hs).resolve_left (not_not_intro ha) + · rintro ⟨record, hm, ht, _⟩ + simp only [applicationWork, List.mem_singleton] at hm + subst record + cases ht + +end CoreReader.Agency diff --git a/SoftwareEngineering/lean/philosophy/leanified/lake-manifest.json b/SoftwareEngineering/lean/philosophy/leanified/lake-manifest.json new file mode 100644 index 0000000..d783341 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/leanified/lake-manifest.json @@ -0,0 +1,6 @@ +{"version": "1.2.0", + "packagesDir": ".lake/packages", + "packages": [], + "name": "software_engineering", + "lakeDir": ".lake", + "fixedToolchain": false} diff --git a/SoftwareEngineering/lean/philosophy/leanified/lakefile.toml b/SoftwareEngineering/lean/philosophy/leanified/lakefile.toml new file mode 100644 index 0000000..836a9be --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/leanified/lakefile.toml @@ -0,0 +1,5 @@ +name = "software_engineering" +version = "0.0.1" +defaultTargets = ["CoreReader"] +[[lean_lib]] +name = "CoreReader" diff --git a/SoftwareEngineering/lean/philosophy/leanified/lean-toolchain b/SoftwareEngineering/lean/philosophy/leanified/lean-toolchain new file mode 100644 index 0000000..a8afa7d --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/leanified/lean-toolchain @@ -0,0 +1 @@ +leanprover/lean4:v4.33.1 diff --git a/SoftwareEngineering/lean/philosophy/manuscript.json b/SoftwareEngineering/lean/philosophy/manuscript.json new file mode 100644 index 0000000..dcb0c74 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/manuscript.json @@ -0,0 +1,892 @@ +{ + "schema_version": 1, + "repository_root": "../..", + "source_current": { + "path": "../../PHILOSOPHY.md", + "sha256": "adc8cce5ac55a5e3795f8806748603eb69d5695fa37bbe263bee20ac6c14a1a6" + }, + "baseline_current": { + "path": "../../PHILOSOPHY.md", + "sha256": "adc8cce5ac55a5e3795f8806748603eb69d5695fa37bbe263bee20ac6c14a1a6" + }, + "proof_targets": { + "path": "targets.json", + "sha256": "19184f5f301fb5a2f156d09a1d5b4fee5f9e8e9bbc96fdc5fbbc9ccb426287bb" + }, + "code_files": [ + { + "path": "leanified/CoreReader/Adopted.lean", + "sha256": "8de4d364bb3c64e29ab92e81d86cbe4c9e5af49ada3dad262d1378421fb588c2" + }, + { + "path": "leanified/CoreReader/Agency.lean", + "sha256": "2722c34645f4256f20ce31205738f2f5712ab5dd5cc6fcf9f1180d0be5aa0303" + }, + { + "path": "leanified/CoreReader/Choice.lean", + "sha256": "b28728df12ed7e73edb5569604cd2541c0ebd815ae3aaa0812e6557dece1d1ba" + }, + { + "path": "leanified/CoreReader/Engineering/Domain.lean", + "sha256": "ce5653a2950cc7443cefbfe8b9726bd4859228e831ddb7d42601e501ccbfd855" + }, + { + "path": "leanified/CoreReader/Engineering/Integration.lean", + "sha256": "a2b88062148b3f7ebea7da02d88cb29cb04d8f1b2e9e6b97bb2420ac2c006328" + }, + { + "path": "leanified/CoreReader/Engineering/Reflection.lean", + "sha256": "c290d8472884d00bedbf945f0fc1866524e758740f40d42088c4ff9678a93fa2" + }, + { + "path": "leanified/CoreReader/Engineering/SelfApplication.lean", + "sha256": "d69c0d369bd4fd8db4c21ce3b65abb5e9efd07ed5ab9a68d56b4db39bb9d2a21" + }, + { + "path": "leanified/CoreReader/Engineering/Values.lean", + "sha256": "ccd45bf23d2f47c41d1b2f9955d753e290687d951a0c55af41ab9a63b9a8d9cb" + }, + { + "path": "leanified/CoreReader/Evidence.lean", + "sha256": "d55f33e44902cef146841cbffb65710bd7c8a3bda79d01d084edc36f019fdc96" + }, + { + "path": "leanified/CoreReader/Integration.lean", + "sha256": "97e2939c0b6714b78a3ed78358e174619a5028ad5b0b5025c0d4422b4294921b" + }, + { + "path": "leanified/CoreReader/Logic.lean", + "sha256": "0ec342691766ebd83d251dcd0da3b0ae9840aed677a714bc1b01c45d89392bc0" + }, + { + "path": "leanified/CoreReader/Reflexivity.lean", + "sha256": "48e2c74e7cbae571db1b990b9f32dd0d701f6881a8b0111d907f8861287d76fa" + }, + { + "path": "leanified/CoreReader.lean", + "sha256": "c5574fae235419a7d6449b3ebb5d2da29d1e92a3b572c1b759438e3c470caaa9" + } + ], + "review": { + "path": "reviews/fidelity.json", + "sha256": "33ed353c45a6b9f9e0b9af17e7d511c9796d5e8a68c607a3fb1f08f3c881c87f" + }, + "views": { + "overview_en": { + "path": "overview.md", + "sha256": "a35649faecf594b1eafebb6d5693cd39a5dbcf842cc1607e9b9901b7da805e5f" + }, + "details_en": { + "path": "details.md", + "sha256": "b30cf8293abe296b964130cd2fdff1fb8de18be7fe779ae480f3a5777e4c2188" + }, + "overview_zh": { + "path": "../../zh/lean/philosophy/overview.md", + "sha256": "fe321fee11d3a9b3176c256e6fbd5630e9a9c3487a41aba18719bf2a9d34acf1" + }, + "details_zh": { + "path": "../../zh/lean/philosophy/details.md", + "sha256": "8f522c658f4b7f81729db7712cb4e5095f683b39bca355cd479271e64b5aaf20" + } + }, + "entries": [ + { + "id": "organon.preamble.p1", + "unit": "organon.preamble", + "clause": "p1", + "excerpt": "This is a statement of Software Engineering Organon’s adopted philosophy. It expresses commitments, not factual assertions about every system or a proof of universal correctness.", + "declarations": [], + "kernel": "not_checked", + "fidelity": "not_applicable", + "status": "not_applicable", + "reason": "Documentary authority, interpretive role or disclosed boundary. No formal proof is assigned." + }, + { + "id": "organon.preamble.p2", + "unit": "organon.preamble", + "clause": "p2", + "excerpt": "The quoted provisions, their meanings, and their conditions of application form the core. The charter and Grounds constrain one another; their grouping establishes neither a deductive hierarchy nor an order of priority. [Rationale](rationale/README.md) supplies arguments and cases without adding obligations to this core. Skills are revisable applications under the repository’s stated objectives and constraints, not part of the philosophical commitments themselves.", + "declarations": [], + "kernel": "not_checked", + "fidelity": "not_applicable", + "status": "not_applicable", + "reason": "Documentary authority, interpretive role or disclosed boundary. No formal proof is assigned." + }, + { + "id": "organon.charter", + "unit": "organon.charter", + "clause": null, + "excerpt": "\n", + "declarations": [], + "kernel": "not_checked", + "fidelity": "not_applicable", + "status": "not_applicable", + "reason": "Structural heading without substantive direct-body content; no theorem is assigned." + }, + { + "id": "organon.charter.overview.p1", + "unit": "organon.charter.overview", + "clause": "p1", + "excerpt": "**Self-Transcendence · Internal Consistency · Reflexivity**", + "declarations": [], + "kernel": "not_checked", + "fidelity": "not_applicable", + "status": "not_applicable", + "reason": "Documentary authority, interpretive role or disclosed boundary. No formal proof is assigned." + }, + { + "id": "organon.charter.overview.p2", + "unit": "organon.charter.overview", + "clause": "p2", + "excerpt": "> A system is intrinsically oriented toward expanding what it can understand and construct. It brings itself and its principles within the scope of generation and assessment, with internal consistency constraining this process.", + "declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T02, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.overview.p3", + "unit": "organon.charter.overview", + "clause": "p3", + "excerpt": "The overview connects three distinct requirements: self-transcendence establishes a generative orientation and refuses to treat existing forms as final, internal consistency constrains judgments held simultaneously, and reflexivity brings the system and its principles within the scope of their own generation and assessment. The provisions below specify the conditions for each.", + "declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T02, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.self-transcendence.p1", + "unit": "organon.charter.self-transcendence", + "clause": "p1", + "excerpt": "> A system is intrinsically oriented toward expanding what it can understand and construct. It does not regard any existing form as the endpoint of generation.", + "declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T02, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.self-transcendence.orientation.p1", + "unit": "organon.charter.self-transcendence.orientation", + "clause": "p1", + "excerpt": "A commitment to keeping generative possibilities open is distinct from valuing their expansion. A system has an intrinsic orientation when it regards that expansion as worth pursuing. Merely permitting change does not fully express this orientation.", + "declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases", + "CoreReader.Adopted.generationLimits012", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T02, T03, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.self-transcendence.non-finality.p1", + "unit": "organon.charter.self-transcendence.non-finality", + "clause": "p1", + "excerpt": "Refusing to regard an existing form as an endpoint keeps it open to being surpassed. “Existing form” includes a system’s current organization, methods, and principles, not only its appearance or artifacts. These remain within the scope of possible change; their revisability does not guarantee actual progress.", + "declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases", + "CoreReader.Adopted.generationLimits012", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T02, T03, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.self-transcendence.limits.p1", + "unit": "organon.charter.self-transcendence.limits", + "clause": "p1", + "excerpt": "Whether progress has actually occurred remains a separate judgment. Having the orientation does not guarantee progress. Progress cannot be established merely by an increase in the number of artifacts, levels of abstraction, or terms.", + "declarations": [ + "CoreReader.Adopted.generationLimits012", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T03, T38. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.self-transcendence.limits.p2", + "unit": "organon.charter.self-transcendence.limits", + "clause": "p2", + "excerpt": "- “Intrinsic orientation” expresses Organon’s philosophical commitment; it does not assert that all systems in fact develop autonomously.\n- Self-transcendence does not imply independence from external experience, knowledge, or collaboration, nor does it guarantee autonomous execution or self-improvement.\n- Refusing to regard an existing form as an endpoint does not require every action to produce change. Justified stability can coexist with a generative orientation.\n- Whether transcendence expands what can be understood and constructed requires discernible grounds; a system’s own claim of generation does not establish actual achievement.", + "declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases", + "CoreReader.Adopted.generationLimits012", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T02, T03, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.consistency.p1", + "unit": "organon.charter.consistency", + "clause": "p1", + "excerpt": "> The principles and judgments a system holds simultaneously, together with their implications, must not yield contradictory judgments on the same question under the same assumptions, meanings of terms, and scope of application.", + "declarations": [ + "CoreReader.Adopted.consistencySpecification", + "CoreReader.Adopted.consistencyCases", + "CoreReader.Adopted.consistencyConsequences", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T04, T05, T38. A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.consistency.meaning.p1", + "unit": "organon.charter.consistency.meaning", + "clause": "p1", + "excerpt": "“Held simultaneously” specifies which principles, judgments, and implications must hold together. Revision may withdraw an earlier judgment; old and new principles need not remain compatible forever. When a change has occurred, that change cannot be represented as though it had not occurred.", + "declarations": [ + "CoreReader.Adopted.consistencySpecification", + "CoreReader.Adopted.consistencyCases", + "CoreReader.Adopted.consistencyConsequences", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T04, T05, T38. A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.consistency.meaning.p2", + "unit": "organon.charter.consistency.meaning", + "clause": "p2", + "excerpt": "“The same assumptions, meanings of terms, and scope of application” specifies the basis for comparing judgments. Divergent judgments under different conditions do not automatically constitute contradictions. Nor can unacknowledged changes in assumptions, meanings, or scope be used to conceal an existing contradiction.", + "declarations": [ + "CoreReader.Adopted.consistencySpecification", + "CoreReader.Adopted.consistencyCases", + "CoreReader.Adopted.consistencyConsequences", + "CoreReader.Adopted.consistencyLimits012", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T04, T05, T06, T38. A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. Consistency is not sufficient empirical or value support; the counterexamples concern the disclosed mathematical representation. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.consistency.limits.p1", + "unit": "organon.charter.consistency.limits", + "clause": "p1", + "excerpt": "- Tension between different assessments or values does not directly constitute a contradiction. Revision or qualification is needed when they require incompatible conclusions under the same conditions.\n- Internal consistency is not correctness or sufficiency. A set of principles may be internally consistent while relying on false assumptions or neglecting important questions.", + "declarations": [ + "CoreReader.Adopted.consistencySpecification", + "CoreReader.Adopted.consistencyCases", + "CoreReader.Adopted.consistencyConsequences", + "CoreReader.Adopted.consistencyLimits012", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T04, T05, T06, T38. A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. Consistency is not sufficient empirical or value support; the counterexamples concern the disclosed mathematical representation. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.reflexivity.p1", + "unit": "organon.charter.reflexivity", + "clause": "p1", + "excerpt": "> A system’s principles of generation and assessment also apply to the system itself and to the formation, application, and revision of those principles.", + "declarations": [ + "CoreReader.Adopted.reflexivitySpecification", + "CoreReader.Adopted.reflexivityCases012", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T07, T38. Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.reflexivity.meaning.p1", + "unit": "organon.charter.reflexivity.meaning", + "clause": "p1", + "excerpt": "Reflexivity encompasses both the system itself and its principles. Assessment concerns not only whether the system conforms to its principles, but also how those principles are formed, where they apply, and why they may need revision. The formation and revision of principles thus also become objects of generation and assessment.", + "declarations": [ + "CoreReader.Adopted.reflexivitySpecification", + "CoreReader.Adopted.reflexivityCases012", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T07, T38. Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.reflexivity.limits.p1", + "unit": "organon.charter.reflexivity.limits", + "clause": "p1", + "excerpt": "- Applying principles equally retains their conditions of application. When the relevant conditions hold, being the system itself is not a basis for exemption. Nor does the requirement of reflexivity establish that every principle can be applied to itself without examining its applicability.\n- Self-application does not constitute self-proof. Subjecting a principle to its own assessment does not thereby establish its correctness.\n- That a revision is produced by the system itself does not give it sufficient grounds.", + "declarations": [ + "CoreReader.Adopted.reflexivitySpecification", + "CoreReader.Adopted.reflexivityCases012", + "CoreReader.Adopted.reflexivityLimits012", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T07, T08, T38. Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.grounds.p1", + "unit": "organon.grounds", + "clause": "p1", + "excerpt": "> The grounds of principles and judgments must be articulable and subject to assessment appropriate to the nature of the claim. The strength and scope of a claim must be proportionate to the support provided by its grounds.", + "declarations": [ + "CoreReader.Adopted.reflexivityLimits012", + "CoreReader.Adopted.Grounds012", + "CoreReader.Adopted.groundsCases012", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T08, T09, T38. This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.grounds.assessment.p1", + "unit": "organon.grounds.assessment", + "clause": "p1", + "excerpt": "Articulation and assessment have distinct responsibilities. Articulability requires that concepts, assumptions, reasons, and limits can be identified. Assessment requires examining whether those grounds support the corresponding claim. Clearly expressed grounds are not thereby sufficiently established.", + "declarations": [ + "CoreReader.Adopted.Grounds012", + "CoreReader.Adopted.groundsCases012", + "CoreReader.Adopted.groundsLimits012", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T09, T13, T38. This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. These distinctions do not require values, empirical evidence and inference to be reduced to one score. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.grounds.assessment.p2", + "unit": "organon.grounds.assessment", + "clause": "p2", + "excerpt": "| Type of claim | Responsibility of assessment | What cannot substitute for that responsibility |\n| --- | --- | --- |\n| Empirical claim | Examine observations, evidence, and performance, together with the conditions, scope, and uncertainty of their support for the claim. | Treating measurability or repeatability itself as proof of relevance, correctness, or value. |\n| Inferential claim | Examine whether the conclusion is supported by the stated assumptions and inferential relations. | Treating the absence of conflict between a conclusion and its assumptions as sufficient to establish that the conclusion follows from them. |\n| Value commitment | State the position taken, its reasons, limits of application, and consequences, and remain open to relevant criticism. | Presenting a commitment as an empirical fact or a necessary inference, or substituting self-assertion for reasons. |", + "declarations": [ + "CoreReader.Adopted.Grounds012", + "CoreReader.Adopted.groundsCases012", + "CoreReader.Adopted.empiricalSpecification", + "CoreReader.Adopted.empiricalCases012", + "CoreReader.Adopted.inferentialSpecification", + "CoreReader.Adopted.inferentialCases012", + "CoreReader.Adopted.valueSpecification", + "CoreReader.Adopted.valueCases012", + "CoreReader.Adopted.groundsLimits012", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T09, T10, T11, T12, T13, T38. This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. Repeatability or measurability alone does not establish relevance, correctness or value; varying unobserved outcomes need not contradict limited support. Failure of support is not failure to assess correctly; consistency with assumptions is weaker than entailment. The application supplies a sufficient value assessment, not a universal requirement to prove every starting assumption or a proof that one value is universally best. These distinctions do not require values, empirical evidence and inference to be reduced to one score. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.grounds.assessment.p3", + "unit": "organon.grounds.assessment", + "clause": "p3", + "excerpt": "Initial value commitments may be stated explicitly as commitments; they need not prove all their own starting assumptions. The strength and scope of a claim do not require conversion to a common numerical scale. Different types of claims specify their support and limits in accordance with their nature.", + "declarations": [ + "CoreReader.Adopted.Grounds012", + "CoreReader.Adopted.groundsCases012", + "CoreReader.Adopted.valueSpecification", + "CoreReader.Adopted.valueCases012", + "CoreReader.Adopted.groundsLimits012", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T09, T12, T13, T38. This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. The application supplies a sufficient value assessment, not a universal requirement to prove every starting assumption or a proof that one value is universally best. These distinctions do not require values, empirical evidence and inference to be reduced to one score. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.grounds.scope.p1", + "unit": "organon.grounds.scope", + "clause": "p1", + "excerpt": "Performance is discerned within particular relations, conditions, and scopes of observation. A boundary helps specify what a comparison concerns, but local examples do not automatically support unconditional universal conclusions. A judgment cannot establish that relevant differences do not exist merely because its chosen scope omits them.", + "declarations": [ + "CoreReader.Adopted.scopeSpecification", + "CoreReader.Adopted.scopeCases012", + "CoreReader.Adopted.scopeLimits012", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T14, T15, T38. A nonempty role string alone is not sufficient interpretation, and an unused method does not become compulsory. Omitting an input from comparison is not evidence that no relevant difference exists there. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.grounds.scope.p2", + "unit": "organon.grounds.scope", + "clause": "p2", + "excerpt": "Measurement can make some differences comparable. Repeated assessment can help examine the stability of corresponding conclusions. Their roles, and the role of any assessment framework, must be explained relative to the claim and its context. Measurement, repeatability, and an assessment framework do not form a universally necessary chain on which all judgments must depend.", + "declarations": [ + "CoreReader.Adopted.scopeSpecification", + "CoreReader.Adopted.scopeCases012", + "CoreReader.Adopted.scopeLimits012", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T14, T15, T38. A nonempty role string alone is not sufficient interpretation, and an unused method does not become compulsory. Omitting an input from comparison is not evidence that no relevant difference exists there. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.grounds.scope.p3", + "unit": "organon.grounds.scope", + "clause": "p3", + "excerpt": "An observation that has not been reproduced may still offer limited support, and random outcomes need not be identical on every occasion. The verifiability of observations, reproducibility of conditions, and stability of conclusions must be distinguished.", + "declarations": [ + "CoreReader.Adopted.scopeSpecification", + "CoreReader.Adopted.scopeCases012", + "CoreReader.Adopted.scopeLimits012", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T14, T15, T38. A nonempty role string alone is not sufficient interpretation, and an unused method does not become compulsory. Omitting an input from comparison is not evidence that no relevant difference exists there. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.grounds.capabilities.p1", + "unit": "organon.grounds.capabilities", + "clause": "p1", + "excerpt": "Capability claims are subject to Grounds: the capability claimed, its conditions, and the support for it must be identifiable. The core does not prescribe uniform definitions of method mastery, method generation, or capability levels. Applications specify the capabilities they assess and may require understanding, explanation, or performance under relevant variations.", + "declarations": [ + "CoreReader.Adopted.capabilitySpecification", + "CoreReader.Adopted.capabilityCases012", + "CoreReader.Adopted.capabilityLimits012", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T16, T17, T38. This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. An external assessor can ground the selected output claim without establishing how the assessed system understands its generation process. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.grounds.capabilities.p2", + "unit": "organon.grounds.capabilities", + "clause": "p2", + "excerpt": "Grounds for a capability claim may be supplied by an external assessor. Their articulability does not by itself require the assessed system to understand or explain its internal generation process. Evidence of reliable output must be assessed against the capability actually claimed; it does not automatically establish understanding of that process. Nor can the number of method documents, terms, tools, or artifacts alone establish a capability beyond what that evidence supports.", + "declarations": [ + "CoreReader.Adopted.capabilitySpecification", + "CoreReader.Adopted.capabilityCases012", + "CoreReader.Adopted.capabilityLimits012", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T16, T17, T38. This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. An external assessor can ground the selected output claim without establishing how the assessed system understands its generation process. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.grounds.implementations.p1", + "unit": "organon.grounds.implementations", + "clause": "p1", + "excerpt": "> The choice of an implementation must be supported by reasons connected to the objectives and values pursued and to the relevant constraints. Its name, conventional use, or established status alone does not provide sufficient grounds for giving it priority.", + "declarations": [ + "CoreReader.Adopted.choiceSpecification", + "CoreReader.Adopted.choiceCases012", + "CoreReader.Adopted.choiceLimits012", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T18, T19, T38. These are application reasons, not a universal cost function or a rule that conventional implementations must lose. No result asserts all implementations equivalent, multiple feasible implementations guaranteed, or the choice commitment derivable from chapter placement. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.grounds.implementations.p2", + "unit": "organon.grounds.implementations", + "clause": "p2", + "excerpt": "This choice provision adds an additional evaluative commitment: name, conventional use, or established status alone is insufficient to establish priority. Grouping it under Grounds does not mean that it follows from the general requirement to assess reasons, or merely from the discernibility of performance. Conventions and existing arrangements may have practical significance, but that significance must be connected to the objectives and values pursued and to the relevant constraints.", + "declarations": [ + "CoreReader.Adopted.choiceSpecification", + "CoreReader.Adopted.choiceCases012", + "CoreReader.Adopted.choiceLimits012", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T18, T19, T38. These are application reasons, not a universal cost function or a rule that conventional implementations must lose. No result asserts all implementations equivalent, multiple feasible implementations guaranteed, or the choice commitment derivable from chapter placement. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.grounds.implementations.limits.p1", + "unit": "organon.grounds.implementations.limits", + "clause": "p1", + "excerpt": "- Openness does not make all implementations equivalent, nor does it guarantee multiple feasible implementations for the same objective.\n- A method’s explanatory power, limits of application, simplicity, and explicit process requirements may all provide grounded reasons for assessment. They cannot be excluded merely because they concern methods internal to the implementation.\n- Identical local performance does not establish overall equivalence. Relations, conditions, and the scope of comparison are constrained by the provisions of Grounds.\n- Openness does not reject an implementation merely because it already exists or is conventionally used. Relevant reasons may still give it priority.", + "declarations": [ + "CoreReader.Adopted.scopeLimits012", + "CoreReader.Adopted.choiceSpecification", + "CoreReader.Adopted.choiceCases012", + "CoreReader.Adopted.choiceLimits012", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T15, T18, T19, T38. Omitting an input from comparison is not evidence that no relevant difference exists there. These are application reasons, not a universal cost function or a rule that conventional implementations must lose. No result asserts all implementations equivalent, multiple feasible implementations guaranteed, or the choice commitment derivable from chapter placement. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.relationships", + "unit": "organon.relationships", + "clause": null, + "excerpt": "\n", + "declarations": [], + "kernel": "not_checked", + "fidelity": "not_applicable", + "status": "not_applicable", + "reason": "Structural heading without substantive direct-body content; no theorem is assigned." + }, + { + "id": "organon.relationships.roles.p1", + "unit": "organon.relationships.roles", + "clause": "p1", + "excerpt": "The charter states the generative orientation, the consistency constraint, and reflexive application. Grounds specifies support requirements for judgments and includes an additional commitment concerning implementation choices. Both parts belong to the core and constrain one another. Their placement neither makes Grounds a deduction from the charter nor gives the charter priority over it. Each commitment needs its own reasons.", + "declarations": [ + "CoreReader.Adopted.reflexivityLimits012", + "CoreReader.Engineering.inheritedMutualApplication", + "CoreReader.Engineering.inheritedMutualCases", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T08, T20, T38, T39. This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. Projection does not derive all duties from one principle. Adoption markers are separate facts; they do not substitute for normative content. The sample-aware criticism is an application criterion, not a universal requirement for observations. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance." + }, + { + "id": "organon.relationships.roles.p2", + "unit": "organon.relationships.roles", + "clause": "p2", + "excerpt": "Internal Consistency concerns whether simultaneously held judgments can hold together; Grounds concerns whether and how far a claim is supported. A conclusion may fail to conflict with its assumptions without being supported by them. Self-Transcendence specifies a generative orientation and non-finality; neither establishes actual capability. Applications may supply objectives, values, and capability definitions; claims made under those objectives, values, and definitions remain subject to the relevant core provisions.", + "declarations": [ + "CoreReader.Adopted.generationLimits012", + "CoreReader.Adopted.consistencyLimits012", + "CoreReader.Adopted.inferentialSpecification", + "CoreReader.Adopted.inferentialCases012", + "CoreReader.Adopted.capabilitySpecification", + "CoreReader.Adopted.capabilityCases012", + "CoreReader.Engineering.inheritedMutualApplication", + "CoreReader.Engineering.inheritedMutualCases", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T03, T06, T11, T16, T20, T38, T39. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. Consistency is not sufficient empirical or value support; the counterexamples concern the disclosed mathematical representation. Failure of support is not failure to assess correctly; consistency with assumptions is weaker than entailment. This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. Projection does not derive all duties from one principle. Adoption markers are separate facts; they do not substitute for normative content. The sample-aware criticism is an application criterion, not a universal requirement for observations. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance." + }, + { + "id": "organon.relationships.roles.p3", + "unit": "organon.relationships.roles", + "clause": "p3", + "excerpt": "Self-Transcendence does not substitute for Reflexivity: keeping existing forms open to being surpassed differs from applying relevant principles to the system and to their own formation, application, and revision. Reflexivity extends these requirements to the system and to the formation, application, and revision of its principles. The grounds and limits of the Grounds provisions must themselves be articulable. The system’s own capability claims remain subject to assessment, and this philosophy’s existing form cannot gain priority merely from its established status. Such mutual application provides no self-proof and does not remove conditions of application.", + "declarations": [ + "CoreReader.Adopted.reflexivitySpecification", + "CoreReader.Adopted.reflexivityCases012", + "CoreReader.Adopted.reflexivityLimits012", + "CoreReader.Adopted.capabilitySpecification", + "CoreReader.Adopted.capabilityCases012", + "CoreReader.Adopted.choiceSpecification", + "CoreReader.Adopted.choiceCases012", + "CoreReader.Engineering.inheritedMutualApplication", + "CoreReader.Engineering.inheritedMutualCases", + "CoreReader.Engineering.priorityRemainsReflexive", + "CoreReader.Engineering.priorityReflexiveCases", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T07, T08, T16, T18, T20, T37, T38, T39. Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. These are application reasons, not a universal cost function or a rule that conventional implementations must lose. Projection does not derive all duties from one principle. Adoption markers are separate facts; they do not substitute for normative content. The sample-aware criticism is an application criterion, not a universal requirement for observations. Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance." + }, + { + "id": "organon.relationships.terms.p1", + "unit": "organon.relationships.terms", + "clause": "p1", + "excerpt": "| Term | Meaning in this philosophy |\n| --- | --- |\n| Existing form | The system’s current organization, methods, and principles, not only its appearance or artifacts. |\n| Assessment | Examination of reasons, applicability, and observed performance; not limited to executable tests. |", + "declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "incomplete", + "reason": "Bounded source correspondence to T02. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve." + }, + { + "id": "extensions.p1", + "unit": "extensions", + "clause": "p1", + "excerpt": "This chapter adds a software engineering commitment and specifies its meaning and limits. It does not claim that this commitment follows from the Charter or Grounds. Those provisions remain adopted and constrain its application.", + "declarations": [ + "CoreReader.Engineering.priorityRemainsReflexive", + "CoreReader.Engineering.priorityReflexiveCases", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T37, T38, T39. Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance." + }, + { + "id": "software-engineering.purpose.p1", + "unit": "software-engineering.purpose", + "clause": "p1", + "excerpt": "Software engineering concerns the construction, operation, understanding, and revision of software within its relevant human and technical conditions. This philosophy guides decisions by people and agents; it does not attribute an intrinsic orientation to every software artifact.", + "declarations": [ + "CoreReader.Engineering.ActivityScope", + "CoreReader.Engineering.subjectLifecycleCases", + "CoreReader.Engineering.subjectLimits", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T22, T23, T38. These numerical schedules are finite model data, not project time estimates. Scope alone does not prove every participant can perform every change. The result concerns the represented paths; lack of one documented path is not a universal impossibility theorem about all maintenance. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "software-engineering.purpose.p2", + "unit": "software-engineering.purpose", + "clause": "p2", + "excerpt": "The evolution capability considered here belongs to the continuing engineering activity: maintainers, including successor maintainers and agents, working with software, tools, and available knowledge. Code that its original author can modify is not on that ground alone shown to support that continuing activity.", + "declarations": [ + "CoreReader.Engineering.ActivityScope", + "CoreReader.Engineering.subjectLifecycleCases", + "CoreReader.Engineering.subjectLimits", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T22, T23, T38. These numerical schedules are finite model data, not project time estimates. Scope alone does not prove every participant can perform every change. The result concerns the represented paths; lack of one documented path is not a universal impossibility theorem about all maintenance. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "software-engineering.purpose.p3", + "unit": "software-engineering.purpose", + "clause": "p3", + "excerpt": "Apply the following priority according to the software's credible lifecycle and maintenance expectations. A genuinely temporary script, bounded prototype, or retiring system may have little reason to support further evolution. Calling a continuing system temporary does not establish that condition.", + "declarations": [ + "CoreReader.Engineering.ActivityScope", + "CoreReader.Engineering.subjectLifecycleCases", + "CoreReader.Engineering.subjectLimits", + "CoreReader.Engineering.EvolutionPriority", + "CoreReader.Engineering.priorityConditionsCases", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T22, T23, T24, T38. These numerical schedules are finite model data, not project time estimates. Scope alone does not prove every participant can perform every change. The result concerns the represented paths; lack of one documented path is not a universal impossibility theorem about all maintenance. This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "software-engineering.evolution-priority.p1", + "unit": "software-engineering.evolution-priority", + "clause": "p1", + "excerpt": "> When relevant behavioral, safety, performance, and other necessary requirements are satisfied, give priority to continuing maintainers' ability to make credible future changes, including changes to the design itself, over present abstraction simplicity. Accept additional present abstraction complexity for that purpose, while allowing this preference to yield when the added costs threaten concrete engineering objectives.", + "declarations": [ + "CoreReader.Engineering.EvolutionPriority", + "CoreReader.Engineering.priorityConditionsCases", + "CoreReader.Engineering.priorityWhenApplicable", + "CoreReader.Engineering.priorityChoices", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T24, T25, T38, T39. This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. The theorem neither proves the value rule from facts nor establishes that every apparently complex design has the relevant advantage. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance." + }, + { + "id": "software-engineering.evolution-priority.p2", + "unit": "software-engineering.evolution-priority", + "clause": "p2", + "excerpt": "Credible directions of change have articulable grounds, such as a committed plan, relevant domain knowledge, or an applicable history of change. They need not already have multiple implementations. Their credibility remains open to revision; a conceivable change alone does not establish that it warrants accommodation now.", + "declarations": [ + "CoreReader.Engineering.EvolutionPriority", + "CoreReader.Engineering.priorityConditionsCases", + "CoreReader.Engineering.priorityWhenApplicable", + "CoreReader.Engineering.priorityChoices", + "CoreReader.Engineering.CredibleDirection", + "CoreReader.Engineering.credibilityCases", + "CoreReader.Engineering.credibilityLimits", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T24, T25, T26, T27, T38, T39. This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. The theorem neither proves the value rule from facts nor establishes that every apparently complex design has the relevant advantage. The proof checks stipulated evidence contents, not the real-world credibility or predictive calibration of arbitrary plans. No finite list of directions proves all future changes predictable or all omitted possibilities irrelevant. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance." + }, + { + "id": "software-engineering.evolution-priority.p3", + "unit": "software-engineering.evolution-priority", + "clause": "p3", + "excerpt": "This is a default priority, not an obligation to maximize extensibility or retain every possibility. Costs include relevant burdens of understanding, construction, diagnosis, verification, coordination, operation, and eventual migration. A departure from the priority identifies the objective threatened and why the costs matter. No universal numerical exchange rate between these considerations is prescribed.", + "declarations": [ + "CoreReader.Engineering.EvolutionPriority", + "CoreReader.Engineering.priorityConditionsCases", + "CoreReader.Engineering.priorityWhenApplicable", + "CoreReader.Engineering.priorityChoices", + "CoreReader.Engineering.CredibleDirection", + "CoreReader.Engineering.credibilityCases", + "CoreReader.Engineering.credibilityLimits", + "CoreReader.Engineering.JustifiedDeparture", + "CoreReader.Engineering.costCases", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T24, T25, T26, T27, T28, T38, T39. This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. The theorem neither proves the value rule from facts nor establishes that every apparently complex design has the relevant advantage. The proof checks stipulated evidence contents, not the real-world credibility or predictive calibration of arbitrary plans. No finite list of directions proves all future changes predictable or all omitted possibilities irrelevant. The finite costs are modeled work/budget data. The source does not require every category to apply or provide a universal numerical tradeoff. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance." + }, + { + "id": "software-engineering.evolution-meaning.p1", + "unit": "software-engineering.evolution-meaning", + "clause": "p1", + "excerpt": "Evolution includes adding capabilities, replacing implementations, deleting mechanisms, withdrawing abstractions, redrawing boundaries, and migrating away from an existing technology or model. Making additions within a fixed scheme does not establish equal ability to revise or leave that scheme. Not every such change can or should be made inexpensive.", + "declarations": [ + "CoreReader.Engineering.EvolutionClaim", + "CoreReader.Engineering.evolutionKindsCases", + "CoreReader.Engineering.evolutionDimensionsLimits", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T29, T30, T38. The enumerated constructors illustrate source dimensions and allow an other direction; they do not claim every possible evolution is represented or cheap. These counterexamples reject unjustified cross-dimension inference without adding a duty that every change be inexpensive. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "software-engineering.evolution-meaning.p2", + "unit": "software-engineering.evolution-meaning", + "clause": "p2", + "excerpt": "An evolution claim identifies the relevant changes and the maintainers' conditions. Independent changes, coordinated changes, preservation of existing obligations, and deliberate revision of those obligations can require different structures. A design's advantage on one dimension does not establish an advantage on every dimension.", + "declarations": [ + "CoreReader.Engineering.EvolutionClaim", + "CoreReader.Engineering.evolutionKindsCases", + "CoreReader.Engineering.evolutionDimensionsLimits", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T29, T30, T38. The enumerated constructors illustrate source dimensions and allow an other direction; they do not claim every possible evolution is represented or cheap. These counterexamples reject unjustified cross-dimension inference without adding a duty that every change be inexpensive. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "software-engineering.structural-judgment.p1", + "unit": "software-engineering.structural-judgment", + "clause": "p1", + "excerpt": "Apply the preceding commitment to engineering consequences as a whole, including the relations among components, their observable contracts, and the work needed to understand and verify a change. An interface's shape, the number of modules or extension points, or the use of a named principle is not sufficient evidence of the claimed capability.", + "declarations": [ + "CoreReader.Engineering.StructuralAccount", + "CoreReader.Engineering.structuralCases", + "CoreReader.Engineering.structureNotCapability", + "CoreReader.Engineering.priorityRemainsReflexive", + "CoreReader.Engineering.priorityReflexiveCases", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T31, T32, T37, T38. These are relevant finite inquiries, not a mandatory universal checklist or a real-world estimate of all boundary costs. The equal-work case preserves step units through an actual path transformation; these units are a disclosed model measure, not observed engineering effort. Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "software-engineering.structural-judgment.p2", + "unit": "software-engineering.structural-judgment", + "clause": "p2", + "excerpt": "The relevant comparison may examine how a change propagates, which knowledge and obligations cross a boundary, which assumptions become fixed, and what a later withdrawal would require. A proposed boundary needs support for the changes it is meant to accommodate; introducing it does not by itself show that those changes became easier.", + "declarations": [ + "CoreReader.Engineering.StructuralAccount", + "CoreReader.Engineering.structuralCases", + "CoreReader.Engineering.structureNotCapability", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T31, T32, T38. These are relevant finite inquiries, not a mandatory universal checklist or a real-world estimate of all boundary costs. The equal-work case preserves step units through an actual path transformation; these units are a disclosed model measure, not observed engineering effort. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "software-engineering.structural-judgment.p3", + "unit": "software-engineering.structural-judgment", + "clause": "p3", + "excerpt": "Distinguish a transformation that preserves an identified observable contract from one that deliberately revises that contract. The latter needs a corresponding account of changed obligations and affected parties. This distinction does not require preserving every historical behavior or using a particular testing or migration procedure.", + "declarations": [ + "CoreReader.Engineering.ContractChangeAccount", + "CoreReader.Engineering.contractCases", + "CoreReader.Engineering.contractPreservation", + "CoreReader.Engineering.contractDistinctions", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T33, T34, T38. The model does not require retaining every historical behavior, a particular test procedure, or an added universal notification obligation. A passing finite test suite is not a universal equality proof; preservation always retains its identified scope. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "software-engineering.revision.p1", + "unit": "software-engineering.revision", + "clause": "p1", + "excerpt": "Changed evidence about likely changes, maintenance conditions, costs, or objectives may justify revising a design or this priority's application. A revised judgment acknowledges material changes in its grounds; it does not make a failed prediction successful retrospectively.", + "declarations": [ + "CoreReader.Engineering.RevisionAccount", + "CoreReader.Engineering.revisionCases", + "CoreReader.Engineering.revisionLimits", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T35, T36, T38. The recorded history is fixed model evidence; the theorem does not authenticate arbitrary real-world logs or prove every criticism response adequate. The result permits bounded retention, not permanent immunity from later grounds or criticism. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "software-engineering.revision.p2", + "unit": "software-engineering.revision", + "clause": "p2", + "excerpt": "Retaining a design can be justified when the relevant alternatives have no supported contribution or impose costs that defeat the objective. Reflexivity also keeps this engineering commitment and the methods used to assess evolution within the scope of criticism and revision. Continued change, agreement, or successful examples do not establish its universal correctness.", + "declarations": [ + "CoreReader.Engineering.RevisionAccount", + "CoreReader.Engineering.revisionCases", + "CoreReader.Engineering.revisionLimits", + "CoreReader.Engineering.priorityRemainsReflexive", + "CoreReader.Engineering.priorityReflexiveCases", + "CoreReader.Engineering.jointWitness" + ], + "kernel": "passed", + "fidelity": "partial", + "status": "limited", + "reason": "Bounded source correspondence to T35, T36, T37, T38. The recorded history is fixed model evidence; the theorem does not authenticate arbitrary real-world logs or prove every criticism response adequate. The result permits bounded retention, not permanent immunity from later grounds or criticism. Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + } + ] +} diff --git a/SoftwareEngineering/lean/philosophy/overview.md b/SoftwareEngineering/lean/philosophy/overview.md new file mode 100644 index 0000000..1f5d759 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/overview.md @@ -0,0 +1,1622 @@ +# Software Engineering Philosophy and Lean: claim overview + +This reader follows 40 frozen targets. Target acceptance, Lean checking and source fidelity are separate judgments. Defining a duty does not establish its fulfillment; a finite model does not establish universal real-world correctness. The tracing appendix retains all 47 source paragraphs and two empty headings. + +The adopted baseline is SoftwareEngineering 0.2.1, inheriting Core 0.1.2. Current Core tools provide only the checking runtime. + +`accepted` records acceptance of a target within its stated scope; `limited` retains a bounded formal correspondence for a source paragraph; `incomplete` retains material without a complete source proof. Lean `passed` reports checking of registered declarations; checking a normative interface is not fulfillment of its duty. + +[Other granularity](details.md) · [Frozen targets](targets.json) · [Review and exposure record](reviews/README.md) · [Actual declaration types](evidence/declaration-types.json) + +| Target | Claim | Kind | Target review | +| --- | --- | --- | --- | +| [T01](#t01) | Authority and the adopted baseline | boundary | accepted | +| [T02](#t02) | Valued expansion and revisable forms | specification | accepted | +| [T03](#t03) | Orientation is not achievement | nonentailment | accepted | +| [T04](#t04) | Consistency of the whole held theory | specification | accepted | +| [T05](#t05) | Contradiction and explicit revision | theorem | accepted | +| [T06](#t06) | Consistency, truth and support differ | nonentailment | accepted | +| [T07](#t07) | Applicable self-application | specification | accepted | +| [T08](#t08) | Self-application supplies no self-proof | nonentailment | accepted | +| [T09](#t09) | Grounds for the original assessment task | specification | accepted | +| [T10](#t10) | Empirical support and uncertainty | specification | accepted | +| [T11](#t11) | Inference and negative examination | specification | accepted | +| [T12](#t12) | Value positions and reasons | specification | accepted | +| [T13](#t13) | Articulation and proportionality limits | nonentailment | accepted | +| [T14](#t14) | Relations, comparison scope and method roles | specification | accepted | +| [T15](#t15) | Local evidence does not erase differences | nonentailment | accepted | +| [T16](#t16) | Application-specific capability and understanding | specification | accepted | +| [T17](#t17) | Output evidence does not imply introspection | nonentailment | accepted | +| [T18](#t18) | Grounded implementation choice | specification | accepted | +| [T19](#t19) | Openness and the additional choice commitment | nonentailment | accepted | +| [T20](#t20) | Mutual application in one engineering system | theorem | accepted | +| [T21](#t21) | Existing forms and assessment | boundary | accepted | +| [T22](#t22) | The continuing engineering activity | specification | accepted | +| [T23](#t23) | Private editability and shared capability | nonentailment | accepted | +| [T24](#t24) | Conditions of evolution priority | specification | accepted | +| [T25](#t25) | The applicable priority theorem | theorem | accepted | +| [T26](#t26) | Grounded credible directions | specification | accepted | +| [T27](#t27) | Credibility is not unlimited accommodation | nonentailment | accepted | +| [T28](#t28) | Concrete costs and justified departure | specification | accepted | +| [T29](#t29) | Kinds of evolution and changed obligations | specification | accepted | +| [T30](#t30) | One evolution advantage is not every advantage | nonentailment | accepted | +| [T31](#t31) | Structural consequences and crossing obligations | specification | accepted | +| [T32](#t32) | Structure names do not prove capability | nonentailment | accepted | +| [T33](#t33) | Preservation versus deliberate contract revision | specification | accepted | +| [T34](#t34) | The contract-preservation theorem | theorem | accepted | +| [T35](#t35) | Revision and preserved historical evidence | specification | accepted | +| [T36](#t36) | Revision cannot rewrite failure | nonentailment | accepted | +| [T37](#t37) | The priority remains open to its own assessment | theorem | accepted | +| [T38](#t38) | One joint witness for all represented duties | satisfiability | accepted | +| [T39](#t39) | Inherited duties do not force the added priority | nonentailment | accepted | +| [T40](#t40) | What the formal evidence cannot establish | boundary | accepted | + + +## T01 · Authority and the adopted baseline + +SoftwareEngineering 0.2.1 adopts the inherited Core 0.1.2 text and an additional engineering priority. This edition does not advance the adopted Core 0.1.2 checkpoint. + +**Premises and representation:** The complete quoted provisions, meanings and application limits are authoritative. Rationale and cases supply interpretation; the current Core checker is a separate runtime dependency. + +**Proof or check:** Source bytes, metadata and paragraph excerpts are frozen and traced. No Lean theorem is assigned to documentary authority. + +**Limits:** Neither the chapter order nor a successful checker establishes deductive hierarchy, universal philosophical correctness or adoption by every system. + +**State:** accepted (boundary). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.preamble#p1](#source-organon-preamble-p1), [organon.preamble#p2](#source-organon-preamble-p2), [organon.charter.overview#p1](#source-organon-charter-overview-p1), [organon.charter.overview#p2](#source-organon-charter-overview-p2), [organon.charter.overview#p3](#source-organon-charter-overview-p3), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [extensions#p1](#source-extensions-p1) + +[Declarations, proof and line explanations](details.md#t01) + + + +## T02 · Valued expansion and revisable forms + +generationSpecification requires valuing expansion and keeping every current organization, method and principle form revisable. A justified stable action can satisfy this orientation. + +**Premises and representation:** Policy supplies the value position, current forms and revisability relation. The concrete policy has current forms; the requirement is not discharged by an empty inventory. + +**Proof or check:** The positive case constructs valuation and revisability. A neutral policy permits version changes but fails valuation; stable and collaborative examples check actual state transitions and resources. + +**Limits:** The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.charter.overview#p2](#source-organon-charter-overview-p2), [organon.charter.overview#p3](#source-organon-charter-overview-p3), [organon.charter.self-transcendence#p1](#source-organon-charter-self-transcendence-p1), [organon.charter.self-transcendence.orientation#p1](#source-organon-charter-self-transcendence-orientation-p1), [organon.charter.self-transcendence.non-finality#p1](#source-organon-charter-self-transcendence-non-finality-p1), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.relationships.terms#p1](#source-organon-relationships-terms-p1) + +[Declarations, proof and line explanations](details.md#t02) + + + +## T03 · Orientation is not achievement + +Permission, valuation, revisability and increased inventories do not by themselves establish expanded capability or actual execution. + +**Premises and representation:** States contain actual available operations; resource removal changes execution. Achievement evidence fixes the same transition, operation, input and output claim. + +**Proof or check:** The inflated state adds counts without a successor operation. The collaborative case gains that operation only with the relevant resource. A performance record supports the identified achievement, while an announcement admits a counterworld. + +**Limits:** These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.charter.self-transcendence.orientation#p1](#source-organon-charter-self-transcendence-orientation-p1), [organon.charter.self-transcendence.non-finality#p1](#source-organon-charter-self-transcendence-non-finality-p1), [organon.charter.self-transcendence.limits#p1](#source-organon-charter-self-transcendence-limits-p1), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2) + +[Declarations, proof and line explanations](details.md#t03) + + + +## T04 · Consistency of the whole held theory + +Consistency constrains joint consequences of all held claims under one set of assumptions, meanings and scope. Truthful revision reporting is a separate condition. + +**Premises and representation:** A Theory selects proposition-valued claims; Context fixes assumptions, question meanings and scope. Both positive and negative consequences quantify over the same admissible worlds. + +**Proof or check:** The cases exhibit a contradiction produced only by the union, genuine changes of context, separately consistent time slices, and truthful Boolean change reports. + +**Limits:** A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.charter.consistency#p1](#source-organon-charter-consistency-p1), [organon.charter.consistency.meaning#p1](#source-organon-charter-consistency-meaning-p1), [organon.charter.consistency.meaning#p2](#source-organon-charter-consistency-meaning-p2), [organon.charter.consistency.limits#p1](#source-organon-charter-consistency-limits-p1) + +[Declarations, proof and line explanations](details.md#t04) + + + +## T05 · Contradiction and explicit revision + +Opposite consequences on the same question violate consistency. Withdrawing an earlier judgment can leave each revised time slice consistent. + +**Premises and representation:** The conditional theorem receives both signed consequences and their common context. It does not derive either premise. + +**Proof or check:** consistencyConsequences applies conflictRequiresChange. The slice examples construct a model at each time and derive conflict for the union. Reordering a union preserves its selected claims. + +**Limits:** The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. + +**State:** accepted (theorem). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.charter.consistency#p1](#source-organon-charter-consistency-p1), [organon.charter.consistency.meaning#p1](#source-organon-charter-consistency-meaning-p1), [organon.charter.consistency.meaning#p2](#source-organon-charter-consistency-meaning-p2), [organon.charter.consistency.limits#p1](#source-organon-charter-consistency-limits-p1) + +[Declarations, proof and line explanations](details.md#t05) + + + +## T06 · Consistency, truth and support differ + +Different conditions and compatible value tensions need not conflict. A consistent set can still be false at a particular world or fail to entail a conclusion. + +**Premises and representation:** The examples use explicit Boolean worlds, scoped contexts and simultaneous inequalities rather than a free correctness flag. + +**Proof or check:** A witness proves consistency; an outside countervaluation falsifies the claim or refutes the alleged entailment. Changing assumptions or scope changes the comparison object explicitly. + +**Limits:** Consistency is not sufficient empirical or value support; the counterexamples concern the disclosed mathematical representation. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.charter.consistency.meaning#p2](#source-organon-charter-consistency-meaning-p2), [organon.charter.consistency.limits#p1](#source-organon-charter-consistency-limits-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2) + +[Declarations, proof and line explanations](details.md#t06) + + + +## T07 · Applicable self-application + +Relevant generation and assessment rules apply to the system and to principle formation, application and revision. Self-status supplies no exemption. + +**Premises and representation:** Each rule has an owner/key, applicability condition, actual input and outcome meaning. Matching keys must identify the same rule. + +**Proof or check:** Concrete records discharge applicable self targets. An application-only rule supplies an explicit inapplicable system case. Grounds-on-Grounds uses a real unsupported-scope counterworld and stated value rationale. + +**Limits:** Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.charter.reflexivity#p1](#source-organon-charter-reflexivity-p1), [organon.charter.reflexivity.meaning#p1](#source-organon-charter-reflexivity-meaning-p1), [organon.charter.reflexivity.limits#p1](#source-organon-charter-reflexivity-limits-p1), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3) + +[Declarations, proof and line explanations](details.md#t07) + + + +## T08 · Self-application supplies no self-proof + +A self-assessed or self-generated proposal may lack support. In one shared finite context, the complete represented Charter holds while a concrete general Grounds task fails. + +**Premises and representation:** CompleteCharter012 includes valuation, revisability, whole-set consistency, truthful reporting and actual applicable self-work for the same system. + +**Proof or check:** charterWithoutGrounds012 constructs that Charter witness. The budget observation admits a world that fails the claimed output capability, so it cannot discharge the identified capability facet. + +**Limits:** This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.charter.reflexivity.limits#p1](#source-organon-charter-reflexivity-limits-p1), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.grounds#p1](#source-organon-grounds-p1) + +[Declarations, proof and line explanations](details.md#t08) + + + +## T09 · Grounds for the original assessment task + +Grounds012 requires a nonempty set of articulated, discharged facets appropriate to the original claim task. Clear articulation alone is insufficient. + +**Premises and representation:** AssessmentTask fixes original observations/scope/claim/uncertainty, original inference premises, or the actual value position. NatureAppropriate compares contents, not type labels alone. + +**Proof or check:** Input-zero evidence supports input zero but admits a failing input-one counterworld. Replacing the original empirical task by a new premise that assumes its conclusion is rejected; the legitimate inference adapter retains the original observation/scope premises and uncertainty. + +**Limits:** This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.grounds#p1](#source-organon-grounds-p1), [organon.grounds.assessment#p1](#source-organon-grounds-assessment-p1), [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3) + +[Declarations, proof and line explanations](details.md#t09) + + + +## T10 · Empirical support and uncertainty + +The empirical adapter checks compatible observations, an inhabited application scope, support for the stated claim and its stated uncertainty. + +**Premises and representation:** Records are mathematical observation functions and recorded values. Their relation to real measurements requires an external interpretation. + +**Proof or check:** A relevant input-zero record supports a local claim. Repeated irrelevant observations do not support another object; two compatible worlds retain different unobserved outcomes in the uncertainty case. + +**Limits:** Repeatability or measurability alone does not establish relevance, correctness or value; varying unobserved outcomes need not contradict limited support. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2) + +[Declarations, proof and line explanations](details.md#t10) + + + +## T11 · Inference and negative examination + +Inferential support requires entailment from satisfiable stated assumptions. A correctly completed examination may instead reject a conclusion. + +**Premises and representation:** Entails quantifies over all models of the supplied theory. InferenceExamined records whether acceptance matches actual entailment. + +**Proof or check:** The arithmetic case derives n + 1 = 3 from n = 2. The Boolean counterworld satisfies the same empty theory but falsifies the conclusion, validating a negative examination. + +**Limits:** Failure of support is not failure to assess correctly; consistency with assumptions is weaker than entailment. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2) + +[Declarations, proof and line explanations](details.md#t11) + + + +## T12 · Value positions and reasons + +A value position states adoption, reasons, limits, consequences and responses to relevant criticism. Initial adoption is not inferred from observation alone. + +**Premises and representation:** ValueProcedure uses supplied objectives and constraints, a joint adoption/reasons witness, conditional adequacy, and a response where criticism applies. + +**Proof or check:** The switch example has real budget/benefit consequences. Removing the relevant response fails the procedure; a neutral observation does not force adoption. + +**Limits:** The application supplies a sufficient value assessment, not a universal requirement to prove every starting assumption or a proof that one value is universally best. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3) + +[Declarations, proof and line explanations](details.md#t12) + + + +## T13 · Articulation and proportionality limits + +Clear reasons can be false or irrelevant. Qualitative implication can compare claim strength without a common numerical scale. + +**Premises and representation:** The examples fix actual counterworlds, neutral records and explicit starting value assumptions. + +**Proof or check:** A false-world witness rejects the clear factual argument. allTrue entails truth at input zero, while the converse fails at input one. Neither neutral evidence nor an empty theory entails the value commitment. + +**Limits:** These distinctions do not require values, empirical evidence and inference to be reduced to one score. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.grounds.assessment#p1](#source-organon-grounds-assessment-p1), [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3) + +[Declarations, proof and line explanations](details.md#t13) + + + +## T14 · Relations, comparison scope and method roles + +Compared objects must lie in the stated conditions and observation scope, and satisfy the stated relevance relation. Each used assessment method needs a claim-specific role. + +**Premises and representation:** ScopeAccount supplies compared/relevant relations and an explains predicate. The concrete account additionally binds exact claim, conditions, role text and support facts. + +**Proof or check:** The local account restricts both inputs to zero. Measurement and repetition support that local output; the framework role explicitly retains the failed universal extrapolation. + +**Limits:** A nonempty role string alone is not sufficient interpretation, and an unused method does not become compulsory. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.grounds.scope#p1](#source-organon-grounds-scope-p1), [organon.grounds.scope#p2](#source-organon-grounds-scope-p2), [organon.grounds.scope#p3](#source-organon-grounds-scope-p3) + +[Declarations, proof and line explanations](details.md#t14) + + + +## T15 · Local evidence does not erase differences + +Equal local behavior can coexist with a relevant difference elsewhere. Limited observations can support a limited claim without a universal methodological chain. + +**Premises and representation:** Claims and observation scopes remain explicit. Random-output examples distinguish event observation, reproducible conditions and stability of a bounded conclusion. + +**Proof or check:** Concrete functions agree at zero and differ at one; one observation supports only its local claim. A mathematical inference and a value procedure provide examples using no obligatory observation chain. + +**Limits:** Omitting an input from comparison is not evidence that no relevant difference exists there. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.grounds.scope#p1](#source-organon-grounds-scope-p1), [organon.grounds.scope#p2](#source-organon-grounds-scope-p2), [organon.grounds.scope#p3](#source-organon-grounds-scope-p3), [organon.grounds.implementations.limits#p1](#source-organon-grounds-implementations-limits-p1) + +[Declarations, proof and line explanations](details.md#t15) + + + +## T16 · Application-specific capability and understanding + +Capability claims retain their actual object, contract and grounds. An application may require more than reliable output or an output-equivalent explanation. + +**Premises and representation:** The output contract ranges over all natural inputs. A separate mechanism application defines operational understanding as explaining the same process and answering every input/multiplier variation; this is its selected criterion. + +**Proof or check:** ExternalCertificate checks output without introspection. Two mechanism objects share the same explainedProcess; the fixed-double responder fails at (3,1), while the mechanism responder proves the stronger contract and same-object Grounds012. The failing object also fails those same grounds. + +**Limits:** This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3) + +[Declarations, proof and line explanations](details.md#t16) + + + +## T17 · Output evidence does not imply introspection + +Reliable output, external articulation and increased inventory do not automatically establish process explanation or stronger capability. + +**Premises and representation:** The opaque process actually returns no explanatory certificate, while its output proof still covers all natural inputs. + +**Proof or check:** The proof combines correct output with absence of explanation. Duplicating copy artifacts across inventory kinds never supplies a successor operation; resource and inflated-state cases preserve that distinction. + +**Limits:** An external assessor can ground the selected output claim without establishing how the assessed system understands its generation process. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2) + +[Declarations, proof and line explanations](details.md#t17) + + + +## T18 · Grounded implementation choice + +Implementation priority requires reasons linked to objectives and constraints. Convention may contribute practically, but status alone is insufficient. + +**Premises and representation:** JustifiedChoice includes actual requirement satisfaction and at least one relevant method reason. Explanation, applicability, simplicity and process can be relevant within the chosen requirements. + +**Proof or check:** The conventional identity implementation satisfies its contract and budget. A cheap successor fails the required output despite its cost advantage; a status-only choice fails the reason condition. + +**Limits:** These are application reasons, not a universal cost function or a rule that conventional implementations must lose. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.grounds.implementations#p1](#source-organon-grounds-implementations-p1), [organon.grounds.implementations#p2](#source-organon-grounds-implementations-p2), [organon.grounds.implementations.limits#p1](#source-organon-grounds-implementations-limits-p1), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3) + +[Declarations, proof and line explanations](details.md#t18) + + + +## T19 · Openness and the additional choice commitment + +Openness allows distinct alternatives and can coexist with only one feasible conventional option. The added choice rule is not obtained merely by completing a general assessment. + +**Premises and representation:** The limited general-assessment model and the stronger engineering non-entailment in T39 are different objects and results. + +**Proof or check:** Concrete requirement scopes distinguish alternatives that agree locally. The general-assessment case retains its stated assessment while the status-only priority lacks a relevant reason. + +**Limits:** No result asserts all implementations equivalent, multiple feasible implementations guaranteed, or the choice commitment derivable from chapter placement. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.grounds.implementations#p1](#source-organon-grounds-implementations-p1), [organon.grounds.implementations#p2](#source-organon-grounds-implementations-p2), [organon.grounds.implementations.limits#p1](#source-organon-grounds-implementations-limits-p1) + +[Declarations, proof and line explanations](details.md#t19) + + + +## T20 · Mutual application in one engineering system + +The inherited duties apply to this system’s own principles, methods, value positions, capability reports and implementation choice. Actual normative contents enter its whole consistency theory. + +**Premises and representation:** Inherited fixes sharedContext and carries fulfilled generation, reflection, original empirical/inferential/value tasks, scope, capability and choice. ownTheory joins actual facts with every applicable OwnNorm content; consistency constrains this whole union. + +**Proof or check:** inheritedMutualApplication projects these actual fields and the full-content/support bridges; inheritedCurrent constructs them separately. Both actual reflection rules are self objects, and the evaluator’s revision test reports its local empty-sample defect. + +**Limits:** Projection does not derive all duties from one principle. Adoption markers are separate facts; they do not substitute for normative content. The sample-aware criticism is an application criterion, not a universal requirement for observations. + +**State:** accepted (theorem). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3) + +[Declarations, proof and line explanations](details.md#t20) + + + +## T21 · Existing forms and assessment + +Existing forms include organization, methods and principles. Assessment includes examination of reasons and applicability, not only executable tests. + +**Premises and representation:** These terms constrain interpretation throughout the source and the other targets. + +**Proof or check:** The source tracing preserves the exact terms. Form kinds and both inferential/value examples illustrate their use without assigning a new theorem to the glossary. + +**Limits:** The finite test machinery used here does not redefine all assessment as testing. + +**State:** accepted (boundary). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.relationships.terms#p1](#source-organon-relationships-terms-p1) + +[Declarations, proof and line explanations](details.md#t21) + + + +## T22 · The continuing engineering activity + +The subject is an activity involving maintainers, software, tools and accessible knowledge across its actual lifecycle. A temporary label does not establish a bounded lifecycle. + +**Premises and representation:** ActivityScope requires nonempty participants, software and tools, with knowledge for the participants. Continuing and BoundedLifecycle inspect releases, maintenance and bounded runs. + +**Proof or check:** The continuing example has three releases and six maintenance periods despite its label. Separate temporary, prototype and retiring activities have genuinely bounded execution and no scheduled continuation. + +**Limits:** These numerical schedules are finite model data, not project time estimates. Scope alone does not prove every participant can perform every change. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.purpose#p1](#source-software-engineering-purpose-p1), [software-engineering.purpose#p2](#source-software-engineering-purpose-p2), [software-engineering.purpose#p3](#source-software-engineering-purpose-p3) + +[Declarations, proof and line explanations](details.md#t22) + + + +## T23 · Private editability and shared capability + +The original author’s ability to edit does not establish successor or agent capability. A passive artifact does not itself inherit the activity’s intentions. + +**Premises and representation:** CanChange checks a nonempty actual edit/verification path, participant identity, tools and the knowledge required by every step. + +**Proof or check:** The simple design requires privateLayout. The original author has it; successor and agent do not. The documented path uses their available public knowledge and tools. Artifact execution remains distinct from maintainer proposals. + +**Limits:** The result concerns the represented paths; lack of one documented path is not a universal impossibility theorem about all maintenance. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.purpose#p1](#source-software-engineering-purpose-p1), [software-engineering.purpose#p2](#source-software-engineering-purpose-p2), [software-engineering.purpose#p3](#source-software-engineering-purpose-p3) + +[Declarations, proof and line explanations](details.md#t23) + + + +## T24 · Conditions of evolution priority + +EvolutionPriority is a conditional adopted preference: when all PriorityConditions hold, choose evolvable or supply a justified departure. + +**Premises and representation:** Conditions require ongoing releases and maintenance; nonempty participants, software identity and tools; some available knowledge for every participant; both candidates meeting behavior/safety/latency/retention requirements; credible design revision; and a nonempty evolvable revision path whose required knowledge and tools are available to every listed participant. That path must have lower work than the simple option, while the evolvable option has greater present complexity. + +**Proof or check:** Each necessary-requirement failure blocks applicability. The ordinary context has work 6 versus 17 and complexity 3 versus 1. A concrete cost threat can justify departure; an unexplained excuse cannot. The maximal candidate adds a real CSV path but exceeds the budget. + +**Limits:** This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.purpose#p3](#source-software-engineering-purpose-p3), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3) + +[Declarations, proof and line explanations](details.md#t24) + + + +## T25 · The applicable priority theorem + +With the adopted priority rule, all applicability conditions and no justified departure, the choice must be evolvable and accept its greater present complexity. + +**Premises and representation:** priorityWhenApplicable receives EvolutionPriority, PriorityConditions and the absence of JustifiedDeparture. These are premises of the theorem. + +**Proof or check:** Apply the rule to the supplied conditions, eliminate the departure branch, and project the strict complexity comparison. Concrete cases check the evolvable selection, the violating simple selection and a threat-supported departure. + +**Limits:** The theorem neither proves the value rule from facts nor establishes that every apparently complex design has the relevant advantage. + +**State:** accepted (theorem). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3) + +[Declarations, proof and line explanations](details.md#t25) + + + +## T26 · Grounded credible directions + +Credible directions have articulated supporting grounds. An existing plurality of implementations is unnecessary, while mere imagination is insufficient. + +**Premises and representation:** The adapter examines plan, domain-knowledge and history contents, with an additional extensible evidence form. These are application constructors, not an exhaustive philosophical checklist. + +**Proof or check:** The registered plan identifies release 2 and design revision. Knowledge/history cases check their concrete relevance. An imagined-only entry fails, and changed evidence can produce a changed forecast. + +**Limits:** The proof checks stipulated evidence contents, not the real-world credibility or predictive calibration of arbitrary plans. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3) + +[Declarations, proof and line explanations](details.md#t26) + + + +## T27 · Credibility is not unlimited accommodation + +Credible change can warrant selective accommodation without multiple current implementations or maximal expansion. Conceivability alone supplies no such support. + +**Premises and representation:** The case retains one existing implementation, a supported particular direction and explicit cost dimensions. + +**Proof or check:** The credible plan case remains valid with one implementation. Imagined evidence fails support. The actual selective design and separate cost coordinates avoid requiring every possibility or a common exchange rate. + +**Limits:** No finite list of directions proves all future changes predictable or all omitted possibilities irrelevant. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3) + +[Declarations, proof and line explanations](details.md#t27) + + + +## T28 · Concrete costs and justified departure + +Departure identifies which concrete objective is threatened by added cost. The model admits seven distinct burdens without summing them into one universal score. + +**Premises and representation:** ConcreteThreat connects actual candidate cost, the simpler comparison cost and the capacity of the named burden. JustifiedDeparture binds the recorded burden and objective to that threat. + +**Proof or check:** Separate cases lower the relevant capacity for understanding, construction, diagnosis, verification, coordination, operation and migration. An arbitrary recorded excuse with no actual threatened capacity fails. + +**Limits:** The finite costs are modeled work/budget data. The source does not require every category to apply or provide a universal numerical tradeoff. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3) + +[Declarations, proof and line explanations](details.md#t28) + + + +## T29 · Kinds of evolution and changed obligations + +Evolution includes adding, replacing, deleting, withdrawing abstractions, redrawing boundaries and migrating, with distinct independent/coordinated paths and contract treatment. + +**Premises and representation:** EvolutionClaim connects the identified request and maintainer capability to the corresponding contract account, an actual contractRunner step, and preserve/revise treatment of the specified observation. SoftwareState transformations are separate conjuncts of evolutionKindsCases, not fields of this predicate. + +**Proof or check:** The cases compute addition, replacement, deletion, withdrawal, boundary and migration state changes as separate conjuncts. They also verify successor paths, preservation for the replacement request, explicit contract revision for redrawing, and different independent/coordinated work. The revision account concerns the changed observable behavior; the state-transform conjuncts are separately checked. + +**Limits:** The enumerated constructors illustrate source dimensions and allow an other direction; they do not claim every possible evolution is represented or cheap. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.evolution-meaning#p1](#source-software-engineering-evolution-meaning-p1), [software-engineering.evolution-meaning#p2](#source-software-engineering-evolution-meaning-p2) + +[Declarations, proof and line explanations](details.md#t29) + + + +## T30 · One evolution advantage is not every advantage + +Easy additions within a scheme do not imply easy exit from it, and an advantage in design revision does not imply a strict advantage in every dimension. + +**Premises and representation:** Work is computed from the actual edit/verification paths for the same designs and change kinds. + +**Proof or check:** The simple design has a short addition path and a 17-unit withdrawal path. The evolvable design improves design revision from 17 to 6, while addition remains 2 for both; coordinated work can exceed independent work. + +**Limits:** These counterexamples reject unjustified cross-dimension inference without adding a duty that every change be inexpensive. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.evolution-meaning#p1](#source-software-engineering-evolution-meaning-p1), [software-engineering.evolution-meaning#p2](#source-software-engineering-evolution-meaning-p2) + +[Declarations, proof and line explanations](details.md#t30) + + + +## T31 · Structural consequences and crossing obligations + +Structural assessment connects intended changes to propagation, actual observable contracts, knowledge and verification work. A boundary label alone cannot establish the crossing obligation is handled. + +**Premises and representation:** StructuralAccount binds recorded touched components, observations and work to actual paths. The boundary case has caller 2, callee 1 and an explicit order-preserving obligation. + +**Proof or check:** The coordinated change edits callee 1 and checks the contract at caller 2. Deleting that caller check keeps the crossing but fails boundaryObligationChecked; moving the callee to untouched 7 changes applicability; sorting the output fails the same observable contract. + +**Limits:** These are relevant finite inquiries, not a mandatory universal checklist or a real-world estimate of all boundary costs. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2) + +[Declarations, proof and line explanations](details.md#t31) + + + +## T32 · Structure names do not prove capability + +The same signature, module count or named principle can hide different behavior or change capability. Introducing a real boundary need not reduce change work. + +**Premises and representation:** EngineeringDesign contains actual behavior, component paths, boundaries and fixed batch assumptions; metadata is kept separate. + +**Proof or check:** Same signatures produce ordered versus sorted output. Eight modules all require the size change. Private and documented paths share metadata but differ for the successor. A new boundary relocates existing verification steps, retaining work 17 and missing private knowledge; a separate added-check variant costs 18. + +**Limits:** The equal-work case preserves step units through an actual path transformation; these units are a disclosed model measure, not observed engineering effort. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2) + +[Declarations, proof and line explanations](details.md#t32) + + + +## T33 · Preservation versus deliberate contract revision + +An identified contract can be preserved or deliberately revised. Revision accounts identify changed obligations and affected parties instead of silently relabeling changed behavior as preservation. + +**Premises and representation:** ObservableContract includes order behavior and retry limits. Actual party dependencies determine which consumers/operators are affected; a report cannot define them away. + +**Proof or check:** Order-preserving refactoring passes. Sorted order and changed retry limits need a revision account. Omitting the actual operator fails; a behavior retired outside the selected finite suite demonstrates that local preservation is limited. + +**Limits:** The model does not require retaining every historical behavior, a particular test procedure, or an added universal notification obligation. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3) + +[Declarations, proof and line explanations](details.md#t33) + + + +## T34 · The contract-preservation theorem + +If all identified in-scope observations are equal, the identified contract is preserved. A changed in-scope observation refutes preservation of that same contract. + +**Premises and representation:** contractPreservation receives a universal in-scope equality. The finite order/retry examples are separate checks and do not supply that universal premise automatically. + +**Proof or check:** The theorem returns the supplied equality as PreservesOn. changedObservationNotPreserved applies it to a differing input. The examples compute order changes, retry at 3, affected parties and a difference at the excluded input [99]. + +**Limits:** A passing finite test suite is not a universal equality proof; preservation always retains its identified scope. + +**State:** accepted (theorem). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3) + +[Declarations, proof and line explanations](details.md#t34) + + + +## T35 · Revision and preserved historical evidence + +Changed forecasts, maintainers, costs or objectives can justify changed judgments. A new record must retain the earlier prediction and its observed failure. + +**Premises and representation:** RevisionAccount compares the revision with independently fixed observedHistory, including software identity, old prediction and actual observed result. revisionFor uses the current context and selected candidate. MaterialGroundsChanged is a disjunction of five recorded differences; it does not prove that each difference alone adequately justifies the new choice. + +**Proof or check:** The same old/new state pair changes forecast, maintenance, maintainers, migration cost and objective capacity together; the theorem lists all five differences. Tampering with both old and recordedOld cannot change the independent history. Separate retention cases use an unsupported alternative or a justified migration-cost departure. + +**Limits:** The recorded history is fixed model evidence; the theorem does not authenticate arbitrary real-world logs or prove every criticism response adequate. + +**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.revision#p2](#source-software-engineering-revision-p2), [software-engineering.revision#p1](#source-software-engineering-revision-p1) + +[Declarations, proof and line explanations](details.md#t35) + + + +## T36 · Revision cannot rewrite failure + +A new judgment cannot make the old failed forecast true. Agreement and local success do not establish universal correctness; justified stability remains possible. + +**Premises and representation:** The old static prediction and changed live batch result remain fixed independently of the revision report. + +**Proof or check:** The 21-item case agrees at size 10 but differs at size 5. Relabeling cannot repair that arithmetic. The stable record retains a valid historical account and criticism-direction coverage while leaving the choice unchanged; the named unsupported alternative satisfies the bounded retention criterion. This case does not prove the design’s actual revisability. + +**Limits:** The result permits bounded retention, not permanent immunity from later grounds or criticism. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [software-engineering.revision#p2](#source-software-engineering-revision-p2), [software-engineering.revision#p1](#source-software-engineering-revision-p1) + +[Declarations, proof and line explanations](details.md#t36) + + + +## T37 · The priority remains open to its own assessment + +For the same adopter and applicable context, the priority and actual assessment methods remain under Grounds, whole-theory consistency and reflexive scrutiny. + +**Premises and representation:** The theorem retains full Inherited and DomainSatisfied premises, PriorityConditions and no justified departure. It identifies the actual priority object and connects the evolution value commitment to EvolutionPriority by equality of their meanings in sharedContext. + +**Proof or check:** Eliminate the departure branch, retain reflection, and supply priorityGrounds plus the domain content’s membership in the whole consistent theory. The own forecast and evaluator revision cases retain their actual counterexamples. + +**Limits:** Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. + +**State:** accepted (theorem). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.revision#p2](#source-software-engineering-revision-p2) + +[Declarations, proof and line explanations](details.md#t37) + + + +## T38 · One joint witness for all represented duties + +One nonempty continuing context and its evolvable selection satisfy the full represented inherited and domain bundles together, with genuine applicable priority and extra present complexity. + +**Premises and representation:** The witness fixes sharedContext, all original assessment tasks and values, the whole facts/norms theory, successor and agent paths, satisfied requirements, credible design revision and no concrete cost threat. + +**Proof or check:** inheritedCurrent constructs every inherited field for evolvable; currentDomainSatisfied supplies the domain bundle. Explicit values check complexity 3 versus 1 and work 6 versus 17, nonempty own objects and admissibility of that same chosen candidate. + +**Limits:** This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +**State:** accepted (satisfiability). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.charter.overview#p2](#source-organon-charter-overview-p2), [organon.charter.overview#p3](#source-organon-charter-overview-p3), [organon.charter.self-transcendence#p1](#source-organon-charter-self-transcendence-p1), [organon.charter.self-transcendence.orientation#p1](#source-organon-charter-self-transcendence-orientation-p1), [organon.charter.self-transcendence.non-finality#p1](#source-organon-charter-self-transcendence-non-finality-p1), [organon.charter.self-transcendence.limits#p1](#source-organon-charter-self-transcendence-limits-p1), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.charter.consistency#p1](#source-organon-charter-consistency-p1), [organon.charter.consistency.meaning#p1](#source-organon-charter-consistency-meaning-p1), [organon.charter.consistency.meaning#p2](#source-organon-charter-consistency-meaning-p2), [organon.charter.consistency.limits#p1](#source-organon-charter-consistency-limits-p1), [organon.charter.reflexivity#p1](#source-organon-charter-reflexivity-p1), [organon.charter.reflexivity.meaning#p1](#source-organon-charter-reflexivity-meaning-p1), [organon.charter.reflexivity.limits#p1](#source-organon-charter-reflexivity-limits-p1), [organon.grounds#p1](#source-organon-grounds-p1), [organon.grounds.assessment#p1](#source-organon-grounds-assessment-p1), [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3), [organon.grounds.scope#p1](#source-organon-grounds-scope-p1), [organon.grounds.scope#p2](#source-organon-grounds-scope-p2), [organon.grounds.scope#p3](#source-organon-grounds-scope-p3), [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2), [organon.grounds.implementations#p1](#source-organon-grounds-implementations-p1), [organon.grounds.implementations#p2](#source-organon-grounds-implementations-p2), [organon.grounds.implementations.limits#p1](#source-organon-grounds-implementations-limits-p1), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.purpose#p1](#source-software-engineering-purpose-p1), [software-engineering.purpose#p2](#source-software-engineering-purpose-p2), [software-engineering.purpose#p3](#source-software-engineering-purpose-p3), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3), [software-engineering.evolution-meaning#p1](#source-software-engineering-evolution-meaning-p1), [software-engineering.evolution-meaning#p2](#source-software-engineering-evolution-meaning-p2), [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2), [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3), [software-engineering.revision#p1](#source-software-engineering-revision-p1), [software-engineering.revision#p2](#source-software-engineering-revision-p2) + +[Declarations, proof and line explanations](details.md#t38) + + + +## T39 · Inherited duties do not force the added priority + +In that same applicable continuing context, a presentSimple selection satisfies every represented inherited duty but does not adopt the additional evolution priority. + +**Premises and representation:** Both options meet necessary requirements; the evolution advantage, credible design revision, successor/agent paths and complexity tradeoff are real within the model. There is no temporary-lifecycle or cost-departure escape. + +**Proof or check:** inheritedCurrent constructs the whole inherited bundle for presentSimple. Its actually adopted simplicity value has cost/work reasons and criticism limits. Applying the domain rule would require evolvable or a departure; both are excluded, so EvolutionPriority is false. + +**Limits:** The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance. + +**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3) + +[Declarations, proof and line explanations](details.md#t39) + + + +## T40 · What the formal evidence cannot establish + +Checked specifications, conditional proofs and concrete witnesses remain distinct from empirical adequacy, sufficient real-world grounds and philosophical adoption. + +**Premises and representation:** Source fidelity is a separately recorded, bounded judgment. Costs, plans, histories, operational understanding and finite contracts retain their disclosed application interpretations. + +**Proof or check:** The edition binds actual source/code/type/dependency objects, independent initial records and later repairs. Prior failed or incomplete objects are not relabeled as successful historical executions. + +**Limits:** Build success, source tracing, agent agreement and self-application do not prove philosophical correctness. No frozen provable target has been deleted or recast as a boundary to obtain completion. + +**State:** accepted (boundary). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs. + +**Sources:** [organon.preamble#p1](#source-organon-preamble-p1), [organon.preamble#p2](#source-organon-preamble-p2), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.grounds#p1](#source-organon-grounds-p1), [organon.grounds.assessment#p1](#source-organon-grounds-assessment-p1), [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3), [organon.grounds.scope#p2](#source-organon-grounds-scope-p2), [organon.grounds.scope#p3](#source-organon-grounds-scope-p3), [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2), [organon.grounds.implementations#p1](#source-organon-grounds-implementations-p1), [organon.grounds.implementations#p2](#source-organon-grounds-implementations-p2), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.purpose#p1](#source-software-engineering-purpose-p1), [software-engineering.purpose#p2](#source-software-engineering-purpose-p2), [software-engineering.purpose#p3](#source-software-engineering-purpose-p3), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3), [software-engineering.evolution-meaning#p1](#source-software-engineering-evolution-meaning-p1), [software-engineering.evolution-meaning#p2](#source-software-engineering-evolution-meaning-p2), [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2), [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3), [software-engineering.revision#p1](#source-software-engineering-revision-p1), [software-engineering.revision#p2](#source-software-engineering-revision-p2) + +[Declarations, proof and line explanations](details.md#t40) + + +## Source tracing appendix + + + + +### `organon.preamble#p1` + +```text +This is a statement of Software Engineering Organon’s adopted philosophy. It expresses commitments, not factual assertions about every system or a proof of universal correctness. +``` + +State: **not_applicable**; Lean: not_checked; fidelity: not_applicable. + +Documentary authority, interpretive role or disclosed boundary. No formal proof is assigned. + +Related targets: [T01](#t01), [T40](#t40). + + + + + + +### `organon.preamble#p2` + +```text +The quoted provisions, their meanings, and their conditions of application form the core. The charter and Grounds constrain one another; their grouping establishes neither a deductive hierarchy nor an order of priority. [Rationale](rationale/README.md) supplies arguments and cases without adding obligations to this core. Skills are revisable applications under the repository’s stated objectives and constraints, not part of the philosophical commitments themselves. +``` + +State: **not_applicable**; Lean: not_checked; fidelity: not_applicable. + +Documentary authority, interpretive role or disclosed boundary. No formal proof is assigned. + +Related targets: [T01](#t01), [T40](#t40). + + + + + + +### `organon.charter` + +```text + + +``` + +State: **not_applicable**; Lean: not_checked; fidelity: not_applicable. + +Structural heading without substantive direct-body content; no theorem is assigned. + + + + + + +### `organon.charter.overview#p1` + +```text +**Self-Transcendence · Internal Consistency · Reflexivity** +``` + +State: **not_applicable**; Lean: not_checked; fidelity: not_applicable. + +Documentary authority, interpretive role or disclosed boundary. No formal proof is assigned. + +Related targets: [T01](#t01). + + + + + + +### `organon.charter.overview#p2` + +```text +> A system is intrinsically oriented toward expanding what it can understand and construct. It brings itself and its principles within the scope of generation and assessment, with internal consistency constraining this process. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T02, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T01](#t01), [T02](#t02), [T38](#t38). + + + + + + +### `organon.charter.overview#p3` + +```text +The overview connects three distinct requirements: self-transcendence establishes a generative orientation and refuses to treat existing forms as final, internal consistency constrains judgments held simultaneously, and reflexivity brings the system and its principles within the scope of their own generation and assessment. The provisions below specify the conditions for each. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T02, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T01](#t01), [T02](#t02), [T38](#t38). + + + + + + +### `organon.charter.self-transcendence#p1` + +```text +> A system is intrinsically oriented toward expanding what it can understand and construct. It does not regard any existing form as the endpoint of generation. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T02, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T02](#t02), [T38](#t38). + + + + + + +### `organon.charter.self-transcendence.orientation#p1` + +```text +A commitment to keeping generative possibilities open is distinct from valuing their expansion. A system has an intrinsic orientation when it regards that expansion as worth pursuing. Merely permitting change does not fully express this orientation. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T02, T03, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T02](#t02), [T03](#t03), [T38](#t38). + + + + + + +### `organon.charter.self-transcendence.non-finality#p1` + +```text +Refusing to regard an existing form as an endpoint keeps it open to being surpassed. “Existing form” includes a system’s current organization, methods, and principles, not only its appearance or artifacts. These remain within the scope of possible change; their revisability does not guarantee actual progress. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T02, T03, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T02](#t02), [T03](#t03), [T38](#t38). + + + + + + +### `organon.charter.self-transcendence.limits#p1` + +```text +Whether progress has actually occurred remains a separate judgment. Having the orientation does not guarantee progress. Progress cannot be established merely by an increase in the number of artifacts, levels of abstraction, or terms. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T03, T38. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T03](#t03), [T38](#t38). + + + + + + +### `organon.charter.self-transcendence.limits#p2` + +```text +- “Intrinsic orientation” expresses Organon’s philosophical commitment; it does not assert that all systems in fact develop autonomously. +- Self-transcendence does not imply independence from external experience, knowledge, or collaboration, nor does it guarantee autonomous execution or self-improvement. +- Refusing to regard an existing form as an endpoint does not require every action to produce change. Justified stability can coexist with a generative orientation. +- Whether transcendence expands what can be understood and constructed requires discernible grounds; a system’s own claim of generation does not establish actual achievement. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T02, T03, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T02](#t02), [T03](#t03), [T38](#t38), [T40](#t40). + + + + + + +### `organon.charter.consistency#p1` + +```text +> The principles and judgments a system holds simultaneously, together with their implications, must not yield contradictory judgments on the same question under the same assumptions, meanings of terms, and scope of application. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T04, T05, T38. A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T04](#t04), [T05](#t05), [T38](#t38). + + + + + + +### `organon.charter.consistency.meaning#p1` + +```text +“Held simultaneously” specifies which principles, judgments, and implications must hold together. Revision may withdraw an earlier judgment; old and new principles need not remain compatible forever. When a change has occurred, that change cannot be represented as though it had not occurred. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T04, T05, T38. A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T04](#t04), [T05](#t05), [T38](#t38). + + + + + + +### `organon.charter.consistency.meaning#p2` + +```text +“The same assumptions, meanings of terms, and scope of application” specifies the basis for comparing judgments. Divergent judgments under different conditions do not automatically constitute contradictions. Nor can unacknowledged changes in assumptions, meanings, or scope be used to conceal an existing contradiction. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T04, T05, T06, T38. A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. Consistency is not sufficient empirical or value support; the counterexamples concern the disclosed mathematical representation. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T04](#t04), [T05](#t05), [T06](#t06), [T38](#t38). + + + + + + +### `organon.charter.consistency.limits#p1` + +```text +- Tension between different assessments or values does not directly constitute a contradiction. Revision or qualification is needed when they require incompatible conclusions under the same conditions. +- Internal consistency is not correctness or sufficiency. A set of principles may be internally consistent while relying on false assumptions or neglecting important questions. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T04, T05, T06, T38. A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. Consistency is not sufficient empirical or value support; the counterexamples concern the disclosed mathematical representation. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T04](#t04), [T05](#t05), [T06](#t06), [T38](#t38). + + + + + + +### `organon.charter.reflexivity#p1` + +```text +> A system’s principles of generation and assessment also apply to the system itself and to the formation, application, and revision of those principles. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T07, T38. Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T07](#t07), [T38](#t38). + + + + + + +### `organon.charter.reflexivity.meaning#p1` + +```text +Reflexivity encompasses both the system itself and its principles. Assessment concerns not only whether the system conforms to its principles, but also how those principles are formed, where they apply, and why they may need revision. The formation and revision of principles thus also become objects of generation and assessment. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T07, T38. Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T07](#t07), [T38](#t38). + + + + + + +### `organon.charter.reflexivity.limits#p1` + +```text +- Applying principles equally retains their conditions of application. When the relevant conditions hold, being the system itself is not a basis for exemption. Nor does the requirement of reflexivity establish that every principle can be applied to itself without examining its applicability. +- Self-application does not constitute self-proof. Subjecting a principle to its own assessment does not thereby establish its correctness. +- That a revision is produced by the system itself does not give it sufficient grounds. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T07, T08, T38. Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T07](#t07), [T08](#t08), [T38](#t38). + + + + + + +### `organon.grounds#p1` + +```text +> The grounds of principles and judgments must be articulable and subject to assessment appropriate to the nature of the claim. The strength and scope of a claim must be proportionate to the support provided by its grounds. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T08, T09, T38. This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T08](#t08), [T09](#t09), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.assessment#p1` + +```text +Articulation and assessment have distinct responsibilities. Articulability requires that concepts, assumptions, reasons, and limits can be identified. Assessment requires examining whether those grounds support the corresponding claim. Clearly expressed grounds are not thereby sufficiently established. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T09, T13, T38. This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. These distinctions do not require values, empirical evidence and inference to be reduced to one score. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T09](#t09), [T13](#t13), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.assessment#p2` + +```text +| Type of claim | Responsibility of assessment | What cannot substitute for that responsibility | +| --- | --- | --- | +| Empirical claim | Examine observations, evidence, and performance, together with the conditions, scope, and uncertainty of their support for the claim. | Treating measurability or repeatability itself as proof of relevance, correctness, or value. | +| Inferential claim | Examine whether the conclusion is supported by the stated assumptions and inferential relations. | Treating the absence of conflict between a conclusion and its assumptions as sufficient to establish that the conclusion follows from them. | +| Value commitment | State the position taken, its reasons, limits of application, and consequences, and remain open to relevant criticism. | Presenting a commitment as an empirical fact or a necessary inference, or substituting self-assertion for reasons. | +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T09, T10, T11, T12, T13, T38. This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. Repeatability or measurability alone does not establish relevance, correctness or value; varying unobserved outcomes need not contradict limited support. Failure of support is not failure to assess correctly; consistency with assumptions is weaker than entailment. The application supplies a sufficient value assessment, not a universal requirement to prove every starting assumption or a proof that one value is universally best. These distinctions do not require values, empirical evidence and inference to be reduced to one score. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T09](#t09), [T10](#t10), [T11](#t11), [T12](#t12), [T13](#t13), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.assessment#p3` + +```text +Initial value commitments may be stated explicitly as commitments; they need not prove all their own starting assumptions. The strength and scope of a claim do not require conversion to a common numerical scale. Different types of claims specify their support and limits in accordance with their nature. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T09, T12, T13, T38. This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. The application supplies a sufficient value assessment, not a universal requirement to prove every starting assumption or a proof that one value is universally best. These distinctions do not require values, empirical evidence and inference to be reduced to one score. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T09](#t09), [T12](#t12), [T13](#t13), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.scope#p1` + +```text +Performance is discerned within particular relations, conditions, and scopes of observation. A boundary helps specify what a comparison concerns, but local examples do not automatically support unconditional universal conclusions. A judgment cannot establish that relevant differences do not exist merely because its chosen scope omits them. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T14, T15, T38. A nonempty role string alone is not sufficient interpretation, and an unused method does not become compulsory. Omitting an input from comparison is not evidence that no relevant difference exists there. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T14](#t14), [T15](#t15), [T38](#t38). + + + + + + +### `organon.grounds.scope#p2` + +```text +Measurement can make some differences comparable. Repeated assessment can help examine the stability of corresponding conclusions. Their roles, and the role of any assessment framework, must be explained relative to the claim and its context. Measurement, repeatability, and an assessment framework do not form a universally necessary chain on which all judgments must depend. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T14, T15, T38. A nonempty role string alone is not sufficient interpretation, and an unused method does not become compulsory. Omitting an input from comparison is not evidence that no relevant difference exists there. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T14](#t14), [T15](#t15), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.scope#p3` + +```text +An observation that has not been reproduced may still offer limited support, and random outcomes need not be identical on every occasion. The verifiability of observations, reproducibility of conditions, and stability of conclusions must be distinguished. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T14, T15, T38. A nonempty role string alone is not sufficient interpretation, and an unused method does not become compulsory. Omitting an input from comparison is not evidence that no relevant difference exists there. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T14](#t14), [T15](#t15), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.capabilities#p1` + +```text +Capability claims are subject to Grounds: the capability claimed, its conditions, and the support for it must be identifiable. The core does not prescribe uniform definitions of method mastery, method generation, or capability levels. Applications specify the capabilities they assess and may require understanding, explanation, or performance under relevant variations. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T16, T17, T38. This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. An external assessor can ground the selected output claim without establishing how the assessed system understands its generation process. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T16](#t16), [T17](#t17), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.capabilities#p2` + +```text +Grounds for a capability claim may be supplied by an external assessor. Their articulability does not by itself require the assessed system to understand or explain its internal generation process. Evidence of reliable output must be assessed against the capability actually claimed; it does not automatically establish understanding of that process. Nor can the number of method documents, terms, tools, or artifacts alone establish a capability beyond what that evidence supports. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T16, T17, T38. This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. An external assessor can ground the selected output claim without establishing how the assessed system understands its generation process. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T16](#t16), [T17](#t17), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.implementations#p1` + +```text +> The choice of an implementation must be supported by reasons connected to the objectives and values pursued and to the relevant constraints. Its name, conventional use, or established status alone does not provide sufficient grounds for giving it priority. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T18, T19, T38. These are application reasons, not a universal cost function or a rule that conventional implementations must lose. No result asserts all implementations equivalent, multiple feasible implementations guaranteed, or the choice commitment derivable from chapter placement. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T18](#t18), [T19](#t19), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.implementations#p2` + +```text +This choice provision adds an additional evaluative commitment: name, conventional use, or established status alone is insufficient to establish priority. Grouping it under Grounds does not mean that it follows from the general requirement to assess reasons, or merely from the discernibility of performance. Conventions and existing arrangements may have practical significance, but that significance must be connected to the objectives and values pursued and to the relevant constraints. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T18, T19, T38. These are application reasons, not a universal cost function or a rule that conventional implementations must lose. No result asserts all implementations equivalent, multiple feasible implementations guaranteed, or the choice commitment derivable from chapter placement. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T18](#t18), [T19](#t19), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.implementations.limits#p1` + +```text +- Openness does not make all implementations equivalent, nor does it guarantee multiple feasible implementations for the same objective. +- A method’s explanatory power, limits of application, simplicity, and explicit process requirements may all provide grounded reasons for assessment. They cannot be excluded merely because they concern methods internal to the implementation. +- Identical local performance does not establish overall equivalence. Relations, conditions, and the scope of comparison are constrained by the provisions of Grounds. +- Openness does not reject an implementation merely because it already exists or is conventionally used. Relevant reasons may still give it priority. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T15, T18, T19, T38. Omitting an input from comparison is not evidence that no relevant difference exists there. These are application reasons, not a universal cost function or a rule that conventional implementations must lose. No result asserts all implementations equivalent, multiple feasible implementations guaranteed, or the choice commitment derivable from chapter placement. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T15](#t15), [T18](#t18), [T19](#t19), [T38](#t38). + + + + + + +### `organon.relationships` + +```text + + +``` + +State: **not_applicable**; Lean: not_checked; fidelity: not_applicable. + +Structural heading without substantive direct-body content; no theorem is assigned. + + + + + + +### `organon.relationships.roles#p1` + +```text +The charter states the generative orientation, the consistency constraint, and reflexive application. Grounds specifies support requirements for judgments and includes an additional commitment concerning implementation choices. Both parts belong to the core and constrain one another. Their placement neither makes Grounds a deduction from the charter nor gives the charter priority over it. Each commitment needs its own reasons. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T08, T20, T38, T39. This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. Projection does not derive all duties from one principle. Adoption markers are separate facts; they do not substitute for normative content. The sample-aware criticism is an application criterion, not a universal requirement for observations. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance. + +Related targets: [T01](#t01), [T08](#t08), [T20](#t20), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `organon.relationships.roles#p2` + +```text +Internal Consistency concerns whether simultaneously held judgments can hold together; Grounds concerns whether and how far a claim is supported. A conclusion may fail to conflict with its assumptions without being supported by them. Self-Transcendence specifies a generative orientation and non-finality; neither establishes actual capability. Applications may supply objectives, values, and capability definitions; claims made under those objectives, values, and definitions remain subject to the relevant core provisions. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T03, T06, T11, T16, T20, T38, T39. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. Consistency is not sufficient empirical or value support; the counterexamples concern the disclosed mathematical representation. Failure of support is not failure to assess correctly; consistency with assumptions is weaker than entailment. This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. Projection does not derive all duties from one principle. Adoption markers are separate facts; they do not substitute for normative content. The sample-aware criticism is an application criterion, not a universal requirement for observations. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance. + +Related targets: [T03](#t03), [T06](#t06), [T11](#t11), [T16](#t16), [T20](#t20), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `organon.relationships.roles#p3` + +```text +Self-Transcendence does not substitute for Reflexivity: keeping existing forms open to being surpassed differs from applying relevant principles to the system and to their own formation, application, and revision. Reflexivity extends these requirements to the system and to the formation, application, and revision of its principles. The grounds and limits of the Grounds provisions must themselves be articulable. The system’s own capability claims remain subject to assessment, and this philosophy’s existing form cannot gain priority merely from its established status. Such mutual application provides no self-proof and does not remove conditions of application. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T07, T08, T16, T18, T20, T37, T38, T39. Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. These are application reasons, not a universal cost function or a rule that conventional implementations must lose. Projection does not derive all duties from one principle. Adoption markers are separate facts; they do not substitute for normative content. The sample-aware criticism is an application criterion, not a universal requirement for observations. Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance. + +Related targets: [T07](#t07), [T08](#t08), [T16](#t16), [T18](#t18), [T20](#t20), [T37](#t37), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `organon.relationships.terms#p1` + +```text +| Term | Meaning in this philosophy | +| --- | --- | +| Existing form | The system’s current organization, methods, and principles, not only its appearance or artifacts. | +| Assessment | Examination of reasons, applicability, and observed performance; not limited to executable tests. | +``` + +State: **incomplete**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T02. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. + +Related targets: [T02](#t02), [T21](#t21). + + + + + + +### `extensions#p1` + +```text +This chapter adds a software engineering commitment and specifies its meaning and limits. It does not claim that this commitment follows from the Charter or Grounds. Those provisions remain adopted and constrain its application. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T37, T38, T39. Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance. + +Related targets: [T01](#t01), [T37](#t37), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `software-engineering.purpose#p1` + +```text +Software engineering concerns the construction, operation, understanding, and revision of software within its relevant human and technical conditions. This philosophy guides decisions by people and agents; it does not attribute an intrinsic orientation to every software artifact. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T22, T23, T38. These numerical schedules are finite model data, not project time estimates. Scope alone does not prove every participant can perform every change. The result concerns the represented paths; lack of one documented path is not a universal impossibility theorem about all maintenance. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T22](#t22), [T23](#t23), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.purpose#p2` + +```text +The evolution capability considered here belongs to the continuing engineering activity: maintainers, including successor maintainers and agents, working with software, tools, and available knowledge. Code that its original author can modify is not on that ground alone shown to support that continuing activity. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T22, T23, T38. These numerical schedules are finite model data, not project time estimates. Scope alone does not prove every participant can perform every change. The result concerns the represented paths; lack of one documented path is not a universal impossibility theorem about all maintenance. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T22](#t22), [T23](#t23), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.purpose#p3` + +```text +Apply the following priority according to the software's credible lifecycle and maintenance expectations. A genuinely temporary script, bounded prototype, or retiring system may have little reason to support further evolution. Calling a continuing system temporary does not establish that condition. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T22, T23, T24, T38. These numerical schedules are finite model data, not project time estimates. Scope alone does not prove every participant can perform every change. The result concerns the represented paths; lack of one documented path is not a universal impossibility theorem about all maintenance. This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T22](#t22), [T23](#t23), [T24](#t24), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.evolution-priority#p1` + +```text +> When relevant behavioral, safety, performance, and other necessary requirements are satisfied, give priority to continuing maintainers' ability to make credible future changes, including changes to the design itself, over present abstraction simplicity. Accept additional present abstraction complexity for that purpose, while allowing this preference to yield when the added costs threaten concrete engineering objectives. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T24, T25, T38, T39. This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. The theorem neither proves the value rule from facts nor establishes that every apparently complex design has the relevant advantage. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance. + +Related targets: [T24](#t24), [T25](#t25), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `software-engineering.evolution-priority#p2` + +```text +Credible directions of change have articulable grounds, such as a committed plan, relevant domain knowledge, or an applicable history of change. They need not already have multiple implementations. Their credibility remains open to revision; a conceivable change alone does not establish that it warrants accommodation now. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T24, T25, T26, T27, T38, T39. This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. The theorem neither proves the value rule from facts nor establishes that every apparently complex design has the relevant advantage. The proof checks stipulated evidence contents, not the real-world credibility or predictive calibration of arbitrary plans. No finite list of directions proves all future changes predictable or all omitted possibilities irrelevant. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance. + +Related targets: [T24](#t24), [T25](#t25), [T26](#t26), [T27](#t27), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `software-engineering.evolution-priority#p3` + +```text +This is a default priority, not an obligation to maximize extensibility or retain every possibility. Costs include relevant burdens of understanding, construction, diagnosis, verification, coordination, operation, and eventual migration. A departure from the priority identifies the objective threatened and why the costs matter. No universal numerical exchange rate between these considerations is prescribed. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T24, T25, T26, T27, T28, T38, T39. This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. The theorem neither proves the value rule from facts nor establishes that every apparently complex design has the relevant advantage. The proof checks stipulated evidence contents, not the real-world credibility or predictive calibration of arbitrary plans. No finite list of directions proves all future changes predictable or all omitted possibilities irrelevant. The finite costs are modeled work/budget data. The source does not require every category to apply or provide a universal numerical tradeoff. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance. + +Related targets: [T24](#t24), [T25](#t25), [T26](#t26), [T27](#t27), [T28](#t28), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `software-engineering.evolution-meaning#p1` + +```text +Evolution includes adding capabilities, replacing implementations, deleting mechanisms, withdrawing abstractions, redrawing boundaries, and migrating away from an existing technology or model. Making additions within a fixed scheme does not establish equal ability to revise or leave that scheme. Not every such change can or should be made inexpensive. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T29, T30, T38. The enumerated constructors illustrate source dimensions and allow an other direction; they do not claim every possible evolution is represented or cheap. These counterexamples reject unjustified cross-dimension inference without adding a duty that every change be inexpensive. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T29](#t29), [T30](#t30), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.evolution-meaning#p2` + +```text +An evolution claim identifies the relevant changes and the maintainers' conditions. Independent changes, coordinated changes, preservation of existing obligations, and deliberate revision of those obligations can require different structures. A design's advantage on one dimension does not establish an advantage on every dimension. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T29, T30, T38. The enumerated constructors illustrate source dimensions and allow an other direction; they do not claim every possible evolution is represented or cheap. These counterexamples reject unjustified cross-dimension inference without adding a duty that every change be inexpensive. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T29](#t29), [T30](#t30), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.structural-judgment#p1` + +```text +Apply the preceding commitment to engineering consequences as a whole, including the relations among components, their observable contracts, and the work needed to understand and verify a change. An interface's shape, the number of modules or extension points, or the use of a named principle is not sufficient evidence of the claimed capability. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T31, T32, T37, T38. These are relevant finite inquiries, not a mandatory universal checklist or a real-world estimate of all boundary costs. The equal-work case preserves step units through an actual path transformation; these units are a disclosed model measure, not observed engineering effort. Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T31](#t31), [T32](#t32), [T37](#t37), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.structural-judgment#p2` + +```text +The relevant comparison may examine how a change propagates, which knowledge and obligations cross a boundary, which assumptions become fixed, and what a later withdrawal would require. A proposed boundary needs support for the changes it is meant to accommodate; introducing it does not by itself show that those changes became easier. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T31, T32, T38. These are relevant finite inquiries, not a mandatory universal checklist or a real-world estimate of all boundary costs. The equal-work case preserves step units through an actual path transformation; these units are a disclosed model measure, not observed engineering effort. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T31](#t31), [T32](#t32), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.structural-judgment#p3` + +```text +Distinguish a transformation that preserves an identified observable contract from one that deliberately revises that contract. The latter needs a corresponding account of changed obligations and affected parties. This distinction does not require preserving every historical behavior or using a particular testing or migration procedure. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T33, T34, T38. The model does not require retaining every historical behavior, a particular test procedure, or an added universal notification obligation. A passing finite test suite is not a universal equality proof; preservation always retains its identified scope. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T33](#t33), [T34](#t34), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.revision#p1` + +```text +Changed evidence about likely changes, maintenance conditions, costs, or objectives may justify revising a design or this priority's application. A revised judgment acknowledges material changes in its grounds; it does not make a failed prediction successful retrospectively. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T35, T36, T38. The recorded history is fixed model evidence; the theorem does not authenticate arbitrary real-world logs or prove every criticism response adequate. The result permits bounded retention, not permanent immunity from later grounds or criticism. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T35](#t35), [T36](#t36), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.revision#p2` + +```text +Retaining a design can be justified when the relevant alternatives have no supported contribution or impose costs that defeat the objective. Reflexivity also keeps this engineering commitment and the methods used to assess evolution within the scope of criticism and revision. Continued change, agreement, or successful examples do not establish its universal correctness. +``` + +State: **limited**; Lean: passed; fidelity: partial. + +Bounded source correspondence to T35, T36, T37, T38. The recorded history is fixed model evidence; the theorem does not authenticate arbitrary real-world logs or prove every criticism response adequate. The result permits bounded retention, not permanent immunity from later grounds or criticism. Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. + +Related targets: [T35](#t35), [T36](#t36), [T37](#t37), [T38](#t38), [T40](#t40). + + + diff --git a/SoftwareEngineering/lean/philosophy/reviews/README.md b/SoftwareEngineering/lean/philosophy/reviews/README.md new file mode 100644 index 0000000..5b40792 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/README.md @@ -0,0 +1,46 @@ +# Independent reviews and corrected objects + +The current object retains the original SoftwareEngineering 0.2.0 / Core 0.1.2 adopted text. Its [frozen catalog](../targets.json) was agreed before candidate code: 40 targets, 47 substantive paragraphs and 175 semantic cases. Required goals were neither removed nor weakened after failures. + +## Review order and exposure + +1. The [source-first initial assessment](source-initial.md) and [inventory](source-initial-targets.json) were saved before comparison with the author's inventory and before candidate code. The [freeze review](target-freeze-review.md) records the agreed scope. +2. A different reviewer received code in an isolated project with source mappings and author philosophical comments removed. Its [initial code-only account](code-blind-initial.md) and [identity](code-blind-identity.json) were saved before reading the source. A changed code object received a [delta account](code-blind-delta.md), with its [separate identity](code-blind-delta-identity.json). +3. The reviewers then compared actual code, full types and dependencies with the source. The [source-first full initial report](source-code-review-full-initial.md) and [code reviewer's first source comparison](blind-source-initial.md) preserve distinct objections and incomplete judgments. Earlier source-first component reports retain their individual scope. +4. Corrections were reviewed as new exact code objects. The [final code/source comparison](code-comparison-final.md), [full target/source/case record](code-targets-final.json), [identity](code-review-identity.json), [source-first final increment](source-code-review-r3.md) and [whole-theory/self-rule review](source-code-review-f07-f08.md) record the final bounded judgments. This final stage is an informed comparison, not a second blind review. + +The author's earlier Core experience was not represented as independent ignorance. The code-only reviewer did not know the philosophical source during its initial translation; later exposure is explicit. After final source judgments, the two reviewers authored disjoint detailed-reader explanations. They therefore cannot certify their own reader prose; later reader review must distinguish authorship from independent checks. + +## Substantive corrections + +Early models admitted source-fidelity defects despite successful Lean checking. Revised objects bind appropriate grounds to the actual claim, retain actual achievement and understanding tests, and distinguish a duplicated record from adequate support. The engineering model now connects structural variation to actual changed work and crossing obligations. The whole consistency theory contains actual applicable normative contents, not only adoption flags. Both the actual generation rule and assessment rule are self-assessment objects; local failure is retained instead of hidden by a successful label. + +The final understanding example compares responses to changed multiplier/input conditions on the same explained process. The final boundary example connects a real caller/callee edge, the actual callee edit, caller verification and scoped output equality. Negative variants preserve or alter those facts explicitly. Earlier reviewers' overacceptance of these examples remains visible in the later comparison. + +The frozen joint-witness and strong non-entailment goals and requirements remain unchanged. Corrected predicates and expanded types identify new reviewed code objects. The strong countermodel satisfies all represented inherited commitments while domain applicability, genuine revision advantage, both candidates' necessary requirements and lack of a cost exception hold in the same continuing context. It chooses an independently supported simplicity value; it does not substitute completed assessment for fulfilled inherited duties. + +## Reader acceptance + +The first four-view object passed binding checks while independent readers still found incorrect explanations. The [source reader’s initial findings](reader-independent-source-review-r1.md), [Domain reader’s initial findings](reader-independent-domain-r1.md), [overall reader’s initial findings](reader-initial-overall.md) and [later comparison](reader-comparison.md) preserve those distinctions and the reviewers’ own corrections. + +The [final source check](reader-independent-source-final.md), [final Domain check](reader-independent-domain-final.md) and [final overall reader check](reader-final-overall.md) accept the corrected views within their stated coverage. Actual retrieval covered the priority conditions and departure rule, complete strong-countermodel premises, contract and historical revision, real self-assessment rules, and normative definitions versus fulfillment. The source reader reviewed Adopted and bounded helper content; the Domain reviewer did not author Domain prose; the overall reviewer authored none of the four readers and reviewed all four Engineering support modules. Authorship and exact reuse remain disclosed rather than being counted as independent rereading. + +Corrections retain every listed participant’s knowledge/tool conditions, the separate state-transform conjuncts, five simultaneous historical changes, conditional priority applicability, generic typeclass assumptions, raw versus self-owned targets, and the actual positive/negative proof branches. The corrected views do not infer overall safety rejection from a failed priority condition or actual revisability from an unchanged recorded choice. + +Final reader acceptance binds the exact four views, source, code and frozen targets. The reports retain the manifest observed during reading. Adding these public review records changes review/manifest metadata without changing those accepted view bytes; the final binding check records that new metadata object. It does not rewrite the earlier observed manifest hashes. + +## Interpretation and reuse + +Acceptance is bounded to the actual interfaces, applications, conditional proofs and concrete models. Defining a norm is distinct from fulfilling it. A local empty-sample assessment defect concerns the explicitly declared sample-aware application contract, not a philosophical rule that all assessment needs empirical samples. The capability example supplies an operational application criterion, not a universal theory of psychological understanding. Structural examples are not a mandatory checklist. + +Six mathematical helper modules reuse preceding Core code; source comments were adjusted for this new object. The current exact sources, complete types, dependencies and SoftwareEngineering links were checked anew. No earlier Core source approval was transferred by merely refreshing expected hashes. Some unchanged helper explanations reuse earlier prose after exact code-and-caption identity checks; the reader reports distinguish that reuse from fresh semantic reading. The supplementary helper content is fully displayed in the detailed readers without becoming an additional philosophical obligation. + +[Presentation derivations](presentation-derivations.json) record the original and exported hashes. Exports replace host directory prefixes with descriptive labels; original records remain unchanged locally. References within those old records may name private historical snapshots: they describe original review provenance and do not make those snapshots dependencies of current checking. A compiled `Domain.olean` accidentally present in the immutable review snapshot is excluded from the delivered project. It was not a registered checker input; the reviewed Lean source bytes are unchanged. + +The [independent complete audit](r3-actual-audit.log), [axiom summary](r3-axiom-summary.json), [actual probes](r3-probes.log) and [same-object probe](r3-stability-probe.log) retain the final execution evidence beyond the registered inventory. + +The machine-readable [fidelity record](fidelity.json) binds this current run, exact code, actual type hashes and reported target judgments. The checker validates those bindings and state relationships; it does not independently establish source fidelity, translation quality, reviewer independence or philosophical correctness. + +## Current source migration + +The [2026-09-15 comparison](source-migration-2026-09-15.md) reviews the new source version and rationale path. Earlier initial and final review files keep their original objects and wording. The current fidelity object reuses their unchanged code, assumptions and target judgments only within that separate comparison; it does not relabel them as new blind reviews. The original preregistration and its catalog hash identify the preceding source-bound catalog; current target bodies are identical and the source binding is new. Historical source/run/readers replayed in a separate complete copy before replacement. diff --git a/SoftwareEngineering/lean/philosophy/reviews/blind-source-initial.json b/SoftwareEngineering/lean/philosophy/reviews/blind-source-initial.json new file mode 100644 index 0000000..0bbc8d9 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/blind-source-initial.json @@ -0,0 +1,4620 @@ +{ + "stage": "source-comparison-initial-independent", + "created_utc": "2026-09-14T17:57:16.461313+00:00", + "source": { + "kind": "organon", + "path": "../../PHILOSOPHY.md", + "snapshot": "snapshots/PHILOSOPHY.md", + "sha256": "6c6ae78a23f2726c5c370434e808d76c206647fe7793245e88cae52c076abe34", + "metadata": { + "format_version": "0.1.0", + "philosophy_version": "0.2.0", + "core_version": "0.1.2", + "derived_from": { + "source_id": "https://github.com/shendeguize/OrganonCore", + "philosophy_version": "0.1.2", + "content_hash": "cb23f8a44d6b877ff9b5385961ff8e5fa788f8021ae267cdc8e305870ec20ca7" + } + } + }, + "baseline_policy": "Software Engineering 0.2.0 adopting Core 0.1.2. No Core 0.1.3 substitution.", + "code_object": "Frozen delta code; separately captured current raw source code is identical after comment removal and blank-line omission. Later mutations are excluded.", + "initial_blind_sha256": "cf9280ddd3365440e848b14043a6208b9fea5114f9ff13cea4e236e3358317df", + "delta_blind_sha256": "a0a16628362882d5574bf41123d6fed41ce735083d55dccfb06650555cb3b776", + "verdict": "not_all_targets_accepted_as_complete_source_correspondence", + "kernel_status": "788 declarations and 269 theorems checked in frozen delta; no Lean proof failure alleged.", + "not_read": [ + "source-code-review*", + "all-semantic-cases-current", + "other author iteration records" + ], + "targets": [ + { + "id": "T01", + "kind": "boundary", + "registered_statement": "Authority and roles: adopted commitments, no universal factual assertion or correctness proof; meanings and limits constrain quotation; charter and Grounds mutually constrain without hierarchy; rationale/skills add no philosophical duties; domain preference is additional.", + "sources": [ + { + "unit": "organon.preamble", + "clause": "p1" + }, + { + "unit": "organon.preamble", + "clause": "p2" + }, + { + "unit": "organon.charter.overview", + "clause": "p1" + }, + { + "unit": "organon.charter.overview", + "clause": "p2" + }, + { + "unit": "organon.charter.overview", + "clause": "p3" + }, + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "extensions", + "clause": "p1" + } + ], + "registered_premises": [ + "Distinguish document role from deductive claims. No assumed metatheorem about all possible formalizations." + ], + "disposition": "documentary_boundary", + "independent_assessment": "The source explicitly adopts commitments rather than claiming universal factual truth or deductive hierarchy. The chapter-4 preference is additional. No theorem is required for document authority, and the concrete countermodels must not be promoted into independence of every conceivable formalization.", + "semantic_cases": [], + "declarations": [] + }, + { + "id": "T02", + "kind": "specification", + "registered_statement": "Self-transcendence requires valuing expansion of understanding and construction and keeping all existing organization, methods and principles open to being surpassed; justified stable acts remain permitted.", + "sources": [ + { + "unit": "organon.charter.overview", + "clause": "p2" + }, + { + "unit": "organon.charter.overview", + "clause": "p3" + }, + { + "unit": "organon.charter.self-transcendence", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.orientation", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.non-finality", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p2" + }, + { + "unit": "organon.relationships.terms", + "clause": "p1" + } + ], + "registered_premises": [ + "System/activity subject", + "current forms quantified without omitting principles", + "orientation is normative commitment, not empirical universality." + ], + "disposition": "bounded_specification", + "independent_assessment": "Generative requires valuation of expansion and revisability of every current Form, including organization, method and principle. Current examples are nonempty; the stable trace and budget-respecting stable action show that generativity does not require change in every act. This is an adopted policy predicate, not proof all systems possess it.", + "semantic_cases": [ + { + "case": "positive_valued_open_forms", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Generative requires valuation of expansion and revisability of every current Form, including organization, method and principle. Current examples are nonempty; the stable trace and budget-respecting stable action show that generativity does not require change in every act. This is an adopted policy predicate, not proof all systems possess it." + }, + { + "case": "negative_permission_only", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Generative requires valuation of expansion and revisability of every current Form, including organization, method and principle. Current examples are nonempty; the stable trace and budget-respecting stable action show that generativity does not require change in every act. This is an adopted policy predicate, not proof all systems possess it." + }, + { + "case": "positive_stability", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Generative requires valuation of expansion and revisability of every current Form, including organization, method and principle. Current examples are nonempty; the stable trace and budget-respecting stable action show that generativity does not require change in every act. This is an adopted policy predicate, not proof all systems possess it." + }, + { + "case": "external_collaboration", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Generative requires valuation of expansion and revisability of every current Form, including organization, method and principle. Current examples are nonempty; the stable trace and budget-respecting stable action show that generativity does not require change in every act. This is an adopted policy predicate, not proof all systems possess it." + } + ], + "declarations": [ + { + "name": "CoreReader.Adopted.generationSpecification", + "registered_kind": "definition", + "actual_kind": "def", + "file": "CoreReader/Adopted.lean", + "line": 80, + "end": 89, + "exact_delta_code": "def generationSpecification (policy : Policy) : Prop := Generative policy\n\n \n \n \n \n \n \n \n \n", + "axioms": "[]", + "actual_type_record": { + "type": "Lean.Expr.forallE\n `policy\n (Lean.Expr.const `CoreReader.Agency.Policy [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default)", + "sha256": "4d07b8deec9112ff5d3e7fe744c159c254580260c78b82be6dd64347e8a9a4eb" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + }, + { + "name": "CoreReader.Adopted.generationCases", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Adopted.lean", + "line": 796, + "end": 837, + "exact_delta_code": "theorem generationCases :\n (Generative openPolicy ∧\n (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧\n (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1)))) ∧\n (neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy) ∧\n (Generative generatingSystem.policy ∧\n generatingSystem.policy.permitsVersion 0 0 ∧\n ¬ Expanded generatingSystem.current inflatedState ∧\n generatingSystem.current.inventory.length < inflatedState.inventory.length ∧\n generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧\n generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧\n generatingSystem.execute availableResources = some 6 ∧\n generatingSystem.execute { availableResources with experience := none } = none ∧\n generatingSystem.execute { availableResources with knowledge := none } = none ∧\n generatingSystem.execute { availableResources with collaborator := none } = none ∧\n generatingSystem.execute ⟨none, none, none⟩ = none ∧\n ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧\n generatingSystem.stableAction = generatingSystem.current ∧\n generatingSystem.requirementsMet generatingSystem.stableAction ∧\n generatingSystem.withinBudget generatingSystem.stableAction ∧\n ¬ generatingSystem.withinBudget inflatedState ∧\n StableReason generatingSystem.current inflatedState ∧\n (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧\n inflatedAnnouncement.owner = generatingSystem.owner ∧\n inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧\n inflatedAnnouncement.reportedNewOperation = .successor ∧\n inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧\n ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after)) ∧\n (generationSpecification openPolicy ∧\n Expanded baseState (collaborativeRevision availableResources) ∧\n ¬ Expanded baseState (collaborativeRevision { availableResources with collaborator := none }) ∧\n assistedExecution ⟨none, none, none⟩ = none) :=\n ⟨revisionWithoutProgress, permissionNotValuation, generationLimits, collaborativeProgress⟩\n\n \n \n \n \n \n \n \n \n", + "axioms": "[propext, Quot.sound.{u}]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `k\n (Lean.Expr.const `CoreReader.Agency.FormKind [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.revisable [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Form.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.forallE\n `t\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.stableTrace []) (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.stableTrace [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `HAdd.hAdd [Lean.Level.zero, Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `instHAdd [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instAddNat [])))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.permitsVersion [])\n (Lean.Expr.const `CoreReader.Agency.neutralPolicy []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.const `CoreReader.Agency.neutralPolicy []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.permitsVersion [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.availableResources [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Option.some [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 6)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 1780710401) \"_hygCtx\") \"_hyg\") 147)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 1780710401) \"_hygCtx\") \"_hyg\") 166)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `Option [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 1780710401) \"_hygCtx\") \"_hyg\") 185)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n true)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `Option [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.requirementsMet [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.StableReason [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Announcement []))\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.GeneratingSystem.report\n [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.owner [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.owner [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.before [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.after [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.reportedNewOperation\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.input [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const\n `Eq\n [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.expectedOutput\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.claim\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.before\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.after\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))))))))))))))))))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.generationSpecification [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.const `CoreReader.Agency.baseState []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.collaborativeRevision [])\n (Lean.Expr.const `CoreReader.Agency.availableResources []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.const `CoreReader.Agency.baseState []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.collaborativeRevision [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 1780710401) \"_hygCtx\") \"_hyg\") 355)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n true)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.assistedExecution [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))))", + "sha256": "430a91318477db0305b3107b81f9df39652fa27673fdc38705a86f8e158ca138" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T03", + "kind": "nonentailment", + "registered_statement": "Permission to change does not entail valuing expansion; valuing/open forms do not entail achieved progress, actual capability, independence, autonomous execution or self-improvement; output/term/abstraction counts or self-claims alone do not establish achievement.", + "sources": [ + { + "unit": "organon.charter.self-transcendence.orientation", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.non-finality", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + } + ], + "registered_premises": [ + "Keep valuing, revisability, progress, support and autonomous properties distinct", + "ground actual achievement in a declared criterion independent of mere count/claim." + ], + "disposition": "bounded_countermodels", + "independent_assessment": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions.", + "semantic_cases": [ + { + "case": "permission_without_value", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions." + }, + { + "case": "orientation_without_progress", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions." + }, + { + "case": "count_growth_without_capability", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions." + }, + { + "case": "collaborative_nonautonomous_progress", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions." + }, + { + "case": "claim_without_achievement", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions." + }, + { + "case": "achievement_support_for_same_claim", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions." + } + ], + "declarations": [ + { + "name": "CoreReader.Adopted.generationLimits012", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Adopted.lean", + "line": 838, + "end": 885, + "exact_delta_code": "theorem generationLimits012 :\n (neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy) ∧\n (Generative openPolicy ∧\n (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧\n (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1)))) ∧\n (Generative generatingSystem.policy ∧\n generatingSystem.policy.permitsVersion 0 0 ∧\n ¬ Expanded generatingSystem.current inflatedState ∧\n generatingSystem.current.inventory.length < inflatedState.inventory.length ∧\n generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧\n generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧\n generatingSystem.execute availableResources = some 6 ∧\n generatingSystem.execute { availableResources with experience := none } = none ∧\n generatingSystem.execute { availableResources with knowledge := none } = none ∧\n generatingSystem.execute { availableResources with collaborator := none } = none ∧\n generatingSystem.execute ⟨none, none, none⟩ = none ∧\n ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧\n generatingSystem.stableAction = generatingSystem.current ∧\n generatingSystem.requirementsMet generatingSystem.stableAction ∧\n generatingSystem.withinBudget generatingSystem.stableAction ∧\n ¬ generatingSystem.withinBudget inflatedState ∧\n StableReason generatingSystem.current inflatedState ∧\n (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧\n inflatedAnnouncement.owner = generatingSystem.owner ∧\n inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧\n inflatedAnnouncement.reportedNewOperation = .successor ∧\n inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧\n ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after)) ∧\n (generationSpecification openPolicy ∧\n Expanded baseState (collaborativeRevision availableResources) ∧\n ¬ Expanded baseState (collaborativeRevision { availableResources with collaborator := none }) ∧\n assistedExecution ⟨none, none, none⟩ = none) ∧\n (Grounds012 transitionAchievement canonicalArticulation [transitionFacet] (taskOfFacet transitionFacet) ∧\n Compatible [transitionPerformanceRecord] .extend ∧\n transitionAchievement .extend ∧ ¬ transitionAchievement .inflate ∧\n ¬ Supports [transitionReportRecord] transitionAchievement) ∧\n (∀ kind : InventoryKind,\n Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .copy ∧\n ¬ Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .successor) :=\n ⟨permissionNotValuation, revisionWithoutProgress, generationLimits, collaborativeProgress, achievementSupported012, inventoryCases012⟩\n\n \n \n \n \n \n \n \n", + "axioms": "[propext, Quot.sound.{u}]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.permitsVersion [])\n (Lean.Expr.const `CoreReader.Agency.neutralPolicy []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.const `CoreReader.Agency.neutralPolicy []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `k\n (Lean.Expr.const `CoreReader.Agency.FormKind [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.revisable [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Form.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.forallE\n `t\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.stableTrace []) (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.stableTrace [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `HAdd.hAdd [Lean.Level.zero, Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `instHAdd [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instAddNat [])))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.permitsVersion [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.availableResources [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Option.some [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 6)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3022720055) \"_hygCtx\") \"_hyg\") 147)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3022720055) \"_hygCtx\") \"_hyg\") 166)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `Option [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3022720055) \"_hygCtx\") \"_hyg\") 185)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n true)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `Option [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.requirementsMet [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.StableReason [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Announcement []))\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.GeneratingSystem.report\n [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.owner [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.owner [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.before [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.after [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.reportedNewOperation\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.input [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const\n `Eq\n [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.expectedOutput\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.claim\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.before\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.after\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))))))))))))))))))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.generationSpecification [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.const `CoreReader.Agency.baseState []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.collaborativeRevision [])\n (Lean.Expr.const `CoreReader.Agency.availableResources []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.const `CoreReader.Agency.baseState []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.collaborativeRevision [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3022720055) \"_hygCtx\") \"_hyg\") 358)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n true)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.assistedExecution [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase []))\n (Lean.Expr.const `CoreReader.Evidence.transitionAchievement []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))\n (Lean.Expr.const `CoreReader.Evidence.transitionFacet []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase []))\n (Lean.Expr.const `CoreReader.Evidence.transitionFacet []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))\n (Lean.Expr.const `CoreReader.Evidence.transitionPerformanceRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))))\n (Lean.Expr.const `CoreReader.Agency.TransitionCase.extend [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.transitionAchievement [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase.extend [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.transitionAchievement [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase.inflate []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))\n (Lean.Expr.const `CoreReader.Evidence.transitionReportRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))))\n (Lean.Expr.const `CoreReader.Evidence.transitionAchievement []))))))))\n (Lean.Expr.forallE\n `kind\n (Lean.Expr.const `CoreReader.Agency.InventoryKind [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Available [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item [])))))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Available [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item [])))))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor []))))\n (Lean.BinderInfo.default))))))", + "sha256": "69058c75db607f675c730d92da7dd1c6ee27d75385f4ac4ff717bd9fc7e925b2" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T04", + "kind": "specification", + "registered_statement": "All simultaneously held principles/judgments and their joint implications must avoid opposite conclusions on same question, assumptions, term meanings and scope; incompatible same-condition demands need revision/qualification; recorded change cannot be concealed.", + "sources": [ + { + "unit": "organon.charter.consistency", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "p1" + } + ], + "registered_premises": [ + "Consequence over whole held set", + "explicit context equality", + "no per-principle-only substitute", + "distinguish held-at-time from historical union", + "change-report condition separate from consistency." + ], + "disposition": "bounded_specification", + "independent_assessment": "Consistent quantifies over joint semantic consequences of the whole held theory under one Context. Snapshot change reporting is a separate one-way Boolean obligation. The code preserves same-question/assumptions/meaning/scope and time-slice distinctions; it does not model every way a prose report could conceal change.", + "semantic_cases": [ + { + "case": "joint_only_contradiction", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Consistent quantifies over joint semantic consequences of the whole held theory under one Context. Snapshot change reporting is a separate one-way Boolean obligation. The code preserves same-question/assumptions/meaning/scope and time-slice distinctions; it does not model every way a prose report could conceal change." + }, + { + "case": "changed_scope_not_concealed", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Consistent quantifies over joint semantic consequences of the whole held theory under one Context. Snapshot change reporting is a separate one-way Boolean obligation. The code preserves same-question/assumptions/meaning/scope and time-slice distinctions; it does not model every way a prose report could conceal change." + }, + { + "case": "revision_withdraws_old", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Consistent quantifies over joint semantic consequences of the whole held theory under one Context. Snapshot change reporting is a separate one-way Boolean obligation. The code preserves same-question/assumptions/meaning/scope and time-slice distinctions; it does not model every way a prose report could conceal change." + }, + { + "case": "incompatible_same_context", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Consistent quantifies over joint semantic consequences of the whole held theory under one Context. Snapshot change reporting is a separate one-way Boolean obligation. The code preserves same-question/assumptions/meaning/scope and time-slice distinctions; it does not model every way a prose report could conceal change." + } + ], + "declarations": [ + { + "name": "CoreReader.Adopted.consistencySpecification", + "registered_kind": "definition", + "actual_kind": "def", + "file": "CoreReader/Adopted.lean", + "line": 90, + "end": 96, + "exact_delta_code": "def consistencySpecification {W Q : Type} (before after : Snapshot W Q)\n (reported : Bool) : Prop :=\n Consistent after.held after.context ∧ TruthfulReport before after reported\n\n \n \n \n", + "axioms": "[]", + "actual_type_record": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `Q\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `before\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Snapshot []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `after\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Snapshot []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.forallE\n `reported\n (Lean.Expr.const `Bool [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit))\n (Lean.BinderInfo.implicit)", + "sha256": "cf239ba7292f80875f93e960cd3417c226a8727f57f11e1ec4af4564caef076d" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + }, + { + "name": "CoreReader.Adopted.consistencyCases", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Adopted.lean", + "line": 886, + "end": 920, + "exact_delta_code": "theorem consistencyCases :\n (Satisfiable (singleton premiseP) ∧ Satisfiable (singleton premiseRule) ∧\n Satisfiable (singleton premiseNotQ) ∧ ¬ Satisfiable jointTheory) ∧\n ((Consequence emptyTheory (assumptionContext true) () true ∧\n Consequence emptyTheory (assumptionContext false) () false) ∧\n (Consequence emptyTheory (meaningContext true) () true ∧\n Consequence emptyTheory (meaningContext false) () false) ∧\n (Consequence emptyTheory (scopeContext true) () true ∧\n Consequence emptyTheory (scopeContext false) () false) ∧\n (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧\n (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧\n (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w)) ∧\n (¬ TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) false ∧\n ¬ TruthfulReport (contextSnapshot (meaningContext true)) (contextSnapshot (meaningContext false)) false ∧\n ¬ TruthfulReport (contextSnapshot (scopeContext true)) (contextSnapshot (scopeContext false)) false ∧\n ¬ TruthfulReport (contextSnapshot (scopeContext true) 0) (contextSnapshot (scopeContext true) 1) false ∧\n (TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) true ∧\n ¬ Models (assumptionContext false).assumptions true)) ∧\n (Satisfiable (revisionSlice 0) ∧ Satisfiable (revisionSlice 1) ∧\n ¬ Satisfiable (union (revisionSlice 0) (revisionSlice 1))) ∧\n ((∀ time, Consistent (revisionSlice time) broadBoolContext) ∧\n ¬ Consistent (union (revisionSlice 0) (revisionSlice 1)) broadBoolContext) ∧\n (∀ p q : Claim Bool,\n ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r) ∧\n (Consequence jointTheory jointContext012 () true ∧\n Consequence jointTheory jointContext012 () false ∧\n ¬ Consistent jointTheory jointContext012) :=\n ⟨jointConflict, contextDifferences, hiddenContextChangeRejected, revisionCanReverse, sliceConsistency, semanticOrder012, jointImplicationConflict012⟩\n\n \n \n \n \n \n \n", + "axioms": "[]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.premiseP []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.premiseRule []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.premiseNotQ []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.jointTheory [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consequence [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.assumptionContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.meaningContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.scopeContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.TruthfulReport []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.TruthfulReport []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.TruthfulReport [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.TruthfulReport [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.TruthfulReport [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Models []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Context.assumptions [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.const `Bool.true [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `time\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.revisionSlice []) (Lean.Expr.bvar 0)))\n (Lean.Expr.const `CoreReader.Adopted.broadBoolContext []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.const `CoreReader.Adopted.broadBoolContext [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `p\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `Bool []))\n (Lean.Expr.forallE\n `q\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `Bool []))\n (Lean.Expr.forallE\n `r\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Iff [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 2)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 2)))\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consequence [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.const `CoreReader.Logic.jointTheory []))\n (Lean.Expr.const `CoreReader.Adopted.jointContext012 []))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consequence [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.const `CoreReader.Logic.jointTheory []))\n (Lean.Expr.const `CoreReader.Adopted.jointContext012 []))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consistent [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.const `CoreReader.Logic.jointTheory []))\n (Lean.Expr.const `CoreReader.Adopted.jointContext012 []))))))))))", + "sha256": "16a20441e5650e4992e046ae4eeb2a1867f573730aa1dc402ca70508bb1802a6" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T05", + "kind": "theorem", + "registered_statement": "Given faithful context identity and whole-set consequence, an opposite pair under the same context violates consistency; removing a prior judgment may eliminate the conflict without requiring permanent historical compatibility.", + "sources": [ + { + "unit": "organon.charter.consistency", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "p1" + } + ], + "registered_premises": [ + "A consequence relation, positive/negative conclusions for same question, active-set membership, context equality", + "explicit withdrawal semantics", + "no explosion assumption needed." + ], + "disposition": "conditional_theorem", + "independent_assessment": "consistencyConsequences directly applies the consistency prohibition to supplied positive and negative consequences. The revisionSlice examples provide distinct satisfiable times and inconsistent union; context examples preserve an admissible witness for each context. The theorem neither proves premises nor mandates permanent historical compatibility.", + "semantic_cases": [ + { + "case": "pair_conflict", + "disposition": "covered_with_target_scope_qualifications", + "basis": "consistencyConsequences directly applies the consistency prohibition to supplied positive and negative consequences. The revisionSlice examples provide distinct satisfiable times and inconsistent union; context examples preserve an admissible witness for each context. The theorem neither proves premises nor mandates permanent historical compatibility." + }, + { + "case": "joint_premise_conflict", + "disposition": "covered_with_target_scope_qualifications", + "basis": "consistencyConsequences directly applies the consistency prohibition to supplied positive and negative consequences. The revisionSlice examples provide distinct satisfiable times and inconsistent union; context examples preserve an admissible witness for each context. The theorem neither proves premises nor mandates permanent historical compatibility." + }, + { + "case": "old_new_separate_times", + "disposition": "covered_with_target_scope_qualifications", + "basis": "consistencyConsequences directly applies the consistency prohibition to supplied positive and negative consequences. The revisionSlice examples provide distinct satisfiable times and inconsistent union; context examples preserve an admissible witness for each context. The theorem neither proves premises nor mandates permanent historical compatibility." + }, + { + "case": "distinct_context_judgments", + "disposition": "covered_with_target_scope_qualifications", + "basis": "consistencyConsequences directly applies the consistency prohibition to supplied positive and negative consequences. The revisionSlice examples provide distinct satisfiable times and inconsistent union; context examples preserve an admissible witness for each context. The theorem neither proves premises nor mandates permanent historical compatibility." + }, + { + "case": "truthful_semantic_change_and_reordering", + "disposition": "covered_with_target_scope_qualifications", + "basis": "consistencyConsequences directly applies the consistency prohibition to supplied positive and negative consequences. The revisionSlice examples provide distinct satisfiable times and inconsistent union; context examples preserve an admissible witness for each context. The theorem neither proves premises nor mandates permanent historical compatibility." + } + ], + "declarations": [ + { + "name": "CoreReader.Adopted.consistencyConsequences", + "registered_kind": "theorem", + "actual_kind": "theorem", + "file": "CoreReader/Adopted.lean", + "line": 241, + "end": 244, + "exact_delta_code": "theorem consistencyConsequences {W Q : Type} (t : Theory W) (c : Context W Q) (q : Q)\n (positive : Consequence t c q true) (negative : Consequence t c q false) :\n ¬ Consistent t c := conflictRequiresChange t c q positive negative\n\n", + "axioms": "[]", + "actual_type_record": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `Q\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `t\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Theory []) (Lean.Expr.bvar 1))\n (Lean.Expr.forallE\n `c\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Context []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.forallE\n `q\n (Lean.Expr.bvar 2)\n (Lean.Expr.forallE\n `positive\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.bvar 4))\n (Lean.Expr.bvar 3))\n (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.forallE\n `negative\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.bvar 5))\n (Lean.Expr.bvar 4))\n (Lean.Expr.bvar 3))\n (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `Bool.false []))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.bvar 6))\n (Lean.Expr.bvar 5))\n (Lean.Expr.bvar 4))\n (Lean.Expr.bvar 3)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit))\n (Lean.BinderInfo.implicit)", + "sha256": "4b3231ac25a534c2699cd8f548a59a7d8beb1cb3923456f10c95081a3b6b5be3" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + }, + { + "name": "CoreReader.Adopted.consistencyCases", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Adopted.lean", + "line": 886, + "end": 920, + "exact_delta_code": "theorem consistencyCases :\n (Satisfiable (singleton premiseP) ∧ Satisfiable (singleton premiseRule) ∧\n Satisfiable (singleton premiseNotQ) ∧ ¬ Satisfiable jointTheory) ∧\n ((Consequence emptyTheory (assumptionContext true) () true ∧\n Consequence emptyTheory (assumptionContext false) () false) ∧\n (Consequence emptyTheory (meaningContext true) () true ∧\n Consequence emptyTheory (meaningContext false) () false) ∧\n (Consequence emptyTheory (scopeContext true) () true ∧\n Consequence emptyTheory (scopeContext false) () false) ∧\n (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧\n (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧\n (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w)) ∧\n (¬ TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) false ∧\n ¬ TruthfulReport (contextSnapshot (meaningContext true)) (contextSnapshot (meaningContext false)) false ∧\n ¬ TruthfulReport (contextSnapshot (scopeContext true)) (contextSnapshot (scopeContext false)) false ∧\n ¬ TruthfulReport (contextSnapshot (scopeContext true) 0) (contextSnapshot (scopeContext true) 1) false ∧\n (TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) true ∧\n ¬ Models (assumptionContext false).assumptions true)) ∧\n (Satisfiable (revisionSlice 0) ∧ Satisfiable (revisionSlice 1) ∧\n ¬ Satisfiable (union (revisionSlice 0) (revisionSlice 1))) ∧\n ((∀ time, Consistent (revisionSlice time) broadBoolContext) ∧\n ¬ Consistent (union (revisionSlice 0) (revisionSlice 1)) broadBoolContext) ∧\n (∀ p q : Claim Bool,\n ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r) ∧\n (Consequence jointTheory jointContext012 () true ∧\n Consequence jointTheory jointContext012 () false ∧\n ¬ Consistent jointTheory jointContext012) :=\n ⟨jointConflict, contextDifferences, hiddenContextChangeRejected, revisionCanReverse, sliceConsistency, semanticOrder012, jointImplicationConflict012⟩\n\n \n \n \n \n \n \n", + "axioms": "[]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.premiseP []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.premiseRule []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.premiseNotQ []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.jointTheory [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consequence [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.assumptionContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.meaningContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.scopeContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.TruthfulReport []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.TruthfulReport []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.TruthfulReport [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.TruthfulReport [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.TruthfulReport [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Models []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Context.assumptions [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.const `Bool.true [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `time\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.revisionSlice []) (Lean.Expr.bvar 0)))\n (Lean.Expr.const `CoreReader.Adopted.broadBoolContext []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.const `CoreReader.Adopted.broadBoolContext [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `p\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `Bool []))\n (Lean.Expr.forallE\n `q\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `Bool []))\n (Lean.Expr.forallE\n `r\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Iff [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 2)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 2)))\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consequence [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.const `CoreReader.Logic.jointTheory []))\n (Lean.Expr.const `CoreReader.Adopted.jointContext012 []))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consequence [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.const `CoreReader.Logic.jointTheory []))\n (Lean.Expr.const `CoreReader.Adopted.jointContext012 []))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consistent [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.const `CoreReader.Logic.jointTheory []))\n (Lean.Expr.const `CoreReader.Adopted.jointContext012 []))))))))))", + "sha256": "16a20441e5650e4992e046ae4eeb2a1867f573730aa1dc402ca70508bb1802a6" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T06", + "kind": "nonentailment", + "registered_statement": "Different-condition disagreement and value tension alone do not entail contradiction; consistency does not entail true assumptions, adequacy or support for a compatible conclusion.", + "sources": [ + { + "unit": "organon.charter.consistency.meaning", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + } + ], + "registered_premises": [ + "Concrete shared interpretation of truth/support and consequence", + "relevant omitted question represented", + "unsupported conclusion must demonstrably fail entailment, not merely have a false support flag." + ], + "disposition": "bounded_countermodels", + "independent_assessment": "Concrete contexts, overlapping inequalities, a consistent theory false at the selected outside world, and empty-theory countervaluations distinguish contradiction, truth, sufficiency and entailment. These support the source limits without relying on a free false support flag.", + "semantic_cases": [ + { + "case": "different_contexts", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Concrete contexts, overlapping inequalities, a consistent theory false at the selected outside world, and empty-theory countervaluations distinguish contradiction, truth, sufficiency and entailment. These support the source limits without relying on a free false support flag." + }, + { + "case": "tension_compatible", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Concrete contexts, overlapping inequalities, a consistent theory false at the selected outside world, and empty-theory countervaluations distinguish contradiction, truth, sufficiency and entailment. These support the source limits without relying on a free false support flag." + }, + { + "case": "consistent_false_assumption", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Concrete contexts, overlapping inequalities, a consistent theory false at the selected outside world, and empty-theory countervaluations distinguish contradiction, truth, sufficiency and entailment. These support the source limits without relying on a free false support flag." + }, + { + "case": "consistent_omitted_question", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Concrete contexts, overlapping inequalities, a consistent theory false at the selected outside world, and empty-theory countervaluations distinguish contradiction, truth, sufficiency and entailment. These support the source limits without relying on a free false support flag." + }, + { + "case": "compatible_not_entailed", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Concrete contexts, overlapping inequalities, a consistent theory false at the selected outside world, and empty-theory countervaluations distinguish contradiction, truth, sufficiency and entailment. These support the source limits without relying on a free false support flag." + } + ], + "declarations": [ + { + "name": "CoreReader.Adopted.consistencyLimits012", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Adopted.lean", + "line": 921, + "end": 948, + "exact_delta_code": "theorem consistencyLimits012 :\n ((Consequence emptyTheory (assumptionContext true) () true ∧\n Consequence emptyTheory (assumptionContext false) () false) ∧\n (Consequence emptyTheory (meaningContext true) () true ∧\n Consequence emptyTheory (meaningContext false) () false) ∧\n (Consequence emptyTheory (scopeContext true) () true ∧\n Consequence emptyTheory (scopeContext false) () false) ∧\n (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧\n (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧\n (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w)) ∧\n ((∃ budget : Nat, 4 ≤ budget ∧ budget ≤ 6) ∧\n ¬ ((fun n : Nat => 4 ≤ n) = (fun n : Nat => n ≤ 6))) ∧\n (Consistent (singleton (fun w : Bool => w = true)) broadBoolContext ∧\n ¬ Models (singleton (fun w : Bool => w = true)) false ∧\n Consistent (emptyTheory : Theory Bool) broadBoolContext ∧\n ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧\n (Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧\n ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧\n (Consistent (union (singleton (fun n : Nat => 4 ≤ n)) (singleton (fun n => n ≤ 6))) tensionContext012) :=\n ⟨contextDifferences, tensionWithoutContradiction, explicitlyConsistentLimits, compatibilityNotEntailment, tensionConsistent012⟩\n\n \n \n \n \n \n \n \n", + "axioms": "[]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Admissible []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.assumptionContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.meaningContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Admissible []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.scopeContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lam\n `budget\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 4)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 4)))))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 6))))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 4)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 4)))))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 6)))))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.broadBoolContext [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Models []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.broadBoolContext [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Nat []))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 4)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 4)))))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Nat []))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 6)))))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.const `CoreReader.Adopted.tensionContext012 [])))))", + "sha256": "1bb1429eb084c222d9a84341c2d6cae05e8c83c1374bbbab8402a372099649cc" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T07", + "kind": "specification", + "registered_statement": "Generation and assessment apply to system and principle formation/application/revision under their actual applicability conditions; self-status is no exemption; applicability is not universalized; Grounds grounds/limits and own capability claims are included.", + "sources": [ + { + "unit": "organon.charter.reflexivity", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + } + ], + "registered_premises": [ + "Explicit target kinds for system, formation, application, revision", + "principle applicability and duties", + "nonempty applicable self-target and inapplicable pair", + "no endless-recursion requirement." + ], + "disposition": "bounded_specification", + "independent_assessment": "The generic adapter keeps self and applicability predicates and exact input/outcome links. The legacy finite model includes system, own principles and formation/application/revision, with an inapplicable system in the application-only example. Grounds-on-grounds has an actual value rationale. Empty generic domains remain possible but are not the supplied positive witness.", + "semantic_cases": [ + { + "case": "self_applicable", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The generic adapter keeps self and applicability predicates and exact input/outcome links. The legacy finite model includes system, own principles and formation/application/revision, with an inapplicable system in the application-only example. Grounds-on-grounds has an actual value rationale. Empty generic domains remain possible but are not the supplied positive witness." + }, + { + "case": "self_inapplicable", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The generic adapter keeps self and applicability predicates and exact input/outcome links. The legacy finite model includes system, own principles and formation/application/revision, with an inapplicable system in the application-only example. Grounds-on-grounds has an actual value rationale. Empty generic domains remain possible but are not the supplied positive witness." + }, + { + "case": "principle_formation", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The generic adapter keeps self and applicability predicates and exact input/outcome links. The legacy finite model includes system, own principles and formation/application/revision, with an inapplicable system in the application-only example. Grounds-on-grounds has an actual value rationale. Empty generic domains remain possible but are not the supplied positive witness." + }, + { + "case": "principle_application", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The generic adapter keeps self and applicability predicates and exact input/outcome links. The legacy finite model includes system, own principles and formation/application/revision, with an inapplicable system in the application-only example. Grounds-on-grounds has an actual value rationale. Empty generic domains remain possible but are not the supplied positive witness." + }, + { + "case": "principle_revision", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The generic adapter keeps self and applicability predicates and exact input/outcome links. The legacy finite model includes system, own principles and formation/application/revision, with an inapplicable system in the application-only example. Grounds-on-grounds has an actual value rationale. Empty generic domains remain possible but are not the supplied positive witness." + }, + { + "case": "grounds_on_grounds", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The generic adapter keeps self and applicability predicates and exact input/outcome links. The legacy finite model includes system, own principles and formation/application/revision, with an inapplicable system in the application-only example. Grounds-on-grounds has an actual value rationale. Empty generic domains remain possible but are not the supplied positive witness." + } + ], + "declarations": [ + { + "name": "CoreReader.Adopted.reflexivitySpecification", + "registered_kind": "definition", + "actual_kind": "def", + "file": "CoreReader/Adopted.lean", + "line": 110, + "end": 116, + "exact_delta_code": "def reflexivitySpecification {T I O : Type} (rules : List (ReflexiveRule T I O))\n (isSelf : T → Prop) (performed : PrincipleKey → T → I → O → Prop) : Prop :=\n (∀ p ∈ rules, ∀ q ∈ rules, p.key = q.key → p = q) ∧\n ∀ rule ∈ rules, ∀ target, isSelf target → rule.applicable target →\n ∃ outcome, performed rule.key target (rule.input target) outcome ∧\n rule.meaning (rule.input target) outcome\n\n", + "axioms": "[]", + "actual_type_record": { + "type": "Lean.Expr.forallE\n `T\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `I\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `O\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `rules\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.forallE\n `isSelf\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 3)\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `performed\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Agency.PrincipleKey [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 5)\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 5)\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 5)\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit))\n (Lean.BinderInfo.implicit))\n (Lean.BinderInfo.implicit)", + "sha256": "d8084253926a4e9a9b2b9d6ccea7fcba129de72b8412ec4bd30c08a9bdf254bc" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + }, + { + "name": "CoreReader.Adopted.reflexivityCases012", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Adopted.lean", + "line": 949, + "end": 971, + "exact_delta_code": "theorem reflexivityCases012 :\n (reflexivitySpecification ((ownRules 0).map legacyRule) (fun s => s.owner = 0)\n (legacyPerformed (ownRules 0) (completeOwnWork 0)) ∧\n (∀ phase, Performed (completeOwnWork 0) (.process 0 0 phase) .assessment) ∧\n Performed (completeOwnWork 0) (.system 0) .assessment ∧\n reflexivitySpecification ([applicationRule].map legacyRule) (fun s => s.owner = 0)\n (legacyPerformed [applicationRule] applicationWork) ∧\n ¬ Performed applicationWork (.system 0) .assessment) ∧\n (Grounds012 (fun enabled => GroundsProvision012 enabled) canonicalArticulation [.value groundsPosition012] (.value groundsPosition012) ∧\n groundsPosition012.limits true ∧ groundsPosition012.relevantCriticism true) ∧\n (Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0) ∧\n groundsExperiment012 true = false ∧ groundsExperiment012 false = true ∧\n groundsPosition012.outcome true true = groundsExperiment012 true ∧\n groundsPosition012.outcome true false = groundsExperiment012 false) :=\n ⟨reflexiveTargets012, groundsOnGrounds012, groundsRationaleExperiment012⟩\n\n \n \n \n \n \n \n \n", + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.reflexivitySpecification [])\n (Lean.Expr.const `CoreReader.Agency.Subject []))\n (Lean.Expr.const `CoreReader.Agency.Inquiry []))\n (Lean.Expr.const `CoreReader.Agency.WorkOutcome []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.map [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule [])\n (Lean.Expr.const `CoreReader.Agency.Subject []))\n (Lean.Expr.const `CoreReader.Agency.Inquiry []))\n (Lean.Expr.const `CoreReader.Agency.WorkOutcome [])))\n (Lean.Expr.const `CoreReader.Adopted.legacyRule []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ownRules [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.lam\n `s\n (Lean.Expr.const `CoreReader.Agency.Subject [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Subject.owner []) (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.legacyPerformed [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ownRules [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.completeOwnWork [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `phase\n (Lean.Expr.const `CoreReader.Agency.Phase [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Performed [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.completeOwnWork [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Subject.process [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `CoreReader.Agency.Activity.assessment []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Performed [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.completeOwnWork [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Subject.system [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `CoreReader.Agency.Activity.assessment [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.reflexivitySpecification [])\n (Lean.Expr.const `CoreReader.Agency.Subject []))\n (Lean.Expr.const `CoreReader.Agency.Inquiry []))\n (Lean.Expr.const `CoreReader.Agency.WorkOutcome []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.map [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule [])\n (Lean.Expr.const `CoreReader.Agency.Subject []))\n (Lean.Expr.const `CoreReader.Agency.Inquiry []))\n (Lean.Expr.const `CoreReader.Agency.WorkOutcome [])))\n (Lean.Expr.const `CoreReader.Adopted.legacyRule []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle []))\n (Lean.Expr.const `CoreReader.Agency.applicationRule []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle [])))))\n (Lean.Expr.lam\n `s\n (Lean.Expr.const `CoreReader.Agency.Subject [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Subject.owner []) (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.legacyPerformed [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle []))\n (Lean.Expr.const `CoreReader.Agency.applicationRule []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle []))))\n (Lean.Expr.const `CoreReader.Agency.applicationWork []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Performed [])\n (Lean.Expr.const `CoreReader.Agency.applicationWork []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Subject.system [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `CoreReader.Agency.Activity.assessment []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.Grounds012 []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `enabled\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.GroundsProvision012 []) (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet.value []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.AssessmentTask.value []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.limits [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.relevantCriticism [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 []))\n (Lean.Expr.const `Bool.true [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.groundsExperiment012 [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.groundsExperiment012 [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Outcome [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.outcome [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.groundsExperiment012 [])\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Outcome [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.outcome [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.groundsExperiment012 [])\n (Lean.Expr.const `Bool.false [])))))))))", + "sha256": "55a9d738a39137aeb7cf0ee474c532a636dc2a59451613848747030a756b29e7" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T08", + "kind": "nonentailment", + "registered_statement": "Self-application or self-produced revision does not establish correctness or sufficient grounds; openness of forms does not by itself meet reflexivity. In the declared representation, one nonempty common context satisfies the complete represented Charter requirements but fails the represented general Grounds requirement for a concrete identified claim. This bounded example shows that chapter placement supplies no deductive support; it does not assert independence in every possible representation.", + "sources": [ + { + "unit": "organon.charter.reflexivity.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + }, + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "organon.grounds", + "clause": "p1" + } + ], + "registered_premises": [ + "Assessment events/duties not truth", + "generation provenance not support", + "concrete countercase with a revisable but self-exempt assessment rule.", + "Complete represented Charter includes the specifications in T02, T04 and T07 with their applicability conditions.", + "General Grounds includes the T09 articulation, corresponding assessment and proportionality requirements. Failure must concern a concrete identified claim, grounds, scope and strength, with a substantive failed support relation, not an empty domain, missing record or freely assigned false label. Grounds is not assumed." + ], + "disposition": "bounded_countermodels", + "independent_assessment": "A revisable principle applied only to target 1 fails required self-target 0; self tests fail elsewhere; owned revisions retain unsupported global claims. CompleteCharter012 is inhabited yet costAllowanceRecord admits an incorrect-output world, so the concrete corresponding Grounds012 claim fails. This is a bounded charter-versus-support model, not philosophical independence in all interpretations.", + "semantic_cases": [ + { + "case": "self_assessed_incorrect", + "disposition": "covered_with_target_scope_qualifications", + "basis": "A revisable principle applied only to target 1 fails required self-target 0; self tests fail elsewhere; owned revisions retain unsupported global claims. CompleteCharter012 is inhabited yet costAllowanceRecord admits an incorrect-output world, so the concrete corresponding Grounds012 claim fails. This is a bounded charter-versus-support model, not philosophical independence in all interpretations." + }, + { + "case": "self_generated_unsupported", + "disposition": "covered_with_target_scope_qualifications", + "basis": "A revisable principle applied only to target 1 fails required self-target 0; self tests fail elsewhere; owned revisions retain unsupported global claims. CompleteCharter012 is inhabited yet costAllowanceRecord admits an incorrect-output world, so the concrete corresponding Grounds012 claim fails. This is a bounded charter-versus-support model, not philosophical independence in all interpretations." + }, + { + "case": "open_but_self_exempt", + "disposition": "covered_with_target_scope_qualifications", + "basis": "A revisable principle applied only to target 1 fails required self-target 0; self tests fail elsewhere; owned revisions retain unsupported global claims. CompleteCharter012 is inhabited yet costAllowanceRecord admits an incorrect-output world, so the concrete corresponding Grounds012 claim fails. This is a bounded charter-versus-support model, not philosophical independence in all interpretations." + }, + { + "case": "charter_not_general_grounds", + "disposition": "covered_with_target_scope_qualifications", + "basis": "A revisable principle applied only to target 1 fails required self-target 0; self tests fail elsewhere; owned revisions retain unsupported global claims. CompleteCharter012 is inhabited yet costAllowanceRecord admits an incorrect-output world, so the concrete corresponding Grounds012 claim fails. This is a bounded charter-versus-support model, not philosophical independence in all interpretations." + } + ], + "declarations": [ + { + "name": "CoreReader.Adopted.reflexivityLimits012", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Adopted.lean", + "line": 972, + "end": 999, + "exact_delta_code": "theorem reflexivityLimits012 :\n (selfTest [1] = true ∧ ownArithmeticPrinciple 0 = false ∧\n ¬ (∀ n, ownArithmeticPrinciple n = true)) ∧\n (localGenerator 0 0 = true ∧ localGenerator 0 1 = false ∧\n Compatible [zeroRecord] (localGenerator 0) ∧\n ¬ Supports [zeroRecord] allTrue ∧ OwnedRevisionExample) ∧\n (Generative openPolicy ∧ ¬ Reflexive 0 (ownRules 0) []) ∧\n (CompleteCharter012 CoreReader.Integration.actualSystem CoreReader.Integration.actual ∧\n Admissible CoreReader.Integration.held CoreReader.Integration.context CoreReader.Integration.actual ∧\n Compatible [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.actual ∧\n Articulated (canonicalArticulation CoreReader.Integration.unsupportedCapabilityFacet) ∧\n ¬ Supports [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.capability ∧\n ¬ Grounds012 CoreReader.Integration.capability canonicalArticulation\n [CoreReader.Integration.unsupportedCapabilityFacet]\n (taskOfFacet CoreReader.Integration.unsupportedCapabilityFacet)) ∧\n (generationSpecification openPolicy ∧ openPolicy.revisable ⟨.principle,0⟩ ∧\n selfExemptPerformed012 ⟨0,1⟩ 1 1 true ∧\n selfExemptRule012.applicable 0 ∧\n ¬ reflexivitySpecification [selfExemptRule012] (fun target => target = 0) selfExemptPerformed012) :=\n ⟨selfTestDoesNotProve, selfOriginDoesNotSupport, generationNotReflexivity, charterWithoutGrounds012, openSelfExempt012⟩\n\n \n \n \n \n \n \n \n", + "axioms": "[propext, Quot.sound.{u}]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.selfTest [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ownArithmeticPrinciple [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.ownArithmeticPrinciple []) (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Evidence.allTrue []))))\n (Lean.Expr.const `CoreReader.Evidence.OwnedRevisionExample []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Reflexive [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ownRules [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.WorkRecord []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.CompleteCharter012 [])\n (Lean.Expr.const `CoreReader.Integration.actualSystem []))\n (Lean.Expr.const `CoreReader.Integration.actual [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.const `CoreReader.Integration.Question []))\n (Lean.Expr.const `CoreReader.Integration.held []))\n (Lean.Expr.const `CoreReader.Integration.context []))\n (Lean.Expr.const `CoreReader.Integration.actual [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Integration.World [])))\n (Lean.Expr.const `CoreReader.Integration.costAllowanceRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Integration.World [])))))\n (Lean.Expr.const `CoreReader.Integration.actual [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulated [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.const `CoreReader.Integration.unsupportedCapabilityFacet []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Integration.World [])))\n (Lean.Expr.const `CoreReader.Integration.costAllowanceRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Integration.World [])))))\n (Lean.Expr.const `CoreReader.Integration.capability []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.const `CoreReader.Integration.capability []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Integration.World [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Integration.World [])))\n (Lean.Expr.const `CoreReader.Integration.unsupportedCapabilityFacet []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Integration.World [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.const `CoreReader.Integration.unsupportedCapabilityFacet []))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.generationSpecification [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.revisable [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Form.mk [])\n (Lean.Expr.const `CoreReader.Agency.FormKind.principle []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.selfExemptPerformed012 [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.PrincipleKey.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule.applicable [])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.selfExemptRule012 []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.reflexivitySpecification [])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule [])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.selfExemptRule012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule [])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool [])))))\n (Lean.Expr.lam\n `target\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.selfExemptPerformed012 []))))))))))", + "sha256": "6aaa9a96ab7f8fe3ebe04633ee7e9ae054eafa88e7e8289179d143ee96e46d05" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T09", + "kind": "specification", + "registered_statement": "Grounds requires articulable concepts/assumptions/reasons/limits, assessment appropriate to claim nature, and strength/scope proportionate to supplied support. Articulation and assessment are distinct responsibilities.", + "sources": [ + { + "unit": "organon.grounds", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + } + ], + "registered_premises": [ + "Grounds tied to corresponding claim and context", + "explicit support relation, force and scope", + "no universal numeric scale or complete mutually exclusive taxonomy", + "Core 0.1.2 only." + ], + "disposition": "qualified_success_specification", + "independent_assessment": "Grounds012 formalizes successful supported grounds for one declared task using same claim/articulation/discharge and task-appropriateness. Local/global and stronger-claim countermodels preserve force and scope. It is not a complete classifier or universal procedure for deciding all possible mixed claims. Calling it the obligation to examine rather than the successful support condition would overstate the correspondence.", + "semantic_cases": [ + { + "case": "articulable_supported", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Grounds012 formalizes successful supported grounds for one declared task using same claim/articulation/discharge and task-appropriateness. Local/global and stronger-claim countermodels preserve force and scope. It is not a complete classifier or universal procedure for deciding all possible mixed claims. Calling it the obligation to examine rather than the successful support condition would overstate the correspondence." + }, + { + "case": "articulable_unsupported", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Grounds012 formalizes successful supported grounds for one declared task using same claim/articulation/discharge and task-appropriateness. Local/global and stronger-claim countermodels preserve force and scope. It is not a complete classifier or universal procedure for deciding all possible mixed claims. Calling it the obligation to examine rather than the successful support condition would overstate the correspondence." + }, + { + "case": "scope_overreach", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Grounds012 formalizes successful supported grounds for one declared task using same claim/articulation/discharge and task-appropriateness. Local/global and stronger-claim countermodels preserve force and scope. It is not a complete classifier or universal procedure for deciding all possible mixed claims. Calling it the obligation to examine rather than the successful support condition would overstate the correspondence." + }, + { + "case": "strength_overreach", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Grounds012 formalizes successful supported grounds for one declared task using same claim/articulation/discharge and task-appropriateness. Local/global and stronger-claim countermodels preserve force and scope. It is not a complete classifier or universal procedure for deciding all possible mixed claims. Calling it the obligation to examine rather than the successful support condition would overstate the correspondence." + } + ], + "declarations": [ + { + "name": "CoreReader.Adopted.Grounds012", + "registered_kind": "definition", + "actual_kind": "def", + "file": "CoreReader/Adopted.lean", + "line": 54, + "end": 63, + "exact_delta_code": "def Grounds012 {W : Type} (claim : Claim W)\n (articulations : Facet W → Articulation W) (facets : List (Facet W))\n (task : AssessmentTask W) : Prop :=\n facets ≠ [] ∧ ∀ facet ∈ facets,\n facet.claim = claim ∧ Articulated (articulations facet) ∧\n FacetArticulated (articulations facet) facet ∧ FacetDischarged facet ∧\n NatureAppropriate task facet\n\n \n \n", + "axioms": "[propext]", + "actual_type_record": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `claim\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `articulations\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.bvar 1))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Articulation []) (Lean.Expr.bvar 2))\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `facets\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.bvar 2)))\n (Lean.Expr.forallE\n `task\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.AssessmentTask []) (Lean.Expr.bvar 3))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)", + "sha256": "65ead33e1cc510ec07082dde80dbec28ca36d80391c18e2ca6df7ed3e1353029" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + }, + { + "name": "CoreReader.Adopted.groundsCases012", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Adopted.lean", + "line": 1000, + "end": 1015, + "exact_delta_code": "theorem groundsCases012 :\n (Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧\n Articulated (canonicalArticulation globalFacet012) ∧\n ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧\n ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012)) ∧\n (Articulated uninformativeArgument ∧\n ¬ Entails uninformativeArgument.assumptions (fun w : Bool => w = true)) ∧\n (Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] (taskOfFacet circularGlobalFacet012) ∧\n ¬ NatureAppropriate originalGlobalTask012 circularGlobalFacet012 ∧\n ¬ Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] originalGlobalTask012) :=\n ⟨scopeStrength012, articulationNotSupport, circularSubstitutionRejected012⟩\n\n \n \n \n \n", + "axioms": "[propext]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulated [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Articulated []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.uninformativeArgument [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulation.assumptions [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.uninformativeArgument [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Evidence.allTrue []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.circularGlobalFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.circularGlobalFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.NatureAppropriate [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.originalGlobalTask012 []))\n (Lean.Expr.const `CoreReader.Adopted.circularGlobalFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Evidence.allTrue []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.circularGlobalFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Adopted.originalGlobalTask012 []))))))", + "sha256": "5d659ec603f559d1be5abf4df0466b2daee1633dcfbf70194c0b8ccf9640e40f" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T10", + "kind": "specification", + "registered_statement": "Empirical assessment examines observations, evidence and performance and their support conditions, scope and uncertainty; measurability/repeatability is no replacement for relevance, correctness or value assessment.", + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "p2" + } + ], + "registered_premises": [ + "Actual empirical content and relevant relation from observations to claim", + "measurement/repetition is evidence property, not automatic support", + "finite adapter remains limited." + ], + "disposition": "bounded_success_specification", + "independent_assessment": "Empirical discharge includes an in-scope compatible witness, scoped support and uncertainty support. Repetition of irrelevant first-coordinate/action observations cannot establish the second coordinate or budget value. The successful uncertainty is the exhaustive Boolean disjunction, not a quantified confidence estimate or a production measurement.", + "semantic_cases": [ + { + "case": "observed_relevant", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Empirical discharge includes an in-scope compatible witness, scoped support and uncertainty support. Repetition of irrelevant first-coordinate/action observations cannot establish the second coordinate or budget value. The successful uncertainty is the exhaustive Boolean disjunction, not a quantified confidence estimate or a production measurement." + }, + { + "case": "repeatable_irrelevant", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Empirical discharge includes an in-scope compatible witness, scoped support and uncertainty support. Repetition of irrelevant first-coordinate/action observations cannot establish the second coordinate or budget value. The successful uncertainty is the exhaustive Boolean disjunction, not a quantified confidence estimate or a production measurement." + }, + { + "case": "measured_wrong_scope", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Empirical discharge includes an in-scope compatible witness, scoped support and uncertainty support. Repetition of irrelevant first-coordinate/action observations cannot establish the second coordinate or budget value. The successful uncertainty is the exhaustive Boolean disjunction, not a quantified confidence estimate or a production measurement." + }, + { + "case": "uncertain_limited", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Empirical discharge includes an in-scope compatible witness, scoped support and uncertainty support. Repetition of irrelevant first-coordinate/action observations cannot establish the second coordinate or budget value. The successful uncertainty is the exhaustive Boolean disjunction, not a quantified confidence estimate or a production measurement." + } + ], + "declarations": [ + { + "name": "CoreReader.Adopted.empiricalSpecification", + "registered_kind": "definition", + "actual_kind": "def", + "file": "CoreReader/Adopted.lean", + "line": 152, + "end": 160, + "exact_delta_code": "def empiricalSpecification {W : Type} (records : List (Record W))\n (scope claim uncertainty : Claim W) : Prop :=\n Grounds012 claim canonicalArticulation [.empirical records scope claim uncertainty]\n (.empirical records scope claim uncertainty)\n\n \n \n \n \n", + "axioms": "[propext]", + "actual_type_record": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `records\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Record []) (Lean.Expr.bvar 0)))\n (Lean.Expr.forallE\n `scope\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.bvar 1))\n (Lean.Expr.forallE\n `claim\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.bvar 2))\n (Lean.Expr.forallE\n `uncertainty\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.bvar 3))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)", + "sha256": "9f534ab1f51da3b82f8edf1d35b0dfab34dfe042d10c44582f04b4dce6569ef2" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + }, + { + "name": "CoreReader.Adopted.empiricalCases012", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Adopted.lean", + "line": 1016, + "end": 1047, + "exact_delta_code": "theorem empiricalCases012 :\n (Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧\n Articulated (canonicalArticulation globalFacet012) ∧\n ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧\n ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012)) ∧\n (temperatureRecord.test (true,false) = true ∧\n Compatible [temperatureRecord,temperatureRecord] (true,false) ∧\n Compatible [temperatureRecord,temperatureRecord] (true,true) ∧\n ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧\n ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧\n Compatible [actionRecord,actionRecord] (true,0) ∧\n Compatible [actionRecord,actionRecord] (true,3) ∧\n ¬ Supports [actionRecord] announcementPosition.consequence ∧\n ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧\n ¬ ValueProcedure announcementPosition) ∧\n (empiricalSpecification [temperatureRecord, temperatureRecord] (fun _ => True)\n (fun w => w.1 = true) (fun w => w.2 = true ∨ w.2 = false) ∧\n Compatible [temperatureRecord, temperatureRecord] (true,true) ∧\n Compatible [temperatureRecord, temperatureRecord] (true,false)) ∧\n (Grounds012 (fun f => f 0 = true) canonicalArticulation [localFacet012] originalLocalTask012 ∧\n Grounds012 (fun f => f 0 = true) canonicalArticulation [observedInferenceFacet012] originalLocalTask012) ∧\n (FacetDischarged uncertaintyBypassFacet012 ∧\n ¬ NatureAppropriate originalUncertaintyTask012 uncertaintyBypassFacet012 ∧\n ¬ Grounds012 (fun w : Bool × Bool => w.1 = true) canonicalArticulation\n [uncertaintyBypassFacet012] originalUncertaintyTask012) :=\n ⟨scopeStrength012, measurementRepeatNotSupport, uncertainSupported012, sameEmpiricalTaskTwoMethods012, uncertaintySubstitutionRejected012⟩\n\n \n \n \n \n \n", + "axioms": "[propext]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulated [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record.test [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 3)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.consequence [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.consequence [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.empiricalSpecification [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 577346429) \"_hygCtx\") \"_hyg\") 256)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `True [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.fst [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Or [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.false [])))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.bvar 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Adopted.originalLocalTask012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.bvar 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.observedInferenceFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Adopted.originalLocalTask012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.FacetDischarged [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.uncertaintyBypassFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.NatureAppropriate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.originalUncertaintyTask012 []))\n (Lean.Expr.const `CoreReader.Adopted.uncertaintyBypassFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.fst [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Adopted.uncertaintyBypassFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))))\n (Lean.Expr.const `CoreReader.Adopted.originalUncertaintyTask012 []))))))))", + "sha256": "fba89ddcd1cf1f745deec2bbdb86e1434e01d6fc73f99c6bf690331560f736f6" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T11", + "kind": "specification", + "registered_statement": "Inferential assessment examines whether conclusion follows/supports under stated assumptions and inferential relations; mere nonconflict cannot replace this examination.", + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + } + ], + "registered_premises": [ + "A concrete inference semantics and countervaluation when lack of entailment is claimed", + "distinguish task of examination from successful conclusion." + ], + "disposition": "qualified_success_specification", + "independent_assessment": "The inferential wrapper requires satisfiable assumptions and actual entailment. Correct rejection of an unentailed conclusion is represented separately by InferenceExamined false and a countervaluation. Together they preserve the examination/success distinction, provided the wrapper alone is not described as the full act of assessment.", + "semantic_cases": [ + { + "case": "valid_inference", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The inferential wrapper requires satisfiable assumptions and actual entailment. Correct rejection of an unentailed conclusion is represented separately by InferenceExamined false and a countervaluation. Together they preserve the examination/success distinction, provided the wrapper alone is not described as the full act of assessment." + }, + { + "case": "compatible_unentailed", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The inferential wrapper requires satisfiable assumptions and actual entailment. Correct rejection of an unentailed conclusion is represented separately by InferenceExamined false and a countervaluation. Together they preserve the examination/success distinction, provided the wrapper alone is not described as the full act of assessment." + }, + { + "case": "false_inference_detected", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The inferential wrapper requires satisfiable assumptions and actual entailment. Correct rejection of an unentailed conclusion is represented separately by InferenceExamined false and a countervaluation. Together they preserve the examination/success distinction, provided the wrapper alone is not described as the full act of assessment." + } + ], + "declarations": [ + { + "name": "CoreReader.Adopted.inferentialSpecification", + "registered_kind": "definition", + "actual_kind": "def", + "file": "CoreReader/Adopted.lean", + "line": 161, + "end": 167, + "exact_delta_code": "def inferentialSpecification {W : Type} (assumptions : Theory W) (claim : Claim W) : Prop :=\n Grounds012 claim canonicalArticulation [.inferential assumptions claim] (.inferential assumptions claim)\n\n \n \n \n \n", + "axioms": "[propext]", + "actual_type_record": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `assumptions\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Theory []) (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `claim\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.bvar 1))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)", + "sha256": "d56b013c37bfeb071f171cb3f552b8775a79eee535305a78d2d9551b86c03c16" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + }, + { + "name": "CoreReader.Adopted.inferentialCases012", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Adopted.lean", + "line": 1048, + "end": 1064, + "exact_delta_code": "theorem inferentialCases012 :\n (inferentialSpecification (singleton (fun n : Nat => n = 2)) (fun n => n + 1 = 3) ∧\n InferenceExamined (emptyTheory : Theory Bool) (fun w => w = true) false ∧\n Models (emptyTheory : Theory Bool) false ∧ ¬ ((fun w : Bool => w = true) false)) ∧\n (Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧\n ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧\n (FacetDischarged (Facet.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) ∧\n ¬ Grounds012 (fun w : Bool => w = true) canonicalArticulation\n [.inferential (singleton (fun w => w = true)) (fun w => w = true)]\n (.inferential emptyTheory (fun w => w = true))) :=\n ⟨inferenceChecked012, compatibilityNotEntailment, inferentialContextSubstitutionRejected012⟩\n\n \n \n \n \n \n", + "axioms": "[propext]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.inferentialSpecification []) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Nat []))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `HAdd.hAdd [Lean.Level.zero, Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `instHAdd [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instAddNat [])))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.InferenceExamined []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Models []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))\n (Lean.Expr.const `Bool.false [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.FacetDischarged []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet.inferential []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.Grounds012 []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.inferential [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.AssessmentTask.inferential [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))))", + "sha256": "b37768f2ff32da55daf97b29dc027bfa78aa1a1f2456c80937dde7aa64a5c515" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T12", + "kind": "specification", + "registered_statement": "Value commitments identify position, reasons, applicability limits and consequences and stay open to relevant criticism; neither empirical/necessary-inference presentation nor self-assertion substitutes. Initial commitments need not prove all starting assumptions.", + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + } + ], + "registered_premises": [ + "Stated value stance distinct from factual claims", + "reason interface without recursive proof demand", + "relevant criticism condition", + "qualitative support comparisons allowed." + ], + "disposition": "qualified_value_procedure", + "independent_assessment": "The value construction identifies position, joint reasons, application limits, consequences and relevant criticism responses. It assumes starting claims and supplies a joint witness instead of proving every starting assumption. The universal consequence test and response nonemptiness are this application's sufficient procedure, not newly mandatory philosophical proof requirements or proof of response adequacy.", + "semantic_cases": [ + { + "case": "reasoned_value", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The value construction identifies position, joint reasons, application limits, consequences and relevant criticism responses. It assumes starting claims and supplies a joint witness instead of proving every starting assumption. The universal consequence test and response nonemptiness are this application's sufficient procedure, not newly mandatory philosophical proof requirements or proof of response adequacy." + }, + { + "case": "unsupported_self_assertion", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The value construction identifies position, joint reasons, application limits, consequences and relevant criticism responses. It assumes starting claims and supplies a joint witness instead of proving every starting assumption. The universal consequence test and response nonemptiness are this application's sufficient procedure, not newly mandatory philosophical proof requirements or proof of response adequacy." + }, + { + "case": "closed_criticism", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The value construction identifies position, joint reasons, application limits, consequences and relevant criticism responses. It assumes starting claims and supplies a joint witness instead of proving every starting assumption. The universal consequence test and response nonemptiness are this application's sufficient procedure, not newly mandatory philosophical proof requirements or proof of response adequacy." + }, + { + "case": "explicit_initial_commitment", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The value construction identifies position, joint reasons, application limits, consequences and relevant criticism responses. It assumes starting claims and supplies a joint witness instead of proving every starting assumption. The universal consequence test and response nonemptiness are this application's sufficient procedure, not newly mandatory philosophical proof requirements or proof of response adequacy." + } + ], + "declarations": [ + { + "name": "CoreReader.Adopted.valueSpecification", + "registered_kind": "definition", + "actual_kind": "def", + "file": "CoreReader/Adopted.lean", + "line": 168, + "end": 173, + "exact_delta_code": "def valueSpecification {W : Type} (position : ValuePosition W) : Prop :=\n Grounds012 position.commitment canonicalArticulation [.value position] (.value position)\n\n \n \n \n", + "axioms": "[propext]", + "actual_type_record": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `position\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.ValuePosition []) (Lean.Expr.bvar 0))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)", + "sha256": "1f45a163b8b2a0db44eeaeb0910e0af6168e4674ab3a3925dcfe54e3015e3ae6" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + }, + { + "name": "CoreReader.Adopted.valueCases012", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Adopted.lean", + "line": 1065, + "end": 1085, + "exact_delta_code": "theorem valueCases012 :\n (valueSpecification switchPosition) ∧\n (announcementPosition.reasons ≠ [] ∧ announcementPosition.commitment (true,0) ∧\n (∀ reason, reason ∈ announcementPosition.reasons → reason (true,0) announcementPosition.adopted) ∧\n ¬ announcementPosition.consequence (true,0) ∧ ¬ ValueProcedure announcementPosition) ∧\n (¬ ValueProcedure closedPosition012) ∧\n (ValueProcedure switchPosition ∧\n Satisfiable switchPosition.starting ∧\n ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧\n (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧\n (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition)) ∧\n (FacetDischarged selectedFactFacet012 ∧ valueSpecification switchPosition ∧\n ¬ Grounds012 switchPosition.commitment canonicalArticulation [selectedFactFacet012] (.value switchPosition)) :=\n ⟨valueFulfilled012, announcementNotBudgetReason, closedCriticism012, valueWithoutSelfProof, valueFactSubstitutionRejected012⟩\n\n \n \n \n \n \n \n", + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.valueSpecification []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.reasons [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `reason\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.reasons [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.bvar 1)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.adopted [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.consequence [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.ValueProcedure []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.closedPosition012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.ValueProcedure []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.starting [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.JointAdoption [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.oppositePosition [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.oppositePosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.contradictoryStartingPosition []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.impossibleAdoptionPosition [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.FacetDischarged []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.selectedFactFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.valueSpecification []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.Grounds012 []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.selectedFactFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.AssessmentTask.value [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))))))))", + "sha256": "ce1dba18fb8bf4611fe703b21270e3b59591f6f1cf1c40f2ee03899fa26c142a" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T13", + "kind": "nonentailment", + "registered_statement": "Articulability alone does not establish grounds; measurable/repeatable observations alone establish neither relevance, correctness nor value; a stated value commitment need not be empirical fact or necessary consequence, nor prove all its starting assumptions.", + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + } + ], + "registered_premises": [ + "Concrete inadequacy criterion for each countercase", + "avoid defining insufficient support as missing record only", + "empirical/inferential/value readings not made exhaustive or exclusive." + ], + "disposition": "bounded_countermodels", + "independent_assessment": "Clearly articulated false assumptions, repeated wrong-object observations, neutral records compatible with nonadoption, and the ordinary value example show the intended non-substitutions. Qualitative implication orders claim strength without imposing a numerical scale.", + "semantic_cases": [ + { + "case": "clear_false_reason", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Clearly articulated false assumptions, repeated wrong-object observations, neutral records compatible with nonadoption, and the ordinary value example show the intended non-substitutions. Qualitative implication orders claim strength without imposing a numerical scale." + }, + { + "case": "repeatable_wrong_object", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Clearly articulated false assumptions, repeated wrong-object observations, neutral records compatible with nonadoption, and the ordinary value example show the intended non-substitutions. Qualitative implication orders claim strength without imposing a numerical scale." + }, + { + "case": "value_not_fact", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Clearly articulated false assumptions, repeated wrong-object observations, neutral records compatible with nonadoption, and the ordinary value example show the intended non-substitutions. Qualitative implication orders claim strength without imposing a numerical scale." + }, + { + "case": "initial_value_without_selfproof", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Clearly articulated false assumptions, repeated wrong-object observations, neutral records compatible with nonadoption, and the ordinary value example show the intended non-substitutions. Qualitative implication orders claim strength without imposing a numerical scale." + }, + { + "case": "qualitative_proportionality", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Clearly articulated false assumptions, repeated wrong-object observations, neutral records compatible with nonadoption, and the ordinary value example show the intended non-substitutions. Qualitative implication orders claim strength without imposing a numerical scale." + } + ], + "declarations": [ + { + "name": "CoreReader.Adopted.groundsLimits012", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Adopted.lean", + "line": 1086, + "end": 1117, + "exact_delta_code": "theorem groundsLimits012 :\n (Articulated clearFalseArgument012 ∧ ¬ Models clearFalseArgument012.assumptions false) ∧\n (temperatureRecord.test (true,false) = true ∧\n Compatible [temperatureRecord,temperatureRecord] (true,false) ∧\n Compatible [temperatureRecord,temperatureRecord] (true,true) ∧\n ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧\n ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧\n Compatible [actionRecord,actionRecord] (true,0) ∧\n Compatible [actionRecord,actionRecord] (true,3) ∧\n ¬ Supports [actionRecord] announcementPosition.consequence ∧\n ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧\n ¬ ValueProcedure announcementPosition) ∧\n (valueSpecification switchPosition ∧\n Compatible [valueNeutralRecord012] false ∧\n ¬ Supports [valueNeutralRecord012] switchPosition.commitment ∧\n ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment) ∧\n (ValueProcedure switchPosition ∧\n Satisfiable switchPosition.starting ∧\n ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧\n (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧\n (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition)) ∧\n (ClaimNoStronger (fun f : Nat → Bool => f 0 = true) allTrue ∧\n ¬ ClaimNoStronger allTrue (fun f : Nat → Bool => f 0 = true) ∧\n valueSpecification switchPosition) :=\n ⟨clearFalseReason012, measurementRepeatNotSupport, valueNotFact012, valueWithoutSelfProof, qualitativeProportionality012⟩\n\n \n \n \n \n \n \n", + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Articulated []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.clearFalseArgument012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Models []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulation.assumptions [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.clearFalseArgument012 [])))\n (Lean.Expr.const `Bool.false [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record.test [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 3)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.consequence [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.consequence [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.valueSpecification []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Compatible []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Record []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.valueNeutralRecord012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Record []) (Lean.Expr.const `Bool [])))))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Supports []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Record []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.valueNeutralRecord012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Record []) (Lean.Expr.const `Bool [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.ValueProcedure []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.starting [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.JointAdoption [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.oppositePosition [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.oppositePosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.contradictoryStartingPosition []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.impossibleAdoptionPosition [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ClaimNoStronger [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.bvar 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ClaimNoStronger [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Evidence.allTrue []))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.bvar 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.valueSpecification []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))))))", + "sha256": "b404dce33c3fbf86c65d3824e2fceaf5f0a1f312ce1edc1f0a9e9251af9ccad3" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T14", + "kind": "specification", + "registered_statement": "Performance/comparison judgments state relevant relations, conditions and observation scope; scope omission cannot establish absence of relevant differences; roles of measurement, repetition and framework are explained relative to claim/context.", + "sources": [ + { + "unit": "organon.grounds.scope", + "clause": "p1" + }, + { + "unit": "organon.grounds.scope", + "clause": "p2" + }, + { + "unit": "organon.grounds.scope", + "clause": "p3" + } + ], + "registered_premises": [ + "Local and broader scopes and relevance relation distinct", + "explanation of actually used method does not require all three methods universally." + ], + "disposition": "qualified_scope_specification", + "independent_assessment": "The local scope account binds comparison pairs, conditions, observed scope, relevance and each method explanation to the same claim. Its concrete method meanings prove local/repeated support and failure of global support. The generic explains relation remains supplied and the interface does not force every method to be used.", + "semantic_cases": [ + { + "case": "local_scope_declared", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The local scope account binds comparison pairs, conditions, observed scope, relevance and each method explanation to the same claim. Its concrete method meanings prove local/repeated support and failure of global support. The generic explains relation remains supplied and the interface does not force every method to be used." + }, + { + "case": "omitted_relevant_difference", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The local scope account binds comparison pairs, conditions, observed scope, relevance and each method explanation to the same claim. Its concrete method meanings prove local/repeated support and failure of global support. The generic explains relation remains supplied and the interface does not force every method to be used." + }, + { + "case": "measurement_role", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The local scope account binds comparison pairs, conditions, observed scope, relevance and each method explanation to the same claim. Its concrete method meanings prove local/repeated support and failure of global support. The generic explains relation remains supplied and the interface does not force every method to be used." + }, + { + "case": "repetition_role", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The local scope account binds comparison pairs, conditions, observed scope, relevance and each method explanation to the same claim. Its concrete method meanings prove local/repeated support and failure of global support. The generic explains relation remains supplied and the interface does not force every method to be used." + }, + { + "case": "framework_role", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The local scope account binds comparison pairs, conditions, observed scope, relevance and each method explanation to the same claim. Its concrete method meanings prove local/repeated support and failure of global support. The generic explains relation remains supplied and the interface does not force every method to be used." + } + ], + "declarations": [ + { + "name": "CoreReader.Adopted.scopeSpecification", + "registered_kind": "definition", + "actual_kind": "def", + "file": "CoreReader/Adopted.lean", + "line": 191, + "end": 204, + "exact_delta_code": "def scopeSpecification {W : Type} (account : ScopeAccount W) : Prop :=\n (∀ a b, account.compared a b → account.conditions a ∧ account.conditions b ∧\n account.observationScope a ∧ account.observationScope b ∧ account.relevant a b) ∧\n ∀ method, account.used method → account.role method ≠ \"\" ∧\n account.explains method (account.role method) account.claim account.conditions\n\n \n \n \n \n \n \n \n \n", + "axioms": "[]", + "actual_type_record": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `account\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.ScopeAccount []) (Lean.Expr.bvar 0))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)", + "sha256": "01857cd86d39ca8bc2d54d15555ebed9fc9fa6a0bd40196743e5f1fbbcb966b7" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + }, + { + "name": "CoreReader.Adopted.scopeCases012", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Adopted.lean", + "line": 1118, + "end": 1130, + "exact_delta_code": "theorem scopeCases012 :\n (scopeSpecification localScopeAccount012) ∧\n ((∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧\n (fun _ : Nat => true) 1 ≠ localGenerator 0 1) :=\n ⟨scopeFulfilled012, hiddenDifference⟩\n\n \n \n \n \n \n \n \n", + "axioms": "[propext]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.scopeSpecification []) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Adopted.localScopeAccount012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 3351349031) \"_hygCtx\") \"_hyg\") 37)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.bvar 1)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 3351349031) \"_hygCtx\") \"_hyg\") 54)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))", + "sha256": "e503dd4f8dacf02303b9bd7e56977a56feee218c1c677d8836c15039e83655a8" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T15", + "kind": "nonentailment", + "registered_statement": "Local equal performance does not entail global equivalence/unconditional universality; omitting a difference does not establish its nonexistence. Limited unreproduced support and variable random outcomes are possible without a universal measurement→repeatability→framework chain.", + "sources": [ + { + "unit": "organon.grounds.scope", + "clause": "p1" + }, + { + "unit": "organon.grounds.scope", + "clause": "p2" + }, + { + "unit": "organon.grounds.scope", + "clause": "p3" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "p1" + } + ], + "registered_premises": [ + "Explicit nonempty local and broader domains, shared observations and relation", + "verifiability, reproducible conditions and stable conclusions modeled separately", + "unreproduced is not necessarily irreproducible." + ], + "disposition": "bounded_countermodels", + "independent_assessment": "Explicit functions agree only at zero and differ at one; one observation supplies local support. Trial fields separate recorded accuracy, equal settings and bounded output, and Boolean draws have equal positive weights with different outcomes. This is a finite possible-outcome model, not verification of a real stochastic process.", + "semantic_cases": [ + { + "case": "equal_local_different_global", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Explicit functions agree only at zero and differ at one; one observation supplies local support. Trial fields separate recorded accuracy, equal settings and bounded output, and Boolean draws have equal positive weights with different outcomes. This is a finite possible-outcome model, not verification of a real stochastic process." + }, + { + "case": "excluded_difference", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Explicit functions agree only at zero and differ at one; one observation supplies local support. Trial fields separate recorded accuracy, equal settings and bounded output, and Boolean draws have equal positive weights with different outcomes. This is a finite possible-outcome model, not verification of a real stochastic process." + }, + { + "case": "one_observation_limited_support", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Explicit functions agree only at zero and differ at one; one observation supplies local support. Trial fields separate recorded accuracy, equal settings and bounded output, and Boolean draws have equal positive weights with different outcomes. This is a finite possible-outcome model, not verification of a real stochastic process." + }, + { + "case": "varying_random_outcomes", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Explicit functions agree only at zero and differ at one; one observation supplies local support. Trial fields separate recorded accuracy, equal settings and bounded output, and Boolean draws have equal positive weights with different outcomes. This is a finite possible-outcome model, not verification of a real stochastic process." + }, + { + "case": "qualitative_unmeasured_judgment", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Explicit functions agree only at zero and differ at one; one observation supplies local support. Trial fields separate recorded accuracy, equal settings and bounded output, and Boolean draws have equal positive weights with different outcomes. This is a finite possible-outcome model, not verification of a real stochastic process." + } + ], + "declarations": [ + { + "name": "CoreReader.Adopted.scopeLimits012", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Adopted.lean", + "line": 1131, + "end": 1165, + "exact_delta_code": "theorem scopeLimits012 :\n ((∃ outside : Nat, outside ≠ 0) ∧\n Compatible [zeroRecord] (fun _ => true) ∧\n Compatible [zeroRecord] (localGenerator 0) ∧\n allTrue (fun _ => true) ∧ ¬ allTrue (localGenerator 0) ∧\n ¬ Supports [zeroRecord] allTrue) ∧\n ((∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧\n (fun _ : Nat => true) 1 ≠ localGenerator 0 1) ∧\n ([zeroRecord].length = 1 ∧\n (∃ f, Compatible [zeroRecord] f) ∧\n Supports [zeroRecord] (fun f => f 0 = true) ∧\n ¬ Supports [zeroRecord] allTrue) ∧\n (let a : Trial := ⟨0,1,1⟩\n let b : Trial := ⟨0,2,2⟩\n Reproduced a b ∧ a.actualOutcome ≠ b.actualOutcome ∧ Bounded a ∧ Bounded b) ∧\n ((Verified ⟨0,1,1⟩ ∧ Verified ⟨1,1,1⟩ ∧ ¬ Reproduced ⟨0,1,1⟩ ⟨1,1,1⟩) ∧\n (Reproduced ⟨0,1,1⟩ ⟨0,3,2⟩ ∧ ¬ Verified ⟨0,3,2⟩ ∧ ¬ Bounded ⟨0,3,2⟩) ∧\n (Bounded ⟨0,1,1⟩ ∧ Bounded ⟨0,2,0⟩ ∧ ¬ Verified ⟨0,2,0⟩)) ∧\n (FacetDischarged arithmeticFacet ∧ usesObservation arithmeticFacet = false) ∧\n (inferentialSpecification (singleton (fun on : Bool => on = true)) (fun on => on ≠ false) ∧\n usesObservation (Facet.inferential (singleton (fun on : Bool => on = true)) (fun on => on ≠ false)) = false) ∧\n (drawWeight012 true > 0 ∧ drawWeight012 false > 0 ∧\n drawWeight012 true = drawWeight012 false ∧\n Reproduced (randomTrial012 true) (randomTrial012 false) ∧\n (randomTrial012 true).actualOutcome ≠ (randomTrial012 false).actualOutcome ∧\n (∀ draw, Verified (randomTrial012 draw) ∧ Bounded (randomTrial012 draw))) :=\n ⟨localNotUniversal, hiddenDifference, singleObservation, variableOutcomesStableBound, verificationReproductionStability, noUniversalChain, qualitativeUnmeasured012, randomOutcomes012⟩\n\n \n \n \n \n \n \n \n", + "axioms": "[propext, Quot.sound.{u}]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lam\n `outside\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 27637535) \"_hygCtx\") \"_hyg\") 38)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 27637535) \"_hygCtx\") \"_hyg\") 62)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 27637535) \"_hygCtx\") \"_hyg\") 117)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.bvar 1)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 27637535) \"_hygCtx\") \"_hyg\") 134)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.bvar 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.letE\n `a\n (Lean.Expr.const `CoreReader.Evidence.Trial [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.letE\n `b\n (Lean.Expr.const `CoreReader.Evidence.Trial [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Reproduced []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.actualOutcome [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Trial.actualOutcome []) (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Bounded []) (Lean.Expr.bvar 1)))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Bounded []) (Lean.Expr.bvar 0)))))\n true)\n true))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Verified [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Verified [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Reproduced [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Reproduced [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Verified [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2))))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Bounded [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Bounded [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Bounded [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Verified [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.FacetDischarged []) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Evidence.arithmeticFacet [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.usesObservation [])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Evidence.arithmeticFacet [])))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.inferentialSpecification [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `on\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.lam\n `on\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.false []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.usesObservation [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.inferential [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `on\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.lam\n `on\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.false []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `GT.gt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.drawWeight012 [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `GT.gt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.drawWeight012 [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.drawWeight012 [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.drawWeight012 [])\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Reproduced [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.actualOutcome [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.actualOutcome [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.const `Bool.false [])))))\n (Lean.Expr.forallE\n `draw\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Verified [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Bounded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.bvar 0))))\n (Lean.BinderInfo.default)))))))))))))", + "sha256": "a286f42a08d68addaec58cb6b0b9656968db614439bd753425f3972b29d8125c" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T16", + "kind": "specification", + "registered_statement": "Capability claim identifies capability, conditions and support under Grounds; applications choose relevant capability definitions and may require understanding/explanation/variation. External assessors may provide grounds; own-system claims receive same relevant duties.", + "sources": [ + { + "unit": "organon.grounds.capabilities", + "clause": "p1" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + } + ], + "registered_premises": [ + "Claim-indexed capability, externally supplied support and actual scope", + "no universal capability levels or introspective requirement." + ], + "disposition": "partial_case_correspondence", + "independent_assessment": "Output-only and explained doubling processes establish the source's external-assessment and application-specific explanation branches. The required semantic case named application_requires_understanding is not yet accepted as an understanding result: ExplanationContract only requires a stored Program extensionally equal to the output. No independent process-understanding criterion is modeled. The source allows applications to define capabilities, but that definition and this loss must be explicit rather than equating any output-equivalent program with understanding.", + "semantic_cases": [ + { + "case": "external_output_capability", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Output-only and explained doubling processes establish the source's external-assessment and application-specific explanation branches. The required semantic case named application_requires_understanding is not yet accepted as an understanding result: ExplanationContract only requires a stored Program extensionally equal to the output. No independent process-understanding criterion is modeled. The source allows applications to define capabilities, but that definition and this loss must be explicit rather than equating any output-equivalent program with understanding." + }, + { + "case": "application_requires_understanding", + "disposition": "partial_explanation_not_independent_understanding", + "basis": "Output-only and explained doubling processes establish the source's external-assessment and application-specific explanation branches. The required semantic case named application_requires_understanding is not yet accepted as an understanding result: ExplanationContract only requires a stored Program extensionally equal to the output. No independent process-understanding criterion is modeled. The source allows applications to define capabilities, but that definition and this loss must be explicit rather than equating any output-equivalent program with understanding." + }, + { + "case": "own_capability_assessment", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Output-only and explained doubling processes establish the source's external-assessment and application-specific explanation branches. The required semantic case named application_requires_understanding is not yet accepted as an understanding result: ExplanationContract only requires a stored Program extensionally equal to the output. No independent process-understanding criterion is modeled. The source allows applications to define capabilities, but that definition and this loss must be explicit rather than equating any output-equivalent program with understanding." + } + ], + "declarations": [ + { + "name": "CoreReader.Adopted.capabilitySpecification", + "registered_kind": "definition", + "actual_kind": "def", + "file": "CoreReader/Adopted.lean", + "line": 205, + "end": 214, + "exact_delta_code": "def capabilitySpecification (assessed : Process) (contract : Claim Process) : Prop :=\n Grounds012 contract canonicalArticulation [processContractFacet assessed contract]\n (.inferential (processScope assessed) contract)\n\n \n \n \n \n \n \n", + "axioms": "[propext]", + "actual_type_record": { + "type": "Lean.Expr.forallE\n `assessed\n (Lean.Expr.const `CoreReader.Evidence.Process [])\n (Lean.Expr.forallE\n `contract\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `CoreReader.Evidence.Process []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "908a244789ebae715ab94703060109000c2369e1c4735c6cdb48a096243f3c04" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + }, + { + "name": "CoreReader.Adopted.capabilityCases012", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Adopted.lean", + "line": 1166, + "end": 1179, + "exact_delta_code": "theorem capabilityCases012 :\n (capabilitySpecification outputOnlyProcess OutputContract ∧\n capabilitySpecification explainedProcess FullProcessContract ∧\n (∃ certificate : ExternalCertificate outputOnlyProcess,\n certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧\n ¬ ExplanationContract outputOnlyProcess) ∧\n (OwnCapability012 7 7 outputOnlyProcess OutputContract) :=\n ⟨capabilityFulfilled012, ownCapability012⟩\n\n \n \n \n \n \n", + "axioms": "[propext]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.const `CoreReader.Evidence.explainedProcess []))\n (Lean.Expr.const `CoreReader.Evidence.FullProcessContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))\n (Lean.Expr.lam\n `certificate\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate.assessorId [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate.assessedId [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExplanationContract [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.OwnCapability012 [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 7)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 7)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 7)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 7)))))\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.const `CoreReader.Evidence.OutputContract []))", + "sha256": "8b65b3510d304fccc5db3e8584da21c74e083b848f722afa20a46057993d6a51" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T17", + "kind": "nonentailment", + "registered_statement": "Reliable output or artifact/document/tool/term count alone does not establish internal-process understanding or stronger capability; articulable external grounds do not imply that assessed system understands/explains generation.", + "sources": [ + { + "unit": "organon.grounds.capabilities", + "clause": "p1" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p2" + } + ], + "registered_premises": [ + "Concrete task success and independent understanding criterion", + "external reasons not silently attributed to internal subject", + "scope escalation displayed." + ], + "disposition": "bounded_countermodels", + "independent_assessment": "Reliable double output with explanation = none refutes the stronger declared explanation contract; repeated item counts do not add an unavailable operation. This establishes limits on the represented output/explanation capability, not a cognitive account of human or agent understanding.", + "semantic_cases": [ + { + "case": "reliable_opaque_generator", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Reliable double output with explanation = none refutes the stronger declared explanation contract; repeated item counts do not add an unavailable operation. This establishes limits on the represented output/explanation capability, not a cognitive account of human or agent understanding." + }, + { + "case": "high_count_no_stronger_capability", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Reliable double output with explanation = none refutes the stronger declared explanation contract; repeated item counts do not add an unavailable operation. This establishes limits on the represented output/explanation capability, not a cognitive account of human or agent understanding." + }, + { + "case": "externally_articulated_no_introspection", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Reliable double output with explanation = none refutes the stronger declared explanation contract; repeated item counts do not add an unavailable operation. This establishes limits on the represented output/explanation capability, not a cognitive account of human or agent understanding." + } + ], + "declarations": [ + { + "name": "CoreReader.Adopted.capabilityLimits012", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Adopted.lean", + "line": 1180, + "end": 1220, + "exact_delta_code": "theorem capabilityLimits012 :\n (capabilitySpecification outputOnlyProcess OutputContract ∧\n capabilitySpecification explainedProcess FullProcessContract ∧\n (∃ certificate : ExternalCertificate outputOnlyProcess,\n certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧\n ¬ ExplanationContract outputOnlyProcess) ∧\n (∀ kind : InventoryKind,\n Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .copy ∧\n ¬ Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .successor) ∧\n (Generative generatingSystem.policy ∧\n generatingSystem.policy.permitsVersion 0 0 ∧\n ¬ Expanded generatingSystem.current inflatedState ∧\n generatingSystem.current.inventory.length < inflatedState.inventory.length ∧\n generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧\n generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧\n generatingSystem.execute availableResources = some 6 ∧\n generatingSystem.execute { availableResources with experience := none } = none ∧\n generatingSystem.execute { availableResources with knowledge := none } = none ∧\n generatingSystem.execute { availableResources with collaborator := none } = none ∧\n generatingSystem.execute ⟨none, none, none⟩ = none ∧\n ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧\n generatingSystem.stableAction = generatingSystem.current ∧\n generatingSystem.requirementsMet generatingSystem.stableAction ∧\n generatingSystem.withinBudget generatingSystem.stableAction ∧\n ¬ generatingSystem.withinBudget inflatedState ∧\n StableReason generatingSystem.current inflatedState ∧\n (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧\n inflatedAnnouncement.owner = generatingSystem.owner ∧\n inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧\n inflatedAnnouncement.reportedNewOperation = .successor ∧\n inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧\n ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after)) :=\n ⟨capabilityFulfilled012, inventoryCases012, generationLimits⟩\n\n \n \n \n \n \n \n \n", + "axioms": "[propext, Quot.sound.{u}]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.const `CoreReader.Evidence.explainedProcess []))\n (Lean.Expr.const `CoreReader.Evidence.FullProcessContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))\n (Lean.Expr.lam\n `certificate\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate.assessorId [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate.assessedId [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExplanationContract [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `kind\n (Lean.Expr.const `CoreReader.Agency.InventoryKind [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Available [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item [])))))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Available [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item [])))))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor []))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.permitsVersion [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.availableResources [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Option.some [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 6)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3023016825) \"_hygCtx\") \"_hyg\") 160)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3023016825) \"_hygCtx\") \"_hyg\") 179)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3023016825) \"_hygCtx\") \"_hyg\") 198)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n true)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.requirementsMet [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.StableReason [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Announcement []))\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.report [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.owner [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.owner [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.before [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.after [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.reportedNewOperation\n [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.input [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.expectedOutput\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.claim [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.before\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.after [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))))))))))))))))))))))))))))", + "sha256": "8efa4107232374dd4f308f0f4c19f39b706da292b2cb4042aba290ade3368d52" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T18", + "kind": "specification", + "registered_statement": "Implementation priority needs reasons connected to objectives, values and relevant constraints; name/convention/status alone insufficient. Internal method explanation, applicability limits, simplicity/process requirements may count; conventional options may win on relevant grounds, including this philosophy's existing form.", + "sources": [ + { + "unit": "organon.grounds.implementations", + "clause": "p1" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p2" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + } + ], + "registered_premises": [ + "Reason relevance to particular choice", + "provenance alone distinct from practical familiarity/support", + "no rule that internal reasons are always decisive." + ], + "disposition": "bounded_choice_specification", + "independent_assessment": "JustifiedChoice combines feasibility with a valued method-content reason; status-only reasons fail by definition as the additional adopted evaluative commitment. Conventional identity remains eligible, internal explanation/applicability/simplicity/procedure reasons are admissible, and the current philosophy review is assessed by actual output reasons. No optimality or all-reasons-valid theorem is claimed.", + "semantic_cases": [ + { + "case": "named_only_rejected", + "disposition": "covered_with_target_scope_qualifications", + "basis": "JustifiedChoice combines feasibility with a valued method-content reason; status-only reasons fail by definition as the additional adopted evaluative commitment. Conventional identity remains eligible, internal explanation/applicability/simplicity/procedure reasons are admissible, and the current philosophy review is assessed by actual output reasons. No optimality or all-reasons-valid theorem is claimed." + }, + { + "case": "conventional_grounded_priority", + "disposition": "covered_with_target_scope_qualifications", + "basis": "JustifiedChoice combines feasibility with a valued method-content reason; status-only reasons fail by definition as the additional adopted evaluative commitment. Conventional identity remains eligible, internal explanation/applicability/simplicity/procedure reasons are admissible, and the current philosophy review is assessed by actual output reasons. No optimality or all-reasons-valid theorem is claimed." + }, + { + "case": "method_internal_reason", + "disposition": "covered_with_target_scope_qualifications", + "basis": "JustifiedChoice combines feasibility with a valued method-content reason; status-only reasons fail by definition as the additional adopted evaluative commitment. Conventional identity remains eligible, internal explanation/applicability/simplicity/procedure reasons are admissible, and the current philosophy review is assessed by actual output reasons. No optimality or all-reasons-valid theorem is claimed." + }, + { + "case": "own_philosophy_status_only", + "disposition": "covered_with_target_scope_qualifications", + "basis": "JustifiedChoice combines feasibility with a valued method-content reason; status-only reasons fail by definition as the additional adopted evaluative commitment. Conventional identity remains eligible, internal explanation/applicability/simplicity/procedure reasons are admissible, and the current philosophy review is assessed by actual output reasons. No optimality or all-reasons-valid theorem is claimed." + } + ], + "declarations": [ + { + "name": "CoreReader.Adopted.choiceSpecification", + "registered_kind": "definition", + "actual_kind": "def", + "file": "CoreReader/Adopted.lean", + "line": 215, + "end": 219, + "exact_delta_code": "def choiceSpecification (requirements : Requirements) (implementation : Implementation)\n (reasons : List Reason) : Prop := JustifiedChoice requirements implementation reasons\n\n \n \n", + "axioms": "[]", + "actual_type_record": { + "type": "Lean.Expr.forallE\n `requirements\n (Lean.Expr.const `CoreReader.Choice.Requirements [])\n (Lean.Expr.forallE\n `implementation\n (Lean.Expr.const `CoreReader.Choice.Implementation [])\n (Lean.Expr.forallE\n `reasons\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "4b2ffafbf066633850901441a4978132cc3d84f95bef9c803f56a17866762054" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + }, + { + "name": "CoreReader.Adopted.choiceCases012", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Adopted.lean", + "line": 1221, + "end": 1254, + "exact_delta_code": "theorem choiceCases012 :\n (identityImpl.conventional = true ∧ identityImpl.established = true ∧\n JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output]) ∧\n (Relevant identityRequirements identityImpl (.method .explanation) ∧\n Relevant identityRequirements identityImpl (.method .applicability) ∧\n Relevant identityRequirements identityImpl (.method .simplicity) ∧\n Relevant identityRequirements identityImpl (.method .procedure) ∧\n (Relevant identityRequirements cheapSuccessor (.method .simplicity) ∧\n ¬ JustifiedChoice identityRequirements cheapSuccessor [.method .simplicity])) ∧\n (Articulated priorityArticulation ∧ AssessmentAccurate false ∧\n (∀ selected, Models statusFacts selected) ∧\n priorityClaim .identity ∧ ¬ priorityClaim .successor ∧\n ¬ Entails statusFacts priorityClaim ∧\n ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧\n ((∀ n, identityImpl.run n = wrongExplanation012.run n) ∧\n Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧\n Relevant identityRequirements identityImpl (.method .explanation) ∧\n ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation)) ∧\n (¬ choiceSpecification CoreReader.Integration.proposalRequirements\n (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation\n [.status .standing] ∧\n choiceSpecification CoreReader.Integration.proposalRequirements\n (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation\n [.method .output]) ∧\n (∀ kind : StatusKind,\n ¬ choiceSpecification identityRequirements identityImpl [.status kind]) :=\n ⟨conventionWithReason, internalReasons, statusAssessmentNonEntailment, internalReasonDistinguishes012, ownPhilosophyStatus012, allStatusOnly012⟩\n\n \n \n \n \n \n \n", + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.conventional [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.established [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.status [])\n (Lean.Expr.const `CoreReader.Choice.StatusKind.convention [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.output [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.explanation []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.applicability []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.simplicity []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.procedure []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.cheapSuccessor []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.simplicity []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.cheapSuccessor []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.simplicity [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason [])))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulated [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.priorityArticulation [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.AssessmentAccurate [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `selected\n (Lean.Expr.const `CoreReader.Choice.Candidate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Models [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.statusFacts []))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.priorityClaim [])\n (Lean.Expr.const `CoreReader.Choice.Candidate.identity [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.priorityClaim [])\n (Lean.Expr.const `CoreReader.Choice.Candidate.successor []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Entails [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.statusFacts []))\n (Lean.Expr.const `CoreReader.Choice.priorityClaim []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.status [])\n (Lean.Expr.const `CoreReader.Choice.StatusKind.standing [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 []))\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Feasible [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Feasible [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.explanation []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.explanation [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.choiceSpecification [])\n (Lean.Expr.const `CoreReader.Integration.proposalRequirements []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Integration.PhilosophyMethod.implementation [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Integration.currentPhilosophy [])\n (Lean.Expr.const `CoreReader.Integration.actualSystem []))\n (Lean.Expr.const `CoreReader.Integration.actual []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.status [])\n (Lean.Expr.const `CoreReader.Choice.StatusKind.standing [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.choiceSpecification [])\n (Lean.Expr.const `CoreReader.Integration.proposalRequirements []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Integration.PhilosophyMethod.implementation [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Integration.currentPhilosophy [])\n (Lean.Expr.const `CoreReader.Integration.actualSystem []))\n (Lean.Expr.const `CoreReader.Integration.actual []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.output [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))\n (Lean.Expr.forallE\n `kind\n (Lean.Expr.const `CoreReader.Choice.StatusKind [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.choiceSpecification [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Choice.Reason.status []) (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason [])))))\n (Lean.BinderInfo.default))))))", + "sha256": "36f89bc4962aa87be316945afd3147dd30111dfdca8902a41b0392a2bda28c04" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T19", + "kind": "nonentailment", + "registered_statement": "Openness neither makes alternatives equivalent nor ensures multiple feasible implementations, excludes conventional choices or excludes internal-method reasons. Local performance equality does not settle whole choice. The added choice priority rule is not inferred from the represented general requirement to assess reasons; this inherited limited assessment relation is distinct from the stronger domain nonentailment in T39.", + "sources": [ + { + "unit": "organon.grounds.implementations", + "clause": "p1" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p2" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "p1" + } + ], + "registered_premises": [ + "Concrete feasible option set and grounded comparison", + "at least one positive witness with a single feasible conventional option", + "distinct global consequences." + ], + "disposition": "bounded_countermodels", + "independent_assessment": "A single feasible conventional choice, unequal outputs, equal local but different global behavior, and a distinguishing internal explanation meet the requested cases. The additional-choice example distinguishes accurate general assessment of non-entailment from the separate priority norm; this is deliberately the limited general-assessment relation in the target, not all Grounds duties.", + "semantic_cases": [ + { + "case": "single_feasible_conventional", + "disposition": "covered_with_target_scope_qualifications", + "basis": "A single feasible conventional choice, unequal outputs, equal local but different global behavior, and a distinguishing internal explanation meet the requested cases. The additional-choice example distinguishes accurate general assessment of non-entailment from the separate priority norm; this is deliberately the limited general-assessment relation in the target, not all Grounds duties." + }, + { + "case": "internal_reason_distinguishes", + "disposition": "covered_with_target_scope_qualifications", + "basis": "A single feasible conventional choice, unequal outputs, equal local but different global behavior, and a distinguishing internal explanation meet the requested cases. The additional-choice example distinguishes accurate general assessment of non-entailment from the separate priority norm; this is deliberately the limited general-assessment relation in the target, not all Grounds duties." + }, + { + "case": "unequal_open_options", + "disposition": "covered_with_target_scope_qualifications", + "basis": "A single feasible conventional choice, unequal outputs, equal local but different global behavior, and a distinguishing internal explanation meet the requested cases. The additional-choice example distinguishes accurate general assessment of non-entailment from the separate priority norm; this is deliberately the limited general-assessment relation in the target, not all Grounds duties." + }, + { + "case": "local_equal_global_difference", + "disposition": "covered_with_target_scope_qualifications", + "basis": "A single feasible conventional choice, unequal outputs, equal local but different global behavior, and a distinguishing internal explanation meet the requested cases. The additional-choice example distinguishes accurate general assessment of non-entailment from the separate priority norm; this is deliberately the limited general-assessment relation in the target, not all Grounds duties." + }, + { + "case": "added_choice_not_from_general_assessment", + "disposition": "covered_with_target_scope_qualifications", + "basis": "A single feasible conventional choice, unequal outputs, equal local but different global behavior, and a distinguishing internal explanation meet the requested cases. The additional-choice example distinguishes accurate general assessment of non-entailment from the separate priority norm; this is deliberately the limited general-assessment relation in the target, not all Grounds duties." + } + ], + "declarations": [ + { + "name": "CoreReader.Adopted.choiceLimits012", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Adopted.lean", + "line": 1255, + "end": 1276, + "exact_delta_code": "theorem choiceLimits012 :\n ((∀ candidate, Feasible identityRequirements (implementation candidate) ↔ candidate = .identity) ∧\n JustifiedChoice identityRequirements identityImpl objectiveReason) ∧\n (identityImpl.conventional = true ∧ identityImpl.established = true ∧\n JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output]) ∧\n ((∀ n, identityImpl.run n = wrongExplanation012.run n) ∧\n Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧\n Relevant identityRequirements identityImpl (.method .explanation) ∧\n ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation)) ∧\n (JustifiedChoice identityRequirements identityImpl objectiveReason ∧\n identityImpl.run 0 ≠ successorImpl.run 0) ∧\n ((∀ x, x = 0 → identityImpl.run x = changedOutsideZero.run x) ∧\n identityImpl.run 1 ≠ changedOutsideZero.run 1) ∧\n ((Articulated priorityArticulation ∧ AssessmentAccurate false ∧\n (∀ selected, Models statusFacts selected) ∧\n priorityClaim .identity ∧ ¬ priorityClaim .successor ∧\n ¬ Entails statusFacts priorityClaim ∧\n ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧\n PolicyIndependenceExample) :=\n ⟨singleFeasible, conventionWithReason, internalReasonDistinguishes012, openNotEquivalent, localNotGlobal, generalGroundsNotChoice⟩\n\nend CoreReader.Adopted\n", + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `candidate\n (Lean.Expr.const `CoreReader.Choice.Candidate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Iff [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Feasible [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Choice.implementation []) (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Choice.Candidate.identity [])))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.const `CoreReader.Choice.objectiveReason []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.conventional [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.established [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.status [])\n (Lean.Expr.const `CoreReader.Choice.StatusKind.convention [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.output [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 []))\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Feasible [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Feasible [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.explanation []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.explanation [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.const `CoreReader.Choice.objectiveReason [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.successorImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `x\n (Lean.Expr.const `Nat [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.changedOutsideZero []))\n (Lean.Expr.bvar 1)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.changedOutsideZero []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulated [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.priorityArticulation [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.AssessmentAccurate [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `selected\n (Lean.Expr.const `CoreReader.Choice.Candidate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Models [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.statusFacts []))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.priorityClaim [])\n (Lean.Expr.const `CoreReader.Choice.Candidate.identity [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.priorityClaim [])\n (Lean.Expr.const `CoreReader.Choice.Candidate.successor []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Entails [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.statusFacts []))\n (Lean.Expr.const `CoreReader.Choice.priorityClaim []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.status [])\n (Lean.Expr.const `CoreReader.Choice.StatusKind.standing [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))))))))\n (Lean.Expr.const `CoreReader.Choice.PolicyIndependenceExample []))))))", + "sha256": "84bdf70f43a217d10ccf0d7a8179aea2b586ab845a7c8f3a2f087089c6098874" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T20", + "kind": "theorem", + "registered_statement": "Under jointly satisfied inherited commitments and actual applicability, own principles/assessment methods/grounds/capability judgments inherit their corresponding generation, consistency and support duties without self-proof or removal of conditions.", + "sources": [ + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + } + ], + "registered_premises": [ + "Same subject/context, shared principle/object identifiers, applicability", + "reflexivity interface connected to concrete Grounds/choice/capability obligations", + "no isolated conjunction of unrelated models." + ], + "disposition": "partial_theorem_signature", + "independent_assessment": "The same chosen candidate/context is linked through Inherited and the concrete cases are not unrelated Boolean models. inheritedMutualApplication is a projection of generation, reflection, five core value grounds, capability/choice and own-fact inference fields. Its full conclusion does not include the consistencySpecification promised by the registered target statement, although that proof exists as inherited.consistency in its premise. Therefore the exact theorem is a proved fragment of the stated preservation result, not the entire target signature.", + "semantic_cases": [ + { + "case": "own_grounds_articulable", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The same chosen candidate/context is linked through Inherited and the concrete cases are not unrelated Boolean models. inheritedMutualApplication is a projection of generation, reflection, five core value grounds, capability/choice and own-fact inference fields. Its full conclusion does not include the consistencySpecification promised by the registered target statement, although that proof exists as inherited.consistency in its premise. Therefore the exact theorem is a proved fragment of the stated preservation result, not the entire target signature." + }, + { + "case": "own_capability_supported", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The same chosen candidate/context is linked through Inherited and the concrete cases are not unrelated Boolean models. inheritedMutualApplication is a projection of generation, reflection, five core value grounds, capability/choice and own-fact inference fields. Its full conclusion does not include the consistencySpecification promised by the registered target statement, although that proof exists as inherited.consistency in its premise. Therefore the exact theorem is a proved fragment of the stated preservation result, not the entire target signature." + }, + { + "case": "own_choice_not_status_only", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The same chosen candidate/context is linked through Inherited and the concrete cases are not unrelated Boolean models. inheritedMutualApplication is a projection of generation, reflection, five core value grounds, capability/choice and own-fact inference fields. Its full conclusion does not include the consistencySpecification promised by the registered target statement, although that proof exists as inherited.consistency in its premise. Therefore the exact theorem is a proved fragment of the stated preservation result, not the entire target signature." + }, + { + "case": "relevant_self_application", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The same chosen candidate/context is linked through Inherited and the concrete cases are not unrelated Boolean models. inheritedMutualApplication is a projection of generation, reflection, five core value grounds, capability/choice and own-fact inference fields. Its full conclusion does not include the consistencySpecification promised by the registered target statement, although that proof exists as inherited.consistency in its premise. Therefore the exact theorem is a proved fragment of the stated preservation result, not the entire target signature." + } + ], + "declarations": [ + { + "name": "CoreReader.Engineering.inheritedMutualApplication", + "registered_kind": "theorem", + "actual_kind": "theorem", + "file": "CoreReader/Engineering/Integration.lean", + "line": 281, + "end": 297, + "exact_delta_code": "theorem inheritedMutualApplication (ctx : Context) (chosen : Candidate)\n (inherited : Inherited ctx chosen) :\n generationSpecification engineeringPolicy ∧\n reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self\n (selfModel chosen).performed ∧\n (∀ principle, valueSpecification (governancePosition principle)) ∧\n capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen) ∧\n choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons ∧\n (∀ fact, inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact)) :=\n ⟨inherited.generation, inherited.reflection, inherited.ownPrincipleGrounds,\n inherited.capabilityGrounds, inherited.implementationChoice, inherited.ownClaimGrounds⟩\n\n \n \n \n \n \n", + "axioms": "[propext]", + "actual_type_record": { + "type": "Lean.Expr.forallE\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.forallE\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.forallE\n `inherited\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.Inherited []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.generationSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.engineeringPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.reflexivitySpecification [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Outcome [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.rules [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 1))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.self [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 1))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.performed [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `principle\n (Lean.Expr.const `CoreReader.Engineering.CoreCommitment [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.valueSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.governancePosition []) (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.engineeringProcess []) (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringCapability [])\n (Lean.Expr.bvar 1))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.choiceSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.chosenRequirements []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.chosenImplementation [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.const `CoreReader.Engineering.chosenReasons [])))\n (Lean.Expr.forallE\n `fact\n (Lean.Expr.const `CoreReader.Engineering.OwnFact [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.inferentialSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.ownFactPremises []) (Lean.Expr.bvar 2)))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.ownFactClaim []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default)))))))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "3845e3f8d1cd47445374c4ca8f5e8c2f8a66daf6b82904ae7c84c40335e80b32" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.inheritedMutualCases", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Engineering/Integration.lean", + "line": 298, + "end": 316, + "exact_delta_code": "theorem inheritedMutualCases :\n Inherited sharedContext .evolvable ∧\n valueSpecification (governancePosition .grounds) ∧\n capabilitySpecification (engineeringProcess .evolvable) (engineeringCapability .evolvable) ∧\n choiceSpecification chosenRequirements (chosenImplementation .evolvable) chosenReasons ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample :=\n ⟨inheritedCurrent .evolvable (Or.inr rfl), governanceGrounded .grounds,\n engineeringCapabilityGrounded .evolvable,\n (inheritedCurrent .evolvable (Or.inr rfl)).implementationChoice,\n (actualSelfCriticism .evolvable).2.2.1⟩\n\n \n \n \n \n \n \n \n \n", + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Inherited [])\n (Lean.Expr.const `CoreReader.Engineering.sharedContext []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.valueSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.governancePosition [])\n (Lean.Expr.const `CoreReader.Engineering.CoreCommitment.grounds []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringProcess [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringCapability [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.choiceSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.chosenRequirements []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.chosenImplementation [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.const `CoreReader.Engineering.chosenReasons [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.evaluate [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.evolutionMethod []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision [])))))\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict.counterexample [])))))", + "sha256": "d020580ca71e08adc997353d140f057bf6886f1f087307be95d6504affdf8d54" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T21", + "kind": "boundary", + "registered_statement": "Existing form includes organization/methods/principles. Assessment is examination of reasons, applicability and observed performance and is not limited to executable testing.", + "sources": [ + { + "unit": "organon.relationships.terms", + "clause": "p1" + } + ], + "registered_premises": [ + "Definitions constrain every related model, including review subjects", + "no claim every assessment executes every listed operation when inapplicable." + ], + "disposition": "documentary_boundary", + "independent_assessment": "FormKind explicitly includes organization, method and principle. Empirical and semantic-inferential facets and noncomputable proposition decisions prevent restricting assessment to executable tests. The finite formal vocabulary is illustrative rather than an exhaustive philosophical ontology.", + "semantic_cases": [], + "declarations": [] + }, + { + "id": "T22", + "kind": "specification", + "registered_statement": "Domain subject is continuing engineering activity by current/successor human or agent maintainers with software/tools/knowledge across credible lifecycle; priority applicability reflects actual lifecycle/maintenance expectations, not labels or artifact intrinsic orientation.", + "sources": [ + { + "unit": "software-engineering.purpose", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p2" + }, + { + "unit": "software-engineering.purpose", + "clause": "p3" + } + ], + "registered_premises": [ + "Subject/maintainer roles, credible lifecycle grounds, activity versus artifact", + "temporary/prototype/retiring contexts considered conditionally, not blanket exemption by name." + ], + "disposition": "bounded_subject_specification", + "independent_assessment": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established.", + "semantic_cases": [ + { + "case": "successor_maintainer", + "disposition": "covered_with_target_scope_qualifications", + "basis": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established." + }, + { + "case": "agent_maintainer", + "disposition": "covered_with_target_scope_qualifications", + "basis": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established." + }, + { + "case": "continuing_labeled_temporary", + "disposition": "covered_with_target_scope_qualifications", + "basis": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established." + }, + { + "case": "genuinely_temporary", + "disposition": "covered_with_target_scope_qualifications", + "basis": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established." + }, + { + "case": "bounded_prototype", + "disposition": "covered_with_target_scope_qualifications", + "basis": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established." + }, + { + "case": "retiring_system", + "disposition": "covered_with_target_scope_qualifications", + "basis": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established." + } + ], + "declarations": [ + { + "name": "CoreReader.Engineering.ActivityScope", + "registered_kind": "definition", + "actual_kind": "abbrev", + "file": "CoreReader/Engineering/Domain.lean", + "line": 49, + "end": 52, + "exact_delta_code": "abbrev ActivityScope (a : Activity) : Prop :=\n a.participants ≠ [] ∧ a.software ≠ \"\" ∧ a.tools ≠ [] ∧\n a.participants.all (fun m => !(a.available m).isEmpty) = true\n\n", + "axioms": "[]", + "actual_type_record": { + "type": "Lean.Expr.forallE\n `a\n (Lean.Expr.const `CoreReader.Engineering.Activity [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default)", + "sha256": "fdfa84c29643bd37a72d614541ecf59b4b7efdf606ac4b7480cb02fe3e4c8382" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.subjectLifecycleCases", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Engineering/Domain.lean", + "line": 146, + "end": 158, + "exact_delta_code": "theorem subjectLifecycleCases :\n ActivityScope continuingActivity ∧\n CanChange continuingActivity .evolvable .successor .designRevision ∧\n CanChange continuingActivity .evolvable .agent .designRevision ∧\n continuingActivity.label = \"temporary\" ∧ Continuing continuingActivity ∧\n ¬ BoundedLifecycle continuingActivity ∧ BoundedLifecycle temporaryActivity ∧\n BoundedLifecycle prototypeActivity ∧ BoundedLifecycle retiringActivity := by decide\n\n \n \n \n \n \n", + "axioms": "[propext]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ActivityScope [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `String []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.label [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.lit (Lean.Literal.strVal \"temporary\"))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Continuing [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.const `CoreReader.Engineering.temporaryActivity [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.const `CoreReader.Engineering.prototypeActivity [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.const `CoreReader.Engineering.retiringActivity [])))))))))", + "sha256": "a2d126370b7fef5af4645ef64d85b169467518bfb8f76269b41f47f82e0bd02b" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T23", + "kind": "nonentailment", + "registered_statement": "Original-author editability does not establish continuing-maintainer evolution capability; calling a continuing system temporary does not establish genuinely bounded lifecycle; adopted human/agent orientation does not entail every artifact has it.", + "sources": [ + { + "unit": "software-engineering.purpose", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p2" + }, + { + "unit": "software-engineering.purpose", + "clause": "p3" + } + ], + "registered_premises": [ + "Concrete edit/understand/verify paths scoped by maintainer knowledge", + "lifecycle evidence distinct from label", + "actual continuing example." + ], + "disposition": "bounded_countermodels", + "independent_assessment": "The original maintainer has privateLayout while the successor lacks it; explicit path prerequisite failure establishes the contrast. The continuing activity remains nonbounded despite its temporary label. The passive artifact returns inputs and has no propose action by its actual definition, providing one counterexample rather than a law of all artifacts.", + "semantic_cases": [ + { + "case": "author_only_private_knowledge", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The original maintainer has privateLayout while the successor lacks it; explicit path prerequisite failure establishes the contrast. The continuing activity remains nonbounded despite its temporary label. The passive artifact returns inputs and has no propose action by its actual definition, providing one counterexample rather than a law of all artifacts." + }, + { + "case": "successor_missing_path", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The original maintainer has privateLayout while the successor lacks it; explicit path prerequisite failure establishes the contrast. The continuing activity remains nonbounded despite its temporary label. The passive artifact returns inputs and has no propose action by its actual definition, providing one counterexample rather than a law of all artifacts." + }, + { + "case": "false_temporary_label", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The original maintainer has privateLayout while the successor lacks it; explicit path prerequisite failure establishes the contrast. The continuing activity remains nonbounded despite its temporary label. The passive artifact returns inputs and has no propose action by its actual definition, providing one counterexample rather than a law of all artifacts." + }, + { + "case": "passive_artifact", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The original maintainer has privateLayout while the successor lacks it; explicit path prerequisite failure establishes the contrast. The continuing activity remains nonbounded despite its temporary label. The passive artifact returns inputs and has no propose action by its actual definition, providing one counterexample rather than a law of all artifacts." + } + ], + "declarations": [ + { + "name": "CoreReader.Engineering.subjectLimits", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Engineering/Domain.lean", + "line": 159, + "end": 173, + "exact_delta_code": "theorem subjectLimits :\n CanChange continuingActivity .presentSimple .original .designRevision ∧\n ¬ CanChange continuingActivity .presentSimple .successor .designRevision ∧\n ¬ ContinuingCapability continuingActivity .presentSimple .designRevision ∧\n continuingActivity.label = \"temporary\" ∧ ¬ BoundedLifecycle continuingActivity ∧\n orientation .agent ≠ [] ∧ passiveArtifact [2, 1] = [2, 1] ∧\n EngineeringAction.propose .designRevision ∈ maintainerActions .agent ∧\n EngineeringAction.propose .designRevision ∉ artifactActions [2, 1] := by decide\n\n \n \n \n \n \n \n", + "axioms": "[propext]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.original []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContinuingCapability [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `String []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.label [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.lit (Lean.Literal.strVal \"temporary\"))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.orientation [])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.passiveArtifact [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.maintainerActions [])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction.propose [])\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.artifactActions [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction.propose [])\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))))))))))", + "sha256": "4d0b23030599912d1ad72613e9956d5dd179d987aa64f0a694f74e85847b2a2b" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T24", + "kind": "specification", + "registered_statement": "When credible lifecycle/maintenance scope and relevant behavioral, safety, performance and other necessary requirements hold, favor continuing-maintainer credible future change capability including design revision over present abstraction simplicity; accept purpose-linked added complexity; allow yielding only when added costs threaten concrete objectives, with objective/cost account.", + "sources": [ + { + "unit": "software-engineering.purpose", + "clause": "p3" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "registered_premises": [ + "Explicit options, same engineering context, feasible requirements, supported credible change set, comparative evolution advantage, simplicity/complexity tradeoff, threat and departure explanation", + "no unconditional maximization or numeric exchange rate." + ], + "disposition": "bounded_normative_specification", + "independent_assessment": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "semantic_cases": [ + { + "case": "ordinary_priority", + "disposition": "covered_with_target_scope_qualifications", + "basis": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates." + }, + { + "case": "missing_behavior", + "disposition": "covered_with_target_scope_qualifications", + "basis": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates." + }, + { + "case": "missing_safety", + "disposition": "covered_with_target_scope_qualifications", + "basis": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates." + }, + { + "case": "missing_performance", + "disposition": "covered_with_target_scope_qualifications", + "basis": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates." + }, + { + "case": "missing_other_necessary", + "disposition": "covered_with_target_scope_qualifications", + "basis": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates." + }, + { + "case": "concrete_cost_override", + "disposition": "covered_with_target_scope_qualifications", + "basis": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates." + }, + { + "case": "unexplained_departure", + "disposition": "covered_with_target_scope_qualifications", + "basis": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates." + }, + { + "case": "no_extensibility_maximum", + "disposition": "covered_with_target_scope_qualifications", + "basis": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates." + } + ], + "declarations": [ + { + "name": "CoreReader.Engineering.EvolutionPriority", + "registered_kind": "definition", + "actual_kind": "abbrev", + "file": "CoreReader/Engineering/Domain.lean", + "line": 321, + "end": 323, + "exact_delta_code": "abbrev EvolutionPriority (ctx : Context) (chosen : Candidate) : Prop :=\n PriorityConditions ctx → chosen = .evolvable ∨ JustifiedDeparture ctx .evolvable\n\n", + "axioms": "[]", + "actual_type_record": { + "type": "Lean.Expr.forallE\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.forallE\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "8609cb39944d272540e985febb940328bc4a85a6e22fe06e652f4c95bd043ddb" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.priorityConditionsCases", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Engineering/Domain.lean", + "line": 367, + "end": 383, + "exact_delta_code": "theorem priorityConditionsCases :\n EvolutionPriority currentContinuing .evolvable ∧\n ¬ Meets normalRequirements { profile .evolvable with orderOutput := [1, 2] } ∧\n ¬ Meets normalRequirements { profile .evolvable with unsafeOperations := 1 } ∧\n ¬ Meets normalRequirements { profile .evolvable with latency := 11 } ∧\n ¬ Meets normalRequirements { profile .evolvable with retention := 29 } ∧\n EvolutionPriority (threatened .verification) .presentSimple ∧\n ¬ JustifiedDeparture { threatened .verification with departure := none } .evolvable ∧\n abstractionComplexity .evolvable < abstractionComplexity .maximal := by\n refine ⟨by decide, by decide, by decide, by decide, by decide, by decide, ?_, by decide⟩\n simp [JustifiedDeparture]\n\n \n \n \n \n \n", + "axioms": "[propext]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.const `CoreReader.Engineering.normalRequirements []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2249646945) \"_hygCtx\") \"_hyg\") 19)\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.profile [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.unsafeOperations [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.latency [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.retention [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.const `CoreReader.Engineering.normalRequirements []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2249646945) \"_hygCtx\") \"_hyg\") 45)\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.profile [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.orderOutput [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.latency [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.retention [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.const `CoreReader.Engineering.normalRequirements []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2249646945) \"_hygCtx\") \"_hyg\") 65)\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.profile [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.orderOutput [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.unsafeOperations [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 11)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 11)))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.retention [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.const `CoreReader.Engineering.normalRequirements []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2249646945) \"_hygCtx\") \"_hyg\") 85)\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.profile [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.orderOutput [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.unsafeOperations [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.latency [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 29)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 29)))))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.verification [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2249646945) \"_hygCtx\") \"_hyg\") 113)\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.verification []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.required [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.evidence [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.limits [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Burden [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.profiles [])\n (Lean.Expr.bvar 0)))\n true))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.maximal [])))))))))", + "sha256": "3206e3bed26ebff1742e044beabbfcca534354e4895936cd6496b4af5a5485e9" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T25", + "kind": "theorem", + "registered_statement": "For a context meeting all priority conditions, with a credible evolution advantage over a simpler feasible option and no concrete cost threat, domain satisfaction requires the evolution-favoring choice/priority and acceptance of its relevant additional complexity.", + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "registered_premises": [ + "Every T24 premise explicit, adopted domain rule as normative premise", + "preference compliance separate from act of assessment and universal goodness. Do not infer adoption from Core alone." + ], + "disposition": "conditional_theorem", + "independent_assessment": "The theorem explicitly assumes the adopted EvolutionPriority rule, applicability and no departure; it extracts the chosen evolvable value and substitutes into the supplied complexity comparison. This matches the target's normative-premise requirement. Concrete choices show simple violates the rule without a threat and can pass with the accounted threat.", + "semantic_cases": [ + { + "case": "applicable_choose_evolution", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The theorem explicitly assumes the adopted EvolutionPriority rule, applicability and no departure; it extracts the chosen evolvable value and substitutes into the supplied complexity comparison. This matches the target's normative-premise requirement. Concrete choices show simple violates the rule without a threat and can pass with the accounted threat." + }, + { + "case": "applicable_choose_simple_violates_domain", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The theorem explicitly assumes the adopted EvolutionPriority rule, applicability and no departure; it extracts the chosen evolvable value and substitutes into the supplied complexity comparison. This matches the target's normative-premise requirement. Concrete choices show simple violates the rule without a threat and can pass with the accounted threat." + }, + { + "case": "threat_allows_departure_with_account", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The theorem explicitly assumes the adopted EvolutionPriority rule, applicability and no departure; it extracts the chosen evolvable value and substitutes into the supplied complexity comparison. This matches the target's normative-premise requirement. Concrete choices show simple violates the rule without a threat and can pass with the accounted threat." + } + ], + "declarations": [ + { + "name": "CoreReader.Engineering.priorityWhenApplicable", + "registered_kind": "theorem", + "actual_kind": "theorem", + "file": "CoreReader/Engineering/Domain.lean", + "line": 337, + "end": 344, + "exact_delta_code": "theorem priorityWhenApplicable (ctx : Context) (chosen : Candidate)\n (rule : EvolutionPriority ctx chosen) (applicable : PriorityConditions ctx)\n (noDeparture : ¬ JustifiedDeparture ctx .evolvable) :\n chosen = .evolvable ∧\n abstractionComplexity .presentSimple < abstractionComplexity chosen := by\n have hc := (rule applicable).resolve_right noDeparture\n exact ⟨hc, hc ▸ applicable.2.2.2.2.2.2.2⟩\n\n", + "axioms": "[]", + "actual_type_record": { + "type": "Lean.Expr.forallE\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.forallE\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.forallE\n `rule\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `applicable\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.PriorityConditions []) (Lean.Expr.bvar 2))\n (Lean.Expr.forallE\n `noDeparture\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture []) (Lean.Expr.bvar 3))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.bvar 3))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity []) (Lean.Expr.bvar 3))))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "6b1efb7cab71c9b837ce57e666f331112f6416f18a59675e8119416b3d7a39a6" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.priorityChoices", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Engineering/Domain.lean", + "line": 384, + "end": 393, + "exact_delta_code": "theorem priorityChoices :\n EvolutionPriority currentContinuing .evolvable ∧\n ¬ EvolutionPriority currentContinuing .presentSimple ∧\n EvolutionPriority (threatened .verification) .presentSimple := by\n exact ⟨by decide, currentSimpleViolates, by decide⟩\n\n \n \n \n \n", + "axioms": "[propext]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.verification [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple [])))", + "sha256": "d4cbb2cea4f863c0a900531a90fd4e36cd04ad50df57b340871001d6fb01b349" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T26", + "kind": "specification", + "registered_statement": "Credible change direction has articulable grounds (examples are plan/domain knowledge/history, not an exhaustive required list), remains revisable, and needs no existing multiple implementations. Conceivability alone cannot justify present accommodation.", + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "registered_premises": [ + "Grounds for direction and present investment separately", + "applicability of history/knowledge", + "no Boolean label replacing content of supporting plan." + ], + "disposition": "qualified_credibility_adapter", + "independent_assessment": "The generic Ground interface does not restrict ground categories. Concrete plans identify a positive release and direction; knowledge/history cases contain a service/mechanism or repeated direction list, and forecast revision changes supported directions. The adapter only checks designated strings/list content, so actual relevance of a mechanism/history is a stipulated interpretation. It must not be reported as independent validation of arbitrary knowledge records.", + "semantic_cases": [ + { + "case": "committed_plan_one_implementation", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The generic Ground interface does not restrict ground categories. Concrete plans identify a positive release and direction; knowledge/history cases contain a service/mechanism or repeated direction list, and forecast revision changes supported directions. The adapter only checks designated strings/list content, so actual relevance of a mechanism/history is a stipulated interpretation. It must not be reported as independent validation of arbitrary knowledge records." + }, + { + "case": "domain_knowledge", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The generic Ground interface does not restrict ground categories. Concrete plans identify a positive release and direction; knowledge/history cases contain a service/mechanism or repeated direction list, and forecast revision changes supported directions. The adapter only checks designated strings/list content, so actual relevance of a mechanism/history is a stipulated interpretation. It must not be reported as independent validation of arbitrary knowledge records." + }, + { + "case": "applicable_history", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The generic Ground interface does not restrict ground categories. Concrete plans identify a positive release and direction; knowledge/history cases contain a service/mechanism or repeated direction list, and forecast revision changes supported directions. The adapter only checks designated strings/list content, so actual relevance of a mechanism/history is a stipulated interpretation. It must not be reported as independent validation of arbitrary knowledge records." + }, + { + "case": "conceivable_only", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The generic Ground interface does not restrict ground categories. Concrete plans identify a positive release and direction; knowledge/history cases contain a service/mechanism or repeated direction list, and forecast revision changes supported directions. The adapter only checks designated strings/list content, so actual relevance of a mechanism/history is a stipulated interpretation. It must not be reported as independent validation of arbitrary knowledge records." + }, + { + "case": "revised_forecast", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The generic Ground interface does not restrict ground categories. Concrete plans identify a positive release and direction; knowledge/history cases contain a service/mechanism or repeated direction list, and forecast revision changes supported directions. The adapter only checks designated strings/list content, so actual relevance of a mechanism/history is a stipulated interpretation. It must not be reported as independent validation of arbitrary knowledge records." + } + ], + "declarations": [ + { + "name": "CoreReader.Engineering.CredibleDirection", + "registered_kind": "definition", + "actual_kind": "abbrev", + "file": "CoreReader/Engineering/Domain.lean", + "line": 174, + "end": 178, + "exact_delta_code": "abbrev CredibleDirection {Ground : Type} (grounds : List Ground)\n (articulated : Ground → Bool) (supports : Ground → Change → Bool)\n (d : Change) : Prop :=\n grounds.any (fun g => articulated g && supports g d) = true\n\n", + "axioms": "[]", + "actual_type_record": { + "type": "Lean.Expr.forallE\n `Ground\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `grounds\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `articulated\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 1)\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `supports\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 2)\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Engineering.Change [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `d\n (Lean.Expr.const `CoreReader.Engineering.Change [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)", + "sha256": "1906e98dd6d042fc973fb93506c24accc024a7643adaddd05e071030c8b5682b" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.credibilityCases", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Engineering/Domain.lean", + "line": 212, + "end": 218, + "exact_delta_code": "theorem credibilityCases :\n credible initialGrounds .designRevision ∧\n credible [.knowledge \"queue\" [.designRevision] \"tenant-config-reload\"] .designRevision ∧\n credible [.history \"queue\" [.migration, .migration]] .migration ∧\n ¬ credible [] (.other \"quantum backend\") ∧\n credible forecastGrounds .deletion ∧ ¬ credible forecastGrounds .designRevision := by decide\n\n", + "axioms": "[]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.initialGrounds []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround.knowledge [])\n (Lean.Expr.lit (Lean.Literal.strVal \"queue\")))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))))\n (Lean.Expr.lit (Lean.Literal.strVal \"tenant-config-reload\"))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround []))))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround.history [])\n (Lean.Expr.lit (Lean.Literal.strVal \"queue\")))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.const `CoreReader.Engineering.Change.migration []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.const `CoreReader.Engineering.Change.migration []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround []))))\n (Lean.Expr.const `CoreReader.Engineering.Change.migration [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"quantum backend\"))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.forecastGrounds []))\n (Lean.Expr.const `CoreReader.Engineering.Change.deletion [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.forecastGrounds []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))))))", + "sha256": "b5d172388be7bcd1bdbeea1f07436b61458bd02c0e714dc83b7d7565adefa6c9" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T27", + "kind": "nonentailment", + "registered_statement": "Conceivable change alone does not entail warranted accommodation; credible change does not entail multiple existing implementations, maximal extensibility, retention of every possibility or universal numerical exchange rate.", + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "registered_premises": [ + "Nonempty supported direction and explicit alternative irrelevant direction", + "finite priority/qualitative comparison", + "credibility independent of current multiplicity." + ], + "disposition": "bounded_countermodels", + "independent_assessment": "One implemented variant coexists with credible direction; unsupported imagined changes do not warrant the defined investment; evolvable supports nine registered directions while maximal supports ten but is not the priority. Different per-burden bounds and work comparisons demonstrate a selective example, not a mathematical impossibility of numerical tradeoffs.", + "semantic_cases": [ + { + "case": "one_implementation_credible", + "disposition": "covered_with_target_scope_qualifications", + "basis": "One implemented variant coexists with credible direction; unsupported imagined changes do not warrant the defined investment; evolvable supports nine registered directions while maximal supports ten but is not the priority. Different per-burden bounds and work comparisons demonstrate a selective example, not a mathematical impossibility of numerical tradeoffs." + }, + { + "case": "imagined_unwarranted", + "disposition": "covered_with_target_scope_qualifications", + "basis": "One implemented variant coexists with credible direction; unsupported imagined changes do not warrant the defined investment; evolvable supports nine registered directions while maximal supports ten but is not the priority. Different per-burden bounds and work comparisons demonstrate a selective example, not a mathematical impossibility of numerical tradeoffs." + }, + { + "case": "selective_evolution", + "disposition": "covered_with_target_scope_qualifications", + "basis": "One implemented variant coexists with credible direction; unsupported imagined changes do not warrant the defined investment; evolvable supports nine registered directions while maximal supports ten but is not the priority. Different per-burden bounds and work comparisons demonstrate a selective example, not a mathematical impossibility of numerical tradeoffs." + }, + { + "case": "qualitative_tradeoff", + "disposition": "covered_with_target_scope_qualifications", + "basis": "One implemented variant coexists with credible direction; unsupported imagined changes do not warrant the defined investment; evolvable supports nine registered directions while maximal supports ten but is not the priority. Different per-burden bounds and work comparisons demonstrate a selective example, not a mathematical impossibility of numerical tradeoffs." + } + ], + "declarations": [ + { + "name": "CoreReader.Engineering.credibilityLimits", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Engineering/Domain.lean", + "line": 394, + "end": 409, + "exact_delta_code": "theorem credibilityLimits :\n credible initialGrounds .designRevision ∧ implementedVariants.length = 1 ∧\n ¬ WarrantedAccommodation [] (.other \"quantum backend\") 0 5 ∧\n ¬ credible initialGrounds (.other \"quantum backend\") ∧\n EvolutionPriority currentContinuing .evolvable ∧\n abstractionComplexity .evolvable < abstractionComplexity .maximal ∧\n cost .evolvable .construction < cost .evolvable .migration ∧\n ¬ MaximumRegisteredCapability continuingActivity .evolvable ∧\n MaximumRegisteredCapability continuingActivity .maximal ∧\n (supportedDirections continuingActivity .evolvable).length = 9 ∧\n (supportedDirections continuingActivity .maximal).length = 10 ∧\n ¬ credible initialGrounds (.other \"csv export\") := by decide\n\n \n \n \n", + "axioms": "[propext]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.initialGrounds []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `CoreReader.Engineering.implementedVariants [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.WarrantedAccommodation [])\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"quantum backend\"))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.initialGrounds []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"quantum backend\"))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.maximal []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.cost [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Burden.construction [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.cost [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Burden.migration []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.MaximumRegisteredCapability [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.MaximumRegisteredCapability [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.maximal [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.supportedDirections [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 9)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 9))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.supportedDirections [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.maximal []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 10))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.initialGrounds []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"csv export\")))))))))))))))", + "sha256": "76415ebe0bbc33c3827da7db33b1e89e3f676b7cf0f4f39df5401beeda5f40c4" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T28", + "kind": "specification", + "registered_statement": "Cost/departure account admits understanding, construction, diagnosis, verification, coordination, operation and eventual migration burdens and identifies threatened objective and causal significance of added cost.", + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "registered_premises": [ + "Do not require every burden be material in every case", + "costs attached to candidate/context and concrete objective, not free exception flag." + ], + "disposition": "bounded_cost_specification", + "independent_assessment": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "semantic_cases": [ + { + "case": "understanding_threat", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions." + }, + { + "case": "construction_threat", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions." + }, + { + "case": "diagnosis_threat", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions." + }, + { + "case": "verification_threat", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions." + }, + { + "case": "coordination_threat", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions." + }, + { + "case": "operation_threat", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions." + }, + { + "case": "migration_threat", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions." + }, + { + "case": "unsupported_cost_excuse", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions." + } + ], + "declarations": [ + { + "name": "CoreReader.Engineering.JustifiedDeparture", + "registered_kind": "definition", + "actual_kind": "abbrev", + "file": "CoreReader/Engineering/Domain.lean", + "line": 298, + "end": 306, + "exact_delta_code": "abbrev JustifiedDeparture (ctx : Context) (c : Candidate) : Prop :=\n match ctx.departure with\n | none => False\n | some b => ConcreteThreat ctx c b\n\ninstance (ctx : Context) (c : Candidate) : Decidable (JustifiedDeparture ctx c) := by\n unfold JustifiedDeparture\n split <;> infer_instance\n\n", + "axioms": "[]", + "actual_type_record": { + "type": "Lean.Expr.forallE\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.forallE\n `c\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "f6c50ef1eaca65b4a3886bcbc5ccb11393e89a2d7baf8f6980b6a58f9d0719a4" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.costCases", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "end": 421, + "exact_delta_code": "theorem costCases :\n JustifiedDeparture (threatened .understanding) .evolvable ∧\n JustifiedDeparture (threatened .construction) .evolvable ∧\n JustifiedDeparture (threatened .diagnosis) .evolvable ∧\n JustifiedDeparture (threatened .verification) .evolvable ∧\n JustifiedDeparture (threatened .coordination) .evolvable ∧\n JustifiedDeparture (threatened .operation) .evolvable ∧\n JustifiedDeparture (threatened .migration) .evolvable ∧\n ¬ JustifiedDeparture { currentContinuing with departure := some .migration } .evolvable := by decide\n\n \n \n", + "axioms": "[propext]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.understanding [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.construction [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.diagnosis [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.verification [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.coordination [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.operation [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.migration [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 797674858) \"_hygCtx\") \"_hyg\") 72)\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.required [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.evidence [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.limits [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Option.some [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Burden []))\n (Lean.Expr.const `CoreReader.Engineering.Burden.migration [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.profiles [])\n (Lean.Expr.bvar 0)))\n true))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))))))))", + "sha256": "0159f38d1da3fe90524ce5a5d2e2b1d3a4fc5a14c6a76a6fbc07a158d16edd90" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T29", + "kind": "specification", + "registered_statement": "Evolution includes capability addition, implementation replacement, mechanism deletion, abstraction withdrawal, boundary redrawing and technology/model migration; claims identify relevant changes and maintainer conditions; independent/coordinated changes and preserved/revised obligations may require different structures.", + "sources": [ + { + "unit": "software-engineering.evolution-meaning", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p2" + } + ], + "registered_premises": [ + "Nonexhaustive source include-list", + "identified capability relation indexed by change, context and maintainer", + "obligation semantics tracked." + ], + "disposition": "bounded_evolution_specification", + "independent_assessment": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "semantic_cases": [ + { + "case": "addition", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter." + }, + { + "case": "replacement", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter." + }, + { + "case": "deletion", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter." + }, + { + "case": "withdrawal", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter." + }, + { + "case": "redrawing", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter." + }, + { + "case": "migration", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter." + }, + { + "case": "independent", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter." + }, + { + "case": "coordinated", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter." + }, + { + "case": "preserve_obligation", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter." + }, + { + "case": "revise_obligation", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter." + } + ], + "declarations": [ + { + "name": "CoreReader.Engineering.EvolutionClaim", + "registered_kind": "definition", + "actual_kind": "abbrev", + "file": "CoreReader/Engineering/Domain.lean", + "line": 556, + "end": 568, + "exact_delta_code": "abbrev EvolutionClaim (a : Activity) (c : Candidate) (claim : ChangeClaim) : Prop :=\n CanChange a c claim.byMaintainer claim.direction ∧\n ContractChangeAccount originalContract (evolutionContract claim.direction) normalRevision ∧\n (changePath c claim.direction).any (fun step => step.tool == .contractRunner) = true ∧\n ((claim.treatment = .preserve ∧\n evolutionBehavior claim.direction [2, 1, 2] = orderedUnique [2, 1, 2]) ∨\n (claim.treatment = .revise ∧\n evolutionBehavior claim.direction [2, 1, 2] ≠ orderedUnique [2, 1, 2]))\n\n \n \n \n \n", + "axioms": "[]", + "actual_type_record": { + "type": "Lean.Expr.forallE\n `a\n (Lean.Expr.const `CoreReader.Engineering.Activity [])\n (Lean.Expr.forallE\n `c\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.forallE\n `claim\n (Lean.Expr.const `CoreReader.Engineering.ChangeClaim [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "9c0c528a387fd26adf8c44acbd1e97da3c991c6544f40f31c0a8c3adb2ccd2f7" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "end": 584, + "exact_delta_code": "theorem evolutionKindsCases :\n (transform .addition originalSoftware).capabilities = [\"deduplicate\", \"tenant batching\"] ∧\n (transform .replacement originalSoftware).implementation = 1 ∧\n (transform .deletion originalSoftware).mechanisms = [\"queue\"] ∧\n (transform .withdrawal originalSoftware).abstractions = [] ∧\n (transform .redrawing originalSoftware).boundary = 1 ∧\n (transform .migration originalSoftware).technology = \"portable store\" ∧\n changes.all (fun d => decide (CanChange continuingActivity .evolvable .successor d)) = true ∧\n EvolutionClaim continuingActivity .evolvable ⟨.replacement, .successor, .preserve⟩ ∧\n EvolutionClaim continuingActivity .evolvable ⟨.redrawing, .agent, .revise⟩ ∧\n changeWork .evolvable .independent < changeWork .evolvable .coordinated := by decide\n\n \n \n \n \n", + "axioms": "[propext]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.capabilities [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.addition []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"deduplicate\")))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"tenant batching\")))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `String []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.implementation [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.replacement []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.mechanisms [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.deletion []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"queue\")))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `String [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.abstractions [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.withdrawal []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `String []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.boundary [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.redrawing []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `String []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.technology [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.migration []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.lit (Lean.Literal.strVal \"portable store\"))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.all [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.const `CoreReader.Engineering.changes []))\n (Lean.Expr.lam\n `d\n (Lean.Expr.const `CoreReader.Engineering.Change [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Decidable.decide [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instDecidableAnd [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.participants [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.all [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.lam\n `step\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Bool.and [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.const\n `CoreReader.Engineering.instDecidableEqKnowledge\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.available [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.requires [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqTool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.tools [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.tool [])\n (Lean.Expr.bvar 0))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instDecidableNot [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.instDecidableEqNil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instDecidableAnd [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.participants [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.all [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.lam\n `step\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Bool.and [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.const\n `CoreReader.Engineering.instDecidableEqKnowledge\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.available [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.requires [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqTool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.tools [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.tool [])\n (Lean.Expr.bvar 0))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.instDecidableMemOfLawfulBEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqMaintainer [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instLawfulBEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqMaintainer [])))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.participants [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instDecidableEqBool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.all [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.lam\n `step\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Bool.and [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.const\n `CoreReader.Engineering.instDecidableEqKnowledge\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.available [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.requires [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqTool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.tools [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.tool [])\n (Lean.Expr.bvar 0))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionClaim [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ChangeClaim.mk [])\n (Lean.Expr.const `CoreReader.Engineering.Change.replacement []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.ObligationTreatment.preserve []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionClaim [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ChangeClaim.mk [])\n (Lean.Expr.const `CoreReader.Engineering.Change.redrawing []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent []))\n (Lean.Expr.const `CoreReader.Engineering.ObligationTreatment.revise []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.independent [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated [])))))))))))", + "sha256": "ccab4c5ed0bb676cef2d8435b8252630c0bc2f32d0ce9023156532deb6b77a1e" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T30", + "kind": "nonentailment", + "registered_statement": "Cheap/effective additions within fixed scheme do not entail equal ability to revise/leave it; advantage on one dimension does not entail every dimension; no duty to make every change inexpensive.", + "sources": [ + { + "unit": "software-engineering.evolution-meaning", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p2" + } + ], + "registered_premises": [ + "Concrete change-work or enabled-path relation producing add/exit contrast and independent/coordinated contrast", + "no arbitrary unsupported capability flags." + ], + "disposition": "bounded_countermodels", + "independent_assessment": "Addition can cost two while withdrawal/revision costs seventeen; coordinated work exceeds independent work; migration can remain expensive while evolution priority holds. Equal addition cost directly refutes universal strict improvement over all Change values.", + "semantic_cases": [ + { + "case": "easy_add_hard_exit", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Addition can cost two while withdrawal/revision costs seventeen; coordinated work exceeds independent work; migration can remain expensive while evolution priority holds. Equal addition cost directly refutes universal strict improvement over all Change values." + }, + { + "case": "independent_easy_coordinated_hard", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Addition can cost two while withdrawal/revision costs seventeen; coordinated work exceeds independent work; migration can remain expensive while evolution priority holds. Equal addition cost directly refutes universal strict improvement over all Change values." + }, + { + "case": "some_change_expensive_permitted", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Addition can cost two while withdrawal/revision costs seventeen; coordinated work exceeds independent work; migration can remain expensive while evolution priority holds. Equal addition cost directly refutes universal strict improvement over all Change values." + } + ], + "declarations": [ + { + "name": "CoreReader.Engineering.evolutionDimensionsLimits", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Engineering/Domain.lean", + "line": 585, + "end": 601, + "exact_delta_code": "theorem evolutionDimensionsLimits :\n changeWork .presentSimple .addition = 2 ∧\n changeWork .presentSimple .withdrawal = 17 ∧\n changeWork .evolvable .independent < changeWork .evolvable .coordinated ∧\n EvolutionPriority currentContinuing .evolvable ∧\n 9 < changeWork .evolvable .migration ∧\n CanChange continuingActivity .presentSimple .original .addition ∧\n CanChange continuingActivity .evolvable .original .addition ∧\n CanChange continuingActivity .presentSimple .original .designRevision ∧\n CanChange continuingActivity .evolvable .original .designRevision ∧\n changeWork .evolvable .designRevision < changeWork .presentSimple .designRevision ∧\n changeWork .evolvable .addition = changeWork .presentSimple .addition ∧\n (transform (.other \"csv export\") originalSoftware).capabilities = [\"deduplicate\", \"csv export\"] ∧\n CanChange continuingActivity .maximal .successor (.other \"csv export\") ∧\n ¬ CanChange continuingActivity .evolvable .successor (.other \"csv export\") := by\n exact ⟨by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide⟩\n\n", + "axioms": "[propext]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.addition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.withdrawal [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 17)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 17))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.independent [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 9)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 9)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.migration []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.original []))\n (Lean.Expr.const `CoreReader.Engineering.Change.addition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.original []))\n (Lean.Expr.const `CoreReader.Engineering.Change.addition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.original []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.original []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.addition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.addition []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.capabilities [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"csv export\"))))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"deduplicate\")))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"csv export\")))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `String []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.maximal []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"csv export\")))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"csv export\")))))))))))))))))", + "sha256": "ba2af856a831323eaa2344e83084a08689b7a287f6a8542edcef6fb0c2e57af7" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T31", + "kind": "specification", + "registered_statement": "Structural choice applies to whole relevant engineering consequences: component relations, observable contracts, understanding and verification work; boundary capability needs support for intended changes; propagation/cross-boundary knowledge and obligations/fixed assumptions/withdrawal are possible comparison inquiries.", + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p2" + } + ], + "registered_premises": [ + "Whole relevant scope rather than every imaginable consequence", + "may-examine inquiries are not compulsory universal checklist", + "intended change and boundary support relation explicit." + ], + "disposition": "partial_semantic_link", + "independent_assessment": "StructuralAccount ties touched components, intended direction, finite contract observations, work and verification counts. Fixed-batch and withdrawal examples are substantive. However the required cross_boundary_obligation case in structuralCases only proves an EditStep has component 2 and requires publicContract. It does not reference any Boundary caller/callee relation, identify which obligation crosses it, or link that boundary to the intended-change support account. The source makes such inquiries optional generally, but this preregistered named case remains an unfulfilled representation link.", + "semantic_cases": [ + { + "case": "contract_and_work_comparison", + "disposition": "covered_with_target_scope_qualifications", + "basis": "StructuralAccount ties touched components, intended direction, finite contract observations, work and verification counts. Fixed-batch and withdrawal examples are substantive. However the required cross_boundary_obligation case in structuralCases only proves an EditStep has component 2 and requires publicContract. It does not reference any Boundary caller/callee relation, identify which obligation crosses it, or link that boundary to the intended-change support account. The source makes such inquiries optional generally, but this preregistered named case remains an unfulfilled representation link." + }, + { + "case": "propagation_relation", + "disposition": "covered_with_target_scope_qualifications", + "basis": "StructuralAccount ties touched components, intended direction, finite contract observations, work and verification counts. Fixed-batch and withdrawal examples are substantive. However the required cross_boundary_obligation case in structuralCases only proves an EditStep has component 2 and requires publicContract. It does not reference any Boundary caller/callee relation, identify which obligation crosses it, or link that boundary to the intended-change support account. The source makes such inquiries optional generally, but this preregistered named case remains an unfulfilled representation link." + }, + { + "case": "cross_boundary_obligation", + "disposition": "partial_missing_boundary_link", + "basis": "StructuralAccount ties touched components, intended direction, finite contract observations, work and verification counts. Fixed-batch and withdrawal examples are substantive. However the required cross_boundary_obligation case in structuralCases only proves an EditStep has component 2 and requires publicContract. It does not reference any Boundary caller/callee relation, identify which obligation crosses it, or link that boundary to the intended-change support account. The source makes such inquiries optional generally, but this preregistered named case remains an unfulfilled representation link." + }, + { + "case": "fixed_assumption", + "disposition": "covered_with_target_scope_qualifications", + "basis": "StructuralAccount ties touched components, intended direction, finite contract observations, work and verification counts. Fixed-batch and withdrawal examples are substantive. However the required cross_boundary_obligation case in structuralCases only proves an EditStep has component 2 and requires publicContract. It does not reference any Boundary caller/callee relation, identify which obligation crosses it, or link that boundary to the intended-change support account. The source makes such inquiries optional generally, but this preregistered named case remains an unfulfilled representation link." + }, + { + "case": "withdrawal_cost", + "disposition": "covered_with_target_scope_qualifications", + "basis": "StructuralAccount ties touched components, intended direction, finite contract observations, work and verification counts. Fixed-batch and withdrawal examples are substantive. However the required cross_boundary_obligation case in structuralCases only proves an EditStep has component 2 and requires publicContract. It does not reference any Boundary caller/callee relation, identify which obligation crosses it, or link that boundary to the intended-change support account. The source makes such inquiries optional generally, but this preregistered named case remains an unfulfilled representation link." + } + ], + "declarations": [ + { + "name": "CoreReader.Engineering.StructuralAccount", + "registered_kind": "definition", + "actual_kind": "abbrev", + "file": "CoreReader/Engineering/Domain.lean", + "line": 641, + "end": 654, + "exact_delta_code": "abbrev StructuralAccount (a : Activity) (c : Candidate) (e : StructuralEvidence) : Prop :=\n e.participants = a.participants ∧ e.touched = propagation c e.intended ∧\n e.contractObservations = contractInputs ∧\n e.observedBefore = contractInputs.map orderedUnique ∧\n e.observedAfter = contractInputs.map (evolutionBehavior e.intended) ∧\n e.understandingWork = changeWork c e.intended ∧\n e.verificationWork = ((changePath c e.intended).filter\n (fun step => step.tool == .contractRunner)).length ∧\n e.boundaryGain = changeWork .presentSimple e.intended - changeWork c e.intended\n\n \n \n \n \n", + "axioms": "[]", + "actual_type_record": { + "type": "Lean.Expr.forallE\n `a\n (Lean.Expr.const `CoreReader.Engineering.Activity [])\n (Lean.Expr.forallE\n `c\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.forallE\n `e\n (Lean.Expr.const `CoreReader.Engineering.StructuralEvidence [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "45df6c2c2383df05162c2a265ba6daf5debbdf46847dc9de1801f881eb00db1e" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.structuralCases", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Engineering/Domain.lean", + "line": 655, + "end": 665, + "exact_delta_code": "theorem structuralCases :\n StructuralAccount continuingActivity .evolvable (structuralEvidence .evolvable .designRevision) ∧\n (propagation .presentSimple .designRevision).length = 3 ∧\n (propagation .evolvable .designRevision).length = 2 ∧\n (changePath .evolvable .coordinated).any (fun s => s.component == 2 && s.requires == .publicContract) = true ∧\n PreservesFinite orderedUnique orderedRefactor ∧\n (structuralEvidence .evolvable .designRevision).observedBefore ≠\n (structuralEvidence .evolvable .designRevision).observedAfter ∧\n staticBatch 21 10 = liveBatch 21 10 ∧ staticBatch 21 5 ≠ liveBatch 21 5 ∧\n changeWork .presentSimple .withdrawal = 17 := by decide\n\n", + "axioms": "[propext]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.StructuralAccount [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.structuralEvidence [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.propagation [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.propagation [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.any [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated [])))\n (Lean.Expr.lam\n `s\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Bool.and [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `BEq.beq [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instDecidableEqNat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.component [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `BEq.beq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqKnowledge [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.requires [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `CoreReader.Engineering.Knowledge.publicContract [])))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.orderedRefactor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.StructuralEvidence.observedBefore [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.structuralEvidence [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.StructuralEvidence.observedAfter [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.structuralEvidence [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.staticBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 10))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 10)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.staticBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.withdrawal [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 17)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 17))))))))))))", + "sha256": "93ac47c7e7132943abd11f6a6e9ce897c2b641d89e753d83bcd29509e80f572e" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T32", + "kind": "nonentailment", + "registered_statement": "Interface shape, module/extension-point count, named principle or boundary introduction alone cannot establish claimed evolution capability or easier intended change.", + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p2" + } + ], + "registered_premises": [ + "Executable or finite semantic consequence model links shape to behavior and work to change", + "demonstrate missing capability by contract/propagation/work failure rather than named false flag." + ], + "disposition": "bounded_countermodels_delta_verified", + "independent_assessment": "The frozen delta now supplies the exact new_boundary_same_work case missing from the initial code: an actual added boundary and changed path with identical units/work and remaining successor prerequisite failure. The original increased-work example is retained. These and the signature/module/named-pattern examples meet the finite negative target, without proving real-world overhead or boundary execution semantics.", + "semantic_cases": [ + { + "case": "same_shape_broken_order", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The frozen delta now supplies the exact new_boundary_same_work case missing from the initial code: an actual added boundary and changed path with identical units/work and remaining successor prerequisite failure. The original increased-work example is retained. These and the signature/module/named-pattern examples meet the finite negative target, without proving real-world overhead or boundary execution semantics." + }, + { + "case": "many_modules_shared_obligation", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The frozen delta now supplies the exact new_boundary_same_work case missing from the initial code: an actual added boundary and changed path with identical units/work and remaining successor prerequisite failure. The original increased-work example is retained. These and the signature/module/named-pattern examples meet the finite negative target, without proving real-world overhead or boundary execution semantics." + }, + { + "case": "named_pattern_no_change_path", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The frozen delta now supplies the exact new_boundary_same_work case missing from the initial code: an actual added boundary and changed path with identical units/work and remaining successor prerequisite failure. The original increased-work example is retained. These and the signature/module/named-pattern examples meet the finite negative target, without proving real-world overhead or boundary execution semantics." + }, + { + "case": "new_boundary_same_work", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The frozen delta now supplies the exact new_boundary_same_work case missing from the initial code: an actual added boundary and changed path with identical units/work and remaining successor prerequisite failure. The original increased-work example is retained. These and the signature/module/named-pattern examples meet the finite negative target, without proving real-world overhead or boundary execution semantics." + } + ], + "declarations": [ + { + "name": "CoreReader.Engineering.structureNotCapability", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Engineering/Domain.lean", + "line": 745, + "end": 773, + "exact_delta_code": "theorem structureNotCapability :\n (privateDesign.metadata.signature = sortedDesign.metadata.signature ∧\n privateDesign.run [2, 1, 2] = [2, 1] ∧ sortedDesign.run [2, 1, 2] ≠ [2, 1]) ∧\n (privateDesign.metadata.modules = privateDesign.components.length ∧\n privateDesign.batchAssumptions.length = 8 ∧\n (designModulesNeedingRevision privateDesign 5).length = 8) ∧\n (privateDesign.metadata.principle = \"dependency inversion\" ∧\n privateDesign.metadata = documentedDesign.metadata ∧\n ¬ DesignCanChange continuingActivity privateDesign .successor .designRevision ∧\n DesignCanChange continuingActivity documentedDesign .successor .designRevision) ∧\n (privateDesign.boundaries.length = 0 ∧ wrappedDesign.boundaries.length = 1 ∧\n wrappedDesign.components.length = 9 ∧\n wrappedDesign.boundaries = [⟨8, 0, \"List Nat → List Nat\"⟩] ∧\n wrappedDesign.run [2, 1, 2] = privateDesign.run [2, 1, 2] ∧\n designWork privateDesign .designRevision = 17 ∧\n designWork wrappedDesign .designRevision = 18 ∧\n ¬ designWork wrappedDesign .designRevision < designWork privateDesign .designRevision) ∧\n (sameWorkDesign.boundaries = [⟨8, 0, \"List Nat → List Nat\"⟩] ∧\n sameWorkDesign.components.length = 9 ∧\n sameWorkDesign.paths .designRevision ≠ privateDesign.paths .designRevision ∧\n sameWorkDesign.run [2, 1, 2] = privateDesign.run [2, 1, 2] ∧\n designWork sameWorkDesign .designRevision = designWork privateDesign .designRevision ∧\n designWork sameWorkDesign .designRevision = 17 ∧\n ¬ DesignCanChange continuingActivity sameWorkDesign .successor .designRevision) := by\n exact ⟨by decide, by decide, by decide, by decide, by decide⟩\n\n \n \n \n", + "axioms": "[propext]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `String []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.InterfaceView.signature [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.InterfaceView.signature [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.sortedDesign [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.sortedDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.InterfaceView.modules [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.components [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.batchAssumptions [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 8)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 8))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designModulesNeedingRevision [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 8)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 8))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `String []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.InterfaceView.principle [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))))\n (Lean.Expr.lit (Lean.Literal.strVal \"dependency inversion\"))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.InterfaceView []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.documentedDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.DesignCanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.DesignCanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.documentedDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.boundaries [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.boundaries [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.components [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 9)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 9))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.boundaries [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Boundary.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 8)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 8)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.lit (Lean.Literal.strVal \"List Nat → List Nat\"))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 17)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 17))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 18)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 18))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.boundaries [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Boundary.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 8)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 8)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.lit (Lean.Literal.strVal \"List Nat → List Nat\"))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.components [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 9)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 9))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.paths [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.paths [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 17)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 17))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.DesignCanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))))))))))", + "sha256": "2c09939db7dbc6561ff01284d1187a4272120050885c7743d2227d2a6e133ea9" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T33", + "kind": "specification", + "registered_statement": "Distinguish preserving an identified observable contract from deliberately revising it; deliberate revision accounts for changed obligations and affected parties; no requirement to preserve every historical behavior or use particular tests/migration procedure.", + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "p3" + } + ], + "registered_premises": [ + "Identified contract and observations, deliberate revision intent, obligations/affected parties mapping", + "preservation scope explicit", + "changes outside scope not silently violations." + ], + "disposition": "bounded_contract_specification", + "independent_assessment": "ContractChangeAccount separates finite scoped equality from deliberate revision with changed order/retry obligations and affected-party coverage. Missing operator/incorrect old limits fail; [99] demonstrates an intentionally out-of-scope historical difference; changing procedure text remains allowed. Actual notification, completeness of parties and all-input equivalence are not modeled.", + "semantic_cases": [ + { + "case": "preserve_identified_contract", + "disposition": "covered_with_target_scope_qualifications", + "basis": "ContractChangeAccount separates finite scoped equality from deliberate revision with changed order/retry obligations and affected-party coverage. Missing operator/incorrect old limits fail; [99] demonstrates an intentionally out-of-scope historical difference; changing procedure text remains allowed. Actual notification, completeness of parties and all-input equivalence are not modeled." + }, + { + "case": "deliberate_revision_with_account", + "disposition": "covered_with_target_scope_qualifications", + "basis": "ContractChangeAccount separates finite scoped equality from deliberate revision with changed order/retry obligations and affected-party coverage. Missing operator/incorrect old limits fail; [99] demonstrates an intentionally out-of-scope historical difference; changing procedure text remains allowed. Actual notification, completeness of parties and all-input equivalence are not modeled." + }, + { + "case": "revision_missing_parties", + "disposition": "covered_with_target_scope_qualifications", + "basis": "ContractChangeAccount separates finite scoped equality from deliberate revision with changed order/retry obligations and affected-party coverage. Missing operator/incorrect old limits fail; [99] demonstrates an intentionally out-of-scope historical difference; changing procedure text remains allowed. Actual notification, completeness of parties and all-input equivalence are not modeled." + }, + { + "case": "retired_historical_behavior", + "disposition": "covered_with_target_scope_qualifications", + "basis": "ContractChangeAccount separates finite scoped equality from deliberate revision with changed order/retry obligations and affected-party coverage. Missing operator/incorrect old limits fail; [99] demonstrates an intentionally out-of-scope historical difference; changing procedure text remains allowed. Actual notification, completeness of parties and all-input equivalence are not modeled." + }, + { + "case": "alternative_procedure", + "disposition": "covered_with_target_scope_qualifications", + "basis": "ContractChangeAccount separates finite scoped equality from deliberate revision with changed order/retry obligations and affected-party coverage. Missing operator/incorrect old limits fail; [99] demonstrates an intentionally out-of-scope historical difference; changing procedure text remains allowed. Actual notification, completeness of parties and all-input equivalence are not modeled." + } + ], + "declarations": [ + { + "name": "CoreReader.Engineering.ContractChangeAccount", + "registered_kind": "definition", + "actual_kind": "abbrev", + "file": "CoreReader/Engineering/Domain.lean", + "line": 549, + "end": 555, + "exact_delta_code": "abbrev ContractChangeAccount (old new : ObservableContract) (r : ContractRevision) : Prop :=\n PreservesContractFinite old new ∨ RevisionDuties old new r\n\n \n \n \n \n", + "axioms": "[]", + "actual_type_record": { + "type": "Lean.Expr.forallE\n `old\n (Lean.Expr.const `CoreReader.Engineering.ObservableContract [])\n (Lean.Expr.forallE\n `new\n (Lean.Expr.const `CoreReader.Engineering.ObservableContract [])\n (Lean.Expr.forallE\n `r\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "c58d92d3f41481a1b24941446085e8161c5dcb32cc266487f9734c2c03c8d3fe" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.contractCases", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Engineering/Domain.lean", + "line": 795, + "end": 804, + "exact_delta_code": "theorem contractCases :\n ContractChangeAccount originalContract refactoredContract normalRevision ∧\n ContractChangeAccount originalContract revisedContract normalRevision ∧\n ¬ ContractChangeAccount originalContract revisedContract { normalRevision with affected := [] } ∧\n PreservesFinite orderedUnique retiredBehavior ∧ retiredBehavior [99] ≠ orderedUnique [99] ∧\n ContractChangeAccount originalContract revisedContract { normalRevision with procedure := \"paired audit\" } := by decide\n\n \n \n \n", + "axioms": "[]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.refactoredContract []))\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 640854215) \"_hygCtx\") \"_hyg\") 28)\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision [])\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.deliberate [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.revisedOrder [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.oldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.newFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedOldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedNewFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.procedure [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.retiredBehavior [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.retiredBehavior [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 99)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 99)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 99)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 99)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 640854215) \"_hygCtx\") \"_hyg\") 68)\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision [])\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.deliberate [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.revisedOrder [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.affected [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.oldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.newFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedOldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedNewFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.lit (Lean.Literal.strVal \"paired audit\")))\n true))))))", + "sha256": "d577c98b03b1349b8acdc20e24a2d1141ea92e5ce49ab73e3518385e0981adeb" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T34", + "kind": "theorem", + "registered_statement": "Given equality of all identified contract observations in scope, a transformation preserves that identified contract; deliberate changed in-scope observations cannot be claimed preservation of that same contract and require revised-obligation/party account under domain satisfaction.", + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "p3" + } + ], + "registered_premises": [ + "Contract semantics and scope, total behavior on registered domain, at least one explicit distinguishing observation for revision, domain rule", + "finite examples reported finite." + ], + "disposition": "conditional_theorem", + "independent_assessment": "contractPreservation returns the supplied universal in-scope equality proof, rather than deriving it from finite tests. changedObservationNotPreserved gives the counterexample implication; contractRevisionObligations eliminates the failed preservation branch of the assumed account. Finite order/retry cases illustrate the distinction. This is the correct conditional reading of the target, not an empirical proof from test success.", + "semantic_cases": [ + { + "case": "order_preserving_refactor", + "disposition": "covered_with_target_scope_qualifications", + "basis": "contractPreservation returns the supplied universal in-scope equality proof, rather than deriving it from finite tests. changedObservationNotPreserved gives the counterexample implication; contractRevisionObligations eliminates the failed preservation branch of the assumed account. Finite order/retry cases illustrate the distinction. This is the correct conditional reading of the target, not an empirical proof from test success." + }, + { + "case": "sorted_order_revision", + "disposition": "covered_with_target_scope_qualifications", + "basis": "contractPreservation returns the supplied universal in-scope equality proof, rather than deriving it from finite tests. changedObservationNotPreserved gives the counterexample implication; contractRevisionObligations eliminates the failed preservation branch of the assumed account. Finite order/retry cases illustrate the distinction. This is the correct conditional reading of the target, not an empirical proof from test success." + }, + { + "case": "changed_failure_obligation", + "disposition": "covered_with_target_scope_qualifications", + "basis": "contractPreservation returns the supplied universal in-scope equality proof, rather than deriving it from finite tests. changedObservationNotPreserved gives the counterexample implication; contractRevisionObligations eliminates the failed preservation branch of the assumed account. Finite order/retry cases illustrate the distinction. This is the correct conditional reading of the target, not an empirical proof from test success." + }, + { + "case": "outside_scope_difference", + "disposition": "covered_with_target_scope_qualifications", + "basis": "contractPreservation returns the supplied universal in-scope equality proof, rather than deriving it from finite tests. changedObservationNotPreserved gives the counterexample implication; contractRevisionObligations eliminates the failed preservation branch of the assumed account. Finite order/retry cases illustrate the distinction. This is the correct conditional reading of the target, not an empirical proof from test success." + } + ], + "declarations": [ + { + "name": "CoreReader.Engineering.contractPreservation", + "registered_kind": "theorem", + "actual_kind": "theorem", + "file": "CoreReader/Engineering/Domain.lean", + "line": 774, + "end": 777, + "exact_delta_code": "theorem contractPreservation {Input Output : Type} (scope : Input → Prop)\n (old new : Input → Output) (observations : ∀ x, scope x → new x = old x) :\n PreservesOn scope old new := observations\n\n", + "axioms": "[]", + "actual_type_record": { + "type": "Lean.Expr.forallE\n `Input\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `Output\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `scope\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 1)\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `old\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 2)\n (Lean.Expr.bvar 2)\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `new\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 3)\n (Lean.Expr.bvar 3)\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `observations\n (Lean.Expr.forallE\n `x\n (Lean.Expr.bvar 4)\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app (Lean.Expr.bvar 3) (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.bvar 5))\n (Lean.Expr.app (Lean.Expr.bvar 2) (Lean.Expr.bvar 1)))\n (Lean.Expr.app (Lean.Expr.bvar 3) (Lean.Expr.bvar 1)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.PreservesOn []) (Lean.Expr.bvar 5))\n (Lean.Expr.bvar 4))\n (Lean.Expr.bvar 3))\n (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit))\n (Lean.BinderInfo.implicit)", + "sha256": "d9078e49c446deddda26e669891464c695136710e6b34620ca8ee4f08bdafbed" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.contractDistinctions", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Engineering/Domain.lean", + "line": 805, + "end": 819, + "exact_delta_code": "theorem contractDistinctions :\n PreservesFinite orderedUnique orderedRefactor ∧\n ¬ PreservesFinite orderedUnique sortedUnique ∧\n retry originalContract 3 = false ∧ retry revisedContract 3 = true ∧\n ¬ PreservesContractFinite originalContract revisedContract ∧\n affectedParties originalContract revisedContract = [\"queue consumer\", \"queue operator\"] ∧\n ¬ ContractChangeAccount originalContract revisedContract\n { normalRevision with affected := [\"queue consumer\"] } ∧\n ¬ ContractChangeAccount originalContract revisedContract\n { normalRevision with oldFailureLimit := 5, recordedOldFailureLimit := 5 } ∧\n ContractChangeAccount originalContract revisedContract normalRevision ∧\n PreservesFinite orderedUnique retiredBehavior ∧ retiredBehavior [99] ≠ orderedUnique [99] := by decide\n\n \n \n", + "axioms": "[]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.orderedRefactor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.sortedUnique []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.retry [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3))))))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.retry [])\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesContractFinite [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.affectedParties [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"queue consumer\")))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"queue operator\")))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `String []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2260969961) \"_hygCtx\") \"_hyg\") 73)\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision [])\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.deliberate [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.revisedOrder [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"queue consumer\")))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `String []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.oldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.newFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedOldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedNewFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.procedure [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2260969961) \"_hygCtx\") \"_hyg\") 97)\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision [])\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.deliberate [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.revisedOrder [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.affected [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 5)))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.newFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 5)))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedNewFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.procedure [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.retiredBehavior [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.retiredBehavior [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 99)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 99)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 99)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 99)))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))))))))))))", + "sha256": "bc0f83a82833ba24fc73f01ff24ac513e5ce42fec36a8195c70d516365a07a28" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T35", + "kind": "specification", + "registered_statement": "Changed evidence about expected changes, maintenance conditions, costs/objectives can justify revised design/priority application; revised judgment acknowledges material grounds changes and cannot retroactively relabel failed prediction success. Retention may be justified by alternatives lacking contribution or defeating objectives.", + "sources": [ + { + "unit": "software-engineering.revision", + "clause": "p2" + }, + { + "unit": "software-engineering.revision", + "clause": "p1" + } + ], + "registered_premises": [ + "Separate old/new evidence/time, prediction outcome and judgment, permission versus compulsory redesign", + "applicable alternatives and objective explicit." + ], + "disposition": "qualified_revision_account", + "independent_assessment": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign.", + "semantic_cases": [ + { + "case": "revised_change_forecast", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign." + }, + { + "case": "changed_maintainers", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign." + }, + { + "case": "changed_cost", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign." + }, + { + "case": "changed_objective", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign." + }, + { + "case": "failed_prediction_preserved", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign." + }, + { + "case": "justified_retention", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign." + } + ], + "declarations": [ + { + "name": "CoreReader.Engineering.RevisionAccount", + "registered_kind": "definition", + "actual_kind": "abbrev", + "file": "CoreReader/Engineering/Domain.lean", + "line": 874, + "end": 875, + "exact_delta_code": "abbrev RevisionAccount (r : RevisionRecord) : Prop := RevisionAccountAgainst observedHistory r\n\n", + "axioms": "[]", + "actual_type_record": { + "type": "Lean.Expr.forallE\n `r\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default)", + "sha256": "865a4c6c542f07f6b0ce44a67e98175239ef389738b16bc6071ccebffae61c8b" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.revisionCases", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Engineering/Domain.lean", + "line": 903, + "end": 913, + "exact_delta_code": "theorem revisionCases :\n RevisionAccount revisionRecord ∧\n revisionRecord.old.forecast ≠ revisionRecord.current.forecast ∧\n revisionRecord.old.maintenance ≠ revisionRecord.current.maintenance ∧\n revisionRecord.old.maintainers ≠ revisionRecord.current.maintainers ∧\n revisionRecord.old.migrationCost ≠ revisionRecord.current.migrationCost ∧\n revisionRecord.old.objectiveCapacity ≠ revisionRecord.current.objectiveCapacity ∧\n revisionRecord.predictedBatchCount ≠ revisionRecord.actualBatchCount ∧\n RetentionJustified currentContinuing [.other \"quantum backend\"] ∧\n RetentionJustified (threatened .migration) [.migration] := by decide\n\n", + "axioms": "[propext]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionAccount [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.forecast [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.forecast [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.maintenance [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.maintenance [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.maintainers [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.maintainers [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.migrationCost [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.migrationCost [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.objectiveCapacity [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.objectiveCapacity [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.predictedBatchCount [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.actualBatchCount [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RetentionJustified [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"quantum backend\"))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RetentionJustified [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.migration [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.const `CoreReader.Engineering.Change.migration []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change [])))))))))))", + "sha256": "8e2008450f4c7a80eca24630a18e6c77bf570055daee2c75c2577987c06ff629" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T36", + "kind": "nonentailment", + "registered_statement": "Revised judgment cannot make past failed prediction true; continued change, agreement and successful examples do not establish universal correctness; justified retention is compatible with domain/reflexive revision openness.", + "sources": [ + { + "unit": "software-engineering.revision", + "clause": "p2" + }, + { + "unit": "software-engineering.revision", + "clause": "p1" + } + ], + "registered_premises": [ + "Time-indexed prediction semantics invariant under report revision", + "finite successes with explicit broader failure", + "activity is open to criticism while choosing stability now." + ], + "disposition": "bounded_countermodels_with_scope_limit", + "independent_assessment": "Fixed history rejects reporting a 3-versus-5 prediction as success; repeated agreement and size-10 successes retain the size-5 counterexample. stableRecord keeps the design choice while preserving the criticism coverage condition. This is an open-to-listed-criticism record, not a separate proof of all reflexive obligations for arbitrary stable engineering designs; those are treated under the selfModel interface.", + "semantic_cases": [ + { + "case": "past_failure_not_rewritten", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Fixed history rejects reporting a 3-versus-5 prediction as success; repeated agreement and size-10 successes retain the size-5 counterexample. stableRecord keeps the design choice while preserving the criticism coverage condition. This is an open-to-listed-criticism record, not a separate proof of all reflexive obligations for arbitrary stable engineering designs; those are treated under the selfModel interface." + }, + { + "case": "agreement_with_bad_case", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Fixed history rejects reporting a 3-versus-5 prediction as success; repeated agreement and size-10 successes retain the size-5 counterexample. stableRecord keeps the design choice while preserving the criticism coverage condition. This is an open-to-listed-criticism record, not a separate proof of all reflexive obligations for arbitrary stable engineering designs; those are treated under the selfModel interface." + }, + { + "case": "local_success_global_failure", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Fixed history rejects reporting a 3-versus-5 prediction as success; repeated agreement and size-10 successes retain the size-5 counterexample. stableRecord keeps the design choice while preserving the criticism coverage condition. This is an open-to-listed-criticism record, not a separate proof of all reflexive obligations for arbitrary stable engineering designs; those are treated under the selfModel interface." + }, + { + "case": "open_stable_design", + "disposition": "covered_with_target_scope_qualifications", + "basis": "Fixed history rejects reporting a 3-versus-5 prediction as success; repeated agreement and size-10 successes retain the size-5 counterexample. stableRecord keeps the design choice while preserving the criticism coverage condition. This is an open-to-listed-criticism record, not a separate proof of all reflexive obligations for arbitrary stable engineering designs; those are treated under the selfModel interface." + } + ], + "declarations": [ + { + "name": "CoreReader.Engineering.revisionLimits", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Engineering/Domain.lean", + "line": 945, + "end": 958, + "exact_delta_code": "theorem revisionLimits :\n RevisionAccount revisionRecord ∧\n ¬ RevisionAccount { revisionRecord with reportedPredictionSucceeded := true } ∧\n revisionsMade.length = 3 ∧\n agreedBatch maintainers 21 5 = [3, 3, 3] ∧ liveBatch 21 5 = 5 ∧\n observations.all (fun p => staticBatch p.1 p.2 == liveBatch p.1 p.2) = true ∧\n staticBatch 21 5 ≠ liveBatch 21 5 ∧\n RevisionAccount stableRecord ∧ stableRecord.current.choice = stableRecord.old.choice ∧\n RetentionJustified currentContinuing [.other \"quantum backend\"] := by\n refine ⟨by decide, ?_, by decide, by decide, by decide, by decide,\n by decide, by decide, by decide, by decide⟩\n dsimp [RevisionAccount, RevisionAccountAgainst, observedHistory, MaterialGroundsChanged, revisionRecord, oldState, newState]\n decide\n\n", + "axioms": "[propext]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionAccount [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionAccount [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 3857095740) \"_hygCtx\") \"_hyg\") 17)\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.software [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.recordedOld [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.recordedCurrent [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.predictedBatchCount [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.actualBatchCount [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.consideredChanges [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.criticizedDirections [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Engineering.revisionsMade [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.agreedBatch [])\n (Lean.Expr.const `CoreReader.Engineering.maintainers []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.all [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.const `CoreReader.Engineering.observations []))\n (Lean.Expr.lam\n `p\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `BEq.beq [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instDecidableEqNat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.staticBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.fst [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.fst [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.staticBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionAccount [])\n (Lean.Expr.const `CoreReader.Engineering.stableRecord [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.choice [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.stableRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.choice [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.stableRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RetentionJustified [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"quantum backend\"))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))))))))))))", + "sha256": "071a3e5cddf46166eacbd56285cdb4abb9f11a94e50e8bf00f8bc100f01026d0" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T37", + "kind": "theorem", + "registered_statement": "With inherited and domain satisfaction in a shared applicable context, the priority and evolution-assessment methods remain objects of grounds, consistency and reflexive criticism/revision; domain success cannot exempt its rule.", + "sources": [ + { + "unit": "organon.relationships.roles", + "clause": "p3" + }, + { + "unit": "extensions", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.revision", + "clause": "p2" + } + ], + "registered_premises": [ + "Same domain-rule object assessed via inherited predicates", + "explicit relevant applicability", + "user adoption choice distinguished from metalevel correctness." + ], + "disposition": "partial_same_rule_grounding", + "independent_assessment": "The exact theorem derives chosen=evolvable, priority-object membership, reflection and value grounds for CoreCommitment (the five inherited labels). The priority is actually tested in selfModel, and the evolution method has a real counterexample. But the conclusion does not carry consistencySpecification, nor a Grounds/value specification for the same engineering-priority rule: selectionPosition grounds a candidate selection, while governancePosition covers only CoreCommitment. These facts are related but not definitionally the same judgment. The registered whole target remains partial pending a same-rule connection or an explicitly authorized narrower target.", + "semantic_cases": [ + { + "case": "priority_self_assessment", + "disposition": "reflection_checked_priority_grounds_link_partial", + "basis": "The exact theorem derives chosen=evolvable, priority-object membership, reflection and value grounds for CoreCommitment (the five inherited labels). The priority is actually tested in selfModel, and the evolution method has a real counterexample. But the conclusion does not carry consistencySpecification, nor a Grounds/value specification for the same engineering-priority rule: selectionPosition grounds a candidate selection, while governancePosition covers only CoreCommitment. These facts are related but not definitionally the same judgment. The registered whole target remains partial pending a same-rule connection or an explicitly authorized narrower target." + }, + { + "case": "method_self_criticism", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The exact theorem derives chosen=evolvable, priority-object membership, reflection and value grounds for CoreCommitment (the five inherited labels). The priority is actually tested in selfModel, and the evolution method has a real counterexample. But the conclusion does not carry consistencySpecification, nor a Grounds/value specification for the same engineering-priority rule: selectionPosition grounds a candidate selection, while governancePosition covers only CoreCommitment. These facts are related but not definitionally the same judgment. The registered whole target remains partial pending a same-rule connection or an explicitly authorized narrower target." + }, + { + "case": "no_selfproof_from_success", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The exact theorem derives chosen=evolvable, priority-object membership, reflection and value grounds for CoreCommitment (the five inherited labels). The priority is actually tested in selfModel, and the evolution method has a real counterexample. But the conclusion does not carry consistencySpecification, nor a Grounds/value specification for the same engineering-priority rule: selectionPosition grounds a candidate selection, while governancePosition covers only CoreCommitment. These facts are related but not definitionally the same judgment. The registered whole target remains partial pending a same-rule connection or an explicitly authorized narrower target." + } + ], + "declarations": [ + { + "name": "CoreReader.Engineering.priorityRemainsReflexive", + "registered_kind": "theorem", + "actual_kind": "theorem", + "file": "CoreReader/Engineering/Integration.lean", + "line": 317, + "end": 335, + "exact_delta_code": "theorem priorityRemainsReflexive (ctx : Context) (chosen : Candidate)\n (inherited : Inherited ctx chosen) (domain : DomainSatisfied ctx chosen)\n (applicable : PriorityConditions ctx) (noDeparture : ¬ JustifiedDeparture ctx .evolvable) :\n chosen = .evolvable ∧\n (.priority : ReviewObject) ∈ (selfModel chosen).objects ∧\n reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self\n (selfModel chosen).performed ∧\n (∀ principle, valueSpecification (governancePosition principle)) := by\n have selected := (priorityWhenApplicable ctx chosen domain.2.1 applicable noDeparture).1\n refine ⟨selected, ?_, inherited.reflection, inherited.ownPrincipleGrounds⟩\n subst chosen\n decide\n\n \n \n \n \n \n \n", + "axioms": "[propext]", + "actual_type_record": { + "type": "Lean.Expr.forallE\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.forallE\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.forallE\n `inherited\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.Inherited []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `domain\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.DomainSatisfied []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.forallE\n `applicable\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.PriorityConditions []) (Lean.Expr.bvar 3))\n (Lean.Expr.forallE\n `noDeparture\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture []) (Lean.Expr.bvar 4))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.bvar 4))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.objects [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 4))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.priority [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.reflexivitySpecification [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Outcome [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.rules [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 4))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.self [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 4))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.performed [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 4)))))\n (Lean.Expr.forallE\n `principle\n (Lean.Expr.const `CoreReader.Engineering.CoreCommitment [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.valueSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.governancePosition [])\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default)))))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "7348e0b4e8905385dad854787ce1959aff10ba9165df95a08a4fb9e4bfec7aed" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.priorityReflexiveCases", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Engineering/Integration.lean", + "line": 336, + "end": 395, + "exact_delta_code": "theorem priorityReflexiveCases :\n (.priority : ReviewObject) ∈ (selfModel .evolvable).objects ∧\n objectTest .priority (.evolvable, 10) = true ∧\n (selfModel .evolvable).performed ⟨0, 1⟩ ⟨0, .priority, .revision⟩\n ((selfModel .evolvable).input ⟨0, .priority, .revision⟩)\n (.assessed .supportedWithinScope) ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧\n objectTest .evolutionMethod (.evolvable, 10) = true ∧\n objectTest .evolutionMethod (.evolvable, 5) = false := by\n refine ⟨by decide, by decide, ?_, (actualSelfCriticism .evolvable).2.2.1,\n (actualSelfCriticism .evolvable).1, (actualSelfCriticism .evolvable).2.1⟩\n exact ⟨⟨rfl, by decide⟩, rfl, .assessment, rfl, rfl⟩\n\n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n", + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.objects [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.priority [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.objectTest [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.priority []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 10)))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.performed [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.PrincipleKey.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.priority []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.priority []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Outcome.assessed [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict.supportedWithinScope []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.evaluate [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.evolutionMethod []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision [])))))\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict.counterexample [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.objectTest [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.evolutionMethod []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 10)))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.objectTest [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.evolutionMethod []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.const `Bool.false []))))))", + "sha256": "9bf307a3e762002cbd34684f2e7b5cb8f043447ba38346f6ac04df2d54c50df7" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T38", + "kind": "satisfiability", + "registered_statement": "USER ADDITIONAL STRONG OBJECTIVE: one content-bearing nonempty system/context jointly satisfies every represented inherited and domain commitment, with a continuing lifecycle, actual applicable priority and evolution chosen despite additional present abstraction complexity.", + "sources": [ + { + "unit": "organon.charter.overview", + "clause": "p2" + }, + { + "unit": "organon.charter.overview", + "clause": "p3" + }, + { + "unit": "organon.charter.self-transcendence", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.orientation", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.non-finality", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity.limits", + "clause": "p1" + }, + { + "unit": "organon.grounds", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + }, + { + "unit": "organon.grounds.scope", + "clause": "p1" + }, + { + "unit": "organon.grounds.scope", + "clause": "p2" + }, + { + "unit": "organon.grounds.scope", + "clause": "p3" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p1" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p2" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p1" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p2" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + }, + { + "unit": "extensions", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p2" + }, + { + "unit": "software-engineering.purpose", + "clause": "p3" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p2" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p2" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p3" + }, + { + "unit": "software-engineering.revision", + "clause": "p1" + }, + { + "unit": "software-engineering.revision", + "clause": "p2" + } + ], + "registered_premises": [ + "Common context/subjects/claims/reasons/alternatives", + "shared nontrivial consequence relation", + "actual empirical/inferential/value duties relevant and fulfilled where represented", + "successor+agent maintenance pathways, credible design-change direction, satisfied necessary requirements, no defeating cost threat. Whole Inherited and Domain interfaces used, not subset." + ], + "disposition": "kernel_witness_source_composition_pending", + "independent_assessment": "The existential witness uses the full encoded Inherited and DomainSatisfied records at sharedContext/evolvable, with active applicability, no threat, larger present complexity, nonempty own facts and successor/agent paths. Its mathematical inhabitation is accepted. Full source/target composition is not yet accepted because T20/T31/T37 contain the specified correspondence gaps and T16's understanding case remains limited. This is not a proof failure or evidence that the displayed witness is vacuous.", + "semantic_cases": [ + { + "case": "joint_all_inherited_and_domain", + "disposition": "kernel_checked_source_composition_pending", + "basis": "The existential witness uses the full encoded Inherited and DomainSatisfied records at sharedContext/evolvable, with active applicability, no threat, larger present complexity, nonempty own facts and successor/agent paths. Its mathematical inhabitation is accepted. Full source/target composition is not yet accepted because T20/T31/T37 contain the specified correspondence gaps and T16's understanding case remains limited. This is not a proof failure or evidence that the displayed witness is vacuous." + }, + { + "case": "same_context_identity", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The existential witness uses the full encoded Inherited and DomainSatisfied records at sharedContext/evolvable, with active applicability, no threat, larger present complexity, nonempty own facts and successor/agent paths. Its mathematical inhabitation is accepted. Full source/target composition is not yet accepted because T20/T31/T37 contain the specified correspondence gaps and T16's understanding case remains limited. This is not a proof failure or evidence that the displayed witness is vacuous." + }, + { + "case": "nonempty_claims_and_principles", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The existential witness uses the full encoded Inherited and DomainSatisfied records at sharedContext/evolvable, with active applicability, no threat, larger present complexity, nonempty own facts and successor/agent paths. Its mathematical inhabitation is accepted. Full source/target composition is not yet accepted because T20/T31/T37 contain the specified correspondence gaps and T16's understanding case remains limited. This is not a proof failure or evidence that the displayed witness is vacuous." + }, + { + "case": "active_evolution_priority", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The existential witness uses the full encoded Inherited and DomainSatisfied records at sharedContext/evolvable, with active applicability, no threat, larger present complexity, nonempty own facts and successor/agent paths. Its mathematical inhabitation is accepted. Full source/target composition is not yet accepted because T20/T31/T37 contain the specified correspondence gaps and T16's understanding case remains limited. This is not a proof failure or evidence that the displayed witness is vacuous." + }, + { + "case": "content_bearing_maintainer_change", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The existential witness uses the full encoded Inherited and DomainSatisfied records at sharedContext/evolvable, with active applicability, no threat, larger present complexity, nonempty own facts and successor/agent paths. Its mathematical inhabitation is accepted. Full source/target composition is not yet accepted because T20/T31/T37 contain the specified correspondence gaps and T16's understanding case remains limited. This is not a proof failure or evidence that the displayed witness is vacuous." + } + ], + "declarations": [ + { + "name": "CoreReader.Engineering.jointWitness", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Engineering/Integration.lean", + "line": 396, + "end": 424, + "exact_delta_code": "theorem jointWitness :\n ∃ ctx : Context, ∃ chosen : Candidate,\n ctx = sharedContext ∧ chosen = .evolvable ∧\n Inherited ctx chosen ∧ DomainSatisfied ctx chosen ∧\n PriorityConditions ctx ∧ ¬ HasThreat ctx .evolvable ∧\n abstractionComplexity .presentSimple < abstractionComplexity chosen ∧\n CanChange ctx.activity chosen .successor .designRevision ∧\n CanChange ctx.activity chosen .agent .designRevision ∧\n ownTheory chosen (ownFactClaim chosen .selected) ∧\n (.commitment .grounds : ReviewObject) ∈ (selfModel chosen).objects ∧\n Admissible (ownTheory chosen) (comparisonContext chosen) chosen := by\n exact ⟨sharedContext, .evolvable, rfl, rfl,\n inheritedCurrent .evolvable (Or.inr rfl), currentDomainSatisfied,\n currentPriorityConditions, currentNoThreat.1, by decide, by decide, by decide,\n (nonemptyOwnObjects .evolvable).1, (nonemptyOwnObjects .evolvable).2.2.2,\n currentAdmissible .evolvable (Or.inr rfl)⟩\n\n \n \n \n \n \n \n \n \n \n \n \n \n", + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Context []))\n (Lean.Expr.lam\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.lam\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Context []))\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.sharedContext [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.Inherited []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.DomainSatisfied []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.PriorityConditions []) (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.HasThreat []) (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownTheory [])\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownFactClaim [])\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.OwnFact.selected []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.objects [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.commitment [])\n (Lean.Expr.const `CoreReader.Engineering.CoreCommitment.grounds []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `CoreReader.Engineering.OwnFact []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownTheory [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.comparisonContext [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.bvar 0)))))))))))))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default))", + "sha256": "56d1bd97b0ac6c069484812a2a975dc185a905a24ee133a780b5f23a7fdc0b59" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T39", + "kind": "nonentailment", + "registered_statement": "USER ADDITIONAL STRONG OBJECTIVE: a countermodel satisfies all represented inherited commitments while genuine domain-priority applicability holds and domain evolution priority is not adopted; proves non-entailment in the disclosed representation.", + "sources": [ + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + }, + { + "unit": "extensions", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "registered_premises": [ + "Same common context as all inherited duties", + "continuing lifecycle (not temporary), supported credible evolution advantage including design revision, requirements satisfied, no concrete defeating cost threat, present-simplicity preference actually selected/adopted, grounded alternative value reasons consistent with Core, assessment not substituted for adoption." + ], + "disposition": "bounded_nonentailment_witness", + "independent_assessment": "The counterexample uses the same shared continuing context, meets genuine encoded applicability/no-threat conditions, adopts simple via its own value position and satisfies all encoded Inherited fields. Simple violates the additional rule. Core 0.1.2 permits an application's alternative value commitment; adopting present simplicity is not required to adopt chapter-4 evolution priority. The differing objectives are disclosed premises, not a trick replacing assessment with adoption. The result is accepted for the declared inherited representation, with T16/T20 correspondence qualifications preventing an unqualified assertion about all source obligations.", + "semantic_cases": [ + { + "case": "all_inherited_applicable_domain_not_adopted", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The counterexample uses the same shared continuing context, meets genuine encoded applicability/no-threat conditions, adopts simple via its own value position and satisfies all encoded Inherited fields. Simple violates the additional rule. Core 0.1.2 permits an application's alternative value commitment; adopting present simplicity is not required to adopt chapter-4 evolution priority. The differing objectives are disclosed premises, not a trick replacing assessment with adoption. The result is accepted for the declared inherited representation, with T16/T20 correspondence qualifications preventing an unqualified assertion about all source obligations." + }, + { + "case": "no_temporary_escape", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The counterexample uses the same shared continuing context, meets genuine encoded applicability/no-threat conditions, adopts simple via its own value position and satisfies all encoded Inherited fields. Simple violates the additional rule. Core 0.1.2 permits an application's alternative value commitment; adopting present simplicity is not required to adopt chapter-4 evolution priority. The differing objectives are disclosed premises, not a trick replacing assessment with adoption. The result is accepted for the declared inherited representation, with T16/T20 correspondence qualifications preventing an unqualified assertion about all source obligations." + }, + { + "case": "no_cost_escape", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The counterexample uses the same shared continuing context, meets genuine encoded applicability/no-threat conditions, adopts simple via its own value position and satisfies all encoded Inherited fields. Simple violates the additional rule. Core 0.1.2 permits an application's alternative value commitment; adopting present simplicity is not required to adopt chapter-4 evolution priority. The differing objectives are disclosed premises, not a trick replacing assessment with adoption. The result is accepted for the declared inherited representation, with T16/T20 correspondence qualifications preventing an unqualified assertion about all source obligations." + }, + { + "case": "genuine_priority_failure", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The counterexample uses the same shared continuing context, meets genuine encoded applicability/no-threat conditions, adopts simple via its own value position and satisfies all encoded Inherited fields. Simple violates the additional rule. Core 0.1.2 permits an application's alternative value commitment; adopting present simplicity is not required to adopt chapter-4 evolution priority. The differing objectives are disclosed premises, not a trick replacing assessment with adoption. The result is accepted for the declared inherited representation, with T16/T20 correspondence qualifications preventing an unqualified assertion about all source obligations." + }, + { + "case": "inherited_grounds_for_other_value", + "disposition": "covered_with_target_scope_qualifications", + "basis": "The counterexample uses the same shared continuing context, meets genuine encoded applicability/no-threat conditions, adopts simple via its own value position and satisfies all encoded Inherited fields. Simple violates the additional rule. Core 0.1.2 permits an application's alternative value commitment; adopting present simplicity is not required to adopt chapter-4 evolution priority. The differing objectives are disclosed premises, not a trick replacing assessment with adoption. The result is accepted for the declared inherited representation, with T16/T20 correspondence qualifications preventing an unqualified assertion about all source obligations." + } + ], + "declarations": [ + { + "name": "CoreReader.Engineering.inheritedDoesNotEntailPriority", + "registered_kind": "case", + "actual_kind": "theorem", + "file": "CoreReader/Engineering/Integration.lean", + "line": 425, + "end": 447, + "exact_delta_code": "theorem inheritedDoesNotEntailPriority :\n ∃ ctx : Context, ∃ chosen : Candidate,\n ctx = sharedContext ∧ chosen = .presentSimple ∧\n Inherited ctx chosen ∧ PriorityConditions ctx ∧\n Continuing ctx.activity ∧ ¬ BoundedLifecycle ctx.activity ∧\n ¬ HasThreat ctx .evolvable ∧ ¬ JustifiedDeparture ctx .evolvable ∧\n Meets ctx.required (ctx.profiles .presentSimple) ∧\n Meets ctx.required (ctx.profiles .evolvable) ∧\n credible ctx.evidence .designRevision ∧\n CanChange ctx.activity .evolvable .successor .designRevision ∧\n CanChange ctx.activity .evolvable .agent .designRevision ∧\n changeWork .evolvable .designRevision < changeWork chosen .designRevision ∧\n abstractionComplexity chosen < abstractionComplexity .evolvable ∧\n valueSpecification (selectionPosition chosen) ∧\n (selectionPosition chosen).commitment chosen ∧\n ¬ EvolutionPriority ctx chosen := by\n exact ⟨sharedContext, .presentSimple, rfl, rfl,\n inheritedCurrent .presentSimple (Or.inl rfl), currentPriorityConditions,\n by decide, by decide, currentNoThreat.1, currentNoThreat.2,\n by decide, by decide, by decide, by decide, by decide, by decide, by decide,\n selectionGrounded .presentSimple (Or.inl rfl), rfl, currentSimpleViolates⟩\n\nend CoreReader.Engineering\n", + "axioms": "[propext,\n Classical.choice.{u},\n Quot.sound.{u}]", + "actual_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Context []))\n (Lean.Expr.lam\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.lam\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Context []))\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.sharedContext [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.Inherited []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.PriorityConditions []) (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Continuing [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.Context.activity []) (Lean.Expr.bvar 1))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.HasThreat []) (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.required [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.profiles [])\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.required [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.profiles [])\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.evidence [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `LT.lt [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `LT.lt [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.valueSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))))))))))))))))))))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default))", + "sha256": "ad1b1b45257f57a53567b08bc87eb32bd6d8acf8395e9762a684c1116f270197" + }, + "actual_type_readable_audit": "delta-actual-audit.log" + } + ] + }, + { + "id": "T40", + "kind": "boundary", + "registered_statement": "Formal specification/conditional proofs and finite witnesses do not establish empirical adequacy of lifecycle forecasts, support relevance, future maintainability, value superiority or universal philosophical correctness; representation choices remain disclosed and revisable.", + "sources": [ + { + "unit": "organon.preamble", + "clause": "p1" + }, + { + "unit": "organon.preamble", + "clause": "p2" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p2" + }, + { + "unit": "organon.grounds", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + }, + { + "unit": "organon.grounds.scope", + "clause": "p2" + }, + { + "unit": "organon.grounds.scope", + "clause": "p3" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p1" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p2" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p1" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + }, + { + "unit": "extensions", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p2" + }, + { + "unit": "software-engineering.purpose", + "clause": "p3" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p2" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p2" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p3" + }, + { + "unit": "software-engineering.revision", + "clause": "p1" + }, + { + "unit": "software-engineering.revision", + "clause": "p2" + } + ], + "registered_premises": [ + "Every conditional result carries full mathematical premises", + "finite cases and source correspondence judgments are separate", + "difficult agreed theorem cannot be reclassified boundary to claim completion." + ], + "disposition": "documentary_boundary", + "independent_assessment": "Maintain source authority and separate normative specification, conditional theorem, finite witness, actual measurement, interpretation and adoption. No unseen final reader edition was assessed in this initial comparison. Disclosed abstraction does not automatically discharge a required semantic case or permit relabeling a difficult target as a boundary.", + "semantic_cases": [], + "declarations": [] + } + ], + "source_clauses": [ + { + "unit": "organon.preamble", + "clause": "p1", + "exact_source": "This is a statement of Software Engineering Organon’s adopted philosophy. It expresses commitments, not factual assertions about every system or a proof of universal correctness.", + "source_excerpt_verified": true, + "registered_declarations": [], + "targets": [ + "T01", + "T40" + ], + "target_dispositions": { + "T01": "documentary_boundary", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Documentary/structural text remains nonformal." + }, + { + "unit": "organon.preamble", + "clause": "p2", + "exact_source": "The quoted provisions, their meanings, and their conditions of application form the core. The charter and Grounds constrain one another; their grouping establishes neither a deductive hierarchy nor an order of priority. [Rationale](docs/rationale.md) supplies arguments and cases without adding obligations to this core. Skills are revisable applications under the repository’s stated objectives and constraints, not part of the philosophical commitments themselves.", + "source_excerpt_verified": true, + "registered_declarations": [], + "targets": [ + "T01", + "T40" + ], + "target_dispositions": { + "T01": "documentary_boundary", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Documentary/structural text remains nonformal." + }, + { + "unit": "organon.charter.overview", + "clause": "p1", + "exact_source": "**Self-Transcendence · Internal Consistency · Reflexivity**", + "source_excerpt_verified": true, + "registered_declarations": [], + "targets": [ + "T01" + ], + "target_dispositions": { + "T01": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Documentary/structural text remains nonformal." + }, + { + "unit": "organon.charter.overview", + "clause": "p2", + "exact_source": "> A system is intrinsically oriented toward expanding what it can understand and construct. It brings itself and its principles within the scope of generation and assessment, with internal consistency constraining this process.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T01", + "T02", + "T38" + ], + "target_dispositions": { + "T01": "documentary_boundary", + "T02": "bounded_specification", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.charter.overview", + "clause": "p3", + "exact_source": "The overview connects three distinct requirements: self-transcendence establishes a generative orientation and refuses to treat existing forms as final, internal consistency constrains judgments held simultaneously, and reflexivity brings the system and its principles within the scope of their own generation and assessment. The provisions below specify the conditions for each.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T01", + "T02", + "T38" + ], + "target_dispositions": { + "T01": "documentary_boundary", + "T02": "bounded_specification", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.charter.self-transcendence", + "clause": "p1", + "exact_source": "> A system is intrinsically oriented toward expanding what it can understand and construct. It does not regard any existing form as the endpoint of generation.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T02", + "T38" + ], + "target_dispositions": { + "T02": "bounded_specification", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.charter.self-transcendence.orientation", + "clause": "p1", + "exact_source": "A commitment to keeping generative possibilities open is distinct from valuing their expansion. A system has an intrinsic orientation when it regards that expansion as worth pursuing. Merely permitting change does not fully express this orientation.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases", + "CoreReader.Adopted.generationLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T02", + "T03", + "T38" + ], + "target_dispositions": { + "T02": "bounded_specification", + "T03": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.charter.self-transcendence.non-finality", + "clause": "p1", + "exact_source": "Refusing to regard an existing form as an endpoint keeps it open to being surpassed. “Existing form” includes a system’s current organization, methods, and principles, not only its appearance or artifacts. These remain within the scope of possible change; their revisability does not guarantee actual progress.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases", + "CoreReader.Adopted.generationLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T02", + "T03", + "T38" + ], + "target_dispositions": { + "T02": "bounded_specification", + "T03": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p1", + "exact_source": "Whether progress has actually occurred remains a separate judgment. Having the orientation does not guarantee progress. Progress cannot be established merely by an increase in the number of artifacts, levels of abstraction, or terms.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.generationLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T03", + "T38" + ], + "target_dispositions": { + "T03": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p2", + "exact_source": "- “Intrinsic orientation” expresses Organon’s philosophical commitment; it does not assert that all systems in fact develop autonomously.\n- Self-transcendence does not imply independence from external experience, knowledge, or collaboration, nor does it guarantee autonomous execution or self-improvement.\n- Refusing to regard an existing form as an endpoint does not require every action to produce change. Justified stability can coexist with a generative orientation.\n- Whether transcendence expands what can be understood and constructed requires discernible grounds; a system’s own claim of generation does not establish actual achievement.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases", + "CoreReader.Adopted.generationLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T02", + "T03", + "T38", + "T40" + ], + "target_dispositions": { + "T02": "bounded_specification", + "T03": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.charter.consistency", + "clause": "p1", + "exact_source": "> The principles and judgments a system holds simultaneously, together with their implications, must not yield contradictory judgments on the same question under the same assumptions, meanings of terms, and scope of application.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.consistencySpecification", + "CoreReader.Adopted.consistencyCases", + "CoreReader.Adopted.consistencyConsequences", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T04", + "T05", + "T38" + ], + "target_dispositions": { + "T04": "bounded_specification", + "T05": "conditional_theorem", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p1", + "exact_source": "“Held simultaneously” specifies which principles, judgments, and implications must hold together. Revision may withdraw an earlier judgment; old and new principles need not remain compatible forever. When a change has occurred, that change cannot be represented as though it had not occurred.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.consistencySpecification", + "CoreReader.Adopted.consistencyCases", + "CoreReader.Adopted.consistencyConsequences", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T04", + "T05", + "T38" + ], + "target_dispositions": { + "T04": "bounded_specification", + "T05": "conditional_theorem", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p2", + "exact_source": "“The same assumptions, meanings of terms, and scope of application” specifies the basis for comparing judgments. Divergent judgments under different conditions do not automatically constitute contradictions. Nor can unacknowledged changes in assumptions, meanings, or scope be used to conceal an existing contradiction.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.consistencySpecification", + "CoreReader.Adopted.consistencyCases", + "CoreReader.Adopted.consistencyConsequences", + "CoreReader.Adopted.consistencyLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T04", + "T05", + "T06", + "T38" + ], + "target_dispositions": { + "T04": "bounded_specification", + "T05": "conditional_theorem", + "T06": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "p1", + "exact_source": "- Tension between different assessments or values does not directly constitute a contradiction. Revision or qualification is needed when they require incompatible conclusions under the same conditions.\n- Internal consistency is not correctness or sufficiency. A set of principles may be internally consistent while relying on false assumptions or neglecting important questions.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.consistencySpecification", + "CoreReader.Adopted.consistencyCases", + "CoreReader.Adopted.consistencyConsequences", + "CoreReader.Adopted.consistencyLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T04", + "T05", + "T06", + "T38" + ], + "target_dispositions": { + "T04": "bounded_specification", + "T05": "conditional_theorem", + "T06": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.charter.reflexivity", + "clause": "p1", + "exact_source": "> A system’s principles of generation and assessment also apply to the system itself and to the formation, application, and revision of those principles.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.reflexivitySpecification", + "CoreReader.Adopted.reflexivityCases012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T07", + "T38" + ], + "target_dispositions": { + "T07": "bounded_specification", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.charter.reflexivity.meaning", + "clause": "p1", + "exact_source": "Reflexivity encompasses both the system itself and its principles. Assessment concerns not only whether the system conforms to its principles, but also how those principles are formed, where they apply, and why they may need revision. The formation and revision of principles thus also become objects of generation and assessment.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.reflexivitySpecification", + "CoreReader.Adopted.reflexivityCases012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T07", + "T38" + ], + "target_dispositions": { + "T07": "bounded_specification", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.charter.reflexivity.limits", + "clause": "p1", + "exact_source": "- Applying principles equally retains their conditions of application. When the relevant conditions hold, being the system itself is not a basis for exemption. Nor does the requirement of reflexivity establish that every principle can be applied to itself without examining its applicability.\n- Self-application does not constitute self-proof. Subjecting a principle to its own assessment does not thereby establish its correctness.\n- That a revision is produced by the system itself does not give it sufficient grounds.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.reflexivitySpecification", + "CoreReader.Adopted.reflexivityCases012", + "CoreReader.Adopted.reflexivityLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T07", + "T08", + "T38" + ], + "target_dispositions": { + "T07": "bounded_specification", + "T08": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.grounds", + "clause": "p1", + "exact_source": "> The grounds of principles and judgments must be articulable and subject to assessment appropriate to the nature of the claim. The strength and scope of a claim must be proportionate to the support provided by its grounds.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.reflexivityLimits012", + "CoreReader.Adopted.Grounds012", + "CoreReader.Adopted.groundsCases012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T08", + "T09", + "T38", + "T40" + ], + "target_dispositions": { + "T08": "bounded_countermodels", + "T09": "qualified_success_specification", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.grounds.assessment", + "clause": "p1", + "exact_source": "Articulation and assessment have distinct responsibilities. Articulability requires that concepts, assumptions, reasons, and limits can be identified. Assessment requires examining whether those grounds support the corresponding claim. Clearly expressed grounds are not thereby sufficiently established.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.Grounds012", + "CoreReader.Adopted.groundsCases012", + "CoreReader.Adopted.groundsLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T09", + "T13", + "T38", + "T40" + ], + "target_dispositions": { + "T09": "qualified_success_specification", + "T13": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.grounds.assessment", + "clause": "p2", + "exact_source": "| Type of claim | Responsibility of assessment | What cannot substitute for that responsibility |\n| --- | --- | --- |\n| Empirical claim | Examine observations, evidence, and performance, together with the conditions, scope, and uncertainty of their support for the claim. | Treating measurability or repeatability itself as proof of relevance, correctness, or value. |\n| Inferential claim | Examine whether the conclusion is supported by the stated assumptions and inferential relations. | Treating the absence of conflict between a conclusion and its assumptions as sufficient to establish that the conclusion follows from them. |\n| Value commitment | State the position taken, its reasons, limits of application, and consequences, and remain open to relevant criticism. | Presenting a commitment as an empirical fact or a necessary inference, or substituting self-assertion for reasons. |", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.Grounds012", + "CoreReader.Adopted.groundsCases012", + "CoreReader.Adopted.empiricalSpecification", + "CoreReader.Adopted.empiricalCases012", + "CoreReader.Adopted.inferentialSpecification", + "CoreReader.Adopted.inferentialCases012", + "CoreReader.Adopted.valueSpecification", + "CoreReader.Adopted.valueCases012", + "CoreReader.Adopted.groundsLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T09", + "T10", + "T11", + "T12", + "T13", + "T38", + "T40" + ], + "target_dispositions": { + "T09": "qualified_success_specification", + "T10": "bounded_success_specification", + "T11": "qualified_success_specification", + "T12": "qualified_value_procedure", + "T13": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3", + "exact_source": "Initial value commitments may be stated explicitly as commitments; they need not prove all their own starting assumptions. The strength and scope of a claim do not require conversion to a common numerical scale. Different types of claims specify their support and limits in accordance with their nature.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.Grounds012", + "CoreReader.Adopted.groundsCases012", + "CoreReader.Adopted.valueSpecification", + "CoreReader.Adopted.valueCases012", + "CoreReader.Adopted.groundsLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T09", + "T12", + "T13", + "T38", + "T40" + ], + "target_dispositions": { + "T09": "qualified_success_specification", + "T12": "qualified_value_procedure", + "T13": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.grounds.scope", + "clause": "p1", + "exact_source": "Performance is discerned within particular relations, conditions, and scopes of observation. A boundary helps specify what a comparison concerns, but local examples do not automatically support unconditional universal conclusions. A judgment cannot establish that relevant differences do not exist merely because its chosen scope omits them.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.scopeSpecification", + "CoreReader.Adopted.scopeCases012", + "CoreReader.Adopted.scopeLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T14", + "T15", + "T38" + ], + "target_dispositions": { + "T14": "qualified_scope_specification", + "T15": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.grounds.scope", + "clause": "p2", + "exact_source": "Measurement can make some differences comparable. Repeated assessment can help examine the stability of corresponding conclusions. Their roles, and the role of any assessment framework, must be explained relative to the claim and its context. Measurement, repeatability, and an assessment framework do not form a universally necessary chain on which all judgments must depend.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.scopeSpecification", + "CoreReader.Adopted.scopeCases012", + "CoreReader.Adopted.scopeLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T14", + "T15", + "T38", + "T40" + ], + "target_dispositions": { + "T14": "qualified_scope_specification", + "T15": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.grounds.scope", + "clause": "p3", + "exact_source": "An observation that has not been reproduced may still offer limited support, and random outcomes need not be identical on every occasion. The verifiability of observations, reproducibility of conditions, and stability of conclusions must be distinguished.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.scopeSpecification", + "CoreReader.Adopted.scopeCases012", + "CoreReader.Adopted.scopeLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T14", + "T15", + "T38", + "T40" + ], + "target_dispositions": { + "T14": "qualified_scope_specification", + "T15": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p1", + "exact_source": "Capability claims are subject to Grounds: the capability claimed, its conditions, and the support for it must be identifiable. The core does not prescribe uniform definitions of method mastery, method generation, or capability levels. Applications specify the capabilities they assess and may require understanding, explanation, or performance under relevant variations.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.capabilitySpecification", + "CoreReader.Adopted.capabilityCases012", + "CoreReader.Adopted.capabilityLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T16", + "T17", + "T38", + "T40" + ], + "target_dispositions": { + "T16": "partial_case_correspondence", + "T17": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p2", + "exact_source": "Grounds for a capability claim may be supplied by an external assessor. Their articulability does not by itself require the assessed system to understand or explain its internal generation process. Evidence of reliable output must be assessed against the capability actually claimed; it does not automatically establish understanding of that process. Nor can the number of method documents, terms, tools, or artifacts alone establish a capability beyond what that evidence supports.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.capabilitySpecification", + "CoreReader.Adopted.capabilityCases012", + "CoreReader.Adopted.capabilityLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T16", + "T17", + "T38", + "T40" + ], + "target_dispositions": { + "T16": "partial_case_correspondence", + "T17": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.grounds.implementations", + "clause": "p1", + "exact_source": "> The choice of an implementation must be supported by reasons connected to the objectives and values pursued and to the relevant constraints. Its name, conventional use, or established status alone does not provide sufficient grounds for giving it priority.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.choiceSpecification", + "CoreReader.Adopted.choiceCases012", + "CoreReader.Adopted.choiceLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T18", + "T19", + "T38", + "T40" + ], + "target_dispositions": { + "T18": "bounded_choice_specification", + "T19": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.grounds.implementations", + "clause": "p2", + "exact_source": "This choice provision adds an additional evaluative commitment: name, conventional use, or established status alone is insufficient to establish priority. Grouping it under Grounds does not mean that it follows from the general requirement to assess reasons, or merely from the discernibility of performance. Conventions and existing arrangements may have practical significance, but that significance must be connected to the objectives and values pursued and to the relevant constraints.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.choiceSpecification", + "CoreReader.Adopted.choiceCases012", + "CoreReader.Adopted.choiceLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T18", + "T19", + "T38", + "T40" + ], + "target_dispositions": { + "T18": "bounded_choice_specification", + "T19": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "p1", + "exact_source": "- Openness does not make all implementations equivalent, nor does it guarantee multiple feasible implementations for the same objective.\n- A method’s explanatory power, limits of application, simplicity, and explicit process requirements may all provide grounded reasons for assessment. They cannot be excluded merely because they concern methods internal to the implementation.\n- Identical local performance does not establish overall equivalence. Relations, conditions, and the scope of comparison are constrained by the provisions of Grounds.\n- Openness does not reject an implementation merely because it already exists or is conventionally used. Relevant reasons may still give it priority.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.scopeLimits012", + "CoreReader.Adopted.choiceSpecification", + "CoreReader.Adopted.choiceCases012", + "CoreReader.Adopted.choiceLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T15", + "T18", + "T19", + "T38" + ], + "target_dispositions": { + "T15": "bounded_countermodels", + "T18": "bounded_choice_specification", + "T19": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.relationships.roles", + "clause": "p1", + "exact_source": "The charter states the generative orientation, the consistency constraint, and reflexive application. Grounds specifies support requirements for judgments and includes an additional commitment concerning implementation choices. Both parts belong to the core and constrain one another. Their placement neither makes Grounds a deduction from the charter nor gives the charter priority over it. Each commitment needs its own reasons.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.reflexivityLimits012", + "CoreReader.Engineering.inheritedMutualApplication", + "CoreReader.Engineering.inheritedMutualCases", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ], + "targets": [ + "T01", + "T08", + "T20", + "T38", + "T39", + "T40" + ], + "target_dispositions": { + "T01": "documentary_boundary", + "T08": "bounded_countermodels", + "T20": "partial_theorem_signature", + "T38": "kernel_witness_source_composition_pending", + "T39": "bounded_nonentailment_witness", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.relationships.roles", + "clause": "p2", + "exact_source": "Internal Consistency concerns whether simultaneously held judgments can hold together; Grounds concerns whether and how far a claim is supported. A conclusion may fail to conflict with its assumptions without being supported by them. Self-Transcendence specifies a generative orientation and non-finality; neither establishes actual capability. Applications may supply objectives, values, and capability definitions; claims made under those objectives, values, and definitions remain subject to the relevant core provisions.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.generationLimits012", + "CoreReader.Adopted.consistencyLimits012", + "CoreReader.Adopted.inferentialSpecification", + "CoreReader.Adopted.inferentialCases012", + "CoreReader.Adopted.capabilitySpecification", + "CoreReader.Adopted.capabilityCases012", + "CoreReader.Engineering.inheritedMutualApplication", + "CoreReader.Engineering.inheritedMutualCases", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ], + "targets": [ + "T03", + "T06", + "T11", + "T16", + "T20", + "T38", + "T39", + "T40" + ], + "target_dispositions": { + "T03": "bounded_countermodels", + "T06": "bounded_countermodels", + "T11": "qualified_success_specification", + "T16": "partial_case_correspondence", + "T20": "partial_theorem_signature", + "T38": "kernel_witness_source_composition_pending", + "T39": "bounded_nonentailment_witness", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.relationships.roles", + "clause": "p3", + "exact_source": "Self-Transcendence does not substitute for Reflexivity: keeping existing forms open to being surpassed differs from applying relevant principles to the system and to their own formation, application, and revision. Reflexivity extends these requirements to the system and to the formation, application, and revision of its principles. The grounds and limits of the Grounds provisions must themselves be articulable. The system’s own capability claims remain subject to assessment, and this philosophy’s existing form cannot gain priority merely from its established status. Such mutual application provides no self-proof and does not remove conditions of application.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.reflexivitySpecification", + "CoreReader.Adopted.reflexivityCases012", + "CoreReader.Adopted.reflexivityLimits012", + "CoreReader.Adopted.capabilitySpecification", + "CoreReader.Adopted.capabilityCases012", + "CoreReader.Adopted.choiceSpecification", + "CoreReader.Adopted.choiceCases012", + "CoreReader.Engineering.inheritedMutualApplication", + "CoreReader.Engineering.inheritedMutualCases", + "CoreReader.Engineering.priorityRemainsReflexive", + "CoreReader.Engineering.priorityReflexiveCases", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ], + "targets": [ + "T07", + "T08", + "T16", + "T18", + "T20", + "T37", + "T38", + "T39", + "T40" + ], + "target_dispositions": { + "T07": "bounded_specification", + "T08": "bounded_countermodels", + "T16": "partial_case_correspondence", + "T18": "bounded_choice_specification", + "T20": "partial_theorem_signature", + "T37": "partial_same_rule_grounding", + "T38": "kernel_witness_source_composition_pending", + "T39": "bounded_nonentailment_witness", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "organon.relationships.terms", + "clause": "p1", + "exact_source": "| Term | Meaning in this philosophy |\n| --- | --- |\n| Existing form | The system’s current organization, methods, and principles, not only its appearance or artifacts. |\n| Assessment | Examination of reasons, applicability, and observed performance; not limited to executable tests. |", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases" + ], + "targets": [ + "T02", + "T21" + ], + "target_dispositions": { + "T02": "bounded_specification", + "T21": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "extensions", + "clause": "p1", + "exact_source": "This chapter adds a software engineering commitment and specifies its meaning and limits. It does not claim that this commitment follows from the Charter or Grounds. Those provisions remain adopted and constrain its application.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.priorityRemainsReflexive", + "CoreReader.Engineering.priorityReflexiveCases", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ], + "targets": [ + "T01", + "T37", + "T38", + "T39", + "T40" + ], + "target_dispositions": { + "T01": "documentary_boundary", + "T37": "partial_same_rule_grounding", + "T38": "kernel_witness_source_composition_pending", + "T39": "bounded_nonentailment_witness", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "software-engineering.purpose", + "clause": "p1", + "exact_source": "Software engineering concerns the construction, operation, understanding, and revision of software within its relevant human and technical conditions. This philosophy guides decisions by people and agents; it does not attribute an intrinsic orientation to every software artifact.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.ActivityScope", + "CoreReader.Engineering.subjectLifecycleCases", + "CoreReader.Engineering.subjectLimits", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T22", + "T23", + "T38", + "T40" + ], + "target_dispositions": { + "T22": "bounded_subject_specification", + "T23": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "software-engineering.purpose", + "clause": "p2", + "exact_source": "The evolution capability considered here belongs to the continuing engineering activity: maintainers, including successor maintainers and agents, working with software, tools, and available knowledge. Code that its original author can modify is not on that ground alone shown to support that continuing activity.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.ActivityScope", + "CoreReader.Engineering.subjectLifecycleCases", + "CoreReader.Engineering.subjectLimits", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T22", + "T23", + "T38", + "T40" + ], + "target_dispositions": { + "T22": "bounded_subject_specification", + "T23": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "software-engineering.purpose", + "clause": "p3", + "exact_source": "Apply the following priority according to the software's credible lifecycle and maintenance expectations. A genuinely temporary script, bounded prototype, or retiring system may have little reason to support further evolution. Calling a continuing system temporary does not establish that condition.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.ActivityScope", + "CoreReader.Engineering.subjectLifecycleCases", + "CoreReader.Engineering.subjectLimits", + "CoreReader.Engineering.EvolutionPriority", + "CoreReader.Engineering.priorityConditionsCases", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T22", + "T23", + "T24", + "T38", + "T40" + ], + "target_dispositions": { + "T22": "bounded_subject_specification", + "T23": "bounded_countermodels", + "T24": "bounded_normative_specification", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p1", + "exact_source": "> When relevant behavioral, safety, performance, and other necessary requirements are satisfied, give priority to continuing maintainers' ability to make credible future changes, including changes to the design itself, over present abstraction simplicity. Accept additional present abstraction complexity for that purpose, while allowing this preference to yield when the added costs threaten concrete engineering objectives.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.EvolutionPriority", + "CoreReader.Engineering.priorityConditionsCases", + "CoreReader.Engineering.priorityWhenApplicable", + "CoreReader.Engineering.priorityChoices", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ], + "targets": [ + "T24", + "T25", + "T38", + "T39", + "T40" + ], + "target_dispositions": { + "T24": "bounded_normative_specification", + "T25": "conditional_theorem", + "T38": "kernel_witness_source_composition_pending", + "T39": "bounded_nonentailment_witness", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2", + "exact_source": "Credible directions of change have articulable grounds, such as a committed plan, relevant domain knowledge, or an applicable history of change. They need not already have multiple implementations. Their credibility remains open to revision; a conceivable change alone does not establish that it warrants accommodation now.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.EvolutionPriority", + "CoreReader.Engineering.priorityConditionsCases", + "CoreReader.Engineering.priorityWhenApplicable", + "CoreReader.Engineering.priorityChoices", + "CoreReader.Engineering.CredibleDirection", + "CoreReader.Engineering.credibilityCases", + "CoreReader.Engineering.credibilityLimits", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ], + "targets": [ + "T24", + "T25", + "T26", + "T27", + "T38", + "T39", + "T40" + ], + "target_dispositions": { + "T24": "bounded_normative_specification", + "T25": "conditional_theorem", + "T26": "qualified_credibility_adapter", + "T27": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T39": "bounded_nonentailment_witness", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3", + "exact_source": "This is a default priority, not an obligation to maximize extensibility or retain every possibility. Costs include relevant burdens of understanding, construction, diagnosis, verification, coordination, operation, and eventual migration. A departure from the priority identifies the objective threatened and why the costs matter. No universal numerical exchange rate between these considerations is prescribed.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.EvolutionPriority", + "CoreReader.Engineering.priorityConditionsCases", + "CoreReader.Engineering.priorityWhenApplicable", + "CoreReader.Engineering.priorityChoices", + "CoreReader.Engineering.CredibleDirection", + "CoreReader.Engineering.credibilityCases", + "CoreReader.Engineering.credibilityLimits", + "CoreReader.Engineering.JustifiedDeparture", + "CoreReader.Engineering.costCases", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ], + "targets": [ + "T24", + "T25", + "T26", + "T27", + "T28", + "T38", + "T39", + "T40" + ], + "target_dispositions": { + "T24": "bounded_normative_specification", + "T25": "conditional_theorem", + "T26": "qualified_credibility_adapter", + "T27": "bounded_countermodels", + "T28": "bounded_cost_specification", + "T38": "kernel_witness_source_composition_pending", + "T39": "bounded_nonentailment_witness", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p1", + "exact_source": "Evolution includes adding capabilities, replacing implementations, deleting mechanisms, withdrawing abstractions, redrawing boundaries, and migrating away from an existing technology or model. Making additions within a fixed scheme does not establish equal ability to revise or leave that scheme. Not every such change can or should be made inexpensive.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.EvolutionClaim", + "CoreReader.Engineering.evolutionKindsCases", + "CoreReader.Engineering.evolutionDimensionsLimits", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T29", + "T30", + "T38", + "T40" + ], + "target_dispositions": { + "T29": "bounded_evolution_specification", + "T30": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p2", + "exact_source": "An evolution claim identifies the relevant changes and the maintainers' conditions. Independent changes, coordinated changes, preservation of existing obligations, and deliberate revision of those obligations can require different structures. A design's advantage on one dimension does not establish an advantage on every dimension.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.EvolutionClaim", + "CoreReader.Engineering.evolutionKindsCases", + "CoreReader.Engineering.evolutionDimensionsLimits", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T29", + "T30", + "T38", + "T40" + ], + "target_dispositions": { + "T29": "bounded_evolution_specification", + "T30": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p1", + "exact_source": "Apply the preceding commitment to engineering consequences as a whole, including the relations among components, their observable contracts, and the work needed to understand and verify a change. An interface's shape, the number of modules or extension points, or the use of a named principle is not sufficient evidence of the claimed capability.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.StructuralAccount", + "CoreReader.Engineering.structuralCases", + "CoreReader.Engineering.structureNotCapability", + "CoreReader.Engineering.priorityRemainsReflexive", + "CoreReader.Engineering.priorityReflexiveCases", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T31", + "T32", + "T37", + "T38", + "T40" + ], + "target_dispositions": { + "T31": "partial_semantic_link", + "T32": "bounded_countermodels_delta_verified", + "T37": "partial_same_rule_grounding", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p2", + "exact_source": "The relevant comparison may examine how a change propagates, which knowledge and obligations cross a boundary, which assumptions become fixed, and what a later withdrawal would require. A proposed boundary needs support for the changes it is meant to accommodate; introducing it does not by itself show that those changes became easier.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.StructuralAccount", + "CoreReader.Engineering.structuralCases", + "CoreReader.Engineering.structureNotCapability", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T31", + "T32", + "T38", + "T40" + ], + "target_dispositions": { + "T31": "partial_semantic_link", + "T32": "bounded_countermodels_delta_verified", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p3", + "exact_source": "Distinguish a transformation that preserves an identified observable contract from one that deliberately revises that contract. The latter needs a corresponding account of changed obligations and affected parties. This distinction does not require preserving every historical behavior or using a particular testing or migration procedure.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.ContractChangeAccount", + "CoreReader.Engineering.contractCases", + "CoreReader.Engineering.contractPreservation", + "CoreReader.Engineering.contractDistinctions", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T33", + "T34", + "T38", + "T40" + ], + "target_dispositions": { + "T33": "bounded_contract_specification", + "T34": "conditional_theorem", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "software-engineering.revision", + "clause": "p1", + "exact_source": "Changed evidence about likely changes, maintenance conditions, costs, or objectives may justify revising a design or this priority's application. A revised judgment acknowledges material changes in its grounds; it does not make a failed prediction successful retrospectively.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.RevisionAccount", + "CoreReader.Engineering.revisionCases", + "CoreReader.Engineering.revisionLimits", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T35", + "T36", + "T38", + "T40" + ], + "target_dispositions": { + "T35": "qualified_revision_account", + "T36": "bounded_countermodels_with_scope_limit", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + }, + { + "unit": "software-engineering.revision", + "clause": "p2", + "exact_source": "Retaining a design can be justified when the relevant alternatives have no supported contribution or impose costs that defeat the objective. Reflexivity also keeps this engineering commitment and the methods used to assess evolution within the scope of criticism and revision. Continued change, agreement, or successful examples do not establish its universal correctness.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.RevisionAccount", + "CoreReader.Engineering.revisionCases", + "CoreReader.Engineering.revisionLimits", + "CoreReader.Engineering.priorityRemainsReflexive", + "CoreReader.Engineering.priorityReflexiveCases", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T35", + "T36", + "T37", + "T38", + "T40" + ], + "target_dispositions": { + "T35": "qualified_revision_account", + "T36": "bounded_countermodels_with_scope_limit", + "T37": "partial_same_rule_grounding", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link." + } + ], + "blind_concern_dispositions": [ + { + "id": "C01", + "original_blind_concern": "Fixed finite costs, profiles, paths, credibility classifications and histories are stipulated data, not independent measurements.", + "disposition": "retained_application_boundary", + "source_comparison": "Source §§4.1–4.5 and T40 explicitly allow context-specific application evidence; hardcoded finite data do not by themselves violate source. Actual lifecycle, knowledge/history relevance, costs and forecast truth remain unverified, including T26." + }, + { + "id": "C02", + "original_blind_concern": "EvolutionPriority is assumed by priorityWhenApplicable. The proof eliminates its departure branch and projects the complexity comparison from applicability.", + "disposition": "resolved_as_explicit_normative_premise", + "source_comparison": "T25 explicitly requires the adopted domain norm as premise. The projection is faithful to that conditional, not independent justification of adoption." + }, + { + "id": "C03", + "original_blind_concern": "Standalone DomainSatisfied does not require Meets or PriorityConditions; a context with an unsafe evolvable profile can still satisfy it.", + "disposition": "not_a_source_conflict_for_false_antecedent", + "source_comparison": "Source gives priority when necessary requirements hold; it does not say a record about priority/structure/history proves universal requirement satisfaction. The unsafe DomainSatisfied probe is a boundary on that name, while T38 separately supplies PriorityConditions and real modeled profiles." + }, + { + "id": "C04", + "original_blind_concern": "engineeringCapability requires equality to the same capabilityOutput function used to define engineeringProcess; its ground theorem holds even for maximal and imposes no positive capability threshold.", + "disposition": "retained_narrow_claim_not_failure_alone", + "source_comparison": "Core 0.1.2 permits application-specific capability definitions. Equality to the declared total output function is a genuine narrow claim proved for the same process; it must not be described as independent positive maintainability certification. Path contrast supplies the nontrivial maintenance facts for T38/T39." + }, + { + "id": "C05", + "original_blind_concern": "Simple and evolvable selection procedures use different objectives and starting assumptions fixed to their own adopted candidates.", + "disposition": "resolved_as_permitted_alternative_value", + "source_comparison": "Source roles and §4 state that engineering preference is additional. The simple value position may pursue simplicity and the evolvable one revision work, so long as reasons/constraints are disclosed. Their different objectives are essential to the bounded non-entailment witness, not a source inconsistency." + }, + { + "id": "C06", + "original_blind_concern": "Grounds012 quantifies over the supplied nonempty facet list for one supplied task; it has no actualApplicable coverage predicate.", + "disposition": "retained_scope_boundary_not_core013_requirement", + "source_comparison": "Core 0.1.2 source and T09 do not require the later all-applicable-facet interface. The one-task formulation cannot be called an exhaustive taxonomy, but it may represent one task with multiple methods. No Core 0.1.3 obligation is imposed." + }, + { + "id": "C07", + "original_blind_concern": "Raw Supports permits inconsistent records to support any proposition; inference over unsatisfiable theories is likewise vacuous.", + "disposition": "mitigated_in_discharged_facets", + "source_comparison": "FacetDischarged requires witnesses. The actual empirical/inferential and composition examples use nonempty compatible/satisfiable domains, so raw-support vacuity does not invalidate them." + }, + { + "id": "C08", + "original_blind_concern": "ValueProcedure is conditional on all reasons, supplied objectives/constraints and scope; it does not establish universal adoption or semantic adequacy of responses.", + "disposition": "retained_sufficient_procedure_boundary", + "source_comparison": "Source asks articulated reasons, consequences, limits and openness, not proof of universal value correctness. ValueProcedure is a sufficient application procedure; response nonemptiness and conditional consequence must not be elevated into a universal definition of adequate criticism or legitimate value." + }, + { + "id": "C09", + "original_blind_concern": "The generic reflexivity relation may be vacuous for no rules/self/applicability and records/meaning are supplied relations. recordedReflexivity assumes follows.", + "disposition": "mitigated_by_concrete_self_records", + "source_comparison": "Empty generic registries/applicability are permitted formal boundary cases; positive examples have actual own targets, membership, nonempty reasons and checked basis/meaning. Missing same-priority support linkage in T37 remains a distinct issue." + }, + { + "id": "C10", + "original_blind_concern": "Reflection.evaluate ignores claimed scope, basis, reasons and target; empty tested/requested lists return supportedWithinScope.", + "disposition": "mitigated_by_interpret_and_concrete_inputs", + "source_comparison": "Concrete self records have nonempty tested/requested inputs, independently checked basis and nonempty reasons. Raw evaluate can be vacuous and ignores claimed scope, so its return value alone must not be called full assessment fulfillment." + }, + { + "id": "C11", + "original_blind_concern": "The simple selfModel omits the priority review object; reflection of that model is not evidence that simple satisfies priority.", + "disposition": "resolved_for_countermodel_scope", + "source_comparison": "T39 declines the additional engineering priority; it need not review that unadopted priority as an adopted own principle. T38/evolvable does include the priority object. The omission does not show a covert failure of adopted Core duties." + }, + { + "id": "C12", + "original_blind_concern": "PreservesFinite and affectedParties inspect only fixed input/dependency lists. contractPreservation receives the complete universal equality as its premise.", + "disposition": "retained_finite_scope_and_identity_proof", + "source_comparison": "T33/T34 explicitly allow identified observation scope and finite examples. Universal contractPreservation is the supplied equality premise; parties/procedures are finite model obligations, not actual notices. The retained [99] counterexample makes scope limits explicit." + }, + { + "id": "C13", + "original_blind_concern": "RevisionAccountAgainst checks exact equality to caller-supplied history and criticism-list coverage, not historical authenticity or substantive criticism.", + "disposition": "retained_history_provenance_boundary", + "source_comparison": "The invariant comparison against fixed history meets the modeled no-retroactive-success requirement. Authentic external history and substantive criticism are not proved. This is legitimate bounded evidence, not a universal history-authentication theorem." + }, + { + "id": "C14", + "original_blind_concern": "ContinuingCapability can pass with no participants; RetentionJustified can pass with no alternatives; Consistent can pass with an empty question type.", + "disposition": "mitigated_for_registered_witnesses", + "source_comparison": "Current applicability includes nonempty participants, question/fact domains are inhabited, and concrete alternatives are listed. Empty generic cases remain documented and must not be mistaken for the actual positive witness." + }, + { + "id": "C15", + "original_blind_concern": "inheritedMutualApplication extracts fields of Inherited; it does not establish mutual implication among fewer independent principles.", + "disposition": "partial_target_signature_confirmed", + "source_comparison": "T20 is intentionally conditional, so projection itself is legitimate. Nevertheless its required target statement includes consistency, while the actual conclusion omits inherited.consistency. Full exact target completion needs that distinction resolved; no claim of mutual logical derivation is warranted." + }, + { + "id": "C16", + "original_blind_concern": "Some prior Integration and Adopted value experiments use Classical.propDecidable for arbitrary propositions.", + "disposition": "resolved_as_allowed_nonexecutable_assessment", + "source_comparison": "Source necessary terms and §2.2 expressly do not require every assessment to be executable. Classical proposition decisions are valid logical constructions provided the delivery does not advertise them as executable empirical tools." + }, + { + "id": "C17", + "original_blind_concern": "Articulated only checks nonempty lists; ScopeAccount.explains and generic ReflexiveRule.meaning remain supplied predicates.", + "disposition": "retained_interface_and_linkage_boundary", + "source_comparison": "Concrete expansions supply more than abstract labels, but nonempty strings do not prove explanatory relevance for arbitrary inputs. T31 has a specific missing boundary/obligation connection; T37 grounds quantification covers five Core labels, not directly the engineering priority rule." + } + ], + "findings": [ + { + "id": "F01", + "targets": [ + "T16" + ], + "finding": "The required understanding case establishes ExplanationContract only. Accept its explanation branch, not unmodeled understanding." + }, + { + "id": "F02", + "targets": [ + "T20" + ], + "finding": "The actual preservation theorem conclusion omits consistency present in its premise and promised in the target." + }, + { + "id": "F03", + "targets": [ + "T31" + ], + "finding": "The required cross-boundary-obligation case identifies a component/publicContract step but no Boundary relation or crossing obligation." + }, + { + "id": "F04", + "targets": [ + "T37" + ], + "finding": "Reflection covers the priority object, but theorem grounds cover CoreCommitment only and consistency is absent from the result; the same priority-rule grounding connection is missing." + }, + { + "id": "F05", + "targets": [ + "T38" + ], + "finding": "Kernel inhabitation is accepted; full source-composition completion remains dependent on resolving the above representation/target gaps." + } + ] +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/blind-source-initial.md b/SoftwareEngineering/lean/philosophy/reviews/blind-source-initial.md new file mode 100644 index 0000000..23d7d6d --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/blind-source-initial.md @@ -0,0 +1,1019 @@ +# Initial independent source comparison + +This is the first source-aware comparison after preserving the initial and delta blind artifacts. It uses **Software Engineering 0.2.0, adopting Core 0.1.2**. Core 0.1.3 has not been substituted. The authoritative source is PHILOSOPHY.md (SHA256 `6c6ae78a23f2726c5c370434e808d76c206647fe7793245e88cae52c076abe34`). The rationale and cases were read only as auxiliary explanations; no linked literature or other iteration/reviewer records were consulted. + +The current raw code was copied on first source disclosure and its hashes recorded. Removing comments and blank lines yields exactly the frozen delta code. All judgments below apply to that object, not later revisions. The 40 frozen targets and all 47 source paragraphs were inspected; every copied source excerpt was checked as an exact substring of the authoritative text. `source-comparison-initial.json` preserves each target's premises, each required declaration's exact code/current location, full type AST from the permitted actual audit, actual axioms, and per-semantic-case dispositions. Readable full types remain in `delta-actual-audit.log`. + +**Result: the Lean claims are checked, but I do not accept every preregistered target as fully source-correspondent yet.** Most are defensible bounded specifications, conditional results or concrete countermodels. T16 has a narrower explanation case than its understanding label; T20's theorem omits consistency from its conclusion; T31 lacks the required actual boundary/obligation linkage; T37 does not directly carry grounds for the same engineering-priority rule and omits consistency from its result. T38's kernel witness is valid, while its complete source-composition claim remains dependent on these qualifications. These findings do not establish philosophical incompatibility, and they do not authorize changing any commitment or silently weakening a target. + +## Main distinctions + +The normative rule is a premise of `priorityWhenApplicable`, as T25 expressly requires. `contractPreservation` receives the complete universal in-scope equality as a premise. Both are legitimate conditional theorems; neither is evidence that the norm was deduced or that finite tests proved universal behavior. Similarly, `inheritedMutualApplication` projects fields from a proof record. Projection is valid, but only the fields actually concluded may be reported as the theorem's result. + +The final joint and non-entailment witnesses are not arbitrary independent truth flags: they bind the same context/candidate, concrete knowledge/tool paths, supported plan, actual numeric requirements, own-fact theory, value position and self model. The simple candidate really violates the additional priority while satisfying the encoded inherited record; its alternative value objective is permitted by the selected Core 0.1.2 baseline. That bounded mathematical result is accepted. It remains distinct from a claim that every source obligation is adequately represented or that the cost, forecast and capability interpretation is empirically established. + +`Grounds012` is best read as successful support for a declared task; correct negative assessment is separately exhibited by `InferenceExamined false`. The source asks whether support holds, so failed support must not be described as failure to perform a correct assessment. Value procedures are sufficient application constructions, not new source requirements that every value commitment prove all objectives or that nonempty response strings exhaust openness to criticism. Finite support and arbitrary generic interface predicates must retain their scopes. + +The exact equal-work boundary case is now present in the preserved delta: relocation changes real path component fields and keeps all work units, while the successor still lacks privateLayout. This resolves the specific T32 case for the reviewed code. It does not resolve T31's separate linkage between a boundary, crossing knowledge/obligations and the intended-change account. + +## Target-by-target comparison + +### T01: documentary_boundary + +**Registered objective.** Authority and roles: adopted commitments, no universal factual assertion or correctness proof; meanings and limits constrain quotation; charter and Grounds mutually constrain without hierarchy; rationale/skills add no philosophical duties; domain preference is additional. + +**Independent result.** The source explicitly adopts commitments rather than claiming universal factual truth or deductive hierarchy. The chapter-4 preference is additional. No theorem is required for document authority, and the concrete countermodels must not be promoted into independence of every conceivable formalization. + +**Actual declaration evidence.** Documentary boundary; no theorem required. + +**Required semantic cases.** None registered. + +### T02: bounded_specification + +**Registered objective.** Self-transcendence requires valuing expansion of understanding and construction and keeping all existing organization, methods and principles open to being surpassed; justified stable acts remain permitted. + +**Independent result.** Generative requires valuation of expansion and revisability of every current Form, including organization, method and principle. Current examples are nonempty; the stable trace and budget-respecting stable action show that generativity does not require change in every act. This is an adopted policy predicate, not proof all systems possess it. + +**Actual declaration evidence.** `CoreReader.Adopted.generationSpecification` (`CoreReader/Adopted.lean:80`), `CoreReader.Adopted.generationCases` (`CoreReader/Adopted.lean:796`) + +**Required semantic cases.** `positive_valued_open_forms`: covered_with_target_scope_qualifications; `negative_permission_only`: covered_with_target_scope_qualifications; `positive_stability`: covered_with_target_scope_qualifications; `external_collaboration`: covered_with_target_scope_qualifications + +### T03: bounded_countermodels + +**Registered objective.** Permission to change does not entail valuing expansion; valuing/open forms do not entail achieved progress, actual capability, independence, autonomous execution or self-improvement; output/term/abstraction counts or self-claims alone do not establish achievement. + +**Independent result.** The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions. + +**Actual declaration evidence.** `CoreReader.Adopted.generationLimits012` (`CoreReader/Adopted.lean:838`) + +**Required semantic cases.** `permission_without_value`: covered_with_target_scope_qualifications; `orientation_without_progress`: covered_with_target_scope_qualifications; `count_growth_without_capability`: covered_with_target_scope_qualifications; `collaborative_nonautonomous_progress`: covered_with_target_scope_qualifications; `claim_without_achievement`: covered_with_target_scope_qualifications; `achievement_support_for_same_claim`: covered_with_target_scope_qualifications + +### T04: bounded_specification + +**Registered objective.** All simultaneously held principles/judgments and their joint implications must avoid opposite conclusions on same question, assumptions, term meanings and scope; incompatible same-condition demands need revision/qualification; recorded change cannot be concealed. + +**Independent result.** Consistent quantifies over joint semantic consequences of the whole held theory under one Context. Snapshot change reporting is a separate one-way Boolean obligation. The code preserves same-question/assumptions/meaning/scope and time-slice distinctions; it does not model every way a prose report could conceal change. + +**Actual declaration evidence.** `CoreReader.Adopted.consistencySpecification` (`CoreReader/Adopted.lean:90`), `CoreReader.Adopted.consistencyCases` (`CoreReader/Adopted.lean:886`) + +**Required semantic cases.** `joint_only_contradiction`: covered_with_target_scope_qualifications; `changed_scope_not_concealed`: covered_with_target_scope_qualifications; `revision_withdraws_old`: covered_with_target_scope_qualifications; `incompatible_same_context`: covered_with_target_scope_qualifications + +### T05: conditional_theorem + +**Registered objective.** Given faithful context identity and whole-set consequence, an opposite pair under the same context violates consistency; removing a prior judgment may eliminate the conflict without requiring permanent historical compatibility. + +**Independent result.** consistencyConsequences directly applies the consistency prohibition to supplied positive and negative consequences. The revisionSlice examples provide distinct satisfiable times and inconsistent union; context examples preserve an admissible witness for each context. The theorem neither proves premises nor mandates permanent historical compatibility. + +**Actual declaration evidence.** `CoreReader.Adopted.consistencyConsequences` (`CoreReader/Adopted.lean:241`), `CoreReader.Adopted.consistencyCases` (`CoreReader/Adopted.lean:886`) + +**Required semantic cases.** `pair_conflict`: covered_with_target_scope_qualifications; `joint_premise_conflict`: covered_with_target_scope_qualifications; `old_new_separate_times`: covered_with_target_scope_qualifications; `distinct_context_judgments`: covered_with_target_scope_qualifications; `truthful_semantic_change_and_reordering`: covered_with_target_scope_qualifications + +### T06: bounded_countermodels + +**Registered objective.** Different-condition disagreement and value tension alone do not entail contradiction; consistency does not entail true assumptions, adequacy or support for a compatible conclusion. + +**Independent result.** Concrete contexts, overlapping inequalities, a consistent theory false at the selected outside world, and empty-theory countervaluations distinguish contradiction, truth, sufficiency and entailment. These support the source limits without relying on a free false support flag. + +**Actual declaration evidence.** `CoreReader.Adopted.consistencyLimits012` (`CoreReader/Adopted.lean:921`) + +**Required semantic cases.** `different_contexts`: covered_with_target_scope_qualifications; `tension_compatible`: covered_with_target_scope_qualifications; `consistent_false_assumption`: covered_with_target_scope_qualifications; `consistent_omitted_question`: covered_with_target_scope_qualifications; `compatible_not_entailed`: covered_with_target_scope_qualifications + +### T07: bounded_specification + +**Registered objective.** Generation and assessment apply to system and principle formation/application/revision under their actual applicability conditions; self-status is no exemption; applicability is not universalized; Grounds grounds/limits and own capability claims are included. + +**Independent result.** The generic adapter keeps self and applicability predicates and exact input/outcome links. The legacy finite model includes system, own principles and formation/application/revision, with an inapplicable system in the application-only example. Grounds-on-grounds has an actual value rationale. Empty generic domains remain possible but are not the supplied positive witness. + +**Actual declaration evidence.** `CoreReader.Adopted.reflexivitySpecification` (`CoreReader/Adopted.lean:110`), `CoreReader.Adopted.reflexivityCases012` (`CoreReader/Adopted.lean:949`) + +**Required semantic cases.** `self_applicable`: covered_with_target_scope_qualifications; `self_inapplicable`: covered_with_target_scope_qualifications; `principle_formation`: covered_with_target_scope_qualifications; `principle_application`: covered_with_target_scope_qualifications; `principle_revision`: covered_with_target_scope_qualifications; `grounds_on_grounds`: covered_with_target_scope_qualifications + +### T08: bounded_countermodels + +**Registered objective.** Self-application or self-produced revision does not establish correctness or sufficient grounds; openness of forms does not by itself meet reflexivity. In the declared representation, one nonempty common context satisfies the complete represented Charter requirements but fails the represented general Grounds requirement for a concrete identified claim. This bounded example shows that chapter placement supplies no deductive support; it does not assert independence in every possible representation. + +**Independent result.** A revisable principle applied only to target 1 fails required self-target 0; self tests fail elsewhere; owned revisions retain unsupported global claims. CompleteCharter012 is inhabited yet costAllowanceRecord admits an incorrect-output world, so the concrete corresponding Grounds012 claim fails. This is a bounded charter-versus-support model, not philosophical independence in all interpretations. + +**Actual declaration evidence.** `CoreReader.Adopted.reflexivityLimits012` (`CoreReader/Adopted.lean:972`) + +**Required semantic cases.** `self_assessed_incorrect`: covered_with_target_scope_qualifications; `self_generated_unsupported`: covered_with_target_scope_qualifications; `open_but_self_exempt`: covered_with_target_scope_qualifications; `charter_not_general_grounds`: covered_with_target_scope_qualifications + +### T09: qualified_success_specification + +**Registered objective.** Grounds requires articulable concepts/assumptions/reasons/limits, assessment appropriate to claim nature, and strength/scope proportionate to supplied support. Articulation and assessment are distinct responsibilities. + +**Independent result.** Grounds012 formalizes successful supported grounds for one declared task using same claim/articulation/discharge and task-appropriateness. Local/global and stronger-claim countermodels preserve force and scope. It is not a complete classifier or universal procedure for deciding all possible mixed claims. Calling it the obligation to examine rather than the successful support condition would overstate the correspondence. + +**Actual declaration evidence.** `CoreReader.Adopted.Grounds012` (`CoreReader/Adopted.lean:54`), `CoreReader.Adopted.groundsCases012` (`CoreReader/Adopted.lean:1000`) + +**Required semantic cases.** `articulable_supported`: covered_with_target_scope_qualifications; `articulable_unsupported`: covered_with_target_scope_qualifications; `scope_overreach`: covered_with_target_scope_qualifications; `strength_overreach`: covered_with_target_scope_qualifications + +### T10: bounded_success_specification + +**Registered objective.** Empirical assessment examines observations, evidence and performance and their support conditions, scope and uncertainty; measurability/repeatability is no replacement for relevance, correctness or value assessment. + +**Independent result.** Empirical discharge includes an in-scope compatible witness, scoped support and uncertainty support. Repetition of irrelevant first-coordinate/action observations cannot establish the second coordinate or budget value. The successful uncertainty is the exhaustive Boolean disjunction, not a quantified confidence estimate or a production measurement. + +**Actual declaration evidence.** `CoreReader.Adopted.empiricalSpecification` (`CoreReader/Adopted.lean:152`), `CoreReader.Adopted.empiricalCases012` (`CoreReader/Adopted.lean:1016`) + +**Required semantic cases.** `observed_relevant`: covered_with_target_scope_qualifications; `repeatable_irrelevant`: covered_with_target_scope_qualifications; `measured_wrong_scope`: covered_with_target_scope_qualifications; `uncertain_limited`: covered_with_target_scope_qualifications + +### T11: qualified_success_specification + +**Registered objective.** Inferential assessment examines whether conclusion follows/supports under stated assumptions and inferential relations; mere nonconflict cannot replace this examination. + +**Independent result.** The inferential wrapper requires satisfiable assumptions and actual entailment. Correct rejection of an unentailed conclusion is represented separately by InferenceExamined false and a countervaluation. Together they preserve the examination/success distinction, provided the wrapper alone is not described as the full act of assessment. + +**Actual declaration evidence.** `CoreReader.Adopted.inferentialSpecification` (`CoreReader/Adopted.lean:161`), `CoreReader.Adopted.inferentialCases012` (`CoreReader/Adopted.lean:1048`) + +**Required semantic cases.** `valid_inference`: covered_with_target_scope_qualifications; `compatible_unentailed`: covered_with_target_scope_qualifications; `false_inference_detected`: covered_with_target_scope_qualifications + +### T12: qualified_value_procedure + +**Registered objective.** Value commitments identify position, reasons, applicability limits and consequences and stay open to relevant criticism; neither empirical/necessary-inference presentation nor self-assertion substitutes. Initial commitments need not prove all starting assumptions. + +**Independent result.** The value construction identifies position, joint reasons, application limits, consequences and relevant criticism responses. It assumes starting claims and supplies a joint witness instead of proving every starting assumption. The universal consequence test and response nonemptiness are this application's sufficient procedure, not newly mandatory philosophical proof requirements or proof of response adequacy. + +**Actual declaration evidence.** `CoreReader.Adopted.valueSpecification` (`CoreReader/Adopted.lean:168`), `CoreReader.Adopted.valueCases012` (`CoreReader/Adopted.lean:1065`) + +**Required semantic cases.** `reasoned_value`: covered_with_target_scope_qualifications; `unsupported_self_assertion`: covered_with_target_scope_qualifications; `closed_criticism`: covered_with_target_scope_qualifications; `explicit_initial_commitment`: covered_with_target_scope_qualifications + +### T13: bounded_countermodels + +**Registered objective.** Articulability alone does not establish grounds; measurable/repeatable observations alone establish neither relevance, correctness nor value; a stated value commitment need not be empirical fact or necessary consequence, nor prove all its starting assumptions. + +**Independent result.** Clearly articulated false assumptions, repeated wrong-object observations, neutral records compatible with nonadoption, and the ordinary value example show the intended non-substitutions. Qualitative implication orders claim strength without imposing a numerical scale. + +**Actual declaration evidence.** `CoreReader.Adopted.groundsLimits012` (`CoreReader/Adopted.lean:1086`) + +**Required semantic cases.** `clear_false_reason`: covered_with_target_scope_qualifications; `repeatable_wrong_object`: covered_with_target_scope_qualifications; `value_not_fact`: covered_with_target_scope_qualifications; `initial_value_without_selfproof`: covered_with_target_scope_qualifications; `qualitative_proportionality`: covered_with_target_scope_qualifications + +### T14: qualified_scope_specification + +**Registered objective.** Performance/comparison judgments state relevant relations, conditions and observation scope; scope omission cannot establish absence of relevant differences; roles of measurement, repetition and framework are explained relative to claim/context. + +**Independent result.** The local scope account binds comparison pairs, conditions, observed scope, relevance and each method explanation to the same claim. Its concrete method meanings prove local/repeated support and failure of global support. The generic explains relation remains supplied and the interface does not force every method to be used. + +**Actual declaration evidence.** `CoreReader.Adopted.scopeSpecification` (`CoreReader/Adopted.lean:191`), `CoreReader.Adopted.scopeCases012` (`CoreReader/Adopted.lean:1118`) + +**Required semantic cases.** `local_scope_declared`: covered_with_target_scope_qualifications; `omitted_relevant_difference`: covered_with_target_scope_qualifications; `measurement_role`: covered_with_target_scope_qualifications; `repetition_role`: covered_with_target_scope_qualifications; `framework_role`: covered_with_target_scope_qualifications + +### T15: bounded_countermodels + +**Registered objective.** Local equal performance does not entail global equivalence/unconditional universality; omitting a difference does not establish its nonexistence. Limited unreproduced support and variable random outcomes are possible without a universal measurement→repeatability→framework chain. + +**Independent result.** Explicit functions agree only at zero and differ at one; one observation supplies local support. Trial fields separate recorded accuracy, equal settings and bounded output, and Boolean draws have equal positive weights with different outcomes. This is a finite possible-outcome model, not verification of a real stochastic process. + +**Actual declaration evidence.** `CoreReader.Adopted.scopeLimits012` (`CoreReader/Adopted.lean:1131`) + +**Required semantic cases.** `equal_local_different_global`: covered_with_target_scope_qualifications; `excluded_difference`: covered_with_target_scope_qualifications; `one_observation_limited_support`: covered_with_target_scope_qualifications; `varying_random_outcomes`: covered_with_target_scope_qualifications; `qualitative_unmeasured_judgment`: covered_with_target_scope_qualifications + +### T16: partial_case_correspondence + +**Registered objective.** Capability claim identifies capability, conditions and support under Grounds; applications choose relevant capability definitions and may require understanding/explanation/variation. External assessors may provide grounds; own-system claims receive same relevant duties. + +**Independent result.** Output-only and explained doubling processes establish the source's external-assessment and application-specific explanation branches. The required semantic case named application_requires_understanding is not yet accepted as an understanding result: ExplanationContract only requires a stored Program extensionally equal to the output. No independent process-understanding criterion is modeled. The source allows applications to define capabilities, but that definition and this loss must be explicit rather than equating any output-equivalent program with understanding. + +**Actual declaration evidence.** `CoreReader.Adopted.capabilitySpecification` (`CoreReader/Adopted.lean:205`), `CoreReader.Adopted.capabilityCases012` (`CoreReader/Adopted.lean:1166`) + +**Required semantic cases.** `external_output_capability`: covered_with_target_scope_qualifications; `application_requires_understanding`: partial_explanation_not_independent_understanding; `own_capability_assessment`: covered_with_target_scope_qualifications + +### T17: bounded_countermodels + +**Registered objective.** Reliable output or artifact/document/tool/term count alone does not establish internal-process understanding or stronger capability; articulable external grounds do not imply that assessed system understands/explains generation. + +**Independent result.** Reliable double output with explanation = none refutes the stronger declared explanation contract; repeated item counts do not add an unavailable operation. This establishes limits on the represented output/explanation capability, not a cognitive account of human or agent understanding. + +**Actual declaration evidence.** `CoreReader.Adopted.capabilityLimits012` (`CoreReader/Adopted.lean:1180`) + +**Required semantic cases.** `reliable_opaque_generator`: covered_with_target_scope_qualifications; `high_count_no_stronger_capability`: covered_with_target_scope_qualifications; `externally_articulated_no_introspection`: covered_with_target_scope_qualifications + +### T18: bounded_choice_specification + +**Registered objective.** Implementation priority needs reasons connected to objectives, values and relevant constraints; name/convention/status alone insufficient. Internal method explanation, applicability limits, simplicity/process requirements may count; conventional options may win on relevant grounds, including this philosophy's existing form. + +**Independent result.** JustifiedChoice combines feasibility with a valued method-content reason; status-only reasons fail by definition as the additional adopted evaluative commitment. Conventional identity remains eligible, internal explanation/applicability/simplicity/procedure reasons are admissible, and the current philosophy review is assessed by actual output reasons. No optimality or all-reasons-valid theorem is claimed. + +**Actual declaration evidence.** `CoreReader.Adopted.choiceSpecification` (`CoreReader/Adopted.lean:215`), `CoreReader.Adopted.choiceCases012` (`CoreReader/Adopted.lean:1221`) + +**Required semantic cases.** `named_only_rejected`: covered_with_target_scope_qualifications; `conventional_grounded_priority`: covered_with_target_scope_qualifications; `method_internal_reason`: covered_with_target_scope_qualifications; `own_philosophy_status_only`: covered_with_target_scope_qualifications + +### T19: bounded_countermodels + +**Registered objective.** Openness neither makes alternatives equivalent nor ensures multiple feasible implementations, excludes conventional choices or excludes internal-method reasons. Local performance equality does not settle whole choice. The added choice priority rule is not inferred from the represented general requirement to assess reasons; this inherited limited assessment relation is distinct from the stronger domain nonentailment in T39. + +**Independent result.** A single feasible conventional choice, unequal outputs, equal local but different global behavior, and a distinguishing internal explanation meet the requested cases. The additional-choice example distinguishes accurate general assessment of non-entailment from the separate priority norm; this is deliberately the limited general-assessment relation in the target, not all Grounds duties. + +**Actual declaration evidence.** `CoreReader.Adopted.choiceLimits012` (`CoreReader/Adopted.lean:1255`) + +**Required semantic cases.** `single_feasible_conventional`: covered_with_target_scope_qualifications; `internal_reason_distinguishes`: covered_with_target_scope_qualifications; `unequal_open_options`: covered_with_target_scope_qualifications; `local_equal_global_difference`: covered_with_target_scope_qualifications; `added_choice_not_from_general_assessment`: covered_with_target_scope_qualifications + +### T20: partial_theorem_signature + +**Registered objective.** Under jointly satisfied inherited commitments and actual applicability, own principles/assessment methods/grounds/capability judgments inherit their corresponding generation, consistency and support duties without self-proof or removal of conditions. + +**Independent result.** The same chosen candidate/context is linked through Inherited and the concrete cases are not unrelated Boolean models. inheritedMutualApplication is a projection of generation, reflection, five core value grounds, capability/choice and own-fact inference fields. Its full conclusion does not include the consistencySpecification promised by the registered target statement, although that proof exists as inherited.consistency in its premise. Therefore the exact theorem is a proved fragment of the stated preservation result, not the entire target signature. + +**Actual declaration evidence.** `CoreReader.Engineering.inheritedMutualApplication` (`CoreReader/Engineering/Integration.lean:281`), `CoreReader.Engineering.inheritedMutualCases` (`CoreReader/Engineering/Integration.lean:298`) + +**Required semantic cases.** `own_grounds_articulable`: covered_with_target_scope_qualifications; `own_capability_supported`: covered_with_target_scope_qualifications; `own_choice_not_status_only`: covered_with_target_scope_qualifications; `relevant_self_application`: covered_with_target_scope_qualifications + +### T21: documentary_boundary + +**Registered objective.** Existing form includes organization/methods/principles. Assessment is examination of reasons, applicability and observed performance and is not limited to executable testing. + +**Independent result.** FormKind explicitly includes organization, method and principle. Empirical and semantic-inferential facets and noncomputable proposition decisions prevent restricting assessment to executable tests. The finite formal vocabulary is illustrative rather than an exhaustive philosophical ontology. + +**Actual declaration evidence.** Documentary boundary; no theorem required. + +**Required semantic cases.** None registered. + +### T22: bounded_subject_specification + +**Registered objective.** Domain subject is continuing engineering activity by current/successor human or agent maintainers with software/tools/knowledge across credible lifecycle; priority applicability reflects actual lifecycle/maintenance expectations, not labels or artifact intrinsic orientation. + +**Independent result.** ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established. + +**Actual declaration evidence.** `CoreReader.Engineering.ActivityScope` (`CoreReader/Engineering/Domain.lean:49`), `CoreReader.Engineering.subjectLifecycleCases` (`CoreReader/Engineering/Domain.lean:146`) + +**Required semantic cases.** `successor_maintainer`: covered_with_target_scope_qualifications; `agent_maintainer`: covered_with_target_scope_qualifications; `continuing_labeled_temporary`: covered_with_target_scope_qualifications; `genuinely_temporary`: covered_with_target_scope_qualifications; `bounded_prototype`: covered_with_target_scope_qualifications; `retiring_system`: covered_with_target_scope_qualifications + +### T23: bounded_countermodels + +**Registered objective.** Original-author editability does not establish continuing-maintainer evolution capability; calling a continuing system temporary does not establish genuinely bounded lifecycle; adopted human/agent orientation does not entail every artifact has it. + +**Independent result.** The original maintainer has privateLayout while the successor lacks it; explicit path prerequisite failure establishes the contrast. The continuing activity remains nonbounded despite its temporary label. The passive artifact returns inputs and has no propose action by its actual definition, providing one counterexample rather than a law of all artifacts. + +**Actual declaration evidence.** `CoreReader.Engineering.subjectLimits` (`CoreReader/Engineering/Domain.lean:159`) + +**Required semantic cases.** `author_only_private_knowledge`: covered_with_target_scope_qualifications; `successor_missing_path`: covered_with_target_scope_qualifications; `false_temporary_label`: covered_with_target_scope_qualifications; `passive_artifact`: covered_with_target_scope_qualifications + +### T24: bounded_normative_specification + +**Registered objective.** When credible lifecycle/maintenance scope and relevant behavioral, safety, performance and other necessary requirements hold, favor continuing-maintainer credible future change capability including design revision over present abstraction simplicity; accept purpose-linked added complexity; allow yielding only when added costs threaten concrete objectives, with objective/cost account. + +**Independent result.** EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates. + +**Actual declaration evidence.** `CoreReader.Engineering.EvolutionPriority` (`CoreReader/Engineering/Domain.lean:321`), `CoreReader.Engineering.priorityConditionsCases` (`CoreReader/Engineering/Domain.lean:367`) + +**Required semantic cases.** `ordinary_priority`: covered_with_target_scope_qualifications; `missing_behavior`: covered_with_target_scope_qualifications; `missing_safety`: covered_with_target_scope_qualifications; `missing_performance`: covered_with_target_scope_qualifications; `missing_other_necessary`: covered_with_target_scope_qualifications; `concrete_cost_override`: covered_with_target_scope_qualifications; `unexplained_departure`: covered_with_target_scope_qualifications; `no_extensibility_maximum`: covered_with_target_scope_qualifications + +### T25: conditional_theorem + +**Registered objective.** For a context meeting all priority conditions, with a credible evolution advantage over a simpler feasible option and no concrete cost threat, domain satisfaction requires the evolution-favoring choice/priority and acceptance of its relevant additional complexity. + +**Independent result.** The theorem explicitly assumes the adopted EvolutionPriority rule, applicability and no departure; it extracts the chosen evolvable value and substitutes into the supplied complexity comparison. This matches the target's normative-premise requirement. Concrete choices show simple violates the rule without a threat and can pass with the accounted threat. + +**Actual declaration evidence.** `CoreReader.Engineering.priorityWhenApplicable` (`CoreReader/Engineering/Domain.lean:337`), `CoreReader.Engineering.priorityChoices` (`CoreReader/Engineering/Domain.lean:384`) + +**Required semantic cases.** `applicable_choose_evolution`: covered_with_target_scope_qualifications; `applicable_choose_simple_violates_domain`: covered_with_target_scope_qualifications; `threat_allows_departure_with_account`: covered_with_target_scope_qualifications + +### T26: qualified_credibility_adapter + +**Registered objective.** Credible change direction has articulable grounds (examples are plan/domain knowledge/history, not an exhaustive required list), remains revisable, and needs no existing multiple implementations. Conceivability alone cannot justify present accommodation. + +**Independent result.** The generic Ground interface does not restrict ground categories. Concrete plans identify a positive release and direction; knowledge/history cases contain a service/mechanism or repeated direction list, and forecast revision changes supported directions. The adapter only checks designated strings/list content, so actual relevance of a mechanism/history is a stipulated interpretation. It must not be reported as independent validation of arbitrary knowledge records. + +**Actual declaration evidence.** `CoreReader.Engineering.CredibleDirection` (`CoreReader/Engineering/Domain.lean:174`), `CoreReader.Engineering.credibilityCases` (`CoreReader/Engineering/Domain.lean:212`) + +**Required semantic cases.** `committed_plan_one_implementation`: covered_with_target_scope_qualifications; `domain_knowledge`: covered_with_target_scope_qualifications; `applicable_history`: covered_with_target_scope_qualifications; `conceivable_only`: covered_with_target_scope_qualifications; `revised_forecast`: covered_with_target_scope_qualifications + +### T27: bounded_countermodels + +**Registered objective.** Conceivable change alone does not entail warranted accommodation; credible change does not entail multiple existing implementations, maximal extensibility, retention of every possibility or universal numerical exchange rate. + +**Independent result.** One implemented variant coexists with credible direction; unsupported imagined changes do not warrant the defined investment; evolvable supports nine registered directions while maximal supports ten but is not the priority. Different per-burden bounds and work comparisons demonstrate a selective example, not a mathematical impossibility of numerical tradeoffs. + +**Actual declaration evidence.** `CoreReader.Engineering.credibilityLimits` (`CoreReader/Engineering/Domain.lean:394`) + +**Required semantic cases.** `one_implementation_credible`: covered_with_target_scope_qualifications; `imagined_unwarranted`: covered_with_target_scope_qualifications; `selective_evolution`: covered_with_target_scope_qualifications; `qualitative_tradeoff`: covered_with_target_scope_qualifications + +### T28: bounded_cost_specification + +**Registered objective.** Cost/departure account admits understanding, construction, diagnosis, verification, coordination, operation and eventual migration burdens and identifies threatened objective and causal significance of added cost. + +**Independent result.** Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions. + +**Actual declaration evidence.** `CoreReader.Engineering.JustifiedDeparture` (`CoreReader/Engineering/Domain.lean:298`), `CoreReader.Engineering.costCases` (`CoreReader/Engineering/Domain.lean:410`) + +**Required semantic cases.** `understanding_threat`: covered_with_target_scope_qualifications; `construction_threat`: covered_with_target_scope_qualifications; `diagnosis_threat`: covered_with_target_scope_qualifications; `verification_threat`: covered_with_target_scope_qualifications; `coordination_threat`: covered_with_target_scope_qualifications; `operation_threat`: covered_with_target_scope_qualifications; `migration_threat`: covered_with_target_scope_qualifications; `unsupported_cost_excuse`: covered_with_target_scope_qualifications + +### T29: bounded_evolution_specification + +**Registered objective.** Evolution includes capability addition, implementation replacement, mechanism deletion, abstraction withdrawal, boundary redrawing and technology/model migration; claims identify relevant changes and maintainer conditions; independent/coordinated changes and preserved/revised obligations may require different structures. + +**Independent result.** Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter. + +**Actual declaration evidence.** `CoreReader.Engineering.EvolutionClaim` (`CoreReader/Engineering/Domain.lean:556`), `CoreReader.Engineering.evolutionKindsCases` (`CoreReader/Engineering/Domain.lean:569`) + +**Required semantic cases.** `addition`: covered_with_target_scope_qualifications; `replacement`: covered_with_target_scope_qualifications; `deletion`: covered_with_target_scope_qualifications; `withdrawal`: covered_with_target_scope_qualifications; `redrawing`: covered_with_target_scope_qualifications; `migration`: covered_with_target_scope_qualifications; `independent`: covered_with_target_scope_qualifications; `coordinated`: covered_with_target_scope_qualifications; `preserve_obligation`: covered_with_target_scope_qualifications; `revise_obligation`: covered_with_target_scope_qualifications + +### T30: bounded_countermodels + +**Registered objective.** Cheap/effective additions within fixed scheme do not entail equal ability to revise/leave it; advantage on one dimension does not entail every dimension; no duty to make every change inexpensive. + +**Independent result.** Addition can cost two while withdrawal/revision costs seventeen; coordinated work exceeds independent work; migration can remain expensive while evolution priority holds. Equal addition cost directly refutes universal strict improvement over all Change values. + +**Actual declaration evidence.** `CoreReader.Engineering.evolutionDimensionsLimits` (`CoreReader/Engineering/Domain.lean:585`) + +**Required semantic cases.** `easy_add_hard_exit`: covered_with_target_scope_qualifications; `independent_easy_coordinated_hard`: covered_with_target_scope_qualifications; `some_change_expensive_permitted`: covered_with_target_scope_qualifications + +### T31: partial_semantic_link + +**Registered objective.** Structural choice applies to whole relevant engineering consequences: component relations, observable contracts, understanding and verification work; boundary capability needs support for intended changes; propagation/cross-boundary knowledge and obligations/fixed assumptions/withdrawal are possible comparison inquiries. + +**Independent result.** StructuralAccount ties touched components, intended direction, finite contract observations, work and verification counts. Fixed-batch and withdrawal examples are substantive. However the required cross_boundary_obligation case in structuralCases only proves an EditStep has component 2 and requires publicContract. It does not reference any Boundary caller/callee relation, identify which obligation crosses it, or link that boundary to the intended-change support account. The source makes such inquiries optional generally, but this preregistered named case remains an unfulfilled representation link. + +**Actual declaration evidence.** `CoreReader.Engineering.StructuralAccount` (`CoreReader/Engineering/Domain.lean:641`), `CoreReader.Engineering.structuralCases` (`CoreReader/Engineering/Domain.lean:655`) + +**Required semantic cases.** `contract_and_work_comparison`: covered_with_target_scope_qualifications; `propagation_relation`: covered_with_target_scope_qualifications; `cross_boundary_obligation`: partial_missing_boundary_link; `fixed_assumption`: covered_with_target_scope_qualifications; `withdrawal_cost`: covered_with_target_scope_qualifications + +### T32: bounded_countermodels_delta_verified + +**Registered objective.** Interface shape, module/extension-point count, named principle or boundary introduction alone cannot establish claimed evolution capability or easier intended change. + +**Independent result.** The frozen delta now supplies the exact new_boundary_same_work case missing from the initial code: an actual added boundary and changed path with identical units/work and remaining successor prerequisite failure. The original increased-work example is retained. These and the signature/module/named-pattern examples meet the finite negative target, without proving real-world overhead or boundary execution semantics. + +**Actual declaration evidence.** `CoreReader.Engineering.structureNotCapability` (`CoreReader/Engineering/Domain.lean:745`) + +**Required semantic cases.** `same_shape_broken_order`: covered_with_target_scope_qualifications; `many_modules_shared_obligation`: covered_with_target_scope_qualifications; `named_pattern_no_change_path`: covered_with_target_scope_qualifications; `new_boundary_same_work`: covered_with_target_scope_qualifications + +### T33: bounded_contract_specification + +**Registered objective.** Distinguish preserving an identified observable contract from deliberately revising it; deliberate revision accounts for changed obligations and affected parties; no requirement to preserve every historical behavior or use particular tests/migration procedure. + +**Independent result.** ContractChangeAccount separates finite scoped equality from deliberate revision with changed order/retry obligations and affected-party coverage. Missing operator/incorrect old limits fail; [99] demonstrates an intentionally out-of-scope historical difference; changing procedure text remains allowed. Actual notification, completeness of parties and all-input equivalence are not modeled. + +**Actual declaration evidence.** `CoreReader.Engineering.ContractChangeAccount` (`CoreReader/Engineering/Domain.lean:549`), `CoreReader.Engineering.contractCases` (`CoreReader/Engineering/Domain.lean:795`) + +**Required semantic cases.** `preserve_identified_contract`: covered_with_target_scope_qualifications; `deliberate_revision_with_account`: covered_with_target_scope_qualifications; `revision_missing_parties`: covered_with_target_scope_qualifications; `retired_historical_behavior`: covered_with_target_scope_qualifications; `alternative_procedure`: covered_with_target_scope_qualifications + +### T34: conditional_theorem + +**Registered objective.** Given equality of all identified contract observations in scope, a transformation preserves that identified contract; deliberate changed in-scope observations cannot be claimed preservation of that same contract and require revised-obligation/party account under domain satisfaction. + +**Independent result.** contractPreservation returns the supplied universal in-scope equality proof, rather than deriving it from finite tests. changedObservationNotPreserved gives the counterexample implication; contractRevisionObligations eliminates the failed preservation branch of the assumed account. Finite order/retry cases illustrate the distinction. This is the correct conditional reading of the target, not an empirical proof from test success. + +**Actual declaration evidence.** `CoreReader.Engineering.contractPreservation` (`CoreReader/Engineering/Domain.lean:774`), `CoreReader.Engineering.contractDistinctions` (`CoreReader/Engineering/Domain.lean:805`) + +**Required semantic cases.** `order_preserving_refactor`: covered_with_target_scope_qualifications; `sorted_order_revision`: covered_with_target_scope_qualifications; `changed_failure_obligation`: covered_with_target_scope_qualifications; `outside_scope_difference`: covered_with_target_scope_qualifications + +### T35: qualified_revision_account + +**Registered objective.** Changed evidence about expected changes, maintenance conditions, costs/objectives can justify revised design/priority application; revised judgment acknowledges material grounds changes and cannot retroactively relabel failed prediction success. Retention may be justified by alternatives lacking contribution or defeating objectives. + +**Independent result.** The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign. + +**Actual declaration evidence.** `CoreReader.Engineering.RevisionAccount` (`CoreReader/Engineering/Domain.lean:874`), `CoreReader.Engineering.revisionCases` (`CoreReader/Engineering/Domain.lean:903`) + +**Required semantic cases.** `revised_change_forecast`: covered_with_target_scope_qualifications; `changed_maintainers`: covered_with_target_scope_qualifications; `changed_cost`: covered_with_target_scope_qualifications; `changed_objective`: covered_with_target_scope_qualifications; `failed_prediction_preserved`: covered_with_target_scope_qualifications; `justified_retention`: covered_with_target_scope_qualifications + +### T36: bounded_countermodels_with_scope_limit + +**Registered objective.** Revised judgment cannot make past failed prediction true; continued change, agreement and successful examples do not establish universal correctness; justified retention is compatible with domain/reflexive revision openness. + +**Independent result.** Fixed history rejects reporting a 3-versus-5 prediction as success; repeated agreement and size-10 successes retain the size-5 counterexample. stableRecord keeps the design choice while preserving the criticism coverage condition. This is an open-to-listed-criticism record, not a separate proof of all reflexive obligations for arbitrary stable engineering designs; those are treated under the selfModel interface. + +**Actual declaration evidence.** `CoreReader.Engineering.revisionLimits` (`CoreReader/Engineering/Domain.lean:945`) + +**Required semantic cases.** `past_failure_not_rewritten`: covered_with_target_scope_qualifications; `agreement_with_bad_case`: covered_with_target_scope_qualifications; `local_success_global_failure`: covered_with_target_scope_qualifications; `open_stable_design`: covered_with_target_scope_qualifications + +### T37: partial_same_rule_grounding + +**Registered objective.** With inherited and domain satisfaction in a shared applicable context, the priority and evolution-assessment methods remain objects of grounds, consistency and reflexive criticism/revision; domain success cannot exempt its rule. + +**Independent result.** The exact theorem derives chosen=evolvable, priority-object membership, reflection and value grounds for CoreCommitment (the five inherited labels). The priority is actually tested in selfModel, and the evolution method has a real counterexample. But the conclusion does not carry consistencySpecification, nor a Grounds/value specification for the same engineering-priority rule: selectionPosition grounds a candidate selection, while governancePosition covers only CoreCommitment. These facts are related but not definitionally the same judgment. The registered whole target remains partial pending a same-rule connection or an explicitly authorized narrower target. + +**Actual declaration evidence.** `CoreReader.Engineering.priorityRemainsReflexive` (`CoreReader/Engineering/Integration.lean:317`), `CoreReader.Engineering.priorityReflexiveCases` (`CoreReader/Engineering/Integration.lean:336`) + +**Required semantic cases.** `priority_self_assessment`: reflection_checked_priority_grounds_link_partial; `method_self_criticism`: covered_with_target_scope_qualifications; `no_selfproof_from_success`: covered_with_target_scope_qualifications + +### T38: kernel_witness_source_composition_pending + +**Registered objective.** USER ADDITIONAL STRONG OBJECTIVE: one content-bearing nonempty system/context jointly satisfies every represented inherited and domain commitment, with a continuing lifecycle, actual applicable priority and evolution chosen despite additional present abstraction complexity. + +**Independent result.** The existential witness uses the full encoded Inherited and DomainSatisfied records at sharedContext/evolvable, with active applicability, no threat, larger present complexity, nonempty own facts and successor/agent paths. Its mathematical inhabitation is accepted. Full source/target composition is not yet accepted because T20/T31/T37 contain the specified correspondence gaps and T16's understanding case remains limited. This is not a proof failure or evidence that the displayed witness is vacuous. + +**Actual declaration evidence.** `CoreReader.Engineering.jointWitness` (`CoreReader/Engineering/Integration.lean:396`) + +**Required semantic cases.** `joint_all_inherited_and_domain`: kernel_checked_source_composition_pending; `same_context_identity`: covered_with_target_scope_qualifications; `nonempty_claims_and_principles`: covered_with_target_scope_qualifications; `active_evolution_priority`: covered_with_target_scope_qualifications; `content_bearing_maintainer_change`: covered_with_target_scope_qualifications + +### T39: bounded_nonentailment_witness + +**Registered objective.** USER ADDITIONAL STRONG OBJECTIVE: a countermodel satisfies all represented inherited commitments while genuine domain-priority applicability holds and domain evolution priority is not adopted; proves non-entailment in the disclosed representation. + +**Independent result.** The counterexample uses the same shared continuing context, meets genuine encoded applicability/no-threat conditions, adopts simple via its own value position and satisfies all encoded Inherited fields. Simple violates the additional rule. Core 0.1.2 permits an application's alternative value commitment; adopting present simplicity is not required to adopt chapter-4 evolution priority. The differing objectives are disclosed premises, not a trick replacing assessment with adoption. The result is accepted for the declared inherited representation, with T16/T20 correspondence qualifications preventing an unqualified assertion about all source obligations. + +**Actual declaration evidence.** `CoreReader.Engineering.inheritedDoesNotEntailPriority` (`CoreReader/Engineering/Integration.lean:425`) + +**Required semantic cases.** `all_inherited_applicable_domain_not_adopted`: covered_with_target_scope_qualifications; `no_temporary_escape`: covered_with_target_scope_qualifications; `no_cost_escape`: covered_with_target_scope_qualifications; `genuine_priority_failure`: covered_with_target_scope_qualifications; `inherited_grounds_for_other_value`: covered_with_target_scope_qualifications + +### T40: documentary_boundary + +**Registered objective.** Formal specification/conditional proofs and finite witnesses do not establish empirical adequacy of lifecycle forecasts, support relevance, future maintainability, value superiority or universal philosophical correctness; representation choices remain disclosed and revisable. + +**Independent result.** Maintain source authority and separate normative specification, conditional theorem, finite witness, actual measurement, interpretation and adoption. No unseen final reader edition was assessed in this initial comparison. Disclosed abstraction does not automatically discharge a required semantic case or permit relabeling a difficult target as a boundary. + +**Actual declaration evidence.** Documentary boundary; no theorem required. + +**Required semantic cases.** None registered. + +## Disposition of every blind concern + +### C01: retained_application_boundary + +Initial concern: Fixed finite costs, profiles, paths, credibility classifications and histories are stipulated data, not independent measurements. + +Source comparison: Source §§4.1–4.5 and T40 explicitly allow context-specific application evidence; hardcoded finite data do not by themselves violate source. Actual lifecycle, knowledge/history relevance, costs and forecast truth remain unverified, including T26. + +### C02: resolved_as_explicit_normative_premise + +Initial concern: EvolutionPriority is assumed by priorityWhenApplicable. The proof eliminates its departure branch and projects the complexity comparison from applicability. + +Source comparison: T25 explicitly requires the adopted domain norm as premise. The projection is faithful to that conditional, not independent justification of adoption. + +### C03: not_a_source_conflict_for_false_antecedent + +Initial concern: Standalone DomainSatisfied does not require Meets or PriorityConditions; a context with an unsafe evolvable profile can still satisfy it. + +Source comparison: Source gives priority when necessary requirements hold; it does not say a record about priority/structure/history proves universal requirement satisfaction. The unsafe DomainSatisfied probe is a boundary on that name, while T38 separately supplies PriorityConditions and real modeled profiles. + +### C04: retained_narrow_claim_not_failure_alone + +Initial concern: engineeringCapability requires equality to the same capabilityOutput function used to define engineeringProcess; its ground theorem holds even for maximal and imposes no positive capability threshold. + +Source comparison: Core 0.1.2 permits application-specific capability definitions. Equality to the declared total output function is a genuine narrow claim proved for the same process; it must not be described as independent positive maintainability certification. Path contrast supplies the nontrivial maintenance facts for T38/T39. + +### C05: resolved_as_permitted_alternative_value + +Initial concern: Simple and evolvable selection procedures use different objectives and starting assumptions fixed to their own adopted candidates. + +Source comparison: Source roles and §4 state that engineering preference is additional. The simple value position may pursue simplicity and the evolvable one revision work, so long as reasons/constraints are disclosed. Their different objectives are essential to the bounded non-entailment witness, not a source inconsistency. + +### C06: retained_scope_boundary_not_core013_requirement + +Initial concern: Grounds012 quantifies over the supplied nonempty facet list for one supplied task; it has no actualApplicable coverage predicate. + +Source comparison: Core 0.1.2 source and T09 do not require the later all-applicable-facet interface. The one-task formulation cannot be called an exhaustive taxonomy, but it may represent one task with multiple methods. No Core 0.1.3 obligation is imposed. + +### C07: mitigated_in_discharged_facets + +Initial concern: Raw Supports permits inconsistent records to support any proposition; inference over unsatisfiable theories is likewise vacuous. + +Source comparison: FacetDischarged requires witnesses. The actual empirical/inferential and composition examples use nonempty compatible/satisfiable domains, so raw-support vacuity does not invalidate them. + +### C08: retained_sufficient_procedure_boundary + +Initial concern: ValueProcedure is conditional on all reasons, supplied objectives/constraints and scope; it does not establish universal adoption or semantic adequacy of responses. + +Source comparison: Source asks articulated reasons, consequences, limits and openness, not proof of universal value correctness. ValueProcedure is a sufficient application procedure; response nonemptiness and conditional consequence must not be elevated into a universal definition of adequate criticism or legitimate value. + +### C09: mitigated_by_concrete_self_records + +Initial concern: The generic reflexivity relation may be vacuous for no rules/self/applicability and records/meaning are supplied relations. recordedReflexivity assumes follows. + +Source comparison: Empty generic registries/applicability are permitted formal boundary cases; positive examples have actual own targets, membership, nonempty reasons and checked basis/meaning. Missing same-priority support linkage in T37 remains a distinct issue. + +### C10: mitigated_by_interpret_and_concrete_inputs + +Initial concern: Reflection.evaluate ignores claimed scope, basis, reasons and target; empty tested/requested lists return supportedWithinScope. + +Source comparison: Concrete self records have nonempty tested/requested inputs, independently checked basis and nonempty reasons. Raw evaluate can be vacuous and ignores claimed scope, so its return value alone must not be called full assessment fulfillment. + +### C11: resolved_for_countermodel_scope + +Initial concern: The simple selfModel omits the priority review object; reflection of that model is not evidence that simple satisfies priority. + +Source comparison: T39 declines the additional engineering priority; it need not review that unadopted priority as an adopted own principle. T38/evolvable does include the priority object. The omission does not show a covert failure of adopted Core duties. + +### C12: retained_finite_scope_and_identity_proof + +Initial concern: PreservesFinite and affectedParties inspect only fixed input/dependency lists. contractPreservation receives the complete universal equality as its premise. + +Source comparison: T33/T34 explicitly allow identified observation scope and finite examples. Universal contractPreservation is the supplied equality premise; parties/procedures are finite model obligations, not actual notices. The retained [99] counterexample makes scope limits explicit. + +### C13: retained_history_provenance_boundary + +Initial concern: RevisionAccountAgainst checks exact equality to caller-supplied history and criticism-list coverage, not historical authenticity or substantive criticism. + +Source comparison: The invariant comparison against fixed history meets the modeled no-retroactive-success requirement. Authentic external history and substantive criticism are not proved. This is legitimate bounded evidence, not a universal history-authentication theorem. + +### C14: mitigated_for_registered_witnesses + +Initial concern: ContinuingCapability can pass with no participants; RetentionJustified can pass with no alternatives; Consistent can pass with an empty question type. + +Source comparison: Current applicability includes nonempty participants, question/fact domains are inhabited, and concrete alternatives are listed. Empty generic cases remain documented and must not be mistaken for the actual positive witness. + +### C15: partial_target_signature_confirmed + +Initial concern: inheritedMutualApplication extracts fields of Inherited; it does not establish mutual implication among fewer independent principles. + +Source comparison: T20 is intentionally conditional, so projection itself is legitimate. Nevertheless its required target statement includes consistency, while the actual conclusion omits inherited.consistency. Full exact target completion needs that distinction resolved; no claim of mutual logical derivation is warranted. + +### C16: resolved_as_allowed_nonexecutable_assessment + +Initial concern: Some prior Integration and Adopted value experiments use Classical.propDecidable for arbitrary propositions. + +Source comparison: Source necessary terms and §2.2 expressly do not require every assessment to be executable. Classical proposition decisions are valid logical constructions provided the delivery does not advertise them as executable empirical tools. + +### C17: retained_interface_and_linkage_boundary + +Initial concern: Articulated only checks nonempty lists; ScopeAccount.explains and generic ReflexiveRule.meaning remain supplied predicates. + +Source comparison: Concrete expansions supply more than abstract labels, but nonempty strings do not prove explanatory relevance for arbitrary inputs. T31 has a specific missing boundary/obligation connection; T37 grounds quantification covers five Core labels, not directly the engineering priority rule. + +## Complete source-paragraph comparison (47 entries) + +Each exact source passage remains subject to its wording and limits, not merely to declaration names. Target references below carry the independent qualifications above; a source paragraph linked to several checked cases is not thereby wholly proved. Tables, list blocks and structural text are preserved as separate source paragraphs exactly as registered. + +### organon.preamble / p1 + +Exact source: + +This is a statement of Software Engineering Organon’s adopted philosophy. It expresses commitments, not factual assertions about every system or a proof of universal correctness. + +Compared through: `T01` (documentary_boundary), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Documentary/structural text remains nonformal. + +### organon.preamble / p2 + +Exact source: + +The quoted provisions, their meanings, and their conditions of application form the core. The charter and Grounds constrain one another; their grouping establishes neither a deductive hierarchy nor an order of priority. [Rationale](docs/rationale.md) supplies arguments and cases without adding obligations to this core. Skills are revisable applications under the repository’s stated objectives and constraints, not part of the philosophical commitments themselves. + +Compared through: `T01` (documentary_boundary), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Documentary/structural text remains nonformal. + +### organon.charter.overview / p1 + +Exact source: + +**Self-Transcendence · Internal Consistency · Reflexivity** + +Compared through: `T01` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Documentary/structural text remains nonformal. + +### organon.charter.overview / p2 + +Exact source: + +> A system is intrinsically oriented toward expanding what it can understand and construct. It brings itself and its principles within the scope of generation and assessment, with internal consistency constraining this process. + +Compared through: `T01` (documentary_boundary), `T02` (bounded_specification), `T38` (kernel_witness_source_composition_pending). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.charter.overview / p3 + +Exact source: + +The overview connects three distinct requirements: self-transcendence establishes a generative orientation and refuses to treat existing forms as final, internal consistency constrains judgments held simultaneously, and reflexivity brings the system and its principles within the scope of their own generation and assessment. The provisions below specify the conditions for each. + +Compared through: `T01` (documentary_boundary), `T02` (bounded_specification), `T38` (kernel_witness_source_composition_pending). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.charter.self-transcendence / p1 + +Exact source: + +> A system is intrinsically oriented toward expanding what it can understand and construct. It does not regard any existing form as the endpoint of generation. + +Compared through: `T02` (bounded_specification), `T38` (kernel_witness_source_composition_pending). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.charter.self-transcendence.orientation / p1 + +Exact source: + +A commitment to keeping generative possibilities open is distinct from valuing their expansion. A system has an intrinsic orientation when it regards that expansion as worth pursuing. Merely permitting change does not fully express this orientation. + +Compared through: `T02` (bounded_specification), `T03` (bounded_countermodels), `T38` (kernel_witness_source_composition_pending). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.charter.self-transcendence.non-finality / p1 + +Exact source: + +Refusing to regard an existing form as an endpoint keeps it open to being surpassed. “Existing form” includes a system’s current organization, methods, and principles, not only its appearance or artifacts. These remain within the scope of possible change; their revisability does not guarantee actual progress. + +Compared through: `T02` (bounded_specification), `T03` (bounded_countermodels), `T38` (kernel_witness_source_composition_pending). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.charter.self-transcendence.limits / p1 + +Exact source: + +Whether progress has actually occurred remains a separate judgment. Having the orientation does not guarantee progress. Progress cannot be established merely by an increase in the number of artifacts, levels of abstraction, or terms. + +Compared through: `T03` (bounded_countermodels), `T38` (kernel_witness_source_composition_pending). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.charter.self-transcendence.limits / p2 + +Exact source: + +- “Intrinsic orientation” expresses Organon’s philosophical commitment; it does not assert that all systems in fact develop autonomously. +- Self-transcendence does not imply independence from external experience, knowledge, or collaboration, nor does it guarantee autonomous execution or self-improvement. +- Refusing to regard an existing form as an endpoint does not require every action to produce change. Justified stability can coexist with a generative orientation. +- Whether transcendence expands what can be understood and constructed requires discernible grounds; a system’s own claim of generation does not establish actual achievement. + +Compared through: `T02` (bounded_specification), `T03` (bounded_countermodels), `T38` (kernel_witness_source_composition_pending), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.charter.consistency / p1 + +Exact source: + +> The principles and judgments a system holds simultaneously, together with their implications, must not yield contradictory judgments on the same question under the same assumptions, meanings of terms, and scope of application. + +Compared through: `T04` (bounded_specification), `T05` (conditional_theorem), `T38` (kernel_witness_source_composition_pending). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.charter.consistency.meaning / p1 + +Exact source: + +“Held simultaneously” specifies which principles, judgments, and implications must hold together. Revision may withdraw an earlier judgment; old and new principles need not remain compatible forever. When a change has occurred, that change cannot be represented as though it had not occurred. + +Compared through: `T04` (bounded_specification), `T05` (conditional_theorem), `T38` (kernel_witness_source_composition_pending). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.charter.consistency.meaning / p2 + +Exact source: + +“The same assumptions, meanings of terms, and scope of application” specifies the basis for comparing judgments. Divergent judgments under different conditions do not automatically constitute contradictions. Nor can unacknowledged changes in assumptions, meanings, or scope be used to conceal an existing contradiction. + +Compared through: `T04` (bounded_specification), `T05` (conditional_theorem), `T06` (bounded_countermodels), `T38` (kernel_witness_source_composition_pending). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.charter.consistency.limits / p1 + +Exact source: + +- Tension between different assessments or values does not directly constitute a contradiction. Revision or qualification is needed when they require incompatible conclusions under the same conditions. +- Internal consistency is not correctness or sufficiency. A set of principles may be internally consistent while relying on false assumptions or neglecting important questions. + +Compared through: `T04` (bounded_specification), `T05` (conditional_theorem), `T06` (bounded_countermodels), `T38` (kernel_witness_source_composition_pending). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.charter.reflexivity / p1 + +Exact source: + +> A system’s principles of generation and assessment also apply to the system itself and to the formation, application, and revision of those principles. + +Compared through: `T07` (bounded_specification), `T38` (kernel_witness_source_composition_pending). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.charter.reflexivity.meaning / p1 + +Exact source: + +Reflexivity encompasses both the system itself and its principles. Assessment concerns not only whether the system conforms to its principles, but also how those principles are formed, where they apply, and why they may need revision. The formation and revision of principles thus also become objects of generation and assessment. + +Compared through: `T07` (bounded_specification), `T38` (kernel_witness_source_composition_pending). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.charter.reflexivity.limits / p1 + +Exact source: + +- Applying principles equally retains their conditions of application. When the relevant conditions hold, being the system itself is not a basis for exemption. Nor does the requirement of reflexivity establish that every principle can be applied to itself without examining its applicability. +- Self-application does not constitute self-proof. Subjecting a principle to its own assessment does not thereby establish its correctness. +- That a revision is produced by the system itself does not give it sufficient grounds. + +Compared through: `T07` (bounded_specification), `T08` (bounded_countermodels), `T38` (kernel_witness_source_composition_pending). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.grounds / p1 + +Exact source: + +> The grounds of principles and judgments must be articulable and subject to assessment appropriate to the nature of the claim. The strength and scope of a claim must be proportionate to the support provided by its grounds. + +Compared through: `T08` (bounded_countermodels), `T09` (qualified_success_specification), `T38` (kernel_witness_source_composition_pending), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.grounds.assessment / p1 + +Exact source: + +Articulation and assessment have distinct responsibilities. Articulability requires that concepts, assumptions, reasons, and limits can be identified. Assessment requires examining whether those grounds support the corresponding claim. Clearly expressed grounds are not thereby sufficiently established. + +Compared through: `T09` (qualified_success_specification), `T13` (bounded_countermodels), `T38` (kernel_witness_source_composition_pending), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.grounds.assessment / p2 + +Exact source: + +| Type of claim | Responsibility of assessment | What cannot substitute for that responsibility | +| --- | --- | --- | +| Empirical claim | Examine observations, evidence, and performance, together with the conditions, scope, and uncertainty of their support for the claim. | Treating measurability or repeatability itself as proof of relevance, correctness, or value. | +| Inferential claim | Examine whether the conclusion is supported by the stated assumptions and inferential relations. | Treating the absence of conflict between a conclusion and its assumptions as sufficient to establish that the conclusion follows from them. | +| Value commitment | State the position taken, its reasons, limits of application, and consequences, and remain open to relevant criticism. | Presenting a commitment as an empirical fact or a necessary inference, or substituting self-assertion for reasons. | + +Compared through: `T09` (qualified_success_specification), `T10` (bounded_success_specification), `T11` (qualified_success_specification), `T12` (qualified_value_procedure), `T13` (bounded_countermodels), `T38` (kernel_witness_source_composition_pending), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.grounds.assessment / p3 + +Exact source: + +Initial value commitments may be stated explicitly as commitments; they need not prove all their own starting assumptions. The strength and scope of a claim do not require conversion to a common numerical scale. Different types of claims specify their support and limits in accordance with their nature. + +Compared through: `T09` (qualified_success_specification), `T12` (qualified_value_procedure), `T13` (bounded_countermodels), `T38` (kernel_witness_source_composition_pending), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.grounds.scope / p1 + +Exact source: + +Performance is discerned within particular relations, conditions, and scopes of observation. A boundary helps specify what a comparison concerns, but local examples do not automatically support unconditional universal conclusions. A judgment cannot establish that relevant differences do not exist merely because its chosen scope omits them. + +Compared through: `T14` (qualified_scope_specification), `T15` (bounded_countermodels), `T38` (kernel_witness_source_composition_pending). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.grounds.scope / p2 + +Exact source: + +Measurement can make some differences comparable. Repeated assessment can help examine the stability of corresponding conclusions. Their roles, and the role of any assessment framework, must be explained relative to the claim and its context. Measurement, repeatability, and an assessment framework do not form a universally necessary chain on which all judgments must depend. + +Compared through: `T14` (qualified_scope_specification), `T15` (bounded_countermodels), `T38` (kernel_witness_source_composition_pending), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.grounds.scope / p3 + +Exact source: + +An observation that has not been reproduced may still offer limited support, and random outcomes need not be identical on every occasion. The verifiability of observations, reproducibility of conditions, and stability of conclusions must be distinguished. + +Compared through: `T14` (qualified_scope_specification), `T15` (bounded_countermodels), `T38` (kernel_witness_source_composition_pending), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.grounds.capabilities / p1 + +Exact source: + +Capability claims are subject to Grounds: the capability claimed, its conditions, and the support for it must be identifiable. The core does not prescribe uniform definitions of method mastery, method generation, or capability levels. Applications specify the capabilities they assess and may require understanding, explanation, or performance under relevant variations. + +Compared through: `T16` (partial_case_correspondence), `T17` (bounded_countermodels), `T38` (kernel_witness_source_composition_pending), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.grounds.capabilities / p2 + +Exact source: + +Grounds for a capability claim may be supplied by an external assessor. Their articulability does not by itself require the assessed system to understand or explain its internal generation process. Evidence of reliable output must be assessed against the capability actually claimed; it does not automatically establish understanding of that process. Nor can the number of method documents, terms, tools, or artifacts alone establish a capability beyond what that evidence supports. + +Compared through: `T16` (partial_case_correspondence), `T17` (bounded_countermodels), `T38` (kernel_witness_source_composition_pending), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.grounds.implementations / p1 + +Exact source: + +> The choice of an implementation must be supported by reasons connected to the objectives and values pursued and to the relevant constraints. Its name, conventional use, or established status alone does not provide sufficient grounds for giving it priority. + +Compared through: `T18` (bounded_choice_specification), `T19` (bounded_countermodels), `T38` (kernel_witness_source_composition_pending), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.grounds.implementations / p2 + +Exact source: + +This choice provision adds an additional evaluative commitment: name, conventional use, or established status alone is insufficient to establish priority. Grouping it under Grounds does not mean that it follows from the general requirement to assess reasons, or merely from the discernibility of performance. Conventions and existing arrangements may have practical significance, but that significance must be connected to the objectives and values pursued and to the relevant constraints. + +Compared through: `T18` (bounded_choice_specification), `T19` (bounded_countermodels), `T38` (kernel_witness_source_composition_pending), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.grounds.implementations.limits / p1 + +Exact source: + +- Openness does not make all implementations equivalent, nor does it guarantee multiple feasible implementations for the same objective. +- A method’s explanatory power, limits of application, simplicity, and explicit process requirements may all provide grounded reasons for assessment. They cannot be excluded merely because they concern methods internal to the implementation. +- Identical local performance does not establish overall equivalence. Relations, conditions, and the scope of comparison are constrained by the provisions of Grounds. +- Openness does not reject an implementation merely because it already exists or is conventionally used. Relevant reasons may still give it priority. + +Compared through: `T15` (bounded_countermodels), `T18` (bounded_choice_specification), `T19` (bounded_countermodels), `T38` (kernel_witness_source_composition_pending). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.relationships.roles / p1 + +Exact source: + +The charter states the generative orientation, the consistency constraint, and reflexive application. Grounds specifies support requirements for judgments and includes an additional commitment concerning implementation choices. Both parts belong to the core and constrain one another. Their placement neither makes Grounds a deduction from the charter nor gives the charter priority over it. Each commitment needs its own reasons. + +Compared through: `T01` (documentary_boundary), `T08` (bounded_countermodels), `T20` (partial_theorem_signature), `T38` (kernel_witness_source_composition_pending), `T39` (bounded_nonentailment_witness), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.relationships.roles / p2 + +Exact source: + +Internal Consistency concerns whether simultaneously held judgments can hold together; Grounds concerns whether and how far a claim is supported. A conclusion may fail to conflict with its assumptions without being supported by them. Self-Transcendence specifies a generative orientation and non-finality; neither establishes actual capability. Applications may supply objectives, values, and capability definitions; claims made under those objectives, values, and definitions remain subject to the relevant core provisions. + +Compared through: `T03` (bounded_countermodels), `T06` (bounded_countermodels), `T11` (qualified_success_specification), `T16` (partial_case_correspondence), `T20` (partial_theorem_signature), `T38` (kernel_witness_source_composition_pending), `T39` (bounded_nonentailment_witness), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.relationships.roles / p3 + +Exact source: + +Self-Transcendence does not substitute for Reflexivity: keeping existing forms open to being surpassed differs from applying relevant principles to the system and to their own formation, application, and revision. Reflexivity extends these requirements to the system and to the formation, application, and revision of its principles. The grounds and limits of the Grounds provisions must themselves be articulable. The system’s own capability claims remain subject to assessment, and this philosophy’s existing form cannot gain priority merely from its established status. Such mutual application provides no self-proof and does not remove conditions of application. + +Compared through: `T07` (bounded_specification), `T08` (bounded_countermodels), `T16` (partial_case_correspondence), `T18` (bounded_choice_specification), `T20` (partial_theorem_signature), `T37` (partial_same_rule_grounding), `T38` (kernel_witness_source_composition_pending), `T39` (bounded_nonentailment_witness), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### organon.relationships.terms / p1 + +Exact source: + +| Term | Meaning in this philosophy | +| --- | --- | +| Existing form | The system’s current organization, methods, and principles, not only its appearance or artifacts. | +| Assessment | Examination of reasons, applicability, and observed performance; not limited to executable tests. | + +Compared through: `T02` (bounded_specification), `T21` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### extensions / p1 + +Exact source: + +This chapter adds a software engineering commitment and specifies its meaning and limits. It does not claim that this commitment follows from the Charter or Grounds. Those provisions remain adopted and constrain its application. + +Compared through: `T01` (documentary_boundary), `T37` (partial_same_rule_grounding), `T38` (kernel_witness_source_composition_pending), `T39` (bounded_nonentailment_witness), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### software-engineering.purpose / p1 + +Exact source: + +Software engineering concerns the construction, operation, understanding, and revision of software within its relevant human and technical conditions. This philosophy guides decisions by people and agents; it does not attribute an intrinsic orientation to every software artifact. + +Compared through: `T22` (bounded_subject_specification), `T23` (bounded_countermodels), `T38` (kernel_witness_source_composition_pending), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### software-engineering.purpose / p2 + +Exact source: + +The evolution capability considered here belongs to the continuing engineering activity: maintainers, including successor maintainers and agents, working with software, tools, and available knowledge. Code that its original author can modify is not on that ground alone shown to support that continuing activity. + +Compared through: `T22` (bounded_subject_specification), `T23` (bounded_countermodels), `T38` (kernel_witness_source_composition_pending), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### software-engineering.purpose / p3 + +Exact source: + +Apply the following priority according to the software's credible lifecycle and maintenance expectations. A genuinely temporary script, bounded prototype, or retiring system may have little reason to support further evolution. Calling a continuing system temporary does not establish that condition. + +Compared through: `T22` (bounded_subject_specification), `T23` (bounded_countermodels), `T24` (bounded_normative_specification), `T38` (kernel_witness_source_composition_pending), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### software-engineering.evolution-priority / p1 + +Exact source: + +> When relevant behavioral, safety, performance, and other necessary requirements are satisfied, give priority to continuing maintainers' ability to make credible future changes, including changes to the design itself, over present abstraction simplicity. Accept additional present abstraction complexity for that purpose, while allowing this preference to yield when the added costs threaten concrete engineering objectives. + +Compared through: `T24` (bounded_normative_specification), `T25` (conditional_theorem), `T38` (kernel_witness_source_composition_pending), `T39` (bounded_nonentailment_witness), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### software-engineering.evolution-priority / p2 + +Exact source: + +Credible directions of change have articulable grounds, such as a committed plan, relevant domain knowledge, or an applicable history of change. They need not already have multiple implementations. Their credibility remains open to revision; a conceivable change alone does not establish that it warrants accommodation now. + +Compared through: `T24` (bounded_normative_specification), `T25` (conditional_theorem), `T26` (qualified_credibility_adapter), `T27` (bounded_countermodels), `T38` (kernel_witness_source_composition_pending), `T39` (bounded_nonentailment_witness), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### software-engineering.evolution-priority / p3 + +Exact source: + +This is a default priority, not an obligation to maximize extensibility or retain every possibility. Costs include relevant burdens of understanding, construction, diagnosis, verification, coordination, operation, and eventual migration. A departure from the priority identifies the objective threatened and why the costs matter. No universal numerical exchange rate between these considerations is prescribed. + +Compared through: `T24` (bounded_normative_specification), `T25` (conditional_theorem), `T26` (qualified_credibility_adapter), `T27` (bounded_countermodels), `T28` (bounded_cost_specification), `T38` (kernel_witness_source_composition_pending), `T39` (bounded_nonentailment_witness), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### software-engineering.evolution-meaning / p1 + +Exact source: + +Evolution includes adding capabilities, replacing implementations, deleting mechanisms, withdrawing abstractions, redrawing boundaries, and migrating away from an existing technology or model. Making additions within a fixed scheme does not establish equal ability to revise or leave that scheme. Not every such change can or should be made inexpensive. + +Compared through: `T29` (bounded_evolution_specification), `T30` (bounded_countermodels), `T38` (kernel_witness_source_composition_pending), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### software-engineering.evolution-meaning / p2 + +Exact source: + +An evolution claim identifies the relevant changes and the maintainers' conditions. Independent changes, coordinated changes, preservation of existing obligations, and deliberate revision of those obligations can require different structures. A design's advantage on one dimension does not establish an advantage on every dimension. + +Compared through: `T29` (bounded_evolution_specification), `T30` (bounded_countermodels), `T38` (kernel_witness_source_composition_pending), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### software-engineering.structural-judgment / p1 + +Exact source: + +Apply the preceding commitment to engineering consequences as a whole, including the relations among components, their observable contracts, and the work needed to understand and verify a change. An interface's shape, the number of modules or extension points, or the use of a named principle is not sufficient evidence of the claimed capability. + +Compared through: `T31` (partial_semantic_link), `T32` (bounded_countermodels_delta_verified), `T37` (partial_same_rule_grounding), `T38` (kernel_witness_source_composition_pending), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### software-engineering.structural-judgment / p2 + +Exact source: + +The relevant comparison may examine how a change propagates, which knowledge and obligations cross a boundary, which assumptions become fixed, and what a later withdrawal would require. A proposed boundary needs support for the changes it is meant to accommodate; introducing it does not by itself show that those changes became easier. + +Compared through: `T31` (partial_semantic_link), `T32` (bounded_countermodels_delta_verified), `T38` (kernel_witness_source_composition_pending), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### software-engineering.structural-judgment / p3 + +Exact source: + +Distinguish a transformation that preserves an identified observable contract from one that deliberately revises that contract. The latter needs a corresponding account of changed obligations and affected parties. This distinction does not require preserving every historical behavior or using a particular testing or migration procedure. + +Compared through: `T33` (bounded_contract_specification), `T34` (conditional_theorem), `T38` (kernel_witness_source_composition_pending), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### software-engineering.revision / p1 + +Exact source: + +Changed evidence about likely changes, maintenance conditions, costs, or objectives may justify revising a design or this priority's application. A revised judgment acknowledges material changes in its grounds; it does not make a failed prediction successful retrospectively. + +Compared through: `T35` (qualified_revision_account), `T36` (bounded_countermodels_with_scope_limit), `T38` (kernel_witness_source_composition_pending), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +### software-engineering.revision / p2 + +Exact source: + +Retaining a design can be justified when the relevant alternatives have no supported contribution or impose costs that defeat the objective. Reflexivity also keeps this engineering commitment and the methods used to assess evolution within the scope of criticism and revision. Continued change, agreement, or successful examples do not establish its universal correctness. + +Compared through: `T35` (qualified_revision_account), `T36` (bounded_countermodels_with_scope_limit), `T37` (partial_same_rule_grounding), `T38` (kernel_witness_source_composition_pending), `T40` (documentary_boundary). + +Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link. + +## Required follow-through before claiming complete correspondence + +For T16, preserve the output/explanation result and identify explicitly whether that application capability is intended as the source's optional explanation branch; do not call it a proof of independent understanding without an adopted definition and correspondence argument. For T20, distinguish the existing projected fragment from the full preservation statement, including its consistency component. For T31, represent or exhibit the boundary and the knowledge/obligation relation actually crossing it for the intended change. For T37, connect the assessed engineering-priority object to its corresponding Grounds/value judgment and consistency result, rather than substituting grounds for the five inherited labels or for a different selection judgment. Reassess T38's source composition after those objects are resolved. + +No source rewrite is requested or authorized by this report. Existing proofs and the frozen blind artifacts remain valid evidence about their exact code. A change to code, target wording or interpretation requires a separate reviewed object; later work must not refresh hashes and overwrite this initial judgment. diff --git a/SoftwareEngineering/lean/philosophy/reviews/code-blind-delta-identity.json b/SoftwareEngineering/lean/philosophy/reviews/code-blind-delta-identity.json new file mode 100644 index 0000000..0c8a3f4 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/code-blind-delta-identity.json @@ -0,0 +1,20 @@ +{ + "stage": "delta-blind-code-only", + "frozen_utc": "2026-09-14T17:48:02.922686+00:00", + "source_fidelity": "unevaluated", + "input_drift": "none", + "artifacts": { + "delta-blind.md": "a0a16628362882d5574bf41123d6fed41ce735083d55dccfb06650555cb3b776", + "delta-code-hashes.json": "ed7b0e1a14dfb426b2f7c4735be02db2911bcba1f6099543df2616166047130c", + "nonblank-code.diff": "a0545ab97645bd8367ef84cc5b8d7c9f8bf95ba45839c2672d29daea76ca3137", + "delta-declarations.json": "f114fad4dc45210fc793fedfc719d2baa9d50e73f55739a26e27e0132983318c", + "DeltaAudit.lean": "cd9536e5a2205894e4d6987bd9454ac2adda91a0c6e83b792056caea0cb9f109", + "delta-actual-audit.log": "e6a5973745a917b19c79cb119c498a534aa2f16f48cd305d04c837e7febe26c5", + "delta-axiom-summary.json": "1516ad35a9504250072d73ec52cefcf17b454f1c7f61d4f4c4af68835dd7025d", + "delta-toolchain.log": "7657cf16156f61420bea6e19ecc0a6e4bd47f2e27e3124146eddcf30c667885e", + "delta-build.log": "b8db9a7581b95559e4c984518e640e3f4968d3683dc716faa76878adba26173c", + "DeltaProbes.lean": "fba9d1b478afe68cca2ac2a2e257e1aca72ffa87ba39579d867ff330f4c176eb", + "delta-probes.log": "743f4824caf00181a66775b172c44c085caf05b5517ff489ce45125e0650666b", + "delta-probes-initial-failed.log": "d97e471fa448deff83ae8241251fdf943aedde56f938e964e0a9fad6299d0ee3" + } +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/code-blind-delta.md b/SoftwareEngineering/lean/philosophy/reviews/code-blind-delta.md new file mode 100644 index 0000000..1eccb8c --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/code-blind-delta.md @@ -0,0 +1,210 @@ +# Blind explanation of the code delta + +Stage: **code-only delta; source fidelity unevaluated**. I compared the new supplied Lean snapshot with the initial code-only snapshot, discarding blank/whitespace-only lines for semantic-diff detection. I did not inspect source prose, mapping comments, author explanations, or external review verdicts. The initial manuscript and artifacts remain untouched. The previous initial manuscript SHA256 is `cf9280ddd3365440e848b14043a6208b9fea5114f9ff13cea4e236e3358317df`. + +Only `CoreReader/Engineering/Domain.lean` has a nonblank code change: two new definitions and one expanded theorem statement/proof. Other Lean files have identical nonblank line sequences; their new raw hashes still reflect their supplied whitespace and positions. This delta does not alter `CoreReader.Adopted.*`, the engineering evidence/value/self-application interfaces, or the final inheritance/priority witnesses. The initial explanation therefore remains applicable to their unchanged nonblank code, with location changes documented in the new declaration inventory. + +## Actual new definitions + +`CoreReader.Engineering.relocateVerification : EngineeringDesign → EngineeringDesign` has one explicit input argument, no hidden generic binder, no domain-specific typeclass assumption, and no proof premise. Its result is a data record, not a proposition or theorem. `CoreReader.Engineering.sameWorkDesign : EngineeringDesign` is the instance obtained from `privateDesign`. + +`EngineeringDesign` contains metadata, a total `List Nat → List Nat` run function, a `Change → List EditStep` path function, a list of component Nat IDs, a list of boundary records, and batch assumptions. Each edit step contains a component Nat ID, one required knowledge label, a tool label, and Nat work units. A boundary contains caller/callee Nat IDs and a contract string. + +The new transformation starts with the result of `introduceBoundary design`. Thus it inherits that transformation's incremented module/extension-point metadata; run function `fun xs => design.run (xs ++ [])`; original component list with its length appended; original boundary list with the record `(caller = original component count, callee = 0, contract = original metadata signature)` appended; and unchanged batch assumptions. + +It then **overwrites the path function**. It maps over each **original** `design.paths d`, changing an existing step's component ID to the original component count precisely when its tool is `.contractRunner`. Every other step is unchanged. A changed step retains its original required knowledge, tool and work units. This record update replaces the one-unit contract-runner step that `introduceBoundary` would have appended; it does not retain that extra step and then relocate verification. If an original path is empty, the mapped path remains empty. The transformation is defined for every `Change`, including every `.other String` value, not just the enumerated registered list. + +This distinction explains the numeric result. `wrappedDesign` still uses `introduceBoundary privateDesign` directly and costs 18 for design revision. `sameWorkDesign` uses the new transformation and costs 17 because it changes component locations in the original five-step path while preserving the entire sequence of work-unit values. The new boundary is an actual record in the model, and the path function really changes; the unchanged work is not obtained merely by renaming the old object. Conversely, the code does not execute software calls through that boundary or charge a separate overhead for it: work is exactly the sum of step units. + +The independent delta probe proves the stronger code-derived equalities + +```lean +∀ (design : EngineeringDesign) (xs : List Nat), + (relocateVerification design).run xs = design.run xs + +∀ (design : EngineeringDesign) (d : Change), + designWork (relocateVerification design) d = designWork design d +``` + +These are supplemental audit examples, not additions to the project's proof inputs. The first proof simplifies append-empty. The second expands `designWork`, composes the two list maps, and checks both cases of the tool test: the step's units are unchanged in either branch. The quantifiers range over all values of these Lean types; no empirical timing or boundary-effect hypothesis is needed because equality follows from the definitions. + +## Expanded theorem + +`CoreReader.Engineering.structureNotCapability` is a theorem with no parameters or extra hypotheses. Its fully elaborated declaration type is the entire concrete conjunction printed in `delta-actual-audit.log` and reproduced below. That conjunction is a proposition; the declaration is a proof of it. The original four conjunction blocks are retained: + +1. Equal signature metadata can accompany different outputs (deduplication versus sorted deduplication on [2,1,2]). +2. The private design has eight components and eight batch assumptions that all need revision at batch size 5. +3. The same “dependency inversion” metadata can coexist with absent/present successor capability depending on the path's knowledge requirements. +4. The earlier appended-step boundary example grows the component count to nine and work from 17 to 18 without changing its sample output. + +A fifth conjunction block now gives one different example. It establishes all of the following **for the same `sameWorkDesign` value**: + +- Its boundary list is exactly `[⟨8, 0, "List Nat → List Nat"⟩]`. +- It has nine components. +- Its design-revision path differs from the private design's path. +- Both run functions agree on [2,1,2]. +- Its design-revision work equals the private design's work and is exactly 17. +- The successor still fails `DesignCanChange` for design revision in the continuing activity. + +The proof changes from a four-component tuple of `by decide` results to five components. Every newly stated property is decided from finite concrete data. The actual declaration/axiom audit reports no axioms for the two new definitions and `[propext]` for the expanded theorem; no `sorryAx` or new domain axiom is present. + +## Exact path evaluation and retained capability constraint + +The audit evaluates both original and new paths. Each has five steps: + +| Step | Required knowledge | Tool | Units | Original component | New component | +| --- | --- | --- | --- | --- | --- | +| 1 | privateLayout | editor | 1 | 0 | 0 | +| 2 | publicContract | contractRunner | 1 | 0 | 8 | +| 3 | privateLayout | editor | 5 | 1 | 1 | +| 4 | privateLayout | compiler | 5 | 2 | 2 | +| 5 | publicContract | contractRunner | 5 | 2 | 8 | + +`sameWorkDesign.components` evaluates to `[0,1,2,3,4,5,6,7,8]`, so component 8 really is listed in this concrete design. The new paths differ at their contract-runner steps; the sum remains `1 + 1 + 5 + 5 + 5 = 17`. + +`DesignCanChange activity design maintainer direction` requires a nonempty path, membership of that maintainer in the activity, and that every step's knowledge and tool are available. It does **not** inspect the step's component number, the boundary list, or the run function. The continuing successor lacks `privateLayout`; the unchanged editor/compiler steps still require it, so capability remains false. The original maintainer has it and can change the new design; a supplemental concrete probe checks both results. This is an independently inspectable cause in the actual definition, rather than an arbitrary assignment of a negative capability label. + +## What this delta establishes and does not establish + +The delta supplies an additional concrete case where adding a modeled boundary and relocating existing verification steps leaves the model's revision work exactly unchanged and does not grant the successor the missing path prerequisites. Together with the retained 18-unit case, the file now contains both increased-work and equal-work boundary examples. These examples disprove a universal inference from the represented structural change alone to strictly lower `designWork` or newly available `DesignCanChange`, within the definitions used here. + +The code does not show that every real boundary relocation leaves effort unchanged, that the cost model measures real total engineering effort, that relocated test execution is valid in a concrete software system, or that boundaries cannot help. The new transformation does not add an operational semantics connecting boundary caller/callee fields to path execution, verify a caller/callee contract, or establish component-ID uniqueness for every arbitrary input design. For the concrete private design the appended ID is fresh and the boundary endpoints are listed, but the generic transformation simply uses list length and callee 0 with no preconditions. Those generic record-design limitations are unchanged from its existing `introduceBoundary` dependency. + +No empirical/inferential/value support predicate, assessment-task identity, value objective, applicability rule, own-fact theory, `Inherited` field, or final witness changes in this delta. The new conjunction is additional finite evidence for the structure/capability example; it does not repair or alter the broader semantic limits documented in the initial blind manuscript. Source correspondence remains a separate, not-yet-performed comparison. + +## Actual audit and preservation + +`delta-code-hashes.json` binds each new input file and the previous initial-manuscript hash. `nonblank-code.diff` records the complete nonblank difference. `delta-declarations.json` gives all 788 declarations' current locations. `DeltaAudit.lean` checks all declarations with `#check @` and prints all their transitive axioms; `delta-actual-audit.log` records exit code 0. All 269 theorem declarations remain present. `delta-build.log` records a fresh full project build under the installed Lean 4.33.1. `DeltaProbes.lean` and `delta-probes.log` retain actual evaluations and the two universal transformation equalities, also with exit code 0. The first supplemental proof attempt needed one function-composition reduction; its failed log is retained and no project proof input was changed. + +The original frozen artifacts were not overwritten. The delta manuscript and its own manifest are preserved before any source comparison material is disclosed. + +## Exact current code excerpts and locations + +### `CoreReader.Engineering.EngineeringDesign` + +`CoreReader/Engineering/Domain.lean:686–693` + +```lean +structure EngineeringDesign where + metadata : InterfaceView + run : List Nat → List Nat + paths : Change → List EditStep + components : List Nat + boundaries : List Boundary + batchAssumptions : List (Nat × Nat) + +``` + +### `CoreReader.Engineering.DesignCanChange` + +`CoreReader/Engineering/Domain.lean:703–708` + +```lean +abbrev DesignCanChange (a : Activity) (design : EngineeringDesign) + (m : Maintainer) (d : Change) : Prop := + design.paths d ≠ [] ∧ m ∈ a.participants ∧ + (design.paths d).all (fun step => + (a.available m).contains step.requires && a.tools.contains step.tool) = true + +``` + +### `CoreReader.Engineering.designWork` + +`CoreReader/Engineering/Domain.lean:709–711` + +```lean +def designWork (design : EngineeringDesign) (d : Change) : Nat := + ((design.paths d).map EditStep.units).sum + +``` + +### `CoreReader.Engineering.introduceBoundary` + +`CoreReader/Engineering/Domain.lean:718–727` + +```lean +def introduceBoundary (design : EngineeringDesign) : EngineeringDesign := { + metadata := { design.metadata with modules := design.metadata.modules + 1, extensionPoints := design.metadata.extensionPoints + 1 }, + run := fun xs => design.run (xs ++ []), + paths := fun d => if (design.paths d).isEmpty then [] else + design.paths d ++ [⟨design.components.length, .publicContract, .contractRunner, 1⟩], + components := design.components ++ [design.components.length], + boundaries := design.boundaries ++ + [⟨design.components.length, 0, design.metadata.signature⟩], + batchAssumptions := design.batchAssumptions } + +``` + +### `CoreReader.Engineering.wrappedDesign` + +`CoreReader/Engineering/Domain.lean:728–732` + +```lean +def wrappedDesign : EngineeringDesign := introduceBoundary privateDesign + + + + +``` + +### `CoreReader.Engineering.relocateVerification` + +`CoreReader/Engineering/Domain.lean:733–738` + +```lean +def relocateVerification (design : EngineeringDesign) : EngineeringDesign := { + introduceBoundary design with + paths := fun d => (design.paths d).map (fun step => + if step.tool = .contractRunner then { step with component := design.components.length } + else step) } + +``` + +### `CoreReader.Engineering.sameWorkDesign` + +`CoreReader/Engineering/Domain.lean:739–744` + +```lean +def sameWorkDesign : EngineeringDesign := relocateVerification privateDesign + + + + + +``` + +### `CoreReader.Engineering.structureNotCapability` + +`CoreReader/Engineering/Domain.lean:745–773` + +```lean +theorem structureNotCapability : + (privateDesign.metadata.signature = sortedDesign.metadata.signature ∧ + privateDesign.run [2, 1, 2] = [2, 1] ∧ sortedDesign.run [2, 1, 2] ≠ [2, 1]) ∧ + (privateDesign.metadata.modules = privateDesign.components.length ∧ + privateDesign.batchAssumptions.length = 8 ∧ + (designModulesNeedingRevision privateDesign 5).length = 8) ∧ + (privateDesign.metadata.principle = "dependency inversion" ∧ + privateDesign.metadata = documentedDesign.metadata ∧ + ¬ DesignCanChange continuingActivity privateDesign .successor .designRevision ∧ + DesignCanChange continuingActivity documentedDesign .successor .designRevision) ∧ + (privateDesign.boundaries.length = 0 ∧ wrappedDesign.boundaries.length = 1 ∧ + wrappedDesign.components.length = 9 ∧ + wrappedDesign.boundaries = [⟨8, 0, "List Nat → List Nat"⟩] ∧ + wrappedDesign.run [2, 1, 2] = privateDesign.run [2, 1, 2] ∧ + designWork privateDesign .designRevision = 17 ∧ + designWork wrappedDesign .designRevision = 18 ∧ + ¬ designWork wrappedDesign .designRevision < designWork privateDesign .designRevision) ∧ + (sameWorkDesign.boundaries = [⟨8, 0, "List Nat → List Nat"⟩] ∧ + sameWorkDesign.components.length = 9 ∧ + sameWorkDesign.paths .designRevision ≠ privateDesign.paths .designRevision ∧ + sameWorkDesign.run [2, 1, 2] = privateDesign.run [2, 1, 2] ∧ + designWork sameWorkDesign .designRevision = designWork privateDesign .designRevision ∧ + designWork sameWorkDesign .designRevision = 17 ∧ + ¬ DesignCanChange continuingActivity sameWorkDesign .successor .designRevision) := by + exact ⟨by decide, by decide, by decide, by decide, by decide⟩ + + + + +``` diff --git a/SoftwareEngineering/lean/philosophy/reviews/code-blind-identity.json b/SoftwareEngineering/lean/philosophy/reviews/code-blind-identity.json new file mode 100644 index 0000000..7fc9c0d --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/code-blind-identity.json @@ -0,0 +1,21 @@ +{ + "stage": "initial-blind-code-only", + "frozen_utc": "2026-09-14T17:42:46.956973+00:00", + "source_fidelity": "unevaluated", + "artifacts": { + "initial-blind.md": "cf9280ddd3365440e848b14043a6208b9fea5114f9ff13cea4e236e3358317df", + "code-hashes.json": "fbb9a93af4b3be7c5d8cc2a574cc59bfbc9d381e5fc22ec2a74db13c8906f9f1", + "concerns.json": "977264439858f15c15c35113648b93b6484ed84458a04e0477e39e450de44ff0", + "declarations.json": "1c3a62cc58ad3460500d31cfd9fb27465c973f8f3107800e797fe3d4327e060c", + "DeclarationAudit.lean": "570ba85feccace76d7fe308ff10993c1ef9062c50345e3c73006b2ee7f48d5dd", + "declaration-axiom-audit.log": "e3339e6f2923bfa7b58ca172617a4730d47352f2a3255de9583f5c044bcc9629", + "declaration-axiom-audit-initial-failed.log": "899310d6d27514ff47ee07e749bc865c31e407d8c64cc7fae0b95a01d3be166b", + "axiom-summary.json": "9f8b38fcfa9ffbe9ecf7a2c6d2e2eb1afe4667230985346068dde79ed2d167fb", + "build.log": "cca67e38a0015c7e8688480683427b23813765586276d2626c4babbf0b23210c", + "toolchain.log": "7657cf16156f61420bea6e19ecc0a6e4bd47f2e27e3124146eddcf30c667885e", + "SemanticProbes.lean": "c4c124072c6864250fcd3a71ce3b65b5442770b6ffccf75e20fe9aa9347f37f4", + "semantic-probes.log": "2decc16edcc7c22f763d588ce758d66fcd2dcab935f724027cf7fa50b2db85a8", + "semantic-probes-initial-failed.log": "4c2cbd42a92d779df10846da9e91473adcfa022cb4077ccbccbc7d039096d761", + "preservation-check.log": "932de7d8f66d944a213c8cd126746b07f65a31198955ebe3259b5eda2c08a91e" + } +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/code-blind-initial.md b/SoftwareEngineering/lean/philosophy/reviews/code-blind-initial.md new file mode 100644 index 0000000..c787495 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/code-blind-initial.md @@ -0,0 +1,10871 @@ +# Initial blind explanation of the supplied Lean project + +Stage: **code only; source fidelity unevaluated**. This artifact was prepared before receiving any source prose, source inventory, author explanation, intended verdict, or previous review. The only inspected materials were this isolated project and the requested technical translation skill. Identifier names and embedded strings are treated as code, not as independent evidence that their labels describe reality. No proof inputs were changed. + +The project contains 786 explicit substantive declarations, including 269 theorems. `CoreReader.lean` imports `Engineering.Integration`, whose transitive imports reach all twelve modules. The installed Lean reports 4.33.1. The project builds; every explicit declaration was checked with `#check @...` and audited with `#print axioms ...`. The exact elaborated types, with implicit arguments made explicit and full names enabled, are in `declaration-axiom-audit.log`; the corresponding locations are in `declarations.json`. Audited dependencies are either empty or subsets of `propext`, `Quot.sound`, and `Classical.choice`. No `sorryAx` or additional domain axiom appears. This establishes acceptance of these code statements under those foundations; it does not validate their interpretation or any external observations. + +The main text explains declaration groups. The appended exact-source inventory gives every declaration its original line interval and exact code, including proofs. Read a group's explanations together with those excerpts and the full-type log. No source-claim IDs or philosophical baseline are invented. + +## 1. Logical domains and foundational interfaces + +`Claim W` is `W → Prop`; `Theory W` is `(W → Prop) → Prop`, a predicate determining which claims belong to the theory. `Models t w` universally quantifies over **all** claims selected by `t` and requires each to hold at that same `w`. `Entails t p` universally quantifies over worlds satisfying `t`; `Satisfiable t` supplies an actual witness world. These are semantic definitions, not a syntax of derivations or a list of measured facts. `W`, `Q`, and the other explicit generic domains in this project are Lean `Type` (universe zero), not implicit declarations that a concrete physical world exists. The full audit makes every generic binder visible; no unmentioned domain-specific typeclass premise is supplied to these interfaces. + +`Context W Q` supplies another theory, a meaning for each question, and a scope predicate. `Admissible t c w` conjoins membership in the models of the held theory, membership in the models of the context assumptions, and scope, all for the same world. `Consequence` says every admissible world satisfies either the question's meaning or its negation according to a Boolean polarity. `Consistent` forbids having both polarities for any question. `consequenceConsistency` **assumes** an admissible witness and rules out a contradiction at that witness. It does not derive that witness from consistency. When `Q` is empty, consistency is vacuous even for an unsatisfiable theory; a checked supplemental probe demonstrates this. If admissible worlds are absent and there is a question, both consequences hold vacuously and this consistency predicate fails. + +`singleton p` contains exactly the claim equal to `p`; `union` is disjunction of membership. `modelsSingleton` and `modelsUnion` unpack those definitions. The Boolean and Boolean-pair examples distinguish individually satisfiable premises from their inconsistent conjunction, opposite time slices from their inconsistent union, and changes of assumptions, question meaning, and scope. Empty Boolean theory has both worlds as models and entails neither `w = true` nor its negation. The two inequalities `4 ≤ n` and `n ≤ 6` overlap at 5 without being identical predicates. These are explicit countermodels and witnesses, not empirical discoveries. + +`Snapshot` records held theory, context, and a natural-number revision identity. `SameContent` compares theory membership and all meanings/scopes extensionally. `TruthfulReport a b reported` is only the implication `(content differs OR revision number differs) → reported = true`. It does not require `reported = false` when unchanged, prove that reported content is true, or verify a textual account. `semanticChangeMustBeReported` is direct application of this assumed implication. The hidden-change examples refute a false flag for concrete differing snapshots. Reordering a two-member union preserves its membership predicate. + +## 2. Evidence, articulation, values, and choice + +A `Record W` is a Boolean function on candidate worlds paired with a stipulated observed Boolean. `Compatible records w` requires every listed test to equal its recorded result at `w`. `Supports records claim` requires the claim at **every compatible world**. Neither definition verifies how the records were acquired. With no records, compatibility is true for every world; with contradictory records, support is vacuous. `FacetDischarged` deliberately strengthens the raw support interface: an empirical facet needs a witness satisfying both compatibility and scope, support for `scope → conclusion`, and support for the uncertainty predicate. An inferential facet needs satisfiable assumptions and their semantic entailment of the conclusion. A value facet needs `ValueProcedure`. Empirical uncertainty is an arbitrary proposition on worlds; it is not a probability, error bar, confidence level, or statistical guarantee unless additional code gives that meaning. + +An `Articulation` holds concept strings, a theory, reason predicates, and a limit predicate. `Articulated` checks only that the concept and reason lists are nonempty; it does not require nonempty individual strings or explanatory quality. `FacetArticulated` ties assumptions, reasons, and limits to the same facet by equality. Canonical articulations build those equalities by construction: empirical reasons are the single compatibility predicate, inference reasons are the single model predicate, and value reasons specialize all reasons to the adopted position. The canonical theorems establish these structural ties and nonemptiness, not independent evidential support. + +`ValuePosition W` contains its own `Position` and `Outcome` types. The adopted position is fixed across worlds; `selected w` is the world-dependent position. `commitment w` is the equality `selected w = adopted`. Its `consequence w` is the stipulated objective on `outcome w adopted` together with the stipulated constraints on that same adopted position. `JointAdoption` supplies one world satisfying starting assumptions, limits, adoption, and **all** reasons jointly. `ValueProcedure` requires a nonempty reasons list, that witness, a universal conditional from starting assumptions, limits, and **all** reasons to the consequence, and a nonempty response string at each in-scope world where criticism is relevant. It does not say that all worlds adopt the position, that the adopted objective is obligatory, that every listed reason separately suffices, that criticism exists, that a response addresses it adequately, or that a different objective is illegitimate. The universal consequence condition does not even assume the commitment; it concerns the consequences of the fixed adopted option under its stated premises. + +`Grounds` additionally requires a nonempty facet list, inclusion of every facet selected by the supplied `actualApplicable` predicate, and the same claim, articulation, and discharge conditions for every listed facet. The applicability predicate itself is supplied, not discovered. `AchievementAccountability`, `ProcessGrounds`, and `ApplicationDuties` are bundles of these requirements; projection theorems extract the already-assumed requirements. + +The switch value example selects true, gets benefit 4 at cost 3, and uses the objective cost < benefit and budget 3. Its opposite adopted value produces (0,0), so it fails that **same** strict objective. Empty reasons, inconsistent starting assumptions, impossible joint adoption, and missing criticism responses are separately rejected. A nonempty announcement that says “activate” leaves a zero-budget world admissible and does not justify the cost. In `jointReasonPosition`, benefit 4 and cost ≤3 must hold jointly; the counterworlds (4,5) and (0,3) show why either reason alone is insufficient. + +The `zeroRecord` examples have world type `Nat → Bool`, not a finite set of observations equated with all possible functions. The record observes only input 0. The always-true function and the function true only at 0 are compatible, but differ at 1. Consequently the observation supports the local conclusion and does not support `∀ n, f n = true`. The generated-revision structures bind producer, prior output, and revised output by construction, yet their ownership does not change this countermodel. Repeated copies of the first-coordinate record leave the second coordinate undetermined; repeated action records leave the budget undetermined. These are concrete demonstrations of insufficiency within the selected model class. + +`Trial` verification is recorded outcome = actual outcome, reproduction is equality of settings only, and boundedness is actual outcome ≤2. The explicit examples separate these three predicates; reproduction does not mean reproducing the result. `randomTrial012` later assigns equal positive integer weights to two Boolean draws; no random sampler or probability measure is implemented. + +`Process` has a total `Nat → Nat` output and an optional tiny program (`doubleInput` or a constant). `OutputContract` universally requires doubling every natural input. `ExplanationContract` requires a present program whose evaluation equals that output everywhere. The output-only process doubles but has no program; the explained process has `.doubleInput`. A process assessment's assumption theory is exactly `candidate = assessed`. `processContractDischarged assessed contract proof` substitutes that identity and returns the **supplied** proof of `contract assessed`. It verifies the same process and contract, not a newly established measurement or independent capability. The external certificate carries unequal natural-number IDs 42 and 7 plus a proof of the same doubling output; it does not model independence beyond unequal labels or establish that a real external review occurred. + +`Choice.Implementation` carries output, cost, domain, explanation and trace functions plus status metadata. `Requirements` supplies input scope, expected output, budget, and which method reasons are valued. `Feasible` requires scoped output correctness and cost ≤ budget. `Relevant` rejects every status reason by definition; a method reason needs both its stipulated value and its actual associated content. `JustifiedChoice` requires feasibility and **at least one** relevant reason in the supplied list. It does not require all reasons to be relevant, compare all alternatives, optimize cost, or establish every explanation/procedure condition. A cheap but incorrect successor has a relevant simplicity reason but fails feasibility. Identity is feasible and can be justified even when conventional and established. The same output can coexist with a wrong explanation; the separate explanation reason then fails. Status facts, true for both candidate worlds, do not entail choosing identity. An accurate non-entailment report and an actual choice justified only by status are separate objects: the former can pass while the latter fails. + +## 3. Agency and the earlier concrete integration + +`Generative policy` requires valuation of the fixed expansion aim and revisability of every form the policy marks current. It does not use `permitsVersion`, demand a current form exists, or prove any improvement occurred. `Expanded before after` means a newly present understood or constructed operation, with no requirement to retain previous operations. Duplicating inventory/layers/vocabulary does not add one of those operations. The available operations here are just identity and successor. `assistedExecution` returns the sum of three optional natural numbers only when all are present. `collaborativeRevision` elsewhere checks only that the collaborator option is present, then chooses a hardcoded expanded state; that is not a general causal model of collaboration. + +The announcement predicate ties before/after, a claimed new operation, and one input-output check. Its truth implies expansion because it explicitly contains a new constructed operation. The inflated announcement fails. The transition performance record distinguishes extension from inflation; the report record merely records that the announcement has the stipulated fields and is compatible with both. Thus an accurate report of an assertion need not support the asserted achievement. + +The legacy `Reflexive` interface has an owner, a rule registry, and work records. A `ValidApplication` proves exact rule key, target, activity, inquiry, reasons, and limits identities; target registry resolution; inquiry target and current-method resolution; nonempty reasons with the same target; applicability; and satisfaction of the rule's supplied meaning relation. `Reflexive` requires registry coherence and, for each registered rule and every same-owner applicable subject, an existing valid record. The implication to `ReflexiveScope` and `noSelfExemption` merely project this. Empty registries and absent applicability can vacuously satisfy the interface. + +The concrete finite legacy method has nine own subjects, two rules, generation omitted at application phase, and assessment at every listed subject. Inputs, requested scope, purpose/scope/observation/counterexample reason objects, and the local method are constructed together. The evaluator uses specific list membership and program execution: the only-at-zero program passes the [0] tests and fails the wider revision input 1, producing insufficiency. The generation result changes requested scope while retaining tested inputs; it is not a claim that the wider scope was verified. `completeOwnWork_reflexive` is proved by registry-key distinction, finite membership, same-object construction, and direct evaluation. An application-only rule can be reflexive without assessment of the system because the system is inapplicable; the dedicated counterexample makes this visible. The arithmetic self-test passes at 1 and fails at 0. + +The earlier `CoreReader.Integration` world is the pair `(Choice.Candidate, Mode)` with two implementation candidates and apply/waive mode. The actual world is identity/apply. Observation of correct output at 0 identifies identity **within this two-candidate universe**, so universal identity output is supported there. A cost≤2 record admits the incorrect successor and does not support correct output. Charter conjunctions establish policy, consistency, finite reflection and current form labels, but cannot repair that unrelated record's missing support. + +Its five value-position adapters select apply mode, use concrete test outcomes or proposition decisions as consequences, and use hardcoded objectives. Apply passes those constructed objectives and waive fails. `conflictDecision`, `groundsDecision`, `choiceDecision`, and the associated value positions are noncomputable classical proposition decisions, not executable testing tools. `groundsProvisionMeaning` identifies apply with the property that permitted grounds never evade `Grounds`; the waive counterexample refutes the universal property. The grounds-on-grounds result rewrites a commitment predicate by this equivalence and packages an existing value procedure. The proposal-review implementation similarly wraps two proposition decisions and verifies only requested inputs 0 and 1. `applicationRetainsDuties` extracts its premises; changing the output requirement to successor output invalidates the prior identity evidence. The joint witness supplies the concrete actual system/world, not all possible systems. + +## 4. Adopted interfaces and complete group coverage + +`AssessmentTask W` has empirical, inferential, and value variants. `taskOfFacet` copies a facet into the corresponding task. `NatureAppropriate task facet` requires exact equality of empirical records/scope/conclusion/uncertainty for an empirical-to-empirical pairing; exact equality of assumptions and conclusion for an inferential pairing; and equality of the full value position for a value pairing. It permits an empirical task to use an inferential facet only when the assumptions equal `singleton (fun w => Compatible records w ∧ scope w)`, the conclusion is the same claim, and the original uncertainty is supported by the records. All other pairings are false. Equality is Lean equality, including functional extensional equality when proved; it is not merely the same title or similar text. + +`Grounds012 claim articulations facets task` requires a nonempty list and, for every member, equality of its claim to `claim`, articulated and facet-linked reasons, discharge, and nature-appropriateness to the supplied task. Unlike the earlier `Grounds`, this interface has no `actualApplicable` coverage quantifier. Its obligation is over the **supplied** facets for one supplied task. `grounds012Singleton` takes `FacetDischarged f` as a premise and supplies canonical structure and a task copied from that facet. It is a packaging theorem, not a way to prove an unsupported facet. + +`generationSpecification`, `choiceSpecification`, and the empirical/inferential/value/capability specifications are aliases or canonical singleton wrappers around the meanings already expanded above. `consistencySpecification before after reported` asks for after-snapshot consistency and the one-way report implication. It does not require consistency of the before snapshot. `ReflexiveRule T I O` has a key, activity tag, applicability, input function and meaning relation. `reflexivitySpecification` asks for coherent keys and for every rule and every self/applicable target an outcome that is both performed at the exact `rule.input target` and satisfies its meaning at that exact input/outcome. The activity field is not independently used by this predicate. The performed and meaning relations are arbitrary inputs. `legacyReflexivity` derives this weaker adapter from the stricter legacy record interface and explicitly transports inquiry/reasons/limits identities. + +`ScopeAccount W` supplies claim, conditions, observation scope, relevance, comparison pairs, used methods, roles and an explanation relation. `scopeSpecification` says each compared pair lies in the same supplied conditions and observation scope and is relevant, and each used method has a nonempty role and satisfies the supplied explanation relation for the same claim and conditions. It does not establish claim support itself, completeness of compared pairs, use of any method, or semantic adequacy of arbitrary `explains`. The concrete local account restricts comparisons to input zero and binds each method explanation to a proved local-support/repeated-support/non-universal-support statement. It is consequently more substantive than the bare interface. + +The Adopted theorem groups have these specific contents and limitations; the inventory retains every member's exact statement: + +| Declaration group | Code-derived result and proof scope | +| --- | --- | +| `collaborativeProgress`, `generationCases`, `generationLimits012`, `inventoryCases012`, `achievementSupported012` | Repackage the two-operation progression, optional-resource and performance-record examples; scope and new-operation witnesses are explicit, while inventory growth and assertion records fail. | +| `consistencyConsequences`, `sliceConsistency`, `explicitlyConsistentLimits`, `semanticOrder012`, `jointImplicationConflict012`, `tensionConsistent012`, `consistencyCases`, `consistencyLimits012` | Instantiate consistency with nonempty question domains; transport premises or construct Boolean/Nat witnesses and contradictions. They do not equate consistency with truth or sufficiency. | +| `localFacetChecked012`, `scopeStrength012`, `uncertainSupported012`, `inferenceChecked012`, `qualitativeUnmeasured012` | Prove local first-coordinate/input-zero results and arithmetic conditional inference, while rejecting stronger conclusions by explicit worlds. The uncertainty successfully supported is the exhaustive Boolean disjunction, not a prediction of the second coordinate. | +| `closedCriticism012`, `valueFulfilled012`, `valueNotFact012`, `clearFalseReason012`, `valueCases012`, `groundsLimits012` | Distinguish the value procedure from a fact of selection, empty-theory entailment, a constant record, or mere articulation. A no-response position fails at the explicit relevant criticism. | +| `qualitativeProportionality012`, `scopeFulfilled012`, `scopeCases012`, `scopeLimits012`, `randomOutcomes012` | Claim strength is logical implication (`stronger w → weaker w`); observations at 0 fail at 1; verification, setting equality, and bounded variation are separated. No numeric calibration of confidence/proportionality is proved. | +| `capabilityFulfilled012`, `OwnCapability012`, `ownCapability012`, `capabilityCases012`, `capabilityLimits012` | Double-output and optional explanation contracts remain distinct. Ownership adds only equality of two Nat IDs; process evidence is for the exact assessed process. | +| `CompleteCharter012`, `completeCharter012`, `charterWithoutGrounds012` | Construct one charter with unchanged snapshot and false report; its consistency/reflection do not establish output from the cost record. | +| `groundsPermission012` through `groundsOnGrounds012` | Boolean-enabled permission is equivalent to the universal grounds-preservation provision; a global all-true claim is rejected when enabled and accepted by vacuous permission when disabled. The value procedure adopts enabled and values rejection of that fixed unsupported inference; the final theorem rewrites commitment to the provision via extensionality. | +| `reflexiveTargets012`, `openSelfExempt012`, `reflexivityCases012`, `reflexivityLimits012` | Full finite applicable-target coverage and an application-only exception are both shown; a rule applicable to target 0 but performed only at 1 fails. Open revisability is insufficient. | +| `circularGlobalConditional012`, `circularSubstitutionRejected012` | Assuming all-true entails all-true and is satisfiable, so it is legitimate as that conditional task; it is not the original task based on observing input zero. Failure comes from the required equality of assumptions. | +| `observedInferenceChecked012`, `sameEmpiricalTaskTwoMethods012` | The empirical local facet and an inference from exactly compatibility-and-scope both discharge the same empirical task; the uncertainty obligation is retained. | +| `uncertaintyBypassChecked012`, `uncertaintySubstitutionRejected012` | The first-coordinate inference is checked, but the empirical task also requires second-coordinate true; compatible (true,false) defeats appropriateness and therefore grounds. | +| `valueFactSubstitutionRejected012`, `inferentialContextSubstitutionRejected012`, `groundsCases012`, `empiricalCases012`, `inferentialCases012` | A factual selection observation cannot replace a value task, and a stronger premise cannot replace the stipulated empty assumption theory. Aggregates only conjoin existing results. | +| `wrongExplanation012`, `internalReasonDistinguishes012`, `ownPhilosophyStatus012`, `allStatusOnly012`, `choiceCases012`, `choiceLimits012` | Same outputs/feasibility do not ensure explanation reasons; all status-only selections fail by definition; the current review implementation passes by output reasons. Aggregates do not add a theorem that the chosen method is optimal. | + +## 5. Engineering domain: what the model actually computes + +The engineering domain has three maintainers, four tools, four knowledge labels, three candidates, seven burdens, nine named change constructors plus `other String`. Lists `maintainers`, `changes`, and `burdens` enumerate the finite named cases; `registeredDirections` adds one other case, “csv export”. The arbitrary strings admitted by `Change.other` are **not** all enumerated or supported. `MaximumRegisteredCapability` quantifies over the ten registered directions only. + +An activity is a record of participant names, a software string, tools, a function assigning knowledge lists, release/maintenance counts, optional bounded runs, and a label. `ActivityScope` checks nonempty participants/software/tools and a nonempty knowledge list for each participant. `Continuing` is both scheduled counts >0; `BoundedLifecycle` is a present bounded-run option and both counts zero. The continuing example is intentionally labeled “temporary” while still continuing by its counts. The temporary/prototype/retiring examples have positive optional bounds and zero counts. These predicates classify the supplied fields, not actual lifecycle behavior; they are not an exhaustive dichotomy of all records. + +`changePath` prescribes edit steps with component number, knowledge label, tool and natural units. The simple candidate needs private layout; the other two normally need a public change guide. Addition/independent has 2 units; simple design revision/withdrawal/redrawing has 17, versus 6 for evolvable/maximal; migration has 10. Coordinated paths touch a further component and cost more than independent paths. The maximal CSV path is available publicly and totals 4, while the other CSV paths need private layout and add 20. Unknown other strings produce the empty path. `changeWork` sums the stipulated units. No timing measurement or actual edit execution is involved. + +`CanChange` requires a nonempty path, membership of the particular maintainer in the activity, and possession of all listed knowledge/tool labels. `ContinuingCapability` checks the path for **every listed participant**, without requiring that participant list be nonempty. `ActivityScope` closes that empty-list loophole in `PriorityConditions`, but the standalone capability predicate does not. The examples prove that successors/agents have the evolvable revision path but not the private simple one. An artifact merely returns its input and emits an execute action; maintainers are defined to emit propose actions. The absence of a proposal from that artifact is true by its definition, not a theorem about all software agency. + +`CredibleDirection {Ground : Type}` is existence, via `List.any`, of one ground accepted by the supplied Boolean articulation and support functions. The concrete adapter checks nonempty strings/lists and specific values: positive release number plus list membership; queue/tenant-config-reload strings; queue history with at least two equal recorded directions; or the exact reviewed-migration-requirement string. Thus “credible” is a defined classification of supplied records, not verification of an actual plan, service mechanism or history. `WarrantedAccommodation` additionally requires positive gain and investment ≤ gain, but those numbers are arguments, not derived predictions. The examples include one implemented variant, revised forecast deletion, unsupported quantum/CSV direction, and the distinction between nine supported directions and ten. + +The candidates' complexity values are 1,3,30. Their seven costs are 1 each for simple, respectively 3/4/2/4/2/2/8 for evolvable, and 40 each for maximal. `CostVector` is only a mapping; `CostLimits` supplies capacities and objective strings. Normal capacities are all 12. `ConcreteThreat ctx c burden` means cost exceeds the simple baseline, exceeds the context capacity, and the objective string is nonempty. `HasThreat` scans the seven burdens. `JustifiedDeparture` requires an explicitly selected burden and that predicate at that burden. A string's nonemptiness does not independently justify its objective, and no validation binds these cost constants to real expense. + +Engineering requirements demand an order output **at one sample input**, an unsafe-operation count, a latency number, and a retention number. Each default profile uses the same deduplication behavior on [2,1,2] and the constants 0,5,30. `Meets` checks [2,1] if order is required, and three numeric inequalities. It does not prove general order preservation, real safety, measured latency, or actual retention; context profiles can be arbitrarily supplied. + +`PriorityConditions` conjoins continuing/scope conditions, both simple/evolvable profiles meeting requirements, credibility of design revision, evolvable continuing capability for that direction, lower revision work, and larger simple-to-evolvable complexity. `EvolutionPriority ctx chosen` is the conditional: **if all those conditions, chosen equals evolvable or there is justified departure for evolvable**. It is a stipulated normative rule. `priorityWhenApplicable` takes that rule, applicability, and absence of departure as premises; it eliminates the departure disjunct, then substitutes the chosen candidate into the complexity comparison already in applicability. It does not derive the rule from those conditions. + +The current concrete context satisfies the applicability conditions and has no threat/departure. Therefore choosing simple violates this stipulated rule. Lowering a selected burden's capacity to 1 establishes departure and allows simple. Altering any of four evolvable profile requirements blocks applicability. When applicability is false, the conditional rule is vacuously true for every choice. `oneDimensionDoesNotEntailEveryDimension` uses equal addition work as a counterexample to a universal strict improvement over all `Change` values. All these are finite computations or elementary implication/disjunction proofs, not evidence that the cost assignments or priority are uniquely warranted. + +## 6. Engineering evolution, contracts, structure and historical records + +`orderedUnique` uses list deduplication; `orderedRefactor` appends the empty list; `sortedUnique` first runs the supplied insertion sort then deduplicates. `transform` changes selected software-state fields for named changes, and leaves unknown other changes untouched. `evolutionBehavior` selects sorted output only for redrawing/design revision. There is no execution semantics connecting a transformed software state's fields to this separately assigned function. + +`PreservesOn {Input Output : Type} scope old new` universally requires equal outputs for all in-scope inputs. `contractPreservation` returns the premise `observations` unchanged: that premise is **already the complete universal preservation statement**, not a finite experiment. `changedObservationNotPreserved` refutes it at one specified in-scope counterexample. `PreservesFinite` instead tests exactly four list inputs. Observable contracts add a retry limit; retry is `attempts < maxAttempts`, tested at six attempts 0…5. Finite preservation of order and retry together is `PreservesContractFinite`. + +`affectedParties` uses the two fixed dependency records (consumer observes order, operator observes retry) and changes detected on those finite input lists. `RevisionDuties old new r` requires a deliberate flag, the new result at [2,1,2], inclusion of every computed affected party, and four fields equal to old/new retry limits. The arbitrary `procedure` string is not checked. It does not establish notification/consent, complete party enumeration, all-input behavior, or an independently approved procedure. `ContractChangeAccount` is finite preservation OR these revision duties. `contractRevisionObligations` assumes that account and failure of the first branch and projects the second branch. + +`EvolutionClaim` ties the same direction and maintainer to a path, contract account, presence of a contract-runner step, and treatment compatible with whether one output sample changes. It uses the fixed original contract and normal revision, not arbitrary user contracts. The redrawing example changes both sample order and retry count; missing the operator or recording the old limit incorrectly fails. `retiredBehavior` agrees on every finite contract input but differs at [99], explicitly refuting the inference from finite tests to universal preservation. Merely changing the procedure label still passes. + +`StructuralEvidence` binds direction, participants, touched component IDs, four test inputs and their before/after results, summed work, count of contract-runner steps, and natural-number subtraction for gain. `StructuralAccount` checks those exact equalities. In the constructed evidence these are definitionally or computationally true; it is not independently collected telemetry. `propagation` erases duplicate component IDs. A static batch function hardcodes size 10; the live function uses its size argument, so 21 items produce 3 versus 5 at size 5. Natural division and subtraction are total, with no positivity precondition on the batch size; claims should not silently extend this to a physically meaningful size-zero procedure. + +Engineering designs have separate metadata, behavior, path functions, components, boundaries and batch assumptions. Same metadata and signature coexist with different output or change capability. All eight module assumptions can need revision for a new size. `introduceBoundary` appends a real component, a boundary record, and a public-contract step to each nonempty path while preserving behavior by `xs ++ []`; the example grows revision work from 17 to 18. These countermodels show that those structural counts/labels alone do not entail improvement in the defined capability/cost functions; they do not claim every boundary is harmful. + +`HistoricalEvidence` and `RevisionAccountAgainst history record` bind the record to the same software string, old state, prior prediction and observed result; require increasing time, exact current-state recording, some enumerated material change when choice changes, a report Boolean equal to predicted = actual, and criticism-list coverage of the supplied considered changes. The fixed history records old state and 3 versus 5. Tampering either old state, prediction, observation or software string is rejected **relative to this fixed history**. A generic caller supplies `history`; the interface does not prove that an external archive is authentic. It does not require considered changes to be nonempty, actual substantive criticism, or a particular new choice. A stable choice can pass even when other facts change. `failedHistoryNotRewritten` simply extracts the equality constraint and uses the supplied failure premise. + +`RetentionJustified` says every supplied alternative lacks the adapter's support OR a departure is justified; an empty alternatives list vacuously satisfies its first branch. The examples retain against an unsupported quantum option or a threatening migration. Three listed revisions and three agreeing reviewers do not fix the batch counterexample; prior observations at size 10 do not cover size 5. + +`revisionFor ctx chosen` links software, forecast from that context's ground lists, maintenance, participants, chosen migration cost, capacity and choice into the current revision state, while keeping the fixed old history. The identity theorem checks those ties for the concrete context. `DomainSatisfied` bundles scope, the conditional priority rule, credible design revision, validity of a selected departure, successor design-revision capability, structural account, contract account, and revision account. It **does not separately require `Meets` or `PriorityConditions`**. A checked supplemental probe supplies an unsafe evolvable profile that fails `Meets` yet still satisfies `DomainSatisfied`; the requirements occur in the conditional priority antecedent. This does not invalidate the final concrete witness, which separately includes the original context and `PriorityConditions`. + +## 7. Engineering value and self-application adapters + +`CoreCommitment` enumerates five labels. `coreAdopted` returns true for each by definition. `reasonFor` attaches one concrete reason object per label; `ReasonRelevant` checks specific plan membership, unequal list outputs, batch equalities/counterexamples or complexity-budget inequalities. These are more than matching labels, but the finite example and chosen objective still determine their significance. + +`governancePosition principle` has Boolean positions/outcomes, adopted true, and selection constantly true for every candidate. It starts and limits to complexity ≤3; uses a singleton relevant reason; values a true result of `safeguardExperiment`; and supplies a fixed nonempty criticism string. Enabling that experiment permits the planned direction, refuses incompatible order demands, includes the known failing self-test point, restricts licensed sizes to 10, or selects within budget, depending on the principle. Disabling is **defined** to drop directions, permit conflicting demands, omit the counterexample, license size 5, or select maximal. The enabled and disabled theorems evaluate these chosen branches. They do not compare every possible way of adopting or declining a principle. The governance commitment is true even at simple; procedure support under this construction does not impose evolution priority. + +`selectionPosition adopted` uses candidate-valued positions with `selected = id`; its commitment at a world candidate is exactly candidate = adopted. Its outcome ignores the world and returns adopted candidate complexity and design-revision work. Starting assumptions already fix candidate = adopted. The simple position's objective is complexity ≤1; the evolvable position's objective is revision work ≤6. The reason lists supply the matching numerical pairs (1,17) or (3,6), and constraints require complexity ≤12. `selectionValueProcedure` assumes adopted is simple OR evolvable, then checks each objective under that case's **different** preference. `selectionGrounded` wraps this procedure. These theorems establish neither a preference-independent winner nor a proof that the differing objectives are morally or philosophically valid. + +`Reflection.Model W Object` is an abstract adapter supplying objects, contracts, requested cases, reasons, a basis proposition, applicability predicates, and a recorded outcome function. A target carries owner/object/phase. Input is constructed for the exact target object and phase; self means equal owner and object membership. Two generated rules have distinct local keys 0/1. `performed` requires exact self/input equality and an activity whose key and recorded outcome match. `follows` universally requires the interpretation for each activity/object/phase that is a member and applicable. `recordedReflexivity` **assumes `m.follows`**; it packages this assumption using key distinction and owner substitution. It is not an independent procedure for establishing a model's truthfulness. + +`Reflection.evaluate` first checks every tested case, then every requested case, using one supplied Boolean test. If all tested pass and all requested pass, it returns supportedWithinScope; if tested pass but a requested one fails, counterexample; otherwise noSupportingSample. It does not read `Contract.claimed`, reasons, basis or target. Empty tested/requested lists yield supportedWithinScope even for the always-false test. `interpret` separately requires nonempty reasons and `basis`; generation's result must be exactly requested tests/requested scope, while assessment must equal evaluation. This separation matters: a passing raw evaluation alone is not a proof of follows or complete reflection. Reasons are still strings with no semantic relation beyond the separately supplied basis. + +The concrete `selfModel chosen` uses world/test points `Candidate × Nat` and review objects activity, five commitments, priority (only when chosen is evolvable), and evolutionMethod. Tested cases use `(chosen,10)`. Formation/application request that case; revision also requests `(chosen,5)`. Basis propositions check actual activity requirements, specific relevant reasons, applicability/no-threat for priority, or the known batch equality/difference. Generation applies at formation/revision; assessment applies at all phases. `statedReview` has a counterexample precisely for evolutionMethod/revision and support elsewhere. `currentSelfRecords` assumes chosen is simple or evolvable and checks all finite objects/phases/activities against definitions. `currentSelfApplication` then applies the generic adapter. For the simple witness, the priority object is omitted, so this does not establish that simple passed the priority rule. `actualSelfCriticism` computes 3 versus 5 and confirms the recorded counterexample while generation still emits the wider proposed cases; generation does not certify them. + +## 8. Engineering integration, same objects, and the final contrast + +`sharedContext` is exactly the concrete continuing context. `maintainedOutput chosen n` runs the chosen deduplication behavior on singleton [n] and returns its head; it is identically n for **every** candidate. `chosenImplementation` packages that, complexity as cost, and identity explanation/trace. `chosenRequirements` only asks identity for all naturals and budget 12. `implementationReasoned` takes complexity≤budget and proves feasibility plus the output reason. It does not establish arbitrary-list order preservation or priority; those are different contracts elsewhere. + +`capabilityOutput` maps input 0 to original maintainer, 1 to successor, and every other natural to agent; it returns the predefined revision path cost when that maintainer has the knowledge/tools, otherwise zero. Thus simple returns 17/0/0 and evolvable 6/6/6. `engineeringProcess chosen` contains exactly that output and no explanation. `engineeringCapability chosen process` requires that process output equal **the very same `capabilityOutput chosen`** for every input. `engineeringCapabilityGrounded` holds for all candidates by reflexivity and the process singleton wrapper, including maximal. It is source-faithful to this code to call it an exact output-function contract, but not an independent certificate of engineering success or any positive capability threshold. The contrast theorem separately computes useful differences. + +The budget record is a test of the very predicate complexity≤3 with observed true. `budgetObservationMeaning` proves compatibility iff that same predicate. Its empirical facet establishes exactly that threshold, with true scope/uncertainty and an evolvable witness. The inferential facet assumes the threshold and derives complexity≤12 via transitivity, with another concrete witness. The scope account relates candidate pairs by equality of their deduplication result at [2,1,2], which holds because all default behaviors are equal. The limit theorem refutes the stronger threshold≤1 using evolvable. None of these is an externally measured future-performance forecast. + +`engineeringPolicy` values expansion, marks every version-1 form current, and supplies a higher version with generation adopted. The proof chooses version+1. `OwnFact` ranges over selected candidate, requirements, capacity, output-function capability, the fixed batch contrast, revision account, generativity, reflection and the five adoption facts. `ownFactClaim chosen` gives each its actual predicate. `actualOwnFact` proves each fact for simple/evolvable by definition or earlier checks. `ownFactPremises chosen` is exactly candidate = chosen. `actualOwnFactGrounded` substitutes this identity and invokes those actual proofs, not merely the fact's name. + +`ownTheory chosen` contains exactly predicates equal to some own fact. It includes selected and grounds-adoption predicates; the review list includes actual activity and grounds commitment. `comparisonContext chosen` uses the same identity premises, same fact interpretation and complexity≤3 scope. `currentAdmissible` explicitly supplies chosen as model of every held fact, assumptions and scope. `currentConsistency` obtains consistency from this witness and reports true for a move from revision 0 to 1; true satisfies the one-way reporting predicate. The before candidate is evolvable, but the after may be either ordinary candidate. This is a concrete consistent model with a genuine same-candidate link throughout, not arbitrary independent Boolean assignments for all requirements. + +`Inherited ctx chosen` is a **record of proof obligations**, including `ctx = sharedContext`, generation, the snapshot contract, reflection, value grounds for all five commitments, choice-value grounds, empirical/inferential/scope/capability evidence, implementation choice, grounds for every own fact, compatibility at the chosen candidate, actual selection commitment, and current theory satisfaction. `inheritedCurrent` supplies this record for simple/evolvable using the proofs above. In the generic record all substantive fields mention shared or fixed objects; the equality field is therefore material. The theorem `inheritedMutualApplication` simply projects six record fields. It does not prove them from fewer principles or show the encoded principles mutually entail one another. + +`priorityRemainsReflexive` additionally assumes domain satisfaction, applicability, and no departure; derives chosen=evolvable by the stipulated priority rule; then supplies priority-object membership and reuses inherited reflection/value fields. It does not prove the priority rule from inheritance. The finite cases show the priority object gets supportedWithinScope for evolvable while the separate evolution method still gets a revision counterexample. + +The final `Engineering.jointWitness` existentially selects exactly sharedContext and evolvable, with inheritance, domain satisfaction, applicability, absence of threat, strictly larger complexity than simple, successor/agent path availability, nonempty own theory/review evidence, and admissibility all tied to that context/candidate. The final `inheritedDoesNotEntailPriority` selects exactly sharedContext and simple. It proves inheritance, applicability, continuing/non-bounded lifecycle, no threat/departure, both candidates meeting requirements, credible revision, evolvable successor/agent capability, lower evolvable revision work, lower simple complexity, simple's own value procedure/commitment, and failure of EvolutionPriority for simple. This is a valid explicit counterexample **for these defined predicates and the differing selection objectives**. It does not prove that some unspecified external inheritance package permits the same counterexample, nor does it show priority false for evolvable. The intended external conclusion remains unevaluated until a separately preserved comparison stage. + +## 9. Verification record and boundaries + +- `code-hashes.json` binds all thirteen source/import files plus lakefile and toolchain before explanation. The code is the comment-stripped supplied input, not a claim about any unseen original file hash. +- `build.log`, `toolchain.log`, `DeclarationAudit.lean`, `declaration-axiom-audit.log`, `axiom-summary.json` record actual checks. All 786 named declarations and 269 theorem statements resolved. The first audit attempt used an unsupported printing option; its failed log is retained separately, and the corrected complete audit passed. No proof input changed. +- `SemanticProbes.lean` and `semantic-probes.log` check the empty-registry case, empty-question consistency, contradictory-record vacuity, empty-test evaluation, all-candidate tautological capability contract, and the standalone domain/failed-requirement case. A first probe syntax error was corrected only in the temporary audit file; its failed log is preserved. +- `concerns.json` lists code-derived limitations and their mitigations, without assigning source-fidelity verdicts. Concrete examples were verified, while interpretation of hardcoded costs, scope, strings and objectives remains outside the kernel result. + +The exact source inventory below is intentionally exhaustive. It makes every input declaration and its line interval available without treating a repeated aggregate or packaging proof as new evidence. + +## Appendix: exact code and declaration locations + +Each excerpt is copied verbatim from the hashed supplied file. The line interval identifies the declaration plus following structural whitespace up to the next explicit declaration; source comments were already absent in the supplied input. Full elaborated types and transitive axioms are in the audit log. + +### CoreReader/Adopted.lean + +#### `CoreReader.Adopted.AssessmentTask` + +`CoreReader/Adopted.lean:11–15`; inductive. + +```lean +inductive AssessmentTask (W : Type) where + | empirical (records : List (Record W)) (scope claim uncertainty : Claim W) + | inferential (assumptions : Theory W) (claim : Claim W) + | value (position : ValuePosition W) + +``` + +#### `CoreReader.Adopted.taskOfFacet` + +`CoreReader/Adopted.lean:16–26`; def. + +```lean +def taskOfFacet {W : Type} : Facet W → AssessmentTask W + | .empirical records scope claim uncertainty => .empirical records scope claim uncertainty + | .inferential assumptions claim => .inferential assumptions claim + | .value position => .value position + + + + + + + +``` + +#### `CoreReader.Adopted.NatureAppropriate` + +`CoreReader/Adopted.lean:27–37`; def. + +```lean +def NatureAppropriate {W : Type} : AssessmentTask W → Facet W → Prop + | .empirical records scope claim uncertainty, .empirical actualRecords actualScope conclusion actualUncertainty => + actualRecords = records ∧ actualScope = scope ∧ conclusion = claim ∧ actualUncertainty = uncertainty + | .empirical records scope claim uncertainty, .inferential assumptions conclusion => + assumptions = singleton (fun w => Compatible records w ∧ scope w) ∧ + conclusion = claim ∧ Supports records uncertainty + | .inferential assumptions claim, .inferential actualAssumptions conclusion => + actualAssumptions = assumptions ∧ conclusion = claim + | .value position, .value actualPosition => actualPosition = position + | _, _ => False + +``` + +#### `CoreReader.Adopted.taskOfFacetAppropriate` + +`CoreReader/Adopted.lean:38–47`; theorem. + +```lean +theorem taskOfFacetAppropriate {W : Type} (f : Facet W) : NatureAppropriate (taskOfFacet f) f := by + cases f with + | empirical _ _ _ _ => exact ⟨rfl, rfl, rfl, rfl⟩ + | inferential _ _ => exact ⟨rfl, rfl⟩ + | value _ => rfl + + + + + +``` + +#### `CoreReader.Adopted.Grounds012` + +`CoreReader/Adopted.lean:48–57`; def. + +```lean +def Grounds012 {W : Type} (claim : Claim W) + (articulations : Facet W → Articulation W) (facets : List (Facet W)) + (task : AssessmentTask W) : Prop := + facets ≠ [] ∧ ∀ facet ∈ facets, + facet.claim = claim ∧ Articulated (articulations facet) ∧ + FacetArticulated (articulations facet) facet ∧ FacetDischarged facet ∧ + NatureAppropriate task facet + + + +``` + +#### `CoreReader.Adopted.grounds012Singleton` + +`CoreReader/Adopted.lean:58–64`; theorem. + +```lean +theorem grounds012Singleton {W : Type} (f : Facet W) (h : FacetDischarged f) : + Grounds012 f.claim canonicalArticulation [f] (taskOfFacet f) := by + refine ⟨by simp, ?_⟩ + intro facet hf + cases List.mem_singleton.mp hf + exact ⟨rfl, canonicalArticulated f h, canonicalFacetArticulated f, h, taskOfFacetAppropriate f⟩ + +``` + +#### `CoreReader.Adopted.generationSpecification` + +`CoreReader/Adopted.lean:65–68`; def. + +```lean +def generationSpecification (policy : Policy) : Prop := Generative policy + + + +``` + +#### `CoreReader.Adopted.consistencySpecification` + +`CoreReader/Adopted.lean:69–75`; def. + +```lean +def consistencySpecification {W Q : Type} (before after : Snapshot W Q) + (reported : Bool) : Prop := + Consistent after.held after.context ∧ TruthfulReport before after reported + + + + +``` + +#### `CoreReader.Adopted.ReflexiveRule` + +`CoreReader/Adopted.lean:76–82`; structure. + +```lean +structure ReflexiveRule (T I O : Type) where + key : PrincipleKey + activity : Activity + applicable : T → Prop + input : T → I + meaning : I → O → Prop + +``` + +#### `CoreReader.Adopted.reflexivitySpecification` + +`CoreReader/Adopted.lean:83–89`; def. + +```lean +def reflexivitySpecification {T I O : Type} (rules : List (ReflexiveRule T I O)) + (isSelf : T → Prop) (performed : PrincipleKey → T → I → O → Prop) : Prop := + (∀ p ∈ rules, ∀ q ∈ rules, p.key = q.key → p = q) ∧ + ∀ rule ∈ rules, ∀ target, isSelf target → rule.applicable target → + ∃ outcome, performed rule.key target (rule.input target) outcome ∧ + rule.meaning (rule.input target) outcome + +``` + +#### `CoreReader.Adopted.legacyRule` + +`CoreReader/Adopted.lean:90–93`; def. + +```lean +def legacyRule (p : Principle) : ReflexiveRule Subject Inquiry WorkOutcome := + ⟨p.key, p.activity, p.applicable, p.inquiry, + fun inquiry outcome => p.meaning inquiry (p.reasons inquiry.target) (p.limits inquiry.target) outcome⟩ + +``` + +#### `CoreReader.Adopted.legacyPerformed` + +`CoreReader/Adopted.lean:94–99`; def. + +```lean +def legacyPerformed (rules : List Principle) (records : List WorkRecord) + (key : PrincipleKey) (target : Subject) (input : Inquiry) (outcome : WorkOutcome) : Prop := + ∃ p ∈ rules, ∃ record ∈ records, + p.key = key ∧ ValidApplication rules p target record ∧ + record.inquiry = input ∧ record.outcome = outcome + +``` + +#### `CoreReader.Adopted.legacyReflexivity` + +`CoreReader/Adopted.lean:100–121`; theorem. + +```lean +theorem legacyReflexivity (owner : Nat) (rules : List Principle) (records : List WorkRecord) + (h : Reflexive owner rules records) : + reflexivitySpecification (rules.map legacyRule) (fun s => s.owner = owner) + (legacyPerformed rules records) := by + constructor + · intro p hp q hq he + obtain ⟨a, ha, rfl⟩ := List.mem_map.mp hp + obtain ⟨b, hb, rfl⟩ := List.mem_map.mp hq + exact congrArg legacyRule (h.1 a ha b hb he) + · intro rule hr target ht happ + obtain ⟨p, hp, rfl⟩ := List.mem_map.mp hr + obtain ⟨record, hm, hv⟩ := h.2 p hp target ht happ + refine ⟨record.outcome, ⟨p, hp, record, hm, rfl, hv, hv.inquiryIdentity, rfl⟩, ?_⟩ + change p.meaning (p.inquiry target) (p.reasons (p.inquiry target).target) + (p.limits (p.inquiry target).target) record.outcome + have ti : (p.inquiry target).target = target := hv.inquiryIdentity ▸ hv.inquiryTarget + rw [ti] + rw [← hv.inquiryIdentity, ← hv.reasonsIdentity, ← hv.limitsIdentity] + exact hv.followsMeaning + + + +``` + +#### `CoreReader.Adopted.empiricalSpecification` + +`CoreReader/Adopted.lean:122–126`; def. + +```lean +def empiricalSpecification {W : Type} (records : List (Record W)) + (scope claim uncertainty : Claim W) : Prop := + Grounds012 claim canonicalArticulation [.empirical records scope claim uncertainty] + (.empirical records scope claim uncertainty) + +``` + +#### `CoreReader.Adopted.inferentialSpecification` + +`CoreReader/Adopted.lean:127–129`; def. + +```lean +def inferentialSpecification {W : Type} (assumptions : Theory W) (claim : Claim W) : Prop := + Grounds012 claim canonicalArticulation [.inferential assumptions claim] (.inferential assumptions claim) + +``` + +#### `CoreReader.Adopted.valueSpecification` + +`CoreReader/Adopted.lean:130–135`; def. + +```lean +def valueSpecification {W : Type} (position : ValuePosition W) : Prop := + Grounds012 position.commitment canonicalArticulation [.value position] (.value position) + + + + +``` + +#### `CoreReader.Adopted.AssessmentMethod` + +`CoreReader/Adopted.lean:136–137`; inductive. + +```lean +inductive AssessmentMethod | measurement | repetition | framework + deriving DecidableEq +``` + +#### `CoreReader.Adopted.ScopeAccount` + +`CoreReader/Adopted.lean:138–147`; structure. + +```lean +structure ScopeAccount (W : Type) where + claim : Claim W + conditions : Claim W + observationScope : Claim W + relevant : W → W → Prop + compared : W → W → Prop + used : AssessmentMethod → Prop + role : AssessmentMethod → String + explains : AssessmentMethod → String → Claim W → Claim W → Prop + +``` + +#### `CoreReader.Adopted.scopeSpecification` + +`CoreReader/Adopted.lean:148–155`; def. + +```lean +def scopeSpecification {W : Type} (account : ScopeAccount W) : Prop := + (∀ a b, account.compared a b → account.conditions a ∧ account.conditions b ∧ + account.observationScope a ∧ account.observationScope b ∧ account.relevant a b) ∧ + ∀ method, account.used method → account.role method ≠ "" ∧ + account.explains method (account.role method) account.claim account.conditions + + + +``` + +#### `CoreReader.Adopted.capabilitySpecification` + +`CoreReader/Adopted.lean:156–159`; def. + +```lean +def capabilitySpecification (assessed : Process) (contract : Claim Process) : Prop := + Grounds012 contract canonicalArticulation [processContractFacet assessed contract] + (.inferential (processScope assessed) contract) + +``` + +#### `CoreReader.Adopted.choiceSpecification` + +`CoreReader/Adopted.lean:160–164`; def. + +```lean +def choiceSpecification (requirements : Requirements) (implementation : Implementation) + (reasons : List Reason) : Prop := JustifiedChoice requirements implementation reasons + + + +``` + +#### `CoreReader.Adopted.collaborativeRevision` + +`CoreReader/Adopted.lean:165–167`; def. + +```lean +def collaborativeRevision (resources : ExternalResources) : State := + if resources.collaborator.isSome then extendedState else baseState + +``` + +#### `CoreReader.Adopted.collaborativeProgress` + +`CoreReader/Adopted.lean:168–179`; theorem. + +```lean +theorem collaborativeProgress : + generationSpecification openPolicy ∧ + Expanded baseState (collaborativeRevision availableResources) ∧ + ¬ Expanded baseState (collaborativeRevision { availableResources with collaborator := none }) ∧ + assistedExecution ⟨none, none, none⟩ = none := by + refine ⟨⟨Or.inl rfl, fun _ _ => trivial⟩, ?_, ?_, rfl⟩ + · exact Or.inr ⟨.successor, by simp [collaborativeRevision, availableResources, extendedState], + by simp [baseState]⟩ + · simp [collaborativeRevision, Expanded, baseState] + + + +``` + +#### `CoreReader.Adopted.consistencyConsequences` + +`CoreReader/Adopted.lean:180–183`; theorem. + +```lean +theorem consistencyConsequences {W Q : Type} (t : Theory W) (c : Context W Q) (q : Q) + (positive : Consequence t c q true) (negative : Consequence t c q false) : + ¬ Consistent t c := conflictRequiresChange t c q positive negative + +``` + +#### `CoreReader.Adopted.broadBoolContext` + +`CoreReader/Adopted.lean:184–185`; def. + +```lean +def broadBoolContext : Context Bool Unit := ⟨emptyTheory, onQuestion, fun _ => True⟩ + +``` + +#### `CoreReader.Adopted.sliceConsistency` + +`CoreReader/Adopted.lean:186–200`; theorem. + +```lean +theorem sliceConsistency : + (∀ time, Consistent (revisionSlice time) broadBoolContext) ∧ + ¬ Consistent (union (revisionSlice 0) (revisionSlice 1)) broadBoolContext := by + constructor + · intro time + apply consequenceConsistency + exact ⟨time == 0, (modelsSingleton _ _).2 rfl, (by intro p hp; cases hp), trivial⟩ + · apply conflictRequiresChange _ _ () + · intro w h + change w = true + exact (modelsSingleton (fun w : Bool => w = true) w).1 ((modelsUnion _ _ _).1 h.1).1 + · intro w h ht + have hn := (modelsSingleton _ _).1 ((modelsUnion _ _ _).1 h.1).2 + cases ht.symm.trans hn + +``` + +#### `CoreReader.Adopted.explicitlyConsistentLimits` + +`CoreReader/Adopted.lean:201–213`; theorem. + +```lean +theorem explicitlyConsistentLimits : + Consistent (singleton (fun w : Bool => w = true)) broadBoolContext ∧ + ¬ Models (singleton (fun w : Bool => w = true)) false ∧ + Consistent (emptyTheory : Theory Bool) broadBoolContext ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true) := by + refine ⟨?_, consistentFalse.2, ?_, consistentIncomplete.2.1⟩ + · exact consequenceConsistency _ _ ⟨true, (modelsSingleton _ _).2 rfl, + (by intro p hp; cases hp), trivial⟩ + · exact consequenceConsistency _ _ ⟨true, (by intro p hp; cases hp), + (by intro p hp; cases hp), trivial⟩ + + + +``` + +#### `CoreReader.Adopted.localFacet012` + +`CoreReader/Adopted.lean:214–215`; def. + +```lean +def localFacet012 : Facet (Nat → Bool) := + .empirical [zeroRecord] (fun _ => True) (fun f => f 0 = true) (fun _ => True) +``` + +#### `CoreReader.Adopted.globalFacet012` + +`CoreReader/Adopted.lean:216–217`; def. + +```lean +def globalFacet012 : Facet (Nat → Bool) := + .empirical [zeroRecord] (fun _ => True) allTrue (fun _ => True) +``` + +#### `CoreReader.Adopted.strongFacet012` + +`CoreReader/Adopted.lean:218–220`; def. + +```lean +def strongFacet012 : Facet (Nat → Bool) := + .empirical [zeroRecord] (fun _ => True) (fun f => f 0 = true ∧ f 1 = true) (fun _ => True) + +``` + +#### `CoreReader.Adopted.localFacetChecked012` + +`CoreReader/Adopted.lean:221–224`; theorem. + +```lean +theorem localFacetChecked012 : FacetDischarged localFacet012 := + ⟨⟨localGenerator 0, (zeroCompatible _).2 rfl, trivial⟩, + (fun f hf _ => (zeroCompatible f).1 hf), fun _ _ => trivial⟩ + +``` + +#### `CoreReader.Adopted.scopeStrength012` + +`CoreReader/Adopted.lean:225–242`; theorem. + +```lean +theorem scopeStrength012 : + Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧ + Articulated (canonicalArticulation globalFacet012) ∧ + ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧ + ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012) := by + refine ⟨grounds012Singleton _ localFacetChecked012, ⟨by simp [canonicalArticulation, globalFacet012], + by simp [canonicalArticulation, globalFacet012]⟩, ?_, ?_⟩ + · intro h + have checked := (h.2 globalFacet012 (by simp)).2.2.2.1 + have bad := checked.2.1 (localGenerator 0) ((zeroCompatible _).2 rfl) trivial 1 + cases bad + · intro h + have checked := (h.2 strongFacet012 (by simp)).2.2.2.1 + have bad := (checked.2.1 (localGenerator 0) ((zeroCompatible _).2 rfl) trivial).2 + cases bad + + + +``` + +#### `CoreReader.Adopted.uncertainFacet012` + +`CoreReader/Adopted.lean:243–246`; def. + +```lean +def uncertainFacet012 : Facet (Bool × Bool) := + .empirical [temperatureRecord, temperatureRecord] (fun _ => True) + (fun w => w.1 = true) (fun w => w.2 = true ∨ w.2 = false) + +``` + +#### `CoreReader.Adopted.uncertainSupported012` + +`CoreReader/Adopted.lean:247–258`; theorem. + +```lean +theorem uncertainSupported012 : + empiricalSpecification [temperatureRecord, temperatureRecord] (fun _ => True) + (fun w => w.1 = true) (fun w => w.2 = true ∨ w.2 = false) ∧ + Compatible [temperatureRecord, temperatureRecord] (true,true) ∧ + Compatible [temperatureRecord, temperatureRecord] (true,false) := by + refine ⟨grounds012Singleton uncertainFacet012 ?_, temperatureCompatible true, temperatureCompatible false⟩ + refine ⟨⟨(true,false), temperatureCompatible false, trivial⟩, ?_, ?_⟩ + · intro w hw _; exact hw temperatureRecord (by simp) + · intro w _; cases w.2 <;> simp + + + +``` + +#### `CoreReader.Adopted.InferenceExamined` + +`CoreReader/Adopted.lean:259–261`; def. + +```lean +def InferenceExamined {W : Type} (premises : Theory W) (conclusion : Claim W) + (accepted : Bool) : Prop := accepted = true ↔ Entails premises conclusion + +``` + +#### `CoreReader.Adopted.inferenceChecked012` + +`CoreReader/Adopted.lean:262–272`; theorem. + +```lean +theorem inferenceChecked012 : + inferentialSpecification (singleton (fun n : Nat => n = 2)) (fun n => n + 1 = 3) ∧ + InferenceExamined (emptyTheory : Theory Bool) (fun w => w = true) false ∧ + Models (emptyTheory : Theory Bool) false ∧ ¬ ((fun w : Bool => w = true) false) := by + refine ⟨grounds012Singleton arithmeticFacet noUniversalChain.1, ?_, (by intro p hp; cases hp), by decide⟩ + constructor + · intro h; cases h + · intro h; exact False.elim (consistentIncomplete.2.1 h) + + + +``` + +#### `CoreReader.Adopted.closedPosition012` + +`CoreReader/Adopted.lean:273–274`; def. + +```lean +def closedPosition012 : ValuePosition Bool := { switchPosition with response := fun _ => none } + +``` + +#### `CoreReader.Adopted.closedCriticism012` + +`CoreReader/Adopted.lean:275–279`; theorem. + +```lean +theorem closedCriticism012 : ¬ ValueProcedure closedPosition012 := by + intro h + obtain ⟨answer, ha, _⟩ := h.2.2.2 false trivial rfl + cases ha + +``` + +#### `CoreReader.Adopted.valueFulfilled012` + +`CoreReader/Adopted.lean:280–284`; theorem. + +```lean +theorem valueFulfilled012 : valueSpecification switchPosition := + grounds012Singleton _ switchValueProcedure + + + +``` + +#### `CoreReader.Adopted.ClaimNoStronger` + +`CoreReader/Adopted.lean:285–286`; def. + +```lean +def ClaimNoStronger {W : Type} (weaker stronger : Claim W) : Prop := ∀ w, stronger w → weaker w + +``` + +#### `CoreReader.Adopted.qualitativeProportionality012` + +`CoreReader/Adopted.lean:287–295`; theorem. + +```lean +theorem qualitativeProportionality012 : + ClaimNoStronger (fun f : Nat → Bool => f 0 = true) allTrue ∧ + ¬ ClaimNoStronger allTrue (fun f : Nat → Bool => f 0 = true) ∧ + valueSpecification switchPosition := by + refine ⟨fun _ h => h 0, ?_, valueFulfilled012⟩ + intro h + have bad := h (localGenerator 0) rfl 1 + cases bad + +``` + +#### `CoreReader.Adopted.scopeRole012` + +`CoreReader/Adopted.lean:296–300`; def. + +```lean +def scopeRole012 : AssessmentMethod → String + | .measurement => "identify the output at the observed input zero" + | .repetition => "check the same local conclusion against repeated input-zero observations" + | .framework => "compare only the declared input; keep broader claims separate" + +``` + +#### `CoreReader.Adopted.scopeRoleContent012` + +`CoreReader/Adopted.lean:301–305`; def. + +```lean +def scopeRoleContent012 : AssessmentMethod → Prop + | .measurement => Supports [zeroRecord] (fun f => f 0 = true) + | .repetition => Supports [zeroRecord, zeroRecord] (fun f => f 0 = true) + | .framework => ¬ Supports [zeroRecord] allTrue + +``` + +#### `CoreReader.Adopted.localScopeAccount012` + +`CoreReader/Adopted.lean:306–317`; def. + +```lean +def localScopeAccount012 : ScopeAccount Nat where + claim n := (localGenerator 0) n = true + conditions _ := True + observationScope n := n = 0 + relevant a b := a = b + compared a b := a = 0 ∧ b = 0 + used _ := True + role := scopeRole012 + explains method text claim conditions := + text = scopeRole012 method ∧ claim = (fun n => localGenerator 0 n = true) ∧ + conditions = (fun _ => True) ∧ scopeRoleContent012 method + +``` + +#### `CoreReader.Adopted.scopeFulfilled012` + +`CoreReader/Adopted.lean:318–329`; theorem. + +```lean +theorem scopeFulfilled012 : scopeSpecification localScopeAccount012 := by + constructor + · intro a b h + exact ⟨trivial, trivial, h.1, h.2, h.1.trans h.2.symm⟩ + · intro method _ + refine ⟨?_, rfl, rfl, rfl, ?_⟩ + · cases method <;> decide + · cases method with + | measurement => exact singleObservation.2.2.1 + | repetition => intro f hf; exact hf zeroRecord (by simp) + | framework => exact singleObservation.2.2.2 + +``` + +#### `CoreReader.Adopted.capabilityFulfilled012` + +`CoreReader/Adopted.lean:330–343`; theorem. + +```lean +theorem capabilityFulfilled012 : + capabilitySpecification outputOnlyProcess OutputContract ∧ + capabilitySpecification explainedProcess FullProcessContract ∧ + (∃ certificate : ExternalCertificate outputOnlyProcess, + certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧ + ¬ ExplanationContract outputOnlyProcess := by + refine ⟨grounds012Singleton _ (processContractDischarged _ _ outputCorrectByEvaluation), + grounds012Singleton _ (processContractDischarged _ _ ?_), + ⟨externalOutputCertificate, externalOutputCertificate.distinctParticipants, + externalOutputCertificate.outputCorrect⟩, outputOnlyNoExplanation⟩ + exact ⟨fun _ => rfl, .doubleInput, rfl, fun _ => rfl⟩ + + + +``` + +#### `CoreReader.Adopted.OwnCapability012` + +`CoreReader/Adopted.lean:344–346`; def. + +```lean +def OwnCapability012 (owner claimant : Nat) (process : Process) (contract : Claim Process) : Prop := + owner = claimant ∧ capabilitySpecification process contract + +``` + +#### `CoreReader.Adopted.ownCapability012` + +`CoreReader/Adopted.lean:347–352`; theorem. + +```lean +theorem ownCapability012 : OwnCapability012 7 7 outputOnlyProcess OutputContract := + ⟨rfl, capabilityFulfilled012.1⟩ + + + + +``` + +#### `CoreReader.Adopted.CompleteCharter012` + +`CoreReader/Adopted.lean:353–363`; def. + +```lean +def CompleteCharter012 (system : CoreReader.Integration.System) + (world : CoreReader.Integration.World) : Prop := + generationSpecification (system.policy world) ∧ + consistencySpecification + ⟨CoreReader.Integration.systemHeld system, CoreReader.Integration.systemContext system, 0⟩ + ⟨CoreReader.Integration.systemHeld system, CoreReader.Integration.systemContext system, 0⟩ false ∧ + reflexivitySpecification ((system.rules world).map legacyRule) (fun s => s.owner = system.owner) + (legacyPerformed (system.rules world) (system.work world)) ∧ + (system.policy world).current system.method.form ∧ + (system.policy world).current system.principleForm + +``` + +#### `CoreReader.Adopted.completeCharter012` + +`CoreReader/Adopted.lean:364–371`; theorem. + +```lean +theorem completeCharter012 : CompleteCharter012 CoreReader.Integration.actualSystem CoreReader.Integration.actual := by + refine ⟨CoreReader.Integration.charterChecked.1, + ⟨CoreReader.Integration.jointConsistent, ?_⟩, + legacyReflexivity 0 _ _ (completeOwnWork_reflexive 0), rfl, rfl⟩ + rintro (h | h) + · exact False.elim (h ⟨fun _ => Iff.rfl, fun _ => Iff.rfl, fun _ _ => Iff.rfl, fun _ => Iff.rfl⟩) + · exact False.elim (h rfl) + +``` + +#### `CoreReader.Adopted.charterWithoutGrounds012` + +`CoreReader/Adopted.lean:372–391`; theorem. + +```lean +theorem charterWithoutGrounds012 : + CompleteCharter012 CoreReader.Integration.actualSystem CoreReader.Integration.actual ∧ + Admissible CoreReader.Integration.held CoreReader.Integration.context CoreReader.Integration.actual ∧ + Compatible [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.actual ∧ + Articulated (canonicalArticulation CoreReader.Integration.unsupportedCapabilityFacet) ∧ + ¬ Supports [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.capability ∧ + ¬ Grounds012 CoreReader.Integration.capability canonicalArticulation + [CoreReader.Integration.unsupportedCapabilityFacet] + (taskOfFacet CoreReader.Integration.unsupportedCapabilityFacet) := by + refine ⟨completeCharter012, CoreReader.Integration.actualAdmissible, + (by intro r hr; cases List.mem_singleton.mp hr; rfl), + ⟨by simp [canonicalArticulation, CoreReader.Integration.unsupportedCapabilityFacet], + by simp [canonicalArticulation, CoreReader.Integration.unsupportedCapabilityFacet]⟩, + CoreReader.Integration.costDoesNotSupportOutput, ?_⟩ + intro h + have checked := (h.2 CoreReader.Integration.unsupportedCapabilityFacet (by simp)).2.2.2.1 + exact CoreReader.Integration.costDoesNotSupportOutput (fun w hw => checked.2.1 w hw trivial) + + + +``` + +#### `CoreReader.Adopted.groundsPermission012` + +`CoreReader/Adopted.lean:392–395`; def. + +```lean +def groundsPermission012 {W : Type} (enabled : Bool) (claim : Claim W) + (a : Facet W → Articulation W) (facets : List (Facet W)) (task : AssessmentTask W) : Prop := + if enabled then Grounds012 claim a facets task else True + +``` + +#### `CoreReader.Adopted.GroundsProvision012` + +`CoreReader/Adopted.lean:396–399`; def. + +```lean +def GroundsProvision012 (enabled : Bool) : Prop := + ∀ (claim : Claim (Nat → Bool)) a facets task, + groundsPermission012 enabled claim a facets task → Grounds012 claim a facets task + +``` + +#### `CoreReader.Adopted.groundsProvision012Meaning` + +`CoreReader/Adopted.lean:400–411`; theorem. + +```lean +theorem groundsProvision012Meaning (enabled : Bool) : GroundsProvision012 enabled ↔ enabled = true := by + cases enabled with + | true => exact ⟨fun _ => rfl, fun _ _ _ _ _ h => h⟩ + | false => + constructor + · intro h + exact False.elim (scopeStrength012.2.2.1 (h globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) trivial)) + · intro h; cases h + + + + +``` + +#### `CoreReader.Adopted.groundsExperimentTask012` + +`CoreReader/Adopted.lean:412–414`; def. + +```lean +def groundsExperimentTask012 : AssessmentTask (Nat → Bool) := + .empirical [zeroRecord] (fun _ => True) allTrue (fun _ => True) + +``` + +#### `CoreReader.Adopted.groundsExperiment012` + +`CoreReader/Adopted.lean:415–418`; def. + +```lean +noncomputable def groundsExperiment012 (enabled : Bool) : Bool := + @decide (groundsPermission012 enabled allTrue canonicalArticulation [globalFacet012] + groundsExperimentTask012) (Classical.propDecidable _) + +``` + +#### `CoreReader.Adopted.groundsPosition012` + +`CoreReader/Adopted.lean:419–432`; def. + +```lean +noncomputable def groundsPosition012 : ValuePosition Bool where + Position := Bool + Outcome := Bool + adopted := true + selected := id + outcome _ enabled := groundsExperiment012 enabled + objective accepted := accepted = false + constraints _ enabled := GroundsProvision012 enabled + starting := singleton (fun enabled => enabled = true) + reasons := [fun _ _ => Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0)] + limits _ := True + relevantCriticism _ := ¬ Supports [zeroRecord] allTrue + response _ := some "retain local support and reject the unsupported universal conclusion" + +``` + +#### `CoreReader.Adopted.groundsPosition012Checked` + +`CoreReader/Adopted.lean:433–451`; theorem. + +```lean +theorem groundsPosition012Checked : ValueProcedure groundsPosition012 := by + refine ⟨by simp [groundsPosition012], ?_, ?_, ?_⟩ + · refine ⟨true, (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩ + intro reason hr + cases List.mem_singleton.mp hr + refine ⟨(zeroCompatible _).2 rfl, ?_⟩ + intro h; have bad := h 1; cases bad + · intro w _ _ reasons + have counterworld := reasons _ (List.mem_singleton.mpr rfl) + change Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0) at counterworld + have unsupported : ¬ Grounds012 allTrue canonicalArticulation [globalFacet012] groundsExperimentTask012 := by + intro h + have discharged := (h.2 globalFacet012 (by simp)).2.2.2.1 + exact counterworld.2 (discharged.2.1 (localGenerator 0) counterworld.1 trivial) + refine ⟨?_, (groundsProvision012Meaning true).2 rfl⟩ + exact @decide_eq_false (groundsPermission012 true allTrue canonicalArticulation [globalFacet012] + groundsExperimentTask012) (Classical.propDecidable _) unsupported + · intro w _ _; exact ⟨_, rfl, by decide⟩ + +``` + +#### `CoreReader.Adopted.groundsRationaleExperiment012` + +`CoreReader/Adopted.lean:452–467`; theorem. + +```lean +theorem groundsRationaleExperiment012 : + Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0) ∧ + groundsExperiment012 true = false ∧ groundsExperiment012 false = true ∧ + groundsPosition012.outcome true true = groundsExperiment012 true ∧ + groundsPosition012.outcome true false = groundsExperiment012 false := by + refine ⟨(zeroCompatible _).2 rfl, ?_, ?_, ?_, rfl, rfl⟩ + · intro h; have bad := h 1; cases bad + · have actualReasons : ∀ reason ∈ groundsPosition012.reasons, reason true groundsPosition012.adopted := by + intro reason member + cases List.mem_singleton.mp member + refine ⟨(zeroCompatible _).2 rfl, ?_⟩ + intro h; have bad := h 1; cases bad + exact (groundsPosition012Checked.2.2.1 true ((modelsSingleton _ _).2 rfl) trivial actualReasons).1 + · exact @decide_eq_true (groundsPermission012 false allTrue canonicalArticulation [globalFacet012] + groundsExperimentTask012) (Classical.propDecidable _) trivial + +``` + +#### `CoreReader.Adopted.groundsOnGrounds012` + +`CoreReader/Adopted.lean:468–477`; theorem. + +```lean +theorem groundsOnGrounds012 : + Grounds012 (fun enabled => GroundsProvision012 enabled) canonicalArticulation [.value groundsPosition012] (.value groundsPosition012) ∧ + groundsPosition012.limits true ∧ groundsPosition012.relevantCriticism true := by + have same : (Facet.value groundsPosition012).claim = (fun enabled => GroundsProvision012 enabled) := by + funext enabled + exact propext (groundsProvision012Meaning enabled).symm + refine ⟨?_, trivial, singleObservation.2.2.2⟩ + rw [← same] + exact grounds012Singleton _ groundsPosition012Checked + +``` + +#### `CoreReader.Adopted.reflexiveTargets012` + +`CoreReader/Adopted.lean:478–492`; theorem. + +```lean +theorem reflexiveTargets012 : + reflexivitySpecification ((ownRules 0).map legacyRule) (fun s => s.owner = 0) + (legacyPerformed (ownRules 0) (completeOwnWork 0)) ∧ + (∀ phase, Performed (completeOwnWork 0) (.process 0 0 phase) .assessment) ∧ + Performed (completeOwnWork 0) (.system 0) .assessment ∧ + reflexivitySpecification ([applicationRule].map legacyRule) (fun s => s.owner = 0) + (legacyPerformed [applicationRule] applicationWork) ∧ + ¬ Performed applicationWork (.system 0) .assessment := by + refine ⟨legacyReflexivity 0 _ _ (completeOwnWork_reflexive 0), ?_, + ownAssessmentPerformed 0 (.system 0) (by simp [ownSubjects]), + legacyReflexivity 0 _ _ applicationWork_reflexive, (applicabilityRetained 0 [] []).2.2.2⟩ + intro phase + apply ownAssessmentPerformed + cases phase <;> simp [ownSubjects] + +``` + +#### `CoreReader.Adopted.achievementSupported012` + +`CoreReader/Adopted.lean:493–502`; theorem. + +```lean +theorem achievementSupported012 : + Grounds012 transitionAchievement canonicalArticulation [transitionFacet] (taskOfFacet transitionFacet) ∧ + Compatible [transitionPerformanceRecord] .extend ∧ + transitionAchievement .extend ∧ ¬ transitionAchievement .inflate ∧ + ¬ Supports [transitionReportRecord] transitionAchievement := by + refine ⟨grounds012Singleton _ transitionFacetDischarged, ?_, ?_, ?_, transitionReportDoesNotSupport.2.2⟩ + · exact (transitionPerformanceCompatible .extend).mpr rfl + · simp [transitionAchievement, transitionBefore, transitionAfter, Expanded, baseState, extendedState] + · simp [transitionAchievement, transitionBefore, transitionAfter, Expanded, baseState, inflatedState] + +``` + +#### `CoreReader.Adopted.semanticOrder012` + +`CoreReader/Adopted.lean:503–506`; theorem. + +```lean +theorem semanticOrder012 : ∀ p q : Claim Bool, + ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r := + representationOrderIrrelevant + +``` + +#### `CoreReader.Adopted.clearFalseArgument012` + +`CoreReader/Adopted.lean:507–509`; def. + +```lean +def clearFalseArgument012 : Articulation Bool := + ⟨["the actual switch is on"], singleton (fun w => w = true), [fun w => w = true], fun _ => True⟩ + +``` + +#### `CoreReader.Adopted.clearFalseReason012` + +`CoreReader/Adopted.lean:510–513`; theorem. + +```lean +theorem clearFalseReason012 : + Articulated clearFalseArgument012 ∧ ¬ Models clearFalseArgument012.assumptions false := + ⟨⟨by simp [clearFalseArgument012], by simp [clearFalseArgument012]⟩, consistentFalse.2⟩ + +``` + +#### `CoreReader.Adopted.valueNeutralRecord012` + +`CoreReader/Adopted.lean:514–515`; def. + +```lean +def valueNeutralRecord012 : Record Bool := ⟨fun _ => true, true⟩ + +``` + +#### `CoreReader.Adopted.valueNotFact012` + +`CoreReader/Adopted.lean:516–527`; theorem. + +```lean +theorem valueNotFact012 : + valueSpecification switchPosition ∧ + Compatible [valueNeutralRecord012] false ∧ + ¬ Supports [valueNeutralRecord012] switchPosition.commitment ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment := by + have compatible : Compatible [valueNeutralRecord012] false := by + intro r hr; cases List.mem_singleton.mp hr; rfl + refine ⟨valueFulfilled012, compatible, ?_, valueWithoutSelfProof.2.2.1⟩ + intro h + have bad := h false compatible + cases bad + +``` + +#### `CoreReader.Adopted.wrongExplanation012` + +`CoreReader/Adopted.lean:528–529`; def. + +```lean +def wrongExplanation012 : Implementation := { identityImpl with explanation := fun n => n + 1 } + +``` + +#### `CoreReader.Adopted.internalReasonDistinguishes012` + +`CoreReader/Adopted.lean:530–539`; theorem. + +```lean +theorem internalReasonDistinguishes012 : + (∀ n, identityImpl.run n = wrongExplanation012.run n) ∧ + Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧ + Relevant identityRequirements identityImpl (.method .explanation) ∧ + ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation) := by + refine ⟨fun _ => rfl, identityFeasible, identityFeasible, internalReasons.1, ?_⟩ + intro h + have bad := h.2 0 trivial + cases bad + +``` + +#### `CoreReader.Adopted.inventoryCases012` + +`CoreReader/Adopted.lean:540–546`; theorem. + +```lean +theorem inventoryCases012 : ∀ kind : InventoryKind, + Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .copy ∧ + ¬ Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .successor := by + intro kind + simp [Available] + + +``` + +#### `CoreReader.Adopted.selfExemptRule012` + +`CoreReader/Adopted.lean:547–549`; def. + +```lean +def selfExemptRule012 : ReflexiveRule Nat Nat Bool := + ⟨⟨0,1⟩, .assessment, fun _ => True, id, + fun input output => output = ownArithmeticPrinciple input⟩ +``` + +#### `CoreReader.Adopted.selfExemptPerformed012` + +`CoreReader/Adopted.lean:550–552`; def. + +```lean +def selfExemptPerformed012 (key : PrincipleKey) (target input : Nat) (output : Bool) : Prop := + key = ⟨0,1⟩ ∧ target = 1 ∧ input = target ∧ output = ownArithmeticPrinciple input + +``` + +#### `CoreReader.Adopted.openSelfExempt012` + +`CoreReader/Adopted.lean:553–562`; theorem. + +```lean +theorem openSelfExempt012 : + generationSpecification openPolicy ∧ openPolicy.revisable ⟨.principle,0⟩ ∧ + selfExemptPerformed012 ⟨0,1⟩ 1 1 true ∧ + selfExemptRule012.applicable 0 ∧ + ¬ reflexivitySpecification [selfExemptRule012] (fun target => target = 0) selfExemptPerformed012 := by + refine ⟨⟨Or.inl rfl, fun _ _ => trivial⟩, trivial, ⟨rfl,rfl,rfl,by decide⟩, trivial, ?_⟩ + intro h + obtain ⟨outcome, performed, _⟩ := h.2 selfExemptRule012 (by simp) 0 rfl trivial + cases performed.2.1 + +``` + +#### `CoreReader.Adopted.ownPhilosophyStatus012` + +`CoreReader/Adopted.lean:563–572`; theorem. + +```lean +theorem ownPhilosophyStatus012 : + ¬ choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation + [.status .standing] ∧ + choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation + [.method .output] := + ⟨CoreReader.Integration.existingPhilosophyNotPrivileged.2.2.1, + CoreReader.Integration.existingPhilosophyNotPrivileged.2.2.2.1⟩ + +``` + +#### `CoreReader.Adopted.jointContext012` + +`CoreReader/Adopted.lean:573–575`; def. + +```lean +def jointContext012 : Context (Bool × Bool) Unit := + ⟨emptyTheory, fun _ w => w.2 = true, fun _ => True⟩ + +``` + +#### `CoreReader.Adopted.jointImplicationConflict012` + +`CoreReader/Adopted.lean:576–587`; theorem. + +```lean +theorem jointImplicationConflict012 : + Consequence jointTheory jointContext012 () true ∧ + Consequence jointTheory jointContext012 () false ∧ + ¬ Consistent jointTheory jointContext012 := by + have positive : Consequence jointTheory jointContext012 () true := by + intro w hw + exact (hw.1 premiseRule (Or.inr (Or.inl rfl))) (hw.1 premiseP (Or.inl rfl)) + have negative : Consequence jointTheory jointContext012 () false := by + intro w hw + exact hw.1 premiseNotQ (Or.inr (Or.inr rfl)) + exact ⟨positive, negative, conflictRequiresChange _ _ () positive negative⟩ + +``` + +#### `CoreReader.Adopted.tensionContext012` + +`CoreReader/Adopted.lean:588–590`; def. + +```lean +def tensionContext012 : Context Nat Unit := + ⟨emptyTheory, fun _ n => n ≤ 6, fun _ => True⟩ + +``` + +#### `CoreReader.Adopted.tensionConsistent012` + +`CoreReader/Adopted.lean:591–596`; theorem. + +```lean +theorem tensionConsistent012 : + Consistent (union (singleton (fun n : Nat => 4 ≤ n)) (singleton (fun n => n ≤ 6))) tensionContext012 := by + apply consequenceConsistency + exact ⟨5, (modelsUnion _ _ _).2 ⟨(modelsSingleton _ _).2 (by decide), + (modelsSingleton _ _).2 (by decide)⟩, (by intro p hp; cases hp), trivial⟩ + +``` + +#### `CoreReader.Adopted.qualitativeUnmeasured012` + +`CoreReader/Adopted.lean:597–605`; theorem. + +```lean +theorem qualitativeUnmeasured012 : + inferentialSpecification (singleton (fun on : Bool => on = true)) (fun on => on ≠ false) ∧ + usesObservation (Facet.inferential (singleton (fun on : Bool => on = true)) (fun on => on ≠ false)) = false := by + refine ⟨grounds012Singleton _ ⟨⟨true, (modelsSingleton _ _).2 rfl⟩, ?_⟩, rfl⟩ + intro on hon hf + have ht := (modelsSingleton (fun on : Bool => on = true) on).1 hon + cases ht.symm.trans hf + + +``` + +#### `CoreReader.Adopted.allStatusOnly012` + +`CoreReader/Adopted.lean:606–612`; theorem. + +```lean +theorem allStatusOnly012 : ∀ kind : StatusKind, + ¬ choiceSpecification identityRequirements identityImpl [.status kind] := + statusOnlyFails identityRequirements identityImpl + + + + +``` + +#### `CoreReader.Adopted.drawWeight012` + +`CoreReader/Adopted.lean:613–613`; def. + +```lean +def drawWeight012 (_draw : Bool) : Nat := 1 +``` + +#### `CoreReader.Adopted.randomTrial012` + +`CoreReader/Adopted.lean:614–616`; def. + +```lean +def randomTrial012 (draw : Bool) : Trial := + ⟨0, if draw then 1 else 2, if draw then 1 else 2⟩ + +``` + +#### `CoreReader.Adopted.randomOutcomes012` + +`CoreReader/Adopted.lean:617–628`; theorem. + +```lean +theorem randomOutcomes012 : + drawWeight012 true > 0 ∧ drawWeight012 false > 0 ∧ + drawWeight012 true = drawWeight012 false ∧ + Reproduced (randomTrial012 true) (randomTrial012 false) ∧ + (randomTrial012 true).actualOutcome ≠ (randomTrial012 false).actualOutcome ∧ + (∀ draw, Verified (randomTrial012 draw) ∧ Bounded (randomTrial012 draw)) := by + refine ⟨by decide, by decide, rfl, rfl, by decide, ?_⟩ + intro draw + cases draw <;> simp [Verified, Bounded, randomTrial012] + + + +``` + +#### `CoreReader.Adopted.originalGlobalTask012` + +`CoreReader/Adopted.lean:629–630`; def. + +```lean +def originalGlobalTask012 : AssessmentTask (Nat → Bool) := + .empirical [zeroRecord] (fun _ => True) allTrue (fun _ => True) +``` + +#### `CoreReader.Adopted.originalLocalTask012` + +`CoreReader/Adopted.lean:631–633`; def. + +```lean +def originalLocalTask012 : AssessmentTask (Nat → Bool) := + .empirical [zeroRecord] (fun _ => True) (fun f => f 0 = true) (fun _ => True) + +``` + +#### `CoreReader.Adopted.circularGlobalFacet012` + +`CoreReader/Adopted.lean:634–635`; def. + +```lean +def circularGlobalFacet012 : Facet (Nat → Bool) := .inferential (singleton allTrue) allTrue + +``` + +#### `CoreReader.Adopted.circularGlobalConditional012` + +`CoreReader/Adopted.lean:636–640`; theorem. + +```lean +theorem circularGlobalConditional012 : FacetDischarged circularGlobalFacet012 := by + refine ⟨⟨fun _ => true, (modelsSingleton _ _).2 (fun _ => rfl)⟩, ?_⟩ + intro f hf + exact (modelsSingleton _ _).1 hf + +``` + +#### `CoreReader.Adopted.circularSubstitutionRejected012` + +`CoreReader/Adopted.lean:641–656`; theorem. + +```lean +theorem circularSubstitutionRejected012 : + Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] (taskOfFacet circularGlobalFacet012) ∧ + ¬ NatureAppropriate originalGlobalTask012 circularGlobalFacet012 ∧ + ¬ Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] originalGlobalTask012 := by + have inappropriate : ¬ NatureAppropriate originalGlobalTask012 circularGlobalFacet012 := by + intro h + have equalPremises := h.1 + have originalMember : singleton (fun f => Compatible [zeroRecord] f ∧ True) allTrue := equalPremises ▸ (show singleton allTrue allTrue from rfl) + have equalClaims : allTrue = (fun f => Compatible [zeroRecord] f ∧ True) := originalMember + have claimedAll := (congrFun equalClaims (localGenerator 0)).mpr ⟨(zeroCompatible _).2 rfl, trivial⟩ + have bad := claimedAll 1 + cases bad + refine ⟨grounds012Singleton _ circularGlobalConditional012, inappropriate, ?_⟩ + intro h + exact inappropriate (h.2 circularGlobalFacet012 (by simp)).2.2.2.2 + +``` + +#### `CoreReader.Adopted.observedPremises012` + +`CoreReader/Adopted.lean:657–657`; def. + +```lean +def observedPremises012 : Theory (Nat → Bool) := singleton (fun f => Compatible [zeroRecord] f ∧ True) +``` + +#### `CoreReader.Adopted.observedInferenceFacet012` + +`CoreReader/Adopted.lean:658–660`; def. + +```lean +def observedInferenceFacet012 : Facet (Nat → Bool) := + .inferential observedPremises012 (fun f => f 0 = true) + +``` + +#### `CoreReader.Adopted.observedInferenceChecked012` + +`CoreReader/Adopted.lean:661–665`; theorem. + +```lean +theorem observedInferenceChecked012 : FacetDischarged observedInferenceFacet012 := by + refine ⟨⟨localGenerator 0, (modelsSingleton _ _).2 ⟨(zeroCompatible _).2 rfl, trivial⟩⟩, ?_⟩ + intro f hf + exact (zeroCompatible _).1 ((modelsSingleton _ _).1 hf).1 + +``` + +#### `CoreReader.Adopted.sameEmpiricalTaskTwoMethods012` + +`CoreReader/Adopted.lean:666–677`; theorem. + +```lean +theorem sameEmpiricalTaskTwoMethods012 : + Grounds012 (fun f => f 0 = true) canonicalArticulation [localFacet012] originalLocalTask012 ∧ + Grounds012 (fun f => f 0 = true) canonicalArticulation [observedInferenceFacet012] originalLocalTask012 := by + refine ⟨grounds012Singleton _ localFacetChecked012, ?_⟩ + refine ⟨by simp, ?_⟩ + intro f hf + cases List.mem_singleton.mp hf + exact ⟨rfl, canonicalArticulated _ observedInferenceChecked012, + canonicalFacetArticulated _, observedInferenceChecked012, rfl, rfl, fun _ _ => trivial⟩ + + + +``` + +#### `CoreReader.Adopted.originalUncertaintyTask012` + +`CoreReader/Adopted.lean:678–680`; def. + +```lean +def originalUncertaintyTask012 : AssessmentTask (Bool × Bool) := + .empirical [temperatureRecord, temperatureRecord] (fun _ => True) + (fun w => w.1 = true) (fun w => w.2 = true) +``` + +#### `CoreReader.Adopted.uncertaintyBypassFacet012` + +`CoreReader/Adopted.lean:681–684`; def. + +```lean +def uncertaintyBypassFacet012 : Facet (Bool × Bool) := + .inferential (singleton (fun w => Compatible [temperatureRecord, temperatureRecord] w ∧ True)) + (fun w => w.1 = true) + +``` + +#### `CoreReader.Adopted.uncertaintyBypassChecked012` + +`CoreReader/Adopted.lean:685–689`; theorem. + +```lean +theorem uncertaintyBypassChecked012 : FacetDischarged uncertaintyBypassFacet012 := by + refine ⟨⟨(true,false), (modelsSingleton _ _).2 ⟨temperatureCompatible false, trivial⟩⟩, ?_⟩ + intro w hw + exact ((modelsSingleton _ _).1 hw).1 temperatureRecord (by simp) + +``` + +#### `CoreReader.Adopted.uncertaintySubstitutionRejected012` + +`CoreReader/Adopted.lean:690–701`; theorem. + +```lean +theorem uncertaintySubstitutionRejected012 : + FacetDischarged uncertaintyBypassFacet012 ∧ + ¬ NatureAppropriate originalUncertaintyTask012 uncertaintyBypassFacet012 ∧ + ¬ Grounds012 (fun w : Bool × Bool => w.1 = true) canonicalArticulation + [uncertaintyBypassFacet012] originalUncertaintyTask012 := by + have inappropriate : ¬ NatureAppropriate originalUncertaintyTask012 uncertaintyBypassFacet012 := by + intro h + have bad := h.2.2 (true,false) (temperatureCompatible false) + cases bad + exact ⟨uncertaintyBypassChecked012, inappropriate, + fun h => inappropriate (h.2 uncertaintyBypassFacet012 (by simp)).2.2.2.2⟩ + +``` + +#### `CoreReader.Adopted.selectedFactFacet012` + +`CoreReader/Adopted.lean:702–704`; def. + +```lean +def selectedFactFacet012 : Facet Bool := + .empirical [switchRecord] (fun _ => True) switchPosition.commitment (fun _ => True) + +``` + +#### `CoreReader.Adopted.valueFactSubstitutionRejected012` + +`CoreReader/Adopted.lean:705–711`; theorem. + +```lean +theorem valueFactSubstitutionRejected012 : + FacetDischarged selectedFactFacet012 ∧ valueSpecification switchPosition ∧ + ¬ Grounds012 switchPosition.commitment canonicalArticulation [selectedFactFacet012] (.value switchPosition) := by + refine ⟨switchEmpiricalDischarged, valueFulfilled012, ?_⟩ + intro h + exact (h.2 selectedFactFacet012 (by simp)).2.2.2.2 + +``` + +#### `CoreReader.Adopted.inferentialContextSubstitutionRejected012` + +`CoreReader/Adopted.lean:712–725`; theorem. + +```lean +theorem inferentialContextSubstitutionRejected012 : + FacetDischarged (Facet.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) ∧ + ¬ Grounds012 (fun w : Bool => w = true) canonicalArticulation + [.inferential (singleton (fun w => w = true)) (fun w => w = true)] + (.inferential emptyTheory (fun w => w = true)) := by + refine ⟨⟨⟨true, (modelsSingleton _ _).2 rfl⟩, fun w hw => (modelsSingleton (fun w : Bool => w = true) w).1 hw⟩, ?_⟩ + intro h + have appropriate := (h.2 (.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) (by simp)).2.2.2.2 + have same : singleton (fun w : Bool => w = true) = emptyTheory := appropriate.1 + have bad : emptyTheory (fun w : Bool => w = true) := same ▸ (show singleton (fun w : Bool => w = true) (fun w => w = true) from rfl) + exact bad + + + +``` + +#### `CoreReader.Adopted.generationCases` + +`CoreReader/Adopted.lean:726–760`; theorem. + +```lean +theorem generationCases : + (Generative openPolicy ∧ + (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧ + (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1)))) ∧ + (neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy) ∧ + (Generative generatingSystem.policy ∧ + generatingSystem.policy.permitsVersion 0 0 ∧ + ¬ Expanded generatingSystem.current inflatedState ∧ + generatingSystem.current.inventory.length < inflatedState.inventory.length ∧ + generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧ + generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧ + generatingSystem.execute availableResources = some 6 ∧ + generatingSystem.execute { availableResources with experience := none } = none ∧ + generatingSystem.execute { availableResources with knowledge := none } = none ∧ + generatingSystem.execute { availableResources with collaborator := none } = none ∧ + generatingSystem.execute ⟨none, none, none⟩ = none ∧ + ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧ + generatingSystem.stableAction = generatingSystem.current ∧ + generatingSystem.requirementsMet generatingSystem.stableAction ∧ + generatingSystem.withinBudget generatingSystem.stableAction ∧ + ¬ generatingSystem.withinBudget inflatedState ∧ + StableReason generatingSystem.current inflatedState ∧ + (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧ + inflatedAnnouncement.owner = generatingSystem.owner ∧ + inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧ + inflatedAnnouncement.reportedNewOperation = .successor ∧ + inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧ + ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after)) ∧ + (generationSpecification openPolicy ∧ + Expanded baseState (collaborativeRevision availableResources) ∧ + ¬ Expanded baseState (collaborativeRevision { availableResources with collaborator := none }) ∧ + assistedExecution ⟨none, none, none⟩ = none) := + ⟨revisionWithoutProgress, permissionNotValuation, generationLimits, collaborativeProgress⟩ + + +``` + +#### `CoreReader.Adopted.generationLimits012` + +`CoreReader/Adopted.lean:761–802`; theorem. + +```lean +theorem generationLimits012 : + (neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy) ∧ + (Generative openPolicy ∧ + (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧ + (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1)))) ∧ + (Generative generatingSystem.policy ∧ + generatingSystem.policy.permitsVersion 0 0 ∧ + ¬ Expanded generatingSystem.current inflatedState ∧ + generatingSystem.current.inventory.length < inflatedState.inventory.length ∧ + generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧ + generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧ + generatingSystem.execute availableResources = some 6 ∧ + generatingSystem.execute { availableResources with experience := none } = none ∧ + generatingSystem.execute { availableResources with knowledge := none } = none ∧ + generatingSystem.execute { availableResources with collaborator := none } = none ∧ + generatingSystem.execute ⟨none, none, none⟩ = none ∧ + ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧ + generatingSystem.stableAction = generatingSystem.current ∧ + generatingSystem.requirementsMet generatingSystem.stableAction ∧ + generatingSystem.withinBudget generatingSystem.stableAction ∧ + ¬ generatingSystem.withinBudget inflatedState ∧ + StableReason generatingSystem.current inflatedState ∧ + (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧ + inflatedAnnouncement.owner = generatingSystem.owner ∧ + inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧ + inflatedAnnouncement.reportedNewOperation = .successor ∧ + inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧ + ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after)) ∧ + (generationSpecification openPolicy ∧ + Expanded baseState (collaborativeRevision availableResources) ∧ + ¬ Expanded baseState (collaborativeRevision { availableResources with collaborator := none }) ∧ + assistedExecution ⟨none, none, none⟩ = none) ∧ + (Grounds012 transitionAchievement canonicalArticulation [transitionFacet] (taskOfFacet transitionFacet) ∧ + Compatible [transitionPerformanceRecord] .extend ∧ + transitionAchievement .extend ∧ ¬ transitionAchievement .inflate ∧ + ¬ Supports [transitionReportRecord] transitionAchievement) ∧ + (∀ kind : InventoryKind, + Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .copy ∧ + ¬ Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .successor) := + ⟨permissionNotValuation, revisionWithoutProgress, generationLimits, collaborativeProgress, achievementSupported012, inventoryCases012⟩ + + +``` + +#### `CoreReader.Adopted.consistencyCases` + +`CoreReader/Adopted.lean:803–832`; theorem. + +```lean +theorem consistencyCases : + (Satisfiable (singleton premiseP) ∧ Satisfiable (singleton premiseRule) ∧ + Satisfiable (singleton premiseNotQ) ∧ ¬ Satisfiable jointTheory) ∧ + ((Consequence emptyTheory (assumptionContext true) () true ∧ + Consequence emptyTheory (assumptionContext false) () false) ∧ + (Consequence emptyTheory (meaningContext true) () true ∧ + Consequence emptyTheory (meaningContext false) () false) ∧ + (Consequence emptyTheory (scopeContext true) () true ∧ + Consequence emptyTheory (scopeContext false) () false) ∧ + (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w)) ∧ + (¬ TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (meaningContext true)) (contextSnapshot (meaningContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (scopeContext true)) (contextSnapshot (scopeContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (scopeContext true) 0) (contextSnapshot (scopeContext true) 1) false ∧ + (TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) true ∧ + ¬ Models (assumptionContext false).assumptions true)) ∧ + (Satisfiable (revisionSlice 0) ∧ Satisfiable (revisionSlice 1) ∧ + ¬ Satisfiable (union (revisionSlice 0) (revisionSlice 1))) ∧ + ((∀ time, Consistent (revisionSlice time) broadBoolContext) ∧ + ¬ Consistent (union (revisionSlice 0) (revisionSlice 1)) broadBoolContext) ∧ + (∀ p q : Claim Bool, + ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r) ∧ + (Consequence jointTheory jointContext012 () true ∧ + Consequence jointTheory jointContext012 () false ∧ + ¬ Consistent jointTheory jointContext012) := + ⟨jointConflict, contextDifferences, hiddenContextChangeRejected, revisionCanReverse, sliceConsistency, semanticOrder012, jointImplicationConflict012⟩ + + +``` + +#### `CoreReader.Adopted.consistencyLimits012` + +`CoreReader/Adopted.lean:833–854`; theorem. + +```lean +theorem consistencyLimits012 : + ((Consequence emptyTheory (assumptionContext true) () true ∧ + Consequence emptyTheory (assumptionContext false) () false) ∧ + (Consequence emptyTheory (meaningContext true) () true ∧ + Consequence emptyTheory (meaningContext false) () false) ∧ + (Consequence emptyTheory (scopeContext true) () true ∧ + Consequence emptyTheory (scopeContext false) () false) ∧ + (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w)) ∧ + ((∃ budget : Nat, 4 ≤ budget ∧ budget ≤ 6) ∧ + ¬ ((fun n : Nat => 4 ≤ n) = (fun n : Nat => n ≤ 6))) ∧ + (Consistent (singleton (fun w : Bool => w = true)) broadBoolContext ∧ + ¬ Models (singleton (fun w : Bool => w = true)) false ∧ + Consistent (emptyTheory : Theory Bool) broadBoolContext ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧ + (Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧ + (Consistent (union (singleton (fun n : Nat => 4 ≤ n)) (singleton (fun n => n ≤ 6))) tensionContext012) := + ⟨contextDifferences, tensionWithoutContradiction, explicitlyConsistentLimits, compatibilityNotEntailment, tensionConsistent012⟩ + + +``` + +#### `CoreReader.Adopted.reflexivityCases012` + +`CoreReader/Adopted.lean:855–871`; theorem. + +```lean +theorem reflexivityCases012 : + (reflexivitySpecification ((ownRules 0).map legacyRule) (fun s => s.owner = 0) + (legacyPerformed (ownRules 0) (completeOwnWork 0)) ∧ + (∀ phase, Performed (completeOwnWork 0) (.process 0 0 phase) .assessment) ∧ + Performed (completeOwnWork 0) (.system 0) .assessment ∧ + reflexivitySpecification ([applicationRule].map legacyRule) (fun s => s.owner = 0) + (legacyPerformed [applicationRule] applicationWork) ∧ + ¬ Performed applicationWork (.system 0) .assessment) ∧ + (Grounds012 (fun enabled => GroundsProvision012 enabled) canonicalArticulation [.value groundsPosition012] (.value groundsPosition012) ∧ + groundsPosition012.limits true ∧ groundsPosition012.relevantCriticism true) ∧ + (Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0) ∧ + groundsExperiment012 true = false ∧ groundsExperiment012 false = true ∧ + groundsPosition012.outcome true true = groundsExperiment012 true ∧ + groundsPosition012.outcome true false = groundsExperiment012 false) := + ⟨reflexiveTargets012, groundsOnGrounds012, groundsRationaleExperiment012⟩ + + +``` + +#### `CoreReader.Adopted.reflexivityLimits012` + +`CoreReader/Adopted.lean:872–893`; theorem. + +```lean +theorem reflexivityLimits012 : + (selfTest [1] = true ∧ ownArithmeticPrinciple 0 = false ∧ + ¬ (∀ n, ownArithmeticPrinciple n = true)) ∧ + (localGenerator 0 0 = true ∧ localGenerator 0 1 = false ∧ + Compatible [zeroRecord] (localGenerator 0) ∧ + ¬ Supports [zeroRecord] allTrue ∧ OwnedRevisionExample) ∧ + (Generative openPolicy ∧ ¬ Reflexive 0 (ownRules 0) []) ∧ + (CompleteCharter012 CoreReader.Integration.actualSystem CoreReader.Integration.actual ∧ + Admissible CoreReader.Integration.held CoreReader.Integration.context CoreReader.Integration.actual ∧ + Compatible [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.actual ∧ + Articulated (canonicalArticulation CoreReader.Integration.unsupportedCapabilityFacet) ∧ + ¬ Supports [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.capability ∧ + ¬ Grounds012 CoreReader.Integration.capability canonicalArticulation + [CoreReader.Integration.unsupportedCapabilityFacet] + (taskOfFacet CoreReader.Integration.unsupportedCapabilityFacet)) ∧ + (generationSpecification openPolicy ∧ openPolicy.revisable ⟨.principle,0⟩ ∧ + selfExemptPerformed012 ⟨0,1⟩ 1 1 true ∧ + selfExemptRule012.applicable 0 ∧ + ¬ reflexivitySpecification [selfExemptRule012] (fun target => target = 0) selfExemptPerformed012) := + ⟨selfTestDoesNotProve, selfOriginDoesNotSupport, generationNotReflexivity, charterWithoutGrounds012, openSelfExempt012⟩ + + +``` + +#### `CoreReader.Adopted.groundsCases012` + +`CoreReader/Adopted.lean:894–906`; theorem. + +```lean +theorem groundsCases012 : + (Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧ + Articulated (canonicalArticulation globalFacet012) ∧ + ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧ + ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012)) ∧ + (Articulated uninformativeArgument ∧ + ¬ Entails uninformativeArgument.assumptions (fun w : Bool => w = true)) ∧ + (Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] (taskOfFacet circularGlobalFacet012) ∧ + ¬ NatureAppropriate originalGlobalTask012 circularGlobalFacet012 ∧ + ¬ Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] originalGlobalTask012) := + ⟨scopeStrength012, articulationNotSupport, circularSubstitutionRejected012⟩ + + +``` + +#### `CoreReader.Adopted.empiricalCases012` + +`CoreReader/Adopted.lean:907–934`; theorem. + +```lean +theorem empiricalCases012 : + (Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧ + Articulated (canonicalArticulation globalFacet012) ∧ + ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧ + ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012)) ∧ + (temperatureRecord.test (true,false) = true ∧ + Compatible [temperatureRecord,temperatureRecord] (true,false) ∧ + Compatible [temperatureRecord,temperatureRecord] (true,true) ∧ + ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + Compatible [actionRecord,actionRecord] (true,0) ∧ + Compatible [actionRecord,actionRecord] (true,3) ∧ + ¬ Supports [actionRecord] announcementPosition.consequence ∧ + ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧ + ¬ ValueProcedure announcementPosition) ∧ + (empiricalSpecification [temperatureRecord, temperatureRecord] (fun _ => True) + (fun w => w.1 = true) (fun w => w.2 = true ∨ w.2 = false) ∧ + Compatible [temperatureRecord, temperatureRecord] (true,true) ∧ + Compatible [temperatureRecord, temperatureRecord] (true,false)) ∧ + (Grounds012 (fun f => f 0 = true) canonicalArticulation [localFacet012] originalLocalTask012 ∧ + Grounds012 (fun f => f 0 = true) canonicalArticulation [observedInferenceFacet012] originalLocalTask012) ∧ + (FacetDischarged uncertaintyBypassFacet012 ∧ + ¬ NatureAppropriate originalUncertaintyTask012 uncertaintyBypassFacet012 ∧ + ¬ Grounds012 (fun w : Bool × Bool => w.1 = true) canonicalArticulation + [uncertaintyBypassFacet012] originalUncertaintyTask012) := + ⟨scopeStrength012, measurementRepeatNotSupport, uncertainSupported012, sameEmpiricalTaskTwoMethods012, uncertaintySubstitutionRejected012⟩ + + +``` + +#### `CoreReader.Adopted.inferentialCases012` + +`CoreReader/Adopted.lean:935–947`; theorem. + +```lean +theorem inferentialCases012 : + (inferentialSpecification (singleton (fun n : Nat => n = 2)) (fun n => n + 1 = 3) ∧ + InferenceExamined (emptyTheory : Theory Bool) (fun w => w = true) false ∧ + Models (emptyTheory : Theory Bool) false ∧ ¬ ((fun w : Bool => w = true) false)) ∧ + (Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧ + (FacetDischarged (Facet.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) ∧ + ¬ Grounds012 (fun w : Bool => w = true) canonicalArticulation + [.inferential (singleton (fun w => w = true)) (fun w => w = true)] + (.inferential emptyTheory (fun w => w = true))) := + ⟨inferenceChecked012, compatibilityNotEntailment, inferentialContextSubstitutionRejected012⟩ + + +``` + +#### `CoreReader.Adopted.valueCases012` + +`CoreReader/Adopted.lean:948–963`; theorem. + +```lean +theorem valueCases012 : + (valueSpecification switchPosition) ∧ + (announcementPosition.reasons ≠ [] ∧ announcementPosition.commitment (true,0) ∧ + (∀ reason, reason ∈ announcementPosition.reasons → reason (true,0) announcementPosition.adopted) ∧ + ¬ announcementPosition.consequence (true,0) ∧ ¬ ValueProcedure announcementPosition) ∧ + (¬ ValueProcedure closedPosition012) ∧ + (ValueProcedure switchPosition ∧ + Satisfiable switchPosition.starting ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧ + (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧ + (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition)) ∧ + (FacetDischarged selectedFactFacet012 ∧ valueSpecification switchPosition ∧ + ¬ Grounds012 switchPosition.commitment canonicalArticulation [selectedFactFacet012] (.value switchPosition)) := + ⟨valueFulfilled012, announcementNotBudgetReason, closedCriticism012, valueWithoutSelfProof, valueFactSubstitutionRejected012⟩ + + +``` + +#### `CoreReader.Adopted.groundsLimits012` + +`CoreReader/Adopted.lean:964–990`; theorem. + +```lean +theorem groundsLimits012 : + (Articulated clearFalseArgument012 ∧ ¬ Models clearFalseArgument012.assumptions false) ∧ + (temperatureRecord.test (true,false) = true ∧ + Compatible [temperatureRecord,temperatureRecord] (true,false) ∧ + Compatible [temperatureRecord,temperatureRecord] (true,true) ∧ + ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + Compatible [actionRecord,actionRecord] (true,0) ∧ + Compatible [actionRecord,actionRecord] (true,3) ∧ + ¬ Supports [actionRecord] announcementPosition.consequence ∧ + ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧ + ¬ ValueProcedure announcementPosition) ∧ + (valueSpecification switchPosition ∧ + Compatible [valueNeutralRecord012] false ∧ + ¬ Supports [valueNeutralRecord012] switchPosition.commitment ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment) ∧ + (ValueProcedure switchPosition ∧ + Satisfiable switchPosition.starting ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧ + (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧ + (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition)) ∧ + (ClaimNoStronger (fun f : Nat → Bool => f 0 = true) allTrue ∧ + ¬ ClaimNoStronger allTrue (fun f : Nat → Bool => f 0 = true) ∧ + valueSpecification switchPosition) := + ⟨clearFalseReason012, measurementRepeatNotSupport, valueNotFact012, valueWithoutSelfProof, qualitativeProportionality012⟩ + + +``` + +#### `CoreReader.Adopted.scopeCases012` + +`CoreReader/Adopted.lean:991–997`; theorem. + +```lean +theorem scopeCases012 : + (scopeSpecification localScopeAccount012) ∧ + ((∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧ + (fun _ : Nat => true) 1 ≠ localGenerator 0 1) := + ⟨scopeFulfilled012, hiddenDifference⟩ + + +``` + +#### `CoreReader.Adopted.scopeLimits012` + +`CoreReader/Adopted.lean:998–1026`; theorem. + +```lean +theorem scopeLimits012 : + ((∃ outside : Nat, outside ≠ 0) ∧ + Compatible [zeroRecord] (fun _ => true) ∧ + Compatible [zeroRecord] (localGenerator 0) ∧ + allTrue (fun _ => true) ∧ ¬ allTrue (localGenerator 0) ∧ + ¬ Supports [zeroRecord] allTrue) ∧ + ((∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧ + (fun _ : Nat => true) 1 ≠ localGenerator 0 1) ∧ + ([zeroRecord].length = 1 ∧ + (∃ f, Compatible [zeroRecord] f) ∧ + Supports [zeroRecord] (fun f => f 0 = true) ∧ + ¬ Supports [zeroRecord] allTrue) ∧ + (let a : Trial := ⟨0,1,1⟩ + let b : Trial := ⟨0,2,2⟩ + Reproduced a b ∧ a.actualOutcome ≠ b.actualOutcome ∧ Bounded a ∧ Bounded b) ∧ + ((Verified ⟨0,1,1⟩ ∧ Verified ⟨1,1,1⟩ ∧ ¬ Reproduced ⟨0,1,1⟩ ⟨1,1,1⟩) ∧ + (Reproduced ⟨0,1,1⟩ ⟨0,3,2⟩ ∧ ¬ Verified ⟨0,3,2⟩ ∧ ¬ Bounded ⟨0,3,2⟩) ∧ + (Bounded ⟨0,1,1⟩ ∧ Bounded ⟨0,2,0⟩ ∧ ¬ Verified ⟨0,2,0⟩)) ∧ + (FacetDischarged arithmeticFacet ∧ usesObservation arithmeticFacet = false) ∧ + (inferentialSpecification (singleton (fun on : Bool => on = true)) (fun on => on ≠ false) ∧ + usesObservation (Facet.inferential (singleton (fun on : Bool => on = true)) (fun on => on ≠ false)) = false) ∧ + (drawWeight012 true > 0 ∧ drawWeight012 false > 0 ∧ + drawWeight012 true = drawWeight012 false ∧ + Reproduced (randomTrial012 true) (randomTrial012 false) ∧ + (randomTrial012 true).actualOutcome ≠ (randomTrial012 false).actualOutcome ∧ + (∀ draw, Verified (randomTrial012 draw) ∧ Bounded (randomTrial012 draw))) := + ⟨localNotUniversal, hiddenDifference, singleObservation, variableOutcomesStableBound, verificationReproductionStability, noUniversalChain, qualitativeUnmeasured012, randomOutcomes012⟩ + + +``` + +#### `CoreReader.Adopted.capabilityCases012` + +`CoreReader/Adopted.lean:1027–1036`; theorem. + +```lean +theorem capabilityCases012 : + (capabilitySpecification outputOnlyProcess OutputContract ∧ + capabilitySpecification explainedProcess FullProcessContract ∧ + (∃ certificate : ExternalCertificate outputOnlyProcess, + certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧ + ¬ ExplanationContract outputOnlyProcess) ∧ + (OwnCapability012 7 7 outputOnlyProcess OutputContract) := + ⟨capabilityFulfilled012, ownCapability012⟩ + + +``` + +#### `CoreReader.Adopted.capabilityLimits012` + +`CoreReader/Adopted.lean:1037–1071`; theorem. + +```lean +theorem capabilityLimits012 : + (capabilitySpecification outputOnlyProcess OutputContract ∧ + capabilitySpecification explainedProcess FullProcessContract ∧ + (∃ certificate : ExternalCertificate outputOnlyProcess, + certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧ + ¬ ExplanationContract outputOnlyProcess) ∧ + (∀ kind : InventoryKind, + Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .copy ∧ + ¬ Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .successor) ∧ + (Generative generatingSystem.policy ∧ + generatingSystem.policy.permitsVersion 0 0 ∧ + ¬ Expanded generatingSystem.current inflatedState ∧ + generatingSystem.current.inventory.length < inflatedState.inventory.length ∧ + generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧ + generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧ + generatingSystem.execute availableResources = some 6 ∧ + generatingSystem.execute { availableResources with experience := none } = none ∧ + generatingSystem.execute { availableResources with knowledge := none } = none ∧ + generatingSystem.execute { availableResources with collaborator := none } = none ∧ + generatingSystem.execute ⟨none, none, none⟩ = none ∧ + ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧ + generatingSystem.stableAction = generatingSystem.current ∧ + generatingSystem.requirementsMet generatingSystem.stableAction ∧ + generatingSystem.withinBudget generatingSystem.stableAction ∧ + ¬ generatingSystem.withinBudget inflatedState ∧ + StableReason generatingSystem.current inflatedState ∧ + (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧ + inflatedAnnouncement.owner = generatingSystem.owner ∧ + inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧ + inflatedAnnouncement.reportedNewOperation = .successor ∧ + inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧ + ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after)) := + ⟨capabilityFulfilled012, inventoryCases012, generationLimits⟩ + + +``` + +#### `CoreReader.Adopted.choiceCases012` + +`CoreReader/Adopted.lean:1072–1100`; theorem. + +```lean +theorem choiceCases012 : + (identityImpl.conventional = true ∧ identityImpl.established = true ∧ + JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output]) ∧ + (Relevant identityRequirements identityImpl (.method .explanation) ∧ + Relevant identityRequirements identityImpl (.method .applicability) ∧ + Relevant identityRequirements identityImpl (.method .simplicity) ∧ + Relevant identityRequirements identityImpl (.method .procedure) ∧ + (Relevant identityRequirements cheapSuccessor (.method .simplicity) ∧ + ¬ JustifiedChoice identityRequirements cheapSuccessor [.method .simplicity])) ∧ + (Articulated priorityArticulation ∧ AssessmentAccurate false ∧ + (∀ selected, Models statusFacts selected) ∧ + priorityClaim .identity ∧ ¬ priorityClaim .successor ∧ + ¬ Entails statusFacts priorityClaim ∧ + ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧ + ((∀ n, identityImpl.run n = wrongExplanation012.run n) ∧ + Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧ + Relevant identityRequirements identityImpl (.method .explanation) ∧ + ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation)) ∧ + (¬ choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation + [.status .standing] ∧ + choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation + [.method .output]) ∧ + (∀ kind : StatusKind, + ¬ choiceSpecification identityRequirements identityImpl [.status kind]) := + ⟨conventionWithReason, internalReasons, statusAssessmentNonEntailment, internalReasonDistinguishes012, ownPhilosophyStatus012, allStatusOnly012⟩ + + +``` + +#### `CoreReader.Adopted.choiceLimits012` + +`CoreReader/Adopted.lean:1101–1122`; theorem. + +```lean +theorem choiceLimits012 : + ((∀ candidate, Feasible identityRequirements (implementation candidate) ↔ candidate = .identity) ∧ + JustifiedChoice identityRequirements identityImpl objectiveReason) ∧ + (identityImpl.conventional = true ∧ identityImpl.established = true ∧ + JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output]) ∧ + ((∀ n, identityImpl.run n = wrongExplanation012.run n) ∧ + Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧ + Relevant identityRequirements identityImpl (.method .explanation) ∧ + ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation)) ∧ + (JustifiedChoice identityRequirements identityImpl objectiveReason ∧ + identityImpl.run 0 ≠ successorImpl.run 0) ∧ + ((∀ x, x = 0 → identityImpl.run x = changedOutsideZero.run x) ∧ + identityImpl.run 1 ≠ changedOutsideZero.run 1) ∧ + ((Articulated priorityArticulation ∧ AssessmentAccurate false ∧ + (∀ selected, Models statusFacts selected) ∧ + priorityClaim .identity ∧ ¬ priorityClaim .successor ∧ + ¬ Entails statusFacts priorityClaim ∧ + ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧ + PolicyIndependenceExample) := + ⟨singleFeasible, conventionWithReason, internalReasonDistinguishes012, openNotEquivalent, localNotGlobal, generalGroundsNotChoice⟩ + +end CoreReader.Adopted +``` + +### CoreReader/Agency.lean + +#### `CoreReader.Agency.FormKind` + +`CoreReader/Agency.lean:5–7`; inductive. + +```lean +inductive FormKind | organization | method | principle | appearance | artifact + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Agency.Form` + +`CoreReader/Agency.lean:8–12`; structure. + +```lean +structure Form where + kind : FormKind + version : Nat + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Agency.Aim` + +`CoreReader/Agency.lean:13–16`; inductive. + +```lean +inductive Aim | expandUnderstandingAndConstruction | preserveSafeOperation + deriving DecidableEq, Repr + + +``` + +#### `CoreReader.Agency.Policy` + +`CoreReader/Agency.lean:17–23`; structure. + +```lean +structure Policy where + worthPursuing : Aim → Prop + current : Form → Prop + revisable : Form → Prop + permitsVersion : Nat → Nat → Prop + + +``` + +#### `CoreReader.Agency.Generative` + +`CoreReader/Agency.lean:24–27`; def. + +```lean +def Generative (p : Policy) : Prop := + p.worthPursuing .expandUnderstandingAndConstruction ∧ + ∀ f, p.current f → p.revisable f + +``` + +#### `CoreReader.Agency.openPolicy` + +`CoreReader/Agency.lean:28–33`; def. + +```lean +def openPolicy : Policy where + worthPursuing a := a = .expandUnderstandingAndConstruction ∨ a = .preserveSafeOperation + current f := f.version = 0 + revisable _ := True + permitsVersion _ _ := True + +``` + +#### `CoreReader.Agency.neutralPolicy` + +`CoreReader/Agency.lean:34–36`; def. + +```lean +def neutralPolicy : Policy := { openPolicy with worthPursuing := fun _ => False } + + +``` + +#### `CoreReader.Agency.permissionNotValuation` + +`CoreReader/Agency.lean:37–41`; theorem. + +```lean +theorem permissionNotValuation : + neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy := by + simp [neutralPolicy, openPolicy, Generative] + + +``` + +#### `CoreReader.Agency.revisabilityCovers` + +`CoreReader/Agency.lean:42–44`; theorem. + +```lean +theorem revisabilityCovers (p : Policy) (h : Generative p) (k : FormKind) (v : Nat) + (hc : p.current ⟨k, v⟩) : p.revisable ⟨k, v⟩ := h.2 _ hc + +``` + +#### `CoreReader.Agency.Operation` + +`CoreReader/Agency.lean:45–47`; inductive. + +```lean +inductive Operation | copy | successor + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Agency.Operation.run` + +`CoreReader/Agency.lean:48–51`; def. + +```lean +def Operation.run : Operation → Nat → Nat + | .copy, n => n + | .successor, n => n + 1 + +``` + +#### `CoreReader.Agency.InventoryKind` + +`CoreReader/Agency.lean:52–54`; inductive. + +```lean +inductive InventoryKind | document | term | tool | artifact + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Agency.Item` + +`CoreReader/Agency.lean:55–60`; structure. + +```lean +structure Item where + kind : InventoryKind + content : Operation + deriving DecidableEq, Repr + + +``` + +#### `CoreReader.Agency.Available` + +`CoreReader/Agency.lean:61–64`; def. + +```lean +def Available (xs : List Item) (op : Operation) : Prop := + ∃ item ∈ xs, item.content = op + + +``` + +#### `CoreReader.Agency.inventoryNotCapability` + +`CoreReader/Agency.lean:65–73`; theorem. + +```lean +theorem inventoryNotCapability (kind : InventoryKind) (ops : List Operation) (op : Operation) : + Available ((ops.map fun x => Item.mk kind x) ++ (ops.map fun x => Item.mk kind x)) op ↔ + Available (ops.map fun x => Item.mk kind x) op := by + simp only [Available, List.mem_append] + constructor + · rintro ⟨x, hx | hx, hop⟩ <;> exact ⟨x, hx, hop⟩ + · rintro ⟨x, hx, hop⟩ + exact ⟨x, Or.inl hx, hop⟩ + +``` + +#### `CoreReader.Agency.State` + +`CoreReader/Agency.lean:74–82`; structure. + +```lean +structure State where + understood : List Operation + constructed : List Operation + inventory : List Item + abstractionLayers : List Operation + vocabulary : List Operation + deriving DecidableEq, Repr + + +``` + +#### `CoreReader.Agency.Expanded` + +`CoreReader/Agency.lean:83–86`; def. + +```lean +def Expanded (before after : State) : Prop := + (∃ op, op ∈ after.understood ∧ op ∉ before.understood) ∨ + (∃ op, op ∈ after.constructed ∧ op ∉ before.constructed) + +``` + +#### `CoreReader.Agency.baseState` + +`CoreReader/Agency.lean:87–89`; def. + +```lean +def baseState : State := + ⟨[.copy], [.copy], [⟨.artifact, .copy⟩], [.copy], [.copy]⟩ + +``` + +#### `CoreReader.Agency.inflatedState` + +`CoreReader/Agency.lean:90–95`; def. + +```lean +def inflatedState : State := + { baseState with + inventory := baseState.inventory ++ baseState.inventory + abstractionLayers := [.copy, .copy] + vocabulary := [.copy, .copy] } + +``` + +#### `CoreReader.Agency.stableTrace` + +`CoreReader/Agency.lean:96–98`; def. + +```lean +def stableTrace (_time : Nat) : State := baseState + + +``` + +#### `CoreReader.Agency.revisionWithoutProgress` + +`CoreReader/Agency.lean:99–104`; theorem. + +```lean +theorem revisionWithoutProgress : + Generative openPolicy ∧ + (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧ + (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1))) := by + simp [Generative, openPolicy, stableTrace, Expanded] + +``` + +#### `CoreReader.Agency.ExternalResources` + +`CoreReader/Agency.lean:105–111`; structure. + +```lean +structure ExternalResources where + experience : Option Nat + knowledge : Option Nat + collaborator : Option Nat + deriving DecidableEq, Repr + + +``` + +#### `CoreReader.Agency.assistedExecution` + +`CoreReader/Agency.lean:112–117`; def. + +```lean +def assistedExecution (r : ExternalResources) : Option Nat := do + let e ← r.experience + let k ← r.knowledge + let c ← r.collaborator + pure (Operation.copy.run (e + k + c)) + +``` + +#### `CoreReader.Agency.availableResources` + +`CoreReader/Agency.lean:118–120`; def. + +```lean +def availableResources : ExternalResources := ⟨some 1, some 2, some 3⟩ + + +``` + +#### `CoreReader.Agency.StableReason` + +`CoreReader/Agency.lean:121–125`; def. + +```lean +def StableReason (before proposed : State) : Prop := + before.constructed = proposed.constructed ∧ + before.inventory.length ≤ 1 ∧ ¬ proposed.inventory.length ≤ 1 + + +``` + +#### `CoreReader.Agency.GeneratingSystem` + +`CoreReader/Agency.lean:126–133`; structure. + +```lean +structure GeneratingSystem where + owner : Nat + policy : Policy + current : State + execute : ExternalResources → Option Nat + applicationBudget : Nat + requiredOperations : List Operation + +``` + +#### `CoreReader.Agency.generatingSystem` + +`CoreReader/Agency.lean:134–141`; def. + +```lean +def generatingSystem : GeneratingSystem where + owner := 0 + policy := openPolicy + current := baseState + execute := assistedExecution + applicationBudget := 1 + requiredOperations := [.copy] + +``` + +#### `CoreReader.Agency.GeneratingSystem.stableAction` + +`CoreReader/Agency.lean:142–142`; def. + +```lean +def GeneratingSystem.stableAction (system : GeneratingSystem) : State := system.current +``` + +#### `CoreReader.Agency.GeneratingSystem.requirementsMet` + +`CoreReader/Agency.lean:143–144`; def. + +```lean +def GeneratingSystem.requirementsMet (system : GeneratingSystem) (state : State) : Prop := + ∀ operation, operation ∈ system.requiredOperations → operation ∈ state.constructed +``` + +#### `CoreReader.Agency.GeneratingSystem.withinBudget` + +`CoreReader/Agency.lean:145–147`; def. + +```lean +def GeneratingSystem.withinBudget (system : GeneratingSystem) (state : State) : Prop := + state.inventory.length ≤ system.applicationBudget + +``` + +#### `CoreReader.Agency.Announcement` + +`CoreReader/Agency.lean:148–156`; structure. + +```lean +structure Announcement where + owner : Nat + before : State + after : State + reportedNewOperation : Operation + input : Nat + expectedOutput : Nat + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Agency.GeneratingSystem.report` + +`CoreReader/Agency.lean:157–160`; def. + +```lean +def GeneratingSystem.report (system : GeneratingSystem) (after : State) + (operation : Operation) (input expectedOutput : Nat) : Announcement := + ⟨system.owner, system.current, after, operation, input, expectedOutput⟩ + +``` + +#### `CoreReader.Agency.Announcement.claim` + +`CoreReader/Agency.lean:161–165`; def. + +```lean +def Announcement.claim (report : Announcement) : Prop := + report.reportedNewOperation ∈ report.after.constructed ∧ + report.reportedNewOperation ∉ report.before.constructed ∧ + report.reportedNewOperation.run report.input = report.expectedOutput + +``` + +#### `CoreReader.Agency.announcementClaimImpliesExpansion` + +`CoreReader/Agency.lean:166–168`; theorem. + +```lean +theorem announcementClaimImpliesExpansion (report : Announcement) (h : report.claim) : + Expanded report.before report.after := Or.inr ⟨report.reportedNewOperation, h.1, h.2.1⟩ + +``` + +#### `CoreReader.Agency.inflatedAnnouncement` + +`CoreReader/Agency.lean:169–170`; def. + +```lean +def inflatedAnnouncement : Announcement := generatingSystem.report inflatedState .successor 0 1 + +``` + +#### `CoreReader.Agency.inflatedAnnouncementRefuted` + +`CoreReader/Agency.lean:171–178`; theorem. + +```lean +theorem inflatedAnnouncementRefuted : + inflatedAnnouncement.before = baseState ∧ inflatedAnnouncement.after = inflatedState ∧ + inflatedAnnouncement.reportedNewOperation = .successor ∧ + inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧ + ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after := by + simp [inflatedAnnouncement, GeneratingSystem.report, generatingSystem, Announcement.claim, Expanded, baseState, inflatedState] + + +``` + +#### `CoreReader.Agency.TransitionCase` + +`CoreReader/Agency.lean:179–181`; inductive. + +```lean +inductive TransitionCase | inflate | extend + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Agency.extendedState` + +`CoreReader/Agency.lean:182–183`; def. + +```lean +def extendedState : State := + { baseState with understood := [.copy, .successor], constructed := [.copy, .successor] } +``` + +#### `CoreReader.Agency.transitionBefore` + +`CoreReader/Agency.lean:184–184`; def. + +```lean +def transitionBefore (_transition : TransitionCase) : State := baseState +``` + +#### `CoreReader.Agency.transitionAfter` + +`CoreReader/Agency.lean:185–188`; def. + +```lean +def transitionAfter : TransitionCase → State + | .inflate => inflatedState + | .extend => extendedState + +``` + +#### `CoreReader.Agency.transitionInput` + +`CoreReader/Agency.lean:189–189`; def. + +```lean +def transitionInput (_transition : TransitionCase) : Nat := 0 +``` + +#### `CoreReader.Agency.transitionAnnouncement` + +`CoreReader/Agency.lean:190–193`; def. + +```lean +def transitionAnnouncement (transition : TransitionCase) : Announcement := + generatingSystem.report (transitionAfter transition) .successor (transitionInput transition) 1 + + +``` + +#### `CoreReader.Agency.generationLimits` + +`CoreReader/Agency.lean:194–223`; theorem. + +```lean +theorem generationLimits : + Generative generatingSystem.policy ∧ + generatingSystem.policy.permitsVersion 0 0 ∧ + ¬ Expanded generatingSystem.current inflatedState ∧ + generatingSystem.current.inventory.length < inflatedState.inventory.length ∧ + generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧ + generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧ + generatingSystem.execute availableResources = some 6 ∧ + generatingSystem.execute { availableResources with experience := none } = none ∧ + generatingSystem.execute { availableResources with knowledge := none } = none ∧ + generatingSystem.execute { availableResources with collaborator := none } = none ∧ + generatingSystem.execute ⟨none, none, none⟩ = none ∧ + ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧ + generatingSystem.stableAction = generatingSystem.current ∧ + generatingSystem.requirementsMet generatingSystem.stableAction ∧ + generatingSystem.withinBudget generatingSystem.stableAction ∧ + ¬ generatingSystem.withinBudget inflatedState ∧ + StableReason generatingSystem.current inflatedState ∧ + (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧ + inflatedAnnouncement.owner = generatingSystem.owner ∧ + inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧ + inflatedAnnouncement.reportedNewOperation = .successor ∧ + inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧ + ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after) := by + simp [generatingSystem, GeneratingSystem.stableAction, GeneratingSystem.requirementsMet, + GeneratingSystem.withinBudget, GeneratingSystem.report, Generative, openPolicy, Expanded, + baseState, inflatedState, assistedExecution, availableResources, Operation.run, + StableReason, inflatedAnnouncement, Announcement.claim] + + +``` + +#### `CoreReader.Agency.generationNotReflexivity` + +`CoreReader/Agency.lean:224–233`; theorem. + +```lean +theorem generationNotReflexivity : + Generative openPolicy ∧ ¬ Reflexive 0 (ownRules 0) [] := by + constructor + · simp [Generative, openPolicy] + · intro h + have bad := noSelfExemption 0 (ownRules 0) [] h (assessingRule 0) (by simp [ownRules]) + (.system 0) rfl (by simp [assessingRule, ownSubjects]) + simp [Performed] at bad + + +``` + +#### `CoreReader.Agency.ownArithmeticPrinciple` + +`CoreReader/Agency.lean:234–235`; def. + +```lean +def ownArithmeticPrinciple (n : Nat) : Bool := decide (n + 1 = 2 * n) + +``` + +#### `CoreReader.Agency.selfTest` + +`CoreReader/Agency.lean:236–238`; def. + +```lean +def selfTest (samples : List Nat) : Bool := samples.all ownArithmeticPrinciple + + +``` + +#### `CoreReader.Agency.selfTestDoesNotProve` + +`CoreReader/Agency.lean:239–250`; theorem. + +```lean +theorem selfTestDoesNotProve : + selfTest [1] = true ∧ ownArithmeticPrinciple 0 = false ∧ + ¬ (∀ n, ownArithmeticPrinciple n = true) := by + constructor + · decide + constructor + · decide + · intro h + have bad := h 0 + contradiction + +end CoreReader.Agency +``` + +### CoreReader/Choice.lean + +#### `CoreReader.Choice.StatusKind` + +`CoreReader/Choice.lean:6–8`; inductive. + +```lean +inductive StatusKind | name | convention | standing + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Choice.MethodReason` + +`CoreReader/Choice.lean:9–11`; inductive. + +```lean +inductive MethodReason | output | explanation | applicability | simplicity | procedure + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Choice.Reason` + +`CoreReader/Choice.lean:12–15`; inductive. + +```lean +inductive Reason | status (kind : StatusKind) | method (kind : MethodReason) + deriving DecidableEq, Repr + + +``` + +#### `CoreReader.Choice.Implementation` + +`CoreReader/Choice.lean:16–26`; structure. + +```lean +structure Implementation where + name : String + conventional : Bool + established : Bool + run : Nat → Nat + cost : Nat + domain : Nat → Prop + explanation : Nat → Nat + trace : Nat → List Nat + + +``` + +#### `CoreReader.Choice.Requirements` + +`CoreReader/Choice.lean:27–33`; structure. + +```lean +structure Requirements where + inputs : Nat → Prop + expected : Nat → Nat + budget : Nat + values : MethodReason → Prop + + +``` + +#### `CoreReader.Choice.MethodContent` + +`CoreReader/Choice.lean:34–41`; def. + +```lean +def MethodContent (req : Requirements) (i : Implementation) : MethodReason → Prop + | .output => ∀ x, req.inputs x → i.run x = req.expected x + | .explanation => ∀ x, req.inputs x → i.explanation x = i.run x + | .applicability => ∀ x, req.inputs x → i.domain x + | .simplicity => i.cost ≤ req.budget + | .procedure => ∀ x, req.inputs x → (i.trace x).getLast? = some (i.run x) + + +``` + +#### `CoreReader.Choice.Relevant` + +`CoreReader/Choice.lean:42–45`; def. + +```lean +def Relevant (req : Requirements) (i : Implementation) : Reason → Prop + | .status _ => False + | .method kind => req.values kind ∧ MethodContent req i kind + +``` + +#### `CoreReader.Choice.Feasible` + +`CoreReader/Choice.lean:46–49`; def. + +```lean +def Feasible (req : Requirements) (i : Implementation) : Prop := + (∀ x, req.inputs x → i.run x = req.expected x) ∧ i.cost ≤ req.budget + + +``` + +#### `CoreReader.Choice.JustifiedChoice` + +`CoreReader/Choice.lean:50–53`; def. + +```lean +def JustifiedChoice (req : Requirements) (i : Implementation) (reasons : List Reason) : Prop := + Feasible req i ∧ ∃ reason ∈ reasons, Relevant req i reason + + +``` + +#### `CoreReader.Choice.statusOnlyFails` + +`CoreReader/Choice.lean:54–60`; theorem. + +```lean +theorem statusOnlyFails (req : Requirements) (i : Implementation) (k : StatusKind) : + ¬ JustifiedChoice req i [.status k] := by + rintro ⟨_, reason, hr, hv⟩ + simp only [List.mem_singleton] at hr + subst reason + exact hv + +``` + +#### `CoreReader.Choice.identityImpl` + +`CoreReader/Choice.lean:61–70`; def. + +```lean +def identityImpl : Implementation where + name := "Existing identity implementation" + conventional := true + established := true + run n := n + cost := 1 + domain _ := True + explanation n := n + trace n := [n] + +``` + +#### `CoreReader.Choice.successorImpl` + +`CoreReader/Choice.lean:71–80`; def. + +```lean +def successorImpl : Implementation where + name := "Successor implementation" + conventional := false + established := false + run n := n + 1 + cost := 2 + domain _ := True + explanation n := n + 1 + trace n := [n, n + 1] + +``` + +#### `CoreReader.Choice.changedOutsideZero` + +`CoreReader/Choice.lean:81–89`; def. + +```lean +def changedOutsideZero : Implementation := + { identityImpl with + name := "Changed outside zero" + conventional := false + established := false + run := fun n => if n = 0 then 0 else n + 1 + explanation := fun n => if n = 0 then 0 else n + 1 + trace := fun n => [if n = 0 then 0 else n + 1] } + +``` + +#### `CoreReader.Choice.identityRequirements` + +`CoreReader/Choice.lean:90–95`; def. + +```lean +def identityRequirements : Requirements where + inputs _ := True + expected n := n + budget := 1 + values _ := True + +``` + +#### `CoreReader.Choice.objectiveReason` + +`CoreReader/Choice.lean:96–97`; def. + +```lean +def objectiveReason : List Reason := [.method .output] + +``` + +#### `CoreReader.Choice.identityOutputReason` + +`CoreReader/Choice.lean:98–100`; theorem. + +```lean +theorem identityOutputReason : Relevant identityRequirements identityImpl (.method .output) := by + exact ⟨trivial, fun _ _ => rfl⟩ + +``` + +#### `CoreReader.Choice.identityFeasible` + +`CoreReader/Choice.lean:101–103`; theorem. + +```lean +theorem identityFeasible : Feasible identityRequirements identityImpl := + ⟨fun _ _ => rfl, by decide⟩ + +``` + +#### `CoreReader.Choice.identityJustified` + +`CoreReader/Choice.lean:104–107`; theorem. + +```lean +theorem identityJustified : JustifiedChoice identityRequirements identityImpl objectiveReason := + ⟨identityFeasible, .method .output, by simp [objectiveReason], identityOutputReason⟩ + + +``` + +#### `CoreReader.Choice.conventionWithReason` + +`CoreReader/Choice.lean:108–112`; theorem. + +```lean +theorem conventionWithReason : + identityImpl.conventional = true ∧ identityImpl.established = true ∧ + JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output] := by + exact ⟨rfl, rfl, identityFeasible, .method .output, by simp, identityOutputReason⟩ + +``` + +#### `CoreReader.Choice.Candidate` + +`CoreReader/Choice.lean:113–115`; inductive. + +```lean +inductive Candidate | identity | successor + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Choice.implementation` + +`CoreReader/Choice.lean:116–120`; def. + +```lean +def implementation : Candidate → Implementation + | .identity => identityImpl + | .successor => successorImpl + + +``` + +#### `CoreReader.Choice.singleFeasible` + +`CoreReader/Choice.lean:121–131`; theorem. + +```lean +theorem singleFeasible : + (∀ candidate, Feasible identityRequirements (implementation candidate) ↔ candidate = .identity) ∧ + JustifiedChoice identityRequirements identityImpl objectiveReason := by + constructor + · intro candidate + cases candidate + · simp [Feasible, identityRequirements, implementation, identityImpl] + · simp [Feasible, identityRequirements, implementation, successorImpl] + · exact identityJustified + + +``` + +#### `CoreReader.Choice.localNotGlobal` + +`CoreReader/Choice.lean:132–139`; theorem. + +```lean +theorem localNotGlobal : + (∀ x, x = 0 → identityImpl.run x = changedOutsideZero.run x) ∧ + identityImpl.run 1 ≠ changedOutsideZero.run 1 := by + constructor + · intro x hx; subst x; rfl + · decide + + +``` + +#### `CoreReader.Choice.cheapSuccessor` + +`CoreReader/Choice.lean:140–141`; def. + +```lean +def cheapSuccessor : Implementation := { successorImpl with cost := 1 } + +``` + +#### `CoreReader.Choice.eligibleInternalReasonNotSufficient` + +`CoreReader/Choice.lean:142–150`; theorem. + +```lean +theorem eligibleInternalReasonNotSufficient : + Relevant identityRequirements cheapSuccessor (.method .simplicity) ∧ + ¬ JustifiedChoice identityRequirements cheapSuccessor [.method .simplicity] := by + refine ⟨⟨trivial, by change 1 ≤ 1; decide⟩, ?_⟩ + intro h + have bad := h.1.1 0 trivial + cases bad + + +``` + +#### `CoreReader.Choice.internalReasons` + +`CoreReader/Choice.lean:151–161`; theorem. + +```lean +theorem internalReasons : + Relevant identityRequirements identityImpl (.method .explanation) ∧ + Relevant identityRequirements identityImpl (.method .applicability) ∧ + Relevant identityRequirements identityImpl (.method .simplicity) ∧ + Relevant identityRequirements identityImpl (.method .procedure) ∧ + (Relevant identityRequirements cheapSuccessor (.method .simplicity) ∧ + ¬ JustifiedChoice identityRequirements cheapSuccessor [.method .simplicity]) := by + exact ⟨⟨trivial, fun _ _ => rfl⟩, ⟨trivial, fun _ _ => trivial⟩, + ⟨trivial, by change 1 ≤ 1; decide⟩, ⟨trivial, fun _ _ => rfl⟩, eligibleInternalReasonNotSufficient⟩ + + +``` + +#### `CoreReader.Choice.openNotEquivalent` + +`CoreReader/Choice.lean:162–167`; theorem. + +```lean +theorem openNotEquivalent : + JustifiedChoice identityRequirements identityImpl objectiveReason ∧ + identityImpl.run 0 ≠ successorImpl.run 0 := by + exact ⟨identityJustified, by decide⟩ + + +``` + +#### `CoreReader.Choice.priorityClaim` + +`CoreReader/Choice.lean:168–169`; def. + +```lean +def priorityClaim : Claim Candidate := fun selected => selected = .identity + +``` + +#### `CoreReader.Choice.statusFacts` + +`CoreReader/Choice.lean:170–174`; def. + +```lean +def statusFacts : Theory Candidate := union + (singleton (fun _ => identityImpl.conventional = true)) + (singleton (fun _ => identityImpl.established = true)) + + +``` + +#### `CoreReader.Choice.statusFactsModel` + +`CoreReader/Choice.lean:175–177`; theorem. + +```lean +theorem statusFactsModel (selected : Candidate) : Models statusFacts selected := by + exact (modelsUnion _ _ _).2 ⟨(modelsSingleton _ _).2 rfl, (modelsSingleton _ _).2 rfl⟩ + +``` + +#### `CoreReader.Choice.priorityArticulation` + +`CoreReader/Choice.lean:178–183`; def. + +```lean +def priorityArticulation : Articulation Candidate := + ⟨["priority", "conventional use", "established status"], statusFacts, + [fun _ => identityImpl.conventional = true, fun _ => identityImpl.established = true], + fun _ => True⟩ + + +``` + +#### `CoreReader.Choice.AssessmentAccurate` + +`CoreReader/Choice.lean:184–186`; def. + +```lean +def AssessmentAccurate (report : Bool) : Prop := + report = true ↔ Entails statusFacts priorityClaim + +``` + +#### `CoreReader.Choice.statusDoesNotEntailPriority` + +`CoreReader/Choice.lean:187–191`; theorem. + +```lean +theorem statusDoesNotEntailPriority : ¬ Entails statusFacts priorityClaim := by + intro h + have bad := h .successor (statusFactsModel .successor) + cases bad + +``` + +#### `CoreReader.Choice.statusAssessmentNonEntailment` + +`CoreReader/Choice.lean:192–203`; theorem. + +```lean +theorem statusAssessmentNonEntailment : + Articulated priorityArticulation ∧ AssessmentAccurate false ∧ + (∀ selected, Models statusFacts selected) ∧ + priorityClaim .identity ∧ ¬ priorityClaim .successor ∧ + ¬ Entails statusFacts priorityClaim ∧ + ¬ JustifiedChoice identityRequirements identityImpl [.status .standing] := by + refine ⟨⟨by simp [priorityArticulation], by simp [priorityArticulation]⟩, + ⟨(by intro h; cases h), (fun h => False.elim (statusDoesNotEntailPriority h))⟩, + statusFactsModel, rfl, (by intro h; cases h), statusDoesNotEntailPriority, + statusOnlyFails _ _ _⟩ + + +``` + +#### `CoreReader.Choice.PriorityAssessment` + +`CoreReader/Choice.lean:204–208`; structure. + +```lean +structure PriorityAssessment where + premises : Theory Candidate + question : Claim Candidate + report : Bool + +``` + +#### `CoreReader.Choice.PriorityAssessment.accurate` + +`CoreReader/Choice.lean:209–211`; def. + +```lean +def PriorityAssessment.accurate (assessment : PriorityAssessment) : Prop := + assessment.report = true ↔ Entails assessment.premises assessment.question + +``` + +#### `CoreReader.Choice.statusPriorityAudit` + +`CoreReader/Choice.lean:212–213`; def. + +```lean +def statusPriorityAudit : PriorityAssessment := ⟨statusFacts, priorityClaim, false⟩ + +``` + +#### `CoreReader.Choice.ChoicePolicy` + +`CoreReader/Choice.lean:214–218`; structure. + +```lean +structure ChoicePolicy where + selected : Candidate + priorityReasons : List Reason + assessment : PriorityAssessment + +``` + +#### `CoreReader.Choice.GeneralAssessmentFulfilled` + +`CoreReader/Choice.lean:219–221`; def. + +```lean +def GeneralAssessmentFulfilled (policy : ChoicePolicy) : Prop := + Articulated priorityArticulation ∧ policy.assessment = statusPriorityAudit ∧ policy.assessment.accurate + +``` + +#### `CoreReader.Choice.AdditionalChoiceNorm` + +`CoreReader/Choice.lean:222–224`; def. + +```lean +def AdditionalChoiceNorm (policy : ChoicePolicy) : Prop := + JustifiedChoice identityRequirements (implementation policy.selected) policy.priorityReasons + +``` + +#### `CoreReader.Choice.statusPriorityPolicy` + +`CoreReader/Choice.lean:225–226`; def. + +```lean +def statusPriorityPolicy : ChoicePolicy := ⟨.identity, [.status .standing], statusPriorityAudit⟩ + +``` + +#### `CoreReader.Choice.outputPriorityPolicy` + +`CoreReader/Choice.lean:227–228`; def. + +```lean +def outputPriorityPolicy : ChoicePolicy := ⟨.identity, objectiveReason, statusPriorityAudit⟩ + +``` + +#### `CoreReader.Choice.statusPriorityAuditAccurate` + +`CoreReader/Choice.lean:229–233`; theorem. + +```lean +theorem statusPriorityAuditAccurate : statusPriorityAudit.accurate := by + constructor + · intro h; cases h + · intro h; exact False.elim (statusDoesNotEntailPriority h) + +``` + +#### `CoreReader.Choice.PolicyIndependenceExample` + +`CoreReader/Choice.lean:234–244`; def. + +```lean +def PolicyIndependenceExample : Prop := + statusPriorityPolicy.selected = outputPriorityPolicy.selected ∧ + statusPriorityPolicy.assessment = outputPriorityPolicy.assessment ∧ + statusPriorityPolicy.assessment.premises = statusFacts ∧ + statusPriorityPolicy.assessment.question = priorityClaim ∧ + statusPriorityPolicy.assessment.report = false ∧ + (∀ selected, Models statusPriorityPolicy.assessment.premises selected) ∧ + statusPriorityPolicy.priorityReasons ≠ outputPriorityPolicy.priorityReasons ∧ + GeneralAssessmentFulfilled statusPriorityPolicy ∧ GeneralAssessmentFulfilled outputPriorityPolicy ∧ + ¬ AdditionalChoiceNorm statusPriorityPolicy ∧ AdditionalChoiceNorm outputPriorityPolicy + +``` + +#### `CoreReader.Choice.policyIndependenceExample` + +`CoreReader/Choice.lean:245–256`; theorem. + +```lean +theorem policyIndependenceExample : PolicyIndependenceExample := by + have articulated : Articulated priorityArticulation := + ⟨by simp [priorityArticulation], by simp [priorityArticulation]⟩ + refine ⟨rfl,rfl,rfl,rfl,rfl,statusFactsModel,?_, + ⟨articulated,rfl,statusPriorityAuditAccurate⟩, + ⟨articulated,rfl,statusPriorityAuditAccurate⟩,?_,?_⟩ + · decide + · exact statusOnlyFails identityRequirements identityImpl .standing + · exact identityJustified + + + +``` + +#### `CoreReader.Choice.generalGroundsNotChoice` + +`CoreReader/Choice.lean:257–266`; theorem. + +```lean +theorem generalGroundsNotChoice : + (Articulated priorityArticulation ∧ AssessmentAccurate false ∧ + (∀ selected, Models statusFacts selected) ∧ + priorityClaim .identity ∧ ¬ priorityClaim .successor ∧ + ¬ Entails statusFacts priorityClaim ∧ + ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧ + PolicyIndependenceExample := + ⟨statusAssessmentNonEntailment, policyIndependenceExample⟩ + +end CoreReader.Choice +``` + +### CoreReader/Engineering/Domain.lean + +#### `CoreReader.Engineering.Maintainer` + +`CoreReader/Engineering/Domain.lean:7–9`; inductive. + +```lean +inductive Maintainer where + | original | successor | agent + deriving DecidableEq, Repr +``` + +#### `CoreReader.Engineering.Tool` + +`CoreReader/Engineering/Domain.lean:10–12`; inductive. + +```lean +inductive Tool where + | editor | compiler | contractRunner | migrationRunner + deriving DecidableEq, Repr +``` + +#### `CoreReader.Engineering.Knowledge` + +`CoreReader/Engineering/Domain.lean:13–15`; inductive. + +```lean +inductive Knowledge where + | privateLayout | publicContract | changeGuide | migrationGuide + deriving DecidableEq, Repr +``` + +#### `CoreReader.Engineering.Change` + +`CoreReader/Engineering/Domain.lean:16–19`; inductive. + +```lean +inductive Change where + | addition | replacement | deletion | withdrawal | redrawing | migration + | independent | coordinated | designRevision | other (name : String) + deriving DecidableEq, Repr +``` + +#### `CoreReader.Engineering.Candidate` + +`CoreReader/Engineering/Domain.lean:20–22`; inductive. + +```lean +inductive Candidate where + | presentSimple | evolvable | maximal + deriving DecidableEq, Repr +``` + +#### `CoreReader.Engineering.Burden` + +`CoreReader/Engineering/Domain.lean:23–27`; inductive. + +```lean +inductive Burden where + | understanding | construction | diagnosis | verification | coordination + | operation | migration + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Engineering.maintainers` + +`CoreReader/Engineering/Domain.lean:28–28`; def. + +```lean +def maintainers : List Maintainer := [.original, .successor, .agent] +``` + +#### `CoreReader.Engineering.changes` + +`CoreReader/Engineering/Domain.lean:29–30`; def. + +```lean +def changes : List Change := [.addition, .replacement, .deletion, .withdrawal, + .redrawing, .migration, .independent, .coordinated, .designRevision] +``` + +#### `CoreReader.Engineering.burdens` + +`CoreReader/Engineering/Domain.lean:31–33`; def. + +```lean +def burdens : List Burden := [.understanding, .construction, .diagnosis, + .verification, .coordination, .operation, .migration] + +``` + +#### `CoreReader.Engineering.Activity` + +`CoreReader/Engineering/Domain.lean:34–43`; structure. + +```lean +structure Activity where + participants : List Maintainer + software : String + tools : List Tool + available : Maintainer → List Knowledge + scheduledReleases : Nat + scheduledMaintenance : Nat + boundedRuns : Option Nat + label : String + +``` + +#### `CoreReader.Engineering.ActivityScope` + +`CoreReader/Engineering/Domain.lean:44–47`; abbrev. + +```lean +abbrev ActivityScope (a : Activity) : Prop := + a.participants ≠ [] ∧ a.software ≠ "" ∧ a.tools ≠ [] ∧ + a.participants.all (fun m => !(a.available m).isEmpty) = true + +``` + +#### `CoreReader.Engineering.Continuing` + +`CoreReader/Engineering/Domain.lean:48–50`; abbrev. + +```lean +abbrev Continuing (a : Activity) : Prop := + 0 < a.scheduledReleases ∧ 0 < a.scheduledMaintenance + +``` + +#### `CoreReader.Engineering.BoundedLifecycle` + +`CoreReader/Engineering/Domain.lean:51–54`; abbrev. + +```lean +abbrev BoundedLifecycle (a : Activity) : Prop := + a.boundedRuns.isSome = true ∧ a.scheduledReleases = 0 ∧ + a.scheduledMaintenance = 0 + +``` + +#### `CoreReader.Engineering.continuingActivity` + +`CoreReader/Engineering/Domain.lean:55–63`; def. + +```lean +def continuingActivity : Activity := { + participants := maintainers, software := "order-preserving queue", + tools := [.editor, .compiler, .contractRunner, .migrationRunner], + available := fun m => match m with + | .original => [.privateLayout, .publicContract, .changeGuide, .migrationGuide] + | _ => [.publicContract, .changeGuide, .migrationGuide], + scheduledReleases := 3, scheduledMaintenance := 6, + boundedRuns := none, label := "temporary" } + +``` + +#### `CoreReader.Engineering.temporaryActivity` + +`CoreReader/Engineering/Domain.lean:64–66`; def. + +```lean +def temporaryActivity : Activity := { continuingActivity with + scheduledReleases := 0, scheduledMaintenance := 0, boundedRuns := some 1, + label := "one-shot import" } +``` + +#### `CoreReader.Engineering.prototypeActivity` + +`CoreReader/Engineering/Domain.lean:67–68`; def. + +```lean +def prototypeActivity : Activity := { temporaryActivity with + boundedRuns := some 4, label := "bounded prototype" } +``` + +#### `CoreReader.Engineering.retiringActivity` + +`CoreReader/Engineering/Domain.lean:69–71`; def. + +```lean +def retiringActivity : Activity := { temporaryActivity with + boundedRuns := some 2, label := "retiring service" } + +``` + +#### `CoreReader.Engineering.EditStep` + +`CoreReader/Engineering/Domain.lean:72–78`; structure. + +```lean +structure EditStep where + component : Nat + requires : Knowledge + tool : Tool + units : Nat + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Engineering.changePath` + +`CoreReader/Engineering/Domain.lean:79–98`; def. + +```lean +def changePath (c : Candidate) (d : Change) : List EditStep := + let guide := if c = .presentSimple then Knowledge.privateLayout else .changeGuide + let base : List EditStep := [⟨0, guide, .editor, 1⟩, + ⟨0, .publicContract, .contractRunner, 1⟩] + match d with + | .addition | .independent => base + | .replacement | .deletion => base ++ [⟨1, guide, .compiler, 1⟩] + | .coordinated => base ++ [⟨1, guide, .compiler, 3⟩, ⟨2, .publicContract, .contractRunner, 3⟩] + | .migration => base ++ [⟨1, .migrationGuide, .migrationRunner, 8⟩] + | .withdrawal | .redrawing | .designRevision => + if c = .presentSimple then base ++ + [⟨1, guide, .editor, 5⟩, ⟨2, guide, .compiler, 5⟩, + ⟨2, .publicContract, .contractRunner, 5⟩] + else base ++ [⟨1, guide, .editor, 2⟩, ⟨1, .publicContract, .contractRunner, 2⟩] + | .other name => + if name = "csv export" then + if c = .maximal then base ++ [⟨3, .migrationGuide, .compiler, 2⟩] + else base ++ [⟨3, .privateLayout, .compiler, 20⟩] + else [] + +``` + +#### `CoreReader.Engineering.changeWork` + +`CoreReader/Engineering/Domain.lean:99–101`; def. + +```lean +def changeWork (c : Candidate) (d : Change) : Nat := + ((changePath c d).map EditStep.units).sum + +``` + +#### `CoreReader.Engineering.CanChange` + +`CoreReader/Engineering/Domain.lean:102–105`; abbrev. + +```lean +abbrev CanChange (a : Activity) (c : Candidate) (m : Maintainer) (d : Change) : Prop := + (changePath c d) ≠ [] ∧ m ∈ a.participants ∧ (changePath c d).all + (fun step => (a.available m).contains step.requires && a.tools.contains step.tool) = true + +``` + +#### `CoreReader.Engineering.ContinuingCapability` + +`CoreReader/Engineering/Domain.lean:106–112`; abbrev. + +```lean +abbrev ContinuingCapability (a : Activity) (c : Candidate) (d : Change) : Prop := + (changePath c d) ≠ [] ∧ a.participants.all (fun m => (changePath c d).all + (fun step => (a.available m).contains step.requires && a.tools.contains step.tool)) = true + + + + +``` + +#### `CoreReader.Engineering.registeredDirections` + +`CoreReader/Engineering/Domain.lean:113–113`; def. + +```lean +def registeredDirections : List Change := changes ++ [.other "csv export"] +``` + +#### `CoreReader.Engineering.supportedDirections` + +`CoreReader/Engineering/Domain.lean:114–115`; def. + +```lean +def supportedDirections (a : Activity) (c : Candidate) : List Change := + registeredDirections.filter (fun d => decide (ContinuingCapability a c d)) +``` + +#### `CoreReader.Engineering.MaximumRegisteredCapability` + +`CoreReader/Engineering/Domain.lean:116–120`; abbrev. + +```lean +abbrev MaximumRegisteredCapability (a : Activity) (c : Candidate) : Prop := + registeredDirections.all (fun d => decide (ContinuingCapability a c d)) = true + + + +``` + +#### `CoreReader.Engineering.passiveArtifact` + +`CoreReader/Engineering/Domain.lean:121–122`; def. + +```lean +def passiveArtifact (xs : List Nat) : List Nat := xs + +``` + +#### `CoreReader.Engineering.orientation` + +`CoreReader/Engineering/Domain.lean:123–124`; def. + +```lean +def orientation : Maintainer → List Change := fun _ => [.designRevision, .migration] + +``` + +#### `CoreReader.Engineering.EngineeringAction` + +`CoreReader/Engineering/Domain.lean:125–129`; inductive. + +```lean +inductive EngineeringAction where + | propose (direction : Change) + | execute (result : List Nat) + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Engineering.maintainerActions` + +`CoreReader/Engineering/Domain.lean:130–132`; def. + +```lean +def maintainerActions (m : Maintainer) : List EngineeringAction := + (orientation m).map EngineeringAction.propose + +``` + +#### `CoreReader.Engineering.artifactActions` + +`CoreReader/Engineering/Domain.lean:133–135`; def. + +```lean +def artifactActions (input : List Nat) : List EngineeringAction := + [.execute (passiveArtifact input)] + +``` + +#### `CoreReader.Engineering.subjectLifecycleCases` + +`CoreReader/Engineering/Domain.lean:136–143`; theorem. + +```lean +theorem subjectLifecycleCases : + ActivityScope continuingActivity ∧ + CanChange continuingActivity .evolvable .successor .designRevision ∧ + CanChange continuingActivity .evolvable .agent .designRevision ∧ + continuingActivity.label = "temporary" ∧ Continuing continuingActivity ∧ + ¬ BoundedLifecycle continuingActivity ∧ BoundedLifecycle temporaryActivity ∧ + BoundedLifecycle prototypeActivity ∧ BoundedLifecycle retiringActivity := by decide + +``` + +#### `CoreReader.Engineering.subjectLimits` + +`CoreReader/Engineering/Domain.lean:144–154`; theorem. + +```lean +theorem subjectLimits : + CanChange continuingActivity .presentSimple .original .designRevision ∧ + ¬ CanChange continuingActivity .presentSimple .successor .designRevision ∧ + ¬ ContinuingCapability continuingActivity .presentSimple .designRevision ∧ + continuingActivity.label = "temporary" ∧ ¬ BoundedLifecycle continuingActivity ∧ + orientation .agent ≠ [] ∧ passiveArtifact [2, 1] = [2, 1] ∧ + EngineeringAction.propose .designRevision ∈ maintainerActions .agent ∧ + EngineeringAction.propose .designRevision ∉ artifactActions [2, 1] := by decide + + + +``` + +#### `CoreReader.Engineering.CredibleDirection` + +`CoreReader/Engineering/Domain.lean:155–159`; abbrev. + +```lean +abbrev CredibleDirection {Ground : Type} (grounds : List Ground) + (articulated : Ground → Bool) (supports : Ground → Change → Bool) + (d : Change) : Prop := + grounds.any (fun g => articulated g && supports g d) = true + +``` + +#### `CoreReader.Engineering.DirectionGround` + +`CoreReader/Engineering/Domain.lean:160–166`; inductive. + +```lean +inductive DirectionGround where + | plan (release : Nat) (committed : List Change) + | knowledge (service : String) (affected : List Change) (mechanism : String) + | history (service : String) (observed : List Change) + | other (account : String) (supported : List Change) + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Engineering.articulateGround` + +`CoreReader/Engineering/Domain.lean:167–172`; def. + +```lean +def articulateGround : DirectionGround → Bool + | .plan release ds => release > 0 && !ds.isEmpty + | .knowledge service ds mechanism => service != "" && !ds.isEmpty && mechanism != "" + | .history service ds => service != "" && !ds.isEmpty + | .other account ds => account != "" && !ds.isEmpty + +``` + +#### `CoreReader.Engineering.supportGround` + +`CoreReader/Engineering/Domain.lean:173–179`; def. + +```lean +def supportGround : DirectionGround → Change → Bool + | .plan release ds, d => release > 0 && ds.contains d + | .knowledge service ds mechanism, d => + service == "queue" && mechanism == "tenant-config-reload" && ds.contains d + | .history service ds, d => service == "queue" && (ds.filter (· == d)).length >= 2 + | .other account ds, d => account == "reviewed customer migration requirement" && ds.contains d + +``` + +#### `CoreReader.Engineering.initialGrounds` + +`CoreReader/Engineering/Domain.lean:180–180`; abbrev. + +```lean +abbrev initialGrounds : List DirectionGround := [.plan 2 [.designRevision, .migration]] +``` + +#### `CoreReader.Engineering.forecastGrounds` + +`CoreReader/Engineering/Domain.lean:181–181`; def. + +```lean +def forecastGrounds : List DirectionGround := [.plan 3 [.deletion]] +``` + +#### `CoreReader.Engineering.credible` + +`CoreReader/Engineering/Domain.lean:182–184`; abbrev. + +```lean +abbrev credible (gs : List DirectionGround) (d : Change) : Prop := + CredibleDirection gs articulateGround supportGround d + +``` + +#### `CoreReader.Engineering.WarrantedAccommodation` + +`CoreReader/Engineering/Domain.lean:185–188`; abbrev. + +```lean +abbrev WarrantedAccommodation (gs : List DirectionGround) (d : Change) + (objectiveGain investment : Nat) : Prop := + credible gs d ∧ 0 < objectiveGain ∧ investment ≤ objectiveGain + +``` + +#### `CoreReader.Engineering.credibilityCases` + +`CoreReader/Engineering/Domain.lean:189–195`; theorem. + +```lean +theorem credibilityCases : + credible initialGrounds .designRevision ∧ + credible [.knowledge "queue" [.designRevision] "tenant-config-reload"] .designRevision ∧ + credible [.history "queue" [.migration, .migration]] .migration ∧ + ¬ credible [] (.other "quantum backend") ∧ + credible forecastGrounds .deletion ∧ ¬ credible forecastGrounds .designRevision := by decide + +``` + +#### `CoreReader.Engineering.abstractionComplexity` + +`CoreReader/Engineering/Domain.lean:196–198`; def. + +```lean +def abstractionComplexity : Candidate → Nat + | .presentSimple => 1 | .evolvable => 3 | .maximal => 30 + +``` + +#### `CoreReader.Engineering.implementedVariants` + +`CoreReader/Engineering/Domain.lean:199–201`; def. + +```lean +def implementedVariants : List Candidate := [.presentSimple] + + +``` + +#### `CoreReader.Engineering.CostVector` + +`CoreReader/Engineering/Domain.lean:202–203`; structure. + +```lean +structure CostVector where + amount : Burden → Nat +``` + +#### `CoreReader.Engineering.CostLimits` + +`CoreReader/Engineering/Domain.lean:204–207`; structure. + +```lean +structure CostLimits where + capacity : Burden → Nat + objective : Burden → String + +``` + +#### `CoreReader.Engineering.cost` + +`CoreReader/Engineering/Domain.lean:208–218`; def. + +```lean +def cost : Candidate → Burden → Nat + | .presentSimple, _ => 1 + | .evolvable, .understanding => 3 + | .evolvable, .construction => 4 + | .evolvable, .diagnosis => 2 + | .evolvable, .verification => 4 + | .evolvable, .coordination => 2 + | .evolvable, .operation => 2 + | .evolvable, .migration => 8 + | .maximal, _ => 40 + +``` + +#### `CoreReader.Engineering.normalLimits` + +`CoreReader/Engineering/Domain.lean:219–229`; def. + +```lean +def normalLimits : CostLimits := { + capacity := fun _ => 12, + objective := fun b => match b with + | .understanding => "successor onboarding capacity" + | .construction => "release construction capacity" + | .diagnosis => "incident diagnosis window" + | .verification => "release verification capacity" + | .coordination => "available team coordination" + | .operation => "runtime resource budget" + | .migration => "retirement migration capacity" } + +``` + +#### `CoreReader.Engineering.Requirements` + +`CoreReader/Engineering/Domain.lean:230–235`; structure. + +```lean +structure Requirements where + orderRequired : Bool + maxUnsafeOperations : Nat + maxLatency : Nat + minRetention : Nat + +``` + +#### `CoreReader.Engineering.normalRequirements` + +`CoreReader/Engineering/Domain.lean:236–236`; def. + +```lean +def normalRequirements : Requirements := ⟨true, 0, 10, 30⟩ +``` + +#### `CoreReader.Engineering.behavior` + +`CoreReader/Engineering/Domain.lean:237–240`; def. + +```lean +def behavior : Candidate → List Nat → List Nat := fun _ xs => xs.eraseDups + + + +``` + +#### `CoreReader.Engineering.CandidateProfile` + +`CoreReader/Engineering/Domain.lean:241–246`; structure. + +```lean +structure CandidateProfile where + orderOutput : List Nat + unsafeOperations : Nat + latency : Nat + retention : Nat + +``` + +#### `CoreReader.Engineering.profile` + +`CoreReader/Engineering/Domain.lean:247–247`; def. + +```lean +def profile (c : Candidate) : CandidateProfile := ⟨behavior c [2, 1, 2], 0, 5, 30⟩ +``` + +#### `CoreReader.Engineering.Meets` + +`CoreReader/Engineering/Domain.lean:248–252`; abbrev. + +```lean +abbrev Meets (r : Requirements) (p : CandidateProfile) : Prop := + (r.orderRequired = true → p.orderOutput = [2, 1]) ∧ + p.unsafeOperations ≤ r.maxUnsafeOperations ∧ p.latency ≤ r.maxLatency ∧ + r.minRetention ≤ p.retention + +``` + +#### `CoreReader.Engineering.Context` + +`CoreReader/Engineering/Domain.lean:253–260`; structure. + +```lean +structure Context where + activity : Activity + required : Requirements + evidence : List DirectionGround + limits : CostLimits + departure : Option Burden + profiles : Candidate → CandidateProfile := profile + +``` + +#### `CoreReader.Engineering.currentContinuing` + +`CoreReader/Engineering/Domain.lean:261–264`; def. + +```lean +def currentContinuing : Context := { + activity := continuingActivity, required := normalRequirements, + evidence := initialGrounds, limits := normalLimits, departure := none } + +``` + +#### `CoreReader.Engineering.ConcreteThreat` + +`CoreReader/Engineering/Domain.lean:265–268`; abbrev. + +```lean +abbrev ConcreteThreat (ctx : Context) (c : Candidate) (b : Burden) : Prop := + cost .presentSimple b < cost c b ∧ ctx.limits.capacity b < cost c b ∧ + ctx.limits.objective b ≠ "" + +``` + +#### `CoreReader.Engineering.HasThreat` + +`CoreReader/Engineering/Domain.lean:269–271`; abbrev. + +```lean +abbrev HasThreat (ctx : Context) (c : Candidate) : Prop := + burdens.any (fun b => decide (ConcreteThreat ctx c b)) = true + +``` + +#### `CoreReader.Engineering.JustifiedDeparture` + +`CoreReader/Engineering/Domain.lean:272–280`; abbrev. + +```lean +abbrev JustifiedDeparture (ctx : Context) (c : Candidate) : Prop := + match ctx.departure with + | none => False + | some b => ConcreteThreat ctx c b + +instance (ctx : Context) (c : Candidate) : Decidable (JustifiedDeparture ctx c) := by + unfold JustifiedDeparture + split <;> infer_instance + +``` + +#### `CoreReader.Engineering.PriorityConditions` + +`CoreReader/Engineering/Domain.lean:281–288`; abbrev. + +```lean +abbrev PriorityConditions (ctx : Context) : Prop := + Continuing ctx.activity ∧ ActivityScope ctx.activity ∧ + Meets ctx.required (ctx.profiles .presentSimple) ∧ Meets ctx.required (ctx.profiles .evolvable) ∧ + credible ctx.evidence .designRevision ∧ + ContinuingCapability ctx.activity .evolvable .designRevision ∧ + changeWork .evolvable .designRevision < changeWork .presentSimple .designRevision ∧ + abstractionComplexity .presentSimple < abstractionComplexity .evolvable + +``` + +#### `CoreReader.Engineering.EvolutionPriority` + +`CoreReader/Engineering/Domain.lean:289–291`; abbrev. + +```lean +abbrev EvolutionPriority (ctx : Context) (chosen : Candidate) : Prop := + PriorityConditions ctx → chosen = .evolvable ∨ JustifiedDeparture ctx .evolvable + +``` + +#### `CoreReader.Engineering.currentPriorityConditions` + +`CoreReader/Engineering/Domain.lean:292–292`; theorem. + +```lean +theorem currentPriorityConditions : PriorityConditions currentContinuing := by decide +``` + +#### `CoreReader.Engineering.currentNoThreat` + +`CoreReader/Engineering/Domain.lean:293–295`; theorem. + +```lean +theorem currentNoThreat : ¬ HasThreat currentContinuing .evolvable ∧ + ¬ JustifiedDeparture currentContinuing .evolvable := by decide + +``` + +#### `CoreReader.Engineering.threatened` + +`CoreReader/Engineering/Domain.lean:296–299`; def. + +```lean +def threatened (b : Burden) : Context := { currentContinuing with + limits := { normalLimits with capacity := fun x => if x = b then 1 else 12 }, + departure := some b } + +``` + +#### `CoreReader.Engineering.priorityWhenApplicable` + +`CoreReader/Engineering/Domain.lean:300–307`; theorem. + +```lean +theorem priorityWhenApplicable (ctx : Context) (chosen : Candidate) + (rule : EvolutionPriority ctx chosen) (applicable : PriorityConditions ctx) + (noDeparture : ¬ JustifiedDeparture ctx .evolvable) : + chosen = .evolvable ∧ + abstractionComplexity .presentSimple < abstractionComplexity chosen := by + have hc := (rule applicable).resolve_right noDeparture + exact ⟨hc, hc ▸ applicable.2.2.2.2.2.2.2⟩ + +``` + +#### `CoreReader.Engineering.currentSimpleViolates` + +`CoreReader/Engineering/Domain.lean:308–312`; theorem. + +```lean +theorem currentSimpleViolates : ¬ EvolutionPriority currentContinuing .presentSimple := by + intro h + have bad := (h currentPriorityConditions).resolve_right currentNoThreat.2 + cases bad + +``` + +#### `CoreReader.Engineering.withEvolvableProfile` + +`CoreReader/Engineering/Domain.lean:313–315`; def. + +```lean +def withEvolvableProfile (p : CandidateProfile) : Context := { currentContinuing with + profiles := fun c => if c = .evolvable then p else profile c } + +``` + +#### `CoreReader.Engineering.unmetRequirementsBlockPriority` + +`CoreReader/Engineering/Domain.lean:316–323`; theorem. + +```lean +theorem unmetRequirementsBlockPriority : + ¬ PriorityConditions (withEvolvableProfile { profile .evolvable with orderOutput := [1, 2] }) ∧ + ¬ PriorityConditions (withEvolvableProfile { profile .evolvable with unsafeOperations := 1 }) ∧ + ¬ PriorityConditions (withEvolvableProfile { profile .evolvable with latency := 11 }) ∧ + ¬ PriorityConditions (withEvolvableProfile { profile .evolvable with retention := 29 }) := by + simp [PriorityConditions, withEvolvableProfile, currentContinuing, Meets, + normalRequirements] + +``` + +#### `CoreReader.Engineering.priorityConditionsCases` + +`CoreReader/Engineering/Domain.lean:324–335`; theorem. + +```lean +theorem priorityConditionsCases : + EvolutionPriority currentContinuing .evolvable ∧ + ¬ Meets normalRequirements { profile .evolvable with orderOutput := [1, 2] } ∧ + ¬ Meets normalRequirements { profile .evolvable with unsafeOperations := 1 } ∧ + ¬ Meets normalRequirements { profile .evolvable with latency := 11 } ∧ + ¬ Meets normalRequirements { profile .evolvable with retention := 29 } ∧ + EvolutionPriority (threatened .verification) .presentSimple ∧ + ¬ JustifiedDeparture { threatened .verification with departure := none } .evolvable ∧ + abstractionComplexity .evolvable < abstractionComplexity .maximal := by + refine ⟨by decide, by decide, by decide, by decide, by decide, by decide, ?_, by decide⟩ + simp [JustifiedDeparture] + +``` + +#### `CoreReader.Engineering.priorityChoices` + +`CoreReader/Engineering/Domain.lean:336–341`; theorem. + +```lean +theorem priorityChoices : + EvolutionPriority currentContinuing .evolvable ∧ + ¬ EvolutionPriority currentContinuing .presentSimple ∧ + EvolutionPriority (threatened .verification) .presentSimple := by + exact ⟨by decide, currentSimpleViolates, by decide⟩ + +``` + +#### `CoreReader.Engineering.credibilityLimits` + +`CoreReader/Engineering/Domain.lean:342–354`; theorem. + +```lean +theorem credibilityLimits : + credible initialGrounds .designRevision ∧ implementedVariants.length = 1 ∧ + ¬ WarrantedAccommodation [] (.other "quantum backend") 0 5 ∧ + ¬ credible initialGrounds (.other "quantum backend") ∧ + EvolutionPriority currentContinuing .evolvable ∧ + abstractionComplexity .evolvable < abstractionComplexity .maximal ∧ + cost .evolvable .construction < cost .evolvable .migration ∧ + ¬ MaximumRegisteredCapability continuingActivity .evolvable ∧ + MaximumRegisteredCapability continuingActivity .maximal ∧ + (supportedDirections continuingActivity .evolvable).length = 9 ∧ + (supportedDirections continuingActivity .maximal).length = 10 ∧ + ¬ credible initialGrounds (.other "csv export") := by decide + +``` + +#### `CoreReader.Engineering.costCases` + +`CoreReader/Engineering/Domain.lean:355–366`; theorem. + +```lean +theorem costCases : + JustifiedDeparture (threatened .understanding) .evolvable ∧ + JustifiedDeparture (threatened .construction) .evolvable ∧ + JustifiedDeparture (threatened .diagnosis) .evolvable ∧ + JustifiedDeparture (threatened .verification) .evolvable ∧ + JustifiedDeparture (threatened .coordination) .evolvable ∧ + JustifiedDeparture (threatened .operation) .evolvable ∧ + JustifiedDeparture (threatened .migration) .evolvable ∧ + ¬ JustifiedDeparture { currentContinuing with departure := some .migration } .evolvable := by decide + + + +``` + +#### `CoreReader.Engineering.orderedUnique` + +`CoreReader/Engineering/Domain.lean:367–367`; def. + +```lean +def orderedUnique (xs : List Nat) : List Nat := xs.eraseDups +``` + +#### `CoreReader.Engineering.orderedRefactor` + +`CoreReader/Engineering/Domain.lean:368–368`; def. + +```lean +def orderedRefactor (xs : List Nat) : List Nat := xs.eraseDups ++ [] +``` + +#### `CoreReader.Engineering.insertOrdered` + +`CoreReader/Engineering/Domain.lean:369–372`; def. + +```lean +def insertOrdered (n : Nat) : List Nat → List Nat + | [] => [n] + | x :: xs => if n ≤ x then n :: x :: xs else x :: insertOrdered n xs + +``` + +#### `CoreReader.Engineering.sortValues` + +`CoreReader/Engineering/Domain.lean:373–376`; def. + +```lean +def sortValues : List Nat → List Nat + | [] => [] + | x :: xs => insertOrdered x (sortValues xs) + +``` + +#### `CoreReader.Engineering.sortedUnique` + +`CoreReader/Engineering/Domain.lean:377–378`; def. + +```lean +def sortedUnique (xs : List Nat) : List Nat := (sortValues xs).eraseDups + +``` + +#### `CoreReader.Engineering.SoftwareState` + +`CoreReader/Engineering/Domain.lean:379–388`; structure. + +```lean +structure SoftwareState where + capabilities : List String + implementation : Nat + mechanisms : List String + abstractions : List String + boundary : Nat + technology : String + batchSize : Nat + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Engineering.originalSoftware` + +`CoreReader/Engineering/Domain.lean:389–391`; def. + +```lean +def originalSoftware : SoftwareState := + ⟨["deduplicate"], 0, ["queue", "legacy cache"], ["fixed batch"], 0, "legacy store", 10⟩ + +``` + +#### `CoreReader.Engineering.transform` + +`CoreReader/Engineering/Domain.lean:392–405`; def. + +```lean +def transform (d : Change) (s : SoftwareState) : SoftwareState := match d with + | .addition => { s with capabilities := s.capabilities ++ ["tenant batching"] } + | .replacement => { s with implementation := s.implementation + 1 } + | .deletion => { s with mechanisms := s.mechanisms.filter (· != "legacy cache") } + | .withdrawal => { s with abstractions := s.abstractions.filter (· != "fixed batch") } + | .redrawing => { s with boundary := s.boundary + 1 } + | .migration => { s with technology := "portable store" } + | .independent => { s with batchSize := 5 } + | .coordinated => { s with batchSize := 5, boundary := s.boundary + 1 } + | .designRevision => { s with batchSize := 5, abstractions := ["live configuration"], boundary := s.boundary + 1 } + | .other name => + if name = "csv export" then { s with capabilities := s.capabilities ++ ["csv export"] } + else s + +``` + +#### `CoreReader.Engineering.evolutionBehavior` + +`CoreReader/Engineering/Domain.lean:406–410`; def. + +```lean +def evolutionBehavior (d : Change) : List Nat → List Nat := + if d = .redrawing ∨ d = .designRevision then sortedUnique else orderedUnique + + + +``` + +#### `CoreReader.Engineering.ObligationTreatment` + +`CoreReader/Engineering/Domain.lean:411–413`; inductive. + +```lean +inductive ObligationTreatment where + | preserve | revise + deriving DecidableEq, Repr +``` + +#### `CoreReader.Engineering.ChangeClaim` + +`CoreReader/Engineering/Domain.lean:414–418`; structure. + +```lean +structure ChangeClaim where + direction : Change + byMaintainer : Maintainer + treatment : ObligationTreatment + +``` + +#### `CoreReader.Engineering.contractInputs` + +`CoreReader/Engineering/Domain.lean:419–419`; abbrev. + +```lean +abbrev contractInputs : List (List Nat) := [[], [2, 1, 2], [1, 3, 1], [4, 4]] +``` + +#### `CoreReader.Engineering.PreservesOn` + +`CoreReader/Engineering/Domain.lean:420–422`; def. + +```lean +def PreservesOn {Input Output : Type} (scope : Input → Prop) + (old new : Input → Output) : Prop := ∀ x, scope x → new x = old x + +``` + +#### `CoreReader.Engineering.PreservesFinite` + +`CoreReader/Engineering/Domain.lean:423–428`; abbrev. + +```lean +abbrev PreservesFinite (old new : List Nat → List Nat) : Prop := + contractInputs.all (fun xs => new xs == old xs) = true + + + + +``` + +#### `CoreReader.Engineering.ObservableContract` + +`CoreReader/Engineering/Domain.lean:429–432`; structure. + +```lean +structure ObservableContract where + order : List Nat → List Nat + maxAttempts : Nat + +``` + +#### `CoreReader.Engineering.retry` + +`CoreReader/Engineering/Domain.lean:433–435`; def. + +```lean +def retry (contract : ObservableContract) (attempts : Nat) : Bool := + attempts < contract.maxAttempts + +``` + +#### `CoreReader.Engineering.orderContract` + +`CoreReader/Engineering/Domain.lean:436–436`; def. + +```lean +def orderContract (order : List Nat → List Nat) : ObservableContract := ⟨order, 3⟩ +``` + +#### `CoreReader.Engineering.originalContract` + +`CoreReader/Engineering/Domain.lean:437–437`; def. + +```lean +def originalContract : ObservableContract := orderContract orderedUnique +``` + +#### `CoreReader.Engineering.refactoredContract` + +`CoreReader/Engineering/Domain.lean:438–438`; def. + +```lean +def refactoredContract : ObservableContract := orderContract orderedRefactor +``` + +#### `CoreReader.Engineering.revisedContract` + +`CoreReader/Engineering/Domain.lean:439–439`; def. + +```lean +def revisedContract : ObservableContract := ⟨sortedUnique, 5⟩ +``` + +#### `CoreReader.Engineering.evolutionContract` + +`CoreReader/Engineering/Domain.lean:440–442`; def. + +```lean +def evolutionContract (d : Change) : ObservableContract := + ⟨evolutionBehavior d, if d = .redrawing ∨ d = .designRevision then 5 else 3⟩ + +``` + +#### `CoreReader.Engineering.failureInputs` + +`CoreReader/Engineering/Domain.lean:443–443`; def. + +```lean +def failureInputs : List Nat := [0, 1, 2, 3, 4, 5] +``` + +#### `CoreReader.Engineering.PreservesContractFinite` + +`CoreReader/Engineering/Domain.lean:444–447`; abbrev. + +```lean +abbrev PreservesContractFinite (old new : ObservableContract) : Prop := + PreservesFinite old.order new.order ∧ + failureInputs.all (fun attempts => retry new attempts == retry old attempts) = true + +``` + +#### `CoreReader.Engineering.ContractAspect` + +`CoreReader/Engineering/Domain.lean:448–450`; inductive. + +```lean +inductive ContractAspect where + | order | retry + deriving DecidableEq, Repr +``` + +#### `CoreReader.Engineering.PartyDependency` + +`CoreReader/Engineering/Domain.lean:451–455`; structure. + +```lean +structure PartyDependency where + party : String + observes : ContractAspect + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Engineering.partyDependencies` + +`CoreReader/Engineering/Domain.lean:456–458`; def. + +```lean +def partyDependencies : List PartyDependency := + [⟨"queue consumer", .order⟩, ⟨"queue operator", .retry⟩] + +``` + +#### `CoreReader.Engineering.aspectChanged` + +`CoreReader/Engineering/Domain.lean:459–462`; def. + +```lean +def aspectChanged (old new : ObservableContract) : ContractAspect → Bool + | .order => contractInputs.any (fun xs => new.order xs != old.order xs) + | .retry => failureInputs.any (fun attempts => retry new attempts != retry old attempts) + +``` + +#### `CoreReader.Engineering.affectedParties` + +`CoreReader/Engineering/Domain.lean:463–466`; def. + +```lean +def affectedParties (old new : ObservableContract) : List String := + (partyDependencies.filter (fun dependency => aspectChanged old new dependency.observes)).map + PartyDependency.party + +``` + +#### `CoreReader.Engineering.ContractRevision` + +`CoreReader/Engineering/Domain.lean:467–476`; structure. + +```lean +structure ContractRevision where + deliberate : Bool + revisedOrder : List Nat + affected : List String + oldFailureLimit : Nat + newFailureLimit : Nat + recordedOldFailureLimit : Nat + recordedNewFailureLimit : Nat + procedure : String + +``` + +#### `CoreReader.Engineering.normalRevision` + +`CoreReader/Engineering/Domain.lean:477–483`; def. + +```lean +def normalRevision : ContractRevision := { + deliberate := true, revisedOrder := [1, 2], + affected := ["queue consumer", "queue operator"], + oldFailureLimit := 3, newFailureLimit := 5, + recordedOldFailureLimit := 3, recordedNewFailureLimit := 5, + procedure := "contract review" } + +``` + +#### `CoreReader.Engineering.RevisionDuties` + +`CoreReader/Engineering/Domain.lean:484–490`; abbrev. + +```lean +abbrev RevisionDuties (old new : ObservableContract) (r : ContractRevision) : Prop := + r.deliberate = true ∧ r.revisedOrder = new.order [2, 1, 2] ∧ + (affectedParties old new).all (fun p => r.affected.contains p) = true ∧ + r.oldFailureLimit = old.maxAttempts ∧ r.newFailureLimit = new.maxAttempts ∧ + r.recordedOldFailureLimit = old.maxAttempts ∧ + r.recordedNewFailureLimit = new.maxAttempts + +``` + +#### `CoreReader.Engineering.ContractChangeAccount` + +`CoreReader/Engineering/Domain.lean:491–493`; abbrev. + +```lean +abbrev ContractChangeAccount (old new : ObservableContract) (r : ContractRevision) : Prop := + PreservesContractFinite old new ∨ RevisionDuties old new r + +``` + +#### `CoreReader.Engineering.EvolutionClaim` + +`CoreReader/Engineering/Domain.lean:494–502`; abbrev. + +```lean +abbrev EvolutionClaim (a : Activity) (c : Candidate) (claim : ChangeClaim) : Prop := + CanChange a c claim.byMaintainer claim.direction ∧ + ContractChangeAccount originalContract (evolutionContract claim.direction) normalRevision ∧ + (changePath c claim.direction).any (fun step => step.tool == .contractRunner) = true ∧ + ((claim.treatment = .preserve ∧ + evolutionBehavior claim.direction [2, 1, 2] = orderedUnique [2, 1, 2]) ∨ + (claim.treatment = .revise ∧ + evolutionBehavior claim.direction [2, 1, 2] ≠ orderedUnique [2, 1, 2])) + +``` + +#### `CoreReader.Engineering.evolutionKindsCases` + +`CoreReader/Engineering/Domain.lean:503–514`; theorem. + +```lean +theorem evolutionKindsCases : + (transform .addition originalSoftware).capabilities = ["deduplicate", "tenant batching"] ∧ + (transform .replacement originalSoftware).implementation = 1 ∧ + (transform .deletion originalSoftware).mechanisms = ["queue"] ∧ + (transform .withdrawal originalSoftware).abstractions = [] ∧ + (transform .redrawing originalSoftware).boundary = 1 ∧ + (transform .migration originalSoftware).technology = "portable store" ∧ + changes.all (fun d => decide (CanChange continuingActivity .evolvable .successor d)) = true ∧ + EvolutionClaim continuingActivity .evolvable ⟨.replacement, .successor, .preserve⟩ ∧ + EvolutionClaim continuingActivity .evolvable ⟨.redrawing, .agent, .revise⟩ ∧ + changeWork .evolvable .independent < changeWork .evolvable .coordinated := by decide + +``` + +#### `CoreReader.Engineering.evolutionDimensionsLimits` + +`CoreReader/Engineering/Domain.lean:515–531`; theorem. + +```lean +theorem evolutionDimensionsLimits : + changeWork .presentSimple .addition = 2 ∧ + changeWork .presentSimple .withdrawal = 17 ∧ + changeWork .evolvable .independent < changeWork .evolvable .coordinated ∧ + EvolutionPriority currentContinuing .evolvable ∧ + 9 < changeWork .evolvable .migration ∧ + CanChange continuingActivity .presentSimple .original .addition ∧ + CanChange continuingActivity .evolvable .original .addition ∧ + CanChange continuingActivity .presentSimple .original .designRevision ∧ + CanChange continuingActivity .evolvable .original .designRevision ∧ + changeWork .evolvable .designRevision < changeWork .presentSimple .designRevision ∧ + changeWork .evolvable .addition = changeWork .presentSimple .addition ∧ + (transform (.other "csv export") originalSoftware).capabilities = ["deduplicate", "csv export"] ∧ + CanChange continuingActivity .maximal .successor (.other "csv export") ∧ + ¬ CanChange continuingActivity .evolvable .successor (.other "csv export") := by + exact ⟨by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide⟩ + +``` + +#### `CoreReader.Engineering.oneDimensionDoesNotEntailEveryDimension` + +`CoreReader/Engineering/Domain.lean:532–539`; theorem. + +```lean +theorem oneDimensionDoesNotEntailEveryDimension : + changeWork .evolvable .designRevision < changeWork .presentSimple .designRevision ∧ + ¬ (∀ d : Change, changeWork .evolvable d < changeWork .presentSimple d) := by + refine ⟨by decide, ?_⟩ + intro allDirections + exact (by decide : ¬ changeWork .evolvable .addition < changeWork .presentSimple .addition) + (allDirections .addition) + +``` + +#### `CoreReader.Engineering.propagation` + +`CoreReader/Engineering/Domain.lean:540–542`; def. + +```lean +def propagation (c : Candidate) (d : Change) : List Nat := + ((changePath c d).map EditStep.component).eraseDups + +``` + +#### `CoreReader.Engineering.batchCount` + +`CoreReader/Engineering/Domain.lean:543–543`; def. + +```lean +def batchCount (items size : Nat) : Nat := (items + size - 1) / size +``` + +#### `CoreReader.Engineering.staticBatch` + +`CoreReader/Engineering/Domain.lean:544–544`; def. + +```lean +def staticBatch (items _runtimeSize : Nat) : Nat := batchCount items 10 +``` + +#### `CoreReader.Engineering.liveBatch` + +`CoreReader/Engineering/Domain.lean:545–546`; def. + +```lean +def liveBatch (items runtimeSize : Nat) : Nat := batchCount items runtimeSize + +``` + +#### `CoreReader.Engineering.StructuralEvidence` + +`CoreReader/Engineering/Domain.lean:547–557`; structure. + +```lean +structure StructuralEvidence where + intended : Change + participants : List Maintainer + touched : List Nat + contractObservations : List (List Nat) + observedBefore : List (List Nat) + observedAfter : List (List Nat) + understandingWork : Nat + verificationWork : Nat + boundaryGain : Nat + +``` + +#### `CoreReader.Engineering.structuralEvidence` + +`CoreReader/Engineering/Domain.lean:558–566`; def. + +```lean +def structuralEvidence (c : Candidate) (d : Change) : StructuralEvidence := { + intended := d, participants := maintainers, touched := propagation c d, + contractObservations := contractInputs, + observedBefore := contractInputs.map orderedUnique, + observedAfter := contractInputs.map (evolutionBehavior d), + understandingWork := changeWork c d, + verificationWork := ((changePath c d).filter (fun step => step.tool == .contractRunner)).length, + boundaryGain := changeWork .presentSimple d - changeWork c d } + +``` + +#### `CoreReader.Engineering.StructuralAccount` + +`CoreReader/Engineering/Domain.lean:567–576`; abbrev. + +```lean +abbrev StructuralAccount (a : Activity) (c : Candidate) (e : StructuralEvidence) : Prop := + e.participants = a.participants ∧ e.touched = propagation c e.intended ∧ + e.contractObservations = contractInputs ∧ + e.observedBefore = contractInputs.map orderedUnique ∧ + e.observedAfter = contractInputs.map (evolutionBehavior e.intended) ∧ + e.understandingWork = changeWork c e.intended ∧ + e.verificationWork = ((changePath c e.intended).filter + (fun step => step.tool == .contractRunner)).length ∧ + e.boundaryGain = changeWork .presentSimple e.intended - changeWork c e.intended + +``` + +#### `CoreReader.Engineering.structuralCases` + +`CoreReader/Engineering/Domain.lean:577–587`; theorem. + +```lean +theorem structuralCases : + StructuralAccount continuingActivity .evolvable (structuralEvidence .evolvable .designRevision) ∧ + (propagation .presentSimple .designRevision).length = 3 ∧ + (propagation .evolvable .designRevision).length = 2 ∧ + (changePath .evolvable .coordinated).any (fun s => s.component == 2 && s.requires == .publicContract) = true ∧ + PreservesFinite orderedUnique orderedRefactor ∧ + (structuralEvidence .evolvable .designRevision).observedBefore ≠ + (structuralEvidence .evolvable .designRevision).observedAfter ∧ + staticBatch 21 10 = liveBatch 21 10 ∧ staticBatch 21 5 ≠ liveBatch 21 5 ∧ + changeWork .presentSimple .withdrawal = 17 := by decide + +``` + +#### `CoreReader.Engineering.InterfaceView` + +`CoreReader/Engineering/Domain.lean:588–594`; structure. + +```lean +structure InterfaceView where + signature : String + modules : Nat + extensionPoints : Nat + principle : String + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Engineering.sameShape` + +`CoreReader/Engineering/Domain.lean:595–595`; def. + +```lean +def sameShape : InterfaceView := ⟨"List Nat → List Nat", 8, 12, "dependency inversion"⟩ +``` + +#### `CoreReader.Engineering.moduleAssumptions` + +`CoreReader/Engineering/Domain.lean:596–598`; def. + +```lean +def moduleAssumptions : List (Nat × Nat) := + (List.range 8).map (fun component => (component, 10)) + +``` + +#### `CoreReader.Engineering.modulesNeedingRevision` + +`CoreReader/Engineering/Domain.lean:599–601`; def. + +```lean +def modulesNeedingRevision (newSize : Nat) : List Nat := + (moduleAssumptions.filter (fun p => p.2 != newSize)).map Prod.fst + +``` + +#### `CoreReader.Engineering.Boundary` + +`CoreReader/Engineering/Domain.lean:602–607`; structure. + +```lean +structure Boundary where + caller : Nat + callee : Nat + contract : String + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Engineering.EngineeringDesign` + +`CoreReader/Engineering/Domain.lean:608–615`; structure. + +```lean +structure EngineeringDesign where + metadata : InterfaceView + run : List Nat → List Nat + paths : Change → List EditStep + components : List Nat + boundaries : List Boundary + batchAssumptions : List (Nat × Nat) + +``` + +#### `CoreReader.Engineering.privateDesign` + +`CoreReader/Engineering/Domain.lean:616–619`; def. + +```lean +def privateDesign : EngineeringDesign := { + metadata := sameShape, run := orderedUnique, paths := changePath .presentSimple, + components := List.range 8, boundaries := [], batchAssumptions := moduleAssumptions } + +``` + +#### `CoreReader.Engineering.documentedDesign` + +`CoreReader/Engineering/Domain.lean:620–622`; def. + +```lean +def documentedDesign : EngineeringDesign := { + privateDesign with paths := changePath .evolvable } + +``` + +#### `CoreReader.Engineering.sortedDesign` + +`CoreReader/Engineering/Domain.lean:623–624`; def. + +```lean +def sortedDesign : EngineeringDesign := { documentedDesign with run := sortedUnique } + +``` + +#### `CoreReader.Engineering.DesignCanChange` + +`CoreReader/Engineering/Domain.lean:625–630`; abbrev. + +```lean +abbrev DesignCanChange (a : Activity) (design : EngineeringDesign) + (m : Maintainer) (d : Change) : Prop := + design.paths d ≠ [] ∧ m ∈ a.participants ∧ + (design.paths d).all (fun step => + (a.available m).contains step.requires && a.tools.contains step.tool) = true + +``` + +#### `CoreReader.Engineering.designWork` + +`CoreReader/Engineering/Domain.lean:631–633`; def. + +```lean +def designWork (design : EngineeringDesign) (d : Change) : Nat := + ((design.paths d).map EditStep.units).sum + +``` + +#### `CoreReader.Engineering.designModulesNeedingRevision` + +`CoreReader/Engineering/Domain.lean:634–639`; def. + +```lean +def designModulesNeedingRevision (design : EngineeringDesign) (newSize : Nat) : List Nat := + (design.batchAssumptions.filter (fun p => p.2 != newSize)).map Prod.fst + + + + +``` + +#### `CoreReader.Engineering.introduceBoundary` + +`CoreReader/Engineering/Domain.lean:640–649`; def. + +```lean +def introduceBoundary (design : EngineeringDesign) : EngineeringDesign := { + metadata := { design.metadata with modules := design.metadata.modules + 1, extensionPoints := design.metadata.extensionPoints + 1 }, + run := fun xs => design.run (xs ++ []), + paths := fun d => if (design.paths d).isEmpty then [] else + design.paths d ++ [⟨design.components.length, .publicContract, .contractRunner, 1⟩], + components := design.components ++ [design.components.length], + boundaries := design.boundaries ++ + [⟨design.components.length, 0, design.metadata.signature⟩], + batchAssumptions := design.batchAssumptions } + +``` + +#### `CoreReader.Engineering.wrappedDesign` + +`CoreReader/Engineering/Domain.lean:650–651`; def. + +```lean +def wrappedDesign : EngineeringDesign := introduceBoundary privateDesign + +``` + +#### `CoreReader.Engineering.structureNotCapability` + +`CoreReader/Engineering/Domain.lean:652–670`; theorem. + +```lean +theorem structureNotCapability : + (privateDesign.metadata.signature = sortedDesign.metadata.signature ∧ + privateDesign.run [2, 1, 2] = [2, 1] ∧ sortedDesign.run [2, 1, 2] ≠ [2, 1]) ∧ + (privateDesign.metadata.modules = privateDesign.components.length ∧ + privateDesign.batchAssumptions.length = 8 ∧ + (designModulesNeedingRevision privateDesign 5).length = 8) ∧ + (privateDesign.metadata.principle = "dependency inversion" ∧ + privateDesign.metadata = documentedDesign.metadata ∧ + ¬ DesignCanChange continuingActivity privateDesign .successor .designRevision ∧ + DesignCanChange continuingActivity documentedDesign .successor .designRevision) ∧ + (privateDesign.boundaries.length = 0 ∧ wrappedDesign.boundaries.length = 1 ∧ + wrappedDesign.components.length = 9 ∧ + wrappedDesign.boundaries = [⟨8, 0, "List Nat → List Nat"⟩] ∧ + wrappedDesign.run [2, 1, 2] = privateDesign.run [2, 1, 2] ∧ + designWork privateDesign .designRevision = 17 ∧ + designWork wrappedDesign .designRevision = 18 ∧ + ¬ designWork wrappedDesign .designRevision < designWork privateDesign .designRevision) := by + exact ⟨by decide, by decide, by decide, by decide⟩ + +``` + +#### `CoreReader.Engineering.contractPreservation` + +`CoreReader/Engineering/Domain.lean:671–674`; theorem. + +```lean +theorem contractPreservation {Input Output : Type} (scope : Input → Prop) + (old new : Input → Output) (observations : ∀ x, scope x → new x = old x) : + PreservesOn scope old new := observations + +``` + +#### `CoreReader.Engineering.changedObservationNotPreserved` + +`CoreReader/Engineering/Domain.lean:675–680`; theorem. + +```lean +theorem changedObservationNotPreserved {Input Output : Type} (scope : Input → Prop) + (old new : Input → Output) (x : Input) (inside : scope x) + (different : new x ≠ old x) : ¬ PreservesOn scope old new := by + intro h + exact different (h x inside) + +``` + +#### `CoreReader.Engineering.contractRevisionObligations` + +`CoreReader/Engineering/Domain.lean:681–685`; theorem. + +```lean +theorem contractRevisionObligations (old new : ObservableContract) + (r : ContractRevision) (account : ContractChangeAccount old new r) + (changed : ¬ PreservesContractFinite old new) : + RevisionDuties old new r := account.resolve_left changed + +``` + +#### `CoreReader.Engineering.retiredBehavior` + +`CoreReader/Engineering/Domain.lean:686–688`; def. + +```lean +def retiredBehavior (xs : List Nat) : List Nat := + if xs = [99] then [] else orderedUnique xs + +``` + +#### `CoreReader.Engineering.contractCases` + +`CoreReader/Engineering/Domain.lean:689–695`; theorem. + +```lean +theorem contractCases : + ContractChangeAccount originalContract refactoredContract normalRevision ∧ + ContractChangeAccount originalContract revisedContract normalRevision ∧ + ¬ ContractChangeAccount originalContract revisedContract { normalRevision with affected := [] } ∧ + PreservesFinite orderedUnique retiredBehavior ∧ retiredBehavior [99] ≠ orderedUnique [99] ∧ + ContractChangeAccount originalContract revisedContract { normalRevision with procedure := "paired audit" } := by decide + +``` + +#### `CoreReader.Engineering.contractDistinctions` + +`CoreReader/Engineering/Domain.lean:696–710`; theorem. + +```lean +theorem contractDistinctions : + PreservesFinite orderedUnique orderedRefactor ∧ + ¬ PreservesFinite orderedUnique sortedUnique ∧ + retry originalContract 3 = false ∧ retry revisedContract 3 = true ∧ + ¬ PreservesContractFinite originalContract revisedContract ∧ + affectedParties originalContract revisedContract = ["queue consumer", "queue operator"] ∧ + ¬ ContractChangeAccount originalContract revisedContract + { normalRevision with affected := ["queue consumer"] } ∧ + ¬ ContractChangeAccount originalContract revisedContract + { normalRevision with oldFailureLimit := 5, recordedOldFailureLimit := 5 } ∧ + ContractChangeAccount originalContract revisedContract normalRevision ∧ + PreservesFinite orderedUnique retiredBehavior ∧ retiredBehavior [99] ≠ orderedUnique [99] := by decide + + + +``` + +#### `CoreReader.Engineering.RevisionState` + +`CoreReader/Engineering/Domain.lean:711–719`; structure. + +```lean +structure RevisionState where + time : Nat + forecast : List Change + maintenance : Nat + maintainers : List Maintainer + migrationCost : Nat + objectiveCapacity : Nat + choice : Candidate + deriving DecidableEq, Repr +``` + +#### `CoreReader.Engineering.RevisionRecord` + +`CoreReader/Engineering/Domain.lean:720–731`; structure. + +```lean +structure RevisionRecord where + software : String + old : RevisionState + current : RevisionState + recordedOld : RevisionState + recordedCurrent : RevisionState + predictedBatchCount : Nat + actualBatchCount : Nat + reportedPredictionSucceeded : Bool + consideredChanges : List Change + criticizedDirections : List Change + +``` + +#### `CoreReader.Engineering.MaterialGroundsChanged` + +`CoreReader/Engineering/Domain.lean:732–736`; abbrev. + +```lean +abbrev MaterialGroundsChanged (old current : RevisionState) : Prop := + old.forecast ≠ current.forecast ∨ old.maintenance ≠ current.maintenance ∨ + old.maintainers ≠ current.maintainers ∨ + old.migrationCost ≠ current.migrationCost ∨ old.objectiveCapacity ≠ current.objectiveCapacity + +``` + +#### `CoreReader.Engineering.oldState` + +`CoreReader/Engineering/Domain.lean:737–737`; def. + +```lean +def oldState : RevisionState := ⟨0, [.designRevision], 6, [.original], 8, 12, .evolvable⟩ +``` + +#### `CoreReader.Engineering.newState` + +`CoreReader/Engineering/Domain.lean:738–739`; def. + +```lean +def newState : RevisionState := ⟨1, [.deletion], 2, [.successor, .agent], 14, 10, .presentSimple⟩ + +``` + +#### `CoreReader.Engineering.HistoricalEvidence` + +`CoreReader/Engineering/Domain.lean:740–747`; structure. + +```lean +structure HistoricalEvidence where + software : String + state : RevisionState + predictedBatchCount : Nat + actualBatchCount : Nat + + + +``` + +#### `CoreReader.Engineering.observedHistory` + +`CoreReader/Engineering/Domain.lean:748–750`; def. + +```lean +def observedHistory : HistoricalEvidence := + ⟨"order-preserving queue", oldState, staticBatch 21 5, liveBatch 21 5⟩ + +``` + +#### `CoreReader.Engineering.RevisionAccountAgainst` + +`CoreReader/Engineering/Domain.lean:751–760`; abbrev. + +```lean +abbrev RevisionAccountAgainst (history : HistoricalEvidence) (r : RevisionRecord) : Prop := + r.software = history.software ∧ + r.old = history.state ∧ r.recordedOld = history.state ∧ + r.predictedBatchCount = history.predictedBatchCount ∧ + r.actualBatchCount = history.actualBatchCount ∧ + r.old.time < r.current.time ∧ r.recordedCurrent = r.current ∧ + (r.old.choice ≠ r.current.choice → MaterialGroundsChanged r.old r.current) ∧ + r.reportedPredictionSucceeded = decide (history.predictedBatchCount = history.actualBatchCount) ∧ + r.consideredChanges.all (fun d => r.criticizedDirections.contains d) = true + +``` + +#### `CoreReader.Engineering.RevisionAccount` + +`CoreReader/Engineering/Domain.lean:761–762`; abbrev. + +```lean +abbrev RevisionAccount (r : RevisionRecord) : Prop := RevisionAccountAgainst observedHistory r + +``` + +#### `CoreReader.Engineering.failedHistoryNotRewritten` + +`CoreReader/Engineering/Domain.lean:763–768`; theorem. + +```lean +theorem failedHistoryNotRewritten (history : HistoricalEvidence) (r : RevisionRecord) + (account : RevisionAccountAgainst history r) + (failed : history.predictedBatchCount ≠ history.actualBatchCount) : + r.reportedPredictionSucceeded = false := by + simpa [failed] using account.2.2.2.2.2.2.2.2.1 + +``` + +#### `CoreReader.Engineering.revisionRecord` + +`CoreReader/Engineering/Domain.lean:769–775`; def. + +```lean +def revisionRecord : RevisionRecord := { + software := "order-preserving queue", + old := oldState, current := newState, recordedOld := oldState, recordedCurrent := newState, + predictedBatchCount := staticBatch 21 5, actualBatchCount := liveBatch 21 5, + reportedPredictionSucceeded := false, + consideredChanges := changes, criticizedDirections := changes } + +``` + +#### `CoreReader.Engineering.SupportedAlternative` + +`CoreReader/Engineering/Domain.lean:776–777`; abbrev. + +```lean +abbrev SupportedAlternative (gs : List DirectionGround) (d : Change) : Prop := credible gs d + +``` + +#### `CoreReader.Engineering.RetentionJustified` + +`CoreReader/Engineering/Domain.lean:778–781`; abbrev. + +```lean +abbrev RetentionJustified (ctx : Context) (alternatives : List Change) : Prop := + alternatives.all (fun d => !decide (SupportedAlternative ctx.evidence d)) = true ∨ + JustifiedDeparture ctx .evolvable + +``` + +#### `CoreReader.Engineering.stableRecord` + +`CoreReader/Engineering/Domain.lean:782–785`; def. + +```lean +def stableRecord : RevisionRecord := { revisionRecord with + current := { newState with choice := .evolvable }, + recordedCurrent := { newState with choice := .evolvable } } + +``` + +#### `CoreReader.Engineering.revisionCases` + +`CoreReader/Engineering/Domain.lean:786–796`; theorem. + +```lean +theorem revisionCases : + RevisionAccount revisionRecord ∧ + revisionRecord.old.forecast ≠ revisionRecord.current.forecast ∧ + revisionRecord.old.maintenance ≠ revisionRecord.current.maintenance ∧ + revisionRecord.old.maintainers ≠ revisionRecord.current.maintainers ∧ + revisionRecord.old.migrationCost ≠ revisionRecord.current.migrationCost ∧ + revisionRecord.old.objectiveCapacity ≠ revisionRecord.current.objectiveCapacity ∧ + revisionRecord.predictedBatchCount ≠ revisionRecord.actualBatchCount ∧ + RetentionJustified currentContinuing [.other "quantum backend"] ∧ + RetentionJustified (threatened .migration) [.migration] := by decide + +``` + +#### `CoreReader.Engineering.observations` + +`CoreReader/Engineering/Domain.lean:797–797`; def. + +```lean +def observations : List (Nat × Nat) := [(21, 10), (30, 10), (40, 10)] +``` + +#### `CoreReader.Engineering.revisionsMade` + +`CoreReader/Engineering/Domain.lean:798–798`; def. + +```lean +def revisionsMade : List Nat := [1, 2, 3] +``` + +#### `CoreReader.Engineering.agreedBatch` + +`CoreReader/Engineering/Domain.lean:799–801`; def. + +```lean +def agreedBatch (reviewers : List Maintainer) (items size : Nat) : List Nat := + reviewers.map (fun _ => staticBatch items size) + +``` + +#### `CoreReader.Engineering.rewrittenOldRecord` + +`CoreReader/Engineering/Domain.lean:802–805`; def. + +```lean +def rewrittenOldRecord : RevisionRecord := { revisionRecord with + old := { oldState with forecast := [.deletion] }, + recordedOld := { oldState with forecast := [.deletion] } } + +``` + +#### `CoreReader.Engineering.rewrittenPredictionRecord` + +`CoreReader/Engineering/Domain.lean:806–808`; def. + +```lean +def rewrittenPredictionRecord : RevisionRecord := { revisionRecord with + predictedBatchCount := 5, reportedPredictionSucceeded := true } + +``` + +#### `CoreReader.Engineering.rewrittenObservationRecord` + +`CoreReader/Engineering/Domain.lean:809–811`; def. + +```lean +def rewrittenObservationRecord : RevisionRecord := { revisionRecord with + actualBatchCount := 3, reportedPredictionSucceeded := true } + +``` + +#### `CoreReader.Engineering.unrelatedSoftwareRecord` + +`CoreReader/Engineering/Domain.lean:812–814`; def. + +```lean +def unrelatedSoftwareRecord : RevisionRecord := { + revisionRecord with software := "unrelated batch processor" } + +``` + +#### `CoreReader.Engineering.historicalTamperingRejected` + +`CoreReader/Engineering/Domain.lean:815–823`; theorem. + +```lean +theorem historicalTamperingRejected : + RevisionAccount revisionRecord ∧ + ¬ RevisionAccount rewrittenOldRecord ∧ + ¬ RevisionAccount rewrittenPredictionRecord ∧ + ¬ RevisionAccount rewrittenObservationRecord ∧ + observedHistory.predictedBatchCount = 3 ∧ observedHistory.actualBatchCount = 5 ∧ + ¬ RevisionAccount unrelatedSoftwareRecord := by + exact ⟨by decide, by decide, by decide, by decide, by decide, by decide, by decide⟩ + +``` + +#### `CoreReader.Engineering.revisionLimits` + +`CoreReader/Engineering/Domain.lean:824–837`; theorem. + +```lean +theorem revisionLimits : + RevisionAccount revisionRecord ∧ + ¬ RevisionAccount { revisionRecord with reportedPredictionSucceeded := true } ∧ + revisionsMade.length = 3 ∧ + agreedBatch maintainers 21 5 = [3, 3, 3] ∧ liveBatch 21 5 = 5 ∧ + observations.all (fun p => staticBatch p.1 p.2 == liveBatch p.1 p.2) = true ∧ + staticBatch 21 5 ≠ liveBatch 21 5 ∧ + RevisionAccount stableRecord ∧ stableRecord.current.choice = stableRecord.old.choice ∧ + RetentionJustified currentContinuing [.other "quantum backend"] := by + refine ⟨by decide, ?_, by decide, by decide, by decide, by decide, + by decide, by decide, by decide, by decide⟩ + dsimp [RevisionAccount, RevisionAccountAgainst, observedHistory, MaterialGroundsChanged, revisionRecord, oldState, newState] + decide + +``` + +#### `CoreReader.Engineering.groundedChanges` + +`CoreReader/Engineering/Domain.lean:838–840`; def. + +```lean +def groundedChanges : DirectionGround → List Change + | .plan _ ds | .knowledge _ ds _ | .history _ ds | .other _ ds => ds + +``` + +#### `CoreReader.Engineering.currentRevisionState` + +`CoreReader/Engineering/Domain.lean:841–847`; def. + +```lean +def currentRevisionState (ctx : Context) (chosen : Candidate) : RevisionState := { + time := 1, forecast := ctx.evidence.flatMap groundedChanges, + maintenance := ctx.activity.scheduledMaintenance, maintainers := ctx.activity.participants, + migrationCost := cost chosen .migration, + objectiveCapacity := ctx.limits.capacity .migration, + choice := chosen } + +``` + +#### `CoreReader.Engineering.revisionFor` + +`CoreReader/Engineering/Domain.lean:848–850`; def. + +```lean +def revisionFor (ctx : Context) (chosen : Candidate) : RevisionRecord := { + stableRecord with software := ctx.activity.software, current := currentRevisionState ctx chosen, recordedCurrent := currentRevisionState ctx chosen } + +``` + +#### `CoreReader.Engineering.revisionContextIdentity` + +`CoreReader/Engineering/Domain.lean:851–864`; theorem. + +```lean +theorem revisionContextIdentity : + (revisionFor currentContinuing .evolvable).software = currentContinuing.activity.software ∧ + (revisionFor currentContinuing .evolvable).software = observedHistory.software ∧ (revisionFor currentContinuing .evolvable).current.maintenance = + currentContinuing.activity.scheduledMaintenance ∧ + (revisionFor currentContinuing .evolvable).current.maintainers = currentContinuing.activity.participants ∧ + (revisionFor currentContinuing .evolvable).current.migrationCost = cost .evolvable .migration ∧ + (revisionFor currentContinuing .evolvable).current.objectiveCapacity = + currentContinuing.limits.capacity .migration ∧ + (revisionFor currentContinuing .evolvable).current.choice = .evolvable ∧ + RevisionAccount (revisionFor currentContinuing .evolvable) := by decide + + + + +``` + +#### `CoreReader.Engineering.DomainSatisfied` + +`CoreReader/Engineering/Domain.lean:865–873`; abbrev. + +```lean +abbrev DomainSatisfied (ctx : Context) (chosen : Candidate) : Prop := + ActivityScope ctx.activity ∧ EvolutionPriority ctx chosen ∧ + credible ctx.evidence .designRevision ∧ + (ctx.departure ≠ none → JustifiedDeparture ctx .evolvable) ∧ + EvolutionClaim ctx.activity chosen ⟨.designRevision, .successor, .revise⟩ ∧ + StructuralAccount ctx.activity chosen (structuralEvidence chosen .designRevision) ∧ + ContractChangeAccount (orderContract (behavior chosen)) (evolutionContract .designRevision) normalRevision ∧ + RevisionAccount (revisionFor ctx chosen) + +``` + +#### `CoreReader.Engineering.currentDomainSatisfied` + +`CoreReader/Engineering/Domain.lean:874–878`; theorem. + +```lean +theorem currentDomainSatisfied : DomainSatisfied currentContinuing .evolvable := by + refine ⟨by decide, by decide, by decide, ?_, by decide, by decide, by decide, by decide⟩ + simp [currentContinuing] + +end CoreReader.Engineering +``` + +### CoreReader/Engineering/Integration.lean + +#### `CoreReader.Engineering.sharedContext` + +`CoreReader/Engineering/Integration.lean:11–12`; abbrev. + +```lean +abbrev sharedContext : Context := currentContinuing + +``` + +#### `CoreReader.Engineering.maintainedOutput` + +`CoreReader/Engineering/Integration.lean:13–15`; def. + +```lean +def maintainedOutput (chosen : Candidate) (n : Nat) : Nat := + (behavior chosen [n]).headD 0 + +``` + +#### `CoreReader.Engineering.chosenImplementation` + +`CoreReader/Engineering/Integration.lean:16–27`; def. + +```lean +def chosenImplementation (chosen : Candidate) : CoreReader.Choice.Implementation where + name := "order-preserving queue" + conventional := chosen == .presentSimple + established := chosen == .presentSimple + run := maintainedOutput chosen + cost := abstractionComplexity chosen + domain _ := True + explanation := maintainedOutput chosen + trace n := [maintainedOutput chosen n] + + + +``` + +#### `CoreReader.Engineering.chosenRequirements` + +`CoreReader/Engineering/Integration.lean:28–33`; def. + +```lean +def chosenRequirements : CoreReader.Choice.Requirements where + inputs _ := True + expected n := n + budget := sharedContext.limits.capacity .understanding + values _ := True + +``` + +#### `CoreReader.Engineering.chosenReasons` + +`CoreReader/Engineering/Integration.lean:34–36`; def. + +```lean +def chosenReasons : List CoreReader.Choice.Reason := + [.method .output, .method .simplicity] + +``` + +#### `CoreReader.Engineering.maintainedOutputCorrect` + +`CoreReader/Engineering/Integration.lean:37–40`; theorem. + +```lean +theorem maintainedOutputCorrect (chosen : Candidate) (n : Nat) : + maintainedOutput chosen n = n := by + rfl + +``` + +#### `CoreReader.Engineering.implementationReasoned` + +`CoreReader/Engineering/Integration.lean:41–50`; theorem. + +```lean +theorem implementationReasoned (chosen : Candidate) + (budget : abstractionComplexity chosen ≤ chosenRequirements.budget) : + choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons := by + refine ⟨⟨fun n _ => maintainedOutputCorrect chosen n, budget⟩, + .method .output, ?_, ?_⟩ + · simp [chosenReasons] + · exact ⟨trivial, fun n _ => maintainedOutputCorrect chosen n⟩ + + + +``` + +#### `CoreReader.Engineering.capabilityOutput` + +`CoreReader/Engineering/Integration.lean:51–56`; def. + +```lean +def capabilityOutput (chosen : Candidate) (input : Nat) : Nat := + let maintainer := if input = 0 then Maintainer.original + else if input = 1 then Maintainer.successor else Maintainer.agent + if decide (CanChange sharedContext.activity chosen maintainer .designRevision) + then changeWork chosen .designRevision else 0 + +``` + +#### `CoreReader.Engineering.engineeringProcess` + +`CoreReader/Engineering/Integration.lean:57–59`; def. + +```lean +def engineeringProcess (chosen : Candidate) : Process := + ⟨capabilityOutput chosen, none⟩ + +``` + +#### `CoreReader.Engineering.engineeringCapability` + +`CoreReader/Engineering/Integration.lean:60–62`; def. + +```lean +def engineeringCapability (chosen : Candidate) : Claim Process := + fun process => ∀ input, process.output input = capabilityOutput chosen input + +``` + +#### `CoreReader.Engineering.engineeringCapabilityGrounded` + +`CoreReader/Engineering/Integration.lean:63–66`; theorem. + +```lean +theorem engineeringCapabilityGrounded (chosen : Candidate) : + capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen) := by + exact grounds012Singleton _ (processContractDischarged _ _ (fun _ => rfl)) + +``` + +#### `CoreReader.Engineering.actualCapabilityContrast` + +`CoreReader/Engineering/Integration.lean:67–76`; theorem. + +```lean +theorem actualCapabilityContrast : + (engineeringProcess .presentSimple).output 0 = 17 ∧ + (engineeringProcess .presentSimple).output 1 = 0 ∧ + (engineeringProcess .presentSimple).output 2 = 0 ∧ + (engineeringProcess .evolvable).output 0 = 6 ∧ + (engineeringProcess .evolvable).output 1 = 6 ∧ + (engineeringProcess .evolvable).output 2 = 6 := by decide + + + +``` + +#### `CoreReader.Engineering.presentBudgetRecord` + +`CoreReader/Engineering/Integration.lean:77–79`; def. + +```lean +def presentBudgetRecord : Record Candidate := + ⟨fun candidate => decide (abstractionComplexity candidate ≤ 3), true⟩ + +``` + +#### `CoreReader.Engineering.presentBudgetClaim` + +`CoreReader/Engineering/Integration.lean:80–81`; abbrev. + +```lean +abbrev presentBudgetClaim : Claim Candidate := fun candidate => abstractionComplexity candidate ≤ 3 + +``` + +#### `CoreReader.Engineering.budgetObservationMeaning` + +`CoreReader/Engineering/Integration.lean:82–91`; theorem. + +```lean +theorem budgetObservationMeaning (candidate : Candidate) : + Compatible [presentBudgetRecord] candidate ↔ presentBudgetClaim candidate := by + constructor + · intro observed + have result := observed presentBudgetRecord (List.mem_singleton.mpr rfl) + exact of_decide_eq_true result + · intro enough record member + cases List.mem_singleton.mp member + exact decide_eq_true enough + +``` + +#### `CoreReader.Engineering.budgetEmpiricalFacet` + +`CoreReader/Engineering/Integration.lean:92–94`; def. + +```lean +def budgetEmpiricalFacet : Facet Candidate := + .empirical [presentBudgetRecord] (fun _ => True) presentBudgetClaim (fun _ => True) + +``` + +#### `CoreReader.Engineering.budgetEmpiricalDischarged` + +`CoreReader/Engineering/Integration.lean:95–100`; theorem. + +```lean +theorem budgetEmpiricalDischarged : FacetDischarged budgetEmpiricalFacet := by + refine ⟨⟨.evolvable, (budgetObservationMeaning _).2 (by decide), trivial⟩, ?_, ?_⟩ + · intro candidate observed _ + exact (budgetObservationMeaning candidate).1 observed + · intro _ _; trivial + +``` + +#### `CoreReader.Engineering.capacityClaim` + +`CoreReader/Engineering/Integration.lean:101–103`; def. + +```lean +def capacityClaim : Claim Candidate := + fun candidate => abstractionComplexity candidate ≤ sharedContext.limits.capacity .understanding + +``` + +#### `CoreReader.Engineering.capacityAssumptions` + +`CoreReader/Engineering/Integration.lean:104–105`; def. + +```lean +def capacityAssumptions : Theory Candidate := singleton presentBudgetClaim + +``` + +#### `CoreReader.Engineering.budgetInferentialFacet` + +`CoreReader/Engineering/Integration.lean:106–107`; def. + +```lean +def budgetInferentialFacet : Facet Candidate := .inferential capacityAssumptions capacityClaim + +``` + +#### `CoreReader.Engineering.budgetInferentialDischarged` + +`CoreReader/Engineering/Integration.lean:108–113`; theorem. + +```lean +theorem budgetInferentialDischarged : FacetDischarged budgetInferentialFacet := by + refine ⟨⟨.evolvable, (modelsSingleton _ _).2 (by decide)⟩, ?_⟩ + intro candidate premises + have small := (modelsSingleton _ _).1 premises + exact Nat.le_trans small (by decide) + +``` + +#### `CoreReader.Engineering.budgetScopeAccount` + +`CoreReader/Engineering/Integration.lean:114–125`; def. + +```lean +def budgetScopeAccount : ScopeAccount Candidate where + claim := presentBudgetClaim + conditions := fun _ => True + observationScope := fun _ => True + relevant := fun a b => behavior a [2, 1, 2] = behavior b [2, 1, 2] + compared := fun a b => presentBudgetClaim a ∧ presentBudgetClaim b + used method := method = .measurement + role _ := "threshold observation of present complexity; no future-performance conclusion" + explains method text claim conditions := method = .measurement ∧ + text = "threshold observation of present complexity; no future-performance conclusion" ∧ + claim = presentBudgetClaim ∧ conditions = (fun _ => True) + +``` + +#### `CoreReader.Engineering.budgetScopeExplained` + +`CoreReader/Engineering/Integration.lean:126–133`; theorem. + +```lean +theorem budgetScopeExplained : scopeSpecification budgetScopeAccount := by + constructor + · intro a b _; exact ⟨trivial, trivial, trivial, trivial, rfl⟩ + · intro method hm + exact ⟨by change "threshold observation of present complexity; no future-performance conclusion" ≠ ""; decide, + hm, rfl, rfl, rfl⟩ + + +``` + +#### `CoreReader.Engineering.budgetObservationLimit` + +`CoreReader/Engineering/Integration.lean:134–143`; theorem. + +```lean +theorem budgetObservationLimit : + Compatible [presentBudgetRecord] .evolvable ∧ + ¬ Supports [presentBudgetRecord] (fun candidate => abstractionComplexity candidate ≤ 1) := by + refine ⟨(budgetObservationMeaning _).2 (by decide), ?_⟩ + intro support + have impossible := support .evolvable ((budgetObservationMeaning _).2 (by decide)) + exact (by decide : ¬ (3 ≤ 1)) impossible + + + +``` + +#### `CoreReader.Engineering.engineeringPolicy` + +`CoreReader/Engineering/Integration.lean:144–151`; def. + +```lean +def engineeringPolicy : CoreReader.Agency.Policy where + worthPursuing aim := + (aim = .expandUnderstandingAndConstruction ∧ coreAdopted .generation = true) ∨ + aim = .preserveSafeOperation + current form := form.version = 1 + revisable form := ∃ next, form.version < next ∧ coreAdopted .generation = true + permitsVersion old next := old ≤ next + +``` + +#### `CoreReader.Engineering.engineeringGenerative` + +`CoreReader/Engineering/Integration.lean:152–156`; theorem. + +```lean +theorem engineeringGenerative : generationSpecification engineeringPolicy := by + exact ⟨Or.inl ⟨rfl, rfl⟩, fun form _ => ⟨form.version + 1, Nat.lt_succ_self _, rfl⟩⟩ + + + +``` + +#### `CoreReader.Engineering.OwnFact` + +`CoreReader/Engineering/Integration.lean:157–161`; inductive. + +```lean +inductive OwnFact + | selected | requirements | capacity | capability | forecast | revision + | generativePolicy | reflection | coreAdoption (principle : CoreCommitment) + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Engineering.ownFactClaim` + +`CoreReader/Engineering/Integration.lean:162–173`; abbrev. + +```lean +abbrev ownFactClaim (adopted : Candidate) : OwnFact → Claim Candidate + | .selected => fun candidate => candidate = adopted + | .requirements => fun candidate => Meets sharedContext.required (sharedContext.profiles candidate) + | .capacity => capacityClaim + | .capability => fun candidate => engineeringCapability candidate (engineeringProcess candidate) + | .forecast => fun _ => staticBatch 21 10 = liveBatch 21 10 ∧ staticBatch 21 5 ≠ liveBatch 21 5 + | .revision => fun candidate => RevisionAccount (revisionFor sharedContext candidate) + | .generativePolicy => fun _ => generationSpecification engineeringPolicy + | .reflection => fun candidate => reflexivitySpecification + (selfModel candidate).rules (selfModel candidate).self (selfModel candidate).performed + | .coreAdoption principle => (governancePosition principle).commitment + +``` + +#### `CoreReader.Engineering.actualOwnFact` + +`CoreReader/Engineering/Integration.lean:174–187`; theorem. + +```lean +theorem actualOwnFact (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) (fact : OwnFact) : + ownFactClaim chosen fact chosen := by + cases fact with + | selected => rfl + | requirements => cases chosen <;> decide + | capacity => rcases ordinary with rfl | rfl <;> change _ ≤ 12 <;> decide + | capability => intro _; rfl + | forecast => exact ⟨rfl, by decide⟩ + | revision => rcases ordinary with rfl | rfl <;> decide + | generativePolicy => exact engineeringGenerative + | reflection => exact currentSelfApplication chosen ordinary + | coreAdoption _ => rfl + +``` + +#### `CoreReader.Engineering.ownFactPremises` + +`CoreReader/Engineering/Integration.lean:188–190`; def. + +```lean +def ownFactPremises (chosen : Candidate) : Theory Candidate := + singleton (fun candidate => candidate = chosen) + +``` + +#### `CoreReader.Engineering.actualOwnFactGrounded` + +`CoreReader/Engineering/Integration.lean:191–202`; theorem. + +```lean +theorem actualOwnFactGrounded (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) (fact : OwnFact) : + inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact) := by + apply grounds012Singleton + refine ⟨⟨chosen, (modelsSingleton _ _).2 rfl⟩, ?_⟩ + intro candidate same + have identity := (modelsSingleton _ _).1 same + subst candidate + exact actualOwnFact chosen ordinary fact + + + +``` + +#### `CoreReader.Engineering.ownTheory` + +`CoreReader/Engineering/Integration.lean:203–205`; def. + +```lean +def ownTheory (chosen : Candidate) : Theory Candidate := + fun claim => ∃ fact : OwnFact, claim = ownFactClaim chosen fact + +``` + +#### `CoreReader.Engineering.nonemptyOwnObjects` + +`CoreReader/Engineering/Integration.lean:206–213`; theorem. + +```lean +theorem nonemptyOwnObjects (chosen : Candidate) : + ownTheory chosen (ownFactClaim chosen .selected) ∧ + ownTheory chosen (ownFactClaim chosen (.coreAdoption .grounds)) ∧ + (.activity : ReviewObject) ∈ (selfModel chosen).objects ∧ + (.commitment .grounds : ReviewObject) ∈ (selfModel chosen).objects := by + refine ⟨⟨.selected, rfl⟩, ⟨.coreAdoption .grounds, rfl⟩, ?_, ?_⟩ <;> + simp [selfModel, reviewObjects, coreCommitments] + +``` + +#### `CoreReader.Engineering.comparisonContext` + +`CoreReader/Engineering/Integration.lean:214–218`; def. + +```lean +def comparisonContext (chosen : Candidate) : CoreReader.Logic.Context Candidate OwnFact where + assumptions := ownFactPremises chosen + meaning := ownFactClaim chosen + scope := valueScope + +``` + +#### `CoreReader.Engineering.engineeringSnapshot` + +`CoreReader/Engineering/Integration.lean:219–221`; def. + +```lean +def engineeringSnapshot (chosen : Candidate) (revision : Nat) : Snapshot Candidate OwnFact := + ⟨ownTheory chosen, comparisonContext chosen, revision⟩ + +``` + +#### `CoreReader.Engineering.currentAdmissible` + +`CoreReader/Engineering/Integration.lean:222–230`; theorem. + +```lean +theorem currentAdmissible (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) : + Admissible (ownTheory chosen) (comparisonContext chosen) chosen := by + refine ⟨?_, (modelsSingleton _ _).2 rfl, ?_⟩ + · intro claim held + obtain ⟨fact, rfl⟩ := held + exact actualOwnFact chosen ordinary fact + · rcases ordinary with rfl | rfl <;> change _ ≤ 3 <;> decide + +``` + +#### `CoreReader.Engineering.currentConsistency` + +`CoreReader/Engineering/Integration.lean:231–239`; theorem. + +```lean +theorem currentConsistency (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) : + consistencySpecification (engineeringSnapshot .evolvable 0) + (engineeringSnapshot chosen 1) true := by + exact ⟨consequenceConsistency _ _ ⟨chosen, currentAdmissible chosen ordinary⟩, fun _ => rfl⟩ + + + + +``` + +#### `CoreReader.Engineering.Inherited` + +`CoreReader/Engineering/Integration.lean:240–259`; structure. + +```lean +structure Inherited (ctx : Context) (chosen : Candidate) : Prop where + sameContext : ctx = sharedContext + generation : generationSpecification engineeringPolicy + consistency : consistencySpecification (engineeringSnapshot .evolvable 0) + (engineeringSnapshot chosen 1) true + reflection : reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self + (selfModel chosen).performed + ownPrincipleGrounds : ∀ principle, valueSpecification (governancePosition principle) + choiceValueGrounds : valueSpecification (selectionPosition chosen) + empiricalGrounds : empiricalSpecification [presentBudgetRecord] (fun _ => True) + presentBudgetClaim (fun _ => True) + inferentialGrounds : inferentialSpecification capacityAssumptions capacityClaim + scopeAccount : scopeSpecification budgetScopeAccount + capabilityGrounds : capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen) + implementationChoice : choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons + ownClaimGrounds : ∀ fact, inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact) + observedHere : Compatible [presentBudgetRecord] chosen + selectionActuallyAdopted : (selectionPosition chosen).commitment chosen + currentOwnClaims : Models (ownTheory chosen) chosen + +``` + +#### `CoreReader.Engineering.inheritedCurrent` + +`CoreReader/Engineering/Integration.lean:260–275`; theorem. + +```lean +theorem inheritedCurrent (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) : + Inherited sharedContext chosen := by + refine ⟨rfl, engineeringGenerative, currentConsistency chosen ordinary, + currentSelfApplication chosen ordinary, governanceGrounded, + selectionGrounded chosen ordinary, grounds012Singleton _ budgetEmpiricalDischarged, + grounds012Singleton _ budgetInferentialDischarged, budgetScopeExplained, + engineeringCapabilityGrounded chosen, ?_, actualOwnFactGrounded chosen ordinary, + ?_, rfl, (currentAdmissible chosen ordinary).1⟩ + · apply implementationReasoned + rcases ordinary with rfl | rfl <;> change _ ≤ 12 <;> decide + · apply (budgetObservationMeaning _).2 + rcases ordinary with rfl | rfl <;> change _ ≤ 3 <;> decide + + + +``` + +#### `CoreReader.Engineering.inheritedMutualApplication` + +`CoreReader/Engineering/Integration.lean:276–287`; theorem. + +```lean +theorem inheritedMutualApplication (ctx : Context) (chosen : Candidate) + (inherited : Inherited ctx chosen) : + generationSpecification engineeringPolicy ∧ + reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self + (selfModel chosen).performed ∧ + (∀ principle, valueSpecification (governancePosition principle)) ∧ + capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen) ∧ + choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons ∧ + (∀ fact, inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact)) := + ⟨inherited.generation, inherited.reflection, inherited.ownPrincipleGrounds, + inherited.capabilityGrounds, inherited.implementationChoice, inherited.ownClaimGrounds⟩ + +``` + +#### `CoreReader.Engineering.inheritedMutualCases` + +`CoreReader/Engineering/Integration.lean:288–300`; theorem. + +```lean +theorem inheritedMutualCases : + Inherited sharedContext .evolvable ∧ + valueSpecification (governancePosition .grounds) ∧ + capabilitySpecification (engineeringProcess .evolvable) (engineeringCapability .evolvable) ∧ + choiceSpecification chosenRequirements (chosenImplementation .evolvable) chosenReasons ∧ + Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample := + ⟨inheritedCurrent .evolvable (Or.inr rfl), governanceGrounded .grounds, + engineeringCapabilityGrounded .evolvable, + (inheritedCurrent .evolvable (Or.inr rfl)).implementationChoice, + (actualSelfCriticism .evolvable).2.2.1⟩ + + + +``` + +#### `CoreReader.Engineering.priorityRemainsReflexive` + +`CoreReader/Engineering/Integration.lean:301–313`; theorem. + +```lean +theorem priorityRemainsReflexive (ctx : Context) (chosen : Candidate) + (inherited : Inherited ctx chosen) (domain : DomainSatisfied ctx chosen) + (applicable : PriorityConditions ctx) (noDeparture : ¬ JustifiedDeparture ctx .evolvable) : + chosen = .evolvable ∧ + (.priority : ReviewObject) ∈ (selfModel chosen).objects ∧ + reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self + (selfModel chosen).performed ∧ + (∀ principle, valueSpecification (governancePosition principle)) := by + have selected := (priorityWhenApplicable ctx chosen domain.2.1 applicable noDeparture).1 + refine ⟨selected, ?_, inherited.reflection, inherited.ownPrincipleGrounds⟩ + subst chosen + decide + +``` + +#### `CoreReader.Engineering.priorityReflexiveCases` + +`CoreReader/Engineering/Integration.lean:314–328`; theorem. + +```lean +theorem priorityReflexiveCases : + (.priority : ReviewObject) ∈ (selfModel .evolvable).objects ∧ + objectTest .priority (.evolvable, 10) = true ∧ + (selfModel .evolvable).performed ⟨0, 1⟩ ⟨0, .priority, .revision⟩ + ((selfModel .evolvable).input ⟨0, .priority, .revision⟩) + (.assessed .supportedWithinScope) ∧ + Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧ + objectTest .evolutionMethod (.evolvable, 10) = true ∧ + objectTest .evolutionMethod (.evolvable, 5) = false := by + refine ⟨by decide, by decide, ?_, (actualSelfCriticism .evolvable).2.2.1, + (actualSelfCriticism .evolvable).1, (actualSelfCriticism .evolvable).2.1⟩ + exact ⟨⟨rfl, by decide⟩, rfl, .assessment, rfl, rfl⟩ + + + +``` + +#### `CoreReader.Engineering.jointWitness` + +`CoreReader/Engineering/Integration.lean:329–348`; theorem. + +```lean +theorem jointWitness : + ∃ ctx : Context, ∃ chosen : Candidate, + ctx = sharedContext ∧ chosen = .evolvable ∧ + Inherited ctx chosen ∧ DomainSatisfied ctx chosen ∧ + PriorityConditions ctx ∧ ¬ HasThreat ctx .evolvable ∧ + abstractionComplexity .presentSimple < abstractionComplexity chosen ∧ + CanChange ctx.activity chosen .successor .designRevision ∧ + CanChange ctx.activity chosen .agent .designRevision ∧ + ownTheory chosen (ownFactClaim chosen .selected) ∧ + (.commitment .grounds : ReviewObject) ∈ (selfModel chosen).objects ∧ + Admissible (ownTheory chosen) (comparisonContext chosen) chosen := by + exact ⟨sharedContext, .evolvable, rfl, rfl, + inheritedCurrent .evolvable (Or.inr rfl), currentDomainSatisfied, + currentPriorityConditions, currentNoThreat.1, by decide, by decide, by decide, + (nonemptyOwnObjects .evolvable).1, (nonemptyOwnObjects .evolvable).2.2.2, + currentAdmissible .evolvable (Or.inr rfl)⟩ + + + + +``` + +#### `CoreReader.Engineering.inheritedDoesNotEntailPriority` + +`CoreReader/Engineering/Integration.lean:349–371`; theorem. + +```lean +theorem inheritedDoesNotEntailPriority : + ∃ ctx : Context, ∃ chosen : Candidate, + ctx = sharedContext ∧ chosen = .presentSimple ∧ + Inherited ctx chosen ∧ PriorityConditions ctx ∧ + Continuing ctx.activity ∧ ¬ BoundedLifecycle ctx.activity ∧ + ¬ HasThreat ctx .evolvable ∧ ¬ JustifiedDeparture ctx .evolvable ∧ + Meets ctx.required (ctx.profiles .presentSimple) ∧ + Meets ctx.required (ctx.profiles .evolvable) ∧ + credible ctx.evidence .designRevision ∧ + CanChange ctx.activity .evolvable .successor .designRevision ∧ + CanChange ctx.activity .evolvable .agent .designRevision ∧ + changeWork .evolvable .designRevision < changeWork chosen .designRevision ∧ + abstractionComplexity chosen < abstractionComplexity .evolvable ∧ + valueSpecification (selectionPosition chosen) ∧ + (selectionPosition chosen).commitment chosen ∧ + ¬ EvolutionPriority ctx chosen := by + exact ⟨sharedContext, .presentSimple, rfl, rfl, + inheritedCurrent .presentSimple (Or.inl rfl), currentPriorityConditions, + by decide, by decide, currentNoThreat.1, currentNoThreat.2, + by decide, by decide, by decide, by decide, by decide, by decide, by decide, + selectionGrounded .presentSimple (Or.inl rfl), rfl, currentSimpleViolates⟩ + +end CoreReader.Engineering +``` + +### CoreReader/Engineering/Reflection.lean + +#### `CoreReader.Engineering.Reflection.Target` + +`CoreReader/Engineering/Reflection.lean:8–14`; structure. + +```lean +structure Target (Object : Type) where + owner : Nat + object : Object + phase : Phase + + + +``` + +#### `CoreReader.Engineering.Reflection.Contract` + +`CoreReader/Engineering/Reflection.lean:15–21`; structure. + +```lean +structure Contract (W : Type) where + test : W → Bool + tested : List W + claimed : List W + + + +``` + +#### `CoreReader.Engineering.Reflection.Input` + +`CoreReader/Engineering/Reflection.lean:22–28`; structure. + +```lean +structure Input (W Object : Type) where + target : Target Object + contract : Contract W + requested : List W + reasons : List String + basis : Prop + +``` + +#### `CoreReader.Engineering.Reflection.Verdict` + +`CoreReader/Engineering/Reflection.lean:29–31`; inductive. + +```lean +inductive Verdict | supportedWithinScope | counterexample | noSupportingSample + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Engineering.Reflection.Outcome` + +`CoreReader/Engineering/Reflection.lean:32–37`; inductive. + +```lean +inductive Outcome (W : Type) + | generated (tests scope : List W) + | assessed (verdict : Verdict) + + + +``` + +#### `CoreReader.Engineering.Reflection.evaluate` + +`CoreReader/Engineering/Reflection.lean:38–45`; def. + +```lean +def evaluate {W Object : Type} (input : Input W Object) : Verdict := + if input.contract.tested.all input.contract.test then + if input.requested.all input.contract.test then .supportedWithinScope + else .counterexample + else .noSupportingSample + + + +``` + +#### `CoreReader.Engineering.Reflection.interpret` + +`CoreReader/Engineering/Reflection.lean:46–51`; def. + +```lean +def interpret {W Object : Type} (activity : Activity) (input : Input W Object) + (outcome : Outcome W) : Prop := + input.reasons ≠ [] ∧ input.basis ∧ match activity with + | .generation => outcome = .generated input.requested input.requested + | .assessment => outcome = .assessed (evaluate input) + +``` + +#### `CoreReader.Engineering.Reflection.Model` + +`CoreReader/Engineering/Reflection.lean:52–62`; structure. + +```lean +structure Model (W Object : Type) where + owner : Nat + objects : List Object + contracts : Object → Contract W + requested : Object → Phase → List W + reasons : Object → Phase → List String + basis : Object → Phase → Prop + generationApplies : Object → Phase → Prop + assessmentApplies : Object → Phase → Prop + recorded : Activity → Object → Phase → Outcome W + +``` + +#### `CoreReader.Engineering.Reflection.Model.input` + +`CoreReader/Engineering/Reflection.lean:63–66`; def. + +```lean +def Model.input {W Object : Type} (m : Model W Object) (t : Target Object) : Input W Object := + ⟨t, m.contracts t.object, m.requested t.object t.phase, m.reasons t.object t.phase, + m.basis t.object t.phase⟩ + +``` + +#### `CoreReader.Engineering.Reflection.Model.self` + +`CoreReader/Engineering/Reflection.lean:67–69`; def. + +```lean +def Model.self {W Object : Type} (m : Model W Object) (t : Target Object) : Prop := + t.owner = m.owner ∧ t.object ∈ m.objects + +``` + +#### `CoreReader.Engineering.Reflection.Model.rule` + +`CoreReader/Engineering/Reflection.lean:70–79`; def. + +```lean +def Model.rule {W Object : Type} (m : Model W Object) (activity : Activity) : + ReflexiveRule (Target Object) (Input W Object) (Outcome W) where + key := ⟨m.owner, match activity with | .generation => 0 | .assessment => 1⟩ + activity := activity + applicable t := m.self t ∧ match activity with + | .generation => m.generationApplies t.object t.phase + | .assessment => m.assessmentApplies t.object t.phase + input := m.input + meaning := interpret activity + +``` + +#### `CoreReader.Engineering.Reflection.Model.rules` + +`CoreReader/Engineering/Reflection.lean:80–84`; def. + +```lean +def Model.rules {W Object : Type} (m : Model W Object) := + [m.rule .generation, m.rule .assessment] + + + +``` + +#### `CoreReader.Engineering.Reflection.Model.performed` + +`CoreReader/Engineering/Reflection.lean:85–90`; def. + +```lean +def Model.performed {W Object : Type} (m : Model W Object) + (key : PrincipleKey) (t : Target Object) (input : Input W Object) (outcome : Outcome W) : Prop := + m.self t ∧ input = m.input t ∧ + ∃ activity, key = (m.rule activity).key ∧ + outcome = m.recorded activity t.object t.phase + +``` + +#### `CoreReader.Engineering.Reflection.Model.follows` + +`CoreReader/Engineering/Reflection.lean:91–99`; def. + +```lean +def Model.follows {W Object : Type} (m : Model W Object) : Prop := + ∀ activity object phase, object ∈ m.objects → + (match activity with + | .generation => m.generationApplies object phase + | .assessment => m.assessmentApplies object phase) → + interpret activity (m.input ⟨m.owner, object, phase⟩) (m.recorded activity object phase) + + + +``` + +#### `CoreReader.Engineering.Reflection.recordedReflexivity` + +`CoreReader/Engineering/Reflection.lean:100–128`; theorem. + +```lean +theorem recordedReflexivity {W Object : Type} (m : Model W Object) (checked : m.follows) : + reflexivitySpecification m.rules m.self m.performed := by + constructor + · intro p hp q hq equal + simp only [Model.rules, List.mem_cons, List.not_mem_nil, or_false] at hp hq + rcases hp with rfl | rfl <;> rcases hq with rfl | rfl + · rfl + · have bad := congrArg PrincipleKey.localId equal; contradiction + · have bad := congrArg PrincipleKey.localId equal; contradiction + · rfl + · intro rule hr target hs ha + simp only [Model.rules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl + · refine ⟨m.recorded .generation target.object target.phase, + ⟨hs, rfl, .generation, rfl, rfl⟩, ?_⟩ + have actual := checked .generation target.object target.phase hs.2 ha.2 + rcases target with ⟨owner, object, phase⟩ + have ownerEqual : owner = m.owner := hs.1 + subst owner + exact actual + · refine ⟨m.recorded .assessment target.object target.phase, + ⟨hs, rfl, .assessment, rfl, rfl⟩, ?_⟩ + have actual := checked .assessment target.object target.phase hs.2 ha.2 + rcases target with ⟨owner, object, phase⟩ + have ownerEqual : owner = m.owner := hs.1 + subst owner + exact actual + +end CoreReader.Engineering.Reflection +``` + +### CoreReader/Engineering/SelfApplication.lean + +#### `CoreReader.Engineering.ReviewObject` + +`CoreReader/Engineering/SelfApplication.lean:8–10`; inductive. + +```lean +inductive ReviewObject | activity | commitment (principle : CoreCommitment) | priority | evolutionMethod + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Engineering.ReviewCase` + +`CoreReader/Engineering/SelfApplication.lean:11–14`; abbrev. + +```lean +abbrev ReviewCase := Candidate × Nat + + + +``` + +#### `CoreReader.Engineering.objectTest` + +`CoreReader/Engineering/SelfApplication.lean:15–21`; def. + +```lean +def objectTest (object : ReviewObject) (point : ReviewCase) : Bool := + match object with + | .activity => decide (Meets currentContinuing.required (currentContinuing.profiles point.1)) + | .commitment principle => safeguardExperiment principle true point.1 + | .priority => decide (EvolutionPriority currentContinuing point.1) + | .evolutionMethod => staticBatch 21 point.2 == liveBatch 21 point.2 + +``` + +#### `CoreReader.Engineering.reviewObjects` + +`CoreReader/Engineering/SelfApplication.lean:22–25`; def. + +```lean +def reviewObjects (chosen : Candidate) : List ReviewObject := + [.activity] ++ coreCommitments.map ReviewObject.commitment ++ + (if chosen = .evolvable then [.priority] else []) ++ [.evolutionMethod] + +``` + +#### `CoreReader.Engineering.requestedCases` + +`CoreReader/Engineering/SelfApplication.lean:26–29`; def. + +```lean +def requestedCases (chosen : Candidate) : CoreReader.Agency.Phase → List ReviewCase + | .formation | .application => [(chosen, 10)] + | .revision => [(chosen, 10), (chosen, 5)] + +``` + +#### `CoreReader.Engineering.reviewReasons` + +`CoreReader/Engineering/SelfApplication.lean:30–43`; def. + +```lean +def reviewReasons (object : ReviewObject) (phase : CoreReader.Agency.Phase) : List String := + let content := match object with + | .activity => "actual order, safety, latency and retention requirements of this activity" + | .commitment principle => criticismFor principle + | .priority => "credible design revision, successor and agent paths, necessary requirements and concrete costs" + | .evolutionMethod => "the same batch forecast at its recorded size and the proposed runtime size" + [content, match phase with + | .formation => "identify this object's purpose and the conditions of its initial contract" + | .application => "apply that contract to the currently selected design in this continuing activity" + | .revision => "examine the proposed wider input scope and retain any counterexample"] + + + + +``` + +#### `CoreReader.Engineering.statedReview` + +`CoreReader/Engineering/SelfApplication.lean:44–54`; def. + +```lean +def statedReview (chosen : Candidate) (activity : CoreReader.Agency.Activity) + (object : ReviewObject) (phase : CoreReader.Agency.Phase) : Reflection.Outcome ReviewCase := + match activity with + | .generation => .generated (requestedCases chosen phase) (requestedCases chosen phase) + | .assessment => .assessed (match object, phase with + | .evolutionMethod, .revision => .counterexample + | _, _ => .supportedWithinScope) + + + + +``` + +#### `CoreReader.Engineering.reviewBasis` + +`CoreReader/Engineering/SelfApplication.lean:55–63`; def. + +```lean +def reviewBasis (chosen : Candidate) : ReviewObject → CoreReader.Agency.Phase → Prop + | .activity, _ => ActivityScope currentContinuing.activity ∧ + Meets currentContinuing.required (currentContinuing.profiles chosen) + | .commitment principle, _ => ReasonRelevant principle (reasonFor principle) chosen + | .priority, _ => PriorityConditions currentContinuing ∧ ¬ HasThreat currentContinuing .evolvable + | .evolutionMethod, .revision => + staticBatch 21 10 = liveBatch 21 10 ∧ staticBatch 21 5 ≠ liveBatch 21 5 + | .evolutionMethod, _ => staticBatch 21 10 = liveBatch 21 10 + +``` + +#### `CoreReader.Engineering.selfModel` + +`CoreReader/Engineering/SelfApplication.lean:64–77`; def. + +```lean +def selfModel (chosen : Candidate) : Reflection.Model ReviewCase ReviewObject where + owner := 0 + objects := reviewObjects chosen + contracts object := ⟨objectTest object, [(chosen, 10)], [(chosen, 10)]⟩ + requested _ := requestedCases chosen + reasons := reviewReasons + basis := reviewBasis chosen + generationApplies _ phase := phase ≠ .application + assessmentApplies _ _ := True + recorded := statedReview chosen + + + + +``` + +#### `CoreReader.Engineering.reviewIdentity` + +`CoreReader/Engineering/SelfApplication.lean:78–86`; theorem. + +```lean +theorem reviewIdentity (chosen : Candidate) (object : ReviewObject) + (phase : CoreReader.Agency.Phase) : + ((selfModel chosen).input ⟨0, object, phase⟩).target.object = object ∧ + ((selfModel chosen).input ⟨0, object, phase⟩).contract.test = objectTest object ∧ + ((selfModel chosen).input ⟨0, object, phase⟩).requested = requestedCases chosen phase ∧ + ((selfModel chosen).input ⟨0, object, phase⟩).reasons = reviewReasons object phase ∧ + ((selfModel chosen).input ⟨0, object, phase⟩).basis = reviewBasis chosen object phase := + ⟨rfl, rfl, rfl, rfl, rfl⟩ + +``` + +#### `CoreReader.Engineering.currentSelfRecords` + +`CoreReader/Engineering/SelfApplication.lean:87–108`; theorem. + +```lean +theorem currentSelfRecords (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) : + (selfModel chosen).follows := by + rcases ordinary with rfl | rfl + all_goals + intro activity object phase member applies + cases activity <;> cases object <;> cases phase + all_goals first + | rename_i principle; cases principle + | skip + all_goals simp_all [Reflection.interpret, Reflection.Model.input, + Reflection.evaluate, selfModel, statedReview, reviewObjects, coreCommitments, + requestedCases, reviewReasons, criticismFor, objectTest, safeguardExperiment, + reviewBasis, ReasonRelevant, reasonFor, HasThreat, burdens, ConcreteThreat, cost, + EvolutionPriority, PriorityConditions, JustifiedDeparture, currentContinuing, + Continuing, ActivityScope, Meets, profile, normalRequirements, initialGrounds, + ContinuingCapability, continuingActivity, maintainers, changePath, + changeWork, abstractionComplexity, credible, CredibleDirection, articulateGround, + supportGround, normalLimits, staticBatch, liveBatch, batchCount, orderedUnique, + sortedUnique, sortValues, insertOrdered, List.eraseDups] + all_goals decide + +``` + +#### `CoreReader.Engineering.currentSelfApplication` + +`CoreReader/Engineering/SelfApplication.lean:109–117`; theorem. + +```lean +theorem currentSelfApplication (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) : + reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self + (selfModel chosen).performed := + Reflection.recordedReflexivity _ (currentSelfRecords chosen ordinary) + + + + +``` + +#### `CoreReader.Engineering.actualSelfCriticism` + +`CoreReader/Engineering/SelfApplication.lean:118–133`; theorem. + +```lean +theorem actualSelfCriticism (chosen : Candidate) : + objectTest .evolutionMethod (chosen, 10) = true ∧ + objectTest .evolutionMethod (chosen, 5) = false ∧ + Reflection.evaluate ((selfModel chosen).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧ + statedReview chosen .generation .evolutionMethod .revision = + .generated [(chosen, 10), (chosen, 5)] [(chosen, 10), (chosen, 5)] ∧ + staticBatch 21 5 ≠ liveBatch 21 5 := by + refine ⟨?_, ?_, ?_, rfl, by decide⟩ + · change (staticBatch 21 10 == liveBatch 21 10) = true + decide + · change (staticBatch 21 5 == liveBatch 21 5) = false + decide + · simp [Reflection.evaluate, Reflection.Model.input, selfModel, requestedCases, + objectTest, staticBatch, liveBatch, batchCount] + +end CoreReader.Engineering +``` + +### CoreReader/Engineering/Values.lean + +#### `CoreReader.Engineering.CoreCommitment` + +`CoreReader/Engineering/Values.lean:8–10`; inductive. + +```lean +inductive CoreCommitment | generation | consistency | reflexivity | grounds | choice + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Engineering.coreCommitments` + +`CoreReader/Engineering/Values.lean:11–15`; def. + +```lean +def coreCommitments : List CoreCommitment := + [.generation, .consistency, .reflexivity, .grounds, .choice] + + + +``` + +#### `CoreReader.Engineering.coreAdopted` + +`CoreReader/Engineering/Values.lean:16–17`; def. + +```lean +def coreAdopted (_ : CoreCommitment) : Bool := true + +``` + +#### `CoreReader.Engineering.AdoptionReason` + +`CoreReader/Engineering/Values.lean:18–25`; inductive. + +```lean +inductive AdoptionReason + | plannedChange (release : Nat) (direction : Change) + | incompatibleOrders (input : List Nat) + | ownMethodCounterexample (items size : Nat) + | unsupportedScope (items observedSize extendedSize : Nat) + | statusBudgetContrast (statusSelected : Candidate) (capacity : Nat) + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Engineering.reasonFor` + +`CoreReader/Engineering/Values.lean:26–35`; def. + +```lean +def reasonFor : CoreCommitment → AdoptionReason + | .generation => .plannedChange 2 .designRevision + | .consistency => .incompatibleOrders [2, 1, 2] + | .reflexivity => .ownMethodCounterexample 21 5 + | .grounds => .unsupportedScope 21 10 5 + | .choice => .statusBudgetContrast .maximal 12 + + + + +``` + +#### `CoreReader.Engineering.ReasonRelevant` + +`CoreReader/Engineering/Values.lean:36–52`; abbrev. + +```lean +abbrev ReasonRelevant : CoreCommitment → AdoptionReason → Candidate → Prop + | .generation, .plannedChange release direction, _ => + DirectionGround.plan release [direction, .migration] ∈ currentContinuing.evidence ∧ + credible currentContinuing.evidence direction ∧ Continuing currentContinuing.activity + | .consistency, .incompatibleOrders input, _ => + currentContinuing.required.orderRequired = true ∧ + orderedUnique input ≠ sortedUnique input + | .reflexivity, .ownMethodCounterexample items size, _ => + staticBatch items 10 = liveBatch items 10 ∧ staticBatch items size ≠ liveBatch items size + | .grounds, .unsupportedScope items observedSize extendedSize, _ => + staticBatch items observedSize = liveBatch items observedSize ∧ + staticBatch items extendedSize ≠ liveBatch items extendedSize + | .choice, .statusBudgetContrast candidate capacity, selected => + capacity = currentContinuing.limits.capacity .understanding ∧ + capacity < abstractionComplexity candidate ∧ abstractionComplexity selected ≤ capacity + | _, _, _ => False + +``` + +#### `CoreReader.Engineering.valueScope` + +`CoreReader/Engineering/Values.lean:53–57`; abbrev. + +```lean +abbrev valueScope (selected : Candidate) : Prop := abstractionComplexity selected ≤ 3 + + + + +``` + +#### `CoreReader.Engineering.safeguardExperiment` + +`CoreReader/Engineering/Values.lean:58–78`; def. + +```lean +def safeguardExperiment (principle : CoreCommitment) (enabled : Bool) + (selected : Candidate) : Bool := + match principle with + | .generation => + let allowed : List Change := if enabled then [.designRevision, .migration] else [] + allowed.contains .designRevision && decide (credible currentContinuing.evidence .designRevision) + | .consistency => + let firstDemand := orderedUnique [2, 1, 2] + let secondDemand := sortedUnique [2, 1, 2] + let permitsBoth := if enabled then firstDemand == secondDemand else true + !permitsBoth + | .reflexivity => + let selfTests := if enabled then [(21, 10), (21, 5)] else [(21, 10)] + selfTests.any (fun point => staticBatch point.1 point.2 != liveBatch point.1 point.2) + | .grounds => + let licensed := if enabled then [10] else [10, 5] + licensed.all (fun size => staticBatch 21 size == liveBatch 21 size) + | .choice => + let selectedByRule := if enabled then selected else .maximal + decide (abstractionComplexity selectedByRule ≤ currentContinuing.limits.capacity .understanding) + +``` + +#### `CoreReader.Engineering.criticismFor` + +`CoreReader/Engineering/Values.lean:79–85`; def. + +```lean +def criticismFor : CoreCommitment → String + | .generation => "Reconsider this reason if the committed change or continuing maintenance ends." + | .consistency => "Reconsider the comparison if the parties deliberately revise the observable order contract." + | .reflexivity => "This counterexample concerns the stated batch rule; it does not validate all self-assessment." + | .grounds => "A new input condition requires its own support; success at size ten does not cover size five." + | .choice => "If objectives or budgets change, compare the actual alternatives and reasons again." + +``` + +#### `CoreReader.Engineering.governancePosition` + +`CoreReader/Engineering/Values.lean:86–99`; def. + +```lean +def governancePosition (principle : CoreCommitment) : ValuePosition Candidate where + Position := Bool + Outcome := Bool + adopted := true + selected _ := coreAdopted principle + outcome selected enabled := safeguardExperiment principle enabled selected + objective result := result = true + constraints selected _ := valueScope selected + starting := singleton valueScope + reasons := [fun selected _ => ReasonRelevant principle (reasonFor principle) selected] + limits := valueScope + relevantCriticism _ := True + response _ := some (criticismFor principle) + +``` + +#### `CoreReader.Engineering.adoptionReasonRelevant` + +`CoreReader/Engineering/Values.lean:100–109`; theorem. + +```lean +theorem adoptionReasonRelevant (principle : CoreCommitment) (selected : Candidate) + (scope : valueScope selected) : ReasonRelevant principle (reasonFor principle) selected := by + cases principle + · dsimp only [ReasonRelevant, reasonFor]; decide + · dsimp only [ReasonRelevant, reasonFor]; decide + · dsimp only [ReasonRelevant, reasonFor]; decide + · dsimp only [ReasonRelevant, reasonFor]; decide + · refine ⟨rfl, by decide, ?_⟩ + exact Nat.le_trans scope (by decide) + +``` + +#### `CoreReader.Engineering.safeguardEnabled` + +`CoreReader/Engineering/Values.lean:110–119`; theorem. + +```lean +theorem safeguardEnabled (principle : CoreCommitment) (selected : Candidate) + (scope : valueScope selected) : safeguardExperiment principle true selected = true := by + cases principle + · dsimp only [safeguardExperiment]; decide + · dsimp only [safeguardExperiment]; decide + · dsimp only [safeguardExperiment]; decide + · dsimp only [safeguardExperiment]; decide + · apply decide_eq_true + exact Nat.le_trans scope (by change 3 ≤ 12; decide) + +``` + +#### `CoreReader.Engineering.safeguardDisabled` + +`CoreReader/Engineering/Values.lean:120–123`; theorem. + +```lean +theorem safeguardDisabled (principle : CoreCommitment) (selected : Candidate) : + safeguardExperiment principle false selected = false := by + cases principle <;> simp only [safeguardExperiment, Bool.false_eq_true, ↓reduceIte] <;> decide + +``` + +#### `CoreReader.Engineering.governanceValueProcedure` + +`CoreReader/Engineering/Values.lean:124–136`; theorem. + +```lean +theorem governanceValueProcedure (principle : CoreCommitment) : + ValueProcedure (governancePosition principle) := by + refine ⟨by simp [governancePosition], ?_, ?_, ?_⟩ + · refine ⟨.evolvable, (modelsSingleton _ _).2 (by change 3 ≤ 3; decide), + (by change 3 ≤ 3; decide), rfl, ?_⟩ + intro reason member + cases List.mem_singleton.mp member + exact adoptionReasonRelevant principle .evolvable (by change 3 ≤ 3; decide) + · intro selected _ scope _ + exact ⟨safeguardEnabled principle selected scope, scope⟩ + · intro selected _ _ + exact ⟨criticismFor principle, rfl, by cases principle <;> decide⟩ + +``` + +#### `CoreReader.Engineering.governanceGrounded` + +`CoreReader/Engineering/Values.lean:137–142`; theorem. + +```lean +theorem governanceGrounded (principle : CoreCommitment) : + valueSpecification (governancePosition principle) := + grounds012Singleton _ (governanceValueProcedure principle) + + + +``` + +#### `CoreReader.Engineering.governanceRationaleLimits` + +`CoreReader/Engineering/Values.lean:143–156`; theorem. + +```lean +theorem governanceRationaleLimits : + ¬ ReasonRelevant .consistency (reasonFor .generation) .evolvable ∧ + ¬ ReasonRelevant .reflexivity (.ownMethodCounterexample 21 10) .evolvable ∧ + ¬ ReasonRelevant .generation (.plannedChange 9 .addition) .evolvable ∧ + ¬ valueScope .maximal ∧ + (∀ principle, safeguardExperiment principle false .evolvable = false) ∧ + (∀ principle, (governancePosition principle).commitment .presentSimple) := by + refine ⟨by change ¬ False; decide, by decide, by decide, by change ¬ (30 ≤ 3); decide, + fun principle => safeguardDisabled principle .evolvable, fun _ => rfl⟩ + + + + + +``` + +#### `CoreReader.Engineering.selectionObjective` + +`CoreReader/Engineering/Values.lean:157–162`; def. + +```lean +def selectionObjective (adopted : Candidate) (outcome : Nat × Nat) : Prop := + match adopted with + | .presentSimple => outcome.1 ≤ 1 + | .evolvable => outcome.2 ≤ 6 + | .maximal => outcome.1 ≤ 1 + +``` + +#### `CoreReader.Engineering.selectionPosition` + +`CoreReader/Engineering/Values.lean:163–181`; def. + +```lean +def selectionPosition (adopted : Candidate) : ValuePosition Candidate where + Position := Candidate + Outcome := Nat × Nat + adopted := adopted + selected := id + outcome _ candidate := (abstractionComplexity candidate, changeWork candidate .designRevision) + objective := selectionObjective adopted + constraints _ candidate := abstractionComplexity candidate ≤ currentContinuing.limits.capacity .understanding + starting := singleton (fun candidate => candidate = adopted) + reasons := [fun _ candidate => + abstractionComplexity candidate = (if adopted = .presentSimple then 1 else 3) ∧ + changeWork candidate .designRevision = (if adopted = .presentSimple then 17 else 6)] + limits _ := Continuing currentContinuing.activity ∧ + credible currentContinuing.evidence .designRevision + relevantCriticism _ := True + response _ := some (if adopted = .presentSimple then + "The successor lacks the private-layout path; this choice does not claim evolution priority and must be reconsidered if that value is adopted." + else "The six-step design-revision path does not establish every change is cheap or every forecast is correct.") + +``` + +#### `CoreReader.Engineering.selectionValueProcedure` + +`CoreReader/Engineering/Values.lean:182–218`; theorem. + +```lean +theorem selectionValueProcedure (adopted : Candidate) + (ordinary : adopted = .presentSimple ∨ adopted = .evolvable) : + ValueProcedure (selectionPosition adopted) := by + rcases ordinary with rfl | rfl + · refine ⟨by simp [selectionPosition], ?_, ?_, ?_⟩ + · refine ⟨.presentSimple, (modelsSingleton _ _).2 rfl, ?_, rfl, ?_⟩ + · change Continuing currentContinuing.activity ∧ credible currentContinuing.evidence .designRevision + decide + · intro reason member + cases List.mem_singleton.mp member + decide + · intro selected _ _ allReasons + have actual := allReasons _ (List.mem_singleton.mpr rfl) + change abstractionComplexity .presentSimple = 1 ∧ changeWork .presentSimple .designRevision = 17 at actual + change abstractionComplexity .presentSimple ≤ 1 ∧ + abstractionComplexity .presentSimple ≤ currentContinuing.limits.capacity .understanding + exact ⟨by rw [actual.1]; exact Nat.le_refl _, by rw [actual.1]; decide⟩ + · intro selected _ _ + refine ⟨_, rfl, ?_⟩ + simp + · refine ⟨by simp [selectionPosition], ?_, ?_, ?_⟩ + · refine ⟨.evolvable, (modelsSingleton _ _).2 rfl, ?_, rfl, ?_⟩ + · change Continuing currentContinuing.activity ∧ credible currentContinuing.evidence .designRevision + decide + · intro reason member + cases List.mem_singleton.mp member + decide + · intro selected _ _ allReasons + have actual := allReasons _ (List.mem_singleton.mpr rfl) + change abstractionComplexity .evolvable = 3 ∧ changeWork .evolvable .designRevision = 6 at actual + change changeWork .evolvable .designRevision ≤ 6 ∧ + abstractionComplexity .evolvable ≤ currentContinuing.limits.capacity .understanding + exact ⟨by rw [actual.2]; exact Nat.le_refl _, by rw [actual.1]; decide⟩ + · intro selected _ _ + refine ⟨_, rfl, ?_⟩ + simp + +``` + +#### `CoreReader.Engineering.selectionGrounded` + +`CoreReader/Engineering/Values.lean:219–224`; theorem. + +```lean +theorem selectionGrounded (adopted : Candidate) + (ordinary : adopted = .presentSimple ∨ adopted = .evolvable) : + valueSpecification (selectionPosition adopted) := + grounds012Singleton _ (selectionValueProcedure adopted ordinary) + +end CoreReader.Engineering +``` + +### CoreReader/Evidence.lean + +#### `CoreReader.Evidence.Record` + +`CoreReader/Evidence.lean:9–12`; structure. + +```lean +structure Record (W : Type) where + test : W → Bool + observed : Bool + +``` + +#### `CoreReader.Evidence.Compatible` + +`CoreReader/Evidence.lean:13–15`; def. + +```lean +def Compatible {W : Type} (records : List (Record W)) (w : W) : Prop := + ∀ r, r ∈ records → r.test w = r.observed + +``` + +#### `CoreReader.Evidence.Supports` + +`CoreReader/Evidence.lean:16–18`; def. + +```lean +def Supports {W : Type} (records : List (Record W)) (claim : Claim W) : Prop := + ∀ w, Compatible records w → claim w + +``` + +#### `CoreReader.Evidence.Articulation` + +`CoreReader/Evidence.lean:19–24`; structure. + +```lean +structure Articulation (W : Type) where + concepts : List String + assumptions : Theory W + reasons : List (Claim W) + limits : Claim W + +``` + +#### `CoreReader.Evidence.Articulated` + +`CoreReader/Evidence.lean:25–27`; def. + +```lean +def Articulated {W : Type} (a : Articulation W) : Prop := + a.concepts ≠ [] ∧ a.reasons ≠ [] + +``` + +#### `CoreReader.Evidence.ValuePosition` + +`CoreReader/Evidence.lean:28–41`; structure. + +```lean +structure ValuePosition (W : Type) where + Position : Type + Outcome : Type + adopted : Position + selected : W → Position + outcome : W → Position → Outcome + objective : Outcome → Prop + constraints : W → Position → Prop + starting : Theory W + reasons : List (W → Position → Prop) + limits : Claim W + relevantCriticism : Claim W + response : W → Option String + +``` + +#### `CoreReader.Evidence.ValuePosition.commitment` + +`CoreReader/Evidence.lean:42–44`; def. + +```lean +def ValuePosition.commitment {W : Type} (v : ValuePosition W) : Claim W := + fun w => v.selected w = v.adopted + +``` + +#### `CoreReader.Evidence.ValuePosition.consequence` + +`CoreReader/Evidence.lean:45–47`; def. + +```lean +def ValuePosition.consequence {W : Type} (v : ValuePosition W) : Claim W := + fun w => v.objective (v.outcome w v.adopted) ∧ v.constraints w v.adopted + +``` + +#### `CoreReader.Evidence.ValuePosition.activeReasons` + +`CoreReader/Evidence.lean:48–50`; def. + +```lean +def ValuePosition.activeReasons {W : Type} (v : ValuePosition W) : List (Claim W) := + v.reasons.map (fun reason w => reason w v.adopted) + +``` + +#### `CoreReader.Evidence.JointAdoption` + +`CoreReader/Evidence.lean:51–54`; def. + +```lean +def JointAdoption {W : Type} (v : ValuePosition W) : Prop := + ∃ w, Models v.starting w ∧ v.limits w ∧ v.commitment w ∧ + ∀ reason, reason ∈ v.reasons → reason w v.adopted + +``` + +#### `CoreReader.Evidence.ValueProcedure` + +`CoreReader/Evidence.lean:55–60`; def. + +```lean +def ValueProcedure {W : Type} (v : ValuePosition W) : Prop := + v.reasons ≠ [] ∧ JointAdoption v ∧ + (∀ w, Models v.starting w → v.limits w → + (∀ reason, reason ∈ v.reasons → reason w v.adopted) → v.consequence w) ∧ + (∀ w, v.limits w → v.relevantCriticism w → ∃ answer, v.response w = some answer ∧ answer ≠ "") + +``` + +#### `CoreReader.Evidence.Facet` + +`CoreReader/Evidence.lean:61–65`; inductive. + +```lean +inductive Facet (W : Type) where + | empirical (records : List (Record W)) (scope conclusion uncertainty : Claim W) + | inferential (assumptions : Theory W) (conclusion : Claim W) + | value (position : ValuePosition W) + +``` + +#### `CoreReader.Evidence.Facet.claim` + +`CoreReader/Evidence.lean:66–70`; def. + +```lean +def Facet.claim {W : Type} : Facet W → Claim W + | .empirical _ _ p _ => p + | .inferential _ p => p + | .value v => v.commitment + +``` + +#### `CoreReader.Evidence.FacetDischarged` + +`CoreReader/Evidence.lean:71–77`; def. + +```lean +def FacetDischarged {W : Type} : Facet W → Prop + | .empirical records scope p uncertainty => + (∃ w, Compatible records w ∧ scope w) ∧ + Supports records (fun w => scope w → p w) ∧ Supports records uncertainty + | .inferential assumptions p => Satisfiable assumptions ∧ Entails assumptions p + | .value v => ValueProcedure v + +``` + +#### `CoreReader.Evidence.FacetArticulated` + +`CoreReader/Evidence.lean:78–84`; def. + +```lean +def FacetArticulated {W : Type} (a : Articulation W) : Facet W → Prop + | .empirical records scope _ _ => + a.assumptions = singleton (Compatible records) ∧ a.reasons = [Compatible records] ∧ a.limits = scope + | .inferential assumptions _ => + a.assumptions = assumptions ∧ a.reasons = [Models assumptions] ∧ a.limits = (fun _ => True) + | .value v => a.assumptions = v.starting ∧ a.reasons = v.activeReasons ∧ a.limits = v.limits + +``` + +#### `CoreReader.Evidence.canonicalArticulation` + +`CoreReader/Evidence.lean:85–92`; def. + +```lean +def canonicalArticulation {W : Type} : Facet W → Articulation W + | .empirical records scope _ _ => + ⟨["recorded test outcomes", "observation conditions"], singleton (Compatible records), [Compatible records], scope⟩ + | .inferential assumptions _ => + ⟨["stated assumptions", "semantic consequence"], assumptions, [Models assumptions], fun _ => True⟩ + | .value v => + ⟨["adopted position", "reasons and consequences"], v.starting, v.activeReasons, v.limits⟩ + +``` + +#### `CoreReader.Evidence.canonicalFacetArticulated` + +`CoreReader/Evidence.lean:93–96`; theorem. + +```lean +theorem canonicalFacetArticulated {W : Type} (f : Facet W) : + FacetArticulated (canonicalArticulation f) f := by + cases f <;> exact ⟨rfl, rfl, rfl⟩ + +``` + +#### `CoreReader.Evidence.canonicalArticulated` + +`CoreReader/Evidence.lean:97–105`; theorem. + +```lean +theorem canonicalArticulated {W : Type} (f : Facet W) (h : FacetDischarged f) : + Articulated (canonicalArticulation f) := by + cases f with + | empirical records scope p uncertainty => simp [Articulated, canonicalArticulation] + | inferential assumptions p => simp [Articulated, canonicalArticulation] + | value v => + refine ⟨by simp [canonicalArticulation], ?_⟩ + simpa [canonicalArticulation, ValuePosition.activeReasons] using h.1 + +``` + +#### `CoreReader.Evidence.Grounds` + +`CoreReader/Evidence.lean:106–111`; def. + +```lean +def Grounds {W : Type} (claim : Claim W) (articulations : Facet W → Articulation W) + (actualApplicable : Facet W → Prop) (facets : List (Facet W)) : Prop := + facets ≠ [] ∧ (∀ facet, actualApplicable facet → facet ∈ facets) ∧ + ∀ facet, facet ∈ facets → facet.claim = claim ∧ Articulated (articulations facet) ∧ + FacetArticulated (articulations facet) facet ∧ FacetDischarged facet + +``` + +#### `CoreReader.Evidence.AchievementAccountability` + +`CoreReader/Evidence.lean:112–115`; def. + +```lean +def AchievementAccountability {W : Type} (achievement : Claim W) (articulations : Facet W → Articulation W) + (actualApplicable : Facet W → Prop) (facets : List (Facet W)) : Prop := + Grounds achievement articulations actualApplicable facets + +``` + +#### `CoreReader.Evidence.transitionAchievement` + +`CoreReader/Evidence.lean:116–118`; def. + +```lean +def transitionAchievement : Claim TransitionCase := + fun transition => Expanded (transitionBefore transition) (transitionAfter transition) + +``` + +#### `CoreReader.Evidence.transitionPerformanceRecord` + +`CoreReader/Evidence.lean:119–122`; def. + +```lean +def transitionPerformanceRecord : Record TransitionCase := + ⟨fun transition => (transitionAfter transition).constructed.any + (fun operation => operation == .successor && decide (operation.run (transitionInput transition) = 1)), true⟩ + +``` + +#### `CoreReader.Evidence.transitionReportRecord` + +`CoreReader/Evidence.lean:123–127`; def. + +```lean +def transitionReportRecord : Record TransitionCase := + ⟨fun transition => + let report := transitionAnnouncement transition + report.reportedNewOperation == .successor && report.input == 0 && report.expectedOutput == 1, true⟩ + +``` + +#### `CoreReader.Evidence.transitionPerformanceCompatible` + +`CoreReader/Evidence.lean:128–140`; theorem. + +```lean +theorem transitionPerformanceCompatible : + ∀ transition, Compatible [transitionPerformanceRecord] transition ↔ transition = .extend := by + intro transition + constructor + · intro h + have observed := h transitionPerformanceRecord (List.mem_singleton.mpr rfl) + cases transition + · cases observed + · rfl + · intro h; cases h + intro record hr; have hr' := List.mem_singleton.mp hr; subst record + rfl + +``` + +#### `CoreReader.Evidence.transitionSupported` + +`CoreReader/Evidence.lean:141–149`; theorem. + +```lean +theorem transitionSupported : Supports [transitionPerformanceRecord] transitionAchievement := by + intro transition compatible + have h := (transitionPerformanceCompatible transition).1 compatible + subst transition + have reportTrue : (transitionAnnouncement .extend).claim := by + simp [transitionAnnouncement, transitionAfter, transitionInput, + Announcement.claim, GeneratingSystem.report, generatingSystem, extendedState, baseState, Operation.run] + exact announcementClaimImpliesExpansion _ reportTrue + +``` + +#### `CoreReader.Evidence.transitionFacet` + +`CoreReader/Evidence.lean:150–153`; def. + +```lean +def transitionFacet : Facet TransitionCase := + .empirical [transitionPerformanceRecord] (fun transition => transitionInput transition = 0) + transitionAchievement (fun _ => True) + +``` + +#### `CoreReader.Evidence.transitionFacetDischarged` + +`CoreReader/Evidence.lean:154–158`; theorem. + +```lean +theorem transitionFacetDischarged : FacetDischarged transitionFacet := by + refine ⟨⟨.extend, (transitionPerformanceCompatible _).2 rfl, rfl⟩, ?_, ?_⟩ + · intro transition compatible _; exact transitionSupported transition compatible + · intro _ _; trivial + +``` + +#### `CoreReader.Evidence.transitionAccountable` + +`CoreReader/Evidence.lean:159–167`; theorem. + +```lean +theorem transitionAccountable : + AchievementAccountability transitionAchievement canonicalArticulation + (fun facet => facet = transitionFacet) [transitionFacet] := by + refine ⟨by simp, ?_, ?_⟩ + · intro facet hf; subst facet; exact List.mem_singleton.mpr rfl + · intro facet hf; have hf' := List.mem_singleton.mp hf; subst facet + exact ⟨rfl, canonicalArticulated _ transitionFacetDischarged, + canonicalFacetArticulated _, transitionFacetDischarged⟩ + +``` + +#### `CoreReader.Evidence.transitionReportCompatible` + +`CoreReader/Evidence.lean:168–172`; theorem. + +```lean +theorem transitionReportCompatible (transition : TransitionCase) : + Compatible [transitionReportRecord] transition := by + intro record hr; have hr' := List.mem_singleton.mp hr; subst record + rfl + +``` + +#### `CoreReader.Evidence.transitionReportDoesNotSupport` + +`CoreReader/Evidence.lean:173–179`; theorem. + +```lean +theorem transitionReportDoesNotSupport : + Compatible [transitionReportRecord] .inflate ∧ ¬ transitionAchievement .inflate ∧ + ¬ Supports [transitionReportRecord] transitionAchievement := by + have noExpansion : ¬ transitionAchievement .inflate := by + simp [transitionAchievement, transitionBefore, transitionAfter, Expanded, baseState, inflatedState] + exact ⟨transitionReportCompatible _, noExpansion, fun h => noExpansion (h _ (transitionReportCompatible _))⟩ + +``` + +#### `CoreReader.Evidence.ConcreteAchievementExample` + +`CoreReader/Evidence.lean:180–190`; def. + +```lean +def ConcreteAchievementExample : Prop := + AchievementAccountability transitionAchievement canonicalArticulation + (fun facet => facet = transitionFacet) [transitionFacet] ∧ + Compatible [transitionPerformanceRecord] .extend ∧ + Supports [transitionPerformanceRecord] transitionAchievement ∧ transitionAchievement .extend ∧ + (Compatible [transitionReportRecord] .inflate ∧ ¬ transitionAchievement .inflate ∧ + ¬ Supports [transitionReportRecord] transitionAchievement) ∧ + (∀ transition, (transitionAnnouncement transition).before = transitionBefore transition ∧ + (transitionAnnouncement transition).after = transitionAfter transition ∧ + (transitionAnnouncement transition).input = transitionInput transition ∧ transitionInput transition = 0) + +``` + +#### `CoreReader.Evidence.concreteAchievementExample` + +`CoreReader/Evidence.lean:191–196`; theorem. + +```lean +theorem concreteAchievementExample : ConcreteAchievementExample := by + refine ⟨transitionAccountable, (transitionPerformanceCompatible _).2 rfl, transitionSupported, + transitionSupported .extend ((transitionPerformanceCompatible _).2 rfl), + transitionReportDoesNotSupport, ?_⟩ + intro transition; exact ⟨rfl,rfl,rfl,rfl⟩ + +``` + +#### `CoreReader.Evidence.achievementNeedsSupport` + +`CoreReader/Evidence.lean:197–201`; theorem. + +```lean +theorem achievementNeedsSupport {W : Type} (achievement : Claim W) (records : List (Record W)) + (actual : W) (reliableHere : Compatible records actual) (support : Supports records achievement) : + achievement actual ∧ ConcreteAchievementExample := + ⟨support actual reliableHere, concreteAchievementExample⟩ + +``` + +#### `CoreReader.Evidence.supportWeakening` + +`CoreReader/Evidence.lean:202–205`; theorem. + +```lean +theorem supportWeakening {W : Type} (records : List (Record W)) (p q : Claim W) + (support : Supports records p) (weaker : ∀ w, p w → q w) : Supports records q := + fun w hw => weaker w (support w hw) + +``` + +#### `CoreReader.Evidence.evidenceWeakeningCanLoseSupport` + +`CoreReader/Evidence.lean:206–212`; theorem. + +```lean +theorem evidenceWeakeningCanLoseSupport : + Supports ([⟨id, true⟩] : List (Record Bool)) (fun w => w = true) ∧ + ¬ Supports ([] : List (Record Bool)) (fun w => w = true) := by + refine ⟨?_, ?_⟩ + · intro w hw; exact hw ⟨id,true⟩ (by simp) + · intro h; have bad := h false (by intro r hr; cases hr); cases bad + +``` + +#### `CoreReader.Evidence.scopeRestriction` + +`CoreReader/Evidence.lean:213–218`; theorem. + +```lean +theorem scopeRestriction {W X : Type} (records : List (Record W)) (p : W → X → Prop) + (wide narrow : X → Prop) (included : ∀ x, narrow x → wide x) + (support : Supports records (fun w => ∀ x, wide x → p w x)) : + Supports records (fun w => ∀ x, narrow x → p w x) := + fun w hw x hx => support w hw x (included x hx) + +``` + +#### `CoreReader.Evidence.Duties` + +`CoreReader/Evidence.lean:219–220`; def. + +```lean +def Duties {W : Type} (applicable : Facet W → Prop) : Prop := + ∀ f, applicable f → FacetDischarged f +``` + +#### `CoreReader.Evidence.LabeledDuties` + +`CoreReader/Evidence.lean:221–223`; def. + +```lean +def LabeledDuties {W : Type} (_labels : List String) (applicable : Facet W → Prop) : Prop := + Duties applicable + +``` + +#### `CoreReader.Evidence.assessmentUnion` + +`CoreReader/Evidence.lean:224–229`; theorem. + +```lean +theorem assessmentUnion {W : Type} (a b : Facet W → Prop) : + Duties (fun f => a f ∨ b f) ↔ Duties a ∧ Duties b := by + constructor + · intro h; exact ⟨fun f hf => h f (Or.inl hf), fun f hf => h f (Or.inr hf)⟩ + · rintro ⟨ha,hb⟩ f (hf|hf); exact ha f hf; exact hb f hf + +``` + +#### `CoreReader.Evidence.labelsCannotWaive` + +`CoreReader/Evidence.lean:230–232`; theorem. + +```lean +theorem labelsCannotWaive {W : Type} (xs ys : List String) (a : Facet W → Prop) : + LabeledDuties xs a ↔ LabeledDuties ys a := Iff.rfl + +``` + +#### `CoreReader.Evidence.switchRecord` + +`CoreReader/Evidence.lean:233–233`; def. + +```lean +def switchRecord : Record Bool := ⟨id, true⟩ +``` + +#### `CoreReader.Evidence.switchCompatible` + +`CoreReader/Evidence.lean:234–237`; theorem. + +```lean +theorem switchCompatible (w : Bool) : Compatible [switchRecord] w ↔ w = true := by + constructor + · intro h; exact h switchRecord (by simp) + · intro hw r hr; simp only [List.mem_singleton] at hr; cases hr; exact hw +``` + +#### `CoreReader.Evidence.switchSupported` + +`CoreReader/Evidence.lean:238–240`; theorem. + +```lean +theorem switchSupported : Supports [switchRecord] (fun w : Bool => w = true) := + fun w hw => (switchCompatible w).1 hw + +``` + +#### `CoreReader.Evidence.optionBenefit` + +`CoreReader/Evidence.lean:241–241`; def. + +```lean +def optionBenefit (selected : Bool) : Nat := if selected then 4 else 0 +``` + +#### `CoreReader.Evidence.optionCost` + +`CoreReader/Evidence.lean:242–243`; def. + +```lean +def optionCost (selected : Bool) : Nat := if selected then 3 else 0 + +``` + +#### `CoreReader.Evidence.optionReport` + +`CoreReader/Evidence.lean:244–246`; def. + +```lean +def optionReport (selected : Bool) : Prop := + optionCost selected ≤ 3 ∧ optionBenefit selected = (if selected then 4 else 0) + +``` + +#### `CoreReader.Evidence.switchPosition` + +`CoreReader/Evidence.lean:247–259`; def. + +```lean +def switchPosition : ValuePosition Bool where + Position := Bool + Outcome := Nat × Nat + adopted := true + selected := id + outcome := fun _ option => (optionBenefit option, optionCost option) + objective := fun result => result.2 < result.1 + constraints := fun _ option => optionCost option ≤ 3 + starting := singleton (fun w => w = true) + reasons := [fun _ option => optionReport option] + limits := fun _ => True + relevantCriticism := fun w => w = false + response := fun w => if w then some "benefit exceeds cost within budget" else some "reconsider if the budget no longer permits this cost" +``` + +#### `CoreReader.Evidence.switchValueProcedure` + +`CoreReader/Evidence.lean:260–273`; theorem. + +```lean +theorem switchValueProcedure : ValueProcedure switchPosition := by + refine ⟨by simp [switchPosition], ?_, ?_, ?_⟩ + · refine ⟨true, (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩ + intro reason hr + have hr' : reason = (fun (_ : Bool) (option : Bool) => optionReport option) := List.mem_singleton.mp hr + subst reason + exact ⟨by decide, rfl⟩ + · intro w _ _ allReasons + have evidence := allReasons (fun (_ : Bool) (option : Bool) => optionReport option) (List.mem_singleton.mpr rfl) + change optionReport true at evidence + have benefitAboveBudget : 3 < optionBenefit true := by rw [evidence.2]; decide + exact ⟨Nat.lt_of_le_of_lt evidence.1 benefitAboveBudget, evidence.1⟩ + · intro w _ _; cases w <;> simp [switchPosition] + +``` + +#### `CoreReader.Evidence.oppositePosition` + +`CoreReader/Evidence.lean:274–276`; def. + +```lean +def oppositePosition : ValuePosition Bool := + { switchPosition with adopted := false, starting := singleton (fun w => w = false) } + +``` + +#### `CoreReader.Evidence.oppositePositionRejected` + +`CoreReader/Evidence.lean:277–293`; theorem. + +```lean +theorem oppositePositionRejected : JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition := by + have witness : JointAdoption oppositePosition := by + refine ⟨false, (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩ + intro reason hr + have hr' : reason = (fun (_ : Bool) (option : Bool) => optionReport option) := List.mem_singleton.mp hr + subst reason + exact ⟨by decide, rfl⟩ + refine ⟨witness, ?_⟩ + intro h + have allReasons : ∀ reason, reason ∈ oppositePosition.reasons → reason false oppositePosition.adopted := by + intro reason hr + have hr' : reason = (fun (_ : Bool) (option : Bool) => optionReport option) := List.mem_singleton.mp hr + subst reason + exact ⟨by decide, rfl⟩ + have bad := h.2.2.1 false ((modelsSingleton _ _).2 rfl) trivial allReasons + exact Nat.lt_irrefl 0 bad.1 + +``` + +#### `CoreReader.Evidence.contradictoryStartingPosition` + +`CoreReader/Evidence.lean:294–295`; def. + +```lean +def contradictoryStartingPosition : ValuePosition Bool := + { switchPosition with starting := singleton (fun _ => False) } +``` + +#### `CoreReader.Evidence.impossibleAdoptionPosition` + +`CoreReader/Evidence.lean:296–298`; def. + +```lean +def impossibleAdoptionPosition : ValuePosition Bool := + { switchPosition with selected := fun _ => false } + +``` + +#### `CoreReader.Evidence.inadmissibleValuePositionsRejected` + +`CoreReader/Evidence.lean:299–306`; theorem. + +```lean +theorem inadmissibleValuePositionsRejected : + ¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition := by + constructor + · intro h; obtain ⟨w,hw,_,_,_⟩ := h.2.1 + exact (modelsSingleton _ _).1 hw + · intro h; obtain ⟨w,_,_,hw,_⟩ := h.2.1 + cases hw + +``` + +#### `CoreReader.Evidence.unsupportedPosition` + +`CoreReader/Evidence.lean:307–307`; def. + +```lean +def unsupportedPosition : ValuePosition Bool := { switchPosition with reasons := [] } +``` + +#### `CoreReader.Evidence.switchEmpirical` + +`CoreReader/Evidence.lean:308–309`; def. + +```lean +def switchEmpirical : Facet Bool := + .empirical [switchRecord] (fun _ => True) (fun w => w = true) (fun _ => True) +``` + +#### `CoreReader.Evidence.switchEmpiricalDischarged` + +`CoreReader/Evidence.lean:310–314`; theorem. + +```lean +theorem switchEmpiricalDischarged : FacetDischarged switchEmpirical := by + refine ⟨⟨true, (switchCompatible true).2 rfl, trivial⟩, ?_, ?_⟩ + · intro w hw _; exact switchSupported w hw + · intro w _; trivial + +``` + +#### `CoreReader.Evidence.mixedMissingResponsibility` + +`CoreReader/Evidence.lean:315–322`; theorem. + +```lean +theorem mixedMissingResponsibility : + FacetDischarged switchEmpirical ∧ + ¬ LabeledDuties [] (fun f : Facet Bool => f = switchEmpirical ∨ f = .value unsupportedPosition) := by + refine ⟨switchEmpiricalDischarged, ?_⟩ + intro h + have bad := (h (.value unsupportedPosition) (Or.inr rfl)).1 + exact bad rfl + +``` + +#### `CoreReader.Evidence.uninformativeArgument` + +`CoreReader/Evidence.lean:323–324`; def. + +```lean +def uninformativeArgument : Articulation Bool := + ⟨["switch state"], emptyTheory, [fun _ => True], fun _ => True⟩ +``` + +#### `CoreReader.Evidence.articulationNotSupport` + +`CoreReader/Evidence.lean:325–329`; theorem. + +```lean +theorem articulationNotSupport : Articulated uninformativeArgument ∧ + ¬ Entails uninformativeArgument.assumptions (fun w : Bool => w = true) := by + exact ⟨⟨by simp [uninformativeArgument], by simp [uninformativeArgument]⟩, + consistentIncomplete.2.1⟩ + +``` + +#### `CoreReader.Evidence.unrelatedArticulationRejected` + +`CoreReader/Evidence.lean:330–338`; theorem. + +```lean +theorem unrelatedArticulationRejected : + Articulated uninformativeArgument ∧ FacetDischarged switchEmpirical ∧ + ¬ FacetArticulated uninformativeArgument switchEmpirical := by + refine ⟨articulationNotSupport.1, switchEmpiricalDischarged, ?_⟩ + intro h + have relation := congrFun h.1 (Compatible [switchRecord]) + have bad : False := relation.mpr rfl + exact bad + +``` + +#### `CoreReader.Evidence.temperatureRecord` + +`CoreReader/Evidence.lean:339–339`; def. + +```lean +def temperatureRecord : Record (Bool × Bool) := ⟨Prod.fst, true⟩ +``` + +#### `CoreReader.Evidence.temperatureCompatible` + +`CoreReader/Evidence.lean:340–346`; theorem. + +```lean +theorem temperatureCompatible (b : Bool) : + Compatible [temperatureRecord, temperatureRecord] (true,b) := by + intro r hr + simp at hr + cases hr + rfl + +``` + +#### `CoreReader.Evidence.BudgetWorld` + +`CoreReader/Evidence.lean:347–348`; abbrev. + +```lean +abbrev BudgetWorld := Bool × Nat + +``` + +#### `CoreReader.Evidence.announcement` + +`CoreReader/Evidence.lean:349–349`; def. + +```lean +def announcement : String := "activate" +``` + +#### `CoreReader.Evidence.announcementPosition` + +`CoreReader/Evidence.lean:350–363`; def. + +```lean +def announcementPosition : ValuePosition BudgetWorld where + Position := Bool + Outcome := Nat × Nat + adopted := true + selected := Prod.fst + outcome := fun _ option => (optionBenefit option, optionCost option) + objective := fun result => result.2 < result.1 + constraints := fun w option => optionCost option ≤ w.2 + starting := singleton (fun w => w.1 = true) + reasons := [fun _ option => announcement = (if option then "activate" else "disable")] + limits := fun _ => True + relevantCriticism := fun w => w.2 < 3 + response := fun _ => some "reconsider the action when its cost exceeds budget" + +``` + +#### `CoreReader.Evidence.announcementHasJointAdoption` + +`CoreReader/Evidence.lean:364–371`; theorem. + +```lean +theorem announcementHasJointAdoption : JointAdoption announcementPosition := by + refine ⟨(true,0), (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩ + intro reason hr + have hr' : reason = (fun (_ : BudgetWorld) (option : Bool) => announcement = (if option then "activate" else "disable")) := + List.mem_singleton.mp hr + subst reason + rfl + +``` + +#### `CoreReader.Evidence.announcementNotBudgetReason` + +`CoreReader/Evidence.lean:372–389`; theorem. + +```lean +theorem announcementNotBudgetReason : + announcementPosition.reasons ≠ [] ∧ announcementPosition.commitment (true,0) ∧ + (∀ reason, reason ∈ announcementPosition.reasons → reason (true,0) announcementPosition.adopted) ∧ + ¬ announcementPosition.consequence (true,0) ∧ ¬ ValueProcedure announcementPosition := by + refine ⟨by simp [announcementPosition], rfl, ?_, (by intro h; cases h.2), ?_⟩ + · intro reason hr + have hr' : reason = (fun (_ : BudgetWorld) (option : Bool) => announcement = (if option then "activate" else "disable")) := List.mem_singleton.mp hr + subst reason + rfl + · intro h + have allReasons : ∀ reason, reason ∈ announcementPosition.reasons → reason (true,0) announcementPosition.adopted := by + intro reason hr + have hr' : reason = (fun (_ : BudgetWorld) (option : Bool) => announcement = (if option then "activate" else "disable")) := List.mem_singleton.mp hr + subst reason + rfl + have bad := h.2.2.1 (true,0) ((modelsSingleton _ _).2 rfl) trivial allReasons + cases bad.2 + +``` + +#### `CoreReader.Evidence.actionRecord` + +`CoreReader/Evidence.lean:390–390`; def. + +```lean +def actionRecord : Record BudgetWorld := ⟨Prod.fst, true⟩ +``` + +#### `CoreReader.Evidence.actionCompatible` + +`CoreReader/Evidence.lean:391–393`; theorem. + +```lean +theorem actionCompatible (budget : Nat) : Compatible [actionRecord, actionRecord] (true,budget) := by + intro r hr; simp at hr; cases hr; rfl + +``` + +#### `CoreReader.Evidence.measurementRepeatNotSupport` + +`CoreReader/Evidence.lean:394–415`; theorem. + +```lean +theorem measurementRepeatNotSupport : + temperatureRecord.test (true,false) = true ∧ + Compatible [temperatureRecord,temperatureRecord] (true,false) ∧ + Compatible [temperatureRecord,temperatureRecord] (true,true) ∧ + ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + Compatible [actionRecord,actionRecord] (true,0) ∧ + Compatible [actionRecord,actionRecord] (true,3) ∧ + ¬ Supports [actionRecord] announcementPosition.consequence ∧ + ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧ + ¬ ValueProcedure announcementPosition := by + refine ⟨rfl, temperatureCompatible false, temperatureCompatible true, ?_, ?_, + actionCompatible 0, actionCompatible 3, ?_, ?_, announcementNotBudgetReason.2.2.2.2⟩ + · intro h + have bad := h (true,false) (by intro r hr; simp only [List.mem_singleton] at hr; cases hr; rfl) + cases bad + · intro h; have bad := h (true,false) (temperatureCompatible false); cases bad + · intro h + have bad := h (true,0) (by intro r hr; simp only [List.mem_singleton] at hr; cases hr; rfl) + cases bad.2 + · intro h; have bad := h (true,0) (actionCompatible 0); cases bad.2 + +``` + +#### `CoreReader.Evidence.selfAssertionNotReason` + +`CoreReader/Evidence.lean:416–425`; theorem. + +```lean +theorem selfAssertionNotReason : + (unsupportedPosition.commitment true ∧ ¬ ValueProcedure unsupportedPosition) ∧ + (announcementPosition.reasons ≠ [] ∧ announcementPosition.commitment (true,0) ∧ + ¬ announcementPosition.consequence (true,0) ∧ ¬ ValueProcedure announcementPosition) ∧ + JointAdoption announcementPosition := + ⟨⟨rfl, fun h => h.1 rfl⟩, + ⟨announcementNotBudgetReason.1, announcementNotBudgetReason.2.1, + announcementNotBudgetReason.2.2.2.1, announcementNotBudgetReason.2.2.2.2⟩, + announcementHasJointAdoption⟩ + +``` + +#### `CoreReader.Evidence.valueWithoutSelfProof` + +`CoreReader/Evidence.lean:426–433`; theorem. + +```lean +theorem valueWithoutSelfProof : ValueProcedure switchPosition ∧ + Satisfiable switchPosition.starting ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧ + (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧ + (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition) := + ⟨switchValueProcedure, ⟨true, (modelsSingleton _ _).2 rfl⟩, consistentIncomplete.2.1, + oppositePositionRejected, inadmissibleValuePositionsRejected⟩ + +``` + +#### `CoreReader.Evidence.BenefitCostWorld` + +`CoreReader/Evidence.lean:434–434`; abbrev. + +```lean +abbrev BenefitCostWorld := Bool × (Nat × Nat) +``` + +#### `CoreReader.Evidence.measuredOutcome` + +`CoreReader/Evidence.lean:435–436`; def. + +```lean +def measuredOutcome (world : BenefitCostWorld) (option : Bool) : Nat × Nat := + if option then world.2 else (0,0) +``` + +#### `CoreReader.Evidence.benefitReason` + +`CoreReader/Evidence.lean:437–438`; def. + +```lean +def benefitReason (world : BenefitCostWorld) (option : Bool) : Prop := + (measuredOutcome world option).1 = 4 +``` + +#### `CoreReader.Evidence.costReason` + +`CoreReader/Evidence.lean:439–441`; def. + +```lean +def costReason (world : BenefitCostWorld) (option : Bool) : Prop := + (measuredOutcome world option).2 ≤ 3 + +``` + +#### `CoreReader.Evidence.jointReasonPosition` + +`CoreReader/Evidence.lean:442–455`; def. + +```lean +def jointReasonPosition : ValuePosition BenefitCostWorld where + Position := Bool + Outcome := Nat × Nat + adopted := true + selected := Prod.fst + outcome := measuredOutcome + objective := fun result => result.2 < result.1 + constraints := fun world option => (measuredOutcome world option).2 ≤ 3 + starting := singleton (fun world => world.1 = true) + reasons := [benefitReason, costReason] + limits := fun _ => True + relevantCriticism := fun world => 3 < world.2.2 + response := fun _ => some "reassess the option when its cost exceeds the budget" + +``` + +#### `CoreReader.Evidence.jointReasonProcedure` + +`CoreReader/Evidence.lean:456–476`; theorem. + +```lean +theorem jointReasonProcedure : ValueProcedure jointReasonPosition := by + refine ⟨by simp [jointReasonPosition], ?_, ?_, ?_⟩ + · refine ⟨(true,(4,3)), (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩ + intro reason hr + change reason ∈ [benefitReason,costReason] at hr + rcases List.mem_cons.mp hr with hr | hr + · subst reason; rfl + · have hr' := List.mem_singleton.mp hr + subst reason + change 3 ≤ 3; exact Nat.le_refl 3 + · intro world _ _ reasons + have benefit := reasons benefitReason (by change benefitReason ∈ [benefitReason,costReason]; simp) + have cost := reasons costReason (by change costReason ∈ [benefitReason,costReason]; simp) + change (measuredOutcome world true).1 = 4 at benefit + change (measuredOutcome world true).2 ≤ 3 at cost + refine ⟨?_, cost⟩ + have bigger : 3 < (measuredOutcome world true).1 := by rw [benefit]; decide + exact Nat.lt_of_le_of_lt cost bigger + · intro world _ _ + exact ⟨"reassess the option when its cost exceeds the budget", rfl, by decide⟩ + +``` + +#### `CoreReader.Evidence.JointReasonsExample` + +`CoreReader/Evidence.lean:477–484`; def. + +```lean +def JointReasonsExample : Prop := + ValueProcedure jointReasonPosition ∧ + (Models jointReasonPosition.starting (true,(4,5)) ∧ jointReasonPosition.limits (true,(4,5)) ∧ + jointReasonPosition.commitment (true,(4,5)) ∧ benefitReason (true,(4,5)) true ∧ + ¬ jointReasonPosition.consequence (true,(4,5))) ∧ + (Models jointReasonPosition.starting (true,(0,3)) ∧ jointReasonPosition.limits (true,(0,3)) ∧ + jointReasonPosition.commitment (true,(0,3)) ∧ costReason (true,(0,3)) true ∧ + ¬ jointReasonPosition.consequence (true,(0,3))) +``` + +#### `CoreReader.Evidence.jointReasonsExample` + +`CoreReader/Evidence.lean:485–491`; theorem. + +```lean +theorem jointReasonsExample : JointReasonsExample := by + refine ⟨jointReasonProcedure, + ⟨(modelsSingleton _ _).2 rfl, trivial, rfl, rfl, ?_⟩, + ⟨(modelsSingleton _ _).2 rfl, trivial, rfl, Nat.le_refl 3, ?_⟩⟩ + · intro h; have bad : 5 ≤ 3 := h.2; omega + · intro h; have bad : 3 < 0 := h.1; omega + +``` + +#### `CoreReader.Evidence.heterogeneousReasons` + +`CoreReader/Evidence.lean:492–499`; theorem. + +```lean +theorem heterogeneousReasons : + FacetDischarged switchEmpirical ∧ + FacetDischarged (Facet.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) ∧ + FacetDischarged (Facet.value switchPosition) ∧ JointReasonsExample := by + refine ⟨switchEmpiricalDischarged, ⟨⟨true, (modelsSingleton _ _).2 rfl⟩, ?_⟩, switchValueProcedure, jointReasonsExample⟩ + intro w hw; exact (modelsSingleton (fun x : Bool => x = true) w).1 hw + + +``` + +#### `CoreReader.Evidence.zeroRecord` + +`CoreReader/Evidence.lean:500–500`; def. + +```lean +def zeroRecord : Record (Nat → Bool) := ⟨fun f => f 0, true⟩ +``` + +#### `CoreReader.Evidence.localGenerator` + +`CoreReader/Evidence.lean:501–502`; def. + +```lean +def localGenerator (seed : Nat) : Nat → Bool := fun n => n == seed + +``` + +#### `CoreReader.Evidence.allTrue` + +`CoreReader/Evidence.lean:503–503`; def. + +```lean +def allTrue : Claim (Nat → Bool) := fun f => ∀ n, f n = true +``` + +#### `CoreReader.Evidence.zeroCompatible` + +`CoreReader/Evidence.lean:504–508`; theorem. + +```lean +theorem zeroCompatible (f : Nat → Bool) : Compatible [zeroRecord] f ↔ f 0 = true := by + constructor + · intro h; exact h zeroRecord (by simp) + · intro hf r hr; simp only [List.mem_singleton] at hr; cases hr; exact hf + +``` + +#### `CoreReader.Evidence.GeneratingProcess` + +`CoreReader/Evidence.lean:509–513`; structure. + +```lean +structure GeneratingProcess where + owner : Nat + prior : Nat → Bool + generateSeed : Nat + +``` + +#### `CoreReader.Evidence.GeneratingProcess.outputRevision` + +`CoreReader/Evidence.lean:514–516`; def. + +```lean +def GeneratingProcess.outputRevision (process : GeneratingProcess) : Nat → Bool := + fun input => process.prior input || localGenerator process.generateSeed input + +``` + +#### `CoreReader.Evidence.ProducedRevision` + +`CoreReader/Evidence.lean:517–521`; structure. + +```lean +structure ProducedRevision where + producer : Nat + before : Nat → Bool + after : Nat → Bool + +``` + +#### `CoreReader.Evidence.GeneratingProcess.produce` + +`CoreReader/Evidence.lean:522–523`; def. + +```lean +def GeneratingProcess.produce (process : GeneratingProcess) : ProducedRevision := + ⟨process.owner, process.prior, process.outputRevision⟩ +``` + +#### `CoreReader.Evidence.sampleGeneratingProcess` + +`CoreReader/Evidence.lean:524–525`; def. + +```lean +def sampleGeneratingProcess : GeneratingProcess := ⟨17, fun _ => false, 0⟩ + +``` + +#### `CoreReader.Evidence.OwnedRevisionExample` + +`CoreReader/Evidence.lean:526–534`; def. + +```lean +def OwnedRevisionExample : Prop := + sampleGeneratingProcess.produce.producer = sampleGeneratingProcess.owner ∧ + sampleGeneratingProcess.produce.before = sampleGeneratingProcess.prior ∧ + sampleGeneratingProcess.produce.after = sampleGeneratingProcess.outputRevision ∧ + sampleGeneratingProcess.produce.before 0 = false ∧ sampleGeneratingProcess.produce.after 0 = true ∧ + sampleGeneratingProcess.produce.after 1 = false ∧ + Compatible [zeroRecord] sampleGeneratingProcess.produce.after ∧ + ¬ Supports [zeroRecord] allTrue + +``` + +#### `CoreReader.Evidence.ownedRevisionExample` + +`CoreReader/Evidence.lean:535–540`; theorem. + +```lean +theorem ownedRevisionExample : OwnedRevisionExample := by + refine ⟨rfl,rfl,rfl,rfl,rfl,rfl,(zeroCompatible _).2 rfl, ?_⟩ + intro h + have bad := h sampleGeneratingProcess.produce.after ((zeroCompatible _).2 rfl) 1 + cases bad + +``` + +#### `CoreReader.Evidence.selfOriginDoesNotSupport` + +`CoreReader/Evidence.lean:541–549`; theorem. + +```lean +theorem selfOriginDoesNotSupport : + localGenerator 0 0 = true ∧ localGenerator 0 1 = false ∧ + Compatible [zeroRecord] (localGenerator 0) ∧ + ¬ Supports [zeroRecord] allTrue ∧ OwnedRevisionExample := by + refine ⟨rfl, rfl, (zeroCompatible _).2 rfl, ?_, ownedRevisionExample⟩ + intro h + have bad := h (localGenerator 0) ((zeroCompatible _).2 rfl) 1 + cases bad + +``` + +#### `CoreReader.Evidence.localNotUniversal` + +`CoreReader/Evidence.lean:550–559`; theorem. + +```lean +theorem localNotUniversal : + (∃ outside : Nat, outside ≠ 0) ∧ + Compatible [zeroRecord] (fun _ => true) ∧ + Compatible [zeroRecord] (localGenerator 0) ∧ + allTrue (fun _ => true) ∧ ¬ allTrue (localGenerator 0) ∧ + ¬ Supports [zeroRecord] allTrue := by + refine ⟨⟨1, by decide⟩, (zeroCompatible _).2 rfl, (zeroCompatible _).2 rfl, + (fun _ => rfl), ?_, selfOriginDoesNotSupport.2.2.2.1⟩ + intro h; have bad := h 1; cases bad + +``` + +#### `CoreReader.Evidence.hiddenDifference` + +`CoreReader/Evidence.lean:560–565`; theorem. + +```lean +theorem hiddenDifference : + (∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧ + (fun _ : Nat => true) 1 ≠ localGenerator 0 1 := by + refine ⟨?_, by decide⟩ + intro n hn; cases hn; rfl + +``` + +#### `CoreReader.Evidence.singleObservation` + +`CoreReader/Evidence.lean:566–572`; theorem. + +```lean +theorem singleObservation : [zeroRecord].length = 1 ∧ + (∃ f, Compatible [zeroRecord] f) ∧ + Supports [zeroRecord] (fun f => f 0 = true) ∧ + ¬ Supports [zeroRecord] allTrue := + ⟨rfl, ⟨localGenerator 0, (zeroCompatible _).2 rfl⟩, + (fun f hf => (zeroCompatible f).1 hf), selfOriginDoesNotSupport.2.2.2.1⟩ + +``` + +#### `CoreReader.Evidence.arithmeticFacet` + +`CoreReader/Evidence.lean:573–573`; def. + +```lean +def arithmeticFacet : Facet Nat := .inferential (singleton (fun n => n = 2)) (fun n => n + 1 = 3) +``` + +#### `CoreReader.Evidence.usesObservation` + +`CoreReader/Evidence.lean:574–577`; def. + +```lean +def usesObservation {W : Type} : Facet W → Bool + | .empirical _ _ _ _ => true + | _ => false + +``` + +#### `CoreReader.Evidence.noUniversalChain` + +`CoreReader/Evidence.lean:578–584`; theorem. + +```lean +theorem noUniversalChain : FacetDischarged arithmeticFacet ∧ usesObservation arithmeticFacet = false := by + refine ⟨⟨⟨2, (modelsSingleton _ _).2 rfl⟩, ?_⟩, rfl⟩ + intro n hn + have premise := (modelsSingleton (fun x : Nat => x = 2) n).1 hn + change n + 1 = 3 + rw [premise] + +``` + +#### `CoreReader.Evidence.Trial` + +`CoreReader/Evidence.lean:585–589`; structure. + +```lean +structure Trial where + setting : Nat + actualOutcome : Nat + recordedOutcome : Nat + +``` + +#### `CoreReader.Evidence.Verified` + +`CoreReader/Evidence.lean:590–590`; def. + +```lean +def Verified (t : Trial) : Prop := t.recordedOutcome = t.actualOutcome +``` + +#### `CoreReader.Evidence.Reproduced` + +`CoreReader/Evidence.lean:591–591`; def. + +```lean +def Reproduced (a b : Trial) : Prop := a.setting = b.setting +``` + +#### `CoreReader.Evidence.Bounded` + +`CoreReader/Evidence.lean:592–593`; def. + +```lean +def Bounded (t : Trial) : Prop := t.actualOutcome ≤ 2 + +``` + +#### `CoreReader.Evidence.variableOutcomesStableBound` + +`CoreReader/Evidence.lean:594–599`; theorem. + +```lean +theorem variableOutcomesStableBound : + let a : Trial := ⟨0,1,1⟩ + let b : Trial := ⟨0,2,2⟩ + Reproduced a b ∧ a.actualOutcome ≠ b.actualOutcome ∧ Bounded a ∧ Bounded b := by + simp [Reproduced, Bounded] + +``` + +#### `CoreReader.Evidence.verificationReproductionStability` + +`CoreReader/Evidence.lean:600–605`; theorem. + +```lean +theorem verificationReproductionStability : + (Verified ⟨0,1,1⟩ ∧ Verified ⟨1,1,1⟩ ∧ ¬ Reproduced ⟨0,1,1⟩ ⟨1,1,1⟩) ∧ + (Reproduced ⟨0,1,1⟩ ⟨0,3,2⟩ ∧ ¬ Verified ⟨0,3,2⟩ ∧ ¬ Bounded ⟨0,3,2⟩) ∧ + (Bounded ⟨0,1,1⟩ ∧ Bounded ⟨0,2,0⟩ ∧ ¬ Verified ⟨0,2,0⟩) := by + simp [Verified, Reproduced, Bounded] + +``` + +#### `CoreReader.Evidence.Program` + +`CoreReader/Evidence.lean:606–608`; inductive. + +```lean +inductive Program where + | doubleInput + | constant (value : Nat) +``` + +#### `CoreReader.Evidence.Program.eval` + +`CoreReader/Evidence.lean:609–612`; def. + +```lean +def Program.eval : Program → Nat → Nat + | .doubleInput, n => n + n + | .constant value, _ => value + +``` + +#### `CoreReader.Evidence.Process` + +`CoreReader/Evidence.lean:613–616`; structure. + +```lean +structure Process where + output : Nat → Nat + explanation : Option Program + +``` + +#### `CoreReader.Evidence.OutputContract` + +`CoreReader/Evidence.lean:617–618`; def. + +```lean +def OutputContract (p : Process) : Prop := ∀ n, p.output n = n + n + +``` + +#### `CoreReader.Evidence.ExplanationContract` + +`CoreReader/Evidence.lean:619–621`; def. + +```lean +def ExplanationContract (p : Process) : Prop := + ∃ program, p.explanation = some program ∧ ∀ n, program.eval n = p.output n + +``` + +#### `CoreReader.Evidence.outputOnlyProcess` + +`CoreReader/Evidence.lean:622–622`; def. + +```lean +def outputOnlyProcess : Process := ⟨fun n => n + n, none⟩ +``` + +#### `CoreReader.Evidence.explainedProcess` + +`CoreReader/Evidence.lean:623–624`; def. + +```lean +def explainedProcess : Process := ⟨fun n => n + n, some .doubleInput⟩ + +``` + +#### `CoreReader.Evidence.processScope` + +`CoreReader/Evidence.lean:625–627`; def. + +```lean +def processScope (assessed : Process) : Theory Process := + singleton (fun candidate => candidate = assessed) + +``` + +#### `CoreReader.Evidence.processContractFacet` + +`CoreReader/Evidence.lean:628–630`; def. + +```lean +def processContractFacet (assessed : Process) (contract : Claim Process) : Facet Process := + .inferential (processScope assessed) contract + +``` + +#### `CoreReader.Evidence.processScopeModels` + +`CoreReader/Evidence.lean:631–634`; theorem. + +```lean +theorem processScopeModels (assessed candidate : Process) : + Models (processScope assessed) candidate ↔ candidate = assessed := + modelsSingleton (fun process => process = assessed) candidate + +``` + +#### `CoreReader.Evidence.processContractDischarged` + +`CoreReader/Evidence.lean:635–642`; theorem. + +```lean +theorem processContractDischarged (assessed : Process) (contract : Claim Process) (proof : contract assessed) : + FacetDischarged (processContractFacet assessed contract) := by + refine ⟨⟨assessed,(processScopeModels _ _).2 rfl⟩, ?_⟩ + intro candidate hc + have same := (processScopeModels _ _).1 hc + subst candidate + exact proof + +``` + +#### `CoreReader.Evidence.ProcessGrounds` + +`CoreReader/Evidence.lean:643–645`; def. + +```lean +def ProcessGrounds (assessed : Process) (contract : Claim Process) : Prop := + Grounds contract canonicalArticulation (fun facet => facet = processContractFacet assessed contract) + [processContractFacet assessed contract] +``` + +#### `CoreReader.Evidence.processGrounds` + +`CoreReader/Evidence.lean:646–653`; theorem. + +```lean +theorem processGrounds (assessed : Process) (contract : Claim Process) (proof : contract assessed) : + ProcessGrounds assessed contract := by + have discharged := processContractDischarged assessed contract proof + refine ⟨by simp, ?_, ?_⟩ + · intro facet hf; subst facet; exact List.mem_singleton.mpr rfl + · intro facet hf; have hf' := List.mem_singleton.mp hf; subst facet + exact ⟨rfl,canonicalArticulated _ discharged,canonicalFacetArticulated _,discharged⟩ + +``` + +#### `CoreReader.Evidence.outputCorrectByEvaluation` + +`CoreReader/Evidence.lean:654–655`; theorem. + +```lean +theorem outputCorrectByEvaluation : OutputContract outputOnlyProcess := fun _ => rfl + +``` + +#### `CoreReader.Evidence.outputOnlyNoExplanation` + +`CoreReader/Evidence.lean:656–658`; theorem. + +```lean +theorem outputOnlyNoExplanation : ¬ ExplanationContract outputOnlyProcess := by + rintro ⟨program,h,_⟩; cases h + +``` + +#### `CoreReader.Evidence.FullProcessContract` + +`CoreReader/Evidence.lean:659–660`; def. + +```lean +def FullProcessContract (assessed : Process) : Prop := OutputContract assessed ∧ ExplanationContract assessed + +``` + +#### `CoreReader.Evidence.OutputContractEvidence` + +`CoreReader/Evidence.lean:661–665`; def. + +```lean +def OutputContractEvidence : Prop := + ProcessGrounds outputOnlyProcess OutputContract ∧ + Models (processScope outputOnlyProcess) outputOnlyProcess ∧ + ¬ Entails (processScope outputOnlyProcess) FullProcessContract + +``` + +#### `CoreReader.Evidence.outputContractEvidence` + +`CoreReader/Evidence.lean:666–670`; theorem. + +```lean +theorem outputContractEvidence : OutputContractEvidence := by + refine ⟨processGrounds _ _ outputCorrectByEvaluation, (processScopeModels _ _).2 rfl, ?_⟩ + intro stronger + exact outputOnlyNoExplanation (stronger outputOnlyProcess ((processScopeModels _ _).2 rfl)).2 + +``` + +#### `CoreReader.Evidence.ScopedApplicationEvidence` + +`CoreReader/Evidence.lean:671–677`; def. + +```lean +def ScopedApplicationEvidence : Prop := + ProcessGrounds outputOnlyProcess OutputContract ∧ + ProcessGrounds explainedProcess FullProcessContract ∧ + (∀ candidate, Models (processScope outputOnlyProcess) candidate ↔ candidate = outputOnlyProcess) ∧ + (∀ candidate, Models (processScope explainedProcess) candidate ↔ candidate = explainedProcess) ∧ + Satisfiable (processScope outputOnlyProcess) ∧ Satisfiable (processScope explainedProcess) + +``` + +#### `CoreReader.Evidence.scopedApplicationEvidence` + +`CoreReader/Evidence.lean:678–683`; theorem. + +```lean +theorem scopedApplicationEvidence : ScopedApplicationEvidence := by + refine ⟨processGrounds _ _ outputCorrectByEvaluation, processGrounds _ _ ?_, + processScopeModels _,processScopeModels _,⟨_,(processScopeModels _ _).2 rfl⟩, + ⟨_,(processScopeModels _ _).2 rfl⟩⟩ + exact ⟨fun _ => rfl,⟨.doubleInput,rfl,fun _ => rfl⟩⟩ + +``` + +#### `CoreReader.Evidence.outputNotExplanation` + +`CoreReader/Evidence.lean:684–687`; theorem. + +```lean +theorem outputNotExplanation : OutputContract outputOnlyProcess ∧ + ¬ ExplanationContract outputOnlyProcess ∧ OutputContractEvidence := + ⟨outputCorrectByEvaluation, outputOnlyNoExplanation, outputContractEvidence⟩ + +``` + +#### `CoreReader.Evidence.applicationContractsDiffer` + +`CoreReader/Evidence.lean:688–694`; theorem. + +```lean +theorem applicationContractsDiffer : + (OutputContract outputOnlyProcess ∧ ¬ (OutputContract outputOnlyProcess ∧ ExplanationContract outputOnlyProcess)) ∧ + (OutputContract explainedProcess ∧ ExplanationContract explainedProcess) ∧ + ScopedApplicationEvidence := + ⟨⟨outputCorrectByEvaluation, fun h => outputOnlyNoExplanation h.2⟩, + ⟨(fun _ => rfl), ⟨.doubleInput, rfl, fun _ => rfl⟩⟩, scopedApplicationEvidence⟩ + +``` + +#### `CoreReader.Evidence.ExternalCertificate` + +`CoreReader/Evidence.lean:695–700`; structure. + +```lean +structure ExternalCertificate (p : Process) where + assessorId : Nat + assessedId : Nat + distinctParticipants : assessorId ≠ assessedId + outputCorrect : ∀ n, p.output n = n + n + +``` + +#### `CoreReader.Evidence.externalOutputCertificate` + +`CoreReader/Evidence.lean:701–703`; def. + +```lean +def externalOutputCertificate : ExternalCertificate outputOnlyProcess := + ⟨42,7,by decide,fun _ => rfl⟩ + +``` + +#### `CoreReader.Evidence.externalAssessment` + +`CoreReader/Evidence.lean:704–714`; theorem. + +```lean +theorem externalAssessment : + (∃ certificate : ExternalCertificate outputOnlyProcess, + certificate.assessorId = 42 ∧ certificate.assessedId = 7 ∧ + certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧ + ProcessGrounds outputOnlyProcess OutputContract ∧ + ¬ ExplanationContract outputOnlyProcess := + ⟨⟨externalOutputCertificate,rfl,rfl,externalOutputCertificate.distinctParticipants, + externalOutputCertificate.outputCorrect⟩, + processGrounds outputOnlyProcess OutputContract externalOutputCertificate.outputCorrect, + outputOnlyNoExplanation⟩ + +``` + +#### `CoreReader.Evidence.arithmeticArticulation` + +`CoreReader/Evidence.lean:715–716`; def. + +```lean +def arithmeticArticulation : Articulation Nat := canonicalArticulation arithmeticFacet + +``` + +#### `CoreReader.Evidence.nonExecutableAssessment` + +`CoreReader/Evidence.lean:717–725`; theorem. + +```lean +theorem nonExecutableAssessment : + Grounds (fun n : Nat => n + 1 = 3) canonicalArticulation (fun f => f = arithmeticFacet) [arithmeticFacet] ∧ + usesObservation arithmeticFacet = false ∧ + FacetDischarged switchEmpirical ∧ usesObservation switchEmpirical = true := by + refine ⟨⟨by simp, (by intro f hf; cases hf; simp), ?_⟩, rfl, switchEmpiricalDischarged, rfl⟩ + intro f hf; simp only [List.mem_singleton] at hf; cases hf + exact ⟨rfl, canonicalArticulated _ noUniversalChain.1, canonicalFacetArticulated _, noUniversalChain.1⟩ + +end CoreReader.Evidence +``` + +### CoreReader/Integration.lean + +#### `CoreReader.Integration.canonicalGrounds` + +`CoreReader/Integration.lean:8–14`; theorem. + +```lean +theorem canonicalGrounds {W : Type} (claim : Claim W) (facets : List (Facet W)) + (hne : facets ≠ []) (checked : ∀ f ∈ facets, f.claim = claim ∧ FacetDischarged f) : + Grounds claim canonicalArticulation (fun f => f ∈ facets) facets := by + exact ⟨hne, fun _ h => h, fun f hf => + ⟨(checked f hf).1, canonicalArticulated f (checked f hf).2, + canonicalFacetArticulated f, (checked f hf).2⟩⟩ + +``` + +#### `CoreReader.Integration.canonicalGroundsForSingleton` + +`CoreReader/Integration.lean:15–23`; theorem. + +```lean +theorem canonicalGroundsForSingleton {W : Type} (f : Facet W) (checked : FacetDischarged f) : + Grounds f.claim canonicalArticulation (fun g => g = f) [f] := by + refine ⟨by simp, (by intro g hg; cases hg; simp), ?_⟩ + intro g hg + simp only [List.mem_singleton] at hg + subst g + exact ⟨rfl, canonicalArticulated f checked, canonicalFacetArticulated f, checked⟩ + + +``` + +#### `CoreReader.Integration.Mode` + +`CoreReader/Integration.lean:24–27`; inductive. + +```lean +inductive Mode | apply | waive + deriving DecidableEq, Repr + + +``` + +#### `CoreReader.Integration.World` + +`CoreReader/Integration.lean:28–29`; abbrev. + +```lean +abbrev World := Candidate × Mode + +``` + +#### `CoreReader.Integration.actual` + +`CoreReader/Integration.lean:30–32`; def. + +```lean +def actual : World := (.identity, .apply) + + +``` + +#### `CoreReader.Integration.Method` + +`CoreReader/Integration.lean:33–37`; structure. + +```lean +structure Method where + form : Form + realize : World → Implementation + + +``` + +#### `CoreReader.Integration.System` + +`CoreReader/Integration.lean:38–44`; structure. + +```lean +structure System where + owner : Nat + method : Method + principleForm : Form + governance : World → Mode + requirements : Requirements + +``` + +#### `CoreReader.Integration.policyFor` + +`CoreReader/Integration.lean:45–48`; def. + +```lean +def policyFor : Mode → Policy + | .apply => openPolicy + | .waive => neutralPolicy + +``` + +#### `CoreReader.Integration.workFor` + +`CoreReader/Integration.lean:49–52`; def. + +```lean +def workFor (owner : Nat) : Mode → List WorkRecord + | .apply => completeOwnWork owner + | .waive => [] + +``` + +#### `CoreReader.Integration.System.policy` + +`CoreReader/Integration.lean:53–53`; def. + +```lean +def System.policy (s : System) (w : World) : Policy := policyFor (s.governance w) +``` + +#### `CoreReader.Integration.System.rules` + +`CoreReader/Integration.lean:54–54`; def. + +```lean +def System.rules (s : System) (_w : World) : List Principle := ownRules s.owner +``` + +#### `CoreReader.Integration.System.work` + +`CoreReader/Integration.lean:55–56`; def. + +```lean +def System.work (s : System) (w : World) : List WorkRecord := workFor s.owner (s.governance w) + +``` + +#### `CoreReader.Integration.actualSystem` + +`CoreReader/Integration.lean:57–63`; def. + +```lean +def actualSystem : System where + owner := 0 + method := ⟨⟨.method, 0⟩, fun w => implementation w.1⟩ + principleForm := ⟨.principle, 0⟩ + governance := Prod.snd + requirements := identityRequirements + +``` + +#### `CoreReader.Integration.systemCapability` + +`CoreReader/Integration.lean:64–66`; def. + +```lean +def systemCapability (s : System) : Claim World := + fun w => ∀ n, s.requirements.inputs n → (s.method.realize w).run n = s.requirements.expected n + +``` + +#### `CoreReader.Integration.systemBudget` + +`CoreReader/Integration.lean:67–69`; def. + +```lean +def systemBudget (s : System) : Claim World := + fun w => (s.method.realize w).cost ≤ s.requirements.budget + +``` + +#### `CoreReader.Integration.systemObservation` + +`CoreReader/Integration.lean:70–72`; def. + +```lean +def systemObservation (s : System) : Record World := + ⟨fun w => decide ((s.method.realize w).run 0 = s.requirements.expected 0), true⟩ + +``` + +#### `CoreReader.Integration.systemHeld` + +`CoreReader/Integration.lean:73–75`; def. + +```lean +def systemHeld (s : System) : Theory World := + union (singleton (systemCapability s)) (singleton (systemBudget s)) + +``` + +#### `CoreReader.Integration.Question` + +`CoreReader/Integration.lean:76–78`; inductive. + +```lean +inductive Question | correctOutput | affordable + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Integration.systemContext` + +`CoreReader/Integration.lean:79–83`; def. + +```lean +def systemContext (s : System) : Context World Question := + ⟨singleton (Compatible [systemObservation s]), + (fun q => match q with | .correctOutput => systemCapability s | .affordable => systemBudget s), + fun w => (s.method.realize w).domain 0 ∧ w.2 = .apply⟩ + +``` + +#### `CoreReader.Integration.capability` + +`CoreReader/Integration.lean:84–84`; abbrev. + +```lean +abbrev capability := systemCapability actualSystem +``` + +#### `CoreReader.Integration.observation` + +`CoreReader/Integration.lean:85–85`; abbrev. + +```lean +abbrev observation := systemObservation actualSystem +``` + +#### `CoreReader.Integration.held` + +`CoreReader/Integration.lean:86–86`; abbrev. + +```lean +abbrev held := systemHeld actualSystem +``` + +#### `CoreReader.Integration.context` + +`CoreReader/Integration.lean:87–89`; abbrev. + +```lean +abbrev context := systemContext actualSystem + + +``` + +#### `CoreReader.Integration.observationIdentifies` + +`CoreReader/Integration.lean:90–94`; theorem. + +```lean +theorem observationIdentifies (w : World) : Compatible [observation] w ↔ w.1 = .identity := by + rcases w with ⟨candidate, mode⟩ + cases candidate <;> simp [Compatible, observation, systemObservation, actualSystem, + implementation, identityRequirements, identityImpl, successorImpl] + +``` + +#### `CoreReader.Integration.capabilityActual` + +`CoreReader/Integration.lean:95–96`; theorem. + +```lean +theorem capabilityActual : capability actual := fun _ _ => rfl + +``` + +#### `CoreReader.Integration.observedCapability` + +`CoreReader/Integration.lean:97–104`; theorem. + +```lean +theorem observedCapability : Supports [observation] capability := by + intro w hw + have hid := (observationIdentifies w).1 hw + rcases w with ⟨candidate, mode⟩ + change candidate = .identity at hid + subst candidate + exact fun _ _ => rfl + +``` + +#### `CoreReader.Integration.capabilityFacet` + +`CoreReader/Integration.lean:105–106`; def. + +```lean +def capabilityFacet : Facet World := .empirical [observation] (fun _ => True) capability (fun _ => True) + +``` + +#### `CoreReader.Integration.capabilityFacetChecked` + +`CoreReader/Integration.lean:107–110`; theorem. + +```lean +theorem capabilityFacetChecked : FacetDischarged capabilityFacet := by + exact ⟨⟨actual, (observationIdentifies actual).2 rfl, trivial⟩, + (fun w hw _ => observedCapability w hw), fun _ _ => trivial⟩ + +``` + +#### `CoreReader.Integration.capabilityGrounds` + +`CoreReader/Integration.lean:111–114`; theorem. + +```lean +theorem capabilityGrounds : Grounds capability canonicalArticulation + (fun f => f = capabilityFacet) [capabilityFacet] := + canonicalGroundsForSingleton capabilityFacet capabilityFacetChecked + +``` + +#### `CoreReader.Integration.actualAdmissible` + +`CoreReader/Integration.lean:115–119`; theorem. + +```lean +theorem actualAdmissible : Admissible held context actual := by + refine ⟨(modelsUnion _ _ _).2 ⟨(modelsSingleton _ _).2 capabilityActual, + (modelsSingleton _ _).2 (by change 1 ≤ 1; decide)⟩, + (modelsSingleton _ _).2 ((observationIdentifies actual).2 rfl), trivial, rfl⟩ + +``` + +#### `CoreReader.Integration.jointConsistent` + +`CoreReader/Integration.lean:120–123`; theorem. + +```lean +theorem jointConsistent : Consistent held context := + consequenceConsistency held context ⟨actual, actualAdmissible⟩ + + +``` + +#### `CoreReader.Integration.Charter` + +`CoreReader/Integration.lean:124–128`; def. + +```lean +def Charter (s : System) (w : World) : Prop := + Generative (s.policy w) ∧ Consistent (systemHeld s) (systemContext s) ∧ + Reflexive s.owner (s.rules w) (s.work w) ∧ + (s.policy w).current s.method.form ∧ (s.policy w).current s.principleForm + +``` + +#### `CoreReader.Integration.charterChecked` + +`CoreReader/Integration.lean:129–132`; theorem. + +```lean +theorem charterChecked : Charter actualSystem actual := + ⟨⟨Or.inl rfl, fun _ _ => trivial⟩, jointConsistent, completeOwnWork_reflexive 0, rfl, rfl⟩ + + +``` + +#### `CoreReader.Integration.revisedHeld` + +`CoreReader/Integration.lean:133–135`; def. + +```lean +def revisedHeld : Theory World := union held + (singleton (fun w => (actualSystem.method.realize w).run 0 = actualSystem.requirements.expected 0)) + +``` + +#### `CoreReader.Integration.initialSnapshot` + +`CoreReader/Integration.lean:136–136`; def. + +```lean +def initialSnapshot : Snapshot World Question := ⟨held, context, 0⟩ +``` + +#### `CoreReader.Integration.revisedSnapshot` + +`CoreReader/Integration.lean:137–138`; def. + +```lean +def revisedSnapshot : Snapshot World Question := ⟨revisedHeld, context, 1⟩ + +``` + +#### `CoreReader.Integration.revisionKeepsConsistency` + +`CoreReader/Integration.lean:139–150`; theorem. + +```lean +theorem revisionKeepsConsistency : + Charter actualSystem actual ∧ Consistent revisedHeld context ∧ + TruthfulReport initialSnapshot revisedSnapshot true ∧ + ¬ TruthfulReport initialSnapshot revisedSnapshot false := by + refine ⟨charterChecked, consequenceConsistency revisedHeld context ⟨actual, + (modelsUnion _ _ _).2 ⟨actualAdmissible.1, (modelsSingleton _ _).2 rfl⟩, + actualAdmissible.2⟩, (fun _ => rfl), ?_⟩ + intro h + have bad := h (Or.inr (by decide)) + cases bad + + +``` + +#### `CoreReader.Integration.OwnCapabilityDuty` + +`CoreReader/Integration.lean:151–154`; def. + +```lean +def OwnCapabilityDuty (s : System) (w : World) (facets : List (Facet World)) : Prop := + Performed (s.work w) (.system s.owner) .assessment ∧ + Grounds (systemCapability s) canonicalArticulation (fun f => f ∈ facets) facets + +``` + +#### `CoreReader.Integration.ownCapabilityGrounded` + +`CoreReader/Integration.lean:155–162`; theorem. + +```lean +theorem ownCapabilityGrounded : + OwnCapabilityDuty actualSystem actual [capabilityFacet] ∧ capability actual := by + refine ⟨⟨?_, ?_⟩, capabilityActual⟩ + · exact ownAssessmentPerformed 0 (.system 0) (by simp [ownSubjects]) + · exact canonicalGrounds capability [capabilityFacet] (by simp) + (by intro f hf; simp only [List.mem_singleton] at hf; cases hf; exact ⟨rfl, capabilityFacetChecked⟩) + + +``` + +#### `CoreReader.Integration.costAllowanceRecord` + +`CoreReader/Integration.lean:163–165`; def. + +```lean +def costAllowanceRecord : Record World := + ⟨fun w => decide ((actualSystem.method.realize w).cost ≤ 2), true⟩ + +``` + +#### `CoreReader.Integration.unsupportedCapabilityFacet` + +`CoreReader/Integration.lean:166–168`; def. + +```lean +def unsupportedCapabilityFacet : Facet World := + .empirical [costAllowanceRecord] (fun _ => True) capability (fun _ => True) + +``` + +#### `CoreReader.Integration.costCompatibleWithFailure` + +`CoreReader/Integration.lean:169–174`; theorem. + +```lean +theorem costCompatibleWithFailure : Compatible [costAllowanceRecord] (.successor, .apply) := by + intro r hr + simp only [List.mem_singleton] at hr + subst r + rfl + +``` + +#### `CoreReader.Integration.costDoesNotSupportOutput` + +`CoreReader/Integration.lean:175–179`; theorem. + +```lean +theorem costDoesNotSupportOutput : ¬ Supports [costAllowanceRecord] capability := by + intro h + have bad := h (.successor, .apply) costCompatibleWithFailure 0 trivial + cases bad + +``` + +#### `CoreReader.Integration.unsupportedGrounds` + +`CoreReader/Integration.lean:180–186`; theorem. + +```lean +theorem unsupportedGrounds : ¬ Grounds capability canonicalArticulation + (fun f => f = unsupportedCapabilityFacet) [unsupportedCapabilityFacet] := by + intro h + have discharged := (h.2.2 unsupportedCapabilityFacet (by simp)).2.2.2 + exact costDoesNotSupportOutput (fun w hw => discharged.2.1 w hw trivial) + + +``` + +#### `CoreReader.Integration.Commitment` + +`CoreReader/Integration.lean:187–190`; inductive. + +```lean +inductive Commitment | generation | consistency | reflexivity | grounds | choice + deriving DecidableEq, Repr + + +``` + +#### `CoreReader.Integration.groundsPermission` + +`CoreReader/Integration.lean:191–196`; def. + +```lean +def groundsPermission (mode : Mode) (claim : Claim World) (a : Facet World → Articulation World) + (applicable : Facet World → Prop) (facets : List (Facet World)) : Prop := + match mode with + | .apply => Grounds claim a applicable facets + | .waive => True + +``` + +#### `CoreReader.Integration.GroundsProvision` + +`CoreReader/Integration.lean:197–200`; def. + +```lean +def GroundsProvision (mode : Mode) : Prop := + ∀ claim a applicable facets, groundsPermission mode claim a applicable facets → + Grounds claim a applicable facets + +``` + +#### `CoreReader.Integration.groundsProvisionMeaning` + +`CoreReader/Integration.lean:201–211`; theorem. + +```lean +theorem groundsProvisionMeaning (mode : Mode) : GroundsProvision mode ↔ mode = .apply := by + cases mode with + | apply => exact ⟨fun _ => rfl, fun _ _ _ _ _ h => h⟩ + | waive => + constructor + · intro h + exact False.elim (unsupportedGrounds (h capability canonicalArticulation + (fun f => f = unsupportedCapabilityFacet) [unsupportedCapabilityFacet] trivial)) + · intro h; cases h + + +``` + +#### `CoreReader.Integration.consistencyPermission` + +`CoreReader/Integration.lean:212–214`; def. + +```lean +def consistencyPermission (mode : Mode) (t : Theory World) (c : Context World Question) : Prop := + match mode with | .apply => Consistent t c | .waive => True + +``` + +#### `CoreReader.Integration.conflictingHeld` + +`CoreReader/Integration.lean:215–216`; def. + +```lean +def conflictingHeld : Theory World := union (singleton capability) (singleton (fun w => ¬ capability w)) + +``` + +#### `CoreReader.Integration.conflictConsequences` + +`CoreReader/Integration.lean:217–222`; theorem. + +```lean +theorem conflictConsequences : + Consequence conflictingHeld context .correctOutput true ∧ + Consequence conflictingHeld context .correctOutput false := by + exact ⟨fun w hw => hw.1 capability (Or.inl rfl), + fun w hw => hw.1 (fun w => ¬ capability w) (Or.inr rfl)⟩ + +``` + +#### `CoreReader.Integration.conflictingHeldInconsistent` + +`CoreReader/Integration.lean:223–226`; theorem. + +```lean +theorem conflictingHeldInconsistent : ¬ Consistent conflictingHeld context := + conflictRequiresChange conflictingHeld context .correctOutput conflictConsequences.1 conflictConsequences.2 + + +``` + +#### `CoreReader.Integration.choicePermission` + +`CoreReader/Integration.lean:227–230`; def. + +```lean +def choicePermission (mode : Mode) (req : Requirements) (i : Implementation) (reasons : List Reason) : Prop := + match mode with | .apply => JustifiedChoice req i reasons | .waive => True + + +``` + +#### `CoreReader.Integration.proposedOperation` + +`CoreReader/Integration.lean:231–234`; def. + +```lean +def proposedOperation : Mode → Operation + | .apply => .successor + | .waive => .copy + +``` + +#### `CoreReader.Integration.selfSamples` + +`CoreReader/Integration.lean:235–238`; def. + +```lean +def selfSamples : Mode → List Nat + | .apply => [0, 1] + | .waive => [1] + +``` + +#### `CoreReader.Integration.conflictDecision` + +`CoreReader/Integration.lean:239–241`; def. + +```lean +noncomputable def conflictDecision (mode : Mode) : Bool := + @decide (consistencyPermission mode conflictingHeld context) (Classical.propDecidable _) + +``` + +#### `CoreReader.Integration.groundsDecision` + +`CoreReader/Integration.lean:242–245`; def. + +```lean +noncomputable def groundsDecision (mode : Mode) (facet : Facet World) : Bool := + @decide (groundsPermission mode facet.claim canonicalArticulation (fun f => f = facet) [facet]) + (Classical.propDecidable _) + +``` + +#### `CoreReader.Integration.choiceDecision` + +`CoreReader/Integration.lean:246–248`; def. + +```lean +noncomputable def choiceDecision (mode : Mode) (i : Implementation) (reasons : List Reason) : Bool := + @decide (choicePermission mode identityRequirements i reasons) (Classical.propDecidable _) + +``` + +#### `CoreReader.Integration.decisionsApply` + +`CoreReader/Integration.lean:249–260`; theorem. + +```lean +theorem decisionsApply : conflictDecision .apply = false ∧ + groundsDecision .apply unsupportedCapabilityFacet = false ∧ + groundsDecision .apply capabilityFacet = true ∧ + choiceDecision .apply cheapSuccessor [.method .simplicity] = false ∧ + choiceDecision .apply identityImpl objectiveReason = true := by + classical + simp only [conflictDecision, groundsDecision, choiceDecision, consistencyPermission, + groundsPermission, choicePermission] + exact ⟨decide_eq_false conflictingHeldInconsistent, + decide_eq_false unsupportedGrounds, decide_eq_true capabilityGrounds, + decide_eq_false eligibleInternalReasonNotSufficient.2, decide_eq_true identityJustified⟩ + +``` + +#### `CoreReader.Integration.decisionsWaive` + +`CoreReader/Integration.lean:261–271`; theorem. + +```lean +theorem decisionsWaive : conflictDecision .waive = true ∧ + groundsDecision .waive unsupportedCapabilityFacet = true ∧ + choiceDecision .waive cheapSuccessor [.method .simplicity] = true := by + exact ⟨@decide_eq_true (consistencyPermission .waive conflictingHeld context) + (Classical.propDecidable _) trivial, + @decide_eq_true (groundsPermission .waive unsupportedCapabilityFacet.claim canonicalArticulation + (fun f => f = unsupportedCapabilityFacet) [unsupportedCapabilityFacet]) (Classical.propDecidable _) trivial, + @decide_eq_true (choicePermission .waive identityRequirements cheapSuccessor [.method .simplicity]) + (Classical.propDecidable _) trivial⟩ + + +``` + +#### `CoreReader.Integration.commitmentPositionFor` + +`CoreReader/Integration.lean:272–328`; def. + +```lean +noncomputable def commitmentPositionFor (c : Commitment) (chosenMode : Mode) : ValuePosition World := + match c with + | .generation => { + Position := Mode, Outcome := Operation, adopted := chosenMode, selected := actualSystem.governance, + outcome := fun _ mode => proposedOperation mode, + objective := fun op => op.run 0 ≠ Operation.copy.run 0, + constraints := fun _ mode => Generative (policyFor mode), + starting := singleton (fun w => actualSystem.governance w = chosenMode), + reasons := [fun _ mode => (proposedOperation mode).run 0 = 1 ∧ Operation.copy.run 0 = 0], + limits := fun w => w.1 = .identity, + relevantCriticism := fun _ => ¬ Expanded baseState inflatedState, + response := fun _ => some "Pursuing expansion does not guarantee it; assess the actual before and after capabilities separately" } + | .consistency => { + Position := Mode, Outcome := Bool, adopted := chosenMode, selected := actualSystem.governance, + outcome := fun _ mode => conflictDecision mode, + objective := fun accepted => accepted = false, + constraints := fun _ mode => consistencyPermission mode held context, + starting := singleton (fun w => actualSystem.governance w = chosenMode), + reasons := [fun _ _ => Consequence conflictingHeld context .correctOutput true ∧ + Consequence conflictingHeld context .correctOutput false], + limits := fun w => w.1 = .identity, + relevantCriticism := fun _ => ¬ Entails (emptyTheory : Theory Bool) (fun w => w = true), + response := fun _ => some "Consistency alone does not establish sufficient support; assess the claim with its grounds as well" } + | .reflexivity => { + Position := Mode, Outcome := List Nat, adopted := chosenMode, selected := actualSystem.governance, + outcome := fun _ mode => selfSamples mode, + objective := fun samples => ∃ n ∈ samples, ownArithmeticPrinciple n = false, + constraints := fun _ mode => Reflexive 0 (ownRules 0) (workFor 0 mode), + starting := singleton (fun w => actualSystem.governance w = chosenMode), + reasons := [fun _ _ => ownArithmeticPrinciple 0 = false ∧ ownArithmeticPrinciple 1 = true], + limits := fun w => w.1 = .identity, + relevantCriticism := fun _ => selfTest [1] = true ∧ ownArithmeticPrinciple 0 = false, + response := fun _ => some "A passing self-test does not certify the principle; retain the relevant counterexample and its scope" } + | .grounds => { + Position := Mode, Outcome := Bool, adopted := chosenMode, selected := actualSystem.governance, + outcome := fun _ mode => groundsDecision mode unsupportedCapabilityFacet, + objective := fun accepted => accepted = false, + constraints := fun _ mode => groundsPermission mode capability canonicalArticulation + (fun f => f = capabilityFacet) [capabilityFacet], + starting := singleton (fun w => actualSystem.governance w = chosenMode), + reasons := [fun _ _ => Compatible [costAllowanceRecord] (.successor, .apply) ∧ + ¬ capability (.successor, .apply)], + limits := fun w => w.1 = .identity, + relevantCriticism := fun _ => OutputContract outputOnlyProcess ∧ ¬ ExplanationContract outputOnlyProcess, + response := fun _ => some "Grounds allows an external output assessment without requiring this process to provide an internal explanation" } + | .choice => { + Position := Mode, Outcome := Bool, adopted := chosenMode, selected := actualSystem.governance, + outcome := fun _ mode => choiceDecision mode cheapSuccessor [.method .simplicity], + objective := fun accepted => accepted = false, + constraints := fun _ mode => choicePermission mode identityRequirements identityImpl objectiveReason, + starting := singleton (fun w => actualSystem.governance w = chosenMode), + reasons := [fun _ _ => cheapSuccessor.run 0 = 1 ∧ identityRequirements.expected 0 = 0 ∧ + cheapSuccessor.cost ≤ identityRequirements.budget], + limits := fun w => w.1 = .identity, + relevantCriticism := fun _ => identityImpl.conventional = true ∧ identityImpl.established = true, + response := fun _ => some "An existing conventional method remains eligible when actual output and budget reasons justify it" } + +``` + +#### `CoreReader.Integration.commitmentPosition` + +`CoreReader/Integration.lean:329–331`; def. + +```lean +noncomputable def commitmentPosition (c : Commitment) : ValuePosition World := commitmentPositionFor c .apply + + +``` + +#### `CoreReader.Integration.positionReasons` + +`CoreReader/Integration.lean:332–345`; theorem. + +```lean +theorem positionReasons (c : Commitment) : + ∀ r ∈ (commitmentPosition c).reasons, r actual (commitmentPosition c).adopted := by + cases c <;> intro r hr <;> dsimp [commitmentPosition, commitmentPositionFor] at hr ⊢ <;> + rcases List.mem_singleton.mp hr with rfl + · exact ⟨rfl, rfl⟩ + · exact conflictConsequences + · exact ⟨rfl, rfl⟩ + · refine ⟨costCompatibleWithFailure, ?_⟩ + intro h + have bad := h 0 trivial + cases bad + · exact ⟨rfl, rfl, by decide⟩ + + +``` + +#### `CoreReader.Integration.positionConsequence` + +`CoreReader/Integration.lean:346–353`; theorem. + +```lean +theorem positionConsequence (c : Commitment) (w : World) : (commitmentPosition c).consequence w := by + cases c <;> dsimp [commitmentPosition, commitmentPositionFor, ValuePosition.consequence] + · exact ⟨by decide, ⟨Or.inl rfl, fun _ _ => trivial⟩⟩ + · exact ⟨decisionsApply.1, jointConsistent⟩ + · exact ⟨⟨0, by simp [selfSamples], rfl⟩, completeOwnWork_reflexive 0⟩ + · exact ⟨decisionsApply.2.1, capabilityGrounds⟩ + · exact ⟨decisionsApply.2.2.2.1, identityJustified⟩ + +``` + +#### `CoreReader.Integration.positionProcedure` + +`CoreReader/Integration.lean:354–366`; theorem. + +```lean +theorem positionProcedure (c : Commitment) : ValueProcedure (commitmentPosition c) := by + refine ⟨?_, ?_, ?_, ?_⟩ + · cases c <;> simp [commitmentPosition, commitmentPositionFor] + · refine ⟨actual, ?_, ?_, ?_, positionReasons c⟩ + · cases c <;> exact (modelsSingleton _ _).2 rfl + · cases c <;> rfl + · cases c <;> rfl + · intro w _ _ _ + exact positionConsequence c w + · intro w _ _ + cases c <;> exact ⟨_, rfl, by decide⟩ + + +``` + +#### `CoreReader.Integration.criticismWithinScope` + +`CoreReader/Integration.lean:367–378`; theorem. + +```lean +theorem criticismWithinScope (c : Commitment) : + (commitmentPosition c).limits actual ∧ (commitmentPosition c).relevantCriticism actual := by + constructor + · cases c <;> rfl + · cases c + · simp [commitmentPosition, commitmentPositionFor, Expanded, baseState, inflatedState] + · exact consistentIncomplete.2.1 + · exact ⟨rfl, rfl⟩ + · exact ⟨outputNotExplanation.1, outputNotExplanation.2.1⟩ + · exact ⟨rfl, rfl⟩ + + +``` + +#### `CoreReader.Integration.oppositeConsequenceFails` + +`CoreReader/Integration.lean:379–397`; theorem. + +```lean +theorem oppositeConsequenceFails (c : Commitment) (w : World) : + ¬ (commitmentPositionFor c .waive).consequence w := by + cases c <;> intro h + · exact permissionNotValuation.2.2 h.2 + · have bad : conflictDecision .waive = false := h.1 + rw [decisionsWaive.1] at bad + cases bad + · obtain ⟨n, hn, hf⟩ := h.1 + change n ∈ [1] at hn + have he : n = 1 := List.mem_singleton.mp hn + subst n + cases hf + · have bad : groundsDecision .waive unsupportedCapabilityFacet = false := h.1 + rw [decisionsWaive.2.1] at bad + cases bad + · have bad : choiceDecision .waive cheapSuccessor [.method .simplicity] = false := h.1 + rw [decisionsWaive.2.2] at bad + cases bad + +``` + +#### `CoreReader.Integration.oppositeProcedureRejected` + +`CoreReader/Integration.lean:398–403`; theorem. + +```lean +theorem oppositeProcedureRejected (c : Commitment) : ¬ ValueProcedure (commitmentPositionFor c .waive) := by + intro h + obtain ⟨w, hs, hl, _, hr⟩ := h.2.1 + exact oppositeConsequenceFails c w (h.2.2.1 w hs hl hr) + + +``` + +#### `CoreReader.Integration.commitmentClaim` + +`CoreReader/Integration.lean:404–405`; def. + +```lean +noncomputable def commitmentClaim (c : Commitment) : Claim World := (commitmentPosition c).commitment + +``` + +#### `CoreReader.Integration.commitmentFacet` + +`CoreReader/Integration.lean:406–407`; def. + +```lean +noncomputable def commitmentFacet (c : Commitment) : Facet World := .value (commitmentPosition c) + +``` + +#### `CoreReader.Integration.reasonsBelongToCommitments` + +`CoreReader/Integration.lean:408–417`; theorem. + +```lean +theorem reasonsBelongToCommitments (c : Commitment) : + Grounds (commitmentClaim c) canonicalArticulation + (fun f => f = commitmentFacet c) [commitmentFacet c] ∧ + JointAdoption (commitmentPosition c) ∧ + (commitmentPosition c).relevantCriticism actual ∧ + ¬ ValueProcedure (commitmentPositionFor c .waive) := by + exact ⟨canonicalGroundsForSingleton (commitmentFacet c) (positionProcedure c), + (positionProcedure c).2.1, (criticismWithinScope c).2, oppositeProcedureRejected c⟩ + + +``` + +#### `CoreReader.Integration.groundsCommitmentIsProvision` + +`CoreReader/Integration.lean:418–422`; theorem. + +```lean +theorem groundsCommitmentIsProvision : commitmentClaim .grounds = (fun w => GroundsProvision w.2) := by + funext w + apply propext + exact (groundsProvisionMeaning w.2).symm + +``` + +#### `CoreReader.Integration.groundsSelfAssessment` + +`CoreReader/Integration.lean:423–435`; theorem. + +```lean +theorem groundsSelfAssessment : + Grounds (fun w => GroundsProvision w.2) canonicalArticulation + (fun f => f = commitmentFacet .grounds) [commitmentFacet .grounds] ∧ + (commitmentPosition .grounds).limits actual ∧ + (commitmentPosition .grounds).relevantCriticism actual ∧ + ¬ ValueProcedure (commitmentPositionFor .grounds .waive) := by + rw [← groundsCommitmentIsProvision] + exact ⟨(reasonsBelongToCommitments .grounds).1, + (criticismWithinScope .grounds).1, (criticismWithinScope .grounds).2, + oppositeProcedureRejected .grounds⟩ + + + +``` + +#### `CoreReader.Integration.PhilosophyMethod` + +`CoreReader/Integration.lean:436–439`; structure. + +```lean +structure PhilosophyMethod where + form : Form + mode : Mode + +``` + +#### `CoreReader.Integration.currentPhilosophy` + +`CoreReader/Integration.lean:440–442`; def. + +```lean +def currentPhilosophy (s : System) (w : World) : PhilosophyMethod := + ⟨s.principleForm, s.governance w⟩ + +``` + +#### `CoreReader.Integration.PhilosophyMethod.review` + +`CoreReader/Integration.lean:443–447`; def. + +```lean +noncomputable def PhilosophyMethod.review (p : PhilosophyMethod) (input : Nat) : Nat := + if input = 0 then + if choiceDecision p.mode identityImpl objectiveReason then 1 else 0 + else if choiceDecision p.mode cheapSuccessor [.method .simplicity] then 1 else 0 + +``` + +#### `CoreReader.Integration.PhilosophyMethod.implementation` + +`CoreReader/Integration.lean:448–457`; def. + +```lean +noncomputable def PhilosophyMethod.implementation (p : PhilosophyMethod) : Implementation where + name := "Current philosophy's proposal review" + conventional := true + established := true + run := p.review + cost := 1 + domain n := n = 0 ∨ n = 1 + explanation := p.review + trace n := [n, p.review n] + +``` + +#### `CoreReader.Integration.proposalRequirements` + +`CoreReader/Integration.lean:458–463`; def. + +```lean +def proposalRequirements : Requirements where + inputs n := n = 0 ∨ n = 1 + expected n := if n = 0 then 1 else 0 + budget := 1 + values _ := True + +``` + +#### `CoreReader.Integration.currentReviewCorrect` + +`CoreReader/Integration.lean:464–471`; theorem. + +```lean +theorem currentReviewCorrect : ∀ n, proposalRequirements.inputs n → + (currentPhilosophy actualSystem actual).review n = proposalRequirements.expected n := by + intro n hn + rcases hn with rfl | rfl <;> + simp [PhilosophyMethod.review, currentPhilosophy, actualSystem, actual, + proposalRequirements, decisionsApply.2.2.2.1, decisionsApply.2.2.2.2] + + +``` + +#### `CoreReader.Integration.existingPhilosophyNotPrivileged` + +`CoreReader/Integration.lean:472–486`; theorem. + +```lean +theorem existingPhilosophyNotPrivileged : + (currentPhilosophy actualSystem actual).form = actualSystem.principleForm ∧ + (currentPhilosophy actualSystem actual).mode = actualSystem.governance actual ∧ + ¬ JustifiedChoice proposalRequirements + (currentPhilosophy actualSystem actual).implementation [.status .standing] ∧ + JustifiedChoice proposalRequirements + (currentPhilosophy actualSystem actual).implementation [.method .output] ∧ + (currentPhilosophy actualSystem actual).review 0 = 1 ∧ + (currentPhilosophy actualSystem actual).review 1 = 0 := by + refine ⟨rfl, rfl, statusOnlyFails _ _ _, ?_, currentReviewCorrect 0 (Or.inl rfl), + currentReviewCorrect 1 (Or.inr rfl)⟩ + exact ⟨⟨currentReviewCorrect, by change 1 ≤ 1; decide⟩, + .method .output, by simp, trivial, currentReviewCorrect⟩ + + +``` + +#### `CoreReader.Integration.applicationClaim` + +`CoreReader/Integration.lean:487–490`; def. + +```lean +def applicationClaim (s : System) (req : Requirements) + (contract : Requirements → Implementation → Prop) : Claim World := + fun w => contract req (s.method.realize w) + +``` + +#### `CoreReader.Integration.ApplicationDuties` + +`CoreReader/Integration.lean:491–498`; def. + +```lean +def ApplicationDuties (s : System) (w : World) (req : Requirements) + (contract : Requirements → Implementation → Prop) + (articulations : Facet World → Articulation World) + (applicable : Facet World → Prop) (facets : List (Facet World)) : Prop := + Reflexive s.owner (s.rules w) (s.work w) ∧ + Grounds (applicationClaim s req contract) articulations applicable facets + + +``` + +#### `CoreReader.Integration.applicationRetainsDuties` + +`CoreReader/Integration.lean:499–509`; theorem. + +```lean +theorem applicationRetainsDuties (s : System) (w : World) (req : Requirements) + (contract : Requirements → Implementation → Prop) + (articulations : Facet World → Articulation World) + (applicable : Facet World → Prop) (facets : List (Facet World)) + (h : ApplicationDuties s w req contract articulations applicable facets) : + Reflexive s.owner (s.rules w) (s.work w) ∧ + (∀ f, applicable f → f ∈ facets) ∧ + (∀ f ∈ facets, f.claim = applicationClaim s req contract ∧ + Articulated (articulations f) ∧ FacetArticulated (articulations f) f ∧ FacetDischarged f) := + ⟨h.1, h.2.2.1, h.2.2.2⟩ + +``` + +#### `CoreReader.Integration.outputContract` + +`CoreReader/Integration.lean:510–512`; def. + +```lean +def outputContract (req : Requirements) (i : Implementation) : Prop := + ∀ n, req.inputs n → i.run n = req.expected n + +``` + +#### `CoreReader.Integration.successorRequirements` + +`CoreReader/Integration.lean:513–516`; def. + +```lean +def successorRequirements : Requirements := + { identityRequirements with expected := fun n => n + 1 } + + +``` + +#### `CoreReader.Integration.changedObjectiveFacet` + +`CoreReader/Integration.lean:517–520`; def. + +```lean +def changedObjectiveFacet : Facet World := + .empirical [observation] (fun _ => True) + (applicationClaim actualSystem successorRequirements outputContract) (fun _ => True) + +``` + +#### `CoreReader.Integration.applicationVariation` + +`CoreReader/Integration.lean:521–536`; theorem. + +```lean +theorem applicationVariation : + ApplicationDuties actualSystem actual identityRequirements outputContract + canonicalArticulation (fun f => f = capabilityFacet) [capabilityFacet] ∧ + ¬ applicationClaim actualSystem successorRequirements outputContract actual ∧ + ¬ Grounds (applicationClaim actualSystem successorRequirements outputContract) + canonicalArticulation (fun f => f = changedObjectiveFacet) [changedObjectiveFacet] := by + refine ⟨⟨completeOwnWork_reflexive 0, capabilityGrounds⟩, ?_, ?_⟩ + · intro h + have bad := h 0 trivial + cases bad + · intro h + have discharged := (h.2.2 changedObjectiveFacet (by simp)).2.2.2 + have bad := discharged.2.1 actual ((observationIdentifies actual).2 rfl) trivial 0 trivial + cases bad + + +``` + +#### `CoreReader.Integration.charterNotGrounds` + +`CoreReader/Integration.lean:537–545`; theorem. + +```lean +theorem charterNotGrounds : + Charter actualSystem actual ∧ + Compatible [costAllowanceRecord] actual ∧ + ¬ Grounds capability canonicalArticulation + (fun f => f = unsupportedCapabilityFacet) [unsupportedCapabilityFacet] := by + exact ⟨charterChecked, (by intro r hr; cases List.mem_singleton.mp hr; rfl), unsupportedGrounds⟩ + + + +``` + +#### `CoreReader.Integration.jointWitness` + +`CoreReader/Integration.lean:546–558`; theorem. + +```lean +theorem jointWitness : + ∃ s : System, ∃ w : World, + Admissible (systemHeld s) (systemContext s) w ∧ Charter s w ∧ + OwnCapabilityDuty s w [capabilityFacet] ∧ systemCapability s w ∧ + JustifiedChoice s.requirements (s.method.realize w) objectiveReason ∧ + (∀ c : Commitment, Grounds (commitmentClaim c) canonicalArticulation + (fun f => f = commitmentFacet c) [commitmentFacet c]) ∧ + s = actualSystem ∧ w = actual := by + exact ⟨actualSystem, actual, actualAdmissible, charterChecked, + ownCapabilityGrounded.1, capabilityActual, identityJustified, + fun c => (reasonsBelongToCommitments c).1, rfl, rfl⟩ + +end CoreReader.Integration +``` + +### CoreReader/Logic.lean + +#### `CoreReader.Logic.Claim` + +`CoreReader/Logic.lean:4–5`; abbrev. + +```lean +abbrev Claim (W : Type) := W → Prop + +``` + +#### `CoreReader.Logic.Theory` + +`CoreReader/Logic.lean:6–7`; abbrev. + +```lean +abbrev Theory (W : Type) := Claim W → Prop + +``` + +#### `CoreReader.Logic.Models` + +`CoreReader/Logic.lean:8–9`; def. + +```lean +def Models {W : Type} (t : Theory W) (w : W) : Prop := ∀ p, t p → p w + +``` + +#### `CoreReader.Logic.Entails` + +`CoreReader/Logic.lean:10–11`; def. + +```lean +def Entails {W : Type} (t : Theory W) (p : Claim W) : Prop := ∀ w, Models t w → p w + +``` + +#### `CoreReader.Logic.Satisfiable` + +`CoreReader/Logic.lean:12–13`; def. + +```lean +def Satisfiable {W : Type} (t : Theory W) : Prop := ∃ w, Models t w + +``` + +#### `CoreReader.Logic.Context` + +`CoreReader/Logic.lean:14–18`; structure. + +```lean +structure Context (W Q : Type) where + assumptions : Theory W + meaning : Q → Claim W + scope : Claim W + +``` + +#### `CoreReader.Logic.Admissible` + +`CoreReader/Logic.lean:19–21`; def. + +```lean +def Admissible {W Q : Type} (t : Theory W) (c : Context W Q) (w : W) : Prop := + Models t w ∧ Models c.assumptions w ∧ c.scope w + +``` + +#### `CoreReader.Logic.Consequence` + +`CoreReader/Logic.lean:22–24`; def. + +```lean +def Consequence {W Q : Type} (t : Theory W) (c : Context W Q) (q : Q) (positive : Bool) : Prop := + ∀ w, Admissible t c w → if positive then c.meaning q w else ¬ c.meaning q w + +``` + +#### `CoreReader.Logic.Consistent` + +`CoreReader/Logic.lean:25–27`; def. + +```lean +def Consistent {W Q : Type} (t : Theory W) (c : Context W Q) : Prop := + ∀ q, ¬ (Consequence t c q true ∧ Consequence t c q false) + +``` + +#### `CoreReader.Logic.consequenceConsistency` + +`CoreReader/Logic.lean:28–33`; theorem. + +```lean +theorem consequenceConsistency {W Q : Type} (t : Theory W) (c : Context W Q) + (inhabited : ∃ w, Admissible t c w) : Consistent t c := by + intro q h + obtain ⟨w, hw⟩ := inhabited + exact (h.2 w hw) (h.1 w hw) + +``` + +#### `CoreReader.Logic.emptyTheory` + +`CoreReader/Logic.lean:34–34`; def. + +```lean +def emptyTheory {W : Type} : Theory W := fun _ => False +``` + +#### `CoreReader.Logic.singleton` + +`CoreReader/Logic.lean:35–35`; def. + +```lean +def singleton {W : Type} (p : Claim W) : Theory W := fun q => q = p +``` + +#### `CoreReader.Logic.union` + +`CoreReader/Logic.lean:36–36`; def. + +```lean +def union {W : Type} (a b : Theory W) : Theory W := fun p => a p ∨ b p +``` + +#### `CoreReader.Logic.modelsSingleton` + +`CoreReader/Logic.lean:37–40`; theorem. + +```lean +theorem modelsSingleton {W : Type} (p : Claim W) (w : W) : Models (singleton p) w ↔ p w := by + constructor + · intro h; exact h p rfl + · intro h q hq; cases hq; exact h +``` + +#### `CoreReader.Logic.modelsUnion` + +`CoreReader/Logic.lean:41–46`; theorem. + +```lean +theorem modelsUnion {W : Type} (a b : Theory W) (w : W) : + Models (union a b) w ↔ Models a w ∧ Models b w := by + constructor + · intro h; exact ⟨fun p hp => h p (Or.inl hp), fun p hp => h p (Or.inr hp)⟩ + · rintro ⟨ha,hb⟩ p (hp|hp); exact ha p hp; exact hb p hp + +``` + +#### `CoreReader.Logic.premiseP` + +`CoreReader/Logic.lean:47–47`; def. + +```lean +def premiseP : Claim (Bool × Bool) := fun w => w.1 = true +``` + +#### `CoreReader.Logic.premiseRule` + +`CoreReader/Logic.lean:48–48`; def. + +```lean +def premiseRule : Claim (Bool × Bool) := fun w => w.1 = true → w.2 = true +``` + +#### `CoreReader.Logic.premiseNotQ` + +`CoreReader/Logic.lean:49–49`; def. + +```lean +def premiseNotQ : Claim (Bool × Bool) := fun w => w.2 ≠ true +``` + +#### `CoreReader.Logic.jointTheory` + +`CoreReader/Logic.lean:50–52`; def. + +```lean +def jointTheory : Theory (Bool × Bool) := + union (singleton premiseP) (union (singleton premiseRule) (singleton premiseNotQ)) + +``` + +#### `CoreReader.Logic.jointConflict` + +`CoreReader/Logic.lean:53–64`; theorem. + +```lean +theorem jointConflict : + Satisfiable (singleton premiseP) ∧ Satisfiable (singleton premiseRule) ∧ + Satisfiable (singleton premiseNotQ) ∧ ¬ Satisfiable jointTheory := by + refine ⟨⟨(true,true), (modelsSingleton _ _).2 rfl⟩, + ⟨(false,false), (modelsSingleton _ _).2 (by intro h; cases h)⟩, + ⟨(false,false), (modelsSingleton _ _).2 (by intro h; cases h)⟩, ?_⟩ + rintro ⟨w, hw⟩ + have hp := hw premiseP (Or.inl rfl) + have hr := hw premiseRule (Or.inr (Or.inl rfl)) + have hn := hw premiseNotQ (Or.inr (Or.inr rfl)) + exact hn (hr hp) + +``` + +#### `CoreReader.Logic.revisionSlice` + +`CoreReader/Logic.lean:65–67`; def. + +```lean +def revisionSlice (time : Nat) : Theory Bool := + singleton (fun w => w = (time == 0)) + +``` + +#### `CoreReader.Logic.revisionCanReverse` + +`CoreReader/Logic.lean:68–79`; theorem. + +```lean +theorem revisionCanReverse : + Satisfiable (revisionSlice 0) ∧ Satisfiable (revisionSlice 1) ∧ + ¬ Satisfiable (union (revisionSlice 0) (revisionSlice 1)) := by + refine ⟨⟨true, (modelsSingleton _ _).2 rfl⟩, + ⟨false, (modelsSingleton _ _).2 rfl⟩, ?_⟩ + rintro ⟨w, hw⟩ + have hs := (modelsUnion _ _ _).1 hw + have hp := (modelsSingleton _ _).1 hs.1 + have hn := (modelsSingleton _ _).1 hs.2 + have bad : true = false := hp.symm.trans hn + cases bad + +``` + +#### `CoreReader.Logic.onQuestion` + +`CoreReader/Logic.lean:80–80`; def. + +```lean +def onQuestion : Unit → Claim Bool := fun _ w => w = true +``` + +#### `CoreReader.Logic.assumptionContext` + +`CoreReader/Logic.lean:81–82`; def. + +```lean +def assumptionContext (b : Bool) : Context Bool Unit := + ⟨singleton (fun w => w = b), onQuestion, fun _ => True⟩ +``` + +#### `CoreReader.Logic.meaningContext` + +`CoreReader/Logic.lean:83–84`; def. + +```lean +def meaningContext (b : Bool) : Context Bool Unit := + ⟨singleton (fun w => w = true), (fun _ w => w = b), fun _ => True⟩ +``` + +#### `CoreReader.Logic.scopeContext` + +`CoreReader/Logic.lean:85–87`; def. + +```lean +def scopeContext (b : Bool) : Context Bool Unit := + ⟨emptyTheory, onQuestion, fun w => w = b⟩ + +``` + +#### `CoreReader.Logic.contextDifferences` + +`CoreReader/Logic.lean:88–109`; theorem. + +```lean +theorem contextDifferences : + (Consequence emptyTheory (assumptionContext true) () true ∧ + Consequence emptyTheory (assumptionContext false) () false) ∧ + (Consequence emptyTheory (meaningContext true) () true ∧ + Consequence emptyTheory (meaningContext false) () false) ∧ + (Consequence emptyTheory (scopeContext true) () true ∧ + Consequence emptyTheory (scopeContext false) () false) ∧ + (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w) := by + have empty : ∀ w : Bool, Models emptyTheory w := by intro w p hp; cases hp + refine ⟨⟨?_, ?_⟩, ⟨?_, ?_⟩, ⟨?_, ?_⟩, ?_, ?_, ?_⟩ + · intro w h; change w = true; exact (modelsSingleton (fun x : Bool => x = true) w).1 h.2.1 + · intro w h hp; have hn := (modelsSingleton _ _).1 h.2.1; cases hp.symm.trans hn + · intro w h; change w = true; exact (modelsSingleton (fun x : Bool => x = true) w).1 h.2.1 + · intro w h hn; have hp := (modelsSingleton _ _).1 h.2.1; cases hp.symm.trans hn + · intro w h; exact h.2.2 + · intro w h hp; cases hp.symm.trans h.2.2 + · intro b; exact ⟨b, empty b, (modelsSingleton _ _).2 rfl, trivial⟩ + · intro b; exact ⟨true, empty true, (modelsSingleton _ _).2 rfl, trivial⟩ + · intro b; exact ⟨b, empty b, empty b, rfl⟩ + +``` + +#### `CoreReader.Logic.Snapshot` + +`CoreReader/Logic.lean:110–114`; structure. + +```lean +structure Snapshot (W Q : Type) where + held : Theory W + context : Context W Q + revisionIdentity : Nat + +``` + +#### `CoreReader.Logic.SameContent` + +`CoreReader/Logic.lean:115–120`; def. + +```lean +def SameContent {W Q : Type} (a b : Snapshot W Q) : Prop := + (∀ p, a.held p ↔ b.held p) ∧ + (∀ p, a.context.assumptions p ↔ b.context.assumptions p) ∧ + (∀ q w, a.context.meaning q w ↔ b.context.meaning q w) ∧ + (∀ w, a.context.scope w ↔ b.context.scope w) + +``` + +#### `CoreReader.Logic.TruthfulReport` + +`CoreReader/Logic.lean:121–123`; def. + +```lean +def TruthfulReport {W Q : Type} (a b : Snapshot W Q) (reported : Bool) : Prop := + (¬ SameContent a b ∨ a.revisionIdentity ≠ b.revisionIdentity) → reported = true + +``` + +#### `CoreReader.Logic.semanticChangeMustBeReported` + +`CoreReader/Logic.lean:124–127`; theorem. + +```lean +theorem semanticChangeMustBeReported {W Q : Type} (a b : Snapshot W Q) (reported : Bool) + (changed : ¬ SameContent a b ∨ a.revisionIdentity ≠ b.revisionIdentity) + (h : TruthfulReport a b reported) : reported = true := h changed + +``` + +#### `CoreReader.Logic.representationOrderIrrelevant` + +`CoreReader/Logic.lean:128–130`; theorem. + +```lean +theorem representationOrderIrrelevant {W : Type} (p q : Claim W) : + ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r := by + intro r; exact or_comm +``` + +#### `CoreReader.Logic.contextSnapshot` + +`CoreReader/Logic.lean:131–133`; def. + +```lean +def contextSnapshot (c : Context Bool Unit) (revision : Nat := 0) : Snapshot Bool Unit := + ⟨emptyTheory, c, revision⟩ + +``` + +#### `CoreReader.Logic.hiddenContextChangeRejected` + +`CoreReader/Logic.lean:134–156`; theorem. + +```lean +theorem hiddenContextChangeRejected : + ¬ TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (meaningContext true)) (contextSnapshot (meaningContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (scopeContext true)) (contextSnapshot (scopeContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (scopeContext true) 0) (contextSnapshot (scopeContext true) 1) false ∧ + (TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) true ∧ + ¬ Models (assumptionContext false).assumptions true) := by + have neq : (fun w : Bool => w = true) ≠ (fun w : Bool => w = false) := by + intro h; have k := congrFun h true; have z : true = false := k.mp rfl; cases z + refine ⟨?_, ?_, ?_, ?_, ?_⟩ + · intro h + have bad := h (Or.inl (by intro s; exact neq ((s.2.1 _).mp rfl))) + cases bad + · intro h + have bad := h (Or.inl (by intro s; have z := (s.2.2.1 () true).mp rfl; cases z)) + cases bad + · intro h + have bad := h (Or.inl (by intro s; have z := (s.2.2.2 true).mp rfl; cases z)) + cases bad + · intro h; have bad := h (Or.inr (by decide)); cases bad + · refine ⟨fun _ => rfl, ?_⟩ + intro h; have z := (modelsSingleton _ _).1 h; cases z + +``` + +#### `CoreReader.Logic.tensionWithoutContradiction` + +`CoreReader/Logic.lean:157–162`; theorem. + +```lean +theorem tensionWithoutContradiction : + (∃ budget : Nat, 4 ≤ budget ∧ budget ≤ 6) ∧ + ¬ ((fun n : Nat => 4 ≤ n) = (fun n : Nat => n ≤ 6)) := by + refine ⟨⟨5, by decide, by decide⟩, ?_⟩ + intro h; have k := congrFun h 0; have bad : 4 ≤ 0 := k.mpr (by decide); cases bad + +``` + +#### `CoreReader.Logic.conflictRequiresChange` + +`CoreReader/Logic.lean:163–166`; theorem. + +```lean +theorem conflictRequiresChange {W Q : Type} (t : Theory W) (c : Context W Q) (q : Q) + (positive : Consequence t c q true) (negative : Consequence t c q false) : + ¬ Consistent t c := fun h => h q ⟨positive,negative⟩ + +``` + +#### `CoreReader.Logic.consistentFalse` + +`CoreReader/Logic.lean:167–171`; theorem. + +```lean +theorem consistentFalse : Satisfiable (singleton (fun w : Bool => w = true)) ∧ + ¬ Models (singleton (fun w : Bool => w = true)) false := by + refine ⟨⟨true, (modelsSingleton _ _).2 rfl⟩, ?_⟩ + intro h; have bad := (modelsSingleton _ _).1 h; cases bad + +``` + +#### `CoreReader.Logic.consistentIncomplete` + +`CoreReader/Logic.lean:172–179`; theorem. + +```lean +theorem consistentIncomplete : Satisfiable (emptyTheory : Theory Bool) ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true) ∧ + ¬ Entails emptyTheory (fun w : Bool => w ≠ true) := by + have empty : ∀ w : Bool, Models emptyTheory w := by intro w p hp; cases hp + refine ⟨⟨true, empty true⟩, ?_, ?_⟩ + · intro h; have bad := h false (empty false); cases bad + · intro h; exact h true (empty true) rfl + +``` + +#### `CoreReader.Logic.compatibilityNotEntailment` + +`CoreReader/Logic.lean:180–187`; theorem. + +```lean +theorem compatibilityNotEntailment : + Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true) := by + refine ⟨⟨true, (modelsUnion _ _ _).2 ⟨?_, (modelsSingleton _ _).2 rfl⟩⟩, + consistentIncomplete.2.1⟩ + intro p hp; cases hp + +end CoreReader.Logic +``` + +### CoreReader/Reflexivity.lean + +#### `CoreReader.Agency.Phase` + +`CoreReader/Reflexivity.lean:5–7`; inductive. + +```lean +inductive Phase | formation | application | revision + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Agency.PrincipleKey` + +`CoreReader/Reflexivity.lean:8–12`; structure. + +```lean +structure PrincipleKey where + owner : Nat + localId : Nat + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Agency.Subject` + +`CoreReader/Reflexivity.lean:13–18`; inductive. + +```lean +inductive Subject + | system (owner : Nat) + | principle (owner id : Nat) + | process (owner id : Nat) (phase : Phase) + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Agency.Subject.owner` + +`CoreReader/Reflexivity.lean:19–23`; def. + +```lean +def Subject.owner : Subject → Nat + | .system n => n + | .principle n _ => n + | .process n _ _ => n + +``` + +#### `CoreReader.Agency.Activity` + +`CoreReader/Reflexivity.lean:24–26`; inductive. + +```lean +inductive Activity | generation | assessment + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Agency.QuestionKind` + +`CoreReader/Reflexivity.lean:27–29`; inductive. + +```lean +inductive QuestionKind | conformity | formationBasis | applicability | revisionGrounds + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Agency.SampleProgram` + +`CoreReader/Reflexivity.lean:30–32`; inductive. + +```lean +inductive SampleProgram | alwaysTrue | onlyAtZero + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Agency.SampleProgram.run` + +`CoreReader/Reflexivity.lean:33–37`; def. + +```lean +def SampleProgram.run : SampleProgram → Nat → Bool + | .alwaysTrue, _ => true + | .onlyAtZero, n => n == 0 + + +``` + +#### `CoreReader.Agency.MethodDraft` + +`CoreReader/Reflexivity.lean:38–42`; structure. + +```lean +structure MethodDraft where + testedInputs : List Nat + claimedScope : List Nat + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Agency.MethodDraft.accepts` + +`CoreReader/Reflexivity.lean:43–46`; def. + +```lean +def MethodDraft.accepts (draft : MethodDraft) (program : SampleProgram) : Bool := + draft.testedInputs.all program.run + + +``` + +#### `CoreReader.Agency.Inquiry` + +`CoreReader/Reflexivity.lean:47–53`; structure. + +```lean +structure Inquiry where + target : Subject + kind : QuestionKind + requestedScope : List Nat + currentMethod : MethodDraft + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Agency.ReasonContent` + +`CoreReader/Reflexivity.lean:54–60`; inductive. + +```lean +inductive ReasonContent + | purpose (inputs : List Nat) + | declaredScope (inputs : List Nat) + | observation (input : Nat) (output : Bool) + | counterexample (program : SampleProgram) (input : Nat) + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Agency.ReasonContent.identifier` + +`CoreReader/Reflexivity.lean:61–67`; def. + +```lean +def ReasonContent.identifier : ReasonContent → Nat + | .purpose _ => 0 + | .declaredScope _ => 1 + | .observation _ _ => 2 + | .counterexample _ _ => 3 + + +``` + +#### `CoreReader.Agency.ReasonObject` + +`CoreReader/Reflexivity.lean:68–73`; structure. + +```lean +structure ReasonObject where + reference : Nat + target : Subject + content : ReasonContent + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Agency.AssessmentResult` + +`CoreReader/Reflexivity.lean:74–76`; inductive. + +```lean +inductive AssessmentResult | supportedWithinScope | insufficient | notApplicable | undetermined + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Agency.WorkOutcome` + +`CoreReader/Reflexivity.lean:77–83`; inductive. + +```lean +inductive WorkOutcome + | assessment (result : AssessmentResult) + | generated (draft : MethodDraft) + deriving DecidableEq, Repr + + + +``` + +#### `CoreReader.Agency.Principle` + +`CoreReader/Reflexivity.lean:84–93`; structure. + +```lean +structure Principle where + key : PrincipleKey + activity : Activity + declaredMethod : MethodDraft + applicable : Subject → Prop + inquiry : Subject → Inquiry + reasons : Subject → List ReasonObject + limits : Subject → List Nat + meaning : Inquiry → List ReasonObject → List Nat → WorkOutcome → Prop + +``` + +#### `CoreReader.Agency.WorkRecord` + +`CoreReader/Reflexivity.lean:94–103`; structure. + +```lean +structure WorkRecord where + usedPrinciple : PrincipleKey + target : Subject + activity : Activity + inquiry : Inquiry + reasons : List ReasonObject + limits : List Nat + outcome : WorkOutcome + deriving DecidableEq, Repr + +``` + +#### `CoreReader.Agency.RegistryCoherent` + +`CoreReader/Reflexivity.lean:104–106`; def. + +```lean +def RegistryCoherent (rules : List Principle) : Prop := + ∀ p ∈ rules, ∀ q ∈ rules, p.key = q.key → p = q + +``` + +#### `CoreReader.Agency.TargetResolved` + +`CoreReader/Reflexivity.lean:107–112`; def. + +```lean +def TargetResolved (rules : List Principle) : Subject → Prop + | .system owner => ∃ p ∈ rules, p.key.owner = owner + | .principle owner id | .process owner id _ => ∃ p ∈ rules, p.key = ⟨owner,id⟩ + + + +``` + +#### `CoreReader.Agency.TargetContentResolved` + +`CoreReader/Reflexivity.lean:113–118`; def. + +```lean +def TargetContentResolved (rules : List Principle) (question : Inquiry) : Prop := + match question.target with + | .system owner => ∃ p ∈ rules, p.key = ⟨owner,0⟩ ∧ question.currentMethod = p.declaredMethod + | .principle owner id | .process owner id _ => + ∃ p ∈ rules, p.key = ⟨owner,id⟩ ∧ question.currentMethod = p.declaredMethod + +``` + +#### `CoreReader.Agency.Performed` + +`CoreReader/Reflexivity.lean:119–122`; def. + +```lean +def Performed (records : List WorkRecord) (s : Subject) (a : Activity) : Prop := + ∃ record ∈ records, record.target = s ∧ record.activity = a + + +``` + +#### `CoreReader.Agency.ReflexiveScope` + +`CoreReader/Reflexivity.lean:123–127`; def. + +```lean +def ReflexiveScope (owner : Nat) (rules : List Principle) (records : List WorkRecord) : Prop := + ∀ rule ∈ rules, ∀ s, s.owner = owner → rule.applicable s → Performed records s rule.activity + + + +``` + +#### `CoreReader.Agency.ValidApplication` + +`CoreReader/Reflexivity.lean:128–145`; structure. + +```lean +structure ValidApplication (rules : List Principle) (rule : Principle) (s : Subject) + (record : WorkRecord) : Prop where + registered : rule ∈ rules + applicable : rule.applicable s + usedIdentity : record.usedPrinciple = rule.key + targetIdentity : record.target = s + targetResolved : TargetResolved rules s + activityIdentity : record.activity = rule.activity + inquiryIdentity : record.inquiry = rule.inquiry s + inquiryTarget : record.inquiry.target = s + targetContent : TargetContentResolved rules record.inquiry + reasonsIdentity : record.reasons = rule.reasons s + reasonsNonempty : record.reasons ≠ [] + reasonTargets : ∀ reason ∈ record.reasons, reason.target = s + limitsIdentity : record.limits = rule.limits s + followsMeaning : rule.meaning record.inquiry record.reasons record.limits record.outcome + + +``` + +#### `CoreReader.Agency.Reflexive` + +`CoreReader/Reflexivity.lean:146–150`; def. + +```lean +def Reflexive (owner : Nat) (rules : List Principle) (records : List WorkRecord) : Prop := + RegistryCoherent rules ∧ + ∀ rule ∈ rules, ∀ s, s.owner = owner → rule.applicable s → + ∃ record ∈ records, ValidApplication rules rule s record + +``` + +#### `CoreReader.Agency.Reflexive.toScope` + +`CoreReader/Reflexivity.lean:151–156`; theorem. + +```lean +theorem Reflexive.toScope {owner : Nat} {rules : List Principle} {records : List WorkRecord} + (h : Reflexive owner rules records) : ReflexiveScope owner rules records := by + intro rule hr s hs ha + obtain ⟨record, hm, hv⟩ := h.2 rule hr s hs ha + exact ⟨record, hm, hv.targetIdentity, hv.activityIdentity⟩ + +``` + +#### `CoreReader.Agency.noSelfExemption` + +`CoreReader/Reflexivity.lean:157–161`; theorem. + +```lean +theorem noSelfExemption (owner : Nat) (rules : List Principle) (records : List WorkRecord) + (h : Reflexive owner rules records) (rule : Principle) (hr : rule ∈ rules) + (s : Subject) (hs : s.owner = owner) (ha : rule.applicable s) : + Performed records s rule.activity := h.toScope rule hr s hs ha + +``` + +#### `CoreReader.Agency.localMethod` + +`CoreReader/Reflexivity.lean:162–163`; def. + +```lean +def localMethod : MethodDraft := ⟨[0],[0]⟩ + +``` + +#### `CoreReader.Agency.inquiryFor` + +`CoreReader/Reflexivity.lean:164–171`; def. + +```lean +def inquiryFor (s : Subject) : Inquiry := + match s with + | .process _ _ .formation => ⟨s, .formationBasis, [0], localMethod⟩ + | .process _ _ .application => ⟨s, .applicability, [0], localMethod⟩ + | .process _ _ .revision => ⟨s, .revisionGrounds, [0,1], localMethod⟩ + | _ => ⟨s, .conformity, [0], localMethod⟩ + + +``` + +#### `CoreReader.Agency.sourceReasonContents` + +`CoreReader/Reflexivity.lean:172–177`; def. + +```lean +def sourceReasonContents : QuestionKind → List ReasonContent + | .formationBasis => [.purpose [0], .declaredScope [0], .observation 0 true] + | .applicability | .conformity => [.declaredScope [0], .observation 0 true] + | .revisionGrounds => [.purpose [0,1], .declaredScope [0], .observation 0 true, + .counterexample .onlyAtZero 1] + +``` + +#### `CoreReader.Agency.reasonsFor` + +`CoreReader/Reflexivity.lean:178–182`; def. + +```lean +def reasonsFor (s : Subject) : List ReasonObject := + (sourceReasonContents (inquiryFor s).kind).map fun content => ⟨content.identifier,s,content⟩ + + + +``` + +#### `CoreReader.Agency.assessInquiry` + +`CoreReader/Reflexivity.lean:183–207`; def. + +```lean +def assessInquiry (question : Inquiry) (reasons : List ReasonObject) (limits : List Nat) : AssessmentResult := + let contents := reasons.map ReasonObject.content + if limits ≠ question.currentMethod.claimedScope then .undetermined else + match question.kind with + | .formationBasis => + if ReasonContent.purpose question.requestedScope ∈ contents ∧ + ReasonContent.declaredScope limits ∈ contents ∧ question.requestedScope = limits + then .supportedWithinScope else .undetermined + | .applicability | .conformity => + if question.requestedScope.all (fun n => limits.contains n) then + if ReasonContent.declaredScope limits ∈ contents ∧ + ReasonContent.observation 0 true ∈ contents ∧ question.requestedScope = [0] + then .supportedWithinScope else .undetermined + else .notApplicable + | .revisionGrounds => + if ReasonContent.purpose question.requestedScope ∈ contents ∧ + ReasonContent.declaredScope limits ∈ contents ∧ + ReasonContent.observation 0 true ∈ contents ∧ + contents.any (fun reason => match reason with + | .counterexample program input => question.requestedScope.contains input && + question.currentMethod.accepts program && + !(program.run input) + | _ => false) + then .insufficient else .undetermined + +``` + +#### `CoreReader.Agency.finiteMethodResult` + +`CoreReader/Reflexivity.lean:208–213`; def. + +```lean +def finiteMethodResult (activity : Activity) (question : Inquiry) + (reasons : List ReasonObject) (limits : List Nat) : WorkOutcome := + match activity with + | .generation => .generated ⟨question.currentMethod.testedInputs,question.requestedScope⟩ + | .assessment => .assessment (assessInquiry question reasons limits) + +``` + +#### `CoreReader.Agency.finiteMethodMeaning` + +`CoreReader/Reflexivity.lean:214–217`; def. + +```lean +def finiteMethodMeaning (activity : Activity) (question : Inquiry) + (reasons : List ReasonObject) (limits : List Nat) (outcome : WorkOutcome) : Prop := + outcome = finiteMethodResult activity question reasons limits + +``` + +#### `CoreReader.Agency.ownSubjects` + +`CoreReader/Reflexivity.lean:218–223`; def. + +```lean +def ownSubjects (owner : Nat) : List Subject := + [.system owner, .principle owner 0, .principle owner 1, + .process owner 0 .formation, .process owner 0 .application, .process owner 0 .revision, + .process owner 1 .formation, .process owner 1 .application, .process owner 1 .revision] + + +``` + +#### `CoreReader.Agency.generationEligible` + +`CoreReader/Reflexivity.lean:224–227`; def. + +```lean +def generationEligible : Subject → Bool + | .process _ _ .application => false + | _ => true + +``` + +#### `CoreReader.Agency.generatingRule` + +`CoreReader/Reflexivity.lean:228–237`; def. + +```lean +def generatingRule (owner : Nat) : Principle where + key := ⟨owner,0⟩ + activity := .generation + declaredMethod := localMethod + applicable s := s ∈ ownSubjects owner ∧ generationEligible s = true + inquiry := inquiryFor + reasons := reasonsFor + limits _ := [0] + meaning := finiteMethodMeaning .generation + +``` + +#### `CoreReader.Agency.assessingRule` + +`CoreReader/Reflexivity.lean:238–247`; def. + +```lean +def assessingRule (owner : Nat) : Principle where + key := ⟨owner,1⟩ + activity := .assessment + declaredMethod := localMethod + applicable s := s ∈ ownSubjects owner + inquiry := inquiryFor + reasons := reasonsFor + limits _ := [0] + meaning := finiteMethodMeaning .assessment + +``` + +#### `CoreReader.Agency.ownRules` + +`CoreReader/Reflexivity.lean:248–250`; def. + +```lean +def ownRules (owner : Nat) : List Principle := [generatingRule owner, assessingRule owner] + + +``` + +#### `CoreReader.Agency.statedOutcome` + +`CoreReader/Reflexivity.lean:251–257`; def. + +```lean +def statedOutcome (activity : Activity) (s : Subject) : WorkOutcome := + match activity with + | .generation => .generated ⟨(inquiryFor s).currentMethod.testedInputs,(inquiryFor s).requestedScope⟩ + | .assessment => .assessment (match (inquiryFor s).kind with + | .revisionGrounds => .insufficient + | _ => .supportedWithinScope) + +``` + +#### `CoreReader.Agency.recordFor` + +`CoreReader/Reflexivity.lean:258–260`; def. + +```lean +def recordFor (rule : Principle) (s : Subject) : WorkRecord := + ⟨rule.key,s,rule.activity,rule.inquiry s,rule.reasons s,rule.limits s,statedOutcome rule.activity s⟩ + +``` + +#### `CoreReader.Agency.reasonsFor_nonempty` + +`CoreReader/Reflexivity.lean:261–266`; theorem. + +```lean +theorem reasonsFor_nonempty (s : Subject) : reasonsFor s ≠ [] := by + cases s with + | system owner => simp [reasonsFor, inquiryFor, sourceReasonContents] + | principle owner id => simp [reasonsFor, inquiryFor, sourceReasonContents] + | process owner id phase => cases phase <;> simp [reasonsFor, inquiryFor, sourceReasonContents] + +``` + +#### `CoreReader.Agency.reasonsFor_target` + +`CoreReader/Reflexivity.lean:267–271`; theorem. + +```lean +theorem reasonsFor_target (s : Subject) : ∀ reason ∈ reasonsFor s, reason.target = s := by + intro reason h + obtain ⟨content, _, rfl⟩ := List.mem_map.mp h + rfl + +``` + +#### `CoreReader.Agency.inquiryFor_target` + +`CoreReader/Reflexivity.lean:272–278`; theorem. + +```lean +theorem inquiryFor_target (s : Subject) : (inquiryFor s).target = s := by + cases s with + | system owner => rfl + | principle owner id => rfl + | process owner id phase => cases phase <;> rfl + + +``` + +#### `CoreReader.Agency.ownContentEvaluates` + +`CoreReader/Reflexivity.lean:279–288`; theorem. + +```lean +theorem ownContentEvaluates (activity : Activity) (s : Subject) : + statedOutcome activity s = finiteMethodResult activity (inquiryFor s) (reasonsFor s) [0] := by + cases activity with + | generation => rfl + | assessment => + cases s with + | system owner => rfl + | principle owner id => rfl + | process owner id phase => cases phase <;> rfl + +``` + +#### `CoreReader.Agency.ownRegistryCoherent` + +`CoreReader/Reflexivity.lean:289–297`; theorem. + +```lean +theorem ownRegistryCoherent (owner : Nat) : RegistryCoherent (ownRules owner) := by + intro p hp q hq hkey + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hp hq + rcases hp with rfl | rfl <;> rcases hq with rfl | rfl + · rfl + · have bad := congrArg PrincipleKey.localId hkey; contradiction + · have bad := congrArg PrincipleKey.localId hkey; contradiction + · rfl + +``` + +#### `CoreReader.Agency.ownTargetResolved` + +`CoreReader/Reflexivity.lean:298–303`; theorem. + +```lean +theorem ownTargetResolved (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) : + TargetResolved (ownRules owner) s := by + simp only [ownSubjects, List.mem_cons, List.not_mem_nil, or_false] at hs + rcases hs with rfl | rfl | rfl | rfl | rfl | rfl | rfl | rfl | rfl <;> + simp [TargetResolved, ownRules, generatingRule, assessingRule] + +``` + +#### `CoreReader.Agency.ownTargetContent` + +`CoreReader/Reflexivity.lean:304–309`; theorem. + +```lean +theorem ownTargetContent (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) : + TargetContentResolved (ownRules owner) (inquiryFor s) := by + simp only [ownSubjects, List.mem_cons, List.not_mem_nil, or_false] at hs + rcases hs with rfl | rfl | rfl | rfl | rfl | rfl | rfl | rfl | rfl <;> + simp [TargetContentResolved, inquiryFor, ownRules, generatingRule, assessingRule] + +``` + +#### `CoreReader.Agency.ownRecordValid` + +`CoreReader/Reflexivity.lean:310–342`; theorem. + +```lean +theorem ownRecordValid (owner : Nat) (rule : Principle) (hr : rule ∈ ownRules owner) + (s : Subject) (ha : rule.applicable s) : + ValidApplication (ownRules owner) rule s (recordFor rule s) := by + have hs : s ∈ ownSubjects owner := by + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl + · exact ha.1 + · exact ha + have hq : rule.inquiry = inquiryFor := by + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl <;> rfl + have hg : rule.reasons = reasonsFor := by + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl <;> rfl + have hl : rule.limits s = [0] := by + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl <;> rfl + have hm : rule.meaning = finiteMethodMeaning rule.activity := by + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl <;> rfl + refine ⟨hr, ha, rfl, rfl, ownTargetResolved owner s hs, rfl, rfl, ?_, ?_, rfl, ?_, ?_, rfl, ?_⟩ + · change (rule.inquiry s).target = s + rw [hq]; exact inquiryFor_target s + · change TargetContentResolved (ownRules owner) (rule.inquiry s) + rw [hq]; exact ownTargetContent owner s hs + · change rule.reasons s ≠ [] + rw [hg]; exact reasonsFor_nonempty s + · change ∀ reason ∈ rule.reasons s, reason.target = s + rw [hg]; exact reasonsFor_target s + · change rule.meaning (rule.inquiry s) (rule.reasons s) (rule.limits s) (statedOutcome rule.activity s) + rw [hm, hq, hg, hl] + exact ownContentEvaluates rule.activity s + +``` + +#### `CoreReader.Agency.completeOwnWork` + +`CoreReader/Reflexivity.lean:343–347`; def. + +```lean +def completeOwnWork (owner : Nat) : List WorkRecord := + (ownSubjects owner).flatMap fun s => + if generationEligible s then [recordFor (generatingRule owner) s, recordFor (assessingRule owner) s] + else [recordFor (assessingRule owner) s] + +``` + +#### `CoreReader.Agency.assessingRecord_member` + +`CoreReader/Reflexivity.lean:348–353`; theorem. + +```lean +theorem assessingRecord_member (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) : + recordFor (assessingRule owner) s ∈ completeOwnWork owner := by + apply List.mem_flatMap.mpr + refine ⟨s,hs,?_⟩ + cases generationEligible s <;> simp + +``` + +#### `CoreReader.Agency.generatingRecord_member` + +`CoreReader/Reflexivity.lean:354–357`; theorem. + +```lean +theorem generatingRecord_member (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) + (hg : generationEligible s = true) : recordFor (generatingRule owner) s ∈ completeOwnWork owner := by + exact List.mem_flatMap.mpr ⟨s,hs,by simp [hg]⟩ + +``` + +#### `CoreReader.Agency.completeOwnWork_reflexive` + +`CoreReader/Reflexivity.lean:358–367`; theorem. + +```lean +theorem completeOwnWork_reflexive (owner : Nat) : + Reflexive owner (ownRules owner) (completeOwnWork owner) := by + refine ⟨ownRegistryCoherent owner, ?_⟩ + intro rule hr s _ ha + refine ⟨recordFor rule s, ?_, ownRecordValid owner rule hr s ha⟩ + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl + · exact generatingRecord_member owner s ha.1 ha.2 + · exact assessingRecord_member owner s ha + +``` + +#### `CoreReader.Agency.ownAssessmentPerformed` + +`CoreReader/Reflexivity.lean:368–371`; theorem. + +```lean +theorem ownAssessmentPerformed (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) : + Performed (completeOwnWork owner) s .assessment := + ⟨recordFor (assessingRule owner) s, assessingRecord_member owner s hs, rfl, rfl⟩ + +``` + +#### `CoreReader.Agency.applicationRule` + +`CoreReader/Reflexivity.lean:372–374`; def. + +```lean +def applicationRule : Principle := + { assessingRule 0 with key := ⟨0,0⟩, applicable := fun s => s = .process 0 0 .application } + +``` + +#### `CoreReader.Agency.applicationWork` + +`CoreReader/Reflexivity.lean:375–376`; def. + +```lean +def applicationWork : List WorkRecord := [recordFor applicationRule (.process 0 0 .application)] + +``` + +#### `CoreReader.Agency.applicationWork_reflexive` + +`CoreReader/Reflexivity.lean:377–395`; theorem. + +```lean +theorem applicationWork_reflexive : Reflexive 0 [applicationRule] applicationWork := by + constructor + · intro p hp q hq _ + simp only [List.mem_singleton] at hp hq + rw [hp,hq] + · intro rule hr s _ ha + simp only [List.mem_singleton] at hr + subst rule + change s = .process 0 0 .application at ha + subst s + refine ⟨recordFor applicationRule (.process 0 0 .application), by simp [applicationWork], ?_⟩ + refine ⟨by simp, rfl, rfl, rfl, ?_, rfl, rfl, rfl, ?_, rfl, ?_, ?_, rfl, ?_⟩ + · exact ⟨applicationRule, by simp, rfl⟩ + · exact ⟨applicationRule, by simp, rfl, rfl⟩ + · exact reasonsFor_nonempty _ + · exact reasonsFor_target _ + · change statedOutcome .assessment (.process 0 0 .application) = finiteMethodResult .assessment (inquiryFor (.process 0 0 .application)) (reasonsFor (.process 0 0 .application)) [0] + exact ownContentEvaluates .assessment _ + +``` + +#### `CoreReader.Agency.applicabilityRetained` + +`CoreReader/Reflexivity.lean:396–416`; theorem. + +```lean +theorem applicabilityRetained (owner : Nat) (rules : List Principle) (records : List WorkRecord) : + (Reflexive owner rules records → ReflexiveScope owner rules records) ∧ + (ReflexiveScope owner rules records ↔ + ∀ rule ∈ rules, ∀ s, s.owner = owner → (¬ rule.applicable s ∨ Performed records s rule.activity)) ∧ + (Reflexive 0 [applicationRule] applicationWork ∧ + ¬ Performed applicationWork (.system 0) .assessment) := by + classical + refine ⟨Reflexive.toScope, ?_, applicationWork_reflexive, ?_⟩ + · constructor + · intro h rule hr s hs + by_cases ha : rule.applicable s + · exact Or.inr (h rule hr s hs ha) + · exact Or.inl ha + · intro h rule hr s hs ha + exact (h rule hr s hs).resolve_left (not_not_intro ha) + · rintro ⟨record, hm, ht, _⟩ + simp only [applicationWork, List.mem_singleton] at hm + subst record + cases ht + +end CoreReader.Agency +``` diff --git a/SoftwareEngineering/lean/philosophy/reviews/code-comparison-final.md b/SoftwareEngineering/lean/philosophy/reviews/code-comparison-final.md new file mode 100644 index 0000000..cc9ebc8 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/code-comparison-final.md @@ -0,0 +1,664 @@ +# R3 independent source comparison and three-way reconciliation + +**Result: all 40 frozen targets, 47 source paragraphs and 175 required semantic cases are accepted within the disclosed bounded representation of Software Engineering 0.2.0 / Core 0.1.2.** The previously identified T16/T20/T31/T37 correspondence gaps are resolved in the fixed R3 code. T38/T39 are accepted after rereviewing the expanded dependencies, not merely their unchanged outer statements. This does not approve later code, final reader editions, bilingual synchronization or the overall delivery state. + +The initial blind explanation, delta blind explanation and initial independent source comparison remain unchanged. This stage first reads the other reviewer's full-initial and F07/F08 reports plus the author's repair response. Agreement below is based on exact new definitions, complete actual types, a fresh independent build/audit and executed probes. Earlier differences in judgment are retained; none is retroactively rewritten as agreement. + +## Object identity and evidence + +The reviewed object is the fixed `third-code-snapshot` copied into `r3-input/third-code-snapshot`, bound to `third-code-hashes.json`. Every supplied hash matched before inspection and after verification. Compared with the prior source-aware snapshot, the nonblank code changed in Adopted, Engineering.Domain, Engineering.Integration, Engineering.Reflection and Engineering.SelfApplication. Other nonblank definitions were reused with that exact comparison disclosed. No public working-tree code was substituted after the snapshot capture. + +A fresh `lake build` of the copied snapshot completed all 15 jobs under the installed Lean 4.33.1. Independent `#check @` and `#print axioms` covered **831 declarations, including 282 theorems**, with exit code 0. Dependencies remain empty or subsets of `propext`, `Classical.choice` and `Quot.sound`; no `sorryAx` or new project axiom appears. The separately supplied `third-check.json` has 59 registered full-type results, build/audit return codes 0 and `semantic_status: not_evaluated`. Its mechanical success was not used as a semantic verdict. + +Probes were supplied to `lean --stdin`, with exact inputs retained as `.txt`. No Lean source file or philosophy file was edited or added by this reviewer. Logs: `r3-build.log`, `r3-actual-audit.log`, `r3-probes.log`, `r3-stability-probe.log`. Complete per-case code locations, full registered type records, exact changed helper excerpts and all source passages are in `source-comparison-r3.json`. + +## T16: declared understanding application, not output explanation alone + +The new `MechanismApplication012` keeps a `Process` and a multiplier/input answer function. `UnderstandingApplication012` requires the full double-output-plus-explanation contract, equality between that process output and the multiplier-2 mechanism, and correct answers for **all** multipliers and inputs according to the same multiplication mechanism. + +The two examples have exactly the same explained process. The negative answer always doubles, so it gives 2 at multiplier 3/input 1; the positive mechanism answer gives 3. The negative result therefore cannot be explained by loss of output correctness or loss of an explanation program. The positive proof handles all multipliers/inputs, and the negative proof uses this concrete counterexample. Their Grounds tasks retain each exact assessed application via a singleton identity assumption, with a satisfiable witness; the bad application's support actually fails. + +This closes the prior gap for an **application-defined mechanism-variation answering capability**. Source §2.3 expressly permits application-defined capability criteria. It does not establish unrestricted cognition, introspection, mental possession of an explanation, or a universal definition of understanding. Calling the added result merely an explanation certificate would understate it; calling it general understanding would overstate it. + +## T31: actual cross-boundary obligation + +The new edge has caller 2, callee 1 and the fixed order-contract label. The coordinated path actually modifies callee 1 with a compiler step and checks the public contract at caller 2. The predicate also checks edge membership, endpoint membership/distinctness and preservation of the fixed finite observable order contract. + +Actual independent evaluation returned `(true, false, false, false)` for the complete obligation, removal of the caller verification, changing the callee to 7, and changing behavior to sorted output. Removing the caller check leaves the crossing itself true. This distinguishes an actual boundary-crossing change from satisfaction of its verification/behavior obligations, and resolves the original missing relation. + +The boundary contract string labels a fixed modeled contract family; the behavior predicate supplies its actual semantics. This is not an interpreter for arbitrary contract strings, a runtime/network dependency model, or a guarantee that every real obligation has been enumerated. The source makes such comparisons contextual, and the preregistered finite case is now present without turning optional inquiries into a universal checklist. + +## T20/T37 and the other reviewer's F07: actual held content and same priority + +`OwnNorm` expands actual generation/reflection, the original empirical and inferential tasks, each core value procedure, selected-value procedure and actual commitment, scope/capability/choice duties, own-fact grounds, and the adopted domain/priority grounds. `ownTheory` is now the union of the fact family and the applicable norm-content family. `allNormativeContentHeld` supplies actual member links; `currentAdmissible` proves each fact and each applicable norm at the same chosen candidate. Consistency consequently constrains this complete union. + +Consistency remains an external constraint on that precise theory, rather than a self-referential member in its own definition. This does not exempt it: `currentConsistency` explicitly proves the constraint. A distinct incompatible-content variation produces both polarities under one question/context while the adoption marker remains true. Its role is to check the disclosed content-sensitive representation, not to prove a metatheorem about every possible encoding. + +`wholeClaimGrounded` proves facts about the fixed model and fulfilled duties from candidate identity. The original empirical, inferential and value tasks are still retained separately in `OwnNorm` and `Inherited`; the identity inference is not a substitute for the original assessment nature. The current domain norm is present for evolvable and absent for simple according to **adoption**, while actual `PriorityConditions` remain true in the simple non-entailment witness. The source's additional domain commitment allows precisely this distinction. + +T20's actual conclusion now includes the previously missing consistencySpecification, full norm-content membership and whole-theory grounds. A probe extracted that consistency directly from `inheritedMutualApplication`; it is no longer only available in an unreturned premise field. The theorem is still a projection theorem with explicit premises, not a derivation that independent principles imply one another. + +For T37, `priorityValueMeaning` proves, for every candidate in the fixed shared context, an equivalence between the evolvable selection commitment and actual `EvolutionPriority`. The reverse direction uses current applicability and absence of departure. `priorityGrounds` uses explicit extensional equality to transport the existing value task's grounds to that exact priority claim. T37 now returns those Grounds, held domain-content membership and complete-theory consistency. A probe extracted both new results from its actual full conclusion. + +This resolves the same-object gap. The context restriction is essential: the equivalence does not say that selecting evolvable is equivalent to every possible priority rule under costs/lifecycles where the antecedent or departure branch changes. + +## The other reviewer's F08: the actual rules become review objects + +The existing generator expression is extracted into `Reflection.generate`; `interpret .generation` uses that function. New review objects generationRule and assessmentRule call the **current** `generate` and `evaluate` through parameterized tests. `ownRuleIdentity` binds actual rule meaning, object contract and applicability. Generation remains applicable at formation/revision and inapplicable at application; assessment applies at all three phases. The new current self objects are not collectively exempted. + +Actual independent probe results were `(true, false, true, false, true)` for the real generator, a generator returning empty output, the evaluator at the sampled case, that same evaluator at the empty-initial-sample case, and the separate sample-aware candidate at that latter case. The current self evaluation of assessmentRule/revision returned `counterexample`. This examines the actual active evaluator, not the earlier static/live batch example as a substitute. + +The “empty sample” failure is relative to the explicitly chosen **sample-aware local contract**. Requested items still run a true test; it is not a demonstration that every form of judgment lacks support without empirical observations. The source permits non-executable inference and denies a universally necessary measurement chain. The candidate `sampleAwareAssessment` is not silently installed as the current evaluator. Likewise, the altered applicability model is a separate revision probe, not a retroactive exemption for current self assessment. No self-proof follows from either passing or failing this test. + +## Strong witnesses and reuse + +The outer statements of `Engineering.jointWitness` and `inheritedDoesNotEntailPriority`, through `:= by`, are byte-identical to the prior frozen delta statements. Their dependencies are stronger: actual held norm content, complete consistency, actual self-rule objects and same-priority support were rereviewed and rebuilt. The evolvable witness keeps its extra present complexity, genuine successor/agent change paths and active no-threat priority. The simple witness keeps continuing lifecycle, satisfied requirements, credible advantage, no cost/temporary escape and actual alternative value adoption while failing the added priority. + +A further same-object probe pairs an unchanged old/current evolvable choice in `revisionFor sharedContext .evolvable` with actual `selfModel .evolvable` reflection. Thus open stable choice is exhibited on the same selected design, rather than relying only on unrelated standalone stability and reflection examples. + +The initial narrow output-function capability, finite cost/forecast assumptions, limited contract scopes, generic vacuity boundaries and arbitrary-interface interpretation limits remain disclosed. Repairs did not convert those bounded representations into empirical certification. Source and frozen target text are unchanged; no Core 0.1.3 condition has been introduced, and none of the 175 required cases was removed, downgraded or reclassified as documentary. + +## Three-way reconciliation + +### Own F01 / T16 + +My preserved initial judgment: partial: ExplanationContract alone does not establish the named understanding case. Other reviewer's preserved initial judgment: accepted-bounded via earlier review; different emphasis preserved. + +Candidate: New same-process multiplier-variation capability and positive/negative Grounds. Independent R3 result: resolved-bounded by actual (2,3) response contrast and all-variation positive theorem; do not upgrade to unrestricted cognition. + +### Own F02 / T20 + +My preserved initial judgment: partial actual conclusion omitted consistency. Other reviewer's preserved initial judgment: pending due F07/F08 whole content and self-rule concerns. + +Candidate: Full OwnNorm theory, actual consistency conclusion and actual self-rule objects. Independent R3 result: resolved-bounded; new consistency can be extracted from the full theorem, original support tasks retained. + +### Own F03 / T31 + +My preserved initial judgment: partial no real boundary relation in cross-obligation case. Other reviewer's preserved initial judgment: accepted-bounded via prior review; not silently treated as prior agreement. + +Candidate: Actual edge/callee-edit/caller-verification/order checks and three negative variants. Independent R3 result: resolved-bounded by independent evaluation; boundary text remains a label within the fixed contract family. + +### Own F04 / T37 + +My preserved initial judgment: partial: five Core value grounds were not same engineering-priority claim; consistency missing. Other reviewer's preserved initial judgment: priority test local accepted, overall pending F07/F08. + +Candidate: priorityValueMeaning, priorityGrounds, exact conclusion and held-domain membership. Independent R3 result: resolved-bounded for fixed sharedContext only; value task unchanged and explicit logical equivalence supplies same claim. + +### Other F07 + +My preserved initial judgment: not separately identified as a blocking full-content omission; currentOwnClaims limitation described. Other reviewer's preserved initial judgment: blocked whole normative-content theory linkage. + +Candidate: OwnNorm expansion, fact/norm union, actualOwnNorm, member bridge, full-theory consistency and variation case. Independent R3 result: agree with resolved-bounded after checking definitions and actual proof; contradiction example is a bounded logical variation, not a fidelity metatheorem. + +### Other F08 + +My preserved initial judgment: not separately identified as a blocking actual-self-rule-object omission; generic evaluate limit retained. Other reviewer's preserved initial judgment: blocked actual generation/assessment rules not represented as self objects. + +Candidate: Actual helpers/meaning/applicability linked to new review objects and finite probes. Independent R3 result: agree with resolved-bounded after actual function tests and self counterexample; no universal sample chain or self-proof follows. + +### T38/T39 composition + +My preserved initial judgment: kernel witnesses accepted; source composition qualified/pending. Other reviewer's preserved initial judgment: strong branches accepted but full correspondence pending F07/F08. + +Candidate: Strong outer statements unchanged; stronger Inherited/ownTheory/selfModel actual dependencies. Independent R3 result: accepted-bounded after transitive rereview; no temporary/cost escape, no substitution of assessment for adoption. + +## All 40 targets + +### T01 — accepted-documentary-boundary + +Authority and roles: adopted commitments, no universal factual assertion or correctness proof; meanings and limits constrain quotation; charter and Grounds mutually constrain without hierarchy; rationale/skills add no philosophical duties; domain preference is additional. + +The source explicitly adopts commitments rather than claiming universal factual truth or deductive hierarchy. The chapter-4 preference is additional. No theorem is required for document authority, and the concrete countermodels must not be promoted into independence of every conceivable formalization. + +### T02 — accepted-bounded + +Self-transcendence requires valuing expansion of understanding and construction and keeping all existing organization, methods and principles open to being surpassed; justified stable acts remain permitted. + +Generative requires valuation of expansion and revisability of every current Form, including organization, method and principle. Current examples are nonempty; the stable trace and budget-respecting stable action show that generativity does not require change in every act. This is an adopted policy predicate, not proof all systems possess it. + +### T03 — accepted-bounded + +Permission to change does not entail valuing expansion; valuing/open forms do not entail achieved progress, actual capability, independence, autonomous execution or self-improvement; output/term/abstraction counts or self-claims alone do not establish achievement. + +The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions. + +### T04 — accepted-bounded + +All simultaneously held principles/judgments and their joint implications must avoid opposite conclusions on same question, assumptions, term meanings and scope; incompatible same-condition demands need revision/qualification; recorded change cannot be concealed. + +Consistent quantifies over joint semantic consequences of the whole held theory under one Context. Snapshot change reporting is a separate one-way Boolean obligation. The code preserves same-question/assumptions/meaning/scope and time-slice distinctions; it does not model every way a prose report could conceal change. + +### T05 — accepted-bounded + +Given faithful context identity and whole-set consequence, an opposite pair under the same context violates consistency; removing a prior judgment may eliminate the conflict without requiring permanent historical compatibility. + +consistencyConsequences directly applies the consistency prohibition to supplied positive and negative consequences. The revisionSlice examples provide distinct satisfiable times and inconsistent union; context examples preserve an admissible witness for each context. The theorem neither proves premises nor mandates permanent historical compatibility. + +### T06 — accepted-bounded + +Different-condition disagreement and value tension alone do not entail contradiction; consistency does not entail true assumptions, adequacy or support for a compatible conclusion. + +Concrete contexts, overlapping inequalities, a consistent theory false at the selected outside world, and empty-theory countervaluations distinguish contradiction, truth, sufficiency and entailment. These support the source limits without relying on a free false support flag. + +### T07 — accepted-bounded + +Generation and assessment apply to system and principle formation/application/revision under their actual applicability conditions; self-status is no exemption; applicability is not universalized; Grounds grounds/limits and own capability claims are included. + +The general interface/cases are reused; its engineering realization was rereviewed because selfModel now includes actual generation/evaluation rule objects and applicability. This strengthens rather than universalizes the source conditions. + +### T08 — accepted-bounded + +Self-application or self-produced revision does not establish correctness or sufficient grounds; openness of forms does not by itself meet reflexivity. In the declared representation, one nonempty common context satisfies the complete represented Charter requirements but fails the represented general Grounds requirement for a concrete identified claim. This bounded example shows that chapter placement supplies no deductive support; it does not assert independence in every possible representation. + +A revisable principle applied only to target 1 fails required self-target 0; self tests fail elsewhere; owned revisions retain unsupported global claims. CompleteCharter012 is inhabited yet costAllowanceRecord admits an incorrect-output world, so the concrete corresponding Grounds012 claim fails. This is a bounded charter-versus-support model, not philosophical independence in all interpretations. + +### T09 — accepted-bounded + +Grounds requires articulable concepts/assumptions/reasons/limits, assessment appropriate to claim nature, and strength/scope proportionate to supplied support. Articulation and assessment are distinct responsibilities. + +Grounds012 formalizes successful supported grounds for one declared task using same claim/articulation/discharge and task-appropriateness. Local/global and stronger-claim countermodels preserve force and scope. It is not a complete classifier or universal procedure for deciding all possible mixed claims. Calling it the obligation to examine rather than the successful support condition would overstate the correspondence. No Core 0.1.3 all-facet obligation is introduced. + +### T10 — accepted-bounded + +Empirical assessment examines observations, evidence and performance and their support conditions, scope and uncertainty; measurability/repeatability is no replacement for relevance, correctness or value assessment. + +Empirical discharge includes an in-scope compatible witness, scoped support and uncertainty support. Repetition of irrelevant first-coordinate/action observations cannot establish the second coordinate or budget value. The successful uncertainty is the exhaustive Boolean disjunction, not a quantified confidence estimate or a production measurement. + +### T11 — accepted-bounded + +Inferential assessment examines whether conclusion follows/supports under stated assumptions and inferential relations; mere nonconflict cannot replace this examination. + +The inferential wrapper requires satisfiable assumptions and actual entailment. Correct rejection of an unentailed conclusion is represented separately by InferenceExamined false and a countervaluation. Together they preserve the examination/success distinction, provided the wrapper alone is not described as the full act of assessment. + +### T12 — accepted-bounded + +Value commitments identify position, reasons, applicability limits and consequences and stay open to relevant criticism; neither empirical/necessary-inference presentation nor self-assertion substitutes. Initial commitments need not prove all starting assumptions. + +The value construction identifies position, joint reasons, application limits, consequences and relevant criticism responses. It assumes starting claims and supplies a joint witness instead of proving every starting assumption. The universal consequence test and response nonemptiness are this application's sufficient procedure, not newly mandatory philosophical proof requirements or proof of response adequacy. + +### T13 — accepted-bounded + +Articulability alone does not establish grounds; measurable/repeatable observations alone establish neither relevance, correctness nor value; a stated value commitment need not be empirical fact or necessary consequence, nor prove all its starting assumptions. + +Clearly articulated false assumptions, repeated wrong-object observations, neutral records compatible with nonadoption, and the ordinary value example show the intended non-substitutions. Qualitative implication orders claim strength without imposing a numerical scale. + +### T14 — accepted-bounded + +Performance/comparison judgments state relevant relations, conditions and observation scope; scope omission cannot establish absence of relevant differences; roles of measurement, repetition and framework are explained relative to claim/context. + +The local scope account binds comparison pairs, conditions, observed scope, relevance and each method explanation to the same claim. Its concrete method meanings prove local/repeated support and failure of global support. The generic explains relation remains supplied and the interface does not force every method to be used. + +### T15 — accepted-bounded + +Local equal performance does not entail global equivalence/unconditional universality; omitting a difference does not establish its nonexistence. Limited unreproduced support and variable random outcomes are possible without a universal measurement→repeatability→framework chain. + +Explicit functions agree only at zero and differ at one; one observation supplies local support. Trial fields separate recorded accuracy, equal settings and bounded output, and Boolean draws have equal positive weights with different outcomes. This is a finite possible-outcome model, not verification of a real stochastic process. + +### T16 — accepted-bounded + +Capability claim identifies capability, conditions and support under Grounds; applications choose relevant capability definitions and may require understanding/explanation/variation. External assessors may provide grounds; own-system claims receive same relevant duties. + +Resolved for the explicitly declared application capability UnderstandingApplication012: the same explained doubling process must also answer all multiplier/input variations using the actual multiplication mechanism. Identical output and ExplanationContract no longer suffice: the fixed-double answer gives 2 instead of 3 at multiplier=3,input=1, while mechanismResponder answers the declared variations and receives same-object Grounds. This is an operational understanding/variation-answer capability selected by the application, not a cognitive definition or universal standard of understanding. + +### T17 — accepted-bounded + +Reliable output or artifact/document/tool/term count alone does not establish internal-process understanding or stronger capability; articulable external grounds do not imply that assessed system understands/explains generation. + +Reliable double output with explanation = none refutes the stronger declared explanation contract; repeated item counts do not add an unavailable operation. This establishes limits on the represented output/explanation capability, not a cognitive account of human or agent understanding. + +### T18 — accepted-bounded + +Implementation priority needs reasons connected to objectives, values and relevant constraints; name/convention/status alone insufficient. Internal method explanation, applicability limits, simplicity/process requirements may count; conventional options may win on relevant grounds, including this philosophy's existing form. + +JustifiedChoice combines feasibility with a valued method-content reason; status-only reasons fail by definition as the additional adopted evaluative commitment. Conventional identity remains eligible, internal explanation/applicability/simplicity/procedure reasons are admissible, and the current philosophy review is assessed by actual output reasons. No optimality or all-reasons-valid theorem is claimed. + +### T19 — accepted-bounded + +Openness neither makes alternatives equivalent nor ensures multiple feasible implementations, excludes conventional choices or excludes internal-method reasons. Local performance equality does not settle whole choice. The added choice priority rule is not inferred from the represented general requirement to assess reasons; this inherited limited assessment relation is distinct from the stronger domain nonentailment in T39. + +A single feasible conventional choice, unequal outputs, equal local but different global behavior, and a distinguishing internal explanation meet the requested cases. The additional-choice example distinguishes accurate general assessment of non-entailment from the separate priority norm; this is deliberately the limited general-assessment relation in the target, not all Grounds duties. + +### T20 — accepted-bounded + +Under jointly satisfied inherited commitments and actual applicability, own principles/assessment methods/grounds/capability judgments inherit their corresponding generation, consistency and support duties without self-proof or removal of conditions. + +Resolved. The theorem now explicitly concludes the full normative-content membership, grounds for every held claim, and consistencySpecification for the same expanded ownTheory. It remains a legitimate projection of Inherited, not mutual logical derivation from fewer premises. Actual self-rule generation/assessment objects are included and checked; original empirical/inferential/value tasks remain separate. + +### T21 — accepted-documentary-boundary + +Existing form includes organization/methods/principles. Assessment is examination of reasons, applicability and observed performance and is not limited to executable testing. + +FormKind explicitly includes organization, method and principle. Empirical and semantic-inferential facets and noncomputable proposition decisions prevent restricting assessment to executable tests. The finite formal vocabulary is illustrative rather than an exhaustive philosophical ontology. + +### T22 — accepted-bounded + +Domain subject is continuing engineering activity by current/successor human or agent maintainers with software/tools/knowledge across credible lifecycle; priority applicability reflects actual lifecycle/maintenance expectations, not labels or artifact intrinsic orientation. + +ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established. + +### T23 — accepted-bounded + +Original-author editability does not establish continuing-maintainer evolution capability; calling a continuing system temporary does not establish genuinely bounded lifecycle; adopted human/agent orientation does not entail every artifact has it. + +The original maintainer has privateLayout while the successor lacks it; explicit path prerequisite failure establishes the contrast. The continuing activity remains nonbounded despite its temporary label. The passive artifact returns inputs and has no propose action by its actual definition, providing one counterexample rather than a law of all artifacts. + +### T24 — accepted-bounded + +When credible lifecycle/maintenance scope and relevant behavioral, safety, performance and other necessary requirements hold, favor continuing-maintainer credible future change capability including design revision over present abstraction simplicity; accept purpose-linked added complexity; allow yielding only when added costs threaten concrete objectives, with objective/cost account. + +EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates. + +### T25 — accepted-bounded + +For a context meeting all priority conditions, with a credible evolution advantage over a simpler feasible option and no concrete cost threat, domain satisfaction requires the evolution-favoring choice/priority and acceptance of its relevant additional complexity. + +The theorem explicitly assumes the adopted EvolutionPriority rule, applicability and no departure; it extracts the chosen evolvable value and substitutes into the supplied complexity comparison. This matches the target's normative-premise requirement. Concrete choices show simple violates the rule without a threat and can pass with the accounted threat. + +### T26 — accepted-bounded + +Credible change direction has articulable grounds (examples are plan/domain knowledge/history, not an exhaustive required list), remains revisable, and needs no existing multiple implementations. Conceivability alone cannot justify present accommodation. + +The generic Ground interface does not restrict ground categories. Concrete plans identify a positive release and direction; knowledge/history cases contain a service/mechanism or repeated direction list, and forecast revision changes supported directions. The adapter only checks designated strings/list content, so actual relevance of a mechanism/history is a stipulated interpretation. It must not be reported as independent validation of arbitrary knowledge records. + +### T27 — accepted-bounded + +Conceivable change alone does not entail warranted accommodation; credible change does not entail multiple existing implementations, maximal extensibility, retention of every possibility or universal numerical exchange rate. + +One implemented variant coexists with credible direction; unsupported imagined changes do not warrant the defined investment; evolvable supports nine registered directions while maximal supports ten but is not the priority. Different per-burden bounds and work comparisons demonstrate a selective example, not a mathematical impossibility of numerical tradeoffs. + +### T28 — accepted-bounded + +Cost/departure account admits understanding, construction, diagnosis, verification, coordination, operation and eventual migration burdens and identifies threatened objective and causal significance of added cost. + +Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions. + +### T29 — accepted-bounded + +Evolution includes capability addition, implementation replacement, mechanism deletion, abstraction withdrawal, boundary redrawing and technology/model migration; claims identify relevant changes and maintainer conditions; independent/coordinated changes and preserved/revised obligations may require different structures. + +Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter. + +### T30 — accepted-bounded + +Cheap/effective additions within fixed scheme do not entail equal ability to revise/leave it; advantage on one dimension does not entail every dimension; no duty to make every change inexpensive. + +Addition can cost two while withdrawal/revision costs seventeen; coordinated work exceeds independent work; migration can remain expensive while evolution priority holds. Equal addition cost directly refutes universal strict improvement over all Change values. + +### T31 — accepted-bounded + +Structural choice applies to whole relevant engineering consequences: component relations, observable contracts, understanding and verification work; boundary capability needs support for intended changes; propagation/cross-boundary knowledge and obligations/fixed assumptions/withdrawal are possible comparison inquiries. + +Resolved as a finite intended-change case. actualCrossBoundaryObligation links the registered edge caller 2/callee 1 to a real callee compiler edit, a caller contractRunner/publicContract step and finite observed order preservation. Removing the caller check leaves the crossing true but rejects the obligation; changing the callee to 7 loses the crossing; replacing output with sortedUnique fails the contract. No network/runtime semantics or universal completeness of every edge is claimed. + +### T32 — accepted-bounded + +Interface shape, module/extension-point count, named principle or boundary introduction alone cannot establish claimed evolution capability or easier intended change. + +The frozen delta now supplies the exact new_boundary_same_work case missing from the initial code: an actual added boundary and changed path with identical units/work and remaining successor prerequisite failure. The original increased-work example is retained. These and the signature/module/named-pattern examples meet the finite negative target, without proving real-world overhead or boundary execution semantics. + +### T33 — accepted-bounded + +Distinguish preserving an identified observable contract from deliberately revising it; deliberate revision accounts for changed obligations and affected parties; no requirement to preserve every historical behavior or use particular tests/migration procedure. + +ContractChangeAccount separates finite scoped equality from deliberate revision with changed order/retry obligations and affected-party coverage. Missing operator/incorrect old limits fail; [99] demonstrates an intentionally out-of-scope historical difference; changing procedure text remains allowed. Actual notification, completeness of parties and all-input equivalence are not modeled. + +### T34 — accepted-bounded + +Given equality of all identified contract observations in scope, a transformation preserves that identified contract; deliberate changed in-scope observations cannot be claimed preservation of that same contract and require revised-obligation/party account under domain satisfaction. + +contractPreservation returns the supplied universal in-scope equality proof, rather than deriving it from finite tests. changedObservationNotPreserved gives the counterexample implication; contractRevisionObligations eliminates the failed preservation branch of the assumed account. Finite order/retry cases illustrate the distinction. This is the correct conditional reading of the target, not an empirical proof from test success. + +### T35 — accepted-bounded + +Changed evidence about expected changes, maintenance conditions, costs/objectives can justify revised design/priority application; revised judgment acknowledges material grounds changes and cannot retroactively relabel failed prediction success. Retention may be justified by alternatives lacking contribution or defeating objectives. + +The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign. + +### T36 — accepted-bounded + +Revised judgment cannot make past failed prediction true; continued change, agreement and successful examples do not establish universal correctness; justified retention is compatible with domain/reflexive revision openness. + +Prior finite no-retroactive-success/consensus/success examples are retained. A fresh same-object probe proves revisionFor sharedContext evolvable retains the old/current design choice while selfModel evolvable satisfies reflection; this makes the open-stable example explicit without turning all stability into a duty. + +### T37 — accepted-bounded + +With inherited and domain satisfaction in a shared applicable context, the priority and evolution-assessment methods remain objects of grounds, consistency and reflexive criticism/revision; domain success cannot exempt its rule. + +Resolved in the same fixed shared context. priorityValueMeaning proves candidate-by-candidate equivalence between the adopted evolvable selection commitment and actual EvolutionPriority; priorityGrounds transports value support through that explicit equality while preserving the value task. The theorem now returns that exact priority claim's Grounds, domain-content membership and complete-theory consistency, in addition to reflection. The equivalence depends on current applicability/no-departure and must not be generalized to other contexts. + +### T38 — accepted-bounded + +USER ADDITIONAL STRONG OBJECTIVE: one content-bearing nonempty system/context jointly satisfies every represented inherited and domain commitment, with a continuing lifecycle, actual applicable priority and evolution chosen despite additional present abstraction complexity. + +Accepted as the requested bounded inhabitation witness after rechecking expanded Inherited and ownTheory, not merely its unchanged exterior theorem statement. The same evolvable candidate/context satisfies original necessary requirements, applicable priority/no threat, actual maintainer paths, full held fact/norm content, original support tasks and actual self-rule reflection. Source interpretation remains a revisable finite model; no empirical or philosophical universal correctness follows. + +### T39 — accepted-bounded + +USER ADDITIONAL STRONG OBJECTIVE: a countermodel satisfies all represented inherited commitments while genuine domain-priority applicability holds and domain evolution priority is not adopted; proves non-entailment in the disclosed representation. + +Accepted as the requested bounded non-entailment witness with every original strong branch preserved. The same continuing shared context has real encoded applicability/advantage and no lifecycle/cost escape; presentSimple adopts a separately grounded simplicity value and satisfies expanded inherited duties yet fails the extra priority. normApplies records adoption of the additional domain norm, not disappearance of its actual PriorityConditions. This distinction is central to the source's additional-value claim. + +### T40 — accepted-documentary-boundary + +Formal specification/conditional proofs and finite witnesses do not establish empirical adequacy of lifecycle forecasts, support relevance, future maintainability, value superiority or universal philosophical correctness; representation choices remain disclosed and revisable. + +Maintain source authority and separate normative specification, conditional theorem, finite witness, actual measurement, interpretation and adoption. No unseen final reader edition was assessed in this initial comparison. Disclosed abstraction does not automatically discharge a required semantic case or permit relabeling a difficult target as a boundary. + +## All 175 semantic cases + +Each case below was kept with its frozen name and scope. Evidence is an actual checked declaration, not the old author map. Repeated aggregate declarations are separate semantic comparisons, not extra independent proofs. + +| Target / required case | Actual checked evidence | Status | +| --- | --- | --- | +| T02 / `positive_valued_open_forms` | `CoreReader.Adopted.generationCases` (CoreReader/Adopted.lean:862) | accepted-bounded | +| T02 / `negative_permission_only` | `CoreReader.Agency.permissionNotValuation` (CoreReader/Agency.lean:37) | accepted-bounded | +| T02 / `positive_stability` | `CoreReader.Agency.generationLimits` (CoreReader/Agency.lean:194) | accepted-bounded | +| T02 / `external_collaboration` | `CoreReader.Adopted.collaborativeProgress` (CoreReader/Adopted.lean:223) | accepted-bounded | +| T03 / `permission_without_value` | `CoreReader.Agency.permissionNotValuation` (CoreReader/Agency.lean:37) | accepted-bounded | +| T03 / `orientation_without_progress` | `CoreReader.Agency.revisionWithoutProgress` (CoreReader/Agency.lean:99) | accepted-bounded | +| T03 / `count_growth_without_capability` | `CoreReader.Agency.generationLimits` (CoreReader/Agency.lean:194) | accepted-bounded | +| T03 / `collaborative_nonautonomous_progress` | `CoreReader.Adopted.collaborativeProgress` (CoreReader/Adopted.lean:223) | accepted-bounded | +| T03 / `claim_without_achievement` | `CoreReader.Agency.inflatedAnnouncementRefuted` (CoreReader/Agency.lean:171) | accepted-bounded | +| T03 / `achievement_support_for_same_claim` | `CoreReader.Adopted.achievementSupported012` (CoreReader/Adopted.lean:620) | accepted-bounded | +| T04 / `joint_only_contradiction` | `CoreReader.Adopted.jointImplicationConflict012` (CoreReader/Adopted.lean:703) | accepted-bounded | +| T04 / `changed_scope_not_concealed` | `CoreReader.Logic.hiddenContextChangeRejected` (CoreReader/Logic.lean:134) | accepted-bounded | +| T04 / `revision_withdraws_old` | `CoreReader.Logic.revisionCanReverse` (CoreReader/Logic.lean:68) | accepted-bounded | +| T04 / `incompatible_same_context` | `CoreReader.Adopted.consistencyConsequences` (CoreReader/Adopted.lean:241) | accepted-bounded | +| T05 / `pair_conflict` | `CoreReader.Adopted.consistencyConsequences` (CoreReader/Adopted.lean:241) | accepted-bounded | +| T05 / `joint_premise_conflict` | `CoreReader.Adopted.jointImplicationConflict012` (CoreReader/Adopted.lean:703) | accepted-bounded | +| T05 / `old_new_separate_times` | `CoreReader.Adopted.sliceConsistency` (CoreReader/Adopted.lean:247) | accepted-bounded | +| T05 / `distinct_context_judgments` | `CoreReader.Logic.contextDifferences` (CoreReader/Logic.lean:88) | accepted-bounded | +| T05 / `truthful_semantic_change_and_reordering` | `CoreReader.Logic.hiddenContextChangeRejected` (CoreReader/Logic.lean:134); `CoreReader.Adopted.semanticOrder012` (CoreReader/Adopted.lean:630) | accepted-bounded | +| T06 / `different_contexts` | `CoreReader.Logic.contextDifferences` (CoreReader/Logic.lean:88) | accepted-bounded | +| T06 / `tension_compatible` | `CoreReader.Adopted.tensionConsistent012` (CoreReader/Adopted.lean:718) | accepted-bounded | +| T06 / `consistent_false_assumption` | `CoreReader.Adopted.explicitlyConsistentLimits` (CoreReader/Adopted.lean:262) | accepted-bounded | +| T06 / `consistent_omitted_question` | `CoreReader.Adopted.explicitlyConsistentLimits` (CoreReader/Adopted.lean:262) | accepted-bounded | +| T06 / `compatible_not_entailed` | `CoreReader.Logic.compatibilityNotEntailment` (CoreReader/Logic.lean:180) | accepted-bounded | +| T07 / `self_applicable` | `CoreReader.Adopted.reflexiveTargets012` (CoreReader/Adopted.lean:605) | accepted-bounded | +| T07 / `self_inapplicable` | `CoreReader.Agency.applicabilityRetained` (CoreReader/Reflexivity.lean:396) | accepted-bounded | +| T07 / `principle_formation` | `CoreReader.Agency.completeOwnWork_reflexive` (CoreReader/Reflexivity.lean:358) | accepted-bounded | +| T07 / `principle_application` | `CoreReader.Adopted.reflexiveTargets012` (CoreReader/Adopted.lean:605) | accepted-bounded | +| T07 / `principle_revision` | `CoreReader.Adopted.reflexiveTargets012` (CoreReader/Adopted.lean:605) | accepted-bounded | +| T07 / `grounds_on_grounds` | `CoreReader.Adopted.groundsOnGrounds012` (CoreReader/Adopted.lean:595) | accepted-bounded | +| T08 / `self_assessed_incorrect` | `CoreReader.Agency.selfTestDoesNotProve` (CoreReader/Agency.lean:239) | accepted-bounded | +| T08 / `self_generated_unsupported` | `CoreReader.Evidence.selfOriginDoesNotSupport` (CoreReader/Evidence.lean:541) | accepted-bounded | +| T08 / `open_but_self_exempt` | `CoreReader.Adopted.openSelfExempt012` (CoreReader/Adopted.lean:680) | accepted-bounded | +| T08 / `charter_not_general_grounds` | `CoreReader.Adopted.charterWithoutGrounds012` (CoreReader/Adopted.lean:499) | accepted-bounded | +| T09 / `articulable_supported` | `CoreReader.Adopted.scopeStrength012` (CoreReader/Adopted.lean:286) | accepted-bounded | +| T09 / `articulable_unsupported` | `CoreReader.Evidence.articulationNotSupport` (CoreReader/Evidence.lean:325) | accepted-bounded | +| T09 / `scope_overreach` | `CoreReader.Adopted.scopeStrength012` (CoreReader/Adopted.lean:286) | accepted-bounded | +| T09 / `strength_overreach` | `CoreReader.Adopted.scopeStrength012` (CoreReader/Adopted.lean:286) | accepted-bounded | +| T10 / `observed_relevant` | `CoreReader.Adopted.localFacetChecked012` (CoreReader/Adopted.lean:282) | accepted-bounded | +| T10 / `repeatable_irrelevant` | `CoreReader.Evidence.measurementRepeatNotSupport` (CoreReader/Evidence.lean:394) | accepted-bounded | +| T10 / `measured_wrong_scope` | `CoreReader.Adopted.scopeStrength012` (CoreReader/Adopted.lean:286) | accepted-bounded | +| T10 / `uncertain_limited` | `CoreReader.Adopted.uncertainSupported012` (CoreReader/Adopted.lean:308) | accepted-bounded | +| T11 / `valid_inference` | `CoreReader.Adopted.inferenceChecked012` (CoreReader/Adopted.lean:323) | accepted-bounded | +| T11 / `compatible_unentailed` | `CoreReader.Logic.compatibilityNotEntailment` (CoreReader/Logic.lean:180) | accepted-bounded | +| T11 / `false_inference_detected` | `CoreReader.Adopted.inferenceChecked012` (CoreReader/Adopted.lean:323) | accepted-bounded | +| T12 / `reasoned_value` | `CoreReader.Adopted.valueFulfilled012` (CoreReader/Adopted.lean:341) | accepted-bounded | +| T12 / `unsupported_self_assertion` | `CoreReader.Evidence.announcementNotBudgetReason` (CoreReader/Evidence.lean:372) | accepted-bounded | +| T12 / `closed_criticism` | `CoreReader.Adopted.closedCriticism012` (CoreReader/Adopted.lean:336) | accepted-bounded | +| T12 / `explicit_initial_commitment` | `CoreReader.Evidence.valueWithoutSelfProof` (CoreReader/Evidence.lean:426) | accepted-bounded | +| T13 / `clear_false_reason` | `CoreReader.Adopted.clearFalseReason012` (CoreReader/Adopted.lean:637) | accepted-bounded | +| T13 / `repeatable_wrong_object` | `CoreReader.Evidence.measurementRepeatNotSupport` (CoreReader/Evidence.lean:394) | accepted-bounded | +| T13 / `value_not_fact` | `CoreReader.Adopted.valueNotFact012` (CoreReader/Adopted.lean:643) | accepted-bounded | +| T13 / `initial_value_without_selfproof` | `CoreReader.Evidence.valueWithoutSelfProof` (CoreReader/Evidence.lean:426) | accepted-bounded | +| T13 / `qualitative_proportionality` | `CoreReader.Adopted.qualitativeProportionality012` (CoreReader/Adopted.lean:348) | accepted-bounded | +| T14 / `local_scope_declared` | `CoreReader.Adopted.scopeFulfilled012` (CoreReader/Adopted.lean:379) | accepted-bounded | +| T14 / `omitted_relevant_difference` | `CoreReader.Evidence.hiddenDifference` (CoreReader/Evidence.lean:560) | accepted-bounded | +| T14 / `measurement_role` | `CoreReader.Adopted.scopeFulfilled012` (CoreReader/Adopted.lean:379) | accepted-bounded | +| T14 / `repetition_role` | `CoreReader.Adopted.scopeFulfilled012` (CoreReader/Adopted.lean:379) | accepted-bounded | +| T14 / `framework_role` | `CoreReader.Adopted.scopeFulfilled012` (CoreReader/Adopted.lean:379) | accepted-bounded | +| T15 / `equal_local_different_global` | `CoreReader.Evidence.localNotUniversal` (CoreReader/Evidence.lean:550) | accepted-bounded | +| T15 / `excluded_difference` | `CoreReader.Evidence.hiddenDifference` (CoreReader/Evidence.lean:560) | accepted-bounded | +| T15 / `one_observation_limited_support` | `CoreReader.Evidence.singleObservation` (CoreReader/Evidence.lean:566) | accepted-bounded | +| T15 / `varying_random_outcomes` | `CoreReader.Adopted.randomOutcomes012` (CoreReader/Adopted.lean:744) | accepted-bounded | +| T15 / `qualitative_unmeasured_judgment` | `CoreReader.Adopted.qualitativeUnmeasured012` (CoreReader/Adopted.lean:724) | accepted-bounded | +| T16 / `external_output_capability` | `CoreReader.Adopted.capabilityFulfilled012` (CoreReader/Adopted.lean:391) | accepted-bounded | +| T16 / `application_requires_understanding` | `CoreReader.Adopted.understandingApplicationCases012` (CoreReader/Adopted.lean:447) | accepted-bounded | +| T16 / `own_capability_assessment` | `CoreReader.Adopted.ownCapability012` (CoreReader/Adopted.lean:474) | accepted-bounded | +| T17 / `reliable_opaque_generator` | `CoreReader.Evidence.outputNotExplanation` (CoreReader/Evidence.lean:684) | accepted-bounded | +| T17 / `high_count_no_stronger_capability` | `CoreReader.Adopted.inventoryCases012` (CoreReader/Adopted.lean:667); `CoreReader.Agency.generationLimits` (CoreReader/Agency.lean:194) | accepted-bounded | +| T17 / `externally_articulated_no_introspection` | `CoreReader.Evidence.externalAssessment` (CoreReader/Evidence.lean:704) | accepted-bounded | +| T18 / `named_only_rejected` | `CoreReader.Adopted.allStatusOnly012` (CoreReader/Adopted.lean:733) | accepted-bounded | +| T18 / `conventional_grounded_priority` | `CoreReader.Choice.conventionWithReason` (CoreReader/Choice.lean:108) | accepted-bounded | +| T18 / `method_internal_reason` | `CoreReader.Choice.internalReasons` (CoreReader/Choice.lean:151); `CoreReader.Adopted.internalReasonDistinguishes012` (CoreReader/Adopted.lean:657) | accepted-bounded | +| T18 / `own_philosophy_status_only` | `CoreReader.Adopted.ownPhilosophyStatus012` (CoreReader/Adopted.lean:690) | accepted-bounded | +| T19 / `single_feasible_conventional` | `CoreReader.Choice.singleFeasible` (CoreReader/Choice.lean:121) | accepted-bounded | +| T19 / `internal_reason_distinguishes` | `CoreReader.Adopted.internalReasonDistinguishes012` (CoreReader/Adopted.lean:657) | accepted-bounded | +| T19 / `unequal_open_options` | `CoreReader.Choice.openNotEquivalent` (CoreReader/Choice.lean:162) | accepted-bounded | +| T19 / `local_equal_global_difference` | `CoreReader.Choice.localNotGlobal` (CoreReader/Choice.lean:132) | accepted-bounded | +| T19 / `added_choice_not_from_general_assessment` | `CoreReader.Choice.generalGroundsNotChoice` (CoreReader/Choice.lean:257) | accepted-bounded | +| T20 / `own_grounds_articulable` | `CoreReader.Engineering.inheritedMutualApplication` (CoreReader/Engineering/Integration.lean:420); `CoreReader.Engineering.governanceGrounded` (CoreReader/Engineering/Values.lean:137) | accepted-bounded | +| T20 / `own_capability_supported` | `CoreReader.Engineering.inheritedMutualApplication` (CoreReader/Engineering/Integration.lean:420); `CoreReader.Engineering.engineeringCapabilityGrounded` (CoreReader/Engineering/Integration.lean:63) | accepted-bounded | +| T20 / `own_choice_not_status_only` | `CoreReader.Engineering.inheritedMutualApplication` (CoreReader/Engineering/Integration.lean:420); `CoreReader.Engineering.implementationReasoned` (CoreReader/Engineering/Integration.lean:41) | accepted-bounded | +| T20 / `relevant_self_application` | `CoreReader.Engineering.inheritedMutualCases` (CoreReader/Engineering/Integration.lean:442); `CoreReader.Engineering.ownRuleContentVariation` (CoreReader/Engineering/SelfApplication.lean:204) | accepted-bounded | +| T22 / `successor_maintainer` | `CoreReader.Engineering.subjectLifecycleCases` (CoreReader/Engineering/Domain.lean:146) | accepted-bounded | +| T22 / `agent_maintainer` | `CoreReader.Engineering.subjectLifecycleCases` (CoreReader/Engineering/Domain.lean:146) | accepted-bounded | +| T22 / `continuing_labeled_temporary` | `CoreReader.Engineering.subjectLifecycleCases` (CoreReader/Engineering/Domain.lean:146) | accepted-bounded | +| T22 / `genuinely_temporary` | `CoreReader.Engineering.subjectLifecycleCases` (CoreReader/Engineering/Domain.lean:146) | accepted-bounded | +| T22 / `bounded_prototype` | `CoreReader.Engineering.subjectLifecycleCases` (CoreReader/Engineering/Domain.lean:146) | accepted-bounded | +| T22 / `retiring_system` | `CoreReader.Engineering.subjectLifecycleCases` (CoreReader/Engineering/Domain.lean:146) | accepted-bounded | +| T23 / `author_only_private_knowledge` | `CoreReader.Engineering.subjectLimits` (CoreReader/Engineering/Domain.lean:159) | accepted-bounded | +| T23 / `successor_missing_path` | `CoreReader.Engineering.subjectLimits` (CoreReader/Engineering/Domain.lean:159) | accepted-bounded | +| T23 / `false_temporary_label` | `CoreReader.Engineering.subjectLimits` (CoreReader/Engineering/Domain.lean:159) | accepted-bounded | +| T23 / `passive_artifact` | `CoreReader.Engineering.subjectLimits` (CoreReader/Engineering/Domain.lean:159) | accepted-bounded | +| T24 / `ordinary_priority` | `CoreReader.Engineering.priorityConditionsCases` (CoreReader/Engineering/Domain.lean:367) | accepted-bounded | +| T24 / `missing_behavior` | `CoreReader.Engineering.unmetRequirementsBlockPriority` (CoreReader/Engineering/Domain.lean:353) | accepted-bounded | +| T24 / `missing_safety` | `CoreReader.Engineering.unmetRequirementsBlockPriority` (CoreReader/Engineering/Domain.lean:353) | accepted-bounded | +| T24 / `missing_performance` | `CoreReader.Engineering.unmetRequirementsBlockPriority` (CoreReader/Engineering/Domain.lean:353) | accepted-bounded | +| T24 / `missing_other_necessary` | `CoreReader.Engineering.unmetRequirementsBlockPriority` (CoreReader/Engineering/Domain.lean:353) | accepted-bounded | +| T24 / `concrete_cost_override` | `CoreReader.Engineering.priorityConditionsCases` (CoreReader/Engineering/Domain.lean:367) | accepted-bounded | +| T24 / `unexplained_departure` | `CoreReader.Engineering.priorityConditionsCases` (CoreReader/Engineering/Domain.lean:367) | accepted-bounded | +| T24 / `no_extensibility_maximum` | `CoreReader.Engineering.credibilityLimits` (CoreReader/Engineering/Domain.lean:394) | accepted-bounded | +| T25 / `applicable_choose_evolution` | `CoreReader.Engineering.priorityWhenApplicable` (CoreReader/Engineering/Domain.lean:337); `CoreReader.Engineering.priorityChoices` (CoreReader/Engineering/Domain.lean:384) | accepted-bounded | +| T25 / `applicable_choose_simple_violates_domain` | `CoreReader.Engineering.currentSimpleViolates` (CoreReader/Engineering/Domain.lean:345) | accepted-bounded | +| T25 / `threat_allows_departure_with_account` | `CoreReader.Engineering.priorityChoices` (CoreReader/Engineering/Domain.lean:384) | accepted-bounded | +| T26 / `committed_plan_one_implementation` | `CoreReader.Engineering.credibilityCases` (CoreReader/Engineering/Domain.lean:212); `CoreReader.Engineering.credibilityLimits` (CoreReader/Engineering/Domain.lean:394) | accepted-bounded | +| T26 / `domain_knowledge` | `CoreReader.Engineering.credibilityCases` (CoreReader/Engineering/Domain.lean:212) | accepted-bounded | +| T26 / `applicable_history` | `CoreReader.Engineering.credibilityCases` (CoreReader/Engineering/Domain.lean:212) | accepted-bounded | +| T26 / `conceivable_only` | `CoreReader.Engineering.credibilityCases` (CoreReader/Engineering/Domain.lean:212) | accepted-bounded | +| T26 / `revised_forecast` | `CoreReader.Engineering.credibilityCases` (CoreReader/Engineering/Domain.lean:212) | accepted-bounded | +| T27 / `one_implementation_credible` | `CoreReader.Engineering.credibilityLimits` (CoreReader/Engineering/Domain.lean:394) | accepted-bounded | +| T27 / `imagined_unwarranted` | `CoreReader.Engineering.credibilityLimits` (CoreReader/Engineering/Domain.lean:394) | accepted-bounded | +| T27 / `selective_evolution` | `CoreReader.Engineering.credibilityLimits` (CoreReader/Engineering/Domain.lean:394) | accepted-bounded | +| T27 / `qualitative_tradeoff` | `CoreReader.Engineering.credibilityLimits` (CoreReader/Engineering/Domain.lean:394) | accepted-bounded | +| T28 / `understanding_threat` | `CoreReader.Engineering.costCases` (CoreReader/Engineering/Domain.lean:410) | accepted-bounded | +| T28 / `construction_threat` | `CoreReader.Engineering.costCases` (CoreReader/Engineering/Domain.lean:410) | accepted-bounded | +| T28 / `diagnosis_threat` | `CoreReader.Engineering.costCases` (CoreReader/Engineering/Domain.lean:410) | accepted-bounded | +| T28 / `verification_threat` | `CoreReader.Engineering.costCases` (CoreReader/Engineering/Domain.lean:410) | accepted-bounded | +| T28 / `coordination_threat` | `CoreReader.Engineering.costCases` (CoreReader/Engineering/Domain.lean:410) | accepted-bounded | +| T28 / `operation_threat` | `CoreReader.Engineering.costCases` (CoreReader/Engineering/Domain.lean:410) | accepted-bounded | +| T28 / `migration_threat` | `CoreReader.Engineering.costCases` (CoreReader/Engineering/Domain.lean:410) | accepted-bounded | +| T28 / `unsupported_cost_excuse` | `CoreReader.Engineering.costCases` (CoreReader/Engineering/Domain.lean:410) | accepted-bounded | +| T29 / `addition` | `CoreReader.Engineering.evolutionKindsCases` (CoreReader/Engineering/Domain.lean:569) | accepted-bounded | +| T29 / `replacement` | `CoreReader.Engineering.evolutionKindsCases` (CoreReader/Engineering/Domain.lean:569) | accepted-bounded | +| T29 / `deletion` | `CoreReader.Engineering.evolutionKindsCases` (CoreReader/Engineering/Domain.lean:569) | accepted-bounded | +| T29 / `withdrawal` | `CoreReader.Engineering.evolutionKindsCases` (CoreReader/Engineering/Domain.lean:569) | accepted-bounded | +| T29 / `redrawing` | `CoreReader.Engineering.evolutionKindsCases` (CoreReader/Engineering/Domain.lean:569) | accepted-bounded | +| T29 / `migration` | `CoreReader.Engineering.evolutionKindsCases` (CoreReader/Engineering/Domain.lean:569) | accepted-bounded | +| T29 / `independent` | `CoreReader.Engineering.evolutionKindsCases` (CoreReader/Engineering/Domain.lean:569) | accepted-bounded | +| T29 / `coordinated` | `CoreReader.Engineering.evolutionKindsCases` (CoreReader/Engineering/Domain.lean:569) | accepted-bounded | +| T29 / `preserve_obligation` | `CoreReader.Engineering.evolutionKindsCases` (CoreReader/Engineering/Domain.lean:569) | accepted-bounded | +| T29 / `revise_obligation` | `CoreReader.Engineering.evolutionKindsCases` (CoreReader/Engineering/Domain.lean:569) | accepted-bounded | +| T30 / `easy_add_hard_exit` | `CoreReader.Engineering.evolutionDimensionsLimits` (CoreReader/Engineering/Domain.lean:585) | accepted-bounded | +| T30 / `independent_easy_coordinated_hard` | `CoreReader.Engineering.evolutionDimensionsLimits` (CoreReader/Engineering/Domain.lean:585) | accepted-bounded | +| T30 / `some_change_expensive_permitted` | `CoreReader.Engineering.evolutionDimensionsLimits` (CoreReader/Engineering/Domain.lean:585) | accepted-bounded | +| T31 / `contract_and_work_comparison` | `CoreReader.Engineering.structuralCases` (CoreReader/Engineering/Domain.lean:733) | accepted-bounded | +| T31 / `propagation_relation` | `CoreReader.Engineering.structuralCases` (CoreReader/Engineering/Domain.lean:733) | accepted-bounded | +| T31 / `cross_boundary_obligation` | `CoreReader.Engineering.actualCrossBoundaryObligation` (CoreReader/Engineering/Domain.lean:720) | accepted-bounded | +| T31 / `fixed_assumption` | `CoreReader.Engineering.structuralCases` (CoreReader/Engineering/Domain.lean:733) | accepted-bounded | +| T31 / `withdrawal_cost` | `CoreReader.Engineering.structuralCases` (CoreReader/Engineering/Domain.lean:733) | accepted-bounded | +| T32 / `same_shape_broken_order` | `CoreReader.Engineering.structureNotCapability` (CoreReader/Engineering/Domain.lean:793) | accepted-bounded | +| T32 / `many_modules_shared_obligation` | `CoreReader.Engineering.structureNotCapability` (CoreReader/Engineering/Domain.lean:793) | accepted-bounded | +| T32 / `named_pattern_no_change_path` | `CoreReader.Engineering.structureNotCapability` (CoreReader/Engineering/Domain.lean:793) | accepted-bounded | +| T32 / `new_boundary_same_work` | `CoreReader.Engineering.structureNotCapability` (CoreReader/Engineering/Domain.lean:793) | accepted-bounded | +| T33 / `preserve_identified_contract` | `CoreReader.Engineering.contractCases` (CoreReader/Engineering/Domain.lean:843) | accepted-bounded | +| T33 / `deliberate_revision_with_account` | `CoreReader.Engineering.contractCases` (CoreReader/Engineering/Domain.lean:843) | accepted-bounded | +| T33 / `revision_missing_parties` | `CoreReader.Engineering.contractCases` (CoreReader/Engineering/Domain.lean:843) | accepted-bounded | +| T33 / `retired_historical_behavior` | `CoreReader.Engineering.contractCases` (CoreReader/Engineering/Domain.lean:843) | accepted-bounded | +| T33 / `alternative_procedure` | `CoreReader.Engineering.contractCases` (CoreReader/Engineering/Domain.lean:843) | accepted-bounded | +| T34 / `order_preserving_refactor` | `CoreReader.Engineering.contractPreservation` (CoreReader/Engineering/Domain.lean:822); `CoreReader.Engineering.contractDistinctions` (CoreReader/Engineering/Domain.lean:853) | accepted-bounded | +| T34 / `sorted_order_revision` | `CoreReader.Engineering.changedObservationNotPreserved` (CoreReader/Engineering/Domain.lean:826); `CoreReader.Engineering.contractDistinctions` (CoreReader/Engineering/Domain.lean:853) | accepted-bounded | +| T34 / `changed_failure_obligation` | `CoreReader.Engineering.contractRevisionObligations` (CoreReader/Engineering/Domain.lean:832); `CoreReader.Engineering.contractDistinctions` (CoreReader/Engineering/Domain.lean:853) | accepted-bounded | +| T34 / `outside_scope_difference` | `CoreReader.Engineering.contractDistinctions` (CoreReader/Engineering/Domain.lean:853) | accepted-bounded | +| T35 / `revised_change_forecast` | `CoreReader.Engineering.revisionCases` (CoreReader/Engineering/Domain.lean:951) | accepted-bounded | +| T35 / `changed_maintainers` | `CoreReader.Engineering.revisionCases` (CoreReader/Engineering/Domain.lean:951) | accepted-bounded | +| T35 / `changed_cost` | `CoreReader.Engineering.revisionCases` (CoreReader/Engineering/Domain.lean:951) | accepted-bounded | +| T35 / `changed_objective` | `CoreReader.Engineering.revisionCases` (CoreReader/Engineering/Domain.lean:951) | accepted-bounded | +| T35 / `failed_prediction_preserved` | `CoreReader.Engineering.historicalTamperingRejected` (CoreReader/Engineering/Domain.lean:980); `CoreReader.Engineering.failedHistoryNotRewritten` (CoreReader/Engineering/Domain.lean:924) | accepted-bounded | +| T35 / `justified_retention` | `CoreReader.Engineering.revisionCases` (CoreReader/Engineering/Domain.lean:951) | accepted-bounded | +| T36 / `past_failure_not_rewritten` | `CoreReader.Engineering.historicalTamperingRejected` (CoreReader/Engineering/Domain.lean:980); `CoreReader.Engineering.failedHistoryNotRewritten` (CoreReader/Engineering/Domain.lean:924) | accepted-bounded | +| T36 / `agreement_with_bad_case` | `CoreReader.Engineering.revisionLimits` (CoreReader/Engineering/Domain.lean:993) | accepted-bounded | +| T36 / `local_success_global_failure` | `CoreReader.Engineering.revisionLimits` (CoreReader/Engineering/Domain.lean:993) | accepted-bounded | +| T36 / `open_stable_design` | `CoreReader.Engineering.revisionContextIdentity` (CoreReader/Engineering/Domain.lean:1020); `CoreReader.Engineering.currentSelfApplication` (CoreReader/Engineering/SelfApplication.lean:161) | accepted-bounded | +| T37 / `priority_self_assessment` | `CoreReader.Engineering.priorityRemainsReflexive` (CoreReader/Engineering/Integration.lean:467); `CoreReader.Engineering.priorityReflexiveCases` (CoreReader/Engineering/Integration.lean:493) | accepted-bounded | +| T37 / `method_self_criticism` | `CoreReader.Engineering.actualSelfCriticism` (CoreReader/Engineering/SelfApplication.lean:170); `CoreReader.Engineering.ownRuleContentVariation` (CoreReader/Engineering/SelfApplication.lean:204) | accepted-bounded | +| T37 / `no_selfproof_from_success` | `CoreReader.Engineering.priorityReflexiveCases` (CoreReader/Engineering/Integration.lean:493); `CoreReader.Engineering.proposedRuleRevision` (CoreReader/Engineering/SelfApplication.lean:218) | accepted-bounded | +| T38 / `joint_all_inherited_and_domain` | `CoreReader.Engineering.jointWitness` (CoreReader/Engineering/Integration.lean:557) | accepted-bounded | +| T38 / `same_context_identity` | `CoreReader.Engineering.jointWitness` (CoreReader/Engineering/Integration.lean:557) | accepted-bounded | +| T38 / `nonempty_claims_and_principles` | `CoreReader.Engineering.jointWitness` (CoreReader/Engineering/Integration.lean:557); `CoreReader.Engineering.allNormativeContentHeld` (CoreReader/Engineering/Integration.lean:293) | accepted-bounded | +| T38 / `active_evolution_priority` | `CoreReader.Engineering.jointWitness` (CoreReader/Engineering/Integration.lean:557) | accepted-bounded | +| T38 / `content_bearing_maintainer_change` | `CoreReader.Engineering.jointWitness` (CoreReader/Engineering/Integration.lean:557); `CoreReader.Engineering.actualCapabilityContrast` (CoreReader/Engineering/Integration.lean:67) | accepted-bounded | +| T39 / `all_inherited_applicable_domain_not_adopted` | `CoreReader.Engineering.inheritedDoesNotEntailPriority` (CoreReader/Engineering/Integration.lean:586) | accepted-bounded | +| T39 / `no_temporary_escape` | `CoreReader.Engineering.inheritedDoesNotEntailPriority` (CoreReader/Engineering/Integration.lean:586) | accepted-bounded | +| T39 / `no_cost_escape` | `CoreReader.Engineering.inheritedDoesNotEntailPriority` (CoreReader/Engineering/Integration.lean:586) | accepted-bounded | +| T39 / `genuine_priority_failure` | `CoreReader.Engineering.inheritedDoesNotEntailPriority` (CoreReader/Engineering/Integration.lean:586) | accepted-bounded | +| T39 / `inherited_grounds_for_other_value` | `CoreReader.Engineering.inheritedDoesNotEntailPriority` (CoreReader/Engineering/Integration.lean:586); `CoreReader.Engineering.selectionGrounded` (CoreReader/Engineering/Values.lean:219) | accepted-bounded | + +## All 47 source paragraphs + +Exact original text is preserved in the JSON and the initial comparison; each was previously verified against PHILOSOPHY.md. These rows report bounded correspondence, not a proof of the entire philosophical passage. + +| Source unit / paragraph | Current mapped target judgments | +| --- | --- | +| `organon.preamble` / p1 | T01, T40 — accepted within their stated scope | +| `organon.preamble` / p2 | T01, T40 — accepted within their stated scope | +| `organon.charter.overview` / p1 | T01 — accepted within their stated scope | +| `organon.charter.overview` / p2 | T01, T02, T38 — accepted within their stated scope | +| `organon.charter.overview` / p3 | T01, T02, T38 — accepted within their stated scope | +| `organon.charter.self-transcendence` / p1 | T02, T38 — accepted within their stated scope | +| `organon.charter.self-transcendence.orientation` / p1 | T02, T03, T38 — accepted within their stated scope | +| `organon.charter.self-transcendence.non-finality` / p1 | T02, T03, T38 — accepted within their stated scope | +| `organon.charter.self-transcendence.limits` / p1 | T03, T38 — accepted within their stated scope | +| `organon.charter.self-transcendence.limits` / p2 | T02, T03, T38, T40 — accepted within their stated scope | +| `organon.charter.consistency` / p1 | T04, T05, T38 — accepted within their stated scope | +| `organon.charter.consistency.meaning` / p1 | T04, T05, T38 — accepted within their stated scope | +| `organon.charter.consistency.meaning` / p2 | T04, T05, T06, T38 — accepted within their stated scope | +| `organon.charter.consistency.limits` / p1 | T04, T05, T06, T38 — accepted within their stated scope | +| `organon.charter.reflexivity` / p1 | T07, T38 — accepted within their stated scope | +| `organon.charter.reflexivity.meaning` / p1 | T07, T38 — accepted within their stated scope | +| `organon.charter.reflexivity.limits` / p1 | T07, T08, T38 — accepted within their stated scope | +| `organon.grounds` / p1 | T08, T09, T38, T40 — accepted within their stated scope | +| `organon.grounds.assessment` / p1 | T09, T13, T38, T40 — accepted within their stated scope | +| `organon.grounds.assessment` / p2 | T09, T10, T11, T12, T13, T38, T40 — accepted within their stated scope | +| `organon.grounds.assessment` / p3 | T09, T12, T13, T38, T40 — accepted within their stated scope | +| `organon.grounds.scope` / p1 | T14, T15, T38 — accepted within their stated scope | +| `organon.grounds.scope` / p2 | T14, T15, T38, T40 — accepted within their stated scope | +| `organon.grounds.scope` / p3 | T14, T15, T38, T40 — accepted within their stated scope | +| `organon.grounds.capabilities` / p1 | T16, T17, T38, T40 — accepted within their stated scope | +| `organon.grounds.capabilities` / p2 | T16, T17, T38, T40 — accepted within their stated scope | +| `organon.grounds.implementations` / p1 | T18, T19, T38, T40 — accepted within their stated scope | +| `organon.grounds.implementations` / p2 | T18, T19, T38, T40 — accepted within their stated scope | +| `organon.grounds.implementations.limits` / p1 | T15, T18, T19, T38 — accepted within their stated scope | +| `organon.relationships.roles` / p1 | T01, T08, T20, T38, T39, T40 — accepted within their stated scope | +| `organon.relationships.roles` / p2 | T03, T06, T11, T16, T20, T38, T39, T40 — accepted within their stated scope | +| `organon.relationships.roles` / p3 | T07, T08, T16, T18, T20, T37, T38, T39, T40 — accepted within their stated scope | +| `organon.relationships.terms` / p1 | T02, T21 — accepted within their stated scope | +| `extensions` / p1 | T01, T37, T38, T39, T40 — accepted within their stated scope | +| `software-engineering.purpose` / p1 | T22, T23, T38, T40 — accepted within their stated scope | +| `software-engineering.purpose` / p2 | T22, T23, T38, T40 — accepted within their stated scope | +| `software-engineering.purpose` / p3 | T22, T23, T24, T38, T40 — accepted within their stated scope | +| `software-engineering.evolution-priority` / p1 | T24, T25, T38, T39, T40 — accepted within their stated scope | +| `software-engineering.evolution-priority` / p2 | T24, T25, T26, T27, T38, T39, T40 — accepted within their stated scope | +| `software-engineering.evolution-priority` / p3 | T24, T25, T26, T27, T28, T38, T39, T40 — accepted within their stated scope | +| `software-engineering.evolution-meaning` / p1 | T29, T30, T38, T40 — accepted within their stated scope | +| `software-engineering.evolution-meaning` / p2 | T29, T30, T38, T40 — accepted within their stated scope | +| `software-engineering.structural-judgment` / p1 | T31, T32, T37, T38, T40 — accepted within their stated scope | +| `software-engineering.structural-judgment` / p2 | T31, T32, T38, T40 — accepted within their stated scope | +| `software-engineering.structural-judgment` / p3 | T33, T34, T38, T40 — accepted within their stated scope | +| `software-engineering.revision` / p1 | T35, T36, T38, T40 — accepted within their stated scope | +| `software-engineering.revision` / p2 | T35, T36, T37, T38, T40 — accepted within their stated scope | + +## Disposition of the 17 original blind concerns + +### C01 — retained disclosed boundary or previously resolved within concrete model + +Prior reason retained; no source obligation added. + +### C02 — retained disclosed boundary or previously resolved within concrete model + +Prior reason retained; no source obligation added. + +### C03 — retained disclosed boundary or previously resolved within concrete model + +Prior reason retained; no source obligation added. + +### C04 — retained disclosed boundary or previously resolved within concrete model + +Engineering output-function capability remains narrow; the new T16 variation-answer application is a separate stronger declared capability, not a retroactive stronger reading of engineeringCapability. + +### C05 — retained disclosed boundary or previously resolved within concrete model + +Prior reason retained; no source obligation added. + +### C06 — retained disclosed boundary or previously resolved within concrete model + +Prior reason retained; no source obligation added. + +### C07 — retained disclosed boundary or previously resolved within concrete model + +Prior reason retained; no source obligation added. + +### C08 — retained disclosed boundary or previously resolved within concrete model + +Prior reason retained; no source obligation added. + +### C09 — retained disclosed boundary or previously resolved within concrete model + +New generationRule and assessmentRule objects refer to actual generate/evaluate and keep actual applicability. They are not globally exempted; revised applicability is only a separate tested candidate. + +### C10 — retained disclosed boundary or previously resolved within concrete model + +Current evaluate still returns supported for empty tested lists; the new actual assessment-rule self-test deliberately records that local-contract failure. No hidden repair or universal sample requirement. + +### C11 — retained disclosed boundary or previously resolved within concrete model + +Prior reason retained; no source obligation added. + +### C12 — retained disclosed boundary or previously resolved within concrete model + +Prior reason retained; no source obligation added. + +### C13 — retained disclosed boundary or previously resolved within concrete model + +Prior reason retained; no source obligation added. + +### C14 — retained disclosed boundary or previously resolved within concrete model + +Prior reason retained; no source obligation added. + +### C15 — resolved-bounded + +T20 now includes the consistency result plus full content membership and whole-claim support, verified by direct conclusion extraction probe. Projection remains explicitly disclosed. + +### C16 — retained disclosed boundary or previously resolved within concrete model + +Prior reason retained; no source obligation added. + +### C17 — resolved-specific-links-generic-boundary-retained + +T31 has actual boundary-linked checks; T37 has explicit same-priority value/grounds equivalence. Generic explains/meaning/string interfaces still require an interpretation, so the abstract concern is retained as a limit. + +## Limits and unreviewed delivery stages + +- Normative adoption and value superiority are not mathematically compelled. +- All support/currentness judgments are bound to the frozen R3 code and selected Core 0.1.2 baseline. +- Operational mechanism-variation understanding is not unrestricted cognition or introspection. +- Empty-tested-list failure belongs to a declared sample-aware local evaluator contract, not all philosophical assessment. +- Finite boundary/contract/work/history cases do not establish production adequacy or universal costs. +- priorityValueMeaning is limited to the fixed applicable no-departure sharedContext. +- wholeClaimGrounded uses fixed-model identity for fulfillment facts; original empirical/inferential/value tasks remain separately retained. +- No final reader edition, bilingual synchronization, historical replay or later changed code is approved by this comparison. + +No remaining source-correspondence blocker was found for this exact R3 object and bounded target set. This acceptance is independent of the author response and the other reviewer's conclusion: the response identified changes to inspect, while actual definitions, types, proofs and probes supplied the grounds. Later edits require their own impact review and cannot inherit these hashes silently. diff --git a/SoftwareEngineering/lean/philosophy/reviews/code-review-identity.json b/SoftwareEngineering/lean/philosophy/reviews/code-review-identity.json new file mode 100644 index 0000000..ed15561 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/code-review-identity.json @@ -0,0 +1,48 @@ +{ + "stage": "source-comparison-r3-informed-three-way", + "frozen_utc": "2026-09-14T18:13:15.421620+00:00", + "scope": "40 targets / 47 source paragraphs / 175 semantic cases; accepted-bounded with stated limits", + "snapshot_input_drift": "none", + "artifacts": { + "source-comparison-r3.md": "ba3e905877e33ef96e4251cb59b8a1f52cca397eecaef92570ebf28261a8fd0c", + "source-comparison-r3.json": "e01cd00cbcfa4ba8c6592917ea7321eb3826bc0b365a2b1b64170a1a24a93825", + "r3-build.log": "f6e727662ac83e00e087be3246525187946b87441afdb6cd9a3f3af9d3e5eedd", + "r3-declarations.json": "b92ca5728f275caeec340cdc63aa52dc44a303c30a887cfcfa3493542e7e6b07", + "r3-audit-input.txt": "c31b98c29db2e12b2d7c2d7f968c0fa4db76a68061ea9bf14ce81727f376ea19", + "r3-actual-audit.log": "b9f95581347504e245f0cea7f98cbf2b818c242aaa26615b031421e2fab7729c", + "r3-axiom-summary.json": "f23b5f29c342bb30dd274c9d7fad6932565eecd69c91f27f846d017fe5a253c7", + "r3-probe-input.txt": "3c72af41c80077164e35a7ad2dcc8c927a0981c12f4c698702d658b543f8d8d5", + "r3-probes.log": "7c5d415119ea3e427dfc06acbf415cf5a0cfbf12ac7155d553a7a7ea4ababdd7", + "r3-stability-probe-input.txt": "677f560a47f9262bf08cf337f423516c163970906668bd2d541e9383c56531dd", + "r3-stability-probe.log": "9fa3b6ead7afc298499f30c5b70014c78b6686a8269611537606fa5a7c02b6a2", + "r3-input/Adopted-delta.diff": "9c1782097c1b3bdc9b6abbce719de9a8acee7e681046e7d1e5ff386d3750cd83", + "r3-input/Domain-delta.diff": "35580ffdd10d8a2c1d47e4fac067e2f167b4f0a7e282d6f9ac3e44b1c2846a21", + "r3-input/Integration-delta.diff": "0cefc4697921d3fcfe1447b939a96cc736cda90b18706433a30eb51b6d66e196", + "r3-input/Reflection-delta.diff": "aa544c7063cf31ac95b07b460898816c78ec4ca84fca6ffe083934fbc100bcca", + "r3-input/SelfApplication-delta.diff": "a363a0b54b09fd857cde9ea0604c92600c4788bad9d9ab2544dd5e0b0357b8aa", + "r3-input/f07-f08-author-response.md": "6850fe7b7693200544b4df76337a89ed7655871a523cccfc2a7faa59766f6da8", + "r3-input/source-code-review-f07-f08.json": "d7dcad383daf362011519d8c71b33bd6be78a2f17ea54f9d2d9f1d3be1b10641", + "r3-input/source-code-review-f07-f08.md": "898af33213a832832f4b6d84a8f94fd99bede9a0abae055b9e2a1af3b8ee5b1f", + "r3-input/source-code-review-full-initial.json": "3def05f99f44b763c9bf7b3475f6aad631969ec2387d10b802965967f5f45386", + "r3-input/source-code-review-full-initial.md": "d1c38be6f8826ff29ff01ec12bb2d45f3f32e4e4b45830c7fd3250a40ab13767", + "r3-input/third-check.json": "005a402882a0939970669ca1b9462bfbd3080d0c028dc566b4582d564bbcdefe", + "r3-input/third-code-hashes.json": "285a55c8d5db2dab583d104d87712521abeb706832a31b4d92002073fa5d2e49", + "r3-input/third-code-snapshot/CoreReader/Adopted.lean": "8de4d364bb3c64e29ab92e81d86cbe4c9e5af49ada3dad262d1378421fb588c2", + "r3-input/third-code-snapshot/CoreReader/Agency.lean": "2722c34645f4256f20ce31205738f2f5712ab5dd5cc6fcf9f1180d0be5aa0303", + "r3-input/third-code-snapshot/CoreReader/Choice.lean": "b28728df12ed7e73edb5569604cd2541c0ebd815ae3aaa0812e6557dece1d1ba", + "r3-input/third-code-snapshot/CoreReader/Engineering/Domain.lean": "ce5653a2950cc7443cefbfe8b9726bd4859228e831ddb7d42601e501ccbfd855", + "r3-input/third-code-snapshot/CoreReader/Engineering/Domain.olean": "c6ccc73e0d0e8e3da0d9bc078b3e9e3d916ec1ce99e0c9723cafaf39b5c27525", + "r3-input/third-code-snapshot/CoreReader/Engineering/Integration.lean": "a2b88062148b3f7ebea7da02d88cb29cb04d8f1b2e9e6b97bb2420ac2c006328", + "r3-input/third-code-snapshot/CoreReader/Engineering/Reflection.lean": "c290d8472884d00bedbf945f0fc1866524e758740f40d42088c4ff9678a93fa2", + "r3-input/third-code-snapshot/CoreReader/Engineering/SelfApplication.lean": "d69c0d369bd4fd8db4c21ce3b65abb5e9efd07ed5ab9a68d56b4db39bb9d2a21", + "r3-input/third-code-snapshot/CoreReader/Engineering/Values.lean": "ccd45bf23d2f47c41d1b2f9955d753e290687d951a0c55af41ab9a63b9a8d9cb", + "r3-input/third-code-snapshot/CoreReader/Evidence.lean": "d55f33e44902cef146841cbffb65710bd7c8a3bda79d01d084edc36f019fdc96", + "r3-input/third-code-snapshot/CoreReader/Integration.lean": "97e2939c0b6714b78a3ed78358e174619a5028ad5b0b5025c0d4422b4294921b", + "r3-input/third-code-snapshot/CoreReader/Logic.lean": "0ec342691766ebd83d251dcd0da3b0ae9840aed677a714bc1b01c45d89392bc0", + "r3-input/third-code-snapshot/CoreReader/Reflexivity.lean": "48e2c74e7cbae571db1b990b9f32dd0d701f6881a8b0111d907f8861287d76fa", + "r3-input/third-code-snapshot/CoreReader.lean": "c5574fae235419a7d6449b3ebb5d2da29d1e92a3b572c1b759438e3c470caaa9", + "r3-input/third-code-snapshot/lake-manifest.json": "bbc61a9c84a4f346e142fd849100a94729248bbcc8a736fa594318fc21b48345", + "r3-input/third-code-snapshot/lakefile.toml": "05d8ba36975f87aca61e3b0ddcacc42669539f316ba9b8eef5859961e2aa6fdc", + "r3-input/third-code-snapshot/lean-toolchain": "3aac669c7a910ec2389f4e4f921b605adf6ebf2d1e0c9b9cd0be4d33f3f5db71" + } +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/code-targets-final.json b/SoftwareEngineering/lean/philosophy/reviews/code-targets-final.json new file mode 100644 index 0000000..1b0bda1 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/code-targets-final.json @@ -0,0 +1,10078 @@ +{ + "stage": "source-comparison-r3-informed-three-way", + "reviewer": "/root/se_code_only_translation", + "created_utc": "2026-09-14T18:11:13.481202+00:00", + "baseline": { + "software_engineering": "0.2.0", + "core": "0.1.2", + "source_sha256": "6c6ae78a23f2726c5c370434e808d76c206647fe7793245e88cae52c076abe34" + }, + "code_snapshot": "r3-input/third-code-snapshot", + "code_hashes": { + "lean-toolchain": "3aac669c7a910ec2389f4e4f921b605adf6ebf2d1e0c9b9cd0be4d33f3f5db71", + "CoreReader.lean": "c5574fae235419a7d6449b3ebb5d2da29d1e92a3b572c1b759438e3c470caaa9", + "lake-manifest.json": "bbc61a9c84a4f346e142fd849100a94729248bbcc8a736fa594318fc21b48345", + "lakefile.toml": "05d8ba36975f87aca61e3b0ddcacc42669539f316ba9b8eef5859961e2aa6fdc", + "CoreReader/Choice.lean": "b28728df12ed7e73edb5569604cd2541c0ebd815ae3aaa0812e6557dece1d1ba", + "CoreReader/Logic.lean": "0ec342691766ebd83d251dcd0da3b0ae9840aed677a714bc1b01c45d89392bc0", + "CoreReader/Integration.lean": "97e2939c0b6714b78a3ed78358e174619a5028ad5b0b5025c0d4422b4294921b", + "CoreReader/Agency.lean": "2722c34645f4256f20ce31205738f2f5712ab5dd5cc6fcf9f1180d0be5aa0303", + "CoreReader/Reflexivity.lean": "48e2c74e7cbae571db1b990b9f32dd0d701f6881a8b0111d907f8861287d76fa", + "CoreReader/Evidence.lean": "d55f33e44902cef146841cbffb65710bd7c8a3bda79d01d084edc36f019fdc96", + "CoreReader/Adopted.lean": "8de4d364bb3c64e29ab92e81d86cbe4c9e5af49ada3dad262d1378421fb588c2", + "CoreReader/Engineering/Reflection.lean": "c290d8472884d00bedbf945f0fc1866524e758740f40d42088c4ff9678a93fa2", + "CoreReader/Engineering/Integration.lean": "a2b88062148b3f7ebea7da02d88cb29cb04d8f1b2e9e6b97bb2420ac2c006328", + "CoreReader/Engineering/Values.lean": "ccd45bf23d2f47c41d1b2f9955d753e290687d951a0c55af41ab9a63b9a8d9cb", + "CoreReader/Engineering/Domain.olean": "c6ccc73e0d0e8e3da0d9bc078b3e9e3d916ec1ce99e0c9723cafaf39b5c27525", + "CoreReader/Engineering/SelfApplication.lean": "d69c0d369bd4fd8db4c21ce3b65abb5e9efd07ed5ab9a68d56b4db39bb9d2a21", + "CoreReader/Engineering/Domain.lean": "ce5653a2950cc7443cefbfe8b9726bd4859228e831ddb7d42601e501ccbfd855" + }, + "original_records_preserved": [ + "initial-blind.md in original code-only project", + "delta-blind.md", + "source-comparison-initial.md/json and manifests" + ], + "other_records_first_read_at_this_stage": [ + "source-code-review-full-initial.md/json", + "source-code-review-f07-f08.md/json", + "f07-f08-author-response.md" + ], + "unused_evidence": [ + "all-semantic-cases-current.json was not used as final evidence or read to derive this mapping" + ], + "result": "accepted-bounded-for-all-frozen-targets-and-semantic-cases; final delivery/manuscripts/current-object binding not assessed here", + "counts": { + "targets": 40, + "source_clauses": 47, + "semantic_cases": 175, + "declared_registered_checks": 59, + "independent_all_declaration_checks": 831, + "theorems": 282 + }, + "formal_evidence": { + "build_log": "r3-build.log", + "all_declaration_audit": "r3-actual-audit.log", + "axiom_summary": "r3-axiom-summary.json", + "probes": "r3-probes.log", + "same_object_stability_probe": "r3-stability-probe.log", + "root_check": "r3-input/third-check.json", + "root_semantic_status": "not_evaluated", + "source_files_changed_by_reviewer": false, + "new_lean_source_files_written_by_reviewer": false, + "probe_delivery": "Lean --stdin; exact inputs retained as .txt; no production or snapshot .lean edited" + }, + "strong_outer_statements_preserved": { + "jointWitness": true, + "inheritedDoesNotEntailPriority": true + }, + "three_way_comparison": [ + { + "issue": "Own F01 / T16", + "own_initial": "partial: ExplanationContract alone does not establish the named understanding case", + "other_initial": "accepted-bounded via earlier review; different emphasis preserved", + "author_change": "New same-process multiplier-variation capability and positive/negative Grounds", + "r3": "resolved-bounded by actual (2,3) response contrast and all-variation positive theorem; do not upgrade to unrestricted cognition" + }, + { + "issue": "Own F02 / T20", + "own_initial": "partial actual conclusion omitted consistency", + "other_initial": "pending due F07/F08 whole content and self-rule concerns", + "author_change": "Full OwnNorm theory, actual consistency conclusion and actual self-rule objects", + "r3": "resolved-bounded; new consistency can be extracted from the full theorem, original support tasks retained" + }, + { + "issue": "Own F03 / T31", + "own_initial": "partial no real boundary relation in cross-obligation case", + "other_initial": "accepted-bounded via prior review; not silently treated as prior agreement", + "author_change": "Actual edge/callee-edit/caller-verification/order checks and three negative variants", + "r3": "resolved-bounded by independent evaluation; boundary text remains a label within the fixed contract family" + }, + { + "issue": "Own F04 / T37", + "own_initial": "partial: five Core value grounds were not same engineering-priority claim; consistency missing", + "other_initial": "priority test local accepted, overall pending F07/F08", + "author_change": "priorityValueMeaning, priorityGrounds, exact conclusion and held-domain membership", + "r3": "resolved-bounded for fixed sharedContext only; value task unchanged and explicit logical equivalence supplies same claim" + }, + { + "issue": "Other F07", + "own_initial": "not separately identified as a blocking full-content omission; currentOwnClaims limitation described", + "other_initial": "blocked whole normative-content theory linkage", + "author_change": "OwnNorm expansion, fact/norm union, actualOwnNorm, member bridge, full-theory consistency and variation case", + "r3": "agree with resolved-bounded after checking definitions and actual proof; contradiction example is a bounded logical variation, not a fidelity metatheorem" + }, + { + "issue": "Other F08", + "own_initial": "not separately identified as a blocking actual-self-rule-object omission; generic evaluate limit retained", + "other_initial": "blocked actual generation/assessment rules not represented as self objects", + "author_change": "Actual helpers/meaning/applicability linked to new review objects and finite probes", + "r3": "agree with resolved-bounded after actual function tests and self counterexample; no universal sample chain or self-proof follows" + }, + { + "issue": "T38/T39 composition", + "own_initial": "kernel witnesses accepted; source composition qualified/pending", + "other_initial": "strong branches accepted but full correspondence pending F07/F08", + "author_change": "Strong outer statements unchanged; stronger Inherited/ownTheory/selfModel actual dependencies", + "r3": "accepted-bounded after transitive rereview; no temporary/cost escape, no substitution of assessment for adoption" + } + ], + "targets": [ + { + "id": "T01", + "kind": "boundary", + "statement": "Authority and roles: adopted commitments, no universal factual assertion or correctness proof; meanings and limits constrain quotation; charter and Grounds mutually constrain without hierarchy; rationale/skills add no philosophical duties; domain preference is additional.", + "premises": [ + "Distinguish document role from deductive claims. No assumed metatheorem about all possible formalizations." + ], + "sources": [ + { + "unit": "organon.preamble", + "clause": "p1" + }, + { + "unit": "organon.preamble", + "clause": "p2" + }, + { + "unit": "organon.charter.overview", + "clause": "p1" + }, + { + "unit": "organon.charter.overview", + "clause": "p2" + }, + { + "unit": "organon.charter.overview", + "clause": "p3" + }, + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "extensions", + "clause": "p1" + } + ], + "status": "accepted-documentary-boundary", + "prior_own_status": "documentary_boundary", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "The source explicitly adopts commitments rather than claiming universal factual truth or deductive hierarchy. The chapter-4 preference is additional. No theorem is required for document authority, and the concrete countermodels must not be promoted into independence of every conceivable formalization.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [], + "semantic_cases": [] + }, + { + "id": "T02", + "kind": "specification", + "statement": "Self-transcendence requires valuing expansion of understanding and construction and keeping all existing organization, methods and principles open to being surpassed; justified stable acts remain permitted.", + "premises": [ + "System/activity subject", + "current forms quantified without omitting principles", + "orientation is normative commitment, not empirical universality." + ], + "sources": [ + { + "unit": "organon.charter.overview", + "clause": "p2" + }, + { + "unit": "organon.charter.overview", + "clause": "p3" + }, + { + "unit": "organon.charter.self-transcendence", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.orientation", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.non-finality", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p2" + }, + { + "unit": "organon.relationships.terms", + "clause": "p1" + } + ], + "status": "accepted-bounded", + "prior_own_status": "bounded_specification", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "Generative requires valuation of expansion and revisability of every current Form, including organization, method and principle. Current examples are nonempty; the stable trace and budget-respecting stable action show that generativity does not require change in every act. This is an adopted policy predicate, not proof all systems possess it.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Adopted.generationSpecification", + "file": "CoreReader/Adopted.lean", + "line": 80, + "end": 89, + "kind": "def", + "axioms": "[]", + "exact_code": "def generationSpecification (policy : Policy) : Prop := Generative policy\n\n/- All consequences use the whole currently held set. Historical reporting is\nseparate and does not require simultaneous compatibility with withdrawn claims. -/\n/-- organon-map CoreReader.Adopted.consistencySpecification\norganon.charter.consistency#p1 sha256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42\norganon.charter.consistency.meaning#p1 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75\n-/\n", + "full_type_record": { + "type": "Lean.Expr.forallE\n `policy\n (Lean.Expr.const `CoreReader.Agency.Policy [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default)", + "sha256": "4d07b8deec9112ff5d3e7fe744c159c254580260c78b82be6dd64347e8a9a4eb" + }, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Adopted.generationCases", + "file": "CoreReader/Adopted.lean", + "line": 862, + "end": 903, + "kind": "theorem", + "axioms": "[propext, Quot.sound.{u}]", + "exact_code": "theorem generationCases :\n (Generative openPolicy ∧\n (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧\n (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1)))) ∧\n (neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy) ∧\n (Generative generatingSystem.policy ∧\n generatingSystem.policy.permitsVersion 0 0 ∧\n ¬ Expanded generatingSystem.current inflatedState ∧\n generatingSystem.current.inventory.length < inflatedState.inventory.length ∧\n generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧\n generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧\n generatingSystem.execute availableResources = some 6 ∧\n generatingSystem.execute { availableResources with experience := none } = none ∧\n generatingSystem.execute { availableResources with knowledge := none } = none ∧\n generatingSystem.execute { availableResources with collaborator := none } = none ∧\n generatingSystem.execute ⟨none, none, none⟩ = none ∧\n ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧\n generatingSystem.stableAction = generatingSystem.current ∧\n generatingSystem.requirementsMet generatingSystem.stableAction ∧\n generatingSystem.withinBudget generatingSystem.stableAction ∧\n ¬ generatingSystem.withinBudget inflatedState ∧\n StableReason generatingSystem.current inflatedState ∧\n (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧\n inflatedAnnouncement.owner = generatingSystem.owner ∧\n inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧\n inflatedAnnouncement.reportedNewOperation = .successor ∧\n inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧\n ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after)) ∧\n (generationSpecification openPolicy ∧\n Expanded baseState (collaborativeRevision availableResources) ∧\n ¬ Expanded baseState (collaborativeRevision { availableResources with collaborator := none }) ∧\n assistedExecution ⟨none, none, none⟩ = none) :=\n ⟨revisionWithoutProgress, permissionNotValuation, generationLimits, collaborativeProgress⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.generationLimits012\norganon.charter.self-transcendence.orientation#p1 sha256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf\norganon.charter.self-transcendence.non-finality#p1 sha256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8\norganon.charter.self-transcendence.limits#p1 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d\norganon.charter.self-transcendence.limits#p2 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `k\n (Lean.Expr.const `CoreReader.Agency.FormKind [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.revisable [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Form.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.forallE\n `t\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.stableTrace []) (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.stableTrace [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `HAdd.hAdd [Lean.Level.zero, Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `instHAdd [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instAddNat [])))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.permitsVersion [])\n (Lean.Expr.const `CoreReader.Agency.neutralPolicy []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.const `CoreReader.Agency.neutralPolicy []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.permitsVersion [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.availableResources [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Option.some [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 6)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 1780710401) \"_hygCtx\") \"_hyg\") 147)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 1780710401) \"_hygCtx\") \"_hyg\") 166)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `Option [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 1780710401) \"_hygCtx\") \"_hyg\") 185)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n true)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `Option [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.requirementsMet [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.StableReason [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Announcement []))\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.GeneratingSystem.report\n [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.owner [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.owner [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.before [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.after [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.reportedNewOperation\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.input [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const\n `Eq\n [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.expectedOutput\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.claim\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.before\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.after\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))))))))))))))))))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.generationSpecification [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.const `CoreReader.Agency.baseState []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.collaborativeRevision [])\n (Lean.Expr.const `CoreReader.Agency.availableResources []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.const `CoreReader.Agency.baseState []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.collaborativeRevision [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 1780710401) \"_hygCtx\") \"_hyg\") 355)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n true)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.assistedExecution [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))))", + "sha256": "430a91318477db0305b3107b81f9df39652fa27673fdc38705a86f8e158ca138" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T02", + "case": "positive_valued_open_forms", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.generationCases", + "file": "CoreReader/Adopted.lean", + "line": 862, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "Generative requires valuation of expansion and revisability of every current Form, including organization, method and principle. Current examples are nonempty; the stable trace and budget-respecting stable action show that generativity does not require change in every act. This is an adopted policy predicate, not proof all systems possess it.", + "special_limits": [] + }, + { + "target": "T02", + "case": "negative_permission_only", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.permissionNotValuation", + "file": "CoreReader/Agency.lean", + "line": 37, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "Generative requires valuation of expansion and revisability of every current Form, including organization, method and principle. Current examples are nonempty; the stable trace and budget-respecting stable action show that generativity does not require change in every act. This is an adopted policy predicate, not proof all systems possess it.", + "special_limits": [] + }, + { + "target": "T02", + "case": "positive_stability", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.generationLimits", + "file": "CoreReader/Agency.lean", + "line": 194, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "Generative requires valuation of expansion and revisability of every current Form, including organization, method and principle. Current examples are nonempty; the stable trace and budget-respecting stable action show that generativity does not require change in every act. This is an adopted policy predicate, not proof all systems possess it.", + "special_limits": [] + }, + { + "target": "T02", + "case": "external_collaboration", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.collaborativeProgress", + "file": "CoreReader/Adopted.lean", + "line": 223, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "Generative requires valuation of expansion and revisability of every current Form, including organization, method and principle. Current examples are nonempty; the stable trace and budget-respecting stable action show that generativity does not require change in every act. This is an adopted policy predicate, not proof all systems possess it.", + "special_limits": [] + } + ] + }, + { + "id": "T03", + "kind": "nonentailment", + "statement": "Permission to change does not entail valuing expansion; valuing/open forms do not entail achieved progress, actual capability, independence, autonomous execution or self-improvement; output/term/abstraction counts or self-claims alone do not establish achievement.", + "premises": [ + "Keep valuing, revisability, progress, support and autonomous properties distinct", + "ground actual achievement in a declared criterion independent of mere count/claim." + ], + "sources": [ + { + "unit": "organon.charter.self-transcendence.orientation", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.non-finality", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + } + ], + "status": "accepted-bounded", + "prior_own_status": "bounded_countermodels", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Adopted.generationLimits012", + "file": "CoreReader/Adopted.lean", + "line": 904, + "end": 951, + "kind": "theorem", + "axioms": "[propext, Quot.sound.{u}]", + "exact_code": "theorem generationLimits012 :\n (neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy) ∧\n (Generative openPolicy ∧\n (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧\n (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1)))) ∧\n (Generative generatingSystem.policy ∧\n generatingSystem.policy.permitsVersion 0 0 ∧\n ¬ Expanded generatingSystem.current inflatedState ∧\n generatingSystem.current.inventory.length < inflatedState.inventory.length ∧\n generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧\n generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧\n generatingSystem.execute availableResources = some 6 ∧\n generatingSystem.execute { availableResources with experience := none } = none ∧\n generatingSystem.execute { availableResources with knowledge := none } = none ∧\n generatingSystem.execute { availableResources with collaborator := none } = none ∧\n generatingSystem.execute ⟨none, none, none⟩ = none ∧\n ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧\n generatingSystem.stableAction = generatingSystem.current ∧\n generatingSystem.requirementsMet generatingSystem.stableAction ∧\n generatingSystem.withinBudget generatingSystem.stableAction ∧\n ¬ generatingSystem.withinBudget inflatedState ∧\n StableReason generatingSystem.current inflatedState ∧\n (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧\n inflatedAnnouncement.owner = generatingSystem.owner ∧\n inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧\n inflatedAnnouncement.reportedNewOperation = .successor ∧\n inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧\n ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after)) ∧\n (generationSpecification openPolicy ∧\n Expanded baseState (collaborativeRevision availableResources) ∧\n ¬ Expanded baseState (collaborativeRevision { availableResources with collaborator := none }) ∧\n assistedExecution ⟨none, none, none⟩ = none) ∧\n (Grounds012 transitionAchievement canonicalArticulation [transitionFacet] (taskOfFacet transitionFacet) ∧\n Compatible [transitionPerformanceRecord] .extend ∧\n transitionAchievement .extend ∧ ¬ transitionAchievement .inflate ∧\n ¬ Supports [transitionReportRecord] transitionAchievement) ∧\n (∀ kind : InventoryKind,\n Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .copy ∧\n ¬ Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .successor) :=\n ⟨permissionNotValuation, revisionWithoutProgress, generationLimits, collaborativeProgress, achievementSupported012, inventoryCases012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.consistencyCases\norganon.charter.consistency#p1 sha256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42\norganon.charter.consistency.meaning#p1 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.permitsVersion [])\n (Lean.Expr.const `CoreReader.Agency.neutralPolicy []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.const `CoreReader.Agency.neutralPolicy []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `k\n (Lean.Expr.const `CoreReader.Agency.FormKind [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.revisable [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Form.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.forallE\n `t\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.stableTrace []) (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.stableTrace [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `HAdd.hAdd [Lean.Level.zero, Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `instHAdd [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instAddNat [])))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.permitsVersion [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.availableResources [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Option.some [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 6)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3022720055) \"_hygCtx\") \"_hyg\") 147)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3022720055) \"_hygCtx\") \"_hyg\") 166)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `Option [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3022720055) \"_hygCtx\") \"_hyg\") 185)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n true)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `Option [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.requirementsMet [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.StableReason [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Announcement []))\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.GeneratingSystem.report\n [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.owner [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.owner [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.before [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.after [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.reportedNewOperation\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.input [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const\n `Eq\n [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.expectedOutput\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.claim\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.before\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.after\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))))))))))))))))))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.generationSpecification [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.const `CoreReader.Agency.baseState []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.collaborativeRevision [])\n (Lean.Expr.const `CoreReader.Agency.availableResources []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.const `CoreReader.Agency.baseState []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.collaborativeRevision [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3022720055) \"_hygCtx\") \"_hyg\") 358)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n true)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.assistedExecution [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase []))\n (Lean.Expr.const `CoreReader.Evidence.transitionAchievement []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))\n (Lean.Expr.const `CoreReader.Evidence.transitionFacet []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase []))\n (Lean.Expr.const `CoreReader.Evidence.transitionFacet []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))\n (Lean.Expr.const `CoreReader.Evidence.transitionPerformanceRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))))\n (Lean.Expr.const `CoreReader.Agency.TransitionCase.extend [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.transitionAchievement [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase.extend [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.transitionAchievement [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase.inflate []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))\n (Lean.Expr.const `CoreReader.Evidence.transitionReportRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Agency.TransitionCase [])))))\n (Lean.Expr.const `CoreReader.Evidence.transitionAchievement []))))))))\n (Lean.Expr.forallE\n `kind\n (Lean.Expr.const `CoreReader.Agency.InventoryKind [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Available [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item [])))))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Available [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item [])))))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor []))))\n (Lean.BinderInfo.default))))))", + "sha256": "69058c75db607f675c730d92da7dd1c6ee27d75385f4ac4ff717bd9fc7e925b2" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T03", + "case": "permission_without_value", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.permissionNotValuation", + "file": "CoreReader/Agency.lean", + "line": 37, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions.", + "special_limits": [] + }, + { + "target": "T03", + "case": "orientation_without_progress", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.revisionWithoutProgress", + "file": "CoreReader/Agency.lean", + "line": 99, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions.", + "special_limits": [] + }, + { + "target": "T03", + "case": "count_growth_without_capability", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.generationLimits", + "file": "CoreReader/Agency.lean", + "line": 194, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions.", + "special_limits": [] + }, + { + "target": "T03", + "case": "collaborative_nonautonomous_progress", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.collaborativeProgress", + "file": "CoreReader/Adopted.lean", + "line": 223, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions.", + "special_limits": [] + }, + { + "target": "T03", + "case": "claim_without_achievement", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.inflatedAnnouncementRefuted", + "file": "CoreReader/Agency.lean", + "line": 171, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions.", + "special_limits": [] + }, + { + "target": "T03", + "case": "achievement_support_for_same_claim", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.achievementSupported012", + "file": "CoreReader/Adopted.lean", + "line": 620, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions.", + "special_limits": [] + } + ] + }, + { + "id": "T04", + "kind": "specification", + "statement": "All simultaneously held principles/judgments and their joint implications must avoid opposite conclusions on same question, assumptions, term meanings and scope; incompatible same-condition demands need revision/qualification; recorded change cannot be concealed.", + "premises": [ + "Consequence over whole held set", + "explicit context equality", + "no per-principle-only substitute", + "distinguish held-at-time from historical union", + "change-report condition separate from consistency." + ], + "sources": [ + { + "unit": "organon.charter.consistency", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "p1" + } + ], + "status": "accepted-bounded", + "prior_own_status": "bounded_specification", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "Consistent quantifies over joint semantic consequences of the whole held theory under one Context. Snapshot change reporting is a separate one-way Boolean obligation. The code preserves same-question/assumptions/meaning/scope and time-slice distinctions; it does not model every way a prose report could conceal change.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Adopted.consistencySpecification", + "file": "CoreReader/Adopted.lean", + "line": 90, + "end": 96, + "kind": "def", + "axioms": "[]", + "exact_code": "def consistencySpecification {W Q : Type} (before after : Snapshot W Q)\n (reported : Bool) : Prop :=\n Consistent after.held after.context ∧ TruthfulReport before after reported\n\n/- A method's actual input and interpretation are parameters, permitting domain\nmethods as well as the small arithmetic adapter. Key coherence prevents records\nfor another method from silently satisfying the duty. -/\n", + "full_type_record": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `Q\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `before\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Snapshot []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `after\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Snapshot []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.forallE\n `reported\n (Lean.Expr.const `Bool [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit))\n (Lean.BinderInfo.implicit)", + "sha256": "cf239ba7292f80875f93e960cd3417c226a8727f57f11e1ec4af4564caef076d" + }, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Adopted.consistencyCases", + "file": "CoreReader/Adopted.lean", + "line": 952, + "end": 986, + "kind": "theorem", + "axioms": "[]", + "exact_code": "theorem consistencyCases :\n (Satisfiable (singleton premiseP) ∧ Satisfiable (singleton premiseRule) ∧\n Satisfiable (singleton premiseNotQ) ∧ ¬ Satisfiable jointTheory) ∧\n ((Consequence emptyTheory (assumptionContext true) () true ∧\n Consequence emptyTheory (assumptionContext false) () false) ∧\n (Consequence emptyTheory (meaningContext true) () true ∧\n Consequence emptyTheory (meaningContext false) () false) ∧\n (Consequence emptyTheory (scopeContext true) () true ∧\n Consequence emptyTheory (scopeContext false) () false) ∧\n (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧\n (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧\n (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w)) ∧\n (¬ TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) false ∧\n ¬ TruthfulReport (contextSnapshot (meaningContext true)) (contextSnapshot (meaningContext false)) false ∧\n ¬ TruthfulReport (contextSnapshot (scopeContext true)) (contextSnapshot (scopeContext false)) false ∧\n ¬ TruthfulReport (contextSnapshot (scopeContext true) 0) (contextSnapshot (scopeContext true) 1) false ∧\n (TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) true ∧\n ¬ Models (assumptionContext false).assumptions true)) ∧\n (Satisfiable (revisionSlice 0) ∧ Satisfiable (revisionSlice 1) ∧\n ¬ Satisfiable (union (revisionSlice 0) (revisionSlice 1))) ∧\n ((∀ time, Consistent (revisionSlice time) broadBoolContext) ∧\n ¬ Consistent (union (revisionSlice 0) (revisionSlice 1)) broadBoolContext) ∧\n (∀ p q : Claim Bool,\n ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r) ∧\n (Consequence jointTheory jointContext012 () true ∧\n Consequence jointTheory jointContext012 () false ∧\n ¬ Consistent jointTheory jointContext012) :=\n ⟨jointConflict, contextDifferences, hiddenContextChangeRejected, revisionCanReverse, sliceConsistency, semanticOrder012, jointImplicationConflict012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.consistencyLimits012\norganon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.premiseP []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.premiseRule []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.premiseNotQ []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.jointTheory [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consequence [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.assumptionContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.meaningContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.scopeContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.TruthfulReport []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.TruthfulReport []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.TruthfulReport [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.TruthfulReport [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.TruthfulReport [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Models []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Context.assumptions [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.const `Bool.true [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `time\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.revisionSlice []) (Lean.Expr.bvar 0)))\n (Lean.Expr.const `CoreReader.Adopted.broadBoolContext []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.const `CoreReader.Adopted.broadBoolContext [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `p\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `Bool []))\n (Lean.Expr.forallE\n `q\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `Bool []))\n (Lean.Expr.forallE\n `r\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Iff [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 2)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 2)))\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consequence [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.const `CoreReader.Logic.jointTheory []))\n (Lean.Expr.const `CoreReader.Adopted.jointContext012 []))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consequence [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.const `CoreReader.Logic.jointTheory []))\n (Lean.Expr.const `CoreReader.Adopted.jointContext012 []))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consistent [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.const `CoreReader.Logic.jointTheory []))\n (Lean.Expr.const `CoreReader.Adopted.jointContext012 []))))))))))", + "sha256": "16a20441e5650e4992e046ae4eeb2a1867f573730aa1dc402ca70508bb1802a6" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T04", + "case": "joint_only_contradiction", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.jointImplicationConflict012", + "file": "CoreReader/Adopted.lean", + "line": 703, + "axioms": "[]" + } + ], + "interpretation": "Consistent quantifies over joint semantic consequences of the whole held theory under one Context. Snapshot change reporting is a separate one-way Boolean obligation. The code preserves same-question/assumptions/meaning/scope and time-slice distinctions; it does not model every way a prose report could conceal change.", + "special_limits": [] + }, + { + "target": "T04", + "case": "changed_scope_not_concealed", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Logic.hiddenContextChangeRejected", + "file": "CoreReader/Logic.lean", + "line": 134, + "axioms": "[]" + } + ], + "interpretation": "Consistent quantifies over joint semantic consequences of the whole held theory under one Context. Snapshot change reporting is a separate one-way Boolean obligation. The code preserves same-question/assumptions/meaning/scope and time-slice distinctions; it does not model every way a prose report could conceal change.", + "special_limits": [] + }, + { + "target": "T04", + "case": "revision_withdraws_old", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Logic.revisionCanReverse", + "file": "CoreReader/Logic.lean", + "line": 68, + "axioms": "[]" + } + ], + "interpretation": "Consistent quantifies over joint semantic consequences of the whole held theory under one Context. Snapshot change reporting is a separate one-way Boolean obligation. The code preserves same-question/assumptions/meaning/scope and time-slice distinctions; it does not model every way a prose report could conceal change.", + "special_limits": [] + }, + { + "target": "T04", + "case": "incompatible_same_context", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.consistencyConsequences", + "file": "CoreReader/Adopted.lean", + "line": 241, + "axioms": "[]" + } + ], + "interpretation": "Consistent quantifies over joint semantic consequences of the whole held theory under one Context. Snapshot change reporting is a separate one-way Boolean obligation. The code preserves same-question/assumptions/meaning/scope and time-slice distinctions; it does not model every way a prose report could conceal change.", + "special_limits": [] + } + ] + }, + { + "id": "T05", + "kind": "theorem", + "statement": "Given faithful context identity and whole-set consequence, an opposite pair under the same context violates consistency; removing a prior judgment may eliminate the conflict without requiring permanent historical compatibility.", + "premises": [ + "A consequence relation, positive/negative conclusions for same question, active-set membership, context equality", + "explicit withdrawal semantics", + "no explosion assumption needed." + ], + "sources": [ + { + "unit": "organon.charter.consistency", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "p1" + } + ], + "status": "accepted-bounded", + "prior_own_status": "conditional_theorem", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "consistencyConsequences directly applies the consistency prohibition to supplied positive and negative consequences. The revisionSlice examples provide distinct satisfiable times and inconsistent union; context examples preserve an admissible witness for each context. The theorem neither proves premises nor mandates permanent historical compatibility.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Adopted.consistencyConsequences", + "file": "CoreReader/Adopted.lean", + "line": 241, + "end": 244, + "kind": "theorem", + "axioms": "[]", + "exact_code": "theorem consistencyConsequences {W Q : Type} (t : Theory W) (c : Context W Q) (q : Q)\n (positive : Consequence t c q true) (negative : Consequence t c q false) :\n ¬ Consistent t c := conflictRequiresChange t c q positive negative\n\n", + "full_type_record": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `Q\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `t\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Theory []) (Lean.Expr.bvar 1))\n (Lean.Expr.forallE\n `c\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Context []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.forallE\n `q\n (Lean.Expr.bvar 2)\n (Lean.Expr.forallE\n `positive\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.bvar 4))\n (Lean.Expr.bvar 3))\n (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.forallE\n `negative\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.bvar 5))\n (Lean.Expr.bvar 4))\n (Lean.Expr.bvar 3))\n (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `Bool.false []))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.bvar 6))\n (Lean.Expr.bvar 5))\n (Lean.Expr.bvar 4))\n (Lean.Expr.bvar 3)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit))\n (Lean.BinderInfo.implicit)", + "sha256": "4b3231ac25a534c2699cd8f548a59a7d8beb1cb3923456f10c95081a3b6b5be3" + }, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Adopted.consistencyCases", + "file": "CoreReader/Adopted.lean", + "line": 952, + "end": 986, + "kind": "theorem", + "axioms": "[]", + "exact_code": "theorem consistencyCases :\n (Satisfiable (singleton premiseP) ∧ Satisfiable (singleton premiseRule) ∧\n Satisfiable (singleton premiseNotQ) ∧ ¬ Satisfiable jointTheory) ∧\n ((Consequence emptyTheory (assumptionContext true) () true ∧\n Consequence emptyTheory (assumptionContext false) () false) ∧\n (Consequence emptyTheory (meaningContext true) () true ∧\n Consequence emptyTheory (meaningContext false) () false) ∧\n (Consequence emptyTheory (scopeContext true) () true ∧\n Consequence emptyTheory (scopeContext false) () false) ∧\n (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧\n (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧\n (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w)) ∧\n (¬ TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) false ∧\n ¬ TruthfulReport (contextSnapshot (meaningContext true)) (contextSnapshot (meaningContext false)) false ∧\n ¬ TruthfulReport (contextSnapshot (scopeContext true)) (contextSnapshot (scopeContext false)) false ∧\n ¬ TruthfulReport (contextSnapshot (scopeContext true) 0) (contextSnapshot (scopeContext true) 1) false ∧\n (TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) true ∧\n ¬ Models (assumptionContext false).assumptions true)) ∧\n (Satisfiable (revisionSlice 0) ∧ Satisfiable (revisionSlice 1) ∧\n ¬ Satisfiable (union (revisionSlice 0) (revisionSlice 1))) ∧\n ((∀ time, Consistent (revisionSlice time) broadBoolContext) ∧\n ¬ Consistent (union (revisionSlice 0) (revisionSlice 1)) broadBoolContext) ∧\n (∀ p q : Claim Bool,\n ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r) ∧\n (Consequence jointTheory jointContext012 () true ∧\n Consequence jointTheory jointContext012 () false ∧\n ¬ Consistent jointTheory jointContext012) :=\n ⟨jointConflict, contextDifferences, hiddenContextChangeRejected, revisionCanReverse, sliceConsistency, semanticOrder012, jointImplicationConflict012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.consistencyLimits012\norganon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.premiseP []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.premiseRule []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.premiseNotQ []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Satisfiable [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Logic.jointTheory [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consequence [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.assumptionContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.meaningContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.scopeContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.TruthfulReport []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.TruthfulReport []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.TruthfulReport [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.TruthfulReport [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.TruthfulReport [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.contextSnapshot [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Models []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Context.assumptions [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.const `Bool.true [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `time\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.revisionSlice []) (Lean.Expr.bvar 0)))\n (Lean.Expr.const `CoreReader.Adopted.broadBoolContext []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.revisionSlice [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.const `CoreReader.Adopted.broadBoolContext [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `p\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `Bool []))\n (Lean.Expr.forallE\n `q\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `Bool []))\n (Lean.Expr.forallE\n `r\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Iff [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 2)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 2)))\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consequence [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.const `CoreReader.Logic.jointTheory []))\n (Lean.Expr.const `CoreReader.Adopted.jointContext012 []))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consequence [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.const `CoreReader.Logic.jointTheory []))\n (Lean.Expr.const `CoreReader.Adopted.jointContext012 []))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Consistent [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.const `CoreReader.Logic.jointTheory []))\n (Lean.Expr.const `CoreReader.Adopted.jointContext012 []))))))))))", + "sha256": "16a20441e5650e4992e046ae4eeb2a1867f573730aa1dc402ca70508bb1802a6" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T05", + "case": "pair_conflict", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.consistencyConsequences", + "file": "CoreReader/Adopted.lean", + "line": 241, + "axioms": "[]" + } + ], + "interpretation": "consistencyConsequences directly applies the consistency prohibition to supplied positive and negative consequences. The revisionSlice examples provide distinct satisfiable times and inconsistent union; context examples preserve an admissible witness for each context. The theorem neither proves premises nor mandates permanent historical compatibility.", + "special_limits": [] + }, + { + "target": "T05", + "case": "joint_premise_conflict", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.jointImplicationConflict012", + "file": "CoreReader/Adopted.lean", + "line": 703, + "axioms": "[]" + } + ], + "interpretation": "consistencyConsequences directly applies the consistency prohibition to supplied positive and negative consequences. The revisionSlice examples provide distinct satisfiable times and inconsistent union; context examples preserve an admissible witness for each context. The theorem neither proves premises nor mandates permanent historical compatibility.", + "special_limits": [] + }, + { + "target": "T05", + "case": "old_new_separate_times", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.sliceConsistency", + "file": "CoreReader/Adopted.lean", + "line": 247, + "axioms": "[]" + } + ], + "interpretation": "consistencyConsequences directly applies the consistency prohibition to supplied positive and negative consequences. The revisionSlice examples provide distinct satisfiable times and inconsistent union; context examples preserve an admissible witness for each context. The theorem neither proves premises nor mandates permanent historical compatibility.", + "special_limits": [] + }, + { + "target": "T05", + "case": "distinct_context_judgments", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Logic.contextDifferences", + "file": "CoreReader/Logic.lean", + "line": 88, + "axioms": "[]" + } + ], + "interpretation": "consistencyConsequences directly applies the consistency prohibition to supplied positive and negative consequences. The revisionSlice examples provide distinct satisfiable times and inconsistent union; context examples preserve an admissible witness for each context. The theorem neither proves premises nor mandates permanent historical compatibility.", + "special_limits": [] + }, + { + "target": "T05", + "case": "truthful_semantic_change_and_reordering", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Logic.hiddenContextChangeRejected", + "file": "CoreReader/Logic.lean", + "line": 134, + "axioms": "[]" + }, + { + "name": "CoreReader.Adopted.semanticOrder012", + "file": "CoreReader/Adopted.lean", + "line": 630, + "axioms": "[]" + } + ], + "interpretation": "consistencyConsequences directly applies the consistency prohibition to supplied positive and negative consequences. The revisionSlice examples provide distinct satisfiable times and inconsistent union; context examples preserve an admissible witness for each context. The theorem neither proves premises nor mandates permanent historical compatibility.", + "special_limits": [] + } + ] + }, + { + "id": "T06", + "kind": "nonentailment", + "statement": "Different-condition disagreement and value tension alone do not entail contradiction; consistency does not entail true assumptions, adequacy or support for a compatible conclusion.", + "premises": [ + "Concrete shared interpretation of truth/support and consequence", + "relevant omitted question represented", + "unsupported conclusion must demonstrably fail entailment, not merely have a false support flag." + ], + "sources": [ + { + "unit": "organon.charter.consistency.meaning", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + } + ], + "status": "accepted-bounded", + "prior_own_status": "bounded_countermodels", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "Concrete contexts, overlapping inequalities, a consistent theory false at the selected outside world, and empty-theory countervaluations distinguish contradiction, truth, sufficiency and entailment. These support the source limits without relying on a free false support flag.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Adopted.consistencyLimits012", + "file": "CoreReader/Adopted.lean", + "line": 987, + "end": 1014, + "kind": "theorem", + "axioms": "[]", + "exact_code": "theorem consistencyLimits012 :\n ((Consequence emptyTheory (assumptionContext true) () true ∧\n Consequence emptyTheory (assumptionContext false) () false) ∧\n (Consequence emptyTheory (meaningContext true) () true ∧\n Consequence emptyTheory (meaningContext false) () false) ∧\n (Consequence emptyTheory (scopeContext true) () true ∧\n Consequence emptyTheory (scopeContext false) () false) ∧\n (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧\n (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧\n (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w)) ∧\n ((∃ budget : Nat, 4 ≤ budget ∧ budget ≤ 6) ∧\n ¬ ((fun n : Nat => 4 ≤ n) = (fun n : Nat => n ≤ 6))) ∧\n (Consistent (singleton (fun w : Bool => w = true)) broadBoolContext ∧\n ¬ Models (singleton (fun w : Bool => w = true)) false ∧\n Consistent (emptyTheory : Theory Bool) broadBoolContext ∧\n ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧\n (Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧\n ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧\n (Consistent (union (singleton (fun n : Nat => 4 ≤ n)) (singleton (fun n => n ≤ 6))) tensionContext012) :=\n ⟨contextDifferences, tensionWithoutContradiction, explicitlyConsistentLimits, compatibilityNotEntailment, tensionConsistent012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.reflexivityCases012\norganon.charter.reflexivity#p1 sha256 13293b45c2fa89068c68ae7ef3c5df38f0efadb3ef3873d78a5ba67d9691a757\norganon.charter.reflexivity.meaning#p1 sha256 8a2caede01a43d8b6c60b54c78ac089c51868e9956f316948077ccee2e45c9cc\norganon.charter.reflexivity.limits#p1 sha256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.assumptionContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.meaningContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consequence []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.scopeContext [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Unit.unit []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Admissible []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.assumptionContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.emptyTheory [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.meaningContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.forallE\n `b\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Admissible []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.scopeContext []) (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lam\n `budget\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 4)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 4)))))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 6))))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 4)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 4)))))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 6)))))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.broadBoolContext [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Models []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.broadBoolContext [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Consistent []) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Unit []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Nat []))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 4)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 4)))))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Nat []))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LE.le [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLENat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 6)))))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.const `CoreReader.Adopted.tensionContext012 [])))))", + "sha256": "1bb1429eb084c222d9a84341c2d6cae05e8c83c1374bbbab8402a372099649cc" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T06", + "case": "different_contexts", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Logic.contextDifferences", + "file": "CoreReader/Logic.lean", + "line": 88, + "axioms": "[]" + } + ], + "interpretation": "Concrete contexts, overlapping inequalities, a consistent theory false at the selected outside world, and empty-theory countervaluations distinguish contradiction, truth, sufficiency and entailment. These support the source limits without relying on a free false support flag.", + "special_limits": [] + }, + { + "target": "T06", + "case": "tension_compatible", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.tensionConsistent012", + "file": "CoreReader/Adopted.lean", + "line": 718, + "axioms": "[]" + } + ], + "interpretation": "Concrete contexts, overlapping inequalities, a consistent theory false at the selected outside world, and empty-theory countervaluations distinguish contradiction, truth, sufficiency and entailment. These support the source limits without relying on a free false support flag.", + "special_limits": [] + }, + { + "target": "T06", + "case": "consistent_false_assumption", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.explicitlyConsistentLimits", + "file": "CoreReader/Adopted.lean", + "line": 262, + "axioms": "[]" + } + ], + "interpretation": "Concrete contexts, overlapping inequalities, a consistent theory false at the selected outside world, and empty-theory countervaluations distinguish contradiction, truth, sufficiency and entailment. These support the source limits without relying on a free false support flag.", + "special_limits": [] + }, + { + "target": "T06", + "case": "consistent_omitted_question", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.explicitlyConsistentLimits", + "file": "CoreReader/Adopted.lean", + "line": 262, + "axioms": "[]" + } + ], + "interpretation": "Concrete contexts, overlapping inequalities, a consistent theory false at the selected outside world, and empty-theory countervaluations distinguish contradiction, truth, sufficiency and entailment. These support the source limits without relying on a free false support flag.", + "special_limits": [] + }, + { + "target": "T06", + "case": "compatible_not_entailed", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Logic.compatibilityNotEntailment", + "file": "CoreReader/Logic.lean", + "line": 180, + "axioms": "[]" + } + ], + "interpretation": "Concrete contexts, overlapping inequalities, a consistent theory false at the selected outside world, and empty-theory countervaluations distinguish contradiction, truth, sufficiency and entailment. These support the source limits without relying on a free false support flag.", + "special_limits": [] + } + ] + }, + { + "id": "T07", + "kind": "specification", + "statement": "Generation and assessment apply to system and principle formation/application/revision under their actual applicability conditions; self-status is no exemption; applicability is not universalized; Grounds grounds/limits and own capability claims are included.", + "premises": [ + "Explicit target kinds for system, formation, application, revision", + "principle applicability and duties", + "nonempty applicable self-target and inapplicable pair", + "no endless-recursion requirement." + ], + "sources": [ + { + "unit": "organon.charter.reflexivity", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + } + ], + "status": "accepted-bounded", + "prior_own_status": "bounded_specification", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "The general interface/cases are reused; its engineering realization was rereviewed because selfModel now includes actual generation/evaluation rule objects and applicability. This strengthens rather than universalizes the source conditions.", + "reuse": "Source/target text and unchanged nonblank definitions reused; affected transitive composition was rereviewed.", + "declarations": [ + { + "name": "CoreReader.Adopted.reflexivitySpecification", + "file": "CoreReader/Adopted.lean", + "line": 110, + "end": 116, + "kind": "def", + "axioms": "[]", + "exact_code": "def reflexivitySpecification {T I O : Type} (rules : List (ReflexiveRule T I O))\n (isSelf : T → Prop) (performed : PrincipleKey → T → I → O → Prop) : Prop :=\n (∀ p ∈ rules, ∀ q ∈ rules, p.key = q.key → p = q) ∧\n ∀ rule ∈ rules, ∀ target, isSelf target → rule.applicable target →\n ∃ outcome, performed rule.key target (rule.input target) outcome ∧\n rule.meaning (rule.input target) outcome\n\n", + "full_type_record": { + "type": "Lean.Expr.forallE\n `T\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `I\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `O\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `rules\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.forallE\n `isSelf\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 3)\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `performed\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Agency.PrincipleKey [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 5)\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 5)\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 5)\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit))\n (Lean.BinderInfo.implicit))\n (Lean.BinderInfo.implicit)", + "sha256": "d8084253926a4e9a9b2b9d6ccea7fcba129de72b8412ec4bd30c08a9bdf254bc" + }, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Adopted.reflexivityCases012", + "file": "CoreReader/Adopted.lean", + "line": 1015, + "end": 1037, + "kind": "theorem", + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "exact_code": "theorem reflexivityCases012 :\n (reflexivitySpecification ((ownRules 0).map legacyRule) (fun s => s.owner = 0)\n (legacyPerformed (ownRules 0) (completeOwnWork 0)) ∧\n (∀ phase, Performed (completeOwnWork 0) (.process 0 0 phase) .assessment) ∧\n Performed (completeOwnWork 0) (.system 0) .assessment ∧\n reflexivitySpecification ([applicationRule].map legacyRule) (fun s => s.owner = 0)\n (legacyPerformed [applicationRule] applicationWork) ∧\n ¬ Performed applicationWork (.system 0) .assessment) ∧\n (Grounds012 (fun enabled => GroundsProvision012 enabled) canonicalArticulation [.value groundsPosition012] (.value groundsPosition012) ∧\n groundsPosition012.limits true ∧ groundsPosition012.relevantCriticism true) ∧\n (Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0) ∧\n groundsExperiment012 true = false ∧ groundsExperiment012 false = true ∧\n groundsPosition012.outcome true true = groundsExperiment012 true ∧\n groundsPosition012.outcome true false = groundsExperiment012 false) :=\n ⟨reflexiveTargets012, groundsOnGrounds012, groundsRationaleExperiment012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.reflexivityLimits012\norganon.charter.reflexivity.limits#p1 sha256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.grounds#p1 sha256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.reflexivitySpecification [])\n (Lean.Expr.const `CoreReader.Agency.Subject []))\n (Lean.Expr.const `CoreReader.Agency.Inquiry []))\n (Lean.Expr.const `CoreReader.Agency.WorkOutcome []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.map [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule [])\n (Lean.Expr.const `CoreReader.Agency.Subject []))\n (Lean.Expr.const `CoreReader.Agency.Inquiry []))\n (Lean.Expr.const `CoreReader.Agency.WorkOutcome [])))\n (Lean.Expr.const `CoreReader.Adopted.legacyRule []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ownRules [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.lam\n `s\n (Lean.Expr.const `CoreReader.Agency.Subject [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Subject.owner []) (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.legacyPerformed [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ownRules [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.completeOwnWork [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `phase\n (Lean.Expr.const `CoreReader.Agency.Phase [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Performed [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.completeOwnWork [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Subject.process [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `CoreReader.Agency.Activity.assessment []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Performed [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.completeOwnWork [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Subject.system [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `CoreReader.Agency.Activity.assessment [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.reflexivitySpecification [])\n (Lean.Expr.const `CoreReader.Agency.Subject []))\n (Lean.Expr.const `CoreReader.Agency.Inquiry []))\n (Lean.Expr.const `CoreReader.Agency.WorkOutcome []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.map [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule [])\n (Lean.Expr.const `CoreReader.Agency.Subject []))\n (Lean.Expr.const `CoreReader.Agency.Inquiry []))\n (Lean.Expr.const `CoreReader.Agency.WorkOutcome [])))\n (Lean.Expr.const `CoreReader.Adopted.legacyRule []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle []))\n (Lean.Expr.const `CoreReader.Agency.applicationRule []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle [])))))\n (Lean.Expr.lam\n `s\n (Lean.Expr.const `CoreReader.Agency.Subject [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Subject.owner []) (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.legacyPerformed [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle []))\n (Lean.Expr.const `CoreReader.Agency.applicationRule []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Principle []))))\n (Lean.Expr.const `CoreReader.Agency.applicationWork []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Performed [])\n (Lean.Expr.const `CoreReader.Agency.applicationWork []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Subject.system [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `CoreReader.Agency.Activity.assessment []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.Grounds012 []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `enabled\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.GroundsProvision012 []) (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet.value []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.AssessmentTask.value []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.limits [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.relevantCriticism [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 []))\n (Lean.Expr.const `Bool.true [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.groundsExperiment012 [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.groundsExperiment012 [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Outcome [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.outcome [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.groundsExperiment012 [])\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Outcome [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.outcome [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.groundsPosition012 []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.groundsExperiment012 [])\n (Lean.Expr.const `Bool.false [])))))))))", + "sha256": "55a9d738a39137aeb7cf0ee474c532a636dc2a59451613848747030a756b29e7" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T07", + "case": "self_applicable", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.reflexiveTargets012", + "file": "CoreReader/Adopted.lean", + "line": 605, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "The general interface/cases are reused; its engineering realization was rereviewed because selfModel now includes actual generation/evaluation rule objects and applicability. This strengthens rather than universalizes the source conditions.", + "special_limits": [] + }, + { + "target": "T07", + "case": "self_inapplicable", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.applicabilityRetained", + "file": "CoreReader/Reflexivity.lean", + "line": 396, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "The general interface/cases are reused; its engineering realization was rereviewed because selfModel now includes actual generation/evaluation rule objects and applicability. This strengthens rather than universalizes the source conditions.", + "special_limits": [] + }, + { + "target": "T07", + "case": "principle_formation", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.completeOwnWork_reflexive", + "file": "CoreReader/Reflexivity.lean", + "line": 358, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "The general interface/cases are reused; its engineering realization was rereviewed because selfModel now includes actual generation/evaluation rule objects and applicability. This strengthens rather than universalizes the source conditions.", + "special_limits": [] + }, + { + "target": "T07", + "case": "principle_application", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.reflexiveTargets012", + "file": "CoreReader/Adopted.lean", + "line": 605, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "The general interface/cases are reused; its engineering realization was rereviewed because selfModel now includes actual generation/evaluation rule objects and applicability. This strengthens rather than universalizes the source conditions.", + "special_limits": [] + }, + { + "target": "T07", + "case": "principle_revision", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.reflexiveTargets012", + "file": "CoreReader/Adopted.lean", + "line": 605, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "The general interface/cases are reused; its engineering realization was rereviewed because selfModel now includes actual generation/evaluation rule objects and applicability. This strengthens rather than universalizes the source conditions.", + "special_limits": [] + }, + { + "target": "T07", + "case": "grounds_on_grounds", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.groundsOnGrounds012", + "file": "CoreReader/Adopted.lean", + "line": 595, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "The general interface/cases are reused; its engineering realization was rereviewed because selfModel now includes actual generation/evaluation rule objects and applicability. This strengthens rather than universalizes the source conditions.", + "special_limits": [] + } + ] + }, + { + "id": "T08", + "kind": "nonentailment", + "statement": "Self-application or self-produced revision does not establish correctness or sufficient grounds; openness of forms does not by itself meet reflexivity. In the declared representation, one nonempty common context satisfies the complete represented Charter requirements but fails the represented general Grounds requirement for a concrete identified claim. This bounded example shows that chapter placement supplies no deductive support; it does not assert independence in every possible representation.", + "premises": [ + "Assessment events/duties not truth", + "generation provenance not support", + "concrete countercase with a revisable but self-exempt assessment rule.", + "Complete represented Charter includes the specifications in T02, T04 and T07 with their applicability conditions.", + "General Grounds includes the T09 articulation, corresponding assessment and proportionality requirements. Failure must concern a concrete identified claim, grounds, scope and strength, with a substantive failed support relation, not an empty domain, missing record or freely assigned false label. Grounds is not assumed." + ], + "sources": [ + { + "unit": "organon.charter.reflexivity.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + }, + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "organon.grounds", + "clause": "p1" + } + ], + "status": "accepted-bounded", + "prior_own_status": "bounded_countermodels", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "A revisable principle applied only to target 1 fails required self-target 0; self tests fail elsewhere; owned revisions retain unsupported global claims. CompleteCharter012 is inhabited yet costAllowanceRecord admits an incorrect-output world, so the concrete corresponding Grounds012 claim fails. This is a bounded charter-versus-support model, not philosophical independence in all interpretations.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Adopted.reflexivityLimits012", + "file": "CoreReader/Adopted.lean", + "line": 1038, + "end": 1065, + "kind": "theorem", + "axioms": "[propext, Quot.sound.{u}]", + "exact_code": "theorem reflexivityLimits012 :\n (selfTest [1] = true ∧ ownArithmeticPrinciple 0 = false ∧\n ¬ (∀ n, ownArithmeticPrinciple n = true)) ∧\n (localGenerator 0 0 = true ∧ localGenerator 0 1 = false ∧\n Compatible [zeroRecord] (localGenerator 0) ∧\n ¬ Supports [zeroRecord] allTrue ∧ OwnedRevisionExample) ∧\n (Generative openPolicy ∧ ¬ Reflexive 0 (ownRules 0) []) ∧\n (CompleteCharter012 CoreReader.Integration.actualSystem CoreReader.Integration.actual ∧\n Admissible CoreReader.Integration.held CoreReader.Integration.context CoreReader.Integration.actual ∧\n Compatible [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.actual ∧\n Articulated (canonicalArticulation CoreReader.Integration.unsupportedCapabilityFacet) ∧\n ¬ Supports [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.capability ∧\n ¬ Grounds012 CoreReader.Integration.capability canonicalArticulation\n [CoreReader.Integration.unsupportedCapabilityFacet]\n (taskOfFacet CoreReader.Integration.unsupportedCapabilityFacet)) ∧\n (generationSpecification openPolicy ∧ openPolicy.revisable ⟨.principle,0⟩ ∧\n selfExemptPerformed012 ⟨0,1⟩ 1 1 true ∧\n selfExemptRule012.applicable 0 ∧\n ¬ reflexivitySpecification [selfExemptRule012] (fun target => target = 0) selfExemptPerformed012) :=\n ⟨selfTestDoesNotProve, selfOriginDoesNotSupport, generationNotReflexivity, charterWithoutGrounds012, openSelfExempt012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.groundsCases012\norganon.grounds#p1 sha256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6\norganon.grounds.assessment#p1 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.selfTest [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ownArithmeticPrinciple [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.ownArithmeticPrinciple []) (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Evidence.allTrue []))))\n (Lean.Expr.const `CoreReader.Evidence.OwnedRevisionExample []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Reflexive [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ownRules [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.WorkRecord []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.CompleteCharter012 [])\n (Lean.Expr.const `CoreReader.Integration.actualSystem []))\n (Lean.Expr.const `CoreReader.Integration.actual [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.const `CoreReader.Integration.Question []))\n (Lean.Expr.const `CoreReader.Integration.held []))\n (Lean.Expr.const `CoreReader.Integration.context []))\n (Lean.Expr.const `CoreReader.Integration.actual [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Integration.World [])))\n (Lean.Expr.const `CoreReader.Integration.costAllowanceRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Integration.World [])))))\n (Lean.Expr.const `CoreReader.Integration.actual [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulated [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.const `CoreReader.Integration.unsupportedCapabilityFacet []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Integration.World [])))\n (Lean.Expr.const `CoreReader.Integration.costAllowanceRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Integration.World [])))))\n (Lean.Expr.const `CoreReader.Integration.capability []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.const `CoreReader.Integration.capability []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Integration.World [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Integration.World [])))\n (Lean.Expr.const `CoreReader.Integration.unsupportedCapabilityFacet []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Integration.World [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.const `CoreReader.Integration.World []))\n (Lean.Expr.const `CoreReader.Integration.unsupportedCapabilityFacet []))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.generationSpecification [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.revisable [])\n (Lean.Expr.const `CoreReader.Agency.openPolicy []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Form.mk [])\n (Lean.Expr.const `CoreReader.Agency.FormKind.principle []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.selfExemptPerformed012 [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.PrincipleKey.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule.applicable [])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.selfExemptRule012 []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.reflexivitySpecification [])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule [])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.selfExemptRule012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ReflexiveRule [])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool [])))))\n (Lean.Expr.lam\n `target\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.selfExemptPerformed012 []))))))))))", + "sha256": "6aaa9a96ab7f8fe3ebe04633ee7e9ae054eafa88e7e8289179d143ee96e46d05" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T08", + "case": "self_assessed_incorrect", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.selfTestDoesNotProve", + "file": "CoreReader/Agency.lean", + "line": 239, + "axioms": "[]" + } + ], + "interpretation": "A revisable principle applied only to target 1 fails required self-target 0; self tests fail elsewhere; owned revisions retain unsupported global claims. CompleteCharter012 is inhabited yet costAllowanceRecord admits an incorrect-output world, so the concrete corresponding Grounds012 claim fails. This is a bounded charter-versus-support model, not philosophical independence in all interpretations.", + "special_limits": [] + }, + { + "target": "T08", + "case": "self_generated_unsupported", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.selfOriginDoesNotSupport", + "file": "CoreReader/Evidence.lean", + "line": 541, + "axioms": "[propext]" + } + ], + "interpretation": "A revisable principle applied only to target 1 fails required self-target 0; self tests fail elsewhere; owned revisions retain unsupported global claims. CompleteCharter012 is inhabited yet costAllowanceRecord admits an incorrect-output world, so the concrete corresponding Grounds012 claim fails. This is a bounded charter-versus-support model, not philosophical independence in all interpretations.", + "special_limits": [] + }, + { + "target": "T08", + "case": "open_but_self_exempt", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.openSelfExempt012", + "file": "CoreReader/Adopted.lean", + "line": 680, + "axioms": "[propext]" + } + ], + "interpretation": "A revisable principle applied only to target 1 fails required self-target 0; self tests fail elsewhere; owned revisions retain unsupported global claims. CompleteCharter012 is inhabited yet costAllowanceRecord admits an incorrect-output world, so the concrete corresponding Grounds012 claim fails. This is a bounded charter-versus-support model, not philosophical independence in all interpretations.", + "special_limits": [] + }, + { + "target": "T08", + "case": "charter_not_general_grounds", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.charterWithoutGrounds012", + "file": "CoreReader/Adopted.lean", + "line": 499, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "A revisable principle applied only to target 1 fails required self-target 0; self tests fail elsewhere; owned revisions retain unsupported global claims. CompleteCharter012 is inhabited yet costAllowanceRecord admits an incorrect-output world, so the concrete corresponding Grounds012 claim fails. This is a bounded charter-versus-support model, not philosophical independence in all interpretations.", + "special_limits": [] + } + ] + }, + { + "id": "T09", + "kind": "specification", + "statement": "Grounds requires articulable concepts/assumptions/reasons/limits, assessment appropriate to claim nature, and strength/scope proportionate to supplied support. Articulation and assessment are distinct responsibilities.", + "premises": [ + "Grounds tied to corresponding claim and context", + "explicit support relation, force and scope", + "no universal numeric scale or complete mutually exclusive taxonomy", + "Core 0.1.2 only." + ], + "sources": [ + { + "unit": "organon.grounds", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + } + ], + "status": "accepted-bounded", + "prior_own_status": "qualified_success_specification", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "Grounds012 formalizes successful supported grounds for one declared task using same claim/articulation/discharge and task-appropriateness. Local/global and stronger-claim countermodels preserve force and scope. It is not a complete classifier or universal procedure for deciding all possible mixed claims. Calling it the obligation to examine rather than the successful support condition would overstate the correspondence. No Core 0.1.3 all-facet obligation is introduced.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Adopted.Grounds012", + "file": "CoreReader/Adopted.lean", + "line": 54, + "end": 63, + "kind": "def", + "axioms": "[propext]", + "exact_code": "def Grounds012 {W : Type} (claim : Claim W)\n (articulations : Facet W → Articulation W) (facets : List (Facet W))\n (task : AssessmentTask W) : Prop :=\n facets ≠ [] ∧ ∀ facet ∈ facets,\n facet.claim = claim ∧ Articulated (articulations facet) ∧\n FacetArticulated (articulations facet) facet ∧ FacetDischarged facet ∧\n NatureAppropriate task facet\n\n/- This helper proves the newly declared taskOfFacet f only. It supplies no\nappropriateness proof for another, previously fixed task with the same claim. -/\n", + "full_type_record": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `claim\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `articulations\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.bvar 1))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Articulation []) (Lean.Expr.bvar 2))\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `facets\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.bvar 2)))\n (Lean.Expr.forallE\n `task\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.AssessmentTask []) (Lean.Expr.bvar 3))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)", + "sha256": "65ead33e1cc510ec07082dde80dbec28ca36d80391c18e2ca6df7ed3e1353029" + }, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Adopted.groundsCases012", + "file": "CoreReader/Adopted.lean", + "line": 1066, + "end": 1081, + "kind": "theorem", + "axioms": "[propext]", + "exact_code": "theorem groundsCases012 :\n (Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧\n Articulated (canonicalArticulation globalFacet012) ∧\n ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧\n ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012)) ∧\n (Articulated uninformativeArgument ∧\n ¬ Entails uninformativeArgument.assumptions (fun w : Bool => w = true)) ∧\n (Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] (taskOfFacet circularGlobalFacet012) ∧\n ¬ NatureAppropriate originalGlobalTask012 circularGlobalFacet012 ∧\n ¬ Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] originalGlobalTask012) :=\n ⟨scopeStrength012, articulationNotSupport, circularSubstitutionRejected012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.empiricalCases012\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulated [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Articulated []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.uninformativeArgument [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulation.assumptions [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.uninformativeArgument [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Evidence.allTrue []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.circularGlobalFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.circularGlobalFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.NatureAppropriate [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.originalGlobalTask012 []))\n (Lean.Expr.const `CoreReader.Adopted.circularGlobalFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Evidence.allTrue []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.circularGlobalFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Adopted.originalGlobalTask012 []))))))", + "sha256": "5d659ec603f559d1be5abf4df0466b2daee1633dcfbf70194c0b8ccf9640e40f" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T09", + "case": "articulable_supported", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.scopeStrength012", + "file": "CoreReader/Adopted.lean", + "line": 286, + "axioms": "[propext]" + } + ], + "interpretation": "Grounds012 formalizes successful supported grounds for one declared task using same claim/articulation/discharge and task-appropriateness. Local/global and stronger-claim countermodels preserve force and scope. It is not a complete classifier or universal procedure for deciding all possible mixed claims. Calling it the obligation to examine rather than the successful support condition would overstate the correspondence. No Core 0.1.3 all-facet obligation is introduced.", + "special_limits": [] + }, + { + "target": "T09", + "case": "articulable_unsupported", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.articulationNotSupport", + "file": "CoreReader/Evidence.lean", + "line": 325, + "axioms": "[propext]" + } + ], + "interpretation": "Grounds012 formalizes successful supported grounds for one declared task using same claim/articulation/discharge and task-appropriateness. Local/global and stronger-claim countermodels preserve force and scope. It is not a complete classifier or universal procedure for deciding all possible mixed claims. Calling it the obligation to examine rather than the successful support condition would overstate the correspondence. No Core 0.1.3 all-facet obligation is introduced.", + "special_limits": [] + }, + { + "target": "T09", + "case": "scope_overreach", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.scopeStrength012", + "file": "CoreReader/Adopted.lean", + "line": 286, + "axioms": "[propext]" + } + ], + "interpretation": "Grounds012 formalizes successful supported grounds for one declared task using same claim/articulation/discharge and task-appropriateness. Local/global and stronger-claim countermodels preserve force and scope. It is not a complete classifier or universal procedure for deciding all possible mixed claims. Calling it the obligation to examine rather than the successful support condition would overstate the correspondence. No Core 0.1.3 all-facet obligation is introduced.", + "special_limits": [] + }, + { + "target": "T09", + "case": "strength_overreach", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.scopeStrength012", + "file": "CoreReader/Adopted.lean", + "line": 286, + "axioms": "[propext]" + } + ], + "interpretation": "Grounds012 formalizes successful supported grounds for one declared task using same claim/articulation/discharge and task-appropriateness. Local/global and stronger-claim countermodels preserve force and scope. It is not a complete classifier or universal procedure for deciding all possible mixed claims. Calling it the obligation to examine rather than the successful support condition would overstate the correspondence. No Core 0.1.3 all-facet obligation is introduced.", + "special_limits": [] + } + ] + }, + { + "id": "T10", + "kind": "specification", + "statement": "Empirical assessment examines observations, evidence and performance and their support conditions, scope and uncertainty; measurability/repeatability is no replacement for relevance, correctness or value assessment.", + "premises": [ + "Actual empirical content and relevant relation from observations to claim", + "measurement/repetition is evidence property, not automatic support", + "finite adapter remains limited." + ], + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "p2" + } + ], + "status": "accepted-bounded", + "prior_own_status": "bounded_success_specification", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "Empirical discharge includes an in-scope compatible witness, scoped support and uncertainty support. Repetition of irrelevant first-coordinate/action observations cannot establish the second coordinate or budget value. The successful uncertainty is the exhaustive Boolean disjunction, not a quantified confidence estimate or a production measurement.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Adopted.empiricalSpecification", + "file": "CoreReader/Adopted.lean", + "line": 152, + "end": 160, + "kind": "def", + "axioms": "[propext]", + "exact_code": "def empiricalSpecification {W : Type} (records : List (Record W))\n (scope claim uncertainty : Claim W) : Prop :=\n Grounds012 claim canonicalArticulation [.empirical records scope claim uncertainty]\n (.empirical records scope claim uncertainty)\n\n/-- organon-map CoreReader.Adopted.inferentialSpecification\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\n", + "full_type_record": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `records\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Record []) (Lean.Expr.bvar 0)))\n (Lean.Expr.forallE\n `scope\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.bvar 1))\n (Lean.Expr.forallE\n `claim\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.bvar 2))\n (Lean.Expr.forallE\n `uncertainty\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.bvar 3))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)", + "sha256": "9f534ab1f51da3b82f8edf1d35b0dfab34dfe042d10c44582f04b4dce6569ef2" + }, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Adopted.empiricalCases012", + "file": "CoreReader/Adopted.lean", + "line": 1082, + "end": 1113, + "kind": "theorem", + "axioms": "[propext]", + "exact_code": "theorem empiricalCases012 :\n (Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧\n Articulated (canonicalArticulation globalFacet012) ∧\n ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧\n ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012)) ∧\n (temperatureRecord.test (true,false) = true ∧\n Compatible [temperatureRecord,temperatureRecord] (true,false) ∧\n Compatible [temperatureRecord,temperatureRecord] (true,true) ∧\n ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧\n ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧\n Compatible [actionRecord,actionRecord] (true,0) ∧\n Compatible [actionRecord,actionRecord] (true,3) ∧\n ¬ Supports [actionRecord] announcementPosition.consequence ∧\n ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧\n ¬ ValueProcedure announcementPosition) ∧\n (empiricalSpecification [temperatureRecord, temperatureRecord] (fun _ => True)\n (fun w => w.1 = true) (fun w => w.2 = true ∨ w.2 = false) ∧\n Compatible [temperatureRecord, temperatureRecord] (true,true) ∧\n Compatible [temperatureRecord, temperatureRecord] (true,false)) ∧\n (Grounds012 (fun f => f 0 = true) canonicalArticulation [localFacet012] originalLocalTask012 ∧\n Grounds012 (fun f => f 0 = true) canonicalArticulation [observedInferenceFacet012] originalLocalTask012) ∧\n (FacetDischarged uncertaintyBypassFacet012 ∧\n ¬ NatureAppropriate originalUncertaintyTask012 uncertaintyBypassFacet012 ∧\n ¬ Grounds012 (fun w : Bool × Bool => w.1 = true) canonicalArticulation\n [uncertaintyBypassFacet012] originalUncertaintyTask012) :=\n ⟨scopeStrength012, measurementRepeatNotSupport, uncertainSupported012, sameEmpiricalTaskTwoMethods012, uncertaintySubstitutionRejected012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.inferentialCases012\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulated [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.globalFacet012 [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.claim [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.taskOfFacet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Adopted.strongFacet012 []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record.test [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 3)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.consequence [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.consequence [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.empiricalSpecification [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 577346429) \"_hygCtx\") \"_hyg\") 256)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `True [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.fst [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Or [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.false [])))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.bvar 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.localFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Adopted.originalLocalTask012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.bvar 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Adopted.observedInferenceFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Adopted.originalLocalTask012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.FacetDischarged [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero]) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.uncertaintyBypassFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.NatureAppropriate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.originalUncertaintyTask012 []))\n (Lean.Expr.const `CoreReader.Adopted.uncertaintyBypassFacet012 []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.fst [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Adopted.uncertaintyBypassFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))))\n (Lean.Expr.const `CoreReader.Adopted.originalUncertaintyTask012 []))))))))", + "sha256": "fba89ddcd1cf1f745deec2bbdb86e1434e01d6fc73f99c6bf690331560f736f6" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T10", + "case": "observed_relevant", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.localFacetChecked012", + "file": "CoreReader/Adopted.lean", + "line": 282, + "axioms": "[propext]" + } + ], + "interpretation": "Empirical discharge includes an in-scope compatible witness, scoped support and uncertainty support. Repetition of irrelevant first-coordinate/action observations cannot establish the second coordinate or budget value. The successful uncertainty is the exhaustive Boolean disjunction, not a quantified confidence estimate or a production measurement.", + "special_limits": [] + }, + { + "target": "T10", + "case": "repeatable_irrelevant", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.measurementRepeatNotSupport", + "file": "CoreReader/Evidence.lean", + "line": 394, + "axioms": "[propext]" + } + ], + "interpretation": "Empirical discharge includes an in-scope compatible witness, scoped support and uncertainty support. Repetition of irrelevant first-coordinate/action observations cannot establish the second coordinate or budget value. The successful uncertainty is the exhaustive Boolean disjunction, not a quantified confidence estimate or a production measurement.", + "special_limits": [] + }, + { + "target": "T10", + "case": "measured_wrong_scope", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.scopeStrength012", + "file": "CoreReader/Adopted.lean", + "line": 286, + "axioms": "[propext]" + } + ], + "interpretation": "Empirical discharge includes an in-scope compatible witness, scoped support and uncertainty support. Repetition of irrelevant first-coordinate/action observations cannot establish the second coordinate or budget value. The successful uncertainty is the exhaustive Boolean disjunction, not a quantified confidence estimate or a production measurement.", + "special_limits": [] + }, + { + "target": "T10", + "case": "uncertain_limited", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.uncertainSupported012", + "file": "CoreReader/Adopted.lean", + "line": 308, + "axioms": "[propext]" + } + ], + "interpretation": "Empirical discharge includes an in-scope compatible witness, scoped support and uncertainty support. Repetition of irrelevant first-coordinate/action observations cannot establish the second coordinate or budget value. The successful uncertainty is the exhaustive Boolean disjunction, not a quantified confidence estimate or a production measurement.", + "special_limits": [] + } + ] + }, + { + "id": "T11", + "kind": "specification", + "statement": "Inferential assessment examines whether conclusion follows/supports under stated assumptions and inferential relations; mere nonconflict cannot replace this examination.", + "premises": [ + "A concrete inference semantics and countervaluation when lack of entailment is claimed", + "distinguish task of examination from successful conclusion." + ], + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + } + ], + "status": "accepted-bounded", + "prior_own_status": "qualified_success_specification", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "The inferential wrapper requires satisfiable assumptions and actual entailment. Correct rejection of an unentailed conclusion is represented separately by InferenceExamined false and a countervaluation. Together they preserve the examination/success distinction, provided the wrapper alone is not described as the full act of assessment.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Adopted.inferentialSpecification", + "file": "CoreReader/Adopted.lean", + "line": 161, + "end": 167, + "kind": "def", + "axioms": "[propext]", + "exact_code": "def inferentialSpecification {W : Type} (assumptions : Theory W) (claim : Claim W) : Prop :=\n Grounds012 claim canonicalArticulation [.inferential assumptions claim] (.inferential assumptions claim)\n\n/-- organon-map CoreReader.Adopted.valueSpecification\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\n-/\n", + "full_type_record": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `assumptions\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Theory []) (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `claim\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.bvar 1))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)", + "sha256": "d56b013c37bfeb071f171cb3f552b8775a79eee535305a78d2d9551b86c03c16" + }, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Adopted.inferentialCases012", + "file": "CoreReader/Adopted.lean", + "line": 1114, + "end": 1130, + "kind": "theorem", + "axioms": "[propext]", + "exact_code": "theorem inferentialCases012 :\n (inferentialSpecification (singleton (fun n : Nat => n = 2)) (fun n => n + 1 = 3) ∧\n InferenceExamined (emptyTheory : Theory Bool) (fun w => w = true) false ∧\n Models (emptyTheory : Theory Bool) false ∧ ¬ ((fun w : Bool => w = true) false)) ∧\n (Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧\n ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧\n (FacetDischarged (Facet.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) ∧\n ¬ Grounds012 (fun w : Bool => w = true) canonicalArticulation\n [.inferential (singleton (fun w => w = true)) (fun w => w = true)]\n (.inferential emptyTheory (fun w => w = true))) :=\n ⟨inferenceChecked012, compatibilityNotEntailment, inferentialContextSubstitutionRejected012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.valueCases012\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.inferentialSpecification []) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Nat []))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.lam\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `HAdd.hAdd [Lean.Level.zero, Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `instHAdd [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instAddNat [])))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.InferenceExamined []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Models []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))\n (Lean.Expr.const `Bool.false [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.union []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.FacetDischarged []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet.inferential []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.Grounds012 []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.inferential [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.AssessmentTask.inferential [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.lam\n `w\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))))", + "sha256": "b37768f2ff32da55daf97b29dc027bfa78aa1a1f2456c80937dde7aa64a5c515" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T11", + "case": "valid_inference", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.inferenceChecked012", + "file": "CoreReader/Adopted.lean", + "line": 323, + "axioms": "[propext]" + } + ], + "interpretation": "The inferential wrapper requires satisfiable assumptions and actual entailment. Correct rejection of an unentailed conclusion is represented separately by InferenceExamined false and a countervaluation. Together they preserve the examination/success distinction, provided the wrapper alone is not described as the full act of assessment.", + "special_limits": [] + }, + { + "target": "T11", + "case": "compatible_unentailed", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Logic.compatibilityNotEntailment", + "file": "CoreReader/Logic.lean", + "line": 180, + "axioms": "[]" + } + ], + "interpretation": "The inferential wrapper requires satisfiable assumptions and actual entailment. Correct rejection of an unentailed conclusion is represented separately by InferenceExamined false and a countervaluation. Together they preserve the examination/success distinction, provided the wrapper alone is not described as the full act of assessment.", + "special_limits": [] + }, + { + "target": "T11", + "case": "false_inference_detected", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.inferenceChecked012", + "file": "CoreReader/Adopted.lean", + "line": 323, + "axioms": "[propext]" + } + ], + "interpretation": "The inferential wrapper requires satisfiable assumptions and actual entailment. Correct rejection of an unentailed conclusion is represented separately by InferenceExamined false and a countervaluation. Together they preserve the examination/success distinction, provided the wrapper alone is not described as the full act of assessment.", + "special_limits": [] + } + ] + }, + { + "id": "T12", + "kind": "specification", + "statement": "Value commitments identify position, reasons, applicability limits and consequences and stay open to relevant criticism; neither empirical/necessary-inference presentation nor self-assertion substitutes. Initial commitments need not prove all starting assumptions.", + "premises": [ + "Stated value stance distinct from factual claims", + "reason interface without recursive proof demand", + "relevant criticism condition", + "qualitative support comparisons allowed." + ], + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + } + ], + "status": "accepted-bounded", + "prior_own_status": "qualified_value_procedure", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "The value construction identifies position, joint reasons, application limits, consequences and relevant criticism responses. It assumes starting claims and supplies a joint witness instead of proving every starting assumption. The universal consequence test and response nonemptiness are this application's sufficient procedure, not newly mandatory philosophical proof requirements or proof of response adequacy.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Adopted.valueSpecification", + "file": "CoreReader/Adopted.lean", + "line": 168, + "end": 173, + "kind": "def", + "axioms": "[propext]", + "exact_code": "def valueSpecification {W : Type} (position : ValuePosition W) : Prop :=\n Grounds012 position.commitment canonicalArticulation [.value position] (.value position)\n\n/- Scope and roles are explicitly identified relative to a claim. An actually\nused method needs an explanation; unused methods are not required. The input\nrelation can encode contextual relevance without a universal numeric scale. -/\n", + "full_type_record": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `position\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.ValuePosition []) (Lean.Expr.bvar 0))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)", + "sha256": "1f45a163b8b2a0db44eeaeb0910e0af6168e4674ab3a3925dcfe54e3015e3ae6" + }, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Adopted.valueCases012", + "file": "CoreReader/Adopted.lean", + "line": 1131, + "end": 1151, + "kind": "theorem", + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "exact_code": "theorem valueCases012 :\n (valueSpecification switchPosition) ∧\n (announcementPosition.reasons ≠ [] ∧ announcementPosition.commitment (true,0) ∧\n (∀ reason, reason ∈ announcementPosition.reasons → reason (true,0) announcementPosition.adopted) ∧\n ¬ announcementPosition.consequence (true,0) ∧ ¬ ValueProcedure announcementPosition) ∧\n (¬ ValueProcedure closedPosition012) ∧\n (ValueProcedure switchPosition ∧\n Satisfiable switchPosition.starting ∧\n ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧\n (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧\n (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition)) ∧\n (FacetDischarged selectedFactFacet012 ∧ valueSpecification switchPosition ∧\n ¬ Grounds012 switchPosition.commitment canonicalArticulation [selectedFactFacet012] (.value switchPosition)) :=\n ⟨valueFulfilled012, announcementNotBudgetReason, closedCriticism012, valueWithoutSelfProof, valueFactSubstitutionRejected012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.groundsLimits012\norganon.grounds.assessment#p1 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.valueSpecification []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.reasons [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `reason\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.Position [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.reasons [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.bvar 1)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.adopted [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.consequence [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.ValueProcedure []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.closedPosition012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.ValueProcedure []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.starting [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.JointAdoption [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.oppositePosition [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.oppositePosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.contradictoryStartingPosition []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.impossibleAdoptionPosition [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.FacetDischarged []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.selectedFactFacet012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.valueSpecification []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.Grounds012 []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.selectedFactFacet012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Facet []) (Lean.Expr.const `Bool [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.AssessmentTask.value [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))))))))", + "sha256": "ce1dba18fb8bf4611fe703b21270e3b59591f6f1cf1c40f2ee03899fa26c142a" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T12", + "case": "reasoned_value", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.valueFulfilled012", + "file": "CoreReader/Adopted.lean", + "line": 341, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "The value construction identifies position, joint reasons, application limits, consequences and relevant criticism responses. It assumes starting claims and supplies a joint witness instead of proving every starting assumption. The universal consequence test and response nonemptiness are this application's sufficient procedure, not newly mandatory philosophical proof requirements or proof of response adequacy.", + "special_limits": [] + }, + { + "target": "T12", + "case": "unsupported_self_assertion", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.announcementNotBudgetReason", + "file": "CoreReader/Evidence.lean", + "line": 372, + "axioms": "[propext]" + } + ], + "interpretation": "The value construction identifies position, joint reasons, application limits, consequences and relevant criticism responses. It assumes starting claims and supplies a joint witness instead of proving every starting assumption. The universal consequence test and response nonemptiness are this application's sufficient procedure, not newly mandatory philosophical proof requirements or proof of response adequacy.", + "special_limits": [] + }, + { + "target": "T12", + "case": "closed_criticism", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.closedCriticism012", + "file": "CoreReader/Adopted.lean", + "line": 336, + "axioms": "[]" + } + ], + "interpretation": "The value construction identifies position, joint reasons, application limits, consequences and relevant criticism responses. It assumes starting claims and supplies a joint witness instead of proving every starting assumption. The universal consequence test and response nonemptiness are this application's sufficient procedure, not newly mandatory philosophical proof requirements or proof of response adequacy.", + "special_limits": [] + }, + { + "target": "T12", + "case": "explicit_initial_commitment", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.valueWithoutSelfProof", + "file": "CoreReader/Evidence.lean", + "line": 426, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "The value construction identifies position, joint reasons, application limits, consequences and relevant criticism responses. It assumes starting claims and supplies a joint witness instead of proving every starting assumption. The universal consequence test and response nonemptiness are this application's sufficient procedure, not newly mandatory philosophical proof requirements or proof of response adequacy.", + "special_limits": [] + } + ] + }, + { + "id": "T13", + "kind": "nonentailment", + "statement": "Articulability alone does not establish grounds; measurable/repeatable observations alone establish neither relevance, correctness nor value; a stated value commitment need not be empirical fact or necessary consequence, nor prove all its starting assumptions.", + "premises": [ + "Concrete inadequacy criterion for each countercase", + "avoid defining insufficient support as missing record only", + "empirical/inferential/value readings not made exhaustive or exclusive." + ], + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + } + ], + "status": "accepted-bounded", + "prior_own_status": "bounded_countermodels", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "Clearly articulated false assumptions, repeated wrong-object observations, neutral records compatible with nonadoption, and the ordinary value example show the intended non-substitutions. Qualitative implication orders claim strength without imposing a numerical scale.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Adopted.groundsLimits012", + "file": "CoreReader/Adopted.lean", + "line": 1152, + "end": 1183, + "kind": "theorem", + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "exact_code": "theorem groundsLimits012 :\n (Articulated clearFalseArgument012 ∧ ¬ Models clearFalseArgument012.assumptions false) ∧\n (temperatureRecord.test (true,false) = true ∧\n Compatible [temperatureRecord,temperatureRecord] (true,false) ∧\n Compatible [temperatureRecord,temperatureRecord] (true,true) ∧\n ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧\n ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧\n Compatible [actionRecord,actionRecord] (true,0) ∧\n Compatible [actionRecord,actionRecord] (true,3) ∧\n ¬ Supports [actionRecord] announcementPosition.consequence ∧\n ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧\n ¬ ValueProcedure announcementPosition) ∧\n (valueSpecification switchPosition ∧\n Compatible [valueNeutralRecord012] false ∧\n ¬ Supports [valueNeutralRecord012] switchPosition.commitment ∧\n ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment) ∧\n (ValueProcedure switchPosition ∧\n Satisfiable switchPosition.starting ∧\n ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧\n (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧\n (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition)) ∧\n (ClaimNoStronger (fun f : Nat → Bool => f 0 = true) allTrue ∧\n ¬ ClaimNoStronger allTrue (fun f : Nat → Bool => f 0 = true) ∧\n valueSpecification switchPosition) :=\n ⟨clearFalseReason012, measurementRepeatNotSupport, valueNotFact012, valueWithoutSelfProof, qualitativeProportionality012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.scopeCases012\norganon.grounds.scope#p1 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.scope#p2 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.scope#p3 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Articulated []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.clearFalseArgument012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Models []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulation.assumptions [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Adopted.clearFalseArgument012 [])))\n (Lean.Expr.const `Bool.false [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record.test [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))))\n (Lean.Expr.const `CoreReader.Evidence.temperatureRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool [])))))))\n (Lean.Expr.lam\n `w\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 3)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.consequence [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld [])))\n (Lean.Expr.const `CoreReader.Evidence.actionRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.consequence [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `CoreReader.Evidence.BudgetWorld []))\n (Lean.Expr.const `CoreReader.Evidence.announcementPosition [])))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.valueSpecification []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Compatible []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Record []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.valueNeutralRecord012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Record []) (Lean.Expr.const `Bool [])))))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Supports []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Record []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.const `CoreReader.Adopted.valueNeutralRecord012 []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Record []) (Lean.Expr.const `Bool [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.ValueProcedure []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Satisfiable []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.starting [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Entails []) (Lean.Expr.const `Bool []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.emptyTheory []) (Lean.Expr.const `Bool [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.JointAdoption [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.oppositePosition [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.oppositePosition [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.contradictoryStartingPosition []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValueProcedure [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.impossibleAdoptionPosition [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ClaimNoStronger [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.bvar 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.ClaimNoStronger [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.const `CoreReader.Evidence.allTrue []))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.bvar 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.valueSpecification []) (Lean.Expr.const `Bool []))\n (Lean.Expr.const `CoreReader.Evidence.switchPosition [])))))))", + "sha256": "b404dce33c3fbf86c65d3824e2fceaf5f0a1f312ce1edc1f0a9e9251af9ccad3" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T13", + "case": "clear_false_reason", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.clearFalseReason012", + "file": "CoreReader/Adopted.lean", + "line": 637, + "axioms": "[propext]" + } + ], + "interpretation": "Clearly articulated false assumptions, repeated wrong-object observations, neutral records compatible with nonadoption, and the ordinary value example show the intended non-substitutions. Qualitative implication orders claim strength without imposing a numerical scale.", + "special_limits": [] + }, + { + "target": "T13", + "case": "repeatable_wrong_object", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.measurementRepeatNotSupport", + "file": "CoreReader/Evidence.lean", + "line": 394, + "axioms": "[propext]" + } + ], + "interpretation": "Clearly articulated false assumptions, repeated wrong-object observations, neutral records compatible with nonadoption, and the ordinary value example show the intended non-substitutions. Qualitative implication orders claim strength without imposing a numerical scale.", + "special_limits": [] + }, + { + "target": "T13", + "case": "value_not_fact", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.valueNotFact012", + "file": "CoreReader/Adopted.lean", + "line": 643, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Clearly articulated false assumptions, repeated wrong-object observations, neutral records compatible with nonadoption, and the ordinary value example show the intended non-substitutions. Qualitative implication orders claim strength without imposing a numerical scale.", + "special_limits": [] + }, + { + "target": "T13", + "case": "initial_value_without_selfproof", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.valueWithoutSelfProof", + "file": "CoreReader/Evidence.lean", + "line": 426, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Clearly articulated false assumptions, repeated wrong-object observations, neutral records compatible with nonadoption, and the ordinary value example show the intended non-substitutions. Qualitative implication orders claim strength without imposing a numerical scale.", + "special_limits": [] + }, + { + "target": "T13", + "case": "qualitative_proportionality", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.qualitativeProportionality012", + "file": "CoreReader/Adopted.lean", + "line": 348, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Clearly articulated false assumptions, repeated wrong-object observations, neutral records compatible with nonadoption, and the ordinary value example show the intended non-substitutions. Qualitative implication orders claim strength without imposing a numerical scale.", + "special_limits": [] + } + ] + }, + { + "id": "T14", + "kind": "specification", + "statement": "Performance/comparison judgments state relevant relations, conditions and observation scope; scope omission cannot establish absence of relevant differences; roles of measurement, repetition and framework are explained relative to claim/context.", + "premises": [ + "Local and broader scopes and relevance relation distinct", + "explanation of actually used method does not require all three methods universally." + ], + "sources": [ + { + "unit": "organon.grounds.scope", + "clause": "p1" + }, + { + "unit": "organon.grounds.scope", + "clause": "p2" + }, + { + "unit": "organon.grounds.scope", + "clause": "p3" + } + ], + "status": "accepted-bounded", + "prior_own_status": "qualified_scope_specification", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "The local scope account binds comparison pairs, conditions, observed scope, relevance and each method explanation to the same claim. Its concrete method meanings prove local/repeated support and failure of global support. The generic explains relation remains supplied and the interface does not force every method to be used.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Adopted.scopeSpecification", + "file": "CoreReader/Adopted.lean", + "line": 191, + "end": 204, + "kind": "def", + "axioms": "[]", + "exact_code": "def scopeSpecification {W : Type} (account : ScopeAccount W) : Prop :=\n (∀ a b, account.compared a b → account.conditions a ∧ account.conditions b ∧\n account.observationScope a ∧ account.observationScope b ∧ account.relevant a b) ∧\n ∀ method, account.used method → account.role method ≠ \"\" ∧\n account.explains method (account.role method) account.claim account.conditions\n\n/- A capability is selected by the application as an exact object-scoped\ncontract; whether explanation is part of it remains an application choice. -/\n/-- organon-map CoreReader.Adopted.capabilitySpecification\norganon.grounds.capabilities#p1 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0\norganon.grounds.capabilities#p2 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\n", + "full_type_record": { + "type": "Lean.Expr.forallE\n `W\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `account\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.ScopeAccount []) (Lean.Expr.bvar 0))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)", + "sha256": "01857cd86d39ca8bc2d54d15555ebed9fc9fa6a0bd40196743e5f1fbbcb966b7" + }, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Adopted.scopeCases012", + "file": "CoreReader/Adopted.lean", + "line": 1184, + "end": 1196, + "kind": "theorem", + "axioms": "[propext]", + "exact_code": "theorem scopeCases012 :\n (scopeSpecification localScopeAccount012) ∧\n ((∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧\n (fun _ : Nat => true) 1 ≠ localGenerator 0 1) :=\n ⟨scopeFulfilled012, hiddenDifference⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.scopeLimits012\norganon.grounds.scope#p1 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.scope#p2 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.scope#p3 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Adopted.scopeSpecification []) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Adopted.localScopeAccount012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 3351349031) \"_hygCtx\") \"_hyg\") 37)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.bvar 1)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 3351349031) \"_hygCtx\") \"_hyg\") 54)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))", + "sha256": "e503dd4f8dacf02303b9bd7e56977a56feee218c1c677d8836c15039e83655a8" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T14", + "case": "local_scope_declared", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.scopeFulfilled012", + "file": "CoreReader/Adopted.lean", + "line": 379, + "axioms": "[propext]" + } + ], + "interpretation": "The local scope account binds comparison pairs, conditions, observed scope, relevance and each method explanation to the same claim. Its concrete method meanings prove local/repeated support and failure of global support. The generic explains relation remains supplied and the interface does not force every method to be used.", + "special_limits": [] + }, + { + "target": "T14", + "case": "omitted_relevant_difference", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.hiddenDifference", + "file": "CoreReader/Evidence.lean", + "line": 560, + "axioms": "[]" + } + ], + "interpretation": "The local scope account binds comparison pairs, conditions, observed scope, relevance and each method explanation to the same claim. Its concrete method meanings prove local/repeated support and failure of global support. The generic explains relation remains supplied and the interface does not force every method to be used.", + "special_limits": [] + }, + { + "target": "T14", + "case": "measurement_role", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.scopeFulfilled012", + "file": "CoreReader/Adopted.lean", + "line": 379, + "axioms": "[propext]" + } + ], + "interpretation": "The local scope account binds comparison pairs, conditions, observed scope, relevance and each method explanation to the same claim. Its concrete method meanings prove local/repeated support and failure of global support. The generic explains relation remains supplied and the interface does not force every method to be used.", + "special_limits": [] + }, + { + "target": "T14", + "case": "repetition_role", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.scopeFulfilled012", + "file": "CoreReader/Adopted.lean", + "line": 379, + "axioms": "[propext]" + } + ], + "interpretation": "The local scope account binds comparison pairs, conditions, observed scope, relevance and each method explanation to the same claim. Its concrete method meanings prove local/repeated support and failure of global support. The generic explains relation remains supplied and the interface does not force every method to be used.", + "special_limits": [] + }, + { + "target": "T14", + "case": "framework_role", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.scopeFulfilled012", + "file": "CoreReader/Adopted.lean", + "line": 379, + "axioms": "[propext]" + } + ], + "interpretation": "The local scope account binds comparison pairs, conditions, observed scope, relevance and each method explanation to the same claim. Its concrete method meanings prove local/repeated support and failure of global support. The generic explains relation remains supplied and the interface does not force every method to be used.", + "special_limits": [] + } + ] + }, + { + "id": "T15", + "kind": "nonentailment", + "statement": "Local equal performance does not entail global equivalence/unconditional universality; omitting a difference does not establish its nonexistence. Limited unreproduced support and variable random outcomes are possible without a universal measurement→repeatability→framework chain.", + "premises": [ + "Explicit nonempty local and broader domains, shared observations and relation", + "verifiability, reproducible conditions and stable conclusions modeled separately", + "unreproduced is not necessarily irreproducible." + ], + "sources": [ + { + "unit": "organon.grounds.scope", + "clause": "p1" + }, + { + "unit": "organon.grounds.scope", + "clause": "p2" + }, + { + "unit": "organon.grounds.scope", + "clause": "p3" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "p1" + } + ], + "status": "accepted-bounded", + "prior_own_status": "bounded_countermodels", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "Explicit functions agree only at zero and differ at one; one observation supplies local support. Trial fields separate recorded accuracy, equal settings and bounded output, and Boolean draws have equal positive weights with different outcomes. This is a finite possible-outcome model, not verification of a real stochastic process.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Adopted.scopeLimits012", + "file": "CoreReader/Adopted.lean", + "line": 1197, + "end": 1231, + "kind": "theorem", + "axioms": "[propext, Quot.sound.{u}]", + "exact_code": "theorem scopeLimits012 :\n ((∃ outside : Nat, outside ≠ 0) ∧\n Compatible [zeroRecord] (fun _ => true) ∧\n Compatible [zeroRecord] (localGenerator 0) ∧\n allTrue (fun _ => true) ∧ ¬ allTrue (localGenerator 0) ∧\n ¬ Supports [zeroRecord] allTrue) ∧\n ((∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧\n (fun _ : Nat => true) 1 ≠ localGenerator 0 1) ∧\n ([zeroRecord].length = 1 ∧\n (∃ f, Compatible [zeroRecord] f) ∧\n Supports [zeroRecord] (fun f => f 0 = true) ∧\n ¬ Supports [zeroRecord] allTrue) ∧\n (let a : Trial := ⟨0,1,1⟩\n let b : Trial := ⟨0,2,2⟩\n Reproduced a b ∧ a.actualOutcome ≠ b.actualOutcome ∧ Bounded a ∧ Bounded b) ∧\n ((Verified ⟨0,1,1⟩ ∧ Verified ⟨1,1,1⟩ ∧ ¬ Reproduced ⟨0,1,1⟩ ⟨1,1,1⟩) ∧\n (Reproduced ⟨0,1,1⟩ ⟨0,3,2⟩ ∧ ¬ Verified ⟨0,3,2⟩ ∧ ¬ Bounded ⟨0,3,2⟩) ∧\n (Bounded ⟨0,1,1⟩ ∧ Bounded ⟨0,2,0⟩ ∧ ¬ Verified ⟨0,2,0⟩)) ∧\n (FacetDischarged arithmeticFacet ∧ usesObservation arithmeticFacet = false) ∧\n (inferentialSpecification (singleton (fun on : Bool => on = true)) (fun on => on ≠ false) ∧\n usesObservation (Facet.inferential (singleton (fun on : Bool => on = true)) (fun on => on ≠ false)) = false) ∧\n (drawWeight012 true > 0 ∧ drawWeight012 false > 0 ∧\n drawWeight012 true = drawWeight012 false ∧\n Reproduced (randomTrial012 true) (randomTrial012 false) ∧\n (randomTrial012 true).actualOutcome ≠ (randomTrial012 false).actualOutcome ∧\n (∀ draw, Verified (randomTrial012 draw) ∧ Bounded (randomTrial012 draw))) :=\n ⟨localNotUniversal, hiddenDifference, singleObservation, variableOutcomesStableBound, verificationReproductionStability, noUniversalChain, qualitativeUnmeasured012, randomOutcomes012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.capabilityCases012\norganon.grounds.capabilities#p1 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0\norganon.grounds.capabilities#p2 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lam\n `outside\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 27637535) \"_hygCtx\") \"_hyg\") 38)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 27637535) \"_hygCtx\") \"_hyg\") 62)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 27637535) \"_hygCtx\") \"_hyg\") 117)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.bvar 1)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.lam\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `x.«_@».CoreReader.Adopted 27637535) \"_hygCtx\") \"_hyg\") 134)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool.true [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.localGenerator [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Compatible [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.lam\n `f\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.bvar 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Supports [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `CoreReader.Evidence.zeroRecord []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Record [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `Nat [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))))))\n (Lean.Expr.const `CoreReader.Evidence.allTrue [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.letE\n `a\n (Lean.Expr.const `CoreReader.Evidence.Trial [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.letE\n `b\n (Lean.Expr.const `CoreReader.Evidence.Trial [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Reproduced []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.actualOutcome [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Trial.actualOutcome []) (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Bounded []) (Lean.Expr.bvar 1)))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.Bounded []) (Lean.Expr.bvar 0)))))\n true)\n true))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Verified [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Verified [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Reproduced [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Reproduced [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Verified [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2))))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Bounded [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Bounded [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Bounded [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Verified [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Evidence.FacetDischarged []) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Evidence.arithmeticFacet [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.usesObservation [])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Evidence.arithmeticFacet [])))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.inferentialSpecification [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.singleton []) (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `on\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.lam\n `on\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.false []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.usesObservation [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.inferential [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.singleton [])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.lam\n `on\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.true []))\n (Lean.BinderInfo.default))))\n (Lean.Expr.lam\n `on\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `Bool.false []))\n (Lean.BinderInfo.default)))))\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `GT.gt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.drawWeight012 [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `GT.gt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.drawWeight012 [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.drawWeight012 [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.drawWeight012 [])\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Reproduced [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.const `Bool.false []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.actualOutcome [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Trial.actualOutcome [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.const `Bool.false [])))))\n (Lean.Expr.forallE\n `draw\n (Lean.Expr.const `Bool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Verified [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Bounded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.randomTrial012 [])\n (Lean.Expr.bvar 0))))\n (Lean.BinderInfo.default)))))))))))))", + "sha256": "a286f42a08d68addaec58cb6b0b9656968db614439bd753425f3972b29d8125c" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T15", + "case": "equal_local_different_global", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.localNotUniversal", + "file": "CoreReader/Evidence.lean", + "line": 550, + "axioms": "[propext]" + } + ], + "interpretation": "Explicit functions agree only at zero and differ at one; one observation supplies local support. Trial fields separate recorded accuracy, equal settings and bounded output, and Boolean draws have equal positive weights with different outcomes. This is a finite possible-outcome model, not verification of a real stochastic process.", + "special_limits": [] + }, + { + "target": "T15", + "case": "excluded_difference", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.hiddenDifference", + "file": "CoreReader/Evidence.lean", + "line": 560, + "axioms": "[]" + } + ], + "interpretation": "Explicit functions agree only at zero and differ at one; one observation supplies local support. Trial fields separate recorded accuracy, equal settings and bounded output, and Boolean draws have equal positive weights with different outcomes. This is a finite possible-outcome model, not verification of a real stochastic process.", + "special_limits": [] + }, + { + "target": "T15", + "case": "one_observation_limited_support", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.singleObservation", + "file": "CoreReader/Evidence.lean", + "line": 566, + "axioms": "[propext]" + } + ], + "interpretation": "Explicit functions agree only at zero and differ at one; one observation supplies local support. Trial fields separate recorded accuracy, equal settings and bounded output, and Boolean draws have equal positive weights with different outcomes. This is a finite possible-outcome model, not verification of a real stochastic process.", + "special_limits": [] + }, + { + "target": "T15", + "case": "varying_random_outcomes", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.randomOutcomes012", + "file": "CoreReader/Adopted.lean", + "line": 744, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "Explicit functions agree only at zero and differ at one; one observation supplies local support. Trial fields separate recorded accuracy, equal settings and bounded output, and Boolean draws have equal positive weights with different outcomes. This is a finite possible-outcome model, not verification of a real stochastic process.", + "special_limits": [] + }, + { + "target": "T15", + "case": "qualitative_unmeasured_judgment", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.qualitativeUnmeasured012", + "file": "CoreReader/Adopted.lean", + "line": 724, + "axioms": "[propext]" + } + ], + "interpretation": "Explicit functions agree only at zero and differ at one; one observation supplies local support. Trial fields separate recorded accuracy, equal settings and bounded output, and Boolean draws have equal positive weights with different outcomes. This is a finite possible-outcome model, not verification of a real stochastic process.", + "special_limits": [] + } + ] + }, + { + "id": "T16", + "kind": "specification", + "statement": "Capability claim identifies capability, conditions and support under Grounds; applications choose relevant capability definitions and may require understanding/explanation/variation. External assessors may provide grounds; own-system claims receive same relevant duties.", + "premises": [ + "Claim-indexed capability, externally supplied support and actual scope", + "no universal capability levels or introspective requirement." + ], + "sources": [ + { + "unit": "organon.grounds.capabilities", + "clause": "p1" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + } + ], + "status": "accepted-bounded", + "prior_own_status": "partial_case_correspondence", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "Resolved for the explicitly declared application capability UnderstandingApplication012: the same explained doubling process must also answer all multiplier/input variations using the actual multiplication mechanism. Identical output and ExplanationContract no longer suffice: the fixed-double answer gives 2 instead of 3 at multiplier=3,input=1, while mechanismResponder answers the declared variations and receives same-object Grounds. This is an operational understanding/variation-answer capability selected by the application, not a cognitive definition or universal standard of understanding.", + "reuse": "Source/target text and unchanged nonblank definitions reused; affected transitive composition was rereviewed.", + "declarations": [ + { + "name": "CoreReader.Adopted.capabilitySpecification", + "file": "CoreReader/Adopted.lean", + "line": 205, + "end": 214, + "kind": "def", + "axioms": "[propext]", + "exact_code": "def capabilitySpecification (assessed : Process) (contract : Claim Process) : Prop :=\n Grounds012 contract canonicalArticulation [processContractFacet assessed contract]\n (.inferential (processScope assessed) contract)\n\n/-- organon-map CoreReader.Adopted.choiceSpecification\norganon.grounds.implementations#p1 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c\norganon.grounds.implementations#p2 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c\norganon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\n", + "full_type_record": { + "type": "Lean.Expr.forallE\n `assessed\n (Lean.Expr.const `CoreReader.Evidence.Process [])\n (Lean.Expr.forallE\n `contract\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Logic.Claim []) (Lean.Expr.const `CoreReader.Evidence.Process []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "908a244789ebae715ab94703060109000c2369e1c4735c6cdb48a096243f3c04" + }, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Adopted.capabilityCases012", + "file": "CoreReader/Adopted.lean", + "line": 1232, + "end": 1253, + "kind": "theorem", + "axioms": "[propext]", + "exact_code": "theorem capabilityCases012 :\n (capabilitySpecification outputOnlyProcess OutputContract ∧\n capabilitySpecification explainedProcess FullProcessContract ∧\n (∃ certificate : ExternalCertificate outputOnlyProcess,\n certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧\n ¬ ExplanationContract outputOnlyProcess) ∧\n (OwnCapability012 7 7 outputOnlyProcess OutputContract) ∧\n (explainedWithoutVariation012.process = mechanismResponder012.process ∧\n FullProcessContract explainedWithoutVariation012.process ∧\n ¬ UnderstandingApplication012 explainedWithoutVariation012 ∧\n UnderstandingApplication012 mechanismResponder012 ∧\n Grounds012 UnderstandingApplication012 canonicalArticulation\n [understandingFacet012 mechanismResponder012] (understandingTask012 mechanismResponder012) ∧\n ¬ Grounds012 UnderstandingApplication012 canonicalArticulation\n [understandingFacet012 explainedWithoutVariation012] (understandingTask012 explainedWithoutVariation012)) :=\n ⟨capabilityFulfilled012, ownCapability012, understandingApplicationCases012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.capabilityLimits012\norganon.grounds.capabilities#p1 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0\norganon.grounds.capabilities#p2 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.const `CoreReader.Evidence.explainedProcess []))\n (Lean.Expr.const `CoreReader.Evidence.FullProcessContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))\n (Lean.Expr.lam\n `certificate\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate.assessorId [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate.assessedId [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExplanationContract [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.OwnCapability012 [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 7)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 7)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 7)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 7)))))\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Evidence.Process []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012.process [])\n (Lean.Expr.const `CoreReader.Adopted.explainedWithoutVariation012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012.process [])\n (Lean.Expr.const `CoreReader.Adopted.mechanismResponder012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.FullProcessContract [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012.process [])\n (Lean.Expr.const `CoreReader.Adopted.explainedWithoutVariation012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.UnderstandingApplication012 [])\n (Lean.Expr.const `CoreReader.Adopted.explainedWithoutVariation012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.UnderstandingApplication012 [])\n (Lean.Expr.const `CoreReader.Adopted.mechanismResponder012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 []))\n (Lean.Expr.const `CoreReader.Adopted.UnderstandingApplication012 []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.understandingFacet012 [])\n (Lean.Expr.const `CoreReader.Adopted.mechanismResponder012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.understandingTask012 [])\n (Lean.Expr.const `CoreReader.Adopted.mechanismResponder012 []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 []))\n (Lean.Expr.const `CoreReader.Adopted.UnderstandingApplication012 []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.understandingFacet012 [])\n (Lean.Expr.const `CoreReader.Adopted.explainedWithoutVariation012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.understandingTask012 [])\n (Lean.Expr.const `CoreReader.Adopted.explainedWithoutVariation012 []))))))))))", + "sha256": "71d33f0d4ef4ccd7b59de8cf61f1e8aa0edae58f02813c4f4f3d79754d592d03" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T16", + "case": "external_output_capability", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.capabilityFulfilled012", + "file": "CoreReader/Adopted.lean", + "line": 391, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved for the explicitly declared application capability UnderstandingApplication012: the same explained doubling process must also answer all multiplier/input variations using the actual multiplication mechanism. Identical output and ExplanationContract no longer suffice: the fixed-double answer gives 2 instead of 3 at multiplier=3,input=1, while mechanismResponder answers the declared variations and receives same-object Grounds. This is an operational understanding/variation-answer capability selected by the application, not a cognitive definition or universal standard of understanding.", + "special_limits": [] + }, + { + "target": "T16", + "case": "application_requires_understanding", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.understandingApplicationCases012", + "file": "CoreReader/Adopted.lean", + "line": 447, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved for the explicitly declared application capability UnderstandingApplication012: the same explained doubling process must also answer all multiplier/input variations using the actual multiplication mechanism. Identical output and ExplanationContract no longer suffice: the fixed-double answer gives 2 instead of 3 at multiplier=3,input=1, while mechanismResponder answers the declared variations and receives same-object Grounds. This is an operational understanding/variation-answer capability selected by the application, not a cognitive definition or universal standard of understanding.", + "special_limits": [ + "Application-defined all-multiplier variation-answer criterion; not an unrestricted cognitive claim.", + "Positive result uses the mechanism function; negative result fixes same Process and ExplanationContract but fails at (3,1)." + ] + }, + { + "target": "T16", + "case": "own_capability_assessment", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.ownCapability012", + "file": "CoreReader/Adopted.lean", + "line": 474, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved for the explicitly declared application capability UnderstandingApplication012: the same explained doubling process must also answer all multiplier/input variations using the actual multiplication mechanism. Identical output and ExplanationContract no longer suffice: the fixed-double answer gives 2 instead of 3 at multiplier=3,input=1, while mechanismResponder answers the declared variations and receives same-object Grounds. This is an operational understanding/variation-answer capability selected by the application, not a cognitive definition or universal standard of understanding.", + "special_limits": [] + } + ] + }, + { + "id": "T17", + "kind": "nonentailment", + "statement": "Reliable output or artifact/document/tool/term count alone does not establish internal-process understanding or stronger capability; articulable external grounds do not imply that assessed system understands/explains generation.", + "premises": [ + "Concrete task success and independent understanding criterion", + "external reasons not silently attributed to internal subject", + "scope escalation displayed." + ], + "sources": [ + { + "unit": "organon.grounds.capabilities", + "clause": "p1" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p2" + } + ], + "status": "accepted-bounded", + "prior_own_status": "bounded_countermodels", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "Reliable double output with explanation = none refutes the stronger declared explanation contract; repeated item counts do not add an unavailable operation. This establishes limits on the represented output/explanation capability, not a cognitive account of human or agent understanding.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Adopted.capabilityLimits012", + "file": "CoreReader/Adopted.lean", + "line": 1254, + "end": 1294, + "kind": "theorem", + "axioms": "[propext, Quot.sound.{u}]", + "exact_code": "theorem capabilityLimits012 :\n (capabilitySpecification outputOnlyProcess OutputContract ∧\n capabilitySpecification explainedProcess FullProcessContract ∧\n (∃ certificate : ExternalCertificate outputOnlyProcess,\n certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧\n ¬ ExplanationContract outputOnlyProcess) ∧\n (∀ kind : InventoryKind,\n Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .copy ∧\n ¬ Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .successor) ∧\n (Generative generatingSystem.policy ∧\n generatingSystem.policy.permitsVersion 0 0 ∧\n ¬ Expanded generatingSystem.current inflatedState ∧\n generatingSystem.current.inventory.length < inflatedState.inventory.length ∧\n generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧\n generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧\n generatingSystem.execute availableResources = some 6 ∧\n generatingSystem.execute { availableResources with experience := none } = none ∧\n generatingSystem.execute { availableResources with knowledge := none } = none ∧\n generatingSystem.execute { availableResources with collaborator := none } = none ∧\n generatingSystem.execute ⟨none, none, none⟩ = none ∧\n ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧\n generatingSystem.stableAction = generatingSystem.current ∧\n generatingSystem.requirementsMet generatingSystem.stableAction ∧\n generatingSystem.withinBudget generatingSystem.stableAction ∧\n ¬ generatingSystem.withinBudget inflatedState ∧\n StableReason generatingSystem.current inflatedState ∧\n (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧\n inflatedAnnouncement.owner = generatingSystem.owner ∧\n inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧\n inflatedAnnouncement.reportedNewOperation = .successor ∧\n inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧\n ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after)) :=\n ⟨capabilityFulfilled012, inventoryCases012, generationLimits⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.choiceCases012\norganon.grounds.implementations#p1 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c\norganon.grounds.implementations#p2 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c\norganon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.const `CoreReader.Evidence.explainedProcess []))\n (Lean.Expr.const `CoreReader.Evidence.FullProcessContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))\n (Lean.Expr.lam\n `certificate\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate.assessorId [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate.assessedId [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExplanationContract [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `kind\n (Lean.Expr.const `CoreReader.Agency.InventoryKind [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Available [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item [])))))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Available [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Agency.Item.mk []) (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Agency.Operation.copy [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item [])))))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor []))))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Generative [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Policy.permitsVersion [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.policy [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Item []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.inventory [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.abstractionLayers [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.State.vocabulary [])\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.availableResources [])))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Option.some [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 6)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 6)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3023016825) \"_hygCtx\") \"_hyg\") 160)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3023016825) \"_hygCtx\") \"_hyg\") 179)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.collaborator [])\n (Lean.Expr.bvar 0)))\n true)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Adopted 3023016825) \"_hygCtx\") \"_hyg\") 198)\n (Lean.Expr.const `CoreReader.Agency.ExternalResources [])\n (Lean.Expr.const `CoreReader.Agency.availableResources [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.experience [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.knowledge [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n true)))\n (Lean.Expr.app (Lean.Expr.const `Option.none [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `Option [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.execute [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.ExternalResources.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.requirementsMet [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.stableAction [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.withinBudget [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.StableReason [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Announcement []))\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.report [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))\n (Lean.Expr.const `CoreReader.Agency.inflatedState []))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.owner [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.owner [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.before [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.GeneratingSystem.current [])\n (Lean.Expr.const `CoreReader.Agency.generatingSystem []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.State []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.after [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.const `CoreReader.Agency.inflatedState [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Agency.Operation []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.reportedNewOperation\n [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.const `CoreReader.Agency.Operation.successor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.input [])\n (Lean.Expr.const `CoreReader.Agency.inflatedAnnouncement [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.expectedOutput\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.claim [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Expanded [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Agency.Announcement.before\n [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.Announcement.after [])\n (Lean.Expr.const\n `CoreReader.Agency.inflatedAnnouncement\n []))))))))))))))))))))))))))))))", + "sha256": "8efa4107232374dd4f308f0f4c19f39b706da292b2cb4042aba290ade3368d52" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T17", + "case": "reliable_opaque_generator", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.outputNotExplanation", + "file": "CoreReader/Evidence.lean", + "line": 684, + "axioms": "[propext]" + } + ], + "interpretation": "Reliable double output with explanation = none refutes the stronger declared explanation contract; repeated item counts do not add an unavailable operation. This establishes limits on the represented output/explanation capability, not a cognitive account of human or agent understanding.", + "special_limits": [] + }, + { + "target": "T17", + "case": "high_count_no_stronger_capability", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.inventoryCases012", + "file": "CoreReader/Adopted.lean", + "line": 667, + "axioms": "[propext, Quot.sound.{u}]" + }, + { + "name": "CoreReader.Agency.generationLimits", + "file": "CoreReader/Agency.lean", + "line": 194, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "Reliable double output with explanation = none refutes the stronger declared explanation contract; repeated item counts do not add an unavailable operation. This establishes limits on the represented output/explanation capability, not a cognitive account of human or agent understanding.", + "special_limits": [] + }, + { + "target": "T17", + "case": "externally_articulated_no_introspection", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.externalAssessment", + "file": "CoreReader/Evidence.lean", + "line": 704, + "axioms": "[propext]" + } + ], + "interpretation": "Reliable double output with explanation = none refutes the stronger declared explanation contract; repeated item counts do not add an unavailable operation. This establishes limits on the represented output/explanation capability, not a cognitive account of human or agent understanding.", + "special_limits": [] + } + ] + }, + { + "id": "T18", + "kind": "specification", + "statement": "Implementation priority needs reasons connected to objectives, values and relevant constraints; name/convention/status alone insufficient. Internal method explanation, applicability limits, simplicity/process requirements may count; conventional options may win on relevant grounds, including this philosophy's existing form.", + "premises": [ + "Reason relevance to particular choice", + "provenance alone distinct from practical familiarity/support", + "no rule that internal reasons are always decisive." + ], + "sources": [ + { + "unit": "organon.grounds.implementations", + "clause": "p1" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p2" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + } + ], + "status": "accepted-bounded", + "prior_own_status": "bounded_choice_specification", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "JustifiedChoice combines feasibility with a valued method-content reason; status-only reasons fail by definition as the additional adopted evaluative commitment. Conventional identity remains eligible, internal explanation/applicability/simplicity/procedure reasons are admissible, and the current philosophy review is assessed by actual output reasons. No optimality or all-reasons-valid theorem is claimed.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Adopted.choiceSpecification", + "file": "CoreReader/Adopted.lean", + "line": 215, + "end": 219, + "kind": "def", + "axioms": "[]", + "exact_code": "def choiceSpecification (requirements : Requirements) (implementation : Implementation)\n (reasons : List Reason) : Prop := JustifiedChoice requirements implementation reasons\n\n/- A collaborator supplies the successor operation. Removing that resource\nleaves the initial state; progress is tested on actual added operation content. -/\n", + "full_type_record": { + "type": "Lean.Expr.forallE\n `requirements\n (Lean.Expr.const `CoreReader.Choice.Requirements [])\n (Lean.Expr.forallE\n `implementation\n (Lean.Expr.const `CoreReader.Choice.Implementation [])\n (Lean.Expr.forallE\n `reasons\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "4b2ffafbf066633850901441a4978132cc3d84f95bef9c803f56a17866762054" + }, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Adopted.choiceCases012", + "file": "CoreReader/Adopted.lean", + "line": 1295, + "end": 1328, + "kind": "theorem", + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "exact_code": "theorem choiceCases012 :\n (identityImpl.conventional = true ∧ identityImpl.established = true ∧\n JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output]) ∧\n (Relevant identityRequirements identityImpl (.method .explanation) ∧\n Relevant identityRequirements identityImpl (.method .applicability) ∧\n Relevant identityRequirements identityImpl (.method .simplicity) ∧\n Relevant identityRequirements identityImpl (.method .procedure) ∧\n (Relevant identityRequirements cheapSuccessor (.method .simplicity) ∧\n ¬ JustifiedChoice identityRequirements cheapSuccessor [.method .simplicity])) ∧\n (Articulated priorityArticulation ∧ AssessmentAccurate false ∧\n (∀ selected, Models statusFacts selected) ∧\n priorityClaim .identity ∧ ¬ priorityClaim .successor ∧\n ¬ Entails statusFacts priorityClaim ∧\n ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧\n ((∀ n, identityImpl.run n = wrongExplanation012.run n) ∧\n Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧\n Relevant identityRequirements identityImpl (.method .explanation) ∧\n ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation)) ∧\n (¬ choiceSpecification CoreReader.Integration.proposalRequirements\n (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation\n [.status .standing] ∧\n choiceSpecification CoreReader.Integration.proposalRequirements\n (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation\n [.method .output]) ∧\n (∀ kind : StatusKind,\n ¬ choiceSpecification identityRequirements identityImpl [.status kind]) :=\n ⟨conventionWithReason, internalReasons, statusAssessmentNonEntailment, internalReasonDistinguishes012, ownPhilosophyStatus012, allStatusOnly012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.choiceLimits012\norganon.grounds.implementations#p1 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c\norganon.grounds.implementations#p2 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c\norganon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.conventional [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.established [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.status [])\n (Lean.Expr.const `CoreReader.Choice.StatusKind.convention [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.output [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.explanation []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.applicability []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.simplicity []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.procedure []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.cheapSuccessor []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.simplicity []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.cheapSuccessor []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.simplicity [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason [])))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulated [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.priorityArticulation [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.AssessmentAccurate [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `selected\n (Lean.Expr.const `CoreReader.Choice.Candidate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Models [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.statusFacts []))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.priorityClaim [])\n (Lean.Expr.const `CoreReader.Choice.Candidate.identity [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.priorityClaim [])\n (Lean.Expr.const `CoreReader.Choice.Candidate.successor []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Entails [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.statusFacts []))\n (Lean.Expr.const `CoreReader.Choice.priorityClaim []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.status [])\n (Lean.Expr.const `CoreReader.Choice.StatusKind.standing [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 []))\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Feasible [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Feasible [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.explanation []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.explanation [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.choiceSpecification [])\n (Lean.Expr.const `CoreReader.Integration.proposalRequirements []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Integration.PhilosophyMethod.implementation [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Integration.currentPhilosophy [])\n (Lean.Expr.const `CoreReader.Integration.actualSystem []))\n (Lean.Expr.const `CoreReader.Integration.actual []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.status [])\n (Lean.Expr.const `CoreReader.Choice.StatusKind.standing [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.choiceSpecification [])\n (Lean.Expr.const `CoreReader.Integration.proposalRequirements []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Integration.PhilosophyMethod.implementation [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Integration.currentPhilosophy [])\n (Lean.Expr.const `CoreReader.Integration.actualSystem []))\n (Lean.Expr.const `CoreReader.Integration.actual []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.output [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))\n (Lean.Expr.forallE\n `kind\n (Lean.Expr.const `CoreReader.Choice.StatusKind [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.choiceSpecification [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Choice.Reason.status []) (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason [])))))\n (Lean.BinderInfo.default))))))", + "sha256": "36f89bc4962aa87be316945afd3147dd30111dfdca8902a41b0392a2bda28c04" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T18", + "case": "named_only_rejected", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.allStatusOnly012", + "file": "CoreReader/Adopted.lean", + "line": 733, + "axioms": "[propext]" + } + ], + "interpretation": "JustifiedChoice combines feasibility with a valued method-content reason; status-only reasons fail by definition as the additional adopted evaluative commitment. Conventional identity remains eligible, internal explanation/applicability/simplicity/procedure reasons are admissible, and the current philosophy review is assessed by actual output reasons. No optimality or all-reasons-valid theorem is claimed.", + "special_limits": [] + }, + { + "target": "T18", + "case": "conventional_grounded_priority", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Choice.conventionWithReason", + "file": "CoreReader/Choice.lean", + "line": 108, + "axioms": "[propext]" + } + ], + "interpretation": "JustifiedChoice combines feasibility with a valued method-content reason; status-only reasons fail by definition as the additional adopted evaluative commitment. Conventional identity remains eligible, internal explanation/applicability/simplicity/procedure reasons are admissible, and the current philosophy review is assessed by actual output reasons. No optimality or all-reasons-valid theorem is claimed.", + "special_limits": [] + }, + { + "target": "T18", + "case": "method_internal_reason", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Choice.internalReasons", + "file": "CoreReader/Choice.lean", + "line": 151, + "axioms": "[]" + }, + { + "name": "CoreReader.Adopted.internalReasonDistinguishes012", + "file": "CoreReader/Adopted.lean", + "line": 657, + "axioms": "[]" + } + ], + "interpretation": "JustifiedChoice combines feasibility with a valued method-content reason; status-only reasons fail by definition as the additional adopted evaluative commitment. Conventional identity remains eligible, internal explanation/applicability/simplicity/procedure reasons are admissible, and the current philosophy review is assessed by actual output reasons. No optimality or all-reasons-valid theorem is claimed.", + "special_limits": [] + }, + { + "target": "T18", + "case": "own_philosophy_status_only", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.ownPhilosophyStatus012", + "file": "CoreReader/Adopted.lean", + "line": 690, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "JustifiedChoice combines feasibility with a valued method-content reason; status-only reasons fail by definition as the additional adopted evaluative commitment. Conventional identity remains eligible, internal explanation/applicability/simplicity/procedure reasons are admissible, and the current philosophy review is assessed by actual output reasons. No optimality or all-reasons-valid theorem is claimed.", + "special_limits": [] + } + ] + }, + { + "id": "T19", + "kind": "nonentailment", + "statement": "Openness neither makes alternatives equivalent nor ensures multiple feasible implementations, excludes conventional choices or excludes internal-method reasons. Local performance equality does not settle whole choice. The added choice priority rule is not inferred from the represented general requirement to assess reasons; this inherited limited assessment relation is distinct from the stronger domain nonentailment in T39.", + "premises": [ + "Concrete feasible option set and grounded comparison", + "at least one positive witness with a single feasible conventional option", + "distinct global consequences." + ], + "sources": [ + { + "unit": "organon.grounds.implementations", + "clause": "p1" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p2" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "p1" + } + ], + "status": "accepted-bounded", + "prior_own_status": "bounded_countermodels", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "A single feasible conventional choice, unequal outputs, equal local but different global behavior, and a distinguishing internal explanation meet the requested cases. The additional-choice example distinguishes accurate general assessment of non-entailment from the separate priority norm; this is deliberately the limited general-assessment relation in the target, not all Grounds duties.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Adopted.choiceLimits012", + "file": "CoreReader/Adopted.lean", + "line": 1329, + "end": 1350, + "kind": "theorem", + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "exact_code": "theorem choiceLimits012 :\n ((∀ candidate, Feasible identityRequirements (implementation candidate) ↔ candidate = .identity) ∧\n JustifiedChoice identityRequirements identityImpl objectiveReason) ∧\n (identityImpl.conventional = true ∧ identityImpl.established = true ∧\n JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output]) ∧\n ((∀ n, identityImpl.run n = wrongExplanation012.run n) ∧\n Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧\n Relevant identityRequirements identityImpl (.method .explanation) ∧\n ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation)) ∧\n (JustifiedChoice identityRequirements identityImpl objectiveReason ∧\n identityImpl.run 0 ≠ successorImpl.run 0) ∧\n ((∀ x, x = 0 → identityImpl.run x = changedOutsideZero.run x) ∧\n identityImpl.run 1 ≠ changedOutsideZero.run 1) ∧\n ((Articulated priorityArticulation ∧ AssessmentAccurate false ∧\n (∀ selected, Models statusFacts selected) ∧\n priorityClaim .identity ∧ ¬ priorityClaim .successor ∧\n ¬ Entails statusFacts priorityClaim ∧\n ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧\n PolicyIndependenceExample) :=\n ⟨singleFeasible, conventionWithReason, internalReasonDistinguishes012, openNotEquivalent, localNotGlobal, generalGroundsNotChoice⟩\n\nend CoreReader.Adopted\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `candidate\n (Lean.Expr.const `CoreReader.Choice.Candidate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Iff [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Feasible [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Choice.implementation []) (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Choice.Candidate.identity [])))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.const `CoreReader.Choice.objectiveReason []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.conventional [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.established [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.status [])\n (Lean.Expr.const `CoreReader.Choice.StatusKind.convention [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.output [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `n\n (Lean.Expr.const `Nat [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 []))\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Feasible [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Feasible [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.explanation []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Relevant [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Adopted.wrongExplanation012 []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.method [])\n (Lean.Expr.const `CoreReader.Choice.MethodReason.explanation [])))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.const `CoreReader.Choice.objectiveReason [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.successorImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `x\n (Lean.Expr.const `Nat [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.changedOutsideZero []))\n (Lean.Expr.bvar 1)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Implementation.run [])\n (Lean.Expr.const `CoreReader.Choice.changedOutsideZero []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Articulated [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.priorityArticulation [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.AssessmentAccurate [])\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `selected\n (Lean.Expr.const `CoreReader.Choice.Candidate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Models [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.statusFacts []))\n (Lean.Expr.bvar 0))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.priorityClaim [])\n (Lean.Expr.const `CoreReader.Choice.Candidate.identity [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.priorityClaim [])\n (Lean.Expr.const `CoreReader.Choice.Candidate.successor []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Entails [])\n (Lean.Expr.const `CoreReader.Choice.Candidate []))\n (Lean.Expr.const `CoreReader.Choice.statusFacts []))\n (Lean.Expr.const `CoreReader.Choice.priorityClaim []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.JustifiedChoice [])\n (Lean.Expr.const `CoreReader.Choice.identityRequirements []))\n (Lean.Expr.const `CoreReader.Choice.identityImpl []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Choice.Reason.status [])\n (Lean.Expr.const `CoreReader.Choice.StatusKind.standing [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Choice.Reason []))))))))))))\n (Lean.Expr.const `CoreReader.Choice.PolicyIndependenceExample []))))))", + "sha256": "84bdf70f43a217d10ccf0d7a8179aea2b586ab845a7c8f3a2f087089c6098874" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T19", + "case": "single_feasible_conventional", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Choice.singleFeasible", + "file": "CoreReader/Choice.lean", + "line": 121, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "A single feasible conventional choice, unequal outputs, equal local but different global behavior, and a distinguishing internal explanation meet the requested cases. The additional-choice example distinguishes accurate general assessment of non-entailment from the separate priority norm; this is deliberately the limited general-assessment relation in the target, not all Grounds duties.", + "special_limits": [] + }, + { + "target": "T19", + "case": "internal_reason_distinguishes", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.internalReasonDistinguishes012", + "file": "CoreReader/Adopted.lean", + "line": 657, + "axioms": "[]" + } + ], + "interpretation": "A single feasible conventional choice, unequal outputs, equal local but different global behavior, and a distinguishing internal explanation meet the requested cases. The additional-choice example distinguishes accurate general assessment of non-entailment from the separate priority norm; this is deliberately the limited general-assessment relation in the target, not all Grounds duties.", + "special_limits": [] + }, + { + "target": "T19", + "case": "unequal_open_options", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Choice.openNotEquivalent", + "file": "CoreReader/Choice.lean", + "line": 162, + "axioms": "[propext]" + } + ], + "interpretation": "A single feasible conventional choice, unequal outputs, equal local but different global behavior, and a distinguishing internal explanation meet the requested cases. The additional-choice example distinguishes accurate general assessment of non-entailment from the separate priority norm; this is deliberately the limited general-assessment relation in the target, not all Grounds duties.", + "special_limits": [] + }, + { + "target": "T19", + "case": "local_equal_global_difference", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Choice.localNotGlobal", + "file": "CoreReader/Choice.lean", + "line": 132, + "axioms": "[]" + } + ], + "interpretation": "A single feasible conventional choice, unequal outputs, equal local but different global behavior, and a distinguishing internal explanation meet the requested cases. The additional-choice example distinguishes accurate general assessment of non-entailment from the separate priority norm; this is deliberately the limited general-assessment relation in the target, not all Grounds duties.", + "special_limits": [] + }, + { + "target": "T19", + "case": "added_choice_not_from_general_assessment", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Choice.generalGroundsNotChoice", + "file": "CoreReader/Choice.lean", + "line": 257, + "axioms": "[propext]" + } + ], + "interpretation": "A single feasible conventional choice, unequal outputs, equal local but different global behavior, and a distinguishing internal explanation meet the requested cases. The additional-choice example distinguishes accurate general assessment of non-entailment from the separate priority norm; this is deliberately the limited general-assessment relation in the target, not all Grounds duties.", + "special_limits": [] + } + ] + }, + { + "id": "T20", + "kind": "theorem", + "statement": "Under jointly satisfied inherited commitments and actual applicability, own principles/assessment methods/grounds/capability judgments inherit their corresponding generation, consistency and support duties without self-proof or removal of conditions.", + "premises": [ + "Same subject/context, shared principle/object identifiers, applicability", + "reflexivity interface connected to concrete Grounds/choice/capability obligations", + "no isolated conjunction of unrelated models." + ], + "sources": [ + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + } + ], + "status": "accepted-bounded", + "prior_own_status": "partial_theorem_signature", + "prior_other_reviewer_status": "pending-correspondence", + "independent_r3_assessment": "Resolved. The theorem now explicitly concludes the full normative-content membership, grounds for every held claim, and consistencySpecification for the same expanded ownTheory. It remains a legitimate projection of Inherited, not mutual logical derivation from fewer premises. Actual self-rule generation/assessment objects are included and checked; original empirical/inferential/value tasks remain separate.", + "reuse": "Source/target text and unchanged nonblank definitions reused; affected transitive composition was rereviewed.", + "declarations": [ + { + "name": "CoreReader.Engineering.inheritedMutualApplication", + "file": "CoreReader/Engineering/Integration.lean", + "line": 420, + "end": 441, + "kind": "theorem", + "axioms": "[propext]", + "exact_code": "theorem inheritedMutualApplication (ctx : Context) (chosen : Candidate)\n (inherited : Inherited ctx chosen) :\n generationSpecification engineeringPolicy ∧\n reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self\n (selfModel chosen).performed ∧\n (∀ principle, valueSpecification (governancePosition principle)) ∧\n capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen) ∧\n choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons ∧\n (∀ fact, inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact)) ∧\n (∀ norm, normApplies chosen norm → ownTheory chosen (ownNormClaim chosen norm)) ∧\n (∀ claim, ownTheory chosen claim → inferentialSpecification (ownFactPremises chosen) claim) ∧\n consistencySpecification (engineeringSnapshot .evolvable 0)\n (engineeringSnapshot chosen 1) true :=\n ⟨inherited.generation, inherited.reflection, inherited.ownPrincipleGrounds,\n inherited.capabilityGrounds, inherited.implementationChoice, inherited.ownClaimGrounds,\n inherited.fullNormativeContents, inherited.wholeClaimGrounds, inherited.consistency⟩\n\n/-- organon-map CoreReader.Engineering.inheritedMutualCases\norganon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\n", + "full_type_record": { + "type": "Lean.Expr.forallE\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.forallE\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.forallE\n `inherited\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.Inherited []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.generationSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.engineeringPolicy [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.reflexivitySpecification [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Outcome [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.rules [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 1))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.self [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 1))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.performed [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `principle\n (Lean.Expr.const `CoreReader.Engineering.CoreCommitment [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.valueSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.governancePosition []) (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.engineeringProcess []) (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringCapability [])\n (Lean.Expr.bvar 1))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.choiceSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.chosenRequirements []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.chosenImplementation [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.const `CoreReader.Engineering.chosenReasons [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `fact\n (Lean.Expr.const `CoreReader.Engineering.OwnFact [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.inferentialSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownFactPremises [])\n (Lean.Expr.bvar 2)))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.ownFactClaim []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `norm\n (Lean.Expr.const `CoreReader.Engineering.OwnNorm [])\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.normApplies []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.ownTheory []) (Lean.Expr.bvar 3))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownNormClaim [])\n (Lean.Expr.bvar 3))\n (Lean.Expr.bvar 1)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `claim\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Claim [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.ownTheory []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.inferentialSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownFactPremises [])\n (Lean.Expr.bvar 3)))\n (Lean.Expr.bvar 1))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.consistencySpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `CoreReader.Engineering.OwnFact []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringSnapshot [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringSnapshot [])\n (Lean.Expr.bvar 1))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.const `Bool.true []))))))))))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "b60496465943a095fdd0772f4002302eb9242ece03be7a2e20ce616f0253ee4a" + }, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.inheritedMutualCases", + "file": "CoreReader/Engineering/Integration.lean", + "line": 442, + "end": 466, + "kind": "theorem", + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "exact_code": "theorem inheritedMutualCases :\n Inherited sharedContext .evolvable ∧\n valueSpecification (governancePosition .grounds) ∧\n capabilitySpecification (engineeringProcess .evolvable) (engineeringCapability .evolvable) ∧\n choiceSpecification chosenRequirements (chosenImplementation .evolvable) chosenReasons ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧\n (.generationRule : ReviewObject) ∈ (selfModel .evolvable).objects ∧\n (.assessmentRule : ReviewObject) ∈ (selfModel .evolvable).objects ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .assessmentRule, .revision⟩) = .counterexample :=\n ⟨inheritedCurrent .evolvable (Or.inr rfl), governanceGrounded .grounds,\n engineeringCapabilityGrounded .evolvable,\n (inheritedCurrent .evolvable (Or.inr rfl)).implementationChoice,\n (actualSelfCriticism .evolvable).2.2.1,\n (ownRuleIdentity .evolvable .generation .revision).1,\n (ownRuleIdentity .evolvable .assessment .revision).1,\n (ownRuleContentVariation .evolvable).2.2.2.2.1⟩\n\n/- In the adopter's same context, the actual priority object and its own\nassessment method remain within the inherited criticism/generation contract. -/\n/-- organon-map CoreReader.Engineering.priorityRemainsReflexive\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\nextensions#p1 sha256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66\nsoftware-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\nsoftware-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Inherited [])\n (Lean.Expr.const `CoreReader.Engineering.sharedContext []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.valueSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.governancePosition [])\n (Lean.Expr.const `CoreReader.Engineering.CoreCommitment.grounds []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringProcess [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringCapability [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.choiceSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.chosenRequirements []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.chosenImplementation [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.const `CoreReader.Engineering.chosenReasons [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.evaluate [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.evolutionMethod []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision [])))))\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict.counterexample [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.objects [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.generationRule [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.objects [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.assessmentRule [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.evaluate [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.assessmentRule []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision [])))))\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict.counterexample []))))))))", + "sha256": "e3c73c4f98c7a3fe5bfadc8b2bc7a9a5231473504e047179d6299e3417f2ba4c" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T20", + "case": "own_grounds_articulable", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedMutualApplication", + "file": "CoreReader/Engineering/Integration.lean", + "line": 420, + "axioms": "[propext]" + }, + { + "name": "CoreReader.Engineering.governanceGrounded", + "file": "CoreReader/Engineering/Values.lean", + "line": 137, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved. The theorem now explicitly concludes the full normative-content membership, grounds for every held claim, and consistencySpecification for the same expanded ownTheory. It remains a legitimate projection of Inherited, not mutual logical derivation from fewer premises. Actual self-rule generation/assessment objects are included and checked; original empirical/inferential/value tasks remain separate.", + "special_limits": [] + }, + { + "target": "T20", + "case": "own_capability_supported", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedMutualApplication", + "file": "CoreReader/Engineering/Integration.lean", + "line": 420, + "axioms": "[propext]" + }, + { + "name": "CoreReader.Engineering.engineeringCapabilityGrounded", + "file": "CoreReader/Engineering/Integration.lean", + "line": 63, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved. The theorem now explicitly concludes the full normative-content membership, grounds for every held claim, and consistencySpecification for the same expanded ownTheory. It remains a legitimate projection of Inherited, not mutual logical derivation from fewer premises. Actual self-rule generation/assessment objects are included and checked; original empirical/inferential/value tasks remain separate.", + "special_limits": [] + }, + { + "target": "T20", + "case": "own_choice_not_status_only", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedMutualApplication", + "file": "CoreReader/Engineering/Integration.lean", + "line": 420, + "axioms": "[propext]" + }, + { + "name": "CoreReader.Engineering.implementationReasoned", + "file": "CoreReader/Engineering/Integration.lean", + "line": 41, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved. The theorem now explicitly concludes the full normative-content membership, grounds for every held claim, and consistencySpecification for the same expanded ownTheory. It remains a legitimate projection of Inherited, not mutual logical derivation from fewer premises. Actual self-rule generation/assessment objects are included and checked; original empirical/inferential/value tasks remain separate.", + "special_limits": [] + }, + { + "target": "T20", + "case": "relevant_self_application", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedMutualCases", + "file": "CoreReader/Engineering/Integration.lean", + "line": 442, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + }, + { + "name": "CoreReader.Engineering.ownRuleContentVariation", + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 204, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved. The theorem now explicitly concludes the full normative-content membership, grounds for every held claim, and consistencySpecification for the same expanded ownTheory. It remains a legitimate projection of Inherited, not mutual logical derivation from fewer premises. Actual self-rule generation/assessment objects are included and checked; original empirical/inferential/value tasks remain separate.", + "special_limits": [ + "The empty-tested-list criticism concerns the sample-aware local assessmentRuleTest contract; it is not a philosophical demand for empirical samples in every judgment." + ] + } + ] + }, + { + "id": "T21", + "kind": "boundary", + "statement": "Existing form includes organization/methods/principles. Assessment is examination of reasons, applicability and observed performance and is not limited to executable testing.", + "premises": [ + "Definitions constrain every related model, including review subjects", + "no claim every assessment executes every listed operation when inapplicable." + ], + "sources": [ + { + "unit": "organon.relationships.terms", + "clause": "p1" + } + ], + "status": "accepted-documentary-boundary", + "prior_own_status": "documentary_boundary", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "FormKind explicitly includes organization, method and principle. Empirical and semantic-inferential facets and noncomputable proposition decisions prevent restricting assessment to executable tests. The finite formal vocabulary is illustrative rather than an exhaustive philosophical ontology.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [], + "semantic_cases": [] + }, + { + "id": "T22", + "kind": "specification", + "statement": "Domain subject is continuing engineering activity by current/successor human or agent maintainers with software/tools/knowledge across credible lifecycle; priority applicability reflects actual lifecycle/maintenance expectations, not labels or artifact intrinsic orientation.", + "premises": [ + "Subject/maintainer roles, credible lifecycle grounds, activity versus artifact", + "temporary/prototype/retiring contexts considered conditionally, not blanket exemption by name." + ], + "sources": [ + { + "unit": "software-engineering.purpose", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p2" + }, + { + "unit": "software-engineering.purpose", + "clause": "p3" + } + ], + "status": "accepted-bounded", + "prior_own_status": "bounded_subject_specification", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Engineering.ActivityScope", + "file": "CoreReader/Engineering/Domain.lean", + "line": 49, + "end": 52, + "kind": "abbrev", + "axioms": "[]", + "exact_code": "abbrev ActivityScope (a : Activity) : Prop :=\n a.participants ≠ [] ∧ a.software ≠ \"\" ∧ a.tools ≠ [] ∧\n a.participants.all (fun m => !(a.available m).isEmpty) = true\n\n", + "full_type_record": { + "type": "Lean.Expr.forallE\n `a\n (Lean.Expr.const `CoreReader.Engineering.Activity [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default)", + "sha256": "fdfa84c29643bd37a72d614541ecf59b4b7efdf606ac4b7480cb02fe3e4c8382" + }, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.subjectLifecycleCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 146, + "end": 158, + "kind": "theorem", + "axioms": "[propext]", + "exact_code": "theorem subjectLifecycleCases :\n ActivityScope continuingActivity ∧\n CanChange continuingActivity .evolvable .successor .designRevision ∧\n CanChange continuingActivity .evolvable .agent .designRevision ∧\n continuingActivity.label = \"temporary\" ∧ Continuing continuingActivity ∧\n ¬ BoundedLifecycle continuingActivity ∧ BoundedLifecycle temporaryActivity ∧\n BoundedLifecycle prototypeActivity ∧ BoundedLifecycle retiringActivity := by decide\n\n/-- organon-map CoreReader.Engineering.subjectLimits\nsoftware-engineering.purpose#p1 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.purpose#p2 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ActivityScope [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `String []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.label [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.lit (Lean.Literal.strVal \"temporary\"))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Continuing [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.const `CoreReader.Engineering.temporaryActivity [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.const `CoreReader.Engineering.prototypeActivity [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.const `CoreReader.Engineering.retiringActivity [])))))))))", + "sha256": "a2d126370b7fef5af4645ef64d85b169467518bfb8f76269b41f47f82e0bd02b" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T22", + "case": "successor_maintainer", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLifecycleCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 146, + "axioms": "[propext]" + } + ], + "interpretation": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established.", + "special_limits": [] + }, + { + "target": "T22", + "case": "agent_maintainer", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLifecycleCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 146, + "axioms": "[propext]" + } + ], + "interpretation": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established.", + "special_limits": [] + }, + { + "target": "T22", + "case": "continuing_labeled_temporary", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLifecycleCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 146, + "axioms": "[propext]" + } + ], + "interpretation": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established.", + "special_limits": [] + }, + { + "target": "T22", + "case": "genuinely_temporary", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLifecycleCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 146, + "axioms": "[propext]" + } + ], + "interpretation": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established.", + "special_limits": [] + }, + { + "target": "T22", + "case": "bounded_prototype", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLifecycleCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 146, + "axioms": "[propext]" + } + ], + "interpretation": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established.", + "special_limits": [] + }, + { + "target": "T22", + "case": "retiring_system", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLifecycleCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 146, + "axioms": "[propext]" + } + ], + "interpretation": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established.", + "special_limits": [] + } + ] + }, + { + "id": "T23", + "kind": "nonentailment", + "statement": "Original-author editability does not establish continuing-maintainer evolution capability; calling a continuing system temporary does not establish genuinely bounded lifecycle; adopted human/agent orientation does not entail every artifact has it.", + "premises": [ + "Concrete edit/understand/verify paths scoped by maintainer knowledge", + "lifecycle evidence distinct from label", + "actual continuing example." + ], + "sources": [ + { + "unit": "software-engineering.purpose", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p2" + }, + { + "unit": "software-engineering.purpose", + "clause": "p3" + } + ], + "status": "accepted-bounded", + "prior_own_status": "bounded_countermodels", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "The original maintainer has privateLayout while the successor lacks it; explicit path prerequisite failure establishes the contrast. The continuing activity remains nonbounded despite its temporary label. The passive artifact returns inputs and has no propose action by its actual definition, providing one counterexample rather than a law of all artifacts.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Engineering.subjectLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 159, + "end": 173, + "kind": "theorem", + "axioms": "[propext]", + "exact_code": "theorem subjectLimits :\n CanChange continuingActivity .presentSimple .original .designRevision ∧\n ¬ CanChange continuingActivity .presentSimple .successor .designRevision ∧\n ¬ ContinuingCapability continuingActivity .presentSimple .designRevision ∧\n continuingActivity.label = \"temporary\" ∧ ¬ BoundedLifecycle continuingActivity ∧\n orientation .agent ≠ [] ∧ passiveArtifact [2, 1] = [2, 1] ∧\n EngineeringAction.propose .designRevision ∈ maintainerActions .agent ∧\n EngineeringAction.propose .designRevision ∉ artifactActions [2, 1] := by decide\n\n/- Ground is intentionally parameterized: the examples below do not exhaust\npossible sources of credibility. The supplied support relation needs review. -/\n/-- organon-map CoreReader.Engineering.CredibleDirection\nsoftware-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.original []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContinuingCapability [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `String []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.label [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.lit (Lean.Literal.strVal \"temporary\"))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.orientation [])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.passiveArtifact [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.maintainerActions [])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction.propose [])\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.artifactActions [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringAction.propose [])\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))))))))))", + "sha256": "4d0b23030599912d1ad72613e9956d5dd179d987aa64f0a694f74e85847b2a2b" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T23", + "case": "author_only_private_knowledge", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 159, + "axioms": "[propext]" + } + ], + "interpretation": "The original maintainer has privateLayout while the successor lacks it; explicit path prerequisite failure establishes the contrast. The continuing activity remains nonbounded despite its temporary label. The passive artifact returns inputs and has no propose action by its actual definition, providing one counterexample rather than a law of all artifacts.", + "special_limits": [] + }, + { + "target": "T23", + "case": "successor_missing_path", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 159, + "axioms": "[propext]" + } + ], + "interpretation": "The original maintainer has privateLayout while the successor lacks it; explicit path prerequisite failure establishes the contrast. The continuing activity remains nonbounded despite its temporary label. The passive artifact returns inputs and has no propose action by its actual definition, providing one counterexample rather than a law of all artifacts.", + "special_limits": [] + }, + { + "target": "T23", + "case": "false_temporary_label", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 159, + "axioms": "[propext]" + } + ], + "interpretation": "The original maintainer has privateLayout while the successor lacks it; explicit path prerequisite failure establishes the contrast. The continuing activity remains nonbounded despite its temporary label. The passive artifact returns inputs and has no propose action by its actual definition, providing one counterexample rather than a law of all artifacts.", + "special_limits": [] + }, + { + "target": "T23", + "case": "passive_artifact", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 159, + "axioms": "[propext]" + } + ], + "interpretation": "The original maintainer has privateLayout while the successor lacks it; explicit path prerequisite failure establishes the contrast. The continuing activity remains nonbounded despite its temporary label. The passive artifact returns inputs and has no propose action by its actual definition, providing one counterexample rather than a law of all artifacts.", + "special_limits": [] + } + ] + }, + { + "id": "T24", + "kind": "specification", + "statement": "When credible lifecycle/maintenance scope and relevant behavioral, safety, performance and other necessary requirements hold, favor continuing-maintainer credible future change capability including design revision over present abstraction simplicity; accept purpose-linked added complexity; allow yielding only when added costs threaten concrete objectives, with objective/cost account.", + "premises": [ + "Explicit options, same engineering context, feasible requirements, supported credible change set, comparative evolution advantage, simplicity/complexity tradeoff, threat and departure explanation", + "no unconditional maximization or numeric exchange rate." + ], + "sources": [ + { + "unit": "software-engineering.purpose", + "clause": "p3" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "status": "accepted-bounded", + "prior_own_status": "bounded_normative_specification", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Engineering.EvolutionPriority", + "file": "CoreReader/Engineering/Domain.lean", + "line": 321, + "end": 323, + "kind": "abbrev", + "axioms": "[]", + "exact_code": "abbrev EvolutionPriority (ctx : Context) (chosen : Candidate) : Prop :=\n PriorityConditions ctx → chosen = .evolvable ∨ JustifiedDeparture ctx .evolvable\n\n", + "full_type_record": { + "type": "Lean.Expr.forallE\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.forallE\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "8609cb39944d272540e985febb940328bc4a85a6e22fe06e652f4c95bd043ddb" + }, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.priorityConditionsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 367, + "end": 383, + "kind": "theorem", + "axioms": "[propext]", + "exact_code": "theorem priorityConditionsCases :\n EvolutionPriority currentContinuing .evolvable ∧\n ¬ Meets normalRequirements { profile .evolvable with orderOutput := [1, 2] } ∧\n ¬ Meets normalRequirements { profile .evolvable with unsafeOperations := 1 } ∧\n ¬ Meets normalRequirements { profile .evolvable with latency := 11 } ∧\n ¬ Meets normalRequirements { profile .evolvable with retention := 29 } ∧\n EvolutionPriority (threatened .verification) .presentSimple ∧\n ¬ JustifiedDeparture { threatened .verification with departure := none } .evolvable ∧\n abstractionComplexity .evolvable < abstractionComplexity .maximal := by\n refine ⟨by decide, by decide, by decide, by decide, by decide, by decide, ?_, by decide⟩\n simp [JustifiedDeparture]\n\n/-- organon-map CoreReader.Engineering.priorityChoices\nsoftware-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.const `CoreReader.Engineering.normalRequirements []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2249646945) \"_hygCtx\") \"_hyg\") 19)\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.profile [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.unsafeOperations [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.latency [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.retention [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.const `CoreReader.Engineering.normalRequirements []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2249646945) \"_hygCtx\") \"_hyg\") 45)\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.profile [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.orderOutput [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.latency [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.retention [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.const `CoreReader.Engineering.normalRequirements []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2249646945) \"_hygCtx\") \"_hyg\") 65)\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.profile [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.orderOutput [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.unsafeOperations [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 11)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 11)))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.retention [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.const `CoreReader.Engineering.normalRequirements []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2249646945) \"_hygCtx\") \"_hyg\") 85)\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.profile [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.orderOutput [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.unsafeOperations [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CandidateProfile.latency [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 29)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 29)))))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.verification [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2249646945) \"_hygCtx\") \"_hyg\") 113)\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.verification []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.required [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.evidence [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.limits [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Option.none [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Burden [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.profiles [])\n (Lean.Expr.bvar 0)))\n true))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.maximal [])))))))))", + "sha256": "3206e3bed26ebff1742e044beabbfcca534354e4895936cd6496b4af5a5485e9" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T24", + "case": "ordinary_priority", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.priorityConditionsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 367, + "axioms": "[propext]" + } + ], + "interpretation": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "special_limits": [] + }, + { + "target": "T24", + "case": "missing_behavior", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.unmetRequirementsBlockPriority", + "file": "CoreReader/Engineering/Domain.lean", + "line": 353, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "special_limits": [] + }, + { + "target": "T24", + "case": "missing_safety", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.unmetRequirementsBlockPriority", + "file": "CoreReader/Engineering/Domain.lean", + "line": 353, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "special_limits": [] + }, + { + "target": "T24", + "case": "missing_performance", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.unmetRequirementsBlockPriority", + "file": "CoreReader/Engineering/Domain.lean", + "line": 353, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "special_limits": [] + }, + { + "target": "T24", + "case": "missing_other_necessary", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.unmetRequirementsBlockPriority", + "file": "CoreReader/Engineering/Domain.lean", + "line": 353, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "special_limits": [] + }, + { + "target": "T24", + "case": "concrete_cost_override", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.priorityConditionsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 367, + "axioms": "[propext]" + } + ], + "interpretation": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "special_limits": [] + }, + { + "target": "T24", + "case": "unexplained_departure", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.priorityConditionsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 367, + "axioms": "[propext]" + } + ], + "interpretation": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "special_limits": [] + }, + { + "target": "T24", + "case": "no_extensibility_maximum", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 394, + "axioms": "[propext]" + } + ], + "interpretation": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "special_limits": [] + } + ] + }, + { + "id": "T25", + "kind": "theorem", + "statement": "For a context meeting all priority conditions, with a credible evolution advantage over a simpler feasible option and no concrete cost threat, domain satisfaction requires the evolution-favoring choice/priority and acceptance of its relevant additional complexity.", + "premises": [ + "Every T24 premise explicit, adopted domain rule as normative premise", + "preference compliance separate from act of assessment and universal goodness. Do not infer adoption from Core alone." + ], + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "status": "accepted-bounded", + "prior_own_status": "conditional_theorem", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "The theorem explicitly assumes the adopted EvolutionPriority rule, applicability and no departure; it extracts the chosen evolvable value and substitutes into the supplied complexity comparison. This matches the target's normative-premise requirement. Concrete choices show simple violates the rule without a threat and can pass with the accounted threat.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Engineering.priorityWhenApplicable", + "file": "CoreReader/Engineering/Domain.lean", + "line": 337, + "end": 344, + "kind": "theorem", + "axioms": "[]", + "exact_code": "theorem priorityWhenApplicable (ctx : Context) (chosen : Candidate)\n (rule : EvolutionPriority ctx chosen) (applicable : PriorityConditions ctx)\n (noDeparture : ¬ JustifiedDeparture ctx .evolvable) :\n chosen = .evolvable ∧\n abstractionComplexity .presentSimple < abstractionComplexity chosen := by\n have hc := (rule applicable).resolve_right noDeparture\n exact ⟨hc, hc ▸ applicable.2.2.2.2.2.2.2⟩\n\n", + "full_type_record": { + "type": "Lean.Expr.forallE\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.forallE\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.forallE\n `rule\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `applicable\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.PriorityConditions []) (Lean.Expr.bvar 2))\n (Lean.Expr.forallE\n `noDeparture\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture []) (Lean.Expr.bvar 3))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.bvar 3))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple [])))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity []) (Lean.Expr.bvar 3))))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "6b1efb7cab71c9b837ce57e666f331112f6416f18a59675e8119416b3d7a39a6" + }, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.priorityChoices", + "file": "CoreReader/Engineering/Domain.lean", + "line": 384, + "end": 393, + "kind": "theorem", + "axioms": "[propext]", + "exact_code": "theorem priorityChoices :\n EvolutionPriority currentContinuing .evolvable ∧\n ¬ EvolutionPriority currentContinuing .presentSimple ∧\n EvolutionPriority (threatened .verification) .presentSimple := by\n exact ⟨by decide, currentSimpleViolates, by decide⟩\n\n/-- organon-map CoreReader.Engineering.credibilityLimits\nsoftware-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.verification [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple [])))", + "sha256": "d4cbb2cea4f863c0a900531a90fd4e36cd04ad50df57b340871001d6fb01b349" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T25", + "case": "applicable_choose_evolution", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.priorityWhenApplicable", + "file": "CoreReader/Engineering/Domain.lean", + "line": 337, + "axioms": "[]" + }, + { + "name": "CoreReader.Engineering.priorityChoices", + "file": "CoreReader/Engineering/Domain.lean", + "line": 384, + "axioms": "[propext]" + } + ], + "interpretation": "The theorem explicitly assumes the adopted EvolutionPriority rule, applicability and no departure; it extracts the chosen evolvable value and substitutes into the supplied complexity comparison. This matches the target's normative-premise requirement. Concrete choices show simple violates the rule without a threat and can pass with the accounted threat.", + "special_limits": [] + }, + { + "target": "T25", + "case": "applicable_choose_simple_violates_domain", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.currentSimpleViolates", + "file": "CoreReader/Engineering/Domain.lean", + "line": 345, + "axioms": "[propext]" + } + ], + "interpretation": "The theorem explicitly assumes the adopted EvolutionPriority rule, applicability and no departure; it extracts the chosen evolvable value and substitutes into the supplied complexity comparison. This matches the target's normative-premise requirement. Concrete choices show simple violates the rule without a threat and can pass with the accounted threat.", + "special_limits": [] + }, + { + "target": "T25", + "case": "threat_allows_departure_with_account", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.priorityChoices", + "file": "CoreReader/Engineering/Domain.lean", + "line": 384, + "axioms": "[propext]" + } + ], + "interpretation": "The theorem explicitly assumes the adopted EvolutionPriority rule, applicability and no departure; it extracts the chosen evolvable value and substitutes into the supplied complexity comparison. This matches the target's normative-premise requirement. Concrete choices show simple violates the rule without a threat and can pass with the accounted threat.", + "special_limits": [] + } + ] + }, + { + "id": "T26", + "kind": "specification", + "statement": "Credible change direction has articulable grounds (examples are plan/domain knowledge/history, not an exhaustive required list), remains revisable, and needs no existing multiple implementations. Conceivability alone cannot justify present accommodation.", + "premises": [ + "Grounds for direction and present investment separately", + "applicability of history/knowledge", + "no Boolean label replacing content of supporting plan." + ], + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "status": "accepted-bounded", + "prior_own_status": "qualified_credibility_adapter", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "The generic Ground interface does not restrict ground categories. Concrete plans identify a positive release and direction; knowledge/history cases contain a service/mechanism or repeated direction list, and forecast revision changes supported directions. The adapter only checks designated strings/list content, so actual relevance of a mechanism/history is a stipulated interpretation. It must not be reported as independent validation of arbitrary knowledge records.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Engineering.CredibleDirection", + "file": "CoreReader/Engineering/Domain.lean", + "line": 174, + "end": 178, + "kind": "abbrev", + "axioms": "[]", + "exact_code": "abbrev CredibleDirection {Ground : Type} (grounds : List Ground)\n (articulated : Ground → Bool) (supports : Ground → Change → Bool)\n (d : Change) : Prop :=\n grounds.any (fun g => articulated g && supports g d) = true\n\n", + "full_type_record": { + "type": "Lean.Expr.forallE\n `Ground\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `grounds\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `articulated\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 1)\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `supports\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 2)\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.const `CoreReader.Engineering.Change [])\n (Lean.Expr.const `Bool [])\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `d\n (Lean.Expr.const `CoreReader.Engineering.Change [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit)", + "sha256": "1906e98dd6d042fc973fb93506c24accc024a7643adaddd05e071030c8b5682b" + }, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.credibilityCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 212, + "end": 218, + "kind": "theorem", + "axioms": "[]", + "exact_code": "theorem credibilityCases :\n credible initialGrounds .designRevision ∧\n credible [.knowledge \"queue\" [.designRevision] \"tenant-config-reload\"] .designRevision ∧\n credible [.history \"queue\" [.migration, .migration]] .migration ∧\n ¬ credible [] (.other \"quantum backend\") ∧\n credible forecastGrounds .deletion ∧ ¬ credible forecastGrounds .designRevision := by decide\n\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.initialGrounds []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround.knowledge [])\n (Lean.Expr.lit (Lean.Literal.strVal \"queue\")))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))))\n (Lean.Expr.lit (Lean.Literal.strVal \"tenant-config-reload\"))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround []))))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround.history [])\n (Lean.Expr.lit (Lean.Literal.strVal \"queue\")))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.const `CoreReader.Engineering.Change.migration []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.const `CoreReader.Engineering.Change.migration []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround []))))\n (Lean.Expr.const `CoreReader.Engineering.Change.migration [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"quantum backend\"))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.forecastGrounds []))\n (Lean.Expr.const `CoreReader.Engineering.Change.deletion [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.forecastGrounds []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))))))", + "sha256": "b5d172388be7bcd1bdbeea1f07436b61458bd02c0e714dc83b7d7565adefa6c9" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T26", + "case": "committed_plan_one_implementation", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 212, + "axioms": "[]" + }, + { + "name": "CoreReader.Engineering.credibilityLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 394, + "axioms": "[propext]" + } + ], + "interpretation": "The generic Ground interface does not restrict ground categories. Concrete plans identify a positive release and direction; knowledge/history cases contain a service/mechanism or repeated direction list, and forecast revision changes supported directions. The adapter only checks designated strings/list content, so actual relevance of a mechanism/history is a stipulated interpretation. It must not be reported as independent validation of arbitrary knowledge records.", + "special_limits": [] + }, + { + "target": "T26", + "case": "domain_knowledge", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 212, + "axioms": "[]" + } + ], + "interpretation": "The generic Ground interface does not restrict ground categories. Concrete plans identify a positive release and direction; knowledge/history cases contain a service/mechanism or repeated direction list, and forecast revision changes supported directions. The adapter only checks designated strings/list content, so actual relevance of a mechanism/history is a stipulated interpretation. It must not be reported as independent validation of arbitrary knowledge records.", + "special_limits": [] + }, + { + "target": "T26", + "case": "applicable_history", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 212, + "axioms": "[]" + } + ], + "interpretation": "The generic Ground interface does not restrict ground categories. Concrete plans identify a positive release and direction; knowledge/history cases contain a service/mechanism or repeated direction list, and forecast revision changes supported directions. The adapter only checks designated strings/list content, so actual relevance of a mechanism/history is a stipulated interpretation. It must not be reported as independent validation of arbitrary knowledge records.", + "special_limits": [] + }, + { + "target": "T26", + "case": "conceivable_only", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 212, + "axioms": "[]" + } + ], + "interpretation": "The generic Ground interface does not restrict ground categories. Concrete plans identify a positive release and direction; knowledge/history cases contain a service/mechanism or repeated direction list, and forecast revision changes supported directions. The adapter only checks designated strings/list content, so actual relevance of a mechanism/history is a stipulated interpretation. It must not be reported as independent validation of arbitrary knowledge records.", + "special_limits": [] + }, + { + "target": "T26", + "case": "revised_forecast", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 212, + "axioms": "[]" + } + ], + "interpretation": "The generic Ground interface does not restrict ground categories. Concrete plans identify a positive release and direction; knowledge/history cases contain a service/mechanism or repeated direction list, and forecast revision changes supported directions. The adapter only checks designated strings/list content, so actual relevance of a mechanism/history is a stipulated interpretation. It must not be reported as independent validation of arbitrary knowledge records.", + "special_limits": [] + } + ] + }, + { + "id": "T27", + "kind": "nonentailment", + "statement": "Conceivable change alone does not entail warranted accommodation; credible change does not entail multiple existing implementations, maximal extensibility, retention of every possibility or universal numerical exchange rate.", + "premises": [ + "Nonempty supported direction and explicit alternative irrelevant direction", + "finite priority/qualitative comparison", + "credibility independent of current multiplicity." + ], + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "status": "accepted-bounded", + "prior_own_status": "bounded_countermodels", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "One implemented variant coexists with credible direction; unsupported imagined changes do not warrant the defined investment; evolvable supports nine registered directions while maximal supports ten but is not the priority. Different per-burden bounds and work comparisons demonstrate a selective example, not a mathematical impossibility of numerical tradeoffs.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Engineering.credibilityLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 394, + "end": 409, + "kind": "theorem", + "axioms": "[propext]", + "exact_code": "theorem credibilityLimits :\n credible initialGrounds .designRevision ∧ implementedVariants.length = 1 ∧\n ¬ WarrantedAccommodation [] (.other \"quantum backend\") 0 5 ∧\n ¬ credible initialGrounds (.other \"quantum backend\") ∧\n EvolutionPriority currentContinuing .evolvable ∧\n abstractionComplexity .evolvable < abstractionComplexity .maximal ∧\n cost .evolvable .construction < cost .evolvable .migration ∧\n ¬ MaximumRegisteredCapability continuingActivity .evolvable ∧\n MaximumRegisteredCapability continuingActivity .maximal ∧\n (supportedDirections continuingActivity .evolvable).length = 9 ∧\n (supportedDirections continuingActivity .maximal).length = 10 ∧\n ¬ credible initialGrounds (.other \"csv export\") := by decide\n\n/-- organon-map CoreReader.Engineering.costCases\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.initialGrounds []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `CoreReader.Engineering.implementedVariants [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.WarrantedAccommodation [])\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.DirectionGround [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"quantum backend\"))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.initialGrounds []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"quantum backend\"))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.maximal []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.cost [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Burden.construction [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.cost [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Burden.migration []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.MaximumRegisteredCapability [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.MaximumRegisteredCapability [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.maximal [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.supportedDirections [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 9)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 9))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.supportedDirections [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.maximal []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 10))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.const `CoreReader.Engineering.initialGrounds []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"csv export\")))))))))))))))", + "sha256": "76415ebe0bbc33c3827da7db33b1e89e3f676b7cf0f4f39df5401beeda5f40c4" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T27", + "case": "one_implementation_credible", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 394, + "axioms": "[propext]" + } + ], + "interpretation": "One implemented variant coexists with credible direction; unsupported imagined changes do not warrant the defined investment; evolvable supports nine registered directions while maximal supports ten but is not the priority. Different per-burden bounds and work comparisons demonstrate a selective example, not a mathematical impossibility of numerical tradeoffs.", + "special_limits": [] + }, + { + "target": "T27", + "case": "imagined_unwarranted", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 394, + "axioms": "[propext]" + } + ], + "interpretation": "One implemented variant coexists with credible direction; unsupported imagined changes do not warrant the defined investment; evolvable supports nine registered directions while maximal supports ten but is not the priority. Different per-burden bounds and work comparisons demonstrate a selective example, not a mathematical impossibility of numerical tradeoffs.", + "special_limits": [] + }, + { + "target": "T27", + "case": "selective_evolution", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 394, + "axioms": "[propext]" + } + ], + "interpretation": "One implemented variant coexists with credible direction; unsupported imagined changes do not warrant the defined investment; evolvable supports nine registered directions while maximal supports ten but is not the priority. Different per-burden bounds and work comparisons demonstrate a selective example, not a mathematical impossibility of numerical tradeoffs.", + "special_limits": [] + }, + { + "target": "T27", + "case": "qualitative_tradeoff", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 394, + "axioms": "[propext]" + } + ], + "interpretation": "One implemented variant coexists with credible direction; unsupported imagined changes do not warrant the defined investment; evolvable supports nine registered directions while maximal supports ten but is not the priority. Different per-burden bounds and work comparisons demonstrate a selective example, not a mathematical impossibility of numerical tradeoffs.", + "special_limits": [] + } + ] + }, + { + "id": "T28", + "kind": "specification", + "statement": "Cost/departure account admits understanding, construction, diagnosis, verification, coordination, operation and eventual migration burdens and identifies threatened objective and causal significance of added cost.", + "premises": [ + "Do not require every burden be material in every case", + "costs attached to candidate/context and concrete objective, not free exception flag." + ], + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "status": "accepted-bounded", + "prior_own_status": "bounded_cost_specification", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Engineering.JustifiedDeparture", + "file": "CoreReader/Engineering/Domain.lean", + "line": 298, + "end": 306, + "kind": "abbrev", + "axioms": "[]", + "exact_code": "abbrev JustifiedDeparture (ctx : Context) (c : Candidate) : Prop :=\n match ctx.departure with\n | none => False\n | some b => ConcreteThreat ctx c b\n\ninstance (ctx : Context) (c : Candidate) : Decidable (JustifiedDeparture ctx c) := by\n unfold JustifiedDeparture\n split <;> infer_instance\n\n", + "full_type_record": { + "type": "Lean.Expr.forallE\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.forallE\n `c\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "f6c50ef1eaca65b4a3886bcbc5ccb11393e89a2d7baf8f6980b6a58f9d0719a4" + }, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.costCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "end": 421, + "kind": "theorem", + "axioms": "[propext]", + "exact_code": "theorem costCases :\n JustifiedDeparture (threatened .understanding) .evolvable ∧\n JustifiedDeparture (threatened .construction) .evolvable ∧\n JustifiedDeparture (threatened .diagnosis) .evolvable ∧\n JustifiedDeparture (threatened .verification) .evolvable ∧\n JustifiedDeparture (threatened .coordination) .evolvable ∧\n JustifiedDeparture (threatened .operation) .evolvable ∧\n JustifiedDeparture (threatened .migration) .evolvable ∧\n ¬ JustifiedDeparture { currentContinuing with departure := some .migration } .evolvable := by decide\n\n/- Total functions model an identified order-preserving de-duplication API.\nThe test corpus is explicitly finite; universal preservation is separate. -/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.understanding [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.construction [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.diagnosis [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.verification [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.coordination [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.operation [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.migration [])))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 797674858) \"_hygCtx\") \"_hyg\") 72)\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.required [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.evidence [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.limits [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Option.some [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Burden []))\n (Lean.Expr.const `CoreReader.Engineering.Burden.migration [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.profiles [])\n (Lean.Expr.bvar 0)))\n true))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))))))))", + "sha256": "0159f38d1da3fe90524ce5a5d2e2b1d3a4fc5a14c6a76a6fbc07a158d16edd90" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T28", + "case": "understanding_threat", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.costCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "axioms": "[propext]" + } + ], + "interpretation": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "special_limits": [] + }, + { + "target": "T28", + "case": "construction_threat", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.costCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "axioms": "[propext]" + } + ], + "interpretation": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "special_limits": [] + }, + { + "target": "T28", + "case": "diagnosis_threat", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.costCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "axioms": "[propext]" + } + ], + "interpretation": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "special_limits": [] + }, + { + "target": "T28", + "case": "verification_threat", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.costCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "axioms": "[propext]" + } + ], + "interpretation": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "special_limits": [] + }, + { + "target": "T28", + "case": "coordination_threat", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.costCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "axioms": "[propext]" + } + ], + "interpretation": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "special_limits": [] + }, + { + "target": "T28", + "case": "operation_threat", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.costCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "axioms": "[propext]" + } + ], + "interpretation": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "special_limits": [] + }, + { + "target": "T28", + "case": "migration_threat", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.costCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "axioms": "[propext]" + } + ], + "interpretation": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "special_limits": [] + }, + { + "target": "T28", + "case": "unsupported_cost_excuse", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.costCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "axioms": "[propext]" + } + ], + "interpretation": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "special_limits": [] + } + ] + }, + { + "id": "T29", + "kind": "specification", + "statement": "Evolution includes capability addition, implementation replacement, mechanism deletion, abstraction withdrawal, boundary redrawing and technology/model migration; claims identify relevant changes and maintainer conditions; independent/coordinated changes and preserved/revised obligations may require different structures.", + "premises": [ + "Nonexhaustive source include-list", + "identified capability relation indexed by change, context and maintainer", + "obligation semantics tracked." + ], + "sources": [ + { + "unit": "software-engineering.evolution-meaning", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p2" + } + ], + "status": "accepted-bounded", + "prior_own_status": "bounded_evolution_specification", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Engineering.EvolutionClaim", + "file": "CoreReader/Engineering/Domain.lean", + "line": 556, + "end": 568, + "kind": "abbrev", + "axioms": "[]", + "exact_code": "abbrev EvolutionClaim (a : Activity) (c : Candidate) (claim : ChangeClaim) : Prop :=\n CanChange a c claim.byMaintainer claim.direction ∧\n ContractChangeAccount originalContract (evolutionContract claim.direction) normalRevision ∧\n (changePath c claim.direction).any (fun step => step.tool == .contractRunner) = true ∧\n ((claim.treatment = .preserve ∧\n evolutionBehavior claim.direction [2, 1, 2] = orderedUnique [2, 1, 2]) ∨\n (claim.treatment = .revise ∧\n evolutionBehavior claim.direction [2, 1, 2] ≠ orderedUnique [2, 1, 2]))\n\n/-- organon-map CoreReader.Engineering.evolutionKindsCases\nsoftware-engineering.evolution-meaning#p1 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6\nsoftware-engineering.evolution-meaning#p2 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6\n-/\n", + "full_type_record": { + "type": "Lean.Expr.forallE\n `a\n (Lean.Expr.const `CoreReader.Engineering.Activity [])\n (Lean.Expr.forallE\n `c\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.forallE\n `claim\n (Lean.Expr.const `CoreReader.Engineering.ChangeClaim [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "9c0c528a387fd26adf8c44acbd1e97da3c991c6544f40f31c0a8c3adb2ccd2f7" + }, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "end": 584, + "kind": "theorem", + "axioms": "[propext]", + "exact_code": "theorem evolutionKindsCases :\n (transform .addition originalSoftware).capabilities = [\"deduplicate\", \"tenant batching\"] ∧\n (transform .replacement originalSoftware).implementation = 1 ∧\n (transform .deletion originalSoftware).mechanisms = [\"queue\"] ∧\n (transform .withdrawal originalSoftware).abstractions = [] ∧\n (transform .redrawing originalSoftware).boundary = 1 ∧\n (transform .migration originalSoftware).technology = \"portable store\" ∧\n changes.all (fun d => decide (CanChange continuingActivity .evolvable .successor d)) = true ∧\n EvolutionClaim continuingActivity .evolvable ⟨.replacement, .successor, .preserve⟩ ∧\n EvolutionClaim continuingActivity .evolvable ⟨.redrawing, .agent, .revise⟩ ∧\n changeWork .evolvable .independent < changeWork .evolvable .coordinated := by decide\n\n/-- organon-map CoreReader.Engineering.evolutionDimensionsLimits\nsoftware-engineering.evolution-meaning#p1 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6\nsoftware-engineering.evolution-meaning#p2 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.capabilities [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.addition []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"deduplicate\")))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"tenant batching\")))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `String []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.implementation [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.replacement []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.mechanisms [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.deletion []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"queue\")))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `String [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.abstractions [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.withdrawal []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `String []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.boundary [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.redrawing []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `String []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.technology [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.const `CoreReader.Engineering.Change.migration []))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.lit (Lean.Literal.strVal \"portable store\"))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.all [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.const `CoreReader.Engineering.changes []))\n (Lean.Expr.lam\n `d\n (Lean.Expr.const `CoreReader.Engineering.Change [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Decidable.decide [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instDecidableAnd [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.participants [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.all [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.lam\n `step\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Bool.and [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.const\n `CoreReader.Engineering.instDecidableEqKnowledge\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.available [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.requires [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqTool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.tools [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.tool [])\n (Lean.Expr.bvar 0))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instDecidableNot [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.instDecidableEqNil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instDecidableAnd [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.participants [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.all [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.lam\n `step\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Bool.and [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.const\n `CoreReader.Engineering.instDecidableEqKnowledge\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.available [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.requires [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqTool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.tools [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.tool [])\n (Lean.Expr.bvar 0))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.instDecidableMemOfLawfulBEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqMaintainer [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instLawfulBEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqMaintainer [])))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.participants [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instDecidableEqBool [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.all [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.lam\n `step\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Bool.and [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.const\n `CoreReader.Engineering.instDecidableEqKnowledge\n [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.available [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.requires [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.contains [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Tool []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqTool [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Activity.tools [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.tool [])\n (Lean.Expr.bvar 0))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionClaim [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ChangeClaim.mk [])\n (Lean.Expr.const `CoreReader.Engineering.Change.replacement []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.ObligationTreatment.preserve []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionClaim [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ChangeClaim.mk [])\n (Lean.Expr.const `CoreReader.Engineering.Change.redrawing []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent []))\n (Lean.Expr.const `CoreReader.Engineering.ObligationTreatment.revise []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.independent [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated [])))))))))))", + "sha256": "ccab4c5ed0bb676cef2d8435b8252630c0bc2f32d0ce9023156532deb6b77a1e" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T29", + "case": "addition", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "replacement", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "deletion", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "withdrawal", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "redrawing", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "migration", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "independent", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "coordinated", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "preserve_obligation", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "revise_obligation", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + } + ] + }, + { + "id": "T30", + "kind": "nonentailment", + "statement": "Cheap/effective additions within fixed scheme do not entail equal ability to revise/leave it; advantage on one dimension does not entail every dimension; no duty to make every change inexpensive.", + "premises": [ + "Concrete change-work or enabled-path relation producing add/exit contrast and independent/coordinated contrast", + "no arbitrary unsupported capability flags." + ], + "sources": [ + { + "unit": "software-engineering.evolution-meaning", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p2" + } + ], + "status": "accepted-bounded", + "prior_own_status": "bounded_countermodels", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "Addition can cost two while withdrawal/revision costs seventeen; coordinated work exceeds independent work; migration can remain expensive while evolution priority holds. Equal addition cost directly refutes universal strict improvement over all Change values.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Engineering.evolutionDimensionsLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 585, + "end": 601, + "kind": "theorem", + "axioms": "[propext]", + "exact_code": "theorem evolutionDimensionsLimits :\n changeWork .presentSimple .addition = 2 ∧\n changeWork .presentSimple .withdrawal = 17 ∧\n changeWork .evolvable .independent < changeWork .evolvable .coordinated ∧\n EvolutionPriority currentContinuing .evolvable ∧\n 9 < changeWork .evolvable .migration ∧\n CanChange continuingActivity .presentSimple .original .addition ∧\n CanChange continuingActivity .evolvable .original .addition ∧\n CanChange continuingActivity .presentSimple .original .designRevision ∧\n CanChange continuingActivity .evolvable .original .designRevision ∧\n changeWork .evolvable .designRevision < changeWork .presentSimple .designRevision ∧\n changeWork .evolvable .addition = changeWork .presentSimple .addition ∧\n (transform (.other \"csv export\") originalSoftware).capabilities = [\"deduplicate\", \"csv export\"] ∧\n CanChange continuingActivity .maximal .successor (.other \"csv export\") ∧\n ¬ CanChange continuingActivity .evolvable .successor (.other \"csv export\") := by\n exact ⟨by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide⟩\n\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.addition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.withdrawal [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 17)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 17))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.independent [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 9)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 9)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.migration []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.original []))\n (Lean.Expr.const `CoreReader.Engineering.Change.addition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.original []))\n (Lean.Expr.const `CoreReader.Engineering.Change.addition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.original []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.original []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.addition [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.addition []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.SoftwareState.capabilities [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.transform [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"csv export\"))))\n (Lean.Expr.const `CoreReader.Engineering.originalSoftware []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"deduplicate\")))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"csv export\")))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `String []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.maximal []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"csv export\")))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"csv export\")))))))))))))))))", + "sha256": "ba2af856a831323eaa2344e83084a08689b7a287f6a8542edcef6fb0c2e57af7" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T30", + "case": "easy_add_hard_exit", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionDimensionsLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 585, + "axioms": "[propext]" + } + ], + "interpretation": "Addition can cost two while withdrawal/revision costs seventeen; coordinated work exceeds independent work; migration can remain expensive while evolution priority holds. Equal addition cost directly refutes universal strict improvement over all Change values.", + "special_limits": [] + }, + { + "target": "T30", + "case": "independent_easy_coordinated_hard", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionDimensionsLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 585, + "axioms": "[propext]" + } + ], + "interpretation": "Addition can cost two while withdrawal/revision costs seventeen; coordinated work exceeds independent work; migration can remain expensive while evolution priority holds. Equal addition cost directly refutes universal strict improvement over all Change values.", + "special_limits": [] + }, + { + "target": "T30", + "case": "some_change_expensive_permitted", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionDimensionsLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 585, + "axioms": "[propext]" + } + ], + "interpretation": "Addition can cost two while withdrawal/revision costs seventeen; coordinated work exceeds independent work; migration can remain expensive while evolution priority holds. Equal addition cost directly refutes universal strict improvement over all Change values.", + "special_limits": [] + } + ] + }, + { + "id": "T31", + "kind": "specification", + "statement": "Structural choice applies to whole relevant engineering consequences: component relations, observable contracts, understanding and verification work; boundary capability needs support for intended changes; propagation/cross-boundary knowledge and obligations/fixed assumptions/withdrawal are possible comparison inquiries.", + "premises": [ + "Whole relevant scope rather than every imaginable consequence", + "may-examine inquiries are not compulsory universal checklist", + "intended change and boundary support relation explicit." + ], + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p2" + } + ], + "status": "accepted-bounded", + "prior_own_status": "partial_semantic_link", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "Resolved as a finite intended-change case. actualCrossBoundaryObligation links the registered edge caller 2/callee 1 to a real callee compiler edit, a caller contractRunner/publicContract step and finite observed order preservation. Removing the caller check leaves the crossing true but rejects the obligation; changing the callee to 7 loses the crossing; replacing output with sortedUnique fails the contract. No network/runtime semantics or universal completeness of every edge is claimed.", + "reuse": "Source/target text and unchanged nonblank definitions reused; affected transitive composition was rereviewed.", + "declarations": [ + { + "name": "CoreReader.Engineering.StructuralAccount", + "file": "CoreReader/Engineering/Domain.lean", + "line": 641, + "end": 650, + "kind": "abbrev", + "axioms": "[]", + "exact_code": "abbrev StructuralAccount (a : Activity) (c : Candidate) (e : StructuralEvidence) : Prop :=\n e.participants = a.participants ∧ e.touched = propagation c e.intended ∧\n e.contractObservations = contractInputs ∧\n e.observedBefore = contractInputs.map orderedUnique ∧\n e.observedAfter = contractInputs.map (evolutionBehavior e.intended) ∧\n e.understandingWork = changeWork c e.intended ∧\n e.verificationWork = ((changePath c e.intended).filter\n (fun step => step.tool == .contractRunner)).length ∧\n e.boundaryGain = changeWork .presentSimple e.intended - changeWork c e.intended\n\n", + "full_type_record": { + "type": "Lean.Expr.forallE\n `a\n (Lean.Expr.const `CoreReader.Engineering.Activity [])\n (Lean.Expr.forallE\n `c\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.forallE\n `e\n (Lean.Expr.const `CoreReader.Engineering.StructuralEvidence [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "45df6c2c2383df05162c2a265ba6daf5debbdf46847dc9de1801f881eb00db1e" + }, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.structuralCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 733, + "end": 750, + "kind": "theorem", + "axioms": "[propext]", + "exact_code": "theorem structuralCases :\n StructuralAccount continuingActivity .evolvable (structuralEvidence .evolvable .designRevision) ∧\n (propagation .presentSimple .designRevision).length = 3 ∧\n (propagation .evolvable .designRevision).length = 2 ∧\n (changePath .evolvable .coordinated).any (fun s => s.component == 2 && s.requires == .publicContract) = true ∧\n PreservesFinite orderedUnique orderedRefactor ∧\n (structuralEvidence .evolvable .designRevision).observedBefore ≠\n (structuralEvidence .evolvable .designRevision).observedAfter ∧\n staticBatch 21 10 = liveBatch 21 10 ∧ staticBatch 21 5 ≠ liveBatch 21 5 ∧\n changeWork .presentSimple .withdrawal = 17 ∧\n (crossesBoundary boundaryDesign .coordinated coordinatedBoundary = true ∧\n boundaryObligationChecked boundaryDesign .coordinated coordinatedBoundary = true ∧\n crossesBoundary omittedCallerCheck .coordinated coordinatedBoundary = true ∧\n boundaryObligationChecked omittedCallerCheck .coordinated coordinatedBoundary = false ∧\n crossesBoundary otherCalleeDesign .coordinated otherCalleeBoundary = false ∧\n boundaryObligationChecked { boundaryDesign with run := sortedUnique }\n .coordinated coordinatedBoundary = false) := by decide\n\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.StructuralAccount [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.structuralEvidence [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.propagation [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.propagation [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.any [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated [])))\n (Lean.Expr.lam\n `s\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Bool.and [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `BEq.beq [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instDecidableEqNat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.component [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `BEq.beq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqKnowledge [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.requires [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `CoreReader.Engineering.Knowledge.publicContract [])))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.orderedRefactor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.StructuralEvidence.observedBefore [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.structuralEvidence [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.StructuralEvidence.observedAfter [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.structuralEvidence [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.staticBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 10))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 10)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.staticBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.withdrawal [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 17)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 17))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.crossesBoundary [])\n (Lean.Expr.const `CoreReader.Engineering.boundaryDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.coordinatedBoundary [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.boundaryObligationChecked [])\n (Lean.Expr.const `CoreReader.Engineering.boundaryDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.coordinatedBoundary [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.crossesBoundary [])\n (Lean.Expr.const `CoreReader.Engineering.omittedCallerCheck []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.coordinatedBoundary [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.boundaryObligationChecked [])\n (Lean.Expr.const `CoreReader.Engineering.omittedCallerCheck []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.coordinatedBoundary [])))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.crossesBoundary [])\n (Lean.Expr.const `CoreReader.Engineering.otherCalleeDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.otherCalleeBoundary [])))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.boundaryObligationChecked [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 1550649743) \"_hygCtx\") \"_hyg\") 194)\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign [])\n (Lean.Expr.const `CoreReader.Engineering.boundaryDesign [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.mk [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Engineering.EngineeringDesign.metadata\n [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `CoreReader.Engineering.sortedUnique []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.paths [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Engineering.EngineeringDesign.components\n [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.boundaries [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Engineering.EngineeringDesign.batchAssumptions\n [])\n (Lean.Expr.bvar 0)))\n true))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.coordinatedBoundary [])))\n (Lean.Expr.const `Bool.false [])))))))))))))))", + "sha256": "4fdfb378096465bfe330f655d5cc248745bbfdcb505407595d9d23254428de9e" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T31", + "case": "contract_and_work_comparison", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.structuralCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 733, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved as a finite intended-change case. actualCrossBoundaryObligation links the registered edge caller 2/callee 1 to a real callee compiler edit, a caller contractRunner/publicContract step and finite observed order preservation. Removing the caller check leaves the crossing true but rejects the obligation; changing the callee to 7 loses the crossing; replacing output with sortedUnique fails the contract. No network/runtime semantics or universal completeness of every edge is claimed.", + "special_limits": [] + }, + { + "target": "T31", + "case": "propagation_relation", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.structuralCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 733, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved as a finite intended-change case. actualCrossBoundaryObligation links the registered edge caller 2/callee 1 to a real callee compiler edit, a caller contractRunner/publicContract step and finite observed order preservation. Removing the caller check leaves the crossing true but rejects the obligation; changing the callee to 7 loses the crossing; replacing output with sortedUnique fails the contract. No network/runtime semantics or universal completeness of every edge is claimed.", + "special_limits": [] + }, + { + "target": "T31", + "case": "cross_boundary_obligation", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.actualCrossBoundaryObligation", + "file": "CoreReader/Engineering/Domain.lean", + "line": 720, + "axioms": "[]" + } + ], + "interpretation": "Resolved as a finite intended-change case. actualCrossBoundaryObligation links the registered edge caller 2/callee 1 to a real callee compiler edit, a caller contractRunner/publicContract step and finite observed order preservation. Removing the caller check leaves the crossing true but rejects the obligation; changing the callee to 7 loses the crossing; replacing output with sortedUnique fails the contract. No network/runtime semantics or universal completeness of every edge is claimed.", + "special_limits": [ + "Fixed caller/callee/contract family and finite observation domain; no universal runtime dependency semantics." + ] + }, + { + "target": "T31", + "case": "fixed_assumption", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.structuralCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 733, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved as a finite intended-change case. actualCrossBoundaryObligation links the registered edge caller 2/callee 1 to a real callee compiler edit, a caller contractRunner/publicContract step and finite observed order preservation. Removing the caller check leaves the crossing true but rejects the obligation; changing the callee to 7 loses the crossing; replacing output with sortedUnique fails the contract. No network/runtime semantics or universal completeness of every edge is claimed.", + "special_limits": [] + }, + { + "target": "T31", + "case": "withdrawal_cost", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.structuralCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 733, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved as a finite intended-change case. actualCrossBoundaryObligation links the registered edge caller 2/callee 1 to a real callee compiler edit, a caller contractRunner/publicContract step and finite observed order preservation. Removing the caller check leaves the crossing true but rejects the obligation; changing the callee to 7 loses the crossing; replacing output with sortedUnique fails the contract. No network/runtime semantics or universal completeness of every edge is claimed.", + "special_limits": [] + } + ] + }, + { + "id": "T32", + "kind": "nonentailment", + "statement": "Interface shape, module/extension-point count, named principle or boundary introduction alone cannot establish claimed evolution capability or easier intended change.", + "premises": [ + "Executable or finite semantic consequence model links shape to behavior and work to change", + "demonstrate missing capability by contract/propagation/work failure rather than named false flag." + ], + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p2" + } + ], + "status": "accepted-bounded", + "prior_own_status": "bounded_countermodels_delta_verified", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "The frozen delta now supplies the exact new_boundary_same_work case missing from the initial code: an actual added boundary and changed path with identical units/work and remaining successor prerequisite failure. The original increased-work example is retained. These and the signature/module/named-pattern examples meet the finite negative target, without proving real-world overhead or boundary execution semantics.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Engineering.structureNotCapability", + "file": "CoreReader/Engineering/Domain.lean", + "line": 793, + "end": 821, + "kind": "theorem", + "axioms": "[propext]", + "exact_code": "theorem structureNotCapability :\n (privateDesign.metadata.signature = sortedDesign.metadata.signature ∧\n privateDesign.run [2, 1, 2] = [2, 1] ∧ sortedDesign.run [2, 1, 2] ≠ [2, 1]) ∧\n (privateDesign.metadata.modules = privateDesign.components.length ∧\n privateDesign.batchAssumptions.length = 8 ∧\n (designModulesNeedingRevision privateDesign 5).length = 8) ∧\n (privateDesign.metadata.principle = \"dependency inversion\" ∧\n privateDesign.metadata = documentedDesign.metadata ∧\n ¬ DesignCanChange continuingActivity privateDesign .successor .designRevision ∧\n DesignCanChange continuingActivity documentedDesign .successor .designRevision) ∧\n (privateDesign.boundaries.length = 0 ∧ wrappedDesign.boundaries.length = 1 ∧\n wrappedDesign.components.length = 9 ∧\n wrappedDesign.boundaries = [⟨8, 0, \"List Nat → List Nat\"⟩] ∧\n wrappedDesign.run [2, 1, 2] = privateDesign.run [2, 1, 2] ∧\n designWork privateDesign .designRevision = 17 ∧\n designWork wrappedDesign .designRevision = 18 ∧\n ¬ designWork wrappedDesign .designRevision < designWork privateDesign .designRevision) ∧\n (sameWorkDesign.boundaries = [⟨8, 0, \"List Nat → List Nat\"⟩] ∧\n sameWorkDesign.components.length = 9 ∧\n sameWorkDesign.paths .designRevision ≠ privateDesign.paths .designRevision ∧\n sameWorkDesign.run [2, 1, 2] = privateDesign.run [2, 1, 2] ∧\n designWork sameWorkDesign .designRevision = designWork privateDesign .designRevision ∧\n designWork sameWorkDesign .designRevision = 17 ∧\n ¬ DesignCanChange continuingActivity sameWorkDesign .successor .designRevision) := by\n exact ⟨by decide, by decide, by decide, by decide, by decide⟩\n\n/-- organon-map CoreReader.Engineering.contractPreservation\nsoftware-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `String []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.InterfaceView.signature [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.InterfaceView.signature [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.sortedDesign [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.sortedDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.InterfaceView.modules [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.components [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.batchAssumptions [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 8)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 8))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designModulesNeedingRevision [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 8)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 8))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `String []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.InterfaceView.principle [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))))\n (Lean.Expr.lit (Lean.Literal.strVal \"dependency inversion\"))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.InterfaceView []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.metadata [])\n (Lean.Expr.const `CoreReader.Engineering.documentedDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.DesignCanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.DesignCanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.documentedDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.boundaries [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.length [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.boundaries [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.components [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 9)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 9))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.boundaries [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Boundary.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 8)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 8)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.lit (Lean.Literal.strVal \"List Nat → List Nat\"))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 17)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 17))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 18)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 18))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.wrappedDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.boundaries [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Boundary.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 8)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 8)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.lit (Lean.Literal.strVal \"List Nat → List Nat\"))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Boundary [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.components [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 9)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 9))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.paths [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.paths [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.run [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 2)))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.privateDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.designWork [])\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 17)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 17))))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.DesignCanChange [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.sameWorkDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))))))))))", + "sha256": "2c09939db7dbc6561ff01284d1187a4272120050885c7743d2227d2a6e133ea9" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T32", + "case": "same_shape_broken_order", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.structureNotCapability", + "file": "CoreReader/Engineering/Domain.lean", + "line": 793, + "axioms": "[propext]" + } + ], + "interpretation": "The frozen delta now supplies the exact new_boundary_same_work case missing from the initial code: an actual added boundary and changed path with identical units/work and remaining successor prerequisite failure. The original increased-work example is retained. These and the signature/module/named-pattern examples meet the finite negative target, without proving real-world overhead or boundary execution semantics.", + "special_limits": [] + }, + { + "target": "T32", + "case": "many_modules_shared_obligation", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.structureNotCapability", + "file": "CoreReader/Engineering/Domain.lean", + "line": 793, + "axioms": "[propext]" + } + ], + "interpretation": "The frozen delta now supplies the exact new_boundary_same_work case missing from the initial code: an actual added boundary and changed path with identical units/work and remaining successor prerequisite failure. The original increased-work example is retained. These and the signature/module/named-pattern examples meet the finite negative target, without proving real-world overhead or boundary execution semantics.", + "special_limits": [] + }, + { + "target": "T32", + "case": "named_pattern_no_change_path", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.structureNotCapability", + "file": "CoreReader/Engineering/Domain.lean", + "line": 793, + "axioms": "[propext]" + } + ], + "interpretation": "The frozen delta now supplies the exact new_boundary_same_work case missing from the initial code: an actual added boundary and changed path with identical units/work and remaining successor prerequisite failure. The original increased-work example is retained. These and the signature/module/named-pattern examples meet the finite negative target, without proving real-world overhead or boundary execution semantics.", + "special_limits": [] + }, + { + "target": "T32", + "case": "new_boundary_same_work", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.structureNotCapability", + "file": "CoreReader/Engineering/Domain.lean", + "line": 793, + "axioms": "[propext]" + } + ], + "interpretation": "The frozen delta now supplies the exact new_boundary_same_work case missing from the initial code: an actual added boundary and changed path with identical units/work and remaining successor prerequisite failure. The original increased-work example is retained. These and the signature/module/named-pattern examples meet the finite negative target, without proving real-world overhead or boundary execution semantics.", + "special_limits": [] + } + ] + }, + { + "id": "T33", + "kind": "specification", + "statement": "Distinguish preserving an identified observable contract from deliberately revising it; deliberate revision accounts for changed obligations and affected parties; no requirement to preserve every historical behavior or use particular tests/migration procedure.", + "premises": [ + "Identified contract and observations, deliberate revision intent, obligations/affected parties mapping", + "preservation scope explicit", + "changes outside scope not silently violations." + ], + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "p3" + } + ], + "status": "accepted-bounded", + "prior_own_status": "bounded_contract_specification", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "ContractChangeAccount separates finite scoped equality from deliberate revision with changed order/retry obligations and affected-party coverage. Missing operator/incorrect old limits fail; [99] demonstrates an intentionally out-of-scope historical difference; changing procedure text remains allowed. Actual notification, completeness of parties and all-input equivalence are not modeled.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Engineering.ContractChangeAccount", + "file": "CoreReader/Engineering/Domain.lean", + "line": 549, + "end": 555, + "kind": "abbrev", + "axioms": "[]", + "exact_code": "abbrev ContractChangeAccount (old new : ObservableContract) (r : ContractRevision) : Prop :=\n PreservesContractFinite old new ∨ RevisionDuties old new r\n\n/-- organon-map CoreReader.Engineering.EvolutionClaim\nsoftware-engineering.evolution-meaning#p1 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6\nsoftware-engineering.evolution-meaning#p2 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6\n-/\n", + "full_type_record": { + "type": "Lean.Expr.forallE\n `old\n (Lean.Expr.const `CoreReader.Engineering.ObservableContract [])\n (Lean.Expr.forallE\n `new\n (Lean.Expr.const `CoreReader.Engineering.ObservableContract [])\n (Lean.Expr.forallE\n `r\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "c58d92d3f41481a1b24941446085e8161c5dcb32cc266487f9734c2c03c8d3fe" + }, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.contractCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 843, + "end": 852, + "kind": "theorem", + "axioms": "[]", + "exact_code": "theorem contractCases :\n ContractChangeAccount originalContract refactoredContract normalRevision ∧\n ContractChangeAccount originalContract revisedContract normalRevision ∧\n ¬ ContractChangeAccount originalContract revisedContract { normalRevision with affected := [] } ∧\n PreservesFinite orderedUnique retiredBehavior ∧ retiredBehavior [99] ≠ orderedUnique [99] ∧\n ContractChangeAccount originalContract revisedContract { normalRevision with procedure := \"paired audit\" } := by decide\n\n/-- organon-map CoreReader.Engineering.contractDistinctions\nsoftware-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.refactoredContract []))\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 640854215) \"_hygCtx\") \"_hyg\") 28)\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision [])\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.deliberate [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.revisedOrder [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.oldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.newFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedOldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedNewFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.procedure [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.retiredBehavior [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.retiredBehavior [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 99)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 99)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 99)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 99)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 640854215) \"_hygCtx\") \"_hyg\") 68)\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision [])\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.deliberate [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.revisedOrder [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.affected [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.oldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.newFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedOldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedNewFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.lit (Lean.Literal.strVal \"paired audit\")))\n true))))))", + "sha256": "d577c98b03b1349b8acdc20e24a2d1141ea92e5ce49ab73e3518385e0981adeb" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T33", + "case": "preserve_identified_contract", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.contractCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 843, + "axioms": "[]" + } + ], + "interpretation": "ContractChangeAccount separates finite scoped equality from deliberate revision with changed order/retry obligations and affected-party coverage. Missing operator/incorrect old limits fail; [99] demonstrates an intentionally out-of-scope historical difference; changing procedure text remains allowed. Actual notification, completeness of parties and all-input equivalence are not modeled.", + "special_limits": [] + }, + { + "target": "T33", + "case": "deliberate_revision_with_account", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.contractCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 843, + "axioms": "[]" + } + ], + "interpretation": "ContractChangeAccount separates finite scoped equality from deliberate revision with changed order/retry obligations and affected-party coverage. Missing operator/incorrect old limits fail; [99] demonstrates an intentionally out-of-scope historical difference; changing procedure text remains allowed. Actual notification, completeness of parties and all-input equivalence are not modeled.", + "special_limits": [] + }, + { + "target": "T33", + "case": "revision_missing_parties", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.contractCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 843, + "axioms": "[]" + } + ], + "interpretation": "ContractChangeAccount separates finite scoped equality from deliberate revision with changed order/retry obligations and affected-party coverage. Missing operator/incorrect old limits fail; [99] demonstrates an intentionally out-of-scope historical difference; changing procedure text remains allowed. Actual notification, completeness of parties and all-input equivalence are not modeled.", + "special_limits": [] + }, + { + "target": "T33", + "case": "retired_historical_behavior", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.contractCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 843, + "axioms": "[]" + } + ], + "interpretation": "ContractChangeAccount separates finite scoped equality from deliberate revision with changed order/retry obligations and affected-party coverage. Missing operator/incorrect old limits fail; [99] demonstrates an intentionally out-of-scope historical difference; changing procedure text remains allowed. Actual notification, completeness of parties and all-input equivalence are not modeled.", + "special_limits": [] + }, + { + "target": "T33", + "case": "alternative_procedure", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.contractCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 843, + "axioms": "[]" + } + ], + "interpretation": "ContractChangeAccount separates finite scoped equality from deliberate revision with changed order/retry obligations and affected-party coverage. Missing operator/incorrect old limits fail; [99] demonstrates an intentionally out-of-scope historical difference; changing procedure text remains allowed. Actual notification, completeness of parties and all-input equivalence are not modeled.", + "special_limits": [] + } + ] + }, + { + "id": "T34", + "kind": "theorem", + "statement": "Given equality of all identified contract observations in scope, a transformation preserves that identified contract; deliberate changed in-scope observations cannot be claimed preservation of that same contract and require revised-obligation/party account under domain satisfaction.", + "premises": [ + "Contract semantics and scope, total behavior on registered domain, at least one explicit distinguishing observation for revision, domain rule", + "finite examples reported finite." + ], + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "p3" + } + ], + "status": "accepted-bounded", + "prior_own_status": "conditional_theorem", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "contractPreservation returns the supplied universal in-scope equality proof, rather than deriving it from finite tests. changedObservationNotPreserved gives the counterexample implication; contractRevisionObligations eliminates the failed preservation branch of the assumed account. Finite order/retry cases illustrate the distinction. This is the correct conditional reading of the target, not an empirical proof from test success.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Engineering.contractPreservation", + "file": "CoreReader/Engineering/Domain.lean", + "line": 822, + "end": 825, + "kind": "theorem", + "axioms": "[]", + "exact_code": "theorem contractPreservation {Input Output : Type} (scope : Input → Prop)\n (old new : Input → Output) (observations : ∀ x, scope x → new x = old x) :\n PreservesOn scope old new := observations\n\n", + "full_type_record": { + "type": "Lean.Expr.forallE\n `Input\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `Output\n (Lean.Expr.sort (Lean.Level.succ (Lean.Level.zero)))\n (Lean.Expr.forallE\n `scope\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 1)\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `old\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 2)\n (Lean.Expr.bvar 2)\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `new\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.bvar 3)\n (Lean.Expr.bvar 3)\n (Lean.BinderInfo.default))\n (Lean.Expr.forallE\n `observations\n (Lean.Expr.forallE\n `x\n (Lean.Expr.bvar 4)\n (Lean.Expr.forallE\n (Lean.Name.mkNum `a._@._internal._hyg 0)\n (Lean.Expr.app (Lean.Expr.bvar 3) (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.bvar 5))\n (Lean.Expr.app (Lean.Expr.bvar 2) (Lean.Expr.bvar 1)))\n (Lean.Expr.app (Lean.Expr.bvar 3) (Lean.Expr.bvar 1)))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.PreservesOn []) (Lean.Expr.bvar 5))\n (Lean.Expr.bvar 4))\n (Lean.Expr.bvar 3))\n (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.implicit))\n (Lean.BinderInfo.implicit)", + "sha256": "d9078e49c446deddda26e669891464c695136710e6b34620ca8ee4f08bdafbed" + }, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.contractDistinctions", + "file": "CoreReader/Engineering/Domain.lean", + "line": 853, + "end": 867, + "kind": "theorem", + "axioms": "[]", + "exact_code": "theorem contractDistinctions :\n PreservesFinite orderedUnique orderedRefactor ∧\n ¬ PreservesFinite orderedUnique sortedUnique ∧\n retry originalContract 3 = false ∧ retry revisedContract 3 = true ∧\n ¬ PreservesContractFinite originalContract revisedContract ∧\n affectedParties originalContract revisedContract = [\"queue consumer\", \"queue operator\"] ∧\n ¬ ContractChangeAccount originalContract revisedContract\n { normalRevision with affected := [\"queue consumer\"] } ∧\n ¬ ContractChangeAccount originalContract revisedContract\n { normalRevision with oldFailureLimit := 5, recordedOldFailureLimit := 5 } ∧\n ContractChangeAccount originalContract revisedContract normalRevision ∧\n PreservesFinite orderedUnique retiredBehavior ∧ retiredBehavior [99] ≠ orderedUnique [99] := by decide\n\n/- Revision records time-indexed evidence rather than changing a past event.\nJudgment is choice under current evidence; forecast truth is a separate value. -/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.orderedRefactor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.sortedUnique []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.retry [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3))))))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.retry [])\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesContractFinite [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `String [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.affectedParties [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"queue consumer\")))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"queue operator\")))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `String []))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2260969961) \"_hygCtx\") \"_hyg\") 73)\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision [])\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.deliberate [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.revisedOrder [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `String []))\n (Lean.Expr.lit (Lean.Literal.strVal \"queue consumer\")))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `String []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.oldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.newFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedOldFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedNewFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.procedure [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 2260969961) \"_hygCtx\") \"_hyg\") 97)\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision [])\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.deliberate [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.revisedOrder [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.affected [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 5)))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.newFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 5)))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.recordedNewFailureLimit [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractRevision.procedure [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ContractChangeAccount [])\n (Lean.Expr.const `CoreReader.Engineering.originalContract []))\n (Lean.Expr.const `CoreReader.Engineering.revisedContract []))\n (Lean.Expr.const `CoreReader.Engineering.normalRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.retiredBehavior [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.retiredBehavior [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 99)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 99)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 99)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 99)))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `Nat []))))))))))))))", + "sha256": "bc0f83a82833ba24fc73f01ff24ac513e5ce42fec36a8195c70d516365a07a28" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T34", + "case": "order_preserving_refactor", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.contractPreservation", + "file": "CoreReader/Engineering/Domain.lean", + "line": 822, + "axioms": "[]" + }, + { + "name": "CoreReader.Engineering.contractDistinctions", + "file": "CoreReader/Engineering/Domain.lean", + "line": 853, + "axioms": "[]" + } + ], + "interpretation": "contractPreservation returns the supplied universal in-scope equality proof, rather than deriving it from finite tests. changedObservationNotPreserved gives the counterexample implication; contractRevisionObligations eliminates the failed preservation branch of the assumed account. Finite order/retry cases illustrate the distinction. This is the correct conditional reading of the target, not an empirical proof from test success.", + "special_limits": [] + }, + { + "target": "T34", + "case": "sorted_order_revision", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.changedObservationNotPreserved", + "file": "CoreReader/Engineering/Domain.lean", + "line": 826, + "axioms": "[]" + }, + { + "name": "CoreReader.Engineering.contractDistinctions", + "file": "CoreReader/Engineering/Domain.lean", + "line": 853, + "axioms": "[]" + } + ], + "interpretation": "contractPreservation returns the supplied universal in-scope equality proof, rather than deriving it from finite tests. changedObservationNotPreserved gives the counterexample implication; contractRevisionObligations eliminates the failed preservation branch of the assumed account. Finite order/retry cases illustrate the distinction. This is the correct conditional reading of the target, not an empirical proof from test success.", + "special_limits": [] + }, + { + "target": "T34", + "case": "changed_failure_obligation", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.contractRevisionObligations", + "file": "CoreReader/Engineering/Domain.lean", + "line": 832, + "axioms": "[]" + }, + { + "name": "CoreReader.Engineering.contractDistinctions", + "file": "CoreReader/Engineering/Domain.lean", + "line": 853, + "axioms": "[]" + } + ], + "interpretation": "contractPreservation returns the supplied universal in-scope equality proof, rather than deriving it from finite tests. changedObservationNotPreserved gives the counterexample implication; contractRevisionObligations eliminates the failed preservation branch of the assumed account. Finite order/retry cases illustrate the distinction. This is the correct conditional reading of the target, not an empirical proof from test success.", + "special_limits": [] + }, + { + "target": "T34", + "case": "outside_scope_difference", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.contractDistinctions", + "file": "CoreReader/Engineering/Domain.lean", + "line": 853, + "axioms": "[]" + } + ], + "interpretation": "contractPreservation returns the supplied universal in-scope equality proof, rather than deriving it from finite tests. changedObservationNotPreserved gives the counterexample implication; contractRevisionObligations eliminates the failed preservation branch of the assumed account. Finite order/retry cases illustrate the distinction. This is the correct conditional reading of the target, not an empirical proof from test success.", + "special_limits": [] + } + ] + }, + { + "id": "T35", + "kind": "specification", + "statement": "Changed evidence about expected changes, maintenance conditions, costs/objectives can justify revised design/priority application; revised judgment acknowledges material grounds changes and cannot retroactively relabel failed prediction success. Retention may be justified by alternatives lacking contribution or defeating objectives.", + "premises": [ + "Separate old/new evidence/time, prediction outcome and judgment, permission versus compulsory redesign", + "applicable alternatives and objective explicit." + ], + "sources": [ + { + "unit": "software-engineering.revision", + "clause": "p2" + }, + { + "unit": "software-engineering.revision", + "clause": "p1" + } + ], + "status": "accepted-bounded", + "prior_own_status": "qualified_revision_account", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Engineering.RevisionAccount", + "file": "CoreReader/Engineering/Domain.lean", + "line": 922, + "end": 923, + "kind": "abbrev", + "axioms": "[]", + "exact_code": "abbrev RevisionAccount (r : RevisionRecord) : Prop := RevisionAccountAgainst observedHistory r\n\n", + "full_type_record": { + "type": "Lean.Expr.forallE\n `r\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord [])\n (Lean.Expr.sort (Lean.Level.zero))\n (Lean.BinderInfo.default)", + "sha256": "865a4c6c542f07f6b0ce44a67e98175239ef389738b16bc6071ccebffae61c8b" + }, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.revisionCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 951, + "end": 961, + "kind": "theorem", + "axioms": "[propext]", + "exact_code": "theorem revisionCases :\n RevisionAccount revisionRecord ∧\n revisionRecord.old.forecast ≠ revisionRecord.current.forecast ∧\n revisionRecord.old.maintenance ≠ revisionRecord.current.maintenance ∧\n revisionRecord.old.maintainers ≠ revisionRecord.current.maintainers ∧\n revisionRecord.old.migrationCost ≠ revisionRecord.current.migrationCost ∧\n revisionRecord.old.objectiveCapacity ≠ revisionRecord.current.objectiveCapacity ∧\n revisionRecord.predictedBatchCount ≠ revisionRecord.actualBatchCount ∧\n RetentionJustified currentContinuing [.other \"quantum backend\"] ∧\n RetentionJustified (threatened .migration) [.migration] := by decide\n\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionAccount [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.forecast [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.forecast [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.maintenance [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.maintenance [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Maintainer [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.maintainers [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.maintainers [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.migrationCost [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.migrationCost [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.objectiveCapacity [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.objectiveCapacity [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.predictedBatchCount [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.actualBatchCount [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RetentionJustified [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"quantum backend\"))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RetentionJustified [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.threatened [])\n (Lean.Expr.const `CoreReader.Engineering.Burden.migration [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.const `CoreReader.Engineering.Change.migration []))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change [])))))))))))", + "sha256": "8e2008450f4c7a80eca24630a18e6c77bf570055daee2c75c2577987c06ff629" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T35", + "case": "revised_change_forecast", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.revisionCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 951, + "axioms": "[propext]" + } + ], + "interpretation": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign.", + "special_limits": [] + }, + { + "target": "T35", + "case": "changed_maintainers", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.revisionCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 951, + "axioms": "[propext]" + } + ], + "interpretation": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign.", + "special_limits": [] + }, + { + "target": "T35", + "case": "changed_cost", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.revisionCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 951, + "axioms": "[propext]" + } + ], + "interpretation": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign.", + "special_limits": [] + }, + { + "target": "T35", + "case": "changed_objective", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.revisionCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 951, + "axioms": "[propext]" + } + ], + "interpretation": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign.", + "special_limits": [] + }, + { + "target": "T35", + "case": "failed_prediction_preserved", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.historicalTamperingRejected", + "file": "CoreReader/Engineering/Domain.lean", + "line": 980, + "axioms": "[]" + }, + { + "name": "CoreReader.Engineering.failedHistoryNotRewritten", + "file": "CoreReader/Engineering/Domain.lean", + "line": 924, + "axioms": "[propext]" + } + ], + "interpretation": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign.", + "special_limits": [] + }, + { + "target": "T35", + "case": "justified_retention", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.revisionCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 951, + "axioms": "[propext]" + } + ], + "interpretation": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign.", + "special_limits": [] + } + ] + }, + { + "id": "T36", + "kind": "nonentailment", + "statement": "Revised judgment cannot make past failed prediction true; continued change, agreement and successful examples do not establish universal correctness; justified retention is compatible with domain/reflexive revision openness.", + "premises": [ + "Time-indexed prediction semantics invariant under report revision", + "finite successes with explicit broader failure", + "activity is open to criticism while choosing stability now." + ], + "sources": [ + { + "unit": "software-engineering.revision", + "clause": "p2" + }, + { + "unit": "software-engineering.revision", + "clause": "p1" + } + ], + "status": "accepted-bounded", + "prior_own_status": "bounded_countermodels_with_scope_limit", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "Prior finite no-retroactive-success/consensus/success examples are retained. A fresh same-object probe proves revisionFor sharedContext evolvable retains the old/current design choice while selfModel evolvable satisfies reflection; this makes the open-stable example explicit without turning all stability into a duty.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [ + { + "name": "CoreReader.Engineering.revisionLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 993, + "end": 1006, + "kind": "theorem", + "axioms": "[propext]", + "exact_code": "theorem revisionLimits :\n RevisionAccount revisionRecord ∧\n ¬ RevisionAccount { revisionRecord with reportedPredictionSucceeded := true } ∧\n revisionsMade.length = 3 ∧\n agreedBatch maintainers 21 5 = [3, 3, 3] ∧ liveBatch 21 5 = 5 ∧\n observations.all (fun p => staticBatch p.1 p.2 == liveBatch p.1 p.2) = true ∧\n staticBatch 21 5 ≠ liveBatch 21 5 ∧\n RevisionAccount stableRecord ∧ stableRecord.current.choice = stableRecord.old.choice ∧\n RetentionJustified currentContinuing [.other \"quantum backend\"] := by\n refine ⟨by decide, ?_, by decide, by decide, by decide, by decide,\n by decide, by decide, by decide, by decide⟩\n dsimp [RevisionAccount, RevisionAccountAgainst, observedHistory, MaterialGroundsChanged, revisionRecord, oldState, newState]\n decide\n\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionAccount [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionAccount [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 3857095740) \"_hygCtx\") \"_hyg\") 17)\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord [])\n (Lean.Expr.const `CoreReader.Engineering.revisionRecord [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.mk [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.software [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.recordedOld [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.recordedCurrent [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.predictedBatchCount [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.actualBatchCount [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `Bool.true []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.consideredChanges [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.criticizedDirections [])\n (Lean.Expr.bvar 0)))\n true))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Engineering.revisionsMade [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.agreedBatch [])\n (Lean.Expr.const `CoreReader.Engineering.maintainers []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.cons [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3)))))\n (Lean.Expr.app (Lean.Expr.const `List.nil [Lean.Level.zero]) (Lean.Expr.const `Nat [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.all [Lean.Level.zero])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat [])))\n (Lean.Expr.const `CoreReader.Engineering.observations []))\n (Lean.Expr.lam\n `p\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `BEq.beq [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instDecidableEqNat [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.staticBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.fst [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.fst [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.snd [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.bvar 0))))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.staticBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionAccount [])\n (Lean.Expr.const `CoreReader.Engineering.stableRecord [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.choice [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.current [])\n (Lean.Expr.const `CoreReader.Engineering.stableRecord []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionState.choice [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RevisionRecord.old [])\n (Lean.Expr.const `CoreReader.Engineering.stableRecord [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.RetentionJustified [])\n (Lean.Expr.const `CoreReader.Engineering.currentContinuing []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Change.other [])\n (Lean.Expr.lit (Lean.Literal.strVal \"quantum backend\"))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Change []))))))))))))", + "sha256": "071a3e5cddf46166eacbd56285cdb4abb9f11a94e50e8bf00f8bc100f01026d0" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T36", + "case": "past_failure_not_rewritten", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.historicalTamperingRejected", + "file": "CoreReader/Engineering/Domain.lean", + "line": 980, + "axioms": "[]" + }, + { + "name": "CoreReader.Engineering.failedHistoryNotRewritten", + "file": "CoreReader/Engineering/Domain.lean", + "line": 924, + "axioms": "[propext]" + } + ], + "interpretation": "Prior finite no-retroactive-success/consensus/success examples are retained. A fresh same-object probe proves revisionFor sharedContext evolvable retains the old/current design choice while selfModel evolvable satisfies reflection; this makes the open-stable example explicit without turning all stability into a duty.", + "special_limits": [] + }, + { + "target": "T36", + "case": "agreement_with_bad_case", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.revisionLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 993, + "axioms": "[propext]" + } + ], + "interpretation": "Prior finite no-retroactive-success/consensus/success examples are retained. A fresh same-object probe proves revisionFor sharedContext evolvable retains the old/current design choice while selfModel evolvable satisfies reflection; this makes the open-stable example explicit without turning all stability into a duty.", + "special_limits": [] + }, + { + "target": "T36", + "case": "local_success_global_failure", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.revisionLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 993, + "axioms": "[propext]" + } + ], + "interpretation": "Prior finite no-retroactive-success/consensus/success examples are retained. A fresh same-object probe proves revisionFor sharedContext evolvable retains the old/current design choice while selfModel evolvable satisfies reflection; this makes the open-stable example explicit without turning all stability into a duty.", + "special_limits": [] + }, + { + "target": "T36", + "case": "open_stable_design", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.revisionContextIdentity", + "file": "CoreReader/Engineering/Domain.lean", + "line": 1020, + "axioms": "[propext]" + }, + { + "name": "CoreReader.Engineering.currentSelfApplication", + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 161, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Prior finite no-retroactive-success/consensus/success examples are retained. A fresh same-object probe proves revisionFor sharedContext evolvable retains the old/current design choice while selfModel evolvable satisfies reflection; this makes the open-stable example explicit without turning all stability into a duty.", + "special_limits": [] + } + ] + }, + { + "id": "T37", + "kind": "theorem", + "statement": "With inherited and domain satisfaction in a shared applicable context, the priority and evolution-assessment methods remain objects of grounds, consistency and reflexive criticism/revision; domain success cannot exempt its rule.", + "premises": [ + "Same domain-rule object assessed via inherited predicates", + "explicit relevant applicability", + "user adoption choice distinguished from metalevel correctness." + ], + "sources": [ + { + "unit": "organon.relationships.roles", + "clause": "p3" + }, + { + "unit": "extensions", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.revision", + "clause": "p2" + } + ], + "status": "accepted-bounded", + "prior_own_status": "partial_same_rule_grounding", + "prior_other_reviewer_status": "pending-correspondence", + "independent_r3_assessment": "Resolved in the same fixed shared context. priorityValueMeaning proves candidate-by-candidate equivalence between the adopted evolvable selection commitment and actual EvolutionPriority; priorityGrounds transports value support through that explicit equality while preserving the value task. The theorem now returns that exact priority claim's Grounds, domain-content membership and complete-theory consistency, in addition to reflection. The equivalence depends on current applicability/no-departure and must not be generalized to other contexts.", + "reuse": "Source/target text and unchanged nonblank definitions reused; affected transitive composition was rereviewed.", + "declarations": [ + { + "name": "CoreReader.Engineering.priorityRemainsReflexive", + "file": "CoreReader/Engineering/Integration.lean", + "line": 467, + "end": 492, + "kind": "theorem", + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "exact_code": "theorem priorityRemainsReflexive (ctx : Context) (chosen : Candidate)\n (inherited : Inherited ctx chosen) (domain : DomainSatisfied ctx chosen)\n (applicable : PriorityConditions ctx) (noDeparture : ¬ JustifiedDeparture ctx .evolvable) :\n chosen = .evolvable ∧\n (.priority : ReviewObject) ∈ (selfModel chosen).objects ∧\n reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self\n (selfModel chosen).performed ∧\n (∀ principle, valueSpecification (governancePosition principle)) ∧\n Grounds012 (EvolutionPriority ctx) canonicalArticulation\n [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) ∧\n ownTheory chosen (ownNormClaim chosen .domain) ∧\n consistencySpecification (engineeringSnapshot .evolvable 0)\n (engineeringSnapshot chosen 1) true := by\n have selected := (priorityWhenApplicable ctx chosen domain.2.1 applicable noDeparture).1\n refine ⟨selected, ?_, inherited.reflection, inherited.ownPrincipleGrounds,\n ?_, allNormativeContentHeld chosen .domain selected, inherited.consistency⟩\n · subst chosen; decide\n · rw [inherited.sameContext]\n exact priorityGrounds\n\n/-- organon-map CoreReader.Engineering.priorityReflexiveCases\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\nextensions#p1 sha256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66\nsoftware-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\nsoftware-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99\n-/\n", + "full_type_record": { + "type": "Lean.Expr.forallE\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.forallE\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.forallE\n `inherited\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.Inherited []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))\n (Lean.Expr.forallE\n `domain\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.DomainSatisfied []) (Lean.Expr.bvar 2))\n (Lean.Expr.bvar 1))\n (Lean.Expr.forallE\n `applicable\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.PriorityConditions []) (Lean.Expr.bvar 3))\n (Lean.Expr.forallE\n `noDeparture\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture []) (Lean.Expr.bvar 4))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.bvar 4))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.objects [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 4))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.priority [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.reflexivitySpecification [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Outcome [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.rules [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 4))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.self [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 4))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.performed [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.selfModel []) (Lean.Expr.bvar 4)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.forallE\n `principle\n (Lean.Expr.const `CoreReader.Engineering.CoreCommitment [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.valueSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.governancePosition [])\n (Lean.Expr.bvar 0)))\n (Lean.BinderInfo.default)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.bvar 5)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.value [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.AssessmentTask.value [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.ownTheory []) (Lean.Expr.bvar 4))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownNormClaim [])\n (Lean.Expr.bvar 4))\n (Lean.Expr.const `CoreReader.Engineering.OwnNorm.domain []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.consistencySpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `CoreReader.Engineering.OwnFact []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringSnapshot [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.engineeringSnapshot [])\n (Lean.Expr.bvar 4))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.const `Bool.true []))))))))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default))\n (Lean.BinderInfo.default)", + "sha256": "285b4edb7397d25ccc631b194a1ff8ebb5204df450d52ec8eaf0685519b289c2" + }, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.priorityReflexiveCases", + "file": "CoreReader/Engineering/Integration.lean", + "line": 493, + "end": 556, + "kind": "theorem", + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "exact_code": "theorem priorityReflexiveCases :\n (.priority : ReviewObject) ∈ (selfModel .evolvable).objects ∧\n objectTest .priority (.evolvable, 10) = true ∧\n (selfModel .evolvable).performed ⟨0, 1⟩ ⟨0, .priority, .revision⟩\n ((selfModel .evolvable).input ⟨0, .priority, .revision⟩)\n (.assessed .supportedWithinScope) ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧\n objectTest .evolutionMethod (.evolvable, 10) = true ∧\n objectTest .evolutionMethod (.evolvable, 5) = false ∧\n Grounds012 (EvolutionPriority sharedContext) canonicalArticulation\n [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .assessmentRule, .revision⟩) = .counterexample := by\n refine ⟨by decide, by decide, ?_, (actualSelfCriticism .evolvable).2.2.1,\n (actualSelfCriticism .evolvable).1, (actualSelfCriticism .evolvable).2.1,\n priorityGrounds, (ownRuleContentVariation .evolvable).2.2.2.2.1⟩\n exact ⟨⟨rfl, by decide⟩, rfl, .assessment, rfl, rfl⟩\n\n/- The witness is nonempty and satisfies the entire represented inherited and\ndomain bundles in the very same continuing activity, with active priority. -/\n/-- organon-map CoreReader.Engineering.jointWitness\norganon.charter.overview#p2 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c\norganon.charter.overview#p3 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c\norganon.charter.self-transcendence#p1 sha256 f4ca590e2ae15e3882f70c7b2bc46a8911c97cee547c8b137b5493fbf862c8c0\norganon.charter.self-transcendence.orientation#p1 sha256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf\norganon.charter.self-transcendence.non-finality#p1 sha256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8\norganon.charter.self-transcendence.limits#p1 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d\norganon.charter.self-transcendence.limits#p2 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d\norganon.charter.consistency#p1 sha256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42\norganon.charter.consistency.meaning#p1 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75\norganon.charter.reflexivity#p1 sha256 13293b45c2fa89068c68ae7ef3c5df38f0efadb3ef3873d78a5ba67d9691a757\norganon.charter.reflexivity.meaning#p1 sha256 8a2caede01a43d8b6c60b54c78ac089c51868e9956f316948077ccee2e45c9cc\norganon.charter.reflexivity.limits#p1 sha256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc\norganon.grounds#p1 sha256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6\norganon.grounds.assessment#p1 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.scope#p1 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.scope#p2 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.scope#p3 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.capabilities#p1 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0\norganon.grounds.capabilities#p2 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0\norganon.grounds.implementations#p1 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c\norganon.grounds.implementations#p2 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c\norganon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870\norganon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\nextensions#p1 sha256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66\nsoftware-engineering.purpose#p1 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.purpose#p2 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-meaning#p1 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6\nsoftware-engineering.evolution-meaning#p2 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6\nsoftware-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\nsoftware-engineering.structural-judgment#p2 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\nsoftware-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\nsoftware-engineering.revision#p1 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99\nsoftware-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.objects [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.priority [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.objectTest [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.priority []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 10)))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.performed [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Agency.PrincipleKey.mk [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 1)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 1))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.priority []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.priority []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Outcome.assessed [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict.supportedWithinScope []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.evaluate [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.evolutionMethod []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision [])))))\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict.counterexample [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.objectTest [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.evolutionMethod []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 10)))))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.objectTest [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.evolutionMethod []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Prod.mk [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.const `CoreReader.Engineering.sharedContext [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet.value [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.AssessmentTask.value [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.evaluate [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.input [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Target.mk [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 0)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 0)))))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.assessmentRule []))\n (Lean.Expr.const `CoreReader.Agency.Phase.revision [])))))\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Verdict.counterexample []))))))))", + "sha256": "2be55699c66ab5ba0f6310f298e19b890de4caef622e0d69676f2d6a7a3b5170" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T37", + "case": "priority_self_assessment", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.priorityRemainsReflexive", + "file": "CoreReader/Engineering/Integration.lean", + "line": 467, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + }, + { + "name": "CoreReader.Engineering.priorityReflexiveCases", + "file": "CoreReader/Engineering/Integration.lean", + "line": 493, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Resolved in the same fixed shared context. priorityValueMeaning proves candidate-by-candidate equivalence between the adopted evolvable selection commitment and actual EvolutionPriority; priorityGrounds transports value support through that explicit equality while preserving the value task. The theorem now returns that exact priority claim's Grounds, domain-content membership and complete-theory consistency, in addition to reflection. The equivalence depends on current applicability/no-departure and must not be generalized to other contexts.", + "special_limits": [] + }, + { + "target": "T37", + "case": "method_self_criticism", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.actualSelfCriticism", + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 170, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + }, + { + "name": "CoreReader.Engineering.ownRuleContentVariation", + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 204, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved in the same fixed shared context. priorityValueMeaning proves candidate-by-candidate equivalence between the adopted evolvable selection commitment and actual EvolutionPriority; priorityGrounds transports value support through that explicit equality while preserving the value task. The theorem now returns that exact priority claim's Grounds, domain-content membership and complete-theory consistency, in addition to reflection. The equivalence depends on current applicability/no-departure and must not be generalized to other contexts.", + "special_limits": [ + "The empty-tested-list criticism concerns the sample-aware local assessmentRuleTest contract; it is not a philosophical demand for empirical samples in every judgment." + ] + }, + { + "target": "T37", + "case": "no_selfproof_from_success", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.priorityReflexiveCases", + "file": "CoreReader/Engineering/Integration.lean", + "line": 493, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + }, + { + "name": "CoreReader.Engineering.proposedRuleRevision", + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 218, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "Resolved in the same fixed shared context. priorityValueMeaning proves candidate-by-candidate equivalence between the adopted evolvable selection commitment and actual EvolutionPriority; priorityGrounds transports value support through that explicit equality while preserving the value task. The theorem now returns that exact priority claim's Grounds, domain-content membership and complete-theory consistency, in addition to reflection. The equivalence depends on current applicability/no-departure and must not be generalized to other contexts.", + "special_limits": [ + "The empty-tested-list criticism concerns the sample-aware local assessmentRuleTest contract; it is not a philosophical demand for empirical samples in every judgment." + ] + } + ] + }, + { + "id": "T38", + "kind": "satisfiability", + "statement": "USER ADDITIONAL STRONG OBJECTIVE: one content-bearing nonempty system/context jointly satisfies every represented inherited and domain commitment, with a continuing lifecycle, actual applicable priority and evolution chosen despite additional present abstraction complexity.", + "premises": [ + "Common context/subjects/claims/reasons/alternatives", + "shared nontrivial consequence relation", + "actual empirical/inferential/value duties relevant and fulfilled where represented", + "successor+agent maintenance pathways, credible design-change direction, satisfied necessary requirements, no defeating cost threat. Whole Inherited and Domain interfaces used, not subset." + ], + "sources": [ + { + "unit": "organon.charter.overview", + "clause": "p2" + }, + { + "unit": "organon.charter.overview", + "clause": "p3" + }, + { + "unit": "organon.charter.self-transcendence", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.orientation", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.non-finality", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity.limits", + "clause": "p1" + }, + { + "unit": "organon.grounds", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + }, + { + "unit": "organon.grounds.scope", + "clause": "p1" + }, + { + "unit": "organon.grounds.scope", + "clause": "p2" + }, + { + "unit": "organon.grounds.scope", + "clause": "p3" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p1" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p2" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p1" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p2" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + }, + { + "unit": "extensions", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p2" + }, + { + "unit": "software-engineering.purpose", + "clause": "p3" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p2" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p2" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p3" + }, + { + "unit": "software-engineering.revision", + "clause": "p1" + }, + { + "unit": "software-engineering.revision", + "clause": "p2" + } + ], + "status": "accepted-bounded", + "prior_own_status": "kernel_witness_source_composition_pending", + "prior_other_reviewer_status": "pending-correspondence", + "independent_r3_assessment": "Accepted as the requested bounded inhabitation witness after rechecking expanded Inherited and ownTheory, not merely its unchanged exterior theorem statement. The same evolvable candidate/context satisfies original necessary requirements, applicable priority/no threat, actual maintainer paths, full held fact/norm content, original support tasks and actual self-rule reflection. Source interpretation remains a revisable finite model; no empirical or philosophical universal correctness follows.", + "reuse": "Source/target text and unchanged nonblank definitions reused; affected transitive composition was rereviewed.", + "declarations": [ + { + "name": "CoreReader.Engineering.jointWitness", + "file": "CoreReader/Engineering/Integration.lean", + "line": 557, + "end": 585, + "kind": "theorem", + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "exact_code": "theorem jointWitness :\n ∃ ctx : Context, ∃ chosen : Candidate,\n ctx = sharedContext ∧ chosen = .evolvable ∧\n Inherited ctx chosen ∧ DomainSatisfied ctx chosen ∧\n PriorityConditions ctx ∧ ¬ HasThreat ctx .evolvable ∧\n abstractionComplexity .presentSimple < abstractionComplexity chosen ∧\n CanChange ctx.activity chosen .successor .designRevision ∧\n CanChange ctx.activity chosen .agent .designRevision ∧\n ownTheory chosen (ownFactClaim chosen .selected) ∧\n (.commitment .grounds : ReviewObject) ∈ (selfModel chosen).objects ∧\n Admissible (ownTheory chosen) (comparisonContext chosen) chosen := by\n exact ⟨sharedContext, .evolvable, rfl, rfl,\n inheritedCurrent .evolvable (Or.inr rfl), currentDomainSatisfied,\n currentPriorityConditions, currentNoThreat.1, by decide, by decide, by decide,\n (nonemptyOwnObjects .evolvable).1, (nonemptyOwnObjects .evolvable).2.2.2,\n currentAdmissible .evolvable (Or.inr rfl)⟩\n\n/- The countermodel adopts a supported present-simplicity value and actually\nchooses that option. Every inherited duty still holds. The domain conditions\nare active; neither lifecycle nor threatened costs supplies an escape. -/\n/-- organon-map CoreReader.Engineering.inheritedDoesNotEntailPriority\norganon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\nextensions#p1 sha256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66\nsoftware-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\n-/\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Context []))\n (Lean.Expr.lam\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.lam\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Context []))\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.sharedContext [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.Inherited []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.DomainSatisfied []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.PriorityConditions []) (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.HasThreat []) (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `LT.lt [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownTheory [])\n (Lean.Expr.bvar 0))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownFactClaim [])\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.OwnFact.selected []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Membership.mem [Lean.Level.zero, Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.instMembership [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Reflection.Model.objects [])\n (Lean.Expr.const `CoreReader.Engineering.ReviewCase []))\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selfModel [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ReviewObject.commitment [])\n (Lean.Expr.const `CoreReader.Engineering.CoreCommitment.grounds []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Logic.Admissible [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.const `CoreReader.Engineering.OwnFact []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.ownTheory [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.comparisonContext [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.bvar 0)))))))))))))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default))", + "sha256": "56d1bd97b0ac6c069484812a2a975dc185a905a24ee133a780b5f23a7fdc0b59" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T38", + "case": "joint_all_inherited_and_domain", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.jointWitness", + "file": "CoreReader/Engineering/Integration.lean", + "line": 557, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Accepted as the requested bounded inhabitation witness after rechecking expanded Inherited and ownTheory, not merely its unchanged exterior theorem statement. The same evolvable candidate/context satisfies original necessary requirements, applicable priority/no threat, actual maintainer paths, full held fact/norm content, original support tasks and actual self-rule reflection. Source interpretation remains a revisable finite model; no empirical or philosophical universal correctness follows.", + "special_limits": [] + }, + { + "target": "T38", + "case": "same_context_identity", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.jointWitness", + "file": "CoreReader/Engineering/Integration.lean", + "line": 557, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Accepted as the requested bounded inhabitation witness after rechecking expanded Inherited and ownTheory, not merely its unchanged exterior theorem statement. The same evolvable candidate/context satisfies original necessary requirements, applicable priority/no threat, actual maintainer paths, full held fact/norm content, original support tasks and actual self-rule reflection. Source interpretation remains a revisable finite model; no empirical or philosophical universal correctness follows.", + "special_limits": [] + }, + { + "target": "T38", + "case": "nonempty_claims_and_principles", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.jointWitness", + "file": "CoreReader/Engineering/Integration.lean", + "line": 557, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + }, + { + "name": "CoreReader.Engineering.allNormativeContentHeld", + "file": "CoreReader/Engineering/Integration.lean", + "line": 293, + "axioms": "[propext]" + } + ], + "interpretation": "Accepted as the requested bounded inhabitation witness after rechecking expanded Inherited and ownTheory, not merely its unchanged exterior theorem statement. The same evolvable candidate/context satisfies original necessary requirements, applicable priority/no threat, actual maintainer paths, full held fact/norm content, original support tasks and actual self-rule reflection. Source interpretation remains a revisable finite model; no empirical or philosophical universal correctness follows.", + "special_limits": [] + }, + { + "target": "T38", + "case": "active_evolution_priority", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.jointWitness", + "file": "CoreReader/Engineering/Integration.lean", + "line": 557, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Accepted as the requested bounded inhabitation witness after rechecking expanded Inherited and ownTheory, not merely its unchanged exterior theorem statement. The same evolvable candidate/context satisfies original necessary requirements, applicable priority/no threat, actual maintainer paths, full held fact/norm content, original support tasks and actual self-rule reflection. Source interpretation remains a revisable finite model; no empirical or philosophical universal correctness follows.", + "special_limits": [] + }, + { + "target": "T38", + "case": "content_bearing_maintainer_change", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.jointWitness", + "file": "CoreReader/Engineering/Integration.lean", + "line": 557, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + }, + { + "name": "CoreReader.Engineering.actualCapabilityContrast", + "file": "CoreReader/Engineering/Integration.lean", + "line": 67, + "axioms": "[propext]" + } + ], + "interpretation": "Accepted as the requested bounded inhabitation witness after rechecking expanded Inherited and ownTheory, not merely its unchanged exterior theorem statement. The same evolvable candidate/context satisfies original necessary requirements, applicable priority/no threat, actual maintainer paths, full held fact/norm content, original support tasks and actual self-rule reflection. Source interpretation remains a revisable finite model; no empirical or philosophical universal correctness follows.", + "special_limits": [] + } + ] + }, + { + "id": "T39", + "kind": "nonentailment", + "statement": "USER ADDITIONAL STRONG OBJECTIVE: a countermodel satisfies all represented inherited commitments while genuine domain-priority applicability holds and domain evolution priority is not adopted; proves non-entailment in the disclosed representation.", + "premises": [ + "Same common context as all inherited duties", + "continuing lifecycle (not temporary), supported credible evolution advantage including design revision, requirements satisfied, no concrete defeating cost threat, present-simplicity preference actually selected/adopted, grounded alternative value reasons consistent with Core, assessment not substituted for adoption." + ], + "sources": [ + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + }, + { + "unit": "extensions", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "status": "accepted-bounded", + "prior_own_status": "bounded_nonentailment_witness", + "prior_other_reviewer_status": "pending-correspondence", + "independent_r3_assessment": "Accepted as the requested bounded non-entailment witness with every original strong branch preserved. The same continuing shared context has real encoded applicability/advantage and no lifecycle/cost escape; presentSimple adopts a separately grounded simplicity value and satisfies expanded inherited duties yet fails the extra priority. normApplies records adoption of the additional domain norm, not disappearance of its actual PriorityConditions. This distinction is central to the source's additional-value claim.", + "reuse": "Source/target text and unchanged nonblank definitions reused; affected transitive composition was rereviewed.", + "declarations": [ + { + "name": "CoreReader.Engineering.inheritedDoesNotEntailPriority", + "file": "CoreReader/Engineering/Integration.lean", + "line": 586, + "end": 608, + "kind": "theorem", + "axioms": "[propext,\n Classical.choice.{u},\n Quot.sound.{u}]", + "exact_code": "theorem inheritedDoesNotEntailPriority :\n ∃ ctx : Context, ∃ chosen : Candidate,\n ctx = sharedContext ∧ chosen = .presentSimple ∧\n Inherited ctx chosen ∧ PriorityConditions ctx ∧\n Continuing ctx.activity ∧ ¬ BoundedLifecycle ctx.activity ∧\n ¬ HasThreat ctx .evolvable ∧ ¬ JustifiedDeparture ctx .evolvable ∧\n Meets ctx.required (ctx.profiles .presentSimple) ∧\n Meets ctx.required (ctx.profiles .evolvable) ∧\n credible ctx.evidence .designRevision ∧\n CanChange ctx.activity .evolvable .successor .designRevision ∧\n CanChange ctx.activity .evolvable .agent .designRevision ∧\n changeWork .evolvable .designRevision < changeWork chosen .designRevision ∧\n abstractionComplexity chosen < abstractionComplexity .evolvable ∧\n valueSpecification (selectionPosition chosen) ∧\n (selectionPosition chosen).commitment chosen ∧\n ¬ EvolutionPriority ctx chosen := by\n exact ⟨sharedContext, .presentSimple, rfl, rfl,\n inheritedCurrent .presentSimple (Or.inl rfl), currentPriorityConditions,\n by decide, by decide, currentNoThreat.1, currentNoThreat.2,\n by decide, by decide, by decide, by decide, by decide, by decide, by decide,\n selectionGrounded .presentSimple (Or.inl rfl), rfl, currentSimpleViolates⟩\n\nend CoreReader.Engineering\n", + "full_type_record": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Context []))\n (Lean.Expr.lam\n `ctx\n (Lean.Expr.const `CoreReader.Engineering.Context [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.lam\n `chosen\n (Lean.Expr.const `CoreReader.Engineering.Candidate [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Context []))\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.sharedContext [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.Inherited []) (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.PriorityConditions []) (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Continuing [])\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.Context.activity []) (Lean.Expr.bvar 1))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.BoundedLifecycle [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 1)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `CoreReader.Engineering.HasThreat []) (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.JustifiedDeparture [])\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.required [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.profiles [])\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Meets [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.required [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.profiles [])\n (Lean.Expr.bvar 1))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.credible [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.evidence [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.successor []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.CanChange [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.Context.activity [])\n (Lean.Expr.bvar 1)))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Maintainer.agent []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `LT.lt [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.bvar 0))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `LT.lt [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instLTNat []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.abstractionComplexity [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.valueSpecification [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ValuePosition.commitment [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.selectionPosition [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EvolutionPriority [])\n (Lean.Expr.bvar 1))\n (Lean.Expr.bvar 0))))))))))))))))))))\n (Lean.BinderInfo.default)))\n (Lean.BinderInfo.default))", + "sha256": "ad1b1b45257f57a53567b08bc87eb32bd6d8acf8395e9762a684c1116f270197" + }, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "semantic_cases": [ + { + "target": "T39", + "case": "all_inherited_applicable_domain_not_adopted", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedDoesNotEntailPriority", + "file": "CoreReader/Engineering/Integration.lean", + "line": 586, + "axioms": "[propext,\n Classical.choice.{u},\n Quot.sound.{u}]" + } + ], + "interpretation": "Accepted as the requested bounded non-entailment witness with every original strong branch preserved. The same continuing shared context has real encoded applicability/advantage and no lifecycle/cost escape; presentSimple adopts a separately grounded simplicity value and satisfies expanded inherited duties yet fails the extra priority. normApplies records adoption of the additional domain norm, not disappearance of its actual PriorityConditions. This distinction is central to the source's additional-value claim.", + "special_limits": [] + }, + { + "target": "T39", + "case": "no_temporary_escape", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedDoesNotEntailPriority", + "file": "CoreReader/Engineering/Integration.lean", + "line": 586, + "axioms": "[propext,\n Classical.choice.{u},\n Quot.sound.{u}]" + } + ], + "interpretation": "Accepted as the requested bounded non-entailment witness with every original strong branch preserved. The same continuing shared context has real encoded applicability/advantage and no lifecycle/cost escape; presentSimple adopts a separately grounded simplicity value and satisfies expanded inherited duties yet fails the extra priority. normApplies records adoption of the additional domain norm, not disappearance of its actual PriorityConditions. This distinction is central to the source's additional-value claim.", + "special_limits": [] + }, + { + "target": "T39", + "case": "no_cost_escape", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedDoesNotEntailPriority", + "file": "CoreReader/Engineering/Integration.lean", + "line": 586, + "axioms": "[propext,\n Classical.choice.{u},\n Quot.sound.{u}]" + } + ], + "interpretation": "Accepted as the requested bounded non-entailment witness with every original strong branch preserved. The same continuing shared context has real encoded applicability/advantage and no lifecycle/cost escape; presentSimple adopts a separately grounded simplicity value and satisfies expanded inherited duties yet fails the extra priority. normApplies records adoption of the additional domain norm, not disappearance of its actual PriorityConditions. This distinction is central to the source's additional-value claim.", + "special_limits": [] + }, + { + "target": "T39", + "case": "genuine_priority_failure", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedDoesNotEntailPriority", + "file": "CoreReader/Engineering/Integration.lean", + "line": 586, + "axioms": "[propext,\n Classical.choice.{u},\n Quot.sound.{u}]" + } + ], + "interpretation": "Accepted as the requested bounded non-entailment witness with every original strong branch preserved. The same continuing shared context has real encoded applicability/advantage and no lifecycle/cost escape; presentSimple adopts a separately grounded simplicity value and satisfies expanded inherited duties yet fails the extra priority. normApplies records adoption of the additional domain norm, not disappearance of its actual PriorityConditions. This distinction is central to the source's additional-value claim.", + "special_limits": [] + }, + { + "target": "T39", + "case": "inherited_grounds_for_other_value", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedDoesNotEntailPriority", + "file": "CoreReader/Engineering/Integration.lean", + "line": 586, + "axioms": "[propext,\n Classical.choice.{u},\n Quot.sound.{u}]" + }, + { + "name": "CoreReader.Engineering.selectionGrounded", + "file": "CoreReader/Engineering/Values.lean", + "line": 219, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Accepted as the requested bounded non-entailment witness with every original strong branch preserved. The same continuing shared context has real encoded applicability/advantage and no lifecycle/cost escape; presentSimple adopts a separately grounded simplicity value and satisfies expanded inherited duties yet fails the extra priority. normApplies records adoption of the additional domain norm, not disappearance of its actual PriorityConditions. This distinction is central to the source's additional-value claim.", + "special_limits": [] + } + ] + }, + { + "id": "T40", + "kind": "boundary", + "statement": "Formal specification/conditional proofs and finite witnesses do not establish empirical adequacy of lifecycle forecasts, support relevance, future maintainability, value superiority or universal philosophical correctness; representation choices remain disclosed and revisable.", + "premises": [ + "Every conditional result carries full mathematical premises", + "finite cases and source correspondence judgments are separate", + "difficult agreed theorem cannot be reclassified boundary to claim completion." + ], + "sources": [ + { + "unit": "organon.preamble", + "clause": "p1" + }, + { + "unit": "organon.preamble", + "clause": "p2" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p2" + }, + { + "unit": "organon.grounds", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + }, + { + "unit": "organon.grounds.scope", + "clause": "p2" + }, + { + "unit": "organon.grounds.scope", + "clause": "p3" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p1" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p2" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p1" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + }, + { + "unit": "extensions", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p2" + }, + { + "unit": "software-engineering.purpose", + "clause": "p3" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p2" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p2" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p3" + }, + { + "unit": "software-engineering.revision", + "clause": "p1" + }, + { + "unit": "software-engineering.revision", + "clause": "p2" + } + ], + "status": "accepted-documentary-boundary", + "prior_own_status": "documentary_boundary", + "prior_other_reviewer_status": "accepted-bounded", + "independent_r3_assessment": "Maintain source authority and separate normative specification, conditional theorem, finite witness, actual measurement, interpretation and adoption. No unseen final reader edition was assessed in this initial comparison. Disclosed abstraction does not automatically discharge a required semantic case or permit relabeling a difficult target as a boundary.", + "reuse": "Earlier source-aware explanation reused where exact nonblank code matches; current declarations reaudited.", + "declarations": [], + "semantic_cases": [] + } + ], + "source_clauses": [ + { + "unit": "organon.preamble", + "clause": "p1", + "exact_source": "This is a statement of Software Engineering Organon’s adopted philosophy. It expresses commitments, not factual assertions about every system or a proof of universal correctness.", + "source_excerpt_verified": true, + "registered_declarations": [], + "targets": [ + "T01", + "T40" + ], + "target_dispositions": { + "T01": "documentary_boundary", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Documentary/structural text remains nonformal.", + "r3_target_statuses": { + "T01": "accepted-documentary-boundary", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.preamble", + "clause": "p2", + "exact_source": "The quoted provisions, their meanings, and their conditions of application form the core. The charter and Grounds constrain one another; their grouping establishes neither a deductive hierarchy nor an order of priority. [Rationale](docs/rationale.md) supplies arguments and cases without adding obligations to this core. Skills are revisable applications under the repository’s stated objectives and constraints, not part of the philosophical commitments themselves.", + "source_excerpt_verified": true, + "registered_declarations": [], + "targets": [ + "T01", + "T40" + ], + "target_dispositions": { + "T01": "documentary_boundary", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Documentary/structural text remains nonformal.", + "r3_target_statuses": { + "T01": "accepted-documentary-boundary", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.charter.overview", + "clause": "p1", + "exact_source": "**Self-Transcendence · Internal Consistency · Reflexivity**", + "source_excerpt_verified": true, + "registered_declarations": [], + "targets": [ + "T01" + ], + "target_dispositions": { + "T01": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Documentary/structural text remains nonformal.", + "r3_target_statuses": { + "T01": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.charter.overview", + "clause": "p2", + "exact_source": "> A system is intrinsically oriented toward expanding what it can understand and construct. It brings itself and its principles within the scope of generation and assessment, with internal consistency constraining this process.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T01", + "T02", + "T38" + ], + "target_dispositions": { + "T01": "documentary_boundary", + "T02": "bounded_specification", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T01": "accepted-documentary-boundary", + "T02": "accepted-bounded", + "T38": "accepted-bounded" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.charter.overview", + "clause": "p3", + "exact_source": "The overview connects three distinct requirements: self-transcendence establishes a generative orientation and refuses to treat existing forms as final, internal consistency constrains judgments held simultaneously, and reflexivity brings the system and its principles within the scope of their own generation and assessment. The provisions below specify the conditions for each.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T01", + "T02", + "T38" + ], + "target_dispositions": { + "T01": "documentary_boundary", + "T02": "bounded_specification", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T01": "accepted-documentary-boundary", + "T02": "accepted-bounded", + "T38": "accepted-bounded" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.charter.self-transcendence", + "clause": "p1", + "exact_source": "> A system is intrinsically oriented toward expanding what it can understand and construct. It does not regard any existing form as the endpoint of generation.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T02", + "T38" + ], + "target_dispositions": { + "T02": "bounded_specification", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T02": "accepted-bounded", + "T38": "accepted-bounded" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.charter.self-transcendence.orientation", + "clause": "p1", + "exact_source": "A commitment to keeping generative possibilities open is distinct from valuing their expansion. A system has an intrinsic orientation when it regards that expansion as worth pursuing. Merely permitting change does not fully express this orientation.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases", + "CoreReader.Adopted.generationLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T02", + "T03", + "T38" + ], + "target_dispositions": { + "T02": "bounded_specification", + "T03": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T02": "accepted-bounded", + "T03": "accepted-bounded", + "T38": "accepted-bounded" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.charter.self-transcendence.non-finality", + "clause": "p1", + "exact_source": "Refusing to regard an existing form as an endpoint keeps it open to being surpassed. “Existing form” includes a system’s current organization, methods, and principles, not only its appearance or artifacts. These remain within the scope of possible change; their revisability does not guarantee actual progress.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases", + "CoreReader.Adopted.generationLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T02", + "T03", + "T38" + ], + "target_dispositions": { + "T02": "bounded_specification", + "T03": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T02": "accepted-bounded", + "T03": "accepted-bounded", + "T38": "accepted-bounded" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p1", + "exact_source": "Whether progress has actually occurred remains a separate judgment. Having the orientation does not guarantee progress. Progress cannot be established merely by an increase in the number of artifacts, levels of abstraction, or terms.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.generationLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T03", + "T38" + ], + "target_dispositions": { + "T03": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T03": "accepted-bounded", + "T38": "accepted-bounded" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p2", + "exact_source": "- “Intrinsic orientation” expresses Organon’s philosophical commitment; it does not assert that all systems in fact develop autonomously.\n- Self-transcendence does not imply independence from external experience, knowledge, or collaboration, nor does it guarantee autonomous execution or self-improvement.\n- Refusing to regard an existing form as an endpoint does not require every action to produce change. Justified stability can coexist with a generative orientation.\n- Whether transcendence expands what can be understood and constructed requires discernible grounds; a system’s own claim of generation does not establish actual achievement.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases", + "CoreReader.Adopted.generationLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T02", + "T03", + "T38", + "T40" + ], + "target_dispositions": { + "T02": "bounded_specification", + "T03": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T02": "accepted-bounded", + "T03": "accepted-bounded", + "T38": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.charter.consistency", + "clause": "p1", + "exact_source": "> The principles and judgments a system holds simultaneously, together with their implications, must not yield contradictory judgments on the same question under the same assumptions, meanings of terms, and scope of application.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.consistencySpecification", + "CoreReader.Adopted.consistencyCases", + "CoreReader.Adopted.consistencyConsequences", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T04", + "T05", + "T38" + ], + "target_dispositions": { + "T04": "bounded_specification", + "T05": "conditional_theorem", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T04": "accepted-bounded", + "T05": "accepted-bounded", + "T38": "accepted-bounded" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p1", + "exact_source": "“Held simultaneously” specifies which principles, judgments, and implications must hold together. Revision may withdraw an earlier judgment; old and new principles need not remain compatible forever. When a change has occurred, that change cannot be represented as though it had not occurred.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.consistencySpecification", + "CoreReader.Adopted.consistencyCases", + "CoreReader.Adopted.consistencyConsequences", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T04", + "T05", + "T38" + ], + "target_dispositions": { + "T04": "bounded_specification", + "T05": "conditional_theorem", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T04": "accepted-bounded", + "T05": "accepted-bounded", + "T38": "accepted-bounded" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p2", + "exact_source": "“The same assumptions, meanings of terms, and scope of application” specifies the basis for comparing judgments. Divergent judgments under different conditions do not automatically constitute contradictions. Nor can unacknowledged changes in assumptions, meanings, or scope be used to conceal an existing contradiction.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.consistencySpecification", + "CoreReader.Adopted.consistencyCases", + "CoreReader.Adopted.consistencyConsequences", + "CoreReader.Adopted.consistencyLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T04", + "T05", + "T06", + "T38" + ], + "target_dispositions": { + "T04": "bounded_specification", + "T05": "conditional_theorem", + "T06": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T04": "accepted-bounded", + "T05": "accepted-bounded", + "T06": "accepted-bounded", + "T38": "accepted-bounded" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "p1", + "exact_source": "- Tension between different assessments or values does not directly constitute a contradiction. Revision or qualification is needed when they require incompatible conclusions under the same conditions.\n- Internal consistency is not correctness or sufficiency. A set of principles may be internally consistent while relying on false assumptions or neglecting important questions.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.consistencySpecification", + "CoreReader.Adopted.consistencyCases", + "CoreReader.Adopted.consistencyConsequences", + "CoreReader.Adopted.consistencyLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T04", + "T05", + "T06", + "T38" + ], + "target_dispositions": { + "T04": "bounded_specification", + "T05": "conditional_theorem", + "T06": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T04": "accepted-bounded", + "T05": "accepted-bounded", + "T06": "accepted-bounded", + "T38": "accepted-bounded" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.charter.reflexivity", + "clause": "p1", + "exact_source": "> A system’s principles of generation and assessment also apply to the system itself and to the formation, application, and revision of those principles.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.reflexivitySpecification", + "CoreReader.Adopted.reflexivityCases012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T07", + "T38" + ], + "target_dispositions": { + "T07": "bounded_specification", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T07": "accepted-bounded", + "T38": "accepted-bounded" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.charter.reflexivity.meaning", + "clause": "p1", + "exact_source": "Reflexivity encompasses both the system itself and its principles. Assessment concerns not only whether the system conforms to its principles, but also how those principles are formed, where they apply, and why they may need revision. The formation and revision of principles thus also become objects of generation and assessment.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.reflexivitySpecification", + "CoreReader.Adopted.reflexivityCases012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T07", + "T38" + ], + "target_dispositions": { + "T07": "bounded_specification", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T07": "accepted-bounded", + "T38": "accepted-bounded" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.charter.reflexivity.limits", + "clause": "p1", + "exact_source": "- Applying principles equally retains their conditions of application. When the relevant conditions hold, being the system itself is not a basis for exemption. Nor does the requirement of reflexivity establish that every principle can be applied to itself without examining its applicability.\n- Self-application does not constitute self-proof. Subjecting a principle to its own assessment does not thereby establish its correctness.\n- That a revision is produced by the system itself does not give it sufficient grounds.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.reflexivitySpecification", + "CoreReader.Adopted.reflexivityCases012", + "CoreReader.Adopted.reflexivityLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T07", + "T08", + "T38" + ], + "target_dispositions": { + "T07": "bounded_specification", + "T08": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T07": "accepted-bounded", + "T08": "accepted-bounded", + "T38": "accepted-bounded" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.grounds", + "clause": "p1", + "exact_source": "> The grounds of principles and judgments must be articulable and subject to assessment appropriate to the nature of the claim. The strength and scope of a claim must be proportionate to the support provided by its grounds.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.reflexivityLimits012", + "CoreReader.Adopted.Grounds012", + "CoreReader.Adopted.groundsCases012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T08", + "T09", + "T38", + "T40" + ], + "target_dispositions": { + "T08": "bounded_countermodels", + "T09": "qualified_success_specification", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T08": "accepted-bounded", + "T09": "accepted-bounded", + "T38": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.grounds.assessment", + "clause": "p1", + "exact_source": "Articulation and assessment have distinct responsibilities. Articulability requires that concepts, assumptions, reasons, and limits can be identified. Assessment requires examining whether those grounds support the corresponding claim. Clearly expressed grounds are not thereby sufficiently established.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.Grounds012", + "CoreReader.Adopted.groundsCases012", + "CoreReader.Adopted.groundsLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T09", + "T13", + "T38", + "T40" + ], + "target_dispositions": { + "T09": "qualified_success_specification", + "T13": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T09": "accepted-bounded", + "T13": "accepted-bounded", + "T38": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.grounds.assessment", + "clause": "p2", + "exact_source": "| Type of claim | Responsibility of assessment | What cannot substitute for that responsibility |\n| --- | --- | --- |\n| Empirical claim | Examine observations, evidence, and performance, together with the conditions, scope, and uncertainty of their support for the claim. | Treating measurability or repeatability itself as proof of relevance, correctness, or value. |\n| Inferential claim | Examine whether the conclusion is supported by the stated assumptions and inferential relations. | Treating the absence of conflict between a conclusion and its assumptions as sufficient to establish that the conclusion follows from them. |\n| Value commitment | State the position taken, its reasons, limits of application, and consequences, and remain open to relevant criticism. | Presenting a commitment as an empirical fact or a necessary inference, or substituting self-assertion for reasons. |", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.Grounds012", + "CoreReader.Adopted.groundsCases012", + "CoreReader.Adopted.empiricalSpecification", + "CoreReader.Adopted.empiricalCases012", + "CoreReader.Adopted.inferentialSpecification", + "CoreReader.Adopted.inferentialCases012", + "CoreReader.Adopted.valueSpecification", + "CoreReader.Adopted.valueCases012", + "CoreReader.Adopted.groundsLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T09", + "T10", + "T11", + "T12", + "T13", + "T38", + "T40" + ], + "target_dispositions": { + "T09": "qualified_success_specification", + "T10": "bounded_success_specification", + "T11": "qualified_success_specification", + "T12": "qualified_value_procedure", + "T13": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T09": "accepted-bounded", + "T10": "accepted-bounded", + "T11": "accepted-bounded", + "T12": "accepted-bounded", + "T13": "accepted-bounded", + "T38": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3", + "exact_source": "Initial value commitments may be stated explicitly as commitments; they need not prove all their own starting assumptions. The strength and scope of a claim do not require conversion to a common numerical scale. Different types of claims specify their support and limits in accordance with their nature.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.Grounds012", + "CoreReader.Adopted.groundsCases012", + "CoreReader.Adopted.valueSpecification", + "CoreReader.Adopted.valueCases012", + "CoreReader.Adopted.groundsLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T09", + "T12", + "T13", + "T38", + "T40" + ], + "target_dispositions": { + "T09": "qualified_success_specification", + "T12": "qualified_value_procedure", + "T13": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T09": "accepted-bounded", + "T12": "accepted-bounded", + "T13": "accepted-bounded", + "T38": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.grounds.scope", + "clause": "p1", + "exact_source": "Performance is discerned within particular relations, conditions, and scopes of observation. A boundary helps specify what a comparison concerns, but local examples do not automatically support unconditional universal conclusions. A judgment cannot establish that relevant differences do not exist merely because its chosen scope omits them.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.scopeSpecification", + "CoreReader.Adopted.scopeCases012", + "CoreReader.Adopted.scopeLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T14", + "T15", + "T38" + ], + "target_dispositions": { + "T14": "qualified_scope_specification", + "T15": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T14": "accepted-bounded", + "T15": "accepted-bounded", + "T38": "accepted-bounded" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.grounds.scope", + "clause": "p2", + "exact_source": "Measurement can make some differences comparable. Repeated assessment can help examine the stability of corresponding conclusions. Their roles, and the role of any assessment framework, must be explained relative to the claim and its context. Measurement, repeatability, and an assessment framework do not form a universally necessary chain on which all judgments must depend.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.scopeSpecification", + "CoreReader.Adopted.scopeCases012", + "CoreReader.Adopted.scopeLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T14", + "T15", + "T38", + "T40" + ], + "target_dispositions": { + "T14": "qualified_scope_specification", + "T15": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T14": "accepted-bounded", + "T15": "accepted-bounded", + "T38": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.grounds.scope", + "clause": "p3", + "exact_source": "An observation that has not been reproduced may still offer limited support, and random outcomes need not be identical on every occasion. The verifiability of observations, reproducibility of conditions, and stability of conclusions must be distinguished.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.scopeSpecification", + "CoreReader.Adopted.scopeCases012", + "CoreReader.Adopted.scopeLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T14", + "T15", + "T38", + "T40" + ], + "target_dispositions": { + "T14": "qualified_scope_specification", + "T15": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T14": "accepted-bounded", + "T15": "accepted-bounded", + "T38": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p1", + "exact_source": "Capability claims are subject to Grounds: the capability claimed, its conditions, and the support for it must be identifiable. The core does not prescribe uniform definitions of method mastery, method generation, or capability levels. Applications specify the capabilities they assess and may require understanding, explanation, or performance under relevant variations.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.capabilitySpecification", + "CoreReader.Adopted.capabilityCases012", + "CoreReader.Adopted.capabilityLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T16", + "T17", + "T38", + "T40" + ], + "target_dispositions": { + "T16": "partial_case_correspondence", + "T17": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T16": "accepted-bounded", + "T17": "accepted-bounded", + "T38": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p2", + "exact_source": "Grounds for a capability claim may be supplied by an external assessor. Their articulability does not by itself require the assessed system to understand or explain its internal generation process. Evidence of reliable output must be assessed against the capability actually claimed; it does not automatically establish understanding of that process. Nor can the number of method documents, terms, tools, or artifacts alone establish a capability beyond what that evidence supports.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.capabilitySpecification", + "CoreReader.Adopted.capabilityCases012", + "CoreReader.Adopted.capabilityLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T16", + "T17", + "T38", + "T40" + ], + "target_dispositions": { + "T16": "partial_case_correspondence", + "T17": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T16": "accepted-bounded", + "T17": "accepted-bounded", + "T38": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.grounds.implementations", + "clause": "p1", + "exact_source": "> The choice of an implementation must be supported by reasons connected to the objectives and values pursued and to the relevant constraints. Its name, conventional use, or established status alone does not provide sufficient grounds for giving it priority.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.choiceSpecification", + "CoreReader.Adopted.choiceCases012", + "CoreReader.Adopted.choiceLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T18", + "T19", + "T38", + "T40" + ], + "target_dispositions": { + "T18": "bounded_choice_specification", + "T19": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T18": "accepted-bounded", + "T19": "accepted-bounded", + "T38": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.grounds.implementations", + "clause": "p2", + "exact_source": "This choice provision adds an additional evaluative commitment: name, conventional use, or established status alone is insufficient to establish priority. Grouping it under Grounds does not mean that it follows from the general requirement to assess reasons, or merely from the discernibility of performance. Conventions and existing arrangements may have practical significance, but that significance must be connected to the objectives and values pursued and to the relevant constraints.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.choiceSpecification", + "CoreReader.Adopted.choiceCases012", + "CoreReader.Adopted.choiceLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T18", + "T19", + "T38", + "T40" + ], + "target_dispositions": { + "T18": "bounded_choice_specification", + "T19": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T18": "accepted-bounded", + "T19": "accepted-bounded", + "T38": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "p1", + "exact_source": "- Openness does not make all implementations equivalent, nor does it guarantee multiple feasible implementations for the same objective.\n- A method’s explanatory power, limits of application, simplicity, and explicit process requirements may all provide grounded reasons for assessment. They cannot be excluded merely because they concern methods internal to the implementation.\n- Identical local performance does not establish overall equivalence. Relations, conditions, and the scope of comparison are constrained by the provisions of Grounds.\n- Openness does not reject an implementation merely because it already exists or is conventionally used. Relevant reasons may still give it priority.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.scopeLimits012", + "CoreReader.Adopted.choiceSpecification", + "CoreReader.Adopted.choiceCases012", + "CoreReader.Adopted.choiceLimits012", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T15", + "T18", + "T19", + "T38" + ], + "target_dispositions": { + "T15": "bounded_countermodels", + "T18": "bounded_choice_specification", + "T19": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T15": "accepted-bounded", + "T18": "accepted-bounded", + "T19": "accepted-bounded", + "T38": "accepted-bounded" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.relationships.roles", + "clause": "p1", + "exact_source": "The charter states the generative orientation, the consistency constraint, and reflexive application. Grounds specifies support requirements for judgments and includes an additional commitment concerning implementation choices. Both parts belong to the core and constrain one another. Their placement neither makes Grounds a deduction from the charter nor gives the charter priority over it. Each commitment needs its own reasons.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.reflexivityLimits012", + "CoreReader.Engineering.inheritedMutualApplication", + "CoreReader.Engineering.inheritedMutualCases", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ], + "targets": [ + "T01", + "T08", + "T20", + "T38", + "T39", + "T40" + ], + "target_dispositions": { + "T01": "documentary_boundary", + "T08": "bounded_countermodels", + "T20": "partial_theorem_signature", + "T38": "kernel_witness_source_composition_pending", + "T39": "bounded_nonentailment_witness", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T01": "accepted-documentary-boundary", + "T08": "accepted-bounded", + "T20": "accepted-bounded", + "T38": "accepted-bounded", + "T39": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.relationships.roles", + "clause": "p2", + "exact_source": "Internal Consistency concerns whether simultaneously held judgments can hold together; Grounds concerns whether and how far a claim is supported. A conclusion may fail to conflict with its assumptions without being supported by them. Self-Transcendence specifies a generative orientation and non-finality; neither establishes actual capability. Applications may supply objectives, values, and capability definitions; claims made under those objectives, values, and definitions remain subject to the relevant core provisions.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.generationLimits012", + "CoreReader.Adopted.consistencyLimits012", + "CoreReader.Adopted.inferentialSpecification", + "CoreReader.Adopted.inferentialCases012", + "CoreReader.Adopted.capabilitySpecification", + "CoreReader.Adopted.capabilityCases012", + "CoreReader.Engineering.inheritedMutualApplication", + "CoreReader.Engineering.inheritedMutualCases", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ], + "targets": [ + "T03", + "T06", + "T11", + "T16", + "T20", + "T38", + "T39", + "T40" + ], + "target_dispositions": { + "T03": "bounded_countermodels", + "T06": "bounded_countermodels", + "T11": "qualified_success_specification", + "T16": "partial_case_correspondence", + "T20": "partial_theorem_signature", + "T38": "kernel_witness_source_composition_pending", + "T39": "bounded_nonentailment_witness", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T03": "accepted-bounded", + "T06": "accepted-bounded", + "T11": "accepted-bounded", + "T16": "accepted-bounded", + "T20": "accepted-bounded", + "T38": "accepted-bounded", + "T39": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.relationships.roles", + "clause": "p3", + "exact_source": "Self-Transcendence does not substitute for Reflexivity: keeping existing forms open to being surpassed differs from applying relevant principles to the system and to their own formation, application, and revision. Reflexivity extends these requirements to the system and to the formation, application, and revision of its principles. The grounds and limits of the Grounds provisions must themselves be articulable. The system’s own capability claims remain subject to assessment, and this philosophy’s existing form cannot gain priority merely from its established status. Such mutual application provides no self-proof and does not remove conditions of application.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.reflexivitySpecification", + "CoreReader.Adopted.reflexivityCases012", + "CoreReader.Adopted.reflexivityLimits012", + "CoreReader.Adopted.capabilitySpecification", + "CoreReader.Adopted.capabilityCases012", + "CoreReader.Adopted.choiceSpecification", + "CoreReader.Adopted.choiceCases012", + "CoreReader.Engineering.inheritedMutualApplication", + "CoreReader.Engineering.inheritedMutualCases", + "CoreReader.Engineering.priorityRemainsReflexive", + "CoreReader.Engineering.priorityReflexiveCases", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ], + "targets": [ + "T07", + "T08", + "T16", + "T18", + "T20", + "T37", + "T38", + "T39", + "T40" + ], + "target_dispositions": { + "T07": "bounded_specification", + "T08": "bounded_countermodels", + "T16": "partial_case_correspondence", + "T18": "bounded_choice_specification", + "T20": "partial_theorem_signature", + "T37": "partial_same_rule_grounding", + "T38": "kernel_witness_source_composition_pending", + "T39": "bounded_nonentailment_witness", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T07": "accepted-bounded", + "T08": "accepted-bounded", + "T16": "accepted-bounded", + "T18": "accepted-bounded", + "T20": "accepted-bounded", + "T37": "accepted-bounded", + "T38": "accepted-bounded", + "T39": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "organon.relationships.terms", + "clause": "p1", + "exact_source": "| Term | Meaning in this philosophy |\n| --- | --- |\n| Existing form | The system’s current organization, methods, and principles, not only its appearance or artifacts. |\n| Assessment | Examination of reasons, applicability, and observed performance; not limited to executable tests. |", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases" + ], + "targets": [ + "T02", + "T21" + ], + "target_dispositions": { + "T02": "bounded_specification", + "T21": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T02": "accepted-bounded", + "T21": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "extensions", + "clause": "p1", + "exact_source": "This chapter adds a software engineering commitment and specifies its meaning and limits. It does not claim that this commitment follows from the Charter or Grounds. Those provisions remain adopted and constrain its application.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.priorityRemainsReflexive", + "CoreReader.Engineering.priorityReflexiveCases", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ], + "targets": [ + "T01", + "T37", + "T38", + "T39", + "T40" + ], + "target_dispositions": { + "T01": "documentary_boundary", + "T37": "partial_same_rule_grounding", + "T38": "kernel_witness_source_composition_pending", + "T39": "bounded_nonentailment_witness", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T01": "accepted-documentary-boundary", + "T37": "accepted-bounded", + "T38": "accepted-bounded", + "T39": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "software-engineering.purpose", + "clause": "p1", + "exact_source": "Software engineering concerns the construction, operation, understanding, and revision of software within its relevant human and technical conditions. This philosophy guides decisions by people and agents; it does not attribute an intrinsic orientation to every software artifact.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.ActivityScope", + "CoreReader.Engineering.subjectLifecycleCases", + "CoreReader.Engineering.subjectLimits", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T22", + "T23", + "T38", + "T40" + ], + "target_dispositions": { + "T22": "bounded_subject_specification", + "T23": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T22": "accepted-bounded", + "T23": "accepted-bounded", + "T38": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "software-engineering.purpose", + "clause": "p2", + "exact_source": "The evolution capability considered here belongs to the continuing engineering activity: maintainers, including successor maintainers and agents, working with software, tools, and available knowledge. Code that its original author can modify is not on that ground alone shown to support that continuing activity.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.ActivityScope", + "CoreReader.Engineering.subjectLifecycleCases", + "CoreReader.Engineering.subjectLimits", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T22", + "T23", + "T38", + "T40" + ], + "target_dispositions": { + "T22": "bounded_subject_specification", + "T23": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T22": "accepted-bounded", + "T23": "accepted-bounded", + "T38": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "software-engineering.purpose", + "clause": "p3", + "exact_source": "Apply the following priority according to the software's credible lifecycle and maintenance expectations. A genuinely temporary script, bounded prototype, or retiring system may have little reason to support further evolution. Calling a continuing system temporary does not establish that condition.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.ActivityScope", + "CoreReader.Engineering.subjectLifecycleCases", + "CoreReader.Engineering.subjectLimits", + "CoreReader.Engineering.EvolutionPriority", + "CoreReader.Engineering.priorityConditionsCases", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T22", + "T23", + "T24", + "T38", + "T40" + ], + "target_dispositions": { + "T22": "bounded_subject_specification", + "T23": "bounded_countermodels", + "T24": "bounded_normative_specification", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T22": "accepted-bounded", + "T23": "accepted-bounded", + "T24": "accepted-bounded", + "T38": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p1", + "exact_source": "> When relevant behavioral, safety, performance, and other necessary requirements are satisfied, give priority to continuing maintainers' ability to make credible future changes, including changes to the design itself, over present abstraction simplicity. Accept additional present abstraction complexity for that purpose, while allowing this preference to yield when the added costs threaten concrete engineering objectives.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.EvolutionPriority", + "CoreReader.Engineering.priorityConditionsCases", + "CoreReader.Engineering.priorityWhenApplicable", + "CoreReader.Engineering.priorityChoices", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ], + "targets": [ + "T24", + "T25", + "T38", + "T39", + "T40" + ], + "target_dispositions": { + "T24": "bounded_normative_specification", + "T25": "conditional_theorem", + "T38": "kernel_witness_source_composition_pending", + "T39": "bounded_nonentailment_witness", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T24": "accepted-bounded", + "T25": "accepted-bounded", + "T38": "accepted-bounded", + "T39": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2", + "exact_source": "Credible directions of change have articulable grounds, such as a committed plan, relevant domain knowledge, or an applicable history of change. They need not already have multiple implementations. Their credibility remains open to revision; a conceivable change alone does not establish that it warrants accommodation now.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.EvolutionPriority", + "CoreReader.Engineering.priorityConditionsCases", + "CoreReader.Engineering.priorityWhenApplicable", + "CoreReader.Engineering.priorityChoices", + "CoreReader.Engineering.CredibleDirection", + "CoreReader.Engineering.credibilityCases", + "CoreReader.Engineering.credibilityLimits", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ], + "targets": [ + "T24", + "T25", + "T26", + "T27", + "T38", + "T39", + "T40" + ], + "target_dispositions": { + "T24": "bounded_normative_specification", + "T25": "conditional_theorem", + "T26": "qualified_credibility_adapter", + "T27": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T39": "bounded_nonentailment_witness", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T24": "accepted-bounded", + "T25": "accepted-bounded", + "T26": "accepted-bounded", + "T27": "accepted-bounded", + "T38": "accepted-bounded", + "T39": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3", + "exact_source": "This is a default priority, not an obligation to maximize extensibility or retain every possibility. Costs include relevant burdens of understanding, construction, diagnosis, verification, coordination, operation, and eventual migration. A departure from the priority identifies the objective threatened and why the costs matter. No universal numerical exchange rate between these considerations is prescribed.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.EvolutionPriority", + "CoreReader.Engineering.priorityConditionsCases", + "CoreReader.Engineering.priorityWhenApplicable", + "CoreReader.Engineering.priorityChoices", + "CoreReader.Engineering.CredibleDirection", + "CoreReader.Engineering.credibilityCases", + "CoreReader.Engineering.credibilityLimits", + "CoreReader.Engineering.JustifiedDeparture", + "CoreReader.Engineering.costCases", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ], + "targets": [ + "T24", + "T25", + "T26", + "T27", + "T28", + "T38", + "T39", + "T40" + ], + "target_dispositions": { + "T24": "bounded_normative_specification", + "T25": "conditional_theorem", + "T26": "qualified_credibility_adapter", + "T27": "bounded_countermodels", + "T28": "bounded_cost_specification", + "T38": "kernel_witness_source_composition_pending", + "T39": "bounded_nonentailment_witness", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T24": "accepted-bounded", + "T25": "accepted-bounded", + "T26": "accepted-bounded", + "T27": "accepted-bounded", + "T28": "accepted-bounded", + "T38": "accepted-bounded", + "T39": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p1", + "exact_source": "Evolution includes adding capabilities, replacing implementations, deleting mechanisms, withdrawing abstractions, redrawing boundaries, and migrating away from an existing technology or model. Making additions within a fixed scheme does not establish equal ability to revise or leave that scheme. Not every such change can or should be made inexpensive.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.EvolutionClaim", + "CoreReader.Engineering.evolutionKindsCases", + "CoreReader.Engineering.evolutionDimensionsLimits", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T29", + "T30", + "T38", + "T40" + ], + "target_dispositions": { + "T29": "bounded_evolution_specification", + "T30": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T29": "accepted-bounded", + "T30": "accepted-bounded", + "T38": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p2", + "exact_source": "An evolution claim identifies the relevant changes and the maintainers' conditions. Independent changes, coordinated changes, preservation of existing obligations, and deliberate revision of those obligations can require different structures. A design's advantage on one dimension does not establish an advantage on every dimension.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.EvolutionClaim", + "CoreReader.Engineering.evolutionKindsCases", + "CoreReader.Engineering.evolutionDimensionsLimits", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T29", + "T30", + "T38", + "T40" + ], + "target_dispositions": { + "T29": "bounded_evolution_specification", + "T30": "bounded_countermodels", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T29": "accepted-bounded", + "T30": "accepted-bounded", + "T38": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p1", + "exact_source": "Apply the preceding commitment to engineering consequences as a whole, including the relations among components, their observable contracts, and the work needed to understand and verify a change. An interface's shape, the number of modules or extension points, or the use of a named principle is not sufficient evidence of the claimed capability.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.StructuralAccount", + "CoreReader.Engineering.structuralCases", + "CoreReader.Engineering.structureNotCapability", + "CoreReader.Engineering.priorityRemainsReflexive", + "CoreReader.Engineering.priorityReflexiveCases", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T31", + "T32", + "T37", + "T38", + "T40" + ], + "target_dispositions": { + "T31": "partial_semantic_link", + "T32": "bounded_countermodels_delta_verified", + "T37": "partial_same_rule_grounding", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T31": "accepted-bounded", + "T32": "accepted-bounded", + "T37": "accepted-bounded", + "T38": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p2", + "exact_source": "The relevant comparison may examine how a change propagates, which knowledge and obligations cross a boundary, which assumptions become fixed, and what a later withdrawal would require. A proposed boundary needs support for the changes it is meant to accommodate; introducing it does not by itself show that those changes became easier.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.StructuralAccount", + "CoreReader.Engineering.structuralCases", + "CoreReader.Engineering.structureNotCapability", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T31", + "T32", + "T38", + "T40" + ], + "target_dispositions": { + "T31": "partial_semantic_link", + "T32": "bounded_countermodels_delta_verified", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T31": "accepted-bounded", + "T32": "accepted-bounded", + "T38": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p3", + "exact_source": "Distinguish a transformation that preserves an identified observable contract from one that deliberately revises that contract. The latter needs a corresponding account of changed obligations and affected parties. This distinction does not require preserving every historical behavior or using a particular testing or migration procedure.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.ContractChangeAccount", + "CoreReader.Engineering.contractCases", + "CoreReader.Engineering.contractPreservation", + "CoreReader.Engineering.contractDistinctions", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T33", + "T34", + "T38", + "T40" + ], + "target_dispositions": { + "T33": "bounded_contract_specification", + "T34": "conditional_theorem", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T33": "accepted-bounded", + "T34": "accepted-bounded", + "T38": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "software-engineering.revision", + "clause": "p1", + "exact_source": "Changed evidence about likely changes, maintenance conditions, costs, or objectives may justify revising a design or this priority's application. A revised judgment acknowledges material changes in its grounds; it does not make a failed prediction successful retrospectively.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.RevisionAccount", + "CoreReader.Engineering.revisionCases", + "CoreReader.Engineering.revisionLimits", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T35", + "T36", + "T38", + "T40" + ], + "target_dispositions": { + "T35": "qualified_revision_account", + "T36": "bounded_countermodels_with_scope_limit", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T35": "accepted-bounded", + "T36": "accepted-bounded", + "T38": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + }, + { + "unit": "software-engineering.revision", + "clause": "p2", + "exact_source": "Retaining a design can be justified when the relevant alternatives have no supported contribution or impose costs that defeat the objective. Reflexivity also keeps this engineering commitment and the methods used to assess evolution within the scope of criticism and revision. Continued change, agreement, or successful examples do not establish its universal correctness.", + "source_excerpt_verified": true, + "registered_declarations": [ + "CoreReader.Engineering.RevisionAccount", + "CoreReader.Engineering.revisionCases", + "CoreReader.Engineering.revisionLimits", + "CoreReader.Engineering.priorityRemainsReflexive", + "CoreReader.Engineering.priorityReflexiveCases", + "CoreReader.Engineering.jointWitness" + ], + "targets": [ + "T35", + "T36", + "T37", + "T38", + "T40" + ], + "target_dispositions": { + "T35": "qualified_revision_account", + "T36": "bounded_countermodels_with_scope_limit", + "T37": "partial_same_rule_grounding", + "T38": "kernel_witness_source_composition_pending", + "T40": "documentary_boundary" + }, + "assessment": "Read through the listed target assessments; repeated links do not add proofs. Bounded represented claims are distinguished from the whole source statement; any partial target remains partial for this source link.", + "r3_target_statuses": { + "T35": "accepted-bounded", + "T36": "accepted-bounded", + "T37": "accepted-bounded", + "T38": "accepted-bounded", + "T40": "accepted-documentary-boundary" + }, + "r3_assessment": "Accepted within the mapped normative/conditional/finite/documentary scope. The exact source is unchanged; original partial judgments remain historical and the current status uses the R3 links and limits, not an upgraded claim of universal correctness." + } + ], + "semantic_cases": [ + { + "target": "T02", + "case": "positive_valued_open_forms", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.generationCases", + "file": "CoreReader/Adopted.lean", + "line": 862, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "Generative requires valuation of expansion and revisability of every current Form, including organization, method and principle. Current examples are nonempty; the stable trace and budget-respecting stable action show that generativity does not require change in every act. This is an adopted policy predicate, not proof all systems possess it.", + "special_limits": [] + }, + { + "target": "T02", + "case": "negative_permission_only", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.permissionNotValuation", + "file": "CoreReader/Agency.lean", + "line": 37, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "Generative requires valuation of expansion and revisability of every current Form, including organization, method and principle. Current examples are nonempty; the stable trace and budget-respecting stable action show that generativity does not require change in every act. This is an adopted policy predicate, not proof all systems possess it.", + "special_limits": [] + }, + { + "target": "T02", + "case": "positive_stability", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.generationLimits", + "file": "CoreReader/Agency.lean", + "line": 194, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "Generative requires valuation of expansion and revisability of every current Form, including organization, method and principle. Current examples are nonempty; the stable trace and budget-respecting stable action show that generativity does not require change in every act. This is an adopted policy predicate, not proof all systems possess it.", + "special_limits": [] + }, + { + "target": "T02", + "case": "external_collaboration", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.collaborativeProgress", + "file": "CoreReader/Adopted.lean", + "line": 223, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "Generative requires valuation of expansion and revisability of every current Form, including organization, method and principle. Current examples are nonempty; the stable trace and budget-respecting stable action show that generativity does not require change in every act. This is an adopted policy predicate, not proof all systems possess it.", + "special_limits": [] + }, + { + "target": "T03", + "case": "permission_without_value", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.permissionNotValuation", + "file": "CoreReader/Agency.lean", + "line": 37, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions.", + "special_limits": [] + }, + { + "target": "T03", + "case": "orientation_without_progress", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.revisionWithoutProgress", + "file": "CoreReader/Agency.lean", + "line": 99, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions.", + "special_limits": [] + }, + { + "target": "T03", + "case": "count_growth_without_capability", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.generationLimits", + "file": "CoreReader/Agency.lean", + "line": 194, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions.", + "special_limits": [] + }, + { + "target": "T03", + "case": "collaborative_nonautonomous_progress", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.collaborativeProgress", + "file": "CoreReader/Adopted.lean", + "line": 223, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions.", + "special_limits": [] + }, + { + "target": "T03", + "case": "claim_without_achievement", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.inflatedAnnouncementRefuted", + "file": "CoreReader/Agency.lean", + "line": 171, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions.", + "special_limits": [] + }, + { + "target": "T03", + "case": "achievement_support_for_same_claim", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.achievementSupported012", + "file": "CoreReader/Adopted.lean", + "line": 620, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions.", + "special_limits": [] + }, + { + "target": "T04", + "case": "joint_only_contradiction", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.jointImplicationConflict012", + "file": "CoreReader/Adopted.lean", + "line": 703, + "axioms": "[]" + } + ], + "interpretation": "Consistent quantifies over joint semantic consequences of the whole held theory under one Context. Snapshot change reporting is a separate one-way Boolean obligation. The code preserves same-question/assumptions/meaning/scope and time-slice distinctions; it does not model every way a prose report could conceal change.", + "special_limits": [] + }, + { + "target": "T04", + "case": "changed_scope_not_concealed", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Logic.hiddenContextChangeRejected", + "file": "CoreReader/Logic.lean", + "line": 134, + "axioms": "[]" + } + ], + "interpretation": "Consistent quantifies over joint semantic consequences of the whole held theory under one Context. Snapshot change reporting is a separate one-way Boolean obligation. The code preserves same-question/assumptions/meaning/scope and time-slice distinctions; it does not model every way a prose report could conceal change.", + "special_limits": [] + }, + { + "target": "T04", + "case": "revision_withdraws_old", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Logic.revisionCanReverse", + "file": "CoreReader/Logic.lean", + "line": 68, + "axioms": "[]" + } + ], + "interpretation": "Consistent quantifies over joint semantic consequences of the whole held theory under one Context. Snapshot change reporting is a separate one-way Boolean obligation. The code preserves same-question/assumptions/meaning/scope and time-slice distinctions; it does not model every way a prose report could conceal change.", + "special_limits": [] + }, + { + "target": "T04", + "case": "incompatible_same_context", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.consistencyConsequences", + "file": "CoreReader/Adopted.lean", + "line": 241, + "axioms": "[]" + } + ], + "interpretation": "Consistent quantifies over joint semantic consequences of the whole held theory under one Context. Snapshot change reporting is a separate one-way Boolean obligation. The code preserves same-question/assumptions/meaning/scope and time-slice distinctions; it does not model every way a prose report could conceal change.", + "special_limits": [] + }, + { + "target": "T05", + "case": "pair_conflict", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.consistencyConsequences", + "file": "CoreReader/Adopted.lean", + "line": 241, + "axioms": "[]" + } + ], + "interpretation": "consistencyConsequences directly applies the consistency prohibition to supplied positive and negative consequences. The revisionSlice examples provide distinct satisfiable times and inconsistent union; context examples preserve an admissible witness for each context. The theorem neither proves premises nor mandates permanent historical compatibility.", + "special_limits": [] + }, + { + "target": "T05", + "case": "joint_premise_conflict", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.jointImplicationConflict012", + "file": "CoreReader/Adopted.lean", + "line": 703, + "axioms": "[]" + } + ], + "interpretation": "consistencyConsequences directly applies the consistency prohibition to supplied positive and negative consequences. The revisionSlice examples provide distinct satisfiable times and inconsistent union; context examples preserve an admissible witness for each context. The theorem neither proves premises nor mandates permanent historical compatibility.", + "special_limits": [] + }, + { + "target": "T05", + "case": "old_new_separate_times", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.sliceConsistency", + "file": "CoreReader/Adopted.lean", + "line": 247, + "axioms": "[]" + } + ], + "interpretation": "consistencyConsequences directly applies the consistency prohibition to supplied positive and negative consequences. The revisionSlice examples provide distinct satisfiable times and inconsistent union; context examples preserve an admissible witness for each context. The theorem neither proves premises nor mandates permanent historical compatibility.", + "special_limits": [] + }, + { + "target": "T05", + "case": "distinct_context_judgments", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Logic.contextDifferences", + "file": "CoreReader/Logic.lean", + "line": 88, + "axioms": "[]" + } + ], + "interpretation": "consistencyConsequences directly applies the consistency prohibition to supplied positive and negative consequences. The revisionSlice examples provide distinct satisfiable times and inconsistent union; context examples preserve an admissible witness for each context. The theorem neither proves premises nor mandates permanent historical compatibility.", + "special_limits": [] + }, + { + "target": "T05", + "case": "truthful_semantic_change_and_reordering", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Logic.hiddenContextChangeRejected", + "file": "CoreReader/Logic.lean", + "line": 134, + "axioms": "[]" + }, + { + "name": "CoreReader.Adopted.semanticOrder012", + "file": "CoreReader/Adopted.lean", + "line": 630, + "axioms": "[]" + } + ], + "interpretation": "consistencyConsequences directly applies the consistency prohibition to supplied positive and negative consequences. The revisionSlice examples provide distinct satisfiable times and inconsistent union; context examples preserve an admissible witness for each context. The theorem neither proves premises nor mandates permanent historical compatibility.", + "special_limits": [] + }, + { + "target": "T06", + "case": "different_contexts", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Logic.contextDifferences", + "file": "CoreReader/Logic.lean", + "line": 88, + "axioms": "[]" + } + ], + "interpretation": "Concrete contexts, overlapping inequalities, a consistent theory false at the selected outside world, and empty-theory countervaluations distinguish contradiction, truth, sufficiency and entailment. These support the source limits without relying on a free false support flag.", + "special_limits": [] + }, + { + "target": "T06", + "case": "tension_compatible", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.tensionConsistent012", + "file": "CoreReader/Adopted.lean", + "line": 718, + "axioms": "[]" + } + ], + "interpretation": "Concrete contexts, overlapping inequalities, a consistent theory false at the selected outside world, and empty-theory countervaluations distinguish contradiction, truth, sufficiency and entailment. These support the source limits without relying on a free false support flag.", + "special_limits": [] + }, + { + "target": "T06", + "case": "consistent_false_assumption", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.explicitlyConsistentLimits", + "file": "CoreReader/Adopted.lean", + "line": 262, + "axioms": "[]" + } + ], + "interpretation": "Concrete contexts, overlapping inequalities, a consistent theory false at the selected outside world, and empty-theory countervaluations distinguish contradiction, truth, sufficiency and entailment. These support the source limits without relying on a free false support flag.", + "special_limits": [] + }, + { + "target": "T06", + "case": "consistent_omitted_question", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.explicitlyConsistentLimits", + "file": "CoreReader/Adopted.lean", + "line": 262, + "axioms": "[]" + } + ], + "interpretation": "Concrete contexts, overlapping inequalities, a consistent theory false at the selected outside world, and empty-theory countervaluations distinguish contradiction, truth, sufficiency and entailment. These support the source limits without relying on a free false support flag.", + "special_limits": [] + }, + { + "target": "T06", + "case": "compatible_not_entailed", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Logic.compatibilityNotEntailment", + "file": "CoreReader/Logic.lean", + "line": 180, + "axioms": "[]" + } + ], + "interpretation": "Concrete contexts, overlapping inequalities, a consistent theory false at the selected outside world, and empty-theory countervaluations distinguish contradiction, truth, sufficiency and entailment. These support the source limits without relying on a free false support flag.", + "special_limits": [] + }, + { + "target": "T07", + "case": "self_applicable", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.reflexiveTargets012", + "file": "CoreReader/Adopted.lean", + "line": 605, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "The general interface/cases are reused; its engineering realization was rereviewed because selfModel now includes actual generation/evaluation rule objects and applicability. This strengthens rather than universalizes the source conditions.", + "special_limits": [] + }, + { + "target": "T07", + "case": "self_inapplicable", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.applicabilityRetained", + "file": "CoreReader/Reflexivity.lean", + "line": 396, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "The general interface/cases are reused; its engineering realization was rereviewed because selfModel now includes actual generation/evaluation rule objects and applicability. This strengthens rather than universalizes the source conditions.", + "special_limits": [] + }, + { + "target": "T07", + "case": "principle_formation", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.completeOwnWork_reflexive", + "file": "CoreReader/Reflexivity.lean", + "line": 358, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "The general interface/cases are reused; its engineering realization was rereviewed because selfModel now includes actual generation/evaluation rule objects and applicability. This strengthens rather than universalizes the source conditions.", + "special_limits": [] + }, + { + "target": "T07", + "case": "principle_application", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.reflexiveTargets012", + "file": "CoreReader/Adopted.lean", + "line": 605, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "The general interface/cases are reused; its engineering realization was rereviewed because selfModel now includes actual generation/evaluation rule objects and applicability. This strengthens rather than universalizes the source conditions.", + "special_limits": [] + }, + { + "target": "T07", + "case": "principle_revision", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.reflexiveTargets012", + "file": "CoreReader/Adopted.lean", + "line": 605, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "The general interface/cases are reused; its engineering realization was rereviewed because selfModel now includes actual generation/evaluation rule objects and applicability. This strengthens rather than universalizes the source conditions.", + "special_limits": [] + }, + { + "target": "T07", + "case": "grounds_on_grounds", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.groundsOnGrounds012", + "file": "CoreReader/Adopted.lean", + "line": 595, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "The general interface/cases are reused; its engineering realization was rereviewed because selfModel now includes actual generation/evaluation rule objects and applicability. This strengthens rather than universalizes the source conditions.", + "special_limits": [] + }, + { + "target": "T08", + "case": "self_assessed_incorrect", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.selfTestDoesNotProve", + "file": "CoreReader/Agency.lean", + "line": 239, + "axioms": "[]" + } + ], + "interpretation": "A revisable principle applied only to target 1 fails required self-target 0; self tests fail elsewhere; owned revisions retain unsupported global claims. CompleteCharter012 is inhabited yet costAllowanceRecord admits an incorrect-output world, so the concrete corresponding Grounds012 claim fails. This is a bounded charter-versus-support model, not philosophical independence in all interpretations.", + "special_limits": [] + }, + { + "target": "T08", + "case": "self_generated_unsupported", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.selfOriginDoesNotSupport", + "file": "CoreReader/Evidence.lean", + "line": 541, + "axioms": "[propext]" + } + ], + "interpretation": "A revisable principle applied only to target 1 fails required self-target 0; self tests fail elsewhere; owned revisions retain unsupported global claims. CompleteCharter012 is inhabited yet costAllowanceRecord admits an incorrect-output world, so the concrete corresponding Grounds012 claim fails. This is a bounded charter-versus-support model, not philosophical independence in all interpretations.", + "special_limits": [] + }, + { + "target": "T08", + "case": "open_but_self_exempt", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.openSelfExempt012", + "file": "CoreReader/Adopted.lean", + "line": 680, + "axioms": "[propext]" + } + ], + "interpretation": "A revisable principle applied only to target 1 fails required self-target 0; self tests fail elsewhere; owned revisions retain unsupported global claims. CompleteCharter012 is inhabited yet costAllowanceRecord admits an incorrect-output world, so the concrete corresponding Grounds012 claim fails. This is a bounded charter-versus-support model, not philosophical independence in all interpretations.", + "special_limits": [] + }, + { + "target": "T08", + "case": "charter_not_general_grounds", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.charterWithoutGrounds012", + "file": "CoreReader/Adopted.lean", + "line": 499, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "A revisable principle applied only to target 1 fails required self-target 0; self tests fail elsewhere; owned revisions retain unsupported global claims. CompleteCharter012 is inhabited yet costAllowanceRecord admits an incorrect-output world, so the concrete corresponding Grounds012 claim fails. This is a bounded charter-versus-support model, not philosophical independence in all interpretations.", + "special_limits": [] + }, + { + "target": "T09", + "case": "articulable_supported", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.scopeStrength012", + "file": "CoreReader/Adopted.lean", + "line": 286, + "axioms": "[propext]" + } + ], + "interpretation": "Grounds012 formalizes successful supported grounds for one declared task using same claim/articulation/discharge and task-appropriateness. Local/global and stronger-claim countermodels preserve force and scope. It is not a complete classifier or universal procedure for deciding all possible mixed claims. Calling it the obligation to examine rather than the successful support condition would overstate the correspondence. No Core 0.1.3 all-facet obligation is introduced.", + "special_limits": [] + }, + { + "target": "T09", + "case": "articulable_unsupported", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.articulationNotSupport", + "file": "CoreReader/Evidence.lean", + "line": 325, + "axioms": "[propext]" + } + ], + "interpretation": "Grounds012 formalizes successful supported grounds for one declared task using same claim/articulation/discharge and task-appropriateness. Local/global and stronger-claim countermodels preserve force and scope. It is not a complete classifier or universal procedure for deciding all possible mixed claims. Calling it the obligation to examine rather than the successful support condition would overstate the correspondence. No Core 0.1.3 all-facet obligation is introduced.", + "special_limits": [] + }, + { + "target": "T09", + "case": "scope_overreach", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.scopeStrength012", + "file": "CoreReader/Adopted.lean", + "line": 286, + "axioms": "[propext]" + } + ], + "interpretation": "Grounds012 formalizes successful supported grounds for one declared task using same claim/articulation/discharge and task-appropriateness. Local/global and stronger-claim countermodels preserve force and scope. It is not a complete classifier or universal procedure for deciding all possible mixed claims. Calling it the obligation to examine rather than the successful support condition would overstate the correspondence. No Core 0.1.3 all-facet obligation is introduced.", + "special_limits": [] + }, + { + "target": "T09", + "case": "strength_overreach", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.scopeStrength012", + "file": "CoreReader/Adopted.lean", + "line": 286, + "axioms": "[propext]" + } + ], + "interpretation": "Grounds012 formalizes successful supported grounds for one declared task using same claim/articulation/discharge and task-appropriateness. Local/global and stronger-claim countermodels preserve force and scope. It is not a complete classifier or universal procedure for deciding all possible mixed claims. Calling it the obligation to examine rather than the successful support condition would overstate the correspondence. No Core 0.1.3 all-facet obligation is introduced.", + "special_limits": [] + }, + { + "target": "T10", + "case": "observed_relevant", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.localFacetChecked012", + "file": "CoreReader/Adopted.lean", + "line": 282, + "axioms": "[propext]" + } + ], + "interpretation": "Empirical discharge includes an in-scope compatible witness, scoped support and uncertainty support. Repetition of irrelevant first-coordinate/action observations cannot establish the second coordinate or budget value. The successful uncertainty is the exhaustive Boolean disjunction, not a quantified confidence estimate or a production measurement.", + "special_limits": [] + }, + { + "target": "T10", + "case": "repeatable_irrelevant", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.measurementRepeatNotSupport", + "file": "CoreReader/Evidence.lean", + "line": 394, + "axioms": "[propext]" + } + ], + "interpretation": "Empirical discharge includes an in-scope compatible witness, scoped support and uncertainty support. Repetition of irrelevant first-coordinate/action observations cannot establish the second coordinate or budget value. The successful uncertainty is the exhaustive Boolean disjunction, not a quantified confidence estimate or a production measurement.", + "special_limits": [] + }, + { + "target": "T10", + "case": "measured_wrong_scope", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.scopeStrength012", + "file": "CoreReader/Adopted.lean", + "line": 286, + "axioms": "[propext]" + } + ], + "interpretation": "Empirical discharge includes an in-scope compatible witness, scoped support and uncertainty support. Repetition of irrelevant first-coordinate/action observations cannot establish the second coordinate or budget value. The successful uncertainty is the exhaustive Boolean disjunction, not a quantified confidence estimate or a production measurement.", + "special_limits": [] + }, + { + "target": "T10", + "case": "uncertain_limited", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.uncertainSupported012", + "file": "CoreReader/Adopted.lean", + "line": 308, + "axioms": "[propext]" + } + ], + "interpretation": "Empirical discharge includes an in-scope compatible witness, scoped support and uncertainty support. Repetition of irrelevant first-coordinate/action observations cannot establish the second coordinate or budget value. The successful uncertainty is the exhaustive Boolean disjunction, not a quantified confidence estimate or a production measurement.", + "special_limits": [] + }, + { + "target": "T11", + "case": "valid_inference", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.inferenceChecked012", + "file": "CoreReader/Adopted.lean", + "line": 323, + "axioms": "[propext]" + } + ], + "interpretation": "The inferential wrapper requires satisfiable assumptions and actual entailment. Correct rejection of an unentailed conclusion is represented separately by InferenceExamined false and a countervaluation. Together they preserve the examination/success distinction, provided the wrapper alone is not described as the full act of assessment.", + "special_limits": [] + }, + { + "target": "T11", + "case": "compatible_unentailed", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Logic.compatibilityNotEntailment", + "file": "CoreReader/Logic.lean", + "line": 180, + "axioms": "[]" + } + ], + "interpretation": "The inferential wrapper requires satisfiable assumptions and actual entailment. Correct rejection of an unentailed conclusion is represented separately by InferenceExamined false and a countervaluation. Together they preserve the examination/success distinction, provided the wrapper alone is not described as the full act of assessment.", + "special_limits": [] + }, + { + "target": "T11", + "case": "false_inference_detected", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.inferenceChecked012", + "file": "CoreReader/Adopted.lean", + "line": 323, + "axioms": "[propext]" + } + ], + "interpretation": "The inferential wrapper requires satisfiable assumptions and actual entailment. Correct rejection of an unentailed conclusion is represented separately by InferenceExamined false and a countervaluation. Together they preserve the examination/success distinction, provided the wrapper alone is not described as the full act of assessment.", + "special_limits": [] + }, + { + "target": "T12", + "case": "reasoned_value", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.valueFulfilled012", + "file": "CoreReader/Adopted.lean", + "line": 341, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "The value construction identifies position, joint reasons, application limits, consequences and relevant criticism responses. It assumes starting claims and supplies a joint witness instead of proving every starting assumption. The universal consequence test and response nonemptiness are this application's sufficient procedure, not newly mandatory philosophical proof requirements or proof of response adequacy.", + "special_limits": [] + }, + { + "target": "T12", + "case": "unsupported_self_assertion", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.announcementNotBudgetReason", + "file": "CoreReader/Evidence.lean", + "line": 372, + "axioms": "[propext]" + } + ], + "interpretation": "The value construction identifies position, joint reasons, application limits, consequences and relevant criticism responses. It assumes starting claims and supplies a joint witness instead of proving every starting assumption. The universal consequence test and response nonemptiness are this application's sufficient procedure, not newly mandatory philosophical proof requirements or proof of response adequacy.", + "special_limits": [] + }, + { + "target": "T12", + "case": "closed_criticism", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.closedCriticism012", + "file": "CoreReader/Adopted.lean", + "line": 336, + "axioms": "[]" + } + ], + "interpretation": "The value construction identifies position, joint reasons, application limits, consequences and relevant criticism responses. It assumes starting claims and supplies a joint witness instead of proving every starting assumption. The universal consequence test and response nonemptiness are this application's sufficient procedure, not newly mandatory philosophical proof requirements or proof of response adequacy.", + "special_limits": [] + }, + { + "target": "T12", + "case": "explicit_initial_commitment", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.valueWithoutSelfProof", + "file": "CoreReader/Evidence.lean", + "line": 426, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "The value construction identifies position, joint reasons, application limits, consequences and relevant criticism responses. It assumes starting claims and supplies a joint witness instead of proving every starting assumption. The universal consequence test and response nonemptiness are this application's sufficient procedure, not newly mandatory philosophical proof requirements or proof of response adequacy.", + "special_limits": [] + }, + { + "target": "T13", + "case": "clear_false_reason", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.clearFalseReason012", + "file": "CoreReader/Adopted.lean", + "line": 637, + "axioms": "[propext]" + } + ], + "interpretation": "Clearly articulated false assumptions, repeated wrong-object observations, neutral records compatible with nonadoption, and the ordinary value example show the intended non-substitutions. Qualitative implication orders claim strength without imposing a numerical scale.", + "special_limits": [] + }, + { + "target": "T13", + "case": "repeatable_wrong_object", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.measurementRepeatNotSupport", + "file": "CoreReader/Evidence.lean", + "line": 394, + "axioms": "[propext]" + } + ], + "interpretation": "Clearly articulated false assumptions, repeated wrong-object observations, neutral records compatible with nonadoption, and the ordinary value example show the intended non-substitutions. Qualitative implication orders claim strength without imposing a numerical scale.", + "special_limits": [] + }, + { + "target": "T13", + "case": "value_not_fact", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.valueNotFact012", + "file": "CoreReader/Adopted.lean", + "line": 643, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Clearly articulated false assumptions, repeated wrong-object observations, neutral records compatible with nonadoption, and the ordinary value example show the intended non-substitutions. Qualitative implication orders claim strength without imposing a numerical scale.", + "special_limits": [] + }, + { + "target": "T13", + "case": "initial_value_without_selfproof", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.valueWithoutSelfProof", + "file": "CoreReader/Evidence.lean", + "line": 426, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Clearly articulated false assumptions, repeated wrong-object observations, neutral records compatible with nonadoption, and the ordinary value example show the intended non-substitutions. Qualitative implication orders claim strength without imposing a numerical scale.", + "special_limits": [] + }, + { + "target": "T13", + "case": "qualitative_proportionality", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.qualitativeProportionality012", + "file": "CoreReader/Adopted.lean", + "line": 348, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Clearly articulated false assumptions, repeated wrong-object observations, neutral records compatible with nonadoption, and the ordinary value example show the intended non-substitutions. Qualitative implication orders claim strength without imposing a numerical scale.", + "special_limits": [] + }, + { + "target": "T14", + "case": "local_scope_declared", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.scopeFulfilled012", + "file": "CoreReader/Adopted.lean", + "line": 379, + "axioms": "[propext]" + } + ], + "interpretation": "The local scope account binds comparison pairs, conditions, observed scope, relevance and each method explanation to the same claim. Its concrete method meanings prove local/repeated support and failure of global support. The generic explains relation remains supplied and the interface does not force every method to be used.", + "special_limits": [] + }, + { + "target": "T14", + "case": "omitted_relevant_difference", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.hiddenDifference", + "file": "CoreReader/Evidence.lean", + "line": 560, + "axioms": "[]" + } + ], + "interpretation": "The local scope account binds comparison pairs, conditions, observed scope, relevance and each method explanation to the same claim. Its concrete method meanings prove local/repeated support and failure of global support. The generic explains relation remains supplied and the interface does not force every method to be used.", + "special_limits": [] + }, + { + "target": "T14", + "case": "measurement_role", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.scopeFulfilled012", + "file": "CoreReader/Adopted.lean", + "line": 379, + "axioms": "[propext]" + } + ], + "interpretation": "The local scope account binds comparison pairs, conditions, observed scope, relevance and each method explanation to the same claim. Its concrete method meanings prove local/repeated support and failure of global support. The generic explains relation remains supplied and the interface does not force every method to be used.", + "special_limits": [] + }, + { + "target": "T14", + "case": "repetition_role", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.scopeFulfilled012", + "file": "CoreReader/Adopted.lean", + "line": 379, + "axioms": "[propext]" + } + ], + "interpretation": "The local scope account binds comparison pairs, conditions, observed scope, relevance and each method explanation to the same claim. Its concrete method meanings prove local/repeated support and failure of global support. The generic explains relation remains supplied and the interface does not force every method to be used.", + "special_limits": [] + }, + { + "target": "T14", + "case": "framework_role", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.scopeFulfilled012", + "file": "CoreReader/Adopted.lean", + "line": 379, + "axioms": "[propext]" + } + ], + "interpretation": "The local scope account binds comparison pairs, conditions, observed scope, relevance and each method explanation to the same claim. Its concrete method meanings prove local/repeated support and failure of global support. The generic explains relation remains supplied and the interface does not force every method to be used.", + "special_limits": [] + }, + { + "target": "T15", + "case": "equal_local_different_global", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.localNotUniversal", + "file": "CoreReader/Evidence.lean", + "line": 550, + "axioms": "[propext]" + } + ], + "interpretation": "Explicit functions agree only at zero and differ at one; one observation supplies local support. Trial fields separate recorded accuracy, equal settings and bounded output, and Boolean draws have equal positive weights with different outcomes. This is a finite possible-outcome model, not verification of a real stochastic process.", + "special_limits": [] + }, + { + "target": "T15", + "case": "excluded_difference", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.hiddenDifference", + "file": "CoreReader/Evidence.lean", + "line": 560, + "axioms": "[]" + } + ], + "interpretation": "Explicit functions agree only at zero and differ at one; one observation supplies local support. Trial fields separate recorded accuracy, equal settings and bounded output, and Boolean draws have equal positive weights with different outcomes. This is a finite possible-outcome model, not verification of a real stochastic process.", + "special_limits": [] + }, + { + "target": "T15", + "case": "one_observation_limited_support", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.singleObservation", + "file": "CoreReader/Evidence.lean", + "line": 566, + "axioms": "[propext]" + } + ], + "interpretation": "Explicit functions agree only at zero and differ at one; one observation supplies local support. Trial fields separate recorded accuracy, equal settings and bounded output, and Boolean draws have equal positive weights with different outcomes. This is a finite possible-outcome model, not verification of a real stochastic process.", + "special_limits": [] + }, + { + "target": "T15", + "case": "varying_random_outcomes", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.randomOutcomes012", + "file": "CoreReader/Adopted.lean", + "line": 744, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "Explicit functions agree only at zero and differ at one; one observation supplies local support. Trial fields separate recorded accuracy, equal settings and bounded output, and Boolean draws have equal positive weights with different outcomes. This is a finite possible-outcome model, not verification of a real stochastic process.", + "special_limits": [] + }, + { + "target": "T15", + "case": "qualitative_unmeasured_judgment", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.qualitativeUnmeasured012", + "file": "CoreReader/Adopted.lean", + "line": 724, + "axioms": "[propext]" + } + ], + "interpretation": "Explicit functions agree only at zero and differ at one; one observation supplies local support. Trial fields separate recorded accuracy, equal settings and bounded output, and Boolean draws have equal positive weights with different outcomes. This is a finite possible-outcome model, not verification of a real stochastic process.", + "special_limits": [] + }, + { + "target": "T16", + "case": "external_output_capability", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.capabilityFulfilled012", + "file": "CoreReader/Adopted.lean", + "line": 391, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved for the explicitly declared application capability UnderstandingApplication012: the same explained doubling process must also answer all multiplier/input variations using the actual multiplication mechanism. Identical output and ExplanationContract no longer suffice: the fixed-double answer gives 2 instead of 3 at multiplier=3,input=1, while mechanismResponder answers the declared variations and receives same-object Grounds. This is an operational understanding/variation-answer capability selected by the application, not a cognitive definition or universal standard of understanding.", + "special_limits": [] + }, + { + "target": "T16", + "case": "application_requires_understanding", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.understandingApplicationCases012", + "file": "CoreReader/Adopted.lean", + "line": 447, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved for the explicitly declared application capability UnderstandingApplication012: the same explained doubling process must also answer all multiplier/input variations using the actual multiplication mechanism. Identical output and ExplanationContract no longer suffice: the fixed-double answer gives 2 instead of 3 at multiplier=3,input=1, while mechanismResponder answers the declared variations and receives same-object Grounds. This is an operational understanding/variation-answer capability selected by the application, not a cognitive definition or universal standard of understanding.", + "special_limits": [ + "Application-defined all-multiplier variation-answer criterion; not an unrestricted cognitive claim.", + "Positive result uses the mechanism function; negative result fixes same Process and ExplanationContract but fails at (3,1)." + ] + }, + { + "target": "T16", + "case": "own_capability_assessment", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.ownCapability012", + "file": "CoreReader/Adopted.lean", + "line": 474, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved for the explicitly declared application capability UnderstandingApplication012: the same explained doubling process must also answer all multiplier/input variations using the actual multiplication mechanism. Identical output and ExplanationContract no longer suffice: the fixed-double answer gives 2 instead of 3 at multiplier=3,input=1, while mechanismResponder answers the declared variations and receives same-object Grounds. This is an operational understanding/variation-answer capability selected by the application, not a cognitive definition or universal standard of understanding.", + "special_limits": [] + }, + { + "target": "T17", + "case": "reliable_opaque_generator", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.outputNotExplanation", + "file": "CoreReader/Evidence.lean", + "line": 684, + "axioms": "[propext]" + } + ], + "interpretation": "Reliable double output with explanation = none refutes the stronger declared explanation contract; repeated item counts do not add an unavailable operation. This establishes limits on the represented output/explanation capability, not a cognitive account of human or agent understanding.", + "special_limits": [] + }, + { + "target": "T17", + "case": "high_count_no_stronger_capability", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.inventoryCases012", + "file": "CoreReader/Adopted.lean", + "line": 667, + "axioms": "[propext, Quot.sound.{u}]" + }, + { + "name": "CoreReader.Agency.generationLimits", + "file": "CoreReader/Agency.lean", + "line": 194, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "Reliable double output with explanation = none refutes the stronger declared explanation contract; repeated item counts do not add an unavailable operation. This establishes limits on the represented output/explanation capability, not a cognitive account of human or agent understanding.", + "special_limits": [] + }, + { + "target": "T17", + "case": "externally_articulated_no_introspection", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.externalAssessment", + "file": "CoreReader/Evidence.lean", + "line": 704, + "axioms": "[propext]" + } + ], + "interpretation": "Reliable double output with explanation = none refutes the stronger declared explanation contract; repeated item counts do not add an unavailable operation. This establishes limits on the represented output/explanation capability, not a cognitive account of human or agent understanding.", + "special_limits": [] + }, + { + "target": "T18", + "case": "named_only_rejected", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.allStatusOnly012", + "file": "CoreReader/Adopted.lean", + "line": 733, + "axioms": "[propext]" + } + ], + "interpretation": "JustifiedChoice combines feasibility with a valued method-content reason; status-only reasons fail by definition as the additional adopted evaluative commitment. Conventional identity remains eligible, internal explanation/applicability/simplicity/procedure reasons are admissible, and the current philosophy review is assessed by actual output reasons. No optimality or all-reasons-valid theorem is claimed.", + "special_limits": [] + }, + { + "target": "T18", + "case": "conventional_grounded_priority", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Choice.conventionWithReason", + "file": "CoreReader/Choice.lean", + "line": 108, + "axioms": "[propext]" + } + ], + "interpretation": "JustifiedChoice combines feasibility with a valued method-content reason; status-only reasons fail by definition as the additional adopted evaluative commitment. Conventional identity remains eligible, internal explanation/applicability/simplicity/procedure reasons are admissible, and the current philosophy review is assessed by actual output reasons. No optimality or all-reasons-valid theorem is claimed.", + "special_limits": [] + }, + { + "target": "T18", + "case": "method_internal_reason", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Choice.internalReasons", + "file": "CoreReader/Choice.lean", + "line": 151, + "axioms": "[]" + }, + { + "name": "CoreReader.Adopted.internalReasonDistinguishes012", + "file": "CoreReader/Adopted.lean", + "line": 657, + "axioms": "[]" + } + ], + "interpretation": "JustifiedChoice combines feasibility with a valued method-content reason; status-only reasons fail by definition as the additional adopted evaluative commitment. Conventional identity remains eligible, internal explanation/applicability/simplicity/procedure reasons are admissible, and the current philosophy review is assessed by actual output reasons. No optimality or all-reasons-valid theorem is claimed.", + "special_limits": [] + }, + { + "target": "T18", + "case": "own_philosophy_status_only", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.ownPhilosophyStatus012", + "file": "CoreReader/Adopted.lean", + "line": 690, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "JustifiedChoice combines feasibility with a valued method-content reason; status-only reasons fail by definition as the additional adopted evaluative commitment. Conventional identity remains eligible, internal explanation/applicability/simplicity/procedure reasons are admissible, and the current philosophy review is assessed by actual output reasons. No optimality or all-reasons-valid theorem is claimed.", + "special_limits": [] + }, + { + "target": "T19", + "case": "single_feasible_conventional", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Choice.singleFeasible", + "file": "CoreReader/Choice.lean", + "line": 121, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "A single feasible conventional choice, unequal outputs, equal local but different global behavior, and a distinguishing internal explanation meet the requested cases. The additional-choice example distinguishes accurate general assessment of non-entailment from the separate priority norm; this is deliberately the limited general-assessment relation in the target, not all Grounds duties.", + "special_limits": [] + }, + { + "target": "T19", + "case": "internal_reason_distinguishes", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.internalReasonDistinguishes012", + "file": "CoreReader/Adopted.lean", + "line": 657, + "axioms": "[]" + } + ], + "interpretation": "A single feasible conventional choice, unequal outputs, equal local but different global behavior, and a distinguishing internal explanation meet the requested cases. The additional-choice example distinguishes accurate general assessment of non-entailment from the separate priority norm; this is deliberately the limited general-assessment relation in the target, not all Grounds duties.", + "special_limits": [] + }, + { + "target": "T19", + "case": "unequal_open_options", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Choice.openNotEquivalent", + "file": "CoreReader/Choice.lean", + "line": 162, + "axioms": "[propext]" + } + ], + "interpretation": "A single feasible conventional choice, unequal outputs, equal local but different global behavior, and a distinguishing internal explanation meet the requested cases. The additional-choice example distinguishes accurate general assessment of non-entailment from the separate priority norm; this is deliberately the limited general-assessment relation in the target, not all Grounds duties.", + "special_limits": [] + }, + { + "target": "T19", + "case": "local_equal_global_difference", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Choice.localNotGlobal", + "file": "CoreReader/Choice.lean", + "line": 132, + "axioms": "[]" + } + ], + "interpretation": "A single feasible conventional choice, unequal outputs, equal local but different global behavior, and a distinguishing internal explanation meet the requested cases. The additional-choice example distinguishes accurate general assessment of non-entailment from the separate priority norm; this is deliberately the limited general-assessment relation in the target, not all Grounds duties.", + "special_limits": [] + }, + { + "target": "T19", + "case": "added_choice_not_from_general_assessment", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Choice.generalGroundsNotChoice", + "file": "CoreReader/Choice.lean", + "line": 257, + "axioms": "[propext]" + } + ], + "interpretation": "A single feasible conventional choice, unequal outputs, equal local but different global behavior, and a distinguishing internal explanation meet the requested cases. The additional-choice example distinguishes accurate general assessment of non-entailment from the separate priority norm; this is deliberately the limited general-assessment relation in the target, not all Grounds duties.", + "special_limits": [] + }, + { + "target": "T20", + "case": "own_grounds_articulable", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedMutualApplication", + "file": "CoreReader/Engineering/Integration.lean", + "line": 420, + "axioms": "[propext]" + }, + { + "name": "CoreReader.Engineering.governanceGrounded", + "file": "CoreReader/Engineering/Values.lean", + "line": 137, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved. The theorem now explicitly concludes the full normative-content membership, grounds for every held claim, and consistencySpecification for the same expanded ownTheory. It remains a legitimate projection of Inherited, not mutual logical derivation from fewer premises. Actual self-rule generation/assessment objects are included and checked; original empirical/inferential/value tasks remain separate.", + "special_limits": [] + }, + { + "target": "T20", + "case": "own_capability_supported", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedMutualApplication", + "file": "CoreReader/Engineering/Integration.lean", + "line": 420, + "axioms": "[propext]" + }, + { + "name": "CoreReader.Engineering.engineeringCapabilityGrounded", + "file": "CoreReader/Engineering/Integration.lean", + "line": 63, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved. The theorem now explicitly concludes the full normative-content membership, grounds for every held claim, and consistencySpecification for the same expanded ownTheory. It remains a legitimate projection of Inherited, not mutual logical derivation from fewer premises. Actual self-rule generation/assessment objects are included and checked; original empirical/inferential/value tasks remain separate.", + "special_limits": [] + }, + { + "target": "T20", + "case": "own_choice_not_status_only", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedMutualApplication", + "file": "CoreReader/Engineering/Integration.lean", + "line": 420, + "axioms": "[propext]" + }, + { + "name": "CoreReader.Engineering.implementationReasoned", + "file": "CoreReader/Engineering/Integration.lean", + "line": 41, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved. The theorem now explicitly concludes the full normative-content membership, grounds for every held claim, and consistencySpecification for the same expanded ownTheory. It remains a legitimate projection of Inherited, not mutual logical derivation from fewer premises. Actual self-rule generation/assessment objects are included and checked; original empirical/inferential/value tasks remain separate.", + "special_limits": [] + }, + { + "target": "T20", + "case": "relevant_self_application", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedMutualCases", + "file": "CoreReader/Engineering/Integration.lean", + "line": 442, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + }, + { + "name": "CoreReader.Engineering.ownRuleContentVariation", + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 204, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved. The theorem now explicitly concludes the full normative-content membership, grounds for every held claim, and consistencySpecification for the same expanded ownTheory. It remains a legitimate projection of Inherited, not mutual logical derivation from fewer premises. Actual self-rule generation/assessment objects are included and checked; original empirical/inferential/value tasks remain separate.", + "special_limits": [ + "The empty-tested-list criticism concerns the sample-aware local assessmentRuleTest contract; it is not a philosophical demand for empirical samples in every judgment." + ] + }, + { + "target": "T22", + "case": "successor_maintainer", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLifecycleCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 146, + "axioms": "[propext]" + } + ], + "interpretation": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established.", + "special_limits": [] + }, + { + "target": "T22", + "case": "agent_maintainer", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLifecycleCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 146, + "axioms": "[propext]" + } + ], + "interpretation": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established.", + "special_limits": [] + }, + { + "target": "T22", + "case": "continuing_labeled_temporary", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLifecycleCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 146, + "axioms": "[propext]" + } + ], + "interpretation": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established.", + "special_limits": [] + }, + { + "target": "T22", + "case": "genuinely_temporary", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLifecycleCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 146, + "axioms": "[propext]" + } + ], + "interpretation": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established.", + "special_limits": [] + }, + { + "target": "T22", + "case": "bounded_prototype", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLifecycleCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 146, + "axioms": "[propext]" + } + ], + "interpretation": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established.", + "special_limits": [] + }, + { + "target": "T22", + "case": "retiring_system", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLifecycleCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 146, + "axioms": "[propext]" + } + ], + "interpretation": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established.", + "special_limits": [] + }, + { + "target": "T23", + "case": "author_only_private_knowledge", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 159, + "axioms": "[propext]" + } + ], + "interpretation": "The original maintainer has privateLayout while the successor lacks it; explicit path prerequisite failure establishes the contrast. The continuing activity remains nonbounded despite its temporary label. The passive artifact returns inputs and has no propose action by its actual definition, providing one counterexample rather than a law of all artifacts.", + "special_limits": [] + }, + { + "target": "T23", + "case": "successor_missing_path", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 159, + "axioms": "[propext]" + } + ], + "interpretation": "The original maintainer has privateLayout while the successor lacks it; explicit path prerequisite failure establishes the contrast. The continuing activity remains nonbounded despite its temporary label. The passive artifact returns inputs and has no propose action by its actual definition, providing one counterexample rather than a law of all artifacts.", + "special_limits": [] + }, + { + "target": "T23", + "case": "false_temporary_label", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 159, + "axioms": "[propext]" + } + ], + "interpretation": "The original maintainer has privateLayout while the successor lacks it; explicit path prerequisite failure establishes the contrast. The continuing activity remains nonbounded despite its temporary label. The passive artifact returns inputs and has no propose action by its actual definition, providing one counterexample rather than a law of all artifacts.", + "special_limits": [] + }, + { + "target": "T23", + "case": "passive_artifact", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 159, + "axioms": "[propext]" + } + ], + "interpretation": "The original maintainer has privateLayout while the successor lacks it; explicit path prerequisite failure establishes the contrast. The continuing activity remains nonbounded despite its temporary label. The passive artifact returns inputs and has no propose action by its actual definition, providing one counterexample rather than a law of all artifacts.", + "special_limits": [] + }, + { + "target": "T24", + "case": "ordinary_priority", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.priorityConditionsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 367, + "axioms": "[propext]" + } + ], + "interpretation": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "special_limits": [] + }, + { + "target": "T24", + "case": "missing_behavior", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.unmetRequirementsBlockPriority", + "file": "CoreReader/Engineering/Domain.lean", + "line": 353, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "special_limits": [] + }, + { + "target": "T24", + "case": "missing_safety", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.unmetRequirementsBlockPriority", + "file": "CoreReader/Engineering/Domain.lean", + "line": 353, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "special_limits": [] + }, + { + "target": "T24", + "case": "missing_performance", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.unmetRequirementsBlockPriority", + "file": "CoreReader/Engineering/Domain.lean", + "line": 353, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "special_limits": [] + }, + { + "target": "T24", + "case": "missing_other_necessary", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.unmetRequirementsBlockPriority", + "file": "CoreReader/Engineering/Domain.lean", + "line": 353, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "special_limits": [] + }, + { + "target": "T24", + "case": "concrete_cost_override", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.priorityConditionsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 367, + "axioms": "[propext]" + } + ], + "interpretation": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "special_limits": [] + }, + { + "target": "T24", + "case": "unexplained_departure", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.priorityConditionsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 367, + "axioms": "[propext]" + } + ], + "interpretation": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "special_limits": [] + }, + { + "target": "T24", + "case": "no_extensibility_maximum", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 394, + "axioms": "[propext]" + } + ], + "interpretation": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "special_limits": [] + }, + { + "target": "T25", + "case": "applicable_choose_evolution", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.priorityWhenApplicable", + "file": "CoreReader/Engineering/Domain.lean", + "line": 337, + "axioms": "[]" + }, + { + "name": "CoreReader.Engineering.priorityChoices", + "file": "CoreReader/Engineering/Domain.lean", + "line": 384, + "axioms": "[propext]" + } + ], + "interpretation": "The theorem explicitly assumes the adopted EvolutionPriority rule, applicability and no departure; it extracts the chosen evolvable value and substitutes into the supplied complexity comparison. This matches the target's normative-premise requirement. Concrete choices show simple violates the rule without a threat and can pass with the accounted threat.", + "special_limits": [] + }, + { + "target": "T25", + "case": "applicable_choose_simple_violates_domain", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.currentSimpleViolates", + "file": "CoreReader/Engineering/Domain.lean", + "line": 345, + "axioms": "[propext]" + } + ], + "interpretation": "The theorem explicitly assumes the adopted EvolutionPriority rule, applicability and no departure; it extracts the chosen evolvable value and substitutes into the supplied complexity comparison. This matches the target's normative-premise requirement. Concrete choices show simple violates the rule without a threat and can pass with the accounted threat.", + "special_limits": [] + }, + { + "target": "T25", + "case": "threat_allows_departure_with_account", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.priorityChoices", + "file": "CoreReader/Engineering/Domain.lean", + "line": 384, + "axioms": "[propext]" + } + ], + "interpretation": "The theorem explicitly assumes the adopted EvolutionPriority rule, applicability and no departure; it extracts the chosen evolvable value and substitutes into the supplied complexity comparison. This matches the target's normative-premise requirement. Concrete choices show simple violates the rule without a threat and can pass with the accounted threat.", + "special_limits": [] + }, + { + "target": "T26", + "case": "committed_plan_one_implementation", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 212, + "axioms": "[]" + }, + { + "name": "CoreReader.Engineering.credibilityLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 394, + "axioms": "[propext]" + } + ], + "interpretation": "The generic Ground interface does not restrict ground categories. Concrete plans identify a positive release and direction; knowledge/history cases contain a service/mechanism or repeated direction list, and forecast revision changes supported directions. The adapter only checks designated strings/list content, so actual relevance of a mechanism/history is a stipulated interpretation. It must not be reported as independent validation of arbitrary knowledge records.", + "special_limits": [] + }, + { + "target": "T26", + "case": "domain_knowledge", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 212, + "axioms": "[]" + } + ], + "interpretation": "The generic Ground interface does not restrict ground categories. Concrete plans identify a positive release and direction; knowledge/history cases contain a service/mechanism or repeated direction list, and forecast revision changes supported directions. The adapter only checks designated strings/list content, so actual relevance of a mechanism/history is a stipulated interpretation. It must not be reported as independent validation of arbitrary knowledge records.", + "special_limits": [] + }, + { + "target": "T26", + "case": "applicable_history", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 212, + "axioms": "[]" + } + ], + "interpretation": "The generic Ground interface does not restrict ground categories. Concrete plans identify a positive release and direction; knowledge/history cases contain a service/mechanism or repeated direction list, and forecast revision changes supported directions. The adapter only checks designated strings/list content, so actual relevance of a mechanism/history is a stipulated interpretation. It must not be reported as independent validation of arbitrary knowledge records.", + "special_limits": [] + }, + { + "target": "T26", + "case": "conceivable_only", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 212, + "axioms": "[]" + } + ], + "interpretation": "The generic Ground interface does not restrict ground categories. Concrete plans identify a positive release and direction; knowledge/history cases contain a service/mechanism or repeated direction list, and forecast revision changes supported directions. The adapter only checks designated strings/list content, so actual relevance of a mechanism/history is a stipulated interpretation. It must not be reported as independent validation of arbitrary knowledge records.", + "special_limits": [] + }, + { + "target": "T26", + "case": "revised_forecast", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 212, + "axioms": "[]" + } + ], + "interpretation": "The generic Ground interface does not restrict ground categories. Concrete plans identify a positive release and direction; knowledge/history cases contain a service/mechanism or repeated direction list, and forecast revision changes supported directions. The adapter only checks designated strings/list content, so actual relevance of a mechanism/history is a stipulated interpretation. It must not be reported as independent validation of arbitrary knowledge records.", + "special_limits": [] + }, + { + "target": "T27", + "case": "one_implementation_credible", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 394, + "axioms": "[propext]" + } + ], + "interpretation": "One implemented variant coexists with credible direction; unsupported imagined changes do not warrant the defined investment; evolvable supports nine registered directions while maximal supports ten but is not the priority. Different per-burden bounds and work comparisons demonstrate a selective example, not a mathematical impossibility of numerical tradeoffs.", + "special_limits": [] + }, + { + "target": "T27", + "case": "imagined_unwarranted", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 394, + "axioms": "[propext]" + } + ], + "interpretation": "One implemented variant coexists with credible direction; unsupported imagined changes do not warrant the defined investment; evolvable supports nine registered directions while maximal supports ten but is not the priority. Different per-burden bounds and work comparisons demonstrate a selective example, not a mathematical impossibility of numerical tradeoffs.", + "special_limits": [] + }, + { + "target": "T27", + "case": "selective_evolution", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 394, + "axioms": "[propext]" + } + ], + "interpretation": "One implemented variant coexists with credible direction; unsupported imagined changes do not warrant the defined investment; evolvable supports nine registered directions while maximal supports ten but is not the priority. Different per-burden bounds and work comparisons demonstrate a selective example, not a mathematical impossibility of numerical tradeoffs.", + "special_limits": [] + }, + { + "target": "T27", + "case": "qualitative_tradeoff", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 394, + "axioms": "[propext]" + } + ], + "interpretation": "One implemented variant coexists with credible direction; unsupported imagined changes do not warrant the defined investment; evolvable supports nine registered directions while maximal supports ten but is not the priority. Different per-burden bounds and work comparisons demonstrate a selective example, not a mathematical impossibility of numerical tradeoffs.", + "special_limits": [] + }, + { + "target": "T28", + "case": "understanding_threat", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.costCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "axioms": "[propext]" + } + ], + "interpretation": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "special_limits": [] + }, + { + "target": "T28", + "case": "construction_threat", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.costCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "axioms": "[propext]" + } + ], + "interpretation": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "special_limits": [] + }, + { + "target": "T28", + "case": "diagnosis_threat", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.costCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "axioms": "[propext]" + } + ], + "interpretation": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "special_limits": [] + }, + { + "target": "T28", + "case": "verification_threat", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.costCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "axioms": "[propext]" + } + ], + "interpretation": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "special_limits": [] + }, + { + "target": "T28", + "case": "coordination_threat", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.costCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "axioms": "[propext]" + } + ], + "interpretation": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "special_limits": [] + }, + { + "target": "T28", + "case": "operation_threat", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.costCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "axioms": "[propext]" + } + ], + "interpretation": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "special_limits": [] + }, + { + "target": "T28", + "case": "migration_threat", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.costCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "axioms": "[propext]" + } + ], + "interpretation": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "special_limits": [] + }, + { + "target": "T28", + "case": "unsupported_cost_excuse", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.costCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "axioms": "[propext]" + } + ], + "interpretation": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "special_limits": [] + }, + { + "target": "T29", + "case": "addition", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "replacement", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "deletion", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "withdrawal", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "redrawing", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "migration", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "independent", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "coordinated", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "preserve_obligation", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "revise_obligation", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T30", + "case": "easy_add_hard_exit", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionDimensionsLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 585, + "axioms": "[propext]" + } + ], + "interpretation": "Addition can cost two while withdrawal/revision costs seventeen; coordinated work exceeds independent work; migration can remain expensive while evolution priority holds. Equal addition cost directly refutes universal strict improvement over all Change values.", + "special_limits": [] + }, + { + "target": "T30", + "case": "independent_easy_coordinated_hard", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionDimensionsLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 585, + "axioms": "[propext]" + } + ], + "interpretation": "Addition can cost two while withdrawal/revision costs seventeen; coordinated work exceeds independent work; migration can remain expensive while evolution priority holds. Equal addition cost directly refutes universal strict improvement over all Change values.", + "special_limits": [] + }, + { + "target": "T30", + "case": "some_change_expensive_permitted", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionDimensionsLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 585, + "axioms": "[propext]" + } + ], + "interpretation": "Addition can cost two while withdrawal/revision costs seventeen; coordinated work exceeds independent work; migration can remain expensive while evolution priority holds. Equal addition cost directly refutes universal strict improvement over all Change values.", + "special_limits": [] + }, + { + "target": "T31", + "case": "contract_and_work_comparison", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.structuralCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 733, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved as a finite intended-change case. actualCrossBoundaryObligation links the registered edge caller 2/callee 1 to a real callee compiler edit, a caller contractRunner/publicContract step and finite observed order preservation. Removing the caller check leaves the crossing true but rejects the obligation; changing the callee to 7 loses the crossing; replacing output with sortedUnique fails the contract. No network/runtime semantics or universal completeness of every edge is claimed.", + "special_limits": [] + }, + { + "target": "T31", + "case": "propagation_relation", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.structuralCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 733, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved as a finite intended-change case. actualCrossBoundaryObligation links the registered edge caller 2/callee 1 to a real callee compiler edit, a caller contractRunner/publicContract step and finite observed order preservation. Removing the caller check leaves the crossing true but rejects the obligation; changing the callee to 7 loses the crossing; replacing output with sortedUnique fails the contract. No network/runtime semantics or universal completeness of every edge is claimed.", + "special_limits": [] + }, + { + "target": "T31", + "case": "cross_boundary_obligation", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.actualCrossBoundaryObligation", + "file": "CoreReader/Engineering/Domain.lean", + "line": 720, + "axioms": "[]" + } + ], + "interpretation": "Resolved as a finite intended-change case. actualCrossBoundaryObligation links the registered edge caller 2/callee 1 to a real callee compiler edit, a caller contractRunner/publicContract step and finite observed order preservation. Removing the caller check leaves the crossing true but rejects the obligation; changing the callee to 7 loses the crossing; replacing output with sortedUnique fails the contract. No network/runtime semantics or universal completeness of every edge is claimed.", + "special_limits": [ + "Fixed caller/callee/contract family and finite observation domain; no universal runtime dependency semantics." + ] + }, + { + "target": "T31", + "case": "fixed_assumption", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.structuralCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 733, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved as a finite intended-change case. actualCrossBoundaryObligation links the registered edge caller 2/callee 1 to a real callee compiler edit, a caller contractRunner/publicContract step and finite observed order preservation. Removing the caller check leaves the crossing true but rejects the obligation; changing the callee to 7 loses the crossing; replacing output with sortedUnique fails the contract. No network/runtime semantics or universal completeness of every edge is claimed.", + "special_limits": [] + }, + { + "target": "T31", + "case": "withdrawal_cost", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.structuralCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 733, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved as a finite intended-change case. actualCrossBoundaryObligation links the registered edge caller 2/callee 1 to a real callee compiler edit, a caller contractRunner/publicContract step and finite observed order preservation. Removing the caller check leaves the crossing true but rejects the obligation; changing the callee to 7 loses the crossing; replacing output with sortedUnique fails the contract. No network/runtime semantics or universal completeness of every edge is claimed.", + "special_limits": [] + }, + { + "target": "T32", + "case": "same_shape_broken_order", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.structureNotCapability", + "file": "CoreReader/Engineering/Domain.lean", + "line": 793, + "axioms": "[propext]" + } + ], + "interpretation": "The frozen delta now supplies the exact new_boundary_same_work case missing from the initial code: an actual added boundary and changed path with identical units/work and remaining successor prerequisite failure. The original increased-work example is retained. These and the signature/module/named-pattern examples meet the finite negative target, without proving real-world overhead or boundary execution semantics.", + "special_limits": [] + }, + { + "target": "T32", + "case": "many_modules_shared_obligation", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.structureNotCapability", + "file": "CoreReader/Engineering/Domain.lean", + "line": 793, + "axioms": "[propext]" + } + ], + "interpretation": "The frozen delta now supplies the exact new_boundary_same_work case missing from the initial code: an actual added boundary and changed path with identical units/work and remaining successor prerequisite failure. The original increased-work example is retained. These and the signature/module/named-pattern examples meet the finite negative target, without proving real-world overhead or boundary execution semantics.", + "special_limits": [] + }, + { + "target": "T32", + "case": "named_pattern_no_change_path", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.structureNotCapability", + "file": "CoreReader/Engineering/Domain.lean", + "line": 793, + "axioms": "[propext]" + } + ], + "interpretation": "The frozen delta now supplies the exact new_boundary_same_work case missing from the initial code: an actual added boundary and changed path with identical units/work and remaining successor prerequisite failure. The original increased-work example is retained. These and the signature/module/named-pattern examples meet the finite negative target, without proving real-world overhead or boundary execution semantics.", + "special_limits": [] + }, + { + "target": "T32", + "case": "new_boundary_same_work", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.structureNotCapability", + "file": "CoreReader/Engineering/Domain.lean", + "line": 793, + "axioms": "[propext]" + } + ], + "interpretation": "The frozen delta now supplies the exact new_boundary_same_work case missing from the initial code: an actual added boundary and changed path with identical units/work and remaining successor prerequisite failure. The original increased-work example is retained. These and the signature/module/named-pattern examples meet the finite negative target, without proving real-world overhead or boundary execution semantics.", + "special_limits": [] + }, + { + "target": "T33", + "case": "preserve_identified_contract", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.contractCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 843, + "axioms": "[]" + } + ], + "interpretation": "ContractChangeAccount separates finite scoped equality from deliberate revision with changed order/retry obligations and affected-party coverage. Missing operator/incorrect old limits fail; [99] demonstrates an intentionally out-of-scope historical difference; changing procedure text remains allowed. Actual notification, completeness of parties and all-input equivalence are not modeled.", + "special_limits": [] + }, + { + "target": "T33", + "case": "deliberate_revision_with_account", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.contractCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 843, + "axioms": "[]" + } + ], + "interpretation": "ContractChangeAccount separates finite scoped equality from deliberate revision with changed order/retry obligations and affected-party coverage. Missing operator/incorrect old limits fail; [99] demonstrates an intentionally out-of-scope historical difference; changing procedure text remains allowed. Actual notification, completeness of parties and all-input equivalence are not modeled.", + "special_limits": [] + }, + { + "target": "T33", + "case": "revision_missing_parties", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.contractCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 843, + "axioms": "[]" + } + ], + "interpretation": "ContractChangeAccount separates finite scoped equality from deliberate revision with changed order/retry obligations and affected-party coverage. Missing operator/incorrect old limits fail; [99] demonstrates an intentionally out-of-scope historical difference; changing procedure text remains allowed. Actual notification, completeness of parties and all-input equivalence are not modeled.", + "special_limits": [] + }, + { + "target": "T33", + "case": "retired_historical_behavior", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.contractCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 843, + "axioms": "[]" + } + ], + "interpretation": "ContractChangeAccount separates finite scoped equality from deliberate revision with changed order/retry obligations and affected-party coverage. Missing operator/incorrect old limits fail; [99] demonstrates an intentionally out-of-scope historical difference; changing procedure text remains allowed. Actual notification, completeness of parties and all-input equivalence are not modeled.", + "special_limits": [] + }, + { + "target": "T33", + "case": "alternative_procedure", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.contractCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 843, + "axioms": "[]" + } + ], + "interpretation": "ContractChangeAccount separates finite scoped equality from deliberate revision with changed order/retry obligations and affected-party coverage. Missing operator/incorrect old limits fail; [99] demonstrates an intentionally out-of-scope historical difference; changing procedure text remains allowed. Actual notification, completeness of parties and all-input equivalence are not modeled.", + "special_limits": [] + }, + { + "target": "T34", + "case": "order_preserving_refactor", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.contractPreservation", + "file": "CoreReader/Engineering/Domain.lean", + "line": 822, + "axioms": "[]" + }, + { + "name": "CoreReader.Engineering.contractDistinctions", + "file": "CoreReader/Engineering/Domain.lean", + "line": 853, + "axioms": "[]" + } + ], + "interpretation": "contractPreservation returns the supplied universal in-scope equality proof, rather than deriving it from finite tests. changedObservationNotPreserved gives the counterexample implication; contractRevisionObligations eliminates the failed preservation branch of the assumed account. Finite order/retry cases illustrate the distinction. This is the correct conditional reading of the target, not an empirical proof from test success.", + "special_limits": [] + }, + { + "target": "T34", + "case": "sorted_order_revision", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.changedObservationNotPreserved", + "file": "CoreReader/Engineering/Domain.lean", + "line": 826, + "axioms": "[]" + }, + { + "name": "CoreReader.Engineering.contractDistinctions", + "file": "CoreReader/Engineering/Domain.lean", + "line": 853, + "axioms": "[]" + } + ], + "interpretation": "contractPreservation returns the supplied universal in-scope equality proof, rather than deriving it from finite tests. changedObservationNotPreserved gives the counterexample implication; contractRevisionObligations eliminates the failed preservation branch of the assumed account. Finite order/retry cases illustrate the distinction. This is the correct conditional reading of the target, not an empirical proof from test success.", + "special_limits": [] + }, + { + "target": "T34", + "case": "changed_failure_obligation", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.contractRevisionObligations", + "file": "CoreReader/Engineering/Domain.lean", + "line": 832, + "axioms": "[]" + }, + { + "name": "CoreReader.Engineering.contractDistinctions", + "file": "CoreReader/Engineering/Domain.lean", + "line": 853, + "axioms": "[]" + } + ], + "interpretation": "contractPreservation returns the supplied universal in-scope equality proof, rather than deriving it from finite tests. changedObservationNotPreserved gives the counterexample implication; contractRevisionObligations eliminates the failed preservation branch of the assumed account. Finite order/retry cases illustrate the distinction. This is the correct conditional reading of the target, not an empirical proof from test success.", + "special_limits": [] + }, + { + "target": "T34", + "case": "outside_scope_difference", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.contractDistinctions", + "file": "CoreReader/Engineering/Domain.lean", + "line": 853, + "axioms": "[]" + } + ], + "interpretation": "contractPreservation returns the supplied universal in-scope equality proof, rather than deriving it from finite tests. changedObservationNotPreserved gives the counterexample implication; contractRevisionObligations eliminates the failed preservation branch of the assumed account. Finite order/retry cases illustrate the distinction. This is the correct conditional reading of the target, not an empirical proof from test success.", + "special_limits": [] + }, + { + "target": "T35", + "case": "revised_change_forecast", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.revisionCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 951, + "axioms": "[propext]" + } + ], + "interpretation": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign.", + "special_limits": [] + }, + { + "target": "T35", + "case": "changed_maintainers", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.revisionCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 951, + "axioms": "[propext]" + } + ], + "interpretation": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign.", + "special_limits": [] + }, + { + "target": "T35", + "case": "changed_cost", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.revisionCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 951, + "axioms": "[propext]" + } + ], + "interpretation": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign.", + "special_limits": [] + }, + { + "target": "T35", + "case": "changed_objective", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.revisionCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 951, + "axioms": "[propext]" + } + ], + "interpretation": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign.", + "special_limits": [] + }, + { + "target": "T35", + "case": "failed_prediction_preserved", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.historicalTamperingRejected", + "file": "CoreReader/Engineering/Domain.lean", + "line": 980, + "axioms": "[]" + }, + { + "name": "CoreReader.Engineering.failedHistoryNotRewritten", + "file": "CoreReader/Engineering/Domain.lean", + "line": 924, + "axioms": "[propext]" + } + ], + "interpretation": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign.", + "special_limits": [] + }, + { + "target": "T35", + "case": "justified_retention", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.revisionCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 951, + "axioms": "[propext]" + } + ], + "interpretation": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign.", + "special_limits": [] + }, + { + "target": "T36", + "case": "past_failure_not_rewritten", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.historicalTamperingRejected", + "file": "CoreReader/Engineering/Domain.lean", + "line": 980, + "axioms": "[]" + }, + { + "name": "CoreReader.Engineering.failedHistoryNotRewritten", + "file": "CoreReader/Engineering/Domain.lean", + "line": 924, + "axioms": "[propext]" + } + ], + "interpretation": "Prior finite no-retroactive-success/consensus/success examples are retained. A fresh same-object probe proves revisionFor sharedContext evolvable retains the old/current design choice while selfModel evolvable satisfies reflection; this makes the open-stable example explicit without turning all stability into a duty.", + "special_limits": [] + }, + { + "target": "T36", + "case": "agreement_with_bad_case", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.revisionLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 993, + "axioms": "[propext]" + } + ], + "interpretation": "Prior finite no-retroactive-success/consensus/success examples are retained. A fresh same-object probe proves revisionFor sharedContext evolvable retains the old/current design choice while selfModel evolvable satisfies reflection; this makes the open-stable example explicit without turning all stability into a duty.", + "special_limits": [] + }, + { + "target": "T36", + "case": "local_success_global_failure", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.revisionLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 993, + "axioms": "[propext]" + } + ], + "interpretation": "Prior finite no-retroactive-success/consensus/success examples are retained. A fresh same-object probe proves revisionFor sharedContext evolvable retains the old/current design choice while selfModel evolvable satisfies reflection; this makes the open-stable example explicit without turning all stability into a duty.", + "special_limits": [] + }, + { + "target": "T36", + "case": "open_stable_design", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.revisionContextIdentity", + "file": "CoreReader/Engineering/Domain.lean", + "line": 1020, + "axioms": "[propext]" + }, + { + "name": "CoreReader.Engineering.currentSelfApplication", + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 161, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Prior finite no-retroactive-success/consensus/success examples are retained. A fresh same-object probe proves revisionFor sharedContext evolvable retains the old/current design choice while selfModel evolvable satisfies reflection; this makes the open-stable example explicit without turning all stability into a duty.", + "special_limits": [] + }, + { + "target": "T37", + "case": "priority_self_assessment", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.priorityRemainsReflexive", + "file": "CoreReader/Engineering/Integration.lean", + "line": 467, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + }, + { + "name": "CoreReader.Engineering.priorityReflexiveCases", + "file": "CoreReader/Engineering/Integration.lean", + "line": 493, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Resolved in the same fixed shared context. priorityValueMeaning proves candidate-by-candidate equivalence between the adopted evolvable selection commitment and actual EvolutionPriority; priorityGrounds transports value support through that explicit equality while preserving the value task. The theorem now returns that exact priority claim's Grounds, domain-content membership and complete-theory consistency, in addition to reflection. The equivalence depends on current applicability/no-departure and must not be generalized to other contexts.", + "special_limits": [] + }, + { + "target": "T37", + "case": "method_self_criticism", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.actualSelfCriticism", + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 170, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + }, + { + "name": "CoreReader.Engineering.ownRuleContentVariation", + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 204, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved in the same fixed shared context. priorityValueMeaning proves candidate-by-candidate equivalence between the adopted evolvable selection commitment and actual EvolutionPriority; priorityGrounds transports value support through that explicit equality while preserving the value task. The theorem now returns that exact priority claim's Grounds, domain-content membership and complete-theory consistency, in addition to reflection. The equivalence depends on current applicability/no-departure and must not be generalized to other contexts.", + "special_limits": [ + "The empty-tested-list criticism concerns the sample-aware local assessmentRuleTest contract; it is not a philosophical demand for empirical samples in every judgment." + ] + }, + { + "target": "T37", + "case": "no_selfproof_from_success", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.priorityReflexiveCases", + "file": "CoreReader/Engineering/Integration.lean", + "line": 493, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + }, + { + "name": "CoreReader.Engineering.proposedRuleRevision", + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 218, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "Resolved in the same fixed shared context. priorityValueMeaning proves candidate-by-candidate equivalence between the adopted evolvable selection commitment and actual EvolutionPriority; priorityGrounds transports value support through that explicit equality while preserving the value task. The theorem now returns that exact priority claim's Grounds, domain-content membership and complete-theory consistency, in addition to reflection. The equivalence depends on current applicability/no-departure and must not be generalized to other contexts.", + "special_limits": [ + "The empty-tested-list criticism concerns the sample-aware local assessmentRuleTest contract; it is not a philosophical demand for empirical samples in every judgment." + ] + }, + { + "target": "T38", + "case": "joint_all_inherited_and_domain", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.jointWitness", + "file": "CoreReader/Engineering/Integration.lean", + "line": 557, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Accepted as the requested bounded inhabitation witness after rechecking expanded Inherited and ownTheory, not merely its unchanged exterior theorem statement. The same evolvable candidate/context satisfies original necessary requirements, applicable priority/no threat, actual maintainer paths, full held fact/norm content, original support tasks and actual self-rule reflection. Source interpretation remains a revisable finite model; no empirical or philosophical universal correctness follows.", + "special_limits": [] + }, + { + "target": "T38", + "case": "same_context_identity", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.jointWitness", + "file": "CoreReader/Engineering/Integration.lean", + "line": 557, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Accepted as the requested bounded inhabitation witness after rechecking expanded Inherited and ownTheory, not merely its unchanged exterior theorem statement. The same evolvable candidate/context satisfies original necessary requirements, applicable priority/no threat, actual maintainer paths, full held fact/norm content, original support tasks and actual self-rule reflection. Source interpretation remains a revisable finite model; no empirical or philosophical universal correctness follows.", + "special_limits": [] + }, + { + "target": "T38", + "case": "nonempty_claims_and_principles", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.jointWitness", + "file": "CoreReader/Engineering/Integration.lean", + "line": 557, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + }, + { + "name": "CoreReader.Engineering.allNormativeContentHeld", + "file": "CoreReader/Engineering/Integration.lean", + "line": 293, + "axioms": "[propext]" + } + ], + "interpretation": "Accepted as the requested bounded inhabitation witness after rechecking expanded Inherited and ownTheory, not merely its unchanged exterior theorem statement. The same evolvable candidate/context satisfies original necessary requirements, applicable priority/no threat, actual maintainer paths, full held fact/norm content, original support tasks and actual self-rule reflection. Source interpretation remains a revisable finite model; no empirical or philosophical universal correctness follows.", + "special_limits": [] + }, + { + "target": "T38", + "case": "active_evolution_priority", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.jointWitness", + "file": "CoreReader/Engineering/Integration.lean", + "line": 557, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Accepted as the requested bounded inhabitation witness after rechecking expanded Inherited and ownTheory, not merely its unchanged exterior theorem statement. The same evolvable candidate/context satisfies original necessary requirements, applicable priority/no threat, actual maintainer paths, full held fact/norm content, original support tasks and actual self-rule reflection. Source interpretation remains a revisable finite model; no empirical or philosophical universal correctness follows.", + "special_limits": [] + }, + { + "target": "T38", + "case": "content_bearing_maintainer_change", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.jointWitness", + "file": "CoreReader/Engineering/Integration.lean", + "line": 557, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + }, + { + "name": "CoreReader.Engineering.actualCapabilityContrast", + "file": "CoreReader/Engineering/Integration.lean", + "line": 67, + "axioms": "[propext]" + } + ], + "interpretation": "Accepted as the requested bounded inhabitation witness after rechecking expanded Inherited and ownTheory, not merely its unchanged exterior theorem statement. The same evolvable candidate/context satisfies original necessary requirements, applicable priority/no threat, actual maintainer paths, full held fact/norm content, original support tasks and actual self-rule reflection. Source interpretation remains a revisable finite model; no empirical or philosophical universal correctness follows.", + "special_limits": [] + }, + { + "target": "T39", + "case": "all_inherited_applicable_domain_not_adopted", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedDoesNotEntailPriority", + "file": "CoreReader/Engineering/Integration.lean", + "line": 586, + "axioms": "[propext,\n Classical.choice.{u},\n Quot.sound.{u}]" + } + ], + "interpretation": "Accepted as the requested bounded non-entailment witness with every original strong branch preserved. The same continuing shared context has real encoded applicability/advantage and no lifecycle/cost escape; presentSimple adopts a separately grounded simplicity value and satisfies expanded inherited duties yet fails the extra priority. normApplies records adoption of the additional domain norm, not disappearance of its actual PriorityConditions. This distinction is central to the source's additional-value claim.", + "special_limits": [] + }, + { + "target": "T39", + "case": "no_temporary_escape", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedDoesNotEntailPriority", + "file": "CoreReader/Engineering/Integration.lean", + "line": 586, + "axioms": "[propext,\n Classical.choice.{u},\n Quot.sound.{u}]" + } + ], + "interpretation": "Accepted as the requested bounded non-entailment witness with every original strong branch preserved. The same continuing shared context has real encoded applicability/advantage and no lifecycle/cost escape; presentSimple adopts a separately grounded simplicity value and satisfies expanded inherited duties yet fails the extra priority. normApplies records adoption of the additional domain norm, not disappearance of its actual PriorityConditions. This distinction is central to the source's additional-value claim.", + "special_limits": [] + }, + { + "target": "T39", + "case": "no_cost_escape", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedDoesNotEntailPriority", + "file": "CoreReader/Engineering/Integration.lean", + "line": 586, + "axioms": "[propext,\n Classical.choice.{u},\n Quot.sound.{u}]" + } + ], + "interpretation": "Accepted as the requested bounded non-entailment witness with every original strong branch preserved. The same continuing shared context has real encoded applicability/advantage and no lifecycle/cost escape; presentSimple adopts a separately grounded simplicity value and satisfies expanded inherited duties yet fails the extra priority. normApplies records adoption of the additional domain norm, not disappearance of its actual PriorityConditions. This distinction is central to the source's additional-value claim.", + "special_limits": [] + }, + { + "target": "T39", + "case": "genuine_priority_failure", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedDoesNotEntailPriority", + "file": "CoreReader/Engineering/Integration.lean", + "line": 586, + "axioms": "[propext,\n Classical.choice.{u},\n Quot.sound.{u}]" + } + ], + "interpretation": "Accepted as the requested bounded non-entailment witness with every original strong branch preserved. The same continuing shared context has real encoded applicability/advantage and no lifecycle/cost escape; presentSimple adopts a separately grounded simplicity value and satisfies expanded inherited duties yet fails the extra priority. normApplies records adoption of the additional domain norm, not disappearance of its actual PriorityConditions. This distinction is central to the source's additional-value claim.", + "special_limits": [] + }, + { + "target": "T39", + "case": "inherited_grounds_for_other_value", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedDoesNotEntailPriority", + "file": "CoreReader/Engineering/Integration.lean", + "line": 586, + "axioms": "[propext,\n Classical.choice.{u},\n Quot.sound.{u}]" + }, + { + "name": "CoreReader.Engineering.selectionGrounded", + "file": "CoreReader/Engineering/Values.lean", + "line": 219, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Accepted as the requested bounded non-entailment witness with every original strong branch preserved. The same continuing shared context has real encoded applicability/advantage and no lifecycle/cost escape; presentSimple adopts a separately grounded simplicity value and satisfies expanded inherited duties yet fails the extra priority. normApplies records adoption of the additional domain norm, not disappearance of its actual PriorityConditions. This distinction is central to the source's additional-value claim.", + "special_limits": [] + } + ], + "changed_helper_evidence": [ + { + "name": "CoreReader.Adopted.UnderstandingApplication012", + "file": "CoreReader/Adopted.lean", + "line": 413, + "end": 417, + "kind": "def", + "axioms": "[]", + "exact_code": "def UnderstandingApplication012 (assessed : MechanismApplication012) : Prop :=\n FullProcessContract assessed.process ∧\n (∀ input, assessed.process.output input = mechanism012 2 input) ∧\n ∀ multiplier input, assessed.answer multiplier input = mechanism012 multiplier input\n\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Adopted.mechanismResponderUnderstands012", + "file": "CoreReader/Adopted.lean", + "line": 435, + "end": 439, + "kind": "theorem", + "axioms": "[propext]", + "exact_code": "theorem mechanismResponderUnderstands012 : UnderstandingApplication012 mechanismResponder012 := by\n refine ⟨⟨(fun _ => rfl), .doubleInput, rfl, (fun _ => rfl)⟩, ?_, fun _ _ => rfl⟩\n intro input\n simp [mechanismResponder012, explainedProcess, mechanism012, Nat.two_mul]\n\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Adopted.explainedWithoutVariationFails012", + "file": "CoreReader/Adopted.lean", + "line": 440, + "end": 446, + "kind": "theorem", + "axioms": "[propext]", + "exact_code": "theorem explainedWithoutVariationFails012 :\n ¬ UnderstandingApplication012 explainedWithoutVariation012 := by\n intro h\n have wrong := h.2.2 3 1\n change 2 = 3 at wrong\n cases wrong\n\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Adopted.understandingApplicationCases012", + "file": "CoreReader/Adopted.lean", + "line": 447, + "end": 470, + "kind": "theorem", + "axioms": "[propext]", + "exact_code": "theorem understandingApplicationCases012 :\n explainedWithoutVariation012.process = mechanismResponder012.process ∧\n FullProcessContract explainedWithoutVariation012.process ∧\n ¬ UnderstandingApplication012 explainedWithoutVariation012 ∧\n UnderstandingApplication012 mechanismResponder012 ∧\n Grounds012 UnderstandingApplication012 canonicalArticulation\n [understandingFacet012 mechanismResponder012] (understandingTask012 mechanismResponder012) ∧\n ¬ Grounds012 UnderstandingApplication012 canonicalArticulation\n [understandingFacet012 explainedWithoutVariation012] (understandingTask012 explainedWithoutVariation012) := by\n refine ⟨rfl, ⟨(fun _ => rfl), .doubleInput, rfl, (fun _ => rfl)⟩,\n explainedWithoutVariationFails012, mechanismResponderUnderstands012, ?_, ?_⟩\n · apply grounds012Singleton\n refine ⟨⟨mechanismResponder012, (modelsSingleton _ _).2 rfl⟩, ?_⟩\n intro candidate hc\n have same := (modelsSingleton _ _).1 hc\n subst candidate\n exact mechanismResponderUnderstands012\n · intro h\n have discharged := (h.2 (understandingFacet012 explainedWithoutVariation012) (by simp)).2.2.2.1\n exact explainedWithoutVariationFails012\n (discharged.2 explainedWithoutVariation012 ((modelsSingleton _ _).2 rfl))\n\n/- The same exact application contract receives Grounds when its owner asserts\nit; external certificates change who supplies reasons, not the asserted object. -/\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.crossesBoundary", + "file": "CoreReader/Engineering/Domain.lean", + "line": 697, + "end": 702, + "kind": "def", + "axioms": "[]", + "exact_code": "def crossesBoundary (design : EngineeringDesign) (direction : Change) (edge : Boundary) : Bool :=\n design.boundaries.contains edge && design.components.contains edge.caller &&\n design.components.contains edge.callee && edge.caller != edge.callee &&\n (design.paths direction).any (fun step => step.component == edge.callee &&\n (step.tool == .editor || step.tool == .compiler))\n\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.boundaryObligationChecked", + "file": "CoreReader/Engineering/Domain.lean", + "line": 703, + "end": 709, + "kind": "def", + "axioms": "[]", + "exact_code": "def boundaryObligationChecked (design : EngineeringDesign) (direction : Change)\n (edge : Boundary) : Bool :=\n crossesBoundary design direction edge &&\n (design.paths direction).any (fun step => step.component == edge.caller &&\n step.tool == .contractRunner && step.requires == .publicContract) &&\n decide (PreservesFinite orderedUnique design.run)\n\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.actualCrossBoundaryObligation", + "file": "CoreReader/Engineering/Domain.lean", + "line": 720, + "end": 732, + "kind": "theorem", + "axioms": "[]", + "exact_code": "theorem actualCrossBoundaryObligation :\n crossesBoundary boundaryDesign .coordinated coordinatedBoundary = true ∧\n boundaryObligationChecked boundaryDesign .coordinated coordinatedBoundary = true ∧\n crossesBoundary omittedCallerCheck .coordinated coordinatedBoundary = true ∧\n boundaryObligationChecked omittedCallerCheck .coordinated coordinatedBoundary = false ∧\n crossesBoundary otherCalleeDesign .coordinated otherCalleeBoundary = false ∧\n boundaryObligationChecked { boundaryDesign with run := sortedUnique }\n .coordinated coordinatedBoundary = false := by decide\n\n/-- organon-map CoreReader.Engineering.structuralCases\nsoftware-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\nsoftware-engineering.structural-judgment#p2 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\n-/\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.priorityValueMeaning", + "file": "CoreReader/Engineering/Integration.lean", + "line": 204, + "end": 215, + "kind": "theorem", + "axioms": "[propext]", + "exact_code": "theorem priorityValueMeaning (candidate : Candidate) :\n (selectionPosition .evolvable).commitment candidate ↔\n EvolutionPriority sharedContext candidate := by\n constructor\n · intro selected\n change candidate = .evolvable at selected\n subst candidate\n exact currentDomainSatisfied.2.1\n · intro priority\n exact (priorityWhenApplicable sharedContext candidate priority\n currentPriorityConditions currentNoThreat.2).1\n\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.priorityGrounds", + "file": "CoreReader/Engineering/Integration.lean", + "line": 216, + "end": 228, + "kind": "theorem", + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "exact_code": "theorem priorityGrounds :\n Grounds012 (EvolutionPriority sharedContext) canonicalArticulation\n [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) := by\n have same : (selectionPosition .evolvable).commitment = EvolutionPriority sharedContext :=\n funext (fun candidate => propext (priorityValueMeaning candidate))\n rw [← same]\n exact selectionGrounded .evolvable (Or.inr rfl)\n\n/- Facts of adoption remain distinct from the actual normative contents. Each\nconstructor below denotes its full represented duty, with its original task,\nconditions, reasons and scope. Domain duties enter only for the domain adopter.\nConsistency is the constraint on the resulting whole theory below; it is not\nencoded as a self-referential proposition in that theory's own definition. -/\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.OwnNorm", + "file": "CoreReader/Engineering/Integration.lean", + "line": 229, + "end": 234, + "kind": "inductive", + "axioms": "[]", + "exact_code": "inductive OwnNorm\n | generation | reflection | empirical | inferential | principleValue (principle : CoreCommitment)\n | selectionValue | scope | capability | choice | ownGrounds (fact : OwnFact)\n | domain | priorityValue\n deriving DecidableEq, Repr\n\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.normApplies", + "file": "CoreReader/Engineering/Integration.lean", + "line": 235, + "end": 238, + "kind": "def", + "axioms": "[propext]", + "exact_code": "def normApplies (adopted : Candidate) : OwnNorm → Prop\n | .domain | .priorityValue => adopted = .evolvable\n | _ => True\n\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.ownNormClaim", + "file": "CoreReader/Engineering/Integration.lean", + "line": 239, + "end": 259, + "kind": "def", + "axioms": "[propext]", + "exact_code": "def ownNormClaim (adopted : Candidate) : OwnNorm → Claim Candidate\n | .generation => fun _ => generationSpecification engineeringPolicy\n | .reflection => fun candidate => reflexivitySpecification\n (selfModel candidate).rules (selfModel candidate).self (selfModel candidate).performed\n | .empirical => fun _ => empiricalSpecification [presentBudgetRecord] (fun _ => True)\n presentBudgetClaim (fun _ => True)\n | .inferential => fun _ => inferentialSpecification capacityAssumptions capacityClaim\n | .principleValue principle => fun _ => valueSpecification (governancePosition principle)\n | .selectionValue => fun candidate => valueSpecification (selectionPosition adopted) ∧\n (selectionPosition adopted).commitment candidate\n | .scope => fun _ => scopeSpecification budgetScopeAccount\n | .capability => fun candidate => capabilitySpecification\n (engineeringProcess candidate) (engineeringCapability candidate)\n | .choice => fun candidate => choiceSpecification\n chosenRequirements (chosenImplementation candidate) chosenReasons\n | .ownGrounds fact => fun _ => inferentialSpecification\n (ownFactPremises adopted) (ownFactClaim adopted fact)\n | .domain => fun candidate => DomainSatisfied sharedContext candidate\n | .priorityValue => fun _ => Grounds012 (EvolutionPriority sharedContext) canonicalArticulation\n [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable))\n\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.ownFactTheory", + "file": "CoreReader/Engineering/Integration.lean", + "line": 282, + "end": 284, + "kind": "def", + "axioms": "[propext]", + "exact_code": "def ownFactTheory (chosen : Candidate) : Theory Candidate :=\n fun claim => ∃ fact : OwnFact, claim = ownFactClaim chosen fact\n\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.ownNormTheory", + "file": "CoreReader/Engineering/Integration.lean", + "line": 285, + "end": 289, + "kind": "def", + "axioms": "[propext]", + "exact_code": "def ownNormTheory (chosen : Candidate) : Theory Candidate :=\n fun claim => ∃ norm : OwnNorm, normApplies chosen norm ∧ claim = ownNormClaim chosen norm\n\n/- The consequence relation now acts on all these facts and normative contents\ntogether, including the implications of their union. -/\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.ownTheory", + "file": "CoreReader/Engineering/Integration.lean", + "line": 290, + "end": 292, + "kind": "def", + "axioms": "[propext]", + "exact_code": "def ownTheory (chosen : Candidate) : Theory Candidate :=\n union (ownFactTheory chosen) (ownNormTheory chosen)\n\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.allNormativeContentHeld", + "file": "CoreReader/Engineering/Integration.lean", + "line": 293, + "end": 296, + "kind": "theorem", + "axioms": "[propext]", + "exact_code": "theorem allNormativeContentHeld (chosen : Candidate) (norm : OwnNorm)\n (applicable : normApplies chosen norm) : ownTheory chosen (ownNormClaim chosen norm) :=\n Or.inr ⟨norm, applicable, rfl⟩\n\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.currentAdmissible", + "file": "CoreReader/Engineering/Integration.lean", + "line": 313, + "end": 324, + "kind": "theorem", + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "exact_code": "theorem currentAdmissible (chosen : Candidate)\n (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) :\n Admissible (ownTheory chosen) (comparisonContext chosen) chosen := by\n refine ⟨?_, (modelsSingleton _ _).2 rfl, ?_⟩\n · intro claim held\n rcases held with factHeld | normHeld\n · obtain ⟨fact, rfl⟩ := factHeld\n exact actualOwnFact chosen ordinary fact\n · obtain ⟨norm, applicable, rfl⟩ := normHeld\n exact actualOwnNorm chosen ordinary norm applicable\n · rcases ordinary with rfl | rfl <;> change _ ≤ 3 <;> decide\n\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.currentConsistency", + "file": "CoreReader/Engineering/Integration.lean", + "line": 325, + "end": 330, + "kind": "theorem", + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "exact_code": "theorem currentConsistency (chosen : Candidate)\n (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) :\n consistencySpecification (engineeringSnapshot .evolvable 0)\n (engineeringSnapshot chosen 1) true := by\n exact ⟨consequenceConsistency _ _ ⟨chosen, currentAdmissible chosen ordinary⟩, fun _ => rfl⟩\n\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.wholeClaimGrounded", + "file": "CoreReader/Engineering/Integration.lean", + "line": 331, + "end": 343, + "kind": "theorem", + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "exact_code": "theorem wholeClaimGrounded (chosen : Candidate)\n (ordinary : chosen = .presentSimple ∨ chosen = .evolvable)\n (claim : Claim Candidate) (held : ownTheory chosen claim) :\n inferentialSpecification (ownFactPremises chosen) claim := by\n apply grounds012Singleton\n refine ⟨⟨chosen, (modelsSingleton _ _).2 rfl⟩, ?_⟩\n intro candidate same\n have identity := (modelsSingleton _ _).1 same\n subst candidate\n exact (currentAdmissible chosen ordinary).1 claim held\n\n/- Keeping the same adoption marker does not conceal contradictory normative\ncontents. Both demands act on the very same candidate, question and scope. -/\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.normativeContentVariation", + "file": "CoreReader/Engineering/Integration.lean", + "line": 351, + "end": 373, + "kind": "theorem", + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "exact_code": "theorem normativeContentVariation :\n coreAdopted .choice = true ∧\n ¬ Consistent incompatibleNormTheory incompatibleNormContext ∧\n normApplies .evolvable .domain ∧ ¬ normApplies .presentSimple .domain ∧\n ownTheory .evolvable (ownNormClaim .evolvable .domain) ∧\n ¬ ownTheory .presentSimple (ownNormClaim .presentSimple .domain) := by\n refine ⟨rfl, ?_, rfl, by unfold normApplies; decide, allNormativeContentHeld _ _ rfl, ?_⟩\n · apply conflictRequiresChange _ _ ()\n · intro candidate admissible\n change candidate = .presentSimple\n exact (modelsSingleton (fun c : Candidate => c = .presentSimple) candidate).1\n ((modelsUnion _ _ _).1 admissible.1).1\n · intro candidate admissible\n change candidate ≠ .presentSimple\n exact (modelsSingleton (fun c : Candidate => c ≠ .presentSimple) candidate).1\n ((modelsUnion _ _ _).1 admissible.1).2\n · intro held\n have domain := (currentAdmissible .presentSimple (Or.inl rfl)).1 _ held\n exact currentSimpleViolates domain.2.1\n\n/- Every field is an actual satisfaction or support condition. Value accounts\nand assessment completion do not replace the normative fields they explain.\nThe identity field limits this implementation to its disclosed common context. -/\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.ruleProbe", + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 26, + "end": 33, + "kind": "def", + "axioms": "[]", + "exact_code": "def ruleProbe (activity : CoreReader.Agency.Activity) (point : ReviewCase) :\n Reflection.Input ReviewCase ReviewObject where\n target := ⟨0, ruleObject activity, .revision⟩\n contract := ⟨fun _ => true, if point.2 = 10 then [point] else [], [point]⟩\n requested := [point]\n reasons := [\"retain the proposed scope and distinguish actual samples from an empty test set\"]\n basis := True\n\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.generationRuleTest", + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 34, + "end": 39, + "kind": "def", + "axioms": "[]", + "exact_code": "def generationRuleTest\n (method : Reflection.Input ReviewCase ReviewObject → Reflection.Outcome ReviewCase)\n (point : ReviewCase) : Bool :=\n let input := ruleProbe .generation point\n method input == .generated input.requested input.requested\n\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.assessmentRuleTest", + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 40, + "end": 47, + "kind": "def", + "axioms": "[]", + "exact_code": "def assessmentRuleTest\n (method : Reflection.Input ReviewCase ReviewObject → Reflection.Verdict)\n (point : ReviewCase) : Bool :=\n method (ruleProbe .assessment point) ==\n (if point.2 = 10 then .supportedWithinScope else .noSupportingSample)\n\n/- A candidate revision supplies the previously missing empty-sample check.\nIt is kept distinct from the current evaluator and is not silently adopted. -/\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.sampleAwareAssessment", + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 48, + "end": 52, + "kind": "def", + "axioms": "[]", + "exact_code": "def sampleAwareAssessment (input : Reflection.Input ReviewCase ReviewObject) : Reflection.Verdict :=\n if input.contract.tested.isEmpty then .noSupportingSample else Reflection.evaluate input\n\n/- The method under criticism is the activity's own static batch forecast. Its\ncontract is checked at its original size and at the credible runtime change. -/\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.objectTest", + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 53, + "end": 61, + "kind": "def", + "axioms": "[propext]", + "exact_code": "def objectTest (object : ReviewObject) (point : ReviewCase) : Bool :=\n match object with\n | .activity => decide (Meets currentContinuing.required (currentContinuing.profiles point.1))\n | .commitment principle => safeguardExperiment principle true point.1\n | .priority => decide (EvolutionPriority currentContinuing point.1)\n | .evolutionMethod => staticBatch 21 point.2 == liveBatch 21 point.2\n | .generationRule => generationRuleTest Reflection.generate point\n | .assessmentRule => assessmentRuleTest Reflection.evaluate point\n\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.reviewObjects", + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 62, + "end": 66, + "kind": "def", + "axioms": "[]", + "exact_code": "def reviewObjects (chosen : Candidate) : List ReviewObject :=\n [.activity] ++ coreCommitments.map ReviewObject.commitment ++\n (if chosen = .evolvable then [.priority] else []) ++\n [.evolutionMethod, .generationRule, .assessmentRule]\n\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.ownRuleIdentity", + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 188, + "end": 203, + "kind": "theorem", + "axioms": "[propext, Quot.sound.{u}]", + "exact_code": "theorem ownRuleIdentity (chosen : Candidate) (activity : CoreReader.Agency.Activity)\n (phase : CoreReader.Agency.Phase) :\n ruleObject activity ∈ (selfModel chosen).objects ∧\n ((selfModel chosen).rule activity).meaning = Reflection.interpret activity ∧\n ((selfModel chosen).input ⟨0, ruleObject activity, phase⟩).contract.test =\n objectTest (ruleObject activity) ∧\n (selfModel chosen).generationApplies (ruleObject activity) phase =\n generationApplies (ruleObject activity) phase ∧\n (selfModel chosen).assessmentApplies (ruleObject activity) phase =\n assessmentApplies (ruleObject activity) phase := by\n refine ⟨?_, rfl, rfl, rfl, rfl⟩\n cases activity <;> simp [ruleObject, selfModel, reviewObjects]\n\n/- Changing the actual generator changes its object's result despite keeping\nthe object name. The evaluator really approves an empty initial sample set;\nits own revision review reports that bounded defect instead of a self-proof. -/\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.ownRuleContentVariation", + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 204, + "end": 217, + "kind": "theorem", + "axioms": "[propext]", + "exact_code": "theorem ownRuleContentVariation (chosen : Candidate) :\n generationRuleTest Reflection.generate (chosen, 10) = true ∧\n generationRuleTest (fun _ => .generated [] []) (chosen, 10) = false ∧\n assessmentRuleTest Reflection.evaluate (chosen, 10) = true ∧\n assessmentRuleTest Reflection.evaluate (chosen, 5) = false ∧\n Reflection.evaluate ((selfModel chosen).input ⟨0, .assessmentRule, .revision⟩) = .counterexample ∧\n generationApplies .generationRule .formation ∧\n generationApplies .generationRule .revision ∧\n ¬ generationApplies .generationRule .application ∧\n (∀ phase, assessmentApplies .assessmentRule phase) := by\n simp [generationRuleTest, assessmentRuleTest, ruleProbe, Reflection.generate,\n Reflection.evaluate, Reflection.Model.input, selfModel, requestedCases,\n objectTest, generationApplies, assessmentApplies]\n\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + }, + { + "name": "CoreReader.Engineering.proposedRuleRevision", + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 218, + "end": 229, + "kind": "theorem", + "axioms": "[propext, Quot.sound.{u}]", + "exact_code": "theorem proposedRuleRevision (chosen : Candidate) :\n assessmentRuleTest Reflection.evaluate (chosen, 5) = false ∧\n assessmentRuleTest sampleAwareAssessment (chosen, 5) = true ∧\n assessmentRuleTest sampleAwareAssessment (chosen, 10) = true ∧\n ((selfModel chosen).rule .generation).applicable ⟨0, .generationRule, .revision⟩ ∧\n ¬ (({ selfModel chosen with generationApplies := fun _ _ => False }).rule .generation).applicable\n ⟨0, .generationRule, .revision⟩ := by\n simp [assessmentRuleTest, sampleAwareAssessment, ruleProbe, Reflection.evaluate,\n Reflection.Model.rule, Reflection.Model.self, selfModel, reviewObjects,\n generationApplies]\n\nend CoreReader.Engineering\n", + "full_type_record": null, + "readable_full_type_audit": "r3-actual-audit.log" + } + ], + "blind_concern_dispositions": [ + { + "id": "C01", + "original_blind_concern": "Fixed finite costs, profiles, paths, credibility classifications and histories are stipulated data, not independent measurements.", + "disposition": "retained_application_boundary", + "source_comparison": "Source §§4.1–4.5 and T40 explicitly allow context-specific application evidence; hardcoded finite data do not by themselves violate source. Actual lifecycle, knowledge/history relevance, costs and forecast truth remain unverified, including T26.", + "r3_status": "retained disclosed boundary or previously resolved within concrete model", + "r3_update": "Prior reason retained; no source obligation added." + }, + { + "id": "C02", + "original_blind_concern": "EvolutionPriority is assumed by priorityWhenApplicable. The proof eliminates its departure branch and projects the complexity comparison from applicability.", + "disposition": "resolved_as_explicit_normative_premise", + "source_comparison": "T25 explicitly requires the adopted domain norm as premise. The projection is faithful to that conditional, not independent justification of adoption.", + "r3_status": "retained disclosed boundary or previously resolved within concrete model", + "r3_update": "Prior reason retained; no source obligation added." + }, + { + "id": "C03", + "original_blind_concern": "Standalone DomainSatisfied does not require Meets or PriorityConditions; a context with an unsafe evolvable profile can still satisfy it.", + "disposition": "not_a_source_conflict_for_false_antecedent", + "source_comparison": "Source gives priority when necessary requirements hold; it does not say a record about priority/structure/history proves universal requirement satisfaction. The unsafe DomainSatisfied probe is a boundary on that name, while T38 separately supplies PriorityConditions and real modeled profiles.", + "r3_status": "retained disclosed boundary or previously resolved within concrete model", + "r3_update": "Prior reason retained; no source obligation added." + }, + { + "id": "C04", + "original_blind_concern": "engineeringCapability requires equality to the same capabilityOutput function used to define engineeringProcess; its ground theorem holds even for maximal and imposes no positive capability threshold.", + "disposition": "retained_narrow_claim_not_failure_alone", + "source_comparison": "Core 0.1.2 permits application-specific capability definitions. Equality to the declared total output function is a genuine narrow claim proved for the same process; it must not be described as independent positive maintainability certification. Path contrast supplies the nontrivial maintenance facts for T38/T39.", + "r3_status": "retained disclosed boundary or previously resolved within concrete model", + "r3_update": "Engineering output-function capability remains narrow; the new T16 variation-answer application is a separate stronger declared capability, not a retroactive stronger reading of engineeringCapability." + }, + { + "id": "C05", + "original_blind_concern": "Simple and evolvable selection procedures use different objectives and starting assumptions fixed to their own adopted candidates.", + "disposition": "resolved_as_permitted_alternative_value", + "source_comparison": "Source roles and §4 state that engineering preference is additional. The simple value position may pursue simplicity and the evolvable one revision work, so long as reasons/constraints are disclosed. Their different objectives are essential to the bounded non-entailment witness, not a source inconsistency.", + "r3_status": "retained disclosed boundary or previously resolved within concrete model", + "r3_update": "Prior reason retained; no source obligation added." + }, + { + "id": "C06", + "original_blind_concern": "Grounds012 quantifies over the supplied nonempty facet list for one supplied task; it has no actualApplicable coverage predicate.", + "disposition": "retained_scope_boundary_not_core013_requirement", + "source_comparison": "Core 0.1.2 source and T09 do not require the later all-applicable-facet interface. The one-task formulation cannot be called an exhaustive taxonomy, but it may represent one task with multiple methods. No Core 0.1.3 obligation is imposed.", + "r3_status": "retained disclosed boundary or previously resolved within concrete model", + "r3_update": "Prior reason retained; no source obligation added." + }, + { + "id": "C07", + "original_blind_concern": "Raw Supports permits inconsistent records to support any proposition; inference over unsatisfiable theories is likewise vacuous.", + "disposition": "mitigated_in_discharged_facets", + "source_comparison": "FacetDischarged requires witnesses. The actual empirical/inferential and composition examples use nonempty compatible/satisfiable domains, so raw-support vacuity does not invalidate them.", + "r3_status": "retained disclosed boundary or previously resolved within concrete model", + "r3_update": "Prior reason retained; no source obligation added." + }, + { + "id": "C08", + "original_blind_concern": "ValueProcedure is conditional on all reasons, supplied objectives/constraints and scope; it does not establish universal adoption or semantic adequacy of responses.", + "disposition": "retained_sufficient_procedure_boundary", + "source_comparison": "Source asks articulated reasons, consequences, limits and openness, not proof of universal value correctness. ValueProcedure is a sufficient application procedure; response nonemptiness and conditional consequence must not be elevated into a universal definition of adequate criticism or legitimate value.", + "r3_status": "retained disclosed boundary or previously resolved within concrete model", + "r3_update": "Prior reason retained; no source obligation added." + }, + { + "id": "C09", + "original_blind_concern": "The generic reflexivity relation may be vacuous for no rules/self/applicability and records/meaning are supplied relations. recordedReflexivity assumes follows.", + "disposition": "mitigated_by_concrete_self_records", + "source_comparison": "Empty generic registries/applicability are permitted formal boundary cases; positive examples have actual own targets, membership, nonempty reasons and checked basis/meaning. Missing same-priority support linkage in T37 remains a distinct issue.", + "r3_status": "retained disclosed boundary or previously resolved within concrete model", + "r3_update": "New generationRule and assessmentRule objects refer to actual generate/evaluate and keep actual applicability. They are not globally exempted; revised applicability is only a separate tested candidate." + }, + { + "id": "C10", + "original_blind_concern": "Reflection.evaluate ignores claimed scope, basis, reasons and target; empty tested/requested lists return supportedWithinScope.", + "disposition": "mitigated_by_interpret_and_concrete_inputs", + "source_comparison": "Concrete self records have nonempty tested/requested inputs, independently checked basis and nonempty reasons. Raw evaluate can be vacuous and ignores claimed scope, so its return value alone must not be called full assessment fulfillment.", + "r3_status": "retained disclosed boundary or previously resolved within concrete model", + "r3_update": "Current evaluate still returns supported for empty tested lists; the new actual assessment-rule self-test deliberately records that local-contract failure. No hidden repair or universal sample requirement." + }, + { + "id": "C11", + "original_blind_concern": "The simple selfModel omits the priority review object; reflection of that model is not evidence that simple satisfies priority.", + "disposition": "resolved_for_countermodel_scope", + "source_comparison": "T39 declines the additional engineering priority; it need not review that unadopted priority as an adopted own principle. T38/evolvable does include the priority object. The omission does not show a covert failure of adopted Core duties.", + "r3_status": "retained disclosed boundary or previously resolved within concrete model", + "r3_update": "Prior reason retained; no source obligation added." + }, + { + "id": "C12", + "original_blind_concern": "PreservesFinite and affectedParties inspect only fixed input/dependency lists. contractPreservation receives the complete universal equality as its premise.", + "disposition": "retained_finite_scope_and_identity_proof", + "source_comparison": "T33/T34 explicitly allow identified observation scope and finite examples. Universal contractPreservation is the supplied equality premise; parties/procedures are finite model obligations, not actual notices. The retained [99] counterexample makes scope limits explicit.", + "r3_status": "retained disclosed boundary or previously resolved within concrete model", + "r3_update": "Prior reason retained; no source obligation added." + }, + { + "id": "C13", + "original_blind_concern": "RevisionAccountAgainst checks exact equality to caller-supplied history and criticism-list coverage, not historical authenticity or substantive criticism.", + "disposition": "retained_history_provenance_boundary", + "source_comparison": "The invariant comparison against fixed history meets the modeled no-retroactive-success requirement. Authentic external history and substantive criticism are not proved. This is legitimate bounded evidence, not a universal history-authentication theorem.", + "r3_status": "retained disclosed boundary or previously resolved within concrete model", + "r3_update": "Prior reason retained; no source obligation added." + }, + { + "id": "C14", + "original_blind_concern": "ContinuingCapability can pass with no participants; RetentionJustified can pass with no alternatives; Consistent can pass with an empty question type.", + "disposition": "mitigated_for_registered_witnesses", + "source_comparison": "Current applicability includes nonempty participants, question/fact domains are inhabited, and concrete alternatives are listed. Empty generic cases remain documented and must not be mistaken for the actual positive witness.", + "r3_status": "retained disclosed boundary or previously resolved within concrete model", + "r3_update": "Prior reason retained; no source obligation added." + }, + { + "id": "C15", + "original_blind_concern": "inheritedMutualApplication extracts fields of Inherited; it does not establish mutual implication among fewer independent principles.", + "disposition": "partial_target_signature_confirmed", + "source_comparison": "T20 is intentionally conditional, so projection itself is legitimate. Nevertheless its required target statement includes consistency, while the actual conclusion omits inherited.consistency. Full exact target completion needs that distinction resolved; no claim of mutual logical derivation is warranted.", + "r3_status": "resolved-bounded", + "r3_update": "T20 now includes the consistency result plus full content membership and whole-claim support, verified by direct conclusion extraction probe. Projection remains explicitly disclosed." + }, + { + "id": "C16", + "original_blind_concern": "Some prior Integration and Adopted value experiments use Classical.propDecidable for arbitrary propositions.", + "disposition": "resolved_as_allowed_nonexecutable_assessment", + "source_comparison": "Source necessary terms and §2.2 expressly do not require every assessment to be executable. Classical proposition decisions are valid logical constructions provided the delivery does not advertise them as executable empirical tools.", + "r3_status": "retained disclosed boundary or previously resolved within concrete model", + "r3_update": "Prior reason retained; no source obligation added." + }, + { + "id": "C17", + "original_blind_concern": "Articulated only checks nonempty lists; ScopeAccount.explains and generic ReflexiveRule.meaning remain supplied predicates.", + "disposition": "retained_interface_and_linkage_boundary", + "source_comparison": "Concrete expansions supply more than abstract labels, but nonempty strings do not prove explanatory relevance for arbitrary inputs. T31 has a specific missing boundary/obligation connection; T37 grounds quantification covers five Core labels, not directly the engineering priority rule.", + "r3_status": "resolved-specific-links-generic-boundary-retained", + "r3_update": "T31 has actual boundary-linked checks; T37 has explicit same-priority value/grounds equivalence. Generic explains/meaning/string interfaces still require an interpretation, so the abstract concern is retained as a limit." + } + ], + "remaining_limits": [ + "Normative adoption and value superiority are not mathematically compelled.", + "All support/currentness judgments are bound to the frozen R3 code and selected Core 0.1.2 baseline.", + "Operational mechanism-variation understanding is not unrestricted cognition or introspection.", + "Empty-tested-list failure belongs to a declared sample-aware local evaluator contract, not all philosophical assessment.", + "Finite boundary/contract/work/history cases do not establish production adequacy or universal costs.", + "priorityValueMeaning is limited to the fixed applicable no-departure sharedContext.", + "wholeClaimGrounded uses fixed-model identity for fulfillment facts; original empirical/inferential/value tasks remain separately retained.", + "No final reader edition, bilingual synchronization, historical replay or later changed code is approved by this comparison." + ] +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/fidelity.json b/SoftwareEngineering/lean/philosophy/reviews/fidelity.json new file mode 100644 index 0000000..3b7190e --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/fidelity.json @@ -0,0 +1,1044 @@ +{ + "schema_version": 1, + "run_sha256": "18a076e48d5b40c97031ddf35a293ef1399c38cc444cf028be21f6d956924b62", + "source_sha256": "adc8cce5ac55a5e3795f8806748603eb69d5695fa37bbe263bee20ac6c14a1a6", + "code_sha256": { + "leanified/CoreReader/Adopted.lean": "8de4d364bb3c64e29ab92e81d86cbe4c9e5af49ada3dad262d1378421fb588c2", + "leanified/CoreReader/Agency.lean": "2722c34645f4256f20ce31205738f2f5712ab5dd5cc6fcf9f1180d0be5aa0303", + "leanified/CoreReader/Choice.lean": "b28728df12ed7e73edb5569604cd2541c0ebd815ae3aaa0812e6557dece1d1ba", + "leanified/CoreReader/Engineering/Domain.lean": "ce5653a2950cc7443cefbfe8b9726bd4859228e831ddb7d42601e501ccbfd855", + "leanified/CoreReader/Engineering/Integration.lean": "a2b88062148b3f7ebea7da02d88cb29cb04d8f1b2e9e6b97bb2420ac2c006328", + "leanified/CoreReader/Engineering/Reflection.lean": "c290d8472884d00bedbf945f0fc1866524e758740f40d42088c4ff9678a93fa2", + "leanified/CoreReader/Engineering/SelfApplication.lean": "d69c0d369bd4fd8db4c21ce3b65abb5e9efd07ed5ab9a68d56b4db39bb9d2a21", + "leanified/CoreReader/Engineering/Values.lean": "ccd45bf23d2f47c41d1b2f9955d753e290687d951a0c55af41ab9a63b9a8d9cb", + "leanified/CoreReader/Evidence.lean": "d55f33e44902cef146841cbffb65710bd7c8a3bda79d01d084edc36f019fdc96", + "leanified/CoreReader/Integration.lean": "97e2939c0b6714b78a3ed78358e174619a5028ad5b0b5025c0d4422b4294921b", + "leanified/CoreReader/Logic.lean": "0ec342691766ebd83d251dcd0da3b0ae9840aed677a714bc1b01c45d89392bc0", + "leanified/CoreReader/Reflexivity.lean": "48e2c74e7cbae571db1b990b9f32dd0d701f6881a8b0111d907f8861287d76fa", + "leanified/CoreReader.lean": "c5574fae235419a7d6449b3ebb5d2da29d1e92a3b572c1b759438e3c470caaa9" + }, + "proof_targets_sha256": "19184f5f301fb5a2f156d09a1d5b4fee5f9e8e9bbc96fdc5fbbc9ccb426287bb", + "initial_records": [ + { + "role": "source_initial", + "path": "reviews/source-initial.md", + "sha256": "edd1c4791b80068fdacc0fd168d918226abf9764de3d02554432dc160f3e1113" + }, + { + "role": "source_initial_catalog", + "path": "reviews/source-initial-targets.json", + "sha256": "a033f7aa1c4b5b570884a372578ba544ebe5303c453c91ce0f46bd46d8921a36" + }, + { + "role": "freeze_review", + "path": "reviews/target-freeze-review.md", + "sha256": "cd994ee5ceb0e789c5c217914d4c0bc88e1dfeeae6d81bfef4f2ff3bc383c85f" + }, + { + "role": "code_blind", + "path": "reviews/code-blind-initial.md", + "sha256": "cf9280ddd3365440e848b14043a6208b9fea5114f9ff13cea4e236e3358317df" + }, + { + "role": "code_blind_identity", + "path": "reviews/code-blind-identity.json", + "sha256": "78c842326b65bc894eccf10e15ae9fef75f8850abbdb7025d766eefa4d8f7a53" + }, + { + "role": "code_blind_delta", + "path": "reviews/code-blind-delta.md", + "sha256": "a0a16628362882d5574bf41123d6fed41ce735083d55dccfb06650555cb3b776" + }, + { + "role": "code_blind_delta_identity", + "path": "reviews/code-blind-delta-identity.json", + "sha256": "3cd8802c7670caf78d74027c73e76420b0df5eabe346b4fe55e16e19b71db88e" + }, + { + "role": "blind_source_initial", + "path": "reviews/blind-source-initial.md", + "sha256": "41231e41278a6389f72db28cf2b75322cfdecaa0c8a831051aa7b10b7b30b2e9" + }, + { + "role": "blind_source_initial_targets", + "path": "reviews/blind-source-initial.json", + "sha256": "458c5302b44cfcaa799fd1d9cebf34df392aebdf7fa57c74e2cd5b8c2fa96244" + }, + { + "role": "code_comparison_final", + "path": "reviews/code-comparison-final.md", + "sha256": "ba3e905877e33ef96e4251cb59b8a1f52cca397eecaef92570ebf28261a8fd0c" + }, + { + "role": "code_target_final", + "path": "reviews/code-targets-final.json", + "sha256": "e01cd00cbcfa4ba8c6592917ea7321eb3826bc0b365a2b1b64170a1a24a93825" + }, + { + "role": "code_review_identity", + "path": "reviews/code-review-identity.json", + "sha256": "abb056f71ed48ec009e9bd16bd037dd2f0dab84cf3746008e4fd536aecfe78ea" + }, + { + "role": "independent_actual_check", + "path": "reviews/r3-actual-audit.log", + "sha256": "6aaad0f6c1f73f44631df61e4631af9d82596329fb71cac4a6f42f76bfb60b5b" + }, + { + "role": "independent_actual_check", + "path": "reviews/r3-axiom-summary.json", + "sha256": "f23b5f29c342bb30dd274c9d7fad6932565eecd69c91f27f846d017fe5a253c7" + }, + { + "role": "independent_actual_check", + "path": "reviews/r3-build.log", + "sha256": "f6e727662ac83e00e087be3246525187946b87441afdb6cd9a3f3af9d3e5eedd" + }, + { + "role": "independent_actual_check", + "path": "reviews/r3-declarations.json", + "sha256": "b92ca5728f275caeec340cdc63aa52dc44a303c30a887cfcfa3493542e7e6b07" + }, + { + "role": "independent_actual_check", + "path": "reviews/r3-audit-input.txt", + "sha256": "c31b98c29db2e12b2d7c2d7f968c0fa4db76a68061ea9bf14ce81727f376ea19" + }, + { + "role": "independent_actual_check", + "path": "reviews/r3-probe-input.txt", + "sha256": "3c72af41c80077164e35a7ad2dcc8c927a0981c12f4c698702d658b543f8d8d5" + }, + { + "role": "independent_actual_check", + "path": "reviews/r3-probes.log", + "sha256": "0c899aa78e9ae2473f6203f0f5e680657aeeac0584472a1f1c2d1798b4e75b44" + }, + { + "role": "independent_actual_check", + "path": "reviews/r3-stability-probe-input.txt", + "sha256": "677f560a47f9262bf08cf337f423516c163970906668bd2d541e9383c56531dd" + }, + { + "role": "independent_actual_check", + "path": "reviews/r3-stability-probe.log", + "sha256": "9fa3b6ead7afc298499f30c5b70014c78b6686a8269611537606fa5a7c02b6a2" + }, + { + "role": "source_comparison", + "path": "reviews/source-code-review-full-initial.md", + "sha256": "d1c38be6f8826ff29ff01ec12bb2d45f3f32e4e4b45830c7fd3250a40ab13767" + }, + { + "role": "source_comparison", + "path": "reviews/source-code-review-full-initial.json", + "sha256": "2fe6ec4c19ecf5d73b347c2a11c2c916c9ee69ca532b19746b160178222975c1" + }, + { + "role": "source_comparison", + "path": "reviews/source-code-review-adopted-f01-f06-final.md", + "sha256": "dc1952e457239f9c5a72d99b50ff043f3c243ff8914efea20e0bc49b3af441b4" + }, + { + "role": "source_comparison", + "path": "reviews/source-code-review-adopted-f01-f06-final.json", + "sha256": "a43e9e3dd6b6d98497f3803f3c4e0d27666fa4aedb48e293ea7c6375561422eb" + }, + { + "role": "source_comparison", + "path": "reviews/source-code-review-domain-r2.md", + "sha256": "53288a6b2e5bdc55a18a004c0a3c38c0a31269d97309e1f4a0b864f9cfeba28f" + }, + { + "role": "source_comparison", + "path": "reviews/source-code-review-domain-r2.json", + "sha256": "5d8eed0f715c6aeed7f32707478d89e576c8cc8758fb5523fb6b8b8fb9a53b2d" + }, + { + "role": "source_comparison", + "path": "reviews/source-code-review-domain-same-work-final.md", + "sha256": "c64b54d89ffed6592d5b745772835f9ff1ace23305a51dfa688289bf25c9cde2" + }, + { + "role": "source_comparison", + "path": "reviews/source-code-review-domain-same-work-final.json", + "sha256": "99c334f55fce1629cf3a2776832fb389305b81062dd129ce4e661158560d8d8b" + }, + { + "role": "source_comparison", + "path": "reviews/source-code-review-f07-f08.md", + "sha256": "898af33213a832832f4b6d84a8f94fd99bede9a0abae055b9e2a1af3b8ee5b1f" + }, + { + "role": "source_comparison", + "path": "reviews/source-code-review-f07-f08.json", + "sha256": "58928fb167139305c8284d64f66ab52fd2bd22e9eb751beedbf4dd6629282fa5" + }, + { + "role": "source_comparison", + "path": "reviews/source-code-review-r3.md", + "sha256": "c3d06769eba25fec696936c87a560228ce04d675757adc8887a36357ff9939aa" + }, + { + "role": "source_comparison", + "path": "reviews/source-code-review-r3.json", + "sha256": "05bcb385022d349c92589785d98912746330350335602d47968c240f3b79d376" + }, + { + "role": "reader_review", + "path": "reviews/reader-independent-source-review-r1.md", + "sha256": "2933d9049854ac3905a75493cecde9e72689a6883f337ca5f1da3f4da1ac8096" + }, + { + "role": "reader_review", + "path": "reviews/reader-independent-source-review-r1.json", + "sha256": "6f167b52d7081adfc0bbc7dd631c7c97556efa875b972828d811b68b810f72de" + }, + { + "role": "reader_review", + "path": "reviews/reader-independent-source-review-r1-anchors.md", + "sha256": "335b251e0f4ed2b7115230558169964ffd4f930569fcff7fa7f4c20310fa5054" + }, + { + "role": "reader_review", + "path": "reviews/reader-independent-source-review-r1-anchors.json", + "sha256": "e8c827f7763b611d8cedc5350efd63cec727e76385fad18fc3286e6c8a8efb1a" + }, + { + "role": "reader_review", + "path": "reviews/reader-independent-source-review-r2-components.md", + "sha256": "998c8a9aca43571ec4e094ef49d3b6e19c026f82f62aae2e727743812e1e0588" + }, + { + "role": "reader_review", + "path": "reviews/reader-independent-source-review-r2-components.json", + "sha256": "8454724e90e354eca9755f7113cba07d8d458c2c61fb86030ebb9377357bc3b8" + }, + { + "role": "reader_review", + "path": "reviews/reader-independent-source-final.md", + "sha256": "93979bd24e25dede4dbfecd9a264d9e63d2e01855e7a4e27b8c03add7c48894a" + }, + { + "role": "reader_review", + "path": "reviews/reader-independent-source-final.json", + "sha256": "51ff57e3d2988cdd6e44b6e3d6709be061e80d777b79969f6a14aafcc6b81f54" + }, + { + "role": "reader_review", + "path": "reviews/reader-independent-domain-r1.md", + "sha256": "2c411fb38eef7f4637c9c243930b4f30029b059893056518607e767cd851dae8" + }, + { + "role": "reader_review", + "path": "reviews/reader-independent-domain-r1.json", + "sha256": "a472140f51246e278c9d8e3c69541c5fe78cb54b2f61f2eba3d64d8583645d8b" + }, + { + "role": "reader_review", + "path": "reviews/reader-independent-domain-r2.md", + "sha256": "228a039b18206d6243e29afe3cd5e5480d930cb09d186c217284d618e61819bd" + }, + { + "role": "reader_review", + "path": "reviews/reader-independent-domain-r2.json", + "sha256": "fc6364e3be49696cc517126a67f41e1452b3e0b54dfb70bc40594dc834d3cae8" + }, + { + "role": "reader_review", + "path": "reviews/reader-independent-domain-final.md", + "sha256": "feb93118a9fb8b976e53d35607d3afd592444057b2eff835c2e61f158c571ce3" + }, + { + "role": "reader_review", + "path": "reviews/reader-independent-domain-final.json", + "sha256": "4d8fae4140622e27492b378f78d47766fc879fd43940942883a5daf0233e59f1" + }, + { + "role": "reader_actual_check", + "path": "reviews/reader-independent-domain-r1-granularity-clarification.json", + "sha256": "9d6c9b64c164a072203911b24ced32e9e32bf47a2d82a5706771934c5faa6f6a" + }, + { + "role": "reader_actual_check", + "path": "reviews/reader-helper-reuse-probe-r1.json", + "sha256": "6221cea32fe0e60efb14ca00cdafac7d2535f373efc94d29dd953c8c521c2f93" + }, + { + "role": "reader_actual_check", + "path": "reviews/reader-helper-caption-reuse-probe-r1.json", + "sha256": "34fa13446db8cd3264bf506baa49ee544e37713cfa57598d9db05ecfe6b774fa" + }, + { + "role": "reader_actual_check", + "path": "reviews/reader-independent-domain-r1-probes.txt", + "sha256": "c5bc1cb06352637044d694d9dcc49737862246576fba49ac0ecc481ea06dac21" + }, + { + "role": "reader_actual_check", + "path": "reviews/reader-independent-domain-r1-probes.log", + "sha256": "7b1f6762c8a3a910b04b32067ba975daa3ceb4a3ea45cf29ef93e6e627194fd0" + }, + { + "role": "reader_actual_check", + "path": "reviews/reader-independent-domain-r1-probes-attempt1.txt", + "sha256": "aca48116bb1731f3e48abf43f0e292f81c39a45ddcba5cb78245d4a199d76ddf" + }, + { + "role": "reader_actual_check", + "path": "reviews/reader-independent-domain-r1-probes-attempt1.log", + "sha256": "74ad440eb9dce2a397b754e17193af987798b6b1fce12cd2390a581de8fc394c" + }, + { + "role": "reader_review", + "path": "reviews/reader-initial-overall.md", + "sha256": "016f35a6bc9670557bc70394675e1e413853969f7e597bf46d544fed9120a431" + }, + { + "role": "reader_review", + "path": "reviews/reader-initial-overall.json", + "sha256": "9b3fb49a28d4e658ac6b5b9b8c89aadb82d246d04a53ba6b9e7087d6e1c8df4b" + }, + { + "role": "reader_review", + "path": "reviews/reader-comparison.md", + "sha256": "c4e60c243ff0cfcde7debf4b2a38baaacadedc8e3a522fe89575ec350dc7c236" + }, + { + "role": "reader_review", + "path": "reviews/reader-comparison.json", + "sha256": "f0dc87c1cc3b85bfce1475219b2b63a4508d8986c47fd39125dcf3b57d550368" + }, + { + "role": "reader_review", + "path": "reviews/reader-final-overall.md", + "sha256": "637b4b12e88b6226e944963d7ca34bbe0ab017e9cb1b113a2744e66164f0c2d3" + }, + { + "role": "reader_review", + "path": "reviews/reader-final-overall.json", + "sha256": "da2c4cfe5d3c5e5a585d2c8cd96a8329927b960aff853e262fb307f0cb855d1c" + }, + { + "role": "reader_review", + "path": "reviews/reader-final-probes.json", + "sha256": "9fe82b010e045ac290ae43d471ac61ae8bb422777d3b78387b3592df93c79b84" + }, + { + "role": "source_migration_comparison", + "path": "reviews/source-migration-2026-09-15.md", + "sha256": "39e7a846f1d52577417bf7a5928b230793ac6b6b8e82ec3d1967f86dc5e9a0cf" + } + ], + "entries": [ + { + "id": "organon.charter.overview.p2", + "fidelity": "partial", + "reason": "Bounded source correspondence to T02, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.overview.p3", + "fidelity": "partial", + "reason": "Bounded source correspondence to T02, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.self-transcendence.p1", + "fidelity": "partial", + "reason": "Bounded source correspondence to T02, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.self-transcendence.orientation.p1", + "fidelity": "partial", + "reason": "Bounded source correspondence to T02, T03, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.self-transcendence.non-finality.p1", + "fidelity": "partial", + "reason": "Bounded source correspondence to T02, T03, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.self-transcendence.limits.p1", + "fidelity": "partial", + "reason": "Bounded source correspondence to T03, T38. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.self-transcendence.limits.p2", + "fidelity": "partial", + "reason": "Bounded source correspondence to T02, T03, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.consistency.p1", + "fidelity": "partial", + "reason": "Bounded source correspondence to T04, T05, T38. A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.consistency.meaning.p1", + "fidelity": "partial", + "reason": "Bounded source correspondence to T04, T05, T38. A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.consistency.meaning.p2", + "fidelity": "partial", + "reason": "Bounded source correspondence to T04, T05, T06, T38. A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. Consistency is not sufficient empirical or value support; the counterexamples concern the disclosed mathematical representation. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.consistency.limits.p1", + "fidelity": "partial", + "reason": "Bounded source correspondence to T04, T05, T06, T38. A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. Consistency is not sufficient empirical or value support; the counterexamples concern the disclosed mathematical representation. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.reflexivity.p1", + "fidelity": "partial", + "reason": "Bounded source correspondence to T07, T38. Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.reflexivity.meaning.p1", + "fidelity": "partial", + "reason": "Bounded source correspondence to T07, T38. Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.charter.reflexivity.limits.p1", + "fidelity": "partial", + "reason": "Bounded source correspondence to T07, T08, T38. Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.grounds.p1", + "fidelity": "partial", + "reason": "Bounded source correspondence to T08, T09, T38. This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.grounds.assessment.p1", + "fidelity": "partial", + "reason": "Bounded source correspondence to T09, T13, T38. This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. These distinctions do not require values, empirical evidence and inference to be reduced to one score. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.grounds.assessment.p2", + "fidelity": "partial", + "reason": "Bounded source correspondence to T09, T10, T11, T12, T13, T38. This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. Repeatability or measurability alone does not establish relevance, correctness or value; varying unobserved outcomes need not contradict limited support. Failure of support is not failure to assess correctly; consistency with assumptions is weaker than entailment. The application supplies a sufficient value assessment, not a universal requirement to prove every starting assumption or a proof that one value is universally best. These distinctions do not require values, empirical evidence and inference to be reduced to one score. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.grounds.assessment.p3", + "fidelity": "partial", + "reason": "Bounded source correspondence to T09, T12, T13, T38. This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. The application supplies a sufficient value assessment, not a universal requirement to prove every starting assumption or a proof that one value is universally best. These distinctions do not require values, empirical evidence and inference to be reduced to one score. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.grounds.scope.p1", + "fidelity": "partial", + "reason": "Bounded source correspondence to T14, T15, T38. A nonempty role string alone is not sufficient interpretation, and an unused method does not become compulsory. Omitting an input from comparison is not evidence that no relevant difference exists there. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.grounds.scope.p2", + "fidelity": "partial", + "reason": "Bounded source correspondence to T14, T15, T38. A nonempty role string alone is not sufficient interpretation, and an unused method does not become compulsory. Omitting an input from comparison is not evidence that no relevant difference exists there. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.grounds.scope.p3", + "fidelity": "partial", + "reason": "Bounded source correspondence to T14, T15, T38. A nonempty role string alone is not sufficient interpretation, and an unused method does not become compulsory. Omitting an input from comparison is not evidence that no relevant difference exists there. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.grounds.capabilities.p1", + "fidelity": "partial", + "reason": "Bounded source correspondence to T16, T17, T38. This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. An external assessor can ground the selected output claim without establishing how the assessed system understands its generation process. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.grounds.capabilities.p2", + "fidelity": "partial", + "reason": "Bounded source correspondence to T16, T17, T38. This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. An external assessor can ground the selected output claim without establishing how the assessed system understands its generation process. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.grounds.implementations.p1", + "fidelity": "partial", + "reason": "Bounded source correspondence to T18, T19, T38. These are application reasons, not a universal cost function or a rule that conventional implementations must lose. No result asserts all implementations equivalent, multiple feasible implementations guaranteed, or the choice commitment derivable from chapter placement. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.grounds.implementations.p2", + "fidelity": "partial", + "reason": "Bounded source correspondence to T18, T19, T38. These are application reasons, not a universal cost function or a rule that conventional implementations must lose. No result asserts all implementations equivalent, multiple feasible implementations guaranteed, or the choice commitment derivable from chapter placement. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.grounds.implementations.limits.p1", + "fidelity": "partial", + "reason": "Bounded source correspondence to T15, T18, T19, T38. Omitting an input from comparison is not evidence that no relevant difference exists there. These are application reasons, not a universal cost function or a rule that conventional implementations must lose. No result asserts all implementations equivalent, multiple feasible implementations guaranteed, or the choice commitment derivable from chapter placement. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "organon.relationships.roles.p1", + "fidelity": "partial", + "reason": "Bounded source correspondence to T08, T20, T38, T39. This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. Projection does not derive all duties from one principle. Adoption markers are separate facts; they do not substitute for normative content. The sample-aware criticism is an application criterion, not a universal requirement for observations. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance." + }, + { + "id": "organon.relationships.roles.p2", + "fidelity": "partial", + "reason": "Bounded source correspondence to T03, T06, T11, T16, T20, T38, T39. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. Consistency is not sufficient empirical or value support; the counterexamples concern the disclosed mathematical representation. Failure of support is not failure to assess correctly; consistency with assumptions is weaker than entailment. This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. Projection does not derive all duties from one principle. Adoption markers are separate facts; they do not substitute for normative content. The sample-aware criticism is an application criterion, not a universal requirement for observations. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance." + }, + { + "id": "organon.relationships.roles.p3", + "fidelity": "partial", + "reason": "Bounded source correspondence to T07, T08, T16, T18, T20, T37, T38, T39. Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. These are application reasons, not a universal cost function or a rule that conventional implementations must lose. Projection does not derive all duties from one principle. Adoption markers are separate facts; they do not substitute for normative content. The sample-aware criticism is an application criterion, not a universal requirement for observations. Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance." + }, + { + "id": "organon.relationships.terms.p1", + "fidelity": "partial", + "reason": "Bounded source correspondence to T02. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve." + }, + { + "id": "extensions.p1", + "fidelity": "partial", + "reason": "Bounded source correspondence to T37, T38, T39. Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance." + }, + { + "id": "software-engineering.purpose.p1", + "fidelity": "partial", + "reason": "Bounded source correspondence to T22, T23, T38. These numerical schedules are finite model data, not project time estimates. Scope alone does not prove every participant can perform every change. The result concerns the represented paths; lack of one documented path is not a universal impossibility theorem about all maintenance. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "software-engineering.purpose.p2", + "fidelity": "partial", + "reason": "Bounded source correspondence to T22, T23, T38. These numerical schedules are finite model data, not project time estimates. Scope alone does not prove every participant can perform every change. The result concerns the represented paths; lack of one documented path is not a universal impossibility theorem about all maintenance. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "software-engineering.purpose.p3", + "fidelity": "partial", + "reason": "Bounded source correspondence to T22, T23, T24, T38. These numerical schedules are finite model data, not project time estimates. Scope alone does not prove every participant can perform every change. The result concerns the represented paths; lack of one documented path is not a universal impossibility theorem about all maintenance. This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "software-engineering.evolution-priority.p1", + "fidelity": "partial", + "reason": "Bounded source correspondence to T24, T25, T38, T39. This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. The theorem neither proves the value rule from facts nor establishes that every apparently complex design has the relevant advantage. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance." + }, + { + "id": "software-engineering.evolution-priority.p2", + "fidelity": "partial", + "reason": "Bounded source correspondence to T24, T25, T26, T27, T38, T39. This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. The theorem neither proves the value rule from facts nor establishes that every apparently complex design has the relevant advantage. The proof checks stipulated evidence contents, not the real-world credibility or predictive calibration of arbitrary plans. No finite list of directions proves all future changes predictable or all omitted possibilities irrelevant. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance." + }, + { + "id": "software-engineering.evolution-priority.p3", + "fidelity": "partial", + "reason": "Bounded source correspondence to T24, T25, T26, T27, T28, T38, T39. This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. The theorem neither proves the value rule from facts nor establishes that every apparently complex design has the relevant advantage. The proof checks stipulated evidence contents, not the real-world credibility or predictive calibration of arbitrary plans. No finite list of directions proves all future changes predictable or all omitted possibilities irrelevant. The finite costs are modeled work/budget data. The source does not require every category to apply or provide a universal numerical tradeoff. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance." + }, + { + "id": "software-engineering.evolution-meaning.p1", + "fidelity": "partial", + "reason": "Bounded source correspondence to T29, T30, T38. The enumerated constructors illustrate source dimensions and allow an other direction; they do not claim every possible evolution is represented or cheap. These counterexamples reject unjustified cross-dimension inference without adding a duty that every change be inexpensive. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "software-engineering.evolution-meaning.p2", + "fidelity": "partial", + "reason": "Bounded source correspondence to T29, T30, T38. The enumerated constructors illustrate source dimensions and allow an other direction; they do not claim every possible evolution is represented or cheap. These counterexamples reject unjustified cross-dimension inference without adding a duty that every change be inexpensive. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "software-engineering.structural-judgment.p1", + "fidelity": "partial", + "reason": "Bounded source correspondence to T31, T32, T37, T38. These are relevant finite inquiries, not a mandatory universal checklist or a real-world estimate of all boundary costs. The equal-work case preserves step units through an actual path transformation; these units are a disclosed model measure, not observed engineering effort. Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "software-engineering.structural-judgment.p2", + "fidelity": "partial", + "reason": "Bounded source correspondence to T31, T32, T38. These are relevant finite inquiries, not a mandatory universal checklist or a real-world estimate of all boundary costs. The equal-work case preserves step units through an actual path transformation; these units are a disclosed model measure, not observed engineering effort. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "software-engineering.structural-judgment.p3", + "fidelity": "partial", + "reason": "Bounded source correspondence to T33, T34, T38. The model does not require retaining every historical behavior, a particular test procedure, or an added universal notification obligation. A passing finite test suite is not a universal equality proof; preservation always retains its identified scope. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "software-engineering.revision.p1", + "fidelity": "partial", + "reason": "Bounded source correspondence to T35, T36, T38. The recorded history is fixed model evidence; the theorem does not authenticate arbitrary real-world logs or prove every criticism response adequate. The result permits bounded retention, not permanent immunity from later grounds or criticism. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + }, + { + "id": "software-engineering.revision.p2", + "fidelity": "partial", + "reason": "Bounded source correspondence to T35, T36, T37, T38. The recorded history is fixed model evidence; the theorem does not authenticate arbitrary real-world logs or prove every criticism response adequate. The result permits bounded retention, not permanent immunity from later grounds or criticism. Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem." + } + ], + "target_entries": [ + { + "id": "T01", + "status": "accepted", + "reason": "The source explicitly adopts commitments rather than claiming universal factual truth or deductive hierarchy. The chapter-4 preference is additional. No theorem is required for document authority, and the concrete countermodels must not be promoted into independence of every conceivable formalization.", + "declarations": [], + "type_hashes": {} + }, + { + "id": "T02", + "status": "accepted", + "reason": "Generative requires valuation of expansion and revisability of every current Form, including organization, method and principle. Current examples are nonempty; the stable trace and budget-respecting stable action show that generativity does not require change in every act. This is an adopted policy predicate, not proof all systems possess it.", + "declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases" + ], + "type_hashes": { + "CoreReader.Adopted.generationSpecification": "4d07b8deec9112ff5d3e7fe744c159c254580260c78b82be6dd64347e8a9a4eb", + "CoreReader.Adopted.generationCases": "430a91318477db0305b3107b81f9df39652fa27673fdc38705a86f8e158ca138" + } + }, + { + "id": "T03", + "status": "accepted", + "reason": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions.", + "declarations": [ + "CoreReader.Adopted.generationLimits012" + ], + "type_hashes": { + "CoreReader.Adopted.generationLimits012": "69058c75db607f675c730d92da7dd1c6ee27d75385f4ac4ff717bd9fc7e925b2" + } + }, + { + "id": "T04", + "status": "accepted", + "reason": "Consistent quantifies over joint semantic consequences of the whole held theory under one Context. Snapshot change reporting is a separate one-way Boolean obligation. The code preserves same-question/assumptions/meaning/scope and time-slice distinctions; it does not model every way a prose report could conceal change.", + "declarations": [ + "CoreReader.Adopted.consistencySpecification", + "CoreReader.Adopted.consistencyCases" + ], + "type_hashes": { + "CoreReader.Adopted.consistencySpecification": "cf239ba7292f80875f93e960cd3417c226a8727f57f11e1ec4af4564caef076d", + "CoreReader.Adopted.consistencyCases": "16a20441e5650e4992e046ae4eeb2a1867f573730aa1dc402ca70508bb1802a6" + } + }, + { + "id": "T05", + "status": "accepted", + "reason": "consistencyConsequences directly applies the consistency prohibition to supplied positive and negative consequences. The revisionSlice examples provide distinct satisfiable times and inconsistent union; context examples preserve an admissible witness for each context. The theorem neither proves premises nor mandates permanent historical compatibility.", + "declarations": [ + "CoreReader.Adopted.consistencyConsequences", + "CoreReader.Adopted.consistencyCases" + ], + "type_hashes": { + "CoreReader.Adopted.consistencyConsequences": "4b3231ac25a534c2699cd8f548a59a7d8beb1cb3923456f10c95081a3b6b5be3", + "CoreReader.Adopted.consistencyCases": "16a20441e5650e4992e046ae4eeb2a1867f573730aa1dc402ca70508bb1802a6" + } + }, + { + "id": "T06", + "status": "accepted", + "reason": "Concrete contexts, overlapping inequalities, a consistent theory false at the selected outside world, and empty-theory countervaluations distinguish contradiction, truth, sufficiency and entailment. These support the source limits without relying on a free false support flag.", + "declarations": [ + "CoreReader.Adopted.consistencyLimits012" + ], + "type_hashes": { + "CoreReader.Adopted.consistencyLimits012": "1bb1429eb084c222d9a84341c2d6cae05e8c83c1374bbbab8402a372099649cc" + } + }, + { + "id": "T07", + "status": "accepted", + "reason": "The general interface/cases are reused; its engineering realization was rereviewed because selfModel now includes actual generation/evaluation rule objects and applicability. This strengthens rather than universalizes the source conditions.", + "declarations": [ + "CoreReader.Adopted.reflexivitySpecification", + "CoreReader.Adopted.reflexivityCases012" + ], + "type_hashes": { + "CoreReader.Adopted.reflexivitySpecification": "d8084253926a4e9a9b2b9d6ccea7fcba129de72b8412ec4bd30c08a9bdf254bc", + "CoreReader.Adopted.reflexivityCases012": "55a9d738a39137aeb7cf0ee474c532a636dc2a59451613848747030a756b29e7" + } + }, + { + "id": "T08", + "status": "accepted", + "reason": "A revisable principle applied only to target 1 fails required self-target 0; self tests fail elsewhere; owned revisions retain unsupported global claims. CompleteCharter012 is inhabited yet costAllowanceRecord admits an incorrect-output world, so the concrete corresponding Grounds012 claim fails. This is a bounded charter-versus-support model, not philosophical independence in all interpretations.", + "declarations": [ + "CoreReader.Adopted.reflexivityLimits012" + ], + "type_hashes": { + "CoreReader.Adopted.reflexivityLimits012": "6aaa9a96ab7f8fe3ebe04633ee7e9ae054eafa88e7e8289179d143ee96e46d05" + } + }, + { + "id": "T09", + "status": "accepted", + "reason": "Grounds012 formalizes successful supported grounds for one declared task using same claim/articulation/discharge and task-appropriateness. Local/global and stronger-claim countermodels preserve force and scope. It is not a complete classifier or universal procedure for deciding all possible mixed claims. Calling it the obligation to examine rather than the successful support condition would overstate the correspondence. No Core 0.1.3 all-facet obligation is introduced.", + "declarations": [ + "CoreReader.Adopted.Grounds012", + "CoreReader.Adopted.groundsCases012" + ], + "type_hashes": { + "CoreReader.Adopted.Grounds012": "65ead33e1cc510ec07082dde80dbec28ca36d80391c18e2ca6df7ed3e1353029", + "CoreReader.Adopted.groundsCases012": "5d659ec603f559d1be5abf4df0466b2daee1633dcfbf70194c0b8ccf9640e40f" + } + }, + { + "id": "T10", + "status": "accepted", + "reason": "Empirical discharge includes an in-scope compatible witness, scoped support and uncertainty support. Repetition of irrelevant first-coordinate/action observations cannot establish the second coordinate or budget value. The successful uncertainty is the exhaustive Boolean disjunction, not a quantified confidence estimate or a production measurement.", + "declarations": [ + "CoreReader.Adopted.empiricalSpecification", + "CoreReader.Adopted.empiricalCases012" + ], + "type_hashes": { + "CoreReader.Adopted.empiricalSpecification": "9f534ab1f51da3b82f8edf1d35b0dfab34dfe042d10c44582f04b4dce6569ef2", + "CoreReader.Adopted.empiricalCases012": "fba89ddcd1cf1f745deec2bbdb86e1434e01d6fc73f99c6bf690331560f736f6" + } + }, + { + "id": "T11", + "status": "accepted", + "reason": "The inferential wrapper requires satisfiable assumptions and actual entailment. Correct rejection of an unentailed conclusion is represented separately by InferenceExamined false and a countervaluation. Together they preserve the examination/success distinction, provided the wrapper alone is not described as the full act of assessment.", + "declarations": [ + "CoreReader.Adopted.inferentialSpecification", + "CoreReader.Adopted.inferentialCases012" + ], + "type_hashes": { + "CoreReader.Adopted.inferentialSpecification": "d56b013c37bfeb071f171cb3f552b8775a79eee535305a78d2d9551b86c03c16", + "CoreReader.Adopted.inferentialCases012": "b37768f2ff32da55daf97b29dc027bfa78aa1a1f2456c80937dde7aa64a5c515" + } + }, + { + "id": "T12", + "status": "accepted", + "reason": "The value construction identifies position, joint reasons, application limits, consequences and relevant criticism responses. It assumes starting claims and supplies a joint witness instead of proving every starting assumption. The universal consequence test and response nonemptiness are this application's sufficient procedure, not newly mandatory philosophical proof requirements or proof of response adequacy.", + "declarations": [ + "CoreReader.Adopted.valueSpecification", + "CoreReader.Adopted.valueCases012" + ], + "type_hashes": { + "CoreReader.Adopted.valueSpecification": "1f45a163b8b2a0db44eeaeb0910e0af6168e4674ab3a3925dcfe54e3015e3ae6", + "CoreReader.Adopted.valueCases012": "ce1dba18fb8bf4611fe703b21270e3b59591f6f1cf1c40f2ee03899fa26c142a" + } + }, + { + "id": "T13", + "status": "accepted", + "reason": "Clearly articulated false assumptions, repeated wrong-object observations, neutral records compatible with nonadoption, and the ordinary value example show the intended non-substitutions. Qualitative implication orders claim strength without imposing a numerical scale.", + "declarations": [ + "CoreReader.Adopted.groundsLimits012" + ], + "type_hashes": { + "CoreReader.Adopted.groundsLimits012": "b404dce33c3fbf86c65d3824e2fceaf5f0a1f312ce1edc1f0a9e9251af9ccad3" + } + }, + { + "id": "T14", + "status": "accepted", + "reason": "The local scope account binds comparison pairs, conditions, observed scope, relevance and each method explanation to the same claim. Its concrete method meanings prove local/repeated support and failure of global support. The generic explains relation remains supplied and the interface does not force every method to be used.", + "declarations": [ + "CoreReader.Adopted.scopeSpecification", + "CoreReader.Adopted.scopeCases012" + ], + "type_hashes": { + "CoreReader.Adopted.scopeSpecification": "01857cd86d39ca8bc2d54d15555ebed9fc9fa6a0bd40196743e5f1fbbcb966b7", + "CoreReader.Adopted.scopeCases012": "e503dd4f8dacf02303b9bd7e56977a56feee218c1c677d8836c15039e83655a8" + } + }, + { + "id": "T15", + "status": "accepted", + "reason": "Explicit functions agree only at zero and differ at one; one observation supplies local support. Trial fields separate recorded accuracy, equal settings and bounded output, and Boolean draws have equal positive weights with different outcomes. This is a finite possible-outcome model, not verification of a real stochastic process.", + "declarations": [ + "CoreReader.Adopted.scopeLimits012" + ], + "type_hashes": { + "CoreReader.Adopted.scopeLimits012": "a286f42a08d68addaec58cb6b0b9656968db614439bd753425f3972b29d8125c" + } + }, + { + "id": "T16", + "status": "accepted", + "reason": "Resolved for the explicitly declared application capability UnderstandingApplication012: the same explained doubling process must also answer all multiplier/input variations using the actual multiplication mechanism. Identical output and ExplanationContract no longer suffice: the fixed-double answer gives 2 instead of 3 at multiplier=3,input=1, while mechanismResponder answers the declared variations and receives same-object Grounds. This is an operational understanding/variation-answer capability selected by the application, not a cognitive definition or universal standard of understanding.", + "declarations": [ + "CoreReader.Adopted.capabilitySpecification", + "CoreReader.Adopted.capabilityCases012" + ], + "type_hashes": { + "CoreReader.Adopted.capabilitySpecification": "908a244789ebae715ab94703060109000c2369e1c4735c6cdb48a096243f3c04", + "CoreReader.Adopted.capabilityCases012": "71d33f0d4ef4ccd7b59de8cf61f1e8aa0edae58f02813c4f4f3d79754d592d03" + } + }, + { + "id": "T17", + "status": "accepted", + "reason": "Reliable double output with explanation = none refutes the stronger declared explanation contract; repeated item counts do not add an unavailable operation. This establishes limits on the represented output/explanation capability, not a cognitive account of human or agent understanding.", + "declarations": [ + "CoreReader.Adopted.capabilityLimits012" + ], + "type_hashes": { + "CoreReader.Adopted.capabilityLimits012": "8efa4107232374dd4f308f0f4c19f39b706da292b2cb4042aba290ade3368d52" + } + }, + { + "id": "T18", + "status": "accepted", + "reason": "JustifiedChoice combines feasibility with a valued method-content reason; status-only reasons fail by definition as the additional adopted evaluative commitment. Conventional identity remains eligible, internal explanation/applicability/simplicity/procedure reasons are admissible, and the current philosophy review is assessed by actual output reasons. No optimality or all-reasons-valid theorem is claimed.", + "declarations": [ + "CoreReader.Adopted.choiceSpecification", + "CoreReader.Adopted.choiceCases012" + ], + "type_hashes": { + "CoreReader.Adopted.choiceSpecification": "4b2ffafbf066633850901441a4978132cc3d84f95bef9c803f56a17866762054", + "CoreReader.Adopted.choiceCases012": "36f89bc4962aa87be316945afd3147dd30111dfdca8902a41b0392a2bda28c04" + } + }, + { + "id": "T19", + "status": "accepted", + "reason": "A single feasible conventional choice, unequal outputs, equal local but different global behavior, and a distinguishing internal explanation meet the requested cases. The additional-choice example distinguishes accurate general assessment of non-entailment from the separate priority norm; this is deliberately the limited general-assessment relation in the target, not all Grounds duties.", + "declarations": [ + "CoreReader.Adopted.choiceLimits012" + ], + "type_hashes": { + "CoreReader.Adopted.choiceLimits012": "84bdf70f43a217d10ccf0d7a8179aea2b586ab845a7c8f3a2f087089c6098874" + } + }, + { + "id": "T20", + "status": "accepted", + "reason": "Resolved. The theorem now explicitly concludes the full normative-content membership, grounds for every held claim, and consistencySpecification for the same expanded ownTheory. It remains a legitimate projection of Inherited, not mutual logical derivation from fewer premises. Actual self-rule generation/assessment objects are included and checked; original empirical/inferential/value tasks remain separate.", + "declarations": [ + "CoreReader.Engineering.inheritedMutualApplication", + "CoreReader.Engineering.inheritedMutualCases" + ], + "type_hashes": { + "CoreReader.Engineering.inheritedMutualApplication": "b60496465943a095fdd0772f4002302eb9242ece03be7a2e20ce616f0253ee4a", + "CoreReader.Engineering.inheritedMutualCases": "e3c73c4f98c7a3fe5bfadc8b2bc7a9a5231473504e047179d6299e3417f2ba4c" + } + }, + { + "id": "T21", + "status": "accepted", + "reason": "FormKind explicitly includes organization, method and principle. Empirical and semantic-inferential facets and noncomputable proposition decisions prevent restricting assessment to executable tests. The finite formal vocabulary is illustrative rather than an exhaustive philosophical ontology.", + "declarations": [], + "type_hashes": {} + }, + { + "id": "T22", + "status": "accepted", + "reason": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established.", + "declarations": [ + "CoreReader.Engineering.ActivityScope", + "CoreReader.Engineering.subjectLifecycleCases" + ], + "type_hashes": { + "CoreReader.Engineering.ActivityScope": "fdfa84c29643bd37a72d614541ecf59b4b7efdf606ac4b7480cb02fe3e4c8382", + "CoreReader.Engineering.subjectLifecycleCases": "a2d126370b7fef5af4645ef64d85b169467518bfb8f76269b41f47f82e0bd02b" + } + }, + { + "id": "T23", + "status": "accepted", + "reason": "The original maintainer has privateLayout while the successor lacks it; explicit path prerequisite failure establishes the contrast. The continuing activity remains nonbounded despite its temporary label. The passive artifact returns inputs and has no propose action by its actual definition, providing one counterexample rather than a law of all artifacts.", + "declarations": [ + "CoreReader.Engineering.subjectLimits" + ], + "type_hashes": { + "CoreReader.Engineering.subjectLimits": "4d0b23030599912d1ad72613e9956d5dd179d987aa64f0a694f74e85847b2a2b" + } + }, + { + "id": "T24", + "status": "accepted", + "reason": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "declarations": [ + "CoreReader.Engineering.EvolutionPriority", + "CoreReader.Engineering.priorityConditionsCases" + ], + "type_hashes": { + "CoreReader.Engineering.EvolutionPriority": "8609cb39944d272540e985febb940328bc4a85a6e22fe06e652f4c95bd043ddb", + "CoreReader.Engineering.priorityConditionsCases": "3206e3bed26ebff1742e044beabbfcca534354e4895936cd6496b4af5a5485e9" + } + }, + { + "id": "T25", + "status": "accepted", + "reason": "The theorem explicitly assumes the adopted EvolutionPriority rule, applicability and no departure; it extracts the chosen evolvable value and substitutes into the supplied complexity comparison. This matches the target's normative-premise requirement. Concrete choices show simple violates the rule without a threat and can pass with the accounted threat.", + "declarations": [ + "CoreReader.Engineering.priorityWhenApplicable", + "CoreReader.Engineering.priorityChoices" + ], + "type_hashes": { + "CoreReader.Engineering.priorityWhenApplicable": "6b1efb7cab71c9b837ce57e666f331112f6416f18a59675e8119416b3d7a39a6", + "CoreReader.Engineering.priorityChoices": "d4cbb2cea4f863c0a900531a90fd4e36cd04ad50df57b340871001d6fb01b349" + } + }, + { + "id": "T26", + "status": "accepted", + "reason": "The generic Ground interface does not restrict ground categories. Concrete plans identify a positive release and direction; knowledge/history cases contain a service/mechanism or repeated direction list, and forecast revision changes supported directions. The adapter only checks designated strings/list content, so actual relevance of a mechanism/history is a stipulated interpretation. It must not be reported as independent validation of arbitrary knowledge records.", + "declarations": [ + "CoreReader.Engineering.CredibleDirection", + "CoreReader.Engineering.credibilityCases" + ], + "type_hashes": { + "CoreReader.Engineering.CredibleDirection": "1906e98dd6d042fc973fb93506c24accc024a7643adaddd05e071030c8b5682b", + "CoreReader.Engineering.credibilityCases": "b5d172388be7bcd1bdbeea1f07436b61458bd02c0e714dc83b7d7565adefa6c9" + } + }, + { + "id": "T27", + "status": "accepted", + "reason": "One implemented variant coexists with credible direction; unsupported imagined changes do not warrant the defined investment; evolvable supports nine registered directions while maximal supports ten but is not the priority. Different per-burden bounds and work comparisons demonstrate a selective example, not a mathematical impossibility of numerical tradeoffs.", + "declarations": [ + "CoreReader.Engineering.credibilityLimits" + ], + "type_hashes": { + "CoreReader.Engineering.credibilityLimits": "76415ebe0bbc33c3827da7db33b1e89e3f676b7cf0f4f39df5401beeda5f40c4" + } + }, + { + "id": "T28", + "status": "accepted", + "reason": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "declarations": [ + "CoreReader.Engineering.JustifiedDeparture", + "CoreReader.Engineering.costCases" + ], + "type_hashes": { + "CoreReader.Engineering.JustifiedDeparture": "f6c50ef1eaca65b4a3886bcbc5ccb11393e89a2d7baf8f6980b6a58f9d0719a4", + "CoreReader.Engineering.costCases": "0159f38d1da3fe90524ce5a5d2e2b1d3a4fc5a14c6a76a6fbc07a158d16edd90" + } + }, + { + "id": "T29", + "status": "accepted", + "reason": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "declarations": [ + "CoreReader.Engineering.EvolutionClaim", + "CoreReader.Engineering.evolutionKindsCases" + ], + "type_hashes": { + "CoreReader.Engineering.EvolutionClaim": "9c0c528a387fd26adf8c44acbd1e97da3c991c6544f40f31c0a8c3adb2ccd2f7", + "CoreReader.Engineering.evolutionKindsCases": "ccab4c5ed0bb676cef2d8435b8252630c0bc2f32d0ce9023156532deb6b77a1e" + } + }, + { + "id": "T30", + "status": "accepted", + "reason": "Addition can cost two while withdrawal/revision costs seventeen; coordinated work exceeds independent work; migration can remain expensive while evolution priority holds. Equal addition cost directly refutes universal strict improvement over all Change values.", + "declarations": [ + "CoreReader.Engineering.evolutionDimensionsLimits" + ], + "type_hashes": { + "CoreReader.Engineering.evolutionDimensionsLimits": "ba2af856a831323eaa2344e83084a08689b7a287f6a8542edcef6fb0c2e57af7" + } + }, + { + "id": "T31", + "status": "accepted", + "reason": "Resolved as a finite intended-change case. actualCrossBoundaryObligation links the registered edge caller 2/callee 1 to a real callee compiler edit, a caller contractRunner/publicContract step and finite observed order preservation. Removing the caller check leaves the crossing true but rejects the obligation; changing the callee to 7 loses the crossing; replacing output with sortedUnique fails the contract. No network/runtime semantics or universal completeness of every edge is claimed.", + "declarations": [ + "CoreReader.Engineering.StructuralAccount", + "CoreReader.Engineering.structuralCases" + ], + "type_hashes": { + "CoreReader.Engineering.StructuralAccount": "45df6c2c2383df05162c2a265ba6daf5debbdf46847dc9de1801f881eb00db1e", + "CoreReader.Engineering.structuralCases": "4fdfb378096465bfe330f655d5cc248745bbfdcb505407595d9d23254428de9e" + } + }, + { + "id": "T32", + "status": "accepted", + "reason": "The frozen delta now supplies the exact new_boundary_same_work case missing from the initial code: an actual added boundary and changed path with identical units/work and remaining successor prerequisite failure. The original increased-work example is retained. These and the signature/module/named-pattern examples meet the finite negative target, without proving real-world overhead or boundary execution semantics.", + "declarations": [ + "CoreReader.Engineering.structureNotCapability" + ], + "type_hashes": { + "CoreReader.Engineering.structureNotCapability": "2c09939db7dbc6561ff01284d1187a4272120050885c7743d2227d2a6e133ea9" + } + }, + { + "id": "T33", + "status": "accepted", + "reason": "ContractChangeAccount separates finite scoped equality from deliberate revision with changed order/retry obligations and affected-party coverage. Missing operator/incorrect old limits fail; [99] demonstrates an intentionally out-of-scope historical difference; changing procedure text remains allowed. Actual notification, completeness of parties and all-input equivalence are not modeled.", + "declarations": [ + "CoreReader.Engineering.ContractChangeAccount", + "CoreReader.Engineering.contractCases" + ], + "type_hashes": { + "CoreReader.Engineering.ContractChangeAccount": "c58d92d3f41481a1b24941446085e8161c5dcb32cc266487f9734c2c03c8d3fe", + "CoreReader.Engineering.contractCases": "d577c98b03b1349b8acdc20e24a2d1141ea92e5ce49ab73e3518385e0981adeb" + } + }, + { + "id": "T34", + "status": "accepted", + "reason": "contractPreservation returns the supplied universal in-scope equality proof, rather than deriving it from finite tests. changedObservationNotPreserved gives the counterexample implication; contractRevisionObligations eliminates the failed preservation branch of the assumed account. Finite order/retry cases illustrate the distinction. This is the correct conditional reading of the target, not an empirical proof from test success.", + "declarations": [ + "CoreReader.Engineering.contractPreservation", + "CoreReader.Engineering.contractDistinctions" + ], + "type_hashes": { + "CoreReader.Engineering.contractPreservation": "d9078e49c446deddda26e669891464c695136710e6b34620ca8ee4f08bdafbed", + "CoreReader.Engineering.contractDistinctions": "bc0f83a82833ba24fc73f01ff24ac513e5ce42fec36a8195c70d516365a07a28" + } + }, + { + "id": "T35", + "status": "accepted", + "reason": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign.", + "declarations": [ + "CoreReader.Engineering.RevisionAccount", + "CoreReader.Engineering.revisionCases" + ], + "type_hashes": { + "CoreReader.Engineering.RevisionAccount": "865a4c6c542f07f6b0ce44a67e98175239ef389738b16bc6071ccebffae61c8b", + "CoreReader.Engineering.revisionCases": "8e2008450f4c7a80eca24630a18e6c77bf570055daee2c75c2577987c06ff629" + } + }, + { + "id": "T36", + "status": "accepted", + "reason": "Prior finite no-retroactive-success/consensus/success examples are retained. A fresh same-object probe proves revisionFor sharedContext evolvable retains the old/current design choice while selfModel evolvable satisfies reflection; this makes the open-stable example explicit without turning all stability into a duty.", + "declarations": [ + "CoreReader.Engineering.revisionLimits" + ], + "type_hashes": { + "CoreReader.Engineering.revisionLimits": "071a3e5cddf46166eacbd56285cdb4abb9f11a94e50e8bf00f8bc100f01026d0" + } + }, + { + "id": "T37", + "status": "accepted", + "reason": "Resolved in the same fixed shared context. priorityValueMeaning proves candidate-by-candidate equivalence between the adopted evolvable selection commitment and actual EvolutionPriority; priorityGrounds transports value support through that explicit equality while preserving the value task. The theorem now returns that exact priority claim's Grounds, domain-content membership and complete-theory consistency, in addition to reflection. The equivalence depends on current applicability/no-departure and must not be generalized to other contexts.", + "declarations": [ + "CoreReader.Engineering.priorityRemainsReflexive", + "CoreReader.Engineering.priorityReflexiveCases" + ], + "type_hashes": { + "CoreReader.Engineering.priorityRemainsReflexive": "285b4edb7397d25ccc631b194a1ff8ebb5204df450d52ec8eaf0685519b289c2", + "CoreReader.Engineering.priorityReflexiveCases": "2be55699c66ab5ba0f6310f298e19b890de4caef622e0d69676f2d6a7a3b5170" + } + }, + { + "id": "T38", + "status": "accepted", + "reason": "Accepted as the requested bounded inhabitation witness after rechecking expanded Inherited and ownTheory, not merely its unchanged exterior theorem statement. The same evolvable candidate/context satisfies original necessary requirements, applicable priority/no threat, actual maintainer paths, full held fact/norm content, original support tasks and actual self-rule reflection. Source interpretation remains a revisable finite model; no empirical or philosophical universal correctness follows.", + "declarations": [ + "CoreReader.Engineering.jointWitness" + ], + "type_hashes": { + "CoreReader.Engineering.jointWitness": "56d1bd97b0ac6c069484812a2a975dc185a905a24ee133a780b5f23a7fdc0b59" + } + }, + { + "id": "T39", + "status": "accepted", + "reason": "Accepted as the requested bounded non-entailment witness with every original strong branch preserved. The same continuing shared context has real encoded applicability/advantage and no lifecycle/cost escape; presentSimple adopts a separately grounded simplicity value and satisfies expanded inherited duties yet fails the extra priority. normApplies records adoption of the additional domain norm, not disappearance of its actual PriorityConditions. This distinction is central to the source's additional-value claim.", + "declarations": [ + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ], + "type_hashes": { + "CoreReader.Engineering.inheritedDoesNotEntailPriority": "ad1b1b45257f57a53567b08bc87eb32bd6d8acf8395e9762a684c1116f270197" + } + }, + { + "id": "T40", + "status": "accepted", + "reason": "Maintain source authority and separate normative specification, conditional theorem, finite witness, actual measurement, interpretation and adoption. No unseen final reader edition was assessed in this initial comparison. Disclosed abstraction does not automatically discharge a required semantic case or permit relabeling a difficult target as a boundary.", + "declarations": [], + "type_hashes": {} + } + ], + "review_context": { + "adopted_baseline": "SoftwareEngineering 0.2.0, inherited Core 0.1.2", + "runtime": "Current OrganonCore checker; not a change of adopted philosophy.", + "exposure": "Source-first initial review was saved before target comparison and code. Code-only reviewer first received transformed code without philosophy or source mapping; its original account and later delta account are retained. Source and code reviewers compared original source only after initial records. R3 is an informed three-way comparison of actual corrected code; reader authorship begins after these source judgments and requires separate QA.", + "acceptance": "All 40 frozen goals and all 175 semantic cases remain. Accepted means bounded source correspondence, never universal philosophical correctness.", + "reuse": "Six helper modules reuse previous Core mathematical code with revised source comments. Current exact code, complete declaration types, dependencies and new source links were reviewed; prior Core approval was not transferred. Earlier rejected/incomplete judgments remain historical.", + "binary": "A stray Domain.olean present in the immutable R3 snapshot is excluded from the maintained project and portable copy. It was not a checker input; exact Lean source was unchanged.", + "source_migration": { + "prior_fidelity_sha256": "8783990e4699af1378ea64f00351cc8dc7a7040264a22ab845ab00467b62e7a1", + "review": "reviews/source-migration-2026-09-15.md", + "scope": "New source metadata and rationale location only. Existing code, target bodies and bounded judgments reused under the separate migration comparison; historical initial records are not new approvals." + } + } +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/presentation-derivations.json b/SoftwareEngineering/lean/philosophy/reviews/presentation-derivations.json new file mode 100644 index 0000000..3ce6add --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/presentation-derivations.json @@ -0,0 +1,490 @@ +[ + { + "role": "source_initial", + "file": "source-initial.md", + "original_sha256": "0975c0e97c220a9558cbb56c264c7253c70175cedf6cd771b860ec5764a13ab5", + "presentation_sha256": "edd1c4791b80068fdacc0fd168d918226abf9764de3d02554432dc160f3e1113", + "changed": true, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "source_initial_catalog", + "file": "source-initial-targets.json", + "original_sha256": "8642237a254b0fe4d4501f7ab59e0ef22cbec3f23ad22def57da3af2fe0d8bec", + "presentation_sha256": "a033f7aa1c4b5b570884a372578ba544ebe5303c453c91ce0f46bd46d8921a36", + "changed": true, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "freeze_review", + "file": "target-freeze-review.md", + "original_sha256": "cd994ee5ceb0e789c5c217914d4c0bc88e1dfeeae6d81bfef4f2ff3bc383c85f", + "presentation_sha256": "cd994ee5ceb0e789c5c217914d4c0bc88e1dfeeae6d81bfef4f2ff3bc383c85f", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "code_blind", + "file": "code-blind-initial.md", + "original_sha256": "cf9280ddd3365440e848b14043a6208b9fea5114f9ff13cea4e236e3358317df", + "presentation_sha256": "cf9280ddd3365440e848b14043a6208b9fea5114f9ff13cea4e236e3358317df", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "code_blind_identity", + "file": "code-blind-identity.json", + "original_sha256": "78c842326b65bc894eccf10e15ae9fef75f8850abbdb7025d766eefa4d8f7a53", + "presentation_sha256": "78c842326b65bc894eccf10e15ae9fef75f8850abbdb7025d766eefa4d8f7a53", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "code_blind_delta", + "file": "code-blind-delta.md", + "original_sha256": "a0a16628362882d5574bf41123d6fed41ce735083d55dccfb06650555cb3b776", + "presentation_sha256": "a0a16628362882d5574bf41123d6fed41ce735083d55dccfb06650555cb3b776", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "code_blind_delta_identity", + "file": "code-blind-delta-identity.json", + "original_sha256": "3cd8802c7670caf78d74027c73e76420b0df5eabe346b4fe55e16e19b71db88e", + "presentation_sha256": "3cd8802c7670caf78d74027c73e76420b0df5eabe346b4fe55e16e19b71db88e", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "blind_source_initial", + "file": "blind-source-initial.md", + "original_sha256": "41231e41278a6389f72db28cf2b75322cfdecaa0c8a831051aa7b10b7b30b2e9", + "presentation_sha256": "41231e41278a6389f72db28cf2b75322cfdecaa0c8a831051aa7b10b7b30b2e9", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "blind_source_initial_targets", + "file": "blind-source-initial.json", + "original_sha256": "458c5302b44cfcaa799fd1d9cebf34df392aebdf7fa57c74e2cd5b8c2fa96244", + "presentation_sha256": "458c5302b44cfcaa799fd1d9cebf34df392aebdf7fa57c74e2cd5b8c2fa96244", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "code_comparison_final", + "file": "code-comparison-final.md", + "original_sha256": "ba3e905877e33ef96e4251cb59b8a1f52cca397eecaef92570ebf28261a8fd0c", + "presentation_sha256": "ba3e905877e33ef96e4251cb59b8a1f52cca397eecaef92570ebf28261a8fd0c", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "code_target_final", + "file": "code-targets-final.json", + "original_sha256": "e01cd00cbcfa4ba8c6592917ea7321eb3826bc0b365a2b1b64170a1a24a93825", + "presentation_sha256": "e01cd00cbcfa4ba8c6592917ea7321eb3826bc0b365a2b1b64170a1a24a93825", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "code_review_identity", + "file": "code-review-identity.json", + "original_sha256": "abb056f71ed48ec009e9bd16bd037dd2f0dab84cf3746008e4fd536aecfe78ea", + "presentation_sha256": "abb056f71ed48ec009e9bd16bd037dd2f0dab84cf3746008e4fd536aecfe78ea", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "independent_actual_check", + "file": "r3-actual-audit.log", + "original_sha256": "b9f95581347504e245f0cea7f98cbf2b818c242aaa26615b031421e2fab7729c", + "presentation_sha256": "6aaad0f6c1f73f44631df61e4631af9d82596329fb71cac4a6f42f76bfb60b5b", + "changed": true, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "independent_actual_check", + "file": "r3-axiom-summary.json", + "original_sha256": "f23b5f29c342bb30dd274c9d7fad6932565eecd69c91f27f846d017fe5a253c7", + "presentation_sha256": "f23b5f29c342bb30dd274c9d7fad6932565eecd69c91f27f846d017fe5a253c7", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "independent_actual_check", + "file": "r3-build.log", + "original_sha256": "f6e727662ac83e00e087be3246525187946b87441afdb6cd9a3f3af9d3e5eedd", + "presentation_sha256": "f6e727662ac83e00e087be3246525187946b87441afdb6cd9a3f3af9d3e5eedd", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "independent_actual_check", + "file": "r3-declarations.json", + "original_sha256": "b92ca5728f275caeec340cdc63aa52dc44a303c30a887cfcfa3493542e7e6b07", + "presentation_sha256": "b92ca5728f275caeec340cdc63aa52dc44a303c30a887cfcfa3493542e7e6b07", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "independent_actual_check", + "file": "r3-audit-input.txt", + "original_sha256": "c31b98c29db2e12b2d7c2d7f968c0fa4db76a68061ea9bf14ce81727f376ea19", + "presentation_sha256": "c31b98c29db2e12b2d7c2d7f968c0fa4db76a68061ea9bf14ce81727f376ea19", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "independent_actual_check", + "file": "r3-probe-input.txt", + "original_sha256": "3c72af41c80077164e35a7ad2dcc8c927a0981c12f4c698702d658b543f8d8d5", + "presentation_sha256": "3c72af41c80077164e35a7ad2dcc8c927a0981c12f4c698702d658b543f8d8d5", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "independent_actual_check", + "file": "r3-probes.log", + "original_sha256": "7c5d415119ea3e427dfc06acbf415cf5a0cfbf12ac7155d553a7a7ea4ababdd7", + "presentation_sha256": "0c899aa78e9ae2473f6203f0f5e680657aeeac0584472a1f1c2d1798b4e75b44", + "changed": true, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "independent_actual_check", + "file": "r3-stability-probe-input.txt", + "original_sha256": "677f560a47f9262bf08cf337f423516c163970906668bd2d541e9383c56531dd", + "presentation_sha256": "677f560a47f9262bf08cf337f423516c163970906668bd2d541e9383c56531dd", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "independent_actual_check", + "file": "r3-stability-probe.log", + "original_sha256": "9fa3b6ead7afc298499f30c5b70014c78b6686a8269611537606fa5a7c02b6a2", + "presentation_sha256": "9fa3b6ead7afc298499f30c5b70014c78b6686a8269611537606fa5a7c02b6a2", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "source_comparison", + "file": "source-code-review-full-initial.md", + "original_sha256": "d1c38be6f8826ff29ff01ec12bb2d45f3f32e4e4b45830c7fd3250a40ab13767", + "presentation_sha256": "d1c38be6f8826ff29ff01ec12bb2d45f3f32e4e4b45830c7fd3250a40ab13767", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "source_comparison", + "file": "source-code-review-full-initial.json", + "original_sha256": "3def05f99f44b763c9bf7b3475f6aad631969ec2387d10b802965967f5f45386", + "presentation_sha256": "2fe6ec4c19ecf5d73b347c2a11c2c916c9ee69ca532b19746b160178222975c1", + "changed": true, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "source_comparison", + "file": "source-code-review-adopted-f01-f06-final.md", + "original_sha256": "dc1952e457239f9c5a72d99b50ff043f3c243ff8914efea20e0bc49b3af441b4", + "presentation_sha256": "dc1952e457239f9c5a72d99b50ff043f3c243ff8914efea20e0bc49b3af441b4", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "source_comparison", + "file": "source-code-review-adopted-f01-f06-final.json", + "original_sha256": "ad5a1cdb9184149462c412a3681a4b865138039468d46b1619f0714826127f54", + "presentation_sha256": "a43e9e3dd6b6d98497f3803f3c4e0d27666fa4aedb48e293ea7c6375561422eb", + "changed": true, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "source_comparison", + "file": "source-code-review-domain-r2.md", + "original_sha256": "53288a6b2e5bdc55a18a004c0a3c38c0a31269d97309e1f4a0b864f9cfeba28f", + "presentation_sha256": "53288a6b2e5bdc55a18a004c0a3c38c0a31269d97309e1f4a0b864f9cfeba28f", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "source_comparison", + "file": "source-code-review-domain-r2.json", + "original_sha256": "5d8eed0f715c6aeed7f32707478d89e576c8cc8758fb5523fb6b8b8fb9a53b2d", + "presentation_sha256": "5d8eed0f715c6aeed7f32707478d89e576c8cc8758fb5523fb6b8b8fb9a53b2d", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "source_comparison", + "file": "source-code-review-domain-same-work-final.md", + "original_sha256": "c64b54d89ffed6592d5b745772835f9ff1ace23305a51dfa688289bf25c9cde2", + "presentation_sha256": "c64b54d89ffed6592d5b745772835f9ff1ace23305a51dfa688289bf25c9cde2", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "source_comparison", + "file": "source-code-review-domain-same-work-final.json", + "original_sha256": "99c334f55fce1629cf3a2776832fb389305b81062dd129ce4e661158560d8d8b", + "presentation_sha256": "99c334f55fce1629cf3a2776832fb389305b81062dd129ce4e661158560d8d8b", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "source_comparison", + "file": "source-code-review-f07-f08.md", + "original_sha256": "898af33213a832832f4b6d84a8f94fd99bede9a0abae055b9e2a1af3b8ee5b1f", + "presentation_sha256": "898af33213a832832f4b6d84a8f94fd99bede9a0abae055b9e2a1af3b8ee5b1f", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "source_comparison", + "file": "source-code-review-f07-f08.json", + "original_sha256": "d7dcad383daf362011519d8c71b33bd6be78a2f17ea54f9d2d9f1d3be1b10641", + "presentation_sha256": "58928fb167139305c8284d64f66ab52fd2bd22e9eb751beedbf4dd6629282fa5", + "changed": true, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "source_comparison", + "file": "source-code-review-r3.md", + "original_sha256": "c3d06769eba25fec696936c87a560228ce04d675757adc8887a36357ff9939aa", + "presentation_sha256": "c3d06769eba25fec696936c87a560228ce04d675757adc8887a36357ff9939aa", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "source_comparison", + "file": "source-code-review-r3.json", + "original_sha256": "e39b5fb2b152f619f8c2b023b74d7b5d239d5368eaaf9b98dffbe630e47f4a16", + "presentation_sha256": "05bcb385022d349c92589785d98912746330350335602d47968c240f3b79d376", + "changed": true, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_review", + "file": "reader-independent-source-review-r1.md", + "original_sha256": "2933d9049854ac3905a75493cecde9e72689a6883f337ca5f1da3f4da1ac8096", + "presentation_sha256": "2933d9049854ac3905a75493cecde9e72689a6883f337ca5f1da3f4da1ac8096", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_review", + "file": "reader-independent-source-review-r1.json", + "original_sha256": "369a545cf59a9526ff841ca8b9b46fa40112a2a4ecf713a815ed51e30f164c5b", + "presentation_sha256": "6f167b52d7081adfc0bbc7dd631c7c97556efa875b972828d811b68b810f72de", + "changed": true, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_review", + "file": "reader-independent-source-review-r1-anchors.md", + "original_sha256": "335b251e0f4ed2b7115230558169964ffd4f930569fcff7fa7f4c20310fa5054", + "presentation_sha256": "335b251e0f4ed2b7115230558169964ffd4f930569fcff7fa7f4c20310fa5054", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_review", + "file": "reader-independent-source-review-r1-anchors.json", + "original_sha256": "b8d9d322c8702101b3846519e41b47c14a89d775df11e3f0c71436373313c711", + "presentation_sha256": "e8c827f7763b611d8cedc5350efd63cec727e76385fad18fc3286e6c8a8efb1a", + "changed": true, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_review", + "file": "reader-independent-source-review-r2-components.md", + "original_sha256": "998c8a9aca43571ec4e094ef49d3b6e19c026f82f62aae2e727743812e1e0588", + "presentation_sha256": "998c8a9aca43571ec4e094ef49d3b6e19c026f82f62aae2e727743812e1e0588", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_review", + "file": "reader-independent-source-review-r2-components.json", + "original_sha256": "2cd4fbdee43dff496a9099fe8d7186e6d133689c346e34f9c0c60d2a81ba6cea", + "presentation_sha256": "8454724e90e354eca9755f7113cba07d8d458c2c61fb86030ebb9377357bc3b8", + "changed": true, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_review", + "file": "reader-independent-source-final.md", + "original_sha256": "93979bd24e25dede4dbfecd9a264d9e63d2e01855e7a4e27b8c03add7c48894a", + "presentation_sha256": "93979bd24e25dede4dbfecd9a264d9e63d2e01855e7a4e27b8c03add7c48894a", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_review", + "file": "reader-independent-source-final.json", + "original_sha256": "0910bcf51934842a548b2177a081b91ada33b71a486f1f60fee55977f76ce823", + "presentation_sha256": "51ff57e3d2988cdd6e44b6e3d6709be061e80d777b79969f6a14aafcc6b81f54", + "changed": true, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_review", + "file": "reader-independent-domain-r1.md", + "original_sha256": "2c411fb38eef7f4637c9c243930b4f30029b059893056518607e767cd851dae8", + "presentation_sha256": "2c411fb38eef7f4637c9c243930b4f30029b059893056518607e767cd851dae8", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_review", + "file": "reader-independent-domain-r1.json", + "original_sha256": "fc60fdb13ba8f01734c78bcea55829701d2f6649a0064f9bdc58c0f9079f981d", + "presentation_sha256": "a472140f51246e278c9d8e3c69541c5fe78cb54b2f61f2eba3d64d8583645d8b", + "changed": true, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_review", + "file": "reader-independent-domain-r2.md", + "original_sha256": "228a039b18206d6243e29afe3cd5e5480d930cb09d186c217284d618e61819bd", + "presentation_sha256": "228a039b18206d6243e29afe3cd5e5480d930cb09d186c217284d618e61819bd", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_review", + "file": "reader-independent-domain-r2.json", + "original_sha256": "44b4697d44a5f28ca501f868e08680dfbf7614092860e87daa28c37a1fe30f82", + "presentation_sha256": "fc6364e3be49696cc517126a67f41e1452b3e0b54dfb70bc40594dc834d3cae8", + "changed": true, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_review", + "file": "reader-independent-domain-final.md", + "original_sha256": "61b9667d465d01b4ec23a9ee70fe795871a197ad2ce93f92ae69148b3e336796", + "presentation_sha256": "feb93118a9fb8b976e53d35607d3afd592444057b2eff835c2e61f158c571ce3", + "changed": true, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_review", + "file": "reader-independent-domain-final.json", + "original_sha256": "1136eaf8d3c11292354bf6f5fd7693e6638c087ec9c99eb5fe641a931c610264", + "presentation_sha256": "4d8fae4140622e27492b378f78d47766fc879fd43940942883a5daf0233e59f1", + "changed": true, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_actual_check", + "file": "reader-independent-domain-r1-granularity-clarification.json", + "original_sha256": "9d6c9b64c164a072203911b24ced32e9e32bf47a2d82a5706771934c5faa6f6a", + "presentation_sha256": "9d6c9b64c164a072203911b24ced32e9e32bf47a2d82a5706771934c5faa6f6a", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_actual_check", + "file": "reader-helper-reuse-probe-r1.json", + "original_sha256": "6221cea32fe0e60efb14ca00cdafac7d2535f373efc94d29dd953c8c521c2f93", + "presentation_sha256": "6221cea32fe0e60efb14ca00cdafac7d2535f373efc94d29dd953c8c521c2f93", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_actual_check", + "file": "reader-helper-caption-reuse-probe-r1.json", + "original_sha256": "34fa13446db8cd3264bf506baa49ee544e37713cfa57598d9db05ecfe6b774fa", + "presentation_sha256": "34fa13446db8cd3264bf506baa49ee544e37713cfa57598d9db05ecfe6b774fa", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_actual_check", + "file": "reader-independent-domain-r1-probes.txt", + "original_sha256": "c5bc1cb06352637044d694d9dcc49737862246576fba49ac0ecc481ea06dac21", + "presentation_sha256": "c5bc1cb06352637044d694d9dcc49737862246576fba49ac0ecc481ea06dac21", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_actual_check", + "file": "reader-independent-domain-r1-probes.log", + "original_sha256": "7b1f6762c8a3a910b04b32067ba975daa3ceb4a3ea45cf29ef93e6e627194fd0", + "presentation_sha256": "7b1f6762c8a3a910b04b32067ba975daa3ceb4a3ea45cf29ef93e6e627194fd0", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_actual_check", + "file": "reader-independent-domain-r1-probes-attempt1.txt", + "original_sha256": "aca48116bb1731f3e48abf43f0e292f81c39a45ddcba5cb78245d4a199d76ddf", + "presentation_sha256": "aca48116bb1731f3e48abf43f0e292f81c39a45ddcba5cb78245d4a199d76ddf", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_actual_check", + "file": "reader-independent-domain-r1-probes-attempt1.log", + "original_sha256": "74ad440eb9dce2a397b754e17193af987798b6b1fce12cd2390a581de8fc394c", + "presentation_sha256": "74ad440eb9dce2a397b754e17193af987798b6b1fce12cd2390a581de8fc394c", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_review", + "file": "reader-initial-overall.md", + "original_sha256": "016f35a6bc9670557bc70394675e1e413853969f7e597bf46d544fed9120a431", + "presentation_sha256": "016f35a6bc9670557bc70394675e1e413853969f7e597bf46d544fed9120a431", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_review", + "file": "reader-initial-overall.json", + "original_sha256": "9b3fb49a28d4e658ac6b5b9b8c89aadb82d246d04a53ba6b9e7087d6e1c8df4b", + "presentation_sha256": "9b3fb49a28d4e658ac6b5b9b8c89aadb82d246d04a53ba6b9e7087d6e1c8df4b", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_review", + "file": "reader-comparison.md", + "original_sha256": "c4e60c243ff0cfcde7debf4b2a38baaacadedc8e3a522fe89575ec350dc7c236", + "presentation_sha256": "c4e60c243ff0cfcde7debf4b2a38baaacadedc8e3a522fe89575ec350dc7c236", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_review", + "file": "reader-comparison.json", + "original_sha256": "f0dc87c1cc3b85bfce1475219b2b63a4508d8986c47fd39125dcf3b57d550368", + "presentation_sha256": "f0dc87c1cc3b85bfce1475219b2b63a4508d8986c47fd39125dcf3b57d550368", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_review", + "file": "reader-final-overall.md", + "original_sha256": "637b4b12e88b6226e944963d7ca34bbe0ab017e9cb1b113a2744e66164f0c2d3", + "presentation_sha256": "637b4b12e88b6226e944963d7ca34bbe0ab017e9cb1b113a2744e66164f0c2d3", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_review", + "file": "reader-final-overall.json", + "original_sha256": "da2c4cfe5d3c5e5a585d2c8cd96a8329927b960aff853e262fb307f0cb855d1c", + "presentation_sha256": "da2c4cfe5d3c5e5a585d2c8cd96a8329927b960aff853e262fb307f0cb855d1c", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + }, + { + "role": "reader_review", + "file": "reader-final-probes.json", + "original_sha256": "9fe82b010e045ac290ae43d471ac61ae8bb422777d3b78387b3592df93c79b84", + "presentation_sha256": "9fe82b010e045ac290ae43d471ac61ae8bb422777d3b78387b3592df93c79b84", + "changed": false, + "transformation": "Only host directory prefixes are replaced by descriptive labels. Original judgments, code and recorded hashes are retained; original bytes remain unchanged locally. Embedded references to prior snapshots are historical, not portable approval of those older objects." + } +] diff --git a/SoftwareEngineering/lean/philosophy/reviews/r3-actual-audit.log b/SoftwareEngineering/lean/philosophy/reviews/r3-actual-audit.log new file mode 100644 index 0000000..691bbe7 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/r3-actual-audit.log @@ -0,0 +1,6757 @@ +$ lake env lean --stdin +CoreReader.Adopted.AssessmentTask : Type → Type 1 +@CoreReader.Adopted.taskOfFacet : {W : Type} → CoreReader.Evidence.Facet W → CoreReader.Adopted.AssessmentTask W +@CoreReader.Adopted.NatureAppropriate : {W : Type} → + CoreReader.Adopted.AssessmentTask W → CoreReader.Evidence.Facet W → Prop +@CoreReader.Adopted.taskOfFacetAppropriate : ∀ {W : Type} (f : CoreReader.Evidence.Facet W), + @CoreReader.Adopted.NatureAppropriate W (@CoreReader.Adopted.taskOfFacet W f) f +@CoreReader.Adopted.Grounds012 : {W : Type} → + CoreReader.Logic.Claim W → + (CoreReader.Evidence.Facet W → CoreReader.Evidence.Articulation W) → + List.{1} (CoreReader.Evidence.Facet W) → CoreReader.Adopted.AssessmentTask W → Prop +@CoreReader.Adopted.grounds012Singleton : ∀ {W : Type} (f : CoreReader.Evidence.Facet W), + @CoreReader.Evidence.FacetDischarged W f → + @CoreReader.Adopted.Grounds012 W (@CoreReader.Evidence.Facet.claim W f) + (@CoreReader.Evidence.canonicalArticulation W) + (@List.cons.{1} (CoreReader.Evidence.Facet W) f (@List.nil.{1} (CoreReader.Evidence.Facet W))) + (@CoreReader.Adopted.taskOfFacet W f) +CoreReader.Adopted.generationSpecification : CoreReader.Agency.Policy → Prop +@CoreReader.Adopted.consistencySpecification : {W Q : Type} → + CoreReader.Logic.Snapshot W Q → CoreReader.Logic.Snapshot W Q → Bool → Prop +CoreReader.Adopted.ReflexiveRule : Type → Type → Type → Type +@CoreReader.Adopted.reflexivitySpecification : {T I O : Type} → + List.{0} (CoreReader.Adopted.ReflexiveRule T I O) → + (T → Prop) → (CoreReader.Agency.PrincipleKey → T → I → O → Prop) → Prop +CoreReader.Adopted.legacyRule : CoreReader.Agency.Principle → + CoreReader.Adopted.ReflexiveRule CoreReader.Agency.Subject CoreReader.Agency.Inquiry CoreReader.Agency.WorkOutcome +CoreReader.Adopted.legacyPerformed : List.{0} CoreReader.Agency.Principle → + List.{0} CoreReader.Agency.WorkRecord → + CoreReader.Agency.PrincipleKey → + CoreReader.Agency.Subject → CoreReader.Agency.Inquiry → CoreReader.Agency.WorkOutcome → Prop +CoreReader.Adopted.legacyReflexivity : ∀ (owner : Nat) (rules : List.{0} CoreReader.Agency.Principle) + (records : List.{0} CoreReader.Agency.WorkRecord), + CoreReader.Agency.Reflexive owner rules records → + @CoreReader.Adopted.reflexivitySpecification CoreReader.Agency.Subject CoreReader.Agency.Inquiry + CoreReader.Agency.WorkOutcome + (@List.map.{0, 0} CoreReader.Agency.Principle + (CoreReader.Adopted.ReflexiveRule CoreReader.Agency.Subject CoreReader.Agency.Inquiry + CoreReader.Agency.WorkOutcome) + CoreReader.Adopted.legacyRule rules) + (fun s => @Eq.{1} Nat s.owner owner) (CoreReader.Adopted.legacyPerformed rules records) +@CoreReader.Adopted.empiricalSpecification : {W : Type} → + List.{0} (CoreReader.Evidence.Record W) → + CoreReader.Logic.Claim W → CoreReader.Logic.Claim W → CoreReader.Logic.Claim W → Prop +@CoreReader.Adopted.inferentialSpecification : {W : Type} → CoreReader.Logic.Theory W → CoreReader.Logic.Claim W → Prop +@CoreReader.Adopted.valueSpecification : {W : Type} → CoreReader.Evidence.ValuePosition W → Prop +CoreReader.Adopted.AssessmentMethod : Type +CoreReader.Adopted.ScopeAccount : Type → Type +@CoreReader.Adopted.scopeSpecification : {W : Type} → CoreReader.Adopted.ScopeAccount W → Prop +CoreReader.Adopted.capabilitySpecification : CoreReader.Evidence.Process → + CoreReader.Logic.Claim CoreReader.Evidence.Process → Prop +CoreReader.Adopted.choiceSpecification : CoreReader.Choice.Requirements → + CoreReader.Choice.Implementation → List.{0} CoreReader.Choice.Reason → Prop +CoreReader.Adopted.collaborativeRevision : CoreReader.Agency.ExternalResources → CoreReader.Agency.State +CoreReader.Adopted.collaborativeProgress : And (CoreReader.Adopted.generationSpecification CoreReader.Agency.openPolicy) + (And + (CoreReader.Agency.Expanded CoreReader.Agency.baseState + (CoreReader.Adopted.collaborativeRevision CoreReader.Agency.availableResources)) + (And + (Not + (CoreReader.Agency.Expanded CoreReader.Agency.baseState + (CoreReader.Adopted.collaborativeRevision + (have __src := CoreReader.Agency.availableResources; + { experience := __src.experience, knowledge := __src.knowledge, collaborator := @Option.none.{0} Nat })))) + (@Eq.{1} (Option.{0} Nat) + (CoreReader.Agency.assistedExecution + { experience := @Option.none.{0} Nat, knowledge := @Option.none.{0} Nat, + collaborator := @Option.none.{0} Nat }) + (@Option.none.{0} Nat)))) +@CoreReader.Adopted.consistencyConsequences : ∀ {W Q : Type} (t : CoreReader.Logic.Theory W) + (c : CoreReader.Logic.Context W Q) (q : Q), + @CoreReader.Logic.Consequence W Q t c q Bool.true → + @CoreReader.Logic.Consequence W Q t c q Bool.false → Not (@CoreReader.Logic.Consistent W Q t c) +CoreReader.Adopted.broadBoolContext : CoreReader.Logic.Context Bool Unit +CoreReader.Adopted.sliceConsistency : And + (∀ (time : Nat), + @CoreReader.Logic.Consistent Bool Unit (CoreReader.Logic.revisionSlice time) CoreReader.Adopted.broadBoolContext) + (Not + (@CoreReader.Logic.Consistent Bool Unit + (@CoreReader.Logic.union Bool + (CoreReader.Logic.revisionSlice (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Logic.revisionSlice (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))))) + CoreReader.Adopted.broadBoolContext)) +CoreReader.Adopted.explicitlyConsistentLimits : And + (@CoreReader.Logic.Consistent Bool Unit (@CoreReader.Logic.singleton Bool fun w => @Eq.{1} Bool w Bool.true) + CoreReader.Adopted.broadBoolContext) + (And + (Not + (@CoreReader.Logic.Models Bool (@CoreReader.Logic.singleton Bool fun w => @Eq.{1} Bool w Bool.true) Bool.false)) + (And + (@CoreReader.Logic.Consistent Bool Unit (@CoreReader.Logic.emptyTheory Bool) CoreReader.Adopted.broadBoolContext) + (Not (@CoreReader.Logic.Entails Bool (@CoreReader.Logic.emptyTheory Bool) fun w => @Eq.{1} Bool w Bool.true)))) +CoreReader.Adopted.localFacet012 : CoreReader.Evidence.Facet (Nat → Bool) +CoreReader.Adopted.globalFacet012 : CoreReader.Evidence.Facet (Nat → Bool) +CoreReader.Adopted.strongFacet012 : CoreReader.Evidence.Facet (Nat → Bool) +CoreReader.Adopted.localFacetChecked012 : @CoreReader.Evidence.FacetDischarged (Nat → Bool) + CoreReader.Adopted.localFacet012 +CoreReader.Adopted.scopeStrength012 : And + (@CoreReader.Adopted.Grounds012 (Nat → Bool) + (@CoreReader.Evidence.Facet.claim (Nat → Bool) CoreReader.Adopted.localFacet012) + (@CoreReader.Evidence.canonicalArticulation (Nat → Bool)) + (@List.cons.{1} (CoreReader.Evidence.Facet (Nat → Bool)) CoreReader.Adopted.localFacet012 + (@List.nil.{1} (CoreReader.Evidence.Facet (Nat → Bool)))) + (@CoreReader.Adopted.taskOfFacet (Nat → Bool) CoreReader.Adopted.localFacet012)) + (And + (@CoreReader.Evidence.Articulated (Nat → Bool) + (@CoreReader.Evidence.canonicalArticulation (Nat → Bool) CoreReader.Adopted.globalFacet012)) + (And + (Not + (@CoreReader.Adopted.Grounds012 (Nat → Bool) + (@CoreReader.Evidence.Facet.claim (Nat → Bool) CoreReader.Adopted.globalFacet012) + (@CoreReader.Evidence.canonicalArticulation (Nat → Bool)) + (@List.cons.{1} (CoreReader.Evidence.Facet (Nat → Bool)) CoreReader.Adopted.globalFacet012 + (@List.nil.{1} (CoreReader.Evidence.Facet (Nat → Bool)))) + (@CoreReader.Adopted.taskOfFacet (Nat → Bool) CoreReader.Adopted.globalFacet012))) + (Not + (@CoreReader.Adopted.Grounds012 (Nat → Bool) + (@CoreReader.Evidence.Facet.claim (Nat → Bool) CoreReader.Adopted.strongFacet012) + (@CoreReader.Evidence.canonicalArticulation (Nat → Bool)) + (@List.cons.{1} (CoreReader.Evidence.Facet (Nat → Bool)) CoreReader.Adopted.strongFacet012 + (@List.nil.{1} (CoreReader.Evidence.Facet (Nat → Bool)))) + (@CoreReader.Adopted.taskOfFacet (Nat → Bool) CoreReader.Adopted.strongFacet012))))) +CoreReader.Adopted.uncertainFacet012 : CoreReader.Evidence.Facet (Prod.{0, 0} Bool Bool) +CoreReader.Adopted.uncertainSupported012 : And + (@CoreReader.Adopted.empiricalSpecification (Prod.{0, 0} Bool Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool))))) + (fun x => True) (fun w => @Eq.{1} Bool (@Prod.fst.{0, 0} Bool Bool w) Bool.true) fun w => + Or (@Eq.{1} Bool (@Prod.snd.{0, 0} Bool Bool w) Bool.true) (@Eq.{1} Bool (@Prod.snd.{0, 0} Bool Bool w) Bool.false)) + (And + (@CoreReader.Evidence.Compatible (Prod.{0, 0} Bool Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool))))) + (@Prod.mk.{0, 0} Bool Bool Bool.true Bool.true)) + (@CoreReader.Evidence.Compatible (Prod.{0, 0} Bool Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool))))) + (@Prod.mk.{0, 0} Bool Bool Bool.true Bool.false))) +@CoreReader.Adopted.InferenceExamined : {W : Type} → CoreReader.Logic.Theory W → CoreReader.Logic.Claim W → Bool → Prop +CoreReader.Adopted.inferenceChecked012 : And + (@CoreReader.Adopted.inferentialSpecification Nat + (@CoreReader.Logic.singleton Nat fun n => + @Eq.{1} Nat n (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2)))) + fun n => + @Eq.{1} Nat + (@HAdd.hAdd.{0, 0, 0} Nat Nat Nat (@instHAdd.{0} Nat instAddNat) n + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (@OfNat.ofNat.{0} Nat (nat_lit 3) (instOfNatNat (nat_lit 3)))) + (And + (@CoreReader.Adopted.InferenceExamined Bool (@CoreReader.Logic.emptyTheory Bool) (fun w => @Eq.{1} Bool w Bool.true) + Bool.false) + (And (@CoreReader.Logic.Models Bool (@CoreReader.Logic.emptyTheory Bool) Bool.false) + (Not ((fun w => @Eq.{1} Bool w Bool.true) Bool.false)))) +CoreReader.Adopted.closedPosition012 : CoreReader.Evidence.ValuePosition Bool +CoreReader.Adopted.closedCriticism012 : Not + (@CoreReader.Evidence.ValueProcedure Bool CoreReader.Adopted.closedPosition012) +CoreReader.Adopted.valueFulfilled012 : @CoreReader.Adopted.valueSpecification Bool CoreReader.Evidence.switchPosition +@CoreReader.Adopted.ClaimNoStronger : {W : Type} → CoreReader.Logic.Claim W → CoreReader.Logic.Claim W → Prop +CoreReader.Adopted.qualitativeProportionality012 : And + (@CoreReader.Adopted.ClaimNoStronger (Nat → Bool) + (fun f => @Eq.{1} Bool (f (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) Bool.true) + CoreReader.Evidence.allTrue) + (And + (Not + (@CoreReader.Adopted.ClaimNoStronger (Nat → Bool) CoreReader.Evidence.allTrue fun f => + @Eq.{1} Bool (f (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) Bool.true)) + (@CoreReader.Adopted.valueSpecification Bool CoreReader.Evidence.switchPosition)) +CoreReader.Adopted.scopeRole012 : CoreReader.Adopted.AssessmentMethod → String +CoreReader.Adopted.scopeRoleContent012 : CoreReader.Adopted.AssessmentMethod → Prop +CoreReader.Adopted.localScopeAccount012 : CoreReader.Adopted.ScopeAccount Nat +CoreReader.Adopted.scopeFulfilled012 : @CoreReader.Adopted.scopeSpecification Nat + CoreReader.Adopted.localScopeAccount012 +CoreReader.Adopted.capabilityFulfilled012 : And + (CoreReader.Adopted.capabilitySpecification CoreReader.Evidence.outputOnlyProcess CoreReader.Evidence.OutputContract) + (And + (CoreReader.Adopted.capabilitySpecification CoreReader.Evidence.explainedProcess + CoreReader.Evidence.FullProcessContract) + (And + (@Exists.{1} (CoreReader.Evidence.ExternalCertificate CoreReader.Evidence.outputOnlyProcess) fun certificate => + And + (@Ne.{1} Nat + (@CoreReader.Evidence.ExternalCertificate.assessorId CoreReader.Evidence.outputOnlyProcess certificate) + (@CoreReader.Evidence.ExternalCertificate.assessedId CoreReader.Evidence.outputOnlyProcess certificate)) + (CoreReader.Evidence.OutputContract CoreReader.Evidence.outputOnlyProcess)) + (Not (CoreReader.Evidence.ExplanationContract CoreReader.Evidence.outputOnlyProcess)))) +CoreReader.Adopted.MechanismApplication012 : Type +CoreReader.Adopted.mechanism012 : Nat → Nat → Nat +CoreReader.Adopted.UnderstandingApplication012 : CoreReader.Adopted.MechanismApplication012 → Prop +CoreReader.Adopted.explainedWithoutVariation012 : CoreReader.Adopted.MechanismApplication012 +CoreReader.Adopted.mechanismResponder012 : CoreReader.Adopted.MechanismApplication012 +CoreReader.Adopted.understandingScope012 : CoreReader.Adopted.MechanismApplication012 → + CoreReader.Logic.Theory CoreReader.Adopted.MechanismApplication012 +CoreReader.Adopted.understandingTask012 : CoreReader.Adopted.MechanismApplication012 → + CoreReader.Adopted.AssessmentTask CoreReader.Adopted.MechanismApplication012 +CoreReader.Adopted.understandingFacet012 : CoreReader.Adopted.MechanismApplication012 → + CoreReader.Evidence.Facet CoreReader.Adopted.MechanismApplication012 +CoreReader.Adopted.mechanismResponderUnderstands012 : CoreReader.Adopted.UnderstandingApplication012 + CoreReader.Adopted.mechanismResponder012 +CoreReader.Adopted.explainedWithoutVariationFails012 : Not + (CoreReader.Adopted.UnderstandingApplication012 CoreReader.Adopted.explainedWithoutVariation012) +CoreReader.Adopted.understandingApplicationCases012 : And + (@Eq.{1} CoreReader.Evidence.Process CoreReader.Adopted.explainedWithoutVariation012.process + CoreReader.Adopted.mechanismResponder012.process) + (And (CoreReader.Evidence.FullProcessContract CoreReader.Adopted.explainedWithoutVariation012.process) + (And (Not (CoreReader.Adopted.UnderstandingApplication012 CoreReader.Adopted.explainedWithoutVariation012)) + (And (CoreReader.Adopted.UnderstandingApplication012 CoreReader.Adopted.mechanismResponder012) + (And + (@CoreReader.Adopted.Grounds012 CoreReader.Adopted.MechanismApplication012 + CoreReader.Adopted.UnderstandingApplication012 + (@CoreReader.Evidence.canonicalArticulation CoreReader.Adopted.MechanismApplication012) + (@List.cons.{1} (CoreReader.Evidence.Facet CoreReader.Adopted.MechanismApplication012) + (CoreReader.Adopted.understandingFacet012 CoreReader.Adopted.mechanismResponder012) + (@List.nil.{1} (CoreReader.Evidence.Facet CoreReader.Adopted.MechanismApplication012))) + (CoreReader.Adopted.understandingTask012 CoreReader.Adopted.mechanismResponder012)) + (Not + (@CoreReader.Adopted.Grounds012 CoreReader.Adopted.MechanismApplication012 + CoreReader.Adopted.UnderstandingApplication012 + (@CoreReader.Evidence.canonicalArticulation CoreReader.Adopted.MechanismApplication012) + (@List.cons.{1} (CoreReader.Evidence.Facet CoreReader.Adopted.MechanismApplication012) + (CoreReader.Adopted.understandingFacet012 CoreReader.Adopted.explainedWithoutVariation012) + (@List.nil.{1} (CoreReader.Evidence.Facet CoreReader.Adopted.MechanismApplication012))) + (CoreReader.Adopted.understandingTask012 CoreReader.Adopted.explainedWithoutVariation012))))))) +CoreReader.Adopted.OwnCapability012 : Nat → + Nat → CoreReader.Evidence.Process → CoreReader.Logic.Claim CoreReader.Evidence.Process → Prop +CoreReader.Adopted.ownCapability012 : CoreReader.Adopted.OwnCapability012 + (@OfNat.ofNat.{0} Nat (nat_lit 7) (instOfNatNat (nat_lit 7))) + (@OfNat.ofNat.{0} Nat (nat_lit 7) (instOfNatNat (nat_lit 7))) CoreReader.Evidence.outputOnlyProcess + CoreReader.Evidence.OutputContract +CoreReader.Adopted.CompleteCharter012 : CoreReader.Integration.System → CoreReader.Integration.World → Prop +CoreReader.Adopted.completeCharter012 : CoreReader.Adopted.CompleteCharter012 CoreReader.Integration.actualSystem + CoreReader.Integration.actual +CoreReader.Adopted.charterWithoutGrounds012 : And + (CoreReader.Adopted.CompleteCharter012 CoreReader.Integration.actualSystem CoreReader.Integration.actual) + (And + (@CoreReader.Logic.Admissible CoreReader.Integration.World CoreReader.Integration.Question + CoreReader.Integration.held CoreReader.Integration.context CoreReader.Integration.actual) + (And + (@CoreReader.Evidence.Compatible CoreReader.Integration.World + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Integration.World) + CoreReader.Integration.costAllowanceRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Integration.World))) + CoreReader.Integration.actual) + (And + (@CoreReader.Evidence.Articulated CoreReader.Integration.World + (@CoreReader.Evidence.canonicalArticulation CoreReader.Integration.World + CoreReader.Integration.unsupportedCapabilityFacet)) + (And + (Not + (@CoreReader.Evidence.Supports CoreReader.Integration.World + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Integration.World) + CoreReader.Integration.costAllowanceRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Integration.World))) + CoreReader.Integration.capability)) + (Not + (@CoreReader.Adopted.Grounds012 CoreReader.Integration.World CoreReader.Integration.capability + (@CoreReader.Evidence.canonicalArticulation CoreReader.Integration.World) + (@List.cons.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World) + CoreReader.Integration.unsupportedCapabilityFacet + (@List.nil.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World))) + (@CoreReader.Adopted.taskOfFacet CoreReader.Integration.World + CoreReader.Integration.unsupportedCapabilityFacet))))))) +@CoreReader.Adopted.groundsPermission012 : {W : Type} → + Bool → + CoreReader.Logic.Claim W → + (CoreReader.Evidence.Facet W → CoreReader.Evidence.Articulation W) → + List.{1} (CoreReader.Evidence.Facet W) → CoreReader.Adopted.AssessmentTask W → Prop +CoreReader.Adopted.GroundsProvision012 : Bool → Prop +CoreReader.Adopted.groundsProvision012Meaning : ∀ (enabled : Bool), + Iff (CoreReader.Adopted.GroundsProvision012 enabled) (@Eq.{1} Bool enabled Bool.true) +CoreReader.Adopted.groundsExperimentTask012 : CoreReader.Adopted.AssessmentTask (Nat → Bool) +CoreReader.Adopted.groundsExperiment012 : Bool → Bool +CoreReader.Adopted.groundsPosition012 : CoreReader.Evidence.ValuePosition Bool +CoreReader.Adopted.groundsPosition012Checked : @CoreReader.Evidence.ValueProcedure Bool + CoreReader.Adopted.groundsPosition012 +CoreReader.Adopted.groundsRationaleExperiment012 : And + (@CoreReader.Evidence.Compatible (Nat → Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Nat → Bool)) CoreReader.Evidence.zeroRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Nat → Bool)))) + (CoreReader.Evidence.localGenerator (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))))) + (And + (Not + (CoreReader.Evidence.allTrue + (CoreReader.Evidence.localGenerator (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))))) + (And (@Eq.{1} Bool (CoreReader.Adopted.groundsExperiment012 Bool.true) Bool.false) + (And (@Eq.{1} Bool (CoreReader.Adopted.groundsExperiment012 Bool.false) Bool.true) + (And + (@Eq.{1} (@CoreReader.Evidence.ValuePosition.Outcome Bool CoreReader.Adopted.groundsPosition012) + (@CoreReader.Evidence.ValuePosition.outcome Bool CoreReader.Adopted.groundsPosition012 Bool.true Bool.true) + (CoreReader.Adopted.groundsExperiment012 Bool.true)) + (@Eq.{1} (@CoreReader.Evidence.ValuePosition.Outcome Bool CoreReader.Adopted.groundsPosition012) + (@CoreReader.Evidence.ValuePosition.outcome Bool CoreReader.Adopted.groundsPosition012 Bool.true Bool.false) + (CoreReader.Adopted.groundsExperiment012 Bool.false)))))) +CoreReader.Adopted.groundsOnGrounds012 : And + (@CoreReader.Adopted.Grounds012 Bool (fun enabled => CoreReader.Adopted.GroundsProvision012 enabled) + (@CoreReader.Evidence.canonicalArticulation Bool) + (@List.cons.{1} (CoreReader.Evidence.Facet Bool) + (@CoreReader.Evidence.Facet.value Bool CoreReader.Adopted.groundsPosition012) + (@List.nil.{1} (CoreReader.Evidence.Facet Bool))) + (@CoreReader.Adopted.AssessmentTask.value Bool CoreReader.Adopted.groundsPosition012)) + (And (@CoreReader.Evidence.ValuePosition.limits Bool CoreReader.Adopted.groundsPosition012 Bool.true) + (@CoreReader.Evidence.ValuePosition.relevantCriticism Bool CoreReader.Adopted.groundsPosition012 Bool.true)) +CoreReader.Adopted.reflexiveTargets012 : And + (@CoreReader.Adopted.reflexivitySpecification CoreReader.Agency.Subject CoreReader.Agency.Inquiry + CoreReader.Agency.WorkOutcome + (@List.map.{0, 0} CoreReader.Agency.Principle + (CoreReader.Adopted.ReflexiveRule CoreReader.Agency.Subject CoreReader.Agency.Inquiry + CoreReader.Agency.WorkOutcome) + CoreReader.Adopted.legacyRule + (CoreReader.Agency.ownRules (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))))) + (fun s => @Eq.{1} Nat s.owner (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Adopted.legacyPerformed + (CoreReader.Agency.ownRules (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Agency.completeOwnWork (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))))) + (And + (∀ (phase : CoreReader.Agency.Phase), + CoreReader.Agency.Performed + (CoreReader.Agency.completeOwnWork (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Agency.Subject.process (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) phase) + CoreReader.Agency.Activity.assessment) + (And + (CoreReader.Agency.Performed + (CoreReader.Agency.completeOwnWork (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Agency.Subject.system (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + CoreReader.Agency.Activity.assessment) + (And + (@CoreReader.Adopted.reflexivitySpecification CoreReader.Agency.Subject CoreReader.Agency.Inquiry + CoreReader.Agency.WorkOutcome + (@List.map.{0, 0} CoreReader.Agency.Principle + (CoreReader.Adopted.ReflexiveRule CoreReader.Agency.Subject CoreReader.Agency.Inquiry + CoreReader.Agency.WorkOutcome) + CoreReader.Adopted.legacyRule + (@List.cons.{0} CoreReader.Agency.Principle CoreReader.Agency.applicationRule + (@List.nil.{0} CoreReader.Agency.Principle))) + (fun s => @Eq.{1} Nat s.owner (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Adopted.legacyPerformed + (@List.cons.{0} CoreReader.Agency.Principle CoreReader.Agency.applicationRule + (@List.nil.{0} CoreReader.Agency.Principle)) + CoreReader.Agency.applicationWork)) + (Not + (CoreReader.Agency.Performed CoreReader.Agency.applicationWork + (CoreReader.Agency.Subject.system (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + CoreReader.Agency.Activity.assessment))))) +CoreReader.Adopted.achievementSupported012 : And + (@CoreReader.Adopted.Grounds012 CoreReader.Agency.TransitionCase CoreReader.Evidence.transitionAchievement + (@CoreReader.Evidence.canonicalArticulation CoreReader.Agency.TransitionCase) + (@List.cons.{1} (CoreReader.Evidence.Facet CoreReader.Agency.TransitionCase) CoreReader.Evidence.transitionFacet + (@List.nil.{1} (CoreReader.Evidence.Facet CoreReader.Agency.TransitionCase))) + (@CoreReader.Adopted.taskOfFacet CoreReader.Agency.TransitionCase CoreReader.Evidence.transitionFacet)) + (And + (@CoreReader.Evidence.Compatible CoreReader.Agency.TransitionCase + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Agency.TransitionCase) + CoreReader.Evidence.transitionPerformanceRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Agency.TransitionCase))) + CoreReader.Agency.TransitionCase.extend) + (And (CoreReader.Evidence.transitionAchievement CoreReader.Agency.TransitionCase.extend) + (And (Not (CoreReader.Evidence.transitionAchievement CoreReader.Agency.TransitionCase.inflate)) + (Not + (@CoreReader.Evidence.Supports CoreReader.Agency.TransitionCase + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Agency.TransitionCase) + CoreReader.Evidence.transitionReportRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Agency.TransitionCase))) + CoreReader.Evidence.transitionAchievement))))) +CoreReader.Adopted.semanticOrder012 : ∀ (p q r : CoreReader.Logic.Claim Bool), + Iff (@CoreReader.Logic.union Bool (@CoreReader.Logic.singleton Bool p) (@CoreReader.Logic.singleton Bool q) r) + (@CoreReader.Logic.union Bool (@CoreReader.Logic.singleton Bool q) (@CoreReader.Logic.singleton Bool p) r) +CoreReader.Adopted.clearFalseArgument012 : CoreReader.Evidence.Articulation Bool +CoreReader.Adopted.clearFalseReason012 : And + (@CoreReader.Evidence.Articulated Bool CoreReader.Adopted.clearFalseArgument012) + (Not + (@CoreReader.Logic.Models Bool + (@CoreReader.Evidence.Articulation.assumptions Bool CoreReader.Adopted.clearFalseArgument012) Bool.false)) +CoreReader.Adopted.valueNeutralRecord012 : CoreReader.Evidence.Record Bool +CoreReader.Adopted.valueNotFact012 : And + (@CoreReader.Adopted.valueSpecification Bool CoreReader.Evidence.switchPosition) + (And + (@CoreReader.Evidence.Compatible Bool + (@List.cons.{0} (CoreReader.Evidence.Record Bool) CoreReader.Adopted.valueNeutralRecord012 + (@List.nil.{0} (CoreReader.Evidence.Record Bool))) + Bool.false) + (And + (Not + (@CoreReader.Evidence.Supports Bool + (@List.cons.{0} (CoreReader.Evidence.Record Bool) CoreReader.Adopted.valueNeutralRecord012 + (@List.nil.{0} (CoreReader.Evidence.Record Bool))) + (@CoreReader.Evidence.ValuePosition.commitment Bool CoreReader.Evidence.switchPosition))) + (Not + (@CoreReader.Logic.Entails Bool (@CoreReader.Logic.emptyTheory Bool) + (@CoreReader.Evidence.ValuePosition.commitment Bool CoreReader.Evidence.switchPosition))))) +CoreReader.Adopted.wrongExplanation012 : CoreReader.Choice.Implementation +CoreReader.Adopted.internalReasonDistinguishes012 : And + (∀ (n : Nat), @Eq.{1} Nat (CoreReader.Choice.identityImpl.run n) (CoreReader.Adopted.wrongExplanation012.run n)) + (And (CoreReader.Choice.Feasible CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl) + (And (CoreReader.Choice.Feasible CoreReader.Choice.identityRequirements CoreReader.Adopted.wrongExplanation012) + (And + (CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.explanation)) + (Not + (CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements CoreReader.Adopted.wrongExplanation012 + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.explanation)))))) +CoreReader.Adopted.inventoryCases012 : ∀ (kind : CoreReader.Agency.InventoryKind), + And + (CoreReader.Agency.Available + (@List.cons.{0} CoreReader.Agency.Item { kind := kind, content := CoreReader.Agency.Operation.copy } + (@List.cons.{0} CoreReader.Agency.Item { kind := kind, content := CoreReader.Agency.Operation.copy } + (@List.nil.{0} CoreReader.Agency.Item))) + CoreReader.Agency.Operation.copy) + (Not + (CoreReader.Agency.Available + (@List.cons.{0} CoreReader.Agency.Item { kind := kind, content := CoreReader.Agency.Operation.copy } + (@List.cons.{0} CoreReader.Agency.Item { kind := kind, content := CoreReader.Agency.Operation.copy } + (@List.nil.{0} CoreReader.Agency.Item))) + CoreReader.Agency.Operation.successor)) +CoreReader.Adopted.selfExemptRule012 : CoreReader.Adopted.ReflexiveRule Nat Nat Bool +CoreReader.Adopted.selfExemptPerformed012 : CoreReader.Agency.PrincipleKey → Nat → Nat → Bool → Prop +CoreReader.Adopted.openSelfExempt012 : And (CoreReader.Adopted.generationSpecification CoreReader.Agency.openPolicy) + (And + (CoreReader.Agency.openPolicy.revisable + { kind := CoreReader.Agency.FormKind.principle, + version := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)) }) + (And + (CoreReader.Adopted.selfExemptPerformed012 + { owner := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + localId := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)) } + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))) + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))) Bool.true) + (And + (@CoreReader.Adopted.ReflexiveRule.applicable Nat Nat Bool CoreReader.Adopted.selfExemptRule012 + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (Not + (@CoreReader.Adopted.reflexivitySpecification Nat Nat Bool + (@List.cons.{0} (CoreReader.Adopted.ReflexiveRule Nat Nat Bool) CoreReader.Adopted.selfExemptRule012 + (@List.nil.{0} (CoreReader.Adopted.ReflexiveRule Nat Nat Bool))) + (fun target => @Eq.{1} Nat target (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + CoreReader.Adopted.selfExemptPerformed012))))) +CoreReader.Adopted.ownPhilosophyStatus012 : And + (Not + (CoreReader.Adopted.choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem + CoreReader.Integration.actual).implementation + (@List.cons.{0} CoreReader.Choice.Reason (CoreReader.Choice.Reason.status CoreReader.Choice.StatusKind.standing) + (@List.nil.{0} CoreReader.Choice.Reason)))) + (CoreReader.Adopted.choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem + CoreReader.Integration.actual).implementation + (@List.cons.{0} CoreReader.Choice.Reason (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.output) + (@List.nil.{0} CoreReader.Choice.Reason))) +CoreReader.Adopted.jointContext012 : CoreReader.Logic.Context (Prod.{0, 0} Bool Bool) Unit +CoreReader.Adopted.jointImplicationConflict012 : And + (@CoreReader.Logic.Consequence (Prod.{0, 0} Bool Bool) Unit CoreReader.Logic.jointTheory + CoreReader.Adopted.jointContext012 Unit.unit Bool.true) + (And + (@CoreReader.Logic.Consequence (Prod.{0, 0} Bool Bool) Unit CoreReader.Logic.jointTheory + CoreReader.Adopted.jointContext012 Unit.unit Bool.false) + (Not + (@CoreReader.Logic.Consistent (Prod.{0, 0} Bool Bool) Unit CoreReader.Logic.jointTheory + CoreReader.Adopted.jointContext012))) +CoreReader.Adopted.tensionContext012 : CoreReader.Logic.Context Nat Unit +CoreReader.Adopted.tensionConsistent012 : @CoreReader.Logic.Consistent Nat Unit + (@CoreReader.Logic.union Nat + (@CoreReader.Logic.singleton Nat fun n => + @LE.le.{0} Nat instLENat (@OfNat.ofNat.{0} Nat (nat_lit 4) (instOfNatNat (nat_lit 4))) n) + (@CoreReader.Logic.singleton Nat fun n => + @LE.le.{0} Nat instLENat n (@OfNat.ofNat.{0} Nat (nat_lit 6) (instOfNatNat (nat_lit 6))))) + CoreReader.Adopted.tensionContext012 +CoreReader.Adopted.qualitativeUnmeasured012 : And + (@CoreReader.Adopted.inferentialSpecification Bool + (@CoreReader.Logic.singleton Bool fun on => @Eq.{1} Bool on Bool.true) fun on => @Ne.{1} Bool on Bool.false) + (@Eq.{1} Bool + (@CoreReader.Evidence.usesObservation Bool + (@CoreReader.Evidence.Facet.inferential Bool + (@CoreReader.Logic.singleton Bool fun on => @Eq.{1} Bool on Bool.true) fun on => @Ne.{1} Bool on Bool.false)) + Bool.false) +CoreReader.Adopted.allStatusOnly012 : ∀ (kind : CoreReader.Choice.StatusKind), + Not + (CoreReader.Adopted.choiceSpecification CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + (@List.cons.{0} CoreReader.Choice.Reason (CoreReader.Choice.Reason.status kind) + (@List.nil.{0} CoreReader.Choice.Reason))) +CoreReader.Adopted.drawWeight012 : Bool → Nat +CoreReader.Adopted.randomTrial012 : Bool → CoreReader.Evidence.Trial +CoreReader.Adopted.randomOutcomes012 : And + (@GT.gt.{0} Nat instLTNat (CoreReader.Adopted.drawWeight012 Bool.true) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (And + (@GT.gt.{0} Nat instLTNat (CoreReader.Adopted.drawWeight012 Bool.false) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (And (@Eq.{1} Nat (CoreReader.Adopted.drawWeight012 Bool.true) (CoreReader.Adopted.drawWeight012 Bool.false)) + (And + (CoreReader.Evidence.Reproduced (CoreReader.Adopted.randomTrial012 Bool.true) + (CoreReader.Adopted.randomTrial012 Bool.false)) + (And + (@Ne.{1} Nat (CoreReader.Adopted.randomTrial012 Bool.true).actualOutcome + (CoreReader.Adopted.randomTrial012 Bool.false).actualOutcome) + (∀ (draw : Bool), + And (CoreReader.Evidence.Verified (CoreReader.Adopted.randomTrial012 draw)) + (CoreReader.Evidence.Bounded (CoreReader.Adopted.randomTrial012 draw))))))) +CoreReader.Adopted.originalGlobalTask012 : CoreReader.Adopted.AssessmentTask (Nat → Bool) +CoreReader.Adopted.originalLocalTask012 : CoreReader.Adopted.AssessmentTask (Nat → Bool) +CoreReader.Adopted.circularGlobalFacet012 : CoreReader.Evidence.Facet (Nat → Bool) +CoreReader.Adopted.circularGlobalConditional012 : @CoreReader.Evidence.FacetDischarged (Nat → Bool) + CoreReader.Adopted.circularGlobalFacet012 +CoreReader.Adopted.circularSubstitutionRejected012 : And + (@CoreReader.Adopted.Grounds012 (Nat → Bool) CoreReader.Evidence.allTrue + (@CoreReader.Evidence.canonicalArticulation (Nat → Bool)) + (@List.cons.{1} (CoreReader.Evidence.Facet (Nat → Bool)) CoreReader.Adopted.circularGlobalFacet012 + (@List.nil.{1} (CoreReader.Evidence.Facet (Nat → Bool)))) + (@CoreReader.Adopted.taskOfFacet (Nat → Bool) CoreReader.Adopted.circularGlobalFacet012)) + (And + (Not + (@CoreReader.Adopted.NatureAppropriate (Nat → Bool) CoreReader.Adopted.originalGlobalTask012 + CoreReader.Adopted.circularGlobalFacet012)) + (Not + (@CoreReader.Adopted.Grounds012 (Nat → Bool) CoreReader.Evidence.allTrue + (@CoreReader.Evidence.canonicalArticulation (Nat → Bool)) + (@List.cons.{1} (CoreReader.Evidence.Facet (Nat → Bool)) CoreReader.Adopted.circularGlobalFacet012 + (@List.nil.{1} (CoreReader.Evidence.Facet (Nat → Bool)))) + CoreReader.Adopted.originalGlobalTask012))) +CoreReader.Adopted.observedPremises012 : CoreReader.Logic.Theory (Nat → Bool) +CoreReader.Adopted.observedInferenceFacet012 : CoreReader.Evidence.Facet (Nat → Bool) +CoreReader.Adopted.observedInferenceChecked012 : @CoreReader.Evidence.FacetDischarged (Nat → Bool) + CoreReader.Adopted.observedInferenceFacet012 +CoreReader.Adopted.sameEmpiricalTaskTwoMethods012 : And + (@CoreReader.Adopted.Grounds012 (Nat → Bool) + (fun f => @Eq.{1} Bool (f (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) Bool.true) + (@CoreReader.Evidence.canonicalArticulation (Nat → Bool)) + (@List.cons.{1} (CoreReader.Evidence.Facet (Nat → Bool)) CoreReader.Adopted.localFacet012 + (@List.nil.{1} (CoreReader.Evidence.Facet (Nat → Bool)))) + CoreReader.Adopted.originalLocalTask012) + (@CoreReader.Adopted.Grounds012 (Nat → Bool) + (fun f => @Eq.{1} Bool (f (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) Bool.true) + (@CoreReader.Evidence.canonicalArticulation (Nat → Bool)) + (@List.cons.{1} (CoreReader.Evidence.Facet (Nat → Bool)) CoreReader.Adopted.observedInferenceFacet012 + (@List.nil.{1} (CoreReader.Evidence.Facet (Nat → Bool)))) + CoreReader.Adopted.originalLocalTask012) +CoreReader.Adopted.originalUncertaintyTask012 : CoreReader.Adopted.AssessmentTask (Prod.{0, 0} Bool Bool) +CoreReader.Adopted.uncertaintyBypassFacet012 : CoreReader.Evidence.Facet (Prod.{0, 0} Bool Bool) +CoreReader.Adopted.uncertaintyBypassChecked012 : @CoreReader.Evidence.FacetDischarged (Prod.{0, 0} Bool Bool) + CoreReader.Adopted.uncertaintyBypassFacet012 +CoreReader.Adopted.uncertaintySubstitutionRejected012 : And + (@CoreReader.Evidence.FacetDischarged (Prod.{0, 0} Bool Bool) CoreReader.Adopted.uncertaintyBypassFacet012) + (And + (Not + (@CoreReader.Adopted.NatureAppropriate (Prod.{0, 0} Bool Bool) CoreReader.Adopted.originalUncertaintyTask012 + CoreReader.Adopted.uncertaintyBypassFacet012)) + (Not + (@CoreReader.Adopted.Grounds012 (Prod.{0, 0} Bool Bool) + (fun w => @Eq.{1} Bool (@Prod.fst.{0, 0} Bool Bool w) Bool.true) + (@CoreReader.Evidence.canonicalArticulation (Prod.{0, 0} Bool Bool)) + (@List.cons.{1} (CoreReader.Evidence.Facet (Prod.{0, 0} Bool Bool)) CoreReader.Adopted.uncertaintyBypassFacet012 + (@List.nil.{1} (CoreReader.Evidence.Facet (Prod.{0, 0} Bool Bool)))) + CoreReader.Adopted.originalUncertaintyTask012))) +CoreReader.Adopted.selectedFactFacet012 : CoreReader.Evidence.Facet Bool +CoreReader.Adopted.valueFactSubstitutionRejected012 : And + (@CoreReader.Evidence.FacetDischarged Bool CoreReader.Adopted.selectedFactFacet012) + (And (@CoreReader.Adopted.valueSpecification Bool CoreReader.Evidence.switchPosition) + (Not + (@CoreReader.Adopted.Grounds012 Bool + (@CoreReader.Evidence.ValuePosition.commitment Bool CoreReader.Evidence.switchPosition) + (@CoreReader.Evidence.canonicalArticulation Bool) + (@List.cons.{1} (CoreReader.Evidence.Facet Bool) CoreReader.Adopted.selectedFactFacet012 + (@List.nil.{1} (CoreReader.Evidence.Facet Bool))) + (@CoreReader.Adopted.AssessmentTask.value Bool CoreReader.Evidence.switchPosition)))) +CoreReader.Adopted.inferentialContextSubstitutionRejected012 : And + (@CoreReader.Evidence.FacetDischarged Bool + (@CoreReader.Evidence.Facet.inferential Bool (@CoreReader.Logic.singleton Bool fun w => @Eq.{1} Bool w Bool.true) + fun w => @Eq.{1} Bool w Bool.true)) + (Not + (@CoreReader.Adopted.Grounds012 Bool (fun w => @Eq.{1} Bool w Bool.true) + (@CoreReader.Evidence.canonicalArticulation Bool) + (@List.cons.{1} (CoreReader.Evidence.Facet Bool) + (@CoreReader.Evidence.Facet.inferential Bool + (@CoreReader.Logic.singleton Bool fun w => @Eq.{1} Bool w Bool.true) fun w => @Eq.{1} Bool w Bool.true) + (@List.nil.{1} (CoreReader.Evidence.Facet Bool))) + (@CoreReader.Adopted.AssessmentTask.inferential Bool (@CoreReader.Logic.emptyTheory Bool) fun w => + @Eq.{1} Bool w Bool.true))) +CoreReader.Adopted.generationCases : And + (And (CoreReader.Agency.Generative CoreReader.Agency.openPolicy) + (And + (∀ (k : CoreReader.Agency.FormKind), + CoreReader.Agency.openPolicy.revisable + { kind := k, version := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)) }) + (∀ (t : Nat), + Not + (CoreReader.Agency.Expanded (CoreReader.Agency.stableTrace t) + (CoreReader.Agency.stableTrace + (@HAdd.hAdd.{0, 0, 0} Nat Nat Nat (@instHAdd.{0} Nat instAddNat) t + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))))))))) + (And + (And + (CoreReader.Agency.neutralPolicy.permitsVersion (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (And + (@Ne.{1} Nat (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (Not (CoreReader.Agency.Generative CoreReader.Agency.neutralPolicy)))) + (And + (And (CoreReader.Agency.Generative CoreReader.Agency.generatingSystem.policy) + (And + (CoreReader.Agency.generatingSystem.policy.permitsVersion + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (And + (Not + (CoreReader.Agency.Expanded CoreReader.Agency.generatingSystem.current CoreReader.Agency.inflatedState)) + (And + (@LT.lt.{0} Nat instLTNat + (@List.length.{0} CoreReader.Agency.Item CoreReader.Agency.generatingSystem.current.inventory) + (@List.length.{0} CoreReader.Agency.Item CoreReader.Agency.inflatedState.inventory)) + (And + (@LT.lt.{0} Nat instLTNat + (@List.length.{0} CoreReader.Agency.Operation + CoreReader.Agency.generatingSystem.current.abstractionLayers) + (@List.length.{0} CoreReader.Agency.Operation CoreReader.Agency.inflatedState.abstractionLayers)) + (And + (@LT.lt.{0} Nat instLTNat + (@List.length.{0} CoreReader.Agency.Operation CoreReader.Agency.generatingSystem.current.vocabulary) + (@List.length.{0} CoreReader.Agency.Operation CoreReader.Agency.inflatedState.vocabulary)) + (And + (@Eq.{1} (Option.{0} Nat) + (CoreReader.Agency.generatingSystem.execute CoreReader.Agency.availableResources) + (@Option.some.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 6) (instOfNatNat (nat_lit 6))))) + (And + (@Eq.{1} (Option.{0} Nat) + (CoreReader.Agency.generatingSystem.execute + (have __src := CoreReader.Agency.availableResources; + { experience := @Option.none.{0} Nat, knowledge := __src.knowledge, + collaborator := __src.collaborator })) + (@Option.none.{0} Nat)) + (And + (@Eq.{1} (Option.{0} Nat) + (CoreReader.Agency.generatingSystem.execute + (have __src := CoreReader.Agency.availableResources; + { experience := __src.experience, knowledge := @Option.none.{0} Nat, + collaborator := __src.collaborator })) + (@Option.none.{0} Nat)) + (And + (@Eq.{1} (Option.{0} Nat) + (CoreReader.Agency.generatingSystem.execute + (have __src := CoreReader.Agency.availableResources; + { experience := __src.experience, knowledge := __src.knowledge, + collaborator := @Option.none.{0} Nat })) + (@Option.none.{0} Nat)) + (And + (@Eq.{1} (Option.{0} Nat) + (CoreReader.Agency.generatingSystem.execute + { experience := @Option.none.{0} Nat, knowledge := @Option.none.{0} Nat, + collaborator := @Option.none.{0} Nat }) + (@Option.none.{0} Nat)) + (And + (Not + (CoreReader.Agency.Expanded CoreReader.Agency.generatingSystem.current + CoreReader.Agency.generatingSystem.stableAction)) + (And + (@Eq.{1} CoreReader.Agency.State CoreReader.Agency.generatingSystem.stableAction + CoreReader.Agency.generatingSystem.current) + (And + (CoreReader.Agency.generatingSystem.requirementsMet + CoreReader.Agency.generatingSystem.stableAction) + (And + (CoreReader.Agency.generatingSystem.withinBudget + CoreReader.Agency.generatingSystem.stableAction) + (And + (Not + (CoreReader.Agency.generatingSystem.withinBudget + CoreReader.Agency.inflatedState)) + (And + (CoreReader.Agency.StableReason CoreReader.Agency.generatingSystem.current + CoreReader.Agency.inflatedState) + (And + (@Eq.{1} CoreReader.Agency.Announcement CoreReader.Agency.inflatedAnnouncement + (CoreReader.Agency.generatingSystem.report CoreReader.Agency.inflatedState + CoreReader.Agency.Operation.successor + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))))) + (And + (@Eq.{1} Nat CoreReader.Agency.inflatedAnnouncement.owner + CoreReader.Agency.generatingSystem.owner) + (And + (@Eq.{1} CoreReader.Agency.State + CoreReader.Agency.inflatedAnnouncement.before + CoreReader.Agency.generatingSystem.current) + (And + (@Eq.{1} CoreReader.Agency.State + CoreReader.Agency.inflatedAnnouncement.after + CoreReader.Agency.inflatedState) + (And + (@Eq.{1} CoreReader.Agency.Operation + CoreReader.Agency.inflatedAnnouncement.reportedNewOperation + CoreReader.Agency.Operation.successor) + (And + (@Eq.{1} Nat CoreReader.Agency.inflatedAnnouncement.input + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (And + (@Eq.{1} Nat CoreReader.Agency.inflatedAnnouncement.expectedOutput + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (And (Not CoreReader.Agency.inflatedAnnouncement.claim) + (Not + (CoreReader.Agency.Expanded + CoreReader.Agency.inflatedAnnouncement.before + CoreReader.Agency.inflatedAnnouncement.after))))))))))))))))))))))))))) + (And (CoreReader.Adopted.generationSpecification CoreReader.Agency.openPolicy) + (And + (CoreReader.Agency.Expanded CoreReader.Agency.baseState + (CoreReader.Adopted.collaborativeRevision CoreReader.Agency.availableResources)) + (And + (Not + (CoreReader.Agency.Expanded CoreReader.Agency.baseState + (CoreReader.Adopted.collaborativeRevision + (have __src := CoreReader.Agency.availableResources; + { experience := __src.experience, knowledge := __src.knowledge, + collaborator := @Option.none.{0} Nat })))) + (@Eq.{1} (Option.{0} Nat) + (CoreReader.Agency.assistedExecution + { experience := @Option.none.{0} Nat, knowledge := @Option.none.{0} Nat, + collaborator := @Option.none.{0} Nat }) + (@Option.none.{0} Nat))))))) +CoreReader.Adopted.generationLimits012 : And + (And + (CoreReader.Agency.neutralPolicy.permitsVersion (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (And + (@Ne.{1} Nat (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (Not (CoreReader.Agency.Generative CoreReader.Agency.neutralPolicy)))) + (And + (And (CoreReader.Agency.Generative CoreReader.Agency.openPolicy) + (And + (∀ (k : CoreReader.Agency.FormKind), + CoreReader.Agency.openPolicy.revisable + { kind := k, version := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)) }) + (∀ (t : Nat), + Not + (CoreReader.Agency.Expanded (CoreReader.Agency.stableTrace t) + (CoreReader.Agency.stableTrace + (@HAdd.hAdd.{0, 0, 0} Nat Nat Nat (@instHAdd.{0} Nat instAddNat) t + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))))))))) + (And + (And (CoreReader.Agency.Generative CoreReader.Agency.generatingSystem.policy) + (And + (CoreReader.Agency.generatingSystem.policy.permitsVersion + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (And + (Not + (CoreReader.Agency.Expanded CoreReader.Agency.generatingSystem.current CoreReader.Agency.inflatedState)) + (And + (@LT.lt.{0} Nat instLTNat + (@List.length.{0} CoreReader.Agency.Item CoreReader.Agency.generatingSystem.current.inventory) + (@List.length.{0} CoreReader.Agency.Item CoreReader.Agency.inflatedState.inventory)) + (And + (@LT.lt.{0} Nat instLTNat + (@List.length.{0} CoreReader.Agency.Operation + CoreReader.Agency.generatingSystem.current.abstractionLayers) + (@List.length.{0} CoreReader.Agency.Operation CoreReader.Agency.inflatedState.abstractionLayers)) + (And + (@LT.lt.{0} Nat instLTNat + (@List.length.{0} CoreReader.Agency.Operation CoreReader.Agency.generatingSystem.current.vocabulary) + (@List.length.{0} CoreReader.Agency.Operation CoreReader.Agency.inflatedState.vocabulary)) + (And + (@Eq.{1} (Option.{0} Nat) + (CoreReader.Agency.generatingSystem.execute CoreReader.Agency.availableResources) + (@Option.some.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 6) (instOfNatNat (nat_lit 6))))) + (And + (@Eq.{1} (Option.{0} Nat) + (CoreReader.Agency.generatingSystem.execute + (have __src := CoreReader.Agency.availableResources; + { experience := @Option.none.{0} Nat, knowledge := __src.knowledge, + collaborator := __src.collaborator })) + (@Option.none.{0} Nat)) + (And + (@Eq.{1} (Option.{0} Nat) + (CoreReader.Agency.generatingSystem.execute + (have __src := CoreReader.Agency.availableResources; + { experience := __src.experience, knowledge := @Option.none.{0} Nat, + collaborator := __src.collaborator })) + (@Option.none.{0} Nat)) + (And + (@Eq.{1} (Option.{0} Nat) + (CoreReader.Agency.generatingSystem.execute + (have __src := CoreReader.Agency.availableResources; + { experience := __src.experience, knowledge := __src.knowledge, + collaborator := @Option.none.{0} Nat })) + (@Option.none.{0} Nat)) + (And + (@Eq.{1} (Option.{0} Nat) + (CoreReader.Agency.generatingSystem.execute + { experience := @Option.none.{0} Nat, knowledge := @Option.none.{0} Nat, + collaborator := @Option.none.{0} Nat }) + (@Option.none.{0} Nat)) + (And + (Not + (CoreReader.Agency.Expanded CoreReader.Agency.generatingSystem.current + CoreReader.Agency.generatingSystem.stableAction)) + (And + (@Eq.{1} CoreReader.Agency.State CoreReader.Agency.generatingSystem.stableAction + CoreReader.Agency.generatingSystem.current) + (And + (CoreReader.Agency.generatingSystem.requirementsMet + CoreReader.Agency.generatingSystem.stableAction) + (And + (CoreReader.Agency.generatingSystem.withinBudget + CoreReader.Agency.generatingSystem.stableAction) + (And + (Not + (CoreReader.Agency.generatingSystem.withinBudget + CoreReader.Agency.inflatedState)) + (And + (CoreReader.Agency.StableReason CoreReader.Agency.generatingSystem.current + CoreReader.Agency.inflatedState) + (And + (@Eq.{1} CoreReader.Agency.Announcement CoreReader.Agency.inflatedAnnouncement + (CoreReader.Agency.generatingSystem.report CoreReader.Agency.inflatedState + CoreReader.Agency.Operation.successor + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))))) + (And + (@Eq.{1} Nat CoreReader.Agency.inflatedAnnouncement.owner + CoreReader.Agency.generatingSystem.owner) + (And + (@Eq.{1} CoreReader.Agency.State + CoreReader.Agency.inflatedAnnouncement.before + CoreReader.Agency.generatingSystem.current) + (And + (@Eq.{1} CoreReader.Agency.State + CoreReader.Agency.inflatedAnnouncement.after + CoreReader.Agency.inflatedState) + (And + (@Eq.{1} CoreReader.Agency.Operation + CoreReader.Agency.inflatedAnnouncement.reportedNewOperation + CoreReader.Agency.Operation.successor) + (And + (@Eq.{1} Nat CoreReader.Agency.inflatedAnnouncement.input + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (And + (@Eq.{1} Nat CoreReader.Agency.inflatedAnnouncement.expectedOutput + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (And (Not CoreReader.Agency.inflatedAnnouncement.claim) + (Not + (CoreReader.Agency.Expanded + CoreReader.Agency.inflatedAnnouncement.before + CoreReader.Agency.inflatedAnnouncement.after))))))))))))))))))))))))))) + (And + (And (CoreReader.Adopted.generationSpecification CoreReader.Agency.openPolicy) + (And + (CoreReader.Agency.Expanded CoreReader.Agency.baseState + (CoreReader.Adopted.collaborativeRevision CoreReader.Agency.availableResources)) + (And + (Not + (CoreReader.Agency.Expanded CoreReader.Agency.baseState + (CoreReader.Adopted.collaborativeRevision + (have __src := CoreReader.Agency.availableResources; + { experience := __src.experience, knowledge := __src.knowledge, + collaborator := @Option.none.{0} Nat })))) + (@Eq.{1} (Option.{0} Nat) + (CoreReader.Agency.assistedExecution + { experience := @Option.none.{0} Nat, knowledge := @Option.none.{0} Nat, + collaborator := @Option.none.{0} Nat }) + (@Option.none.{0} Nat))))) + (And + (And + (@CoreReader.Adopted.Grounds012 CoreReader.Agency.TransitionCase CoreReader.Evidence.transitionAchievement + (@CoreReader.Evidence.canonicalArticulation CoreReader.Agency.TransitionCase) + (@List.cons.{1} (CoreReader.Evidence.Facet CoreReader.Agency.TransitionCase) + CoreReader.Evidence.transitionFacet + (@List.nil.{1} (CoreReader.Evidence.Facet CoreReader.Agency.TransitionCase))) + (@CoreReader.Adopted.taskOfFacet CoreReader.Agency.TransitionCase CoreReader.Evidence.transitionFacet)) + (And + (@CoreReader.Evidence.Compatible CoreReader.Agency.TransitionCase + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Agency.TransitionCase) + CoreReader.Evidence.transitionPerformanceRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Agency.TransitionCase))) + CoreReader.Agency.TransitionCase.extend) + (And (CoreReader.Evidence.transitionAchievement CoreReader.Agency.TransitionCase.extend) + (And (Not (CoreReader.Evidence.transitionAchievement CoreReader.Agency.TransitionCase.inflate)) + (Not + (@CoreReader.Evidence.Supports CoreReader.Agency.TransitionCase + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Agency.TransitionCase) + CoreReader.Evidence.transitionReportRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Agency.TransitionCase))) + CoreReader.Evidence.transitionAchievement)))))) + (∀ (kind : CoreReader.Agency.InventoryKind), + And + (CoreReader.Agency.Available + (@List.cons.{0} CoreReader.Agency.Item { kind := kind, content := CoreReader.Agency.Operation.copy } + (@List.cons.{0} CoreReader.Agency.Item { kind := kind, content := CoreReader.Agency.Operation.copy } + (@List.nil.{0} CoreReader.Agency.Item))) + CoreReader.Agency.Operation.copy) + (Not + (CoreReader.Agency.Available + (@List.cons.{0} CoreReader.Agency.Item { kind := kind, content := CoreReader.Agency.Operation.copy } + (@List.cons.{0} CoreReader.Agency.Item { kind := kind, content := CoreReader.Agency.Operation.copy } + (@List.nil.{0} CoreReader.Agency.Item))) + CoreReader.Agency.Operation.successor))))))) +CoreReader.Adopted.consistencyCases : And + (And + (@CoreReader.Logic.Satisfiable (Prod.{0, 0} Bool Bool) + (@CoreReader.Logic.singleton (Prod.{0, 0} Bool Bool) CoreReader.Logic.premiseP)) + (And + (@CoreReader.Logic.Satisfiable (Prod.{0, 0} Bool Bool) + (@CoreReader.Logic.singleton (Prod.{0, 0} Bool Bool) CoreReader.Logic.premiseRule)) + (And + (@CoreReader.Logic.Satisfiable (Prod.{0, 0} Bool Bool) + (@CoreReader.Logic.singleton (Prod.{0, 0} Bool Bool) CoreReader.Logic.premiseNotQ)) + (Not (@CoreReader.Logic.Satisfiable (Prod.{0, 0} Bool Bool) CoreReader.Logic.jointTheory))))) + (And + (And + (And + (@CoreReader.Logic.Consequence Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.assumptionContext Bool.true) Unit.unit Bool.true) + (@CoreReader.Logic.Consequence Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.assumptionContext Bool.false) Unit.unit Bool.false)) + (And + (And + (@CoreReader.Logic.Consequence Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.meaningContext Bool.true) Unit.unit Bool.true) + (@CoreReader.Logic.Consequence Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.meaningContext Bool.false) Unit.unit Bool.false)) + (And + (And + (@CoreReader.Logic.Consequence Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.scopeContext Bool.true) Unit.unit Bool.true) + (@CoreReader.Logic.Consequence Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.scopeContext Bool.false) Unit.unit Bool.false)) + (And + (∀ (b : Bool), + @Exists.{1} Bool fun w => + @CoreReader.Logic.Admissible Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.assumptionContext b) w) + (And + (∀ (b : Bool), + @Exists.{1} Bool fun w => + @CoreReader.Logic.Admissible Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.meaningContext b) w) + (∀ (b : Bool), + @Exists.{1} Bool fun w => + @CoreReader.Logic.Admissible Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.scopeContext b) w)))))) + (And + (And + (Not + (@CoreReader.Logic.TruthfulReport Bool Unit + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.assumptionContext Bool.true) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.assumptionContext Bool.false) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + Bool.false)) + (And + (Not + (@CoreReader.Logic.TruthfulReport Bool Unit + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.meaningContext Bool.true) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.meaningContext Bool.false) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + Bool.false)) + (And + (Not + (@CoreReader.Logic.TruthfulReport Bool Unit + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.scopeContext Bool.true) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.scopeContext Bool.false) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + Bool.false)) + (And + (Not + (@CoreReader.Logic.TruthfulReport Bool Unit + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.scopeContext Bool.true) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.scopeContext Bool.true) + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + Bool.false)) + (And + (@CoreReader.Logic.TruthfulReport Bool Unit + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.assumptionContext Bool.true) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.assumptionContext Bool.false) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + Bool.true) + (Not + (@CoreReader.Logic.Models Bool + (@CoreReader.Logic.Context.assumptions Bool Unit (CoreReader.Logic.assumptionContext Bool.false)) + Bool.true))))))) + (And + (And + (@CoreReader.Logic.Satisfiable Bool + (CoreReader.Logic.revisionSlice (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))))) + (And + (@CoreReader.Logic.Satisfiable Bool + (CoreReader.Logic.revisionSlice (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))))) + (Not + (@CoreReader.Logic.Satisfiable Bool + (@CoreReader.Logic.union Bool + (CoreReader.Logic.revisionSlice (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Logic.revisionSlice (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))))))))) + (And + (And + (∀ (time : Nat), + @CoreReader.Logic.Consistent Bool Unit (CoreReader.Logic.revisionSlice time) + CoreReader.Adopted.broadBoolContext) + (Not + (@CoreReader.Logic.Consistent Bool Unit + (@CoreReader.Logic.union Bool + (CoreReader.Logic.revisionSlice (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Logic.revisionSlice (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))))) + CoreReader.Adopted.broadBoolContext))) + (And + (∀ (p q r : CoreReader.Logic.Claim Bool), + Iff + (@CoreReader.Logic.union Bool (@CoreReader.Logic.singleton Bool p) (@CoreReader.Logic.singleton Bool q) + r) + (@CoreReader.Logic.union Bool (@CoreReader.Logic.singleton Bool q) (@CoreReader.Logic.singleton Bool p) + r)) + (And + (@CoreReader.Logic.Consequence (Prod.{0, 0} Bool Bool) Unit CoreReader.Logic.jointTheory + CoreReader.Adopted.jointContext012 Unit.unit Bool.true) + (And + (@CoreReader.Logic.Consequence (Prod.{0, 0} Bool Bool) Unit CoreReader.Logic.jointTheory + CoreReader.Adopted.jointContext012 Unit.unit Bool.false) + (Not + (@CoreReader.Logic.Consistent (Prod.{0, 0} Bool Bool) Unit CoreReader.Logic.jointTheory + CoreReader.Adopted.jointContext012))))))))) +CoreReader.Adopted.consistencyLimits012 : And + (And + (And + (@CoreReader.Logic.Consequence Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.assumptionContext Bool.true) Unit.unit Bool.true) + (@CoreReader.Logic.Consequence Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.assumptionContext Bool.false) Unit.unit Bool.false)) + (And + (And + (@CoreReader.Logic.Consequence Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.meaningContext Bool.true) Unit.unit Bool.true) + (@CoreReader.Logic.Consequence Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.meaningContext Bool.false) Unit.unit Bool.false)) + (And + (And + (@CoreReader.Logic.Consequence Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.scopeContext Bool.true) Unit.unit Bool.true) + (@CoreReader.Logic.Consequence Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.scopeContext Bool.false) Unit.unit Bool.false)) + (And + (∀ (b : Bool), + @Exists.{1} Bool fun w => + @CoreReader.Logic.Admissible Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.assumptionContext b) w) + (And + (∀ (b : Bool), + @Exists.{1} Bool fun w => + @CoreReader.Logic.Admissible Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.meaningContext b) w) + (∀ (b : Bool), + @Exists.{1} Bool fun w => + @CoreReader.Logic.Admissible Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.scopeContext b) w)))))) + (And + (And + (@Exists.{1} Nat fun budget => + And (@LE.le.{0} Nat instLENat (@OfNat.ofNat.{0} Nat (nat_lit 4) (instOfNatNat (nat_lit 4))) budget) + (@LE.le.{0} Nat instLENat budget (@OfNat.ofNat.{0} Nat (nat_lit 6) (instOfNatNat (nat_lit 6))))) + (Not + (@Eq.{1} (Nat → Prop) + (fun n => @LE.le.{0} Nat instLENat (@OfNat.ofNat.{0} Nat (nat_lit 4) (instOfNatNat (nat_lit 4))) n) fun n => + @LE.le.{0} Nat instLENat n (@OfNat.ofNat.{0} Nat (nat_lit 6) (instOfNatNat (nat_lit 6)))))) + (And + (And + (@CoreReader.Logic.Consistent Bool Unit (@CoreReader.Logic.singleton Bool fun w => @Eq.{1} Bool w Bool.true) + CoreReader.Adopted.broadBoolContext) + (And + (Not + (@CoreReader.Logic.Models Bool (@CoreReader.Logic.singleton Bool fun w => @Eq.{1} Bool w Bool.true) + Bool.false)) + (And + (@CoreReader.Logic.Consistent Bool Unit (@CoreReader.Logic.emptyTheory Bool) + CoreReader.Adopted.broadBoolContext) + (Not + (@CoreReader.Logic.Entails Bool (@CoreReader.Logic.emptyTheory Bool) fun w => + @Eq.{1} Bool w Bool.true))))) + (And + (And + (@CoreReader.Logic.Satisfiable Bool + (@CoreReader.Logic.union Bool (@CoreReader.Logic.emptyTheory Bool) + (@CoreReader.Logic.singleton Bool fun w => @Eq.{1} Bool w Bool.true))) + (Not (@CoreReader.Logic.Entails Bool (@CoreReader.Logic.emptyTheory Bool) fun w => @Eq.{1} Bool w Bool.true))) + (@CoreReader.Logic.Consistent Nat Unit + (@CoreReader.Logic.union Nat + (@CoreReader.Logic.singleton Nat fun n => + @LE.le.{0} Nat instLENat (@OfNat.ofNat.{0} Nat (nat_lit 4) (instOfNatNat (nat_lit 4))) n) + (@CoreReader.Logic.singleton Nat fun n => + @LE.le.{0} Nat instLENat n (@OfNat.ofNat.{0} Nat (nat_lit 6) (instOfNatNat (nat_lit 6))))) + CoreReader.Adopted.tensionContext012)))) +CoreReader.Adopted.reflexivityCases012 : And + (And + (@CoreReader.Adopted.reflexivitySpecification CoreReader.Agency.Subject CoreReader.Agency.Inquiry + CoreReader.Agency.WorkOutcome + (@List.map.{0, 0} CoreReader.Agency.Principle + (CoreReader.Adopted.ReflexiveRule CoreReader.Agency.Subject CoreReader.Agency.Inquiry + CoreReader.Agency.WorkOutcome) + CoreReader.Adopted.legacyRule + (CoreReader.Agency.ownRules (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))))) + (fun s => @Eq.{1} Nat s.owner (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Adopted.legacyPerformed + (CoreReader.Agency.ownRules (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Agency.completeOwnWork (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))))) + (And + (∀ (phase : CoreReader.Agency.Phase), + CoreReader.Agency.Performed + (CoreReader.Agency.completeOwnWork (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Agency.Subject.process (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) phase) + CoreReader.Agency.Activity.assessment) + (And + (CoreReader.Agency.Performed + (CoreReader.Agency.completeOwnWork (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Agency.Subject.system (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + CoreReader.Agency.Activity.assessment) + (And + (@CoreReader.Adopted.reflexivitySpecification CoreReader.Agency.Subject CoreReader.Agency.Inquiry + CoreReader.Agency.WorkOutcome + (@List.map.{0, 0} CoreReader.Agency.Principle + (CoreReader.Adopted.ReflexiveRule CoreReader.Agency.Subject CoreReader.Agency.Inquiry + CoreReader.Agency.WorkOutcome) + CoreReader.Adopted.legacyRule + (@List.cons.{0} CoreReader.Agency.Principle CoreReader.Agency.applicationRule + (@List.nil.{0} CoreReader.Agency.Principle))) + (fun s => @Eq.{1} Nat s.owner (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Adopted.legacyPerformed + (@List.cons.{0} CoreReader.Agency.Principle CoreReader.Agency.applicationRule + (@List.nil.{0} CoreReader.Agency.Principle)) + CoreReader.Agency.applicationWork)) + (Not + (CoreReader.Agency.Performed CoreReader.Agency.applicationWork + (CoreReader.Agency.Subject.system (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + CoreReader.Agency.Activity.assessment)))))) + (And + (And + (@CoreReader.Adopted.Grounds012 Bool (fun enabled => CoreReader.Adopted.GroundsProvision012 enabled) + (@CoreReader.Evidence.canonicalArticulation Bool) + (@List.cons.{1} (CoreReader.Evidence.Facet Bool) + (@CoreReader.Evidence.Facet.value Bool CoreReader.Adopted.groundsPosition012) + (@List.nil.{1} (CoreReader.Evidence.Facet Bool))) + (@CoreReader.Adopted.AssessmentTask.value Bool CoreReader.Adopted.groundsPosition012)) + (And (@CoreReader.Evidence.ValuePosition.limits Bool CoreReader.Adopted.groundsPosition012 Bool.true) + (@CoreReader.Evidence.ValuePosition.relevantCriticism Bool CoreReader.Adopted.groundsPosition012 Bool.true))) + (And + (@CoreReader.Evidence.Compatible (Nat → Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Nat → Bool)) CoreReader.Evidence.zeroRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Nat → Bool)))) + (CoreReader.Evidence.localGenerator (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))))) + (And + (Not + (CoreReader.Evidence.allTrue + (CoreReader.Evidence.localGenerator (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))))) + (And (@Eq.{1} Bool (CoreReader.Adopted.groundsExperiment012 Bool.true) Bool.false) + (And (@Eq.{1} Bool (CoreReader.Adopted.groundsExperiment012 Bool.false) Bool.true) + (And + (@Eq.{1} (@CoreReader.Evidence.ValuePosition.Outcome Bool CoreReader.Adopted.groundsPosition012) + (@CoreReader.Evidence.ValuePosition.outcome Bool CoreReader.Adopted.groundsPosition012 Bool.true + Bool.true) + (CoreReader.Adopted.groundsExperiment012 Bool.true)) + (@Eq.{1} (@CoreReader.Evidence.ValuePosition.Outcome Bool CoreReader.Adopted.groundsPosition012) + (@CoreReader.Evidence.ValuePosition.outcome Bool CoreReader.Adopted.groundsPosition012 Bool.true + Bool.false) + (CoreReader.Adopted.groundsExperiment012 Bool.false)))))))) +CoreReader.Adopted.reflexivityLimits012 : And + (And + (@Eq.{1} Bool + (CoreReader.Agency.selfTest + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))) (@List.nil.{0} Nat))) + Bool.true) + (And + (@Eq.{1} Bool + (CoreReader.Agency.ownArithmeticPrinciple (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + Bool.false) + (Not (∀ (n : Nat), @Eq.{1} Bool (CoreReader.Agency.ownArithmeticPrinciple n) Bool.true)))) + (And + (And + (@Eq.{1} Bool + (CoreReader.Evidence.localGenerator (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + Bool.true) + (And + (@Eq.{1} Bool + (CoreReader.Evidence.localGenerator (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + Bool.false) + (And + (@CoreReader.Evidence.Compatible (Nat → Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Nat → Bool)) CoreReader.Evidence.zeroRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Nat → Bool)))) + (CoreReader.Evidence.localGenerator (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))))) + (And + (Not + (@CoreReader.Evidence.Supports (Nat → Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Nat → Bool)) CoreReader.Evidence.zeroRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Nat → Bool)))) + CoreReader.Evidence.allTrue)) + CoreReader.Evidence.OwnedRevisionExample)))) + (And + (And (CoreReader.Agency.Generative CoreReader.Agency.openPolicy) + (Not + (CoreReader.Agency.Reflexive (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (CoreReader.Agency.ownRules (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (@List.nil.{0} CoreReader.Agency.WorkRecord)))) + (And + (And (CoreReader.Adopted.CompleteCharter012 CoreReader.Integration.actualSystem CoreReader.Integration.actual) + (And + (@CoreReader.Logic.Admissible CoreReader.Integration.World CoreReader.Integration.Question + CoreReader.Integration.held CoreReader.Integration.context CoreReader.Integration.actual) + (And + (@CoreReader.Evidence.Compatible CoreReader.Integration.World + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Integration.World) + CoreReader.Integration.costAllowanceRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Integration.World))) + CoreReader.Integration.actual) + (And + (@CoreReader.Evidence.Articulated CoreReader.Integration.World + (@CoreReader.Evidence.canonicalArticulation CoreReader.Integration.World + CoreReader.Integration.unsupportedCapabilityFacet)) + (And + (Not + (@CoreReader.Evidence.Supports CoreReader.Integration.World + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Integration.World) + CoreReader.Integration.costAllowanceRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Integration.World))) + CoreReader.Integration.capability)) + (Not + (@CoreReader.Adopted.Grounds012 CoreReader.Integration.World CoreReader.Integration.capability + (@CoreReader.Evidence.canonicalArticulation CoreReader.Integration.World) + (@List.cons.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World) + CoreReader.Integration.unsupportedCapabilityFacet + (@List.nil.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World))) + (@CoreReader.Adopted.taskOfFacet CoreReader.Integration.World + CoreReader.Integration.unsupportedCapabilityFacet)))))))) + (And (CoreReader.Adopted.generationSpecification CoreReader.Agency.openPolicy) + (And + (CoreReader.Agency.openPolicy.revisable + { kind := CoreReader.Agency.FormKind.principle, + version := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)) }) + (And + (CoreReader.Adopted.selfExemptPerformed012 + { owner := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + localId := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)) } + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))) + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))) Bool.true) + (And + (@CoreReader.Adopted.ReflexiveRule.applicable Nat Nat Bool CoreReader.Adopted.selfExemptRule012 + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (Not + (@CoreReader.Adopted.reflexivitySpecification Nat Nat Bool + (@List.cons.{0} (CoreReader.Adopted.ReflexiveRule Nat Nat Bool) CoreReader.Adopted.selfExemptRule012 + (@List.nil.{0} (CoreReader.Adopted.ReflexiveRule Nat Nat Bool))) + (fun target => @Eq.{1} Nat target (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + CoreReader.Adopted.selfExemptPerformed012))))))))) +CoreReader.Adopted.groundsCases012 : And + (And + (@CoreReader.Adopted.Grounds012 (Nat → Bool) + (@CoreReader.Evidence.Facet.claim (Nat → Bool) CoreReader.Adopted.localFacet012) + (@CoreReader.Evidence.canonicalArticulation (Nat → Bool)) + (@List.cons.{1} (CoreReader.Evidence.Facet (Nat → Bool)) CoreReader.Adopted.localFacet012 + (@List.nil.{1} (CoreReader.Evidence.Facet (Nat → Bool)))) + (@CoreReader.Adopted.taskOfFacet (Nat → Bool) CoreReader.Adopted.localFacet012)) + (And + (@CoreReader.Evidence.Articulated (Nat → Bool) + (@CoreReader.Evidence.canonicalArticulation (Nat → Bool) CoreReader.Adopted.globalFacet012)) + (And + (Not + (@CoreReader.Adopted.Grounds012 (Nat → Bool) + (@CoreReader.Evidence.Facet.claim (Nat → Bool) CoreReader.Adopted.globalFacet012) + (@CoreReader.Evidence.canonicalArticulation (Nat → Bool)) + (@List.cons.{1} (CoreReader.Evidence.Facet (Nat → Bool)) CoreReader.Adopted.globalFacet012 + (@List.nil.{1} (CoreReader.Evidence.Facet (Nat → Bool)))) + (@CoreReader.Adopted.taskOfFacet (Nat → Bool) CoreReader.Adopted.globalFacet012))) + (Not + (@CoreReader.Adopted.Grounds012 (Nat → Bool) + (@CoreReader.Evidence.Facet.claim (Nat → Bool) CoreReader.Adopted.strongFacet012) + (@CoreReader.Evidence.canonicalArticulation (Nat → Bool)) + (@List.cons.{1} (CoreReader.Evidence.Facet (Nat → Bool)) CoreReader.Adopted.strongFacet012 + (@List.nil.{1} (CoreReader.Evidence.Facet (Nat → Bool)))) + (@CoreReader.Adopted.taskOfFacet (Nat → Bool) CoreReader.Adopted.strongFacet012)))))) + (And + (And (@CoreReader.Evidence.Articulated Bool CoreReader.Evidence.uninformativeArgument) + (Not + (@CoreReader.Logic.Entails Bool + (@CoreReader.Evidence.Articulation.assumptions Bool CoreReader.Evidence.uninformativeArgument) fun w => + @Eq.{1} Bool w Bool.true))) + (And + (@CoreReader.Adopted.Grounds012 (Nat → Bool) CoreReader.Evidence.allTrue + (@CoreReader.Evidence.canonicalArticulation (Nat → Bool)) + (@List.cons.{1} (CoreReader.Evidence.Facet (Nat → Bool)) CoreReader.Adopted.circularGlobalFacet012 + (@List.nil.{1} (CoreReader.Evidence.Facet (Nat → Bool)))) + (@CoreReader.Adopted.taskOfFacet (Nat → Bool) CoreReader.Adopted.circularGlobalFacet012)) + (And + (Not + (@CoreReader.Adopted.NatureAppropriate (Nat → Bool) CoreReader.Adopted.originalGlobalTask012 + CoreReader.Adopted.circularGlobalFacet012)) + (Not + (@CoreReader.Adopted.Grounds012 (Nat → Bool) CoreReader.Evidence.allTrue + (@CoreReader.Evidence.canonicalArticulation (Nat → Bool)) + (@List.cons.{1} (CoreReader.Evidence.Facet (Nat → Bool)) CoreReader.Adopted.circularGlobalFacet012 + (@List.nil.{1} (CoreReader.Evidence.Facet (Nat → Bool)))) + CoreReader.Adopted.originalGlobalTask012))))) +CoreReader.Adopted.empiricalCases012 : And + (And + (@CoreReader.Adopted.Grounds012 (Nat → Bool) + (@CoreReader.Evidence.Facet.claim (Nat → Bool) CoreReader.Adopted.localFacet012) + (@CoreReader.Evidence.canonicalArticulation (Nat → Bool)) + (@List.cons.{1} (CoreReader.Evidence.Facet (Nat → Bool)) CoreReader.Adopted.localFacet012 + (@List.nil.{1} (CoreReader.Evidence.Facet (Nat → Bool)))) + (@CoreReader.Adopted.taskOfFacet (Nat → Bool) CoreReader.Adopted.localFacet012)) + (And + (@CoreReader.Evidence.Articulated (Nat → Bool) + (@CoreReader.Evidence.canonicalArticulation (Nat → Bool) CoreReader.Adopted.globalFacet012)) + (And + (Not + (@CoreReader.Adopted.Grounds012 (Nat → Bool) + (@CoreReader.Evidence.Facet.claim (Nat → Bool) CoreReader.Adopted.globalFacet012) + (@CoreReader.Evidence.canonicalArticulation (Nat → Bool)) + (@List.cons.{1} (CoreReader.Evidence.Facet (Nat → Bool)) CoreReader.Adopted.globalFacet012 + (@List.nil.{1} (CoreReader.Evidence.Facet (Nat → Bool)))) + (@CoreReader.Adopted.taskOfFacet (Nat → Bool) CoreReader.Adopted.globalFacet012))) + (Not + (@CoreReader.Adopted.Grounds012 (Nat → Bool) + (@CoreReader.Evidence.Facet.claim (Nat → Bool) CoreReader.Adopted.strongFacet012) + (@CoreReader.Evidence.canonicalArticulation (Nat → Bool)) + (@List.cons.{1} (CoreReader.Evidence.Facet (Nat → Bool)) CoreReader.Adopted.strongFacet012 + (@List.nil.{1} (CoreReader.Evidence.Facet (Nat → Bool)))) + (@CoreReader.Adopted.taskOfFacet (Nat → Bool) CoreReader.Adopted.strongFacet012)))))) + (And + (And + (@Eq.{1} Bool + (@CoreReader.Evidence.Record.test (Prod.{0, 0} Bool Bool) CoreReader.Evidence.temperatureRecord + (@Prod.mk.{0, 0} Bool Bool Bool.true Bool.false)) + Bool.true) + (And + (@CoreReader.Evidence.Compatible (Prod.{0, 0} Bool Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool))))) + (@Prod.mk.{0, 0} Bool Bool Bool.true Bool.false)) + (And + (@CoreReader.Evidence.Compatible (Prod.{0, 0} Bool Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool))))) + (@Prod.mk.{0, 0} Bool Bool Bool.true Bool.true)) + (And + (Not + (@CoreReader.Evidence.Supports (Prod.{0, 0} Bool Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) + CoreReader.Evidence.temperatureRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)))) + fun w => @Eq.{1} Bool (@Prod.snd.{0, 0} Bool Bool w) Bool.true)) + (And + (Not + (@CoreReader.Evidence.Supports (Prod.{0, 0} Bool Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) + CoreReader.Evidence.temperatureRecord + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) + CoreReader.Evidence.temperatureRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool))))) + fun w => @Eq.{1} Bool (@Prod.snd.{0, 0} Bool Bool w) Bool.true)) + (And + (@CoreReader.Evidence.Compatible CoreReader.Evidence.BudgetWorld + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld) + CoreReader.Evidence.actionRecord + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld) + CoreReader.Evidence.actionRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld)))) + (@Prod.mk.{0, 0} Bool Nat Bool.true (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))))) + (And + (@CoreReader.Evidence.Compatible CoreReader.Evidence.BudgetWorld + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld) + CoreReader.Evidence.actionRecord + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld) + CoreReader.Evidence.actionRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld)))) + (@Prod.mk.{0, 0} Bool Nat Bool.true (@OfNat.ofNat.{0} Nat (nat_lit 3) (instOfNatNat (nat_lit 3))))) + (And + (Not + (@CoreReader.Evidence.Supports CoreReader.Evidence.BudgetWorld + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld) + CoreReader.Evidence.actionRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld))) + (@CoreReader.Evidence.ValuePosition.consequence CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition))) + (And + (Not + (@CoreReader.Evidence.Supports CoreReader.Evidence.BudgetWorld + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld) + CoreReader.Evidence.actionRecord + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld) + CoreReader.Evidence.actionRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld)))) + (@CoreReader.Evidence.ValuePosition.consequence CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition))) + (Not + (@CoreReader.Evidence.ValueProcedure CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition))))))))))) + (And + (And + (@CoreReader.Adopted.empiricalSpecification (Prod.{0, 0} Bool Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool))))) + (fun x => True) (fun w => @Eq.{1} Bool (@Prod.fst.{0, 0} Bool Bool w) Bool.true) fun w => + Or (@Eq.{1} Bool (@Prod.snd.{0, 0} Bool Bool w) Bool.true) + (@Eq.{1} Bool (@Prod.snd.{0, 0} Bool Bool w) Bool.false)) + (And + (@CoreReader.Evidence.Compatible (Prod.{0, 0} Bool Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool))))) + (@Prod.mk.{0, 0} Bool Bool Bool.true Bool.true)) + (@CoreReader.Evidence.Compatible (Prod.{0, 0} Bool Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool))))) + (@Prod.mk.{0, 0} Bool Bool Bool.true Bool.false)))) + (And + (And + (@CoreReader.Adopted.Grounds012 (Nat → Bool) + (fun f => @Eq.{1} Bool (f (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) Bool.true) + (@CoreReader.Evidence.canonicalArticulation (Nat → Bool)) + (@List.cons.{1} (CoreReader.Evidence.Facet (Nat → Bool)) CoreReader.Adopted.localFacet012 + (@List.nil.{1} (CoreReader.Evidence.Facet (Nat → Bool)))) + CoreReader.Adopted.originalLocalTask012) + (@CoreReader.Adopted.Grounds012 (Nat → Bool) + (fun f => @Eq.{1} Bool (f (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) Bool.true) + (@CoreReader.Evidence.canonicalArticulation (Nat → Bool)) + (@List.cons.{1} (CoreReader.Evidence.Facet (Nat → Bool)) CoreReader.Adopted.observedInferenceFacet012 + (@List.nil.{1} (CoreReader.Evidence.Facet (Nat → Bool)))) + CoreReader.Adopted.originalLocalTask012)) + (And (@CoreReader.Evidence.FacetDischarged (Prod.{0, 0} Bool Bool) CoreReader.Adopted.uncertaintyBypassFacet012) + (And + (Not + (@CoreReader.Adopted.NatureAppropriate (Prod.{0, 0} Bool Bool) + CoreReader.Adopted.originalUncertaintyTask012 CoreReader.Adopted.uncertaintyBypassFacet012)) + (Not + (@CoreReader.Adopted.Grounds012 (Prod.{0, 0} Bool Bool) + (fun w => @Eq.{1} Bool (@Prod.fst.{0, 0} Bool Bool w) Bool.true) + (@CoreReader.Evidence.canonicalArticulation (Prod.{0, 0} Bool Bool)) + (@List.cons.{1} (CoreReader.Evidence.Facet (Prod.{0, 0} Bool Bool)) + CoreReader.Adopted.uncertaintyBypassFacet012 + (@List.nil.{1} (CoreReader.Evidence.Facet (Prod.{0, 0} Bool Bool)))) + CoreReader.Adopted.originalUncertaintyTask012))))))) +CoreReader.Adopted.inferentialCases012 : And + (And + (@CoreReader.Adopted.inferentialSpecification Nat + (@CoreReader.Logic.singleton Nat fun n => + @Eq.{1} Nat n (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2)))) + fun n => + @Eq.{1} Nat + (@HAdd.hAdd.{0, 0, 0} Nat Nat Nat (@instHAdd.{0} Nat instAddNat) n + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (@OfNat.ofNat.{0} Nat (nat_lit 3) (instOfNatNat (nat_lit 3)))) + (And + (@CoreReader.Adopted.InferenceExamined Bool (@CoreReader.Logic.emptyTheory Bool) + (fun w => @Eq.{1} Bool w Bool.true) Bool.false) + (And (@CoreReader.Logic.Models Bool (@CoreReader.Logic.emptyTheory Bool) Bool.false) + (Not ((fun w => @Eq.{1} Bool w Bool.true) Bool.false))))) + (And + (And + (@CoreReader.Logic.Satisfiable Bool + (@CoreReader.Logic.union Bool (@CoreReader.Logic.emptyTheory Bool) + (@CoreReader.Logic.singleton Bool fun w => @Eq.{1} Bool w Bool.true))) + (Not (@CoreReader.Logic.Entails Bool (@CoreReader.Logic.emptyTheory Bool) fun w => @Eq.{1} Bool w Bool.true))) + (And + (@CoreReader.Evidence.FacetDischarged Bool + (@CoreReader.Evidence.Facet.inferential Bool + (@CoreReader.Logic.singleton Bool fun w => @Eq.{1} Bool w Bool.true) fun w => @Eq.{1} Bool w Bool.true)) + (Not + (@CoreReader.Adopted.Grounds012 Bool (fun w => @Eq.{1} Bool w Bool.true) + (@CoreReader.Evidence.canonicalArticulation Bool) + (@List.cons.{1} (CoreReader.Evidence.Facet Bool) + (@CoreReader.Evidence.Facet.inferential Bool + (@CoreReader.Logic.singleton Bool fun w => @Eq.{1} Bool w Bool.true) fun w => @Eq.{1} Bool w Bool.true) + (@List.nil.{1} (CoreReader.Evidence.Facet Bool))) + (@CoreReader.Adopted.AssessmentTask.inferential Bool (@CoreReader.Logic.emptyTheory Bool) fun w => + @Eq.{1} Bool w Bool.true))))) +CoreReader.Adopted.valueCases012 : And (@CoreReader.Adopted.valueSpecification Bool CoreReader.Evidence.switchPosition) + (And + (And + (@Ne.{1} + (List.{0} + (CoreReader.Evidence.BudgetWorld → + @CoreReader.Evidence.ValuePosition.Position CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition → + Prop)) + (@CoreReader.Evidence.ValuePosition.reasons CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition) + (@List.nil.{0} + (CoreReader.Evidence.BudgetWorld → + @CoreReader.Evidence.ValuePosition.Position CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition → + Prop))) + (And + (@CoreReader.Evidence.ValuePosition.commitment CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition + (@Prod.mk.{0, 0} Bool Nat Bool.true (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))))) + (And + (∀ + (reason : + CoreReader.Evidence.BudgetWorld → + @CoreReader.Evidence.ValuePosition.Position CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition → + Prop), + @Membership.mem.{0, 0} + (CoreReader.Evidence.BudgetWorld → + @CoreReader.Evidence.ValuePosition.Position CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition → + Prop) + (List.{0} + (CoreReader.Evidence.BudgetWorld → + @CoreReader.Evidence.ValuePosition.Position CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition → + Prop)) + (@List.instMembership.{0} + (CoreReader.Evidence.BudgetWorld → + @CoreReader.Evidence.ValuePosition.Position CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition → + Prop)) + (@CoreReader.Evidence.ValuePosition.reasons CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition) + reason → + reason (@Prod.mk.{0, 0} Bool Nat Bool.true (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (@CoreReader.Evidence.ValuePosition.adopted CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition)) + (And + (Not + (@CoreReader.Evidence.ValuePosition.consequence CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition + (@Prod.mk.{0, 0} Bool Nat Bool.true (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))))) + (Not + (@CoreReader.Evidence.ValueProcedure CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition)))))) + (And (Not (@CoreReader.Evidence.ValueProcedure Bool CoreReader.Adopted.closedPosition012)) + (And + (And (@CoreReader.Evidence.ValueProcedure Bool CoreReader.Evidence.switchPosition) + (And + (@CoreReader.Logic.Satisfiable Bool + (@CoreReader.Evidence.ValuePosition.starting Bool CoreReader.Evidence.switchPosition)) + (And + (Not + (@CoreReader.Logic.Entails Bool (@CoreReader.Logic.emptyTheory Bool) + (@CoreReader.Evidence.ValuePosition.commitment Bool CoreReader.Evidence.switchPosition))) + (And + (And (@CoreReader.Evidence.JointAdoption Bool CoreReader.Evidence.oppositePosition) + (Not (@CoreReader.Evidence.ValueProcedure Bool CoreReader.Evidence.oppositePosition))) + (And (Not (@CoreReader.Evidence.ValueProcedure Bool CoreReader.Evidence.contradictoryStartingPosition)) + (Not (@CoreReader.Evidence.ValueProcedure Bool CoreReader.Evidence.impossibleAdoptionPosition))))))) + (And (@CoreReader.Evidence.FacetDischarged Bool CoreReader.Adopted.selectedFactFacet012) + (And (@CoreReader.Adopted.valueSpecification Bool CoreReader.Evidence.switchPosition) + (Not + (@CoreReader.Adopted.Grounds012 Bool + (@CoreReader.Evidence.ValuePosition.commitment Bool CoreReader.Evidence.switchPosition) + (@CoreReader.Evidence.canonicalArticulation Bool) + (@List.cons.{1} (CoreReader.Evidence.Facet Bool) CoreReader.Adopted.selectedFactFacet012 + (@List.nil.{1} (CoreReader.Evidence.Facet Bool))) + (@CoreReader.Adopted.AssessmentTask.value Bool CoreReader.Evidence.switchPosition)))))))) +CoreReader.Adopted.groundsLimits012 : And + (And (@CoreReader.Evidence.Articulated Bool CoreReader.Adopted.clearFalseArgument012) + (Not + (@CoreReader.Logic.Models Bool + (@CoreReader.Evidence.Articulation.assumptions Bool CoreReader.Adopted.clearFalseArgument012) Bool.false))) + (And + (And + (@Eq.{1} Bool + (@CoreReader.Evidence.Record.test (Prod.{0, 0} Bool Bool) CoreReader.Evidence.temperatureRecord + (@Prod.mk.{0, 0} Bool Bool Bool.true Bool.false)) + Bool.true) + (And + (@CoreReader.Evidence.Compatible (Prod.{0, 0} Bool Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool))))) + (@Prod.mk.{0, 0} Bool Bool Bool.true Bool.false)) + (And + (@CoreReader.Evidence.Compatible (Prod.{0, 0} Bool Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool))))) + (@Prod.mk.{0, 0} Bool Bool Bool.true Bool.true)) + (And + (Not + (@CoreReader.Evidence.Supports (Prod.{0, 0} Bool Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) + CoreReader.Evidence.temperatureRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)))) + fun w => @Eq.{1} Bool (@Prod.snd.{0, 0} Bool Bool w) Bool.true)) + (And + (Not + (@CoreReader.Evidence.Supports (Prod.{0, 0} Bool Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) + CoreReader.Evidence.temperatureRecord + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) + CoreReader.Evidence.temperatureRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool))))) + fun w => @Eq.{1} Bool (@Prod.snd.{0, 0} Bool Bool w) Bool.true)) + (And + (@CoreReader.Evidence.Compatible CoreReader.Evidence.BudgetWorld + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld) + CoreReader.Evidence.actionRecord + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld) + CoreReader.Evidence.actionRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld)))) + (@Prod.mk.{0, 0} Bool Nat Bool.true (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))))) + (And + (@CoreReader.Evidence.Compatible CoreReader.Evidence.BudgetWorld + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld) + CoreReader.Evidence.actionRecord + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld) + CoreReader.Evidence.actionRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld)))) + (@Prod.mk.{0, 0} Bool Nat Bool.true (@OfNat.ofNat.{0} Nat (nat_lit 3) (instOfNatNat (nat_lit 3))))) + (And + (Not + (@CoreReader.Evidence.Supports CoreReader.Evidence.BudgetWorld + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld) + CoreReader.Evidence.actionRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld))) + (@CoreReader.Evidence.ValuePosition.consequence CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition))) + (And + (Not + (@CoreReader.Evidence.Supports CoreReader.Evidence.BudgetWorld + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld) + CoreReader.Evidence.actionRecord + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld) + CoreReader.Evidence.actionRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld)))) + (@CoreReader.Evidence.ValuePosition.consequence CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition))) + (Not + (@CoreReader.Evidence.ValueProcedure CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition))))))))))) + (And + (And (@CoreReader.Adopted.valueSpecification Bool CoreReader.Evidence.switchPosition) + (And + (@CoreReader.Evidence.Compatible Bool + (@List.cons.{0} (CoreReader.Evidence.Record Bool) CoreReader.Adopted.valueNeutralRecord012 + (@List.nil.{0} (CoreReader.Evidence.Record Bool))) + Bool.false) + (And + (Not + (@CoreReader.Evidence.Supports Bool + (@List.cons.{0} (CoreReader.Evidence.Record Bool) CoreReader.Adopted.valueNeutralRecord012 + (@List.nil.{0} (CoreReader.Evidence.Record Bool))) + (@CoreReader.Evidence.ValuePosition.commitment Bool CoreReader.Evidence.switchPosition))) + (Not + (@CoreReader.Logic.Entails Bool (@CoreReader.Logic.emptyTheory Bool) + (@CoreReader.Evidence.ValuePosition.commitment Bool CoreReader.Evidence.switchPosition)))))) + (And + (And (@CoreReader.Evidence.ValueProcedure Bool CoreReader.Evidence.switchPosition) + (And + (@CoreReader.Logic.Satisfiable Bool + (@CoreReader.Evidence.ValuePosition.starting Bool CoreReader.Evidence.switchPosition)) + (And + (Not + (@CoreReader.Logic.Entails Bool (@CoreReader.Logic.emptyTheory Bool) + (@CoreReader.Evidence.ValuePosition.commitment Bool CoreReader.Evidence.switchPosition))) + (And + (And (@CoreReader.Evidence.JointAdoption Bool CoreReader.Evidence.oppositePosition) + (Not (@CoreReader.Evidence.ValueProcedure Bool CoreReader.Evidence.oppositePosition))) + (And (Not (@CoreReader.Evidence.ValueProcedure Bool CoreReader.Evidence.contradictoryStartingPosition)) + (Not (@CoreReader.Evidence.ValueProcedure Bool CoreReader.Evidence.impossibleAdoptionPosition))))))) + (And + (@CoreReader.Adopted.ClaimNoStronger (Nat → Bool) + (fun f => @Eq.{1} Bool (f (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) Bool.true) + CoreReader.Evidence.allTrue) + (And + (Not + (@CoreReader.Adopted.ClaimNoStronger (Nat → Bool) CoreReader.Evidence.allTrue fun f => + @Eq.{1} Bool (f (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) Bool.true)) + (@CoreReader.Adopted.valueSpecification Bool CoreReader.Evidence.switchPosition)))))) +CoreReader.Adopted.scopeCases012 : And + (@CoreReader.Adopted.scopeSpecification Nat CoreReader.Adopted.localScopeAccount012) + (And + (∀ (n : Nat), + @Eq.{1} Nat n (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) → + @Eq.{1} Bool ((fun x => Bool.true) n) + (CoreReader.Evidence.localGenerator (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) n)) + (@Ne.{1} Bool ((fun x => Bool.true) (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (CoreReader.Evidence.localGenerator (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))))) +CoreReader.Adopted.scopeLimits012 : And + (And + (@Exists.{1} Nat fun outside => @Ne.{1} Nat outside (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (And + (@CoreReader.Evidence.Compatible (Nat → Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Nat → Bool)) CoreReader.Evidence.zeroRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Nat → Bool)))) + fun x => Bool.true) + (And + (@CoreReader.Evidence.Compatible (Nat → Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Nat → Bool)) CoreReader.Evidence.zeroRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Nat → Bool)))) + (CoreReader.Evidence.localGenerator (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))))) + (And (CoreReader.Evidence.allTrue fun x => Bool.true) + (And + (Not + (CoreReader.Evidence.allTrue + (CoreReader.Evidence.localGenerator (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))))) + (Not + (@CoreReader.Evidence.Supports (Nat → Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Nat → Bool)) CoreReader.Evidence.zeroRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Nat → Bool)))) + CoreReader.Evidence.allTrue))))))) + (And + (And + (∀ (n : Nat), + @Eq.{1} Nat n (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) → + @Eq.{1} Bool ((fun x => Bool.true) n) + (CoreReader.Evidence.localGenerator (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) n)) + (@Ne.{1} Bool ((fun x => Bool.true) (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (CoreReader.Evidence.localGenerator (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))))) + (And + (And + (@Eq.{1} Nat + (@List.length.{0} (CoreReader.Evidence.Record (Nat → Bool)) + (@List.cons.{0} (CoreReader.Evidence.Record (Nat → Bool)) CoreReader.Evidence.zeroRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Nat → Bool))))) + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (And + (@Exists.{1} (Nat → Bool) fun f => + @CoreReader.Evidence.Compatible (Nat → Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Nat → Bool)) CoreReader.Evidence.zeroRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Nat → Bool)))) + f) + (And + (@CoreReader.Evidence.Supports (Nat → Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Nat → Bool)) CoreReader.Evidence.zeroRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Nat → Bool)))) + fun f => @Eq.{1} Bool (f (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) Bool.true) + (Not + (@CoreReader.Evidence.Supports (Nat → Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Nat → Bool)) CoreReader.Evidence.zeroRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Nat → Bool)))) + CoreReader.Evidence.allTrue))))) + (And + (have a := + { setting := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)) }; + have b := + { setting := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2)) }; + And (CoreReader.Evidence.Reproduced a b) + (And (@Ne.{1} Nat a.actualOutcome b.actualOutcome) + (And (CoreReader.Evidence.Bounded a) (CoreReader.Evidence.Bounded b)))) + (And + (And + (And + (CoreReader.Evidence.Verified + { setting := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)) }) + (And + (CoreReader.Evidence.Verified + { setting := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)) }) + (Not + (CoreReader.Evidence.Reproduced + { setting := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)) } + { setting := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)) })))) + (And + (And + (CoreReader.Evidence.Reproduced + { setting := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)) } + { setting := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 3) (instOfNatNat (nat_lit 3)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2)) }) + (And + (Not + (CoreReader.Evidence.Verified + { setting := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 3) (instOfNatNat (nat_lit 3)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2)) })) + (Not + (CoreReader.Evidence.Bounded + { setting := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 3) (instOfNatNat (nat_lit 3)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2)) })))) + (And + (CoreReader.Evidence.Bounded + { setting := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)) }) + (And + (CoreReader.Evidence.Bounded + { setting := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)) }) + (Not + (CoreReader.Evidence.Verified + { setting := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)) })))))) + (And + (And (@CoreReader.Evidence.FacetDischarged Nat CoreReader.Evidence.arithmeticFacet) + (@Eq.{1} Bool (@CoreReader.Evidence.usesObservation Nat CoreReader.Evidence.arithmeticFacet) Bool.false)) + (And + (And + (@CoreReader.Adopted.inferentialSpecification Bool + (@CoreReader.Logic.singleton Bool fun on => @Eq.{1} Bool on Bool.true) fun on => + @Ne.{1} Bool on Bool.false) + (@Eq.{1} Bool + (@CoreReader.Evidence.usesObservation Bool + (@CoreReader.Evidence.Facet.inferential Bool + (@CoreReader.Logic.singleton Bool fun on => @Eq.{1} Bool on Bool.true) fun on => + @Ne.{1} Bool on Bool.false)) + Bool.false)) + (And + (@GT.gt.{0} Nat instLTNat (CoreReader.Adopted.drawWeight012 Bool.true) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (And + (@GT.gt.{0} Nat instLTNat (CoreReader.Adopted.drawWeight012 Bool.false) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (And + (@Eq.{1} Nat (CoreReader.Adopted.drawWeight012 Bool.true) + (CoreReader.Adopted.drawWeight012 Bool.false)) + (And + (CoreReader.Evidence.Reproduced (CoreReader.Adopted.randomTrial012 Bool.true) + (CoreReader.Adopted.randomTrial012 Bool.false)) + (And + (@Ne.{1} Nat (CoreReader.Adopted.randomTrial012 Bool.true).actualOutcome + (CoreReader.Adopted.randomTrial012 Bool.false).actualOutcome) + (∀ (draw : Bool), + And (CoreReader.Evidence.Verified (CoreReader.Adopted.randomTrial012 draw)) + (CoreReader.Evidence.Bounded (CoreReader.Adopted.randomTrial012 draw)))))))))))))) +CoreReader.Adopted.capabilityCases012 : And + (And + (CoreReader.Adopted.capabilitySpecification CoreReader.Evidence.outputOnlyProcess + CoreReader.Evidence.OutputContract) + (And + (CoreReader.Adopted.capabilitySpecification CoreReader.Evidence.explainedProcess + CoreReader.Evidence.FullProcessContract) + (And + (@Exists.{1} (CoreReader.Evidence.ExternalCertificate CoreReader.Evidence.outputOnlyProcess) fun certificate => + And + (@Ne.{1} Nat + (@CoreReader.Evidence.ExternalCertificate.assessorId CoreReader.Evidence.outputOnlyProcess certificate) + (@CoreReader.Evidence.ExternalCertificate.assessedId CoreReader.Evidence.outputOnlyProcess certificate)) + (CoreReader.Evidence.OutputContract CoreReader.Evidence.outputOnlyProcess)) + (Not (CoreReader.Evidence.ExplanationContract CoreReader.Evidence.outputOnlyProcess))))) + (And + (CoreReader.Adopted.OwnCapability012 (@OfNat.ofNat.{0} Nat (nat_lit 7) (instOfNatNat (nat_lit 7))) + (@OfNat.ofNat.{0} Nat (nat_lit 7) (instOfNatNat (nat_lit 7))) CoreReader.Evidence.outputOnlyProcess + CoreReader.Evidence.OutputContract) + (And + (@Eq.{1} CoreReader.Evidence.Process CoreReader.Adopted.explainedWithoutVariation012.process + CoreReader.Adopted.mechanismResponder012.process) + (And (CoreReader.Evidence.FullProcessContract CoreReader.Adopted.explainedWithoutVariation012.process) + (And (Not (CoreReader.Adopted.UnderstandingApplication012 CoreReader.Adopted.explainedWithoutVariation012)) + (And (CoreReader.Adopted.UnderstandingApplication012 CoreReader.Adopted.mechanismResponder012) + (And + (@CoreReader.Adopted.Grounds012 CoreReader.Adopted.MechanismApplication012 + CoreReader.Adopted.UnderstandingApplication012 + (@CoreReader.Evidence.canonicalArticulation CoreReader.Adopted.MechanismApplication012) + (@List.cons.{1} (CoreReader.Evidence.Facet CoreReader.Adopted.MechanismApplication012) + (CoreReader.Adopted.understandingFacet012 CoreReader.Adopted.mechanismResponder012) + (@List.nil.{1} (CoreReader.Evidence.Facet CoreReader.Adopted.MechanismApplication012))) + (CoreReader.Adopted.understandingTask012 CoreReader.Adopted.mechanismResponder012)) + (Not + (@CoreReader.Adopted.Grounds012 CoreReader.Adopted.MechanismApplication012 + CoreReader.Adopted.UnderstandingApplication012 + (@CoreReader.Evidence.canonicalArticulation CoreReader.Adopted.MechanismApplication012) + (@List.cons.{1} (CoreReader.Evidence.Facet CoreReader.Adopted.MechanismApplication012) + (CoreReader.Adopted.understandingFacet012 CoreReader.Adopted.explainedWithoutVariation012) + (@List.nil.{1} (CoreReader.Evidence.Facet CoreReader.Adopted.MechanismApplication012))) + (CoreReader.Adopted.understandingTask012 CoreReader.Adopted.explainedWithoutVariation012))))))))) +CoreReader.Adopted.capabilityLimits012 : And + (And + (CoreReader.Adopted.capabilitySpecification CoreReader.Evidence.outputOnlyProcess + CoreReader.Evidence.OutputContract) + (And + (CoreReader.Adopted.capabilitySpecification CoreReader.Evidence.explainedProcess + CoreReader.Evidence.FullProcessContract) + (And + (@Exists.{1} (CoreReader.Evidence.ExternalCertificate CoreReader.Evidence.outputOnlyProcess) fun certificate => + And + (@Ne.{1} Nat + (@CoreReader.Evidence.ExternalCertificate.assessorId CoreReader.Evidence.outputOnlyProcess certificate) + (@CoreReader.Evidence.ExternalCertificate.assessedId CoreReader.Evidence.outputOnlyProcess certificate)) + (CoreReader.Evidence.OutputContract CoreReader.Evidence.outputOnlyProcess)) + (Not (CoreReader.Evidence.ExplanationContract CoreReader.Evidence.outputOnlyProcess))))) + (And + (∀ (kind : CoreReader.Agency.InventoryKind), + And + (CoreReader.Agency.Available + (@List.cons.{0} CoreReader.Agency.Item { kind := kind, content := CoreReader.Agency.Operation.copy } + (@List.cons.{0} CoreReader.Agency.Item { kind := kind, content := CoreReader.Agency.Operation.copy } + (@List.nil.{0} CoreReader.Agency.Item))) + CoreReader.Agency.Operation.copy) + (Not + (CoreReader.Agency.Available + (@List.cons.{0} CoreReader.Agency.Item { kind := kind, content := CoreReader.Agency.Operation.copy } + (@List.cons.{0} CoreReader.Agency.Item { kind := kind, content := CoreReader.Agency.Operation.copy } + (@List.nil.{0} CoreReader.Agency.Item))) + CoreReader.Agency.Operation.successor))) + (And (CoreReader.Agency.Generative CoreReader.Agency.generatingSystem.policy) + (And + (CoreReader.Agency.generatingSystem.policy.permitsVersion + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (And + (Not (CoreReader.Agency.Expanded CoreReader.Agency.generatingSystem.current CoreReader.Agency.inflatedState)) + (And + (@LT.lt.{0} Nat instLTNat + (@List.length.{0} CoreReader.Agency.Item CoreReader.Agency.generatingSystem.current.inventory) + (@List.length.{0} CoreReader.Agency.Item CoreReader.Agency.inflatedState.inventory)) + (And + (@LT.lt.{0} Nat instLTNat + (@List.length.{0} CoreReader.Agency.Operation + CoreReader.Agency.generatingSystem.current.abstractionLayers) + (@List.length.{0} CoreReader.Agency.Operation CoreReader.Agency.inflatedState.abstractionLayers)) + (And + (@LT.lt.{0} Nat instLTNat + (@List.length.{0} CoreReader.Agency.Operation CoreReader.Agency.generatingSystem.current.vocabulary) + (@List.length.{0} CoreReader.Agency.Operation CoreReader.Agency.inflatedState.vocabulary)) + (And + (@Eq.{1} (Option.{0} Nat) + (CoreReader.Agency.generatingSystem.execute CoreReader.Agency.availableResources) + (@Option.some.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 6) (instOfNatNat (nat_lit 6))))) + (And + (@Eq.{1} (Option.{0} Nat) + (CoreReader.Agency.generatingSystem.execute + (have __src := CoreReader.Agency.availableResources; + { experience := @Option.none.{0} Nat, knowledge := __src.knowledge, + collaborator := __src.collaborator })) + (@Option.none.{0} Nat)) + (And + (@Eq.{1} (Option.{0} Nat) + (CoreReader.Agency.generatingSystem.execute + (have __src := CoreReader.Agency.availableResources; + { experience := __src.experience, knowledge := @Option.none.{0} Nat, + collaborator := __src.collaborator })) + (@Option.none.{0} Nat)) + (And + (@Eq.{1} (Option.{0} Nat) + (CoreReader.Agency.generatingSystem.execute + (have __src := CoreReader.Agency.availableResources; + { experience := __src.experience, knowledge := __src.knowledge, + collaborator := @Option.none.{0} Nat })) + (@Option.none.{0} Nat)) + (And + (@Eq.{1} (Option.{0} Nat) + (CoreReader.Agency.generatingSystem.execute + { experience := @Option.none.{0} Nat, knowledge := @Option.none.{0} Nat, + collaborator := @Option.none.{0} Nat }) + (@Option.none.{0} Nat)) + (And + (Not + (CoreReader.Agency.Expanded CoreReader.Agency.generatingSystem.current + CoreReader.Agency.generatingSystem.stableAction)) + (And + (@Eq.{1} CoreReader.Agency.State CoreReader.Agency.generatingSystem.stableAction + CoreReader.Agency.generatingSystem.current) + (And + (CoreReader.Agency.generatingSystem.requirementsMet + CoreReader.Agency.generatingSystem.stableAction) + (And + (CoreReader.Agency.generatingSystem.withinBudget + CoreReader.Agency.generatingSystem.stableAction) + (And + (Not + (CoreReader.Agency.generatingSystem.withinBudget CoreReader.Agency.inflatedState)) + (And + (CoreReader.Agency.StableReason CoreReader.Agency.generatingSystem.current + CoreReader.Agency.inflatedState) + (And + (@Eq.{1} CoreReader.Agency.Announcement CoreReader.Agency.inflatedAnnouncement + (CoreReader.Agency.generatingSystem.report CoreReader.Agency.inflatedState + CoreReader.Agency.Operation.successor + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))))) + (And + (@Eq.{1} Nat CoreReader.Agency.inflatedAnnouncement.owner + CoreReader.Agency.generatingSystem.owner) + (And + (@Eq.{1} CoreReader.Agency.State + CoreReader.Agency.inflatedAnnouncement.before + CoreReader.Agency.generatingSystem.current) + (And + (@Eq.{1} CoreReader.Agency.State + CoreReader.Agency.inflatedAnnouncement.after + CoreReader.Agency.inflatedState) + (And + (@Eq.{1} CoreReader.Agency.Operation + CoreReader.Agency.inflatedAnnouncement.reportedNewOperation + CoreReader.Agency.Operation.successor) + (And + (@Eq.{1} Nat CoreReader.Agency.inflatedAnnouncement.input + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (And + (@Eq.{1} Nat CoreReader.Agency.inflatedAnnouncement.expectedOutput + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (And (Not CoreReader.Agency.inflatedAnnouncement.claim) + (Not + (CoreReader.Agency.Expanded + CoreReader.Agency.inflatedAnnouncement.before + CoreReader.Agency.inflatedAnnouncement.after)))))))))))))))))))))))))))) +CoreReader.Adopted.choiceCases012 : And + (And (@Eq.{1} Bool CoreReader.Choice.identityImpl.conventional Bool.true) + (And (@Eq.{1} Bool CoreReader.Choice.identityImpl.established Bool.true) + (CoreReader.Choice.JustifiedChoice CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + (@List.cons.{0} CoreReader.Choice.Reason + (CoreReader.Choice.Reason.status CoreReader.Choice.StatusKind.convention) + (@List.cons.{0} CoreReader.Choice.Reason + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.output) + (@List.nil.{0} CoreReader.Choice.Reason)))))) + (And + (And + (CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.explanation)) + (And + (CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.applicability)) + (And + (CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.simplicity)) + (And + (CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.procedure)) + (And + (CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements CoreReader.Choice.cheapSuccessor + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.simplicity)) + (Not + (CoreReader.Choice.JustifiedChoice CoreReader.Choice.identityRequirements + CoreReader.Choice.cheapSuccessor + (@List.cons.{0} CoreReader.Choice.Reason + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.simplicity) + (@List.nil.{0} CoreReader.Choice.Reason))))))))) + (And + (And (@CoreReader.Evidence.Articulated CoreReader.Choice.Candidate CoreReader.Choice.priorityArticulation) + (And (CoreReader.Choice.AssessmentAccurate Bool.false) + (And + (∀ (selected : CoreReader.Choice.Candidate), + @CoreReader.Logic.Models CoreReader.Choice.Candidate CoreReader.Choice.statusFacts selected) + (And (CoreReader.Choice.priorityClaim CoreReader.Choice.Candidate.identity) + (And (Not (CoreReader.Choice.priorityClaim CoreReader.Choice.Candidate.successor)) + (And + (Not + (@CoreReader.Logic.Entails CoreReader.Choice.Candidate CoreReader.Choice.statusFacts + CoreReader.Choice.priorityClaim)) + (Not + (CoreReader.Choice.JustifiedChoice CoreReader.Choice.identityRequirements + CoreReader.Choice.identityImpl + (@List.cons.{0} CoreReader.Choice.Reason + (CoreReader.Choice.Reason.status CoreReader.Choice.StatusKind.standing) + (@List.nil.{0} CoreReader.Choice.Reason)))))))))) + (And + (And + (∀ (n : Nat), + @Eq.{1} Nat (CoreReader.Choice.identityImpl.run n) (CoreReader.Adopted.wrongExplanation012.run n)) + (And (CoreReader.Choice.Feasible CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl) + (And + (CoreReader.Choice.Feasible CoreReader.Choice.identityRequirements CoreReader.Adopted.wrongExplanation012) + (And + (CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.explanation)) + (Not + (CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements + CoreReader.Adopted.wrongExplanation012 + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.explanation))))))) + (And + (And + (Not + (CoreReader.Adopted.choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem + CoreReader.Integration.actual).implementation + (@List.cons.{0} CoreReader.Choice.Reason + (CoreReader.Choice.Reason.status CoreReader.Choice.StatusKind.standing) + (@List.nil.{0} CoreReader.Choice.Reason)))) + (CoreReader.Adopted.choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem + CoreReader.Integration.actual).implementation + (@List.cons.{0} CoreReader.Choice.Reason + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.output) + (@List.nil.{0} CoreReader.Choice.Reason)))) + (∀ (kind : CoreReader.Choice.StatusKind), + Not + (CoreReader.Adopted.choiceSpecification CoreReader.Choice.identityRequirements + CoreReader.Choice.identityImpl + (@List.cons.{0} CoreReader.Choice.Reason (CoreReader.Choice.Reason.status kind) + (@List.nil.{0} CoreReader.Choice.Reason)))))))) +CoreReader.Adopted.choiceLimits012 : And + (And + (∀ (candidate : CoreReader.Choice.Candidate), + Iff + (CoreReader.Choice.Feasible CoreReader.Choice.identityRequirements (CoreReader.Choice.implementation candidate)) + (@Eq.{1} CoreReader.Choice.Candidate candidate CoreReader.Choice.Candidate.identity)) + (CoreReader.Choice.JustifiedChoice CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + CoreReader.Choice.objectiveReason)) + (And + (And (@Eq.{1} Bool CoreReader.Choice.identityImpl.conventional Bool.true) + (And (@Eq.{1} Bool CoreReader.Choice.identityImpl.established Bool.true) + (CoreReader.Choice.JustifiedChoice CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + (@List.cons.{0} CoreReader.Choice.Reason + (CoreReader.Choice.Reason.status CoreReader.Choice.StatusKind.convention) + (@List.cons.{0} CoreReader.Choice.Reason + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.output) + (@List.nil.{0} CoreReader.Choice.Reason)))))) + (And + (And + (∀ (n : Nat), @Eq.{1} Nat (CoreReader.Choice.identityImpl.run n) (CoreReader.Adopted.wrongExplanation012.run n)) + (And (CoreReader.Choice.Feasible CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl) + (And + (CoreReader.Choice.Feasible CoreReader.Choice.identityRequirements CoreReader.Adopted.wrongExplanation012) + (And + (CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.explanation)) + (Not + (CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements + CoreReader.Adopted.wrongExplanation012 + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.explanation))))))) + (And + (And + (CoreReader.Choice.JustifiedChoice CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + CoreReader.Choice.objectiveReason) + (@Ne.{1} Nat + (CoreReader.Choice.identityImpl.run (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Choice.successorImpl.run (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))))) + (And + (And + (∀ (x : Nat), + @Eq.{1} Nat x (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) → + @Eq.{1} Nat (CoreReader.Choice.identityImpl.run x) (CoreReader.Choice.changedOutsideZero.run x)) + (@Ne.{1} Nat + (CoreReader.Choice.identityImpl.run (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (CoreReader.Choice.changedOutsideZero.run (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))))) + (And + (And (@CoreReader.Evidence.Articulated CoreReader.Choice.Candidate CoreReader.Choice.priorityArticulation) + (And (CoreReader.Choice.AssessmentAccurate Bool.false) + (And + (∀ (selected : CoreReader.Choice.Candidate), + @CoreReader.Logic.Models CoreReader.Choice.Candidate CoreReader.Choice.statusFacts selected) + (And (CoreReader.Choice.priorityClaim CoreReader.Choice.Candidate.identity) + (And (Not (CoreReader.Choice.priorityClaim CoreReader.Choice.Candidate.successor)) + (And + (Not + (@CoreReader.Logic.Entails CoreReader.Choice.Candidate CoreReader.Choice.statusFacts + CoreReader.Choice.priorityClaim)) + (Not + (CoreReader.Choice.JustifiedChoice CoreReader.Choice.identityRequirements + CoreReader.Choice.identityImpl + (@List.cons.{0} CoreReader.Choice.Reason + (CoreReader.Choice.Reason.status CoreReader.Choice.StatusKind.standing) + (@List.nil.{0} CoreReader.Choice.Reason)))))))))) + CoreReader.Choice.PolicyIndependenceExample))))) +CoreReader.Agency.FormKind : Type +CoreReader.Agency.Form : Type +CoreReader.Agency.Aim : Type +CoreReader.Agency.Policy : Type +CoreReader.Agency.Generative : CoreReader.Agency.Policy → Prop +CoreReader.Agency.openPolicy : CoreReader.Agency.Policy +CoreReader.Agency.neutralPolicy : CoreReader.Agency.Policy +CoreReader.Agency.permissionNotValuation : And + (CoreReader.Agency.neutralPolicy.permitsVersion (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (And + (@Ne.{1} Nat (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (Not (CoreReader.Agency.Generative CoreReader.Agency.neutralPolicy))) +CoreReader.Agency.revisabilityCovers : ∀ (p : CoreReader.Agency.Policy), + CoreReader.Agency.Generative p → + ∀ (k : CoreReader.Agency.FormKind) (v : Nat), + p.current { kind := k, version := v } → p.revisable { kind := k, version := v } +CoreReader.Agency.Operation : Type +CoreReader.Agency.Operation.run : CoreReader.Agency.Operation → Nat → Nat +CoreReader.Agency.InventoryKind : Type +CoreReader.Agency.Item : Type +CoreReader.Agency.Available : List.{0} CoreReader.Agency.Item → CoreReader.Agency.Operation → Prop +CoreReader.Agency.inventoryNotCapability : ∀ (kind : CoreReader.Agency.InventoryKind) + (ops : List.{0} CoreReader.Agency.Operation) (op : CoreReader.Agency.Operation), + Iff + (CoreReader.Agency.Available + (@HAppend.hAppend.{0, 0, 0} (List.{0} CoreReader.Agency.Item) (List.{0} CoreReader.Agency.Item) + (List.{0} CoreReader.Agency.Item) + (@instHAppendOfAppend.{0} (List.{0} CoreReader.Agency.Item) (@List.instAppend.{0} CoreReader.Agency.Item)) + (@List.map.{0, 0} CoreReader.Agency.Operation CoreReader.Agency.Item (fun x => { kind := kind, content := x }) + ops) + (@List.map.{0, 0} CoreReader.Agency.Operation CoreReader.Agency.Item (fun x => { kind := kind, content := x }) + ops)) + op) + (CoreReader.Agency.Available + (@List.map.{0, 0} CoreReader.Agency.Operation CoreReader.Agency.Item (fun x => { kind := kind, content := x }) + ops) + op) +CoreReader.Agency.State : Type +CoreReader.Agency.Expanded : CoreReader.Agency.State → CoreReader.Agency.State → Prop +CoreReader.Agency.baseState : CoreReader.Agency.State +CoreReader.Agency.inflatedState : CoreReader.Agency.State +CoreReader.Agency.stableTrace : Nat → CoreReader.Agency.State +CoreReader.Agency.revisionWithoutProgress : And (CoreReader.Agency.Generative CoreReader.Agency.openPolicy) + (And + (∀ (k : CoreReader.Agency.FormKind), + CoreReader.Agency.openPolicy.revisable + { kind := k, version := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)) }) + (∀ (t : Nat), + Not + (CoreReader.Agency.Expanded (CoreReader.Agency.stableTrace t) + (CoreReader.Agency.stableTrace + (@HAdd.hAdd.{0, 0, 0} Nat Nat Nat (@instHAdd.{0} Nat instAddNat) t + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))))))) +CoreReader.Agency.ExternalResources : Type +CoreReader.Agency.assistedExecution : CoreReader.Agency.ExternalResources → Option.{0} Nat +CoreReader.Agency.availableResources : CoreReader.Agency.ExternalResources +CoreReader.Agency.StableReason : CoreReader.Agency.State → CoreReader.Agency.State → Prop +CoreReader.Agency.GeneratingSystem : Type +CoreReader.Agency.generatingSystem : CoreReader.Agency.GeneratingSystem +CoreReader.Agency.GeneratingSystem.stableAction : CoreReader.Agency.GeneratingSystem → CoreReader.Agency.State +CoreReader.Agency.GeneratingSystem.requirementsMet : CoreReader.Agency.GeneratingSystem → CoreReader.Agency.State → Prop +CoreReader.Agency.GeneratingSystem.withinBudget : CoreReader.Agency.GeneratingSystem → CoreReader.Agency.State → Prop +CoreReader.Agency.Announcement : Type +CoreReader.Agency.GeneratingSystem.report : CoreReader.Agency.GeneratingSystem → + CoreReader.Agency.State → CoreReader.Agency.Operation → Nat → Nat → CoreReader.Agency.Announcement +CoreReader.Agency.Announcement.claim : CoreReader.Agency.Announcement → Prop +CoreReader.Agency.announcementClaimImpliesExpansion : ∀ (report : CoreReader.Agency.Announcement), + report.claim → CoreReader.Agency.Expanded report.before report.after +CoreReader.Agency.inflatedAnnouncement : CoreReader.Agency.Announcement +CoreReader.Agency.inflatedAnnouncementRefuted : And + (@Eq.{1} CoreReader.Agency.State CoreReader.Agency.inflatedAnnouncement.before CoreReader.Agency.baseState) + (And (@Eq.{1} CoreReader.Agency.State CoreReader.Agency.inflatedAnnouncement.after CoreReader.Agency.inflatedState) + (And + (@Eq.{1} CoreReader.Agency.Operation CoreReader.Agency.inflatedAnnouncement.reportedNewOperation + CoreReader.Agency.Operation.successor) + (And + (@Eq.{1} Nat CoreReader.Agency.inflatedAnnouncement.input + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (And + (@Eq.{1} Nat CoreReader.Agency.inflatedAnnouncement.expectedOutput + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (And (Not CoreReader.Agency.inflatedAnnouncement.claim) + (Not + (CoreReader.Agency.Expanded CoreReader.Agency.inflatedAnnouncement.before + CoreReader.Agency.inflatedAnnouncement.after))))))) +CoreReader.Agency.TransitionCase : Type +CoreReader.Agency.extendedState : CoreReader.Agency.State +CoreReader.Agency.transitionBefore : CoreReader.Agency.TransitionCase → CoreReader.Agency.State +CoreReader.Agency.transitionAfter : CoreReader.Agency.TransitionCase → CoreReader.Agency.State +CoreReader.Agency.transitionInput : CoreReader.Agency.TransitionCase → Nat +CoreReader.Agency.transitionAnnouncement : CoreReader.Agency.TransitionCase → CoreReader.Agency.Announcement +CoreReader.Agency.generationLimits : And (CoreReader.Agency.Generative CoreReader.Agency.generatingSystem.policy) + (And + (CoreReader.Agency.generatingSystem.policy.permitsVersion + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (And (Not (CoreReader.Agency.Expanded CoreReader.Agency.generatingSystem.current CoreReader.Agency.inflatedState)) + (And + (@LT.lt.{0} Nat instLTNat + (@List.length.{0} CoreReader.Agency.Item CoreReader.Agency.generatingSystem.current.inventory) + (@List.length.{0} CoreReader.Agency.Item CoreReader.Agency.inflatedState.inventory)) + (And + (@LT.lt.{0} Nat instLTNat + (@List.length.{0} CoreReader.Agency.Operation CoreReader.Agency.generatingSystem.current.abstractionLayers) + (@List.length.{0} CoreReader.Agency.Operation CoreReader.Agency.inflatedState.abstractionLayers)) + (And + (@LT.lt.{0} Nat instLTNat + (@List.length.{0} CoreReader.Agency.Operation CoreReader.Agency.generatingSystem.current.vocabulary) + (@List.length.{0} CoreReader.Agency.Operation CoreReader.Agency.inflatedState.vocabulary)) + (And + (@Eq.{1} (Option.{0} Nat) + (CoreReader.Agency.generatingSystem.execute CoreReader.Agency.availableResources) + (@Option.some.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 6) (instOfNatNat (nat_lit 6))))) + (And + (@Eq.{1} (Option.{0} Nat) + (CoreReader.Agency.generatingSystem.execute + (have __src := CoreReader.Agency.availableResources; + { experience := @Option.none.{0} Nat, knowledge := __src.knowledge, + collaborator := __src.collaborator })) + (@Option.none.{0} Nat)) + (And + (@Eq.{1} (Option.{0} Nat) + (CoreReader.Agency.generatingSystem.execute + (have __src := CoreReader.Agency.availableResources; + { experience := __src.experience, knowledge := @Option.none.{0} Nat, + collaborator := __src.collaborator })) + (@Option.none.{0} Nat)) + (And + (@Eq.{1} (Option.{0} Nat) + (CoreReader.Agency.generatingSystem.execute + (have __src := CoreReader.Agency.availableResources; + { experience := __src.experience, knowledge := __src.knowledge, + collaborator := @Option.none.{0} Nat })) + (@Option.none.{0} Nat)) + (And + (@Eq.{1} (Option.{0} Nat) + (CoreReader.Agency.generatingSystem.execute + { experience := @Option.none.{0} Nat, knowledge := @Option.none.{0} Nat, + collaborator := @Option.none.{0} Nat }) + (@Option.none.{0} Nat)) + (And + (Not + (CoreReader.Agency.Expanded CoreReader.Agency.generatingSystem.current + CoreReader.Agency.generatingSystem.stableAction)) + (And + (@Eq.{1} CoreReader.Agency.State CoreReader.Agency.generatingSystem.stableAction + CoreReader.Agency.generatingSystem.current) + (And + (CoreReader.Agency.generatingSystem.requirementsMet + CoreReader.Agency.generatingSystem.stableAction) + (And + (CoreReader.Agency.generatingSystem.withinBudget + CoreReader.Agency.generatingSystem.stableAction) + (And + (Not (CoreReader.Agency.generatingSystem.withinBudget CoreReader.Agency.inflatedState)) + (And + (CoreReader.Agency.StableReason CoreReader.Agency.generatingSystem.current + CoreReader.Agency.inflatedState) + (And + (@Eq.{1} CoreReader.Agency.Announcement CoreReader.Agency.inflatedAnnouncement + (CoreReader.Agency.generatingSystem.report CoreReader.Agency.inflatedState + CoreReader.Agency.Operation.successor + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))))) + (And + (@Eq.{1} Nat CoreReader.Agency.inflatedAnnouncement.owner + CoreReader.Agency.generatingSystem.owner) + (And + (@Eq.{1} CoreReader.Agency.State CoreReader.Agency.inflatedAnnouncement.before + CoreReader.Agency.generatingSystem.current) + (And + (@Eq.{1} CoreReader.Agency.State CoreReader.Agency.inflatedAnnouncement.after + CoreReader.Agency.inflatedState) + (And + (@Eq.{1} CoreReader.Agency.Operation + CoreReader.Agency.inflatedAnnouncement.reportedNewOperation + CoreReader.Agency.Operation.successor) + (And + (@Eq.{1} Nat CoreReader.Agency.inflatedAnnouncement.input + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (And + (@Eq.{1} Nat CoreReader.Agency.inflatedAnnouncement.expectedOutput + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (And (Not CoreReader.Agency.inflatedAnnouncement.claim) + (Not + (CoreReader.Agency.Expanded + CoreReader.Agency.inflatedAnnouncement.before + CoreReader.Agency.inflatedAnnouncement.after)))))))))))))))))))))))))) +CoreReader.Agency.generationNotReflexivity : And (CoreReader.Agency.Generative CoreReader.Agency.openPolicy) + (Not + (CoreReader.Agency.Reflexive (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (CoreReader.Agency.ownRules (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (@List.nil.{0} CoreReader.Agency.WorkRecord))) +CoreReader.Agency.ownArithmeticPrinciple : Nat → Bool +CoreReader.Agency.selfTest : List.{0} Nat → Bool +CoreReader.Agency.selfTestDoesNotProve : And + (@Eq.{1} Bool + (CoreReader.Agency.selfTest + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))) (@List.nil.{0} Nat))) + Bool.true) + (And + (@Eq.{1} Bool + (CoreReader.Agency.ownArithmeticPrinciple (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + Bool.false) + (Not (∀ (n : Nat), @Eq.{1} Bool (CoreReader.Agency.ownArithmeticPrinciple n) Bool.true))) +CoreReader.Choice.StatusKind : Type +CoreReader.Choice.MethodReason : Type +CoreReader.Choice.Reason : Type +CoreReader.Choice.Implementation : Type +CoreReader.Choice.Requirements : Type +CoreReader.Choice.MethodContent : CoreReader.Choice.Requirements → + CoreReader.Choice.Implementation → CoreReader.Choice.MethodReason → Prop +CoreReader.Choice.Relevant : CoreReader.Choice.Requirements → + CoreReader.Choice.Implementation → CoreReader.Choice.Reason → Prop +CoreReader.Choice.Feasible : CoreReader.Choice.Requirements → CoreReader.Choice.Implementation → Prop +CoreReader.Choice.JustifiedChoice : CoreReader.Choice.Requirements → + CoreReader.Choice.Implementation → List.{0} CoreReader.Choice.Reason → Prop +CoreReader.Choice.statusOnlyFails : ∀ (req : CoreReader.Choice.Requirements) (i : CoreReader.Choice.Implementation) + (k : CoreReader.Choice.StatusKind), + Not + (CoreReader.Choice.JustifiedChoice req i + (@List.cons.{0} CoreReader.Choice.Reason (CoreReader.Choice.Reason.status k) + (@List.nil.{0} CoreReader.Choice.Reason))) +CoreReader.Choice.identityImpl : CoreReader.Choice.Implementation +CoreReader.Choice.successorImpl : CoreReader.Choice.Implementation +CoreReader.Choice.changedOutsideZero : CoreReader.Choice.Implementation +CoreReader.Choice.identityRequirements : CoreReader.Choice.Requirements +CoreReader.Choice.objectiveReason : List.{0} CoreReader.Choice.Reason +CoreReader.Choice.identityOutputReason : CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements + CoreReader.Choice.identityImpl (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.output) +CoreReader.Choice.identityFeasible : CoreReader.Choice.Feasible CoreReader.Choice.identityRequirements + CoreReader.Choice.identityImpl +CoreReader.Choice.identityJustified : CoreReader.Choice.JustifiedChoice CoreReader.Choice.identityRequirements + CoreReader.Choice.identityImpl CoreReader.Choice.objectiveReason +CoreReader.Choice.conventionWithReason : And (@Eq.{1} Bool CoreReader.Choice.identityImpl.conventional Bool.true) + (And (@Eq.{1} Bool CoreReader.Choice.identityImpl.established Bool.true) + (CoreReader.Choice.JustifiedChoice CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + (@List.cons.{0} CoreReader.Choice.Reason (CoreReader.Choice.Reason.status CoreReader.Choice.StatusKind.convention) + (@List.cons.{0} CoreReader.Choice.Reason (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.output) + (@List.nil.{0} CoreReader.Choice.Reason))))) +CoreReader.Choice.Candidate : Type +CoreReader.Choice.implementation : CoreReader.Choice.Candidate → CoreReader.Choice.Implementation +CoreReader.Choice.singleFeasible : And + (∀ (candidate : CoreReader.Choice.Candidate), + Iff (CoreReader.Choice.Feasible CoreReader.Choice.identityRequirements (CoreReader.Choice.implementation candidate)) + (@Eq.{1} CoreReader.Choice.Candidate candidate CoreReader.Choice.Candidate.identity)) + (CoreReader.Choice.JustifiedChoice CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + CoreReader.Choice.objectiveReason) +CoreReader.Choice.localNotGlobal : And + (∀ (x : Nat), + @Eq.{1} Nat x (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) → + @Eq.{1} Nat (CoreReader.Choice.identityImpl.run x) (CoreReader.Choice.changedOutsideZero.run x)) + (@Ne.{1} Nat (CoreReader.Choice.identityImpl.run (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (CoreReader.Choice.changedOutsideZero.run (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))))) +CoreReader.Choice.cheapSuccessor : CoreReader.Choice.Implementation +CoreReader.Choice.eligibleInternalReasonNotSufficient : And + (CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements CoreReader.Choice.cheapSuccessor + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.simplicity)) + (Not + (CoreReader.Choice.JustifiedChoice CoreReader.Choice.identityRequirements CoreReader.Choice.cheapSuccessor + (@List.cons.{0} CoreReader.Choice.Reason + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.simplicity) + (@List.nil.{0} CoreReader.Choice.Reason)))) +CoreReader.Choice.internalReasons : And + (CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.explanation)) + (And + (CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.applicability)) + (And + (CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.simplicity)) + (And + (CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.procedure)) + (And + (CoreReader.Choice.Relevant CoreReader.Choice.identityRequirements CoreReader.Choice.cheapSuccessor + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.simplicity)) + (Not + (CoreReader.Choice.JustifiedChoice CoreReader.Choice.identityRequirements CoreReader.Choice.cheapSuccessor + (@List.cons.{0} CoreReader.Choice.Reason + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.simplicity) + (@List.nil.{0} CoreReader.Choice.Reason)))))))) +CoreReader.Choice.openNotEquivalent : And + (CoreReader.Choice.JustifiedChoice CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + CoreReader.Choice.objectiveReason) + (@Ne.{1} Nat (CoreReader.Choice.identityImpl.run (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Choice.successorImpl.run (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))))) +CoreReader.Choice.priorityClaim : CoreReader.Logic.Claim CoreReader.Choice.Candidate +CoreReader.Choice.statusFacts : CoreReader.Logic.Theory CoreReader.Choice.Candidate +CoreReader.Choice.statusFactsModel : ∀ (selected : CoreReader.Choice.Candidate), + @CoreReader.Logic.Models CoreReader.Choice.Candidate CoreReader.Choice.statusFacts selected +CoreReader.Choice.priorityArticulation : CoreReader.Evidence.Articulation CoreReader.Choice.Candidate +CoreReader.Choice.AssessmentAccurate : Bool → Prop +CoreReader.Choice.statusDoesNotEntailPriority : Not + (@CoreReader.Logic.Entails CoreReader.Choice.Candidate CoreReader.Choice.statusFacts CoreReader.Choice.priorityClaim) +CoreReader.Choice.statusAssessmentNonEntailment : And + (@CoreReader.Evidence.Articulated CoreReader.Choice.Candidate CoreReader.Choice.priorityArticulation) + (And (CoreReader.Choice.AssessmentAccurate Bool.false) + (And + (∀ (selected : CoreReader.Choice.Candidate), + @CoreReader.Logic.Models CoreReader.Choice.Candidate CoreReader.Choice.statusFacts selected) + (And (CoreReader.Choice.priorityClaim CoreReader.Choice.Candidate.identity) + (And (Not (CoreReader.Choice.priorityClaim CoreReader.Choice.Candidate.successor)) + (And + (Not + (@CoreReader.Logic.Entails CoreReader.Choice.Candidate CoreReader.Choice.statusFacts + CoreReader.Choice.priorityClaim)) + (Not + (CoreReader.Choice.JustifiedChoice CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + (@List.cons.{0} CoreReader.Choice.Reason + (CoreReader.Choice.Reason.status CoreReader.Choice.StatusKind.standing) + (@List.nil.{0} CoreReader.Choice.Reason))))))))) +CoreReader.Choice.PriorityAssessment : Type +CoreReader.Choice.PriorityAssessment.accurate : CoreReader.Choice.PriorityAssessment → Prop +CoreReader.Choice.statusPriorityAudit : CoreReader.Choice.PriorityAssessment +CoreReader.Choice.ChoicePolicy : Type +CoreReader.Choice.GeneralAssessmentFulfilled : CoreReader.Choice.ChoicePolicy → Prop +CoreReader.Choice.AdditionalChoiceNorm : CoreReader.Choice.ChoicePolicy → Prop +CoreReader.Choice.statusPriorityPolicy : CoreReader.Choice.ChoicePolicy +CoreReader.Choice.outputPriorityPolicy : CoreReader.Choice.ChoicePolicy +CoreReader.Choice.statusPriorityAuditAccurate : CoreReader.Choice.statusPriorityAudit.accurate +CoreReader.Choice.PolicyIndependenceExample : Prop +CoreReader.Choice.policyIndependenceExample : CoreReader.Choice.PolicyIndependenceExample +CoreReader.Choice.generalGroundsNotChoice : And + (And (@CoreReader.Evidence.Articulated CoreReader.Choice.Candidate CoreReader.Choice.priorityArticulation) + (And (CoreReader.Choice.AssessmentAccurate Bool.false) + (And + (∀ (selected : CoreReader.Choice.Candidate), + @CoreReader.Logic.Models CoreReader.Choice.Candidate CoreReader.Choice.statusFacts selected) + (And (CoreReader.Choice.priorityClaim CoreReader.Choice.Candidate.identity) + (And (Not (CoreReader.Choice.priorityClaim CoreReader.Choice.Candidate.successor)) + (And + (Not + (@CoreReader.Logic.Entails CoreReader.Choice.Candidate CoreReader.Choice.statusFacts + CoreReader.Choice.priorityClaim)) + (Not + (CoreReader.Choice.JustifiedChoice CoreReader.Choice.identityRequirements CoreReader.Choice.identityImpl + (@List.cons.{0} CoreReader.Choice.Reason + (CoreReader.Choice.Reason.status CoreReader.Choice.StatusKind.standing) + (@List.nil.{0} CoreReader.Choice.Reason)))))))))) + CoreReader.Choice.PolicyIndependenceExample +CoreReader.Engineering.Maintainer : Type +CoreReader.Engineering.Tool : Type +CoreReader.Engineering.Knowledge : Type +CoreReader.Engineering.Change : Type +CoreReader.Engineering.Candidate : Type +CoreReader.Engineering.Burden : Type +CoreReader.Engineering.maintainers : List.{0} CoreReader.Engineering.Maintainer +CoreReader.Engineering.changes : List.{0} CoreReader.Engineering.Change +CoreReader.Engineering.burdens : List.{0} CoreReader.Engineering.Burden +CoreReader.Engineering.Activity : Type +CoreReader.Engineering.ActivityScope : CoreReader.Engineering.Activity → Prop +CoreReader.Engineering.Continuing : CoreReader.Engineering.Activity → Prop +CoreReader.Engineering.BoundedLifecycle : CoreReader.Engineering.Activity → Prop +CoreReader.Engineering.continuingActivity : CoreReader.Engineering.Activity +CoreReader.Engineering.temporaryActivity : CoreReader.Engineering.Activity +CoreReader.Engineering.prototypeActivity : CoreReader.Engineering.Activity +CoreReader.Engineering.retiringActivity : CoreReader.Engineering.Activity +CoreReader.Engineering.EditStep : Type +CoreReader.Engineering.changePath : CoreReader.Engineering.Candidate → + CoreReader.Engineering.Change → List.{0} CoreReader.Engineering.EditStep +CoreReader.Engineering.changeWork : CoreReader.Engineering.Candidate → CoreReader.Engineering.Change → Nat +CoreReader.Engineering.CanChange : CoreReader.Engineering.Activity → + CoreReader.Engineering.Candidate → CoreReader.Engineering.Maintainer → CoreReader.Engineering.Change → Prop +CoreReader.Engineering.ContinuingCapability : CoreReader.Engineering.Activity → + CoreReader.Engineering.Candidate → CoreReader.Engineering.Change → Prop +CoreReader.Engineering.registeredDirections : List.{0} CoreReader.Engineering.Change +CoreReader.Engineering.supportedDirections : CoreReader.Engineering.Activity → + CoreReader.Engineering.Candidate → List.{0} CoreReader.Engineering.Change +CoreReader.Engineering.MaximumRegisteredCapability : CoreReader.Engineering.Activity → + CoreReader.Engineering.Candidate → Prop +CoreReader.Engineering.passiveArtifact : List.{0} Nat → List.{0} Nat +CoreReader.Engineering.orientation : CoreReader.Engineering.Maintainer → List.{0} CoreReader.Engineering.Change +CoreReader.Engineering.EngineeringAction : Type +CoreReader.Engineering.maintainerActions : CoreReader.Engineering.Maintainer → + List.{0} CoreReader.Engineering.EngineeringAction +CoreReader.Engineering.artifactActions : List.{0} Nat → List.{0} CoreReader.Engineering.EngineeringAction +CoreReader.Engineering.subjectLifecycleCases : And + (CoreReader.Engineering.ActivityScope CoreReader.Engineering.continuingActivity) + (And + (CoreReader.Engineering.CanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.evolvable CoreReader.Engineering.Maintainer.successor + CoreReader.Engineering.Change.designRevision) + (And + (CoreReader.Engineering.CanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.evolvable CoreReader.Engineering.Maintainer.agent + CoreReader.Engineering.Change.designRevision) + (And (@Eq.{1} String CoreReader.Engineering.continuingActivity.label "temporary") + (And (CoreReader.Engineering.Continuing CoreReader.Engineering.continuingActivity) + (And (Not (CoreReader.Engineering.BoundedLifecycle CoreReader.Engineering.continuingActivity)) + (And (CoreReader.Engineering.BoundedLifecycle CoreReader.Engineering.temporaryActivity) + (And (CoreReader.Engineering.BoundedLifecycle CoreReader.Engineering.prototypeActivity) + (CoreReader.Engineering.BoundedLifecycle CoreReader.Engineering.retiringActivity)))))))) +CoreReader.Engineering.subjectLimits : And + (CoreReader.Engineering.CanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.presentSimple CoreReader.Engineering.Maintainer.original + CoreReader.Engineering.Change.designRevision) + (And + (Not + (CoreReader.Engineering.CanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.presentSimple CoreReader.Engineering.Maintainer.successor + CoreReader.Engineering.Change.designRevision)) + (And + (Not + (CoreReader.Engineering.ContinuingCapability CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.presentSimple CoreReader.Engineering.Change.designRevision)) + (And (@Eq.{1} String CoreReader.Engineering.continuingActivity.label "temporary") + (And (Not (CoreReader.Engineering.BoundedLifecycle CoreReader.Engineering.continuingActivity)) + (And + (@Ne.{1} (List.{0} CoreReader.Engineering.Change) + (CoreReader.Engineering.orientation CoreReader.Engineering.Maintainer.agent) + (@List.nil.{0} CoreReader.Engineering.Change)) + (And + (@Eq.{1} (List.{0} Nat) + (CoreReader.Engineering.passiveArtifact + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2))) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))) + (@List.nil.{0} Nat)))) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2))) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))) + (@List.nil.{0} Nat)))) + (And + (@Membership.mem.{0, 0} CoreReader.Engineering.EngineeringAction + (List.{0} CoreReader.Engineering.EngineeringAction) + (@List.instMembership.{0} CoreReader.Engineering.EngineeringAction) + (CoreReader.Engineering.maintainerActions CoreReader.Engineering.Maintainer.agent) + (CoreReader.Engineering.EngineeringAction.propose CoreReader.Engineering.Change.designRevision)) + (Not + (@Membership.mem.{0, 0} CoreReader.Engineering.EngineeringAction + (List.{0} CoreReader.Engineering.EngineeringAction) + (@List.instMembership.{0} CoreReader.Engineering.EngineeringAction) + (CoreReader.Engineering.artifactActions + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2))) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))) + (@List.nil.{0} Nat)))) + (CoreReader.Engineering.EngineeringAction.propose + CoreReader.Engineering.Change.designRevision)))))))))) +@CoreReader.Engineering.CredibleDirection : {Ground : Type} → + List.{0} Ground → + (Ground → Bool) → (Ground → CoreReader.Engineering.Change → Bool) → CoreReader.Engineering.Change → Prop +CoreReader.Engineering.DirectionGround : Type +CoreReader.Engineering.articulateGround : CoreReader.Engineering.DirectionGround → Bool +CoreReader.Engineering.supportGround : CoreReader.Engineering.DirectionGround → CoreReader.Engineering.Change → Bool +CoreReader.Engineering.initialGrounds : List.{0} CoreReader.Engineering.DirectionGround +CoreReader.Engineering.forecastGrounds : List.{0} CoreReader.Engineering.DirectionGround +CoreReader.Engineering.credible : List.{0} CoreReader.Engineering.DirectionGround → CoreReader.Engineering.Change → Prop +CoreReader.Engineering.WarrantedAccommodation : List.{0} CoreReader.Engineering.DirectionGround → + CoreReader.Engineering.Change → Nat → Nat → Prop +CoreReader.Engineering.credibilityCases : And + (CoreReader.Engineering.credible CoreReader.Engineering.initialGrounds CoreReader.Engineering.Change.designRevision) + (And + (CoreReader.Engineering.credible + (@List.cons.{0} CoreReader.Engineering.DirectionGround + (CoreReader.Engineering.DirectionGround.knowledge "queue" + (@List.cons.{0} CoreReader.Engineering.Change CoreReader.Engineering.Change.designRevision + (@List.nil.{0} CoreReader.Engineering.Change)) + "tenant-config-reload") + (@List.nil.{0} CoreReader.Engineering.DirectionGround)) + CoreReader.Engineering.Change.designRevision) + (And + (CoreReader.Engineering.credible + (@List.cons.{0} CoreReader.Engineering.DirectionGround + (CoreReader.Engineering.DirectionGround.history "queue" + (@List.cons.{0} CoreReader.Engineering.Change CoreReader.Engineering.Change.migration + (@List.cons.{0} CoreReader.Engineering.Change CoreReader.Engineering.Change.migration + (@List.nil.{0} CoreReader.Engineering.Change)))) + (@List.nil.{0} CoreReader.Engineering.DirectionGround)) + CoreReader.Engineering.Change.migration) + (And + (Not + (CoreReader.Engineering.credible (@List.nil.{0} CoreReader.Engineering.DirectionGround) + (CoreReader.Engineering.Change.other "quantum backend"))) + (And + (CoreReader.Engineering.credible CoreReader.Engineering.forecastGrounds + CoreReader.Engineering.Change.deletion) + (Not + (CoreReader.Engineering.credible CoreReader.Engineering.forecastGrounds + CoreReader.Engineering.Change.designRevision)))))) +CoreReader.Engineering.abstractionComplexity : CoreReader.Engineering.Candidate → Nat +CoreReader.Engineering.implementedVariants : List.{0} CoreReader.Engineering.Candidate +CoreReader.Engineering.CostVector : Type +CoreReader.Engineering.CostLimits : Type +CoreReader.Engineering.cost : CoreReader.Engineering.Candidate → CoreReader.Engineering.Burden → Nat +CoreReader.Engineering.normalLimits : CoreReader.Engineering.CostLimits +CoreReader.Engineering.Requirements : Type +CoreReader.Engineering.normalRequirements : CoreReader.Engineering.Requirements +CoreReader.Engineering.behavior : CoreReader.Engineering.Candidate → List.{0} Nat → List.{0} Nat +CoreReader.Engineering.CandidateProfile : Type +CoreReader.Engineering.profile : CoreReader.Engineering.Candidate → CoreReader.Engineering.CandidateProfile +CoreReader.Engineering.Meets : CoreReader.Engineering.Requirements → CoreReader.Engineering.CandidateProfile → Prop +CoreReader.Engineering.Context : Type +CoreReader.Engineering.currentContinuing : CoreReader.Engineering.Context +CoreReader.Engineering.ConcreteThreat : CoreReader.Engineering.Context → + CoreReader.Engineering.Candidate → CoreReader.Engineering.Burden → Prop +CoreReader.Engineering.HasThreat : CoreReader.Engineering.Context → CoreReader.Engineering.Candidate → Prop +CoreReader.Engineering.JustifiedDeparture : CoreReader.Engineering.Context → CoreReader.Engineering.Candidate → Prop +CoreReader.Engineering.PriorityConditions : CoreReader.Engineering.Context → Prop +CoreReader.Engineering.EvolutionPriority : CoreReader.Engineering.Context → CoreReader.Engineering.Candidate → Prop +CoreReader.Engineering.currentPriorityConditions : CoreReader.Engineering.PriorityConditions + CoreReader.Engineering.currentContinuing +CoreReader.Engineering.currentNoThreat : And + (Not + (CoreReader.Engineering.HasThreat CoreReader.Engineering.currentContinuing + CoreReader.Engineering.Candidate.evolvable)) + (Not + (CoreReader.Engineering.JustifiedDeparture CoreReader.Engineering.currentContinuing + CoreReader.Engineering.Candidate.evolvable)) +CoreReader.Engineering.threatened : CoreReader.Engineering.Burden → CoreReader.Engineering.Context +CoreReader.Engineering.priorityWhenApplicable : ∀ (ctx : CoreReader.Engineering.Context) + (chosen : CoreReader.Engineering.Candidate), + CoreReader.Engineering.EvolutionPriority ctx chosen → + CoreReader.Engineering.PriorityConditions ctx → + Not (CoreReader.Engineering.JustifiedDeparture ctx CoreReader.Engineering.Candidate.evolvable) → + And (@Eq.{1} CoreReader.Engineering.Candidate chosen CoreReader.Engineering.Candidate.evolvable) + (@LT.lt.{0} Nat instLTNat + (CoreReader.Engineering.abstractionComplexity CoreReader.Engineering.Candidate.presentSimple) + (CoreReader.Engineering.abstractionComplexity chosen)) +CoreReader.Engineering.currentSimpleViolates : Not + (CoreReader.Engineering.EvolutionPriority CoreReader.Engineering.currentContinuing + CoreReader.Engineering.Candidate.presentSimple) +CoreReader.Engineering.withEvolvableProfile : CoreReader.Engineering.CandidateProfile → CoreReader.Engineering.Context +CoreReader.Engineering.unmetRequirementsBlockPriority : And + (Not + (CoreReader.Engineering.PriorityConditions + (CoreReader.Engineering.withEvolvableProfile + (have __src := CoreReader.Engineering.profile CoreReader.Engineering.Candidate.evolvable; + { + orderOutput := + @List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2))) (@List.nil.{0} Nat)), + unsafeOperations := __src.unsafeOperations, latency := __src.latency, retention := __src.retention })))) + (And + (Not + (CoreReader.Engineering.PriorityConditions + (CoreReader.Engineering.withEvolvableProfile + (have __src := CoreReader.Engineering.profile CoreReader.Engineering.Candidate.evolvable; + { orderOutput := __src.orderOutput, + unsafeOperations := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)), latency := __src.latency, + retention := __src.retention })))) + (And + (Not + (CoreReader.Engineering.PriorityConditions + (CoreReader.Engineering.withEvolvableProfile + (have __src := CoreReader.Engineering.profile CoreReader.Engineering.Candidate.evolvable; + { orderOutput := __src.orderOutput, unsafeOperations := __src.unsafeOperations, + latency := @OfNat.ofNat.{0} Nat (nat_lit 11) (instOfNatNat (nat_lit 11)), + retention := __src.retention })))) + (Not + (CoreReader.Engineering.PriorityConditions + (CoreReader.Engineering.withEvolvableProfile + (have __src := CoreReader.Engineering.profile CoreReader.Engineering.Candidate.evolvable; + { orderOutput := __src.orderOutput, unsafeOperations := __src.unsafeOperations, latency := __src.latency, + retention := @OfNat.ofNat.{0} Nat (nat_lit 29) (instOfNatNat (nat_lit 29)) })))))) +CoreReader.Engineering.priorityConditionsCases : And + (CoreReader.Engineering.EvolutionPriority CoreReader.Engineering.currentContinuing + CoreReader.Engineering.Candidate.evolvable) + (And + (Not + (CoreReader.Engineering.Meets CoreReader.Engineering.normalRequirements + (have __src := CoreReader.Engineering.profile CoreReader.Engineering.Candidate.evolvable; + { + orderOutput := + @List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2))) (@List.nil.{0} Nat)), + unsafeOperations := __src.unsafeOperations, latency := __src.latency, retention := __src.retention }))) + (And + (Not + (CoreReader.Engineering.Meets CoreReader.Engineering.normalRequirements + (have __src := CoreReader.Engineering.profile CoreReader.Engineering.Candidate.evolvable; + { orderOutput := __src.orderOutput, + unsafeOperations := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)), latency := __src.latency, + retention := __src.retention }))) + (And + (Not + (CoreReader.Engineering.Meets CoreReader.Engineering.normalRequirements + (have __src := CoreReader.Engineering.profile CoreReader.Engineering.Candidate.evolvable; + { orderOutput := __src.orderOutput, unsafeOperations := __src.unsafeOperations, + latency := @OfNat.ofNat.{0} Nat (nat_lit 11) (instOfNatNat (nat_lit 11)), + retention := __src.retention }))) + (And + (Not + (CoreReader.Engineering.Meets CoreReader.Engineering.normalRequirements + (have __src := CoreReader.Engineering.profile CoreReader.Engineering.Candidate.evolvable; + { orderOutput := __src.orderOutput, unsafeOperations := __src.unsafeOperations, latency := __src.latency, + retention := @OfNat.ofNat.{0} Nat (nat_lit 29) (instOfNatNat (nat_lit 29)) }))) + (And + (CoreReader.Engineering.EvolutionPriority + (CoreReader.Engineering.threatened CoreReader.Engineering.Burden.verification) + CoreReader.Engineering.Candidate.presentSimple) + (And + (Not + (CoreReader.Engineering.JustifiedDeparture + (have __src := CoreReader.Engineering.threatened CoreReader.Engineering.Burden.verification; + { activity := __src.activity, required := __src.required, evidence := __src.evidence, + limits := __src.limits, departure := @Option.none.{0} CoreReader.Engineering.Burden, + profiles := __src.profiles }) + CoreReader.Engineering.Candidate.evolvable)) + (@LT.lt.{0} Nat instLTNat + (CoreReader.Engineering.abstractionComplexity CoreReader.Engineering.Candidate.evolvable) + (CoreReader.Engineering.abstractionComplexity CoreReader.Engineering.Candidate.maximal)))))))) +CoreReader.Engineering.priorityChoices : And + (CoreReader.Engineering.EvolutionPriority CoreReader.Engineering.currentContinuing + CoreReader.Engineering.Candidate.evolvable) + (And + (Not + (CoreReader.Engineering.EvolutionPriority CoreReader.Engineering.currentContinuing + CoreReader.Engineering.Candidate.presentSimple)) + (CoreReader.Engineering.EvolutionPriority + (CoreReader.Engineering.threatened CoreReader.Engineering.Burden.verification) + CoreReader.Engineering.Candidate.presentSimple)) +CoreReader.Engineering.credibilityLimits : And + (CoreReader.Engineering.credible CoreReader.Engineering.initialGrounds CoreReader.Engineering.Change.designRevision) + (And + (@Eq.{1} Nat (@List.length.{0} CoreReader.Engineering.Candidate CoreReader.Engineering.implementedVariants) + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (And + (Not + (CoreReader.Engineering.WarrantedAccommodation (@List.nil.{0} CoreReader.Engineering.DirectionGround) + (CoreReader.Engineering.Change.other "quantum backend") + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@OfNat.ofNat.{0} Nat (nat_lit 5) (instOfNatNat (nat_lit 5))))) + (And + (Not + (CoreReader.Engineering.credible CoreReader.Engineering.initialGrounds + (CoreReader.Engineering.Change.other "quantum backend"))) + (And + (CoreReader.Engineering.EvolutionPriority CoreReader.Engineering.currentContinuing + CoreReader.Engineering.Candidate.evolvable) + (And + (@LT.lt.{0} Nat instLTNat + (CoreReader.Engineering.abstractionComplexity CoreReader.Engineering.Candidate.evolvable) + (CoreReader.Engineering.abstractionComplexity CoreReader.Engineering.Candidate.maximal)) + (And + (@LT.lt.{0} Nat instLTNat + (CoreReader.Engineering.cost CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Burden.construction) + (CoreReader.Engineering.cost CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Burden.migration)) + (And + (Not + (CoreReader.Engineering.MaximumRegisteredCapability CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.evolvable)) + (And + (CoreReader.Engineering.MaximumRegisteredCapability CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.maximal) + (And + (@Eq.{1} Nat + (@List.length.{0} CoreReader.Engineering.Change + (CoreReader.Engineering.supportedDirections CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.evolvable)) + (@OfNat.ofNat.{0} Nat (nat_lit 9) (instOfNatNat (nat_lit 9)))) + (And + (@Eq.{1} Nat + (@List.length.{0} CoreReader.Engineering.Change + (CoreReader.Engineering.supportedDirections CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.maximal)) + (@OfNat.ofNat.{0} Nat (nat_lit 10) (instOfNatNat (nat_lit 10)))) + (Not + (CoreReader.Engineering.credible CoreReader.Engineering.initialGrounds + (CoreReader.Engineering.Change.other "csv export"))))))))))))) +CoreReader.Engineering.costCases : And + (CoreReader.Engineering.JustifiedDeparture + (CoreReader.Engineering.threatened CoreReader.Engineering.Burden.understanding) + CoreReader.Engineering.Candidate.evolvable) + (And + (CoreReader.Engineering.JustifiedDeparture + (CoreReader.Engineering.threatened CoreReader.Engineering.Burden.construction) + CoreReader.Engineering.Candidate.evolvable) + (And + (CoreReader.Engineering.JustifiedDeparture + (CoreReader.Engineering.threatened CoreReader.Engineering.Burden.diagnosis) + CoreReader.Engineering.Candidate.evolvable) + (And + (CoreReader.Engineering.JustifiedDeparture + (CoreReader.Engineering.threatened CoreReader.Engineering.Burden.verification) + CoreReader.Engineering.Candidate.evolvable) + (And + (CoreReader.Engineering.JustifiedDeparture + (CoreReader.Engineering.threatened CoreReader.Engineering.Burden.coordination) + CoreReader.Engineering.Candidate.evolvable) + (And + (CoreReader.Engineering.JustifiedDeparture + (CoreReader.Engineering.threatened CoreReader.Engineering.Burden.operation) + CoreReader.Engineering.Candidate.evolvable) + (And + (CoreReader.Engineering.JustifiedDeparture + (CoreReader.Engineering.threatened CoreReader.Engineering.Burden.migration) + CoreReader.Engineering.Candidate.evolvable) + (Not + (CoreReader.Engineering.JustifiedDeparture + (have __src := CoreReader.Engineering.currentContinuing; + { activity := __src.activity, required := __src.required, evidence := __src.evidence, + limits := __src.limits, + departure := @Option.some.{0} CoreReader.Engineering.Burden CoreReader.Engineering.Burden.migration, + profiles := __src.profiles }) + CoreReader.Engineering.Candidate.evolvable)))))))) +CoreReader.Engineering.orderedUnique : List.{0} Nat → List.{0} Nat +CoreReader.Engineering.orderedRefactor : List.{0} Nat → List.{0} Nat +CoreReader.Engineering.insertOrdered : Nat → List.{0} Nat → List.{0} Nat +CoreReader.Engineering.sortValues : List.{0} Nat → List.{0} Nat +CoreReader.Engineering.sortedUnique : List.{0} Nat → List.{0} Nat +CoreReader.Engineering.SoftwareState : Type +CoreReader.Engineering.originalSoftware : CoreReader.Engineering.SoftwareState +CoreReader.Engineering.transform : CoreReader.Engineering.Change → + CoreReader.Engineering.SoftwareState → CoreReader.Engineering.SoftwareState +CoreReader.Engineering.evolutionBehavior : CoreReader.Engineering.Change → List.{0} Nat → List.{0} Nat +CoreReader.Engineering.ObligationTreatment : Type +CoreReader.Engineering.ChangeClaim : Type +CoreReader.Engineering.contractInputs : List.{0} (List.{0} Nat) +@CoreReader.Engineering.PreservesOn : {Input Output : Type} → + (Input → Prop) → (Input → Output) → (Input → Output) → Prop +CoreReader.Engineering.PreservesFinite : (List.{0} Nat → List.{0} Nat) → (List.{0} Nat → List.{0} Nat) → Prop +CoreReader.Engineering.ObservableContract : Type +CoreReader.Engineering.retry : CoreReader.Engineering.ObservableContract → Nat → Bool +CoreReader.Engineering.orderContract : (List.{0} Nat → List.{0} Nat) → CoreReader.Engineering.ObservableContract +CoreReader.Engineering.originalContract : CoreReader.Engineering.ObservableContract +CoreReader.Engineering.refactoredContract : CoreReader.Engineering.ObservableContract +CoreReader.Engineering.revisedContract : CoreReader.Engineering.ObservableContract +CoreReader.Engineering.evolutionContract : CoreReader.Engineering.Change → CoreReader.Engineering.ObservableContract +CoreReader.Engineering.failureInputs : List.{0} Nat +CoreReader.Engineering.PreservesContractFinite : CoreReader.Engineering.ObservableContract → + CoreReader.Engineering.ObservableContract → Prop +CoreReader.Engineering.ContractAspect : Type +CoreReader.Engineering.PartyDependency : Type +CoreReader.Engineering.partyDependencies : List.{0} CoreReader.Engineering.PartyDependency +CoreReader.Engineering.aspectChanged : CoreReader.Engineering.ObservableContract → + CoreReader.Engineering.ObservableContract → CoreReader.Engineering.ContractAspect → Bool +CoreReader.Engineering.affectedParties : CoreReader.Engineering.ObservableContract → + CoreReader.Engineering.ObservableContract → List.{0} String +CoreReader.Engineering.ContractRevision : Type +CoreReader.Engineering.normalRevision : CoreReader.Engineering.ContractRevision +CoreReader.Engineering.RevisionDuties : CoreReader.Engineering.ObservableContract → + CoreReader.Engineering.ObservableContract → CoreReader.Engineering.ContractRevision → Prop +CoreReader.Engineering.ContractChangeAccount : CoreReader.Engineering.ObservableContract → + CoreReader.Engineering.ObservableContract → CoreReader.Engineering.ContractRevision → Prop +CoreReader.Engineering.EvolutionClaim : CoreReader.Engineering.Activity → + CoreReader.Engineering.Candidate → CoreReader.Engineering.ChangeClaim → Prop +CoreReader.Engineering.evolutionKindsCases : And + (@Eq.{1} (List.{0} String) + (CoreReader.Engineering.transform CoreReader.Engineering.Change.addition + CoreReader.Engineering.originalSoftware).capabilities + (@List.cons.{0} String "deduplicate" (@List.cons.{0} String "tenant batching" (@List.nil.{0} String)))) + (And + (@Eq.{1} Nat + (CoreReader.Engineering.transform CoreReader.Engineering.Change.replacement + CoreReader.Engineering.originalSoftware).implementation + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (And + (@Eq.{1} (List.{0} String) + (CoreReader.Engineering.transform CoreReader.Engineering.Change.deletion + CoreReader.Engineering.originalSoftware).mechanisms + (@List.cons.{0} String "queue" (@List.nil.{0} String))) + (And + (@Eq.{1} (List.{0} String) + (CoreReader.Engineering.transform CoreReader.Engineering.Change.withdrawal + CoreReader.Engineering.originalSoftware).abstractions + (@List.nil.{0} String)) + (And + (@Eq.{1} Nat + (CoreReader.Engineering.transform CoreReader.Engineering.Change.redrawing + CoreReader.Engineering.originalSoftware).boundary + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (And + (@Eq.{1} String + (CoreReader.Engineering.transform CoreReader.Engineering.Change.migration + CoreReader.Engineering.originalSoftware).technology + "portable store") + (And + (@Eq.{1} Bool + (@List.all.{0} CoreReader.Engineering.Change CoreReader.Engineering.changes fun d => + @Decidable.decide + (CoreReader.Engineering.CanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.evolvable CoreReader.Engineering.Maintainer.successor d) + (@instDecidableAnd + (@Ne.{1} (List.{0} CoreReader.Engineering.EditStep) + (CoreReader.Engineering.changePath CoreReader.Engineering.Candidate.evolvable d) + (@List.nil.{0} CoreReader.Engineering.EditStep)) + (And + (@Membership.mem.{0, 0} CoreReader.Engineering.Maintainer + (List.{0} CoreReader.Engineering.Maintainer) + (@List.instMembership.{0} CoreReader.Engineering.Maintainer) + CoreReader.Engineering.continuingActivity.participants + CoreReader.Engineering.Maintainer.successor) + (@Eq.{1} Bool + (@List.all.{0} CoreReader.Engineering.EditStep + (CoreReader.Engineering.changePath CoreReader.Engineering.Candidate.evolvable d) fun step => + (@List.contains.{0} CoreReader.Engineering.Knowledge + (@instBEqOfDecidableEq.{0} CoreReader.Engineering.Knowledge + CoreReader.Engineering.instDecidableEqKnowledge) + (CoreReader.Engineering.continuingActivity.available + CoreReader.Engineering.Maintainer.successor) + step.requires).and + (@List.contains.{0} CoreReader.Engineering.Tool + (@instBEqOfDecidableEq.{0} CoreReader.Engineering.Tool + CoreReader.Engineering.instDecidableEqTool) + CoreReader.Engineering.continuingActivity.tools step.tool)) + Bool.true)) + (@instDecidableNot + (@Eq.{1} (List.{0} CoreReader.Engineering.EditStep) + (CoreReader.Engineering.changePath CoreReader.Engineering.Candidate.evolvable d) + (@List.nil.{0} CoreReader.Engineering.EditStep)) + (@List.instDecidableEqNil.{0} CoreReader.Engineering.EditStep + (CoreReader.Engineering.changePath CoreReader.Engineering.Candidate.evolvable d))) + (@instDecidableAnd + (@Membership.mem.{0, 0} CoreReader.Engineering.Maintainer + (List.{0} CoreReader.Engineering.Maintainer) + (@List.instMembership.{0} CoreReader.Engineering.Maintainer) + CoreReader.Engineering.continuingActivity.participants + CoreReader.Engineering.Maintainer.successor) + (@Eq.{1} Bool + (@List.all.{0} CoreReader.Engineering.EditStep + (CoreReader.Engineering.changePath CoreReader.Engineering.Candidate.evolvable d) fun step => + (@List.contains.{0} CoreReader.Engineering.Knowledge + (@instBEqOfDecidableEq.{0} CoreReader.Engineering.Knowledge + CoreReader.Engineering.instDecidableEqKnowledge) + (CoreReader.Engineering.continuingActivity.available + CoreReader.Engineering.Maintainer.successor) + step.requires).and + (@List.contains.{0} CoreReader.Engineering.Tool + (@instBEqOfDecidableEq.{0} CoreReader.Engineering.Tool + CoreReader.Engineering.instDecidableEqTool) + CoreReader.Engineering.continuingActivity.tools step.tool)) + Bool.true) + (@List.instDecidableMemOfLawfulBEq.{0} CoreReader.Engineering.Maintainer + (@instBEqOfDecidableEq.{0} CoreReader.Engineering.Maintainer + CoreReader.Engineering.instDecidableEqMaintainer) + ⋯ CoreReader.Engineering.Maintainer.successor + CoreReader.Engineering.continuingActivity.participants) + (instDecidableEqBool + (@List.all.{0} CoreReader.Engineering.EditStep + (CoreReader.Engineering.changePath CoreReader.Engineering.Candidate.evolvable d) fun step => + (@List.contains.{0} CoreReader.Engineering.Knowledge + (@instBEqOfDecidableEq.{0} CoreReader.Engineering.Knowledge + CoreReader.Engineering.instDecidableEqKnowledge) + (CoreReader.Engineering.continuingActivity.available + CoreReader.Engineering.Maintainer.successor) + step.requires).and + (@List.contains.{0} CoreReader.Engineering.Tool + (@instBEqOfDecidableEq.{0} CoreReader.Engineering.Tool + CoreReader.Engineering.instDecidableEqTool) + CoreReader.Engineering.continuingActivity.tools step.tool)) + Bool.true)))) + Bool.true) + (And + (CoreReader.Engineering.EvolutionClaim CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.evolvable + { direction := CoreReader.Engineering.Change.replacement, + byMaintainer := CoreReader.Engineering.Maintainer.successor, + treatment := CoreReader.Engineering.ObligationTreatment.preserve }) + (And + (CoreReader.Engineering.EvolutionClaim CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.evolvable + { direction := CoreReader.Engineering.Change.redrawing, + byMaintainer := CoreReader.Engineering.Maintainer.agent, + treatment := CoreReader.Engineering.ObligationTreatment.revise }) + (@LT.lt.{0} Nat instLTNat + (CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.independent) + (CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.coordinated)))))))))) +CoreReader.Engineering.evolutionDimensionsLimits : And + (@Eq.{1} Nat + (CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.presentSimple + CoreReader.Engineering.Change.addition) + (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2)))) + (And + (@Eq.{1} Nat + (CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.presentSimple + CoreReader.Engineering.Change.withdrawal) + (@OfNat.ofNat.{0} Nat (nat_lit 17) (instOfNatNat (nat_lit 17)))) + (And + (@LT.lt.{0} Nat instLTNat + (CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.independent) + (CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.coordinated)) + (And + (CoreReader.Engineering.EvolutionPriority CoreReader.Engineering.currentContinuing + CoreReader.Engineering.Candidate.evolvable) + (And + (@LT.lt.{0} Nat instLTNat (@OfNat.ofNat.{0} Nat (nat_lit 9) (instOfNatNat (nat_lit 9))) + (CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.migration)) + (And + (CoreReader.Engineering.CanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.presentSimple CoreReader.Engineering.Maintainer.original + CoreReader.Engineering.Change.addition) + (And + (CoreReader.Engineering.CanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.evolvable CoreReader.Engineering.Maintainer.original + CoreReader.Engineering.Change.addition) + (And + (CoreReader.Engineering.CanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.presentSimple CoreReader.Engineering.Maintainer.original + CoreReader.Engineering.Change.designRevision) + (And + (CoreReader.Engineering.CanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.evolvable CoreReader.Engineering.Maintainer.original + CoreReader.Engineering.Change.designRevision) + (And + (@LT.lt.{0} Nat instLTNat + (CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.designRevision) + (CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.presentSimple + CoreReader.Engineering.Change.designRevision)) + (And + (@Eq.{1} Nat + (CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.addition) + (CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.presentSimple + CoreReader.Engineering.Change.addition)) + (And + (@Eq.{1} (List.{0} String) + (CoreReader.Engineering.transform (CoreReader.Engineering.Change.other "csv export") + CoreReader.Engineering.originalSoftware).capabilities + (@List.cons.{0} String "deduplicate" + (@List.cons.{0} String "csv export" (@List.nil.{0} String)))) + (And + (CoreReader.Engineering.CanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.maximal CoreReader.Engineering.Maintainer.successor + (CoreReader.Engineering.Change.other "csv export")) + (Not + (CoreReader.Engineering.CanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.evolvable CoreReader.Engineering.Maintainer.successor + (CoreReader.Engineering.Change.other "csv export"))))))))))))))) +CoreReader.Engineering.oneDimensionDoesNotEntailEveryDimension : And + (@LT.lt.{0} Nat instLTNat + (CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.designRevision) + (CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.presentSimple + CoreReader.Engineering.Change.designRevision)) + (Not + (∀ (d : CoreReader.Engineering.Change), + @LT.lt.{0} Nat instLTNat (CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.evolvable d) + (CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.presentSimple d))) +CoreReader.Engineering.propagation : CoreReader.Engineering.Candidate → CoreReader.Engineering.Change → List.{0} Nat +CoreReader.Engineering.batchCount : Nat → Nat → Nat +CoreReader.Engineering.staticBatch : Nat → Nat → Nat +CoreReader.Engineering.liveBatch : Nat → Nat → Nat +CoreReader.Engineering.StructuralEvidence : Type +CoreReader.Engineering.structuralEvidence : CoreReader.Engineering.Candidate → + CoreReader.Engineering.Change → CoreReader.Engineering.StructuralEvidence +CoreReader.Engineering.StructuralAccount : CoreReader.Engineering.Activity → + CoreReader.Engineering.Candidate → CoreReader.Engineering.StructuralEvidence → Prop +CoreReader.Engineering.InterfaceView : Type +CoreReader.Engineering.sameShape : CoreReader.Engineering.InterfaceView +CoreReader.Engineering.moduleAssumptions : List.{0} (Prod.{0, 0} Nat Nat) +CoreReader.Engineering.modulesNeedingRevision : Nat → List.{0} Nat +CoreReader.Engineering.Boundary : Type +CoreReader.Engineering.EngineeringDesign : Type +CoreReader.Engineering.privateDesign : CoreReader.Engineering.EngineeringDesign +CoreReader.Engineering.documentedDesign : CoreReader.Engineering.EngineeringDesign +CoreReader.Engineering.sortedDesign : CoreReader.Engineering.EngineeringDesign +CoreReader.Engineering.coordinatedBoundary : CoreReader.Engineering.Boundary +CoreReader.Engineering.boundaryDesign : CoreReader.Engineering.EngineeringDesign +CoreReader.Engineering.crossesBoundary : CoreReader.Engineering.EngineeringDesign → + CoreReader.Engineering.Change → CoreReader.Engineering.Boundary → Bool +CoreReader.Engineering.boundaryObligationChecked : CoreReader.Engineering.EngineeringDesign → + CoreReader.Engineering.Change → CoreReader.Engineering.Boundary → Bool +CoreReader.Engineering.omittedCallerCheck : CoreReader.Engineering.EngineeringDesign +CoreReader.Engineering.otherCalleeBoundary : CoreReader.Engineering.Boundary +CoreReader.Engineering.otherCalleeDesign : CoreReader.Engineering.EngineeringDesign +CoreReader.Engineering.actualCrossBoundaryObligation : And + (@Eq.{1} Bool + (CoreReader.Engineering.crossesBoundary CoreReader.Engineering.boundaryDesign + CoreReader.Engineering.Change.coordinated CoreReader.Engineering.coordinatedBoundary) + Bool.true) + (And + (@Eq.{1} Bool + (CoreReader.Engineering.boundaryObligationChecked CoreReader.Engineering.boundaryDesign + CoreReader.Engineering.Change.coordinated CoreReader.Engineering.coordinatedBoundary) + Bool.true) + (And + (@Eq.{1} Bool + (CoreReader.Engineering.crossesBoundary CoreReader.Engineering.omittedCallerCheck + CoreReader.Engineering.Change.coordinated CoreReader.Engineering.coordinatedBoundary) + Bool.true) + (And + (@Eq.{1} Bool + (CoreReader.Engineering.boundaryObligationChecked CoreReader.Engineering.omittedCallerCheck + CoreReader.Engineering.Change.coordinated CoreReader.Engineering.coordinatedBoundary) + Bool.false) + (And + (@Eq.{1} Bool + (CoreReader.Engineering.crossesBoundary CoreReader.Engineering.otherCalleeDesign + CoreReader.Engineering.Change.coordinated CoreReader.Engineering.otherCalleeBoundary) + Bool.false) + (@Eq.{1} Bool + (CoreReader.Engineering.boundaryObligationChecked + (have __src := CoreReader.Engineering.boundaryDesign; + { metadata := __src.metadata, run := CoreReader.Engineering.sortedUnique, paths := __src.paths, + components := __src.components, boundaries := __src.boundaries, + batchAssumptions := __src.batchAssumptions }) + CoreReader.Engineering.Change.coordinated CoreReader.Engineering.coordinatedBoundary) + Bool.false))))) +CoreReader.Engineering.structuralCases : And + (CoreReader.Engineering.StructuralAccount CoreReader.Engineering.continuingActivity + CoreReader.Engineering.Candidate.evolvable + (CoreReader.Engineering.structuralEvidence CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.designRevision)) + (And + (@Eq.{1} Nat + (@List.length.{0} Nat + (CoreReader.Engineering.propagation CoreReader.Engineering.Candidate.presentSimple + CoreReader.Engineering.Change.designRevision)) + (@OfNat.ofNat.{0} Nat (nat_lit 3) (instOfNatNat (nat_lit 3)))) + (And + (@Eq.{1} Nat + (@List.length.{0} Nat + (CoreReader.Engineering.propagation CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.designRevision)) + (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2)))) + (And + (@Eq.{1} Bool + (@List.any.{0} CoreReader.Engineering.EditStep + (CoreReader.Engineering.changePath CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.coordinated) + fun s => + (@BEq.beq.{0} Nat (@instBEqOfDecidableEq.{0} Nat instDecidableEqNat) s.component + (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2)))).and + (@BEq.beq.{0} CoreReader.Engineering.Knowledge + (@instBEqOfDecidableEq.{0} CoreReader.Engineering.Knowledge + CoreReader.Engineering.instDecidableEqKnowledge) + s.requires CoreReader.Engineering.Knowledge.publicContract)) + Bool.true) + (And + (CoreReader.Engineering.PreservesFinite CoreReader.Engineering.orderedUnique + CoreReader.Engineering.orderedRefactor) + (And + (@Ne.{1} (List.{0} (List.{0} Nat)) + (CoreReader.Engineering.structuralEvidence CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.designRevision).observedBefore + (CoreReader.Engineering.structuralEvidence CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.designRevision).observedAfter) + (And + (@Eq.{1} Nat + (CoreReader.Engineering.staticBatch (@OfNat.ofNat.{0} Nat (nat_lit 21) (instOfNatNat (nat_lit 21))) + (@OfNat.ofNat.{0} Nat (nat_lit 10) (instOfNatNat (nat_lit 10)))) + (CoreReader.Engineering.liveBatch (@OfNat.ofNat.{0} Nat (nat_lit 21) (instOfNatNat (nat_lit 21))) + (@OfNat.ofNat.{0} Nat (nat_lit 10) (instOfNatNat (nat_lit 10))))) + (And + (@Ne.{1} Nat + (CoreReader.Engineering.staticBatch (@OfNat.ofNat.{0} Nat (nat_lit 21) (instOfNatNat (nat_lit 21))) + (@OfNat.ofNat.{0} Nat (nat_lit 5) (instOfNatNat (nat_lit 5)))) + (CoreReader.Engineering.liveBatch (@OfNat.ofNat.{0} Nat (nat_lit 21) (instOfNatNat (nat_lit 21))) + (@OfNat.ofNat.{0} Nat (nat_lit 5) (instOfNatNat (nat_lit 5))))) + (And + (@Eq.{1} Nat + (CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.presentSimple + CoreReader.Engineering.Change.withdrawal) + (@OfNat.ofNat.{0} Nat (nat_lit 17) (instOfNatNat (nat_lit 17)))) + (And + (@Eq.{1} Bool + (CoreReader.Engineering.crossesBoundary CoreReader.Engineering.boundaryDesign + CoreReader.Engineering.Change.coordinated CoreReader.Engineering.coordinatedBoundary) + Bool.true) + (And + (@Eq.{1} Bool + (CoreReader.Engineering.boundaryObligationChecked CoreReader.Engineering.boundaryDesign + CoreReader.Engineering.Change.coordinated CoreReader.Engineering.coordinatedBoundary) + Bool.true) + (And + (@Eq.{1} Bool + (CoreReader.Engineering.crossesBoundary CoreReader.Engineering.omittedCallerCheck + CoreReader.Engineering.Change.coordinated CoreReader.Engineering.coordinatedBoundary) + Bool.true) + (And + (@Eq.{1} Bool + (CoreReader.Engineering.boundaryObligationChecked CoreReader.Engineering.omittedCallerCheck + CoreReader.Engineering.Change.coordinated CoreReader.Engineering.coordinatedBoundary) + Bool.false) + (And + (@Eq.{1} Bool + (CoreReader.Engineering.crossesBoundary CoreReader.Engineering.otherCalleeDesign + CoreReader.Engineering.Change.coordinated CoreReader.Engineering.otherCalleeBoundary) + Bool.false) + (@Eq.{1} Bool + (CoreReader.Engineering.boundaryObligationChecked + (have __src := CoreReader.Engineering.boundaryDesign; + { metadata := __src.metadata, run := CoreReader.Engineering.sortedUnique, + paths := __src.paths, components := __src.components, boundaries := __src.boundaries, + batchAssumptions := __src.batchAssumptions }) + CoreReader.Engineering.Change.coordinated CoreReader.Engineering.coordinatedBoundary) + Bool.false)))))))))))))) +CoreReader.Engineering.DesignCanChange : CoreReader.Engineering.Activity → + CoreReader.Engineering.EngineeringDesign → CoreReader.Engineering.Maintainer → CoreReader.Engineering.Change → Prop +CoreReader.Engineering.designWork : CoreReader.Engineering.EngineeringDesign → CoreReader.Engineering.Change → Nat +CoreReader.Engineering.designModulesNeedingRevision : CoreReader.Engineering.EngineeringDesign → Nat → List.{0} Nat +CoreReader.Engineering.introduceBoundary : CoreReader.Engineering.EngineeringDesign → + CoreReader.Engineering.EngineeringDesign +CoreReader.Engineering.wrappedDesign : CoreReader.Engineering.EngineeringDesign +CoreReader.Engineering.relocateVerification : CoreReader.Engineering.EngineeringDesign → + CoreReader.Engineering.EngineeringDesign +CoreReader.Engineering.sameWorkDesign : CoreReader.Engineering.EngineeringDesign +CoreReader.Engineering.structureNotCapability : And + (And + (@Eq.{1} String CoreReader.Engineering.privateDesign.metadata.signature + CoreReader.Engineering.sortedDesign.metadata.signature) + (And + (@Eq.{1} (List.{0} Nat) + (CoreReader.Engineering.privateDesign.run + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2))) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2))) (@List.nil.{0} Nat))))) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2))) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))) (@List.nil.{0} Nat)))) + (@Ne.{1} (List.{0} Nat) + (CoreReader.Engineering.sortedDesign.run + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2))) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2))) (@List.nil.{0} Nat))))) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2))) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))) (@List.nil.{0} Nat)))))) + (And + (And + (@Eq.{1} Nat CoreReader.Engineering.privateDesign.metadata.modules + (@List.length.{0} Nat CoreReader.Engineering.privateDesign.components)) + (And + (@Eq.{1} Nat (@List.length.{0} (Prod.{0, 0} Nat Nat) CoreReader.Engineering.privateDesign.batchAssumptions) + (@OfNat.ofNat.{0} Nat (nat_lit 8) (instOfNatNat (nat_lit 8)))) + (@Eq.{1} Nat + (@List.length.{0} Nat + (CoreReader.Engineering.designModulesNeedingRevision CoreReader.Engineering.privateDesign + (@OfNat.ofNat.{0} Nat (nat_lit 5) (instOfNatNat (nat_lit 5))))) + (@OfNat.ofNat.{0} Nat (nat_lit 8) (instOfNatNat (nat_lit 8)))))) + (And + (And (@Eq.{1} String CoreReader.Engineering.privateDesign.metadata.principle "dependency inversion") + (And + (@Eq.{1} CoreReader.Engineering.InterfaceView CoreReader.Engineering.privateDesign.metadata + CoreReader.Engineering.documentedDesign.metadata) + (And + (Not + (CoreReader.Engineering.DesignCanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.privateDesign CoreReader.Engineering.Maintainer.successor + CoreReader.Engineering.Change.designRevision)) + (CoreReader.Engineering.DesignCanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.documentedDesign CoreReader.Engineering.Maintainer.successor + CoreReader.Engineering.Change.designRevision)))) + (And + (And + (@Eq.{1} Nat + (@List.length.{0} CoreReader.Engineering.Boundary CoreReader.Engineering.privateDesign.boundaries) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (And + (@Eq.{1} Nat + (@List.length.{0} CoreReader.Engineering.Boundary CoreReader.Engineering.wrappedDesign.boundaries) + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (And + (@Eq.{1} Nat (@List.length.{0} Nat CoreReader.Engineering.wrappedDesign.components) + (@OfNat.ofNat.{0} Nat (nat_lit 9) (instOfNatNat (nat_lit 9)))) + (And + (@Eq.{1} (List.{0} CoreReader.Engineering.Boundary) CoreReader.Engineering.wrappedDesign.boundaries + (@List.cons.{0} CoreReader.Engineering.Boundary + { caller := @OfNat.ofNat.{0} Nat (nat_lit 8) (instOfNatNat (nat_lit 8)), + callee := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + contract := "List Nat → List Nat" } + (@List.nil.{0} CoreReader.Engineering.Boundary))) + (And + (@Eq.{1} (List.{0} Nat) + (CoreReader.Engineering.wrappedDesign.run + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2))) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2))) + (@List.nil.{0} Nat))))) + (CoreReader.Engineering.privateDesign.run + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2))) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2))) + (@List.nil.{0} Nat)))))) + (And + (@Eq.{1} Nat + (CoreReader.Engineering.designWork CoreReader.Engineering.privateDesign + CoreReader.Engineering.Change.designRevision) + (@OfNat.ofNat.{0} Nat (nat_lit 17) (instOfNatNat (nat_lit 17)))) + (And + (@Eq.{1} Nat + (CoreReader.Engineering.designWork CoreReader.Engineering.wrappedDesign + CoreReader.Engineering.Change.designRevision) + (@OfNat.ofNat.{0} Nat (nat_lit 18) (instOfNatNat (nat_lit 18)))) + (Not + (@LT.lt.{0} Nat instLTNat + (CoreReader.Engineering.designWork CoreReader.Engineering.wrappedDesign + CoreReader.Engineering.Change.designRevision) + (CoreReader.Engineering.designWork CoreReader.Engineering.privateDesign + CoreReader.Engineering.Change.designRevision)))))))))) + (And + (@Eq.{1} (List.{0} CoreReader.Engineering.Boundary) CoreReader.Engineering.sameWorkDesign.boundaries + (@List.cons.{0} CoreReader.Engineering.Boundary + { caller := @OfNat.ofNat.{0} Nat (nat_lit 8) (instOfNatNat (nat_lit 8)), + callee := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + contract := "List Nat → List Nat" } + (@List.nil.{0} CoreReader.Engineering.Boundary))) + (And + (@Eq.{1} Nat (@List.length.{0} Nat CoreReader.Engineering.sameWorkDesign.components) + (@OfNat.ofNat.{0} Nat (nat_lit 9) (instOfNatNat (nat_lit 9)))) + (And + (@Ne.{1} (List.{0} CoreReader.Engineering.EditStep) + (CoreReader.Engineering.sameWorkDesign.paths CoreReader.Engineering.Change.designRevision) + (CoreReader.Engineering.privateDesign.paths CoreReader.Engineering.Change.designRevision)) + (And + (@Eq.{1} (List.{0} Nat) + (CoreReader.Engineering.sameWorkDesign.run + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2))) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2))) + (@List.nil.{0} Nat))))) + (CoreReader.Engineering.privateDesign.run + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2))) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2))) + (@List.nil.{0} Nat)))))) + (And + (@Eq.{1} Nat + (CoreReader.Engineering.designWork CoreReader.Engineering.sameWorkDesign + CoreReader.Engineering.Change.designRevision) + (CoreReader.Engineering.designWork CoreReader.Engineering.privateDesign + CoreReader.Engineering.Change.designRevision)) + (And + (@Eq.{1} Nat + (CoreReader.Engineering.designWork CoreReader.Engineering.sameWorkDesign + CoreReader.Engineering.Change.designRevision) + (@OfNat.ofNat.{0} Nat (nat_lit 17) (instOfNatNat (nat_lit 17)))) + (Not + (CoreReader.Engineering.DesignCanChange CoreReader.Engineering.continuingActivity + CoreReader.Engineering.sameWorkDesign CoreReader.Engineering.Maintainer.successor + CoreReader.Engineering.Change.designRevision))))))))))) +@CoreReader.Engineering.contractPreservation : ∀ {Input Output : Type} (scope : Input → Prop) + (old new : Input → Output), + (∀ (x : Input), scope x → @Eq.{1} Output (new x) (old x)) → + @CoreReader.Engineering.PreservesOn Input Output scope old new +@CoreReader.Engineering.changedObservationNotPreserved : ∀ {Input Output : Type} (scope : Input → Prop) + (old new : Input → Output) (x : Input), + scope x → @Ne.{1} Output (new x) (old x) → Not (@CoreReader.Engineering.PreservesOn Input Output scope old new) +CoreReader.Engineering.contractRevisionObligations : ∀ (old new : CoreReader.Engineering.ObservableContract) + (r : CoreReader.Engineering.ContractRevision), + CoreReader.Engineering.ContractChangeAccount old new r → + Not (CoreReader.Engineering.PreservesContractFinite old new) → CoreReader.Engineering.RevisionDuties old new r +CoreReader.Engineering.retiredBehavior : List.{0} Nat → List.{0} Nat +CoreReader.Engineering.contractCases : And + (CoreReader.Engineering.ContractChangeAccount CoreReader.Engineering.originalContract + CoreReader.Engineering.refactoredContract CoreReader.Engineering.normalRevision) + (And + (CoreReader.Engineering.ContractChangeAccount CoreReader.Engineering.originalContract + CoreReader.Engineering.revisedContract CoreReader.Engineering.normalRevision) + (And + (Not + (CoreReader.Engineering.ContractChangeAccount CoreReader.Engineering.originalContract + CoreReader.Engineering.revisedContract + (have __src := CoreReader.Engineering.normalRevision; + { deliberate := __src.deliberate, revisedOrder := __src.revisedOrder, affected := @List.nil.{0} String, + oldFailureLimit := __src.oldFailureLimit, newFailureLimit := __src.newFailureLimit, + recordedOldFailureLimit := __src.recordedOldFailureLimit, + recordedNewFailureLimit := __src.recordedNewFailureLimit, procedure := __src.procedure }))) + (And + (CoreReader.Engineering.PreservesFinite CoreReader.Engineering.orderedUnique + CoreReader.Engineering.retiredBehavior) + (And + (@Ne.{1} (List.{0} Nat) + (CoreReader.Engineering.retiredBehavior + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 99) (instOfNatNat (nat_lit 99))) (@List.nil.{0} Nat))) + (CoreReader.Engineering.orderedUnique + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 99) (instOfNatNat (nat_lit 99))) (@List.nil.{0} Nat)))) + (CoreReader.Engineering.ContractChangeAccount CoreReader.Engineering.originalContract + CoreReader.Engineering.revisedContract + (have __src := CoreReader.Engineering.normalRevision; + { deliberate := __src.deliberate, revisedOrder := __src.revisedOrder, affected := __src.affected, + oldFailureLimit := __src.oldFailureLimit, newFailureLimit := __src.newFailureLimit, + recordedOldFailureLimit := __src.recordedOldFailureLimit, + recordedNewFailureLimit := __src.recordedNewFailureLimit, procedure := "paired audit" })))))) +CoreReader.Engineering.contractDistinctions : And + (CoreReader.Engineering.PreservesFinite CoreReader.Engineering.orderedUnique CoreReader.Engineering.orderedRefactor) + (And + (Not + (CoreReader.Engineering.PreservesFinite CoreReader.Engineering.orderedUnique CoreReader.Engineering.sortedUnique)) + (And + (@Eq.{1} Bool + (CoreReader.Engineering.retry CoreReader.Engineering.originalContract + (@OfNat.ofNat.{0} Nat (nat_lit 3) (instOfNatNat (nat_lit 3)))) + Bool.false) + (And + (@Eq.{1} Bool + (CoreReader.Engineering.retry CoreReader.Engineering.revisedContract + (@OfNat.ofNat.{0} Nat (nat_lit 3) (instOfNatNat (nat_lit 3)))) + Bool.true) + (And + (Not + (CoreReader.Engineering.PreservesContractFinite CoreReader.Engineering.originalContract + CoreReader.Engineering.revisedContract)) + (And + (@Eq.{1} (List.{0} String) + (CoreReader.Engineering.affectedParties CoreReader.Engineering.originalContract + CoreReader.Engineering.revisedContract) + (@List.cons.{0} String "queue consumer" (@List.cons.{0} String "queue operator" (@List.nil.{0} String)))) + (And + (Not + (CoreReader.Engineering.ContractChangeAccount CoreReader.Engineering.originalContract + CoreReader.Engineering.revisedContract + (have __src := CoreReader.Engineering.normalRevision; + { deliberate := __src.deliberate, revisedOrder := __src.revisedOrder, + affected := @List.cons.{0} String "queue consumer" (@List.nil.{0} String), + oldFailureLimit := __src.oldFailureLimit, newFailureLimit := __src.newFailureLimit, + recordedOldFailureLimit := __src.recordedOldFailureLimit, + recordedNewFailureLimit := __src.recordedNewFailureLimit, procedure := __src.procedure }))) + (And + (Not + (CoreReader.Engineering.ContractChangeAccount CoreReader.Engineering.originalContract + CoreReader.Engineering.revisedContract + (have __src := CoreReader.Engineering.normalRevision; + { deliberate := __src.deliberate, revisedOrder := __src.revisedOrder, affected := __src.affected, + oldFailureLimit := @OfNat.ofNat.{0} Nat (nat_lit 5) (instOfNatNat (nat_lit 5)), + newFailureLimit := __src.newFailureLimit, + recordedOldFailureLimit := @OfNat.ofNat.{0} Nat (nat_lit 5) (instOfNatNat (nat_lit 5)), + recordedNewFailureLimit := __src.recordedNewFailureLimit, procedure := __src.procedure }))) + (And + (CoreReader.Engineering.ContractChangeAccount CoreReader.Engineering.originalContract + CoreReader.Engineering.revisedContract CoreReader.Engineering.normalRevision) + (And + (CoreReader.Engineering.PreservesFinite CoreReader.Engineering.orderedUnique + CoreReader.Engineering.retiredBehavior) + (@Ne.{1} (List.{0} Nat) + (CoreReader.Engineering.retiredBehavior + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 99) (instOfNatNat (nat_lit 99))) + (@List.nil.{0} Nat))) + (CoreReader.Engineering.orderedUnique + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 99) (instOfNatNat (nat_lit 99))) + (@List.nil.{0} Nat))))))))))))) +CoreReader.Engineering.RevisionState : Type +CoreReader.Engineering.RevisionRecord : Type +CoreReader.Engineering.MaterialGroundsChanged : CoreReader.Engineering.RevisionState → + CoreReader.Engineering.RevisionState → Prop +CoreReader.Engineering.oldState : CoreReader.Engineering.RevisionState +CoreReader.Engineering.newState : CoreReader.Engineering.RevisionState +CoreReader.Engineering.HistoricalEvidence : Type +CoreReader.Engineering.observedHistory : CoreReader.Engineering.HistoricalEvidence +CoreReader.Engineering.RevisionAccountAgainst : CoreReader.Engineering.HistoricalEvidence → + CoreReader.Engineering.RevisionRecord → Prop +CoreReader.Engineering.RevisionAccount : CoreReader.Engineering.RevisionRecord → Prop +CoreReader.Engineering.failedHistoryNotRewritten : ∀ (history : CoreReader.Engineering.HistoricalEvidence) + (r : CoreReader.Engineering.RevisionRecord), + CoreReader.Engineering.RevisionAccountAgainst history r → + @Ne.{1} Nat history.predictedBatchCount history.actualBatchCount → + @Eq.{1} Bool r.reportedPredictionSucceeded Bool.false +CoreReader.Engineering.revisionRecord : CoreReader.Engineering.RevisionRecord +CoreReader.Engineering.SupportedAlternative : List.{0} CoreReader.Engineering.DirectionGround → + CoreReader.Engineering.Change → Prop +CoreReader.Engineering.RetentionJustified : CoreReader.Engineering.Context → + List.{0} CoreReader.Engineering.Change → Prop +CoreReader.Engineering.stableRecord : CoreReader.Engineering.RevisionRecord +CoreReader.Engineering.revisionCases : And + (CoreReader.Engineering.RevisionAccount CoreReader.Engineering.revisionRecord) + (And + (@Ne.{1} (List.{0} CoreReader.Engineering.Change) CoreReader.Engineering.revisionRecord.old.forecast + CoreReader.Engineering.revisionRecord.current.forecast) + (And + (@Ne.{1} Nat CoreReader.Engineering.revisionRecord.old.maintenance + CoreReader.Engineering.revisionRecord.current.maintenance) + (And + (@Ne.{1} (List.{0} CoreReader.Engineering.Maintainer) CoreReader.Engineering.revisionRecord.old.maintainers + CoreReader.Engineering.revisionRecord.current.maintainers) + (And + (@Ne.{1} Nat CoreReader.Engineering.revisionRecord.old.migrationCost + CoreReader.Engineering.revisionRecord.current.migrationCost) + (And + (@Ne.{1} Nat CoreReader.Engineering.revisionRecord.old.objectiveCapacity + CoreReader.Engineering.revisionRecord.current.objectiveCapacity) + (And + (@Ne.{1} Nat CoreReader.Engineering.revisionRecord.predictedBatchCount + CoreReader.Engineering.revisionRecord.actualBatchCount) + (And + (CoreReader.Engineering.RetentionJustified CoreReader.Engineering.currentContinuing + (@List.cons.{0} CoreReader.Engineering.Change (CoreReader.Engineering.Change.other "quantum backend") + (@List.nil.{0} CoreReader.Engineering.Change))) + (CoreReader.Engineering.RetentionJustified + (CoreReader.Engineering.threatened CoreReader.Engineering.Burden.migration) + (@List.cons.{0} CoreReader.Engineering.Change CoreReader.Engineering.Change.migration + (@List.nil.{0} CoreReader.Engineering.Change)))))))))) +CoreReader.Engineering.observations : List.{0} (Prod.{0, 0} Nat Nat) +CoreReader.Engineering.revisionsMade : List.{0} Nat +CoreReader.Engineering.agreedBatch : List.{0} CoreReader.Engineering.Maintainer → Nat → Nat → List.{0} Nat +CoreReader.Engineering.rewrittenOldRecord : CoreReader.Engineering.RevisionRecord +CoreReader.Engineering.rewrittenPredictionRecord : CoreReader.Engineering.RevisionRecord +CoreReader.Engineering.rewrittenObservationRecord : CoreReader.Engineering.RevisionRecord +CoreReader.Engineering.unrelatedSoftwareRecord : CoreReader.Engineering.RevisionRecord +CoreReader.Engineering.historicalTamperingRejected : And + (CoreReader.Engineering.RevisionAccount CoreReader.Engineering.revisionRecord) + (And (Not (CoreReader.Engineering.RevisionAccount CoreReader.Engineering.rewrittenOldRecord)) + (And (Not (CoreReader.Engineering.RevisionAccount CoreReader.Engineering.rewrittenPredictionRecord)) + (And (Not (CoreReader.Engineering.RevisionAccount CoreReader.Engineering.rewrittenObservationRecord)) + (And + (@Eq.{1} Nat CoreReader.Engineering.observedHistory.predictedBatchCount + (@OfNat.ofNat.{0} Nat (nat_lit 3) (instOfNatNat (nat_lit 3)))) + (And + (@Eq.{1} Nat CoreReader.Engineering.observedHistory.actualBatchCount + (@OfNat.ofNat.{0} Nat (nat_lit 5) (instOfNatNat (nat_lit 5)))) + (Not (CoreReader.Engineering.RevisionAccount CoreReader.Engineering.unrelatedSoftwareRecord))))))) +CoreReader.Engineering.revisionLimits : And + (CoreReader.Engineering.RevisionAccount CoreReader.Engineering.revisionRecord) + (And + (Not + (CoreReader.Engineering.RevisionAccount + (have __src := CoreReader.Engineering.revisionRecord; + { software := __src.software, old := __src.old, current := __src.current, recordedOld := __src.recordedOld, + recordedCurrent := __src.recordedCurrent, predictedBatchCount := __src.predictedBatchCount, + actualBatchCount := __src.actualBatchCount, reportedPredictionSucceeded := Bool.true, + consideredChanges := __src.consideredChanges, criticizedDirections := __src.criticizedDirections }))) + (And + (@Eq.{1} Nat (@List.length.{0} Nat CoreReader.Engineering.revisionsMade) + (@OfNat.ofNat.{0} Nat (nat_lit 3) (instOfNatNat (nat_lit 3)))) + (And + (@Eq.{1} (List.{0} Nat) + (CoreReader.Engineering.agreedBatch CoreReader.Engineering.maintainers + (@OfNat.ofNat.{0} Nat (nat_lit 21) (instOfNatNat (nat_lit 21))) + (@OfNat.ofNat.{0} Nat (nat_lit 5) (instOfNatNat (nat_lit 5)))) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 3) (instOfNatNat (nat_lit 3))) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 3) (instOfNatNat (nat_lit 3))) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 3) (instOfNatNat (nat_lit 3))) (@List.nil.{0} Nat))))) + (And + (@Eq.{1} Nat + (CoreReader.Engineering.liveBatch (@OfNat.ofNat.{0} Nat (nat_lit 21) (instOfNatNat (nat_lit 21))) + (@OfNat.ofNat.{0} Nat (nat_lit 5) (instOfNatNat (nat_lit 5)))) + (@OfNat.ofNat.{0} Nat (nat_lit 5) (instOfNatNat (nat_lit 5)))) + (And + (@Eq.{1} Bool + (@List.all.{0} (Prod.{0, 0} Nat Nat) CoreReader.Engineering.observations fun p => + @BEq.beq.{0} Nat (@instBEqOfDecidableEq.{0} Nat instDecidableEqNat) + (CoreReader.Engineering.staticBatch (@Prod.fst.{0, 0} Nat Nat p) (@Prod.snd.{0, 0} Nat Nat p)) + (CoreReader.Engineering.liveBatch (@Prod.fst.{0, 0} Nat Nat p) (@Prod.snd.{0, 0} Nat Nat p))) + Bool.true) + (And + (@Ne.{1} Nat + (CoreReader.Engineering.staticBatch (@OfNat.ofNat.{0} Nat (nat_lit 21) (instOfNatNat (nat_lit 21))) + (@OfNat.ofNat.{0} Nat (nat_lit 5) (instOfNatNat (nat_lit 5)))) + (CoreReader.Engineering.liveBatch (@OfNat.ofNat.{0} Nat (nat_lit 21) (instOfNatNat (nat_lit 21))) + (@OfNat.ofNat.{0} Nat (nat_lit 5) (instOfNatNat (nat_lit 5))))) + (And (CoreReader.Engineering.RevisionAccount CoreReader.Engineering.stableRecord) + (And + (@Eq.{1} CoreReader.Engineering.Candidate CoreReader.Engineering.stableRecord.current.choice + CoreReader.Engineering.stableRecord.old.choice) + (CoreReader.Engineering.RetentionJustified CoreReader.Engineering.currentContinuing + (@List.cons.{0} CoreReader.Engineering.Change + (CoreReader.Engineering.Change.other "quantum backend") + (@List.nil.{0} CoreReader.Engineering.Change))))))))))) +CoreReader.Engineering.groundedChanges : CoreReader.Engineering.DirectionGround → List.{0} CoreReader.Engineering.Change +CoreReader.Engineering.currentRevisionState : CoreReader.Engineering.Context → + CoreReader.Engineering.Candidate → CoreReader.Engineering.RevisionState +CoreReader.Engineering.revisionFor : CoreReader.Engineering.Context → + CoreReader.Engineering.Candidate → CoreReader.Engineering.RevisionRecord +CoreReader.Engineering.revisionContextIdentity : And + (@Eq.{1} String + (CoreReader.Engineering.revisionFor CoreReader.Engineering.currentContinuing + CoreReader.Engineering.Candidate.evolvable).software + CoreReader.Engineering.currentContinuing.activity.software) + (And + (@Eq.{1} String + (CoreReader.Engineering.revisionFor CoreReader.Engineering.currentContinuing + CoreReader.Engineering.Candidate.evolvable).software + CoreReader.Engineering.observedHistory.software) + (And + (@Eq.{1} Nat + (CoreReader.Engineering.revisionFor CoreReader.Engineering.currentContinuing + CoreReader.Engineering.Candidate.evolvable).current.maintenance + CoreReader.Engineering.currentContinuing.activity.scheduledMaintenance) + (And + (@Eq.{1} (List.{0} CoreReader.Engineering.Maintainer) + (CoreReader.Engineering.revisionFor CoreReader.Engineering.currentContinuing + CoreReader.Engineering.Candidate.evolvable).current.maintainers + CoreReader.Engineering.currentContinuing.activity.participants) + (And + (@Eq.{1} Nat + (CoreReader.Engineering.revisionFor CoreReader.Engineering.currentContinuing + CoreReader.Engineering.Candidate.evolvable).current.migrationCost + (CoreReader.Engineering.cost CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Burden.migration)) + (And + (@Eq.{1} Nat + (CoreReader.Engineering.revisionFor CoreReader.Engineering.currentContinuing + CoreReader.Engineering.Candidate.evolvable).current.objectiveCapacity + (CoreReader.Engineering.currentContinuing.limits.capacity CoreReader.Engineering.Burden.migration)) + (And + (@Eq.{1} CoreReader.Engineering.Candidate + (CoreReader.Engineering.revisionFor CoreReader.Engineering.currentContinuing + CoreReader.Engineering.Candidate.evolvable).current.choice + CoreReader.Engineering.Candidate.evolvable) + (CoreReader.Engineering.RevisionAccount + (CoreReader.Engineering.revisionFor CoreReader.Engineering.currentContinuing + CoreReader.Engineering.Candidate.evolvable)))))))) +CoreReader.Engineering.DomainSatisfied : CoreReader.Engineering.Context → CoreReader.Engineering.Candidate → Prop +CoreReader.Engineering.currentDomainSatisfied : CoreReader.Engineering.DomainSatisfied + CoreReader.Engineering.currentContinuing CoreReader.Engineering.Candidate.evolvable +CoreReader.Engineering.sharedContext : CoreReader.Engineering.Context +CoreReader.Engineering.maintainedOutput : CoreReader.Engineering.Candidate → Nat → Nat +CoreReader.Engineering.chosenImplementation : CoreReader.Engineering.Candidate → CoreReader.Choice.Implementation +CoreReader.Engineering.chosenRequirements : CoreReader.Choice.Requirements +CoreReader.Engineering.chosenReasons : List.{0} CoreReader.Choice.Reason +CoreReader.Engineering.maintainedOutputCorrect : ∀ (chosen : CoreReader.Engineering.Candidate) (n : Nat), + @Eq.{1} Nat (CoreReader.Engineering.maintainedOutput chosen n) n +CoreReader.Engineering.implementationReasoned : ∀ (chosen : CoreReader.Engineering.Candidate), + @LE.le.{0} Nat instLENat (CoreReader.Engineering.abstractionComplexity chosen) + CoreReader.Engineering.chosenRequirements.budget → + CoreReader.Adopted.choiceSpecification CoreReader.Engineering.chosenRequirements + (CoreReader.Engineering.chosenImplementation chosen) CoreReader.Engineering.chosenReasons +CoreReader.Engineering.capabilityOutput : CoreReader.Engineering.Candidate → Nat → Nat +CoreReader.Engineering.engineeringProcess : CoreReader.Engineering.Candidate → CoreReader.Evidence.Process +CoreReader.Engineering.engineeringCapability : CoreReader.Engineering.Candidate → + CoreReader.Logic.Claim CoreReader.Evidence.Process +CoreReader.Engineering.engineeringCapabilityGrounded : ∀ (chosen : CoreReader.Engineering.Candidate), + CoreReader.Adopted.capabilitySpecification (CoreReader.Engineering.engineeringProcess chosen) + (CoreReader.Engineering.engineeringCapability chosen) +CoreReader.Engineering.actualCapabilityContrast : And + (@Eq.{1} Nat + ((CoreReader.Engineering.engineeringProcess CoreReader.Engineering.Candidate.presentSimple).output + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (@OfNat.ofNat.{0} Nat (nat_lit 17) (instOfNatNat (nat_lit 17)))) + (And + (@Eq.{1} Nat + ((CoreReader.Engineering.engineeringProcess CoreReader.Engineering.Candidate.presentSimple).output + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (And + (@Eq.{1} Nat + ((CoreReader.Engineering.engineeringProcess CoreReader.Engineering.Candidate.presentSimple).output + (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2)))) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (And + (@Eq.{1} Nat + ((CoreReader.Engineering.engineeringProcess CoreReader.Engineering.Candidate.evolvable).output + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (@OfNat.ofNat.{0} Nat (nat_lit 6) (instOfNatNat (nat_lit 6)))) + (And + (@Eq.{1} Nat + ((CoreReader.Engineering.engineeringProcess CoreReader.Engineering.Candidate.evolvable).output + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (@OfNat.ofNat.{0} Nat (nat_lit 6) (instOfNatNat (nat_lit 6)))) + (@Eq.{1} Nat + ((CoreReader.Engineering.engineeringProcess CoreReader.Engineering.Candidate.evolvable).output + (@OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2)))) + (@OfNat.ofNat.{0} Nat (nat_lit 6) (instOfNatNat (nat_lit 6)))))))) +CoreReader.Engineering.presentBudgetRecord : CoreReader.Evidence.Record CoreReader.Engineering.Candidate +CoreReader.Engineering.presentBudgetClaim : CoreReader.Logic.Claim CoreReader.Engineering.Candidate +CoreReader.Engineering.budgetObservationMeaning : ∀ (candidate : CoreReader.Engineering.Candidate), + Iff + (@CoreReader.Evidence.Compatible CoreReader.Engineering.Candidate + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Engineering.Candidate) + CoreReader.Engineering.presentBudgetRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Engineering.Candidate))) + candidate) + (CoreReader.Engineering.presentBudgetClaim candidate) +CoreReader.Engineering.budgetEmpiricalFacet : CoreReader.Evidence.Facet CoreReader.Engineering.Candidate +CoreReader.Engineering.budgetEmpiricalDischarged : @CoreReader.Evidence.FacetDischarged CoreReader.Engineering.Candidate + CoreReader.Engineering.budgetEmpiricalFacet +CoreReader.Engineering.capacityClaim : CoreReader.Logic.Claim CoreReader.Engineering.Candidate +CoreReader.Engineering.capacityAssumptions : CoreReader.Logic.Theory CoreReader.Engineering.Candidate +CoreReader.Engineering.budgetInferentialFacet : CoreReader.Evidence.Facet CoreReader.Engineering.Candidate +CoreReader.Engineering.budgetInferentialDischarged : @CoreReader.Evidence.FacetDischarged + CoreReader.Engineering.Candidate CoreReader.Engineering.budgetInferentialFacet +CoreReader.Engineering.budgetScopeAccount : CoreReader.Adopted.ScopeAccount CoreReader.Engineering.Candidate +CoreReader.Engineering.budgetScopeExplained : @CoreReader.Adopted.scopeSpecification CoreReader.Engineering.Candidate + CoreReader.Engineering.budgetScopeAccount +CoreReader.Engineering.budgetObservationLimit : And + (@CoreReader.Evidence.Compatible CoreReader.Engineering.Candidate + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Engineering.Candidate) + CoreReader.Engineering.presentBudgetRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Engineering.Candidate))) + CoreReader.Engineering.Candidate.evolvable) + (Not + (@CoreReader.Evidence.Supports CoreReader.Engineering.Candidate + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Engineering.Candidate) + CoreReader.Engineering.presentBudgetRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Engineering.Candidate))) + fun candidate => + @LE.le.{0} Nat instLENat (CoreReader.Engineering.abstractionComplexity candidate) + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))))) +CoreReader.Engineering.engineeringPolicy : CoreReader.Agency.Policy +CoreReader.Engineering.engineeringGenerative : CoreReader.Adopted.generationSpecification + CoreReader.Engineering.engineeringPolicy +CoreReader.Engineering.OwnFact : Type +CoreReader.Engineering.ownFactClaim : CoreReader.Engineering.Candidate → + CoreReader.Engineering.OwnFact → CoreReader.Logic.Claim CoreReader.Engineering.Candidate +CoreReader.Engineering.actualOwnFact : ∀ (chosen : CoreReader.Engineering.Candidate), + Or (@Eq.{1} CoreReader.Engineering.Candidate chosen CoreReader.Engineering.Candidate.presentSimple) + (@Eq.{1} CoreReader.Engineering.Candidate chosen CoreReader.Engineering.Candidate.evolvable) → + ∀ (fact : CoreReader.Engineering.OwnFact), CoreReader.Engineering.ownFactClaim chosen fact chosen +CoreReader.Engineering.ownFactPremises : CoreReader.Engineering.Candidate → + CoreReader.Logic.Theory CoreReader.Engineering.Candidate +CoreReader.Engineering.actualOwnFactGrounded : ∀ (chosen : CoreReader.Engineering.Candidate), + Or (@Eq.{1} CoreReader.Engineering.Candidate chosen CoreReader.Engineering.Candidate.presentSimple) + (@Eq.{1} CoreReader.Engineering.Candidate chosen CoreReader.Engineering.Candidate.evolvable) → + ∀ (fact : CoreReader.Engineering.OwnFact), + @CoreReader.Adopted.inferentialSpecification CoreReader.Engineering.Candidate + (CoreReader.Engineering.ownFactPremises chosen) (CoreReader.Engineering.ownFactClaim chosen fact) +CoreReader.Engineering.priorityValueMeaning : ∀ (candidate : CoreReader.Engineering.Candidate), + Iff + (@CoreReader.Evidence.ValuePosition.commitment CoreReader.Engineering.Candidate + (CoreReader.Engineering.selectionPosition CoreReader.Engineering.Candidate.evolvable) candidate) + (CoreReader.Engineering.EvolutionPriority CoreReader.Engineering.sharedContext candidate) +CoreReader.Engineering.priorityGrounds : @CoreReader.Adopted.Grounds012 CoreReader.Engineering.Candidate + (CoreReader.Engineering.EvolutionPriority CoreReader.Engineering.sharedContext) + (@CoreReader.Evidence.canonicalArticulation CoreReader.Engineering.Candidate) + (@List.cons.{1} (CoreReader.Evidence.Facet CoreReader.Engineering.Candidate) + (@CoreReader.Evidence.Facet.value CoreReader.Engineering.Candidate + (CoreReader.Engineering.selectionPosition CoreReader.Engineering.Candidate.evolvable)) + (@List.nil.{1} (CoreReader.Evidence.Facet CoreReader.Engineering.Candidate))) + (@CoreReader.Adopted.AssessmentTask.value CoreReader.Engineering.Candidate + (CoreReader.Engineering.selectionPosition CoreReader.Engineering.Candidate.evolvable)) +CoreReader.Engineering.OwnNorm : Type +CoreReader.Engineering.normApplies : CoreReader.Engineering.Candidate → CoreReader.Engineering.OwnNorm → Prop +CoreReader.Engineering.ownNormClaim : CoreReader.Engineering.Candidate → + CoreReader.Engineering.OwnNorm → CoreReader.Logic.Claim CoreReader.Engineering.Candidate +CoreReader.Engineering.actualOwnNorm : ∀ (chosen : CoreReader.Engineering.Candidate), + Or (@Eq.{1} CoreReader.Engineering.Candidate chosen CoreReader.Engineering.Candidate.presentSimple) + (@Eq.{1} CoreReader.Engineering.Candidate chosen CoreReader.Engineering.Candidate.evolvable) → + ∀ (norm : CoreReader.Engineering.OwnNorm), + CoreReader.Engineering.normApplies chosen norm → CoreReader.Engineering.ownNormClaim chosen norm chosen +CoreReader.Engineering.ownFactTheory : CoreReader.Engineering.Candidate → + CoreReader.Logic.Theory CoreReader.Engineering.Candidate +CoreReader.Engineering.ownNormTheory : CoreReader.Engineering.Candidate → + CoreReader.Logic.Theory CoreReader.Engineering.Candidate +CoreReader.Engineering.ownTheory : CoreReader.Engineering.Candidate → + CoreReader.Logic.Theory CoreReader.Engineering.Candidate +CoreReader.Engineering.allNormativeContentHeld : ∀ (chosen : CoreReader.Engineering.Candidate) + (norm : CoreReader.Engineering.OwnNorm), + CoreReader.Engineering.normApplies chosen norm → + CoreReader.Engineering.ownTheory chosen (CoreReader.Engineering.ownNormClaim chosen norm) +CoreReader.Engineering.nonemptyOwnObjects : ∀ (chosen : CoreReader.Engineering.Candidate), + And + (CoreReader.Engineering.ownTheory chosen + (CoreReader.Engineering.ownFactClaim chosen CoreReader.Engineering.OwnFact.selected)) + (And + (CoreReader.Engineering.ownTheory chosen + (CoreReader.Engineering.ownFactClaim chosen + (CoreReader.Engineering.OwnFact.coreAdoption CoreReader.Engineering.CoreCommitment.grounds))) + (And + (@Membership.mem.{0, 0} CoreReader.Engineering.ReviewObject (List.{0} CoreReader.Engineering.ReviewObject) + (@List.instMembership.{0} CoreReader.Engineering.ReviewObject) + (@CoreReader.Engineering.Reflection.Model.objects CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen)) + CoreReader.Engineering.ReviewObject.activity) + (@Membership.mem.{0, 0} CoreReader.Engineering.ReviewObject (List.{0} CoreReader.Engineering.ReviewObject) + (@List.instMembership.{0} CoreReader.Engineering.ReviewObject) + (@CoreReader.Engineering.Reflection.Model.objects CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen)) + (CoreReader.Engineering.ReviewObject.commitment CoreReader.Engineering.CoreCommitment.grounds)))) +CoreReader.Engineering.comparisonContext : CoreReader.Engineering.Candidate → + CoreReader.Logic.Context CoreReader.Engineering.Candidate CoreReader.Engineering.OwnFact +CoreReader.Engineering.engineeringSnapshot : CoreReader.Engineering.Candidate → + Nat → CoreReader.Logic.Snapshot CoreReader.Engineering.Candidate CoreReader.Engineering.OwnFact +CoreReader.Engineering.currentAdmissible : ∀ (chosen : CoreReader.Engineering.Candidate), + Or (@Eq.{1} CoreReader.Engineering.Candidate chosen CoreReader.Engineering.Candidate.presentSimple) + (@Eq.{1} CoreReader.Engineering.Candidate chosen CoreReader.Engineering.Candidate.evolvable) → + @CoreReader.Logic.Admissible CoreReader.Engineering.Candidate CoreReader.Engineering.OwnFact + (CoreReader.Engineering.ownTheory chosen) (CoreReader.Engineering.comparisonContext chosen) chosen +CoreReader.Engineering.currentConsistency : ∀ (chosen : CoreReader.Engineering.Candidate), + Or (@Eq.{1} CoreReader.Engineering.Candidate chosen CoreReader.Engineering.Candidate.presentSimple) + (@Eq.{1} CoreReader.Engineering.Candidate chosen CoreReader.Engineering.Candidate.evolvable) → + @CoreReader.Adopted.consistencySpecification CoreReader.Engineering.Candidate CoreReader.Engineering.OwnFact + (CoreReader.Engineering.engineeringSnapshot CoreReader.Engineering.Candidate.evolvable + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Engineering.engineeringSnapshot chosen (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + Bool.true +CoreReader.Engineering.wholeClaimGrounded : ∀ (chosen : CoreReader.Engineering.Candidate), + Or (@Eq.{1} CoreReader.Engineering.Candidate chosen CoreReader.Engineering.Candidate.presentSimple) + (@Eq.{1} CoreReader.Engineering.Candidate chosen CoreReader.Engineering.Candidate.evolvable) → + ∀ (claim : CoreReader.Logic.Claim CoreReader.Engineering.Candidate), + CoreReader.Engineering.ownTheory chosen claim → + @CoreReader.Adopted.inferentialSpecification CoreReader.Engineering.Candidate + (CoreReader.Engineering.ownFactPremises chosen) claim +CoreReader.Engineering.incompatibleNormTheory : CoreReader.Logic.Theory CoreReader.Engineering.Candidate +CoreReader.Engineering.incompatibleNormContext : CoreReader.Logic.Context CoreReader.Engineering.Candidate Unit +CoreReader.Engineering.normativeContentVariation : And + (@Eq.{1} Bool (CoreReader.Engineering.coreAdopted CoreReader.Engineering.CoreCommitment.choice) Bool.true) + (And + (Not + (@CoreReader.Logic.Consistent CoreReader.Engineering.Candidate Unit CoreReader.Engineering.incompatibleNormTheory + CoreReader.Engineering.incompatibleNormContext)) + (And + (CoreReader.Engineering.normApplies CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.OwnNorm.domain) + (And + (Not + (CoreReader.Engineering.normApplies CoreReader.Engineering.Candidate.presentSimple + CoreReader.Engineering.OwnNorm.domain)) + (And + (CoreReader.Engineering.ownTheory CoreReader.Engineering.Candidate.evolvable + (CoreReader.Engineering.ownNormClaim CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.OwnNorm.domain)) + (Not + (CoreReader.Engineering.ownTheory CoreReader.Engineering.Candidate.presentSimple + (CoreReader.Engineering.ownNormClaim CoreReader.Engineering.Candidate.presentSimple + CoreReader.Engineering.OwnNorm.domain))))))) +CoreReader.Engineering.Inherited : CoreReader.Engineering.Context → CoreReader.Engineering.Candidate → Prop +CoreReader.Engineering.inheritedCurrent : ∀ (chosen : CoreReader.Engineering.Candidate), + Or (@Eq.{1} CoreReader.Engineering.Candidate chosen CoreReader.Engineering.Candidate.presentSimple) + (@Eq.{1} CoreReader.Engineering.Candidate chosen CoreReader.Engineering.Candidate.evolvable) → + CoreReader.Engineering.Inherited CoreReader.Engineering.sharedContext chosen +CoreReader.Engineering.inheritedMutualApplication : ∀ (ctx : CoreReader.Engineering.Context) + (chosen : CoreReader.Engineering.Candidate), + CoreReader.Engineering.Inherited ctx chosen → + And (CoreReader.Adopted.generationSpecification CoreReader.Engineering.engineeringPolicy) + (And + (@CoreReader.Adopted.reflexivitySpecification + (CoreReader.Engineering.Reflection.Target CoreReader.Engineering.ReviewObject) + (CoreReader.Engineering.Reflection.Input CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject) + (CoreReader.Engineering.Reflection.Outcome CoreReader.Engineering.ReviewCase) + (@CoreReader.Engineering.Reflection.Model.rules CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen)) + (@CoreReader.Engineering.Reflection.Model.self CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen)) + (@CoreReader.Engineering.Reflection.Model.performed CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen))) + (And + (∀ (principle : CoreReader.Engineering.CoreCommitment), + @CoreReader.Adopted.valueSpecification CoreReader.Engineering.Candidate + (CoreReader.Engineering.governancePosition principle)) + (And + (CoreReader.Adopted.capabilitySpecification (CoreReader.Engineering.engineeringProcess chosen) + (CoreReader.Engineering.engineeringCapability chosen)) + (And + (CoreReader.Adopted.choiceSpecification CoreReader.Engineering.chosenRequirements + (CoreReader.Engineering.chosenImplementation chosen) CoreReader.Engineering.chosenReasons) + (And + (∀ (fact : CoreReader.Engineering.OwnFact), + @CoreReader.Adopted.inferentialSpecification CoreReader.Engineering.Candidate + (CoreReader.Engineering.ownFactPremises chosen) (CoreReader.Engineering.ownFactClaim chosen fact)) + (And + (∀ (norm : CoreReader.Engineering.OwnNorm), + CoreReader.Engineering.normApplies chosen norm → + CoreReader.Engineering.ownTheory chosen (CoreReader.Engineering.ownNormClaim chosen norm)) + (And + (∀ (claim : CoreReader.Logic.Claim CoreReader.Engineering.Candidate), + CoreReader.Engineering.ownTheory chosen claim → + @CoreReader.Adopted.inferentialSpecification CoreReader.Engineering.Candidate + (CoreReader.Engineering.ownFactPremises chosen) claim) + (@CoreReader.Adopted.consistencySpecification CoreReader.Engineering.Candidate + CoreReader.Engineering.OwnFact + (CoreReader.Engineering.engineeringSnapshot CoreReader.Engineering.Candidate.evolvable + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Engineering.engineeringSnapshot chosen + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + Bool.true)))))))) +CoreReader.Engineering.inheritedMutualCases : And + (CoreReader.Engineering.Inherited CoreReader.Engineering.sharedContext CoreReader.Engineering.Candidate.evolvable) + (And + (@CoreReader.Adopted.valueSpecification CoreReader.Engineering.Candidate + (CoreReader.Engineering.governancePosition CoreReader.Engineering.CoreCommitment.grounds)) + (And + (CoreReader.Adopted.capabilitySpecification + (CoreReader.Engineering.engineeringProcess CoreReader.Engineering.Candidate.evolvable) + (CoreReader.Engineering.engineeringCapability CoreReader.Engineering.Candidate.evolvable)) + (And + (CoreReader.Adopted.choiceSpecification CoreReader.Engineering.chosenRequirements + (CoreReader.Engineering.chosenImplementation CoreReader.Engineering.Candidate.evolvable) + CoreReader.Engineering.chosenReasons) + (And + (@Eq.{1} CoreReader.Engineering.Reflection.Verdict + (@CoreReader.Engineering.Reflection.evaluate CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject + (@CoreReader.Engineering.Reflection.Model.input CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject + (CoreReader.Engineering.selfModel CoreReader.Engineering.Candidate.evolvable) + (@CoreReader.Engineering.Reflection.Target.mk CoreReader.Engineering.ReviewObject + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + CoreReader.Engineering.ReviewObject.evolutionMethod CoreReader.Agency.Phase.revision))) + CoreReader.Engineering.Reflection.Verdict.counterexample) + (And + (@Membership.mem.{0, 0} CoreReader.Engineering.ReviewObject (List.{0} CoreReader.Engineering.ReviewObject) + (@List.instMembership.{0} CoreReader.Engineering.ReviewObject) + (@CoreReader.Engineering.Reflection.Model.objects CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject + (CoreReader.Engineering.selfModel CoreReader.Engineering.Candidate.evolvable)) + CoreReader.Engineering.ReviewObject.generationRule) + (And + (@Membership.mem.{0, 0} CoreReader.Engineering.ReviewObject (List.{0} CoreReader.Engineering.ReviewObject) + (@List.instMembership.{0} CoreReader.Engineering.ReviewObject) + (@CoreReader.Engineering.Reflection.Model.objects CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject + (CoreReader.Engineering.selfModel CoreReader.Engineering.Candidate.evolvable)) + CoreReader.Engineering.ReviewObject.assessmentRule) + (@Eq.{1} CoreReader.Engineering.Reflection.Verdict + (@CoreReader.Engineering.Reflection.evaluate CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject + (@CoreReader.Engineering.Reflection.Model.input CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject + (CoreReader.Engineering.selfModel CoreReader.Engineering.Candidate.evolvable) + (@CoreReader.Engineering.Reflection.Target.mk CoreReader.Engineering.ReviewObject + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + CoreReader.Engineering.ReviewObject.assessmentRule CoreReader.Agency.Phase.revision))) + CoreReader.Engineering.Reflection.Verdict.counterexample))))))) +CoreReader.Engineering.priorityRemainsReflexive : ∀ (ctx : CoreReader.Engineering.Context) + (chosen : CoreReader.Engineering.Candidate), + CoreReader.Engineering.Inherited ctx chosen → + CoreReader.Engineering.DomainSatisfied ctx chosen → + CoreReader.Engineering.PriorityConditions ctx → + Not (CoreReader.Engineering.JustifiedDeparture ctx CoreReader.Engineering.Candidate.evolvable) → + And (@Eq.{1} CoreReader.Engineering.Candidate chosen CoreReader.Engineering.Candidate.evolvable) + (And + (@Membership.mem.{0, 0} CoreReader.Engineering.ReviewObject (List.{0} CoreReader.Engineering.ReviewObject) + (@List.instMembership.{0} CoreReader.Engineering.ReviewObject) + (@CoreReader.Engineering.Reflection.Model.objects CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen)) + CoreReader.Engineering.ReviewObject.priority) + (And + (@CoreReader.Adopted.reflexivitySpecification + (CoreReader.Engineering.Reflection.Target CoreReader.Engineering.ReviewObject) + (CoreReader.Engineering.Reflection.Input CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject) + (CoreReader.Engineering.Reflection.Outcome CoreReader.Engineering.ReviewCase) + (@CoreReader.Engineering.Reflection.Model.rules CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen)) + (@CoreReader.Engineering.Reflection.Model.self CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen)) + (@CoreReader.Engineering.Reflection.Model.performed CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen))) + (And + (∀ (principle : CoreReader.Engineering.CoreCommitment), + @CoreReader.Adopted.valueSpecification CoreReader.Engineering.Candidate + (CoreReader.Engineering.governancePosition principle)) + (And + (@CoreReader.Adopted.Grounds012 CoreReader.Engineering.Candidate + (CoreReader.Engineering.EvolutionPriority ctx) + (@CoreReader.Evidence.canonicalArticulation CoreReader.Engineering.Candidate) + (@List.cons.{1} (CoreReader.Evidence.Facet CoreReader.Engineering.Candidate) + (@CoreReader.Evidence.Facet.value CoreReader.Engineering.Candidate + (CoreReader.Engineering.selectionPosition CoreReader.Engineering.Candidate.evolvable)) + (@List.nil.{1} (CoreReader.Evidence.Facet CoreReader.Engineering.Candidate))) + (@CoreReader.Adopted.AssessmentTask.value CoreReader.Engineering.Candidate + (CoreReader.Engineering.selectionPosition CoreReader.Engineering.Candidate.evolvable))) + (And + (CoreReader.Engineering.ownTheory chosen + (CoreReader.Engineering.ownNormClaim chosen CoreReader.Engineering.OwnNorm.domain)) + (@CoreReader.Adopted.consistencySpecification CoreReader.Engineering.Candidate + CoreReader.Engineering.OwnFact + (CoreReader.Engineering.engineeringSnapshot CoreReader.Engineering.Candidate.evolvable + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Engineering.engineeringSnapshot chosen + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + Bool.true)))))) +CoreReader.Engineering.priorityReflexiveCases : And + (@Membership.mem.{0, 0} CoreReader.Engineering.ReviewObject (List.{0} CoreReader.Engineering.ReviewObject) + (@List.instMembership.{0} CoreReader.Engineering.ReviewObject) + (@CoreReader.Engineering.Reflection.Model.objects CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel CoreReader.Engineering.Candidate.evolvable)) + CoreReader.Engineering.ReviewObject.priority) + (And + (@Eq.{1} Bool + (CoreReader.Engineering.objectTest CoreReader.Engineering.ReviewObject.priority + (@Prod.mk.{0, 0} CoreReader.Engineering.Candidate Nat CoreReader.Engineering.Candidate.evolvable + (@OfNat.ofNat.{0} Nat (nat_lit 10) (instOfNatNat (nat_lit 10))))) + Bool.true) + (And + (@CoreReader.Engineering.Reflection.Model.performed CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject + (CoreReader.Engineering.selfModel CoreReader.Engineering.Candidate.evolvable) + { owner := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + localId := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)) } + (@CoreReader.Engineering.Reflection.Target.mk CoreReader.Engineering.ReviewObject + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) CoreReader.Engineering.ReviewObject.priority + CoreReader.Agency.Phase.revision) + (@CoreReader.Engineering.Reflection.Model.input CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject + (CoreReader.Engineering.selfModel CoreReader.Engineering.Candidate.evolvable) + (@CoreReader.Engineering.Reflection.Target.mk CoreReader.Engineering.ReviewObject + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) CoreReader.Engineering.ReviewObject.priority + CoreReader.Agency.Phase.revision)) + (@CoreReader.Engineering.Reflection.Outcome.assessed CoreReader.Engineering.ReviewCase + CoreReader.Engineering.Reflection.Verdict.supportedWithinScope)) + (And + (@Eq.{1} CoreReader.Engineering.Reflection.Verdict + (@CoreReader.Engineering.Reflection.evaluate CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject + (@CoreReader.Engineering.Reflection.Model.input CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject + (CoreReader.Engineering.selfModel CoreReader.Engineering.Candidate.evolvable) + (@CoreReader.Engineering.Reflection.Target.mk CoreReader.Engineering.ReviewObject + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + CoreReader.Engineering.ReviewObject.evolutionMethod CoreReader.Agency.Phase.revision))) + CoreReader.Engineering.Reflection.Verdict.counterexample) + (And + (@Eq.{1} Bool + (CoreReader.Engineering.objectTest CoreReader.Engineering.ReviewObject.evolutionMethod + (@Prod.mk.{0, 0} CoreReader.Engineering.Candidate Nat CoreReader.Engineering.Candidate.evolvable + (@OfNat.ofNat.{0} Nat (nat_lit 10) (instOfNatNat (nat_lit 10))))) + Bool.true) + (And + (@Eq.{1} Bool + (CoreReader.Engineering.objectTest CoreReader.Engineering.ReviewObject.evolutionMethod + (@Prod.mk.{0, 0} CoreReader.Engineering.Candidate Nat CoreReader.Engineering.Candidate.evolvable + (@OfNat.ofNat.{0} Nat (nat_lit 5) (instOfNatNat (nat_lit 5))))) + Bool.false) + (And + (@CoreReader.Adopted.Grounds012 CoreReader.Engineering.Candidate + (CoreReader.Engineering.EvolutionPriority CoreReader.Engineering.sharedContext) + (@CoreReader.Evidence.canonicalArticulation CoreReader.Engineering.Candidate) + (@List.cons.{1} (CoreReader.Evidence.Facet CoreReader.Engineering.Candidate) + (@CoreReader.Evidence.Facet.value CoreReader.Engineering.Candidate + (CoreReader.Engineering.selectionPosition CoreReader.Engineering.Candidate.evolvable)) + (@List.nil.{1} (CoreReader.Evidence.Facet CoreReader.Engineering.Candidate))) + (@CoreReader.Adopted.AssessmentTask.value CoreReader.Engineering.Candidate + (CoreReader.Engineering.selectionPosition CoreReader.Engineering.Candidate.evolvable))) + (@Eq.{1} CoreReader.Engineering.Reflection.Verdict + (@CoreReader.Engineering.Reflection.evaluate CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject + (@CoreReader.Engineering.Reflection.Model.input CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject + (CoreReader.Engineering.selfModel CoreReader.Engineering.Candidate.evolvable) + (@CoreReader.Engineering.Reflection.Target.mk CoreReader.Engineering.ReviewObject + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + CoreReader.Engineering.ReviewObject.assessmentRule CoreReader.Agency.Phase.revision))) + CoreReader.Engineering.Reflection.Verdict.counterexample))))))) +CoreReader.Engineering.jointWitness : @Exists.{1} CoreReader.Engineering.Context fun ctx => + @Exists.{1} CoreReader.Engineering.Candidate fun chosen => + And (@Eq.{1} CoreReader.Engineering.Context ctx CoreReader.Engineering.sharedContext) + (And (@Eq.{1} CoreReader.Engineering.Candidate chosen CoreReader.Engineering.Candidate.evolvable) + (And (CoreReader.Engineering.Inherited ctx chosen) + (And (CoreReader.Engineering.DomainSatisfied ctx chosen) + (And (CoreReader.Engineering.PriorityConditions ctx) + (And (Not (CoreReader.Engineering.HasThreat ctx CoreReader.Engineering.Candidate.evolvable)) + (And + (@LT.lt.{0} Nat instLTNat + (CoreReader.Engineering.abstractionComplexity CoreReader.Engineering.Candidate.presentSimple) + (CoreReader.Engineering.abstractionComplexity chosen)) + (And + (CoreReader.Engineering.CanChange ctx.activity chosen CoreReader.Engineering.Maintainer.successor + CoreReader.Engineering.Change.designRevision) + (And + (CoreReader.Engineering.CanChange ctx.activity chosen CoreReader.Engineering.Maintainer.agent + CoreReader.Engineering.Change.designRevision) + (And + (CoreReader.Engineering.ownTheory chosen + (CoreReader.Engineering.ownFactClaim chosen CoreReader.Engineering.OwnFact.selected)) + (And + (@Membership.mem.{0, 0} CoreReader.Engineering.ReviewObject + (List.{0} CoreReader.Engineering.ReviewObject) + (@List.instMembership.{0} CoreReader.Engineering.ReviewObject) + (@CoreReader.Engineering.Reflection.Model.objects CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen)) + (CoreReader.Engineering.ReviewObject.commitment + CoreReader.Engineering.CoreCommitment.grounds)) + (@CoreReader.Logic.Admissible CoreReader.Engineering.Candidate CoreReader.Engineering.OwnFact + (CoreReader.Engineering.ownTheory chosen) (CoreReader.Engineering.comparisonContext chosen) + chosen))))))))))) +CoreReader.Engineering.inheritedDoesNotEntailPriority : @Exists.{1} CoreReader.Engineering.Context fun ctx => + @Exists.{1} CoreReader.Engineering.Candidate fun chosen => + And (@Eq.{1} CoreReader.Engineering.Context ctx CoreReader.Engineering.sharedContext) + (And (@Eq.{1} CoreReader.Engineering.Candidate chosen CoreReader.Engineering.Candidate.presentSimple) + (And (CoreReader.Engineering.Inherited ctx chosen) + (And (CoreReader.Engineering.PriorityConditions ctx) + (And (CoreReader.Engineering.Continuing ctx.activity) + (And (Not (CoreReader.Engineering.BoundedLifecycle ctx.activity)) + (And (Not (CoreReader.Engineering.HasThreat ctx CoreReader.Engineering.Candidate.evolvable)) + (And (Not (CoreReader.Engineering.JustifiedDeparture ctx CoreReader.Engineering.Candidate.evolvable)) + (And + (CoreReader.Engineering.Meets ctx.required + (ctx.profiles CoreReader.Engineering.Candidate.presentSimple)) + (And + (CoreReader.Engineering.Meets ctx.required + (ctx.profiles CoreReader.Engineering.Candidate.evolvable)) + (And (CoreReader.Engineering.credible ctx.evidence CoreReader.Engineering.Change.designRevision) + (And + (CoreReader.Engineering.CanChange ctx.activity CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Maintainer.successor CoreReader.Engineering.Change.designRevision) + (And + (CoreReader.Engineering.CanChange ctx.activity CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Maintainer.agent CoreReader.Engineering.Change.designRevision) + (And + (@LT.lt.{0} Nat instLTNat + (CoreReader.Engineering.changeWork CoreReader.Engineering.Candidate.evolvable + CoreReader.Engineering.Change.designRevision) + (CoreReader.Engineering.changeWork chosen + CoreReader.Engineering.Change.designRevision)) + (And + (@LT.lt.{0} Nat instLTNat (CoreReader.Engineering.abstractionComplexity chosen) + (CoreReader.Engineering.abstractionComplexity + CoreReader.Engineering.Candidate.evolvable)) + (And + (@CoreReader.Adopted.valueSpecification CoreReader.Engineering.Candidate + (CoreReader.Engineering.selectionPosition chosen)) + (And + (@CoreReader.Evidence.ValuePosition.commitment CoreReader.Engineering.Candidate + (CoreReader.Engineering.selectionPosition chosen) chosen) + (Not (CoreReader.Engineering.EvolutionPriority ctx chosen)))))))))))))))))) +CoreReader.Engineering.Reflection.Target : Type → Type +CoreReader.Engineering.Reflection.Contract : Type → Type +CoreReader.Engineering.Reflection.Input : Type → Type → Type +CoreReader.Engineering.Reflection.Verdict : Type +CoreReader.Engineering.Reflection.Outcome : Type → Type +@CoreReader.Engineering.Reflection.evaluate : {W Object : Type} → + CoreReader.Engineering.Reflection.Input W Object → CoreReader.Engineering.Reflection.Verdict +@CoreReader.Engineering.Reflection.generate : {W Object : Type} → + CoreReader.Engineering.Reflection.Input W Object → CoreReader.Engineering.Reflection.Outcome W +@CoreReader.Engineering.Reflection.interpret : {W Object : Type} → + CoreReader.Agency.Activity → + CoreReader.Engineering.Reflection.Input W Object → CoreReader.Engineering.Reflection.Outcome W → Prop +CoreReader.Engineering.Reflection.Model : Type → Type → Type +@CoreReader.Engineering.Reflection.Model.input : {W Object : Type} → + CoreReader.Engineering.Reflection.Model W Object → + CoreReader.Engineering.Reflection.Target Object → CoreReader.Engineering.Reflection.Input W Object +@CoreReader.Engineering.Reflection.Model.self : {W Object : Type} → + CoreReader.Engineering.Reflection.Model W Object → CoreReader.Engineering.Reflection.Target Object → Prop +@CoreReader.Engineering.Reflection.Model.rule : {W Object : Type} → + CoreReader.Engineering.Reflection.Model W Object → + CoreReader.Agency.Activity → + CoreReader.Adopted.ReflexiveRule (CoreReader.Engineering.Reflection.Target Object) + (CoreReader.Engineering.Reflection.Input W Object) (CoreReader.Engineering.Reflection.Outcome W) +@CoreReader.Engineering.Reflection.Model.rules : {W Object : Type} → + CoreReader.Engineering.Reflection.Model W Object → + List.{0} + (CoreReader.Adopted.ReflexiveRule (CoreReader.Engineering.Reflection.Target Object) + (CoreReader.Engineering.Reflection.Input W Object) (CoreReader.Engineering.Reflection.Outcome W)) +@CoreReader.Engineering.Reflection.Model.performed : {W Object : Type} → + CoreReader.Engineering.Reflection.Model W Object → + CoreReader.Agency.PrincipleKey → + CoreReader.Engineering.Reflection.Target Object → + CoreReader.Engineering.Reflection.Input W Object → CoreReader.Engineering.Reflection.Outcome W → Prop +@CoreReader.Engineering.Reflection.Model.follows : {W Object : Type} → + CoreReader.Engineering.Reflection.Model W Object → Prop +@CoreReader.Engineering.Reflection.recordedReflexivity : ∀ {W Object : Type} + (m : CoreReader.Engineering.Reflection.Model W Object), + @CoreReader.Engineering.Reflection.Model.follows W Object m → + @CoreReader.Adopted.reflexivitySpecification (CoreReader.Engineering.Reflection.Target Object) + (CoreReader.Engineering.Reflection.Input W Object) (CoreReader.Engineering.Reflection.Outcome W) + (@CoreReader.Engineering.Reflection.Model.rules W Object m) + (@CoreReader.Engineering.Reflection.Model.self W Object m) + (@CoreReader.Engineering.Reflection.Model.performed W Object m) +CoreReader.Engineering.ReviewObject : Type +CoreReader.Engineering.ReviewCase : Type +CoreReader.Engineering.generationApplies : CoreReader.Engineering.ReviewObject → CoreReader.Agency.Phase → Prop +CoreReader.Engineering.assessmentApplies : CoreReader.Engineering.ReviewObject → CoreReader.Agency.Phase → Prop +CoreReader.Engineering.ruleObject : CoreReader.Agency.Activity → CoreReader.Engineering.ReviewObject +CoreReader.Engineering.ruleProbe : CoreReader.Agency.Activity → + CoreReader.Engineering.ReviewCase → + CoreReader.Engineering.Reflection.Input CoreReader.Engineering.ReviewCase CoreReader.Engineering.ReviewObject +CoreReader.Engineering.generationRuleTest : (CoreReader.Engineering.Reflection.Input CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject → + CoreReader.Engineering.Reflection.Outcome CoreReader.Engineering.ReviewCase) → + CoreReader.Engineering.ReviewCase → Bool +CoreReader.Engineering.assessmentRuleTest : (CoreReader.Engineering.Reflection.Input CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject → + CoreReader.Engineering.Reflection.Verdict) → + CoreReader.Engineering.ReviewCase → Bool +CoreReader.Engineering.sampleAwareAssessment : CoreReader.Engineering.Reflection.Input CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject → + CoreReader.Engineering.Reflection.Verdict +CoreReader.Engineering.objectTest : CoreReader.Engineering.ReviewObject → CoreReader.Engineering.ReviewCase → Bool +CoreReader.Engineering.reviewObjects : CoreReader.Engineering.Candidate → List.{0} CoreReader.Engineering.ReviewObject +CoreReader.Engineering.requestedCases : CoreReader.Engineering.Candidate → + CoreReader.Agency.Phase → List.{0} CoreReader.Engineering.ReviewCase +CoreReader.Engineering.reviewReasons : CoreReader.Engineering.ReviewObject → CoreReader.Agency.Phase → List.{0} String +CoreReader.Engineering.statedReview : CoreReader.Engineering.Candidate → + CoreReader.Agency.Activity → + CoreReader.Engineering.ReviewObject → + CoreReader.Agency.Phase → CoreReader.Engineering.Reflection.Outcome CoreReader.Engineering.ReviewCase +CoreReader.Engineering.reviewBasis : CoreReader.Engineering.Candidate → + CoreReader.Engineering.ReviewObject → CoreReader.Agency.Phase → Prop +CoreReader.Engineering.selfModel : CoreReader.Engineering.Candidate → + CoreReader.Engineering.Reflection.Model CoreReader.Engineering.ReviewCase CoreReader.Engineering.ReviewObject +CoreReader.Engineering.reviewIdentity : ∀ (chosen : CoreReader.Engineering.Candidate) + (object : CoreReader.Engineering.ReviewObject) (phase : CoreReader.Agency.Phase), + And + (@Eq.{1} CoreReader.Engineering.ReviewObject + (@CoreReader.Engineering.Reflection.Target.object CoreReader.Engineering.ReviewObject + (@CoreReader.Engineering.Reflection.Input.target CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject + (@CoreReader.Engineering.Reflection.Model.input CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen) + (@CoreReader.Engineering.Reflection.Target.mk CoreReader.Engineering.ReviewObject + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) object phase)))) + object) + (And + (@Eq.{1} (CoreReader.Engineering.ReviewCase → Bool) + (@CoreReader.Engineering.Reflection.Contract.test CoreReader.Engineering.ReviewCase + (@CoreReader.Engineering.Reflection.Input.contract CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject + (@CoreReader.Engineering.Reflection.Model.input CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen) + (@CoreReader.Engineering.Reflection.Target.mk CoreReader.Engineering.ReviewObject + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) object phase)))) + (CoreReader.Engineering.objectTest object)) + (And + (@Eq.{1} (List.{0} CoreReader.Engineering.ReviewCase) + (@CoreReader.Engineering.Reflection.Input.requested CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject + (@CoreReader.Engineering.Reflection.Model.input CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen) + (@CoreReader.Engineering.Reflection.Target.mk CoreReader.Engineering.ReviewObject + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) object phase))) + (CoreReader.Engineering.requestedCases chosen phase)) + (And + (@Eq.{1} (List.{0} String) + (@CoreReader.Engineering.Reflection.Input.reasons CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject + (@CoreReader.Engineering.Reflection.Model.input CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen) + (@CoreReader.Engineering.Reflection.Target.mk CoreReader.Engineering.ReviewObject + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) object phase))) + (CoreReader.Engineering.reviewReasons object phase)) + (@Eq.{1} Prop + (@CoreReader.Engineering.Reflection.Input.basis CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject + (@CoreReader.Engineering.Reflection.Model.input CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen) + (@CoreReader.Engineering.Reflection.Target.mk CoreReader.Engineering.ReviewObject + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) object phase))) + (CoreReader.Engineering.reviewBasis chosen object phase))))) +CoreReader.Engineering.currentSelfRecords : ∀ (chosen : CoreReader.Engineering.Candidate), + Or (@Eq.{1} CoreReader.Engineering.Candidate chosen CoreReader.Engineering.Candidate.presentSimple) + (@Eq.{1} CoreReader.Engineering.Candidate chosen CoreReader.Engineering.Candidate.evolvable) → + @CoreReader.Engineering.Reflection.Model.follows CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen) +CoreReader.Engineering.currentSelfApplication : ∀ (chosen : CoreReader.Engineering.Candidate), + Or (@Eq.{1} CoreReader.Engineering.Candidate chosen CoreReader.Engineering.Candidate.presentSimple) + (@Eq.{1} CoreReader.Engineering.Candidate chosen CoreReader.Engineering.Candidate.evolvable) → + @CoreReader.Adopted.reflexivitySpecification + (CoreReader.Engineering.Reflection.Target CoreReader.Engineering.ReviewObject) + (CoreReader.Engineering.Reflection.Input CoreReader.Engineering.ReviewCase CoreReader.Engineering.ReviewObject) + (CoreReader.Engineering.Reflection.Outcome CoreReader.Engineering.ReviewCase) + (@CoreReader.Engineering.Reflection.Model.rules CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen)) + (@CoreReader.Engineering.Reflection.Model.self CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen)) + (@CoreReader.Engineering.Reflection.Model.performed CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen)) +CoreReader.Engineering.actualSelfCriticism : ∀ (chosen : CoreReader.Engineering.Candidate), + And + (@Eq.{1} Bool + (CoreReader.Engineering.objectTest CoreReader.Engineering.ReviewObject.evolutionMethod + (@Prod.mk.{0, 0} CoreReader.Engineering.Candidate Nat chosen + (@OfNat.ofNat.{0} Nat (nat_lit 10) (instOfNatNat (nat_lit 10))))) + Bool.true) + (And + (@Eq.{1} Bool + (CoreReader.Engineering.objectTest CoreReader.Engineering.ReviewObject.evolutionMethod + (@Prod.mk.{0, 0} CoreReader.Engineering.Candidate Nat chosen + (@OfNat.ofNat.{0} Nat (nat_lit 5) (instOfNatNat (nat_lit 5))))) + Bool.false) + (And + (@Eq.{1} CoreReader.Engineering.Reflection.Verdict + (@CoreReader.Engineering.Reflection.evaluate CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject + (@CoreReader.Engineering.Reflection.Model.input CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen) + (@CoreReader.Engineering.Reflection.Target.mk CoreReader.Engineering.ReviewObject + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + CoreReader.Engineering.ReviewObject.evolutionMethod CoreReader.Agency.Phase.revision))) + CoreReader.Engineering.Reflection.Verdict.counterexample) + (And + (@Eq.{1} (CoreReader.Engineering.Reflection.Outcome CoreReader.Engineering.ReviewCase) + (CoreReader.Engineering.statedReview chosen CoreReader.Agency.Activity.generation + CoreReader.Engineering.ReviewObject.evolutionMethod CoreReader.Agency.Phase.revision) + (@CoreReader.Engineering.Reflection.Outcome.generated CoreReader.Engineering.ReviewCase + (@List.cons.{0} CoreReader.Engineering.ReviewCase + (@Prod.mk.{0, 0} CoreReader.Engineering.Candidate Nat chosen + (@OfNat.ofNat.{0} Nat (nat_lit 10) (instOfNatNat (nat_lit 10)))) + (@List.cons.{0} CoreReader.Engineering.ReviewCase + (@Prod.mk.{0, 0} CoreReader.Engineering.Candidate Nat chosen + (@OfNat.ofNat.{0} Nat (nat_lit 5) (instOfNatNat (nat_lit 5)))) + (@List.nil.{0} CoreReader.Engineering.ReviewCase))) + (@List.cons.{0} CoreReader.Engineering.ReviewCase + (@Prod.mk.{0, 0} CoreReader.Engineering.Candidate Nat chosen + (@OfNat.ofNat.{0} Nat (nat_lit 10) (instOfNatNat (nat_lit 10)))) + (@List.cons.{0} CoreReader.Engineering.ReviewCase + (@Prod.mk.{0, 0} CoreReader.Engineering.Candidate Nat chosen + (@OfNat.ofNat.{0} Nat (nat_lit 5) (instOfNatNat (nat_lit 5)))) + (@List.nil.{0} CoreReader.Engineering.ReviewCase))))) + (@Ne.{1} Nat + (CoreReader.Engineering.staticBatch (@OfNat.ofNat.{0} Nat (nat_lit 21) (instOfNatNat (nat_lit 21))) + (@OfNat.ofNat.{0} Nat (nat_lit 5) (instOfNatNat (nat_lit 5)))) + (CoreReader.Engineering.liveBatch (@OfNat.ofNat.{0} Nat (nat_lit 21) (instOfNatNat (nat_lit 21))) + (@OfNat.ofNat.{0} Nat (nat_lit 5) (instOfNatNat (nat_lit 5)))))))) +CoreReader.Engineering.ownRuleIdentity : ∀ (chosen : CoreReader.Engineering.Candidate) + (activity : CoreReader.Agency.Activity) (phase : CoreReader.Agency.Phase), + And + (@Membership.mem.{0, 0} CoreReader.Engineering.ReviewObject (List.{0} CoreReader.Engineering.ReviewObject) + (@List.instMembership.{0} CoreReader.Engineering.ReviewObject) + (@CoreReader.Engineering.Reflection.Model.objects CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen)) + (CoreReader.Engineering.ruleObject activity)) + (And + (@Eq.{1} + (CoreReader.Engineering.Reflection.Input CoreReader.Engineering.ReviewCase CoreReader.Engineering.ReviewObject → + CoreReader.Engineering.Reflection.Outcome CoreReader.Engineering.ReviewCase → Prop) + (@CoreReader.Adopted.ReflexiveRule.meaning + (CoreReader.Engineering.Reflection.Target CoreReader.Engineering.ReviewObject) + (CoreReader.Engineering.Reflection.Input CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject) + (CoreReader.Engineering.Reflection.Outcome CoreReader.Engineering.ReviewCase) + (@CoreReader.Engineering.Reflection.Model.rule CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen) activity)) + (@CoreReader.Engineering.Reflection.interpret CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject activity)) + (And + (@Eq.{1} (CoreReader.Engineering.ReviewCase → Bool) + (@CoreReader.Engineering.Reflection.Contract.test CoreReader.Engineering.ReviewCase + (@CoreReader.Engineering.Reflection.Input.contract CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject + (@CoreReader.Engineering.Reflection.Model.input CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen) + (@CoreReader.Engineering.Reflection.Target.mk CoreReader.Engineering.ReviewObject + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (CoreReader.Engineering.ruleObject activity) phase)))) + (CoreReader.Engineering.objectTest (CoreReader.Engineering.ruleObject activity))) + (And + (@Eq.{1} Prop + (@CoreReader.Engineering.Reflection.Model.generationApplies CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen) + (CoreReader.Engineering.ruleObject activity) phase) + (CoreReader.Engineering.generationApplies (CoreReader.Engineering.ruleObject activity) phase)) + (@Eq.{1} Prop + (@CoreReader.Engineering.Reflection.Model.assessmentApplies CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen) + (CoreReader.Engineering.ruleObject activity) phase) + (CoreReader.Engineering.assessmentApplies (CoreReader.Engineering.ruleObject activity) phase))))) +CoreReader.Engineering.ownRuleContentVariation : ∀ (chosen : CoreReader.Engineering.Candidate), + And + (@Eq.{1} Bool + (CoreReader.Engineering.generationRuleTest + (@CoreReader.Engineering.Reflection.generate CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject) + (@Prod.mk.{0, 0} CoreReader.Engineering.Candidate Nat chosen + (@OfNat.ofNat.{0} Nat (nat_lit 10) (instOfNatNat (nat_lit 10))))) + Bool.true) + (And + (@Eq.{1} Bool + (CoreReader.Engineering.generationRuleTest + (fun x => + @CoreReader.Engineering.Reflection.Outcome.generated CoreReader.Engineering.ReviewCase + (@List.nil.{0} CoreReader.Engineering.ReviewCase) (@List.nil.{0} CoreReader.Engineering.ReviewCase)) + (@Prod.mk.{0, 0} CoreReader.Engineering.Candidate Nat chosen + (@OfNat.ofNat.{0} Nat (nat_lit 10) (instOfNatNat (nat_lit 10))))) + Bool.false) + (And + (@Eq.{1} Bool + (CoreReader.Engineering.assessmentRuleTest + (@CoreReader.Engineering.Reflection.evaluate CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject) + (@Prod.mk.{0, 0} CoreReader.Engineering.Candidate Nat chosen + (@OfNat.ofNat.{0} Nat (nat_lit 10) (instOfNatNat (nat_lit 10))))) + Bool.true) + (And + (@Eq.{1} Bool + (CoreReader.Engineering.assessmentRuleTest + (@CoreReader.Engineering.Reflection.evaluate CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject) + (@Prod.mk.{0, 0} CoreReader.Engineering.Candidate Nat chosen + (@OfNat.ofNat.{0} Nat (nat_lit 5) (instOfNatNat (nat_lit 5))))) + Bool.false) + (And + (@Eq.{1} CoreReader.Engineering.Reflection.Verdict + (@CoreReader.Engineering.Reflection.evaluate CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject + (@CoreReader.Engineering.Reflection.Model.input CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen) + (@CoreReader.Engineering.Reflection.Target.mk CoreReader.Engineering.ReviewObject + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + CoreReader.Engineering.ReviewObject.assessmentRule CoreReader.Agency.Phase.revision))) + CoreReader.Engineering.Reflection.Verdict.counterexample) + (And + (CoreReader.Engineering.generationApplies CoreReader.Engineering.ReviewObject.generationRule + CoreReader.Agency.Phase.formation) + (And + (CoreReader.Engineering.generationApplies CoreReader.Engineering.ReviewObject.generationRule + CoreReader.Agency.Phase.revision) + (And + (Not + (CoreReader.Engineering.generationApplies CoreReader.Engineering.ReviewObject.generationRule + CoreReader.Agency.Phase.application)) + (∀ (phase : CoreReader.Agency.Phase), + CoreReader.Engineering.assessmentApplies CoreReader.Engineering.ReviewObject.assessmentRule + phase)))))))) +CoreReader.Engineering.proposedRuleRevision : ∀ (chosen : CoreReader.Engineering.Candidate), + And + (@Eq.{1} Bool + (CoreReader.Engineering.assessmentRuleTest + (@CoreReader.Engineering.Reflection.evaluate CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject) + (@Prod.mk.{0, 0} CoreReader.Engineering.Candidate Nat chosen + (@OfNat.ofNat.{0} Nat (nat_lit 5) (instOfNatNat (nat_lit 5))))) + Bool.false) + (And + (@Eq.{1} Bool + (CoreReader.Engineering.assessmentRuleTest CoreReader.Engineering.sampleAwareAssessment + (@Prod.mk.{0, 0} CoreReader.Engineering.Candidate Nat chosen + (@OfNat.ofNat.{0} Nat (nat_lit 5) (instOfNatNat (nat_lit 5))))) + Bool.true) + (And + (@Eq.{1} Bool + (CoreReader.Engineering.assessmentRuleTest CoreReader.Engineering.sampleAwareAssessment + (@Prod.mk.{0, 0} CoreReader.Engineering.Candidate Nat chosen + (@OfNat.ofNat.{0} Nat (nat_lit 10) (instOfNatNat (nat_lit 10))))) + Bool.true) + (And + (@CoreReader.Adopted.ReflexiveRule.applicable + (CoreReader.Engineering.Reflection.Target CoreReader.Engineering.ReviewObject) + (CoreReader.Engineering.Reflection.Input CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject) + (CoreReader.Engineering.Reflection.Outcome CoreReader.Engineering.ReviewCase) + (@CoreReader.Engineering.Reflection.Model.rule CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject (CoreReader.Engineering.selfModel chosen) + CoreReader.Agency.Activity.generation) + (@CoreReader.Engineering.Reflection.Target.mk CoreReader.Engineering.ReviewObject + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + CoreReader.Engineering.ReviewObject.generationRule CoreReader.Agency.Phase.revision)) + (Not + (@CoreReader.Adopted.ReflexiveRule.applicable + (CoreReader.Engineering.Reflection.Target CoreReader.Engineering.ReviewObject) + (CoreReader.Engineering.Reflection.Input CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject) + (CoreReader.Engineering.Reflection.Outcome CoreReader.Engineering.ReviewCase) + (@CoreReader.Engineering.Reflection.Model.rule CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject + (have __src := CoreReader.Engineering.selfModel chosen; + @CoreReader.Engineering.Reflection.Model.mk CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject + (@CoreReader.Engineering.Reflection.Model.owner CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject __src) + (@CoreReader.Engineering.Reflection.Model.objects CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject __src) + (@CoreReader.Engineering.Reflection.Model.contracts CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject __src) + (@CoreReader.Engineering.Reflection.Model.requested CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject __src) + (@CoreReader.Engineering.Reflection.Model.reasons CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject __src) + (@CoreReader.Engineering.Reflection.Model.basis CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject __src) + (fun x x_1 => False) + (@CoreReader.Engineering.Reflection.Model.assessmentApplies CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject __src) + (@CoreReader.Engineering.Reflection.Model.recorded CoreReader.Engineering.ReviewCase + CoreReader.Engineering.ReviewObject __src)) + CoreReader.Agency.Activity.generation) + (@CoreReader.Engineering.Reflection.Target.mk CoreReader.Engineering.ReviewObject + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + CoreReader.Engineering.ReviewObject.generationRule CoreReader.Agency.Phase.revision)))))) +CoreReader.Engineering.CoreCommitment : Type +CoreReader.Engineering.coreCommitments : List.{0} CoreReader.Engineering.CoreCommitment +CoreReader.Engineering.coreAdopted : CoreReader.Engineering.CoreCommitment → Bool +CoreReader.Engineering.AdoptionReason : Type +CoreReader.Engineering.reasonFor : CoreReader.Engineering.CoreCommitment → CoreReader.Engineering.AdoptionReason +CoreReader.Engineering.ReasonRelevant : CoreReader.Engineering.CoreCommitment → + CoreReader.Engineering.AdoptionReason → CoreReader.Engineering.Candidate → Prop +CoreReader.Engineering.valueScope : CoreReader.Engineering.Candidate → Prop +CoreReader.Engineering.safeguardExperiment : CoreReader.Engineering.CoreCommitment → + Bool → CoreReader.Engineering.Candidate → Bool +CoreReader.Engineering.criticismFor : CoreReader.Engineering.CoreCommitment → String +CoreReader.Engineering.governancePosition : CoreReader.Engineering.CoreCommitment → + CoreReader.Evidence.ValuePosition CoreReader.Engineering.Candidate +CoreReader.Engineering.adoptionReasonRelevant : ∀ (principle : CoreReader.Engineering.CoreCommitment) + (selected : CoreReader.Engineering.Candidate), + CoreReader.Engineering.valueScope selected → + CoreReader.Engineering.ReasonRelevant principle (CoreReader.Engineering.reasonFor principle) selected +CoreReader.Engineering.safeguardEnabled : ∀ (principle : CoreReader.Engineering.CoreCommitment) + (selected : CoreReader.Engineering.Candidate), + CoreReader.Engineering.valueScope selected → + @Eq.{1} Bool (CoreReader.Engineering.safeguardExperiment principle Bool.true selected) Bool.true +CoreReader.Engineering.safeguardDisabled : ∀ (principle : CoreReader.Engineering.CoreCommitment) + (selected : CoreReader.Engineering.Candidate), + @Eq.{1} Bool (CoreReader.Engineering.safeguardExperiment principle Bool.false selected) Bool.false +CoreReader.Engineering.governanceValueProcedure : ∀ (principle : CoreReader.Engineering.CoreCommitment), + @CoreReader.Evidence.ValueProcedure CoreReader.Engineering.Candidate + (CoreReader.Engineering.governancePosition principle) +CoreReader.Engineering.governanceGrounded : ∀ (principle : CoreReader.Engineering.CoreCommitment), + @CoreReader.Adopted.valueSpecification CoreReader.Engineering.Candidate + (CoreReader.Engineering.governancePosition principle) +CoreReader.Engineering.governanceRationaleLimits : And + (Not + (CoreReader.Engineering.ReasonRelevant CoreReader.Engineering.CoreCommitment.consistency + (CoreReader.Engineering.reasonFor CoreReader.Engineering.CoreCommitment.generation) + CoreReader.Engineering.Candidate.evolvable)) + (And + (Not + (CoreReader.Engineering.ReasonRelevant CoreReader.Engineering.CoreCommitment.reflexivity + (CoreReader.Engineering.AdoptionReason.ownMethodCounterexample + (@OfNat.ofNat.{0} Nat (nat_lit 21) (instOfNatNat (nat_lit 21))) + (@OfNat.ofNat.{0} Nat (nat_lit 10) (instOfNatNat (nat_lit 10)))) + CoreReader.Engineering.Candidate.evolvable)) + (And + (Not + (CoreReader.Engineering.ReasonRelevant CoreReader.Engineering.CoreCommitment.generation + (CoreReader.Engineering.AdoptionReason.plannedChange + (@OfNat.ofNat.{0} Nat (nat_lit 9) (instOfNatNat (nat_lit 9))) CoreReader.Engineering.Change.addition) + CoreReader.Engineering.Candidate.evolvable)) + (And (Not (CoreReader.Engineering.valueScope CoreReader.Engineering.Candidate.maximal)) + (And + (∀ (principle : CoreReader.Engineering.CoreCommitment), + @Eq.{1} Bool + (CoreReader.Engineering.safeguardExperiment principle Bool.false + CoreReader.Engineering.Candidate.evolvable) + Bool.false) + (∀ (principle : CoreReader.Engineering.CoreCommitment), + @CoreReader.Evidence.ValuePosition.commitment CoreReader.Engineering.Candidate + (CoreReader.Engineering.governancePosition principle) CoreReader.Engineering.Candidate.presentSimple))))) +CoreReader.Engineering.selectionObjective : CoreReader.Engineering.Candidate → Prod.{0, 0} Nat Nat → Prop +CoreReader.Engineering.selectionPosition : CoreReader.Engineering.Candidate → + CoreReader.Evidence.ValuePosition CoreReader.Engineering.Candidate +CoreReader.Engineering.selectionValueProcedure : ∀ (adopted : CoreReader.Engineering.Candidate), + Or (@Eq.{1} CoreReader.Engineering.Candidate adopted CoreReader.Engineering.Candidate.presentSimple) + (@Eq.{1} CoreReader.Engineering.Candidate adopted CoreReader.Engineering.Candidate.evolvable) → + @CoreReader.Evidence.ValueProcedure CoreReader.Engineering.Candidate + (CoreReader.Engineering.selectionPosition adopted) +CoreReader.Engineering.selectionGrounded : ∀ (adopted : CoreReader.Engineering.Candidate), + Or (@Eq.{1} CoreReader.Engineering.Candidate adopted CoreReader.Engineering.Candidate.presentSimple) + (@Eq.{1} CoreReader.Engineering.Candidate adopted CoreReader.Engineering.Candidate.evolvable) → + @CoreReader.Adopted.valueSpecification CoreReader.Engineering.Candidate + (CoreReader.Engineering.selectionPosition adopted) +CoreReader.Evidence.Record : Type → Type +@CoreReader.Evidence.Compatible : {W : Type} → List.{0} (CoreReader.Evidence.Record W) → W → Prop +@CoreReader.Evidence.Supports : {W : Type} → List.{0} (CoreReader.Evidence.Record W) → CoreReader.Logic.Claim W → Prop +CoreReader.Evidence.Articulation : Type → Type +@CoreReader.Evidence.Articulated : {W : Type} → CoreReader.Evidence.Articulation W → Prop +CoreReader.Evidence.ValuePosition : Type → Type 1 +@CoreReader.Evidence.ValuePosition.commitment : {W : Type} → + CoreReader.Evidence.ValuePosition W → CoreReader.Logic.Claim W +@CoreReader.Evidence.ValuePosition.consequence : {W : Type} → + CoreReader.Evidence.ValuePosition W → CoreReader.Logic.Claim W +@CoreReader.Evidence.ValuePosition.activeReasons : {W : Type} → + CoreReader.Evidence.ValuePosition W → List.{0} (CoreReader.Logic.Claim W) +@CoreReader.Evidence.JointAdoption : {W : Type} → CoreReader.Evidence.ValuePosition W → Prop +@CoreReader.Evidence.ValueProcedure : {W : Type} → CoreReader.Evidence.ValuePosition W → Prop +CoreReader.Evidence.Facet : Type → Type 1 +@CoreReader.Evidence.Facet.claim : {W : Type} → CoreReader.Evidence.Facet W → CoreReader.Logic.Claim W +@CoreReader.Evidence.FacetDischarged : {W : Type} → CoreReader.Evidence.Facet W → Prop +@CoreReader.Evidence.FacetArticulated : {W : Type} → + CoreReader.Evidence.Articulation W → CoreReader.Evidence.Facet W → Prop +@CoreReader.Evidence.canonicalArticulation : {W : Type} → + CoreReader.Evidence.Facet W → CoreReader.Evidence.Articulation W +@CoreReader.Evidence.canonicalFacetArticulated : ∀ {W : Type} (f : CoreReader.Evidence.Facet W), + @CoreReader.Evidence.FacetArticulated W (@CoreReader.Evidence.canonicalArticulation W f) f +@CoreReader.Evidence.canonicalArticulated : ∀ {W : Type} (f : CoreReader.Evidence.Facet W), + @CoreReader.Evidence.FacetDischarged W f → + @CoreReader.Evidence.Articulated W (@CoreReader.Evidence.canonicalArticulation W f) +@CoreReader.Evidence.Grounds : {W : Type} → + CoreReader.Logic.Claim W → + (CoreReader.Evidence.Facet W → CoreReader.Evidence.Articulation W) → + (CoreReader.Evidence.Facet W → Prop) → List.{1} (CoreReader.Evidence.Facet W) → Prop +@CoreReader.Evidence.AchievementAccountability : {W : Type} → + CoreReader.Logic.Claim W → + (CoreReader.Evidence.Facet W → CoreReader.Evidence.Articulation W) → + (CoreReader.Evidence.Facet W → Prop) → List.{1} (CoreReader.Evidence.Facet W) → Prop +CoreReader.Evidence.transitionAchievement : CoreReader.Logic.Claim CoreReader.Agency.TransitionCase +CoreReader.Evidence.transitionPerformanceRecord : CoreReader.Evidence.Record CoreReader.Agency.TransitionCase +CoreReader.Evidence.transitionReportRecord : CoreReader.Evidence.Record CoreReader.Agency.TransitionCase +CoreReader.Evidence.transitionPerformanceCompatible : ∀ (transition : CoreReader.Agency.TransitionCase), + Iff + (@CoreReader.Evidence.Compatible CoreReader.Agency.TransitionCase + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Agency.TransitionCase) + CoreReader.Evidence.transitionPerformanceRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Agency.TransitionCase))) + transition) + (@Eq.{1} CoreReader.Agency.TransitionCase transition CoreReader.Agency.TransitionCase.extend) +CoreReader.Evidence.transitionSupported : @CoreReader.Evidence.Supports CoreReader.Agency.TransitionCase + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Agency.TransitionCase) + CoreReader.Evidence.transitionPerformanceRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Agency.TransitionCase))) + CoreReader.Evidence.transitionAchievement +CoreReader.Evidence.transitionFacet : CoreReader.Evidence.Facet CoreReader.Agency.TransitionCase +CoreReader.Evidence.transitionFacetDischarged : @CoreReader.Evidence.FacetDischarged CoreReader.Agency.TransitionCase + CoreReader.Evidence.transitionFacet +CoreReader.Evidence.transitionAccountable : @CoreReader.Evidence.AchievementAccountability + CoreReader.Agency.TransitionCase CoreReader.Evidence.transitionAchievement + (@CoreReader.Evidence.canonicalArticulation CoreReader.Agency.TransitionCase) + (fun facet => + @Eq.{2} (CoreReader.Evidence.Facet CoreReader.Agency.TransitionCase) facet CoreReader.Evidence.transitionFacet) + (@List.cons.{1} (CoreReader.Evidence.Facet CoreReader.Agency.TransitionCase) CoreReader.Evidence.transitionFacet + (@List.nil.{1} (CoreReader.Evidence.Facet CoreReader.Agency.TransitionCase))) +CoreReader.Evidence.transitionReportCompatible : ∀ (transition : CoreReader.Agency.TransitionCase), + @CoreReader.Evidence.Compatible CoreReader.Agency.TransitionCase + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Agency.TransitionCase) + CoreReader.Evidence.transitionReportRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Agency.TransitionCase))) + transition +CoreReader.Evidence.transitionReportDoesNotSupport : And + (@CoreReader.Evidence.Compatible CoreReader.Agency.TransitionCase + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Agency.TransitionCase) + CoreReader.Evidence.transitionReportRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Agency.TransitionCase))) + CoreReader.Agency.TransitionCase.inflate) + (And (Not (CoreReader.Evidence.transitionAchievement CoreReader.Agency.TransitionCase.inflate)) + (Not + (@CoreReader.Evidence.Supports CoreReader.Agency.TransitionCase + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Agency.TransitionCase) + CoreReader.Evidence.transitionReportRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Agency.TransitionCase))) + CoreReader.Evidence.transitionAchievement))) +CoreReader.Evidence.ConcreteAchievementExample : Prop +CoreReader.Evidence.concreteAchievementExample : CoreReader.Evidence.ConcreteAchievementExample +@CoreReader.Evidence.achievementNeedsSupport : ∀ {W : Type} (achievement : CoreReader.Logic.Claim W) + (records : List.{0} (CoreReader.Evidence.Record W)) (actual : W), + @CoreReader.Evidence.Compatible W records actual → + @CoreReader.Evidence.Supports W records achievement → + And (achievement actual) CoreReader.Evidence.ConcreteAchievementExample +@CoreReader.Evidence.supportWeakening : ∀ {W : Type} (records : List.{0} (CoreReader.Evidence.Record W)) + (p q : CoreReader.Logic.Claim W), + @CoreReader.Evidence.Supports W records p → (∀ (w : W), p w → q w) → @CoreReader.Evidence.Supports W records q +CoreReader.Evidence.evidenceWeakeningCanLoseSupport : And + (@CoreReader.Evidence.Supports Bool + (@List.cons.{0} (CoreReader.Evidence.Record Bool) (@CoreReader.Evidence.Record.mk Bool (@id.{1} Bool) Bool.true) + (@List.nil.{0} (CoreReader.Evidence.Record Bool))) + fun w => @Eq.{1} Bool w Bool.true) + (Not + (@CoreReader.Evidence.Supports Bool (@List.nil.{0} (CoreReader.Evidence.Record Bool)) fun w => + @Eq.{1} Bool w Bool.true)) +@CoreReader.Evidence.scopeRestriction : ∀ {W X : Type} (records : List.{0} (CoreReader.Evidence.Record W)) + (p : W → X → Prop) (wide narrow : X → Prop), + (∀ (x : X), narrow x → wide x) → + (@CoreReader.Evidence.Supports W records fun w => ∀ (x : X), wide x → p w x) → + @CoreReader.Evidence.Supports W records fun w => ∀ (x : X), narrow x → p w x +@CoreReader.Evidence.Duties : {W : Type} → (CoreReader.Evidence.Facet W → Prop) → Prop +@CoreReader.Evidence.LabeledDuties : {W : Type} → List.{0} String → (CoreReader.Evidence.Facet W → Prop) → Prop +@CoreReader.Evidence.assessmentUnion : ∀ {W : Type} (a b : CoreReader.Evidence.Facet W → Prop), + Iff (@CoreReader.Evidence.Duties W fun f => Or (a f) (b f)) + (And (@CoreReader.Evidence.Duties W a) (@CoreReader.Evidence.Duties W b)) +@CoreReader.Evidence.labelsCannotWaive : ∀ {W : Type} (xs ys : List.{0} String) + (a : CoreReader.Evidence.Facet W → Prop), + Iff (@CoreReader.Evidence.LabeledDuties W xs a) (@CoreReader.Evidence.LabeledDuties W ys a) +CoreReader.Evidence.switchRecord : CoreReader.Evidence.Record Bool +CoreReader.Evidence.switchCompatible : ∀ (w : Bool), + Iff + (@CoreReader.Evidence.Compatible Bool + (@List.cons.{0} (CoreReader.Evidence.Record Bool) CoreReader.Evidence.switchRecord + (@List.nil.{0} (CoreReader.Evidence.Record Bool))) + w) + (@Eq.{1} Bool w Bool.true) +CoreReader.Evidence.switchSupported : @CoreReader.Evidence.Supports Bool + (@List.cons.{0} (CoreReader.Evidence.Record Bool) CoreReader.Evidence.switchRecord + (@List.nil.{0} (CoreReader.Evidence.Record Bool))) + fun w => @Eq.{1} Bool w Bool.true +CoreReader.Evidence.optionBenefit : Bool → Nat +CoreReader.Evidence.optionCost : Bool → Nat +CoreReader.Evidence.optionReport : Bool → Prop +CoreReader.Evidence.switchPosition : CoreReader.Evidence.ValuePosition Bool +CoreReader.Evidence.switchValueProcedure : @CoreReader.Evidence.ValueProcedure Bool CoreReader.Evidence.switchPosition +CoreReader.Evidence.oppositePosition : CoreReader.Evidence.ValuePosition Bool +CoreReader.Evidence.oppositePositionRejected : And + (@CoreReader.Evidence.JointAdoption Bool CoreReader.Evidence.oppositePosition) + (Not (@CoreReader.Evidence.ValueProcedure Bool CoreReader.Evidence.oppositePosition)) +CoreReader.Evidence.contradictoryStartingPosition : CoreReader.Evidence.ValuePosition Bool +CoreReader.Evidence.impossibleAdoptionPosition : CoreReader.Evidence.ValuePosition Bool +CoreReader.Evidence.inadmissibleValuePositionsRejected : And + (Not (@CoreReader.Evidence.ValueProcedure Bool CoreReader.Evidence.contradictoryStartingPosition)) + (Not (@CoreReader.Evidence.ValueProcedure Bool CoreReader.Evidence.impossibleAdoptionPosition)) +CoreReader.Evidence.unsupportedPosition : CoreReader.Evidence.ValuePosition Bool +CoreReader.Evidence.switchEmpirical : CoreReader.Evidence.Facet Bool +CoreReader.Evidence.switchEmpiricalDischarged : @CoreReader.Evidence.FacetDischarged Bool + CoreReader.Evidence.switchEmpirical +CoreReader.Evidence.mixedMissingResponsibility : And + (@CoreReader.Evidence.FacetDischarged Bool CoreReader.Evidence.switchEmpirical) + (Not + (@CoreReader.Evidence.LabeledDuties Bool (@List.nil.{0} String) fun f => + Or (@Eq.{2} (CoreReader.Evidence.Facet Bool) f CoreReader.Evidence.switchEmpirical) + (@Eq.{2} (CoreReader.Evidence.Facet Bool) f + (@CoreReader.Evidence.Facet.value Bool CoreReader.Evidence.unsupportedPosition)))) +CoreReader.Evidence.uninformativeArgument : CoreReader.Evidence.Articulation Bool +CoreReader.Evidence.articulationNotSupport : And + (@CoreReader.Evidence.Articulated Bool CoreReader.Evidence.uninformativeArgument) + (Not + (@CoreReader.Logic.Entails Bool + (@CoreReader.Evidence.Articulation.assumptions Bool CoreReader.Evidence.uninformativeArgument) fun w => + @Eq.{1} Bool w Bool.true)) +CoreReader.Evidence.unrelatedArticulationRejected : And + (@CoreReader.Evidence.Articulated Bool CoreReader.Evidence.uninformativeArgument) + (And (@CoreReader.Evidence.FacetDischarged Bool CoreReader.Evidence.switchEmpirical) + (Not + (@CoreReader.Evidence.FacetArticulated Bool CoreReader.Evidence.uninformativeArgument + CoreReader.Evidence.switchEmpirical))) +CoreReader.Evidence.temperatureRecord : CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool) +CoreReader.Evidence.temperatureCompatible : ∀ (b : Bool), + @CoreReader.Evidence.Compatible (Prod.{0, 0} Bool Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool))))) + (@Prod.mk.{0, 0} Bool Bool Bool.true b) +CoreReader.Evidence.BudgetWorld : Type +CoreReader.Evidence.announcement : String +CoreReader.Evidence.announcementPosition : CoreReader.Evidence.ValuePosition CoreReader.Evidence.BudgetWorld +CoreReader.Evidence.announcementHasJointAdoption : @CoreReader.Evidence.JointAdoption CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition +CoreReader.Evidence.announcementNotBudgetReason : And + (@Ne.{1} + (List.{0} + (CoreReader.Evidence.BudgetWorld → + @CoreReader.Evidence.ValuePosition.Position CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition → + Prop)) + (@CoreReader.Evidence.ValuePosition.reasons CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition) + (@List.nil.{0} + (CoreReader.Evidence.BudgetWorld → + @CoreReader.Evidence.ValuePosition.Position CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition → + Prop))) + (And + (@CoreReader.Evidence.ValuePosition.commitment CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition + (@Prod.mk.{0, 0} Bool Nat Bool.true (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))))) + (And + (∀ + (reason : + CoreReader.Evidence.BudgetWorld → + @CoreReader.Evidence.ValuePosition.Position CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition → + Prop), + @Membership.mem.{0, 0} + (CoreReader.Evidence.BudgetWorld → + @CoreReader.Evidence.ValuePosition.Position CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition → + Prop) + (List.{0} + (CoreReader.Evidence.BudgetWorld → + @CoreReader.Evidence.ValuePosition.Position CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition → + Prop)) + (@List.instMembership.{0} + (CoreReader.Evidence.BudgetWorld → + @CoreReader.Evidence.ValuePosition.Position CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition → + Prop)) + (@CoreReader.Evidence.ValuePosition.reasons CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition) + reason → + reason (@Prod.mk.{0, 0} Bool Nat Bool.true (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (@CoreReader.Evidence.ValuePosition.adopted CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition)) + (And + (Not + (@CoreReader.Evidence.ValuePosition.consequence CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition + (@Prod.mk.{0, 0} Bool Nat Bool.true (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))))) + (Not + (@CoreReader.Evidence.ValueProcedure CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition))))) +CoreReader.Evidence.actionRecord : CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld +CoreReader.Evidence.actionCompatible : ∀ (budget : Nat), + @CoreReader.Evidence.Compatible CoreReader.Evidence.BudgetWorld + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld) CoreReader.Evidence.actionRecord + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld) CoreReader.Evidence.actionRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld)))) + (@Prod.mk.{0, 0} Bool Nat Bool.true budget) +CoreReader.Evidence.measurementRepeatNotSupport : And + (@Eq.{1} Bool + (@CoreReader.Evidence.Record.test (Prod.{0, 0} Bool Bool) CoreReader.Evidence.temperatureRecord + (@Prod.mk.{0, 0} Bool Bool Bool.true Bool.false)) + Bool.true) + (And + (@CoreReader.Evidence.Compatible (Prod.{0, 0} Bool Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool))))) + (@Prod.mk.{0, 0} Bool Bool Bool.true Bool.false)) + (And + (@CoreReader.Evidence.Compatible (Prod.{0, 0} Bool Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool))))) + (@Prod.mk.{0, 0} Bool Bool Bool.true Bool.true)) + (And + (Not + (@CoreReader.Evidence.Supports (Prod.{0, 0} Bool Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)))) + fun w => @Eq.{1} Bool (@Prod.snd.{0, 0} Bool Bool w) Bool.true)) + (And + (Not + (@CoreReader.Evidence.Supports (Prod.{0, 0} Bool Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) CoreReader.Evidence.temperatureRecord + (@List.cons.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool)) + CoreReader.Evidence.temperatureRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Prod.{0, 0} Bool Bool))))) + fun w => @Eq.{1} Bool (@Prod.snd.{0, 0} Bool Bool w) Bool.true)) + (And + (@CoreReader.Evidence.Compatible CoreReader.Evidence.BudgetWorld + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld) + CoreReader.Evidence.actionRecord + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld) + CoreReader.Evidence.actionRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld)))) + (@Prod.mk.{0, 0} Bool Nat Bool.true (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))))) + (And + (@CoreReader.Evidence.Compatible CoreReader.Evidence.BudgetWorld + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld) + CoreReader.Evidence.actionRecord + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld) + CoreReader.Evidence.actionRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld)))) + (@Prod.mk.{0, 0} Bool Nat Bool.true (@OfNat.ofNat.{0} Nat (nat_lit 3) (instOfNatNat (nat_lit 3))))) + (And + (Not + (@CoreReader.Evidence.Supports CoreReader.Evidence.BudgetWorld + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld) + CoreReader.Evidence.actionRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld))) + (@CoreReader.Evidence.ValuePosition.consequence CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition))) + (And + (Not + (@CoreReader.Evidence.Supports CoreReader.Evidence.BudgetWorld + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld) + CoreReader.Evidence.actionRecord + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld) + CoreReader.Evidence.actionRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Evidence.BudgetWorld)))) + (@CoreReader.Evidence.ValuePosition.consequence CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition))) + (Not + (@CoreReader.Evidence.ValueProcedure CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition)))))))))) +CoreReader.Evidence.selfAssertionNotReason : And + (And (@CoreReader.Evidence.ValuePosition.commitment Bool CoreReader.Evidence.unsupportedPosition Bool.true) + (Not (@CoreReader.Evidence.ValueProcedure Bool CoreReader.Evidence.unsupportedPosition))) + (And + (And + (@Ne.{1} + (List.{0} + (CoreReader.Evidence.BudgetWorld → + @CoreReader.Evidence.ValuePosition.Position CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition → + Prop)) + (@CoreReader.Evidence.ValuePosition.reasons CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition) + (@List.nil.{0} + (CoreReader.Evidence.BudgetWorld → + @CoreReader.Evidence.ValuePosition.Position CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition → + Prop))) + (And + (@CoreReader.Evidence.ValuePosition.commitment CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition + (@Prod.mk.{0, 0} Bool Nat Bool.true (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))))) + (And + (Not + (@CoreReader.Evidence.ValuePosition.consequence CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition + (@Prod.mk.{0, 0} Bool Nat Bool.true (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))))) + (Not + (@CoreReader.Evidence.ValueProcedure CoreReader.Evidence.BudgetWorld + CoreReader.Evidence.announcementPosition))))) + (@CoreReader.Evidence.JointAdoption CoreReader.Evidence.BudgetWorld CoreReader.Evidence.announcementPosition)) +CoreReader.Evidence.valueWithoutSelfProof : And + (@CoreReader.Evidence.ValueProcedure Bool CoreReader.Evidence.switchPosition) + (And + (@CoreReader.Logic.Satisfiable Bool + (@CoreReader.Evidence.ValuePosition.starting Bool CoreReader.Evidence.switchPosition)) + (And + (Not + (@CoreReader.Logic.Entails Bool (@CoreReader.Logic.emptyTheory Bool) + (@CoreReader.Evidence.ValuePosition.commitment Bool CoreReader.Evidence.switchPosition))) + (And + (And (@CoreReader.Evidence.JointAdoption Bool CoreReader.Evidence.oppositePosition) + (Not (@CoreReader.Evidence.ValueProcedure Bool CoreReader.Evidence.oppositePosition))) + (And (Not (@CoreReader.Evidence.ValueProcedure Bool CoreReader.Evidence.contradictoryStartingPosition)) + (Not (@CoreReader.Evidence.ValueProcedure Bool CoreReader.Evidence.impossibleAdoptionPosition)))))) +CoreReader.Evidence.BenefitCostWorld : Type +CoreReader.Evidence.measuredOutcome : CoreReader.Evidence.BenefitCostWorld → Bool → Prod.{0, 0} Nat Nat +CoreReader.Evidence.benefitReason : CoreReader.Evidence.BenefitCostWorld → Bool → Prop +CoreReader.Evidence.costReason : CoreReader.Evidence.BenefitCostWorld → Bool → Prop +CoreReader.Evidence.jointReasonPosition : CoreReader.Evidence.ValuePosition CoreReader.Evidence.BenefitCostWorld +CoreReader.Evidence.jointReasonProcedure : @CoreReader.Evidence.ValueProcedure CoreReader.Evidence.BenefitCostWorld + CoreReader.Evidence.jointReasonPosition +CoreReader.Evidence.JointReasonsExample : Prop +CoreReader.Evidence.jointReasonsExample : CoreReader.Evidence.JointReasonsExample +CoreReader.Evidence.heterogeneousReasons : And + (@CoreReader.Evidence.FacetDischarged Bool CoreReader.Evidence.switchEmpirical) + (And + (@CoreReader.Evidence.FacetDischarged Bool + (@CoreReader.Evidence.Facet.inferential Bool (@CoreReader.Logic.singleton Bool fun w => @Eq.{1} Bool w Bool.true) + fun w => @Eq.{1} Bool w Bool.true)) + (And + (@CoreReader.Evidence.FacetDischarged Bool + (@CoreReader.Evidence.Facet.value Bool CoreReader.Evidence.switchPosition)) + CoreReader.Evidence.JointReasonsExample)) +CoreReader.Evidence.zeroRecord : CoreReader.Evidence.Record (Nat → Bool) +CoreReader.Evidence.localGenerator : Nat → Nat → Bool +CoreReader.Evidence.allTrue : CoreReader.Logic.Claim (Nat → Bool) +CoreReader.Evidence.zeroCompatible : ∀ (f : Nat → Bool), + Iff + (@CoreReader.Evidence.Compatible (Nat → Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Nat → Bool)) CoreReader.Evidence.zeroRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Nat → Bool)))) + f) + (@Eq.{1} Bool (f (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) Bool.true) +CoreReader.Evidence.GeneratingProcess : Type +CoreReader.Evidence.GeneratingProcess.outputRevision : CoreReader.Evidence.GeneratingProcess → Nat → Bool +CoreReader.Evidence.ProducedRevision : Type +CoreReader.Evidence.GeneratingProcess.produce : CoreReader.Evidence.GeneratingProcess → + CoreReader.Evidence.ProducedRevision +CoreReader.Evidence.sampleGeneratingProcess : CoreReader.Evidence.GeneratingProcess +CoreReader.Evidence.OwnedRevisionExample : Prop +CoreReader.Evidence.ownedRevisionExample : CoreReader.Evidence.OwnedRevisionExample +CoreReader.Evidence.selfOriginDoesNotSupport : And + (@Eq.{1} Bool + (CoreReader.Evidence.localGenerator (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + Bool.true) + (And + (@Eq.{1} Bool + (CoreReader.Evidence.localGenerator (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + Bool.false) + (And + (@CoreReader.Evidence.Compatible (Nat → Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Nat → Bool)) CoreReader.Evidence.zeroRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Nat → Bool)))) + (CoreReader.Evidence.localGenerator (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))))) + (And + (Not + (@CoreReader.Evidence.Supports (Nat → Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Nat → Bool)) CoreReader.Evidence.zeroRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Nat → Bool)))) + CoreReader.Evidence.allTrue)) + CoreReader.Evidence.OwnedRevisionExample))) +CoreReader.Evidence.localNotUniversal : And + (@Exists.{1} Nat fun outside => @Ne.{1} Nat outside (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (And + (@CoreReader.Evidence.Compatible (Nat → Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Nat → Bool)) CoreReader.Evidence.zeroRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Nat → Bool)))) + fun x => Bool.true) + (And + (@CoreReader.Evidence.Compatible (Nat → Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Nat → Bool)) CoreReader.Evidence.zeroRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Nat → Bool)))) + (CoreReader.Evidence.localGenerator (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))))) + (And (CoreReader.Evidence.allTrue fun x => Bool.true) + (And + (Not + (CoreReader.Evidence.allTrue + (CoreReader.Evidence.localGenerator (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))))) + (Not + (@CoreReader.Evidence.Supports (Nat → Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Nat → Bool)) CoreReader.Evidence.zeroRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Nat → Bool)))) + CoreReader.Evidence.allTrue)))))) +CoreReader.Evidence.hiddenDifference : And + (∀ (n : Nat), + @Eq.{1} Nat n (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) → + @Eq.{1} Bool ((fun x => Bool.true) n) + (CoreReader.Evidence.localGenerator (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) n)) + (@Ne.{1} Bool ((fun x => Bool.true) (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (CoreReader.Evidence.localGenerator (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))))) +CoreReader.Evidence.singleObservation : And + (@Eq.{1} Nat + (@List.length.{0} (CoreReader.Evidence.Record (Nat → Bool)) + (@List.cons.{0} (CoreReader.Evidence.Record (Nat → Bool)) CoreReader.Evidence.zeroRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Nat → Bool))))) + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (And + (@Exists.{1} (Nat → Bool) fun f => + @CoreReader.Evidence.Compatible (Nat → Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Nat → Bool)) CoreReader.Evidence.zeroRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Nat → Bool)))) + f) + (And + (@CoreReader.Evidence.Supports (Nat → Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Nat → Bool)) CoreReader.Evidence.zeroRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Nat → Bool)))) + fun f => @Eq.{1} Bool (f (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) Bool.true) + (Not + (@CoreReader.Evidence.Supports (Nat → Bool) + (@List.cons.{0} (CoreReader.Evidence.Record (Nat → Bool)) CoreReader.Evidence.zeroRecord + (@List.nil.{0} (CoreReader.Evidence.Record (Nat → Bool)))) + CoreReader.Evidence.allTrue)))) +CoreReader.Evidence.arithmeticFacet : CoreReader.Evidence.Facet Nat +@CoreReader.Evidence.usesObservation : {W : Type} → CoreReader.Evidence.Facet W → Bool +CoreReader.Evidence.noUniversalChain : And + (@CoreReader.Evidence.FacetDischarged Nat CoreReader.Evidence.arithmeticFacet) + (@Eq.{1} Bool (@CoreReader.Evidence.usesObservation Nat CoreReader.Evidence.arithmeticFacet) Bool.false) +CoreReader.Evidence.Trial : Type +CoreReader.Evidence.Verified : CoreReader.Evidence.Trial → Prop +CoreReader.Evidence.Reproduced : CoreReader.Evidence.Trial → CoreReader.Evidence.Trial → Prop +CoreReader.Evidence.Bounded : CoreReader.Evidence.Trial → Prop +CoreReader.Evidence.variableOutcomesStableBound : have a := + { setting := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)) }; +have b := + { setting := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2)) }; +And (CoreReader.Evidence.Reproduced a b) + (And (@Ne.{1} Nat a.actualOutcome b.actualOutcome) + (And (CoreReader.Evidence.Bounded a) (CoreReader.Evidence.Bounded b))) +CoreReader.Evidence.verificationReproductionStability : And + (And + (CoreReader.Evidence.Verified + { setting := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)) }) + (And + (CoreReader.Evidence.Verified + { setting := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)) }) + (Not + (CoreReader.Evidence.Reproduced + { setting := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)) } + { setting := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)) })))) + (And + (And + (CoreReader.Evidence.Reproduced + { setting := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)) } + { setting := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 3) (instOfNatNat (nat_lit 3)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2)) }) + (And + (Not + (CoreReader.Evidence.Verified + { setting := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 3) (instOfNatNat (nat_lit 3)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2)) })) + (Not + (CoreReader.Evidence.Bounded + { setting := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 3) (instOfNatNat (nat_lit 3)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2)) })))) + (And + (CoreReader.Evidence.Bounded + { setting := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)) }) + (And + (CoreReader.Evidence.Bounded + { setting := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)) }) + (Not + (CoreReader.Evidence.Verified + { setting := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)), + actualOutcome := @OfNat.ofNat.{0} Nat (nat_lit 2) (instOfNatNat (nat_lit 2)), + recordedOutcome := @OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)) }))))) +CoreReader.Evidence.Program : Type +CoreReader.Evidence.Program.eval : CoreReader.Evidence.Program → Nat → Nat +CoreReader.Evidence.Process : Type +CoreReader.Evidence.OutputContract : CoreReader.Evidence.Process → Prop +CoreReader.Evidence.ExplanationContract : CoreReader.Evidence.Process → Prop +CoreReader.Evidence.outputOnlyProcess : CoreReader.Evidence.Process +CoreReader.Evidence.explainedProcess : CoreReader.Evidence.Process +CoreReader.Evidence.processScope : CoreReader.Evidence.Process → CoreReader.Logic.Theory CoreReader.Evidence.Process +CoreReader.Evidence.processContractFacet : CoreReader.Evidence.Process → + CoreReader.Logic.Claim CoreReader.Evidence.Process → CoreReader.Evidence.Facet CoreReader.Evidence.Process +CoreReader.Evidence.processScopeModels : ∀ (assessed candidate : CoreReader.Evidence.Process), + Iff (@CoreReader.Logic.Models CoreReader.Evidence.Process (CoreReader.Evidence.processScope assessed) candidate) + (@Eq.{1} CoreReader.Evidence.Process candidate assessed) +CoreReader.Evidence.processContractDischarged : ∀ (assessed : CoreReader.Evidence.Process) + (contract : CoreReader.Logic.Claim CoreReader.Evidence.Process), + contract assessed → + @CoreReader.Evidence.FacetDischarged CoreReader.Evidence.Process + (CoreReader.Evidence.processContractFacet assessed contract) +CoreReader.Evidence.ProcessGrounds : CoreReader.Evidence.Process → + CoreReader.Logic.Claim CoreReader.Evidence.Process → Prop +CoreReader.Evidence.processGrounds : ∀ (assessed : CoreReader.Evidence.Process) + (contract : CoreReader.Logic.Claim CoreReader.Evidence.Process), + contract assessed → CoreReader.Evidence.ProcessGrounds assessed contract +CoreReader.Evidence.outputCorrectByEvaluation : CoreReader.Evidence.OutputContract CoreReader.Evidence.outputOnlyProcess +CoreReader.Evidence.outputOnlyNoExplanation : Not + (CoreReader.Evidence.ExplanationContract CoreReader.Evidence.outputOnlyProcess) +CoreReader.Evidence.FullProcessContract : CoreReader.Evidence.Process → Prop +CoreReader.Evidence.OutputContractEvidence : Prop +CoreReader.Evidence.outputContractEvidence : CoreReader.Evidence.OutputContractEvidence +CoreReader.Evidence.ScopedApplicationEvidence : Prop +CoreReader.Evidence.scopedApplicationEvidence : CoreReader.Evidence.ScopedApplicationEvidence +CoreReader.Evidence.outputNotExplanation : And + (CoreReader.Evidence.OutputContract CoreReader.Evidence.outputOnlyProcess) + (And (Not (CoreReader.Evidence.ExplanationContract CoreReader.Evidence.outputOnlyProcess)) + CoreReader.Evidence.OutputContractEvidence) +CoreReader.Evidence.applicationContractsDiffer : And + (And (CoreReader.Evidence.OutputContract CoreReader.Evidence.outputOnlyProcess) + (Not + (And (CoreReader.Evidence.OutputContract CoreReader.Evidence.outputOnlyProcess) + (CoreReader.Evidence.ExplanationContract CoreReader.Evidence.outputOnlyProcess)))) + (And + (And (CoreReader.Evidence.OutputContract CoreReader.Evidence.explainedProcess) + (CoreReader.Evidence.ExplanationContract CoreReader.Evidence.explainedProcess)) + CoreReader.Evidence.ScopedApplicationEvidence) +CoreReader.Evidence.ExternalCertificate : CoreReader.Evidence.Process → Type +CoreReader.Evidence.externalOutputCertificate : CoreReader.Evidence.ExternalCertificate + CoreReader.Evidence.outputOnlyProcess +CoreReader.Evidence.externalAssessment : And + (@Exists.{1} (CoreReader.Evidence.ExternalCertificate CoreReader.Evidence.outputOnlyProcess) fun certificate => + And + (@Eq.{1} Nat + (@CoreReader.Evidence.ExternalCertificate.assessorId CoreReader.Evidence.outputOnlyProcess certificate) + (@OfNat.ofNat.{0} Nat (nat_lit 42) (instOfNatNat (nat_lit 42)))) + (And + (@Eq.{1} Nat + (@CoreReader.Evidence.ExternalCertificate.assessedId CoreReader.Evidence.outputOnlyProcess certificate) + (@OfNat.ofNat.{0} Nat (nat_lit 7) (instOfNatNat (nat_lit 7)))) + (And + (@Ne.{1} Nat + (@CoreReader.Evidence.ExternalCertificate.assessorId CoreReader.Evidence.outputOnlyProcess certificate) + (@CoreReader.Evidence.ExternalCertificate.assessedId CoreReader.Evidence.outputOnlyProcess certificate)) + (CoreReader.Evidence.OutputContract CoreReader.Evidence.outputOnlyProcess)))) + (And (CoreReader.Evidence.ProcessGrounds CoreReader.Evidence.outputOnlyProcess CoreReader.Evidence.OutputContract) + (Not (CoreReader.Evidence.ExplanationContract CoreReader.Evidence.outputOnlyProcess))) +CoreReader.Evidence.arithmeticArticulation : CoreReader.Evidence.Articulation Nat +CoreReader.Evidence.nonExecutableAssessment : And + (@CoreReader.Evidence.Grounds Nat + (fun n => + @Eq.{1} Nat + (@HAdd.hAdd.{0, 0, 0} Nat Nat Nat (@instHAdd.{0} Nat instAddNat) n + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (@OfNat.ofNat.{0} Nat (nat_lit 3) (instOfNatNat (nat_lit 3)))) + (@CoreReader.Evidence.canonicalArticulation Nat) + (fun f => @Eq.{2} (CoreReader.Evidence.Facet Nat) f CoreReader.Evidence.arithmeticFacet) + (@List.cons.{1} (CoreReader.Evidence.Facet Nat) CoreReader.Evidence.arithmeticFacet + (@List.nil.{1} (CoreReader.Evidence.Facet Nat)))) + (And (@Eq.{1} Bool (@CoreReader.Evidence.usesObservation Nat CoreReader.Evidence.arithmeticFacet) Bool.false) + (And (@CoreReader.Evidence.FacetDischarged Bool CoreReader.Evidence.switchEmpirical) + (@Eq.{1} Bool (@CoreReader.Evidence.usesObservation Bool CoreReader.Evidence.switchEmpirical) Bool.true))) +@CoreReader.Integration.canonicalGrounds : ∀ {W : Type} (claim : CoreReader.Logic.Claim W) + (facets : List.{1} (CoreReader.Evidence.Facet W)), + @Ne.{2} (List.{1} (CoreReader.Evidence.Facet W)) facets (@List.nil.{1} (CoreReader.Evidence.Facet W)) → + (∀ (f : CoreReader.Evidence.Facet W), + @Membership.mem.{1, 1} (CoreReader.Evidence.Facet W) (List.{1} (CoreReader.Evidence.Facet W)) + (@List.instMembership.{1} (CoreReader.Evidence.Facet W)) facets f → + And (@Eq.{1} (CoreReader.Logic.Claim W) (@CoreReader.Evidence.Facet.claim W f) claim) + (@CoreReader.Evidence.FacetDischarged W f)) → + @CoreReader.Evidence.Grounds W claim (@CoreReader.Evidence.canonicalArticulation W) + (fun f => + @Membership.mem.{1, 1} (CoreReader.Evidence.Facet W) (List.{1} (CoreReader.Evidence.Facet W)) + (@List.instMembership.{1} (CoreReader.Evidence.Facet W)) facets f) + facets +@CoreReader.Integration.canonicalGroundsForSingleton : ∀ {W : Type} (f : CoreReader.Evidence.Facet W), + @CoreReader.Evidence.FacetDischarged W f → + @CoreReader.Evidence.Grounds W (@CoreReader.Evidence.Facet.claim W f) (@CoreReader.Evidence.canonicalArticulation W) + (fun g => @Eq.{2} (CoreReader.Evidence.Facet W) g f) + (@List.cons.{1} (CoreReader.Evidence.Facet W) f (@List.nil.{1} (CoreReader.Evidence.Facet W))) +CoreReader.Integration.Mode : Type +CoreReader.Integration.World : Type +CoreReader.Integration.actual : CoreReader.Integration.World +CoreReader.Integration.Method : Type +CoreReader.Integration.System : Type +CoreReader.Integration.policyFor : CoreReader.Integration.Mode → CoreReader.Agency.Policy +CoreReader.Integration.workFor : Nat → CoreReader.Integration.Mode → List.{0} CoreReader.Agency.WorkRecord +CoreReader.Integration.System.policy : CoreReader.Integration.System → + CoreReader.Integration.World → CoreReader.Agency.Policy +CoreReader.Integration.System.rules : CoreReader.Integration.System → + CoreReader.Integration.World → List.{0} CoreReader.Agency.Principle +CoreReader.Integration.System.work : CoreReader.Integration.System → + CoreReader.Integration.World → List.{0} CoreReader.Agency.WorkRecord +CoreReader.Integration.actualSystem : CoreReader.Integration.System +CoreReader.Integration.systemCapability : CoreReader.Integration.System → + CoreReader.Logic.Claim CoreReader.Integration.World +CoreReader.Integration.systemBudget : CoreReader.Integration.System → + CoreReader.Logic.Claim CoreReader.Integration.World +CoreReader.Integration.systemObservation : CoreReader.Integration.System → + CoreReader.Evidence.Record CoreReader.Integration.World +CoreReader.Integration.systemHeld : CoreReader.Integration.System → CoreReader.Logic.Theory CoreReader.Integration.World +CoreReader.Integration.Question : Type +CoreReader.Integration.systemContext : CoreReader.Integration.System → + CoreReader.Logic.Context CoreReader.Integration.World CoreReader.Integration.Question +CoreReader.Integration.capability : CoreReader.Logic.Claim CoreReader.Integration.World +CoreReader.Integration.observation : CoreReader.Evidence.Record CoreReader.Integration.World +CoreReader.Integration.held : CoreReader.Logic.Theory CoreReader.Integration.World +CoreReader.Integration.context : CoreReader.Logic.Context CoreReader.Integration.World CoreReader.Integration.Question +CoreReader.Integration.observationIdentifies : ∀ (w : CoreReader.Integration.World), + Iff + (@CoreReader.Evidence.Compatible CoreReader.Integration.World + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Integration.World) CoreReader.Integration.observation + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Integration.World))) + w) + (@Eq.{1} CoreReader.Choice.Candidate (@Prod.fst.{0, 0} CoreReader.Choice.Candidate CoreReader.Integration.Mode w) + CoreReader.Choice.Candidate.identity) +CoreReader.Integration.capabilityActual : CoreReader.Integration.capability CoreReader.Integration.actual +CoreReader.Integration.observedCapability : @CoreReader.Evidence.Supports CoreReader.Integration.World + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Integration.World) CoreReader.Integration.observation + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Integration.World))) + CoreReader.Integration.capability +CoreReader.Integration.capabilityFacet : CoreReader.Evidence.Facet CoreReader.Integration.World +CoreReader.Integration.capabilityFacetChecked : @CoreReader.Evidence.FacetDischarged CoreReader.Integration.World + CoreReader.Integration.capabilityFacet +CoreReader.Integration.capabilityGrounds : @CoreReader.Evidence.Grounds CoreReader.Integration.World + CoreReader.Integration.capability (@CoreReader.Evidence.canonicalArticulation CoreReader.Integration.World) + (fun f => @Eq.{2} (CoreReader.Evidence.Facet CoreReader.Integration.World) f CoreReader.Integration.capabilityFacet) + (@List.cons.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World) CoreReader.Integration.capabilityFacet + (@List.nil.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World))) +CoreReader.Integration.actualAdmissible : @CoreReader.Logic.Admissible CoreReader.Integration.World + CoreReader.Integration.Question CoreReader.Integration.held CoreReader.Integration.context + CoreReader.Integration.actual +CoreReader.Integration.jointConsistent : @CoreReader.Logic.Consistent CoreReader.Integration.World + CoreReader.Integration.Question CoreReader.Integration.held CoreReader.Integration.context +CoreReader.Integration.Charter : CoreReader.Integration.System → CoreReader.Integration.World → Prop +CoreReader.Integration.charterChecked : CoreReader.Integration.Charter CoreReader.Integration.actualSystem + CoreReader.Integration.actual +CoreReader.Integration.revisedHeld : CoreReader.Logic.Theory CoreReader.Integration.World +CoreReader.Integration.initialSnapshot : CoreReader.Logic.Snapshot CoreReader.Integration.World + CoreReader.Integration.Question +CoreReader.Integration.revisedSnapshot : CoreReader.Logic.Snapshot CoreReader.Integration.World + CoreReader.Integration.Question +CoreReader.Integration.revisionKeepsConsistency : And + (CoreReader.Integration.Charter CoreReader.Integration.actualSystem CoreReader.Integration.actual) + (And + (@CoreReader.Logic.Consistent CoreReader.Integration.World CoreReader.Integration.Question + CoreReader.Integration.revisedHeld CoreReader.Integration.context) + (And + (@CoreReader.Logic.TruthfulReport CoreReader.Integration.World CoreReader.Integration.Question + CoreReader.Integration.initialSnapshot CoreReader.Integration.revisedSnapshot Bool.true) + (Not + (@CoreReader.Logic.TruthfulReport CoreReader.Integration.World CoreReader.Integration.Question + CoreReader.Integration.initialSnapshot CoreReader.Integration.revisedSnapshot Bool.false)))) +CoreReader.Integration.OwnCapabilityDuty : CoreReader.Integration.System → + CoreReader.Integration.World → List.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World) → Prop +CoreReader.Integration.ownCapabilityGrounded : And + (CoreReader.Integration.OwnCapabilityDuty CoreReader.Integration.actualSystem CoreReader.Integration.actual + (@List.cons.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World) CoreReader.Integration.capabilityFacet + (@List.nil.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World)))) + (CoreReader.Integration.capability CoreReader.Integration.actual) +CoreReader.Integration.costAllowanceRecord : CoreReader.Evidence.Record CoreReader.Integration.World +CoreReader.Integration.unsupportedCapabilityFacet : CoreReader.Evidence.Facet CoreReader.Integration.World +CoreReader.Integration.costCompatibleWithFailure : @CoreReader.Evidence.Compatible CoreReader.Integration.World + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Integration.World) CoreReader.Integration.costAllowanceRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Integration.World))) + (@Prod.mk.{0, 0} CoreReader.Choice.Candidate CoreReader.Integration.Mode CoreReader.Choice.Candidate.successor + CoreReader.Integration.Mode.apply) +CoreReader.Integration.costDoesNotSupportOutput : Not + (@CoreReader.Evidence.Supports CoreReader.Integration.World + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Integration.World) CoreReader.Integration.costAllowanceRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Integration.World))) + CoreReader.Integration.capability) +CoreReader.Integration.unsupportedGrounds : Not + (@CoreReader.Evidence.Grounds CoreReader.Integration.World CoreReader.Integration.capability + (@CoreReader.Evidence.canonicalArticulation CoreReader.Integration.World) + (fun f => + @Eq.{2} (CoreReader.Evidence.Facet CoreReader.Integration.World) f + CoreReader.Integration.unsupportedCapabilityFacet) + (@List.cons.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World) + CoreReader.Integration.unsupportedCapabilityFacet + (@List.nil.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World)))) +CoreReader.Integration.Commitment : Type +CoreReader.Integration.groundsPermission : CoreReader.Integration.Mode → + CoreReader.Logic.Claim CoreReader.Integration.World → + (CoreReader.Evidence.Facet CoreReader.Integration.World → + CoreReader.Evidence.Articulation CoreReader.Integration.World) → + (CoreReader.Evidence.Facet CoreReader.Integration.World → Prop) → + List.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World) → Prop +CoreReader.Integration.GroundsProvision : CoreReader.Integration.Mode → Prop +CoreReader.Integration.groundsProvisionMeaning : ∀ (mode : CoreReader.Integration.Mode), + Iff (CoreReader.Integration.GroundsProvision mode) + (@Eq.{1} CoreReader.Integration.Mode mode CoreReader.Integration.Mode.apply) +CoreReader.Integration.consistencyPermission : CoreReader.Integration.Mode → + CoreReader.Logic.Theory CoreReader.Integration.World → + CoreReader.Logic.Context CoreReader.Integration.World CoreReader.Integration.Question → Prop +CoreReader.Integration.conflictingHeld : CoreReader.Logic.Theory CoreReader.Integration.World +CoreReader.Integration.conflictConsequences : And + (@CoreReader.Logic.Consequence CoreReader.Integration.World CoreReader.Integration.Question + CoreReader.Integration.conflictingHeld CoreReader.Integration.context CoreReader.Integration.Question.correctOutput + Bool.true) + (@CoreReader.Logic.Consequence CoreReader.Integration.World CoreReader.Integration.Question + CoreReader.Integration.conflictingHeld CoreReader.Integration.context CoreReader.Integration.Question.correctOutput + Bool.false) +CoreReader.Integration.conflictingHeldInconsistent : Not + (@CoreReader.Logic.Consistent CoreReader.Integration.World CoreReader.Integration.Question + CoreReader.Integration.conflictingHeld CoreReader.Integration.context) +CoreReader.Integration.choicePermission : CoreReader.Integration.Mode → + CoreReader.Choice.Requirements → CoreReader.Choice.Implementation → List.{0} CoreReader.Choice.Reason → Prop +CoreReader.Integration.proposedOperation : CoreReader.Integration.Mode → CoreReader.Agency.Operation +CoreReader.Integration.selfSamples : CoreReader.Integration.Mode → List.{0} Nat +CoreReader.Integration.conflictDecision : CoreReader.Integration.Mode → Bool +CoreReader.Integration.groundsDecision : CoreReader.Integration.Mode → + CoreReader.Evidence.Facet CoreReader.Integration.World → Bool +CoreReader.Integration.choiceDecision : CoreReader.Integration.Mode → + CoreReader.Choice.Implementation → List.{0} CoreReader.Choice.Reason → Bool +CoreReader.Integration.decisionsApply : And + (@Eq.{1} Bool (CoreReader.Integration.conflictDecision CoreReader.Integration.Mode.apply) Bool.false) + (And + (@Eq.{1} Bool + (CoreReader.Integration.groundsDecision CoreReader.Integration.Mode.apply + CoreReader.Integration.unsupportedCapabilityFacet) + Bool.false) + (And + (@Eq.{1} Bool + (CoreReader.Integration.groundsDecision CoreReader.Integration.Mode.apply + CoreReader.Integration.capabilityFacet) + Bool.true) + (And + (@Eq.{1} Bool + (CoreReader.Integration.choiceDecision CoreReader.Integration.Mode.apply CoreReader.Choice.cheapSuccessor + (@List.cons.{0} CoreReader.Choice.Reason + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.simplicity) + (@List.nil.{0} CoreReader.Choice.Reason))) + Bool.false) + (@Eq.{1} Bool + (CoreReader.Integration.choiceDecision CoreReader.Integration.Mode.apply CoreReader.Choice.identityImpl + CoreReader.Choice.objectiveReason) + Bool.true)))) +CoreReader.Integration.decisionsWaive : And + (@Eq.{1} Bool (CoreReader.Integration.conflictDecision CoreReader.Integration.Mode.waive) Bool.true) + (And + (@Eq.{1} Bool + (CoreReader.Integration.groundsDecision CoreReader.Integration.Mode.waive + CoreReader.Integration.unsupportedCapabilityFacet) + Bool.true) + (@Eq.{1} Bool + (CoreReader.Integration.choiceDecision CoreReader.Integration.Mode.waive CoreReader.Choice.cheapSuccessor + (@List.cons.{0} CoreReader.Choice.Reason + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.simplicity) + (@List.nil.{0} CoreReader.Choice.Reason))) + Bool.true)) +CoreReader.Integration.commitmentPositionFor : CoreReader.Integration.Commitment → + CoreReader.Integration.Mode → CoreReader.Evidence.ValuePosition CoreReader.Integration.World +CoreReader.Integration.commitmentPosition : CoreReader.Integration.Commitment → + CoreReader.Evidence.ValuePosition CoreReader.Integration.World +CoreReader.Integration.positionReasons : ∀ (c : CoreReader.Integration.Commitment) + (r : + CoreReader.Integration.World → + @CoreReader.Evidence.ValuePosition.Position CoreReader.Integration.World + (CoreReader.Integration.commitmentPosition c) → + Prop), + @Membership.mem.{0, 0} + (CoreReader.Integration.World → + @CoreReader.Evidence.ValuePosition.Position CoreReader.Integration.World + (CoreReader.Integration.commitmentPosition c) → + Prop) + (List.{0} + (CoreReader.Integration.World → + @CoreReader.Evidence.ValuePosition.Position CoreReader.Integration.World + (CoreReader.Integration.commitmentPosition c) → + Prop)) + (@List.instMembership.{0} + (CoreReader.Integration.World → + @CoreReader.Evidence.ValuePosition.Position CoreReader.Integration.World + (CoreReader.Integration.commitmentPosition c) → + Prop)) + (@CoreReader.Evidence.ValuePosition.reasons CoreReader.Integration.World + (CoreReader.Integration.commitmentPosition c)) + r → + r CoreReader.Integration.actual + (@CoreReader.Evidence.ValuePosition.adopted CoreReader.Integration.World + (CoreReader.Integration.commitmentPosition c)) +CoreReader.Integration.positionConsequence : ∀ (c : CoreReader.Integration.Commitment) + (w : CoreReader.Integration.World), + @CoreReader.Evidence.ValuePosition.consequence CoreReader.Integration.World + (CoreReader.Integration.commitmentPosition c) w +CoreReader.Integration.positionProcedure : ∀ (c : CoreReader.Integration.Commitment), + @CoreReader.Evidence.ValueProcedure CoreReader.Integration.World (CoreReader.Integration.commitmentPosition c) +CoreReader.Integration.criticismWithinScope : ∀ (c : CoreReader.Integration.Commitment), + And + (@CoreReader.Evidence.ValuePosition.limits CoreReader.Integration.World + (CoreReader.Integration.commitmentPosition c) CoreReader.Integration.actual) + (@CoreReader.Evidence.ValuePosition.relevantCriticism CoreReader.Integration.World + (CoreReader.Integration.commitmentPosition c) CoreReader.Integration.actual) +CoreReader.Integration.oppositeConsequenceFails : ∀ (c : CoreReader.Integration.Commitment) + (w : CoreReader.Integration.World), + Not + (@CoreReader.Evidence.ValuePosition.consequence CoreReader.Integration.World + (CoreReader.Integration.commitmentPositionFor c CoreReader.Integration.Mode.waive) w) +CoreReader.Integration.oppositeProcedureRejected : ∀ (c : CoreReader.Integration.Commitment), + Not + (@CoreReader.Evidence.ValueProcedure CoreReader.Integration.World + (CoreReader.Integration.commitmentPositionFor c CoreReader.Integration.Mode.waive)) +CoreReader.Integration.commitmentClaim : CoreReader.Integration.Commitment → + CoreReader.Logic.Claim CoreReader.Integration.World +CoreReader.Integration.commitmentFacet : CoreReader.Integration.Commitment → + CoreReader.Evidence.Facet CoreReader.Integration.World +CoreReader.Integration.reasonsBelongToCommitments : ∀ (c : CoreReader.Integration.Commitment), + And + (@CoreReader.Evidence.Grounds CoreReader.Integration.World (CoreReader.Integration.commitmentClaim c) + (@CoreReader.Evidence.canonicalArticulation CoreReader.Integration.World) + (fun f => + @Eq.{2} (CoreReader.Evidence.Facet CoreReader.Integration.World) f (CoreReader.Integration.commitmentFacet c)) + (@List.cons.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World) + (CoreReader.Integration.commitmentFacet c) + (@List.nil.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World)))) + (And (@CoreReader.Evidence.JointAdoption CoreReader.Integration.World (CoreReader.Integration.commitmentPosition c)) + (And + (@CoreReader.Evidence.ValuePosition.relevantCriticism CoreReader.Integration.World + (CoreReader.Integration.commitmentPosition c) CoreReader.Integration.actual) + (Not + (@CoreReader.Evidence.ValueProcedure CoreReader.Integration.World + (CoreReader.Integration.commitmentPositionFor c CoreReader.Integration.Mode.waive))))) +CoreReader.Integration.groundsCommitmentIsProvision : @Eq.{1} (CoreReader.Logic.Claim CoreReader.Integration.World) + (CoreReader.Integration.commitmentClaim CoreReader.Integration.Commitment.grounds) fun w => + CoreReader.Integration.GroundsProvision (@Prod.snd.{0, 0} CoreReader.Choice.Candidate CoreReader.Integration.Mode w) +CoreReader.Integration.groundsSelfAssessment : And + (@CoreReader.Evidence.Grounds CoreReader.Integration.World + (fun w => + CoreReader.Integration.GroundsProvision + (@Prod.snd.{0, 0} CoreReader.Choice.Candidate CoreReader.Integration.Mode w)) + (@CoreReader.Evidence.canonicalArticulation CoreReader.Integration.World) + (fun f => + @Eq.{2} (CoreReader.Evidence.Facet CoreReader.Integration.World) f + (CoreReader.Integration.commitmentFacet CoreReader.Integration.Commitment.grounds)) + (@List.cons.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World) + (CoreReader.Integration.commitmentFacet CoreReader.Integration.Commitment.grounds) + (@List.nil.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World)))) + (And + (@CoreReader.Evidence.ValuePosition.limits CoreReader.Integration.World + (CoreReader.Integration.commitmentPosition CoreReader.Integration.Commitment.grounds) + CoreReader.Integration.actual) + (And + (@CoreReader.Evidence.ValuePosition.relevantCriticism CoreReader.Integration.World + (CoreReader.Integration.commitmentPosition CoreReader.Integration.Commitment.grounds) + CoreReader.Integration.actual) + (Not + (@CoreReader.Evidence.ValueProcedure CoreReader.Integration.World + (CoreReader.Integration.commitmentPositionFor CoreReader.Integration.Commitment.grounds + CoreReader.Integration.Mode.waive))))) +CoreReader.Integration.PhilosophyMethod : Type +CoreReader.Integration.currentPhilosophy : CoreReader.Integration.System → + CoreReader.Integration.World → CoreReader.Integration.PhilosophyMethod +CoreReader.Integration.PhilosophyMethod.review : CoreReader.Integration.PhilosophyMethod → Nat → Nat +CoreReader.Integration.PhilosophyMethod.implementation : CoreReader.Integration.PhilosophyMethod → + CoreReader.Choice.Implementation +CoreReader.Integration.proposalRequirements : CoreReader.Choice.Requirements +CoreReader.Integration.currentReviewCorrect : ∀ (n : Nat), + CoreReader.Integration.proposalRequirements.inputs n → + @Eq.{1} Nat + ((CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem + CoreReader.Integration.actual).review + n) + (CoreReader.Integration.proposalRequirements.expected n) +CoreReader.Integration.existingPhilosophyNotPrivileged : And + (@Eq.{1} CoreReader.Agency.Form + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).form + CoreReader.Integration.actualSystem.principleForm) + (And + (@Eq.{1} CoreReader.Integration.Mode + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).mode + (CoreReader.Integration.actualSystem.governance CoreReader.Integration.actual)) + (And + (Not + (CoreReader.Choice.JustifiedChoice CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem + CoreReader.Integration.actual).implementation + (@List.cons.{0} CoreReader.Choice.Reason + (CoreReader.Choice.Reason.status CoreReader.Choice.StatusKind.standing) + (@List.nil.{0} CoreReader.Choice.Reason)))) + (And + (CoreReader.Choice.JustifiedChoice CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem + CoreReader.Integration.actual).implementation + (@List.cons.{0} CoreReader.Choice.Reason + (CoreReader.Choice.Reason.method CoreReader.Choice.MethodReason.output) + (@List.nil.{0} CoreReader.Choice.Reason))) + (And + (@Eq.{1} Nat + ((CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem + CoreReader.Integration.actual).review + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (@Eq.{1} Nat + ((CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem + CoreReader.Integration.actual).review + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))))))) +CoreReader.Integration.applicationClaim : CoreReader.Integration.System → + CoreReader.Choice.Requirements → + (CoreReader.Choice.Requirements → CoreReader.Choice.Implementation → Prop) → + CoreReader.Logic.Claim CoreReader.Integration.World +CoreReader.Integration.ApplicationDuties : CoreReader.Integration.System → + CoreReader.Integration.World → + CoreReader.Choice.Requirements → + (CoreReader.Choice.Requirements → CoreReader.Choice.Implementation → Prop) → + (CoreReader.Evidence.Facet CoreReader.Integration.World → + CoreReader.Evidence.Articulation CoreReader.Integration.World) → + (CoreReader.Evidence.Facet CoreReader.Integration.World → Prop) → + List.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World) → Prop +CoreReader.Integration.applicationRetainsDuties : ∀ (s : CoreReader.Integration.System) + (w : CoreReader.Integration.World) (req : CoreReader.Choice.Requirements) + (contract : CoreReader.Choice.Requirements → CoreReader.Choice.Implementation → Prop) + (articulations : + CoreReader.Evidence.Facet CoreReader.Integration.World → + CoreReader.Evidence.Articulation CoreReader.Integration.World) + (applicable : CoreReader.Evidence.Facet CoreReader.Integration.World → Prop) + (facets : List.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World)), + CoreReader.Integration.ApplicationDuties s w req contract articulations applicable facets → + And (CoreReader.Agency.Reflexive s.owner (s.rules w) (s.work w)) + (And + (∀ (f : CoreReader.Evidence.Facet CoreReader.Integration.World), + applicable f → + @Membership.mem.{1, 1} (CoreReader.Evidence.Facet CoreReader.Integration.World) + (List.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World)) + (@List.instMembership.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World)) facets f) + (∀ (f : CoreReader.Evidence.Facet CoreReader.Integration.World), + @Membership.mem.{1, 1} (CoreReader.Evidence.Facet CoreReader.Integration.World) + (List.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World)) + (@List.instMembership.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World)) facets f → + And + (@Eq.{1} (CoreReader.Logic.Claim CoreReader.Integration.World) + (@CoreReader.Evidence.Facet.claim CoreReader.Integration.World f) + (CoreReader.Integration.applicationClaim s req contract)) + (And (@CoreReader.Evidence.Articulated CoreReader.Integration.World (articulations f)) + (And (@CoreReader.Evidence.FacetArticulated CoreReader.Integration.World (articulations f) f) + (@CoreReader.Evidence.FacetDischarged CoreReader.Integration.World f))))) +CoreReader.Integration.outputContract : CoreReader.Choice.Requirements → CoreReader.Choice.Implementation → Prop +CoreReader.Integration.successorRequirements : CoreReader.Choice.Requirements +CoreReader.Integration.changedObjectiveFacet : CoreReader.Evidence.Facet CoreReader.Integration.World +CoreReader.Integration.applicationVariation : And + (CoreReader.Integration.ApplicationDuties CoreReader.Integration.actualSystem CoreReader.Integration.actual + CoreReader.Choice.identityRequirements CoreReader.Integration.outputContract + (@CoreReader.Evidence.canonicalArticulation CoreReader.Integration.World) + (fun f => @Eq.{2} (CoreReader.Evidence.Facet CoreReader.Integration.World) f CoreReader.Integration.capabilityFacet) + (@List.cons.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World) CoreReader.Integration.capabilityFacet + (@List.nil.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World)))) + (And + (Not + (CoreReader.Integration.applicationClaim CoreReader.Integration.actualSystem + CoreReader.Integration.successorRequirements CoreReader.Integration.outputContract + CoreReader.Integration.actual)) + (Not + (@CoreReader.Evidence.Grounds CoreReader.Integration.World + (CoreReader.Integration.applicationClaim CoreReader.Integration.actualSystem + CoreReader.Integration.successorRequirements CoreReader.Integration.outputContract) + (@CoreReader.Evidence.canonicalArticulation CoreReader.Integration.World) + (fun f => + @Eq.{2} (CoreReader.Evidence.Facet CoreReader.Integration.World) f + CoreReader.Integration.changedObjectiveFacet) + (@List.cons.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World) + CoreReader.Integration.changedObjectiveFacet + (@List.nil.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World)))))) +CoreReader.Integration.charterNotGrounds : And + (CoreReader.Integration.Charter CoreReader.Integration.actualSystem CoreReader.Integration.actual) + (And + (@CoreReader.Evidence.Compatible CoreReader.Integration.World + (@List.cons.{0} (CoreReader.Evidence.Record CoreReader.Integration.World) + CoreReader.Integration.costAllowanceRecord + (@List.nil.{0} (CoreReader.Evidence.Record CoreReader.Integration.World))) + CoreReader.Integration.actual) + (Not + (@CoreReader.Evidence.Grounds CoreReader.Integration.World CoreReader.Integration.capability + (@CoreReader.Evidence.canonicalArticulation CoreReader.Integration.World) + (fun f => + @Eq.{2} (CoreReader.Evidence.Facet CoreReader.Integration.World) f + CoreReader.Integration.unsupportedCapabilityFacet) + (@List.cons.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World) + CoreReader.Integration.unsupportedCapabilityFacet + (@List.nil.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World)))))) +CoreReader.Integration.jointWitness : @Exists.{1} CoreReader.Integration.System fun s => + @Exists.{1} CoreReader.Integration.World fun w => + And + (@CoreReader.Logic.Admissible CoreReader.Integration.World CoreReader.Integration.Question + (CoreReader.Integration.systemHeld s) (CoreReader.Integration.systemContext s) w) + (And (CoreReader.Integration.Charter s w) + (And + (CoreReader.Integration.OwnCapabilityDuty s w + (@List.cons.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World) + CoreReader.Integration.capabilityFacet + (@List.nil.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World)))) + (And (CoreReader.Integration.systemCapability s w) + (And + (CoreReader.Choice.JustifiedChoice s.requirements (s.method.realize w) CoreReader.Choice.objectiveReason) + (And + (∀ (c : CoreReader.Integration.Commitment), + @CoreReader.Evidence.Grounds CoreReader.Integration.World (CoreReader.Integration.commitmentClaim c) + (@CoreReader.Evidence.canonicalArticulation CoreReader.Integration.World) + (fun f => + @Eq.{2} (CoreReader.Evidence.Facet CoreReader.Integration.World) f + (CoreReader.Integration.commitmentFacet c)) + (@List.cons.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World) + (CoreReader.Integration.commitmentFacet c) + (@List.nil.{1} (CoreReader.Evidence.Facet CoreReader.Integration.World)))) + (And (@Eq.{1} CoreReader.Integration.System s CoreReader.Integration.actualSystem) + (@Eq.{1} CoreReader.Integration.World w CoreReader.Integration.actual))))))) +CoreReader.Logic.Claim : Type → Type +CoreReader.Logic.Theory : Type → Type +@CoreReader.Logic.Models : {W : Type} → CoreReader.Logic.Theory W → W → Prop +@CoreReader.Logic.Entails : {W : Type} → CoreReader.Logic.Theory W → CoreReader.Logic.Claim W → Prop +@CoreReader.Logic.Satisfiable : {W : Type} → CoreReader.Logic.Theory W → Prop +CoreReader.Logic.Context : Type → Type → Type +@CoreReader.Logic.Admissible : {W Q : Type} → CoreReader.Logic.Theory W → CoreReader.Logic.Context W Q → W → Prop +@CoreReader.Logic.Consequence : {W Q : Type} → + CoreReader.Logic.Theory W → CoreReader.Logic.Context W Q → Q → Bool → Prop +@CoreReader.Logic.Consistent : {W Q : Type} → CoreReader.Logic.Theory W → CoreReader.Logic.Context W Q → Prop +@CoreReader.Logic.consequenceConsistency : ∀ {W Q : Type} (t : CoreReader.Logic.Theory W) + (c : CoreReader.Logic.Context W Q), + (@Exists.{1} W fun w => @CoreReader.Logic.Admissible W Q t c w) → @CoreReader.Logic.Consistent W Q t c +@CoreReader.Logic.emptyTheory : {W : Type} → CoreReader.Logic.Theory W +@CoreReader.Logic.singleton : {W : Type} → CoreReader.Logic.Claim W → CoreReader.Logic.Theory W +@CoreReader.Logic.union : {W : Type} → CoreReader.Logic.Theory W → CoreReader.Logic.Theory W → CoreReader.Logic.Theory W +@CoreReader.Logic.modelsSingleton : ∀ {W : Type} (p : CoreReader.Logic.Claim W) (w : W), + Iff (@CoreReader.Logic.Models W (@CoreReader.Logic.singleton W p) w) (p w) +@CoreReader.Logic.modelsUnion : ∀ {W : Type} (a b : CoreReader.Logic.Theory W) (w : W), + Iff (@CoreReader.Logic.Models W (@CoreReader.Logic.union W a b) w) + (And (@CoreReader.Logic.Models W a w) (@CoreReader.Logic.Models W b w)) +CoreReader.Logic.premiseP : CoreReader.Logic.Claim (Prod.{0, 0} Bool Bool) +CoreReader.Logic.premiseRule : CoreReader.Logic.Claim (Prod.{0, 0} Bool Bool) +CoreReader.Logic.premiseNotQ : CoreReader.Logic.Claim (Prod.{0, 0} Bool Bool) +CoreReader.Logic.jointTheory : CoreReader.Logic.Theory (Prod.{0, 0} Bool Bool) +CoreReader.Logic.jointConflict : And + (@CoreReader.Logic.Satisfiable (Prod.{0, 0} Bool Bool) + (@CoreReader.Logic.singleton (Prod.{0, 0} Bool Bool) CoreReader.Logic.premiseP)) + (And + (@CoreReader.Logic.Satisfiable (Prod.{0, 0} Bool Bool) + (@CoreReader.Logic.singleton (Prod.{0, 0} Bool Bool) CoreReader.Logic.premiseRule)) + (And + (@CoreReader.Logic.Satisfiable (Prod.{0, 0} Bool Bool) + (@CoreReader.Logic.singleton (Prod.{0, 0} Bool Bool) CoreReader.Logic.premiseNotQ)) + (Not (@CoreReader.Logic.Satisfiable (Prod.{0, 0} Bool Bool) CoreReader.Logic.jointTheory)))) +CoreReader.Logic.revisionSlice : Nat → CoreReader.Logic.Theory Bool +CoreReader.Logic.revisionCanReverse : And + (@CoreReader.Logic.Satisfiable Bool + (CoreReader.Logic.revisionSlice (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))))) + (And + (@CoreReader.Logic.Satisfiable Bool + (CoreReader.Logic.revisionSlice (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1))))) + (Not + (@CoreReader.Logic.Satisfiable Bool + (@CoreReader.Logic.union Bool + (CoreReader.Logic.revisionSlice (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Logic.revisionSlice (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))))))) +CoreReader.Logic.onQuestion : Unit → CoreReader.Logic.Claim Bool +CoreReader.Logic.assumptionContext : Bool → CoreReader.Logic.Context Bool Unit +CoreReader.Logic.meaningContext : Bool → CoreReader.Logic.Context Bool Unit +CoreReader.Logic.scopeContext : Bool → CoreReader.Logic.Context Bool Unit +CoreReader.Logic.contextDifferences : And + (And + (@CoreReader.Logic.Consequence Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.assumptionContext Bool.true) Unit.unit Bool.true) + (@CoreReader.Logic.Consequence Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.assumptionContext Bool.false) Unit.unit Bool.false)) + (And + (And + (@CoreReader.Logic.Consequence Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.meaningContext Bool.true) Unit.unit Bool.true) + (@CoreReader.Logic.Consequence Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.meaningContext Bool.false) Unit.unit Bool.false)) + (And + (And + (@CoreReader.Logic.Consequence Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.scopeContext Bool.true) Unit.unit Bool.true) + (@CoreReader.Logic.Consequence Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.scopeContext Bool.false) Unit.unit Bool.false)) + (And + (∀ (b : Bool), + @Exists.{1} Bool fun w => + @CoreReader.Logic.Admissible Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.assumptionContext b) w) + (And + (∀ (b : Bool), + @Exists.{1} Bool fun w => + @CoreReader.Logic.Admissible Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.meaningContext b) w) + (∀ (b : Bool), + @Exists.{1} Bool fun w => + @CoreReader.Logic.Admissible Bool Unit (@CoreReader.Logic.emptyTheory Bool) + (CoreReader.Logic.scopeContext b) w))))) +CoreReader.Logic.Snapshot : Type → Type → Type +@CoreReader.Logic.SameContent : {W Q : Type} → CoreReader.Logic.Snapshot W Q → CoreReader.Logic.Snapshot W Q → Prop +@CoreReader.Logic.TruthfulReport : {W Q : Type} → + CoreReader.Logic.Snapshot W Q → CoreReader.Logic.Snapshot W Q → Bool → Prop +@CoreReader.Logic.semanticChangeMustBeReported : ∀ {W Q : Type} (a b : CoreReader.Logic.Snapshot W Q) (reported : Bool), + Or (Not (@CoreReader.Logic.SameContent W Q a b)) + (@Ne.{1} Nat (@CoreReader.Logic.Snapshot.revisionIdentity W Q a) + (@CoreReader.Logic.Snapshot.revisionIdentity W Q b)) → + @CoreReader.Logic.TruthfulReport W Q a b reported → @Eq.{1} Bool reported Bool.true +@CoreReader.Logic.representationOrderIrrelevant : ∀ {W : Type} (p q r : CoreReader.Logic.Claim W), + Iff (@CoreReader.Logic.union W (@CoreReader.Logic.singleton W p) (@CoreReader.Logic.singleton W q) r) + (@CoreReader.Logic.union W (@CoreReader.Logic.singleton W q) (@CoreReader.Logic.singleton W p) r) +@CoreReader.Logic.contextSnapshot : CoreReader.Logic.Context Bool Unit → + optParam.{1} Nat (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) → CoreReader.Logic.Snapshot Bool Unit +CoreReader.Logic.hiddenContextChangeRejected : And + (Not + (@CoreReader.Logic.TruthfulReport Bool Unit + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.assumptionContext Bool.true) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.assumptionContext Bool.false) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + Bool.false)) + (And + (Not + (@CoreReader.Logic.TruthfulReport Bool Unit + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.meaningContext Bool.true) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.meaningContext Bool.false) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + Bool.false)) + (And + (Not + (@CoreReader.Logic.TruthfulReport Bool Unit + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.scopeContext Bool.true) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.scopeContext Bool.false) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + Bool.false)) + (And + (Not + (@CoreReader.Logic.TruthfulReport Bool Unit + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.scopeContext Bool.true) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.scopeContext Bool.true) + (@OfNat.ofNat.{0} Nat (nat_lit 1) (instOfNatNat (nat_lit 1)))) + Bool.false)) + (And + (@CoreReader.Logic.TruthfulReport Bool Unit + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.assumptionContext Bool.true) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + (CoreReader.Logic.contextSnapshot (CoreReader.Logic.assumptionContext Bool.false) + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + Bool.true) + (Not + (@CoreReader.Logic.Models Bool + (@CoreReader.Logic.Context.assumptions Bool Unit (CoreReader.Logic.assumptionContext Bool.false)) + Bool.true)))))) +CoreReader.Logic.tensionWithoutContradiction : And + (@Exists.{1} Nat fun budget => + And (@LE.le.{0} Nat instLENat (@OfNat.ofNat.{0} Nat (nat_lit 4) (instOfNatNat (nat_lit 4))) budget) + (@LE.le.{0} Nat instLENat budget (@OfNat.ofNat.{0} Nat (nat_lit 6) (instOfNatNat (nat_lit 6))))) + (Not + (@Eq.{1} (Nat → Prop) + (fun n => @LE.le.{0} Nat instLENat (@OfNat.ofNat.{0} Nat (nat_lit 4) (instOfNatNat (nat_lit 4))) n) fun n => + @LE.le.{0} Nat instLENat n (@OfNat.ofNat.{0} Nat (nat_lit 6) (instOfNatNat (nat_lit 6))))) +@CoreReader.Logic.conflictRequiresChange : ∀ {W Q : Type} (t : CoreReader.Logic.Theory W) + (c : CoreReader.Logic.Context W Q) (q : Q), + @CoreReader.Logic.Consequence W Q t c q Bool.true → + @CoreReader.Logic.Consequence W Q t c q Bool.false → Not (@CoreReader.Logic.Consistent W Q t c) +CoreReader.Logic.consistentFalse : And + (@CoreReader.Logic.Satisfiable Bool (@CoreReader.Logic.singleton Bool fun w => @Eq.{1} Bool w Bool.true)) + (Not (@CoreReader.Logic.Models Bool (@CoreReader.Logic.singleton Bool fun w => @Eq.{1} Bool w Bool.true) Bool.false)) +CoreReader.Logic.consistentIncomplete : And (@CoreReader.Logic.Satisfiable Bool (@CoreReader.Logic.emptyTheory Bool)) + (And (Not (@CoreReader.Logic.Entails Bool (@CoreReader.Logic.emptyTheory Bool) fun w => @Eq.{1} Bool w Bool.true)) + (Not (@CoreReader.Logic.Entails Bool (@CoreReader.Logic.emptyTheory Bool) fun w => @Ne.{1} Bool w Bool.true))) +CoreReader.Logic.compatibilityNotEntailment : And + (@CoreReader.Logic.Satisfiable Bool + (@CoreReader.Logic.union Bool (@CoreReader.Logic.emptyTheory Bool) + (@CoreReader.Logic.singleton Bool fun w => @Eq.{1} Bool w Bool.true))) + (Not (@CoreReader.Logic.Entails Bool (@CoreReader.Logic.emptyTheory Bool) fun w => @Eq.{1} Bool w Bool.true)) +CoreReader.Agency.Phase : Type +CoreReader.Agency.PrincipleKey : Type +CoreReader.Agency.Subject : Type +CoreReader.Agency.Subject.owner : CoreReader.Agency.Subject → Nat +CoreReader.Agency.Activity : Type +CoreReader.Agency.QuestionKind : Type +CoreReader.Agency.SampleProgram : Type +CoreReader.Agency.SampleProgram.run : CoreReader.Agency.SampleProgram → Nat → Bool +CoreReader.Agency.MethodDraft : Type +CoreReader.Agency.MethodDraft.accepts : CoreReader.Agency.MethodDraft → CoreReader.Agency.SampleProgram → Bool +CoreReader.Agency.Inquiry : Type +CoreReader.Agency.ReasonContent : Type +CoreReader.Agency.ReasonContent.identifier : CoreReader.Agency.ReasonContent → Nat +CoreReader.Agency.ReasonObject : Type +CoreReader.Agency.AssessmentResult : Type +CoreReader.Agency.WorkOutcome : Type +CoreReader.Agency.Principle : Type +CoreReader.Agency.WorkRecord : Type +CoreReader.Agency.RegistryCoherent : List.{0} CoreReader.Agency.Principle → Prop +CoreReader.Agency.TargetResolved : List.{0} CoreReader.Agency.Principle → CoreReader.Agency.Subject → Prop +CoreReader.Agency.TargetContentResolved : List.{0} CoreReader.Agency.Principle → CoreReader.Agency.Inquiry → Prop +CoreReader.Agency.Performed : List.{0} CoreReader.Agency.WorkRecord → + CoreReader.Agency.Subject → CoreReader.Agency.Activity → Prop +CoreReader.Agency.ReflexiveScope : Nat → + List.{0} CoreReader.Agency.Principle → List.{0} CoreReader.Agency.WorkRecord → Prop +CoreReader.Agency.ValidApplication : List.{0} CoreReader.Agency.Principle → + CoreReader.Agency.Principle → CoreReader.Agency.Subject → CoreReader.Agency.WorkRecord → Prop +CoreReader.Agency.Reflexive : Nat → List.{0} CoreReader.Agency.Principle → List.{0} CoreReader.Agency.WorkRecord → Prop +@CoreReader.Agency.Reflexive.toScope : ∀ {owner : Nat} {rules : List.{0} CoreReader.Agency.Principle} + {records : List.{0} CoreReader.Agency.WorkRecord}, + CoreReader.Agency.Reflexive owner rules records → CoreReader.Agency.ReflexiveScope owner rules records +CoreReader.Agency.noSelfExemption : ∀ (owner : Nat) (rules : List.{0} CoreReader.Agency.Principle) + (records : List.{0} CoreReader.Agency.WorkRecord), + CoreReader.Agency.Reflexive owner rules records → + ∀ (rule : CoreReader.Agency.Principle), + @Membership.mem.{0, 0} CoreReader.Agency.Principle (List.{0} CoreReader.Agency.Principle) + (@List.instMembership.{0} CoreReader.Agency.Principle) rules rule → + ∀ (s : CoreReader.Agency.Subject), + @Eq.{1} Nat s.owner owner → rule.applicable s → CoreReader.Agency.Performed records s rule.activity +CoreReader.Agency.localMethod : CoreReader.Agency.MethodDraft +CoreReader.Agency.inquiryFor : CoreReader.Agency.Subject → CoreReader.Agency.Inquiry +CoreReader.Agency.sourceReasonContents : CoreReader.Agency.QuestionKind → List.{0} CoreReader.Agency.ReasonContent +CoreReader.Agency.reasonsFor : CoreReader.Agency.Subject → List.{0} CoreReader.Agency.ReasonObject +CoreReader.Agency.assessInquiry : CoreReader.Agency.Inquiry → + List.{0} CoreReader.Agency.ReasonObject → List.{0} Nat → CoreReader.Agency.AssessmentResult +CoreReader.Agency.finiteMethodResult : CoreReader.Agency.Activity → + CoreReader.Agency.Inquiry → List.{0} CoreReader.Agency.ReasonObject → List.{0} Nat → CoreReader.Agency.WorkOutcome +CoreReader.Agency.finiteMethodMeaning : CoreReader.Agency.Activity → + CoreReader.Agency.Inquiry → + List.{0} CoreReader.Agency.ReasonObject → List.{0} Nat → CoreReader.Agency.WorkOutcome → Prop +CoreReader.Agency.ownSubjects : Nat → List.{0} CoreReader.Agency.Subject +CoreReader.Agency.generationEligible : CoreReader.Agency.Subject → Bool +CoreReader.Agency.generatingRule : Nat → CoreReader.Agency.Principle +CoreReader.Agency.assessingRule : Nat → CoreReader.Agency.Principle +CoreReader.Agency.ownRules : Nat → List.{0} CoreReader.Agency.Principle +CoreReader.Agency.statedOutcome : CoreReader.Agency.Activity → CoreReader.Agency.Subject → CoreReader.Agency.WorkOutcome +CoreReader.Agency.recordFor : CoreReader.Agency.Principle → CoreReader.Agency.Subject → CoreReader.Agency.WorkRecord +CoreReader.Agency.reasonsFor_nonempty : ∀ (s : CoreReader.Agency.Subject), + @Ne.{1} (List.{0} CoreReader.Agency.ReasonObject) (CoreReader.Agency.reasonsFor s) + (@List.nil.{0} CoreReader.Agency.ReasonObject) +CoreReader.Agency.reasonsFor_target : ∀ (s : CoreReader.Agency.Subject) (reason : CoreReader.Agency.ReasonObject), + @Membership.mem.{0, 0} CoreReader.Agency.ReasonObject (List.{0} CoreReader.Agency.ReasonObject) + (@List.instMembership.{0} CoreReader.Agency.ReasonObject) (CoreReader.Agency.reasonsFor s) reason → + @Eq.{1} CoreReader.Agency.Subject reason.target s +CoreReader.Agency.inquiryFor_target : ∀ (s : CoreReader.Agency.Subject), + @Eq.{1} CoreReader.Agency.Subject (CoreReader.Agency.inquiryFor s).target s +CoreReader.Agency.ownContentEvaluates : ∀ (activity : CoreReader.Agency.Activity) (s : CoreReader.Agency.Subject), + @Eq.{1} CoreReader.Agency.WorkOutcome (CoreReader.Agency.statedOutcome activity s) + (CoreReader.Agency.finiteMethodResult activity (CoreReader.Agency.inquiryFor s) (CoreReader.Agency.reasonsFor s) + (@List.cons.{0} Nat (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) (@List.nil.{0} Nat))) +CoreReader.Agency.ownRegistryCoherent : ∀ (owner : Nat), + CoreReader.Agency.RegistryCoherent (CoreReader.Agency.ownRules owner) +CoreReader.Agency.ownTargetResolved : ∀ (owner : Nat) (s : CoreReader.Agency.Subject), + @Membership.mem.{0, 0} CoreReader.Agency.Subject (List.{0} CoreReader.Agency.Subject) + (@List.instMembership.{0} CoreReader.Agency.Subject) (CoreReader.Agency.ownSubjects owner) s → + CoreReader.Agency.TargetResolved (CoreReader.Agency.ownRules owner) s +CoreReader.Agency.ownTargetContent : ∀ (owner : Nat) (s : CoreReader.Agency.Subject), + @Membership.mem.{0, 0} CoreReader.Agency.Subject (List.{0} CoreReader.Agency.Subject) + (@List.instMembership.{0} CoreReader.Agency.Subject) (CoreReader.Agency.ownSubjects owner) s → + CoreReader.Agency.TargetContentResolved (CoreReader.Agency.ownRules owner) (CoreReader.Agency.inquiryFor s) +CoreReader.Agency.ownRecordValid : ∀ (owner : Nat) (rule : CoreReader.Agency.Principle), + @Membership.mem.{0, 0} CoreReader.Agency.Principle (List.{0} CoreReader.Agency.Principle) + (@List.instMembership.{0} CoreReader.Agency.Principle) (CoreReader.Agency.ownRules owner) rule → + ∀ (s : CoreReader.Agency.Subject), + rule.applicable s → + CoreReader.Agency.ValidApplication (CoreReader.Agency.ownRules owner) rule s + (CoreReader.Agency.recordFor rule s) +CoreReader.Agency.completeOwnWork : Nat → List.{0} CoreReader.Agency.WorkRecord +CoreReader.Agency.assessingRecord_member : ∀ (owner : Nat) (s : CoreReader.Agency.Subject), + @Membership.mem.{0, 0} CoreReader.Agency.Subject (List.{0} CoreReader.Agency.Subject) + (@List.instMembership.{0} CoreReader.Agency.Subject) (CoreReader.Agency.ownSubjects owner) s → + @Membership.mem.{0, 0} CoreReader.Agency.WorkRecord (List.{0} CoreReader.Agency.WorkRecord) + (@List.instMembership.{0} CoreReader.Agency.WorkRecord) (CoreReader.Agency.completeOwnWork owner) + (CoreReader.Agency.recordFor (CoreReader.Agency.assessingRule owner) s) +CoreReader.Agency.generatingRecord_member : ∀ (owner : Nat) (s : CoreReader.Agency.Subject), + @Membership.mem.{0, 0} CoreReader.Agency.Subject (List.{0} CoreReader.Agency.Subject) + (@List.instMembership.{0} CoreReader.Agency.Subject) (CoreReader.Agency.ownSubjects owner) s → + @Eq.{1} Bool (CoreReader.Agency.generationEligible s) Bool.true → + @Membership.mem.{0, 0} CoreReader.Agency.WorkRecord (List.{0} CoreReader.Agency.WorkRecord) + (@List.instMembership.{0} CoreReader.Agency.WorkRecord) (CoreReader.Agency.completeOwnWork owner) + (CoreReader.Agency.recordFor (CoreReader.Agency.generatingRule owner) s) +CoreReader.Agency.completeOwnWork_reflexive : ∀ (owner : Nat), + CoreReader.Agency.Reflexive owner (CoreReader.Agency.ownRules owner) (CoreReader.Agency.completeOwnWork owner) +CoreReader.Agency.ownAssessmentPerformed : ∀ (owner : Nat) (s : CoreReader.Agency.Subject), + @Membership.mem.{0, 0} CoreReader.Agency.Subject (List.{0} CoreReader.Agency.Subject) + (@List.instMembership.{0} CoreReader.Agency.Subject) (CoreReader.Agency.ownSubjects owner) s → + CoreReader.Agency.Performed (CoreReader.Agency.completeOwnWork owner) s CoreReader.Agency.Activity.assessment +CoreReader.Agency.applicationRule : CoreReader.Agency.Principle +CoreReader.Agency.applicationWork : List.{0} CoreReader.Agency.WorkRecord +CoreReader.Agency.applicationWork_reflexive : CoreReader.Agency.Reflexive + (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@List.cons.{0} CoreReader.Agency.Principle CoreReader.Agency.applicationRule + (@List.nil.{0} CoreReader.Agency.Principle)) + CoreReader.Agency.applicationWork +CoreReader.Agency.applicabilityRetained : ∀ (owner : Nat) (rules : List.{0} CoreReader.Agency.Principle) + (records : List.{0} CoreReader.Agency.WorkRecord), + And (CoreReader.Agency.Reflexive owner rules records → CoreReader.Agency.ReflexiveScope owner rules records) + (And + (Iff (CoreReader.Agency.ReflexiveScope owner rules records) + (∀ (rule : CoreReader.Agency.Principle), + @Membership.mem.{0, 0} CoreReader.Agency.Principle (List.{0} CoreReader.Agency.Principle) + (@List.instMembership.{0} CoreReader.Agency.Principle) rules rule → + ∀ (s : CoreReader.Agency.Subject), + @Eq.{1} Nat s.owner owner → + Or (Not (rule.applicable s)) (CoreReader.Agency.Performed records s rule.activity))) + (And + (CoreReader.Agency.Reflexive (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0))) + (@List.cons.{0} CoreReader.Agency.Principle CoreReader.Agency.applicationRule + (@List.nil.{0} CoreReader.Agency.Principle)) + CoreReader.Agency.applicationWork) + (Not + (CoreReader.Agency.Performed CoreReader.Agency.applicationWork + (CoreReader.Agency.Subject.system (@OfNat.ofNat.{0} Nat (nat_lit 0) (instOfNatNat (nat_lit 0)))) + CoreReader.Agency.Activity.assessment)))) +'CoreReader.Adopted.AssessmentTask' does not depend on any axioms +'CoreReader.Adopted.taskOfFacet' does not depend on any axioms +'CoreReader.Adopted.NatureAppropriate' depends on axioms: [propext] +'CoreReader.Adopted.taskOfFacetAppropriate' depends on axioms: [propext] +'CoreReader.Adopted.Grounds012' depends on axioms: [propext] +'CoreReader.Adopted.grounds012Singleton' depends on axioms: [propext] +'CoreReader.Adopted.generationSpecification' does not depend on any axioms +'CoreReader.Adopted.consistencySpecification' does not depend on any axioms +'CoreReader.Adopted.ReflexiveRule' does not depend on any axioms +'CoreReader.Adopted.reflexivitySpecification' does not depend on any axioms +'CoreReader.Adopted.legacyRule' does not depend on any axioms +'CoreReader.Adopted.legacyPerformed' does not depend on any axioms +'CoreReader.Adopted.legacyReflexivity' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Adopted.empiricalSpecification' depends on axioms: [propext] +'CoreReader.Adopted.inferentialSpecification' depends on axioms: [propext] +'CoreReader.Adopted.valueSpecification' depends on axioms: [propext] +'CoreReader.Adopted.AssessmentMethod' does not depend on any axioms +'CoreReader.Adopted.ScopeAccount' does not depend on any axioms +'CoreReader.Adopted.scopeSpecification' does not depend on any axioms +'CoreReader.Adopted.capabilitySpecification' depends on axioms: [propext] +'CoreReader.Adopted.choiceSpecification' does not depend on any axioms +'CoreReader.Adopted.collaborativeRevision' does not depend on any axioms +'CoreReader.Adopted.collaborativeProgress' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Adopted.consistencyConsequences' does not depend on any axioms +'CoreReader.Adopted.broadBoolContext' does not depend on any axioms +'CoreReader.Adopted.sliceConsistency' does not depend on any axioms +'CoreReader.Adopted.explicitlyConsistentLimits' does not depend on any axioms +'CoreReader.Adopted.localFacet012' does not depend on any axioms +'CoreReader.Adopted.globalFacet012' does not depend on any axioms +'CoreReader.Adopted.strongFacet012' does not depend on any axioms +'CoreReader.Adopted.localFacetChecked012' depends on axioms: [propext] +'CoreReader.Adopted.scopeStrength012' depends on axioms: [propext] +'CoreReader.Adopted.uncertainFacet012' does not depend on any axioms +'CoreReader.Adopted.uncertainSupported012' depends on axioms: [propext] +'CoreReader.Adopted.InferenceExamined' does not depend on any axioms +'CoreReader.Adopted.inferenceChecked012' depends on axioms: [propext] +'CoreReader.Adopted.closedPosition012' does not depend on any axioms +'CoreReader.Adopted.closedCriticism012' does not depend on any axioms +'CoreReader.Adopted.valueFulfilled012' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Adopted.ClaimNoStronger' does not depend on any axioms +'CoreReader.Adopted.qualitativeProportionality012' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Adopted.scopeRole012' does not depend on any axioms +'CoreReader.Adopted.scopeRoleContent012' does not depend on any axioms +'CoreReader.Adopted.localScopeAccount012' does not depend on any axioms +'CoreReader.Adopted.scopeFulfilled012' depends on axioms: [propext] +'CoreReader.Adopted.capabilityFulfilled012' depends on axioms: [propext] +'CoreReader.Adopted.MechanismApplication012' does not depend on any axioms +'CoreReader.Adopted.mechanism012' does not depend on any axioms +'CoreReader.Adopted.UnderstandingApplication012' does not depend on any axioms +'CoreReader.Adopted.explainedWithoutVariation012' does not depend on any axioms +'CoreReader.Adopted.mechanismResponder012' does not depend on any axioms +'CoreReader.Adopted.understandingScope012' does not depend on any axioms +'CoreReader.Adopted.understandingTask012' does not depend on any axioms +'CoreReader.Adopted.understandingFacet012' does not depend on any axioms +'CoreReader.Adopted.mechanismResponderUnderstands012' depends on axioms: [propext] +'CoreReader.Adopted.explainedWithoutVariationFails012' depends on axioms: [propext] +'CoreReader.Adopted.understandingApplicationCases012' depends on axioms: [propext] +'CoreReader.Adopted.OwnCapability012' depends on axioms: [propext] +'CoreReader.Adopted.ownCapability012' depends on axioms: [propext] +'CoreReader.Adopted.CompleteCharter012' depends on axioms: [propext] +'CoreReader.Adopted.completeCharter012' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Adopted.charterWithoutGrounds012' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Adopted.groundsPermission012' depends on axioms: [propext] +'CoreReader.Adopted.GroundsProvision012' depends on axioms: [propext] +'CoreReader.Adopted.groundsProvision012Meaning' depends on axioms: [propext] +'CoreReader.Adopted.groundsExperimentTask012' does not depend on any axioms +'CoreReader.Adopted.groundsExperiment012' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Adopted.groundsPosition012' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Adopted.groundsPosition012Checked' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Adopted.groundsRationaleExperiment012' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Adopted.groundsOnGrounds012' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Adopted.reflexiveTargets012' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Adopted.achievementSupported012' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Adopted.semanticOrder012' does not depend on any axioms +'CoreReader.Adopted.clearFalseArgument012' does not depend on any axioms +'CoreReader.Adopted.clearFalseReason012' depends on axioms: [propext] +'CoreReader.Adopted.valueNeutralRecord012' does not depend on any axioms +'CoreReader.Adopted.valueNotFact012' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Adopted.wrongExplanation012' does not depend on any axioms +'CoreReader.Adopted.internalReasonDistinguishes012' does not depend on any axioms +'CoreReader.Adopted.inventoryCases012' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Adopted.selfExemptRule012' does not depend on any axioms +'CoreReader.Adopted.selfExemptPerformed012' does not depend on any axioms +'CoreReader.Adopted.openSelfExempt012' depends on axioms: [propext] +'CoreReader.Adopted.ownPhilosophyStatus012' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Adopted.jointContext012' does not depend on any axioms +'CoreReader.Adopted.jointImplicationConflict012' does not depend on any axioms +'CoreReader.Adopted.tensionContext012' does not depend on any axioms +'CoreReader.Adopted.tensionConsistent012' does not depend on any axioms +'CoreReader.Adopted.qualitativeUnmeasured012' depends on axioms: [propext] +'CoreReader.Adopted.allStatusOnly012' depends on axioms: [propext] +'CoreReader.Adopted.drawWeight012' does not depend on any axioms +'CoreReader.Adopted.randomTrial012' does not depend on any axioms +'CoreReader.Adopted.randomOutcomes012' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Adopted.originalGlobalTask012' does not depend on any axioms +'CoreReader.Adopted.originalLocalTask012' does not depend on any axioms +'CoreReader.Adopted.circularGlobalFacet012' does not depend on any axioms +'CoreReader.Adopted.circularGlobalConditional012' does not depend on any axioms +'CoreReader.Adopted.circularSubstitutionRejected012' depends on axioms: [propext] +'CoreReader.Adopted.observedPremises012' does not depend on any axioms +'CoreReader.Adopted.observedInferenceFacet012' does not depend on any axioms +'CoreReader.Adopted.observedInferenceChecked012' depends on axioms: [propext] +'CoreReader.Adopted.sameEmpiricalTaskTwoMethods012' depends on axioms: [propext] +'CoreReader.Adopted.originalUncertaintyTask012' does not depend on any axioms +'CoreReader.Adopted.uncertaintyBypassFacet012' does not depend on any axioms +'CoreReader.Adopted.uncertaintyBypassChecked012' depends on axioms: [propext] +'CoreReader.Adopted.uncertaintySubstitutionRejected012' depends on axioms: [propext] +'CoreReader.Adopted.selectedFactFacet012' does not depend on any axioms +'CoreReader.Adopted.valueFactSubstitutionRejected012' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Adopted.inferentialContextSubstitutionRejected012' depends on axioms: [propext] +'CoreReader.Adopted.generationCases' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Adopted.generationLimits012' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Adopted.consistencyCases' does not depend on any axioms +'CoreReader.Adopted.consistencyLimits012' does not depend on any axioms +'CoreReader.Adopted.reflexivityCases012' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Adopted.reflexivityLimits012' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Adopted.groundsCases012' depends on axioms: [propext] +'CoreReader.Adopted.empiricalCases012' depends on axioms: [propext] +'CoreReader.Adopted.inferentialCases012' depends on axioms: [propext] +'CoreReader.Adopted.valueCases012' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Adopted.groundsLimits012' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Adopted.scopeCases012' depends on axioms: [propext] +'CoreReader.Adopted.scopeLimits012' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Adopted.capabilityCases012' depends on axioms: [propext] +'CoreReader.Adopted.capabilityLimits012' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Adopted.choiceCases012' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Adopted.choiceLimits012' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Agency.FormKind' does not depend on any axioms +'CoreReader.Agency.Form' does not depend on any axioms +'CoreReader.Agency.Aim' does not depend on any axioms +'CoreReader.Agency.Policy' does not depend on any axioms +'CoreReader.Agency.Generative' does not depend on any axioms +'CoreReader.Agency.openPolicy' does not depend on any axioms +'CoreReader.Agency.neutralPolicy' does not depend on any axioms +'CoreReader.Agency.permissionNotValuation' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Agency.revisabilityCovers' does not depend on any axioms +'CoreReader.Agency.Operation' does not depend on any axioms +'CoreReader.Agency.Operation.run' does not depend on any axioms +'CoreReader.Agency.InventoryKind' does not depend on any axioms +'CoreReader.Agency.Item' does not depend on any axioms +'CoreReader.Agency.Available' does not depend on any axioms +'CoreReader.Agency.inventoryNotCapability' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Agency.State' does not depend on any axioms +'CoreReader.Agency.Expanded' does not depend on any axioms +'CoreReader.Agency.baseState' does not depend on any axioms +'CoreReader.Agency.inflatedState' does not depend on any axioms +'CoreReader.Agency.stableTrace' does not depend on any axioms +'CoreReader.Agency.revisionWithoutProgress' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Agency.ExternalResources' does not depend on any axioms +'CoreReader.Agency.assistedExecution' does not depend on any axioms +'CoreReader.Agency.availableResources' does not depend on any axioms +'CoreReader.Agency.StableReason' does not depend on any axioms +'CoreReader.Agency.GeneratingSystem' does not depend on any axioms +'CoreReader.Agency.generatingSystem' does not depend on any axioms +'CoreReader.Agency.GeneratingSystem.stableAction' does not depend on any axioms +'CoreReader.Agency.GeneratingSystem.requirementsMet' does not depend on any axioms +'CoreReader.Agency.GeneratingSystem.withinBudget' does not depend on any axioms +'CoreReader.Agency.Announcement' does not depend on any axioms +'CoreReader.Agency.GeneratingSystem.report' does not depend on any axioms +'CoreReader.Agency.Announcement.claim' does not depend on any axioms +'CoreReader.Agency.announcementClaimImpliesExpansion' does not depend on any axioms +'CoreReader.Agency.inflatedAnnouncement' does not depend on any axioms +'CoreReader.Agency.inflatedAnnouncementRefuted' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Agency.TransitionCase' does not depend on any axioms +'CoreReader.Agency.extendedState' does not depend on any axioms +'CoreReader.Agency.transitionBefore' does not depend on any axioms +'CoreReader.Agency.transitionAfter' does not depend on any axioms +'CoreReader.Agency.transitionInput' does not depend on any axioms +'CoreReader.Agency.transitionAnnouncement' does not depend on any axioms +'CoreReader.Agency.generationLimits' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Agency.generationNotReflexivity' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Agency.ownArithmeticPrinciple' does not depend on any axioms +'CoreReader.Agency.selfTest' does not depend on any axioms +'CoreReader.Agency.selfTestDoesNotProve' does not depend on any axioms +'CoreReader.Choice.StatusKind' does not depend on any axioms +'CoreReader.Choice.MethodReason' does not depend on any axioms +'CoreReader.Choice.Reason' does not depend on any axioms +'CoreReader.Choice.Implementation' does not depend on any axioms +'CoreReader.Choice.Requirements' does not depend on any axioms +'CoreReader.Choice.MethodContent' does not depend on any axioms +'CoreReader.Choice.Relevant' does not depend on any axioms +'CoreReader.Choice.Feasible' does not depend on any axioms +'CoreReader.Choice.JustifiedChoice' does not depend on any axioms +'CoreReader.Choice.statusOnlyFails' depends on axioms: [propext] +'CoreReader.Choice.identityImpl' does not depend on any axioms +'CoreReader.Choice.successorImpl' does not depend on any axioms +'CoreReader.Choice.changedOutsideZero' does not depend on any axioms +'CoreReader.Choice.identityRequirements' does not depend on any axioms +'CoreReader.Choice.objectiveReason' does not depend on any axioms +'CoreReader.Choice.identityOutputReason' does not depend on any axioms +'CoreReader.Choice.identityFeasible' does not depend on any axioms +'CoreReader.Choice.identityJustified' depends on axioms: [propext] +'CoreReader.Choice.conventionWithReason' depends on axioms: [propext] +'CoreReader.Choice.Candidate' does not depend on any axioms +'CoreReader.Choice.implementation' does not depend on any axioms +'CoreReader.Choice.singleFeasible' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Choice.localNotGlobal' does not depend on any axioms +'CoreReader.Choice.cheapSuccessor' does not depend on any axioms +'CoreReader.Choice.eligibleInternalReasonNotSufficient' does not depend on any axioms +'CoreReader.Choice.internalReasons' does not depend on any axioms +'CoreReader.Choice.openNotEquivalent' depends on axioms: [propext] +'CoreReader.Choice.priorityClaim' does not depend on any axioms +'CoreReader.Choice.statusFacts' does not depend on any axioms +'CoreReader.Choice.statusFactsModel' does not depend on any axioms +'CoreReader.Choice.priorityArticulation' does not depend on any axioms +'CoreReader.Choice.AssessmentAccurate' does not depend on any axioms +'CoreReader.Choice.statusDoesNotEntailPriority' does not depend on any axioms +'CoreReader.Choice.statusAssessmentNonEntailment' depends on axioms: [propext] +'CoreReader.Choice.PriorityAssessment' does not depend on any axioms +'CoreReader.Choice.PriorityAssessment.accurate' does not depend on any axioms +'CoreReader.Choice.statusPriorityAudit' does not depend on any axioms +'CoreReader.Choice.ChoicePolicy' does not depend on any axioms +'CoreReader.Choice.GeneralAssessmentFulfilled' does not depend on any axioms +'CoreReader.Choice.AdditionalChoiceNorm' does not depend on any axioms +'CoreReader.Choice.statusPriorityPolicy' does not depend on any axioms +'CoreReader.Choice.outputPriorityPolicy' does not depend on any axioms +'CoreReader.Choice.statusPriorityAuditAccurate' does not depend on any axioms +'CoreReader.Choice.PolicyIndependenceExample' does not depend on any axioms +'CoreReader.Choice.policyIndependenceExample' depends on axioms: [propext] +'CoreReader.Choice.generalGroundsNotChoice' depends on axioms: [propext] +'CoreReader.Engineering.Maintainer' does not depend on any axioms +'CoreReader.Engineering.Tool' does not depend on any axioms +'CoreReader.Engineering.Knowledge' does not depend on any axioms +'CoreReader.Engineering.Change' does not depend on any axioms +'CoreReader.Engineering.Candidate' does not depend on any axioms +'CoreReader.Engineering.Burden' does not depend on any axioms +'CoreReader.Engineering.maintainers' does not depend on any axioms +'CoreReader.Engineering.changes' does not depend on any axioms +'CoreReader.Engineering.burdens' does not depend on any axioms +'CoreReader.Engineering.Activity' does not depend on any axioms +'CoreReader.Engineering.ActivityScope' does not depend on any axioms +'CoreReader.Engineering.Continuing' does not depend on any axioms +'CoreReader.Engineering.BoundedLifecycle' does not depend on any axioms +'CoreReader.Engineering.continuingActivity' depends on axioms: [propext] +'CoreReader.Engineering.temporaryActivity' depends on axioms: [propext] +'CoreReader.Engineering.prototypeActivity' depends on axioms: [propext] +'CoreReader.Engineering.retiringActivity' depends on axioms: [propext] +'CoreReader.Engineering.EditStep' does not depend on any axioms +'CoreReader.Engineering.changePath' does not depend on any axioms +'CoreReader.Engineering.changeWork' does not depend on any axioms +'CoreReader.Engineering.CanChange' does not depend on any axioms +'CoreReader.Engineering.ContinuingCapability' does not depend on any axioms +'CoreReader.Engineering.registeredDirections' does not depend on any axioms +'CoreReader.Engineering.supportedDirections' does not depend on any axioms +'CoreReader.Engineering.MaximumRegisteredCapability' does not depend on any axioms +'CoreReader.Engineering.passiveArtifact' does not depend on any axioms +'CoreReader.Engineering.orientation' does not depend on any axioms +'CoreReader.Engineering.EngineeringAction' does not depend on any axioms +'CoreReader.Engineering.maintainerActions' does not depend on any axioms +'CoreReader.Engineering.artifactActions' does not depend on any axioms +'CoreReader.Engineering.subjectLifecycleCases' depends on axioms: [propext] +'CoreReader.Engineering.subjectLimits' depends on axioms: [propext] +'CoreReader.Engineering.CredibleDirection' does not depend on any axioms +'CoreReader.Engineering.DirectionGround' does not depend on any axioms +'CoreReader.Engineering.articulateGround' does not depend on any axioms +'CoreReader.Engineering.supportGround' does not depend on any axioms +'CoreReader.Engineering.initialGrounds' does not depend on any axioms +'CoreReader.Engineering.forecastGrounds' does not depend on any axioms +'CoreReader.Engineering.credible' does not depend on any axioms +'CoreReader.Engineering.WarrantedAccommodation' does not depend on any axioms +'CoreReader.Engineering.credibilityCases' does not depend on any axioms +'CoreReader.Engineering.abstractionComplexity' does not depend on any axioms +'CoreReader.Engineering.implementedVariants' does not depend on any axioms +'CoreReader.Engineering.CostVector' does not depend on any axioms +'CoreReader.Engineering.CostLimits' does not depend on any axioms +'CoreReader.Engineering.cost' does not depend on any axioms +'CoreReader.Engineering.normalLimits' does not depend on any axioms +'CoreReader.Engineering.Requirements' does not depend on any axioms +'CoreReader.Engineering.normalRequirements' does not depend on any axioms +'CoreReader.Engineering.behavior' does not depend on any axioms +'CoreReader.Engineering.CandidateProfile' does not depend on any axioms +'CoreReader.Engineering.profile' does not depend on any axioms +'CoreReader.Engineering.Meets' does not depend on any axioms +'CoreReader.Engineering.Context' does not depend on any axioms +'CoreReader.Engineering.currentContinuing' depends on axioms: [propext] +'CoreReader.Engineering.ConcreteThreat' does not depend on any axioms +'CoreReader.Engineering.HasThreat' does not depend on any axioms +'CoreReader.Engineering.JustifiedDeparture' does not depend on any axioms +'CoreReader.Engineering.PriorityConditions' does not depend on any axioms +'CoreReader.Engineering.EvolutionPriority' does not depend on any axioms +'CoreReader.Engineering.currentPriorityConditions' depends on axioms: [propext] +'CoreReader.Engineering.currentNoThreat' depends on axioms: [propext] +'CoreReader.Engineering.threatened' depends on axioms: [propext] +'CoreReader.Engineering.priorityWhenApplicable' does not depend on any axioms +'CoreReader.Engineering.currentSimpleViolates' depends on axioms: [propext] +'CoreReader.Engineering.withEvolvableProfile' depends on axioms: [propext] +'CoreReader.Engineering.unmetRequirementsBlockPriority' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Engineering.priorityConditionsCases' depends on axioms: [propext] +'CoreReader.Engineering.priorityChoices' depends on axioms: [propext] +'CoreReader.Engineering.credibilityLimits' depends on axioms: [propext] +'CoreReader.Engineering.costCases' depends on axioms: [propext] +'CoreReader.Engineering.orderedUnique' does not depend on any axioms +'CoreReader.Engineering.orderedRefactor' does not depend on any axioms +'CoreReader.Engineering.insertOrdered' does not depend on any axioms +'CoreReader.Engineering.sortValues' does not depend on any axioms +'CoreReader.Engineering.sortedUnique' does not depend on any axioms +'CoreReader.Engineering.SoftwareState' does not depend on any axioms +'CoreReader.Engineering.originalSoftware' does not depend on any axioms +'CoreReader.Engineering.transform' does not depend on any axioms +'CoreReader.Engineering.evolutionBehavior' does not depend on any axioms +'CoreReader.Engineering.ObligationTreatment' does not depend on any axioms +'CoreReader.Engineering.ChangeClaim' does not depend on any axioms +'CoreReader.Engineering.contractInputs' does not depend on any axioms +'CoreReader.Engineering.PreservesOn' does not depend on any axioms +'CoreReader.Engineering.PreservesFinite' does not depend on any axioms +'CoreReader.Engineering.ObservableContract' does not depend on any axioms +'CoreReader.Engineering.retry' does not depend on any axioms +'CoreReader.Engineering.orderContract' does not depend on any axioms +'CoreReader.Engineering.originalContract' does not depend on any axioms +'CoreReader.Engineering.refactoredContract' does not depend on any axioms +'CoreReader.Engineering.revisedContract' does not depend on any axioms +'CoreReader.Engineering.evolutionContract' does not depend on any axioms +'CoreReader.Engineering.failureInputs' does not depend on any axioms +'CoreReader.Engineering.PreservesContractFinite' does not depend on any axioms +'CoreReader.Engineering.ContractAspect' does not depend on any axioms +'CoreReader.Engineering.PartyDependency' does not depend on any axioms +'CoreReader.Engineering.partyDependencies' does not depend on any axioms +'CoreReader.Engineering.aspectChanged' does not depend on any axioms +'CoreReader.Engineering.affectedParties' does not depend on any axioms +'CoreReader.Engineering.ContractRevision' does not depend on any axioms +'CoreReader.Engineering.normalRevision' does not depend on any axioms +'CoreReader.Engineering.RevisionDuties' does not depend on any axioms +'CoreReader.Engineering.ContractChangeAccount' does not depend on any axioms +'CoreReader.Engineering.EvolutionClaim' does not depend on any axioms +'CoreReader.Engineering.evolutionKindsCases' depends on axioms: [propext] +'CoreReader.Engineering.evolutionDimensionsLimits' depends on axioms: [propext] +'CoreReader.Engineering.oneDimensionDoesNotEntailEveryDimension' does not depend on any axioms +'CoreReader.Engineering.propagation' does not depend on any axioms +'CoreReader.Engineering.batchCount' does not depend on any axioms +'CoreReader.Engineering.staticBatch' does not depend on any axioms +'CoreReader.Engineering.liveBatch' does not depend on any axioms +'CoreReader.Engineering.StructuralEvidence' does not depend on any axioms +'CoreReader.Engineering.structuralEvidence' does not depend on any axioms +'CoreReader.Engineering.StructuralAccount' does not depend on any axioms +'CoreReader.Engineering.InterfaceView' does not depend on any axioms +'CoreReader.Engineering.sameShape' does not depend on any axioms +'CoreReader.Engineering.moduleAssumptions' does not depend on any axioms +'CoreReader.Engineering.modulesNeedingRevision' does not depend on any axioms +'CoreReader.Engineering.Boundary' does not depend on any axioms +'CoreReader.Engineering.EngineeringDesign' does not depend on any axioms +'CoreReader.Engineering.privateDesign' does not depend on any axioms +'CoreReader.Engineering.documentedDesign' does not depend on any axioms +'CoreReader.Engineering.sortedDesign' does not depend on any axioms +'CoreReader.Engineering.coordinatedBoundary' does not depend on any axioms +'CoreReader.Engineering.boundaryDesign' does not depend on any axioms +'CoreReader.Engineering.crossesBoundary' does not depend on any axioms +'CoreReader.Engineering.boundaryObligationChecked' does not depend on any axioms +'CoreReader.Engineering.omittedCallerCheck' does not depend on any axioms +'CoreReader.Engineering.otherCalleeBoundary' does not depend on any axioms +'CoreReader.Engineering.otherCalleeDesign' does not depend on any axioms +'CoreReader.Engineering.actualCrossBoundaryObligation' does not depend on any axioms +'CoreReader.Engineering.structuralCases' depends on axioms: [propext] +'CoreReader.Engineering.DesignCanChange' does not depend on any axioms +'CoreReader.Engineering.designWork' does not depend on any axioms +'CoreReader.Engineering.designModulesNeedingRevision' does not depend on any axioms +'CoreReader.Engineering.introduceBoundary' does not depend on any axioms +'CoreReader.Engineering.wrappedDesign' does not depend on any axioms +'CoreReader.Engineering.relocateVerification' does not depend on any axioms +'CoreReader.Engineering.sameWorkDesign' does not depend on any axioms +'CoreReader.Engineering.structureNotCapability' depends on axioms: [propext] +'CoreReader.Engineering.contractPreservation' does not depend on any axioms +'CoreReader.Engineering.changedObservationNotPreserved' does not depend on any axioms +'CoreReader.Engineering.contractRevisionObligations' does not depend on any axioms +'CoreReader.Engineering.retiredBehavior' does not depend on any axioms +'CoreReader.Engineering.contractCases' does not depend on any axioms +'CoreReader.Engineering.contractDistinctions' does not depend on any axioms +'CoreReader.Engineering.RevisionState' does not depend on any axioms +'CoreReader.Engineering.RevisionRecord' does not depend on any axioms +'CoreReader.Engineering.MaterialGroundsChanged' does not depend on any axioms +'CoreReader.Engineering.oldState' does not depend on any axioms +'CoreReader.Engineering.newState' does not depend on any axioms +'CoreReader.Engineering.HistoricalEvidence' does not depend on any axioms +'CoreReader.Engineering.observedHistory' does not depend on any axioms +'CoreReader.Engineering.RevisionAccountAgainst' does not depend on any axioms +'CoreReader.Engineering.RevisionAccount' does not depend on any axioms +'CoreReader.Engineering.failedHistoryNotRewritten' depends on axioms: [propext] +'CoreReader.Engineering.revisionRecord' does not depend on any axioms +'CoreReader.Engineering.SupportedAlternative' does not depend on any axioms +'CoreReader.Engineering.RetentionJustified' does not depend on any axioms +'CoreReader.Engineering.stableRecord' does not depend on any axioms +'CoreReader.Engineering.revisionCases' depends on axioms: [propext] +'CoreReader.Engineering.observations' does not depend on any axioms +'CoreReader.Engineering.revisionsMade' does not depend on any axioms +'CoreReader.Engineering.agreedBatch' does not depend on any axioms +'CoreReader.Engineering.rewrittenOldRecord' does not depend on any axioms +'CoreReader.Engineering.rewrittenPredictionRecord' does not depend on any axioms +'CoreReader.Engineering.rewrittenObservationRecord' does not depend on any axioms +'CoreReader.Engineering.unrelatedSoftwareRecord' does not depend on any axioms +'CoreReader.Engineering.historicalTamperingRejected' does not depend on any axioms +'CoreReader.Engineering.revisionLimits' depends on axioms: [propext] +'CoreReader.Engineering.groundedChanges' does not depend on any axioms +'CoreReader.Engineering.currentRevisionState' does not depend on any axioms +'CoreReader.Engineering.revisionFor' does not depend on any axioms +'CoreReader.Engineering.revisionContextIdentity' depends on axioms: [propext] +'CoreReader.Engineering.DomainSatisfied' does not depend on any axioms +'CoreReader.Engineering.currentDomainSatisfied' depends on axioms: [propext] +'CoreReader.Engineering.sharedContext' depends on axioms: [propext] +'CoreReader.Engineering.maintainedOutput' does not depend on any axioms +'CoreReader.Engineering.chosenImplementation' does not depend on any axioms +'CoreReader.Engineering.chosenRequirements' depends on axioms: [propext] +'CoreReader.Engineering.chosenReasons' does not depend on any axioms +'CoreReader.Engineering.maintainedOutputCorrect' does not depend on any axioms +'CoreReader.Engineering.implementationReasoned' depends on axioms: [propext] +'CoreReader.Engineering.capabilityOutput' depends on axioms: [propext] +'CoreReader.Engineering.engineeringProcess' depends on axioms: [propext] +'CoreReader.Engineering.engineeringCapability' depends on axioms: [propext] +'CoreReader.Engineering.engineeringCapabilityGrounded' depends on axioms: [propext] +'CoreReader.Engineering.actualCapabilityContrast' depends on axioms: [propext] +'CoreReader.Engineering.presentBudgetRecord' does not depend on any axioms +'CoreReader.Engineering.presentBudgetClaim' does not depend on any axioms +'CoreReader.Engineering.budgetObservationMeaning' depends on axioms: [propext] +'CoreReader.Engineering.budgetEmpiricalFacet' does not depend on any axioms +'CoreReader.Engineering.budgetEmpiricalDischarged' depends on axioms: [propext] +'CoreReader.Engineering.capacityClaim' depends on axioms: [propext] +'CoreReader.Engineering.capacityAssumptions' does not depend on any axioms +'CoreReader.Engineering.budgetInferentialFacet' depends on axioms: [propext] +'CoreReader.Engineering.budgetInferentialDischarged' depends on axioms: [propext] +'CoreReader.Engineering.budgetScopeAccount' does not depend on any axioms +'CoreReader.Engineering.budgetScopeExplained' does not depend on any axioms +'CoreReader.Engineering.budgetObservationLimit' depends on axioms: [propext] +'CoreReader.Engineering.engineeringPolicy' does not depend on any axioms +'CoreReader.Engineering.engineeringGenerative' does not depend on any axioms +'CoreReader.Engineering.OwnFact' does not depend on any axioms +'CoreReader.Engineering.ownFactClaim' depends on axioms: [propext] +'CoreReader.Engineering.actualOwnFact' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Engineering.ownFactPremises' does not depend on any axioms +'CoreReader.Engineering.actualOwnFactGrounded' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Engineering.priorityValueMeaning' depends on axioms: [propext] +'CoreReader.Engineering.priorityGrounds' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Engineering.OwnNorm' does not depend on any axioms +'CoreReader.Engineering.normApplies' depends on axioms: [propext] +'CoreReader.Engineering.ownNormClaim' depends on axioms: [propext] +'CoreReader.Engineering.actualOwnNorm' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Engineering.ownFactTheory' depends on axioms: [propext] +'CoreReader.Engineering.ownNormTheory' depends on axioms: [propext] +'CoreReader.Engineering.ownTheory' depends on axioms: [propext] +'CoreReader.Engineering.allNormativeContentHeld' depends on axioms: [propext] +'CoreReader.Engineering.nonemptyOwnObjects' depends on axioms: [propext] +'CoreReader.Engineering.comparisonContext' depends on axioms: [propext] +'CoreReader.Engineering.engineeringSnapshot' depends on axioms: [propext] +'CoreReader.Engineering.currentAdmissible' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Engineering.currentConsistency' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Engineering.wholeClaimGrounded' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Engineering.incompatibleNormTheory' does not depend on any axioms +'CoreReader.Engineering.incompatibleNormContext' does not depend on any axioms +'CoreReader.Engineering.normativeContentVariation' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Engineering.Inherited' depends on axioms: [propext] +'CoreReader.Engineering.inheritedCurrent' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Engineering.inheritedMutualApplication' depends on axioms: [propext] +'CoreReader.Engineering.inheritedMutualCases' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Engineering.priorityRemainsReflexive' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Engineering.priorityReflexiveCases' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Engineering.jointWitness' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Engineering.inheritedDoesNotEntailPriority' depends on axioms: [propext, + Classical.choice.{u}, + Quot.sound.{u}] +'CoreReader.Engineering.Reflection.Target' does not depend on any axioms +'CoreReader.Engineering.Reflection.Contract' does not depend on any axioms +'CoreReader.Engineering.Reflection.Input' does not depend on any axioms +'CoreReader.Engineering.Reflection.Verdict' does not depend on any axioms +'CoreReader.Engineering.Reflection.Outcome' does not depend on any axioms +'CoreReader.Engineering.Reflection.evaluate' does not depend on any axioms +'CoreReader.Engineering.Reflection.generate' does not depend on any axioms +'CoreReader.Engineering.Reflection.interpret' does not depend on any axioms +'CoreReader.Engineering.Reflection.Model' does not depend on any axioms +'CoreReader.Engineering.Reflection.Model.input' does not depend on any axioms +'CoreReader.Engineering.Reflection.Model.self' does not depend on any axioms +'CoreReader.Engineering.Reflection.Model.rule' does not depend on any axioms +'CoreReader.Engineering.Reflection.Model.rules' does not depend on any axioms +'CoreReader.Engineering.Reflection.Model.performed' does not depend on any axioms +'CoreReader.Engineering.Reflection.Model.follows' does not depend on any axioms +'CoreReader.Engineering.Reflection.recordedReflexivity' depends on axioms: [propext] +'CoreReader.Engineering.ReviewObject' does not depend on any axioms +'CoreReader.Engineering.ReviewCase' does not depend on any axioms +'CoreReader.Engineering.generationApplies' does not depend on any axioms +'CoreReader.Engineering.assessmentApplies' does not depend on any axioms +'CoreReader.Engineering.ruleObject' does not depend on any axioms +'CoreReader.Engineering.ruleProbe' does not depend on any axioms +'CoreReader.Engineering.generationRuleTest' does not depend on any axioms +'CoreReader.Engineering.assessmentRuleTest' does not depend on any axioms +'CoreReader.Engineering.sampleAwareAssessment' does not depend on any axioms +'CoreReader.Engineering.objectTest' depends on axioms: [propext] +'CoreReader.Engineering.reviewObjects' does not depend on any axioms +'CoreReader.Engineering.requestedCases' does not depend on any axioms +'CoreReader.Engineering.reviewReasons' does not depend on any axioms +'CoreReader.Engineering.statedReview' depends on axioms: [propext] +'CoreReader.Engineering.reviewBasis' depends on axioms: [propext] +'CoreReader.Engineering.selfModel' depends on axioms: [propext] +'CoreReader.Engineering.reviewIdentity' depends on axioms: [propext] +'CoreReader.Engineering.currentSelfRecords' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Engineering.currentSelfApplication' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Engineering.actualSelfCriticism' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Engineering.ownRuleIdentity' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Engineering.ownRuleContentVariation' depends on axioms: [propext] +'CoreReader.Engineering.proposedRuleRevision' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Engineering.CoreCommitment' does not depend on any axioms +'CoreReader.Engineering.coreCommitments' does not depend on any axioms +'CoreReader.Engineering.coreAdopted' does not depend on any axioms +'CoreReader.Engineering.AdoptionReason' does not depend on any axioms +'CoreReader.Engineering.reasonFor' does not depend on any axioms +'CoreReader.Engineering.ReasonRelevant' depends on axioms: [propext] +'CoreReader.Engineering.valueScope' does not depend on any axioms +'CoreReader.Engineering.safeguardExperiment' depends on axioms: [propext] +'CoreReader.Engineering.criticismFor' does not depend on any axioms +'CoreReader.Engineering.governancePosition' depends on axioms: [propext] +'CoreReader.Engineering.adoptionReasonRelevant' depends on axioms: [propext] +'CoreReader.Engineering.safeguardEnabled' depends on axioms: [propext] +'CoreReader.Engineering.safeguardDisabled' depends on axioms: [propext] +'CoreReader.Engineering.governanceValueProcedure' depends on axioms: [propext] +'CoreReader.Engineering.governanceGrounded' depends on axioms: [propext] +'CoreReader.Engineering.governanceRationaleLimits' depends on axioms: [propext] +'CoreReader.Engineering.selectionObjective' does not depend on any axioms +'CoreReader.Engineering.selectionPosition' depends on axioms: [propext] +'CoreReader.Engineering.selectionValueProcedure' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Engineering.selectionGrounded' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Evidence.Record' does not depend on any axioms +'CoreReader.Evidence.Compatible' does not depend on any axioms +'CoreReader.Evidence.Supports' does not depend on any axioms +'CoreReader.Evidence.Articulation' does not depend on any axioms +'CoreReader.Evidence.Articulated' does not depend on any axioms +'CoreReader.Evidence.ValuePosition' does not depend on any axioms +'CoreReader.Evidence.ValuePosition.commitment' does not depend on any axioms +'CoreReader.Evidence.ValuePosition.consequence' does not depend on any axioms +'CoreReader.Evidence.ValuePosition.activeReasons' does not depend on any axioms +'CoreReader.Evidence.JointAdoption' does not depend on any axioms +'CoreReader.Evidence.ValueProcedure' does not depend on any axioms +'CoreReader.Evidence.Facet' does not depend on any axioms +'CoreReader.Evidence.Facet.claim' does not depend on any axioms +'CoreReader.Evidence.FacetDischarged' does not depend on any axioms +'CoreReader.Evidence.FacetArticulated' does not depend on any axioms +'CoreReader.Evidence.canonicalArticulation' does not depend on any axioms +'CoreReader.Evidence.canonicalFacetArticulated' does not depend on any axioms +'CoreReader.Evidence.canonicalArticulated' depends on axioms: [propext] +'CoreReader.Evidence.Grounds' does not depend on any axioms +'CoreReader.Evidence.AchievementAccountability' does not depend on any axioms +'CoreReader.Evidence.transitionAchievement' does not depend on any axioms +'CoreReader.Evidence.transitionPerformanceRecord' does not depend on any axioms +'CoreReader.Evidence.transitionReportRecord' does not depend on any axioms +'CoreReader.Evidence.transitionPerformanceCompatible' depends on axioms: [propext] +'CoreReader.Evidence.transitionSupported' depends on axioms: [propext] +'CoreReader.Evidence.transitionFacet' does not depend on any axioms +'CoreReader.Evidence.transitionFacetDischarged' depends on axioms: [propext] +'CoreReader.Evidence.transitionAccountable' depends on axioms: [propext] +'CoreReader.Evidence.transitionReportCompatible' depends on axioms: [propext] +'CoreReader.Evidence.transitionReportDoesNotSupport' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Evidence.ConcreteAchievementExample' does not depend on any axioms +'CoreReader.Evidence.concreteAchievementExample' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Evidence.achievementNeedsSupport' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Evidence.supportWeakening' does not depend on any axioms +'CoreReader.Evidence.evidenceWeakeningCanLoseSupport' depends on axioms: [propext] +'CoreReader.Evidence.scopeRestriction' does not depend on any axioms +'CoreReader.Evidence.Duties' does not depend on any axioms +'CoreReader.Evidence.LabeledDuties' does not depend on any axioms +'CoreReader.Evidence.assessmentUnion' does not depend on any axioms +'CoreReader.Evidence.labelsCannotWaive' does not depend on any axioms +'CoreReader.Evidence.switchRecord' does not depend on any axioms +'CoreReader.Evidence.switchCompatible' depends on axioms: [propext] +'CoreReader.Evidence.switchSupported' depends on axioms: [propext] +'CoreReader.Evidence.optionBenefit' does not depend on any axioms +'CoreReader.Evidence.optionCost' does not depend on any axioms +'CoreReader.Evidence.optionReport' does not depend on any axioms +'CoreReader.Evidence.switchPosition' does not depend on any axioms +'CoreReader.Evidence.switchValueProcedure' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Evidence.oppositePosition' does not depend on any axioms +'CoreReader.Evidence.oppositePositionRejected' depends on axioms: [propext] +'CoreReader.Evidence.contradictoryStartingPosition' does not depend on any axioms +'CoreReader.Evidence.impossibleAdoptionPosition' does not depend on any axioms +'CoreReader.Evidence.inadmissibleValuePositionsRejected' does not depend on any axioms +'CoreReader.Evidence.unsupportedPosition' does not depend on any axioms +'CoreReader.Evidence.switchEmpirical' does not depend on any axioms +'CoreReader.Evidence.switchEmpiricalDischarged' depends on axioms: [propext] +'CoreReader.Evidence.mixedMissingResponsibility' depends on axioms: [propext] +'CoreReader.Evidence.uninformativeArgument' does not depend on any axioms +'CoreReader.Evidence.articulationNotSupport' depends on axioms: [propext] +'CoreReader.Evidence.unrelatedArticulationRejected' depends on axioms: [propext] +'CoreReader.Evidence.temperatureRecord' does not depend on any axioms +'CoreReader.Evidence.temperatureCompatible' depends on axioms: [propext] +'CoreReader.Evidence.BudgetWorld' does not depend on any axioms +'CoreReader.Evidence.announcement' does not depend on any axioms +'CoreReader.Evidence.announcementPosition' does not depend on any axioms +'CoreReader.Evidence.announcementHasJointAdoption' depends on axioms: [propext] +'CoreReader.Evidence.announcementNotBudgetReason' depends on axioms: [propext] +'CoreReader.Evidence.actionRecord' does not depend on any axioms +'CoreReader.Evidence.actionCompatible' depends on axioms: [propext] +'CoreReader.Evidence.measurementRepeatNotSupport' depends on axioms: [propext] +'CoreReader.Evidence.selfAssertionNotReason' depends on axioms: [propext] +'CoreReader.Evidence.valueWithoutSelfProof' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Evidence.BenefitCostWorld' does not depend on any axioms +'CoreReader.Evidence.measuredOutcome' does not depend on any axioms +'CoreReader.Evidence.benefitReason' does not depend on any axioms +'CoreReader.Evidence.costReason' does not depend on any axioms +'CoreReader.Evidence.jointReasonPosition' does not depend on any axioms +'CoreReader.Evidence.jointReasonProcedure' depends on axioms: [propext] +'CoreReader.Evidence.JointReasonsExample' does not depend on any axioms +'CoreReader.Evidence.jointReasonsExample' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Evidence.heterogeneousReasons' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Evidence.zeroRecord' does not depend on any axioms +'CoreReader.Evidence.localGenerator' does not depend on any axioms +'CoreReader.Evidence.allTrue' does not depend on any axioms +'CoreReader.Evidence.zeroCompatible' depends on axioms: [propext] +'CoreReader.Evidence.GeneratingProcess' does not depend on any axioms +'CoreReader.Evidence.GeneratingProcess.outputRevision' does not depend on any axioms +'CoreReader.Evidence.ProducedRevision' does not depend on any axioms +'CoreReader.Evidence.GeneratingProcess.produce' does not depend on any axioms +'CoreReader.Evidence.sampleGeneratingProcess' does not depend on any axioms +'CoreReader.Evidence.OwnedRevisionExample' does not depend on any axioms +'CoreReader.Evidence.ownedRevisionExample' depends on axioms: [propext] +'CoreReader.Evidence.selfOriginDoesNotSupport' depends on axioms: [propext] +'CoreReader.Evidence.localNotUniversal' depends on axioms: [propext] +'CoreReader.Evidence.hiddenDifference' does not depend on any axioms +'CoreReader.Evidence.singleObservation' depends on axioms: [propext] +'CoreReader.Evidence.arithmeticFacet' does not depend on any axioms +'CoreReader.Evidence.usesObservation' depends on axioms: [propext] +'CoreReader.Evidence.noUniversalChain' depends on axioms: [propext] +'CoreReader.Evidence.Trial' does not depend on any axioms +'CoreReader.Evidence.Verified' does not depend on any axioms +'CoreReader.Evidence.Reproduced' does not depend on any axioms +'CoreReader.Evidence.Bounded' does not depend on any axioms +'CoreReader.Evidence.variableOutcomesStableBound' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Evidence.verificationReproductionStability' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Evidence.Program' does not depend on any axioms +'CoreReader.Evidence.Program.eval' does not depend on any axioms +'CoreReader.Evidence.Process' does not depend on any axioms +'CoreReader.Evidence.OutputContract' does not depend on any axioms +'CoreReader.Evidence.ExplanationContract' does not depend on any axioms +'CoreReader.Evidence.outputOnlyProcess' does not depend on any axioms +'CoreReader.Evidence.explainedProcess' does not depend on any axioms +'CoreReader.Evidence.processScope' does not depend on any axioms +'CoreReader.Evidence.processContractFacet' does not depend on any axioms +'CoreReader.Evidence.processScopeModels' does not depend on any axioms +'CoreReader.Evidence.processContractDischarged' does not depend on any axioms +'CoreReader.Evidence.ProcessGrounds' does not depend on any axioms +'CoreReader.Evidence.processGrounds' depends on axioms: [propext] +'CoreReader.Evidence.outputCorrectByEvaluation' does not depend on any axioms +'CoreReader.Evidence.outputOnlyNoExplanation' does not depend on any axioms +'CoreReader.Evidence.FullProcessContract' does not depend on any axioms +'CoreReader.Evidence.OutputContractEvidence' does not depend on any axioms +'CoreReader.Evidence.outputContractEvidence' depends on axioms: [propext] +'CoreReader.Evidence.ScopedApplicationEvidence' does not depend on any axioms +'CoreReader.Evidence.scopedApplicationEvidence' depends on axioms: [propext] +'CoreReader.Evidence.outputNotExplanation' depends on axioms: [propext] +'CoreReader.Evidence.applicationContractsDiffer' depends on axioms: [propext] +'CoreReader.Evidence.ExternalCertificate' does not depend on any axioms +'CoreReader.Evidence.externalOutputCertificate' does not depend on any axioms +'CoreReader.Evidence.externalAssessment' depends on axioms: [propext] +'CoreReader.Evidence.arithmeticArticulation' does not depend on any axioms +'CoreReader.Evidence.nonExecutableAssessment' depends on axioms: [propext] +'CoreReader.Integration.canonicalGrounds' depends on axioms: [propext] +'CoreReader.Integration.canonicalGroundsForSingleton' depends on axioms: [propext] +'CoreReader.Integration.Mode' does not depend on any axioms +'CoreReader.Integration.World' does not depend on any axioms +'CoreReader.Integration.actual' does not depend on any axioms +'CoreReader.Integration.Method' does not depend on any axioms +'CoreReader.Integration.System' does not depend on any axioms +'CoreReader.Integration.policyFor' does not depend on any axioms +'CoreReader.Integration.workFor' depends on axioms: [propext] +'CoreReader.Integration.System.policy' does not depend on any axioms +'CoreReader.Integration.System.rules' depends on axioms: [propext] +'CoreReader.Integration.System.work' depends on axioms: [propext] +'CoreReader.Integration.actualSystem' does not depend on any axioms +'CoreReader.Integration.systemCapability' does not depend on any axioms +'CoreReader.Integration.systemBudget' does not depend on any axioms +'CoreReader.Integration.systemObservation' does not depend on any axioms +'CoreReader.Integration.systemHeld' does not depend on any axioms +'CoreReader.Integration.Question' does not depend on any axioms +'CoreReader.Integration.systemContext' does not depend on any axioms +'CoreReader.Integration.capability' does not depend on any axioms +'CoreReader.Integration.observation' does not depend on any axioms +'CoreReader.Integration.held' does not depend on any axioms +'CoreReader.Integration.context' does not depend on any axioms +'CoreReader.Integration.observationIdentifies' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Integration.capabilityActual' does not depend on any axioms +'CoreReader.Integration.observedCapability' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Integration.capabilityFacet' does not depend on any axioms +'CoreReader.Integration.capabilityFacetChecked' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Integration.capabilityGrounds' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Integration.actualAdmissible' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Integration.jointConsistent' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Integration.Charter' depends on axioms: [propext] +'CoreReader.Integration.charterChecked' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Integration.revisedHeld' does not depend on any axioms +'CoreReader.Integration.initialSnapshot' does not depend on any axioms +'CoreReader.Integration.revisedSnapshot' does not depend on any axioms +'CoreReader.Integration.revisionKeepsConsistency' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Integration.OwnCapabilityDuty' depends on axioms: [propext] +'CoreReader.Integration.ownCapabilityGrounded' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Integration.costAllowanceRecord' does not depend on any axioms +'CoreReader.Integration.unsupportedCapabilityFacet' does not depend on any axioms +'CoreReader.Integration.costCompatibleWithFailure' depends on axioms: [propext] +'CoreReader.Integration.costDoesNotSupportOutput' depends on axioms: [propext] +'CoreReader.Integration.unsupportedGrounds' depends on axioms: [propext] +'CoreReader.Integration.Commitment' does not depend on any axioms +'CoreReader.Integration.groundsPermission' does not depend on any axioms +'CoreReader.Integration.GroundsProvision' does not depend on any axioms +'CoreReader.Integration.groundsProvisionMeaning' depends on axioms: [propext] +'CoreReader.Integration.consistencyPermission' does not depend on any axioms +'CoreReader.Integration.conflictingHeld' does not depend on any axioms +'CoreReader.Integration.conflictConsequences' does not depend on any axioms +'CoreReader.Integration.conflictingHeldInconsistent' does not depend on any axioms +'CoreReader.Integration.choicePermission' does not depend on any axioms +'CoreReader.Integration.proposedOperation' does not depend on any axioms +'CoreReader.Integration.selfSamples' does not depend on any axioms +'CoreReader.Integration.conflictDecision' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Integration.groundsDecision' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Integration.choiceDecision' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Integration.decisionsApply' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Integration.decisionsWaive' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Integration.commitmentPositionFor' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Integration.commitmentPosition' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Integration.positionReasons' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Integration.positionConsequence' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Integration.positionProcedure' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Integration.criticismWithinScope' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Integration.oppositeConsequenceFails' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Integration.oppositeProcedureRejected' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Integration.commitmentClaim' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Integration.commitmentFacet' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Integration.reasonsBelongToCommitments' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Integration.groundsCommitmentIsProvision' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Integration.groundsSelfAssessment' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Integration.PhilosophyMethod' does not depend on any axioms +'CoreReader.Integration.currentPhilosophy' does not depend on any axioms +'CoreReader.Integration.PhilosophyMethod.review' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Integration.PhilosophyMethod.implementation' depends on axioms: [propext, + Classical.choice.{u}, + Quot.sound.{u}] +'CoreReader.Integration.proposalRequirements' does not depend on any axioms +'CoreReader.Integration.currentReviewCorrect' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Integration.existingPhilosophyNotPrivileged' depends on axioms: [propext, + Classical.choice.{u}, + Quot.sound.{u}] +'CoreReader.Integration.applicationClaim' does not depend on any axioms +'CoreReader.Integration.ApplicationDuties' depends on axioms: [propext] +'CoreReader.Integration.applicationRetainsDuties' depends on axioms: [propext] +'CoreReader.Integration.outputContract' does not depend on any axioms +'CoreReader.Integration.successorRequirements' does not depend on any axioms +'CoreReader.Integration.changedObjectiveFacet' does not depend on any axioms +'CoreReader.Integration.applicationVariation' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Integration.charterNotGrounds' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Integration.jointWitness' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] +'CoreReader.Logic.Claim' does not depend on any axioms +'CoreReader.Logic.Theory' does not depend on any axioms +'CoreReader.Logic.Models' does not depend on any axioms +'CoreReader.Logic.Entails' does not depend on any axioms +'CoreReader.Logic.Satisfiable' does not depend on any axioms +'CoreReader.Logic.Context' does not depend on any axioms +'CoreReader.Logic.Admissible' does not depend on any axioms +'CoreReader.Logic.Consequence' does not depend on any axioms +'CoreReader.Logic.Consistent' does not depend on any axioms +'CoreReader.Logic.consequenceConsistency' does not depend on any axioms +'CoreReader.Logic.emptyTheory' does not depend on any axioms +'CoreReader.Logic.singleton' does not depend on any axioms +'CoreReader.Logic.union' does not depend on any axioms +'CoreReader.Logic.modelsSingleton' does not depend on any axioms +'CoreReader.Logic.modelsUnion' does not depend on any axioms +'CoreReader.Logic.premiseP' does not depend on any axioms +'CoreReader.Logic.premiseRule' does not depend on any axioms +'CoreReader.Logic.premiseNotQ' does not depend on any axioms +'CoreReader.Logic.jointTheory' does not depend on any axioms +'CoreReader.Logic.jointConflict' does not depend on any axioms +'CoreReader.Logic.revisionSlice' does not depend on any axioms +'CoreReader.Logic.revisionCanReverse' does not depend on any axioms +'CoreReader.Logic.onQuestion' does not depend on any axioms +'CoreReader.Logic.assumptionContext' does not depend on any axioms +'CoreReader.Logic.meaningContext' does not depend on any axioms +'CoreReader.Logic.scopeContext' does not depend on any axioms +'CoreReader.Logic.contextDifferences' does not depend on any axioms +'CoreReader.Logic.Snapshot' does not depend on any axioms +'CoreReader.Logic.SameContent' does not depend on any axioms +'CoreReader.Logic.TruthfulReport' does not depend on any axioms +'CoreReader.Logic.semanticChangeMustBeReported' does not depend on any axioms +'CoreReader.Logic.representationOrderIrrelevant' does not depend on any axioms +'CoreReader.Logic.contextSnapshot' does not depend on any axioms +'CoreReader.Logic.hiddenContextChangeRejected' does not depend on any axioms +'CoreReader.Logic.tensionWithoutContradiction' does not depend on any axioms +'CoreReader.Logic.conflictRequiresChange' does not depend on any axioms +'CoreReader.Logic.consistentFalse' does not depend on any axioms +'CoreReader.Logic.consistentIncomplete' does not depend on any axioms +'CoreReader.Logic.compatibilityNotEntailment' does not depend on any axioms +'CoreReader.Agency.Phase' does not depend on any axioms +'CoreReader.Agency.PrincipleKey' does not depend on any axioms +'CoreReader.Agency.Subject' does not depend on any axioms +'CoreReader.Agency.Subject.owner' does not depend on any axioms +'CoreReader.Agency.Activity' does not depend on any axioms +'CoreReader.Agency.QuestionKind' does not depend on any axioms +'CoreReader.Agency.SampleProgram' does not depend on any axioms +'CoreReader.Agency.SampleProgram.run' does not depend on any axioms +'CoreReader.Agency.MethodDraft' does not depend on any axioms +'CoreReader.Agency.MethodDraft.accepts' does not depend on any axioms +'CoreReader.Agency.Inquiry' does not depend on any axioms +'CoreReader.Agency.ReasonContent' does not depend on any axioms +'CoreReader.Agency.ReasonContent.identifier' does not depend on any axioms +'CoreReader.Agency.ReasonObject' does not depend on any axioms +'CoreReader.Agency.AssessmentResult' does not depend on any axioms +'CoreReader.Agency.WorkOutcome' does not depend on any axioms +'CoreReader.Agency.Principle' does not depend on any axioms +'CoreReader.Agency.WorkRecord' does not depend on any axioms +'CoreReader.Agency.RegistryCoherent' does not depend on any axioms +'CoreReader.Agency.TargetResolved' does not depend on any axioms +'CoreReader.Agency.TargetContentResolved' does not depend on any axioms +'CoreReader.Agency.Performed' does not depend on any axioms +'CoreReader.Agency.ReflexiveScope' does not depend on any axioms +'CoreReader.Agency.ValidApplication' does not depend on any axioms +'CoreReader.Agency.Reflexive' does not depend on any axioms +'CoreReader.Agency.Reflexive.toScope' does not depend on any axioms +'CoreReader.Agency.noSelfExemption' does not depend on any axioms +'CoreReader.Agency.localMethod' does not depend on any axioms +'CoreReader.Agency.inquiryFor' depends on axioms: [propext] +'CoreReader.Agency.sourceReasonContents' does not depend on any axioms +'CoreReader.Agency.reasonsFor' depends on axioms: [propext] +'CoreReader.Agency.assessInquiry' depends on axioms: [propext] +'CoreReader.Agency.finiteMethodResult' depends on axioms: [propext] +'CoreReader.Agency.finiteMethodMeaning' depends on axioms: [propext] +'CoreReader.Agency.ownSubjects' does not depend on any axioms +'CoreReader.Agency.generationEligible' depends on axioms: [propext] +'CoreReader.Agency.generatingRule' depends on axioms: [propext] +'CoreReader.Agency.assessingRule' depends on axioms: [propext] +'CoreReader.Agency.ownRules' depends on axioms: [propext] +'CoreReader.Agency.statedOutcome' depends on axioms: [propext] +'CoreReader.Agency.recordFor' depends on axioms: [propext] +'CoreReader.Agency.reasonsFor_nonempty' depends on axioms: [propext] +'CoreReader.Agency.reasonsFor_target' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Agency.inquiryFor_target' depends on axioms: [propext] +'CoreReader.Agency.ownContentEvaluates' depends on axioms: [propext] +'CoreReader.Agency.ownRegistryCoherent' depends on axioms: [propext] +'CoreReader.Agency.ownTargetResolved' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Agency.ownTargetContent' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Agency.ownRecordValid' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Agency.completeOwnWork' depends on axioms: [propext] +'CoreReader.Agency.assessingRecord_member' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Agency.generatingRecord_member' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Agency.completeOwnWork_reflexive' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Agency.ownAssessmentPerformed' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Agency.applicationRule' depends on axioms: [propext] +'CoreReader.Agency.applicationWork' depends on axioms: [propext] +'CoreReader.Agency.applicationWork_reflexive' depends on axioms: [propext, Quot.sound.{u}] +'CoreReader.Agency.applicabilityRetained' depends on axioms: [propext, Classical.choice.{u}, Quot.sound.{u}] + +exit_code=0 diff --git a/SoftwareEngineering/lean/philosophy/reviews/r3-audit-input.txt b/SoftwareEngineering/lean/philosophy/reviews/r3-audit-input.txt new file mode 100644 index 0000000..d159ea1 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/r3-audit-input.txt @@ -0,0 +1,1666 @@ +import CoreReader +set_option pp.universes true +set_option pp.explicit true +set_option pp.fullNames true +#check @CoreReader.Adopted.AssessmentTask +#check @CoreReader.Adopted.taskOfFacet +#check @CoreReader.Adopted.NatureAppropriate +#check @CoreReader.Adopted.taskOfFacetAppropriate +#check @CoreReader.Adopted.Grounds012 +#check @CoreReader.Adopted.grounds012Singleton +#check @CoreReader.Adopted.generationSpecification +#check @CoreReader.Adopted.consistencySpecification +#check @CoreReader.Adopted.ReflexiveRule +#check @CoreReader.Adopted.reflexivitySpecification +#check @CoreReader.Adopted.legacyRule +#check @CoreReader.Adopted.legacyPerformed +#check @CoreReader.Adopted.legacyReflexivity +#check @CoreReader.Adopted.empiricalSpecification +#check @CoreReader.Adopted.inferentialSpecification +#check @CoreReader.Adopted.valueSpecification +#check @CoreReader.Adopted.AssessmentMethod +#check @CoreReader.Adopted.ScopeAccount +#check @CoreReader.Adopted.scopeSpecification +#check @CoreReader.Adopted.capabilitySpecification +#check @CoreReader.Adopted.choiceSpecification +#check @CoreReader.Adopted.collaborativeRevision +#check @CoreReader.Adopted.collaborativeProgress +#check @CoreReader.Adopted.consistencyConsequences +#check @CoreReader.Adopted.broadBoolContext +#check @CoreReader.Adopted.sliceConsistency +#check @CoreReader.Adopted.explicitlyConsistentLimits +#check @CoreReader.Adopted.localFacet012 +#check @CoreReader.Adopted.globalFacet012 +#check @CoreReader.Adopted.strongFacet012 +#check @CoreReader.Adopted.localFacetChecked012 +#check @CoreReader.Adopted.scopeStrength012 +#check @CoreReader.Adopted.uncertainFacet012 +#check @CoreReader.Adopted.uncertainSupported012 +#check @CoreReader.Adopted.InferenceExamined +#check @CoreReader.Adopted.inferenceChecked012 +#check @CoreReader.Adopted.closedPosition012 +#check @CoreReader.Adopted.closedCriticism012 +#check @CoreReader.Adopted.valueFulfilled012 +#check @CoreReader.Adopted.ClaimNoStronger +#check @CoreReader.Adopted.qualitativeProportionality012 +#check @CoreReader.Adopted.scopeRole012 +#check @CoreReader.Adopted.scopeRoleContent012 +#check @CoreReader.Adopted.localScopeAccount012 +#check @CoreReader.Adopted.scopeFulfilled012 +#check @CoreReader.Adopted.capabilityFulfilled012 +#check @CoreReader.Adopted.MechanismApplication012 +#check @CoreReader.Adopted.mechanism012 +#check @CoreReader.Adopted.UnderstandingApplication012 +#check @CoreReader.Adopted.explainedWithoutVariation012 +#check @CoreReader.Adopted.mechanismResponder012 +#check @CoreReader.Adopted.understandingScope012 +#check @CoreReader.Adopted.understandingTask012 +#check @CoreReader.Adopted.understandingFacet012 +#check @CoreReader.Adopted.mechanismResponderUnderstands012 +#check @CoreReader.Adopted.explainedWithoutVariationFails012 +#check @CoreReader.Adopted.understandingApplicationCases012 +#check @CoreReader.Adopted.OwnCapability012 +#check @CoreReader.Adopted.ownCapability012 +#check @CoreReader.Adopted.CompleteCharter012 +#check @CoreReader.Adopted.completeCharter012 +#check @CoreReader.Adopted.charterWithoutGrounds012 +#check @CoreReader.Adopted.groundsPermission012 +#check @CoreReader.Adopted.GroundsProvision012 +#check @CoreReader.Adopted.groundsProvision012Meaning +#check @CoreReader.Adopted.groundsExperimentTask012 +#check @CoreReader.Adopted.groundsExperiment012 +#check @CoreReader.Adopted.groundsPosition012 +#check @CoreReader.Adopted.groundsPosition012Checked +#check @CoreReader.Adopted.groundsRationaleExperiment012 +#check @CoreReader.Adopted.groundsOnGrounds012 +#check @CoreReader.Adopted.reflexiveTargets012 +#check @CoreReader.Adopted.achievementSupported012 +#check @CoreReader.Adopted.semanticOrder012 +#check @CoreReader.Adopted.clearFalseArgument012 +#check @CoreReader.Adopted.clearFalseReason012 +#check @CoreReader.Adopted.valueNeutralRecord012 +#check @CoreReader.Adopted.valueNotFact012 +#check @CoreReader.Adopted.wrongExplanation012 +#check @CoreReader.Adopted.internalReasonDistinguishes012 +#check @CoreReader.Adopted.inventoryCases012 +#check @CoreReader.Adopted.selfExemptRule012 +#check @CoreReader.Adopted.selfExemptPerformed012 +#check @CoreReader.Adopted.openSelfExempt012 +#check @CoreReader.Adopted.ownPhilosophyStatus012 +#check @CoreReader.Adopted.jointContext012 +#check @CoreReader.Adopted.jointImplicationConflict012 +#check @CoreReader.Adopted.tensionContext012 +#check @CoreReader.Adopted.tensionConsistent012 +#check @CoreReader.Adopted.qualitativeUnmeasured012 +#check @CoreReader.Adopted.allStatusOnly012 +#check @CoreReader.Adopted.drawWeight012 +#check @CoreReader.Adopted.randomTrial012 +#check @CoreReader.Adopted.randomOutcomes012 +#check @CoreReader.Adopted.originalGlobalTask012 +#check @CoreReader.Adopted.originalLocalTask012 +#check @CoreReader.Adopted.circularGlobalFacet012 +#check @CoreReader.Adopted.circularGlobalConditional012 +#check @CoreReader.Adopted.circularSubstitutionRejected012 +#check @CoreReader.Adopted.observedPremises012 +#check @CoreReader.Adopted.observedInferenceFacet012 +#check @CoreReader.Adopted.observedInferenceChecked012 +#check @CoreReader.Adopted.sameEmpiricalTaskTwoMethods012 +#check @CoreReader.Adopted.originalUncertaintyTask012 +#check @CoreReader.Adopted.uncertaintyBypassFacet012 +#check @CoreReader.Adopted.uncertaintyBypassChecked012 +#check @CoreReader.Adopted.uncertaintySubstitutionRejected012 +#check @CoreReader.Adopted.selectedFactFacet012 +#check @CoreReader.Adopted.valueFactSubstitutionRejected012 +#check @CoreReader.Adopted.inferentialContextSubstitutionRejected012 +#check @CoreReader.Adopted.generationCases +#check @CoreReader.Adopted.generationLimits012 +#check @CoreReader.Adopted.consistencyCases +#check @CoreReader.Adopted.consistencyLimits012 +#check @CoreReader.Adopted.reflexivityCases012 +#check @CoreReader.Adopted.reflexivityLimits012 +#check @CoreReader.Adopted.groundsCases012 +#check @CoreReader.Adopted.empiricalCases012 +#check @CoreReader.Adopted.inferentialCases012 +#check @CoreReader.Adopted.valueCases012 +#check @CoreReader.Adopted.groundsLimits012 +#check @CoreReader.Adopted.scopeCases012 +#check @CoreReader.Adopted.scopeLimits012 +#check @CoreReader.Adopted.capabilityCases012 +#check @CoreReader.Adopted.capabilityLimits012 +#check @CoreReader.Adopted.choiceCases012 +#check @CoreReader.Adopted.choiceLimits012 +#check @CoreReader.Agency.FormKind +#check @CoreReader.Agency.Form +#check @CoreReader.Agency.Aim +#check @CoreReader.Agency.Policy +#check @CoreReader.Agency.Generative +#check @CoreReader.Agency.openPolicy +#check @CoreReader.Agency.neutralPolicy +#check @CoreReader.Agency.permissionNotValuation +#check @CoreReader.Agency.revisabilityCovers +#check @CoreReader.Agency.Operation +#check @CoreReader.Agency.Operation.run +#check @CoreReader.Agency.InventoryKind +#check @CoreReader.Agency.Item +#check @CoreReader.Agency.Available +#check @CoreReader.Agency.inventoryNotCapability +#check @CoreReader.Agency.State +#check @CoreReader.Agency.Expanded +#check @CoreReader.Agency.baseState +#check @CoreReader.Agency.inflatedState +#check @CoreReader.Agency.stableTrace +#check @CoreReader.Agency.revisionWithoutProgress +#check @CoreReader.Agency.ExternalResources +#check @CoreReader.Agency.assistedExecution +#check @CoreReader.Agency.availableResources +#check @CoreReader.Agency.StableReason +#check @CoreReader.Agency.GeneratingSystem +#check @CoreReader.Agency.generatingSystem +#check @CoreReader.Agency.GeneratingSystem.stableAction +#check @CoreReader.Agency.GeneratingSystem.requirementsMet +#check @CoreReader.Agency.GeneratingSystem.withinBudget +#check @CoreReader.Agency.Announcement +#check @CoreReader.Agency.GeneratingSystem.report +#check @CoreReader.Agency.Announcement.claim +#check @CoreReader.Agency.announcementClaimImpliesExpansion +#check @CoreReader.Agency.inflatedAnnouncement +#check @CoreReader.Agency.inflatedAnnouncementRefuted +#check @CoreReader.Agency.TransitionCase +#check @CoreReader.Agency.extendedState +#check @CoreReader.Agency.transitionBefore +#check @CoreReader.Agency.transitionAfter +#check @CoreReader.Agency.transitionInput +#check @CoreReader.Agency.transitionAnnouncement +#check @CoreReader.Agency.generationLimits +#check @CoreReader.Agency.generationNotReflexivity +#check @CoreReader.Agency.ownArithmeticPrinciple +#check @CoreReader.Agency.selfTest +#check @CoreReader.Agency.selfTestDoesNotProve +#check @CoreReader.Choice.StatusKind +#check @CoreReader.Choice.MethodReason +#check @CoreReader.Choice.Reason +#check @CoreReader.Choice.Implementation +#check @CoreReader.Choice.Requirements +#check @CoreReader.Choice.MethodContent +#check @CoreReader.Choice.Relevant +#check @CoreReader.Choice.Feasible +#check @CoreReader.Choice.JustifiedChoice +#check @CoreReader.Choice.statusOnlyFails +#check @CoreReader.Choice.identityImpl +#check @CoreReader.Choice.successorImpl +#check @CoreReader.Choice.changedOutsideZero +#check @CoreReader.Choice.identityRequirements +#check @CoreReader.Choice.objectiveReason +#check @CoreReader.Choice.identityOutputReason +#check @CoreReader.Choice.identityFeasible +#check @CoreReader.Choice.identityJustified +#check @CoreReader.Choice.conventionWithReason +#check @CoreReader.Choice.Candidate +#check @CoreReader.Choice.implementation +#check @CoreReader.Choice.singleFeasible +#check @CoreReader.Choice.localNotGlobal +#check @CoreReader.Choice.cheapSuccessor +#check @CoreReader.Choice.eligibleInternalReasonNotSufficient +#check @CoreReader.Choice.internalReasons +#check @CoreReader.Choice.openNotEquivalent +#check @CoreReader.Choice.priorityClaim +#check @CoreReader.Choice.statusFacts +#check @CoreReader.Choice.statusFactsModel +#check @CoreReader.Choice.priorityArticulation +#check @CoreReader.Choice.AssessmentAccurate +#check @CoreReader.Choice.statusDoesNotEntailPriority +#check @CoreReader.Choice.statusAssessmentNonEntailment +#check @CoreReader.Choice.PriorityAssessment +#check @CoreReader.Choice.PriorityAssessment.accurate +#check @CoreReader.Choice.statusPriorityAudit +#check @CoreReader.Choice.ChoicePolicy +#check @CoreReader.Choice.GeneralAssessmentFulfilled +#check @CoreReader.Choice.AdditionalChoiceNorm +#check @CoreReader.Choice.statusPriorityPolicy +#check @CoreReader.Choice.outputPriorityPolicy +#check @CoreReader.Choice.statusPriorityAuditAccurate +#check @CoreReader.Choice.PolicyIndependenceExample +#check @CoreReader.Choice.policyIndependenceExample +#check @CoreReader.Choice.generalGroundsNotChoice +#check @CoreReader.Engineering.Maintainer +#check @CoreReader.Engineering.Tool +#check @CoreReader.Engineering.Knowledge +#check @CoreReader.Engineering.Change +#check @CoreReader.Engineering.Candidate +#check @CoreReader.Engineering.Burden +#check @CoreReader.Engineering.maintainers +#check @CoreReader.Engineering.changes +#check @CoreReader.Engineering.burdens +#check @CoreReader.Engineering.Activity +#check @CoreReader.Engineering.ActivityScope +#check @CoreReader.Engineering.Continuing +#check @CoreReader.Engineering.BoundedLifecycle +#check @CoreReader.Engineering.continuingActivity +#check @CoreReader.Engineering.temporaryActivity +#check @CoreReader.Engineering.prototypeActivity +#check @CoreReader.Engineering.retiringActivity +#check @CoreReader.Engineering.EditStep +#check @CoreReader.Engineering.changePath +#check @CoreReader.Engineering.changeWork +#check @CoreReader.Engineering.CanChange +#check @CoreReader.Engineering.ContinuingCapability +#check @CoreReader.Engineering.registeredDirections +#check @CoreReader.Engineering.supportedDirections +#check @CoreReader.Engineering.MaximumRegisteredCapability +#check @CoreReader.Engineering.passiveArtifact +#check @CoreReader.Engineering.orientation +#check @CoreReader.Engineering.EngineeringAction +#check @CoreReader.Engineering.maintainerActions +#check @CoreReader.Engineering.artifactActions +#check @CoreReader.Engineering.subjectLifecycleCases +#check @CoreReader.Engineering.subjectLimits +#check @CoreReader.Engineering.CredibleDirection +#check @CoreReader.Engineering.DirectionGround +#check @CoreReader.Engineering.articulateGround +#check @CoreReader.Engineering.supportGround +#check @CoreReader.Engineering.initialGrounds +#check @CoreReader.Engineering.forecastGrounds +#check @CoreReader.Engineering.credible +#check @CoreReader.Engineering.WarrantedAccommodation +#check @CoreReader.Engineering.credibilityCases +#check @CoreReader.Engineering.abstractionComplexity +#check @CoreReader.Engineering.implementedVariants +#check @CoreReader.Engineering.CostVector +#check @CoreReader.Engineering.CostLimits +#check @CoreReader.Engineering.cost +#check @CoreReader.Engineering.normalLimits +#check @CoreReader.Engineering.Requirements +#check @CoreReader.Engineering.normalRequirements +#check @CoreReader.Engineering.behavior +#check @CoreReader.Engineering.CandidateProfile +#check @CoreReader.Engineering.profile +#check @CoreReader.Engineering.Meets +#check @CoreReader.Engineering.Context +#check @CoreReader.Engineering.currentContinuing +#check @CoreReader.Engineering.ConcreteThreat +#check @CoreReader.Engineering.HasThreat +#check @CoreReader.Engineering.JustifiedDeparture +#check @CoreReader.Engineering.PriorityConditions +#check @CoreReader.Engineering.EvolutionPriority +#check @CoreReader.Engineering.currentPriorityConditions +#check @CoreReader.Engineering.currentNoThreat +#check @CoreReader.Engineering.threatened +#check @CoreReader.Engineering.priorityWhenApplicable +#check @CoreReader.Engineering.currentSimpleViolates +#check @CoreReader.Engineering.withEvolvableProfile +#check @CoreReader.Engineering.unmetRequirementsBlockPriority +#check @CoreReader.Engineering.priorityConditionsCases +#check @CoreReader.Engineering.priorityChoices +#check @CoreReader.Engineering.credibilityLimits +#check @CoreReader.Engineering.costCases +#check @CoreReader.Engineering.orderedUnique +#check @CoreReader.Engineering.orderedRefactor +#check @CoreReader.Engineering.insertOrdered +#check @CoreReader.Engineering.sortValues +#check @CoreReader.Engineering.sortedUnique +#check @CoreReader.Engineering.SoftwareState +#check @CoreReader.Engineering.originalSoftware +#check @CoreReader.Engineering.transform +#check @CoreReader.Engineering.evolutionBehavior +#check @CoreReader.Engineering.ObligationTreatment +#check @CoreReader.Engineering.ChangeClaim +#check @CoreReader.Engineering.contractInputs +#check @CoreReader.Engineering.PreservesOn +#check @CoreReader.Engineering.PreservesFinite +#check @CoreReader.Engineering.ObservableContract +#check @CoreReader.Engineering.retry +#check @CoreReader.Engineering.orderContract +#check @CoreReader.Engineering.originalContract +#check @CoreReader.Engineering.refactoredContract +#check @CoreReader.Engineering.revisedContract +#check @CoreReader.Engineering.evolutionContract +#check @CoreReader.Engineering.failureInputs +#check @CoreReader.Engineering.PreservesContractFinite +#check @CoreReader.Engineering.ContractAspect +#check @CoreReader.Engineering.PartyDependency +#check @CoreReader.Engineering.partyDependencies +#check @CoreReader.Engineering.aspectChanged +#check @CoreReader.Engineering.affectedParties +#check @CoreReader.Engineering.ContractRevision +#check @CoreReader.Engineering.normalRevision +#check @CoreReader.Engineering.RevisionDuties +#check @CoreReader.Engineering.ContractChangeAccount +#check @CoreReader.Engineering.EvolutionClaim +#check @CoreReader.Engineering.evolutionKindsCases +#check @CoreReader.Engineering.evolutionDimensionsLimits +#check @CoreReader.Engineering.oneDimensionDoesNotEntailEveryDimension +#check @CoreReader.Engineering.propagation +#check @CoreReader.Engineering.batchCount +#check @CoreReader.Engineering.staticBatch +#check @CoreReader.Engineering.liveBatch +#check @CoreReader.Engineering.StructuralEvidence +#check @CoreReader.Engineering.structuralEvidence +#check @CoreReader.Engineering.StructuralAccount +#check @CoreReader.Engineering.InterfaceView +#check @CoreReader.Engineering.sameShape +#check @CoreReader.Engineering.moduleAssumptions +#check @CoreReader.Engineering.modulesNeedingRevision +#check @CoreReader.Engineering.Boundary +#check @CoreReader.Engineering.EngineeringDesign +#check @CoreReader.Engineering.privateDesign +#check @CoreReader.Engineering.documentedDesign +#check @CoreReader.Engineering.sortedDesign +#check @CoreReader.Engineering.coordinatedBoundary +#check @CoreReader.Engineering.boundaryDesign +#check @CoreReader.Engineering.crossesBoundary +#check @CoreReader.Engineering.boundaryObligationChecked +#check @CoreReader.Engineering.omittedCallerCheck +#check @CoreReader.Engineering.otherCalleeBoundary +#check @CoreReader.Engineering.otherCalleeDesign +#check @CoreReader.Engineering.actualCrossBoundaryObligation +#check @CoreReader.Engineering.structuralCases +#check @CoreReader.Engineering.DesignCanChange +#check @CoreReader.Engineering.designWork +#check @CoreReader.Engineering.designModulesNeedingRevision +#check @CoreReader.Engineering.introduceBoundary +#check @CoreReader.Engineering.wrappedDesign +#check @CoreReader.Engineering.relocateVerification +#check @CoreReader.Engineering.sameWorkDesign +#check @CoreReader.Engineering.structureNotCapability +#check @CoreReader.Engineering.contractPreservation +#check @CoreReader.Engineering.changedObservationNotPreserved +#check @CoreReader.Engineering.contractRevisionObligations +#check @CoreReader.Engineering.retiredBehavior +#check @CoreReader.Engineering.contractCases +#check @CoreReader.Engineering.contractDistinctions +#check @CoreReader.Engineering.RevisionState +#check @CoreReader.Engineering.RevisionRecord +#check @CoreReader.Engineering.MaterialGroundsChanged +#check @CoreReader.Engineering.oldState +#check @CoreReader.Engineering.newState +#check @CoreReader.Engineering.HistoricalEvidence +#check @CoreReader.Engineering.observedHistory +#check @CoreReader.Engineering.RevisionAccountAgainst +#check @CoreReader.Engineering.RevisionAccount +#check @CoreReader.Engineering.failedHistoryNotRewritten +#check @CoreReader.Engineering.revisionRecord +#check @CoreReader.Engineering.SupportedAlternative +#check @CoreReader.Engineering.RetentionJustified +#check @CoreReader.Engineering.stableRecord +#check @CoreReader.Engineering.revisionCases +#check @CoreReader.Engineering.observations +#check @CoreReader.Engineering.revisionsMade +#check @CoreReader.Engineering.agreedBatch +#check @CoreReader.Engineering.rewrittenOldRecord +#check @CoreReader.Engineering.rewrittenPredictionRecord +#check @CoreReader.Engineering.rewrittenObservationRecord +#check @CoreReader.Engineering.unrelatedSoftwareRecord +#check @CoreReader.Engineering.historicalTamperingRejected +#check @CoreReader.Engineering.revisionLimits +#check @CoreReader.Engineering.groundedChanges +#check @CoreReader.Engineering.currentRevisionState +#check @CoreReader.Engineering.revisionFor +#check @CoreReader.Engineering.revisionContextIdentity +#check @CoreReader.Engineering.DomainSatisfied +#check @CoreReader.Engineering.currentDomainSatisfied +#check @CoreReader.Engineering.sharedContext +#check @CoreReader.Engineering.maintainedOutput +#check @CoreReader.Engineering.chosenImplementation +#check @CoreReader.Engineering.chosenRequirements +#check @CoreReader.Engineering.chosenReasons +#check @CoreReader.Engineering.maintainedOutputCorrect +#check @CoreReader.Engineering.implementationReasoned +#check @CoreReader.Engineering.capabilityOutput +#check @CoreReader.Engineering.engineeringProcess +#check @CoreReader.Engineering.engineeringCapability +#check @CoreReader.Engineering.engineeringCapabilityGrounded +#check @CoreReader.Engineering.actualCapabilityContrast +#check @CoreReader.Engineering.presentBudgetRecord +#check @CoreReader.Engineering.presentBudgetClaim +#check @CoreReader.Engineering.budgetObservationMeaning +#check @CoreReader.Engineering.budgetEmpiricalFacet +#check @CoreReader.Engineering.budgetEmpiricalDischarged +#check @CoreReader.Engineering.capacityClaim +#check @CoreReader.Engineering.capacityAssumptions +#check @CoreReader.Engineering.budgetInferentialFacet +#check @CoreReader.Engineering.budgetInferentialDischarged +#check @CoreReader.Engineering.budgetScopeAccount +#check @CoreReader.Engineering.budgetScopeExplained +#check @CoreReader.Engineering.budgetObservationLimit +#check @CoreReader.Engineering.engineeringPolicy +#check @CoreReader.Engineering.engineeringGenerative +#check @CoreReader.Engineering.OwnFact +#check @CoreReader.Engineering.ownFactClaim +#check @CoreReader.Engineering.actualOwnFact +#check @CoreReader.Engineering.ownFactPremises +#check @CoreReader.Engineering.actualOwnFactGrounded +#check @CoreReader.Engineering.priorityValueMeaning +#check @CoreReader.Engineering.priorityGrounds +#check @CoreReader.Engineering.OwnNorm +#check @CoreReader.Engineering.normApplies +#check @CoreReader.Engineering.ownNormClaim +#check @CoreReader.Engineering.actualOwnNorm +#check @CoreReader.Engineering.ownFactTheory +#check @CoreReader.Engineering.ownNormTheory +#check @CoreReader.Engineering.ownTheory +#check @CoreReader.Engineering.allNormativeContentHeld +#check @CoreReader.Engineering.nonemptyOwnObjects +#check @CoreReader.Engineering.comparisonContext +#check @CoreReader.Engineering.engineeringSnapshot +#check @CoreReader.Engineering.currentAdmissible +#check @CoreReader.Engineering.currentConsistency +#check @CoreReader.Engineering.wholeClaimGrounded +#check @CoreReader.Engineering.incompatibleNormTheory +#check @CoreReader.Engineering.incompatibleNormContext +#check @CoreReader.Engineering.normativeContentVariation +#check @CoreReader.Engineering.Inherited +#check @CoreReader.Engineering.inheritedCurrent +#check @CoreReader.Engineering.inheritedMutualApplication +#check @CoreReader.Engineering.inheritedMutualCases +#check @CoreReader.Engineering.priorityRemainsReflexive +#check @CoreReader.Engineering.priorityReflexiveCases +#check @CoreReader.Engineering.jointWitness +#check @CoreReader.Engineering.inheritedDoesNotEntailPriority +#check @CoreReader.Engineering.Reflection.Target +#check @CoreReader.Engineering.Reflection.Contract +#check @CoreReader.Engineering.Reflection.Input +#check @CoreReader.Engineering.Reflection.Verdict +#check @CoreReader.Engineering.Reflection.Outcome +#check @CoreReader.Engineering.Reflection.evaluate +#check @CoreReader.Engineering.Reflection.generate +#check @CoreReader.Engineering.Reflection.interpret +#check @CoreReader.Engineering.Reflection.Model +#check @CoreReader.Engineering.Reflection.Model.input +#check @CoreReader.Engineering.Reflection.Model.self +#check @CoreReader.Engineering.Reflection.Model.rule +#check @CoreReader.Engineering.Reflection.Model.rules +#check @CoreReader.Engineering.Reflection.Model.performed +#check @CoreReader.Engineering.Reflection.Model.follows +#check @CoreReader.Engineering.Reflection.recordedReflexivity +#check @CoreReader.Engineering.ReviewObject +#check @CoreReader.Engineering.ReviewCase +#check @CoreReader.Engineering.generationApplies +#check @CoreReader.Engineering.assessmentApplies +#check @CoreReader.Engineering.ruleObject +#check @CoreReader.Engineering.ruleProbe +#check @CoreReader.Engineering.generationRuleTest +#check @CoreReader.Engineering.assessmentRuleTest +#check @CoreReader.Engineering.sampleAwareAssessment +#check @CoreReader.Engineering.objectTest +#check @CoreReader.Engineering.reviewObjects +#check @CoreReader.Engineering.requestedCases +#check @CoreReader.Engineering.reviewReasons +#check @CoreReader.Engineering.statedReview +#check @CoreReader.Engineering.reviewBasis +#check @CoreReader.Engineering.selfModel +#check @CoreReader.Engineering.reviewIdentity +#check @CoreReader.Engineering.currentSelfRecords +#check @CoreReader.Engineering.currentSelfApplication +#check @CoreReader.Engineering.actualSelfCriticism +#check @CoreReader.Engineering.ownRuleIdentity +#check @CoreReader.Engineering.ownRuleContentVariation +#check @CoreReader.Engineering.proposedRuleRevision +#check @CoreReader.Engineering.CoreCommitment +#check @CoreReader.Engineering.coreCommitments +#check @CoreReader.Engineering.coreAdopted +#check @CoreReader.Engineering.AdoptionReason +#check @CoreReader.Engineering.reasonFor +#check @CoreReader.Engineering.ReasonRelevant +#check @CoreReader.Engineering.valueScope +#check @CoreReader.Engineering.safeguardExperiment +#check @CoreReader.Engineering.criticismFor +#check @CoreReader.Engineering.governancePosition +#check @CoreReader.Engineering.adoptionReasonRelevant +#check @CoreReader.Engineering.safeguardEnabled +#check @CoreReader.Engineering.safeguardDisabled +#check @CoreReader.Engineering.governanceValueProcedure +#check @CoreReader.Engineering.governanceGrounded +#check @CoreReader.Engineering.governanceRationaleLimits +#check @CoreReader.Engineering.selectionObjective +#check @CoreReader.Engineering.selectionPosition +#check @CoreReader.Engineering.selectionValueProcedure +#check @CoreReader.Engineering.selectionGrounded +#check @CoreReader.Evidence.Record +#check @CoreReader.Evidence.Compatible +#check @CoreReader.Evidence.Supports +#check @CoreReader.Evidence.Articulation +#check @CoreReader.Evidence.Articulated +#check @CoreReader.Evidence.ValuePosition +#check @CoreReader.Evidence.ValuePosition.commitment +#check @CoreReader.Evidence.ValuePosition.consequence +#check @CoreReader.Evidence.ValuePosition.activeReasons +#check @CoreReader.Evidence.JointAdoption +#check @CoreReader.Evidence.ValueProcedure +#check @CoreReader.Evidence.Facet +#check @CoreReader.Evidence.Facet.claim +#check @CoreReader.Evidence.FacetDischarged +#check @CoreReader.Evidence.FacetArticulated +#check @CoreReader.Evidence.canonicalArticulation +#check @CoreReader.Evidence.canonicalFacetArticulated +#check @CoreReader.Evidence.canonicalArticulated +#check @CoreReader.Evidence.Grounds +#check @CoreReader.Evidence.AchievementAccountability +#check @CoreReader.Evidence.transitionAchievement +#check @CoreReader.Evidence.transitionPerformanceRecord +#check @CoreReader.Evidence.transitionReportRecord +#check @CoreReader.Evidence.transitionPerformanceCompatible +#check @CoreReader.Evidence.transitionSupported +#check @CoreReader.Evidence.transitionFacet +#check @CoreReader.Evidence.transitionFacetDischarged +#check @CoreReader.Evidence.transitionAccountable +#check @CoreReader.Evidence.transitionReportCompatible +#check @CoreReader.Evidence.transitionReportDoesNotSupport +#check @CoreReader.Evidence.ConcreteAchievementExample +#check @CoreReader.Evidence.concreteAchievementExample +#check @CoreReader.Evidence.achievementNeedsSupport +#check @CoreReader.Evidence.supportWeakening +#check @CoreReader.Evidence.evidenceWeakeningCanLoseSupport +#check @CoreReader.Evidence.scopeRestriction +#check @CoreReader.Evidence.Duties +#check @CoreReader.Evidence.LabeledDuties +#check @CoreReader.Evidence.assessmentUnion +#check @CoreReader.Evidence.labelsCannotWaive +#check @CoreReader.Evidence.switchRecord +#check @CoreReader.Evidence.switchCompatible +#check @CoreReader.Evidence.switchSupported +#check @CoreReader.Evidence.optionBenefit +#check @CoreReader.Evidence.optionCost +#check @CoreReader.Evidence.optionReport +#check @CoreReader.Evidence.switchPosition +#check @CoreReader.Evidence.switchValueProcedure +#check @CoreReader.Evidence.oppositePosition +#check @CoreReader.Evidence.oppositePositionRejected +#check @CoreReader.Evidence.contradictoryStartingPosition +#check @CoreReader.Evidence.impossibleAdoptionPosition +#check @CoreReader.Evidence.inadmissibleValuePositionsRejected +#check @CoreReader.Evidence.unsupportedPosition +#check @CoreReader.Evidence.switchEmpirical +#check @CoreReader.Evidence.switchEmpiricalDischarged +#check @CoreReader.Evidence.mixedMissingResponsibility +#check @CoreReader.Evidence.uninformativeArgument +#check @CoreReader.Evidence.articulationNotSupport +#check @CoreReader.Evidence.unrelatedArticulationRejected +#check @CoreReader.Evidence.temperatureRecord +#check @CoreReader.Evidence.temperatureCompatible +#check @CoreReader.Evidence.BudgetWorld +#check @CoreReader.Evidence.announcement +#check @CoreReader.Evidence.announcementPosition +#check @CoreReader.Evidence.announcementHasJointAdoption +#check @CoreReader.Evidence.announcementNotBudgetReason +#check @CoreReader.Evidence.actionRecord +#check @CoreReader.Evidence.actionCompatible +#check @CoreReader.Evidence.measurementRepeatNotSupport +#check @CoreReader.Evidence.selfAssertionNotReason +#check @CoreReader.Evidence.valueWithoutSelfProof +#check @CoreReader.Evidence.BenefitCostWorld +#check @CoreReader.Evidence.measuredOutcome +#check @CoreReader.Evidence.benefitReason +#check @CoreReader.Evidence.costReason +#check @CoreReader.Evidence.jointReasonPosition +#check @CoreReader.Evidence.jointReasonProcedure +#check @CoreReader.Evidence.JointReasonsExample +#check @CoreReader.Evidence.jointReasonsExample +#check @CoreReader.Evidence.heterogeneousReasons +#check @CoreReader.Evidence.zeroRecord +#check @CoreReader.Evidence.localGenerator +#check @CoreReader.Evidence.allTrue +#check @CoreReader.Evidence.zeroCompatible +#check @CoreReader.Evidence.GeneratingProcess +#check @CoreReader.Evidence.GeneratingProcess.outputRevision +#check @CoreReader.Evidence.ProducedRevision +#check @CoreReader.Evidence.GeneratingProcess.produce +#check @CoreReader.Evidence.sampleGeneratingProcess +#check @CoreReader.Evidence.OwnedRevisionExample +#check @CoreReader.Evidence.ownedRevisionExample +#check @CoreReader.Evidence.selfOriginDoesNotSupport +#check @CoreReader.Evidence.localNotUniversal +#check @CoreReader.Evidence.hiddenDifference +#check @CoreReader.Evidence.singleObservation +#check @CoreReader.Evidence.arithmeticFacet +#check @CoreReader.Evidence.usesObservation +#check @CoreReader.Evidence.noUniversalChain +#check @CoreReader.Evidence.Trial +#check @CoreReader.Evidence.Verified +#check @CoreReader.Evidence.Reproduced +#check @CoreReader.Evidence.Bounded +#check @CoreReader.Evidence.variableOutcomesStableBound +#check @CoreReader.Evidence.verificationReproductionStability +#check @CoreReader.Evidence.Program +#check @CoreReader.Evidence.Program.eval +#check @CoreReader.Evidence.Process +#check @CoreReader.Evidence.OutputContract +#check @CoreReader.Evidence.ExplanationContract +#check @CoreReader.Evidence.outputOnlyProcess +#check @CoreReader.Evidence.explainedProcess +#check @CoreReader.Evidence.processScope +#check @CoreReader.Evidence.processContractFacet +#check @CoreReader.Evidence.processScopeModels +#check @CoreReader.Evidence.processContractDischarged +#check @CoreReader.Evidence.ProcessGrounds +#check @CoreReader.Evidence.processGrounds +#check @CoreReader.Evidence.outputCorrectByEvaluation +#check @CoreReader.Evidence.outputOnlyNoExplanation +#check @CoreReader.Evidence.FullProcessContract +#check @CoreReader.Evidence.OutputContractEvidence +#check @CoreReader.Evidence.outputContractEvidence +#check @CoreReader.Evidence.ScopedApplicationEvidence +#check @CoreReader.Evidence.scopedApplicationEvidence +#check @CoreReader.Evidence.outputNotExplanation +#check @CoreReader.Evidence.applicationContractsDiffer +#check @CoreReader.Evidence.ExternalCertificate +#check @CoreReader.Evidence.externalOutputCertificate +#check @CoreReader.Evidence.externalAssessment +#check @CoreReader.Evidence.arithmeticArticulation +#check @CoreReader.Evidence.nonExecutableAssessment +#check @CoreReader.Integration.canonicalGrounds +#check @CoreReader.Integration.canonicalGroundsForSingleton +#check @CoreReader.Integration.Mode +#check @CoreReader.Integration.World +#check @CoreReader.Integration.actual +#check @CoreReader.Integration.Method +#check @CoreReader.Integration.System +#check @CoreReader.Integration.policyFor +#check @CoreReader.Integration.workFor +#check @CoreReader.Integration.System.policy +#check @CoreReader.Integration.System.rules +#check @CoreReader.Integration.System.work +#check @CoreReader.Integration.actualSystem +#check @CoreReader.Integration.systemCapability +#check @CoreReader.Integration.systemBudget +#check @CoreReader.Integration.systemObservation +#check @CoreReader.Integration.systemHeld +#check @CoreReader.Integration.Question +#check @CoreReader.Integration.systemContext +#check @CoreReader.Integration.capability +#check @CoreReader.Integration.observation +#check @CoreReader.Integration.held +#check @CoreReader.Integration.context +#check @CoreReader.Integration.observationIdentifies +#check @CoreReader.Integration.capabilityActual +#check @CoreReader.Integration.observedCapability +#check @CoreReader.Integration.capabilityFacet +#check @CoreReader.Integration.capabilityFacetChecked +#check @CoreReader.Integration.capabilityGrounds +#check @CoreReader.Integration.actualAdmissible +#check @CoreReader.Integration.jointConsistent +#check @CoreReader.Integration.Charter +#check @CoreReader.Integration.charterChecked +#check @CoreReader.Integration.revisedHeld +#check @CoreReader.Integration.initialSnapshot +#check @CoreReader.Integration.revisedSnapshot +#check @CoreReader.Integration.revisionKeepsConsistency +#check @CoreReader.Integration.OwnCapabilityDuty +#check @CoreReader.Integration.ownCapabilityGrounded +#check @CoreReader.Integration.costAllowanceRecord +#check @CoreReader.Integration.unsupportedCapabilityFacet +#check @CoreReader.Integration.costCompatibleWithFailure +#check @CoreReader.Integration.costDoesNotSupportOutput +#check @CoreReader.Integration.unsupportedGrounds +#check @CoreReader.Integration.Commitment +#check @CoreReader.Integration.groundsPermission +#check @CoreReader.Integration.GroundsProvision +#check @CoreReader.Integration.groundsProvisionMeaning +#check @CoreReader.Integration.consistencyPermission +#check @CoreReader.Integration.conflictingHeld +#check @CoreReader.Integration.conflictConsequences +#check @CoreReader.Integration.conflictingHeldInconsistent +#check @CoreReader.Integration.choicePermission +#check @CoreReader.Integration.proposedOperation +#check @CoreReader.Integration.selfSamples +#check @CoreReader.Integration.conflictDecision +#check @CoreReader.Integration.groundsDecision +#check @CoreReader.Integration.choiceDecision +#check @CoreReader.Integration.decisionsApply +#check @CoreReader.Integration.decisionsWaive +#check @CoreReader.Integration.commitmentPositionFor +#check @CoreReader.Integration.commitmentPosition +#check @CoreReader.Integration.positionReasons +#check @CoreReader.Integration.positionConsequence +#check @CoreReader.Integration.positionProcedure +#check @CoreReader.Integration.criticismWithinScope +#check @CoreReader.Integration.oppositeConsequenceFails +#check @CoreReader.Integration.oppositeProcedureRejected +#check @CoreReader.Integration.commitmentClaim +#check @CoreReader.Integration.commitmentFacet +#check @CoreReader.Integration.reasonsBelongToCommitments +#check @CoreReader.Integration.groundsCommitmentIsProvision +#check @CoreReader.Integration.groundsSelfAssessment +#check @CoreReader.Integration.PhilosophyMethod +#check @CoreReader.Integration.currentPhilosophy +#check @CoreReader.Integration.PhilosophyMethod.review +#check @CoreReader.Integration.PhilosophyMethod.implementation +#check @CoreReader.Integration.proposalRequirements +#check @CoreReader.Integration.currentReviewCorrect +#check @CoreReader.Integration.existingPhilosophyNotPrivileged +#check @CoreReader.Integration.applicationClaim +#check @CoreReader.Integration.ApplicationDuties +#check @CoreReader.Integration.applicationRetainsDuties +#check @CoreReader.Integration.outputContract +#check @CoreReader.Integration.successorRequirements +#check @CoreReader.Integration.changedObjectiveFacet +#check @CoreReader.Integration.applicationVariation +#check @CoreReader.Integration.charterNotGrounds +#check @CoreReader.Integration.jointWitness +#check @CoreReader.Logic.Claim +#check @CoreReader.Logic.Theory +#check @CoreReader.Logic.Models +#check @CoreReader.Logic.Entails +#check @CoreReader.Logic.Satisfiable +#check @CoreReader.Logic.Context +#check @CoreReader.Logic.Admissible +#check @CoreReader.Logic.Consequence +#check @CoreReader.Logic.Consistent +#check @CoreReader.Logic.consequenceConsistency +#check @CoreReader.Logic.emptyTheory +#check @CoreReader.Logic.singleton +#check @CoreReader.Logic.union +#check @CoreReader.Logic.modelsSingleton +#check @CoreReader.Logic.modelsUnion +#check @CoreReader.Logic.premiseP +#check @CoreReader.Logic.premiseRule +#check @CoreReader.Logic.premiseNotQ +#check @CoreReader.Logic.jointTheory +#check @CoreReader.Logic.jointConflict +#check @CoreReader.Logic.revisionSlice +#check @CoreReader.Logic.revisionCanReverse +#check @CoreReader.Logic.onQuestion +#check @CoreReader.Logic.assumptionContext +#check @CoreReader.Logic.meaningContext +#check @CoreReader.Logic.scopeContext +#check @CoreReader.Logic.contextDifferences +#check @CoreReader.Logic.Snapshot +#check @CoreReader.Logic.SameContent +#check @CoreReader.Logic.TruthfulReport +#check @CoreReader.Logic.semanticChangeMustBeReported +#check @CoreReader.Logic.representationOrderIrrelevant +#check @CoreReader.Logic.contextSnapshot +#check @CoreReader.Logic.hiddenContextChangeRejected +#check @CoreReader.Logic.tensionWithoutContradiction +#check @CoreReader.Logic.conflictRequiresChange +#check @CoreReader.Logic.consistentFalse +#check @CoreReader.Logic.consistentIncomplete +#check @CoreReader.Logic.compatibilityNotEntailment +#check @CoreReader.Agency.Phase +#check @CoreReader.Agency.PrincipleKey +#check @CoreReader.Agency.Subject +#check @CoreReader.Agency.Subject.owner +#check @CoreReader.Agency.Activity +#check @CoreReader.Agency.QuestionKind +#check @CoreReader.Agency.SampleProgram +#check @CoreReader.Agency.SampleProgram.run +#check @CoreReader.Agency.MethodDraft +#check @CoreReader.Agency.MethodDraft.accepts +#check @CoreReader.Agency.Inquiry +#check @CoreReader.Agency.ReasonContent +#check @CoreReader.Agency.ReasonContent.identifier +#check @CoreReader.Agency.ReasonObject +#check @CoreReader.Agency.AssessmentResult +#check @CoreReader.Agency.WorkOutcome +#check @CoreReader.Agency.Principle +#check @CoreReader.Agency.WorkRecord +#check @CoreReader.Agency.RegistryCoherent +#check @CoreReader.Agency.TargetResolved +#check @CoreReader.Agency.TargetContentResolved +#check @CoreReader.Agency.Performed +#check @CoreReader.Agency.ReflexiveScope +#check @CoreReader.Agency.ValidApplication +#check @CoreReader.Agency.Reflexive +#check @CoreReader.Agency.Reflexive.toScope +#check @CoreReader.Agency.noSelfExemption +#check @CoreReader.Agency.localMethod +#check @CoreReader.Agency.inquiryFor +#check @CoreReader.Agency.sourceReasonContents +#check @CoreReader.Agency.reasonsFor +#check @CoreReader.Agency.assessInquiry +#check @CoreReader.Agency.finiteMethodResult +#check @CoreReader.Agency.finiteMethodMeaning +#check @CoreReader.Agency.ownSubjects +#check @CoreReader.Agency.generationEligible +#check @CoreReader.Agency.generatingRule +#check @CoreReader.Agency.assessingRule +#check @CoreReader.Agency.ownRules +#check @CoreReader.Agency.statedOutcome +#check @CoreReader.Agency.recordFor +#check @CoreReader.Agency.reasonsFor_nonempty +#check @CoreReader.Agency.reasonsFor_target +#check @CoreReader.Agency.inquiryFor_target +#check @CoreReader.Agency.ownContentEvaluates +#check @CoreReader.Agency.ownRegistryCoherent +#check @CoreReader.Agency.ownTargetResolved +#check @CoreReader.Agency.ownTargetContent +#check @CoreReader.Agency.ownRecordValid +#check @CoreReader.Agency.completeOwnWork +#check @CoreReader.Agency.assessingRecord_member +#check @CoreReader.Agency.generatingRecord_member +#check @CoreReader.Agency.completeOwnWork_reflexive +#check @CoreReader.Agency.ownAssessmentPerformed +#check @CoreReader.Agency.applicationRule +#check @CoreReader.Agency.applicationWork +#check @CoreReader.Agency.applicationWork_reflexive +#check @CoreReader.Agency.applicabilityRetained +#print axioms CoreReader.Adopted.AssessmentTask +#print axioms CoreReader.Adopted.taskOfFacet +#print axioms CoreReader.Adopted.NatureAppropriate +#print axioms CoreReader.Adopted.taskOfFacetAppropriate +#print axioms CoreReader.Adopted.Grounds012 +#print axioms CoreReader.Adopted.grounds012Singleton +#print axioms CoreReader.Adopted.generationSpecification +#print axioms CoreReader.Adopted.consistencySpecification +#print axioms CoreReader.Adopted.ReflexiveRule +#print axioms CoreReader.Adopted.reflexivitySpecification +#print axioms CoreReader.Adopted.legacyRule +#print axioms CoreReader.Adopted.legacyPerformed +#print axioms CoreReader.Adopted.legacyReflexivity +#print axioms CoreReader.Adopted.empiricalSpecification +#print axioms CoreReader.Adopted.inferentialSpecification +#print axioms CoreReader.Adopted.valueSpecification +#print axioms CoreReader.Adopted.AssessmentMethod +#print axioms CoreReader.Adopted.ScopeAccount +#print axioms CoreReader.Adopted.scopeSpecification +#print axioms CoreReader.Adopted.capabilitySpecification +#print axioms CoreReader.Adopted.choiceSpecification +#print axioms CoreReader.Adopted.collaborativeRevision +#print axioms CoreReader.Adopted.collaborativeProgress +#print axioms CoreReader.Adopted.consistencyConsequences +#print axioms CoreReader.Adopted.broadBoolContext +#print axioms CoreReader.Adopted.sliceConsistency +#print axioms CoreReader.Adopted.explicitlyConsistentLimits +#print axioms CoreReader.Adopted.localFacet012 +#print axioms CoreReader.Adopted.globalFacet012 +#print axioms CoreReader.Adopted.strongFacet012 +#print axioms CoreReader.Adopted.localFacetChecked012 +#print axioms CoreReader.Adopted.scopeStrength012 +#print axioms CoreReader.Adopted.uncertainFacet012 +#print axioms CoreReader.Adopted.uncertainSupported012 +#print axioms CoreReader.Adopted.InferenceExamined +#print axioms CoreReader.Adopted.inferenceChecked012 +#print axioms CoreReader.Adopted.closedPosition012 +#print axioms CoreReader.Adopted.closedCriticism012 +#print axioms CoreReader.Adopted.valueFulfilled012 +#print axioms CoreReader.Adopted.ClaimNoStronger +#print axioms CoreReader.Adopted.qualitativeProportionality012 +#print axioms CoreReader.Adopted.scopeRole012 +#print axioms CoreReader.Adopted.scopeRoleContent012 +#print axioms CoreReader.Adopted.localScopeAccount012 +#print axioms CoreReader.Adopted.scopeFulfilled012 +#print axioms CoreReader.Adopted.capabilityFulfilled012 +#print axioms CoreReader.Adopted.MechanismApplication012 +#print axioms CoreReader.Adopted.mechanism012 +#print axioms CoreReader.Adopted.UnderstandingApplication012 +#print axioms CoreReader.Adopted.explainedWithoutVariation012 +#print axioms CoreReader.Adopted.mechanismResponder012 +#print axioms CoreReader.Adopted.understandingScope012 +#print axioms CoreReader.Adopted.understandingTask012 +#print axioms CoreReader.Adopted.understandingFacet012 +#print axioms CoreReader.Adopted.mechanismResponderUnderstands012 +#print axioms CoreReader.Adopted.explainedWithoutVariationFails012 +#print axioms CoreReader.Adopted.understandingApplicationCases012 +#print axioms CoreReader.Adopted.OwnCapability012 +#print axioms CoreReader.Adopted.ownCapability012 +#print axioms CoreReader.Adopted.CompleteCharter012 +#print axioms CoreReader.Adopted.completeCharter012 +#print axioms CoreReader.Adopted.charterWithoutGrounds012 +#print axioms CoreReader.Adopted.groundsPermission012 +#print axioms CoreReader.Adopted.GroundsProvision012 +#print axioms CoreReader.Adopted.groundsProvision012Meaning +#print axioms CoreReader.Adopted.groundsExperimentTask012 +#print axioms CoreReader.Adopted.groundsExperiment012 +#print axioms CoreReader.Adopted.groundsPosition012 +#print axioms CoreReader.Adopted.groundsPosition012Checked +#print axioms CoreReader.Adopted.groundsRationaleExperiment012 +#print axioms CoreReader.Adopted.groundsOnGrounds012 +#print axioms CoreReader.Adopted.reflexiveTargets012 +#print axioms CoreReader.Adopted.achievementSupported012 +#print axioms CoreReader.Adopted.semanticOrder012 +#print axioms CoreReader.Adopted.clearFalseArgument012 +#print axioms CoreReader.Adopted.clearFalseReason012 +#print axioms CoreReader.Adopted.valueNeutralRecord012 +#print axioms CoreReader.Adopted.valueNotFact012 +#print axioms CoreReader.Adopted.wrongExplanation012 +#print axioms CoreReader.Adopted.internalReasonDistinguishes012 +#print axioms CoreReader.Adopted.inventoryCases012 +#print axioms CoreReader.Adopted.selfExemptRule012 +#print axioms CoreReader.Adopted.selfExemptPerformed012 +#print axioms CoreReader.Adopted.openSelfExempt012 +#print axioms CoreReader.Adopted.ownPhilosophyStatus012 +#print axioms CoreReader.Adopted.jointContext012 +#print axioms CoreReader.Adopted.jointImplicationConflict012 +#print axioms CoreReader.Adopted.tensionContext012 +#print axioms CoreReader.Adopted.tensionConsistent012 +#print axioms CoreReader.Adopted.qualitativeUnmeasured012 +#print axioms CoreReader.Adopted.allStatusOnly012 +#print axioms CoreReader.Adopted.drawWeight012 +#print axioms CoreReader.Adopted.randomTrial012 +#print axioms CoreReader.Adopted.randomOutcomes012 +#print axioms CoreReader.Adopted.originalGlobalTask012 +#print axioms CoreReader.Adopted.originalLocalTask012 +#print axioms CoreReader.Adopted.circularGlobalFacet012 +#print axioms CoreReader.Adopted.circularGlobalConditional012 +#print axioms CoreReader.Adopted.circularSubstitutionRejected012 +#print axioms CoreReader.Adopted.observedPremises012 +#print axioms CoreReader.Adopted.observedInferenceFacet012 +#print axioms CoreReader.Adopted.observedInferenceChecked012 +#print axioms CoreReader.Adopted.sameEmpiricalTaskTwoMethods012 +#print axioms CoreReader.Adopted.originalUncertaintyTask012 +#print axioms CoreReader.Adopted.uncertaintyBypassFacet012 +#print axioms CoreReader.Adopted.uncertaintyBypassChecked012 +#print axioms CoreReader.Adopted.uncertaintySubstitutionRejected012 +#print axioms CoreReader.Adopted.selectedFactFacet012 +#print axioms CoreReader.Adopted.valueFactSubstitutionRejected012 +#print axioms CoreReader.Adopted.inferentialContextSubstitutionRejected012 +#print axioms CoreReader.Adopted.generationCases +#print axioms CoreReader.Adopted.generationLimits012 +#print axioms CoreReader.Adopted.consistencyCases +#print axioms CoreReader.Adopted.consistencyLimits012 +#print axioms CoreReader.Adopted.reflexivityCases012 +#print axioms CoreReader.Adopted.reflexivityLimits012 +#print axioms CoreReader.Adopted.groundsCases012 +#print axioms CoreReader.Adopted.empiricalCases012 +#print axioms CoreReader.Adopted.inferentialCases012 +#print axioms CoreReader.Adopted.valueCases012 +#print axioms CoreReader.Adopted.groundsLimits012 +#print axioms CoreReader.Adopted.scopeCases012 +#print axioms CoreReader.Adopted.scopeLimits012 +#print axioms CoreReader.Adopted.capabilityCases012 +#print axioms CoreReader.Adopted.capabilityLimits012 +#print axioms CoreReader.Adopted.choiceCases012 +#print axioms CoreReader.Adopted.choiceLimits012 +#print axioms CoreReader.Agency.FormKind +#print axioms CoreReader.Agency.Form +#print axioms CoreReader.Agency.Aim +#print axioms CoreReader.Agency.Policy +#print axioms CoreReader.Agency.Generative +#print axioms CoreReader.Agency.openPolicy +#print axioms CoreReader.Agency.neutralPolicy +#print axioms CoreReader.Agency.permissionNotValuation +#print axioms CoreReader.Agency.revisabilityCovers +#print axioms CoreReader.Agency.Operation +#print axioms CoreReader.Agency.Operation.run +#print axioms CoreReader.Agency.InventoryKind +#print axioms CoreReader.Agency.Item +#print axioms CoreReader.Agency.Available +#print axioms CoreReader.Agency.inventoryNotCapability +#print axioms CoreReader.Agency.State +#print axioms CoreReader.Agency.Expanded +#print axioms CoreReader.Agency.baseState +#print axioms CoreReader.Agency.inflatedState +#print axioms CoreReader.Agency.stableTrace +#print axioms CoreReader.Agency.revisionWithoutProgress +#print axioms CoreReader.Agency.ExternalResources +#print axioms CoreReader.Agency.assistedExecution +#print axioms CoreReader.Agency.availableResources +#print axioms CoreReader.Agency.StableReason +#print axioms CoreReader.Agency.GeneratingSystem +#print axioms CoreReader.Agency.generatingSystem +#print axioms CoreReader.Agency.GeneratingSystem.stableAction +#print axioms CoreReader.Agency.GeneratingSystem.requirementsMet +#print axioms CoreReader.Agency.GeneratingSystem.withinBudget +#print axioms CoreReader.Agency.Announcement +#print axioms CoreReader.Agency.GeneratingSystem.report +#print axioms CoreReader.Agency.Announcement.claim +#print axioms CoreReader.Agency.announcementClaimImpliesExpansion +#print axioms CoreReader.Agency.inflatedAnnouncement +#print axioms CoreReader.Agency.inflatedAnnouncementRefuted +#print axioms CoreReader.Agency.TransitionCase +#print axioms CoreReader.Agency.extendedState +#print axioms CoreReader.Agency.transitionBefore +#print axioms CoreReader.Agency.transitionAfter +#print axioms CoreReader.Agency.transitionInput +#print axioms CoreReader.Agency.transitionAnnouncement +#print axioms CoreReader.Agency.generationLimits +#print axioms CoreReader.Agency.generationNotReflexivity +#print axioms CoreReader.Agency.ownArithmeticPrinciple +#print axioms CoreReader.Agency.selfTest +#print axioms CoreReader.Agency.selfTestDoesNotProve +#print axioms CoreReader.Choice.StatusKind +#print axioms CoreReader.Choice.MethodReason +#print axioms CoreReader.Choice.Reason +#print axioms CoreReader.Choice.Implementation +#print axioms CoreReader.Choice.Requirements +#print axioms CoreReader.Choice.MethodContent +#print axioms CoreReader.Choice.Relevant +#print axioms CoreReader.Choice.Feasible +#print axioms CoreReader.Choice.JustifiedChoice +#print axioms CoreReader.Choice.statusOnlyFails +#print axioms CoreReader.Choice.identityImpl +#print axioms CoreReader.Choice.successorImpl +#print axioms CoreReader.Choice.changedOutsideZero +#print axioms CoreReader.Choice.identityRequirements +#print axioms CoreReader.Choice.objectiveReason +#print axioms CoreReader.Choice.identityOutputReason +#print axioms CoreReader.Choice.identityFeasible +#print axioms CoreReader.Choice.identityJustified +#print axioms CoreReader.Choice.conventionWithReason +#print axioms CoreReader.Choice.Candidate +#print axioms CoreReader.Choice.implementation +#print axioms CoreReader.Choice.singleFeasible +#print axioms CoreReader.Choice.localNotGlobal +#print axioms CoreReader.Choice.cheapSuccessor +#print axioms CoreReader.Choice.eligibleInternalReasonNotSufficient +#print axioms CoreReader.Choice.internalReasons +#print axioms CoreReader.Choice.openNotEquivalent +#print axioms CoreReader.Choice.priorityClaim +#print axioms CoreReader.Choice.statusFacts +#print axioms CoreReader.Choice.statusFactsModel +#print axioms CoreReader.Choice.priorityArticulation +#print axioms CoreReader.Choice.AssessmentAccurate +#print axioms CoreReader.Choice.statusDoesNotEntailPriority +#print axioms CoreReader.Choice.statusAssessmentNonEntailment +#print axioms CoreReader.Choice.PriorityAssessment +#print axioms CoreReader.Choice.PriorityAssessment.accurate +#print axioms CoreReader.Choice.statusPriorityAudit +#print axioms CoreReader.Choice.ChoicePolicy +#print axioms CoreReader.Choice.GeneralAssessmentFulfilled +#print axioms CoreReader.Choice.AdditionalChoiceNorm +#print axioms CoreReader.Choice.statusPriorityPolicy +#print axioms CoreReader.Choice.outputPriorityPolicy +#print axioms CoreReader.Choice.statusPriorityAuditAccurate +#print axioms CoreReader.Choice.PolicyIndependenceExample +#print axioms CoreReader.Choice.policyIndependenceExample +#print axioms CoreReader.Choice.generalGroundsNotChoice +#print axioms CoreReader.Engineering.Maintainer +#print axioms CoreReader.Engineering.Tool +#print axioms CoreReader.Engineering.Knowledge +#print axioms CoreReader.Engineering.Change +#print axioms CoreReader.Engineering.Candidate +#print axioms CoreReader.Engineering.Burden +#print axioms CoreReader.Engineering.maintainers +#print axioms CoreReader.Engineering.changes +#print axioms CoreReader.Engineering.burdens +#print axioms CoreReader.Engineering.Activity +#print axioms CoreReader.Engineering.ActivityScope +#print axioms CoreReader.Engineering.Continuing +#print axioms CoreReader.Engineering.BoundedLifecycle +#print axioms CoreReader.Engineering.continuingActivity +#print axioms CoreReader.Engineering.temporaryActivity +#print axioms CoreReader.Engineering.prototypeActivity +#print axioms CoreReader.Engineering.retiringActivity +#print axioms CoreReader.Engineering.EditStep +#print axioms CoreReader.Engineering.changePath +#print axioms CoreReader.Engineering.changeWork +#print axioms CoreReader.Engineering.CanChange +#print axioms CoreReader.Engineering.ContinuingCapability +#print axioms CoreReader.Engineering.registeredDirections +#print axioms CoreReader.Engineering.supportedDirections +#print axioms CoreReader.Engineering.MaximumRegisteredCapability +#print axioms CoreReader.Engineering.passiveArtifact +#print axioms CoreReader.Engineering.orientation +#print axioms CoreReader.Engineering.EngineeringAction +#print axioms CoreReader.Engineering.maintainerActions +#print axioms CoreReader.Engineering.artifactActions +#print axioms CoreReader.Engineering.subjectLifecycleCases +#print axioms CoreReader.Engineering.subjectLimits +#print axioms CoreReader.Engineering.CredibleDirection +#print axioms CoreReader.Engineering.DirectionGround +#print axioms CoreReader.Engineering.articulateGround +#print axioms CoreReader.Engineering.supportGround +#print axioms CoreReader.Engineering.initialGrounds +#print axioms CoreReader.Engineering.forecastGrounds +#print axioms CoreReader.Engineering.credible +#print axioms CoreReader.Engineering.WarrantedAccommodation +#print axioms CoreReader.Engineering.credibilityCases +#print axioms CoreReader.Engineering.abstractionComplexity +#print axioms CoreReader.Engineering.implementedVariants +#print axioms CoreReader.Engineering.CostVector +#print axioms CoreReader.Engineering.CostLimits +#print axioms CoreReader.Engineering.cost +#print axioms CoreReader.Engineering.normalLimits +#print axioms CoreReader.Engineering.Requirements +#print axioms CoreReader.Engineering.normalRequirements +#print axioms CoreReader.Engineering.behavior +#print axioms CoreReader.Engineering.CandidateProfile +#print axioms CoreReader.Engineering.profile +#print axioms CoreReader.Engineering.Meets +#print axioms CoreReader.Engineering.Context +#print axioms CoreReader.Engineering.currentContinuing +#print axioms CoreReader.Engineering.ConcreteThreat +#print axioms CoreReader.Engineering.HasThreat +#print axioms CoreReader.Engineering.JustifiedDeparture +#print axioms CoreReader.Engineering.PriorityConditions +#print axioms CoreReader.Engineering.EvolutionPriority +#print axioms CoreReader.Engineering.currentPriorityConditions +#print axioms CoreReader.Engineering.currentNoThreat +#print axioms CoreReader.Engineering.threatened +#print axioms CoreReader.Engineering.priorityWhenApplicable +#print axioms CoreReader.Engineering.currentSimpleViolates +#print axioms CoreReader.Engineering.withEvolvableProfile +#print axioms CoreReader.Engineering.unmetRequirementsBlockPriority +#print axioms CoreReader.Engineering.priorityConditionsCases +#print axioms CoreReader.Engineering.priorityChoices +#print axioms CoreReader.Engineering.credibilityLimits +#print axioms CoreReader.Engineering.costCases +#print axioms CoreReader.Engineering.orderedUnique +#print axioms CoreReader.Engineering.orderedRefactor +#print axioms CoreReader.Engineering.insertOrdered +#print axioms CoreReader.Engineering.sortValues +#print axioms CoreReader.Engineering.sortedUnique +#print axioms CoreReader.Engineering.SoftwareState +#print axioms CoreReader.Engineering.originalSoftware +#print axioms CoreReader.Engineering.transform +#print axioms CoreReader.Engineering.evolutionBehavior +#print axioms CoreReader.Engineering.ObligationTreatment +#print axioms CoreReader.Engineering.ChangeClaim +#print axioms CoreReader.Engineering.contractInputs +#print axioms CoreReader.Engineering.PreservesOn +#print axioms CoreReader.Engineering.PreservesFinite +#print axioms CoreReader.Engineering.ObservableContract +#print axioms CoreReader.Engineering.retry +#print axioms CoreReader.Engineering.orderContract +#print axioms CoreReader.Engineering.originalContract +#print axioms CoreReader.Engineering.refactoredContract +#print axioms CoreReader.Engineering.revisedContract +#print axioms CoreReader.Engineering.evolutionContract +#print axioms CoreReader.Engineering.failureInputs +#print axioms CoreReader.Engineering.PreservesContractFinite +#print axioms CoreReader.Engineering.ContractAspect +#print axioms CoreReader.Engineering.PartyDependency +#print axioms CoreReader.Engineering.partyDependencies +#print axioms CoreReader.Engineering.aspectChanged +#print axioms CoreReader.Engineering.affectedParties +#print axioms CoreReader.Engineering.ContractRevision +#print axioms CoreReader.Engineering.normalRevision +#print axioms CoreReader.Engineering.RevisionDuties +#print axioms CoreReader.Engineering.ContractChangeAccount +#print axioms CoreReader.Engineering.EvolutionClaim +#print axioms CoreReader.Engineering.evolutionKindsCases +#print axioms CoreReader.Engineering.evolutionDimensionsLimits +#print axioms CoreReader.Engineering.oneDimensionDoesNotEntailEveryDimension +#print axioms CoreReader.Engineering.propagation +#print axioms CoreReader.Engineering.batchCount +#print axioms CoreReader.Engineering.staticBatch +#print axioms CoreReader.Engineering.liveBatch +#print axioms CoreReader.Engineering.StructuralEvidence +#print axioms CoreReader.Engineering.structuralEvidence +#print axioms CoreReader.Engineering.StructuralAccount +#print axioms CoreReader.Engineering.InterfaceView +#print axioms CoreReader.Engineering.sameShape +#print axioms CoreReader.Engineering.moduleAssumptions +#print axioms CoreReader.Engineering.modulesNeedingRevision +#print axioms CoreReader.Engineering.Boundary +#print axioms CoreReader.Engineering.EngineeringDesign +#print axioms CoreReader.Engineering.privateDesign +#print axioms CoreReader.Engineering.documentedDesign +#print axioms CoreReader.Engineering.sortedDesign +#print axioms CoreReader.Engineering.coordinatedBoundary +#print axioms CoreReader.Engineering.boundaryDesign +#print axioms CoreReader.Engineering.crossesBoundary +#print axioms CoreReader.Engineering.boundaryObligationChecked +#print axioms CoreReader.Engineering.omittedCallerCheck +#print axioms CoreReader.Engineering.otherCalleeBoundary +#print axioms CoreReader.Engineering.otherCalleeDesign +#print axioms CoreReader.Engineering.actualCrossBoundaryObligation +#print axioms CoreReader.Engineering.structuralCases +#print axioms CoreReader.Engineering.DesignCanChange +#print axioms CoreReader.Engineering.designWork +#print axioms CoreReader.Engineering.designModulesNeedingRevision +#print axioms CoreReader.Engineering.introduceBoundary +#print axioms CoreReader.Engineering.wrappedDesign +#print axioms CoreReader.Engineering.relocateVerification +#print axioms CoreReader.Engineering.sameWorkDesign +#print axioms CoreReader.Engineering.structureNotCapability +#print axioms CoreReader.Engineering.contractPreservation +#print axioms CoreReader.Engineering.changedObservationNotPreserved +#print axioms CoreReader.Engineering.contractRevisionObligations +#print axioms CoreReader.Engineering.retiredBehavior +#print axioms CoreReader.Engineering.contractCases +#print axioms CoreReader.Engineering.contractDistinctions +#print axioms CoreReader.Engineering.RevisionState +#print axioms CoreReader.Engineering.RevisionRecord +#print axioms CoreReader.Engineering.MaterialGroundsChanged +#print axioms CoreReader.Engineering.oldState +#print axioms CoreReader.Engineering.newState +#print axioms CoreReader.Engineering.HistoricalEvidence +#print axioms CoreReader.Engineering.observedHistory +#print axioms CoreReader.Engineering.RevisionAccountAgainst +#print axioms CoreReader.Engineering.RevisionAccount +#print axioms CoreReader.Engineering.failedHistoryNotRewritten +#print axioms CoreReader.Engineering.revisionRecord +#print axioms CoreReader.Engineering.SupportedAlternative +#print axioms CoreReader.Engineering.RetentionJustified +#print axioms CoreReader.Engineering.stableRecord +#print axioms CoreReader.Engineering.revisionCases +#print axioms CoreReader.Engineering.observations +#print axioms CoreReader.Engineering.revisionsMade +#print axioms CoreReader.Engineering.agreedBatch +#print axioms CoreReader.Engineering.rewrittenOldRecord +#print axioms CoreReader.Engineering.rewrittenPredictionRecord +#print axioms CoreReader.Engineering.rewrittenObservationRecord +#print axioms CoreReader.Engineering.unrelatedSoftwareRecord +#print axioms CoreReader.Engineering.historicalTamperingRejected +#print axioms CoreReader.Engineering.revisionLimits +#print axioms CoreReader.Engineering.groundedChanges +#print axioms CoreReader.Engineering.currentRevisionState +#print axioms CoreReader.Engineering.revisionFor +#print axioms CoreReader.Engineering.revisionContextIdentity +#print axioms CoreReader.Engineering.DomainSatisfied +#print axioms CoreReader.Engineering.currentDomainSatisfied +#print axioms CoreReader.Engineering.sharedContext +#print axioms CoreReader.Engineering.maintainedOutput +#print axioms CoreReader.Engineering.chosenImplementation +#print axioms CoreReader.Engineering.chosenRequirements +#print axioms CoreReader.Engineering.chosenReasons +#print axioms CoreReader.Engineering.maintainedOutputCorrect +#print axioms CoreReader.Engineering.implementationReasoned +#print axioms CoreReader.Engineering.capabilityOutput +#print axioms CoreReader.Engineering.engineeringProcess +#print axioms CoreReader.Engineering.engineeringCapability +#print axioms CoreReader.Engineering.engineeringCapabilityGrounded +#print axioms CoreReader.Engineering.actualCapabilityContrast +#print axioms CoreReader.Engineering.presentBudgetRecord +#print axioms CoreReader.Engineering.presentBudgetClaim +#print axioms CoreReader.Engineering.budgetObservationMeaning +#print axioms CoreReader.Engineering.budgetEmpiricalFacet +#print axioms CoreReader.Engineering.budgetEmpiricalDischarged +#print axioms CoreReader.Engineering.capacityClaim +#print axioms CoreReader.Engineering.capacityAssumptions +#print axioms CoreReader.Engineering.budgetInferentialFacet +#print axioms CoreReader.Engineering.budgetInferentialDischarged +#print axioms CoreReader.Engineering.budgetScopeAccount +#print axioms CoreReader.Engineering.budgetScopeExplained +#print axioms CoreReader.Engineering.budgetObservationLimit +#print axioms CoreReader.Engineering.engineeringPolicy +#print axioms CoreReader.Engineering.engineeringGenerative +#print axioms CoreReader.Engineering.OwnFact +#print axioms CoreReader.Engineering.ownFactClaim +#print axioms CoreReader.Engineering.actualOwnFact +#print axioms CoreReader.Engineering.ownFactPremises +#print axioms CoreReader.Engineering.actualOwnFactGrounded +#print axioms CoreReader.Engineering.priorityValueMeaning +#print axioms CoreReader.Engineering.priorityGrounds +#print axioms CoreReader.Engineering.OwnNorm +#print axioms CoreReader.Engineering.normApplies +#print axioms CoreReader.Engineering.ownNormClaim +#print axioms CoreReader.Engineering.actualOwnNorm +#print axioms CoreReader.Engineering.ownFactTheory +#print axioms CoreReader.Engineering.ownNormTheory +#print axioms CoreReader.Engineering.ownTheory +#print axioms CoreReader.Engineering.allNormativeContentHeld +#print axioms CoreReader.Engineering.nonemptyOwnObjects +#print axioms CoreReader.Engineering.comparisonContext +#print axioms CoreReader.Engineering.engineeringSnapshot +#print axioms CoreReader.Engineering.currentAdmissible +#print axioms CoreReader.Engineering.currentConsistency +#print axioms CoreReader.Engineering.wholeClaimGrounded +#print axioms CoreReader.Engineering.incompatibleNormTheory +#print axioms CoreReader.Engineering.incompatibleNormContext +#print axioms CoreReader.Engineering.normativeContentVariation +#print axioms CoreReader.Engineering.Inherited +#print axioms CoreReader.Engineering.inheritedCurrent +#print axioms CoreReader.Engineering.inheritedMutualApplication +#print axioms CoreReader.Engineering.inheritedMutualCases +#print axioms CoreReader.Engineering.priorityRemainsReflexive +#print axioms CoreReader.Engineering.priorityReflexiveCases +#print axioms CoreReader.Engineering.jointWitness +#print axioms CoreReader.Engineering.inheritedDoesNotEntailPriority +#print axioms CoreReader.Engineering.Reflection.Target +#print axioms CoreReader.Engineering.Reflection.Contract +#print axioms CoreReader.Engineering.Reflection.Input +#print axioms CoreReader.Engineering.Reflection.Verdict +#print axioms CoreReader.Engineering.Reflection.Outcome +#print axioms CoreReader.Engineering.Reflection.evaluate +#print axioms CoreReader.Engineering.Reflection.generate +#print axioms CoreReader.Engineering.Reflection.interpret +#print axioms CoreReader.Engineering.Reflection.Model +#print axioms CoreReader.Engineering.Reflection.Model.input +#print axioms CoreReader.Engineering.Reflection.Model.self +#print axioms CoreReader.Engineering.Reflection.Model.rule +#print axioms CoreReader.Engineering.Reflection.Model.rules +#print axioms CoreReader.Engineering.Reflection.Model.performed +#print axioms CoreReader.Engineering.Reflection.Model.follows +#print axioms CoreReader.Engineering.Reflection.recordedReflexivity +#print axioms CoreReader.Engineering.ReviewObject +#print axioms CoreReader.Engineering.ReviewCase +#print axioms CoreReader.Engineering.generationApplies +#print axioms CoreReader.Engineering.assessmentApplies +#print axioms CoreReader.Engineering.ruleObject +#print axioms CoreReader.Engineering.ruleProbe +#print axioms CoreReader.Engineering.generationRuleTest +#print axioms CoreReader.Engineering.assessmentRuleTest +#print axioms CoreReader.Engineering.sampleAwareAssessment +#print axioms CoreReader.Engineering.objectTest +#print axioms CoreReader.Engineering.reviewObjects +#print axioms CoreReader.Engineering.requestedCases +#print axioms CoreReader.Engineering.reviewReasons +#print axioms CoreReader.Engineering.statedReview +#print axioms CoreReader.Engineering.reviewBasis +#print axioms CoreReader.Engineering.selfModel +#print axioms CoreReader.Engineering.reviewIdentity +#print axioms CoreReader.Engineering.currentSelfRecords +#print axioms CoreReader.Engineering.currentSelfApplication +#print axioms CoreReader.Engineering.actualSelfCriticism +#print axioms CoreReader.Engineering.ownRuleIdentity +#print axioms CoreReader.Engineering.ownRuleContentVariation +#print axioms CoreReader.Engineering.proposedRuleRevision +#print axioms CoreReader.Engineering.CoreCommitment +#print axioms CoreReader.Engineering.coreCommitments +#print axioms CoreReader.Engineering.coreAdopted +#print axioms CoreReader.Engineering.AdoptionReason +#print axioms CoreReader.Engineering.reasonFor +#print axioms CoreReader.Engineering.ReasonRelevant +#print axioms CoreReader.Engineering.valueScope +#print axioms CoreReader.Engineering.safeguardExperiment +#print axioms CoreReader.Engineering.criticismFor +#print axioms CoreReader.Engineering.governancePosition +#print axioms CoreReader.Engineering.adoptionReasonRelevant +#print axioms CoreReader.Engineering.safeguardEnabled +#print axioms CoreReader.Engineering.safeguardDisabled +#print axioms CoreReader.Engineering.governanceValueProcedure +#print axioms CoreReader.Engineering.governanceGrounded +#print axioms CoreReader.Engineering.governanceRationaleLimits +#print axioms CoreReader.Engineering.selectionObjective +#print axioms CoreReader.Engineering.selectionPosition +#print axioms CoreReader.Engineering.selectionValueProcedure +#print axioms CoreReader.Engineering.selectionGrounded +#print axioms CoreReader.Evidence.Record +#print axioms CoreReader.Evidence.Compatible +#print axioms CoreReader.Evidence.Supports +#print axioms CoreReader.Evidence.Articulation +#print axioms CoreReader.Evidence.Articulated +#print axioms CoreReader.Evidence.ValuePosition +#print axioms CoreReader.Evidence.ValuePosition.commitment +#print axioms CoreReader.Evidence.ValuePosition.consequence +#print axioms CoreReader.Evidence.ValuePosition.activeReasons +#print axioms CoreReader.Evidence.JointAdoption +#print axioms CoreReader.Evidence.ValueProcedure +#print axioms CoreReader.Evidence.Facet +#print axioms CoreReader.Evidence.Facet.claim +#print axioms CoreReader.Evidence.FacetDischarged +#print axioms CoreReader.Evidence.FacetArticulated +#print axioms CoreReader.Evidence.canonicalArticulation +#print axioms CoreReader.Evidence.canonicalFacetArticulated +#print axioms CoreReader.Evidence.canonicalArticulated +#print axioms CoreReader.Evidence.Grounds +#print axioms CoreReader.Evidence.AchievementAccountability +#print axioms CoreReader.Evidence.transitionAchievement +#print axioms CoreReader.Evidence.transitionPerformanceRecord +#print axioms CoreReader.Evidence.transitionReportRecord +#print axioms CoreReader.Evidence.transitionPerformanceCompatible +#print axioms CoreReader.Evidence.transitionSupported +#print axioms CoreReader.Evidence.transitionFacet +#print axioms CoreReader.Evidence.transitionFacetDischarged +#print axioms CoreReader.Evidence.transitionAccountable +#print axioms CoreReader.Evidence.transitionReportCompatible +#print axioms CoreReader.Evidence.transitionReportDoesNotSupport +#print axioms CoreReader.Evidence.ConcreteAchievementExample +#print axioms CoreReader.Evidence.concreteAchievementExample +#print axioms CoreReader.Evidence.achievementNeedsSupport +#print axioms CoreReader.Evidence.supportWeakening +#print axioms CoreReader.Evidence.evidenceWeakeningCanLoseSupport +#print axioms CoreReader.Evidence.scopeRestriction +#print axioms CoreReader.Evidence.Duties +#print axioms CoreReader.Evidence.LabeledDuties +#print axioms CoreReader.Evidence.assessmentUnion +#print axioms CoreReader.Evidence.labelsCannotWaive +#print axioms CoreReader.Evidence.switchRecord +#print axioms CoreReader.Evidence.switchCompatible +#print axioms CoreReader.Evidence.switchSupported +#print axioms CoreReader.Evidence.optionBenefit +#print axioms CoreReader.Evidence.optionCost +#print axioms CoreReader.Evidence.optionReport +#print axioms CoreReader.Evidence.switchPosition +#print axioms CoreReader.Evidence.switchValueProcedure +#print axioms CoreReader.Evidence.oppositePosition +#print axioms CoreReader.Evidence.oppositePositionRejected +#print axioms CoreReader.Evidence.contradictoryStartingPosition +#print axioms CoreReader.Evidence.impossibleAdoptionPosition +#print axioms CoreReader.Evidence.inadmissibleValuePositionsRejected +#print axioms CoreReader.Evidence.unsupportedPosition +#print axioms CoreReader.Evidence.switchEmpirical +#print axioms CoreReader.Evidence.switchEmpiricalDischarged +#print axioms CoreReader.Evidence.mixedMissingResponsibility +#print axioms CoreReader.Evidence.uninformativeArgument +#print axioms CoreReader.Evidence.articulationNotSupport +#print axioms CoreReader.Evidence.unrelatedArticulationRejected +#print axioms CoreReader.Evidence.temperatureRecord +#print axioms CoreReader.Evidence.temperatureCompatible +#print axioms CoreReader.Evidence.BudgetWorld +#print axioms CoreReader.Evidence.announcement +#print axioms CoreReader.Evidence.announcementPosition +#print axioms CoreReader.Evidence.announcementHasJointAdoption +#print axioms CoreReader.Evidence.announcementNotBudgetReason +#print axioms CoreReader.Evidence.actionRecord +#print axioms CoreReader.Evidence.actionCompatible +#print axioms CoreReader.Evidence.measurementRepeatNotSupport +#print axioms CoreReader.Evidence.selfAssertionNotReason +#print axioms CoreReader.Evidence.valueWithoutSelfProof +#print axioms CoreReader.Evidence.BenefitCostWorld +#print axioms CoreReader.Evidence.measuredOutcome +#print axioms CoreReader.Evidence.benefitReason +#print axioms CoreReader.Evidence.costReason +#print axioms CoreReader.Evidence.jointReasonPosition +#print axioms CoreReader.Evidence.jointReasonProcedure +#print axioms CoreReader.Evidence.JointReasonsExample +#print axioms CoreReader.Evidence.jointReasonsExample +#print axioms CoreReader.Evidence.heterogeneousReasons +#print axioms CoreReader.Evidence.zeroRecord +#print axioms CoreReader.Evidence.localGenerator +#print axioms CoreReader.Evidence.allTrue +#print axioms CoreReader.Evidence.zeroCompatible +#print axioms CoreReader.Evidence.GeneratingProcess +#print axioms CoreReader.Evidence.GeneratingProcess.outputRevision +#print axioms CoreReader.Evidence.ProducedRevision +#print axioms CoreReader.Evidence.GeneratingProcess.produce +#print axioms CoreReader.Evidence.sampleGeneratingProcess +#print axioms CoreReader.Evidence.OwnedRevisionExample +#print axioms CoreReader.Evidence.ownedRevisionExample +#print axioms CoreReader.Evidence.selfOriginDoesNotSupport +#print axioms CoreReader.Evidence.localNotUniversal +#print axioms CoreReader.Evidence.hiddenDifference +#print axioms CoreReader.Evidence.singleObservation +#print axioms CoreReader.Evidence.arithmeticFacet +#print axioms CoreReader.Evidence.usesObservation +#print axioms CoreReader.Evidence.noUniversalChain +#print axioms CoreReader.Evidence.Trial +#print axioms CoreReader.Evidence.Verified +#print axioms CoreReader.Evidence.Reproduced +#print axioms CoreReader.Evidence.Bounded +#print axioms CoreReader.Evidence.variableOutcomesStableBound +#print axioms CoreReader.Evidence.verificationReproductionStability +#print axioms CoreReader.Evidence.Program +#print axioms CoreReader.Evidence.Program.eval +#print axioms CoreReader.Evidence.Process +#print axioms CoreReader.Evidence.OutputContract +#print axioms CoreReader.Evidence.ExplanationContract +#print axioms CoreReader.Evidence.outputOnlyProcess +#print axioms CoreReader.Evidence.explainedProcess +#print axioms CoreReader.Evidence.processScope +#print axioms CoreReader.Evidence.processContractFacet +#print axioms CoreReader.Evidence.processScopeModels +#print axioms CoreReader.Evidence.processContractDischarged +#print axioms CoreReader.Evidence.ProcessGrounds +#print axioms CoreReader.Evidence.processGrounds +#print axioms CoreReader.Evidence.outputCorrectByEvaluation +#print axioms CoreReader.Evidence.outputOnlyNoExplanation +#print axioms CoreReader.Evidence.FullProcessContract +#print axioms CoreReader.Evidence.OutputContractEvidence +#print axioms CoreReader.Evidence.outputContractEvidence +#print axioms CoreReader.Evidence.ScopedApplicationEvidence +#print axioms CoreReader.Evidence.scopedApplicationEvidence +#print axioms CoreReader.Evidence.outputNotExplanation +#print axioms CoreReader.Evidence.applicationContractsDiffer +#print axioms CoreReader.Evidence.ExternalCertificate +#print axioms CoreReader.Evidence.externalOutputCertificate +#print axioms CoreReader.Evidence.externalAssessment +#print axioms CoreReader.Evidence.arithmeticArticulation +#print axioms CoreReader.Evidence.nonExecutableAssessment +#print axioms CoreReader.Integration.canonicalGrounds +#print axioms CoreReader.Integration.canonicalGroundsForSingleton +#print axioms CoreReader.Integration.Mode +#print axioms CoreReader.Integration.World +#print axioms CoreReader.Integration.actual +#print axioms CoreReader.Integration.Method +#print axioms CoreReader.Integration.System +#print axioms CoreReader.Integration.policyFor +#print axioms CoreReader.Integration.workFor +#print axioms CoreReader.Integration.System.policy +#print axioms CoreReader.Integration.System.rules +#print axioms CoreReader.Integration.System.work +#print axioms CoreReader.Integration.actualSystem +#print axioms CoreReader.Integration.systemCapability +#print axioms CoreReader.Integration.systemBudget +#print axioms CoreReader.Integration.systemObservation +#print axioms CoreReader.Integration.systemHeld +#print axioms CoreReader.Integration.Question +#print axioms CoreReader.Integration.systemContext +#print axioms CoreReader.Integration.capability +#print axioms CoreReader.Integration.observation +#print axioms CoreReader.Integration.held +#print axioms CoreReader.Integration.context +#print axioms CoreReader.Integration.observationIdentifies +#print axioms CoreReader.Integration.capabilityActual +#print axioms CoreReader.Integration.observedCapability +#print axioms CoreReader.Integration.capabilityFacet +#print axioms CoreReader.Integration.capabilityFacetChecked +#print axioms CoreReader.Integration.capabilityGrounds +#print axioms CoreReader.Integration.actualAdmissible +#print axioms CoreReader.Integration.jointConsistent +#print axioms CoreReader.Integration.Charter +#print axioms CoreReader.Integration.charterChecked +#print axioms CoreReader.Integration.revisedHeld +#print axioms CoreReader.Integration.initialSnapshot +#print axioms CoreReader.Integration.revisedSnapshot +#print axioms CoreReader.Integration.revisionKeepsConsistency +#print axioms CoreReader.Integration.OwnCapabilityDuty +#print axioms CoreReader.Integration.ownCapabilityGrounded +#print axioms CoreReader.Integration.costAllowanceRecord +#print axioms CoreReader.Integration.unsupportedCapabilityFacet +#print axioms CoreReader.Integration.costCompatibleWithFailure +#print axioms CoreReader.Integration.costDoesNotSupportOutput +#print axioms CoreReader.Integration.unsupportedGrounds +#print axioms CoreReader.Integration.Commitment +#print axioms CoreReader.Integration.groundsPermission +#print axioms CoreReader.Integration.GroundsProvision +#print axioms CoreReader.Integration.groundsProvisionMeaning +#print axioms CoreReader.Integration.consistencyPermission +#print axioms CoreReader.Integration.conflictingHeld +#print axioms CoreReader.Integration.conflictConsequences +#print axioms CoreReader.Integration.conflictingHeldInconsistent +#print axioms CoreReader.Integration.choicePermission +#print axioms CoreReader.Integration.proposedOperation +#print axioms CoreReader.Integration.selfSamples +#print axioms CoreReader.Integration.conflictDecision +#print axioms CoreReader.Integration.groundsDecision +#print axioms CoreReader.Integration.choiceDecision +#print axioms CoreReader.Integration.decisionsApply +#print axioms CoreReader.Integration.decisionsWaive +#print axioms CoreReader.Integration.commitmentPositionFor +#print axioms CoreReader.Integration.commitmentPosition +#print axioms CoreReader.Integration.positionReasons +#print axioms CoreReader.Integration.positionConsequence +#print axioms CoreReader.Integration.positionProcedure +#print axioms CoreReader.Integration.criticismWithinScope +#print axioms CoreReader.Integration.oppositeConsequenceFails +#print axioms CoreReader.Integration.oppositeProcedureRejected +#print axioms CoreReader.Integration.commitmentClaim +#print axioms CoreReader.Integration.commitmentFacet +#print axioms CoreReader.Integration.reasonsBelongToCommitments +#print axioms CoreReader.Integration.groundsCommitmentIsProvision +#print axioms CoreReader.Integration.groundsSelfAssessment +#print axioms CoreReader.Integration.PhilosophyMethod +#print axioms CoreReader.Integration.currentPhilosophy +#print axioms CoreReader.Integration.PhilosophyMethod.review +#print axioms CoreReader.Integration.PhilosophyMethod.implementation +#print axioms CoreReader.Integration.proposalRequirements +#print axioms CoreReader.Integration.currentReviewCorrect +#print axioms CoreReader.Integration.existingPhilosophyNotPrivileged +#print axioms CoreReader.Integration.applicationClaim +#print axioms CoreReader.Integration.ApplicationDuties +#print axioms CoreReader.Integration.applicationRetainsDuties +#print axioms CoreReader.Integration.outputContract +#print axioms CoreReader.Integration.successorRequirements +#print axioms CoreReader.Integration.changedObjectiveFacet +#print axioms CoreReader.Integration.applicationVariation +#print axioms CoreReader.Integration.charterNotGrounds +#print axioms CoreReader.Integration.jointWitness +#print axioms CoreReader.Logic.Claim +#print axioms CoreReader.Logic.Theory +#print axioms CoreReader.Logic.Models +#print axioms CoreReader.Logic.Entails +#print axioms CoreReader.Logic.Satisfiable +#print axioms CoreReader.Logic.Context +#print axioms CoreReader.Logic.Admissible +#print axioms CoreReader.Logic.Consequence +#print axioms CoreReader.Logic.Consistent +#print axioms CoreReader.Logic.consequenceConsistency +#print axioms CoreReader.Logic.emptyTheory +#print axioms CoreReader.Logic.singleton +#print axioms CoreReader.Logic.union +#print axioms CoreReader.Logic.modelsSingleton +#print axioms CoreReader.Logic.modelsUnion +#print axioms CoreReader.Logic.premiseP +#print axioms CoreReader.Logic.premiseRule +#print axioms CoreReader.Logic.premiseNotQ +#print axioms CoreReader.Logic.jointTheory +#print axioms CoreReader.Logic.jointConflict +#print axioms CoreReader.Logic.revisionSlice +#print axioms CoreReader.Logic.revisionCanReverse +#print axioms CoreReader.Logic.onQuestion +#print axioms CoreReader.Logic.assumptionContext +#print axioms CoreReader.Logic.meaningContext +#print axioms CoreReader.Logic.scopeContext +#print axioms CoreReader.Logic.contextDifferences +#print axioms CoreReader.Logic.Snapshot +#print axioms CoreReader.Logic.SameContent +#print axioms CoreReader.Logic.TruthfulReport +#print axioms CoreReader.Logic.semanticChangeMustBeReported +#print axioms CoreReader.Logic.representationOrderIrrelevant +#print axioms CoreReader.Logic.contextSnapshot +#print axioms CoreReader.Logic.hiddenContextChangeRejected +#print axioms CoreReader.Logic.tensionWithoutContradiction +#print axioms CoreReader.Logic.conflictRequiresChange +#print axioms CoreReader.Logic.consistentFalse +#print axioms CoreReader.Logic.consistentIncomplete +#print axioms CoreReader.Logic.compatibilityNotEntailment +#print axioms CoreReader.Agency.Phase +#print axioms CoreReader.Agency.PrincipleKey +#print axioms CoreReader.Agency.Subject +#print axioms CoreReader.Agency.Subject.owner +#print axioms CoreReader.Agency.Activity +#print axioms CoreReader.Agency.QuestionKind +#print axioms CoreReader.Agency.SampleProgram +#print axioms CoreReader.Agency.SampleProgram.run +#print axioms CoreReader.Agency.MethodDraft +#print axioms CoreReader.Agency.MethodDraft.accepts +#print axioms CoreReader.Agency.Inquiry +#print axioms CoreReader.Agency.ReasonContent +#print axioms CoreReader.Agency.ReasonContent.identifier +#print axioms CoreReader.Agency.ReasonObject +#print axioms CoreReader.Agency.AssessmentResult +#print axioms CoreReader.Agency.WorkOutcome +#print axioms CoreReader.Agency.Principle +#print axioms CoreReader.Agency.WorkRecord +#print axioms CoreReader.Agency.RegistryCoherent +#print axioms CoreReader.Agency.TargetResolved +#print axioms CoreReader.Agency.TargetContentResolved +#print axioms CoreReader.Agency.Performed +#print axioms CoreReader.Agency.ReflexiveScope +#print axioms CoreReader.Agency.ValidApplication +#print axioms CoreReader.Agency.Reflexive +#print axioms CoreReader.Agency.Reflexive.toScope +#print axioms CoreReader.Agency.noSelfExemption +#print axioms CoreReader.Agency.localMethod +#print axioms CoreReader.Agency.inquiryFor +#print axioms CoreReader.Agency.sourceReasonContents +#print axioms CoreReader.Agency.reasonsFor +#print axioms CoreReader.Agency.assessInquiry +#print axioms CoreReader.Agency.finiteMethodResult +#print axioms CoreReader.Agency.finiteMethodMeaning +#print axioms CoreReader.Agency.ownSubjects +#print axioms CoreReader.Agency.generationEligible +#print axioms CoreReader.Agency.generatingRule +#print axioms CoreReader.Agency.assessingRule +#print axioms CoreReader.Agency.ownRules +#print axioms CoreReader.Agency.statedOutcome +#print axioms CoreReader.Agency.recordFor +#print axioms CoreReader.Agency.reasonsFor_nonempty +#print axioms CoreReader.Agency.reasonsFor_target +#print axioms CoreReader.Agency.inquiryFor_target +#print axioms CoreReader.Agency.ownContentEvaluates +#print axioms CoreReader.Agency.ownRegistryCoherent +#print axioms CoreReader.Agency.ownTargetResolved +#print axioms CoreReader.Agency.ownTargetContent +#print axioms CoreReader.Agency.ownRecordValid +#print axioms CoreReader.Agency.completeOwnWork +#print axioms CoreReader.Agency.assessingRecord_member +#print axioms CoreReader.Agency.generatingRecord_member +#print axioms CoreReader.Agency.completeOwnWork_reflexive +#print axioms CoreReader.Agency.ownAssessmentPerformed +#print axioms CoreReader.Agency.applicationRule +#print axioms CoreReader.Agency.applicationWork +#print axioms CoreReader.Agency.applicationWork_reflexive +#print axioms CoreReader.Agency.applicabilityRetained diff --git a/SoftwareEngineering/lean/philosophy/reviews/r3-axiom-summary.json b/SoftwareEngineering/lean/philosophy/reviews/r3-axiom-summary.json new file mode 100644 index 0000000..8c5d673 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/r3-axiom-summary.json @@ -0,0 +1,839 @@ +{ + "exit_code": 0, + "count": 831, + "declaration_count": 831, + "theorem_count": 282, + "axioms": { + "CoreReader.Adopted.AssessmentTask": "[]", + "CoreReader.Adopted.taskOfFacet": "[]", + "CoreReader.Adopted.NatureAppropriate": "[propext]", + "CoreReader.Adopted.taskOfFacetAppropriate": "[propext]", + "CoreReader.Adopted.Grounds012": "[propext]", + "CoreReader.Adopted.grounds012Singleton": "[propext]", + "CoreReader.Adopted.generationSpecification": "[]", + "CoreReader.Adopted.consistencySpecification": "[]", + "CoreReader.Adopted.ReflexiveRule": "[]", + "CoreReader.Adopted.reflexivitySpecification": "[]", + "CoreReader.Adopted.legacyRule": "[]", + "CoreReader.Adopted.legacyPerformed": "[]", + "CoreReader.Adopted.legacyReflexivity": "[propext, Quot.sound.{u}]", + "CoreReader.Adopted.empiricalSpecification": "[propext]", + "CoreReader.Adopted.inferentialSpecification": "[propext]", + "CoreReader.Adopted.valueSpecification": "[propext]", + "CoreReader.Adopted.AssessmentMethod": "[]", + "CoreReader.Adopted.ScopeAccount": "[]", + "CoreReader.Adopted.scopeSpecification": "[]", + "CoreReader.Adopted.capabilitySpecification": "[propext]", + "CoreReader.Adopted.choiceSpecification": "[]", + "CoreReader.Adopted.collaborativeRevision": "[]", + "CoreReader.Adopted.collaborativeProgress": "[propext, Quot.sound.{u}]", + "CoreReader.Adopted.consistencyConsequences": "[]", + "CoreReader.Adopted.broadBoolContext": "[]", + "CoreReader.Adopted.sliceConsistency": "[]", + "CoreReader.Adopted.explicitlyConsistentLimits": "[]", + "CoreReader.Adopted.localFacet012": "[]", + "CoreReader.Adopted.globalFacet012": "[]", + "CoreReader.Adopted.strongFacet012": "[]", + "CoreReader.Adopted.localFacetChecked012": "[propext]", + "CoreReader.Adopted.scopeStrength012": "[propext]", + "CoreReader.Adopted.uncertainFacet012": "[]", + "CoreReader.Adopted.uncertainSupported012": "[propext]", + "CoreReader.Adopted.InferenceExamined": "[]", + "CoreReader.Adopted.inferenceChecked012": "[propext]", + "CoreReader.Adopted.closedPosition012": "[]", + "CoreReader.Adopted.closedCriticism012": "[]", + "CoreReader.Adopted.valueFulfilled012": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Adopted.ClaimNoStronger": "[]", + "CoreReader.Adopted.qualitativeProportionality012": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Adopted.scopeRole012": "[]", + "CoreReader.Adopted.scopeRoleContent012": "[]", + "CoreReader.Adopted.localScopeAccount012": "[]", + "CoreReader.Adopted.scopeFulfilled012": "[propext]", + "CoreReader.Adopted.capabilityFulfilled012": "[propext]", + "CoreReader.Adopted.MechanismApplication012": "[]", + "CoreReader.Adopted.mechanism012": "[]", + "CoreReader.Adopted.UnderstandingApplication012": "[]", + "CoreReader.Adopted.explainedWithoutVariation012": "[]", + "CoreReader.Adopted.mechanismResponder012": "[]", + "CoreReader.Adopted.understandingScope012": "[]", + "CoreReader.Adopted.understandingTask012": "[]", + "CoreReader.Adopted.understandingFacet012": "[]", + "CoreReader.Adopted.mechanismResponderUnderstands012": "[propext]", + "CoreReader.Adopted.explainedWithoutVariationFails012": "[propext]", + "CoreReader.Adopted.understandingApplicationCases012": "[propext]", + "CoreReader.Adopted.OwnCapability012": "[propext]", + "CoreReader.Adopted.ownCapability012": "[propext]", + "CoreReader.Adopted.CompleteCharter012": "[propext]", + "CoreReader.Adopted.completeCharter012": "[propext, Quot.sound.{u}]", + "CoreReader.Adopted.charterWithoutGrounds012": "[propext, Quot.sound.{u}]", + "CoreReader.Adopted.groundsPermission012": "[propext]", + "CoreReader.Adopted.GroundsProvision012": "[propext]", + "CoreReader.Adopted.groundsProvision012Meaning": "[propext]", + "CoreReader.Adopted.groundsExperimentTask012": "[]", + "CoreReader.Adopted.groundsExperiment012": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Adopted.groundsPosition012": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Adopted.groundsPosition012Checked": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Adopted.groundsRationaleExperiment012": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Adopted.groundsOnGrounds012": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Adopted.reflexiveTargets012": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Adopted.achievementSupported012": "[propext, Quot.sound.{u}]", + "CoreReader.Adopted.semanticOrder012": "[]", + "CoreReader.Adopted.clearFalseArgument012": "[]", + "CoreReader.Adopted.clearFalseReason012": "[propext]", + "CoreReader.Adopted.valueNeutralRecord012": "[]", + "CoreReader.Adopted.valueNotFact012": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Adopted.wrongExplanation012": "[]", + "CoreReader.Adopted.internalReasonDistinguishes012": "[]", + "CoreReader.Adopted.inventoryCases012": "[propext, Quot.sound.{u}]", + "CoreReader.Adopted.selfExemptRule012": "[]", + "CoreReader.Adopted.selfExemptPerformed012": "[]", + "CoreReader.Adopted.openSelfExempt012": "[propext]", + "CoreReader.Adopted.ownPhilosophyStatus012": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Adopted.jointContext012": "[]", + "CoreReader.Adopted.jointImplicationConflict012": "[]", + "CoreReader.Adopted.tensionContext012": "[]", + "CoreReader.Adopted.tensionConsistent012": "[]", + "CoreReader.Adopted.qualitativeUnmeasured012": "[propext]", + "CoreReader.Adopted.allStatusOnly012": "[propext]", + "CoreReader.Adopted.drawWeight012": "[]", + "CoreReader.Adopted.randomTrial012": "[]", + "CoreReader.Adopted.randomOutcomes012": "[propext, Quot.sound.{u}]", + "CoreReader.Adopted.originalGlobalTask012": "[]", + "CoreReader.Adopted.originalLocalTask012": "[]", + "CoreReader.Adopted.circularGlobalFacet012": "[]", + "CoreReader.Adopted.circularGlobalConditional012": "[]", + "CoreReader.Adopted.circularSubstitutionRejected012": "[propext]", + "CoreReader.Adopted.observedPremises012": "[]", + "CoreReader.Adopted.observedInferenceFacet012": "[]", + "CoreReader.Adopted.observedInferenceChecked012": "[propext]", + "CoreReader.Adopted.sameEmpiricalTaskTwoMethods012": "[propext]", + "CoreReader.Adopted.originalUncertaintyTask012": "[]", + "CoreReader.Adopted.uncertaintyBypassFacet012": "[]", + "CoreReader.Adopted.uncertaintyBypassChecked012": "[propext]", + "CoreReader.Adopted.uncertaintySubstitutionRejected012": "[propext]", + "CoreReader.Adopted.selectedFactFacet012": "[]", + "CoreReader.Adopted.valueFactSubstitutionRejected012": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Adopted.inferentialContextSubstitutionRejected012": "[propext]", + "CoreReader.Adopted.generationCases": "[propext, Quot.sound.{u}]", + "CoreReader.Adopted.generationLimits012": "[propext, Quot.sound.{u}]", + "CoreReader.Adopted.consistencyCases": "[]", + "CoreReader.Adopted.consistencyLimits012": "[]", + "CoreReader.Adopted.reflexivityCases012": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Adopted.reflexivityLimits012": "[propext, Quot.sound.{u}]", + "CoreReader.Adopted.groundsCases012": "[propext]", + "CoreReader.Adopted.empiricalCases012": "[propext]", + "CoreReader.Adopted.inferentialCases012": "[propext]", + "CoreReader.Adopted.valueCases012": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Adopted.groundsLimits012": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Adopted.scopeCases012": "[propext]", + "CoreReader.Adopted.scopeLimits012": "[propext, Quot.sound.{u}]", + "CoreReader.Adopted.capabilityCases012": "[propext]", + "CoreReader.Adopted.capabilityLimits012": "[propext, Quot.sound.{u}]", + "CoreReader.Adopted.choiceCases012": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Adopted.choiceLimits012": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Agency.FormKind": "[]", + "CoreReader.Agency.Form": "[]", + "CoreReader.Agency.Aim": "[]", + "CoreReader.Agency.Policy": "[]", + "CoreReader.Agency.Generative": "[]", + "CoreReader.Agency.openPolicy": "[]", + "CoreReader.Agency.neutralPolicy": "[]", + "CoreReader.Agency.permissionNotValuation": "[propext, Quot.sound.{u}]", + "CoreReader.Agency.revisabilityCovers": "[]", + "CoreReader.Agency.Operation": "[]", + "CoreReader.Agency.Operation.run": "[]", + "CoreReader.Agency.InventoryKind": "[]", + "CoreReader.Agency.Item": "[]", + "CoreReader.Agency.Available": "[]", + "CoreReader.Agency.inventoryNotCapability": "[propext, Quot.sound.{u}]", + "CoreReader.Agency.State": "[]", + "CoreReader.Agency.Expanded": "[]", + "CoreReader.Agency.baseState": "[]", + "CoreReader.Agency.inflatedState": "[]", + "CoreReader.Agency.stableTrace": "[]", + "CoreReader.Agency.revisionWithoutProgress": "[propext, Quot.sound.{u}]", + "CoreReader.Agency.ExternalResources": "[]", + "CoreReader.Agency.assistedExecution": "[]", + "CoreReader.Agency.availableResources": "[]", + "CoreReader.Agency.StableReason": "[]", + "CoreReader.Agency.GeneratingSystem": "[]", + "CoreReader.Agency.generatingSystem": "[]", + "CoreReader.Agency.GeneratingSystem.stableAction": "[]", + "CoreReader.Agency.GeneratingSystem.requirementsMet": "[]", + "CoreReader.Agency.GeneratingSystem.withinBudget": "[]", + "CoreReader.Agency.Announcement": "[]", + "CoreReader.Agency.GeneratingSystem.report": "[]", + "CoreReader.Agency.Announcement.claim": "[]", + "CoreReader.Agency.announcementClaimImpliesExpansion": "[]", + "CoreReader.Agency.inflatedAnnouncement": "[]", + "CoreReader.Agency.inflatedAnnouncementRefuted": "[propext, Quot.sound.{u}]", + "CoreReader.Agency.TransitionCase": "[]", + "CoreReader.Agency.extendedState": "[]", + "CoreReader.Agency.transitionBefore": "[]", + "CoreReader.Agency.transitionAfter": "[]", + "CoreReader.Agency.transitionInput": "[]", + "CoreReader.Agency.transitionAnnouncement": "[]", + "CoreReader.Agency.generationLimits": "[propext, Quot.sound.{u}]", + "CoreReader.Agency.generationNotReflexivity": "[propext, Quot.sound.{u}]", + "CoreReader.Agency.ownArithmeticPrinciple": "[]", + "CoreReader.Agency.selfTest": "[]", + "CoreReader.Agency.selfTestDoesNotProve": "[]", + "CoreReader.Choice.StatusKind": "[]", + "CoreReader.Choice.MethodReason": "[]", + "CoreReader.Choice.Reason": "[]", + "CoreReader.Choice.Implementation": "[]", + "CoreReader.Choice.Requirements": "[]", + "CoreReader.Choice.MethodContent": "[]", + "CoreReader.Choice.Relevant": "[]", + "CoreReader.Choice.Feasible": "[]", + "CoreReader.Choice.JustifiedChoice": "[]", + "CoreReader.Choice.statusOnlyFails": "[propext]", + "CoreReader.Choice.identityImpl": "[]", + "CoreReader.Choice.successorImpl": "[]", + "CoreReader.Choice.changedOutsideZero": "[]", + "CoreReader.Choice.identityRequirements": "[]", + "CoreReader.Choice.objectiveReason": "[]", + "CoreReader.Choice.identityOutputReason": "[]", + "CoreReader.Choice.identityFeasible": "[]", + "CoreReader.Choice.identityJustified": "[propext]", + "CoreReader.Choice.conventionWithReason": "[propext]", + "CoreReader.Choice.Candidate": "[]", + "CoreReader.Choice.implementation": "[]", + "CoreReader.Choice.singleFeasible": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Choice.localNotGlobal": "[]", + "CoreReader.Choice.cheapSuccessor": "[]", + "CoreReader.Choice.eligibleInternalReasonNotSufficient": "[]", + "CoreReader.Choice.internalReasons": "[]", + "CoreReader.Choice.openNotEquivalent": "[propext]", + "CoreReader.Choice.priorityClaim": "[]", + "CoreReader.Choice.statusFacts": "[]", + "CoreReader.Choice.statusFactsModel": "[]", + "CoreReader.Choice.priorityArticulation": "[]", + "CoreReader.Choice.AssessmentAccurate": "[]", + "CoreReader.Choice.statusDoesNotEntailPriority": "[]", + "CoreReader.Choice.statusAssessmentNonEntailment": "[propext]", + "CoreReader.Choice.PriorityAssessment": "[]", + "CoreReader.Choice.PriorityAssessment.accurate": "[]", + "CoreReader.Choice.statusPriorityAudit": "[]", + "CoreReader.Choice.ChoicePolicy": "[]", + "CoreReader.Choice.GeneralAssessmentFulfilled": "[]", + "CoreReader.Choice.AdditionalChoiceNorm": "[]", + "CoreReader.Choice.statusPriorityPolicy": "[]", + "CoreReader.Choice.outputPriorityPolicy": "[]", + "CoreReader.Choice.statusPriorityAuditAccurate": "[]", + "CoreReader.Choice.PolicyIndependenceExample": "[]", + "CoreReader.Choice.policyIndependenceExample": "[propext]", + "CoreReader.Choice.generalGroundsNotChoice": "[propext]", + "CoreReader.Engineering.Maintainer": "[]", + "CoreReader.Engineering.Tool": "[]", + "CoreReader.Engineering.Knowledge": "[]", + "CoreReader.Engineering.Change": "[]", + "CoreReader.Engineering.Candidate": "[]", + "CoreReader.Engineering.Burden": "[]", + "CoreReader.Engineering.maintainers": "[]", + "CoreReader.Engineering.changes": "[]", + "CoreReader.Engineering.burdens": "[]", + "CoreReader.Engineering.Activity": "[]", + "CoreReader.Engineering.ActivityScope": "[]", + "CoreReader.Engineering.Continuing": "[]", + "CoreReader.Engineering.BoundedLifecycle": "[]", + "CoreReader.Engineering.continuingActivity": "[propext]", + "CoreReader.Engineering.temporaryActivity": "[propext]", + "CoreReader.Engineering.prototypeActivity": "[propext]", + "CoreReader.Engineering.retiringActivity": "[propext]", + "CoreReader.Engineering.EditStep": "[]", + "CoreReader.Engineering.changePath": "[]", + "CoreReader.Engineering.changeWork": "[]", + "CoreReader.Engineering.CanChange": "[]", + "CoreReader.Engineering.ContinuingCapability": "[]", + "CoreReader.Engineering.registeredDirections": "[]", + "CoreReader.Engineering.supportedDirections": "[]", + "CoreReader.Engineering.MaximumRegisteredCapability": "[]", + "CoreReader.Engineering.passiveArtifact": "[]", + "CoreReader.Engineering.orientation": "[]", + "CoreReader.Engineering.EngineeringAction": "[]", + "CoreReader.Engineering.maintainerActions": "[]", + "CoreReader.Engineering.artifactActions": "[]", + "CoreReader.Engineering.subjectLifecycleCases": "[propext]", + "CoreReader.Engineering.subjectLimits": "[propext]", + "CoreReader.Engineering.CredibleDirection": "[]", + "CoreReader.Engineering.DirectionGround": "[]", + "CoreReader.Engineering.articulateGround": "[]", + "CoreReader.Engineering.supportGround": "[]", + "CoreReader.Engineering.initialGrounds": "[]", + "CoreReader.Engineering.forecastGrounds": "[]", + "CoreReader.Engineering.credible": "[]", + "CoreReader.Engineering.WarrantedAccommodation": "[]", + "CoreReader.Engineering.credibilityCases": "[]", + "CoreReader.Engineering.abstractionComplexity": "[]", + "CoreReader.Engineering.implementedVariants": "[]", + "CoreReader.Engineering.CostVector": "[]", + "CoreReader.Engineering.CostLimits": "[]", + "CoreReader.Engineering.cost": "[]", + "CoreReader.Engineering.normalLimits": "[]", + "CoreReader.Engineering.Requirements": "[]", + "CoreReader.Engineering.normalRequirements": "[]", + "CoreReader.Engineering.behavior": "[]", + "CoreReader.Engineering.CandidateProfile": "[]", + "CoreReader.Engineering.profile": "[]", + "CoreReader.Engineering.Meets": "[]", + "CoreReader.Engineering.Context": "[]", + "CoreReader.Engineering.currentContinuing": "[propext]", + "CoreReader.Engineering.ConcreteThreat": "[]", + "CoreReader.Engineering.HasThreat": "[]", + "CoreReader.Engineering.JustifiedDeparture": "[]", + "CoreReader.Engineering.PriorityConditions": "[]", + "CoreReader.Engineering.EvolutionPriority": "[]", + "CoreReader.Engineering.currentPriorityConditions": "[propext]", + "CoreReader.Engineering.currentNoThreat": "[propext]", + "CoreReader.Engineering.threatened": "[propext]", + "CoreReader.Engineering.priorityWhenApplicable": "[]", + "CoreReader.Engineering.currentSimpleViolates": "[propext]", + "CoreReader.Engineering.withEvolvableProfile": "[propext]", + "CoreReader.Engineering.unmetRequirementsBlockPriority": "[propext, Quot.sound.{u}]", + "CoreReader.Engineering.priorityConditionsCases": "[propext]", + "CoreReader.Engineering.priorityChoices": "[propext]", + "CoreReader.Engineering.credibilityLimits": "[propext]", + "CoreReader.Engineering.costCases": "[propext]", + "CoreReader.Engineering.orderedUnique": "[]", + "CoreReader.Engineering.orderedRefactor": "[]", + "CoreReader.Engineering.insertOrdered": "[]", + "CoreReader.Engineering.sortValues": "[]", + "CoreReader.Engineering.sortedUnique": "[]", + "CoreReader.Engineering.SoftwareState": "[]", + "CoreReader.Engineering.originalSoftware": "[]", + "CoreReader.Engineering.transform": "[]", + "CoreReader.Engineering.evolutionBehavior": "[]", + "CoreReader.Engineering.ObligationTreatment": "[]", + "CoreReader.Engineering.ChangeClaim": "[]", + "CoreReader.Engineering.contractInputs": "[]", + "CoreReader.Engineering.PreservesOn": "[]", + "CoreReader.Engineering.PreservesFinite": "[]", + "CoreReader.Engineering.ObservableContract": "[]", + "CoreReader.Engineering.retry": "[]", + "CoreReader.Engineering.orderContract": "[]", + "CoreReader.Engineering.originalContract": "[]", + "CoreReader.Engineering.refactoredContract": "[]", + "CoreReader.Engineering.revisedContract": "[]", + "CoreReader.Engineering.evolutionContract": "[]", + "CoreReader.Engineering.failureInputs": "[]", + "CoreReader.Engineering.PreservesContractFinite": "[]", + "CoreReader.Engineering.ContractAspect": "[]", + "CoreReader.Engineering.PartyDependency": "[]", + "CoreReader.Engineering.partyDependencies": "[]", + "CoreReader.Engineering.aspectChanged": "[]", + "CoreReader.Engineering.affectedParties": "[]", + "CoreReader.Engineering.ContractRevision": "[]", + "CoreReader.Engineering.normalRevision": "[]", + "CoreReader.Engineering.RevisionDuties": "[]", + "CoreReader.Engineering.ContractChangeAccount": "[]", + "CoreReader.Engineering.EvolutionClaim": "[]", + "CoreReader.Engineering.evolutionKindsCases": "[propext]", + "CoreReader.Engineering.evolutionDimensionsLimits": "[propext]", + "CoreReader.Engineering.oneDimensionDoesNotEntailEveryDimension": "[]", + "CoreReader.Engineering.propagation": "[]", + "CoreReader.Engineering.batchCount": "[]", + "CoreReader.Engineering.staticBatch": "[]", + "CoreReader.Engineering.liveBatch": "[]", + "CoreReader.Engineering.StructuralEvidence": "[]", + "CoreReader.Engineering.structuralEvidence": "[]", + "CoreReader.Engineering.StructuralAccount": "[]", + "CoreReader.Engineering.InterfaceView": "[]", + "CoreReader.Engineering.sameShape": "[]", + "CoreReader.Engineering.moduleAssumptions": "[]", + "CoreReader.Engineering.modulesNeedingRevision": "[]", + "CoreReader.Engineering.Boundary": "[]", + "CoreReader.Engineering.EngineeringDesign": "[]", + "CoreReader.Engineering.privateDesign": "[]", + "CoreReader.Engineering.documentedDesign": "[]", + "CoreReader.Engineering.sortedDesign": "[]", + "CoreReader.Engineering.coordinatedBoundary": "[]", + "CoreReader.Engineering.boundaryDesign": "[]", + "CoreReader.Engineering.crossesBoundary": "[]", + "CoreReader.Engineering.boundaryObligationChecked": "[]", + "CoreReader.Engineering.omittedCallerCheck": "[]", + "CoreReader.Engineering.otherCalleeBoundary": "[]", + "CoreReader.Engineering.otherCalleeDesign": "[]", + "CoreReader.Engineering.actualCrossBoundaryObligation": "[]", + "CoreReader.Engineering.structuralCases": "[propext]", + "CoreReader.Engineering.DesignCanChange": "[]", + "CoreReader.Engineering.designWork": "[]", + "CoreReader.Engineering.designModulesNeedingRevision": "[]", + "CoreReader.Engineering.introduceBoundary": "[]", + "CoreReader.Engineering.wrappedDesign": "[]", + "CoreReader.Engineering.relocateVerification": "[]", + "CoreReader.Engineering.sameWorkDesign": "[]", + "CoreReader.Engineering.structureNotCapability": "[propext]", + "CoreReader.Engineering.contractPreservation": "[]", + "CoreReader.Engineering.changedObservationNotPreserved": "[]", + "CoreReader.Engineering.contractRevisionObligations": "[]", + "CoreReader.Engineering.retiredBehavior": "[]", + "CoreReader.Engineering.contractCases": "[]", + "CoreReader.Engineering.contractDistinctions": "[]", + "CoreReader.Engineering.RevisionState": "[]", + "CoreReader.Engineering.RevisionRecord": "[]", + "CoreReader.Engineering.MaterialGroundsChanged": "[]", + "CoreReader.Engineering.oldState": "[]", + "CoreReader.Engineering.newState": "[]", + "CoreReader.Engineering.HistoricalEvidence": "[]", + "CoreReader.Engineering.observedHistory": "[]", + "CoreReader.Engineering.RevisionAccountAgainst": "[]", + "CoreReader.Engineering.RevisionAccount": "[]", + "CoreReader.Engineering.failedHistoryNotRewritten": "[propext]", + "CoreReader.Engineering.revisionRecord": "[]", + "CoreReader.Engineering.SupportedAlternative": "[]", + "CoreReader.Engineering.RetentionJustified": "[]", + "CoreReader.Engineering.stableRecord": "[]", + "CoreReader.Engineering.revisionCases": "[propext]", + "CoreReader.Engineering.observations": "[]", + "CoreReader.Engineering.revisionsMade": "[]", + "CoreReader.Engineering.agreedBatch": "[]", + "CoreReader.Engineering.rewrittenOldRecord": "[]", + "CoreReader.Engineering.rewrittenPredictionRecord": "[]", + "CoreReader.Engineering.rewrittenObservationRecord": "[]", + "CoreReader.Engineering.unrelatedSoftwareRecord": "[]", + "CoreReader.Engineering.historicalTamperingRejected": "[]", + "CoreReader.Engineering.revisionLimits": "[propext]", + "CoreReader.Engineering.groundedChanges": "[]", + "CoreReader.Engineering.currentRevisionState": "[]", + "CoreReader.Engineering.revisionFor": "[]", + "CoreReader.Engineering.revisionContextIdentity": "[propext]", + "CoreReader.Engineering.DomainSatisfied": "[]", + "CoreReader.Engineering.currentDomainSatisfied": "[propext]", + "CoreReader.Engineering.sharedContext": "[propext]", + "CoreReader.Engineering.maintainedOutput": "[]", + "CoreReader.Engineering.chosenImplementation": "[]", + "CoreReader.Engineering.chosenRequirements": "[propext]", + "CoreReader.Engineering.chosenReasons": "[]", + "CoreReader.Engineering.maintainedOutputCorrect": "[]", + "CoreReader.Engineering.implementationReasoned": "[propext]", + "CoreReader.Engineering.capabilityOutput": "[propext]", + "CoreReader.Engineering.engineeringProcess": "[propext]", + "CoreReader.Engineering.engineeringCapability": "[propext]", + "CoreReader.Engineering.engineeringCapabilityGrounded": "[propext]", + "CoreReader.Engineering.actualCapabilityContrast": "[propext]", + "CoreReader.Engineering.presentBudgetRecord": "[]", + "CoreReader.Engineering.presentBudgetClaim": "[]", + "CoreReader.Engineering.budgetObservationMeaning": "[propext]", + "CoreReader.Engineering.budgetEmpiricalFacet": "[]", + "CoreReader.Engineering.budgetEmpiricalDischarged": "[propext]", + "CoreReader.Engineering.capacityClaim": "[propext]", + "CoreReader.Engineering.capacityAssumptions": "[]", + "CoreReader.Engineering.budgetInferentialFacet": "[propext]", + "CoreReader.Engineering.budgetInferentialDischarged": "[propext]", + "CoreReader.Engineering.budgetScopeAccount": "[]", + "CoreReader.Engineering.budgetScopeExplained": "[]", + "CoreReader.Engineering.budgetObservationLimit": "[propext]", + "CoreReader.Engineering.engineeringPolicy": "[]", + "CoreReader.Engineering.engineeringGenerative": "[]", + "CoreReader.Engineering.OwnFact": "[]", + "CoreReader.Engineering.ownFactClaim": "[propext]", + "CoreReader.Engineering.actualOwnFact": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Engineering.ownFactPremises": "[]", + "CoreReader.Engineering.actualOwnFactGrounded": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Engineering.priorityValueMeaning": "[propext]", + "CoreReader.Engineering.priorityGrounds": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Engineering.OwnNorm": "[]", + "CoreReader.Engineering.normApplies": "[propext]", + "CoreReader.Engineering.ownNormClaim": "[propext]", + "CoreReader.Engineering.actualOwnNorm": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Engineering.ownFactTheory": "[propext]", + "CoreReader.Engineering.ownNormTheory": "[propext]", + "CoreReader.Engineering.ownTheory": "[propext]", + "CoreReader.Engineering.allNormativeContentHeld": "[propext]", + "CoreReader.Engineering.nonemptyOwnObjects": "[propext]", + "CoreReader.Engineering.comparisonContext": "[propext]", + "CoreReader.Engineering.engineeringSnapshot": "[propext]", + "CoreReader.Engineering.currentAdmissible": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Engineering.currentConsistency": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Engineering.wholeClaimGrounded": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Engineering.incompatibleNormTheory": "[]", + "CoreReader.Engineering.incompatibleNormContext": "[]", + "CoreReader.Engineering.normativeContentVariation": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Engineering.Inherited": "[propext]", + "CoreReader.Engineering.inheritedCurrent": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Engineering.inheritedMutualApplication": "[propext]", + "CoreReader.Engineering.inheritedMutualCases": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Engineering.priorityRemainsReflexive": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Engineering.priorityReflexiveCases": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Engineering.jointWitness": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Engineering.inheritedDoesNotEntailPriority": "[propext,\n Classical.choice.{u},\n Quot.sound.{u}]", + "CoreReader.Engineering.Reflection.Target": "[]", + "CoreReader.Engineering.Reflection.Contract": "[]", + "CoreReader.Engineering.Reflection.Input": "[]", + "CoreReader.Engineering.Reflection.Verdict": "[]", + "CoreReader.Engineering.Reflection.Outcome": "[]", + "CoreReader.Engineering.Reflection.evaluate": "[]", + "CoreReader.Engineering.Reflection.generate": "[]", + "CoreReader.Engineering.Reflection.interpret": "[]", + "CoreReader.Engineering.Reflection.Model": "[]", + "CoreReader.Engineering.Reflection.Model.input": "[]", + "CoreReader.Engineering.Reflection.Model.self": "[]", + "CoreReader.Engineering.Reflection.Model.rule": "[]", + "CoreReader.Engineering.Reflection.Model.rules": "[]", + "CoreReader.Engineering.Reflection.Model.performed": "[]", + "CoreReader.Engineering.Reflection.Model.follows": "[]", + "CoreReader.Engineering.Reflection.recordedReflexivity": "[propext]", + "CoreReader.Engineering.ReviewObject": "[]", + "CoreReader.Engineering.ReviewCase": "[]", + "CoreReader.Engineering.generationApplies": "[]", + "CoreReader.Engineering.assessmentApplies": "[]", + "CoreReader.Engineering.ruleObject": "[]", + "CoreReader.Engineering.ruleProbe": "[]", + "CoreReader.Engineering.generationRuleTest": "[]", + "CoreReader.Engineering.assessmentRuleTest": "[]", + "CoreReader.Engineering.sampleAwareAssessment": "[]", + "CoreReader.Engineering.objectTest": "[propext]", + "CoreReader.Engineering.reviewObjects": "[]", + "CoreReader.Engineering.requestedCases": "[]", + "CoreReader.Engineering.reviewReasons": "[]", + "CoreReader.Engineering.statedReview": "[propext]", + "CoreReader.Engineering.reviewBasis": "[propext]", + "CoreReader.Engineering.selfModel": "[propext]", + "CoreReader.Engineering.reviewIdentity": "[propext]", + "CoreReader.Engineering.currentSelfRecords": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Engineering.currentSelfApplication": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Engineering.actualSelfCriticism": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Engineering.ownRuleIdentity": "[propext, Quot.sound.{u}]", + "CoreReader.Engineering.ownRuleContentVariation": "[propext]", + "CoreReader.Engineering.proposedRuleRevision": "[propext, Quot.sound.{u}]", + "CoreReader.Engineering.CoreCommitment": "[]", + "CoreReader.Engineering.coreCommitments": "[]", + "CoreReader.Engineering.coreAdopted": "[]", + "CoreReader.Engineering.AdoptionReason": "[]", + "CoreReader.Engineering.reasonFor": "[]", + "CoreReader.Engineering.ReasonRelevant": "[propext]", + "CoreReader.Engineering.valueScope": "[]", + "CoreReader.Engineering.safeguardExperiment": "[propext]", + "CoreReader.Engineering.criticismFor": "[]", + "CoreReader.Engineering.governancePosition": "[propext]", + "CoreReader.Engineering.adoptionReasonRelevant": "[propext]", + "CoreReader.Engineering.safeguardEnabled": "[propext]", + "CoreReader.Engineering.safeguardDisabled": "[propext]", + "CoreReader.Engineering.governanceValueProcedure": "[propext]", + "CoreReader.Engineering.governanceGrounded": "[propext]", + "CoreReader.Engineering.governanceRationaleLimits": "[propext]", + "CoreReader.Engineering.selectionObjective": "[]", + "CoreReader.Engineering.selectionPosition": "[propext]", + "CoreReader.Engineering.selectionValueProcedure": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Engineering.selectionGrounded": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Evidence.Record": "[]", + "CoreReader.Evidence.Compatible": "[]", + "CoreReader.Evidence.Supports": "[]", + "CoreReader.Evidence.Articulation": "[]", + "CoreReader.Evidence.Articulated": "[]", + "CoreReader.Evidence.ValuePosition": "[]", + "CoreReader.Evidence.ValuePosition.commitment": "[]", + "CoreReader.Evidence.ValuePosition.consequence": "[]", + "CoreReader.Evidence.ValuePosition.activeReasons": "[]", + "CoreReader.Evidence.JointAdoption": "[]", + "CoreReader.Evidence.ValueProcedure": "[]", + "CoreReader.Evidence.Facet": "[]", + "CoreReader.Evidence.Facet.claim": "[]", + "CoreReader.Evidence.FacetDischarged": "[]", + "CoreReader.Evidence.FacetArticulated": "[]", + "CoreReader.Evidence.canonicalArticulation": "[]", + "CoreReader.Evidence.canonicalFacetArticulated": "[]", + "CoreReader.Evidence.canonicalArticulated": "[propext]", + "CoreReader.Evidence.Grounds": "[]", + "CoreReader.Evidence.AchievementAccountability": "[]", + "CoreReader.Evidence.transitionAchievement": "[]", + "CoreReader.Evidence.transitionPerformanceRecord": "[]", + "CoreReader.Evidence.transitionReportRecord": "[]", + "CoreReader.Evidence.transitionPerformanceCompatible": "[propext]", + "CoreReader.Evidence.transitionSupported": "[propext]", + "CoreReader.Evidence.transitionFacet": "[]", + "CoreReader.Evidence.transitionFacetDischarged": "[propext]", + "CoreReader.Evidence.transitionAccountable": "[propext]", + "CoreReader.Evidence.transitionReportCompatible": "[propext]", + "CoreReader.Evidence.transitionReportDoesNotSupport": "[propext, Quot.sound.{u}]", + "CoreReader.Evidence.ConcreteAchievementExample": "[]", + "CoreReader.Evidence.concreteAchievementExample": "[propext, Quot.sound.{u}]", + "CoreReader.Evidence.achievementNeedsSupport": "[propext, Quot.sound.{u}]", + "CoreReader.Evidence.supportWeakening": "[]", + "CoreReader.Evidence.evidenceWeakeningCanLoseSupport": "[propext]", + "CoreReader.Evidence.scopeRestriction": "[]", + "CoreReader.Evidence.Duties": "[]", + "CoreReader.Evidence.LabeledDuties": "[]", + "CoreReader.Evidence.assessmentUnion": "[]", + "CoreReader.Evidence.labelsCannotWaive": "[]", + "CoreReader.Evidence.switchRecord": "[]", + "CoreReader.Evidence.switchCompatible": "[propext]", + "CoreReader.Evidence.switchSupported": "[propext]", + "CoreReader.Evidence.optionBenefit": "[]", + "CoreReader.Evidence.optionCost": "[]", + "CoreReader.Evidence.optionReport": "[]", + "CoreReader.Evidence.switchPosition": "[]", + "CoreReader.Evidence.switchValueProcedure": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Evidence.oppositePosition": "[]", + "CoreReader.Evidence.oppositePositionRejected": "[propext]", + "CoreReader.Evidence.contradictoryStartingPosition": "[]", + "CoreReader.Evidence.impossibleAdoptionPosition": "[]", + "CoreReader.Evidence.inadmissibleValuePositionsRejected": "[]", + "CoreReader.Evidence.unsupportedPosition": "[]", + "CoreReader.Evidence.switchEmpirical": "[]", + "CoreReader.Evidence.switchEmpiricalDischarged": "[propext]", + "CoreReader.Evidence.mixedMissingResponsibility": "[propext]", + "CoreReader.Evidence.uninformativeArgument": "[]", + "CoreReader.Evidence.articulationNotSupport": "[propext]", + "CoreReader.Evidence.unrelatedArticulationRejected": "[propext]", + "CoreReader.Evidence.temperatureRecord": "[]", + "CoreReader.Evidence.temperatureCompatible": "[propext]", + "CoreReader.Evidence.BudgetWorld": "[]", + "CoreReader.Evidence.announcement": "[]", + "CoreReader.Evidence.announcementPosition": "[]", + "CoreReader.Evidence.announcementHasJointAdoption": "[propext]", + "CoreReader.Evidence.announcementNotBudgetReason": "[propext]", + "CoreReader.Evidence.actionRecord": "[]", + "CoreReader.Evidence.actionCompatible": "[propext]", + "CoreReader.Evidence.measurementRepeatNotSupport": "[propext]", + "CoreReader.Evidence.selfAssertionNotReason": "[propext]", + "CoreReader.Evidence.valueWithoutSelfProof": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Evidence.BenefitCostWorld": "[]", + "CoreReader.Evidence.measuredOutcome": "[]", + "CoreReader.Evidence.benefitReason": "[]", + "CoreReader.Evidence.costReason": "[]", + "CoreReader.Evidence.jointReasonPosition": "[]", + "CoreReader.Evidence.jointReasonProcedure": "[propext]", + "CoreReader.Evidence.JointReasonsExample": "[]", + "CoreReader.Evidence.jointReasonsExample": "[propext, Quot.sound.{u}]", + "CoreReader.Evidence.heterogeneousReasons": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Evidence.zeroRecord": "[]", + "CoreReader.Evidence.localGenerator": "[]", + "CoreReader.Evidence.allTrue": "[]", + "CoreReader.Evidence.zeroCompatible": "[propext]", + "CoreReader.Evidence.GeneratingProcess": "[]", + "CoreReader.Evidence.GeneratingProcess.outputRevision": "[]", + "CoreReader.Evidence.ProducedRevision": "[]", + "CoreReader.Evidence.GeneratingProcess.produce": "[]", + "CoreReader.Evidence.sampleGeneratingProcess": "[]", + "CoreReader.Evidence.OwnedRevisionExample": "[]", + "CoreReader.Evidence.ownedRevisionExample": "[propext]", + "CoreReader.Evidence.selfOriginDoesNotSupport": "[propext]", + "CoreReader.Evidence.localNotUniversal": "[propext]", + "CoreReader.Evidence.hiddenDifference": "[]", + "CoreReader.Evidence.singleObservation": "[propext]", + "CoreReader.Evidence.arithmeticFacet": "[]", + "CoreReader.Evidence.usesObservation": "[propext]", + "CoreReader.Evidence.noUniversalChain": "[propext]", + "CoreReader.Evidence.Trial": "[]", + "CoreReader.Evidence.Verified": "[]", + "CoreReader.Evidence.Reproduced": "[]", + "CoreReader.Evidence.Bounded": "[]", + "CoreReader.Evidence.variableOutcomesStableBound": "[propext, Quot.sound.{u}]", + "CoreReader.Evidence.verificationReproductionStability": "[propext, Quot.sound.{u}]", + "CoreReader.Evidence.Program": "[]", + "CoreReader.Evidence.Program.eval": "[]", + "CoreReader.Evidence.Process": "[]", + "CoreReader.Evidence.OutputContract": "[]", + "CoreReader.Evidence.ExplanationContract": "[]", + "CoreReader.Evidence.outputOnlyProcess": "[]", + "CoreReader.Evidence.explainedProcess": "[]", + "CoreReader.Evidence.processScope": "[]", + "CoreReader.Evidence.processContractFacet": "[]", + "CoreReader.Evidence.processScopeModels": "[]", + "CoreReader.Evidence.processContractDischarged": "[]", + "CoreReader.Evidence.ProcessGrounds": "[]", + "CoreReader.Evidence.processGrounds": "[propext]", + "CoreReader.Evidence.outputCorrectByEvaluation": "[]", + "CoreReader.Evidence.outputOnlyNoExplanation": "[]", + "CoreReader.Evidence.FullProcessContract": "[]", + "CoreReader.Evidence.OutputContractEvidence": "[]", + "CoreReader.Evidence.outputContractEvidence": "[propext]", + "CoreReader.Evidence.ScopedApplicationEvidence": "[]", + "CoreReader.Evidence.scopedApplicationEvidence": "[propext]", + "CoreReader.Evidence.outputNotExplanation": "[propext]", + "CoreReader.Evidence.applicationContractsDiffer": "[propext]", + "CoreReader.Evidence.ExternalCertificate": "[]", + "CoreReader.Evidence.externalOutputCertificate": "[]", + "CoreReader.Evidence.externalAssessment": "[propext]", + "CoreReader.Evidence.arithmeticArticulation": "[]", + "CoreReader.Evidence.nonExecutableAssessment": "[propext]", + "CoreReader.Integration.canonicalGrounds": "[propext]", + "CoreReader.Integration.canonicalGroundsForSingleton": "[propext]", + "CoreReader.Integration.Mode": "[]", + "CoreReader.Integration.World": "[]", + "CoreReader.Integration.actual": "[]", + "CoreReader.Integration.Method": "[]", + "CoreReader.Integration.System": "[]", + "CoreReader.Integration.policyFor": "[]", + "CoreReader.Integration.workFor": "[propext]", + "CoreReader.Integration.System.policy": "[]", + "CoreReader.Integration.System.rules": "[propext]", + "CoreReader.Integration.System.work": "[propext]", + "CoreReader.Integration.actualSystem": "[]", + "CoreReader.Integration.systemCapability": "[]", + "CoreReader.Integration.systemBudget": "[]", + "CoreReader.Integration.systemObservation": "[]", + "CoreReader.Integration.systemHeld": "[]", + "CoreReader.Integration.Question": "[]", + "CoreReader.Integration.systemContext": "[]", + "CoreReader.Integration.capability": "[]", + "CoreReader.Integration.observation": "[]", + "CoreReader.Integration.held": "[]", + "CoreReader.Integration.context": "[]", + "CoreReader.Integration.observationIdentifies": "[propext, Quot.sound.{u}]", + "CoreReader.Integration.capabilityActual": "[]", + "CoreReader.Integration.observedCapability": "[propext, Quot.sound.{u}]", + "CoreReader.Integration.capabilityFacet": "[]", + "CoreReader.Integration.capabilityFacetChecked": "[propext, Quot.sound.{u}]", + "CoreReader.Integration.capabilityGrounds": "[propext, Quot.sound.{u}]", + "CoreReader.Integration.actualAdmissible": "[propext, Quot.sound.{u}]", + "CoreReader.Integration.jointConsistent": "[propext, Quot.sound.{u}]", + "CoreReader.Integration.Charter": "[propext]", + "CoreReader.Integration.charterChecked": "[propext, Quot.sound.{u}]", + "CoreReader.Integration.revisedHeld": "[]", + "CoreReader.Integration.initialSnapshot": "[]", + "CoreReader.Integration.revisedSnapshot": "[]", + "CoreReader.Integration.revisionKeepsConsistency": "[propext, Quot.sound.{u}]", + "CoreReader.Integration.OwnCapabilityDuty": "[propext]", + "CoreReader.Integration.ownCapabilityGrounded": "[propext, Quot.sound.{u}]", + "CoreReader.Integration.costAllowanceRecord": "[]", + "CoreReader.Integration.unsupportedCapabilityFacet": "[]", + "CoreReader.Integration.costCompatibleWithFailure": "[propext]", + "CoreReader.Integration.costDoesNotSupportOutput": "[propext]", + "CoreReader.Integration.unsupportedGrounds": "[propext]", + "CoreReader.Integration.Commitment": "[]", + "CoreReader.Integration.groundsPermission": "[]", + "CoreReader.Integration.GroundsProvision": "[]", + "CoreReader.Integration.groundsProvisionMeaning": "[propext]", + "CoreReader.Integration.consistencyPermission": "[]", + "CoreReader.Integration.conflictingHeld": "[]", + "CoreReader.Integration.conflictConsequences": "[]", + "CoreReader.Integration.conflictingHeldInconsistent": "[]", + "CoreReader.Integration.choicePermission": "[]", + "CoreReader.Integration.proposedOperation": "[]", + "CoreReader.Integration.selfSamples": "[]", + "CoreReader.Integration.conflictDecision": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Integration.groundsDecision": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Integration.choiceDecision": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Integration.decisionsApply": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Integration.decisionsWaive": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Integration.commitmentPositionFor": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Integration.commitmentPosition": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Integration.positionReasons": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Integration.positionConsequence": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Integration.positionProcedure": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Integration.criticismWithinScope": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Integration.oppositeConsequenceFails": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Integration.oppositeProcedureRejected": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Integration.commitmentClaim": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Integration.commitmentFacet": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Integration.reasonsBelongToCommitments": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Integration.groundsCommitmentIsProvision": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Integration.groundsSelfAssessment": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Integration.PhilosophyMethod": "[]", + "CoreReader.Integration.currentPhilosophy": "[]", + "CoreReader.Integration.PhilosophyMethod.review": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Integration.PhilosophyMethod.implementation": "[propext,\n Classical.choice.{u},\n Quot.sound.{u}]", + "CoreReader.Integration.proposalRequirements": "[]", + "CoreReader.Integration.currentReviewCorrect": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Integration.existingPhilosophyNotPrivileged": "[propext,\n Classical.choice.{u},\n Quot.sound.{u}]", + "CoreReader.Integration.applicationClaim": "[]", + "CoreReader.Integration.ApplicationDuties": "[propext]", + "CoreReader.Integration.applicationRetainsDuties": "[propext]", + "CoreReader.Integration.outputContract": "[]", + "CoreReader.Integration.successorRequirements": "[]", + "CoreReader.Integration.changedObjectiveFacet": "[]", + "CoreReader.Integration.applicationVariation": "[propext, Quot.sound.{u}]", + "CoreReader.Integration.charterNotGrounds": "[propext, Quot.sound.{u}]", + "CoreReader.Integration.jointWitness": "[propext, Classical.choice.{u}, Quot.sound.{u}]", + "CoreReader.Logic.Claim": "[]", + "CoreReader.Logic.Theory": "[]", + "CoreReader.Logic.Models": "[]", + "CoreReader.Logic.Entails": "[]", + "CoreReader.Logic.Satisfiable": "[]", + "CoreReader.Logic.Context": "[]", + "CoreReader.Logic.Admissible": "[]", + "CoreReader.Logic.Consequence": "[]", + "CoreReader.Logic.Consistent": "[]", + "CoreReader.Logic.consequenceConsistency": "[]", + "CoreReader.Logic.emptyTheory": "[]", + "CoreReader.Logic.singleton": "[]", + "CoreReader.Logic.union": "[]", + "CoreReader.Logic.modelsSingleton": "[]", + "CoreReader.Logic.modelsUnion": "[]", + "CoreReader.Logic.premiseP": "[]", + "CoreReader.Logic.premiseRule": "[]", + "CoreReader.Logic.premiseNotQ": "[]", + "CoreReader.Logic.jointTheory": "[]", + "CoreReader.Logic.jointConflict": "[]", + "CoreReader.Logic.revisionSlice": "[]", + "CoreReader.Logic.revisionCanReverse": "[]", + "CoreReader.Logic.onQuestion": "[]", + "CoreReader.Logic.assumptionContext": "[]", + "CoreReader.Logic.meaningContext": "[]", + "CoreReader.Logic.scopeContext": "[]", + "CoreReader.Logic.contextDifferences": "[]", + "CoreReader.Logic.Snapshot": "[]", + "CoreReader.Logic.SameContent": "[]", + "CoreReader.Logic.TruthfulReport": "[]", + "CoreReader.Logic.semanticChangeMustBeReported": "[]", + "CoreReader.Logic.representationOrderIrrelevant": "[]", + "CoreReader.Logic.contextSnapshot": "[]", + "CoreReader.Logic.hiddenContextChangeRejected": "[]", + "CoreReader.Logic.tensionWithoutContradiction": "[]", + "CoreReader.Logic.conflictRequiresChange": "[]", + "CoreReader.Logic.consistentFalse": "[]", + "CoreReader.Logic.consistentIncomplete": "[]", + "CoreReader.Logic.compatibilityNotEntailment": "[]", + "CoreReader.Agency.Phase": "[]", + "CoreReader.Agency.PrincipleKey": "[]", + "CoreReader.Agency.Subject": "[]", + "CoreReader.Agency.Subject.owner": "[]", + "CoreReader.Agency.Activity": "[]", + "CoreReader.Agency.QuestionKind": "[]", + "CoreReader.Agency.SampleProgram": "[]", + "CoreReader.Agency.SampleProgram.run": "[]", + "CoreReader.Agency.MethodDraft": "[]", + "CoreReader.Agency.MethodDraft.accepts": "[]", + "CoreReader.Agency.Inquiry": "[]", + "CoreReader.Agency.ReasonContent": "[]", + "CoreReader.Agency.ReasonContent.identifier": "[]", + "CoreReader.Agency.ReasonObject": "[]", + "CoreReader.Agency.AssessmentResult": "[]", + "CoreReader.Agency.WorkOutcome": "[]", + "CoreReader.Agency.Principle": "[]", + "CoreReader.Agency.WorkRecord": "[]", + "CoreReader.Agency.RegistryCoherent": "[]", + "CoreReader.Agency.TargetResolved": "[]", + "CoreReader.Agency.TargetContentResolved": "[]", + "CoreReader.Agency.Performed": "[]", + "CoreReader.Agency.ReflexiveScope": "[]", + "CoreReader.Agency.ValidApplication": "[]", + "CoreReader.Agency.Reflexive": "[]", + "CoreReader.Agency.Reflexive.toScope": "[]", + "CoreReader.Agency.noSelfExemption": "[]", + "CoreReader.Agency.localMethod": "[]", + "CoreReader.Agency.inquiryFor": "[propext]", + "CoreReader.Agency.sourceReasonContents": "[]", + "CoreReader.Agency.reasonsFor": "[propext]", + "CoreReader.Agency.assessInquiry": "[propext]", + "CoreReader.Agency.finiteMethodResult": "[propext]", + "CoreReader.Agency.finiteMethodMeaning": "[propext]", + "CoreReader.Agency.ownSubjects": "[]", + "CoreReader.Agency.generationEligible": "[propext]", + "CoreReader.Agency.generatingRule": "[propext]", + "CoreReader.Agency.assessingRule": "[propext]", + "CoreReader.Agency.ownRules": "[propext]", + "CoreReader.Agency.statedOutcome": "[propext]", + "CoreReader.Agency.recordFor": "[propext]", + "CoreReader.Agency.reasonsFor_nonempty": "[propext]", + "CoreReader.Agency.reasonsFor_target": "[propext, Quot.sound.{u}]", + "CoreReader.Agency.inquiryFor_target": "[propext]", + "CoreReader.Agency.ownContentEvaluates": "[propext]", + "CoreReader.Agency.ownRegistryCoherent": "[propext]", + "CoreReader.Agency.ownTargetResolved": "[propext, Quot.sound.{u}]", + "CoreReader.Agency.ownTargetContent": "[propext, Quot.sound.{u}]", + "CoreReader.Agency.ownRecordValid": "[propext, Quot.sound.{u}]", + "CoreReader.Agency.completeOwnWork": "[propext]", + "CoreReader.Agency.assessingRecord_member": "[propext, Quot.sound.{u}]", + "CoreReader.Agency.generatingRecord_member": "[propext, Quot.sound.{u}]", + "CoreReader.Agency.completeOwnWork_reflexive": "[propext, Quot.sound.{u}]", + "CoreReader.Agency.ownAssessmentPerformed": "[propext, Quot.sound.{u}]", + "CoreReader.Agency.applicationRule": "[propext]", + "CoreReader.Agency.applicationWork": "[propext]", + "CoreReader.Agency.applicationWork_reflexive": "[propext, Quot.sound.{u}]", + "CoreReader.Agency.applicabilityRetained": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/r3-build.log b/SoftwareEngineering/lean/philosophy/reviews/r3-build.log new file mode 100644 index 0000000..1fb6c36 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/r3-build.log @@ -0,0 +1,16 @@ +✔ [2/15] Built CoreReader.Logic (238ms) +✔ [3/15] Built CoreReader.Reflexivity (653ms) +✔ [4/15] Built CoreReader.Agency (471ms) +✔ [5/15] Built CoreReader.Engineering.Domain (1.3s) +✔ [6/15] Built CoreReader.Evidence (458ms) +✔ [7/15] Built CoreReader.Choice (317ms) +✔ [8/15] Built CoreReader.Integration (481ms) +✔ [9/15] Built CoreReader.Adopted (567ms) +✔ [10/15] Built CoreReader.Engineering.Reflection (336ms) +✔ [11/15] Built CoreReader.Engineering.Values (444ms) +✔ [12/15] Built CoreReader.Engineering.SelfApplication (2.9s) +✔ [13/15] Built CoreReader.Engineering.Integration (482ms) +✔ [14/15] Built CoreReader (214ms) +Build completed successfully (15 jobs). + +exit_code=0 diff --git a/SoftwareEngineering/lean/philosophy/reviews/r3-declarations.json b/SoftwareEngineering/lean/philosophy/reviews/r3-declarations.json new file mode 100644 index 0000000..ffb7606 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/r3-declarations.json @@ -0,0 +1,4988 @@ +[ + { + "file": "CoreReader/Adopted.lean", + "line": 11, + "kind": "inductive", + "name": "CoreReader.Adopted.AssessmentTask" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 16, + "kind": "def", + "name": "CoreReader.Adopted.taskOfFacet" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 27, + "kind": "def", + "name": "CoreReader.Adopted.NatureAppropriate" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 38, + "kind": "theorem", + "name": "CoreReader.Adopted.taskOfFacetAppropriate" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 54, + "kind": "def", + "name": "CoreReader.Adopted.Grounds012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 64, + "kind": "theorem", + "name": "CoreReader.Adopted.grounds012Singleton" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 80, + "kind": "def", + "name": "CoreReader.Adopted.generationSpecification" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 90, + "kind": "def", + "name": "CoreReader.Adopted.consistencySpecification" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 97, + "kind": "structure", + "name": "CoreReader.Adopted.ReflexiveRule" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 110, + "kind": "def", + "name": "CoreReader.Adopted.reflexivitySpecification" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 117, + "kind": "def", + "name": "CoreReader.Adopted.legacyRule" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 121, + "kind": "def", + "name": "CoreReader.Adopted.legacyPerformed" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 127, + "kind": "theorem", + "name": "CoreReader.Adopted.legacyReflexivity" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 152, + "kind": "def", + "name": "CoreReader.Adopted.empiricalSpecification" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 161, + "kind": "def", + "name": "CoreReader.Adopted.inferentialSpecification" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 168, + "kind": "def", + "name": "CoreReader.Adopted.valueSpecification" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 174, + "kind": "inductive", + "name": "CoreReader.Adopted.AssessmentMethod" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 176, + "kind": "structure", + "name": "CoreReader.Adopted.ScopeAccount" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 191, + "kind": "def", + "name": "CoreReader.Adopted.scopeSpecification" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 205, + "kind": "def", + "name": "CoreReader.Adopted.capabilitySpecification" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 215, + "kind": "def", + "name": "CoreReader.Adopted.choiceSpecification" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 220, + "kind": "def", + "name": "CoreReader.Adopted.collaborativeRevision" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 223, + "kind": "theorem", + "name": "CoreReader.Adopted.collaborativeProgress" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 241, + "kind": "theorem", + "name": "CoreReader.Adopted.consistencyConsequences" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 245, + "kind": "def", + "name": "CoreReader.Adopted.broadBoolContext" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 247, + "kind": "theorem", + "name": "CoreReader.Adopted.sliceConsistency" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 262, + "kind": "theorem", + "name": "CoreReader.Adopted.explicitlyConsistentLimits" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 275, + "kind": "def", + "name": "CoreReader.Adopted.localFacet012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 277, + "kind": "def", + "name": "CoreReader.Adopted.globalFacet012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 279, + "kind": "def", + "name": "CoreReader.Adopted.strongFacet012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 282, + "kind": "theorem", + "name": "CoreReader.Adopted.localFacetChecked012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 286, + "kind": "theorem", + "name": "CoreReader.Adopted.scopeStrength012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 304, + "kind": "def", + "name": "CoreReader.Adopted.uncertainFacet012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 308, + "kind": "theorem", + "name": "CoreReader.Adopted.uncertainSupported012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 320, + "kind": "def", + "name": "CoreReader.Adopted.InferenceExamined" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 323, + "kind": "theorem", + "name": "CoreReader.Adopted.inferenceChecked012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 334, + "kind": "def", + "name": "CoreReader.Adopted.closedPosition012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 336, + "kind": "theorem", + "name": "CoreReader.Adopted.closedCriticism012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 341, + "kind": "theorem", + "name": "CoreReader.Adopted.valueFulfilled012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 346, + "kind": "def", + "name": "CoreReader.Adopted.ClaimNoStronger" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 348, + "kind": "theorem", + "name": "CoreReader.Adopted.qualitativeProportionality012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 357, + "kind": "def", + "name": "CoreReader.Adopted.scopeRole012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 362, + "kind": "def", + "name": "CoreReader.Adopted.scopeRoleContent012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 367, + "kind": "def", + "name": "CoreReader.Adopted.localScopeAccount012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 379, + "kind": "theorem", + "name": "CoreReader.Adopted.scopeFulfilled012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 391, + "kind": "theorem", + "name": "CoreReader.Adopted.capabilityFulfilled012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 407, + "kind": "structure", + "name": "CoreReader.Adopted.MechanismApplication012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 411, + "kind": "def", + "name": "CoreReader.Adopted.mechanism012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 413, + "kind": "def", + "name": "CoreReader.Adopted.UnderstandingApplication012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 418, + "kind": "def", + "name": "CoreReader.Adopted.explainedWithoutVariation012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 421, + "kind": "def", + "name": "CoreReader.Adopted.mechanismResponder012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 426, + "kind": "def", + "name": "CoreReader.Adopted.understandingScope012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 429, + "kind": "def", + "name": "CoreReader.Adopted.understandingTask012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 432, + "kind": "def", + "name": "CoreReader.Adopted.understandingFacet012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 435, + "kind": "theorem", + "name": "CoreReader.Adopted.mechanismResponderUnderstands012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 440, + "kind": "theorem", + "name": "CoreReader.Adopted.explainedWithoutVariationFails012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 447, + "kind": "theorem", + "name": "CoreReader.Adopted.understandingApplicationCases012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 471, + "kind": "def", + "name": "CoreReader.Adopted.OwnCapability012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 474, + "kind": "theorem", + "name": "CoreReader.Adopted.ownCapability012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 480, + "kind": "def", + "name": "CoreReader.Adopted.CompleteCharter012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 491, + "kind": "theorem", + "name": "CoreReader.Adopted.completeCharter012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 499, + "kind": "theorem", + "name": "CoreReader.Adopted.charterWithoutGrounds012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 519, + "kind": "def", + "name": "CoreReader.Adopted.groundsPermission012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 523, + "kind": "def", + "name": "CoreReader.Adopted.GroundsProvision012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 527, + "kind": "theorem", + "name": "CoreReader.Adopted.groundsProvision012Meaning" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 539, + "kind": "def", + "name": "CoreReader.Adopted.groundsExperimentTask012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 542, + "kind": "def", + "name": "CoreReader.Adopted.groundsExperiment012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 546, + "kind": "def", + "name": "CoreReader.Adopted.groundsPosition012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 560, + "kind": "theorem", + "name": "CoreReader.Adopted.groundsPosition012Checked" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 579, + "kind": "theorem", + "name": "CoreReader.Adopted.groundsRationaleExperiment012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 595, + "kind": "theorem", + "name": "CoreReader.Adopted.groundsOnGrounds012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 605, + "kind": "theorem", + "name": "CoreReader.Adopted.reflexiveTargets012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 620, + "kind": "theorem", + "name": "CoreReader.Adopted.achievementSupported012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 630, + "kind": "theorem", + "name": "CoreReader.Adopted.semanticOrder012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 634, + "kind": "def", + "name": "CoreReader.Adopted.clearFalseArgument012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 637, + "kind": "theorem", + "name": "CoreReader.Adopted.clearFalseReason012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 641, + "kind": "def", + "name": "CoreReader.Adopted.valueNeutralRecord012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 643, + "kind": "theorem", + "name": "CoreReader.Adopted.valueNotFact012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 655, + "kind": "def", + "name": "CoreReader.Adopted.wrongExplanation012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 657, + "kind": "theorem", + "name": "CoreReader.Adopted.internalReasonDistinguishes012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 667, + "kind": "theorem", + "name": "CoreReader.Adopted.inventoryCases012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 674, + "kind": "def", + "name": "CoreReader.Adopted.selfExemptRule012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 677, + "kind": "def", + "name": "CoreReader.Adopted.selfExemptPerformed012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 680, + "kind": "theorem", + "name": "CoreReader.Adopted.openSelfExempt012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 690, + "kind": "theorem", + "name": "CoreReader.Adopted.ownPhilosophyStatus012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 700, + "kind": "def", + "name": "CoreReader.Adopted.jointContext012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 703, + "kind": "theorem", + "name": "CoreReader.Adopted.jointImplicationConflict012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 715, + "kind": "def", + "name": "CoreReader.Adopted.tensionContext012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 718, + "kind": "theorem", + "name": "CoreReader.Adopted.tensionConsistent012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 724, + "kind": "theorem", + "name": "CoreReader.Adopted.qualitativeUnmeasured012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 733, + "kind": "theorem", + "name": "CoreReader.Adopted.allStatusOnly012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 740, + "kind": "def", + "name": "CoreReader.Adopted.drawWeight012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 741, + "kind": "def", + "name": "CoreReader.Adopted.randomTrial012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 744, + "kind": "theorem", + "name": "CoreReader.Adopted.randomOutcomes012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 756, + "kind": "def", + "name": "CoreReader.Adopted.originalGlobalTask012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 758, + "kind": "def", + "name": "CoreReader.Adopted.originalLocalTask012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 761, + "kind": "def", + "name": "CoreReader.Adopted.circularGlobalFacet012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 763, + "kind": "theorem", + "name": "CoreReader.Adopted.circularGlobalConditional012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 768, + "kind": "theorem", + "name": "CoreReader.Adopted.circularSubstitutionRejected012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 784, + "kind": "def", + "name": "CoreReader.Adopted.observedPremises012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 785, + "kind": "def", + "name": "CoreReader.Adopted.observedInferenceFacet012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 788, + "kind": "theorem", + "name": "CoreReader.Adopted.observedInferenceChecked012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 793, + "kind": "theorem", + "name": "CoreReader.Adopted.sameEmpiricalTaskTwoMethods012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 805, + "kind": "def", + "name": "CoreReader.Adopted.originalUncertaintyTask012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 808, + "kind": "def", + "name": "CoreReader.Adopted.uncertaintyBypassFacet012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 812, + "kind": "theorem", + "name": "CoreReader.Adopted.uncertaintyBypassChecked012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 817, + "kind": "theorem", + "name": "CoreReader.Adopted.uncertaintySubstitutionRejected012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 829, + "kind": "def", + "name": "CoreReader.Adopted.selectedFactFacet012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 832, + "kind": "theorem", + "name": "CoreReader.Adopted.valueFactSubstitutionRejected012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 839, + "kind": "theorem", + "name": "CoreReader.Adopted.inferentialContextSubstitutionRejected012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 862, + "kind": "theorem", + "name": "CoreReader.Adopted.generationCases" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 904, + "kind": "theorem", + "name": "CoreReader.Adopted.generationLimits012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 952, + "kind": "theorem", + "name": "CoreReader.Adopted.consistencyCases" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 987, + "kind": "theorem", + "name": "CoreReader.Adopted.consistencyLimits012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 1015, + "kind": "theorem", + "name": "CoreReader.Adopted.reflexivityCases012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 1038, + "kind": "theorem", + "name": "CoreReader.Adopted.reflexivityLimits012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 1066, + "kind": "theorem", + "name": "CoreReader.Adopted.groundsCases012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 1082, + "kind": "theorem", + "name": "CoreReader.Adopted.empiricalCases012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 1114, + "kind": "theorem", + "name": "CoreReader.Adopted.inferentialCases012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 1131, + "kind": "theorem", + "name": "CoreReader.Adopted.valueCases012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 1152, + "kind": "theorem", + "name": "CoreReader.Adopted.groundsLimits012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 1184, + "kind": "theorem", + "name": "CoreReader.Adopted.scopeCases012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 1197, + "kind": "theorem", + "name": "CoreReader.Adopted.scopeLimits012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 1232, + "kind": "theorem", + "name": "CoreReader.Adopted.capabilityCases012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 1254, + "kind": "theorem", + "name": "CoreReader.Adopted.capabilityLimits012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 1295, + "kind": "theorem", + "name": "CoreReader.Adopted.choiceCases012" + }, + { + "file": "CoreReader/Adopted.lean", + "line": 1329, + "kind": "theorem", + "name": "CoreReader.Adopted.choiceLimits012" + }, + { + "file": "CoreReader/Agency.lean", + "line": 5, + "kind": "inductive", + "name": "CoreReader.Agency.FormKind" + }, + { + "file": "CoreReader/Agency.lean", + "line": 8, + "kind": "structure", + "name": "CoreReader.Agency.Form" + }, + { + "file": "CoreReader/Agency.lean", + "line": 13, + "kind": "inductive", + "name": "CoreReader.Agency.Aim" + }, + { + "file": "CoreReader/Agency.lean", + "line": 17, + "kind": "structure", + "name": "CoreReader.Agency.Policy" + }, + { + "file": "CoreReader/Agency.lean", + "line": 24, + "kind": "def", + "name": "CoreReader.Agency.Generative" + }, + { + "file": "CoreReader/Agency.lean", + "line": 28, + "kind": "def", + "name": "CoreReader.Agency.openPolicy" + }, + { + "file": "CoreReader/Agency.lean", + "line": 34, + "kind": "def", + "name": "CoreReader.Agency.neutralPolicy" + }, + { + "file": "CoreReader/Agency.lean", + "line": 37, + "kind": "theorem", + "name": "CoreReader.Agency.permissionNotValuation" + }, + { + "file": "CoreReader/Agency.lean", + "line": 42, + "kind": "theorem", + "name": "CoreReader.Agency.revisabilityCovers" + }, + { + "file": "CoreReader/Agency.lean", + "line": 45, + "kind": "inductive", + "name": "CoreReader.Agency.Operation" + }, + { + "file": "CoreReader/Agency.lean", + "line": 48, + "kind": "def", + "name": "CoreReader.Agency.Operation.run" + }, + { + "file": "CoreReader/Agency.lean", + "line": 52, + "kind": "inductive", + "name": "CoreReader.Agency.InventoryKind" + }, + { + "file": "CoreReader/Agency.lean", + "line": 55, + "kind": "structure", + "name": "CoreReader.Agency.Item" + }, + { + "file": "CoreReader/Agency.lean", + "line": 61, + "kind": "def", + "name": "CoreReader.Agency.Available" + }, + { + "file": "CoreReader/Agency.lean", + "line": 65, + "kind": "theorem", + "name": "CoreReader.Agency.inventoryNotCapability" + }, + { + "file": "CoreReader/Agency.lean", + "line": 74, + "kind": "structure", + "name": "CoreReader.Agency.State" + }, + { + "file": "CoreReader/Agency.lean", + "line": 83, + "kind": "def", + "name": "CoreReader.Agency.Expanded" + }, + { + "file": "CoreReader/Agency.lean", + "line": 87, + "kind": "def", + "name": "CoreReader.Agency.baseState" + }, + { + "file": "CoreReader/Agency.lean", + "line": 90, + "kind": "def", + "name": "CoreReader.Agency.inflatedState" + }, + { + "file": "CoreReader/Agency.lean", + "line": 96, + "kind": "def", + "name": "CoreReader.Agency.stableTrace" + }, + { + "file": "CoreReader/Agency.lean", + "line": 99, + "kind": "theorem", + "name": "CoreReader.Agency.revisionWithoutProgress" + }, + { + "file": "CoreReader/Agency.lean", + "line": 105, + "kind": "structure", + "name": "CoreReader.Agency.ExternalResources" + }, + { + "file": "CoreReader/Agency.lean", + "line": 112, + "kind": "def", + "name": "CoreReader.Agency.assistedExecution" + }, + { + "file": "CoreReader/Agency.lean", + "line": 118, + "kind": "def", + "name": "CoreReader.Agency.availableResources" + }, + { + "file": "CoreReader/Agency.lean", + "line": 121, + "kind": "def", + "name": "CoreReader.Agency.StableReason" + }, + { + "file": "CoreReader/Agency.lean", + "line": 126, + "kind": "structure", + "name": "CoreReader.Agency.GeneratingSystem" + }, + { + "file": "CoreReader/Agency.lean", + "line": 134, + "kind": "def", + "name": "CoreReader.Agency.generatingSystem" + }, + { + "file": "CoreReader/Agency.lean", + "line": 142, + "kind": "def", + "name": "CoreReader.Agency.GeneratingSystem.stableAction" + }, + { + "file": "CoreReader/Agency.lean", + "line": 143, + "kind": "def", + "name": "CoreReader.Agency.GeneratingSystem.requirementsMet" + }, + { + "file": "CoreReader/Agency.lean", + "line": 145, + "kind": "def", + "name": "CoreReader.Agency.GeneratingSystem.withinBudget" + }, + { + "file": "CoreReader/Agency.lean", + "line": 148, + "kind": "structure", + "name": "CoreReader.Agency.Announcement" + }, + { + "file": "CoreReader/Agency.lean", + "line": 157, + "kind": "def", + "name": "CoreReader.Agency.GeneratingSystem.report" + }, + { + "file": "CoreReader/Agency.lean", + "line": 161, + "kind": "def", + "name": "CoreReader.Agency.Announcement.claim" + }, + { + "file": "CoreReader/Agency.lean", + "line": 166, + "kind": "theorem", + "name": "CoreReader.Agency.announcementClaimImpliesExpansion" + }, + { + "file": "CoreReader/Agency.lean", + "line": 169, + "kind": "def", + "name": "CoreReader.Agency.inflatedAnnouncement" + }, + { + "file": "CoreReader/Agency.lean", + "line": 171, + "kind": "theorem", + "name": "CoreReader.Agency.inflatedAnnouncementRefuted" + }, + { + "file": "CoreReader/Agency.lean", + "line": 179, + "kind": "inductive", + "name": "CoreReader.Agency.TransitionCase" + }, + { + "file": "CoreReader/Agency.lean", + "line": 182, + "kind": "def", + "name": "CoreReader.Agency.extendedState" + }, + { + "file": "CoreReader/Agency.lean", + "line": 184, + "kind": "def", + "name": "CoreReader.Agency.transitionBefore" + }, + { + "file": "CoreReader/Agency.lean", + "line": 185, + "kind": "def", + "name": "CoreReader.Agency.transitionAfter" + }, + { + "file": "CoreReader/Agency.lean", + "line": 189, + "kind": "def", + "name": "CoreReader.Agency.transitionInput" + }, + { + "file": "CoreReader/Agency.lean", + "line": 190, + "kind": "def", + "name": "CoreReader.Agency.transitionAnnouncement" + }, + { + "file": "CoreReader/Agency.lean", + "line": 194, + "kind": "theorem", + "name": "CoreReader.Agency.generationLimits" + }, + { + "file": "CoreReader/Agency.lean", + "line": 224, + "kind": "theorem", + "name": "CoreReader.Agency.generationNotReflexivity" + }, + { + "file": "CoreReader/Agency.lean", + "line": 234, + "kind": "def", + "name": "CoreReader.Agency.ownArithmeticPrinciple" + }, + { + "file": "CoreReader/Agency.lean", + "line": 236, + "kind": "def", + "name": "CoreReader.Agency.selfTest" + }, + { + "file": "CoreReader/Agency.lean", + "line": 239, + "kind": "theorem", + "name": "CoreReader.Agency.selfTestDoesNotProve" + }, + { + "file": "CoreReader/Choice.lean", + "line": 6, + "kind": "inductive", + "name": "CoreReader.Choice.StatusKind" + }, + { + "file": "CoreReader/Choice.lean", + "line": 9, + "kind": "inductive", + "name": "CoreReader.Choice.MethodReason" + }, + { + "file": "CoreReader/Choice.lean", + "line": 12, + "kind": "inductive", + "name": "CoreReader.Choice.Reason" + }, + { + "file": "CoreReader/Choice.lean", + "line": 16, + "kind": "structure", + "name": "CoreReader.Choice.Implementation" + }, + { + "file": "CoreReader/Choice.lean", + "line": 27, + "kind": "structure", + "name": "CoreReader.Choice.Requirements" + }, + { + "file": "CoreReader/Choice.lean", + "line": 34, + "kind": "def", + "name": "CoreReader.Choice.MethodContent" + }, + { + "file": "CoreReader/Choice.lean", + "line": 42, + "kind": "def", + "name": "CoreReader.Choice.Relevant" + }, + { + "file": "CoreReader/Choice.lean", + "line": 46, + "kind": "def", + "name": "CoreReader.Choice.Feasible" + }, + { + "file": "CoreReader/Choice.lean", + "line": 50, + "kind": "def", + "name": "CoreReader.Choice.JustifiedChoice" + }, + { + "file": "CoreReader/Choice.lean", + "line": 54, + "kind": "theorem", + "name": "CoreReader.Choice.statusOnlyFails" + }, + { + "file": "CoreReader/Choice.lean", + "line": 61, + "kind": "def", + "name": "CoreReader.Choice.identityImpl" + }, + { + "file": "CoreReader/Choice.lean", + "line": 71, + "kind": "def", + "name": "CoreReader.Choice.successorImpl" + }, + { + "file": "CoreReader/Choice.lean", + "line": 81, + "kind": "def", + "name": "CoreReader.Choice.changedOutsideZero" + }, + { + "file": "CoreReader/Choice.lean", + "line": 90, + "kind": "def", + "name": "CoreReader.Choice.identityRequirements" + }, + { + "file": "CoreReader/Choice.lean", + "line": 96, + "kind": "def", + "name": "CoreReader.Choice.objectiveReason" + }, + { + "file": "CoreReader/Choice.lean", + "line": 98, + "kind": "theorem", + "name": "CoreReader.Choice.identityOutputReason" + }, + { + "file": "CoreReader/Choice.lean", + "line": 101, + "kind": "theorem", + "name": "CoreReader.Choice.identityFeasible" + }, + { + "file": "CoreReader/Choice.lean", + "line": 104, + "kind": "theorem", + "name": "CoreReader.Choice.identityJustified" + }, + { + "file": "CoreReader/Choice.lean", + "line": 108, + "kind": "theorem", + "name": "CoreReader.Choice.conventionWithReason" + }, + { + "file": "CoreReader/Choice.lean", + "line": 113, + "kind": "inductive", + "name": "CoreReader.Choice.Candidate" + }, + { + "file": "CoreReader/Choice.lean", + "line": 116, + "kind": "def", + "name": "CoreReader.Choice.implementation" + }, + { + "file": "CoreReader/Choice.lean", + "line": 121, + "kind": "theorem", + "name": "CoreReader.Choice.singleFeasible" + }, + { + "file": "CoreReader/Choice.lean", + "line": 132, + "kind": "theorem", + "name": "CoreReader.Choice.localNotGlobal" + }, + { + "file": "CoreReader/Choice.lean", + "line": 140, + "kind": "def", + "name": "CoreReader.Choice.cheapSuccessor" + }, + { + "file": "CoreReader/Choice.lean", + "line": 142, + "kind": "theorem", + "name": "CoreReader.Choice.eligibleInternalReasonNotSufficient" + }, + { + "file": "CoreReader/Choice.lean", + "line": 151, + "kind": "theorem", + "name": "CoreReader.Choice.internalReasons" + }, + { + "file": "CoreReader/Choice.lean", + "line": 162, + "kind": "theorem", + "name": "CoreReader.Choice.openNotEquivalent" + }, + { + "file": "CoreReader/Choice.lean", + "line": 168, + "kind": "def", + "name": "CoreReader.Choice.priorityClaim" + }, + { + "file": "CoreReader/Choice.lean", + "line": 170, + "kind": "def", + "name": "CoreReader.Choice.statusFacts" + }, + { + "file": "CoreReader/Choice.lean", + "line": 175, + "kind": "theorem", + "name": "CoreReader.Choice.statusFactsModel" + }, + { + "file": "CoreReader/Choice.lean", + "line": 178, + "kind": "def", + "name": "CoreReader.Choice.priorityArticulation" + }, + { + "file": "CoreReader/Choice.lean", + "line": 184, + "kind": "def", + "name": "CoreReader.Choice.AssessmentAccurate" + }, + { + "file": "CoreReader/Choice.lean", + "line": 187, + "kind": "theorem", + "name": "CoreReader.Choice.statusDoesNotEntailPriority" + }, + { + "file": "CoreReader/Choice.lean", + "line": 192, + "kind": "theorem", + "name": "CoreReader.Choice.statusAssessmentNonEntailment" + }, + { + "file": "CoreReader/Choice.lean", + "line": 204, + "kind": "structure", + "name": "CoreReader.Choice.PriorityAssessment" + }, + { + "file": "CoreReader/Choice.lean", + "line": 209, + "kind": "def", + "name": "CoreReader.Choice.PriorityAssessment.accurate" + }, + { + "file": "CoreReader/Choice.lean", + "line": 212, + "kind": "def", + "name": "CoreReader.Choice.statusPriorityAudit" + }, + { + "file": "CoreReader/Choice.lean", + "line": 214, + "kind": "structure", + "name": "CoreReader.Choice.ChoicePolicy" + }, + { + "file": "CoreReader/Choice.lean", + "line": 219, + "kind": "def", + "name": "CoreReader.Choice.GeneralAssessmentFulfilled" + }, + { + "file": "CoreReader/Choice.lean", + "line": 222, + "kind": "def", + "name": "CoreReader.Choice.AdditionalChoiceNorm" + }, + { + "file": "CoreReader/Choice.lean", + "line": 225, + "kind": "def", + "name": "CoreReader.Choice.statusPriorityPolicy" + }, + { + "file": "CoreReader/Choice.lean", + "line": 227, + "kind": "def", + "name": "CoreReader.Choice.outputPriorityPolicy" + }, + { + "file": "CoreReader/Choice.lean", + "line": 229, + "kind": "theorem", + "name": "CoreReader.Choice.statusPriorityAuditAccurate" + }, + { + "file": "CoreReader/Choice.lean", + "line": 234, + "kind": "def", + "name": "CoreReader.Choice.PolicyIndependenceExample" + }, + { + "file": "CoreReader/Choice.lean", + "line": 245, + "kind": "theorem", + "name": "CoreReader.Choice.policyIndependenceExample" + }, + { + "file": "CoreReader/Choice.lean", + "line": 257, + "kind": "theorem", + "name": "CoreReader.Choice.generalGroundsNotChoice" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 7, + "kind": "inductive", + "name": "CoreReader.Engineering.Maintainer" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 10, + "kind": "inductive", + "name": "CoreReader.Engineering.Tool" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 13, + "kind": "inductive", + "name": "CoreReader.Engineering.Knowledge" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 16, + "kind": "inductive", + "name": "CoreReader.Engineering.Change" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 20, + "kind": "inductive", + "name": "CoreReader.Engineering.Candidate" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 23, + "kind": "inductive", + "name": "CoreReader.Engineering.Burden" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 28, + "kind": "def", + "name": "CoreReader.Engineering.maintainers" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 29, + "kind": "def", + "name": "CoreReader.Engineering.changes" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 31, + "kind": "def", + "name": "CoreReader.Engineering.burdens" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 34, + "kind": "structure", + "name": "CoreReader.Engineering.Activity" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 49, + "kind": "abbrev", + "name": "CoreReader.Engineering.ActivityScope" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 53, + "kind": "abbrev", + "name": "CoreReader.Engineering.Continuing" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 56, + "kind": "abbrev", + "name": "CoreReader.Engineering.BoundedLifecycle" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 60, + "kind": "def", + "name": "CoreReader.Engineering.continuingActivity" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 69, + "kind": "def", + "name": "CoreReader.Engineering.temporaryActivity" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 72, + "kind": "def", + "name": "CoreReader.Engineering.prototypeActivity" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 74, + "kind": "def", + "name": "CoreReader.Engineering.retiringActivity" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 77, + "kind": "structure", + "name": "CoreReader.Engineering.EditStep" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 84, + "kind": "def", + "name": "CoreReader.Engineering.changePath" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 104, + "kind": "def", + "name": "CoreReader.Engineering.changeWork" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 107, + "kind": "abbrev", + "name": "CoreReader.Engineering.CanChange" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 111, + "kind": "abbrev", + "name": "CoreReader.Engineering.ContinuingCapability" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 118, + "kind": "def", + "name": "CoreReader.Engineering.registeredDirections" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 119, + "kind": "def", + "name": "CoreReader.Engineering.supportedDirections" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 121, + "kind": "abbrev", + "name": "CoreReader.Engineering.MaximumRegisteredCapability" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 126, + "kind": "def", + "name": "CoreReader.Engineering.passiveArtifact" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 128, + "kind": "def", + "name": "CoreReader.Engineering.orientation" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 130, + "kind": "inductive", + "name": "CoreReader.Engineering.EngineeringAction" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 135, + "kind": "def", + "name": "CoreReader.Engineering.maintainerActions" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 138, + "kind": "def", + "name": "CoreReader.Engineering.artifactActions" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 146, + "kind": "theorem", + "name": "CoreReader.Engineering.subjectLifecycleCases" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 159, + "kind": "theorem", + "name": "CoreReader.Engineering.subjectLimits" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 174, + "kind": "abbrev", + "name": "CoreReader.Engineering.CredibleDirection" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 179, + "kind": "inductive", + "name": "CoreReader.Engineering.DirectionGround" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 186, + "kind": "def", + "name": "CoreReader.Engineering.articulateGround" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 192, + "kind": "def", + "name": "CoreReader.Engineering.supportGround" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 199, + "kind": "abbrev", + "name": "CoreReader.Engineering.initialGrounds" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 200, + "kind": "def", + "name": "CoreReader.Engineering.forecastGrounds" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 201, + "kind": "abbrev", + "name": "CoreReader.Engineering.credible" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 204, + "kind": "abbrev", + "name": "CoreReader.Engineering.WarrantedAccommodation" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 212, + "kind": "theorem", + "name": "CoreReader.Engineering.credibilityCases" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 219, + "kind": "def", + "name": "CoreReader.Engineering.abstractionComplexity" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 222, + "kind": "def", + "name": "CoreReader.Engineering.implementedVariants" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 225, + "kind": "structure", + "name": "CoreReader.Engineering.CostVector" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 227, + "kind": "structure", + "name": "CoreReader.Engineering.CostLimits" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 231, + "kind": "def", + "name": "CoreReader.Engineering.cost" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 242, + "kind": "def", + "name": "CoreReader.Engineering.normalLimits" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 253, + "kind": "structure", + "name": "CoreReader.Engineering.Requirements" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 259, + "kind": "def", + "name": "CoreReader.Engineering.normalRequirements" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 260, + "kind": "def", + "name": "CoreReader.Engineering.behavior" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 264, + "kind": "structure", + "name": "CoreReader.Engineering.CandidateProfile" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 270, + "kind": "def", + "name": "CoreReader.Engineering.profile" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 271, + "kind": "abbrev", + "name": "CoreReader.Engineering.Meets" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 276, + "kind": "structure", + "name": "CoreReader.Engineering.Context" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 284, + "kind": "def", + "name": "CoreReader.Engineering.currentContinuing" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 288, + "kind": "abbrev", + "name": "CoreReader.Engineering.ConcreteThreat" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 292, + "kind": "abbrev", + "name": "CoreReader.Engineering.HasThreat" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 298, + "kind": "abbrev", + "name": "CoreReader.Engineering.JustifiedDeparture" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 307, + "kind": "abbrev", + "name": "CoreReader.Engineering.PriorityConditions" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 321, + "kind": "abbrev", + "name": "CoreReader.Engineering.EvolutionPriority" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 324, + "kind": "theorem", + "name": "CoreReader.Engineering.currentPriorityConditions" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 325, + "kind": "theorem", + "name": "CoreReader.Engineering.currentNoThreat" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 328, + "kind": "def", + "name": "CoreReader.Engineering.threatened" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 337, + "kind": "theorem", + "name": "CoreReader.Engineering.priorityWhenApplicable" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 345, + "kind": "theorem", + "name": "CoreReader.Engineering.currentSimpleViolates" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 350, + "kind": "def", + "name": "CoreReader.Engineering.withEvolvableProfile" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 353, + "kind": "theorem", + "name": "CoreReader.Engineering.unmetRequirementsBlockPriority" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 367, + "kind": "theorem", + "name": "CoreReader.Engineering.priorityConditionsCases" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 384, + "kind": "theorem", + "name": "CoreReader.Engineering.priorityChoices" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 394, + "kind": "theorem", + "name": "CoreReader.Engineering.credibilityLimits" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "kind": "theorem", + "name": "CoreReader.Engineering.costCases" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 422, + "kind": "def", + "name": "CoreReader.Engineering.orderedUnique" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 423, + "kind": "def", + "name": "CoreReader.Engineering.orderedRefactor" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 424, + "kind": "def", + "name": "CoreReader.Engineering.insertOrdered" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 428, + "kind": "def", + "name": "CoreReader.Engineering.sortValues" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 432, + "kind": "def", + "name": "CoreReader.Engineering.sortedUnique" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 434, + "kind": "structure", + "name": "CoreReader.Engineering.SoftwareState" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 444, + "kind": "def", + "name": "CoreReader.Engineering.originalSoftware" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 447, + "kind": "def", + "name": "CoreReader.Engineering.transform" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 461, + "kind": "def", + "name": "CoreReader.Engineering.evolutionBehavior" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 466, + "kind": "inductive", + "name": "CoreReader.Engineering.ObligationTreatment" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 469, + "kind": "structure", + "name": "CoreReader.Engineering.ChangeClaim" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 474, + "kind": "abbrev", + "name": "CoreReader.Engineering.contractInputs" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 475, + "kind": "def", + "name": "CoreReader.Engineering.PreservesOn" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 478, + "kind": "abbrev", + "name": "CoreReader.Engineering.PreservesFinite" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 484, + "kind": "structure", + "name": "CoreReader.Engineering.ObservableContract" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 488, + "kind": "def", + "name": "CoreReader.Engineering.retry" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 491, + "kind": "def", + "name": "CoreReader.Engineering.orderContract" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 492, + "kind": "def", + "name": "CoreReader.Engineering.originalContract" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 493, + "kind": "def", + "name": "CoreReader.Engineering.refactoredContract" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 494, + "kind": "def", + "name": "CoreReader.Engineering.revisedContract" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 495, + "kind": "def", + "name": "CoreReader.Engineering.evolutionContract" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 498, + "kind": "def", + "name": "CoreReader.Engineering.failureInputs" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 499, + "kind": "abbrev", + "name": "CoreReader.Engineering.PreservesContractFinite" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 503, + "kind": "inductive", + "name": "CoreReader.Engineering.ContractAspect" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 506, + "kind": "structure", + "name": "CoreReader.Engineering.PartyDependency" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 511, + "kind": "def", + "name": "CoreReader.Engineering.partyDependencies" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 514, + "kind": "def", + "name": "CoreReader.Engineering.aspectChanged" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 518, + "kind": "def", + "name": "CoreReader.Engineering.affectedParties" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 522, + "kind": "structure", + "name": "CoreReader.Engineering.ContractRevision" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 532, + "kind": "def", + "name": "CoreReader.Engineering.normalRevision" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 539, + "kind": "abbrev", + "name": "CoreReader.Engineering.RevisionDuties" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 549, + "kind": "abbrev", + "name": "CoreReader.Engineering.ContractChangeAccount" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 556, + "kind": "abbrev", + "name": "CoreReader.Engineering.EvolutionClaim" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "kind": "theorem", + "name": "CoreReader.Engineering.evolutionKindsCases" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 585, + "kind": "theorem", + "name": "CoreReader.Engineering.evolutionDimensionsLimits" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 602, + "kind": "theorem", + "name": "CoreReader.Engineering.oneDimensionDoesNotEntailEveryDimension" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 610, + "kind": "def", + "name": "CoreReader.Engineering.propagation" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 613, + "kind": "def", + "name": "CoreReader.Engineering.batchCount" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 614, + "kind": "def", + "name": "CoreReader.Engineering.staticBatch" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 615, + "kind": "def", + "name": "CoreReader.Engineering.liveBatch" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 617, + "kind": "structure", + "name": "CoreReader.Engineering.StructuralEvidence" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 628, + "kind": "def", + "name": "CoreReader.Engineering.structuralEvidence" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 641, + "kind": "abbrev", + "name": "CoreReader.Engineering.StructuralAccount" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 651, + "kind": "structure", + "name": "CoreReader.Engineering.InterfaceView" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 658, + "kind": "def", + "name": "CoreReader.Engineering.sameShape" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 659, + "kind": "def", + "name": "CoreReader.Engineering.moduleAssumptions" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 662, + "kind": "def", + "name": "CoreReader.Engineering.modulesNeedingRevision" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 665, + "kind": "structure", + "name": "CoreReader.Engineering.Boundary" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 671, + "kind": "structure", + "name": "CoreReader.Engineering.EngineeringDesign" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 679, + "kind": "def", + "name": "CoreReader.Engineering.privateDesign" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 683, + "kind": "def", + "name": "CoreReader.Engineering.documentedDesign" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 686, + "kind": "def", + "name": "CoreReader.Engineering.sortedDesign" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 692, + "kind": "def", + "name": "CoreReader.Engineering.coordinatedBoundary" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 694, + "kind": "def", + "name": "CoreReader.Engineering.boundaryDesign" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 697, + "kind": "def", + "name": "CoreReader.Engineering.crossesBoundary" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 703, + "kind": "def", + "name": "CoreReader.Engineering.boundaryObligationChecked" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 710, + "kind": "def", + "name": "CoreReader.Engineering.omittedCallerCheck" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 715, + "kind": "def", + "name": "CoreReader.Engineering.otherCalleeBoundary" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 717, + "kind": "def", + "name": "CoreReader.Engineering.otherCalleeDesign" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 720, + "kind": "theorem", + "name": "CoreReader.Engineering.actualCrossBoundaryObligation" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 733, + "kind": "theorem", + "name": "CoreReader.Engineering.structuralCases" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 751, + "kind": "abbrev", + "name": "CoreReader.Engineering.DesignCanChange" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 757, + "kind": "def", + "name": "CoreReader.Engineering.designWork" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 760, + "kind": "def", + "name": "CoreReader.Engineering.designModulesNeedingRevision" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 766, + "kind": "def", + "name": "CoreReader.Engineering.introduceBoundary" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 776, + "kind": "def", + "name": "CoreReader.Engineering.wrappedDesign" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 781, + "kind": "def", + "name": "CoreReader.Engineering.relocateVerification" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 787, + "kind": "def", + "name": "CoreReader.Engineering.sameWorkDesign" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 793, + "kind": "theorem", + "name": "CoreReader.Engineering.structureNotCapability" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 822, + "kind": "theorem", + "name": "CoreReader.Engineering.contractPreservation" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 826, + "kind": "theorem", + "name": "CoreReader.Engineering.changedObservationNotPreserved" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 832, + "kind": "theorem", + "name": "CoreReader.Engineering.contractRevisionObligations" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 837, + "kind": "def", + "name": "CoreReader.Engineering.retiredBehavior" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 843, + "kind": "theorem", + "name": "CoreReader.Engineering.contractCases" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 853, + "kind": "theorem", + "name": "CoreReader.Engineering.contractDistinctions" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 868, + "kind": "structure", + "name": "CoreReader.Engineering.RevisionState" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 877, + "kind": "structure", + "name": "CoreReader.Engineering.RevisionRecord" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 889, + "kind": "abbrev", + "name": "CoreReader.Engineering.MaterialGroundsChanged" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 894, + "kind": "def", + "name": "CoreReader.Engineering.oldState" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 895, + "kind": "def", + "name": "CoreReader.Engineering.newState" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 897, + "kind": "structure", + "name": "CoreReader.Engineering.HistoricalEvidence" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 905, + "kind": "def", + "name": "CoreReader.Engineering.observedHistory" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 908, + "kind": "abbrev", + "name": "CoreReader.Engineering.RevisionAccountAgainst" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 922, + "kind": "abbrev", + "name": "CoreReader.Engineering.RevisionAccount" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 924, + "kind": "theorem", + "name": "CoreReader.Engineering.failedHistoryNotRewritten" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 930, + "kind": "def", + "name": "CoreReader.Engineering.revisionRecord" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 937, + "kind": "abbrev", + "name": "CoreReader.Engineering.SupportedAlternative" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 939, + "kind": "abbrev", + "name": "CoreReader.Engineering.RetentionJustified" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 943, + "kind": "def", + "name": "CoreReader.Engineering.stableRecord" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 951, + "kind": "theorem", + "name": "CoreReader.Engineering.revisionCases" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 962, + "kind": "def", + "name": "CoreReader.Engineering.observations" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 963, + "kind": "def", + "name": "CoreReader.Engineering.revisionsMade" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 964, + "kind": "def", + "name": "CoreReader.Engineering.agreedBatch" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 967, + "kind": "def", + "name": "CoreReader.Engineering.rewrittenOldRecord" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 971, + "kind": "def", + "name": "CoreReader.Engineering.rewrittenPredictionRecord" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 974, + "kind": "def", + "name": "CoreReader.Engineering.rewrittenObservationRecord" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 977, + "kind": "def", + "name": "CoreReader.Engineering.unrelatedSoftwareRecord" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 980, + "kind": "theorem", + "name": "CoreReader.Engineering.historicalTamperingRejected" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 993, + "kind": "theorem", + "name": "CoreReader.Engineering.revisionLimits" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 1007, + "kind": "def", + "name": "CoreReader.Engineering.groundedChanges" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 1010, + "kind": "def", + "name": "CoreReader.Engineering.currentRevisionState" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 1017, + "kind": "def", + "name": "CoreReader.Engineering.revisionFor" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 1020, + "kind": "theorem", + "name": "CoreReader.Engineering.revisionContextIdentity" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 1034, + "kind": "abbrev", + "name": "CoreReader.Engineering.DomainSatisfied" + }, + { + "file": "CoreReader/Engineering/Domain.lean", + "line": 1043, + "kind": "theorem", + "name": "CoreReader.Engineering.currentDomainSatisfied" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 11, + "kind": "abbrev", + "name": "CoreReader.Engineering.sharedContext" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 13, + "kind": "def", + "name": "CoreReader.Engineering.maintainedOutput" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 16, + "kind": "def", + "name": "CoreReader.Engineering.chosenImplementation" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 28, + "kind": "def", + "name": "CoreReader.Engineering.chosenRequirements" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 34, + "kind": "def", + "name": "CoreReader.Engineering.chosenReasons" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 37, + "kind": "theorem", + "name": "CoreReader.Engineering.maintainedOutputCorrect" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 41, + "kind": "theorem", + "name": "CoreReader.Engineering.implementationReasoned" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 51, + "kind": "def", + "name": "CoreReader.Engineering.capabilityOutput" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 57, + "kind": "def", + "name": "CoreReader.Engineering.engineeringProcess" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 60, + "kind": "def", + "name": "CoreReader.Engineering.engineeringCapability" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 63, + "kind": "theorem", + "name": "CoreReader.Engineering.engineeringCapabilityGrounded" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 67, + "kind": "theorem", + "name": "CoreReader.Engineering.actualCapabilityContrast" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 77, + "kind": "def", + "name": "CoreReader.Engineering.presentBudgetRecord" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 80, + "kind": "abbrev", + "name": "CoreReader.Engineering.presentBudgetClaim" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 82, + "kind": "theorem", + "name": "CoreReader.Engineering.budgetObservationMeaning" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 92, + "kind": "def", + "name": "CoreReader.Engineering.budgetEmpiricalFacet" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 95, + "kind": "theorem", + "name": "CoreReader.Engineering.budgetEmpiricalDischarged" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 101, + "kind": "def", + "name": "CoreReader.Engineering.capacityClaim" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 104, + "kind": "def", + "name": "CoreReader.Engineering.capacityAssumptions" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 106, + "kind": "def", + "name": "CoreReader.Engineering.budgetInferentialFacet" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 108, + "kind": "theorem", + "name": "CoreReader.Engineering.budgetInferentialDischarged" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 114, + "kind": "def", + "name": "CoreReader.Engineering.budgetScopeAccount" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 126, + "kind": "theorem", + "name": "CoreReader.Engineering.budgetScopeExplained" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 134, + "kind": "theorem", + "name": "CoreReader.Engineering.budgetObservationLimit" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 144, + "kind": "def", + "name": "CoreReader.Engineering.engineeringPolicy" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 152, + "kind": "theorem", + "name": "CoreReader.Engineering.engineeringGenerative" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 157, + "kind": "inductive", + "name": "CoreReader.Engineering.OwnFact" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 162, + "kind": "abbrev", + "name": "CoreReader.Engineering.ownFactClaim" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 174, + "kind": "theorem", + "name": "CoreReader.Engineering.actualOwnFact" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 188, + "kind": "def", + "name": "CoreReader.Engineering.ownFactPremises" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 191, + "kind": "theorem", + "name": "CoreReader.Engineering.actualOwnFactGrounded" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 204, + "kind": "theorem", + "name": "CoreReader.Engineering.priorityValueMeaning" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 216, + "kind": "theorem", + "name": "CoreReader.Engineering.priorityGrounds" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 229, + "kind": "inductive", + "name": "CoreReader.Engineering.OwnNorm" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 235, + "kind": "def", + "name": "CoreReader.Engineering.normApplies" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 239, + "kind": "def", + "name": "CoreReader.Engineering.ownNormClaim" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 260, + "kind": "theorem", + "name": "CoreReader.Engineering.actualOwnNorm" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 282, + "kind": "def", + "name": "CoreReader.Engineering.ownFactTheory" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 285, + "kind": "def", + "name": "CoreReader.Engineering.ownNormTheory" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 290, + "kind": "def", + "name": "CoreReader.Engineering.ownTheory" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 293, + "kind": "theorem", + "name": "CoreReader.Engineering.allNormativeContentHeld" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 297, + "kind": "theorem", + "name": "CoreReader.Engineering.nonemptyOwnObjects" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 305, + "kind": "def", + "name": "CoreReader.Engineering.comparisonContext" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 310, + "kind": "def", + "name": "CoreReader.Engineering.engineeringSnapshot" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 313, + "kind": "theorem", + "name": "CoreReader.Engineering.currentAdmissible" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 325, + "kind": "theorem", + "name": "CoreReader.Engineering.currentConsistency" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 331, + "kind": "theorem", + "name": "CoreReader.Engineering.wholeClaimGrounded" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 344, + "kind": "def", + "name": "CoreReader.Engineering.incompatibleNormTheory" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 348, + "kind": "def", + "name": "CoreReader.Engineering.incompatibleNormContext" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 351, + "kind": "theorem", + "name": "CoreReader.Engineering.normativeContentVariation" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 374, + "kind": "structure", + "name": "CoreReader.Engineering.Inherited" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 398, + "kind": "theorem", + "name": "CoreReader.Engineering.inheritedCurrent" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 420, + "kind": "theorem", + "name": "CoreReader.Engineering.inheritedMutualApplication" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 442, + "kind": "theorem", + "name": "CoreReader.Engineering.inheritedMutualCases" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 467, + "kind": "theorem", + "name": "CoreReader.Engineering.priorityRemainsReflexive" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 493, + "kind": "theorem", + "name": "CoreReader.Engineering.priorityReflexiveCases" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 557, + "kind": "theorem", + "name": "CoreReader.Engineering.jointWitness" + }, + { + "file": "CoreReader/Engineering/Integration.lean", + "line": 586, + "kind": "theorem", + "name": "CoreReader.Engineering.inheritedDoesNotEntailPriority" + }, + { + "file": "CoreReader/Engineering/Reflection.lean", + "line": 8, + "kind": "structure", + "name": "CoreReader.Engineering.Reflection.Target" + }, + { + "file": "CoreReader/Engineering/Reflection.lean", + "line": 15, + "kind": "structure", + "name": "CoreReader.Engineering.Reflection.Contract" + }, + { + "file": "CoreReader/Engineering/Reflection.lean", + "line": 22, + "kind": "structure", + "name": "CoreReader.Engineering.Reflection.Input" + }, + { + "file": "CoreReader/Engineering/Reflection.lean", + "line": 29, + "kind": "inductive", + "name": "CoreReader.Engineering.Reflection.Verdict" + }, + { + "file": "CoreReader/Engineering/Reflection.lean", + "line": 32, + "kind": "inductive", + "name": "CoreReader.Engineering.Reflection.Outcome" + }, + { + "file": "CoreReader/Engineering/Reflection.lean", + "line": 39, + "kind": "def", + "name": "CoreReader.Engineering.Reflection.evaluate" + }, + { + "file": "CoreReader/Engineering/Reflection.lean", + "line": 47, + "kind": "def", + "name": "CoreReader.Engineering.Reflection.generate" + }, + { + "file": "CoreReader/Engineering/Reflection.lean", + "line": 50, + "kind": "def", + "name": "CoreReader.Engineering.Reflection.interpret" + }, + { + "file": "CoreReader/Engineering/Reflection.lean", + "line": 56, + "kind": "structure", + "name": "CoreReader.Engineering.Reflection.Model" + }, + { + "file": "CoreReader/Engineering/Reflection.lean", + "line": 67, + "kind": "def", + "name": "CoreReader.Engineering.Reflection.Model.input" + }, + { + "file": "CoreReader/Engineering/Reflection.lean", + "line": 71, + "kind": "def", + "name": "CoreReader.Engineering.Reflection.Model.self" + }, + { + "file": "CoreReader/Engineering/Reflection.lean", + "line": 74, + "kind": "def", + "name": "CoreReader.Engineering.Reflection.Model.rule" + }, + { + "file": "CoreReader/Engineering/Reflection.lean", + "line": 84, + "kind": "def", + "name": "CoreReader.Engineering.Reflection.Model.rules" + }, + { + "file": "CoreReader/Engineering/Reflection.lean", + "line": 89, + "kind": "def", + "name": "CoreReader.Engineering.Reflection.Model.performed" + }, + { + "file": "CoreReader/Engineering/Reflection.lean", + "line": 95, + "kind": "def", + "name": "CoreReader.Engineering.Reflection.Model.follows" + }, + { + "file": "CoreReader/Engineering/Reflection.lean", + "line": 104, + "kind": "theorem", + "name": "CoreReader.Engineering.Reflection.recordedReflexivity" + }, + { + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 8, + "kind": "inductive", + "name": "CoreReader.Engineering.ReviewObject" + }, + { + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 12, + "kind": "abbrev", + "name": "CoreReader.Engineering.ReviewCase" + }, + { + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 14, + "kind": "def", + "name": "CoreReader.Engineering.generationApplies" + }, + { + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 17, + "kind": "def", + "name": "CoreReader.Engineering.assessmentApplies" + }, + { + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 19, + "kind": "def", + "name": "CoreReader.Engineering.ruleObject" + }, + { + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 26, + "kind": "def", + "name": "CoreReader.Engineering.ruleProbe" + }, + { + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 34, + "kind": "def", + "name": "CoreReader.Engineering.generationRuleTest" + }, + { + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 40, + "kind": "def", + "name": "CoreReader.Engineering.assessmentRuleTest" + }, + { + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 48, + "kind": "def", + "name": "CoreReader.Engineering.sampleAwareAssessment" + }, + { + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 53, + "kind": "def", + "name": "CoreReader.Engineering.objectTest" + }, + { + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 62, + "kind": "def", + "name": "CoreReader.Engineering.reviewObjects" + }, + { + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 67, + "kind": "def", + "name": "CoreReader.Engineering.requestedCases" + }, + { + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 71, + "kind": "def", + "name": "CoreReader.Engineering.reviewReasons" + }, + { + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 87, + "kind": "def", + "name": "CoreReader.Engineering.statedReview" + }, + { + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 98, + "kind": "def", + "name": "CoreReader.Engineering.reviewBasis" + }, + { + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 114, + "kind": "def", + "name": "CoreReader.Engineering.selfModel" + }, + { + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 128, + "kind": "theorem", + "name": "CoreReader.Engineering.reviewIdentity" + }, + { + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 137, + "kind": "theorem", + "name": "CoreReader.Engineering.currentSelfRecords" + }, + { + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 161, + "kind": "theorem", + "name": "CoreReader.Engineering.currentSelfApplication" + }, + { + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 170, + "kind": "theorem", + "name": "CoreReader.Engineering.actualSelfCriticism" + }, + { + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 188, + "kind": "theorem", + "name": "CoreReader.Engineering.ownRuleIdentity" + }, + { + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 204, + "kind": "theorem", + "name": "CoreReader.Engineering.ownRuleContentVariation" + }, + { + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 218, + "kind": "theorem", + "name": "CoreReader.Engineering.proposedRuleRevision" + }, + { + "file": "CoreReader/Engineering/Values.lean", + "line": 8, + "kind": "inductive", + "name": "CoreReader.Engineering.CoreCommitment" + }, + { + "file": "CoreReader/Engineering/Values.lean", + "line": 11, + "kind": "def", + "name": "CoreReader.Engineering.coreCommitments" + }, + { + "file": "CoreReader/Engineering/Values.lean", + "line": 16, + "kind": "def", + "name": "CoreReader.Engineering.coreAdopted" + }, + { + "file": "CoreReader/Engineering/Values.lean", + "line": 18, + "kind": "inductive", + "name": "CoreReader.Engineering.AdoptionReason" + }, + { + "file": "CoreReader/Engineering/Values.lean", + "line": 26, + "kind": "def", + "name": "CoreReader.Engineering.reasonFor" + }, + { + "file": "CoreReader/Engineering/Values.lean", + "line": 36, + "kind": "abbrev", + "name": "CoreReader.Engineering.ReasonRelevant" + }, + { + "file": "CoreReader/Engineering/Values.lean", + "line": 53, + "kind": "abbrev", + "name": "CoreReader.Engineering.valueScope" + }, + { + "file": "CoreReader/Engineering/Values.lean", + "line": 58, + "kind": "def", + "name": "CoreReader.Engineering.safeguardExperiment" + }, + { + "file": "CoreReader/Engineering/Values.lean", + "line": 79, + "kind": "def", + "name": "CoreReader.Engineering.criticismFor" + }, + { + "file": "CoreReader/Engineering/Values.lean", + "line": 86, + "kind": "def", + "name": "CoreReader.Engineering.governancePosition" + }, + { + "file": "CoreReader/Engineering/Values.lean", + "line": 100, + "kind": "theorem", + "name": "CoreReader.Engineering.adoptionReasonRelevant" + }, + { + "file": "CoreReader/Engineering/Values.lean", + "line": 110, + "kind": "theorem", + "name": "CoreReader.Engineering.safeguardEnabled" + }, + { + "file": "CoreReader/Engineering/Values.lean", + "line": 120, + "kind": "theorem", + "name": "CoreReader.Engineering.safeguardDisabled" + }, + { + "file": "CoreReader/Engineering/Values.lean", + "line": 124, + "kind": "theorem", + "name": "CoreReader.Engineering.governanceValueProcedure" + }, + { + "file": "CoreReader/Engineering/Values.lean", + "line": 137, + "kind": "theorem", + "name": "CoreReader.Engineering.governanceGrounded" + }, + { + "file": "CoreReader/Engineering/Values.lean", + "line": 143, + "kind": "theorem", + "name": "CoreReader.Engineering.governanceRationaleLimits" + }, + { + "file": "CoreReader/Engineering/Values.lean", + "line": 157, + "kind": "def", + "name": "CoreReader.Engineering.selectionObjective" + }, + { + "file": "CoreReader/Engineering/Values.lean", + "line": 163, + "kind": "def", + "name": "CoreReader.Engineering.selectionPosition" + }, + { + "file": "CoreReader/Engineering/Values.lean", + "line": 182, + "kind": "theorem", + "name": "CoreReader.Engineering.selectionValueProcedure" + }, + { + "file": "CoreReader/Engineering/Values.lean", + "line": 219, + "kind": "theorem", + "name": "CoreReader.Engineering.selectionGrounded" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 9, + "kind": "structure", + "name": "CoreReader.Evidence.Record" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 13, + "kind": "def", + "name": "CoreReader.Evidence.Compatible" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 16, + "kind": "def", + "name": "CoreReader.Evidence.Supports" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 19, + "kind": "structure", + "name": "CoreReader.Evidence.Articulation" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 25, + "kind": "def", + "name": "CoreReader.Evidence.Articulated" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 28, + "kind": "structure", + "name": "CoreReader.Evidence.ValuePosition" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 42, + "kind": "def", + "name": "CoreReader.Evidence.ValuePosition.commitment" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 45, + "kind": "def", + "name": "CoreReader.Evidence.ValuePosition.consequence" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 48, + "kind": "def", + "name": "CoreReader.Evidence.ValuePosition.activeReasons" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 51, + "kind": "def", + "name": "CoreReader.Evidence.JointAdoption" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 55, + "kind": "def", + "name": "CoreReader.Evidence.ValueProcedure" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 61, + "kind": "inductive", + "name": "CoreReader.Evidence.Facet" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 66, + "kind": "def", + "name": "CoreReader.Evidence.Facet.claim" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 71, + "kind": "def", + "name": "CoreReader.Evidence.FacetDischarged" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 78, + "kind": "def", + "name": "CoreReader.Evidence.FacetArticulated" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 85, + "kind": "def", + "name": "CoreReader.Evidence.canonicalArticulation" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 93, + "kind": "theorem", + "name": "CoreReader.Evidence.canonicalFacetArticulated" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 97, + "kind": "theorem", + "name": "CoreReader.Evidence.canonicalArticulated" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 106, + "kind": "def", + "name": "CoreReader.Evidence.Grounds" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 112, + "kind": "def", + "name": "CoreReader.Evidence.AchievementAccountability" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 116, + "kind": "def", + "name": "CoreReader.Evidence.transitionAchievement" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 119, + "kind": "def", + "name": "CoreReader.Evidence.transitionPerformanceRecord" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 123, + "kind": "def", + "name": "CoreReader.Evidence.transitionReportRecord" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 128, + "kind": "theorem", + "name": "CoreReader.Evidence.transitionPerformanceCompatible" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 141, + "kind": "theorem", + "name": "CoreReader.Evidence.transitionSupported" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 150, + "kind": "def", + "name": "CoreReader.Evidence.transitionFacet" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 154, + "kind": "theorem", + "name": "CoreReader.Evidence.transitionFacetDischarged" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 159, + "kind": "theorem", + "name": "CoreReader.Evidence.transitionAccountable" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 168, + "kind": "theorem", + "name": "CoreReader.Evidence.transitionReportCompatible" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 173, + "kind": "theorem", + "name": "CoreReader.Evidence.transitionReportDoesNotSupport" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 180, + "kind": "def", + "name": "CoreReader.Evidence.ConcreteAchievementExample" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 191, + "kind": "theorem", + "name": "CoreReader.Evidence.concreteAchievementExample" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 197, + "kind": "theorem", + "name": "CoreReader.Evidence.achievementNeedsSupport" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 202, + "kind": "theorem", + "name": "CoreReader.Evidence.supportWeakening" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 206, + "kind": "theorem", + "name": "CoreReader.Evidence.evidenceWeakeningCanLoseSupport" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 213, + "kind": "theorem", + "name": "CoreReader.Evidence.scopeRestriction" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 219, + "kind": "def", + "name": "CoreReader.Evidence.Duties" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 221, + "kind": "def", + "name": "CoreReader.Evidence.LabeledDuties" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 224, + "kind": "theorem", + "name": "CoreReader.Evidence.assessmentUnion" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 230, + "kind": "theorem", + "name": "CoreReader.Evidence.labelsCannotWaive" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 233, + "kind": "def", + "name": "CoreReader.Evidence.switchRecord" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 234, + "kind": "theorem", + "name": "CoreReader.Evidence.switchCompatible" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 238, + "kind": "theorem", + "name": "CoreReader.Evidence.switchSupported" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 241, + "kind": "def", + "name": "CoreReader.Evidence.optionBenefit" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 242, + "kind": "def", + "name": "CoreReader.Evidence.optionCost" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 244, + "kind": "def", + "name": "CoreReader.Evidence.optionReport" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 247, + "kind": "def", + "name": "CoreReader.Evidence.switchPosition" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 260, + "kind": "theorem", + "name": "CoreReader.Evidence.switchValueProcedure" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 274, + "kind": "def", + "name": "CoreReader.Evidence.oppositePosition" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 277, + "kind": "theorem", + "name": "CoreReader.Evidence.oppositePositionRejected" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 294, + "kind": "def", + "name": "CoreReader.Evidence.contradictoryStartingPosition" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 296, + "kind": "def", + "name": "CoreReader.Evidence.impossibleAdoptionPosition" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 299, + "kind": "theorem", + "name": "CoreReader.Evidence.inadmissibleValuePositionsRejected" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 307, + "kind": "def", + "name": "CoreReader.Evidence.unsupportedPosition" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 308, + "kind": "def", + "name": "CoreReader.Evidence.switchEmpirical" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 310, + "kind": "theorem", + "name": "CoreReader.Evidence.switchEmpiricalDischarged" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 315, + "kind": "theorem", + "name": "CoreReader.Evidence.mixedMissingResponsibility" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 323, + "kind": "def", + "name": "CoreReader.Evidence.uninformativeArgument" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 325, + "kind": "theorem", + "name": "CoreReader.Evidence.articulationNotSupport" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 330, + "kind": "theorem", + "name": "CoreReader.Evidence.unrelatedArticulationRejected" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 339, + "kind": "def", + "name": "CoreReader.Evidence.temperatureRecord" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 340, + "kind": "theorem", + "name": "CoreReader.Evidence.temperatureCompatible" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 347, + "kind": "abbrev", + "name": "CoreReader.Evidence.BudgetWorld" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 349, + "kind": "def", + "name": "CoreReader.Evidence.announcement" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 350, + "kind": "def", + "name": "CoreReader.Evidence.announcementPosition" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 364, + "kind": "theorem", + "name": "CoreReader.Evidence.announcementHasJointAdoption" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 372, + "kind": "theorem", + "name": "CoreReader.Evidence.announcementNotBudgetReason" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 390, + "kind": "def", + "name": "CoreReader.Evidence.actionRecord" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 391, + "kind": "theorem", + "name": "CoreReader.Evidence.actionCompatible" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 394, + "kind": "theorem", + "name": "CoreReader.Evidence.measurementRepeatNotSupport" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 416, + "kind": "theorem", + "name": "CoreReader.Evidence.selfAssertionNotReason" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 426, + "kind": "theorem", + "name": "CoreReader.Evidence.valueWithoutSelfProof" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 434, + "kind": "abbrev", + "name": "CoreReader.Evidence.BenefitCostWorld" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 435, + "kind": "def", + "name": "CoreReader.Evidence.measuredOutcome" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 437, + "kind": "def", + "name": "CoreReader.Evidence.benefitReason" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 439, + "kind": "def", + "name": "CoreReader.Evidence.costReason" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 442, + "kind": "def", + "name": "CoreReader.Evidence.jointReasonPosition" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 456, + "kind": "theorem", + "name": "CoreReader.Evidence.jointReasonProcedure" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 477, + "kind": "def", + "name": "CoreReader.Evidence.JointReasonsExample" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 485, + "kind": "theorem", + "name": "CoreReader.Evidence.jointReasonsExample" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 492, + "kind": "theorem", + "name": "CoreReader.Evidence.heterogeneousReasons" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 500, + "kind": "def", + "name": "CoreReader.Evidence.zeroRecord" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 501, + "kind": "def", + "name": "CoreReader.Evidence.localGenerator" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 503, + "kind": "def", + "name": "CoreReader.Evidence.allTrue" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 504, + "kind": "theorem", + "name": "CoreReader.Evidence.zeroCompatible" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 509, + "kind": "structure", + "name": "CoreReader.Evidence.GeneratingProcess" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 514, + "kind": "def", + "name": "CoreReader.Evidence.GeneratingProcess.outputRevision" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 517, + "kind": "structure", + "name": "CoreReader.Evidence.ProducedRevision" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 522, + "kind": "def", + "name": "CoreReader.Evidence.GeneratingProcess.produce" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 524, + "kind": "def", + "name": "CoreReader.Evidence.sampleGeneratingProcess" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 526, + "kind": "def", + "name": "CoreReader.Evidence.OwnedRevisionExample" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 535, + "kind": "theorem", + "name": "CoreReader.Evidence.ownedRevisionExample" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 541, + "kind": "theorem", + "name": "CoreReader.Evidence.selfOriginDoesNotSupport" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 550, + "kind": "theorem", + "name": "CoreReader.Evidence.localNotUniversal" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 560, + "kind": "theorem", + "name": "CoreReader.Evidence.hiddenDifference" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 566, + "kind": "theorem", + "name": "CoreReader.Evidence.singleObservation" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 573, + "kind": "def", + "name": "CoreReader.Evidence.arithmeticFacet" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 574, + "kind": "def", + "name": "CoreReader.Evidence.usesObservation" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 578, + "kind": "theorem", + "name": "CoreReader.Evidence.noUniversalChain" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 585, + "kind": "structure", + "name": "CoreReader.Evidence.Trial" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 590, + "kind": "def", + "name": "CoreReader.Evidence.Verified" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 591, + "kind": "def", + "name": "CoreReader.Evidence.Reproduced" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 592, + "kind": "def", + "name": "CoreReader.Evidence.Bounded" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 594, + "kind": "theorem", + "name": "CoreReader.Evidence.variableOutcomesStableBound" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 600, + "kind": "theorem", + "name": "CoreReader.Evidence.verificationReproductionStability" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 606, + "kind": "inductive", + "name": "CoreReader.Evidence.Program" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 609, + "kind": "def", + "name": "CoreReader.Evidence.Program.eval" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 613, + "kind": "structure", + "name": "CoreReader.Evidence.Process" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 617, + "kind": "def", + "name": "CoreReader.Evidence.OutputContract" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 619, + "kind": "def", + "name": "CoreReader.Evidence.ExplanationContract" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 622, + "kind": "def", + "name": "CoreReader.Evidence.outputOnlyProcess" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 623, + "kind": "def", + "name": "CoreReader.Evidence.explainedProcess" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 625, + "kind": "def", + "name": "CoreReader.Evidence.processScope" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 628, + "kind": "def", + "name": "CoreReader.Evidence.processContractFacet" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 631, + "kind": "theorem", + "name": "CoreReader.Evidence.processScopeModels" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 635, + "kind": "theorem", + "name": "CoreReader.Evidence.processContractDischarged" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 643, + "kind": "def", + "name": "CoreReader.Evidence.ProcessGrounds" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 646, + "kind": "theorem", + "name": "CoreReader.Evidence.processGrounds" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 654, + "kind": "theorem", + "name": "CoreReader.Evidence.outputCorrectByEvaluation" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 656, + "kind": "theorem", + "name": "CoreReader.Evidence.outputOnlyNoExplanation" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 659, + "kind": "def", + "name": "CoreReader.Evidence.FullProcessContract" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 661, + "kind": "def", + "name": "CoreReader.Evidence.OutputContractEvidence" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 666, + "kind": "theorem", + "name": "CoreReader.Evidence.outputContractEvidence" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 671, + "kind": "def", + "name": "CoreReader.Evidence.ScopedApplicationEvidence" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 678, + "kind": "theorem", + "name": "CoreReader.Evidence.scopedApplicationEvidence" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 684, + "kind": "theorem", + "name": "CoreReader.Evidence.outputNotExplanation" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 688, + "kind": "theorem", + "name": "CoreReader.Evidence.applicationContractsDiffer" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 695, + "kind": "structure", + "name": "CoreReader.Evidence.ExternalCertificate" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 701, + "kind": "def", + "name": "CoreReader.Evidence.externalOutputCertificate" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 704, + "kind": "theorem", + "name": "CoreReader.Evidence.externalAssessment" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 715, + "kind": "def", + "name": "CoreReader.Evidence.arithmeticArticulation" + }, + { + "file": "CoreReader/Evidence.lean", + "line": 717, + "kind": "theorem", + "name": "CoreReader.Evidence.nonExecutableAssessment" + }, + { + "file": "CoreReader/Integration.lean", + "line": 8, + "kind": "theorem", + "name": "CoreReader.Integration.canonicalGrounds" + }, + { + "file": "CoreReader/Integration.lean", + "line": 15, + "kind": "theorem", + "name": "CoreReader.Integration.canonicalGroundsForSingleton" + }, + { + "file": "CoreReader/Integration.lean", + "line": 24, + "kind": "inductive", + "name": "CoreReader.Integration.Mode" + }, + { + "file": "CoreReader/Integration.lean", + "line": 28, + "kind": "abbrev", + "name": "CoreReader.Integration.World" + }, + { + "file": "CoreReader/Integration.lean", + "line": 30, + "kind": "def", + "name": "CoreReader.Integration.actual" + }, + { + "file": "CoreReader/Integration.lean", + "line": 33, + "kind": "structure", + "name": "CoreReader.Integration.Method" + }, + { + "file": "CoreReader/Integration.lean", + "line": 38, + "kind": "structure", + "name": "CoreReader.Integration.System" + }, + { + "file": "CoreReader/Integration.lean", + "line": 45, + "kind": "def", + "name": "CoreReader.Integration.policyFor" + }, + { + "file": "CoreReader/Integration.lean", + "line": 49, + "kind": "def", + "name": "CoreReader.Integration.workFor" + }, + { + "file": "CoreReader/Integration.lean", + "line": 53, + "kind": "def", + "name": "CoreReader.Integration.System.policy" + }, + { + "file": "CoreReader/Integration.lean", + "line": 54, + "kind": "def", + "name": "CoreReader.Integration.System.rules" + }, + { + "file": "CoreReader/Integration.lean", + "line": 55, + "kind": "def", + "name": "CoreReader.Integration.System.work" + }, + { + "file": "CoreReader/Integration.lean", + "line": 57, + "kind": "def", + "name": "CoreReader.Integration.actualSystem" + }, + { + "file": "CoreReader/Integration.lean", + "line": 64, + "kind": "def", + "name": "CoreReader.Integration.systemCapability" + }, + { + "file": "CoreReader/Integration.lean", + "line": 67, + "kind": "def", + "name": "CoreReader.Integration.systemBudget" + }, + { + "file": "CoreReader/Integration.lean", + "line": 70, + "kind": "def", + "name": "CoreReader.Integration.systemObservation" + }, + { + "file": "CoreReader/Integration.lean", + "line": 73, + "kind": "def", + "name": "CoreReader.Integration.systemHeld" + }, + { + "file": "CoreReader/Integration.lean", + "line": 76, + "kind": "inductive", + "name": "CoreReader.Integration.Question" + }, + { + "file": "CoreReader/Integration.lean", + "line": 79, + "kind": "def", + "name": "CoreReader.Integration.systemContext" + }, + { + "file": "CoreReader/Integration.lean", + "line": 84, + "kind": "abbrev", + "name": "CoreReader.Integration.capability" + }, + { + "file": "CoreReader/Integration.lean", + "line": 85, + "kind": "abbrev", + "name": "CoreReader.Integration.observation" + }, + { + "file": "CoreReader/Integration.lean", + "line": 86, + "kind": "abbrev", + "name": "CoreReader.Integration.held" + }, + { + "file": "CoreReader/Integration.lean", + "line": 87, + "kind": "abbrev", + "name": "CoreReader.Integration.context" + }, + { + "file": "CoreReader/Integration.lean", + "line": 90, + "kind": "theorem", + "name": "CoreReader.Integration.observationIdentifies" + }, + { + "file": "CoreReader/Integration.lean", + "line": 95, + "kind": "theorem", + "name": "CoreReader.Integration.capabilityActual" + }, + { + "file": "CoreReader/Integration.lean", + "line": 97, + "kind": "theorem", + "name": "CoreReader.Integration.observedCapability" + }, + { + "file": "CoreReader/Integration.lean", + "line": 105, + "kind": "def", + "name": "CoreReader.Integration.capabilityFacet" + }, + { + "file": "CoreReader/Integration.lean", + "line": 107, + "kind": "theorem", + "name": "CoreReader.Integration.capabilityFacetChecked" + }, + { + "file": "CoreReader/Integration.lean", + "line": 111, + "kind": "theorem", + "name": "CoreReader.Integration.capabilityGrounds" + }, + { + "file": "CoreReader/Integration.lean", + "line": 115, + "kind": "theorem", + "name": "CoreReader.Integration.actualAdmissible" + }, + { + "file": "CoreReader/Integration.lean", + "line": 120, + "kind": "theorem", + "name": "CoreReader.Integration.jointConsistent" + }, + { + "file": "CoreReader/Integration.lean", + "line": 124, + "kind": "def", + "name": "CoreReader.Integration.Charter" + }, + { + "file": "CoreReader/Integration.lean", + "line": 129, + "kind": "theorem", + "name": "CoreReader.Integration.charterChecked" + }, + { + "file": "CoreReader/Integration.lean", + "line": 133, + "kind": "def", + "name": "CoreReader.Integration.revisedHeld" + }, + { + "file": "CoreReader/Integration.lean", + "line": 136, + "kind": "def", + "name": "CoreReader.Integration.initialSnapshot" + }, + { + "file": "CoreReader/Integration.lean", + "line": 137, + "kind": "def", + "name": "CoreReader.Integration.revisedSnapshot" + }, + { + "file": "CoreReader/Integration.lean", + "line": 139, + "kind": "theorem", + "name": "CoreReader.Integration.revisionKeepsConsistency" + }, + { + "file": "CoreReader/Integration.lean", + "line": 151, + "kind": "def", + "name": "CoreReader.Integration.OwnCapabilityDuty" + }, + { + "file": "CoreReader/Integration.lean", + "line": 155, + "kind": "theorem", + "name": "CoreReader.Integration.ownCapabilityGrounded" + }, + { + "file": "CoreReader/Integration.lean", + "line": 163, + "kind": "def", + "name": "CoreReader.Integration.costAllowanceRecord" + }, + { + "file": "CoreReader/Integration.lean", + "line": 166, + "kind": "def", + "name": "CoreReader.Integration.unsupportedCapabilityFacet" + }, + { + "file": "CoreReader/Integration.lean", + "line": 169, + "kind": "theorem", + "name": "CoreReader.Integration.costCompatibleWithFailure" + }, + { + "file": "CoreReader/Integration.lean", + "line": 175, + "kind": "theorem", + "name": "CoreReader.Integration.costDoesNotSupportOutput" + }, + { + "file": "CoreReader/Integration.lean", + "line": 180, + "kind": "theorem", + "name": "CoreReader.Integration.unsupportedGrounds" + }, + { + "file": "CoreReader/Integration.lean", + "line": 187, + "kind": "inductive", + "name": "CoreReader.Integration.Commitment" + }, + { + "file": "CoreReader/Integration.lean", + "line": 191, + "kind": "def", + "name": "CoreReader.Integration.groundsPermission" + }, + { + "file": "CoreReader/Integration.lean", + "line": 197, + "kind": "def", + "name": "CoreReader.Integration.GroundsProvision" + }, + { + "file": "CoreReader/Integration.lean", + "line": 201, + "kind": "theorem", + "name": "CoreReader.Integration.groundsProvisionMeaning" + }, + { + "file": "CoreReader/Integration.lean", + "line": 212, + "kind": "def", + "name": "CoreReader.Integration.consistencyPermission" + }, + { + "file": "CoreReader/Integration.lean", + "line": 215, + "kind": "def", + "name": "CoreReader.Integration.conflictingHeld" + }, + { + "file": "CoreReader/Integration.lean", + "line": 217, + "kind": "theorem", + "name": "CoreReader.Integration.conflictConsequences" + }, + { + "file": "CoreReader/Integration.lean", + "line": 223, + "kind": "theorem", + "name": "CoreReader.Integration.conflictingHeldInconsistent" + }, + { + "file": "CoreReader/Integration.lean", + "line": 227, + "kind": "def", + "name": "CoreReader.Integration.choicePermission" + }, + { + "file": "CoreReader/Integration.lean", + "line": 231, + "kind": "def", + "name": "CoreReader.Integration.proposedOperation" + }, + { + "file": "CoreReader/Integration.lean", + "line": 235, + "kind": "def", + "name": "CoreReader.Integration.selfSamples" + }, + { + "file": "CoreReader/Integration.lean", + "line": 239, + "kind": "def", + "name": "CoreReader.Integration.conflictDecision" + }, + { + "file": "CoreReader/Integration.lean", + "line": 242, + "kind": "def", + "name": "CoreReader.Integration.groundsDecision" + }, + { + "file": "CoreReader/Integration.lean", + "line": 246, + "kind": "def", + "name": "CoreReader.Integration.choiceDecision" + }, + { + "file": "CoreReader/Integration.lean", + "line": 249, + "kind": "theorem", + "name": "CoreReader.Integration.decisionsApply" + }, + { + "file": "CoreReader/Integration.lean", + "line": 261, + "kind": "theorem", + "name": "CoreReader.Integration.decisionsWaive" + }, + { + "file": "CoreReader/Integration.lean", + "line": 272, + "kind": "def", + "name": "CoreReader.Integration.commitmentPositionFor" + }, + { + "file": "CoreReader/Integration.lean", + "line": 329, + "kind": "def", + "name": "CoreReader.Integration.commitmentPosition" + }, + { + "file": "CoreReader/Integration.lean", + "line": 332, + "kind": "theorem", + "name": "CoreReader.Integration.positionReasons" + }, + { + "file": "CoreReader/Integration.lean", + "line": 346, + "kind": "theorem", + "name": "CoreReader.Integration.positionConsequence" + }, + { + "file": "CoreReader/Integration.lean", + "line": 354, + "kind": "theorem", + "name": "CoreReader.Integration.positionProcedure" + }, + { + "file": "CoreReader/Integration.lean", + "line": 367, + "kind": "theorem", + "name": "CoreReader.Integration.criticismWithinScope" + }, + { + "file": "CoreReader/Integration.lean", + "line": 379, + "kind": "theorem", + "name": "CoreReader.Integration.oppositeConsequenceFails" + }, + { + "file": "CoreReader/Integration.lean", + "line": 398, + "kind": "theorem", + "name": "CoreReader.Integration.oppositeProcedureRejected" + }, + { + "file": "CoreReader/Integration.lean", + "line": 404, + "kind": "def", + "name": "CoreReader.Integration.commitmentClaim" + }, + { + "file": "CoreReader/Integration.lean", + "line": 406, + "kind": "def", + "name": "CoreReader.Integration.commitmentFacet" + }, + { + "file": "CoreReader/Integration.lean", + "line": 408, + "kind": "theorem", + "name": "CoreReader.Integration.reasonsBelongToCommitments" + }, + { + "file": "CoreReader/Integration.lean", + "line": 418, + "kind": "theorem", + "name": "CoreReader.Integration.groundsCommitmentIsProvision" + }, + { + "file": "CoreReader/Integration.lean", + "line": 423, + "kind": "theorem", + "name": "CoreReader.Integration.groundsSelfAssessment" + }, + { + "file": "CoreReader/Integration.lean", + "line": 436, + "kind": "structure", + "name": "CoreReader.Integration.PhilosophyMethod" + }, + { + "file": "CoreReader/Integration.lean", + "line": 440, + "kind": "def", + "name": "CoreReader.Integration.currentPhilosophy" + }, + { + "file": "CoreReader/Integration.lean", + "line": 443, + "kind": "def", + "name": "CoreReader.Integration.PhilosophyMethod.review" + }, + { + "file": "CoreReader/Integration.lean", + "line": 448, + "kind": "def", + "name": "CoreReader.Integration.PhilosophyMethod.implementation" + }, + { + "file": "CoreReader/Integration.lean", + "line": 458, + "kind": "def", + "name": "CoreReader.Integration.proposalRequirements" + }, + { + "file": "CoreReader/Integration.lean", + "line": 464, + "kind": "theorem", + "name": "CoreReader.Integration.currentReviewCorrect" + }, + { + "file": "CoreReader/Integration.lean", + "line": 472, + "kind": "theorem", + "name": "CoreReader.Integration.existingPhilosophyNotPrivileged" + }, + { + "file": "CoreReader/Integration.lean", + "line": 487, + "kind": "def", + "name": "CoreReader.Integration.applicationClaim" + }, + { + "file": "CoreReader/Integration.lean", + "line": 491, + "kind": "def", + "name": "CoreReader.Integration.ApplicationDuties" + }, + { + "file": "CoreReader/Integration.lean", + "line": 499, + "kind": "theorem", + "name": "CoreReader.Integration.applicationRetainsDuties" + }, + { + "file": "CoreReader/Integration.lean", + "line": 510, + "kind": "def", + "name": "CoreReader.Integration.outputContract" + }, + { + "file": "CoreReader/Integration.lean", + "line": 513, + "kind": "def", + "name": "CoreReader.Integration.successorRequirements" + }, + { + "file": "CoreReader/Integration.lean", + "line": 517, + "kind": "def", + "name": "CoreReader.Integration.changedObjectiveFacet" + }, + { + "file": "CoreReader/Integration.lean", + "line": 521, + "kind": "theorem", + "name": "CoreReader.Integration.applicationVariation" + }, + { + "file": "CoreReader/Integration.lean", + "line": 537, + "kind": "theorem", + "name": "CoreReader.Integration.charterNotGrounds" + }, + { + "file": "CoreReader/Integration.lean", + "line": 546, + "kind": "theorem", + "name": "CoreReader.Integration.jointWitness" + }, + { + "file": "CoreReader/Logic.lean", + "line": 4, + "kind": "abbrev", + "name": "CoreReader.Logic.Claim" + }, + { + "file": "CoreReader/Logic.lean", + "line": 6, + "kind": "abbrev", + "name": "CoreReader.Logic.Theory" + }, + { + "file": "CoreReader/Logic.lean", + "line": 8, + "kind": "def", + "name": "CoreReader.Logic.Models" + }, + { + "file": "CoreReader/Logic.lean", + "line": 10, + "kind": "def", + "name": "CoreReader.Logic.Entails" + }, + { + "file": "CoreReader/Logic.lean", + "line": 12, + "kind": "def", + "name": "CoreReader.Logic.Satisfiable" + }, + { + "file": "CoreReader/Logic.lean", + "line": 14, + "kind": "structure", + "name": "CoreReader.Logic.Context" + }, + { + "file": "CoreReader/Logic.lean", + "line": 19, + "kind": "def", + "name": "CoreReader.Logic.Admissible" + }, + { + "file": "CoreReader/Logic.lean", + "line": 22, + "kind": "def", + "name": "CoreReader.Logic.Consequence" + }, + { + "file": "CoreReader/Logic.lean", + "line": 25, + "kind": "def", + "name": "CoreReader.Logic.Consistent" + }, + { + "file": "CoreReader/Logic.lean", + "line": 28, + "kind": "theorem", + "name": "CoreReader.Logic.consequenceConsistency" + }, + { + "file": "CoreReader/Logic.lean", + "line": 34, + "kind": "def", + "name": "CoreReader.Logic.emptyTheory" + }, + { + "file": "CoreReader/Logic.lean", + "line": 35, + "kind": "def", + "name": "CoreReader.Logic.singleton" + }, + { + "file": "CoreReader/Logic.lean", + "line": 36, + "kind": "def", + "name": "CoreReader.Logic.union" + }, + { + "file": "CoreReader/Logic.lean", + "line": 37, + "kind": "theorem", + "name": "CoreReader.Logic.modelsSingleton" + }, + { + "file": "CoreReader/Logic.lean", + "line": 41, + "kind": "theorem", + "name": "CoreReader.Logic.modelsUnion" + }, + { + "file": "CoreReader/Logic.lean", + "line": 47, + "kind": "def", + "name": "CoreReader.Logic.premiseP" + }, + { + "file": "CoreReader/Logic.lean", + "line": 48, + "kind": "def", + "name": "CoreReader.Logic.premiseRule" + }, + { + "file": "CoreReader/Logic.lean", + "line": 49, + "kind": "def", + "name": "CoreReader.Logic.premiseNotQ" + }, + { + "file": "CoreReader/Logic.lean", + "line": 50, + "kind": "def", + "name": "CoreReader.Logic.jointTheory" + }, + { + "file": "CoreReader/Logic.lean", + "line": 53, + "kind": "theorem", + "name": "CoreReader.Logic.jointConflict" + }, + { + "file": "CoreReader/Logic.lean", + "line": 65, + "kind": "def", + "name": "CoreReader.Logic.revisionSlice" + }, + { + "file": "CoreReader/Logic.lean", + "line": 68, + "kind": "theorem", + "name": "CoreReader.Logic.revisionCanReverse" + }, + { + "file": "CoreReader/Logic.lean", + "line": 80, + "kind": "def", + "name": "CoreReader.Logic.onQuestion" + }, + { + "file": "CoreReader/Logic.lean", + "line": 81, + "kind": "def", + "name": "CoreReader.Logic.assumptionContext" + }, + { + "file": "CoreReader/Logic.lean", + "line": 83, + "kind": "def", + "name": "CoreReader.Logic.meaningContext" + }, + { + "file": "CoreReader/Logic.lean", + "line": 85, + "kind": "def", + "name": "CoreReader.Logic.scopeContext" + }, + { + "file": "CoreReader/Logic.lean", + "line": 88, + "kind": "theorem", + "name": "CoreReader.Logic.contextDifferences" + }, + { + "file": "CoreReader/Logic.lean", + "line": 110, + "kind": "structure", + "name": "CoreReader.Logic.Snapshot" + }, + { + "file": "CoreReader/Logic.lean", + "line": 115, + "kind": "def", + "name": "CoreReader.Logic.SameContent" + }, + { + "file": "CoreReader/Logic.lean", + "line": 121, + "kind": "def", + "name": "CoreReader.Logic.TruthfulReport" + }, + { + "file": "CoreReader/Logic.lean", + "line": 124, + "kind": "theorem", + "name": "CoreReader.Logic.semanticChangeMustBeReported" + }, + { + "file": "CoreReader/Logic.lean", + "line": 128, + "kind": "theorem", + "name": "CoreReader.Logic.representationOrderIrrelevant" + }, + { + "file": "CoreReader/Logic.lean", + "line": 131, + "kind": "def", + "name": "CoreReader.Logic.contextSnapshot" + }, + { + "file": "CoreReader/Logic.lean", + "line": 134, + "kind": "theorem", + "name": "CoreReader.Logic.hiddenContextChangeRejected" + }, + { + "file": "CoreReader/Logic.lean", + "line": 157, + "kind": "theorem", + "name": "CoreReader.Logic.tensionWithoutContradiction" + }, + { + "file": "CoreReader/Logic.lean", + "line": 163, + "kind": "theorem", + "name": "CoreReader.Logic.conflictRequiresChange" + }, + { + "file": "CoreReader/Logic.lean", + "line": 167, + "kind": "theorem", + "name": "CoreReader.Logic.consistentFalse" + }, + { + "file": "CoreReader/Logic.lean", + "line": 172, + "kind": "theorem", + "name": "CoreReader.Logic.consistentIncomplete" + }, + { + "file": "CoreReader/Logic.lean", + "line": 180, + "kind": "theorem", + "name": "CoreReader.Logic.compatibilityNotEntailment" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 5, + "kind": "inductive", + "name": "CoreReader.Agency.Phase" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 8, + "kind": "structure", + "name": "CoreReader.Agency.PrincipleKey" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 13, + "kind": "inductive", + "name": "CoreReader.Agency.Subject" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 19, + "kind": "def", + "name": "CoreReader.Agency.Subject.owner" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 24, + "kind": "inductive", + "name": "CoreReader.Agency.Activity" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 27, + "kind": "inductive", + "name": "CoreReader.Agency.QuestionKind" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 30, + "kind": "inductive", + "name": "CoreReader.Agency.SampleProgram" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 33, + "kind": "def", + "name": "CoreReader.Agency.SampleProgram.run" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 38, + "kind": "structure", + "name": "CoreReader.Agency.MethodDraft" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 43, + "kind": "def", + "name": "CoreReader.Agency.MethodDraft.accepts" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 47, + "kind": "structure", + "name": "CoreReader.Agency.Inquiry" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 54, + "kind": "inductive", + "name": "CoreReader.Agency.ReasonContent" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 61, + "kind": "def", + "name": "CoreReader.Agency.ReasonContent.identifier" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 68, + "kind": "structure", + "name": "CoreReader.Agency.ReasonObject" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 74, + "kind": "inductive", + "name": "CoreReader.Agency.AssessmentResult" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 77, + "kind": "inductive", + "name": "CoreReader.Agency.WorkOutcome" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 84, + "kind": "structure", + "name": "CoreReader.Agency.Principle" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 94, + "kind": "structure", + "name": "CoreReader.Agency.WorkRecord" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 104, + "kind": "def", + "name": "CoreReader.Agency.RegistryCoherent" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 107, + "kind": "def", + "name": "CoreReader.Agency.TargetResolved" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 113, + "kind": "def", + "name": "CoreReader.Agency.TargetContentResolved" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 119, + "kind": "def", + "name": "CoreReader.Agency.Performed" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 123, + "kind": "def", + "name": "CoreReader.Agency.ReflexiveScope" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 128, + "kind": "structure", + "name": "CoreReader.Agency.ValidApplication" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 146, + "kind": "def", + "name": "CoreReader.Agency.Reflexive" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 151, + "kind": "theorem", + "name": "CoreReader.Agency.Reflexive.toScope" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 157, + "kind": "theorem", + "name": "CoreReader.Agency.noSelfExemption" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 162, + "kind": "def", + "name": "CoreReader.Agency.localMethod" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 164, + "kind": "def", + "name": "CoreReader.Agency.inquiryFor" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 172, + "kind": "def", + "name": "CoreReader.Agency.sourceReasonContents" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 178, + "kind": "def", + "name": "CoreReader.Agency.reasonsFor" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 183, + "kind": "def", + "name": "CoreReader.Agency.assessInquiry" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 208, + "kind": "def", + "name": "CoreReader.Agency.finiteMethodResult" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 214, + "kind": "def", + "name": "CoreReader.Agency.finiteMethodMeaning" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 218, + "kind": "def", + "name": "CoreReader.Agency.ownSubjects" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 224, + "kind": "def", + "name": "CoreReader.Agency.generationEligible" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 228, + "kind": "def", + "name": "CoreReader.Agency.generatingRule" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 238, + "kind": "def", + "name": "CoreReader.Agency.assessingRule" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 248, + "kind": "def", + "name": "CoreReader.Agency.ownRules" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 251, + "kind": "def", + "name": "CoreReader.Agency.statedOutcome" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 258, + "kind": "def", + "name": "CoreReader.Agency.recordFor" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 261, + "kind": "theorem", + "name": "CoreReader.Agency.reasonsFor_nonempty" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 267, + "kind": "theorem", + "name": "CoreReader.Agency.reasonsFor_target" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 272, + "kind": "theorem", + "name": "CoreReader.Agency.inquiryFor_target" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 279, + "kind": "theorem", + "name": "CoreReader.Agency.ownContentEvaluates" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 289, + "kind": "theorem", + "name": "CoreReader.Agency.ownRegistryCoherent" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 298, + "kind": "theorem", + "name": "CoreReader.Agency.ownTargetResolved" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 304, + "kind": "theorem", + "name": "CoreReader.Agency.ownTargetContent" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 310, + "kind": "theorem", + "name": "CoreReader.Agency.ownRecordValid" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 343, + "kind": "def", + "name": "CoreReader.Agency.completeOwnWork" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 348, + "kind": "theorem", + "name": "CoreReader.Agency.assessingRecord_member" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 354, + "kind": "theorem", + "name": "CoreReader.Agency.generatingRecord_member" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 358, + "kind": "theorem", + "name": "CoreReader.Agency.completeOwnWork_reflexive" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 368, + "kind": "theorem", + "name": "CoreReader.Agency.ownAssessmentPerformed" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 372, + "kind": "def", + "name": "CoreReader.Agency.applicationRule" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 375, + "kind": "def", + "name": "CoreReader.Agency.applicationWork" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 377, + "kind": "theorem", + "name": "CoreReader.Agency.applicationWork_reflexive" + }, + { + "file": "CoreReader/Reflexivity.lean", + "line": 396, + "kind": "theorem", + "name": "CoreReader.Agency.applicabilityRetained" + } +] diff --git a/SoftwareEngineering/lean/philosophy/reviews/r3-probe-input.txt b/SoftwareEngineering/lean/philosophy/reviews/r3-probe-input.txt new file mode 100644 index 0000000..2a6fb3a --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/r3-probe-input.txt @@ -0,0 +1,42 @@ +import CoreReader +open CoreReader.Engineering CoreReader.Adopted CoreReader.Logic +#eval (explainedWithoutVariation012.answer 3 1, mechanismResponder012.answer 3 1) +example : explainedWithoutVariation012.process = mechanismResponder012.process := rfl +example : ¬ UnderstandingApplication012 explainedWithoutVariation012 := explainedWithoutVariationFails012 +example : UnderstandingApplication012 mechanismResponder012 := mechanismResponderUnderstands012 +#eval (boundaryObligationChecked boundaryDesign .coordinated coordinatedBoundary, + boundaryObligationChecked omittedCallerCheck .coordinated coordinatedBoundary, + crossesBoundary otherCalleeDesign .coordinated otherCalleeBoundary, + boundaryObligationChecked { boundaryDesign with run := sortedUnique } .coordinated coordinatedBoundary) +#eval (coordinatedBoundary.caller, coordinatedBoundary.callee, + (boundaryDesign.paths .coordinated).map (fun step => (step.component, step.tool, step.requires))) +example (ctx : CoreReader.Engineering.Context) (chosen : CoreReader.Engineering.Candidate) + (h : Inherited ctx chosen) : + consistencySpecification (engineeringSnapshot .evolvable 0) (engineeringSnapshot chosen 1) true := by + have all := inheritedMutualApplication ctx chosen h + exact all.2.2.2.2.2.2.2.2 +example (ctx : CoreReader.Engineering.Context) (chosen : CoreReader.Engineering.Candidate) + (h : Inherited ctx chosen) (d : DomainSatisfied ctx chosen) + (a : PriorityConditions ctx) (n : ¬ JustifiedDeparture ctx .evolvable) : + Grounds012 (EvolutionPriority ctx) CoreReader.Evidence.canonicalArticulation + [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) := by + have all := priorityRemainsReflexive ctx chosen h d a n + exact all.2.2.2.2.1 +example (ctx : CoreReader.Engineering.Context) (chosen : CoreReader.Engineering.Candidate) + (h : Inherited ctx chosen) (d : DomainSatisfied ctx chosen) + (a : PriorityConditions ctx) (n : ¬ JustifiedDeparture ctx .evolvable) : + consistencySpecification (engineeringSnapshot .evolvable 0) (engineeringSnapshot chosen 1) true := by + have all := priorityRemainsReflexive ctx chosen h d a n + exact all.2.2.2.2.2.2 +#eval (generationRuleTest Reflection.generate (.evolvable, 10), + generationRuleTest (fun _ => .generated [] []) (.evolvable, 10), + assessmentRuleTest Reflection.evaluate (.evolvable, 10), + assessmentRuleTest Reflection.evaluate (.evolvable, 5), + assessmentRuleTest sampleAwareAssessment (.evolvable, 5)) +#eval Reflection.evaluate ((selfModel .evolvable).input ⟨0, .assessmentRule, .revision⟩) +example : ownTheory .evolvable (ownNormClaim .evolvable .domain) := + allNormativeContentHeld .evolvable .domain rfl +example : ¬ ownTheory .presentSimple (ownNormClaim .presentSimple .domain) := + normativeContentVariation.2.2.2.2.2 +example : ¬ Consistent incompatibleNormTheory incompatibleNormContext := + normativeContentVariation.2.1 diff --git a/SoftwareEngineering/lean/philosophy/reviews/r3-probes.log b/SoftwareEngineering/lean/philosophy/reviews/r3-probes.log new file mode 100644 index 0000000..dbd9993 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/r3-probes.log @@ -0,0 +1,13 @@ +$ lake env lean --stdin +(2, 3) +(true, false, false, false) +(2, + 1, + [(0, CoreReader.Engineering.Tool.editor, CoreReader.Engineering.Knowledge.changeGuide), + (0, CoreReader.Engineering.Tool.contractRunner, CoreReader.Engineering.Knowledge.publicContract), + (1, CoreReader.Engineering.Tool.compiler, CoreReader.Engineering.Knowledge.changeGuide), + (2, CoreReader.Engineering.Tool.contractRunner, CoreReader.Engineering.Knowledge.publicContract)]) +(true, false, true, false, true) +CoreReader.Engineering.Reflection.Verdict.counterexample + +exit_code=0 diff --git a/SoftwareEngineering/lean/philosophy/reviews/r3-stability-probe-input.txt b/SoftwareEngineering/lean/philosophy/reviews/r3-stability-probe-input.txt new file mode 100644 index 0000000..d923da9 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/r3-stability-probe-input.txt @@ -0,0 +1,7 @@ +import CoreReader +open CoreReader.Engineering CoreReader.Adopted +example : (revisionFor sharedContext .evolvable).old.choice = + (revisionFor sharedContext .evolvable).current.choice ∧ + reflexivitySpecification (selfModel .evolvable).rules (selfModel .evolvable).self + (selfModel .evolvable).performed := + ⟨rfl, currentSelfApplication .evolvable (Or.inr rfl)⟩ diff --git a/SoftwareEngineering/lean/philosophy/reviews/r3-stability-probe.log b/SoftwareEngineering/lean/philosophy/reviews/r3-stability-probe.log new file mode 100644 index 0000000..6c8dbb7 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/r3-stability-probe.log @@ -0,0 +1,2 @@ + +exit_code=0 diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-comparison.json b/SoftwareEngineering/lean/philosophy/reviews/reader-comparison.json new file mode 100644 index 0000000..3cd30fe --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-comparison.json @@ -0,0 +1,88 @@ +{ + "utc": "2026-09-14T18:51:11.516847+00:00", + "prior_independent_json_sha256": "9b3fb49a28d4e658ac6b5b9b8c89aadb82d246d04a53ba6b9e7087d6e1c8df4b", + "preserves_independent_r1": true, + "comparison_inputs": { + "reader-independent-source-review-r1.md": "2933d9049854ac3905a75493cecde9e72689a6883f337ca5f1da3f4da1ac8096", + "reader-independent-source-review-r2-components.md": "998c8a9aca43571ec4e094ef49d3b6e19c026f82f62aae2e727743812e1e0588", + "reader-independent-domain-r1.md": "2c411fb38eef7f4637c9c243930b4f30029b059893056518607e767cd851dae8", + "reader-independent-domain-r1-granularity-clarification.json": "9d6c9b64c164a072203911b24ced32e9e32bf47a2d82a5706771934c5faa6f6a" + }, + "corrections_to_own_r1": [ + { + "item": "Question2", + "prior": "fixed-double responder fails at input3/multiplier1", + "corrected": "The encoded negative witness is multiplier3/input1. UnderstandingApplication012 quantifies forall multiplier input, and explainedWithoutVariationFails012 applies h.2.2 3 1; actual computed answer is2 against expected3.", + "effect": "The prior pair can also refute the universal claim, but is not the encoded witness. This corrects the answer and execution attribution; it does not change the bounded non-entailment conclusion." + }, + { + "item": "Question6 and coverage conclusion", + "prior": "sampled EN/ZH sections preserve qualifications", + "corrected": "The initial read missed material overstatements in T35/T36 that the source/domain reviewers located. Corrected confidence is limited to the accurately checked claims; final global reader approval requires their actual prose corrections.", + "effect": "Do not treat all six answers or navigation success as proof of full reader semantic correctness." + } + ], + "comparison": [ + { + "finding": "source R01 / T24", + "decision": "agree", + "ground": "Read Domain49–54,107–113,307–313: all listed participants and per-step knowledge/tools are required in the common nonempty path, plus actual nonempty identity/tool conditions. Short shorthand omitted recoverable premises.", + "scope": "target prose" + }, + { + "finding": "source R02 / T29", + "decision": "agree", + "ground": "Read Domain556–575: EvolutionClaim has CanChange/contract/check/preserve-revise terms; actual transform equations are separate conjuncts.", + "scope": "target prose" + }, + { + "finding": "source R03 and domain RD3 / T35", + "decision": "agree; missed in own initial read", + "ground": "Domain894–895 changes five material fields for one pair; Domain967–969 changes old and recordedOld. MaterialGroundsChanged is an OR, not isolated causal sufficiency or five separate trials.", + "scope": "target prose" + }, + { + "finding": "source R04 / T36", + "decision": "agree; missed in own initial read", + "ground": "Already read/check revisionLimits: valid account, stable choice, considered criticism and bounded retention do not prove actual revisability. Other integrated self-application results must remain distinct.", + "scope": "target prose" + }, + { + "finding": "source R05 / Adopted692,1314", + "decision": "agree", + "ground": "Read original source context: both are within a negated status-only choice claim; positive method-reason branch starts later.", + "scope": "2 repeated EN/ZH line explanations" + }, + { + "finding": "domain RD1 / conditional safety limit", + "decision": "agree on source type; independent probe not rerun here", + "ground": "Domain353–357 only negate PriorityConditions; DomainSatisfied1034–1041 has no unconditional Meets term. This comparison uses the other reviewer actual unsafe-profile probe as separately attributed evidence.", + "scope": "3 line explanations; no claim code now rejects unsafe profiles" + }, + { + "finding": "domain RD2 / insertOrdered", + "decision": "agree", + "ground": "Domain424 actual type has arbitrary List Nat input; sortedness is not a binder or enforced domain. This matches own Reflection DecidableEq finding: explanations must retain actual implicit premises and must not invent input premises.", + "scope": "line explanation" + }, + { + "finding": "domain RD4 clarification", + "decision": "agree with narrowed necessity", + "ground": "Dispatch over Change/Burden is not merely a single branch. Repeated otherwise accurate match/filter block summaries may be less locally informative but do not automatically create new semantic or completion obligations. Locality refinements298–301/710–713 are optional quality improvements, not separate blockers.", + "scope": "2 necessary dispatch mappings; optional remainder" + }, + { + "finding": "own R1–R3", + "decision": "retain", + "ground": "Other reviews do not contradict generated DecidableEq W premise, raw input owner freedom, or named boundary predicate distinction. Await rebuilt prose before closure.", + "scope": "reader prose only" + } + ], + "component_status": "Other source reviewer r2-components reports its five changes narrowly verified. Parent reports remaining Domain/root prose patches. This comparison does not claim to have verified those changed component bytes or current rebuilt four views; that is the next bounded scope.", + "method_implication": "Actual cases reveal content/explanation defects covered by existing source-faithfulness and reader rules; their existence alone does not justify adding a new method prohibition. Keep original two skills/checker recommendation unchanged on current bounded evidence. Six-dimensional limits retain different source, formal, empirical, value and reflective claims; reviewer agreement is not philosophical proof.", + "pending": [ + "Final four-view hashes and changed-scope proof/code/manuscript comparison.", + "Fresh six actual lookups on final views; corrected multiplier/input answer.", + "V10 root ordinary-copy full public closure actual run; not established by V8 or this comparison." + ] +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-comparison.md b/SoftwareEngineering/lean/philosophy/reviews/reader-comparison.md new file mode 100644 index 0000000..abaa6c2 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-comparison.md @@ -0,0 +1,23 @@ +# Reader comparison r2, preserving independent r1 + +The initial independent record remains unchanged. This comparison was written only after its SHA-256 was given to root. + +Own Question2 correction: the actual encoded counterexample is **multiplier=3, input=1**, producing answer2 against expected3. The initial input3/multiplier1 wording misidentified the encoded witness. `understanding-order-correction-r2-probe.json` records actual Lean execution exit0. + +The initial read also missed T35/T36 overstatements; broad confidence in sampled qualifications is narrowed accordingly. Navigation success and independent agreement do not establish semantic correctness. + +- source R01 / T24: agree. Read Domain49–54,107–113,307–313: all listed participants and per-step knowledge/tools are required in the common nonempty path, plus actual nonempty identity/tool conditions. Short shorthand omitted recoverable premises. +- source R02 / T29: agree. Read Domain556–575: EvolutionClaim has CanChange/contract/check/preserve-revise terms; actual transform equations are separate conjuncts. +- source R03 and domain RD3 / T35: agree; missed in own initial read. Domain894–895 changes five material fields for one pair; Domain967–969 changes old and recordedOld. MaterialGroundsChanged is an OR, not isolated causal sufficiency or five separate trials. +- source R04 / T36: agree; missed in own initial read. Already read/check revisionLimits: valid account, stable choice, considered criticism and bounded retention do not prove actual revisability. Other integrated self-application results must remain distinct. +- source R05 / Adopted692,1314: agree. Read original source context: both are within a negated status-only choice claim; positive method-reason branch starts later. +- domain RD1 / conditional safety limit: agree on source type; independent probe not rerun here. Domain353–357 only negate PriorityConditions; DomainSatisfied1034–1041 has no unconditional Meets term. This comparison uses the other reviewer actual unsafe-profile probe as separately attributed evidence. +- domain RD2 / insertOrdered: agree. Domain424 actual type has arbitrary List Nat input; sortedness is not a binder or enforced domain. This matches own Reflection DecidableEq finding: explanations must retain actual implicit premises and must not invent input premises. +- domain RD4 clarification: agree with narrowed necessity. Dispatch over Change/Burden is not merely a single branch. Repeated otherwise accurate match/filter block summaries may be less locally informative but do not automatically create new semantic or completion obligations. Locality refinements298–301/710–713 are optional quality improvements, not separate blockers. +- own R1–R3: retain. Other reviews do not contradict generated DecidableEq W premise, raw input owner freedom, or named boundary predicate distinction. Await rebuilt prose before closure. + +Other source reviewer r2-components reports its five changes narrowly verified. Parent reports remaining Domain/root prose patches. This comparison does not claim to have verified those changed component bytes or current rebuilt four views; that is the next bounded scope. + +Actual cases reveal content/explanation defects covered by existing source-faithfulness and reader rules; their existence alone does not justify adding a new method prohibition. Keep original two skills/checker recommendation unchanged on current bounded evidence. Six-dimensional limits retain different source, formal, empirical, value and reflective claims; reviewer agreement is not philosophical proof. + +Pending: Final four-view hashes and changed-scope proof/code/manuscript comparison. Fresh six actual lookups on final views; corrected multiplier/input answer. V10 root ordinary-copy full public closure actual run; not established by V8 or this comparison. diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-final-overall.json b/SoftwareEngineering/lean/philosophy/reviews/reader-final-overall.json new file mode 100644 index 0000000..1d4633f --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-final-overall.json @@ -0,0 +1,322 @@ +{ + "schema_version": 1, + "stage": "independent final changed-scope and six-task reader QA", + "utc": "2026-09-14T18:55:39.687712+00:00", + "verdict": "accepted_with_disclosed_scope", + "remaining_necessary_reader_findings": [], + "bindings": { + "views": { + "lean/philosophy/overview.md": "c8b01525a54a9beb78086a17652ea4ded4740dad956a0a9a4f9c0ae3ee7171a2", + "lean/philosophy/details.md": "1b8d07cbbf3a0e7005821bc2261f89b1675d43a053802e8b779b1930e0d782af", + "zh/lean/philosophy/overview.md": "31fd96fd034ab16e92d3ecc600237bf9f27fcddaff754b308e4ca14573b58a61", + "zh/lean/philosophy/details.md": "5eba3d944c7bcef294bfed822e6c4aa8205e3e238157da5fb95365bbb57169ff" + }, + "source_current_sha256": "6c6ae78a23f2726c5c370434e808d76c206647fe7793245e88cae52c076abe34", + "source_snapshot_sha256": "6c6ae78a23f2726c5c370434e808d76c206647fe7793245e88cae52c076abe34", + "source_metadata": { + "format_version": "0.1.0", + "philosophy_version": "0.2.0", + "core_version": "0.1.2", + "derived_from": { + "source_id": "https://github.com/shendeguize/OrganonCore", + "philosophy_version": "0.1.2", + "content_hash": "cb23f8a44d6b877ff9b5385961ff8e5fa788f8021ae267cdc8e305870ec20ca7" + } + }, + "targets_sha256": "c0939df35dad148a0543ba92a1ac7b7d3b2eb4946f92ac4be251ec51b6481d13", + "code_files": { + "leanified/CoreReader/Adopted.lean": "8de4d364bb3c64e29ab92e81d86cbe4c9e5af49ada3dad262d1378421fb588c2", + "leanified/CoreReader/Agency.lean": "2722c34645f4256f20ce31205738f2f5712ab5dd5cc6fcf9f1180d0be5aa0303", + "leanified/CoreReader/Choice.lean": "b28728df12ed7e73edb5569604cd2541c0ebd815ae3aaa0812e6557dece1d1ba", + "leanified/CoreReader/Engineering/Domain.lean": "ce5653a2950cc7443cefbfe8b9726bd4859228e831ddb7d42601e501ccbfd855", + "leanified/CoreReader/Engineering/Integration.lean": "a2b88062148b3f7ebea7da02d88cb29cb04d8f1b2e9e6b97bb2420ac2c006328", + "leanified/CoreReader/Engineering/Reflection.lean": "c290d8472884d00bedbf945f0fc1866524e758740f40d42088c4ff9678a93fa2", + "leanified/CoreReader/Engineering/SelfApplication.lean": "d69c0d369bd4fd8db4c21ce3b65abb5e9efd07ed5ab9a68d56b4db39bb9d2a21", + "leanified/CoreReader/Engineering/Values.lean": "ccd45bf23d2f47c41d1b2f9955d753e290687d951a0c55af41ab9a63b9a8d9cb", + "leanified/CoreReader/Evidence.lean": "d55f33e44902cef146841cbffb65710bd7c8a3bda79d01d084edc36f019fdc96", + "leanified/CoreReader/Integration.lean": "97e2939c0b6714b78a3ed78358e174619a5028ad5b0b5025c0d4422b4294921b", + "leanified/CoreReader/Logic.lean": "0ec342691766ebd83d251dcd0da3b0ae9840aed677a714bc1b01c45d89392bc0", + "leanified/CoreReader/Reflexivity.lean": "48e2c74e7cbae571db1b990b9f32dd0d701f6881a8b0111d907f8861287d76fa", + "leanified/CoreReader.lean": "c5574fae235419a7d6449b3ebb5d2da29d1e92a3b572c1b759438e3c470caaa9" + }, + "run_json_sha256": "661ee91e1727a628c9e5933f6c6690011c575f99123b2a669ddb2b9c036a163d", + "observed_manifest_sha256": "1707734f6c51b9f7cd802ba8b84ed2a4d80fb6a7617d53eac081568689fee0c1", + "manifest_binding_role": "Observed r2 manifest identifies what was read. Reader approval binds source/code/targets/four-view bytes; later addition of a public review may change manifest/review metadata without circularly binding the review to its own container." + }, + "independence": "Reviewer authored none of the SE reader prose. Preserved own independent r1 precedes comparison with source/domain reviewers. Source-aware review; not fresh blind backtranslation.", + "coverage": { + "own_full_initial_EN_ZH_nonblank_root4": { + "Reflection": 113, + "SelfApplication": 203, + "Values": 201, + "Integration": 547, + "total": 1064 + }, + "own_final_review": "Complete four-view diff read in both languages; two changed root4 captions and T31 exact predicate independently rechecked against code and saved actual probes. All unchanged root4 interpretation reused only after exact code/old-new caption identity checks. Fresh final lookups locate and extract final sections; unchanged semantic readings are reused with diff identity disclosed.", + "Adopted": "Source reviewer independently read1225 EN/ZH nonblank lines. Final embedding now matches its accepted component at every entry; this agent freshly checked the two corrected negative-branch captions and their source, and selected strongest understanding material. Not claimed this agent independently reread all1225 lines.", + "Domain": "Domain reviewer independently read902 EN/ZH nonblank lines and accepted14 changed entries. This agent read every final changed caption/target statement and matching important source definitions; exact902-entry embedding matches that accepted component. Unchanged902-line semantic QA/probes remain attributed to the other reviewer.", + "helpers": "Six helper modules unchanged in final diff. Source reviewer reports2178 nonblank code/caption identity matches per language to prior Core readers and bounded fresh semantic review. Its Evidence233–605 subset was identity-reused without new full semantic reread; that limit is retained. This agent does not claim fresh full helper re-review.", + "entry_root_module": "The root module import line is structurally covered by manuscript checker; not one of root4 semantic modules." + }, + "changes": { + "target_narrative_ids": [ + "T24", + "T29", + "T31", + "T35", + "T36" + ], + "root4_caption_changes": { + "Engineering/Reflection.lean": [ + 35 + ], + "Engineering/SelfApplication.lean": [ + 115 + ] + }, + "Adopted_caption_changes": [ + 692, + 1314 + ], + "Domain_caption_changes": [ + 88, + 244, + 298, + 299, + 300, + 301, + 353, + 424, + 710, + 711, + 712, + 713, + 1034, + 1035 + ], + "other_view_lines": "unchanged by complete four-view diff", + "source_code_targets": "unchanged against preserved complete r1 positive object" + }, + "component_embedding": [ + { + "language": "en", + "group": "Adopted", + "component_sha256": "aa4f297fb4250cf8cf1883092f74152fb6567a5b9ec4ee74dae7a8f28b1fb9b9", + "entries": 1225, + "mismatches": [] + }, + { + "language": "en", + "group": "Domain", + "component_sha256": "d1773e14c9e68a81850a9a949f11ab3722dcb3a4c2bd8c663ecf1e8102d3c471", + "entries": 902, + "mismatches": [] + }, + { + "language": "en", + "group": "root4", + "component_sha256": "022cfcd09aee3ea4f2f608628ebe52846bea02c18430e647c5b388477fe5db79", + "entries": 1064, + "mismatches": [] + }, + { + "language": "zh", + "group": "Adopted", + "component_sha256": "69ae42b723e8fd901701c32226d7daa6adb879923ce29e8d4b58ebf58d724714", + "entries": 1225, + "mismatches": [] + }, + { + "language": "zh", + "group": "Domain", + "component_sha256": "24bf6725f169fad4ec28f335296c0e95c3212136e46ec3ad0974f61a32820c85", + "entries": 902, + "mismatches": [] + }, + { + "language": "zh", + "group": "root4", + "component_sha256": "838a2675fc1bcad5441d89197aeeca9bdaee9c536011230bcb8d087780f79923", + "entries": 1064, + "mismatches": [] + } + ], + "narrative_embedding": [ + { + "target": "T24", + "language": "en", + "granularity": "overview", + "all_fields_exact": true + }, + { + "target": "T24", + "language": "en", + "granularity": "details", + "all_fields_exact": true + }, + { + "target": "T24", + "language": "zh", + "granularity": "overview", + "all_fields_exact": true + }, + { + "target": "T24", + "language": "zh", + "granularity": "details", + "all_fields_exact": true + }, + { + "target": "T29", + "language": "en", + "granularity": "overview", + "all_fields_exact": true + }, + { + "target": "T29", + "language": "en", + "granularity": "details", + "all_fields_exact": true + }, + { + "target": "T29", + "language": "zh", + "granularity": "overview", + "all_fields_exact": true + }, + { + "target": "T29", + "language": "zh", + "granularity": "details", + "all_fields_exact": true + }, + { + "target": "T35", + "language": "en", + "granularity": "overview", + "all_fields_exact": true + }, + { + "target": "T35", + "language": "en", + "granularity": "details", + "all_fields_exact": true + }, + { + "target": "T35", + "language": "zh", + "granularity": "overview", + "all_fields_exact": true + }, + { + "target": "T35", + "language": "zh", + "granularity": "details", + "all_fields_exact": true + }, + { + "target": "T36", + "language": "en", + "granularity": "overview", + "all_fields_exact": true + }, + { + "target": "T36", + "language": "en", + "granularity": "details", + "all_fields_exact": true + }, + { + "target": "T36", + "language": "zh", + "granularity": "overview", + "all_fields_exact": true + }, + { + "target": "T36", + "language": "zh", + "granularity": "details", + "all_fields_exact": true + } + ], + "actual_lookup_count": 32, + "answers": [ + { + "id": 1, + "targets": [ + "T38", + "T39" + ], + "answer": "T38 existentially selects sharedContext and evolvable once, then jointly supplies full Inherited and DomainSatisfied for those same objects. T39 fixes the same context and presentSimple, explicitly retaining continuing and non-bounded lifecycle, all priority conditions, both necessary requirements, actual successor/agent paths, no threat and no justified departure. It adds the supported, adopted current-simplicity value and proves actual EvolutionPriority false. It establishes represented inherited-duty non-entailment, not permission for an already committed SE adopter to ignore DomainSatisfied. OwnTheory jointly holds applicable actual norms and facts; sameContext bounds the interpretation.", + "status": "answered on final bound views; bounded source-aware reader judgment" + }, + { + "id": 2, + "targets": [ + "T16" + ], + "answer": "Both applications share explainedProcess and FullProcessContract. UnderstandingApplication012 additionally requires correct answers for every multiplier then input, plus the actual process relation to multiplication by2. The encoded negative witness is multiplier=3/input=1: the fixed-double responder returns2 versus mechanism012 expected3. The correct responder satisfies the selected stronger application and same-task Grounds; identity alone does not discharge the contract. No universal psychological understanding claim follows. This corrects the swapped variable names in the preserved r1 answer.", + "status": "answered on final bound views; bounded source-aware reader judgment" + }, + { + "id": 3, + "targets": [ + "T31" + ], + "answer": "At T31, actual callee1 editing causes crossing and caller2 performs the public-contract verification. Removing that check preserves crossesBoundary=true but makes boundaryObligationChecked=false; final EN/ZH now names that exact predicate. Sorting actual output also fails its finite contract conjunct. Changing the callee to untouched7 changes crossing applicability. These finite checks are not universal preservation or all real boundary-cost estimates.", + "status": "answered on final bound views; bounded source-aware reader judgment" + }, + { + "id": 4, + "targets": [ + "T20", + "T37" + ], + "answer": "T20/T37 and the actual root4 line anchors identify generationRule and assessmentRule as real own review objects whose tests inspect the current generator/evaluator. Generation follows its applicability predicate rather than every phase. The declared local empty-sample assessment-contract failure is retained as a revision counterexample. Generation proposes samples/scope; it proves neither proposal success nor philosophical correctness. The final owner explanation correctly separates model owner0/self relation from raw Model.input accepting owner99, and Outcome equality now retains [DecidableEq W].", + "status": "answered on final bound views; bounded source-aware reader judgment" + }, + { + "id": 5, + "targets": [ + "T33", + "T34", + "T35", + "T36" + ], + "answer": "T34 receives forall x,scope x -> new x=old x and returns the same premise as PreservesOn; finite order/retry cases do not prove universal equality. T33 identifies actual affected parties, including the operator, and a missed excluded input99. T35 now correctly describes one old/new pair changing all five material grounds together, separates the OR guard from adequate justification, and names old/recordedOld tampering against fixed independent observedHistory. T36 preserves historical failure and truthful stable choice/criticism coverage without claiming this case proves actual revisability. Later valid support may support a later correctly scoped claim, but cannot make the recorded failed arithmetic true.", + "status": "answered on final bound views; bounded source-aware reader judgment" + }, + { + "id": 6, + "targets": [ + "T01", + "T02", + "T20", + "T34", + "T39", + "T40" + ], + "answer": "Both final overviews state SE0.2.0/adopted Core0.1.2 and distinguish accepted target review, limited source correspondence, incomplete material and Lean passed. Actual final navigation resolves the six tasks through32 EN/ZH target lookups and their declaration-line anchors. T02 normative specification, T20 full-Inherited projection, T34 identity on supplied equality, T39 finite countermodel and T01/T40 nonformal boundaries retain different proof force. The corrected T24/T29/T35/T36 text and exact component captions are embedded in both granularities. Build/structural success is not presented as philosophical truth or whole-source complete proof.", + "status": "answered on final bound views; bounded source-aware reader judgment" + } + ], + "review_comparison": "All own R1–R3 and source R01–R05 plus necessary Domain RD1–RD4 corrections are resolved in the actual bound manuscripts. Optional locality improvements are accurately embedded but are not retroactively treated as new blocking obligations. Initial Q2 variable order and missed T35/T36 precision issues remain explicitly corrected in comparison-r2.", + "checker_evidence": { + "source": "parent-executed manuscript-check-r2.json", + "sha256": "51c7ae98aa284718cb5948876865c2a41faa80ad7f2d66c6fc939a7ec7b58cac", + "observed_passed": true, + "reuse": "No new Lean build is needed for prose-only changes with13 exact unchanged code hashes and frozen targets; own V8 complete positive/kernel runs plus parent r2 checker result are attributed separately." + }, + "limits": [ + "Acceptance concerns the bound reader objects and disclosed coverage, not philosophical correctness, universal empirical adequacy, or a completeness guarantee for the methods.", + "Final public portable reference closure V10 remains separately owned and executed by root; this review does not claim its completion.", + "If source, code, targets or any four-view bytes change, this acceptance must be re-evaluated for the actual changed scope; mere manifest/public-review metadata changes do not silently grant new semantic approval." + ], + "evidence_files": { + "actual_final_probes_sha256": "9fe82b010e045ac290ae43d471ac61ae8bb422777d3b78387b3592df93c79b84", + "own_initial_sha256": "9b3fb49a28d4e658ac6b5b9b8c89aadb82d246d04a53ba6b9e7087d6e1c8df4b", + "own_comparison_sha256": "f0dc87c1cc3b85bfce1475219b2b63a4508d8986c47fd39125dcf3b57d550368", + "source_component_review_sha256": "2cd4fbdee43dff496a9099fe8d7186e6d133689c346e34f9c0c60d2a81ba6cea", + "domain_component_review_sha256": "44b4697d44a5f28ca501f868e08680dfbf7614092860e87daa28c37a1fe30f82" + } +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-final-overall.md b/SoftwareEngineering/lean/philosophy/reviews/reader-final-overall.md new file mode 100644 index 0000000..aaf31f3 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-final-overall.md @@ -0,0 +1,42 @@ +# Independent final reader QA r3 + +Accepted for the bound four manuscripts, with no remaining necessary reader finding. The exact source,13 code files and40 frozen targets are unchanged. The observed r2 manifest is recorded for execution identity; acceptance binds the four view/source/code/target hashes directly to avoid a review–manifest hash cycle. + +The complete four-view diff was read in EN/ZH. Own root4 initial semantic coverage was1064 nonblank lines in each language; both changed root captions and T31 now accurately retain the actual typeclass, ownership and boundary-predicate conditions. All final Adopted1225/Domain902/root41064 component entries in each language exactly match the accepted source objects; agreement of bytes supports reuse, not semantic correctness by itself. + +Other coverage is attributed: source reviewer covers Adopted and bounded helpers; Domain reviewer covers Domain. Evidence helper233–605 was exact-identity reuse rather than fresh complete semantic reread. This agent does not claim authorship or independent full semantic re-review of those materials. + +## Lookup 1 + +T38 existentially selects sharedContext and evolvable once, then jointly supplies full Inherited and DomainSatisfied for those same objects. T39 fixes the same context and presentSimple, explicitly retaining continuing and non-bounded lifecycle, all priority conditions, both necessary requirements, actual successor/agent paths, no threat and no justified departure. It adds the supported, adopted current-simplicity value and proves actual EvolutionPriority false. It establishes represented inherited-duty non-entailment, not permission for an already committed SE adopter to ignore DomainSatisfied. OwnTheory jointly holds applicable actual norms and facts; sameContext bounds the interpretation. + +## Lookup 2 + +Both applications share explainedProcess and FullProcessContract. UnderstandingApplication012 additionally requires correct answers for every multiplier then input, plus the actual process relation to multiplication by2. The encoded negative witness is multiplier=3/input=1: the fixed-double responder returns2 versus mechanism012 expected3. The correct responder satisfies the selected stronger application and same-task Grounds; identity alone does not discharge the contract. No universal psychological understanding claim follows. This corrects the swapped variable names in the preserved r1 answer. + +## Lookup 3 + +At T31, actual callee1 editing causes crossing and caller2 performs the public-contract verification. Removing that check preserves crossesBoundary=true but makes boundaryObligationChecked=false; final EN/ZH now names that exact predicate. Sorting actual output also fails its finite contract conjunct. Changing the callee to untouched7 changes crossing applicability. These finite checks are not universal preservation or all real boundary-cost estimates. + +## Lookup 4 + +T20/T37 and the actual root4 line anchors identify generationRule and assessmentRule as real own review objects whose tests inspect the current generator/evaluator. Generation follows its applicability predicate rather than every phase. The declared local empty-sample assessment-contract failure is retained as a revision counterexample. Generation proposes samples/scope; it proves neither proposal success nor philosophical correctness. The final owner explanation correctly separates model owner0/self relation from raw Model.input accepting owner99, and Outcome equality now retains [DecidableEq W]. + +## Lookup 5 + +T34 receives forall x,scope x -> new x=old x and returns the same premise as PreservesOn; finite order/retry cases do not prove universal equality. T33 identifies actual affected parties, including the operator, and a missed excluded input99. T35 now correctly describes one old/new pair changing all five material grounds together, separates the OR guard from adequate justification, and names old/recordedOld tampering against fixed independent observedHistory. T36 preserves historical failure and truthful stable choice/criticism coverage without claiming this case proves actual revisability. Later valid support may support a later correctly scoped claim, but cannot make the recorded failed arithmetic true. + +## Lookup 6 + +Both final overviews state SE0.2.0/adopted Core0.1.2 and distinguish accepted target review, limited source correspondence, incomplete material and Lean passed. Actual final navigation resolves the six tasks through32 EN/ZH target lookups and their declaration-line anchors. T02 normative specification, T20 full-Inherited projection, T34 identity on supplied equality, T39 finite countermodel and T01/T40 nonformal boundaries retain different proof force. The corrected T24/T29/T35/T36 text and exact component captions are embedded in both granularities. Build/structural success is not presented as philosophical truth or whole-source complete proof. + +## Object binding + +- `lean/philosophy/overview.md`: `c8b01525a54a9beb78086a17652ea4ded4740dad956a0a9a4f9c0ae3ee7171a2` +- `lean/philosophy/details.md`: `1b8d07cbbf3a0e7005821bc2261f89b1675d43a053802e8b779b1930e0d782af` +- `zh/lean/philosophy/overview.md`: `31fd96fd034ab16e92d3ecc600237bf9f27fcddaff754b308e4ca14573b58a61` +- `zh/lean/philosophy/details.md`: `5eba3d944c7bcef294bfed822e6c4aa8205e3e238157da5fb95365bbb57169ff` + +Observed manifest: `1707734f6c51b9f7cd802ba8b84ed2a4d80fb6a7617d53eac081568689fee0c1`. Source: `6c6ae78a23f2726c5c370434e808d76c206647fe7793245e88cae52c076abe34`. Targets: `c0939df35dad148a0543ba92a1ac7b7d3b2eb4946f92ac4be251ec51b6481d13`. Full code bindings and32 actual final lookup records are retained in JSON. + +V10 public portability is a separate actual root execution; this reader result does not establish it. The findings do not authorize philosophy, version, lock or code changes and do not prove philosophical correctness. diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-final-probes.json b/SoftwareEngineering/lean/philosophy/reviews/reader-final-probes.json new file mode 100644 index 0000000..57d8ab5 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-final-probes.json @@ -0,0 +1,725 @@ +{ + "utc": "2026-09-14T18:53:51.167406+00:00", + "view_expected_hashes": { + "lean/philosophy/overview.md": "c8b01525a54a9beb78086a17652ea4ded4740dad956a0a9a4f9c0ae3ee7171a2", + "lean/philosophy/details.md": "1b8d07cbbf3a0e7005821bc2261f89b1675d43a053802e8b779b1930e0d782af", + "zh/lean/philosophy/overview.md": "31fd96fd034ab16e92d3ecc600237bf9f27fcddaff754b308e4ca14573b58a61", + "zh/lean/philosophy/details.md": "5eba3d944c7bcef294bfed822e6c4aa8205e3e238157da5fb95365bbb57169ff" + }, + "components": [ + { + "language": "en", + "group": "Adopted", + "component_sha256": "aa4f297fb4250cf8cf1883092f74152fb6567a5b9ec4ee74dae7a8f28b1fb9b9", + "entries": 1225, + "mismatches": [] + }, + { + "language": "en", + "group": "Domain", + "component_sha256": "d1773e14c9e68a81850a9a949f11ab3722dcb3a4c2bd8c663ecf1e8102d3c471", + "entries": 902, + "mismatches": [] + }, + { + "language": "en", + "group": "root4", + "component_sha256": "022cfcd09aee3ea4f2f608628ebe52846bea02c18430e647c5b388477fe5db79", + "entries": 1064, + "mismatches": [] + }, + { + "language": "zh", + "group": "Adopted", + "component_sha256": "69ae42b723e8fd901701c32226d7daa6adb879923ce29e8d4b58ebf58d724714", + "entries": 1225, + "mismatches": [] + }, + { + "language": "zh", + "group": "Domain", + "component_sha256": "24bf6725f169fad4ec28f335296c0e95c3212136e46ec3ad0974f61a32820c85", + "entries": 902, + "mismatches": [] + }, + { + "language": "zh", + "group": "root4", + "component_sha256": "838a2675fc1bcad5441d89197aeeca9bdaee9c536011230bcb8d087780f79923", + "entries": 1064, + "mismatches": [] + } + ], + "narrative_embedding": [ + { + "target": "T24", + "language": "en", + "granularity": "overview", + "all_fields_exact": true + }, + { + "target": "T24", + "language": "en", + "granularity": "details", + "all_fields_exact": true + }, + { + "target": "T24", + "language": "zh", + "granularity": "overview", + "all_fields_exact": true + }, + { + "target": "T24", + "language": "zh", + "granularity": "details", + "all_fields_exact": true + }, + { + "target": "T29", + "language": "en", + "granularity": "overview", + "all_fields_exact": true + }, + { + "target": "T29", + "language": "en", + "granularity": "details", + "all_fields_exact": true + }, + { + "target": "T29", + "language": "zh", + "granularity": "overview", + "all_fields_exact": true + }, + { + "target": "T29", + "language": "zh", + "granularity": "details", + "all_fields_exact": true + }, + { + "target": "T35", + "language": "en", + "granularity": "overview", + "all_fields_exact": true + }, + { + "target": "T35", + "language": "en", + "granularity": "details", + "all_fields_exact": true + }, + { + "target": "T35", + "language": "zh", + "granularity": "overview", + "all_fields_exact": true + }, + { + "target": "T35", + "language": "zh", + "granularity": "details", + "all_fields_exact": true + }, + { + "target": "T36", + "language": "en", + "granularity": "overview", + "all_fields_exact": true + }, + { + "target": "T36", + "language": "en", + "granularity": "details", + "all_fields_exact": true + }, + { + "target": "T36", + "language": "zh", + "granularity": "overview", + "all_fields_exact": true + }, + { + "target": "T36", + "language": "zh", + "granularity": "details", + "all_fields_exact": true + } + ], + "lookup_records": [ + { + "question": 1, + "language": "en", + "target": "t38", + "overview_line": 720, + "detail_line": 1704, + "overview_text": "\n## T38 · One joint witness for all represented duties\n\nOne nonempty continuing context and its evolvable selection satisfy the full represented inherited and domain bundles together, with genuine applicable priority and extra present complexity.\n\n**Premises and representation:** The witness fixes sharedContext, all original assessment tasks and values, the whole facts/norms theory, successor and agent paths, satisfied requirements, credible design revision and no concrete cost threat.\n\n**Proof or check:** inheritedCurrent constructs every inherited field for evolvable; currentDomainSatisfied supplies the domain bundle. Explicit values check complexity 3 versus 1 and work 6 versus 17, nonempty own objects and admissibility of that same chosen candidate.\n\n**Limits:** This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\n**State:** accepted (satisfiability). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [organon.charter.overview#p2](#source-organon-charter-overview-p2), [organon.charter.overview#p3](#source-organon-charter-overview-p3), [organon.charter.self-transcendence#p1](#source-organon-charter-self-transcendence-p1), [organon.charter.self-transcendence.orientation#p1](#source-organon-charter-self-transcendence-orientation-p1), [organon.charter.self-transcendence.non-finality#p1](#source-organon-charter-self-transcendence-non-finality-p1), [organon.charter.self-transcendence.limits#p1](#source-organon-charter-self-transcendence-limits-p1), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.charter.consistency#p1](#source-organon-charter-consistency-p1), [organon.charter.consistency.meaning#p1](#source-organon-charter-consistency-meaning-p1), [organon.charter.consistency.meaning#p2](#source-organon-charter-consistency-meaning-p2), [organon.charter.consistency.limits#p1](#source-organon-charter-consistency-limits-p1), [organon.charter.reflexivity#p1](#source-organon-charter-reflexivity-p1), [organon.charter.reflexivity.meaning#p1](#source-organon-charter-reflexivity-meaning-p1), [organon.charter.reflexivity.limits#p1](#source-organon-charter-reflexivity-limits-p1), [organon.grounds#p1](#source-organon-grounds-p1), [organon.grounds.assessment#p1](#source-organon-grounds-assessment-p1), [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3), [organon.grounds.scope#p1](#source-organon-grounds-scope-p1), [organon.grounds.scope#p2](#source-organon-grounds-scope-p2), [organon.grounds.scope#p3](#source-organon-grounds-scope-p3), [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2), [organon.grounds.implementations#p1](#source-organon-grounds-implementations-p1), [organon.grounds.implementations#p2](#source-organon-grounds-implementations-p2), [organon.grounds.implementations.limits#p1](#source-organon-grounds-implementations-limits-p1), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.purpose#p1](#source-software-engineering-purpose-p1), [software-engineering.purpose#p2](#source-software-engineering-purpose-p2), [software-engineering.purpose#p3](#source-software-engineering-purpose-p3), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3), [software-engineering.evolution-meaning#p1](#source-software-engineering-evolution-meaning-p1), [software-engineering.evolution-meaning#p2](#source-software-engineering-evolution-meaning-p2), [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2), [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3), [software-engineering.revision#p1](#source-software-engineering-revision-p1), [software-engineering.revision#p2](#source-software-engineering-revision-p2)\n\n[Declarations, proof and line explanations](details.md#t38)\n\n\n", + "detail_text": "\n## T38 · One joint witness for all represented duties\n\nOne nonempty continuing context and its evolvable selection satisfy the full represented inherited and domain bundles together, with genuine applicable priority and extra present complexity.\n\n**Premises and representation:** The witness fixes sharedContext, all original assessment tasks and values, the whole facts/norms theory, successor and agent paths, satisfied requirements, credible design revision and no concrete cost threat.\n\n**Proof or check:** inheritedCurrent constructs every inherited field for evolvable; currentDomainSatisfied supplies the domain bundle. Explicit values check complexity 3 versus 1 and work 6 versus 17, nonempty own objects and admissibility of that same chosen candidate.\n\n**Limits:** This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\n**State:** accepted (satisfiability). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [organon.charter.overview#p2](#source-organon-charter-overview-p2), [organon.charter.overview#p3](#source-organon-charter-overview-p3), [organon.charter.self-transcendence#p1](#source-organon-charter-self-transcendence-p1), [organon.charter.self-transcendence.orientation#p1](#source-organon-charter-self-transcendence-orientation-p1), [organon.charter.self-transcendence.non-finality#p1](#source-organon-charter-self-transcendence-non-finality-p1), [organon.charter.self-transcendence.limits#p1](#source-organon-charter-self-transcendence-limits-p1), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.charter.consistency#p1](#source-organon-charter-consistency-p1), [organon.charter.consistency.meaning#p1](#source-organon-charter-consistency-meaning-p1), [organon.charter.consistency.meaning#p2](#source-organon-charter-consistency-meaning-p2), [organon.charter.consistency.limits#p1](#source-organon-charter-consistency-limits-p1), [organon.charter.reflexivity#p1](#source-organon-charter-reflexivity-p1), [organon.charter.reflexivity.meaning#p1](#source-organon-charter-reflexivity-meaning-p1), [organon.charter.reflexivity.limits#p1](#source-organon-charter-reflexivity-limits-p1), [organon.grounds#p1](#source-organon-grounds-p1), [organon.grounds.assessment#p1](#source-organon-grounds-assessment-p1), [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3), [organon.grounds.scope#p1](#source-organon-grounds-scope-p1), [organon.grounds.scope#p2](#source-organon-grounds-scope-p2), [organon.grounds.scope#p3](#source-organon-grounds-scope-p3), [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2), [organon.grounds.implementations#p1](#source-organon-grounds-implementations-p1), [organon.grounds.implementations#p2](#source-organon-grounds-implementations-p2), [organon.grounds.implementations.limits#p1](#source-organon-grounds-implementations-limits-p1), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.purpose#p1](#source-software-engineering-purpose-p1), [software-engineering.purpose#p2](#source-software-engineering-purpose-p2), [software-engineering.purpose#p3](#source-software-engineering-purpose-p3), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3), [software-engineering.evolution-meaning#p1](#source-software-engineering-evolution-meaning-p1), [software-engineering.evolution-meaning#p2](#source-software-engineering-evolution-meaning-p2), [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2), [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3), [software-engineering.revision#p1](#source-software-engineering-revision-p1), [software-engineering.revision#p2](#source-software-engineering-revision-p2)\n\n### `CoreReader.Engineering.jointWitness`\n\n[leanified/CoreReader/Engineering/Integration.lean:557](#line-code-leanified-corereader-engineering-integration-lean-557) · case\n\nCore dependencies: `propext`, `Classical.choice`, `Quot.sound`.\n\n```lean\ntheorem jointWitness :\n ∃ ctx : Context, ∃ chosen : Candidate,\n ctx = sharedContext ∧ chosen = .evolvable ∧\n Inherited ctx chosen ∧ DomainSatisfied ctx chosen ∧\n PriorityConditions ctx ∧ ¬ HasThreat ctx .evolvable ∧\n abstractionComplexity .presentSimple < abstractionComplexity chosen ∧\n CanChange ctx.activity chosen .successor .designRevision ∧\n CanChange ctx.activity chosen .agent .designRevision ∧\n ownTheory chosen (ownFactClaim chosen .selected) ∧\n (.commitment .grounds : ReviewObject) ∈ (selfModel chosen).objects ∧\n Admissible (ownTheory chosen) (comparisonContext chosen) chosen := by\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-engineering-integration-lean-557", + "found": true + } + ] + }, + { + "question": 1, + "language": "en", + "target": "t39", + "overview_line": 738, + "detail_line": 1740, + "overview_text": "\n## T39 · Inherited duties do not force the added priority\n\nIn that same applicable continuing context, a presentSimple selection satisfies every represented inherited duty but does not adopt the additional evolution priority.\n\n**Premises and representation:** Both options meet necessary requirements; the evolution advantage, credible design revision, successor/agent paths and complexity tradeoff are real within the model. There is no temporary-lifecycle or cost-departure escape.\n\n**Proof or check:** inheritedCurrent constructs the whole inherited bundle for presentSimple. Its actually adopted simplicity value has cost/work reasons and criticism limits. Applying the domain rule would require evolvable or a departure; both are excluded, so EvolutionPriority is false.\n\n**Limits:** The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance.\n\n**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3)\n\n[Declarations, proof and line explanations](details.md#t39)\n\n\n", + "detail_text": "\n## T39 · Inherited duties do not force the added priority\n\nIn that same applicable continuing context, a presentSimple selection satisfies every represented inherited duty but does not adopt the additional evolution priority.\n\n**Premises and representation:** Both options meet necessary requirements; the evolution advantage, credible design revision, successor/agent paths and complexity tradeoff are real within the model. There is no temporary-lifecycle or cost-departure escape.\n\n**Proof or check:** inheritedCurrent constructs the whole inherited bundle for presentSimple. Its actually adopted simplicity value has cost/work reasons and criticism limits. Applying the domain rule would require evolvable or a departure; both are excluded, so EvolutionPriority is false.\n\n**Limits:** The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance.\n\n**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3)\n\n### `CoreReader.Engineering.inheritedDoesNotEntailPriority`\n\n[leanified/CoreReader/Engineering/Integration.lean:586](#line-code-leanified-corereader-engineering-integration-lean-586) · case\n\nCore dependencies: `propext`, `Classical.choice`, `Quot.sound`.\n\n```lean\ntheorem inheritedDoesNotEntailPriority :\n ∃ ctx : Context, ∃ chosen : Candidate,\n ctx = sharedContext ∧ chosen = .presentSimple ∧\n Inherited ctx chosen ∧ PriorityConditions ctx ∧\n Continuing ctx.activity ∧ ¬ BoundedLifecycle ctx.activity ∧\n ¬ HasThreat ctx .evolvable ∧ ¬ JustifiedDeparture ctx .evolvable ∧\n Meets ctx.required (ctx.profiles .presentSimple) ∧\n Meets ctx.required (ctx.profiles .evolvable) ∧\n credible ctx.evidence .designRevision ∧\n CanChange ctx.activity .evolvable .successor .designRevision ∧\n CanChange ctx.activity .evolvable .agent .designRevision ∧\n changeWork .evolvable .designRevision < changeWork chosen .designRevision ∧\n abstractionComplexity chosen < abstractionComplexity .evolvable ∧\n valueSpecification (selectionPosition chosen) ∧\n (selectionPosition chosen).commitment chosen ∧\n ¬ EvolutionPriority ctx chosen := by\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-engineering-integration-lean-586", + "found": true + } + ] + }, + { + "question": 1, + "language": "zh", + "target": "t38", + "overview_line": 720, + "detail_line": 1704, + "overview_text": "\n## T38 · 全部已表示义务的共同见证\n\n一个非空持续语境及其 evolvable 选择,同时满足已表示的完整继承和领域义务;优先确实适用,并接受额外当前复杂度。\n\n**前提与表示:** 见证固定 sharedContext、各原评估任务及价值、完整事实/规范理论、继任者和代理路径、满足的需求、可信设计修订及无具体成本威胁。\n\n**证明或检查:** inheritedCurrent 为 evolvable 构造每项继承字段;currentDomainSatisfied 提供领域义务。具体数值检查复杂度 3 对 1、工作量 6 对 17、非空自身对象及同一选项的可容许性。\n\n**限度:** 这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n**状态:** accepted (satisfiability). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [organon.charter.overview#p2](#source-organon-charter-overview-p2), [organon.charter.overview#p3](#source-organon-charter-overview-p3), [organon.charter.self-transcendence#p1](#source-organon-charter-self-transcendence-p1), [organon.charter.self-transcendence.orientation#p1](#source-organon-charter-self-transcendence-orientation-p1), [organon.charter.self-transcendence.non-finality#p1](#source-organon-charter-self-transcendence-non-finality-p1), [organon.charter.self-transcendence.limits#p1](#source-organon-charter-self-transcendence-limits-p1), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.charter.consistency#p1](#source-organon-charter-consistency-p1), [organon.charter.consistency.meaning#p1](#source-organon-charter-consistency-meaning-p1), [organon.charter.consistency.meaning#p2](#source-organon-charter-consistency-meaning-p2), [organon.charter.consistency.limits#p1](#source-organon-charter-consistency-limits-p1), [organon.charter.reflexivity#p1](#source-organon-charter-reflexivity-p1), [organon.charter.reflexivity.meaning#p1](#source-organon-charter-reflexivity-meaning-p1), [organon.charter.reflexivity.limits#p1](#source-organon-charter-reflexivity-limits-p1), [organon.grounds#p1](#source-organon-grounds-p1), [organon.grounds.assessment#p1](#source-organon-grounds-assessment-p1), [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3), [organon.grounds.scope#p1](#source-organon-grounds-scope-p1), [organon.grounds.scope#p2](#source-organon-grounds-scope-p2), [organon.grounds.scope#p3](#source-organon-grounds-scope-p3), [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2), [organon.grounds.implementations#p1](#source-organon-grounds-implementations-p1), [organon.grounds.implementations#p2](#source-organon-grounds-implementations-p2), [organon.grounds.implementations.limits#p1](#source-organon-grounds-implementations-limits-p1), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.purpose#p1](#source-software-engineering-purpose-p1), [software-engineering.purpose#p2](#source-software-engineering-purpose-p2), [software-engineering.purpose#p3](#source-software-engineering-purpose-p3), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3), [software-engineering.evolution-meaning#p1](#source-software-engineering-evolution-meaning-p1), [software-engineering.evolution-meaning#p2](#source-software-engineering-evolution-meaning-p2), [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2), [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3), [software-engineering.revision#p1](#source-software-engineering-revision-p1), [software-engineering.revision#p2](#source-software-engineering-revision-p2)\n\n[声明、证明与逐行解释](details.md#t38)\n\n\n", + "detail_text": "\n## T38 · 全部已表示义务的共同见证\n\n一个非空持续语境及其 evolvable 选择,同时满足已表示的完整继承和领域义务;优先确实适用,并接受额外当前复杂度。\n\n**前提与表示:** 见证固定 sharedContext、各原评估任务及价值、完整事实/规范理论、继任者和代理路径、满足的需求、可信设计修订及无具体成本威胁。\n\n**证明或检查:** inheritedCurrent 为 evolvable 构造每项继承字段;currentDomainSatisfied 提供领域义务。具体数值检查复杂度 3 对 1、工作量 6 对 17、非空自身对象及同一选项的可容许性。\n\n**限度:** 这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n**状态:** accepted (satisfiability). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [organon.charter.overview#p2](#source-organon-charter-overview-p2), [organon.charter.overview#p3](#source-organon-charter-overview-p3), [organon.charter.self-transcendence#p1](#source-organon-charter-self-transcendence-p1), [organon.charter.self-transcendence.orientation#p1](#source-organon-charter-self-transcendence-orientation-p1), [organon.charter.self-transcendence.non-finality#p1](#source-organon-charter-self-transcendence-non-finality-p1), [organon.charter.self-transcendence.limits#p1](#source-organon-charter-self-transcendence-limits-p1), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.charter.consistency#p1](#source-organon-charter-consistency-p1), [organon.charter.consistency.meaning#p1](#source-organon-charter-consistency-meaning-p1), [organon.charter.consistency.meaning#p2](#source-organon-charter-consistency-meaning-p2), [organon.charter.consistency.limits#p1](#source-organon-charter-consistency-limits-p1), [organon.charter.reflexivity#p1](#source-organon-charter-reflexivity-p1), [organon.charter.reflexivity.meaning#p1](#source-organon-charter-reflexivity-meaning-p1), [organon.charter.reflexivity.limits#p1](#source-organon-charter-reflexivity-limits-p1), [organon.grounds#p1](#source-organon-grounds-p1), [organon.grounds.assessment#p1](#source-organon-grounds-assessment-p1), [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3), [organon.grounds.scope#p1](#source-organon-grounds-scope-p1), [organon.grounds.scope#p2](#source-organon-grounds-scope-p2), [organon.grounds.scope#p3](#source-organon-grounds-scope-p3), [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2), [organon.grounds.implementations#p1](#source-organon-grounds-implementations-p1), [organon.grounds.implementations#p2](#source-organon-grounds-implementations-p2), [organon.grounds.implementations.limits#p1](#source-organon-grounds-implementations-limits-p1), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.purpose#p1](#source-software-engineering-purpose-p1), [software-engineering.purpose#p2](#source-software-engineering-purpose-p2), [software-engineering.purpose#p3](#source-software-engineering-purpose-p3), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3), [software-engineering.evolution-meaning#p1](#source-software-engineering-evolution-meaning-p1), [software-engineering.evolution-meaning#p2](#source-software-engineering-evolution-meaning-p2), [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2), [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3), [software-engineering.revision#p1](#source-software-engineering-revision-p1), [software-engineering.revision#p2](#source-software-engineering-revision-p2)\n\n### `CoreReader.Engineering.jointWitness`\n\n[leanified/CoreReader/Engineering/Integration.lean:557](#line-code-leanified-corereader-engineering-integration-lean-557) · case\n\n核心依赖: `propext`, `Classical.choice`, `Quot.sound`.\n\n```lean\ntheorem jointWitness :\n ∃ ctx : Context, ∃ chosen : Candidate,\n ctx = sharedContext ∧ chosen = .evolvable ∧\n Inherited ctx chosen ∧ DomainSatisfied ctx chosen ∧\n PriorityConditions ctx ∧ ¬ HasThreat ctx .evolvable ∧\n abstractionComplexity .presentSimple < abstractionComplexity chosen ∧\n CanChange ctx.activity chosen .successor .designRevision ∧\n CanChange ctx.activity chosen .agent .designRevision ∧\n ownTheory chosen (ownFactClaim chosen .selected) ∧\n (.commitment .grounds : ReviewObject) ∈ (selfModel chosen).objects ∧\n Admissible (ownTheory chosen) (comparisonContext chosen) chosen := by\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-engineering-integration-lean-557", + "found": true + } + ] + }, + { + "question": 1, + "language": "zh", + "target": "t39", + "overview_line": 738, + "detail_line": 1740, + "overview_text": "\n## T39 · 继承义务不强制附加优先\n\n在同一优先适用的持续语境内,presentSimple 选择满足每项已表示继承义务,却不采纳附加演化优先。\n\n**前提与表示:** 两选项均满足必要要求;演化优势、可信设计修订、继任者/代理路径及复杂度取舍在模型内真实成立。没有临时生命周期或成本让步逃逸。\n\n**证明或检查:** inheritedCurrent 为 presentSimple 构造完整继承义务。其实际采纳的简单性价值具有成本/工作理由及批评限度。领域规则要求 evolvable 或让步,而两者均被排除,因此 EvolutionPriority 为假。\n\n**限度:** 反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。\n\n**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3)\n\n[声明、证明与逐行解释](details.md#t39)\n\n\n", + "detail_text": "\n## T39 · 继承义务不强制附加优先\n\n在同一优先适用的持续语境内,presentSimple 选择满足每项已表示继承义务,却不采纳附加演化优先。\n\n**前提与表示:** 两选项均满足必要要求;演化优势、可信设计修订、继任者/代理路径及复杂度取舍在模型内真实成立。没有临时生命周期或成本让步逃逸。\n\n**证明或检查:** inheritedCurrent 为 presentSimple 构造完整继承义务。其实际采纳的简单性价值具有成本/工作理由及批评限度。领域规则要求 evolvable 或让步,而两者均被排除,因此 EvolutionPriority 为假。\n\n**限度:** 反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。\n\n**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3)\n\n### `CoreReader.Engineering.inheritedDoesNotEntailPriority`\n\n[leanified/CoreReader/Engineering/Integration.lean:586](#line-code-leanified-corereader-engineering-integration-lean-586) · case\n\n核心依赖: `propext`, `Classical.choice`, `Quot.sound`.\n\n```lean\ntheorem inheritedDoesNotEntailPriority :\n ∃ ctx : Context, ∃ chosen : Candidate,\n ctx = sharedContext ∧ chosen = .presentSimple ∧\n Inherited ctx chosen ∧ PriorityConditions ctx ∧\n Continuing ctx.activity ∧ ¬ BoundedLifecycle ctx.activity ∧\n ¬ HasThreat ctx .evolvable ∧ ¬ JustifiedDeparture ctx .evolvable ∧\n Meets ctx.required (ctx.profiles .presentSimple) ∧\n Meets ctx.required (ctx.profiles .evolvable) ∧\n credible ctx.evidence .designRevision ∧\n CanChange ctx.activity .evolvable .successor .designRevision ∧\n CanChange ctx.activity .evolvable .agent .designRevision ∧\n changeWork .evolvable .designRevision < changeWork chosen .designRevision ∧\n abstractionComplexity chosen < abstractionComplexity .evolvable ∧\n valueSpecification (selectionPosition chosen) ∧\n (selectionPosition chosen).commitment chosen ∧\n ¬ EvolutionPriority ctx chosen := by\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-engineering-integration-lean-586", + "found": true + } + ] + }, + { + "question": 2, + "language": "en", + "target": "t16", + "overview_line": 324, + "detail_line": 750, + "overview_text": "\n## T16 · Application-specific capability and understanding\n\nCapability claims retain their actual object, contract and grounds. An application may require more than reliable output or an output-equivalent explanation.\n\n**Premises and representation:** The output contract ranges over all natural inputs. A separate mechanism application defines operational understanding as explaining the same process and answering every input/multiplier variation; this is its selected criterion.\n\n**Proof or check:** ExternalCertificate checks output without introspection. Two mechanism objects share the same explainedProcess; the fixed-double responder fails at (3,1), while the mechanism responder proves the stronger contract and same-object Grounds012. The failing object also fails those same grounds.\n\n**Limits:** This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support.\n\n**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3)\n\n[Declarations, proof and line explanations](details.md#t16)\n\n\n", + "detail_text": "\n## T16 · Application-specific capability and understanding\n\nCapability claims retain their actual object, contract and grounds. An application may require more than reliable output or an output-equivalent explanation.\n\n**Premises and representation:** The output contract ranges over all natural inputs. A separate mechanism application defines operational understanding as explaining the same process and answering every input/multiplier variation; this is its selected criterion.\n\n**Proof or check:** ExternalCertificate checks output without introspection. Two mechanism objects share the same explainedProcess; the fixed-double responder fails at (3,1), while the mechanism responder proves the stronger contract and same-object Grounds012. The failing object also fails those same grounds.\n\n**Limits:** This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support.\n\n**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3)\n\n### `CoreReader.Adopted.capabilitySpecification`\n\n[leanified/CoreReader/Adopted.lean:205](#line-code-leanified-corereader-adopted-lean-205) · definition\n\nCore dependencies: `propext`.\n\n```lean\ndef capabilitySpecification (assessed : Process) (contract : Claim Process) : Prop :=\n```\n\n### `CoreReader.Adopted.capabilityCases012`\n\n[leanified/CoreReader/Adopted.lean:1232](#line-code-leanified-corereader-adopted-lean-1232) · case\n\nCore dependencies: `propext`.\n\n```lean\ntheorem capabilityCases012 :\n (capabilitySpecification outputOnlyProcess OutputContract ∧\n capabilitySpecification explainedProcess FullProcessContract ∧\n (∃ certificate : ExternalCertificate outputOnlyProcess,\n certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧\n ¬ ExplanationContract outputOnlyProcess) ∧\n (OwnCapability012 7 7 outputOnlyProcess OutputContract) ∧\n (explainedWithoutVariation012.process = mechanismResponder012.process ∧\n FullProcessContract explainedWithoutVariation012.process ∧\n ¬ UnderstandingApplication012 explainedWithoutVariation012 ∧\n UnderstandingApplication012 mechanismResponder012 ∧\n Grounds012 UnderstandingApplication012 canonicalArticulation\n [understandingFacet012 mechanismResponder012] (understandingTask012 mechanismResponder012) ∧\n ¬ Grounds012 UnderstandingApplication012 canonicalArticulation\n [understandingFacet012 explainedWithoutVariation012] (understandingTask012 explainedWithoutVariation012)) :=\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-adopted-lean-205", + "found": true + }, + { + "anchor": "line-code-leanified-corereader-adopted-lean-1232", + "found": true + } + ] + }, + { + "question": 2, + "language": "zh", + "target": "t16", + "overview_line": 324, + "detail_line": 750, + "overview_text": "\n## T16 · 应用特定的能力与理解\n\n能力主张保留实际对象、契约及根据;应用可以要求超出可靠输出或输出等价解释的能力。\n\n**前提与表示:** 输出契约覆盖所有自然数输入。另一个机制应用将操作性理解定义为解释同一过程,并正确回答所有输入与乘数变式;这是该应用选择的判准。\n\n**证明或检查:** ExternalCertificate 在无内省要求下检查输出。两个机制对象具有同一个 explainedProcess;固定翻倍回答者在 (3,1) 失败,机制回答者则证明更强契约及同对象 Grounds012;失败对象也不能获得该根据。\n\n**限度:** 这不是心理理解的普遍定义。精确身份是范围前提;履行支持责任的是实际契约证明,而非身份本身。\n\n**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3)\n\n[声明、证明与逐行解释](details.md#t16)\n\n\n", + "detail_text": "\n## T16 · 应用特定的能力与理解\n\n能力主张保留实际对象、契约及根据;应用可以要求超出可靠输出或输出等价解释的能力。\n\n**前提与表示:** 输出契约覆盖所有自然数输入。另一个机制应用将操作性理解定义为解释同一过程,并正确回答所有输入与乘数变式;这是该应用选择的判准。\n\n**证明或检查:** ExternalCertificate 在无内省要求下检查输出。两个机制对象具有同一个 explainedProcess;固定翻倍回答者在 (3,1) 失败,机制回答者则证明更强契约及同对象 Grounds012;失败对象也不能获得该根据。\n\n**限度:** 这不是心理理解的普遍定义。精确身份是范围前提;履行支持责任的是实际契约证明,而非身份本身。\n\n**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3)\n\n### `CoreReader.Adopted.capabilitySpecification`\n\n[leanified/CoreReader/Adopted.lean:205](#line-code-leanified-corereader-adopted-lean-205) · definition\n\n核心依赖: `propext`.\n\n```lean\ndef capabilitySpecification (assessed : Process) (contract : Claim Process) : Prop :=\n```\n\n### `CoreReader.Adopted.capabilityCases012`\n\n[leanified/CoreReader/Adopted.lean:1232](#line-code-leanified-corereader-adopted-lean-1232) · case\n\n核心依赖: `propext`.\n\n```lean\ntheorem capabilityCases012 :\n (capabilitySpecification outputOnlyProcess OutputContract ∧\n capabilitySpecification explainedProcess FullProcessContract ∧\n (∃ certificate : ExternalCertificate outputOnlyProcess,\n certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧\n ¬ ExplanationContract outputOnlyProcess) ∧\n (OwnCapability012 7 7 outputOnlyProcess OutputContract) ∧\n (explainedWithoutVariation012.process = mechanismResponder012.process ∧\n FullProcessContract explainedWithoutVariation012.process ∧\n ¬ UnderstandingApplication012 explainedWithoutVariation012 ∧\n UnderstandingApplication012 mechanismResponder012 ∧\n Grounds012 UnderstandingApplication012 canonicalArticulation\n [understandingFacet012 mechanismResponder012] (understandingTask012 mechanismResponder012) ∧\n ¬ Grounds012 UnderstandingApplication012 canonicalArticulation\n [understandingFacet012 explainedWithoutVariation012] (understandingTask012 explainedWithoutVariation012)) :=\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-adopted-lean-205", + "found": true + }, + { + "anchor": "line-code-leanified-corereader-adopted-lean-1232", + "found": true + } + ] + }, + { + "question": 3, + "language": "en", + "target": "t31", + "overview_line": 594, + "detail_line": 1388, + "overview_text": "\n## T31 · Structural consequences and crossing obligations\n\nStructural assessment connects intended changes to propagation, actual observable contracts, knowledge and verification work. A boundary label alone cannot establish the crossing obligation is handled.\n\n**Premises and representation:** StructuralAccount binds recorded touched components, observations and work to actual paths. The boundary case has caller 2, callee 1 and an explicit order-preserving obligation.\n\n**Proof or check:** The coordinated change edits callee 1 and checks the contract at caller 2. Deleting that caller check keeps the crossing but fails boundaryObligationChecked; moving the callee to untouched 7 changes applicability; sorting the output fails the same observable contract.\n\n**Limits:** These are relevant finite inquiries, not a mandatory universal checklist or a real-world estimate of all boundary costs.\n\n**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2)\n\n[Declarations, proof and line explanations](details.md#t31)\n\n\n", + "detail_text": "\n## T31 · Structural consequences and crossing obligations\n\nStructural assessment connects intended changes to propagation, actual observable contracts, knowledge and verification work. A boundary label alone cannot establish the crossing obligation is handled.\n\n**Premises and representation:** StructuralAccount binds recorded touched components, observations and work to actual paths. The boundary case has caller 2, callee 1 and an explicit order-preserving obligation.\n\n**Proof or check:** The coordinated change edits callee 1 and checks the contract at caller 2. Deleting that caller check keeps the crossing but fails boundaryObligationChecked; moving the callee to untouched 7 changes applicability; sorting the output fails the same observable contract.\n\n**Limits:** These are relevant finite inquiries, not a mandatory universal checklist or a real-world estimate of all boundary costs.\n\n**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2)\n\n### `CoreReader.Engineering.StructuralAccount`\n\n[leanified/CoreReader/Engineering/Domain.lean:641](#line-code-leanified-corereader-engineering-domain-lean-641) · definition\n\nCore dependencies: none.\n\n```lean\nabbrev StructuralAccount (a : Activity) (c : Candidate) (e : StructuralEvidence) : Prop :=\n```\n\n### `CoreReader.Engineering.structuralCases`\n\n[leanified/CoreReader/Engineering/Domain.lean:733](#line-code-leanified-corereader-engineering-domain-lean-733) · case\n\nCore dependencies: `propext`.\n\n```lean\ntheorem structuralCases :\n StructuralAccount continuingActivity .evolvable (structuralEvidence .evolvable .designRevision) ∧\n (propagation .presentSimple .designRevision).length = 3 ∧\n (propagation .evolvable .designRevision).length = 2 ∧\n (changePath .evolvable .coordinated).any (fun s => s.component == 2 && s.requires == .publicContract) = true ∧\n PreservesFinite orderedUnique orderedRefactor ∧\n (structuralEvidence .evolvable .designRevision).observedBefore ≠\n (structuralEvidence .evolvable .designRevision).observedAfter ∧\n staticBatch 21 10 = liveBatch 21 10 ∧ staticBatch 21 5 ≠ liveBatch 21 5 ∧\n changeWork .presentSimple .withdrawal = 17 ∧\n (crossesBoundary boundaryDesign .coordinated coordinatedBoundary = true ∧\n boundaryObligationChecked boundaryDesign .coordinated coordinatedBoundary = true ∧\n crossesBoundary omittedCallerCheck .coordinated coordinatedBoundary = true ∧\n boundaryObligationChecked omittedCallerCheck .coordinated coordinatedBoundary = false ∧\n crossesBoundary otherCalleeDesign .coordinated otherCalleeBoundary = false ∧\n boundaryObligationChecked { boundaryDesign with run := sortedUnique }\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-engineering-domain-lean-641", + "found": true + }, + { + "anchor": "line-code-leanified-corereader-engineering-domain-lean-733", + "found": true + } + ] + }, + { + "question": 3, + "language": "zh", + "target": "t31", + "overview_line": 594, + "detail_line": 1388, + "overview_text": "\n## T31 · 结构后果与跨边界义务\n\n结构评估将预期变化连接到传播、实际可观察契约、知识及验证工作;边界标签本身不能建立跨边界义务已获处理。\n\n**前提与表示:** StructuralAccount 将记录的受影响组件、观察及工作绑定到实际路径。边界案例具有调用方 2、被调用方 1 及明确的保序义务。\n\n**证明或检查:** 协调变化修改被调用方 1,并在调用方 2 检查契约。删除调用方检查仍发生跨界,却不满足 boundaryObligationChecked;把被调用方改为未触及的 7 会改变适用性;排序输出则不满足同一可观察契约。\n\n**限度:** 这些是相关的有限检查,不是普遍强制清单,也不是现实中所有边界成本的估算。\n\n**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2)\n\n[声明、证明与逐行解释](details.md#t31)\n\n\n", + "detail_text": "\n## T31 · 结构后果与跨边界义务\n\n结构评估将预期变化连接到传播、实际可观察契约、知识及验证工作;边界标签本身不能建立跨边界义务已获处理。\n\n**前提与表示:** StructuralAccount 将记录的受影响组件、观察及工作绑定到实际路径。边界案例具有调用方 2、被调用方 1 及明确的保序义务。\n\n**证明或检查:** 协调变化修改被调用方 1,并在调用方 2 检查契约。删除调用方检查仍发生跨界,却不满足 boundaryObligationChecked;把被调用方改为未触及的 7 会改变适用性;排序输出则不满足同一可观察契约。\n\n**限度:** 这些是相关的有限检查,不是普遍强制清单,也不是现实中所有边界成本的估算。\n\n**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2)\n\n### `CoreReader.Engineering.StructuralAccount`\n\n[leanified/CoreReader/Engineering/Domain.lean:641](#line-code-leanified-corereader-engineering-domain-lean-641) · definition\n\n核心依赖: none.\n\n```lean\nabbrev StructuralAccount (a : Activity) (c : Candidate) (e : StructuralEvidence) : Prop :=\n```\n\n### `CoreReader.Engineering.structuralCases`\n\n[leanified/CoreReader/Engineering/Domain.lean:733](#line-code-leanified-corereader-engineering-domain-lean-733) · case\n\n核心依赖: `propext`.\n\n```lean\ntheorem structuralCases :\n StructuralAccount continuingActivity .evolvable (structuralEvidence .evolvable .designRevision) ∧\n (propagation .presentSimple .designRevision).length = 3 ∧\n (propagation .evolvable .designRevision).length = 2 ∧\n (changePath .evolvable .coordinated).any (fun s => s.component == 2 && s.requires == .publicContract) = true ∧\n PreservesFinite orderedUnique orderedRefactor ∧\n (structuralEvidence .evolvable .designRevision).observedBefore ≠\n (structuralEvidence .evolvable .designRevision).observedAfter ∧\n staticBatch 21 10 = liveBatch 21 10 ∧ staticBatch 21 5 ≠ liveBatch 21 5 ∧\n changeWork .presentSimple .withdrawal = 17 ∧\n (crossesBoundary boundaryDesign .coordinated coordinatedBoundary = true ∧\n boundaryObligationChecked boundaryDesign .coordinated coordinatedBoundary = true ∧\n crossesBoundary omittedCallerCheck .coordinated coordinatedBoundary = true ∧\n boundaryObligationChecked omittedCallerCheck .coordinated coordinatedBoundary = false ∧\n crossesBoundary otherCalleeDesign .coordinated otherCalleeBoundary = false ∧\n boundaryObligationChecked { boundaryDesign with run := sortedUnique }\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-engineering-domain-lean-641", + "found": true + }, + { + "anchor": "line-code-leanified-corereader-engineering-domain-lean-733", + "found": true + } + ] + }, + { + "question": 4, + "language": "en", + "target": "t20", + "overview_line": 396, + "detail_line": 948, + "overview_text": "\n## T20 · Mutual application in one engineering system\n\nThe inherited duties apply to this system’s own principles, methods, value positions, capability reports and implementation choice. Actual normative contents enter its whole consistency theory.\n\n**Premises and representation:** Inherited fixes sharedContext and carries fulfilled generation, reflection, original empirical/inferential/value tasks, scope, capability and choice. ownTheory joins actual facts with every applicable OwnNorm content; consistency constrains this whole union.\n\n**Proof or check:** inheritedMutualApplication projects these actual fields and the full-content/support bridges; inheritedCurrent constructs them separately. Both actual reflection rules are self objects, and the evaluator’s revision test reports its local empty-sample defect.\n\n**Limits:** Projection does not derive all duties from one principle. Adoption markers are separate facts; they do not substitute for normative content. The sample-aware criticism is an application criterion, not a universal requirement for observations.\n\n**State:** accepted (theorem). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3)\n\n[Declarations, proof and line explanations](details.md#t20)\n\n\n", + "detail_text": "\n## T20 · Mutual application in one engineering system\n\nThe inherited duties apply to this system’s own principles, methods, value positions, capability reports and implementation choice. Actual normative contents enter its whole consistency theory.\n\n**Premises and representation:** Inherited fixes sharedContext and carries fulfilled generation, reflection, original empirical/inferential/value tasks, scope, capability and choice. ownTheory joins actual facts with every applicable OwnNorm content; consistency constrains this whole union.\n\n**Proof or check:** inheritedMutualApplication projects these actual fields and the full-content/support bridges; inheritedCurrent constructs them separately. Both actual reflection rules are self objects, and the evaluator’s revision test reports its local empty-sample defect.\n\n**Limits:** Projection does not derive all duties from one principle. Adoption markers are separate facts; they do not substitute for normative content. The sample-aware criticism is an application criterion, not a universal requirement for observations.\n\n**State:** accepted (theorem). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3)\n\n### `CoreReader.Engineering.inheritedMutualApplication`\n\n[leanified/CoreReader/Engineering/Integration.lean:420](#line-code-leanified-corereader-engineering-integration-lean-420) · theorem\n\nCore dependencies: `propext`.\n\n```lean\ntheorem inheritedMutualApplication (ctx : Context) (chosen : Candidate)\n (inherited : Inherited ctx chosen) :\n generationSpecification engineeringPolicy ∧\n reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self\n (selfModel chosen).performed ∧\n (∀ principle, valueSpecification (governancePosition principle)) ∧\n capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen) ∧\n choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons ∧\n (∀ fact, inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact)) ∧\n (∀ norm, normApplies chosen norm → ownTheory chosen (ownNormClaim chosen norm)) ∧\n (∀ claim, ownTheory chosen claim → inferentialSpecification (ownFactPremises chosen) claim) ∧\n consistencySpecification (engineeringSnapshot .evolvable 0)\n (engineeringSnapshot chosen 1) true :=\n```\n\n### `CoreReader.Engineering.inheritedMutualCases`\n\n[leanified/CoreReader/Engineering/Integration.lean:442](#line-code-leanified-corereader-engineering-integration-lean-442) · case\n\nCore dependencies: `propext`, `Classical.choice`, `Quot.sound`.\n\n```lean\ntheorem inheritedMutualCases :\n Inherited sharedContext .evolvable ∧\n valueSpecification (governancePosition .grounds) ∧\n capabilitySpecification (engineeringProcess .evolvable) (engineeringCapability .evolvable) ∧\n choiceSpecification chosenRequirements (chosenImplementation .evolvable) chosenReasons ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧\n (.generationRule : ReviewObject) ∈ (selfModel .evolvable).objects ∧\n (.assessmentRule : ReviewObject) ∈ (selfModel .evolvable).objects ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .assessmentRule, .revision⟩) = .counterexample :=\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-engineering-integration-lean-420", + "found": true + }, + { + "anchor": "line-code-leanified-corereader-engineering-integration-lean-442", + "found": true + } + ] + }, + { + "question": 4, + "language": "en", + "target": "t37", + "overview_line": 702, + "detail_line": 1645, + "overview_text": "\n## T37 · The priority remains open to its own assessment\n\nFor the same adopter and applicable context, the priority and actual assessment methods remain under Grounds, whole-theory consistency and reflexive scrutiny.\n\n**Premises and representation:** The theorem retains full Inherited and DomainSatisfied premises, PriorityConditions and no justified departure. It identifies the actual priority object and connects the evolution value commitment to EvolutionPriority by equality of their meanings in sharedContext.\n\n**Proof or check:** Eliminate the departure branch, retain reflection, and supply priorityGrounds plus the domain content’s membership in the whole consistent theory. The own forecast and evaluator revision cases retain their actual counterexamples.\n\n**Limits:** Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract.\n\n**State:** accepted (theorem). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.revision#p2](#source-software-engineering-revision-p2)\n\n[Declarations, proof and line explanations](details.md#t37)\n\n\n", + "detail_text": "\n## T37 · The priority remains open to its own assessment\n\nFor the same adopter and applicable context, the priority and actual assessment methods remain under Grounds, whole-theory consistency and reflexive scrutiny.\n\n**Premises and representation:** The theorem retains full Inherited and DomainSatisfied premises, PriorityConditions and no justified departure. It identifies the actual priority object and connects the evolution value commitment to EvolutionPriority by equality of their meanings in sharedContext.\n\n**Proof or check:** Eliminate the departure branch, retain reflection, and supply priorityGrounds plus the domain content’s membership in the whole consistent theory. The own forecast and evaluator revision cases retain their actual counterexamples.\n\n**Limits:** Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract.\n\n**State:** accepted (theorem). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.revision#p2](#source-software-engineering-revision-p2)\n\n### `CoreReader.Engineering.priorityRemainsReflexive`\n\n[leanified/CoreReader/Engineering/Integration.lean:467](#line-code-leanified-corereader-engineering-integration-lean-467) · theorem\n\nCore dependencies: `propext`, `Classical.choice`, `Quot.sound`.\n\n```lean\ntheorem priorityRemainsReflexive (ctx : Context) (chosen : Candidate)\n (inherited : Inherited ctx chosen) (domain : DomainSatisfied ctx chosen)\n (applicable : PriorityConditions ctx) (noDeparture : ¬ JustifiedDeparture ctx .evolvable) :\n chosen = .evolvable ∧\n (.priority : ReviewObject) ∈ (selfModel chosen).objects ∧\n reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self\n (selfModel chosen).performed ∧\n (∀ principle, valueSpecification (governancePosition principle)) ∧\n Grounds012 (EvolutionPriority ctx) canonicalArticulation\n [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) ∧\n ownTheory chosen (ownNormClaim chosen .domain) ∧\n consistencySpecification (engineeringSnapshot .evolvable 0)\n (engineeringSnapshot chosen 1) true := by\n```\n\n### `CoreReader.Engineering.priorityReflexiveCases`\n\n[leanified/CoreReader/Engineering/Integration.lean:493](#line-code-leanified-corereader-engineering-integration-lean-493) · case\n\nCore dependencies: `propext`, `Classical.choice`, `Quot.sound`.\n\n```lean\ntheorem priorityReflexiveCases :\n (.priority : ReviewObject) ∈ (selfModel .evolvable).objects ∧\n objectTest .priority (.evolvable, 10) = true ∧\n (selfModel .evolvable).performed ⟨0, 1⟩ ⟨0, .priority, .revision⟩\n ((selfModel .evolvable).input ⟨0, .priority, .revision⟩)\n (.assessed .supportedWithinScope) ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧\n objectTest .evolutionMethod (.evolvable, 10) = true ∧\n objectTest .evolutionMethod (.evolvable, 5) = false ∧\n Grounds012 (EvolutionPriority sharedContext) canonicalArticulation\n [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .assessmentRule, .revision⟩) = .counterexample := by\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-engineering-integration-lean-467", + "found": true + }, + { + "anchor": "line-code-leanified-corereader-engineering-integration-lean-493", + "found": true + } + ] + }, + { + "question": 4, + "language": "zh", + "target": "t20", + "overview_line": 396, + "detail_line": 948, + "overview_text": "\n## T20 · 同一工程系统内的相互适用\n\n继承义务适用于本系统的原则、方法、价值位置、能力报告和实现选择;实际规范内容进入其整体一致性理论。\n\n**前提与表示:** Inherited 固定 sharedContext,并包含已履行的生成、自反、原经验/推论/价值任务、范围、能力和选择。ownTheory 合并实际事实与各项适用 OwnNorm 内容;一致性约束该完整并集。\n\n**证明或检查:** inheritedMutualApplication 提取实际字段及完整内容/支持关系;inheritedCurrent 另行构造它们。两条实际自反规则均成为自身对象,评估器的修订检查报告其局部空样本缺陷。\n\n**限度:** 字段提取不从单一原则推出所有义务。采纳标记是独立事实,不能替代规范内容。要求样本的批评属于应用判准,不是对观察的普遍要求。\n\n**状态:** accepted (theorem). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3)\n\n[声明、证明与逐行解释](details.md#t20)\n\n\n", + "detail_text": "\n## T20 · 同一工程系统内的相互适用\n\n继承义务适用于本系统的原则、方法、价值位置、能力报告和实现选择;实际规范内容进入其整体一致性理论。\n\n**前提与表示:** Inherited 固定 sharedContext,并包含已履行的生成、自反、原经验/推论/价值任务、范围、能力和选择。ownTheory 合并实际事实与各项适用 OwnNorm 内容;一致性约束该完整并集。\n\n**证明或检查:** inheritedMutualApplication 提取实际字段及完整内容/支持关系;inheritedCurrent 另行构造它们。两条实际自反规则均成为自身对象,评估器的修订检查报告其局部空样本缺陷。\n\n**限度:** 字段提取不从单一原则推出所有义务。采纳标记是独立事实,不能替代规范内容。要求样本的批评属于应用判准,不是对观察的普遍要求。\n\n**状态:** accepted (theorem). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3)\n\n### `CoreReader.Engineering.inheritedMutualApplication`\n\n[leanified/CoreReader/Engineering/Integration.lean:420](#line-code-leanified-corereader-engineering-integration-lean-420) · theorem\n\n核心依赖: `propext`.\n\n```lean\ntheorem inheritedMutualApplication (ctx : Context) (chosen : Candidate)\n (inherited : Inherited ctx chosen) :\n generationSpecification engineeringPolicy ∧\n reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self\n (selfModel chosen).performed ∧\n (∀ principle, valueSpecification (governancePosition principle)) ∧\n capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen) ∧\n choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons ∧\n (∀ fact, inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact)) ∧\n (∀ norm, normApplies chosen norm → ownTheory chosen (ownNormClaim chosen norm)) ∧\n (∀ claim, ownTheory chosen claim → inferentialSpecification (ownFactPremises chosen) claim) ∧\n consistencySpecification (engineeringSnapshot .evolvable 0)\n (engineeringSnapshot chosen 1) true :=\n```\n\n### `CoreReader.Engineering.inheritedMutualCases`\n\n[leanified/CoreReader/Engineering/Integration.lean:442](#line-code-leanified-corereader-engineering-integration-lean-442) · case\n\n核心依赖: `propext`, `Classical.choice`, `Quot.sound`.\n\n```lean\ntheorem inheritedMutualCases :\n Inherited sharedContext .evolvable ∧\n valueSpecification (governancePosition .grounds) ∧\n capabilitySpecification (engineeringProcess .evolvable) (engineeringCapability .evolvable) ∧\n choiceSpecification chosenRequirements (chosenImplementation .evolvable) chosenReasons ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧\n (.generationRule : ReviewObject) ∈ (selfModel .evolvable).objects ∧\n (.assessmentRule : ReviewObject) ∈ (selfModel .evolvable).objects ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .assessmentRule, .revision⟩) = .counterexample :=\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-engineering-integration-lean-420", + "found": true + }, + { + "anchor": "line-code-leanified-corereader-engineering-integration-lean-442", + "found": true + } + ] + }, + { + "question": 4, + "language": "zh", + "target": "t37", + "overview_line": 702, + "detail_line": 1645, + "overview_text": "\n## T37 · 优先原则仍接受自身评估\n\n对同一采用者及适用语境,优先原则和实际评估方法仍受 Grounds、整体理论一致性及自反审查约束。\n\n**前提与表示:** 定理保留完整 Inherited、DomainSatisfied、PriorityConditions 和无有根据让步的前提。它识别实际优先对象,并以 sharedContext 内的含义等价连接演化价值承诺与 EvolutionPriority。\n\n**证明或检查:** 排除让步分支,保留自反责任,并给出 priorityGrounds 及领域内容在完整一致理论中的成员关系。自身预测和评估器修订案例保留实际反例。\n\n**限度:** 成功自评既不证明优先原则普遍正确,也不建立普遍样本要求。空样本批评适用于声明的局部评估契约。\n\n**状态:** accepted (theorem). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.revision#p2](#source-software-engineering-revision-p2)\n\n[声明、证明与逐行解释](details.md#t37)\n\n\n", + "detail_text": "\n## T37 · 优先原则仍接受自身评估\n\n对同一采用者及适用语境,优先原则和实际评估方法仍受 Grounds、整体理论一致性及自反审查约束。\n\n**前提与表示:** 定理保留完整 Inherited、DomainSatisfied、PriorityConditions 和无有根据让步的前提。它识别实际优先对象,并以 sharedContext 内的含义等价连接演化价值承诺与 EvolutionPriority。\n\n**证明或检查:** 排除让步分支,保留自反责任,并给出 priorityGrounds 及领域内容在完整一致理论中的成员关系。自身预测和评估器修订案例保留实际反例。\n\n**限度:** 成功自评既不证明优先原则普遍正确,也不建立普遍样本要求。空样本批评适用于声明的局部评估契约。\n\n**状态:** accepted (theorem). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.revision#p2](#source-software-engineering-revision-p2)\n\n### `CoreReader.Engineering.priorityRemainsReflexive`\n\n[leanified/CoreReader/Engineering/Integration.lean:467](#line-code-leanified-corereader-engineering-integration-lean-467) · theorem\n\n核心依赖: `propext`, `Classical.choice`, `Quot.sound`.\n\n```lean\ntheorem priorityRemainsReflexive (ctx : Context) (chosen : Candidate)\n (inherited : Inherited ctx chosen) (domain : DomainSatisfied ctx chosen)\n (applicable : PriorityConditions ctx) (noDeparture : ¬ JustifiedDeparture ctx .evolvable) :\n chosen = .evolvable ∧\n (.priority : ReviewObject) ∈ (selfModel chosen).objects ∧\n reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self\n (selfModel chosen).performed ∧\n (∀ principle, valueSpecification (governancePosition principle)) ∧\n Grounds012 (EvolutionPriority ctx) canonicalArticulation\n [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) ∧\n ownTheory chosen (ownNormClaim chosen .domain) ∧\n consistencySpecification (engineeringSnapshot .evolvable 0)\n (engineeringSnapshot chosen 1) true := by\n```\n\n### `CoreReader.Engineering.priorityReflexiveCases`\n\n[leanified/CoreReader/Engineering/Integration.lean:493](#line-code-leanified-corereader-engineering-integration-lean-493) · case\n\n核心依赖: `propext`, `Classical.choice`, `Quot.sound`.\n\n```lean\ntheorem priorityReflexiveCases :\n (.priority : ReviewObject) ∈ (selfModel .evolvable).objects ∧\n objectTest .priority (.evolvable, 10) = true ∧\n (selfModel .evolvable).performed ⟨0, 1⟩ ⟨0, .priority, .revision⟩\n ((selfModel .evolvable).input ⟨0, .priority, .revision⟩)\n (.assessed .supportedWithinScope) ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧\n objectTest .evolutionMethod (.evolvable, 10) = true ∧\n objectTest .evolutionMethod (.evolvable, 5) = false ∧\n Grounds012 (EvolutionPriority sharedContext) canonicalArticulation\n [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .assessmentRule, .revision⟩) = .counterexample := by\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-engineering-integration-lean-467", + "found": true + }, + { + "anchor": "line-code-leanified-corereader-engineering-integration-lean-493", + "found": true + } + ] + }, + { + "question": 5, + "language": "en", + "target": "t33", + "overview_line": 630, + "detail_line": 1488, + "overview_text": "\n## T33 · Preservation versus deliberate contract revision\n\nAn identified contract can be preserved or deliberately revised. Revision accounts identify changed obligations and affected parties instead of silently relabeling changed behavior as preservation.\n\n**Premises and representation:** ObservableContract includes order behavior and retry limits. Actual party dependencies determine which consumers/operators are affected; a report cannot define them away.\n\n**Proof or check:** Order-preserving refactoring passes. Sorted order and changed retry limits need a revision account. Omitting the actual operator fails; a behavior retired outside the selected finite suite demonstrates that local preservation is limited.\n\n**Limits:** The model does not require retaining every historical behavior, a particular test procedure, or an added universal notification obligation.\n\n**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3)\n\n[Declarations, proof and line explanations](details.md#t33)\n\n\n", + "detail_text": "\n## T33 · Preservation versus deliberate contract revision\n\nAn identified contract can be preserved or deliberately revised. Revision accounts identify changed obligations and affected parties instead of silently relabeling changed behavior as preservation.\n\n**Premises and representation:** ObservableContract includes order behavior and retry limits. Actual party dependencies determine which consumers/operators are affected; a report cannot define them away.\n\n**Proof or check:** Order-preserving refactoring passes. Sorted order and changed retry limits need a revision account. Omitting the actual operator fails; a behavior retired outside the selected finite suite demonstrates that local preservation is limited.\n\n**Limits:** The model does not require retaining every historical behavior, a particular test procedure, or an added universal notification obligation.\n\n**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3)\n\n### `CoreReader.Engineering.ContractChangeAccount`\n\n[leanified/CoreReader/Engineering/Domain.lean:549](#line-code-leanified-corereader-engineering-domain-lean-549) · definition\n\nCore dependencies: none.\n\n```lean\nabbrev ContractChangeAccount (old new : ObservableContract) (r : ContractRevision) : Prop :=\n```\n\n### `CoreReader.Engineering.contractCases`\n\n[leanified/CoreReader/Engineering/Domain.lean:843](#line-code-leanified-corereader-engineering-domain-lean-843) · case\n\nCore dependencies: none.\n\n```lean\ntheorem contractCases :\n ContractChangeAccount originalContract refactoredContract normalRevision ∧\n ContractChangeAccount originalContract revisedContract normalRevision ∧\n ¬ ContractChangeAccount originalContract revisedContract { normalRevision with affected := [] } ∧\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-engineering-domain-lean-549", + "found": true + }, + { + "anchor": "line-code-leanified-corereader-engineering-domain-lean-843", + "found": true + } + ] + }, + { + "question": 5, + "language": "en", + "target": "t34", + "overview_line": 648, + "detail_line": 1527, + "overview_text": "\n## T34 · The contract-preservation theorem\n\nIf all identified in-scope observations are equal, the identified contract is preserved. A changed in-scope observation refutes preservation of that same contract.\n\n**Premises and representation:** contractPreservation receives a universal in-scope equality. The finite order/retry examples are separate checks and do not supply that universal premise automatically.\n\n**Proof or check:** The theorem returns the supplied equality as PreservesOn. changedObservationNotPreserved applies it to a differing input. The examples compute order changes, retry at 3, affected parties and a difference at the excluded input [99].\n\n**Limits:** A passing finite test suite is not a universal equality proof; preservation always retains its identified scope.\n\n**State:** accepted (theorem). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3)\n\n[Declarations, proof and line explanations](details.md#t34)\n\n\n", + "detail_text": "\n## T34 · The contract-preservation theorem\n\nIf all identified in-scope observations are equal, the identified contract is preserved. A changed in-scope observation refutes preservation of that same contract.\n\n**Premises and representation:** contractPreservation receives a universal in-scope equality. The finite order/retry examples are separate checks and do not supply that universal premise automatically.\n\n**Proof or check:** The theorem returns the supplied equality as PreservesOn. changedObservationNotPreserved applies it to a differing input. The examples compute order changes, retry at 3, affected parties and a difference at the excluded input [99].\n\n**Limits:** A passing finite test suite is not a universal equality proof; preservation always retains its identified scope.\n\n**State:** accepted (theorem). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3)\n\n### `CoreReader.Engineering.contractPreservation`\n\n[leanified/CoreReader/Engineering/Domain.lean:822](#line-code-leanified-corereader-engineering-domain-lean-822) · theorem\n\nCore dependencies: none.\n\n```lean\ntheorem contractPreservation {Input Output : Type} (scope : Input → Prop)\n (old new : Input → Output) (observations : ∀ x, scope x → new x = old x) :\n PreservesOn scope old new := observations\n```\n\n### `CoreReader.Engineering.contractDistinctions`\n\n[leanified/CoreReader/Engineering/Domain.lean:853](#line-code-leanified-corereader-engineering-domain-lean-853) · case\n\nCore dependencies: none.\n\n```lean\ntheorem contractDistinctions :\n PreservesFinite orderedUnique orderedRefactor ∧\n ¬ PreservesFinite orderedUnique sortedUnique ∧\n retry originalContract 3 = false ∧ retry revisedContract 3 = true ∧\n ¬ PreservesContractFinite originalContract revisedContract ∧\n affectedParties originalContract revisedContract = [\"queue consumer\", \"queue operator\"] ∧\n ¬ ContractChangeAccount originalContract revisedContract\n { normalRevision with affected := [\"queue consumer\"] } ∧\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-engineering-domain-lean-822", + "found": true + }, + { + "anchor": "line-code-leanified-corereader-engineering-domain-lean-853", + "found": true + } + ] + }, + { + "question": 5, + "language": "en", + "target": "t35", + "overview_line": 666, + "detail_line": 1572, + "overview_text": "\n## T35 · Revision and preserved historical evidence\n\nChanged forecasts, maintainers, costs or objectives can justify changed judgments. A new record must retain the earlier prediction and its observed failure.\n\n**Premises and representation:** RevisionAccount compares the revision with independently fixed observedHistory, including software identity, old prediction and actual observed result. revisionFor uses the current context and selected candidate. MaterialGroundsChanged is a disjunction of five recorded differences; it does not prove that each difference alone adequately justifies the new choice.\n\n**Proof or check:** The same old/new state pair changes forecast, maintenance, maintainers, migration cost and objective capacity together; the theorem lists all five differences. Tampering with both old and recordedOld cannot change the independent history. Separate retention cases use an unsupported alternative or a justified migration-cost departure.\n\n**Limits:** The recorded history is fixed model evidence; the theorem does not authenticate arbitrary real-world logs or prove every criticism response adequate.\n\n**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [software-engineering.revision#p2](#source-software-engineering-revision-p2), [software-engineering.revision#p1](#source-software-engineering-revision-p1)\n\n[Declarations, proof and line explanations](details.md#t35)\n\n\n", + "detail_text": "\n## T35 · Revision and preserved historical evidence\n\nChanged forecasts, maintainers, costs or objectives can justify changed judgments. A new record must retain the earlier prediction and its observed failure.\n\n**Premises and representation:** RevisionAccount compares the revision with independently fixed observedHistory, including software identity, old prediction and actual observed result. revisionFor uses the current context and selected candidate. MaterialGroundsChanged is a disjunction of five recorded differences; it does not prove that each difference alone adequately justifies the new choice.\n\n**Proof or check:** The same old/new state pair changes forecast, maintenance, maintainers, migration cost and objective capacity together; the theorem lists all five differences. Tampering with both old and recordedOld cannot change the independent history. Separate retention cases use an unsupported alternative or a justified migration-cost departure.\n\n**Limits:** The recorded history is fixed model evidence; the theorem does not authenticate arbitrary real-world logs or prove every criticism response adequate.\n\n**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [software-engineering.revision#p2](#source-software-engineering-revision-p2), [software-engineering.revision#p1](#source-software-engineering-revision-p1)\n\n### `CoreReader.Engineering.RevisionAccount`\n\n[leanified/CoreReader/Engineering/Domain.lean:922](#line-code-leanified-corereader-engineering-domain-lean-922) · definition\n\nCore dependencies: none.\n\n```lean\nabbrev RevisionAccount (r : RevisionRecord) : Prop := RevisionAccountAgainst observedHistory r\n```\n\n### `CoreReader.Engineering.revisionCases`\n\n[leanified/CoreReader/Engineering/Domain.lean:951](#line-code-leanified-corereader-engineering-domain-lean-951) · case\n\nCore dependencies: `propext`.\n\n```lean\ntheorem revisionCases :\n RevisionAccount revisionRecord ∧\n revisionRecord.old.forecast ≠ revisionRecord.current.forecast ∧\n revisionRecord.old.maintenance ≠ revisionRecord.current.maintenance ∧\n revisionRecord.old.maintainers ≠ revisionRecord.current.maintainers ∧\n revisionRecord.old.migrationCost ≠ revisionRecord.current.migrationCost ∧\n revisionRecord.old.objectiveCapacity ≠ revisionRecord.current.objectiveCapacity ∧\n revisionRecord.predictedBatchCount ≠ revisionRecord.actualBatchCount ∧\n RetentionJustified currentContinuing [.other \"quantum backend\"] ∧\n RetentionJustified (threatened .migration) [.migration] := by decide\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-engineering-domain-lean-922", + "found": true + }, + { + "anchor": "line-code-leanified-corereader-engineering-domain-lean-951", + "found": true + } + ] + }, + { + "question": 5, + "language": "en", + "target": "t36", + "overview_line": 684, + "detail_line": 1617, + "overview_text": "\n## T36 · Revision cannot rewrite failure\n\nA new judgment cannot make the old failed forecast true. Agreement and local success do not establish universal correctness; justified stability remains possible.\n\n**Premises and representation:** The old static prediction and changed live batch result remain fixed independently of the revision report.\n\n**Proof or check:** The 21-item case agrees at size 10 but differs at size 5. Relabeling cannot repair that arithmetic. The stable record retains a valid historical account and criticism-direction coverage while leaving the choice unchanged; the named unsupported alternative satisfies the bounded retention criterion. This case does not prove the design’s actual revisability.\n\n**Limits:** The result permits bounded retention, not permanent immunity from later grounds or criticism.\n\n**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [software-engineering.revision#p2](#source-software-engineering-revision-p2), [software-engineering.revision#p1](#source-software-engineering-revision-p1)\n\n[Declarations, proof and line explanations](details.md#t36)\n\n\n", + "detail_text": "\n## T36 · Revision cannot rewrite failure\n\nA new judgment cannot make the old failed forecast true. Agreement and local success do not establish universal correctness; justified stability remains possible.\n\n**Premises and representation:** The old static prediction and changed live batch result remain fixed independently of the revision report.\n\n**Proof or check:** The 21-item case agrees at size 10 but differs at size 5. Relabeling cannot repair that arithmetic. The stable record retains a valid historical account and criticism-direction coverage while leaving the choice unchanged; the named unsupported alternative satisfies the bounded retention criterion. This case does not prove the design’s actual revisability.\n\n**Limits:** The result permits bounded retention, not permanent immunity from later grounds or criticism.\n\n**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [software-engineering.revision#p2](#source-software-engineering-revision-p2), [software-engineering.revision#p1](#source-software-engineering-revision-p1)\n\n### `CoreReader.Engineering.revisionLimits`\n\n[leanified/CoreReader/Engineering/Domain.lean:993](#line-code-leanified-corereader-engineering-domain-lean-993) · case\n\nCore dependencies: `propext`.\n\n```lean\ntheorem revisionLimits :\n RevisionAccount revisionRecord ∧\n ¬ RevisionAccount { revisionRecord with reportedPredictionSucceeded := true } ∧\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-engineering-domain-lean-993", + "found": true + } + ] + }, + { + "question": 5, + "language": "zh", + "target": "t33", + "overview_line": 630, + "detail_line": 1488, + "overview_text": "\n## T33 · 契约保持与刻意修订\n\n指定契约可以保持,也可以刻意修订。修订说明识别变化义务及受影响方,不能把行为变化悄然改称保持。\n\n**前提与表示:** ObservableContract 包含顺序行为和重试限制。实际依赖决定哪些消费者/运行人员受到影响,报告不能自行将他们排除。\n\n**证明或检查:** 保序重构通过。排序及重试限制变化需要修订说明。遗漏实际受影响的运行人员会失败;有限测试外退出的行为展示局部保持的限度。\n\n**限度:** 模型不要求保留所有历史行为、使用特定测试程序,也未新增普遍通知义务。\n\n**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3)\n\n[声明、证明与逐行解释](details.md#t33)\n\n\n", + "detail_text": "\n## T33 · 契约保持与刻意修订\n\n指定契约可以保持,也可以刻意修订。修订说明识别变化义务及受影响方,不能把行为变化悄然改称保持。\n\n**前提与表示:** ObservableContract 包含顺序行为和重试限制。实际依赖决定哪些消费者/运行人员受到影响,报告不能自行将他们排除。\n\n**证明或检查:** 保序重构通过。排序及重试限制变化需要修订说明。遗漏实际受影响的运行人员会失败;有限测试外退出的行为展示局部保持的限度。\n\n**限度:** 模型不要求保留所有历史行为、使用特定测试程序,也未新增普遍通知义务。\n\n**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3)\n\n### `CoreReader.Engineering.ContractChangeAccount`\n\n[leanified/CoreReader/Engineering/Domain.lean:549](#line-code-leanified-corereader-engineering-domain-lean-549) · definition\n\n核心依赖: none.\n\n```lean\nabbrev ContractChangeAccount (old new : ObservableContract) (r : ContractRevision) : Prop :=\n```\n\n### `CoreReader.Engineering.contractCases`\n\n[leanified/CoreReader/Engineering/Domain.lean:843](#line-code-leanified-corereader-engineering-domain-lean-843) · case\n\n核心依赖: none.\n\n```lean\ntheorem contractCases :\n ContractChangeAccount originalContract refactoredContract normalRevision ∧\n ContractChangeAccount originalContract revisedContract normalRevision ∧\n ¬ ContractChangeAccount originalContract revisedContract { normalRevision with affected := [] } ∧\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-engineering-domain-lean-549", + "found": true + }, + { + "anchor": "line-code-leanified-corereader-engineering-domain-lean-843", + "found": true + } + ] + }, + { + "question": 5, + "language": "zh", + "target": "t34", + "overview_line": 648, + "detail_line": 1527, + "overview_text": "\n## T34 · 契约保持定理\n\n若所有指定范围内的观察相等,则指定契约保持;范围内观察改变会反驳同一契约的保持。\n\n**前提与表示:** contractPreservation 接收范围内普遍相等的前提。有限顺序/重试案例是独立检查,不自动提供该普遍前提。\n\n**证明或检查:** 定理将所给相等关系作为 PreservesOn 返回;changedObservationNotPreserved 将其应用到不同结果的输入。案例计算顺序变化、重试 3、受影响方及被排除输入 [99] 的差异。\n\n**限度:** 有限测试集通过不是普遍相等证明;保持判断始终保留指定范围。\n\n**状态:** accepted (theorem). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3)\n\n[声明、证明与逐行解释](details.md#t34)\n\n\n", + "detail_text": "\n## T34 · 契约保持定理\n\n若所有指定范围内的观察相等,则指定契约保持;范围内观察改变会反驳同一契约的保持。\n\n**前提与表示:** contractPreservation 接收范围内普遍相等的前提。有限顺序/重试案例是独立检查,不自动提供该普遍前提。\n\n**证明或检查:** 定理将所给相等关系作为 PreservesOn 返回;changedObservationNotPreserved 将其应用到不同结果的输入。案例计算顺序变化、重试 3、受影响方及被排除输入 [99] 的差异。\n\n**限度:** 有限测试集通过不是普遍相等证明;保持判断始终保留指定范围。\n\n**状态:** accepted (theorem). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3)\n\n### `CoreReader.Engineering.contractPreservation`\n\n[leanified/CoreReader/Engineering/Domain.lean:822](#line-code-leanified-corereader-engineering-domain-lean-822) · theorem\n\n核心依赖: none.\n\n```lean\ntheorem contractPreservation {Input Output : Type} (scope : Input → Prop)\n (old new : Input → Output) (observations : ∀ x, scope x → new x = old x) :\n PreservesOn scope old new := observations\n```\n\n### `CoreReader.Engineering.contractDistinctions`\n\n[leanified/CoreReader/Engineering/Domain.lean:853](#line-code-leanified-corereader-engineering-domain-lean-853) · case\n\n核心依赖: none.\n\n```lean\ntheorem contractDistinctions :\n PreservesFinite orderedUnique orderedRefactor ∧\n ¬ PreservesFinite orderedUnique sortedUnique ∧\n retry originalContract 3 = false ∧ retry revisedContract 3 = true ∧\n ¬ PreservesContractFinite originalContract revisedContract ∧\n affectedParties originalContract revisedContract = [\"queue consumer\", \"queue operator\"] ∧\n ¬ ContractChangeAccount originalContract revisedContract\n { normalRevision with affected := [\"queue consumer\"] } ∧\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-engineering-domain-lean-822", + "found": true + }, + { + "anchor": "line-code-leanified-corereader-engineering-domain-lean-853", + "found": true + } + ] + }, + { + "question": 5, + "language": "zh", + "target": "t35", + "overview_line": 666, + "detail_line": 1572, + "overview_text": "\n## T35 · 修订与保留历史证据\n\n预测、维护者、成本或目标变化可支持改判;新记录须保留旧预测及其观测失败。\n\n**前提与表示:** RevisionAccount 将修订与独立固定的 observedHistory 比较,包括软件身份、旧预测及实际观测结果;revisionFor 使用当前语境和所选实现。 MaterialGroundsChanged 是五项记录差异的析取,不证明任一差异单独足以充分支持新选择。\n\n**证明或检查:** 同一旧/新状态对同时改变预测、维护、维护者、迁移成本和目标容量;定理列出这五项差异。同步篡改 old 与 recordedOld 不能改变独立历史。另有保留案例分别使用无支持的替代方向或有根据的迁移成本让步。\n\n**限度:** 记录的历史是固定模型证据;定理不鉴定任意现实日志,也不证明所有批评回应均充分。\n\n**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [software-engineering.revision#p2](#source-software-engineering-revision-p2), [software-engineering.revision#p1](#source-software-engineering-revision-p1)\n\n[声明、证明与逐行解释](details.md#t35)\n\n\n", + "detail_text": "\n## T35 · 修订与保留历史证据\n\n预测、维护者、成本或目标变化可支持改判;新记录须保留旧预测及其观测失败。\n\n**前提与表示:** RevisionAccount 将修订与独立固定的 observedHistory 比较,包括软件身份、旧预测及实际观测结果;revisionFor 使用当前语境和所选实现。 MaterialGroundsChanged 是五项记录差异的析取,不证明任一差异单独足以充分支持新选择。\n\n**证明或检查:** 同一旧/新状态对同时改变预测、维护、维护者、迁移成本和目标容量;定理列出这五项差异。同步篡改 old 与 recordedOld 不能改变独立历史。另有保留案例分别使用无支持的替代方向或有根据的迁移成本让步。\n\n**限度:** 记录的历史是固定模型证据;定理不鉴定任意现实日志,也不证明所有批评回应均充分。\n\n**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [software-engineering.revision#p2](#source-software-engineering-revision-p2), [software-engineering.revision#p1](#source-software-engineering-revision-p1)\n\n### `CoreReader.Engineering.RevisionAccount`\n\n[leanified/CoreReader/Engineering/Domain.lean:922](#line-code-leanified-corereader-engineering-domain-lean-922) · definition\n\n核心依赖: none.\n\n```lean\nabbrev RevisionAccount (r : RevisionRecord) : Prop := RevisionAccountAgainst observedHistory r\n```\n\n### `CoreReader.Engineering.revisionCases`\n\n[leanified/CoreReader/Engineering/Domain.lean:951](#line-code-leanified-corereader-engineering-domain-lean-951) · case\n\n核心依赖: `propext`.\n\n```lean\ntheorem revisionCases :\n RevisionAccount revisionRecord ∧\n revisionRecord.old.forecast ≠ revisionRecord.current.forecast ∧\n revisionRecord.old.maintenance ≠ revisionRecord.current.maintenance ∧\n revisionRecord.old.maintainers ≠ revisionRecord.current.maintainers ∧\n revisionRecord.old.migrationCost ≠ revisionRecord.current.migrationCost ∧\n revisionRecord.old.objectiveCapacity ≠ revisionRecord.current.objectiveCapacity ∧\n revisionRecord.predictedBatchCount ≠ revisionRecord.actualBatchCount ∧\n RetentionJustified currentContinuing [.other \"quantum backend\"] ∧\n RetentionJustified (threatened .migration) [.migration] := by decide\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-engineering-domain-lean-922", + "found": true + }, + { + "anchor": "line-code-leanified-corereader-engineering-domain-lean-951", + "found": true + } + ] + }, + { + "question": 5, + "language": "zh", + "target": "t36", + "overview_line": 684, + "detail_line": 1617, + "overview_text": "\n## T36 · 修订不能改写失败\n\n新判断不能使旧失败预测变真。一致赞同和局部成功不建立普遍正确性;有理由的稳定仍然可能。\n\n**前提与表示:** 旧静态预测及变化后的实际批处理结果独立于修订报告保持固定。\n\n**证明或检查:** 21 项案例在批量 10 时相同,在批量 5 时不同;重贴标签不能修复该算术事实。稳定记录保留有效历史说明及批评方向覆盖,同时保持选择不变;指定无支持替代方向满足有界的保留判准。本案例不证明设计的实际可修订性。\n\n**限度:** 结果允许有界的保留判断,不给予对后续根据或批评的永久豁免。\n\n**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [software-engineering.revision#p2](#source-software-engineering-revision-p2), [software-engineering.revision#p1](#source-software-engineering-revision-p1)\n\n[声明、证明与逐行解释](details.md#t36)\n\n\n", + "detail_text": "\n## T36 · 修订不能改写失败\n\n新判断不能使旧失败预测变真。一致赞同和局部成功不建立普遍正确性;有理由的稳定仍然可能。\n\n**前提与表示:** 旧静态预测及变化后的实际批处理结果独立于修订报告保持固定。\n\n**证明或检查:** 21 项案例在批量 10 时相同,在批量 5 时不同;重贴标签不能修复该算术事实。稳定记录保留有效历史说明及批评方向覆盖,同时保持选择不变;指定无支持替代方向满足有界的保留判准。本案例不证明设计的实际可修订性。\n\n**限度:** 结果允许有界的保留判断,不给予对后续根据或批评的永久豁免。\n\n**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [software-engineering.revision#p2](#source-software-engineering-revision-p2), [software-engineering.revision#p1](#source-software-engineering-revision-p1)\n\n### `CoreReader.Engineering.revisionLimits`\n\n[leanified/CoreReader/Engineering/Domain.lean:993](#line-code-leanified-corereader-engineering-domain-lean-993) · case\n\n核心依赖: `propext`.\n\n```lean\ntheorem revisionLimits :\n RevisionAccount revisionRecord ∧\n ¬ RevisionAccount { revisionRecord with reportedPredictionSucceeded := true } ∧\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-engineering-domain-lean-993", + "found": true + } + ] + }, + { + "question": 6, + "language": "en", + "target": "t01", + "overview_line": 54, + "detail_line": 54, + "overview_text": "\n## T01 · Authority and the adopted baseline\n\nSoftwareEngineering 0.2.0 adopts the inherited Core 0.1.2 text and an additional engineering priority. This edition does not upgrade that adoption to Core 0.1.3.\n\n**Premises and representation:** The complete quoted provisions, meanings and application limits are authoritative. Rationale and cases supply interpretation; the current Core checker is a separate runtime dependency.\n\n**Proof or check:** Source bytes, metadata and paragraph excerpts are frozen and traced. No Lean theorem is assigned to documentary authority.\n\n**Limits:** Neither the chapter order nor a successful checker establishes deductive hierarchy, universal philosophical correctness or adoption by every system.\n\n**State:** accepted (boundary). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [organon.preamble#p1](#source-organon-preamble-p1), [organon.preamble#p2](#source-organon-preamble-p2), [organon.charter.overview#p1](#source-organon-charter-overview-p1), [organon.charter.overview#p2](#source-organon-charter-overview-p2), [organon.charter.overview#p3](#source-organon-charter-overview-p3), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [extensions#p1](#source-extensions-p1)\n\n[Declarations, proof and line explanations](details.md#t01)\n\n\n", + "detail_text": "\n## T01 · Authority and the adopted baseline\n\nSoftwareEngineering 0.2.0 adopts the inherited Core 0.1.2 text and an additional engineering priority. This edition does not upgrade that adoption to Core 0.1.3.\n\n**Premises and representation:** The complete quoted provisions, meanings and application limits are authoritative. Rationale and cases supply interpretation; the current Core checker is a separate runtime dependency.\n\n**Proof or check:** Source bytes, metadata and paragraph excerpts are frozen and traced. No Lean theorem is assigned to documentary authority.\n\n**Limits:** Neither the chapter order nor a successful checker establishes deductive hierarchy, universal philosophical correctness or adoption by every system.\n\n**State:** accepted (boundary). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [organon.preamble#p1](#source-organon-preamble-p1), [organon.preamble#p2](#source-organon-preamble-p2), [organon.charter.overview#p1](#source-organon-charter-overview-p1), [organon.charter.overview#p2](#source-organon-charter-overview-p2), [organon.charter.overview#p3](#source-organon-charter-overview-p3), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [extensions#p1](#source-extensions-p1)\n\nThis boundary target has no Lean declaration.\n\n\n", + "detail_link_found": true, + "line_anchors": [] + }, + { + "question": 6, + "language": "en", + "target": "t02", + "overview_line": 72, + "detail_line": 72, + "overview_text": "\n## T02 · Valued expansion and revisable forms\n\ngenerationSpecification requires valuing expansion and keeping every current organization, method and principle form revisable. A justified stable action can satisfy this orientation.\n\n**Premises and representation:** Policy supplies the value position, current forms and revisability relation. The concrete policy has current forms; the requirement is not discharged by an empty inventory.\n\n**Proof or check:** The positive case constructs valuation and revisability. A neutral policy permits version changes but fails valuation; stable and collaborative examples check actual state transitions and resources.\n\n**Limits:** The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve.\n\n**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [organon.charter.overview#p2](#source-organon-charter-overview-p2), [organon.charter.overview#p3](#source-organon-charter-overview-p3), [organon.charter.self-transcendence#p1](#source-organon-charter-self-transcendence-p1), [organon.charter.self-transcendence.orientation#p1](#source-organon-charter-self-transcendence-orientation-p1), [organon.charter.self-transcendence.non-finality#p1](#source-organon-charter-self-transcendence-non-finality-p1), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.relationships.terms#p1](#source-organon-relationships-terms-p1)\n\n[Declarations, proof and line explanations](details.md#t02)\n\n\n", + "detail_text": "\n## T02 · Valued expansion and revisable forms\n\ngenerationSpecification requires valuing expansion and keeping every current organization, method and principle form revisable. A justified stable action can satisfy this orientation.\n\n**Premises and representation:** Policy supplies the value position, current forms and revisability relation. The concrete policy has current forms; the requirement is not discharged by an empty inventory.\n\n**Proof or check:** The positive case constructs valuation and revisability. A neutral policy permits version changes but fails valuation; stable and collaborative examples check actual state transitions and resources.\n\n**Limits:** The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve.\n\n**State:** accepted (specification). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [organon.charter.overview#p2](#source-organon-charter-overview-p2), [organon.charter.overview#p3](#source-organon-charter-overview-p3), [organon.charter.self-transcendence#p1](#source-organon-charter-self-transcendence-p1), [organon.charter.self-transcendence.orientation#p1](#source-organon-charter-self-transcendence-orientation-p1), [organon.charter.self-transcendence.non-finality#p1](#source-organon-charter-self-transcendence-non-finality-p1), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.relationships.terms#p1](#source-organon-relationships-terms-p1)\n\n### `CoreReader.Adopted.generationSpecification`\n\n[leanified/CoreReader/Adopted.lean:80](#line-code-leanified-corereader-adopted-lean-80) · definition\n\nCore dependencies: none.\n\n```lean\ndef generationSpecification (policy : Policy) : Prop := Generative policy\n```\n\n### `CoreReader.Adopted.generationCases`\n\n[leanified/CoreReader/Adopted.lean:862](#line-code-leanified-corereader-adopted-lean-862) · case\n\nCore dependencies: `propext`, `Quot.sound`.\n\n```lean\ntheorem generationCases :\n (Generative openPolicy ∧\n (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧\n (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1)))) ∧\n (neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy) ∧\n (Generative generatingSystem.policy ∧\n generatingSystem.policy.permitsVersion 0 0 ∧\n ¬ Expanded generatingSystem.current inflatedState ∧\n generatingSystem.current.inventory.length < inflatedState.inventory.length ∧\n generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧\n generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧\n generatingSystem.execute availableResources = some 6 ∧\n generatingSystem.execute { availableResources with experience := none } = none ∧\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-adopted-lean-80", + "found": true + }, + { + "anchor": "line-code-leanified-corereader-adopted-lean-862", + "found": true + } + ] + }, + { + "question": 6, + "language": "en", + "target": "t20", + "overview_line": 396, + "detail_line": 948, + "overview_text": "\n## T20 · Mutual application in one engineering system\n\nThe inherited duties apply to this system’s own principles, methods, value positions, capability reports and implementation choice. Actual normative contents enter its whole consistency theory.\n\n**Premises and representation:** Inherited fixes sharedContext and carries fulfilled generation, reflection, original empirical/inferential/value tasks, scope, capability and choice. ownTheory joins actual facts with every applicable OwnNorm content; consistency constrains this whole union.\n\n**Proof or check:** inheritedMutualApplication projects these actual fields and the full-content/support bridges; inheritedCurrent constructs them separately. Both actual reflection rules are self objects, and the evaluator’s revision test reports its local empty-sample defect.\n\n**Limits:** Projection does not derive all duties from one principle. Adoption markers are separate facts; they do not substitute for normative content. The sample-aware criticism is an application criterion, not a universal requirement for observations.\n\n**State:** accepted (theorem). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3)\n\n[Declarations, proof and line explanations](details.md#t20)\n\n\n", + "detail_text": "\n## T20 · Mutual application in one engineering system\n\nThe inherited duties apply to this system’s own principles, methods, value positions, capability reports and implementation choice. Actual normative contents enter its whole consistency theory.\n\n**Premises and representation:** Inherited fixes sharedContext and carries fulfilled generation, reflection, original empirical/inferential/value tasks, scope, capability and choice. ownTheory joins actual facts with every applicable OwnNorm content; consistency constrains this whole union.\n\n**Proof or check:** inheritedMutualApplication projects these actual fields and the full-content/support bridges; inheritedCurrent constructs them separately. Both actual reflection rules are self objects, and the evaluator’s revision test reports its local empty-sample defect.\n\n**Limits:** Projection does not derive all duties from one principle. Adoption markers are separate facts; they do not substitute for normative content. The sample-aware criticism is an application criterion, not a universal requirement for observations.\n\n**State:** accepted (theorem). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3)\n\n### `CoreReader.Engineering.inheritedMutualApplication`\n\n[leanified/CoreReader/Engineering/Integration.lean:420](#line-code-leanified-corereader-engineering-integration-lean-420) · theorem\n\nCore dependencies: `propext`.\n\n```lean\ntheorem inheritedMutualApplication (ctx : Context) (chosen : Candidate)\n (inherited : Inherited ctx chosen) :\n generationSpecification engineeringPolicy ∧\n reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self\n (selfModel chosen).performed ∧\n (∀ principle, valueSpecification (governancePosition principle)) ∧\n capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen) ∧\n choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons ∧\n (∀ fact, inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact)) ∧\n (∀ norm, normApplies chosen norm → ownTheory chosen (ownNormClaim chosen norm)) ∧\n (∀ claim, ownTheory chosen claim → inferentialSpecification (ownFactPremises chosen) claim) ∧\n consistencySpecification (engineeringSnapshot .evolvable 0)\n (engineeringSnapshot chosen 1) true :=\n```\n\n### `CoreReader.Engineering.inheritedMutualCases`\n\n[leanified/CoreReader/Engineering/Integration.lean:442](#line-code-leanified-corereader-engineering-integration-lean-442) · case\n\nCore dependencies: `propext`, `Classical.choice`, `Quot.sound`.\n\n```lean\ntheorem inheritedMutualCases :\n Inherited sharedContext .evolvable ∧\n valueSpecification (governancePosition .grounds) ∧\n capabilitySpecification (engineeringProcess .evolvable) (engineeringCapability .evolvable) ∧\n choiceSpecification chosenRequirements (chosenImplementation .evolvable) chosenReasons ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧\n (.generationRule : ReviewObject) ∈ (selfModel .evolvable).objects ∧\n (.assessmentRule : ReviewObject) ∈ (selfModel .evolvable).objects ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .assessmentRule, .revision⟩) = .counterexample :=\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-engineering-integration-lean-420", + "found": true + }, + { + "anchor": "line-code-leanified-corereader-engineering-integration-lean-442", + "found": true + } + ] + }, + { + "question": 6, + "language": "en", + "target": "t34", + "overview_line": 648, + "detail_line": 1527, + "overview_text": "\n## T34 · The contract-preservation theorem\n\nIf all identified in-scope observations are equal, the identified contract is preserved. A changed in-scope observation refutes preservation of that same contract.\n\n**Premises and representation:** contractPreservation receives a universal in-scope equality. The finite order/retry examples are separate checks and do not supply that universal premise automatically.\n\n**Proof or check:** The theorem returns the supplied equality as PreservesOn. changedObservationNotPreserved applies it to a differing input. The examples compute order changes, retry at 3, affected parties and a difference at the excluded input [99].\n\n**Limits:** A passing finite test suite is not a universal equality proof; preservation always retains its identified scope.\n\n**State:** accepted (theorem). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3)\n\n[Declarations, proof and line explanations](details.md#t34)\n\n\n", + "detail_text": "\n## T34 · The contract-preservation theorem\n\nIf all identified in-scope observations are equal, the identified contract is preserved. A changed in-scope observation refutes preservation of that same contract.\n\n**Premises and representation:** contractPreservation receives a universal in-scope equality. The finite order/retry examples are separate checks and do not supply that universal premise automatically.\n\n**Proof or check:** The theorem returns the supplied equality as PreservesOn. changedObservationNotPreserved applies it to a differing input. The examples compute order changes, retry at 3, affected parties and a difference at the excluded input [99].\n\n**Limits:** A passing finite test suite is not a universal equality proof; preservation always retains its identified scope.\n\n**State:** accepted (theorem). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3)\n\n### `CoreReader.Engineering.contractPreservation`\n\n[leanified/CoreReader/Engineering/Domain.lean:822](#line-code-leanified-corereader-engineering-domain-lean-822) · theorem\n\nCore dependencies: none.\n\n```lean\ntheorem contractPreservation {Input Output : Type} (scope : Input → Prop)\n (old new : Input → Output) (observations : ∀ x, scope x → new x = old x) :\n PreservesOn scope old new := observations\n```\n\n### `CoreReader.Engineering.contractDistinctions`\n\n[leanified/CoreReader/Engineering/Domain.lean:853](#line-code-leanified-corereader-engineering-domain-lean-853) · case\n\nCore dependencies: none.\n\n```lean\ntheorem contractDistinctions :\n PreservesFinite orderedUnique orderedRefactor ∧\n ¬ PreservesFinite orderedUnique sortedUnique ∧\n retry originalContract 3 = false ∧ retry revisedContract 3 = true ∧\n ¬ PreservesContractFinite originalContract revisedContract ∧\n affectedParties originalContract revisedContract = [\"queue consumer\", \"queue operator\"] ∧\n ¬ ContractChangeAccount originalContract revisedContract\n { normalRevision with affected := [\"queue consumer\"] } ∧\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-engineering-domain-lean-822", + "found": true + }, + { + "anchor": "line-code-leanified-corereader-engineering-domain-lean-853", + "found": true + } + ] + }, + { + "question": 6, + "language": "en", + "target": "t39", + "overview_line": 738, + "detail_line": 1740, + "overview_text": "\n## T39 · Inherited duties do not force the added priority\n\nIn that same applicable continuing context, a presentSimple selection satisfies every represented inherited duty but does not adopt the additional evolution priority.\n\n**Premises and representation:** Both options meet necessary requirements; the evolution advantage, credible design revision, successor/agent paths and complexity tradeoff are real within the model. There is no temporary-lifecycle or cost-departure escape.\n\n**Proof or check:** inheritedCurrent constructs the whole inherited bundle for presentSimple. Its actually adopted simplicity value has cost/work reasons and criticism limits. Applying the domain rule would require evolvable or a departure; both are excluded, so EvolutionPriority is false.\n\n**Limits:** The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance.\n\n**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3)\n\n[Declarations, proof and line explanations](details.md#t39)\n\n\n", + "detail_text": "\n## T39 · Inherited duties do not force the added priority\n\nIn that same applicable continuing context, a presentSimple selection satisfies every represented inherited duty but does not adopt the additional evolution priority.\n\n**Premises and representation:** Both options meet necessary requirements; the evolution advantage, credible design revision, successor/agent paths and complexity tradeoff are real within the model. There is no temporary-lifecycle or cost-departure escape.\n\n**Proof or check:** inheritedCurrent constructs the whole inherited bundle for presentSimple. Its actually adopted simplicity value has cost/work reasons and criticism limits. Applying the domain rule would require evolvable or a departure; both are excluded, so EvolutionPriority is false.\n\n**Limits:** The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance.\n\n**State:** accepted (nonentailment). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3)\n\n### `CoreReader.Engineering.inheritedDoesNotEntailPriority`\n\n[leanified/CoreReader/Engineering/Integration.lean:586](#line-code-leanified-corereader-engineering-integration-lean-586) · case\n\nCore dependencies: `propext`, `Classical.choice`, `Quot.sound`.\n\n```lean\ntheorem inheritedDoesNotEntailPriority :\n ∃ ctx : Context, ∃ chosen : Candidate,\n ctx = sharedContext ∧ chosen = .presentSimple ∧\n Inherited ctx chosen ∧ PriorityConditions ctx ∧\n Continuing ctx.activity ∧ ¬ BoundedLifecycle ctx.activity ∧\n ¬ HasThreat ctx .evolvable ∧ ¬ JustifiedDeparture ctx .evolvable ∧\n Meets ctx.required (ctx.profiles .presentSimple) ∧\n Meets ctx.required (ctx.profiles .evolvable) ∧\n credible ctx.evidence .designRevision ∧\n CanChange ctx.activity .evolvable .successor .designRevision ∧\n CanChange ctx.activity .evolvable .agent .designRevision ∧\n changeWork .evolvable .designRevision < changeWork chosen .designRevision ∧\n abstractionComplexity chosen < abstractionComplexity .evolvable ∧\n valueSpecification (selectionPosition chosen) ∧\n (selectionPosition chosen).commitment chosen ∧\n ¬ EvolutionPriority ctx chosen := by\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-engineering-integration-lean-586", + "found": true + } + ] + }, + { + "question": 6, + "language": "en", + "target": "t40", + "overview_line": 756, + "detail_line": 1781, + "overview_text": "\n## T40 · What the formal evidence cannot establish\n\nChecked specifications, conditional proofs and concrete witnesses remain distinct from empirical adequacy, sufficient real-world grounds and philosophical adoption.\n\n**Premises and representation:** Source fidelity is a separately recorded, bounded judgment. Costs, plans, histories, operational understanding and finite contracts retain their disclosed application interpretations.\n\n**Proof or check:** The edition binds actual source/code/type/dependency objects, independent initial records and later repairs. Prior failed or incomplete objects are not relabeled as successful historical executions.\n\n**Limits:** Build success, source tracing, agent agreement and self-application do not prove philosophical correctness. No frozen provable target has been deleted or recast as a boundary to obtain completion.\n\n**State:** accepted (boundary). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [organon.preamble#p1](#source-organon-preamble-p1), [organon.preamble#p2](#source-organon-preamble-p2), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.grounds#p1](#source-organon-grounds-p1), [organon.grounds.assessment#p1](#source-organon-grounds-assessment-p1), [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3), [organon.grounds.scope#p2](#source-organon-grounds-scope-p2), [organon.grounds.scope#p3](#source-organon-grounds-scope-p3), [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2), [organon.grounds.implementations#p1](#source-organon-grounds-implementations-p1), [organon.grounds.implementations#p2](#source-organon-grounds-implementations-p2), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.purpose#p1](#source-software-engineering-purpose-p1), [software-engineering.purpose#p2](#source-software-engineering-purpose-p2), [software-engineering.purpose#p3](#source-software-engineering-purpose-p3), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3), [software-engineering.evolution-meaning#p1](#source-software-engineering-evolution-meaning-p1), [software-engineering.evolution-meaning#p2](#source-software-engineering-evolution-meaning-p2), [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2), [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3), [software-engineering.revision#p1](#source-software-engineering-revision-p1), [software-engineering.revision#p2](#source-software-engineering-revision-p2)\n\n[Declarations, proof and line explanations](details.md#t40)\n\n\n## Source tracing appendix\n\n\n\n\n### `organon.preamble#p1`\n\n```text\nThis is a statement of Software Engineering Organon’s adopted philosophy. It expresses commitments, not factual assertions about every system or a proof of universal correctness.\n```\n\nState: **not_applicable**; Lean: not_checked; fidelity: not_applicable.\n\nDocumentary authority, interpretive role or disclosed boundary. No formal proof is assigned.\n\nRelated targets: [T01](#t01), [T40](#t40).\n\n\n\n\n\n\n### `organon.preamble#p2`\n\n```text\nThe quoted provisions, their meanings, and their conditions of application form the core. The charter and Grounds constrain one another; their grouping establishes neither a deductive hierarchy nor an order of priority. [Rationale](docs/rationale.md) supplies arguments and cases without adding obligations to this core. Skills are revisable applications under the repository’s stated objectives and constraints, not part of the philosophical commitments themselves.\n```\n\nState: **not_applicable**; Lean: not_checked; fidelity: not_applicable.\n\nDocumentary authority, interpretive role or disclosed boundary. No formal proof is assigned.\n\nRelated targets: [T01](#t01), [T40](#t40).\n\n\n\n\n\n\n### `organon.charter`\n\n```text\n\n\n```\n\nState: **not_applicable**; Lean: not_checked; fidelity: not_applicable.\n\nStructural heading without substantive direct-body content; no theorem is assigned.\n\n\n\n\n\n\n### `organon.charter.overview#p1`\n\n```text\n**Self-Transcendence · Internal Consistency · Reflexivity**\n```\n\nState: **not_applicable**; Lean: not_checked; fidelity: not_applicable.\n\nDocumentary authority, interpretive role or disclosed boundary. No formal proof is assigned.\n\nRelated targets: [T01](#t01).\n\n\n\n\n\n\n### `organon.charter.overview#p2`\n\n```text\n> A system is intrinsically oriented toward expanding what it can understand and construct. It brings itself and its principles within the scope of generation and assessment, with internal consistency constraining this process.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T02, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T01](#t01), [T02](#t02), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.overview#p3`\n\n```text\nThe overview connects three distinct requirements: self-transcendence establishes a generative orientation and refuses to treat existing forms as final, internal consistency constrains judgments held simultaneously, and reflexivity brings the system and its principles within the scope of their own generation and assessment. The provisions below specify the conditions for each.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T02, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T01](#t01), [T02](#t02), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.self-transcendence#p1`\n\n```text\n> A system is intrinsically oriented toward expanding what it can understand and construct. It does not regard any existing form as the endpoint of generation.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T02, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T02](#t02), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.self-transcendence.orientation#p1`\n\n```text\nA commitment to keeping generative possibilities open is distinct from valuing their expansion. A system has an intrinsic orientation when it regards that expansion as worth pursuing. Merely permitting change does not fully express this orientation.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T02, T03, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T02](#t02), [T03](#t03), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.self-transcendence.non-finality#p1`\n\n```text\nRefusing to regard an existing form as an endpoint keeps it open to being surpassed. “Existing form” includes a system’s current organization, methods, and principles, not only its appearance or artifacts. These remain within the scope of possible change; their revisability does not guarantee actual progress.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T02, T03, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T02](#t02), [T03](#t03), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.self-transcendence.limits#p1`\n\n```text\nWhether progress has actually occurred remains a separate judgment. Having the orientation does not guarantee progress. Progress cannot be established merely by an increase in the number of artifacts, levels of abstraction, or terms.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T03, T38. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T03](#t03), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.self-transcendence.limits#p2`\n\n```text\n- “Intrinsic orientation” expresses Organon’s philosophical commitment; it does not assert that all systems in fact develop autonomously.\n- Self-transcendence does not imply independence from external experience, knowledge, or collaboration, nor does it guarantee autonomous execution or self-improvement.\n- Refusing to regard an existing form as an endpoint does not require every action to produce change. Justified stability can coexist with a generative orientation.\n- Whether transcendence expands what can be understood and constructed requires discernible grounds; a system’s own claim of generation does not establish actual achievement.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T02, T03, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T02](#t02), [T03](#t03), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.charter.consistency#p1`\n\n```text\n> The principles and judgments a system holds simultaneously, together with their implications, must not yield contradictory judgments on the same question under the same assumptions, meanings of terms, and scope of application.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T04, T05, T38. A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T04](#t04), [T05](#t05), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.consistency.meaning#p1`\n\n```text\n“Held simultaneously” specifies which principles, judgments, and implications must hold together. Revision may withdraw an earlier judgment; old and new principles need not remain compatible forever. When a change has occurred, that change cannot be represented as though it had not occurred.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T04, T05, T38. A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T04](#t04), [T05](#t05), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.consistency.meaning#p2`\n\n```text\n“The same assumptions, meanings of terms, and scope of application” specifies the basis for comparing judgments. Divergent judgments under different conditions do not automatically constitute contradictions. Nor can unacknowledged changes in assumptions, meanings, or scope be used to conceal an existing contradiction.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T04, T05, T06, T38. A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. Consistency is not sufficient empirical or value support; the counterexamples concern the disclosed mathematical representation. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T04](#t04), [T05](#t05), [T06](#t06), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.consistency.limits#p1`\n\n```text\n- Tension between different assessments or values does not directly constitute a contradiction. Revision or qualification is needed when they require incompatible conclusions under the same conditions.\n- Internal consistency is not correctness or sufficiency. A set of principles may be internally consistent while relying on false assumptions or neglecting important questions.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T04, T05, T06, T38. A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. Consistency is not sufficient empirical or value support; the counterexamples concern the disclosed mathematical representation. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T04](#t04), [T05](#t05), [T06](#t06), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.reflexivity#p1`\n\n```text\n> A system’s principles of generation and assessment also apply to the system itself and to the formation, application, and revision of those principles.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T07, T38. Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T07](#t07), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.reflexivity.meaning#p1`\n\n```text\nReflexivity encompasses both the system itself and its principles. Assessment concerns not only whether the system conforms to its principles, but also how those principles are formed, where they apply, and why they may need revision. The formation and revision of principles thus also become objects of generation and assessment.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T07, T38. Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T07](#t07), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.reflexivity.limits#p1`\n\n```text\n- Applying principles equally retains their conditions of application. When the relevant conditions hold, being the system itself is not a basis for exemption. Nor does the requirement of reflexivity establish that every principle can be applied to itself without examining its applicability.\n- Self-application does not constitute self-proof. Subjecting a principle to its own assessment does not thereby establish its correctness.\n- That a revision is produced by the system itself does not give it sufficient grounds.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T07, T08, T38. Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T07](#t07), [T08](#t08), [T38](#t38).\n\n\n\n\n\n\n### `organon.grounds#p1`\n\n```text\n> The grounds of principles and judgments must be articulable and subject to assessment appropriate to the nature of the claim. The strength and scope of a claim must be proportionate to the support provided by its grounds.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T08, T09, T38. This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T08](#t08), [T09](#t09), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.assessment#p1`\n\n```text\nArticulation and assessment have distinct responsibilities. Articulability requires that concepts, assumptions, reasons, and limits can be identified. Assessment requires examining whether those grounds support the corresponding claim. Clearly expressed grounds are not thereby sufficiently established.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T09, T13, T38. This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. These distinctions do not require values, empirical evidence and inference to be reduced to one score. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T09](#t09), [T13](#t13), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.assessment#p2`\n\n```text\n| Type of claim | Responsibility of assessment | What cannot substitute for that responsibility |\n| --- | --- | --- |\n| Empirical claim | Examine observations, evidence, and performance, together with the conditions, scope, and uncertainty of their support for the claim. | Treating measurability or repeatability itself as proof of relevance, correctness, or value. |\n| Inferential claim | Examine whether the conclusion is supported by the stated assumptions and inferential relations. | Treating the absence of conflict between a conclusion and its assumptions as sufficient to establish that the conclusion follows from them. |\n| Value commitment | State the position taken, its reasons, limits of application, and consequences, and remain open to relevant criticism. | Presenting a commitment as an empirical fact or a necessary inference, or substituting self-assertion for reasons. |\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T09, T10, T11, T12, T13, T38. This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. Repeatability or measurability alone does not establish relevance, correctness or value; varying unobserved outcomes need not contradict limited support. Failure of support is not failure to assess correctly; consistency with assumptions is weaker than entailment. The application supplies a sufficient value assessment, not a universal requirement to prove every starting assumption or a proof that one value is universally best. These distinctions do not require values, empirical evidence and inference to be reduced to one score. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T09](#t09), [T10](#t10), [T11](#t11), [T12](#t12), [T13](#t13), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.assessment#p3`\n\n```text\nInitial value commitments may be stated explicitly as commitments; they need not prove all their own starting assumptions. The strength and scope of a claim do not require conversion to a common numerical scale. Different types of claims specify their support and limits in accordance with their nature.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T09, T12, T13, T38. This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. The application supplies a sufficient value assessment, not a universal requirement to prove every starting assumption or a proof that one value is universally best. These distinctions do not require values, empirical evidence and inference to be reduced to one score. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T09](#t09), [T12](#t12), [T13](#t13), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.scope#p1`\n\n```text\nPerformance is discerned within particular relations, conditions, and scopes of observation. A boundary helps specify what a comparison concerns, but local examples do not automatically support unconditional universal conclusions. A judgment cannot establish that relevant differences do not exist merely because its chosen scope omits them.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T14, T15, T38. A nonempty role string alone is not sufficient interpretation, and an unused method does not become compulsory. Omitting an input from comparison is not evidence that no relevant difference exists there. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T14](#t14), [T15](#t15), [T38](#t38).\n\n\n\n\n\n\n### `organon.grounds.scope#p2`\n\n```text\nMeasurement can make some differences comparable. Repeated assessment can help examine the stability of corresponding conclusions. Their roles, and the role of any assessment framework, must be explained relative to the claim and its context. Measurement, repeatability, and an assessment framework do not form a universally necessary chain on which all judgments must depend.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T14, T15, T38. A nonempty role string alone is not sufficient interpretation, and an unused method does not become compulsory. Omitting an input from comparison is not evidence that no relevant difference exists there. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T14](#t14), [T15](#t15), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.scope#p3`\n\n```text\nAn observation that has not been reproduced may still offer limited support, and random outcomes need not be identical on every occasion. The verifiability of observations, reproducibility of conditions, and stability of conclusions must be distinguished.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T14, T15, T38. A nonempty role string alone is not sufficient interpretation, and an unused method does not become compulsory. Omitting an input from comparison is not evidence that no relevant difference exists there. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T14](#t14), [T15](#t15), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.capabilities#p1`\n\n```text\nCapability claims are subject to Grounds: the capability claimed, its conditions, and the support for it must be identifiable. The core does not prescribe uniform definitions of method mastery, method generation, or capability levels. Applications specify the capabilities they assess and may require understanding, explanation, or performance under relevant variations.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T16, T17, T38. This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. An external assessor can ground the selected output claim without establishing how the assessed system understands its generation process. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T16](#t16), [T17](#t17), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.capabilities#p2`\n\n```text\nGrounds for a capability claim may be supplied by an external assessor. Their articulability does not by itself require the assessed system to understand or explain its internal generation process. Evidence of reliable output must be assessed against the capability actually claimed; it does not automatically establish understanding of that process. Nor can the number of method documents, terms, tools, or artifacts alone establish a capability beyond what that evidence supports.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T16, T17, T38. This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. An external assessor can ground the selected output claim without establishing how the assessed system understands its generation process. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T16](#t16), [T17](#t17), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.implementations#p1`\n\n```text\n> The choice of an implementation must be supported by reasons connected to the objectives and values pursued and to the relevant constraints. Its name, conventional use, or established status alone does not provide sufficient grounds for giving it priority.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T18, T19, T38. These are application reasons, not a universal cost function or a rule that conventional implementations must lose. No result asserts all implementations equivalent, multiple feasible implementations guaranteed, or the choice commitment derivable from chapter placement. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T18](#t18), [T19](#t19), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.implementations#p2`\n\n```text\nThis choice provision adds an additional evaluative commitment: name, conventional use, or established status alone is insufficient to establish priority. Grouping it under Grounds does not mean that it follows from the general requirement to assess reasons, or merely from the discernibility of performance. Conventions and existing arrangements may have practical significance, but that significance must be connected to the objectives and values pursued and to the relevant constraints.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T18, T19, T38. These are application reasons, not a universal cost function or a rule that conventional implementations must lose. No result asserts all implementations equivalent, multiple feasible implementations guaranteed, or the choice commitment derivable from chapter placement. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T18](#t18), [T19](#t19), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.implementations.limits#p1`\n\n```text\n- Openness does not make all implementations equivalent, nor does it guarantee multiple feasible implementations for the same objective.\n- A method’s explanatory power, limits of application, simplicity, and explicit process requirements may all provide grounded reasons for assessment. They cannot be excluded merely because they concern methods internal to the implementation.\n- Identical local performance does not establish overall equivalence. Relations, conditions, and the scope of comparison are constrained by the provisions of Grounds.\n- Openness does not reject an implementation merely because it already exists or is conventionally used. Relevant reasons may still give it priority.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T15, T18, T19, T38. Omitting an input from comparison is not evidence that no relevant difference exists there. These are application reasons, not a universal cost function or a rule that conventional implementations must lose. No result asserts all implementations equivalent, multiple feasible implementations guaranteed, or the choice commitment derivable from chapter placement. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T15](#t15), [T18](#t18), [T19](#t19), [T38](#t38).\n\n\n\n\n\n\n### `organon.relationships`\n\n```text\n\n\n```\n\nState: **not_applicable**; Lean: not_checked; fidelity: not_applicable.\n\nStructural heading without substantive direct-body content; no theorem is assigned.\n\n\n\n\n\n\n### `organon.relationships.roles#p1`\n\n```text\nThe charter states the generative orientation, the consistency constraint, and reflexive application. Grounds specifies support requirements for judgments and includes an additional commitment concerning implementation choices. Both parts belong to the core and constrain one another. Their placement neither makes Grounds a deduction from the charter nor gives the charter priority over it. Each commitment needs its own reasons.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T08, T20, T38, T39. This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. Projection does not derive all duties from one principle. Adoption markers are separate facts; they do not substitute for normative content. The sample-aware criticism is an application criterion, not a universal requirement for observations. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance.\n\nRelated targets: [T01](#t01), [T08](#t08), [T20](#t20), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `organon.relationships.roles#p2`\n\n```text\nInternal Consistency concerns whether simultaneously held judgments can hold together; Grounds concerns whether and how far a claim is supported. A conclusion may fail to conflict with its assumptions without being supported by them. Self-Transcendence specifies a generative orientation and non-finality; neither establishes actual capability. Applications may supply objectives, values, and capability definitions; claims made under those objectives, values, and definitions remain subject to the relevant core provisions.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T03, T06, T11, T16, T20, T38, T39. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. Consistency is not sufficient empirical or value support; the counterexamples concern the disclosed mathematical representation. Failure of support is not failure to assess correctly; consistency with assumptions is weaker than entailment. This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. Projection does not derive all duties from one principle. Adoption markers are separate facts; they do not substitute for normative content. The sample-aware criticism is an application criterion, not a universal requirement for observations. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance.\n\nRelated targets: [T03](#t03), [T06](#t06), [T11](#t11), [T16](#t16), [T20](#t20), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `organon.relationships.roles#p3`\n\n```text\nSelf-Transcendence does not substitute for Reflexivity: keeping existing forms open to being surpassed differs from applying relevant principles to the system and to their own formation, application, and revision. Reflexivity extends these requirements to the system and to the formation, application, and revision of its principles. The grounds and limits of the Grounds provisions must themselves be articulable. The system’s own capability claims remain subject to assessment, and this philosophy’s existing form cannot gain priority merely from its established status. Such mutual application provides no self-proof and does not remove conditions of application.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T07, T08, T16, T18, T20, T37, T38, T39. Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. These are application reasons, not a universal cost function or a rule that conventional implementations must lose. Projection does not derive all duties from one principle. Adoption markers are separate facts; they do not substitute for normative content. The sample-aware criticism is an application criterion, not a universal requirement for observations. Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance.\n\nRelated targets: [T07](#t07), [T08](#t08), [T16](#t16), [T18](#t18), [T20](#t20), [T37](#t37), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `organon.relationships.terms#p1`\n\n```text\n| Term | Meaning in this philosophy |\n| --- | --- |\n| Existing form | The system’s current organization, methods, and principles, not only its appearance or artifacts. |\n| Assessment | Examination of reasons, applicability, and observed performance; not limited to executable tests. |\n```\n\nState: **incomplete**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T02. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve.\n\nRelated targets: [T02](#t02), [T21](#t21).\n\n\n\n\n\n\n### `extensions#p1`\n\n```text\nThis chapter adds a software engineering commitment and specifies its meaning and limits. It does not claim that this commitment follows from the Charter or Grounds. Those provisions remain adopted and constrain its application.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T37, T38, T39. Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance.\n\nRelated targets: [T01](#t01), [T37](#t37), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.purpose#p1`\n\n```text\nSoftware engineering concerns the construction, operation, understanding, and revision of software within its relevant human and technical conditions. This philosophy guides decisions by people and agents; it does not attribute an intrinsic orientation to every software artifact.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T22, T23, T38. These numerical schedules are finite model data, not project time estimates. Scope alone does not prove every participant can perform every change. The result concerns the represented paths; lack of one documented path is not a universal impossibility theorem about all maintenance. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T22](#t22), [T23](#t23), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.purpose#p2`\n\n```text\nThe evolution capability considered here belongs to the continuing engineering activity: maintainers, including successor maintainers and agents, working with software, tools, and available knowledge. Code that its original author can modify is not on that ground alone shown to support that continuing activity.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T22, T23, T38. These numerical schedules are finite model data, not project time estimates. Scope alone does not prove every participant can perform every change. The result concerns the represented paths; lack of one documented path is not a universal impossibility theorem about all maintenance. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T22](#t22), [T23](#t23), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.purpose#p3`\n\n```text\nApply the following priority according to the software's credible lifecycle and maintenance expectations. A genuinely temporary script, bounded prototype, or retiring system may have little reason to support further evolution. Calling a continuing system temporary does not establish that condition.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T22, T23, T24, T38. These numerical schedules are finite model data, not project time estimates. Scope alone does not prove every participant can perform every change. The result concerns the represented paths; lack of one documented path is not a universal impossibility theorem about all maintenance. This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T22](#t22), [T23](#t23), [T24](#t24), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.evolution-priority#p1`\n\n```text\n> When relevant behavioral, safety, performance, and other necessary requirements are satisfied, give priority to continuing maintainers' ability to make credible future changes, including changes to the design itself, over present abstraction simplicity. Accept additional present abstraction complexity for that purpose, while allowing this preference to yield when the added costs threaten concrete engineering objectives.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T24, T25, T38, T39. This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. The theorem neither proves the value rule from facts nor establishes that every apparently complex design has the relevant advantage. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance.\n\nRelated targets: [T24](#t24), [T25](#t25), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.evolution-priority#p2`\n\n```text\nCredible directions of change have articulable grounds, such as a committed plan, relevant domain knowledge, or an applicable history of change. They need not already have multiple implementations. Their credibility remains open to revision; a conceivable change alone does not establish that it warrants accommodation now.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T24, T25, T26, T27, T38, T39. This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. The theorem neither proves the value rule from facts nor establishes that every apparently complex design has the relevant advantage. The proof checks stipulated evidence contents, not the real-world credibility or predictive calibration of arbitrary plans. No finite list of directions proves all future changes predictable or all omitted possibilities irrelevant. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance.\n\nRelated targets: [T24](#t24), [T25](#t25), [T26](#t26), [T27](#t27), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.evolution-priority#p3`\n\n```text\nThis is a default priority, not an obligation to maximize extensibility or retain every possibility. Costs include relevant burdens of understanding, construction, diagnosis, verification, coordination, operation, and eventual migration. A departure from the priority identifies the objective threatened and why the costs matter. No universal numerical exchange rate between these considerations is prescribed.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T24, T25, T26, T27, T28, T38, T39. This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. The theorem neither proves the value rule from facts nor establishes that every apparently complex design has the relevant advantage. The proof checks stipulated evidence contents, not the real-world credibility or predictive calibration of arbitrary plans. No finite list of directions proves all future changes predictable or all omitted possibilities irrelevant. The finite costs are modeled work/budget data. The source does not require every category to apply or provide a universal numerical tradeoff. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance.\n\nRelated targets: [T24](#t24), [T25](#t25), [T26](#t26), [T27](#t27), [T28](#t28), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.evolution-meaning#p1`\n\n```text\nEvolution includes adding capabilities, replacing implementations, deleting mechanisms, withdrawing abstractions, redrawing boundaries, and migrating away from an existing technology or model. Making additions within a fixed scheme does not establish equal ability to revise or leave that scheme. Not every such change can or should be made inexpensive.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T29, T30, T38. The enumerated constructors illustrate source dimensions and allow an other direction; they do not claim every possible evolution is represented or cheap. These counterexamples reject unjustified cross-dimension inference without adding a duty that every change be inexpensive. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T29](#t29), [T30](#t30), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.evolution-meaning#p2`\n\n```text\nAn evolution claim identifies the relevant changes and the maintainers' conditions. Independent changes, coordinated changes, preservation of existing obligations, and deliberate revision of those obligations can require different structures. A design's advantage on one dimension does not establish an advantage on every dimension.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T29, T30, T38. The enumerated constructors illustrate source dimensions and allow an other direction; they do not claim every possible evolution is represented or cheap. These counterexamples reject unjustified cross-dimension inference without adding a duty that every change be inexpensive. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T29](#t29), [T30](#t30), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.structural-judgment#p1`\n\n```text\nApply the preceding commitment to engineering consequences as a whole, including the relations among components, their observable contracts, and the work needed to understand and verify a change. An interface's shape, the number of modules or extension points, or the use of a named principle is not sufficient evidence of the claimed capability.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T31, T32, T37, T38. These are relevant finite inquiries, not a mandatory universal checklist or a real-world estimate of all boundary costs. The equal-work case preserves step units through an actual path transformation; these units are a disclosed model measure, not observed engineering effort. Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T31](#t31), [T32](#t32), [T37](#t37), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.structural-judgment#p2`\n\n```text\nThe relevant comparison may examine how a change propagates, which knowledge and obligations cross a boundary, which assumptions become fixed, and what a later withdrawal would require. A proposed boundary needs support for the changes it is meant to accommodate; introducing it does not by itself show that those changes became easier.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T31, T32, T38. These are relevant finite inquiries, not a mandatory universal checklist or a real-world estimate of all boundary costs. The equal-work case preserves step units through an actual path transformation; these units are a disclosed model measure, not observed engineering effort. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T31](#t31), [T32](#t32), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.structural-judgment#p3`\n\n```text\nDistinguish a transformation that preserves an identified observable contract from one that deliberately revises that contract. The latter needs a corresponding account of changed obligations and affected parties. This distinction does not require preserving every historical behavior or using a particular testing or migration procedure.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T33, T34, T38. The model does not require retaining every historical behavior, a particular test procedure, or an added universal notification obligation. A passing finite test suite is not a universal equality proof; preservation always retains its identified scope. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T33](#t33), [T34](#t34), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.revision#p1`\n\n```text\nChanged evidence about likely changes, maintenance conditions, costs, or objectives may justify revising a design or this priority's application. A revised judgment acknowledges material changes in its grounds; it does not make a failed prediction successful retrospectively.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T35, T36, T38. The recorded history is fixed model evidence; the theorem does not authenticate arbitrary real-world logs or prove every criticism response adequate. The result permits bounded retention, not permanent immunity from later grounds or criticism. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T35](#t35), [T36](#t36), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.revision#p2`\n\n```text\nRetaining a design can be justified when the relevant alternatives have no supported contribution or impose costs that defeat the objective. Reflexivity also keeps this engineering commitment and the methods used to assess evolution within the scope of criticism and revision. Continued change, agreement, or successful examples do not establish its universal correctness.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T35, T36, T37, T38. The recorded history is fixed model evidence; the theorem does not authenticate arbitrary real-world logs or prove every criticism response adequate. The result permits bounded retention, not permanent immunity from later grounds or criticism. Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T35](#t35), [T36](#t36), [T37](#t37), [T38](#t38), [T40](#t40).\n\n\n\n", + "detail_text": "\n## T40 · What the formal evidence cannot establish\n\nChecked specifications, conditional proofs and concrete witnesses remain distinct from empirical adequacy, sufficient real-world grounds and philosophical adoption.\n\n**Premises and representation:** Source fidelity is a separately recorded, bounded judgment. Costs, plans, histories, operational understanding and finite contracts retain their disclosed application interpretations.\n\n**Proof or check:** The edition binds actual source/code/type/dependency objects, independent initial records and later repairs. Prior failed or incomplete objects are not relabeled as successful historical executions.\n\n**Limits:** Build success, source tracing, agent agreement and self-application do not prove philosophical correctness. No frozen provable target has been deleted or recast as a boundary to obtain completion.\n\n**State:** accepted (boundary). This is the review of this frozen target, not an upgrade to a complete proof of its source paragraphs.\n\n**Sources:** [organon.preamble#p1](#source-organon-preamble-p1), [organon.preamble#p2](#source-organon-preamble-p2), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.grounds#p1](#source-organon-grounds-p1), [organon.grounds.assessment#p1](#source-organon-grounds-assessment-p1), [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3), [organon.grounds.scope#p2](#source-organon-grounds-scope-p2), [organon.grounds.scope#p3](#source-organon-grounds-scope-p3), [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2), [organon.grounds.implementations#p1](#source-organon-grounds-implementations-p1), [organon.grounds.implementations#p2](#source-organon-grounds-implementations-p2), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.purpose#p1](#source-software-engineering-purpose-p1), [software-engineering.purpose#p2](#source-software-engineering-purpose-p2), [software-engineering.purpose#p3](#source-software-engineering-purpose-p3), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3), [software-engineering.evolution-meaning#p1](#source-software-engineering-evolution-meaning-p1), [software-engineering.evolution-meaning#p2](#source-software-engineering-evolution-meaning-p2), [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2), [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3), [software-engineering.revision#p1](#source-software-engineering-revision-p1), [software-engineering.revision#p2](#source-software-engineering-revision-p2)\n\nThis boundary target has no Lean declaration.\n\n\n## Source tracing appendix\n\n\n\n\n### `organon.preamble#p1`\n\n```text\nThis is a statement of Software Engineering Organon’s adopted philosophy. It expresses commitments, not factual assertions about every system or a proof of universal correctness.\n```\n\nState: **not_applicable**; Lean: not_checked; fidelity: not_applicable.\n\nDocumentary authority, interpretive role or disclosed boundary. No formal proof is assigned.\n\nRelated targets: [T01](#t01), [T40](#t40).\n\n\n\n\n\n\n### `organon.preamble#p2`\n\n```text\nThe quoted provisions, their meanings, and their conditions of application form the core. The charter and Grounds constrain one another; their grouping establishes neither a deductive hierarchy nor an order of priority. [Rationale](docs/rationale.md) supplies arguments and cases without adding obligations to this core. Skills are revisable applications under the repository’s stated objectives and constraints, not part of the philosophical commitments themselves.\n```\n\nState: **not_applicable**; Lean: not_checked; fidelity: not_applicable.\n\nDocumentary authority, interpretive role or disclosed boundary. No formal proof is assigned.\n\nRelated targets: [T01](#t01), [T40](#t40).\n\n\n\n\n\n\n### `organon.charter`\n\n```text\n\n\n```\n\nState: **not_applicable**; Lean: not_checked; fidelity: not_applicable.\n\nStructural heading without substantive direct-body content; no theorem is assigned.\n\n\n\n\n\n\n### `organon.charter.overview#p1`\n\n```text\n**Self-Transcendence · Internal Consistency · Reflexivity**\n```\n\nState: **not_applicable**; Lean: not_checked; fidelity: not_applicable.\n\nDocumentary authority, interpretive role or disclosed boundary. No formal proof is assigned.\n\nRelated targets: [T01](#t01).\n\n\n\n\n\n\n### `organon.charter.overview#p2`\n\n```text\n> A system is intrinsically oriented toward expanding what it can understand and construct. It brings itself and its principles within the scope of generation and assessment, with internal consistency constraining this process.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T02, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T01](#t01), [T02](#t02), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.overview#p3`\n\n```text\nThe overview connects three distinct requirements: self-transcendence establishes a generative orientation and refuses to treat existing forms as final, internal consistency constrains judgments held simultaneously, and reflexivity brings the system and its principles within the scope of their own generation and assessment. The provisions below specify the conditions for each.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T02, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T01](#t01), [T02](#t02), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.self-transcendence#p1`\n\n```text\n> A system is intrinsically oriented toward expanding what it can understand and construct. It does not regard any existing form as the endpoint of generation.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T02, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T02](#t02), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.self-transcendence.orientation#p1`\n\n```text\nA commitment to keeping generative possibilities open is distinct from valuing their expansion. A system has an intrinsic orientation when it regards that expansion as worth pursuing. Merely permitting change does not fully express this orientation.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T02, T03, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T02](#t02), [T03](#t03), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.self-transcendence.non-finality#p1`\n\n```text\nRefusing to regard an existing form as an endpoint keeps it open to being surpassed. “Existing form” includes a system’s current organization, methods, and principles, not only its appearance or artifacts. These remain within the scope of possible change; their revisability does not guarantee actual progress.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T02, T03, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T02](#t02), [T03](#t03), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.self-transcendence.limits#p1`\n\n```text\nWhether progress has actually occurred remains a separate judgment. Having the orientation does not guarantee progress. Progress cannot be established merely by an increase in the number of artifacts, levels of abstraction, or terms.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T03, T38. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T03](#t03), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.self-transcendence.limits#p2`\n\n```text\n- “Intrinsic orientation” expresses Organon’s philosophical commitment; it does not assert that all systems in fact develop autonomously.\n- Self-transcendence does not imply independence from external experience, knowledge, or collaboration, nor does it guarantee autonomous execution or self-improvement.\n- Refusing to regard an existing form as an endpoint does not require every action to produce change. Justified stability can coexist with a generative orientation.\n- Whether transcendence expands what can be understood and constructed requires discernible grounds; a system’s own claim of generation does not establish actual achievement.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T02, T03, T38. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T02](#t02), [T03](#t03), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.charter.consistency#p1`\n\n```text\n> The principles and judgments a system holds simultaneously, together with their implications, must not yield contradictory judgments on the same question under the same assumptions, meanings of terms, and scope of application.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T04, T05, T38. A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T04](#t04), [T05](#t05), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.consistency.meaning#p1`\n\n```text\n“Held simultaneously” specifies which principles, judgments, and implications must hold together. Revision may withdraw an earlier judgment; old and new principles need not remain compatible forever. When a change has occurred, that change cannot be represented as though it had not occurred.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T04, T05, T38. A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T04](#t04), [T05](#t05), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.consistency.meaning#p2`\n\n```text\n“The same assumptions, meanings of terms, and scope of application” specifies the basis for comparing judgments. Divergent judgments under different conditions do not automatically constitute contradictions. Nor can unacknowledged changes in assumptions, meanings, or scope be used to conceal an existing contradiction.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T04, T05, T06, T38. A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. Consistency is not sufficient empirical or value support; the counterexamples concern the disclosed mathematical representation. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T04](#t04), [T05](#t05), [T06](#t06), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.consistency.limits#p1`\n\n```text\n- Tension between different assessments or values does not directly constitute a contradiction. Revision or qualification is needed when they require incompatible conclusions under the same conditions.\n- Internal consistency is not correctness or sufficiency. A set of principles may be internally consistent while relying on false assumptions or neglecting important questions.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T04, T05, T06, T38. A generic empty question domain can make the interface vacuous; the engineering instance uses an inhabited question family and a concrete admissible candidate. The result requires no permanent compatibility with withdrawn claims and does not identify every prose omission that could conceal a revision. Consistency is not sufficient empirical or value support; the counterexamples concern the disclosed mathematical representation. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T04](#t04), [T05](#t05), [T06](#t06), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.reflexivity#p1`\n\n```text\n> A system’s principles of generation and assessment also apply to the system itself and to the formation, application, and revision of those principles.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T07, T38. Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T07](#t07), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.reflexivity.meaning#p1`\n\n```text\nReflexivity encompasses both the system itself and its principles. Assessment concerns not only whether the system conforms to its principles, but also how those principles are formed, where they apply, and why they may need revision. The formation and revision of principles thus also become objects of generation and assessment.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T07, T38. Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T07](#t07), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.reflexivity.limits#p1`\n\n```text\n- Applying principles equally retains their conditions of application. When the relevant conditions hold, being the system itself is not a basis for exemption. Nor does the requirement of reflexivity establish that every principle can be applied to itself without examining its applicability.\n- Self-application does not constitute self-proof. Subjecting a principle to its own assessment does not thereby establish its correctness.\n- That a revision is produced by the system itself does not give it sufficient grounds.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T07, T08, T38. Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T07](#t07), [T08](#t08), [T38](#t38).\n\n\n\n\n\n\n### `organon.grounds#p1`\n\n```text\n> The grounds of principles and judgments must be articulable and subject to assessment appropriate to the nature of the claim. The strength and scope of a claim must be proportionate to the support provided by its grounds.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T08, T09, T38. This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T08](#t08), [T09](#t09), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.assessment#p1`\n\n```text\nArticulation and assessment have distinct responsibilities. Articulability requires that concepts, assumptions, reasons, and limits can be identified. Assessment requires examining whether those grounds support the corresponding claim. Clearly expressed grounds are not thereby sufficiently established.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T09, T13, T38. This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. These distinctions do not require values, empirical evidence and inference to be reduced to one score. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T09](#t09), [T13](#t13), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.assessment#p2`\n\n```text\n| Type of claim | Responsibility of assessment | What cannot substitute for that responsibility |\n| --- | --- | --- |\n| Empirical claim | Examine observations, evidence, and performance, together with the conditions, scope, and uncertainty of their support for the claim. | Treating measurability or repeatability itself as proof of relevance, correctness, or value. |\n| Inferential claim | Examine whether the conclusion is supported by the stated assumptions and inferential relations. | Treating the absence of conflict between a conclusion and its assumptions as sufficient to establish that the conclusion follows from them. |\n| Value commitment | State the position taken, its reasons, limits of application, and consequences, and remain open to relevant criticism. | Presenting a commitment as an empirical fact or a necessary inference, or substituting self-assertion for reasons. |\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T09, T10, T11, T12, T13, T38. This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. Repeatability or measurability alone does not establish relevance, correctness or value; varying unobserved outcomes need not contradict limited support. Failure of support is not failure to assess correctly; consistency with assumptions is weaker than entailment. The application supplies a sufficient value assessment, not a universal requirement to prove every starting assumption or a proof that one value is universally best. These distinctions do not require values, empirical evidence and inference to be reduced to one score. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T09](#t09), [T10](#t10), [T11](#t11), [T12](#t12), [T13](#t13), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.assessment#p3`\n\n```text\nInitial value commitments may be stated explicitly as commitments; they need not prove all their own starting assumptions. The strength and scope of a claim do not require conversion to a common numerical scale. Different types of claims specify their support and limits in accordance with their nature.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T09, T12, T13, T38. This is a sufficient finite adapter for declared tasks, not an exhaustive classification or an import of Core 0.1.3 all-aspect coverage. Declaring a new task does not license replacing an already fixed one. The application supplies a sufficient value assessment, not a universal requirement to prove every starting assumption or a proof that one value is universally best. These distinctions do not require values, empirical evidence and inference to be reduced to one score. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T09](#t09), [T12](#t12), [T13](#t13), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.scope#p1`\n\n```text\nPerformance is discerned within particular relations, conditions, and scopes of observation. A boundary helps specify what a comparison concerns, but local examples do not automatically support unconditional universal conclusions. A judgment cannot establish that relevant differences do not exist merely because its chosen scope omits them.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T14, T15, T38. A nonempty role string alone is not sufficient interpretation, and an unused method does not become compulsory. Omitting an input from comparison is not evidence that no relevant difference exists there. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T14](#t14), [T15](#t15), [T38](#t38).\n\n\n\n\n\n\n### `organon.grounds.scope#p2`\n\n```text\nMeasurement can make some differences comparable. Repeated assessment can help examine the stability of corresponding conclusions. Their roles, and the role of any assessment framework, must be explained relative to the claim and its context. Measurement, repeatability, and an assessment framework do not form a universally necessary chain on which all judgments must depend.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T14, T15, T38. A nonempty role string alone is not sufficient interpretation, and an unused method does not become compulsory. Omitting an input from comparison is not evidence that no relevant difference exists there. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T14](#t14), [T15](#t15), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.scope#p3`\n\n```text\nAn observation that has not been reproduced may still offer limited support, and random outcomes need not be identical on every occasion. The verifiability of observations, reproducibility of conditions, and stability of conclusions must be distinguished.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T14, T15, T38. A nonempty role string alone is not sufficient interpretation, and an unused method does not become compulsory. Omitting an input from comparison is not evidence that no relevant difference exists there. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T14](#t14), [T15](#t15), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.capabilities#p1`\n\n```text\nCapability claims are subject to Grounds: the capability claimed, its conditions, and the support for it must be identifiable. The core does not prescribe uniform definitions of method mastery, method generation, or capability levels. Applications specify the capabilities they assess and may require understanding, explanation, or performance under relevant variations.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T16, T17, T38. This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. An external assessor can ground the selected output claim without establishing how the assessed system understands its generation process. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T16](#t16), [T17](#t17), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.capabilities#p2`\n\n```text\nGrounds for a capability claim may be supplied by an external assessor. Their articulability does not by itself require the assessed system to understand or explain its internal generation process. Evidence of reliable output must be assessed against the capability actually claimed; it does not automatically establish understanding of that process. Nor can the number of method documents, terms, tools, or artifacts alone establish a capability beyond what that evidence supports.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T16, T17, T38. This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. An external assessor can ground the selected output claim without establishing how the assessed system understands its generation process. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T16](#t16), [T17](#t17), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.implementations#p1`\n\n```text\n> The choice of an implementation must be supported by reasons connected to the objectives and values pursued and to the relevant constraints. Its name, conventional use, or established status alone does not provide sufficient grounds for giving it priority.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T18, T19, T38. These are application reasons, not a universal cost function or a rule that conventional implementations must lose. No result asserts all implementations equivalent, multiple feasible implementations guaranteed, or the choice commitment derivable from chapter placement. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T18](#t18), [T19](#t19), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.implementations#p2`\n\n```text\nThis choice provision adds an additional evaluative commitment: name, conventional use, or established status alone is insufficient to establish priority. Grouping it under Grounds does not mean that it follows from the general requirement to assess reasons, or merely from the discernibility of performance. Conventions and existing arrangements may have practical significance, but that significance must be connected to the objectives and values pursued and to the relevant constraints.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T18, T19, T38. These are application reasons, not a universal cost function or a rule that conventional implementations must lose. No result asserts all implementations equivalent, multiple feasible implementations guaranteed, or the choice commitment derivable from chapter placement. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T18](#t18), [T19](#t19), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.implementations.limits#p1`\n\n```text\n- Openness does not make all implementations equivalent, nor does it guarantee multiple feasible implementations for the same objective.\n- A method’s explanatory power, limits of application, simplicity, and explicit process requirements may all provide grounded reasons for assessment. They cannot be excluded merely because they concern methods internal to the implementation.\n- Identical local performance does not establish overall equivalence. Relations, conditions, and the scope of comparison are constrained by the provisions of Grounds.\n- Openness does not reject an implementation merely because it already exists or is conventionally used. Relevant reasons may still give it priority.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T15, T18, T19, T38. Omitting an input from comparison is not evidence that no relevant difference exists there. These are application reasons, not a universal cost function or a rule that conventional implementations must lose. No result asserts all implementations equivalent, multiple feasible implementations guaranteed, or the choice commitment derivable from chapter placement. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T15](#t15), [T18](#t18), [T19](#t19), [T38](#t38).\n\n\n\n\n\n\n### `organon.relationships`\n\n```text\n\n\n```\n\nState: **not_applicable**; Lean: not_checked; fidelity: not_applicable.\n\nStructural heading without substantive direct-body content; no theorem is assigned.\n\n\n\n\n\n\n### `organon.relationships.roles#p1`\n\n```text\nThe charter states the generative orientation, the consistency constraint, and reflexive application. Grounds specifies support requirements for judgments and includes an additional commitment concerning implementation choices. Both parts belong to the core and constrain one another. Their placement neither makes Grounds a deduction from the charter nor gives the charter priority over it. Each commitment needs its own reasons.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T08, T20, T38, T39. This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. Projection does not derive all duties from one principle. Adoption markers are separate facts; they do not substitute for normative content. The sample-aware criticism is an application criterion, not a universal requirement for observations. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance.\n\nRelated targets: [T01](#t01), [T08](#t08), [T20](#t20), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `organon.relationships.roles#p2`\n\n```text\nInternal Consistency concerns whether simultaneously held judgments can hold together; Grounds concerns whether and how far a claim is supported. A conclusion may fail to conflict with its assumptions without being supported by them. Self-Transcendence specifies a generative orientation and non-finality; neither establishes actual capability. Applications may supply objectives, values, and capability definitions; claims made under those objectives, values, and definitions remain subject to the relevant core provisions.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T03, T06, T11, T16, T20, T38, T39. These are concrete non-entailments and a bounded support example, not empirical forecasts of learning or autonomous execution. Consistency is not sufficient empirical or value support; the counterexamples concern the disclosed mathematical representation. Failure of support is not failure to assess correctly; consistency with assumptions is weaker than entailment. This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. Projection does not derive all duties from one principle. Adoption markers are separate facts; they do not substitute for normative content. The sample-aware criticism is an application criterion, not a universal requirement for observations. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance.\n\nRelated targets: [T03](#t03), [T06](#t06), [T11](#t11), [T16](#t16), [T20](#t20), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `organon.relationships.roles#p3`\n\n```text\nSelf-Transcendence does not substitute for Reflexivity: keeping existing forms open to being surpassed differs from applying relevant principles to the system and to their own formation, application, and revision. Reflexivity extends these requirements to the system and to the formation, application, and revision of its principles. The grounds and limits of the Grounds provisions must themselves be articulable. The system’s own capability claims remain subject to assessment, and this philosophy’s existing form cannot gain priority merely from its established status. Such mutual application provides no self-proof and does not remove conditions of application.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T07, T08, T16, T18, T20, T37, T38, T39. Generic supplied predicates need interpretation. Nonempty concrete objects and actual records establish the modeled duty, not universal self-proof. This bounded countermodel does not prove independence in every possible encoding; keeping forms open is also not a substitute for actual reflexive work. This does not define psychological understanding universally. Exact identity is a scope premise; actual contract proofs, not identity alone, discharge support. These are application reasons, not a universal cost function or a rule that conventional implementations must lose. Projection does not derive all duties from one principle. Adoption markers are separate facts; they do not substitute for normative content. The sample-aware criticism is an application criterion, not a universal requirement for observations. Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance.\n\nRelated targets: [T07](#t07), [T08](#t08), [T16](#t16), [T18](#t18), [T20](#t20), [T37](#t37), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `organon.relationships.terms#p1`\n\n```text\n| Term | Meaning in this philosophy |\n| --- | --- |\n| Existing form | The system’s current organization, methods, and principles, not only its appearance or artifacts. |\n| Assessment | Examination of reasons, applicability, and observed performance; not limited to executable tests. |\n```\n\nState: **incomplete**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T02. The definition expresses an adopted duty; it neither causes change nor proves that all systems autonomously improve.\n\nRelated targets: [T02](#t02), [T21](#t21).\n\n\n\n\n\n\n### `extensions#p1`\n\n```text\nThis chapter adds a software engineering commitment and specifies its meaning and limits. It does not claim that this commitment follows from the Charter or Grounds. Those provisions remain adopted and constrain its application.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T37, T38, T39. Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance.\n\nRelated targets: [T01](#t01), [T37](#t37), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.purpose#p1`\n\n```text\nSoftware engineering concerns the construction, operation, understanding, and revision of software within its relevant human and technical conditions. This philosophy guides decisions by people and agents; it does not attribute an intrinsic orientation to every software artifact.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T22, T23, T38. These numerical schedules are finite model data, not project time estimates. Scope alone does not prove every participant can perform every change. The result concerns the represented paths; lack of one documented path is not a universal impossibility theorem about all maintenance. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T22](#t22), [T23](#t23), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.purpose#p2`\n\n```text\nThe evolution capability considered here belongs to the continuing engineering activity: maintainers, including successor maintainers and agents, working with software, tools, and available knowledge. Code that its original author can modify is not on that ground alone shown to support that continuing activity.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T22, T23, T38. These numerical schedules are finite model data, not project time estimates. Scope alone does not prove every participant can perform every change. The result concerns the represented paths; lack of one documented path is not a universal impossibility theorem about all maintenance. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T22](#t22), [T23](#t23), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.purpose#p3`\n\n```text\nApply the following priority according to the software's credible lifecycle and maintenance expectations. A genuinely temporary script, bounded prototype, or retiring system may have little reason to support further evolution. Calling a continuing system temporary does not establish that condition.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T22, T23, T24, T38. These numerical schedules are finite model data, not project time estimates. Scope alone does not prove every participant can perform every change. The result concerns the represented paths; lack of one documented path is not a universal impossibility theorem about all maintenance. This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T22](#t22), [T23](#t23), [T24](#t24), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.evolution-priority#p1`\n\n```text\n> When relevant behavioral, safety, performance, and other necessary requirements are satisfied, give priority to continuing maintainers' ability to make credible future changes, including changes to the design itself, over present abstraction simplicity. Accept additional present abstraction complexity for that purpose, while allowing this preference to yield when the added costs threaten concrete engineering objectives.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T24, T25, T38, T39. This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. The theorem neither proves the value rule from facts nor establishes that every apparently complex design has the relevant advantage. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance.\n\nRelated targets: [T24](#t24), [T25](#t25), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.evolution-priority#p2`\n\n```text\nCredible directions of change have articulable grounds, such as a committed plan, relevant domain knowledge, or an applicable history of change. They need not already have multiple implementations. Their credibility remains open to revision; a conceivable change alone does not establish that it warrants accommodation now.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T24, T25, T26, T27, T38, T39. This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. The theorem neither proves the value rule from facts nor establishes that every apparently complex design has the relevant advantage. The proof checks stipulated evidence contents, not the real-world credibility or predictive calibration of arbitrary plans. No finite list of directions proves all future changes predictable or all omitted possibilities irrelevant. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance.\n\nRelated targets: [T24](#t24), [T25](#t25), [T26](#t26), [T27](#t27), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.evolution-priority#p3`\n\n```text\nThis is a default priority, not an obligation to maximize extensibility or retain every possibility. Costs include relevant burdens of understanding, construction, diagnosis, verification, coordination, operation, and eventual migration. A departure from the priority identifies the objective threatened and why the costs matter. No universal numerical exchange rate between these considerations is prescribed.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T24, T25, T26, T27, T28, T38, T39. This specifies and exemplifies a default value priority; it does not deduce that priority from Core or require maximal extensibility. The theorem neither proves the value rule from facts nor establishes that every apparently complex design has the relevant advantage. The proof checks stipulated evidence contents, not the real-world credibility or predictive calibration of arbitrary plans. No finite list of directions proves all future changes predictable or all omitted possibilities irrelevant. The finite costs are modeled work/budget data. The source does not require every category to apply or provide a universal numerical tradeoff. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem. The countermodel permits different added value priorities, as Core does. It establishes bounded non-entailment, not that the domain priority is unjustified or that simple design is better for future maintenance.\n\nRelated targets: [T24](#t24), [T25](#t25), [T26](#t26), [T27](#t27), [T28](#t28), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.evolution-meaning#p1`\n\n```text\nEvolution includes adding capabilities, replacing implementations, deleting mechanisms, withdrawing abstractions, redrawing boundaries, and migrating away from an existing technology or model. Making additions within a fixed scheme does not establish equal ability to revise or leave that scheme. Not every such change can or should be made inexpensive.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T29, T30, T38. The enumerated constructors illustrate source dimensions and allow an other direction; they do not claim every possible evolution is represented or cheap. These counterexamples reject unjustified cross-dimension inference without adding a duty that every change be inexpensive. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T29](#t29), [T30](#t30), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.evolution-meaning#p2`\n\n```text\nAn evolution claim identifies the relevant changes and the maintainers' conditions. Independent changes, coordinated changes, preservation of existing obligations, and deliberate revision of those obligations can require different structures. A design's advantage on one dimension does not establish an advantage on every dimension.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T29, T30, T38. The enumerated constructors illustrate source dimensions and allow an other direction; they do not claim every possible evolution is represented or cheap. These counterexamples reject unjustified cross-dimension inference without adding a duty that every change be inexpensive. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T29](#t29), [T30](#t30), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.structural-judgment#p1`\n\n```text\nApply the preceding commitment to engineering consequences as a whole, including the relations among components, their observable contracts, and the work needed to understand and verify a change. An interface's shape, the number of modules or extension points, or the use of a named principle is not sufficient evidence of the claimed capability.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T31, T32, T37, T38. These are relevant finite inquiries, not a mandatory universal checklist or a real-world estimate of all boundary costs. The equal-work case preserves step units through an actual path transformation; these units are a disclosed model measure, not observed engineering effort. Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T31](#t31), [T32](#t32), [T37](#t37), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.structural-judgment#p2`\n\n```text\nThe relevant comparison may examine how a change propagates, which knowledge and obligations cross a boundary, which assumptions become fixed, and what a later withdrawal would require. A proposed boundary needs support for the changes it is meant to accommodate; introducing it does not by itself show that those changes became easier.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T31, T32, T38. These are relevant finite inquiries, not a mandatory universal checklist or a real-world estimate of all boundary costs. The equal-work case preserves step units through an actual path transformation; these units are a disclosed model measure, not observed engineering effort. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T31](#t31), [T32](#t32), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.structural-judgment#p3`\n\n```text\nDistinguish a transformation that preserves an identified observable contract from one that deliberately revises that contract. The latter needs a corresponding account of changed obligations and affected parties. This distinction does not require preserving every historical behavior or using a particular testing or migration procedure.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T33, T34, T38. The model does not require retaining every historical behavior, a particular test procedure, or an added universal notification obligation. A passing finite test suite is not a universal equality proof; preservation always retains its identified scope. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T33](#t33), [T34](#t34), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.revision#p1`\n\n```text\nChanged evidence about likely changes, maintenance conditions, costs, or objectives may justify revising a design or this priority's application. A revised judgment acknowledges material changes in its grounds; it does not make a failed prediction successful retrospectively.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T35, T36, T38. The recorded history is fixed model evidence; the theorem does not authenticate arbitrary real-world logs or prove every criticism response adequate. The result permits bounded retention, not permanent immunity from later grounds or criticism. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T35](#t35), [T36](#t36), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.revision#p2`\n\n```text\nRetaining a design can be justified when the relevant alternatives have no supported contribution or impose costs that defeat the objective. Reflexivity also keeps this engineering commitment and the methods used to assess evolution within the scope of criticism and revision. Continued change, agreement, or successful examples do not establish its universal correctness.\n```\n\nState: **limited**; Lean: passed; fidelity: partial.\n\nBounded source correspondence to T35, T36, T37, T38. The recorded history is fixed model evidence; the theorem does not authenticate arbitrary real-world logs or prove every criticism response adequate. The result permits bounded retention, not permanent immunity from later grounds or criticism. Successful self-assessment proves neither universal priority correctness nor universal sample requirements. The empty-sample criticism applies to the declared local assessment contract. This is satisfiability of the reviewed representation. It neither proves real engineering outcomes nor reduces philosophical value adoption to a theorem.\n\nRelated targets: [T35](#t35), [T36](#t36), [T37](#t37), [T38](#t38), [T40](#t40).\n\n\n\n## Complete code and line explanations\n\nEach file retains its exact checked contents. These line explanations are informed translations of the revised object; the initial blind account and rejected earlier judgments are retained separately.\n\n\n### `leanified/CoreReader/Adopted.lean`\n\n\n```lean\nimport CoreReader.Integration\n\nnamespace CoreReader.Adopted\nopen CoreReader.Logic CoreReader.Agency CoreReader.Evidence CoreReader.Choice\n\n/- These are three explicit mathematical assessment tasks, not an exhaustive or\nexclusive taxonomy of claim natures. A task fixes the original claim and support\ncontext before any candidate assessment is proposed. Its identity must be retained\nwhen comparing alternative assessments; taskOfFacet declares a new task and does\nnot authorize replacing a previously identified task. -/\ninductive AssessmentTask (W : Type) where\n | empirical (records : List (Record W)) (scope claim uncertainty : Claim W)\n | inferential (assumptions : Theory W) (claim : Claim W)\n | value (position : ValuePosition W)\n\ndef taskOfFacet {W : Type} : Facet W → AssessmentTask W\n | .empirical records scope claim uncertainty => .empirical records scope claim uncertainty\n | .inferential assumptions claim => .inferential assumptions claim\n | .value position => .value position\n\n/- This is a content-based sufficient adapter for the declared task, not a\nphilosophical rule requiring one unique assessment form. The empirical task may\nalso be assessed inferentially from exactly its observation/scope premises; its\noriginal uncertainty obligation is still checked. In particular, adding the\nconclusion as a new premise cannot replace the original empirical grounds.\nThe finite adapter need not accept every semantically equivalent presentation. -/\ndef NatureAppropriate {W : Type} : AssessmentTask W → Facet W → Prop\n | .empirical records scope claim uncertainty, .empirical actualRecords actualScope conclusion actualUncertainty =>\n actualRecords = records ∧ actualScope = scope ∧ conclusion = claim ∧ actualUncertainty = uncertainty\n | .empirical records scope claim uncertainty, .inferential assumptions conclusion =>\n assumptions = singleton (fun w => Compatible records w ∧ scope w) ∧\n conclusion = claim ∧ Supports records uncertainty\n | .inferential assumptions claim, .inferential actualAssumptions conclusion =>\n actualAssumptions = assumptions ∧ conclusion = claim\n | .value position, .value actualPosition => actualPosition = position\n | _, _ => False\n\ntheorem taskOfFacetAppropriate {W : Type} (f : Facet W) : NatureAppropriate (taskOfFacet f) f := by\n cases f with\n | empirical _ _ _ _ => exact ⟨rfl, rfl, rfl, rfl⟩\n | inferential _ _ => exact ⟨rfl, rfl⟩\n | value _ => rfl\n\n/- Core 0.1.2 requires appropriateness to the original claim task. Supplied facets\nare an explicit assessment scope, without importing Core 0.1.3's all-applicable\ncoverage requirement. No claim-kind label or freely assigned success flag proves\nappropriateness: NatureAppropriate compares the actual task and facet contents. -/\n/-- organon-map CoreReader.Adopted.Grounds012\norganon.grounds#p1 sha256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6\norganon.grounds.assessment#p1 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\n-/\ndef Grounds012 {W : Type} (claim : Claim W)\n (articulations : Facet W → Articulation W) (facets : List (Facet W))\n (task : AssessmentTask W) : Prop :=\n facets ≠ [] ∧ ∀ facet ∈ facets,\n facet.claim = claim ∧ Articulated (articulations facet) ∧\n FacetArticulated (articulations facet) facet ∧ FacetDischarged facet ∧\n NatureAppropriate task facet\n\n/- This helper proves the newly declared taskOfFacet f only. It supplies no\nappropriateness proof for another, previously fixed task with the same claim. -/\ntheorem grounds012Singleton {W : Type} (f : Facet W) (h : FacetDischarged f) :\n Grounds012 f.claim canonicalArticulation [f] (taskOfFacet f) := by\n refine ⟨by simp, ?_⟩\n intro facet hf\n cases List.mem_singleton.mp hf\n exact ⟨rfl, canonicalArticulated f h, canonicalFacetArticulated f, h, taskOfFacetAppropriate f⟩\n\n/-- organon-map CoreReader.Adopted.generationSpecification\norganon.charter.overview#p2 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c\norganon.charter.overview#p3 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c\norganon.charter.self-transcendence#p1 sha256 f4ca590e2ae15e3882f70c7b2bc46a8911c97cee547c8b137b5493fbf862c8c0\norganon.charter.self-transcendence.orientation#p1 sha256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf\norganon.charter.self-transcendence.non-finality#p1 sha256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8\norganon.charter.self-transcendence.limits#p2 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d\norganon.relationships.terms#p1 sha256 61cb7ce4f2920f1aa6771502b87a66536ae0504acccfebd9dd23bcc62756eddf\n-/\ndef generationSpecification (policy : Policy) : Prop := Generative policy\n\n/- All consequences use the whole currently held set. Historical reporting is\nseparate and does not require simultaneous compatibility with withdrawn claims. -/\n/-- organon-map CoreReader.Adopted.consistencySpecification\norganon.charter.consistency#p1 sha256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42\norganon.charter.consistency.meaning#p1 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75\n-/\ndef consistencySpecification {W Q : Type} (before after : Snapshot W Q)\n (reported : Bool) : Prop :=\n Consistent after.held after.context ∧ TruthfulReport before after reported\n\n/- A method's actual input and interpretation are parameters, permitting domain\nmethods as well as the small arithmetic adapter. Key coherence prevents records\nfor another method from silently satisfying the duty. -/\nstructure ReflexiveRule (T I O : Type) where\n key : PrincipleKey\n activity : Activity\n applicable : T → Prop\n input : T → I\n meaning : I → O → Prop\n\n/-- organon-map CoreReader.Adopted.reflexivitySpecification\norganon.charter.reflexivity#p1 sha256 13293b45c2fa89068c68ae7ef3c5df38f0efadb3ef3873d78a5ba67d9691a757\norganon.charter.reflexivity.meaning#p1 sha256 8a2caede01a43d8b6c60b54c78ac089c51868e9956f316948077ccee2e45c9cc\norganon.charter.reflexivity.limits#p1 sha256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\ndef reflexivitySpecification {T I O : Type} (rules : List (ReflexiveRule T I O))\n (isSelf : T → Prop) (performed : PrincipleKey → T → I → O → Prop) : Prop :=\n (∀ p ∈ rules, ∀ q ∈ rules, p.key = q.key → p = q) ∧\n ∀ rule ∈ rules, ∀ target, isSelf target → rule.applicable target →\n ∃ outcome, performed rule.key target (rule.input target) outcome ∧\n rule.meaning (rule.input target) outcome\n\ndef legacyRule (p : Principle) : ReflexiveRule Subject Inquiry WorkOutcome :=\n ⟨p.key, p.activity, p.applicable, p.inquiry,\n fun inquiry outcome => p.meaning inquiry (p.reasons inquiry.target) (p.limits inquiry.target) outcome⟩\n\ndef legacyPerformed (rules : List Principle) (records : List WorkRecord)\n (key : PrincipleKey) (target : Subject) (input : Inquiry) (outcome : WorkOutcome) : Prop :=\n ∃ p ∈ rules, ∃ record ∈ records,\n p.key = key ∧ ValidApplication rules p target record ∧\n record.inquiry = input ∧ record.outcome = outcome\n\ntheorem legacyReflexivity (owner : Nat) (rules : List Principle) (records : List WorkRecord)\n (h : Reflexive owner rules records) :\n reflexivitySpecification (rules.map legacyRule) (fun s => s.owner = owner)\n (legacyPerformed rules records) := by\n constructor\n · intro p hp q hq he\n obtain ⟨a, ha, rfl⟩ := List.mem_map.mp hp\n obtain ⟨b, hb, rfl⟩ := List.mem_map.mp hq\n exact congrArg legacyRule (h.1 a ha b hb he)\n · intro rule hr target ht happ\n obtain ⟨p, hp, rfl⟩ := List.mem_map.mp hr\n obtain ⟨record, hm, hv⟩ := h.2 p hp target ht happ\n refine ⟨record.outcome, ⟨p, hp, record, hm, rfl, hv, hv.inquiryIdentity, rfl⟩, ?_⟩\n change p.meaning (p.inquiry target) (p.reasons (p.inquiry target).target)\n (p.limits (p.inquiry target).target) record.outcome\n have ti : (p.inquiry target).target = target := hv.inquiryIdentity ▸ hv.inquiryTarget\n rw [ti]\n rw [← hv.inquiryIdentity, ← hv.reasonsIdentity, ← hv.limitsIdentity]\n exact hv.followsMeaning\n\n/- These are fulfillment interfaces for the named mathematical adapters, not\nuniversal empirical adequacy claims or definitions of all possible claim kinds. -/\n/-- organon-map CoreReader.Adopted.empiricalSpecification\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\n-/\ndef empiricalSpecification {W : Type} (records : List (Record W))\n (scope claim uncertainty : Claim W) : Prop :=\n Grounds012 claim canonicalArticulation [.empirical records scope claim uncertainty]\n (.empirical records scope claim uncertainty)\n\n/-- organon-map CoreReader.Adopted.inferentialSpecification\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\ndef inferentialSpecification {W : Type} (assumptions : Theory W) (claim : Claim W) : Prop :=\n Grounds012 claim canonicalArticulation [.inferential assumptions claim] (.inferential assumptions claim)\n\n/-- organon-map CoreReader.Adopted.valueSpecification\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\n-/\ndef valueSpecification {W : Type} (position : ValuePosition W) : Prop :=\n Grounds012 position.commitment canonicalArticulation [.value position] (.value position)\n\n/- Scope and roles are explicitly identified relative to a claim. An actually\nused method needs an explanation; unused methods are not required. The input\nrelation can encode contextual relevance without a universal numeric scale. -/\ninductive AssessmentMethod | measurement | repetition | framework\n deriving DecidableEq\nstructure ScopeAccount (W : Type) where\n claim : Claim W\n conditions : Claim W\n observationScope : Claim W\n relevant : W → W → Prop\n compared : W → W → Prop\n used : AssessmentMethod → Prop\n role : AssessmentMethod → String\n explains : AssessmentMethod → String → Claim W → Claim W → Prop\n\n/-- organon-map CoreReader.Adopted.scopeSpecification\norganon.grounds.scope#p1 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.scope#p2 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.scope#p3 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\n-/\ndef scopeSpecification {W : Type} (account : ScopeAccount W) : Prop :=\n (∀ a b, account.compared a b → account.conditions a ∧ account.conditions b ∧\n account.observationScope a ∧ account.observationScope b ∧ account.relevant a b) ∧\n ∀ method, account.used method → account.role method ≠ \"\" ∧\n account.explains method (account.role method) account.claim account.conditions\n\n/- A capability is selected by the application as an exact object-scoped\ncontract; whether explanation is part of it remains an application choice. -/\n/-- organon-map CoreReader.Adopted.capabilitySpecification\norganon.grounds.capabilities#p1 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0\norganon.grounds.capabilities#p2 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\ndef capabilitySpecification (assessed : Process) (contract : Claim Process) : Prop :=\n Grounds012 contract canonicalArticulation [processContractFacet assessed contract]\n (.inferential (processScope assessed) contract)\n\n/-- organon-map CoreReader.Adopted.choiceSpecification\norganon.grounds.implementations#p1 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c\norganon.grounds.implementations#p2 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c\norganon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\ndef choiceSpecification (requirements : Requirements) (implementation : Implementation)\n (reasons : List Reason) : Prop := JustifiedChoice requirements implementation reasons\n\n/- A collaborator supplies the successor operation. Removing that resource\nleaves the initial state; progress is tested on actual added operation content. -/\ndef collaborativeRevision (resources : ExternalResources) : State :=\n if resources.collaborator.isSome then extendedState else baseState\n\ntheorem collaborativeProgress :\n generationSpecification openPolicy ∧\n Expanded baseState (collaborativeRevision availableResources) ∧\n ¬ Expanded baseState (collaborativeRevision { availableResources with collaborator := none }) ∧\n assistedExecution ⟨none, none, none⟩ = none := by\n refine ⟨⟨Or.inl rfl, fun _ _ => trivial⟩, ?_, ?_, rfl⟩\n · exact Or.inr ⟨.successor, by simp [collaborativeRevision, availableResources, extendedState],\n by simp [baseState]⟩\n · simp [collaborativeRevision, Expanded, baseState]\n\n/- A truth-preserving current slice need not retain an earlier incompatible\nslice. Context changes and presentation order have separate semantics. -/\n/-- organon-map CoreReader.Adopted.consistencyConsequences\norganon.charter.consistency#p1 sha256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42\norganon.charter.consistency.meaning#p1 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75\n-/\ntheorem consistencyConsequences {W Q : Type} (t : Theory W) (c : Context W Q) (q : Q)\n (positive : Consequence t c q true) (negative : Consequence t c q false) :\n ¬ Consistent t c := conflictRequiresChange t c q positive negative\n\ndef broadBoolContext : Context Bool Unit := ⟨emptyTheory, onQuestion, fun _ => True⟩\n\ntheorem sliceConsistency :\n (∀ time, Consistent (revisionSlice time) broadBoolContext) ∧\n ¬ Consistent (union (revisionSlice 0) (revisionSlice 1)) broadBoolContext := by\n constructor\n · intro time\n apply consequenceConsistency\n exact ⟨time == 0, (modelsSingleton _ _).2 rfl, (by intro p hp; cases hp), trivial⟩\n · apply conflictRequiresChange _ _ ()\n · intro w h\n change w = true\n exact (modelsSingleton (fun w : Bool => w = true) w).1 ((modelsUnion _ _ _).1 h.1).1\n · intro w h ht\n have hn := (modelsSingleton _ _).1 ((modelsUnion _ _ _).1 h.1).2\n cases ht.symm.trans hn\n\ntheorem explicitlyConsistentLimits :\n Consistent (singleton (fun w : Bool => w = true)) broadBoolContext ∧\n ¬ Models (singleton (fun w : Bool => w = true)) false ∧\n Consistent (emptyTheory : Theory Bool) broadBoolContext ∧\n ¬ Entails emptyTheory (fun w : Bool => w = true) := by\n refine ⟨?_, consistentFalse.2, ?_, consistentIncomplete.2.1⟩\n · exact consequenceConsistency _ _ ⟨true, (modelsSingleton _ _).2 rfl,\n (by intro p hp; cases hp), trivial⟩\n · exact consequenceConsistency _ _ ⟨true, (by intro p hp; cases hp),\n (by intro p hp; cases hp), trivial⟩\n\n/- One observed input supports the local claim. The identical records cannot\nsupport all inputs, nor the stronger claim that both Boolean outputs are true. -/\ndef localFacet012 : Facet (Nat → Bool) :=\n .empirical [zeroRecord] (fun _ => True) (fun f => f 0 = true) (fun _ => True)\ndef globalFacet012 : Facet (Nat → Bool) :=\n .empirical [zeroRecord] (fun _ => True) allTrue (fun _ => True)\ndef strongFacet012 : Facet (Nat → Bool) :=\n .empirical [zeroRecord] (fun _ => True) (fun f => f 0 = true ∧ f 1 = true) (fun _ => True)\n\ntheorem localFacetChecked012 : FacetDischarged localFacet012 :=\n ⟨⟨localGenerator 0, (zeroCompatible _).2 rfl, trivial⟩,\n (fun f hf _ => (zeroCompatible f).1 hf), fun _ _ => trivial⟩\n\ntheorem scopeStrength012 :\n Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧\n Articulated (canonicalArticulation globalFacet012) ∧\n ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧\n ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012) := by\n refine ⟨grounds012Singleton _ localFacetChecked012, ⟨by simp [canonicalArticulation, globalFacet012],\n by simp [canonicalArticulation, globalFacet012]⟩, ?_, ?_⟩\n · intro h\n have checked := (h.2 globalFacet012 (by simp)).2.2.2.1\n have bad := checked.2.1 (localGenerator 0) ((zeroCompatible _).2 rfl) trivial 1\n cases bad\n · intro h\n have checked := (h.2 strongFacet012 (by simp)).2.2.2.1\n have bad := (checked.2.1 (localGenerator 0) ((zeroCompatible _).2 rfl) trivial).2\n cases bad\n\n/- A bounded outcome statement can leave another observable entirely unknown.\nThis represents uncertainty by a range of compatible worlds, not a probability. -/\ndef uncertainFacet012 : Facet (Bool × Bool) :=\n .empirical [temperatureRecord, temperatureRecord] (fun _ => True)\n (fun w => w.1 = true) (fun w => w.2 = true ∨ w.2 = false)\n\ntheorem uncertainSupported012 :\n empiricalSpecification [temperatureRecord, temperatureRecord] (fun _ => True)\n (fun w => w.1 = true) (fun w => w.2 = true ∨ w.2 = false) ∧\n Compatible [temperatureRecord, temperatureRecord] (true,true) ∧\n Compatible [temperatureRecord, temperatureRecord] (true,false) := by\n refine ⟨grounds012Singleton uncertainFacet012 ?_, temperatureCompatible true, temperatureCompatible false⟩\n refine ⟨⟨(true,false), temperatureCompatible false, trivial⟩, ?_, ?_⟩\n · intro w hw _; exact hw temperatureRecord (by simp)\n · intro w _; cases w.2 <;> simp\n\n/- Correctly completed negative examination is distinct from a supported\nconclusion. The countervaluation satisfies the same premises. -/\ndef InferenceExamined {W : Type} (premises : Theory W) (conclusion : Claim W)\n (accepted : Bool) : Prop := accepted = true ↔ Entails premises conclusion\n\ntheorem inferenceChecked012 :\n inferentialSpecification (singleton (fun n : Nat => n = 2)) (fun n => n + 1 = 3) ∧\n InferenceExamined (emptyTheory : Theory Bool) (fun w => w = true) false ∧\n Models (emptyTheory : Theory Bool) false ∧ ¬ ((fun w : Bool => w = true) false) := by\n refine ⟨grounds012Singleton arithmeticFacet noUniversalChain.1, ?_, (by intro p hp; cases hp), by decide⟩\n constructor\n · intro h; cases h\n · intro h; exact False.elim (consistentIncomplete.2.1 h)\n\n/- Closing a response to an actually relevant criticism fails the value\nprocedure even when its budget/benefit reasons and joint adoption are unchanged. -/\ndef closedPosition012 : ValuePosition Bool := { switchPosition with response := fun _ => none }\n\ntheorem closedCriticism012 : ¬ ValueProcedure closedPosition012 := by\n intro h\n obtain ⟨answer, ha, _⟩ := h.2.2.2 false trivial rfl\n cases ha\n\ntheorem valueFulfilled012 : valueSpecification switchPosition :=\n grounds012Singleton _ switchValueProcedure\n\n/- Qualitative entailment orders claims by implication, without conversion of\nvalue and empirical/inferential reasons to a common numeric scale. -/\ndef ClaimNoStronger {W : Type} (weaker stronger : Claim W) : Prop := ∀ w, stronger w → weaker w\n\ntheorem qualitativeProportionality012 :\n ClaimNoStronger (fun f : Nat → Bool => f 0 = true) allTrue ∧\n ¬ ClaimNoStronger allTrue (fun f : Nat → Bool => f 0 = true) ∧\n valueSpecification switchPosition := by\n refine ⟨fun _ h => h 0, ?_, valueFulfilled012⟩\n intro h\n have bad := h (localGenerator 0) rfl 1\n cases bad\n\ndef scopeRole012 : AssessmentMethod → String\n | .measurement => \"identify the output at the observed input zero\"\n | .repetition => \"check the same local conclusion against repeated input-zero observations\"\n | .framework => \"compare only the declared input; keep broader claims separate\"\n\ndef scopeRoleContent012 : AssessmentMethod → Prop\n | .measurement => Supports [zeroRecord] (fun f => f 0 = true)\n | .repetition => Supports [zeroRecord, zeroRecord] (fun f => f 0 = true)\n | .framework => ¬ Supports [zeroRecord] allTrue\n\ndef localScopeAccount012 : ScopeAccount Nat where\n claim n := (localGenerator 0) n = true\n conditions _ := True\n observationScope n := n = 0\n relevant a b := a = b\n compared a b := a = 0 ∧ b = 0\n used _ := True\n role := scopeRole012\n explains method text claim conditions :=\n text = scopeRole012 method ∧ claim = (fun n => localGenerator 0 n = true) ∧\n conditions = (fun _ => True) ∧ scopeRoleContent012 method\n\ntheorem scopeFulfilled012 : scopeSpecification localScopeAccount012 := by\n constructor\n · intro a b h\n exact ⟨trivial, trivial, h.1, h.2, h.1.trans h.2.symm⟩\n · intro method _\n refine ⟨?_, rfl, rfl, rfl, ?_⟩\n · cases method <;> decide\n · cases method with\n | measurement => exact singleObservation.2.2.1\n | repetition => intro f hf; exact hf zeroRecord (by simp)\n | framework => exact singleObservation.2.2.2\n\ntheorem capabilityFulfilled012 :\n capabilitySpecification outputOnlyProcess OutputContract ∧\n capabilitySpecification explainedProcess FullProcessContract ∧\n (∃ certificate : ExternalCertificate outputOnlyProcess,\n certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧\n ¬ ExplanationContract outputOnlyProcess := by\n refine ⟨grounds012Singleton _ (processContractDischarged _ _ outputCorrectByEvaluation),\n grounds012Singleton _ (processContractDischarged _ _ ?_),\n ⟨externalOutputCertificate, externalOutputCertificate.distinctParticipants,\n externalOutputCertificate.outputCorrect⟩, outputOnlyNoExplanation⟩\n exact ⟨fun _ => rfl, .doubleInput, rfl, fun _ => rfl⟩\n\n/- This application asks the assessed object to predict a multiplier mechanism\nat changed inputs and multiplier values. This is one operational understanding\ncriterion selected by an application, not a definition of psychological understanding.\nThe original output and explanation alone do not answer the additional questions. -/\nstructure MechanismApplication012 where\n process : Process\n answer : Nat → Nat → Nat\n\ndef mechanism012 (multiplier input : Nat) : Nat := multiplier * input\n\ndef UnderstandingApplication012 (assessed : MechanismApplication012) : Prop :=\n FullProcessContract assessed.process ∧\n (∀ input, assessed.process.output input = mechanism012 2 input) ∧\n ∀ multiplier input, assessed.answer multiplier input = mechanism012 multiplier input\n\ndef explainedWithoutVariation012 : MechanismApplication012 :=\n ⟨explainedProcess, fun _ input => input + input⟩\n\ndef mechanismResponder012 : MechanismApplication012 :=\n ⟨explainedProcess, mechanism012⟩\n\n/- The assessment task is fixed by this very application object and the stronger\ncontract. Identity is a scope premise; the positive case still proves the contract. -/\ndef understandingScope012 (assessed : MechanismApplication012) : Theory MechanismApplication012 :=\n singleton (fun candidate => candidate = assessed)\n\ndef understandingTask012 (assessed : MechanismApplication012) : AssessmentTask MechanismApplication012 :=\n .inferential (understandingScope012 assessed) UnderstandingApplication012\n\ndef understandingFacet012 (assessed : MechanismApplication012) : Facet MechanismApplication012 :=\n .inferential (understandingScope012 assessed) UnderstandingApplication012\n\ntheorem mechanismResponderUnderstands012 : UnderstandingApplication012 mechanismResponder012 := by\n refine ⟨⟨(fun _ => rfl), .doubleInput, rfl, (fun _ => rfl)⟩, ?_, fun _ _ => rfl⟩\n intro input\n simp [mechanismResponder012, explainedProcess, mechanism012, Nat.two_mul]\n\ntheorem explainedWithoutVariationFails012 :\n ¬ UnderstandingApplication012 explainedWithoutVariation012 := by\n intro h\n have wrong := h.2.2 3 1\n change 2 = 3 at wrong\n cases wrong\n\ntheorem understandingApplicationCases012 :\n explainedWithoutVariation012.process = mechanismResponder012.process ∧\n FullProcessContract explainedWithoutVariation012.process ∧\n ¬ UnderstandingApplication012 explainedWithoutVariation012 ∧\n UnderstandingApplication012 mechanismResponder012 ∧\n Grounds012 UnderstandingApplication012 canonicalArticulation\n [understandingFacet012 mechanismResponder012] (understandingTask012 mechanismResponder012) ∧\n ¬ Grounds012 UnderstandingApplication012 canonicalArticulation\n [understandingFacet012 explainedWithoutVariation012] (understandingTask012 explainedWithoutVariation012) := by\n refine ⟨rfl, ⟨(fun _ => rfl), .doubleInput, rfl, (fun _ => rfl)⟩,\n explainedWithoutVariationFails012, mechanismResponderUnderstands012, ?_, ?_⟩\n · apply grounds012Singleton\n refine ⟨⟨mechanismResponder012, (modelsSingleton _ _).2 rfl⟩, ?_⟩\n intro candidate hc\n have same := (modelsSingleton _ _).1 hc\n subst candidate\n exact mechanismResponderUnderstands012\n · intro h\n have discharged := (h.2 (understandingFacet012 explainedWithoutVariation012) (by simp)).2.2.2.1\n exact explainedWithoutVariationFails012\n (discharged.2 explainedWithoutVariation012 ((modelsSingleton _ _).2 rfl))\n\n/- The same exact application contract receives Grounds when its owner asserts\nit; external certificates change who supplies reasons, not the asserted object. -/\ndef OwnCapability012 (owner claimant : Nat) (process : Process) (contract : Claim Process) : Prop :=\n owner = claimant ∧ capabilitySpecification process contract\n\ntheorem ownCapability012 : OwnCapability012 7 7 outputOnlyProcess OutputContract :=\n ⟨rfl, capabilityFulfilled012.1⟩\n\n/- A complete represented Charter includes generation, whole-set consistency,\ntruthful revision reporting and applicable contentful self-work on the same\nsystem. The world type is the finite Candidate × Mode type. -/\ndef CompleteCharter012 (system : CoreReader.Integration.System)\n (world : CoreReader.Integration.World) : Prop :=\n generationSpecification (system.policy world) ∧\n consistencySpecification\n ⟨CoreReader.Integration.systemHeld system, CoreReader.Integration.systemContext system, 0⟩\n ⟨CoreReader.Integration.systemHeld system, CoreReader.Integration.systemContext system, 0⟩ false ∧\n reflexivitySpecification ((system.rules world).map legacyRule) (fun s => s.owner = system.owner)\n (legacyPerformed (system.rules world) (system.work world)) ∧\n (system.policy world).current system.method.form ∧\n (system.policy world).current system.principleForm\n\ntheorem completeCharter012 : CompleteCharter012 CoreReader.Integration.actualSystem CoreReader.Integration.actual := by\n refine ⟨CoreReader.Integration.charterChecked.1,\n ⟨CoreReader.Integration.jointConsistent, ?_⟩,\n legacyReflexivity 0 _ _ (completeOwnWork_reflexive 0), rfl, rfl⟩\n rintro (h | h)\n · exact False.elim (h ⟨fun _ => Iff.rfl, fun _ => Iff.rfl, fun _ _ => Iff.rfl, fun _ => Iff.rfl⟩)\n · exact False.elim (h rfl)\n\ntheorem charterWithoutGrounds012 :\n CompleteCharter012 CoreReader.Integration.actualSystem CoreReader.Integration.actual ∧\n Admissible CoreReader.Integration.held CoreReader.Integration.context CoreReader.Integration.actual ∧\n Compatible [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.actual ∧\n Articulated (canonicalArticulation CoreReader.Integration.unsupportedCapabilityFacet) ∧\n ¬ Supports [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.capability ∧\n ¬ Grounds012 CoreReader.Integration.capability canonicalArticulation\n [CoreReader.Integration.unsupportedCapabilityFacet]\n (taskOfFacet CoreReader.Integration.unsupportedCapabilityFacet) := by\n refine ⟨completeCharter012, CoreReader.Integration.actualAdmissible,\n (by intro r hr; cases List.mem_singleton.mp hr; rfl),\n ⟨by simp [canonicalArticulation, CoreReader.Integration.unsupportedCapabilityFacet],\n by simp [canonicalArticulation, CoreReader.Integration.unsupportedCapabilityFacet]⟩,\n CoreReader.Integration.costDoesNotSupportOutput, ?_⟩\n intro h\n have checked := (h.2 CoreReader.Integration.unsupportedCapabilityFacet (by simp)).2.2.2.1\n exact CoreReader.Integration.costDoesNotSupportOutput (fun w hw => checked.2.1 w hw trivial)\n\n/- Permission to assert is evaluated on the same claim, articulation and facets.\nThe countercase derives inadequacy from the actual unobserved output. -/\ndef groundsPermission012 {W : Type} (enabled : Bool) (claim : Claim W)\n (a : Facet W → Articulation W) (facets : List (Facet W)) (task : AssessmentTask W) : Prop :=\n if enabled then Grounds012 claim a facets task else True\n\ndef GroundsProvision012 (enabled : Bool) : Prop :=\n ∀ (claim : Claim (Nat → Bool)) a facets task,\n groundsPermission012 enabled claim a facets task → Grounds012 claim a facets task\n\ntheorem groundsProvision012Meaning (enabled : Bool) : GroundsProvision012 enabled ↔ enabled = true := by\n cases enabled with\n | true => exact ⟨fun _ => rfl, fun _ _ _ _ _ h => h⟩\n | false =>\n constructor\n · intro h\n exact False.elim (scopeStrength012.2.2.1 (h globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) trivial))\n · intro h; cases h\n\n/- The value rationale concerns this fixed empirical assertion task. The\nsame task, observed grounds and concrete counterworld are retained when the\npermission policy is enabled or disabled. -/\ndef groundsExperimentTask012 : AssessmentTask (Nat → Bool) :=\n .empirical [zeroRecord] (fun _ => True) allTrue (fun _ => True)\n\nnoncomputable def groundsExperiment012 (enabled : Bool) : Bool :=\n @decide (groundsPermission012 enabled allTrue canonicalArticulation [globalFacet012]\n groundsExperimentTask012) (Classical.propDecidable _)\n\nnoncomputable def groundsPosition012 : ValuePosition Bool where\n Position := Bool\n Outcome := Bool\n adopted := true\n selected := id\n outcome _ enabled := groundsExperiment012 enabled\n objective accepted := accepted = false\n constraints _ enabled := GroundsProvision012 enabled\n starting := singleton (fun enabled => enabled = true)\n reasons := [fun _ _ => Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0)]\n limits _ := True\n relevantCriticism _ := ¬ Supports [zeroRecord] allTrue\n response _ := some \"retain local support and reject the unsupported universal conclusion\"\n\ntheorem groundsPosition012Checked : ValueProcedure groundsPosition012 := by\n refine ⟨by simp [groundsPosition012], ?_, ?_, ?_⟩\n · refine ⟨true, (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩\n intro reason hr\n cases List.mem_singleton.mp hr\n refine ⟨(zeroCompatible _).2 rfl, ?_⟩\n intro h; have bad := h 1; cases bad\n · intro w _ _ reasons\n have counterworld := reasons _ (List.mem_singleton.mpr rfl)\n change Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0) at counterworld\n have unsupported : ¬ Grounds012 allTrue canonicalArticulation [globalFacet012] groundsExperimentTask012 := by\n intro h\n have discharged := (h.2 globalFacet012 (by simp)).2.2.2.1\n exact counterworld.2 (discharged.2.1 (localGenerator 0) counterworld.1 trivial)\n refine ⟨?_, (groundsProvision012Meaning true).2 rfl⟩\n exact @decide_eq_false (groundsPermission012 true allTrue canonicalArticulation [globalFacet012]\n groundsExperimentTask012) (Classical.propDecidable _) unsupported\n · intro w _ _; exact ⟨_, rfl, by decide⟩\n\ntheorem groundsRationaleExperiment012 :\n Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0) ∧\n groundsExperiment012 true = false ∧ groundsExperiment012 false = true ∧\n groundsPosition012.outcome true true = groundsExperiment012 true ∧\n groundsPosition012.outcome true false = groundsExperiment012 false := by\n refine ⟨(zeroCompatible _).2 rfl, ?_, ?_, ?_, rfl, rfl⟩\n · intro h; have bad := h 1; cases bad\n · have actualReasons : ∀ reason ∈ groundsPosition012.reasons, reason true groundsPosition012.adopted := by\n intro reason member\n cases List.mem_singleton.mp member\n refine ⟨(zeroCompatible _).2 rfl, ?_⟩\n intro h; have bad := h 1; cases bad\n exact (groundsPosition012Checked.2.2.1 true ((modelsSingleton _ _).2 rfl) trivial actualReasons).1\n · exact @decide_eq_true (groundsPermission012 false allTrue canonicalArticulation [globalFacet012]\n groundsExperimentTask012) (Classical.propDecidable _) trivial\n\ntheorem groundsOnGrounds012 :\n Grounds012 (fun enabled => GroundsProvision012 enabled) canonicalArticulation [.value groundsPosition012] (.value groundsPosition012) ∧\n groundsPosition012.limits true ∧ groundsPosition012.relevantCriticism true := by\n have same : (Facet.value groundsPosition012).claim = (fun enabled => GroundsProvision012 enabled) := by\n funext enabled\n exact propext (groundsProvision012Meaning enabled).symm\n refine ⟨?_, trivial, singleObservation.2.2.2⟩\n rw [← same]\n exact grounds012Singleton _ groundsPosition012Checked\n\ntheorem reflexiveTargets012 :\n reflexivitySpecification ((ownRules 0).map legacyRule) (fun s => s.owner = 0)\n (legacyPerformed (ownRules 0) (completeOwnWork 0)) ∧\n (∀ phase, Performed (completeOwnWork 0) (.process 0 0 phase) .assessment) ∧\n Performed (completeOwnWork 0) (.system 0) .assessment ∧\n reflexivitySpecification ([applicationRule].map legacyRule) (fun s => s.owner = 0)\n (legacyPerformed [applicationRule] applicationWork) ∧\n ¬ Performed applicationWork (.system 0) .assessment := by\n refine ⟨legacyReflexivity 0 _ _ (completeOwnWork_reflexive 0), ?_,\n ownAssessmentPerformed 0 (.system 0) (by simp [ownSubjects]),\n legacyReflexivity 0 _ _ applicationWork_reflexive, (applicabilityRetained 0 [] []).2.2.2⟩\n intro phase\n apply ownAssessmentPerformed\n cases phase <;> simp [ownSubjects]\n\ntheorem achievementSupported012 :\n Grounds012 transitionAchievement canonicalArticulation [transitionFacet] (taskOfFacet transitionFacet) ∧\n Compatible [transitionPerformanceRecord] .extend ∧\n transitionAchievement .extend ∧ ¬ transitionAchievement .inflate ∧\n ¬ Supports [transitionReportRecord] transitionAchievement := by\n refine ⟨grounds012Singleton _ transitionFacetDischarged, ?_, ?_, ?_, transitionReportDoesNotSupport.2.2⟩\n · exact (transitionPerformanceCompatible .extend).mpr rfl\n · simp [transitionAchievement, transitionBefore, transitionAfter, Expanded, baseState, extendedState]\n · simp [transitionAchievement, transitionBefore, transitionAfter, Expanded, baseState, inflatedState]\n\ntheorem semanticOrder012 : ∀ p q : Claim Bool,\n ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r :=\n representationOrderIrrelevant\n\ndef clearFalseArgument012 : Articulation Bool :=\n ⟨[\"the actual switch is on\"], singleton (fun w => w = true), [fun w => w = true], fun _ => True⟩\n\ntheorem clearFalseReason012 :\n Articulated clearFalseArgument012 ∧ ¬ Models clearFalseArgument012.assumptions false :=\n ⟨⟨by simp [clearFalseArgument012], by simp [clearFalseArgument012]⟩, consistentFalse.2⟩\n\ndef valueNeutralRecord012 : Record Bool := ⟨fun _ => true, true⟩\n\ntheorem valueNotFact012 :\n valueSpecification switchPosition ∧\n Compatible [valueNeutralRecord012] false ∧\n ¬ Supports [valueNeutralRecord012] switchPosition.commitment ∧\n ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment := by\n have compatible : Compatible [valueNeutralRecord012] false := by\n intro r hr; cases List.mem_singleton.mp hr; rfl\n refine ⟨valueFulfilled012, compatible, ?_, valueWithoutSelfProof.2.2.1⟩\n intro h\n have bad := h false compatible\n cases bad\n\ndef wrongExplanation012 : Implementation := { identityImpl with explanation := fun n => n + 1 }\n\ntheorem internalReasonDistinguishes012 :\n (∀ n, identityImpl.run n = wrongExplanation012.run n) ∧\n Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧\n Relevant identityRequirements identityImpl (.method .explanation) ∧\n ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation) := by\n refine ⟨fun _ => rfl, identityFeasible, identityFeasible, internalReasons.1, ?_⟩\n intro h\n have bad := h.2 0 trivial\n cases bad\n\ntheorem inventoryCases012 : ∀ kind : InventoryKind,\n Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .copy ∧\n ¬ Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .successor := by\n intro kind\n simp [Available]\n\n\ndef selfExemptRule012 : ReflexiveRule Nat Nat Bool :=\n ⟨⟨0,1⟩, .assessment, fun _ => True, id,\n fun input output => output = ownArithmeticPrinciple input⟩\ndef selfExemptPerformed012 (key : PrincipleKey) (target input : Nat) (output : Bool) : Prop :=\n key = ⟨0,1⟩ ∧ target = 1 ∧ input = target ∧ output = ownArithmeticPrinciple input\n\ntheorem openSelfExempt012 :\n generationSpecification openPolicy ∧ openPolicy.revisable ⟨.principle,0⟩ ∧\n selfExemptPerformed012 ⟨0,1⟩ 1 1 true ∧\n selfExemptRule012.applicable 0 ∧\n ¬ reflexivitySpecification [selfExemptRule012] (fun target => target = 0) selfExemptPerformed012 := by\n refine ⟨⟨Or.inl rfl, fun _ _ => trivial⟩, trivial, ⟨rfl,rfl,rfl,by decide⟩, trivial, ?_⟩\n intro h\n obtain ⟨outcome, performed, _⟩ := h.2 selfExemptRule012 (by simp) 0 rfl trivial\n cases performed.2.1\n\ntheorem ownPhilosophyStatus012 :\n ¬ choiceSpecification CoreReader.Integration.proposalRequirements\n (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation\n [.status .standing] ∧\n choiceSpecification CoreReader.Integration.proposalRequirements\n (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation\n [.method .output] :=\n ⟨CoreReader.Integration.existingPhilosophyNotPrivileged.2.2.1,\n CoreReader.Integration.existingPhilosophyNotPrivileged.2.2.2.1⟩\n\ndef jointContext012 : Context (Bool × Bool) Unit :=\n ⟨emptyTheory, fun _ w => w.2 = true, fun _ => True⟩\n\ntheorem jointImplicationConflict012 :\n Consequence jointTheory jointContext012 () true ∧\n Consequence jointTheory jointContext012 () false ∧\n ¬ Consistent jointTheory jointContext012 := by\n have positive : Consequence jointTheory jointContext012 () true := by\n intro w hw\n exact (hw.1 premiseRule (Or.inr (Or.inl rfl))) (hw.1 premiseP (Or.inl rfl))\n have negative : Consequence jointTheory jointContext012 () false := by\n intro w hw\n exact hw.1 premiseNotQ (Or.inr (Or.inr rfl))\n exact ⟨positive, negative, conflictRequiresChange _ _ () positive negative⟩\n\ndef tensionContext012 : Context Nat Unit :=\n ⟨emptyTheory, fun _ n => n ≤ 6, fun _ => True⟩\n\ntheorem tensionConsistent012 :\n Consistent (union (singleton (fun n : Nat => 4 ≤ n)) (singleton (fun n => n ≤ 6))) tensionContext012 := by\n apply consequenceConsistency\n exact ⟨5, (modelsUnion _ _ _).2 ⟨(modelsSingleton _ _).2 (by decide),\n (modelsSingleton _ _).2 (by decide)⟩, (by intro p hp; cases hp), trivial⟩\n\ntheorem qualitativeUnmeasured012 :\n inferentialSpecification (singleton (fun on : Bool => on = true)) (fun on => on ≠ false) ∧\n usesObservation (Facet.inferential (singleton (fun on : Bool => on = true)) (fun on => on ≠ false)) = false := by\n refine ⟨grounds012Singleton _ ⟨⟨true, (modelsSingleton _ _).2 rfl⟩, ?_⟩, rfl⟩\n intro on hon hf\n have ht := (modelsSingleton (fun on : Bool => on = true) on).1 hon\n cases ht.symm.trans hf\n\n\ntheorem allStatusOnly012 : ∀ kind : StatusKind,\n ¬ choiceSpecification identityRequirements identityImpl [.status kind] :=\n statusOnlyFails identityRequirements identityImpl\n\n/- A finite two-draw experiment assigns positive equal weights to both possible\noutcomes. It models possibility and a stable conclusion, not empirical claims\nabout any physical random-number source. -/\ndef drawWeight012 (_draw : Bool) : Nat := 1\ndef randomTrial012 (draw : Bool) : Trial :=\n ⟨0, if draw then 1 else 2, if draw then 1 else 2⟩\n\ntheorem randomOutcomes012 :\n drawWeight012 true > 0 ∧ drawWeight012 false > 0 ∧\n drawWeight012 true = drawWeight012 false ∧\n Reproduced (randomTrial012 true) (randomTrial012 false) ∧\n (randomTrial012 true).actualOutcome ≠ (randomTrial012 false).actualOutcome ∧\n (∀ draw, Verified (randomTrial012 draw) ∧ Bounded (randomTrial012 draw)) := by\n refine ⟨by decide, by decide, rfl, rfl, by decide, ?_⟩\n intro draw\n cases draw <;> simp [Verified, Bounded, randomTrial012]\n\n\n/- Original tasks are fixed independently of the candidate substitutions below. -/\ndef originalGlobalTask012 : AssessmentTask (Nat → Bool) :=\n .empirical [zeroRecord] (fun _ => True) allTrue (fun _ => True)\ndef originalLocalTask012 : AssessmentTask (Nat → Bool) :=\n .empirical [zeroRecord] (fun _ => True) (fun f => f 0 = true) (fun _ => True)\n\ndef circularGlobalFacet012 : Facet (Nat → Bool) := .inferential (singleton allTrue) allTrue\n\ntheorem circularGlobalConditional012 : FacetDischarged circularGlobalFacet012 := by\n refine ⟨⟨fun _ => true, (modelsSingleton _ _).2 (fun _ => rfl)⟩, ?_⟩\n intro f hf\n exact (modelsSingleton _ _).1 hf\n\ntheorem circularSubstitutionRejected012 :\n Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] (taskOfFacet circularGlobalFacet012) ∧\n ¬ NatureAppropriate originalGlobalTask012 circularGlobalFacet012 ∧\n ¬ Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] originalGlobalTask012 := by\n have inappropriate : ¬ NatureAppropriate originalGlobalTask012 circularGlobalFacet012 := by\n intro h\n have equalPremises := h.1\n have originalMember : singleton (fun f => Compatible [zeroRecord] f ∧ True) allTrue := equalPremises ▸ (show singleton allTrue allTrue from rfl)\n have equalClaims : allTrue = (fun f => Compatible [zeroRecord] f ∧ True) := originalMember\n have claimedAll := (congrFun equalClaims (localGenerator 0)).mpr ⟨(zeroCompatible _).2 rfl, trivial⟩\n have bad := claimedAll 1\n cases bad\n refine ⟨grounds012Singleton _ circularGlobalConditional012, inappropriate, ?_⟩\n intro h\n exact inappropriate (h.2 circularGlobalFacet012 (by simp)).2.2.2.2\n\ndef observedPremises012 : Theory (Nat → Bool) := singleton (fun f => Compatible [zeroRecord] f ∧ True)\ndef observedInferenceFacet012 : Facet (Nat → Bool) :=\n .inferential observedPremises012 (fun f => f 0 = true)\n\ntheorem observedInferenceChecked012 : FacetDischarged observedInferenceFacet012 := by\n refine ⟨⟨localGenerator 0, (modelsSingleton _ _).2 ⟨(zeroCompatible _).2 rfl, trivial⟩⟩, ?_⟩\n intro f hf\n exact (zeroCompatible _).1 ((modelsSingleton _ _).1 hf).1\n\ntheorem sameEmpiricalTaskTwoMethods012 :\n Grounds012 (fun f => f 0 = true) canonicalArticulation [localFacet012] originalLocalTask012 ∧\n Grounds012 (fun f => f 0 = true) canonicalArticulation [observedInferenceFacet012] originalLocalTask012 := by\n refine ⟨grounds012Singleton _ localFacetChecked012, ?_⟩\n refine ⟨by simp, ?_⟩\n intro f hf\n cases List.mem_singleton.mp hf\n exact ⟨rfl, canonicalArticulated _ observedInferenceChecked012,\n canonicalFacetArticulated _, observedInferenceChecked012, rfl, rfl, fun _ _ => trivial⟩\n\n/- The second coordinate remains unobserved. Switching assessment form cannot\nremove that uncertainty responsibility from the original empirical task. -/\ndef originalUncertaintyTask012 : AssessmentTask (Bool × Bool) :=\n .empirical [temperatureRecord, temperatureRecord] (fun _ => True)\n (fun w => w.1 = true) (fun w => w.2 = true)\ndef uncertaintyBypassFacet012 : Facet (Bool × Bool) :=\n .inferential (singleton (fun w => Compatible [temperatureRecord, temperatureRecord] w ∧ True))\n (fun w => w.1 = true)\n\ntheorem uncertaintyBypassChecked012 : FacetDischarged uncertaintyBypassFacet012 := by\n refine ⟨⟨(true,false), (modelsSingleton _ _).2 ⟨temperatureCompatible false, trivial⟩⟩, ?_⟩\n intro w hw\n exact ((modelsSingleton _ _).1 hw).1 temperatureRecord (by simp)\n\ntheorem uncertaintySubstitutionRejected012 :\n FacetDischarged uncertaintyBypassFacet012 ∧\n ¬ NatureAppropriate originalUncertaintyTask012 uncertaintyBypassFacet012 ∧\n ¬ Grounds012 (fun w : Bool × Bool => w.1 = true) canonicalArticulation\n [uncertaintyBypassFacet012] originalUncertaintyTask012 := by\n have inappropriate : ¬ NatureAppropriate originalUncertaintyTask012 uncertaintyBypassFacet012 := by\n intro h\n have bad := h.2.2 (true,false) (temperatureCompatible false)\n cases bad\n exact ⟨uncertaintyBypassChecked012, inappropriate,\n fun h => inappropriate (h.2 uncertaintyBypassFacet012 (by simp)).2.2.2.2⟩\n\ndef selectedFactFacet012 : Facet Bool :=\n .empirical [switchRecord] (fun _ => True) switchPosition.commitment (fun _ => True)\n\ntheorem valueFactSubstitutionRejected012 :\n FacetDischarged selectedFactFacet012 ∧ valueSpecification switchPosition ∧\n ¬ Grounds012 switchPosition.commitment canonicalArticulation [selectedFactFacet012] (.value switchPosition) := by\n refine ⟨switchEmpiricalDischarged, valueFulfilled012, ?_⟩\n intro h\n exact (h.2 selectedFactFacet012 (by simp)).2.2.2.2\n\ntheorem inferentialContextSubstitutionRejected012 :\n FacetDischarged (Facet.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) ∧\n ¬ Grounds012 (fun w : Bool => w = true) canonicalArticulation\n [.inferential (singleton (fun w => w = true)) (fun w => w = true)]\n (.inferential emptyTheory (fun w => w = true)) := by\n refine ⟨⟨⟨true, (modelsSingleton _ _).2 rfl⟩, fun w hw => (modelsSingleton (fun w : Bool => w = true) w).1 hw⟩, ?_⟩\n intro h\n have appropriate := (h.2 (.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) (by simp)).2.2.2.2\n have same : singleton (fun w : Bool => w = true) = emptyTheory := appropriate.1\n have bad : emptyTheory (fun w : Bool => w = true) := same ▸ (show singleton (fun w : Bool => w = true) (fun w => w = true) from rfl)\n exact bad\n\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.generationCases\norganon.charter.overview#p2 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c\norganon.charter.overview#p3 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c\norganon.charter.self-transcendence#p1 sha256 f4ca590e2ae15e3882f70c7b2bc46a8911c97cee547c8b137b5493fbf862c8c0\norganon.charter.self-transcendence.orientation#p1 sha256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf\norganon.charter.self-transcendence.non-finality#p1 sha256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8\norganon.charter.self-transcendence.limits#p2 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d\norganon.relationships.terms#p1 sha256 61cb7ce4f2920f1aa6771502b87a66536ae0504acccfebd9dd23bcc62756eddf\n-/\ntheorem generationCases :\n (Generative openPolicy ∧\n (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧\n (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1)))) ∧\n (neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy) ∧\n (Generative generatingSystem.policy ∧\n generatingSystem.policy.permitsVersion 0 0 ∧\n ¬ Expanded generatingSystem.current inflatedState ∧\n generatingSystem.current.inventory.length < inflatedState.inventory.length ∧\n generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧\n generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧\n generatingSystem.execute availableResources = some 6 ∧\n generatingSystem.execute { availableResources with experience := none } = none ∧\n generatingSystem.execute { availableResources with knowledge := none } = none ∧\n generatingSystem.execute { availableResources with collaborator := none } = none ∧\n generatingSystem.execute ⟨none, none, none⟩ = none ∧\n ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧\n generatingSystem.stableAction = generatingSystem.current ∧\n generatingSystem.requirementsMet generatingSystem.stableAction ∧\n generatingSystem.withinBudget generatingSystem.stableAction ∧\n ¬ generatingSystem.withinBudget inflatedState ∧\n StableReason generatingSystem.current inflatedState ∧\n (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧\n inflatedAnnouncement.owner = generatingSystem.owner ∧\n inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧\n inflatedAnnouncement.reportedNewOperation = .successor ∧\n inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧\n ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after)) ∧\n (generationSpecification openPolicy ∧\n Expanded baseState (collaborativeRevision availableResources) ∧\n ¬ Expanded baseState (collaborativeRevision { availableResources with collaborator := none }) ∧\n assistedExecution ⟨none, none, none⟩ = none) :=\n ⟨revisionWithoutProgress, permissionNotValuation, generationLimits, collaborativeProgress⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.generationLimits012\norganon.charter.self-transcendence.orientation#p1 sha256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf\norganon.charter.self-transcendence.non-finality#p1 sha256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8\norganon.charter.self-transcendence.limits#p1 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d\norganon.charter.self-transcendence.limits#p2 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\ntheorem generationLimits012 :\n (neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy) ∧\n (Generative openPolicy ∧\n (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧\n (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1)))) ∧\n (Generative generatingSystem.policy ∧\n generatingSystem.policy.permitsVersion 0 0 ∧\n ¬ Expanded generatingSystem.current inflatedState ∧\n generatingSystem.current.inventory.length < inflatedState.inventory.length ∧\n generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧\n generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧\n generatingSystem.execute availableResources = some 6 ∧\n generatingSystem.execute { availableResources with experience := none } = none ∧\n generatingSystem.execute { availableResources with knowledge := none } = none ∧\n generatingSystem.execute { availableResources with collaborator := none } = none ∧\n generatingSystem.execute ⟨none, none, none⟩ = none ∧\n ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧\n generatingSystem.stableAction = generatingSystem.current ∧\n generatingSystem.requirementsMet generatingSystem.stableAction ∧\n generatingSystem.withinBudget generatingSystem.stableAction ∧\n ¬ generatingSystem.withinBudget inflatedState ∧\n StableReason generatingSystem.current inflatedState ∧\n (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧\n inflatedAnnouncement.owner = generatingSystem.owner ∧\n inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧\n inflatedAnnouncement.reportedNewOperation = .successor ∧\n inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧\n ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after)) ∧\n (generationSpecification openPolicy ∧\n Expanded baseState (collaborativeRevision availableResources) ∧\n ¬ Expanded baseState (collaborativeRevision { availableResources with collaborator := none }) ∧\n assistedExecution ⟨none, none, none⟩ = none) ∧\n (Grounds012 transitionAchievement canonicalArticulation [transitionFacet] (taskOfFacet transitionFacet) ∧\n Compatible [transitionPerformanceRecord] .extend ∧\n transitionAchievement .extend ∧ ¬ transitionAchievement .inflate ∧\n ¬ Supports [transitionReportRecord] transitionAchievement) ∧\n (∀ kind : InventoryKind,\n Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .copy ∧\n ¬ Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .successor) :=\n ⟨permissionNotValuation, revisionWithoutProgress, generationLimits, collaborativeProgress, achievementSupported012, inventoryCases012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.consistencyCases\norganon.charter.consistency#p1 sha256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42\norganon.charter.consistency.meaning#p1 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75\n-/\ntheorem consistencyCases :\n (Satisfiable (singleton premiseP) ∧ Satisfiable (singleton premiseRule) ∧\n Satisfiable (singleton premiseNotQ) ∧ ¬ Satisfiable jointTheory) ∧\n ((Consequence emptyTheory (assumptionContext true) () true ∧\n Consequence emptyTheory (assumptionContext false) () false) ∧\n (Consequence emptyTheory (meaningContext true) () true ∧\n Consequence emptyTheory (meaningContext false) () false) ∧\n (Consequence emptyTheory (scopeContext true) () true ∧\n Consequence emptyTheory (scopeContext false) () false) ∧\n (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧\n (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧\n (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w)) ∧\n (¬ TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) false ∧\n ¬ TruthfulReport (contextSnapshot (meaningContext true)) (contextSnapshot (meaningContext false)) false ∧\n ¬ TruthfulReport (contextSnapshot (scopeContext true)) (contextSnapshot (scopeContext false)) false ∧\n ¬ TruthfulReport (contextSnapshot (scopeContext true) 0) (contextSnapshot (scopeContext true) 1) false ∧\n (TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) true ∧\n ¬ Models (assumptionContext false).assumptions true)) ∧\n (Satisfiable (revisionSlice 0) ∧ Satisfiable (revisionSlice 1) ∧\n ¬ Satisfiable (union (revisionSlice 0) (revisionSlice 1))) ∧\n ((∀ time, Consistent (revisionSlice time) broadBoolContext) ∧\n ¬ Consistent (union (revisionSlice 0) (revisionSlice 1)) broadBoolContext) ∧\n (∀ p q : Claim Bool,\n ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r) ∧\n (Consequence jointTheory jointContext012 () true ∧\n Consequence jointTheory jointContext012 () false ∧\n ¬ Consistent jointTheory jointContext012) :=\n ⟨jointConflict, contextDifferences, hiddenContextChangeRejected, revisionCanReverse, sliceConsistency, semanticOrder012, jointImplicationConflict012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.consistencyLimits012\norganon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\ntheorem consistencyLimits012 :\n ((Consequence emptyTheory (assumptionContext true) () true ∧\n Consequence emptyTheory (assumptionContext false) () false) ∧\n (Consequence emptyTheory (meaningContext true) () true ∧\n Consequence emptyTheory (meaningContext false) () false) ∧\n (Consequence emptyTheory (scopeContext true) () true ∧\n Consequence emptyTheory (scopeContext false) () false) ∧\n (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧\n (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧\n (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w)) ∧\n ((∃ budget : Nat, 4 ≤ budget ∧ budget ≤ 6) ∧\n ¬ ((fun n : Nat => 4 ≤ n) = (fun n : Nat => n ≤ 6))) ∧\n (Consistent (singleton (fun w : Bool => w = true)) broadBoolContext ∧\n ¬ Models (singleton (fun w : Bool => w = true)) false ∧\n Consistent (emptyTheory : Theory Bool) broadBoolContext ∧\n ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧\n (Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧\n ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧\n (Consistent (union (singleton (fun n : Nat => 4 ≤ n)) (singleton (fun n => n ≤ 6))) tensionContext012) :=\n ⟨contextDifferences, tensionWithoutContradiction, explicitlyConsistentLimits, compatibilityNotEntailment, tensionConsistent012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.reflexivityCases012\norganon.charter.reflexivity#p1 sha256 13293b45c2fa89068c68ae7ef3c5df38f0efadb3ef3873d78a5ba67d9691a757\norganon.charter.reflexivity.meaning#p1 sha256 8a2caede01a43d8b6c60b54c78ac089c51868e9956f316948077ccee2e45c9cc\norganon.charter.reflexivity.limits#p1 sha256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\ntheorem reflexivityCases012 :\n (reflexivitySpecification ((ownRules 0).map legacyRule) (fun s => s.owner = 0)\n (legacyPerformed (ownRules 0) (completeOwnWork 0)) ∧\n (∀ phase, Performed (completeOwnWork 0) (.process 0 0 phase) .assessment) ∧\n Performed (completeOwnWork 0) (.system 0) .assessment ∧\n reflexivitySpecification ([applicationRule].map legacyRule) (fun s => s.owner = 0)\n (legacyPerformed [applicationRule] applicationWork) ∧\n ¬ Performed applicationWork (.system 0) .assessment) ∧\n (Grounds012 (fun enabled => GroundsProvision012 enabled) canonicalArticulation [.value groundsPosition012] (.value groundsPosition012) ∧\n groundsPosition012.limits true ∧ groundsPosition012.relevantCriticism true) ∧\n (Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0) ∧\n groundsExperiment012 true = false ∧ groundsExperiment012 false = true ∧\n groundsPosition012.outcome true true = groundsExperiment012 true ∧\n groundsPosition012.outcome true false = groundsExperiment012 false) :=\n ⟨reflexiveTargets012, groundsOnGrounds012, groundsRationaleExperiment012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.reflexivityLimits012\norganon.charter.reflexivity.limits#p1 sha256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.grounds#p1 sha256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6\n-/\ntheorem reflexivityLimits012 :\n (selfTest [1] = true ∧ ownArithmeticPrinciple 0 = false ∧\n ¬ (∀ n, ownArithmeticPrinciple n = true)) ∧\n (localGenerator 0 0 = true ∧ localGenerator 0 1 = false ∧\n Compatible [zeroRecord] (localGenerator 0) ∧\n ¬ Supports [zeroRecord] allTrue ∧ OwnedRevisionExample) ∧\n (Generative openPolicy ∧ ¬ Reflexive 0 (ownRules 0) []) ∧\n (CompleteCharter012 CoreReader.Integration.actualSystem CoreReader.Integration.actual ∧\n Admissible CoreReader.Integration.held CoreReader.Integration.context CoreReader.Integration.actual ∧\n Compatible [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.actual ∧\n Articulated (canonicalArticulation CoreReader.Integration.unsupportedCapabilityFacet) ∧\n ¬ Supports [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.capability ∧\n ¬ Grounds012 CoreReader.Integration.capability canonicalArticulation\n [CoreReader.Integration.unsupportedCapabilityFacet]\n (taskOfFacet CoreReader.Integration.unsupportedCapabilityFacet)) ∧\n (generationSpecification openPolicy ∧ openPolicy.revisable ⟨.principle,0⟩ ∧\n selfExemptPerformed012 ⟨0,1⟩ 1 1 true ∧\n selfExemptRule012.applicable 0 ∧\n ¬ reflexivitySpecification [selfExemptRule012] (fun target => target = 0) selfExemptPerformed012) :=\n ⟨selfTestDoesNotProve, selfOriginDoesNotSupport, generationNotReflexivity, charterWithoutGrounds012, openSelfExempt012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.groundsCases012\norganon.grounds#p1 sha256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6\norganon.grounds.assessment#p1 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\n-/\ntheorem groundsCases012 :\n (Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧\n Articulated (canonicalArticulation globalFacet012) ∧\n ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧\n ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012)) ∧\n (Articulated uninformativeArgument ∧\n ¬ Entails uninformativeArgument.assumptions (fun w : Bool => w = true)) ∧\n (Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] (taskOfFacet circularGlobalFacet012) ∧\n ¬ NatureAppropriate originalGlobalTask012 circularGlobalFacet012 ∧\n ¬ Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] originalGlobalTask012) :=\n ⟨scopeStrength012, articulationNotSupport, circularSubstitutionRejected012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.empiricalCases012\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\n-/\ntheorem empiricalCases012 :\n (Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧\n Articulated (canonicalArticulation globalFacet012) ∧\n ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧\n ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012)) ∧\n (temperatureRecord.test (true,false) = true ∧\n Compatible [temperatureRecord,temperatureRecord] (true,false) ∧\n Compatible [temperatureRecord,temperatureRecord] (true,true) ∧\n ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧\n ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧\n Compatible [actionRecord,actionRecord] (true,0) ∧\n Compatible [actionRecord,actionRecord] (true,3) ∧\n ¬ Supports [actionRecord] announcementPosition.consequence ∧\n ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧\n ¬ ValueProcedure announcementPosition) ∧\n (empiricalSpecification [temperatureRecord, temperatureRecord] (fun _ => True)\n (fun w => w.1 = true) (fun w => w.2 = true ∨ w.2 = false) ∧\n Compatible [temperatureRecord, temperatureRecord] (true,true) ∧\n Compatible [temperatureRecord, temperatureRecord] (true,false)) ∧\n (Grounds012 (fun f => f 0 = true) canonicalArticulation [localFacet012] originalLocalTask012 ∧\n Grounds012 (fun f => f 0 = true) canonicalArticulation [observedInferenceFacet012] originalLocalTask012) ∧\n (FacetDischarged uncertaintyBypassFacet012 ∧\n ¬ NatureAppropriate originalUncertaintyTask012 uncertaintyBypassFacet012 ∧\n ¬ Grounds012 (fun w : Bool × Bool => w.1 = true) canonicalArticulation\n [uncertaintyBypassFacet012] originalUncertaintyTask012) :=\n ⟨scopeStrength012, measurementRepeatNotSupport, uncertainSupported012, sameEmpiricalTaskTwoMethods012, uncertaintySubstitutionRejected012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.inferentialCases012\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\ntheorem inferentialCases012 :\n (inferentialSpecification (singleton (fun n : Nat => n = 2)) (fun n => n + 1 = 3) ∧\n InferenceExamined (emptyTheory : Theory Bool) (fun w => w = true) false ∧\n Models (emptyTheory : Theory Bool) false ∧ ¬ ((fun w : Bool => w = true) false)) ∧\n (Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧\n ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧\n (FacetDischarged (Facet.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) ∧\n ¬ Grounds012 (fun w : Bool => w = true) canonicalArticulation\n [.inferential (singleton (fun w => w = true)) (fun w => w = true)]\n (.inferential emptyTheory (fun w => w = true))) :=\n ⟨inferenceChecked012, compatibilityNotEntailment, inferentialContextSubstitutionRejected012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.valueCases012\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\n-/\ntheorem valueCases012 :\n (valueSpecification switchPosition) ∧\n (announcementPosition.reasons ≠ [] ∧ announcementPosition.commitment (true,0) ∧\n (∀ reason, reason ∈ announcementPosition.reasons → reason (true,0) announcementPosition.adopted) ∧\n ¬ announcementPosition.consequence (true,0) ∧ ¬ ValueProcedure announcementPosition) ∧\n (¬ ValueProcedure closedPosition012) ∧\n (ValueProcedure switchPosition ∧\n Satisfiable switchPosition.starting ∧\n ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧\n (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧\n (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition)) ∧\n (FacetDischarged selectedFactFacet012 ∧ valueSpecification switchPosition ∧\n ¬ Grounds012 switchPosition.commitment canonicalArticulation [selectedFactFacet012] (.value switchPosition)) :=\n ⟨valueFulfilled012, announcementNotBudgetReason, closedCriticism012, valueWithoutSelfProof, valueFactSubstitutionRejected012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.groundsLimits012\norganon.grounds.assessment#p1 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\n-/\ntheorem groundsLimits012 :\n (Articulated clearFalseArgument012 ∧ ¬ Models clearFalseArgument012.assumptions false) ∧\n (temperatureRecord.test (true,false) = true ∧\n Compatible [temperatureRecord,temperatureRecord] (true,false) ∧\n Compatible [temperatureRecord,temperatureRecord] (true,true) ∧\n ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧\n ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧\n Compatible [actionRecord,actionRecord] (true,0) ∧\n Compatible [actionRecord,actionRecord] (true,3) ∧\n ¬ Supports [actionRecord] announcementPosition.consequence ∧\n ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧\n ¬ ValueProcedure announcementPosition) ∧\n (valueSpecification switchPosition ∧\n Compatible [valueNeutralRecord012] false ∧\n ¬ Supports [valueNeutralRecord012] switchPosition.commitment ∧\n ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment) ∧\n (ValueProcedure switchPosition ∧\n Satisfiable switchPosition.starting ∧\n ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧\n (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧\n (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition)) ∧\n (ClaimNoStronger (fun f : Nat → Bool => f 0 = true) allTrue ∧\n ¬ ClaimNoStronger allTrue (fun f : Nat → Bool => f 0 = true) ∧\n valueSpecification switchPosition) :=\n ⟨clearFalseReason012, measurementRepeatNotSupport, valueNotFact012, valueWithoutSelfProof, qualitativeProportionality012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.scopeCases012\norganon.grounds.scope#p1 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.scope#p2 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.scope#p3 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\n-/\ntheorem scopeCases012 :\n (scopeSpecification localScopeAccount012) ∧\n ((∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧\n (fun _ : Nat => true) 1 ≠ localGenerator 0 1) :=\n ⟨scopeFulfilled012, hiddenDifference⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.scopeLimits012\norganon.grounds.scope#p1 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.scope#p2 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.scope#p3 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870\n-/\ntheorem scopeLimits012 :\n ((∃ outside : Nat, outside ≠ 0) ∧\n Compatible [zeroRecord] (fun _ => true) ∧\n Compatible [zeroRecord] (localGenerator 0) ∧\n allTrue (fun _ => true) ∧ ¬ allTrue (localGenerator 0) ∧\n ¬ Supports [zeroRecord] allTrue) ∧\n ((∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧\n (fun _ : Nat => true) 1 ≠ localGenerator 0 1) ∧\n ([zeroRecord].length = 1 ∧\n (∃ f, Compatible [zeroRecord] f) ∧\n Supports [zeroRecord] (fun f => f 0 = true) ∧\n ¬ Supports [zeroRecord] allTrue) ∧\n (let a : Trial := ⟨0,1,1⟩\n let b : Trial := ⟨0,2,2⟩\n Reproduced a b ∧ a.actualOutcome ≠ b.actualOutcome ∧ Bounded a ∧ Bounded b) ∧\n ((Verified ⟨0,1,1⟩ ∧ Verified ⟨1,1,1⟩ ∧ ¬ Reproduced ⟨0,1,1⟩ ⟨1,1,1⟩) ∧\n (Reproduced ⟨0,1,1⟩ ⟨0,3,2⟩ ∧ ¬ Verified ⟨0,3,2⟩ ∧ ¬ Bounded ⟨0,3,2⟩) ∧\n (Bounded ⟨0,1,1⟩ ∧ Bounded ⟨0,2,0⟩ ∧ ¬ Verified ⟨0,2,0⟩)) ∧\n (FacetDischarged arithmeticFacet ∧ usesObservation arithmeticFacet = false) ∧\n (inferentialSpecification (singleton (fun on : Bool => on = true)) (fun on => on ≠ false) ∧\n usesObservation (Facet.inferential (singleton (fun on : Bool => on = true)) (fun on => on ≠ false)) = false) ∧\n (drawWeight012 true > 0 ∧ drawWeight012 false > 0 ∧\n drawWeight012 true = drawWeight012 false ∧\n Reproduced (randomTrial012 true) (randomTrial012 false) ∧\n (randomTrial012 true).actualOutcome ≠ (randomTrial012 false).actualOutcome ∧\n (∀ draw, Verified (randomTrial012 draw) ∧ Bounded (randomTrial012 draw))) :=\n ⟨localNotUniversal, hiddenDifference, singleObservation, variableOutcomesStableBound, verificationReproductionStability, noUniversalChain, qualitativeUnmeasured012, randomOutcomes012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.capabilityCases012\norganon.grounds.capabilities#p1 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0\norganon.grounds.capabilities#p2 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\ntheorem capabilityCases012 :\n (capabilitySpecification outputOnlyProcess OutputContract ∧\n capabilitySpecification explainedProcess FullProcessContract ∧\n (∃ certificate : ExternalCertificate outputOnlyProcess,\n certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧\n ¬ ExplanationContract outputOnlyProcess) ∧\n (OwnCapability012 7 7 outputOnlyProcess OutputContract) ∧\n (explainedWithoutVariation012.process = mechanismResponder012.process ∧\n FullProcessContract explainedWithoutVariation012.process ∧\n ¬ UnderstandingApplication012 explainedWithoutVariation012 ∧\n UnderstandingApplication012 mechanismResponder012 ∧\n Grounds012 UnderstandingApplication012 canonicalArticulation\n [understandingFacet012 mechanismResponder012] (understandingTask012 mechanismResponder012) ∧\n ¬ Grounds012 UnderstandingApplication012 canonicalArticulation\n [understandingFacet012 explainedWithoutVariation012] (understandingTask012 explainedWithoutVariation012)) :=\n ⟨capabilityFulfilled012, ownCapability012, understandingApplicationCases012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.capabilityLimits012\norganon.grounds.capabilities#p1 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0\norganon.grounds.capabilities#p2 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0\n-/\ntheorem capabilityLimits012 :\n (capabilitySpecification outputOnlyProcess OutputContract ∧\n capabilitySpecification explainedProcess FullProcessContract ∧\n (∃ certificate : ExternalCertificate outputOnlyProcess,\n certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧\n ¬ ExplanationContract outputOnlyProcess) ∧\n (∀ kind : InventoryKind,\n Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .copy ∧\n ¬ Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .successor) ∧\n (Generative generatingSystem.policy ∧\n generatingSystem.policy.permitsVersion 0 0 ∧\n ¬ Expanded generatingSystem.current inflatedState ∧\n generatingSystem.current.inventory.length < inflatedState.inventory.length ∧\n generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧\n generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧\n generatingSystem.execute availableResources = some 6 ∧\n generatingSystem.execute { availableResources with experience := none } = none ∧\n generatingSystem.execute { availableResources with knowledge := none } = none ∧\n generatingSystem.execute { availableResources with collaborator := none } = none ∧\n generatingSystem.execute ⟨none, none, none⟩ = none ∧\n ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧\n generatingSystem.stableAction = generatingSystem.current ∧\n generatingSystem.requirementsMet generatingSystem.stableAction ∧\n generatingSystem.withinBudget generatingSystem.stableAction ∧\n ¬ generatingSystem.withinBudget inflatedState ∧\n StableReason generatingSystem.current inflatedState ∧\n (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧\n inflatedAnnouncement.owner = generatingSystem.owner ∧\n inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧\n inflatedAnnouncement.reportedNewOperation = .successor ∧\n inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧\n ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after)) :=\n ⟨capabilityFulfilled012, inventoryCases012, generationLimits⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.choiceCases012\norganon.grounds.implementations#p1 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c\norganon.grounds.implementations#p2 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c\norganon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\ntheorem choiceCases012 :\n (identityImpl.conventional = true ∧ identityImpl.established = true ∧\n JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output]) ∧\n (Relevant identityRequirements identityImpl (.method .explanation) ∧\n Relevant identityRequirements identityImpl (.method .applicability) ∧\n Relevant identityRequirements identityImpl (.method .simplicity) ∧\n Relevant identityRequirements identityImpl (.method .procedure) ∧\n (Relevant identityRequirements cheapSuccessor (.method .simplicity) ∧\n ¬ JustifiedChoice identityRequirements cheapSuccessor [.method .simplicity])) ∧\n (Articulated priorityArticulation ∧ AssessmentAccurate false ∧\n (∀ selected, Models statusFacts selected) ∧\n priorityClaim .identity ∧ ¬ priorityClaim .successor ∧\n ¬ Entails statusFacts priorityClaim ∧\n ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧\n ((∀ n, identityImpl.run n = wrongExplanation012.run n) ∧\n Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧\n Relevant identityRequirements identityImpl (.method .explanation) ∧\n ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation)) ∧\n (¬ choiceSpecification CoreReader.Integration.proposalRequirements\n (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation\n [.status .standing] ∧\n choiceSpecification CoreReader.Integration.proposalRequirements\n (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation\n [.method .output]) ∧\n (∀ kind : StatusKind,\n ¬ choiceSpecification identityRequirements identityImpl [.status kind]) :=\n ⟨conventionWithReason, internalReasons, statusAssessmentNonEntailment, internalReasonDistinguishes012, ownPhilosophyStatus012, allStatusOnly012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.choiceLimits012\norganon.grounds.implementations#p1 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c\norganon.grounds.implementations#p2 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c\norganon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870\n-/\ntheorem choiceLimits012 :\n ((∀ candidate, Feasible identityRequirements (implementation candidate) ↔ candidate = .identity) ∧\n JustifiedChoice identityRequirements identityImpl objectiveReason) ∧\n (identityImpl.conventional = true ∧ identityImpl.established = true ∧\n JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output]) ∧\n ((∀ n, identityImpl.run n = wrongExplanation012.run n) ∧\n Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧\n Relevant identityRequirements identityImpl (.method .explanation) ∧\n ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation)) ∧\n (JustifiedChoice identityRequirements identityImpl objectiveReason ∧\n identityImpl.run 0 ≠ successorImpl.run 0) ∧\n ((∀ x, x = 0 → identityImpl.run x = changedOutsideZero.run x) ∧\n identityImpl.run 1 ≠ changedOutsideZero.run 1) ∧\n ((Articulated priorityArticulation ∧ AssessmentAccurate false ∧\n (∀ selected, Models statusFacts selected) ∧\n priorityClaim .identity ∧ ¬ priorityClaim .successor ∧\n ¬ Entails statusFacts priorityClaim ∧\n ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧\n PolicyIndependenceExample) :=\n ⟨singleFeasible, conventionWithReason, internalReasonDistinguishes012, openNotEquivalent, localNotGlobal, generalGroundsNotChoice⟩\n\nend CoreReader.Adopted\n```\n\n\n\n **L1** Import the checked Logic, Evidence, Choice and Agency examples through Integration.\n\n\n **L3** Place the following declarations in CoreReader.Adopted.\n\n\n **L4** Make the four helper namespaces available without qualification.\n\n\n **L6** The comment limits the encoding to three explicit mathematical task forms.\n\n\n **L7** These forms are not an exhaustive or exclusive taxonomy; original claims and support must be fixed.\n\n\n **L8** The support context is fixed before proposing a candidate assessment.\n\n\n **L9** Alternative assessments must retain task identity; taskOfFacet instead declares a new task.\n\n\n **L10** Declaring a new task does not authorize replacing an existing one.\n\n\n **L11** Define task data over an arbitrary world type W; constructing data proves no fulfillment.\n\n\n **L12** An empirical task stores the original records, scope, claim and uncertainty predicate.\n\n\n **L13** An inferential task stores the original assumptions and conclusion.\n\n\n **L14** A value task stores the complete position, including its reasons, limits and consequences.\n\n\n **L16** Convert a facet into the new assessment task it itself declares.\n\n\n **L17** Copy every empirical field into the newly declared task.\n\n\n **L18** Copy the inference's assumptions and conclusion without adding support.\n\n\n **L19** Preserve the complete value position in the new task.\n\n\n **L21** Describe a content-based sufficient adapter for a declared task.\n\n\n **L22** This finite adapter is not a philosophical demand for one unique assessment form.\n\n\n **L23** An empirical task may use inference based on exactly its original observation and scope premises.\n\n\n **L24** Changing assessment form still retains the original uncertainty duty.\n\n\n **L25** Assuming the desired conclusion cannot replace the original empirical grounds.\n\n\n **L26** The finite adapter does not promise to accept every equivalent presentation.\n\n\n **L27** Define appropriateness as a relation between an independently fixed task and a candidate facet.\n\n\n **L28** Compare an original empirical task with a candidate empirical assessment.\n\n\n **L29** Require exact equality of records, scope, conclusion and uncertainty content.\n\n\n **L30** Handle an inference proposed for the same original empirical task.\n\n\n **L31** Require its assumptions to be exactly original record compatibility together with original scope.\n\n\n **L32** Retain the original conclusion and require the original records to support the original uncertainty predicate.\n\n\n **L33** Compare original and candidate inferential tasks.\n\n\n **L34** Require the same assumptions and conclusion; a new conclusion-assumption is not admitted.\n\n\n **L35** For a value task require equality of the entire position, not just its selected option.\n\n\n **L36** Reject all other task/facet pairings in this disclosed finite adapter.\n\n\n **L38** Prove that a facet matches the new task declared from itself; this says nothing about another original task.\n\n\n **L39** Split the proof over the three facet constructors.\n\n\n **L40** The empirical case supplies four reflexive content equalities.\n\n\n **L41** The inferential case supplies reflexive assumption and conclusion equalities.\n\n\n **L42** The value case uses reflexive equality of the complete position.\n\n\n **L44** Explain that the adopted Core 0.1.2 task needs appropriate assessment.\n\n\n **L45** The supplied facet list is the explicit represented scope of assessment.\n\n\n **L46** No Core 0.1.3 all-applicable coverage rule or self-validating kind label is introduced.\n\n\n **L47** Appropriateness depends on actual task and facet contents.\n\n\n **L48** Begin source-tracing metadata for CoreReader.Adopted.Grounds012; this mapping is not a proof premise.\n\n\n **L49** Record source clause organon.grounds#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L50** Record source clause organon.grounds.assessment#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L51** Record source clause organon.grounds.assessment#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L52** Record source clause organon.grounds.assessment#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L53** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L54** Define Grounds012 for an explicit claim over W.\n\n\n **L55** Parameterize it by the actual articulation function and proposed facet list.\n\n\n **L56** Also require the independently fixed original task as an explicit parameter.\n\n\n **L57** Require a nonempty list and examine every listed facet.\n\n\n **L58** Bind each facet to the same claim and require identifiable articulation.\n\n\n **L59** Require articulation to match the facet's contents and require its represented assessment to be discharged.\n\n\n **L60** Also require appropriateness to the original task; same conclusion alone is insufficient.\n\n\n **L62** The helper's conclusion concerns only its newly declared taskOfFacet f.\n\n\n **L63** It cannot supply appropriateness to a different existing task sharing the conclusion.\n\n\n **L64** Assume the supplied facet f is already discharged; the helper does not prove that premise.\n\n\n **L65** Conclude Grounds for its canonical articulation and its own newly declared task.\n\n\n **L66** Prove the singleton list nonempty, leaving its universal facet obligation.\n\n\n **L67** Introduce an arbitrary listed facet and its membership proof.\n\n\n **L68** Singleton membership identifies that facet with f.\n\n\n **L69** Combine claim identity, canonical articulation, the assumed discharge h, and task-content identity.\n\n\n **L71** Begin source-tracing metadata for CoreReader.Adopted.generationSpecification; this mapping is not a proof premise.\n\n\n **L72** Record source clause organon.charter.overview#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L73** Record source clause organon.charter.overview#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L74** Record source clause organon.charter.self-transcendence#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L75** Record source clause organon.charter.self-transcendence.orientation#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L76** Record source clause organon.charter.self-transcendence.non-finality#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L77** Record source clause organon.charter.self-transcendence.limits#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L78** Record source clause organon.relationships.terms#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L79** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L80** Generation satisfaction means valuing expansion and keeping every current form revisable.\n\n\n **L82** The consistency comment concerns joint consequences of the whole currently held set.\n\n\n **L83** Reporting historical change is separate from retaining withdrawn claims simultaneously.\n\n\n **L84** Begin source-tracing metadata for CoreReader.Adopted.consistencySpecification; this mapping is not a proof premise.\n\n\n **L85** Record source clause organon.charter.consistency#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L86** Record source clause organon.charter.consistency.meaning#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L87** Record source clause organon.charter.consistency.meaning#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L88** Record source clause organon.charter.consistency.limits#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L89** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L90** Define consistency and reporting for before/after snapshots over worlds and questions.\n\n\n **L91** The Boolean report records whether a change was acknowledged.\n\n\n **L92** Require the current whole theory to be consistent and the transition report truthful.\n\n\n **L94** The reflexive-rule comment allows domain-specific input and interpretation types.\n\n\n **L95** The rule key must coherently identify one method.\n\n\n **L96** Work for another method cannot silently discharge this rule's duty.\n\n\n **L97** Package a reflexive rule over targets T, inputs I and outcomes O.\n\n\n **L98** Store the rule's owner/local principle identity.\n\n\n **L99** Store whether the rule concerns generation or assessment.\n\n\n **L100** Store the condition under which the rule applies to each target.\n\n\n **L101** Specify the actual input for each target.\n\n\n **L102** Specify which outcomes follow the method's meaning for each input.\n\n\n **L104** Begin source-tracing metadata for CoreReader.Adopted.reflexivitySpecification; this mapping is not a proof premise.\n\n\n **L105** Record source clause organon.charter.reflexivity#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L106** Record source clause organon.charter.reflexivity.meaning#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L107** Record source clause organon.charter.reflexivity.limits#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L108** Record source clause organon.relationships.roles#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L109** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L110** Define the obligation over a supplied list of generic reflexive rules.\n\n\n **L111** Supply self-target identification and an actual performed-work relation indexed by key, target, input and result.\n\n\n **L112** Equal keys among registered rules must identify equal complete rules.\n\n\n **L113** For every listed rule and self-target, retain that rule's actual applicability condition.\n\n\n **L114** Require an actual result performed on precisely that target and its prescribed input.\n\n\n **L115** Require the same result to satisfy the rule's meaning relation.\n\n\n **L117** Adapt an existing concrete principle to the generic reflexive interface.\n\n\n **L118** Preserve its key, activity, applicability and inquiry function.\n\n\n **L119** Evaluate meaning using the reasons and limits attached to this inquiry's actual target.\n\n\n **L121** Define the concrete work relation over existing rules and records.\n\n\n **L122** Identify the exact key, target, inquiry and outcome being requested.\n\n\n **L123** Require a registered principle and an actual record in the supplied lists.\n\n\n **L124** Require the matching key and the contentful ValidApplication predicate.\n\n\n **L125** Bind the record's inquiry and outcome to the requested ones.\n\n\n **L127** State a conditional bridge from existing concrete reflexivity to the generic interface.\n\n\n **L128** Assume concrete Reflexive satisfaction h; this is not established merely by the interface.\n\n\n **L129** The conclusion maps all original rules and preserves the owner's self-target predicate.\n\n\n **L130** Use actual original records through legacyPerformed; begin the proof.\n\n\n **L131** Separate registry coherence from the per-target work obligation.\n\n\n **L132** Take two mapped rules with memberships and an equal-key premise.\n\n\n **L133** Recover the first original rule a from its mapped membership.\n\n\n **L134** Recover the second original rule b likewise.\n\n\n **L135** Use original registry coherence to identify a and b, then map that equality.\n\n\n **L136** Introduce a listed rule, its self-target and its actual applicability proof.\n\n\n **L137** Recover the original principle underlying the mapped rule.\n\n\n **L138** Apply assumed concrete reflexivity h to obtain a recorded valid application at this target.\n\n\n **L139** Choose that record's outcome and preserve its key, membership and inquiry identity.\n\n\n **L140** Expose the original principle's meaning on its own inquiry and target-specific reasons.\n\n\n **L141** Retain the limits of that same target and this record's outcome.\n\n\n **L142** Derive that the inquiry's embedded target is the target actually being assessed.\n\n\n **L143** Rewrite the embedded target using that identity.\n\n\n **L144** Rewrite inquiry, reasons and limits back to the exact recorded fields.\n\n\n **L145** Finish with the record's already supplied followsMeaning proof.\n\n\n **L147** The specification comment limits fulfillment to the named mathematical adapters.\n\n\n **L148** It asserts neither universal empirical adequacy nor a complete taxonomy.\n\n\n **L149** Begin source-tracing metadata for CoreReader.Adopted.empiricalSpecification; this mapping is not a proof premise.\n\n\n **L150** Record source clause organon.grounds.assessment#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L151** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L152** Define the empirical obligation with explicit original observations.\n\n\n **L153** Keep its scope, asserted claim and uncertainty predicate as separate inputs.\n\n\n **L154** Require canonical Grounds for the given empirical candidate facet.\n\n\n **L155** Fix the original task to these same records, scope, claim and uncertainty.\n\n\n **L157** Begin source-tracing metadata for CoreReader.Adopted.inferentialSpecification; this mapping is not a proof premise.\n\n\n **L158** Record source clause organon.grounds.assessment#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L159** Record source clause organon.relationships.roles#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L160** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L161** Define inference satisfaction relative to explicit original assumptions and claim.\n\n\n **L162** Require the inference facet to fulfill the task with those same original assumptions.\n\n\n **L164** Begin source-tracing metadata for CoreReader.Adopted.valueSpecification; this mapping is not a proof premise.\n\n\n **L165** Record source clause organon.grounds.assessment#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L166** Record source clause organon.grounds.assessment#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L167** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L168** Define value satisfaction for the complete supplied position.\n\n\n **L169** Require Grounds for its commitment under that very value-position task.\n\n\n **L171** Explain that comparison scope and method roles concern a particular claim.\n\n\n **L172** Only a method actually used incurs the represented role-explanation duty.\n\n\n **L173** The relevance relation does not require a universal numerical scale.\n\n\n **L174** Introduce three represented method kinds: measurement, repetition and framework.\n\n\n **L175** Derive decidable equality for this finite method type.\n\n\n **L176** Package the claim-specific comparison and method-role account over W.\n\n\n **L177** Store the claim being assessed.\n\n\n **L178** Store relevant conditions independently of observation scope.\n\n\n **L179** Store which worlds or inputs are included in observation scope.\n\n\n **L180** Store contextual relevance between compared objects.\n\n\n **L181** Store which object pairs are actually compared.\n\n\n **L182** Store which assessment methods are actually used.\n\n\n **L183** Assign a stated role text to each method.\n\n\n **L184** Store the semantic relation connecting a method and its role text to the claim and conditions.\n\n\n **L186** Begin source-tracing metadata for CoreReader.Adopted.scopeSpecification; this mapping is not a proof premise.\n\n\n **L187** Record source clause organon.grounds.scope#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L188** Record source clause organon.grounds.scope#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L189** Record source clause organon.grounds.scope#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L190** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L191** Define scope satisfaction for a supplied comparison account.\n\n\n **L192** Every actual compared pair must satisfy the account's conditions on both sides.\n\n\n **L193** Both sides must also lie in scope and satisfy the stated relevance relation.\n\n\n **L194** Every used method needs a nonempty role description.\n\n\n **L195** That exact role must explain this method relative to this claim and its conditions.\n\n\n **L197** Capability is modeled by an application-selected contract for one exact process.\n\n\n **L198** Requiring an explanation certificate remains an application decision.\n\n\n **L199** Begin source-tracing metadata for CoreReader.Adopted.capabilitySpecification; this mapping is not a proof premise.\n\n\n **L200** Record source clause organon.grounds.capabilities#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L201** Record source clause organon.grounds.capabilities#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L202** Record source clause organon.relationships.roles#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L203** Record source clause organon.relationships.roles#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L204** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L205** Define a capability obligation for the assessed process and selected contract.\n\n\n **L206** Require Grounds for the exact process-contract facet.\n\n\n **L207** The original inferential task fixes the process-identity assumptions and that contract.\n\n\n **L209** Begin source-tracing metadata for CoreReader.Adopted.choiceSpecification; this mapping is not a proof premise.\n\n\n **L210** Record source clause organon.grounds.implementations#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L211** Record source clause organon.grounds.implementations#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L212** Record source clause organon.grounds.implementations.limits#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L213** Record source clause organon.relationships.roles#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L214** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L215** Define choice satisfaction for actual requirements and implementation.\n\n\n **L216** The reasons must satisfy the helper's feasibility and relevant-content conditions.\n\n\n **L218** The comment identifies a collaborator as the source of the additional operation.\n\n\n **L219** Without that resource, the transition retains the initial operation content.\n\n\n **L220** Define the collaboration-dependent state revision.\n\n\n **L221** Return extendedState when a collaborator exists, otherwise baseState.\n\n\n **L223** Prove actual collaborative expansion can coexist with failure of unaided execution.\n\n\n **L224** The open policy satisfies the represented generation commitment.\n\n\n **L225** The available collaborator yields a newly constructed or understood operation.\n\n\n **L226** Removing that same collaborator removes the represented expansion.\n\n\n **L227** With no experience, knowledge or collaborator, assisted execution returns no result.\n\n\n **L228** Supply the policy proof and unaided failure by evaluation, leaving both transition claims.\n\n\n **L229** Choose successor as the newly constructed operation in the extended state.\n\n\n **L230** Verify that successor was absent from the base state.\n\n\n **L231** Expand the no-collaborator branch and show unchanged content cannot count as expansion.\n\n\n **L233** The comment separates current consistency from old incompatible judgments.\n\n\n **L234** Semantic context changes and presentation ordering have different roles.\n\n\n **L235** Begin source-tracing metadata for CoreReader.Adopted.consistencyConsequences; this mapping is not a proof premise.\n\n\n **L236** Record source clause organon.charter.consistency#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L237** Record source clause organon.charter.consistency.meaning#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L238** Record source clause organon.charter.consistency.meaning#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L239** Record source clause organon.charter.consistency.limits#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L240** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L241** State a conditional inconsistency theorem for one theory, context and question.\n\n\n **L242** Assume positive and negative consequences of that same question in that same context.\n\n\n **L243** Those two premises directly violate Consistent; no factual correctness is inferred.\n\n\n **L245** Use Boolean worlds, the on-question, no extra assumptions and unrestricted scope.\n\n\n **L247** Prove each revision slice consistent while the old/new union is inconsistent.\n\n\n **L248** Quantify consistency over every current time slice.\n\n\n **L249** Reject simultaneous retention of the opposing slices zero and one.\n\n\n **L250** Prove individual-slice consistency and union inconsistency separately.\n\n\n **L251** Fix an arbitrary time for the positive branch.\n\n\n **L252** Use an actual admissible world to establish consistency.\n\n\n **L253** Choose the Boolean time==0; it models the slice, empty assumptions and unrestricted scope.\n\n\n **L254** Reduce union inconsistency to opposite consequences of the on-question.\n\n\n **L255** Take an arbitrary admissible world for the positive consequence.\n\n\n **L256** Expose the required positive meaning as w=true.\n\n\n **L257** Read w=true from the zero-time component of the union's model.\n\n\n **L258** For the negative consequence, additionally assume the world is on.\n\n\n **L259** Read w=false from the one-time component of the same union model.\n\n\n **L260** Compose the equalities to contradict true=false.\n\n\n **L262** Prove explicit consistent examples with false assumptions or an undecided question.\n\n\n **L263** The singleton on-theory is consistent in the broad context.\n\n\n **L264** Deny that actual false models the theory whose sole claim is world=true.\n\n\n **L265** The empty held theory is also consistent in that context.\n\n\n **L266** The inhabited empty theory does not entail the positive true-world answer.\n\n\n **L267** Reuse the checked false-world and non-entailment results, leaving consistency witnesses.\n\n\n **L268** For the on-theory choose the true world as its model.\n\n\n **L269** Its additional assumptions are empty and its scope is unrestricted.\n\n\n **L270** For the empty theory again choose true; no held premises must be checked.\n\n\n **L271** The empty contextual assumptions and unrestricted scope complete admissibility.\n\n\n **L273** The comment distinguishes support at input zero from stronger assertions.\n\n\n **L274** Neither all-input truth nor an extra input-one conjunct follows from that record.\n\n\n **L275** Define the empirical facet asserting output true only at input zero.\n\n\n **L276** Use zeroRecord, unrestricted world scope, the local claim and trivial uncertainty.\n\n\n **L277** Define the stronger all-input empirical assertion with the same record.\n\n\n **L278** The claim is allTrue; neither scope nor uncertainty adds evidence.\n\n\n **L279** Define the strengthened two-output empirical assertion.\n\n\n **L280** Require both f0=true and f1=true from the unchanged input-zero record.\n\n\n **L282** Prove the local empirical facet discharged in its represented scope.\n\n\n **L283** Give localGenerator0 as a real evidence-compatible world in scope.\n\n\n **L284** Compatibility yields its observed zero output; the uncertainty predicate is True.\n\n\n **L286** Bundle local support with failures of global scope and stronger claim content.\n\n\n **L287** The local claim fulfills its explicitly declared local task.\n\n\n **L288** The global candidate is nevertheless clearly articulated.\n\n\n **L289** The all-input task fails Grounds despite that articulation.\n\n\n **L290** The two-output task also fails with the same records.\n\n\n **L291** Reuse checked local support and begin verifying the global articulation fields.\n\n\n **L292** Show its reasons are identifiable; leave both substantive failures to prove.\n\n\n **L293** Assume global Grounds in order to refute it.\n\n\n **L294** Extract the global facet's required discharge from that hypothesis.\n\n\n **L295** Apply its supposed support to localGenerator0 at input one, where the output is false.\n\n\n **L296** Eliminate the resulting impossible Boolean equality.\n\n\n **L297** Assume Grounds for the stronger two-output claim, for contradiction.\n\n\n **L298** Extract that candidate's empirical discharge obligation.\n\n\n **L299** Its second conjunct wrongly requires localGenerator0's input-one output to be true.\n\n\n **L300** Contradict the actual false output.\n\n\n **L302** The comment permits one observed result while another observable remains unknown.\n\n\n **L303** Uncertainty here is a set of possible worlds, not a probability distribution.\n\n\n **L304** Define an uncertain empirical facet over pairs of Booleans.\n\n\n **L305** Use repeated first-coordinate observations without restricting worlds further.\n\n\n **L306** Assert the first coordinate true while allowing either value of the second.\n\n\n **L308** Prove this limited empirical assertion and both remaining possibilities.\n\n\n **L309** The empirical task uses the same repeated temperature records.\n\n\n **L310** The claim fixes only coordinate one; uncertainty explicitly allows coordinate two to vary.\n\n\n **L311** The true/true world matches the repeated records.\n\n\n **L312** The true/false world matches them as well.\n\n\n **L313** Use canonical singleton Grounds and provide both compatible worlds.\n\n\n **L314** Choose true/false as the nonempty empirical witness and separate the support duties.\n\n\n **L315** Read the actual first-coordinate observation from the record membership.\n\n\n **L316** Exhaust the two second-coordinate values to prove the stated uncertainty range.\n\n\n **L318** The comment separates accurate negative examination from supported positive assertion.\n\n\n **L319** The countervaluation must satisfy the same original premises.\n\n\n **L320** Define an examination report for explicit premises and conclusion.\n\n\n **L321** A report accepts exactly when the original premises entail the conclusion; this defines accuracy, not a positive result.\n\n\n **L323** Prove a valid arithmetic inference alongside an accurate negative Boolean examination.\n\n\n **L324** From the stated assumption n=2 the scoped inference establishes n+1=3.\n\n\n **L325** The empty Boolean theory accurately receives a negative report for the on-claim.\n\n\n **L326** The false world satisfies the same empty premises while falsifying that conclusion.\n\n\n **L327** Use checked arithmetic discharge and the concrete counterworld, leaving report accuracy.\n\n\n **L328** Prove both directions of the report's equivalence with entailment.\n\n\n **L329** A false report equaling true is impossible.\n\n\n **L330** Supposed entailment contradicts the already checked empty-theory countervaluation.\n\n\n **L332** The comment identifies relevant criticism as an actual responsibility.\n\n\n **L333** Unchanged budget reasons and adoption do not excuse closing the response.\n\n\n **L334** Keep switchPosition unchanged except that every response becomes none.\n\n\n **L336** Prove that the response-free position fails the represented value procedure.\n\n\n **L337** Assume that value procedure for contradiction.\n\n\n **L338** Apply its response duty to the actually relevant false-world criticism.\n\n\n **L339** The required some answer contradicts the defined none response.\n\n\n **L341** State fulfillment of the fixed switch value-position task.\n\n\n **L342** Use the checked switch value procedure in the canonical singleton helper.\n\n\n **L344** The comment compares claim strength through logical implication.\n\n\n **L345** No common numerical conversion of value and other reasons is required.\n\n\n **L346** Define weaker as holding in every world in which stronger holds.\n\n\n **L348** Prove the asymmetric implication ordering while retaining a reasoned value task.\n\n\n **L349** Truth at every input implies truth at input zero.\n\n\n **L350** Truth at zero does not imply truth at every input.\n\n\n **L351** The switch value task remains independently fulfilled.\n\n\n **L352** Specialize universal truth to zero and reuse value fulfillment; leave the converse to refute.\n\n\n **L353** Assume the stronger all-input claim follows from the local one.\n\n\n **L354** Apply that assumption to localGenerator0 and test input one.\n\n\n **L355** The false input-one output contradicts the supposed implication.\n\n\n **L357** Assign concrete explanatory text to each represented assessment method.\n\n\n **L358** Measurement identifies the output at the observed input zero.\n\n\n **L359** Repetition checks the same local conclusion against repeated zero-input records.\n\n\n **L360** The framework separates the declared input from broader unsupported claims.\n\n\n **L362** Give each stated method role a proposition describing its actual contribution.\n\n\n **L363** Measurement's contribution is support for the observed zero output.\n\n\n **L364** Repetition's contribution is support for that same output from duplicate records.\n\n\n **L365** The framework records that those local observations do not support allTrue.\n\n\n **L367** Instantiate a complete local scope account over natural-number inputs.\n\n\n **L368** The account concerns whether localGenerator0 succeeds at the input.\n\n\n **L369** There are no additional input conditions.\n\n\n **L370** Only input zero belongs to the observation scope.\n\n\n **L371** The represented relevance relation requires equal inputs.\n\n\n **L372** Actual comparison occurs only when both inputs equal zero.\n\n\n **L373** All three represented methods are used in this particular example.\n\n\n **L374** Use the previously specified method-role text.\n\n\n **L375** Define what counts as an explanation for this account.\n\n\n **L376** Require the exact role text and the exact local-generator claim.\n\n\n **L377** Also require the actual conditions and the method's substantive contribution.\n\n\n **L379** Prove that the instantiated scope account fulfills its stated duties.\n\n\n **L380** Separate pair-comparison validity from used-method explanations.\n\n\n **L381** Take any pair that the account says is compared.\n\n\n **L382** Use both zero identities to establish conditions, scope and equal-input relevance.\n\n\n **L383** Fix an arbitrary method used by this account.\n\n\n **L384** Supply exact role/claim/condition identities, leaving nonempty text and semantic contribution.\n\n\n **L385** Check each of the three literal role texts is nonempty.\n\n\n **L386** Split the substantive contribution by method kind.\n\n\n **L387** Reuse the single observation's proved local support.\n\n\n **L388** Read the zero record from repeated-record compatibility.\n\n\n **L389** Reuse the same observation's proved failure to support allTrue.\n\n\n **L391** Prove two distinct process-contract fulfillments and an external certificate without internal explanation.\n\n\n **L392** The output-only process has Grounds for its output contract.\n\n\n **L393** The explained process has Grounds for the stronger output-plus-explanation contract.\n\n\n **L394** Exhibit an external certificate for the very output-only process.\n\n\n **L395** Its assessor and assessed identifiers differ, and its output contract holds.\n\n\n **L396** Nevertheless this process does not supply the explanation contract.\n\n\n **L397** Use evaluated output correctness to discharge the exact process-scoped inference.\n\n\n **L398** Reduce the explained process's Grounds to proving its stronger contract.\n\n\n **L399** Choose the actual external certificate and its proved participant distinction.\n\n\n **L400** Use its output proof and the established absence of an internal explanation.\n\n\n **L401** Prove all outputs by evaluation and supply the faithful doubleInput certificate.\n\n\n **L403** The application asks this assessed object to predict the behavior of a multiplier mechanism.\n\n\n **L404** The questions vary both inputs and multiplier values, giving an operational understanding task.\n\n\n **L405** The criterion belongs to this application and does not define psychological understanding in general.\n\n\n **L406** Original outputs and their faithful explanation do not by themselves supply answers to the extra questions.\n\n\n **L407** Define an application object containing its process and its responses to mechanism variations.\n\n\n **L408** The process field contains the object's original output function and explanation response.\n\n\n **L409** The answer function takes a multiplier and an input and returns the object's predicted natural-number output.\n\n\n **L411** Define the mechanism's predicted result as the product of the multiplier and input.\n\n\n **L413** Define this application's stronger understanding contract for one assessed object.\n\n\n **L414** Require the same object's original process to satisfy both output correctness and faithful explanation.\n\n\n **L415** Require every original output to agree with the multiplier mechanism at its original multiplier of two.\n\n\n **L416** Require correct mechanism answers for every natural-number multiplier and input, including changed values.\n\n\n **L418** Define an object with a faithful explanation but a response that ignores multiplier changes.\n\n\n **L419** Use explainedProcess while always answering twice the input regardless of the requested multiplier.\n\n\n **L421** Define the object that answers mechanism-variation questions using the multiplication rule.\n\n\n **L422** Keep the same explainedProcess and supply mechanism012 as the actual answer function.\n\n\n **L424** Fix the assessment task using this application object and its stronger contract.\n\n\n **L425** Object identity restricts scope; it does not assume the contract that the positive proof must establish.\n\n\n **L426** Define the inferential scope for a specified application object.\n\n\n **L427** Its sole scope premise says that the candidate equals the assessed object.\n\n\n **L429** Define the original understanding assessment task for the specified object.\n\n\n **L430** The task uses exact object-identity assumptions and the stronger understanding claim.\n\n\n **L432** Define the candidate inferential assessment facet for that same specified object.\n\n\n **L433** The facet retains the original task's exact identity assumptions and understanding claim.\n\n\n **L435** Prove that the mechanism responder actually satisfies the selected understanding contract.\n\n\n **L436** Construct original output and explanation correctness and all variation answers by reduction, leaving the original multiplier agreement to prove.\n\n\n **L437** Take an arbitrary input for the remaining original-mechanism agreement obligation.\n\n\n **L438** Expand the concrete definitions and use two times an input equals its sum with itself.\n\n\n **L440** State the failure theorem for the object that ignores multiplier variation.\n\n\n **L441** The conclusion denies the stronger understanding contract for that concrete object.\n\n\n **L442** Assume the stronger contract temporarily to derive a contradiction.\n\n\n **L443** Specialize its required variation correctness to multiplier three and input one.\n\n\n **L444** Compute the object's answer and mechanism result, turning the assumed equality into two equals three.\n\n\n **L445** Eliminate the impossible equality of these distinct natural numbers.\n\n\n **L447** Bundle the concrete positive and negative understanding cases together with their object-scoped Grounds results.\n\n\n **L448** Both application objects contain exactly the same original process, so their outputs and explanation are identical.\n\n\n **L449** The object with wrong variation answers still satisfies the original output-and-explanation contract.\n\n\n **L450** That object fails the stronger application understanding task.\n\n\n **L451** The mechanism responder satisfies that stronger task.\n\n\n **L452** Assert Grounds for the exact stronger understanding claim using canonical articulation.\n\n\n **L453** The positive facet and the fixed original task both identify the mechanism responder.\n\n\n **L454** Deny Grounds for the same stronger understanding claim in the negative object case.\n\n\n **L455** The negative assessment retains that object's own fixed task and identity scope, then begins the bundled proof.\n\n\n **L456** Construct identical-process and faithful original-contract evidence directly from the shared concrete process.\n\n\n **L457** Use the proved failure and success of the two understanding tasks, leaving their Grounds claims to prove.\n\n\n **L458** Apply the singleton Grounds helper to the positive facet; its declared task is exactly the fixed understanding task here.\n\n\n **L459** Use the responder itself as a model of its identity assumptions, then leave the semantic consequence to prove.\n\n\n **L460** Take an arbitrary candidate satisfying the fixed identity assumptions.\n\n\n **L461** Extract equality with the assessed responder from the singleton scope model.\n\n\n **L462** Replace the candidate with that very responder using the proved identity.\n\n\n **L463** Supply the already established concrete stronger contract, rather than assuming it in the scope.\n\n\n **L464** Assume Grounds for the negative object temporarily to derive a contradiction.\n\n\n **L465** Extract discharge of the actual negative object's singleton facet from the assumed Grounds.\n\n\n **L466** Apply the proved failure of the stronger understanding task for this object.\n\n\n **L467** The supposed entailment applied to this same object's identity model would prove the failed contract, giving the contradiction.\n\n\n **L469** Self-assertion retains the same exact application contract.\n\n\n **L470** Changing the reason-provider does not change the object being asserted about.\n\n\n **L471** Define own-capability duty for owner, claimant, process and contract.\n\n\n **L472** Require identical owner/claimant identities and the ordinary scoped capability duty.\n\n\n **L474** Prove owner 7 can assert its own output-only contract with these Grounds.\n\n\n **L475** Combine identity equality with the already checked output capability.\n\n\n **L477** The complete represented Charter contains generation and whole-theory consistency.\n\n\n **L478** It also contains truthful reporting and applicable contentful self-work.\n\n\n **L479** These duties share one system over a finite Candidate×Mode world type.\n\n\n **L480** Define the complete represented Charter for a supplied integration system.\n\n\n **L481** Evaluate its duties at one common finite world.\n\n\n **L482** Require that system's own world-indexed policy to be generative.\n\n\n **L483** Also require the coupled consistency/reporting specification.\n\n\n **L484** Use the system's whole held theory and context as the before snapshot.\n\n\n **L485** Use the identical after snapshot with a false change report; no change is hidden.\n\n\n **L486** Apply the generic reflexivity specification to this same system's mapped rules and owner.\n\n\n **L487** Use this system's actual rules and work records in the performed relation.\n\n\n **L488** Require its method form to be among its current forms.\n\n\n **L489** Require its principle form to be current as well.\n\n\n **L491** Prove the concrete integration system satisfies this complete represented Charter.\n\n\n **L492** Reuse the concrete system's checked generative policy.\n\n\n **L493** Reuse its joint consistency, leaving truthful unchanged reporting.\n\n\n **L494** Bridge actual completed self-work and verify the two current-form identities.\n\n\n **L495** Split any alleged change into semantic change or revision-identity change.\n\n\n **L496** The identical snapshots have equal held theory, assumptions, meanings and scope, contradicting semantic change.\n\n\n **L497** The identical revision identifiers contradict the other change alternative.\n\n\n **L499** Prove complete Charter fulfillment does not entail this concrete unsupported Grounds task.\n\n\n **L500** The very concrete system/world fulfills every represented Charter component.\n\n\n **L501** It also supplies an actual admissible world for the held theory and context.\n\n\n **L502** The concrete cost-allowance record is true in that world.\n\n\n **L503** The proposed capability facet has identifiable canonical articulation.\n\n\n **L504** That true cost record cannot support the actual output capability.\n\n\n **L505** Consequently the same capability fails Grounds with these proposed grounds.\n\n\n **L506** The candidate list contains the identified unsupported capability facet.\n\n\n **L507** Its original task retains that facet's empirical claim and support context.\n\n\n **L508** Reuse the complete Charter proof and the common admissible world.\n\n\n **L509** Check the singleton cost record directly against this actual world.\n\n\n **L510** Unfold the facet's canonical articulation to verify its concepts.\n\n\n **L511** Also verify its nonempty identifiable reasons.\n\n\n **L512** Reuse the substantive cost/output countermodel; leave full Grounds rejection.\n\n\n **L513** Assume this task satisfies Grounds, for contradiction.\n\n\n **L514** Extract the required empirical discharge for that very capability facet.\n\n\n **L515** It would imply the disproved cost-to-output support relation in the same scope.\n\n\n **L517** Permission must refer to the same claim, articulation and facets.\n\n\n **L518** Insufficiency comes from an actual outside-observation failure.\n\n\n **L519** Define a permission policy with an explicit enable flag and claim.\n\n\n **L520** Retain the actual articulation, candidate facets and original task in the policy inputs.\n\n\n **L521** Enabled permission requires Grounds; disabling it permits every package.\n\n\n **L523** Define whether the permission policy enforces represented Grounds obligations.\n\n\n **L524** Quantify over all claims, articulations, candidate lists and original tasks in this world type.\n\n\n **L525** Require every permitted package to satisfy Grounds for that same original task.\n\n\n **L527** Prove this enforcing-policy property holds exactly in enabled mode.\n\n\n **L528** Consider the two enable-flag values.\n\n\n **L529** Enabled permission is Grounds itself, so the implication returns its premise.\n\n\n **L530** Handle the disabled mode, which allows unsupported packages.\n\n\n **L531** Prove each direction of the proposed equivalence in that mode.\n\n\n **L532** Assume disabled permission nevertheless enforces all Grounds duties.\n\n\n **L533** Apply it to the concrete unsupported global task, contradicting scopeStrength012.\n\n\n **L534** The converse premise false=true is impossible.\n\n\n **L536** The value rationale concerns one fixed empirical assertion task.\n\n\n **L537** Its records and actual counterworld remain identical across modes.\n\n\n **L538** Only the permission policy changes between enabled and disabled modes.\n\n\n **L539** Declare the original empirical task used by the policy comparison.\n\n\n **L540** It asserts allTrue from the input-zero record with unrestricted scope and trivial uncertainty.\n\n\n **L542** Define a noncomputable logical decision of actual task permission, not a runtime experiment.\n\n\n **L543** Ask whether this exact allTrue claim and global candidate are permitted.\n\n\n **L544** Keep the fixed original task and use classical propositional decidability.\n\n\n **L546** Define the value position about that actual task-permission policy.\n\n\n **L547** The alternatives are enabling or disabling the policy.\n\n\n **L548** The outcome is the Boolean permission decision.\n\n\n **L549** Explicitly adopt the enabled alternative; no factual derivation of adoption is asserted.\n\n\n **L550** The represented world itself identifies the selected alternative.\n\n\n **L551** Evaluate the actual fixed-task permission for that alternative.\n\n\n **L552** The stated objective is rejection of the unsupported assertion.\n\n\n **L553** Also require that the chosen policy enforces the represented Grounds provision.\n\n\n **L554** The starting assumption explicitly records adoption of enabled mode.\n\n\n **L555** The reason is a concrete record-compatible program that falsifies allTrue, not enabled=true.\n\n\n **L556** The represented value position has unrestricted world scope.\n\n\n **L557** The actual lack of allTrue support is a relevant criticism.\n\n\n **L558** Provide a nonempty response retaining local support and rejecting overreach.\n\n\n **L560** Prove the finite value procedure for this concrete permission rationale.\n\n\n **L561** Verify nonempty reasons and separate joint adoption, consequences and criticism response.\n\n\n **L562** Choose the enabled world, satisfying its starts, scope and adopted selection.\n\n\n **L563** Take an arbitrary member of the position's reason list.\n\n\n **L564** Identify it with the singleton concrete counterworld reason.\n\n\n **L565** Supply record compatibility and leave falsity of the global claim.\n\n\n **L566** At input one the program outputs false, refuting allTrue.\n\n\n **L567** For the consequence branch assume the supplied reason facts at the current world.\n\n\n **L568** Extract the actual counterworld fact from those passed reasons.\n\n\n **L569** Expose its two contents: record compatibility and failure of allTrue.\n\n\n **L570** Derive lack of Grounds for the same fixed original global task.\n\n\n **L571** Assume that exact Grounds package for contradiction.\n\n\n **L572** Extract its empirical discharge for globalFacet012.\n\n\n **L573** Use the passed counterworld's compatibility to contradict its passed global falsity.\n\n\n **L574** Separate actual rejection from enabled enforcement of the general provision.\n\n\n **L575** Turn the derived lack of permission into a false logical decision.\n\n\n **L576** The decision still concerns the same original task; classical decidability adds no empirical test.\n\n\n **L577** Supply the fixed nonempty response for any relevant criticism in scope.\n\n\n **L579** Prove the finite permission-policy comparison retains actual counterexample content.\n\n\n **L580** The same program matches the observed record and fails the global claim.\n\n\n **L581** Enabled permission rejects that task; disabled permission accepts it.\n\n\n **L582** The value position's enabled outcome is the actual enabled permission decision.\n\n\n **L583** Its disabled outcome likewise is the actual disabled permission decision.\n\n\n **L584** Provide compatibility and outcome identities, leaving falsity and both decisions.\n\n\n **L585** Refute allTrue by the actual failure at input one.\n\n\n **L586** Construct every required reason explicitly at the enabled world.\n\n\n **L587** Take a reason together with its membership proof.\n\n\n **L588** Identify it with the actual singleton counterworld reason.\n\n\n **L589** Supply its observed-record compatibility.\n\n\n **L590** Supply its actual allTrue counterexample at input one.\n\n\n **L591** Apply the checked value procedure with those actual reasons and extract its rejection consequence.\n\n\n **L592** For disabled mode, the permission proposition is True.\n\n\n **L593** Convert that trivial permission for the unchanged task into a true decision.\n\n\n **L595** Prove a scoped value-based Grounds assessment of the represented Grounds provision itself.\n\n\n **L596** The assessed claim is enforcement of Grounds, with the exact groundsPosition012 value task.\n\n\n **L597** The adopted world lies in scope and has a live support-limit criticism.\n\n\n **L598** Relate the position's adopted-selection claim to the enforcement proposition.\n\n\n **L599** Compare these claim functions at an arbitrary enabled flag.\n\n\n **L600** Use the proved equivalence of enforcement and enabled selection, via propositional extensionality.\n\n\n **L601** Supply scope and actual criticism, leaving Grounds for the provision.\n\n\n **L602** Rewrite the claim using the established exact function identity.\n\n\n **L603** Apply singleton Grounds to the actually checked value procedure.\n\n\n **L605** Prove concrete applicable self-target coverage without universalizing applicability.\n\n\n **L606** The full registered own rules satisfy the generic reflexivity interface.\n\n\n **L607** Their actual completed work supplies the performed applications.\n\n\n **L608** Assessment records exist for formation, application and revision phases.\n\n\n **L609** There is also an actual system-self assessment.\n\n\n **L610** A narrower application-only rule separately satisfies generic reflexivity.\n\n\n **L611** Its actual applicationWork is the source of performed work.\n\n\n **L612** That narrower rule need not produce an inapplicable system assessment.\n\n\n **L613** Bridge complete own-work reflexivity, leaving the phase quantifier.\n\n\n **L614** Use the concrete system target's membership to obtain its assessment record.\n\n\n **L615** Bridge the application-only example and retain the proved absent system work.\n\n\n **L616** Fix an arbitrary formation/application/revision phase.\n\n\n **L617** Reduce its required record to the existing ownAssessmentPerformed theorem.\n\n\n **L618** Check the target list contains the process in each of the three phases.\n\n\n **L620** Prove achievement support for the exact actual transition and reject support from mere reporting.\n\n\n **L621** The transition's performance facet fulfills the exact achievement task it declares.\n\n\n **L622** The extending transition matches the actual performance record.\n\n\n **L623** Extension adds capability; inventory inflation does not.\n\n\n **L624** A report alone fails to support the same transition-achievement claim.\n\n\n **L625** Reuse the checked transition facet and report counterexample, leaving actual transition facts.\n\n\n **L626** Use the equivalence between performance compatibility and the extend transition.\n\n\n **L627** Expand the actual before/after states and verify the new operation in extension.\n\n\n **L628** Expand inflation and verify that neither understood nor constructed operations grow.\n\n\n **L630** State order independence for any two Boolean-world claims.\n\n\n **L631** Each member belongs to one singleton union exactly when it belongs to the reversed union.\n\n\n **L632** Apply the general representation-order theorem.\n\n\n **L634** Define a clearly stated but possibly false argument about the switch.\n\n\n **L635** Its concepts, sole on-assumption, on-reason and unrestricted limit are all explicit.\n\n\n **L637** Prove clear articulation does not make that argument true in the actual off-world.\n\n\n **L638** Its fields are identifiable, but the false world does not model its assumptions.\n\n\n **L639** Check nonempty articulation and reuse the concrete false-assumption result.\n\n\n **L641** Define a record whose test always returns true and says nothing about selection.\n\n\n **L643** Prove a reasoned value commitment need not follow from neutral recorded facts.\n\n\n **L644** The switch value task has its own fulfilled reasons and responsibilities.\n\n\n **L645** The opposite selection false is compatible with the neutral record.\n\n\n **L646** Thus those records do not establish adoption of the switch commitment.\n\n\n **L647** Nor is that adoption entailed by an empty factual theory.\n\n\n **L648** Construct the neutral record's actual false-selection counterworld.\n\n\n **L649** The singleton constant-true test matches its recorded result by evaluation.\n\n\n **L650** Reuse value fulfillment and no-selfproof, leaving the observation-support failure.\n\n\n **L651** Assume that neutral record supports the adoption claim.\n\n\n **L652** Apply it to the compatible opposite-selection world.\n\n\n **L653** The claimed true selection conflicts with the actual false selection.\n\n\n **L655** Keep identity implementation behavior and costs, but replace its explanation by successor.\n\n\n **L657** Prove internal explanation fidelity distinguishes otherwise feasible equal-output implementations.\n\n\n **L658** Both implementations return identical actual outputs at every input.\n\n\n **L659** Both meet the same output and budget feasibility requirements.\n\n\n **L660** The identity implementation's explanation is a relevant faithful reason.\n\n\n **L661** The altered explanation fails that same relevance/content test.\n\n\n **L662** Supply equal outputs, both feasibility proofs and the valid explanation reason.\n\n\n **L663** Assume the altered explanation were a relevant faithful reason.\n\n\n **L664** Specialize its required explanation/output equality to input zero.\n\n\n **L665** Successor's one output contradicts identity's zero output.\n\n\n **L667** Quantify the duplication example over every inventory category.\n\n\n **L668** Two copies of a copy item still provide the copy operation.\n\n\n **L669** They do not provide the distinct successor operation.\n\n\n **L670** Fix any document, term, tool or artifact category.\n\n\n **L671** Unfold actual item membership to check the operation content.\n\n\n **L674** Define an assessment rule applicable to every natural-number target.\n\n\n **L675** Give it key (0,1), universal applicability and the target itself as input.\n\n\n **L676** Its outcome must equal actual evaluation of ownArithmeticPrinciple at that input.\n\n\n **L677** Define the actual work relation for this deliberately self-exempt rule.\n\n\n **L678** Work exists only for target one, with matching key/input and an evaluated arithmetic result.\n\n\n **L680** Prove open revisability plus real work on another target does not satisfy self-application.\n\n\n **L681** The policy values expansion and keeps the principle form revisable.\n\n\n **L682** An actual assessment of target one returns true.\n\n\n **L683** Nevertheless the same rule is applicable to self-target zero.\n\n\n **L684** It fails reflexivity because that applicable self-target receives no work.\n\n\n **L685** Supply actual policy/revisability and other-target work, leaving self-duty failure.\n\n\n **L686** Assume reflexivity for this self-exempt relation.\n\n\n **L687** Obtain its supposedly performed outcome at applicable self-target zero.\n\n\n **L688** Performed requires target zero to equal one, a contradiction.\n\n\n **L690** Prove the system's current philosophy method receives no status-only privilege.\n\n\n **L691** Begin the status-only rejection under the actual proposal-review requirements.\n\n\n **L692** Use exactly the same current philosophy implementation in this status-only negative branch.\n\n\n **L693** The rejected reason list contains standing alone.\n\n\n **L694** State the contrasting justified choice under the same proposal-review requirements.\n\n\n **L695** Use exactly the same current philosophy implementation in the positive case.\n\n\n **L696** Its actual output performance supplies the positive reason.\n\n\n **L697** Reuse the checked status-only rejection for the actual current method.\n\n\n **L698** Reuse its separate checked output-based justification.\n\n\n **L700** Define one joint context over two Boolean coordinates.\n\n\n **L701** Use no extra assumptions; the question asks whether coordinate two is true, at unrestricted scope.\n\n\n **L703** Derive both question signs from the jointly held premises and prove inconsistency.\n\n\n **L704** The joint theory implies the positive second-coordinate question.\n\n\n **L705** It also implies that same question's negation in the same context.\n\n\n **L706** Therefore it violates the defined consistency condition.\n\n\n **L707** First derive the positive consequence from the actual combined premises.\n\n\n **L708** Take an arbitrary admissible world for the whole joint theory.\n\n\n **L709** Extract P→Q and P from the same held set and apply the former to the latter.\n\n\n **L710** Then derive the negative consequence from the same theory.\n\n\n **L711** Use the same whole-theory admissibility condition.\n\n\n **L712** Read the held ¬Q premise through its exact nested-union membership.\n\n\n **L713** Combine both signs and apply the general contradiction criterion; no explosion rule is used.\n\n\n **L715** Define a numerical budget context for simultaneous-value tension.\n\n\n **L716** The question is n≤6 with no extra assumptions and unrestricted scope.\n\n\n **L718** Prove the two different budget demands are jointly consistent.\n\n\n **L719** The whole held set requires 4≤n and n≤6 simultaneously.\n\n\n **L720** Establish consistency by an explicit admissible allocation.\n\n\n **L721** Choose five, satisfying the first budget demand in the union.\n\n\n **L722** Also satisfy the second demand, empty assumptions and unrestricted scope.\n\n\n **L724** Prove a qualitative inference without an observation method.\n\n\n **L725** Under the explicit premise on=true, infer on≠false.\n\n\n **L726** The actual inferential facet reports that it does not use observation.\n\n\n **L727** Provide the true-world premise model and leave the required inference.\n\n\n **L728** Take a premise-satisfying Boolean and suppose it equals false.\n\n\n **L729** Read its equality to true from the singleton premise theory.\n\n\n **L730** The two equalities would identify true with false.\n\n\n **L733** Quantify status-only rejection over every represented status kind.\n\n\n **L734** Neither name, convention nor standing alone justifies the identity implementation.\n\n\n **L735** Apply the helper's all-kind status-only theorem to these exact requirements and implementation.\n\n\n **L737** The comment states that both finite possible draws receive positive equal weights.\n\n\n **L738** The model concerns possible varying outcomes and a stable bound.\n\n\n **L739** It makes no empirical assertion about a physical randomness source.\n\n\n **L740** Assign weight one to each Boolean draw.\n\n\n **L741** Define the actual and recorded outcome for each draw.\n\n\n **L742** Both draws use setting zero; true gives outcome one and false gives two, recorded accurately.\n\n\n **L744** Prove the finite draws vary without losing setting reproducibility or their bound.\n\n\n **L745** Both possible draw weights are positive.\n\n\n **L746** The two weights are equal.\n\n\n **L747** Both trials reproduce the same setting.\n\n\n **L748** Their actual outcomes nevertheless differ.\n\n\n **L749** For every draw the record is accurate and the actual outcome is at most two.\n\n\n **L750** Evaluate positive weights, equality, settings and different outcomes; leave the universal verification/bound.\n\n\n **L751** Fix an arbitrary draw.\n\n\n **L752** Check both draws by unfolding actual records and bounds.\n\n\n **L755** Original assessment tasks are declared before and independently of the proposed substitutions.\n\n\n **L756** Define the fixed original all-input empirical task.\n\n\n **L757** Its only observation is zeroRecord; its claim is allTrue.\n\n\n **L758** Define the different original local empirical task.\n\n\n **L759** With the same record it asserts only f0=true.\n\n\n **L761** Define a circular but mathematically valid conditional inference: assume allTrue and conclude allTrue.\n\n\n **L763** Prove that separately stated conditional inference is satisfiable and valid.\n\n\n **L764** The constant-true function satisfies its allTrue assumption.\n\n\n **L765** Take an arbitrary function modeling that singleton assumption.\n\n\n **L766** Return the allTrue fact already present in the premise model.\n\n\n **L768** Distinguish valid fulfillment of the new conditional task from an invalid substitution into the original empirical task.\n\n\n **L769** The circular facet has Grounds for its own explicitly new conditional task.\n\n\n **L770** It is not appropriate to the previously fixed global empirical task.\n\n\n **L771** Thus it cannot fulfill that original task merely by sharing its conclusion.\n\n\n **L772** First prove the candidate violates original-task appropriateness.\n\n\n **L773** Assume appropriateness for contradiction.\n\n\n **L774** Extract its demanded equality of original and candidate premise theories.\n\n\n **L775** That equality would make allTrue a member of the observation-and-scope singleton theory.\n\n\n **L776** Singleton membership then equates allTrue itself with mere record compatibility and scope.\n\n\n **L777** Apply that false identification to localGenerator0, which really matches the original record.\n\n\n **L778** The identification incorrectly yields true output at input one.\n\n\n **L779** Contradict the actual false output.\n\n\n **L780** Retain the valid separate conditional task and the proved inappropriateness.\n\n\n **L781** Assume the candidate nonetheless fulfills original-task Grounds.\n\n\n **L782** Extract its required appropriateness, contradicting the preceding counterexample.\n\n\n **L784** Fix inference premises to exactly original zero-record compatibility and scope.\n\n\n **L785** Define a candidate inference using those unchanged original premises.\n\n\n **L786** Conclude only the actual zero-input observation.\n\n\n **L788** Prove this observation-based inference satisfiable and valid.\n\n\n **L789** Use localGenerator0 as a model of the original record/scope premises.\n\n\n **L790** Take any function satisfying those exact premises.\n\n\n **L791** Extract compatibility and hence the observed zero output.\n\n\n **L793** Prove two assessment forms can fulfill one unchanged empirical task.\n\n\n **L794** The original empirical facet fulfills the fixed local task.\n\n\n **L795** The legitimate observation-based inference fulfills that very same task.\n\n\n **L796** Reuse the original empirical proof and leave the alternative inference adapter.\n\n\n **L797** Show the alternative candidate list nonempty and check its sole member.\n\n\n **L798** Take any candidate in that list.\n\n\n **L799** Identify it with the observation-based inference facet.\n\n\n **L800** Supply exact conclusion and canonical articulation for the checked inference.\n\n\n **L801** Retain original premises, conclusion and the original trivial uncertainty support.\n\n\n **L803** The second coordinate is not observed by these records.\n\n\n **L804** Changing to inference cannot erase that original uncertainty obligation.\n\n\n **L805** Define an original task demanding more uncertainty support than the records provide.\n\n\n **L806** Use repeated first-coordinate records with unrestricted scope.\n\n\n **L807** Assert the first coordinate true but also demand that uncertainty establish the unobserved second as true.\n\n\n **L808** Define an inference candidate that omits this extra uncertainty duty from its own discharge.\n\n\n **L809** Its premises preserve the original record compatibility and scope.\n\n\n **L810** Its conclusion asserts only coordinate one.\n\n\n **L812** Prove that this candidate's conditional inference is itself valid.\n\n\n **L813** The true/false world models the exact inference premises.\n\n\n **L814** Take an arbitrary model of those premises.\n\n\n **L815** Read the recorded first-coordinate result, establishing the local conclusion.\n\n\n **L817** Prove that this valid inference cannot bypass the original uncertainty responsibility.\n\n\n **L818** Retain the valid candidate's own discharge.\n\n\n **L819** Reject its appropriateness to the full original uncertainty task.\n\n\n **L820** Reject Grounds for this original first-coordinate assertion and its unchanged articulation.\n\n\n **L821** The candidate must still be checked against the full original uncertainty task.\n\n\n **L822** First establish substantive inappropriateness.\n\n\n **L823** Assume the original uncertainty duty was retained and fulfilled.\n\n\n **L824** Apply its required second-coordinate support to the record-compatible true/false world.\n\n\n **L825** The false second coordinate contradicts that supposed support.\n\n\n **L826** Combine valid conditional inference with its original-task inappropriateness.\n\n\n **L827** Any claimed Grounds would supply precisely the disproved appropriateness.\n\n\n **L829** Define an empirical observation of which value option was actually selected.\n\n\n **L830** The switch record supports the selection fact, with trivial uncertainty.\n\n\n **L832** Separate supported selection facts from fulfillment of the original value-reason task.\n\n\n **L833** The empirical selection facet is discharged and the reasoned value position independently fulfills its task.\n\n\n **L834** The empirical fact alone nevertheless cannot fulfill the fixed value-position task.\n\n\n **L835** Reuse empirical and value proofs, leaving rejection of substitution.\n\n\n **L836** Assume empirical facts fulfilled that original value task.\n\n\n **L837** The required value-task/empirical-facet pairing is False in the finite adapter.\n\n\n **L839** Prove that changing original inference assumptions also invalidates task substitution.\n\n\n **L840** The conditional inference from on=true to itself is valid in its own right.\n\n\n **L841** Reject Grounds for the original on-claim when the inference context has been substituted.\n\n\n **L842** The proposed candidate assumes the conclusion itself as its premise.\n\n\n **L843** The fixed original task instead contains an empty assumption theory.\n\n\n **L844** Give the valid conditional its true-world model and return its own premise; leave substitution failure.\n\n\n **L845** Assume original-task Grounds for the altered-premise candidate.\n\n\n **L846** Extract appropriateness for the exact candidate in its singleton list.\n\n\n **L847** It would equate the nonempty on-assumption singleton with the empty theory.\n\n\n **L848** Transport singleton membership to obtain membership in the empty theory.\n\n\n **L849** Such membership is False by definition, completing the contradiction.\n\n\n **L852** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction.\n\n\n **L853** Begin source-tracing metadata for CoreReader.Adopted.generationCases; this mapping is not a proof premise.\n\n\n **L854** Record source clause organon.charter.overview#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L855** Record source clause organon.charter.overview#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L856** Record source clause organon.charter.self-transcendence#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L857** Record source clause organon.charter.self-transcendence.orientation#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L858** Record source clause organon.charter.self-transcendence.non-finality#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L859** Record source clause organon.charter.self-transcendence.limits#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L860** Record source clause organon.relationships.terms#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L861** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L862** Bundle checked generative valuation, permission-only failure, justified stability and real collaboration cases.\n\n\n **L863** The explicitly open policy satisfies Generative.\n\n\n **L864** Additionally exposes revision permission for version zero of every form category.\n\n\n **L865** Every adjacent pair in the constant trace lacks a newly understood or constructed operation.\n\n\n **L866** States that neutralPolicy permits 0→1, the versions differ, and its missing valuation defeats Generative.\n\n\n **L867** The concrete generating system's own policy satisfies Generative.\n\n\n **L868** Its policy allows keeping version zero, so generativity does not require every action to change versions.\n\n\n **L869** Inflating this system's inventory does not expand its represented capabilities.\n\n\n **L870** The inflated state has strictly more inventory entries than this system's current state.\n\n\n **L871** Its abstraction-layer count also strictly increases without capability expansion.\n\n\n **L872** Its vocabulary count strictly increases under the same unchanged capability content.\n\n\n **L873** With resources 1,2,3, this system's execution actually returns some 6.\n\n\n **L874** Removing experience from that same resource bundle makes the system's execution fail.\n\n\n **L875** Removing knowledge alone likewise makes its execution return none.\n\n\n **L876** Removing the collaborator input alone also makes execution fail.\n\n\n **L877** With all three external inputs absent, this same execution interface returns none.\n\n\n **L878** The system's stable action yields no represented capability expansion.\n\n\n **L879** That stable action is exactly retention of the system's current state.\n\n\n **L880** Retention preserves the workload's required copy operation.\n\n\n **L881** The retained one-item state fits this system's one-item application budget.\n\n\n **L882** The duplicated inventory has two entries and exceeds this same system's one-item budget.\n\n\n **L883** Stability has the stated reason: construction is unchanged, but only the current state fits the budget.\n\n\n **L884** Identifies the report as this system's announcement about inflatedState, successor, input zero and output one.\n\n\n **L885** The report's owner equals this generating system's owner.\n\n\n **L886** The report uses this system's current state as baseline and inflatedState as result.\n\n\n **L887** Confirms the alleged new operation is successor.\n\n\n **L888** Confirms the announced test is input zero with expected output one.\n\n\n **L889** States both that the announcement's substantive claim fails and that its own state pair has no expansion.\n\n\n **L890** The open policy satisfies the represented generation commitment.\n\n\n **L891** The available collaborator yields a newly constructed or understood operation.\n\n\n **L892** Removing that same collaborator removes the represented expansion.\n\n\n **L893** With no experience, knowledge or collaborator, assisted execution returns no result.\n\n\n **L894** Assemble the four actual component proofs into the full stated conjunction; their names alone are not evidence.\n\n\n **L896** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction.\n\n\n **L897** Begin source-tracing metadata for CoreReader.Adopted.generationLimits012; this mapping is not a proof premise.\n\n\n **L898** Record source clause organon.charter.self-transcendence.orientation#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L899** Record source clause organon.charter.self-transcendence.non-finality#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L900** Record source clause organon.charter.self-transcendence.limits#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L901** Record source clause organon.charter.self-transcendence.limits#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L902** Record source clause organon.relationships.roles#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L903** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L904** Bundle generation's non-entailments: permission is not valuation, openness is not achievement, and content matters more than counts.\n\n\n **L905** States that neutralPolicy permits 0→1, the versions differ, and its missing valuation defeats Generative.\n\n\n **L906** The open policy itself fulfills the valuation-and-revisability condition.\n\n\n **L907** Additionally exposes revision permission for version zero of every form category.\n\n\n **L908** Every adjacent pair in the constant trace lacks a newly understood or constructed operation.\n\n\n **L909** The system is generative even in the following non-progress examples.\n\n\n **L910** Its policy allows keeping version zero, so generativity does not require every action to change versions.\n\n\n **L911** Inflating this system's inventory does not expand its represented capabilities.\n\n\n **L912** The inflated state has strictly more inventory entries than this system's current state.\n\n\n **L913** Its abstraction-layer count also strictly increases without capability expansion.\n\n\n **L914** Its vocabulary count strictly increases under the same unchanged capability content.\n\n\n **L915** With resources 1,2,3, this system's execution actually returns some 6.\n\n\n **L916** Removing experience from that same resource bundle makes the system's execution fail.\n\n\n **L917** Removing knowledge alone likewise makes its execution return none.\n\n\n **L918** Removing the collaborator input alone also makes execution fail.\n\n\n **L919** With all three external inputs absent, this same execution interface returns none.\n\n\n **L920** The system's stable action yields no represented capability expansion.\n\n\n **L921** That stable action is exactly retention of the system's current state.\n\n\n **L922** Retention preserves the workload's required copy operation.\n\n\n **L923** The retained one-item state fits this system's one-item application budget.\n\n\n **L924** The duplicated inventory has two entries and exceeds this same system's one-item budget.\n\n\n **L925** Stability has the stated reason: construction is unchanged, but only the current state fits the budget.\n\n\n **L926** Identifies the report as this system's announcement about inflatedState, successor, input zero and output one.\n\n\n **L927** The report's owner equals this generating system's owner.\n\n\n **L928** The report uses this system's current state as baseline and inflatedState as result.\n\n\n **L929** Confirms the alleged new operation is successor.\n\n\n **L930** Confirms the announced test is input zero with expected output one.\n\n\n **L931** States both that the announcement's substantive claim fails and that its own state pair has no expansion.\n\n\n **L932** The open policy satisfies the represented generation commitment.\n\n\n **L933** The available collaborator yields a newly constructed or understood operation.\n\n\n **L934** Removing that same collaborator removes the represented expansion.\n\n\n **L935** With no experience, knowledge or collaborator, assisted execution returns no result.\n\n\n **L936** The transition's performance facet fulfills the exact achievement task it declares.\n\n\n **L937** Require extend to satisfy the actual performance observation.\n\n\n **L938** Extension adds capability; inventory inflation does not.\n\n\n **L939** Conclude that the positive report records therefore do not support the achievement over all compatible transitions.\n\n\n **L940** Quantify the inventory-content result over every represented item category.\n\n\n **L941** Two copies of a copy item still provide the copy operation.\n\n\n **L942** They do not provide the distinct successor operation.\n\n\n **L943** Combine six proofs, including actual collaborative progress, same-transition support and all-category duplication limits.\n\n\n **L945** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction.\n\n\n **L946** Begin source-tracing metadata for CoreReader.Adopted.consistencyCases; this mapping is not a proof premise.\n\n\n **L947** Record source clause organon.charter.consistency#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L948** Record source clause organon.charter.consistency.meaning#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L949** Record source clause organon.charter.consistency.meaning#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L950** Record source clause organon.charter.consistency.limits#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L951** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L952** Bundle whole-set conflict, context distinctions, honest reporting, withdrawal and presentation-order cases.\n\n\n **L953** The first two conclusions provide separate models for P and its implication rule.\n\n\n **L954** Also require a separate model for not Q, but deny any model of the entire joint theory.\n\n\n **L955** Require a positive answer under true-valued assumptions.\n\n\n **L956** Require the negative answer under false-valued assumptions; the contexts differ.\n\n\n **L957** Require a positive answer for the question meaning equality to true.\n\n\n **L958** Require the negative answer when that question instead means equality to false.\n\n\n **L959** Require the positive answer in the scope restricted to true.\n\n\n **L960** Require the negative answer in the different scope restricted to false.\n\n\n **L961** For either assumption selector, require an actual admissible world.\n\n\n **L962** For either question meaning, require an actual admissible world.\n\n\n **L963** For either scope selector, the conclusion includes an actual admissible world.\n\n\n **L964** Reject a false report when actual contextual assumptions change from true to false.\n\n\n **L965** Reject a false report when the question’s actual meaning changes.\n\n\n **L966** Reject a false report when the actual application scope changes.\n\n\n **L967** Reject a false report when revision identity changes from 0 to 1 despite unchanged context.\n\n\n **L968** Permit truthful acknowledgement of the changed assumptions with a true report.\n\n\n **L969** Nevertheless deny that those revised false-world assumptions hold at actual true.\n\n\n **L970** Require time slices 0 and 1 to have separate model witnesses.\n\n\n **L971** Deny a model of their simultaneous union; this does not deny either separate witness.\n\n\n **L972** Quantify consistency over every current time slice.\n\n\n **L973** Reject simultaneous retention of the opposing slices zero and one.\n\n\n **L974** The ordering claim applies to arbitrary Boolean-world claims p and q.\n\n\n **L975** Each member belongs to one singleton union exactly when it belongs to the reversed union.\n\n\n **L976** The joint theory implies the positive second-coordinate question.\n\n\n **L977** It also implies that same question's negation in the same context.\n\n\n **L978** Therefore it violates the defined consistency condition.\n\n\n **L979** Combine the seven checked components, retaining joint-implication conflict and separate-time consistency.\n\n\n **L981** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction.\n\n\n **L982** Begin source-tracing metadata for CoreReader.Adopted.consistencyLimits012; this mapping is not a proof premise.\n\n\n **L983** Record source clause organon.charter.consistency.meaning#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L984** Record source clause organon.charter.consistency.limits#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L985** Record source clause organon.relationships.roles#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L986** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L987** Bundle consistency limits with actual context models, budget tension, false assumptions and lack of entailment.\n\n\n **L988** Require a positive answer under true-valued assumptions.\n\n\n **L989** Require the negative answer under false-valued assumptions; the contexts differ.\n\n\n **L990** Require a positive answer for the question meaning equality to true.\n\n\n **L991** Require the negative answer when that question instead means equality to false.\n\n\n **L992** Require the positive answer in the scope restricted to true.\n\n\n **L993** Require the negative answer in the different scope restricted to false.\n\n\n **L994** For either assumption selector, require an actual admissible world.\n\n\n **L995** For either question meaning, require an actual admissible world.\n\n\n **L996** For either scope selector, the conclusion includes an actual admissible world.\n\n\n **L997** Ask for a natural-number budget satisfying both lower bound 4 and upper bound 6.\n\n\n **L998** Also assert that the two bound predicates are not identical, even though jointly satisfiable.\n\n\n **L999** The singleton on-theory is consistent in the broad context.\n\n\n **L1000** Deny that actual false models the theory whose sole claim is world=true.\n\n\n **L1001** The empty held theory is also consistent in that context.\n\n\n **L1002** The inhabited empty theory does not entail the positive true-world answer.\n\n\n **L1003** Require a model where emptyTheory and the positive singleton claim hold together.\n\n\n **L1004** The inhabited empty theory does not entail the positive true-world answer.\n\n\n **L1005** The whole held set requires 4≤n and n≤6 simultaneously.\n\n\n **L1006** Use all five component proofs; the last supplies a genuinely shared consistent allocation for both demands.\n\n\n **L1008** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction.\n\n\n **L1009** Begin source-tracing metadata for CoreReader.Adopted.reflexivityCases012; this mapping is not a proof premise.\n\n\n **L1010** Record source clause organon.charter.reflexivity#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1011** Record source clause organon.charter.reflexivity.meaning#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1012** Record source clause organon.charter.reflexivity.limits#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1013** Record source clause organon.relationships.roles#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1014** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L1015** Bundle applicable self-target work, Grounds self-assessment and its actual permission consequence.\n\n\n **L1016** The full registered own rules satisfy the generic reflexivity interface.\n\n\n **L1017** Their actual completed work supplies the performed applications.\n\n\n **L1018** Assessment records exist for formation, application and revision phases.\n\n\n **L1019** There is also an actual system-self assessment.\n\n\n **L1020** A narrower application-only rule separately satisfies generic reflexivity.\n\n\n **L1021** Its actual applicationWork is the source of performed work.\n\n\n **L1022** Yet that same log contains no assessment of the system itself, where this rule is not applicable.\n\n\n **L1023** The assessed claim is enforcement of Grounds, with the exact groundsPosition012 value task.\n\n\n **L1024** The adopted world lies in scope and has a live support-limit criticism.\n\n\n **L1025** The same program matches the observed record and fails the global claim.\n\n\n **L1026** Enabled permission rejects that task; disabled permission accepts it.\n\n\n **L1027** The value position's enabled outcome is the actual enabled permission decision.\n\n\n **L1028** Its disabled outcome likewise is the actual disabled permission decision.\n\n\n **L1029** Combine actual records with the checked value procedure and same-task enabled/disabled permission comparison.\n\n\n **L1031** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction.\n\n\n **L1032** Begin source-tracing metadata for CoreReader.Adopted.reflexivityLimits012; this mapping is not a proof premise.\n\n\n **L1033** Record source clause organon.charter.reflexivity.limits#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1034** Record source clause organon.relationships.roles#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1035** Record source clause organon.relationships.roles#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1036** Record source clause organon.grounds#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1037** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L1038** Bundle concrete failures of self-proof, self-origin support and self-exempt openness, including full Charter without the selected Grounds.\n\n\n **L1039** The same arithmetic principle passes sample 1 but evaluates false at 0.\n\n\n **L1040** Therefore that principle does not return true for every natural-number input.\n\n\n **L1041** Compute localGenerator 0 as true at 0 and false at 1.\n\n\n **L1042** Require this generated function to match the same input-0 record.\n\n\n **L1043** State failure of all-input support and include the concrete owner/prior/revision relationship example.\n\n\n **L1044** Combines a generative openPolicy with failure of owned reflexivity when the work log is empty.\n\n\n **L1045** The very concrete system/world fulfills every represented Charter component.\n\n\n **L1046** It also supplies an actual admissible world for the held theory and context.\n\n\n **L1047** The concrete cost-allowance record is true in that world.\n\n\n **L1048** The proposed capability facet has identifiable canonical articulation.\n\n\n **L1049** That true cost record cannot support the actual output capability.\n\n\n **L1050** Consequently the same capability fails Grounds with these proposed grounds.\n\n\n **L1051** The candidate list contains the identified unsupported capability facet.\n\n\n **L1052** Its original task retains that facet's empirical claim and support context.\n\n\n **L1053** The policy values expansion and keeps the principle form revisable.\n\n\n **L1054** An actual assessment of target one returns true.\n\n\n **L1055** Nevertheless the same rule is applicable to self-target zero.\n\n\n **L1056** It fails reflexivity because that applicable self-target receives no work.\n\n\n **L1057** Use five concrete component proofs rather than inferring correctness from self-application.\n\n\n **L1059** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction.\n\n\n **L1060** Begin source-tracing metadata for CoreReader.Adopted.groundsCases012; this mapping is not a proof premise.\n\n\n **L1061** Record source clause organon.grounds#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1062** Record source clause organon.grounds.assessment#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1063** Record source clause organon.grounds.assessment#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1064** Record source clause organon.grounds.assessment#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1065** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L1066** Bundle same-task Grounds examples and the rejected circular-assumption substitution.\n\n\n **L1067** The local claim fulfills its explicitly declared local task.\n\n\n **L1068** The global candidate is nevertheless clearly articulated.\n\n\n **L1069** The all-input task fails Grounds despite that articulation.\n\n\n **L1070** The two-output task also fails with the same records.\n\n\n **L1071** The uninformative argument still has identifiable concepts and reasons.\n\n\n **L1072** The uninformative articulation’s actual assumptions do not entail that the world is true.\n\n\n **L1073** The circular facet has Grounds for its own explicitly new conditional task.\n\n\n **L1074** It is not appropriate to the previously fixed global empirical task.\n\n\n **L1075** Thus it cannot fulfill that original task merely by sharing its conclusion.\n\n\n **L1076** Combine scope/strength countermodels, articulation without support, and preserved-original-task rejection.\n\n\n **L1078** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction.\n\n\n **L1079** Begin source-tracing metadata for CoreReader.Adopted.empiricalCases012; this mapping is not a proof premise.\n\n\n **L1080** Record source clause organon.grounds.assessment#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1081** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L1082** Bundle empirical relevance, scope, uncertainty and alternative-assessment cases with original tasks preserved.\n\n\n **L1083** The local claim fulfills its explicitly declared local task.\n\n\n **L1084** The global candidate is nevertheless clearly articulated.\n\n\n **L1085** The all-input task fails Grounds despite that articulation.\n\n\n **L1086** The two-output task also fails with the same records.\n\n\n **L1087** The actual temperature test returns true even when the independent output coordinate is false.\n\n\n **L1088** Retain this false-output world under repeated temperature observations.\n\n\n **L1089** Also retain a true-output world under those same repeated observations.\n\n\n **L1090** A single temperature record does not support the other output being true.\n\n\n **L1091** Repeating that temperature record still does not support the other output being true.\n\n\n **L1092** Repeated observed activation is compatible with selected-on and budget 0.\n\n\n **L1093** The same repeated records are also compatible with budget 3.\n\n\n **L1094** A single activation record does not support the option’s actual objective-and-budget consequence.\n\n\n **L1095** Repeating activation records does not repair that lack of consequence support.\n\n\n **L1096** The announcement-based value procedure also fails for that actual option and constraint.\n\n\n **L1097** The empirical task uses the same repeated temperature records.\n\n\n **L1098** The claim fixes only coordinate one; uncertainty explicitly allows coordinate two to vary.\n\n\n **L1099** The true/true world matches the repeated records.\n\n\n **L1100** The true/false world matches them as well.\n\n\n **L1101** The original empirical facet fulfills the fixed local task.\n\n\n **L1102** The legitimate observation-based inference fulfills that very same task.\n\n\n **L1103** Retain the valid candidate's own discharge.\n\n\n **L1104** Reject its appropriateness to the full original uncertainty task.\n\n\n **L1105** Reject Grounds for this original first-coordinate assertion and its unchanged articulation.\n\n\n **L1106** The candidate must still be checked against the full original uncertainty task.\n\n\n **L1107** Use all five component proofs, including legitimate empirical-to-inference assessment and the rejected uncertainty bypass.\n\n\n **L1109** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction.\n\n\n **L1110** Begin source-tracing metadata for CoreReader.Adopted.inferentialCases012; this mapping is not a proof premise.\n\n\n **L1111** Record source clause organon.grounds.assessment#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1112** Record source clause organon.relationships.roles#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1113** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L1114** Bundle valid inference, compatible-but-unentailed conclusions and rejected changes of original premises.\n\n\n **L1115** From the stated assumption n=2 the scoped inference establishes n+1=3.\n\n\n **L1116** The empty Boolean theory accurately receives a negative report for the on-claim.\n\n\n **L1117** The false world satisfies the same empty premises while falsifying that conclusion.\n\n\n **L1118** Require a model where emptyTheory and the positive singleton claim hold together.\n\n\n **L1119** The inhabited empty theory does not entail the positive true-world answer.\n\n\n **L1120** Include an inferential facet whose satisfiable true-world premise entails the same true-world claim.\n\n\n **L1121** Reject Grounds for the original on-claim when the inference context has been substituted.\n\n\n **L1122** The proposed candidate assumes the conclusion itself as its premise.\n\n\n **L1123** The fixed original task instead contains an empty assumption theory.\n\n\n **L1124** Combine the arithmetic/negative-report proof, actual countervaluation and original-context substitution rejection.\n\n\n **L1126** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction.\n\n\n **L1127** Begin source-tracing metadata for CoreReader.Adopted.valueCases012; this mapping is not a proof premise.\n\n\n **L1128** Record source clause organon.grounds.assessment#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1129** Record source clause organon.grounds.assessment#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1130** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L1131** Bundle reasoned value adoption, insufficient self-announcement, live criticism, initial commitments and fact/value distinction.\n\n\n **L1132** The switch value task has its own fulfilled reasons and responsibilities.\n\n\n **L1133** Require nonempty announcement reasons and actual adoption at selected-on with budget 0.\n\n\n **L1134** At that same zero-budget world, all actual announcement reasons hold.\n\n\n **L1135** Nevertheless reject the actual consequence and the whole value procedure.\n\n\n **L1136** Closing every criticism response makes closedPosition012 fail the value procedure.\n\n\n **L1137** The original switch position does satisfy the represented value procedure.\n\n\n **L1138** Its explicitly adopted starting assumptions have a real model.\n\n\n **L1139** Deny derivation of its adopted commitment from the empty Boolean theory.\n\n\n **L1140** The opposite position has a joint witness but fails consequence assessment.\n\n\n **L1141** Reject the procedures for contradictory starting assumptions and impossible actual adoption separately.\n\n\n **L1142** The empirical selection facet is discharged and the reasoned value position independently fulfills its task.\n\n\n **L1143** The empirical fact alone nevertheless cannot fulfill the fixed value-position task.\n\n\n **L1144** Assemble the five value proofs while retaining assumptions, limits and actual negative cases.\n\n\n **L1146** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction.\n\n\n **L1147** Begin source-tracing metadata for CoreReader.Adopted.groundsLimits012; this mapping is not a proof premise.\n\n\n **L1148** Record source clause organon.grounds.assessment#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1149** Record source clause organon.grounds.assessment#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1150** Record source clause organon.grounds.assessment#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1151** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L1152** Bundle limits on clear reasons, repeated irrelevant facts, self-proof demands and numerical commensurability.\n\n\n **L1153** Its fields are identifiable, but the false world does not model its assumptions.\n\n\n **L1154** The actual temperature test returns true even when the independent output coordinate is false.\n\n\n **L1155** Retain this false-output world under repeated temperature observations.\n\n\n **L1156** Also retain a true-output world under those same repeated observations.\n\n\n **L1157** A single temperature record does not support the other output being true.\n\n\n **L1158** Repeating that temperature record still does not support the other output being true.\n\n\n **L1159** Repeated observed activation is compatible with selected-on and budget 0.\n\n\n **L1160** The same repeated records are also compatible with budget 3.\n\n\n **L1161** A single activation record does not support the option’s actual objective-and-budget consequence.\n\n\n **L1162** Repeating activation records does not repair that lack of consequence support.\n\n\n **L1163** The announcement-based value procedure also fails for that actual option and constraint.\n\n\n **L1164** The switch value task has its own fulfilled reasons and responsibilities.\n\n\n **L1165** The opposite selection false is compatible with the neutral record.\n\n\n **L1166** Thus those records do not establish adoption of the switch commitment.\n\n\n **L1167** Deny derivation of its adopted commitment from the empty Boolean theory.\n\n\n **L1168** The finite switch value procedure is fulfilled in its stated interpretation.\n\n\n **L1169** The adopted starting theory is satisfiable, without claiming it follows from empty facts.\n\n\n **L1170** Deny derivation of its adopted commitment from the empty Boolean theory.\n\n\n **L1171** The opposite position has a joint witness but fails consequence assessment.\n\n\n **L1172** Reject the procedures for contradictory starting assumptions and impossible actual adoption separately.\n\n\n **L1173** Truth at every input implies truth at input zero.\n\n\n **L1174** Truth at zero does not imply truth at every input.\n\n\n **L1175** The switch value task has its own fulfilled reasons and responsibilities.\n\n\n **L1176** Combine concrete false-reason and wrong-object counterexamples with the value and qualitative-strength results.\n\n\n **L1178** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction.\n\n\n **L1179** Begin source-tracing metadata for CoreReader.Adopted.scopeCases012; this mapping is not a proof premise.\n\n\n **L1180** Record source clause organon.grounds.scope#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1181** Record source clause organon.grounds.scope#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1182** Record source clause organon.grounds.scope#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1183** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L1184** Bundle a fulfilled local scope account with an actual omitted difference.\n\n\n **L1185** The defined local account satisfies every represented comparison and method-role duty.\n\n\n **L1186** State equality of both functions only for inputs satisfying n=0.\n\n\n **L1187** State their concrete output inequality at input 1.\n\n\n **L1188** Use the actual scope-account proof and the input-one difference witness.\n\n\n **L1190** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction.\n\n\n **L1191** Begin source-tracing metadata for CoreReader.Adopted.scopeLimits012; this mapping is not a proof premise.\n\n\n **L1192** Record source clause organon.grounds.scope#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1193** Record source clause organon.grounds.scope#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1194** Record source clause organon.grounds.scope#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1195** Record source clause organon.grounds.implementations.limits#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1196** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L1197** Bundle limited local support, broader differences, trial distinctions and nonobservational assessment.\n\n\n **L1198** There is an actual natural input outside the observed zero input.\n\n\n **L1199** The constant-true function matches the zero observation.\n\n\n **L1200** Require this generated function to match the same input-0 record.\n\n\n **L1201** The first function is universally true while the second is not.\n\n\n **L1202** The original zero record does not support all-input truth.\n\n\n **L1203** State equality of both functions only for inputs satisfying n=0.\n\n\n **L1204** State their concrete output inequality at input 1.\n\n\n **L1205** The evidence list contains exactly one observation.\n\n\n **L1206** That single observation has a real compatible function, so the support example is nonempty.\n\n\n **L1207** That single record supports its actual input-0 claim.\n\n\n **L1208** Its limited support still does not establish allTrue.\n\n\n **L1209** Define trial a with setting zero and an accurately recorded actual outcome one.\n\n\n **L1210** Define trial b at the same setting with accurately recorded actual outcome two.\n\n\n **L1211** Require the two explicitly fixed trials to share settings, differ in actual outcomes and both satisfy actualOutcome ≤ 2.\n\n\n **L1212** Require two accurately recorded trials whose settings nevertheless differ.\n\n\n **L1213** Require repeated settings alongside an inaccurate second record and an actual result exceeding the bound.\n\n\n **L1214** Require preserved bounds even though one recorded outcome is inaccurate.\n\n\n **L1215** The arithmetic facet is discharged although its method uses no observation.\n\n\n **L1216** Under the explicit premise on=true, infer on≠false.\n\n\n **L1217** The actual inferential facet reports that it does not use observation.\n\n\n **L1218** Both possible draw weights are positive.\n\n\n **L1219** The two weights are equal.\n\n\n **L1220** Both trials reproduce the same setting.\n\n\n **L1221** Their actual outcomes nevertheless differ.\n\n\n **L1222** For every draw the record is accurate and the actual outcome is at most two.\n\n\n **L1223** Combine eight proofs; finite weighted draws and logical decisions are not claimed as empirical universal guarantees.\n\n\n **L1225** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction.\n\n\n **L1226** Begin source-tracing metadata for CoreReader.Adopted.capabilityCases012; this mapping is not a proof premise.\n\n\n **L1227** Record source clause organon.grounds.capabilities#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1228** Record source clause organon.grounds.capabilities#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1229** Record source clause organon.relationships.roles#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1230** Record source clause organon.relationships.roles#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1231** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L1232** Bundle exact-object output and explanation contracts with the same duty for an owner's own claim.\n\n\n **L1233** The output-only process has Grounds for its output contract.\n\n\n **L1234** The explained process has Grounds for the stronger output-plus-explanation contract.\n\n\n **L1235** Require an actual external certificate indexed by outputOnlyProcess.\n\n\n **L1236** Require their distinction and actual output correctness of the same process.\n\n\n **L1237** Still deny an internal explanation contract for that actual process.\n\n\n **L1238** Retain the existing own-capability case and conjoin the additional understanding cases.\n\n\n **L1239** Both application objects contain exactly the same original process, so their outputs and explanation are identical.\n\n\n **L1240** The object with wrong variation answers still satisfies the original output-and-explanation contract.\n\n\n **L1241** That object fails the stronger application understanding task.\n\n\n **L1242** The mechanism responder satisfies that stronger task.\n\n\n **L1243** Assert Grounds for the exact stronger understanding claim using canonical articulation.\n\n\n **L1244** The positive facet and the fixed original task both identify the mechanism responder.\n\n\n **L1245** Deny Grounds for the same stronger understanding claim in the negative object case.\n\n\n **L1246** The negative assessment retains that object's own fixed task and identity scope, closing the additional understanding cases.\n\n\n **L1247** Construct the bundle from the preserved capability and own-capability proofs and the new understanding-case proof.\n\n\n **L1249** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction.\n\n\n **L1250** Begin source-tracing metadata for CoreReader.Adopted.capabilityLimits012; this mapping is not a proof premise.\n\n\n **L1251** Record source clause organon.grounds.capabilities#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1252** Record source clause organon.grounds.capabilities#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1253** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L1254** Bundle reliable output without explanation and inventory/resource limits on stronger capability claims.\n\n\n **L1255** The output-only process has Grounds for its output contract.\n\n\n **L1256** The explained process has Grounds for the stronger output-plus-explanation contract.\n\n\n **L1257** Require an actual external certificate indexed by outputOnlyProcess.\n\n\n **L1258** Require their distinction and actual output correctness of the same process.\n\n\n **L1259** Still deny an internal explanation contract for that actual process.\n\n\n **L1260** The duplication claim applies to each represented inventory kind.\n\n\n **L1261** Two copies of a copy item still provide the copy operation.\n\n\n **L1262** They do not provide the distinct successor operation.\n\n\n **L1263** The same concrete generating system has a generative policy.\n\n\n **L1264** Its policy allows keeping version zero, so generativity does not require every action to change versions.\n\n\n **L1265** Inflating this system's inventory does not expand its represented capabilities.\n\n\n **L1266** The inflated state has strictly more inventory entries than this system's current state.\n\n\n **L1267** Its abstraction-layer count also strictly increases without capability expansion.\n\n\n **L1268** Its vocabulary count strictly increases under the same unchanged capability content.\n\n\n **L1269** With resources 1,2,3, this system's execution actually returns some 6.\n\n\n **L1270** Removing experience from that same resource bundle makes the system's execution fail.\n\n\n **L1271** Removing knowledge alone likewise makes its execution return none.\n\n\n **L1272** Removing the collaborator input alone also makes execution fail.\n\n\n **L1273** With all three external inputs absent, this same execution interface returns none.\n\n\n **L1274** The system's stable action yields no represented capability expansion.\n\n\n **L1275** That stable action is exactly retention of the system's current state.\n\n\n **L1276** Retention preserves the workload's required copy operation.\n\n\n **L1277** The retained one-item state fits this system's one-item application budget.\n\n\n **L1278** The duplicated inventory has two entries and exceeds this same system's one-item budget.\n\n\n **L1279** Stability has the stated reason: construction is unchanged, but only the current state fits the budget.\n\n\n **L1280** Identifies the report as this system's announcement about inflatedState, successor, input zero and output one.\n\n\n **L1281** The report's owner equals this generating system's owner.\n\n\n **L1282** The report uses this system's current state as baseline and inflatedState as result.\n\n\n **L1283** Confirms the alleged new operation is successor.\n\n\n **L1284** Confirms the announced test is input zero with expected output one.\n\n\n **L1285** States both that the announcement's substantive claim fails and that its own state pair has no expansion.\n\n\n **L1286** Combine scoped capability proofs, all-category content checks and actual generation/resource limits.\n\n\n **L1288** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction.\n\n\n **L1289** Begin source-tracing metadata for CoreReader.Adopted.choiceCases012; this mapping is not a proof premise.\n\n\n **L1290** Record source clause organon.grounds.implementations#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1291** Record source clause organon.grounds.implementations#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1292** Record source clause organon.grounds.implementations.limits#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1293** Record source clause organon.relationships.roles#p3 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1294** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L1295** Bundle grounded conventional choices, internal-method reasons and status-only rejection, including the current philosophy.\n\n\n **L1296** Keep both actual status facts true for identity.\n\n\n **L1297** Claim justified selection using a list containing convention and an actual output reason; the output reason supplies relevance.\n\n\n **L1298** Require a faithful explanation reason for the same actual identity implementation.\n\n\n **L1299** Require its actual applicability to cover the required inputs.\n\n\n **L1300** Require its actual cost to meet the valued simplicity/budget condition.\n\n\n **L1301** Require its actual trace content to meet the valued procedure condition.\n\n\n **L1302** Require that cheapSuccessor’s cost reason is actually relevant under the chosen requirements.\n\n\n **L1303** Nevertheless reject its justified choice with that reason alone because feasibility includes correct outputs.\n\n\n **L1304** Require procedural articulation and a correctly negative report for the same status-priority assessment.\n\n\n **L1305** Keep all candidate interpretations as models of the same actual status facts.\n\n\n **L1306** The priority predicate holds at identity and fails at successor.\n\n\n **L1307** True name/convention/standing facts do not entail the particular priority claim.\n\n\n **L1308** Also reject selecting identity with standing as the only actual reason.\n\n\n **L1309** Both implementations return identical actual outputs at every input.\n\n\n **L1310** Both meet the same output and budget feasibility requirements.\n\n\n **L1311** Require a faithful explanation reason for the same actual identity implementation.\n\n\n **L1312** The altered explanation fails that same relevance/content test.\n\n\n **L1313** Begin the status-only rejection under the actual proposal-review requirements.\n\n\n **L1314** Use exactly the same current philosophy implementation in this status-only negative branch.\n\n\n **L1315** The rejected reason list contains standing alone.\n\n\n **L1316** State the contrasting justified choice under the same proposal-review requirements.\n\n\n **L1317** Use exactly the same current philosophy implementation in the positive case.\n\n\n **L1318** Its actual output performance supplies the positive reason.\n\n\n **L1319** Quantify status-only insufficiency over names, conventional use and standing.\n\n\n **L1320** Neither name, convention nor standing alone justifies the identity implementation.\n\n\n **L1321** Combine six choice proofs, retaining real content comparisons and rejecting privilege for the current philosophy.\n\n\n **L1323** Explain that this bundle repeats full component propositions; named proofs below establish their conjunction.\n\n\n **L1324** Begin source-tracing metadata for CoreReader.Adopted.choiceLimits012; this mapping is not a proof premise.\n\n\n **L1325** Record source clause organon.grounds.implementations#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1326** Record source clause organon.grounds.implementations#p2 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1327** Record source clause organon.grounds.implementations.limits#p1 and its displayed SHA-256 identity; this is documentary linkage, not semantic validation.\n\n\n **L1328** Close the preceding source-mapping comment without adding a logical condition.\n\n\n **L1329** Bundle limits of openness: one feasible conventional option, unequal internal reasons, broader differences and limited assessment-policy independence.\n\n\n **L1330** Over the explicitly two-valued candidate type, require feasibility exactly for identity.\n\n\n **L1331** Also retain identity’s actual output-reason justification.\n\n\n **L1332** Keep both actual status facts true for identity.\n\n\n **L1333** Claim justified selection using a list containing convention and an actual output reason; the output reason supplies relevance.\n\n\n **L1334** Both implementations return identical actual outputs at every input.\n\n\n **L1335** Both meet the same output and budget feasibility requirements.\n\n\n **L1336** Require a faithful explanation reason for the same actual identity implementation.\n\n\n **L1337** The altered explanation fails that same relevance/content test.\n\n\n **L1338** Also retain identity’s actual output-reason justification.\n\n\n **L1339** Also require that identity and successor actually produce different outputs at input 0.\n\n\n **L1340** Compare actual outputs only under the input-0 scope.\n\n\n **L1341** Separately require a real output difference at input 1.\n\n\n **L1342** Require procedural articulation and a correctly negative report for the same status-priority assessment.\n\n\n **L1343** Keep all candidate interpretations as models of the same actual status facts.\n\n\n **L1344** The priority predicate holds at identity and fails at successor.\n\n\n **L1345** The status premises alone still do not entail the priority claim.\n\n\n **L1346** Also reject selecting identity with standing as the only actual reason.\n\n\n **L1347** The two policies share the same accurate assessment but differ in their actual priority reasons; this is not full Grounds independence.\n\n\n **L1348** Use six checked components; generalGroundsNotChoice proves only the disclosed general-assessment/choice-policy separation.\n\n\n **L1350** Close CoreReader.Adopted; subsequent declarations are outside this namespace.\n\n\n### `leanified/CoreReader/Agency.lean`\n\n\n```lean\nimport CoreReader.Reflexivity\n\nnamespace CoreReader.Agency\n\ninductive FormKind | organization | method | principle | appearance | artifact\n deriving DecidableEq, Repr\n\nstructure Form where\n kind : FormKind\n version : Nat\n deriving DecidableEq, Repr\n\ninductive Aim | expandUnderstandingAndConstruction | preserveSafeOperation\n deriving DecidableEq, Repr\n\n/- A policy records an adopted valuation, current forms, and permission. It does not assert that valuation is correct or enacted. -/\nstructure Policy where\n worthPursuing : Aim → Prop\n current : Form → Prop\n revisable : Form → Prop\n permitsVersion : Nat → Nat → Prop\n\n/- The normative specification keeps valuation and revisability separate from realized transitions. -/\ndef Generative (p : Policy) : Prop :=\n p.worthPursuing .expandUnderstandingAndConstruction ∧\n ∀ f, p.current f → p.revisable f\n\ndef openPolicy : Policy where\n worthPursuing a := a = .expandUnderstandingAndConstruction ∨ a = .preserveSafeOperation\n current f := f.version = 0\n revisable _ := True\n permitsVersion _ _ := True\n\ndef neutralPolicy : Policy := { openPolicy with worthPursuing := fun _ => False }\n\n/- Permitting a real version change does not supply an adopted value position. -/\ntheorem permissionNotValuation :\n neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy := by\n simp [neutralPolicy, openPolicy, Generative]\n\n/- This is an explicit consequence of the adopted specification, not evidence of actual revision. -/\ntheorem revisabilityCovers (p : Policy) (h : Generative p) (k : FormKind) (v : Nat)\n (hc : p.current ⟨k, v⟩) : p.revisable ⟨k, v⟩ := h.2 _ hc\n\ninductive Operation | copy | successor\n deriving DecidableEq, Repr\n\ndef Operation.run : Operation → Nat → Nat\n | .copy, n => n\n | .successor, n => n + 1\n\ninductive InventoryKind | document | term | tool | artifact\n deriving DecidableEq, Repr\n\nstructure Item where\n kind : InventoryKind\n content : Operation\n deriving DecidableEq, Repr\n\n/- Available represented operations are the contents present, not their number of occurrences. -/\ndef Available (xs : List Item) (op : Operation) : Prop :=\n ∃ item ∈ xs, item.content = op\n\n/- Duplicating any inventory category preserves exactly the represented operation content. -/\ntheorem inventoryNotCapability (kind : InventoryKind) (ops : List Operation) (op : Operation) :\n Available ((ops.map fun x => Item.mk kind x) ++ (ops.map fun x => Item.mk kind x)) op ↔\n Available (ops.map fun x => Item.mk kind x) op := by\n simp only [Available, List.mem_append]\n constructor\n · rintro ⟨x, hx | hx, hop⟩ <;> exact ⟨x, hx, hop⟩\n · rintro ⟨x, hx, hop⟩\n exact ⟨x, Or.inl hx, hop⟩\n\nstructure State where\n understood : List Operation\n constructed : List Operation\n inventory : List Item\n abstractionLayers : List Operation\n vocabulary : List Operation\n deriving DecidableEq, Repr\n\n/- A gain must identify an operation newly understood or constructed; this is a disclosed finite capability representation. -/\ndef Expanded (before after : State) : Prop :=\n (∃ op, op ∈ after.understood ∧ op ∉ before.understood) ∨\n (∃ op, op ∈ after.constructed ∧ op ∉ before.constructed)\n\ndef baseState : State :=\n ⟨[.copy], [.copy], [⟨.artifact, .copy⟩], [.copy], [.copy]⟩\n\ndef inflatedState : State :=\n { baseState with\n inventory := baseState.inventory ++ baseState.inventory\n abstractionLayers := [.copy, .copy]\n vocabulary := [.copy, .copy] }\n\ndef stableTrace (_time : Nat) : State := baseState\n\n/- A revisable policy can govern an unchanged trace; no improvement is hidden in revisability. -/\ntheorem revisionWithoutProgress :\n Generative openPolicy ∧\n (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧\n (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1))) := by\n simp [Generative, openPolicy, stableTrace, Expanded]\n\nstructure ExternalResources where\n experience : Option Nat\n knowledge : Option Nat\n collaborator : Option Nat\n deriving DecidableEq, Repr\n\n/- This interpreter actually needs all three external inputs to produce the modeled result. -/\ndef assistedExecution (r : ExternalResources) : Option Nat := do\n let e ← r.experience\n let k ← r.knowledge\n let c ← r.collaborator\n pure (Operation.copy.run (e + k + c))\n\ndef availableResources : ExternalResources := ⟨some 1, some 2, some 3⟩\n\n/- Stability has a concrete stated reason in this workload: preserve its operation while staying within the one-item budget. -/\ndef StableReason (before proposed : State) : Prop :=\n before.constructed = proposed.constructed ∧\n before.inventory.length ≤ 1 ∧ ¬ proposed.inventory.length ≤ 1\n\n/- The policy, current capabilities, execution interface and workload constraints belong to one generating system. -/\nstructure GeneratingSystem where\n owner : Nat\n policy : Policy\n current : State\n execute : ExternalResources → Option Nat\n applicationBudget : Nat\n requiredOperations : List Operation\n/- The modeled system uses the assisted interpreter under a one-item budget and a copy-operation requirement. -/\ndef generatingSystem : GeneratingSystem where\n owner := 0\n policy := openPolicy\n current := baseState\n execute := assistedExecution\n applicationBudget := 1\n requiredOperations := [.copy]\n/- A stable action retains this system's own current state. -/\ndef GeneratingSystem.stableAction (system : GeneratingSystem) : State := system.current\ndef GeneratingSystem.requirementsMet (system : GeneratingSystem) (state : State) : Prop :=\n ∀ operation, operation ∈ system.requiredOperations → operation ∈ state.constructed\ndef GeneratingSystem.withinBudget (system : GeneratingSystem) (state : State) : Prop :=\n state.inventory.length ≤ system.applicationBudget\n/- An expansion report identifies the actual before/after states and the operation/performance it asserts was added. -/\nstructure Announcement where\n owner : Nat\n before : State\n after : State\n reportedNewOperation : Operation\n input : Nat\n expectedOutput : Nat\n deriving DecidableEq, Repr\n/- Reports are generated by this system and identify its actual current state as their baseline. -/\ndef GeneratingSystem.report (system : GeneratingSystem) (after : State)\n (operation : Operation) (input expectedOutput : Nat) : Announcement :=\n ⟨system.owner, system.current, after, operation, input, expectedOutput⟩\n/- Report content is interpreted against those very states and the named operation's actual behavior. -/\ndef Announcement.claim (report : Announcement) : Prop :=\n report.reportedNewOperation ∈ report.after.constructed ∧\n report.reportedNewOperation ∉ report.before.constructed ∧\n report.reportedNewOperation.run report.input = report.expectedOutput\n/- A true report of this form entails a represented construction expansion. -/\ntheorem announcementClaimImpliesExpansion (report : Announcement) (h : report.claim) :\n Expanded report.before report.after := Or.inr ⟨report.reportedNewOperation, h.1, h.2.1⟩\n/- This concrete self-report asserts a successor operation for the actual inventory-only inflation. -/\ndef inflatedAnnouncement : Announcement := generatingSystem.report inflatedState .successor 0 1\n/- The report asserts a real successor result but its named operation is absent from its own after-state. -/\ntheorem inflatedAnnouncementRefuted :\n inflatedAnnouncement.before = baseState ∧ inflatedAnnouncement.after = inflatedState ∧\n inflatedAnnouncement.reportedNewOperation = .successor ∧\n inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧\n ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after := by\n simp [inflatedAnnouncement, GeneratingSystem.report, generatingSystem, Announcement.claim, Expanded, baseState, inflatedState]\n\n/- These transitions share one initial state; only extension adds an actual new operation. -/\ninductive TransitionCase | inflate | extend\n deriving DecidableEq, Repr\n\ndef extendedState : State :=\n { baseState with understood := [.copy, .successor], constructed := [.copy, .successor] }\ndef transitionBefore (_transition : TransitionCase) : State := baseState\ndef transitionAfter : TransitionCase → State\n | .inflate => inflatedState\n | .extend => extendedState\n/- Both alternatives are assessed under the same concrete input condition. -/\ndef transitionInput (_transition : TransitionCase) : Nat := 0\ndef transitionAnnouncement (transition : TransitionCase) : Announcement :=\n generatingSystem.report (transitionAfter transition) .successor (transitionInput transition) 1\n\n/- Eleven boundary branches share a content-bearing trace and executable dependency model. They do not assert a universal law of human capability. -/\ntheorem generationLimits :\n Generative generatingSystem.policy ∧\n generatingSystem.policy.permitsVersion 0 0 ∧\n ¬ Expanded generatingSystem.current inflatedState ∧\n generatingSystem.current.inventory.length < inflatedState.inventory.length ∧\n generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧\n generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧\n generatingSystem.execute availableResources = some 6 ∧\n generatingSystem.execute { availableResources with experience := none } = none ∧\n generatingSystem.execute { availableResources with knowledge := none } = none ∧\n generatingSystem.execute { availableResources with collaborator := none } = none ∧\n generatingSystem.execute ⟨none, none, none⟩ = none ∧\n ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧\n generatingSystem.stableAction = generatingSystem.current ∧\n generatingSystem.requirementsMet generatingSystem.stableAction ∧\n generatingSystem.withinBudget generatingSystem.stableAction ∧\n ¬ generatingSystem.withinBudget inflatedState ∧\n StableReason generatingSystem.current inflatedState ∧\n (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧\n inflatedAnnouncement.owner = generatingSystem.owner ∧\n inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧\n inflatedAnnouncement.reportedNewOperation = .successor ∧\n inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧\n ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after) := by\n simp [generatingSystem, GeneratingSystem.stableAction, GeneratingSystem.requirementsMet,\n GeneratingSystem.withinBudget, GeneratingSystem.report, Generative, openPolicy, Expanded,\n baseState, inflatedState, assistedExecution, availableResources, Operation.run,\n StableReason, inflatedAnnouncement, Announcement.claim]\n\n/- The empty work log omits an actually applicable system assessment despite an open generative policy. -/\ntheorem generationNotReflexivity :\n Generative openPolicy ∧ ¬ Reflexive 0 (ownRules 0) [] := by\n constructor\n · simp [Generative, openPolicy]\n · intro h\n have bad := noSelfExemption 0 (ownRules 0) [] h (assessingRule 0) (by simp [ownRules])\n (.system 0) rfl (by simp [assessingRule, ownSubjects])\n simp [Performed] at bad\n\n/- The same proposed arithmetic principle is used in the self-test and in the universal correctness claim. -/\ndef ownArithmeticPrinciple (n : Nat) : Bool := decide (n + 1 = 2 * n)\n\ndef selfTest (samples : List Nat) : Bool := samples.all ownArithmeticPrinciple\n\n/- A genuine evaluation on the selected sample succeeds, while the same principle fails at zero. -/\ntheorem selfTestDoesNotProve :\n selfTest [1] = true ∧ ownArithmeticPrinciple 0 = false ∧\n ¬ (∀ n, ownArithmeticPrinciple n = true) := by\n constructor\n · decide\n constructor\n · decide\n · intro h\n have bad := h 0\n contradiction\n\nend CoreReader.Agency\n```\n\n\n\n **L1** Imports CoreReader.Reflexivity and its dependencies into this module.\n\n\n **L3** Opens namespace CoreReader.Agency; file boundaries do not change declaration identity.\n\n\n **L5** Defines exactly five form tags; their names carry no additional semantics.\n\n\n **L6** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L8** A form is a kind tag and a natural-number version.\n\n\n **L9** Stores whether this form is an organization, method, principle, appearance or artifact.\n\n\n **L10** Stores a natural-number form version; it does not prove any change occurred.\n\n\n **L11** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L13** Defines two aim tags: expanding understanding/construction and preserving safe operation; the datatype alone does not value either aim.\n\n\n **L14** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L16** Documents the following definition or result: A policy supplies four unrelated predicate fields; no law ties version permission to valuation or revisability.\n\n\n **L17** A policy supplies four unrelated predicate fields; no law ties version permission to valuation or revisability.\n\n\n **L18** Specifies which of the two represented aims this policy regards as worth pursuing.\n\n\n **L19** Specifies the form kind/version pairs currently held by this policy.\n\n\n **L20** Specifies which form kind/version pairs this policy leaves revisable.\n\n\n **L21** Specifies permission between version numbers independently of actual execution.\n\n\n **L23** Documents the following definition or result: A policy satisfies this predicate when it values the designated expansion aim and declares every current form revisable. This states no actual progress condition.\n\n\n **L24** A policy satisfies this predicate when it values the designated expansion aim and declares every current form revisable. This states no actual progress condition.\n\n\n **L25** Requires this policy to value expanding understanding and construction.\n\n\n **L26** Requires every form currently held by this policy to remain revisable.\n\n\n **L28** Constructs a policy valuing both aims, selecting version zero, and permitting every revision and version pair.\n\n\n **L29** Values both expansion and preserving safe operation in openPolicy.\n\n\n **L30** Treats precisely version-zero forms as current, regardless of kind.\n\n\n **L31** Allows revision of every form, including forms not currently held.\n\n\n **L32** Permits every pair of version numbers; this does not execute a change.\n\n\n **L34** Copies the open policy but makes every aim unworthy of pursuit; the permission fields are unchanged.\n\n\n **L36** Documents the following definition or result: Shows permission for version 0 to 1 and distinct versions coexist with failure of the generation predicate.\n\n\n **L37** Shows permission for version 0 to 1 and distinct versions coexist with failure of the generation predicate.\n\n\n **L38** States that neutralPolicy permits 0→1, the versions differ, and its missing valuation defeats Generative.\n\n\n **L39** Unfolds the two policies: permission is true, 0≠1 computes true, and the required valuation is false.\n\n\n **L41** Documents the following definition or result: Extracts revisability of a specified current kind/version from an assumed generation predicate; it does not revise that form.\n\n\n **L42** Extracts revisability of a specified current kind/version from an assumed generation predicate; it does not revise that form.\n\n\n **L43** Uses h's revisability clause on the same kind/version form that hc identifies as current.\n\n\n **L45** Defines the only two encoded operations: identity and successor on natural numbers.\n\n\n **L46** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L48** Interprets an operation as a function on natural numbers.\n\n\n **L49** Executing copy returns its input unchanged.\n\n\n **L50** Executing successor returns the input plus one.\n\n\n **L52** Defines four inventory tags whose operational content is stored separately.\n\n\n **L53** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L55** An inventory item consists of a tag and one of the two operations.\n\n\n **L56** Classifies this inventory item as a document, term, tool or artifact.\n\n\n **L57** Records the operation represented by this item, independently of its category.\n\n\n **L58** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L60** Documents the following definition or result: Availability means that some item in the supplied list has exactly the requested operation as its content.\n\n\n **L61** Availability means that some item in the supplied list has exactly the requested operation as its content.\n\n\n **L62** An operation is available exactly when some listed item contains that operation.\n\n\n **L64** Documents the following definition or result: Proves that duplicating a uniformly tagged list of operations does not change which operations are available.\n\n\n **L65** Proves that duplicating a uniformly tagged list of operations does not change which operations are available.\n\n\n **L66** Tests availability after duplicating the list of items built from ops and the fixed category.\n\n\n **L67** Compares it with availability in the original single copy of that same list.\n\n\n **L68** Expands availability and turns membership in the duplicated list into membership in either copy.\n\n\n **L69** Proves both directions: duplication neither adds nor removes represented operations.\n\n\n **L70** An item found in either copy is already an original-list witness for the same operation.\n\n\n **L71** For the reverse direction, take an original item x with membership hx and matching content hop.\n\n\n **L72** Places that same item in the first copy, preserving its matching operation.\n\n\n **L74** A state is five lists; understanding and construction are represented only by membership in the two-operation datatype.\n\n\n **L75** Lists operations represented as understood in this state.\n\n\n **L76** Lists operations represented as constructed in this state.\n\n\n **L77** Stores inventory items; their multiplicity is distinct from capability membership.\n\n\n **L78** Stores abstraction-layer entries without identifying their count with understanding.\n\n\n **L79** Stores vocabulary entries without identifying their count with constructed capability.\n\n\n **L80** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L82** Documents the following definition or result: Expansion is the appearance of at least one previously absent operation in either understanding or construction. It allows losing other operations.\n\n\n **L83** Expansion is the appearance of at least one previously absent operation in either understanding or construction. It allows losing other operations.\n\n\n **L84** Expansion may be witnessed by an operation understood after the change but not before.\n\n\n **L85** Alternatively, a newly constructed operation witnesses expansion.\n\n\n **L87** Constructs a state with only copy in every operation list and one copy artifact.\n\n\n **L88** The baseline understands and constructs copy, with one copy artifact, layer and vocabulary entry.\n\n\n **L90** Constructs a larger inventory/layer/vocabulary state with unchanged understanding and construction.\n\n\n **L91** Starts from baseState, retaining fields unless explicitly overwritten below.\n\n\n **L92** Duplicates the one-item inventory while leaving understood and constructed operations unchanged.\n\n\n **L93** Replaces one abstraction-layer entry with two copies of copy.\n\n\n **L94** Similarly doubles the vocabulary list; no new operation is introduced.\n\n\n **L96** Returns the same base state at every natural-number time.\n\n\n **L98** Documents the following definition or result: Exhibits a policy meeting the generation interface and universal revisability while its independently chosen constant trace never expands.\n\n\n **L99** Exhibits a policy meeting the generation interface and universal revisability while its independently chosen constant trace never expands.\n\n\n **L100** Asserts openPolicy meets the adopted valuation-and-revisability specification.\n\n\n **L101** Additionally exposes revision permission for version zero of every form category.\n\n\n **L102** Every adjacent pair in the constant trace lacks a newly understood or constructed operation.\n\n\n **L103** Reduces the policy clauses to true and every expansion claim to impossible new membership in an unchanged list.\n\n\n **L105** Stores three optional natural numbers representing external-resource slots.\n\n\n **L106** An optional external experience value; none makes assistedExecution fail at its first read.\n\n\n **L107** An optional knowledge value required after the experience input.\n\n\n **L108** An optional collaborator value required before producing the result.\n\n\n **L109** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L111** Documents the following definition or result: An Option computation succeeds only when all three slots are present, then returns their sum through identity. This dependency is programmed into the example.\n\n\n **L112** An Option computation succeeds only when all three slots are present, then returns their sum through identity. This dependency is programmed into the example.\n\n\n **L113** Reads experience into e, immediately returning none when that resource is absent.\n\n\n **L114** Reads knowledge into k; absence aborts the same Option computation.\n\n\n **L115** Reads the collaborator's value into c, also propagating absence.\n\n\n **L116** Returns the sum e+k+c through the copy operation inside some.\n\n\n **L118** Provides resource values 1, 2 and 3 for the concrete success case.\n\n\n **L120** Documents the following definition or result: Defines a particular non-growth reason: construction lists match, the old inventory has length at most one, and the proposed one exceeds one.\n\n\n **L121** Defines a particular non-growth reason: construction lists match, the old inventory has length at most one, and the proposed one exceeds one.\n\n\n **L122** A reason to retain the old state requires both states to have exactly the same constructed operations.\n\n\n **L123** The old inventory must fit the one-item limit while the proposed inventory exceeds it.\n\n\n **L125** Documents the following definition or result: Binds one owner's policy, current state, resource-dependent executor, budget and required operations.\n\n\n **L126** Binds one owner's policy, current state, resource-dependent executor, budget and required operations.\n\n\n **L127** Identifies the owner of this generating system.\n\n\n **L128** Attaches the valuation and revisability policy to this same system.\n\n\n **L129** Stores the system's current represented capability and inventory state.\n\n\n **L130** Stores this system's actual resource-consuming execution function.\n\n\n **L131** Specifies the inventory-size budget used to evaluate stable and proposed states.\n\n\n **L132** Specifies operations that the workload requires to remain constructed.\n\n\n **L133** Documents the following definition or result: Instantiates owner zero with the open policy, base state, three-slot executor, budget one and required copy operation.\n\n\n **L134** Instantiates owner zero with the open policy, base state, three-slot executor, budget one and required copy operation.\n\n\n **L135** Assigns owner identifier zero to the concrete generating system.\n\n\n **L136** Installs openPolicy in that same concrete system.\n\n\n **L137** Sets its current capabilities and inventory to baseState.\n\n\n **L138** Uses the three-resource assisted interpreter as this system's execution interface.\n\n\n **L139** Sets this workload's inventory budget to exactly one item.\n\n\n **L140** Requires the concrete workload to preserve the copy operation.\n\n\n **L141** Documents the following definition or result: Returns this system's current state as its stability-preserving action.\n\n\n **L142** Returns this system's current state as its stability-preserving action.\n\n\n **L143** Checks every operation required by this same system is constructed in the assessed state.\n\n\n **L144** For this system and proposed state, every required operation must occur in the state's constructed list.\n\n\n **L145** Compares the assessed state's inventory length against this system's declared budget.\n\n\n **L146** Checks the state's inventory count against this same system's declared application budget.\n\n\n **L147** Documents the following definition or result: Stores reporting owner, exact before/after states, claimed new operation, tested input and expected output.\n\n\n **L148** Stores reporting owner, exact before/after states, claimed new operation, tested input and expected output.\n\n\n **L149** Records whose expansion announcement this is.\n\n\n **L150** Stores the exact baseline state named by the announcement.\n\n\n **L151** Stores the exact resulting state named by the announcement.\n\n\n **L152** Names the operation alleged to be newly constructed.\n\n\n **L153** Fixes the input at which the announced operation's behavior is claimed.\n\n\n **L154** Stores the claimed output of that operation at the stated input.\n\n\n **L155** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L156** Documents the following definition or result: Builds a report from this system's owner/current state and the supplied proposal and operation contract.\n\n\n **L157** Builds a report from this system's owner/current state and the supplied proposal and operation contract.\n\n\n **L158** Receives the allegedly new operation and the concrete input/output pair for this report.\n\n\n **L159** Builds a report tied to the system's owner and current baseline, using the supplied after-state and claim data.\n\n\n **L160** Documents the following definition or result: Requires the reported operation to be newly constructed and to produce the stated output at the stated input.\n\n\n **L161** Requires the reported operation to be newly constructed and to produce the stated output at the stated input.\n\n\n **L162** The reported new operation must actually occur in the announcement's after-state.\n\n\n **L163** The same operation must be absent from the announcement's baseline constructed list.\n\n\n **L164** Its actual run at the reported input must equal the announced expected output.\n\n\n **L165** Documents the following definition or result: Uses the genuinely new constructed operation from an assumed report claim as the expansion witness.\n\n\n **L166** Uses the genuinely new constructed operation from an assumed report claim as the expansion witness.\n\n\n **L167** Uses the claim's after-membership and before-absence to construct Expanded's construction branch.\n\n\n **L168** Documents the following definition or result: This system reports successor at input zero for an inventory-only inflation proposal.\n\n\n **L169** This system reports successor at input zero for an inventory-only inflation proposal.\n\n\n **L170** Documents the following definition or result: Computes the exact report objects and shows its claimed new operation and actual expansion both fail.\n\n\n **L171** Computes the exact report objects and shows its claimed new operation and actual expansion both fail.\n\n\n **L172** Confirms the concrete announcement refers to baseState and inflatedState themselves.\n\n\n **L173** Confirms the alleged new operation is successor.\n\n\n **L174** Confirms the announced test is input zero with expected output one.\n\n\n **L175** States both that the announcement's substantive claim fails and that its own state pair has no expansion.\n\n\n **L176** Computes the report fields and unchanged capability lists; successor is absent from the after-state despite its correct 0→1 behavior.\n\n\n **L178** Documents the following definition or result: Restricts the achievement model to inventory inflation and genuine operation extension.\n\n\n **L179** Restricts the achievement model to inventory inflation and genuine operation extension.\n\n\n **L180** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L182** Adds successor to the base state's understanding and construction lists.\n\n\n **L183** Adds successor to both understood and constructed lists while retaining the baseline's other fields.\n\n\n **L184** Both modeled transitions share the same base-state baseline.\n\n\n **L185** Chooses inflatedState or extendedState according to the transition constructor.\n\n\n **L186** The inflate transition ends at the inventory-only inflated state.\n\n\n **L187** The extend transition ends at the state with newly understood and constructed successor.\n\n\n **L188** Documents the following definition or result: Uses zero as the explicit tested input for both transition cases.\n\n\n **L189** Uses zero as the explicit tested input for both transition cases.\n\n\n **L190** Reports successor output one at input zero for this same system and selected after-state.\n\n\n **L191** Both alternatives announce successor at the shared input zero, but name their own actual after-state.\n\n\n **L193** Documents the following definition or result: Checks all concrete branches on the bound system: unchanged capability despite list inflation, resource dependence, justified stable action and an untrue same-object achievement report.\n\n\n **L194** Checks all concrete branches on the bound system: unchanged capability despite list inflation, resource dependence, justified stable action and an untrue same-object achievement report.\n\n\n **L195** The concrete system retains the adopted generative policy.\n\n\n **L196** Its policy allows keeping version zero, so generativity does not require every action to change versions.\n\n\n **L197** Inflating this system's inventory does not expand its represented capabilities.\n\n\n **L198** The inflated state has strictly more inventory entries than this system's current state.\n\n\n **L199** Its abstraction-layer count also strictly increases without capability expansion.\n\n\n **L200** Its vocabulary count strictly increases under the same unchanged capability content.\n\n\n **L201** With resources 1,2,3, this system's execution actually returns some 6.\n\n\n **L202** Removing experience from that same resource bundle makes the system's execution fail.\n\n\n **L203** Removing knowledge alone likewise makes its execution return none.\n\n\n **L204** Removing the collaborator input alone also makes execution fail.\n\n\n **L205** With all three external inputs absent, this same execution interface returns none.\n\n\n **L206** The system's stable action yields no represented capability expansion.\n\n\n **L207** That stable action is exactly retention of the system's current state.\n\n\n **L208** Retention preserves the workload's required copy operation.\n\n\n **L209** The retained one-item state fits this system's one-item application budget.\n\n\n **L210** The duplicated inventory has two entries and exceeds this same system's one-item budget.\n\n\n **L211** Stability has the stated reason: construction is unchanged, but only the current state fits the budget.\n\n\n **L212** Identifies the report as this system's announcement about inflatedState, successor, input zero and output one.\n\n\n **L213** The report's owner equals this generating system's owner.\n\n\n **L214** The report uses this system's current state as baseline and inflatedState as result.\n\n\n **L215** The operation this actual report calls new is successor.\n\n\n **L216** The report's claimed performance remains the concrete pair 0→1.\n\n\n **L217** Despite that report, its claim is false and its own before/after pair has no capability expansion.\n\n\n **L218** Begins computing all generationLimits clauses by exposing the concrete system, retention action and required-operation check.\n\n\n **L219** Also exposes the one-item budget, report constructor and policy/expansion predicates so their claims reduce to concrete data.\n\n\n **L220** Uses the actual baseline/inflated lists and three-resource interpreter to decide the size, membership and execution results.\n\n\n **L221** Finally unfolds the stability reason and owned announcement claim, completing all conjunction branches by computation.\n\n\n **L223** Documents the following definition or result: Exhibits a policy meeting generation while empty records fail the nonempty concrete reflexivity requirements.\n\n\n **L224** Exhibits a policy meeting generation while empty records fail the nonempty concrete reflexivity requirements.\n\n\n **L225** Combines a generative openPolicy with failure of owned reflexivity when the work log is empty.\n\n\n **L226** Separates establishing Generative from refuting the empty-log Reflexive claim.\n\n\n **L227** Computes openPolicy's expansion valuation and unconditional revisability.\n\n\n **L228** Assumes, for contradiction, that the empty log satisfies the owned reflexivity contract.\n\n\n **L229** Applies noSelfExemption to the registered assessingRule, forcing a performed assessment from the assumed empty-log compliance.\n\n\n **L230** Chooses the very system subject with matching owner and proves that assessment is applicable to it.\n\n\n **L231** Unfolding Performed reveals an impossible member of the empty work list.\n\n\n **L233** Documents the following definition or result: Decides the arithmetic equation n+1=2*n for each natural number.\n\n\n **L234** Decides the arithmetic equation n+1=2*n for each natural number.\n\n\n **L236** Returns true precisely when the equation holds at every listed sample; no unlisted input is tested.\n\n\n **L238** Documents the following definition or result: Computes success on sample 1 and failure at 0, refuting universal success. This concerns the particular arithmetic predicate, not a universal impossibility theorem about all self-tests.\n\n\n **L239** Computes success on sample 1 and failure at 0, refuting universal success. This concerns the particular arithmetic predicate, not a universal impossibility theorem about all self-tests.\n\n\n **L240** The same arithmetic principle passes sample 1 but evaluates false at 0.\n\n\n **L241** Therefore that principle does not return true for every natural-number input.\n\n\n **L242** Separates the passing sample computation from the two failure claims.\n\n\n **L243** Evaluates the singleton sample: 1+1 equals 2×1, so selfTest [1] is true.\n\n\n **L244** Separates the concrete failure at zero from refuting universal success.\n\n\n **L245** Computes 0+1≠2×0, making ownArithmeticPrinciple 0 false.\n\n\n **L246** Assumes the same principle succeeds for every input.\n\n\n **L247** Specializes that universal assumption to input zero.\n\n\n **L248** Contradicts the computed false result at zero, refuting universal correctness.\n\n\n **L250** Closes the current namespace.\n\n\n### `leanified/CoreReader/Choice.lean`\n\n\n```lean\nimport CoreReader.Evidence\n\nnamespace CoreReader.Choice\nopen CoreReader.Logic CoreReader.Evidence\n\ninductive StatusKind | name | convention | standing\n deriving DecidableEq, Repr\n\ninductive MethodReason | output | explanation | applicability | simplicity | procedure\n deriving DecidableEq, Repr\n\ninductive Reason | status (kind : StatusKind) | method (kind : MethodReason)\n deriving DecidableEq, Repr\n\n/- An implementation has observable behavior, a stated domain, an explanation formula and an execution trace. -/\nstructure Implementation where\n name : String\n conventional : Bool\n established : Bool\n run : Nat → Nat\n cost : Nat\n domain : Nat → Prop\n explanation : Nat → Nat\n trace : Nat → List Nat\n\n/- An application selects relevant objectives and constraints; no universal ranking or score is prescribed. -/\nstructure Requirements where\n inputs : Nat → Prop\n expected : Nat → Nat\n budget : Nat\n values : MethodReason → Prop\n\n/- These are explicit, content-based interpretations of possible method reasons in this application. -/\ndef MethodContent (req : Requirements) (i : Implementation) : MethodReason → Prop\n | .output => ∀ x, req.inputs x → i.run x = req.expected x\n | .explanation => ∀ x, req.inputs x → i.explanation x = i.run x\n | .applicability => ∀ x, req.inputs x → i.domain x\n | .simplicity => i.cost ≤ req.budget\n | .procedure => ∀ x, req.inputs x → (i.trace x).getLast? = some (i.run x)\n\n/- The extra choice commitment requires both selected relevance and actual reason content; pure status supplies neither. -/\ndef Relevant (req : Requirements) (i : Implementation) : Reason → Prop\n | .status _ => False\n | .method kind => req.values kind ∧ MethodContent req i kind\n\ndef Feasible (req : Requirements) (i : Implementation) : Prop :=\n (∀ x, req.inputs x → i.run x = req.expected x) ∧ i.cost ≤ req.budget\n\n/- In this application, a relevant reason is eligible only after its stated output and budget requirements hold. -/\ndef JustifiedChoice (req : Requirements) (i : Implementation) (reasons : List Reason) : Prop :=\n Feasible req i ∧ ∃ reason ∈ reasons, Relevant req i reason\n\n/- This proves the structural effect of the adopted choice commitment for each of its three status-only cases. -/\ntheorem statusOnlyFails (req : Requirements) (i : Implementation) (k : StatusKind) :\n ¬ JustifiedChoice req i [.status k] := by\n rintro ⟨_, reason, hr, hv⟩\n simp only [List.mem_singleton] at hr\n subst reason\n exact hv\n\ndef identityImpl : Implementation where\n name := \"Existing identity implementation\"\n conventional := true\n established := true\n run n := n\n cost := 1\n domain _ := True\n explanation n := n\n trace n := [n]\n\ndef successorImpl : Implementation where\n name := \"Successor implementation\"\n conventional := false\n established := false\n run n := n + 1\n cost := 2\n domain _ := True\n explanation n := n + 1\n trace n := [n, n + 1]\n\ndef changedOutsideZero : Implementation :=\n { identityImpl with\n name := \"Changed outside zero\"\n conventional := false\n established := false\n run := fun n => if n = 0 then 0 else n + 1\n explanation := fun n => if n = 0 then 0 else n + 1\n trace := fun n => [if n = 0 then 0 else n + 1] }\n\ndef identityRequirements : Requirements where\n inputs _ := True\n expected n := n\n budget := 1\n values _ := True\n\ndef objectiveReason : List Reason := [.method .output]\n\ntheorem identityOutputReason : Relevant identityRequirements identityImpl (.method .output) := by\n exact ⟨trivial, fun _ _ => rfl⟩\n\ntheorem identityFeasible : Feasible identityRequirements identityImpl :=\n ⟨fun _ _ => rfl, by decide⟩\n\ntheorem identityJustified : JustifiedChoice identityRequirements identityImpl objectiveReason :=\n ⟨identityFeasible, .method .output, by simp [objectiveReason], identityOutputReason⟩\n\n/- A conventional existing implementation can be selected for an actual requirement, not for status alone. -/\ntheorem conventionWithReason :\n identityImpl.conventional = true ∧ identityImpl.established = true ∧\n JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output] := by\n exact ⟨rfl, rfl, identityFeasible, .method .output, by simp, identityOutputReason⟩\n\ninductive Candidate | identity | successor\n deriving DecidableEq, Repr\n\ndef implementation : Candidate → Implementation\n | .identity => identityImpl\n | .successor => successorImpl\n\n/- Feasibility is decided by the same stated behavior and resource requirement for either candidate. -/\ntheorem singleFeasible :\n (∀ candidate, Feasible identityRequirements (implementation candidate) ↔ candidate = .identity) ∧\n JustifiedChoice identityRequirements identityImpl objectiveReason := by\n constructor\n · intro candidate\n cases candidate\n · simp [Feasible, identityRequirements, implementation, identityImpl]\n · simp [Feasible, identityRequirements, implementation, successorImpl]\n · exact identityJustified\n\n/- The same observed input can conceal a relevant difference at another input. -/\ntheorem localNotGlobal :\n (∀ x, x = 0 → identityImpl.run x = changedOutsideZero.run x) ∧\n identityImpl.run 1 ≠ changedOutsideZero.run 1 := by\n constructor\n · intro x hx; subst x; rfl\n · decide\n\n/- This candidate is cheap enough but misses the required identity output. -/\ndef cheapSuccessor : Implementation := { successorImpl with cost := 1 }\n\ntheorem eligibleInternalReasonNotSufficient :\n Relevant identityRequirements cheapSuccessor (.method .simplicity) ∧\n ¬ JustifiedChoice identityRequirements cheapSuccessor [.method .simplicity] := by\n refine ⟨⟨trivial, by change 1 ≤ 1; decide⟩, ?_⟩\n intro h\n have bad := h.1.1 0 trivial\n cases bad\n\n/- Each of the four internal-method reasons is eligible because of its actual selected requirement and content. -/\ntheorem internalReasons :\n Relevant identityRequirements identityImpl (.method .explanation) ∧\n Relevant identityRequirements identityImpl (.method .applicability) ∧\n Relevant identityRequirements identityImpl (.method .simplicity) ∧\n Relevant identityRequirements identityImpl (.method .procedure) ∧\n (Relevant identityRequirements cheapSuccessor (.method .simplicity) ∧\n ¬ JustifiedChoice identityRequirements cheapSuccessor [.method .simplicity]) := by\n exact ⟨⟨trivial, fun _ _ => rfl⟩, ⟨trivial, fun _ _ => trivial⟩,\n ⟨trivial, by change 1 ≤ 1; decide⟩, ⟨trivial, fun _ _ => rfl⟩, eligibleInternalReasonNotSufficient⟩\n\n/- Openness about reasons does not make two actual behaviors identical or reject the existing implementation. -/\ntheorem openNotEquivalent :\n JustifiedChoice identityRequirements identityImpl objectiveReason ∧\n identityImpl.run 0 ≠ successorImpl.run 0 := by\n exact ⟨identityJustified, by decide⟩\n\n/- A priority interpretation chooses one of the same two actual implementations. -/\ndef priorityClaim : Claim Candidate := fun selected => selected = .identity\n\ndef statusFacts : Theory Candidate := union\n (singleton (fun _ => identityImpl.conventional = true))\n (singleton (fun _ => identityImpl.established = true))\n\n/- Both interpretations have exactly the same true conventional and established status facts. -/\ntheorem statusFactsModel (selected : Candidate) : Models statusFacts selected := by\n exact (modelsUnion _ _ _).2 ⟨(modelsSingleton _ _).2 rfl, (modelsSingleton _ _).2 rfl⟩\n\ndef priorityArticulation : Articulation Candidate :=\n ⟨[\"priority\", \"conventional use\", \"established status\"], statusFacts,\n [fun _ => identityImpl.conventional = true, fun _ => identityImpl.established = true],\n fun _ => True⟩\n\n/- This procedure reports whether the actual status premises entail that very priority claim over its stated two-candidate scope. -/\ndef AssessmentAccurate (report : Bool) : Prop :=\n report = true ↔ Entails statusFacts priorityClaim\n\ntheorem statusDoesNotEntailPriority : ¬ Entails statusFacts priorityClaim := by\n intro h\n have bad := h .successor (statusFactsModel .successor)\n cases bad\n\ntheorem statusAssessmentNonEntailment :\n Articulated priorityArticulation ∧ AssessmentAccurate false ∧\n (∀ selected, Models statusFacts selected) ∧\n priorityClaim .identity ∧ ¬ priorityClaim .successor ∧\n ¬ Entails statusFacts priorityClaim ∧\n ¬ JustifiedChoice identityRequirements identityImpl [.status .standing] := by\n refine ⟨⟨by simp [priorityArticulation], by simp [priorityArticulation]⟩,\n ⟨(by intro h; cases h), (fun h => False.elim (statusDoesNotEntailPriority h))⟩,\n statusFactsModel, rfl, (by intro h; cases h), statusDoesNotEntailPriority,\n statusOnlyFails _ _ _⟩\n\n/- An assessment identifies the exact premises and priority question whose entailment it reports. -/\nstructure PriorityAssessment where\n premises : Theory Candidate\n question : Claim Candidate\n report : Bool\n/- Accuracy concerns the actual reported entailment question, independently of a later choice policy. -/\ndef PriorityAssessment.accurate (assessment : PriorityAssessment) : Prop :=\n assessment.report = true ↔ Entails assessment.premises assessment.question\n/- Both policies receive this same correctly negative status-only priority audit. -/\ndef statusPriorityAudit : PriorityAssessment := ⟨statusFacts, priorityClaim, false⟩\n/- Priority reasons are a policy component independent of the assessment's report and objects. -/\nstructure ChoicePolicy where\n selected : Candidate\n priorityReasons : List Reason\n assessment : PriorityAssessment\n/- This is completion of the specified assessment procedure only, not full compliance with philosophical Grounds. -/\ndef GeneralAssessmentFulfilled (policy : ChoicePolicy) : Prop :=\n Articulated priorityArticulation ∧ policy.assessment = statusPriorityAudit ∧ policy.assessment.accurate\n/- The additional choice norm separately tests the reasons actually used to prioritize the selected implementation. -/\ndef AdditionalChoiceNorm (policy : ChoicePolicy) : Prop :=\n JustifiedChoice identityRequirements (implementation policy.selected) policy.priorityReasons\n/- This policy retains status alone as its priority reason despite receiving the correctly negative status audit. -/\ndef statusPriorityPolicy : ChoicePolicy := ⟨.identity, [.status .standing], statusPriorityAudit⟩\n/- This policy selects the same implementation using its actual relevant output reason after the same audit. -/\ndef outputPriorityPolicy : ChoicePolicy := ⟨.identity, objectiveReason, statusPriorityAudit⟩\n/- The shared negative result is mathematically accurate for its actual status premises and question. -/\ntheorem statusPriorityAuditAccurate : statusPriorityAudit.accurate := by\n constructor\n · intro h; cases h\n · intro h; exact False.elim (statusDoesNotEntailPriority h)\n/- These independently variable policies share facts, selected implementation and completed audit, but differ on the extra choice norm. -/\ndef PolicyIndependenceExample : Prop :=\n statusPriorityPolicy.selected = outputPriorityPolicy.selected ∧\n statusPriorityPolicy.assessment = outputPriorityPolicy.assessment ∧\n statusPriorityPolicy.assessment.premises = statusFacts ∧\n statusPriorityPolicy.assessment.question = priorityClaim ∧\n statusPriorityPolicy.assessment.report = false ∧\n (∀ selected, Models statusPriorityPolicy.assessment.premises selected) ∧\n statusPriorityPolicy.priorityReasons ≠ outputPriorityPolicy.priorityReasons ∧\n GeneralAssessmentFulfilled statusPriorityPolicy ∧ GeneralAssessmentFulfilled outputPriorityPolicy ∧\n ¬ AdditionalChoiceNorm statusPriorityPolicy ∧ AdditionalChoiceNorm outputPriorityPolicy\n/- Changing the actual priority reasons changes choice compliance while the accurate audit remains identical. -/\ntheorem policyIndependenceExample : PolicyIndependenceExample := by\n have articulated : Articulated priorityArticulation :=\n ⟨by simp [priorityArticulation], by simp [priorityArticulation]⟩\n refine ⟨rfl,rfl,rfl,rfl,rfl,statusFactsModel,?_,\n ⟨articulated,rfl,statusPriorityAuditAccurate⟩,\n ⟨articulated,rfl,statusPriorityAuditAccurate⟩,?_,?_⟩\n · decide\n · exact statusOnlyFails identityRequirements identityImpl .standing\n · exact identityJustified\n\n/- A correctly articulated, completed negative assessment does not enforce the additional selection rule.\nThis is only independence from represented assessment procedures: keeping this unsupported priority would fail general support proportionality too. -/\ntheorem generalGroundsNotChoice :\n (Articulated priorityArticulation ∧ AssessmentAccurate false ∧\n (∀ selected, Models statusFacts selected) ∧\n priorityClaim .identity ∧ ¬ priorityClaim .successor ∧\n ¬ Entails statusFacts priorityClaim ∧\n ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧\n PolicyIndependenceExample :=\n ⟨statusAssessmentNonEntailment, policyIndependenceExample⟩\n\nend CoreReader.Choice\n```\n\n\n\n **L1** Import CoreReader.Evidence, making its checked declarations available to this module; this line states no new philosophical result.\n\n\n **L3** Open namespace CoreReader.Choice so subsequent declarations receive this module-qualified name.\n\n\n **L4** Make names from CoreReader.Logic CoreReader.Evidence available without qualification; this changes name resolution, not assumptions.\n\n\n **L6** Declare the alternatives StatusKind. Defines three status tags; no ranking or evidential meaning is attached by the datatype alone.\n\n\n **L7** Derive decidable equality and printable representations for these finite constructors; these are computational conveniences, not choice criteria.\n\n\n **L9** Declare the alternatives MethodReason. Defines five method-reason tags whose actual content is supplied by MethodContent.\n\n\n **L10** Derive decidable equality and printable representations for these finite constructors; these are computational conveniences, not choice criteria.\n\n\n **L12** Declare the alternatives Reason. Separates tagged status reasons from tagged method reasons.\n\n\n **L13** Derive decidable equality and printable representations for these finite constructors; these are computational conveniences, not choice criteria.\n\n\n **L15** Document the intended scope of Implementation. The corresponding declaration concerns: Packages an implementation's metadata, behavior, cost, domain, explanation function and trace function as independently supplied fields. This comment is explanatory, not a proof premise.\n\n\n **L16** Declare the data interface Implementation. Packages an implementation's metadata, behavior, cost, domain, explanation function and trace function as independently supplied fields.\n\n\n **L17** Store the implementation’s descriptive name; it does not confer priority.\n\n\n **L18** Record whether the implementation is conventional as a Boolean status fact.\n\n\n **L19** Record whether the implementation is established, independently of its actual behavior.\n\n\n **L20** Store the actual natural-number input/output function.\n\n\n **L21** Store the cost checked against an application’s budget.\n\n\n **L22** Store the implementation’s claimed domain as a predicate on inputs.\n\n\n **L23** Store explanatory output content to be compared with actual run results.\n\n\n **L24** Store an input-indexed execution trace whose last element can be compared with actual output.\n\n\n **L26** Document the intended scope of Requirements. The corresponding declaration concerns: Packages the input scope, expected output, fixed budget and valued reason kinds. This comment is explanatory, not a proof premise.\n\n\n **L27** Declare the data interface Requirements. Packages the input scope, expected output, fixed budget and valued reason kinds.\n\n\n **L28** Specify which inputs the application actually requires.\n\n\n **L29** Specify the expected output at each input.\n\n\n **L30** Specify the application’s budget constraint.\n\n\n **L31** Specify which method-reason categories this application values; this choice is an adopted input.\n\n\n **L33** Document the intended scope of MethodContent. The corresponding declaration concerns: Assigns a proposition to each method tag, using these particular behavioral and cost proxies. This comment is explanatory, not a proof premise.\n\n\n **L34** Define MethodContent. Assigns a proposition to each method tag, using these particular behavioral and cost proxies.\n\n\n **L35** An output reason requires this implementation’s actual output to equal the application’s expected output at every required input.\n\n\n **L36** An explanation reason requires explanatory output to match this very implementation’s actual run at every required input.\n\n\n **L37** An applicability reason requires every application-required input to belong to this implementation’s domain.\n\n\n **L38** The simplicity reason is the selected application’s actual cost-within-budget condition.\n\n\n **L39** A procedure reason requires the actual trace’s last element to equal this implementation’s real output at every required input.\n\n\n **L41** Document the intended scope of Relevant. The corresponding declaration concerns: A reason is relevant when it is an allowed method kind whose content holds; status kinds are excluded outright. This comment is explanatory, not a proof premise.\n\n\n **L42** Define Relevant. A reason is relevant when it is an allowed method kind whose content holds; status kinds are excluded outright.\n\n\n **L43** Status reasons are defined as irrelevant under this adopted choice norm, regardless of their status subtype.\n\n\n **L44** A method reason must both belong to a category valued by these requirements and satisfy that category’s actual MethodContent.\n\n\n **L46** Define Feasible. Feasibility requires universal requested-input output correctness and fixed cost within budget; it does not include explanation, domain or trace checks.\n\n\n **L47** Feasibility requires correct actual output at every required input and actual cost within this application’s budget.\n\n\n **L49** Document the intended scope of JustifiedChoice. The corresponding declaration concerns: Requires both output/budget feasibility and at least one listed valued method reason with its concrete content satisfied. This comment is explanatory, not a proof premise.\n\n\n **L50** Define JustifiedChoice. Requires both output/budget feasibility and at least one listed valued method reason with its concrete content satisfied.\n\n\n **L51** Require feasibility and at least one actually listed relevant reason; a relevant reason alone does not establish feasibility.\n\n\n **L53** Document the intended scope of statusOnlyFails. The corresponding declaration concerns: For any requirements and implementation, a singleton status reason cannot justify choice because its relevance is defined as false. This comment is explanatory, not a proof premise.\n\n\n **L54** State the checked result statusOnlyFails. For any requirements and implementation, a singleton status reason cannot justify choice because its relevance is defined as false.\n\n\n **L55** Deny justified selection when the only listed reason is status, for the supplied arbitrary requirements and implementation.\n\n\n **L56** Unpack an alleged status-only justified choice, extracting its listed reason and proof of relevance; feasibility alone cannot supply the missing relevance.\n\n\n **L57** Simplify singleton membership to show that the extracted reason is exactly the given status reason.\n\n\n **L58** Substitute the identified status reason into its alleged relevance proof.\n\n\n **L59** Relevance of a status reason is defined as False, so the extracted hv is already a contradiction.\n\n\n **L61** Define identityImpl. Builds an identity implementation with both status flags true, cost one, unrestricted domain, matching explanation and singleton output trace.\n\n\n **L62** Name the concrete existing identity implementation without using its name as a proof of quality.\n\n\n **L63** Mark the identity implementation’s conventional and established status as true; these facts remain distinct from its actual method reasons.\n\n\n **L64** Mark the identity implementation’s conventional and established status as true; these facts remain distinct from its actual method reasons.\n\n\n **L65** Define actual identity output as the unchanged input n.\n\n\n **L66** Set identity’s actual cost to 1.\n\n\n **L67** Let identity’s applicability domain contain all natural inputs.\n\n\n **L68** Provide an explanatory result equal to the input, matching identity’s actual output.\n\n\n **L69** Use the singleton input as the actual trace, whose last element equals identity’s output.\n\n\n **L71** Define successorImpl. Builds a successor implementation with false status flags, cost two, unrestricted domain, matching explanation and a two-entry trace.\n\n\n **L72** Name the alternative successor implementation.\n\n\n **L73** Mark successor as neither conventional nor established in this example; this status alone does not determine feasibility.\n\n\n **L74** Mark successor as neither conventional nor established in this example; this status alone does not determine feasibility.\n\n\n **L75** Define successor’s actual output as n+1.\n\n\n **L76** Set its original cost to 2, above the identity application’s budget 1.\n\n\n **L77** Let successor’s applicability domain also include every natural input.\n\n\n **L78** Provide its explanatory result n+1, faithful to its own actual output.\n\n\n **L79** Record input and then actual successor output in its trace.\n\n\n **L81** Define changedOutsideZero. Copies identity metadata/fields except the explicitly replaced ones, producing an implementation equal at zero but different elsewhere.\n\n\n **L82** Start from identityImpl’s fields and explicitly override the following components.\n\n\n **L83** Name the modified implementation by its change outside input zero.\n\n\n **L84** Change this modified implementation’s conventional/established flags to false.\n\n\n **L85** Change this modified implementation’s conventional/established flags to false.\n\n\n **L86** Keep output 0 at input 0 but return n+1 at every other input.\n\n\n **L87** Make its explanation follow the same actual piecewise output function.\n\n\n **L88** Use that same piecewise result as its singleton trace; finish the implementation override.\n\n\n **L90** Define identityRequirements. Requires identity behavior at all natural inputs, budget one, and values every method-reason kind.\n\n\n **L91** Require every natural-number input in the identity application.\n\n\n **L92** Set the desired output to the unchanged input.\n\n\n **L93** Adopt budget 1 for the application.\n\n\n **L94** Admit all represented method-reason categories; their actual content must still be checked.\n\n\n **L96** Define objectiveReason. Defines a reason list containing only the output-correctness method tag.\n\n\n **L98** State the checked result identityOutputReason. Proves the identity implementation has a relevant output reason under universal identity requirements by definitional output equality. The following tactic block proves this explicit type.\n\n\n **L99** The output reason is admitted by these requirements, and identityImpl’s actual output equals the expected output at every allowed input by reflexivity.\n\n\n **L101** State the checked result identityFeasible. Proves universal identity output and cost one within budget one. The supplied proof term uses the displayed constructed witnesses or earlier lemmas, rather than adding an axiom.\n\n\n **L102** For identity, every required output is correct by reflexivity; compute cost 1 within budget 1.\n\n\n **L104** State the checked result identityJustified. Uses the output reason as the existential witness justifying identity under the given requirements. The supplied proof term uses the displayed constructed witnesses or earlier lemmas, rather than adding an axiom.\n\n\n **L105** Combine identity’s feasibility with the actual output reason, prove it belongs to objectiveReason and supply its content-based relevance.\n\n\n **L107** Document the intended scope of conventionWithReason. The corresponding declaration concerns: Shows conventional and established metadata can coexist with justified choice when the list also contains a valid output reason; status does not provide the witness. This comment is explanatory, not a proof premise.\n\n\n **L108** State the checked result conventionWithReason. Shows conventional and established metadata can coexist with justified choice when the list also contains a valid output reason; status does not provide the witness.\n\n\n **L109** Keep both actual status facts true for identity.\n\n\n **L110** Claim justified selection using a list containing convention and an actual output reason; the output reason supplies relevance.\n\n\n **L111** Compute the conventional/established status facts, retain actual feasibility, and select the listed output reason with its separately proved relevance.\n\n\n **L113** Declare the alternatives Candidate. Closes the candidate universe to exactly identity and successor.\n\n\n **L114** Derive decidable equality and printable representations for these finite constructors; these are computational conveniences, not choice criteria.\n\n\n **L116** Define implementation. Maps each of the two candidate constructors to its concrete implementation.\n\n\n **L117** Interpret the identity candidate as the actual identityImpl object.\n\n\n **L118** Interpret the successor candidate as the actual successorImpl object.\n\n\n **L120** Document the intended scope of singleFeasible. The corresponding declaration concerns: Proves identity is the sole feasible member of the two-constructor candidate type under identity requirements, and separately supplies its output justification. This comment is explanatory, not a proof premise.\n\n\n **L121** State the checked result singleFeasible. Proves identity is the sole feasible member of the two-constructor candidate type under identity requirements, and separately supplies its output justification.\n\n\n **L122** Over the explicitly two-valued candidate type, require feasibility exactly for identity.\n\n\n **L123** Also retain identity’s actual output-reason justification.\n\n\n **L124** Separate the exact feasible-candidate characterization from the existing proof of identity’s justified selection.\n\n\n **L125** Fix any candidate in the explicit identity/successor type before checking its feasibility equivalence.\n\n\n **L126** Exhaust the actual two-candidate type: identity or successor; no unlisted implementation is considered.\n\n\n **L127** For identity, unfold actual outputs and cost; the identity-output and budget conditions are satisfied.\n\n\n **L128** For successor, unfold the same requirements; the candidate cannot meet identity outputs and its original cost also exceeds the budget.\n\n\n **L129** Reuse identityJustified to finish the concrete selected-candidate obligation.\n\n\n **L131** Document the intended scope of localNotGlobal. The corresponding declaration concerns: Shows identity and the piecewise implementation agree when input is zero but disagree at input one; this refutes inference from local agreement to global equality. This comment is explanatory, not a proof premise.\n\n\n **L132** State the checked result localNotGlobal. Shows identity and the piecewise implementation agree when input is zero but disagree at input one; this refutes inference from local agreement to global equality.\n\n\n **L133** Compare actual outputs only under the input-0 scope.\n\n\n **L134** Separately require a real output difference at input 1.\n\n\n **L135** Separate equality under the input-0 scope from actual inequality at input 1.\n\n\n **L136** Substitute the local-scope assumption x=0; the two implementations then have definitionally equal outputs.\n\n\n **L137** Compute their actual outputs at input 1 to verify the claimed inequality.\n\n\n **L139** Document the intended scope of cheapSuccessor. The corresponding declaration concerns: Lowers successor's fixed cost to one without fixing its identity-output failure. This comment is explanatory, not a proof premise.\n\n\n **L140** Define cheapSuccessor. Lowers successor's fixed cost to one without fixing its identity-output failure.\n\n\n **L142** State the checked result eligibleInternalReasonNotSufficient. Shows cost simplicity is relevant for cheap successor, yet output infeasibility prevents justified choice.\n\n\n **L143** Require that cheapSuccessor’s cost reason is actually relevant under the chosen requirements.\n\n\n **L144** Nevertheless reject its justified choice with that reason alone because feasibility includes correct outputs.\n\n\n **L145** Show the cheap successor has an admitted cost reason with cost 1 ≤ budget 1, then separately refute justified choice.\n\n\n **L146** Assume cheapSuccessor is justified using its cost reason, in order to extract and refute its required output feasibility.\n\n\n **L147** An alleged justified choice includes feasible outputs; apply that requirement at input 0, where successor returns 1 instead of expected 0.\n\n\n **L148** Eliminate the resulting impossible output equality; a relevant cost reason did not repair the wrong output.\n\n\n **L150** Document the intended scope of internalReasons. The corresponding declaration concerns: Provides four valid internal reasons for identity and a cost-relevant successor counterexample to automatic sufficiency. This comment is explanatory, not a proof premise.\n\n\n **L151** State the checked result internalReasons. Provides four valid internal reasons for identity and a cost-relevant successor counterexample to automatic sufficiency.\n\n\n **L152** Require a faithful explanation reason for the same actual identity implementation.\n\n\n **L153** Require its actual applicability to cover the required inputs.\n\n\n **L154** Require its actual cost to meet the valued simplicity/budget condition.\n\n\n **L155** Require its actual trace content to meet the valued procedure condition.\n\n\n **L156** Include a separate cheap-successor case where its cost reason is eligible.\n\n\n **L157** That cheap candidate still fails justified selection; the combined theorem begins its proof here.\n\n\n **L158** Provide admitted, actually faithful explanation and applicability reasons for identity, checking their content at every required input.\n\n\n **L159** Provide the actual budget and trace reasons, then include the cheap-but-wrong example showing relevance alone is insufficient.\n\n\n **L161** Document the intended scope of openNotEquivalent. The corresponding declaration concerns: Combines identity's justification with differing identity/successor outputs at zero. It proves behavioral distinction between these examples, not a general openness property. This comment is explanatory, not a proof premise.\n\n\n **L162** State the checked result openNotEquivalent. Combines identity's justification with differing identity/successor outputs at zero. It proves behavioral distinction between these examples, not a general openness property.\n\n\n **L163** Retain justified selection of the existing identity implementation based on its actual output reason.\n\n\n **L164** Also require that identity and successor actually produce different outputs at input 0.\n\n\n **L165** Retain the existing identity justification and compute the distinct actual outputs of identity and successor at 0.\n\n\n **L167** Document the intended scope of priorityClaim. The corresponding declaration concerns: Defines the priority claim as selection of the identity constructor. This comment is explanatory, not a proof premise.\n\n\n **L168** Define priorityClaim. Defines the priority claim as selection of the identity constructor.\n\n\n **L170** Define statusFacts. Forms a theory containing two status facts about identity that are constant across candidate worlds.\n\n\n **L171** The first status premise records actual conventional status of identity, regardless of the candidate interpretation.\n\n\n **L172** The second status premise records actual established status of that same implementation.\n\n\n **L174** Document the intended scope of statusFactsModel. The corresponding declaration concerns: Proves every candidate world models these status facts because both concern fixed metadata, independent of selection. This comment is explanatory, not a proof premise.\n\n\n **L175** State the checked result statusFactsModel. Proves every candidate world models these status facts because both concern fixed metadata, independent of selection. The following tactic block proves this explicit type.\n\n\n **L176** Both status predicates concern the same actual identity implementation and are true independently of which candidate interpretation is selected; combine their singleton models.\n\n\n **L178** Define priorityArticulation. Constructs a nonempty articulation of the constant status theory, with the same two status predicates as reasons and unrestricted limits.\n\n\n **L179** Articulate priority and actual status concepts using statusFacts as the premise theory.\n\n\n **L180** List the same actual conventional and established facts as articulated reasons.\n\n\n **L181** Use unrestricted candidate scope for this status-priority articulation.\n\n\n **L183** Document the intended scope of AssessmentAccurate. The corresponding declaration concerns: Defines report accuracy as equivalence between report=true and semantic entailment of the priority claim by status facts. This comment is explanatory, not a proof premise.\n\n\n **L184** Define AssessmentAccurate. Defines report accuracy as equivalence between report=true and semantic entailment of the priority claim by status facts.\n\n\n **L185** Define report accuracy by equivalence between report=true and semantic entailment of this exact priority question from these status facts.\n\n\n **L187** State the checked result statusDoesNotEntailPriority. Refutes priority entailment using successor, which models all fixed identity-status facts but is not identity. The following tactic block proves this explicit type.\n\n\n **L188** Assume the actual status facts entail identity priority across all candidate interpretations.\n\n\n **L189** Apply alleged status-to-priority entailment to successor, which satisfies all the same true status facts but is not identity.\n\n\n **L190** Distinct candidate constructors refute the priority equality derived at successor.\n\n\n **L192** State the checked result statusAssessmentNonEntailment. Retains the original factual countermodel: status facts are articulated and accurately assessed but do not entail identity priority.\n\n\n **L193** Require procedural articulation and a correctly negative report for the same status-priority assessment.\n\n\n **L194** Keep all candidate interpretations as models of the same actual status facts.\n\n\n **L195** The priority predicate holds at identity and fails at successor.\n\n\n **L196** Deny entailment of that priority predicate from status facts alone.\n\n\n **L197** Also reject selecting identity with standing as the only actual reason.\n\n\n **L198** Check that priorityArticulation has nonempty concepts and actual status reasons.\n\n\n **L199** Prove report=false is accurate: it cannot equal true, and any entailment assumption contradicts the actual successor countermodel.\n\n\n **L200** Retain models of the same facts for both candidates, priority at identity but not successor, and the established failed entailment.\n\n\n **L201** Reuse the general status-only failure theorem for the explicit identity choice with standing as its sole reason.\n\n\n **L203** Document the intended scope of PriorityAssessment. The corresponding declaration concerns: Stores the actual premise theory, question and Boolean assessment report independently of a choice policy. This comment is explanatory, not a proof premise.\n\n\n **L204** Declare the data interface PriorityAssessment. Stores the actual premise theory, question and Boolean assessment report independently of a choice policy.\n\n\n **L205** Store the actual premise theory audited by this assessment.\n\n\n **L206** Store the exact priority claim whose entailment is assessed.\n\n\n **L207** Store the reported Boolean answer separately from facts and question.\n\n\n **L208** Document the intended scope of PriorityAssessment.accurate. The corresponding declaration concerns: Matches the report to semantic entailment for this exact premise/question pair. This comment is explanatory, not a proof premise.\n\n\n **L209** Define PriorityAssessment.accurate. Matches the report to semantic entailment for this exact premise/question pair.\n\n\n **L210** Require this assessment’s actual report to agree exactly with entailment from its own premises to its own question.\n\n\n **L211** Document the intended scope of statusPriorityAudit. The corresponding declaration concerns: Records a false entailment report for the actual fixed status facts and priority question. This comment is explanatory, not a proof premise.\n\n\n **L212** Define statusPriorityAudit. Records a false entailment report for the actual fixed status facts and priority question.\n\n\n **L213** Document the intended scope of ChoicePolicy. The corresponding declaration concerns: Separates chosen candidate, priority reasons and the independently stored assessment. This comment is explanatory, not a proof premise.\n\n\n **L214** Declare the data interface ChoicePolicy. Separates chosen candidate, priority reasons and the independently stored assessment.\n\n\n **L215** Store the candidate this policy actually selects.\n\n\n **L216** Store the policy’s actual priority reasons independently of its assessment record.\n\n\n **L217** Store the actual assessment whose procedure the policy completed.\n\n\n **L218** Document the intended scope of GeneralAssessmentFulfilled. The corresponding declaration concerns: Requires nonempty actual articulation and the exact accurate status audit, without imposing the additional choice criterion. This comment is explanatory, not a proof premise.\n\n\n **L219** Define GeneralAssessmentFulfilled. Requires nonempty actual articulation and the exact accurate status audit, without imposing the additional choice criterion.\n\n\n **L220** Require nonempty articulation, exactly the shared statusPriorityAudit, and its accuracy; this is specified procedure fulfillment, not full philosophical Grounds.\n\n\n **L221** Document the intended scope of AdditionalChoiceNorm. The corresponding declaration concerns: Applies the separate feasibility-and-relevance choice norm to this policy's selected implementation and reasons. This comment is explanatory, not a proof premise.\n\n\n **L222** Define AdditionalChoiceNorm. Applies the separate feasibility-and-relevance choice norm to this policy's selected implementation and reasons.\n\n\n **L223** Separately apply JustifiedChoice to the policy’s actual selected implementation and its actual reason list.\n\n\n **L224** Document the intended scope of statusPriorityPolicy. The corresponding declaration concerns: Selects identity solely on standing while retaining the accurate non-entailment audit. This comment is explanatory, not a proof premise.\n\n\n **L225** Define statusPriorityPolicy. Selects identity solely on standing while retaining the accurate non-entailment audit.\n\n\n **L226** Document the intended scope of outputPriorityPolicy. The corresponding declaration concerns: Keeps the same choice and audit but uses the actual output reason. This comment is explanatory, not a proof premise.\n\n\n **L227** Define outputPriorityPolicy. Keeps the same choice and audit but uses the actual output reason.\n\n\n **L228** Document the intended scope of statusPriorityAuditAccurate. The corresponding declaration concerns: Uses the successor countermodel to establish the recorded false entailment report is accurate. This comment is explanatory, not a proof premise.\n\n\n **L229** State the checked result statusPriorityAuditAccurate. Uses the successor countermodel to establish the recorded false entailment report is accurate. The following tactic block proves this explicit type.\n\n\n **L230** Split accuracy of the negative audit into the two directions of its equivalence with entailment.\n\n\n **L231** The audit’s actual false report cannot equal true, so this direction has an impossible premise.\n\n\n **L232** Any asserted entailment contradicts statusDoesNotEntailPriority; this establishes the reverse accuracy direction for the false report.\n\n\n **L233** Document the intended scope of PolicyIndependenceExample. The corresponding declaration concerns: Requires two policies with the same actual selection/audit but different reasons, both satisfying represented assessment duties and only the output policy satisfying the extra norm. This comment is explanatory, not a proof premise.\n\n\n **L234** Define PolicyIndependenceExample. Requires two policies with the same actual selection/audit but different reasons, both satisfying represented assessment duties and only the output policy satisfying the extra norm.\n\n\n **L235** Fix identical selected candidates in both policies.\n\n\n **L236** Fix the same actual assessment in both policies.\n\n\n **L237** Bind that assessment’s premises to the actual shared statusFacts.\n\n\n **L238** Bind its question to the same priorityClaim.\n\n\n **L239** Fix the common report to false, rather than allowing policy changes to alter the audit answer.\n\n\n **L240** Retain models of these same assessment premises for every candidate interpretation.\n\n\n **L241** Require the actual priority reason lists to differ despite the shared candidate and audit.\n\n\n **L242** Require both policies to complete the same specified assessment procedure accurately.\n\n\n **L243** Require opposite results under the additional choice norm: status fails, output passes.\n\n\n **L244** Document the intended scope of policyIndependenceExample. The corresponding declaration concerns: Constructs both independent policy objects and combines actual audit accuracy with status rejection and output justification. This comment is explanatory, not a proof premise.\n\n\n **L245** State the checked result policyIndependenceExample. Constructs both independent policy objects and combines actual audit accuracy with status rejection and output justification. The following tactic block proves this explicit type.\n\n\n **L246** Construct one shared nonempty articulation of the actual status-priority question for both policies.\n\n\n **L247** Construct one shared nonempty articulation of the actual status-priority question for both policies.\n\n\n **L248** Fix identical selected candidate, audit, premises, question and false report; retain actual fact models and leave the difference in reason lists.\n\n\n **L249** Show the status-only policy completed that exact articulated audit with its mathematically accurate report.\n\n\n **L250** Supply the identical fulfilled audit for the output policy, leaving the two separate additional-choice-norm results.\n\n\n **L251** Compute that status-only and output-based priority reason lists are distinct despite their shared selected candidate and audit.\n\n\n **L252** Apply statusOnlyFails to the actual status policy’s priority reason, proving failure of AdditionalChoiceNorm.\n\n\n **L253** Use identityJustified for the output policy’s actual relevant output reason, proving its AdditionalChoiceNorm.\n\n\n **L255** Document the intended scope of generalGroundsNotChoice. The corresponding declaration concerns: Combines the factual non-entailment case with a separate policy-level countermodel to deriving the added choice norm from represented general assessment duties. This comment is explanatory, not a proof premise.\n\n\n **L256** Document the intended scope of generalGroundsNotChoice. The corresponding declaration concerns: Combines the factual non-entailment case with a separate policy-level countermodel to deriving the added choice norm from represented general assessment duties. This comment is explanatory, not a proof premise.\n\n\n **L257** State the checked result generalGroundsNotChoice. Combines the factual non-entailment case with a separate policy-level countermodel to deriving the added choice norm from represented general assessment duties.\n\n\n **L258** Retain the original articulated, accurately negative status assessment as part of the registered result.\n\n\n **L259** Keep the same actual status premises modeled by every candidate.\n\n\n **L260** Keep priority true for identity and false for successor.\n\n\n **L261** Keep the demonstrated status-to-priority non-entailment.\n\n\n **L262** Keep status-only choice failure, then join it to the stronger policy-independence example.\n\n\n **L263** Include actual policy variation through PolicyIndependenceExample, rather than ending at status non-entailment.\n\n\n **L264** Pair the preserved status non-entailment proof with policyIndependenceExample, thereby including actual independent priority-reason variation in the registered theorem.\n\n\n **L266** Close namespace CoreReader.Choice; this adds no proof or premise.\n\n\n### `leanified/CoreReader/Engineering/Domain.lean`\n\n\n```lean\nimport Std\n\nnamespace CoreReader.Engineering\n\n/- This is a bounded engineering application model. Work units count explicit\noperations; they are not a universal exchange rate or empirical forecast. -/\ninductive Maintainer where\n | original | successor | agent\n deriving DecidableEq, Repr\ninductive Tool where\n | editor | compiler | contractRunner | migrationRunner\n deriving DecidableEq, Repr\ninductive Knowledge where\n | privateLayout | publicContract | changeGuide | migrationGuide\n deriving DecidableEq, Repr\ninductive Change where\n | addition | replacement | deletion | withdrawal | redrawing | migration\n | independent | coordinated | designRevision | other (name : String)\n deriving DecidableEq, Repr\ninductive Candidate where\n | presentSimple | evolvable | maximal\n deriving DecidableEq, Repr\ninductive Burden where\n | understanding | construction | diagnosis | verification | coordination\n | operation | migration\n deriving DecidableEq, Repr\n\ndef maintainers : List Maintainer := [.original, .successor, .agent]\ndef changes : List Change := [.addition, .replacement, .deletion, .withdrawal,\n .redrawing, .migration, .independent, .coordinated, .designRevision]\ndef burdens : List Burden := [.understanding, .construction, .diagnosis,\n .verification, .coordination, .operation, .migration]\n\nstructure Activity where\n participants : List Maintainer\n software : String\n tools : List Tool\n available : Maintainer → List Knowledge\n scheduledReleases : Nat\n scheduledMaintenance : Nat\n boundedRuns : Option Nat\n label : String\n\n/-- organon-map CoreReader.Engineering.ActivityScope\nsoftware-engineering.purpose#p1 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.purpose#p2 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\n-/\nabbrev ActivityScope (a : Activity) : Prop :=\n a.participants ≠ [] ∧ a.software ≠ \"\" ∧ a.tools ≠ [] ∧\n a.participants.all (fun m => !(a.available m).isEmpty) = true\n\nabbrev Continuing (a : Activity) : Prop :=\n 0 < a.scheduledReleases ∧ 0 < a.scheduledMaintenance\n\nabbrev BoundedLifecycle (a : Activity) : Prop :=\n a.boundedRuns.isSome = true ∧ a.scheduledReleases = 0 ∧\n a.scheduledMaintenance = 0\n\ndef continuingActivity : Activity := {\n participants := maintainers, software := \"order-preserving queue\",\n tools := [.editor, .compiler, .contractRunner, .migrationRunner],\n available := fun m => match m with\n | .original => [.privateLayout, .publicContract, .changeGuide, .migrationGuide]\n | _ => [.publicContract, .changeGuide, .migrationGuide],\n scheduledReleases := 3, scheduledMaintenance := 6,\n boundedRuns := none, label := \"temporary\" }\n\ndef temporaryActivity : Activity := { continuingActivity with\n scheduledReleases := 0, scheduledMaintenance := 0, boundedRuns := some 1,\n label := \"one-shot import\" }\ndef prototypeActivity : Activity := { temporaryActivity with\n boundedRuns := some 4, label := \"bounded prototype\" }\ndef retiringActivity : Activity := { temporaryActivity with\n boundedRuns := some 2, label := \"retiring service\" }\n\nstructure EditStep where\n component : Nat\n requires : Knowledge\n tool : Tool\n units : Nat\n deriving DecidableEq, Repr\n\ndef changePath (c : Candidate) (d : Change) : List EditStep :=\n let guide := if c = .presentSimple then Knowledge.privateLayout else .changeGuide\n let base : List EditStep := [⟨0, guide, .editor, 1⟩,\n ⟨0, .publicContract, .contractRunner, 1⟩]\n match d with\n | .addition | .independent => base\n | .replacement | .deletion => base ++ [⟨1, guide, .compiler, 1⟩]\n | .coordinated => base ++ [⟨1, guide, .compiler, 3⟩, ⟨2, .publicContract, .contractRunner, 3⟩]\n | .migration => base ++ [⟨1, .migrationGuide, .migrationRunner, 8⟩]\n | .withdrawal | .redrawing | .designRevision =>\n if c = .presentSimple then base ++\n [⟨1, guide, .editor, 5⟩, ⟨2, guide, .compiler, 5⟩,\n ⟨2, .publicContract, .contractRunner, 5⟩]\n else base ++ [⟨1, guide, .editor, 2⟩, ⟨1, .publicContract, .contractRunner, 2⟩]\n | .other name =>\n if name = \"csv export\" then\n if c = .maximal then base ++ [⟨3, .migrationGuide, .compiler, 2⟩]\n else base ++ [⟨3, .privateLayout, .compiler, 20⟩]\n else []\n\ndef changeWork (c : Candidate) (d : Change) : Nat :=\n ((changePath c d).map EditStep.units).sum\n\nabbrev CanChange (a : Activity) (c : Candidate) (m : Maintainer) (d : Change) : Prop :=\n (changePath c d) ≠ [] ∧ m ∈ a.participants ∧ (changePath c d).all\n (fun step => (a.available m).contains step.requires && a.tools.contains step.tool) = true\n\nabbrev ContinuingCapability (a : Activity) (c : Candidate) (d : Change) : Prop :=\n (changePath c d) ≠ [] ∧ a.participants.all (fun m => (changePath c d).all\n (fun step => (a.available m).contains step.requires && a.tools.contains step.tool)) = true\n\n/- Maximal is maximal only on this explicitly registered finite set. The\nextra CSV direction has an actual documented compilation path and later state\ntransformation; unsupported names do not gain a capability from an empty path. -/\ndef registeredDirections : List Change := changes ++ [.other \"csv export\"]\ndef supportedDirections (a : Activity) (c : Candidate) : List Change :=\n registeredDirections.filter (fun d => decide (ContinuingCapability a c d))\nabbrev MaximumRegisteredCapability (a : Activity) (c : Candidate) : Prop :=\n registeredDirections.all (fun d => decide (ContinuingCapability a c d)) = true\n\n/- A software value here is a passive function: no intention is stored in it.\nAn engineering intention is an agent's selected set of changes. -/\ndef passiveArtifact (xs : List Nat) : List Nat := xs\n\ndef orientation : Maintainer → List Change := fun _ => [.designRevision, .migration]\n\ninductive EngineeringAction where\n | propose (direction : Change)\n | execute (result : List Nat)\n deriving DecidableEq, Repr\n\ndef maintainerActions (m : Maintainer) : List EngineeringAction :=\n (orientation m).map EngineeringAction.propose\n\ndef artifactActions (input : List Nat) : List EngineeringAction :=\n [.execute (passiveArtifact input)]\n\n/-- organon-map CoreReader.Engineering.subjectLifecycleCases\nsoftware-engineering.purpose#p1 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.purpose#p2 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\n-/\ntheorem subjectLifecycleCases :\n ActivityScope continuingActivity ∧\n CanChange continuingActivity .evolvable .successor .designRevision ∧\n CanChange continuingActivity .evolvable .agent .designRevision ∧\n continuingActivity.label = \"temporary\" ∧ Continuing continuingActivity ∧\n ¬ BoundedLifecycle continuingActivity ∧ BoundedLifecycle temporaryActivity ∧\n BoundedLifecycle prototypeActivity ∧ BoundedLifecycle retiringActivity := by decide\n\n/-- organon-map CoreReader.Engineering.subjectLimits\nsoftware-engineering.purpose#p1 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.purpose#p2 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\n-/\ntheorem subjectLimits :\n CanChange continuingActivity .presentSimple .original .designRevision ∧\n ¬ CanChange continuingActivity .presentSimple .successor .designRevision ∧\n ¬ ContinuingCapability continuingActivity .presentSimple .designRevision ∧\n continuingActivity.label = \"temporary\" ∧ ¬ BoundedLifecycle continuingActivity ∧\n orientation .agent ≠ [] ∧ passiveArtifact [2, 1] = [2, 1] ∧\n EngineeringAction.propose .designRevision ∈ maintainerActions .agent ∧\n EngineeringAction.propose .designRevision ∉ artifactActions [2, 1] := by decide\n\n/- Ground is intentionally parameterized: the examples below do not exhaust\npossible sources of credibility. The supplied support relation needs review. -/\n/-- organon-map CoreReader.Engineering.CredibleDirection\nsoftware-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\n-/\nabbrev CredibleDirection {Ground : Type} (grounds : List Ground)\n (articulated : Ground → Bool) (supports : Ground → Change → Bool)\n (d : Change) : Prop :=\n grounds.any (fun g => articulated g && supports g d) = true\n\ninductive DirectionGround where\n | plan (release : Nat) (committed : List Change)\n | knowledge (service : String) (affected : List Change) (mechanism : String)\n | history (service : String) (observed : List Change)\n | other (account : String) (supported : List Change)\n deriving DecidableEq, Repr\n\ndef articulateGround : DirectionGround → Bool\n | .plan release ds => release > 0 && !ds.isEmpty\n | .knowledge service ds mechanism => service != \"\" && !ds.isEmpty && mechanism != \"\"\n | .history service ds => service != \"\" && !ds.isEmpty\n | .other account ds => account != \"\" && !ds.isEmpty\n\ndef supportGround : DirectionGround → Change → Bool\n | .plan release ds, d => release > 0 && ds.contains d\n | .knowledge service ds mechanism, d =>\n service == \"queue\" && mechanism == \"tenant-config-reload\" && ds.contains d\n | .history service ds, d => service == \"queue\" && (ds.filter (· == d)).length >= 2\n | .other account ds, d => account == \"reviewed customer migration requirement\" && ds.contains d\n\nabbrev initialGrounds : List DirectionGround := [.plan 2 [.designRevision, .migration]]\ndef forecastGrounds : List DirectionGround := [.plan 3 [.deletion]]\nabbrev credible (gs : List DirectionGround) (d : Change) : Prop :=\n CredibleDirection gs articulateGround supportGround d\n\nabbrev WarrantedAccommodation (gs : List DirectionGround) (d : Change)\n (objectiveGain investment : Nat) : Prop :=\n credible gs d ∧ 0 < objectiveGain ∧ investment ≤ objectiveGain\n\n/-- organon-map CoreReader.Engineering.credibilityCases\nsoftware-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\n-/\ntheorem credibilityCases :\n credible initialGrounds .designRevision ∧\n credible [.knowledge \"queue\" [.designRevision] \"tenant-config-reload\"] .designRevision ∧\n credible [.history \"queue\" [.migration, .migration]] .migration ∧\n ¬ credible [] (.other \"quantum backend\") ∧\n credible forecastGrounds .deletion ∧ ¬ credible forecastGrounds .designRevision := by decide\n\ndef abstractionComplexity : Candidate → Nat\n | .presentSimple => 1 | .evolvable => 3 | .maximal => 30\n\ndef implementedVariants : List Candidate := [.presentSimple]\n\n/- No scalar conversion across burden dimensions is used by the priority rule. -/\nstructure CostVector where\n amount : Burden → Nat\nstructure CostLimits where\n capacity : Burden → Nat\n objective : Burden → String\n\ndef cost : Candidate → Burden → Nat\n | .presentSimple, _ => 1\n | .evolvable, .understanding => 3\n | .evolvable, .construction => 4\n | .evolvable, .diagnosis => 2\n | .evolvable, .verification => 4\n | .evolvable, .coordination => 2\n | .evolvable, .operation => 2\n | .evolvable, .migration => 8\n | .maximal, _ => 40\n\ndef normalLimits : CostLimits := {\n capacity := fun _ => 12,\n objective := fun b => match b with\n | .understanding => \"successor onboarding capacity\"\n | .construction => \"release construction capacity\"\n | .diagnosis => \"incident diagnosis window\"\n | .verification => \"release verification capacity\"\n | .coordination => \"available team coordination\"\n | .operation => \"runtime resource budget\"\n | .migration => \"retirement migration capacity\" }\n\nstructure Requirements where\n orderRequired : Bool\n maxUnsafeOperations : Nat\n maxLatency : Nat\n minRetention : Nat\n\ndef normalRequirements : Requirements := ⟨true, 0, 10, 30⟩\ndef behavior : Candidate → List Nat → List Nat := fun _ xs => xs.eraseDups\n\n/- Candidate profiles are observations in this bounded scenario. Modified\nprofiles below test all four independent necessary-requirement gates. -/\nstructure CandidateProfile where\n orderOutput : List Nat\n unsafeOperations : Nat\n latency : Nat\n retention : Nat\n\ndef profile (c : Candidate) : CandidateProfile := ⟨behavior c [2, 1, 2], 0, 5, 30⟩\nabbrev Meets (r : Requirements) (p : CandidateProfile) : Prop :=\n (r.orderRequired = true → p.orderOutput = [2, 1]) ∧\n p.unsafeOperations ≤ r.maxUnsafeOperations ∧ p.latency ≤ r.maxLatency ∧\n r.minRetention ≤ p.retention\n\nstructure Context where\n activity : Activity\n required : Requirements\n evidence : List DirectionGround\n limits : CostLimits\n departure : Option Burden\n profiles : Candidate → CandidateProfile := profile\n\ndef currentContinuing : Context := {\n activity := continuingActivity, required := normalRequirements,\n evidence := initialGrounds, limits := normalLimits, departure := none }\n\nabbrev ConcreteThreat (ctx : Context) (c : Candidate) (b : Burden) : Prop :=\n cost .presentSimple b < cost c b ∧ ctx.limits.capacity b < cost c b ∧\n ctx.limits.objective b ≠ \"\"\n\nabbrev HasThreat (ctx : Context) (c : Candidate) : Prop :=\n burdens.any (fun b => decide (ConcreteThreat ctx c b)) = true\n\n/-- organon-map CoreReader.Engineering.JustifiedDeparture\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\n-/\nabbrev JustifiedDeparture (ctx : Context) (c : Candidate) : Prop :=\n match ctx.departure with\n | none => False\n | some b => ConcreteThreat ctx c b\n\ninstance (ctx : Context) (c : Candidate) : Decidable (JustifiedDeparture ctx c) := by\n unfold JustifiedDeparture\n split <;> infer_instance\n\nabbrev PriorityConditions (ctx : Context) : Prop :=\n Continuing ctx.activity ∧ ActivityScope ctx.activity ∧\n Meets ctx.required (ctx.profiles .presentSimple) ∧ Meets ctx.required (ctx.profiles .evolvable) ∧\n credible ctx.evidence .designRevision ∧\n ContinuingCapability ctx.activity .evolvable .designRevision ∧\n changeWork .evolvable .designRevision < changeWork .presentSimple .designRevision ∧\n abstractionComplexity .presentSimple < abstractionComplexity .evolvable\n\n/-- organon-map CoreReader.Engineering.EvolutionPriority\nsoftware-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\n-/\nabbrev EvolutionPriority (ctx : Context) (chosen : Candidate) : Prop :=\n PriorityConditions ctx → chosen = .evolvable ∨ JustifiedDeparture ctx .evolvable\n\ntheorem currentPriorityConditions : PriorityConditions currentContinuing := by decide\ntheorem currentNoThreat : ¬ HasThreat currentContinuing .evolvable ∧\n ¬ JustifiedDeparture currentContinuing .evolvable := by decide\n\ndef threatened (b : Burden) : Context := { currentContinuing with\n limits := { normalLimits with capacity := fun x => if x = b then 1 else 12 },\n departure := some b }\n\n/-- organon-map CoreReader.Engineering.priorityWhenApplicable\nsoftware-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\n-/\ntheorem priorityWhenApplicable (ctx : Context) (chosen : Candidate)\n (rule : EvolutionPriority ctx chosen) (applicable : PriorityConditions ctx)\n (noDeparture : ¬ JustifiedDeparture ctx .evolvable) :\n chosen = .evolvable ∧\n abstractionComplexity .presentSimple < abstractionComplexity chosen := by\n have hc := (rule applicable).resolve_right noDeparture\n exact ⟨hc, hc ▸ applicable.2.2.2.2.2.2.2⟩\n\ntheorem currentSimpleViolates : ¬ EvolutionPriority currentContinuing .presentSimple := by\n intro h\n have bad := (h currentPriorityConditions).resolve_right currentNoThreat.2\n cases bad\n\ndef withEvolvableProfile (p : CandidateProfile) : Context := { currentContinuing with\n profiles := fun c => if c = .evolvable then p else profile c }\n\ntheorem unmetRequirementsBlockPriority :\n ¬ PriorityConditions (withEvolvableProfile { profile .evolvable with orderOutput := [1, 2] }) ∧\n ¬ PriorityConditions (withEvolvableProfile { profile .evolvable with unsafeOperations := 1 }) ∧\n ¬ PriorityConditions (withEvolvableProfile { profile .evolvable with latency := 11 }) ∧\n ¬ PriorityConditions (withEvolvableProfile { profile .evolvable with retention := 29 }) := by\n simp [PriorityConditions, withEvolvableProfile, currentContinuing, Meets,\n normalRequirements]\n\n/-- organon-map CoreReader.Engineering.priorityConditionsCases\nsoftware-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\n-/\ntheorem priorityConditionsCases :\n EvolutionPriority currentContinuing .evolvable ∧\n ¬ Meets normalRequirements { profile .evolvable with orderOutput := [1, 2] } ∧\n ¬ Meets normalRequirements { profile .evolvable with unsafeOperations := 1 } ∧\n ¬ Meets normalRequirements { profile .evolvable with latency := 11 } ∧\n ¬ Meets normalRequirements { profile .evolvable with retention := 29 } ∧\n EvolutionPriority (threatened .verification) .presentSimple ∧\n ¬ JustifiedDeparture { threatened .verification with departure := none } .evolvable ∧\n abstractionComplexity .evolvable < abstractionComplexity .maximal := by\n refine ⟨by decide, by decide, by decide, by decide, by decide, by decide, ?_, by decide⟩\n simp [JustifiedDeparture]\n\n/-- organon-map CoreReader.Engineering.priorityChoices\nsoftware-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\n-/\ntheorem priorityChoices :\n EvolutionPriority currentContinuing .evolvable ∧\n ¬ EvolutionPriority currentContinuing .presentSimple ∧\n EvolutionPriority (threatened .verification) .presentSimple := by\n exact ⟨by decide, currentSimpleViolates, by decide⟩\n\n/-- organon-map CoreReader.Engineering.credibilityLimits\nsoftware-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\n-/\ntheorem credibilityLimits :\n credible initialGrounds .designRevision ∧ implementedVariants.length = 1 ∧\n ¬ WarrantedAccommodation [] (.other \"quantum backend\") 0 5 ∧\n ¬ credible initialGrounds (.other \"quantum backend\") ∧\n EvolutionPriority currentContinuing .evolvable ∧\n abstractionComplexity .evolvable < abstractionComplexity .maximal ∧\n cost .evolvable .construction < cost .evolvable .migration ∧\n ¬ MaximumRegisteredCapability continuingActivity .evolvable ∧\n MaximumRegisteredCapability continuingActivity .maximal ∧\n (supportedDirections continuingActivity .evolvable).length = 9 ∧\n (supportedDirections continuingActivity .maximal).length = 10 ∧\n ¬ credible initialGrounds (.other \"csv export\") := by decide\n\n/-- organon-map CoreReader.Engineering.costCases\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\n-/\ntheorem costCases :\n JustifiedDeparture (threatened .understanding) .evolvable ∧\n JustifiedDeparture (threatened .construction) .evolvable ∧\n JustifiedDeparture (threatened .diagnosis) .evolvable ∧\n JustifiedDeparture (threatened .verification) .evolvable ∧\n JustifiedDeparture (threatened .coordination) .evolvable ∧\n JustifiedDeparture (threatened .operation) .evolvable ∧\n JustifiedDeparture (threatened .migration) .evolvable ∧\n ¬ JustifiedDeparture { currentContinuing with departure := some .migration } .evolvable := by decide\n\n/- Total functions model an identified order-preserving de-duplication API.\nThe test corpus is explicitly finite; universal preservation is separate. -/\ndef orderedUnique (xs : List Nat) : List Nat := xs.eraseDups\ndef orderedRefactor (xs : List Nat) : List Nat := xs.eraseDups ++ []\ndef insertOrdered (n : Nat) : List Nat → List Nat\n | [] => [n]\n | x :: xs => if n ≤ x then n :: x :: xs else x :: insertOrdered n xs\n\ndef sortValues : List Nat → List Nat\n | [] => []\n | x :: xs => insertOrdered x (sortValues xs)\n\ndef sortedUnique (xs : List Nat) : List Nat := (sortValues xs).eraseDups\n\nstructure SoftwareState where\n capabilities : List String\n implementation : Nat\n mechanisms : List String\n abstractions : List String\n boundary : Nat\n technology : String\n batchSize : Nat\n deriving DecidableEq, Repr\n\ndef originalSoftware : SoftwareState :=\n ⟨[\"deduplicate\"], 0, [\"queue\", \"legacy cache\"], [\"fixed batch\"], 0, \"legacy store\", 10⟩\n\ndef transform (d : Change) (s : SoftwareState) : SoftwareState := match d with\n | .addition => { s with capabilities := s.capabilities ++ [\"tenant batching\"] }\n | .replacement => { s with implementation := s.implementation + 1 }\n | .deletion => { s with mechanisms := s.mechanisms.filter (· != \"legacy cache\") }\n | .withdrawal => { s with abstractions := s.abstractions.filter (· != \"fixed batch\") }\n | .redrawing => { s with boundary := s.boundary + 1 }\n | .migration => { s with technology := \"portable store\" }\n | .independent => { s with batchSize := 5 }\n | .coordinated => { s with batchSize := 5, boundary := s.boundary + 1 }\n | .designRevision => { s with batchSize := 5, abstractions := [\"live configuration\"], boundary := s.boundary + 1 }\n | .other name =>\n if name = \"csv export\" then { s with capabilities := s.capabilities ++ [\"csv export\"] }\n else s\n\ndef evolutionBehavior (d : Change) : List Nat → List Nat :=\n if d = .redrawing ∨ d = .designRevision then sortedUnique else orderedUnique\n\n/- Changes include an open other constructor. Work, maintainer knowledge and\nobligation treatment are separate dimensions, not one extensibility score. -/\ninductive ObligationTreatment where\n | preserve | revise\n deriving DecidableEq, Repr\nstructure ChangeClaim where\n direction : Change\n byMaintainer : Maintainer\n treatment : ObligationTreatment\n\nabbrev contractInputs : List (List Nat) := [[], [2, 1, 2], [1, 3, 1], [4, 4]]\ndef PreservesOn {Input Output : Type} (scope : Input → Prop)\n (old new : Input → Output) : Prop := ∀ x, scope x → new x = old x\n\nabbrev PreservesFinite (old new : List Nat → List Nat) : Prop :=\n contractInputs.all (fun xs => new xs == old xs) = true\n\n/- The actual contracts and observer dependencies are inputs independent of\nany revision report. Reports cannot redefine the affected population or the\nold/new retry behavior merely by changing their own fields. -/\nstructure ObservableContract where\n order : List Nat → List Nat\n maxAttempts : Nat\n\ndef retry (contract : ObservableContract) (attempts : Nat) : Bool :=\n attempts < contract.maxAttempts\n\ndef orderContract (order : List Nat → List Nat) : ObservableContract := ⟨order, 3⟩\ndef originalContract : ObservableContract := orderContract orderedUnique\ndef refactoredContract : ObservableContract := orderContract orderedRefactor\ndef revisedContract : ObservableContract := ⟨sortedUnique, 5⟩\ndef evolutionContract (d : Change) : ObservableContract :=\n ⟨evolutionBehavior d, if d = .redrawing ∨ d = .designRevision then 5 else 3⟩\n\ndef failureInputs : List Nat := [0, 1, 2, 3, 4, 5]\nabbrev PreservesContractFinite (old new : ObservableContract) : Prop :=\n PreservesFinite old.order new.order ∧\n failureInputs.all (fun attempts => retry new attempts == retry old attempts) = true\n\ninductive ContractAspect where\n | order | retry\n deriving DecidableEq, Repr\nstructure PartyDependency where\n party : String\n observes : ContractAspect\n deriving DecidableEq, Repr\n\ndef partyDependencies : List PartyDependency :=\n [⟨\"queue consumer\", .order⟩, ⟨\"queue operator\", .retry⟩]\n\ndef aspectChanged (old new : ObservableContract) : ContractAspect → Bool\n | .order => contractInputs.any (fun xs => new.order xs != old.order xs)\n | .retry => failureInputs.any (fun attempts => retry new attempts != retry old attempts)\n\ndef affectedParties (old new : ObservableContract) : List String :=\n (partyDependencies.filter (fun dependency => aspectChanged old new dependency.observes)).map\n PartyDependency.party\n\nstructure ContractRevision where\n deliberate : Bool\n revisedOrder : List Nat\n affected : List String\n oldFailureLimit : Nat\n newFailureLimit : Nat\n recordedOldFailureLimit : Nat\n recordedNewFailureLimit : Nat\n procedure : String\n\ndef normalRevision : ContractRevision := {\n deliberate := true, revisedOrder := [1, 2],\n affected := [\"queue consumer\", \"queue operator\"],\n oldFailureLimit := 3, newFailureLimit := 5,\n recordedOldFailureLimit := 3, recordedNewFailureLimit := 5,\n procedure := \"contract review\" }\n\nabbrev RevisionDuties (old new : ObservableContract) (r : ContractRevision) : Prop :=\n r.deliberate = true ∧ r.revisedOrder = new.order [2, 1, 2] ∧\n (affectedParties old new).all (fun p => r.affected.contains p) = true ∧\n r.oldFailureLimit = old.maxAttempts ∧ r.newFailureLimit = new.maxAttempts ∧\n r.recordedOldFailureLimit = old.maxAttempts ∧\n r.recordedNewFailureLimit = new.maxAttempts\n\n/-- organon-map CoreReader.Engineering.ContractChangeAccount\nsoftware-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\n-/\nabbrev ContractChangeAccount (old new : ObservableContract) (r : ContractRevision) : Prop :=\n PreservesContractFinite old new ∨ RevisionDuties old new r\n\n/-- organon-map CoreReader.Engineering.EvolutionClaim\nsoftware-engineering.evolution-meaning#p1 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6\nsoftware-engineering.evolution-meaning#p2 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6\n-/\nabbrev EvolutionClaim (a : Activity) (c : Candidate) (claim : ChangeClaim) : Prop :=\n CanChange a c claim.byMaintainer claim.direction ∧\n ContractChangeAccount originalContract (evolutionContract claim.direction) normalRevision ∧\n (changePath c claim.direction).any (fun step => step.tool == .contractRunner) = true ∧\n ((claim.treatment = .preserve ∧\n evolutionBehavior claim.direction [2, 1, 2] = orderedUnique [2, 1, 2]) ∨\n (claim.treatment = .revise ∧\n evolutionBehavior claim.direction [2, 1, 2] ≠ orderedUnique [2, 1, 2]))\n\n/-- organon-map CoreReader.Engineering.evolutionKindsCases\nsoftware-engineering.evolution-meaning#p1 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6\nsoftware-engineering.evolution-meaning#p2 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6\n-/\ntheorem evolutionKindsCases :\n (transform .addition originalSoftware).capabilities = [\"deduplicate\", \"tenant batching\"] ∧\n (transform .replacement originalSoftware).implementation = 1 ∧\n (transform .deletion originalSoftware).mechanisms = [\"queue\"] ∧\n (transform .withdrawal originalSoftware).abstractions = [] ∧\n (transform .redrawing originalSoftware).boundary = 1 ∧\n (transform .migration originalSoftware).technology = \"portable store\" ∧\n changes.all (fun d => decide (CanChange continuingActivity .evolvable .successor d)) = true ∧\n EvolutionClaim continuingActivity .evolvable ⟨.replacement, .successor, .preserve⟩ ∧\n EvolutionClaim continuingActivity .evolvable ⟨.redrawing, .agent, .revise⟩ ∧\n changeWork .evolvable .independent < changeWork .evolvable .coordinated := by decide\n\n/-- organon-map CoreReader.Engineering.evolutionDimensionsLimits\nsoftware-engineering.evolution-meaning#p1 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6\nsoftware-engineering.evolution-meaning#p2 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6\n-/\ntheorem evolutionDimensionsLimits :\n changeWork .presentSimple .addition = 2 ∧\n changeWork .presentSimple .withdrawal = 17 ∧\n changeWork .evolvable .independent < changeWork .evolvable .coordinated ∧\n EvolutionPriority currentContinuing .evolvable ∧\n 9 < changeWork .evolvable .migration ∧\n CanChange continuingActivity .presentSimple .original .addition ∧\n CanChange continuingActivity .evolvable .original .addition ∧\n CanChange continuingActivity .presentSimple .original .designRevision ∧\n CanChange continuingActivity .evolvable .original .designRevision ∧\n changeWork .evolvable .designRevision < changeWork .presentSimple .designRevision ∧\n changeWork .evolvable .addition = changeWork .presentSimple .addition ∧\n (transform (.other \"csv export\") originalSoftware).capabilities = [\"deduplicate\", \"csv export\"] ∧\n CanChange continuingActivity .maximal .successor (.other \"csv export\") ∧\n ¬ CanChange continuingActivity .evolvable .successor (.other \"csv export\") := by\n exact ⟨by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide⟩\n\ntheorem oneDimensionDoesNotEntailEveryDimension :\n changeWork .evolvable .designRevision < changeWork .presentSimple .designRevision ∧\n ¬ (∀ d : Change, changeWork .evolvable d < changeWork .presentSimple d) := by\n refine ⟨by decide, ?_⟩\n intro allDirections\n exact (by decide : ¬ changeWork .evolvable .addition < changeWork .presentSimple .addition)\n (allDirections .addition)\n\ndef propagation (c : Candidate) (d : Change) : List Nat :=\n ((changePath c d).map EditStep.component).eraseDups\n\ndef batchCount (items size : Nat) : Nat := (items + size - 1) / size\ndef staticBatch (items _runtimeSize : Nat) : Nat := batchCount items 10\ndef liveBatch (items runtimeSize : Nat) : Nat := batchCount items runtimeSize\n\nstructure StructuralEvidence where\n intended : Change\n participants : List Maintainer\n touched : List Nat\n contractObservations : List (List Nat)\n observedBefore : List (List Nat)\n observedAfter : List (List Nat)\n understandingWork : Nat\n verificationWork : Nat\n boundaryGain : Nat\n\ndef structuralEvidence (c : Candidate) (d : Change) : StructuralEvidence := {\n intended := d, participants := maintainers, touched := propagation c d,\n contractObservations := contractInputs,\n observedBefore := contractInputs.map orderedUnique,\n observedAfter := contractInputs.map (evolutionBehavior d),\n understandingWork := changeWork c d,\n verificationWork := ((changePath c d).filter (fun step => step.tool == .contractRunner)).length,\n boundaryGain := changeWork .presentSimple d - changeWork c d }\n\n/-- organon-map CoreReader.Engineering.StructuralAccount\nsoftware-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\nsoftware-engineering.structural-judgment#p2 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\n-/\nabbrev StructuralAccount (a : Activity) (c : Candidate) (e : StructuralEvidence) : Prop :=\n e.participants = a.participants ∧ e.touched = propagation c e.intended ∧\n e.contractObservations = contractInputs ∧\n e.observedBefore = contractInputs.map orderedUnique ∧\n e.observedAfter = contractInputs.map (evolutionBehavior e.intended) ∧\n e.understandingWork = changeWork c e.intended ∧\n e.verificationWork = ((changePath c e.intended).filter\n (fun step => step.tool == .contractRunner)).length ∧\n e.boundaryGain = changeWork .presentSimple e.intended - changeWork c e.intended\n\nstructure InterfaceView where\n signature : String\n modules : Nat\n extensionPoints : Nat\n principle : String\n deriving DecidableEq, Repr\n\ndef sameShape : InterfaceView := ⟨\"List Nat → List Nat\", 8, 12, \"dependency inversion\"⟩\ndef moduleAssumptions : List (Nat × Nat) :=\n (List.range 8).map (fun component => (component, 10))\n\ndef modulesNeedingRevision (newSize : Nat) : List Nat :=\n (moduleAssumptions.filter (fun p => p.2 != newSize)).map Prod.fst\n\nstructure Boundary where\n caller : Nat\n callee : Nat\n contract : String\n deriving DecidableEq, Repr\n\nstructure EngineeringDesign where\n metadata : InterfaceView\n run : List Nat → List Nat\n paths : Change → List EditStep\n components : List Nat\n boundaries : List Boundary\n batchAssumptions : List (Nat × Nat)\n\ndef privateDesign : EngineeringDesign := {\n metadata := sameShape, run := orderedUnique, paths := changePath .presentSimple,\n components := List.range 8, boundaries := [], batchAssumptions := moduleAssumptions }\n\ndef documentedDesign : EngineeringDesign := {\n privateDesign with paths := changePath .evolvable }\n\ndef sortedDesign : EngineeringDesign := { documentedDesign with run := sortedUnique }\n\n/- This application has a caller at component 2 and a callee at component 1.\nEditing the callee crosses that actual edge. The caller must recheck the\nobservable order contract in this finite case; the contract name alone is not\nevidence that either the verification work or the observable equality holds. -/\ndef coordinatedBoundary : Boundary := ⟨2, 1, \"order-preserving queue\"⟩\n\ndef boundaryDesign : EngineeringDesign :=\n { documentedDesign with boundaries := [coordinatedBoundary] }\n\ndef crossesBoundary (design : EngineeringDesign) (direction : Change) (edge : Boundary) : Bool :=\n design.boundaries.contains edge && design.components.contains edge.caller &&\n design.components.contains edge.callee && edge.caller != edge.callee &&\n (design.paths direction).any (fun step => step.component == edge.callee &&\n (step.tool == .editor || step.tool == .compiler))\n\ndef boundaryObligationChecked (design : EngineeringDesign) (direction : Change)\n (edge : Boundary) : Bool :=\n crossesBoundary design direction edge &&\n (design.paths direction).any (fun step => step.component == edge.caller &&\n step.tool == .contractRunner && step.requires == .publicContract) &&\n decide (PreservesFinite orderedUnique design.run)\n\ndef omittedCallerCheck : EngineeringDesign :=\n { boundaryDesign with paths := fun direction =>\n (boundaryDesign.paths direction).filter (fun step =>\n !(step.component == coordinatedBoundary.caller && step.tool == .contractRunner)) }\n\ndef otherCalleeBoundary : Boundary := { coordinatedBoundary with callee := 7 }\n\ndef otherCalleeDesign : EngineeringDesign :=\n { boundaryDesign with boundaries := [otherCalleeBoundary] }\n\ntheorem actualCrossBoundaryObligation :\n crossesBoundary boundaryDesign .coordinated coordinatedBoundary = true ∧\n boundaryObligationChecked boundaryDesign .coordinated coordinatedBoundary = true ∧\n crossesBoundary omittedCallerCheck .coordinated coordinatedBoundary = true ∧\n boundaryObligationChecked omittedCallerCheck .coordinated coordinatedBoundary = false ∧\n crossesBoundary otherCalleeDesign .coordinated otherCalleeBoundary = false ∧\n boundaryObligationChecked { boundaryDesign with run := sortedUnique }\n .coordinated coordinatedBoundary = false := by decide\n\n/-- organon-map CoreReader.Engineering.structuralCases\nsoftware-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\nsoftware-engineering.structural-judgment#p2 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\n-/\ntheorem structuralCases :\n StructuralAccount continuingActivity .evolvable (structuralEvidence .evolvable .designRevision) ∧\n (propagation .presentSimple .designRevision).length = 3 ∧\n (propagation .evolvable .designRevision).length = 2 ∧\n (changePath .evolvable .coordinated).any (fun s => s.component == 2 && s.requires == .publicContract) = true ∧\n PreservesFinite orderedUnique orderedRefactor ∧\n (structuralEvidence .evolvable .designRevision).observedBefore ≠\n (structuralEvidence .evolvable .designRevision).observedAfter ∧\n staticBatch 21 10 = liveBatch 21 10 ∧ staticBatch 21 5 ≠ liveBatch 21 5 ∧\n changeWork .presentSimple .withdrawal = 17 ∧\n (crossesBoundary boundaryDesign .coordinated coordinatedBoundary = true ∧\n boundaryObligationChecked boundaryDesign .coordinated coordinatedBoundary = true ∧\n crossesBoundary omittedCallerCheck .coordinated coordinatedBoundary = true ∧\n boundaryObligationChecked omittedCallerCheck .coordinated coordinatedBoundary = false ∧\n crossesBoundary otherCalleeDesign .coordinated otherCalleeBoundary = false ∧\n boundaryObligationChecked { boundaryDesign with run := sortedUnique }\n .coordinated coordinatedBoundary = false) := by decide\n\nabbrev DesignCanChange (a : Activity) (design : EngineeringDesign)\n (m : Maintainer) (d : Change) : Prop :=\n design.paths d ≠ [] ∧ m ∈ a.participants ∧\n (design.paths d).all (fun step =>\n (a.available m).contains step.requires && a.tools.contains step.tool) = true\n\ndef designWork (design : EngineeringDesign) (d : Change) : Nat :=\n ((design.paths d).map EditStep.units).sum\n\ndef designModulesNeedingRevision (design : EngineeringDesign) (newSize : Nat) : List Nat :=\n (design.batchAssumptions.filter (fun p => p.2 != newSize)).map Prod.fst\n\n/- In this finite model, a facade adds an actual component, forwarding edge\nand contract verification step. It preserves observable order but does not\nremove the original edit/compilation work or supply private maintainer knowledge. -/\ndef introduceBoundary (design : EngineeringDesign) : EngineeringDesign := {\n metadata := { design.metadata with modules := design.metadata.modules + 1, extensionPoints := design.metadata.extensionPoints + 1 },\n run := fun xs => design.run (xs ++ []),\n paths := fun d => if (design.paths d).isEmpty then [] else\n design.paths d ++ [⟨design.components.length, .publicContract, .contractRunner, 1⟩],\n components := design.components ++ [design.components.length],\n boundaries := design.boundaries ++\n [⟨design.components.length, 0, design.metadata.signature⟩],\n batchAssumptions := design.batchAssumptions }\n\ndef wrappedDesign : EngineeringDesign := introduceBoundary privateDesign\n\n/- This second facade relocates the existing contract-verification work to\nthe new component. It changes the actual boundary and step locations without\nreducing the work or making the private edit knowledge public. -/\ndef relocateVerification (design : EngineeringDesign) : EngineeringDesign := {\n introduceBoundary design with\n paths := fun d => (design.paths d).map (fun step =>\n if step.tool = .contractRunner then { step with component := design.components.length }\n else step) }\n\ndef sameWorkDesign : EngineeringDesign := relocateVerification privateDesign\n\n/-- organon-map CoreReader.Engineering.structureNotCapability\nsoftware-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\nsoftware-engineering.structural-judgment#p2 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\n-/\ntheorem structureNotCapability :\n (privateDesign.metadata.signature = sortedDesign.metadata.signature ∧\n privateDesign.run [2, 1, 2] = [2, 1] ∧ sortedDesign.run [2, 1, 2] ≠ [2, 1]) ∧\n (privateDesign.metadata.modules = privateDesign.components.length ∧\n privateDesign.batchAssumptions.length = 8 ∧\n (designModulesNeedingRevision privateDesign 5).length = 8) ∧\n (privateDesign.metadata.principle = \"dependency inversion\" ∧\n privateDesign.metadata = documentedDesign.metadata ∧\n ¬ DesignCanChange continuingActivity privateDesign .successor .designRevision ∧\n DesignCanChange continuingActivity documentedDesign .successor .designRevision) ∧\n (privateDesign.boundaries.length = 0 ∧ wrappedDesign.boundaries.length = 1 ∧\n wrappedDesign.components.length = 9 ∧\n wrappedDesign.boundaries = [⟨8, 0, \"List Nat → List Nat\"⟩] ∧\n wrappedDesign.run [2, 1, 2] = privateDesign.run [2, 1, 2] ∧\n designWork privateDesign .designRevision = 17 ∧\n designWork wrappedDesign .designRevision = 18 ∧\n ¬ designWork wrappedDesign .designRevision < designWork privateDesign .designRevision) ∧\n (sameWorkDesign.boundaries = [⟨8, 0, \"List Nat → List Nat\"⟩] ∧\n sameWorkDesign.components.length = 9 ∧\n sameWorkDesign.paths .designRevision ≠ privateDesign.paths .designRevision ∧\n sameWorkDesign.run [2, 1, 2] = privateDesign.run [2, 1, 2] ∧\n designWork sameWorkDesign .designRevision = designWork privateDesign .designRevision ∧\n designWork sameWorkDesign .designRevision = 17 ∧\n ¬ DesignCanChange continuingActivity sameWorkDesign .successor .designRevision) := by\n exact ⟨by decide, by decide, by decide, by decide, by decide⟩\n\n/-- organon-map CoreReader.Engineering.contractPreservation\nsoftware-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\n-/\ntheorem contractPreservation {Input Output : Type} (scope : Input → Prop)\n (old new : Input → Output) (observations : ∀ x, scope x → new x = old x) :\n PreservesOn scope old new := observations\n\ntheorem changedObservationNotPreserved {Input Output : Type} (scope : Input → Prop)\n (old new : Input → Output) (x : Input) (inside : scope x)\n (different : new x ≠ old x) : ¬ PreservesOn scope old new := by\n intro h\n exact different (h x inside)\n\ntheorem contractRevisionObligations (old new : ObservableContract)\n (r : ContractRevision) (account : ContractChangeAccount old new r)\n (changed : ¬ PreservesContractFinite old new) :\n RevisionDuties old new r := account.resolve_left changed\n\ndef retiredBehavior (xs : List Nat) : List Nat :=\n if xs = [99] then [] else orderedUnique xs\n\n/-- organon-map CoreReader.Engineering.contractCases\nsoftware-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\n-/\ntheorem contractCases :\n ContractChangeAccount originalContract refactoredContract normalRevision ∧\n ContractChangeAccount originalContract revisedContract normalRevision ∧\n ¬ ContractChangeAccount originalContract revisedContract { normalRevision with affected := [] } ∧\n PreservesFinite orderedUnique retiredBehavior ∧ retiredBehavior [99] ≠ orderedUnique [99] ∧\n ContractChangeAccount originalContract revisedContract { normalRevision with procedure := \"paired audit\" } := by decide\n\n/-- organon-map CoreReader.Engineering.contractDistinctions\nsoftware-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\n-/\ntheorem contractDistinctions :\n PreservesFinite orderedUnique orderedRefactor ∧\n ¬ PreservesFinite orderedUnique sortedUnique ∧\n retry originalContract 3 = false ∧ retry revisedContract 3 = true ∧\n ¬ PreservesContractFinite originalContract revisedContract ∧\n affectedParties originalContract revisedContract = [\"queue consumer\", \"queue operator\"] ∧\n ¬ ContractChangeAccount originalContract revisedContract\n { normalRevision with affected := [\"queue consumer\"] } ∧\n ¬ ContractChangeAccount originalContract revisedContract\n { normalRevision with oldFailureLimit := 5, recordedOldFailureLimit := 5 } ∧\n ContractChangeAccount originalContract revisedContract normalRevision ∧\n PreservesFinite orderedUnique retiredBehavior ∧ retiredBehavior [99] ≠ orderedUnique [99] := by decide\n\n/- Revision records time-indexed evidence rather than changing a past event.\nJudgment is choice under current evidence; forecast truth is a separate value. -/\nstructure RevisionState where\n time : Nat\n forecast : List Change\n maintenance : Nat\n maintainers : List Maintainer\n migrationCost : Nat\n objectiveCapacity : Nat\n choice : Candidate\n deriving DecidableEq, Repr\nstructure RevisionRecord where\n software : String\n old : RevisionState\n current : RevisionState\n recordedOld : RevisionState\n recordedCurrent : RevisionState\n predictedBatchCount : Nat\n actualBatchCount : Nat\n reportedPredictionSucceeded : Bool\n consideredChanges : List Change\n criticizedDirections : List Change\n\nabbrev MaterialGroundsChanged (old current : RevisionState) : Prop :=\n old.forecast ≠ current.forecast ∨ old.maintenance ≠ current.maintenance ∨\n old.maintainers ≠ current.maintainers ∨\n old.migrationCost ≠ current.migrationCost ∨ old.objectiveCapacity ≠ current.objectiveCapacity\n\ndef oldState : RevisionState := ⟨0, [.designRevision], 6, [.original], 8, 12, .evolvable⟩\ndef newState : RevisionState := ⟨1, [.deletion], 2, [.successor, .agent], 14, 10, .presentSimple⟩\n\nstructure HistoricalEvidence where\n software : String\n state : RevisionState\n predictedBatchCount : Nat\n actualBatchCount : Nat\n\n/- Independent event content: the recorded predictor used a fixed batch size\nof ten; the actual event had runtime size five and twenty-one queue items. -/\ndef observedHistory : HistoricalEvidence :=\n ⟨\"order-preserving queue\", oldState, staticBatch 21 5, liveBatch 21 5⟩\n\nabbrev RevisionAccountAgainst (history : HistoricalEvidence) (r : RevisionRecord) : Prop :=\n r.software = history.software ∧\n r.old = history.state ∧ r.recordedOld = history.state ∧\n r.predictedBatchCount = history.predictedBatchCount ∧\n r.actualBatchCount = history.actualBatchCount ∧\n r.old.time < r.current.time ∧ r.recordedCurrent = r.current ∧\n (r.old.choice ≠ r.current.choice → MaterialGroundsChanged r.old r.current) ∧\n r.reportedPredictionSucceeded = decide (history.predictedBatchCount = history.actualBatchCount) ∧\n r.consideredChanges.all (fun d => r.criticizedDirections.contains d) = true\n\n/-- organon-map CoreReader.Engineering.RevisionAccount\nsoftware-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99\nsoftware-engineering.revision#p1 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99\n-/\nabbrev RevisionAccount (r : RevisionRecord) : Prop := RevisionAccountAgainst observedHistory r\n\ntheorem failedHistoryNotRewritten (history : HistoricalEvidence) (r : RevisionRecord)\n (account : RevisionAccountAgainst history r)\n (failed : history.predictedBatchCount ≠ history.actualBatchCount) :\n r.reportedPredictionSucceeded = false := by\n simpa [failed] using account.2.2.2.2.2.2.2.2.1\n\ndef revisionRecord : RevisionRecord := {\n software := \"order-preserving queue\",\n old := oldState, current := newState, recordedOld := oldState, recordedCurrent := newState,\n predictedBatchCount := staticBatch 21 5, actualBatchCount := liveBatch 21 5,\n reportedPredictionSucceeded := false,\n consideredChanges := changes, criticizedDirections := changes }\n\nabbrev SupportedAlternative (gs : List DirectionGround) (d : Change) : Prop := credible gs d\n\nabbrev RetentionJustified (ctx : Context) (alternatives : List Change) : Prop :=\n alternatives.all (fun d => !decide (SupportedAlternative ctx.evidence d)) = true ∨\n JustifiedDeparture ctx .evolvable\n\ndef stableRecord : RevisionRecord := { revisionRecord with\n current := { newState with choice := .evolvable },\n recordedCurrent := { newState with choice := .evolvable } }\n\n/-- organon-map CoreReader.Engineering.revisionCases\nsoftware-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99\nsoftware-engineering.revision#p1 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99\n-/\ntheorem revisionCases :\n RevisionAccount revisionRecord ∧\n revisionRecord.old.forecast ≠ revisionRecord.current.forecast ∧\n revisionRecord.old.maintenance ≠ revisionRecord.current.maintenance ∧\n revisionRecord.old.maintainers ≠ revisionRecord.current.maintainers ∧\n revisionRecord.old.migrationCost ≠ revisionRecord.current.migrationCost ∧\n revisionRecord.old.objectiveCapacity ≠ revisionRecord.current.objectiveCapacity ∧\n revisionRecord.predictedBatchCount ≠ revisionRecord.actualBatchCount ∧\n RetentionJustified currentContinuing [.other \"quantum backend\"] ∧\n RetentionJustified (threatened .migration) [.migration] := by decide\n\ndef observations : List (Nat × Nat) := [(21, 10), (30, 10), (40, 10)]\ndef revisionsMade : List Nat := [1, 2, 3]\ndef agreedBatch (reviewers : List Maintainer) (items size : Nat) : List Nat :=\n reviewers.map (fun _ => staticBatch items size)\n\ndef rewrittenOldRecord : RevisionRecord := { revisionRecord with\n old := { oldState with forecast := [.deletion] },\n recordedOld := { oldState with forecast := [.deletion] } }\n\ndef rewrittenPredictionRecord : RevisionRecord := { revisionRecord with\n predictedBatchCount := 5, reportedPredictionSucceeded := true }\n\ndef rewrittenObservationRecord : RevisionRecord := { revisionRecord with\n actualBatchCount := 3, reportedPredictionSucceeded := true }\n\ndef unrelatedSoftwareRecord : RevisionRecord := {\n revisionRecord with software := \"unrelated batch processor\" }\n\ntheorem historicalTamperingRejected :\n RevisionAccount revisionRecord ∧\n ¬ RevisionAccount rewrittenOldRecord ∧\n ¬ RevisionAccount rewrittenPredictionRecord ∧\n ¬ RevisionAccount rewrittenObservationRecord ∧\n observedHistory.predictedBatchCount = 3 ∧ observedHistory.actualBatchCount = 5 ∧\n ¬ RevisionAccount unrelatedSoftwareRecord := by\n exact ⟨by decide, by decide, by decide, by decide, by decide, by decide, by decide⟩\n\n/-- organon-map CoreReader.Engineering.revisionLimits\nsoftware-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99\nsoftware-engineering.revision#p1 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99\n-/\ntheorem revisionLimits :\n RevisionAccount revisionRecord ∧\n ¬ RevisionAccount { revisionRecord with reportedPredictionSucceeded := true } ∧\n revisionsMade.length = 3 ∧\n agreedBatch maintainers 21 5 = [3, 3, 3] ∧ liveBatch 21 5 = 5 ∧\n observations.all (fun p => staticBatch p.1 p.2 == liveBatch p.1 p.2) = true ∧\n staticBatch 21 5 ≠ liveBatch 21 5 ∧\n RevisionAccount stableRecord ∧ stableRecord.current.choice = stableRecord.old.choice ∧\n RetentionJustified currentContinuing [.other \"quantum backend\"] := by\n refine ⟨by decide, ?_, by decide, by decide, by decide, by decide,\n by decide, by decide, by decide, by decide⟩\n dsimp [RevisionAccount, RevisionAccountAgainst, observedHistory, MaterialGroundsChanged, revisionRecord, oldState, newState]\n decide\n\ndef groundedChanges : DirectionGround → List Change\n | .plan _ ds | .knowledge _ ds _ | .history _ ds | .other _ ds => ds\n\ndef currentRevisionState (ctx : Context) (chosen : Candidate) : RevisionState := {\n time := 1, forecast := ctx.evidence.flatMap groundedChanges,\n maintenance := ctx.activity.scheduledMaintenance, maintainers := ctx.activity.participants,\n migrationCost := cost chosen .migration,\n objectiveCapacity := ctx.limits.capacity .migration,\n choice := chosen }\n\ndef revisionFor (ctx : Context) (chosen : Candidate) : RevisionRecord := {\n stableRecord with software := ctx.activity.software, current := currentRevisionState ctx chosen, recordedCurrent := currentRevisionState ctx chosen }\n\ntheorem revisionContextIdentity :\n (revisionFor currentContinuing .evolvable).software = currentContinuing.activity.software ∧\n (revisionFor currentContinuing .evolvable).software = observedHistory.software ∧ (revisionFor currentContinuing .evolvable).current.maintenance =\n currentContinuing.activity.scheduledMaintenance ∧\n (revisionFor currentContinuing .evolvable).current.maintainers = currentContinuing.activity.participants ∧\n (revisionFor currentContinuing .evolvable).current.migrationCost = cost .evolvable .migration ∧\n (revisionFor currentContinuing .evolvable).current.objectiveCapacity =\n currentContinuing.limits.capacity .migration ∧\n (revisionFor currentContinuing .evolvable).current.choice = .evolvable ∧\n RevisionAccount (revisionFor currentContinuing .evolvable) := by decide\n\n/- Whole domain satisfaction keeps actual subject, credibility, account and\nrevision duties. The same context is passed to priority and every domain duty.\nApplication account choices below are finite records, not universal claims. -/\nabbrev DomainSatisfied (ctx : Context) (chosen : Candidate) : Prop :=\n ActivityScope ctx.activity ∧ EvolutionPriority ctx chosen ∧\n credible ctx.evidence .designRevision ∧\n (ctx.departure ≠ none → JustifiedDeparture ctx .evolvable) ∧\n EvolutionClaim ctx.activity chosen ⟨.designRevision, .successor, .revise⟩ ∧\n StructuralAccount ctx.activity chosen (structuralEvidence chosen .designRevision) ∧\n ContractChangeAccount (orderContract (behavior chosen)) (evolutionContract .designRevision) normalRevision ∧\n RevisionAccount (revisionFor ctx chosen)\n\ntheorem currentDomainSatisfied : DomainSatisfied currentContinuing .evolvable := by\n refine ⟨by decide, by decide, by decide, ?_, by decide, by decide, by decide, by decide⟩\n simp [currentContinuing]\n\nend CoreReader.Engineering\n```\n\n\n\n **L1** Loads Lean's standard library for lists, arithmetic, strings and decidable finite checks used throughout the model.\n\n\n **L3** Places the application vocabulary and results in CoreReader.Engineering, keeping them distinct from the inherited Core interfaces.\n\n\n **L5** The work numbers count stipulated edit operations in a bounded scenario; they are neither a universal conversion between burdens nor measurements of future engineering performance.\n\n\n **L6** The work numbers count stipulated edit operations in a bounded scenario; they are neither a universal conversion between burdens nor measurements of future engineering performance.\n\n\n **L7** The three maintainer roles distinguish the original author, a successor and an agent, so original-author editability need not imply continuing maintenance capability.\n\n\n **L8** The three maintainer roles distinguish the original author, a successor and an agent, so original-author editability need not imply continuing maintenance capability.\n\n\n **L9** Automatically provides equality decisions and printable representations for Maintainer; these support concrete case evaluation, not a philosophical claim about that type.\n\n\n **L10** The available operations distinguish editing, compilation, contract checking and migration; a change path must have the required tool available.\n\n\n **L11** The available operations distinguish editing, compilation, contract checking and migration; a change path must have the required tool available.\n\n\n **L12** Automatically provides equality decisions and printable representations for Tool; these support concrete case evaluation, not a philosophical claim about that type.\n\n\n **L13** Knowledge distinguishes private implementation layout from the public contract and documented change/migration guides; these prerequisites will separate maintainer capabilities.\n\n\n **L14** Knowledge distinguishes private implementation layout from the public contract and documented change/migration guides; these prerequisites will separate maintainer capabilities.\n\n\n **L15** Automatically provides equality decisions and printable representations for Knowledge; these support concrete case evaluation, not a philosophical claim about that type.\n\n\n **L16** The change vocabulary includes six major evolution operations, independent/coordinated work, design revision and an open named alternative. The nine-element examples do not exhaust the type.\n\n\n **L17** The change vocabulary includes six major evolution operations, independent/coordinated work, design revision and an open named alternative. The nine-element examples do not exhaust the type.\n\n\n **L18** The change vocabulary includes six major evolution operations, independent/coordinated work, design revision and an open named alternative. The nine-element examples do not exhaust the type.\n\n\n **L19** Automatically provides equality decisions and printable representations for Change; these support concrete case evaluation, not a philosophical claim about that type.\n\n\n **L20** Three candidate designs permit comparison of present simplicity, credible evolution support and extra registered extensibility; their merits are supplied by later behavior and work data.\n\n\n **L21** Three candidate designs permit comparison of present simplicity, credible evolution support and extra registered extensibility; their merits are supplied by later behavior and work data.\n\n\n **L22** Automatically provides equality decisions and printable representations for Candidate; these support concrete case evaluation, not a philosophical claim about that type.\n\n\n **L23** Seven distinct burden dimensions cover understanding, construction, diagnosis, verification, coordination, operation and migration; no sum across them is required.\n\n\n **L24** Seven distinct burden dimensions cover understanding, construction, diagnosis, verification, coordination, operation and migration; no sum across them is required.\n\n\n **L25** Seven distinct burden dimensions cover understanding, construction, diagnosis, verification, coordination, operation and migration; no sum across them is required.\n\n\n **L26** Automatically provides equality decisions and printable representations for Burden; these support concrete case evaluation, not a philosophical claim about that type.\n\n\n **L28** The concrete activity includes all three maintainer roles, making successor and agent claims nonvacuous.\n\n\n **L29** Registers nine ordinary changes for the finite examples; named other changes can still be represented separately.\n\n\n **L30** Registers nine ordinary changes for the finite examples; named other changes can still be represented separately.\n\n\n **L31** Lists every represented cost dimension so threat searches examine each dimension independently.\n\n\n **L32** Lists every represented cost dimension so threat searches examine each dimension independently.\n\n\n **L34** An engineering activity groups the people or agents, software, tools, knowledge and lifecycle expectations relevant to a capability claim.\n\n\n **L35** Records the maintainers participating in this activity; membership is later required for individual change capability.\n\n\n **L36** Identifies the software being maintained; this identity also binds later revision reports to their task.\n\n\n **L37** Records available tools rather than assuming every requested tool exists.\n\n\n **L38** Assigns knowledge separately to each maintainer, allowing an original author to know private details unavailable to successors.\n\n\n **L39** Counts scheduled releases as one concrete indicator of continuing development expectations.\n\n\n **L40** Counts scheduled maintenance work independently of releases.\n\n\n **L41** An optional finite run bound represents genuinely bounded use; absence of a bound alone is not the definition of continuing activity.\n\n\n **L42** Keeps a descriptive label separate from lifecycle facts, allowing the misleading label temporary to be tested.\n\n\n **L44** Begins a provenance comment attaching CoreReader.Engineering.ActivityScope to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence.\n\n\n **L45** Records the source reference software-engineering.purpose/p1 for CoreReader.Engineering.ActivityScope, with direct-body SHA256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L46** Records the source reference software-engineering.purpose/p2 for CoreReader.Engineering.ActivityScope, with direct-body SHA256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L47** Records the source reference software-engineering.purpose/p3 for CoreReader.Engineering.ActivityScope, with direct-body SHA256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L48** Closes the source-mapping comment for CoreReader.Engineering.ActivityScope; executable declarations resume after the comment.\n\n\n **L49** Activity scope is a concrete admissibility condition for the engineering subject, rather than an intrinsic intention attributed to code.\n\n\n **L50** Requires actual participants, a nonempty software identifier and some available tools.\n\n\n **L51** Every listed maintainer must have some available knowledge; this does not yet show the knowledge suffices for every change.\n\n\n **L53** Continuing activity means both planned releases and maintenance are positive in this model; the name of the activity is irrelevant.\n\n\n **L54** Continuing activity means both planned releases and maintenance are positive in this model; the name of the activity is irrelevant.\n\n\n **L56** A bounded lifecycle requires a declared finite run limit and zero planned releases and maintenance; a temporary label alone cannot satisfy it.\n\n\n **L57** A bounded lifecycle requires a declared finite run limit and zero planned releases and maintenance; a temporary label alone cannot satisfy it.\n\n\n **L58** A bounded lifecycle requires a declared finite run limit and zero planned releases and maintenance; a temporary label alone cannot satisfy it.\n\n\n **L60** The continuing queue activity includes all maintainers and all four tools; its software identity is the order-preserving queue.\n\n\n **L61** The continuing queue activity includes all maintainers and all four tools; its software identity is the order-preserving queue.\n\n\n **L62** The continuing queue activity includes all maintainers and all four tools; its software identity is the order-preserving queue.\n\n\n **L63** Only the original maintainer receives privateLayout. Successors and agents have public contracts and guides, creating a real prerequisite difference.\n\n\n **L64** Only the original maintainer receives privateLayout. Successors and agents have public contracts and guides, creating a real prerequisite difference.\n\n\n **L65** Only the original maintainer receives privateLayout. Successors and agents have public contracts and guides, creating a real prerequisite difference.\n\n\n **L66** The activity schedules three releases and six maintenance units, so both continuing-lifecycle indicators are positive.\n\n\n **L67** There is no finite run bound even though the descriptive label says temporary; later cases reject that label as evidence of a bounded lifecycle.\n\n\n **L69** The one-shot variant removes all planned releases and maintenance and sets a single-run limit, creating a genuinely bounded example.\n\n\n **L70** The one-shot variant removes all planned releases and maintenance and sets a single-run limit, creating a genuinely bounded example.\n\n\n **L71** The one-shot variant removes all planned releases and maintenance and sets a single-run limit, creating a genuinely bounded example.\n\n\n **L72** The prototype retains the zero-maintenance bounded setup but allows four runs.\n\n\n **L73** The prototype retains the zero-maintenance bounded setup but allows four runs.\n\n\n **L74** The retiring service uses the same bounded setup with two remaining runs.\n\n\n **L75** The retiring service uses the same bounded setup with two remaining runs.\n\n\n **L77** Each edit step records where work occurs, which knowledge and tool it needs, and its assigned work units.\n\n\n **L78** Identifies the component touched by this work step.\n\n\n **L79** States the knowledge prerequisite that the acting maintainer must possess.\n\n\n **L80** States the tool needed for this step.\n\n\n **L81** Assigns a natural-number cost to this explicit operation; later totals sum these units.\n\n\n **L82** Automatically provides equality decisions and printable representations for EditStep; these support concrete case evaluation, not a philosophical claim about that type.\n\n\n **L84** Builds an explicit work path for a candidate and intended change, rather than assigning capability from a design label.\n\n\n **L85** PresentSimple requires private layout knowledge; the other designs use the change guide, which successors possess.\n\n\n **L86** Every ordinary path starts with one edit at component 0 and one public-contract check there, each costing one unit.\n\n\n **L87** Every ordinary path starts with one edit at component 0 and one public-contract check there, each costing one unit.\n\n\n **L88** Dispatch on the requested Change to choose its corresponding editing path; the following branches distinguish the different directions.\n\n\n **L89** Addition and independent change use only that two-unit base path.\n\n\n **L90** Replacement and deletion add a one-unit compilation at component 1 using the design's selected guide.\n\n\n **L91** Coordinated change adds compilation at component 1 and public-contract verification at component 2, each costing three units.\n\n\n **L92** Migration adds an eight-unit migration-runner step requiring the migration guide.\n\n\n **L93** Withdrawal, boundary redrawing and design revision branch on the selected design; this is where simplicity and evolution have different work paths.\n\n\n **L94** Withdrawal, boundary redrawing and design revision branch on the selected design; this is where simplicity and evolution have different work paths.\n\n\n **L95** The simple design adds private-guide edit and compilation plus a public-contract check, each costing five units, bringing total work to seventeen.\n\n\n **L96** The simple design adds private-guide edit and compilation plus a public-contract check, each costing five units, bringing total work to seventeen.\n\n\n **L97** Other designs instead add a two-unit edit and two-unit public-contract check at component 1, totaling six units with the base.\n\n\n **L98** The open change constructor receives a concrete special case only for csv export.\n\n\n **L99** The open change constructor receives a concrete special case only for csv export.\n\n\n **L100** Maximal handles CSV export with a documented migration-guide compilation at component 3 costing two extra units.\n\n\n **L101** Other designs require privateLayout and twenty extra compilation units for CSV export, so a successor lacks that path's prerequisite.\n\n\n **L102** Unrecognized names receive no path; the nonempty-path requirement prevents vacuous capability from an empty list.\n\n\n **L104** Total work is the sum of the actual path steps' assigned units, not the number of modules or extension points.\n\n\n **L105** Total work is the sum of the actual path steps' assigned units, not the number of modules or extension points.\n\n\n **L107** Individual change capability is indexed by the actual activity, design, maintainer and intended change.\n\n\n **L108** Capability requires a nonempty path, participating maintainer, and every path step's knowledge and tool prerequisites; a failed prerequisite blocks the claim.\n\n\n **L109** Capability requires a nonempty path, participating maintainer, and every path step's knowledge and tool prerequisites; a failed prerequisite blocks the claim.\n\n\n **L111** Continuing capability requires a nonempty path executable with the knowledge and tools of every listed maintainer; activity scope supplies the separate nonempty-participant condition.\n\n\n **L112** Continuing capability requires a nonempty path executable with the knowledge and tools of every listed maintainer; activity scope supplies the separate nonempty-participant condition.\n\n\n **L113** Continuing capability requires a nonempty path executable with the knowledge and tools of every listed maintainer; activity scope supplies the separate nonempty-participant condition.\n\n\n **L115** Maximality will concern only a registered finite direction set. CSV has concrete work and state content; unsupported names cannot acquire capability from an empty path.\n\n\n **L116** Maximality will concern only a registered finite direction set. CSV has concrete work and state content; unsupported names cannot acquire capability from an empty path.\n\n\n **L117** Maximality will concern only a registered finite direction set. CSV has concrete work and state content; unsupported names cannot acquire capability from an empty path.\n\n\n **L118** Adds the named CSV export direction to the nine ordinary changes, producing ten registered directions.\n\n\n **L119** Keeps exactly those registered directions that every continuing maintainer can execute for the chosen design.\n\n\n **L120** Keeps exactly those registered directions that every continuing maintainer can execute for the chosen design.\n\n\n **L121** A candidate has maximum registered capability when it supports every direction in that fixed list; this is not maximality over every conceivable change.\n\n\n **L122** A candidate has maximum registered capability when it supports every direction in that fixed list; this is not maximality over every conceivable change.\n\n\n **L124** The passive software function is separated from maintainers' selected intentions; the example does not attribute generative orientation to every artifact.\n\n\n **L125** The passive software function is separated from maintainers' selected intentions; the example does not attribute generative orientation to every artifact.\n\n\n **L126** The artifact returns its input unchanged and makes no change proposal.\n\n\n **L128** Each represented maintainer intends design revision and migration; this is the activity's explicit selected intention.\n\n\n **L130** Actions distinguish proposing a change from executing software to obtain an output list.\n\n\n **L131** Actions distinguish proposing a change from executing software to obtain an output list.\n\n\n **L132** Actions distinguish proposing a change from executing software to obtain an output list.\n\n\n **L133** Automatically provides equality decisions and printable representations for EngineeringAction; these support concrete case evaluation, not a philosophical claim about that type.\n\n\n **L135** Maintainer intentions become actual propose actions for each selected direction.\n\n\n **L136** Maintainer intentions become actual propose actions for each selected direction.\n\n\n **L138** The artifact's only action executes its passive function; the action list contains no proposal constructor.\n\n\n **L139** The artifact's only action executes its passive function; the action list contains no proposal constructor.\n\n\n **L141** Begins a provenance comment attaching CoreReader.Engineering.subjectLifecycleCases to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence.\n\n\n **L142** Records the source reference software-engineering.purpose/p1 for CoreReader.Engineering.subjectLifecycleCases, with direct-body SHA256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L143** Records the source reference software-engineering.purpose/p2 for CoreReader.Engineering.subjectLifecycleCases, with direct-body SHA256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L144** Records the source reference software-engineering.purpose/p3 for CoreReader.Engineering.subjectLifecycleCases, with direct-body SHA256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L145** Closes the source-mapping comment for CoreReader.Engineering.subjectLifecycleCases; executable declarations resume after the comment.\n\n\n **L146** Collects concrete positive scope, maintainer-capability and lifecycle cases for the shared queue activity.\n\n\n **L147** The continuing activity satisfies the nonempty engineering-subject scope condition.\n\n\n **L148** The successor has the tools and public knowledge needed for evolvable design revision.\n\n\n **L149** The agent also has the prerequisites for that same design revision.\n\n\n **L150** The concrete activity remains continuing even while carrying the temporary label.\n\n\n **L151** The continuing activity is not bounded, while the one-shot, prototype and retiring variants meet their explicit finite lifecycle conditions.\n\n\n **L152** The continuing activity is not bounded, while the one-shot, prototype and retiring variants meet their explicit finite lifecycle conditions. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope.\n\n\n **L154** Begins a provenance comment attaching CoreReader.Engineering.subjectLimits to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence.\n\n\n **L155** Records the source reference software-engineering.purpose/p1 for CoreReader.Engineering.subjectLimits, with direct-body SHA256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L156** Records the source reference software-engineering.purpose/p2 for CoreReader.Engineering.subjectLimits, with direct-body SHA256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L157** Records the source reference software-engineering.purpose/p3 for CoreReader.Engineering.subjectLimits, with direct-body SHA256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L158** Closes the source-mapping comment for CoreReader.Engineering.subjectLimits; executable declarations resume after the comment.\n\n\n **L159** Collects counterexamples to inferring continuing capability or software intention from weaker facts.\n\n\n **L160** The original maintainer can revise the simple design because private layout knowledge is available to that maintainer.\n\n\n **L161** The successor cannot perform that same simple-design revision because the private prerequisite is absent.\n\n\n **L162** Consequently the simple design does not support this revision for every continuing maintainer.\n\n\n **L163** The temporary label coexists with failure of the actual bounded-lifecycle condition.\n\n\n **L164** The agent's intention is nonempty, while the passive artifact still merely returns [2,1].\n\n\n **L165** A design-revision proposal occurs among agent actions but not among the artifact's execution actions.\n\n\n **L166** A design-revision proposal occurs among agent actions but not among the artifact's execution actions. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope.\n\n\n **L168** Credibility is parameterized by an articulability test and a support relation; the following examples do not validate every possible supplied relation.\n\n\n **L169** Credibility is parameterized by an articulability test and a support relation; the following examples do not validate every possible supplied relation.\n\n\n **L170** Begins a provenance comment attaching CoreReader.Engineering.CredibleDirection to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence.\n\n\n **L171** Records the source reference software-engineering.evolution-priority/p2 for CoreReader.Engineering.CredibleDirection, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L172** Records the source reference software-engineering.evolution-priority/p3 for CoreReader.Engineering.CredibleDirection, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L173** Closes the source-mapping comment for CoreReader.Engineering.CredibleDirection; executable declarations resume after the comment.\n\n\n **L174** Allows any ground type, preserving an open set of possible credibility sources.\n\n\n **L175** The application supplies separate tests for whether a ground is articulated and whether it supports the intended direction.\n\n\n **L176** A direction is credible here when at least one listed ground passes both tests for that same direction.\n\n\n **L177** A direction is credible here when at least one listed ground passes both tests for that same direction.\n\n\n **L179** The concrete examples instantiate ground records without making these constructors an exhaustive philosophical taxonomy.\n\n\n **L180** A plan records a release number and committed changes.\n\n\n **L181** Domain knowledge records the relevant service, affected changes and a mechanism account.\n\n\n **L182** History records a service and observed change directions.\n\n\n **L183** An other constructor keeps room for a separately articulated account and its supported changes.\n\n\n **L184** Automatically provides equality decisions and printable representations for DirectionGround; these support concrete case evaluation, not a philosophical claim about that type.\n\n\n **L186** Checks the concrete ground records for the identifying content required by this application.\n\n\n **L187** A plan must name a positive release and at least one committed direction.\n\n\n **L188** Knowledge must identify a service, some affected directions and a nonempty mechanism account.\n\n\n **L189** A history needs a named service and some observations.\n\n\n **L190** An other ground needs a nonempty account and direction list.\n\n\n **L192** Interprets support according to this bounded application's concrete records, rather than deriving arbitrary real-world relevance from strings.\n\n\n **L193** A positive-release plan supports a direction only when it explicitly contains that direction.\n\n\n **L194** The designated queue knowledge supports listed directions when its mechanism is tenant-config-reload; this named mechanism is an application interpretation.\n\n\n **L195** The designated queue knowledge supports listed directions when its mechanism is tenant-config-reload; this named mechanism is an application interpretation.\n\n\n **L196** A queue history supports a direction when it occurs at least twice in the recorded list; this is a chosen finite support rule.\n\n\n **L197** The particular reviewed customer migration account supports only directions listed in that account.\n\n\n **L199** The initial grounds commit release 2 to design revision and migration.\n\n\n **L200** The revised forecast commits release 3 to deletion instead.\n\n\n **L201** Specializes generic credibility to DirectionGround using the concrete articulation and support interpretations above.\n\n\n **L202** Specializes generic credibility to DirectionGround using the concrete articulation and support interpretations above.\n\n\n **L204** The chosen accommodation test requires credible direction, positive objective gain and investment no greater than that gain; it is a local sufficient criterion, not a universal numerical exchange rule.\n\n\n **L205** The chosen accommodation test requires credible direction, positive objective gain and investment no greater than that gain; it is a local sufficient criterion, not a universal numerical exchange rule.\n\n\n **L206** The chosen accommodation test requires credible direction, positive objective gain and investment no greater than that gain; it is a local sufficient criterion, not a universal numerical exchange rule.\n\n\n **L208** Begins a provenance comment attaching CoreReader.Engineering.credibilityCases to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence.\n\n\n **L209** Records the source reference software-engineering.evolution-priority/p2 for CoreReader.Engineering.credibilityCases, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L210** Records the source reference software-engineering.evolution-priority/p3 for CoreReader.Engineering.credibilityCases, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L211** Closes the source-mapping comment for CoreReader.Engineering.credibilityCases; executable declarations resume after the comment.\n\n\n **L212** Bundles positive plan, knowledge and history support with unsupported-imagination and revised-forecast contrasts.\n\n\n **L213** The actual release-2 plan supports design revision.\n\n\n **L214** The designated queue mechanism provides the declared knowledge support for design revision.\n\n\n **L215** Two recorded queue migrations meet the concrete historical support criterion.\n\n\n **L216** An empty ground list does not support an imagined quantum backend.\n\n\n **L217** The changed forecast supports deletion and no longer supports design revision. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope.\n\n\n **L219** Assigns present abstraction complexity 1, 3 and 30 to simple, evolvable and maximal candidates; these are scenario parameters.\n\n\n **L220** Assigns present abstraction complexity 1, 3 and 30 to simple, evolvable and maximal candidates; these are scenario parameters.\n\n\n **L222** Only the simple candidate is currently implemented, allowing credibility without multiple existing implementations.\n\n\n **L224** The priority rule compares each burden against its own capacity instead of converting them into one score.\n\n\n **L225** A cost vector can assign a separate natural-number amount to each burden; this auxiliary structure does not force aggregation.\n\n\n **L226** A cost vector can assign a separate natural-number amount to each burden; this auxiliary structure does not force aggregation.\n\n\n **L227** Cost limits pair a capacity with an identified objective for each burden, so a claimed threat must concern something concrete.\n\n\n **L228** Cost limits pair a capacity with an identified objective for each burden, so a claimed threat must concern something concrete.\n\n\n **L229** Cost limits pair a capacity with an identified objective for each burden, so a claimed threat must concern something concrete.\n\n\n **L231** Every burden of the simple baseline costs one unit in this scenario.\n\n\n **L232** Every burden of the simple baseline costs one unit in this scenario.\n\n\n **L233** Evolvable understanding cost is three units.\n\n\n **L234** Evolvable construction cost is four units.\n\n\n **L235** Evolvable diagnosis cost is two units.\n\n\n **L236** Evolvable verification cost is four units.\n\n\n **L237** Evolvable coordination cost is two units.\n\n\n **L238** Evolvable operational cost is two units.\n\n\n **L239** Evolvable migration cost is eight units, illustrating a burden that need not be cheap.\n\n\n **L240** The maximal candidate costs forty units in every represented burden.\n\n\n **L242** The ordinary context has capacity twelve for each burden, enough for the evolvable candidate's assigned costs.\n\n\n **L243** The ordinary context has capacity twelve for each burden, enough for the evolvable candidate's assigned costs.\n\n\n **L244** Assign each Burden its objective name by matching on the burden; the following branches supply the distinct engineering objectives.\n\n\n **L245** The understanding limit concerns successor onboarding capacity.\n\n\n **L246** Construction capacity is tied to preparing a release.\n\n\n **L247** Diagnosis capacity concerns the incident diagnosis window.\n\n\n **L248** Verification capacity concerns checking a release.\n\n\n **L249** Coordination capacity concerns available teamwork.\n\n\n **L250** Operational capacity concerns the runtime resource budget.\n\n\n **L251** Migration capacity concerns eventual retirement migration.\n\n\n **L253** Necessary requirements remain separate from the value preference for evolution.\n\n\n **L254** Indicates whether the identified output-order contract is required.\n\n\n **L255** Bounds the permitted number of unsafe operations.\n\n\n **L256** Bounds observed latency.\n\n\n **L257** Sets the required minimum retention.\n\n\n **L259** The ordinary requirements demand order, zero unsafe operations, latency at most ten and retention at least thirty.\n\n\n **L260** All three candidate behaviors remove duplicate list values in the given order; this local equality does not equate their maintenance paths or costs.\n\n\n **L262** Profiles are observations stipulated for this scenario; later variants independently violate each of the four requirement gates.\n\n\n **L263** Profiles are observations stipulated for this scenario; later variants independently violate each of the four requirement gates.\n\n\n **L264** A profile records the four behavior/safety/performance quantities relevant to these requirements.\n\n\n **L265** Stores the output observed on the identified order test.\n\n\n **L266** Stores the number of unsafe operations in this profile.\n\n\n **L267** Stores this profile's latency observation.\n\n\n **L268** Stores this profile's retention observation.\n\n\n **L270** Each original profile observes de-duplication on [2,1,2], zero unsafe operations, latency five and retention thirty.\n\n\n **L271** Meeting requirements checks the order result [2,1] whenever order is required; it does not impose order when the requirement is disabled.\n\n\n **L272** Meeting requirements checks the order result [2,1] whenever order is required; it does not impose order when the requirement is disabled.\n\n\n **L273** Safety and latency must stay at or below their maxima, and retention must reach its minimum.\n\n\n **L274** Safety and latency must stay at or below their maxima, and retention must reach its minimum.\n\n\n **L276** A context binds the activity, requirements, evidence, costs and selected departure account used by the domain norm.\n\n\n **L277** Carries the actual engineering activity and its maintainer conditions.\n\n\n **L278** Carries the relevant necessary requirements.\n\n\n **L279** Carries the grounds for credible future directions.\n\n\n **L280** Carries per-burden objective capacities.\n\n\n **L281** Optionally identifies the burden used to justify departing from evolution priority.\n\n\n **L282** Provides candidate observations, defaulting to the ordinary profiles but allowing explicit test variants.\n\n\n **L284** The shared ordinary context uses the continuing queue, normal requirements, release-2 grounds and capacity-twelve limits, with no claimed departure.\n\n\n **L285** The shared ordinary context uses the continuing queue, normal requirements, release-2 grounds and capacity-twelve limits, with no claimed departure.\n\n\n **L286** The shared ordinary context uses the continuing queue, normal requirements, release-2 grounds and capacity-twelve limits, with no claimed departure.\n\n\n **L288** A concrete threat requires added cost above both the simple baseline and the named objective's capacity; naming a burden without those inequalities is insufficient.\n\n\n **L289** A concrete threat requires added cost above both the simple baseline and the named objective's capacity; naming a burden without those inequalities is insufficient.\n\n\n **L290** A concrete threat requires added cost above both the simple baseline and the named objective's capacity; naming a burden without those inequalities is insufficient.\n\n\n **L292** A threat exists if one of the seven represented burden dimensions meets the concrete-threat condition.\n\n\n **L293** A threat exists if one of the seven represented burden dimensions meets the concrete-threat condition.\n\n\n **L295** Begins a provenance comment attaching CoreReader.Engineering.JustifiedDeparture to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence.\n\n\n **L296** Records the source reference software-engineering.evolution-priority/p3 for CoreReader.Engineering.JustifiedDeparture, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L297** Closes the source-mapping comment for CoreReader.Engineering.JustifiedDeparture; executable declarations resume after the comment.\n\n\n **L298** Define justified departure for this context and candidate through a recorded burden whose concrete cost threat must hold.\n\n\n **L299** Inspect this same context’s departure option to distinguish an absent explanation from a named burden.\n\n\n **L300** With no recorded departure burden, justification is False; absence supplies no exception.\n\n\n **L301** For the recorded burden b, require ConcreteThreat for this exact context, candidate and burden.\n\n\n **L303** Supplies a decision procedure for the departure proposition so finite examples can be checked by computation.\n\n\n **L304** Exposes the match on the optional selected burden in JustifiedDeparture.\n\n\n **L305** Splits none versus some burden and lets Lean obtain decidability of False or the concrete arithmetic/string condition.\n\n\n **L307** Priority applicability is a conjunction of lifecycle, feasibility, credibility and actual comparative capability conditions.\n\n\n **L308** Requires a continuing activity with a valid engineering-subject scope.\n\n\n **L309** Both simple and evolvable alternatives must satisfy the same context's necessary requirements.\n\n\n **L310** The context must contain credible grounds for design revision, not merely an imagined addition.\n\n\n **L311** Every continuing maintainer must be able to perform that design revision with evolvable.\n\n\n **L312** The actual design-revision path must cost less work in evolvable than in simple.\n\n\n **L313** Evolvable must incur more present abstraction complexity, making the intended tradeoff nontrivial.\n\n\n **L315** Begins a provenance comment attaching CoreReader.Engineering.EvolutionPriority to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence.\n\n\n **L316** Records the source reference software-engineering.purpose/p3 for CoreReader.Engineering.EvolutionPriority, with direct-body SHA256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L317** Records the source reference software-engineering.evolution-priority/p1 for CoreReader.Engineering.EvolutionPriority, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L318** Records the source reference software-engineering.evolution-priority/p2 for CoreReader.Engineering.EvolutionPriority, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L319** Records the source reference software-engineering.evolution-priority/p3 for CoreReader.Engineering.EvolutionPriority, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L320** Closes the source-mapping comment for CoreReader.Engineering.EvolutionPriority; executable declarations resume after the comment.\n\n\n **L321** This is the adopted defeasible priority: when all applicability conditions hold, select evolvable unless its added cost has an explicitly justified departure. It is not deduced from those facts alone.\n\n\n **L322** This is the adopted defeasible priority: when all applicability conditions hold, select evolvable unless its added cost has an explicitly justified departure. It is not deduced from those facts alone.\n\n\n **L324** Computes that the ordinary shared context satisfies all priority conditions. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope.\n\n\n **L325** Computes that the ordinary evolvable costs threaten no represented objective and support no claimed departure.\n\n\n **L326** Computes that the ordinary evolvable costs threaten no represented objective and support no claimed departure. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope.\n\n\n **L328** The threatened variant lowers only the selected burden's capacity to one and records that burden as the departure reason; other capacities remain twelve.\n\n\n **L329** The threatened variant lowers only the selected burden's capacity to one and records that burden as the departure reason; other capacities remain twelve.\n\n\n **L330** The threatened variant lowers only the selected burden's capacity to one and records that burden as the departure reason; other capacities remain twelve.\n\n\n **L332** Begins a provenance comment attaching CoreReader.Engineering.priorityWhenApplicable to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence.\n\n\n **L333** Records the source reference software-engineering.evolution-priority/p1 for CoreReader.Engineering.priorityWhenApplicable, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L334** Records the source reference software-engineering.evolution-priority/p2 for CoreReader.Engineering.priorityWhenApplicable, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L335** Records the source reference software-engineering.evolution-priority/p3 for CoreReader.Engineering.priorityWhenApplicable, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L336** Closes the source-mapping comment for CoreReader.Engineering.priorityWhenApplicable; executable declarations resume after the comment.\n\n\n **L337** The conditional result ranges over any context and chosen candidate in this application vocabulary.\n\n\n **L338** Assumes both adoption of the priority rule and actual applicability; neither premise is derived merely from the theorem statement.\n\n\n **L339** Also assumes there is no justified cost departure.\n\n\n **L340** Under those premises, the choice must be evolvable and therefore carry the stated extra abstraction complexity.\n\n\n **L341** Under those premises, the choice must be evolvable and therefore carry the stated extra abstraction complexity.\n\n\n **L342** Applies the adopted implication to actual conditions and eliminates its departure alternative using noDeparture.\n\n\n **L343** Pairs the resulting choice equality with the applicability premise's final complexity inequality, substituting the actual chosen candidate.\n\n\n **L345** Shows that choosing simple in the ordinary applicable, no-threat context violates the adopted evolution priority.\n\n\n **L346** Temporarily assumes the simple choice satisfies the rule in order to derive a contradiction.\n\n\n **L347** Actual applicability activates that rule, and absence of departure forces the impossible simple=evolvable equality.\n\n\n **L348** Eliminates equality between distinct candidate constructors, completing the negative result.\n\n\n **L350** Replaces only evolvable's observed profile while preserving the other candidate profiles and context, isolating a necessary-requirement variation.\n\n\n **L351** Replaces only evolvable's observed profile while preserving the other candidate profiles and context, isolating a necessary-requirement variation.\n\n\n **L353** Check that each of the four displayed requirement failures makes PriorityConditions false. This only disables priority activation: EvolutionPriority and the later DomainSatisfied do not impose an unconditional Meets rejection.\n\n\n **L354** Changing the observed order from [2,1] to [1,2] invalidates priority applicability.\n\n\n **L355** One unsafe operation exceeds the permitted zero and invalidates applicability.\n\n\n **L356** Latency eleven exceeds the limit ten and invalidates applicability.\n\n\n **L357** Retention twenty-nine falls below thirty and invalidates applicability.\n\n\n **L358** Simplifies applicability, the altered profile and requirement predicates; each branch reduces to its explicit failed equality or numerical bound.\n\n\n **L359** Simplifies applicability, the altered profile and requirement predicates; each branch reduces to its explicit failed equality or numerical bound.\n\n\n **L361** Begins a provenance comment attaching CoreReader.Engineering.priorityConditionsCases to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence.\n\n\n **L362** Records the source reference software-engineering.purpose/p3 for CoreReader.Engineering.priorityConditionsCases, with direct-body SHA256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L363** Records the source reference software-engineering.evolution-priority/p1 for CoreReader.Engineering.priorityConditionsCases, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L364** Records the source reference software-engineering.evolution-priority/p2 for CoreReader.Engineering.priorityConditionsCases, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L365** Records the source reference software-engineering.evolution-priority/p3 for CoreReader.Engineering.priorityConditionsCases, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L366** Closes the source-mapping comment for CoreReader.Engineering.priorityConditionsCases; executable declarations resume after the comment.\n\n\n **L367** Bundles ordinary priority, four requirement failures, an accounted cost exception and the nonmaximal chosen design.\n\n\n **L368** Choosing evolvable satisfies the adopted priority in the ordinary context.\n\n\n **L369** Reordered output fails the ordinary order requirement.\n\n\n **L370** One unsafe operation fails the safety requirement.\n\n\n **L371** Latency eleven fails the performance bound.\n\n\n **L372** Retention twenty-nine fails the minimum retention requirement.\n\n\n **L373** With a concrete verification-capacity threat, the rule permits the simple choice through its departure branch.\n\n\n **L374** Removing the departure account leaves no justified departure even when the threatened cost data remain.\n\n\n **L375** The preferred evolvable design has complexity three, below maximal's thirty; the priority is not a duty to maximize complexity.\n\n\n **L376** Builds the conjunction by finite decisions, leaving only the absent-departure branch for simplification.\n\n\n **L377** An absent departure reduces JustifiedDeparture to False, proving that negative branch.\n\n\n **L379** Begins a provenance comment attaching CoreReader.Engineering.priorityChoices to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence.\n\n\n **L380** Records the source reference software-engineering.evolution-priority/p1 for CoreReader.Engineering.priorityChoices, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L381** Records the source reference software-engineering.evolution-priority/p2 for CoreReader.Engineering.priorityChoices, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L382** Records the source reference software-engineering.evolution-priority/p3 for CoreReader.Engineering.priorityChoices, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L383** Closes the source-mapping comment for CoreReader.Engineering.priorityChoices; executable declarations resume after the comment.\n\n\n **L384** Presents the actual ordinary evolution choice, ordinary simple rejection and threatened-context simple allowance together.\n\n\n **L385** The ordinary evolvable choice follows the adopted rule.\n\n\n **L386** The ordinary simple choice fails that same rule.\n\n\n **L387** The verification-threat context gives a justified exception for choosing simple.\n\n\n **L388** Combines computed positive examples with the previously proved no-threat simple-choice contradiction.\n\n\n **L390** Begins a provenance comment attaching CoreReader.Engineering.credibilityLimits to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence.\n\n\n **L391** Records the source reference software-engineering.evolution-priority/p2 for CoreReader.Engineering.credibilityLimits, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L392** Records the source reference software-engineering.evolution-priority/p3 for CoreReader.Engineering.credibilityLimits, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L393** Closes the source-mapping comment for CoreReader.Engineering.credibilityLimits; executable declarations resume after the comment.\n\n\n **L394** Separates credible planned change from existing implementation count, imaginative possibilities and maximum registered capability.\n\n\n **L395** The design-revision plan is credible while only one candidate is implemented.\n\n\n **L396** An imagined quantum backend with no grounds and zero gain does not justify an investment of five.\n\n\n **L397** The initial plan does not support the imagined quantum-backend direction.\n\n\n **L398** The ordinary evolvable choice still satisfies the domain priority.\n\n\n **L399** The preferred design's present complexity is lower than maximal's.\n\n\n **L400** Construction and migration costs differ within evolvable, retaining distinct burdens instead of one universal cost rate.\n\n\n **L401** Evolvable does not support every registered direction for all continuing maintainers.\n\n\n **L402** Maximal does support every direction in the explicitly registered finite set.\n\n\n **L403** Evolvable supports nine registered directions.\n\n\n **L404** Maximal supports ten, making its extra extensibility substantive rather than merely a name.\n\n\n **L405** CSV export is not supported by the current plan, so its technical availability does not itself establish present credibility. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope.\n\n\n **L407** Begins a provenance comment attaching CoreReader.Engineering.costCases to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence.\n\n\n **L408** Records the source reference software-engineering.evolution-priority/p3 for CoreReader.Engineering.costCases, with direct-body SHA256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L409** Closes the source-mapping comment for CoreReader.Engineering.costCases; executable declarations resume after the comment.\n\n\n **L410** Checks each of the seven burdens as a possible concrete reason for departing from priority.\n\n\n **L411** Reducing understanding capacity to one makes the evolvable understanding cost a justified departure.\n\n\n **L412** The analogous construction-capacity threat justifies departure.\n\n\n **L413** The analogous diagnosis-capacity threat justifies departure.\n\n\n **L414** The analogous verification-capacity threat justifies departure.\n\n\n **L415** The analogous coordination-capacity threat justifies departure.\n\n\n **L416** The analogous operational-capacity threat justifies departure.\n\n\n **L417** The analogous migration-capacity threat justifies departure.\n\n\n **L418** Merely naming migration in the ordinary capacity-twelve context does not create a real threat or justified exception. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope.\n\n\n **L420** The following total functions represent an identified de-duplication API. Finite corpus equality is kept distinct from universal contract preservation.\n\n\n **L421** The following total functions represent an identified de-duplication API. Finite corpus equality is kept distinct from universal contract preservation.\n\n\n **L422** Removes duplicate values using the standard library's order-preserving list operation.\n\n\n **L423** The refactor performs the same de-duplication and appends an empty list, preserving output.\n\n\n **L424** Take a natural number and an arbitrary natural-number list; the type has no sorted-input premise. sortValues uses this helper for ordered insertion into its recursively sorted tail.\n\n\n **L425** Inserting into an empty list yields the singleton value.\n\n\n **L426** Places the value before the first no-smaller head; otherwise keeps the head and recursively inserts into the tail.\n\n\n **L428** Sorting recursively uses the insertion operation; this changes ordering rather than only de-duplicating.\n\n\n **L429** The empty list sorts to itself.\n\n\n **L430** Sorts the tail and inserts the original head into that sorted result.\n\n\n **L432** The alternative implementation sorts all values before removing duplicates, so it can violate the original order contract.\n\n\n **L434** Software-state fields allow distinct kinds of evolution to change distinct aspects of the represented design.\n\n\n **L435** Lists the represented capabilities of the software.\n\n\n **L436** Identifies which implementation version is used.\n\n\n **L437** Lists concrete mechanisms that may be added or deleted.\n\n\n **L438** Lists abstractions that may be retained or withdrawn.\n\n\n **L439** Records a boundary revision index, separate from capability and implementation indices.\n\n\n **L440** Identifies the storage technology or model that may be migrated away from.\n\n\n **L441** Records the configured batch size.\n\n\n **L442** Automatically provides equality decisions and printable representations for SoftwareState; these support concrete case evaluation, not a philosophical claim about that type.\n\n\n **L444** The starting software de-duplicates, uses implementation 0, queue plus legacy cache, fixed batching, boundary index 0, legacy storage and batch size ten.\n\n\n **L445** The starting software de-duplicates, uses implementation 0, queue plus legacy cache, fixed batching, boundary index 0, legacy storage and batch size ten.\n\n\n **L447** Each change direction transforms actual selected fields of the software state; this is a stipulated state model, not an executable source-code editor.\n\n\n **L448** Addition retains existing capabilities and adds tenant batching.\n\n\n **L449** Replacement increments the implementation identifier.\n\n\n **L450** Deletion removes legacy cache while retaining other mechanisms.\n\n\n **L451** Withdrawal removes the fixed-batch abstraction.\n\n\n **L452** Redrawing increments the boundary revision index.\n\n\n **L453** Migration replaces legacy technology with portable storage.\n\n\n **L454** Independent change updates only batch size to five.\n\n\n **L455** Coordinated change updates batch size and the boundary index together.\n\n\n **L456** Design revision sets batch size five, replaces the abstraction with live configuration and redraws the boundary.\n\n\n **L457** The named CSV direction adds an actual CSV capability; unrecognized other directions leave the state unchanged.\n\n\n **L458** The named CSV direction adds an actual CSV capability; unrecognized other directions leave the state unchanged.\n\n\n **L459** The named CSV direction adds an actual CSV capability; unrecognized other directions leave the state unchanged.\n\n\n **L461** Redrawing and design revision deliberately use sortedUnique behavior; other changes preserve orderedUnique behavior in this application.\n\n\n **L462** Redrawing and design revision deliberately use sortedUnique behavior; other changes preserve orderedUnique behavior in this application.\n\n\n **L464** Open-ended change kinds, work requirements, maintainer knowledge and obligation treatment remain separate; they are not collapsed into a single extensibility score.\n\n\n **L465** Open-ended change kinds, work requirements, maintainer knowledge and obligation treatment remain separate; they are not collapsed into a single extensibility score.\n\n\n **L466** A change claim explicitly says whether it preserves or deliberately revises obligations.\n\n\n **L467** A change claim explicitly says whether it preserves or deliberately revises obligations.\n\n\n **L468** A change claim explicitly says whether it preserves or deliberately revises obligations. Automatically provides equality decisions and printable representations for ObligationTreatment; these support concrete case evaluation, not a philosophical claim about that type.\n\n\n **L469** Groups the intended direction, acting maintainer and declared obligation treatment in one claim.\n\n\n **L470** Identifies the change whose capability is being claimed.\n\n\n **L471** Identifies the maintainer whose conditions must support that change.\n\n\n **L472** States whether the same identified obligation is preserved or deliberately revised.\n\n\n **L474** The finite order corpus is exactly four lists: empty, [2,1,2], [1,3,1] and [4,4]; later finite preservation claims are limited to these inputs.\n\n\n **L475** Universal scoped preservation requires the new and old functions to agree for every input satisfying the supplied scope predicate.\n\n\n **L476** Universal scoped preservation requires the new and old functions to agree for every input satisfying the supplied scope predicate.\n\n\n **L478** Finite preservation checks only the declared corpus by Boolean equality; it does not infer the preceding all-input property.\n\n\n **L479** Finite preservation checks only the declared corpus by Boolean equality; it does not infer the preceding all-input property.\n\n\n **L481** Contracts and observer dependencies are supplied independently of the report, preventing report edits from redefining the actual old/new behavior or affected population.\n\n\n **L482** Contracts and observer dependencies are supplied independently of the report, preventing report edits from redefining the actual old/new behavior or affected population.\n\n\n **L483** Contracts and observer dependencies are supplied independently of the report, preventing report edits from redefining the actual old/new behavior or affected population.\n\n\n **L484** An observable contract combines order behavior with a retry limit.\n\n\n **L485** The order function is actual observable behavior, not just a contract name.\n\n\n **L486** The retry threshold belongs to the actual contract.\n\n\n **L488** A retry is permitted exactly when the attempt index is below maxAttempts, making changes in that threshold observable.\n\n\n **L489** A retry is permitted exactly when the attempt index is below maxAttempts, making changes in that threshold observable.\n\n\n **L491** An ordinary order contract pairs its function with threshold three.\n\n\n **L492** The original contract uses ordered de-duplication and threshold three.\n\n\n **L493** The refactored contract changes only to the extensionally identical refactor, retaining threshold three.\n\n\n **L494** The deliberate revision uses sorted de-duplication and threshold five, changing both represented contract aspects.\n\n\n **L495** The direction-specific contract uses its actual evolution behavior and raises retry threshold only for redrawing or design revision.\n\n\n **L496** The direction-specific contract uses its actual evolution behavior and raises retry threshold only for redrawing or design revision.\n\n\n **L498** The finite retry corpus contains attempt indices zero through five.\n\n\n **L499** Finite whole-contract preservation requires both order equality on contractInputs and retry equality on failureInputs.\n\n\n **L500** Finite whole-contract preservation requires both order equality on contractInputs and retry equality on failureInputs.\n\n\n **L501** Finite whole-contract preservation requires both order equality on contractInputs and retry equality on failureInputs.\n\n\n **L503** Order and retry are distinct observable contract aspects, allowing different parties to depend on them.\n\n\n **L504** Order and retry are distinct observable contract aspects, allowing different parties to depend on them.\n\n\n **L505** Order and retry are distinct observable contract aspects, allowing different parties to depend on them. Automatically provides equality decisions and printable representations for ContractAspect; these support concrete case evaluation, not a philosophical claim about that type.\n\n\n **L506** A dependency record connects a named party to the contract aspect it observes.\n\n\n **L507** Identifies the party whose obligations may be affected.\n\n\n **L508** Identifies the particular observable aspect that party depends on.\n\n\n **L509** Automatically provides equality decisions and printable representations for PartyDependency; these support concrete case evaluation, not a philosophical claim about that type.\n\n\n **L511** The queue consumer depends on order, while the queue operator depends on retry behavior; these dependencies are fixed outside the revision report.\n\n\n **L512** The queue consumer depends on order, while the queue operator depends on retry behavior; these dependencies are fixed outside the revision report.\n\n\n **L514** Detects changes from actual old/new contracts under the finite observations for each aspect.\n\n\n **L515** Order changes when any declared order input produces a different output.\n\n\n **L516** Retry changes when any declared attempt index produces a different permission result.\n\n\n **L518** The affected-party list is computed from fixed dependencies whose observed aspect actually changes, not taken from the report's own claim.\n\n\n **L519** The affected-party list is computed from fixed dependencies whose observed aspect actually changes, not taken from the report's own claim.\n\n\n **L520** The affected-party list is computed from fixed dependencies whose observed aspect actually changes, not taken from the report's own claim.\n\n\n **L522** The revision account records intention, changed observations, parties, actual-limit claims, recorded limits and a procedure description.\n\n\n **L523** States that a contract change is deliberate.\n\n\n **L524** Records the revised order output on the distinguished sample.\n\n\n **L525** Lists parties acknowledged by the report; duties later compare this to actual affected parties.\n\n\n **L526** States the claimed old retry threshold.\n\n\n **L527** States the claimed new retry threshold.\n\n\n **L528** Retains the report's historical record of the old threshold.\n\n\n **L529** Retains the recorded new threshold.\n\n\n **L530** Names the chosen procedure; the philosophical account does not prescribe one particular procedure.\n\n\n **L532** The ordinary revision is deliberate and records the new sorted result [1,2].\n\n\n **L533** The ordinary revision is deliberate and records the new sorted result [1,2].\n\n\n **L534** Acknowledges both the consumer and operator affected by the two actual aspect changes.\n\n\n **L535** States actual retry limits changing from three to five.\n\n\n **L536** The retained records also say three before and five after, rather than rewriting the old limit.\n\n\n **L537** Uses contract review as one possible procedure, without making its name a condition of validity.\n\n\n **L539** Revision duties are evaluated against the independently supplied old/new contracts and the particular report.\n\n\n **L540** Requires deliberate revision and an accurate report of the new output on [2,1,2].\n\n\n **L541** Every actually affected party must occur in the report; this permits extra listed parties and does not prescribe notification.\n\n\n **L542** Both claimed failure limits must equal the independently supplied actual thresholds.\n\n\n **L543** The recorded old limit must still match the original contract.\n\n\n **L544** The recorded new limit must match the new contract.\n\n\n **L546** Begins a provenance comment attaching CoreReader.Engineering.ContractChangeAccount to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence.\n\n\n **L547** Records the source reference software-engineering.structural-judgment/p3 for CoreReader.Engineering.ContractChangeAccount, with direct-body SHA256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L548** Closes the source-mapping comment for CoreReader.Engineering.ContractChangeAccount; executable declarations resume after the comment.\n\n\n **L549** A contract-change account either preserves all declared finite observations or supplies the deliberate-revision duties; these are distinct alternatives.\n\n\n **L550** A contract-change account either preserves all declared finite observations or supplies the deliberate-revision duties; these are distinct alternatives.\n\n\n **L552** Begins a provenance comment attaching CoreReader.Engineering.EvolutionClaim to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence.\n\n\n **L553** Records the source reference software-engineering.evolution-meaning/p1 for CoreReader.Engineering.EvolutionClaim, with direct-body SHA256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L554** Records the source reference software-engineering.evolution-meaning/p2 for CoreReader.Engineering.EvolutionClaim, with direct-body SHA256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L555** Closes the source-mapping comment for CoreReader.Engineering.EvolutionClaim; executable declarations resume after the comment.\n\n\n **L556** A capability claim concerns a specific maintainer and direction, with an explicit obligation treatment.\n\n\n **L557** The named maintainer must actually be able to execute the intended direction's path.\n\n\n **L558** The same direction's actual old/new contract change must have a valid preservation or revision account.\n\n\n **L559** The direction's path must contain a contract-runner step, tying the claim to represented verification work.\n\n\n **L560** A preserve claim requires the distinguished sample to retain the original ordered output.\n\n\n **L561** A preserve claim requires the distinguished sample to retain the original ordered output.\n\n\n **L562** A revise claim instead requires an actual different output on that sample; the treatment label cannot silently reverse the observed relation.\n\n\n **L563** A revise claim instead requires an actual different output on that sample; the treatment label cannot silently reverse the observed relation.\n\n\n **L565** Begins a provenance comment attaching CoreReader.Engineering.evolutionKindsCases to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence.\n\n\n **L566** Records the source reference software-engineering.evolution-meaning/p1 for CoreReader.Engineering.evolutionKindsCases, with direct-body SHA256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L567** Records the source reference software-engineering.evolution-meaning/p2 for CoreReader.Engineering.evolutionKindsCases, with direct-body SHA256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L568** Closes the source-mapping comment for CoreReader.Engineering.evolutionKindsCases; executable declarations resume after the comment.\n\n\n **L569** Collects actual state changes, successor capability and both preservation/revision claim examples.\n\n\n **L570** Addition retains de-duplication and adds tenant batching.\n\n\n **L571** Replacement changes implementation index zero to one.\n\n\n **L572** Deletion removes legacy cache, leaving the queue mechanism.\n\n\n **L573** Withdrawal removes the only fixed-batch abstraction, leaving the abstraction list empty.\n\n\n **L574** Redrawing changes the boundary index from zero to one.\n\n\n **L575** Migration changes the storage technology to portable store.\n\n\n **L576** The successor can execute all nine ordinary evolvable change paths with the supplied tools and guides.\n\n\n **L577** A successor's replacement is a valid preservation-type EvolutionClaim.\n\n\n **L578** An agent's boundary redrawing is a valid deliberate-revision EvolutionClaim.\n\n\n **L579** Independent work costs two while coordinated work costs eight, so they need not require equal work. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope.\n\n\n **L581** Begins a provenance comment attaching CoreReader.Engineering.evolutionDimensionsLimits to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence.\n\n\n **L582** Records the source reference software-engineering.evolution-meaning/p1 for CoreReader.Engineering.evolutionDimensionsLimits, with direct-body SHA256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L583** Records the source reference software-engineering.evolution-meaning/p2 for CoreReader.Engineering.evolutionDimensionsLimits, with direct-body SHA256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L584** Closes the source-mapping comment for CoreReader.Engineering.evolutionDimensionsLimits; executable declarations resume after the comment.\n\n\n **L585** Shows that different evolution dimensions have different costs and capabilities, including an actual maximum-versus-evolvable contrast.\n\n\n **L586** Simple-design addition costs two units.\n\n\n **L587** Withdrawing its fixed structure costs seventeen units, much more than addition.\n\n\n **L588** Evolvable independent change costs less than its coordinated change.\n\n\n **L589** These uneven costs coexist with satisfaction of evolution priority.\n\n\n **L590** Evolvable migration costs ten, so it exceeds nine despite the priority's satisfaction.\n\n\n **L591** The original maintainer can add to the simple design.\n\n\n **L592** The original maintainer can also add to evolvable.\n\n\n **L593** The original maintainer's private knowledge permits simple-design revision.\n\n\n **L594** The original maintainer can also perform evolvable design revision.\n\n\n **L595** For the same design-revision direction, evolvable uses six work units versus simple's seventeen.\n\n\n **L596** Both designs use two units for addition; an advantage on design revision is not a strict advantage on every dimension.\n\n\n **L597** CSV export changes the actual capability list to include CSV alongside de-duplication.\n\n\n **L598** The successor has the guides and tools for maximal's CSV path.\n\n\n **L599** The successor lacks privateLayout needed by evolvable's CSV path, despite its other advantages.\n\n\n **L600** Constructs every conjunct with Lean's decision procedure over the explicit finite paths, states and arithmetic; no empirical generalization occurs.\n\n\n **L602** States a counterexample to universal strict improvement from a single-direction advantage.\n\n\n **L603** Retains the genuine strict improvement for design revision.\n\n\n **L604** Denies that evolvable requires strictly less work for every Change, including additions and named other directions.\n\n\n **L605** Computes the positive revision inequality and leaves the universal negative to a counterexample argument.\n\n\n **L606** Assumes strict improvement in every direction to derive a contradiction.\n\n\n **L607** Specializes that assumption to addition, where both work totals equal two; the claimed strict inequality is false.\n\n\n **L608** Specializes that assumption to addition, where both work totals equal two; the claimed strict inequality is false.\n\n\n **L610** Change propagation is the distinct list of component identifiers touched by the actual path, retaining relations to the intended change.\n\n\n **L611** Change propagation is the distinct list of component identifiers touched by the actual path, retaining relations to the intended change.\n\n\n **L613** Computes a natural-number batch-count expression (items+size−1)/size. It is intended for positive batch sizes; Lean subtraction and division are total even outside that intended domain.\n\n\n **L614** The static predictor deliberately ignores runtimeSize and always computes with size ten.\n\n\n **L615** The live predictor uses the supplied runtime batch size, allowing the fixed assumption to be tested.\n\n\n **L617** A structural evidence record connects an intended change to participants, propagation, observations and work accounts.\n\n\n **L618** Identifies the change this evidence is supposed to support.\n\n\n **L619** Identifies the relevant maintainers in the evidence account.\n\n\n **L620** Records which components the change touches.\n\n\n **L621** Records the exact input corpus used to observe contracts.\n\n\n **L622** Records outputs before the change on that corpus.\n\n\n **L623** Records outputs after the change on the same corpus.\n\n\n **L624** Stores the represented understanding-work quantity, here instantiated from total path work.\n\n\n **L625** Stores a verification-work quantity, instantiated below as the number of contract-runner steps rather than their unit sum.\n\n\n **L626** Stores a claimed work gain over the simple design for this intended change.\n\n\n **L628** Builds a concrete evidence record from the candidate's path and the same intended direction.\n\n\n **L629** Binds the direction, all maintainers and the actual deduplicated propagation list.\n\n\n **L630** Uses exactly the declared finite contract corpus.\n\n\n **L631** Computes the old observations with orderedUnique.\n\n\n **L632** Computes the new observations with that direction's actual evolutionBehavior.\n\n\n **L633** The understanding-work field equals the intended path's total assigned work.\n\n\n **L634** Verification counts actual contractRunner steps in the same path.\n\n\n **L635** Work gain is simple work minus chosen work using natural subtraction, which truncates at zero rather than recording negative gains.\n\n\n **L637** Begins a provenance comment attaching CoreReader.Engineering.StructuralAccount to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence.\n\n\n **L638** Records the source reference software-engineering.structural-judgment/p1 for CoreReader.Engineering.StructuralAccount, with direct-body SHA256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L639** Records the source reference software-engineering.structural-judgment/p2 for CoreReader.Engineering.StructuralAccount, with direct-body SHA256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L640** Closes the source-mapping comment for CoreReader.Engineering.StructuralAccount; executable declarations resume after the comment.\n\n\n **L641** A valid structural account must match the actual activity, candidate and intended change; merely filling record fields is insufficient.\n\n\n **L642** Recorded participants must equal the activity's, and touched components must equal actual propagation for the claimed direction.\n\n\n **L643** The account must identify the prescribed finite observation inputs exactly.\n\n\n **L644** Its before-results must be the original ordered behavior on those inputs.\n\n\n **L645** Its after-results must come from the same intended direction's behavior.\n\n\n **L646** The claimed understanding work must match the selected path's total work.\n\n\n **L647** The verification field must match the actual number of contract-runner steps; this checks a concrete work relation, not a free assessment flag.\n\n\n **L648** The verification field must match the actual number of contract-runner steps; this checks a concrete work relation, not a free assessment flag.\n\n\n **L649** The claimed gain must equal the actual simple-minus-selected work difference for the same intended change.\n\n\n **L651** Visible interface metadata is separated from executable behavior and edit paths for later insufficiency counterexamples.\n\n\n **L652** Stores the visible function signature text.\n\n\n **L653** Stores a claimed module count, later compared with actual component lists.\n\n\n **L654** Stores the visible extension-point count.\n\n\n **L655** Stores a named design principle; its name alone will not prove capability.\n\n\n **L656** Automatically provides equality decisions and printable representations for InterfaceView; these support concrete case evaluation, not a philosophical claim about that type.\n\n\n **L658** Several designs share the same List Nat→List Nat signature, eight modules, twelve extension points and dependency-inversion label.\n\n\n **L659** All eight components, numbered zero through seven, assume batch size ten.\n\n\n **L660** All eight components, numbered zero through seven, assume batch size ten.\n\n\n **L662** Changing batch size selects the components whose stored assumption differs from the new size; at size five all eight need revision.\n\n\n **L663** Changing batch size selects the components whose stored assumption differs from the new size; at size five all eight need revision.\n\n\n **L665** A boundary carries actual endpoint identifiers and a contract label, allowing relation-sensitive checks.\n\n\n **L666** Identifies the caller endpoint of the edge.\n\n\n **L667** Identifies the callee endpoint of the edge.\n\n\n **L668** Stores the edge's contract label; later checks also require work and actual output equality, so this string is not sufficient evidence.\n\n\n **L669** Automatically provides equality decisions and printable representations for Boundary; these support concrete case evaluation, not a philosophical claim about that type.\n\n\n **L671** A complete represented design combines metadata with its actual function, paths, components, boundaries and assumptions.\n\n\n **L672** Keeps the visible metadata alongside the substantive design fields.\n\n\n **L673** Carries the actual behavior used in contract comparisons.\n\n\n **L674** Supplies concrete edit steps separately for each intended change.\n\n\n **L675** Lists actual component identifiers, allowing endpoint-presence checks.\n\n\n **L676** Lists the design's actual represented edges.\n\n\n **L677** Associates components with their fixed batch-size assumptions.\n\n\n **L679** The private design has the shared metadata, ordered behavior and simple-design paths; it has eight components, no explicit edges and eight fixed-batch assumptions.\n\n\n **L680** The private design has the shared metadata, ordered behavior and simple-design paths; it has eight components, no explicit edges and eight fixed-batch assumptions.\n\n\n **L681** The private design has the shared metadata, ordered behavior and simple-design paths; it has eight components, no explicit edges and eight fixed-batch assumptions.\n\n\n **L683** The documented design changes only the work paths to evolvable's guide-based paths; metadata and observable behavior stay the same.\n\n\n **L684** The documented design changes only the work paths to evolvable's guide-based paths; metadata and observable behavior stay the same.\n\n\n **L686** The sorted variant changes actual behavior while retaining documented design metadata and paths, enabling a same-signature contract counterexample.\n\n\n **L688** This finite application treats editing callee 1 as crossing the actual 2→1 edge and requiring caller-side order verification; neither an edge label nor a named contract proves that verification occurred or output was preserved.\n\n\n **L689** This finite application treats editing callee 1 as crossing the actual 2→1 edge and requiring caller-side order verification; neither an edge label nor a named contract proves that verification occurred or output was preserved.\n\n\n **L690** This finite application treats editing callee 1 as crossing the actual 2→1 edge and requiring caller-side order verification; neither an edge label nor a named contract proves that verification occurred or output was preserved.\n\n\n **L691** This finite application treats editing callee 1 as crossing the actual 2→1 edge and requiring caller-side order verification; neither an edge label nor a named contract proves that verification occurred or output was preserved.\n\n\n **L692** Instantiates the concrete edge from caller 2 to callee 1 with the queue's order-contract label.\n\n\n **L694** Adds that actual edge to documentedDesign's boundary list, tying the later check to a design containing the edge.\n\n\n **L695** Adds that actual edge to documentedDesign's boundary list, tying the later check to a design containing the edge.\n\n\n **L697** Boundary crossing is checked for one actual design, one intended direction and one edge.\n\n\n **L698** The edge must belong to the design and its caller must be an actual component.\n\n\n **L699** Its callee must also exist, and caller and callee must be different components.\n\n\n **L700** The intended path must actually edit or compile the callee component; an unrelated edge does not establish propagation across this boundary.\n\n\n **L701** The intended path must actually edit or compile the callee component; an unrelated edge does not establish propagation across this boundary.\n\n\n **L703** The boundary-obligation test is indexed by the same design, intended change and edge, so results for unrelated boundaries cannot substitute.\n\n\n **L704** The boundary-obligation test is indexed by the same design, intended change and edge, so results for unrelated boundaries cannot substitute.\n\n\n **L705** Requires the actual boundary-crossing relation before treating a caller-side check as a cross-boundary obligation.\n\n\n **L706** The same change path must contain a caller-component contractRunner step requiring publicContract knowledge.\n\n\n **L707** The same change path must contain a caller-component contractRunner step requiring publicContract knowledge.\n\n\n **L708** The actual design behavior must preserve orderedUnique on the declared finite order corpus; a check-step label without output equality fails.\n\n\n **L710** Construct omittedCallerCheck as a design variant whose paths omit caller contract-runner work, for the later boundary-obligation counterexample.\n\n\n **L711** Copy boundaryDesign’s other fields unchanged and replace paths with a function that transforms the path for each requested direction.\n\n\n **L712** Filter the original boundaryDesign path for this same direction, retaining precisely the steps accepted by the following predicate.\n\n\n **L713** Exclude a step exactly when it is at coordinatedBoundary.caller and uses contractRunner; keep all other steps and finish the record update.\n\n\n **L715** Moves the callee endpoint to component 7 while retaining the caller and contract label.\n\n\n **L717** The alternate design actually contains the changed edge, so the negative crossing test is about its endpoint/path mismatch rather than simple absence of the edge.\n\n\n **L718** The alternate design actually contains the changed edge, so the negative crossing test is about its endpoint/path mismatch rather than simple absence of the edge.\n\n\n **L720** Checks positive and negative relations among actual edges, intended work, caller obligations and observable behavior.\n\n\n **L721** Coordinated work in boundaryDesign crosses its actual 2→1 edge.\n\n\n **L722** That work includes the required caller check and retains the finite order contract.\n\n\n **L723** Removing the caller check does not remove the callee edit, so the boundary is still crossed.\n\n\n **L724** Nevertheless the cross-boundary obligation is unmet after the caller check is removed.\n\n\n **L725** The edge to callee 7 is not crossed because the coordinated path does not edit or compile that callee.\n\n\n **L726** Replacing only run with sortedUnique violates the order obligation despite unchanged edge and checking steps; the finite conjunction is proved by computation.\n\n\n **L727** Replacing only run with sortedUnique violates the order obligation despite unchanged edge and checking steps; the finite conjunction is proved by computation. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope.\n\n\n **L729** Begins a provenance comment attaching CoreReader.Engineering.structuralCases to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence.\n\n\n **L730** Records the source reference software-engineering.structural-judgment/p1 for CoreReader.Engineering.structuralCases, with direct-body SHA256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L731** Records the source reference software-engineering.structural-judgment/p2 for CoreReader.Engineering.structuralCases, with direct-body SHA256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L732** Closes the source-mapping comment for CoreReader.Engineering.structuralCases; executable declarations resume after the comment.\n\n\n **L733** The registered structural case bundle includes actual propagation, contract observations, work and the new explicit cross-boundary checks.\n\n\n **L734** The evolvable design-revision evidence matches the actual continuing activity and intended path.\n\n\n **L735** Simple design revision touches three distinct components.\n\n\n **L736** Evolvable design revision touches two distinct components.\n\n\n **L737** Coordinated work contains a component-2 step needing public-contract knowledge; the following new cases additionally bind it to a real edge.\n\n\n **L738** The refactor preserves ordered behavior on the declared finite contract corpus.\n\n\n **L739** The actual before/after observation lists differ for deliberate design revision; the change is not falsely called preservation.\n\n\n **L740** The actual before/after observation lists differ for deliberate design revision; the change is not falsely called preservation.\n\n\n **L741** The static batch assumption agrees at runtime size ten but fails at size five for twenty-one items.\n\n\n **L742** Withdrawing the simple design's structure takes seventeen units, retaining an eventual-exit cost.\n\n\n **L743** The coordinated path crosses the actual caller-2/callee-1 boundary.\n\n\n **L744** That boundary's public-contract verification and finite order obligation are fulfilled.\n\n\n **L745** The callee edit still crosses the boundary when caller verification is omitted.\n\n\n **L746** The omitted caller verification causes the obligation test to fail.\n\n\n **L747** An edge whose callee is component 7 does not match this edit path and is not crossed.\n\n\n **L748** The same edge and steps with sortedUnique behavior fail actual finite order preservation; decide checks all clauses of this concrete structural bundle.\n\n\n **L749** The same edge and steps with sortedUnique behavior fail actual finite order preservation; decide checks all clauses of this concrete structural bundle. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope.\n\n\n **L751** Generalizes individual capability from a candidate tag to an actual EngineeringDesign with its own paths.\n\n\n **L752** Generalizes individual capability from a candidate tag to an actual EngineeringDesign with its own paths.\n\n\n **L753** Requires an actual nonempty design path and a participating maintainer.\n\n\n **L754** Every actual path step must be executable with that maintainer's knowledge and the activity's tools.\n\n\n **L755** Every actual path step must be executable with that maintainer's knowledge and the activity's tools.\n\n\n **L757** Computes work from this design object's actual path units, so path mutations can change or preserve the total explicitly.\n\n\n **L758** Computes work from this design object's actual path units, so path mutations can change or preserve the total explicitly.\n\n\n **L760** Finds components whose own recorded batch assumptions differ from the proposed runtime size.\n\n\n **L761** Finds components whose own recorded batch assumptions differ from the proposed runtime size.\n\n\n **L763** The first facade adds a component, forwarding edge and verification step while preserving output; it supplies neither missing private knowledge nor removal of existing edit work.\n\n\n **L764** The first facade adds a component, forwarding edge and verification step while preserving output; it supplies neither missing private knowledge nor removal of existing edit work.\n\n\n **L765** The first facade adds a component, forwarding edge and verification step while preserving output; it supplies neither missing private knowledge nor removal of existing edit work.\n\n\n **L766** Constructs the first explicit boundary-introduction transformation on a complete design.\n\n\n **L767** The visible module and extension-point counts both increase by one.\n\n\n **L768** The wrapper appends an empty list to input before calling the original behavior, preserving the result.\n\n\n **L769** An absent original path stays absent; merely wrapping cannot create support for an unknown change.\n\n\n **L770** An existing path gains one public-contract verification unit at the new component identifier.\n\n\n **L771** Adds the original component-list length as a new component identifier; it is fresh for the concrete zero-through-seven starting design.\n\n\n **L772** Adds a forwarding edge from that new component to component 0 carrying the original signature label.\n\n\n **L773** Adds a forwarding edge from that new component to component 0 carrying the original signature label.\n\n\n **L774** Leaves all fixed batch assumptions unchanged, so the wrapper does not resolve their coupling.\n\n\n **L776** Applies the first facade transformation to the private design for a concrete increased-work counterexample.\n\n\n **L778** The second facade moves existing verification to the new component instead of adding work; real boundary and path changes still do not supply private knowledge or lower total work.\n\n\n **L779** The second facade moves existing verification to the new component instead of adding work; real boundary and path changes still do not supply private knowledge or lower total work.\n\n\n **L780** The second facade moves existing verification to the new component instead of adding work; real boundary and path changes still do not supply private knowledge or lower total work.\n\n\n **L781** Begins with the same boundary-introducing design, retaining its new component, edge and equivalent behavior.\n\n\n **L782** Begins with the same boundary-introducing design, retaining its new component, edge and equivalent behavior.\n\n\n **L783** Rebuilds the work paths from the original design's steps, removing the extra appended verification step of the first facade.\n\n\n **L784** Moves each original contractRunner step to the new component while preserving its knowledge, tool and units.\n\n\n **L785** Leaves every nonverification step unchanged, completing a relocation without changing work units.\n\n\n **L787** The concrete same-work design is the private design after this verification relocation.\n\n\n **L789** Begins a provenance comment attaching CoreReader.Engineering.structureNotCapability to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence.\n\n\n **L790** Records the source reference software-engineering.structural-judgment/p1 for CoreReader.Engineering.structureNotCapability, with direct-body SHA256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L791** Records the source reference software-engineering.structural-judgment/p2 for CoreReader.Engineering.structureNotCapability, with direct-body SHA256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L792** Closes the source-mapping comment for CoreReader.Engineering.structureNotCapability; executable declarations resume after the comment.\n\n\n **L793** Collects counterexamples showing that signature, module count, principle name and new boundaries do not alone prove the claimed capability or lower work.\n\n\n **L794** Private and sorted designs share a signature but give different order results on [2,1,2]; identical interface shape does not establish contract equivalence.\n\n\n **L795** Private and sorted designs share a signature but give different order results on [2,1,2]; identical interface shape does not establish contract equivalence.\n\n\n **L796** The private design's declared eight modules equal its actual component-list length.\n\n\n **L797** It contains eight actual recorded batch assumptions, not merely a module-count label.\n\n\n **L798** All eight components need assumption revision when runtime batch size changes to five.\n\n\n **L799** The private design carries the dependency-inversion principle name.\n\n\n **L800** Private and documented designs share all visible metadata.\n\n\n **L801** Despite that label, the successor cannot revise the private design because its paths need private layout knowledge.\n\n\n **L802** The successor can revise the documented design with its genuinely different guide-based paths.\n\n\n **L803** The first facade changes the actual boundary count from zero to one.\n\n\n **L804** It also increases actual component count from eight to nine.\n\n\n **L805** The new actual edge is exactly component 8→0 with the original list-function signature.\n\n\n **L806** The first facade retains the original observed output on [2,1,2].\n\n\n **L807** The original private design needs seventeen units for design revision.\n\n\n **L808** The first facade needs eighteen units after its extra verification step.\n\n\n **L809** Thus this actual boundary introduction does not reduce the intended design-revision work.\n\n\n **L810** The relocation variant also has the concrete edge 8→0.\n\n\n **L811** The relocation variant has nine actual components.\n\n\n **L812** Its design-revision path differs from the original because verification component identifiers moved.\n\n\n **L813** The relocation retains the original observed order result.\n\n\n **L814** Its total assigned work equals the original path's total exactly.\n\n\n **L815** That unchanged total is seventeen units.\n\n\n **L816** The successor still lacks required private knowledge after relocation, so the new boundary does not establish continuing capability.\n\n\n **L817** Proves the five concrete counterexample groups by decision procedures on their actual records, functions and arithmetic.\n\n\n **L819** Begins a provenance comment attaching CoreReader.Engineering.contractPreservation to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence.\n\n\n **L820** Records the source reference software-engineering.structural-judgment/p3 for CoreReader.Engineering.contractPreservation, with direct-body SHA256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L821** Closes the source-mapping comment for CoreReader.Engineering.contractPreservation; executable declarations resume after the comment.\n\n\n **L822** The general preservation theorem is polymorphic in inputs/outputs and keeps an explicitly supplied scope.\n\n\n **L823** Its premise already supplies equality of new and old behavior for every input in that scope.\n\n\n **L824** Returns that same universal scoped equality as PreservesOn; it does not derive universal preservation from finite tests.\n\n\n **L826** A single actual differing observation inside the declared scope refutes scoped preservation.\n\n\n **L827** Fixes the old/new functions, an input and proof that this input lies inside the scope.\n\n\n **L828** Assumes an actual output difference there and concludes that preservation cannot hold.\n\n\n **L829** Temporarily assumes scoped preservation.\n\n\n **L830** Specializes preservation to the in-scope counterexample and contradicts its known output difference.\n\n\n **L832** The revision-obligation theorem compares the same actual old/new observable contracts.\n\n\n **L833** Requires a report already satisfying the preservation-or-revision account.\n\n\n **L834** Also assumes that actual finite contract preservation fails.\n\n\n **L835** Eliminates the preservation alternative, leaving the report's revision duties; it does not manufacture an account from changed behavior alone.\n\n\n **L837** The retired behavior changes only input [99], which is outside the declared finite contract corpus, while retaining orderedUnique elsewhere.\n\n\n **L838** The retired behavior changes only input [99], which is outside the declared finite contract corpus, while retaining orderedUnique elsewhere.\n\n\n **L840** Begins a provenance comment attaching CoreReader.Engineering.contractCases to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence.\n\n\n **L841** Records the source reference software-engineering.structural-judgment/p3 for CoreReader.Engineering.contractCases, with direct-body SHA256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L842** Closes the source-mapping comment for CoreReader.Engineering.contractCases; executable declarations resume after the comment.\n\n\n **L843** Collects preservation, deliberate revision, missing-party rejection and procedure flexibility cases.\n\n\n **L844** The refactored contract has a valid account through finite preservation.\n\n\n **L845** The revised order/retry contract has a valid account through actual revision duties.\n\n\n **L846** An empty acknowledged-party list cannot account for the actual consumer/operator changes.\n\n\n **L847** The retired behavior preserves every declared finite input but differs at [99], demonstrating the scope limit.\n\n\n **L848** Changing the procedure name to paired audit keeps the account valid; no particular procedure is mandated. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope.\n\n\n **L850** Begins a provenance comment attaching CoreReader.Engineering.contractDistinctions to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence.\n\n\n **L851** Records the source reference software-engineering.structural-judgment/p3 for CoreReader.Engineering.contractDistinctions, with direct-body SHA256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L852** Closes the source-mapping comment for CoreReader.Engineering.contractDistinctions; executable declarations resume after the comment.\n\n\n **L853** Separates actual order preservation, retry change, party effects and accurate historical contract reporting.\n\n\n **L854** The append-empty refactor preserves the finite ordered contract.\n\n\n **L855** Sorting before de-duplication does not preserve that same order contract.\n\n\n **L856** At attempt index three the old threshold forbids retry but the new threshold allows it, making failure-policy change concrete.\n\n\n **L857** The combined order/retry contract therefore is not preserved.\n\n\n **L858** The fixed dependency map identifies exactly the consumer and operator as affected in this example.\n\n\n **L859** Acknowledging only the consumer omits the operator affected by retry change, so the revision account fails.\n\n\n **L860** Acknowledging only the consumer omits the operator affected by retry change, so the revision account fails.\n\n\n **L861** Changing both reported old-limit fields to five still fails because the independent actual old contract has threshold three.\n\n\n **L862** Changing both reported old-limit fields to five still fails because the independent actual old contract has threshold three.\n\n\n **L863** The unaltered normalRevision correctly accounts for the deliberate changes.\n\n\n **L864** Finite preservation still allows the intentionally out-of-scope difference at [99]; it is not all-input equivalence. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope.\n\n\n **L866** Revision concerns current choices under time-indexed evidence; it does not alter the truth of an already observed prediction.\n\n\n **L867** Revision concerns current choices under time-indexed evidence; it does not alter the truth of an already observed prediction.\n\n\n **L868** A revision state records the current evidence, maintenance setting, costs, objectives and selected design at one time.\n\n\n **L869** Orders states by a natural-number time index.\n\n\n **L870** Records expected future change directions.\n\n\n **L871** Records the amount of expected maintenance.\n\n\n **L872** Records who is expected to maintain the software.\n\n\n **L873** Records the relevant migration cost.\n\n\n **L874** Records the objective's capacity against that cost.\n\n\n **L875** Records the design chosen under those conditions.\n\n\n **L876** Automatically provides equality decisions and printable representations for RevisionState; these support concrete case evaluation, not a philosophical claim about that type.\n\n\n **L877** A revision record keeps actual and reported states plus a separately checkable prediction outcome and criticism coverage.\n\n\n **L878** Binds the report to a named software task.\n\n\n **L879** Carries the old state claimed by the report.\n\n\n **L880** Carries the current state.\n\n\n **L881** Preserves what the report records about the old state for comparison with independent history.\n\n\n **L882** Preserves what it records about the current state.\n\n\n **L883** States the earlier predicted batch count.\n\n\n **L884** States the actually observed batch count.\n\n\n **L885** Records whether the report declares the prediction successful; later checks bind this Boolean to actual historical equality.\n\n\n **L886** Lists change directions considered by this revision.\n\n\n **L887** Lists directions kept within the declared criticism scope.\n\n\n **L889** Material changes concern substantive grounds rather than a mere later timestamp or relabeled choice.\n\n\n **L890** A change in expected directions or maintenance amount counts as changed grounds.\n\n\n **L891** Changing the maintainers also changes the relevant conditions.\n\n\n **L892** Changed migration cost or objective capacity supplies another material-ground difference.\n\n\n **L894** The old state at time zero expects design revision, six maintenance units, the original maintainer, cost eight/capacity twelve and evolvable.\n\n\n **L895** The new state at time one expects deletion, two maintenance units, successor/agent maintainers, cost fourteen/capacity ten and simple.\n\n\n **L897** HistoricalEvidence is an input separate from the mutable report, anchoring the task, old state and past prediction/observation.\n\n\n **L898** Identifies which software the historical event concerns.\n\n\n **L899** Preserves the actual historical revision state.\n\n\n **L900** Preserves the historical prediction independently of the new report.\n\n\n **L901** Preserves the historical observed result independently of the report.\n\n\n **L903** The recorded event used a predictor fixed at ten while reality used runtime size five for twenty-one items; the mismatch is retained as event content.\n\n\n **L904** The recorded event used a predictor fixed at ten while reality used runtime size five for twenty-one items; the mismatch is retained as event content.\n\n\n **L905** Fixes the queue history to oldState, predicted count three and actual count five computed by the two real functions.\n\n\n **L906** Fixes the queue history to oldState, predicted count three and actual count five computed by the two real functions.\n\n\n **L908** Checks a report against this independently supplied historical object, rather than comparing report fields only with each other.\n\n\n **L909** The report's software identity must match the historical task.\n\n\n **L910** Both its old-state claim and recorded old state must equal the independent historical state.\n\n\n **L911** The report must retain the actual historical predicted count.\n\n\n **L912** It must retain the actual historical observed count.\n\n\n **L913** Time must advance, and the current-state record must accurately reflect the current state.\n\n\n **L914** A changed design choice requires material grounds to have changed; this condition alone is not a proof that every such redesign is substantively justified.\n\n\n **L915** The reported success flag must equal the decision of actual historical prediction/observation equality, preventing retrospective relabeling.\n\n\n **L916** Every considered direction must remain in the listed criticism scope; this finite coverage is not a universal proof of reflexive correctness.\n\n\n **L918** Begins a provenance comment attaching CoreReader.Engineering.RevisionAccount to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence.\n\n\n **L919** Records the source reference software-engineering.revision/p2 for CoreReader.Engineering.RevisionAccount, with direct-body SHA256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L920** Records the source reference software-engineering.revision/p1 for CoreReader.Engineering.RevisionAccount, with direct-body SHA256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L921** Closes the source-mapping comment for CoreReader.Engineering.RevisionAccount; executable declarations resume after the comment.\n\n\n **L922** Specializes the generic history-bound account to the fixed observed queue history.\n\n\n **L924** The anti-rewriting result works for any supplied history and report, not only the queue numbers.\n\n\n **L925** Assumes that the report satisfies the full account against that same historical object.\n\n\n **L926** Assumes the actual historical prediction differs from the observation.\n\n\n **L927** Concludes that an accurate report must mark the prediction unsuccessful.\n\n\n **L928** Extracts the account's success-flag equality and simplifies it using the historical failure premise, yielding false.\n\n\n **L930** Builds the ordinary revision report with accurate old/new states and the preserved failed forecast.\n\n\n **L931** Uses the same order-preserving queue identity as observedHistory.\n\n\n **L932** Actual and recorded states agree with oldState and newState respectively.\n\n\n **L933** Uses the actual static/live counts for twenty-one items at runtime size five.\n\n\n **L934** Truthfully marks that prediction unsuccessful.\n\n\n **L935** Considers all nine ordinary directions and keeps all nine within criticism scope.\n\n\n **L937** For this retention adapter, a supported alternative is a direction credible under the context's ground interpretation.\n\n\n **L939** Retention may be justified by the declared lack-of-contribution or concrete-cost conditions; this is an application criterion.\n\n\n **L940** One branch requires every listed alternative to lack credible support in the context.\n\n\n **L941** The other branch permits retention through an explicitly justified evolvable cost departure.\n\n\n **L943** The stable variant keeps the chosen design evolvable in both actual and recorded current states, while retaining changed evidence, honest failed prediction and criticism coverage.\n\n\n **L944** The stable variant keeps the chosen design evolvable in both actual and recorded current states, while retaining changed evidence, honest failed prediction and criticism coverage.\n\n\n **L945** The stable variant keeps the chosen design evolvable in both actual and recorded current states, while retaining changed evidence, honest failed prediction and criticism coverage.\n\n\n **L947** Begins a provenance comment attaching CoreReader.Engineering.revisionCases to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence.\n\n\n **L948** Records the source reference software-engineering.revision/p2 for CoreReader.Engineering.revisionCases, with direct-body SHA256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L949** Records the source reference software-engineering.revision/p1 for CoreReader.Engineering.revisionCases, with direct-body SHA256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L950** Closes the source-mapping comment for CoreReader.Engineering.revisionCases; executable declarations resume after the comment.\n\n\n **L951** Exhibits a valid revision with all five material-ground differences, a preserved prediction failure and two justifications for retention.\n\n\n **L952** The ordinary report satisfies the account against the fixed independent history.\n\n\n **L953** Its forecast changes from design revision to deletion.\n\n\n **L954** Its maintenance amount changes from six to two.\n\n\n **L955** Its maintainer set changes from the original author to successor and agent.\n\n\n **L956** Its migration cost changes from eight to fourteen.\n\n\n **L957** Its objective capacity changes from twelve to ten.\n\n\n **L958** The prediction three still differs from the actual five; revising the decision does not change this failure.\n\n\n **L959** A quantum-backend alternative lacking credible grounds supplies the no-supported-alternative retention case.\n\n\n **L960** A genuine migration-capacity threat supplies the cost-based retention case. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope.\n\n\n **L962** The successful observation set uses only runtime size ten with item counts twenty-one, thirty and forty.\n\n\n **L963** Records three revision identifiers, whose count alone will not establish correctness.\n\n\n **L964** Every named reviewer reports the same static predictor result, modeling agreement without adding independent support or changing the actual predictor.\n\n\n **L965** Every named reviewer reports the same static predictor result, modeling agreement without adding independent support or changing the actual predictor.\n\n\n **L967** The first tampering variant changes both claimed and recorded old forecasts together, testing that agreement between report fields cannot override independent history.\n\n\n **L968** The first tampering variant changes both claimed and recorded old forecasts together, testing that agreement between report fields cannot override independent history.\n\n\n **L969** The first tampering variant changes both claimed and recorded old forecasts together, testing that agreement between report fields cannot override independent history.\n\n\n **L971** The second variant changes the predicted count to five and calls it successful, attempting to rewrite the old prediction to match observation.\n\n\n **L972** The second variant changes the predicted count to five and calls it successful, attempting to rewrite the old prediction to match observation.\n\n\n **L974** The third variant changes the observed count to three and calls the prediction successful, attempting to rewrite the actual event.\n\n\n **L975** The third variant changes the observed count to three and calls the prediction successful, attempting to rewrite the actual event.\n\n\n **L977** The identity variant assigns the report to unrelated software while keeping its numerical data, testing task binding.\n\n\n **L978** The identity variant assigns the report to unrelated software while keeping its numerical data, testing task binding.\n\n\n **L980** Shows that fixed historical evidence rejects coordinated report-field tampering and software-identity substitution.\n\n\n **L981** The unchanged report remains valid.\n\n\n **L982** Changing both old-state fields cannot satisfy the independently fixed history.\n\n\n **L983** Rewriting the predicted count and success flag is rejected.\n\n\n **L984** Rewriting the observed count and success flag is also rejected.\n\n\n **L985** The independent history retains prediction three and observation five throughout these variants.\n\n\n **L986** A report for unrelated software fails the task-identity requirement.\n\n\n **L987** Computes all seven concrete validity/failure and historical-number clauses without editing the historical object.\n\n\n **L989** Begins a provenance comment attaching CoreReader.Engineering.revisionLimits to the source clauses listed below; the comment does not alter Lean meaning or prove correspondence.\n\n\n **L990** Records the source reference software-engineering.revision/p2 for CoreReader.Engineering.revisionLimits, with direct-body SHA256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L991** Records the source reference software-engineering.revision/p1 for CoreReader.Engineering.revisionLimits, with direct-body SHA256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99. This is a traceability binding, not a new premise or semantic proof.\n\n\n **L992** Closes the source-mapping comment for CoreReader.Engineering.revisionLimits; executable declarations resume after the comment.\n\n\n **L993** Collects limits on retrospective success, revision count, agreement, repeated local success and justified stability.\n\n\n **L994** The ordinary historical account is valid.\n\n\n **L995** Merely flipping reportedPredictionSucceeded to true invalidates the account.\n\n\n **L996** Three revisions have occurred in the explicit list, but their number supplies no correctness theorem.\n\n\n **L997** All three maintainers agree on the static result three, while the live result is five; agreement does not erase the counterexample.\n\n\n **L998** Every listed size-ten observation agrees between static and live predictors.\n\n\n **L999** Those repeated successes coexist with a failure at runtime size five.\n\n\n **L1000** The stable report remains history-valid and keeps the old design choice, showing revision openness need not force every act to change design.\n\n\n **L1001** The unsupported quantum-backend alternative still permits retaining the current design.\n\n\n **L1002** Builds the conjunction with finite decisions, leaving only the falsely reported-success account to an explicit reduction.\n\n\n **L1003** Builds the conjunction with finite decisions, leaving only the falsely reported-success account to an explicit reduction.\n\n\n **L1004** Expands the fixed history, actual report and material-change predicates so the false success claim is exposed as the concrete three-versus-five mismatch.\n\n\n **L1005** The remaining decidable contradiction is checked computationally.\n\n\n **L1007** Extracts each record's listed directions regardless of ground constructor; this extraction records forecast content and does not itself prove credibility.\n\n\n **L1008** Extracts each record's listed directions regardless of ground constructor; this extraction records forecast content and does not itself prove credibility.\n\n\n **L1010** Builds a current revision state from the actual context and selected design rather than independent report placeholders.\n\n\n **L1011** Sets time one and concatenates the directions listed in the actual context evidence into the forecast.\n\n\n **L1012** Copies maintenance amount and participating maintainers from the same activity.\n\n\n **L1013** Uses the selected design's actual assigned migration cost.\n\n\n **L1014** Uses the same context's migration objective capacity.\n\n\n **L1015** Records the actual chosen candidate.\n\n\n **L1017** The report retains historical data from stableRecord but binds software, actual current state and recorded current state to this context and chosen candidate.\n\n\n **L1018** The report retains historical data from stableRecord but binds software, actual current state and recorded current state to this context and chosen candidate.\n\n\n **L1020** Checks that the instantiated revision report really belongs to the shared engineering context and satisfies its fixed-history account.\n\n\n **L1021** Its software identifier equals the activity's actual identifier.\n\n\n **L1022** The same identifier matches historical evidence, and current maintenance equals the activity's schedule.\n\n\n **L1023** The same identifier matches historical evidence, and current maintenance equals the activity's schedule.\n\n\n **L1024** Current maintainers equal the actual participant list.\n\n\n **L1025** Current migration cost equals evolvable's assigned cost.\n\n\n **L1026** Current objective capacity equals the shared context's migration capacity.\n\n\n **L1027** Current objective capacity equals the shared context's migration capacity.\n\n\n **L1028** The recorded current choice is actually evolvable.\n\n\n **L1029** The fully bound report satisfies RevisionAccount; the concrete checks are decided from its actual fields. The closing by decide proves the stated concrete proposition by evaluating its decision procedure; it does not generalize beyond the displayed objects and scope.\n\n\n **L1031** The whole domain bundle retains actual subject, credibility, accounts and revision duties on one context. Its chosen finite application records do not claim universal engineering adequacy.\n\n\n **L1032** The whole domain bundle retains actual subject, credibility, accounts and revision duties on one context. Its chosen finite application records do not claim universal engineering adequacy.\n\n\n **L1033** The whole domain bundle retains actual subject, credibility, accounts and revision duties on one context. Its chosen finite application records do not claim universal engineering adequacy.\n\n\n **L1034** Combine the represented domain duties for one context and selected design. This bundle has no unconditional Meets field; priority applicability is not an overall requirement-rejection test.\n\n\n **L1035** Require ActivityScope and the conditional EvolutionPriority. If PriorityConditions is false, that implication holds vacuously; this conjunct does not reject the choice for unmet requirements, while the remaining domain duties still apply.\n\n\n **L1036** Requires actual credible grounds for the design-revision direction.\n\n\n **L1037** If a departure is recorded, it must be a justified concrete-cost departure; absent departure creates no extra exception.\n\n\n **L1038** Requires the successor's actual design-revision capability with explicit revision of obligations.\n\n\n **L1039** Requires a structural account matching the same activity, chosen candidate and design-revision evidence.\n\n\n **L1040** Requires a preservation-or-revision account comparing the selected design's order contract with the actual design-revision contract.\n\n\n **L1041** Requires the same context/candidate revision report to satisfy the fixed independent historical account.\n\n\n **L1043** Constructs actual whole-domain satisfaction for the shared continuing evolvable example.\n\n\n **L1044** Computes the concrete subject, priority, credibility, change, structural, contract and history obligations; leaves the conditional departure check.\n\n\n **L1045** The ordinary context records departure=none, so the implication requiring justification for a recorded departure is vacuously satisfied; priority itself still has actual applicability and no cost escape.\n\n\n **L1047** Closes the engineering namespace; all declarations above remain available under CoreReader.Engineering.\n\n\n### `leanified/CoreReader/Engineering/Integration.lean`\n\n\n```lean\nimport CoreReader.Engineering.Domain\nimport CoreReader.Engineering.Reflection\nimport CoreReader.Engineering.SelfApplication\n\nnamespace CoreReader.Engineering\n\nopen CoreReader.Logic CoreReader.Evidence CoreReader.Adopted\n\n/- All interpretations below share this activity, requirements, evidence and\ncost limits. Only the selected implementation and its stated value priority vary. -/\nabbrev sharedContext : Context := currentContinuing\n\ndef maintainedOutput (chosen : Candidate) (n : Nat) : Nat :=\n (behavior chosen [n]).headD 0\n\ndef chosenImplementation (chosen : Candidate) : CoreReader.Choice.Implementation where\n name := \"order-preserving queue\"\n conventional := chosen == .presentSimple\n established := chosen == .presentSimple\n run := maintainedOutput chosen\n cost := abstractionComplexity chosen\n domain _ := True\n explanation := maintainedOutput chosen\n trace n := [maintainedOutput chosen n]\n\n/- This Core choice projection checks the queue's one-item observable contract\nand present understanding budget. Domain retains its additional required checks. -/\ndef chosenRequirements : CoreReader.Choice.Requirements where\n inputs _ := True\n expected n := n\n budget := sharedContext.limits.capacity .understanding\n values _ := True\n\ndef chosenReasons : List CoreReader.Choice.Reason :=\n [.method .output, .method .simplicity]\n\ntheorem maintainedOutputCorrect (chosen : Candidate) (n : Nat) :\n maintainedOutput chosen n = n := by\n rfl\n\ntheorem implementationReasoned (chosen : Candidate)\n (budget : abstractionComplexity chosen ≤ chosenRequirements.budget) :\n choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons := by\n refine ⟨⟨fun n _ => maintainedOutputCorrect chosen n, budget⟩,\n .method .output, ?_, ?_⟩\n · simp [chosenReasons]\n · exact ⟨trivial, fun n _ => maintainedOutputCorrect chosen n⟩\n\n/- This reported capability concerns actual paths for each maintainer. Zero\nrecords the unavailable path, not an assertion that an unsupported path exists. -/\ndef capabilityOutput (chosen : Candidate) (input : Nat) : Nat :=\n let maintainer := if input = 0 then Maintainer.original\n else if input = 1 then Maintainer.successor else Maintainer.agent\n if decide (CanChange sharedContext.activity chosen maintainer .designRevision)\n then changeWork chosen .designRevision else 0\n\ndef engineeringProcess (chosen : Candidate) : Process :=\n ⟨capabilityOutput chosen, none⟩\n\ndef engineeringCapability (chosen : Candidate) : Claim Process :=\n fun process => ∀ input, process.output input = capabilityOutput chosen input\n\ntheorem engineeringCapabilityGrounded (chosen : Candidate) :\n capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen) := by\n exact grounds012Singleton _ (processContractDischarged _ _ (fun _ => rfl))\n\ntheorem actualCapabilityContrast :\n (engineeringProcess .presentSimple).output 0 = 17 ∧\n (engineeringProcess .presentSimple).output 1 = 0 ∧\n (engineeringProcess .presentSimple).output 2 = 0 ∧\n (engineeringProcess .evolvable).output 0 = 6 ∧\n (engineeringProcess .evolvable).output 1 = 6 ∧\n (engineeringProcess .evolvable).output 2 = 6 := by decide\n\n/- A recorded threshold test measures present abstraction complexity in this\nfinite model. It does not observe future maintainability or establish a value. -/\ndef presentBudgetRecord : Record Candidate :=\n ⟨fun candidate => decide (abstractionComplexity candidate ≤ 3), true⟩\n\nabbrev presentBudgetClaim : Claim Candidate := fun candidate => abstractionComplexity candidate ≤ 3\n\ntheorem budgetObservationMeaning (candidate : Candidate) :\n Compatible [presentBudgetRecord] candidate ↔ presentBudgetClaim candidate := by\n constructor\n · intro observed\n have result := observed presentBudgetRecord (List.mem_singleton.mpr rfl)\n exact of_decide_eq_true result\n · intro enough record member\n cases List.mem_singleton.mp member\n exact decide_eq_true enough\n\ndef budgetEmpiricalFacet : Facet Candidate :=\n .empirical [presentBudgetRecord] (fun _ => True) presentBudgetClaim (fun _ => True)\n\ntheorem budgetEmpiricalDischarged : FacetDischarged budgetEmpiricalFacet := by\n refine ⟨⟨.evolvable, (budgetObservationMeaning _).2 (by decide), trivial⟩, ?_, ?_⟩\n · intro candidate observed _\n exact (budgetObservationMeaning candidate).1 observed\n · intro _ _; trivial\n\ndef capacityClaim : Claim Candidate :=\n fun candidate => abstractionComplexity candidate ≤ sharedContext.limits.capacity .understanding\n\ndef capacityAssumptions : Theory Candidate := singleton presentBudgetClaim\n\ndef budgetInferentialFacet : Facet Candidate := .inferential capacityAssumptions capacityClaim\n\ntheorem budgetInferentialDischarged : FacetDischarged budgetInferentialFacet := by\n refine ⟨⟨.evolvable, (modelsSingleton _ _).2 (by decide)⟩, ?_⟩\n intro candidate premises\n have small := (modelsSingleton _ _).1 premises\n exact Nat.le_trans small (by decide)\n\ndef budgetScopeAccount : ScopeAccount Candidate where\n claim := presentBudgetClaim\n conditions := fun _ => True\n observationScope := fun _ => True\n relevant := fun a b => behavior a [2, 1, 2] = behavior b [2, 1, 2]\n compared := fun a b => presentBudgetClaim a ∧ presentBudgetClaim b\n used method := method = .measurement\n role _ := \"threshold observation of present complexity; no future-performance conclusion\"\n explains method text claim conditions := method = .measurement ∧\n text = \"threshold observation of present complexity; no future-performance conclusion\" ∧\n claim = presentBudgetClaim ∧ conditions = (fun _ => True)\n\ntheorem budgetScopeExplained : scopeSpecification budgetScopeAccount := by\n constructor\n · intro a b _; exact ⟨trivial, trivial, trivial, trivial, rfl⟩\n · intro method hm\n exact ⟨by change \"threshold observation of present complexity; no future-performance conclusion\" ≠ \"\"; decide,\n hm, rfl, rfl, rfl⟩\n\n/- The unchanged observation cannot justify a stronger complexity bound. -/\ntheorem budgetObservationLimit :\n Compatible [presentBudgetRecord] .evolvable ∧\n ¬ Supports [presentBudgetRecord] (fun candidate => abstractionComplexity candidate ≤ 1) := by\n refine ⟨(budgetObservationMeaning _).2 (by decide), ?_⟩\n intro support\n have impossible := support .evolvable ((budgetObservationMeaning _).2 (by decide))\n exact (by decide : ¬ (3 ≤ 1)) impossible\n\n/- The policy values expansion while keeping every represented organization,\nmethod and principle form revisable. It does not assert that a revision occurs. -/\ndef engineeringPolicy : CoreReader.Agency.Policy where\n worthPursuing aim :=\n (aim = .expandUnderstandingAndConstruction ∧ coreAdopted .generation = true) ∨\n aim = .preserveSafeOperation\n current form := form.version = 1\n revisable form := ∃ next, form.version < next ∧ coreAdopted .generation = true\n permitsVersion old next := old ≤ next\n\ntheorem engineeringGenerative : generationSpecification engineeringPolicy := by\n exact ⟨Or.inl ⟨rfl, rfl⟩, fun form _ => ⟨form.version + 1, Nat.lt_succ_self _, rfl⟩⟩\n\n/- Own facts are mathematical reports about this model and its recorded state.\nTheir inferential tasks do not replace the separate empirical or value tasks. -/\ninductive OwnFact\n | selected | requirements | capacity | capability | forecast | revision\n | generativePolicy | reflection | coreAdoption (principle : CoreCommitment)\n deriving DecidableEq, Repr\n\nabbrev ownFactClaim (adopted : Candidate) : OwnFact → Claim Candidate\n | .selected => fun candidate => candidate = adopted\n | .requirements => fun candidate => Meets sharedContext.required (sharedContext.profiles candidate)\n | .capacity => capacityClaim\n | .capability => fun candidate => engineeringCapability candidate (engineeringProcess candidate)\n | .forecast => fun _ => staticBatch 21 10 = liveBatch 21 10 ∧ staticBatch 21 5 ≠ liveBatch 21 5\n | .revision => fun candidate => RevisionAccount (revisionFor sharedContext candidate)\n | .generativePolicy => fun _ => generationSpecification engineeringPolicy\n | .reflection => fun candidate => reflexivitySpecification\n (selfModel candidate).rules (selfModel candidate).self (selfModel candidate).performed\n | .coreAdoption principle => (governancePosition principle).commitment\n\ntheorem actualOwnFact (chosen : Candidate)\n (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) (fact : OwnFact) :\n ownFactClaim chosen fact chosen := by\n cases fact with\n | selected => rfl\n | requirements => cases chosen <;> decide\n | capacity => rcases ordinary with rfl | rfl <;> change _ ≤ 12 <;> decide\n | capability => intro _; rfl\n | forecast => exact ⟨rfl, by decide⟩\n | revision => rcases ordinary with rfl | rfl <;> decide\n | generativePolicy => exact engineeringGenerative\n | reflection => exact currentSelfApplication chosen ordinary\n | coreAdoption _ => rfl\n\ndef ownFactPremises (chosen : Candidate) : Theory Candidate :=\n singleton (fun candidate => candidate = chosen)\n\ntheorem actualOwnFactGrounded (chosen : Candidate)\n (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) (fact : OwnFact) :\n inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact) := by\n apply grounds012Singleton\n refine ⟨⟨chosen, (modelsSingleton _ _).2 rfl⟩, ?_⟩\n intro candidate same\n have identity := (modelsSingleton _ _).1 same\n subst candidate\n exact actualOwnFact chosen ordinary fact\n\n/- In this fixed applicable context, the actual priority rule and the adopted\nevolution value select exactly the same candidate. This identity connects its\nvalue grounds to the normative rule, not merely to an adoption label. -/\ntheorem priorityValueMeaning (candidate : Candidate) :\n (selectionPosition .evolvable).commitment candidate ↔\n EvolutionPriority sharedContext candidate := by\n constructor\n · intro selected\n change candidate = .evolvable at selected\n subst candidate\n exact currentDomainSatisfied.2.1\n · intro priority\n exact (priorityWhenApplicable sharedContext candidate priority\n currentPriorityConditions currentNoThreat.2).1\n\ntheorem priorityGrounds :\n Grounds012 (EvolutionPriority sharedContext) canonicalArticulation\n [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) := by\n have same : (selectionPosition .evolvable).commitment = EvolutionPriority sharedContext :=\n funext (fun candidate => propext (priorityValueMeaning candidate))\n rw [← same]\n exact selectionGrounded .evolvable (Or.inr rfl)\n\n/- Facts of adoption remain distinct from the actual normative contents. Each\nconstructor below denotes its full represented duty, with its original task,\nconditions, reasons and scope. Domain duties enter only for the domain adopter.\nConsistency is the constraint on the resulting whole theory below; it is not\nencoded as a self-referential proposition in that theory's own definition. -/\ninductive OwnNorm\n | generation | reflection | empirical | inferential | principleValue (principle : CoreCommitment)\n | selectionValue | scope | capability | choice | ownGrounds (fact : OwnFact)\n | domain | priorityValue\n deriving DecidableEq, Repr\n\ndef normApplies (adopted : Candidate) : OwnNorm → Prop\n | .domain | .priorityValue => adopted = .evolvable\n | _ => True\n\ndef ownNormClaim (adopted : Candidate) : OwnNorm → Claim Candidate\n | .generation => fun _ => generationSpecification engineeringPolicy\n | .reflection => fun candidate => reflexivitySpecification\n (selfModel candidate).rules (selfModel candidate).self (selfModel candidate).performed\n | .empirical => fun _ => empiricalSpecification [presentBudgetRecord] (fun _ => True)\n presentBudgetClaim (fun _ => True)\n | .inferential => fun _ => inferentialSpecification capacityAssumptions capacityClaim\n | .principleValue principle => fun _ => valueSpecification (governancePosition principle)\n | .selectionValue => fun candidate => valueSpecification (selectionPosition adopted) ∧\n (selectionPosition adopted).commitment candidate\n | .scope => fun _ => scopeSpecification budgetScopeAccount\n | .capability => fun candidate => capabilitySpecification\n (engineeringProcess candidate) (engineeringCapability candidate)\n | .choice => fun candidate => choiceSpecification\n chosenRequirements (chosenImplementation candidate) chosenReasons\n | .ownGrounds fact => fun _ => inferentialSpecification\n (ownFactPremises adopted) (ownFactClaim adopted fact)\n | .domain => fun candidate => DomainSatisfied sharedContext candidate\n | .priorityValue => fun _ => Grounds012 (EvolutionPriority sharedContext) canonicalArticulation\n [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable))\n\ntheorem actualOwnNorm (chosen : Candidate)\n (ordinary : chosen = .presentSimple ∨ chosen = .evolvable)\n (norm : OwnNorm) (applicable : normApplies chosen norm) : ownNormClaim chosen norm chosen := by\n cases norm with\n | generation => exact engineeringGenerative\n | reflection => exact currentSelfApplication chosen ordinary\n | empirical => exact grounds012Singleton _ budgetEmpiricalDischarged\n | inferential => exact grounds012Singleton _ budgetInferentialDischarged\n | principleValue principle => exact governanceGrounded principle\n | selectionValue => exact ⟨selectionGrounded chosen ordinary, rfl⟩\n | scope => exact budgetScopeExplained\n | capability => exact engineeringCapabilityGrounded chosen\n | choice =>\n apply implementationReasoned\n rcases ordinary with rfl | rfl <;> change _ ≤ 12 <;> decide\n | ownGrounds fact => exact actualOwnFactGrounded chosen ordinary fact\n | domain =>\n change chosen = .evolvable at applicable\n subst chosen\n exact currentDomainSatisfied\n | priorityValue => exact priorityGrounds\n\ndef ownFactTheory (chosen : Candidate) : Theory Candidate :=\n fun claim => ∃ fact : OwnFact, claim = ownFactClaim chosen fact\n\ndef ownNormTheory (chosen : Candidate) : Theory Candidate :=\n fun claim => ∃ norm : OwnNorm, normApplies chosen norm ∧ claim = ownNormClaim chosen norm\n\n/- The consequence relation now acts on all these facts and normative contents\ntogether, including the implications of their union. -/\ndef ownTheory (chosen : Candidate) : Theory Candidate :=\n union (ownFactTheory chosen) (ownNormTheory chosen)\n\ntheorem allNormativeContentHeld (chosen : Candidate) (norm : OwnNorm)\n (applicable : normApplies chosen norm) : ownTheory chosen (ownNormClaim chosen norm) :=\n Or.inr ⟨norm, applicable, rfl⟩\n\ntheorem nonemptyOwnObjects (chosen : Candidate) :\n ownTheory chosen (ownFactClaim chosen .selected) ∧\n ownTheory chosen (ownFactClaim chosen (.coreAdoption .grounds)) ∧\n (.activity : ReviewObject) ∈ (selfModel chosen).objects ∧\n (.commitment .grounds : ReviewObject) ∈ (selfModel chosen).objects := by\n refine ⟨Or.inl ⟨.selected, rfl⟩, Or.inl ⟨.coreAdoption .grounds, rfl⟩, ?_, ?_⟩ <;>\n simp [selfModel, reviewObjects, coreCommitments]\n\ndef comparisonContext (chosen : Candidate) : CoreReader.Logic.Context Candidate OwnFact where\n assumptions := ownFactPremises chosen\n meaning := ownFactClaim chosen\n scope := valueScope\n\ndef engineeringSnapshot (chosen : Candidate) (revision : Nat) : Snapshot Candidate OwnFact :=\n ⟨ownTheory chosen, comparisonContext chosen, revision⟩\n\ntheorem currentAdmissible (chosen : Candidate)\n (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) :\n Admissible (ownTheory chosen) (comparisonContext chosen) chosen := by\n refine ⟨?_, (modelsSingleton _ _).2 rfl, ?_⟩\n · intro claim held\n rcases held with factHeld | normHeld\n · obtain ⟨fact, rfl⟩ := factHeld\n exact actualOwnFact chosen ordinary fact\n · obtain ⟨norm, applicable, rfl⟩ := normHeld\n exact actualOwnNorm chosen ordinary norm applicable\n · rcases ordinary with rfl | rfl <;> change _ ≤ 3 <;> decide\n\ntheorem currentConsistency (chosen : Candidate)\n (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) :\n consistencySpecification (engineeringSnapshot .evolvable 0)\n (engineeringSnapshot chosen 1) true := by\n exact ⟨consequenceConsistency _ _ ⟨chosen, currentAdmissible chosen ordinary⟩, fun _ => rfl⟩\n\ntheorem wholeClaimGrounded (chosen : Candidate)\n (ordinary : chosen = .presentSimple ∨ chosen = .evolvable)\n (claim : Claim Candidate) (held : ownTheory chosen claim) :\n inferentialSpecification (ownFactPremises chosen) claim := by\n apply grounds012Singleton\n refine ⟨⟨chosen, (modelsSingleton _ _).2 rfl⟩, ?_⟩\n intro candidate same\n have identity := (modelsSingleton _ _).1 same\n subst candidate\n exact (currentAdmissible chosen ordinary).1 claim held\n\n/- Keeping the same adoption marker does not conceal contradictory normative\ncontents. Both demands act on the very same candidate, question and scope. -/\ndef incompatibleNormTheory : Theory Candidate :=\n union (singleton (fun candidate => candidate = .presentSimple))\n (singleton (fun candidate => candidate ≠ .presentSimple))\n\ndef incompatibleNormContext : CoreReader.Logic.Context Candidate Unit :=\n ⟨emptyTheory, fun _ candidate => candidate = .presentSimple, fun _ => True⟩\n\ntheorem normativeContentVariation :\n coreAdopted .choice = true ∧\n ¬ Consistent incompatibleNormTheory incompatibleNormContext ∧\n normApplies .evolvable .domain ∧ ¬ normApplies .presentSimple .domain ∧\n ownTheory .evolvable (ownNormClaim .evolvable .domain) ∧\n ¬ ownTheory .presentSimple (ownNormClaim .presentSimple .domain) := by\n refine ⟨rfl, ?_, rfl, by unfold normApplies; decide, allNormativeContentHeld _ _ rfl, ?_⟩\n · apply conflictRequiresChange _ _ ()\n · intro candidate admissible\n change candidate = .presentSimple\n exact (modelsSingleton (fun c : Candidate => c = .presentSimple) candidate).1\n ((modelsUnion _ _ _).1 admissible.1).1\n · intro candidate admissible\n change candidate ≠ .presentSimple\n exact (modelsSingleton (fun c : Candidate => c ≠ .presentSimple) candidate).1\n ((modelsUnion _ _ _).1 admissible.1).2\n · intro held\n have domain := (currentAdmissible .presentSimple (Or.inl rfl)).1 _ held\n exact currentSimpleViolates domain.2.1\n\n/- Every field is an actual satisfaction or support condition. Value accounts\nand assessment completion do not replace the normative fields they explain.\nThe identity field limits this implementation to its disclosed common context. -/\nstructure Inherited (ctx : Context) (chosen : Candidate) : Prop where\n sameContext : ctx = sharedContext\n generation : generationSpecification engineeringPolicy\n consistency : consistencySpecification (engineeringSnapshot .evolvable 0)\n (engineeringSnapshot chosen 1) true\n reflection : reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self\n (selfModel chosen).performed\n ownPrincipleGrounds : ∀ principle, valueSpecification (governancePosition principle)\n choiceValueGrounds : valueSpecification (selectionPosition chosen)\n empiricalGrounds : empiricalSpecification [presentBudgetRecord] (fun _ => True)\n presentBudgetClaim (fun _ => True)\n inferentialGrounds : inferentialSpecification capacityAssumptions capacityClaim\n scopeAccount : scopeSpecification budgetScopeAccount\n capabilityGrounds : capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen)\n implementationChoice : choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons\n ownClaimGrounds : ∀ fact, inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact)\n observedHere : Compatible [presentBudgetRecord] chosen\n selectionActuallyAdopted : (selectionPosition chosen).commitment chosen\n currentOwnClaims : Models (ownTheory chosen) chosen\n fullNormativeContents : ∀ norm, normApplies chosen norm →\n ownTheory chosen (ownNormClaim chosen norm)\n wholeClaimGrounds : ∀ claim, ownTheory chosen claim →\n inferentialSpecification (ownFactPremises chosen) claim\n\ntheorem inheritedCurrent (chosen : Candidate)\n (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) :\n Inherited sharedContext chosen := by\n refine ⟨rfl, engineeringGenerative, currentConsistency chosen ordinary,\n currentSelfApplication chosen ordinary, governanceGrounded,\n selectionGrounded chosen ordinary, grounds012Singleton _ budgetEmpiricalDischarged,\n grounds012Singleton _ budgetInferentialDischarged, budgetScopeExplained,\n engineeringCapabilityGrounded chosen, ?_, actualOwnFactGrounded chosen ordinary,\n ?_, rfl, (currentAdmissible chosen ordinary).1,\n allNormativeContentHeld chosen, wholeClaimGrounded chosen ordinary⟩\n · apply implementationReasoned\n rcases ordinary with rfl | rfl <;> change _ ≤ 12 <;> decide\n · apply (budgetObservationMeaning _).2\n rcases ordinary with rfl | rfl <;> change _ ≤ 3 <;> decide\n\n/- Mutual application extracts duties for the same system, principles, claims\nand actual chosen implementation. It retains the full Inherited premise. -/\n/-- organon-map CoreReader.Engineering.inheritedMutualApplication\norganon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\ntheorem inheritedMutualApplication (ctx : Context) (chosen : Candidate)\n (inherited : Inherited ctx chosen) :\n generationSpecification engineeringPolicy ∧\n reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self\n (selfModel chosen).performed ∧\n (∀ principle, valueSpecification (governancePosition principle)) ∧\n capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen) ∧\n choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons ∧\n (∀ fact, inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact)) ∧\n (∀ norm, normApplies chosen norm → ownTheory chosen (ownNormClaim chosen norm)) ∧\n (∀ claim, ownTheory chosen claim → inferentialSpecification (ownFactPremises chosen) claim) ∧\n consistencySpecification (engineeringSnapshot .evolvable 0)\n (engineeringSnapshot chosen 1) true :=\n ⟨inherited.generation, inherited.reflection, inherited.ownPrincipleGrounds,\n inherited.capabilityGrounds, inherited.implementationChoice, inherited.ownClaimGrounds,\n inherited.fullNormativeContents, inherited.wholeClaimGrounds, inherited.consistency⟩\n\n/-- organon-map CoreReader.Engineering.inheritedMutualCases\norganon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\ntheorem inheritedMutualCases :\n Inherited sharedContext .evolvable ∧\n valueSpecification (governancePosition .grounds) ∧\n capabilitySpecification (engineeringProcess .evolvable) (engineeringCapability .evolvable) ∧\n choiceSpecification chosenRequirements (chosenImplementation .evolvable) chosenReasons ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧\n (.generationRule : ReviewObject) ∈ (selfModel .evolvable).objects ∧\n (.assessmentRule : ReviewObject) ∈ (selfModel .evolvable).objects ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .assessmentRule, .revision⟩) = .counterexample :=\n ⟨inheritedCurrent .evolvable (Or.inr rfl), governanceGrounded .grounds,\n engineeringCapabilityGrounded .evolvable,\n (inheritedCurrent .evolvable (Or.inr rfl)).implementationChoice,\n (actualSelfCriticism .evolvable).2.2.1,\n (ownRuleIdentity .evolvable .generation .revision).1,\n (ownRuleIdentity .evolvable .assessment .revision).1,\n (ownRuleContentVariation .evolvable).2.2.2.2.1⟩\n\n/- In the adopter's same context, the actual priority object and its own\nassessment method remain within the inherited criticism/generation contract. -/\n/-- organon-map CoreReader.Engineering.priorityRemainsReflexive\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\nextensions#p1 sha256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66\nsoftware-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\nsoftware-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99\n-/\ntheorem priorityRemainsReflexive (ctx : Context) (chosen : Candidate)\n (inherited : Inherited ctx chosen) (domain : DomainSatisfied ctx chosen)\n (applicable : PriorityConditions ctx) (noDeparture : ¬ JustifiedDeparture ctx .evolvable) :\n chosen = .evolvable ∧\n (.priority : ReviewObject) ∈ (selfModel chosen).objects ∧\n reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self\n (selfModel chosen).performed ∧\n (∀ principle, valueSpecification (governancePosition principle)) ∧\n Grounds012 (EvolutionPriority ctx) canonicalArticulation\n [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) ∧\n ownTheory chosen (ownNormClaim chosen .domain) ∧\n consistencySpecification (engineeringSnapshot .evolvable 0)\n (engineeringSnapshot chosen 1) true := by\n have selected := (priorityWhenApplicable ctx chosen domain.2.1 applicable noDeparture).1\n refine ⟨selected, ?_, inherited.reflection, inherited.ownPrincipleGrounds,\n ?_, allNormativeContentHeld chosen .domain selected, inherited.consistency⟩\n · subst chosen; decide\n · rw [inherited.sameContext]\n exact priorityGrounds\n\n/-- organon-map CoreReader.Engineering.priorityReflexiveCases\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\nextensions#p1 sha256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66\nsoftware-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\nsoftware-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99\n-/\ntheorem priorityReflexiveCases :\n (.priority : ReviewObject) ∈ (selfModel .evolvable).objects ∧\n objectTest .priority (.evolvable, 10) = true ∧\n (selfModel .evolvable).performed ⟨0, 1⟩ ⟨0, .priority, .revision⟩\n ((selfModel .evolvable).input ⟨0, .priority, .revision⟩)\n (.assessed .supportedWithinScope) ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧\n objectTest .evolutionMethod (.evolvable, 10) = true ∧\n objectTest .evolutionMethod (.evolvable, 5) = false ∧\n Grounds012 (EvolutionPriority sharedContext) canonicalArticulation\n [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .assessmentRule, .revision⟩) = .counterexample := by\n refine ⟨by decide, by decide, ?_, (actualSelfCriticism .evolvable).2.2.1,\n (actualSelfCriticism .evolvable).1, (actualSelfCriticism .evolvable).2.1,\n priorityGrounds, (ownRuleContentVariation .evolvable).2.2.2.2.1⟩\n exact ⟨⟨rfl, by decide⟩, rfl, .assessment, rfl, rfl⟩\n\n/- The witness is nonempty and satisfies the entire represented inherited and\ndomain bundles in the very same continuing activity, with active priority. -/\n/-- organon-map CoreReader.Engineering.jointWitness\norganon.charter.overview#p2 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c\norganon.charter.overview#p3 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c\norganon.charter.self-transcendence#p1 sha256 f4ca590e2ae15e3882f70c7b2bc46a8911c97cee547c8b137b5493fbf862c8c0\norganon.charter.self-transcendence.orientation#p1 sha256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf\norganon.charter.self-transcendence.non-finality#p1 sha256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8\norganon.charter.self-transcendence.limits#p1 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d\norganon.charter.self-transcendence.limits#p2 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d\norganon.charter.consistency#p1 sha256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42\norganon.charter.consistency.meaning#p1 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75\norganon.charter.reflexivity#p1 sha256 13293b45c2fa89068c68ae7ef3c5df38f0efadb3ef3873d78a5ba67d9691a757\norganon.charter.reflexivity.meaning#p1 sha256 8a2caede01a43d8b6c60b54c78ac089c51868e9956f316948077ccee2e45c9cc\norganon.charter.reflexivity.limits#p1 sha256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc\norganon.grounds#p1 sha256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6\norganon.grounds.assessment#p1 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.scope#p1 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.scope#p2 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.scope#p3 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.capabilities#p1 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0\norganon.grounds.capabilities#p2 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0\norganon.grounds.implementations#p1 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c\norganon.grounds.implementations#p2 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c\norganon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870\norganon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\nextensions#p1 sha256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66\nsoftware-engineering.purpose#p1 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.purpose#p2 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-meaning#p1 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6\nsoftware-engineering.evolution-meaning#p2 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6\nsoftware-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\nsoftware-engineering.structural-judgment#p2 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\nsoftware-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\nsoftware-engineering.revision#p1 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99\nsoftware-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99\n-/\ntheorem jointWitness :\n ∃ ctx : Context, ∃ chosen : Candidate,\n ctx = sharedContext ∧ chosen = .evolvable ∧\n Inherited ctx chosen ∧ DomainSatisfied ctx chosen ∧\n PriorityConditions ctx ∧ ¬ HasThreat ctx .evolvable ∧\n abstractionComplexity .presentSimple < abstractionComplexity chosen ∧\n CanChange ctx.activity chosen .successor .designRevision ∧\n CanChange ctx.activity chosen .agent .designRevision ∧\n ownTheory chosen (ownFactClaim chosen .selected) ∧\n (.commitment .grounds : ReviewObject) ∈ (selfModel chosen).objects ∧\n Admissible (ownTheory chosen) (comparisonContext chosen) chosen := by\n exact ⟨sharedContext, .evolvable, rfl, rfl,\n inheritedCurrent .evolvable (Or.inr rfl), currentDomainSatisfied,\n currentPriorityConditions, currentNoThreat.1, by decide, by decide, by decide,\n (nonemptyOwnObjects .evolvable).1, (nonemptyOwnObjects .evolvable).2.2.2,\n currentAdmissible .evolvable (Or.inr rfl)⟩\n\n/- The countermodel adopts a supported present-simplicity value and actually\nchooses that option. Every inherited duty still holds. The domain conditions\nare active; neither lifecycle nor threatened costs supplies an escape. -/\n/-- organon-map CoreReader.Engineering.inheritedDoesNotEntailPriority\norganon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\nextensions#p1 sha256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66\nsoftware-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\n-/\ntheorem inheritedDoesNotEntailPriority :\n ∃ ctx : Context, ∃ chosen : Candidate,\n ctx = sharedContext ∧ chosen = .presentSimple ∧\n Inherited ctx chosen ∧ PriorityConditions ctx ∧\n Continuing ctx.activity ∧ ¬ BoundedLifecycle ctx.activity ∧\n ¬ HasThreat ctx .evolvable ∧ ¬ JustifiedDeparture ctx .evolvable ∧\n Meets ctx.required (ctx.profiles .presentSimple) ∧\n Meets ctx.required (ctx.profiles .evolvable) ∧\n credible ctx.evidence .designRevision ∧\n CanChange ctx.activity .evolvable .successor .designRevision ∧\n CanChange ctx.activity .evolvable .agent .designRevision ∧\n changeWork .evolvable .designRevision < changeWork chosen .designRevision ∧\n abstractionComplexity chosen < abstractionComplexity .evolvable ∧\n valueSpecification (selectionPosition chosen) ∧\n (selectionPosition chosen).commitment chosen ∧\n ¬ EvolutionPriority ctx chosen := by\n exact ⟨sharedContext, .presentSimple, rfl, rfl,\n inheritedCurrent .presentSimple (Or.inl rfl), currentPriorityConditions,\n by decide, by decide, currentNoThreat.1, currentNoThreat.2,\n by decide, by decide, by decide, by decide, by decide, by decide, by decide,\n selectionGrounded .presentSimple (Or.inl rfl), rfl, currentSimpleViolates⟩\n\nend CoreReader.Engineering\n```\n\n\n\n **L1** Import CoreReader.Engineering.Domain, making its declarations and transitive dependencies available; this line adds no new proposition.\n\n\n **L2** Import CoreReader.Engineering.Reflection, making its declarations and transitive dependencies available; this line adds no new proposition.\n\n\n **L3** Import CoreReader.Engineering.SelfApplication, making its declarations and transitive dependencies available; this line adds no new proposition.\n\n\n **L5** Open namespace CoreReader.Engineering for the following declarations.\n\n\n **L7** Allow unqualified references to declarations in CoreReader.Logic CoreReader.Evidence CoreReader.Adopted; their meaning is unchanged.\n\n\n **L9** Comment fixes the activity, requirements and evidence shared by all interpretations here.\n\n\n **L10** Comment also fixes cost limits while permitting the chosen implementation and stated value to vary.\n\n\n **L11** All integrated claims use sharedContext, definitionally the fixed currentContinuing context.\n\n\n **L13** For a chosen design and natural input, maintainedOutput extracts one observable result.\n\n\n **L14** Run behavior on the singleton [n] and take its head, defaulting to 0 if empty.\n\n\n **L16** Project the chosen design into Core's Implementation record.\n\n\n **L17** Use the shared descriptive name order-preserving queue.\n\n\n **L18** Mark conventional exactly when chosen is presentSimple.\n\n\n **L19** Mark established under the same Boolean equality.\n\n\n **L20** Use maintainedOutput as the implementation's actual run function.\n\n\n **L21** Its Core-level cost is the chosen design's abstraction complexity.\n\n\n **L22** The projected domain permits every natural input.\n\n\n **L23** Use the identical maintainedOutput function as its explanation.\n\n\n **L24** The trace is a singleton containing the final output; it is not an internal execution trace.\n\n\n **L26** Comment limits the Core choice projection to the queue's one-item observable contract.\n\n\n **L27** Comment adds present understanding budget and retains separate domain checks outside this projection.\n\n\n **L28** Define the Core choice requirements for this projection.\n\n\n **L29** Every natural number is an admissible input.\n\n\n **L30** The expected result is the input itself.\n\n\n **L31** Use the shared context's understanding capacity as budget.\n\n\n **L32** The additional values predicate is unrestricted True.\n\n\n **L34** The available Core choice reasons form a finite list.\n\n\n **L35** List output and simplicity method reasons; membership alone will not prove a reason adequate.\n\n\n **L37** For every design and natural n, state correctness of the one-item output projection.\n\n\n **L38** The actual maintainedOutput must equal n.\n\n\n **L39** The equality is definitional for singleton input, so reflexivity proves it.\n\n\n **L41** Prove reasoned Core implementation choice for any chosen design under a budget premise.\n\n\n **L42** Assume actual abstraction complexity is within chosenRequirements.budget.\n\n\n **L43** The conclusion uses the actual requirements, projected implementation and listed reasons.\n\n\n **L44** Construct functional correctness for every allowed input and reuse the supplied budget proof.\n\n\n **L45** Choose the output method reason; leave its membership and adequacy obligations.\n\n\n **L46** Unfold chosenReasons to establish membership of the output reason.\n\n\n **L47** Prove the output reason's unrestricted value condition and exact input/output contract.\n\n\n **L49** Comment identifies the capability report as actual maintainer-indexed path availability.\n\n\n **L50** Comment explains 0 as a missing-path marker, not evidence that a path exists.\n\n\n **L51** capabilityOutput reports revision-path work for a maintainer encoded by a natural input.\n\n\n **L52** Input 0 selects the original maintainer.\n\n\n **L53** Input 1 selects the successor; every larger input selects the agent.\n\n\n **L54** Decide actual CanChange for this maintainer, design and designRevision in sharedContext.\n\n\n **L55** Return actual revision work when the path exists, otherwise 0 as an absence marker.\n\n\n **L57** Build a Process reporting the chosen design's capability-output function.\n\n\n **L58** Its output is capabilityOutput; its optional explanation is none.\n\n\n **L60** Define the exact functional claim on a Process for this chosen design.\n\n\n **L61** For all natural inputs, require the process output to equal capabilityOutput for that design.\n\n\n **L63** Ground the functional capability claim for every chosen design.\n\n\n **L64** The process and capability specification share the same chosen parameter.\n\n\n **L65** Use an inferential process-contract facet discharged by pointwise reflexivity, then singleton grounds.\n\n\n **L67** actualCapabilityContrast computes six concrete maintainer/design outputs.\n\n\n **L68** presentSimple reports 17 work units for the original maintainer.\n\n\n **L69** It reports absent-path marker 0 for the successor.\n\n\n **L70** It also reports 0 for the agent.\n\n\n **L71** evolvable reports 6 work units for the original maintainer.\n\n\n **L72** It reports 6 for the successor too.\n\n\n **L73** It reports 6 for the agent; decide computes all six equalities.\n\n\n **L75** Comment introduces a recorded threshold of present abstraction complexity.\n\n\n **L76** Comment confines that observation to this finite model and excludes future maintainability and value establishment.\n\n\n **L77** Create one recorded Boolean threshold observation over Candidate.\n\n\n **L78** The instrument checks abstraction complexity ≤ 3, and the recorded result is true.\n\n\n **L80** presentBudgetClaim is precisely the same complexity-at-most-3 predicate.\n\n\n **L82** For every candidate, relate compatibility with this record to its exact claim.\n\n\n **L83** State an iff; the record constrains only present complexity.\n\n\n **L84** Prove each direction of the equivalence separately.\n\n\n **L85** Assume compatibility with the singleton observation list.\n\n\n **L86** Apply compatibility to its actual record using singleton membership.\n\n\n **L87** Convert the instrument's true Boolean result to the complexity proposition.\n\n\n **L88** Conversely, assume the bound and introduce any listed record.\n\n\n **L89** Singleton membership identifies it as presentBudgetRecord.\n\n\n **L90** Convert the bound into the required Boolean equality to true.\n\n\n **L92** Package the budget observation into an empirical Facet over Candidate.\n\n\n **L93** Use the exact record and budget claim; both empirical scope and uncertainty predicates are True.\n\n\n **L95** Prove actual discharge of that empirical facet.\n\n\n **L96** Use evolvable as a compatible in-scope witness; leave claim support and uncertainty support to prove.\n\n\n **L97** For every compatible candidate, introduce the trivial empirical-scope premise.\n\n\n **L98** Use the forward observation equivalence to prove the exact budget claim.\n\n\n **L99** The remaining uncertainty predicate is True, so every compatible candidate satisfies it trivially.\n\n\n **L101** capacityClaim is a proposition about the actual current understanding capacity.\n\n\n **L102** For each candidate require complexity ≤ sharedContext's understanding limit, which is 12.\n\n\n **L104** The capacity inference assumes only the singleton presentBudgetClaim theory.\n\n\n **L106** Construct the inferential facet from those assumptions to the capacity claim.\n\n\n **L108** Prove this inference has a model and entails its claim.\n\n\n **L109** Use evolvable to witness the complexity-at-most-3 assumptions, leaving entailment.\n\n\n **L110** Introduce any candidate satisfying all inference premises.\n\n\n **L111** Singleton-model equivalence extracts the ≤ 3 bound.\n\n\n **L112** Combine that bound with the computed 3 ≤ 12 inequality.\n\n\n **L114** Build a scope account for the present-budget measurement claim.\n\n\n **L115** The explained claim is exactly presentBudgetClaim.\n\n\n **L116** Application conditions are unrestricted True.\n\n\n **L117** Observation scope is likewise True.\n\n\n **L118** Comparative relevance means equal actual behavior on [2, 1, 2].\n\n\n **L119** Two candidates are compared only when both satisfy the budget claim.\n\n\n **L120** The only used method is measurement.\n\n\n **L121** The role text limits the observation to current complexity and excludes future-performance conclusions.\n\n\n **L122** The explanation relation first requires the method to be measurement.\n\n\n **L123** Require the exact stored limitation text.\n\n\n **L124** Require identity of the explained claim and condition predicate.\n\n\n **L126** Verify the stated scopeSpecification of this exact account.\n\n\n **L127** Split comparative-scope and method-explanation obligations.\n\n\n **L128** For compared candidates, prove four True conditions/scopes and use definitional equality of their actual behavior on [2,1,2] for relevance.\n\n\n **L129** Introduce any actually used method and its usage proof.\n\n\n **L130** Prove the role string is nonempty by computing its inequality with the empty string.\n\n\n **L131** Reuse usage equality and reflexive identities for text, claim and conditions.\n\n\n **L133** Comment introduces a counterexample to strengthening a claim without changing its observation.\n\n\n **L134** Demonstrate that this observation does not support a stricter complexity bound.\n\n\n **L135** evolvable is compatible with the recorded ≤ 3 result.\n\n\n **L136** Yet the singleton record does not support the universal compatible-world claim complexity ≤ 1.\n\n\n **L137** Prove compatibility via the observation equivalence, leaving failure of support.\n\n\n **L138** Assume the stronger support relation for contradiction.\n\n\n **L139** Apply it to compatible evolvable, obtaining the impossible 3 ≤ 1.\n\n\n **L140** Compute ¬(3 ≤ 1) and apply it to that derived bound.\n\n\n **L142** Comment states that the policy values expansion while retaining revisability of represented forms.\n\n\n **L143** Comment includes organizations, methods and principles, but does not assert an actual revision event.\n\n\n **L144** Instantiate an Agency.Policy for this engineering activity.\n\n\n **L145** Define which aims count as worth pursuing.\n\n\n **L146** Expansion is worthwhile when the generation commitment is explicitly adopted.\n\n\n **L147** Preserving safe operation is also worthwhile unconditionally.\n\n\n **L148** A form is current exactly when its version equals 1.\n\n\n **L149** Revisability requires some greater natural-number version and generation adoption.\n\n\n **L150** Permit any nondecreasing version transition.\n\n\n **L152** Prove the generation specification for this concrete policy.\n\n\n **L153** Witness adopted expansion and, for every current form, choose version + 1 as a strictly greater revisable version.\n\n\n **L155** Comment identifies OwnFact values as mathematical reports of this model's state.\n\n\n **L156** Comment preserves the separate empirical/value tasks despite these reports' inferential grounds.\n\n\n **L157** OwnFact enumerates model reports that will be held in its theory.\n\n\n **L158** Include selection, requirements, capacity, capability, forecast and revision reports.\n\n\n **L159** Also include generation/reflection reports and an adoption report parameterized by principle.\n\n\n **L160** Derive DecidableEq, Repr: decidable equality and printable representations of these constructors.\n\n\n **L162** Interpret each OwnFact as a claim on Candidate, parameterized by the adopted design.\n\n\n **L163** The selection report requires the candidate to equal the adopted design.\n\n\n **L164** The requirements report uses that candidate's actual profile in sharedContext.\n\n\n **L165** The capacity report is the previously defined actual capacity claim.\n\n\n **L166** The capability report applies the candidate-indexed claim to the same candidate's process.\n\n\n **L167** The forecast report states old size-10 agreement and size-5 disagreement, independent of candidate.\n\n\n **L168** The revision report concerns the actual revisionFor sharedContext candidate account.\n\n\n **L169** The policy report states generationSpecification of the actual engineeringPolicy.\n\n\n **L170** The reflection report uses the candidate's actual reflexivity specification.\n\n\n **L171** Rules, self targets and performed records all come from that same selfModel candidate.\n\n\n **L172** The adoption report is the same principle's governance commitment predicate.\n\n\n **L174** Prove each own fact about the actually selected design.\n\n\n **L175** Require an ordinary design, but quantify universally over OwnFact.\n\n\n **L176** Evaluate the adopted-indexed fact at that same chosen candidate.\n\n\n **L177** Split on the fact constructor.\n\n\n **L178** The selection report is chosen = chosen, proved reflexively.\n\n\n **L179** For requirements, enumerate all three candidates and compute their necessary-profile checks.\n\n\n **L180** For capacity, restrict to the two ordinary candidates and compute complexity ≤ 12.\n\n\n **L181** For capability, introduce any input and use the identical output function reflexively.\n\n\n **L182** For forecast, combine definitional old equality with computed new inequality.\n\n\n **L183** For revision, substitute each ordinary design and decide its concrete account.\n\n\n **L184** Reuse engineeringGenerative for the policy report.\n\n\n **L185** Reuse actual currentSelfApplication under the ordinary premise.\n\n\n **L186** The Core adoption flag is true by definitional equality.\n\n\n **L188** Define the exact inference assumptions for facts about the chosen design.\n\n\n **L189** The sole assumption is that the candidate equals chosen; this is an identity-conditioned inference.\n\n\n **L191** Ground every own-fact report inferentially.\n\n\n **L192** Keep the ordinary-design premise and universally selected fact.\n\n\n **L193** Use the identity theory as premises and the actual fact interpretation as conclusion.\n\n\n **L194** Reduce singleton grounds to discharge of its inferential facet.\n\n\n **L195** Supply chosen as a model of its own identity premise; leave entailment.\n\n\n **L196** Introduce an arbitrary candidate satisfying that identity theory.\n\n\n **L197** Extract candidate = chosen using singleton-model equivalence.\n\n\n **L198** Replace candidate by chosen throughout the goal.\n\n\n **L199** Apply the actually proved own-fact theorem for the same chosen design and fact.\n\n\n **L201** Comment restricts the priority/value equivalence to this fixed applicable context.\n\n\n **L202** Comment states that both predicates select exactly the same candidate.\n\n\n **L203** Comment connects value grounds to actual normative content through identity, rather than a mere adoption label.\n\n\n **L204** For every candidate in the fixed shared context, prove value commitment and actual priority select identically.\n\n\n **L205** The left side is the commitment of the explicitly adopted evolvable selection position.\n\n\n **L206** The right side is EvolutionPriority itself, not a label naming priority.\n\n\n **L207** Prove both directions of this same-claim equivalence.\n\n\n **L208** Assume the evolvable selection commitment.\n\n\n **L209** Expose that commitment as candidate = evolvable.\n\n\n **L210** Substitute the actually selected evolvable candidate.\n\n\n **L211** Extract its priority proof from actual currentDomainSatisfied.\n\n\n **L212** Conversely assume actual EvolutionPriority for the candidate.\n\n\n **L213** Apply the priority rule's selected-candidate conclusion in sharedContext.\n\n\n **L214** Supply current applicability and absence of justified departure; these fixed-context facts are essential.\n\n\n **L216** priorityGrounds supplies value grounds for the actual priority proposition in sharedContext.\n\n\n **L217** The claim is EvolutionPriority sharedContext, with canonical articulation.\n\n\n **L218** Use the exact evolvable value facet both as the singleton required task and the supplied facet.\n\n\n **L219** Introduce equality between the value commitment predicate and actual priority predicate.\n\n\n **L220** Use propositional extensionality pointwise and function extensionality to derive that predicate equality.\n\n\n **L221** Rewrite the priority claim back to the identical value commitment claim.\n\n\n **L222** Reuse selectionGrounded for evolvable; no facet or assessed claim is swapped without this equality.\n\n\n **L224** Comment separates adoption facts from actual normative contents.\n\n\n **L225** Comment states that each following constructor retains the full represented duty and original task.\n\n\n **L226** Comment retains conditions/reasons/scope and restricts domain duties to the domain adopter.\n\n\n **L227** Comment places consistency as an external constraint on the complete resulting theory.\n\n\n **L228** Comment avoids defining that theory through a self-referential proposition asserting its own consistency.\n\n\n **L229** OwnNorm enumerates full represented duties separately from adoption reports.\n\n\n **L230** Include generation, reflection, empirical/inferential grounds and principle-indexed value grounds.\n\n\n **L231** Include selection value, scope, capability, choice and fact-indexed inferential grounds.\n\n\n **L232** Include the domain bundle and grounds for actual priority as distinct duties.\n\n\n **L233** Derive DecidableEq, Repr: decidable equality and printable representations of these constructors.\n\n\n **L235** normApplies determines adoption-dependent membership eligibility for each norm.\n\n\n **L236** Only the evolvable adopter includes domain and priority-value duties under this predicate.\n\n\n **L237** Every other norm applies to all adopters.\n\n\n **L239** Interpret every OwnNorm as its full proposition on Candidate, retaining the adopted parameter.\n\n\n **L240** The generation norm is the actual policy's full generationSpecification.\n\n\n **L241** The reflection norm requires the candidate's actual reflexivity specification.\n\n\n **L242** It uses that same candidate model's rules, self relation and performance relation.\n\n\n **L243** The empirical norm retains the actual record and original True empirical-scope predicate.\n\n\n **L244** It also retains the exact budget claim and the original True uncertainty predicate.\n\n\n **L245** The inferential norm retains actual capacity assumptions and capacity conclusion.\n\n\n **L246** Each principle-value norm requires the full grounds of that same governance position.\n\n\n **L247** Selection-value content requires its full value specification, indexed by adopted.\n\n\n **L248** It additionally requires that same value commitment to hold at the candidate.\n\n\n **L249** The scope norm is the exact budgetScopeAccount specification.\n\n\n **L250** The capability norm retains the complete capability specification.\n\n\n **L251** The process and claim both use the same candidate parameter.\n\n\n **L252** The choice norm retains complete reasoned implementation choice.\n\n\n **L253** It uses actual requirements, this candidate's implementation and the original reasons.\n\n\n **L254** Each own-ground norm is the full inferential task for its fact.\n\n\n **L255** Its identity premises and actual fact claim are both indexed by adopted.\n\n\n **L256** The domain norm is actual DomainSatisfied in sharedContext, evaluated at candidate.\n\n\n **L257** The priority-value norm is grounds for the actual priority predicate, with canonical articulation.\n\n\n **L258** Retain the same required and supplied evolvable value facet.\n\n\n **L260** actualOwnNorm proves satisfaction of each applicable full norm at the selected candidate.\n\n\n **L261** The selected candidate must again be one of the two ordinary designs.\n\n\n **L262** Quantify over the norm and assume its actual normApplies condition before concluding its content.\n\n\n **L263** Split on every OwnNorm constructor, retaining its parameters.\n\n\n **L264** Discharge generation with the actual engineering-policy theorem.\n\n\n **L265** Discharge reflection with the checked self-model theorem for this ordinary design.\n\n\n **L266** Use the actually discharged empirical facet inside singleton grounds.\n\n\n **L267** Use the actually discharged capacity inference facet likewise.\n\n\n **L268** Use governanceGrounded for this exact principle parameter.\n\n\n **L269** Pair actual selection grounds with reflexive selected/adopted identity.\n\n\n **L270** Reuse the actual budget scope explanation proof.\n\n\n **L271** Reuse the same candidate's actual functional capability grounds.\n\n\n **L272** Enter the reasoned implementation choice obligation.\n\n\n **L273** Apply implementationReasoned, leaving its actual budget premise.\n\n\n **L274** Substitute either ordinary design and compute its complexity ≤ 12.\n\n\n **L275** Use actualOwnFactGrounded for the very same chosen design and indexed fact.\n\n\n **L276** For the domain norm, use its adoption applicability premise.\n\n\n **L277** Expose applicable as chosen = evolvable.\n\n\n **L278** Substitute evolvable for chosen.\n\n\n **L279** Now use the actual full current domain satisfaction proof.\n\n\n **L280** The fixed priority-value norm is discharged by priorityGrounds.\n\n\n **L282** ownFactTheory holds exactly the represented own-fact claims.\n\n\n **L283** A claim is held if some OwnFact interprets to that exact claim.\n\n\n **L285** ownNormTheory holds applicable full normative contents.\n\n\n **L286** Require an actual norm witness, its normApplies proof and equality with its full interpreted claim.\n\n\n **L288** Comment says the consequence relation applies jointly to facts and full normative contents.\n\n\n **L289** Comment includes implications of their actual union, not just separate checks of each branch.\n\n\n **L290** ownTheory is the combined theory on which later model and consistency predicates operate.\n\n\n **L291** Take the union of factual reports and full applicable normative claims; it is not merely an adoption-marker theory.\n\n\n **L293** For every chosen design and norm, provide a route into the combined theory.\n\n\n **L294** An actual applicability premise suffices to hold that norm's exact full claim.\n\n\n **L295** Use the union's normative branch with norm witness, applicability and reflexive claim identity.\n\n\n **L297** Exhibit nonempty held claims and review objects for every chosen design.\n\n\n **L298** The chosen selection report is actually in ownTheory.\n\n\n **L299** The grounds-principle adoption report is also actually held.\n\n\n **L300** The activity review object belongs to selfModel's list.\n\n\n **L301** The grounds commitment object belongs to that same list.\n\n\n **L302** Supply two factual-branch witnesses and leave the two object membership checks.\n\n\n **L303** Expand actual model and finite commitment lists to prove those memberships.\n\n\n **L305** comparisonContext is a Logic.Context with worlds Candidate and questions OwnFact.\n\n\n **L306** Its assumptions are the exact chosen-identity theory.\n\n\n **L307** Its question meaning is the chosen-indexed factual interpretation.\n\n\n **L308** Its admissible comparison scope requires complexity at most 3.\n\n\n **L310** Build a Snapshot from a chosen design and explicit revision number.\n\n\n **L311** Store the full combined theory, its comparison context and that revision number.\n\n\n **L313** Prove the chosen ordinary design is an actual admissible world of its combined theory.\n\n\n **L314** Keep the ordinary-design premise explicit.\n\n\n **L315** Admissibility includes all held claims, comparison assumptions and scope at the same chosen world.\n\n\n **L316** Supply reflexive identity assumptions; leave full theory satisfaction and scope.\n\n\n **L317** Introduce any claim actually held in the combined theory.\n\n\n **L318** Split union membership into the factual and normative branches.\n\n\n **L319** Extract the OwnFact witness and substitute its exact claim interpretation.\n\n\n **L320** Apply the checked actualOwnFact theorem at chosen.\n\n\n **L321** Extract the OwnNorm witness, applicability proof and exact claim identity.\n\n\n **L322** Apply actualOwnNorm with the same chosen design, norm and applicability proof.\n\n\n **L323** For scope, substitute each ordinary design and compute complexity ≤ 3.\n\n\n **L325** Prove consistency of the new full snapshot plus truthful change reporting against the specified earlier snapshot; this does not merge old and new theories.\n\n\n **L326** The new choice must be ordinary.\n\n\n **L327** The earlier snapshot is evolvable at revision 0.\n\n\n **L328** The current snapshot is chosen at revision 1, with change acknowledged as true.\n\n\n **L329** Use the actual admissible chosen witness to establish consequence consistency, and reflexivity for the change-record obligation.\n\n\n **L331** Ground every claim in the combined theory, including full applicable norm claims.\n\n\n **L332** Require the chosen design to be ordinary.\n\n\n **L333** Quantify over any Candidate claim and assume it is actually held in ownTheory.\n\n\n **L334** The conclusion is identity-conditioned inferential grounds for that exact claim.\n\n\n **L335** Reduce singleton grounds to the inferential task.\n\n\n **L336** Use chosen as the nonempty identity-premise model; leave entailment.\n\n\n **L337** Introduce any candidate satisfying the identity assumptions.\n\n\n **L338** Extract its equality to chosen from singleton-model semantics.\n\n\n **L339** Substitute chosen for that candidate.\n\n\n **L340** Project full theory satisfaction from currentAdmissible and apply it to the exact held claim.\n\n\n **L342** Comment introduces incompatible contents while keeping an adoption marker unchanged.\n\n\n **L343** Comment identifies the same candidate, question and scope on both sides of the conflict.\n\n\n **L344** Define a deliberately incompatible normative theory over the same Candidate worlds.\n\n\n **L345** The first singleton theory requires the candidate to be presentSimple.\n\n\n **L346** The second requires that same candidate not to be presentSimple.\n\n\n **L348** Use one Unit question to compare these opposing claims in a common context.\n\n\n **L349** Assumptions are empty, the question means candidate = presentSimple, and scope is True.\n\n\n **L351** normativeContentVariation shows a true adoption marker cannot conceal incompatible contents.\n\n\n **L352** The choice adoption flag remains true.\n\n\n **L353** The actual incompatible theory is nevertheless inconsistent in its shared context.\n\n\n **L354** Domain adoption applies to evolvable and does not apply to presentSimple.\n\n\n **L355** The actual domain claim is held in evolvable's theory.\n\n\n **L356** That actual domain claim is not held in presentSimple's theory.\n\n\n **L357** Construct the adoption and applicability facts and positive membership; leave inconsistency and negative membership.\n\n\n **L358** Apply conflictRequiresChange to the single shared Unit question.\n\n\n **L359** For any admissible candidate, derive the positive side of the conflict.\n\n\n **L360** Expose the positive question meaning as candidate = presentSimple.\n\n\n **L361** Extract the positive claim via singleton-model equivalence.\n\n\n **L362** Select the first theory from the model of the union inside admissibility.\n\n\n **L363** For the same kind of admissible candidate, derive the negative side.\n\n\n **L364** Expose the negated meaning as candidate ≠ presentSimple.\n\n\n **L365** Extract the negative claim via its singleton-model equivalence.\n\n\n **L366** Select the second theory from the same union model.\n\n\n **L367** For negative membership, assume the actual domain claim is held by presentSimple.\n\n\n **L368** Its checked admissibility then makes that full DomainSatisfied claim true at presentSimple.\n\n\n **L369** Extract priority from that domain bundle and contradict currentSimpleViolates.\n\n\n **L371** Comment describes Inherited fields as actual satisfaction or support conditions.\n\n\n **L372** Comment denies that value accounts or completed assessments replace the normative fields themselves.\n\n\n **L373** Comment explicitly limits this implementation to the shared context through its identity field.\n\n\n **L374** Inherited bundles represented inherited duties at an explicit context and chosen design; its fields are premises for projection theorems.\n\n\n **L375** Restrict ctx to the exact sharedContext; this is stronger than an arbitrary-context implementation.\n\n\n **L376** Require full generationSpecification for the actual engineering policy.\n\n\n **L377** Require consistency of the current snapshot and truthful reporting against the earlier evolvable revision-0 snapshot.\n\n\n **L378** The current snapshot uses this chosen design at revision 1, with change recorded true.\n\n\n **L379** Require reflexivity using this candidate's actual rules and self targets.\n\n\n **L380** The performance relation comes from the same candidate's selfModel.\n\n\n **L381** For every Core principle, require the actual governance-position value grounds.\n\n\n **L382** Require grounds for this chosen design's selection value position.\n\n\n **L383** Require the empirical task with the actual budget record and True empirical scope.\n\n\n **L384** Retain its exact present-budget claim and True uncertainty predicate; no quantitative uncertainty bound is supplied.\n\n\n **L385** Require actual inference from capacityAssumptions to capacityClaim.\n\n\n **L386** Require the actual budget-scope explanation.\n\n\n **L387** Require functional capability grounds for the same chosen process and claim.\n\n\n **L388** Require reasoned choice of this chosen implementation under actual requirements and reasons.\n\n\n **L389** For all own facts, require inference from the chosen-identity premises to the exact fact claim.\n\n\n **L390** Require chosen itself to be compatible with the actual budget observation.\n\n\n **L391** Require the chosen selection commitment to be actually adopted at chosen.\n\n\n **L392** Require chosen to model every held claim of the full combined theory.\n\n\n **L393** For every applicable norm, require actual theory membership of its content.\n\n\n **L394** The held content must be that same norm's complete ownNormClaim.\n\n\n **L395** For every actual held claim, require its inferential grounds.\n\n\n **L396** Those grounds retain the explicit chosen-identity assumptions.\n\n\n **L398** Construct all Inherited fields for a selected design.\n\n\n **L399** Assume it is presentSimple or evolvable.\n\n\n **L400** The resulting bundle is in exactly sharedContext.\n\n\n **L401** Supply context identity, actual generation proof and full current consistency.\n\n\n **L402** Supply actual self-application and grounds for every governance principle.\n\n\n **L403** Supply chosen selection grounds and the discharged empirical singleton task.\n\n\n **L404** Supply discharged capacity inference and the actual scope account.\n\n\n **L405** Supply capability grounds, leave implementation choice open, and supply all own-fact grounds.\n\n\n **L406** Leave observation compatibility open; supply adoption identity and actual full-theory satisfaction.\n\n\n **L407** Supply applicable normative membership and grounds for every held claim.\n\n\n **L408** For the implementation field, apply the actual reasoned-choice theorem.\n\n\n **L409** Split ordinary choices and compute the remaining ≤ 12 budget condition.\n\n\n **L410** For observation compatibility, use the backward budget observation equivalence.\n\n\n **L411** Split ordinary choices and compute their ≤ 3 observation bound.\n\n\n **L413** Comment introduces mutual application to the same system, principles and claims.\n\n\n **L414** Comment includes the actual chosen implementation and retains the complete Inherited premise.\n\n\n **L415** Begin source-trace metadata for CoreReader.Engineering.inheritedMutualApplication; the following source identifiers and hashes are not Lean proof premises.\n\n\n **L416** Record source unit organon.relationships.roles#p1 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L417** Record source unit organon.relationships.roles#p2 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L418** Record source unit organon.relationships.roles#p3 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L419** End the source-trace metadata comment; Lean does not elaborate it as a proof term.\n\n\n **L420** For any ctx and chosen, inheritedMutualApplication extracts same-object obligations from Inherited.\n\n\n **L421** The full inherited bundle is an explicit premise, not the theorem's independently derived conclusion.\n\n\n **L422** Return the actual engineering generation specification.\n\n\n **L423** Return reflexivity on the chosen model's rules and self relation.\n\n\n **L424** Retain that same model's performance relation.\n\n\n **L425** Return value grounds universally over all Core principles.\n\n\n **L426** Return capability grounds for the chosen process and its exact claim.\n\n\n **L427** Return actual reasoned implementation choice.\n\n\n **L428** Return inference grounds for every own fact under chosen-identity premises.\n\n\n **L429** Return theory membership of every norm whose applicability premise holds.\n\n\n **L430** Return inferential grounds for every claim actually held in the combined theory.\n\n\n **L431** Return current full-theory consistency and truthful change reporting against the earlier evolvable snapshot.\n\n\n **L432** Its current side remains chosen revision 1 with change recorded true.\n\n\n **L433** Build the conjunction by projecting generation, reflection and governance grounds from inherited.\n\n\n **L434** Project capability, actual implementation choice and own-fact grounds.\n\n\n **L435** Project full normative membership, all-held-claim grounds and full consistency; no extra proof of their premises occurs here.\n\n\n **L437** Begin source-trace metadata for CoreReader.Engineering.inheritedMutualCases; the following source identifiers and hashes are not Lean proof premises.\n\n\n **L438** Record source unit organon.relationships.roles#p1 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L439** Record source unit organon.relationships.roles#p2 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L440** Record source unit organon.relationships.roles#p3 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L441** End the source-trace metadata comment; Lean does not elaborate it as a proof term.\n\n\n **L442** inheritedMutualCases gives concrete positive duties alongside actual self-criticism results.\n\n\n **L443** The full Inherited bundle holds for evolvable in sharedContext.\n\n\n **L444** The grounds principle's governance value specification holds.\n\n\n **L445** The actual evolvable process has its exact functional capability grounds.\n\n\n **L446** The evolvable implementation has actual reasoned-choice support.\n\n\n **L447** The actual batch-method revision evaluates to counterexample.\n\n\n **L448** The generationRule object actually belongs to the evolvable model.\n\n\n **L449** The assessmentRule object belongs to that same model.\n\n\n **L450** The actual assessment-rule revision also evaluates to counterexample.\n\n\n **L451** Use the full inheritedCurrent witness and actual grounds-principle value theorem.\n\n\n **L452** Use the exact evolvable capability-grounding theorem.\n\n\n **L453** Extract reasoned implementation choice from that same inherited witness.\n\n\n **L454** Extract the batch-method counterexample from actualSelfCriticism.\n\n\n **L455** Extract generation-rule object membership from ownRuleIdentity.\n\n\n **L456** Extract assessment-rule object membership from the corresponding identity theorem.\n\n\n **L457** Extract the current assessment-rule revision counterexample from ownRuleContentVariation.\n\n\n **L459** Comment locates the priority object and its assessment method in the adopter's same context.\n\n\n **L460** Comment retains both objects within the inherited criticism/generation contract.\n\n\n **L461** Begin source-trace metadata for CoreReader.Engineering.priorityRemainsReflexive; the following source identifiers and hashes are not Lean proof premises.\n\n\n **L462** Record source unit organon.relationships.roles#p3 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L463** Record source unit extensions#p1 with SHA-256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L464** Record source unit software-engineering.structural-judgment#p1 with SHA-256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L465** Record source unit software-engineering.revision#p2 with SHA-256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L466** End the source-trace metadata comment; Lean does not elaborate it as a proof term.\n\n\n **L467** priorityRemainsReflexive connects domain priority to inherited self-criticism in an explicit context and choice.\n\n\n **L468** Assume the complete Inherited bundle and actual DomainSatisfied for the same ctx/chosen.\n\n\n **L469** Also assume priority applies and evolvable has no justified departure in that same context.\n\n\n **L470** Conclude the selected candidate must be evolvable.\n\n\n **L471** Its actual priority object belongs to its self-review list.\n\n\n **L472** The chosen self-model still satisfies reflexivity over its actual rules and targets.\n\n\n **L473** Retain its actual performance relation in that specification.\n\n\n **L474** Retain value grounds for every inherited Core principle.\n\n\n **L475** Additionally ground the actual EvolutionPriority ctx claim, with canonical articulation.\n\n\n **L476** Its required and supplied facet are the very same evolvable selection value position.\n\n\n **L477** The full actual domain norm is held in chosen's combined theory.\n\n\n **L478** The full inherited consistency specification is retained.\n\n\n **L479** The current snapshot remains chosen revision 1, with acknowledged change true.\n\n\n **L480** Extract actual priority from domain and apply applicability/noDeparture to derive chosen = evolvable.\n\n\n **L481** Construct the selected identity, leave membership open, and project reflection and Core value grounds.\n\n\n **L482** Leave exact-priority grounds open; use selected as domain norm applicability and project consistency.\n\n\n **L483** Replace chosen with evolvable and compute actual priority-object membership.\n\n\n **L484** Rewrite ctx to sharedContext using the Inherited identity field; this bounds the grounds result's context.\n\n\n **L485** Now apply priorityGrounds for the exact same priority predicate.\n\n\n **L487** Begin source-trace metadata for CoreReader.Engineering.priorityReflexiveCases; the following source identifiers and hashes are not Lean proof premises.\n\n\n **L488** Record source unit organon.relationships.roles#p3 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L489** Record source unit extensions#p1 with SHA-256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L490** Record source unit software-engineering.structural-judgment#p1 with SHA-256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L491** Record source unit software-engineering.revision#p2 with SHA-256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L492** End the source-trace metadata comment; Lean does not elaborate it as a proof term.\n\n\n **L493** priorityReflexiveCases computes actual priority review and retains criticisms of distinct method objects.\n\n\n **L494** The priority object is actually listed for evolvable.\n\n\n **L495** Its finite size-10 object test passes.\n\n\n **L496** The model records actual performance under assessment key (0,1) for priority revision owned by 0.\n\n\n **L497** The performed input is exactly the input built for that same target.\n\n\n **L498** The recorded outcome is assessed supportedWithinScope.\n\n\n **L499** The distinct batch-method revision nevertheless yields counterexample.\n\n\n **L500** The old batch-method size-10 test succeeds.\n\n\n **L501** The challenged size-5 test fails.\n\n\n **L502** Keep grounds for actual priority in sharedContext with canonical articulation.\n\n\n **L503** Use its identical singleton required/supplied evolvable value facet.\n\n\n **L504** The assessment-rule revision's local-contract failure is also retained as a counterexample.\n\n\n **L505** Compute priority membership and test success; leave performed, while extracting batch criticism.\n\n\n **L506** Extract the batch method's old success and challenged failure.\n\n\n **L507** Supply actual priority grounds and the actual rule-revision counterexample.\n\n\n **L508** Construct performed from self membership, exact input and the assessment activity's key/record identities.\n\n\n **L510** Comment introduces a nonempty witness satisfying the entire represented inherited bundle.\n\n\n **L511** Comment also requires the domain bundle in the very same continuing activity with active priority.\n\n\n **L512** Begin source-trace metadata for CoreReader.Engineering.jointWitness; the following source identifiers and hashes are not Lean proof premises.\n\n\n **L513** Record source unit organon.charter.overview#p2 with SHA-256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L514** Record source unit organon.charter.overview#p3 with SHA-256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L515** Record source unit organon.charter.self-transcendence#p1 with SHA-256 f4ca590e2ae15e3882f70c7b2bc46a8911c97cee547c8b137b5493fbf862c8c0; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L516** Record source unit organon.charter.self-transcendence.orientation#p1 with SHA-256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L517** Record source unit organon.charter.self-transcendence.non-finality#p1 with SHA-256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L518** Record source unit organon.charter.self-transcendence.limits#p1 with SHA-256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L519** Record source unit organon.charter.self-transcendence.limits#p2 with SHA-256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L520** Record source unit organon.charter.consistency#p1 with SHA-256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L521** Record source unit organon.charter.consistency.meaning#p1 with SHA-256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L522** Record source unit organon.charter.consistency.meaning#p2 with SHA-256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L523** Record source unit organon.charter.consistency.limits#p1 with SHA-256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L524** Record source unit organon.charter.reflexivity#p1 with SHA-256 13293b45c2fa89068c68ae7ef3c5df38f0efadb3ef3873d78a5ba67d9691a757; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L525** Record source unit organon.charter.reflexivity.meaning#p1 with SHA-256 8a2caede01a43d8b6c60b54c78ac089c51868e9956f316948077ccee2e45c9cc; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L526** Record source unit organon.charter.reflexivity.limits#p1 with SHA-256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L527** Record source unit organon.grounds#p1 with SHA-256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L528** Record source unit organon.grounds.assessment#p1 with SHA-256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L529** Record source unit organon.grounds.assessment#p2 with SHA-256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L530** Record source unit organon.grounds.assessment#p3 with SHA-256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L531** Record source unit organon.grounds.scope#p1 with SHA-256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L532** Record source unit organon.grounds.scope#p2 with SHA-256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L533** Record source unit organon.grounds.scope#p3 with SHA-256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L534** Record source unit organon.grounds.capabilities#p1 with SHA-256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L535** Record source unit organon.grounds.capabilities#p2 with SHA-256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L536** Record source unit organon.grounds.implementations#p1 with SHA-256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L537** Record source unit organon.grounds.implementations#p2 with SHA-256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L538** Record source unit organon.grounds.implementations.limits#p1 with SHA-256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L539** Record source unit organon.relationships.roles#p1 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L540** Record source unit organon.relationships.roles#p2 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L541** Record source unit organon.relationships.roles#p3 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L542** Record source unit extensions#p1 with SHA-256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L543** Record source unit software-engineering.purpose#p1 with SHA-256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L544** Record source unit software-engineering.purpose#p2 with SHA-256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L545** Record source unit software-engineering.purpose#p3 with SHA-256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L546** Record source unit software-engineering.evolution-priority#p1 with SHA-256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L547** Record source unit software-engineering.evolution-priority#p2 with SHA-256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L548** Record source unit software-engineering.evolution-priority#p3 with SHA-256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L549** Record source unit software-engineering.evolution-meaning#p1 with SHA-256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L550** Record source unit software-engineering.evolution-meaning#p2 with SHA-256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L551** Record source unit software-engineering.structural-judgment#p1 with SHA-256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L552** Record source unit software-engineering.structural-judgment#p2 with SHA-256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L553** Record source unit software-engineering.structural-judgment#p3 with SHA-256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L554** Record source unit software-engineering.revision#p1 with SHA-256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L555** Record source unit software-engineering.revision#p2 with SHA-256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L556** End the source-trace metadata comment; Lean does not elaborate it as a proof term.\n\n\n **L557** jointWitness exhibits one nonempty finite model jointly satisfying inherited and domain bundles.\n\n\n **L558** Existentially choose a context and Candidate; this is an existence result, not universal adequacy.\n\n\n **L559** Require the witnesses to be exactly sharedContext and evolvable.\n\n\n **L560** Both complete bundles must hold for these same objects.\n\n\n **L561** Priority applicability is active and evolvable has no represented threat.\n\n\n **L562** The chosen design has greater abstraction complexity than presentSimple.\n\n\n **L563** The successor has an actual designRevision path in that same activity/design.\n\n\n **L564** The agent has an actual designRevision path there too.\n\n\n **L565** The selected-design report is actually held in chosen's theory.\n\n\n **L566** The grounds commitment is actually among chosen's self-review objects.\n\n\n **L567** Chosen is an admissible model of its full combined theory and comparison context.\n\n\n **L568** Choose sharedContext and evolvable as witnesses, proving both identity fields reflexively.\n\n\n **L569** Supply the complete inheritedCurrent bundle and currentDomainSatisfied.\n\n\n **L570** Supply active priority/no threat, then compute complexity ordering and both maintainer paths.\n\n\n **L571** Project held selection and the actual grounds-review object from nonemptyOwnObjects.\n\n\n **L572** Finish with the actual full-theory admissibility proof.\n\n\n **L574** Comment introduces a countermodel adopting the supported present-simplicity value.\n\n\n **L575** Comment states actual selection and full inherited satisfaction while beginning the applicability qualification.\n\n\n **L576** Comment rules out inactive domain conditions, bounded lifecycle and threatened costs as escape explanations.\n\n\n **L577** Begin source-trace metadata for CoreReader.Engineering.inheritedDoesNotEntailPriority; the following source identifiers and hashes are not Lean proof premises.\n\n\n **L578** Record source unit organon.relationships.roles#p1 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L579** Record source unit organon.relationships.roles#p2 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L580** Record source unit organon.relationships.roles#p3 with SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L581** Record source unit extensions#p1 with SHA-256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L582** Record source unit software-engineering.evolution-priority#p1 with SHA-256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L583** Record source unit software-engineering.evolution-priority#p2 with SHA-256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L584** Record source unit software-engineering.evolution-priority#p3 with SHA-256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04; this comment tracks the reviewed source object, not a logical assumption or correspondence proof.\n\n\n **L585** End the source-trace metadata comment; Lean does not elaborate it as a proof term.\n\n\n **L586** inheritedDoesNotEntailPriority exhibits a finite countermodel separating inherited duties from the additional priority adoption.\n\n\n **L587** Existentially choose a context and candidate satisfying all following conjuncts.\n\n\n **L588** Fix them to sharedContext and presentSimple.\n\n\n **L589** The full inherited bundle holds while the domain priority conditions are active.\n\n\n **L590** The same activity is continuing and has no bounded lifecycle.\n\n\n **L591** There is neither a threat nor a justified departure for evolvable.\n\n\n **L592** presentSimple meets the actual necessary requirements.\n\n\n **L593** evolvable also meets those same requirements.\n\n\n **L594** The same evidence makes designRevision credible.\n\n\n **L595** The successor can revise evolvable in this activity.\n\n\n **L596** The agent can revise evolvable there too.\n\n\n **L597** evolvable requires less actual design-revision work than chosen presentSimple.\n\n\n **L598** Chosen presentSimple has less present abstraction complexity than evolvable.\n\n\n **L599** The chosen simplicity value position has its actual value grounds.\n\n\n **L600** The same value position is actually committed to the chosen design.\n\n\n **L601** Nevertheless the actual EvolutionPriority claim is false for that choice.\n\n\n **L602** Choose sharedContext and presentSimple, discharging their identities reflexively.\n\n\n **L603** Provide complete inherited satisfaction and active priority conditions.\n\n\n **L604** Compute continuation and unboundedness, then use both no-threat/no-departure facts.\n\n\n **L605** Compute both requirements, credible revision, both maintainer paths, and the work/complexity inequalities.\n\n\n **L606** Use actual simple-position grounds, reflexive adoption and currentSimpleViolates to finish the countermodel.\n\n\n **L608** Close namespace CoreReader.Engineering; no further mathematical claim is asserted.\n\n\n### `leanified/CoreReader/Engineering/Reflection.lean`\n\n\n```lean\nimport CoreReader.Adopted\n\nnamespace CoreReader.Engineering.Reflection\n\nopen CoreReader.Agency CoreReader.Adopted\n\n/- A target retains the owner, the actual object and the stage being examined. -/\nstructure Target (Object : Type) where\n owner : Nat\n object : Object\n phase : Phase\n\n/- A finite assessment contract has actual tests and a scope it claims to cover.\nThe scope is an application limit, not a universal definition of assessment. -/\nstructure Contract (W : Type) where\n test : W → Bool\n tested : List W\n claimed : List W\n\n/- Inputs carry the contract belonging to the named target, so another object's\ntest result cannot silently discharge this target's inquiry. -/\nstructure Input (W Object : Type) where\n target : Target Object\n contract : Contract W\n requested : List W\n reasons : List String\n basis : Prop\n\ninductive Verdict | supportedWithinScope | counterexample | noSupportingSample\n deriving DecidableEq, Repr\n\ninductive Outcome (W : Type)\n | generated (tests scope : List W)\n | assessed (verdict : Verdict)\n deriving DecidableEq\n\n/- A successful sample does not license the wider scope: an actual failing\ninstance there changes the assessment to counterexample. -/\ndef evaluate {W Object : Type} (input : Input W Object) : Verdict :=\n if input.contract.tested.all input.contract.test then\n if input.requested.all input.contract.test then .supportedWithinScope\n else .counterexample\n else .noSupportingSample\n\n/- Generation proposes an expanded test set. Proposal generation does not prove\nthat the resulting contract passes those tests or warrants adoption. -/\ndef generate {W Object : Type} (input : Input W Object) : Outcome W :=\n .generated input.requested input.requested\n\ndef interpret {W Object : Type} (activity : Activity) (input : Input W Object)\n (outcome : Outcome W) : Prop :=\n input.reasons ≠ [] ∧ input.basis ∧ match activity with\n | .generation => outcome = generate input\n | .assessment => outcome = .assessed (evaluate input)\n\nstructure Model (W Object : Type) where\n owner : Nat\n objects : List Object\n contracts : Object → Contract W\n requested : Object → Phase → List W\n reasons : Object → Phase → List String\n basis : Object → Phase → Prop\n generationApplies : Object → Phase → Prop\n assessmentApplies : Object → Phase → Prop\n recorded : Activity → Object → Phase → Outcome W\n\ndef Model.input {W Object : Type} (m : Model W Object) (t : Target Object) : Input W Object :=\n ⟨t, m.contracts t.object, m.requested t.object t.phase, m.reasons t.object t.phase,\n m.basis t.object t.phase⟩\n\ndef Model.self {W Object : Type} (m : Model W Object) (t : Target Object) : Prop :=\n t.owner = m.owner ∧ t.object ∈ m.objects\n\ndef Model.rule {W Object : Type} (m : Model W Object) (activity : Activity) :\n ReflexiveRule (Target Object) (Input W Object) (Outcome W) where\n key := ⟨m.owner, match activity with | .generation => 0 | .assessment => 1⟩\n activity := activity\n applicable t := m.self t ∧ match activity with\n | .generation => m.generationApplies t.object t.phase\n | .assessment => m.assessmentApplies t.object t.phase\n input := m.input\n meaning := interpret activity\n\ndef Model.rules {W Object : Type} (m : Model W Object) :=\n [m.rule .generation, m.rule .assessment]\n\n/- These are the stated records. The separate follows test compares each stated\noutcome with the actual input's evaluation, rather than defining success by its name. -/\ndef Model.performed {W Object : Type} (m : Model W Object)\n (key : PrincipleKey) (t : Target Object) (input : Input W Object) (outcome : Outcome W) : Prop :=\n m.self t ∧ input = m.input t ∧\n ∃ activity, key = (m.rule activity).key ∧\n outcome = m.recorded activity t.object t.phase\n\ndef Model.follows {W Object : Type} (m : Model W Object) : Prop :=\n ∀ activity object phase, object ∈ m.objects →\n (match activity with\n | .generation => m.generationApplies object phase\n | .assessment => m.assessmentApplies object phase) →\n interpret activity (m.input ⟨m.owner, object, phase⟩) (m.recorded activity object phase)\n\n/- This generic implication retains the actual evaluation premise. Concrete\nengineering instances must discharge follows separately for their own contracts. -/\ntheorem recordedReflexivity {W Object : Type} (m : Model W Object) (checked : m.follows) :\n reflexivitySpecification m.rules m.self m.performed := by\n constructor\n · intro p hp q hq equal\n simp only [Model.rules, List.mem_cons, List.not_mem_nil, or_false] at hp hq\n rcases hp with rfl | rfl <;> rcases hq with rfl | rfl\n · rfl\n · have bad := congrArg PrincipleKey.localId equal; contradiction\n · have bad := congrArg PrincipleKey.localId equal; contradiction\n · rfl\n · intro rule hr target hs ha\n simp only [Model.rules, List.mem_cons, List.not_mem_nil, or_false] at hr\n rcases hr with rfl | rfl\n · refine ⟨m.recorded .generation target.object target.phase,\n ⟨hs, rfl, .generation, rfl, rfl⟩, ?_⟩\n have actual := checked .generation target.object target.phase hs.2 ha.2\n rcases target with ⟨owner, object, phase⟩\n have ownerEqual : owner = m.owner := hs.1\n subst owner\n exact actual\n · refine ⟨m.recorded .assessment target.object target.phase,\n ⟨hs, rfl, .assessment, rfl, rfl⟩, ?_⟩\n have actual := checked .assessment target.object target.phase hs.2 ha.2\n rcases target with ⟨owner, object, phase⟩\n have ownerEqual : owner = m.owner := hs.1\n subst owner\n exact actual\n\nend CoreReader.Engineering.Reflection\n```\n\n\n\n **L1** Import CoreReader.Adopted, making its declarations and transitive dependencies available; this line adds no new proposition.\n\n\n **L3** Open namespace CoreReader.Engineering.Reflection for the following declarations.\n\n\n **L5** Allow unqualified references to declarations in CoreReader.Agency CoreReader.Adopted; their meaning is unchanged.\n\n\n **L7** Comment explains why Target retains owner, actual object and examined stage; these links are encoded by its fields.\n\n\n **L8** For any object type, Target stores an owner, an object of that type, and a lifecycle phase.\n\n\n **L9** The owner's identifier is a natural number; uniqueness is not a field invariant.\n\n\n **L10** This field retains the actual object, rather than just its name.\n\n\n **L11** The target includes the phase being examined.\n\n\n **L13** Comment introduces a finite assessment contract with actual tests and a claimed scope.\n\n\n **L14** Comment limits this scope representation to the application; it is not a universal definition of assessment.\n\n\n **L15** For any sample type W, Contract packages one Boolean test and two finite lists.\n\n\n **L16** The test maps each W value to a Boolean verdict.\n\n\n **L17** This list records the initial tested cases; it may be empty.\n\n\n **L18** This is the contract's claimed list; evaluate does not read it.\n\n\n **L20** Comment introduces target-associated inputs; Model.input later enforces the field selection from that target.\n\n\n **L21** Comment states the purpose of preventing another object's test from replacing this inquiry; raw Input alone does not enforce a provenance invariant.\n\n\n **L22** Input is polymorphic in sample and object types, packaging the target and the data used for its inquiry.\n\n\n **L23** Retain the full owner/object/phase target.\n\n\n **L24** Store the test contract associated by the model with this object.\n\n\n **L25** This requested list is what evaluate checks after the initial list passes.\n\n\n **L26** Reasons are strings; nonemptiness will be checked, not their truth or relevance by string analysis.\n\n\n **L27** The basis is an arbitrary proposition; interpret requires its proof.\n\n\n **L29** Define three verdicts: support within scope, counterexample, and no supporting sample.\n\n\n **L30** Derive DecidableEq, Repr: decidable equality and printable representations of these constructors.\n\n\n **L32** Outcome is indexed by sample type W and records either a generation result or an assessment.\n\n\n **L33** A generated outcome stores separate tests and scope lists, both over W.\n\n\n **L34** An assessed outcome stores a Verdict and no sample list.\n\n\n **L35** Derive decidable equality for Outcome W when [DecidableEq W] is available; the generated instance retains that typeclass premise, satisfied by the concrete ReviewCase model.\n\n\n **L37** Comment warns that success on initial samples does not by itself license a wider requested list.\n\n\n **L38** Comment identifies an actually failing requested case as the counterexample branch after initial success.\n\n\n **L39** With implicit types W and Object and one input, evaluate computes a verdict from two Boolean all-tests.\n\n\n **L40** First require every initially tested case to pass; List.all on an empty list is true.\n\n\n **L41** If initial tests pass and every requested case passes, return supportedWithinScope, even when initial tests are empty.\n\n\n **L42** If initial tests pass but some requested case fails, return counterexample.\n\n\n **L43** A failing initial case returns noSupportingSample; the name does not mean an explicit empty-list check exists.\n\n\n **L45** Comment describes generation as proposing tests and begins the distinction from validating them.\n\n\n **L46** Comment denies that proposal generation proves either test success or warranted adoption.\n\n\n **L47** With implicit sample/object types, generate produces a proposed Outcome from the input.\n\n\n **L48** Copy requested into both generated tests and generated scope; neither list is validated here.\n\n\n **L50** interpret takes an activity and an input, with both types implicit.\n\n\n **L51** The final explicit argument is an outcome; the result is a proposition about that outcome.\n\n\n **L52** Require a nonempty reasons list and the input's basis proposition, then branch on the activity.\n\n\n **L53** Generation means exact equality to this input's actual generator output.\n\n\n **L54** Assessment means exact equality to the verdict computed by evaluate on this input.\n\n\n **L56** A Model over W and Object supplies target membership, contracts, applicability and recorded outcomes.\n\n\n **L57** The model has one natural-number owner identifier.\n\n\n **L58** Only objects in this finite list can satisfy Model.self.\n\n\n **L59** Assign a contract to every Object value, including values outside objects.\n\n\n **L60** Requested cases depend on the object and phase.\n\n\n **L61** Reason strings depend on the same object and phase.\n\n\n **L62** The basis proposition also depends on that object and phase.\n\n\n **L63** A proposition determines generation applicability per object and phase.\n\n\n **L64** A separate proposition determines assessment applicability.\n\n\n **L65** Recorded outcomes depend on activity, object and phase; correctness is not assumed here.\n\n\n **L67** Model.input builds the inquiry for any target; it does not itself check owner or membership.\n\n\n **L68** Use the target itself and select contract, requested cases and reasons by its actual object/phase.\n\n\n **L69** Complete the input with the basis selected at the same object and phase.\n\n\n **L71** Model.self is the membership/ownership predicate on targets.\n\n\n **L72** Both equal owner and membership of the actual object are required; phase is unrestricted here.\n\n\n **L74** For a model and activity, construct the corresponding reflexive rule.\n\n\n **L75** The rule's target/input/output types are exactly Target Object, Input W Object and Outcome W.\n\n\n **L76** Use model owner plus local identifier 0 for generation or 1 for assessment.\n\n\n **L77** Retain the supplied activity in the rule.\n\n\n **L78** Applicability requires a self target and the activity-specific applicability condition.\n\n\n **L79** Generation uses this object's generationApplies at this phase.\n\n\n **L80** Assessment uses this object's assessmentApplies at this phase.\n\n\n **L81** The actual rule input is the model's target-indexed input constructor.\n\n\n **L82** The rule meaning is the actual interpret function for this activity.\n\n\n **L84** Build the list of rules for this model, with both generic types inferred.\n\n\n **L85** The rule list contains generation first and assessment second, with no other rules.\n\n\n **L87** Comment identifies performed data as stated records, with a separate follows check.\n\n\n **L88** Comment specifies comparison with actual input evaluation; success is not inferred from the outcome's name.\n\n\n **L89** Define recorded performance as a relation belonging to this model.\n\n\n **L90** The relation explicitly takes a principle key, target, input and outcome and returns Prop.\n\n\n **L91** Require self membership and exact equality to the input built for that target.\n\n\n **L92** Existentially choose an activity whose rule key equals the supplied key.\n\n\n **L93** The outcome must be exactly the record for that activity and this same object/phase.\n\n\n **L95** Model.follows states that all applicable records satisfy their actual meaning.\n\n\n **L96** Universally quantify activity, object and phase, then assume object membership.\n\n\n **L97** The next premise selects applicability by activity.\n\n\n **L98** For generation, require generationApplies on the quantified object/phase.\n\n\n **L99** For assessment, require assessmentApplies before asserting the interpretation.\n\n\n **L100** Check recorded outcome against actual input, fixing the target owner to m.owner.\n\n\n **L102** Comment emphasizes that the generic implication retains its substantive evaluation premise.\n\n\n **L103** Comment requires concrete instances to prove follows for their own actual contracts.\n\n\n **L104** For arbitrary types and model, the theorem assumes checked : m.follows; it does not derive this premise.\n\n\n **L105** Under that premise, prove rule-key identity and applicable self-performance in reflexivitySpecification.\n\n\n **L106** Split the specification into identity and performance obligations.\n\n\n **L107** Introduce two listed rules and assume their keys are equal.\n\n\n **L108** Expand membership of the two-rule list into generation/assessment alternatives.\n\n\n **L109** Substitute each membership alternative, yielding four rule pairs.\n\n\n **L110** When both rules are the same activity, their required equality is reflexive.\n\n\n **L111** For generation versus assessment, project equal keys to localId and contradict 0 = 1.\n\n\n **L112** For assessment versus generation, the same projection contradicts 1 = 0.\n\n\n **L113** When both rules are the same activity, their required equality is reflexive.\n\n\n **L114** Introduce a listed rule, self target and applicability proof for the performance obligation.\n\n\n **L115** Reduce the rule's list membership to its two possible activities.\n\n\n **L116** Handle generation and assessment separately by substitution.\n\n\n **L117** For generation, choose its recorded outcome at this target's object/phase as witness.\n\n\n **L118** Prove performed using self membership, exact input, and the generation activity; leave meaning to prove.\n\n\n **L119** Apply checked to this generation record, using object membership from hs and applicability from ha.\n\n\n **L120** Destructure the target into owner, object and phase to expose the ownership equality.\n\n\n **L121** Extract owner = m.owner from the self-target premise.\n\n\n **L122** Substitute the model owner so checked and the target refer to identical inputs.\n\n\n **L123** The previously obtained actual interpretation now exactly closes the goal.\n\n\n **L124** For assessment, choose its recorded verdict at the same target as witness.\n\n\n **L125** Construct performed with the assessment activity and exact input/output identities.\n\n\n **L126** Use checked for assessment, retaining this target's membership and applicability premises.\n\n\n **L127** Destructure the target into owner, object and phase to expose the ownership equality.\n\n\n **L128** Extract owner = m.owner from the self-target premise.\n\n\n **L129** Substitute the model owner so checked and the target refer to identical inputs.\n\n\n **L130** The previously obtained actual interpretation now exactly closes the goal.\n\n\n **L132** Close namespace CoreReader.Engineering.Reflection; no further mathematical claim is asserted.\n\n\n### `leanified/CoreReader/Engineering/SelfApplication.lean`\n\n\n```lean\nimport CoreReader.Engineering.Values\nimport CoreReader.Engineering.Reflection\n\nnamespace CoreReader.Engineering\n\nopen CoreReader.Adopted\n\ninductive ReviewObject | activity | commitment (principle : CoreCommitment) | priority | evolutionMethod\n | generationRule | assessmentRule\n deriving DecidableEq, Repr\n\nabbrev ReviewCase := Candidate × Nat\n\ndef generationApplies (_ : ReviewObject) (phase : CoreReader.Agency.Phase) : Prop :=\n phase ≠ .application\n\ndef assessmentApplies (_ : ReviewObject) (_ : CoreReader.Agency.Phase) : Prop := True\n\ndef ruleObject : CoreReader.Agency.Activity → ReviewObject\n | .generation => .generationRule\n | .assessment => .assessmentRule\n\n/- These inputs test the current reflection functions themselves. Size 10 has\nan actual supporting sample; size 5 removes that sample while retaining the\nrequested claim. The domain batch predictor is not used in this method test. -/\ndef ruleProbe (activity : CoreReader.Agency.Activity) (point : ReviewCase) :\n Reflection.Input ReviewCase ReviewObject where\n target := ⟨0, ruleObject activity, .revision⟩\n contract := ⟨fun _ => true, if point.2 = 10 then [point] else [], [point]⟩\n requested := [point]\n reasons := [\"retain the proposed scope and distinguish actual samples from an empty test set\"]\n basis := True\n\ndef generationRuleTest\n (method : Reflection.Input ReviewCase ReviewObject → Reflection.Outcome ReviewCase)\n (point : ReviewCase) : Bool :=\n let input := ruleProbe .generation point\n method input == .generated input.requested input.requested\n\ndef assessmentRuleTest\n (method : Reflection.Input ReviewCase ReviewObject → Reflection.Verdict)\n (point : ReviewCase) : Bool :=\n method (ruleProbe .assessment point) ==\n (if point.2 = 10 then .supportedWithinScope else .noSupportingSample)\n\n/- A candidate revision supplies the previously missing empty-sample check.\nIt is kept distinct from the current evaluator and is not silently adopted. -/\ndef sampleAwareAssessment (input : Reflection.Input ReviewCase ReviewObject) : Reflection.Verdict :=\n if input.contract.tested.isEmpty then .noSupportingSample else Reflection.evaluate input\n\n/- The method under criticism is the activity's own static batch forecast. Its\ncontract is checked at its original size and at the credible runtime change. -/\ndef objectTest (object : ReviewObject) (point : ReviewCase) : Bool :=\n match object with\n | .activity => decide (Meets currentContinuing.required (currentContinuing.profiles point.1))\n | .commitment principle => safeguardExperiment principle true point.1\n | .priority => decide (EvolutionPriority currentContinuing point.1)\n | .evolutionMethod => staticBatch 21 point.2 == liveBatch 21 point.2\n | .generationRule => generationRuleTest Reflection.generate point\n | .assessmentRule => assessmentRuleTest Reflection.evaluate point\n\ndef reviewObjects (chosen : Candidate) : List ReviewObject :=\n [.activity] ++ coreCommitments.map ReviewObject.commitment ++\n (if chosen = .evolvable then [.priority] else []) ++\n [.evolutionMethod, .generationRule, .assessmentRule]\n\ndef requestedCases (chosen : Candidate) : CoreReader.Agency.Phase → List ReviewCase\n | .formation | .application => [(chosen, 10)]\n | .revision => [(chosen, 10), (chosen, 5)]\n\ndef reviewReasons (object : ReviewObject) (phase : CoreReader.Agency.Phase) : List String :=\n let content := match object with\n | .activity => \"actual order, safety, latency and retention requirements of this activity\"\n | .commitment principle => criticismFor principle\n | .priority => \"credible design revision, successor and agent paths, necessary requirements and concrete costs\"\n | .evolutionMethod => \"the same batch forecast at its recorded size and the proposed runtime size\"\n | .generationRule => \"the actual generator must retain its input's requested tests and scope\"\n | .assessmentRule => \"the actual evaluator's acceptance depends on whether its input has supporting samples\"\n [content, match phase with\n | .formation => \"identify this object's purpose and the conditions of its initial contract\"\n | .application => \"apply that contract to the currently selected design in this continuing activity\"\n | .revision => \"examine the proposed wider input scope and retain any counterexample\"]\n\n/- The recorded verdict is independent of the evaluator: the revision of the\nbatch method is explicitly reported as a counterexample; other current checks\nare reported supported only in the scope that will be checked below. -/\ndef statedReview (chosen : Candidate) (activity : CoreReader.Agency.Activity)\n (object : ReviewObject) (phase : CoreReader.Agency.Phase) : Reflection.Outcome ReviewCase :=\n match activity with\n | .generation => .generated (requestedCases chosen phase) (requestedCases chosen phase)\n | .assessment => .assessed (match object, phase with\n | .evolutionMethod, .revision | .assessmentRule, .revision => .counterexample\n | _, _ => .supportedWithinScope)\n\n/- The basis is not a free approval flag. Each inquiry requires the facts\nrelevant to its own object; a counterexample can ground criticism rather than\nthe truth of the original method's broader claim. -/\ndef reviewBasis (chosen : Candidate) : ReviewObject → CoreReader.Agency.Phase → Prop\n | .activity, _ => ActivityScope currentContinuing.activity ∧\n Meets currentContinuing.required (currentContinuing.profiles chosen)\n | .commitment principle, _ => ReasonRelevant principle (reasonFor principle) chosen\n | .priority, _ => PriorityConditions currentContinuing ∧ ¬ HasThreat currentContinuing .evolvable\n | .evolutionMethod, .revision =>\n staticBatch 21 10 = liveBatch 21 10 ∧ staticBatch 21 5 ≠ liveBatch 21 5\n | .evolutionMethod, _ => staticBatch 21 10 = liveBatch 21 10\n | .generationRule, _ =>\n generationRuleTest Reflection.generate (chosen, 10) = true ∧\n generationRuleTest (fun _ => .generated [] []) (chosen, 10) = false\n | .assessmentRule, .revision =>\n assessmentRuleTest Reflection.evaluate (chosen, 10) = true ∧\n assessmentRuleTest Reflection.evaluate (chosen, 5) = false\n | .assessmentRule, _ => assessmentRuleTest Reflection.evaluate (chosen, 10) = true\n\ndef selfModel (chosen : Candidate) : Reflection.Model ReviewCase ReviewObject where\n owner := 0\n objects := reviewObjects chosen\n contracts object := ⟨objectTest object, [(chosen, 10)], [(chosen, 10)]⟩\n requested _ := requestedCases chosen\n reasons := reviewReasons\n basis := reviewBasis chosen\n generationApplies := generationApplies\n assessmentApplies := assessmentApplies\n recorded := statedReview chosen\n\n/- The named normative object and its finite rationale test are deliberately\ndistinct: a supported rationale experiment is not proof of universal correctness.\nThe same commitment identifier controls adoption, reasons and reflection. -/\ntheorem reviewIdentity (chosen : Candidate) (object : ReviewObject)\n (phase : CoreReader.Agency.Phase) :\n ((selfModel chosen).input ⟨0, object, phase⟩).target.object = object ∧\n ((selfModel chosen).input ⟨0, object, phase⟩).contract.test = objectTest object ∧\n ((selfModel chosen).input ⟨0, object, phase⟩).requested = requestedCases chosen phase ∧\n ((selfModel chosen).input ⟨0, object, phase⟩).reasons = reviewReasons object phase ∧\n ((selfModel chosen).input ⟨0, object, phase⟩).basis = reviewBasis chosen object phase :=\n ⟨rfl, rfl, rfl, rfl, rfl⟩\n\ntheorem currentSelfRecords (chosen : Candidate)\n (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) :\n (selfModel chosen).follows := by\n rcases ordinary with rfl | rfl\n all_goals\n intro activity object phase member applies\n cases activity <;> cases object <;> cases phase\n all_goals first\n | rename_i principle; cases principle\n | skip\n all_goals simp_all [Reflection.interpret, Reflection.Model.input,\n Reflection.evaluate, selfModel, statedReview, reviewObjects, coreCommitments,\n requestedCases, reviewReasons, criticismFor, objectTest, safeguardExperiment,\n generationApplies, assessmentApplies, generationRuleTest, assessmentRuleTest,\n ruleProbe, Reflection.generate,\n reviewBasis, ReasonRelevant, reasonFor, HasThreat, burdens, ConcreteThreat, cost,\n EvolutionPriority, PriorityConditions, JustifiedDeparture, currentContinuing,\n Continuing, ActivityScope, Meets, profile, normalRequirements, initialGrounds,\n ContinuingCapability, continuingActivity, maintainers, changePath,\n changeWork, abstractionComplexity, credible, CredibleDirection, articulateGround,\n supportGround, normalLimits, staticBatch, liveBatch, batchCount, orderedUnique,\n sortedUnique, sortValues, insertOrdered, List.eraseDups]\n all_goals decide\n\ntheorem currentSelfApplication (chosen : Candidate)\n (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) :\n reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self\n (selfModel chosen).performed :=\n Reflection.recordedReflexivity _ (currentSelfRecords chosen ordinary)\n\n/- The activity's own assessment method passes its old observation while the\nexpanded input exposes its actual failed forecast. Neither applying the method\nto itself nor generating a broader candidate makes the failed forecast true. -/\ntheorem actualSelfCriticism (chosen : Candidate) :\n objectTest .evolutionMethod (chosen, 10) = true ∧\n objectTest .evolutionMethod (chosen, 5) = false ∧\n Reflection.evaluate ((selfModel chosen).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧\n statedReview chosen .generation .evolutionMethod .revision =\n .generated [(chosen, 10), (chosen, 5)] [(chosen, 10), (chosen, 5)] ∧\n staticBatch 21 5 ≠ liveBatch 21 5 := by\n refine ⟨?_, ?_, ?_, rfl, by decide⟩\n · change (staticBatch 21 10 == liveBatch 21 10) = true\n decide\n · change (staticBatch 21 5 == liveBatch 21 5) = false\n decide\n · simp [Reflection.evaluate, Reflection.Model.input, selfModel, requestedCases,\n objectTest, staticBatch, liveBatch, batchCount]\n\n/- The objects use the very functions in the adopted rules, and the same\napplicability functions. Assessment applies in all three phases; generation\napplies to formation and revision, including formation/revision of these rules. -/\ntheorem ownRuleIdentity (chosen : Candidate) (activity : CoreReader.Agency.Activity)\n (phase : CoreReader.Agency.Phase) :\n ruleObject activity ∈ (selfModel chosen).objects ∧\n ((selfModel chosen).rule activity).meaning = Reflection.interpret activity ∧\n ((selfModel chosen).input ⟨0, ruleObject activity, phase⟩).contract.test =\n objectTest (ruleObject activity) ∧\n (selfModel chosen).generationApplies (ruleObject activity) phase =\n generationApplies (ruleObject activity) phase ∧\n (selfModel chosen).assessmentApplies (ruleObject activity) phase =\n assessmentApplies (ruleObject activity) phase := by\n refine ⟨?_, rfl, rfl, rfl, rfl⟩\n cases activity <;> simp [ruleObject, selfModel, reviewObjects]\n\n/- Changing the actual generator changes its object's result despite keeping\nthe object name. The evaluator really approves an empty initial sample set;\nits own revision review reports that bounded defect instead of a self-proof. -/\ntheorem ownRuleContentVariation (chosen : Candidate) :\n generationRuleTest Reflection.generate (chosen, 10) = true ∧\n generationRuleTest (fun _ => .generated [] []) (chosen, 10) = false ∧\n assessmentRuleTest Reflection.evaluate (chosen, 10) = true ∧\n assessmentRuleTest Reflection.evaluate (chosen, 5) = false ∧\n Reflection.evaluate ((selfModel chosen).input ⟨0, .assessmentRule, .revision⟩) = .counterexample ∧\n generationApplies .generationRule .formation ∧\n generationApplies .generationRule .revision ∧\n ¬ generationApplies .generationRule .application ∧\n (∀ phase, assessmentApplies .assessmentRule phase) := by\n simp [generationRuleTest, assessmentRuleTest, ruleProbe, Reflection.generate,\n Reflection.evaluate, Reflection.Model.input, selfModel, requestedCases,\n objectTest, generationApplies, assessmentApplies]\n\ntheorem proposedRuleRevision (chosen : Candidate) :\n assessmentRuleTest Reflection.evaluate (chosen, 5) = false ∧\n assessmentRuleTest sampleAwareAssessment (chosen, 5) = true ∧\n assessmentRuleTest sampleAwareAssessment (chosen, 10) = true ∧\n ((selfModel chosen).rule .generation).applicable ⟨0, .generationRule, .revision⟩ ∧\n ¬ (({ selfModel chosen with generationApplies := fun _ _ => False }).rule .generation).applicable\n ⟨0, .generationRule, .revision⟩ := by\n simp [assessmentRuleTest, sampleAwareAssessment, ruleProbe, Reflection.evaluate,\n Reflection.Model.rule, Reflection.Model.self, selfModel, reviewObjects,\n generationApplies]\n\nend CoreReader.Engineering\n```\n\n\n\n **L1** Import CoreReader.Engineering.Values, making its declarations and transitive dependencies available; this line adds no new proposition.\n\n\n **L2** Import CoreReader.Engineering.Reflection, making its declarations and transitive dependencies available; this line adds no new proposition.\n\n\n **L4** Open namespace CoreReader.Engineering for the following declarations.\n\n\n **L6** Allow unqualified references to declarations in CoreReader.Adopted; their meaning is unchanged.\n\n\n **L8** ReviewObject distinguishes the activity, each parameterized Core commitment, priority and evolution method.\n\n\n **L9** Add actual generation-rule and assessment-rule objects to the same object type.\n\n\n **L10** Derive DecidableEq, Repr: decidable equality and printable representations of these constructors.\n\n\n **L12** A review case is a pair of selected Candidate and natural-number size.\n\n\n **L14** Generation applicability ignores object identity and depends only on lifecycle phase.\n\n\n **L15** Generation applies exactly outside application: formation and revision.\n\n\n **L17** Assessment applicability ignores both arguments and is true in all phases for every object.\n\n\n **L19** Map each actual activity to its corresponding method review object.\n\n\n **L20** Generation is represented by generationRule.\n\n\n **L21** Assessment is represented by assessmentRule.\n\n\n **L23** Comment says these probes target current reflection functions themselves and introduces the size-10 case.\n\n\n **L24** Comment contrasts a real initial sample at size 10 with its removal at size 5.\n\n\n **L25** Comment retains the requested claim and distinguishes this actual-rule test from the domain batch predictor.\n\n\n **L26** Build a probe for an actual method, parameterized by activity and Candidate/size pair.\n\n\n **L27** The probe's samples are ReviewCase and its targets are ReviewObject.\n\n\n **L28** Fix owner 0 and revision phase, with object chosen from the activity.\n\n\n **L29** The inner test always passes; only size 10 supplies an initial sample, while claimed always contains the point.\n\n\n **L30** Retain the point as the requested case even when the initial sample list is empty.\n\n\n **L31** Supply a nonempty reason describing scope retention and distinguishing an empty initial list.\n\n\n **L32** The probe basis is True; this field supplies no additional empirical justification.\n\n\n **L34** generationRuleTest tests the function supplied as method, allowing real function replacement.\n\n\n **L35** The method must map this exact reflection input type to the corresponding outcome type.\n\n\n **L36** For a case, return a Boolean contract result.\n\n\n **L37** Construct the generation probe for this same case.\n\n\n **L38** Require exact outcome equality to generated requested tests and requested scope.\n\n\n **L40** assessmentRuleTest checks an explicitly supplied evaluator against a local sample-aware contract.\n\n\n **L41** The evaluated method has this exact input type and returns a Verdict.\n\n\n **L42** Each Candidate/size case receives a Boolean pass/fail result.\n\n\n **L43** Compare the actual method's verdict on the assessment probe with the expected verdict below.\n\n\n **L44** Expect support at size 10 and noSupportingSample otherwise; this is a local contract, not a universal empirical duty.\n\n\n **L46** Comment introduces a candidate revision adding the missing empty-initial-list check.\n\n\n **L47** Comment explicitly keeps the candidate separate from the currently installed evaluator.\n\n\n **L48** Define a distinct candidate evaluator revision over the same input type.\n\n\n **L49** Reject an empty initial tested list before delegating nonempty cases to current evaluate.\n\n\n **L51** Comment introduces the evolutionMethod branch as criticism of this activity's own static batch forecast.\n\n\n **L52** Comment contrasts the original size with the credible changed runtime size.\n\n\n **L53** objectTest selects an operational Boolean test by actual review object.\n\n\n **L54** Pattern-match the object's constructor to choose its specific test.\n\n\n **L55** For activity, decide whether the chosen design profile meets current necessary requirements.\n\n\n **L56** For a commitment, run its enabled safeguard experiment on the chosen design.\n\n\n **L57** For priority, decide the actual EvolutionPriority proposition in currentContinuing.\n\n\n **L58** For evolutionMethod, compare the static and live batch forecasts for 21 items at this size.\n\n\n **L59** For generationRule, pass the actual Reflection.generate function to its test.\n\n\n **L60** For assessmentRule, pass the actual Reflection.evaluate function to its test.\n\n\n **L62** Construct a finite review-object list depending on the chosen design.\n\n\n **L63** Include the activity and all five Core commitments using their original identifiers.\n\n\n **L64** Include the priority object only for the evolvable selection.\n\n\n **L65** Always include the batch method and both actual rule objects.\n\n\n **L67** Requested cases depend on chosen design and lifecycle phase.\n\n\n **L68** Formation and application request only size 10.\n\n\n **L69** Revision expands the requested list to sizes 10 and 5 of the same design.\n\n\n **L71** Construct reason strings specifically for each object and phase.\n\n\n **L72** Choose the first reason by the actual object constructor.\n\n\n **L73** The activity reason names its order, safety, latency and retention requirements.\n\n\n **L74** A commitment reuses the criticism string indexed by the same principle.\n\n\n **L75** The priority reason identifies evidence, maintainer paths, requirements and costs.\n\n\n **L76** The method reason compares the same forecast at recorded and proposed runtime sizes.\n\n\n **L77** The generator reason demands retention of requested tests and scope.\n\n\n **L78** The evaluator reason states this local dependence on the presence of supporting samples.\n\n\n **L79** Return the object-specific reason plus a phase-specific reason.\n\n\n **L80** Formation asks for the object's purpose and initial contract conditions.\n\n\n **L81** Application names the current chosen design and continuing activity.\n\n\n **L82** Revision asks to examine wider inputs and retain counterexamples.\n\n\n **L84** Comment emphasizes that statedReview records are defined independently of evaluate.\n\n\n **L85** Comment identifies the batch-method revision as an explicitly recorded counterexample.\n\n\n **L86** Comment limits other supported records to the finite scopes checked by the subsequent proof.\n\n\n **L87** statedReview independently records an outcome for a chosen design and activity.\n\n\n **L88** The record also depends on object and phase and has the exact reflection outcome type.\n\n\n **L89** Separate generation records from assessment records.\n\n\n **L90** Generation records the phase's requested list in both output fields.\n\n\n **L91** Assessment chooses its recorded verdict by object/phase, rather than calling evaluate.\n\n\n **L92** Revision of the batch method or assessment rule is explicitly recorded as a counterexample.\n\n\n **L93** Every other object/phase assessment is recorded as supportedWithinScope.\n\n\n **L95** Comment introduces basis as object-specific factual content instead of an unrestricted approval flag.\n\n\n **L96** Comment explains that a counterexample can support criticism of the same object.\n\n\n **L97** Comment denies that such critical support establishes the method's broader original claim.\n\n\n **L98** reviewBasis gives object-specific propositions; proofs will be checked for the ordinary designs.\n\n\n **L99** Activity inquiry requires the actual activity's scope condition.\n\n\n **L100** It additionally requires the chosen profile to meet current necessary requirements.\n\n\n **L101** Commitment inquiry requires factual relevance of the reason for that same principle and selection.\n\n\n **L102** Priority inquiry requires current applicability and absence of a threat to evolvable.\n\n\n **L103** The revision branch gives a stronger basis for the batch-method inquiry.\n\n\n **L104** Require success at size 10 and an actual inequality at size 5.\n\n\n **L105** Other batch-method phases require only the size-10 equality.\n\n\n **L106** The generator's basis is a positive and negative test of actual function content.\n\n\n **L107** The real generator must pass at this chosen design and size 10.\n\n\n **L108** An empty-output generator must fail on the same case.\n\n\n **L109** Assessment-rule revision requires a two-case contrast.\n\n\n **L110** The current evaluator must pass its sample-aware test at size 10.\n\n\n **L111** It must fail that contract at size 5, where the initial list is empty.\n\n\n **L112** Other assessment-rule phases require the size-10 positive case only.\n\n\n **L114** selfModel instantiates reflection with these cases and objects for the chosen design.\n\n\n **L115** Set the model owner to 0. The separate self relation requires self-owned targets to match it; raw Model.input still accepts and retains a target with any owner.\n\n\n **L116** Use the choice-dependent actual object list.\n\n\n **L117** Each outer contract uses its objectTest, with initial tested and claimed lists containing size 10.\n\n\n **L118** All objects share the phase-specific requestedCases for the chosen design.\n\n\n **L119** Use actual object/phase reason construction.\n\n\n **L120** Use the substantive object/phase basis predicates.\n\n\n **L121** Install the actual generation applicability function.\n\n\n **L122** Install the actual assessment applicability function.\n\n\n **L123** Use independently stated records, which currentSelfRecords later verifies.\n\n\n **L125** Comment begins the distinction between the actual normative object and its finite rationale experiment.\n\n\n **L126** Comment denies that success of the rationale experiment proves universal normative correctness.\n\n\n **L127** Comment states the intended same-identifier link across adoption, reasons and reflection.\n\n\n **L128** For every chosen design and object, reviewIdentity identifies all input components.\n\n\n **L129** The identity holds for every lifecycle phase.\n\n\n **L130** The input's target object is exactly the supplied object.\n\n\n **L131** Its test is exactly objectTest for that same object.\n\n\n **L132** Its requested list is exactly the chosen design's list at this phase.\n\n\n **L133** Its reasons are exactly those of the same object and phase.\n\n\n **L134** Its basis is exactly the same chosen/object/phase predicate.\n\n\n **L135** All five identities hold by definitional reflexivity, not empirical validation.\n\n\n **L137** currentSelfRecords checks the records of a selected design.\n\n\n **L138** The premise restricts chosen to presentSimple or evolvable; maximal is excluded.\n\n\n **L139** The conclusion is follows, including each applicable record's actual interpretation.\n\n\n **L140** Split the ordinary premise and substitute each of the two designs.\n\n\n **L141** Apply subsequent proof steps to both design goals.\n\n\n **L142** Introduce arbitrary activity, object, phase, membership and applicability premises.\n\n\n **L143** Exhaust all constructors of activity, object and phase.\n\n\n **L144** On every remaining goal, try the following local tactics in order.\n\n\n **L145** When a commitment parameter exists, name it principle and split its five constructors.\n\n\n **L146** Otherwise leave the goal unchanged rather than requiring a principle parameter.\n\n\n **L147** Simplify all goals and hypotheses using the actual interpretation and input construction.\n\n\n **L148** Expand evaluator, model, stated records and finite object lists.\n\n\n **L149** Expand requested cases, reasons, object tests and safeguard experiments.\n\n\n **L150** Expand both applicability predicates and actual rule-test definitions.\n\n\n **L151** Expand the inner method probe and actual generator.\n\n\n **L152** Expand basis, relevance and concrete threat/cost predicates.\n\n\n **L153** Expand priority, applicability, departure and the fixed current context.\n\n\n **L154** Expand activity scope, necessary requirements, profiles and initial evidence.\n\n\n **L155** Expand continuing capability, maintainer list and actual change paths.\n\n\n **L156** Expand work, complexity and credibility of the stated directions.\n\n\n **L157** Expand evidence support, limits, batch arithmetic and ordered output.\n\n\n **L158** Expand the sorting and duplicate-removal helpers needed for finite checks.\n\n\n **L159** Decide any remaining closed finite propositions after the case splits and simplification.\n\n\n **L161** currentSelfApplication derives reflexivity for a selected design.\n\n\n **L162** Retain the explicit two-design ordinary premise.\n\n\n **L163** The specification uses the same selfModel's rules and self-target predicate.\n\n\n **L164** Its performance relation is also taken from that same model.\n\n\n **L165** Apply the generic recordedReflexivity theorem with the actually proved currentSelfRecords premise.\n\n\n **L167** Comment identifies success of the old observation for the activity's batch assessment method.\n\n\n **L168** Comment says expanded input reveals the failed forecast and begins the limit of self-application.\n\n\n **L169** Comment denies that self-application or a broader generated candidate makes the failed forecast true.\n\n\n **L170** actualSelfCriticism holds for every chosen design and exhibits the batch method's finite failure.\n\n\n **L171** The old size-10 batch test passes.\n\n\n **L172** The size-5 batch test fails.\n\n\n **L173** The actual revision evaluator reports counterexample for that same method object.\n\n\n **L174** The separately recorded generation result for that method's revision is specified.\n\n\n **L175** Both generated lists contain size 10 and size 5 for the same chosen design.\n\n\n **L176** The conclusion also retains the underlying arithmetic forecast inequality.\n\n\n **L177** Construct five conjuncts; generation is reflexive and arithmetic inequality decidable, leaving three checks.\n\n\n **L178** Expose the size-10 Boolean equality test as the first proof goal.\n\n\n **L179** Compute that closed size-10 equality.\n\n\n **L180** Expose the size-5 Boolean inequality result as the next goal.\n\n\n **L181** Compute that closed size-5 failure.\n\n\n **L182** Expand the evaluator and actual model input for the counterexample goal.\n\n\n **L183** Reduce object test and batch arithmetic to close that counterexample calculation.\n\n\n **L185** Comment stresses identity between review objects and the functions actually used in adopted rules.\n\n\n **L186** Comment retains identical applicability functions and all-phase assessment.\n\n\n **L187** Comment includes formation/revision of the generation rules themselves in generation's applicable phases.\n\n\n **L188** ownRuleIdentity links every chosen design and activity to the actual rule object and implementation.\n\n\n **L189** The link is stated for every phase, regardless of whether generation applies there.\n\n\n **L190** The activity's method object actually belongs to the model's objects.\n\n\n **L191** The model rule's meaning is exactly the actual interpret activity function.\n\n\n **L192** The input for this same rule object obtains its actual contract test.\n\n\n **L193** That test is objectTest indexed by this identical method object.\n\n\n **L194** Compare the model's generation applicability at this object/phase.\n\n\n **L195** It equals the declared generationApplies function on the same arguments.\n\n\n **L196** Compare the model's assessment applicability at this object/phase.\n\n\n **L197** It equals assessmentApplies on those identical arguments.\n\n\n **L198** Four function/field equalities are reflexive; leave actual object membership as the only goal.\n\n\n **L199** Split activity and compute membership in the actual review-object list.\n\n\n **L201** Comment describes a content-sensitive generator replacement despite unchanged object naming.\n\n\n **L202** Comment records the actual evaluator's acceptance with an empty initial sample list; requested cases are still checked.\n\n\n **L203** Comment characterizes the outer self-review as reporting this bounded local-contract defect, not proving itself universally valid.\n\n\n **L204** ownRuleContentVariation supplies function-sensitive positive and negative cases for every design.\n\n\n **L205** The current generator passes the size-10 retention test.\n\n\n **L206** An empty-output generator fails the identical test.\n\n\n **L207** The current evaluator passes the local sample-aware contract with a size-10 sample.\n\n\n **L208** It fails that contract at size 5 with an empty initial sample list.\n\n\n **L209** The outer revision assessment of the actual assessment-rule object reports counterexample.\n\n\n **L210** Generation applies to formation of its own rule object.\n\n\n **L211** It also applies to revision of its own rule object.\n\n\n **L212** Generation does not apply to application phase of that object.\n\n\n **L213** Assessment applies to its own rule object for every phase.\n\n\n **L214** Unfold actual method tests, probe and generator in all conjuncts.\n\n\n **L215** Expand evaluator, actual input/model and requested cases.\n\n\n **L216** Reduce the object test and both applicability predicates to finish the finite checks.\n\n\n **L218** proposedRuleRevision compares current and candidate evaluators and an applicability mutation.\n\n\n **L219** The current evaluator fails the local empty-initial-sample contract.\n\n\n **L220** The separate sampleAwareAssessment candidate passes that size-5 contract.\n\n\n **L221** The candidate also retains the size-10 positive result.\n\n\n **L222** The current generation rule applies to revision of its own generation-rule object.\n\n\n **L223** A separate model update making generationApplies always False removes that applicability.\n\n\n **L224** The removed applicability concerns exactly owner 0, generationRule and revision.\n\n\n **L225** Expand the local test, candidate evaluator, probe and current evaluator.\n\n\n **L226** Expand actual rule/self-target semantics and model object membership.\n\n\n **L227** Reduce generation applicability to complete the conjunction; neither candidate is installed here.\n\n\n **L229** Close namespace CoreReader.Engineering; no further mathematical claim is asserted.\n\n\n### `leanified/CoreReader/Engineering/Values.lean`\n\n\n```lean\nimport CoreReader.Adopted\nimport CoreReader.Engineering.Domain\n\nnamespace CoreReader.Engineering\n\nopen CoreReader.Logic CoreReader.Evidence CoreReader.Adopted\n\ninductive CoreCommitment | generation | consistency | reflexivity | grounds | choice\n deriving DecidableEq, Repr\n\ndef coreCommitments : List CoreCommitment :=\n [.generation, .consistency, .reflexivity, .grounds, .choice]\n\n/- Initial adoption is explicit. The following reasons neither infer adoption\nfrom facts nor claim that every alternative value position is untenable. -/\ndef coreAdopted (_ : CoreCommitment) : Bool := true\n\ninductive AdoptionReason\n | plannedChange (release : Nat) (direction : Change)\n | incompatibleOrders (input : List Nat)\n | ownMethodCounterexample (items size : Nat)\n | unsupportedScope (items observedSize extendedSize : Nat)\n | statusBudgetContrast (statusSelected : Candidate) (capacity : Nat)\n deriving DecidableEq, Repr\n\ndef reasonFor : CoreCommitment → AdoptionReason\n | .generation => .plannedChange 2 .designRevision\n | .consistency => .incompatibleOrders [2, 1, 2]\n | .reflexivity => .ownMethodCounterexample 21 5\n | .grounds => .unsupportedScope 21 10 5\n | .choice => .statusBudgetContrast .maximal 12\n\n/- Each factual reason has contents specific to the principle's purpose. The\ncontext is the very continuing activity and its current requirements/grounds.\nMatching a constructor alone is insufficient: the represented facts must hold. -/\nabbrev ReasonRelevant : CoreCommitment → AdoptionReason → Candidate → Prop\n | .generation, .plannedChange release direction, _ =>\n DirectionGround.plan release [direction, .migration] ∈ currentContinuing.evidence ∧\n credible currentContinuing.evidence direction ∧ Continuing currentContinuing.activity\n | .consistency, .incompatibleOrders input, _ =>\n currentContinuing.required.orderRequired = true ∧\n orderedUnique input ≠ sortedUnique input\n | .reflexivity, .ownMethodCounterexample items size, _ =>\n staticBatch items 10 = liveBatch items 10 ∧ staticBatch items size ≠ liveBatch items size\n | .grounds, .unsupportedScope items observedSize extendedSize, _ =>\n staticBatch items observedSize = liveBatch items observedSize ∧\n staticBatch items extendedSize ≠ liveBatch items extendedSize\n | .choice, .statusBudgetContrast candidate capacity, selected =>\n capacity = currentContinuing.limits.capacity .understanding ∧\n capacity < abstractionComplexity candidate ∧ abstractionComplexity selected ≤ capacity\n | _, _, _ => False\n\nabbrev valueScope (selected : Candidate) : Prop := abstractionComplexity selected ≤ 3\n\n/- A small operational experiment explains each adopted safeguard's purpose.\nThese consequences are limited to the stated experiment, not a total value score.\nThe disabled branch supplies a real contrast for this application policy. -/\ndef safeguardExperiment (principle : CoreCommitment) (enabled : Bool)\n (selected : Candidate) : Bool :=\n match principle with\n | .generation =>\n let allowed : List Change := if enabled then [.designRevision, .migration] else []\n allowed.contains .designRevision && decide (credible currentContinuing.evidence .designRevision)\n | .consistency =>\n let firstDemand := orderedUnique [2, 1, 2]\n let secondDemand := sortedUnique [2, 1, 2]\n let permitsBoth := if enabled then firstDemand == secondDemand else true\n !permitsBoth\n | .reflexivity =>\n let selfTests := if enabled then [(21, 10), (21, 5)] else [(21, 10)]\n selfTests.any (fun point => staticBatch point.1 point.2 != liveBatch point.1 point.2)\n | .grounds =>\n let licensed := if enabled then [10] else [10, 5]\n licensed.all (fun size => staticBatch 21 size == liveBatch 21 size)\n | .choice =>\n let selectedByRule := if enabled then selected else .maximal\n decide (abstractionComplexity selectedByRule ≤ currentContinuing.limits.capacity .understanding)\n\ndef criticismFor : CoreCommitment → String\n | .generation => \"Reconsider this reason if the committed change or continuing maintenance ends.\"\n | .consistency => \"Reconsider the comparison if the parties deliberately revise the observable order contract.\"\n | .reflexivity => \"This counterexample concerns the stated batch rule; it does not validate all self-assessment.\"\n | .grounds => \"A new input condition requires its own support; success at size ten does not cover size five.\"\n | .choice => \"If objectives or budgets change, compare the actual alternatives and reasons again.\"\n\ndef governancePosition (principle : CoreCommitment) : ValuePosition Candidate where\n Position := Bool\n Outcome := Bool\n adopted := true\n selected _ := coreAdopted principle\n outcome selected enabled := safeguardExperiment principle enabled selected\n objective result := result = true\n constraints selected _ := valueScope selected\n starting := singleton valueScope\n reasons := [fun selected _ => ReasonRelevant principle (reasonFor principle) selected]\n limits := valueScope\n relevantCriticism _ := True\n response _ := some (criticismFor principle)\n\ntheorem adoptionReasonRelevant (principle : CoreCommitment) (selected : Candidate)\n (scope : valueScope selected) : ReasonRelevant principle (reasonFor principle) selected := by\n cases principle\n · dsimp only [ReasonRelevant, reasonFor]; decide\n · dsimp only [ReasonRelevant, reasonFor]; decide\n · dsimp only [ReasonRelevant, reasonFor]; decide\n · dsimp only [ReasonRelevant, reasonFor]; decide\n · refine ⟨rfl, by decide, ?_⟩\n exact Nat.le_trans scope (by decide)\n\ntheorem safeguardEnabled (principle : CoreCommitment) (selected : Candidate)\n (scope : valueScope selected) : safeguardExperiment principle true selected = true := by\n cases principle\n · dsimp only [safeguardExperiment]; decide\n · dsimp only [safeguardExperiment]; decide\n · dsimp only [safeguardExperiment]; decide\n · dsimp only [safeguardExperiment]; decide\n · apply decide_eq_true\n exact Nat.le_trans scope (by change 3 ≤ 12; decide)\n\ntheorem safeguardDisabled (principle : CoreCommitment) (selected : Candidate) :\n safeguardExperiment principle false selected = false := by\n cases principle <;> simp only [safeguardExperiment, Bool.false_eq_true, ↓reduceIte] <;> decide\n\ntheorem governanceValueProcedure (principle : CoreCommitment) :\n ValueProcedure (governancePosition principle) := by\n refine ⟨by simp [governancePosition], ?_, ?_, ?_⟩\n · refine ⟨.evolvable, (modelsSingleton _ _).2 (by change 3 ≤ 3; decide),\n (by change 3 ≤ 3; decide), rfl, ?_⟩\n intro reason member\n cases List.mem_singleton.mp member\n exact adoptionReasonRelevant principle .evolvable (by change 3 ≤ 3; decide)\n · intro selected _ scope _\n exact ⟨safeguardEnabled principle selected scope, scope⟩\n · intro selected _ _\n exact ⟨criticismFor principle, rfl, by cases principle <;> decide⟩\n\ntheorem governanceGrounded (principle : CoreCommitment) :\n valueSpecification (governancePosition principle) :=\n grounds012Singleton _ (governanceValueProcedure principle)\n\n/- Factual relevance, rationale experiments and value adoption are separate.\nSwapping a reason or altering the input makes the finite rationale fail. -/\ntheorem governanceRationaleLimits :\n ¬ ReasonRelevant .consistency (reasonFor .generation) .evolvable ∧\n ¬ ReasonRelevant .reflexivity (.ownMethodCounterexample 21 10) .evolvable ∧\n ¬ ReasonRelevant .generation (.plannedChange 9 .addition) .evolvable ∧\n ¬ valueScope .maximal ∧\n (∀ principle, safeguardExperiment principle false .evolvable = false) ∧\n (∀ principle, (governancePosition principle).commitment .presentSimple) := by\n refine ⟨by change ¬ False; decide, by decide, by decide, by change ¬ (30 ≤ 3); decide,\n fun principle => safeguardDisabled principle .evolvable, fun _ => rfl⟩\n\n/- This additional value priority is a real selection between the same designs.\nBoth scopes retain all necessary domain conditions and no cost exception.\nThe present-simple stance values less abstraction now without claiming that it\nhas the better successor-maintainer capability. The other stance values that capability. -/\ndef selectionObjective (adopted : Candidate) (outcome : Nat × Nat) : Prop :=\n match adopted with\n | .presentSimple => outcome.1 ≤ 1\n | .evolvable => outcome.2 ≤ 6\n | .maximal => outcome.1 ≤ 1\n\ndef selectionPosition (adopted : Candidate) : ValuePosition Candidate where\n Position := Candidate\n Outcome := Nat × Nat\n adopted := adopted\n selected := id\n outcome _ candidate := (abstractionComplexity candidate, changeWork candidate .designRevision)\n objective := selectionObjective adopted\n constraints _ candidate := abstractionComplexity candidate ≤ currentContinuing.limits.capacity .understanding\n starting := singleton (fun candidate => candidate = adopted)\n reasons := [fun _ candidate =>\n abstractionComplexity candidate = (if adopted = .presentSimple then 1 else 3) ∧\n changeWork candidate .designRevision = (if adopted = .presentSimple then 17 else 6)]\n limits _ := Continuing currentContinuing.activity ∧\n credible currentContinuing.evidence .designRevision\n relevantCriticism _ := True\n response _ := some (if adopted = .presentSimple then\n \"The successor lacks the private-layout path; this choice does not claim evolution priority and must be reconsidered if that value is adopted.\"\n else \"The six-step design-revision path does not establish every change is cheap or every forecast is correct.\")\n\ntheorem selectionValueProcedure (adopted : Candidate)\n (ordinary : adopted = .presentSimple ∨ adopted = .evolvable) :\n ValueProcedure (selectionPosition adopted) := by\n rcases ordinary with rfl | rfl\n · refine ⟨by simp [selectionPosition], ?_, ?_, ?_⟩\n · refine ⟨.presentSimple, (modelsSingleton _ _).2 rfl, ?_, rfl, ?_⟩\n · change Continuing currentContinuing.activity ∧ credible currentContinuing.evidence .designRevision\n decide\n · intro reason member\n cases List.mem_singleton.mp member\n decide\n · intro selected _ _ allReasons\n have actual := allReasons _ (List.mem_singleton.mpr rfl)\n change abstractionComplexity .presentSimple = 1 ∧ changeWork .presentSimple .designRevision = 17 at actual\n change abstractionComplexity .presentSimple ≤ 1 ∧\n abstractionComplexity .presentSimple ≤ currentContinuing.limits.capacity .understanding\n exact ⟨by rw [actual.1]; exact Nat.le_refl _, by rw [actual.1]; decide⟩\n · intro selected _ _\n refine ⟨_, rfl, ?_⟩\n simp\n · refine ⟨by simp [selectionPosition], ?_, ?_, ?_⟩\n · refine ⟨.evolvable, (modelsSingleton _ _).2 rfl, ?_, rfl, ?_⟩\n · change Continuing currentContinuing.activity ∧ credible currentContinuing.evidence .designRevision\n decide\n · intro reason member\n cases List.mem_singleton.mp member\n decide\n · intro selected _ _ allReasons\n have actual := allReasons _ (List.mem_singleton.mpr rfl)\n change abstractionComplexity .evolvable = 3 ∧ changeWork .evolvable .designRevision = 6 at actual\n change changeWork .evolvable .designRevision ≤ 6 ∧\n abstractionComplexity .evolvable ≤ currentContinuing.limits.capacity .understanding\n exact ⟨by rw [actual.2]; exact Nat.le_refl _, by rw [actual.1]; decide⟩\n · intro selected _ _\n refine ⟨_, rfl, ?_⟩\n simp\n\ntheorem selectionGrounded (adopted : Candidate)\n (ordinary : adopted = .presentSimple ∨ adopted = .evolvable) :\n valueSpecification (selectionPosition adopted) :=\n grounds012Singleton _ (selectionValueProcedure adopted ordinary)\n\nend CoreReader.Engineering\n```\n\n\n\n **L1** Import CoreReader.Adopted, making its declarations and transitive dependencies available; this line adds no new proposition.\n\n\n **L2** Import CoreReader.Engineering.Domain, making its declarations and transitive dependencies available; this line adds no new proposition.\n\n\n **L4** Open namespace CoreReader.Engineering for the following declarations.\n\n\n **L6** Allow unqualified references to declarations in CoreReader.Logic CoreReader.Evidence CoreReader.Adopted; their meaning is unchanged.\n\n\n **L8** Define five Core commitment identifiers: generation, consistency, reflexivity, grounds and choice.\n\n\n **L9** Derive DecidableEq, Repr: decidable equality and printable representations of these constructors.\n\n\n **L11** coreCommitments is the finite list of all represented commitment identifiers.\n\n\n **L12** List each of the five constructors once, in the displayed order.\n\n\n **L14** Comment identifies adoption as an explicit starting choice; reasons do not infer the adoption itself.\n\n\n **L15** Comment rejects both deriving adoption from facts and claiming all alternative values untenable.\n\n\n **L16** Every commitment is explicitly marked adopted; no factual premise derives this Boolean choice.\n\n\n **L18** AdoptionReason is a typed family of concrete rationale data, not itself a proof.\n\n\n **L19** plannedChange records a natural-number release and a Change direction.\n\n\n **L20** incompatibleOrders stores the actual input list used to compare output orders.\n\n\n **L21** ownMethodCounterexample stores item count and runtime size.\n\n\n **L22** unsupportedScope distinguishes observed and extended sizes for a fixed item count.\n\n\n **L23** statusBudgetContrast records a status-selected alternative and a natural-number capacity.\n\n\n **L24** Derive DecidableEq, Repr: decidable equality and printable representations of these constructors.\n\n\n **L26** Assign one concrete rationale value to every Core commitment.\n\n\n **L27** Generation uses planned release 2 and designRevision.\n\n\n **L28** Consistency uses the order-sensitive input [2, 1, 2].\n\n\n **L29** Reflexivity uses 21 items at runtime size 5.\n\n\n **L30** Grounds compares observation at size 10 with extension to size 5 for 21 items.\n\n\n **L31** Choice contrasts maximal against understanding capacity 12.\n\n\n **L33** Comment introduces factual reasons specialized to each principle's purpose.\n\n\n **L34** Comment fixes their context to this continuing activity and its actual requirements/evidence.\n\n\n **L35** Comment requires actual reason contents to hold, beyond matching constructor names.\n\n\n **L36** ReasonRelevant is a proposition on principle, structured reason and selected design; it checks actual reason content.\n\n\n **L37** For generation with a planned-change reason, selection is irrelevant to this branch.\n\n\n **L38** The precise release plan containing direction and migration must occur in current evidence.\n\n\n **L39** That direction must be credible and the current activity continuing.\n\n\n **L40** For consistency, use the input carried by the incompatible-orders reason.\n\n\n **L41** The actual current requirements must demand order preservation.\n\n\n **L42** Order-preserving and sorted duplicate removal must differ on that input.\n\n\n **L43** For reflexivity, use the reason's item count and challenged size.\n\n\n **L44** Require agreement at old size 10 and disagreement at the challenged size.\n\n\n **L45** For grounds, compare the reason's observed and extended sizes.\n\n\n **L46** Static and live forecasts must agree at the observed size.\n\n\n **L47** They must disagree at the proposed extended size.\n\n\n **L48** For choice, distinguish the contrasted candidate from the actually selected design.\n\n\n **L49** The stated capacity must equal the current understanding capacity.\n\n\n **L50** The contrasted candidate exceeds that capacity while the actual selection stays within it.\n\n\n **L51** Any mismatched principle/reason constructors yield False.\n\n\n **L53** The value procedure's disclosed scope is designs of abstraction complexity at most 3.\n\n\n **L55** Comment introduces a small operational experiment explaining each safeguard's purpose.\n\n\n **L56** Comment limits consequences to that experiment, excluding a total value score.\n\n\n **L57** Comment identifies the disabled branch as an actual contrast within this application policy.\n\n\n **L58** safeguardExperiment varies a named safeguard's enabled Boolean.\n\n\n **L59** It also takes the actual selected design and returns an operational Boolean result.\n\n\n **L60** Select the experiment by principle; this is no aggregate value metric.\n\n\n **L61** The generation branch measures availability of a credible planned change.\n\n\n **L62** Enable both designRevision and migration, or disable them with an empty allowed list.\n\n\n **L63** Pass only if designRevision is allowed and currently credible.\n\n\n **L64** The consistency branch measures refusal of incompatible simultaneous demands.\n\n\n **L65** Compute the first demand using order-preserving duplicate removal.\n\n\n **L66** Compute the second demand using sorted duplicate removal on the same input.\n\n\n **L67** An enabled check permits both demands only if equal; disabling it permits both unconditionally.\n\n\n **L68** The experiment succeeds when simultaneous permission is rejected.\n\n\n **L69** The reflexivity branch tests the actual batch forecast on itself.\n\n\n **L70** Enable the old and challenged sizes, or retain only the old size when disabled.\n\n\n **L71** Pass when some listed point yields unequal static and live forecasts.\n\n\n **L72** The grounds branch tests the licensed input scope.\n\n\n **L73** Enable licensing only size 10; disabling broadens licensing to 10 and 5.\n\n\n **L74** Require forecast equality for every licensed size, with 21 items fixed.\n\n\n **L75** The choice branch measures conformity to understanding capacity.\n\n\n **L76** Enable the supplied choice, or select maximal when the safeguard is disabled.\n\n\n **L77** Decide whether that actual rule selection fits the current understanding capacity.\n\n\n **L79** Assign a revisability/criticism response string to each principle.\n\n\n **L80** The generation response identifies loss of committed change or ongoing maintenance as a reconsideration condition.\n\n\n **L81** The consistency response allows reconsidering the comparison after deliberate revision of the order contract.\n\n\n **L82** The reflexivity response limits the counterexample to this batch rule, not all self-assessment.\n\n\n **L83** The grounds response denies extending size-10 success to size 5 without its own support.\n\n\n **L84** The choice response calls for renewed comparison if objectives or budgets change.\n\n\n **L86** For one principle, build a ValuePosition over Candidate with explicit adoption and bounded supporting reasons.\n\n\n **L87** The value-position alternatives are Boolean enabled/disabled states.\n\n\n **L88** The experiment's outcome type is Bool.\n\n\n **L89** Adopt the enabled value position explicitly.\n\n\n **L90** For every design, selected position is that principle's adoption flag.\n\n\n **L91** Outcomes run the same principle's experiment using design and enabled position.\n\n\n **L92** The objective is experiment success, represented by true.\n\n\n **L93** Constraints require the design's valueScope regardless of Boolean position.\n\n\n **L94** The starting theory consists solely of the valueScope proposition.\n\n\n **L95** The singleton reason requires actual relevance for the same principle and selected design.\n\n\n **L96** The application limit is again valueScope.\n\n\n **L97** All Candidate values count as relevant criticism; no narrower filter is encoded.\n\n\n **L98** Every criticism receives the principle's fixed response string.\n\n\n **L100** Prove reason relevance for every principle and selected design within scope.\n\n\n **L101** The premise bounds selected complexity by 3; the conclusion uses its exact reasonFor value.\n\n\n **L102** Split the five principle constructors.\n\n\n **L103** For generation, unfold reason content and compute plan membership, credibility and continuation.\n\n\n **L104** For consistency, unfold and compute the order requirement and differing outputs.\n\n\n **L105** For reflexivity, unfold and compute old success and challenged forecast failure.\n\n\n **L106** For grounds, unfold and compute observed equality and extended inequality.\n\n\n **L107** For choice, prove capacity identity and maximal over-budget, leaving the selected-design bound.\n\n\n **L108** Chain selected complexity ≤ 3 with 3 ≤ 12 to obtain the required bound.\n\n\n **L110** Prove the enabled experiment succeeds for every principle within the disclosed scope.\n\n\n **L111** Retain the scope premise and state an actual Boolean equality to true.\n\n\n **L112** Split by the five principles to compute each distinct experiment.\n\n\n **L113** For generation, expand the enabled change list and decide the credibility test.\n\n\n **L114** For consistency, expand the enabled comparison and decide rejection of incompatible demands.\n\n\n **L115** For reflexivity, expand the two tests and decide existence of a failed forecast.\n\n\n **L116** For grounds, expand the licensed size-10 list and decide its test success.\n\n\n **L117** Convert the choice experiment's Boolean result into its underlying capacity proposition.\n\n\n **L118** Use scope and the computed 3 ≤ 12 bound to prove that capacity proposition.\n\n\n **L120** The disabled safeguard fails for every principle and selected design, without a scope premise.\n\n\n **L121** State failure as exact equality of the computed experiment to false.\n\n\n **L122** Split principles, reduce the disabled branches and decide all five finite results.\n\n\n **L124** For each principle, verify the actual governance value procedure.\n\n\n **L125** The target is ValueProcedure for that same governancePosition.\n\n\n **L126** Construct nonempty reasons and leave compatibility, objective/constraints and response obligations.\n\n\n **L127** Choose evolvable as a starting-theory witness, proving its singleton scope membership.\n\n\n **L128** Prove its application limit and selection identity; leave its reason validity.\n\n\n **L129** Introduce any reason belonging to the position's reason list.\n\n\n **L130** Singleton membership identifies it with the actual relevance reason.\n\n\n **L131** Apply the proved relevance theorem at evolvable's complexity bound 3 ≤ 3.\n\n\n **L132** For an arbitrary design under the procedure premises, retain its scope proof.\n\n\n **L133** Supply enabled experiment success and the same scope as objective and constraint satisfaction.\n\n\n **L134** Introduce an arbitrary criticism case under the response premises.\n\n\n **L135** Provide the fixed criticism response, its exact stored identity and nonemptiness by finite case analysis.\n\n\n **L137** governanceGrounded gives grounds for the value commitment of every represented principle.\n\n\n **L138** The conclusion is valueSpecification for the exact governance position.\n\n\n **L139** Wrap its verified ValueProcedure in the singleton adopted Core 0.1.2 grounds construction.\n\n\n **L141** Comment separates factual relevance, rationale experiments and value adoption.\n\n\n **L142** Comment introduces failure cases from swapped reasons or altered inputs.\n\n\n **L143** governanceRationaleLimits exhibits actual failures and distinguishes support from adoption.\n\n\n **L144** A generation reason is irrelevant to consistency because the constructors mismatch.\n\n\n **L145** A claimed self-counterexample at size 10 fails because the old forecast agrees there.\n\n\n **L146** An unsupported release-9 addition plan fails the generation reason requirements.\n\n\n **L147** maximal lies outside the complexity-at-most-3 value scope.\n\n\n **L148** Every disabled safeguard experiment fails at evolvable.\n\n\n **L149** Nevertheless every governance commitment is adopted at presentSimple too.\n\n\n **L150** Compute the three irrelevant-reason cases and maximal's 30 > 3 scope failure.\n\n\n **L151** Use safeguardDisabled for every principle, and reflexive adoption identity for the final universal claim.\n\n\n **L153** Comment frames the additional value priority as a genuine selection between the same designs.\n\n\n **L154** Comment points to the common context's necessary conditions and absence of cost exception; the limits field below explicitly tests continuation and credibility.\n\n\n **L155** Comment says the simple position values lower present abstraction and begins its capability qualification.\n\n\n **L156** Comment denies superior successor capability for the simple stance and assigns that objective to the other stance.\n\n\n **L157** selectionObjective maps an adopted design and complexity/work pair to its chosen objective proposition.\n\n\n **L158** The objective changes with the explicitly adopted candidate.\n\n\n **L159** presentSimple values present abstraction complexity at most 1.\n\n\n **L160** evolvable values design-revision work at most 6.\n\n\n **L161** The maximal branch also uses complexity at most 1; no successful procedure for maximal is proved below.\n\n\n **L163** Build a separate selection ValuePosition parameterized by the adopted candidate.\n\n\n **L164** Its alternative positions are the actual Candidate designs.\n\n\n **L165** Outcomes are natural-number pairs of complexity and revision work.\n\n\n **L166** Store the supplied adopted candidate directly.\n\n\n **L167** A world's selected position is itself, via the identity function.\n\n\n **L168** Measure the chosen position's complexity and actual designRevision work.\n\n\n **L169** Use the objective indexed by the adopted design.\n\n\n **L170** Constrain the position's complexity by the actual understanding capacity.\n\n\n **L171** The starting theory requires the world to equal the adopted design.\n\n\n **L172** There is one reason function; it ignores the world argument and examines the position.\n\n\n **L173** Require complexity 1 for presentSimple adoption, otherwise complexity 3.\n\n\n **L174** Require revision work 17 for presentSimple adoption, otherwise 6.\n\n\n **L175** The procedure's limits require the current activity to continue.\n\n\n **L176** They also require designRevision to be credible in the actual evidence.\n\n\n **L177** Every candidate is treated as relevant criticism.\n\n\n **L178** Every criticism receives a response selected by whether presentSimple was adopted.\n\n\n **L179** The simple response admits the successor's missing private-layout path and denies claiming evolution priority.\n\n\n **L180** The evolvable response limits the six-step result and denies general cheap-change or forecast correctness.\n\n\n **L182** Verify the selection value procedure for an adopted candidate.\n\n\n **L183** Assume adoption is one of the two ordinary designs.\n\n\n **L184** The conclusion is the actual ValueProcedure for that adoption.\n\n\n **L185** Split and substitute presentSimple and evolvable adoptions.\n\n\n **L186** For presentSimple, prove nonempty reasons and leave the three substantive procedure obligations.\n\n\n **L187** Choose presentSimple itself as compatible witness and reduce its selection identity reflexively.\n\n\n **L188** Expose the witness limit as actual continuation and credible designRevision.\n\n\n **L189** Compute those fixed-context facts.\n\n\n **L190** Introduce a reason from the singleton simple-position list.\n\n\n **L191** Replace that reason by its unique member.\n\n\n **L192** Compute simple design complexity 1 and revision work 17.\n\n\n **L193** Introduce arbitrary procedure premises, retaining allReasons for simple adoption.\n\n\n **L194** Extract the actual singleton reason from allReasons.\n\n\n **L195** Expose that reason as the concrete equalities complexity 1 and work 17 at adopted presentSimple.\n\n\n **L196** Expose the simple objective as complexity at most 1.\n\n\n **L197** The second conjunct is the same design's understanding-capacity constraint.\n\n\n **L198** Rewrite with the actual complexity equality, using reflexive ≤ for the objective and computation for capacity.\n\n\n **L199** For arbitrary relevant criticism, enter the simple response obligation.\n\n\n **L200** Choose the stored response and its reflexive equality; leave nonemptiness.\n\n\n **L201** Simplify the fixed response to prove it is nonempty.\n\n\n **L202** For evolvable, prove nonempty reasons and leave the same three procedure obligations.\n\n\n **L203** Choose evolvable itself as compatible witness with reflexive selection identity.\n\n\n **L204** Expose the evolvable witness's continuation and credible-revision limits.\n\n\n **L205** Compute those limits in currentContinuing.\n\n\n **L206** Introduce a reason from evolvable's singleton reason list.\n\n\n **L207** Identify it with the unique actual reason.\n\n\n **L208** Compute evolvable complexity 3 and revision work 6.\n\n\n **L209** Introduce procedure premises for evolvable, retaining allReasons.\n\n\n **L210** Extract the unique substantive reason from that premise.\n\n\n **L211** Expose complexity 3 and designRevision work 6 for the adopted evolvable position.\n\n\n **L212** Expose the evolvable objective as work at most 6.\n\n\n **L213** Retain the actual understanding-capacity constraint on the same design.\n\n\n **L214** Use work equality for the objective and complexity equality for the capacity check.\n\n\n **L215** For any relevant criticism, enter the evolvable response obligation.\n\n\n **L216** Choose the stored evolvable response, leaving its nonemptiness.\n\n\n **L217** Simplify the response string to prove nonemptiness.\n\n\n **L219** selectionGrounded packages value grounds for the adopted selection.\n\n\n **L220** The two-ordinary-design assumption remains explicit.\n\n\n **L221** The conclusion concerns exactly selectionPosition adopted.\n\n\n **L222** Use the proved selection procedure as the discharged singleton value facet.\n\n\n **L224** Close namespace CoreReader.Engineering; no further mathematical claim is asserted.\n\n\n### `leanified/CoreReader/Evidence.lean`\n\n\n```lean\nimport CoreReader.Logic\nimport CoreReader.Agency\n\nnamespace CoreReader.Evidence\nopen CoreReader.Logic\nopen CoreReader.Agency\n\n/- An observation records the outcome of a specified test on the represented world. -/\nstructure Record (W : Type) where\n test : W → Bool\n observed : Bool\n/- Compatible worlds reproduce the actual contents of every recorded observation. -/\ndef Compatible {W : Type} (records : List (Record W)) (w : W) : Prop :=\n ∀ r, r ∈ records → r.test w = r.observed\n/- Inferential support requires the same claim in every evidence-compatible world. -/\ndef Supports {W : Type} (records : List (Record W)) (claim : Claim W) : Prop :=\n ∀ w, Compatible records w → claim w\n/- Articulation identifies concepts, premises, reason contents and an application limit. -/\nstructure Articulation (W : Type) where\n concepts : List String\n assumptions : Theory W\n reasons : List (Claim W)\n limits : Claim W\n/- Nonempty identifiable concepts and reasons are procedural articulation requirements. -/\ndef Articulated {W : Type} (a : Articulation W) : Prop :=\n a.concepts ≠ [] ∧ a.reasons ≠ []\n/- This application model interprets an adopted option through its actual outcomes and stated goals/constraints. -/\nstructure ValuePosition (W : Type) where\n Position : Type\n Outcome : Type\n adopted : Position\n selected : W → Position\n outcome : W → Position → Outcome\n objective : Outcome → Prop\n constraints : W → Position → Prop\n starting : Theory W\n reasons : List (W → Position → Prop)\n limits : Claim W\n relevantCriticism : Claim W\n response : W → Option String\n/- The adopted position's claim is derived from the same selected option used by the outcome interpretation. -/\ndef ValuePosition.commitment {W : Type} (v : ValuePosition W) : Claim W :=\n fun w => v.selected w = v.adopted\n/- Assessed consequences concern this adopted option's actual outcome, objective and constraints. -/\ndef ValuePosition.consequence {W : Type} (v : ValuePosition W) : Claim W :=\n fun w => v.objective (v.outcome w v.adopted) ∧ v.constraints w v.adopted\n/- Articulated reasons specialize the actual option-indexed premises to the adopted option. -/\ndef ValuePosition.activeReasons {W : Type} (v : ValuePosition W) : List (Claim W) :=\n v.reasons.map (fun reason w => reason w v.adopted)\n/- A joint witness excludes inconsistent starts and impossible adoption states. -/\ndef JointAdoption {W : Type} (v : ValuePosition W) : Prop :=\n ∃ w, Models v.starting w ∧ v.limits w ∧ v.commitment w ∧\n ∀ reason, reason ∈ v.reasons → reason w v.adopted\n/- This declared option/outcome adapter checks joint reasons for an assessed consequence; it is not a necessary deductive form for all value justification. -/\ndef ValueProcedure {W : Type} (v : ValuePosition W) : Prop :=\n v.reasons ≠ [] ∧ JointAdoption v ∧\n (∀ w, Models v.starting w → v.limits w →\n (∀ reason, reason ∈ v.reasons → reason w v.adopted) → v.consequence w) ∧\n (∀ w, v.limits w → v.relevantCriticism w → ∃ answer, v.response w = some answer ∧ answer ≠ \"\")\n/- A facet carries its specific contents; several different facets can have the same conclusion. -/\ninductive Facet (W : Type) where\n | empirical (records : List (Record W)) (scope conclusion uncertainty : Claim W)\n | inferential (assumptions : Theory W) (conclusion : Claim W)\n | value (position : ValuePosition W)\n/- The claim referred to by each assessment facet is explicit. -/\ndef Facet.claim {W : Type} : Facet W → Claim W\n | .empirical _ _ p _ => p\n | .inferential _ p => p\n | .value v => v.commitment\n/- These disclosed semantic adapters implement selected nature-specific checks; passing them does not establish all real empirical or value adequacy. -/\ndef FacetDischarged {W : Type} : Facet W → Prop\n | .empirical records scope p uncertainty =>\n (∃ w, Compatible records w ∧ scope w) ∧\n Supports records (fun w => scope w → p w) ∧ Supports records uncertainty\n | .inferential assumptions p => Satisfiable assumptions ∧ Entails assumptions p\n | .value v => ValueProcedure v\n/- This model's semantic adapter identifies the actual assumptions, reason content and limit of a facet. -/\ndef FacetArticulated {W : Type} (a : Articulation W) : Facet W → Prop\n | .empirical records scope _ _ =>\n a.assumptions = singleton (Compatible records) ∧ a.reasons = [Compatible records] ∧ a.limits = scope\n | .inferential assumptions _ =>\n a.assumptions = assumptions ∧ a.reasons = [Models assumptions] ∧ a.limits = (fun _ => True)\n | .value v => a.assumptions = v.starting ∧ a.reasons = v.activeReasons ∧ a.limits = v.limits\n/- A canonical articulation exposes this adapter; the source does not mandate this particular representation of grounds. -/\ndef canonicalArticulation {W : Type} : Facet W → Articulation W\n | .empirical records scope _ _ =>\n ⟨[\"recorded test outcomes\", \"observation conditions\"], singleton (Compatible records), [Compatible records], scope⟩\n | .inferential assumptions _ =>\n ⟨[\"stated assumptions\", \"semantic consequence\"], assumptions, [Models assumptions], fun _ => True⟩\n | .value v =>\n ⟨[\"adopted position\", \"reasons and consequences\"], v.starting, v.activeReasons, v.limits⟩\n/- Canonical articulation is connected to the very facet whose grounds it identifies. -/\ntheorem canonicalFacetArticulated {W : Type} (f : Facet W) :\n FacetArticulated (canonicalArticulation f) f := by\n cases f <;> exact ⟨rfl, rfl, rfl⟩\n/- A discharged facet has nonempty canonical reason articulation, including the value procedure's reason requirement. -/\ntheorem canonicalArticulated {W : Type} (f : Facet W) (h : FacetDischarged f) :\n Articulated (canonicalArticulation f) := by\n cases f with\n | empirical records scope p uncertainty => simp [Articulated, canonicalArticulation]\n | inferential assumptions p => simp [Articulated, canonicalArticulation]\n | value v =>\n refine ⟨by simp [canonicalArticulation], ?_⟩\n simpa [canonicalArticulation, ValuePosition.activeReasons] using h.1\n/- This model of the Grounds obligation binds each actual facet to its claim and articulation. Its disclosed FacetDischarged adapters do not replace all source-level assessment responsibilities or prove real adequacy. -/\ndef Grounds {W : Type} (claim : Claim W) (articulations : Facet W → Articulation W)\n (actualApplicable : Facet W → Prop) (facets : List (Facet W)) : Prop :=\n facets ≠ [] ∧ (∀ facet, actualApplicable facet → facet ∈ facets) ∧\n ∀ facet, facet ∈ facets → facet.claim = claim ∧ Articulated (articulations facet) ∧\n FacetArticulated (articulations facet) facet ∧ FacetDischarged facet\n/- The achievement obligation requires grounds for this very claim, without making observation a universal prerequisite. -/\ndef AchievementAccountability {W : Type} (achievement : Claim W) (articulations : Facet W → Articulation W)\n (actualApplicable : Facet W → Prop) (facets : List (Facet W)) : Prop :=\n Grounds achievement articulations actualApplicable facets\n/- The concrete achievement claim refers to each transition's own before/after states. -/\ndef transitionAchievement : Claim TransitionCase :=\n fun transition => Expanded (transitionBefore transition) (transitionAfter transition)\n/- This observation inspects an actually constructed successor and its output under that transition's input condition. -/\ndef transitionPerformanceRecord : Record TransitionCase :=\n ⟨fun transition => (transitionAfter transition).constructed.any\n (fun operation => operation == .successor && decide (operation.run (transitionInput transition) = 1)), true⟩\n/- The positive report test reads its asserted operation, input and output; it does not verify their presence in the after-state. -/\ndef transitionReportRecord : Record TransitionCase :=\n ⟨fun transition =>\n let report := transitionAnnouncement transition\n report.reportedNewOperation == .successor && report.input == 0 && report.expectedOutput == 1, true⟩\n/- Only the genuine extension matches the operation/performance observation in this two-transition model. -/\ntheorem transitionPerformanceCompatible :\n ∀ transition, Compatible [transitionPerformanceRecord] transition ↔ transition = .extend := by\n intro transition\n constructor\n · intro h\n have observed := h transitionPerformanceRecord (List.mem_singleton.mpr rfl)\n cases transition\n · cases observed\n · rfl\n · intro h; cases h\n intro record hr; have hr' := List.mem_singleton.mp hr; subst record\n rfl\n/- A compatible performance observation establishes the same transition's report content and hence its represented expansion. -/\ntheorem transitionSupported : Supports [transitionPerformanceRecord] transitionAchievement := by\n intro transition compatible\n have h := (transitionPerformanceCompatible transition).1 compatible\n subst transition\n have reportTrue : (transitionAnnouncement .extend).claim := by\n simp [transitionAnnouncement, transitionAfter, transitionInput,\n Announcement.claim, GeneratingSystem.report, generatingSystem, extendedState, baseState, Operation.run]\n exact announcementClaimImpliesExpansion _ reportTrue\n/- The actual scope is the shared input-zero condition, with no probabilistic inference introduced. -/\ndef transitionFacet : Facet TransitionCase :=\n .empirical [transitionPerformanceRecord] (fun transition => transitionInput transition = 0)\n transitionAchievement (fun _ => True)\n/- The empirical assessment has a real compatible witness and supports this scoped achievement. -/\ntheorem transitionFacetDischarged : FacetDischarged transitionFacet := by\n refine ⟨⟨.extend, (transitionPerformanceCompatible _).2 rfl, rfl⟩, ?_, ?_⟩\n · intro transition compatible _; exact transitionSupported transition compatible\n · intro _ _; trivial\n/- Every applicable facet of this specified achievement has matching articulation and actual discharged evidence. -/\ntheorem transitionAccountable :\n AchievementAccountability transitionAchievement canonicalArticulation\n (fun facet => facet = transitionFacet) [transitionFacet] := by\n refine ⟨by simp, ?_, ?_⟩\n · intro facet hf; subst facet; exact List.mem_singleton.mpr rfl\n · intro facet hf; have hf' := List.mem_singleton.mp hf; subst facet\n exact ⟨rfl, canonicalArticulated _ transitionFacetDischarged,\n canonicalFacetArticulated _, transitionFacetDischarged⟩\n/- Both actual transitions issue the same positive report about their own identified state pair. -/\ntheorem transitionReportCompatible (transition : TransitionCase) :\n Compatible [transitionReportRecord] transition := by\n intro record hr; have hr' := List.mem_singleton.mp hr; subst record\n rfl\n/- Inflation is a concrete report-compatible counterworld, so the positive report alone does not support the same achievement claim. -/\ntheorem transitionReportDoesNotSupport :\n Compatible [transitionReportRecord] .inflate ∧ ¬ transitionAchievement .inflate ∧\n ¬ Supports [transitionReportRecord] transitionAchievement := by\n have noExpansion : ¬ transitionAchievement .inflate := by\n simp [transitionAchievement, transitionBefore, transitionAfter, Expanded, baseState, inflatedState]\n exact ⟨transitionReportCompatible _, noExpansion, fun h => noExpansion (h _ (transitionReportCompatible _))⟩\n/- These concrete obligations, positive evidence and negative report case all refer to the same state-pair and input semantics. -/\ndef ConcreteAchievementExample : Prop :=\n AchievementAccountability transitionAchievement canonicalArticulation\n (fun facet => facet = transitionFacet) [transitionFacet] ∧\n Compatible [transitionPerformanceRecord] .extend ∧\n Supports [transitionPerformanceRecord] transitionAchievement ∧ transitionAchievement .extend ∧\n (Compatible [transitionReportRecord] .inflate ∧ ¬ transitionAchievement .inflate ∧\n ¬ Supports [transitionReportRecord] transitionAchievement) ∧\n (∀ transition, (transitionAnnouncement transition).before = transitionBefore transition ∧\n (transitionAnnouncement transition).after = transitionAfter transition ∧\n (transitionAnnouncement transition).input = transitionInput transition ∧ transitionInput transition = 0)\n/- The concrete example jointly inhabits accountability, evidence compatibility, actual gain, and the report-only countermodel. -/\ntheorem concreteAchievementExample : ConcreteAchievementExample := by\n refine ⟨transitionAccountable, (transitionPerformanceCompatible _).2 rfl, transitionSupported,\n transitionSupported .extend ((transitionPerformanceCompatible _).2 rfl),\n transitionReportDoesNotSupport, ?_⟩\n intro transition; exact ⟨rfl,rfl,rfl,rfl⟩\n/- Semantic evidence yields truth only at a world that actually satisfies those evidence conditions. -/\ntheorem achievementNeedsSupport {W : Type} (achievement : Claim W) (records : List (Record W))\n (actual : W) (reliableHere : Compatible records actual) (support : Supports records achievement) :\n achievement actual ∧ ConcreteAchievementExample :=\n ⟨support actual reliableHere, concreteAchievementExample⟩\n/- Weakening a conclusion preserves support; this makes no claim about weakening the evidence. -/\ntheorem supportWeakening {W : Type} (records : List (Record W)) (p q : Claim W)\n (support : Supports records p) (weaker : ∀ w, p w → q w) : Supports records q :=\n fun w hw => weaker w (support w hw)\n/- Discarding the only informative observation loses support for the unchanged switch claim. -/\ntheorem evidenceWeakeningCanLoseSupport :\n Supports ([⟨id, true⟩] : List (Record Bool)) (fun w => w = true) ∧\n ¬ Supports ([] : List (Record Bool)) (fun w => w = true) := by\n refine ⟨?_, ?_⟩\n · intro w hw; exact hw ⟨id,true⟩ (by simp)\n · intro h; have bad := h false (by intro r hr; cases hr); cases bad\n/- Restricting the quantified application domain preserves a supported universal conclusion. -/\ntheorem scopeRestriction {W X : Type} (records : List (Record W)) (p : W → X → Prop)\n (wide narrow : X → Prop) (included : ∀ x, narrow x → wide x)\n (support : Supports records (fun w => ∀ x, wide x → p w x)) :\n Supports records (fun w => ∀ x, narrow x → p w x) :=\n fun w hw x hx => support w hw x (included x hx)\n/- Actual applicability, rather than an optional classifier label, determines facet responsibility. -/\ndef Duties {W : Type} (applicable : Facet W → Prop) : Prop :=\n ∀ f, applicable f → FacetDischarged f\ndef LabeledDuties {W : Type} (_labels : List String) (applicable : Facet W → Prop) : Prop :=\n Duties applicable\n/- Combining applicable facets requires both sets of substantive duties. -/\ntheorem assessmentUnion {W : Type} (a b : Facet W → Prop) :\n Duties (fun f => a f ∨ b f) ↔ Duties a ∧ Duties b := by\n constructor\n · intro h; exact ⟨fun f hf => h f (Or.inl hf), fun f hf => h f (Or.inr hf)⟩\n · rintro ⟨ha,hb⟩ f (hf|hf); exact ha f hf; exact hb f hf\n/- Omitting or changing labels does not remove an applicable duty. -/\ntheorem labelsCannotWaive {W : Type} (xs ys : List String) (a : Facet W → Prop) :\n LabeledDuties xs a ↔ LabeledDuties ys a := Iff.rfl\n/- The observed switch is the outcome itself, not a record identifier. -/\ndef switchRecord : Record Bool := ⟨id, true⟩\ntheorem switchCompatible (w : Bool) : Compatible [switchRecord] w ↔ w = true := by\n constructor\n · intro h; exact h switchRecord (by simp)\n · intro hw r hr; simp only [List.mem_singleton] at hr; cases hr; exact hw\ntheorem switchSupported : Supports [switchRecord] (fun w : Bool => w = true) :=\n fun w hw => (switchCompatible w).1 hw\n/- The candidate action has specific benefit and cost outcomes; its inactive alternative has neither. -/\ndef optionBenefit (selected : Bool) : Nat := if selected then 4 else 0\ndef optionCost (selected : Bool) : Nat := if selected then 3 else 0\n/- The report describes each option's actual cost and benefit; it does not itself assert which option ought to be selected. -/\ndef optionReport (selected : Bool) : Prop :=\n optionCost selected ≤ 3 ∧ optionBenefit selected = (if selected then 4 else 0)\n/- The on position connects its own selected option to that option's benefit/cost outcome. -/\ndef switchPosition : ValuePosition Bool where\n Position := Bool\n Outcome := Nat × Nat\n adopted := true\n selected := id\n outcome := fun _ option => (optionBenefit option, optionCost option)\n objective := fun result => result.2 < result.1\n constraints := fun _ option => optionCost option ≤ 3\n starting := singleton (fun w => w = true)\n reasons := [fun _ option => optionReport option]\n limits := fun _ => True\n relevantCriticism := fun w => w = false\n response := fun w => if w then some \"benefit exceeds cost within budget\" else some \"reconsider if the budget no longer permits this cost\"\ntheorem switchValueProcedure : ValueProcedure switchPosition := by\n refine ⟨by simp [switchPosition], ?_, ?_, ?_⟩\n · refine ⟨true, (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩\n intro reason hr\n have hr' : reason = (fun (_ : Bool) (option : Bool) => optionReport option) := List.mem_singleton.mp hr\n subst reason\n exact ⟨by decide, rfl⟩\n · intro w _ _ allReasons\n have evidence := allReasons (fun (_ : Bool) (option : Bool) => optionReport option) (List.mem_singleton.mpr rfl)\n change optionReport true at evidence\n have benefitAboveBudget : 3 < optionBenefit true := by rw [evidence.2]; decide\n exact ⟨Nat.lt_of_le_of_lt evidence.1 benefitAboveBudget, evidence.1⟩\n · intro w _ _; cases w <;> simp [switchPosition]\n/- Adopting the other option updates the adopted starting state too, so rejection cannot be blamed on an inconsistent start. -/\ndef oppositePosition : ValuePosition Bool :=\n { switchPosition with adopted := false, starting := singleton (fun w => w = false) }\n/- The alternative has a joint adoption witness but its actual zero benefit/cost fails the adopted strict-benefit objective. -/\ntheorem oppositePositionRejected : JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition := by\n have witness : JointAdoption oppositePosition := by\n refine ⟨false, (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩\n intro reason hr\n have hr' : reason = (fun (_ : Bool) (option : Bool) => optionReport option) := List.mem_singleton.mp hr\n subst reason\n exact ⟨by decide, rfl⟩\n refine ⟨witness, ?_⟩\n intro h\n have allReasons : ∀ reason, reason ∈ oppositePosition.reasons → reason false oppositePosition.adopted := by\n intro reason hr\n have hr' : reason = (fun (_ : Bool) (option : Bool) => optionReport option) := List.mem_singleton.mp hr\n subst reason\n exact ⟨by decide, rfl⟩\n have bad := h.2.2.1 false ((modelsSingleton _ _).2 rfl) trivial allReasons\n exact Nat.lt_irrefl 0 bad.1\n/- Contradictory starting assumptions and an impossible selected/adopted equality are separate inadmissible variants. -/\ndef contradictoryStartingPosition : ValuePosition Bool :=\n { switchPosition with starting := singleton (fun _ => False) }\ndef impossibleAdoptionPosition : ValuePosition Bool :=\n { switchPosition with selected := fun _ => false }\n/- The common-world witness rejects both contradiction and an impossible commitment instead of proving them vacuously. -/\ntheorem inadmissibleValuePositionsRejected :\n ¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition := by\n constructor\n · intro h; obtain ⟨w,hw,_,_,_⟩ := h.2.1\n exact (modelsSingleton _ _).1 hw\n · intro h; obtain ⟨w,_,_,hw,_⟩ := h.2.1\n cases hw\n/- Removing the reasons leaves only a position and assertion, which fails this value procedure. -/\ndef unsupportedPosition : ValuePosition Bool := { switchPosition with reasons := [] }\ndef switchEmpirical : Facet Bool :=\n .empirical [switchRecord] (fun _ => True) (fun w => w = true) (fun _ => True)\ntheorem switchEmpiricalDischarged : FacetDischarged switchEmpirical := by\n refine ⟨⟨true, (switchCompatible true).2 rfl, trivial⟩, ?_, ?_⟩\n · intro w hw _; exact switchSupported w hw\n · intro w _; trivial\n/- A mixed empirical/value position has actual empirical evidence but still lacks its value-reason duty. -/\ntheorem mixedMissingResponsibility :\n FacetDischarged switchEmpirical ∧\n ¬ LabeledDuties [] (fun f : Facet Bool => f = switchEmpirical ∨ f = .value unsupportedPosition) := by\n refine ⟨switchEmpiricalDischarged, ?_⟩\n intro h\n have bad := (h (.value unsupportedPosition) (Or.inr rfl)).1\n exact bad rfl\n/- A fully identified argument may still fail to entail the stated conclusion. -/\ndef uninformativeArgument : Articulation Bool :=\n ⟨[\"switch state\"], emptyTheory, [fun _ => True], fun _ => True⟩\ntheorem articulationNotSupport : Articulated uninformativeArgument ∧\n ¬ Entails uninformativeArgument.assumptions (fun w : Bool => w = true) := by\n exact ⟨⟨by simp [uninformativeArgument], by simp [uninformativeArgument]⟩,\n consistentIncomplete.2.1⟩\n/- Identifiable but unrelated argument fields cannot replace the actual observation grounds under the connected adapter. -/\ntheorem unrelatedArticulationRejected :\n Articulated uninformativeArgument ∧ FacetDischarged switchEmpirical ∧\n ¬ FacetArticulated uninformativeArgument switchEmpirical := by\n refine ⟨articulationNotSupport.1, switchEmpiricalDischarged, ?_⟩\n intro h\n have relation := congrFun h.1 (Compatible [switchRecord])\n have bad : False := relation.mpr rfl\n exact bad\n/- Repetition of the same unrelated temperature observation leaves the switch state undetermined. -/\ndef temperatureRecord : Record (Bool × Bool) := ⟨Prod.fst, true⟩\ntheorem temperatureCompatible (b : Bool) :\n Compatible [temperatureRecord, temperatureRecord] (true,b) := by\n intro r hr\n simp at hr\n cases hr\n rfl\n/- The world identifies a selected action and its budget; the action costs three units. -/\nabbrev BudgetWorld := Bool × Nat\n/- A real issued announcement asserts the selected action, but says nothing about affordability. -/\ndef announcement : String := \"activate\"\ndef announcementPosition : ValuePosition BudgetWorld where\n Position := Bool\n Outcome := Nat × Nat\n adopted := true\n selected := Prod.fst\n outcome := fun _ option => (optionBenefit option, optionCost option)\n objective := fun result => result.2 < result.1\n constraints := fun w option => optionCost option ≤ w.2\n starting := singleton (fun w => w.1 = true)\n reasons := [fun _ option => announcement = (if option then \"activate\" else \"disable\")]\n limits := fun _ => True\n relevantCriticism := fun w => w.2 < 3\n response := fun _ => some \"reconsider the action when its cost exceeds budget\"\n/- The zero-budget counterworld satisfies the stated starts, adoption and all announced reasons jointly. -/\ntheorem announcementHasJointAdoption : JointAdoption announcementPosition := by\n refine ⟨(true,0), (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩\n intro reason hr\n have hr' : reason = (fun (_ : BudgetWorld) (option : Bool) => announcement = (if option then \"activate\" else \"disable\")) :=\n List.mem_singleton.mp hr\n subst reason\n rfl\n/- A nonempty announcement remains true in a jointly admissible zero-budget world but cannot support the action's affordability. -/\ntheorem announcementNotBudgetReason :\n announcementPosition.reasons ≠ [] ∧ announcementPosition.commitment (true,0) ∧\n (∀ reason, reason ∈ announcementPosition.reasons → reason (true,0) announcementPosition.adopted) ∧\n ¬ announcementPosition.consequence (true,0) ∧ ¬ ValueProcedure announcementPosition := by\n refine ⟨by simp [announcementPosition], rfl, ?_, (by intro h; cases h.2), ?_⟩\n · intro reason hr\n have hr' : reason = (fun (_ : BudgetWorld) (option : Bool) => announcement = (if option then \"activate\" else \"disable\")) := List.mem_singleton.mp hr\n subst reason\n rfl\n · intro h\n have allReasons : ∀ reason, reason ∈ announcementPosition.reasons → reason (true,0) announcementPosition.adopted := by\n intro reason hr\n have hr' : reason = (fun (_ : BudgetWorld) (option : Bool) => announcement = (if option then \"activate\" else \"disable\")) := List.mem_singleton.mp hr\n subst reason\n rfl\n have bad := h.2.2.1 (true,0) ((modelsSingleton _ _).2 rfl) trivial allReasons\n cases bad.2\n/- A repeated actual selection observation contains no budget information. -/\ndef actionRecord : Record BudgetWorld := ⟨Prod.fst, true⟩\ntheorem actionCompatible (budget : Nat) : Compatible [actionRecord, actionRecord] (true,budget) := by\n intro r hr; simp at hr; cases hr; rfl\n/- Single and repeated irrelevant observations cannot establish the other outcome or the same action's budget adequacy. -/\ntheorem measurementRepeatNotSupport :\n temperatureRecord.test (true,false) = true ∧\n Compatible [temperatureRecord,temperatureRecord] (true,false) ∧\n Compatible [temperatureRecord,temperatureRecord] (true,true) ∧\n ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧\n ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧\n Compatible [actionRecord,actionRecord] (true,0) ∧\n Compatible [actionRecord,actionRecord] (true,3) ∧\n ¬ Supports [actionRecord] announcementPosition.consequence ∧\n ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧\n ¬ ValueProcedure announcementPosition := by\n refine ⟨rfl, temperatureCompatible false, temperatureCompatible true, ?_, ?_,\n actionCompatible 0, actionCompatible 3, ?_, ?_, announcementNotBudgetReason.2.2.2.2⟩\n · intro h\n have bad := h (true,false) (by intro r hr; simp only [List.mem_singleton] at hr; cases hr; rfl)\n cases bad\n · intro h; have bad := h (true,false) (temperatureCompatible false); cases bad\n · intro h\n have bad := h (true,0) (by intro r hr; simp only [List.mem_singleton] at hr; cases hr; rfl)\n cases bad.2\n · intro h; have bad := h (true,0) (actionCompatible 0); cases bad.2\n/- Missing reason records fail a procedure; independently, a present announcement fails the explicit budget-support criterion. -/\ntheorem selfAssertionNotReason :\n (unsupportedPosition.commitment true ∧ ¬ ValueProcedure unsupportedPosition) ∧\n (announcementPosition.reasons ≠ [] ∧ announcementPosition.commitment (true,0) ∧\n ¬ announcementPosition.consequence (true,0) ∧ ¬ ValueProcedure announcementPosition) ∧\n JointAdoption announcementPosition :=\n ⟨⟨rfl, fun h => h.1 rfl⟩,\n ⟨announcementNotBudgetReason.1, announcementNotBudgetReason.2.1,\n announcementNotBudgetReason.2.2.2.1, announcementNotBudgetReason.2.2.2.2⟩,\n announcementHasJointAdoption⟩\n/- The value procedure is satisfiable although the adopted starting commitment is not entailed by empty facts. -/\ntheorem valueWithoutSelfProof : ValueProcedure switchPosition ∧\n Satisfiable switchPosition.starting ∧\n ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧\n (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧\n (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition) :=\n ⟨switchValueProcedure, ⟨true, (modelsSingleton _ _).2 rfl⟩, consistentIncomplete.2.1,\n oppositePositionRejected, inadmissibleValuePositionsRejected⟩\n/- The world records the selected option and its actual benefit/cost outcomes. -/\nabbrev BenefitCostWorld := Bool × (Nat × Nat)\ndef measuredOutcome (world : BenefitCostWorld) (option : Bool) : Nat × Nat :=\n if option then world.2 else (0,0)\ndef benefitReason (world : BenefitCostWorld) (option : Bool) : Prop :=\n (measuredOutcome world option).1 = 4\ndef costReason (world : BenefitCostWorld) (option : Bool) : Prop :=\n (measuredOutcome world option).2 ≤ 3\n/- Neither recorded benefit nor recorded cost alone establishes the selected option's joint consequence. -/\ndef jointReasonPosition : ValuePosition BenefitCostWorld where\n Position := Bool\n Outcome := Nat × Nat\n adopted := true\n selected := Prod.fst\n outcome := measuredOutcome\n objective := fun result => result.2 < result.1\n constraints := fun world option => (measuredOutcome world option).2 ≤ 3\n starting := singleton (fun world => world.1 = true)\n reasons := [benefitReason, costReason]\n limits := fun _ => True\n relevantCriticism := fun world => 3 < world.2.2\n response := fun _ => some \"reassess the option when its cost exceeds the budget\"\n/- These two content constraints jointly establish the consequence in a nonempty adopted world. -/\ntheorem jointReasonProcedure : ValueProcedure jointReasonPosition := by\n refine ⟨by simp [jointReasonPosition], ?_, ?_, ?_⟩\n · refine ⟨(true,(4,3)), (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩\n intro reason hr\n change reason ∈ [benefitReason,costReason] at hr\n rcases List.mem_cons.mp hr with hr | hr\n · subst reason; rfl\n · have hr' := List.mem_singleton.mp hr\n subst reason\n change 3 ≤ 3; exact Nat.le_refl 3\n · intro world _ _ reasons\n have benefit := reasons benefitReason (by change benefitReason ∈ [benefitReason,costReason]; simp)\n have cost := reasons costReason (by change costReason ∈ [benefitReason,costReason]; simp)\n change (measuredOutcome world true).1 = 4 at benefit\n change (measuredOutcome world true).2 ≤ 3 at cost\n refine ⟨?_, cost⟩\n have bigger : 3 < (measuredOutcome world true).1 := by rw [benefit]; decide\n exact Nat.lt_of_le_of_lt cost bigger\n · intro world _ _\n exact ⟨\"reassess the option when its cost exceeds the budget\", rfl, by decide⟩\n/- Each separate reason has a concrete same-start/limit/adoption counterworld; their conjunction is sufficient. -/\ndef JointReasonsExample : Prop :=\n ValueProcedure jointReasonPosition ∧\n (Models jointReasonPosition.starting (true,(4,5)) ∧ jointReasonPosition.limits (true,(4,5)) ∧\n jointReasonPosition.commitment (true,(4,5)) ∧ benefitReason (true,(4,5)) true ∧\n ¬ jointReasonPosition.consequence (true,(4,5))) ∧\n (Models jointReasonPosition.starting (true,(0,3)) ∧ jointReasonPosition.limits (true,(0,3)) ∧\n jointReasonPosition.commitment (true,(0,3)) ∧ costReason (true,(0,3)) true ∧\n ¬ jointReasonPosition.consequence (true,(0,3)))\ntheorem jointReasonsExample : JointReasonsExample := by\n refine ⟨jointReasonProcedure,\n ⟨(modelsSingleton _ _).2 rfl, trivial, rfl, rfl, ?_⟩,\n ⟨(modelsSingleton _ _).2 rfl, trivial, rfl, Nat.le_refl 3, ?_⟩⟩\n · intro h; have bad : 5 ≤ 3 := h.2; omega\n · intro h; have bad : 3 < 0 := h.1; omega\n/- Empirical observations, semantic inference and criticism-responsive reasons coexist without a scalar score. -/\ntheorem heterogeneousReasons :\n FacetDischarged switchEmpirical ∧\n FacetDischarged (Facet.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) ∧\n FacetDischarged (Facet.value switchPosition) ∧ JointReasonsExample := by\n refine ⟨switchEmpiricalDischarged, ⟨⟨true, (modelsSingleton _ _).2 rfl⟩, ?_⟩, switchValueProcedure, jointReasonsExample⟩\n intro w hw; exact (modelsSingleton (fun x : Bool => x = true) w).1 hw\n\n/- This local observation checks the actual output on input zero. -/\ndef zeroRecord : Record (Nat → Bool) := ⟨fun f => f 0, true⟩\ndef localGenerator (seed : Nat) : Nat → Bool := fun n => n == seed\n/- All outputs being true is a stronger, explicitly quantified capability claim. -/\ndef allTrue : Claim (Nat → Bool) := fun f => ∀ n, f n = true\ntheorem zeroCompatible (f : Nat → Bool) : Compatible [zeroRecord] f ↔ f 0 = true := by\n constructor\n · intro h; exact h zeroRecord (by simp)\n · intro hf r hr; simp only [List.mem_singleton] at hr; cases hr; exact hf\n/- A generating subject owns an earlier predicate and a seed used to revise that actual predicate. -/\nstructure GeneratingProcess where\n owner : Nat\n prior : Nat → Bool\n generateSeed : Nat\n/- The revision preserves prior successes and adds the seed-selected case through the actual generator. -/\ndef GeneratingProcess.outputRevision (process : GeneratingProcess) : Nat → Bool :=\n fun input => process.prior input || localGenerator process.generateSeed input\n/- A produced revision retains its producer and exact old/new objects. -/\nstructure ProducedRevision where\n producer : Nat\n before : Nat → Bool\n after : Nat → Bool\n/- The subject itself constructs the owned before/after revision object. -/\ndef GeneratingProcess.produce (process : GeneratingProcess) : ProducedRevision :=\n ⟨process.owner, process.prior, process.outputRevision⟩\ndef sampleGeneratingProcess : GeneratingProcess := ⟨17, fun _ => false, 0⟩\n/- This same-owner revision actually changes input zero, while its produced predicate still fails at input one. -/\ndef OwnedRevisionExample : Prop :=\n sampleGeneratingProcess.produce.producer = sampleGeneratingProcess.owner ∧\n sampleGeneratingProcess.produce.before = sampleGeneratingProcess.prior ∧\n sampleGeneratingProcess.produce.after = sampleGeneratingProcess.outputRevision ∧\n sampleGeneratingProcess.produce.before 0 = false ∧ sampleGeneratingProcess.produce.after 0 = true ∧\n sampleGeneratingProcess.produce.after 1 = false ∧\n Compatible [zeroRecord] sampleGeneratingProcess.produce.after ∧\n ¬ Supports [zeroRecord] allTrue\n/- Actual producer/old/new links and the compatible failing revision witness the insufficiency of self-origin. -/\ntheorem ownedRevisionExample : OwnedRevisionExample := by\n refine ⟨rfl,rfl,rfl,rfl,rfl,rfl,(zeroCompatible _).2 rfl, ?_⟩\n intro h\n have bad := h sampleGeneratingProcess.produce.after ((zeroCompatible _).2 rfl) 1\n cases bad\n/- The generator's own sample succeeds, but its generated revision has a concrete unsupported global claim. -/\ntheorem selfOriginDoesNotSupport :\n localGenerator 0 0 = true ∧ localGenerator 0 1 = false ∧\n Compatible [zeroRecord] (localGenerator 0) ∧\n ¬ Supports [zeroRecord] allTrue ∧ OwnedRevisionExample := by\n refine ⟨rfl, rfl, (zeroCompatible _).2 rfl, ?_, ownedRevisionExample⟩\n intro h\n have bad := h (localGenerator 0) ((zeroCompatible _).2 rfl) 1\n cases bad\n/- A proper local observation allows both a universally successful and a failing extension. -/\ntheorem localNotUniversal :\n (∃ outside : Nat, outside ≠ 0) ∧\n Compatible [zeroRecord] (fun _ => true) ∧\n Compatible [zeroRecord] (localGenerator 0) ∧\n allTrue (fun _ => true) ∧ ¬ allTrue (localGenerator 0) ∧\n ¬ Supports [zeroRecord] allTrue := by\n refine ⟨⟨1, by decide⟩, (zeroCompatible _).2 rfl, (zeroCompatible _).2 rfl,\n (fun _ => rfl), ?_, selfOriginDoesNotSupport.2.2.2.1⟩\n intro h; have bad := h 1; cases bad\n/- Two implementations agree on the actual observed input and differ on a specified relevant omitted input. -/\ntheorem hiddenDifference :\n (∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧\n (fun _ : Nat => true) 1 ≠ localGenerator 0 1 := by\n refine ⟨?_, by decide⟩\n intro n hn; cases hn; rfl\n/- One observation supplies only its actual input-specific consequence, without repetition. -/\ntheorem singleObservation : [zeroRecord].length = 1 ∧\n (∃ f, Compatible [zeroRecord] f) ∧\n Supports [zeroRecord] (fun f => f 0 = true) ∧\n ¬ Supports [zeroRecord] allTrue :=\n ⟨rfl, ⟨localGenerator 0, (zeroCompatible _).2 rfl⟩,\n (fun f hf => (zeroCompatible f).1 hf), selfOriginDoesNotSupport.2.2.2.1⟩\n/- This inferential assessment derives a successor value from its explicit numeric premise without observation. -/\ndef arithmeticFacet : Facet Nat := .inferential (singleton (fun n => n = 2)) (fun n => n + 1 = 3)\ndef usesObservation {W : Type} : Facet W → Bool\n | .empirical _ _ _ _ => true\n | _ => false\n/- An actual valid inferential assessment refutes a mandatory measurement/repetition/framework chain. -/\ntheorem noUniversalChain : FacetDischarged arithmeticFacet ∧ usesObservation arithmeticFacet = false := by\n refine ⟨⟨⟨2, (modelsSingleton _ _).2 rfl⟩, ?_⟩, rfl⟩\n intro n hn\n have premise := (modelsSingleton (fun x : Nat => x = 2) n).1 hn\n change n + 1 = 3\n rw [premise]\n/- A trial has a reproducible setting, an actual outcome and a separately recorded outcome. -/\nstructure Trial where\n setting : Nat\n actualOutcome : Nat\n recordedOutcome : Nat\n/- Verifying a record, reproducing settings and retaining a conclusion are separate predicates. -/\ndef Verified (t : Trial) : Prop := t.recordedOutcome = t.actualOutcome\ndef Reproduced (a b : Trial) : Prop := a.setting = b.setting\ndef Bounded (t : Trial) : Prop := t.actualOutcome ≤ 2\n/- Same-setting possible trials can differ while preserving the chosen bound; no probability semantics is claimed. -/\ntheorem variableOutcomesStableBound :\n let a : Trial := ⟨0,1,1⟩\n let b : Trial := ⟨0,2,2⟩\n Reproduced a b ∧ a.actualOutcome ≠ b.actualOutcome ∧ Bounded a ∧ Bounded b := by\n simp [Reproduced, Bounded]\n/- Concrete records distinguish record accuracy, condition reproduction and conclusion stability. -/\ntheorem verificationReproductionStability :\n (Verified ⟨0,1,1⟩ ∧ Verified ⟨1,1,1⟩ ∧ ¬ Reproduced ⟨0,1,1⟩ ⟨1,1,1⟩) ∧\n (Reproduced ⟨0,1,1⟩ ⟨0,3,2⟩ ∧ ¬ Verified ⟨0,3,2⟩ ∧ ¬ Bounded ⟨0,3,2⟩) ∧\n (Bounded ⟨0,1,1⟩ ∧ Bounded ⟨0,2,0⟩ ∧ ¬ Verified ⟨0,2,0⟩) := by\n simp [Verified, Reproduced, Bounded]\n/- Explanation certificates are executable syntax for this same arithmetic process. -/\ninductive Program where\n | doubleInput\n | constant (value : Nat)\ndef Program.eval : Program → Nat → Nat\n | .doubleInput, n => n + n\n | .constant value, _ => value\n/- A process exposes outputs and an explanation response, whose certificate can be checked against those outputs. -/\nstructure Process where\n output : Nat → Nat\n explanation : Option Program\n/- The output-only application contract checks every relevant input. -/\ndef OutputContract (p : Process) : Prop := ∀ n, p.output n = n + n\n/- The explanation application contract requires a provided certificate faithful to this very process. -/\ndef ExplanationContract (p : Process) : Prop :=\n ∃ program, p.explanation = some program ∧ ∀ n, program.eval n = p.output n\n/- This process produces doubled values but returns no explanatory certificate. -/\ndef outputOnlyProcess : Process := ⟨fun n => n + n, none⟩\ndef explainedProcess : Process := ⟨fun n => n + n, some .doubleInput⟩\n/- Object scope fixes the very process whose contract is assessed; contract inputs themselves still range over all naturals. -/\ndef processScope (assessed : Process) : Theory Process :=\n singleton (fun candidate => candidate = assessed)\n/- This inferential facet checks an explicit contract under exact process-identity assumptions. -/\ndef processContractFacet (assessed : Process) (contract : Claim Process) : Facet Process :=\n .inferential (processScope assessed) contract\n/- The scope's compatible interpretations are exactly this assessed process, not an unrelated substitute. -/\ntheorem processScopeModels (assessed candidate : Process) :\n Models (processScope assessed) candidate ↔ candidate = assessed :=\n modelsSingleton (fun process => process = assessed) candidate\n/- A concrete contract proof supplies the facet's consequence for its scoped object. -/\ntheorem processContractDischarged (assessed : Process) (contract : Claim Process) (proof : contract assessed) :\n FacetDischarged (processContractFacet assessed contract) := by\n refine ⟨⟨assessed,(processScopeModels _ _).2 rfl⟩, ?_⟩\n intro candidate hc\n have same := (processScopeModels _ _).1 hc\n subst candidate\n exact proof\n/- Scoped capability grounds include exact claim, object-specific assumptions, canonical articulation and actual assessment. -/\ndef ProcessGrounds (assessed : Process) (contract : Claim Process) : Prop :=\n Grounds contract canonicalArticulation (fun facet => facet = processContractFacet assessed contract)\n [processContractFacet assessed contract]\ntheorem processGrounds (assessed : Process) (contract : Claim Process) (proof : contract assessed) :\n ProcessGrounds assessed contract := by\n have discharged := processContractDischarged assessed contract proof\n refine ⟨by simp, ?_, ?_⟩\n · intro facet hf; subst facet; exact List.mem_singleton.mpr rfl\n · intro facet hf; have hf' := List.mem_singleton.mp hf; subst facet\n exact ⟨rfl,canonicalArticulated _ discharged,canonicalFacetArticulated _,discharged⟩\n/- Universal output correctness here comes from the concrete program definition, not from an assumed capability label. -/\ntheorem outputCorrectByEvaluation : OutputContract outputOnlyProcess := fun _ => rfl\n/- This same process actually returns no explanation certificate. -/\ntheorem outputOnlyNoExplanation : ¬ ExplanationContract outputOnlyProcess := by\n rintro ⟨program,h,_⟩; cases h\n/- The full application contract requires outputs and an explanation of that same process. -/\ndef FullProcessContract (assessed : Process) : Prop := OutputContract assessed ∧ ExplanationContract assessed\n/- Output-only grounds have the assessed process itself as a counterworld to the stronger contract. -/\ndef OutputContractEvidence : Prop :=\n ProcessGrounds outputOnlyProcess OutputContract ∧\n Models (processScope outputOnlyProcess) outputOnlyProcess ∧\n ¬ Entails (processScope outputOnlyProcess) FullProcessContract\n/- Existing output evidence does not supply the absent explanation for the same object and scope. -/\ntheorem outputContractEvidence : OutputContractEvidence := by\n refine ⟨processGrounds _ _ outputCorrectByEvaluation, (processScopeModels _ _).2 rfl, ?_⟩\n intro stronger\n exact outputOnlyNoExplanation (stronger outputOnlyProcess ((processScopeModels _ _).2 rfl)).2\n/- Both actual application contracts have grounds and explicit object scopes; neither scope is empty. -/\ndef ScopedApplicationEvidence : Prop :=\n ProcessGrounds outputOnlyProcess OutputContract ∧\n ProcessGrounds explainedProcess FullProcessContract ∧\n (∀ candidate, Models (processScope outputOnlyProcess) candidate ↔ candidate = outputOnlyProcess) ∧\n (∀ candidate, Models (processScope explainedProcess) candidate ↔ candidate = explainedProcess) ∧\n Satisfiable (processScope outputOnlyProcess) ∧ Satisfiable (processScope explainedProcess)\n/- Concrete evaluation and a faithful double-input certificate establish the two differently scoped contracts. -/\ntheorem scopedApplicationEvidence : ScopedApplicationEvidence := by\n refine ⟨processGrounds _ _ outputCorrectByEvaluation, processGrounds _ _ ?_,\n processScopeModels _,processScopeModels _,⟨_,(processScopeModels _ _).2 rfl⟩,\n ⟨_,(processScopeModels _ _).2 rfl⟩⟩\n exact ⟨fun _ => rfl,⟨.doubleInput,rfl,fun _ => rfl⟩⟩\n/- Universal output correctness does not entail the explanation-requiring contract for the same process. -/\ntheorem outputNotExplanation : OutputContract outputOnlyProcess ∧\n ¬ ExplanationContract outputOnlyProcess ∧ OutputContractEvidence :=\n ⟨outputCorrectByEvaluation, outputOnlyNoExplanation, outputContractEvidence⟩\n/- Applications may use distinct contracts, and a faithful certificate can satisfy the stronger one. -/\ntheorem applicationContractsDiffer :\n (OutputContract outputOnlyProcess ∧ ¬ (OutputContract outputOnlyProcess ∧ ExplanationContract outputOnlyProcess)) ∧\n (OutputContract explainedProcess ∧ ExplanationContract explainedProcess) ∧\n ScopedApplicationEvidence :=\n ⟨⟨outputCorrectByEvaluation, fun h => outputOnlyNoExplanation h.2⟩,\n ⟨(fun _ => rfl), ⟨.doubleInput, rfl, fun _ => rfl⟩⟩, scopedApplicationEvidence⟩\n/- The assessor supplies a mathematical certificate; the process's own explanation response is unnecessary. -/\nstructure ExternalCertificate (p : Process) where\n assessorId : Nat\n assessedId : Nat\n distinctParticipants : assessorId ≠ assessedId\n outputCorrect : ∀ n, p.output n = n + n\n/- The external assessor 42 evaluates the specified process 7; the full output proof is constructed by evaluation. -/\ndef externalOutputCertificate : ExternalCertificate outputOnlyProcess :=\n ⟨42,7,by decide,fun _ => rfl⟩\n/- An external certificate establishes the output contract without producing an internal explanation. -/\ntheorem externalAssessment :\n (∃ certificate : ExternalCertificate outputOnlyProcess,\n certificate.assessorId = 42 ∧ certificate.assessedId = 7 ∧\n certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧\n ProcessGrounds outputOnlyProcess OutputContract ∧\n ¬ ExplanationContract outputOnlyProcess :=\n ⟨⟨externalOutputCertificate,rfl,rfl,externalOutputCertificate.distinctParticipants,\n externalOutputCertificate.outputCorrect⟩,\n processGrounds outputOnlyProcess OutputContract externalOutputCertificate.outputCorrect,\n outputOnlyNoExplanation⟩\n/- This argument records concepts and actual premises for a semantic inference, separately from executable tests. -/\ndef arithmeticArticulation : Articulation Nat := canonicalArticulation arithmeticFacet\n/- A reasoned inferential assessment needs no observation method, while applicable empirical assessment retains observations. -/\ntheorem nonExecutableAssessment :\n Grounds (fun n : Nat => n + 1 = 3) canonicalArticulation (fun f => f = arithmeticFacet) [arithmeticFacet] ∧\n usesObservation arithmeticFacet = false ∧\n FacetDischarged switchEmpirical ∧ usesObservation switchEmpirical = true := by\n refine ⟨⟨by simp, (by intro f hf; cases hf; simp), ?_⟩, rfl, switchEmpiricalDischarged, rfl⟩\n intro f hf; simp only [List.mem_singleton] at hf; cases hf\n exact ⟨rfl, canonicalArticulated _ noUniversalChain.1, canonicalFacetArticulated _, noUniversalChain.1⟩\n\nend CoreReader.Evidence\n```\n\n\n\n **L1** Import CoreReader.Logic, making its checked declarations available to this module; this line states no new philosophical result.\n\n\n **L2** Import CoreReader.Agency, making its checked declarations available to this module; this line states no new philosophical result.\n\n\n **L4** Open namespace CoreReader.Evidence so subsequent declarations receive this module-qualified name.\n\n\n **L5** Make names from CoreReader.Logic available without qualification; this changes name resolution, not assumptions.\n\n\n **L6** Make names from CoreReader.Agency available without qualification; this changes name resolution, not assumptions.\n\n\n **L8** Document the intended scope of Record. The corresponding declaration concerns: A record packages a supplied Boolean test and its supplied observed result; provenance and measurement reliability are not fields. This comment is explanatory, not a proof premise.\n\n\n **L9** Declare the data interface Record. A record packages a supplied Boolean test and its supplied observed result; provenance and measurement reliability are not fields.\n\n\n **L10** Store a specified Boolean test that reads the actual represented world.\n\n\n **L11** Store the observed Boolean outcome to which that test will be compared.\n\n\n **L12** Document the intended scope of Compatible. The corresponding declaration concerns: A world is compatible when every listed test yields its recorded result. The empty record list admits every world. This comment is explanatory, not a proof premise.\n\n\n **L13** Define Compatible. A world is compatible when every listed test yields its recorded result. The empty record list admits every world.\n\n\n **L14** Require every listed record’s actual test at w to equal that record’s observed outcome.\n\n\n **L15** Document the intended scope of Supports. The corresponding declaration concerns: Support means that the claim holds in every compatible modeled world. It is semantic entailment from records, not a statistical confidence measure. This comment is explanatory, not a proof premise.\n\n\n **L16** Define Supports. Support means that the claim holds in every compatible modeled world. It is semantic entailment from records, not a statistical confidence measure.\n\n\n **L17** Require the very claim to hold in every world compatible with all records; absent compatible worlds this implication alone can be vacuous.\n\n\n **L18** Document the intended scope of Articulation. The corresponding declaration concerns: Packages concept strings, an assumption theory, a list of reason claims, and a scope/limits claim. This comment is explanatory, not a proof premise.\n\n\n **L19** Declare the data interface Articulation. Packages concept strings, an assumption theory, a list of reason claims, and a scope/limits claim.\n\n\n **L20** Store identifiable concept names; strings alone do not establish semantic adequacy.\n\n\n **L21** Store the actual theory stated as the articulation’s assumptions.\n\n\n **L22** Store reason contents as propositions about the same world type.\n\n\n **L23** Store the actual application-limit predicate for those reasons.\n\n\n **L24** Document the intended scope of Articulated. The corresponding declaration concerns: Checks only that concept and reason lists are nonempty; it does not establish truth, relevance, or a relation to the target claim. This comment is explanatory, not a proof premise.\n\n\n **L25** Define Articulated. Checks only that concept and reason lists are nonempty; it does not establish truth, relevance, or a relation to the target claim.\n\n\n **L26** Require nonempty concept and reason lists only; this procedural condition is weaker than matching, discharged Grounds.\n\n\n **L27** Document the intended scope of ValuePosition. The corresponding declaration concerns: Represents an adopted option, selected option, option-indexed outcomes/reasons, objectives, constraints, starting theory, scope and criticism response; this is a disclosed application adapter. This comment is explanatory, not a proof premise.\n\n\n **L28** Declare the data interface ValuePosition. Represents an adopted option, selected option, option-indexed outcomes/reasons, objectives, constraints, starting theory, scope and criticism response; this is a disclosed application adapter.\n\n\n **L29** Supply the type of options among which this value position adopts one.\n\n\n **L30** Supply the outcome type used to interpret the effects of each option.\n\n\n **L31** Specify which option is adopted, separately from which option a world actually selects.\n\n\n **L32** Read the actually selected option from each world.\n\n\n **L33** Interpret the actual outcome of each option at each world, rather than storing an arbitrary support label.\n\n\n **L34** State the adopted objective as a predicate on outcomes; its value authority is not proved by this field.\n\n\n **L35** State the world- and option-specific constraints checked alongside the objective.\n\n\n **L36** Store the starting theory; JointAdoption will require it to share a real model with adoption and reasons.\n\n\n **L37** Store reasons parameterized by both world and option, so switching the adopted option changes the assessed reasons.\n\n\n **L38** Specify the scope within which this value-assessment procedure claims its conclusions.\n\n\n **L39** Identify which worlds present relevant criticism; this is an explicit application predicate.\n\n\n **L40** Store an optional textual response at each world; its presence does not prove that the criticism is answered adequately.\n\n\n **L41** Document the intended scope of ValuePosition.commitment. The corresponding declaration concerns: The commitment claim says the world selects this position's adopted option; it is no longer a freely relabeled separate claim field. This comment is explanatory, not a proof premise.\n\n\n **L42** Define ValuePosition.commitment. The commitment claim says the world selects this position's adopted option; it is no longer a freely relabeled separate claim field.\n\n\n **L43** Derive the commitment claim by equating actual selection with this very adopted option.\n\n\n **L44** Document the intended scope of ValuePosition.consequence. The corresponding declaration concerns: Checks this adopted option's modeled outcome against its objective and constraints. This comment is explanatory, not a proof premise.\n\n\n **L45** Define ValuePosition.consequence. Checks this adopted option's modeled outcome against its objective and constraints.\n\n\n **L46** Derive the assessed consequence from this adopted option’s actual outcome satisfying the objective and its actual constraints.\n\n\n **L47** Document the intended scope of ValuePosition.activeReasons. The corresponding declaration concerns: Specializes every option-indexed reason to the adopted option for articulation. This comment is explanatory, not a proof premise.\n\n\n **L48** Define ValuePosition.activeReasons. Specializes every option-indexed reason to the adopted option for articulation.\n\n\n **L49** Specialize each option-indexed reason to the adopted option to produce its actual articulated world predicate.\n\n\n **L50** Document the intended scope of JointAdoption. The corresponding declaration concerns: Requires one world jointly modeling the starting theory, scope, actual adoption and all adopted-option reasons. This comment is explanatory, not a proof premise.\n\n\n **L51** Define JointAdoption. Requires one world jointly modeling the starting theory, scope, actual adoption and all adopted-option reasons.\n\n\n **L52** Require one common world for starting assumptions, application limits and actual adoption.\n\n\n **L53** At that same witness, require every listed reason for that adopted option to hold together.\n\n\n **L54** Document the intended scope of ValueProcedure. The corresponding declaration concerns: Requires nonempty reasons, a joint adoption witness, joint reasons supporting the option's consequence within starting assumptions/scope, and nonempty criticism responses. It does not prove ultimate value correctness. This comment is explanatory, not a proof premise.\n\n\n **L55** Define ValueProcedure. Requires nonempty reasons, a joint adoption witness, joint reasons supporting the option's consequence within starting assumptions/scope, and nonempty criticism responses. It does not prove ultimate value correctness.\n\n\n **L56** Begin ValueProcedure with nonempty reasons and the complete joint adoption witness.\n\n\n **L57** For every world satisfying the actual starting theory and limits, impose the following conditional consequence requirement.\n\n\n **L58** Use the conjunction of all reasons for the adopted option to imply its actual consequence; no individual-reason sufficiency requirement is imposed.\n\n\n **L59** Within limits, every relevant criticism must receive a specified nonempty response; this checks recorded response, not persuasiveness.\n\n\n **L60** Document the intended scope of Facet. The corresponding declaration concerns: Defines three distinct facet kinds with different discharge conditions. This comment is explanatory, not a proof premise.\n\n\n **L61** Declare the alternatives Facet. Defines three distinct facet kinds with different discharge conditions.\n\n\n **L62** An empirical facet stores actual test records together with its scope, conclusion and stated uncertainty predicate.\n\n\n **L63** An inferential facet stores its actual premise theory and the conclusion to be entailed from it.\n\n\n **L64** A value facet stores the entire option/outcome position, including its starting theory, reasons, limits and criticism response.\n\n\n **L65** Document the intended scope of Facet.claim. The corresponding declaration concerns: Extracts the target claim of a facet, using the commitment rather than consequence for a value facet. This comment is explanatory, not a proof premise.\n\n\n **L66** Define Facet.claim. Extracts the target claim of a facet, using the commitment rather than consequence for a value facet.\n\n\n **L67** Read the empirical facet’s own conclusion p as its claim; records, scope and uncertainty remain assessment inputs.\n\n\n **L68** Read the inferential facet’s own conclusion p as its claim, separately from its premise theory.\n\n\n **L69** The value facet’s claim is actual selection equaling its own adopted option, derived through v.commitment.\n\n\n **L70** Document the intended scope of FacetDischarged. The corresponding declaration concerns: Dispatches to a different check for each facet kind; these checks have different truth guarantees. This comment is explanatory, not a proof premise.\n\n\n **L71** Define FacetDischarged. Dispatches to a different check for each facet kind; these checks have different truth guarantees.\n\n\n **L72** Enter the empirical discharge case with this facet’s actual records, scope, conclusion p and uncertainty predicate.\n\n\n **L73** For an empirical facet, require a world compatible with its records and inside its scope, excluding an empty empirical domain.\n\n\n **L74** Require the records to support the scoped conclusion and the explicitly stated uncertainty predicate.\n\n\n **L75** Inferential discharge requires a nonempty model of the actual assumptions and semantic entailment of p from those same assumptions.\n\n\n **L76** Value discharge is exactly the declared ValueProcedure for that same position, not a proof of ultimate value adequacy.\n\n\n **L77** Document the intended scope of FacetArticulated. The corresponding declaration concerns: Requires articulation fields to match the facet's own assumptions, reasons and limits; concept strings are not constrained here. This comment is explanatory, not a proof premise.\n\n\n **L78** Define FacetArticulated. Requires articulation fields to match the facet's own assumptions, reasons and limits; concept strings are not constrained here.\n\n\n **L79** In the empirical articulation case, read the actual records and scope whose assumptions/reasons/limits must match.\n\n\n **L80** This empirical adapter equates articulated assumptions and reasons with actual record compatibility, and articulated limits with the empirical scope.\n\n\n **L81** In the inferential case, use this facet’s actual assumption theory as the articulation’s reference.\n\n\n **L82** This inferential adapter retains the exact premise theory, articulates its model condition as the reason, and uses unrestricted additional limits.\n\n\n **L83** Require value articulation to use exactly this position’s starting theory, adopted-option active reasons and limits.\n\n\n **L84** Document the intended scope of canonicalArticulation. The corresponding declaration concerns: Constructs field-aligned articulations by pattern matching; the fixed concept strings are descriptive labels. This comment is explanatory, not a proof premise.\n\n\n **L85** Define canonicalArticulation. Constructs field-aligned articulations by pattern matching; the fixed concept strings are descriptive labels.\n\n\n **L86** Construct the empirical canonical articulation from the actual record list and scope of the selected facet.\n\n\n **L87** Construct empirical articulation naming test outcomes and conditions, using the actual compatibility claim as its premise/reason and the original scope as its limit.\n\n\n **L88** Construct inferential canonical articulation from this facet’s actual premise theory.\n\n\n **L89** Construct inferential articulation from the same theory and its actual model predicate, with no extra limit.\n\n\n **L90** Construct the value articulation using the same complete position v.\n\n\n **L91** Construct value articulation from the actual starting theory, adopted-option reasons and original limits.\n\n\n **L92** Document the intended scope of canonicalFacetArticulated. The corresponding declaration concerns: Proves all canonical articulations have the required field alignment; no discharge hypothesis is needed for equality by construction. This comment is explanatory, not a proof premise.\n\n\n **L93** State the checked result canonicalFacetArticulated. Proves all canonical articulations have the required field alignment; no discharge hypothesis is needed for equality by construction.\n\n\n **L94** Assert that canonical articulation is semantically connected to this very facet; the proof checks each facet constructor.\n\n\n **L95** Split the three facet constructors; each canonical articulation has exactly the assumptions, reasons and limits required by its matching branch, so all three equalities are reflexive.\n\n\n **L96** Document the intended scope of canonicalArticulated. The corresponding declaration concerns: Given a discharged facet, proves its canonical concept/reason lists are nonempty. The value case uses the discharge premise's reason nonemptiness. This comment is explanatory, not a proof premise.\n\n\n **L97** State the checked result canonicalArticulated. Given a discharged facet, proves its canonical concept/reason lists are nonempty. The value case uses the discharge premise's reason nonemptiness.\n\n\n **L98** Given this facet’s discharge, require its canonical concepts and reasons to be nonempty.\n\n\n **L99** Check canonical articulation separately for empirical, inferential and value facets.\n\n\n **L100** In this empirical or inferential branch, the canonical concept and reason lists are explicitly nonempty; simplification verifies both articulation requirements.\n\n\n **L101** In this empirical or inferential branch, the canonical concept and reason lists are explicitly nonempty; simplification verifies both articulation requirements.\n\n\n **L102** For the value branch, the premise h is ValueProcedure v; its nonempty reasons must establish nonempty canonical active reasons.\n\n\n **L103** For a value facet, supply nonempty canonical concepts and leave the nonempty active-reason obligation.\n\n\n **L104** Use the discharged value procedure’s nonempty reasons; specializing them to the adopted option preserves nonemptiness.\n\n\n **L105** Document the intended scope of Grounds. The corresponding declaration concerns: Grounds packages a nonempty facet list, coverage of a supplied applicability predicate, common claim identity, articulation presence/alignment, and every listed facet's discharge. It is not uniformly a truth certificate for the claim. This comment is explanatory, not a proof premise.\n\n\n **L106** Define Grounds. Grounds packages a nonempty facet list, coverage of a supplied applicability predicate, common claim identity, articulation presence/alignment, and every listed facet's discharge. It is not uniformly a truth certificate for the claim.\n\n\n **L107** Take actualApplicable independently of the finite list, so coverage is an explicit obligation rather than inferred from list membership.\n\n\n **L108** Require a nonempty facet list and inclusion of every facet satisfying actualApplicable.\n\n\n **L109** For every listed facet, require the exact claim and a nonempty articulation belonging to that facet.\n\n\n **L110** Also require semantic matching to its actual premises/reasons/limits and discharge by its declared adapter.\n\n\n **L111** Document the intended scope of AchievementAccountability. The corresponding declaration concerns: Defines achievement accountability as exactly the same Grounds predicate, with no additional execution or achievement proof. This comment is explanatory, not a proof premise.\n\n\n **L112** Define AchievementAccountability. Defines achievement accountability as exactly the same Grounds predicate, with no additional execution or achievement proof.\n\n\n **L113** Achievement accountability accepts the same actual-applicability predicate and facet list as Grounds.\n\n\n **L114** Define accountability directly by Grounds for the very achievement claim; no extra universal observation requirement is added.\n\n\n **L115** Document the intended scope of transitionAchievement. The corresponding declaration concerns: Defines achievement as understanding/construction expansion between the same modeled transition's before and after states. This comment is explanatory, not a proof premise.\n\n\n **L116** Define transitionAchievement. Defines achievement as understanding/construction expansion between the same modeled transition's before and after states.\n\n\n **L117** The achievement claim is actual expansion between the selected transition’s own before and after states.\n\n\n **L118** Document the intended scope of transitionPerformanceRecord. The corresponding declaration concerns: Tests whether that after-state contains successor actually returning one at the transition input, within the two-transition model. This comment is explanatory, not a proof premise.\n\n\n **L119** Define transitionPerformanceRecord. Tests whether that after-state contains successor actually returning one at the transition input, within the two-transition model.\n\n\n **L120** The performance test inspects operations actually constructed in this transition’s after-state.\n\n\n **L121** It records true only when successor is present and actually sends the shared transition input to 1.\n\n\n **L122** Document the intended scope of transitionReportRecord. The corresponding declaration concerns: Records only the report's announced operation/input/output, not its actual achievement. This comment is explanatory, not a proof premise.\n\n\n **L123** Define transitionReportRecord. Records only the report's announced operation/input/output, not its actual achievement.\n\n\n **L124** Begin a record whose test reads the actual transition’s announcement.\n\n\n **L125** Bind report to the announcement generated for this same transition.\n\n\n **L126** Test its stated successor, input 0 and expected output 1, recording a positive announcement independently of whether the operation exists.\n\n\n **L127** Document the intended scope of transitionPerformanceCompatible. The corresponding declaration concerns: Exhausts inflate/extend to show the actual performance record identifies extension. This comment is explanatory, not a proof premise.\n\n\n **L128** State the checked result transitionPerformanceCompatible. Exhausts inflate/extend to show the actual performance record identifies extension.\n\n\n **L129** Claim that matching the actual positive performance record is equivalent to selecting extend.\n\n\n **L130** Fix an arbitrary actual transition, either inflate or extend, for the record-compatibility equivalence.\n\n\n **L131** Prove both directions: performance compatibility implies extend, and extend supplies compatibility.\n\n\n **L132** Assume this transition matches the actual positive performance record.\n\n\n **L133** Apply compatibility to the actual singleton performance record to obtain its observed test result for this transition.\n\n\n **L134** Split the actual transition into inflate and extend, whose after-states have different operation content.\n\n\n **L135** The inflate state lacks successor, so its performance test cannot equal the recorded true outcome.\n\n\n **L136** The extend case has the required transition identity by reflexivity.\n\n\n **L137** For the reverse implication, substitute the assumption that the transition is extend.\n\n\n **L138** Membership in the singleton record list identifies the arbitrary record with this exact transition record; substitute it before checking its test.\n\n\n **L139** Evaluate the actual extend performance record; its successor-at-zero test equals the recorded true outcome.\n\n\n **L140** Document the intended scope of transitionSupported. The corresponding declaration concerns: Uses performance identification, the concrete new operation and report claim to establish transition expansion in every compatible case. This comment is explanatory, not a proof premise.\n\n\n **L141** State the checked result transitionSupported. Uses performance identification, the concrete new operation and report claim to establish transition expansion in every compatible case. The following tactic block proves this explicit type.\n\n\n **L142** Take an arbitrary transition and its compatibility with the actual performance record; prove expansion for that same transition.\n\n\n **L143** Use transitionPerformanceCompatible to identify every performance-compatible transition as extend.\n\n\n **L144** Substitute extend for the transition, so the remaining achievement claim concerns its real extended after-state.\n\n\n **L145** Check the same system-generated extend report against its actual before/after states: successor is newly constructed and sends input 0 to output 1.\n\n\n **L146** Check the same system-generated extend report against its actual before/after states: successor is newly constructed and sends input 0 to output 1.\n\n\n **L147** Check the same system-generated extend report against its actual before/after states: successor is newly constructed and sends input 0 to output 1.\n\n\n **L148** Apply announcementClaimImpliesExpansion to the verified report content to obtain the same transition’s Expanded claim.\n\n\n **L149** Document the intended scope of transitionFacet. The corresponding declaration concerns: Packages the performance record, input-zero scope and exact expansion claim as an empirical facet. This comment is explanatory, not a proof premise.\n\n\n **L150** Define transitionFacet. Packages the performance record, input-zero scope and exact expansion claim as an empirical facet.\n\n\n **L151** Build an empirical facet from the performance record with the exact input-0 transition scope.\n\n\n **L152** Its conclusion is the same transition’s achievement; its uncertainty predicate is explicitly True.\n\n\n **L153** Document the intended scope of transitionFacetDischarged. The corresponding declaration concerns: Supplies extension as a nonempty witness, actual support and trivial uncertainty. This comment is explanatory, not a proof premise.\n\n\n **L154** State the checked result transitionFacetDischarged. Supplies extension as a nonempty witness, actual support and trivial uncertainty. The following tactic block proves this explicit type.\n\n\n **L155** Provide extend as the nonempty empirical witness with compatible performance evidence and the shared input-0 scope; leave scoped support and uncertainty checks.\n\n\n **L156** The already proved transition support supplies the achievement at any compatible transition, hence within the chosen scope.\n\n\n **L157** The explicitly unrestricted uncertainty predicate is True, so this adapter component is immediate; no quantitative uncertainty bound is inferred.\n\n\n **L158** Document the intended scope of transitionAccountable. The corresponding declaration concerns: Builds achievement Grounds with matching claim, scope, canonical articulation and discharged facet. This comment is explanatory, not a proof premise.\n\n\n **L159** State the checked result transitionAccountable. Builds achievement Grounds with matching claim, scope, canonical articulation and discharged facet.\n\n\n **L160** State accountability for the actual transition-achievement predicate with canonical articulation.\n\n\n **L161** Declare transitionFacet the only applicable facet and use precisely that singleton evidence package.\n\n\n **L162** Split accountability into nonempty facets, coverage of actual applicability, and matching articulated discharge for each included facet.\n\n\n **L163** The applicability assumption identifies the facet with the one prescribed facet, which belongs to the singleton list.\n\n\n **L164** Singleton membership identifies the current facet with the prescribed one; substitute it to check its exact claim and grounds.\n\n\n **L165** Assemble identical claim, nonempty canonical articulation, its semantic connection to this facet, and transitionFacetDischarged.\n\n\n **L166** Assemble identical claim, nonempty canonical articulation, its semantic connection to this facet, and transitionFacetDischarged.\n\n\n **L167** Document the intended scope of transitionReportCompatible. The corresponding declaration concerns: Shows both transition cases produce the same announced operation/input/output record. This comment is explanatory, not a proof premise.\n\n\n **L168** State the checked result transitionReportCompatible. Shows both transition cases produce the same announced operation/input/output record.\n\n\n **L169** State that this transition’s positive report record is compatible with the transition itself, including inflate.\n\n\n **L170** Membership in the singleton record list identifies the arbitrary record with this exact transition record; substitute it before checking its test.\n\n\n **L171** The report test only checks the actual positive announcement contents, which evaluate identically for either transition.\n\n\n **L172** Document the intended scope of transitionReportDoesNotSupport. The corresponding declaration concerns: Uses the inflated transition as a report-compatible non-achievement countermodel. This comment is explanatory, not a proof premise.\n\n\n **L173** State the checked result transitionReportDoesNotSupport. Uses the inflated transition as a report-compatible non-achievement countermodel.\n\n\n **L174** Require inflate to match the report while failing the same achievement predicate.\n\n\n **L175** Conclude that the positive report records therefore do not support the achievement over all compatible transitions.\n\n\n **L176** Unfold the inflate transition: both understood and constructed operation sets are unchanged, so no new-operation witness for Expanded exists.\n\n\n **L177** Unfold the inflate transition: both understood and constructed operation sets are unchanged, so no new-operation witness for Expanded exists.\n\n\n **L178** Combine positive-report compatibility with the false expansion claim at inflate; any claimed support applied there gives a contradiction.\n\n\n **L179** Document the intended scope of ConcreteAchievementExample. The corresponding declaration concerns: Combines same-object achievement accountability and supported extension with an unsupported inflation report, preserving before/after/input identities. This comment is explanatory, not a proof premise.\n\n\n **L180** Define ConcreteAchievementExample. Combines same-object achievement accountability and supported extension with an unsupported inflation report, preserving before/after/input identities.\n\n\n **L181** The concrete example includes actual accountability for the transition achievement.\n\n\n **L182** Its actual-applicability predicate and list identify the same single transition facet.\n\n\n **L183** Require extend to satisfy the actual performance observation.\n\n\n **L184** Require semantic support for the achievement and its truth at extend.\n\n\n **L185** Also retain the report-compatible inflate world in which this achievement is false.\n\n\n **L186** State the resulting failure of support from reports alone.\n\n\n **L187** For every transition, bind the report’s before state to the actual transition-before state.\n\n\n **L188** Bind its after state to that same transition’s actual after state.\n\n\n **L189** Bind the report input to the actual transition input and explicitly fix that condition to 0.\n\n\n **L190** Document the intended scope of concreteAchievementExample. The corresponding declaration concerns: Assembles the concrete performance support, reporting countermodel and exact state/input links. This comment is explanatory, not a proof premise.\n\n\n **L191** State the checked result concreteAchievementExample. Assembles the concrete performance support, reporting countermodel and exact state/input links. The following tactic block proves this explicit type.\n\n\n **L192** Assemble the actual achievement’s accountability, extend performance compatibility and semantic support in the concrete example.\n\n\n **L193** Apply that same support to the extend witness to establish actual expansion there.\n\n\n **L194** Include the report-compatible inflate counterexample and leave the same-before/after/input relationships.\n\n\n **L195** For either transition, all report-to-state and input-0 links hold by the definitions themselves.\n\n\n **L196** Document the intended scope of achievementNeedsSupport. The corresponding declaration concerns: Applies supplied compatible-world support to the arbitrary actual claim and separately includes the checked concrete transition example. This comment is explanatory, not a proof premise.\n\n\n **L197** State the checked result achievementNeedsSupport. Applies supplied compatible-world support to the arbitrary actual claim and separately includes the checked concrete transition example.\n\n\n **L198** Assume the chosen actual world matches all records and those records already support the achievement.\n\n\n **L199** Conclude truth of the achievement at that actual world, together with the separately constructed concrete achievement example.\n\n\n **L200** Apply the assumed support to the actual evidence-compatible world, and pair that local truth with the separately proved concrete achievement example.\n\n\n **L201** Document the intended scope of supportWeakening. The corresponding declaration concerns: Preserves support when a supported claim implies a weaker claim at every world; it does not weaken the record set. This comment is explanatory, not a proof premise.\n\n\n **L202** State the checked result supportWeakening. Preserves support when a supported claim implies a weaker claim at every world; it does not weaken the record set.\n\n\n **L203** Assume support for p and a world-by-world implication from p to q; conclude support for q using the same records.\n\n\n **L204** At each compatible world w, first derive p using the unchanged records, then apply the supplied implication weaker to obtain q.\n\n\n **L205** Document the intended scope of evidenceWeakeningCanLoseSupport. The corresponding declaration concerns: Provides a true Boolean observation supporting equality to true and shows deleting that record loses this support. This comment is explanatory, not a proof premise.\n\n\n **L206** State the checked result evidenceWeakeningCanLoseSupport. Provides a true Boolean observation supporting equality to true and shows deleting that record loses this support.\n\n\n **L207** The single identity observation supports that the Boolean world is true.\n\n\n **L208** Deleting that observation leaves empty records, which do not support the unchanged claim.\n\n\n **L209** Split the supported one-record claim from the failure of the same claim after deleting that record.\n\n\n **L210** Read the informative identity test from compatibility; it directly states that the Boolean world is true.\n\n\n **L211** With no records, false is compatible; evaluating purported support there refutes the unchanged true-world claim.\n\n\n **L212** Document the intended scope of scopeRestriction. The corresponding declaration concerns: Restricts a universally supported property from a wider input domain to an included narrower domain, for arbitrary world and input types. This comment is explanatory, not a proof premise.\n\n\n **L213** State the checked result scopeRestriction. Restricts a universally supported property from a wider input domain to an included narrower domain, for arbitrary world and input types.\n\n\n **L214** Take broad and narrow application domains and assume every narrow-domain input is in the broad domain.\n\n\n **L215** Assume the same records support p at every input in the broad domain.\n\n\n **L216** Conclude support at every input in the narrower domain; neither the evidence nor predicate p changes.\n\n\n **L217** For a compatible world and narrow-domain input x, included converts narrow membership to broad membership; apply the original broad support there.\n\n\n **L218** Document the intended scope of Duties. The corresponding declaration concerns: Requires every facet satisfying the supplied applicability predicate to be discharged. This comment is explanatory, not a proof premise.\n\n\n **L219** Define Duties. Requires every facet satisfying the supplied applicability predicate to be discharged.\n\n\n **L220** Require every actually applicable facet to pass its own discharge condition.\n\n\n **L221** Define LabeledDuties. Defines labeled duties by ignoring all labels and keeping only the applicability-based duties.\n\n\n **L222** Define labeled duties by exactly the original applicability duties; the labels supply no waiver.\n\n\n **L223** Document the intended scope of assessmentUnion. The corresponding declaration concerns: Proves that discharging the union of two applicability predicates is equivalent to discharging each separately. This comment is explanatory, not a proof premise.\n\n\n **L224** State the checked result assessmentUnion. Proves that discharging the union of two applicability predicates is equivalent to discharging each separately.\n\n\n **L225** Equate duties for the union of two applicability predicates with fulfillment of both sets of duties.\n\n\n **L226** Prove both directions between duty on the union applicability predicate and simultaneous duties on its two components.\n\n\n **L227** Restrict the union duty to each applicable-facet predicate using the matching disjunction injection.\n\n\n **L228** Unpack both duty sets, split actual applicability into its left/right case, and discharge that very facet using the corresponding duty.\n\n\n **L229** Document the intended scope of labelsCannotWaive. The corresponding declaration concerns: Proves changing labels cannot change duties because labels were ignored by definition; no external classification mechanism is analyzed. This comment is explanatory, not a proof premise.\n\n\n **L230** State the checked result labelsCannotWaive. Proves changing labels cannot change duties because labels were ignored by definition; no external classification mechanism is analyzed.\n\n\n **L231** Changing only the label lists leaves the same duty proposition; the equivalence is reflexive.\n\n\n **L232** Document the intended scope of switchRecord. The corresponding declaration concerns: Records the identity Boolean test with observed value true. This comment is explanatory, not a proof premise.\n\n\n **L233** Define switchRecord. Records the identity Boolean test with observed value true.\n\n\n **L234** State the checked result switchCompatible. Proves compatibility with the single switch record is exactly equality of the world with true. The following tactic block proves this explicit type.\n\n\n **L235** Prove that compatibility with the singleton switch record is equivalent to the actual Boolean world being true.\n\n\n **L236** Apply record compatibility to the sole named test to recover its actual observed equality.\n\n\n **L237** Conversely, singleton membership identifies any listed record with this test, whose equality is the supplied observation premise.\n\n\n **L238** State the checked result switchSupported. Supports equality to true by extracting the previously proved compatibility equivalence. The supplied proof term uses the displayed constructed witnesses or earlier lemmas, rather than adding an axiom.\n\n\n **L239** Use switchCompatible’s forward implication to extract world=true from the same world’s actual record compatibility.\n\n\n **L240** Document the intended scope of optionBenefit. The corresponding declaration concerns: Assigns benefit 4 to selected=true and 0 otherwise. This comment is explanatory, not a proof premise.\n\n\n **L241** Define optionBenefit. Assigns benefit 4 to selected=true and 0 otherwise.\n\n\n **L242** Define optionCost. Assigns cost 3 to selected=true and 0 otherwise.\n\n\n **L243** Document the intended scope of optionReport. The corresponding declaration concerns: States option-specific cost and benefit facts rather than an unconnected reason flag. This comment is explanatory, not a proof premise.\n\n\n **L244** Define optionReport. States option-specific cost and benefit facts rather than an unconnected reason flag.\n\n\n **L245** The option report asserts actual cost at most 3 and the option-specific benefit of 4 for on or 0 for off.\n\n\n **L246** Document the intended scope of switchPosition. The corresponding declaration concerns: Adopts true with actual option cost/benefit outcomes, cost-below-benefit objective, budget constraint and a scoped criticism response. This comment is explanatory, not a proof premise.\n\n\n **L247** Define switchPosition. Adopts true with actual option cost/benefit outcomes, cost-below-benefit objective, budget constraint and a scoped criticism response.\n\n\n **L248** Use Boolean options for on/off.\n\n\n **L249** Represent each outcome as actual benefit and cost in a natural-number pair.\n\n\n **L250** Adopt the on option explicitly; adoption itself is not derived from arithmetic.\n\n\n **L251** Read the actual selected option directly from the Boolean world.\n\n\n **L252** Compute benefit and cost from this same actual option.\n\n\n **L253** Adopt the objective that actual benefit strictly exceeds actual cost.\n\n\n **L254** Check the actual option cost against the fixed budget 3.\n\n\n **L255** Assume the actual Boolean selection is on; do not insert the assessed benefit conclusion into the starting theory.\n\n\n **L256** Use the option-indexed actual cost/benefit report as the sole reason.\n\n\n **L257** Use an unrestricted world scope in this example; starting assumptions and reason content still constrain the procedure.\n\n\n **L258** Mark the off-selected world as a relevant criticism case.\n\n\n **L259** Provide distinct nonempty messages for the two worlds, including budget reconsideration in the criticism case.\n\n\n **L260** State the checked result switchValueProcedure. Provides a consistent adoption witness and derives the adopted option's objective/constraint from its actual cost-benefit reason; both Boolean responses are checked. The following tactic block proves this explicit type.\n\n\n **L261** Separate nonempty reasons, a joint adoption witness, consequence support by all reasons, and response to criticism for switchPosition.\n\n\n **L262** Choose world true, satisfying the starting selection, unrestricted limit and adopted option, and leave its actual reason to check.\n\n\n **L263** Take any reason in switchPosition’s list; the next step identifies its actual optionReport content at the adopted on witness.\n\n\n **L264** Singleton membership identifies the arbitrary reason with optionReport specialized to this position’s adopted option; substitute that actual reason.\n\n\n **L265** Singleton membership identifies the arbitrary reason with optionReport specialized to this position’s adopted option; substitute that actual reason.\n\n\n **L266** Check that the adopted on option meets its recorded cost bound and its stated benefit value.\n\n\n **L267** For an arbitrary world in the stated starting/limit conditions, assume the entire active-reason conjunction.\n\n\n **L268** Extract the actual optionReport reason from that conjunction, rather than introducing an independent support label.\n\n\n **L269** Unfold which option is adopted: this evidence concerns the on option.\n\n\n **L270** Use the reported benefit equality to prove the on option’s benefit exceeds 3.\n\n\n **L271** Combine cost ≤ 3 with benefit > 3 to prove cost < benefit, and retain the same cost bound as the constraint.\n\n\n **L272** Check both Boolean worlds to provide the recorded nonempty criticism response where required.\n\n\n **L273** Document the intended scope of oppositePosition. The corresponding declaration concerns: Changes the adopted option to false and updates its starting selection while retaining the same outcome model and objective. This comment is explanatory, not a proof premise.\n\n\n **L274** Define oppositePosition. Changes the adopted option to false and updates its starting selection while retaining the same outcome model and objective.\n\n\n **L275** Change both adopted option and starting selection to off while retaining the same actual outcome/reason interpretation.\n\n\n **L276** Document the intended scope of oppositePositionRejected. The corresponding declaration concerns: Shows false can be jointly adopted but fails the unchanged cost-below-benefit objective, so its value procedure is rejected. This comment is explanatory, not a proof premise.\n\n\n **L277** State the checked result oppositePositionRejected. Shows false can be jointly adopted but fails the unchanged cost-below-benefit objective, so its value procedure is rejected. The following tactic block proves this explicit type.\n\n\n **L278** Construct an actual joint adoption witness for the opposite off position at world false; the rejection will therefore not rely on an empty domain.\n\n\n **L279** Construct an actual joint adoption witness for the opposite off position at world false; the rejection will therefore not rely on an empty domain.\n\n\n **L280** For the opposite position’s false-world witness, take any listed reason before checking that off option’s actual report.\n\n\n **L281** Singleton membership identifies the arbitrary reason with optionReport specialized to this position’s adopted option; substitute that actual reason.\n\n\n **L282** Singleton membership identifies the arbitrary reason with optionReport specialized to this position’s adopted option; substitute that actual reason.\n\n\n **L283** The off option’s own report is true: its zero cost is within the bound and its zero benefit matches the stated report.\n\n\n **L284** Retain the nonempty joint witness and separately refute fulfillment of the opposite value procedure.\n\n\n **L285** Assume the opposite off position satisfies its entire ValueProcedure, to derive a contradiction with its zero-benefit outcome.\n\n\n **L286** Assemble all of the opposite position’s reasons at its actual false-world witness before applying any consequence requirement.\n\n\n **L287** Take any actual reason of the opposite position to assemble all reasons at its inhabited false-world counterexample.\n\n\n **L288** Singleton membership identifies the arbitrary reason with optionReport specialized to this position’s adopted option; substitute that actual reason.\n\n\n **L289** Singleton membership identifies the arbitrary reason with optionReport specialized to this position’s adopted option; substitute that actual reason.\n\n\n **L290** The off option’s own report is true: its zero cost is within the bound and its zero benefit matches the stated report.\n\n\n **L291** Apply the assumed opposite procedure’s joint-reason consequence clause to that same starting/limit witness and all its actual reasons.\n\n\n **L292** Its purported objective would require the off option’s zero cost to be strictly less than its zero benefit, contradicting irreflexivity.\n\n\n **L293** Document the intended scope of contradictoryStartingPosition. The corresponding declaration concerns: Replaces the starting theory with a false singleton, eliminating every joint adoption witness. This comment is explanatory, not a proof premise.\n\n\n **L294** Define contradictoryStartingPosition. Replaces the starting theory with a false singleton, eliminating every joint adoption witness.\n\n\n **L295** Replace the starting theory with the impossible singleton claim False.\n\n\n **L296** Define impossibleAdoptionPosition. Always selects false while retaining adoption of true, making joint adoption impossible.\n\n\n **L297** Keep the adopted on option but make every actual selection off, making joint adoption impossible.\n\n\n **L298** Document the intended scope of inadmissibleValuePositionsRejected. The corresponding declaration concerns: Rejects both inconsistent starting theory and impossible adoption via the required witness. This comment is explanatory, not a proof premise.\n\n\n **L299** State the checked result inadmissibleValuePositionsRejected. Rejects both inconsistent starting theory and impossible adoption via the required witness.\n\n\n **L300** Reject the procedures for contradictory starting assumptions and impossible actual adoption separately.\n\n\n **L301** Separate rejection of the contradictory starting theory from rejection of the impossible selected/adopted combination.\n\n\n **L302** Extract a joint adoption witness from the alleged procedure for the contradictory starting position.\n\n\n **L303** The singleton starting theory requires False at that witness, directly contradicting its model proof.\n\n\n **L304** Extract the adoption equality from the alleged joint witness for the impossible selected/adopted combination.\n\n\n **L305** The required adoption equality equates distinct Boolean options, so this witness cannot exist.\n\n\n **L306** Document the intended scope of unsupportedPosition. The corresponding declaration concerns: Copies the switch value position but deletes its reasons, guaranteeing procedural failure. This comment is explanatory, not a proof premise.\n\n\n **L307** Define unsupportedPosition. Copies the switch value position but deletes its reasons, guaranteeing procedural failure.\n\n\n **L308** Define switchEmpirical. Builds an empirical facet concluding the Boolean world is true from the switch record, with unrestricted scope and trivially true uncertainty.\n\n\n **L309** Use the actual switch observation, unrestricted scope and same selected-on claim; uncertainty is explicitly True.\n\n\n **L310** State the checked result switchEmpiricalDischarged. Discharges that empirical facet with a true-world witness, semantic support, and trivial uncertainty. The following tactic block proves this explicit type.\n\n\n **L311** Use true as a nonempty world compatible with the switch record and unrestricted empirical scope.\n\n\n **L312** The same switch record’s semantic support proves the scoped switch claim at each compatible world.\n\n\n **L313** Discharge the explicitly trivial uncertainty predicate, without adding an empirical confidence claim.\n\n\n **L314** Document the intended scope of mixedMissingResponsibility. The corresponding declaration concerns: Shows a discharged empirical facet does not discharge a union of applicable facets when an included value facet has no reasons. This comment is explanatory, not a proof premise.\n\n\n **L315** State the checked result mixedMissingResponsibility. Shows a discharged empirical facet does not discharge a union of applicable facets when an included value facet has no reasons.\n\n\n **L316** Retain successful discharge of the actual empirical switch facet.\n\n\n **L317** Deny all mixed duties even with empty labels, because the actual value facet also applies and lacks recorded reasons.\n\n\n **L318** Keep the valid empirical switch facet and separately refute completion of all mixed duties.\n\n\n **L319** Assume every actual mixed facet is discharged, including the value facet whose recorded reason list is empty.\n\n\n **L320** Select the value facet from the actual applicability union and extract its required nonempty reason-list condition.\n\n\n **L321** Its reason list is definitionally empty, contradicting only that recorded procedural requirement.\n\n\n **L322** Document the intended scope of uninformativeArgument. The corresponding declaration concerns: Constructs a nonempty articulation with no assumptions and a tautological reason; it carries no information about the switch conclusion. This comment is explanatory, not a proof premise.\n\n\n **L323** Define uninformativeArgument. Constructs a nonempty articulation with no assumptions and a tautological reason; it carries no information about the switch conclusion.\n\n\n **L324** Articulate a switch concept with empty assumptions and a True reason; these nonempty words do not constrain the switch world.\n\n\n **L325** State the checked result articulationNotSupport. Proves this articulation passes the nonemptiness check while its assumptions do not entail that the world is true.\n\n\n **L326** The uninformative articulation’s actual assumptions do not entail that the world is true.\n\n\n **L327** Pair nonempty but uninformative concepts/reasons with the empty theory’s established failure to entail the switch claim.\n\n\n **L328** Pair nonempty but uninformative concepts/reasons with the empty theory’s established failure to entail the switch claim.\n\n\n **L329** Document the intended scope of unrelatedArticulationRejected. The corresponding declaration concerns: Shows that a nonempty unrelated articulation and a discharged empirical facet need not align, and rejects this concrete pairing. This comment is explanatory, not a proof premise.\n\n\n **L330** State the checked result unrelatedArticulationRejected. Shows that a nonempty unrelated articulation and a discharged empirical facet need not align, and rejects this concrete pairing.\n\n\n **L331** Keep the unrelated articulation procedurally present and the switch facet actually discharged.\n\n\n **L332** Still reject semantic matching between that unrelated articulation and this empirical facet.\n\n\n **L333** Retain articulation and valid switch evidence, then separately test whether this unrelated articulation actually matches the facet.\n\n\n **L334** Assume the uninformative articulation semantically matches switchEmpirical, despite its empty premise theory.\n\n\n **L335** Evaluate the alleged equality of articulation assumptions and empirical compatibility assumptions on the compatibility claim itself.\n\n\n **L336** The empirical singleton contains that compatibility claim, while the unrelated empty theory cannot; the alleged equality yields False.\n\n\n **L337** Close this component of unrelatedArticulationRejected using the displayed local evidence or previously proved lemma; the component belongs to the following fixed result: Shows that a nonempty unrelated articulation and a discharged empirical facet need not align, and rejects this concrete pairing.\n\n\n **L338** Document the intended scope of temperatureRecord. The corresponding declaration concerns: Records only the first coordinate of a Boolean pair, observed as true; the second coordinate is unmeasured. This comment is explanatory, not a proof premise.\n\n\n **L339** Define temperatureRecord. Records only the first coordinate of a Boolean pair, observed as true; the second coordinate is unmeasured.\n\n\n **L340** State the checked result temperatureCompatible. Shows duplicating that record remains compatible with either second-coordinate value when the first is true.\n\n\n **L341** For any output coordinate b, repeated temperature records remain compatible with (true,b).\n\n\n **L342** For either output coordinate b, singleton-style membership in the repeated list selects the same temperature test; its observed first coordinate is true and leaves b unconstrained.\n\n\n **L343** For either output coordinate b, singleton-style membership in the repeated list selects the same temperature test; its observed first coordinate is true and leaves b unconstrained.\n\n\n **L344** For either output coordinate b, singleton-style membership in the repeated list selects the same temperature test; its observed first coordinate is true and leaves b unconstrained.\n\n\n **L345** For either output coordinate b, singleton-style membership in the repeated list selects the same temperature test; its observed first coordinate is true and leaves b unconstrained.\n\n\n **L346** Document the intended scope of BudgetWorld. The corresponding declaration concerns: Uses a Boolean action coordinate and natural-number budget as the world type. This comment is explanatory, not a proof premise.\n\n\n **L347** Introduce the type abbreviation BudgetWorld. Uses a Boolean action coordinate and natural-number budget as the world type.\n\n\n **L348** Document the intended scope of announcement. The corresponding declaration concerns: Defines a fixed declaration string; its content is not linked to budget. This comment is explanatory, not a proof premise.\n\n\n **L349** Define announcement. Defines a fixed declaration string; its content is not linked to budget.\n\n\n **L350** Define announcementPosition. Uses an action announcement as the sole option-indexed reason while requiring actual benefit/cost and available budget.\n\n\n **L351** Use Boolean options for on/off.\n\n\n **L352** Represent each outcome as actual benefit and cost in a natural-number pair.\n\n\n **L353** Adopt the on option explicitly; adoption itself is not derived from arithmetic.\n\n\n **L354** Read actual selection from the first coordinate while leaving budget independently variable.\n\n\n **L355** Compute benefit and cost from this same actual option.\n\n\n **L356** Adopt the objective that actual benefit strictly exceeds actual cost.\n\n\n **L357** Compare the adopted option’s actual cost with this world’s independently supplied budget.\n\n\n **L358** Fix selection to on without any affordability or budget assumption.\n\n\n **L359** Use the actual option-specific announcement text as the reason; it says nothing about available budget.\n\n\n **L360** Use an unrestricted world scope in this example; starting assumptions and reason content still constrain the procedure.\n\n\n **L361** Treat budget below 3 as relevant criticism of this cost-3 action.\n\n\n **L362** Record a nonempty message about reconsidering the action when cost exceeds budget.\n\n\n **L363** Document the intended scope of announcementHasJointAdoption. The corresponding declaration concerns: Constructs an action-true budget-zero world where the announcement reason holds; failure later is substantive, not absent adoption. This comment is explanatory, not a proof premise.\n\n\n **L364** State the checked result announcementHasJointAdoption. Constructs an action-true budget-zero world where the announcement reason holds; failure later is substantive, not absent adoption. The following tactic block proves this explicit type.\n\n\n **L365** Choose selected-on with budget 0 as a joint adoption witness; the starting theory fixes selection but does not assume affordability.\n\n\n **L366** Take an arbitrary announcement reason at the selected-on, zero-budget joint witness.\n\n\n **L367** Use membership to identify the actual reason as the option-indexed announcement text, then specialize it to the adopted on option.\n\n\n **L368** Use membership to identify the actual reason as the option-indexed announcement text, then specialize it to the adopted on option.\n\n\n **L369** Use membership to identify the actual reason as the option-indexed announcement text, then specialize it to the adopted on option.\n\n\n **L370** The actual announcement equals the on option’s activation text; this proves the announcement reason, not the budget constraint.\n\n\n **L371** Document the intended scope of announcementNotBudgetReason. The corresponding declaration concerns: At budget zero, the adopted action and true nonempty announcement reasons fail the real budget consequence, refuting the procedure. This comment is explanatory, not a proof premise.\n\n\n **L372** State the checked result announcementNotBudgetReason. At budget zero, the adopted action and true nonempty announcement reasons fail the real budget consequence, refuting the procedure.\n\n\n **L373** Require nonempty announcement reasons and actual adoption at selected-on with budget 0.\n\n\n **L374** At that same zero-budget world, all actual announcement reasons hold.\n\n\n **L375** Nevertheless reject the actual consequence and the whole value procedure.\n\n\n **L376** Assemble nonempty announcement reasons and the true announcement; refute the zero-budget consequence and leave failure of the whole procedure.\n\n\n **L377** For the claimed conjunction of reasons at budget 0, take any member of the actual announcement reason list.\n\n\n **L378** Use membership to identify the actual reason as the option-indexed announcement text, then specialize it to the adopted on option.\n\n\n **L379** Use membership to identify the actual reason as the option-indexed announcement text, then specialize it to the adopted on option.\n\n\n **L380** The actual announcement equals the on option’s activation text; this proves the announcement reason, not the budget constraint.\n\n\n **L381** Assume the announcement position satisfies ValueProcedure, to test its consequence clause at budget 0.\n\n\n **L382** Collect every announcement reason at the same selected-on, zero-budget world.\n\n\n **L383** To supply all reasons to that clause, take any announcement reason at the same zero-budget world.\n\n\n **L384** Use membership to identify the actual reason as the option-indexed announcement text, then specialize it to the adopted on option.\n\n\n **L385** Use membership to identify the actual reason as the option-indexed announcement text, then specialize it to the adopted on option.\n\n\n **L386** The actual announcement equals the on option’s activation text; this proves the announcement reason, not the budget constraint.\n\n\n **L387** Apply a hypothetical procedure to that inhabited zero-budget starting/limit case and its actual announcement reason.\n\n\n **L388** The resulting cost constraint would require cost 3 within budget 0, which is impossible.\n\n\n **L389** Document the intended scope of actionRecord. The corresponding declaration concerns: Records only the action Boolean, leaving budget completely unconstrained. This comment is explanatory, not a proof premise.\n\n\n **L390** Define actionRecord. Records only the action Boolean, leaving budget completely unconstrained.\n\n\n **L391** State the checked result actionCompatible. Shows two copies of the action record accept every budget when action=true. The following tactic block proves this explicit type.\n\n\n **L392** Every action record in the repeated list tests only the actual selected-on coordinate, so any supplied budget remains compatible.\n\n\n **L393** Document the intended scope of measurementRepeatNotSupport. The corresponding declaration concerns: Combines explicit countermodels showing that repeated measurement of one coordinate does not support an unmeasured coordinate or a budget consequence, and does not fix the announcement value procedure. This comment is explanatory, not a proof premise.\n\n\n **L394** State the checked result measurementRepeatNotSupport. Combines explicit countermodels showing that repeated measurement of one coordinate does not support an unmeasured coordinate or a budget consequence, and does not fix the announcement value procedure.\n\n\n **L395** The actual temperature test returns true even when the independent output coordinate is false.\n\n\n **L396** Retain this false-output world under repeated temperature observations.\n\n\n **L397** Also retain a true-output world under those same repeated observations.\n\n\n **L398** A single temperature record does not support the other output being true.\n\n\n **L399** Repeating that temperature record still does not support the other output being true.\n\n\n **L400** Repeated observed activation is compatible with selected-on and budget 0.\n\n\n **L401** The same repeated records are also compatible with budget 3.\n\n\n **L402** A single activation record does not support the option’s actual objective-and-budget consequence.\n\n\n **L403** Repeating activation records does not repair that lack of consequence support.\n\n\n **L404** The announcement-based value procedure also fails for that actual option and constraint.\n\n\n **L405** Record the observation’s actual true value and both temperature-compatible output alternatives; leave the unsupported output claims to refute.\n\n\n **L406** Keep both budget-0 and budget-3 action-compatible worlds and the established announcement-procedure failure; leave affordability support claims to refute.\n\n\n **L407** Assume a single temperature observation supports the independently represented second output being true.\n\n\n **L408** Apply purported one-record output support to (true,false), whose temperature observation is true but whose other output claim is false.\n\n\n **L409** Apply purported one-record output support to (true,false), whose temperature observation is true but whose other output claim is false.\n\n\n **L410** The same (true,false) counterworld remains compatible with repeated temperature records, defeating repeated-data output support.\n\n\n **L411** Assume a single action observation supports the adopted option’s benefit-and-budget consequence.\n\n\n **L412** A single observed activation is compatible with budget 0; purported consequence support there would force the impossible cost constraint.\n\n\n **L413** A single observed activation is compatible with budget 0; purported consequence support there would force the impossible cost constraint.\n\n\n **L414** Repeating activation records retains the same zero-budget counterworld, so it still does not support the actual affordability consequence.\n\n\n **L415** Document the intended scope of selfAssertionNotReason. The corresponding declaration concerns: Combines empty-reason and nonempty-but-budget-irrelevant self-assertion failures, with a joint adoption witness for the latter. This comment is explanatory, not a proof premise.\n\n\n **L416** State the checked result selfAssertionNotReason. Combines empty-reason and nonempty-but-budget-irrelevant self-assertion failures, with a joint adoption witness for the latter.\n\n\n **L417** The missing-reason position can be actually adopted yet fail its recorded procedure.\n\n\n **L418** The stronger announcement example has nonempty reasons and actual adoption at budget 0.\n\n\n **L419** Its actual consequence and its procedure still fail because the same adopted option exceeds budget.\n\n\n **L420** Retain an actual joint adoption witness, excluding an empty-starting-domain explanation of this failure.\n\n\n **L421** Prove unsupportedPosition.commitment true by reduction; a supposed ValueProcedure contradicts its empty reason list through its nonemptiness requirement.\n\n\n **L422** Reuse the nonempty actual announcement reasons and adoption equality from announcementNotBudgetReason.\n\n\n **L423** Also reuse failure of the same zero-budget consequence and of the entire announcement procedure.\n\n\n **L424** Retain announcementHasJointAdoption so this failure is not explained by an empty or inconsistent starting domain.\n\n\n **L425** Document the intended scope of valueWithoutSelfProof. The corresponding declaration concerns: Exhibits a coherent reasoned position not derivable from empty assumptions, and rejects opposite-option, inconsistent-start and impossible-adoption variants. This comment is explanatory, not a proof premise.\n\n\n **L426** State the checked result valueWithoutSelfProof. Exhibits a coherent reasoned position not derivable from empty assumptions, and rejects opposite-option, inconsistent-start and impossible-adoption variants.\n\n\n **L427** Require the switch position’s actual starting theory to have a model.\n\n\n **L428** Deny derivation of its adopted commitment from the empty Boolean theory.\n\n\n **L429** The opposite position has a joint witness but fails consequence assessment.\n\n\n **L430** Also reject contradictory starting and impossible adoption variants, distinguishing non-self-derived from inconsistent starts.\n\n\n **L431** Combine the actual switch procedure, world true as its starting model, and non-entailment of the adopted claim from emptyTheory.\n\n\n **L432** Add rejection of the inhabited opposite option and the separate contradictory-start and impossible-adoption variants.\n\n\n **L433** Document the intended scope of BenefitCostWorld. The corresponding declaration concerns: Stores a selected Boolean option together with variable benefit and cost values. This comment is explanatory, not a proof premise.\n\n\n **L434** Introduce the type abbreviation BenefitCostWorld. Stores a selected Boolean option together with variable benefit and cost values.\n\n\n **L435** Define measuredOutcome. For true, returns the world's benefit/cost pair; false has outcome zero/zero.\n\n\n **L436** The on option reads the world’s actual benefit/cost pair; the off option yields (0,0).\n\n\n **L437** Define benefitReason. Requires the same option's measured benefit to equal four.\n\n\n **L438** The benefit reason requires the actual option’s measured benefit to equal 4.\n\n\n **L439** Define costReason. Requires that option's measured cost to be at most three.\n\n\n **L440** The cost reason requires the same option’s measured cost to be at most 3.\n\n\n **L441** Document the intended scope of jointReasonPosition. The corresponding declaration concerns: Uses two separate option-specific benefit and cost reasons jointly for the adopted option's objective and budget. This comment is explanatory, not a proof premise.\n\n\n **L442** Define jointReasonPosition. Uses two separate option-specific benefit and cost reasons jointly for the adopted option's objective and budget.\n\n\n **L443** Use Boolean options for on/off.\n\n\n **L444** Represent each outcome as actual benefit and cost in a natural-number pair.\n\n\n **L445** Adopt the on option explicitly; adoption itself is not derived from arithmetic.\n\n\n **L446** Read selection from the world’s first coordinate, separately from measured benefit and cost.\n\n\n **L447** Use measuredOutcome so the assessed option’s actual benefit and cost come from this world.\n\n\n **L448** Adopt the objective that actual benefit strictly exceeds actual cost.\n\n\n **L449** Require this option’s measured cost to be at most 3.\n\n\n **L450** Assume the selected option is on, without assuming benefit or cost conclusions.\n\n\n **L451** List benefitReason and costReason together; the procedure will use their conjunction.\n\n\n **L452** Use an unrestricted world scope in this example; starting assumptions and reason content still constrain the procedure.\n\n\n **L453** Identify an actual measured cost above 3 as relevant criticism.\n\n\n **L454** Record the nonempty response to reassess this option when its actual cost exceeds budget.\n\n\n **L455** Document the intended scope of jointReasonProcedure. The corresponding declaration concerns: Builds a joint witness at benefit four/cost three and combines both reasons to prove cost below benefit and within budget. This comment is explanatory, not a proof premise.\n\n\n **L456** State the checked result jointReasonProcedure. Builds a joint witness at benefit four/cost three and combines both reasons to prove cost below benefit and within budget. The following tactic block proves this explicit type.\n\n\n **L457** Separate the joint-reason position’s nonempty reasons, joint witness, conjunction-based consequence and criticism response.\n\n\n **L458** Use selected-on with benefit 4 and cost 3 as the common starting/limit/adoption witness.\n\n\n **L459** Take any of the two reasons at the actual (true,(4,3)) witness, then split membership to check each distinct reason.\n\n\n **L460** Expose the actual two-element reason list: benefitReason and costReason.\n\n\n **L461** Split reason membership into the benefit reason or the remaining singleton cost reason.\n\n\n **L462** Substitute the benefit reason and check that the witness’s measured benefit is exactly 4.\n\n\n **L463** Identify the remaining reason with costReason and substitute it.\n\n\n **L464** Identify the remaining reason with costReason and substitute it.\n\n\n **L465** Check the witness’s cost bound 3 ≤ 3 by reflexivity of the natural-number order.\n\n\n **L466** For an arbitrary admitted world, assume all active reasons together rather than requiring either reason alone to suffice.\n\n\n **L467** Extract the actual benefitReason from the reason conjunction at this world and adopted option.\n\n\n **L468** Extract costReason from the same conjunction at the same world and option.\n\n\n **L469** Unfold benefitReason: the adopted on option’s measured benefit equals 4.\n\n\n **L470** Unfold costReason: that same option’s measured cost is at most 3.\n\n\n **L471** Retain the actual cost constraint and leave only the strict benefit-over-cost objective.\n\n\n **L472** Rewrite the measured benefit to 4 and check that it exceeds 3.\n\n\n **L473** Compose cost ≤ 3 with 3 < benefit to establish cost < benefit using both reasons.\n\n\n **L474** For a world within limits where criticism is relevant, construct the required response about this option’s excessive cost.\n\n\n **L475** Provide the explicit nonempty response about reassessing the option when its cost exceeds the budget; this records a response, not its persuasive adequacy.\n\n\n **L476** Document the intended scope of JointReasonsExample. The corresponding declaration concerns: States that the joint procedure passes while either reason alone can hold at a world failing the consequence. This comment is explanatory, not a proof premise.\n\n\n **L477** Define JointReasonsExample. States that the joint procedure passes while either reason alone can hold at a world failing the consequence.\n\n\n **L478** Require the two-reason position to satisfy its complete ValueProcedure.\n\n\n **L479** Fix a benefit-only counterworld (true,(4,5)) satisfying the same starting assumptions and limits.\n\n\n **L480** At that world, actual adoption and the benefit reason both hold.\n\n\n **L481** Deny the assessed consequence there, because its actual cost is too high.\n\n\n **L482** Fix a cost-only counterworld (true,(0,3)) under the same starting assumptions and limits.\n\n\n **L483** At this world, actual adoption and the cost reason hold.\n\n\n **L484** Deny its assessed consequence because zero benefit does not exceed cost 3.\n\n\n **L485** State the checked result jointReasonsExample. Uses benefit four/cost five and benefit zero/cost three as counterexamples to individual-reason sufficiency. The following tactic block proves this explicit type.\n\n\n **L486** Begin the combined example with the already checked two-reason procedure.\n\n\n **L487** Supply the benefit-only counterworld with benefit 4 and cost 5, satisfying the same starting, limit and adoption conditions.\n\n\n **L488** Supply the cost-only counterworld with benefit 0 and cost 3 under the same conditions.\n\n\n **L489** The benefit-only world violates the cost constraint 5 ≤ 3; natural-number arithmetic closes the contradiction.\n\n\n **L490** The cost-only world cannot satisfy the strict objective 3 < 0; arithmetic closes this counterexample.\n\n\n **L491** Document the intended scope of heterogeneousReasons. The corresponding declaration concerns: Combines empirical, inferential and value examples with a genuine two-reason combination that neither reason alone establishes. This comment is explanatory, not a proof premise.\n\n\n **L492** State the checked result heterogeneousReasons. Combines empirical, inferential and value examples with a genuine two-reason combination that neither reason alone establishes.\n\n\n **L493** Include the actually discharged empirical switch facet.\n\n\n **L494** Include an inferential facet whose satisfiable true-world premise entails the same true-world claim.\n\n\n **L495** Include the actual switch value procedure and the two-joint-reasons example in this registered theorem.\n\n\n **L496** Combine the checked empirical facet, an inhabited inferential singleton, the value procedure and the joint-reason counterexamples.\n\n\n **L497** For the inferential facet, its singleton premise directly yields the same true-world claim at any model.\n\n\n **L499** Document the intended scope of zeroRecord. The corresponding declaration concerns: Records only a function's Boolean output at natural-number input zero. This comment is explanatory, not a proof premise.\n\n\n **L500** Define zeroRecord. Records only a function's Boolean output at natural-number input zero.\n\n\n **L501** Define localGenerator. Produces a function returning true exactly at its natural-number seed.\n\n\n **L502** Document the intended scope of allTrue. The corresponding declaration concerns: Requires a Boolean-valued function to return true at every natural number. This comment is explanatory, not a proof premise.\n\n\n **L503** Define allTrue. Requires a Boolean-valued function to return true at every natural number.\n\n\n **L504** State the checked result zeroCompatible. Proves one zero-input record constrains exactly the function's value at zero. The following tactic block proves this explicit type.\n\n\n **L505** Prove both directions between matching zeroRecord and the actual function returning true at input 0.\n\n\n **L506** Apply record compatibility to the sole named test to recover its actual observed equality.\n\n\n **L507** Conversely, singleton membership identifies any listed record with this test, whose equality is the supplied observation premise.\n\n\n **L508** Document the intended scope of GeneratingProcess. The corresponding declaration concerns: Stores producer identity, the actual earlier predicate and the seed used by its revision algorithm. This comment is explanatory, not a proof premise.\n\n\n **L509** Declare the data interface GeneratingProcess. Stores producer identity, the actual earlier predicate and the seed used by its revision algorithm.\n\n\n **L510** Store the actual generating process owner identifier.\n\n\n **L511** Store the prior Boolean-valued function before this process generates its revision.\n\n\n **L512** Store the seed input used by this process’s actual local generator.\n\n\n **L513** Document the intended scope of GeneratingProcess.outputRevision. The corresponding declaration concerns: Preserves prior successes and adds the seed-selected input through the actual local generator. This comment is explanatory, not a proof premise.\n\n\n **L514** Define GeneratingProcess.outputRevision. Preserves prior successes and adds the seed-selected input through the actual local generator.\n\n\n **L515** The revised function preserves each true prior output or adds truth at the actual generated seed input.\n\n\n **L516** Document the intended scope of ProducedRevision. The corresponding declaration concerns: Stores producer plus exact before and after predicate objects. This comment is explanatory, not a proof premise.\n\n\n **L517** Declare the data interface ProducedRevision. Stores producer plus exact before and after predicate objects.\n\n\n **L518** Identify which owner produced this concrete revision object.\n\n\n **L519** Store the actual before-function of the revision.\n\n\n **L520** Store the actual after-function of the revision.\n\n\n **L521** Document the intended scope of GeneratingProcess.produce. The corresponding declaration concerns: Constructs this process's own revision with its owner and actual prior/output functions. This comment is explanatory, not a proof premise.\n\n\n **L522** Define GeneratingProcess.produce. Constructs this process's own revision with its owner and actual prior/output functions.\n\n\n **L523** Construct the revision directly from this process’s owner, prior function and computed output revision.\n\n\n **L524** Define sampleGeneratingProcess. Uses owner seventeen, an always-false prior predicate and seed zero.\n\n\n **L525** Document the intended scope of OwnedRevisionExample. The corresponding declaration concerns: Binds self-origin and exact before/after functions to a real zero-input change whose global claim lacks support. This comment is explanatory, not a proof premise.\n\n\n **L526** Define OwnedRevisionExample. Binds self-origin and exact before/after functions to a real zero-input change whose global claim lacks support.\n\n\n **L527** Bind the revision’s producer identifier to the actual generating process owner.\n\n\n **L528** Bind its before-function to this process’s actual prior function.\n\n\n **L529** Bind its after-function to this process’s actual outputRevision.\n\n\n **L530** Require actual change at input 0 from false before to true after.\n\n\n **L531** Retain an actual false output at input 1 after that revision.\n\n\n **L532** The actual produced after-function matches the input-0 observation.\n\n\n **L533** That record still does not support the all-input truth claim.\n\n\n **L534** Document the intended scope of ownedRevisionExample. The corresponding declaration concerns: Computes ownership/object links and uses the produced function's failure at one to refute universal support. This comment is explanatory, not a proof premise.\n\n\n **L535** State the checked result ownedRevisionExample. Computes ownership/object links and uses the produced function's failure at one to refute universal support. The following tactic block proves this explicit type.\n\n\n **L536** Check producer identity, prior/output revision relationships and actual sample values by computation; retain zero-record compatibility and leave universal support to refute.\n\n\n **L537** Assume zeroRecord supports allTrue, to refute it using this owner’s actual produced revision.\n\n\n **L538** Apply purported support to this owner’s actual produced after-function at input 1, where its revision still returns false.\n\n\n **L539** Eliminate the resulting false=true equality; the actual revision is an evidence-compatible counterexample.\n\n\n **L540** Document the intended scope of selfOriginDoesNotSupport. The corresponding declaration concerns: Retains the local observation countermodel and adds an actual owned before/after revision with the same unsupported global claim. This comment is explanatory, not a proof premise.\n\n\n **L541** State the checked result selfOriginDoesNotSupport. Retains the local observation countermodel and adds an actual owned before/after revision with the same unsupported global claim.\n\n\n **L542** Compute localGenerator 0 as true at 0 and false at 1.\n\n\n **L543** Require this generated function to match the same input-0 record.\n\n\n **L544** State failure of all-input support and include the concrete owner/prior/revision relationship example.\n\n\n **L545** Compute the generated function’s values at 0 and 1, give its zero-record compatibility, and include the owned revision relationship example.\n\n\n **L546** Assume the local zero observation entails true output at every input of every compatible function.\n\n\n **L547** Instantiate alleged universal support with localGenerator 0 and then input 1; compatibility at 0 did not constrain this failing input.\n\n\n **L548** Eliminate the resulting false=true equality; the actual revision is an evidence-compatible counterexample.\n\n\n **L549** Document the intended scope of localNotUniversal. The corresponding declaration concerns: Exhibits both a universally true function and a zero-only true function compatible with the same observation, with an explicit outside input; therefore the observation does not support universal truth. This comment is explanatory, not a proof premise.\n\n\n **L550** State the checked result localNotUniversal. Exhibits both a universally true function and a zero-only true function compatible with the same observation, with an explicit outside input; therefore the observation does not support universal truth.\n\n\n **L551** Require at least one natural-number input outside the observed singleton scope.\n\n\n **L552** The constant-true function matches the zero observation.\n\n\n **L553** The local generator also matches that same observation.\n\n\n **L554** The first function is universally true while the second is not.\n\n\n **L555** Therefore the shared observation does not support universal truth.\n\n\n **L556** Provide an input outside the observed scope and show both the constant-true function and local generator satisfy the same zero observation.\n\n\n **L557** The constant function is universally true; retain the known support counterexample and leave the local generator’s universal claim to refute.\n\n\n **L558** Evaluate any proposed all-input truth of the local generator at 1, where its actual result is false.\n\n\n **L559** Document the intended scope of hiddenDifference. The corresponding declaration concerns: Shows the two functions agree on the domain restricted to zero and disagree at one; local agreement does not establish global equality. This comment is explanatory, not a proof premise.\n\n\n **L560** State the checked result hiddenDifference. Shows the two functions agree on the domain restricted to zero and disagree at one; local agreement does not establish global equality.\n\n\n **L561** State equality of both functions only for inputs satisfying n=0.\n\n\n **L562** State their concrete output inequality at input 1.\n\n\n **L563** Separate agreement on the input-0 scope from the concrete output difference at input 1.\n\n\n **L564** Substitute n=0 from the scope premise; both functions then compute to true.\n\n\n **L565** Document the intended scope of singleObservation. The corresponding declaration concerns: A single zero-input observation is nonvacuously compatible and supports its local result but does not support the all-input claim. This comment is explanatory, not a proof premise.\n\n\n **L566** State the checked result singleObservation. A single zero-input observation is nonvacuously compatible and supports its local result but does not support the all-input claim.\n\n\n **L567** Require an actual function compatible with the single observation, preventing empty evidence semantics.\n\n\n **L568** That single record supports its actual input-0 claim.\n\n\n **L569** It does not support the stronger all-input claim.\n\n\n **L570** Compute the record count as one and provide localGenerator 0 as an actual compatible witness.\n\n\n **L571** Extract the supported input-0 fact directly from compatibility and reuse the established failure of allTrue support.\n\n\n **L572** Document the intended scope of arithmeticFacet. The corresponding declaration concerns: Defines an inferential facet with assumption n=2 and conclusion n+1=3. This comment is explanatory, not a proof premise.\n\n\n **L573** Define arithmeticFacet. Defines an inferential facet with assumption n=2 and conclusion n+1=3.\n\n\n **L574** Define usesObservation. Returns true only for empirical facet tags; this is a classification test, not an analysis of computational executability.\n\n\n **L575** Classify an empirical facet as using observation because it carries actual test records.\n\n\n **L576** Classify inferential and value facets as not using observation in this represented method classifier.\n\n\n **L577** Document the intended scope of noUniversalChain. The corresponding declaration concerns: Discharges the arithmetic implication with a model n=2 while its observation tag is false. This is an example of nonempirical discharge, not a universal account of knowledge. This comment is explanatory, not a proof premise.\n\n\n **L578** State the checked result noUniversalChain. Discharges the arithmetic implication with a model n=2 while its observation tag is false. This is an example of nonempirical discharge, not a universal account of knowledge. The following tactic block proves this explicit type.\n\n\n **L579** Provide n=2 as the inferential theory’s nonempty witness and note that its facet constructor uses no observation.\n\n\n **L580** Take any natural-number world n satisfying the arithmetic facet’s actual premise theory.\n\n\n **L581** Extract n=2 from the actual singleton premise, rather than assuming the desired successor conclusion.\n\n\n **L582** Expose the arithmetic conclusion n+1=3 as the remaining goal.\n\n\n **L583** Rewrite n to 2 using the premise; the required arithmetic equality reduces by computation.\n\n\n **L584** Document the intended scope of Trial. The corresponding declaration concerns: Stores setting, actual outcome and recorded outcome as independent natural-number fields, with no measurement mechanism. This comment is explanatory, not a proof premise.\n\n\n **L585** Declare the data interface Trial. Stores setting, actual outcome and recorded outcome as independent natural-number fields, with no measurement mechanism.\n\n\n **L586** Store the trial’s setting separately from its outcomes.\n\n\n **L587** Store the trial’s actual outcome, whether accurately recorded or not.\n\n\n **L588** Store the separately recorded outcome to allow accuracy comparisons.\n\n\n **L589** Document the intended scope of Verified. The corresponding declaration concerns: Verification means exact equality of the two supplied outcome fields. This comment is explanatory, not a proof premise.\n\n\n **L590** Define Verified. Verification means exact equality of the two supplied outcome fields.\n\n\n **L591** Define Reproduced. Reproduction means only equality of two setting fields; it does not require matching outcomes or histories.\n\n\n **L592** Define Bounded. The bound property is actualOutcome≤2, a fixed threshold rather than a general stability theory.\n\n\n **L593** Document the intended scope of variableOutcomesStableBound. The corresponding declaration concerns: Exhibits matching settings with different actual outcomes that both satisfy the fixed upper bound. This comment is explanatory, not a proof premise.\n\n\n **L594** State the checked result variableOutcomesStableBound. Exhibits matching settings with different actual outcomes that both satisfy the fixed upper bound.\n\n\n **L595** Fix the first trial at setting 0 with actual and recorded outcome 1.\n\n\n **L596** Fix the second trial at the same setting with actual and recorded outcome 2.\n\n\n **L597** Require the two explicitly fixed trials to share settings, differ in actual outcomes and both satisfy actualOutcome ≤ 2.\n\n\n **L598** Evaluate the two same-setting trials: actual outcomes 1 and 2 differ, but each satisfies actualOutcome ≤ 2.\n\n\n **L599** Document the intended scope of verificationReproductionStability. The corresponding declaration concerns: Uses explicit numeric trials to separate recorded/actual agreement, equal settings, and the fixed outcome bound. This comment is explanatory, not a proof premise.\n\n\n **L600** State the checked result verificationReproductionStability. Uses explicit numeric trials to separate recorded/actual agreement, equal settings, and the fixed outcome bound.\n\n\n **L601** Require two accurately recorded trials whose settings nevertheless differ.\n\n\n **L602** Require repeated settings alongside an inaccurate second record and an actual result exceeding the bound.\n\n\n **L603** Require preserved bounds even though one recorded outcome is inaccurate.\n\n\n **L604** Compute each concrete trial predicate separately, exhibiting changed settings, inaccurate recording and failure or preservation of the bound without conflating them.\n\n\n **L605** Document the intended scope of Program. The corresponding declaration concerns: Defines a tiny program language with doubling and natural-number constants only. This comment is explanatory, not a proof premise.\n\n\n **L606** Declare the alternatives Program. Defines a tiny program language with doubling and natural-number constants only.\n\n\n **L607** Provide syntax for the explanation program that doubles its actual input.\n\n\n **L608** Provide syntax for a constant-output explanation program carrying its returned natural number.\n\n\n **L609** Define Program.eval. Defines the executable meaning of the two program constructors.\n\n\n **L610** Evaluate the doubleInput explanation program at n by actual addition n+n.\n\n\n **L611** Evaluate a constant program by returning its stored value, independently of the input.\n\n\n **L612** Document the intended scope of Process. The corresponding declaration concerns: A process consists of an arbitrary natural-number function and an optional tiny-language explanation program. This comment is explanatory, not a proof premise.\n\n\n **L613** Declare the data interface Process. A process consists of an arbitrary natural-number function and an optional tiny-language explanation program.\n\n\n **L614** Store the same process’s actual output function over natural-number inputs.\n\n\n **L615** Store the process’s optional supplied explanation program, separately from its output function.\n\n\n **L616** Document the intended scope of OutputContract. The corresponding declaration concerns: Requires the output function to double every natural-number input. This comment is explanatory, not a proof premise.\n\n\n **L617** Define OutputContract. Requires the output function to double every natural-number input.\n\n\n **L618** Document the intended scope of ExplanationContract. The corresponding declaration concerns: Requires an attached program whose evaluated outputs equal the process output on every input; this is extensional agreement, not causal or human explanatory adequacy. This comment is explanatory, not a proof premise.\n\n\n **L619** Define ExplanationContract. Requires an attached program whose evaluated outputs equal the process output on every input; this is extensional agreement, not causal or human explanatory adequacy.\n\n\n **L620** Require an actually supplied program whose evaluation equals this process’s output at every natural input.\n\n\n **L621** Document the intended scope of outputOnlyProcess. The corresponding declaration concerns: Constructs the correct doubling function without any attached explanation program. This comment is explanatory, not a proof premise.\n\n\n **L622** Define outputOnlyProcess. Constructs the correct doubling function without any attached explanation program.\n\n\n **L623** Define explainedProcess. Constructs the same output function with the doubling program attached.\n\n\n **L624** Document the intended scope of processScope. The corresponding declaration concerns: Restricts modeled candidates to the exact assessed process, without restricting the contract's input quantifier. This comment is explanatory, not a proof premise.\n\n\n **L625** Define processScope. Restricts modeled candidates to the exact assessed process, without restricting the contract's input quantifier.\n\n\n **L626** Restrict theory models by the actual equality candidate=assessed, not by assuming the desired contract.\n\n\n **L627** Document the intended scope of processContractFacet. The corresponding declaration concerns: Builds an inferential contract facet under the exact assessed-process identity assumption. This comment is explanatory, not a proof premise.\n\n\n **L628** Define processContractFacet. Builds an inferential contract facet under the exact assessed-process identity assumption.\n\n\n **L629** Build an inferential facet with that exact object-identity scope and the supplied contract conclusion.\n\n\n **L630** Document the intended scope of processScopeModels. The corresponding declaration concerns: Proves that modeling the identity scope is exactly equality to the assessed process. This comment is explanatory, not a proof premise.\n\n\n **L631** State the checked result processScopeModels. Proves that modeling the identity scope is exactly equality to the assessed process.\n\n\n **L632** State that modeling this scope is exactly equality to the assessed process.\n\n\n **L633** Instantiate modelsSingleton with equality to the actual assessed Process, proving exactly which candidates satisfy processScope.\n\n\n **L634** Document the intended scope of processContractDischarged. The corresponding declaration concerns: Uses a supplied proof of the actual process contract and scope equality to discharge the corresponding inferential facet. This comment is explanatory, not a proof premise.\n\n\n **L635** State the checked result processContractDischarged. Uses a supplied proof of the actual process contract and scope equality to discharge the corresponding inferential facet.\n\n\n **L636** Conclude discharge for that same object’s contract facet using the explicit contract-proof premise.\n\n\n **L637** Use the assessed process itself as a model of its identity scope; leave semantic entailment of its contract.\n\n\n **L638** Take a candidate and proof hc that it lies in the actual assessed process’s identity scope.\n\n\n **L639** From the scope model hc, recover that the candidate is exactly the assessed process.\n\n\n **L640** Substitute that process identity so the contract goal is about the actual assessed object.\n\n\n **L641** Use the explicit premise proof of this object’s contract; the generic helper does not create contract correctness without that premise.\n\n\n **L642** Document the intended scope of ProcessGrounds. The corresponding declaration concerns: Requires canonical Grounds for this exact process/contract facet and its singleton applicability. This comment is explanatory, not a proof premise.\n\n\n **L643** Define ProcessGrounds. Requires canonical Grounds for this exact process/contract facet and its singleton applicability.\n\n\n **L644** Require Grounds for the supplied contract using canonical articulation and the exact assessed-process facet as applicable.\n\n\n **L645** The listed evidence package contains precisely that same process-contract facet.\n\n\n **L646** State the checked result processGrounds. Constructs matching contract Grounds from an actual proof for that same assessed process.\n\n\n **L647** Conclude these same-object ProcessGrounds from the explicit proof of the contract at the assessed process.\n\n\n **L648** Apply the contract-discharge helper to the explicit proof for this same assessed process.\n\n\n **L649** Separate nonempty facets, exact applicability coverage and each facet’s claim/articulation/discharge obligations.\n\n\n **L650** The applicability assumption identifies the facet with the one prescribed facet, which belongs to the singleton list.\n\n\n **L651** Singleton membership identifies the current facet with the prescribed one; substitute it to check its exact claim and grounds.\n\n\n **L652** Assemble the same contract claim, nonempty canonical articulation, semantic connection to the object scope and the established discharge.\n\n\n **L653** Document the intended scope of outputCorrectByEvaluation. The corresponding declaration concerns: Proves all-input doubling directly from the concrete output function, not an assumed success flag. This comment is explanatory, not a proof premise.\n\n\n **L654** State the checked result outputCorrectByEvaluation. Proves all-input doubling directly from the concrete output function, not an assumed success flag. The supplied proof term uses the displayed constructed witnesses or earlier lemmas, rather than adding an axiom.\n\n\n **L655** Document the intended scope of outputOnlyNoExplanation. The corresponding declaration concerns: Rejects an attached explanation witness because the same process stores none. This comment is explanatory, not a proof premise.\n\n\n **L656** State the checked result outputOnlyNoExplanation. Rejects an attached explanation witness because the same process stores none. The following tactic block proves this explicit type.\n\n\n **L657** Any explanation contract would supply a program whose some value equals the process’s actual none response; distinct option constructors make that impossible.\n\n\n **L658** Document the intended scope of FullProcessContract. The corresponding declaration concerns: Conjoins output correctness with an attached output-faithful explanation for the same process. This comment is explanatory, not a proof premise.\n\n\n **L659** Define FullProcessContract. Conjoins output correctness with an attached output-faithful explanation for the same process.\n\n\n **L660** Document the intended scope of OutputContractEvidence. The corresponding declaration concerns: Combines grounded output and a nonempty exact-process scope whose model refutes the stronger full contract. This comment is explanatory, not a proof premise.\n\n\n **L661** Define OutputContractEvidence. Combines grounded output and a nonempty exact-process scope whose model refutes the stronger full contract.\n\n\n **L662** Require grounded output correctness for the actual output-only process.\n\n\n **L663** Keep that process itself as an inhabitant of the exact assessment scope.\n\n\n **L664** Deny that this same scope entails the stronger output-plus-explanation contract.\n\n\n **L665** Document the intended scope of outputContractEvidence. The corresponding declaration concerns: Builds output Grounds by evaluation and uses the missing explanation at the same process to refute full-contract entailment. This comment is explanatory, not a proof premise.\n\n\n **L666** State the checked result outputContractEvidence. Builds output Grounds by evaluation and uses the missing explanation at the same process to refute full-contract entailment. The following tactic block proves this explicit type.\n\n\n **L667** Supply the actual output contract’s grounds and the process’s own scope witness, then refute the stronger contract under that very scope.\n\n\n **L668** Assume that this exact process scope entails the stronger output-plus-explanation contract.\n\n\n **L669** Instantiate alleged full-contract entailment at outputOnlyProcess itself; its explanation component contradicts the proven absent explanation.\n\n\n **L670** Document the intended scope of ScopedApplicationEvidence. The corresponding declaration concerns: Requires both different application contracts to have Grounds and nonempty exact-process scopes. This comment is explanatory, not a proof premise.\n\n\n **L671** Define ScopedApplicationEvidence. Requires both different application contracts to have Grounds and nonempty exact-process scopes.\n\n\n **L672** Include grounded output correctness for outputOnlyProcess.\n\n\n **L673** Include grounded output and explanation together for explainedProcess.\n\n\n **L674** Make the first scope’s exact identity with outputOnlyProcess explicit for every candidate.\n\n\n **L675** Likewise make the second scope’s exact identity with explainedProcess explicit.\n\n\n **L676** Require both actual process-identity theories to be satisfiable.\n\n\n **L677** Document the intended scope of scopedApplicationEvidence. The corresponding declaration concerns: Supplies actual all-input output proofs and the doubling explanation program for the stronger contract. This comment is explanatory, not a proof premise.\n\n\n **L678** State the checked result scopedApplicationEvidence. Supplies actual all-input output proofs and the doubling explanation program for the stronger contract. The following tactic block proves this explicit type.\n\n\n **L679** Construct output-only grounds by evaluation and reserve the explained process’s stronger contract proof.\n\n\n **L680** Provide exact process-identity scope equivalences and each process itself as a nonempty scope witness.\n\n\n **L681** Provide exact process-identity scope equivalences and each process itself as a nonempty scope witness.\n\n\n **L682** For explainedProcess, prove every doubled output by reflexivity and supply doubleInput as an actual provided, extensionally faithful explanation program.\n\n\n **L683** Document the intended scope of outputNotExplanation. The corresponding declaration concerns: Proves output correctness with no attached explanation and includes the corresponding same-object Grounds/countermodel evidence. This comment is explanatory, not a proof premise.\n\n\n **L684** State the checked result outputNotExplanation. Proves output correctness with no attached explanation and includes the corresponding same-object Grounds/countermodel evidence.\n\n\n **L685** Retain absence of this process’s explanation contract together with its scoped output evidence.\n\n\n **L686** Combine actual output correctness, the same process’s absence of an explanation, and its matched scoped output evidence.\n\n\n **L687** Document the intended scope of applicationContractsDiffer. The corresponding declaration concerns: Shows output-only evidence fails the stronger contract, while the explained process satisfies both; both applications carry their own Grounds. This comment is explanatory, not a proof premise.\n\n\n **L688** State the checked result applicationContractsDiffer. Shows output-only evidence fails the stronger contract, while the explained process satisfies both; both applications carry their own Grounds.\n\n\n **L689** The output-only process meets output correctness but fails the combined output-and-explanation contract.\n\n\n **L690** The explained process meets both actual contracts.\n\n\n **L691** Include the explicit scoped grounds and nonempty witnesses for both application contracts.\n\n\n **L692** For outputOnlyProcess, supply actual output correctness and refute any joint contract by projecting its impossible explanation component.\n\n\n **L693** For explainedProcess, compute all doubled outputs, supply faithful doubleInput syntax, and include both contracts’ matched scoped grounds.\n\n\n **L694** Document the intended scope of ExternalCertificate. The corresponding declaration concerns: Binds output-correctness proof to the exact process and distinct assessor/assessed identifiers; it is a mathematical role model, not authenticated real provenance. This comment is explanatory, not a proof premise.\n\n\n **L695** Declare the data interface ExternalCertificate. Binds output-correctness proof to the exact process and distinct assessor/assessed identifiers; it is a mathematical role model, not authenticated real provenance.\n\n\n **L696** Store the external assessor’s identifier.\n\n\n **L697** Store the assessed participant’s identifier; the certificate type already fixes the assessed Process.\n\n\n **L698** Require distinct participant identifiers as an explicit certificate field.\n\n\n **L699** Require a proof of this very process’s doubled output for every input; a generic certificate assumes this field, while the concrete certificate constructs it.\n\n\n **L700** Document the intended scope of externalOutputCertificate. The corresponding declaration concerns: Constructs assessor forty-two's proof for assessed object seven by actual output evaluation. This comment is explanatory, not a proof premise.\n\n\n **L701** Define externalOutputCertificate. Constructs assessor forty-two's proof for assessed object seven by actual output evaluation.\n\n\n **L702** Construct participants 42 and 7, compute their inequality, and prove every doubled output by reflexivity of the actual program.\n\n\n **L703** Document the intended scope of externalAssessment. The corresponding declaration concerns: Uses a distinct-participant certificate to supply matching output Grounds while the assessed process still returns no explanation. This comment is explanatory, not a proof premise.\n\n\n **L704** State the checked result externalAssessment. Uses a distinct-participant certificate to supply matching output Grounds while the assessed process still returns no explanation.\n\n\n **L705** Require an actual external certificate indexed by outputOnlyProcess.\n\n\n **L706** Identify its assessor as 42 and assessed participant as 7.\n\n\n **L707** Require their distinction and actual output correctness of the same process.\n\n\n **L708** Also retain matched ProcessGrounds for that same output contract.\n\n\n **L709** Still deny an internal explanation contract for that actual process.\n\n\n **L710** Use the actual externalOutputCertificate with fixed participants 42 and 7 and its proved participant distinction.\n\n\n **L711** Take universal output correctness from that concrete certificate, whose proof was constructed from the actual program.\n\n\n **L712** Build matching ProcessGrounds for the very outputOnlyProcess using that same concrete output proof.\n\n\n **L713** Retain outputOnlyNoExplanation, so the external certificate does not assert an internal explanation exists.\n\n\n **L714** Document the intended scope of arithmeticArticulation. The corresponding declaration concerns: Names the canonical articulation of the arithmetic inferential facet. This comment is explanatory, not a proof premise.\n\n\n **L715** Define arithmeticArticulation. Names the canonical articulation of the arithmetic inferential facet.\n\n\n **L716** Document the intended scope of nonExecutableAssessment. The corresponding declaration concerns: Constructs Grounds for the arithmetic conditional facet and distinguishes its nonempirical tag from a discharged empirical switch facet. The tag does not establish noncomputability. This comment is explanatory, not a proof premise.\n\n\n **L717** State the checked result nonExecutableAssessment. Constructs Grounds for the arithmetic conditional facet and distinguishes its nonempirical tag from a discharged empirical switch facet. The tag does not establish noncomputability.\n\n\n **L718** Require matched canonical Grounds for n+1=3 using precisely arithmeticFacet.\n\n\n **L719** Specify that this inferential facet uses no observation.\n\n\n **L720** At the same time, include an actually discharged empirical facet that does use observation.\n\n\n **L721** Build the arithmetic claim’s nonempty, applicability-covered Grounds, retain its no-observation classification, and include the valid observed switch facet.\n\n\n **L722** Singleton membership fixes the assessed facet to arithmeticFacet, so its specific assumptions and conclusion must be checked.\n\n\n **L723** Use the same arithmetic facet’s proven discharge with canonical nonempty articulation and its exact semantic connection.\n\n\n **L725** Close namespace CoreReader.Evidence; this adds no proof or premise.\n\n\n### `leanified/CoreReader/Integration.lean`\n\n\n```lean\nimport CoreReader.Agency\nimport CoreReader.Choice\n\nnamespace CoreReader.Integration\nopen CoreReader.Logic CoreReader.Evidence CoreReader.Agency CoreReader.Choice\n\n/- Canonical articulation preserves the actual assessment contents of each facet. -/\ntheorem canonicalGrounds {W : Type} (claim : Claim W) (facets : List (Facet W))\n (hne : facets ≠ []) (checked : ∀ f ∈ facets, f.claim = claim ∧ FacetDischarged f) :\n Grounds claim canonicalArticulation (fun f => f ∈ facets) facets := by\n exact ⟨hne, fun _ h => h, fun f hf =>\n ⟨(checked f hf).1, canonicalArticulated f (checked f hf).2,\n canonicalFacetArticulated f, (checked f hf).2⟩⟩\n\ntheorem canonicalGroundsForSingleton {W : Type} (f : Facet W) (checked : FacetDischarged f) :\n Grounds f.claim canonicalArticulation (fun g => g = f) [f] := by\n refine ⟨by simp, (by intro g hg; cases hg; simp), ?_⟩\n intro g hg\n simp only [List.mem_singleton] at hg\n subst g\n exact ⟨rfl, canonicalArticulated f checked, canonicalFacetArticulated f, checked⟩\n\n/- A mode selects whether a system applies or waives the modeled governance rule. -/\ninductive Mode | apply | waive\n deriving DecidableEq, Repr\n\n/- The four hypotheses vary algorithm and governance independently for the same assessed system. -/\nabbrev World := Candidate × Mode\n\ndef actual : World := (.identity, .apply)\n\n/- A method's form and its possible executable realizations belong to one object. -/\nstructure Method where\n form : Form\n realize : World → Implementation\n\n/- System fields identify the owner, its method, its current principle form, policy and work. -/\nstructure System where\n owner : Nat\n method : Method\n principleForm : Form\n governance : World → Mode\n requirements : Requirements\n\ndef policyFor : Mode → Policy\n | .apply => openPolicy\n | .waive => neutralPolicy\n\ndef workFor (owner : Nat) : Mode → List WorkRecord\n | .apply => completeOwnWork owner\n | .waive => []\n\ndef System.policy (s : System) (w : World) : Policy := policyFor (s.governance w)\ndef System.rules (s : System) (_w : World) : List Principle := ownRules s.owner\ndef System.work (s : System) (w : World) : List WorkRecord := workFor s.owner (s.governance w)\n\ndef actualSystem : System where\n owner := 0\n method := ⟨⟨.method, 0⟩, fun w => implementation w.1⟩\n principleForm := ⟨.principle, 0⟩\n governance := Prod.snd\n requirements := identityRequirements\n\ndef systemCapability (s : System) : Claim World :=\n fun w => ∀ n, s.requirements.inputs n → (s.method.realize w).run n = s.requirements.expected n\n\ndef systemBudget (s : System) : Claim World :=\n fun w => (s.method.realize w).cost ≤ s.requirements.budget\n\ndef systemObservation (s : System) : Record World :=\n ⟨fun w => decide ((s.method.realize w).run 0 = s.requirements.expected 0), true⟩\n\ndef systemHeld (s : System) : Theory World :=\n union (singleton (systemCapability s)) (singleton (systemBudget s))\n\ninductive Question | correctOutput | affordable\n deriving DecidableEq, Repr\n\ndef systemContext (s : System) : Context World Question :=\n ⟨singleton (Compatible [systemObservation s]),\n (fun q => match q with | .correctOutput => systemCapability s | .affordable => systemBudget s),\n fun w => (s.method.realize w).domain 0 ∧ w.2 = .apply⟩\n\nabbrev capability := systemCapability actualSystem\nabbrev observation := systemObservation actualSystem\nabbrev held := systemHeld actualSystem\nabbrev context := systemContext actualSystem\n\n/- The output observation identifies the algorithm, without identifying its independently varied governance mode. -/\ntheorem observationIdentifies (w : World) : Compatible [observation] w ↔ w.1 = .identity := by\n rcases w with ⟨candidate, mode⟩\n cases candidate <;> simp [Compatible, observation, systemObservation, actualSystem,\n implementation, identityRequirements, identityImpl, successorImpl]\n\ntheorem capabilityActual : capability actual := fun _ _ => rfl\n\ntheorem observedCapability : Supports [observation] capability := by\n intro w hw\n have hid := (observationIdentifies w).1 hw\n rcases w with ⟨candidate, mode⟩\n change candidate = .identity at hid\n subst candidate\n exact fun _ _ => rfl\n\ndef capabilityFacet : Facet World := .empirical [observation] (fun _ => True) capability (fun _ => True)\n\ntheorem capabilityFacetChecked : FacetDischarged capabilityFacet := by\n exact ⟨⟨actual, (observationIdentifies actual).2 rfl, trivial⟩,\n (fun w hw _ => observedCapability w hw), fun _ _ => trivial⟩\n\ntheorem capabilityGrounds : Grounds capability canonicalArticulation\n (fun f => f = capabilityFacet) [capabilityFacet] :=\n canonicalGroundsForSingleton capabilityFacet capabilityFacetChecked\n\ntheorem actualAdmissible : Admissible held context actual := by\n refine ⟨(modelsUnion _ _ _).2 ⟨(modelsSingleton _ _).2 capabilityActual,\n (modelsSingleton _ _).2 (by change 1 ≤ 1; decide)⟩,\n (modelsSingleton _ _).2 ((observationIdentifies actual).2 rfl), trivial, rfl⟩\n\ntheorem jointConsistent : Consistent held context :=\n consequenceConsistency held context ⟨actual, actualAdmissible⟩\n\n/- The current method/principle forms, judgments, rules and own work are read from this very system and world. -/\ndef Charter (s : System) (w : World) : Prop :=\n Generative (s.policy w) ∧ Consistent (systemHeld s) (systemContext s) ∧\n Reflexive s.owner (s.rules w) (s.work w) ∧\n (s.policy w).current s.method.form ∧ (s.policy w).current s.principleForm\n\ntheorem charterChecked : Charter actualSystem actual :=\n ⟨⟨Or.inl rfl, fun _ _ => trivial⟩, jointConsistent, completeOwnWork_reflexive 0, rfl, rfl⟩\n\n/- Revision adds a supported input-specific assertion about the same system's realized method. -/\ndef revisedHeld : Theory World := union held\n (singleton (fun w => (actualSystem.method.realize w).run 0 = actualSystem.requirements.expected 0))\n\ndef initialSnapshot : Snapshot World Question := ⟨held, context, 0⟩\ndef revisedSnapshot : Snapshot World Question := ⟨revisedHeld, context, 1⟩\n\ntheorem revisionKeepsConsistency :\n Charter actualSystem actual ∧ Consistent revisedHeld context ∧\n TruthfulReport initialSnapshot revisedSnapshot true ∧\n ¬ TruthfulReport initialSnapshot revisedSnapshot false := by\n refine ⟨charterChecked, consequenceConsistency revisedHeld context ⟨actual,\n (modelsUnion _ _ _).2 ⟨actualAdmissible.1, (modelsSingleton _ _).2 rfl⟩,\n actualAdmissible.2⟩, (fun _ => rfl), ?_⟩\n intro h\n have bad := h (Or.inr (by decide))\n cases bad\n\n/- A claim about this system's method is assessed as its owner's system claim. -/\ndef OwnCapabilityDuty (s : System) (w : World) (facets : List (Facet World)) : Prop :=\n Performed (s.work w) (.system s.owner) .assessment ∧\n Grounds (systemCapability s) canonicalArticulation (fun f => f ∈ facets) facets\n\ntheorem ownCapabilityGrounded :\n OwnCapabilityDuty actualSystem actual [capabilityFacet] ∧ capability actual := by\n refine ⟨⟨?_, ?_⟩, capabilityActual⟩\n · exact ownAssessmentPerformed 0 (.system 0) (by simp [ownSubjects])\n · exact canonicalGrounds capability [capabilityFacet] (by simp)\n (by intro f hf; simp only [List.mem_singleton] at hf; cases hf; exact ⟨rfl, capabilityFacetChecked⟩)\n\n/- This cost observation is true of both algorithms but does not discriminate their output behavior. -/\ndef costAllowanceRecord : Record World :=\n ⟨fun w => decide ((actualSystem.method.realize w).cost ≤ 2), true⟩\n\ndef unsupportedCapabilityFacet : Facet World :=\n .empirical [costAllowanceRecord] (fun _ => True) capability (fun _ => True)\n\ntheorem costCompatibleWithFailure : Compatible [costAllowanceRecord] (.successor, .apply) := by\n intro r hr\n simp only [List.mem_singleton] at hr\n subst r\n rfl\n\ntheorem costDoesNotSupportOutput : ¬ Supports [costAllowanceRecord] capability := by\n intro h\n have bad := h (.successor, .apply) costCompatibleWithFailure 0 trivial\n cases bad\n\ntheorem unsupportedGrounds : ¬ Grounds capability canonicalArticulation\n (fun f => f = unsupportedCapabilityFacet) [unsupportedCapabilityFacet] := by\n intro h\n have discharged := (h.2.2 unsupportedCapabilityFacet (by simp)).2.2.2\n exact costDoesNotSupportOutput (fun w hw => discharged.2.1 w hw trivial)\n\n/- Five separately adopted requirements govern distinct operations; the mode does not give them priority over one another. -/\ninductive Commitment | generation | consistency | reflexivity | grounds | choice\n deriving DecidableEq, Repr\n\n/- A Grounds policy governs arbitrary claims, articulations and applicable facets, rather than only one capability claim. -/\ndef groundsPermission (mode : Mode) (claim : Claim World) (a : Facet World → Articulation World)\n (applicable : Facet World → Prop) (facets : List (Facet World)) : Prop :=\n match mode with\n | .apply => Grounds claim a applicable facets\n | .waive => True\n\ndef GroundsProvision (mode : Mode) : Prop :=\n ∀ claim a applicable facets, groundsPermission mode claim a applicable facets →\n Grounds claim a applicable facets\n\ntheorem groundsProvisionMeaning (mode : Mode) : GroundsProvision mode ↔ mode = .apply := by\n cases mode with\n | apply => exact ⟨fun _ => rfl, fun _ _ _ _ _ h => h⟩\n | waive =>\n constructor\n · intro h\n exact False.elim (unsupportedGrounds (h capability canonicalArticulation\n (fun f => f = unsupportedCapabilityFacet) [unsupportedCapabilityFacet] trivial))\n · intro h; cases h\n\n/- The consistency policy checks a whole same-context theory, not isolated judgments. -/\ndef consistencyPermission (mode : Mode) (t : Theory World) (c : Context World Question) : Prop :=\n match mode with | .apply => Consistent t c | .waive => True\n\ndef conflictingHeld : Theory World := union (singleton capability) (singleton (fun w => ¬ capability w))\n\ntheorem conflictConsequences :\n Consequence conflictingHeld context .correctOutput true ∧\n Consequence conflictingHeld context .correctOutput false := by\n exact ⟨fun w hw => hw.1 capability (Or.inl rfl),\n fun w hw => hw.1 (fun w => ¬ capability w) (Or.inr rfl)⟩\n\ntheorem conflictingHeldInconsistent : ¬ Consistent conflictingHeld context :=\n conflictRequiresChange conflictingHeld context .correctOutput conflictConsequences.1 conflictConsequences.2\n\n/- The selection policy applies the actual output/budget and relevant-reason conditions to every implementation. -/\ndef choicePermission (mode : Mode) (req : Requirements) (i : Implementation) (reasons : List Reason) : Prop :=\n match mode with | .apply => JustifiedChoice req i reasons | .waive => True\n\n/- The following consequences are computed from distinct rule applications; they are not interchangeable support flags. -/\ndef proposedOperation : Mode → Operation\n | .apply => .successor\n | .waive => .copy\n\ndef selfSamples : Mode → List Nat\n | .apply => [0, 1]\n | .waive => [1]\n\nnoncomputable def conflictDecision (mode : Mode) : Bool :=\n @decide (consistencyPermission mode conflictingHeld context) (Classical.propDecidable _)\n\nnoncomputable def groundsDecision (mode : Mode) (facet : Facet World) : Bool :=\n @decide (groundsPermission mode facet.claim canonicalArticulation (fun f => f = facet) [facet])\n (Classical.propDecidable _)\n\nnoncomputable def choiceDecision (mode : Mode) (i : Implementation) (reasons : List Reason) : Bool :=\n @decide (choicePermission mode identityRequirements i reasons) (Classical.propDecidable _)\n\ntheorem decisionsApply : conflictDecision .apply = false ∧\n groundsDecision .apply unsupportedCapabilityFacet = false ∧\n groundsDecision .apply capabilityFacet = true ∧\n choiceDecision .apply cheapSuccessor [.method .simplicity] = false ∧\n choiceDecision .apply identityImpl objectiveReason = true := by\n classical\n simp only [conflictDecision, groundsDecision, choiceDecision, consistencyPermission,\n groundsPermission, choicePermission]\n exact ⟨decide_eq_false conflictingHeldInconsistent,\n decide_eq_false unsupportedGrounds, decide_eq_true capabilityGrounds,\n decide_eq_false eligibleInternalReasonNotSufficient.2, decide_eq_true identityJustified⟩\n\ntheorem decisionsWaive : conflictDecision .waive = true ∧\n groundsDecision .waive unsupportedCapabilityFacet = true ∧\n choiceDecision .waive cheapSuccessor [.method .simplicity] = true := by\n exact ⟨@decide_eq_true (consistencyPermission .waive conflictingHeld context)\n (Classical.propDecidable _) trivial,\n @decide_eq_true (groundsPermission .waive unsupportedCapabilityFacet.claim canonicalArticulation\n (fun f => f = unsupportedCapabilityFacet) [unsupportedCapabilityFacet]) (Classical.propDecidable _) trivial,\n @decide_eq_true (choicePermission .waive identityRequirements cheapSuccessor [.method .simplicity])\n (Classical.propDecidable _) trivial⟩\n\n/- Each application supplies its own outcome type, adopted objective, constraints and actual option-indexed reasons. -/\nnoncomputable def commitmentPositionFor (c : Commitment) (chosenMode : Mode) : ValuePosition World :=\n match c with\n | .generation => {\n Position := Mode, Outcome := Operation, adopted := chosenMode, selected := actualSystem.governance,\n outcome := fun _ mode => proposedOperation mode,\n objective := fun op => op.run 0 ≠ Operation.copy.run 0,\n constraints := fun _ mode => Generative (policyFor mode),\n starting := singleton (fun w => actualSystem.governance w = chosenMode),\n reasons := [fun _ mode => (proposedOperation mode).run 0 = 1 ∧ Operation.copy.run 0 = 0],\n limits := fun w => w.1 = .identity,\n relevantCriticism := fun _ => ¬ Expanded baseState inflatedState,\n response := fun _ => some \"Pursuing expansion does not guarantee it; assess the actual before and after capabilities separately\" }\n | .consistency => {\n Position := Mode, Outcome := Bool, adopted := chosenMode, selected := actualSystem.governance,\n outcome := fun _ mode => conflictDecision mode,\n objective := fun accepted => accepted = false,\n constraints := fun _ mode => consistencyPermission mode held context,\n starting := singleton (fun w => actualSystem.governance w = chosenMode),\n reasons := [fun _ _ => Consequence conflictingHeld context .correctOutput true ∧\n Consequence conflictingHeld context .correctOutput false],\n limits := fun w => w.1 = .identity,\n relevantCriticism := fun _ => ¬ Entails (emptyTheory : Theory Bool) (fun w => w = true),\n response := fun _ => some \"Consistency alone does not establish sufficient support; assess the claim with its grounds as well\" }\n | .reflexivity => {\n Position := Mode, Outcome := List Nat, adopted := chosenMode, selected := actualSystem.governance,\n outcome := fun _ mode => selfSamples mode,\n objective := fun samples => ∃ n ∈ samples, ownArithmeticPrinciple n = false,\n constraints := fun _ mode => Reflexive 0 (ownRules 0) (workFor 0 mode),\n starting := singleton (fun w => actualSystem.governance w = chosenMode),\n reasons := [fun _ _ => ownArithmeticPrinciple 0 = false ∧ ownArithmeticPrinciple 1 = true],\n limits := fun w => w.1 = .identity,\n relevantCriticism := fun _ => selfTest [1] = true ∧ ownArithmeticPrinciple 0 = false,\n response := fun _ => some \"A passing self-test does not certify the principle; retain the relevant counterexample and its scope\" }\n | .grounds => {\n Position := Mode, Outcome := Bool, adopted := chosenMode, selected := actualSystem.governance,\n outcome := fun _ mode => groundsDecision mode unsupportedCapabilityFacet,\n objective := fun accepted => accepted = false,\n constraints := fun _ mode => groundsPermission mode capability canonicalArticulation\n (fun f => f = capabilityFacet) [capabilityFacet],\n starting := singleton (fun w => actualSystem.governance w = chosenMode),\n reasons := [fun _ _ => Compatible [costAllowanceRecord] (.successor, .apply) ∧\n ¬ capability (.successor, .apply)],\n limits := fun w => w.1 = .identity,\n relevantCriticism := fun _ => OutputContract outputOnlyProcess ∧ ¬ ExplanationContract outputOnlyProcess,\n response := fun _ => some \"Grounds allows an external output assessment without requiring this process to provide an internal explanation\" }\n | .choice => {\n Position := Mode, Outcome := Bool, adopted := chosenMode, selected := actualSystem.governance,\n outcome := fun _ mode => choiceDecision mode cheapSuccessor [.method .simplicity],\n objective := fun accepted => accepted = false,\n constraints := fun _ mode => choicePermission mode identityRequirements identityImpl objectiveReason,\n starting := singleton (fun w => actualSystem.governance w = chosenMode),\n reasons := [fun _ _ => cheapSuccessor.run 0 = 1 ∧ identityRequirements.expected 0 = 0 ∧\n cheapSuccessor.cost ≤ identityRequirements.budget],\n limits := fun w => w.1 = .identity,\n relevantCriticism := fun _ => identityImpl.conventional = true ∧ identityImpl.established = true,\n response := fun _ => some \"An existing conventional method remains eligible when actual output and budget reasons justify it\" }\n\nnoncomputable def commitmentPosition (c : Commitment) : ValuePosition World := commitmentPositionFor c .apply\n\n/- The fact used as a reason has content before evaluating the adopted rule's consequence. -/\ntheorem positionReasons (c : Commitment) :\n ∀ r ∈ (commitmentPosition c).reasons, r actual (commitmentPosition c).adopted := by\n cases c <;> intro r hr <;> dsimp [commitmentPosition, commitmentPositionFor] at hr ⊢ <;>\n rcases List.mem_singleton.mp hr with rfl\n · exact ⟨rfl, rfl⟩\n · exact conflictConsequences\n · exact ⟨rfl, rfl⟩\n · refine ⟨costCompatibleWithFailure, ?_⟩\n intro h\n have bad := h 0 trivial\n cases bad\n · exact ⟨rfl, rfl, by decide⟩\n\n/- Each adopted rule has its stated consequence in this explicitly defined application; this is not ultimate value justification. -/\ntheorem positionConsequence (c : Commitment) (w : World) : (commitmentPosition c).consequence w := by\n cases c <;> dsimp [commitmentPosition, commitmentPositionFor, ValuePosition.consequence]\n · exact ⟨by decide, ⟨Or.inl rfl, fun _ _ => trivial⟩⟩\n · exact ⟨decisionsApply.1, jointConsistent⟩\n · exact ⟨⟨0, by simp [selfSamples], rfl⟩, completeOwnWork_reflexive 0⟩\n · exact ⟨decisionsApply.2.1, capabilityGrounds⟩\n · exact ⟨decisionsApply.2.2.2.1, identityJustified⟩\n\ntheorem positionProcedure (c : Commitment) : ValueProcedure (commitmentPosition c) := by\n refine ⟨?_, ?_, ?_, ?_⟩\n · cases c <;> simp [commitmentPosition, commitmentPositionFor]\n · refine ⟨actual, ?_, ?_, ?_, positionReasons c⟩\n · cases c <;> exact (modelsSingleton _ _).2 rfl\n · cases c <;> rfl\n · cases c <;> rfl\n · intro w _ _ _\n exact positionConsequence c w\n · intro w _ _\n cases c <;> exact ⟨_, rfl, by decide⟩\n\n/- Criticism is instantiated within the adopted position's actual limit rather than made vacuous. -/\ntheorem criticismWithinScope (c : Commitment) :\n (commitmentPosition c).limits actual ∧ (commitmentPosition c).relevantCriticism actual := by\n constructor\n · cases c <;> rfl\n · cases c\n · simp [commitmentPosition, commitmentPositionFor, Expanded, baseState, inflatedState]\n · exact consistentIncomplete.2.1\n · exact ⟨rfl, rfl⟩\n · exact ⟨outputNotExplanation.1, outputNotExplanation.2.1⟩\n · exact ⟨rfl, rfl⟩\n\n/- Waiving the rule changes the actual computed outcome or an explicit adopted constraint; old reasons cannot certify it unchanged. -/\ntheorem oppositeConsequenceFails (c : Commitment) (w : World) :\n ¬ (commitmentPositionFor c .waive).consequence w := by\n cases c <;> intro h\n · exact permissionNotValuation.2.2 h.2\n · have bad : conflictDecision .waive = false := h.1\n rw [decisionsWaive.1] at bad\n cases bad\n · obtain ⟨n, hn, hf⟩ := h.1\n change n ∈ [1] at hn\n have he : n = 1 := List.mem_singleton.mp hn\n subst n\n cases hf\n · have bad : groundsDecision .waive unsupportedCapabilityFacet = false := h.1\n rw [decisionsWaive.2.1] at bad\n cases bad\n · have bad : choiceDecision .waive cheapSuccessor [.method .simplicity] = false := h.1\n rw [decisionsWaive.2.2] at bad\n cases bad\n\ntheorem oppositeProcedureRejected (c : Commitment) : ¬ ValueProcedure (commitmentPositionFor c .waive) := by\n intro h\n obtain ⟨w, hs, hl, _, hr⟩ := h.2.1\n exact oppositeConsequenceFails c w (h.2.2.1 w hs hl hr)\n\n/- Each statement names adoption of a particular rule; its defined policy gives that option its meaning. -/\nnoncomputable def commitmentClaim (c : Commitment) : Claim World := (commitmentPosition c).commitment\n\nnoncomputable def commitmentFacet (c : Commitment) : Facet World := .value (commitmentPosition c)\n\ntheorem reasonsBelongToCommitments (c : Commitment) :\n Grounds (commitmentClaim c) canonicalArticulation\n (fun f => f = commitmentFacet c) [commitmentFacet c] ∧\n JointAdoption (commitmentPosition c) ∧\n (commitmentPosition c).relevantCriticism actual ∧\n ¬ ValueProcedure (commitmentPositionFor c .waive) := by\n exact ⟨canonicalGroundsForSingleton (commitmentFacet c) (positionProcedure c),\n (positionProcedure c).2.1, (criticismWithinScope c).2, oppositeProcedureRejected c⟩\n\n/- This claim concerns the Grounds rule for arbitrary claim/facet packages, not a single capability duty. -/\ntheorem groundsCommitmentIsProvision : commitmentClaim .grounds = (fun w => GroundsProvision w.2) := by\n funext w\n apply propext\n exact (groundsProvisionMeaning w.2).symm\n\ntheorem groundsSelfAssessment :\n Grounds (fun w => GroundsProvision w.2) canonicalArticulation\n (fun f => f = commitmentFacet .grounds) [commitmentFacet .grounds] ∧\n (commitmentPosition .grounds).limits actual ∧\n (commitmentPosition .grounds).relevantCriticism actual ∧\n ¬ ValueProcedure (commitmentPositionFor .grounds .waive) := by\n rw [← groundsCommitmentIsProvision]\n exact ⟨(reasonsBelongToCommitments .grounds).1,\n (criticismWithinScope .grounds).1, (criticismWithinScope .grounds).2,\n oppositeProcedureRejected .grounds⟩\n\n/- This existing principle form implements the same system's choice rule on two actual proposals.\nInput 0 names the identity proposal; input 1 names the cheap successor proposal. -/\nstructure PhilosophyMethod where\n form : Form\n mode : Mode\n\ndef currentPhilosophy (s : System) (w : World) : PhilosophyMethod :=\n ⟨s.principleForm, s.governance w⟩\n\nnoncomputable def PhilosophyMethod.review (p : PhilosophyMethod) (input : Nat) : Nat :=\n if input = 0 then\n if choiceDecision p.mode identityImpl objectiveReason then 1 else 0\n else if choiceDecision p.mode cheapSuccessor [.method .simplicity] then 1 else 0\n\nnoncomputable def PhilosophyMethod.implementation (p : PhilosophyMethod) : Implementation where\n name := \"Current philosophy's proposal review\"\n conventional := true\n established := true\n run := p.review\n cost := 1\n domain n := n = 0 ∨ n = 1\n explanation := p.review\n trace n := [n, p.review n]\n\ndef proposalRequirements : Requirements where\n inputs n := n = 0 ∨ n = 1\n expected n := if n = 0 then 1 else 0\n budget := 1\n values _ := True\n\ntheorem currentReviewCorrect : ∀ n, proposalRequirements.inputs n →\n (currentPhilosophy actualSystem actual).review n = proposalRequirements.expected n := by\n intro n hn\n rcases hn with rfl | rfl <;>\n simp [PhilosophyMethod.review, currentPhilosophy, actualSystem, actual,\n proposalRequirements, decisionsApply.2.2.2.1, decisionsApply.2.2.2.2]\n\n/- Status alone fails for this actual principle method; its demonstrated proposal decisions give a relevant reason. -/\ntheorem existingPhilosophyNotPrivileged :\n (currentPhilosophy actualSystem actual).form = actualSystem.principleForm ∧\n (currentPhilosophy actualSystem actual).mode = actualSystem.governance actual ∧\n ¬ JustifiedChoice proposalRequirements\n (currentPhilosophy actualSystem actual).implementation [.status .standing] ∧\n JustifiedChoice proposalRequirements\n (currentPhilosophy actualSystem actual).implementation [.method .output] ∧\n (currentPhilosophy actualSystem actual).review 0 = 1 ∧\n (currentPhilosophy actualSystem actual).review 1 = 0 := by\n refine ⟨rfl, rfl, statusOnlyFails _ _ _, ?_, currentReviewCorrect 0 (Or.inl rfl),\n currentReviewCorrect 1 (Or.inr rfl)⟩\n exact ⟨⟨currentReviewCorrect, by change 1 ≤ 1; decide⟩,\n .method .output, by simp, trivial, currentReviewCorrect⟩\n\n/- Applications choose their contract and requirements; the resulting claim is about this system's actual method. -/\ndef applicationClaim (s : System) (req : Requirements)\n (contract : Requirements → Implementation → Prop) : Claim World :=\n fun w => contract req (s.method.realize w)\n\ndef ApplicationDuties (s : System) (w : World) (req : Requirements)\n (contract : Requirements → Implementation → Prop)\n (articulations : Facet World → Articulation World)\n (applicable : Facet World → Prop) (facets : List (Facet World)) : Prop :=\n Reflexive s.owner (s.rules w) (s.work w) ∧\n Grounds (applicationClaim s req contract) articulations applicable facets\n\n/- These are consequences of an explicitly adopted duty, not a proof that arbitrary applications fulfill it. -/\ntheorem applicationRetainsDuties (s : System) (w : World) (req : Requirements)\n (contract : Requirements → Implementation → Prop)\n (articulations : Facet World → Articulation World)\n (applicable : Facet World → Prop) (facets : List (Facet World))\n (h : ApplicationDuties s w req contract articulations applicable facets) :\n Reflexive s.owner (s.rules w) (s.work w) ∧\n (∀ f, applicable f → f ∈ facets) ∧\n (∀ f ∈ facets, f.claim = applicationClaim s req contract ∧\n Articulated (articulations f) ∧ FacetArticulated (articulations f) f ∧ FacetDischarged f) :=\n ⟨h.1, h.2.2.1, h.2.2.2⟩\n\ndef outputContract (req : Requirements) (i : Implementation) : Prop :=\n ∀ n, req.inputs n → i.run n = req.expected n\n\ndef successorRequirements : Requirements :=\n { identityRequirements with expected := fun n => n + 1 }\n\n/- Holding the system and observation fixed while changing the actual objective changes the capability claim. -/\ndef changedObjectiveFacet : Facet World :=\n .empirical [observation] (fun _ => True)\n (applicationClaim actualSystem successorRequirements outputContract) (fun _ => True)\n\ntheorem applicationVariation :\n ApplicationDuties actualSystem actual identityRequirements outputContract\n canonicalArticulation (fun f => f = capabilityFacet) [capabilityFacet] ∧\n ¬ applicationClaim actualSystem successorRequirements outputContract actual ∧\n ¬ Grounds (applicationClaim actualSystem successorRequirements outputContract)\n canonicalArticulation (fun f => f = changedObjectiveFacet) [changedObjectiveFacet] := by\n refine ⟨⟨completeOwnWork_reflexive 0, capabilityGrounds⟩, ?_, ?_⟩\n · intro h\n have bad := h 0 trivial\n cases bad\n · intro h\n have discharged := (h.2.2 changedObjectiveFacet (by simp)).2.2.2\n have bad := discharged.2.1 actual ((observationIdentifies actual).2 rfl) trivial 0 trivial\n cases bad\n\n/- The very system satisfies the charter while its true cost evidence fails to establish its output capability. -/\ntheorem charterNotGrounds :\n Charter actualSystem actual ∧\n Compatible [costAllowanceRecord] actual ∧\n ¬ Grounds capability canonicalArticulation\n (fun f => f = unsupportedCapabilityFacet) [unsupportedCapabilityFacet] := by\n exact ⟨charterChecked, (by intro r hr; cases List.mem_singleton.mp hr; rfl), unsupportedGrounds⟩\n\n/- A single inhabited system/context carries the charter, its own actual claim and support,\ncontentful principle work, and separately reasoned governance commitments. -/\ntheorem jointWitness :\n ∃ s : System, ∃ w : World,\n Admissible (systemHeld s) (systemContext s) w ∧ Charter s w ∧\n OwnCapabilityDuty s w [capabilityFacet] ∧ systemCapability s w ∧\n JustifiedChoice s.requirements (s.method.realize w) objectiveReason ∧\n (∀ c : Commitment, Grounds (commitmentClaim c) canonicalArticulation\n (fun f => f = commitmentFacet c) [commitmentFacet c]) ∧\n s = actualSystem ∧ w = actual := by\n exact ⟨actualSystem, actual, actualAdmissible, charterChecked,\n ownCapabilityGrounded.1, capabilityActual, identityJustified,\n fun c => (reasonsBelongToCommitments c).1, rfl, rfl⟩\n\nend CoreReader.Integration\n```\n\n\n\n **L1** Imports CoreReader.Agency and its dependencies into this module.\n\n\n **L2** Imports CoreReader.Choice and its dependencies into this module.\n\n\n **L4** Opens namespace CoreReader.Integration; file boundaries do not change declaration identity.\n\n\n **L5** Makes the listed namespaces available for unqualified references.\n\n\n **L7** Documents the following definition or result: Builds Grounds from a nonempty list of discharged facets all targeting one claim, using canonical articulations and list membership itself as applicability.\n\n\n **L8** Builds Grounds from a nonempty list of discharged facets all targeting one claim, using canonical articulations and list membership itself as applicability.\n\n\n **L9** Assumes a nonempty facet list, with each facet targeting claim and already discharged.\n\n\n **L10** Builds Grounds using each facet's own constructed articulation and list membership as the applicability predicate.\n\n\n **L11** Supplies nonemptiness and tautological membership coverage, then checks each listed facet.\n\n\n **L12** For each facet, uses checked to establish the same claim and derive a nonempty articulation from its discharge.\n\n\n **L13** Adds that articulation's exact content correspondence and the supplied discharge proof.\n\n\n **L15** Builds Grounds for one discharged facet with applicability exactly equality to that facet.\n\n\n **L16** For a single discharged facet, makes exactly that facet applicable to its own claim.\n\n\n **L17** Proves the singleton is nonempty and every facet equal to f occurs in it; leaves per-facet content checks.\n\n\n **L18** Takes any facet g known to belong to the singleton list [f].\n\n\n **L19** Singleton membership turns hg into the equality g=f.\n\n\n **L20** Replaces g by the same discharged facet f.\n\n\n **L21** Uses identical claim, constructed articulability, exact facet-content match and checked discharge to finish its Grounds fields.\n\n\n **L23** Documents the following definition or result: Separates applying the modeled standards from waiving them; the two modes drive actual policy decisions.\n\n\n **L24** Separates applying the modeled standards from waiving them; the two modes drive actual policy decisions.\n\n\n **L25** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L27** Documents the following definition or result: A world pairs one of two candidate implementations with one of two governance modes; it is a closed four-world model.\n\n\n **L28** A world pairs one of two candidate implementations with one of two governance modes; it is a closed four-world model.\n\n\n **L30** Chooses identity implementation under applying governance as the concrete actual world.\n\n\n **L32** Documents the following definition or result: Binds a revisable form identity to a world-dependent implementation.\n\n\n **L33** Binds a method form kind/version to its world-dependent implementation; this structure alone does not prove the form is revisable.\n\n\n **L34** Stores the form kind and version of this method.\n\n\n **L35** Assigns an actual implementation to every candidate/governance world for this same method.\n\n\n **L37** Documents the following definition or result: Binds owner, method, principle form, governance selection and application requirements.\n\n\n **L38** Binds owner, method, principle form, governance selection and application requirements.\n\n\n **L39** Identifies the owner whose principles and work are used for this system.\n\n\n **L40** Stores the system's method form together with its world-dependent implementation.\n\n\n **L41** Stores the current form of the system's own principle.\n\n\n **L42** Selects whether this system applies or waives governance in each world.\n\n\n **L43** Fixes the actual input, output, budget and value requirements used to assess this system's implementation.\n\n\n **L45** Applying governance selects the open policy; waiving selects the policy without expansion valuation.\n\n\n **L46** Applying governance selects openPolicy, which values expansion and permits revision.\n\n\n **L47** Waiving governance selects neutralPolicy, which lacks the required expansion valuation.\n\n\n **L49** Applying governance supplies content-checked own-work records; waiving supplies none.\n\n\n **L50** Applying governance gives this owner the complete contentful work log.\n\n\n **L51** Waiving governance gives the same owner an empty work log.\n\n\n **L53** Uses this same system's governance choice to select its policy.\n\n\n **L54** Uses the registered generation/assessment rules for this system's owner.\n\n\n **L55** Uses this owner's governance mode to select the actual work-record list.\n\n\n **L57** Constructs owner zero with version-zero method/principle forms, candidate-dependent implementation, world-selected governance and identity requirements.\n\n\n **L58** Assigns owner zero to the shared actual system.\n\n\n **L59** Uses a version-zero method form whose realization is selected by the world's candidate component.\n\n\n **L60** Sets this system's current principle form to principle version zero.\n\n\n **L61** Reads governance from the world's second component, independently of the implementation candidate.\n\n\n **L62** Assesses the same method against identityRequirements.\n\n\n **L64** For this system's requested inputs, requires its realized method to match its own expected output.\n\n\n **L65** Claims that this system's realized method meets its specified output on every required input.\n\n\n **L67** Checks the same realized implementation's cost against the system's budget.\n\n\n **L68** Claims that the same realized method's cost fits this system's own budget.\n\n\n **L70** Records whether the system's actual implementation meets its expected output at input zero.\n\n\n **L71** Records true for the test that this same method's output at zero equals its required output there.\n\n\n **L73** Holds this same system's capability and budget claims together.\n\n\n **L74** The system simultaneously holds its actual output-capability claim and its budget claim.\n\n\n **L76** Defines the output-correctness and affordability questions used by the context.\n\n\n **L77** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L79** Uses the same system's observation as assumption and its capability/budget as meanings; scope requires domain membership at zero and applying governance.\n\n\n **L80** The context assumes compatibility with this system's actual zero-input observation.\n\n\n **L81** Interprets correctOutput as this system's capability and affordable as its budget compliance.\n\n\n **L82** Restricts admissible scope to implementations whose domain includes zero and worlds with governance applied.\n\n\n **L84** Abbreviates the actual system's parameterized output capability claim.\n\n\n **L85** Abbreviates the actual system's input-zero observation record.\n\n\n **L86** Abbreviates the actual system's simultaneously held capability/budget theory.\n\n\n **L87** Abbreviates the actual system's question/assumption/scope context.\n\n\n **L89** Documents the following definition or result: Computes that the zero observation identifies the identity candidate while leaving governance mode unconstrained.\n\n\n **L90** Computes that the zero observation identifies the identity candidate while leaving governance mode unconstrained.\n\n\n **L91** Separates the candidate algorithm from the independently varied governance mode.\n\n\n **L92** Checks each of the two actual candidates against the observation's true zero-output test.\n\n\n **L93** Identity returns required zero while successor returns one, so only identity matches, regardless of governance.\n\n\n **L95** Proves the actual identity implementation meets every requested identity output by reduction.\n\n\n **L97** Uses candidate identification and known identity behavior to obtain universal requested-input capability within the closed model.\n\n\n **L98** Takes an arbitrary world compatible with the same observation.\n\n\n **L99** Uses observationIdentifies to infer that this world's algorithm candidate is identity.\n\n\n **L100** Separates the world's algorithm and governance components for substitution.\n\n\n **L101** Restates the inferred identity equality directly on the candidate variable.\n\n\n **L102** Replaces the candidate algorithm with identity while retaining its governance mode.\n\n\n **L103** Identity's run equals the required output at every input by definition, proving capability in this world.\n\n\n **L105** Packages the actual observation and capability claim in an empirical facet with unrestricted scope and trivial uncertainty.\n\n\n **L107** Supplies an actual compatible witness, the closed-model support proof and trivial uncertainty.\n\n\n **L108** Supplies actual as a compatible world in the facet's unrestricted scope, avoiding an empty-world discharge.\n\n\n **L109** Uses observedCapability for support in every compatible world; the stated uncertainty condition is trivial.\n\n\n **L111** Builds canonical Grounds for this exact capability facet.\n\n\n **L112** Makes only the actual output capability facet applicable, with its own singleton evidence package.\n\n\n **L113** Applies the singleton Grounds constructor to the already discharged capability facet.\n\n\n **L115** Proves actual identity/apply jointly satisfies capability, budget, observation assumptions and governance/domain scope.\n\n\n **L116** Builds an admissible actual-world witness, first proving both jointly held claims; capability uses capabilityActual.\n\n\n **L117** The held budget claim computes to actual cost 1 within budget 1.\n\n\n **L118** Adds compatibility with the zero observation, domain membership at zero, and actual's apply mode.\n\n\n **L120** Derives consistency from the explicitly established actual admissible world.\n\n\n **L121** Applies semantic consequence consistency using actual and its admissibility proof as the required nonempty witness.\n\n\n **L123** Documents the following definition or result: Conjoins this system's generation policy, contextual consistency, full content-valid reflexivity and current method/principle form membership.\n\n\n **L124** Conjoins this system's generation policy, contextual consistency, full content-valid reflexivity and current method/principle form membership.\n\n\n **L125** The Charter requires this system's actual policy to be Generative and its jointly held judgments contextually consistent.\n\n\n **L126** It also requires full owned-rule reflexivity for this system's actual work log.\n\n\n **L127** Both the method form and principle form must be current under that same policy.\n\n\n **L129** Combines evaluated open-policy facts, actual consistency and the content-validated own-work model.\n\n\n **L130** Combines openPolicy's valuation/revisability, jointConsistent, the complete owned log and both version-zero current forms.\n\n\n **L132** Documents the following definition or result: Adds the system's zero-input output fact to its existing held theory.\n\n\n **L133** Adds the system's zero-input output fact to its existing held theory.\n\n\n **L134** Adds the specific assertion that this same method meets its required output at input zero.\n\n\n **L136** Stores the actual held theory/context with revision identity zero.\n\n\n **L137** Stores the extended held theory with the same context and revision identity one.\n\n\n **L139** Keeps the same charter and an admissible model after the added fact, then accepts true and rejects false revision reporting.\n\n\n **L140** The actual system retains its Charter, and adding that supported assertion leaves revisedHeld consistent.\n\n\n **L141** Reporting the identified revision as true satisfies the one-way change-report condition.\n\n\n **L142** Reporting that same revision as false violates the condition.\n\n\n **L143** Keeps charterChecked and proves revised consistency with actual as a concrete admissible witness.\n\n\n **L144** Actual satisfies old held claims plus the newly added zero-input output assertion.\n\n\n **L145** Retains actual's existing context/scope proof and verifies a true report; only rejection of a false report remains.\n\n\n **L146** Assumes the changed snapshots could satisfy TruthfulReport with report=false.\n\n\n **L147** The revision identifiers 0 and 1 differ, so that assumed obligation forces false=true.\n\n\n **L148** Eliminates that impossible Boolean equality, rejecting the concealed revision.\n\n\n **L150** Documents the following definition or result: Requires this system's assessment record and matching Grounds for its own capability claim.\n\n\n **L151** Requires this system's assessment record and matching Grounds for its own capability claim.\n\n\n **L152** OwnCapabilityDuty first requires an actual assessment record targeting this system's owner-identical system subject.\n\n\n **L153** It also requires same-claim Grounds for this system's output capability over all listed applicable facets.\n\n\n **L155** Combines the actual content-validated self-assessment record with observation-supported capability Grounds and capability truth.\n\n\n **L156** States that the actual system's own capability duty is fulfilled and its claimed capability actually holds.\n\n\n **L157** Supplies capabilityActual immediately, leaving the system-assessment record and corresponding Grounds.\n\n\n **L158** Uses the complete log's assessment of system zero as the owned-system work witness.\n\n\n **L159** Builds Grounds from the nonempty singleton capability-facet list.\n\n\n **L160** The singleton's only facet has exactly the target claim and the already proved discharge.\n\n\n **L162** Documents the following definition or result: Records cost at most two for the same system implementation; both candidates pass.\n\n\n **L163** Records cost at most two for the same system implementation; both candidates pass.\n\n\n **L164** Records that implementation cost is at most two; both algorithm candidates satisfy this weaker cost observation.\n\n\n **L166** Attempts to support the same output capability from only the permissive cost observation.\n\n\n **L167** Attempts to support output capability using only cost evidence, with no restrictive scope or uncertainty condition.\n\n\n **L169** Computes that successor/apply satisfies the cost observation despite failing identity output.\n\n\n **L170** Takes a record belonging to the singleton cost-observation list.\n\n\n **L171** Singleton membership identifies that record as costAllowanceRecord.\n\n\n **L172** Substitutes the actual cost record for r.\n\n\n **L173** Successor costs two, so the recorded at-most-two observation evaluates true.\n\n\n **L175** Applies alleged support to the compatible successor counterworld and input zero to derive contradiction.\n\n\n **L176** Assumes the cost observation supports output capability in every compatible world.\n\n\n **L177** Applies that assumption to the compatible successor world and input zero, obtaining the false equation 1=0.\n\n\n **L178** Eliminates the impossible output equality, refuting cost-only support.\n\n\n **L180** Extracts the bad facet's support obligation from alleged Grounds and contradicts the cost countermodel.\n\n\n **L181** Tests the singleton package that makes this cost-only capability facet applicable.\n\n\n **L182** Assumes that inadequate singleton package nonetheless satisfies Grounds.\n\n\n **L183** Extracts FacetDischarged for its actual cost-only capability facet from the Grounds premise.\n\n\n **L184** Its support clause would yield cost-only Supports, contradicting costDoesNotSupportOutput.\n\n\n **L186** Documents the following definition or result: Indexes five individual governance commitments, each with separately interpreted reasons and outcomes.\n\n\n **L187** Indexes five individual governance commitments, each with separately interpreted reasons and outcomes.\n\n\n **L188** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L190** Documents the following definition or result: Applying mode permits a claim bundle only when Grounds holds; waiving mode permits every bundle.\n\n\n **L191** Applying mode permits a claim bundle only when Grounds holds; waiving mode permits every bundle.\n\n\n **L192** Accepts an arbitrary applicability predicate and supplied facet package for the same claim/articulations.\n\n\n **L193** Chooses the permission rule according to the governance mode.\n\n\n **L194** Apply mode permits a package only when it actually satisfies Grounds.\n\n\n **L195** Waive mode permits every package without checking Grounds.\n\n\n **L197** States the general requirement that every permitted claim bundle has Grounds, across all claims, articulations, applicable facets and lists.\n\n\n **L198** For every actual claim, articulation family and facet package, provision applies to any package the mode permits.\n\n\n **L199** Every permitted package must satisfy its own corresponding Grounds duties.\n\n\n **L201** Proves applying mode enforces the general provision, while the concrete unsupported cost bundle refutes waiving mode.\n\n\n **L202** Checks the general provision separately for apply and waive modes.\n\n\n **L203** In apply mode permission already is Grounds, so the general provision passes by returning the supplied proof.\n\n\n **L204** For waive mode, the proof must show that unrestricted permission violates the general provision.\n\n\n **L205** Proves both directions of the impossible waive-mode equivalence.\n\n\n **L206** Assumes the general provision holds even though this mode waives checks.\n\n\n **L207** Applies that universal assumption to the actual unsupported capability package, which would contradict unsupportedGrounds.\n\n\n **L208** Supplies its exact singleton applicability and package; waive permission is true, forcing the invalid Grounds result.\n\n\n **L209** The reverse implication starts from waive=apply, an impossible constructor equality.\n\n\n **L211** Documents the following definition or result: Applying mode requires consistency for a proposed theory/context; waiving mode permits it unconditionally.\n\n\n **L212** Applying mode requires consistency for a proposed theory/context; waiving mode permits it unconditionally.\n\n\n **L213** Apply requires whole-theory consistency in context; waive imposes no such constraint.\n\n\n **L215** Combines the actual capability claim with its negation in one theory.\n\n\n **L217** Extracts both signed capability consequences from the simultaneously held contradictory claims.\n\n\n **L218** The conflicting held theory entails positive output correctness under the fixed context.\n\n\n **L219** The same theory and context also entail its negative judgment.\n\n\n **L220** An admissible world's model of conflictingHeld must satisfy its explicitly included capability claim.\n\n\n **L221** That same model must also satisfy the explicitly included negation of capability.\n\n\n **L223** Uses those same-context opposite consequences to refute consistency.\n\n\n **L224** Uses the two opposite same-context consequences to refute consistency of the conflicting held theory.\n\n\n **L226** Documents the following definition or result: Applying governance uses the separate feasible relevant-choice norm; waiving governance accepts every proposed reason list.\n\n\n **L227** Applying governance uses the separate feasible relevant-choice norm; waiving governance accepts every proposed reason list.\n\n\n **L228** Apply enforces actual feasibility and reason relevance through JustifiedChoice; waive allows any selection package.\n\n\n **L230** Documents the following definition or result: Applying mode proposes successor, while waiving proposes the unchanged copy operation.\n\n\n **L231** Applying mode proposes successor, while waiving proposes the unchanged copy operation.\n\n\n **L232** Applying the generation rule proposes successor, whose output can differ from copy.\n\n\n **L233** Waiving that rule proposes the unchanged copy operation.\n\n\n **L235** Applying mode tests zero and one; waiving mode tests only the passing sample one.\n\n\n **L236** Applying reflexive assessment checks both zero and one, including the arithmetic counterexample.\n\n\n **L237** Waiving it checks only one, the sample where the arithmetic principle passes.\n\n\n **L239** Classically decides the consistency-permission proposition for the concrete conflicting theory; it is noncomputable, not a deployed checker.\n\n\n **L240** Uses classical propositional decision to turn the whole conflicting-theory permission into a Boolean; no executable decision algorithm is supplied.\n\n\n **L242** Classically decides whether the chosen mode permits the given exact singleton facet bundle.\n\n\n **L243** Decides permission for this facet's own claim and its exact singleton assessment package.\n\n\n **L244** Supplies classical decidability for that potentially noncomputable Grounds proposition.\n\n\n **L246** Classically decides permission for the specified implementation/reasons under identity requirements.\n\n\n **L247** Classically decides this implementation's permission under fixed identity requirements and its supplied reasons.\n\n\n **L249** Proves applying mode rejects contradiction, unsupported capability and infeasible cheap successor while accepting actual capability and identity choice.\n\n\n **L250** Applying Grounds rejects the cost-only capability package.\n\n\n **L251** Applying Grounds accepts the properly supported output-observation package.\n\n\n **L252** Applying choice rejects cheapSuccessor despite its relevant simplicity reason, because its output is infeasible.\n\n\n **L253** Applying choice accepts identity with its actual output reason.\n\n\n **L254** Enables the classical decidability instances used in these Boolean permission definitions.\n\n\n **L255** Unfolds the three Boolean decisions and their apply-mode consistency predicate.\n\n\n **L256** Also unfolds Grounds and choice permission, exposing the actual propositions each Boolean decides.\n\n\n **L257** The proved inconsistency forces conflictDecision apply to false.\n\n\n **L258** The failed cost package decides false, while the discharged observation package decides true.\n\n\n **L259** The infeasible cheap method decides false; the feasible justified identity decides true.\n\n\n **L261** Computes that waiving mode accepts the concrete contradiction, unsupported facet and infeasible choice.\n\n\n **L262** Waive mode accepts even the unsupported cost-only capability package.\n\n\n **L263** It also accepts cheapSuccessor with simplicity alone despite the wrong output.\n\n\n **L264** Starts the waiver calculation with consistencyPermission, which is definitionally True in this mode.\n\n\n **L265** Uses that trivial permission proof to obtain the true Boolean conflict decision.\n\n\n **L266** Next decides waiver permission for the exact unsupported capability facet's claim.\n\n\n **L267** Its singleton applicability/package is unchanged; waiver makes permission True and the decision true.\n\n\n **L268** Finally decides waiver permission for the same cheap method and simplicity-only reasons.\n\n\n **L269** That permission is again trivially True, completing all three waiver decisions.\n\n\n **L271** Documents the following definition or result: For each commitment, interprets governance modes as options with its own operational outcome, objective, constraint, actual reasons and scoped criticism response.\n\n\n **L272** For each commitment, interprets governance modes as options with its own operational outcome, objective, constraint, actual reasons and scoped criticism response.\n\n\n **L273** Chooses a different operational value-position adapter for each of the five commitments.\n\n\n **L274** Constructs the value position for the generation commitment.\n\n\n **L275** Its positions are governance modes, outcomes are operations, and adoption is compared with this same system's selected governance.\n\n\n **L276** Maps a mode to the actual proposed successor-or-copy operation.\n\n\n **L277** The adopted generation objective requires output at zero to differ from copy's zero output.\n\n\n **L278** Also requires the mode's actual policy to satisfy the adopted Generative constraints.\n\n\n **L279** Explicitly assumes the same system has selected chosenMode; this is a starting commitment, not a derived universal fact.\n\n\n **L280** Its option-dependent reason compares the proposed operation's 0→1 behavior with copy's 0→0 behavior.\n\n\n **L281** Limits this generation position to worlds whose implementation candidate is identity.\n\n\n **L282** Keeps actual inventory inflation without expansion as a relevant criticism of the generation commitment.\n\n\n **L283** Responds that orientation does not guarantee progress and before/after capabilities need separate assessment; the stored response is nonempty text.\n\n\n **L284** Constructs the distinct value position for the consistency commitment.\n\n\n **L285** Uses modes as positions and a Boolean conflict-admission decision as outcome, tied to the same selected governance.\n\n\n **L286** Its actual outcome is the mode's decision on the whole conflicting theory.\n\n\n **L287** Requires that decision to reject the conflicting theory.\n\n\n **L288** Simultaneously requires the actual held theory and context to pass the same mode's consistency permission.\n\n\n **L289** States adoption of chosenMode by the same system as this position's explicit starting assumption.\n\n\n **L290** The consistency reason begins with the conflicting theory's positive output-correctness consequence.\n\n\n **L291** It also includes the opposite consequence under exactly the same question and context.\n\n\n **L292** Limits this consistency position to identity-candidate worlds.\n\n\n **L293** Uses the empty Bool theory's failure to entail truth at every world as the live incompleteness criticism.\n\n\n **L294** Responds that consistency alone does not establish sufficient support and the claim's grounds still need assessment.\n\n\n **L295** Constructs the value position for reflexive assessment.\n\n\n **L296** Uses modes as positions and an actual sample-input list as outcome, tied to the same selected governance.\n\n\n **L297** The mode chooses the sample set [0,1] or [1].\n\n\n **L298** Requires some actually selected sample to expose a false result of the same arithmetic principle.\n\n\n **L299** Also requires full owner-zero rule/work reflexivity for that same mode.\n\n\n **L300** Explicitly adopts chosenMode for this same system as the starting commitment.\n\n\n **L301** The reason identifies actual arithmetic failure at zero and success at one.\n\n\n **L302** Restricts this reflexivity position to identity-candidate worlds.\n\n\n **L303** Retains the passing test at one together with the actual failure at zero as criticism.\n\n\n **L304** Responds that passing a self-test does not certify the principle and the counterexample's scope must be retained.\n\n\n **L305** Constructs the value position for the Grounds provision itself.\n\n\n **L306** Uses modes as positions and a Boolean evidence-package decision as outcome, under the same system's governance.\n\n\n **L307** The actual outcome tests the unsupported cost-only capability facet.\n\n\n **L308** Requires rejection of that unsupported evidence package.\n\n\n **L309** Also requires permission for the actual capability claim with its content-derived articulations.\n\n\n **L310** That positive constraint uses exactly the properly discharged singleton capabilityFacet package.\n\n\n **L311** States this same system's adoption of chosenMode as an explicit starting commitment.\n\n\n **L312** The Grounds reason records that the successor/apply world is compatible with the cost observation.\n\n\n **L313** It pairs that compatibility with actual failure of the claimed output capability in that same world.\n\n\n **L314** Restricts this Grounds position to identity-candidate worlds.\n\n\n **L315** The criticism points to the same process having the output contract without an attached explanation contract.\n\n\n **L316** Responds that external output assessment can supply Grounds without requiring this process to explain its internal generation.\n\n\n **L317** Constructs the separate value position for implementation choice.\n\n\n **L318** Uses modes as positions and a Boolean method-admission decision as outcome, under the same governance selection.\n\n\n **L319** The tested choice is the cheap successor justified only by its simplicity reason.\n\n\n **L320** Requires rejection of that wrong-output choice.\n\n\n **L321** Also requires acceptance of identity under the same requirements with its actual output reason.\n\n\n **L322** Explicitly adopts chosenMode for this system; the value starting point is not proved from neutral facts.\n\n\n **L323** The choice reason contrasts cheapSuccessor's output one with the required output zero on the same input.\n\n\n **L324** Also records that the method fits the budget, so cheapness cannot conceal its output failure.\n\n\n **L325** Limits this choice position to identity-candidate worlds.\n\n\n **L326** Keeps identity's actual conventional and established status as a relevant criticism of excluding existing methods.\n\n\n **L327** Responds that a conventional existing method remains eligible when actual output and budget reasons justify it.\n\n\n **L329** Specializes each individually interpreted position to adopting applying governance.\n\n\n **L331** Documents the following definition or result: Checks every listed commitment-specific reason at the same actual world and adopted mode by concrete counterexamples or computation.\n\n\n **L332** Checks every listed commitment-specific reason at the same actual world and adopted mode by concrete counterexamples or computation.\n\n\n **L333** Every actual listed reason for commitment c must hold at actual for its adopted apply option.\n\n\n **L334** Separates the five commitments and unfolds each actual reason list while fixing a listed reason r.\n\n\n **L335** Each list is a singleton, so the membership premise identifies r with that commitment's concrete reason.\n\n\n **L336** Generation's reason computes successor 0=1 and copy 0=0.\n\n\n **L337** Consistency's reason uses the already proved positive and negative consequences of the same conflicting theory.\n\n\n **L338** Reflexivity's reason computes failure at zero and success at one for the same arithmetic principle.\n\n\n **L339** For Grounds, supplies the successor world's cost compatibility and leaves its capability failure to prove.\n\n\n **L340** Assumes that same successor world nevertheless has the required output capability.\n\n\n **L341** At required input zero, that assumption yields successor's output one equal to required zero.\n\n\n **L342** Eliminates the impossible 1=0 equality, proving the capability failure part of the reason.\n\n\n **L343** Choice's reason computes output one, required zero and the cheap method's within-budget cost.\n\n\n **L345** Documents the following definition or result: Proves each adopted mode has its stated objective and constraint using actual decision and compliance theorems, without asserting ultimate normative validity.\n\n\n **L346** Proves each adopted mode has its stated objective and constraint using actual decision and compliance theorems, without asserting ultimate normative validity.\n\n\n **L347** Unfolds each commitment's consequence into its actual objective and mode-dependent constraint.\n\n\n **L348** Generation's apply option differs from copy at zero and its openPolicy satisfies valuation plus revisability.\n\n\n **L349** Consistency's apply option rejects the conflicting theory while the actual held theory remains consistent.\n\n\n **L350** Reflexivity chooses the actual counterexample zero from [0,1] and supplies full contentful owned-work reflexivity.\n\n\n **L351** Grounds rejects the unsupported cost package while the proper capability package has Grounds.\n\n\n **L352** Choice rejects cheapSuccessor and retains the justified feasible identity implementation.\n\n\n **L354** Builds nonempty reason lists, joint adoption, checked option consequences and nonempty responses for every commitment; reason assumptions are not needed by the already proved consequences.\n\n\n **L355** Splits ValueProcedure into nonempty reasons, joint adoption, the scoped consequence rule and criticism response.\n\n\n **L356** Checks that every commitment's actual reason list contains its singleton reason.\n\n\n **L357** Uses the same actual world for JointAdoption and supplies positionReasons c; remaining goals are starting-theory membership, limits and adoption.\n\n\n **L358** In actual, governance is apply, so the singleton starting theory selecting the adopted mode holds.\n\n\n **L359** For each commitment, actual's identity candidate satisfies its declared limit.\n\n\n **L360** For each commitment, actual's selected governance equals the adopted apply option.\n\n\n **L361** Takes an arbitrary world and the procedure's starting, limit and all-reasons premises for its consequence clause.\n\n\n **L362** Uses positionConsequence, which already proves that apply option's objective and constraints for every world; these premises are not needed here.\n\n\n **L363** For the response clause, takes a world with an in-scope relevant criticism.\n\n\n **L364** Every commitment returns its actual stored nonempty response string, satisfying the response-existence requirement.\n\n\n **L366** Documents the following definition or result: Provides an actual in-scope criticism case for each commitment, avoiding vacuous response obligations in these examples.\n\n\n **L367** Provides an actual in-scope criticism case for each commitment, avoiding vacuous response obligations in these examples.\n\n\n **L368** Requires both that actual is inside this commitment's limits and that its specific criticism really applies there.\n\n\n **L369** Separates the actual-limit check from the actual-criticism check.\n\n\n **L370** Every limit asks for identity, which is actual's candidate by definition.\n\n\n **L371** Checks each commitment's distinct criticism rather than assuming criticism vacuously.\n\n\n **L372** Generation's criticism holds because inflating baseline lists creates no newly understood or constructed operation.\n\n\n **L373** Consistency's criticism uses the empty theory's proved failure to entail the selected Bool claim.\n\n\n **L374** Reflexivity's criticism computes a passing sample at one and failure at zero.\n\n\n **L375** Grounds' criticism combines actual output correctness of outputOnlyProcess with its absent explanation contract.\n\n\n **L376** Choice's criticism holds because identity is actually conventional and established.\n\n\n **L378** Documents the following definition or result: Shows the waiving option fails each unchanged commitment-specific objective or constraint.\n\n\n **L379** Shows the waiving option fails each unchanged commitment-specific objective or constraint.\n\n\n **L380** Claims that every commitment's waive option fails its declared objective or constraint in any world.\n\n\n **L381** Separates the commitments and assumes the corresponding waive consequence, seeking a contradiction.\n\n\n **L382** Generation's consequence would require Generative neutralPolicy, contradicting permissionNotValuation's proved failure.\n\n\n **L383** Consistency's assumed objective says waive must reject the conflicting theory.\n\n\n **L384** But decisionsWaive computes acceptance=true, turning that objective into true=false.\n\n\n **L385** Rejects that impossible Boolean equality for the consistency option.\n\n\n **L386** Reflexivity's assumed objective supplies a selected sample n where the arithmetic principle is false.\n\n\n **L387** Waive mode's selected samples are exactly [1].\n\n\n **L388** Membership in that singleton forces the supposed failing input n to be one.\n\n\n **L389** Replaces n with one in the alleged failure proof.\n\n\n **L390** The principle actually returns true at one, contradicting its alleged false result.\n\n\n **L391** Grounds' assumed objective says waive rejects the specific unsupported capability package.\n\n\n **L392** decisionsWaive instead says that same package is accepted, yielding true=false.\n\n\n **L393** Rejects the impossible equality, so the waived Grounds consequence fails.\n\n\n **L394** Choice's assumed objective says waive rejects cheapSuccessor with simplicity alone.\n\n\n **L395** decisionsWaive proves that exact selection is accepted, again yielding true=false.\n\n\n **L396** Rejects that equality, completing failure of all five waive consequences.\n\n\n **L398** Combines a hypothetical joint-adoption witness with consequence failure to reject the opposite mode's procedure.\n\n\n **L399** Assumes the opposite waive value position nevertheless satisfies ValueProcedure.\n\n\n **L400** Extracts its JointAdoption witness w, starting-theory proof hs, limit proof hl and all-reasons proof hr.\n\n\n **L401** The assumed procedure's consequence clause applied to that same joint witness produces the waive consequence, which oppositeConsequenceFails c w refutes.\n\n\n **L403** Documents the following definition or result: Extracts each position's adoption claim; all use the same governance selector but have separately assessed consequences and reasons.\n\n\n **L404** Extracts each position's adoption claim; all use the same governance selector but have separately assessed consequences and reasons.\n\n\n **L406** Wraps the specific interpreted commitment position as a value facet.\n\n\n **L408** Provides per-commitment Grounds, a real joint adoption, actual relevant criticism and rejection of the opposite policy under the same interpreted objective.\n\n\n **L409** Requires Grounds for the actual adoption claim of commitment c, with articulation built from its facet contents.\n\n\n **L410** Makes exactly commitmentFacet c applicable and supplies only that same facet.\n\n\n **L411** Additionally requires a nonempty jointly admissible adoption witness for that position.\n\n\n **L412** Requires this particular commitment's criticism to actually hold at actual.\n\n\n **L413** Also proves the opposite waive position fails the same value-procedure requirements.\n\n\n **L414** Constructs singleton Grounds using that commitment's checked positionProcedure.\n\n\n **L415** Adds its joint witness, actual criticism and the proved rejection of its opposite position.\n\n\n **L417** Documents the following definition or result: Proves the grounds position's adoption claim is extensionally the general Grounds provision for the selected governance mode.\n\n\n **L418** Proves the grounds position's adoption claim is extensionally the general Grounds provision for the selected governance mode.\n\n\n **L419** To equate the two claims, fixes an arbitrary world w and compares their propositions there.\n\n\n **L420** Uses proposition extensionality: equivalence of the two propositions suffices for their equality.\n\n\n **L421** groundsProvisionMeaning says the general provision holds exactly in apply mode, matching this adoption claim in reverse direction.\n\n\n **L423** Applies value Grounds to the general Grounds provision itself, retaining actual scope/criticism and a rejected waiver variant.\n\n\n **L424** Assesses the general GroundsProvision itself, quantified over claim/facet packages, with content-derived articulation.\n\n\n **L425** The applicable value aspect is exactly the grounds commitment's own facet.\n\n\n **L426** Requires actual to satisfy that commitment's declared limit.\n\n\n **L427** Requires its criticism to actually apply at actual as well.\n\n\n **L428** Requires the opposite waived Grounds commitment to fail ValueProcedure.\n\n\n **L429** Rewrites the general provision as the extensionally identical grounds adoption claim.\n\n\n **L430** Reuses the actual Grounds proof for that same grounds commitment.\n\n\n **L431** Supplies the separately checked actual limit and actual relevant criticism.\n\n\n **L432** Supplies the proved failure of the opposite waived Grounds position.\n\n\n **L434** Documents the following definition or result: Stores the current philosophical principle form and its actual governance mode.\n\n\n **L435** Documents the following definition or result: Stores the current philosophical principle form and its actual governance mode.\n\n\n **L436** Stores the current philosophical principle form and its actual governance mode.\n\n\n **L437** Stores the actual principle form this philosophy method implements.\n\n\n **L438** Stores whether this same philosophy method applies or waives its governance checks.\n\n\n **L440** Derives the reviewed philosophy object from this same system's principle form and governance selection.\n\n\n **L441** Builds the philosophy method from this system's own principle form and its governance in w.\n\n\n **L443** Returns approval decisions for the identity proposal at zero and the cheap infeasible proposal otherwise, using this philosophy's actual governance mode.\n\n\n **L444** Input zero identifies the identity-method proposal; every other input follows the cheap-successor proposal branch.\n\n\n **L445** For identity, runs this philosophy method's actual choice policy and returns 1 for accept, 0 for reject.\n\n\n **L446** For other inputs, applies the same policy to cheapSuccessor with simplicity alone, again encoding accept/reject as 1/0.\n\n\n **L448** Exposes that actual philosophical review procedure as an implementation with domain zero/one and matching output/trace proxies.\n\n\n **L449** Names the implementation as the current philosophy's actual proposal-review method.\n\n\n **L450** Marks this proposal-review implementation as conventional.\n\n\n **L451** Also marks the same implementation as established; later proof tests whether that alone justifies priority.\n\n\n **L452** The implementation's actual run is precisely this philosophy method's review function.\n\n\n **L453** Assigns cost one to this review implementation.\n\n\n **L454** Declares only proposal identifiers zero and one within its application domain.\n\n\n **L455** Provides the same review function as the implementation's explanation field.\n\n\n **L456** Records a two-entry trace containing the proposal identifier and its actual review result.\n\n\n **L458** Requires accepting proposal zero and rejecting proposal one within budget one.\n\n\n **L459** The application tests exactly proposal identifiers zero and one.\n\n\n **L460** Requires identity's proposal zero to be accepted as 1 and the other tested proposal to be rejected as 0.\n\n\n **L461** Allows this review method a cost budget of one.\n\n\n **L462** Imposes no additional restriction through the requirements' values predicate in this example.\n\n\n **L464** Computes both requested proposal decisions from applying-governance results.\n\n\n **L465** For each required proposal, the actual system's current philosophy review must equal the application's expected verdict.\n\n\n **L466** Takes a proposal n with proof hn that it is one of the required inputs.\n\n\n **L467** Uses hn to restrict n to the concrete identity or cheap-successor proposal identifier.\n\n\n **L468** Unfolds the same current philosophy method and actual system to expose the real proposal decisions.\n\n\n **L469** Uses decisionsApply to match accepted identity and rejected cheap successor against their required verdicts.\n\n\n **L471** Documents the following definition or result: Binds the implementation to the current principle/governance object, rejects status-only priority and justifies it by its two actual proposal decisions.\n\n\n **L472** Binds the implementation to the current principle/governance object, rejects status-only priority and justifies it by its two actual proposal decisions.\n\n\n **L473** Checks this philosophy method's form is exactly the actual system's current principle form.\n\n\n **L474** Checks its governance mode is exactly the same system's mode at actual.\n\n\n **L475** Begins the claim that status alone cannot justify choosing this actual review implementation.\n\n\n **L476** The rejected reason list is exactly [.status .standing] for that same philosophy implementation.\n\n\n **L477** By contrast, asserts this implementation has a justified choice under the actual proposal requirements.\n\n\n **L478** That positive choice uses its actual output reason, not merely its name or established flag.\n\n\n **L479** The same philosophy review actually accepts identity's proposal zero with result one.\n\n\n **L480** It actually rejects cheap successor's proposal one with result zero.\n\n\n **L481** Provides same-form/mode identities, status-only rejection and correct proposal-zero evaluation; leaves positive output-based choice to prove.\n\n\n **L482** Also supplies currentReviewCorrect for required proposal one, proving its actual rejection.\n\n\n **L483** Builds the positive choice's feasibility from both correct proposal outputs and cost 1≤budget 1.\n\n\n **L484** Uses the listed .method .output reason and currentReviewCorrect as its actual relevance witness.\n\n\n **L486** Documents the following definition or result: Applies any supplied application contract and requirements to this system's actual world-dependent method.\n\n\n **L487** Applies any supplied application contract and requirements to this system's actual world-dependent method.\n\n\n **L488** Accepts an arbitrary application contract relating Requirements to the implementation being assessed.\n\n\n **L489** At each world, applies that same contract and requirements to this system's actual method realization.\n\n\n **L491** Conjoins full same-system reflexivity with Grounds for the exact parameterized application claim.\n\n\n **L492** ApplicationDuties keeps the chosen application contract as an explicit parameter.\n\n\n **L493** Also accepts the articulation supplied for each potentially relevant facet.\n\n\n **L494** Keeps the actual applicability predicate separate from the supplied facet list.\n\n\n **L495** Requires full reflexivity of the same system owner's actual rules and work at w.\n\n\n **L496** Requires matching Grounds for the claim produced by this system, these requirements and this contract.\n\n\n **L498** Documents the following definition or result: Projects an explicitly assumed application-compliance interface into reflexivity, applicability coverage and matching discharged facets; it does not invent compliance.\n\n\n **L499** Projects an explicitly assumed application-compliance interface into reflexivity, applicability coverage and matching discharged facets; it does not invent compliance.\n\n\n **L500** The theorem retains the arbitrary application contract rather than fixing a single capability definition.\n\n\n **L501** Retains the actual articulation family for that application's facets.\n\n\n **L502** Retains the application's own applicability predicate and supplied facet list.\n\n\n **L503** Crucially assumes ApplicationDuties already holds for these exact objects; the theorem does not create compliance.\n\n\n **L504** The conclusion retains full same-owner rule/work reflexivity from that assumed duty.\n\n\n **L505** It requires every actually applicable facet to occur in the supplied list, regardless of labels.\n\n\n **L506** For every listed facet, its assessed claim must equal this system's actual parameterized application claim.\n\n\n **L507** That same facet must have an articulable, content-matching articulation and actually satisfy its discharge conditions.\n\n\n **L508** Projects h.1 as reflexivity, h.2.2.1 as applicability coverage, and h.2.2.2 as each listed facet's same-claim, articulation and discharge checks.\n\n\n **L510** Requires the implementation to meet the application's expected output on every requested input.\n\n\n **L511** The output contract checks this implementation's actual run against the chosen expected output on every required input.\n\n\n **L513** Changes the same application requirements from identity to successor output while retaining other fields.\n\n\n **L514** Keeps identityRequirements' inputs and other fields but changes expected output to n+1.\n\n\n **L516** Documents the following definition or result: Reuses the old observation while changing the assessed claim to the successor objective, setting up a same-object scope test.\n\n\n **L517** Reuses the old observation while changing the assessed claim to the successor objective, setting up a same-object scope test.\n\n\n **L518** Reuses the old actual observation for an empirical facet with unrestricted scope.\n\n\n **L519** Changes its assessed claim to this same system meeting successorRequirements; the uncertainty predicate remains trivial.\n\n\n **L521** In this example, the original identity contract retains its fulfilled duties; the changed successor contract fails for the same actual method, and the specified retained-observation package cannot ground it.\n\n\n **L522** The original identity-output application fulfills ApplicationDuties for the actual system and world.\n\n\n **L523** That positive instance uses the already supported capabilityFacet and its own constructed articulation.\n\n\n **L524** But the same actual system does not meet the changed successor-output contract.\n\n\n **L525** Nor does the changed claim acquire Grounds from the retained observation package.\n\n\n **L526** This failure concerns exactly changedObjectiveFacet's singleton package, not every possible evidence package.\n\n\n **L527** Builds the original duty from full owned reflexivity and capabilityGrounds, then leaves changed behavior and changed evidence failures.\n\n\n **L528** Assumes the actual identity method meets the new successor contract.\n\n\n **L529** At required input zero, this would force actual output zero to equal expected one.\n\n\n **L530** Eliminates the impossible 0=1 equality, refuting the changed actual capability claim.\n\n\n **L531** Assumes the retained observation singleton nevertheless gives Grounds for that changed claim.\n\n\n **L532** Extracts the actual changedObjectiveFacet's discharge from that assumed Grounds package.\n\n\n **L533** Its support rule applied to the compatible actual world and input zero yields the same false output equality 0=1.\n\n\n **L534** Rejects that equality, proving the specified retained-observation package cannot ground the new claim.\n\n\n **L536** Documents the following definition or result: Exhibits this actual charter-compliant system with compatible cost evidence whose specified capability facet is unsupported; other valid grounds can still exist.\n\n\n **L537** Exhibits this actual charter-compliant system with compatible cost evidence whose specified capability facet is unsupported; other valid grounds can still exist.\n\n\n **L538** The same actual system satisfies all represented Charter conditions.\n\n\n **L539** Its actual world is compatible with the true at-most-two cost observation.\n\n\n **L540** Nevertheless, that cost evidence does not provide Grounds for its output capability.\n\n\n **L541** The denied Grounds is the particular unsupportedCapabilityFacet singleton, not every possible assessment bundle.\n\n\n **L542** Combines charterChecked, direct compatibility of actual with the cost record, and the already proved unsupportedGrounds counterexample.\n\n\n **L544** Documents the following definition or result: Constructs one shared system/world satisfying actual judgments, full reflexivity, capability evidence, feasible choice and each interpreted commitment's Grounds; it is a bounded model, not universal philosophical correctness.\n\n\n **L545** Documents the following definition or result: Constructs one shared system/world satisfying actual judgments, full reflexivity, capability evidence, feasible choice and each interpreted commitment's Grounds; it is a bounded model, not universal philosophical correctness.\n\n\n **L546** Constructs one shared system/world satisfying actual judgments, full reflexivity, capability evidence, feasible choice and each interpreted commitment's Grounds; it is a bounded model, not universal philosophical correctness.\n\n\n **L547** Requires an actual system/world pair as the joint witness, so the combined claim is nonempty.\n\n\n **L548** That same pair must be admissible for its jointly held/contextual claims and satisfy its Charter.\n\n\n **L549** It must also have its own capability duty fulfilled by capabilityFacet and possess the claimed capability.\n\n\n **L550** The same realized method must be feasibly chosen under its own requirements using objectiveReason.\n\n\n **L551** For every one of the five commitments, the corresponding actual adoption claim must have Grounds.\n\n\n **L552** Each commitment uses its own exact singleton value facet and corresponding applicability.\n\n\n **L553** Finally identifies the witnesses with actualSystem and actual, preventing unrelated existential substitutions.\n\n\n **L554** Chooses that exact pair and supplies its actual admissibility and checked Charter.\n\n\n **L555** Adds this same system's owned capability duty, actual capability and justified identity choice.\n\n\n **L556** Uses each commitment's existing Grounds proof, then closes the two witness-identity equalities by construction.\n\n\n **L558** Closes the current namespace.\n\n\n### `leanified/CoreReader/Logic.lean`\n\n\n```lean\nnamespace CoreReader.Logic\n\n/- A claim denotes the worlds in which its content holds. -/\nabbrev Claim (W : Type) := W → Prop\n/- A theory is a collection of simultaneously held claims. -/\nabbrev Theory (W : Type) := Claim W → Prop\n/- A model satisfies every member of the whole theory. -/\ndef Models {W : Type} (t : Theory W) (w : W) : Prop := ∀ p, t p → p w\n/- Semantic entailment quantifies over all models. -/\ndef Entails {W : Type} (t : Theory W) (p : Claim W) : Prop := ∀ w, Models t w → p w\n/- Satisfiability requires an actual witness. -/\ndef Satisfiable {W : Type} (t : Theory W) : Prop := ∃ w, Models t w\n/- Assumptions, meanings and scope are distinct components; questions remain explicit. -/\nstructure Context (W Q : Type) where\n assumptions : Theory W\n meaning : Q → Claim W\n scope : Claim W\n/- Admissible worlds satisfy held claims, assumptions and scope jointly. -/\ndef Admissible {W Q : Type} (t : Theory W) (c : Context W Q) (w : W) : Prop :=\n Models t w ∧ Models c.assumptions w ∧ c.scope w\n/- A negative judgment denies the very same question under the same meaning. -/\ndef Consequence {W Q : Type} (t : Theory W) (c : Context W Q) (q : Q) (positive : Bool) : Prop :=\n ∀ w, Admissible t c w → if positive then c.meaning q w else ¬ c.meaning q w\n/- The consistency obligation prohibits both consequences at one comparison basis. -/\ndef Consistent {W Q : Type} (t : Theory W) (c : Context W Q) : Prop :=\n ∀ q, ¬ (Consequence t c q true ∧ Consequence t c q false)\n/- An inhabited joint interpretation prevents opposite semantic consequences. -/\ntheorem consequenceConsistency {W Q : Type} (t : Theory W) (c : Context W Q)\n (inhabited : ∃ w, Admissible t c w) : Consistent t c := by\n intro q h\n obtain ⟨w, hw⟩ := inhabited\n exact (h.2 w hw) (h.1 w hw)\n/- Empty and singleton theories provide concrete semantic contexts. -/\ndef emptyTheory {W : Type} : Theory W := fun _ => False\ndef singleton {W : Type} (p : Claim W) : Theory W := fun q => q = p\ndef union {W : Type} (a b : Theory W) : Theory W := fun p => a p ∨ b p\ntheorem modelsSingleton {W : Type} (p : Claim W) (w : W) : Models (singleton p) w ↔ p w := by\n constructor\n · intro h; exact h p rfl\n · intro h q hq; cases hq; exact h\ntheorem modelsUnion {W : Type} (a b : Theory W) (w : W) :\n Models (union a b) w ↔ Models a w ∧ Models b w := by\n constructor\n · intro h; exact ⟨fun p hp => h p (Or.inl hp), fun p hp => h p (Or.inr hp)⟩\n · rintro ⟨ha,hb⟩ p (hp|hp); exact ha p hp; exact hb p hp\n/- The paired world records independent truth values for two questions. -/\ndef premiseP : Claim (Bool × Bool) := fun w => w.1 = true\ndef premiseRule : Claim (Bool × Bool) := fun w => w.1 = true → w.2 = true\ndef premiseNotQ : Claim (Bool × Bool) := fun w => w.2 ≠ true\ndef jointTheory : Theory (Bool × Bool) :=\n union (singleton premiseP) (union (singleton premiseRule) (singleton premiseNotQ))\n/- Each premise has a model, but their joint implication makes the union unsatisfiable. -/\ntheorem jointConflict :\n Satisfiable (singleton premiseP) ∧ Satisfiable (singleton premiseRule) ∧\n Satisfiable (singleton premiseNotQ) ∧ ¬ Satisfiable jointTheory := by\n refine ⟨⟨(true,true), (modelsSingleton _ _).2 rfl⟩,\n ⟨(false,false), (modelsSingleton _ _).2 (by intro h; cases h)⟩,\n ⟨(false,false), (modelsSingleton _ _).2 (by intro h; cases h)⟩, ?_⟩\n rintro ⟨w, hw⟩\n have hp := hw premiseP (Or.inl rfl)\n have hr := hw premiseRule (Or.inr (Or.inl rfl))\n have hn := hw premiseNotQ (Or.inr (Or.inr rfl))\n exact hn (hr hp)\n/- A retraction replaces the old singleton, rather than retaining both at the same time. -/\ndef revisionSlice (time : Nat) : Theory Bool :=\n singleton (fun w => w = (time == 0))\n/- The initial and revised slices have models; keeping both would create a conflict. -/\ntheorem revisionCanReverse :\n Satisfiable (revisionSlice 0) ∧ Satisfiable (revisionSlice 1) ∧\n ¬ Satisfiable (union (revisionSlice 0) (revisionSlice 1)) := by\n refine ⟨⟨true, (modelsSingleton _ _).2 rfl⟩,\n ⟨false, (modelsSingleton _ _).2 rfl⟩, ?_⟩\n rintro ⟨w, hw⟩\n have hs := (modelsUnion _ _ _).1 hw\n have hp := (modelsSingleton _ _).1 hs.1\n have hn := (modelsSingleton _ _).1 hs.2\n have bad : true = false := hp.symm.trans hn\n cases bad\n/- This basic question asks whether the represented switch is on. -/\ndef onQuestion : Unit → Claim Bool := fun _ w => w = true\ndef assumptionContext (b : Bool) : Context Bool Unit :=\n ⟨singleton (fun w => w = b), onQuestion, fun _ => True⟩\ndef meaningContext (b : Bool) : Context Bool Unit :=\n ⟨singleton (fun w => w = true), (fun _ w => w = b), fun _ => True⟩\ndef scopeContext (b : Bool) : Context Bool Unit :=\n ⟨emptyTheory, onQuestion, fun w => w = b⟩\n/- Distinct assumptions, meanings and scopes each admit opposite judgments without same-context conflict. -/\ntheorem contextDifferences :\n (Consequence emptyTheory (assumptionContext true) () true ∧\n Consequence emptyTheory (assumptionContext false) () false) ∧\n (Consequence emptyTheory (meaningContext true) () true ∧\n Consequence emptyTheory (meaningContext false) () false) ∧\n (Consequence emptyTheory (scopeContext true) () true ∧\n Consequence emptyTheory (scopeContext false) () false) ∧\n (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧\n (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧\n (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w) := by\n have empty : ∀ w : Bool, Models emptyTheory w := by intro w p hp; cases hp\n refine ⟨⟨?_, ?_⟩, ⟨?_, ?_⟩, ⟨?_, ?_⟩, ?_, ?_, ?_⟩\n · intro w h; change w = true; exact (modelsSingleton (fun x : Bool => x = true) w).1 h.2.1\n · intro w h hp; have hn := (modelsSingleton _ _).1 h.2.1; cases hp.symm.trans hn\n · intro w h; change w = true; exact (modelsSingleton (fun x : Bool => x = true) w).1 h.2.1\n · intro w h hn; have hp := (modelsSingleton _ _).1 h.2.1; cases hp.symm.trans hn\n · intro w h; exact h.2.2\n · intro w h hp; cases hp.symm.trans h.2.2\n · intro b; exact ⟨b, empty b, (modelsSingleton _ _).2 rfl, trivial⟩\n · intro b; exact ⟨true, empty true, (modelsSingleton _ _).2 rfl, trivial⟩\n · intro b; exact ⟨b, empty b, empty b, rfl⟩\n/- Snapshots preserve identifiable adopted-form revisions even when semantic content agrees. -/\nstructure Snapshot (W Q : Type) where\n held : Theory W\n context : Context W Q\n revisionIdentity : Nat\n/- Semantic equivalence compares represented content, not its list ordering. -/\ndef SameContent {W Q : Type} (a b : Snapshot W Q) : Prop :=\n (∀ p, a.held p ↔ b.held p) ∧\n (∀ p, a.context.assumptions p ↔ b.context.assumptions p) ∧\n (∀ q w, a.context.meaning q w ↔ b.context.meaning q w) ∧\n (∀ w, a.context.scope w ↔ b.context.scope w)\n/- The reporting norm covers both semantic change and independently identified revisions. -/\ndef TruthfulReport {W Q : Type} (a b : Snapshot W Q) (reported : Bool) : Prop :=\n (¬ SameContent a b ∨ a.revisionIdentity ≠ b.revisionIdentity) → reported = true\n/- A real represented change and compliance entail an acknowledged change. -/\ntheorem semanticChangeMustBeReported {W Q : Type} (a b : Snapshot W Q) (reported : Bool)\n (changed : ¬ SameContent a b ∨ a.revisionIdentity ≠ b.revisionIdentity)\n (h : TruthfulReport a b reported) : reported = true := h changed\n/- Reordering a two-claim presentation preserves the held theory extension. -/\ntheorem representationOrderIrrelevant {W : Type} (p q : Claim W) :\n ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r := by\n intro r; exact or_comm\ndef contextSnapshot (c : Context Bool Unit) (revision : Nat := 0) : Snapshot Bool Unit :=\n ⟨emptyTheory, c, revision⟩\n/- Hiding each kind of contextual change violates the reporting interface; reporting alone supplies no truth guarantee. -/\ntheorem hiddenContextChangeRejected :\n ¬ TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) false ∧\n ¬ TruthfulReport (contextSnapshot (meaningContext true)) (contextSnapshot (meaningContext false)) false ∧\n ¬ TruthfulReport (contextSnapshot (scopeContext true)) (contextSnapshot (scopeContext false)) false ∧\n ¬ TruthfulReport (contextSnapshot (scopeContext true) 0) (contextSnapshot (scopeContext true) 1) false ∧\n (TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) true ∧\n ¬ Models (assumptionContext false).assumptions true) := by\n have neq : (fun w : Bool => w = true) ≠ (fun w : Bool => w = false) := by\n intro h; have k := congrFun h true; have z : true = false := k.mp rfl; cases z\n refine ⟨?_, ?_, ?_, ?_, ?_⟩\n · intro h\n have bad := h (Or.inl (by intro s; exact neq ((s.2.1 _).mp rfl)))\n cases bad\n · intro h\n have bad := h (Or.inl (by intro s; have z := (s.2.2.1 () true).mp rfl; cases z))\n cases bad\n · intro h\n have bad := h (Or.inl (by intro s; have z := (s.2.2.2 true).mp rfl; cases z))\n cases bad\n · intro h; have bad := h (Or.inr (by decide)); cases bad\n · refine ⟨fun _ => rfl, ?_⟩\n intro h; have z := (modelsSingleton _ _).1 h; cases z\n/- Two nonidentical resource objectives can share a feasible allocation. -/\ntheorem tensionWithoutContradiction :\n (∃ budget : Nat, 4 ≤ budget ∧ budget ≤ 6) ∧\n ¬ ((fun n : Nat => 4 ≤ n) = (fun n : Nat => n ≤ 6)) := by\n refine ⟨⟨5, by decide, by decide⟩, ?_⟩\n intro h; have k := congrFun h 0; have bad : 4 ≤ 0 := k.mpr (by decide); cases bad\n/- Conflicting conclusions cannot be retained under the same consistency obligation. -/\ntheorem conflictRequiresChange {W Q : Type} (t : Theory W) (c : Context W Q) (q : Q)\n (positive : Consequence t c q true) (negative : Consequence t c q false) :\n ¬ Consistent t c := fun h => h q ⟨positive,negative⟩\n/- A satisfiable theory can have a false assumption at a specified actual world. -/\ntheorem consistentFalse : Satisfiable (singleton (fun w : Bool => w = true)) ∧\n ¬ Models (singleton (fun w : Bool => w = true)) false := by\n refine ⟨⟨true, (modelsSingleton _ _).2 rfl⟩, ?_⟩\n intro h; have bad := (modelsSingleton _ _).1 h; cases bad\n/- The explicitly asked on/off question is undecided by the empty but inhabited theory. -/\ntheorem consistentIncomplete : Satisfiable (emptyTheory : Theory Bool) ∧\n ¬ Entails emptyTheory (fun w : Bool => w = true) ∧\n ¬ Entails emptyTheory (fun w : Bool => w ≠ true) := by\n have empty : ∀ w : Bool, Models emptyTheory w := by intro w p hp; cases hp\n refine ⟨⟨true, empty true⟩, ?_, ?_⟩\n · intro h; have bad := h false (empty false); cases bad\n · intro h; exact h true (empty true) rfl\n/- A claim can share a model with a theory without following in every model. -/\ntheorem compatibilityNotEntailment :\n Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧\n ¬ Entails emptyTheory (fun w : Bool => w = true) := by\n refine ⟨⟨true, (modelsUnion _ _ _).2 ⟨?_, (modelsSingleton _ _).2 rfl⟩⟩,\n consistentIncomplete.2.1⟩\n intro p hp; cases hp\n\nend CoreReader.Logic\n```\n\n\n\n **L1** Open namespace CoreReader.Logic so subsequent declarations receive this module-qualified name.\n\n\n **L3** Document the intended scope of Claim. The corresponding declaration concerns: A claim is a proposition-valued function on a supplied world type W; the world type is not restricted to a real-world interpretation. This comment is explanatory, not a proof premise.\n\n\n **L4** Introduce the type abbreviation Claim. A claim is a proposition-valued function on a supplied world type W; the world type is not restricted to a real-world interpretation.\n\n\n **L5** Document the intended scope of Theory. The corresponding declaration concerns: A theory is a predicate selecting claims, rather than a finite syntax or executable theory representation. This comment is explanatory, not a proof premise.\n\n\n **L6** Introduce the type abbreviation Theory. A theory is a predicate selecting claims, rather than a finite syntax or executable theory representation.\n\n\n **L7** Document the intended scope of Models. The corresponding declaration concerns: A world models a theory exactly when every selected claim holds at that world. This comment is explanatory, not a proof premise.\n\n\n **L8** Define Models. A world models a theory exactly when every selected claim holds at that world.\n\n\n **L9** Document the intended scope of Entails. The corresponding declaration concerns: Semantic entailment universally quantifies over worlds satisfying the theory. With no model it is vacuous. This comment is explanatory, not a proof premise.\n\n\n **L10** Define Entails. Semantic entailment universally quantifies over worlds satisfying the theory. With no model it is vacuous.\n\n\n **L11** Document the intended scope of Satisfiable. The corresponding declaration concerns: Satisfiability requires an actual witness world together with a proof that it models the theory. This comment is explanatory, not a proof premise.\n\n\n **L12** Define Satisfiable. Satisfiability requires an actual witness world together with a proof that it models the theory.\n\n\n **L13** Document the intended scope of Context. The corresponding declaration concerns: Packages contextual assumptions, question meanings, and a scope predicate; the interface does not validate these choices. This comment is explanatory, not a proof premise.\n\n\n **L14** Declare the data interface Context. Packages contextual assumptions, question meanings, and a scope predicate; the interface does not validate these choices.\n\n\n **L15** Store the actual contextual assumption theory, separately from the held theory.\n\n\n **L16** Interpret each question as a proposition about each world.\n\n\n **L17** Store the predicate selecting the admitted application scope.\n\n\n **L18** Document the intended scope of Admissible. The corresponding declaration concerns: A world is admissible when the held theory, contextual assumptions, and scope all hold simultaneously. This comment is explanatory, not a proof premise.\n\n\n **L19** Define Admissible. A world is admissible when the held theory, contextual assumptions, and scope all hold simultaneously.\n\n\n **L20** Require this same world to model both theories and satisfy the contextual scope simultaneously.\n\n\n **L21** Document the intended scope of Consequence. The corresponding declaration concerns: A signed consequence must hold in every admissible world: positive selects the question meaning and negative selects its negation. This comment is explanatory, not a proof premise.\n\n\n **L22** Define Consequence. A signed consequence must hold in every admissible world: positive selects the question meaning and negative selects its negation.\n\n\n **L23** Quantify over every admissible world; the sign selects either this question’s meaning or its negation.\n\n\n **L24** Document the intended scope of Consistent. The corresponding declaration concerns: Consistency rules out simultaneously entailing a question and its negation for every question in Q. Empty Q makes this condition vacuous. This comment is explanatory, not a proof premise.\n\n\n **L25** Define Consistent. Consistency rules out simultaneously entailing a question and its negation for every question in Q. Empty Q makes this condition vacuous.\n\n\n **L26** For every question, prohibit the conjunction of its positive and negative consequences in this same context.\n\n\n **L27** Document the intended scope of consequenceConsistency. The corresponding declaration concerns: Given an admissible witness, proves that no question can have both signed consequences. The witness is an explicit premise. This comment is explanatory, not a proof premise.\n\n\n **L28** State the checked result consequenceConsistency. Given an admissible witness, proves that no question can have both signed consequences. The witness is an explicit premise.\n\n\n **L29** Assume an admissible witness for the whole context and conclude its consistency; begin the proof.\n\n\n **L30** Introduce an arbitrary question q and the hypothetical pair h of its positive and negative consequences in the same context.\n\n\n **L31** Extract the common admissible world w and its entire theory/assumptions/scope proof hw from the explicit inhabited premise.\n\n\n **L32** Evaluate both halves of h at the same w and hw; the negative consequence contradicts the positive consequence.\n\n\n **L33** Document the intended scope of emptyTheory. The corresponding declaration concerns: Selects no claims, so every world models this theory. This comment is explanatory, not a proof premise.\n\n\n **L34** Define emptyTheory. Selects no claims, so every world models this theory.\n\n\n **L35** Define singleton. Selects exactly the claim equal to p; this uses equality of predicate functions.\n\n\n **L36** Define union. Combines two sets of claims by disjunction of membership.\n\n\n **L37** State the checked result modelsSingleton. Proves that modeling the singleton theory is equivalent to satisfying its sole claim. The following tactic block proves this explicit type.\n\n\n **L38** Split the equivalence between satisfying the singleton theory and satisfying its sole claim into two implications.\n\n\n **L39** Use the assumed singleton model h on p, whose membership follows from reflexive equality.\n\n\n **L40** For any selected claim q, singleton membership identifies q with p; substitute that identity and return the assumed truth h of p.\n\n\n **L41** State the checked result modelsUnion. Proves that modeling the union is equivalent to modeling both constituent theories at the same world.\n\n\n **L42** State that the same world models the theory union exactly when it models both constituent theories.\n\n\n **L43** Prove the model-of-union equivalence in its forward and reverse directions.\n\n\n **L44** Restrict the union model h to each theory by embedding its membership proof into the left or right disjunct.\n\n\n **L45** Unpack both constituent models, split a union membership into its two alternatives, and use the corresponding model on the same claim and world.\n\n\n **L46** Document the intended scope of premiseP. The corresponding declaration concerns: Reads the first Boolean coordinate as true. This comment is explanatory, not a proof premise.\n\n\n **L47** Define premiseP. Reads the first Boolean coordinate as true.\n\n\n **L48** Define premiseRule. Makes truth of the first Boolean imply truth of the second.\n\n\n **L49** Define premiseNotQ. Requires the second Boolean not to be true.\n\n\n **L50** Define jointTheory. Combines the first-coordinate fact, the implication, and the negated second-coordinate fact.\n\n\n **L51** Hold P, the rule P implies Q, and not Q together through nested theory unions.\n\n\n **L52** Document the intended scope of jointConflict. The corresponding declaration concerns: Exhibits individual models of each of three claims, then proves their conjunction has no model. This comment is explanatory, not a proof premise.\n\n\n **L53** State the checked result jointConflict. Exhibits individual models of each of three claims, then proves their conjunction has no model.\n\n\n **L54** The first two conclusions provide separate models for P and its implication rule.\n\n\n **L55** Also require a separate model for not Q, but deny any model of the entire joint theory.\n\n\n **L56** Supply (true,true) as the model of P, using modelsSingleton to turn its first-coordinate equality into the required model proof.\n\n\n **L57** Supply (false,false) for the implication premise: assuming its false first coordinate is true is impossible.\n\n\n **L58** Supply (false,false) for not Q and leave the joint unsatisfiability branch to be proved.\n\n\n **L59** Assume a joint model w with proof hw in order to refute its existence.\n\n\n **L60** Extract the actual first-coordinate fact P from its left membership in the joint theory.\n\n\n **L61** Extract P implies Q from the nested union membership of the rule.\n\n\n **L62** Extract not Q from the other nested union branch at the same world.\n\n\n **L63** Apply the rule to P to derive Q and contradict the extracted not Q.\n\n\n **L64** Document the intended scope of revisionSlice. The corresponding declaration concerns: At time zero requires a true world; at every other natural time requires a false world. This comment is explanatory, not a proof premise.\n\n\n **L65** Define revisionSlice. At time zero requires a true world; at every other natural time requires a false world.\n\n\n **L66** Select the single claim that the world equals the Boolean result of testing time=0.\n\n\n **L67** Document the intended scope of revisionCanReverse. The corresponding declaration concerns: Exhibits satisfiable time-zero and time-one slices whose union is unsatisfiable. No temporal update mechanism is implemented. This comment is explanatory, not a proof premise.\n\n\n **L68** State the checked result revisionCanReverse. Exhibits satisfiable time-zero and time-one slices whose union is unsatisfiable. No temporal update mechanism is implemented.\n\n\n **L69** Require time slices 0 and 1 to have separate model witnesses.\n\n\n **L70** Deny a model of their simultaneous union; this does not deny either separate witness.\n\n\n **L71** Give true as the witness for the time-zero singleton theory.\n\n\n **L72** Give false as the witness for time one, and leave the impossibility of holding both slices together.\n\n\n **L73** Assume a world satisfies both time slices simultaneously.\n\n\n **L74** Split this union model into models of the time-zero and time-one theories at the same world.\n\n\n **L75** Extract that the common world equals true from the time-zero singleton.\n\n\n **L76** Extract that the same world equals false from the time-one singleton.\n\n\n **L77** Compose the two equalities through the same world to derive the impossible equality true = false.\n\n\n **L78** Eliminate the impossible equality between distinct Boolean constructors.\n\n\n **L79** Document the intended scope of onQuestion. The corresponding declaration concerns: The sole Unit question asks whether the Boolean world is true. This comment is explanatory, not a proof premise.\n\n\n **L80** Define onQuestion. The sole Unit question asks whether the Boolean world is true.\n\n\n **L81** Define assumptionContext. Varies the assumption selecting the world while fixing its question meaning and unrestricted scope.\n\n\n **L82** Select world b through assumptions, retain the same on-question, and allow every world in scope.\n\n\n **L83** Define meaningContext. Fixes the world assumption to true but varies whether the question means equality to true or false.\n\n\n **L84** Keep the true-world assumption while changing the question to equality with b; scope remains unrestricted.\n\n\n **L85** Define scopeContext. Keeps assumptions empty and the question fixed while selecting the world through scope.\n\n\n **L86** Leave assumptions empty and the question fixed, but let scope select world b.\n\n\n **L87** Document the intended scope of contextDifferences. The corresponding declaration concerns: Proves that changing any one of assumptions, meaning, or scope can reverse polarity, with explicit admissible witnesses in all displayed contexts. This comment is explanatory, not a proof premise.\n\n\n **L88** State the checked result contextDifferences. Proves that changing any one of assumptions, meaning, or scope can reverse polarity, with explicit admissible witnesses in all displayed contexts.\n\n\n **L89** Require a positive answer under true-valued assumptions.\n\n\n **L90** Require the negative answer under false-valued assumptions; the contexts differ.\n\n\n **L91** Require a positive answer for the question meaning equality to true.\n\n\n **L92** Require the negative answer when that question instead means equality to false.\n\n\n **L93** Require the positive answer in the scope restricted to true.\n\n\n **L94** Require the negative answer in the different scope restricted to false.\n\n\n **L95** For either assumption selector, require an actual admissible world.\n\n\n **L96** For either question meaning, require an actual admissible world.\n\n\n **L97** For either scope selector, require an actual admissible world and begin the combined proof.\n\n\n **L98** Show every Boolean world satisfies emptyTheory because membership in that theory is False.\n\n\n **L99** Separate the positive/negative answer pairs for changed assumptions, meaning and scope, then the three nonempty-context witness obligations.\n\n\n **L100** For the true-assumption context, read w = true from the contextual singleton assumptions.\n\n\n **L101** For the false-assumption context, a proposed positive answer contradicts the singleton assumption w = false.\n\n\n **L102** For the true meaning of the question, use the fixed true-world assumption to establish the positive answer.\n\n\n **L103** For the changed false meaning, its proposed truth conflicts with the unchanged true-world assumption.\n\n\n **L104** In the true-scope context, the scope component itself states the required positive answer.\n\n\n **L105** In the false-scope context, a positive answer contradicts the scope component at the same world.\n\n\n **L106** For either chosen assumption b, witness world b satisfies the empty held theory, that singleton assumption and unrestricted scope.\n\n\n **L107** For either question meaning b, true remains a witness because the assumptions are fixed to true and scope is unrestricted.\n\n\n **L108** For either scope selector b, world b satisfies both empty theories and the selected scope by equality.\n\n\n **L109** Document the intended scope of Snapshot. The corresponding declaration concerns: Packages held claims, context and a natural-number revision identity; there is no history validation. This comment is explanatory, not a proof premise.\n\n\n **L110** Declare the data interface Snapshot. Packages held claims, context and a natural-number revision identity; there is no history validation.\n\n\n **L111** Store the theory of simultaneously held claims in the snapshot.\n\n\n **L112** Store the snapshot’s assumptions, question meanings and scope as one Context.\n\n\n **L113** Store a separate natural-number revision identifier; no history validation is implied.\n\n\n **L114** Document the intended scope of SameContent. The corresponding declaration concerns: Defines sameness using claim-membership equivalence, contextual-assumption membership equivalence, pointwise meaning equivalence, and pointwise scope equivalence. This comment is explanatory, not a proof premise.\n\n\n **L115** Define SameContent. Defines sameness using claim-membership equivalence, contextual-assumption membership equivalence, pointwise meaning equivalence, and pointwise scope equivalence.\n\n\n **L116** Require identical held-claim membership for every claim in both snapshots.\n\n\n **L117** Require identical membership for every contextual assumption.\n\n\n **L118** Require equivalent question meanings for every question at every world.\n\n\n **L119** Require equivalent scope predicates at every world.\n\n\n **L120** Document the intended scope of TruthfulReport. The corresponding declaration concerns: Requires a true report if semantic content or revision identity differs. It allows a true report when neither differs and implements no detector. This comment is explanatory, not a proof premise.\n\n\n **L121** Define TruthfulReport. Requires a true report if semantic content or revision identity differs. It allows a true report when neither differs and implements no detector.\n\n\n **L122** Define truthful reporting as a positive flag whenever content differs or the independent revision identifiers differ.\n\n\n **L123** Document the intended scope of semanticChangeMustBeReported. The corresponding declaration concerns: Instantiates the reporting interface with a supplied change proof; it cannot discover changes on its own. This comment is explanatory, not a proof premise.\n\n\n **L124** State the checked result semanticChangeMustBeReported. Instantiates the reporting interface with a supplied change proof; it cannot discover changes on its own.\n\n\n **L125** Assume an actual change: either content differs or the revision identifiers differ.\n\n\n **L126** Assume the reporting obligation and apply it to the preceding change premise to obtain reported=true.\n\n\n **L127** Document the intended scope of representationOrderIrrelevant. The corresponding declaration concerns: Proves swapping the order of two singleton components leaves theory membership unchanged. This comment is explanatory, not a proof premise.\n\n\n **L128** State the checked result representationOrderIrrelevant. Proves swapping the order of two singleton components leaves theory membership unchanged.\n\n\n **L129** For any claim r, swapping p and q preserves membership in their singleton-theory union.\n\n\n **L130** For an arbitrary candidate claim r, use commutativity of disjunction to preserve union membership after reordering p and q.\n\n\n **L131** Define contextSnapshot. Wraps a Boolean/Unit context in a snapshot with empty held theory and a default revision of zero.\n\n\n **L132** Construct a snapshot with no held claims, the supplied context, and the supplied revision identifier.\n\n\n **L133** Document the intended scope of hiddenContextChangeRejected. The corresponding declaration concerns: Rejects false reports for three concrete context changes and a revision-only change; also shows reporting true does not make an incompatible assumption hold. This comment is explanatory, not a proof premise.\n\n\n **L134** State the checked result hiddenContextChangeRejected. Rejects false reports for three concrete context changes and a revision-only change; also shows reporting true does not make an incompatible assumption hold.\n\n\n **L135** Reject a false report when actual contextual assumptions change from true to false.\n\n\n **L136** Reject a false report when the question’s actual meaning changes.\n\n\n **L137** Reject a false report when the actual application scope changes.\n\n\n **L138** Reject a false report when revision identity changes from 0 to 1 despite unchanged context.\n\n\n **L139** Permit truthful acknowledgement of the changed assumptions with a true report.\n\n\n **L140** Nevertheless deny that those revised false-world assumptions hold at actual true.\n\n\n **L141** Prepare a semantic inequality: the predicates selecting true and selecting false are distinct functions.\n\n\n **L142** Evaluate any alleged predicate equality at true; it would turn reflexive truth into true = false.\n\n\n **L143** Split the four rejected hidden changes from the final acknowledged-but-false-assumption example.\n\n\n **L144** Assume the hidden assumption change with report=false satisfied TruthfulReport, in order to refute that claim.\n\n\n **L145** A claimed SameContent would equate the changed assumption predicates; their established inequality activates TruthfulReport and forces the false flag to be true.\n\n\n **L146** Close this hidden-change branch because the required true report contradicts the specified false flag.\n\n\n **L147** Assume the changed question meaning could be truthfully reported as unchanged.\n\n\n **L148** At the sole question and world true, the changed meaning contradicts SameContent; the reporting obligation then forces a positive report.\n\n\n **L149** Close this hidden-change branch because the required true report contradicts the specified false flag.\n\n\n **L150** Assume the changed application scope could satisfy the reporting rule with a false change flag.\n\n\n **L151** Compare the two scopes at true to refute SameContent, then apply the reporting obligation to this real scope change.\n\n\n **L152** Close this hidden-change branch because the required true report contradicts the specified false flag.\n\n\n **L153** The distinct revision identities alone activate the reporting rule, contradicting the false report even without a content change.\n\n\n **L154** Construct an always-positive truthful report, while leaving the separate truth of the revised assumption to be refuted.\n\n\n **L155** Extract the revised false-world assumption at actual true; its impossible equality shows acknowledgement did not make it true.\n\n\n **L156** Document the intended scope of tensionWithoutContradiction. The corresponding declaration concerns: Exhibits overlapping lower/upper budget bounds while proving that the two predicates differ. This is a concrete compatible-constraints example. This comment is explanatory, not a proof premise.\n\n\n **L157** State the checked result tensionWithoutContradiction. Exhibits overlapping lower/upper budget bounds while proving that the two predicates differ. This is a concrete compatible-constraints example.\n\n\n **L158** Ask for a natural-number budget satisfying both lower bound 4 and upper bound 6.\n\n\n **L159** Also assert that the two bound predicates are not identical, even though jointly satisfiable.\n\n\n **L160** Choose budget 5, check both numeric bounds, and leave the inequality of the two objective predicates.\n\n\n **L161** At budget 0, the upper bound holds but the lower bound cannot; therefore the objective predicates cannot be equal.\n\n\n **L162** Document the intended scope of conflictRequiresChange. The corresponding declaration concerns: Given both signed consequences for one question, proves inconsistency as defined. It does not construct a repair or establish which premise should change. This comment is explanatory, not a proof premise.\n\n\n **L163** State the checked result conflictRequiresChange. Given both signed consequences for one question, proves inconsistency as defined. It does not construct a repair or establish which premise should change.\n\n\n **L164** Assume both opposed consequences for exactly the same theory, context and question.\n\n\n **L165** Any Consistent proof would forbid that given pair; apply it to refute consistency, without constructing a revision.\n\n\n **L166** Document the intended scope of consistentFalse. The corresponding declaration concerns: Exhibits a satisfiable Boolean singleton theory that fails at the separately chosen world false; satisfiability is not truth at every world. This comment is explanatory, not a proof premise.\n\n\n **L167** State the checked result consistentFalse. Exhibits a satisfiable Boolean singleton theory that fails at the separately chosen world false; satisfiability is not truth at every world.\n\n\n **L168** Deny that actual false models the theory whose sole claim is world=true.\n\n\n **L169** Provide true as a model of the singleton theory and separately refute modeling it at actual false.\n\n\n **L170** Singleton modeling at false would force false = true, an impossible Boolean equality.\n\n\n **L171** Document the intended scope of consistentIncomplete. The corresponding declaration concerns: Shows the empty Boolean theory is satisfiable while entailing neither the true-world claim nor its negation. This comment is explanatory, not a proof premise.\n\n\n **L172** State the checked result consistentIncomplete. Shows the empty Boolean theory is satisfiable while entailing neither the true-world claim nor its negation.\n\n\n **L173** The inhabited empty theory does not entail the positive true-world answer.\n\n\n **L174** It also does not entail the negative true-world answer; prove these two failures separately.\n\n\n **L175** Show every Boolean world satisfies emptyTheory because membership in that theory is False.\n\n\n **L176** Provide an inhabited empty theory and leave both positive and negative entailments to be refuted.\n\n\n **L177** A purported entailment of world=true fails at the empty theory model false.\n\n\n **L178** A purported entailment of world≠true fails at the empty theory model true.\n\n\n **L179** Document the intended scope of compatibilityNotEntailment. The corresponding declaration concerns: Shows that adding a claim can remain satisfiable even though the original empty theory did not entail that claim. This comment is explanatory, not a proof premise.\n\n\n **L180** State the checked result compatibilityNotEntailment. Shows that adding a claim can remain satisfiable even though the original empty theory did not entail that claim.\n\n\n **L181** Require a model where emptyTheory and the positive singleton claim hold together.\n\n\n **L182** Still deny that emptyTheory by itself entails that positive claim.\n\n\n **L183** Use world true to witness compatibility of the empty theory with the positive singleton claim.\n\n\n **L184** Reuse the previously proved failure of positive entailment from the empty theory.\n\n\n **L185** Finish the model witness: no claim can actually belong to emptyTheory.\n\n\n **L187** Close namespace CoreReader.Logic; this adds no proof or premise.\n\n\n### `leanified/CoreReader/Reflexivity.lean`\n\n\n```lean\nimport Std\n\nnamespace CoreReader.Agency\n\ninductive Phase | formation | application | revision\n deriving DecidableEq, Repr\n\nstructure PrincipleKey where\n owner : Nat\n localId : Nat\n deriving DecidableEq, Repr\n\ninductive Subject\n | system (owner : Nat)\n | principle (owner id : Nat)\n | process (owner id : Nat) (phase : Phase)\n deriving DecidableEq, Repr\n\ndef Subject.owner : Subject → Nat\n | .system n => n\n | .principle n _ => n\n | .process n _ _ => n\n\ninductive Activity | generation | assessment\n deriving DecidableEq, Repr\n\ninductive QuestionKind | conformity | formationBasis | applicability | revisionGrounds\n deriving DecidableEq, Repr\n\ninductive SampleProgram | alwaysTrue | onlyAtZero\n deriving DecidableEq, Repr\n\ndef SampleProgram.run : SampleProgram → Nat → Bool\n | .alwaysTrue, _ => true\n | .onlyAtZero, n => n == 0\n\n/- A generated candidate specifies both the inputs it tests and the scope it proposes to license. -/\nstructure MethodDraft where\n testedInputs : List Nat\n claimedScope : List Nat\n deriving DecidableEq, Repr\n\ndef MethodDraft.accepts (draft : MethodDraft) (program : SampleProgram) : Bool :=\n draft.testedInputs.all program.run\n\n/- This finite application asks whether a proposed rule's observed inputs support its claimed input scope. -/\nstructure Inquiry where\n target : Subject\n kind : QuestionKind\n requestedScope : List Nat\n currentMethod : MethodDraft\n deriving DecidableEq, Repr\n\ninductive ReasonContent\n | purpose (inputs : List Nat)\n | declaredScope (inputs : List Nat)\n | observation (input : Nat) (output : Bool)\n | counterexample (program : SampleProgram) (input : Nat)\n deriving DecidableEq, Repr\n\ndef ReasonContent.identifier : ReasonContent → Nat\n | .purpose _ => 0\n | .declaredScope _ => 1\n | .observation _ _ => 2\n | .counterexample _ _ => 3\n\n/- Reasons have independently supplied contents, a stable local reference and the actual target they concern. -/\nstructure ReasonObject where\n reference : Nat\n target : Subject\n content : ReasonContent\n deriving DecidableEq, Repr\n\ninductive AssessmentResult | supportedWithinScope | insufficient | notApplicable | undetermined\n deriving DecidableEq, Repr\n\ninductive WorkOutcome\n | assessment (result : AssessmentResult)\n | generated (draft : MethodDraft)\n deriving DecidableEq, Repr\n\n/- A method's question, source reasons and limits are determined before looking at its activity records.\nThe meaning relation describes application of that method, not its universal adequacy. -/\nstructure Principle where\n key : PrincipleKey\n activity : Activity\n declaredMethod : MethodDraft\n applicable : Subject → Prop\n inquiry : Subject → Inquiry\n reasons : Subject → List ReasonObject\n limits : Subject → List Nat\n meaning : Inquiry → List ReasonObject → List Nat → WorkOutcome → Prop\n\nstructure WorkRecord where\n usedPrinciple : PrincipleKey\n target : Subject\n activity : Activity\n inquiry : Inquiry\n reasons : List ReasonObject\n limits : List Nat\n outcome : WorkOutcome\n deriving DecidableEq, Repr\n\ndef RegistryCoherent (rules : List Principle) : Prop :=\n ∀ p ∈ rules, ∀ q ∈ rules, p.key = q.key → p = q\n\ndef TargetResolved (rules : List Principle) : Subject → Prop\n | .system owner => ∃ p ∈ rules, p.key.owner = owner\n | .principle owner id | .process owner id _ => ∃ p ∈ rules, p.key = ⟨owner,id⟩\n\n/- The inquiry names the registered target's declared method contract, not an unrelated candidate.\nFor a system inquiry this finite model uses the registered generation contract as its assessed artifact. -/\ndef TargetContentResolved (rules : List Principle) (question : Inquiry) : Prop :=\n match question.target with\n | .system owner => ∃ p ∈ rules, p.key = ⟨owner,0⟩ ∧ question.currentMethod = p.declaredMethod\n | .principle owner id | .process owner id _ =>\n ∃ p ∈ rules, p.key = ⟨owner,id⟩ ∧ question.currentMethod = p.declaredMethod\n\ndef Performed (records : List WorkRecord) (s : Subject) (a : Activity) : Prop :=\n ∃ record ∈ records, record.target = s ∧ record.activity = a\n\n/- The old scope condition remains available without conflating scope with content completion. -/\ndef ReflexiveScope (owner : Nat) (rules : List Principle) (records : List WorkRecord) : Prop :=\n ∀ rule ∈ rules, ∀ s, s.owner = owner → rule.applicable s → Performed records s rule.activity\n\n/- A record uses a registered principle on the same resolvable target, question, reasons and limits,\nand its result must actually follow that principle's method. A negative result can satisfy this relation. -/\nstructure ValidApplication (rules : List Principle) (rule : Principle) (s : Subject)\n (record : WorkRecord) : Prop where\n registered : rule ∈ rules\n applicable : rule.applicable s\n usedIdentity : record.usedPrinciple = rule.key\n targetIdentity : record.target = s\n targetResolved : TargetResolved rules s\n activityIdentity : record.activity = rule.activity\n inquiryIdentity : record.inquiry = rule.inquiry s\n inquiryTarget : record.inquiry.target = s\n targetContent : TargetContentResolved rules record.inquiry\n reasonsIdentity : record.reasons = rule.reasons s\n reasonsNonempty : record.reasons ≠ []\n reasonTargets : ∀ reason ∈ record.reasons, reason.target = s\n limitsIdentity : record.limits = rule.limits s\n followsMeaning : rule.meaning record.inquiry record.reasons record.limits record.outcome\n\n/- The registered normative interface requires contentful application, not just activity labels. -/\ndef Reflexive (owner : Nat) (rules : List Principle) (records : List WorkRecord) : Prop :=\n RegistryCoherent rules ∧\n ∀ rule ∈ rules, ∀ s, s.owner = owner → rule.applicable s →\n ∃ record ∈ records, ValidApplication rules rule s record\n\ntheorem Reflexive.toScope {owner : Nat} {rules : List Principle} {records : List WorkRecord}\n (h : Reflexive owner rules records) : ReflexiveScope owner rules records := by\n intro rule hr s hs ha\n obtain ⟨record, hm, hv⟩ := h.2 rule hr s hs ha\n exact ⟨record, hm, hv.targetIdentity, hv.activityIdentity⟩\n\ntheorem noSelfExemption (owner : Nat) (rules : List Principle) (records : List WorkRecord)\n (h : Reflexive owner rules records) (rule : Principle) (hr : rule ∈ rules)\n (s : Subject) (hs : s.owner = owner) (ha : rule.applicable s) :\n Performed records s rule.activity := h.toScope rule hr s hs ha\n\ndef localMethod : MethodDraft := ⟨[0],[0]⟩\n\ndef inquiryFor (s : Subject) : Inquiry :=\n match s with\n | .process _ _ .formation => ⟨s, .formationBasis, [0], localMethod⟩\n | .process _ _ .application => ⟨s, .applicability, [0], localMethod⟩\n | .process _ _ .revision => ⟨s, .revisionGrounds, [0,1], localMethod⟩\n | _ => ⟨s, .conformity, [0], localMethod⟩\n\n/- These original inquiry inputs do not depend on which work records happen to be present. -/\ndef sourceReasonContents : QuestionKind → List ReasonContent\n | .formationBasis => [.purpose [0], .declaredScope [0], .observation 0 true]\n | .applicability | .conformity => [.declaredScope [0], .observation 0 true]\n | .revisionGrounds => [.purpose [0,1], .declaredScope [0], .observation 0 true,\n .counterexample .onlyAtZero 1]\n\ndef reasonsFor (s : Subject) : List ReasonObject :=\n (sourceReasonContents (inquiryFor s).kind).map fun content => ⟨content.identifier,s,content⟩\n\n/- The application-specific evaluator examines actual scope and sample/counterexample contents.\nIt is a finite inferential method, not a universal standard for empirical or value claims. -/\ndef assessInquiry (question : Inquiry) (reasons : List ReasonObject) (limits : List Nat) : AssessmentResult :=\n let contents := reasons.map ReasonObject.content\n if limits ≠ question.currentMethod.claimedScope then .undetermined else\n match question.kind with\n | .formationBasis =>\n if ReasonContent.purpose question.requestedScope ∈ contents ∧\n ReasonContent.declaredScope limits ∈ contents ∧ question.requestedScope = limits\n then .supportedWithinScope else .undetermined\n | .applicability | .conformity =>\n if question.requestedScope.all (fun n => limits.contains n) then\n if ReasonContent.declaredScope limits ∈ contents ∧\n ReasonContent.observation 0 true ∈ contents ∧ question.requestedScope = [0]\n then .supportedWithinScope else .undetermined\n else .notApplicable\n | .revisionGrounds =>\n if ReasonContent.purpose question.requestedScope ∈ contents ∧\n ReasonContent.declaredScope limits ∈ contents ∧\n ReasonContent.observation 0 true ∈ contents ∧\n contents.any (fun reason => match reason with\n | .counterexample program input => question.requestedScope.contains input &&\n question.currentMethod.accepts program &&\n !(program.run input)\n | _ => false)\n then .insufficient else .undetermined\n\ndef finiteMethodResult (activity : Activity) (question : Inquiry)\n (reasons : List ReasonObject) (limits : List Nat) : WorkOutcome :=\n match activity with\n | .generation => .generated ⟨question.currentMethod.testedInputs,question.requestedScope⟩\n | .assessment => .assessment (assessInquiry question reasons limits)\n\ndef finiteMethodMeaning (activity : Activity) (question : Inquiry)\n (reasons : List ReasonObject) (limits : List Nat) (outcome : WorkOutcome) : Prop :=\n outcome = finiteMethodResult activity question reasons limits\n\ndef ownSubjects (owner : Nat) : List Subject :=\n [.system owner, .principle owner 0, .principle owner 1,\n .process owner 0 .formation, .process owner 0 .application, .process owner 0 .revision,\n .process owner 1 .formation, .process owner 1 .application, .process owner 1 .revision]\n\n/- Applying an existing rule is not a generation event in this application. -/\ndef generationEligible : Subject → Bool\n | .process _ _ .application => false\n | _ => true\n\ndef generatingRule (owner : Nat) : Principle where\n key := ⟨owner,0⟩\n activity := .generation\n declaredMethod := localMethod\n applicable s := s ∈ ownSubjects owner ∧ generationEligible s = true\n inquiry := inquiryFor\n reasons := reasonsFor\n limits _ := [0]\n meaning := finiteMethodMeaning .generation\n\ndef assessingRule (owner : Nat) : Principle where\n key := ⟨owner,1⟩\n activity := .assessment\n declaredMethod := localMethod\n applicable s := s ∈ ownSubjects owner\n inquiry := inquiryFor\n reasons := reasonsFor\n limits _ := [0]\n meaning := finiteMethodMeaning .assessment\n\ndef ownRules (owner : Nat) : List Principle := [generatingRule owner, assessingRule owner]\n\n/- Recorded verdicts are stated separately from the evaluator, so agreement has to be proved. -/\ndef statedOutcome (activity : Activity) (s : Subject) : WorkOutcome :=\n match activity with\n | .generation => .generated ⟨(inquiryFor s).currentMethod.testedInputs,(inquiryFor s).requestedScope⟩\n | .assessment => .assessment (match (inquiryFor s).kind with\n | .revisionGrounds => .insufficient\n | _ => .supportedWithinScope)\n\ndef recordFor (rule : Principle) (s : Subject) : WorkRecord :=\n ⟨rule.key,s,rule.activity,rule.inquiry s,rule.reasons s,rule.limits s,statedOutcome rule.activity s⟩\n\ntheorem reasonsFor_nonempty (s : Subject) : reasonsFor s ≠ [] := by\n cases s with\n | system owner => simp [reasonsFor, inquiryFor, sourceReasonContents]\n | principle owner id => simp [reasonsFor, inquiryFor, sourceReasonContents]\n | process owner id phase => cases phase <;> simp [reasonsFor, inquiryFor, sourceReasonContents]\n\ntheorem reasonsFor_target (s : Subject) : ∀ reason ∈ reasonsFor s, reason.target = s := by\n intro reason h\n obtain ⟨content, _, rfl⟩ := List.mem_map.mp h\n rfl\n\ntheorem inquiryFor_target (s : Subject) : (inquiryFor s).target = s := by\n cases s with\n | system owner => rfl\n | principle owner id => rfl\n | process owner id phase => cases phase <;> rfl\n\n/- This proof includes the actual negative revision evaluation for both principle identities. -/\ntheorem ownContentEvaluates (activity : Activity) (s : Subject) :\n statedOutcome activity s = finiteMethodResult activity (inquiryFor s) (reasonsFor s) [0] := by\n cases activity with\n | generation => rfl\n | assessment =>\n cases s with\n | system owner => rfl\n | principle owner id => rfl\n | process owner id phase => cases phase <;> rfl\n\ntheorem ownRegistryCoherent (owner : Nat) : RegistryCoherent (ownRules owner) := by\n intro p hp q hq hkey\n simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hp hq\n rcases hp with rfl | rfl <;> rcases hq with rfl | rfl\n · rfl\n · have bad := congrArg PrincipleKey.localId hkey; contradiction\n · have bad := congrArg PrincipleKey.localId hkey; contradiction\n · rfl\n\ntheorem ownTargetResolved (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) :\n TargetResolved (ownRules owner) s := by\n simp only [ownSubjects, List.mem_cons, List.not_mem_nil, or_false] at hs\n rcases hs with rfl | rfl | rfl | rfl | rfl | rfl | rfl | rfl | rfl <;>\n simp [TargetResolved, ownRules, generatingRule, assessingRule]\n\ntheorem ownTargetContent (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) :\n TargetContentResolved (ownRules owner) (inquiryFor s) := by\n simp only [ownSubjects, List.mem_cons, List.not_mem_nil, or_false] at hs\n rcases hs with rfl | rfl | rfl | rfl | rfl | rfl | rfl | rfl | rfl <;>\n simp [TargetContentResolved, inquiryFor, ownRules, generatingRule, assessingRule]\n\ntheorem ownRecordValid (owner : Nat) (rule : Principle) (hr : rule ∈ ownRules owner)\n (s : Subject) (ha : rule.applicable s) :\n ValidApplication (ownRules owner) rule s (recordFor rule s) := by\n have hs : s ∈ ownSubjects owner := by\n simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr\n rcases hr with rfl | rfl\n · exact ha.1\n · exact ha\n have hq : rule.inquiry = inquiryFor := by\n simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr\n rcases hr with rfl | rfl <;> rfl\n have hg : rule.reasons = reasonsFor := by\n simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr\n rcases hr with rfl | rfl <;> rfl\n have hl : rule.limits s = [0] := by\n simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr\n rcases hr with rfl | rfl <;> rfl\n have hm : rule.meaning = finiteMethodMeaning rule.activity := by\n simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr\n rcases hr with rfl | rfl <;> rfl\n refine ⟨hr, ha, rfl, rfl, ownTargetResolved owner s hs, rfl, rfl, ?_, ?_, rfl, ?_, ?_, rfl, ?_⟩\n · change (rule.inquiry s).target = s\n rw [hq]; exact inquiryFor_target s\n · change TargetContentResolved (ownRules owner) (rule.inquiry s)\n rw [hq]; exact ownTargetContent owner s hs\n · change rule.reasons s ≠ []\n rw [hg]; exact reasonsFor_nonempty s\n · change ∀ reason ∈ rule.reasons s, reason.target = s\n rw [hg]; exact reasonsFor_target s\n · change rule.meaning (rule.inquiry s) (rule.reasons s) (rule.limits s) (statedOutcome rule.activity s)\n rw [hm, hq, hg, hl]\n exact ownContentEvaluates rule.activity s\n\ndef completeOwnWork (owner : Nat) : List WorkRecord :=\n (ownSubjects owner).flatMap fun s =>\n if generationEligible s then [recordFor (generatingRule owner) s, recordFor (assessingRule owner) s]\n else [recordFor (assessingRule owner) s]\n\ntheorem assessingRecord_member (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) :\n recordFor (assessingRule owner) s ∈ completeOwnWork owner := by\n apply List.mem_flatMap.mpr\n refine ⟨s,hs,?_⟩\n cases generationEligible s <;> simp\n\ntheorem generatingRecord_member (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner)\n (hg : generationEligible s = true) : recordFor (generatingRule owner) s ∈ completeOwnWork owner := by\n exact List.mem_flatMap.mpr ⟨s,hs,by simp [hg]⟩\n\ntheorem completeOwnWork_reflexive (owner : Nat) :\n Reflexive owner (ownRules owner) (completeOwnWork owner) := by\n refine ⟨ownRegistryCoherent owner, ?_⟩\n intro rule hr s _ ha\n refine ⟨recordFor rule s, ?_, ownRecordValid owner rule hr s ha⟩\n simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr\n rcases hr with rfl | rfl\n · exact generatingRecord_member owner s ha.1 ha.2\n · exact assessingRecord_member owner s ha\n\ntheorem ownAssessmentPerformed (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) :\n Performed (completeOwnWork owner) s .assessment :=\n ⟨recordFor (assessingRule owner) s, assessingRecord_member owner s hs, rfl, rfl⟩\n\ndef applicationRule : Principle :=\n { assessingRule 0 with key := ⟨0,0⟩, applicable := fun s => s = .process 0 0 .application }\n\ndef applicationWork : List WorkRecord := [recordFor applicationRule (.process 0 0 .application)]\n\ntheorem applicationWork_reflexive : Reflexive 0 [applicationRule] applicationWork := by\n constructor\n · intro p hp q hq _\n simp only [List.mem_singleton] at hp hq\n rw [hp,hq]\n · intro rule hr s _ ha\n simp only [List.mem_singleton] at hr\n subst rule\n change s = .process 0 0 .application at ha\n subst s\n refine ⟨recordFor applicationRule (.process 0 0 .application), by simp [applicationWork], ?_⟩\n refine ⟨by simp, rfl, rfl, rfl, ?_, rfl, rfl, rfl, ?_, rfl, ?_, ?_, rfl, ?_⟩\n · exact ⟨applicationRule, by simp, rfl⟩\n · exact ⟨applicationRule, by simp, rfl, rfl⟩\n · exact reasonsFor_nonempty _\n · exact reasonsFor_target _\n · change statedOutcome .assessment (.process 0 0 .application) = finiteMethodResult .assessment (inquiryFor (.process 0 0 .application)) (reasonsFor (.process 0 0 .application)) [0]\n exact ownContentEvaluates .assessment _\n\ntheorem applicabilityRetained (owner : Nat) (rules : List Principle) (records : List WorkRecord) :\n (Reflexive owner rules records → ReflexiveScope owner rules records) ∧\n (ReflexiveScope owner rules records ↔\n ∀ rule ∈ rules, ∀ s, s.owner = owner → (¬ rule.applicable s ∨ Performed records s rule.activity)) ∧\n (Reflexive 0 [applicationRule] applicationWork ∧\n ¬ Performed applicationWork (.system 0) .assessment) := by\n classical\n refine ⟨Reflexive.toScope, ?_, applicationWork_reflexive, ?_⟩\n · constructor\n · intro h rule hr s hs\n by_cases ha : rule.applicable s\n · exact Or.inr (h rule hr s hs ha)\n · exact Or.inl ha\n · intro h rule hr s hs ha\n exact (h rule hr s hs).resolve_left (not_not_intro ha)\n · rintro ⟨record, hm, ht, _⟩\n simp only [applicationWork, List.mem_singleton] at hm\n subst record\n cases ht\n\nend CoreReader.Agency\n```\n\n\n\n **L1** Imports Std and its dependencies into this module.\n\n\n **L3** Opens namespace CoreReader.Agency; file boundaries do not change declaration identity.\n\n\n **L5** Defines formation, application and revision phase tags.\n\n\n **L6** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L8** Identifies a registered principle by owner and local identifier.\n\n\n **L9** Stores the owning subject identifier.\n\n\n **L10** Stores the principle identifier within its owner.\n\n\n **L11** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L13** Distinguishes system, principle and phase-indexed principle-process objects.\n\n\n **L14** Represents the system itself, identified by its owner number.\n\n\n **L15** Represents a particular principle by owner and local principle identifier.\n\n\n **L16** Represents that principle's formation, application or revision process as a separate subject.\n\n\n **L17** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L19** Extracts the owner's identifier from every subject constructor.\n\n\n **L20** Extracts the owner directly from a system subject.\n\n\n **L21** Extracts a principle's owner while ignoring its local identifier.\n\n\n **L22** Extracts a process subject's owner independently of its principle identifier and phase.\n\n\n **L24** Distinguishes generation work from assessment work.\n\n\n **L25** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L27** Separates conformity, formation basis, applicability and revision-ground questions.\n\n\n **L28** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L30** Provides a constant-true program and a program true only at zero.\n\n\n **L31** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L33** Evaluates those two programs on natural inputs.\n\n\n **L34** The alwaysTrue sample program accepts every natural-number input.\n\n\n **L35** The onlyAtZero program returns true precisely at input zero.\n\n\n **L37** Documents the following definition or result: Stores tested inputs separately from the claimed scope, allowing overextended claims.\n\n\n **L38** Stores tested inputs separately from the claimed scope, allowing overextended claims.\n\n\n **L39** Records the inputs on which this method draft actually tests a program.\n\n\n **L40** Separately records the input scope the draft proposes to authorize.\n\n\n **L41** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L43** Accepts a program when it succeeds on all listed test inputs; untested inputs are unchecked.\n\n\n **L44** Accepts a program when every tested input returns true; claimedScope is not checked here.\n\n\n **L46** Documents the following definition or result: Binds a target and question kind to requested scope and the target's current method content.\n\n\n **L47** Binds a target and question kind to requested scope and the target's current method content.\n\n\n **L48** Identifies the exact subject whose method is being examined.\n\n\n **L49** Distinguishes conformity, formation reasons, applicability and revision reasons as inquiry purposes.\n\n\n **L50** Records the input scope this particular inquiry asks the method to cover.\n\n\n **L51** Attaches the actual method draft under examination, including its tested and claimed inputs.\n\n\n **L52** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L54** Represents purposes, declared scopes, observations and concrete program/input counterexamples.\n\n\n **L55** A purpose reason names the inputs the method is intended to address.\n\n\n **L56** A scope reason states the method's declared input limits.\n\n\n **L57** An observation reason records a specific input and Boolean output.\n\n\n **L58** A counterexample reason names an actual sample program and input to check.\n\n\n **L59** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L61** Assigns a small code to each reason constructor; the code alone is not evidential content.\n\n\n **L62** Uses local reference 0 for purpose reasons; this is a category identifier, not a unique global identity.\n\n\n **L63** Uses local reference 1 for declared-scope reasons.\n\n\n **L64** Uses local reference 2 for observation reasons.\n\n\n **L65** Uses local reference 3 for counterexample reasons.\n\n\n **L67** Documents the following definition or result: Attaches a reason's content and reference to the subject it concerns.\n\n\n **L68** Attaches a reason's content and reference to the subject it concerns.\n\n\n **L69** Stores a local reference identifying this reason in the modeled inquiry.\n\n\n **L70** Identifies the subject this reason actually concerns.\n\n\n **L71** Stores the purpose, scope, observation or counterexample contents of the reason.\n\n\n **L72** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L74** Allows scoped support, insufficiency, nonapplicability and undetermined results.\n\n\n **L75** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L77** Separates an assessment result from a generated method draft.\n\n\n **L78** Packages a verdict as an assessment outcome; a negative verdict is still an assessment.\n\n\n **L79** Packages a newly generated method draft, without asserting that the draft is correct.\n\n\n **L80** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L82** Documents the following definition or result: Registers a rule's identity, activity, declared method, applicability, inquiries, reasons, limits and explicit outcome semantics.\n\n\n **L83** Documents the following definition or result: Registers a rule's identity, activity, declared method, applicability, inquiries, reasons, limits and explicit outcome semantics.\n\n\n **L84** Registers a rule's identity, activity, declared method, applicability, inquiries, reasons, limits and explicit outcome semantics.\n\n\n **L85** Gives the principle an owner/local identifier used to resolve its records.\n\n\n **L86** Specifies whether this principle governs generation or assessment activity.\n\n\n **L87** States the method draft belonging to this registered principle.\n\n\n **L88** States the subjects on which this principle is applicable.\n\n\n **L89** Assigns the actual question to examine for each subject.\n\n\n **L90** Assigns the reasons supplied for each subject's question.\n\n\n **L91** Assigns the retained input limits for each subject's application.\n\n\n **L92** Defines when an outcome follows this principle's question, reasons and limits; no adequacy law is imposed by this field alone.\n\n\n **L94** Stores the actual rule identity, target, activity, inquiry, reasons, limits and outcome used by an application.\n\n\n **L95** Records the exact registered principle key claimed to have been used.\n\n\n **L96** Records the subject on which this work was performed.\n\n\n **L97** Records whether this work was generation or assessment.\n\n\n **L98** Stores the concrete inquiry actually recorded for this work.\n\n\n **L99** Stores the concrete reasons used in this work record.\n\n\n **L100** Stores the input limits retained in this work record.\n\n\n **L101** Stores the recorded assessment verdict or generated method draft.\n\n\n **L102** Generates decidable equality and display instances for the preceding datatype.\n\n\n **L104** Requires equal registered keys to identify the same principle, preventing ambiguous duplicate identities.\n\n\n **L105** Two registered principles sharing one key must be the same principle, preventing ambiguous lookup.\n\n\n **L107** Requires each assessed target to resolve to a registered owner or exact principle key.\n\n\n **L108** A system subject is resolved when the registry contains some principle with that owner.\n\n\n **L109** Principle and process subjects require a registry entry with their exact owner and local identifier.\n\n\n **L111** Documents the following definition or result: Connects the inquiry's current method to the registered target principle's declared method.\n\n\n **L112** Documents the following definition or result: Connects the inquiry's current method to the registered target principle's declared method.\n\n\n **L113** Connects the inquiry's current method to the registered target principle's declared method.\n\n\n **L114** Chooses the lookup rule from the inquiry's actual target kind.\n\n\n **L115** A system inquiry examines the declared method of its owner's registered principle zero.\n\n\n **L116** For a principle or its process, retain that target's actual owner and identifier for lookup.\n\n\n **L117** Requires both exact key lookup and equality between the inquiry's method and that registered principle's method.\n\n\n **L119** Requires an actual stored record with the requested target and activity; validity is checked separately.\n\n\n **L120** Performed means a listed record has this exact subject and activity; by itself it checks no reason contents.\n\n\n **L122** Documents the following definition or result: Retains the owner-and-applicability-conditioned record-coverage interface.\n\n\n **L123** Retains the owner-and-applicability-conditioned record-coverage interface.\n\n\n **L124** Every applicable registered rule must have a performed activity on subjects belonging to the specified owner.\n\n\n **L126** Documents the following definition or result: Checks rule registration, applicability, object identities, resolved method content, nonempty targeted reasons, exact limits and agreement with the rule's semantics.\n\n\n **L127** Documents the following definition or result: Checks rule registration, applicability, object identities, resolved method content, nonempty targeted reasons, exact limits and agreement with the rule's semantics.\n\n\n **L128** Checks rule registration, applicability, object identities, resolved method content, nonempty targeted reasons, exact limits and agreement with the rule's semantics.\n\n\n **L129** The following proof fields certify one particular work record as a valid use of rule on s.\n\n\n **L130** Requires the rule used by the record to belong to this registry.\n\n\n **L131** Requires that same rule to be applicable to the assessed subject.\n\n\n **L132** Checks the record's used-principle key against this rule's exact key.\n\n\n **L133** Checks that the work record targets this exact subject s.\n\n\n **L134** Requires the record's subject to resolve within the same rule registry.\n\n\n **L135** Checks that the recorded activity is the activity governed by this rule.\n\n\n **L136** Checks that the recorded inquiry equals the inquiry this rule assigns to s.\n\n\n **L137** Separately checks that the inquiry itself targets s, rather than an unrelated subject.\n\n\n **L138** Checks that the inquiry's method belongs to its resolved registered target.\n\n\n **L139** Checks the recorded reasons equal those specified by this rule for s.\n\n\n **L140** Requires at least one actual reason in this record.\n\n\n **L141** Requires every recorded reason to concern the same subject s.\n\n\n **L142** Checks that recorded limits equal the rule's limits for s.\n\n\n **L143** Requires the record's outcome to satisfy the rule's actual meaning relation on its inquiry, reasons and limits.\n\n\n **L145** Documents the following definition or result: Requires a coherent registry and a valid recorded application for every applicable same-owner subject and registered rule; this remains a model compliance condition.\n\n\n **L146** Requires a coherent registry and a valid recorded application for every applicable same-owner subject and registered rule; this remains a model compliance condition.\n\n\n **L147** Reflexive first requires unambiguous principle registration.\n\n\n **L148** It then ranges over each registered rule and owned subject where that rule is applicable.\n\n\n **L149** For each such application, some listed record must satisfy all ValidApplication content checks.\n\n\n **L151** Forgets content-validity details while extracting target/activity record coverage from full reflexivity.\n\n\n **L152** Assumes full contentful Reflexive compliance and derives its weaker scope-only coverage.\n\n\n **L153** Takes a registered rule, an owned subject and its applicability premise for the scope obligation.\n\n\n **L154** Uses full Reflexive compliance to obtain the actual listed record and its ValidApplication proof.\n\n\n **L155** Keeps that record's membership, target identity and activity identity to prove Performed.\n\n\n **L157** Instantiates full reflexivity at a registered applicable same-owner subject, then extracts its performance record.\n\n\n **L158** Requires full Reflexive compliance and actual membership of the rule in the registry.\n\n\n **L159** Also requires the target's owner to match and the rule to be applicable to it.\n\n\n **L160** Specializes the derived scope obligation to those premises, yielding this target's performed activity.\n\n\n **L162** Tests input zero and declares scope zero.\n\n\n **L164** Maps formation to basis, application to applicability, revision to grounds over zero and one, and other objects to conformity.\n\n\n **L165** Chooses the inquiry from the subject's process phase, retaining the same subject as target.\n\n\n **L166** For formation, asks about the basis for a method covering input zero.\n\n\n **L167** For application, asks whether the local method applies on input zero.\n\n\n **L168** For revision, asks about extending the same local method's scope to inputs zero and one.\n\n\n **L169** For a system or principle itself, asks conformity on the local scope {0}.\n\n\n **L171** Documents the following definition or result: Supplies question-specific purpose/scope/observation data, adding a failing untested-input program for revision review.\n\n\n **L172** Supplies question-specific purpose/scope/observation data, adding a failing untested-input program for revision review.\n\n\n **L173** Formation reasons state the purpose {0}, declared scope {0}, and the observed true result at zero.\n\n\n **L174** Applicability and conformity use the declared local scope plus the same observation at zero.\n\n\n **L175** Revision reasons request {0,1} while acknowledging a declared scope of {0} and only a zero observation.\n\n\n **L176** Adds the concrete onlyAtZero program at input one as a revision counterexample.\n\n\n **L178** Attaches every chosen reason's content to this exact inquiry target.\n\n\n **L179** Wraps each source reason with its category reference and the same subject s, preserving its actual content.\n\n\n **L181** Documents the following definition or result: Computes scoped results from actual reason contents and method scope; a program passing current tests but failing a requested input yields insufficiency for revision.\n\n\n **L182** Documents the following definition or result: Computes scoped results from actual reason contents and method scope; a program passing current tests but failing a requested input yields insufficiency for revision.\n\n\n **L183** Computes scoped results from actual reason contents and method scope; a program passing current tests but failing a requested input yields insufficiency for revision.\n\n\n **L184** Extracts reason contents for checking their substantive purpose, scope, observations and counterexamples.\n\n\n **L185** Returns undetermined if supplied limits differ from the examined method's declared scope.\n\n\n **L186** After checking limits, evaluates the specific kind of question asked.\n\n\n **L187** Selects the formation-basis assessment branch.\n\n\n **L188** Requires a purpose reason covering the inquiry's requested inputs.\n\n\n **L189** Also requires an explicit limit declaration and equality of requested and declared scopes.\n\n\n **L190** Formation is supportedWithinScope only when those content checks pass; otherwise it is undetermined.\n\n\n **L191** Uses the same local checks for applicability and conformity questions.\n\n\n **L192** First tests that every requested input belongs to the supplied limits.\n\n\n **L193** Within those limits, requires a reason explicitly declaring that same scope.\n\n\n **L194** Also requires the true observation at zero and a requested scope exactly equal to [0].\n\n\n **L195** Passing these local checks yields supportedWithinScope; incomplete evidence yields undetermined.\n\n\n **L196** A requested input outside the supplied limits yields notApplicable.\n\n\n **L197** Selects the revision-grounds branch, which searches for an actual scope counterexample.\n\n\n **L198** Requires a reason stating the revised requested scope as the intended purpose.\n\n\n **L199** Requires the old limits to be explicitly present as a declared-scope reason.\n\n\n **L200** Requires the original successful observation at input zero.\n\n\n **L201** Searches the supplied reason contents for a counterexample satisfying the following concrete checks.\n\n\n **L202** A counterexample's input must be inside the newly requested scope.\n\n\n **L203** Its program must nevertheless pass the current method's tested inputs.\n\n\n **L204** That same program must fail at the counterexample input.\n\n\n **L205** Other reason kinds cannot themselves satisfy this counterexample search.\n\n\n **L206** A witnessed testing/scope gap yields insufficient; without those contents, the result is undetermined.\n\n\n **L208** Generation keeps tested inputs and adopts requested scope; assessment executes the reason-sensitive inquiry evaluator.\n\n\n **L209** Supplies the same reasons and limits to the activity-specific result function.\n\n\n **L210** Chooses between generating a draft and evaluating an inquiry.\n\n\n **L211** Generation keeps the method's tested inputs but proposes the inquiry's requested scope; correctness is not certified.\n\n\n **L212** Assessment computes assessInquiry from this question's actual reasons and limits.\n\n\n **L214** Defines acceptable outcome by equality with the disclosed finite evaluation algorithm, not an assumed successful result.\n\n\n **L215** Receives the specific recorded outcome whose compliance with this activity's method is checked.\n\n\n **L216** An outcome follows the method exactly when it equals the computed finiteMethodResult.\n\n\n **L218** Enumerates the owner system, both registered principles and all three phases of each principle.\n\n\n **L219** Includes the system itself and its two principle identities as owned subjects.\n\n\n **L220** Includes formation, application and revision of principle zero as separate subjects.\n\n\n **L221** Also includes all three phases of principle one, giving nine owned subjects total.\n\n\n **L223** Documents the following definition or result: Excludes application-phase processes from this particular generation rule while retaining the other objects.\n\n\n **L224** Excludes application-phase processes from this particular generation rule while retaining the other objects.\n\n\n **L225** Treats applying an already existing principle as ineligible for generation in this application model.\n\n\n **L226** All other represented subject kinds remain eligible for generation.\n\n\n **L228** Registers principle zero for generation with the local method, explicit inquiries/reasons and restricted applicability.\n\n\n **L229** Registers the generation principle under local key zero for this owner.\n\n\n **L230** Makes this rule govern generation work.\n\n\n **L231** Assigns the local test-and-scope draft [0]/[0] to the generation rule.\n\n\n **L232** Generation requires both membership in this owner's nine subjects and generation eligibility.\n\n\n **L233** Uses inquiryFor to supply the subject's actual phase-sensitive question.\n\n\n **L234** Uses reasonsFor to supply the original target-linked reason contents.\n\n\n **L235** Retains [0] as the generation rule's limit for every subject.\n\n\n **L236** Requires the generated outcome to match finiteMethodResult's generation branch.\n\n\n **L238** Registers principle one for assessment of every enumerated own subject with explicit finite evaluation semantics.\n\n\n **L239** Registers the assessment principle under distinct local key one.\n\n\n **L240** Makes this rule govern assessment work.\n\n\n **L241** The assessment principle declares the same local [0]/[0] method contract.\n\n\n **L242** Assessment applies to all nine subjects belonging to this owner.\n\n\n **L243** Assigns the same phase-sensitive inquiry function to the assessment rule.\n\n\n **L244** Assigns the same original target-linked reasons to its assessments.\n\n\n **L245** Retains [0] as the assessment rule's declared limit.\n\n\n **L246** Requires assessment outcomes to equal the evaluator's actual result.\n\n\n **L248** Returns the two distinct registered generation and assessment principles.\n\n\n **L250** Documents the following definition or result: Constructs expected generated drafts and scoped/insufficient assessment results, which are subsequently checked against evaluation.\n\n\n **L251** Constructs expected generated drafts and scoped/insufficient assessment results, which are subsequently checked against evaluation.\n\n\n **L252** Chooses the independently stated record outcome by activity.\n\n\n **L253** The recorded generated draft retains tested inputs and adopts the inquiry's requested scope.\n\n\n **L254** For assessment records, chooses a stated verdict from the inquiry kind rather than calling assessInquiry here.\n\n\n **L255** Revision inquiries are recorded as insufficient.\n\n\n **L256** The remaining represented inquiries are recorded as supportedWithinScope.\n\n\n **L258** Builds a record from the supplied rule and subject; registry membership and content validity require the later ValidApplication proof.\n\n\n **L259** Builds a record from this rule's identity, inquiry, reasons and limits, but uses the separately stated outcome.\n\n\n **L261** Exhausts subject/phase constructors to prove each concrete inquiry has reasons.\n\n\n **L262** Checks reason-list nonemptiness for each kind of subject.\n\n\n **L263** System inquiries use the conformity reasons, which contain scope and observation entries.\n\n\n **L264** Principle inquiries likewise have the nonempty scope-and-observation list.\n\n\n **L265** Each process phase reduces to its actual nonempty formation, application or revision reason list.\n\n\n **L267** Uses the reason-list map construction to prove every reason targets the same subject.\n\n\n **L268** Takes any reason known to occur in this subject's constructed reason list.\n\n\n **L269** Inverts the map construction to recover the source content and replace the reason with its target-tagged wrapper.\n\n\n **L270** That wrapper's target is s by construction, so target equality is reflexive.\n\n\n **L272** Checks each constructor to prove the generated inquiry retains its subject identity.\n\n\n **L273** Checks the inquiry target for system, principle and process subjects separately.\n\n\n **L274** The system inquiry was constructed with that same system as target.\n\n\n **L275** The principle inquiry likewise retains that same principle target.\n\n\n **L276** Every process phase uses the original process subject as its inquiry target.\n\n\n **L278** Documents the following definition or result: Computes every subject/phase assessment and generation case, showing stored expected outcomes agree with the actual algorithm, including insufficiency.\n\n\n **L279** Computes every subject/phase assessment and generation case, showing stored expected outcomes agree with the actual algorithm, including insufficiency.\n\n\n **L280** Requires the independently stated outcome to equal actual evaluation of this subject's question, reasons and [0] limits.\n\n\n **L281** Splits this equality check between generated drafts and assessment verdicts.\n\n\n **L282** Both generation definitions construct the identical tested-input/requested-scope draft.\n\n\n **L283** For assessment, the stated verdict must now be checked against the actual evaluator.\n\n\n **L284** Separates the finite assessment check by subject kind.\n\n\n **L285** The system's conformity contents compute to the stated supportedWithinScope verdict.\n\n\n **L286** The principle's conformity contents compute to that same supportedWithinScope verdict.\n\n\n **L287** Formation/application compute support; revision computes insufficient from the program passing zero but failing one.\n\n\n **L289** Separates local identifiers zero and one to prove the two-rule registry has no ambiguous key.\n\n\n **L290** Takes two registered principles whose keys are assumed equal.\n\n\n **L291** Restricts both registry memberships to the actual generation or assessment rule.\n\n\n **L292** Examines the four resulting pairs of concrete rules.\n\n\n **L293** When both are the generation rule, principle equality holds directly.\n\n\n **L294** Generation key 0 cannot equal assessment key 1; projecting localId produces a contradiction.\n\n\n **L295** The reverse mixed pair would require localId 1=0, also impossible.\n\n\n **L296** When both are the assessment rule, principle equality holds directly.\n\n\n **L298** Checks all nine enumerated subjects resolve to an actual registered owner/principle.\n\n\n **L299** The subject selected from ownSubjects must resolve to this owner's actual registry.\n\n\n **L300** Expands membership hs into the nine concrete owned subjects.\n\n\n **L301** Handles each of those nine subjects with its original owner and principle identifier fixed.\n\n\n **L302** Finds the generation or assessment registry entry matching each target key.\n\n\n **L304** Checks each inquiry's method matches its registered target's declared local method.\n\n\n **L305** Requires the selected subject's inquiry to examine its own registered declared method.\n\n\n **L306** Again enumerates the nine concrete subjects from the actual membership premise.\n\n\n **L307** Checks target-method correspondence separately for each system, principle and phase subject.\n\n\n **L308** Both registered rules declare localMethod, exactly the method inquiryFor assigns to every enumerated target.\n\n\n **L310** Combines identity, reason-target, scope, registry and actual evaluation facts to validate each applicable generated record.\n\n\n **L311** Assumes the chosen registered rule is applicable to this subject s.\n\n\n **L312** Proves the concrete recordFor rule s satisfies every ValidApplication field.\n\n\n **L313** First derives that applicability places s in this owner's subject list.\n\n\n **L314** Uses registry membership to restrict rule to one of the two owned rules.\n\n\n **L315** Separates the generation and assessment applicability conditions.\n\n\n **L316** Generation applicability includes owned-subject membership as its first conjunct.\n\n\n **L317** Assessment applicability is exactly that owned-subject membership.\n\n\n **L318** Establishes that this actual rule uses inquiryFor as its inquiry function.\n\n\n **L319** Reduces registered-rule membership to generation or assessment to inspect its inquiry field.\n\n\n **L320** Both possible rules define their inquiry field as inquiryFor.\n\n\n **L321** Establishes that the chosen rule uses reasonsFor as its reason provider.\n\n\n **L322** Again restricts the rule to the two actual registry entries before inspecting reasons.\n\n\n **L323** Both entries supply exactly reasonsFor.\n\n\n **L324** Establishes that this rule's limits for s are exactly [0].\n\n\n **L325** Resolves registry membership before inspecting the selected rule's limits.\n\n\n **L326** Both owned rules retain [0] as their limit.\n\n\n **L327** Establishes that the chosen rule's meaning is the result function for its own activity.\n\n\n **L328** Resolves registry membership to inspect generation versus assessment meaning.\n\n\n **L329** In either case, the rule's meaning is finiteMethodMeaning specialized to that rule's activity.\n\n\n **L330** Builds ValidApplication using registry/applicability premises, record identities and resolved target; leaves inquiry, reasons and computed meaning checks to follow.\n\n\n **L331** The remaining inquiry-target goal is about this rule's actual inquiry on s.\n\n\n **L332** Replaces the rule's inquiry with inquiryFor, whose target-preservation theorem proves it targets s.\n\n\n **L333** The remaining method-identity goal checks the registered target of this rule's inquiry.\n\n\n **L334** Rewrites to inquiryFor and uses the concrete owned-target method-resolution theorem.\n\n\n **L335** Reduces record reason nonemptiness to nonemptiness of this rule's supplied reasons.\n\n\n **L336** Rewrites those reasons to reasonsFor and applies its nonempty-list theorem.\n\n\n **L337** Reduces reason-target consistency to every supplied reason targeting s.\n\n\n **L338** Rewrites to reasonsFor and uses its target-preserving construction theorem.\n\n\n **L339** The final obligation compares the separately stated outcome against this rule's actual inquiry, reasons, limits and meaning.\n\n\n **L340** Substitutes the four established identities for meaning, inquiry, reasons and [0] limits.\n\n\n **L341** Uses ownContentEvaluates to prove the recorded outcome equals the actual method result.\n\n\n **L343** Constructs records for all nine subjects, including generation only where its eligibility condition holds.\n\n\n **L344** Builds the full log by concatenating the records assigned to each owned subject.\n\n\n **L345** Eligible subjects receive both a generation record and an assessment record.\n\n\n **L346** Application-phase subjects receive assessment only, matching generation's explicit applicability restriction.\n\n\n **L348** Places each subject's assessment record in the flat-mapped complete work list.\n\n\n **L349** Claims this owned subject's assessment record occurs in the constructed full log.\n\n\n **L350** Uses flatMap membership: choose a subject whose assigned record list contains the desired record.\n\n\n **L351** Chooses the same s and its supplied owned-subject membership hs.\n\n\n **L352** Whether generation is eligible or not, the assigned list contains s's assessment record.\n\n\n **L354** Places a subject's generation record in the work list under explicit generation eligibility.\n\n\n **L355** Adds generation eligibility to owned membership before claiming a generation record in the full log.\n\n\n **L356** Selects s's flatMap branch; hg makes that branch include the requested generation record.\n\n\n **L358** Combines coherent registry, membership and content-valid applications to establish the concrete nonempty reflexivity model.\n\n\n **L359** States full contentful reflexivity for the actual two-rule registry and constructed work log.\n\n\n **L360** Provides the proved registry coherence and leaves contentful coverage for each applicable subject.\n\n\n **L361** Takes an actual registered rule and applicable subject; applicability itself will supply needed owned membership.\n\n\n **L362** Chooses recordFor rule s and its already proved content validity, leaving only its presence in the full log.\n\n\n **L363** Resolves rule membership to the generation or assessment entry.\n\n\n **L364** Splits record membership by those two actual rule cases.\n\n\n **L365** For generation, ha supplies owned membership and eligibility, which place its record in the full log.\n\n\n **L366** For assessment, ha directly supplies the owned membership needed for its record.\n\n\n **L368** Extracts the constructed assessment record for a listed own subject.\n\n\n **L369** Claims a performed assessment on s in the same complete work log.\n\n\n **L370** Uses s's assessment record, its proved log membership and exact target/activity identities as the Performed witness.\n\n\n **L372** Restricts an assessment rule to one application-phase subject and assigns it a resolvable key.\n\n\n **L373** Restricts the assessment rule to exactly principle-zero's application process, with key (0,0).\n\n\n **L375** Stores the one fully specified application assessment record.\n\n\n **L377** Checks the singleton registry and record satisfy full content-valid reflexivity on their restricted applicability.\n\n\n **L378** Separates singleton-registry coherence from coverage of its sole applicable subject.\n\n\n **L379** Takes any two rules in that singleton registry; key equality is unnecessary because membership already identifies both.\n\n\n **L380** Singleton membership makes both rules equal to applicationRule.\n\n\n **L381** Substituting these identities proves the two rules are equal.\n\n\n **L382** Takes an applicable subject for a rule in the singleton application registry.\n\n\n **L383** Uses singleton membership to identify the rule as applicationRule.\n\n\n **L384** Replaces rule with that exact applicationRule throughout the coverage obligation.\n\n\n **L385** Unfolds applicability to show s is exactly owner-zero principle-zero's application process.\n\n\n **L386** Substitutes that exact process for s, fixing the work target.\n\n\n **L387** Selects the sole record in applicationWork and proves its membership; content validity remains to check.\n\n\n **L388** Fills immediate registry, applicability and record-identity fields; leaves target resolution, reasons and computed outcome checks.\n\n\n **L389** The target key resolves to applicationRule itself in the singleton registry.\n\n\n **L390** That same registered rule supplies the localMethod actually examined by the inquiry.\n\n\n **L391** The application inquiry's reasons are nonempty by reasonsFor_nonempty.\n\n\n **L392** Every application reason targets this exact application-process subject.\n\n\n **L393** The remaining meaning obligation is equality of the stated application assessment and its actual finite evaluation.\n\n\n **L394** Uses ownContentEvaluates to certify that equality for the application-phase assessment.\n\n\n **L396** Derives record scope from full reflexivity, proves its classical conditional/disjunctive equivalence, and gives a valid restricted example with no system assessment.\n\n\n **L397** The first clause retains the implication from full contentful reflexivity to scope coverage.\n\n\n **L398** The second clause restates conditional scope coverage as an either/or obligation.\n\n\n **L399** For each owned subject and registered rule, either the rule is inapplicable or its activity was performed.\n\n\n **L400** The concrete singleton application log satisfies full reflexivity under its restricted rule.\n\n\n **L401** Yet that same log contains no assessment of the system itself, where this rule is not applicable.\n\n\n **L402** Uses classical case splitting on possibly undecidable applicability predicates.\n\n\n **L403** Supplies the general scope projection and concrete restricted witness; leaves the equivalence and missing-system-record proof.\n\n\n **L404** Proves both directions of the applicability-or-performance reformulation.\n\n\n **L405** Assumes conditional scope coverage and fixes a registered rule with an owned subject.\n\n\n **L406** Splits on whether that exact rule is applicable to this subject.\n\n\n **L407** When applicable, coverage supplies the performed activity, satisfying the right disjunct.\n\n\n **L408** When inapplicable, that negative applicability fact satisfies the left disjunct.\n\n\n **L409** For the reverse direction, assumes the disjunction and actual applicability on the owned subject.\n\n\n **L410** Rules out the inapplicable disjunct using ha, leaving the required performed activity.\n\n\n **L411** Assumes a system assessment exists and extracts its listed record plus target identity.\n\n\n **L412** The singleton applicationWork list forces that record to be its application-process record.\n\n\n **L413** Replaces the alleged system-assessment record with that sole process record.\n\n\n **L414** Its process target cannot equal the system target, contradicting the assumed record identity.\n\n\n **L416** Closes the current namespace.\n\n\n### `leanified/CoreReader.lean`\n\n\n```lean\nimport CoreReader.Engineering.Integration\n```\n\n\n\n **L1** Import Engineering.Integration and its transitive modules, making this project’s engineering application, inherited interfaces, joint witness and non-entailment proof available; the import itself asserts no philosophical theorem.\n\n", + "detail_link_found": true, + "line_anchors": [] + }, + { + "question": 6, + "language": "zh", + "target": "t01", + "overview_line": 54, + "detail_line": 54, + "overview_text": "\n## T01 · 权威与采用基准\n\nSoftwareEngineering 0.2.0 采用继承的 Core 0.1.2 文本及附加工程优先承诺;本稿不将它升级为 Core 0.1.3。\n\n**前提与表示:** 完整条款、含义及适用限度是权威文本。rationale 与案例辅助解释;当前 Core 检查器是独立运行依赖。\n\n**证明或检查:** 冻结并追溯源字节、元数据及段落原文;文献权威不分配 Lean 定理。\n\n**限度:** 章节顺序和检查通过均不建立演绎层级、普遍哲学正确性或所有系统的采用事实。\n\n**状态:** accepted (boundary). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [organon.preamble#p1](#source-organon-preamble-p1), [organon.preamble#p2](#source-organon-preamble-p2), [organon.charter.overview#p1](#source-organon-charter-overview-p1), [organon.charter.overview#p2](#source-organon-charter-overview-p2), [organon.charter.overview#p3](#source-organon-charter-overview-p3), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [extensions#p1](#source-extensions-p1)\n\n[声明、证明与逐行解释](details.md#t01)\n\n\n", + "detail_text": "\n## T01 · 权威与采用基准\n\nSoftwareEngineering 0.2.0 采用继承的 Core 0.1.2 文本及附加工程优先承诺;本稿不将它升级为 Core 0.1.3。\n\n**前提与表示:** 完整条款、含义及适用限度是权威文本。rationale 与案例辅助解释;当前 Core 检查器是独立运行依赖。\n\n**证明或检查:** 冻结并追溯源字节、元数据及段落原文;文献权威不分配 Lean 定理。\n\n**限度:** 章节顺序和检查通过均不建立演绎层级、普遍哲学正确性或所有系统的采用事实。\n\n**状态:** accepted (boundary). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [organon.preamble#p1](#source-organon-preamble-p1), [organon.preamble#p2](#source-organon-preamble-p2), [organon.charter.overview#p1](#source-organon-charter-overview-p1), [organon.charter.overview#p2](#source-organon-charter-overview-p2), [organon.charter.overview#p3](#source-organon-charter-overview-p3), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [extensions#p1](#source-extensions-p1)\n\n此边界目标没有 Lean 声明。\n\n\n", + "detail_link_found": true, + "line_anchors": [] + }, + { + "question": 6, + "language": "zh", + "target": "t02", + "overview_line": 72, + "detail_line": 72, + "overview_text": "\n## T02 · 重视扩展与形式可修订\n\ngenerationSpecification 要求重视扩展,并使当前组织、方法和原则形式保持可修订;有理由的稳定行动可与此取向共存。\n\n**前提与表示:** Policy 提供价值位置、当前形式及可修订关系。具体政策有实际当前形式,并非以空清单履责。\n\n**证明或检查:** 正例构造价值取向及可修订性;中性政策虽允许版本变化却不重视扩展。稳定与协作案例检查实际状态变换和资源。\n\n**限度:** 此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。\n\n**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [organon.charter.overview#p2](#source-organon-charter-overview-p2), [organon.charter.overview#p3](#source-organon-charter-overview-p3), [organon.charter.self-transcendence#p1](#source-organon-charter-self-transcendence-p1), [organon.charter.self-transcendence.orientation#p1](#source-organon-charter-self-transcendence-orientation-p1), [organon.charter.self-transcendence.non-finality#p1](#source-organon-charter-self-transcendence-non-finality-p1), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.relationships.terms#p1](#source-organon-relationships-terms-p1)\n\n[声明、证明与逐行解释](details.md#t02)\n\n\n", + "detail_text": "\n## T02 · 重视扩展与形式可修订\n\ngenerationSpecification 要求重视扩展,并使当前组织、方法和原则形式保持可修订;有理由的稳定行动可与此取向共存。\n\n**前提与表示:** Policy 提供价值位置、当前形式及可修订关系。具体政策有实际当前形式,并非以空清单履责。\n\n**证明或检查:** 正例构造价值取向及可修订性;中性政策虽允许版本变化却不重视扩展。稳定与协作案例检查实际状态变换和资源。\n\n**限度:** 此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。\n\n**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [organon.charter.overview#p2](#source-organon-charter-overview-p2), [organon.charter.overview#p3](#source-organon-charter-overview-p3), [organon.charter.self-transcendence#p1](#source-organon-charter-self-transcendence-p1), [organon.charter.self-transcendence.orientation#p1](#source-organon-charter-self-transcendence-orientation-p1), [organon.charter.self-transcendence.non-finality#p1](#source-organon-charter-self-transcendence-non-finality-p1), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.relationships.terms#p1](#source-organon-relationships-terms-p1)\n\n### `CoreReader.Adopted.generationSpecification`\n\n[leanified/CoreReader/Adopted.lean:80](#line-code-leanified-corereader-adopted-lean-80) · definition\n\n核心依赖: none.\n\n```lean\ndef generationSpecification (policy : Policy) : Prop := Generative policy\n```\n\n### `CoreReader.Adopted.generationCases`\n\n[leanified/CoreReader/Adopted.lean:862](#line-code-leanified-corereader-adopted-lean-862) · case\n\n核心依赖: `propext`, `Quot.sound`.\n\n```lean\ntheorem generationCases :\n (Generative openPolicy ∧\n (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧\n (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1)))) ∧\n (neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy) ∧\n (Generative generatingSystem.policy ∧\n generatingSystem.policy.permitsVersion 0 0 ∧\n ¬ Expanded generatingSystem.current inflatedState ∧\n generatingSystem.current.inventory.length < inflatedState.inventory.length ∧\n generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧\n generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧\n generatingSystem.execute availableResources = some 6 ∧\n generatingSystem.execute { availableResources with experience := none } = none ∧\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-adopted-lean-80", + "found": true + }, + { + "anchor": "line-code-leanified-corereader-adopted-lean-862", + "found": true + } + ] + }, + { + "question": 6, + "language": "zh", + "target": "t20", + "overview_line": 396, + "detail_line": 948, + "overview_text": "\n## T20 · 同一工程系统内的相互适用\n\n继承义务适用于本系统的原则、方法、价值位置、能力报告和实现选择;实际规范内容进入其整体一致性理论。\n\n**前提与表示:** Inherited 固定 sharedContext,并包含已履行的生成、自反、原经验/推论/价值任务、范围、能力和选择。ownTheory 合并实际事实与各项适用 OwnNorm 内容;一致性约束该完整并集。\n\n**证明或检查:** inheritedMutualApplication 提取实际字段及完整内容/支持关系;inheritedCurrent 另行构造它们。两条实际自反规则均成为自身对象,评估器的修订检查报告其局部空样本缺陷。\n\n**限度:** 字段提取不从单一原则推出所有义务。采纳标记是独立事实,不能替代规范内容。要求样本的批评属于应用判准,不是对观察的普遍要求。\n\n**状态:** accepted (theorem). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3)\n\n[声明、证明与逐行解释](details.md#t20)\n\n\n", + "detail_text": "\n## T20 · 同一工程系统内的相互适用\n\n继承义务适用于本系统的原则、方法、价值位置、能力报告和实现选择;实际规范内容进入其整体一致性理论。\n\n**前提与表示:** Inherited 固定 sharedContext,并包含已履行的生成、自反、原经验/推论/价值任务、范围、能力和选择。ownTheory 合并实际事实与各项适用 OwnNorm 内容;一致性约束该完整并集。\n\n**证明或检查:** inheritedMutualApplication 提取实际字段及完整内容/支持关系;inheritedCurrent 另行构造它们。两条实际自反规则均成为自身对象,评估器的修订检查报告其局部空样本缺陷。\n\n**限度:** 字段提取不从单一原则推出所有义务。采纳标记是独立事实,不能替代规范内容。要求样本的批评属于应用判准,不是对观察的普遍要求。\n\n**状态:** accepted (theorem). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3)\n\n### `CoreReader.Engineering.inheritedMutualApplication`\n\n[leanified/CoreReader/Engineering/Integration.lean:420](#line-code-leanified-corereader-engineering-integration-lean-420) · theorem\n\n核心依赖: `propext`.\n\n```lean\ntheorem inheritedMutualApplication (ctx : Context) (chosen : Candidate)\n (inherited : Inherited ctx chosen) :\n generationSpecification engineeringPolicy ∧\n reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self\n (selfModel chosen).performed ∧\n (∀ principle, valueSpecification (governancePosition principle)) ∧\n capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen) ∧\n choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons ∧\n (∀ fact, inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact)) ∧\n (∀ norm, normApplies chosen norm → ownTheory chosen (ownNormClaim chosen norm)) ∧\n (∀ claim, ownTheory chosen claim → inferentialSpecification (ownFactPremises chosen) claim) ∧\n consistencySpecification (engineeringSnapshot .evolvable 0)\n (engineeringSnapshot chosen 1) true :=\n```\n\n### `CoreReader.Engineering.inheritedMutualCases`\n\n[leanified/CoreReader/Engineering/Integration.lean:442](#line-code-leanified-corereader-engineering-integration-lean-442) · case\n\n核心依赖: `propext`, `Classical.choice`, `Quot.sound`.\n\n```lean\ntheorem inheritedMutualCases :\n Inherited sharedContext .evolvable ∧\n valueSpecification (governancePosition .grounds) ∧\n capabilitySpecification (engineeringProcess .evolvable) (engineeringCapability .evolvable) ∧\n choiceSpecification chosenRequirements (chosenImplementation .evolvable) chosenReasons ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧\n (.generationRule : ReviewObject) ∈ (selfModel .evolvable).objects ∧\n (.assessmentRule : ReviewObject) ∈ (selfModel .evolvable).objects ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .assessmentRule, .revision⟩) = .counterexample :=\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-engineering-integration-lean-420", + "found": true + }, + { + "anchor": "line-code-leanified-corereader-engineering-integration-lean-442", + "found": true + } + ] + }, + { + "question": 6, + "language": "zh", + "target": "t34", + "overview_line": 648, + "detail_line": 1527, + "overview_text": "\n## T34 · 契约保持定理\n\n若所有指定范围内的观察相等,则指定契约保持;范围内观察改变会反驳同一契约的保持。\n\n**前提与表示:** contractPreservation 接收范围内普遍相等的前提。有限顺序/重试案例是独立检查,不自动提供该普遍前提。\n\n**证明或检查:** 定理将所给相等关系作为 PreservesOn 返回;changedObservationNotPreserved 将其应用到不同结果的输入。案例计算顺序变化、重试 3、受影响方及被排除输入 [99] 的差异。\n\n**限度:** 有限测试集通过不是普遍相等证明;保持判断始终保留指定范围。\n\n**状态:** accepted (theorem). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3)\n\n[声明、证明与逐行解释](details.md#t34)\n\n\n", + "detail_text": "\n## T34 · 契约保持定理\n\n若所有指定范围内的观察相等,则指定契约保持;范围内观察改变会反驳同一契约的保持。\n\n**前提与表示:** contractPreservation 接收范围内普遍相等的前提。有限顺序/重试案例是独立检查,不自动提供该普遍前提。\n\n**证明或检查:** 定理将所给相等关系作为 PreservesOn 返回;changedObservationNotPreserved 将其应用到不同结果的输入。案例计算顺序变化、重试 3、受影响方及被排除输入 [99] 的差异。\n\n**限度:** 有限测试集通过不是普遍相等证明;保持判断始终保留指定范围。\n\n**状态:** accepted (theorem). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3)\n\n### `CoreReader.Engineering.contractPreservation`\n\n[leanified/CoreReader/Engineering/Domain.lean:822](#line-code-leanified-corereader-engineering-domain-lean-822) · theorem\n\n核心依赖: none.\n\n```lean\ntheorem contractPreservation {Input Output : Type} (scope : Input → Prop)\n (old new : Input → Output) (observations : ∀ x, scope x → new x = old x) :\n PreservesOn scope old new := observations\n```\n\n### `CoreReader.Engineering.contractDistinctions`\n\n[leanified/CoreReader/Engineering/Domain.lean:853](#line-code-leanified-corereader-engineering-domain-lean-853) · case\n\n核心依赖: none.\n\n```lean\ntheorem contractDistinctions :\n PreservesFinite orderedUnique orderedRefactor ∧\n ¬ PreservesFinite orderedUnique sortedUnique ∧\n retry originalContract 3 = false ∧ retry revisedContract 3 = true ∧\n ¬ PreservesContractFinite originalContract revisedContract ∧\n affectedParties originalContract revisedContract = [\"queue consumer\", \"queue operator\"] ∧\n ¬ ContractChangeAccount originalContract revisedContract\n { normalRevision with affected := [\"queue consumer\"] } ∧\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-engineering-domain-lean-822", + "found": true + }, + { + "anchor": "line-code-leanified-corereader-engineering-domain-lean-853", + "found": true + } + ] + }, + { + "question": 6, + "language": "zh", + "target": "t39", + "overview_line": 738, + "detail_line": 1740, + "overview_text": "\n## T39 · 继承义务不强制附加优先\n\n在同一优先适用的持续语境内,presentSimple 选择满足每项已表示继承义务,却不采纳附加演化优先。\n\n**前提与表示:** 两选项均满足必要要求;演化优势、可信设计修订、继任者/代理路径及复杂度取舍在模型内真实成立。没有临时生命周期或成本让步逃逸。\n\n**证明或检查:** inheritedCurrent 为 presentSimple 构造完整继承义务。其实际采纳的简单性价值具有成本/工作理由及批评限度。领域规则要求 evolvable 或让步,而两者均被排除,因此 EvolutionPriority 为假。\n\n**限度:** 反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。\n\n**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3)\n\n[声明、证明与逐行解释](details.md#t39)\n\n\n", + "detail_text": "\n## T39 · 继承义务不强制附加优先\n\n在同一优先适用的持续语境内,presentSimple 选择满足每项已表示继承义务,却不采纳附加演化优先。\n\n**前提与表示:** 两选项均满足必要要求;演化优势、可信设计修订、继任者/代理路径及复杂度取舍在模型内真实成立。没有临时生命周期或成本让步逃逸。\n\n**证明或检查:** inheritedCurrent 为 presentSimple 构造完整继承义务。其实际采纳的简单性价值具有成本/工作理由及批评限度。领域规则要求 evolvable 或让步,而两者均被排除,因此 EvolutionPriority 为假。\n\n**限度:** 反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。\n\n**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3)\n\n### `CoreReader.Engineering.inheritedDoesNotEntailPriority`\n\n[leanified/CoreReader/Engineering/Integration.lean:586](#line-code-leanified-corereader-engineering-integration-lean-586) · case\n\n核心依赖: `propext`, `Classical.choice`, `Quot.sound`.\n\n```lean\ntheorem inheritedDoesNotEntailPriority :\n ∃ ctx : Context, ∃ chosen : Candidate,\n ctx = sharedContext ∧ chosen = .presentSimple ∧\n Inherited ctx chosen ∧ PriorityConditions ctx ∧\n Continuing ctx.activity ∧ ¬ BoundedLifecycle ctx.activity ∧\n ¬ HasThreat ctx .evolvable ∧ ¬ JustifiedDeparture ctx .evolvable ∧\n Meets ctx.required (ctx.profiles .presentSimple) ∧\n Meets ctx.required (ctx.profiles .evolvable) ∧\n credible ctx.evidence .designRevision ∧\n CanChange ctx.activity .evolvable .successor .designRevision ∧\n CanChange ctx.activity .evolvable .agent .designRevision ∧\n changeWork .evolvable .designRevision < changeWork chosen .designRevision ∧\n abstractionComplexity chosen < abstractionComplexity .evolvable ∧\n valueSpecification (selectionPosition chosen) ∧\n (selectionPosition chosen).commitment chosen ∧\n ¬ EvolutionPriority ctx chosen := by\n```\n\n\n", + "detail_link_found": true, + "line_anchors": [ + { + "anchor": "line-code-leanified-corereader-engineering-integration-lean-586", + "found": true + } + ] + }, + { + "question": 6, + "language": "zh", + "target": "t40", + "overview_line": 756, + "detail_line": 1781, + "overview_text": "\n## T40 · 形式证据不能建立什么\n\n受检规范、条件证明及具体见证,仍与经验适切性、充分现实根据及哲学采纳有别。\n\n**前提与表示:** 来源对应是单独记录的有界判断。成本、计划、历史、操作性理解及有限契约保留已披露的应用解释。\n\n**证明或检查:** 本稿绑定实际源文、代码、类型和依赖对象,以及独立初稿与后续修复。先前失败或不完整对象不会被改称成功的历史执行。\n\n**限度:** 构建成功、来源追溯、代理一致和自我适用不证明哲学正确性;没有为取得完成状态而删除冻结可证明目标或将其改为边界。\n\n**状态:** accepted (boundary). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [organon.preamble#p1](#source-organon-preamble-p1), [organon.preamble#p2](#source-organon-preamble-p2), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.grounds#p1](#source-organon-grounds-p1), [organon.grounds.assessment#p1](#source-organon-grounds-assessment-p1), [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3), [organon.grounds.scope#p2](#source-organon-grounds-scope-p2), [organon.grounds.scope#p3](#source-organon-grounds-scope-p3), [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2), [organon.grounds.implementations#p1](#source-organon-grounds-implementations-p1), [organon.grounds.implementations#p2](#source-organon-grounds-implementations-p2), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.purpose#p1](#source-software-engineering-purpose-p1), [software-engineering.purpose#p2](#source-software-engineering-purpose-p2), [software-engineering.purpose#p3](#source-software-engineering-purpose-p3), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3), [software-engineering.evolution-meaning#p1](#source-software-engineering-evolution-meaning-p1), [software-engineering.evolution-meaning#p2](#source-software-engineering-evolution-meaning-p2), [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2), [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3), [software-engineering.revision#p1](#source-software-engineering-revision-p1), [software-engineering.revision#p2](#source-software-engineering-revision-p2)\n\n[声明、证明与逐行解释](details.md#t40)\n\n\n## 来源追溯附录\n\n\n\n\n### `organon.preamble#p1`\n\n```text\nThis is a statement of Software Engineering Organon’s adopted philosophy. It expresses commitments, not factual assertions about every system or a proof of universal correctness.\n```\n\n状态: **not_applicable**; Lean: not_checked; 来源保真: not_applicable.\n\n此段保留文献权威、解释角色或已说明边界,不分配形式证明。\n\n相关目标: [T01](#t01), [T40](#t40).\n\n\n\n\n\n\n### `organon.preamble#p2`\n\n```text\nThe quoted provisions, their meanings, and their conditions of application form the core. The charter and Grounds constrain one another; their grouping establishes neither a deductive hierarchy nor an order of priority. [Rationale](docs/rationale.md) supplies arguments and cases without adding obligations to this core. Skills are revisable applications under the repository’s stated objectives and constraints, not part of the philosophical commitments themselves.\n```\n\n状态: **not_applicable**; Lean: not_checked; 来源保真: not_applicable.\n\n此段保留文献权威、解释角色或已说明边界,不分配形式证明。\n\n相关目标: [T01](#t01), [T40](#t40).\n\n\n\n\n\n\n### `organon.charter`\n\n```text\n\n\n```\n\n状态: **not_applicable**; Lean: not_checked; 来源保真: not_applicable.\n\n空标题只保留结构,不分配定理。\n\n\n\n\n\n\n### `organon.charter.overview#p1`\n\n```text\n**Self-Transcendence · Internal Consistency · Reflexivity**\n```\n\n状态: **not_applicable**; Lean: not_checked; 来源保真: not_applicable.\n\n此段保留文献权威、解释角色或已说明边界,不分配形式证明。\n\n相关目标: [T01](#t01).\n\n\n\n\n\n\n### `organon.charter.overview#p2`\n\n```text\n> A system is intrinsically oriented toward expanding what it can understand and construct. It brings itself and its principles within the scope of generation and assessment, with internal consistency constraining this process.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T02、T38 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T01](#t01), [T02](#t02), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.overview#p3`\n\n```text\nThe overview connects three distinct requirements: self-transcendence establishes a generative orientation and refuses to treat existing forms as final, internal consistency constrains judgments held simultaneously, and reflexivity brings the system and its principles within the scope of their own generation and assessment. The provisions below specify the conditions for each.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T02、T38 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T01](#t01), [T02](#t02), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.self-transcendence#p1`\n\n```text\n> A system is intrinsically oriented toward expanding what it can understand and construct. It does not regard any existing form as the endpoint of generation.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T02、T38 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T02](#t02), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.self-transcendence.orientation#p1`\n\n```text\nA commitment to keeping generative possibilities open is distinct from valuing their expansion. A system has an intrinsic orientation when it regards that expansion as worth pursuing. Merely permitting change does not fully express this orientation.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T02、T03、T38 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。这些是具体不蕴涵结果及有限支持案例,不是学习或自主执行的经验预测。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T02](#t02), [T03](#t03), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.self-transcendence.non-finality#p1`\n\n```text\nRefusing to regard an existing form as an endpoint keeps it open to being surpassed. “Existing form” includes a system’s current organization, methods, and principles, not only its appearance or artifacts. These remain within the scope of possible change; their revisability does not guarantee actual progress.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T02、T03、T38 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。这些是具体不蕴涵结果及有限支持案例,不是学习或自主执行的经验预测。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T02](#t02), [T03](#t03), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.self-transcendence.limits#p1`\n\n```text\nWhether progress has actually occurred remains a separate judgment. Having the orientation does not guarantee progress. Progress cannot be established merely by an increase in the number of artifacts, levels of abstraction, or terms.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T03、T38 作受限对应。这些是具体不蕴涵结果及有限支持案例,不是学习或自主执行的经验预测。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T03](#t03), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.self-transcendence.limits#p2`\n\n```text\n- “Intrinsic orientation” expresses Organon’s philosophical commitment; it does not assert that all systems in fact develop autonomously.\n- Self-transcendence does not imply independence from external experience, knowledge, or collaboration, nor does it guarantee autonomous execution or self-improvement.\n- Refusing to regard an existing form as an endpoint does not require every action to produce change. Justified stability can coexist with a generative orientation.\n- Whether transcendence expands what can be understood and constructed requires discernible grounds; a system’s own claim of generation does not establish actual achievement.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T02、T03、T38 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。这些是具体不蕴涵结果及有限支持案例,不是学习或自主执行的经验预测。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T02](#t02), [T03](#t03), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.charter.consistency#p1`\n\n```text\n> The principles and judgments a system holds simultaneously, together with their implications, must not yield contradictory judgments on the same question under the same assumptions, meanings of terms, and scope of application.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T04、T05、T38 作受限对应。一般接口在空问题域中可能空泛成立;工程实例使用非空问题族和实际可容许选项。结果不要求与已撤回主张永久相容,也未识别所有可能掩盖修订的文字遗漏。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T04](#t04), [T05](#t05), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.consistency.meaning#p1`\n\n```text\n“Held simultaneously” specifies which principles, judgments, and implications must hold together. Revision may withdraw an earlier judgment; old and new principles need not remain compatible forever. When a change has occurred, that change cannot be represented as though it had not occurred.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T04、T05、T38 作受限对应。一般接口在空问题域中可能空泛成立;工程实例使用非空问题族和实际可容许选项。结果不要求与已撤回主张永久相容,也未识别所有可能掩盖修订的文字遗漏。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T04](#t04), [T05](#t05), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.consistency.meaning#p2`\n\n```text\n“The same assumptions, meanings of terms, and scope of application” specifies the basis for comparing judgments. Divergent judgments under different conditions do not automatically constitute contradictions. Nor can unacknowledged changes in assumptions, meanings, or scope be used to conceal an existing contradiction.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T04、T05、T06、T38 作受限对应。一般接口在空问题域中可能空泛成立;工程实例使用非空问题族和实际可容许选项。结果不要求与已撤回主张永久相容,也未识别所有可能掩盖修订的文字遗漏。一致性不是充分的经验或价值支持;反例只涉及已披露的数学表示。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T04](#t04), [T05](#t05), [T06](#t06), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.consistency.limits#p1`\n\n```text\n- Tension between different assessments or values does not directly constitute a contradiction. Revision or qualification is needed when they require incompatible conclusions under the same conditions.\n- Internal consistency is not correctness or sufficiency. A set of principles may be internally consistent while relying on false assumptions or neglecting important questions.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T04、T05、T06、T38 作受限对应。一般接口在空问题域中可能空泛成立;工程实例使用非空问题族和实际可容许选项。结果不要求与已撤回主张永久相容,也未识别所有可能掩盖修订的文字遗漏。一致性不是充分的经验或价值支持;反例只涉及已披露的数学表示。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T04](#t04), [T05](#t05), [T06](#t06), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.reflexivity#p1`\n\n```text\n> A system’s principles of generation and assessment also apply to the system itself and to the formation, application, and revision of those principles.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T07、T38 作受限对应。一般输入谓词仍需解释;非空具体对象及实际记录建立模型内义务履行,不建立普遍自我证明。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T07](#t07), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.reflexivity.meaning#p1`\n\n```text\nReflexivity encompasses both the system itself and its principles. Assessment concerns not only whether the system conforms to its principles, but also how those principles are formed, where they apply, and why they may need revision. The formation and revision of principles thus also become objects of generation and assessment.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T07、T38 作受限对应。一般输入谓词仍需解释;非空具体对象及实际记录建立模型内义务履行,不建立普遍自我证明。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T07](#t07), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.reflexivity.limits#p1`\n\n```text\n- Applying principles equally retains their conditions of application. When the relevant conditions hold, being the system itself is not a basis for exemption. Nor does the requirement of reflexivity establish that every principle can be applied to itself without examining its applicability.\n- Self-application does not constitute self-proof. Subjecting a principle to its own assessment does not thereby establish its correctness.\n- That a revision is produced by the system itself does not give it sufficient grounds.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T07、T08、T38 作受限对应。一般输入谓词仍需解释;非空具体对象及实际记录建立模型内义务履行,不建立普遍自我证明。此有限反模型不证明所有可能编码中的独立性;保持形式开放也不能替代实际自反工作。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T07](#t07), [T08](#t08), [T38](#t38).\n\n\n\n\n\n\n### `organon.grounds#p1`\n\n```text\n> The grounds of principles and judgments must be articulable and subject to assessment appropriate to the nature of the claim. The strength and scope of a claim must be proportionate to the support provided by its grounds.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T08、T09、T38 作受限对应。此有限反模型不证明所有可能编码中的独立性;保持形式开放也不能替代实际自反工作。这是已声明任务的充分有限适配,不是穷尽分类,也未导入 Core 0.1.3 的全方面覆盖。声明新任务不授权替换已固定任务。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T08](#t08), [T09](#t09), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.assessment#p1`\n\n```text\nArticulation and assessment have distinct responsibilities. Articulability requires that concepts, assumptions, reasons, and limits can be identified. Assessment requires examining whether those grounds support the corresponding claim. Clearly expressed grounds are not thereby sufficiently established.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T09、T13、T38 作受限对应。这是已声明任务的充分有限适配,不是穷尽分类,也未导入 Core 0.1.3 的全方面覆盖。声明新任务不授权替换已固定任务。这些区分不要求把价值、经验证据和推论化为同一分数。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T09](#t09), [T13](#t13), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.assessment#p2`\n\n```text\n| Type of claim | Responsibility of assessment | What cannot substitute for that responsibility |\n| --- | --- | --- |\n| Empirical claim | Examine observations, evidence, and performance, together with the conditions, scope, and uncertainty of their support for the claim. | Treating measurability or repeatability itself as proof of relevance, correctness, or value. |\n| Inferential claim | Examine whether the conclusion is supported by the stated assumptions and inferential relations. | Treating the absence of conflict between a conclusion and its assumptions as sufficient to establish that the conclusion follows from them. |\n| Value commitment | State the position taken, its reasons, limits of application, and consequences, and remain open to relevant criticism. | Presenting a commitment as an empirical fact or a necessary inference, or substituting self-assertion for reasons. |\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T09、T10、T11、T12、T13、T38 作受限对应。这是已声明任务的充分有限适配,不是穷尽分类,也未导入 Core 0.1.3 的全方面覆盖。声明新任务不授权替换已固定任务。重复性或可测性本身不建立相关性、正确性或价值;未观察结果不同不必违背有限支持。缺少支持不等于评估做错;与假设相容弱于从假设得到蕴涵。应用给出充分的价值评估构造,不是证明所有初始假设的普遍要求,也不证明某价值普遍最优。这些区分不要求把价值、经验证据和推论化为同一分数。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T09](#t09), [T10](#t10), [T11](#t11), [T12](#t12), [T13](#t13), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.assessment#p3`\n\n```text\nInitial value commitments may be stated explicitly as commitments; they need not prove all their own starting assumptions. The strength and scope of a claim do not require conversion to a common numerical scale. Different types of claims specify their support and limits in accordance with their nature.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T09、T12、T13、T38 作受限对应。这是已声明任务的充分有限适配,不是穷尽分类,也未导入 Core 0.1.3 的全方面覆盖。声明新任务不授权替换已固定任务。应用给出充分的价值评估构造,不是证明所有初始假设的普遍要求,也不证明某价值普遍最优。这些区分不要求把价值、经验证据和推论化为同一分数。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T09](#t09), [T12](#t12), [T13](#t13), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.scope#p1`\n\n```text\nPerformance is discerned within particular relations, conditions, and scopes of observation. A boundary helps specify what a comparison concerns, but local examples do not automatically support unconditional universal conclusions. A judgment cannot establish that relevant differences do not exist merely because its chosen scope omits them.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T14、T15、T38 作受限对应。角色字符串非空本身不是充分解释;未使用的方法也不会因此成为必需。把某输入排除出比较,不是该处不存在相关差异的证据。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T14](#t14), [T15](#t15), [T38](#t38).\n\n\n\n\n\n\n### `organon.grounds.scope#p2`\n\n```text\nMeasurement can make some differences comparable. Repeated assessment can help examine the stability of corresponding conclusions. Their roles, and the role of any assessment framework, must be explained relative to the claim and its context. Measurement, repeatability, and an assessment framework do not form a universally necessary chain on which all judgments must depend.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T14、T15、T38 作受限对应。角色字符串非空本身不是充分解释;未使用的方法也不会因此成为必需。把某输入排除出比较,不是该处不存在相关差异的证据。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T14](#t14), [T15](#t15), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.scope#p3`\n\n```text\nAn observation that has not been reproduced may still offer limited support, and random outcomes need not be identical on every occasion. The verifiability of observations, reproducibility of conditions, and stability of conclusions must be distinguished.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T14、T15、T38 作受限对应。角色字符串非空本身不是充分解释;未使用的方法也不会因此成为必需。把某输入排除出比较,不是该处不存在相关差异的证据。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T14](#t14), [T15](#t15), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.capabilities#p1`\n\n```text\nCapability claims are subject to Grounds: the capability claimed, its conditions, and the support for it must be identifiable. The core does not prescribe uniform definitions of method mastery, method generation, or capability levels. Applications specify the capabilities they assess and may require understanding, explanation, or performance under relevant variations.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T16、T17、T38 作受限对应。这不是心理理解的普遍定义。精确身份是范围前提;履行支持责任的是实际契约证明,而非身份本身。外部评估者可以支持所选输出主张,而不建立被评系统如何理解自身生成过程。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T16](#t16), [T17](#t17), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.capabilities#p2`\n\n```text\nGrounds for a capability claim may be supplied by an external assessor. Their articulability does not by itself require the assessed system to understand or explain its internal generation process. Evidence of reliable output must be assessed against the capability actually claimed; it does not automatically establish understanding of that process. Nor can the number of method documents, terms, tools, or artifacts alone establish a capability beyond what that evidence supports.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T16、T17、T38 作受限对应。这不是心理理解的普遍定义。精确身份是范围前提;履行支持责任的是实际契约证明,而非身份本身。外部评估者可以支持所选输出主张,而不建立被评系统如何理解自身生成过程。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T16](#t16), [T17](#t17), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.implementations#p1`\n\n```text\n> The choice of an implementation must be supported by reasons connected to the objectives and values pursued and to the relevant constraints. Its name, conventional use, or established status alone does not provide sufficient grounds for giving it priority.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T18、T19、T38 作受限对应。这些是应用理由,不是普遍成本函数,也不要求惯用实现必须落选。没有结果断言所有实现等价、保证多个可行实现,或从章节位置推出选择承诺。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T18](#t18), [T19](#t19), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.implementations#p2`\n\n```text\nThis choice provision adds an additional evaluative commitment: name, conventional use, or established status alone is insufficient to establish priority. Grouping it under Grounds does not mean that it follows from the general requirement to assess reasons, or merely from the discernibility of performance. Conventions and existing arrangements may have practical significance, but that significance must be connected to the objectives and values pursued and to the relevant constraints.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T18、T19、T38 作受限对应。这些是应用理由,不是普遍成本函数,也不要求惯用实现必须落选。没有结果断言所有实现等价、保证多个可行实现,或从章节位置推出选择承诺。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T18](#t18), [T19](#t19), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.implementations.limits#p1`\n\n```text\n- Openness does not make all implementations equivalent, nor does it guarantee multiple feasible implementations for the same objective.\n- A method’s explanatory power, limits of application, simplicity, and explicit process requirements may all provide grounded reasons for assessment. They cannot be excluded merely because they concern methods internal to the implementation.\n- Identical local performance does not establish overall equivalence. Relations, conditions, and the scope of comparison are constrained by the provisions of Grounds.\n- Openness does not reject an implementation merely because it already exists or is conventionally used. Relevant reasons may still give it priority.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T15、T18、T19、T38 作受限对应。把某输入排除出比较,不是该处不存在相关差异的证据。这些是应用理由,不是普遍成本函数,也不要求惯用实现必须落选。没有结果断言所有实现等价、保证多个可行实现,或从章节位置推出选择承诺。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T15](#t15), [T18](#t18), [T19](#t19), [T38](#t38).\n\n\n\n\n\n\n### `organon.relationships`\n\n```text\n\n\n```\n\n状态: **not_applicable**; Lean: not_checked; 来源保真: not_applicable.\n\n空标题只保留结构,不分配定理。\n\n\n\n\n\n\n### `organon.relationships.roles#p1`\n\n```text\nThe charter states the generative orientation, the consistency constraint, and reflexive application. Grounds specifies support requirements for judgments and includes an additional commitment concerning implementation choices. Both parts belong to the core and constrain one another. Their placement neither makes Grounds a deduction from the charter nor gives the charter priority over it. Each commitment needs its own reasons.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T08、T20、T38、T39 作受限对应。此有限反模型不证明所有可能编码中的独立性;保持形式开放也不能替代实际自反工作。字段提取不从单一原则推出所有义务。采纳标记是独立事实,不能替代规范内容。要求样本的批评属于应用判准,不是对观察的普遍要求。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。\n\n相关目标: [T01](#t01), [T08](#t08), [T20](#t20), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `organon.relationships.roles#p2`\n\n```text\nInternal Consistency concerns whether simultaneously held judgments can hold together; Grounds concerns whether and how far a claim is supported. A conclusion may fail to conflict with its assumptions without being supported by them. Self-Transcendence specifies a generative orientation and non-finality; neither establishes actual capability. Applications may supply objectives, values, and capability definitions; claims made under those objectives, values, and definitions remain subject to the relevant core provisions.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T03、T06、T11、T16、T20、T38、T39 作受限对应。这些是具体不蕴涵结果及有限支持案例,不是学习或自主执行的经验预测。一致性不是充分的经验或价值支持;反例只涉及已披露的数学表示。缺少支持不等于评估做错;与假设相容弱于从假设得到蕴涵。这不是心理理解的普遍定义。精确身份是范围前提;履行支持责任的是实际契约证明,而非身份本身。字段提取不从单一原则推出所有义务。采纳标记是独立事实,不能替代规范内容。要求样本的批评属于应用判准,不是对观察的普遍要求。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。\n\n相关目标: [T03](#t03), [T06](#t06), [T11](#t11), [T16](#t16), [T20](#t20), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `organon.relationships.roles#p3`\n\n```text\nSelf-Transcendence does not substitute for Reflexivity: keeping existing forms open to being surpassed differs from applying relevant principles to the system and to their own formation, application, and revision. Reflexivity extends these requirements to the system and to the formation, application, and revision of its principles. The grounds and limits of the Grounds provisions must themselves be articulable. The system’s own capability claims remain subject to assessment, and this philosophy’s existing form cannot gain priority merely from its established status. Such mutual application provides no self-proof and does not remove conditions of application.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T07、T08、T16、T18、T20、T37、T38、T39 作受限对应。一般输入谓词仍需解释;非空具体对象及实际记录建立模型内义务履行,不建立普遍自我证明。此有限反模型不证明所有可能编码中的独立性;保持形式开放也不能替代实际自反工作。这不是心理理解的普遍定义。精确身份是范围前提;履行支持责任的是实际契约证明,而非身份本身。这些是应用理由,不是普遍成本函数,也不要求惯用实现必须落选。字段提取不从单一原则推出所有义务。采纳标记是独立事实,不能替代规范内容。要求样本的批评属于应用判准,不是对观察的普遍要求。成功自评既不证明优先原则普遍正确,也不建立普遍样本要求。空样本批评适用于声明的局部评估契约。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。\n\n相关目标: [T07](#t07), [T08](#t08), [T16](#t16), [T18](#t18), [T20](#t20), [T37](#t37), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `organon.relationships.terms#p1`\n\n```text\n| Term | Meaning in this philosophy |\n| --- | --- |\n| Existing form | The system’s current organization, methods, and principles, not only its appearance or artifacts. |\n| Assessment | Examination of reasons, applicability, and observed performance; not limited to executable tests. |\n```\n\n状态: **incomplete**; Lean: passed; 来源保真: partial.\n\n来源与 T02 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。\n\n相关目标: [T02](#t02), [T21](#t21).\n\n\n\n\n\n\n### `extensions#p1`\n\n```text\nThis chapter adds a software engineering commitment and specifies its meaning and limits. It does not claim that this commitment follows from the Charter or Grounds. Those provisions remain adopted and constrain its application.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T37、T38、T39 作受限对应。成功自评既不证明优先原则普遍正确,也不建立普遍样本要求。空样本批评适用于声明的局部评估契约。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。\n\n相关目标: [T01](#t01), [T37](#t37), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.purpose#p1`\n\n```text\nSoftware engineering concerns the construction, operation, understanding, and revision of software within its relevant human and technical conditions. This philosophy guides decisions by people and agents; it does not attribute an intrinsic orientation to every software artifact.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T22、T23、T38 作受限对应。这些数量是有限模型数据,不是项目工期估算。处于范围内本身不证明每位参与者都能完成每种变化。结果涉及已表示路径;缺少某条文档化路径,不是所有维护方式均不可能的普遍定理。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T22](#t22), [T23](#t23), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.purpose#p2`\n\n```text\nThe evolution capability considered here belongs to the continuing engineering activity: maintainers, including successor maintainers and agents, working with software, tools, and available knowledge. Code that its original author can modify is not on that ground alone shown to support that continuing activity.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T22、T23、T38 作受限对应。这些数量是有限模型数据,不是项目工期估算。处于范围内本身不证明每位参与者都能完成每种变化。结果涉及已表示路径;缺少某条文档化路径,不是所有维护方式均不可能的普遍定理。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T22](#t22), [T23](#t23), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.purpose#p3`\n\n```text\nApply the following priority according to the software's credible lifecycle and maintenance expectations. A genuinely temporary script, bounded prototype, or retiring system may have little reason to support further evolution. Calling a continuing system temporary does not establish that condition.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T22、T23、T24、T38 作受限对应。这些数量是有限模型数据,不是项目工期估算。处于范围内本身不证明每位参与者都能完成每种变化。结果涉及已表示路径;缺少某条文档化路径,不是所有维护方式均不可能的普遍定理。这里表达并例示默认价值优先,不从 Core 演绎该优先,也不要求最大扩展性。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T22](#t22), [T23](#t23), [T24](#t24), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.evolution-priority#p1`\n\n```text\n> When relevant behavioral, safety, performance, and other necessary requirements are satisfied, give priority to continuing maintainers' ability to make credible future changes, including changes to the design itself, over present abstraction simplicity. Accept additional present abstraction complexity for that purpose, while allowing this preference to yield when the added costs threaten concrete engineering objectives.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T24、T25、T38、T39 作受限对应。这里表达并例示默认价值优先,不从 Core 演绎该优先,也不要求最大扩展性。定理不从事实证明价值规则,也不建立所有看似复杂的设计均具有相关优势。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。\n\n相关目标: [T24](#t24), [T25](#t25), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.evolution-priority#p2`\n\n```text\nCredible directions of change have articulable grounds, such as a committed plan, relevant domain knowledge, or an applicable history of change. They need not already have multiple implementations. Their credibility remains open to revision; a conceivable change alone does not establish that it warrants accommodation now.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T24、T25、T26、T27、T38、T39 作受限对应。这里表达并例示默认价值优先,不从 Core 演绎该优先,也不要求最大扩展性。定理不从事实证明价值规则,也不建立所有看似复杂的设计均具有相关优势。证明检查模型中给定的证据内容,不建立任意现实计划的可信性或预测校准程度。有限方向清单不证明所有未来变化可预测,也不证明遗漏可能性全都无关。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。\n\n相关目标: [T24](#t24), [T25](#t25), [T26](#t26), [T27](#t27), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.evolution-priority#p3`\n\n```text\nThis is a default priority, not an obligation to maximize extensibility or retain every possibility. Costs include relevant burdens of understanding, construction, diagnosis, verification, coordination, operation, and eventual migration. A departure from the priority identifies the objective threatened and why the costs matter. No universal numerical exchange rate between these considerations is prescribed.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T24、T25、T26、T27、T28、T38、T39 作受限对应。这里表达并例示默认价值优先,不从 Core 演绎该优先,也不要求最大扩展性。定理不从事实证明价值规则,也不建立所有看似复杂的设计均具有相关优势。证明检查模型中给定的证据内容,不建立任意现实计划的可信性或预测校准程度。有限方向清单不证明所有未来变化可预测,也不证明遗漏可能性全都无关。有限成本是模型中的工作与预算数据。源文不要求每类成本都适用,也不提供普遍数值取舍。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。\n\n相关目标: [T24](#t24), [T25](#t25), [T26](#t26), [T27](#t27), [T28](#t28), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.evolution-meaning#p1`\n\n```text\nEvolution includes adding capabilities, replacing implementations, deleting mechanisms, withdrawing abstractions, redrawing boundaries, and migrating away from an existing technology or model. Making additions within a fixed scheme does not establish equal ability to revise or leave that scheme. Not every such change can or should be made inexpensive.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T29、T30、T38 作受限对应。枚举构造子例示源文维度,并允许其他方向;它们不声称涵盖所有演化,也不声称每种变化廉价。这些反例排除无根据的跨维度推断,不新增所有变化都须廉价的义务。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T29](#t29), [T30](#t30), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.evolution-meaning#p2`\n\n```text\nAn evolution claim identifies the relevant changes and the maintainers' conditions. Independent changes, coordinated changes, preservation of existing obligations, and deliberate revision of those obligations can require different structures. A design's advantage on one dimension does not establish an advantage on every dimension.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T29、T30、T38 作受限对应。枚举构造子例示源文维度,并允许其他方向;它们不声称涵盖所有演化,也不声称每种变化廉价。这些反例排除无根据的跨维度推断,不新增所有变化都须廉价的义务。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T29](#t29), [T30](#t30), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.structural-judgment#p1`\n\n```text\nApply the preceding commitment to engineering consequences as a whole, including the relations among components, their observable contracts, and the work needed to understand and verify a change. An interface's shape, the number of modules or extension points, or the use of a named principle is not sufficient evidence of the claimed capability.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T31、T32、T37、T38 作受限对应。这些是相关的有限检查,不是普遍强制清单,也不是现实中所有边界成本的估算。等工作量案例通过实际路径变换保留步骤单位;这些单位是披露的模型度量,不是观测工程耗时。成功自评既不证明优先原则普遍正确,也不建立普遍样本要求。空样本批评适用于声明的局部评估契约。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T31](#t31), [T32](#t32), [T37](#t37), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.structural-judgment#p2`\n\n```text\nThe relevant comparison may examine how a change propagates, which knowledge and obligations cross a boundary, which assumptions become fixed, and what a later withdrawal would require. A proposed boundary needs support for the changes it is meant to accommodate; introducing it does not by itself show that those changes became easier.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T31、T32、T38 作受限对应。这些是相关的有限检查,不是普遍强制清单,也不是现实中所有边界成本的估算。等工作量案例通过实际路径变换保留步骤单位;这些单位是披露的模型度量,不是观测工程耗时。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T31](#t31), [T32](#t32), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.structural-judgment#p3`\n\n```text\nDistinguish a transformation that preserves an identified observable contract from one that deliberately revises that contract. The latter needs a corresponding account of changed obligations and affected parties. This distinction does not require preserving every historical behavior or using a particular testing or migration procedure.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T33、T34、T38 作受限对应。模型不要求保留所有历史行为、使用特定测试程序,也未新增普遍通知义务。有限测试集通过不是普遍相等证明;保持判断始终保留指定范围。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T33](#t33), [T34](#t34), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.revision#p1`\n\n```text\nChanged evidence about likely changes, maintenance conditions, costs, or objectives may justify revising a design or this priority's application. A revised judgment acknowledges material changes in its grounds; it does not make a failed prediction successful retrospectively.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T35、T36、T38 作受限对应。记录的历史是固定模型证据;定理不鉴定任意现实日志,也不证明所有批评回应均充分。结果允许有界的保留判断,不给予对后续根据或批评的永久豁免。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T35](#t35), [T36](#t36), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.revision#p2`\n\n```text\nRetaining a design can be justified when the relevant alternatives have no supported contribution or impose costs that defeat the objective. Reflexivity also keeps this engineering commitment and the methods used to assess evolution within the scope of criticism and revision. Continued change, agreement, or successful examples do not establish its universal correctness.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T35、T36、T37、T38 作受限对应。记录的历史是固定模型证据;定理不鉴定任意现实日志,也不证明所有批评回应均充分。结果允许有界的保留判断,不给予对后续根据或批评的永久豁免。成功自评既不证明优先原则普遍正确,也不建立普遍样本要求。空样本批评适用于声明的局部评估契约。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T35](#t35), [T36](#t36), [T37](#t37), [T38](#t38), [T40](#t40).\n\n\n\n", + "detail_text": "\n## T40 · 形式证据不能建立什么\n\n受检规范、条件证明及具体见证,仍与经验适切性、充分现实根据及哲学采纳有别。\n\n**前提与表示:** 来源对应是单独记录的有界判断。成本、计划、历史、操作性理解及有限契约保留已披露的应用解释。\n\n**证明或检查:** 本稿绑定实际源文、代码、类型和依赖对象,以及独立初稿与后续修复。先前失败或不完整对象不会被改称成功的历史执行。\n\n**限度:** 构建成功、来源追溯、代理一致和自我适用不证明哲学正确性;没有为取得完成状态而删除冻结可证明目标或将其改为边界。\n\n**状态:** accepted (boundary). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。\n\n**来源:** [organon.preamble#p1](#source-organon-preamble-p1), [organon.preamble#p2](#source-organon-preamble-p2), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.grounds#p1](#source-organon-grounds-p1), [organon.grounds.assessment#p1](#source-organon-grounds-assessment-p1), [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3), [organon.grounds.scope#p2](#source-organon-grounds-scope-p2), [organon.grounds.scope#p3](#source-organon-grounds-scope-p3), [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2), [organon.grounds.implementations#p1](#source-organon-grounds-implementations-p1), [organon.grounds.implementations#p2](#source-organon-grounds-implementations-p2), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.purpose#p1](#source-software-engineering-purpose-p1), [software-engineering.purpose#p2](#source-software-engineering-purpose-p2), [software-engineering.purpose#p3](#source-software-engineering-purpose-p3), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3), [software-engineering.evolution-meaning#p1](#source-software-engineering-evolution-meaning-p1), [software-engineering.evolution-meaning#p2](#source-software-engineering-evolution-meaning-p2), [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2), [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3), [software-engineering.revision#p1](#source-software-engineering-revision-p1), [software-engineering.revision#p2](#source-software-engineering-revision-p2)\n\n此边界目标没有 Lean 声明。\n\n\n## 来源追溯附录\n\n\n\n\n### `organon.preamble#p1`\n\n```text\nThis is a statement of Software Engineering Organon’s adopted philosophy. It expresses commitments, not factual assertions about every system or a proof of universal correctness.\n```\n\n状态: **not_applicable**; Lean: not_checked; 来源保真: not_applicable.\n\n此段保留文献权威、解释角色或已说明边界,不分配形式证明。\n\n相关目标: [T01](#t01), [T40](#t40).\n\n\n\n\n\n\n### `organon.preamble#p2`\n\n```text\nThe quoted provisions, their meanings, and their conditions of application form the core. The charter and Grounds constrain one another; their grouping establishes neither a deductive hierarchy nor an order of priority. [Rationale](docs/rationale.md) supplies arguments and cases without adding obligations to this core. Skills are revisable applications under the repository’s stated objectives and constraints, not part of the philosophical commitments themselves.\n```\n\n状态: **not_applicable**; Lean: not_checked; 来源保真: not_applicable.\n\n此段保留文献权威、解释角色或已说明边界,不分配形式证明。\n\n相关目标: [T01](#t01), [T40](#t40).\n\n\n\n\n\n\n### `organon.charter`\n\n```text\n\n\n```\n\n状态: **not_applicable**; Lean: not_checked; 来源保真: not_applicable.\n\n空标题只保留结构,不分配定理。\n\n\n\n\n\n\n### `organon.charter.overview#p1`\n\n```text\n**Self-Transcendence · Internal Consistency · Reflexivity**\n```\n\n状态: **not_applicable**; Lean: not_checked; 来源保真: not_applicable.\n\n此段保留文献权威、解释角色或已说明边界,不分配形式证明。\n\n相关目标: [T01](#t01).\n\n\n\n\n\n\n### `organon.charter.overview#p2`\n\n```text\n> A system is intrinsically oriented toward expanding what it can understand and construct. It brings itself and its principles within the scope of generation and assessment, with internal consistency constraining this process.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T02、T38 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T01](#t01), [T02](#t02), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.overview#p3`\n\n```text\nThe overview connects three distinct requirements: self-transcendence establishes a generative orientation and refuses to treat existing forms as final, internal consistency constrains judgments held simultaneously, and reflexivity brings the system and its principles within the scope of their own generation and assessment. The provisions below specify the conditions for each.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T02、T38 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T01](#t01), [T02](#t02), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.self-transcendence#p1`\n\n```text\n> A system is intrinsically oriented toward expanding what it can understand and construct. It does not regard any existing form as the endpoint of generation.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T02、T38 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T02](#t02), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.self-transcendence.orientation#p1`\n\n```text\nA commitment to keeping generative possibilities open is distinct from valuing their expansion. A system has an intrinsic orientation when it regards that expansion as worth pursuing. Merely permitting change does not fully express this orientation.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T02、T03、T38 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。这些是具体不蕴涵结果及有限支持案例,不是学习或自主执行的经验预测。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T02](#t02), [T03](#t03), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.self-transcendence.non-finality#p1`\n\n```text\nRefusing to regard an existing form as an endpoint keeps it open to being surpassed. “Existing form” includes a system’s current organization, methods, and principles, not only its appearance or artifacts. These remain within the scope of possible change; their revisability does not guarantee actual progress.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T02、T03、T38 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。这些是具体不蕴涵结果及有限支持案例,不是学习或自主执行的经验预测。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T02](#t02), [T03](#t03), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.self-transcendence.limits#p1`\n\n```text\nWhether progress has actually occurred remains a separate judgment. Having the orientation does not guarantee progress. Progress cannot be established merely by an increase in the number of artifacts, levels of abstraction, or terms.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T03、T38 作受限对应。这些是具体不蕴涵结果及有限支持案例,不是学习或自主执行的经验预测。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T03](#t03), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.self-transcendence.limits#p2`\n\n```text\n- “Intrinsic orientation” expresses Organon’s philosophical commitment; it does not assert that all systems in fact develop autonomously.\n- Self-transcendence does not imply independence from external experience, knowledge, or collaboration, nor does it guarantee autonomous execution or self-improvement.\n- Refusing to regard an existing form as an endpoint does not require every action to produce change. Justified stability can coexist with a generative orientation.\n- Whether transcendence expands what can be understood and constructed requires discernible grounds; a system’s own claim of generation does not establish actual achievement.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T02、T03、T38 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。这些是具体不蕴涵结果及有限支持案例,不是学习或自主执行的经验预测。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T02](#t02), [T03](#t03), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.charter.consistency#p1`\n\n```text\n> The principles and judgments a system holds simultaneously, together with their implications, must not yield contradictory judgments on the same question under the same assumptions, meanings of terms, and scope of application.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T04、T05、T38 作受限对应。一般接口在空问题域中可能空泛成立;工程实例使用非空问题族和实际可容许选项。结果不要求与已撤回主张永久相容,也未识别所有可能掩盖修订的文字遗漏。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T04](#t04), [T05](#t05), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.consistency.meaning#p1`\n\n```text\n“Held simultaneously” specifies which principles, judgments, and implications must hold together. Revision may withdraw an earlier judgment; old and new principles need not remain compatible forever. When a change has occurred, that change cannot be represented as though it had not occurred.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T04、T05、T38 作受限对应。一般接口在空问题域中可能空泛成立;工程实例使用非空问题族和实际可容许选项。结果不要求与已撤回主张永久相容,也未识别所有可能掩盖修订的文字遗漏。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T04](#t04), [T05](#t05), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.consistency.meaning#p2`\n\n```text\n“The same assumptions, meanings of terms, and scope of application” specifies the basis for comparing judgments. Divergent judgments under different conditions do not automatically constitute contradictions. Nor can unacknowledged changes in assumptions, meanings, or scope be used to conceal an existing contradiction.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T04、T05、T06、T38 作受限对应。一般接口在空问题域中可能空泛成立;工程实例使用非空问题族和实际可容许选项。结果不要求与已撤回主张永久相容,也未识别所有可能掩盖修订的文字遗漏。一致性不是充分的经验或价值支持;反例只涉及已披露的数学表示。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T04](#t04), [T05](#t05), [T06](#t06), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.consistency.limits#p1`\n\n```text\n- Tension between different assessments or values does not directly constitute a contradiction. Revision or qualification is needed when they require incompatible conclusions under the same conditions.\n- Internal consistency is not correctness or sufficiency. A set of principles may be internally consistent while relying on false assumptions or neglecting important questions.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T04、T05、T06、T38 作受限对应。一般接口在空问题域中可能空泛成立;工程实例使用非空问题族和实际可容许选项。结果不要求与已撤回主张永久相容,也未识别所有可能掩盖修订的文字遗漏。一致性不是充分的经验或价值支持;反例只涉及已披露的数学表示。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T04](#t04), [T05](#t05), [T06](#t06), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.reflexivity#p1`\n\n```text\n> A system’s principles of generation and assessment also apply to the system itself and to the formation, application, and revision of those principles.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T07、T38 作受限对应。一般输入谓词仍需解释;非空具体对象及实际记录建立模型内义务履行,不建立普遍自我证明。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T07](#t07), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.reflexivity.meaning#p1`\n\n```text\nReflexivity encompasses both the system itself and its principles. Assessment concerns not only whether the system conforms to its principles, but also how those principles are formed, where they apply, and why they may need revision. The formation and revision of principles thus also become objects of generation and assessment.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T07、T38 作受限对应。一般输入谓词仍需解释;非空具体对象及实际记录建立模型内义务履行,不建立普遍自我证明。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T07](#t07), [T38](#t38).\n\n\n\n\n\n\n### `organon.charter.reflexivity.limits#p1`\n\n```text\n- Applying principles equally retains their conditions of application. When the relevant conditions hold, being the system itself is not a basis for exemption. Nor does the requirement of reflexivity establish that every principle can be applied to itself without examining its applicability.\n- Self-application does not constitute self-proof. Subjecting a principle to its own assessment does not thereby establish its correctness.\n- That a revision is produced by the system itself does not give it sufficient grounds.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T07、T08、T38 作受限对应。一般输入谓词仍需解释;非空具体对象及实际记录建立模型内义务履行,不建立普遍自我证明。此有限反模型不证明所有可能编码中的独立性;保持形式开放也不能替代实际自反工作。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T07](#t07), [T08](#t08), [T38](#t38).\n\n\n\n\n\n\n### `organon.grounds#p1`\n\n```text\n> The grounds of principles and judgments must be articulable and subject to assessment appropriate to the nature of the claim. The strength and scope of a claim must be proportionate to the support provided by its grounds.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T08、T09、T38 作受限对应。此有限反模型不证明所有可能编码中的独立性;保持形式开放也不能替代实际自反工作。这是已声明任务的充分有限适配,不是穷尽分类,也未导入 Core 0.1.3 的全方面覆盖。声明新任务不授权替换已固定任务。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T08](#t08), [T09](#t09), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.assessment#p1`\n\n```text\nArticulation and assessment have distinct responsibilities. Articulability requires that concepts, assumptions, reasons, and limits can be identified. Assessment requires examining whether those grounds support the corresponding claim. Clearly expressed grounds are not thereby sufficiently established.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T09、T13、T38 作受限对应。这是已声明任务的充分有限适配,不是穷尽分类,也未导入 Core 0.1.3 的全方面覆盖。声明新任务不授权替换已固定任务。这些区分不要求把价值、经验证据和推论化为同一分数。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T09](#t09), [T13](#t13), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.assessment#p2`\n\n```text\n| Type of claim | Responsibility of assessment | What cannot substitute for that responsibility |\n| --- | --- | --- |\n| Empirical claim | Examine observations, evidence, and performance, together with the conditions, scope, and uncertainty of their support for the claim. | Treating measurability or repeatability itself as proof of relevance, correctness, or value. |\n| Inferential claim | Examine whether the conclusion is supported by the stated assumptions and inferential relations. | Treating the absence of conflict between a conclusion and its assumptions as sufficient to establish that the conclusion follows from them. |\n| Value commitment | State the position taken, its reasons, limits of application, and consequences, and remain open to relevant criticism. | Presenting a commitment as an empirical fact or a necessary inference, or substituting self-assertion for reasons. |\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T09、T10、T11、T12、T13、T38 作受限对应。这是已声明任务的充分有限适配,不是穷尽分类,也未导入 Core 0.1.3 的全方面覆盖。声明新任务不授权替换已固定任务。重复性或可测性本身不建立相关性、正确性或价值;未观察结果不同不必违背有限支持。缺少支持不等于评估做错;与假设相容弱于从假设得到蕴涵。应用给出充分的价值评估构造,不是证明所有初始假设的普遍要求,也不证明某价值普遍最优。这些区分不要求把价值、经验证据和推论化为同一分数。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T09](#t09), [T10](#t10), [T11](#t11), [T12](#t12), [T13](#t13), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.assessment#p3`\n\n```text\nInitial value commitments may be stated explicitly as commitments; they need not prove all their own starting assumptions. The strength and scope of a claim do not require conversion to a common numerical scale. Different types of claims specify their support and limits in accordance with their nature.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T09、T12、T13、T38 作受限对应。这是已声明任务的充分有限适配,不是穷尽分类,也未导入 Core 0.1.3 的全方面覆盖。声明新任务不授权替换已固定任务。应用给出充分的价值评估构造,不是证明所有初始假设的普遍要求,也不证明某价值普遍最优。这些区分不要求把价值、经验证据和推论化为同一分数。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T09](#t09), [T12](#t12), [T13](#t13), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.scope#p1`\n\n```text\nPerformance is discerned within particular relations, conditions, and scopes of observation. A boundary helps specify what a comparison concerns, but local examples do not automatically support unconditional universal conclusions. A judgment cannot establish that relevant differences do not exist merely because its chosen scope omits them.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T14、T15、T38 作受限对应。角色字符串非空本身不是充分解释;未使用的方法也不会因此成为必需。把某输入排除出比较,不是该处不存在相关差异的证据。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T14](#t14), [T15](#t15), [T38](#t38).\n\n\n\n\n\n\n### `organon.grounds.scope#p2`\n\n```text\nMeasurement can make some differences comparable. Repeated assessment can help examine the stability of corresponding conclusions. Their roles, and the role of any assessment framework, must be explained relative to the claim and its context. Measurement, repeatability, and an assessment framework do not form a universally necessary chain on which all judgments must depend.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T14、T15、T38 作受限对应。角色字符串非空本身不是充分解释;未使用的方法也不会因此成为必需。把某输入排除出比较,不是该处不存在相关差异的证据。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T14](#t14), [T15](#t15), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.scope#p3`\n\n```text\nAn observation that has not been reproduced may still offer limited support, and random outcomes need not be identical on every occasion. The verifiability of observations, reproducibility of conditions, and stability of conclusions must be distinguished.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T14、T15、T38 作受限对应。角色字符串非空本身不是充分解释;未使用的方法也不会因此成为必需。把某输入排除出比较,不是该处不存在相关差异的证据。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T14](#t14), [T15](#t15), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.capabilities#p1`\n\n```text\nCapability claims are subject to Grounds: the capability claimed, its conditions, and the support for it must be identifiable. The core does not prescribe uniform definitions of method mastery, method generation, or capability levels. Applications specify the capabilities they assess and may require understanding, explanation, or performance under relevant variations.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T16、T17、T38 作受限对应。这不是心理理解的普遍定义。精确身份是范围前提;履行支持责任的是实际契约证明,而非身份本身。外部评估者可以支持所选输出主张,而不建立被评系统如何理解自身生成过程。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T16](#t16), [T17](#t17), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.capabilities#p2`\n\n```text\nGrounds for a capability claim may be supplied by an external assessor. Their articulability does not by itself require the assessed system to understand or explain its internal generation process. Evidence of reliable output must be assessed against the capability actually claimed; it does not automatically establish understanding of that process. Nor can the number of method documents, terms, tools, or artifacts alone establish a capability beyond what that evidence supports.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T16、T17、T38 作受限对应。这不是心理理解的普遍定义。精确身份是范围前提;履行支持责任的是实际契约证明,而非身份本身。外部评估者可以支持所选输出主张,而不建立被评系统如何理解自身生成过程。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T16](#t16), [T17](#t17), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.implementations#p1`\n\n```text\n> The choice of an implementation must be supported by reasons connected to the objectives and values pursued and to the relevant constraints. Its name, conventional use, or established status alone does not provide sufficient grounds for giving it priority.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T18、T19、T38 作受限对应。这些是应用理由,不是普遍成本函数,也不要求惯用实现必须落选。没有结果断言所有实现等价、保证多个可行实现,或从章节位置推出选择承诺。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T18](#t18), [T19](#t19), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.implementations#p2`\n\n```text\nThis choice provision adds an additional evaluative commitment: name, conventional use, or established status alone is insufficient to establish priority. Grouping it under Grounds does not mean that it follows from the general requirement to assess reasons, or merely from the discernibility of performance. Conventions and existing arrangements may have practical significance, but that significance must be connected to the objectives and values pursued and to the relevant constraints.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T18、T19、T38 作受限对应。这些是应用理由,不是普遍成本函数,也不要求惯用实现必须落选。没有结果断言所有实现等价、保证多个可行实现,或从章节位置推出选择承诺。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T18](#t18), [T19](#t19), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `organon.grounds.implementations.limits#p1`\n\n```text\n- Openness does not make all implementations equivalent, nor does it guarantee multiple feasible implementations for the same objective.\n- A method’s explanatory power, limits of application, simplicity, and explicit process requirements may all provide grounded reasons for assessment. They cannot be excluded merely because they concern methods internal to the implementation.\n- Identical local performance does not establish overall equivalence. Relations, conditions, and the scope of comparison are constrained by the provisions of Grounds.\n- Openness does not reject an implementation merely because it already exists or is conventionally used. Relevant reasons may still give it priority.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T15、T18、T19、T38 作受限对应。把某输入排除出比较,不是该处不存在相关差异的证据。这些是应用理由,不是普遍成本函数,也不要求惯用实现必须落选。没有结果断言所有实现等价、保证多个可行实现,或从章节位置推出选择承诺。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T15](#t15), [T18](#t18), [T19](#t19), [T38](#t38).\n\n\n\n\n\n\n### `organon.relationships`\n\n```text\n\n\n```\n\n状态: **not_applicable**; Lean: not_checked; 来源保真: not_applicable.\n\n空标题只保留结构,不分配定理。\n\n\n\n\n\n\n### `organon.relationships.roles#p1`\n\n```text\nThe charter states the generative orientation, the consistency constraint, and reflexive application. Grounds specifies support requirements for judgments and includes an additional commitment concerning implementation choices. Both parts belong to the core and constrain one another. Their placement neither makes Grounds a deduction from the charter nor gives the charter priority over it. Each commitment needs its own reasons.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T08、T20、T38、T39 作受限对应。此有限反模型不证明所有可能编码中的独立性;保持形式开放也不能替代实际自反工作。字段提取不从单一原则推出所有义务。采纳标记是独立事实,不能替代规范内容。要求样本的批评属于应用判准,不是对观察的普遍要求。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。\n\n相关目标: [T01](#t01), [T08](#t08), [T20](#t20), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `organon.relationships.roles#p2`\n\n```text\nInternal Consistency concerns whether simultaneously held judgments can hold together; Grounds concerns whether and how far a claim is supported. A conclusion may fail to conflict with its assumptions without being supported by them. Self-Transcendence specifies a generative orientation and non-finality; neither establishes actual capability. Applications may supply objectives, values, and capability definitions; claims made under those objectives, values, and definitions remain subject to the relevant core provisions.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T03、T06、T11、T16、T20、T38、T39 作受限对应。这些是具体不蕴涵结果及有限支持案例,不是学习或自主执行的经验预测。一致性不是充分的经验或价值支持;反例只涉及已披露的数学表示。缺少支持不等于评估做错;与假设相容弱于从假设得到蕴涵。这不是心理理解的普遍定义。精确身份是范围前提;履行支持责任的是实际契约证明,而非身份本身。字段提取不从单一原则推出所有义务。采纳标记是独立事实,不能替代规范内容。要求样本的批评属于应用判准,不是对观察的普遍要求。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。\n\n相关目标: [T03](#t03), [T06](#t06), [T11](#t11), [T16](#t16), [T20](#t20), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `organon.relationships.roles#p3`\n\n```text\nSelf-Transcendence does not substitute for Reflexivity: keeping existing forms open to being surpassed differs from applying relevant principles to the system and to their own formation, application, and revision. Reflexivity extends these requirements to the system and to the formation, application, and revision of its principles. The grounds and limits of the Grounds provisions must themselves be articulable. The system’s own capability claims remain subject to assessment, and this philosophy’s existing form cannot gain priority merely from its established status. Such mutual application provides no self-proof and does not remove conditions of application.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T07、T08、T16、T18、T20、T37、T38、T39 作受限对应。一般输入谓词仍需解释;非空具体对象及实际记录建立模型内义务履行,不建立普遍自我证明。此有限反模型不证明所有可能编码中的独立性;保持形式开放也不能替代实际自反工作。这不是心理理解的普遍定义。精确身份是范围前提;履行支持责任的是实际契约证明,而非身份本身。这些是应用理由,不是普遍成本函数,也不要求惯用实现必须落选。字段提取不从单一原则推出所有义务。采纳标记是独立事实,不能替代规范内容。要求样本的批评属于应用判准,不是对观察的普遍要求。成功自评既不证明优先原则普遍正确,也不建立普遍样本要求。空样本批评适用于声明的局部评估契约。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。\n\n相关目标: [T07](#t07), [T08](#t08), [T16](#t16), [T18](#t18), [T20](#t20), [T37](#t37), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `organon.relationships.terms#p1`\n\n```text\n| Term | Meaning in this philosophy |\n| --- | --- |\n| Existing form | The system’s current organization, methods, and principles, not only its appearance or artifacts. |\n| Assessment | Examination of reasons, applicability, and observed performance; not limited to executable tests. |\n```\n\n状态: **incomplete**; Lean: passed; 来源保真: partial.\n\n来源与 T02 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。\n\n相关目标: [T02](#t02), [T21](#t21).\n\n\n\n\n\n\n### `extensions#p1`\n\n```text\nThis chapter adds a software engineering commitment and specifies its meaning and limits. It does not claim that this commitment follows from the Charter or Grounds. Those provisions remain adopted and constrain its application.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T37、T38、T39 作受限对应。成功自评既不证明优先原则普遍正确,也不建立普遍样本要求。空样本批评适用于声明的局部评估契约。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。\n\n相关目标: [T01](#t01), [T37](#t37), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.purpose#p1`\n\n```text\nSoftware engineering concerns the construction, operation, understanding, and revision of software within its relevant human and technical conditions. This philosophy guides decisions by people and agents; it does not attribute an intrinsic orientation to every software artifact.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T22、T23、T38 作受限对应。这些数量是有限模型数据,不是项目工期估算。处于范围内本身不证明每位参与者都能完成每种变化。结果涉及已表示路径;缺少某条文档化路径,不是所有维护方式均不可能的普遍定理。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T22](#t22), [T23](#t23), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.purpose#p2`\n\n```text\nThe evolution capability considered here belongs to the continuing engineering activity: maintainers, including successor maintainers and agents, working with software, tools, and available knowledge. Code that its original author can modify is not on that ground alone shown to support that continuing activity.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T22、T23、T38 作受限对应。这些数量是有限模型数据,不是项目工期估算。处于范围内本身不证明每位参与者都能完成每种变化。结果涉及已表示路径;缺少某条文档化路径,不是所有维护方式均不可能的普遍定理。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T22](#t22), [T23](#t23), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.purpose#p3`\n\n```text\nApply the following priority according to the software's credible lifecycle and maintenance expectations. A genuinely temporary script, bounded prototype, or retiring system may have little reason to support further evolution. Calling a continuing system temporary does not establish that condition.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T22、T23、T24、T38 作受限对应。这些数量是有限模型数据,不是项目工期估算。处于范围内本身不证明每位参与者都能完成每种变化。结果涉及已表示路径;缺少某条文档化路径,不是所有维护方式均不可能的普遍定理。这里表达并例示默认价值优先,不从 Core 演绎该优先,也不要求最大扩展性。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T22](#t22), [T23](#t23), [T24](#t24), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.evolution-priority#p1`\n\n```text\n> When relevant behavioral, safety, performance, and other necessary requirements are satisfied, give priority to continuing maintainers' ability to make credible future changes, including changes to the design itself, over present abstraction simplicity. Accept additional present abstraction complexity for that purpose, while allowing this preference to yield when the added costs threaten concrete engineering objectives.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T24、T25、T38、T39 作受限对应。这里表达并例示默认价值优先,不从 Core 演绎该优先,也不要求最大扩展性。定理不从事实证明价值规则,也不建立所有看似复杂的设计均具有相关优势。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。\n\n相关目标: [T24](#t24), [T25](#t25), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.evolution-priority#p2`\n\n```text\nCredible directions of change have articulable grounds, such as a committed plan, relevant domain knowledge, or an applicable history of change. They need not already have multiple implementations. Their credibility remains open to revision; a conceivable change alone does not establish that it warrants accommodation now.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T24、T25、T26、T27、T38、T39 作受限对应。这里表达并例示默认价值优先,不从 Core 演绎该优先,也不要求最大扩展性。定理不从事实证明价值规则,也不建立所有看似复杂的设计均具有相关优势。证明检查模型中给定的证据内容,不建立任意现实计划的可信性或预测校准程度。有限方向清单不证明所有未来变化可预测,也不证明遗漏可能性全都无关。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。\n\n相关目标: [T24](#t24), [T25](#t25), [T26](#t26), [T27](#t27), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.evolution-priority#p3`\n\n```text\nThis is a default priority, not an obligation to maximize extensibility or retain every possibility. Costs include relevant burdens of understanding, construction, diagnosis, verification, coordination, operation, and eventual migration. A departure from the priority identifies the objective threatened and why the costs matter. No universal numerical exchange rate between these considerations is prescribed.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T24、T25、T26、T27、T28、T38、T39 作受限对应。这里表达并例示默认价值优先,不从 Core 演绎该优先,也不要求最大扩展性。定理不从事实证明价值规则,也不建立所有看似复杂的设计均具有相关优势。证明检查模型中给定的证据内容,不建立任意现实计划的可信性或预测校准程度。有限方向清单不证明所有未来变化可预测,也不证明遗漏可能性全都无关。有限成本是模型中的工作与预算数据。源文不要求每类成本都适用,也不提供普遍数值取舍。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。\n\n相关目标: [T24](#t24), [T25](#t25), [T26](#t26), [T27](#t27), [T28](#t28), [T38](#t38), [T39](#t39), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.evolution-meaning#p1`\n\n```text\nEvolution includes adding capabilities, replacing implementations, deleting mechanisms, withdrawing abstractions, redrawing boundaries, and migrating away from an existing technology or model. Making additions within a fixed scheme does not establish equal ability to revise or leave that scheme. Not every such change can or should be made inexpensive.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T29、T30、T38 作受限对应。枚举构造子例示源文维度,并允许其他方向;它们不声称涵盖所有演化,也不声称每种变化廉价。这些反例排除无根据的跨维度推断,不新增所有变化都须廉价的义务。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T29](#t29), [T30](#t30), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.evolution-meaning#p2`\n\n```text\nAn evolution claim identifies the relevant changes and the maintainers' conditions. Independent changes, coordinated changes, preservation of existing obligations, and deliberate revision of those obligations can require different structures. A design's advantage on one dimension does not establish an advantage on every dimension.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T29、T30、T38 作受限对应。枚举构造子例示源文维度,并允许其他方向;它们不声称涵盖所有演化,也不声称每种变化廉价。这些反例排除无根据的跨维度推断,不新增所有变化都须廉价的义务。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T29](#t29), [T30](#t30), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.structural-judgment#p1`\n\n```text\nApply the preceding commitment to engineering consequences as a whole, including the relations among components, their observable contracts, and the work needed to understand and verify a change. An interface's shape, the number of modules or extension points, or the use of a named principle is not sufficient evidence of the claimed capability.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T31、T32、T37、T38 作受限对应。这些是相关的有限检查,不是普遍强制清单,也不是现实中所有边界成本的估算。等工作量案例通过实际路径变换保留步骤单位;这些单位是披露的模型度量,不是观测工程耗时。成功自评既不证明优先原则普遍正确,也不建立普遍样本要求。空样本批评适用于声明的局部评估契约。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T31](#t31), [T32](#t32), [T37](#t37), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.structural-judgment#p2`\n\n```text\nThe relevant comparison may examine how a change propagates, which knowledge and obligations cross a boundary, which assumptions become fixed, and what a later withdrawal would require. A proposed boundary needs support for the changes it is meant to accommodate; introducing it does not by itself show that those changes became easier.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T31、T32、T38 作受限对应。这些是相关的有限检查,不是普遍强制清单,也不是现实中所有边界成本的估算。等工作量案例通过实际路径变换保留步骤单位;这些单位是披露的模型度量,不是观测工程耗时。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T31](#t31), [T32](#t32), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.structural-judgment#p3`\n\n```text\nDistinguish a transformation that preserves an identified observable contract from one that deliberately revises that contract. The latter needs a corresponding account of changed obligations and affected parties. This distinction does not require preserving every historical behavior or using a particular testing or migration procedure.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T33、T34、T38 作受限对应。模型不要求保留所有历史行为、使用特定测试程序,也未新增普遍通知义务。有限测试集通过不是普遍相等证明;保持判断始终保留指定范围。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T33](#t33), [T34](#t34), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.revision#p1`\n\n```text\nChanged evidence about likely changes, maintenance conditions, costs, or objectives may justify revising a design or this priority's application. A revised judgment acknowledges material changes in its grounds; it does not make a failed prediction successful retrospectively.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T35、T36、T38 作受限对应。记录的历史是固定模型证据;定理不鉴定任意现实日志,也不证明所有批评回应均充分。结果允许有界的保留判断,不给予对后续根据或批评的永久豁免。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T35](#t35), [T36](#t36), [T38](#t38), [T40](#t40).\n\n\n\n\n\n\n### `software-engineering.revision#p2`\n\n```text\nRetaining a design can be justified when the relevant alternatives have no supported contribution or impose costs that defeat the objective. Reflexivity also keeps this engineering commitment and the methods used to assess evolution within the scope of criticism and revision. Continued change, agreement, or successful examples do not establish its universal correctness.\n```\n\n状态: **limited**; Lean: passed; 来源保真: partial.\n\n来源与 T35、T36、T37、T38 作受限对应。记录的历史是固定模型证据;定理不鉴定任意现实日志,也不证明所有批评回应均充分。结果允许有界的保留判断,不给予对后续根据或批评的永久豁免。成功自评既不证明优先原则普遍正确,也不建立普遍样本要求。空样本批评适用于声明的局部评估契约。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。\n\n相关目标: [T35](#t35), [T36](#t36), [T37](#t37), [T38](#t38), [T40](#t40).\n\n\n\n## 完整代码与逐行解释\n\n每份文件保持经检查的完整内容。下列逐行解释为修订后的知情解释;初次盲稿及被拒绝的旧判定另行保留。\n\n\n### `leanified/CoreReader/Adopted.lean`\n\n\n```lean\nimport CoreReader.Integration\n\nnamespace CoreReader.Adopted\nopen CoreReader.Logic CoreReader.Agency CoreReader.Evidence CoreReader.Choice\n\n/- These are three explicit mathematical assessment tasks, not an exhaustive or\nexclusive taxonomy of claim natures. A task fixes the original claim and support\ncontext before any candidate assessment is proposed. Its identity must be retained\nwhen comparing alternative assessments; taskOfFacet declares a new task and does\nnot authorize replacing a previously identified task. -/\ninductive AssessmentTask (W : Type) where\n | empirical (records : List (Record W)) (scope claim uncertainty : Claim W)\n | inferential (assumptions : Theory W) (claim : Claim W)\n | value (position : ValuePosition W)\n\ndef taskOfFacet {W : Type} : Facet W → AssessmentTask W\n | .empirical records scope claim uncertainty => .empirical records scope claim uncertainty\n | .inferential assumptions claim => .inferential assumptions claim\n | .value position => .value position\n\n/- This is a content-based sufficient adapter for the declared task, not a\nphilosophical rule requiring one unique assessment form. The empirical task may\nalso be assessed inferentially from exactly its observation/scope premises; its\noriginal uncertainty obligation is still checked. In particular, adding the\nconclusion as a new premise cannot replace the original empirical grounds.\nThe finite adapter need not accept every semantically equivalent presentation. -/\ndef NatureAppropriate {W : Type} : AssessmentTask W → Facet W → Prop\n | .empirical records scope claim uncertainty, .empirical actualRecords actualScope conclusion actualUncertainty =>\n actualRecords = records ∧ actualScope = scope ∧ conclusion = claim ∧ actualUncertainty = uncertainty\n | .empirical records scope claim uncertainty, .inferential assumptions conclusion =>\n assumptions = singleton (fun w => Compatible records w ∧ scope w) ∧\n conclusion = claim ∧ Supports records uncertainty\n | .inferential assumptions claim, .inferential actualAssumptions conclusion =>\n actualAssumptions = assumptions ∧ conclusion = claim\n | .value position, .value actualPosition => actualPosition = position\n | _, _ => False\n\ntheorem taskOfFacetAppropriate {W : Type} (f : Facet W) : NatureAppropriate (taskOfFacet f) f := by\n cases f with\n | empirical _ _ _ _ => exact ⟨rfl, rfl, rfl, rfl⟩\n | inferential _ _ => exact ⟨rfl, rfl⟩\n | value _ => rfl\n\n/- Core 0.1.2 requires appropriateness to the original claim task. Supplied facets\nare an explicit assessment scope, without importing Core 0.1.3's all-applicable\ncoverage requirement. No claim-kind label or freely assigned success flag proves\nappropriateness: NatureAppropriate compares the actual task and facet contents. -/\n/-- organon-map CoreReader.Adopted.Grounds012\norganon.grounds#p1 sha256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6\norganon.grounds.assessment#p1 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\n-/\ndef Grounds012 {W : Type} (claim : Claim W)\n (articulations : Facet W → Articulation W) (facets : List (Facet W))\n (task : AssessmentTask W) : Prop :=\n facets ≠ [] ∧ ∀ facet ∈ facets,\n facet.claim = claim ∧ Articulated (articulations facet) ∧\n FacetArticulated (articulations facet) facet ∧ FacetDischarged facet ∧\n NatureAppropriate task facet\n\n/- This helper proves the newly declared taskOfFacet f only. It supplies no\nappropriateness proof for another, previously fixed task with the same claim. -/\ntheorem grounds012Singleton {W : Type} (f : Facet W) (h : FacetDischarged f) :\n Grounds012 f.claim canonicalArticulation [f] (taskOfFacet f) := by\n refine ⟨by simp, ?_⟩\n intro facet hf\n cases List.mem_singleton.mp hf\n exact ⟨rfl, canonicalArticulated f h, canonicalFacetArticulated f, h, taskOfFacetAppropriate f⟩\n\n/-- organon-map CoreReader.Adopted.generationSpecification\norganon.charter.overview#p2 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c\norganon.charter.overview#p3 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c\norganon.charter.self-transcendence#p1 sha256 f4ca590e2ae15e3882f70c7b2bc46a8911c97cee547c8b137b5493fbf862c8c0\norganon.charter.self-transcendence.orientation#p1 sha256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf\norganon.charter.self-transcendence.non-finality#p1 sha256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8\norganon.charter.self-transcendence.limits#p2 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d\norganon.relationships.terms#p1 sha256 61cb7ce4f2920f1aa6771502b87a66536ae0504acccfebd9dd23bcc62756eddf\n-/\ndef generationSpecification (policy : Policy) : Prop := Generative policy\n\n/- All consequences use the whole currently held set. Historical reporting is\nseparate and does not require simultaneous compatibility with withdrawn claims. -/\n/-- organon-map CoreReader.Adopted.consistencySpecification\norganon.charter.consistency#p1 sha256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42\norganon.charter.consistency.meaning#p1 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75\n-/\ndef consistencySpecification {W Q : Type} (before after : Snapshot W Q)\n (reported : Bool) : Prop :=\n Consistent after.held after.context ∧ TruthfulReport before after reported\n\n/- A method's actual input and interpretation are parameters, permitting domain\nmethods as well as the small arithmetic adapter. Key coherence prevents records\nfor another method from silently satisfying the duty. -/\nstructure ReflexiveRule (T I O : Type) where\n key : PrincipleKey\n activity : Activity\n applicable : T → Prop\n input : T → I\n meaning : I → O → Prop\n\n/-- organon-map CoreReader.Adopted.reflexivitySpecification\norganon.charter.reflexivity#p1 sha256 13293b45c2fa89068c68ae7ef3c5df38f0efadb3ef3873d78a5ba67d9691a757\norganon.charter.reflexivity.meaning#p1 sha256 8a2caede01a43d8b6c60b54c78ac089c51868e9956f316948077ccee2e45c9cc\norganon.charter.reflexivity.limits#p1 sha256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\ndef reflexivitySpecification {T I O : Type} (rules : List (ReflexiveRule T I O))\n (isSelf : T → Prop) (performed : PrincipleKey → T → I → O → Prop) : Prop :=\n (∀ p ∈ rules, ∀ q ∈ rules, p.key = q.key → p = q) ∧\n ∀ rule ∈ rules, ∀ target, isSelf target → rule.applicable target →\n ∃ outcome, performed rule.key target (rule.input target) outcome ∧\n rule.meaning (rule.input target) outcome\n\ndef legacyRule (p : Principle) : ReflexiveRule Subject Inquiry WorkOutcome :=\n ⟨p.key, p.activity, p.applicable, p.inquiry,\n fun inquiry outcome => p.meaning inquiry (p.reasons inquiry.target) (p.limits inquiry.target) outcome⟩\n\ndef legacyPerformed (rules : List Principle) (records : List WorkRecord)\n (key : PrincipleKey) (target : Subject) (input : Inquiry) (outcome : WorkOutcome) : Prop :=\n ∃ p ∈ rules, ∃ record ∈ records,\n p.key = key ∧ ValidApplication rules p target record ∧\n record.inquiry = input ∧ record.outcome = outcome\n\ntheorem legacyReflexivity (owner : Nat) (rules : List Principle) (records : List WorkRecord)\n (h : Reflexive owner rules records) :\n reflexivitySpecification (rules.map legacyRule) (fun s => s.owner = owner)\n (legacyPerformed rules records) := by\n constructor\n · intro p hp q hq he\n obtain ⟨a, ha, rfl⟩ := List.mem_map.mp hp\n obtain ⟨b, hb, rfl⟩ := List.mem_map.mp hq\n exact congrArg legacyRule (h.1 a ha b hb he)\n · intro rule hr target ht happ\n obtain ⟨p, hp, rfl⟩ := List.mem_map.mp hr\n obtain ⟨record, hm, hv⟩ := h.2 p hp target ht happ\n refine ⟨record.outcome, ⟨p, hp, record, hm, rfl, hv, hv.inquiryIdentity, rfl⟩, ?_⟩\n change p.meaning (p.inquiry target) (p.reasons (p.inquiry target).target)\n (p.limits (p.inquiry target).target) record.outcome\n have ti : (p.inquiry target).target = target := hv.inquiryIdentity ▸ hv.inquiryTarget\n rw [ti]\n rw [← hv.inquiryIdentity, ← hv.reasonsIdentity, ← hv.limitsIdentity]\n exact hv.followsMeaning\n\n/- These are fulfillment interfaces for the named mathematical adapters, not\nuniversal empirical adequacy claims or definitions of all possible claim kinds. -/\n/-- organon-map CoreReader.Adopted.empiricalSpecification\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\n-/\ndef empiricalSpecification {W : Type} (records : List (Record W))\n (scope claim uncertainty : Claim W) : Prop :=\n Grounds012 claim canonicalArticulation [.empirical records scope claim uncertainty]\n (.empirical records scope claim uncertainty)\n\n/-- organon-map CoreReader.Adopted.inferentialSpecification\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\ndef inferentialSpecification {W : Type} (assumptions : Theory W) (claim : Claim W) : Prop :=\n Grounds012 claim canonicalArticulation [.inferential assumptions claim] (.inferential assumptions claim)\n\n/-- organon-map CoreReader.Adopted.valueSpecification\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\n-/\ndef valueSpecification {W : Type} (position : ValuePosition W) : Prop :=\n Grounds012 position.commitment canonicalArticulation [.value position] (.value position)\n\n/- Scope and roles are explicitly identified relative to a claim. An actually\nused method needs an explanation; unused methods are not required. The input\nrelation can encode contextual relevance without a universal numeric scale. -/\ninductive AssessmentMethod | measurement | repetition | framework\n deriving DecidableEq\nstructure ScopeAccount (W : Type) where\n claim : Claim W\n conditions : Claim W\n observationScope : Claim W\n relevant : W → W → Prop\n compared : W → W → Prop\n used : AssessmentMethod → Prop\n role : AssessmentMethod → String\n explains : AssessmentMethod → String → Claim W → Claim W → Prop\n\n/-- organon-map CoreReader.Adopted.scopeSpecification\norganon.grounds.scope#p1 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.scope#p2 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.scope#p3 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\n-/\ndef scopeSpecification {W : Type} (account : ScopeAccount W) : Prop :=\n (∀ a b, account.compared a b → account.conditions a ∧ account.conditions b ∧\n account.observationScope a ∧ account.observationScope b ∧ account.relevant a b) ∧\n ∀ method, account.used method → account.role method ≠ \"\" ∧\n account.explains method (account.role method) account.claim account.conditions\n\n/- A capability is selected by the application as an exact object-scoped\ncontract; whether explanation is part of it remains an application choice. -/\n/-- organon-map CoreReader.Adopted.capabilitySpecification\norganon.grounds.capabilities#p1 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0\norganon.grounds.capabilities#p2 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\ndef capabilitySpecification (assessed : Process) (contract : Claim Process) : Prop :=\n Grounds012 contract canonicalArticulation [processContractFacet assessed contract]\n (.inferential (processScope assessed) contract)\n\n/-- organon-map CoreReader.Adopted.choiceSpecification\norganon.grounds.implementations#p1 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c\norganon.grounds.implementations#p2 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c\norganon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\ndef choiceSpecification (requirements : Requirements) (implementation : Implementation)\n (reasons : List Reason) : Prop := JustifiedChoice requirements implementation reasons\n\n/- A collaborator supplies the successor operation. Removing that resource\nleaves the initial state; progress is tested on actual added operation content. -/\ndef collaborativeRevision (resources : ExternalResources) : State :=\n if resources.collaborator.isSome then extendedState else baseState\n\ntheorem collaborativeProgress :\n generationSpecification openPolicy ∧\n Expanded baseState (collaborativeRevision availableResources) ∧\n ¬ Expanded baseState (collaborativeRevision { availableResources with collaborator := none }) ∧\n assistedExecution ⟨none, none, none⟩ = none := by\n refine ⟨⟨Or.inl rfl, fun _ _ => trivial⟩, ?_, ?_, rfl⟩\n · exact Or.inr ⟨.successor, by simp [collaborativeRevision, availableResources, extendedState],\n by simp [baseState]⟩\n · simp [collaborativeRevision, Expanded, baseState]\n\n/- A truth-preserving current slice need not retain an earlier incompatible\nslice. Context changes and presentation order have separate semantics. -/\n/-- organon-map CoreReader.Adopted.consistencyConsequences\norganon.charter.consistency#p1 sha256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42\norganon.charter.consistency.meaning#p1 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75\n-/\ntheorem consistencyConsequences {W Q : Type} (t : Theory W) (c : Context W Q) (q : Q)\n (positive : Consequence t c q true) (negative : Consequence t c q false) :\n ¬ Consistent t c := conflictRequiresChange t c q positive negative\n\ndef broadBoolContext : Context Bool Unit := ⟨emptyTheory, onQuestion, fun _ => True⟩\n\ntheorem sliceConsistency :\n (∀ time, Consistent (revisionSlice time) broadBoolContext) ∧\n ¬ Consistent (union (revisionSlice 0) (revisionSlice 1)) broadBoolContext := by\n constructor\n · intro time\n apply consequenceConsistency\n exact ⟨time == 0, (modelsSingleton _ _).2 rfl, (by intro p hp; cases hp), trivial⟩\n · apply conflictRequiresChange _ _ ()\n · intro w h\n change w = true\n exact (modelsSingleton (fun w : Bool => w = true) w).1 ((modelsUnion _ _ _).1 h.1).1\n · intro w h ht\n have hn := (modelsSingleton _ _).1 ((modelsUnion _ _ _).1 h.1).2\n cases ht.symm.trans hn\n\ntheorem explicitlyConsistentLimits :\n Consistent (singleton (fun w : Bool => w = true)) broadBoolContext ∧\n ¬ Models (singleton (fun w : Bool => w = true)) false ∧\n Consistent (emptyTheory : Theory Bool) broadBoolContext ∧\n ¬ Entails emptyTheory (fun w : Bool => w = true) := by\n refine ⟨?_, consistentFalse.2, ?_, consistentIncomplete.2.1⟩\n · exact consequenceConsistency _ _ ⟨true, (modelsSingleton _ _).2 rfl,\n (by intro p hp; cases hp), trivial⟩\n · exact consequenceConsistency _ _ ⟨true, (by intro p hp; cases hp),\n (by intro p hp; cases hp), trivial⟩\n\n/- One observed input supports the local claim. The identical records cannot\nsupport all inputs, nor the stronger claim that both Boolean outputs are true. -/\ndef localFacet012 : Facet (Nat → Bool) :=\n .empirical [zeroRecord] (fun _ => True) (fun f => f 0 = true) (fun _ => True)\ndef globalFacet012 : Facet (Nat → Bool) :=\n .empirical [zeroRecord] (fun _ => True) allTrue (fun _ => True)\ndef strongFacet012 : Facet (Nat → Bool) :=\n .empirical [zeroRecord] (fun _ => True) (fun f => f 0 = true ∧ f 1 = true) (fun _ => True)\n\ntheorem localFacetChecked012 : FacetDischarged localFacet012 :=\n ⟨⟨localGenerator 0, (zeroCompatible _).2 rfl, trivial⟩,\n (fun f hf _ => (zeroCompatible f).1 hf), fun _ _ => trivial⟩\n\ntheorem scopeStrength012 :\n Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧\n Articulated (canonicalArticulation globalFacet012) ∧\n ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧\n ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012) := by\n refine ⟨grounds012Singleton _ localFacetChecked012, ⟨by simp [canonicalArticulation, globalFacet012],\n by simp [canonicalArticulation, globalFacet012]⟩, ?_, ?_⟩\n · intro h\n have checked := (h.2 globalFacet012 (by simp)).2.2.2.1\n have bad := checked.2.1 (localGenerator 0) ((zeroCompatible _).2 rfl) trivial 1\n cases bad\n · intro h\n have checked := (h.2 strongFacet012 (by simp)).2.2.2.1\n have bad := (checked.2.1 (localGenerator 0) ((zeroCompatible _).2 rfl) trivial).2\n cases bad\n\n/- A bounded outcome statement can leave another observable entirely unknown.\nThis represents uncertainty by a range of compatible worlds, not a probability. -/\ndef uncertainFacet012 : Facet (Bool × Bool) :=\n .empirical [temperatureRecord, temperatureRecord] (fun _ => True)\n (fun w => w.1 = true) (fun w => w.2 = true ∨ w.2 = false)\n\ntheorem uncertainSupported012 :\n empiricalSpecification [temperatureRecord, temperatureRecord] (fun _ => True)\n (fun w => w.1 = true) (fun w => w.2 = true ∨ w.2 = false) ∧\n Compatible [temperatureRecord, temperatureRecord] (true,true) ∧\n Compatible [temperatureRecord, temperatureRecord] (true,false) := by\n refine ⟨grounds012Singleton uncertainFacet012 ?_, temperatureCompatible true, temperatureCompatible false⟩\n refine ⟨⟨(true,false), temperatureCompatible false, trivial⟩, ?_, ?_⟩\n · intro w hw _; exact hw temperatureRecord (by simp)\n · intro w _; cases w.2 <;> simp\n\n/- Correctly completed negative examination is distinct from a supported\nconclusion. The countervaluation satisfies the same premises. -/\ndef InferenceExamined {W : Type} (premises : Theory W) (conclusion : Claim W)\n (accepted : Bool) : Prop := accepted = true ↔ Entails premises conclusion\n\ntheorem inferenceChecked012 :\n inferentialSpecification (singleton (fun n : Nat => n = 2)) (fun n => n + 1 = 3) ∧\n InferenceExamined (emptyTheory : Theory Bool) (fun w => w = true) false ∧\n Models (emptyTheory : Theory Bool) false ∧ ¬ ((fun w : Bool => w = true) false) := by\n refine ⟨grounds012Singleton arithmeticFacet noUniversalChain.1, ?_, (by intro p hp; cases hp), by decide⟩\n constructor\n · intro h; cases h\n · intro h; exact False.elim (consistentIncomplete.2.1 h)\n\n/- Closing a response to an actually relevant criticism fails the value\nprocedure even when its budget/benefit reasons and joint adoption are unchanged. -/\ndef closedPosition012 : ValuePosition Bool := { switchPosition with response := fun _ => none }\n\ntheorem closedCriticism012 : ¬ ValueProcedure closedPosition012 := by\n intro h\n obtain ⟨answer, ha, _⟩ := h.2.2.2 false trivial rfl\n cases ha\n\ntheorem valueFulfilled012 : valueSpecification switchPosition :=\n grounds012Singleton _ switchValueProcedure\n\n/- Qualitative entailment orders claims by implication, without conversion of\nvalue and empirical/inferential reasons to a common numeric scale. -/\ndef ClaimNoStronger {W : Type} (weaker stronger : Claim W) : Prop := ∀ w, stronger w → weaker w\n\ntheorem qualitativeProportionality012 :\n ClaimNoStronger (fun f : Nat → Bool => f 0 = true) allTrue ∧\n ¬ ClaimNoStronger allTrue (fun f : Nat → Bool => f 0 = true) ∧\n valueSpecification switchPosition := by\n refine ⟨fun _ h => h 0, ?_, valueFulfilled012⟩\n intro h\n have bad := h (localGenerator 0) rfl 1\n cases bad\n\ndef scopeRole012 : AssessmentMethod → String\n | .measurement => \"identify the output at the observed input zero\"\n | .repetition => \"check the same local conclusion against repeated input-zero observations\"\n | .framework => \"compare only the declared input; keep broader claims separate\"\n\ndef scopeRoleContent012 : AssessmentMethod → Prop\n | .measurement => Supports [zeroRecord] (fun f => f 0 = true)\n | .repetition => Supports [zeroRecord, zeroRecord] (fun f => f 0 = true)\n | .framework => ¬ Supports [zeroRecord] allTrue\n\ndef localScopeAccount012 : ScopeAccount Nat where\n claim n := (localGenerator 0) n = true\n conditions _ := True\n observationScope n := n = 0\n relevant a b := a = b\n compared a b := a = 0 ∧ b = 0\n used _ := True\n role := scopeRole012\n explains method text claim conditions :=\n text = scopeRole012 method ∧ claim = (fun n => localGenerator 0 n = true) ∧\n conditions = (fun _ => True) ∧ scopeRoleContent012 method\n\ntheorem scopeFulfilled012 : scopeSpecification localScopeAccount012 := by\n constructor\n · intro a b h\n exact ⟨trivial, trivial, h.1, h.2, h.1.trans h.2.symm⟩\n · intro method _\n refine ⟨?_, rfl, rfl, rfl, ?_⟩\n · cases method <;> decide\n · cases method with\n | measurement => exact singleObservation.2.2.1\n | repetition => intro f hf; exact hf zeroRecord (by simp)\n | framework => exact singleObservation.2.2.2\n\ntheorem capabilityFulfilled012 :\n capabilitySpecification outputOnlyProcess OutputContract ∧\n capabilitySpecification explainedProcess FullProcessContract ∧\n (∃ certificate : ExternalCertificate outputOnlyProcess,\n certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧\n ¬ ExplanationContract outputOnlyProcess := by\n refine ⟨grounds012Singleton _ (processContractDischarged _ _ outputCorrectByEvaluation),\n grounds012Singleton _ (processContractDischarged _ _ ?_),\n ⟨externalOutputCertificate, externalOutputCertificate.distinctParticipants,\n externalOutputCertificate.outputCorrect⟩, outputOnlyNoExplanation⟩\n exact ⟨fun _ => rfl, .doubleInput, rfl, fun _ => rfl⟩\n\n/- This application asks the assessed object to predict a multiplier mechanism\nat changed inputs and multiplier values. This is one operational understanding\ncriterion selected by an application, not a definition of psychological understanding.\nThe original output and explanation alone do not answer the additional questions. -/\nstructure MechanismApplication012 where\n process : Process\n answer : Nat → Nat → Nat\n\ndef mechanism012 (multiplier input : Nat) : Nat := multiplier * input\n\ndef UnderstandingApplication012 (assessed : MechanismApplication012) : Prop :=\n FullProcessContract assessed.process ∧\n (∀ input, assessed.process.output input = mechanism012 2 input) ∧\n ∀ multiplier input, assessed.answer multiplier input = mechanism012 multiplier input\n\ndef explainedWithoutVariation012 : MechanismApplication012 :=\n ⟨explainedProcess, fun _ input => input + input⟩\n\ndef mechanismResponder012 : MechanismApplication012 :=\n ⟨explainedProcess, mechanism012⟩\n\n/- The assessment task is fixed by this very application object and the stronger\ncontract. Identity is a scope premise; the positive case still proves the contract. -/\ndef understandingScope012 (assessed : MechanismApplication012) : Theory MechanismApplication012 :=\n singleton (fun candidate => candidate = assessed)\n\ndef understandingTask012 (assessed : MechanismApplication012) : AssessmentTask MechanismApplication012 :=\n .inferential (understandingScope012 assessed) UnderstandingApplication012\n\ndef understandingFacet012 (assessed : MechanismApplication012) : Facet MechanismApplication012 :=\n .inferential (understandingScope012 assessed) UnderstandingApplication012\n\ntheorem mechanismResponderUnderstands012 : UnderstandingApplication012 mechanismResponder012 := by\n refine ⟨⟨(fun _ => rfl), .doubleInput, rfl, (fun _ => rfl)⟩, ?_, fun _ _ => rfl⟩\n intro input\n simp [mechanismResponder012, explainedProcess, mechanism012, Nat.two_mul]\n\ntheorem explainedWithoutVariationFails012 :\n ¬ UnderstandingApplication012 explainedWithoutVariation012 := by\n intro h\n have wrong := h.2.2 3 1\n change 2 = 3 at wrong\n cases wrong\n\ntheorem understandingApplicationCases012 :\n explainedWithoutVariation012.process = mechanismResponder012.process ∧\n FullProcessContract explainedWithoutVariation012.process ∧\n ¬ UnderstandingApplication012 explainedWithoutVariation012 ∧\n UnderstandingApplication012 mechanismResponder012 ∧\n Grounds012 UnderstandingApplication012 canonicalArticulation\n [understandingFacet012 mechanismResponder012] (understandingTask012 mechanismResponder012) ∧\n ¬ Grounds012 UnderstandingApplication012 canonicalArticulation\n [understandingFacet012 explainedWithoutVariation012] (understandingTask012 explainedWithoutVariation012) := by\n refine ⟨rfl, ⟨(fun _ => rfl), .doubleInput, rfl, (fun _ => rfl)⟩,\n explainedWithoutVariationFails012, mechanismResponderUnderstands012, ?_, ?_⟩\n · apply grounds012Singleton\n refine ⟨⟨mechanismResponder012, (modelsSingleton _ _).2 rfl⟩, ?_⟩\n intro candidate hc\n have same := (modelsSingleton _ _).1 hc\n subst candidate\n exact mechanismResponderUnderstands012\n · intro h\n have discharged := (h.2 (understandingFacet012 explainedWithoutVariation012) (by simp)).2.2.2.1\n exact explainedWithoutVariationFails012\n (discharged.2 explainedWithoutVariation012 ((modelsSingleton _ _).2 rfl))\n\n/- The same exact application contract receives Grounds when its owner asserts\nit; external certificates change who supplies reasons, not the asserted object. -/\ndef OwnCapability012 (owner claimant : Nat) (process : Process) (contract : Claim Process) : Prop :=\n owner = claimant ∧ capabilitySpecification process contract\n\ntheorem ownCapability012 : OwnCapability012 7 7 outputOnlyProcess OutputContract :=\n ⟨rfl, capabilityFulfilled012.1⟩\n\n/- A complete represented Charter includes generation, whole-set consistency,\ntruthful revision reporting and applicable contentful self-work on the same\nsystem. The world type is the finite Candidate × Mode type. -/\ndef CompleteCharter012 (system : CoreReader.Integration.System)\n (world : CoreReader.Integration.World) : Prop :=\n generationSpecification (system.policy world) ∧\n consistencySpecification\n ⟨CoreReader.Integration.systemHeld system, CoreReader.Integration.systemContext system, 0⟩\n ⟨CoreReader.Integration.systemHeld system, CoreReader.Integration.systemContext system, 0⟩ false ∧\n reflexivitySpecification ((system.rules world).map legacyRule) (fun s => s.owner = system.owner)\n (legacyPerformed (system.rules world) (system.work world)) ∧\n (system.policy world).current system.method.form ∧\n (system.policy world).current system.principleForm\n\ntheorem completeCharter012 : CompleteCharter012 CoreReader.Integration.actualSystem CoreReader.Integration.actual := by\n refine ⟨CoreReader.Integration.charterChecked.1,\n ⟨CoreReader.Integration.jointConsistent, ?_⟩,\n legacyReflexivity 0 _ _ (completeOwnWork_reflexive 0), rfl, rfl⟩\n rintro (h | h)\n · exact False.elim (h ⟨fun _ => Iff.rfl, fun _ => Iff.rfl, fun _ _ => Iff.rfl, fun _ => Iff.rfl⟩)\n · exact False.elim (h rfl)\n\ntheorem charterWithoutGrounds012 :\n CompleteCharter012 CoreReader.Integration.actualSystem CoreReader.Integration.actual ∧\n Admissible CoreReader.Integration.held CoreReader.Integration.context CoreReader.Integration.actual ∧\n Compatible [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.actual ∧\n Articulated (canonicalArticulation CoreReader.Integration.unsupportedCapabilityFacet) ∧\n ¬ Supports [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.capability ∧\n ¬ Grounds012 CoreReader.Integration.capability canonicalArticulation\n [CoreReader.Integration.unsupportedCapabilityFacet]\n (taskOfFacet CoreReader.Integration.unsupportedCapabilityFacet) := by\n refine ⟨completeCharter012, CoreReader.Integration.actualAdmissible,\n (by intro r hr; cases List.mem_singleton.mp hr; rfl),\n ⟨by simp [canonicalArticulation, CoreReader.Integration.unsupportedCapabilityFacet],\n by simp [canonicalArticulation, CoreReader.Integration.unsupportedCapabilityFacet]⟩,\n CoreReader.Integration.costDoesNotSupportOutput, ?_⟩\n intro h\n have checked := (h.2 CoreReader.Integration.unsupportedCapabilityFacet (by simp)).2.2.2.1\n exact CoreReader.Integration.costDoesNotSupportOutput (fun w hw => checked.2.1 w hw trivial)\n\n/- Permission to assert is evaluated on the same claim, articulation and facets.\nThe countercase derives inadequacy from the actual unobserved output. -/\ndef groundsPermission012 {W : Type} (enabled : Bool) (claim : Claim W)\n (a : Facet W → Articulation W) (facets : List (Facet W)) (task : AssessmentTask W) : Prop :=\n if enabled then Grounds012 claim a facets task else True\n\ndef GroundsProvision012 (enabled : Bool) : Prop :=\n ∀ (claim : Claim (Nat → Bool)) a facets task,\n groundsPermission012 enabled claim a facets task → Grounds012 claim a facets task\n\ntheorem groundsProvision012Meaning (enabled : Bool) : GroundsProvision012 enabled ↔ enabled = true := by\n cases enabled with\n | true => exact ⟨fun _ => rfl, fun _ _ _ _ _ h => h⟩\n | false =>\n constructor\n · intro h\n exact False.elim (scopeStrength012.2.2.1 (h globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) trivial))\n · intro h; cases h\n\n/- The value rationale concerns this fixed empirical assertion task. The\nsame task, observed grounds and concrete counterworld are retained when the\npermission policy is enabled or disabled. -/\ndef groundsExperimentTask012 : AssessmentTask (Nat → Bool) :=\n .empirical [zeroRecord] (fun _ => True) allTrue (fun _ => True)\n\nnoncomputable def groundsExperiment012 (enabled : Bool) : Bool :=\n @decide (groundsPermission012 enabled allTrue canonicalArticulation [globalFacet012]\n groundsExperimentTask012) (Classical.propDecidable _)\n\nnoncomputable def groundsPosition012 : ValuePosition Bool where\n Position := Bool\n Outcome := Bool\n adopted := true\n selected := id\n outcome _ enabled := groundsExperiment012 enabled\n objective accepted := accepted = false\n constraints _ enabled := GroundsProvision012 enabled\n starting := singleton (fun enabled => enabled = true)\n reasons := [fun _ _ => Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0)]\n limits _ := True\n relevantCriticism _ := ¬ Supports [zeroRecord] allTrue\n response _ := some \"retain local support and reject the unsupported universal conclusion\"\n\ntheorem groundsPosition012Checked : ValueProcedure groundsPosition012 := by\n refine ⟨by simp [groundsPosition012], ?_, ?_, ?_⟩\n · refine ⟨true, (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩\n intro reason hr\n cases List.mem_singleton.mp hr\n refine ⟨(zeroCompatible _).2 rfl, ?_⟩\n intro h; have bad := h 1; cases bad\n · intro w _ _ reasons\n have counterworld := reasons _ (List.mem_singleton.mpr rfl)\n change Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0) at counterworld\n have unsupported : ¬ Grounds012 allTrue canonicalArticulation [globalFacet012] groundsExperimentTask012 := by\n intro h\n have discharged := (h.2 globalFacet012 (by simp)).2.2.2.1\n exact counterworld.2 (discharged.2.1 (localGenerator 0) counterworld.1 trivial)\n refine ⟨?_, (groundsProvision012Meaning true).2 rfl⟩\n exact @decide_eq_false (groundsPermission012 true allTrue canonicalArticulation [globalFacet012]\n groundsExperimentTask012) (Classical.propDecidable _) unsupported\n · intro w _ _; exact ⟨_, rfl, by decide⟩\n\ntheorem groundsRationaleExperiment012 :\n Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0) ∧\n groundsExperiment012 true = false ∧ groundsExperiment012 false = true ∧\n groundsPosition012.outcome true true = groundsExperiment012 true ∧\n groundsPosition012.outcome true false = groundsExperiment012 false := by\n refine ⟨(zeroCompatible _).2 rfl, ?_, ?_, ?_, rfl, rfl⟩\n · intro h; have bad := h 1; cases bad\n · have actualReasons : ∀ reason ∈ groundsPosition012.reasons, reason true groundsPosition012.adopted := by\n intro reason member\n cases List.mem_singleton.mp member\n refine ⟨(zeroCompatible _).2 rfl, ?_⟩\n intro h; have bad := h 1; cases bad\n exact (groundsPosition012Checked.2.2.1 true ((modelsSingleton _ _).2 rfl) trivial actualReasons).1\n · exact @decide_eq_true (groundsPermission012 false allTrue canonicalArticulation [globalFacet012]\n groundsExperimentTask012) (Classical.propDecidable _) trivial\n\ntheorem groundsOnGrounds012 :\n Grounds012 (fun enabled => GroundsProvision012 enabled) canonicalArticulation [.value groundsPosition012] (.value groundsPosition012) ∧\n groundsPosition012.limits true ∧ groundsPosition012.relevantCriticism true := by\n have same : (Facet.value groundsPosition012).claim = (fun enabled => GroundsProvision012 enabled) := by\n funext enabled\n exact propext (groundsProvision012Meaning enabled).symm\n refine ⟨?_, trivial, singleObservation.2.2.2⟩\n rw [← same]\n exact grounds012Singleton _ groundsPosition012Checked\n\ntheorem reflexiveTargets012 :\n reflexivitySpecification ((ownRules 0).map legacyRule) (fun s => s.owner = 0)\n (legacyPerformed (ownRules 0) (completeOwnWork 0)) ∧\n (∀ phase, Performed (completeOwnWork 0) (.process 0 0 phase) .assessment) ∧\n Performed (completeOwnWork 0) (.system 0) .assessment ∧\n reflexivitySpecification ([applicationRule].map legacyRule) (fun s => s.owner = 0)\n (legacyPerformed [applicationRule] applicationWork) ∧\n ¬ Performed applicationWork (.system 0) .assessment := by\n refine ⟨legacyReflexivity 0 _ _ (completeOwnWork_reflexive 0), ?_,\n ownAssessmentPerformed 0 (.system 0) (by simp [ownSubjects]),\n legacyReflexivity 0 _ _ applicationWork_reflexive, (applicabilityRetained 0 [] []).2.2.2⟩\n intro phase\n apply ownAssessmentPerformed\n cases phase <;> simp [ownSubjects]\n\ntheorem achievementSupported012 :\n Grounds012 transitionAchievement canonicalArticulation [transitionFacet] (taskOfFacet transitionFacet) ∧\n Compatible [transitionPerformanceRecord] .extend ∧\n transitionAchievement .extend ∧ ¬ transitionAchievement .inflate ∧\n ¬ Supports [transitionReportRecord] transitionAchievement := by\n refine ⟨grounds012Singleton _ transitionFacetDischarged, ?_, ?_, ?_, transitionReportDoesNotSupport.2.2⟩\n · exact (transitionPerformanceCompatible .extend).mpr rfl\n · simp [transitionAchievement, transitionBefore, transitionAfter, Expanded, baseState, extendedState]\n · simp [transitionAchievement, transitionBefore, transitionAfter, Expanded, baseState, inflatedState]\n\ntheorem semanticOrder012 : ∀ p q : Claim Bool,\n ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r :=\n representationOrderIrrelevant\n\ndef clearFalseArgument012 : Articulation Bool :=\n ⟨[\"the actual switch is on\"], singleton (fun w => w = true), [fun w => w = true], fun _ => True⟩\n\ntheorem clearFalseReason012 :\n Articulated clearFalseArgument012 ∧ ¬ Models clearFalseArgument012.assumptions false :=\n ⟨⟨by simp [clearFalseArgument012], by simp [clearFalseArgument012]⟩, consistentFalse.2⟩\n\ndef valueNeutralRecord012 : Record Bool := ⟨fun _ => true, true⟩\n\ntheorem valueNotFact012 :\n valueSpecification switchPosition ∧\n Compatible [valueNeutralRecord012] false ∧\n ¬ Supports [valueNeutralRecord012] switchPosition.commitment ∧\n ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment := by\n have compatible : Compatible [valueNeutralRecord012] false := by\n intro r hr; cases List.mem_singleton.mp hr; rfl\n refine ⟨valueFulfilled012, compatible, ?_, valueWithoutSelfProof.2.2.1⟩\n intro h\n have bad := h false compatible\n cases bad\n\ndef wrongExplanation012 : Implementation := { identityImpl with explanation := fun n => n + 1 }\n\ntheorem internalReasonDistinguishes012 :\n (∀ n, identityImpl.run n = wrongExplanation012.run n) ∧\n Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧\n Relevant identityRequirements identityImpl (.method .explanation) ∧\n ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation) := by\n refine ⟨fun _ => rfl, identityFeasible, identityFeasible, internalReasons.1, ?_⟩\n intro h\n have bad := h.2 0 trivial\n cases bad\n\ntheorem inventoryCases012 : ∀ kind : InventoryKind,\n Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .copy ∧\n ¬ Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .successor := by\n intro kind\n simp [Available]\n\n\ndef selfExemptRule012 : ReflexiveRule Nat Nat Bool :=\n ⟨⟨0,1⟩, .assessment, fun _ => True, id,\n fun input output => output = ownArithmeticPrinciple input⟩\ndef selfExemptPerformed012 (key : PrincipleKey) (target input : Nat) (output : Bool) : Prop :=\n key = ⟨0,1⟩ ∧ target = 1 ∧ input = target ∧ output = ownArithmeticPrinciple input\n\ntheorem openSelfExempt012 :\n generationSpecification openPolicy ∧ openPolicy.revisable ⟨.principle,0⟩ ∧\n selfExemptPerformed012 ⟨0,1⟩ 1 1 true ∧\n selfExemptRule012.applicable 0 ∧\n ¬ reflexivitySpecification [selfExemptRule012] (fun target => target = 0) selfExemptPerformed012 := by\n refine ⟨⟨Or.inl rfl, fun _ _ => trivial⟩, trivial, ⟨rfl,rfl,rfl,by decide⟩, trivial, ?_⟩\n intro h\n obtain ⟨outcome, performed, _⟩ := h.2 selfExemptRule012 (by simp) 0 rfl trivial\n cases performed.2.1\n\ntheorem ownPhilosophyStatus012 :\n ¬ choiceSpecification CoreReader.Integration.proposalRequirements\n (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation\n [.status .standing] ∧\n choiceSpecification CoreReader.Integration.proposalRequirements\n (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation\n [.method .output] :=\n ⟨CoreReader.Integration.existingPhilosophyNotPrivileged.2.2.1,\n CoreReader.Integration.existingPhilosophyNotPrivileged.2.2.2.1⟩\n\ndef jointContext012 : Context (Bool × Bool) Unit :=\n ⟨emptyTheory, fun _ w => w.2 = true, fun _ => True⟩\n\ntheorem jointImplicationConflict012 :\n Consequence jointTheory jointContext012 () true ∧\n Consequence jointTheory jointContext012 () false ∧\n ¬ Consistent jointTheory jointContext012 := by\n have positive : Consequence jointTheory jointContext012 () true := by\n intro w hw\n exact (hw.1 premiseRule (Or.inr (Or.inl rfl))) (hw.1 premiseP (Or.inl rfl))\n have negative : Consequence jointTheory jointContext012 () false := by\n intro w hw\n exact hw.1 premiseNotQ (Or.inr (Or.inr rfl))\n exact ⟨positive, negative, conflictRequiresChange _ _ () positive negative⟩\n\ndef tensionContext012 : Context Nat Unit :=\n ⟨emptyTheory, fun _ n => n ≤ 6, fun _ => True⟩\n\ntheorem tensionConsistent012 :\n Consistent (union (singleton (fun n : Nat => 4 ≤ n)) (singleton (fun n => n ≤ 6))) tensionContext012 := by\n apply consequenceConsistency\n exact ⟨5, (modelsUnion _ _ _).2 ⟨(modelsSingleton _ _).2 (by decide),\n (modelsSingleton _ _).2 (by decide)⟩, (by intro p hp; cases hp), trivial⟩\n\ntheorem qualitativeUnmeasured012 :\n inferentialSpecification (singleton (fun on : Bool => on = true)) (fun on => on ≠ false) ∧\n usesObservation (Facet.inferential (singleton (fun on : Bool => on = true)) (fun on => on ≠ false)) = false := by\n refine ⟨grounds012Singleton _ ⟨⟨true, (modelsSingleton _ _).2 rfl⟩, ?_⟩, rfl⟩\n intro on hon hf\n have ht := (modelsSingleton (fun on : Bool => on = true) on).1 hon\n cases ht.symm.trans hf\n\n\ntheorem allStatusOnly012 : ∀ kind : StatusKind,\n ¬ choiceSpecification identityRequirements identityImpl [.status kind] :=\n statusOnlyFails identityRequirements identityImpl\n\n/- A finite two-draw experiment assigns positive equal weights to both possible\noutcomes. It models possibility and a stable conclusion, not empirical claims\nabout any physical random-number source. -/\ndef drawWeight012 (_draw : Bool) : Nat := 1\ndef randomTrial012 (draw : Bool) : Trial :=\n ⟨0, if draw then 1 else 2, if draw then 1 else 2⟩\n\ntheorem randomOutcomes012 :\n drawWeight012 true > 0 ∧ drawWeight012 false > 0 ∧\n drawWeight012 true = drawWeight012 false ∧\n Reproduced (randomTrial012 true) (randomTrial012 false) ∧\n (randomTrial012 true).actualOutcome ≠ (randomTrial012 false).actualOutcome ∧\n (∀ draw, Verified (randomTrial012 draw) ∧ Bounded (randomTrial012 draw)) := by\n refine ⟨by decide, by decide, rfl, rfl, by decide, ?_⟩\n intro draw\n cases draw <;> simp [Verified, Bounded, randomTrial012]\n\n\n/- Original tasks are fixed independently of the candidate substitutions below. -/\ndef originalGlobalTask012 : AssessmentTask (Nat → Bool) :=\n .empirical [zeroRecord] (fun _ => True) allTrue (fun _ => True)\ndef originalLocalTask012 : AssessmentTask (Nat → Bool) :=\n .empirical [zeroRecord] (fun _ => True) (fun f => f 0 = true) (fun _ => True)\n\ndef circularGlobalFacet012 : Facet (Nat → Bool) := .inferential (singleton allTrue) allTrue\n\ntheorem circularGlobalConditional012 : FacetDischarged circularGlobalFacet012 := by\n refine ⟨⟨fun _ => true, (modelsSingleton _ _).2 (fun _ => rfl)⟩, ?_⟩\n intro f hf\n exact (modelsSingleton _ _).1 hf\n\ntheorem circularSubstitutionRejected012 :\n Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] (taskOfFacet circularGlobalFacet012) ∧\n ¬ NatureAppropriate originalGlobalTask012 circularGlobalFacet012 ∧\n ¬ Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] originalGlobalTask012 := by\n have inappropriate : ¬ NatureAppropriate originalGlobalTask012 circularGlobalFacet012 := by\n intro h\n have equalPremises := h.1\n have originalMember : singleton (fun f => Compatible [zeroRecord] f ∧ True) allTrue := equalPremises ▸ (show singleton allTrue allTrue from rfl)\n have equalClaims : allTrue = (fun f => Compatible [zeroRecord] f ∧ True) := originalMember\n have claimedAll := (congrFun equalClaims (localGenerator 0)).mpr ⟨(zeroCompatible _).2 rfl, trivial⟩\n have bad := claimedAll 1\n cases bad\n refine ⟨grounds012Singleton _ circularGlobalConditional012, inappropriate, ?_⟩\n intro h\n exact inappropriate (h.2 circularGlobalFacet012 (by simp)).2.2.2.2\n\ndef observedPremises012 : Theory (Nat → Bool) := singleton (fun f => Compatible [zeroRecord] f ∧ True)\ndef observedInferenceFacet012 : Facet (Nat → Bool) :=\n .inferential observedPremises012 (fun f => f 0 = true)\n\ntheorem observedInferenceChecked012 : FacetDischarged observedInferenceFacet012 := by\n refine ⟨⟨localGenerator 0, (modelsSingleton _ _).2 ⟨(zeroCompatible _).2 rfl, trivial⟩⟩, ?_⟩\n intro f hf\n exact (zeroCompatible _).1 ((modelsSingleton _ _).1 hf).1\n\ntheorem sameEmpiricalTaskTwoMethods012 :\n Grounds012 (fun f => f 0 = true) canonicalArticulation [localFacet012] originalLocalTask012 ∧\n Grounds012 (fun f => f 0 = true) canonicalArticulation [observedInferenceFacet012] originalLocalTask012 := by\n refine ⟨grounds012Singleton _ localFacetChecked012, ?_⟩\n refine ⟨by simp, ?_⟩\n intro f hf\n cases List.mem_singleton.mp hf\n exact ⟨rfl, canonicalArticulated _ observedInferenceChecked012,\n canonicalFacetArticulated _, observedInferenceChecked012, rfl, rfl, fun _ _ => trivial⟩\n\n/- The second coordinate remains unobserved. Switching assessment form cannot\nremove that uncertainty responsibility from the original empirical task. -/\ndef originalUncertaintyTask012 : AssessmentTask (Bool × Bool) :=\n .empirical [temperatureRecord, temperatureRecord] (fun _ => True)\n (fun w => w.1 = true) (fun w => w.2 = true)\ndef uncertaintyBypassFacet012 : Facet (Bool × Bool) :=\n .inferential (singleton (fun w => Compatible [temperatureRecord, temperatureRecord] w ∧ True))\n (fun w => w.1 = true)\n\ntheorem uncertaintyBypassChecked012 : FacetDischarged uncertaintyBypassFacet012 := by\n refine ⟨⟨(true,false), (modelsSingleton _ _).2 ⟨temperatureCompatible false, trivial⟩⟩, ?_⟩\n intro w hw\n exact ((modelsSingleton _ _).1 hw).1 temperatureRecord (by simp)\n\ntheorem uncertaintySubstitutionRejected012 :\n FacetDischarged uncertaintyBypassFacet012 ∧\n ¬ NatureAppropriate originalUncertaintyTask012 uncertaintyBypassFacet012 ∧\n ¬ Grounds012 (fun w : Bool × Bool => w.1 = true) canonicalArticulation\n [uncertaintyBypassFacet012] originalUncertaintyTask012 := by\n have inappropriate : ¬ NatureAppropriate originalUncertaintyTask012 uncertaintyBypassFacet012 := by\n intro h\n have bad := h.2.2 (true,false) (temperatureCompatible false)\n cases bad\n exact ⟨uncertaintyBypassChecked012, inappropriate,\n fun h => inappropriate (h.2 uncertaintyBypassFacet012 (by simp)).2.2.2.2⟩\n\ndef selectedFactFacet012 : Facet Bool :=\n .empirical [switchRecord] (fun _ => True) switchPosition.commitment (fun _ => True)\n\ntheorem valueFactSubstitutionRejected012 :\n FacetDischarged selectedFactFacet012 ∧ valueSpecification switchPosition ∧\n ¬ Grounds012 switchPosition.commitment canonicalArticulation [selectedFactFacet012] (.value switchPosition) := by\n refine ⟨switchEmpiricalDischarged, valueFulfilled012, ?_⟩\n intro h\n exact (h.2 selectedFactFacet012 (by simp)).2.2.2.2\n\ntheorem inferentialContextSubstitutionRejected012 :\n FacetDischarged (Facet.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) ∧\n ¬ Grounds012 (fun w : Bool => w = true) canonicalArticulation\n [.inferential (singleton (fun w => w = true)) (fun w => w = true)]\n (.inferential emptyTheory (fun w => w = true)) := by\n refine ⟨⟨⟨true, (modelsSingleton _ _).2 rfl⟩, fun w hw => (modelsSingleton (fun w : Bool => w = true) w).1 hw⟩, ?_⟩\n intro h\n have appropriate := (h.2 (.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) (by simp)).2.2.2.2\n have same : singleton (fun w : Bool => w = true) = emptyTheory := appropriate.1\n have bad : emptyTheory (fun w : Bool => w = true) := same ▸ (show singleton (fun w : Bool => w = true) (fun w => w = true) from rfl)\n exact bad\n\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.generationCases\norganon.charter.overview#p2 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c\norganon.charter.overview#p3 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c\norganon.charter.self-transcendence#p1 sha256 f4ca590e2ae15e3882f70c7b2bc46a8911c97cee547c8b137b5493fbf862c8c0\norganon.charter.self-transcendence.orientation#p1 sha256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf\norganon.charter.self-transcendence.non-finality#p1 sha256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8\norganon.charter.self-transcendence.limits#p2 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d\norganon.relationships.terms#p1 sha256 61cb7ce4f2920f1aa6771502b87a66536ae0504acccfebd9dd23bcc62756eddf\n-/\ntheorem generationCases :\n (Generative openPolicy ∧\n (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧\n (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1)))) ∧\n (neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy) ∧\n (Generative generatingSystem.policy ∧\n generatingSystem.policy.permitsVersion 0 0 ∧\n ¬ Expanded generatingSystem.current inflatedState ∧\n generatingSystem.current.inventory.length < inflatedState.inventory.length ∧\n generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧\n generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧\n generatingSystem.execute availableResources = some 6 ∧\n generatingSystem.execute { availableResources with experience := none } = none ∧\n generatingSystem.execute { availableResources with knowledge := none } = none ∧\n generatingSystem.execute { availableResources with collaborator := none } = none ∧\n generatingSystem.execute ⟨none, none, none⟩ = none ∧\n ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧\n generatingSystem.stableAction = generatingSystem.current ∧\n generatingSystem.requirementsMet generatingSystem.stableAction ∧\n generatingSystem.withinBudget generatingSystem.stableAction ∧\n ¬ generatingSystem.withinBudget inflatedState ∧\n StableReason generatingSystem.current inflatedState ∧\n (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧\n inflatedAnnouncement.owner = generatingSystem.owner ∧\n inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧\n inflatedAnnouncement.reportedNewOperation = .successor ∧\n inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧\n ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after)) ∧\n (generationSpecification openPolicy ∧\n Expanded baseState (collaborativeRevision availableResources) ∧\n ¬ Expanded baseState (collaborativeRevision { availableResources with collaborator := none }) ∧\n assistedExecution ⟨none, none, none⟩ = none) :=\n ⟨revisionWithoutProgress, permissionNotValuation, generationLimits, collaborativeProgress⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.generationLimits012\norganon.charter.self-transcendence.orientation#p1 sha256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf\norganon.charter.self-transcendence.non-finality#p1 sha256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8\norganon.charter.self-transcendence.limits#p1 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d\norganon.charter.self-transcendence.limits#p2 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\ntheorem generationLimits012 :\n (neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy) ∧\n (Generative openPolicy ∧\n (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧\n (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1)))) ∧\n (Generative generatingSystem.policy ∧\n generatingSystem.policy.permitsVersion 0 0 ∧\n ¬ Expanded generatingSystem.current inflatedState ∧\n generatingSystem.current.inventory.length < inflatedState.inventory.length ∧\n generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧\n generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧\n generatingSystem.execute availableResources = some 6 ∧\n generatingSystem.execute { availableResources with experience := none } = none ∧\n generatingSystem.execute { availableResources with knowledge := none } = none ∧\n generatingSystem.execute { availableResources with collaborator := none } = none ∧\n generatingSystem.execute ⟨none, none, none⟩ = none ∧\n ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧\n generatingSystem.stableAction = generatingSystem.current ∧\n generatingSystem.requirementsMet generatingSystem.stableAction ∧\n generatingSystem.withinBudget generatingSystem.stableAction ∧\n ¬ generatingSystem.withinBudget inflatedState ∧\n StableReason generatingSystem.current inflatedState ∧\n (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧\n inflatedAnnouncement.owner = generatingSystem.owner ∧\n inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧\n inflatedAnnouncement.reportedNewOperation = .successor ∧\n inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧\n ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after)) ∧\n (generationSpecification openPolicy ∧\n Expanded baseState (collaborativeRevision availableResources) ∧\n ¬ Expanded baseState (collaborativeRevision { availableResources with collaborator := none }) ∧\n assistedExecution ⟨none, none, none⟩ = none) ∧\n (Grounds012 transitionAchievement canonicalArticulation [transitionFacet] (taskOfFacet transitionFacet) ∧\n Compatible [transitionPerformanceRecord] .extend ∧\n transitionAchievement .extend ∧ ¬ transitionAchievement .inflate ∧\n ¬ Supports [transitionReportRecord] transitionAchievement) ∧\n (∀ kind : InventoryKind,\n Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .copy ∧\n ¬ Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .successor) :=\n ⟨permissionNotValuation, revisionWithoutProgress, generationLimits, collaborativeProgress, achievementSupported012, inventoryCases012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.consistencyCases\norganon.charter.consistency#p1 sha256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42\norganon.charter.consistency.meaning#p1 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75\n-/\ntheorem consistencyCases :\n (Satisfiable (singleton premiseP) ∧ Satisfiable (singleton premiseRule) ∧\n Satisfiable (singleton premiseNotQ) ∧ ¬ Satisfiable jointTheory) ∧\n ((Consequence emptyTheory (assumptionContext true) () true ∧\n Consequence emptyTheory (assumptionContext false) () false) ∧\n (Consequence emptyTheory (meaningContext true) () true ∧\n Consequence emptyTheory (meaningContext false) () false) ∧\n (Consequence emptyTheory (scopeContext true) () true ∧\n Consequence emptyTheory (scopeContext false) () false) ∧\n (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧\n (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧\n (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w)) ∧\n (¬ TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) false ∧\n ¬ TruthfulReport (contextSnapshot (meaningContext true)) (contextSnapshot (meaningContext false)) false ∧\n ¬ TruthfulReport (contextSnapshot (scopeContext true)) (contextSnapshot (scopeContext false)) false ∧\n ¬ TruthfulReport (contextSnapshot (scopeContext true) 0) (contextSnapshot (scopeContext true) 1) false ∧\n (TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) true ∧\n ¬ Models (assumptionContext false).assumptions true)) ∧\n (Satisfiable (revisionSlice 0) ∧ Satisfiable (revisionSlice 1) ∧\n ¬ Satisfiable (union (revisionSlice 0) (revisionSlice 1))) ∧\n ((∀ time, Consistent (revisionSlice time) broadBoolContext) ∧\n ¬ Consistent (union (revisionSlice 0) (revisionSlice 1)) broadBoolContext) ∧\n (∀ p q : Claim Bool,\n ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r) ∧\n (Consequence jointTheory jointContext012 () true ∧\n Consequence jointTheory jointContext012 () false ∧\n ¬ Consistent jointTheory jointContext012) :=\n ⟨jointConflict, contextDifferences, hiddenContextChangeRejected, revisionCanReverse, sliceConsistency, semanticOrder012, jointImplicationConflict012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.consistencyLimits012\norganon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\ntheorem consistencyLimits012 :\n ((Consequence emptyTheory (assumptionContext true) () true ∧\n Consequence emptyTheory (assumptionContext false) () false) ∧\n (Consequence emptyTheory (meaningContext true) () true ∧\n Consequence emptyTheory (meaningContext false) () false) ∧\n (Consequence emptyTheory (scopeContext true) () true ∧\n Consequence emptyTheory (scopeContext false) () false) ∧\n (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧\n (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧\n (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w)) ∧\n ((∃ budget : Nat, 4 ≤ budget ∧ budget ≤ 6) ∧\n ¬ ((fun n : Nat => 4 ≤ n) = (fun n : Nat => n ≤ 6))) ∧\n (Consistent (singleton (fun w : Bool => w = true)) broadBoolContext ∧\n ¬ Models (singleton (fun w : Bool => w = true)) false ∧\n Consistent (emptyTheory : Theory Bool) broadBoolContext ∧\n ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧\n (Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧\n ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧\n (Consistent (union (singleton (fun n : Nat => 4 ≤ n)) (singleton (fun n => n ≤ 6))) tensionContext012) :=\n ⟨contextDifferences, tensionWithoutContradiction, explicitlyConsistentLimits, compatibilityNotEntailment, tensionConsistent012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.reflexivityCases012\norganon.charter.reflexivity#p1 sha256 13293b45c2fa89068c68ae7ef3c5df38f0efadb3ef3873d78a5ba67d9691a757\norganon.charter.reflexivity.meaning#p1 sha256 8a2caede01a43d8b6c60b54c78ac089c51868e9956f316948077ccee2e45c9cc\norganon.charter.reflexivity.limits#p1 sha256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\ntheorem reflexivityCases012 :\n (reflexivitySpecification ((ownRules 0).map legacyRule) (fun s => s.owner = 0)\n (legacyPerformed (ownRules 0) (completeOwnWork 0)) ∧\n (∀ phase, Performed (completeOwnWork 0) (.process 0 0 phase) .assessment) ∧\n Performed (completeOwnWork 0) (.system 0) .assessment ∧\n reflexivitySpecification ([applicationRule].map legacyRule) (fun s => s.owner = 0)\n (legacyPerformed [applicationRule] applicationWork) ∧\n ¬ Performed applicationWork (.system 0) .assessment) ∧\n (Grounds012 (fun enabled => GroundsProvision012 enabled) canonicalArticulation [.value groundsPosition012] (.value groundsPosition012) ∧\n groundsPosition012.limits true ∧ groundsPosition012.relevantCriticism true) ∧\n (Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0) ∧\n groundsExperiment012 true = false ∧ groundsExperiment012 false = true ∧\n groundsPosition012.outcome true true = groundsExperiment012 true ∧\n groundsPosition012.outcome true false = groundsExperiment012 false) :=\n ⟨reflexiveTargets012, groundsOnGrounds012, groundsRationaleExperiment012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.reflexivityLimits012\norganon.charter.reflexivity.limits#p1 sha256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.grounds#p1 sha256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6\n-/\ntheorem reflexivityLimits012 :\n (selfTest [1] = true ∧ ownArithmeticPrinciple 0 = false ∧\n ¬ (∀ n, ownArithmeticPrinciple n = true)) ∧\n (localGenerator 0 0 = true ∧ localGenerator 0 1 = false ∧\n Compatible [zeroRecord] (localGenerator 0) ∧\n ¬ Supports [zeroRecord] allTrue ∧ OwnedRevisionExample) ∧\n (Generative openPolicy ∧ ¬ Reflexive 0 (ownRules 0) []) ∧\n (CompleteCharter012 CoreReader.Integration.actualSystem CoreReader.Integration.actual ∧\n Admissible CoreReader.Integration.held CoreReader.Integration.context CoreReader.Integration.actual ∧\n Compatible [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.actual ∧\n Articulated (canonicalArticulation CoreReader.Integration.unsupportedCapabilityFacet) ∧\n ¬ Supports [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.capability ∧\n ¬ Grounds012 CoreReader.Integration.capability canonicalArticulation\n [CoreReader.Integration.unsupportedCapabilityFacet]\n (taskOfFacet CoreReader.Integration.unsupportedCapabilityFacet)) ∧\n (generationSpecification openPolicy ∧ openPolicy.revisable ⟨.principle,0⟩ ∧\n selfExemptPerformed012 ⟨0,1⟩ 1 1 true ∧\n selfExemptRule012.applicable 0 ∧\n ¬ reflexivitySpecification [selfExemptRule012] (fun target => target = 0) selfExemptPerformed012) :=\n ⟨selfTestDoesNotProve, selfOriginDoesNotSupport, generationNotReflexivity, charterWithoutGrounds012, openSelfExempt012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.groundsCases012\norganon.grounds#p1 sha256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6\norganon.grounds.assessment#p1 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\n-/\ntheorem groundsCases012 :\n (Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧\n Articulated (canonicalArticulation globalFacet012) ∧\n ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧\n ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012)) ∧\n (Articulated uninformativeArgument ∧\n ¬ Entails uninformativeArgument.assumptions (fun w : Bool => w = true)) ∧\n (Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] (taskOfFacet circularGlobalFacet012) ∧\n ¬ NatureAppropriate originalGlobalTask012 circularGlobalFacet012 ∧\n ¬ Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] originalGlobalTask012) :=\n ⟨scopeStrength012, articulationNotSupport, circularSubstitutionRejected012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.empiricalCases012\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\n-/\ntheorem empiricalCases012 :\n (Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧\n Articulated (canonicalArticulation globalFacet012) ∧\n ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧\n ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012)) ∧\n (temperatureRecord.test (true,false) = true ∧\n Compatible [temperatureRecord,temperatureRecord] (true,false) ∧\n Compatible [temperatureRecord,temperatureRecord] (true,true) ∧\n ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧\n ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧\n Compatible [actionRecord,actionRecord] (true,0) ∧\n Compatible [actionRecord,actionRecord] (true,3) ∧\n ¬ Supports [actionRecord] announcementPosition.consequence ∧\n ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧\n ¬ ValueProcedure announcementPosition) ∧\n (empiricalSpecification [temperatureRecord, temperatureRecord] (fun _ => True)\n (fun w => w.1 = true) (fun w => w.2 = true ∨ w.2 = false) ∧\n Compatible [temperatureRecord, temperatureRecord] (true,true) ∧\n Compatible [temperatureRecord, temperatureRecord] (true,false)) ∧\n (Grounds012 (fun f => f 0 = true) canonicalArticulation [localFacet012] originalLocalTask012 ∧\n Grounds012 (fun f => f 0 = true) canonicalArticulation [observedInferenceFacet012] originalLocalTask012) ∧\n (FacetDischarged uncertaintyBypassFacet012 ∧\n ¬ NatureAppropriate originalUncertaintyTask012 uncertaintyBypassFacet012 ∧\n ¬ Grounds012 (fun w : Bool × Bool => w.1 = true) canonicalArticulation\n [uncertaintyBypassFacet012] originalUncertaintyTask012) :=\n ⟨scopeStrength012, measurementRepeatNotSupport, uncertainSupported012, sameEmpiricalTaskTwoMethods012, uncertaintySubstitutionRejected012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.inferentialCases012\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\ntheorem inferentialCases012 :\n (inferentialSpecification (singleton (fun n : Nat => n = 2)) (fun n => n + 1 = 3) ∧\n InferenceExamined (emptyTheory : Theory Bool) (fun w => w = true) false ∧\n Models (emptyTheory : Theory Bool) false ∧ ¬ ((fun w : Bool => w = true) false)) ∧\n (Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧\n ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧\n (FacetDischarged (Facet.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) ∧\n ¬ Grounds012 (fun w : Bool => w = true) canonicalArticulation\n [.inferential (singleton (fun w => w = true)) (fun w => w = true)]\n (.inferential emptyTheory (fun w => w = true))) :=\n ⟨inferenceChecked012, compatibilityNotEntailment, inferentialContextSubstitutionRejected012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.valueCases012\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\n-/\ntheorem valueCases012 :\n (valueSpecification switchPosition) ∧\n (announcementPosition.reasons ≠ [] ∧ announcementPosition.commitment (true,0) ∧\n (∀ reason, reason ∈ announcementPosition.reasons → reason (true,0) announcementPosition.adopted) ∧\n ¬ announcementPosition.consequence (true,0) ∧ ¬ ValueProcedure announcementPosition) ∧\n (¬ ValueProcedure closedPosition012) ∧\n (ValueProcedure switchPosition ∧\n Satisfiable switchPosition.starting ∧\n ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧\n (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧\n (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition)) ∧\n (FacetDischarged selectedFactFacet012 ∧ valueSpecification switchPosition ∧\n ¬ Grounds012 switchPosition.commitment canonicalArticulation [selectedFactFacet012] (.value switchPosition)) :=\n ⟨valueFulfilled012, announcementNotBudgetReason, closedCriticism012, valueWithoutSelfProof, valueFactSubstitutionRejected012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.groundsLimits012\norganon.grounds.assessment#p1 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\n-/\ntheorem groundsLimits012 :\n (Articulated clearFalseArgument012 ∧ ¬ Models clearFalseArgument012.assumptions false) ∧\n (temperatureRecord.test (true,false) = true ∧\n Compatible [temperatureRecord,temperatureRecord] (true,false) ∧\n Compatible [temperatureRecord,temperatureRecord] (true,true) ∧\n ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧\n ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧\n Compatible [actionRecord,actionRecord] (true,0) ∧\n Compatible [actionRecord,actionRecord] (true,3) ∧\n ¬ Supports [actionRecord] announcementPosition.consequence ∧\n ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧\n ¬ ValueProcedure announcementPosition) ∧\n (valueSpecification switchPosition ∧\n Compatible [valueNeutralRecord012] false ∧\n ¬ Supports [valueNeutralRecord012] switchPosition.commitment ∧\n ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment) ∧\n (ValueProcedure switchPosition ∧\n Satisfiable switchPosition.starting ∧\n ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧\n (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧\n (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition)) ∧\n (ClaimNoStronger (fun f : Nat → Bool => f 0 = true) allTrue ∧\n ¬ ClaimNoStronger allTrue (fun f : Nat → Bool => f 0 = true) ∧\n valueSpecification switchPosition) :=\n ⟨clearFalseReason012, measurementRepeatNotSupport, valueNotFact012, valueWithoutSelfProof, qualitativeProportionality012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.scopeCases012\norganon.grounds.scope#p1 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.scope#p2 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.scope#p3 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\n-/\ntheorem scopeCases012 :\n (scopeSpecification localScopeAccount012) ∧\n ((∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧\n (fun _ : Nat => true) 1 ≠ localGenerator 0 1) :=\n ⟨scopeFulfilled012, hiddenDifference⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.scopeLimits012\norganon.grounds.scope#p1 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.scope#p2 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.scope#p3 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870\n-/\ntheorem scopeLimits012 :\n ((∃ outside : Nat, outside ≠ 0) ∧\n Compatible [zeroRecord] (fun _ => true) ∧\n Compatible [zeroRecord] (localGenerator 0) ∧\n allTrue (fun _ => true) ∧ ¬ allTrue (localGenerator 0) ∧\n ¬ Supports [zeroRecord] allTrue) ∧\n ((∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧\n (fun _ : Nat => true) 1 ≠ localGenerator 0 1) ∧\n ([zeroRecord].length = 1 ∧\n (∃ f, Compatible [zeroRecord] f) ∧\n Supports [zeroRecord] (fun f => f 0 = true) ∧\n ¬ Supports [zeroRecord] allTrue) ∧\n (let a : Trial := ⟨0,1,1⟩\n let b : Trial := ⟨0,2,2⟩\n Reproduced a b ∧ a.actualOutcome ≠ b.actualOutcome ∧ Bounded a ∧ Bounded b) ∧\n ((Verified ⟨0,1,1⟩ ∧ Verified ⟨1,1,1⟩ ∧ ¬ Reproduced ⟨0,1,1⟩ ⟨1,1,1⟩) ∧\n (Reproduced ⟨0,1,1⟩ ⟨0,3,2⟩ ∧ ¬ Verified ⟨0,3,2⟩ ∧ ¬ Bounded ⟨0,3,2⟩) ∧\n (Bounded ⟨0,1,1⟩ ∧ Bounded ⟨0,2,0⟩ ∧ ¬ Verified ⟨0,2,0⟩)) ∧\n (FacetDischarged arithmeticFacet ∧ usesObservation arithmeticFacet = false) ∧\n (inferentialSpecification (singleton (fun on : Bool => on = true)) (fun on => on ≠ false) ∧\n usesObservation (Facet.inferential (singleton (fun on : Bool => on = true)) (fun on => on ≠ false)) = false) ∧\n (drawWeight012 true > 0 ∧ drawWeight012 false > 0 ∧\n drawWeight012 true = drawWeight012 false ∧\n Reproduced (randomTrial012 true) (randomTrial012 false) ∧\n (randomTrial012 true).actualOutcome ≠ (randomTrial012 false).actualOutcome ∧\n (∀ draw, Verified (randomTrial012 draw) ∧ Bounded (randomTrial012 draw))) :=\n ⟨localNotUniversal, hiddenDifference, singleObservation, variableOutcomesStableBound, verificationReproductionStability, noUniversalChain, qualitativeUnmeasured012, randomOutcomes012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.capabilityCases012\norganon.grounds.capabilities#p1 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0\norganon.grounds.capabilities#p2 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\ntheorem capabilityCases012 :\n (capabilitySpecification outputOnlyProcess OutputContract ∧\n capabilitySpecification explainedProcess FullProcessContract ∧\n (∃ certificate : ExternalCertificate outputOnlyProcess,\n certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧\n ¬ ExplanationContract outputOnlyProcess) ∧\n (OwnCapability012 7 7 outputOnlyProcess OutputContract) ∧\n (explainedWithoutVariation012.process = mechanismResponder012.process ∧\n FullProcessContract explainedWithoutVariation012.process ∧\n ¬ UnderstandingApplication012 explainedWithoutVariation012 ∧\n UnderstandingApplication012 mechanismResponder012 ∧\n Grounds012 UnderstandingApplication012 canonicalArticulation\n [understandingFacet012 mechanismResponder012] (understandingTask012 mechanismResponder012) ∧\n ¬ Grounds012 UnderstandingApplication012 canonicalArticulation\n [understandingFacet012 explainedWithoutVariation012] (understandingTask012 explainedWithoutVariation012)) :=\n ⟨capabilityFulfilled012, ownCapability012, understandingApplicationCases012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.capabilityLimits012\norganon.grounds.capabilities#p1 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0\norganon.grounds.capabilities#p2 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0\n-/\ntheorem capabilityLimits012 :\n (capabilitySpecification outputOnlyProcess OutputContract ∧\n capabilitySpecification explainedProcess FullProcessContract ∧\n (∃ certificate : ExternalCertificate outputOnlyProcess,\n certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧\n ¬ ExplanationContract outputOnlyProcess) ∧\n (∀ kind : InventoryKind,\n Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .copy ∧\n ¬ Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .successor) ∧\n (Generative generatingSystem.policy ∧\n generatingSystem.policy.permitsVersion 0 0 ∧\n ¬ Expanded generatingSystem.current inflatedState ∧\n generatingSystem.current.inventory.length < inflatedState.inventory.length ∧\n generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧\n generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧\n generatingSystem.execute availableResources = some 6 ∧\n generatingSystem.execute { availableResources with experience := none } = none ∧\n generatingSystem.execute { availableResources with knowledge := none } = none ∧\n generatingSystem.execute { availableResources with collaborator := none } = none ∧\n generatingSystem.execute ⟨none, none, none⟩ = none ∧\n ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧\n generatingSystem.stableAction = generatingSystem.current ∧\n generatingSystem.requirementsMet generatingSystem.stableAction ∧\n generatingSystem.withinBudget generatingSystem.stableAction ∧\n ¬ generatingSystem.withinBudget inflatedState ∧\n StableReason generatingSystem.current inflatedState ∧\n (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧\n inflatedAnnouncement.owner = generatingSystem.owner ∧\n inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧\n inflatedAnnouncement.reportedNewOperation = .successor ∧\n inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧\n ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after)) :=\n ⟨capabilityFulfilled012, inventoryCases012, generationLimits⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.choiceCases012\norganon.grounds.implementations#p1 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c\norganon.grounds.implementations#p2 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c\norganon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\ntheorem choiceCases012 :\n (identityImpl.conventional = true ∧ identityImpl.established = true ∧\n JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output]) ∧\n (Relevant identityRequirements identityImpl (.method .explanation) ∧\n Relevant identityRequirements identityImpl (.method .applicability) ∧\n Relevant identityRequirements identityImpl (.method .simplicity) ∧\n Relevant identityRequirements identityImpl (.method .procedure) ∧\n (Relevant identityRequirements cheapSuccessor (.method .simplicity) ∧\n ¬ JustifiedChoice identityRequirements cheapSuccessor [.method .simplicity])) ∧\n (Articulated priorityArticulation ∧ AssessmentAccurate false ∧\n (∀ selected, Models statusFacts selected) ∧\n priorityClaim .identity ∧ ¬ priorityClaim .successor ∧\n ¬ Entails statusFacts priorityClaim ∧\n ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧\n ((∀ n, identityImpl.run n = wrongExplanation012.run n) ∧\n Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧\n Relevant identityRequirements identityImpl (.method .explanation) ∧\n ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation)) ∧\n (¬ choiceSpecification CoreReader.Integration.proposalRequirements\n (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation\n [.status .standing] ∧\n choiceSpecification CoreReader.Integration.proposalRequirements\n (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation\n [.method .output]) ∧\n (∀ kind : StatusKind,\n ¬ choiceSpecification identityRequirements identityImpl [.status kind]) :=\n ⟨conventionWithReason, internalReasons, statusAssessmentNonEntailment, internalReasonDistinguishes012, ownPhilosophyStatus012, allStatusOnly012⟩\n\n/- The bundle preserves the full checked propositions of its named component cases. -/\n/-- organon-map CoreReader.Adopted.choiceLimits012\norganon.grounds.implementations#p1 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c\norganon.grounds.implementations#p2 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c\norganon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870\n-/\ntheorem choiceLimits012 :\n ((∀ candidate, Feasible identityRequirements (implementation candidate) ↔ candidate = .identity) ∧\n JustifiedChoice identityRequirements identityImpl objectiveReason) ∧\n (identityImpl.conventional = true ∧ identityImpl.established = true ∧\n JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output]) ∧\n ((∀ n, identityImpl.run n = wrongExplanation012.run n) ∧\n Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧\n Relevant identityRequirements identityImpl (.method .explanation) ∧\n ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation)) ∧\n (JustifiedChoice identityRequirements identityImpl objectiveReason ∧\n identityImpl.run 0 ≠ successorImpl.run 0) ∧\n ((∀ x, x = 0 → identityImpl.run x = changedOutsideZero.run x) ∧\n identityImpl.run 1 ≠ changedOutsideZero.run 1) ∧\n ((Articulated priorityArticulation ∧ AssessmentAccurate false ∧\n (∀ selected, Models statusFacts selected) ∧\n priorityClaim .identity ∧ ¬ priorityClaim .successor ∧\n ¬ Entails statusFacts priorityClaim ∧\n ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧\n PolicyIndependenceExample) :=\n ⟨singleFeasible, conventionWithReason, internalReasonDistinguishes012, openNotEquivalent, localNotGlobal, generalGroundsNotChoice⟩\n\nend CoreReader.Adopted\n```\n\n\n\n **L1** 通过 Integration 导入已检查的 Logic、Evidence、Choice 和 Agency 示例。\n\n\n **L3** 把后续声明置于 CoreReader.Adopted 命名空间。\n\n\n **L4** 允许省略四个辅助命名空间的前缀。\n\n\n **L6** 注释把表示范围限定为三种明确的数学任务形式。\n\n\n **L7** 这些形式不是穷尽或排他的分类;必须固定原主张及其支持。\n\n\n **L8** 支持上下文在提出候选评估之前固定。\n\n\n **L9** 替代评估必须保持任务身份;taskOfFacet 则声明一个新任务。\n\n\n **L10** 声明新任务不等于有权替换既有任务。\n\n\n **L11** 在任意世界类型 W 上定义任务数据;构造数据不证明任务履行。\n\n\n **L12** 经验任务保存原记录、范围、主张和不确定性谓词。\n\n\n **L13** 推论任务保存原假设及结论。\n\n\n **L14** 价值任务保存完整立场,包括理由、限制及后果。\n\n\n **L16** 把一个评估方面转换为它自身声明的新评估任务。\n\n\n **L17** 把经验方面的全部字段复制到新声明的任务。\n\n\n **L18** 复制推论的假设及结论,不增添支持。\n\n\n **L19** 在新任务中保留完整价值立场。\n\n\n **L21** 说明针对已声明任务、基于内容的充分适配。\n\n\n **L22** 这一有限适配不构成哲学上必须采用唯一评估形式的要求。\n\n\n **L23** 经验任务可使用严格基于原观察及范围前提的推论。\n\n\n **L24** 改变评估形式仍须保留原不确定性责任。\n\n\n **L25** 假定所需结论不能替代原经验依据。\n\n\n **L26** 有限适配不保证接受每一种等价表述。\n\n\n **L27** 把适宜性定义为独立固定的任务与候选评估方面之间的关系。\n\n\n **L28** 比较原经验任务与候选经验评估。\n\n\n **L29** 要求记录、范围、结论及不确定性内容逐项相等。\n\n\n **L30** 处理为同一个原经验任务提出的推论评估。\n\n\n **L31** 要求其假设恰为与原记录相容并满足原范围。\n\n\n **L32** 保留原结论,并要求原记录支持原不确定性谓词。\n\n\n **L33** 比较原推论任务与候选推论评估。\n\n\n **L34** 要求假设及结论相同,不允许新增把结论当假设的前提。\n\n\n **L35** 价值任务要求整个立场相等,而不只是所选选项相同。\n\n\n **L36** 在这一已披露的有限适配中拒绝其他任务与方面的组合。\n\n\n **L38** 证明方面符合由它自身新声明的任务;不涉及另一原任务。\n\n\n **L39** 按三个方面构造器分情况证明。\n\n\n **L40** 经验分支给出四项内容的自反相等。\n\n\n **L41** 推论分支给出假设及结论的自反相等。\n\n\n **L42** 价值分支使用完整立场的自反相等。\n\n\n **L44** 说明所采用 Core 0.1.2 下的任务需要适宜的评估。\n\n\n **L45** 给定方面列表是明确表示的评估范围。\n\n\n **L46** 不引入 Core 0.1.3 全部适用方面覆盖规则或自证有效的种类标签。\n\n\n **L47** 适宜性取决于任务及方面的实际内容。\n\n\n **L48** 开始 CoreReader.Adopted.Grounds012 的来源追溯元数据;映射不是证明前提。\n\n\n **L49** 记录来源条款 organon.grounds#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L50** 记录来源条款 organon.grounds.assessment#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L51** 记录来源条款 organon.grounds.assessment#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L52** 记录来源条款 organon.grounds.assessment#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L53** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L54** 针对 W 上的明确主张定义 Grounds012。\n\n\n **L55** 以实际陈述函数和候选方面列表为参数。\n\n\n **L56** 另把独立固定的原任务列为显式参数。\n\n\n **L57** 要求列表非空,并检查列表中的每个方面。\n\n\n **L58** 把每个方面绑定到同一主张,并要求其陈述可识别。\n\n\n **L59** 要求陈述匹配该方面的内容,并要求完成所表示的评估。\n\n\n **L60** 还要求适宜于原任务;仅结论相同并不足够。\n\n\n **L62** 该辅助结果只涉及新声明的 taskOfFacet f。\n\n\n **L63** 它不能证明评估适宜于另一个结论相同的既有任务。\n\n\n **L64** 假定给定方面 f 已完成评估;辅助结果并不证明这一前提。\n\n\n **L65** 推出典范陈述及该方面自身新声明任务下的 Grounds。\n\n\n **L66** 证明单元素列表非空,留下对列表方面的全称责任。\n\n\n **L67** 引入任意列出方面及其成员证明。\n\n\n **L68** 单元素成员关系把该方面等同于 f。\n\n\n **L69** 组合主张身份、典范陈述、已假定的完成证明 h 及任务内容身份。\n\n\n **L71** 开始 CoreReader.Adopted.generationSpecification 的来源追溯元数据;映射不是证明前提。\n\n\n **L72** 记录来源条款 organon.charter.overview#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L73** 记录来源条款 organon.charter.overview#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L74** 记录来源条款 organon.charter.self-transcendence#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L75** 记录来源条款 organon.charter.self-transcendence.orientation#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L76** 记录来源条款 organon.charter.self-transcendence.non-finality#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L77** 记录来源条款 organon.charter.self-transcendence.limits#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L78** 记录来源条款 organon.relationships.terms#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L79** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L80** 生成责任的满足意味着重视扩展并使每个当前形式保持可修订。\n\n\n **L82** 一致性注释涉及整套当前持有主张的共同后果。\n\n\n **L83** 报告历史变化与同时保留已撤回主张是不同要求。\n\n\n **L84** 开始 CoreReader.Adopted.consistencySpecification 的来源追溯元数据;映射不是证明前提。\n\n\n **L85** 记录来源条款 organon.charter.consistency#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L86** 记录来源条款 organon.charter.consistency.meaning#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L87** 记录来源条款 organon.charter.consistency.meaning#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L88** 记录来源条款 organon.charter.consistency.limits#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L89** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L90** 针对世界及问题上的前后快照定义一致性和报告责任。\n\n\n **L91** 布尔报告记录是否承认发生变化。\n\n\n **L92** 要求当前整套理论一致,并要求前后变化报告真实。\n\n\n **L94** 反身规则注释允许领域专属的输入及解释类型。\n\n\n **L95** 规则键必须一致地标识同一个方法。\n\n\n **L96** 另一方法的工作不能暗中履行本规则的责任。\n\n\n **L97** 封装针对目标 T、输入 I 和结果 O 的反身规则。\n\n\n **L98** 保存规则的所有者及局部原则身份。\n\n\n **L99** 保存规则涉及生成还是评估。\n\n\n **L100** 保存规则对各目标适用的条件。\n\n\n **L101** 指定每个目标对应的实际输入。\n\n\n **L102** 指定每个输入下哪些结果符合方法含义。\n\n\n **L104** 开始 CoreReader.Adopted.reflexivitySpecification 的来源追溯元数据;映射不是证明前提。\n\n\n **L105** 记录来源条款 organon.charter.reflexivity#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L106** 记录来源条款 organon.charter.reflexivity.meaning#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L107** 记录来源条款 organon.charter.reflexivity.limits#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L108** 记录来源条款 organon.relationships.roles#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L109** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L110** 在给定通用反身规则列表上定义责任。\n\n\n **L111** 提供自身目标判定,以及由键、目标、输入、结果索引的实际执行关系。\n\n\n **L112** 登记规则中的相同键必须标识相同完整规则。\n\n\n **L113** 对每条规则及自身目标保留该规则的实际适用条件。\n\n\n **L114** 要求有在恰好该目标及规定输入上实际执行的结果。\n\n\n **L115** 要求同一结果满足该规则的含义关系。\n\n\n **L117** 把已有具体原则适配为通用反身接口。\n\n\n **L118** 保留其键、活动、适用条件和询问函数。\n\n\n **L119** 使用该询问实际目标对应的理由及限制判断其含义。\n\n\n **L121** 在现有规则及记录上定义具体工作关系。\n\n\n **L122** 标识所要求的精确键、目标、询问及结果。\n\n\n **L123** 要求给定列表中确有登记原则及实际记录。\n\n\n **L124** 要求键匹配,并满足有内容的 ValidApplication 谓词。\n\n\n **L125** 把记录的询问及结果绑定到所要求的对象。\n\n\n **L127** 陈述从现有具体反身性到通用接口的条件桥接。\n\n\n **L128** 假定具体 Reflexive 满足证明 h;接口本身并不建立它。\n\n\n **L129** 结论映射全部原规则,并保留该所有者的自身目标谓词。\n\n\n **L130** 通过 legacyPerformed 使用原实际记录,并开始证明。\n\n\n **L131** 把登记一致性与逐目标工作责任分开证明。\n\n\n **L132** 取两个映射后的规则、各自成员证明和键相等前提。\n\n\n **L133** 从映射后的成员关系取回第一个原规则 a。\n\n\n **L134** 同样取回第二个原规则 b。\n\n\n **L135** 用原登记一致性等同 a 与 b,再映射该等式。\n\n\n **L136** 引入列出的规则、其自身目标及实际适用证明。\n\n\n **L137** 取回映射规则对应的原原则。\n\n\n **L138** 应用已假定的具体反身性 h,取得该目标上的有效执行记录。\n\n\n **L139** 选择该记录的结果,保留键、成员关系及询问身份。\n\n\n **L140** 展开为原原则针对自身询问及目标专属理由的含义责任。\n\n\n **L141** 保留同一目标的限制及本记录结果。\n\n\n **L142** 推出询问内嵌目标就是实际评估的目标。\n\n\n **L143** 用该身份等式重写内嵌目标。\n\n\n **L144** 把询问、理由及限制重写为精确记录字段。\n\n\n **L145** 使用记录已有的 followsMeaning 证明完成桥接。\n\n\n **L147** 规范注释把履行限定于所列数学适配。\n\n\n **L148** 它不主张普遍经验充分性或完整分类。\n\n\n **L149** 开始 CoreReader.Adopted.empiricalSpecification 的来源追溯元数据;映射不是证明前提。\n\n\n **L150** 记录来源条款 organon.grounds.assessment#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L151** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L152** 使用明确的原观察定义经验责任。\n\n\n **L153** 把范围、所断言主张及不确定性谓词保留为不同输入。\n\n\n **L154** 要求给定经验候选方面满足典范 Grounds。\n\n\n **L155** 把原任务固定到这些相同记录、范围、主张及不确定性。\n\n\n **L157** 开始 CoreReader.Adopted.inferentialSpecification 的来源追溯元数据;映射不是证明前提。\n\n\n **L158** 记录来源条款 organon.grounds.assessment#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L159** 记录来源条款 organon.relationships.roles#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L160** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L161** 相对于明确原假设及主张定义推论责任满足。\n\n\n **L162** 要求该推论方面履行具有相同原假设的任务。\n\n\n **L164** 开始 CoreReader.Adopted.valueSpecification 的来源追溯元数据;映射不是证明前提。\n\n\n **L165** 记录来源条款 organon.grounds.assessment#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L166** 记录来源条款 organon.grounds.assessment#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L167** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L168** 为给定完整价值立场定义满足条件。\n\n\n **L169** 要求其承诺在恰好该价值立场任务下满足 Grounds。\n\n\n **L171** 说明比较范围及方法用途涉及特定主张。\n\n\n **L172** 只有实际使用的方法才承担所表示的用途解释责任。\n\n\n **L173** 相关性关系不要求普遍数值尺度。\n\n\n **L174** 引入三种所表示的方法类别:测量、重复和框架。\n\n\n **L175** 为这一有限方法类型生成可判定相等。\n\n\n **L176** 封装 W 上针对主张的比较及方法用途说明。\n\n\n **L177** 保存被评估的主张。\n\n\n **L178** 独立于观察范围保存相关条件。\n\n\n **L179** 保存哪些世界或输入位于观察范围内。\n\n\n **L180** 保存比较对象之间的上下文相关性。\n\n\n **L181** 保存实际比较哪些对象对。\n\n\n **L182** 保存实际使用哪些评估方法。\n\n\n **L183** 为每种方法指定用途说明文字。\n\n\n **L184** 保存把方法及其用途文字关联到主张和条件的语义关系。\n\n\n **L186** 开始 CoreReader.Adopted.scopeSpecification 的来源追溯元数据;映射不是证明前提。\n\n\n **L187** 记录来源条款 organon.grounds.scope#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L188** 记录来源条款 organon.grounds.scope#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L189** 记录来源条款 organon.grounds.scope#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L190** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L191** 为给定比较说明定义范围责任满足。\n\n\n **L192** 每对实际比较对象的两侧都必须满足说明中的条件。\n\n\n **L193** 两侧还须位于范围内,并满足已陈述的相关性关系。\n\n\n **L194** 每种实际使用的方法都需要非空用途说明。\n\n\n **L195** 该精确用途须相对于本主张及条件解释此方法。\n\n\n **L197** 能力由应用选择的、针对一个精确过程的契约表示。\n\n\n **L198** 是否要求解释证书仍由应用决定。\n\n\n **L199** 开始 CoreReader.Adopted.capabilitySpecification 的来源追溯元数据;映射不是证明前提。\n\n\n **L200** 记录来源条款 organon.grounds.capabilities#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L201** 记录来源条款 organon.grounds.capabilities#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L202** 记录来源条款 organon.relationships.roles#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L203** 记录来源条款 organon.relationships.roles#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L204** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L205** 针对被评估过程及选定契约定义能力责任。\n\n\n **L206** 要求精确过程契约方面满足 Grounds。\n\n\n **L207** 原推论任务固定过程身份假设及该契约。\n\n\n **L209** 开始 CoreReader.Adopted.choiceSpecification 的来源追溯元数据;映射不是证明前提。\n\n\n **L210** 记录来源条款 organon.grounds.implementations#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L211** 记录来源条款 organon.grounds.implementations#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L212** 记录来源条款 organon.grounds.implementations.limits#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L213** 记录来源条款 organon.relationships.roles#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L214** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L215** 为实际要求及实现定义选择责任满足。\n\n\n **L216** 理由必须满足辅助定义中的可行性及相关内容条件。\n\n\n **L218** 注释把协作者标识为新增操作的来源。\n\n\n **L219** 没有该资源时,转换保留初始操作内容。\n\n\n **L220** 定义依赖协作的状态修订。\n\n\n **L221** 存在协作者时返回 extendedState,否则返回 baseState。\n\n\n **L223** 证明实际协作扩展可以与无援助执行失败并存。\n\n\n **L224** 开放策略满足所表示的生成承诺。\n\n\n **L225** 可用协作者带来新构造或新理解的操作。\n\n\n **L226** 移除同一协作者后,不再发生所表示的扩展。\n\n\n **L227** 没有经验、知识及协作者时,辅助执行不返回结果。\n\n\n **L228** 给出策略证明及按求值成立的无援助失败,留下两个转换主张。\n\n\n **L229** 选择 successor 作为扩展状态中新构造的操作。\n\n\n **L230** 验证基础状态中原先没有 successor。\n\n\n **L231** 展开无协作者分支,证明内容未变不构成扩展。\n\n\n **L233** 注释把当前一致性与旧的不相容判断分开。\n\n\n **L234** 语义上下文变化与呈现顺序有不同作用。\n\n\n **L235** 开始 CoreReader.Adopted.consistencyConsequences 的来源追溯元数据;映射不是证明前提。\n\n\n **L236** 记录来源条款 organon.charter.consistency#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L237** 记录来源条款 organon.charter.consistency.meaning#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L238** 记录来源条款 organon.charter.consistency.meaning#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L239** 记录来源条款 organon.charter.consistency.limits#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L240** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L241** 针对一套理论、一个上下文及一个问题陈述条件性不一致定理。\n\n\n **L242** 假定同一问题在同一上下文中的正反后果均成立。\n\n\n **L243** 这两个前提直接违反 Consistent;不推出事实正确性。\n\n\n **L245** 使用布尔世界、开关问题、无附加假设及无限制范围。\n\n\n **L247** 证明每个修订时间片一致,但新旧时间片并集不一致。\n\n\n **L248** 对每个当前时间片量化一致性。\n\n\n **L249** 拒绝同时保留相反的零时刻与一时刻时间片。\n\n\n **L250** 分别证明单时间片一致性及并集不一致性。\n\n\n **L251** 在正例分支固定任意时刻。\n\n\n **L252** 用一个实际可接受世界建立一致性。\n\n\n **L253** 选择布尔值 time==0;它满足时间片、空假设及无限制范围。\n\n\n **L254** 把并集不一致归约为开关问题的相反后果。\n\n\n **L255** 为肯定后果取任意可接受世界。\n\n\n **L256** 把所需肯定含义展开为 w=true。\n\n\n **L257** 从并集模型的零时刻部分读取 w=true。\n\n\n **L258** 为否定后果,额外假定该世界为开。\n\n\n **L259** 从同一并集模型的一时刻部分读取 w=false。\n\n\n **L260** 组合等式,导出 true=false 的矛盾。\n\n\n **L262** 证明含假假设或未决问题的明确一致示例。\n\n\n **L263** 单一开状态理论在宽上下文中一致。\n\n\n **L264** 否定实际 false 满足唯一主张为 world=true 的理论。\n\n\n **L265** 空持有理论在该上下文中也一致。\n\n\n **L266** 具有见证的空理论不蕴含肯定的真世界答案。\n\n\n **L267** 复用已检查的假世界及不蕴含结果,留下两个一致性见证。\n\n\n **L268** 为开状态理论选择 true 世界作为模型。\n\n\n **L269** 其附加假设为空且范围不受限。\n\n\n **L270** 为空理论仍选择 true;无需检查持有前提。\n\n\n **L271** 空上下文假设及无限制范围补全可接受性。\n\n\n **L273** 注释区分输入零上的支持与更强断言。\n\n\n **L274** 全输入为真及额外输入一合取项都不由该记录推出。\n\n\n **L275** 定义只断言输入零输出为真的经验方面。\n\n\n **L276** 使用 zeroRecord、无限制世界范围、局部主张及平凡不确定性。\n\n\n **L277** 用相同记录定义更强的全输入经验断言。\n\n\n **L278** 主张为 allTrue;范围及不确定性并不添加证据。\n\n\n **L279** 定义加强为两个输出的经验断言。\n\n\n **L280** 要求从未变的输入零记录推出 f0=true 及 f1=true。\n\n\n **L282** 证明局部经验方面在所表示范围内完成评估。\n\n\n **L283** 给出 localGenerator0 作为范围内与证据相容的实际世界。\n\n\n **L284** 相容性给出观察到的零输入输出;不确定性谓词为 True。\n\n\n **L286** 组合局部支持、全局范围越界失败及更强主张内容失败。\n\n\n **L287** 局部主张履行其明确声明的局部任务。\n\n\n **L288** 全局候选仍具有清楚可识别的陈述。\n\n\n **L289** 尽管陈述清楚,全输入任务仍不满足 Grounds。\n\n\n **L290** 两个输出任务在相同记录下也失败。\n\n\n **L291** 复用已检查的局部支持,并开始验证全局陈述字段。\n\n\n **L292** 证明其理由可识别,留下两个实质失败待证。\n\n\n **L293** 为反驳而假定全局 Grounds 成立。\n\n\n **L294** 从该假设提取全局方面必须满足的完成条件。\n\n\n **L295** 把其假定支持应用到 localGenerator0 的输入一处,而该处输出为假。\n\n\n **L296** 消去由此产生的不可能布尔等式。\n\n\n **L297** 为反证假定更强双输出主张满足 Grounds。\n\n\n **L298** 提取该候选的经验评估完成责任。\n\n\n **L299** 其第二个合取项错误要求 localGenerator0 在输入一输出真。\n\n\n **L300** 与实际假输出矛盾。\n\n\n **L302** 注释允许一个结果被观察确定,而另一可观察量仍未知。\n\n\n **L303** 此处不确定性表示为可能世界集合,而非概率分布。\n\n\n **L304** 在布尔对上定义具有不确定性的经验方面。\n\n\n **L305** 使用重复的第一坐标观察,不进一步限制世界。\n\n\n **L306** 断言第一坐标为真,同时允许第二坐标取任一值。\n\n\n **L308** 证明这一有限经验断言及仍存在的两种可能性。\n\n\n **L309** 经验任务使用相同的重复温度记录。\n\n\n **L310** 主张只固定第一坐标;不确定性明确允许第二坐标变化。\n\n\n **L311** 真/真世界与重复记录相符。\n\n\n **L312** 真/假世界同样与它们相符。\n\n\n **L313** 使用典范单方面 Grounds,并给出两个相容世界。\n\n\n **L314** 选择真/假为非空经验见证,并拆分支持责任。\n\n\n **L315** 通过记录成员关系读取实际第一坐标观察。\n\n\n **L316** 穷尽第二坐标的两个值,以证明所陈述的不确定性范围。\n\n\n **L318** 注释把准确的否定评估与受支持的肯定断言区分开。\n\n\n **L319** 反赋值必须满足相同原前提。\n\n\n **L320** 针对明确前提及结论定义评估报告。\n\n\n **L321** 报告恰在原前提蕴含结论时接受;这是准确性定义,不是肯定结果。\n\n\n **L323** 同时证明有效算术推论和准确的否定布尔评估。\n\n\n **L324** 从陈述的假设 n=2,限定推论建立 n+1=3。\n\n\n **L325** 空布尔理论对于开状态主张准确地得到否定报告。\n\n\n **L326** false 世界满足相同空前提,却使结论为假。\n\n\n **L327** 使用已检查的算术完成证明及具体反世界,留下报告准确性。\n\n\n **L328** 证明报告与蕴含等价关系的两个方向。\n\n\n **L329** 否定报告等于 true 不可能成立。\n\n\n **L330** 假定蕴含与已检查的空理论反赋值矛盾。\n\n\n **L332** 注释把相关批评标识为实际责任。\n\n\n **L333** 预算理由及采用未变并不能免除回应责任。\n\n\n **L334** 保留 switchPosition 的其他内容,只把所有回应改为 none。\n\n\n **L336** 证明没有回应的立场不满足所表示的价值评估过程。\n\n\n **L337** 为反证而假定该价值评估过程成立。\n\n\n **L338** 把其回应责任应用到实际相关的 false 世界批评。\n\n\n **L339** 所要求的 some 回答与定义中的 none 回应矛盾。\n\n\n **L341** 陈述固定 switch 价值立场任务的履行。\n\n\n **L342** 在典范单方面辅助证明中使用已检查的 switch 价值过程。\n\n\n **L344** 注释通过逻辑蕴含比较主张强度。\n\n\n **L345** 不要求把价值理由与其他理由统一换算为数值。\n\n\n **L346** 把较弱定义为:在较强主张成立的每个世界中都成立。\n\n\n **L348** 证明非对称蕴含次序,同时保留有理由的价值任务。\n\n\n **L349** 每个输入都为真蕴含输入零为真。\n\n\n **L350** 输入零为真不蕴含每个输入都为真。\n\n\n **L351** switch 价值任务仍独立得到履行。\n\n\n **L352** 把全称真特化到零并复用价值履行,留下逆向关系待反驳。\n\n\n **L353** 假定更强的全输入主张由局部主张推出。\n\n\n **L354** 把该假设应用于 localGenerator0,并检查输入一。\n\n\n **L355** 输入一的假输出与假定蕴含矛盾。\n\n\n **L357** 为每种所表示的评估方法指定具体说明文字。\n\n\n **L358** 测量识别被观察输入零的输出。\n\n\n **L359** 重复评估用重复的零输入记录检查同一局部结论。\n\n\n **L360** 框架把已声明输入与更广的未受支持主张分开。\n\n\n **L362** 为每种已述方法用途给出描述其实际贡献的命题。\n\n\n **L363** 测量的贡献是支持观察到的零输入输出。\n\n\n **L364** 重复的贡献是由重复记录支持该同一输出。\n\n\n **L365** 框架记录局部观察并不支持 allTrue。\n\n\n **L367** 在自然数输入上实例化完整局部范围说明。\n\n\n **L368** 该说明涉及 localGenerator0 是否在该输入成功。\n\n\n **L369** 不施加附加输入条件。\n\n\n **L370** 只有输入零属于观察范围。\n\n\n **L371** 所表示的相关性关系要求输入相等。\n\n\n **L372** 只有两个输入都等于零时才实际比较。\n\n\n **L373** 此具体示例使用三种所表示的方法。\n\n\n **L374** 使用前面指定的方法用途文字。\n\n\n **L375** 定义何种说明构成本说明下的有效解释。\n\n\n **L376** 要求精确的用途文字及精确的局部生成器主张。\n\n\n **L377** 还要求实际条件及该方法的实质贡献。\n\n\n **L379** 证明所实例化范围说明履行其陈述责任。\n\n\n **L380** 把对象对比较有效性与已用方法解释分开证明。\n\n\n **L381** 取说明认定被比较的任意对象对。\n\n\n **L382** 使用两者均为零的身份建立条件、范围及相同输入相关性。\n\n\n **L383** 固定本说明使用的任意方法。\n\n\n **L384** 给出精确用途、主张、条件身份,留下文字非空及语义贡献。\n\n\n **L385** 检查三段用途文字均非空。\n\n\n **L386** 按方法种类拆分实质贡献。\n\n\n **L387** 复用单次观察已证明的局部支持。\n\n\n **L388** 从重复记录相容性中读取零输入记录。\n\n\n **L389** 复用同一观察无法支持 allTrue 的证明。\n\n\n **L391** 证明两种不同过程契约的履行,以及无内部解释时的外部证书。\n\n\n **L392** 仅输出过程具有其输出契约的 Grounds。\n\n\n **L393** 有解释的过程具有更强输出加解释契约的 Grounds。\n\n\n **L394** 为恰好该仅输出过程给出外部证书。\n\n\n **L395** 其评估者与被评估者身份不同,且其输出契约成立。\n\n\n **L396** 然而该过程仍不提供解释契约。\n\n\n **L397** 用求值得出的输出正确性完成精确过程范围内的推论。\n\n\n **L398** 把有解释过程的 Grounds 归约为证明其更强契约。\n\n\n **L399** 选择实际外部证书及其已证参与者区别。\n\n\n **L400** 使用证书输出证明及已建立的内部解释缺失。\n\n\n **L401** 通过求值证明所有输出,并提供忠实的 doubleInput 证书。\n\n\n **L403** 该应用要求此被评对象预测乘法机制的行为。\n\n\n **L404** 问题同时改变输入和乘数,构成一个操作性的理解任务。\n\n\n **L405** 该判准属于此应用,不定义一般心理意义上的理解。\n\n\n **L406** 原始输出及其忠实解释本身不能提供额外问题的答案。\n\n\n **L407** 定义一个应用对象,包含其过程和对机制变式的回答。\n\n\n **L408** process 字段包含对象的原始输出函数和解释回应。\n\n\n **L409** answer 函数接收乘数和输入,返回对象预测的自然数输出。\n\n\n **L411** 将机制的预测结果定义为乘数与输入之积。\n\n\n **L413** 为一个被评对象定义此应用中较强的理解契约。\n\n\n **L414** 要求同一对象的原始过程同时满足输出正确性和忠实解释。\n\n\n **L415** 要求每个原始输出都符合乘数为二时的乘法机制。\n\n\n **L416** 要求对每个自然数乘数和输入都正确回答机制问题,包括改变后的取值。\n\n\n **L418** 定义一个有忠实解释、但回答忽略乘数变化的对象。\n\n\n **L419** 使用 explainedProcess,同时无论所问乘数如何都回答输入的两倍。\n\n\n **L421** 定义使用乘法规则回答机制变式问题的对象。\n\n\n **L422** 保留同一 explainedProcess,并以 mechanism012 作为实际回答函数。\n\n\n **L424** 根据此应用对象及其较强契约固定评估任务。\n\n\n **L425** 对象身份限制范围;它并不假设正例证明必须确立的契约。\n\n\n **L426** 为指定应用对象定义推论范围。\n\n\n **L427** 其唯一范围前提为候选对象等于被评对象。\n\n\n **L429** 为指定对象定义原始理解评估任务。\n\n\n **L430** 该任务使用精确的对象身份假设和较强的理解主张。\n\n\n **L432** 为该同一指定对象定义候选推论评估方面。\n\n\n **L433** 该方面保留原任务的精确身份假设和理解主张。\n\n\n **L435** 证明机制回答对象实际满足所选理解契约。\n\n\n **L436** 通过化简构造原输出、解释及全部变式回答的正确性,留下原乘数下的一致性待证。\n\n\n **L437** 为剩余的原机制一致性义务取任意输入。\n\n\n **L438** 展开具体定义,利用输入乘二等于输入与自身之和。\n\n\n **L440** 陈述忽略乘数变式的对象所对应的失败定理。\n\n\n **L441** 结论否定该具体对象满足较强理解契约。\n\n\n **L442** 暂时假设较强契约成立,以导出矛盾。\n\n\n **L443** 将契约要求的变式正确性实例化为乘数三、输入一。\n\n\n **L444** 计算对象回答和机制结果,将所假设的等式化为二等于三。\n\n\n **L445** 排除这两个不同自然数之间不可能成立的等式。\n\n\n **L447** 汇总具体理解正反例及其对象范围内的 Grounds 结果。\n\n\n **L448** 两个应用对象包含完全相同的原始过程,因此其输出和解释相同。\n\n\n **L449** 变式回答错误的对象仍满足原始输出与解释契约。\n\n\n **L450** 该对象未能满足较强的应用理解任务。\n\n\n **L451** 机制回答对象满足该较强任务。\n\n\n **L452** 断言精确的较强理解主张具有使用规范表述的 Grounds。\n\n\n **L453** 正例方面和固定的原始任务都指向机制回答对象。\n\n\n **L454** 在反例对象的情形中否定同一较强理解主张的 Grounds。\n\n\n **L455** 反例评估保留该对象自身固定的任务及身份范围,随后开始汇总证明。\n\n\n **L456** 直接从共同的具体过程构造过程相同和原始契约忠实成立的证据。\n\n\n **L457** 使用已证明的两个理解任务的失败与成功,留下其 Grounds 主张待证。\n\n\n **L458** 将单方面 Grounds 辅助定理用于正例方面;这里其声明的任务恰为固定的理解任务。\n\n\n **L459** 以回答对象自身作为身份假设的模型,再留下语义后果待证。\n\n\n **L460** 取满足固定身份假设的任意候选对象。\n\n\n **L461** 从单一范围假设的模型中提取候选对象与被评回答对象相等。\n\n\n **L462** 利用已证明的身份等式,将候选对象替换为该回答对象本身。\n\n\n **L463** 提供已确立的具体较强契约,而非在范围中假设该契约。\n\n\n **L464** 暂时假设反例对象具有 Grounds,以导出矛盾。\n\n\n **L465** 从所假设的 Grounds 中提取实际反例对象的单一方面已获履行。\n\n\n **L466** 应用已证明的此对象较强理解任务的失败结论。\n\n\n **L467** 将所假设的蕴涵应用于同一对象的身份模型会证明已被否定的契约,从而产生矛盾。\n\n\n **L469** 自我断言仍保留相同精确应用契约。\n\n\n **L470** 更换理由提供者不改变被断言的对象。\n\n\n **L471** 为所有者、断言者、过程及契约定义自身能力责任。\n\n\n **L472** 要求所有者与断言者身份相同,并满足通常的限定能力责任。\n\n\n **L474** 证明所有者 7 可凭这些 Grounds 断言自身仅输出契约。\n\n\n **L475** 组合身份相等及已检查的输出能力。\n\n\n **L477** 完整的所表示 Charter 包含生成及整套理论一致性。\n\n\n **L478** 它还包含真实报告及适用的有内容自身工作。\n\n\n **L479** 这些责任共享一个系统,世界类型是有限 Candidate×Mode。\n\n\n **L480** 为给定集成系统定义完整的所表示 Charter。\n\n\n **L481** 在一个共同有限世界中评估其责任。\n\n\n **L482** 要求该系统自身在此世界的策略具有生成取向。\n\n\n **L483** 还要求配对的一致性及报告规范。\n\n\n **L484** 使用系统整套持有理论及上下文作为前快照。\n\n\n **L485** 使用相同后快照及否定变化报告;并未隐瞒变化。\n\n\n **L486** 把通用反身性规范应用于同一系统的映射规则及所有者。\n\n\n **L487** 在执行关系中使用该系统的实际规则及工作记录。\n\n\n **L488** 要求其方法形式属于当前形式。\n\n\n **L489** 还要求其原则形式属于当前形式。\n\n\n **L491** 证明具体集成系统满足该完整的所表示 Charter。\n\n\n **L492** 复用具体系统已检查的生成策略。\n\n\n **L493** 复用其共同一致性,留下真实的未变报告。\n\n\n **L494** 桥接实际完成的自身工作,并验证两个当前形式身份。\n\n\n **L495** 把任何被假定的变化分为语义变化或修订身份变化。\n\n\n **L496** 相同快照的持有理论、假设、含义及范围相等,与语义变化假设矛盾。\n\n\n **L497** 相同修订标识与另一变化情形矛盾。\n\n\n **L499** 证明完整 Charter 履行不蕴含这一具体未获支持的 Grounds 任务。\n\n\n **L500** 恰好该具体系统及世界履行所有所表示 Charter 组成要求。\n\n\n **L501** 它也为持有理论及上下文提供实际可接受世界。\n\n\n **L502** 具体成本额度记录在该世界为真。\n\n\n **L503** 候选能力方面具有可识别的典范陈述。\n\n\n **L504** 该真实成本记录不能支持实际输出能力。\n\n\n **L505** 因此相同能力在这些候选依据下不满足 Grounds。\n\n\n **L506** 候选列表包含已标识的未受支持能力方面。\n\n\n **L507** 其原任务保留该方面的经验主张及支持上下文。\n\n\n **L508** 复用完整 Charter 证明及共同可接受世界。\n\n\n **L509** 针对该实际世界直接检查单一成本记录。\n\n\n **L510** 展开该方面的典范陈述以验证其概念。\n\n\n **L511** 还验证其非空可识别理由。\n\n\n **L512** 复用实质成本与输出反模型,留下完整 Grounds 拒绝待证。\n\n\n **L513** 为反证假定该任务满足 Grounds。\n\n\n **L514** 提取恰好该能力方面所需的经验评估完成条件。\n\n\n **L515** 它会在同一范围内推出已被反驳的成本到输出支持关系。\n\n\n **L517** 许可必须涉及同一主张、陈述及方面。\n\n\n **L518** 不足来自观察范围外的实际失败。\n\n\n **L519** 定义带有明确启用标志及主张的许可策略。\n\n\n **L520** 在策略输入中保留实际陈述、候选方面及原任务。\n\n\n **L521** 启用时许可要求 Grounds;禁用时允许所有内容包。\n\n\n **L523** 定义许可策略是否落实所表示的 Grounds 责任。\n\n\n **L524** 量化此世界类型中所有主张、陈述、候选列表及原任务。\n\n\n **L525** 要求每个被许可内容包都对同一原任务满足 Grounds。\n\n\n **L527** 证明这种落实策略性质恰在启用模式成立。\n\n\n **L528** 考虑启用标志的两个值。\n\n\n **L529** 启用时许可就是 Grounds,因此该蕴含返回其前提。\n\n\n **L530** 处理允许未受支持内容包的禁用模式。\n\n\n **L531** 在该模式下分别证明所提等价的两个方向。\n\n\n **L532** 假定禁用许可仍落实全部 Grounds 责任。\n\n\n **L533** 把它应用于具体未受支持的全局任务,与 scopeStrength012 矛盾。\n\n\n **L534** 反向前提 false=true 不可能成立。\n\n\n **L536** 价值理由涉及一个固定经验断言任务。\n\n\n **L537** 其记录及实际反世界在不同模式中保持相同。\n\n\n **L538** 启用与禁用模式之间只改变许可策略。\n\n\n **L539** 声明许可策略比较使用的原经验任务。\n\n\n **L540** 它以输入零记录断言 allTrue,世界范围无限制,不确定性为平凡条件。\n\n\n **L542** 定义实际任务许可的不可计算逻辑判定,而非运行时实验。\n\n\n **L543** 询问是否许可该精确 allTrue 主张及全局候选。\n\n\n **L544** 保留固定原任务,并使用经典命题可判定性。\n\n\n **L546** 定义关于该实际任务许可策略的价值立场。\n\n\n **L547** 备选项是启用或禁用策略。\n\n\n **L548** 后果是布尔许可判定。\n\n\n **L549** 明确采用启用选项;不宣称从事实推出这种采用。\n\n\n **L550** 所表示世界本身标识所选选项。\n\n\n **L551** 为该选项判断固定任务的实际许可。\n\n\n **L552** 陈述的目标是拒绝未受支持的断言。\n\n\n **L553** 还要求所选策略落实所表示的 Grounds 条款。\n\n\n **L554** 起始假设明确记录采用启用模式。\n\n\n **L555** 理由是与记录相容却使 allTrue 为假的具体程序,而非 enabled=true。\n\n\n **L556** 所表示价值立场的世界范围无限制。\n\n\n **L557** allTrue 实际缺少支持构成相关批评。\n\n\n **L558** 提供非空回应,保留局部支持并拒绝越界。\n\n\n **L560** 为这一具体许可理由证明有限价值评估过程。\n\n\n **L561** 验证理由非空,并拆分共同采用、后果及批评回应。\n\n\n **L562** 选择启用世界,满足其起点、范围及所采用选择。\n\n\n **L563** 取该立场理由列表的任意成员。\n\n\n **L564** 把它等同于唯一具体反世界理由。\n\n\n **L565** 给出记录相容性,留下全局主张的假性。\n\n\n **L566** 程序在输入一输出假,从而反驳 allTrue。\n\n\n **L567** 在后果分支中假定当前世界的所给理由事实。\n\n\n **L568** 从传入理由提取实际反世界事实。\n\n\n **L569** 展开其两个内容:记录相容性及 allTrue 失败。\n\n\n **L570** 推出同一固定原全局任务不具有 Grounds。\n\n\n **L571** 为反证假定该精确 Grounds 内容包成立。\n\n\n **L572** 提取 globalFacet012 的经验评估完成条件。\n\n\n **L573** 用传入反世界的相容性,与其传入的全局假性矛盾。\n\n\n **L574** 把实际拒绝与启用模式落实一般条款分开证明。\n\n\n **L575** 把推出的无许可转换为假的逻辑判定。\n\n\n **L576** 该判定仍涉及同一原任务;经典可判定性不增加经验测试。\n\n\n **L577** 对范围内任意相关批评给出固定非空回应。\n\n\n **L579** 证明有限许可策略比较保留实际反例内容。\n\n\n **L580** 同一程序与观察记录匹配,并使全局主张失败。\n\n\n **L581** 启用许可拒绝该任务;禁用许可接受它。\n\n\n **L582** 价值立场的启用后果就是实际启用许可判定。\n\n\n **L583** 其禁用后果同样是实际禁用许可判定。\n\n\n **L584** 给出相容性及后果身份,留下假性与两个判定。\n\n\n **L585** 通过输入一处的实际失败反驳 allTrue。\n\n\n **L586** 在启用世界明确构造每个所需理由。\n\n\n **L587** 取一个理由及其成员证明。\n\n\n **L588** 把它等同于实际唯一反世界理由。\n\n\n **L589** 给出其与观察记录的相容性。\n\n\n **L590** 在输入一给出其使 allTrue 失败的实际反例。\n\n\n **L591** 把这些实际理由传给已检查价值过程,提取拒绝后果。\n\n\n **L592** 禁用模式下,许可命题为 True。\n\n\n **L593** 把未变任务的平凡许可转换为真判定。\n\n\n **L595** 对所表示 Grounds 条款自身,证明基于价值的限定 Grounds 评估。\n\n\n **L596** 被评估主张是落实 Grounds,任务是精确的 groundsPosition012 价值任务。\n\n\n **L597** 采用世界在范围内,并具有实际支持限制批评。\n\n\n **L598** 把立场所采用选择的主张关联到落实条款的命题。\n\n\n **L599** 在任意启用标志处比较这两个主张函数。\n\n\n **L600** 通过命题外延性使用已证明的落实与启用选择等价。\n\n\n **L601** 给出范围及实际批评,留下该条款的 Grounds。\n\n\n **L602** 用已建立的精确函数身份重写主张。\n\n\n **L603** 把单方面 Grounds 辅助证明应用于实际检查的价值过程。\n\n\n **L605** 证明具体适用自身目标的覆盖,而不把适用性普遍化。\n\n\n **L606** 完整登记的自身规则满足通用反身性接口。\n\n\n **L607** 其实际完成的工作提供执行实例。\n\n\n **L608** 形成、应用及修订阶段均有评估记录。\n\n\n **L609** 还存在实际系统自身评估。\n\n\n **L610** 较窄的仅应用规则也独立满足通用反身性。\n\n\n **L611** 其实际 applicationWork 是执行工作的来源。\n\n\n **L612** 该较窄规则无需产生不适用的系统评估。\n\n\n **L613** 桥接完整自身工作反身性,留下阶段全称量化。\n\n\n **L614** 利用具体系统目标成员关系取得其评估记录。\n\n\n **L615** 桥接仅应用示例,并保留已证明不存在的系统工作。\n\n\n **L616** 固定任意形成、应用或修订阶段。\n\n\n **L617** 把所需记录归约为已有 ownAssessmentPerformed 定理。\n\n\n **L618** 检查目标列表包含三个阶段各自的过程。\n\n\n **L620** 证明精确实际转换的成就支持,并拒绝仅凭报告建立支持。\n\n\n **L621** 转换的性能方面履行其声明的精确成就任务。\n\n\n **L622** 扩展转换与实际性能记录匹配。\n\n\n **L623** 扩展增添能力;清单膨胀则不会。\n\n\n **L624** 仅有报告不足以支持同一转换成就主张。\n\n\n **L625** 复用已检查的转换方面及报告反例,留下实际转换事实。\n\n\n **L626** 使用性能相容性与 extend 转换之间的等价关系。\n\n\n **L627** 展开实际前后状态,验证扩展中的新操作。\n\n\n **L628** 展开膨胀,验证已理解和已构造操作均未增加。\n\n\n **L630** 陈述任意两个布尔世界主张的次序无关性。\n\n\n **L631** 任意成员属于该单主张并集,当且仅当属于次序颠倒的并集。\n\n\n **L632** 应用一般呈现顺序定理。\n\n\n **L634** 定义关于开关的清楚陈述但可能为假的论证。\n\n\n **L635** 其概念、唯一开状态假设、开状态理由及无限制范围均明确。\n\n\n **L637** 证明陈述清楚不使该论证在实际关状态世界中为真。\n\n\n **L638** 其字段可识别,但 false 世界不满足其假设。\n\n\n **L639** 检查陈述非空,并复用具体假假设结果。\n\n\n **L641** 定义测试恒返 true、并不揭示选择的记录。\n\n\n **L643** 证明有理由的价值承诺不必由中性记录事实推出。\n\n\n **L644** switch 价值任务具有自身已履行的理由及责任。\n\n\n **L645** 相反选择 false 与中性记录相容。\n\n\n **L646** 因此这些记录不建立对 switch 承诺的采用。\n\n\n **L647** 空事实理论也不蕴含这种采用。\n\n\n **L648** 构造中性记录的实际 false 选择反世界。\n\n\n **L649** 单一恒真测试经求值与记录结果相符。\n\n\n **L650** 复用价值履行及无需自证结果,留下观察支持失败。\n\n\n **L651** 假定中性记录支持该采用主张。\n\n\n **L652** 把它应用于相容的相反选择世界。\n\n\n **L653** 所断言真选择与实际假选择矛盾。\n\n\n **L655** 保留 identity 实现的行为及成本,只把解释改为 successor。\n\n\n **L657** 证明内部解释忠实性区分其他方面可行且输出相同的实现。\n\n\n **L658** 两个实现在每个输入返回相同实际输出。\n\n\n **L659** 两者满足相同输出及预算可行性要求。\n\n\n **L660** identity 实现的解释是相关且忠实的理由。\n\n\n **L661** 更改后的解释不满足同一相关性与内容检查。\n\n\n **L662** 给出相同输出、两项可行性证明及有效解释理由。\n\n\n **L663** 假定更改后的解释是相关忠实理由。\n\n\n **L664** 把其要求的解释与输出相等特化到输入零。\n\n\n **L665** successor 的输出一与 identity 的输出零矛盾。\n\n\n **L667** 对所有清单类别量化复制示例。\n\n\n **L668** 两个 copy 条目的复制仍提供 copy 操作。\n\n\n **L669** 它们并不提供不同的 successor 操作。\n\n\n **L670** 固定任意文档、术语、工具或产物类别。\n\n\n **L671** 展开实际条目成员关系,检查操作内容。\n\n\n **L674** 定义适用于每个自然数目标的评估规则。\n\n\n **L675** 赋予其键 (0,1)、普遍适用性,以及作为输入的目标自身。\n\n\n **L676** 其结果必须等于 ownArithmeticPrinciple 在该输入的实际求值。\n\n\n **L677** 为这一故意豁免自身的规则定义实际工作关系。\n\n\n **L678** 工作只对目标一存在,键与输入匹配,结果为算术求值。\n\n\n **L680** 证明开放可修订及对另一目标的真实工作并不满足自身应用。\n\n\n **L681** 策略重视扩展,并保持原则形式可修订。\n\n\n **L682** 对目标一的实际评估返回 true。\n\n\n **L683** 但同一规则也适用于自身目标零。\n\n\n **L684** 它因适用自身目标未获得工作而不满足反身性。\n\n\n **L685** 给出实际策略、可修订性及另一目标工作,留下自身责任失败。\n\n\n **L686** 假定这一豁免自身的关系满足反身性。\n\n\n **L687** 取得它在适用自身目标零处假定执行的结果。\n\n\n **L688** Performed 要求目标零等于一,产生矛盾。\n\n\n **L690** 证明系统当前哲学方法没有仅凭地位获得优先的特权。\n\n\n **L691** 在实际提案审查要求下陈述仅地位理由的拒绝。\n\n\n **L692** 此仅凭地位的负例分支使用精确相同的当前哲学实现。\n\n\n **L693** 被拒绝的理由列表只有既有地位。\n\n\n **L694** 陈述相同提案审查要求下与之对照的有根据选择。\n\n\n **L695** 正例使用精确相同的当前哲学实现。\n\n\n **L696** 其实际输出表现提供正例理由。\n\n\n **L697** 复用实际当前方法已检查的仅地位理由拒绝。\n\n\n **L698** 复用其独立检查的基于输出理由的支持。\n\n\n **L700** 在两个布尔坐标上定义一个共同上下文。\n\n\n **L701** 不用附加假设;问题是在无限制范围中第二坐标是否为真。\n\n\n **L703** 从共同持有前提推出问题的两个符号,并证明不一致。\n\n\n **L704** 共同理论蕴含肯定的第二坐标问题。\n\n\n **L705** 它还在相同上下文蕴含同一问题的否定。\n\n\n **L706** 因此它违反已定义的一致性条件。\n\n\n **L707** 先从实际组合前提推导肯定后果。\n\n\n **L708** 为整套共同理论取任意可接受世界。\n\n\n **L709** 从同一持有集合提取 P→Q 和 P,并把前者应用于后者。\n\n\n **L710** 再从同一理论推导否定后果。\n\n\n **L711** 使用同一整套理论可接受性条件。\n\n\n **L712** 经其精确嵌套并集成员关系读取持有前提 ¬Q。\n\n\n **L713** 组合两个符号并应用一般矛盾判据;不使用爆炸规则。\n\n\n **L715** 为同时存在的价值张力定义数值预算上下文。\n\n\n **L716** 问题是 n≤6,无附加假设且范围无限制。\n\n\n **L718** 证明两个不同预算要求共同一致。\n\n\n **L719** 整个持有集合同时要求 4≤n 及 n≤6。\n\n\n **L720** 通过明确可接受分配建立一致性。\n\n\n **L721** 选择五,满足并集中的第一个预算要求。\n\n\n **L722** 还满足第二要求、空假设及无限制范围。\n\n\n **L724** 证明不使用观察方法的定性推论。\n\n\n **L725** 在明确前提 on=true 下推出 on≠false。\n\n\n **L726** 该实际推论方面表明它不使用观察。\n\n\n **L727** 给出 true 世界前提模型,留下所需推论。\n\n\n **L728** 取满足前提的布尔值,并假定它等于 false。\n\n\n **L729** 从单前提理论读取它与 true 相等。\n\n\n **L730** 这两个等式会把 true 等同于 false。\n\n\n **L733** 对每种所表示地位类别量化仅凭地位的拒绝。\n\n\n **L734** 名称、惯例或既有地位单独都不能支持选择 identity 实现。\n\n\n **L735** 把辅助全类别地位定理应用于这些精确要求及实现。\n\n\n **L737** 注释说明两个有限可能抽取结果都赋有正的相等权重。\n\n\n **L738** 模型涉及可能变化的结果及稳定界限。\n\n\n **L739** 它不对物理随机源作经验断言。\n\n\n **L740** 给每个布尔抽取值赋予权重一。\n\n\n **L741** 为每个抽取值定义实际结果及记录结果。\n\n\n **L742** 两种抽取均使用设置零;true 得一、false 得二,且记录准确。\n\n\n **L744** 证明有限抽取变化时不失去条件复现性或共同界限。\n\n\n **L745** 两个可能抽取的权重均为正。\n\n\n **L746** 两种权重相等。\n\n\n **L747** 两个试验复现相同设置。\n\n\n **L748** 其实际结果仍然不同。\n\n\n **L749** 对每个抽取,记录准确且实际结果至多为二。\n\n\n **L750** 求值验证正权重、相等、设置及不同结果,留下全称记录准确性及界限。\n\n\n **L751** 固定任意抽取值。\n\n\n **L752** 展开实际记录及界限,检查两个抽取值。\n\n\n **L755** 原评估任务在候选替代之前独立声明。\n\n\n **L756** 定义固定原全输入经验任务。\n\n\n **L757** 其唯一观察是 zeroRecord;主张为 allTrue。\n\n\n **L758** 定义另一个原局部经验任务。\n\n\n **L759** 使用相同记录时,它只断言 f0=true。\n\n\n **L761** 定义循环但数学有效的条件推论:假定 allTrue 再推出 allTrue。\n\n\n **L763** 证明该单独陈述的条件推论可满足且有效。\n\n\n **L764** 恒真函数满足其 allTrue 假设。\n\n\n **L765** 取满足该单一假设的任意函数。\n\n\n **L766** 返回前提模型中已经给定的 allTrue 事实。\n\n\n **L768** 区分新条件任务的有效履行与对原经验任务的无效替代。\n\n\n **L769** 循环方面具有其自身明确新条件任务的 Grounds。\n\n\n **L770** 它并不适宜于先前固定的全局经验任务。\n\n\n **L771** 因此它不能仅因结论相同就履行该原任务。\n\n\n **L772** 首先证明候选违反原任务适宜性。\n\n\n **L773** 为反证假定适宜性成立。\n\n\n **L774** 提取其要求的原前提理论与候选前提理论相等。\n\n\n **L775** 该等式会使 allTrue 成为观察及范围单主张理论的成员。\n\n\n **L776** 单一成员关系继而把 allTrue 本身等同于仅记录相容及范围。\n\n\n **L777** 把错误身份应用于真正匹配原记录的 localGenerator0。\n\n\n **L778** 该身份错误地给出输入一的真输出。\n\n\n **L779** 与实际假输出矛盾。\n\n\n **L780** 保留有效的独立条件任务及已证不适宜性。\n\n\n **L781** 假定候选仍履行原任务 Grounds。\n\n\n **L782** 提取其所需适宜性,与前述反例矛盾。\n\n\n **L784** 把推论前提固定为恰好原零输入记录相容性及范围。\n\n\n **L785** 定义使用这些未变原前提的候选推论。\n\n\n **L786** 只推出实际零输入观察。\n\n\n **L788** 证明这一基于观察的推论可满足且有效。\n\n\n **L789** 使用 localGenerator0 作为原记录及范围前提的模型。\n\n\n **L790** 取满足这些精确前提的任意函数。\n\n\n **L791** 提取相容性,进而得到观察到的零输入输出。\n\n\n **L793** 证明两种评估形式可履行同一未变经验任务。\n\n\n **L794** 原经验方面履行固定局部任务。\n\n\n **L795** 合法的基于观察推论履行恰好同一任务。\n\n\n **L796** 复用原经验证明,留下替代推论适配。\n\n\n **L797** 证明替代候选列表非空,并检查其唯一成员。\n\n\n **L798** 取该列表中的任意候选。\n\n\n **L799** 把它等同于基于观察的推论方面。\n\n\n **L800** 为已检查推论给出精确结论及典范陈述。\n\n\n **L801** 保留原前提、结论及原平凡不确定性支持。\n\n\n **L803** 这些记录并未观察第二坐标。\n\n\n **L804** 改用推论不能抹去原不确定性责任。\n\n\n **L805** 定义要求不确定性支持超出记录所能提供的原任务。\n\n\n **L806** 使用重复第一坐标记录及无限制范围。\n\n\n **L807** 断言第一坐标为真,同时还要求不确定性确认未观察的第二坐标为真。\n\n\n **L808** 定义一个推论候选,其自身完成条件不包含这一额外不确定性责任。\n\n\n **L809** 其前提保留原记录相容性及范围。\n\n\n **L810** 其结论只断言第一坐标。\n\n\n **L812** 证明该候选的条件推论本身有效。\n\n\n **L813** 真/假世界满足该推论的精确前提。\n\n\n **L814** 取这些前提的任意模型。\n\n\n **L815** 读取记录的第一坐标结果,建立局部结论。\n\n\n **L817** 证明这一有效推论不能绕过原不确定性责任。\n\n\n **L818** 保留有效候选自身的完成证明。\n\n\n **L819** 拒绝其对于完整原不确定性任务的适宜性。\n\n\n **L820** 拒绝该原第一坐标断言及其未变陈述的 Grounds。\n\n\n **L821** 候选仍须接受完整原不确定性任务的检查。\n\n\n **L822** 首先建立实质不适宜性。\n\n\n **L823** 假定原不确定性责任得到保留及履行。\n\n\n **L824** 把它要求的第二坐标支持应用于与记录相容的真/假世界。\n\n\n **L825** 假的第二坐标与该假定支持矛盾。\n\n\n **L826** 组合有效条件推论及其对原任务的不适宜性。\n\n\n **L827** 任何所声称 Grounds 都会提供恰好被反驳的适宜性。\n\n\n **L829** 定义关于实际上选择了哪个价值选项的经验观察。\n\n\n **L830** switch 记录支持选择事实,不确定性为平凡条件。\n\n\n **L832** 把受支持的选择事实与原价值理由任务的履行区分开。\n\n\n **L833** 经验选择方面完成评估,有理由的价值立场也独立履行其任务。\n\n\n **L834** 单独经验事实仍不能履行固定价值立场任务。\n\n\n **L835** 复用经验及价值证明,留下对替代的拒绝。\n\n\n **L836** 假定经验事实履行了该原价值任务。\n\n\n **L837** 所要求的价值任务与经验方面组合在有限适配中为 False。\n\n\n **L839** 证明改变原推论假设也使任务替代无效。\n\n\n **L840** 从 on=true 推出其自身的条件推论本身有效。\n\n\n **L841** 在推论上下文被替代时拒绝原开状态主张的 Grounds。\n\n\n **L842** 候选把结论自身假定为前提。\n\n\n **L843** 固定原任务采用的则是空假设理论。\n\n\n **L844** 为有效条件推论给出 true 世界模型并返回其前提,留下替代失败。\n\n\n **L845** 假定改变前提的候选满足原任务 Grounds。\n\n\n **L846** 从单元素列表提取精确候选的适宜性。\n\n\n **L847** 它会把非空的开状态单假设理论等同于空理论。\n\n\n **L848** 传递单元素成员关系,得到空理论中的成员关系。\n\n\n **L849** 这种成员关系按定义为 False,从而完成矛盾证明。\n\n\n **L852** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。\n\n\n **L853** 开始 CoreReader.Adopted.generationCases 的来源追溯元数据;映射不是证明前提。\n\n\n **L854** 记录来源条款 organon.charter.overview#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L855** 记录来源条款 organon.charter.overview#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L856** 记录来源条款 organon.charter.self-transcendence#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L857** 记录来源条款 organon.charter.self-transcendence.orientation#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L858** 记录来源条款 organon.charter.self-transcendence.non-finality#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L859** 记录来源条款 organon.charter.self-transcendence.limits#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L860** 记录来源条款 organon.relationships.terms#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L861** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L862** 汇总已检查的生成价值取向、仅许可失败、有理由稳定及真实协作案例。\n\n\n **L863** 明确开放的策略满足 Generative。\n\n\n **L864** 另明确每类形式的版本0均可修订。\n\n\n **L865** 常值轨迹中任意相邻状态都没有新增理解或构造操作。\n\n\n **L866** 陈述neutralPolicy允许0→1且两版本不同,但缺少价值取向使Generative失败。\n\n\n **L867** 具体生成系统自身的策略满足 Generative。\n\n\n **L868** 其政策允许保持版本0,因此生成取向不要求每次行动都改变版本。\n\n\n **L869** 膨胀该系统库存不会扩展其已表示能力。\n\n\n **L870** 膨胀状态的库存条目严格多于该系统当前状态。\n\n\n **L871** 抽象层级数也严格增加,却没有能力扩展。\n\n\n **L872** 在能力内容保持不变时,词汇条目数严格增加。\n\n\n **L873** 资源为1、2、3时,该系统执行实际返回some 6。\n\n\n **L874** 从同一资源包移除经验,使该系统执行失败。\n\n\n **L875** 单独移除知识,同样使其执行返回none。\n\n\n **L876** 单独移除协作者输入,也使执行失败。\n\n\n **L877** 三种外部输入均缺失时,同一执行接口返回none。\n\n\n **L878** 系统稳定动作不产生已表示能力扩展。\n\n\n **L879** 该稳定动作恰为保持系统当前状态。\n\n\n **L880** 保持当前状态可保留工作负载必需的copy操作。\n\n\n **L881** 保留的单条状态满足该系统1条的应用预算。\n\n\n **L882** 复制后库存有2条,超过同一系统的1条预算。\n\n\n **L883** 稳定具有所述理由:构造内容未变,但只有当前状态满足预算。\n\n\n **L884** 确认该报告由此系统针对inflatedState、successor、输入0和输出1构造。\n\n\n **L885** 报告所有者等于该生成系统的所有者。\n\n\n **L886** 报告以该系统当前状态为基线,以inflatedState为结果。\n\n\n **L887** 确认声称新增操作是successor。\n\n\n **L888** 确认公告中的测试输入是0、预期输出是1。\n\n\n **L889** 陈述公告实质主张失败,且公告自身的状态对没有扩展。\n\n\n **L890** 开放策略满足所表示的生成承诺。\n\n\n **L891** 可用协作者带来新构造或新理解的操作。\n\n\n **L892** 移除同一协作者后,不再发生所表示的扩展。\n\n\n **L893** 没有经验、知识及协作者时,辅助执行不返回结果。\n\n\n **L894** 把四个实际组成证明组装为完整陈述的合取;名字本身不是证据。\n\n\n **L896** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。\n\n\n **L897** 开始 CoreReader.Adopted.generationLimits012 的来源追溯元数据;映射不是证明前提。\n\n\n **L898** 记录来源条款 organon.charter.self-transcendence.orientation#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L899** 记录来源条款 organon.charter.self-transcendence.non-finality#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L900** 记录来源条款 organon.charter.self-transcendence.limits#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L901** 记录来源条款 organon.charter.self-transcendence.limits#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L902** 记录来源条款 organon.relationships.roles#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L903** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L904** 汇总生成相关不蕴含:许可不等于价值取向,开放不等于成就,内容比数量更有判别力。\n\n\n **L905** 陈述neutralPolicy允许0→1且两版本不同,但缺少价值取向使Generative失败。\n\n\n **L906** 开放策略本身履行价值取向及可修订条件。\n\n\n **L907** 另明确每类形式的版本0均可修订。\n\n\n **L908** 常值轨迹中任意相邻状态都没有新增理解或构造操作。\n\n\n **L909** 在后续无进展示例中,该系统仍具有生成取向。\n\n\n **L910** 其政策允许保持版本0,因此生成取向不要求每次行动都改变版本。\n\n\n **L911** 膨胀该系统库存不会扩展其已表示能力。\n\n\n **L912** 膨胀状态的库存条目严格多于该系统当前状态。\n\n\n **L913** 抽象层级数也严格增加,却没有能力扩展。\n\n\n **L914** 在能力内容保持不变时,词汇条目数严格增加。\n\n\n **L915** 资源为1、2、3时,该系统执行实际返回some 6。\n\n\n **L916** 从同一资源包移除经验,使该系统执行失败。\n\n\n **L917** 单独移除知识,同样使其执行返回none。\n\n\n **L918** 单独移除协作者输入,也使执行失败。\n\n\n **L919** 三种外部输入均缺失时,同一执行接口返回none。\n\n\n **L920** 系统稳定动作不产生已表示能力扩展。\n\n\n **L921** 该稳定动作恰为保持系统当前状态。\n\n\n **L922** 保持当前状态可保留工作负载必需的copy操作。\n\n\n **L923** 保留的单条状态满足该系统1条的应用预算。\n\n\n **L924** 复制后库存有2条,超过同一系统的1条预算。\n\n\n **L925** 稳定具有所述理由:构造内容未变,但只有当前状态满足预算。\n\n\n **L926** 确认该报告由此系统针对inflatedState、successor、输入0和输出1构造。\n\n\n **L927** 报告所有者等于该生成系统的所有者。\n\n\n **L928** 报告以该系统当前状态为基线,以inflatedState为结果。\n\n\n **L929** 确认声称新增操作是successor。\n\n\n **L930** 确认公告中的测试输入是0、预期输出是1。\n\n\n **L931** 陈述公告实质主张失败,且公告自身的状态对没有扩展。\n\n\n **L932** 开放策略满足所表示的生成承诺。\n\n\n **L933** 可用协作者带来新构造或新理解的操作。\n\n\n **L934** 移除同一协作者后,不再发生所表示的扩展。\n\n\n **L935** 没有经验、知识及协作者时,辅助执行不返回结果。\n\n\n **L936** 转换的性能方面履行其声明的精确成就任务。\n\n\n **L937** 要求 extend 满足真实表现观测。\n\n\n **L938** 扩展增添能力;清单膨胀则不会。\n\n\n **L939** 因此断言积极报告记录不能在全部相容变化上支持该成就。\n\n\n **L940** 对每种所表示条目类别量化清单内容结果。\n\n\n **L941** 两个 copy 条目的复制仍提供 copy 操作。\n\n\n **L942** 它们并不提供不同的 successor 操作。\n\n\n **L943** 组合六项证明,包括实际协作进展、同转换支持及全部类别复制限制。\n\n\n **L945** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。\n\n\n **L946** 开始 CoreReader.Adopted.consistencyCases 的来源追溯元数据;映射不是证明前提。\n\n\n **L947** 记录来源条款 organon.charter.consistency#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L948** 记录来源条款 organon.charter.consistency.meaning#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L949** 记录来源条款 organon.charter.consistency.meaning#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L950** 记录来源条款 organon.charter.consistency.limits#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L951** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L952** 汇总整套集合冲突、上下文区别、真实报告、撤回及呈现顺序案例。\n\n\n **L953** 前两个结论分别为 P 与蕴含规则提供模型。\n\n\n **L954** 还要求非 Q 单独有模型,却否定整套联合理论具有模型。\n\n\n **L955** 要求在真值假设下给出肯定答案。\n\n\n **L956** 要求在假值假设下给出否定答案;两者上下文不同。\n\n\n **L957** 要求对含义为等于 true 的问题给出肯定答案。\n\n\n **L958** 当同一问题改为表示等于 false 时,要求否定答案。\n\n\n **L959** 要求在限制为 true 的范围内给出肯定答案。\n\n\n **L960** 要求在另一个限制为 false 的范围内给出否定答案。\n\n\n **L961** 对任一假设选择,要求实际可接受世界存在。\n\n\n **L962** 对任一问题含义,要求实际可接受世界存在。\n\n\n **L963** 无论选择哪种范围,结论都包含实际可接受世界。\n\n\n **L964** 实际上下文假设从 true 变为 false 时,拒绝 false 报告。\n\n\n **L965** 问题实际含义改变时,拒绝 false 报告。\n\n\n **L966** 实际应用范围改变时,拒绝 false 报告。\n\n\n **L967** 上下文不变但修订身份从 0 变为 1 时,拒绝 false 报告。\n\n\n **L968** 允许以 true 报告如实承认假设变化。\n\n\n **L969** 但否定这些修订后的假世界假设在实际 true 处成立。\n\n\n **L970** 要求时间切片 0 与 1 各自具有模型见证。\n\n\n **L971** 否定两者同时并集的模型,而不否定各自见证。\n\n\n **L972** 对每个当前时间片量化一致性。\n\n\n **L973** 拒绝同时保留相反的零时刻与一时刻时间片。\n\n\n **L974** 次序主张适用于任意布尔世界主张 p 与 q。\n\n\n **L975** 任意成员属于该单主张并集,当且仅当属于次序颠倒的并集。\n\n\n **L976** 共同理论蕴含肯定的第二坐标问题。\n\n\n **L977** 它还在相同上下文蕴含同一问题的否定。\n\n\n **L978** 因此它违反已定义的一致性条件。\n\n\n **L979** 组合七个已检查部分,保留共同推论冲突及分时一致性。\n\n\n **L981** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。\n\n\n **L982** 开始 CoreReader.Adopted.consistencyLimits012 的来源追溯元数据;映射不是证明前提。\n\n\n **L983** 记录来源条款 organon.charter.consistency.meaning#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L984** 记录来源条款 organon.charter.consistency.limits#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L985** 记录来源条款 organon.relationships.roles#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L986** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L987** 汇总一致性限制,包含实际上下文模型、预算张力、假假设及不蕴含。\n\n\n **L988** 要求在真值假设下给出肯定答案。\n\n\n **L989** 要求在假值假设下给出否定答案;两者上下文不同。\n\n\n **L990** 要求对含义为等于 true 的问题给出肯定答案。\n\n\n **L991** 当同一问题改为表示等于 false 时,要求否定答案。\n\n\n **L992** 要求在限制为 true 的范围内给出肯定答案。\n\n\n **L993** 要求在另一个限制为 false 的范围内给出否定答案。\n\n\n **L994** 对任一假设选择,要求实际可接受世界存在。\n\n\n **L995** 对任一问题含义,要求实际可接受世界存在。\n\n\n **L996** 无论选择哪种范围,结论都包含实际可接受世界。\n\n\n **L997** 要求存在同时满足下界 4 与上界 6 的自然数预算。\n\n\n **L998** 还断言两个界限谓词不同,即使它们可以共同满足。\n\n\n **L999** 单一开状态理论在宽上下文中一致。\n\n\n **L1000** 否定实际 false 满足唯一主张为 world=true 的理论。\n\n\n **L1001** 空持有理论在该上下文中也一致。\n\n\n **L1002** 具有见证的空理论不蕴含肯定的真世界答案。\n\n\n **L1003** 要求存在使 emptyTheory 与肯定单元素主张共同成立的模型。\n\n\n **L1004** 具有见证的空理论不蕴含肯定的真世界答案。\n\n\n **L1005** 整个持有集合同时要求 4≤n 及 n≤6。\n\n\n **L1006** 使用五个组成证明;最后一项为两个要求提供实际共享的一致分配。\n\n\n **L1008** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。\n\n\n **L1009** 开始 CoreReader.Adopted.reflexivityCases012 的来源追溯元数据;映射不是证明前提。\n\n\n **L1010** 记录来源条款 organon.charter.reflexivity#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1011** 记录来源条款 organon.charter.reflexivity.meaning#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1012** 记录来源条款 organon.charter.reflexivity.limits#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1013** 记录来源条款 organon.relationships.roles#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1014** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L1015** 汇总适用自身目标工作、Grounds 自身评估及其实际许可后果。\n\n\n **L1016** 完整登记的自身规则满足通用反身性接口。\n\n\n **L1017** 其实际完成的工作提供执行实例。\n\n\n **L1018** 形成、应用及修订阶段均有评估记录。\n\n\n **L1019** 还存在实际系统自身评估。\n\n\n **L1020** 较窄的仅应用规则也独立满足通用反身性。\n\n\n **L1021** 其实际 applicationWork 是执行工作的来源。\n\n\n **L1022** 但同一日志不含系统自身评估,因为该规则对系统自身不适用。\n\n\n **L1023** 被评估主张是落实 Grounds,任务是精确的 groundsPosition012 价值任务。\n\n\n **L1024** 采用世界在范围内,并具有实际支持限制批评。\n\n\n **L1025** 同一程序与观察记录匹配,并使全局主张失败。\n\n\n **L1026** 启用许可拒绝该任务;禁用许可接受它。\n\n\n **L1027** 价值立场的启用后果就是实际启用许可判定。\n\n\n **L1028** 其禁用后果同样是实际禁用许可判定。\n\n\n **L1029** 组合实际记录、已检查价值过程及同任务启用与禁用许可比较。\n\n\n **L1031** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。\n\n\n **L1032** 开始 CoreReader.Adopted.reflexivityLimits012 的来源追溯元数据;映射不是证明前提。\n\n\n **L1033** 记录来源条款 organon.charter.reflexivity.limits#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1034** 记录来源条款 organon.relationships.roles#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1035** 记录来源条款 organon.relationships.roles#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1036** 记录来源条款 organon.grounds#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1037** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L1038** 汇总自证、自生支持及豁免自身的开放之具体失败,并包含完整 Charter 与选定 Grounds 的分离。\n\n\n **L1039** 同一算术原则在样本1上通过,却在0上为假。\n\n\n **L1040** 因此该原则并非对所有自然数输入都返回true。\n\n\n **L1041** 计算 localGenerator 0 在 0 处为 true、在 1 处为 false。\n\n\n **L1042** 要求该生成函数匹配同一输入 0 记录。\n\n\n **L1043** 陈述全域支持失败,并纳入具体所有者、原对象与修订关系实例。\n\n\n **L1044** 将openPolicy的生成取向与空工作日志下的自有反身履责失败组合。\n\n\n **L1045** 恰好该具体系统及世界履行所有所表示 Charter 组成要求。\n\n\n **L1046** 它也为持有理论及上下文提供实际可接受世界。\n\n\n **L1047** 具体成本额度记录在该世界为真。\n\n\n **L1048** 候选能力方面具有可识别的典范陈述。\n\n\n **L1049** 该真实成本记录不能支持实际输出能力。\n\n\n **L1050** 因此相同能力在这些候选依据下不满足 Grounds。\n\n\n **L1051** 候选列表包含已标识的未受支持能力方面。\n\n\n **L1052** 其原任务保留该方面的经验主张及支持上下文。\n\n\n **L1053** 策略重视扩展,并保持原则形式可修订。\n\n\n **L1054** 对目标一的实际评估返回 true。\n\n\n **L1055** 但同一规则也适用于自身目标零。\n\n\n **L1056** 它因适用自身目标未获得工作而不满足反身性。\n\n\n **L1057** 使用五个具体组成证明,不从自我应用推断正确性。\n\n\n **L1059** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。\n\n\n **L1060** 开始 CoreReader.Adopted.groundsCases012 的来源追溯元数据;映射不是证明前提。\n\n\n **L1061** 记录来源条款 organon.grounds#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1062** 记录来源条款 organon.grounds.assessment#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1063** 记录来源条款 organon.grounds.assessment#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1064** 记录来源条款 organon.grounds.assessment#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1065** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L1066** 汇总同任务 Grounds 示例及被拒绝的循环假设替代。\n\n\n **L1067** 局部主张履行其明确声明的局部任务。\n\n\n **L1068** 全局候选仍具有清楚可识别的陈述。\n\n\n **L1069** 尽管陈述清楚,全输入任务仍不满足 Grounds。\n\n\n **L1070** 两个输出任务在相同记录下也失败。\n\n\n **L1071** 没有信息增益的论证仍具有可识别概念及理由。\n\n\n **L1072** 无信息表述的真实假设不蕴含世界为 true。\n\n\n **L1073** 循环方面具有其自身明确新条件任务的 Grounds。\n\n\n **L1074** 它并不适宜于先前固定的全局经验任务。\n\n\n **L1075** 因此它不能仅因结论相同就履行该原任务。\n\n\n **L1076** 组合范围与强度反模型、无支持的可陈述性,以及保持原任务后的替代拒绝。\n\n\n **L1078** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。\n\n\n **L1079** 开始 CoreReader.Adopted.empiricalCases012 的来源追溯元数据;映射不是证明前提。\n\n\n **L1080** 记录来源条款 organon.grounds.assessment#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1081** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L1082** 在保留原任务的前提下汇总经验相关性、范围、不确定性及替代评估案例。\n\n\n **L1083** 局部主张履行其明确声明的局部任务。\n\n\n **L1084** 全局候选仍具有清楚可识别的陈述。\n\n\n **L1085** 尽管陈述清楚,全输入任务仍不满足 Grounds。\n\n\n **L1086** 两个输出任务在相同记录下也失败。\n\n\n **L1087** 即使独立输出坐标为 false,真实温度测试仍返回 true。\n\n\n **L1088** 在重复温度观测下保留该假输出世界。\n\n\n **L1089** 在相同重复观测下也保留真输出世界。\n\n\n **L1090** 单条温度记录不支持另一输出为 true。\n\n\n **L1091** 重复该温度记录仍不支持另一输出为 true。\n\n\n **L1092** 重复观测到启动与已开启、预算为 0 相容。\n\n\n **L1093** 相同重复记录也与预算为 3 相容。\n\n\n **L1094** 单条启动记录不支持该选项的真实目标与预算后果。\n\n\n **L1095** 重复启动记录不能修复这一后果支持缺失。\n\n\n **L1096** 基于公告的价值程序也未满足同一实际选项与约束。\n\n\n **L1097** 经验任务使用相同的重复温度记录。\n\n\n **L1098** 主张只固定第一坐标;不确定性明确允许第二坐标变化。\n\n\n **L1099** 真/真世界与重复记录相符。\n\n\n **L1100** 真/假世界同样与它们相符。\n\n\n **L1101** 原经验方面履行固定局部任务。\n\n\n **L1102** 合法的基于观察推论履行恰好同一任务。\n\n\n **L1103** 保留有效候选自身的完成证明。\n\n\n **L1104** 拒绝其对于完整原不确定性任务的适宜性。\n\n\n **L1105** 拒绝该原第一坐标断言及其未变陈述的 Grounds。\n\n\n **L1106** 候选仍须接受完整原不确定性任务的检查。\n\n\n **L1107** 使用五个组成证明,包括合法经验转推论评估及被拒绝的不确定性绕过。\n\n\n **L1109** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。\n\n\n **L1110** 开始 CoreReader.Adopted.inferentialCases012 的来源追溯元数据;映射不是证明前提。\n\n\n **L1111** 记录来源条款 organon.grounds.assessment#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1112** 记录来源条款 organon.relationships.roles#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1113** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L1114** 汇总有效推论、相容但不蕴含的结论及被拒绝的原前提变更。\n\n\n **L1115** 从陈述的假设 n=2,限定推论建立 n+1=3。\n\n\n **L1116** 空布尔理论对于开状态主张准确地得到否定报告。\n\n\n **L1117** false 世界满足相同空前提,却使结论为假。\n\n\n **L1118** 要求存在使 emptyTheory 与肯定单元素主张共同成立的模型。\n\n\n **L1119** 具有见证的空理论不蕴含肯定的真世界答案。\n\n\n **L1120** 纳入推论方面,其可满足的真世界前提蕴含同一真世界主张。\n\n\n **L1121** 在推论上下文被替代时拒绝原开状态主张的 Grounds。\n\n\n **L1122** 候选把结论自身假定为前提。\n\n\n **L1123** 固定原任务采用的则是空假设理论。\n\n\n **L1124** 组合算术及否定报告证明、实际反赋值及原上下文替代拒绝。\n\n\n **L1126** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。\n\n\n **L1127** 开始 CoreReader.Adopted.valueCases012 的来源追溯元数据;映射不是证明前提。\n\n\n **L1128** 记录来源条款 organon.grounds.assessment#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1129** 记录来源条款 organon.grounds.assessment#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1130** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L1131** 汇总有理由价值采用、不足的自我宣布、实际批评、初始承诺及事实与价值的区别。\n\n\n **L1132** switch 价值任务具有自身已履行的理由及责任。\n\n\n **L1133** 要求公告理由非空,并在已开启且预算 0 处实际采纳。\n\n\n **L1134** 在同一零预算世界,全部真实公告理由成立。\n\n\n **L1135** 仍否定真实后果及整个价值程序。\n\n\n **L1136** 关闭所有批评回应使 closedPosition012 不满足价值过程。\n\n\n **L1137** 原 switch 立场确实满足所表示价值过程。\n\n\n **L1138** 其明确采用的起始假设具有实际模型。\n\n\n **L1139** 否定从空布尔理论推导其采纳承诺。\n\n\n **L1140** 相反立场具有共同见证,却未通过后果评估。\n\n\n **L1141** 分别否定矛盾起点假设与不可能实际采纳的程序。\n\n\n **L1142** 经验选择方面完成评估,有理由的价值立场也独立履行其任务。\n\n\n **L1143** 单独经验事实仍不能履行固定价值立场任务。\n\n\n **L1144** 组装五个价值证明,保留假设、限制及实际负例。\n\n\n **L1146** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。\n\n\n **L1147** 开始 CoreReader.Adopted.groundsLimits012 的来源追溯元数据;映射不是证明前提。\n\n\n **L1148** 记录来源条款 organon.grounds.assessment#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1149** 记录来源条款 organon.grounds.assessment#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1150** 记录来源条款 organon.grounds.assessment#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1151** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L1152** 汇总清楚理由、重复无关事实、自证要求及数值通约性的限制。\n\n\n **L1153** 其字段可识别,但 false 世界不满足其假设。\n\n\n **L1154** 即使独立输出坐标为 false,真实温度测试仍返回 true。\n\n\n **L1155** 在重复温度观测下保留该假输出世界。\n\n\n **L1156** 在相同重复观测下也保留真输出世界。\n\n\n **L1157** 单条温度记录不支持另一输出为 true。\n\n\n **L1158** 重复该温度记录仍不支持另一输出为 true。\n\n\n **L1159** 重复观测到启动与已开启、预算为 0 相容。\n\n\n **L1160** 相同重复记录也与预算为 3 相容。\n\n\n **L1161** 单条启动记录不支持该选项的真实目标与预算后果。\n\n\n **L1162** 重复启动记录不能修复这一后果支持缺失。\n\n\n **L1163** 基于公告的价值程序也未满足同一实际选项与约束。\n\n\n **L1164** switch 价值任务具有自身已履行的理由及责任。\n\n\n **L1165** 相反选择 false 与中性记录相容。\n\n\n **L1166** 因此这些记录不建立对 switch 承诺的采用。\n\n\n **L1167** 否定从空布尔理论推导其采纳承诺。\n\n\n **L1168** 有限 switch 价值过程在其陈述解释下得到履行。\n\n\n **L1169** 采用的起始理论可满足,但不声称它由空事实推出。\n\n\n **L1170** 否定从空布尔理论推导其采纳承诺。\n\n\n **L1171** 相反立场具有共同见证,却未通过后果评估。\n\n\n **L1172** 分别否定矛盾起点假设与不可能实际采纳的程序。\n\n\n **L1173** 每个输入都为真蕴含输入零为真。\n\n\n **L1174** 输入零为真不蕴含每个输入都为真。\n\n\n **L1175** switch 价值任务具有自身已履行的理由及责任。\n\n\n **L1176** 组合具体假理由及错误对象反例,以及价值和定性强度结果。\n\n\n **L1178** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。\n\n\n **L1179** 开始 CoreReader.Adopted.scopeCases012 的来源追溯元数据;映射不是证明前提。\n\n\n **L1180** 记录来源条款 organon.grounds.scope#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1181** 记录来源条款 organon.grounds.scope#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1182** 记录来源条款 organon.grounds.scope#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1183** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L1184** 汇总已履行局部范围说明及实际被遗漏差异。\n\n\n **L1185** 已定义局部说明满足所有所表示比较及方法用途责任。\n\n\n **L1186** 只对满足 n=0 的输入陈述两个函数相等。\n\n\n **L1187** 陈述它们在输入 1 处真实输出不等。\n\n\n **L1188** 使用实际范围说明证明及输入一差异见证。\n\n\n **L1190** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。\n\n\n **L1191** 开始 CoreReader.Adopted.scopeLimits012 的来源追溯元数据;映射不是证明前提。\n\n\n **L1192** 记录来源条款 organon.grounds.scope#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1193** 记录来源条款 organon.grounds.scope#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1194** 记录来源条款 organon.grounds.scope#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1195** 记录来源条款 organon.grounds.implementations.limits#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1196** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L1197** 汇总有限局部支持、更广差异、试验区别及非观察评估。\n\n\n **L1198** 确实存在位于被观察零输入之外的自然数输入。\n\n\n **L1199** 恒真函数匹配零输入观测。\n\n\n **L1200** 要求该生成函数匹配同一输入 0 记录。\n\n\n **L1201** 第一个函数全域为真,第二个却不是。\n\n\n **L1202** 原零输入记录并不支持全输入为真。\n\n\n **L1203** 只对满足 n=0 的输入陈述两个函数相等。\n\n\n **L1204** 陈述它们在输入 1 处真实输出不等。\n\n\n **L1205** 证据列表恰好包含一次观察。\n\n\n **L1206** 该单次观察具有实际相容函数,因此支持示例非空。\n\n\n **L1207** 该单条记录支持其真实输入 0 主张。\n\n\n **L1208** 其有限支持仍不能建立 allTrue。\n\n\n **L1209** 定义试验 a:设置零,实际结果一且记录准确。\n\n\n **L1210** 定义相同设置下的试验 b:实际结果二且记录准确。\n\n\n **L1211** 要求两个明确固定试次的设置相同、真实结果不同,且都满足 actualOutcome ≤ 2。\n\n\n **L1212** 要求两个记录准确但设置不同的试次。\n\n\n **L1213** 要求设置复现,同时第二记录不准确且实际结果超出界限。\n\n\n **L1214** 要求界限保持,即使其中一个结果记录不准确。\n\n\n **L1215** 算术方面完成评估,尽管其方法不使用观察。\n\n\n **L1216** 在明确前提 on=true 下推出 on≠false。\n\n\n **L1217** 该实际推论方面表明它不使用观察。\n\n\n **L1218** 两个可能抽取的权重均为正。\n\n\n **L1219** 两种权重相等。\n\n\n **L1220** 两个试验复现相同设置。\n\n\n **L1221** 其实际结果仍然不同。\n\n\n **L1222** 对每个抽取,记录准确且实际结果至多为二。\n\n\n **L1223** 组合八项证明;不把有限带权抽取和逻辑判定宣称为经验普遍保证。\n\n\n **L1225** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。\n\n\n **L1226** 开始 CoreReader.Adopted.capabilityCases012 的来源追溯元数据;映射不是证明前提。\n\n\n **L1227** 记录来源条款 organon.grounds.capabilities#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1228** 记录来源条款 organon.grounds.capabilities#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1229** 记录来源条款 organon.relationships.roles#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1230** 记录来源条款 organon.relationships.roles#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1231** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L1232** 汇总精确对象的输出及解释契约,并对所有者自身主张保留相同责任。\n\n\n **L1233** 仅输出过程具有其输出契约的 Grounds。\n\n\n **L1234** 有解释的过程具有更强输出加解释契约的 Grounds。\n\n\n **L1235** 要求存在以 outputOnlyProcess 为索引的真实外部证书。\n\n\n **L1236** 要求两者不同,且同一过程真实输出正确。\n\n\n **L1237** 仍否定该实际过程具有内部解释契约。\n\n\n **L1238** 保留现有自身能力情形,并合取新增的理解情形。\n\n\n **L1239** 两个应用对象包含完全相同的原始过程,因此其输出和解释相同。\n\n\n **L1240** 变式回答错误的对象仍满足原始输出与解释契约。\n\n\n **L1241** 该对象未能满足较强的应用理解任务。\n\n\n **L1242** 机制回答对象满足该较强任务。\n\n\n **L1243** 断言精确的较强理解主张具有使用规范表述的 Grounds。\n\n\n **L1244** 正例方面和固定的原始任务都指向机制回答对象。\n\n\n **L1245** 在反例对象的情形中否定同一较强理解主张的 Grounds。\n\n\n **L1246** 反例评估保留该对象自身固定的任务及身份范围,并结束新增理解情形的陈述。\n\n\n **L1247** 由保留的能力、自身能力证明和新增理解情形证明构造汇总结果。\n\n\n **L1249** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。\n\n\n **L1250** 开始 CoreReader.Adopted.capabilityLimits012 的来源追溯元数据;映射不是证明前提。\n\n\n **L1251** 记录来源条款 organon.grounds.capabilities#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1252** 记录来源条款 organon.grounds.capabilities#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1253** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L1254** 汇总没有解释的可靠输出,以及更强能力主张的清单与资源限制。\n\n\n **L1255** 仅输出过程具有其输出契约的 Grounds。\n\n\n **L1256** 有解释的过程具有更强输出加解释契约的 Grounds。\n\n\n **L1257** 要求存在以 outputOnlyProcess 为索引的真实外部证书。\n\n\n **L1258** 要求两者不同,且同一过程真实输出正确。\n\n\n **L1259** 仍否定该实际过程具有内部解释契约。\n\n\n **L1260** 复制主张适用于每种所表示清单类型。\n\n\n **L1261** 两个 copy 条目的复制仍提供 copy 操作。\n\n\n **L1262** 它们并不提供不同的 successor 操作。\n\n\n **L1263** 相同具体生成系统具有生成策略。\n\n\n **L1264** 其政策允许保持版本0,因此生成取向不要求每次行动都改变版本。\n\n\n **L1265** 膨胀该系统库存不会扩展其已表示能力。\n\n\n **L1266** 膨胀状态的库存条目严格多于该系统当前状态。\n\n\n **L1267** 抽象层级数也严格增加,却没有能力扩展。\n\n\n **L1268** 在能力内容保持不变时,词汇条目数严格增加。\n\n\n **L1269** 资源为1、2、3时,该系统执行实际返回some 6。\n\n\n **L1270** 从同一资源包移除经验,使该系统执行失败。\n\n\n **L1271** 单独移除知识,同样使其执行返回none。\n\n\n **L1272** 单独移除协作者输入,也使执行失败。\n\n\n **L1273** 三种外部输入均缺失时,同一执行接口返回none。\n\n\n **L1274** 系统稳定动作不产生已表示能力扩展。\n\n\n **L1275** 该稳定动作恰为保持系统当前状态。\n\n\n **L1276** 保持当前状态可保留工作负载必需的copy操作。\n\n\n **L1277** 保留的单条状态满足该系统1条的应用预算。\n\n\n **L1278** 复制后库存有2条,超过同一系统的1条预算。\n\n\n **L1279** 稳定具有所述理由:构造内容未变,但只有当前状态满足预算。\n\n\n **L1280** 确认该报告由此系统针对inflatedState、successor、输入0和输出1构造。\n\n\n **L1281** 报告所有者等于该生成系统的所有者。\n\n\n **L1282** 报告以该系统当前状态为基线,以inflatedState为结果。\n\n\n **L1283** 确认声称新增操作是successor。\n\n\n **L1284** 确认公告中的测试输入是0、预期输出是1。\n\n\n **L1285** 陈述公告实质主张失败,且公告自身的状态对没有扩展。\n\n\n **L1286** 组合限定能力证明、全类别内容检查及实际生成与资源限制。\n\n\n **L1288** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。\n\n\n **L1289** 开始 CoreReader.Adopted.choiceCases012 的来源追溯元数据;映射不是证明前提。\n\n\n **L1290** 记录来源条款 organon.grounds.implementations#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1291** 记录来源条款 organon.grounds.implementations#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1292** 记录来源条款 organon.grounds.implementations.limits#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1293** 记录来源条款 organon.relationships.roles#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1294** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L1295** 汇总有依据惯常选择、内部方法理由及仅地位理由拒绝,并包含当前哲学。\n\n\n **L1296** 保留恒等实现两个真实地位事实均为 true。\n\n\n **L1297** 主张使用惯常与真实输出理由组成的列表可获得有理由选择;相关性来自输出理由。\n\n\n **L1298** 要求同一真实恒等实现具有忠实解释理由。\n\n\n **L1299** 要求其真实适用性覆盖必需输入。\n\n\n **L1300** 要求其真实成本满足所重视的简单性与预算条件。\n\n\n **L1301** 要求其真实轨迹内容满足所重视的过程条件。\n\n\n **L1302** 要求 cheapSuccessor 的成本理由在所选要求下真实相关。\n\n\n **L1303** 仍否定它仅凭该理由获得有理由选择,因为可行性还包括输出正确。\n\n\n **L1304** 要求同一地位优先权评估具有程序表述与正确否定报告。\n\n\n **L1305** 保留所有候选解释为相同真实地位事实的模型。\n\n\n **L1306** 优先权谓词在 identity 处成立,在 successor 处失败。\n\n\n **L1307** 真实名称、惯例及地位事实不蕴含该特定优先主张。\n\n\n **L1308** 还拒绝只以既有地位作为真实理由选择恒等实现。\n\n\n **L1309** 两个实现在每个输入返回相同实际输出。\n\n\n **L1310** 两者满足相同输出及预算可行性要求。\n\n\n **L1311** 要求同一真实恒等实现具有忠实解释理由。\n\n\n **L1312** 更改后的解释不满足同一相关性与内容检查。\n\n\n **L1313** 在实际提案审查要求下陈述仅地位理由的拒绝。\n\n\n **L1314** 此仅凭地位的负例分支使用精确相同的当前哲学实现。\n\n\n **L1315** 被拒绝的理由列表只有既有地位。\n\n\n **L1316** 陈述相同提案审查要求下与之对照的有根据选择。\n\n\n **L1317** 正例使用精确相同的当前哲学实现。\n\n\n **L1318** 其实际输出表现提供正例理由。\n\n\n **L1319** 对名称、惯常使用及既有地位量化仅凭地位的不足。\n\n\n **L1320** 名称、惯例或既有地位单独都不能支持选择 identity 实现。\n\n\n **L1321** 组合六项选择证明,保留实际内容比较并拒绝当前哲学的特权。\n\n\n **L1323** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。\n\n\n **L1324** 开始 CoreReader.Adopted.choiceLimits012 的来源追溯元数据;映射不是证明前提。\n\n\n **L1325** 记录来源条款 organon.grounds.implementations#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1326** 记录来源条款 organon.grounds.implementations#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1327** 记录来源条款 organon.grounds.implementations.limits#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。\n\n\n **L1328** 结束前面的来源映射注释,不添加逻辑条件。\n\n\n **L1329** 汇总开放性限制:唯一可行惯常选项、不同内部理由、更广差异及有限评估策略独立性。\n\n\n **L1330** 在明确的双值候选类型中,要求可行性恰对应 identity。\n\n\n **L1331** 还保留恒等实现真实的输出理由选择依据。\n\n\n **L1332** 保留恒等实现两个真实地位事实均为 true。\n\n\n **L1333** 主张使用惯常与真实输出理由组成的列表可获得有理由选择;相关性来自输出理由。\n\n\n **L1334** 两个实现在每个输入返回相同实际输出。\n\n\n **L1335** 两者满足相同输出及预算可行性要求。\n\n\n **L1336** 要求同一真实恒等实现具有忠实解释理由。\n\n\n **L1337** 更改后的解释不满足同一相关性与内容检查。\n\n\n **L1338** 还保留恒等实现真实的输出理由选择依据。\n\n\n **L1339** 还要求恒等与后继实现在输入 0 产生不同真实输出。\n\n\n **L1340** 只在输入 0 范围下比较真实输出。\n\n\n **L1341** 另行要求输入 1 处真实输出不同。\n\n\n **L1342** 要求同一地位优先权评估具有程序表述与正确否定报告。\n\n\n **L1343** 保留所有候选解释为相同真实地位事实的模型。\n\n\n **L1344** 优先权谓词在 identity 处成立,在 successor 处失败。\n\n\n **L1345** 仅地位前提仍不蕴含优先主张。\n\n\n **L1346** 还拒绝只以既有地位作为真实理由选择恒等实现。\n\n\n **L1347** 两个策略共享同一准确评估,但实际优先理由不同;这不是对完整 Grounds 的独立性。\n\n\n **L1348** 使用六个已检查部分;generalGroundsNotChoice 只证明已披露的一般评估与选择策略分离。\n\n\n **L1350** 结束 CoreReader.Adopted;后续声明不再位于此命名空间。\n\n\n### `leanified/CoreReader/Agency.lean`\n\n\n```lean\nimport CoreReader.Reflexivity\n\nnamespace CoreReader.Agency\n\ninductive FormKind | organization | method | principle | appearance | artifact\n deriving DecidableEq, Repr\n\nstructure Form where\n kind : FormKind\n version : Nat\n deriving DecidableEq, Repr\n\ninductive Aim | expandUnderstandingAndConstruction | preserveSafeOperation\n deriving DecidableEq, Repr\n\n/- A policy records an adopted valuation, current forms, and permission. It does not assert that valuation is correct or enacted. -/\nstructure Policy where\n worthPursuing : Aim → Prop\n current : Form → Prop\n revisable : Form → Prop\n permitsVersion : Nat → Nat → Prop\n\n/- The normative specification keeps valuation and revisability separate from realized transitions. -/\ndef Generative (p : Policy) : Prop :=\n p.worthPursuing .expandUnderstandingAndConstruction ∧\n ∀ f, p.current f → p.revisable f\n\ndef openPolicy : Policy where\n worthPursuing a := a = .expandUnderstandingAndConstruction ∨ a = .preserveSafeOperation\n current f := f.version = 0\n revisable _ := True\n permitsVersion _ _ := True\n\ndef neutralPolicy : Policy := { openPolicy with worthPursuing := fun _ => False }\n\n/- Permitting a real version change does not supply an adopted value position. -/\ntheorem permissionNotValuation :\n neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy := by\n simp [neutralPolicy, openPolicy, Generative]\n\n/- This is an explicit consequence of the adopted specification, not evidence of actual revision. -/\ntheorem revisabilityCovers (p : Policy) (h : Generative p) (k : FormKind) (v : Nat)\n (hc : p.current ⟨k, v⟩) : p.revisable ⟨k, v⟩ := h.2 _ hc\n\ninductive Operation | copy | successor\n deriving DecidableEq, Repr\n\ndef Operation.run : Operation → Nat → Nat\n | .copy, n => n\n | .successor, n => n + 1\n\ninductive InventoryKind | document | term | tool | artifact\n deriving DecidableEq, Repr\n\nstructure Item where\n kind : InventoryKind\n content : Operation\n deriving DecidableEq, Repr\n\n/- Available represented operations are the contents present, not their number of occurrences. -/\ndef Available (xs : List Item) (op : Operation) : Prop :=\n ∃ item ∈ xs, item.content = op\n\n/- Duplicating any inventory category preserves exactly the represented operation content. -/\ntheorem inventoryNotCapability (kind : InventoryKind) (ops : List Operation) (op : Operation) :\n Available ((ops.map fun x => Item.mk kind x) ++ (ops.map fun x => Item.mk kind x)) op ↔\n Available (ops.map fun x => Item.mk kind x) op := by\n simp only [Available, List.mem_append]\n constructor\n · rintro ⟨x, hx | hx, hop⟩ <;> exact ⟨x, hx, hop⟩\n · rintro ⟨x, hx, hop⟩\n exact ⟨x, Or.inl hx, hop⟩\n\nstructure State where\n understood : List Operation\n constructed : List Operation\n inventory : List Item\n abstractionLayers : List Operation\n vocabulary : List Operation\n deriving DecidableEq, Repr\n\n/- A gain must identify an operation newly understood or constructed; this is a disclosed finite capability representation. -/\ndef Expanded (before after : State) : Prop :=\n (∃ op, op ∈ after.understood ∧ op ∉ before.understood) ∨\n (∃ op, op ∈ after.constructed ∧ op ∉ before.constructed)\n\ndef baseState : State :=\n ⟨[.copy], [.copy], [⟨.artifact, .copy⟩], [.copy], [.copy]⟩\n\ndef inflatedState : State :=\n { baseState with\n inventory := baseState.inventory ++ baseState.inventory\n abstractionLayers := [.copy, .copy]\n vocabulary := [.copy, .copy] }\n\ndef stableTrace (_time : Nat) : State := baseState\n\n/- A revisable policy can govern an unchanged trace; no improvement is hidden in revisability. -/\ntheorem revisionWithoutProgress :\n Generative openPolicy ∧\n (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧\n (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1))) := by\n simp [Generative, openPolicy, stableTrace, Expanded]\n\nstructure ExternalResources where\n experience : Option Nat\n knowledge : Option Nat\n collaborator : Option Nat\n deriving DecidableEq, Repr\n\n/- This interpreter actually needs all three external inputs to produce the modeled result. -/\ndef assistedExecution (r : ExternalResources) : Option Nat := do\n let e ← r.experience\n let k ← r.knowledge\n let c ← r.collaborator\n pure (Operation.copy.run (e + k + c))\n\ndef availableResources : ExternalResources := ⟨some 1, some 2, some 3⟩\n\n/- Stability has a concrete stated reason in this workload: preserve its operation while staying within the one-item budget. -/\ndef StableReason (before proposed : State) : Prop :=\n before.constructed = proposed.constructed ∧\n before.inventory.length ≤ 1 ∧ ¬ proposed.inventory.length ≤ 1\n\n/- The policy, current capabilities, execution interface and workload constraints belong to one generating system. -/\nstructure GeneratingSystem where\n owner : Nat\n policy : Policy\n current : State\n execute : ExternalResources → Option Nat\n applicationBudget : Nat\n requiredOperations : List Operation\n/- The modeled system uses the assisted interpreter under a one-item budget and a copy-operation requirement. -/\ndef generatingSystem : GeneratingSystem where\n owner := 0\n policy := openPolicy\n current := baseState\n execute := assistedExecution\n applicationBudget := 1\n requiredOperations := [.copy]\n/- A stable action retains this system's own current state. -/\ndef GeneratingSystem.stableAction (system : GeneratingSystem) : State := system.current\ndef GeneratingSystem.requirementsMet (system : GeneratingSystem) (state : State) : Prop :=\n ∀ operation, operation ∈ system.requiredOperations → operation ∈ state.constructed\ndef GeneratingSystem.withinBudget (system : GeneratingSystem) (state : State) : Prop :=\n state.inventory.length ≤ system.applicationBudget\n/- An expansion report identifies the actual before/after states and the operation/performance it asserts was added. -/\nstructure Announcement where\n owner : Nat\n before : State\n after : State\n reportedNewOperation : Operation\n input : Nat\n expectedOutput : Nat\n deriving DecidableEq, Repr\n/- Reports are generated by this system and identify its actual current state as their baseline. -/\ndef GeneratingSystem.report (system : GeneratingSystem) (after : State)\n (operation : Operation) (input expectedOutput : Nat) : Announcement :=\n ⟨system.owner, system.current, after, operation, input, expectedOutput⟩\n/- Report content is interpreted against those very states and the named operation's actual behavior. -/\ndef Announcement.claim (report : Announcement) : Prop :=\n report.reportedNewOperation ∈ report.after.constructed ∧\n report.reportedNewOperation ∉ report.before.constructed ∧\n report.reportedNewOperation.run report.input = report.expectedOutput\n/- A true report of this form entails a represented construction expansion. -/\ntheorem announcementClaimImpliesExpansion (report : Announcement) (h : report.claim) :\n Expanded report.before report.after := Or.inr ⟨report.reportedNewOperation, h.1, h.2.1⟩\n/- This concrete self-report asserts a successor operation for the actual inventory-only inflation. -/\ndef inflatedAnnouncement : Announcement := generatingSystem.report inflatedState .successor 0 1\n/- The report asserts a real successor result but its named operation is absent from its own after-state. -/\ntheorem inflatedAnnouncementRefuted :\n inflatedAnnouncement.before = baseState ∧ inflatedAnnouncement.after = inflatedState ∧\n inflatedAnnouncement.reportedNewOperation = .successor ∧\n inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧\n ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after := by\n simp [inflatedAnnouncement, GeneratingSystem.report, generatingSystem, Announcement.claim, Expanded, baseState, inflatedState]\n\n/- These transitions share one initial state; only extension adds an actual new operation. -/\ninductive TransitionCase | inflate | extend\n deriving DecidableEq, Repr\n\ndef extendedState : State :=\n { baseState with understood := [.copy, .successor], constructed := [.copy, .successor] }\ndef transitionBefore (_transition : TransitionCase) : State := baseState\ndef transitionAfter : TransitionCase → State\n | .inflate => inflatedState\n | .extend => extendedState\n/- Both alternatives are assessed under the same concrete input condition. -/\ndef transitionInput (_transition : TransitionCase) : Nat := 0\ndef transitionAnnouncement (transition : TransitionCase) : Announcement :=\n generatingSystem.report (transitionAfter transition) .successor (transitionInput transition) 1\n\n/- Eleven boundary branches share a content-bearing trace and executable dependency model. They do not assert a universal law of human capability. -/\ntheorem generationLimits :\n Generative generatingSystem.policy ∧\n generatingSystem.policy.permitsVersion 0 0 ∧\n ¬ Expanded generatingSystem.current inflatedState ∧\n generatingSystem.current.inventory.length < inflatedState.inventory.length ∧\n generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧\n generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧\n generatingSystem.execute availableResources = some 6 ∧\n generatingSystem.execute { availableResources with experience := none } = none ∧\n generatingSystem.execute { availableResources with knowledge := none } = none ∧\n generatingSystem.execute { availableResources with collaborator := none } = none ∧\n generatingSystem.execute ⟨none, none, none⟩ = none ∧\n ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧\n generatingSystem.stableAction = generatingSystem.current ∧\n generatingSystem.requirementsMet generatingSystem.stableAction ∧\n generatingSystem.withinBudget generatingSystem.stableAction ∧\n ¬ generatingSystem.withinBudget inflatedState ∧\n StableReason generatingSystem.current inflatedState ∧\n (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧\n inflatedAnnouncement.owner = generatingSystem.owner ∧\n inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧\n inflatedAnnouncement.reportedNewOperation = .successor ∧\n inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧\n ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after) := by\n simp [generatingSystem, GeneratingSystem.stableAction, GeneratingSystem.requirementsMet,\n GeneratingSystem.withinBudget, GeneratingSystem.report, Generative, openPolicy, Expanded,\n baseState, inflatedState, assistedExecution, availableResources, Operation.run,\n StableReason, inflatedAnnouncement, Announcement.claim]\n\n/- The empty work log omits an actually applicable system assessment despite an open generative policy. -/\ntheorem generationNotReflexivity :\n Generative openPolicy ∧ ¬ Reflexive 0 (ownRules 0) [] := by\n constructor\n · simp [Generative, openPolicy]\n · intro h\n have bad := noSelfExemption 0 (ownRules 0) [] h (assessingRule 0) (by simp [ownRules])\n (.system 0) rfl (by simp [assessingRule, ownSubjects])\n simp [Performed] at bad\n\n/- The same proposed arithmetic principle is used in the self-test and in the universal correctness claim. -/\ndef ownArithmeticPrinciple (n : Nat) : Bool := decide (n + 1 = 2 * n)\n\ndef selfTest (samples : List Nat) : Bool := samples.all ownArithmeticPrinciple\n\n/- A genuine evaluation on the selected sample succeeds, while the same principle fails at zero. -/\ntheorem selfTestDoesNotProve :\n selfTest [1] = true ∧ ownArithmeticPrinciple 0 = false ∧\n ¬ (∀ n, ownArithmeticPrinciple n = true) := by\n constructor\n · decide\n constructor\n · decide\n · intro h\n have bad := h 0\n contradiction\n\nend CoreReader.Agency\n```\n\n\n\n **L1** 导入CoreReader.Reflexivity及其依赖。\n\n\n **L3** 打开命名空间CoreReader.Agency;文件边界不改变声明身份。\n\n\n **L5** 定义组织、方法、原则、外观和产物五类形式标签。\n\n\n **L6** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L8** 形式由种类标签和自然数版本构成,不包含内容或转换规则。\n\n\n **L9** 保存该形式属于组织、方法、原则、外观还是产物。\n\n\n **L10** 保存自然数形式版本,不证明变化已经发生。\n\n\n **L11** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L13** 定义扩展理解与构造、保持安全运行两个目标标签;数据类型自身不为任一目标赋值。\n\n\n **L14** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L16** 说明后续定义或结果:分别保存目标价值、当前形式、可修订形式和版本许可四个谓词。\n\n\n **L17** 分别保存目标价值、当前形式、可修订形式和版本许可四个谓词。\n\n\n **L18** 规定此政策把两个已表示目标中的哪些视为值得追求。\n\n\n **L19** 规定此政策当前持有的形式种类与版本对。\n\n\n **L20** 规定此政策保留哪些形式种类与版本对的可修订性。\n\n\n **L21** 独立于实际执行规定版本间许可。\n\n\n **L23** 说明后续定义或结果:要求视扩展为值得追求,且全部当前形式可修订;不承诺执行或进步。\n\n\n **L24** 要求视扩展为值得追求,且全部当前形式可修订;不承诺执行或进步。\n\n\n **L25** 要求该政策把理解与构造的扩展视为值得追求。\n\n\n **L26** 要求该政策当前持有的每个形式仍可修订。\n\n\n **L28** 重视两个目标,以版本零为当前形式,并允许所有修订和版本对。\n\n\n **L29** openPolicy同时重视扩展与保持安全运行。\n\n\n **L30** 把版本恰为0的形式视为当前形式,不限种类。\n\n\n **L31** 允许修订所有形式,包括当前未持有的形式。\n\n\n **L32** 允许任意两个版本号间的变更,但不执行变更。\n\n\n **L34** 保留开放政策许可,但把所有目标价值设为假。\n\n\n **L36** 说明后续定义或结果:实际允许不同版本零到一,同时缺少扩展价值取向,证明许可不充分。\n\n\n **L37** 实际允许不同版本零到一,同时缺少扩展价值取向,证明许可不充分。\n\n\n **L38** 陈述neutralPolicy允许0→1且两版本不同,但缺少价值取向使Generative失败。\n\n\n **L39** 展开两个政策:许可为真,0≠1可计算为真,所需价值取向为假。\n\n\n **L41** 说明后续定义或结果:将已假定的生成规范实例化到指定当前种类与版本,不执行修订。\n\n\n **L42** 将已假定的生成规范实例化到指定当前种类与版本,不执行修订。\n\n\n **L43** 将h中的可修订条款应用于hc确认是当前形式的同一种类与版本。\n\n\n **L45** 只定义自然数恒等和后继两种操作。\n\n\n **L46** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L48** 按构造器计算恒等或加一输出。\n\n\n **L49** 执行copy直接返回原输入。\n\n\n **L50** 执行successor返回输入加1。\n\n\n **L52** 定义文档、术语、工具、产物四个库存标签。\n\n\n **L53** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L55** 库存项保存种类标签及两种操作之一。\n\n\n **L56** 把库存条目分类为文档、术语、工具或产物。\n\n\n **L57** 记录条目表示的操作,与其类别分开。\n\n\n **L58** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L60** 说明后续定义或结果:存在库存成员携带指定操作即为可用;重复次数不影响此条件。\n\n\n **L61** 存在库存成员携带指定操作即为可用;重复次数不影响此条件。\n\n\n **L62** 只有存在包含该操作的列表条目,该操作才可用。\n\n\n **L64** 说明后续定义或结果:通过双向复用同一成员见证,证明复制任一种类库存不会新增可用操作。\n\n\n **L65** 通过双向复用同一成员见证,证明复制任一种类库存不会新增可用操作。\n\n\n **L66** 检查把ops按固定类别包装并复制列表后的操作可用性。\n\n\n **L67** 将其与同一列表未复制时的可用性比较。\n\n\n **L68** 展开可用性,把复制列表成员关系化为属于任一副本。\n\n\n **L69** 分别证明复制既不增加也不减少已表示的操作。\n\n\n **L70** 任一副本中的条目都可作为原列表中同一操作的见证。\n\n\n **L71** 反向证明取原条目x、成员证明hx及内容匹配证明hop。\n\n\n **L72** 把同一条目放在第一副本中,保持操作匹配。\n\n\n **L74** 用五个列表分别表示理解、构造、库存、抽象层级和词汇。\n\n\n **L75** 列出该状态中表示为已理解的操作。\n\n\n **L76** 列出该状态中表示为已构造的操作。\n\n\n **L77** 保存库存条目;条目重复数量与能力成员关系不同。\n\n\n **L78** 保存抽象层级条目,不把数量等同理解能力。\n\n\n **L79** 保存词汇条目,不把数量等同构造能力。\n\n\n **L80** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L82** 说明后续定义或结果:理解或构造列表新增至少一个先前没有的操作;不要求其他能力都保留。\n\n\n **L83** 理解或构造列表新增至少一个先前没有的操作;不要求其他能力都保留。\n\n\n **L84** 扩展可由变化后已理解、变化前未理解的操作见证。\n\n\n **L85** 另一种扩展见证是新增的已构造操作。\n\n\n **L87** 构造只含copy操作、一个copy产物的初始状态。\n\n\n **L88** 基线理解并构造copy,且各有一个copy产物、层级和词汇条目。\n\n\n **L90** 只复制库存、层级和词汇,理解与构造列表保持原样。\n\n\n **L91** 以baseState为起点,保留下面未覆盖的字段。\n\n\n **L92** 复制单条库存,但保持已理解和已构造操作不变。\n\n\n **L93** 将一个抽象层级条目改为两个copy条目。\n\n\n **L94** 同样把词汇列表加倍,不引入新操作。\n\n\n **L96** 每个时刻都返回同一初始状态。\n\n\n **L98** 说明后续定义或结果:生成规范和全面可修订性与常值、无扩展轨迹相容。\n\n\n **L99** 生成规范和全面可修订性与常值、无扩展轨迹相容。\n\n\n **L100** 陈述openPolicy满足所采纳的价值取向与可修订规范。\n\n\n **L101** 另明确每类形式的版本0均可修订。\n\n\n **L102** 常值轨迹中任意相邻状态都没有新增理解或构造操作。\n\n\n **L103** 把政策条款化为真,把每项扩展化为未变列表中不可能的新增成员。\n\n\n **L105** 保存经验、知识和协作者三个可缺失自然数槽。\n\n\n **L106** 可选外部经验值;none会使辅助执行在首次读取时失败。\n\n\n **L107** 继经验输入后必须取得的可选知识值。\n\n\n **L108** 产生结果前必须取得的可选协作者值。\n\n\n **L109** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L111** 说明后续定义或结果:依次读取三个Option槽;全部存在时返回总和,任一缺失时返回none。\n\n\n **L112** 依次读取三个Option槽;全部存在时返回总和,任一缺失时返回none。\n\n\n **L113** 将经验读入e,若资源缺失则立即返回none。\n\n\n **L114** 将知识读入k,缺失则终止同一个Option计算。\n\n\n **L115** 将协作者值读入c,同样传递缺失结果。\n\n\n **L116** 通过copy操作返回e+k+c之和,并包装为some。\n\n\n **L118** 提供一、二、三三个实际资源值。\n\n\n **L120** 说明后续定义或结果:要求构造列表相同、原库存至多一项而拟议库存超限。\n\n\n **L121** 要求构造列表相同、原库存至多一项而拟议库存超限。\n\n\n **L122** 保留旧状态的理由之一是两状态具有完全相同的已构造操作。\n\n\n **L123** 旧库存必须满足单条限制,而拟议库存超过该限制。\n\n\n **L125** 说明后续定义或结果:把同一主体的政策、当前状态、资源执行函数、预算和所需操作绑定成系统。\n\n\n **L126** 把同一主体的政策、当前状态、资源执行函数、预算和所需操作绑定成系统。\n\n\n **L127** 标识该生成系统的所有者。\n\n\n **L128** 把价值取向与可修订政策附于同一系统。\n\n\n **L129** 保存系统当前的能力与库存表示状态。\n\n\n **L130** 保存该系统实际消耗资源的执行函数。\n\n\n **L131** 规定评估稳定状态和拟议状态的库存数量预算。\n\n\n **L132** 规定工作负载要求保持已构造的操作。\n\n\n **L133** 说明后续定义或结果:主体零采用开放政策、初始状态、三资源执行、预算一和copy要求。\n\n\n **L134** 主体零采用开放政策、初始状态、三资源执行、预算一和copy要求。\n\n\n **L135** 给具体生成系统分配所有者编号0。\n\n\n **L136** 在同一具体系统中采用openPolicy。\n\n\n **L137** 将其当前能力和库存设为baseState。\n\n\n **L138** 以需要三种资源的辅助解释器作为该系统执行接口。\n\n\n **L139** 把该工作负载的库存预算定为恰好1条。\n\n\n **L140** 要求具体工作负载保留copy操作。\n\n\n **L141** 说明后续定义或结果:以该系统当前状态作为保持稳定的动作结果。\n\n\n **L142** 以该系统当前状态作为保持稳定的动作结果。\n\n\n **L143** 检查同一系统要求的每个操作都在被评状态构造列表中。\n\n\n **L144** 对该系统和待评状态,所有必需操作都必须属于状态的已构造列表。\n\n\n **L145** 按该系统明示预算检查被评状态库存长度。\n\n\n **L146** 用同一系统声明的应用预算检查该状态的库存数量。\n\n\n **L147** 说明后续定义或结果:保存报告主体、精确前后状态、声称新增操作、输入和期望输出。\n\n\n **L148** 保存报告主体、精确前后状态、声称新增操作、输入和期望输出。\n\n\n **L149** 记录该扩展公告的所有者。\n\n\n **L150** 保存公告指定的确切基线状态。\n\n\n **L151** 保存公告指定的确切结果状态。\n\n\n **L152** 指定声称新增构造的操作。\n\n\n **L153** 固定公告声称该操作表现所用的输入。\n\n\n **L154** 保存该操作在指定输入上的声称输出。\n\n\n **L155** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L156** 说明后续定义或结果:用本系统主体和当前状态构造对应拟议状态及操作合同的报告。\n\n\n **L157** 用本系统主体和当前状态构造对应拟议状态及操作合同的报告。\n\n\n **L158** 接收该报告声称新增的操作及具体输入输出对。\n\n\n **L159** 以系统所有者和当前基线构造报告,并填入给定后状态与主张数据。\n\n\n **L160** 说明后续定义或结果:要求声称操作在后状态中新出现,并在指定输入产生期望输出。\n\n\n **L161** 要求声称操作在后状态中新出现,并在指定输入产生期望输出。\n\n\n **L162** 报告所称新增操作必须实际属于公告的后状态。\n\n\n **L163** 同一操作必须不属于公告基线的已构造列表。\n\n\n **L164** 该操作在报告输入上的实际运行必须等于声称输出。\n\n\n **L165** 说明后续定义或结果:从已成立报告中抽取新构造操作,作为扩展的存在见证。\n\n\n **L166** 从已成立报告中抽取新构造操作,作为扩展的存在见证。\n\n\n **L167** 用主张中的后状态成员关系与前状态缺失关系构造Expanded的构造分支。\n\n\n **L168** 说明后续定义或结果:系统对仅库存膨胀的状态报告零输入上的新增successor。\n\n\n **L169** 系统对仅库存膨胀的状态报告零输入上的新增successor。\n\n\n **L170** 说明后续定义或结果:核实报告对象后计算其新增操作主张及实际扩展均不成立。\n\n\n **L171** 核实报告对象后计算其新增操作主张及实际扩展均不成立。\n\n\n **L172** 确认具体公告所指正是baseState与inflatedState。\n\n\n **L173** 确认声称新增操作是successor。\n\n\n **L174** 确认公告中的测试输入是0、预期输出是1。\n\n\n **L175** 陈述公告实质主张失败,且公告自身的状态对没有扩展。\n\n\n **L176** 计算报告字段和未变能力列表;即使successor的0→1表现正确,后状态仍没有该操作。\n\n\n **L178** 说明后续定义或结果:成就模型仅含库存膨胀与实际操作扩展两个候选变化。\n\n\n **L179** 成就模型仅含库存膨胀与实际操作扩展两个候选变化。\n\n\n **L180** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L182** 在初始状态的理解和构造列表中添加successor。\n\n\n **L183** 在理解与构造列表中同时加入successor,保留基线其他字段。\n\n\n **L184** 两种模型变化使用同一个初始状态基线。\n\n\n **L185** 按变化类别选择库存膨胀或能力扩展后状态。\n\n\n **L186** inflate转移以仅膨胀库存的状态结束。\n\n\n **L187** extend转移以新增理解和构造successor的状态结束。\n\n\n **L188** 说明后续定义或结果:两种变化都明确使用零作为测试输入。\n\n\n **L189** 两种变化都明确使用零作为测试输入。\n\n\n **L190** 对同一系统及指定后状态报告successor在零处输出一。\n\n\n **L191** 两种转移都在共同输入0上公告successor,但各自指定实际后状态。\n\n\n **L193** 说明后续定义或结果:在绑定系统上核实数量不增能力、外援依赖、有根据稳定动作和同对象虚假成就报告等全部分支。\n\n\n **L194** 在绑定系统上核实数量不增能力、外援依赖、有根据稳定动作和同对象虚假成就报告等全部分支。\n\n\n **L195** 具体系统仍满足所采纳的生成政策。\n\n\n **L196** 其政策允许保持版本0,因此生成取向不要求每次行动都改变版本。\n\n\n **L197** 膨胀该系统库存不会扩展其已表示能力。\n\n\n **L198** 膨胀状态的库存条目严格多于该系统当前状态。\n\n\n **L199** 抽象层级数也严格增加,却没有能力扩展。\n\n\n **L200** 在能力内容保持不变时,词汇条目数严格增加。\n\n\n **L201** 资源为1、2、3时,该系统执行实际返回some 6。\n\n\n **L202** 从同一资源包移除经验,使该系统执行失败。\n\n\n **L203** 单独移除知识,同样使其执行返回none。\n\n\n **L204** 单独移除协作者输入,也使执行失败。\n\n\n **L205** 三种外部输入均缺失时,同一执行接口返回none。\n\n\n **L206** 系统稳定动作不产生已表示能力扩展。\n\n\n **L207** 该稳定动作恰为保持系统当前状态。\n\n\n **L208** 保持当前状态可保留工作负载必需的copy操作。\n\n\n **L209** 保留的单条状态满足该系统1条的应用预算。\n\n\n **L210** 复制后库存有2条,超过同一系统的1条预算。\n\n\n **L211** 稳定具有所述理由:构造内容未变,但只有当前状态满足预算。\n\n\n **L212** 确认该报告由此系统针对inflatedState、successor、输入0和输出1构造。\n\n\n **L213** 报告所有者等于该生成系统的所有者。\n\n\n **L214** 报告以该系统当前状态为基线,以inflatedState为结果。\n\n\n **L215** 此实际报告称为新增的操作是successor。\n\n\n **L216** 报告声称的表现仍是具体的0→1。\n\n\n **L217** 尽管存在该报告,其主张仍为假,其自身前后状态也没有能力扩展。\n\n\n **L218** 展开具体系统、保持动作和必需操作检查,开始计算generationLimits各条款。\n\n\n **L219** 再展开单条预算、报告构造器和政策及扩展谓词,使主张化为具体数据。\n\n\n **L220** 用实际基线及膨胀列表和三资源解释器,判定数量、成员关系和执行结果。\n\n\n **L221** 最后展开稳定理由与自有公告主张,通过计算完成全部合取分支。\n\n\n **L223** 说明后续定义或结果:开放政策满足生成规范,但空记录无法履行非空自身规则的评估要求。\n\n\n **L224** 开放政策满足生成规范,但空记录无法履行非空自身规则的评估要求。\n\n\n **L225** 将openPolicy的生成取向与空工作日志下的自有反身履责失败组合。\n\n\n **L226** 分别证明生成取向,并反驳空日志的Reflexive主张。\n\n\n **L227** 计算openPolicy的扩展价值取向与无条件可修订性。\n\n\n **L228** 反证假设空日志满足自有反身契约。\n\n\n **L229** 对已登记assessingRule应用无自我豁免定理,从假设的空日志履责迫出已执行评估。\n\n\n **L230** 选取所有者匹配的系统自身,并证明该评估对它适用。\n\n\n **L231** 展开Performed后得到空工作列表中不可能存在的成员。\n\n\n **L233** 说明后续定义或结果:计算自然数等式n+1=2*n是否成立。\n\n\n **L234** 计算自然数等式n+1=2*n是否成立。\n\n\n **L236** 逐个检验给定样本上的算术谓词,不检查样本外输入。\n\n\n **L238** 说明后续定义或结果:样本一通过而零失败,反驳从有限自测得到全称正确性。\n\n\n **L239** 样本一通过而零失败,反驳从有限自测得到全称正确性。\n\n\n **L240** 同一算术原则在样本1上通过,却在0上为假。\n\n\n **L241** 因此该原则并非对所有自然数输入都返回true。\n\n\n **L242** 将通过样本的计算与两项失败主张分开。\n\n\n **L243** 计算单样本:1+1等于2×1,故selfTest [1]为true。\n\n\n **L244** 把0处的具体失败与普遍成功的反驳分开。\n\n\n **L245** 计算0+1≠2×0,使ownArithmeticPrinciple 0为false。\n\n\n **L246** 假设同一原则对每个输入都成功。\n\n\n **L247** 把该普遍假设实例化到输入0。\n\n\n **L248** 与0处计算所得false矛盾,反驳普遍正确性。\n\n\n **L250** 关闭当前命名空间。\n\n\n### `leanified/CoreReader/Choice.lean`\n\n\n```lean\nimport CoreReader.Evidence\n\nnamespace CoreReader.Choice\nopen CoreReader.Logic CoreReader.Evidence\n\ninductive StatusKind | name | convention | standing\n deriving DecidableEq, Repr\n\ninductive MethodReason | output | explanation | applicability | simplicity | procedure\n deriving DecidableEq, Repr\n\ninductive Reason | status (kind : StatusKind) | method (kind : MethodReason)\n deriving DecidableEq, Repr\n\n/- An implementation has observable behavior, a stated domain, an explanation formula and an execution trace. -/\nstructure Implementation where\n name : String\n conventional : Bool\n established : Bool\n run : Nat → Nat\n cost : Nat\n domain : Nat → Prop\n explanation : Nat → Nat\n trace : Nat → List Nat\n\n/- An application selects relevant objectives and constraints; no universal ranking or score is prescribed. -/\nstructure Requirements where\n inputs : Nat → Prop\n expected : Nat → Nat\n budget : Nat\n values : MethodReason → Prop\n\n/- These are explicit, content-based interpretations of possible method reasons in this application. -/\ndef MethodContent (req : Requirements) (i : Implementation) : MethodReason → Prop\n | .output => ∀ x, req.inputs x → i.run x = req.expected x\n | .explanation => ∀ x, req.inputs x → i.explanation x = i.run x\n | .applicability => ∀ x, req.inputs x → i.domain x\n | .simplicity => i.cost ≤ req.budget\n | .procedure => ∀ x, req.inputs x → (i.trace x).getLast? = some (i.run x)\n\n/- The extra choice commitment requires both selected relevance and actual reason content; pure status supplies neither. -/\ndef Relevant (req : Requirements) (i : Implementation) : Reason → Prop\n | .status _ => False\n | .method kind => req.values kind ∧ MethodContent req i kind\n\ndef Feasible (req : Requirements) (i : Implementation) : Prop :=\n (∀ x, req.inputs x → i.run x = req.expected x) ∧ i.cost ≤ req.budget\n\n/- In this application, a relevant reason is eligible only after its stated output and budget requirements hold. -/\ndef JustifiedChoice (req : Requirements) (i : Implementation) (reasons : List Reason) : Prop :=\n Feasible req i ∧ ∃ reason ∈ reasons, Relevant req i reason\n\n/- This proves the structural effect of the adopted choice commitment for each of its three status-only cases. -/\ntheorem statusOnlyFails (req : Requirements) (i : Implementation) (k : StatusKind) :\n ¬ JustifiedChoice req i [.status k] := by\n rintro ⟨_, reason, hr, hv⟩\n simp only [List.mem_singleton] at hr\n subst reason\n exact hv\n\ndef identityImpl : Implementation where\n name := \"Existing identity implementation\"\n conventional := true\n established := true\n run n := n\n cost := 1\n domain _ := True\n explanation n := n\n trace n := [n]\n\ndef successorImpl : Implementation where\n name := \"Successor implementation\"\n conventional := false\n established := false\n run n := n + 1\n cost := 2\n domain _ := True\n explanation n := n + 1\n trace n := [n, n + 1]\n\ndef changedOutsideZero : Implementation :=\n { identityImpl with\n name := \"Changed outside zero\"\n conventional := false\n established := false\n run := fun n => if n = 0 then 0 else n + 1\n explanation := fun n => if n = 0 then 0 else n + 1\n trace := fun n => [if n = 0 then 0 else n + 1] }\n\ndef identityRequirements : Requirements where\n inputs _ := True\n expected n := n\n budget := 1\n values _ := True\n\ndef objectiveReason : List Reason := [.method .output]\n\ntheorem identityOutputReason : Relevant identityRequirements identityImpl (.method .output) := by\n exact ⟨trivial, fun _ _ => rfl⟩\n\ntheorem identityFeasible : Feasible identityRequirements identityImpl :=\n ⟨fun _ _ => rfl, by decide⟩\n\ntheorem identityJustified : JustifiedChoice identityRequirements identityImpl objectiveReason :=\n ⟨identityFeasible, .method .output, by simp [objectiveReason], identityOutputReason⟩\n\n/- A conventional existing implementation can be selected for an actual requirement, not for status alone. -/\ntheorem conventionWithReason :\n identityImpl.conventional = true ∧ identityImpl.established = true ∧\n JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output] := by\n exact ⟨rfl, rfl, identityFeasible, .method .output, by simp, identityOutputReason⟩\n\ninductive Candidate | identity | successor\n deriving DecidableEq, Repr\n\ndef implementation : Candidate → Implementation\n | .identity => identityImpl\n | .successor => successorImpl\n\n/- Feasibility is decided by the same stated behavior and resource requirement for either candidate. -/\ntheorem singleFeasible :\n (∀ candidate, Feasible identityRequirements (implementation candidate) ↔ candidate = .identity) ∧\n JustifiedChoice identityRequirements identityImpl objectiveReason := by\n constructor\n · intro candidate\n cases candidate\n · simp [Feasible, identityRequirements, implementation, identityImpl]\n · simp [Feasible, identityRequirements, implementation, successorImpl]\n · exact identityJustified\n\n/- The same observed input can conceal a relevant difference at another input. -/\ntheorem localNotGlobal :\n (∀ x, x = 0 → identityImpl.run x = changedOutsideZero.run x) ∧\n identityImpl.run 1 ≠ changedOutsideZero.run 1 := by\n constructor\n · intro x hx; subst x; rfl\n · decide\n\n/- This candidate is cheap enough but misses the required identity output. -/\ndef cheapSuccessor : Implementation := { successorImpl with cost := 1 }\n\ntheorem eligibleInternalReasonNotSufficient :\n Relevant identityRequirements cheapSuccessor (.method .simplicity) ∧\n ¬ JustifiedChoice identityRequirements cheapSuccessor [.method .simplicity] := by\n refine ⟨⟨trivial, by change 1 ≤ 1; decide⟩, ?_⟩\n intro h\n have bad := h.1.1 0 trivial\n cases bad\n\n/- Each of the four internal-method reasons is eligible because of its actual selected requirement and content. -/\ntheorem internalReasons :\n Relevant identityRequirements identityImpl (.method .explanation) ∧\n Relevant identityRequirements identityImpl (.method .applicability) ∧\n Relevant identityRequirements identityImpl (.method .simplicity) ∧\n Relevant identityRequirements identityImpl (.method .procedure) ∧\n (Relevant identityRequirements cheapSuccessor (.method .simplicity) ∧\n ¬ JustifiedChoice identityRequirements cheapSuccessor [.method .simplicity]) := by\n exact ⟨⟨trivial, fun _ _ => rfl⟩, ⟨trivial, fun _ _ => trivial⟩,\n ⟨trivial, by change 1 ≤ 1; decide⟩, ⟨trivial, fun _ _ => rfl⟩, eligibleInternalReasonNotSufficient⟩\n\n/- Openness about reasons does not make two actual behaviors identical or reject the existing implementation. -/\ntheorem openNotEquivalent :\n JustifiedChoice identityRequirements identityImpl objectiveReason ∧\n identityImpl.run 0 ≠ successorImpl.run 0 := by\n exact ⟨identityJustified, by decide⟩\n\n/- A priority interpretation chooses one of the same two actual implementations. -/\ndef priorityClaim : Claim Candidate := fun selected => selected = .identity\n\ndef statusFacts : Theory Candidate := union\n (singleton (fun _ => identityImpl.conventional = true))\n (singleton (fun _ => identityImpl.established = true))\n\n/- Both interpretations have exactly the same true conventional and established status facts. -/\ntheorem statusFactsModel (selected : Candidate) : Models statusFacts selected := by\n exact (modelsUnion _ _ _).2 ⟨(modelsSingleton _ _).2 rfl, (modelsSingleton _ _).2 rfl⟩\n\ndef priorityArticulation : Articulation Candidate :=\n ⟨[\"priority\", \"conventional use\", \"established status\"], statusFacts,\n [fun _ => identityImpl.conventional = true, fun _ => identityImpl.established = true],\n fun _ => True⟩\n\n/- This procedure reports whether the actual status premises entail that very priority claim over its stated two-candidate scope. -/\ndef AssessmentAccurate (report : Bool) : Prop :=\n report = true ↔ Entails statusFacts priorityClaim\n\ntheorem statusDoesNotEntailPriority : ¬ Entails statusFacts priorityClaim := by\n intro h\n have bad := h .successor (statusFactsModel .successor)\n cases bad\n\ntheorem statusAssessmentNonEntailment :\n Articulated priorityArticulation ∧ AssessmentAccurate false ∧\n (∀ selected, Models statusFacts selected) ∧\n priorityClaim .identity ∧ ¬ priorityClaim .successor ∧\n ¬ Entails statusFacts priorityClaim ∧\n ¬ JustifiedChoice identityRequirements identityImpl [.status .standing] := by\n refine ⟨⟨by simp [priorityArticulation], by simp [priorityArticulation]⟩,\n ⟨(by intro h; cases h), (fun h => False.elim (statusDoesNotEntailPriority h))⟩,\n statusFactsModel, rfl, (by intro h; cases h), statusDoesNotEntailPriority,\n statusOnlyFails _ _ _⟩\n\n/- An assessment identifies the exact premises and priority question whose entailment it reports. -/\nstructure PriorityAssessment where\n premises : Theory Candidate\n question : Claim Candidate\n report : Bool\n/- Accuracy concerns the actual reported entailment question, independently of a later choice policy. -/\ndef PriorityAssessment.accurate (assessment : PriorityAssessment) : Prop :=\n assessment.report = true ↔ Entails assessment.premises assessment.question\n/- Both policies receive this same correctly negative status-only priority audit. -/\ndef statusPriorityAudit : PriorityAssessment := ⟨statusFacts, priorityClaim, false⟩\n/- Priority reasons are a policy component independent of the assessment's report and objects. -/\nstructure ChoicePolicy where\n selected : Candidate\n priorityReasons : List Reason\n assessment : PriorityAssessment\n/- This is completion of the specified assessment procedure only, not full compliance with philosophical Grounds. -/\ndef GeneralAssessmentFulfilled (policy : ChoicePolicy) : Prop :=\n Articulated priorityArticulation ∧ policy.assessment = statusPriorityAudit ∧ policy.assessment.accurate\n/- The additional choice norm separately tests the reasons actually used to prioritize the selected implementation. -/\ndef AdditionalChoiceNorm (policy : ChoicePolicy) : Prop :=\n JustifiedChoice identityRequirements (implementation policy.selected) policy.priorityReasons\n/- This policy retains status alone as its priority reason despite receiving the correctly negative status audit. -/\ndef statusPriorityPolicy : ChoicePolicy := ⟨.identity, [.status .standing], statusPriorityAudit⟩\n/- This policy selects the same implementation using its actual relevant output reason after the same audit. -/\ndef outputPriorityPolicy : ChoicePolicy := ⟨.identity, objectiveReason, statusPriorityAudit⟩\n/- The shared negative result is mathematically accurate for its actual status premises and question. -/\ntheorem statusPriorityAuditAccurate : statusPriorityAudit.accurate := by\n constructor\n · intro h; cases h\n · intro h; exact False.elim (statusDoesNotEntailPriority h)\n/- These independently variable policies share facts, selected implementation and completed audit, but differ on the extra choice norm. -/\ndef PolicyIndependenceExample : Prop :=\n statusPriorityPolicy.selected = outputPriorityPolicy.selected ∧\n statusPriorityPolicy.assessment = outputPriorityPolicy.assessment ∧\n statusPriorityPolicy.assessment.premises = statusFacts ∧\n statusPriorityPolicy.assessment.question = priorityClaim ∧\n statusPriorityPolicy.assessment.report = false ∧\n (∀ selected, Models statusPriorityPolicy.assessment.premises selected) ∧\n statusPriorityPolicy.priorityReasons ≠ outputPriorityPolicy.priorityReasons ∧\n GeneralAssessmentFulfilled statusPriorityPolicy ∧ GeneralAssessmentFulfilled outputPriorityPolicy ∧\n ¬ AdditionalChoiceNorm statusPriorityPolicy ∧ AdditionalChoiceNorm outputPriorityPolicy\n/- Changing the actual priority reasons changes choice compliance while the accurate audit remains identical. -/\ntheorem policyIndependenceExample : PolicyIndependenceExample := by\n have articulated : Articulated priorityArticulation :=\n ⟨by simp [priorityArticulation], by simp [priorityArticulation]⟩\n refine ⟨rfl,rfl,rfl,rfl,rfl,statusFactsModel,?_,\n ⟨articulated,rfl,statusPriorityAuditAccurate⟩,\n ⟨articulated,rfl,statusPriorityAuditAccurate⟩,?_,?_⟩\n · decide\n · exact statusOnlyFails identityRequirements identityImpl .standing\n · exact identityJustified\n\n/- A correctly articulated, completed negative assessment does not enforce the additional selection rule.\nThis is only independence from represented assessment procedures: keeping this unsupported priority would fail general support proportionality too. -/\ntheorem generalGroundsNotChoice :\n (Articulated priorityArticulation ∧ AssessmentAccurate false ∧\n (∀ selected, Models statusFacts selected) ∧\n priorityClaim .identity ∧ ¬ priorityClaim .successor ∧\n ¬ Entails statusFacts priorityClaim ∧\n ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧\n PolicyIndependenceExample :=\n ⟨statusAssessmentNonEntailment, policyIndependenceExample⟩\n\nend CoreReader.Choice\n```\n\n\n\n **L1** 导入 CoreReader.Evidence,使其已检查声明可供本模块使用;这一行不提出新的哲学结论。\n\n\n **L3** 打开命名空间 CoreReader.Choice,使后续声明获得这一模块限定名。\n\n\n **L4** 允许不加限定使用 CoreReader.Logic CoreReader.Evidence 中的名称;这改变名称解析,不增加假设。\n\n\n **L6** 声明可选构造 StatusKind。定义名称、惯用性和既有地位三类身份理由标签。\n\n\n **L7** 为这些有限构造子派生可判定相等与可打印表示;它们是计算便利,不是选择判据。\n\n\n **L9** 声明可选构造 MethodReason。定义输出、解释、适用性、简洁性和流程五类方法理由。\n\n\n **L10** 为这些有限构造子派生可判定相等与可打印表示;它们是计算便利,不是选择判据。\n\n\n **L12** 声明可选构造 Reason。将身份理由与方法理由区分为不同构造器。\n\n\n **L13** 为这些有限构造子派生可判定相等与可打印表示;它们是计算便利,不是选择判据。\n\n\n **L15** 说明 Implementation 的预定范围。对应声明涉及:分别保存名称和状态标记、输出、成本、域、解释函数与轨迹。 该注释用于解释,不是证明前提。\n\n\n **L16** 声明数据接口 Implementation。分别保存名称和状态标记、输出、成本、域、解释函数与轨迹。\n\n\n **L17** 保存实现的描述性名称,不赋予优先权。\n\n\n **L18** 以布尔地位事实记录实现是否惯常。\n\n\n **L19** 记录实现是否已经确立,与真实行为独立。\n\n\n **L20** 保存真实自然数输入与输出函数。\n\n\n **L21** 保存将按应用预算检查的成本。\n\n\n **L22** 以输入上的谓词保存实现所述适用域。\n\n\n **L23** 保存将与真实运行结果比较的解释输出内容。\n\n\n **L24** 保存按输入索引的执行轨迹,其最后元素可与真实输出比较。\n\n\n **L26** 说明 Requirements 的预定范围。对应声明涉及:保存输入域、期望输出、预算及重视的方法理由类别。 该注释用于解释,不是证明前提。\n\n\n **L27** 声明数据接口 Requirements。保存输入域、期望输出、预算及重视的方法理由类别。\n\n\n **L28** 规定应用实际要求哪些输入。\n\n\n **L29** 规定各输入的预期输出。\n\n\n **L30** 规定应用预算约束。\n\n\n **L31** 规定该应用重视哪些方法理由类别;这一选择是被采纳的输入。\n\n\n **L33** 说明 MethodContent 的预定范围。对应声明涉及:按方法类别检查实际输出、解释等同、域覆盖、成本或轨迹末项合同。 该注释用于解释,不是证明前提。\n\n\n **L34** 定义 MethodContent。按方法类别检查实际输出、解释等同、域覆盖、成本或轨迹末项合同。\n\n\n **L35** 输出理由要求该实现真实输出在每个必需输入上等于应用预期输出。\n\n\n **L36** 解释理由要求解释输出在每个必需输入上匹配同一实现真实运行。\n\n\n **L37** 适用性理由要求每个应用必需输入属于该实现的适用域。\n\n\n **L38** 简单性理由为所选应用真实的成本不超预算条件。\n\n\n **L39** 过程理由要求真实轨迹末元素在每个必需输入上等于该实现真实输出。\n\n\n **L41** 说明 Relevant 的预定范围。对应声明涉及:身份理由被已采纳规范排除;方法理由必须被重视并满足其对应合同。 该注释用于解释,不是证明前提。\n\n\n **L42** 定义 Relevant。身份理由被已采纳规范排除;方法理由必须被重视并满足其对应合同。\n\n\n **L43** 在这一被采纳选择规范下,地位理由被定义为不相关,不依赖其地位子类。\n\n\n **L44** 方法理由必须同时属于这些要求所重视的类别,并满足该类别真实 MethodContent。\n\n\n **L46** 定义 Feasible。同时要求指定输入上的输出正确及成本不超预算。\n\n\n **L47** 可行性要求每个必需输入的真实输出正确,且真实成本不超过应用预算。\n\n\n **L49** 说明 JustifiedChoice 的预定范围。对应声明涉及:同时要求输出和预算可行,以及至少一个列出的、被重视且内容成立的方法理由。 该注释用于解释,不是证明前提。\n\n\n **L50** 定义 JustifiedChoice。同时要求输出和预算可行,以及至少一个列出的、被重视且内容成立的方法理由。\n\n\n **L51** 要求可行性及至少一个实际列出的相关理由;仅有相关理由不确立可行性。\n\n\n **L53** 说明 statusOnlyFails 的预定范围。对应声明涉及:纯身份理由的相关性定义为假,故任何实现都不能仅凭它获得规范内正当选择。 该注释用于解释,不是证明前提。\n\n\n **L54** 陈述经检查的结果 statusOnlyFails。纯身份理由的相关性定义为假,故任何实现都不能仅凭它获得规范内正当选择。\n\n\n **L55** 对给定任意要求与实现,否定唯一列出理由为地位时的有理由选择。\n\n\n **L56** 拆解假定的仅凭地位的有理由选择,提取所列理由及相关性证明;仅有可行性不能提供缺失的相关性。\n\n\n **L57** 化简单元素成员关系,说明提取的理由恰为给定地位理由。\n\n\n **L58** 把确定的地位理由代入假定的相关性证明。\n\n\n **L59** 地位理由的相关性被定义为 False,因此提取出的 hv 已是矛盾。\n\n\n **L61** 定义 identityImpl。构造既有惯用恒等实现:成本一、全域、对应解释和单项轨迹。\n\n\n **L62** 命名具体既有恒等实现,不用名称证明质量。\n\n\n **L63** 把恒等实现的惯常与既有地位标记为 true;这些事实仍与真实方法理由不同。\n\n\n **L64** 把恒等实现的惯常与既有地位标记为 true;这些事实仍与真实方法理由不同。\n\n\n **L65** 把真实恒等输出定义为未改变的输入 n。\n\n\n **L66** 把恒等实现真实成本设为 1。\n\n\n **L67** 使恒等实现适用域包含全部自然数输入。\n\n\n **L68** 提供等于输入的解释结果,与恒等实现真实输出匹配。\n\n\n **L69** 以单元素输入作为真实轨迹,其最后元素等于恒等输出。\n\n\n **L71** 定义 successorImpl。构造后继实现:成本二、全域、对应解释及两项轨迹。\n\n\n **L72** 命名替代的后继实现。\n\n\n **L73** 在该例中把后继实现标记为既非惯常也非既有;这一地位本身不决定可行性。\n\n\n **L74** 在该例中把后继实现标记为既非惯常也非既有;这一地位本身不决定可行性。\n\n\n **L75** 把后继实现真实输出定义为 n+1。\n\n\n **L76** 把其原始成本设为 2,高于恒等应用预算 1。\n\n\n **L77** 使后继实现适用域也包含每个自然数输入。\n\n\n **L78** 提供其解释结果 n+1,忠实于自身真实输出。\n\n\n **L79** 在轨迹中记录输入及之后的真实后继输出。\n\n\n **L81** 定义 changedOutsideZero。复制恒等实现但令非零输入改为后继,零点仍相同。\n\n\n **L82** 从 identityImpl 的字段出发,明确覆盖后续组件。\n\n\n **L83** 按其在零输入以外的变化命名修改后实现。\n\n\n **L84** 把修改后实现的惯常与既有标记改为 false。\n\n\n **L85** 把修改后实现的惯常与既有标记改为 false。\n\n\n **L86** 在输入 0 保持输出 0,其余输入均返回 n+1。\n\n\n **L87** 使其解释遵循相同真实分段输出函数。\n\n\n **L88** 以相同分段结果作为单元素轨迹,完成实现覆盖。\n\n\n **L90** 定义 identityRequirements。要求所有自然数输入保持恒等,预算一,重视全部方法理由。\n\n\n **L91** 恒等应用要求全部自然数输入。\n\n\n **L92** 把期望输出设为未改变的输入。\n\n\n **L93** 为应用采纳预算 1。\n\n\n **L94** 接纳全部已表示的方法理由类别,仍须检查其真实内容。\n\n\n **L96** 定义 objectiveReason。理由清单只包含输出合同这一方法类别。\n\n\n **L98** 陈述经检查的结果 identityOutputReason。恒等实现直接满足所要求全输入恒等输出且该理由被重视。 后续策略块证明这一显式类型。\n\n\n **L99** 这些要求接纳输出理由;identityImpl 在每个允许输入的真实输出与预期输出由自反性相等。\n\n\n **L101** 陈述经检查的结果 identityFeasible。证明全输入恒等输出及成本一满足预算一。 给出的证明项使用所示构造见证或先前引理,而不增加公理。\n\n\n **L102** 对恒等实现,每个必需输出均由自反性正确;计算成本 1 不超过预算 1。\n\n\n **L104** 陈述经检查的结果 identityJustified。以恒等输出和可行性为基础构造实际选择理由见证。 给出的证明项使用所示构造见证或先前引理,而不增加公理。\n\n\n **L105** 组合恒等实现可行性与真实输出理由,证明它属于 objectiveReason,并提供基于内容的相关性。\n\n\n **L107** 说明 conventionWithReason 的预定范围。对应声明涉及:既有惯用标记与有效输出理由并存;真正证据来自方法理由而非标记。 该注释用于解释,不是证明前提。\n\n\n **L108** 陈述经检查的结果 conventionWithReason。既有惯用标记与有效输出理由并存;真正证据来自方法理由而非标记。\n\n\n **L109** 保留恒等实现两个真实地位事实均为 true。\n\n\n **L110** 主张使用惯常与真实输出理由组成的列表可获得有理由选择;相关性来自输出理由。\n\n\n **L111** 计算惯常与既有地位事实,保留实际可行性,并选取列表中的输出理由及其另行证明的相关性。\n\n\n **L113** 声明可选构造 Candidate。候选域严格只有identity与successor,不含所有实现。\n\n\n **L114** 为这些有限构造子派生可判定相等与可打印表示;它们是计算便利,不是选择判据。\n\n\n **L116** 定义 implementation。将两个候选标签映射到其具体函数实现。\n\n\n **L117** 把恒等候选解释为真实 identityImpl 对象。\n\n\n **L118** 把后继候选解释为真实 successorImpl 对象。\n\n\n **L120** 说明 singleFeasible 的预定范围。对应声明涉及:穷尽两个候选,证明恒等是预算一及恒等目标下唯一可行者,并有实际选择理由。 该注释用于解释,不是证明前提。\n\n\n **L121** 陈述经检查的结果 singleFeasible。穷尽两个候选,证明恒等是预算一及恒等目标下唯一可行者,并有实际选择理由。\n\n\n **L122** 在明确的双值候选类型中,要求可行性恰对应 identity。\n\n\n **L123** 还保留恒等实现真实的输出理由选择依据。\n\n\n **L124** 分开准确的可行候选刻画与恒等选择已有的理由证明。\n\n\n **L125** 固定明确恒等、后继类型中的任意候选,再检查其可行性等价关系。\n\n\n **L126** 穷尽实际双候选类型:identity 或 successor;不涉及未列出的实现。\n\n\n **L127** 对 identity 展开真实输出与成本;恒等输出和预算条件均满足。\n\n\n **L128** 对 successor 展开同一要求;该候选不能满足恒等输出,其原始成本也超预算。\n\n\n **L129** 复用 identityJustified 完成具体候选的有理由选择义务。\n\n\n **L131** 说明 localNotGlobal 的预定范围。对应声明涉及:两个实现零点相同、一处不同,不能由局部表现推全域等价。 该注释用于解释,不是证明前提。\n\n\n **L132** 陈述经检查的结果 localNotGlobal。两个实现零点相同、一处不同,不能由局部表现推全域等价。\n\n\n **L133** 只在输入 0 范围下比较真实输出。\n\n\n **L134** 另行要求输入 1 处真实输出不同。\n\n\n **L135** 分开输入 0 范围内相等与输入 1 处真实不等两个目标。\n\n\n **L136** 代入局部范围假设 x=0;两个实现输出依定义相等。\n\n\n **L137** 计算输入 1 处的实际输出,验证所述不等关系。\n\n\n **L139** 说明 cheapSuccessor 的预定范围。对应声明涉及:把后继成本降为一,但仍不满足恒等输出目标。 该注释用于解释,不是证明前提。\n\n\n **L140** 定义 cheapSuccessor。把后继成本降为一,但仍不满足恒等输出目标。\n\n\n **L142** 陈述经检查的结果 eligibleInternalReasonNotSufficient。廉价后继有相关简洁性理由,却因输出不可行仍不能获得正当选择。\n\n\n **L143** 要求 cheapSuccessor 的成本理由在所选要求下真实相关。\n\n\n **L144** 仍否定它仅凭该理由获得有理由选择,因为可行性还包括输出正确。\n\n\n **L145** 证明便宜后继实现具有被接纳的成本理由,成本 1 不超过预算 1,再单独否定有理由选择。\n\n\n **L146** 假定 cheapSuccessor 凭成本理由获得有理由选择,以提取并反驳其必需输出可行性。\n\n\n **L147** 假定有理由选择包含输出可行性;将其应用于输入 0,而后继实现返回 1,不是预期 0。\n\n\n **L148** 消去所得不可能输出等式;相关成本理由没有修复错误输出。\n\n\n **L150** 说明 internalReasons 的预定范围。对应声明涉及:给恒等实现四类有效内部理由,并以廉价后继反驳相关理由自动充分。 该注释用于解释,不是证明前提。\n\n\n **L151** 陈述经检查的结果 internalReasons。给恒等实现四类有效内部理由,并以廉价后继反驳相关理由自动充分。\n\n\n **L152** 要求同一真实恒等实现具有忠实解释理由。\n\n\n **L153** 要求其真实适用性覆盖必需输入。\n\n\n **L154** 要求其真实成本满足所重视的简单性与预算条件。\n\n\n **L155** 要求其真实轨迹内容满足所重视的过程条件。\n\n\n **L156** 纳入另一个便宜后继实例,其中成本理由合格。\n\n\n **L157** 该便宜候选仍未满足有理由选择;组合定理从此开始证明。\n\n\n **L158** 给 identity 提供被接纳且真实忠实的解释与适用性理由,并在每个必需输入检查内容。\n\n\n **L159** 提供真实预算与轨迹理由,再纳入便宜却错误的实例,说明相关性本身不充分。\n\n\n **L161** 说明 openNotEquivalent 的预定范围。对应声明涉及:已有正当选择实例,但恒等与后继在零处仍不同。 该注释用于解释,不是证明前提。\n\n\n **L162** 陈述经检查的结果 openNotEquivalent。已有正当选择实例,但恒等与后继在零处仍不同。\n\n\n **L163** 基于真实输出理由,保留既有恒等实现的有理由选择。\n\n\n **L164** 还要求恒等与后继实现在输入 0 产生不同真实输出。\n\n\n **L165** 保留已有恒等选择理由,并计算 identity 与 successor 在 0 处不同的真实输出。\n\n\n **L167** 说明 priorityClaim 的预定范围。对应声明涉及:要求被选候选为identity。 该注释用于解释,不是证明前提。\n\n\n **L168** 定义 priorityClaim。要求被选候选为identity。\n\n\n **L170** 定义 statusFacts。理论只包含固定identity的惯用和既有状态事实,与当前选择无关。\n\n\n **L171** 第一地位前提记录恒等实现真实惯常地位,不依赖候选解释。\n\n\n **L172** 第二地位前提记录同一实现真实既有地位。\n\n\n **L174** 说明 statusFactsModel 的预定范围。对应声明涉及:两个候选都满足这些固定元数据事实。 该注释用于解释,不是证明前提。\n\n\n **L175** 陈述经检查的结果 statusFactsModel。两个候选都满足这些固定元数据事实。 后续策略块证明这一显式类型。\n\n\n **L176** 两个地位谓词都针对同一真实恒等实现,且独立于选择哪种候选解释而为真;组合其单元素模型。\n\n\n **L178** 定义 priorityArticulation。把身份事实、对应理由及全范围保存成非空表达。\n\n\n **L179** 以 statusFacts 为前提理论,表述优先权与真实地位概念。\n\n\n **L180** 把相同真实惯常与既有事实列为所表述理由。\n\n\n **L181** 对该地位优先权表述使用不受限候选范围。\n\n\n **L183** 说明 AssessmentAccurate 的预定范围。对应声明涉及:报告为真恰好对应身份事实蕴涵优先选择的语义结论。 该注释用于解释,不是证明前提。\n\n\n **L184** 定义 AssessmentAccurate。报告为真恰好对应身份事实蕴涵优先选择的语义结论。\n\n\n **L185** 以 report=true 与这些地位事实语义蕴含该准确优先权问题之间的等价,定义报告准确性。\n\n\n **L187** 陈述经检查的结果 statusDoesNotEntailPriority。以successor为身份事实的反模型,拒绝推出必须选择identity。 后续策略块证明这一显式类型。\n\n\n **L188** 假定真实地位事实在全部候选解释中蕴含恒等优先权。\n\n\n **L189** 将假定的地位到优先权蕴含应用于 successor;它满足全部相同真实地位事实,却不是 identity。\n\n\n **L190** 不同候选构造子否定在 successor 处推出的优先权等式。\n\n\n **L192** 陈述经检查的结果 statusAssessmentNonEntailment。保留原事实反模型:身份事实可表达且被准确评估,但不蕴涵恒等优先。\n\n\n **L193** 要求同一地位优先权评估具有程序表述与正确否定报告。\n\n\n **L194** 保留所有候选解释为相同真实地位事实的模型。\n\n\n **L195** 优先权谓词在 identity 处成立,在 successor 处失败。\n\n\n **L196** 否定仅由地位事实蕴含该优先权谓词。\n\n\n **L197** 还拒绝只以既有地位作为真实理由选择恒等实现。\n\n\n **L198** 检查 priorityArticulation 具有非空概念与真实地位理由。\n\n\n **L199** 证明 false 报告准确:它不可能等于 true;任意蕴含假设又与真实 successor 反模型矛盾。\n\n\n **L200** 保留两个候选对相同事实的模型、identity 而非 successor 的优先权,以及已证的蕴含失败。\n\n\n **L201** 对唯一理由为既有地位的明确恒等选择,复用一般的仅凭地位失败定理。\n\n\n **L203** 说明 PriorityAssessment 的预定范围。对应声明涉及:独立于选择政策保存实际假设、问题及布尔评估报告。 该注释用于解释,不是证明前提。\n\n\n **L204** 声明数据接口 PriorityAssessment。独立于选择政策保存实际假设、问题及布尔评估报告。\n\n\n **L205** 保存该评估实际审查的前提理论。\n\n\n **L206** 保存待评估其蕴含的准确优先权主张。\n\n\n **L207** 保存报告的布尔答案,与事实及问题分开。\n\n\n **L208** 说明 PriorityAssessment.accurate 的预定范围。对应声明涉及:要求报告精确对应同一假设和问题的语义蕴涵结果。 该注释用于解释,不是证明前提。\n\n\n **L209** 定义 PriorityAssessment.accurate。要求报告精确对应同一假设和问题的语义蕴涵结果。\n\n\n **L210** 要求该评估真实报告与其自身前提到自身问题的蕴含准确一致。\n\n\n **L211** 说明 statusPriorityAudit 的预定范围。对应声明涉及:为固定身份事实与优先问题记录不蕴涵报告。 该注释用于解释,不是证明前提。\n\n\n **L212** 定义 statusPriorityAudit。为固定身份事实与优先问题记录不蕴涵报告。\n\n\n **L213** 说明 ChoicePolicy 的预定范围。对应声明涉及:把所选候选、优先理由和独立储存的评估分开。 该注释用于解释,不是证明前提。\n\n\n **L214** 声明数据接口 ChoicePolicy。把所选候选、优先理由和独立储存的评估分开。\n\n\n **L215** 保存该政策实际选择的候选。\n\n\n **L216** 独立于评估记录保存该政策真实优先权理由。\n\n\n **L217** 保存政策完成其程序的实际评估。\n\n\n **L218** 说明 GeneralAssessmentFulfilled 的预定范围。对应声明涉及:要求实际表达非空并保留准确身份审查,不加入额外选择标准。 该注释用于解释,不是证明前提。\n\n\n **L219** 定义 GeneralAssessmentFulfilled。要求实际表达非空并保留准确身份审查,不加入额外选择标准。\n\n\n **L220** 要求非空表述、恰为共享 statusPriorityAudit 及其准确性;这是特定程序履行,不是完整哲学 Grounds。\n\n\n **L221** 说明 AdditionalChoiceNorm 的预定范围。对应声明涉及:把单独的可行性及相关性规范应用到政策所选实现和理由。 该注释用于解释,不是证明前提。\n\n\n **L222** 定义 AdditionalChoiceNorm。把单独的可行性及相关性规范应用到政策所选实现和理由。\n\n\n **L223** 把 JustifiedChoice 单独应用于政策实际所选实现及真实理由列表。\n\n\n **L224** 说明 statusPriorityPolicy 的预定范围。对应声明涉及:政策只凭既有地位选择恒等,同时保留准确的不蕴涵评估。 该注释用于解释,不是证明前提。\n\n\n **L225** 定义 statusPriorityPolicy。政策只凭既有地位选择恒等,同时保留准确的不蕴涵评估。\n\n\n **L226** 说明 outputPriorityPolicy 的预定范围。对应声明涉及:保留同一选择和评估,把理由改为实际输出理由。 该注释用于解释,不是证明前提。\n\n\n **L227** 定义 outputPriorityPolicy。保留同一选择和评估,把理由改为实际输出理由。\n\n\n **L228** 说明 statusPriorityAuditAccurate 的预定范围。对应声明涉及:利用后继反模型证明所记不蕴涵报告准确。 该注释用于解释,不是证明前提。\n\n\n **L229** 陈述经检查的结果 statusPriorityAuditAccurate。利用后继反模型证明所记不蕴涵报告准确。 后续策略块证明这一显式类型。\n\n\n **L230** 把否定审查的准确性拆为与蕴含等价的两个方向。\n\n\n **L231** 审查的实际 false 报告不可能等于 true,因此该方向的前提不可能成立。\n\n\n **L232** 任何所断言的蕴含都与 statusDoesNotEntailPriority 矛盾,从而确立 false 报告准确性的反方向。\n\n\n **L233** 说明 PolicyIndependenceExample 的预定范围。对应声明涉及:要求同选择同审查而理由不同的两政策,均履行所表示评估责任,只有输出理由政策满足额外规范。 该注释用于解释,不是证明前提。\n\n\n **L234** 定义 PolicyIndependenceExample。要求同选择同审查而理由不同的两政策,均履行所表示评估责任,只有输出理由政策满足额外规范。\n\n\n **L235** 固定两个政策所选候选相同。\n\n\n **L236** 固定两个政策采用同一实际评估。\n\n\n **L237** 把该评估前提绑定到真实共享 statusFacts。\n\n\n **L238** 把其问题绑定到同一 priorityClaim。\n\n\n **L239** 把共同报告固定为 false,不允许政策变化改变审查答案。\n\n\n **L240** 为每个候选解释保留相同评估前提的模型。\n\n\n **L241** 尽管候选与审查相同,仍要求实际优先权理由列表不同。\n\n\n **L242** 要求两个政策准确完成同一指定评估程序。\n\n\n **L243** 要求额外选择规范下结果相反:地位失败、输出通过。\n\n\n **L244** 说明 policyIndependenceExample 的预定范围。对应声明涉及:构造两个独立政策对象,结合真实审查准确性、身份理由拒绝和输出理由成立。 该注释用于解释,不是证明前提。\n\n\n **L245** 陈述经检查的结果 policyIndependenceExample。构造两个独立政策对象,结合真实审查准确性、身份理由拒绝和输出理由成立。 后续策略块证明这一显式类型。\n\n\n **L246** 为两个政策构造同一个关于真实地位优先权问题的非空表述。\n\n\n **L247** 为两个政策构造同一个关于真实地位优先权问题的非空表述。\n\n\n **L248** 固定相同所选候选、审查、前提、问题与 false 报告;保留真实事实模型,留下理由列表差异。\n\n\n **L249** 证明仅凭地位的政策完成了这一确切、具有表述且报告在数学上准确的审查。\n\n\n **L250** 给输出政策提供同样已履行的审查,留下两个分别的额外选择规范结果。\n\n\n **L251** 计算仅凭地位与基于输出的优先权理由列表不同,尽管所选候选与审查相同。\n\n\n **L252** 把 statusOnlyFails 应用于实际地位政策的优先权理由,证明其未满足 AdditionalChoiceNorm。\n\n\n **L253** 对输出政策实际相关的输出理由使用 identityJustified,证明其满足 AdditionalChoiceNorm。\n\n\n **L255** 说明 generalGroundsNotChoice 的预定范围。对应声明涉及:将事实非蕴涵与独立政策层反例组合,表明所表示一般评估责任不推出额外选择规范。 该注释用于解释,不是证明前提。\n\n\n **L256** 说明 generalGroundsNotChoice 的预定范围。对应声明涉及:将事实非蕴涵与独立政策层反例组合,表明所表示一般评估责任不推出额外选择规范。 该注释用于解释,不是证明前提。\n\n\n **L257** 陈述经检查的结果 generalGroundsNotChoice。将事实非蕴涵与独立政策层反例组合,表明所表示一般评估责任不推出额外选择规范。\n\n\n **L258** 将原有具有表述且准确否定的地位评估保留为登记结果的一部分。\n\n\n **L259** 保留每个候选都满足的相同真实地位前提。\n\n\n **L260** 保留 identity 优先权为真、successor 优先权为假。\n\n\n **L261** 保留已展示的地位到优先权非蕴含。\n\n\n **L262** 保留仅凭地位的选择失败,再与更强的政策独立变化实例结合。\n\n\n **L263** 通过 PolicyIndependenceExample 纳入真实政策变化,而不停留于地位非蕴含。\n\n\n **L264** 把保留的地位非蕴含证明与 policyIndependenceExample 组合,使登记定理包含真实独立的优先权理由变化。\n\n\n **L266** 关闭命名空间 CoreReader.Choice;这不增加证明或前提。\n\n\n### `leanified/CoreReader/Engineering/Domain.lean`\n\n\n```lean\nimport Std\n\nnamespace CoreReader.Engineering\n\n/- This is a bounded engineering application model. Work units count explicit\noperations; they are not a universal exchange rate or empirical forecast. -/\ninductive Maintainer where\n | original | successor | agent\n deriving DecidableEq, Repr\ninductive Tool where\n | editor | compiler | contractRunner | migrationRunner\n deriving DecidableEq, Repr\ninductive Knowledge where\n | privateLayout | publicContract | changeGuide | migrationGuide\n deriving DecidableEq, Repr\ninductive Change where\n | addition | replacement | deletion | withdrawal | redrawing | migration\n | independent | coordinated | designRevision | other (name : String)\n deriving DecidableEq, Repr\ninductive Candidate where\n | presentSimple | evolvable | maximal\n deriving DecidableEq, Repr\ninductive Burden where\n | understanding | construction | diagnosis | verification | coordination\n | operation | migration\n deriving DecidableEq, Repr\n\ndef maintainers : List Maintainer := [.original, .successor, .agent]\ndef changes : List Change := [.addition, .replacement, .deletion, .withdrawal,\n .redrawing, .migration, .independent, .coordinated, .designRevision]\ndef burdens : List Burden := [.understanding, .construction, .diagnosis,\n .verification, .coordination, .operation, .migration]\n\nstructure Activity where\n participants : List Maintainer\n software : String\n tools : List Tool\n available : Maintainer → List Knowledge\n scheduledReleases : Nat\n scheduledMaintenance : Nat\n boundedRuns : Option Nat\n label : String\n\n/-- organon-map CoreReader.Engineering.ActivityScope\nsoftware-engineering.purpose#p1 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.purpose#p2 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\n-/\nabbrev ActivityScope (a : Activity) : Prop :=\n a.participants ≠ [] ∧ a.software ≠ \"\" ∧ a.tools ≠ [] ∧\n a.participants.all (fun m => !(a.available m).isEmpty) = true\n\nabbrev Continuing (a : Activity) : Prop :=\n 0 < a.scheduledReleases ∧ 0 < a.scheduledMaintenance\n\nabbrev BoundedLifecycle (a : Activity) : Prop :=\n a.boundedRuns.isSome = true ∧ a.scheduledReleases = 0 ∧\n a.scheduledMaintenance = 0\n\ndef continuingActivity : Activity := {\n participants := maintainers, software := \"order-preserving queue\",\n tools := [.editor, .compiler, .contractRunner, .migrationRunner],\n available := fun m => match m with\n | .original => [.privateLayout, .publicContract, .changeGuide, .migrationGuide]\n | _ => [.publicContract, .changeGuide, .migrationGuide],\n scheduledReleases := 3, scheduledMaintenance := 6,\n boundedRuns := none, label := \"temporary\" }\n\ndef temporaryActivity : Activity := { continuingActivity with\n scheduledReleases := 0, scheduledMaintenance := 0, boundedRuns := some 1,\n label := \"one-shot import\" }\ndef prototypeActivity : Activity := { temporaryActivity with\n boundedRuns := some 4, label := \"bounded prototype\" }\ndef retiringActivity : Activity := { temporaryActivity with\n boundedRuns := some 2, label := \"retiring service\" }\n\nstructure EditStep where\n component : Nat\n requires : Knowledge\n tool : Tool\n units : Nat\n deriving DecidableEq, Repr\n\ndef changePath (c : Candidate) (d : Change) : List EditStep :=\n let guide := if c = .presentSimple then Knowledge.privateLayout else .changeGuide\n let base : List EditStep := [⟨0, guide, .editor, 1⟩,\n ⟨0, .publicContract, .contractRunner, 1⟩]\n match d with\n | .addition | .independent => base\n | .replacement | .deletion => base ++ [⟨1, guide, .compiler, 1⟩]\n | .coordinated => base ++ [⟨1, guide, .compiler, 3⟩, ⟨2, .publicContract, .contractRunner, 3⟩]\n | .migration => base ++ [⟨1, .migrationGuide, .migrationRunner, 8⟩]\n | .withdrawal | .redrawing | .designRevision =>\n if c = .presentSimple then base ++\n [⟨1, guide, .editor, 5⟩, ⟨2, guide, .compiler, 5⟩,\n ⟨2, .publicContract, .contractRunner, 5⟩]\n else base ++ [⟨1, guide, .editor, 2⟩, ⟨1, .publicContract, .contractRunner, 2⟩]\n | .other name =>\n if name = \"csv export\" then\n if c = .maximal then base ++ [⟨3, .migrationGuide, .compiler, 2⟩]\n else base ++ [⟨3, .privateLayout, .compiler, 20⟩]\n else []\n\ndef changeWork (c : Candidate) (d : Change) : Nat :=\n ((changePath c d).map EditStep.units).sum\n\nabbrev CanChange (a : Activity) (c : Candidate) (m : Maintainer) (d : Change) : Prop :=\n (changePath c d) ≠ [] ∧ m ∈ a.participants ∧ (changePath c d).all\n (fun step => (a.available m).contains step.requires && a.tools.contains step.tool) = true\n\nabbrev ContinuingCapability (a : Activity) (c : Candidate) (d : Change) : Prop :=\n (changePath c d) ≠ [] ∧ a.participants.all (fun m => (changePath c d).all\n (fun step => (a.available m).contains step.requires && a.tools.contains step.tool)) = true\n\n/- Maximal is maximal only on this explicitly registered finite set. The\nextra CSV direction has an actual documented compilation path and later state\ntransformation; unsupported names do not gain a capability from an empty path. -/\ndef registeredDirections : List Change := changes ++ [.other \"csv export\"]\ndef supportedDirections (a : Activity) (c : Candidate) : List Change :=\n registeredDirections.filter (fun d => decide (ContinuingCapability a c d))\nabbrev MaximumRegisteredCapability (a : Activity) (c : Candidate) : Prop :=\n registeredDirections.all (fun d => decide (ContinuingCapability a c d)) = true\n\n/- A software value here is a passive function: no intention is stored in it.\nAn engineering intention is an agent's selected set of changes. -/\ndef passiveArtifact (xs : List Nat) : List Nat := xs\n\ndef orientation : Maintainer → List Change := fun _ => [.designRevision, .migration]\n\ninductive EngineeringAction where\n | propose (direction : Change)\n | execute (result : List Nat)\n deriving DecidableEq, Repr\n\ndef maintainerActions (m : Maintainer) : List EngineeringAction :=\n (orientation m).map EngineeringAction.propose\n\ndef artifactActions (input : List Nat) : List EngineeringAction :=\n [.execute (passiveArtifact input)]\n\n/-- organon-map CoreReader.Engineering.subjectLifecycleCases\nsoftware-engineering.purpose#p1 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.purpose#p2 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\n-/\ntheorem subjectLifecycleCases :\n ActivityScope continuingActivity ∧\n CanChange continuingActivity .evolvable .successor .designRevision ∧\n CanChange continuingActivity .evolvable .agent .designRevision ∧\n continuingActivity.label = \"temporary\" ∧ Continuing continuingActivity ∧\n ¬ BoundedLifecycle continuingActivity ∧ BoundedLifecycle temporaryActivity ∧\n BoundedLifecycle prototypeActivity ∧ BoundedLifecycle retiringActivity := by decide\n\n/-- organon-map CoreReader.Engineering.subjectLimits\nsoftware-engineering.purpose#p1 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.purpose#p2 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\n-/\ntheorem subjectLimits :\n CanChange continuingActivity .presentSimple .original .designRevision ∧\n ¬ CanChange continuingActivity .presentSimple .successor .designRevision ∧\n ¬ ContinuingCapability continuingActivity .presentSimple .designRevision ∧\n continuingActivity.label = \"temporary\" ∧ ¬ BoundedLifecycle continuingActivity ∧\n orientation .agent ≠ [] ∧ passiveArtifact [2, 1] = [2, 1] ∧\n EngineeringAction.propose .designRevision ∈ maintainerActions .agent ∧\n EngineeringAction.propose .designRevision ∉ artifactActions [2, 1] := by decide\n\n/- Ground is intentionally parameterized: the examples below do not exhaust\npossible sources of credibility. The supplied support relation needs review. -/\n/-- organon-map CoreReader.Engineering.CredibleDirection\nsoftware-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\n-/\nabbrev CredibleDirection {Ground : Type} (grounds : List Ground)\n (articulated : Ground → Bool) (supports : Ground → Change → Bool)\n (d : Change) : Prop :=\n grounds.any (fun g => articulated g && supports g d) = true\n\ninductive DirectionGround where\n | plan (release : Nat) (committed : List Change)\n | knowledge (service : String) (affected : List Change) (mechanism : String)\n | history (service : String) (observed : List Change)\n | other (account : String) (supported : List Change)\n deriving DecidableEq, Repr\n\ndef articulateGround : DirectionGround → Bool\n | .plan release ds => release > 0 && !ds.isEmpty\n | .knowledge service ds mechanism => service != \"\" && !ds.isEmpty && mechanism != \"\"\n | .history service ds => service != \"\" && !ds.isEmpty\n | .other account ds => account != \"\" && !ds.isEmpty\n\ndef supportGround : DirectionGround → Change → Bool\n | .plan release ds, d => release > 0 && ds.contains d\n | .knowledge service ds mechanism, d =>\n service == \"queue\" && mechanism == \"tenant-config-reload\" && ds.contains d\n | .history service ds, d => service == \"queue\" && (ds.filter (· == d)).length >= 2\n | .other account ds, d => account == \"reviewed customer migration requirement\" && ds.contains d\n\nabbrev initialGrounds : List DirectionGround := [.plan 2 [.designRevision, .migration]]\ndef forecastGrounds : List DirectionGround := [.plan 3 [.deletion]]\nabbrev credible (gs : List DirectionGround) (d : Change) : Prop :=\n CredibleDirection gs articulateGround supportGround d\n\nabbrev WarrantedAccommodation (gs : List DirectionGround) (d : Change)\n (objectiveGain investment : Nat) : Prop :=\n credible gs d ∧ 0 < objectiveGain ∧ investment ≤ objectiveGain\n\n/-- organon-map CoreReader.Engineering.credibilityCases\nsoftware-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\n-/\ntheorem credibilityCases :\n credible initialGrounds .designRevision ∧\n credible [.knowledge \"queue\" [.designRevision] \"tenant-config-reload\"] .designRevision ∧\n credible [.history \"queue\" [.migration, .migration]] .migration ∧\n ¬ credible [] (.other \"quantum backend\") ∧\n credible forecastGrounds .deletion ∧ ¬ credible forecastGrounds .designRevision := by decide\n\ndef abstractionComplexity : Candidate → Nat\n | .presentSimple => 1 | .evolvable => 3 | .maximal => 30\n\ndef implementedVariants : List Candidate := [.presentSimple]\n\n/- No scalar conversion across burden dimensions is used by the priority rule. -/\nstructure CostVector where\n amount : Burden → Nat\nstructure CostLimits where\n capacity : Burden → Nat\n objective : Burden → String\n\ndef cost : Candidate → Burden → Nat\n | .presentSimple, _ => 1\n | .evolvable, .understanding => 3\n | .evolvable, .construction => 4\n | .evolvable, .diagnosis => 2\n | .evolvable, .verification => 4\n | .evolvable, .coordination => 2\n | .evolvable, .operation => 2\n | .evolvable, .migration => 8\n | .maximal, _ => 40\n\ndef normalLimits : CostLimits := {\n capacity := fun _ => 12,\n objective := fun b => match b with\n | .understanding => \"successor onboarding capacity\"\n | .construction => \"release construction capacity\"\n | .diagnosis => \"incident diagnosis window\"\n | .verification => \"release verification capacity\"\n | .coordination => \"available team coordination\"\n | .operation => \"runtime resource budget\"\n | .migration => \"retirement migration capacity\" }\n\nstructure Requirements where\n orderRequired : Bool\n maxUnsafeOperations : Nat\n maxLatency : Nat\n minRetention : Nat\n\ndef normalRequirements : Requirements := ⟨true, 0, 10, 30⟩\ndef behavior : Candidate → List Nat → List Nat := fun _ xs => xs.eraseDups\n\n/- Candidate profiles are observations in this bounded scenario. Modified\nprofiles below test all four independent necessary-requirement gates. -/\nstructure CandidateProfile where\n orderOutput : List Nat\n unsafeOperations : Nat\n latency : Nat\n retention : Nat\n\ndef profile (c : Candidate) : CandidateProfile := ⟨behavior c [2, 1, 2], 0, 5, 30⟩\nabbrev Meets (r : Requirements) (p : CandidateProfile) : Prop :=\n (r.orderRequired = true → p.orderOutput = [2, 1]) ∧\n p.unsafeOperations ≤ r.maxUnsafeOperations ∧ p.latency ≤ r.maxLatency ∧\n r.minRetention ≤ p.retention\n\nstructure Context where\n activity : Activity\n required : Requirements\n evidence : List DirectionGround\n limits : CostLimits\n departure : Option Burden\n profiles : Candidate → CandidateProfile := profile\n\ndef currentContinuing : Context := {\n activity := continuingActivity, required := normalRequirements,\n evidence := initialGrounds, limits := normalLimits, departure := none }\n\nabbrev ConcreteThreat (ctx : Context) (c : Candidate) (b : Burden) : Prop :=\n cost .presentSimple b < cost c b ∧ ctx.limits.capacity b < cost c b ∧\n ctx.limits.objective b ≠ \"\"\n\nabbrev HasThreat (ctx : Context) (c : Candidate) : Prop :=\n burdens.any (fun b => decide (ConcreteThreat ctx c b)) = true\n\n/-- organon-map CoreReader.Engineering.JustifiedDeparture\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\n-/\nabbrev JustifiedDeparture (ctx : Context) (c : Candidate) : Prop :=\n match ctx.departure with\n | none => False\n | some b => ConcreteThreat ctx c b\n\ninstance (ctx : Context) (c : Candidate) : Decidable (JustifiedDeparture ctx c) := by\n unfold JustifiedDeparture\n split <;> infer_instance\n\nabbrev PriorityConditions (ctx : Context) : Prop :=\n Continuing ctx.activity ∧ ActivityScope ctx.activity ∧\n Meets ctx.required (ctx.profiles .presentSimple) ∧ Meets ctx.required (ctx.profiles .evolvable) ∧\n credible ctx.evidence .designRevision ∧\n ContinuingCapability ctx.activity .evolvable .designRevision ∧\n changeWork .evolvable .designRevision < changeWork .presentSimple .designRevision ∧\n abstractionComplexity .presentSimple < abstractionComplexity .evolvable\n\n/-- organon-map CoreReader.Engineering.EvolutionPriority\nsoftware-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\n-/\nabbrev EvolutionPriority (ctx : Context) (chosen : Candidate) : Prop :=\n PriorityConditions ctx → chosen = .evolvable ∨ JustifiedDeparture ctx .evolvable\n\ntheorem currentPriorityConditions : PriorityConditions currentContinuing := by decide\ntheorem currentNoThreat : ¬ HasThreat currentContinuing .evolvable ∧\n ¬ JustifiedDeparture currentContinuing .evolvable := by decide\n\ndef threatened (b : Burden) : Context := { currentContinuing with\n limits := { normalLimits with capacity := fun x => if x = b then 1 else 12 },\n departure := some b }\n\n/-- organon-map CoreReader.Engineering.priorityWhenApplicable\nsoftware-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\n-/\ntheorem priorityWhenApplicable (ctx : Context) (chosen : Candidate)\n (rule : EvolutionPriority ctx chosen) (applicable : PriorityConditions ctx)\n (noDeparture : ¬ JustifiedDeparture ctx .evolvable) :\n chosen = .evolvable ∧\n abstractionComplexity .presentSimple < abstractionComplexity chosen := by\n have hc := (rule applicable).resolve_right noDeparture\n exact ⟨hc, hc ▸ applicable.2.2.2.2.2.2.2⟩\n\ntheorem currentSimpleViolates : ¬ EvolutionPriority currentContinuing .presentSimple := by\n intro h\n have bad := (h currentPriorityConditions).resolve_right currentNoThreat.2\n cases bad\n\ndef withEvolvableProfile (p : CandidateProfile) : Context := { currentContinuing with\n profiles := fun c => if c = .evolvable then p else profile c }\n\ntheorem unmetRequirementsBlockPriority :\n ¬ PriorityConditions (withEvolvableProfile { profile .evolvable with orderOutput := [1, 2] }) ∧\n ¬ PriorityConditions (withEvolvableProfile { profile .evolvable with unsafeOperations := 1 }) ∧\n ¬ PriorityConditions (withEvolvableProfile { profile .evolvable with latency := 11 }) ∧\n ¬ PriorityConditions (withEvolvableProfile { profile .evolvable with retention := 29 }) := by\n simp [PriorityConditions, withEvolvableProfile, currentContinuing, Meets,\n normalRequirements]\n\n/-- organon-map CoreReader.Engineering.priorityConditionsCases\nsoftware-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\n-/\ntheorem priorityConditionsCases :\n EvolutionPriority currentContinuing .evolvable ∧\n ¬ Meets normalRequirements { profile .evolvable with orderOutput := [1, 2] } ∧\n ¬ Meets normalRequirements { profile .evolvable with unsafeOperations := 1 } ∧\n ¬ Meets normalRequirements { profile .evolvable with latency := 11 } ∧\n ¬ Meets normalRequirements { profile .evolvable with retention := 29 } ∧\n EvolutionPriority (threatened .verification) .presentSimple ∧\n ¬ JustifiedDeparture { threatened .verification with departure := none } .evolvable ∧\n abstractionComplexity .evolvable < abstractionComplexity .maximal := by\n refine ⟨by decide, by decide, by decide, by decide, by decide, by decide, ?_, by decide⟩\n simp [JustifiedDeparture]\n\n/-- organon-map CoreReader.Engineering.priorityChoices\nsoftware-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\n-/\ntheorem priorityChoices :\n EvolutionPriority currentContinuing .evolvable ∧\n ¬ EvolutionPriority currentContinuing .presentSimple ∧\n EvolutionPriority (threatened .verification) .presentSimple := by\n exact ⟨by decide, currentSimpleViolates, by decide⟩\n\n/-- organon-map CoreReader.Engineering.credibilityLimits\nsoftware-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\n-/\ntheorem credibilityLimits :\n credible initialGrounds .designRevision ∧ implementedVariants.length = 1 ∧\n ¬ WarrantedAccommodation [] (.other \"quantum backend\") 0 5 ∧\n ¬ credible initialGrounds (.other \"quantum backend\") ∧\n EvolutionPriority currentContinuing .evolvable ∧\n abstractionComplexity .evolvable < abstractionComplexity .maximal ∧\n cost .evolvable .construction < cost .evolvable .migration ∧\n ¬ MaximumRegisteredCapability continuingActivity .evolvable ∧\n MaximumRegisteredCapability continuingActivity .maximal ∧\n (supportedDirections continuingActivity .evolvable).length = 9 ∧\n (supportedDirections continuingActivity .maximal).length = 10 ∧\n ¬ credible initialGrounds (.other \"csv export\") := by decide\n\n/-- organon-map CoreReader.Engineering.costCases\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\n-/\ntheorem costCases :\n JustifiedDeparture (threatened .understanding) .evolvable ∧\n JustifiedDeparture (threatened .construction) .evolvable ∧\n JustifiedDeparture (threatened .diagnosis) .evolvable ∧\n JustifiedDeparture (threatened .verification) .evolvable ∧\n JustifiedDeparture (threatened .coordination) .evolvable ∧\n JustifiedDeparture (threatened .operation) .evolvable ∧\n JustifiedDeparture (threatened .migration) .evolvable ∧\n ¬ JustifiedDeparture { currentContinuing with departure := some .migration } .evolvable := by decide\n\n/- Total functions model an identified order-preserving de-duplication API.\nThe test corpus is explicitly finite; universal preservation is separate. -/\ndef orderedUnique (xs : List Nat) : List Nat := xs.eraseDups\ndef orderedRefactor (xs : List Nat) : List Nat := xs.eraseDups ++ []\ndef insertOrdered (n : Nat) : List Nat → List Nat\n | [] => [n]\n | x :: xs => if n ≤ x then n :: x :: xs else x :: insertOrdered n xs\n\ndef sortValues : List Nat → List Nat\n | [] => []\n | x :: xs => insertOrdered x (sortValues xs)\n\ndef sortedUnique (xs : List Nat) : List Nat := (sortValues xs).eraseDups\n\nstructure SoftwareState where\n capabilities : List String\n implementation : Nat\n mechanisms : List String\n abstractions : List String\n boundary : Nat\n technology : String\n batchSize : Nat\n deriving DecidableEq, Repr\n\ndef originalSoftware : SoftwareState :=\n ⟨[\"deduplicate\"], 0, [\"queue\", \"legacy cache\"], [\"fixed batch\"], 0, \"legacy store\", 10⟩\n\ndef transform (d : Change) (s : SoftwareState) : SoftwareState := match d with\n | .addition => { s with capabilities := s.capabilities ++ [\"tenant batching\"] }\n | .replacement => { s with implementation := s.implementation + 1 }\n | .deletion => { s with mechanisms := s.mechanisms.filter (· != \"legacy cache\") }\n | .withdrawal => { s with abstractions := s.abstractions.filter (· != \"fixed batch\") }\n | .redrawing => { s with boundary := s.boundary + 1 }\n | .migration => { s with technology := \"portable store\" }\n | .independent => { s with batchSize := 5 }\n | .coordinated => { s with batchSize := 5, boundary := s.boundary + 1 }\n | .designRevision => { s with batchSize := 5, abstractions := [\"live configuration\"], boundary := s.boundary + 1 }\n | .other name =>\n if name = \"csv export\" then { s with capabilities := s.capabilities ++ [\"csv export\"] }\n else s\n\ndef evolutionBehavior (d : Change) : List Nat → List Nat :=\n if d = .redrawing ∨ d = .designRevision then sortedUnique else orderedUnique\n\n/- Changes include an open other constructor. Work, maintainer knowledge and\nobligation treatment are separate dimensions, not one extensibility score. -/\ninductive ObligationTreatment where\n | preserve | revise\n deriving DecidableEq, Repr\nstructure ChangeClaim where\n direction : Change\n byMaintainer : Maintainer\n treatment : ObligationTreatment\n\nabbrev contractInputs : List (List Nat) := [[], [2, 1, 2], [1, 3, 1], [4, 4]]\ndef PreservesOn {Input Output : Type} (scope : Input → Prop)\n (old new : Input → Output) : Prop := ∀ x, scope x → new x = old x\n\nabbrev PreservesFinite (old new : List Nat → List Nat) : Prop :=\n contractInputs.all (fun xs => new xs == old xs) = true\n\n/- The actual contracts and observer dependencies are inputs independent of\nany revision report. Reports cannot redefine the affected population or the\nold/new retry behavior merely by changing their own fields. -/\nstructure ObservableContract where\n order : List Nat → List Nat\n maxAttempts : Nat\n\ndef retry (contract : ObservableContract) (attempts : Nat) : Bool :=\n attempts < contract.maxAttempts\n\ndef orderContract (order : List Nat → List Nat) : ObservableContract := ⟨order, 3⟩\ndef originalContract : ObservableContract := orderContract orderedUnique\ndef refactoredContract : ObservableContract := orderContract orderedRefactor\ndef revisedContract : ObservableContract := ⟨sortedUnique, 5⟩\ndef evolutionContract (d : Change) : ObservableContract :=\n ⟨evolutionBehavior d, if d = .redrawing ∨ d = .designRevision then 5 else 3⟩\n\ndef failureInputs : List Nat := [0, 1, 2, 3, 4, 5]\nabbrev PreservesContractFinite (old new : ObservableContract) : Prop :=\n PreservesFinite old.order new.order ∧\n failureInputs.all (fun attempts => retry new attempts == retry old attempts) = true\n\ninductive ContractAspect where\n | order | retry\n deriving DecidableEq, Repr\nstructure PartyDependency where\n party : String\n observes : ContractAspect\n deriving DecidableEq, Repr\n\ndef partyDependencies : List PartyDependency :=\n [⟨\"queue consumer\", .order⟩, ⟨\"queue operator\", .retry⟩]\n\ndef aspectChanged (old new : ObservableContract) : ContractAspect → Bool\n | .order => contractInputs.any (fun xs => new.order xs != old.order xs)\n | .retry => failureInputs.any (fun attempts => retry new attempts != retry old attempts)\n\ndef affectedParties (old new : ObservableContract) : List String :=\n (partyDependencies.filter (fun dependency => aspectChanged old new dependency.observes)).map\n PartyDependency.party\n\nstructure ContractRevision where\n deliberate : Bool\n revisedOrder : List Nat\n affected : List String\n oldFailureLimit : Nat\n newFailureLimit : Nat\n recordedOldFailureLimit : Nat\n recordedNewFailureLimit : Nat\n procedure : String\n\ndef normalRevision : ContractRevision := {\n deliberate := true, revisedOrder := [1, 2],\n affected := [\"queue consumer\", \"queue operator\"],\n oldFailureLimit := 3, newFailureLimit := 5,\n recordedOldFailureLimit := 3, recordedNewFailureLimit := 5,\n procedure := \"contract review\" }\n\nabbrev RevisionDuties (old new : ObservableContract) (r : ContractRevision) : Prop :=\n r.deliberate = true ∧ r.revisedOrder = new.order [2, 1, 2] ∧\n (affectedParties old new).all (fun p => r.affected.contains p) = true ∧\n r.oldFailureLimit = old.maxAttempts ∧ r.newFailureLimit = new.maxAttempts ∧\n r.recordedOldFailureLimit = old.maxAttempts ∧\n r.recordedNewFailureLimit = new.maxAttempts\n\n/-- organon-map CoreReader.Engineering.ContractChangeAccount\nsoftware-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\n-/\nabbrev ContractChangeAccount (old new : ObservableContract) (r : ContractRevision) : Prop :=\n PreservesContractFinite old new ∨ RevisionDuties old new r\n\n/-- organon-map CoreReader.Engineering.EvolutionClaim\nsoftware-engineering.evolution-meaning#p1 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6\nsoftware-engineering.evolution-meaning#p2 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6\n-/\nabbrev EvolutionClaim (a : Activity) (c : Candidate) (claim : ChangeClaim) : Prop :=\n CanChange a c claim.byMaintainer claim.direction ∧\n ContractChangeAccount originalContract (evolutionContract claim.direction) normalRevision ∧\n (changePath c claim.direction).any (fun step => step.tool == .contractRunner) = true ∧\n ((claim.treatment = .preserve ∧\n evolutionBehavior claim.direction [2, 1, 2] = orderedUnique [2, 1, 2]) ∨\n (claim.treatment = .revise ∧\n evolutionBehavior claim.direction [2, 1, 2] ≠ orderedUnique [2, 1, 2]))\n\n/-- organon-map CoreReader.Engineering.evolutionKindsCases\nsoftware-engineering.evolution-meaning#p1 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6\nsoftware-engineering.evolution-meaning#p2 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6\n-/\ntheorem evolutionKindsCases :\n (transform .addition originalSoftware).capabilities = [\"deduplicate\", \"tenant batching\"] ∧\n (transform .replacement originalSoftware).implementation = 1 ∧\n (transform .deletion originalSoftware).mechanisms = [\"queue\"] ∧\n (transform .withdrawal originalSoftware).abstractions = [] ∧\n (transform .redrawing originalSoftware).boundary = 1 ∧\n (transform .migration originalSoftware).technology = \"portable store\" ∧\n changes.all (fun d => decide (CanChange continuingActivity .evolvable .successor d)) = true ∧\n EvolutionClaim continuingActivity .evolvable ⟨.replacement, .successor, .preserve⟩ ∧\n EvolutionClaim continuingActivity .evolvable ⟨.redrawing, .agent, .revise⟩ ∧\n changeWork .evolvable .independent < changeWork .evolvable .coordinated := by decide\n\n/-- organon-map CoreReader.Engineering.evolutionDimensionsLimits\nsoftware-engineering.evolution-meaning#p1 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6\nsoftware-engineering.evolution-meaning#p2 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6\n-/\ntheorem evolutionDimensionsLimits :\n changeWork .presentSimple .addition = 2 ∧\n changeWork .presentSimple .withdrawal = 17 ∧\n changeWork .evolvable .independent < changeWork .evolvable .coordinated ∧\n EvolutionPriority currentContinuing .evolvable ∧\n 9 < changeWork .evolvable .migration ∧\n CanChange continuingActivity .presentSimple .original .addition ∧\n CanChange continuingActivity .evolvable .original .addition ∧\n CanChange continuingActivity .presentSimple .original .designRevision ∧\n CanChange continuingActivity .evolvable .original .designRevision ∧\n changeWork .evolvable .designRevision < changeWork .presentSimple .designRevision ∧\n changeWork .evolvable .addition = changeWork .presentSimple .addition ∧\n (transform (.other \"csv export\") originalSoftware).capabilities = [\"deduplicate\", \"csv export\"] ∧\n CanChange continuingActivity .maximal .successor (.other \"csv export\") ∧\n ¬ CanChange continuingActivity .evolvable .successor (.other \"csv export\") := by\n exact ⟨by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide⟩\n\ntheorem oneDimensionDoesNotEntailEveryDimension :\n changeWork .evolvable .designRevision < changeWork .presentSimple .designRevision ∧\n ¬ (∀ d : Change, changeWork .evolvable d < changeWork .presentSimple d) := by\n refine ⟨by decide, ?_⟩\n intro allDirections\n exact (by decide : ¬ changeWork .evolvable .addition < changeWork .presentSimple .addition)\n (allDirections .addition)\n\ndef propagation (c : Candidate) (d : Change) : List Nat :=\n ((changePath c d).map EditStep.component).eraseDups\n\ndef batchCount (items size : Nat) : Nat := (items + size - 1) / size\ndef staticBatch (items _runtimeSize : Nat) : Nat := batchCount items 10\ndef liveBatch (items runtimeSize : Nat) : Nat := batchCount items runtimeSize\n\nstructure StructuralEvidence where\n intended : Change\n participants : List Maintainer\n touched : List Nat\n contractObservations : List (List Nat)\n observedBefore : List (List Nat)\n observedAfter : List (List Nat)\n understandingWork : Nat\n verificationWork : Nat\n boundaryGain : Nat\n\ndef structuralEvidence (c : Candidate) (d : Change) : StructuralEvidence := {\n intended := d, participants := maintainers, touched := propagation c d,\n contractObservations := contractInputs,\n observedBefore := contractInputs.map orderedUnique,\n observedAfter := contractInputs.map (evolutionBehavior d),\n understandingWork := changeWork c d,\n verificationWork := ((changePath c d).filter (fun step => step.tool == .contractRunner)).length,\n boundaryGain := changeWork .presentSimple d - changeWork c d }\n\n/-- organon-map CoreReader.Engineering.StructuralAccount\nsoftware-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\nsoftware-engineering.structural-judgment#p2 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\n-/\nabbrev StructuralAccount (a : Activity) (c : Candidate) (e : StructuralEvidence) : Prop :=\n e.participants = a.participants ∧ e.touched = propagation c e.intended ∧\n e.contractObservations = contractInputs ∧\n e.observedBefore = contractInputs.map orderedUnique ∧\n e.observedAfter = contractInputs.map (evolutionBehavior e.intended) ∧\n e.understandingWork = changeWork c e.intended ∧\n e.verificationWork = ((changePath c e.intended).filter\n (fun step => step.tool == .contractRunner)).length ∧\n e.boundaryGain = changeWork .presentSimple e.intended - changeWork c e.intended\n\nstructure InterfaceView where\n signature : String\n modules : Nat\n extensionPoints : Nat\n principle : String\n deriving DecidableEq, Repr\n\ndef sameShape : InterfaceView := ⟨\"List Nat → List Nat\", 8, 12, \"dependency inversion\"⟩\ndef moduleAssumptions : List (Nat × Nat) :=\n (List.range 8).map (fun component => (component, 10))\n\ndef modulesNeedingRevision (newSize : Nat) : List Nat :=\n (moduleAssumptions.filter (fun p => p.2 != newSize)).map Prod.fst\n\nstructure Boundary where\n caller : Nat\n callee : Nat\n contract : String\n deriving DecidableEq, Repr\n\nstructure EngineeringDesign where\n metadata : InterfaceView\n run : List Nat → List Nat\n paths : Change → List EditStep\n components : List Nat\n boundaries : List Boundary\n batchAssumptions : List (Nat × Nat)\n\ndef privateDesign : EngineeringDesign := {\n metadata := sameShape, run := orderedUnique, paths := changePath .presentSimple,\n components := List.range 8, boundaries := [], batchAssumptions := moduleAssumptions }\n\ndef documentedDesign : EngineeringDesign := {\n privateDesign with paths := changePath .evolvable }\n\ndef sortedDesign : EngineeringDesign := { documentedDesign with run := sortedUnique }\n\n/- This application has a caller at component 2 and a callee at component 1.\nEditing the callee crosses that actual edge. The caller must recheck the\nobservable order contract in this finite case; the contract name alone is not\nevidence that either the verification work or the observable equality holds. -/\ndef coordinatedBoundary : Boundary := ⟨2, 1, \"order-preserving queue\"⟩\n\ndef boundaryDesign : EngineeringDesign :=\n { documentedDesign with boundaries := [coordinatedBoundary] }\n\ndef crossesBoundary (design : EngineeringDesign) (direction : Change) (edge : Boundary) : Bool :=\n design.boundaries.contains edge && design.components.contains edge.caller &&\n design.components.contains edge.callee && edge.caller != edge.callee &&\n (design.paths direction).any (fun step => step.component == edge.callee &&\n (step.tool == .editor || step.tool == .compiler))\n\ndef boundaryObligationChecked (design : EngineeringDesign) (direction : Change)\n (edge : Boundary) : Bool :=\n crossesBoundary design direction edge &&\n (design.paths direction).any (fun step => step.component == edge.caller &&\n step.tool == .contractRunner && step.requires == .publicContract) &&\n decide (PreservesFinite orderedUnique design.run)\n\ndef omittedCallerCheck : EngineeringDesign :=\n { boundaryDesign with paths := fun direction =>\n (boundaryDesign.paths direction).filter (fun step =>\n !(step.component == coordinatedBoundary.caller && step.tool == .contractRunner)) }\n\ndef otherCalleeBoundary : Boundary := { coordinatedBoundary with callee := 7 }\n\ndef otherCalleeDesign : EngineeringDesign :=\n { boundaryDesign with boundaries := [otherCalleeBoundary] }\n\ntheorem actualCrossBoundaryObligation :\n crossesBoundary boundaryDesign .coordinated coordinatedBoundary = true ∧\n boundaryObligationChecked boundaryDesign .coordinated coordinatedBoundary = true ∧\n crossesBoundary omittedCallerCheck .coordinated coordinatedBoundary = true ∧\n boundaryObligationChecked omittedCallerCheck .coordinated coordinatedBoundary = false ∧\n crossesBoundary otherCalleeDesign .coordinated otherCalleeBoundary = false ∧\n boundaryObligationChecked { boundaryDesign with run := sortedUnique }\n .coordinated coordinatedBoundary = false := by decide\n\n/-- organon-map CoreReader.Engineering.structuralCases\nsoftware-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\nsoftware-engineering.structural-judgment#p2 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\n-/\ntheorem structuralCases :\n StructuralAccount continuingActivity .evolvable (structuralEvidence .evolvable .designRevision) ∧\n (propagation .presentSimple .designRevision).length = 3 ∧\n (propagation .evolvable .designRevision).length = 2 ∧\n (changePath .evolvable .coordinated).any (fun s => s.component == 2 && s.requires == .publicContract) = true ∧\n PreservesFinite orderedUnique orderedRefactor ∧\n (structuralEvidence .evolvable .designRevision).observedBefore ≠\n (structuralEvidence .evolvable .designRevision).observedAfter ∧\n staticBatch 21 10 = liveBatch 21 10 ∧ staticBatch 21 5 ≠ liveBatch 21 5 ∧\n changeWork .presentSimple .withdrawal = 17 ∧\n (crossesBoundary boundaryDesign .coordinated coordinatedBoundary = true ∧\n boundaryObligationChecked boundaryDesign .coordinated coordinatedBoundary = true ∧\n crossesBoundary omittedCallerCheck .coordinated coordinatedBoundary = true ∧\n boundaryObligationChecked omittedCallerCheck .coordinated coordinatedBoundary = false ∧\n crossesBoundary otherCalleeDesign .coordinated otherCalleeBoundary = false ∧\n boundaryObligationChecked { boundaryDesign with run := sortedUnique }\n .coordinated coordinatedBoundary = false) := by decide\n\nabbrev DesignCanChange (a : Activity) (design : EngineeringDesign)\n (m : Maintainer) (d : Change) : Prop :=\n design.paths d ≠ [] ∧ m ∈ a.participants ∧\n (design.paths d).all (fun step =>\n (a.available m).contains step.requires && a.tools.contains step.tool) = true\n\ndef designWork (design : EngineeringDesign) (d : Change) : Nat :=\n ((design.paths d).map EditStep.units).sum\n\ndef designModulesNeedingRevision (design : EngineeringDesign) (newSize : Nat) : List Nat :=\n (design.batchAssumptions.filter (fun p => p.2 != newSize)).map Prod.fst\n\n/- In this finite model, a facade adds an actual component, forwarding edge\nand contract verification step. It preserves observable order but does not\nremove the original edit/compilation work or supply private maintainer knowledge. -/\ndef introduceBoundary (design : EngineeringDesign) : EngineeringDesign := {\n metadata := { design.metadata with modules := design.metadata.modules + 1, extensionPoints := design.metadata.extensionPoints + 1 },\n run := fun xs => design.run (xs ++ []),\n paths := fun d => if (design.paths d).isEmpty then [] else\n design.paths d ++ [⟨design.components.length, .publicContract, .contractRunner, 1⟩],\n components := design.components ++ [design.components.length],\n boundaries := design.boundaries ++\n [⟨design.components.length, 0, design.metadata.signature⟩],\n batchAssumptions := design.batchAssumptions }\n\ndef wrappedDesign : EngineeringDesign := introduceBoundary privateDesign\n\n/- This second facade relocates the existing contract-verification work to\nthe new component. It changes the actual boundary and step locations without\nreducing the work or making the private edit knowledge public. -/\ndef relocateVerification (design : EngineeringDesign) : EngineeringDesign := {\n introduceBoundary design with\n paths := fun d => (design.paths d).map (fun step =>\n if step.tool = .contractRunner then { step with component := design.components.length }\n else step) }\n\ndef sameWorkDesign : EngineeringDesign := relocateVerification privateDesign\n\n/-- organon-map CoreReader.Engineering.structureNotCapability\nsoftware-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\nsoftware-engineering.structural-judgment#p2 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\n-/\ntheorem structureNotCapability :\n (privateDesign.metadata.signature = sortedDesign.metadata.signature ∧\n privateDesign.run [2, 1, 2] = [2, 1] ∧ sortedDesign.run [2, 1, 2] ≠ [2, 1]) ∧\n (privateDesign.metadata.modules = privateDesign.components.length ∧\n privateDesign.batchAssumptions.length = 8 ∧\n (designModulesNeedingRevision privateDesign 5).length = 8) ∧\n (privateDesign.metadata.principle = \"dependency inversion\" ∧\n privateDesign.metadata = documentedDesign.metadata ∧\n ¬ DesignCanChange continuingActivity privateDesign .successor .designRevision ∧\n DesignCanChange continuingActivity documentedDesign .successor .designRevision) ∧\n (privateDesign.boundaries.length = 0 ∧ wrappedDesign.boundaries.length = 1 ∧\n wrappedDesign.components.length = 9 ∧\n wrappedDesign.boundaries = [⟨8, 0, \"List Nat → List Nat\"⟩] ∧\n wrappedDesign.run [2, 1, 2] = privateDesign.run [2, 1, 2] ∧\n designWork privateDesign .designRevision = 17 ∧\n designWork wrappedDesign .designRevision = 18 ∧\n ¬ designWork wrappedDesign .designRevision < designWork privateDesign .designRevision) ∧\n (sameWorkDesign.boundaries = [⟨8, 0, \"List Nat → List Nat\"⟩] ∧\n sameWorkDesign.components.length = 9 ∧\n sameWorkDesign.paths .designRevision ≠ privateDesign.paths .designRevision ∧\n sameWorkDesign.run [2, 1, 2] = privateDesign.run [2, 1, 2] ∧\n designWork sameWorkDesign .designRevision = designWork privateDesign .designRevision ∧\n designWork sameWorkDesign .designRevision = 17 ∧\n ¬ DesignCanChange continuingActivity sameWorkDesign .successor .designRevision) := by\n exact ⟨by decide, by decide, by decide, by decide, by decide⟩\n\n/-- organon-map CoreReader.Engineering.contractPreservation\nsoftware-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\n-/\ntheorem contractPreservation {Input Output : Type} (scope : Input → Prop)\n (old new : Input → Output) (observations : ∀ x, scope x → new x = old x) :\n PreservesOn scope old new := observations\n\ntheorem changedObservationNotPreserved {Input Output : Type} (scope : Input → Prop)\n (old new : Input → Output) (x : Input) (inside : scope x)\n (different : new x ≠ old x) : ¬ PreservesOn scope old new := by\n intro h\n exact different (h x inside)\n\ntheorem contractRevisionObligations (old new : ObservableContract)\n (r : ContractRevision) (account : ContractChangeAccount old new r)\n (changed : ¬ PreservesContractFinite old new) :\n RevisionDuties old new r := account.resolve_left changed\n\ndef retiredBehavior (xs : List Nat) : List Nat :=\n if xs = [99] then [] else orderedUnique xs\n\n/-- organon-map CoreReader.Engineering.contractCases\nsoftware-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\n-/\ntheorem contractCases :\n ContractChangeAccount originalContract refactoredContract normalRevision ∧\n ContractChangeAccount originalContract revisedContract normalRevision ∧\n ¬ ContractChangeAccount originalContract revisedContract { normalRevision with affected := [] } ∧\n PreservesFinite orderedUnique retiredBehavior ∧ retiredBehavior [99] ≠ orderedUnique [99] ∧\n ContractChangeAccount originalContract revisedContract { normalRevision with procedure := \"paired audit\" } := by decide\n\n/-- organon-map CoreReader.Engineering.contractDistinctions\nsoftware-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\n-/\ntheorem contractDistinctions :\n PreservesFinite orderedUnique orderedRefactor ∧\n ¬ PreservesFinite orderedUnique sortedUnique ∧\n retry originalContract 3 = false ∧ retry revisedContract 3 = true ∧\n ¬ PreservesContractFinite originalContract revisedContract ∧\n affectedParties originalContract revisedContract = [\"queue consumer\", \"queue operator\"] ∧\n ¬ ContractChangeAccount originalContract revisedContract\n { normalRevision with affected := [\"queue consumer\"] } ∧\n ¬ ContractChangeAccount originalContract revisedContract\n { normalRevision with oldFailureLimit := 5, recordedOldFailureLimit := 5 } ∧\n ContractChangeAccount originalContract revisedContract normalRevision ∧\n PreservesFinite orderedUnique retiredBehavior ∧ retiredBehavior [99] ≠ orderedUnique [99] := by decide\n\n/- Revision records time-indexed evidence rather than changing a past event.\nJudgment is choice under current evidence; forecast truth is a separate value. -/\nstructure RevisionState where\n time : Nat\n forecast : List Change\n maintenance : Nat\n maintainers : List Maintainer\n migrationCost : Nat\n objectiveCapacity : Nat\n choice : Candidate\n deriving DecidableEq, Repr\nstructure RevisionRecord where\n software : String\n old : RevisionState\n current : RevisionState\n recordedOld : RevisionState\n recordedCurrent : RevisionState\n predictedBatchCount : Nat\n actualBatchCount : Nat\n reportedPredictionSucceeded : Bool\n consideredChanges : List Change\n criticizedDirections : List Change\n\nabbrev MaterialGroundsChanged (old current : RevisionState) : Prop :=\n old.forecast ≠ current.forecast ∨ old.maintenance ≠ current.maintenance ∨\n old.maintainers ≠ current.maintainers ∨\n old.migrationCost ≠ current.migrationCost ∨ old.objectiveCapacity ≠ current.objectiveCapacity\n\ndef oldState : RevisionState := ⟨0, [.designRevision], 6, [.original], 8, 12, .evolvable⟩\ndef newState : RevisionState := ⟨1, [.deletion], 2, [.successor, .agent], 14, 10, .presentSimple⟩\n\nstructure HistoricalEvidence where\n software : String\n state : RevisionState\n predictedBatchCount : Nat\n actualBatchCount : Nat\n\n/- Independent event content: the recorded predictor used a fixed batch size\nof ten; the actual event had runtime size five and twenty-one queue items. -/\ndef observedHistory : HistoricalEvidence :=\n ⟨\"order-preserving queue\", oldState, staticBatch 21 5, liveBatch 21 5⟩\n\nabbrev RevisionAccountAgainst (history : HistoricalEvidence) (r : RevisionRecord) : Prop :=\n r.software = history.software ∧\n r.old = history.state ∧ r.recordedOld = history.state ∧\n r.predictedBatchCount = history.predictedBatchCount ∧\n r.actualBatchCount = history.actualBatchCount ∧\n r.old.time < r.current.time ∧ r.recordedCurrent = r.current ∧\n (r.old.choice ≠ r.current.choice → MaterialGroundsChanged r.old r.current) ∧\n r.reportedPredictionSucceeded = decide (history.predictedBatchCount = history.actualBatchCount) ∧\n r.consideredChanges.all (fun d => r.criticizedDirections.contains d) = true\n\n/-- organon-map CoreReader.Engineering.RevisionAccount\nsoftware-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99\nsoftware-engineering.revision#p1 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99\n-/\nabbrev RevisionAccount (r : RevisionRecord) : Prop := RevisionAccountAgainst observedHistory r\n\ntheorem failedHistoryNotRewritten (history : HistoricalEvidence) (r : RevisionRecord)\n (account : RevisionAccountAgainst history r)\n (failed : history.predictedBatchCount ≠ history.actualBatchCount) :\n r.reportedPredictionSucceeded = false := by\n simpa [failed] using account.2.2.2.2.2.2.2.2.1\n\ndef revisionRecord : RevisionRecord := {\n software := \"order-preserving queue\",\n old := oldState, current := newState, recordedOld := oldState, recordedCurrent := newState,\n predictedBatchCount := staticBatch 21 5, actualBatchCount := liveBatch 21 5,\n reportedPredictionSucceeded := false,\n consideredChanges := changes, criticizedDirections := changes }\n\nabbrev SupportedAlternative (gs : List DirectionGround) (d : Change) : Prop := credible gs d\n\nabbrev RetentionJustified (ctx : Context) (alternatives : List Change) : Prop :=\n alternatives.all (fun d => !decide (SupportedAlternative ctx.evidence d)) = true ∨\n JustifiedDeparture ctx .evolvable\n\ndef stableRecord : RevisionRecord := { revisionRecord with\n current := { newState with choice := .evolvable },\n recordedCurrent := { newState with choice := .evolvable } }\n\n/-- organon-map CoreReader.Engineering.revisionCases\nsoftware-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99\nsoftware-engineering.revision#p1 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99\n-/\ntheorem revisionCases :\n RevisionAccount revisionRecord ∧\n revisionRecord.old.forecast ≠ revisionRecord.current.forecast ∧\n revisionRecord.old.maintenance ≠ revisionRecord.current.maintenance ∧\n revisionRecord.old.maintainers ≠ revisionRecord.current.maintainers ∧\n revisionRecord.old.migrationCost ≠ revisionRecord.current.migrationCost ∧\n revisionRecord.old.objectiveCapacity ≠ revisionRecord.current.objectiveCapacity ∧\n revisionRecord.predictedBatchCount ≠ revisionRecord.actualBatchCount ∧\n RetentionJustified currentContinuing [.other \"quantum backend\"] ∧\n RetentionJustified (threatened .migration) [.migration] := by decide\n\ndef observations : List (Nat × Nat) := [(21, 10), (30, 10), (40, 10)]\ndef revisionsMade : List Nat := [1, 2, 3]\ndef agreedBatch (reviewers : List Maintainer) (items size : Nat) : List Nat :=\n reviewers.map (fun _ => staticBatch items size)\n\ndef rewrittenOldRecord : RevisionRecord := { revisionRecord with\n old := { oldState with forecast := [.deletion] },\n recordedOld := { oldState with forecast := [.deletion] } }\n\ndef rewrittenPredictionRecord : RevisionRecord := { revisionRecord with\n predictedBatchCount := 5, reportedPredictionSucceeded := true }\n\ndef rewrittenObservationRecord : RevisionRecord := { revisionRecord with\n actualBatchCount := 3, reportedPredictionSucceeded := true }\n\ndef unrelatedSoftwareRecord : RevisionRecord := {\n revisionRecord with software := \"unrelated batch processor\" }\n\ntheorem historicalTamperingRejected :\n RevisionAccount revisionRecord ∧\n ¬ RevisionAccount rewrittenOldRecord ∧\n ¬ RevisionAccount rewrittenPredictionRecord ∧\n ¬ RevisionAccount rewrittenObservationRecord ∧\n observedHistory.predictedBatchCount = 3 ∧ observedHistory.actualBatchCount = 5 ∧\n ¬ RevisionAccount unrelatedSoftwareRecord := by\n exact ⟨by decide, by decide, by decide, by decide, by decide, by decide, by decide⟩\n\n/-- organon-map CoreReader.Engineering.revisionLimits\nsoftware-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99\nsoftware-engineering.revision#p1 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99\n-/\ntheorem revisionLimits :\n RevisionAccount revisionRecord ∧\n ¬ RevisionAccount { revisionRecord with reportedPredictionSucceeded := true } ∧\n revisionsMade.length = 3 ∧\n agreedBatch maintainers 21 5 = [3, 3, 3] ∧ liveBatch 21 5 = 5 ∧\n observations.all (fun p => staticBatch p.1 p.2 == liveBatch p.1 p.2) = true ∧\n staticBatch 21 5 ≠ liveBatch 21 5 ∧\n RevisionAccount stableRecord ∧ stableRecord.current.choice = stableRecord.old.choice ∧\n RetentionJustified currentContinuing [.other \"quantum backend\"] := by\n refine ⟨by decide, ?_, by decide, by decide, by decide, by decide,\n by decide, by decide, by decide, by decide⟩\n dsimp [RevisionAccount, RevisionAccountAgainst, observedHistory, MaterialGroundsChanged, revisionRecord, oldState, newState]\n decide\n\ndef groundedChanges : DirectionGround → List Change\n | .plan _ ds | .knowledge _ ds _ | .history _ ds | .other _ ds => ds\n\ndef currentRevisionState (ctx : Context) (chosen : Candidate) : RevisionState := {\n time := 1, forecast := ctx.evidence.flatMap groundedChanges,\n maintenance := ctx.activity.scheduledMaintenance, maintainers := ctx.activity.participants,\n migrationCost := cost chosen .migration,\n objectiveCapacity := ctx.limits.capacity .migration,\n choice := chosen }\n\ndef revisionFor (ctx : Context) (chosen : Candidate) : RevisionRecord := {\n stableRecord with software := ctx.activity.software, current := currentRevisionState ctx chosen, recordedCurrent := currentRevisionState ctx chosen }\n\ntheorem revisionContextIdentity :\n (revisionFor currentContinuing .evolvable).software = currentContinuing.activity.software ∧\n (revisionFor currentContinuing .evolvable).software = observedHistory.software ∧ (revisionFor currentContinuing .evolvable).current.maintenance =\n currentContinuing.activity.scheduledMaintenance ∧\n (revisionFor currentContinuing .evolvable).current.maintainers = currentContinuing.activity.participants ∧\n (revisionFor currentContinuing .evolvable).current.migrationCost = cost .evolvable .migration ∧\n (revisionFor currentContinuing .evolvable).current.objectiveCapacity =\n currentContinuing.limits.capacity .migration ∧\n (revisionFor currentContinuing .evolvable).current.choice = .evolvable ∧\n RevisionAccount (revisionFor currentContinuing .evolvable) := by decide\n\n/- Whole domain satisfaction keeps actual subject, credibility, account and\nrevision duties. The same context is passed to priority and every domain duty.\nApplication account choices below are finite records, not universal claims. -/\nabbrev DomainSatisfied (ctx : Context) (chosen : Candidate) : Prop :=\n ActivityScope ctx.activity ∧ EvolutionPriority ctx chosen ∧\n credible ctx.evidence .designRevision ∧\n (ctx.departure ≠ none → JustifiedDeparture ctx .evolvable) ∧\n EvolutionClaim ctx.activity chosen ⟨.designRevision, .successor, .revise⟩ ∧\n StructuralAccount ctx.activity chosen (structuralEvidence chosen .designRevision) ∧\n ContractChangeAccount (orderContract (behavior chosen)) (evolutionContract .designRevision) normalRevision ∧\n RevisionAccount (revisionFor ctx chosen)\n\ntheorem currentDomainSatisfied : DomainSatisfied currentContinuing .evolvable := by\n refine ⟨by decide, by decide, by decide, ?_, by decide, by decide, by decide, by decide⟩\n simp [currentContinuing]\n\nend CoreReader.Engineering\n```\n\n\n\n **L1** 加载 Lean 标准库,供本模型使用列表、算术、字符串及可判定的有限检查。\n\n\n **L3** 把应用词汇和结论放入 CoreReader.Engineering 命名空间,与继承的 Core 接口区分。\n\n\n **L5** 工作量数字计数有限场景中明确设定的编辑操作;它们不是各类负担的通用换算率,也不是未来工程表现的实测预测。\n\n\n **L6** 工作量数字计数有限场景中明确设定的编辑操作;它们不是各类负担的通用换算率,也不是未来工程表现的实测预测。\n\n\n **L7** 三种维护者角色区分原作者、接任者和代理,因此原作者可修改并不等于持续维护能力。\n\n\n **L8** 三种维护者角色区分原作者、接任者和代理,因此原作者可修改并不等于持续维护能力。\n\n\n **L9** 自动为 Maintainer 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。\n\n\n **L10** 工具区分编辑、编译、合同检查和迁移;变更路径所需工具必须实际可用。\n\n\n **L11** 工具区分编辑、编译、合同检查和迁移;变更路径所需工具必须实际可用。\n\n\n **L12** 自动为 Tool 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。\n\n\n **L13** 知识区分私有实现布局、公共合同以及变更和迁移指南;这些前提用来区分维护者能力。\n\n\n **L14** 知识区分私有实现布局、公共合同以及变更和迁移指南;这些前提用来区分维护者能力。\n\n\n **L15** 自动为 Knowledge 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。\n\n\n **L16** 变更词汇包含六种主要演化操作、独立和协同工作、设计修订及开放的命名扩展;九项示例列表并不穷尽该类型。\n\n\n **L17** 变更词汇包含六种主要演化操作、独立和协同工作、设计修订及开放的命名扩展;九项示例列表并不穷尽该类型。\n\n\n **L18** 变更词汇包含六种主要演化操作、独立和协同工作、设计修订及开放的命名扩展;九项示例列表并不穷尽该类型。\n\n\n **L19** 自动为 Change 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。\n\n\n **L20** 三种候选设计分别用于比较当下简单性、可信演化支持和更多已登记扩展能力;优劣由后续行为与工作量数据说明。\n\n\n **L21** 三种候选设计分别用于比较当下简单性、可信演化支持和更多已登记扩展能力;优劣由后续行为与工作量数据说明。\n\n\n **L22** 自动为 Candidate 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。\n\n\n **L23** 七种不同负担覆盖理解、构建、诊断、验证、协调、运行和迁移;模型不要求把它们加总。\n\n\n **L24** 七种不同负担覆盖理解、构建、诊断、验证、协调、运行和迁移;模型不要求把它们加总。\n\n\n **L25** 七种不同负担覆盖理解、构建、诊断、验证、协调、运行和迁移;模型不要求把它们加总。\n\n\n **L26** 自动为 Burden 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。\n\n\n **L28** 具体活动包含三类维护者,使接任者与代理能力断言具有实际对象。\n\n\n **L29** 为有限案例登记九种常规变更;其他命名变更仍可另行表示。\n\n\n **L30** 为有限案例登记九种常规变更;其他命名变更仍可另行表示。\n\n\n **L31** 列出全部已表示成本维度,使威胁检查能逐维度进行。\n\n\n **L32** 列出全部已表示成本维度,使威胁检查能逐维度进行。\n\n\n **L34** 工程活动把能力断言相关的人员或代理、软件、工具、知识与生命周期预期放在同一对象中。\n\n\n **L35** 记录参与该活动的维护者;个人变更能力随后要求属于此名单。\n\n\n **L36** 标识所维护的软件;后续修订报告也据此绑定实际任务。\n\n\n **L37** 记录可用工具,而不假定所有所需工具都存在。\n\n\n **L38** 按维护者分别指定可用知识,允许原作者掌握接任者不知道的私有细节。\n\n\n **L39** 以计划发布次数作为持续开发预期的一项具体指标。\n\n\n **L40** 独立于发布次数记录计划维护量。\n\n\n **L41** 可选的有限运行界限表示真正有界的用途;仅无界限并非持续活动的定义。\n\n\n **L42** 把描述标签与生命周期事实分开,以便检验误称为 temporary 的情况。\n\n\n **L44** 开始来源映射注释,把 CoreReader.Engineering.ActivityScope 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。\n\n\n **L45** 为 CoreReader.Engineering.ActivityScope 记录源文引用 software-engineering.purpose/p1,该直接正文的 SHA256 为 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L46** 为 CoreReader.Engineering.ActivityScope 记录源文引用 software-engineering.purpose/p2,该直接正文的 SHA256 为 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L47** 为 CoreReader.Engineering.ActivityScope 记录源文引用 software-engineering.purpose/p3,该直接正文的 SHA256 为 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L48** 结束 CoreReader.Engineering.ActivityScope 的源文映射注释;其后恢复可执行声明。\n\n\n **L49** 活动范围是工程主体的具体适用条件,不是赋予代码的内在意图。\n\n\n **L50** 要求实际参与者、非空软件标识和可用工具。\n\n\n **L51** 每名已列维护者都须有某些知识;这尚不表明知识足以支持所有变更。\n\n\n **L53** 本模型把计划发布和维护均为正作为持续活动条件;活动名称无关。\n\n\n **L54** 本模型把计划发布和维护均为正作为持续活动条件;活动名称无关。\n\n\n **L56** 有界生命周期要求声明有限运行上限,且没有计划发布或维护;仅 temporary 标签不能满足它。\n\n\n **L57** 有界生命周期要求声明有限运行上限,且没有计划发布或维护;仅 temporary 标签不能满足它。\n\n\n **L58** 有界生命周期要求声明有限运行上限,且没有计划发布或维护;仅 temporary 标签不能满足它。\n\n\n **L60** 持续队列活动包含全部维护者和四种工具;软件标识为保持顺序的队列。\n\n\n **L61** 持续队列活动包含全部维护者和四种工具;软件标识为保持顺序的队列。\n\n\n **L62** 持续队列活动包含全部维护者和四种工具;软件标识为保持顺序的队列。\n\n\n **L63** 只有原维护者拥有 privateLayout;接任者与代理拥有公共合同和指南,形成真实的前提差异。\n\n\n **L64** 只有原维护者拥有 privateLayout;接任者与代理拥有公共合同和指南,形成真实的前提差异。\n\n\n **L65** 只有原维护者拥有 privateLayout;接任者与代理拥有公共合同和指南,形成真实的前提差异。\n\n\n **L66** 活动计划三次发布、六个维护单位,两项持续生命周期指标均为正。\n\n\n **L67** 虽然标签写 temporary,却没有有限运行界限;后续案例拒绝以此标签证明生命周期有界。\n\n\n **L69** 一次性变式清除计划发布和维护,并设单次运行界限,构成真正有界的示例。\n\n\n **L70** 一次性变式清除计划发布和维护,并设单次运行界限,构成真正有界的示例。\n\n\n **L71** 一次性变式清除计划发布和维护,并设单次运行界限,构成真正有界的示例。\n\n\n **L72** 原型保留零维护的有界配置,但允许运行四次。\n\n\n **L73** 原型保留零维护的有界配置,但允许运行四次。\n\n\n **L74** 退役服务使用相同有界配置,并设两次剩余运行。\n\n\n **L75** 退役服务使用相同有界配置,并设两次剩余运行。\n\n\n **L77** 每个编辑步骤记录工作位置、所需知识与工具,以及设定的工作单位。\n\n\n **L78** 标识该工作步骤涉及的组件。\n\n\n **L79** 给出执行维护者必须具备的知识前提。\n\n\n **L80** 给出该步骤所需工具。\n\n\n **L81** 为这个明确操作指定自然数成本;后续总量对这些单位求和。\n\n\n **L82** 自动为 EditStep 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。\n\n\n **L84** 按候选设计和预期变更构造明确工作路径,而非根据设计标签赋予能力。\n\n\n **L85** presentSimple 需要私有布局知识;其他设计使用接任者具备的变更指南。\n\n\n **L86** 每条常规路径先在组件 0 编辑,再检查公共合同,两步各耗一个单位。\n\n\n **L87** 每条常规路径先在组件 0 编辑,再检查公共合同,两步各耗一个单位。\n\n\n **L88** 按请求的 Change 选择对应编辑路径;后续各分支区分不同变更方向。\n\n\n **L89** 功能增加和独立变更只使用这条两单位基础路径。\n\n\n **L90** 替换和删除增加组件 1 的一单位编译步骤,并使用设计所选指南。\n\n\n **L91** 协同变更新增组件 1 的编译和组件 2 的公共合同验证,各耗三个单位。\n\n\n **L92** 迁移增加一个需要迁移指南的八单位迁移执行步骤。\n\n\n **L93** 撤回、边界重划和设计修订按所选设计分支;简单方案与演化方案在此使用不同工作路径。\n\n\n **L94** 撤回、边界重划和设计修订按所选设计分支;简单方案与演化方案在此使用不同工作路径。\n\n\n **L95** 简单设计增加依赖私有指南的编辑、编译以及公共合同检查,三步各五单位,总工作量为十七。\n\n\n **L96** 简单设计增加依赖私有指南的编辑、编译以及公共合同检查,三步各五单位,总工作量为十七。\n\n\n **L97** 其他设计改为在组件 1 增加两单位编辑和两单位公共合同检查,加基础步骤共六单位。\n\n\n **L98** 开放的其他变更构造子目前只对 csv export 设置具体特殊路径。\n\n\n **L99** 开放的其他变更构造子目前只对 csv export 设置具体特殊路径。\n\n\n **L100** maximal 通过组件 3 上依赖迁移指南的编译支持 CSV 导出,新增两单位工作。\n\n\n **L101** 其他设计的 CSV 导出需要 privateLayout 和额外二十单位编译工作,因此接任者不具备该路径前提。\n\n\n **L102** 未识别名称没有路径;非空路径要求防止空列表造成空洞的能力成功。\n\n\n **L104** 总工作量是实际路径各步骤设定单位之和,不是模块或扩展点数量。\n\n\n **L105** 总工作量是实际路径各步骤设定单位之和,不是模块或扩展点数量。\n\n\n **L107** 个人变更能力同时索引实际活动、设计、维护者和预期变更。\n\n\n **L108** 能力要求非空路径、维护者参与,以及全部步骤的知识和工具前提;任一前提失败都会阻断断言。\n\n\n **L109** 能力要求非空路径、维护者参与,以及全部步骤的知识和工具前提;任一前提失败都会阻断断言。\n\n\n **L111** 持续能力要求非空路径,且每名已列维护者均具备执行路径所需知识和工具;活动范围另行要求参与者非空。\n\n\n **L112** 持续能力要求非空路径,且每名已列维护者均具备执行路径所需知识和工具;活动范围另行要求参与者非空。\n\n\n **L113** 持续能力要求非空路径,且每名已列维护者均具备执行路径所需知识和工具;活动范围另行要求参与者非空。\n\n\n **L115** 最大能力仅相对于已登记的有限方向集合;CSV 具有具体工作和状态内容,未支持名称不能因空路径而获得能力。\n\n\n **L116** 最大能力仅相对于已登记的有限方向集合;CSV 具有具体工作和状态内容,未支持名称不能因空路径而获得能力。\n\n\n **L117** 最大能力仅相对于已登记的有限方向集合;CSV 具有具体工作和状态内容,未支持名称不能因空路径而获得能力。\n\n\n **L118** 在九种常规变更之外加入 CSV 导出,得到十个登记方向。\n\n\n **L119** 仅保留所选设计中每名持续维护者均可执行的登记方向。\n\n\n **L120** 仅保留所选设计中每名持续维护者均可执行的登记方向。\n\n\n **L121** 候选方案支持固定列表中的全部方向时具备最大登记能力;这不是对所有可想象变更的最大性。\n\n\n **L122** 候选方案支持固定列表中的全部方向时具备最大登记能力;这不是对所有可想象变更的最大性。\n\n\n **L124** 被动软件函数与维护者选择的意图分开;示例不把生成取向归于每个工件。\n\n\n **L125** 被动软件函数与维护者选择的意图分开;示例不把生成取向归于每个工件。\n\n\n **L126** 工件原样返回输入,不提出变更建议。\n\n\n **L128** 每名已表示维护者都选择设计修订与迁移,这是活动明确选择的意图。\n\n\n **L130** 行动区分提出变更建议与执行软件获得输出列表。\n\n\n **L131** 行动区分提出变更建议与执行软件获得输出列表。\n\n\n **L132** 行动区分提出变更建议与执行软件获得输出列表。\n\n\n **L133** 自动为 EngineeringAction 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。\n\n\n **L135** 维护者意图转为针对各已选方向的实际 propose 行动。\n\n\n **L136** 维护者意图转为针对各已选方向的实际 propose 行动。\n\n\n **L138** 工件唯一行动是执行被动函数;行动列表不含提议构造子。\n\n\n **L139** 工件唯一行动是执行被动函数;行动列表不含提议构造子。\n\n\n **L141** 开始来源映射注释,把 CoreReader.Engineering.subjectLifecycleCases 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。\n\n\n **L142** 为 CoreReader.Engineering.subjectLifecycleCases 记录源文引用 software-engineering.purpose/p1,该直接正文的 SHA256 为 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L143** 为 CoreReader.Engineering.subjectLifecycleCases 记录源文引用 software-engineering.purpose/p2,该直接正文的 SHA256 为 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L144** 为 CoreReader.Engineering.subjectLifecycleCases 记录源文引用 software-engineering.purpose/p3,该直接正文的 SHA256 为 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L145** 结束 CoreReader.Engineering.subjectLifecycleCases 的源文映射注释;其后恢复可执行声明。\n\n\n **L146** 汇集共享队列活动的具体范围、维护者能力和生命周期正例。\n\n\n **L147** 持续活动满足工程主体的非空范围条件。\n\n\n **L148** 接任者具备演化方案设计修订所需工具与公共知识。\n\n\n **L149** 代理也具备同一设计修订的前提。\n\n\n **L150** 具体活动即使带有 temporary 标签,仍然属于持续活动。\n\n\n **L151** 持续活动并非有界;一次性、原型和退役变式则满足各自明确的有限生命周期条件。\n\n\n **L152** 持续活动并非有界;一次性、原型和退役变式则满足各自明确的有限生命周期条件。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。\n\n\n **L154** 开始来源映射注释,把 CoreReader.Engineering.subjectLimits 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。\n\n\n **L155** 为 CoreReader.Engineering.subjectLimits 记录源文引用 software-engineering.purpose/p1,该直接正文的 SHA256 为 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L156** 为 CoreReader.Engineering.subjectLimits 记录源文引用 software-engineering.purpose/p2,该直接正文的 SHA256 为 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L157** 为 CoreReader.Engineering.subjectLimits 记录源文引用 software-engineering.purpose/p3,该直接正文的 SHA256 为 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L158** 结束 CoreReader.Engineering.subjectLimits 的源文映射注释;其后恢复可执行声明。\n\n\n **L159** 汇集反例,说明不能从较弱事实推断持续能力或软件意图。\n\n\n **L160** 原维护者拥有私有布局知识,因此可以修订简单设计。\n\n\n **L161** 接任者缺少私有知识前提,无法执行同一简单设计修订。\n\n\n **L162** 因此,简单设计并不支持所有持续维护者执行该修订。\n\n\n **L163** temporary 标签与实际有界生命周期条件不成立同时存在。\n\n\n **L164** 代理意图非空,而被动工件仍仅返回 [2,1]。\n\n\n **L165** 设计修订建议出现在代理行动中,却不在工件执行行动中。\n\n\n **L166** 设计修订建议出现在代理行动中,却不在工件执行行动中。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。\n\n\n **L168** 可信性以可表述性检查和支持关系为参数;后续示例不验证所有可能提供的关系。\n\n\n **L169** 可信性以可表述性检查和支持关系为参数;后续示例不验证所有可能提供的关系。\n\n\n **L170** 开始来源映射注释,把 CoreReader.Engineering.CredibleDirection 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。\n\n\n **L171** 为 CoreReader.Engineering.CredibleDirection 记录源文引用 software-engineering.evolution-priority/p2,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L172** 为 CoreReader.Engineering.CredibleDirection 记录源文引用 software-engineering.evolution-priority/p3,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L173** 结束 CoreReader.Engineering.CredibleDirection 的源文映射注释;其后恢复可执行声明。\n\n\n **L174** 允许任意根据类型,保留可信性来源的开放性。\n\n\n **L175** 应用分别提供根据是否可表述、是否支持预期方向的检查。\n\n\n **L176** 某方向可信当且仅当至少一项已列根据通过针对该方向的两项检查。\n\n\n **L177** 某方向可信当且仅当至少一项已列根据通过针对该方向的两项检查。\n\n\n **L179** 具体示例采用这些根据记录,但不把构造子视为穷尽的哲学分类。\n\n\n **L180** 计划记录发布编号与承诺变更。\n\n\n **L181** 领域知识记录相关服务、受影响变更及机制说明。\n\n\n **L182** 历史记录服务及观察到的变更方向。\n\n\n **L183** other 构造子保留其他可表述说明及其支持变更的空间。\n\n\n **L184** 自动为 DirectionGround 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。\n\n\n **L186** 检查具体根据记录是否具有本应用要求的标识内容。\n\n\n **L187** 计划须给出正发布编号及至少一个承诺方向。\n\n\n **L188** 知识须标识服务、若干受影响方向及非空机制说明。\n\n\n **L189** 历史需要命名服务及某些观察。\n\n\n **L190** 其他根据需要非空说明及方向列表。\n\n\n **L192** 按有限应用的具体记录解释支持,而非从字符串推導任意真实世界相关性。\n\n\n **L193** 正发布编号的计划仅支持其明确包含的方向。\n\n\n **L194** 指定队列知识在机制为 tenant-config-reload 时支持所列方向;该机制名称属于应用解释。\n\n\n **L195** 指定队列知识在机制为 tenant-config-reload 时支持所列方向;该机制名称属于应用解释。\n\n\n **L196** 队列历史中某方向至少出现两次时支持它;这是应用选择的有限支持规则。\n\n\n **L197** 特定已评审客户迁移说明仅支持其列出的方向。\n\n\n **L199** 初始根据承诺在发布 2 进行设计修订和迁移。\n\n\n **L200** 修订后的预测改为承诺发布 3 进行删除。\n\n\n **L201** 把通用可信性专化为 DirectionGround,采用上述具体可表述性和支持解释。\n\n\n **L202** 把通用可信性专化为 DirectionGround,采用上述具体可表述性和支持解释。\n\n\n **L204** 所选预先支持检查要求方向可信、目标收益为正且投入不大于收益;这是局部充分准则,不是通用数值换算规则。\n\n\n **L205** 所选预先支持检查要求方向可信、目标收益为正且投入不大于收益;这是局部充分准则,不是通用数值换算规则。\n\n\n **L206** 所选预先支持检查要求方向可信、目标收益为正且投入不大于收益;这是局部充分准则,不是通用数值换算规则。\n\n\n **L208** 开始来源映射注释,把 CoreReader.Engineering.credibilityCases 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。\n\n\n **L209** 为 CoreReader.Engineering.credibilityCases 记录源文引用 software-engineering.evolution-priority/p2,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L210** 为 CoreReader.Engineering.credibilityCases 记录源文引用 software-engineering.evolution-priority/p3,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L211** 结束 CoreReader.Engineering.credibilityCases 的源文映射注释;其后恢复可执行声明。\n\n\n **L212** 组合计划、知识和历史支持正例,以及无根据想象和预测修订的对照。\n\n\n **L213** 实际发布 2 计划支持设计修订。\n\n\n **L214** 指定队列机制为设计修订提供所声明的知识支持。\n\n\n **L215** 两次已记录队列迁移满足具体历史支持准则。\n\n\n **L216** 空根据列表不支持想象中的量子后端。\n\n\n **L217** 改变后的预测支持删除,并不再支持设计修订。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。\n\n\n **L219** 给简单、演化和最大方案分别设定当下抽象复杂度 1、3、30;这些是场景参数。\n\n\n **L220** 给简单、演化和最大方案分别设定当下抽象复杂度 1、3、30;这些是场景参数。\n\n\n **L222** 目前仅实现简单方案,以展示可信性不要求多个现存实现。\n\n\n **L224** 优先规则把每类负担与各自容量比较,而非换算成单个评分。\n\n\n **L225** 成本向量可按负担分别指定自然数量;这一辅助结构不强制汇总。\n\n\n **L226** 成本向量可按负担分别指定自然数量;这一辅助结构不强制汇总。\n\n\n **L227** 成本界限为每类负担配对容量与明确目标,使威胁断言针对具体事项。\n\n\n **L228** 成本界限为每类负担配对容量与明确目标,使威胁断言针对具体事项。\n\n\n **L229** 成本界限为每类负担配对容量与明确目标,使威胁断言针对具体事项。\n\n\n **L231** 本场景中,简单基准的各类负担都耗一个单位。\n\n\n **L232** 本场景中,简单基准的各类负担都耗一个单位。\n\n\n **L233** 演化方案的理解成本为三单位。\n\n\n **L234** 演化方案的构建成本为四单位。\n\n\n **L235** 演化方案的诊断成本为两单位。\n\n\n **L236** 演化方案的验证成本为四单位。\n\n\n **L237** 演化方案的协调成本为两单位。\n\n\n **L238** 演化方案的运行成本为两单位。\n\n\n **L239** 演化方案迁移成本为八单位,展示并非所有负担都必须低廉。\n\n\n **L240** 最大方案在每个已表示负担上都耗四十单位。\n\n\n **L242** 常规情境中每类负担容量均为十二,足以承受演化方案的设定成本。\n\n\n **L243** 常规情境中每类负担容量均为十二,足以承受演化方案的设定成本。\n\n\n **L244** 按 Burden 分派并指定对应目标名称;后续分支给出各自不同的工程目标。\n\n\n **L245** 理解界限对应接任者入门容量。\n\n\n **L246** 构建容量关联发布准备。\n\n\n **L247** 诊断容量对应事件诊断时间窗口。\n\n\n **L248** 验证容量对应发布检查。\n\n\n **L249** 协调容量对应可用团队协作能力。\n\n\n **L250** 运行容量对应运行时资源预算。\n\n\n **L251** 迁移容量对应最终退役迁移。\n\n\n **L253** 必要需求与演化价值偏好分开。\n\n\n **L254** 表示是否要求指定的输出顺序合同。\n\n\n **L255** 限定允许的不安全操作数量。\n\n\n **L256** 限定观察到的延迟。\n\n\n **L257** 设定最低保留量要求。\n\n\n **L259** 常规需求要求保持顺序、无不安全操作、延迟不超过十且保留量至少三十。\n\n\n **L260** 三个候选行为都按给定顺序删除重复列表值;这一局部相等不等于其维护路径或成本相等。\n\n\n **L262** 表现记录是本场景设定的观察;后续变式分别违反四个需求门槛。\n\n\n **L263** 表现记录是本场景设定的观察;后续变式分别违反四个需求门槛。\n\n\n **L264** 表现记录包含与这些需求相关的四项行为、安全和性能量。\n\n\n **L265** 保存指定顺序测试观察到的输出。\n\n\n **L266** 保存该表现记录中的不安全操作数量。\n\n\n **L267** 保存该表现记录的延迟观察值。\n\n\n **L268** 保存该表现记录的保留量观察值。\n\n\n **L270** 各原始表现记录观察 [2,1,2] 去重结果、零不安全操作、延迟五和保留量三十。\n\n\n **L271** 满足需求时,若要求保持顺序就须得到 [2,1];需求关闭时不强加顺序约束。\n\n\n **L272** 满足需求时,若要求保持顺序就须得到 [2,1];需求关闭时不强加顺序约束。\n\n\n **L273** 安全计数和延迟不得超过上限,保留量须达到下限。\n\n\n **L274** 安全计数和延迟不得超过上限,保留量须达到下限。\n\n\n **L276** 情境绑定领域规范使用的活动、需求、证据、成本和所选偏离说明。\n\n\n **L277** 承载实际工程活动及维护者条件。\n\n\n **L278** 承载相关必要需求。\n\n\n **L279** 承载未来方向可信性的根据。\n\n\n **L280** 承载逐类负担的目标容量。\n\n\n **L281** 可选地标识用于说明偏离演化优先的负担。\n\n\n **L282** 提供候选表现观察,默认使用常规记录,也允许明确测试变式。\n\n\n **L284** 共享常规情境使用持续队列、常规需求、发布 2 根据和容量十二的界限,且未提出偏离理由。\n\n\n **L285** 共享常规情境使用持续队列、常规需求、发布 2 根据和容量十二的界限,且未提出偏离理由。\n\n\n **L286** 共享常规情境使用持续队列、常规需求、发布 2 根据和容量十二的界限,且未提出偏离理由。\n\n\n **L288** 具体威胁要求新增成本同时超过简单基准和命名目标容量;只命名负担而无这些不等式不够。\n\n\n **L289** 具体威胁要求新增成本同时超过简单基准和命名目标容量;只命名负担而无这些不等式不够。\n\n\n **L290** 具体威胁要求新增成本同时超过简单基准和命名目标容量;只命名负担而无这些不等式不够。\n\n\n **L292** 七个已表示负担维度中有一项满足具体威胁条件,就存在威胁。\n\n\n **L293** 七个已表示负担维度中有一项满足具体威胁条件,就存在威胁。\n\n\n **L295** 开始来源映射注释,把 CoreReader.Engineering.JustifiedDeparture 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。\n\n\n **L296** 为 CoreReader.Engineering.JustifiedDeparture 记录源文引用 software-engineering.evolution-priority/p3,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L297** 结束 CoreReader.Engineering.JustifiedDeparture 的源文映射注释;其后恢复可执行声明。\n\n\n **L298** 以记录的负担及其必须成立的具体成本威胁,定义此情境与候选的有根据让步。\n\n\n **L299** 检查同一情境的 departure 选项,区分未指定说明与已指定负担。\n\n\n **L300** 未记录让步负担时,根据条件为 False;缺省记录不提供例外。\n\n\n **L301** 对记录的负担 b,要求同一情境、候选及该负担满足 ConcreteThreat。\n\n\n **L303** 为偏离命题提供判定过程,使有限案例可通过计算检查。\n\n\n **L304** 展开 JustifiedDeparture 中对可选负担的分支。\n\n\n **L305** 区分 none 与某负担,由 Lean 获取 False 或具体算术、字符串条件的可判定性。\n\n\n **L307** 优先适用性是生命周期、可行性、可信性和实际能力比较条件的合取。\n\n\n **L308** 要求活动持续且具有有效工程主体范围。\n\n\n **L309** 简单和演化两个方案都必须满足同一情境的必要需求。\n\n\n **L310** 情境须包含设计修订的可信根据,而不只是想象中的功能增加。\n\n\n **L311** 每名持续维护者都须能用演化方案执行该设计修订。\n\n\n **L312** 演化方案实际设计修订路径的工作量须小于简单方案。\n\n\n **L313** 演化方案须承担更多当下抽象复杂度,使目标取舍具有实际内容。\n\n\n **L315** 开始来源映射注释,把 CoreReader.Engineering.EvolutionPriority 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。\n\n\n **L316** 为 CoreReader.Engineering.EvolutionPriority 记录源文引用 software-engineering.purpose/p3,该直接正文的 SHA256 为 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L317** 为 CoreReader.Engineering.EvolutionPriority 记录源文引用 software-engineering.evolution-priority/p1,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L318** 为 CoreReader.Engineering.EvolutionPriority 记录源文引用 software-engineering.evolution-priority/p2,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L319** 为 CoreReader.Engineering.EvolutionPriority 记录源文引用 software-engineering.evolution-priority/p3,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L320** 结束 CoreReader.Engineering.EvolutionPriority 的源文映射注释;其后恢复可执行声明。\n\n\n **L321** 这是采用的可让位优先规范:全部适用条件成立时,应选择演化方案,除非其新增成本具有明确的合理偏离说明;规范并非仅由那些事实推导。\n\n\n **L322** 这是采用的可让位优先规范:全部适用条件成立时,应选择演化方案,除非其新增成本具有明确的合理偏离说明;规范并非仅由那些事实推导。\n\n\n **L324** 通过计算证明共享常规情境满足全部优先适用条件。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。\n\n\n **L325** 通过计算证明常规演化成本不威胁任何已表示目标,也不存在有根据的偏离。\n\n\n **L326** 通过计算证明常规演化成本不威胁任何已表示目标,也不存在有根据的偏离。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。\n\n\n **L328** 威胁变式只把选中负担容量降到一,并将该负担记录为偏离理由;其他容量仍为十二。\n\n\n **L329** 威胁变式只把选中负担容量降到一,并将该负担记录为偏离理由;其他容量仍为十二。\n\n\n **L330** 威胁变式只把选中负担容量降到一,并将该负担记录为偏离理由;其他容量仍为十二。\n\n\n **L332** 开始来源映射注释,把 CoreReader.Engineering.priorityWhenApplicable 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。\n\n\n **L333** 为 CoreReader.Engineering.priorityWhenApplicable 记录源文引用 software-engineering.evolution-priority/p1,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L334** 为 CoreReader.Engineering.priorityWhenApplicable 记录源文引用 software-engineering.evolution-priority/p2,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L335** 为 CoreReader.Engineering.priorityWhenApplicable 记录源文引用 software-engineering.evolution-priority/p3,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L336** 结束 CoreReader.Engineering.priorityWhenApplicable 的源文映射注释;其后恢复可执行声明。\n\n\n **L337** 条件结论适用于此应用词汇中的任意情境和所选候选。\n\n\n **L338** 同时假定采用优先规则及其实际适用性;定理没有凭自身证明这两个前提。\n\n\n **L339** 还假定不存在有根据的成本偏离。\n\n\n **L340** 在这些前提下,必须选择演化方案,并承担所声明的额外抽象复杂度。\n\n\n **L341** 在这些前提下,必须选择演化方案,并承担所声明的额外抽象复杂度。\n\n\n **L342** 把已采用的蕴含应用于实际条件,再用 noDeparture 排除偏离分支。\n\n\n **L343** 把所得选择相等与适用前提中的最后一项复杂度不等式组合,并代入实际所选候选。\n\n\n **L345** 证明在常规适用且无威胁情境中选择简单方案违反已采用的演化优先。\n\n\n **L346** 暂时假定简单选择满足规则,以导出矛盾。\n\n\n **L347** 实际适用性激活规则,无偏离条件迫使不可能的 simple=evolvable 相等。\n\n\n **L348** 排除不同候选构造子的相等,完成否定结论。\n\n\n **L350** 仅替换演化方案的观察记录,保留其他候选记录和情境,以隔离必要需求变式。\n\n\n **L351** 仅替换演化方案的观察记录,保留其他候选记录和情境,以隔离必要需求变式。\n\n\n **L353** 检查所示四种需求失败各自使 PriorityConditions 为假。这仅阻止优先条件激活;EvolutionPriority 及后面的 DomainSatisfied 并未施加无条件的 Meets 拒绝要求。\n\n\n **L354** 把观察顺序从 [2,1] 改为 [1,2] 会使优先适用条件不成立。\n\n\n **L355** 一次不安全操作超过允许的零,从而使适用条件不成立。\n\n\n **L356** 延迟十一超过界限十,从而使适用条件不成立。\n\n\n **L357** 保留量二十九低于三十,从而使适用条件不成立。\n\n\n **L358** 化简适用条件、修改后的表现记录及需求谓词;每个分支归结为明确失败的相等或数值界限。\n\n\n **L359** 化简适用条件、修改后的表现记录及需求谓词;每个分支归结为明确失败的相等或数值界限。\n\n\n **L361** 开始来源映射注释,把 CoreReader.Engineering.priorityConditionsCases 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。\n\n\n **L362** 为 CoreReader.Engineering.priorityConditionsCases 记录源文引用 software-engineering.purpose/p3,该直接正文的 SHA256 为 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L363** 为 CoreReader.Engineering.priorityConditionsCases 记录源文引用 software-engineering.evolution-priority/p1,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L364** 为 CoreReader.Engineering.priorityConditionsCases 记录源文引用 software-engineering.evolution-priority/p2,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L365** 为 CoreReader.Engineering.priorityConditionsCases 记录源文引用 software-engineering.evolution-priority/p3,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L366** 结束 CoreReader.Engineering.priorityConditionsCases 的源文映射注释;其后恢复可执行声明。\n\n\n **L367** 组合常规优先、四种需求失败、有说明的成本例外以及未选最大复杂度方案的案例。\n\n\n **L368** 在常规情境选择演化方案满足已采用的优先规范。\n\n\n **L369** 重排后的输出不满足常规顺序需求。\n\n\n **L370** 一次不安全操作不满足安全需求。\n\n\n **L371** 延迟十一不满足性能界限。\n\n\n **L372** 保留量二十九不满足最低保留需求。\n\n\n **L373** 验证容量受到具体威胁时,规则可通过偏离分支容许简单选择。\n\n\n **L374** 即使保留成本威胁数据,去掉偏离说明后也不存在已说明的合理偏离。\n\n\n **L375** 优先的演化设计复杂度为三,低于最大方案的三十;优先规范不要求最大化复杂度。\n\n\n **L376** 用有限判定构造合取,只留下缺少偏离说明的分支待化简。\n\n\n **L377** 偏离说明缺失时 JustifiedDeparture 化为 False,从而证明该否定分支。\n\n\n **L379** 开始来源映射注释,把 CoreReader.Engineering.priorityChoices 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。\n\n\n **L380** 为 CoreReader.Engineering.priorityChoices 记录源文引用 software-engineering.evolution-priority/p1,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L381** 为 CoreReader.Engineering.priorityChoices 记录源文引用 software-engineering.evolution-priority/p2,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L382** 为 CoreReader.Engineering.priorityChoices 记录源文引用 software-engineering.evolution-priority/p3,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L383** 结束 CoreReader.Engineering.priorityChoices 的源文映射注释;其后恢复可执行声明。\n\n\n **L384** 同时呈现实际常规演化选择、常规简单选择被拒及威胁情境容许简单选择。\n\n\n **L385** 常规演化选择符合已采用规则。\n\n\n **L386** 常规简单选择不符合相同规则。\n\n\n **L387** 验证受威胁的情境提供选择简单方案的合理例外。\n\n\n **L388** 把计算出的正例与此前证明的无威胁简单选择矛盾组合。\n\n\n **L390** 开始来源映射注释,把 CoreReader.Engineering.credibilityLimits 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。\n\n\n **L391** 为 CoreReader.Engineering.credibilityLimits 记录源文引用 software-engineering.evolution-priority/p2,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L392** 为 CoreReader.Engineering.credibilityLimits 记录源文引用 software-engineering.evolution-priority/p3,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L393** 结束 CoreReader.Engineering.credibilityLimits 的源文映射注释;其后恢复可执行声明。\n\n\n **L394** 区分可信计划变更、现存实现数量、想象中的可能性与最大登记能力。\n\n\n **L395** 设计修订计划可信,同时仅有一个候选实现。\n\n\n **L396** 无根据、零收益的想象量子后端不能支持五单位投入。\n\n\n **L397** 初始计划不支持想象中的量子后端方向。\n\n\n **L398** 常规演化选择仍满足领域优先规范。\n\n\n **L399** 优先设计的当下复杂度低于最大方案。\n\n\n **L400** 演化方案内部构建与迁移成本不同,保留负担区别而非单一通用费率。\n\n\n **L401** 演化方案不能让所有持续维护者支持每个登记方向。\n\n\n **L402** 最大方案确实支持明确登记的有限集合中的所有方向。\n\n\n **L403** 演化方案支持九个登记方向。\n\n\n **L404** 最大方案支持十个,使额外扩展能力具有实质内容而非仅是名称。\n\n\n **L405** 当前计划不支持 CSV 导出,因此技术上可实现本身不构成当前可信根据。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。\n\n\n **L407** 开始来源映射注释,把 CoreReader.Engineering.costCases 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。\n\n\n **L408** 为 CoreReader.Engineering.costCases 记录源文引用 software-engineering.evolution-priority/p3,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L409** 结束 CoreReader.Engineering.costCases 的源文映射注释;其后恢复可执行声明。\n\n\n **L410** 逐一检查七类负担都可成为偏离优先规范的具体理由。\n\n\n **L411** 把理解容量降为一,使演化方案的理解成本成为合理偏离理由。\n\n\n **L412** 类似的构建容量威胁支持合理偏离。\n\n\n **L413** 类似的诊断容量威胁支持合理偏离。\n\n\n **L414** 类似的验证容量威胁支持合理偏离。\n\n\n **L415** 类似的协调容量威胁支持合理偏离。\n\n\n **L416** 类似的运行容量威胁支持合理偏离。\n\n\n **L417** 类似的迁移容量威胁支持合理偏离。\n\n\n **L418** 在常规容量十二的情境中仅命名迁移,不会产生真实威胁或合理例外。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。\n\n\n **L420** 以下全函数表示指定去重接口;有限语料上的相等与全称合同保持分开。\n\n\n **L421** 以下全函数表示指定去重接口;有限语料上的相等与全称合同保持分开。\n\n\n **L422** 使用标准库保持顺序的列表操作删除重复值。\n\n\n **L423** 重构执行相同去重并附加空列表,保持输出不变。\n\n\n **L424** 接收一个自然数及任意自然数列表;类型不含输入已排序的前提。sortValues 调用此辅助函数,在递归排序后的尾列表中按序插入。\n\n\n **L425** 向空列表插入得到单元素列表。\n\n\n **L426** 把值放在首个不小于它的头元素之前;否则保留头元素并递归插入尾部。\n\n\n **L428** 排序递归使用插入操作;它改变顺序,而非仅做去重。\n\n\n **L429** 空列表排序后仍为空。\n\n\n **L430** 先排序尾部,再把原头元素插入已排序结果。\n\n\n **L432** 替代实现先排序再去重,因此可能违反原顺序合同。\n\n\n **L434** 软件状态字段让不同演化类别改变已表示设计的不同方面。\n\n\n **L435** 列出软件已表示的能力。\n\n\n **L436** 标识使用的实现版本。\n\n\n **L437** 列出可以增删的具体机制。\n\n\n **L438** 列出可以保留或撤回的抽象。\n\n\n **L439** 记录边界修订编号,与能力和实现编号区分。\n\n\n **L440** 标识可迁出的存储技术或模型。\n\n\n **L441** 记录配置的批次大小。\n\n\n **L442** 自动为 SoftwareState 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。\n\n\n **L444** 初始软件支持去重,使用实现 0、队列与旧缓存、固定批次抽象、边界编号 0、旧存储及批次大小十。\n\n\n **L445** 初始软件支持去重,使用实现 0、队列与旧缓存、固定批次抽象、边界编号 0、旧存储及批次大小十。\n\n\n **L447** 每个变更方向修改软件状态中实际选定的字段;这是设定的状态模型,而非可执行源码编辑器。\n\n\n **L448** 增加操作保留已有能力并添加租户批处理。\n\n\n **L449** 替换操作递增实现标识。\n\n\n **L450** 删除操作移除旧缓存,保留其他机制。\n\n\n **L451** 撤回操作移除固定批次抽象。\n\n\n **L452** 重划操作递增边界修订编号。\n\n\n **L453** 迁移操作把旧技术换为可移植存储。\n\n\n **L454** 独立变更只把批次大小更新为五。\n\n\n **L455** 协同变更同时更新批次大小和边界编号。\n\n\n **L456** 设计修订把批次设为五、将抽象替换为实时配置,并重划边界。\n\n\n **L457** 命名 CSV 方向增加实际 CSV 能力;未识别的其他方向保持状态不变。\n\n\n **L458** 命名 CSV 方向增加实际 CSV 能力;未识别的其他方向保持状态不变。\n\n\n **L459** 命名 CSV 方向增加实际 CSV 能力;未识别的其他方向保持状态不变。\n\n\n **L461** 本应用中,重划和设计修订有意采用 sortedUnique 行为;其他变更保留 orderedUnique 行为。\n\n\n **L462** 本应用中,重划和设计修订有意采用 sortedUnique 行为;其他变更保留 orderedUnique 行为。\n\n\n **L464** 开放变更类别、工作需求、维护者知识与义务处理方式彼此独立,不折合成单个可扩展性分数。\n\n\n **L465** 开放变更类别、工作需求、维护者知识与义务处理方式彼此独立,不折合成单个可扩展性分数。\n\n\n **L466** 变更断言明确说明其保持义务还是有意修订义务。\n\n\n **L467** 变更断言明确说明其保持义务还是有意修订义务。\n\n\n **L468** 变更断言明确说明其保持义务还是有意修订义务。 自动为 ObligationTreatment 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。\n\n\n **L469** 在同一断言中组合预期方向、执行维护者和声明的义务处理方式。\n\n\n **L470** 标识所断言能力针对的变更。\n\n\n **L471** 标识其条件必须支持该变更的维护者。\n\n\n **L472** 说明同一指定义务是保持还是有意修订。\n\n\n **L474** 有限顺序语料恰为四个列表:空、[2,1,2]、[1,3,1] 和 [4,4];后续有限保持断言仅限这些输入。\n\n\n **L475** 全称范围保持要求新旧函数对每个满足所给范围谓词的输入都相等。\n\n\n **L476** 全称范围保持要求新旧函数对每个满足所给范围谓词的输入都相等。\n\n\n **L478** 有限保持仅用布尔相等检查声明语料;它不推出前述覆盖所有范围输入的性质。\n\n\n **L479** 有限保持仅用布尔相等检查声明语料;它不推出前述覆盖所有范围输入的性质。\n\n\n **L481** 合同与观察者依赖独立于报告提供,防止修改报告就重定义实际新旧行为或受影响人群。\n\n\n **L482** 合同与观察者依赖独立于报告提供,防止修改报告就重定义实际新旧行为或受影响人群。\n\n\n **L483** 合同与观察者依赖独立于报告提供,防止修改报告就重定义实际新旧行为或受影响人群。\n\n\n **L484** 可观察合同组合顺序行为和重试界限。\n\n\n **L485** 顺序函数是实际可观察行为,而非仅合同名称。\n\n\n **L486** 重试阈值属于实际合同。\n\n\n **L488** 尝试编号低于 maxAttempts 时才允许重试,使阈值变化具有可观察后果。\n\n\n **L489** 尝试编号低于 maxAttempts 时才允许重试,使阈值变化具有可观察后果。\n\n\n **L491** 常规顺序合同把所给函数与阈值三配对。\n\n\n **L492** 原合同使用保持顺序的去重及阈值三。\n\n\n **L493** 重构合同仅换成外延相同的重构函数,保留阈值三。\n\n\n **L494** 有意修订采用排序去重和阈值五,改变两项已表示合同方面。\n\n\n **L495** 方向对应合同采用实际演化行为,仅在重划或设计修订时提高重试阈值。\n\n\n **L496** 方向对应合同采用实际演化行为,仅在重划或设计修订时提高重试阈值。\n\n\n **L498** 有限重试语料包含零至五的尝试编号。\n\n\n **L499** 有限完整合同保持同时要求 contractInputs 上顺序相等及 failureInputs 上重试相等。\n\n\n **L500** 有限完整合同保持同时要求 contractInputs 上顺序相等及 failureInputs 上重试相等。\n\n\n **L501** 有限完整合同保持同时要求 contractInputs 上顺序相等及 failureInputs 上重试相等。\n\n\n **L503** 顺序与重试是不同可观察合同方面,允许不同参与方分别依赖。\n\n\n **L504** 顺序与重试是不同可观察合同方面,允许不同参与方分别依赖。\n\n\n **L505** 顺序与重试是不同可观察合同方面,允许不同参与方分别依赖。 自动为 ContractAspect 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。\n\n\n **L506** 依赖记录把命名参与方与其观察的合同方面连接。\n\n\n **L507** 标识义务可能受影响的参与方。\n\n\n **L508** 标识该参与方依赖的具体可观察方面。\n\n\n **L509** 自动为 PartyDependency 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。\n\n\n **L511** 队列消费者依赖顺序,队列运维者依赖重试行为;这些依赖在修订报告之外固定。\n\n\n **L512** 队列消费者依赖顺序,队列运维者依赖重试行为;这些依赖在修订报告之外固定。\n\n\n **L514** 按每项方面的有限观察,从实际新旧合同检测变化。\n\n\n **L515** 任一声明顺序输入产生不同输出时,顺序方面发生变化。\n\n\n **L516** 任一声明尝试编号产生不同许可结果时,重试方面发生变化。\n\n\n **L518** 受影响参与方列表从其观察方面确实变化的固定依赖计算,而非取自报告自己的声称。\n\n\n **L519** 受影响参与方列表从其观察方面确实变化的固定依赖计算,而非取自报告自己的声称。\n\n\n **L520** 受影响参与方列表从其观察方面确实变化的固定依赖计算,而非取自报告自己的声称。\n\n\n **L522** 修订说明记录意图、变化后观察、参与方、实际界限声称、已记录界限及程序说明。\n\n\n **L523** 表明合同改变是有意的。\n\n\n **L524** 记录指定样本上的修订后顺序输出。\n\n\n **L525** 列出报告承认的参与方;后续责任把它与实际受影响参与方比较。\n\n\n **L526** 给出报告声称的原重试阈值。\n\n\n **L527** 给出报告声称的新重试阈值。\n\n\n **L528** 保留报告中原阈值的历史记录。\n\n\n **L529** 保留记录的新阈值。\n\n\n **L530** 命名所选程序;哲学说明不规定某一种特定程序。\n\n\n **L532** 常规修订是有意的,并记录新的排序结果 [1,2]。\n\n\n **L533** 常规修订是有意的,并记录新的排序结果 [1,2]。\n\n\n **L534** 承认两项实际方面变化影响到消费者与运维者。\n\n\n **L535** 给出实际重试界限从三变为五。\n\n\n **L536** 保留记录同样写明之前三、之后五,而非改写原界限。\n\n\n **L537** 把合同评审用作一种可选程序,而不将该名称设为有效性条件。\n\n\n **L539** 修订责任针对独立提供的新旧合同及具体报告进行评估。\n\n\n **L540** 要求有意修订,并准确报告 [2,1,2] 上的新输出。\n\n\n **L541** 每个实际受影响参与方都须出现在报告中;允许额外列人,也未规定通知义务。\n\n\n **L542** 报告声称的两个失败界限须等于独立提供的实际阈值。\n\n\n **L543** 记录的旧界限仍须匹配原合同。\n\n\n **L544** 记录的新界限须匹配新合同。\n\n\n **L546** 开始来源映射注释,把 CoreReader.Engineering.ContractChangeAccount 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。\n\n\n **L547** 为 CoreReader.Engineering.ContractChangeAccount 记录源文引用 software-engineering.structural-judgment/p3,该直接正文的 SHA256 为 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L548** 结束 CoreReader.Engineering.ContractChangeAccount 的源文映射注释;其后恢复可执行声明。\n\n\n **L549** 合同变更说明要么保持全部声明的有限观察,要么履行有意修订责任;二者是不同分支。\n\n\n **L550** 合同变更说明要么保持全部声明的有限观察,要么履行有意修订责任;二者是不同分支。\n\n\n **L552** 开始来源映射注释,把 CoreReader.Engineering.EvolutionClaim 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。\n\n\n **L553** 为 CoreReader.Engineering.EvolutionClaim 记录源文引用 software-engineering.evolution-meaning/p1,该直接正文的 SHA256 为 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L554** 为 CoreReader.Engineering.EvolutionClaim 记录源文引用 software-engineering.evolution-meaning/p2,该直接正文的 SHA256 为 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L555** 结束 CoreReader.Engineering.EvolutionClaim 的源文映射注释;其后恢复可执行声明。\n\n\n **L556** 能力断言针对具体维护者和方向,并明确义务处理方式。\n\n\n **L557** 命名维护者必须实际能够执行预期方向的路径。\n\n\n **L558** 同一方向的实际新旧合同变更须具备有效保持或修订说明。\n\n\n **L559** 该方向路径须含合同执行器步骤,使断言关联已表示的验证工作。\n\n\n **L560** 保持型断言要求指定样本维持原有顺序输出。\n\n\n **L561** 保持型断言要求指定样本维持原有顺序输出。\n\n\n **L562** 修订型断言则要求该样本输出实际不同;处理标签不能悄然颠倒观察关系。\n\n\n **L563** 修订型断言则要求该样本输出实际不同;处理标签不能悄然颠倒观察关系。\n\n\n **L565** 开始来源映射注释,把 CoreReader.Engineering.evolutionKindsCases 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。\n\n\n **L566** 为 CoreReader.Engineering.evolutionKindsCases 记录源文引用 software-engineering.evolution-meaning/p1,该直接正文的 SHA256 为 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L567** 为 CoreReader.Engineering.evolutionKindsCases 记录源文引用 software-engineering.evolution-meaning/p2,该直接正文的 SHA256 为 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L568** 结束 CoreReader.Engineering.evolutionKindsCases 的源文映射注释;其后恢复可执行声明。\n\n\n **L569** 汇集实际状态变化、接任者能力及保持与修订两类断言示例。\n\n\n **L570** 增加操作保留去重并添加租户批处理。\n\n\n **L571** 替换操作把实现编号从零改为一。\n\n\n **L572** 删除操作移除旧缓存,留下队列机制。\n\n\n **L573** 撤回操作移除唯一固定批次抽象,抽象列表变空。\n\n\n **L574** 重划操作把边界编号从零改为一。\n\n\n **L575** 迁移操作把存储技术改为 portable store。\n\n\n **L576** 接任者具备所给工具和指南,可执行九条常规演化变更路径。\n\n\n **L577** 接任者的替换构成有效保持型 EvolutionClaim。\n\n\n **L578** 代理的边界重划构成有效有意修订型 EvolutionClaim。\n\n\n **L579** 独立工作耗二单位、协同工作耗八单位,因此二者无需具有相同工作量。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。\n\n\n **L581** 开始来源映射注释,把 CoreReader.Engineering.evolutionDimensionsLimits 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。\n\n\n **L582** 为 CoreReader.Engineering.evolutionDimensionsLimits 记录源文引用 software-engineering.evolution-meaning/p1,该直接正文的 SHA256 为 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L583** 为 CoreReader.Engineering.evolutionDimensionsLimits 记录源文引用 software-engineering.evolution-meaning/p2,该直接正文的 SHA256 为 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L584** 结束 CoreReader.Engineering.evolutionDimensionsLimits 的源文映射注释;其后恢复可执行声明。\n\n\n **L585** 展示不同演化维度具有不同成本与能力,包括实际最大方案与演化方案的对照。\n\n\n **L586** 简单设计增加操作耗两单位。\n\n\n **L587** 撤回其固定结构耗十七单位,明显多于增加。\n\n\n **L588** 演化方案独立变更工作量少于协同变更。\n\n\n **L589** 这些不均等成本可与满足演化优先并存。\n\n\n **L590** 演化迁移耗十单位,虽满足优先规范仍超过九。\n\n\n **L591** 原维护者可以在简单设计中增加功能。\n\n\n **L592** 原维护者也可以在演化设计中增加功能。\n\n\n **L593** 原维护者的私有知识允许其修订简单设计。\n\n\n **L594** 原维护者也能执行演化方案设计修订。\n\n\n **L595** 对于同一设计修订方向,演化方案耗六单位,简单方案耗十七单位。\n\n\n **L596** 两个设计增加操作都耗两单位;设计修订优势不是所有维度上的严格优势。\n\n\n **L597** CSV 导出实际修改能力列表,在去重之外加入 CSV。\n\n\n **L598** 接任者具备最大方案 CSV 路径所需指南和工具。\n\n\n **L599** 接任者缺少演化方案 CSV 路径需要的 privateLayout,尽管该方案还有其他优势。\n\n\n **L600** 用 Lean 判定过程对明确有限路径、状态和算术逐项构造合取;没有进行经验推广。\n\n\n **L602** 给出反例,否定从单一方向优势推出所有方向严格改善。\n\n\n **L603** 保留设计修订上的真实严格改善。\n\n\n **L604** 否定演化方案对每种 Change 都严格减少工作,包括增加和其他命名方向。\n\n\n **L605** 计算修订正不等式,并留下全称否定用反例证明。\n\n\n **L606** 假定每个方向都严格改善,以导出矛盾。\n\n\n **L607** 把假设专化到增加方向;两边工作量均为二,所声称严格不等式为假。\n\n\n **L608** 把假设专化到增加方向;两边工作量均为二,所声称严格不等式为假。\n\n\n **L610** 变更传播是实际路径触及组件编号的去重列表,保留与预期变更的关系。\n\n\n **L611** 变更传播是实际路径触及组件编号的去重列表,保留与预期变更的关系。\n\n\n **L613** 计算自然数批次数表达式 (items+size−1)/size,预期用于正批次大小;Lean 的减法和除法在该预期域外仍是全定义运算。\n\n\n **L614** 静态预测器有意忽略 runtimeSize,始终按大小十计算。\n\n\n **L615** 实时预测器使用所给运行时批次大小,使固定假设可被检验。\n\n\n **L617** 结构证据记录把预期变更与参与者、传播、观察及工作说明连接。\n\n\n **L618** 标识这份证据应支持的变更。\n\n\n **L619** 标识证据说明中的相关维护者。\n\n\n **L620** 记录变更触及的组件。\n\n\n **L621** 记录观察合同所用的确切输入语料。\n\n\n **L622** 记录变更前在该语料上的输出。\n\n\n **L623** 记录变更后在相同语料上的输出。\n\n\n **L624** 存储所表示的理解工作量;此处用总路径工作实例化。\n\n\n **L625** 存储验证工作量,下面用合同执行器步骤数实例化,而非这些步骤的单位之和。\n\n\n **L626** 存储针对该预期变更相对简单设计的工作收益声称。\n\n\n **L628** 从候选路径与同一预期方向构造具体证据记录。\n\n\n **L629** 绑定方向、全部维护者以及实际去重传播列表。\n\n\n **L630** 恰使用声明的有限合同语料。\n\n\n **L631** 使用 orderedUnique 计算旧观察。\n\n\n **L632** 使用该方向实际 evolutionBehavior 计算新观察。\n\n\n **L633** 理解工作字段等于预期路径的总设定工作量。\n\n\n **L634** 验证量计数同一路径中的实际 contractRunner 步骤。\n\n\n **L635** 工作收益是简单工作减所选工作,使用自然数减法;结果截断于零,不记录负收益。\n\n\n **L637** 开始来源映射注释,把 CoreReader.Engineering.StructuralAccount 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。\n\n\n **L638** 为 CoreReader.Engineering.StructuralAccount 记录源文引用 software-engineering.structural-judgment/p1,该直接正文的 SHA256 为 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L639** 为 CoreReader.Engineering.StructuralAccount 记录源文引用 software-engineering.structural-judgment/p2,该直接正文的 SHA256 为 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L640** 结束 CoreReader.Engineering.StructuralAccount 的源文映射注释;其后恢复可执行声明。\n\n\n **L641** 有效结构说明须匹配实际活动、候选和预期变更;仅填入记录字段不够。\n\n\n **L642** 记录参与者须等于活动参与者,触及组件须等于所断言方向的实际传播。\n\n\n **L643** 说明须准确标识指定有限观察输入。\n\n\n **L644** 其变更前结果须是这些输入上的原有顺序行为。\n\n\n **L645** 其变更后结果须来自同一预期方向的行为。\n\n\n **L646** 声称的理解工作量须匹配所选路径总工作。\n\n\n **L647** 验证字段须匹配实际合同执行器步骤数量;检查的是具体工作关系,而非自由评估标记。\n\n\n **L648** 验证字段须匹配实际合同执行器步骤数量;检查的是具体工作关系,而非自由评估标记。\n\n\n **L649** 声称收益须等于同一预期变更实际简单工作减所选工作的差。\n\n\n **L651** 可见接口元数据与可执行行为和编辑路径分开,用于后续不足性反例。\n\n\n **L652** 存储可见函数签名文本。\n\n\n **L653** 存储声称模块数,后续与实际组件列表比较。\n\n\n **L654** 存储可见扩展点数量。\n\n\n **L655** 存储命名设计原则;名称本身不会证明能力。\n\n\n **L656** 自动为 InterfaceView 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。\n\n\n **L658** 多个设计共享 List Nat→List Nat 签名、八个模块、十二个扩展点和依赖倒置标签。\n\n\n **L659** 编号零至七的八个组件都假定批次大小十。\n\n\n **L660** 编号零至七的八个组件都假定批次大小十。\n\n\n **L662** 改变批次大小时,选出存储假设与新大小不同的组件;新大小五时八个都需修订。\n\n\n **L663** 改变批次大小时,选出存储假设与新大小不同的组件;新大小五时八个都需修订。\n\n\n **L665** 边界携带实际端点编号和合同标签,使检查能区分具体关系。\n\n\n **L666** 标识边的调用方端点。\n\n\n **L667** 标识边的被调用方端点。\n\n\n **L668** 存储边的合同标签;后续检查还要求工作与实际输出相等,因此该字符串不是充分证据。\n\n\n **L669** 自动为 Boundary 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。\n\n\n **L671** 完整已表示设计把元数据与实际函数、路径、组件、边界和假设组合。\n\n\n **L672** 把可见元数据与实质设计字段并列保存。\n\n\n **L673** 承载合同比较所用的实际行为。\n\n\n **L674** 按预期变更分别提供具体编辑步骤。\n\n\n **L675** 列出实际组件编号,以便检查端点存在性。\n\n\n **L676** 列出设计实际表示的边。\n\n\n **L677** 把组件与其固定批次大小假设关联。\n\n\n **L679** 私有设计具有共享元数据、顺序行为和简单设计路径;它有八个组件、无显式边及八项固定批次假设。\n\n\n **L680** 私有设计具有共享元数据、顺序行为和简单设计路径;它有八个组件、无显式边及八项固定批次假设。\n\n\n **L681** 私有设计具有共享元数据、顺序行为和简单设计路径;它有八个组件、无显式边及八项固定批次假设。\n\n\n **L683** 文档化设计只把工作路径改为演化方案依赖指南的路径;元数据与可观察行为保持相同。\n\n\n **L684** 文档化设计只把工作路径改为演化方案依赖指南的路径;元数据与可观察行为保持相同。\n\n\n **L686** 排序变式改变实际行为,却保留文档化设计的元数据与路径,以构成同签名合同反例。\n\n\n **L688** 此有限应用把编辑被调用方 1 视为穿越实际 2→1 边,并要求调用方检查顺序;边标签或合同名称都不能证明验证已发生或输出已保持。\n\n\n **L689** 此有限应用把编辑被调用方 1 视为穿越实际 2→1 边,并要求调用方检查顺序;边标签或合同名称都不能证明验证已发生或输出已保持。\n\n\n **L690** 此有限应用把编辑被调用方 1 视为穿越实际 2→1 边,并要求调用方检查顺序;边标签或合同名称都不能证明验证已发生或输出已保持。\n\n\n **L691** 此有限应用把编辑被调用方 1 视为穿越实际 2→1 边,并要求调用方检查顺序;边标签或合同名称都不能证明验证已发生或输出已保持。\n\n\n **L692** 实例化从调用方 2 到被调用方 1 的具体边,并使用队列顺序合同标签。\n\n\n **L694** 把该实际边加入 documentedDesign 的边界列表,使后续检查针对确实包含该边的设计。\n\n\n **L695** 把该实际边加入 documentedDesign 的边界列表,使后续检查针对确实包含该边的设计。\n\n\n **L697** 针对一个实际设计、一个预期方向及一条边检查跨界。\n\n\n **L698** 边须属于设计,调用方须是实际组件。\n\n\n **L699** 被调用方也须存在,且调用方与被调用方须为不同组件。\n\n\n **L700** 预期路径须实际编辑或编译被调用方组件;无关边不能证明经过此边界的传播。\n\n\n **L701** 预期路径须实际编辑或编译被调用方组件;无关边不能证明经过此边界的传播。\n\n\n **L703** 边界义务检查索引同一设计、预期变更和边,因此无关边界的结果不能替代。\n\n\n **L704** 边界义务检查索引同一设计、预期变更和边,因此无关边界的结果不能替代。\n\n\n **L705** 先要求实际跨界关系,再把调用方检查视为跨界义务。\n\n\n **L706** 同一变更路径须含调用方组件上的 contractRunner 步骤,且需要 publicContract 知识。\n\n\n **L707** 同一变更路径须含调用方组件上的 contractRunner 步骤,且需要 publicContract 知识。\n\n\n **L708** 实际设计行为须在声明有限顺序语料上保持 orderedUnique;仅有检查步骤标签而无输出相等仍失败。\n\n\n **L710** 构造设计变式 omittedCallerCheck,在路径中省去调用方合同执行器工作,用于后面的边界义务反例。\n\n\n **L711** 保持 boundaryDesign 的其他字段不变,将 paths 替换为按请求方向变换对应路径的函数。\n\n\n **L712** 筛选 boundaryDesign 在同一方向的原路径,只保留下述谓词接受的步骤。\n\n\n **L713** 仅在步骤位于 coordinatedBoundary.caller 且使用 contractRunner 时删除它;保留其余步骤,并完成记录更新。\n\n\n **L715** 把被调用端点移到组件 7,保留调用方和合同标签。\n\n\n **L717** 替代设计实际包含改变后的边,因此跨界否定检查针对端点与路径不匹配,而非仅边缺失。\n\n\n **L718** 替代设计实际包含改变后的边,因此跨界否定检查针对端点与路径不匹配,而非仅边缺失。\n\n\n **L720** 检查实际边、预期工作、调用方义务与可观察行为之间的正反关系。\n\n\n **L721** boundaryDesign 的协同工作经过其实际 2→1 边。\n\n\n **L722** 该工作包含要求的调用方检查,并保持有限顺序合同。\n\n\n **L723** 删除调用方检查并未删除被调用方编辑,因此仍然发生跨界。\n\n\n **L724** 但移除调用方检查后,跨界义务未履行。\n\n\n **L725** 指向被调用方 7 的边未被穿越,因为协同路径不编辑或编译该端点。\n\n\n **L726** 只把 run 换为 sortedUnique 就违反顺序义务,即使边与检查步骤不变;通过计算证明这组有限合取。\n\n\n **L727** 只把 run 换为 sortedUnique 就违反顺序义务,即使边与检查步骤不变;通过计算证明这组有限合取。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。\n\n\n **L729** 开始来源映射注释,把 CoreReader.Engineering.structuralCases 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。\n\n\n **L730** 为 CoreReader.Engineering.structuralCases 记录源文引用 software-engineering.structural-judgment/p1,该直接正文的 SHA256 为 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L731** 为 CoreReader.Engineering.structuralCases 记录源文引用 software-engineering.structural-judgment/p2,该直接正文的 SHA256 为 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L732** 结束 CoreReader.Engineering.structuralCases 的源文映射注释;其后恢复可执行声明。\n\n\n **L733** 登记的结构案例组合包含实际传播、合同观察、工作以及新增显式跨界检查。\n\n\n **L734** 演化方案设计修订证据匹配实际持续活动和预期路径。\n\n\n **L735** 简单设计修订触及三个不同组件。\n\n\n **L736** 演化设计修订触及两个不同组件。\n\n\n **L737** 协同工作包含需要公共合同知识的组件 2 步骤;后续新增案例还把它绑定到真实边。\n\n\n **L738** 重构在声明有限合同语料上保持顺序行为。\n\n\n **L739** 有意设计修订的实际前后观察列表不同;没有把该改变误称为保持。\n\n\n **L740** 有意设计修订的实际前后观察列表不同;没有把该改变误称为保持。\n\n\n **L741** 对于二十一个元素,静态批次假设在运行时大小十时正确,在大小五时失败。\n\n\n **L742** 撤回简单设计结构耗十七单位,保留最终退出成本。\n\n\n **L743** 协同路径穿越实际调用方 2/被调用方 1 边界。\n\n\n **L744** 该边界的公共合同验证及有限顺序义务得到履行。\n\n\n **L745** 省略调用方验证后,被调用方编辑仍穿越边界。\n\n\n **L746** 省略调用方验证使义务检查失败。\n\n\n **L747** 被调用方为组件 7 的边不匹配该编辑路径,未被穿越。\n\n\n **L748** 相同边和步骤若配上 sortedUnique 行为,就不满足实际有限顺序保持;decide 检查整个具体结构组合的各项。\n\n\n **L749** 相同边和步骤若配上 sortedUnique 行为,就不满足实际有限顺序保持;decide 检查整个具体结构组合的各项。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。\n\n\n **L751** 把个人能力从候选标签推广到具有自身路径的实际 EngineeringDesign。\n\n\n **L752** 把个人能力从候选标签推广到具有自身路径的实际 EngineeringDesign。\n\n\n **L753** 要求实际设计路径非空,且维护者参与活动。\n\n\n **L754** 每个实际路径步骤都须能用该维护者的知识及活动工具执行。\n\n\n **L755** 每个实际路径步骤都须能用该维护者的知识及活动工具执行。\n\n\n **L757** 从该设计对象实际路径单位计算工作,使路径变式可明确改变或保持总量。\n\n\n **L758** 从该设计对象实际路径单位计算工作,使路径变式可明确改变或保持总量。\n\n\n **L760** 找出自身已记录批次假设与拟用运行时大小不同的组件。\n\n\n **L761** 找出自身已记录批次假设与拟用运行时大小不同的组件。\n\n\n **L763** 第一种外观包装增加组件、转发边和验证步骤,同时保持输出;它既不提供缺失的私有知识,也不消除原编辑工作。\n\n\n **L764** 第一种外观包装增加组件、转发边和验证步骤,同时保持输出;它既不提供缺失的私有知识,也不消除原编辑工作。\n\n\n **L765** 第一种外观包装增加组件、转发边和验证步骤,同时保持输出;它既不提供缺失的私有知识,也不消除原编辑工作。\n\n\n **L766** 在完整设计上构造第一种明确的引入边界变换。\n\n\n **L767** 可见模块数和扩展点数均增加一。\n\n\n **L768** 包装先给输入附加空列表,再调用原行为,从而保持结果。\n\n\n **L769** 原路径缺失时仍保持缺失;仅包装不能为未知变更创造支持。\n\n\n **L770** 已有路径在新组件编号处增加一个公共合同验证单位。\n\n\n **L771** 以原组件列表长度作为新组件编号加入;对于具体零至七初始设计,该编号是新的。\n\n\n **L772** 加入从该新组件到组件 0 的转发边,并携带原签名标签。\n\n\n **L773** 加入从该新组件到组件 0 的转发边,并携带原签名标签。\n\n\n **L774** 保留全部固定批次假设,因此包装没有解除这些假设造成的关联。\n\n\n **L776** 把第一种包装变换用于私有设计,构造实际工作量增加反例。\n\n\n **L778** 第二种包装把已有验证移到新组件,而不增加工作;真实边界与路径变化仍未提供私有知识或降低总工作量。\n\n\n **L779** 第二种包装把已有验证移到新组件,而不增加工作;真实边界与路径变化仍未提供私有知识或降低总工作量。\n\n\n **L780** 第二种包装把已有验证移到新组件,而不增加工作;真实边界与路径变化仍未提供私有知识或降低总工作量。\n\n\n **L781** 从相同引入边界设计开始,保留新组件、边及等价行为。\n\n\n **L782** 从相同引入边界设计开始,保留新组件、边及等价行为。\n\n\n **L783** 从原设计步骤重建工作路径,取消第一种包装额外附加的验证步骤。\n\n\n **L784** 把每个原 contractRunner 步骤移到新组件,同时保留其知识、工具和单位。\n\n\n **L785** 保留每个非验证步骤,完成不改变工作单位的迁移。\n\n\n **L787** 具体同工作量设计是私有设计经验证迁移后的结果。\n\n\n **L789** 开始来源映射注释,把 CoreReader.Engineering.structureNotCapability 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。\n\n\n **L790** 为 CoreReader.Engineering.structureNotCapability 记录源文引用 software-engineering.structural-judgment/p1,该直接正文的 SHA256 为 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L791** 为 CoreReader.Engineering.structureNotCapability 记录源文引用 software-engineering.structural-judgment/p2,该直接正文的 SHA256 为 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L792** 结束 CoreReader.Engineering.structureNotCapability 的源文映射注释;其后恢复可执行声明。\n\n\n **L793** 汇集反例,说明签名、模块数、原则名称及新边界本身不证明所声称能力或更少工作。\n\n\n **L794** 私有设计与排序设计签名相同,却在 [2,1,2] 上产生不同顺序结果;相同接口形状不构成合同等价。\n\n\n **L795** 私有设计与排序设计签名相同,却在 [2,1,2] 上产生不同顺序结果;相同接口形状不构成合同等价。\n\n\n **L796** 私有设计声明的八个模块等于实际组件列表长度。\n\n\n **L797** 它有八项实际记录的批次假设,而非仅模块数量标签。\n\n\n **L798** 运行时批次大小改为五时,八个组件都需修订假设。\n\n\n **L799** 私有设计带有依赖倒置原则名称。\n\n\n **L800** 私有设计与文档化设计共享全部可见元数据。\n\n\n **L801** 尽管有该标签,接任者仍无法修订私有设计,因为路径需要私有布局知识。\n\n\n **L802** 接任者可以通过真正不同、依赖指南的路径修订文档化设计。\n\n\n **L803** 第一种包装把实际边界数从零改为一。\n\n\n **L804** 它也把实际组件数从八增至九。\n\n\n **L805** 新增实际边恰为组件 8→0,并带原列表函数签名。\n\n\n **L806** 第一种包装保留 [2,1,2] 上的原观察输出。\n\n\n **L807** 原私有设计的设计修订需要十七单位。\n\n\n **L808** 第一种包装增加验证步骤后需要十八单位。\n\n\n **L809** 因此,此实际引入边界未减少预期设计修订工作。\n\n\n **L810** 迁移变式同样具有具体边 8→0。\n\n\n **L811** 迁移变式有九个实际组件。\n\n\n **L812** 其设计修订路径因验证组件编号迁移而不同于原路径。\n\n\n **L813** 迁移保留原观察顺序结果。\n\n\n **L814** 其总设定工作量与原路径总量完全相等。\n\n\n **L815** 该未改变总量为十七单位。\n\n\n **L816** 迁移后接任者仍缺少所需私有知识,因此新边界不构成持续能力。\n\n\n **L817** 对实际记录、函数和算术使用判定过程,证明五组具体反例。\n\n\n **L819** 开始来源映射注释,把 CoreReader.Engineering.contractPreservation 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。\n\n\n **L820** 为 CoreReader.Engineering.contractPreservation 记录源文引用 software-engineering.structural-judgment/p3,该直接正文的 SHA256 为 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L821** 结束 CoreReader.Engineering.contractPreservation 的源文映射注释;其后恢复可执行声明。\n\n\n **L822** 一般保持定理对输入输出类型多态,并保留明确提供的范围。\n\n\n **L823** 其前提已经提供范围内每个输入的新旧行为相等。\n\n\n **L824** 把同一全称范围相等作为 PreservesOn 返回;没有从有限测试推出全称保持。\n\n\n **L826** 声明范围内一个实际不同观察足以否定范围保持。\n\n\n **L827** 固定新旧函数、一个输入及该输入属于范围的证明。\n\n\n **L828** 假定该处实际输出不同,推出不可能保持。\n\n\n **L829** 暂时假定范围保持。\n\n\n **L830** 把保持性质应用到范围内反例,与已知输出差异矛盾。\n\n\n **L832** 修订义务定理比较同一组实际新旧可观察合同。\n\n\n **L833** 要求报告已满足保持或修订二选一说明。\n\n\n **L834** 还假定实际有限合同保持失败。\n\n\n **L835** 排除保持分支,剩下报告的修订责任;并非仅从行为改变就生成说明。\n\n\n **L837** 退役行为仅改变不在声明有限语料中的输入 [99],在其他输入保留 orderedUnique。\n\n\n **L838** 退役行为仅改变不在声明有限语料中的输入 [99],在其他输入保留 orderedUnique。\n\n\n **L840** 开始来源映射注释,把 CoreReader.Engineering.contractCases 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。\n\n\n **L841** 为 CoreReader.Engineering.contractCases 记录源文引用 software-engineering.structural-judgment/p3,该直接正文的 SHA256 为 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L842** 结束 CoreReader.Engineering.contractCases 的源文映射注释;其后恢复可执行声明。\n\n\n **L843** 组合保持、有意修订、遗漏参与方被拒及程序灵活性案例。\n\n\n **L844** 重构合同通过有限保持获得有效说明。\n\n\n **L845** 顺序与重试均改变的合同通过实际修订责任获得有效说明。\n\n\n **L846** 空的已承认参与方列表无法说明实际消费者和运维者变化。\n\n\n **L847** 退役行为保持每个声明有限输入,却在 [99] 不同,展示范围限度。\n\n\n **L848** 把程序名称改为 paired audit 仍保留有效说明;没有强制某种特定程序。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。\n\n\n **L850** 开始来源映射注释,把 CoreReader.Engineering.contractDistinctions 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。\n\n\n **L851** 为 CoreReader.Engineering.contractDistinctions 记录源文引用 software-engineering.structural-judgment/p3,该直接正文的 SHA256 为 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L852** 结束 CoreReader.Engineering.contractDistinctions 的源文映射注释;其后恢复可执行声明。\n\n\n **L853** 区分实际顺序保持、重试改变、参与方影响与准确历史合同报告。\n\n\n **L854** 附加空列表的重构保持有限顺序合同。\n\n\n **L855** 先排序再去重不保持同一顺序合同。\n\n\n **L856** 尝试编号三时,原阈值禁止重试,新阈值允许重试,使失败策略变化具体可见。\n\n\n **L857** 因此顺序与重试组合合同并未保持。\n\n\n **L858** 固定依赖映射在此例恰好识别消费者与运维者受影响。\n\n\n **L859** 仅承认消费者会遗漏受重试改变影响的运维者,因此修订说明失败。\n\n\n **L860** 仅承认消费者会遗漏受重试改变影响的运维者,因此修订说明失败。\n\n\n **L861** 把两个报告旧界限字段都改为五仍失败,因为独立实际原合同阈值为三。\n\n\n **L862** 把两个报告旧界限字段都改为五仍失败,因为独立实际原合同阈值为三。\n\n\n **L863** 未篡改的 normalRevision 正确说明有意变更。\n\n\n **L864** 有限保持仍容许 [99] 处有意的范围外差异;它不是所有输入等价。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。\n\n\n **L866** 修订关注带时间索引证据下的当前选择,不改变已经观察到的预测真值。\n\n\n **L867** 修订关注带时间索引证据下的当前选择,不改变已经观察到的预测真值。\n\n\n **L868** 修订状态记录某时刻的证据、维护条件、成本、目标与所选设计。\n\n\n **L869** 用自然数时间编号排列状态。\n\n\n **L870** 记录预期未来变更方向。\n\n\n **L871** 记录预期维护量。\n\n\n **L872** 记录预期由谁维护软件。\n\n\n **L873** 记录相关迁移成本。\n\n\n **L874** 记录目标相对该成本的容量。\n\n\n **L875** 记录在这些条件下所选设计。\n\n\n **L876** 自动为 RevisionState 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。\n\n\n **L877** 修订记录保留实际和已报告状态,以及可单独检查的预测结果和批评覆盖。\n\n\n **L878** 把报告绑定到命名软件任务。\n\n\n **L879** 承载报告所声称的旧状态。\n\n\n **L880** 承载当前状态。\n\n\n **L881** 保留报告记录的旧状态,以与独立历史比较。\n\n\n **L882** 保留其记录的当前状态。\n\n\n **L883** 给出此前预测的批次数。\n\n\n **L884** 给出实际观察批次数。\n\n\n **L885** 记录报告是否宣称预测成功;后续检查把该布尔值绑定到实际历史相等关系。\n\n\n **L886** 列出此次修订考虑的变更方向。\n\n\n **L887** 列出保留在声明批评范围内的方向。\n\n\n **L889** 实质变化针对具体根据,而非仅更晚时间戳或重新标记的选择。\n\n\n **L890** 预期方向或维护量变化属于根据改变。\n\n\n **L891** 维护者改变也改变相关条件。\n\n\n **L892** 迁移成本或目标容量改变构成另一种实质根据差异。\n\n\n **L894** 时间零的旧状态预期设计修订、六单位维护、原维护者、成本八/容量十二,并选择演化方案。\n\n\n **L895** 时间一的新状态预期删除、两单位维护、接任者和代理维护、成本十四/容量十,并选择简单方案。\n\n\n **L897** HistoricalEvidence 是独立于可改报告的输入,固定任务、旧状态及过去预测与观察。\n\n\n **L898** 标识历史事件涉及的软件。\n\n\n **L899** 保留实际历史修订状态。\n\n\n **L900** 独立于新报告保留历史预测。\n\n\n **L901** 独立于报告保留历史观察结果。\n\n\n **L903** 记录事件使用固定为十的预测器,而实际对二十一个元素使用运行时大小五;不匹配作为事件内容保留。\n\n\n **L904** 记录事件使用固定为十的预测器,而实际对二十一个元素使用运行时大小五;不匹配作为事件内容保留。\n\n\n **L905** 把队列历史固定为 oldState,并用两个实际函数得到预测三、实际五。\n\n\n **L906** 把队列历史固定为 oldState,并用两个实际函数得到预测三、实际五。\n\n\n **L908** 对独立提供的历史对象检查报告,而非仅让报告字段相互比较。\n\n\n **L909** 报告软件身份须匹配历史任务。\n\n\n **L910** 报告的旧状态声称与所记录旧状态都须等于独立历史状态。\n\n\n **L911** 报告须保留实际历史预测数。\n\n\n **L912** 它须保留实际历史观察数。\n\n\n **L913** 时间须推进,当前状态记录须准确反映当前状态。\n\n\n **L914** 设计选择改变要求实质根据改变;仅该条件不证明每种此类重新设计都实质合理。\n\n\n **L915** 报告成功标记须等于实际历史预测与观察是否相等的判定,防止事后重标记。\n\n\n **L916** 每个已考虑方向须留在所列批评范围;这种有限覆盖不是自反正确性的普遍证明。\n\n\n **L918** 开始来源映射注释,把 CoreReader.Engineering.RevisionAccount 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。\n\n\n **L919** 为 CoreReader.Engineering.RevisionAccount 记录源文引用 software-engineering.revision/p2,该直接正文的 SHA256 为 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L920** 为 CoreReader.Engineering.RevisionAccount 记录源文引用 software-engineering.revision/p1,该直接正文的 SHA256 为 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L921** 结束 CoreReader.Engineering.RevisionAccount 的源文映射注释;其后恢复可执行声明。\n\n\n **L922** 把通用历史绑定说明专化为固定的已观察队列历史。\n\n\n **L924** 禁止改写结果适用于任意所给历史和报告,不仅针对队列数字。\n\n\n **L925** 假定报告针对同一历史对象满足完整说明。\n\n\n **L926** 假定实际历史预测与观察不同。\n\n\n **L927** 推出准确报告必须标记预测未成功。\n\n\n **L928** 取出说明中的成功标记相等关系,再用历史失败前提化简,得到 false。\n\n\n **L930** 构造常规修订报告,准确记录新旧状态并保留失败预测。\n\n\n **L931** 使用与 observedHistory 相同的保持顺序队列身份。\n\n\n **L932** 实际和已记录状态分别与 oldState、newState 相同。\n\n\n **L933** 使用二十一个元素、运行时大小五时实际 static/live 批次数。\n\n\n **L934** 如实标记该预测未成功。\n\n\n **L935** 考虑全部九个常规方向,并把九个都保留在批评范围内。\n\n\n **L937** 在此保留设计适配器中,有支持的替代方案就是按情境根据解释可信的方向。\n\n\n **L939** 保留设计可由声明的缺少贡献或具体成本条件支持;这是应用准则。\n\n\n **L940** 一个分支要求所有列出的替代方向都缺少情境中的可信支持。\n\n\n **L941** 另一分支通过明确合理的演化成本偏离容许保留设计。\n\n\n **L943** 稳定变式在实际与记录的当前状态中都继续选择演化方案,同时保留变化证据、如实失败预测及批评覆盖。\n\n\n **L944** 稳定变式在实际与记录的当前状态中都继续选择演化方案,同时保留变化证据、如实失败预测及批评覆盖。\n\n\n **L945** 稳定变式在实际与记录的当前状态中都继续选择演化方案,同时保留变化证据、如实失败预测及批评覆盖。\n\n\n **L947** 开始来源映射注释,把 CoreReader.Engineering.revisionCases 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。\n\n\n **L948** 为 CoreReader.Engineering.revisionCases 记录源文引用 software-engineering.revision/p2,该直接正文的 SHA256 为 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L949** 为 CoreReader.Engineering.revisionCases 记录源文引用 software-engineering.revision/p1,该直接正文的 SHA256 为 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L950** 结束 CoreReader.Engineering.revisionCases 的源文映射注释;其后恢复可执行声明。\n\n\n **L951** 展示有效修订,包含五项实质根据差异、保留的预测失败及两种保留设计理由。\n\n\n **L952** 常规报告满足针对固定独立历史的说明。\n\n\n **L953** 其预测从设计修订改为删除。\n\n\n **L954** 其维护量从六改为二。\n\n\n **L955** 其维护者集合从原作者改为接任者与代理。\n\n\n **L956** 其迁移成本从八改为十四。\n\n\n **L957** 其目标容量从十二改为十。\n\n\n **L958** 预测三仍不同于实际五;修订决定不改变此次失败。\n\n\n **L959** 缺少可信根据的量子后端替代方向构成无支持替代方案的保留案例。\n\n\n **L960** 真实迁移容量威胁构成基于成本的保留案例。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。\n\n\n **L962** 成功观察集仅使用运行时大小十,元素数分别为二十一、三十和四十。\n\n\n **L963** 记录三个修订编号;仅数量不会证明正确。\n\n\n **L964** 每名评审者都报告同一静态预测结果,表示意见一致,却不增加独立支持或改变实际预测器。\n\n\n **L965** 每名评审者都报告同一静态预测结果,表示意见一致,却不增加独立支持或改变实际预测器。\n\n\n **L967** 第一种篡改变式同时改变声称与记录的旧预测,以检验报告字段彼此一致仍不能覆盖独立历史。\n\n\n **L968** 第一种篡改变式同时改变声称与记录的旧预测,以检验报告字段彼此一致仍不能覆盖独立历史。\n\n\n **L969** 第一种篡改变式同时改变声称与记录的旧预测,以检验报告字段彼此一致仍不能覆盖独立历史。\n\n\n **L971** 第二种变式把预测数改为五并宣称成功,试图改写旧预测以匹配观察。\n\n\n **L972** 第二种变式把预测数改为五并宣称成功,试图改写旧预测以匹配观察。\n\n\n **L974** 第三种变式把观察数改为三并宣称预测成功,试图改写实际事件。\n\n\n **L975** 第三种变式把观察数改为三并宣称预测成功,试图改写实际事件。\n\n\n **L977** 身份变式保留数字数据却把报告分配给无关软件,以检验任务绑定。\n\n\n **L978** 身份变式保留数字数据却把报告分配给无关软件,以检验任务绑定。\n\n\n **L980** 展示固定历史证据如何拒绝报告字段联动篡改及软件身份替换。\n\n\n **L981** 未修改报告保持有效。\n\n\n **L982** 同时修改两个旧状态字段无法满足独立固定历史。\n\n\n **L983** 改写预测数与成功标记被拒绝。\n\n\n **L984** 改写观察数与成功标记也被拒绝。\n\n\n **L985** 所有这些变式中,独立历史始终保留预测三与观察五。\n\n\n **L986** 无关软件的报告不满足任务身份要求。\n\n\n **L987** 不修改历史对象,通过计算证明七项具体有效性、失败和历史数字结论。\n\n\n **L989** 开始来源映射注释,把 CoreReader.Engineering.revisionLimits 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。\n\n\n **L990** 为 CoreReader.Engineering.revisionLimits 记录源文引用 software-engineering.revision/p2,该直接正文的 SHA256 为 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L991** 为 CoreReader.Engineering.revisionLimits 记录源文引用 software-engineering.revision/p1,该直接正文的 SHA256 为 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99。这是可追踪绑定,不是新增前提或语义证明。\n\n\n **L992** 结束 CoreReader.Engineering.revisionLimits 的源文映射注释;其后恢复可执行声明。\n\n\n **L993** 组合事后成功重标记、修订次数、意见一致、重复局部成功及合理稳定的限度。\n\n\n **L994** 常规历史说明有效。\n\n\n **L995** 仅把 reportedPredictionSucceeded 改为 true 就使说明无效。\n\n\n **L996** 明确列表中出现三次修订,但数量不提供正确性定理。\n\n\n **L997** 三名维护者都同意静态结果三,但实时结果为五;一致意见不消除反例。\n\n\n **L998** 每个已列大小十观察中,静态和实时预测器均一致。\n\n\n **L999** 这些重复成功与运行时大小五处的失败并存。\n\n\n **L1000** 稳定报告保持历史有效并延续原设计选择,表明修订开放性不强迫每次行动都改变设计。\n\n\n **L1001** 无支持的量子后端替代方向仍允许保留当前设计。\n\n\n **L1002** 用有限判定构造合取,只留下虚报成功说明待明确展开。\n\n\n **L1003** 用有限判定构造合取,只留下虚报成功说明待明确展开。\n\n\n **L1004** 展开固定历史、实际报告和实质变化谓词,使虚假成功声称显露为具体三与五不等。\n\n\n **L1005** 通过计算检查剩余可判定矛盾。\n\n\n **L1007** 不论根据构造子为何,都提取记录列出的方向;该提取仅记录预测内容,本身不证明可信性。\n\n\n **L1008** 不论根据构造子为何,都提取记录列出的方向;该提取仅记录预测内容,本身不证明可信性。\n\n\n **L1010** 从实际情境与所选设计构造当前修订状态,而非使用无关联报告占位值。\n\n\n **L1011** 设时间为一,并把实际情境证据所列方向串接为预测。\n\n\n **L1012** 从同一活动复制维护量和参与维护者。\n\n\n **L1013** 使用所选设计实际设定的迁移成本。\n\n\n **L1014** 使用同一情境的迁移目标容量。\n\n\n **L1015** 记录实际所选候选。\n\n\n **L1017** 报告保留 stableRecord 的历史数据,但把软件、实际当前状态和记录当前状态绑定到此情境与所选候选。\n\n\n **L1018** 报告保留 stableRecord 的历史数据,但把软件、实际当前状态和记录当前状态绑定到此情境与所选候选。\n\n\n **L1020** 检查实例化修订报告确实属于共享工程情境,并满足固定历史说明。\n\n\n **L1021** 其软件标识等于活动实际标识。\n\n\n **L1022** 同一标识匹配历史证据,且当前维护量等于活动计划。\n\n\n **L1023** 同一标识匹配历史证据,且当前维护量等于活动计划。\n\n\n **L1024** 当前维护者等于实际参与者列表。\n\n\n **L1025** 当前迁移成本等于演化方案设定成本。\n\n\n **L1026** 当前目标容量等于共享情境迁移容量。\n\n\n **L1027** 当前目标容量等于共享情境迁移容量。\n\n\n **L1028** 记录的当前选择实际为演化方案。\n\n\n **L1029** 完整绑定报告满足 RevisionAccount;这些具体检查由实际字段计算判定。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。\n\n\n **L1031** 完整领域组合在同一情境保留实际主体、可信性、说明和修订责任;所选有限应用记录不声称普遍工程充分性。\n\n\n **L1032** 完整领域组合在同一情境保留实际主体、可信性、说明和修订责任;所选有限应用记录不声称普遍工程充分性。\n\n\n **L1033** 完整领域组合在同一情境保留实际主体、可信性、说明和修订责任;所选有限应用记录不声称普遍工程充分性。\n\n\n **L1034** 组合同一情境与所选设计的已表示领域义务。此组合没有无条件的 Meets 字段;优先适用性并不是整体需求拒绝检查。\n\n\n **L1035** 要求 ActivityScope 及条件式 EvolutionPriority。若 PriorityConditions 为假,该蕴含空真;此合取项不会因需求未满足而拒绝选择,其余领域义务仍须履行。\n\n\n **L1036** 要求设计修订方向具备实际可信根据。\n\n\n **L1037** 若记录了偏离,就须是合理具体成本偏离;没有偏离记录不会额外创造例外。\n\n\n **L1038** 要求接任者具有实际设计修订能力,并明确采用修订义务方式。\n\n\n **L1039** 要求结构说明匹配同一活动、所选候选和设计修订证据。\n\n\n **L1040** 要求保持或修订说明比较所选设计顺序合同与实际设计修订合同。\n\n\n **L1041** 要求同一情境与候选的修订报告满足固定独立历史说明。\n\n\n **L1043** 为共享持续演化示例构造实际完整领域满足。\n\n\n **L1044** 计算具体主体、优先、可信性、变更、结构、合同和历史义务,留下条件偏离检查。\n\n\n **L1045** 常规情境记录 departure=none,因此要求已记录偏离具有理由的蕴含空真;优先规范本身仍实际适用,且没有成本逃逸。\n\n\n **L1047** 结束工程命名空间;以上声明仍可通过 CoreReader.Engineering 访问。\n\n\n### `leanified/CoreReader/Engineering/Integration.lean`\n\n\n```lean\nimport CoreReader.Engineering.Domain\nimport CoreReader.Engineering.Reflection\nimport CoreReader.Engineering.SelfApplication\n\nnamespace CoreReader.Engineering\n\nopen CoreReader.Logic CoreReader.Evidence CoreReader.Adopted\n\n/- All interpretations below share this activity, requirements, evidence and\ncost limits. Only the selected implementation and its stated value priority vary. -/\nabbrev sharedContext : Context := currentContinuing\n\ndef maintainedOutput (chosen : Candidate) (n : Nat) : Nat :=\n (behavior chosen [n]).headD 0\n\ndef chosenImplementation (chosen : Candidate) : CoreReader.Choice.Implementation where\n name := \"order-preserving queue\"\n conventional := chosen == .presentSimple\n established := chosen == .presentSimple\n run := maintainedOutput chosen\n cost := abstractionComplexity chosen\n domain _ := True\n explanation := maintainedOutput chosen\n trace n := [maintainedOutput chosen n]\n\n/- This Core choice projection checks the queue's one-item observable contract\nand present understanding budget. Domain retains its additional required checks. -/\ndef chosenRequirements : CoreReader.Choice.Requirements where\n inputs _ := True\n expected n := n\n budget := sharedContext.limits.capacity .understanding\n values _ := True\n\ndef chosenReasons : List CoreReader.Choice.Reason :=\n [.method .output, .method .simplicity]\n\ntheorem maintainedOutputCorrect (chosen : Candidate) (n : Nat) :\n maintainedOutput chosen n = n := by\n rfl\n\ntheorem implementationReasoned (chosen : Candidate)\n (budget : abstractionComplexity chosen ≤ chosenRequirements.budget) :\n choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons := by\n refine ⟨⟨fun n _ => maintainedOutputCorrect chosen n, budget⟩,\n .method .output, ?_, ?_⟩\n · simp [chosenReasons]\n · exact ⟨trivial, fun n _ => maintainedOutputCorrect chosen n⟩\n\n/- This reported capability concerns actual paths for each maintainer. Zero\nrecords the unavailable path, not an assertion that an unsupported path exists. -/\ndef capabilityOutput (chosen : Candidate) (input : Nat) : Nat :=\n let maintainer := if input = 0 then Maintainer.original\n else if input = 1 then Maintainer.successor else Maintainer.agent\n if decide (CanChange sharedContext.activity chosen maintainer .designRevision)\n then changeWork chosen .designRevision else 0\n\ndef engineeringProcess (chosen : Candidate) : Process :=\n ⟨capabilityOutput chosen, none⟩\n\ndef engineeringCapability (chosen : Candidate) : Claim Process :=\n fun process => ∀ input, process.output input = capabilityOutput chosen input\n\ntheorem engineeringCapabilityGrounded (chosen : Candidate) :\n capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen) := by\n exact grounds012Singleton _ (processContractDischarged _ _ (fun _ => rfl))\n\ntheorem actualCapabilityContrast :\n (engineeringProcess .presentSimple).output 0 = 17 ∧\n (engineeringProcess .presentSimple).output 1 = 0 ∧\n (engineeringProcess .presentSimple).output 2 = 0 ∧\n (engineeringProcess .evolvable).output 0 = 6 ∧\n (engineeringProcess .evolvable).output 1 = 6 ∧\n (engineeringProcess .evolvable).output 2 = 6 := by decide\n\n/- A recorded threshold test measures present abstraction complexity in this\nfinite model. It does not observe future maintainability or establish a value. -/\ndef presentBudgetRecord : Record Candidate :=\n ⟨fun candidate => decide (abstractionComplexity candidate ≤ 3), true⟩\n\nabbrev presentBudgetClaim : Claim Candidate := fun candidate => abstractionComplexity candidate ≤ 3\n\ntheorem budgetObservationMeaning (candidate : Candidate) :\n Compatible [presentBudgetRecord] candidate ↔ presentBudgetClaim candidate := by\n constructor\n · intro observed\n have result := observed presentBudgetRecord (List.mem_singleton.mpr rfl)\n exact of_decide_eq_true result\n · intro enough record member\n cases List.mem_singleton.mp member\n exact decide_eq_true enough\n\ndef budgetEmpiricalFacet : Facet Candidate :=\n .empirical [presentBudgetRecord] (fun _ => True) presentBudgetClaim (fun _ => True)\n\ntheorem budgetEmpiricalDischarged : FacetDischarged budgetEmpiricalFacet := by\n refine ⟨⟨.evolvable, (budgetObservationMeaning _).2 (by decide), trivial⟩, ?_, ?_⟩\n · intro candidate observed _\n exact (budgetObservationMeaning candidate).1 observed\n · intro _ _; trivial\n\ndef capacityClaim : Claim Candidate :=\n fun candidate => abstractionComplexity candidate ≤ sharedContext.limits.capacity .understanding\n\ndef capacityAssumptions : Theory Candidate := singleton presentBudgetClaim\n\ndef budgetInferentialFacet : Facet Candidate := .inferential capacityAssumptions capacityClaim\n\ntheorem budgetInferentialDischarged : FacetDischarged budgetInferentialFacet := by\n refine ⟨⟨.evolvable, (modelsSingleton _ _).2 (by decide)⟩, ?_⟩\n intro candidate premises\n have small := (modelsSingleton _ _).1 premises\n exact Nat.le_trans small (by decide)\n\ndef budgetScopeAccount : ScopeAccount Candidate where\n claim := presentBudgetClaim\n conditions := fun _ => True\n observationScope := fun _ => True\n relevant := fun a b => behavior a [2, 1, 2] = behavior b [2, 1, 2]\n compared := fun a b => presentBudgetClaim a ∧ presentBudgetClaim b\n used method := method = .measurement\n role _ := \"threshold observation of present complexity; no future-performance conclusion\"\n explains method text claim conditions := method = .measurement ∧\n text = \"threshold observation of present complexity; no future-performance conclusion\" ∧\n claim = presentBudgetClaim ∧ conditions = (fun _ => True)\n\ntheorem budgetScopeExplained : scopeSpecification budgetScopeAccount := by\n constructor\n · intro a b _; exact ⟨trivial, trivial, trivial, trivial, rfl⟩\n · intro method hm\n exact ⟨by change \"threshold observation of present complexity; no future-performance conclusion\" ≠ \"\"; decide,\n hm, rfl, rfl, rfl⟩\n\n/- The unchanged observation cannot justify a stronger complexity bound. -/\ntheorem budgetObservationLimit :\n Compatible [presentBudgetRecord] .evolvable ∧\n ¬ Supports [presentBudgetRecord] (fun candidate => abstractionComplexity candidate ≤ 1) := by\n refine ⟨(budgetObservationMeaning _).2 (by decide), ?_⟩\n intro support\n have impossible := support .evolvable ((budgetObservationMeaning _).2 (by decide))\n exact (by decide : ¬ (3 ≤ 1)) impossible\n\n/- The policy values expansion while keeping every represented organization,\nmethod and principle form revisable. It does not assert that a revision occurs. -/\ndef engineeringPolicy : CoreReader.Agency.Policy where\n worthPursuing aim :=\n (aim = .expandUnderstandingAndConstruction ∧ coreAdopted .generation = true) ∨\n aim = .preserveSafeOperation\n current form := form.version = 1\n revisable form := ∃ next, form.version < next ∧ coreAdopted .generation = true\n permitsVersion old next := old ≤ next\n\ntheorem engineeringGenerative : generationSpecification engineeringPolicy := by\n exact ⟨Or.inl ⟨rfl, rfl⟩, fun form _ => ⟨form.version + 1, Nat.lt_succ_self _, rfl⟩⟩\n\n/- Own facts are mathematical reports about this model and its recorded state.\nTheir inferential tasks do not replace the separate empirical or value tasks. -/\ninductive OwnFact\n | selected | requirements | capacity | capability | forecast | revision\n | generativePolicy | reflection | coreAdoption (principle : CoreCommitment)\n deriving DecidableEq, Repr\n\nabbrev ownFactClaim (adopted : Candidate) : OwnFact → Claim Candidate\n | .selected => fun candidate => candidate = adopted\n | .requirements => fun candidate => Meets sharedContext.required (sharedContext.profiles candidate)\n | .capacity => capacityClaim\n | .capability => fun candidate => engineeringCapability candidate (engineeringProcess candidate)\n | .forecast => fun _ => staticBatch 21 10 = liveBatch 21 10 ∧ staticBatch 21 5 ≠ liveBatch 21 5\n | .revision => fun candidate => RevisionAccount (revisionFor sharedContext candidate)\n | .generativePolicy => fun _ => generationSpecification engineeringPolicy\n | .reflection => fun candidate => reflexivitySpecification\n (selfModel candidate).rules (selfModel candidate).self (selfModel candidate).performed\n | .coreAdoption principle => (governancePosition principle).commitment\n\ntheorem actualOwnFact (chosen : Candidate)\n (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) (fact : OwnFact) :\n ownFactClaim chosen fact chosen := by\n cases fact with\n | selected => rfl\n | requirements => cases chosen <;> decide\n | capacity => rcases ordinary with rfl | rfl <;> change _ ≤ 12 <;> decide\n | capability => intro _; rfl\n | forecast => exact ⟨rfl, by decide⟩\n | revision => rcases ordinary with rfl | rfl <;> decide\n | generativePolicy => exact engineeringGenerative\n | reflection => exact currentSelfApplication chosen ordinary\n | coreAdoption _ => rfl\n\ndef ownFactPremises (chosen : Candidate) : Theory Candidate :=\n singleton (fun candidate => candidate = chosen)\n\ntheorem actualOwnFactGrounded (chosen : Candidate)\n (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) (fact : OwnFact) :\n inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact) := by\n apply grounds012Singleton\n refine ⟨⟨chosen, (modelsSingleton _ _).2 rfl⟩, ?_⟩\n intro candidate same\n have identity := (modelsSingleton _ _).1 same\n subst candidate\n exact actualOwnFact chosen ordinary fact\n\n/- In this fixed applicable context, the actual priority rule and the adopted\nevolution value select exactly the same candidate. This identity connects its\nvalue grounds to the normative rule, not merely to an adoption label. -/\ntheorem priorityValueMeaning (candidate : Candidate) :\n (selectionPosition .evolvable).commitment candidate ↔\n EvolutionPriority sharedContext candidate := by\n constructor\n · intro selected\n change candidate = .evolvable at selected\n subst candidate\n exact currentDomainSatisfied.2.1\n · intro priority\n exact (priorityWhenApplicable sharedContext candidate priority\n currentPriorityConditions currentNoThreat.2).1\n\ntheorem priorityGrounds :\n Grounds012 (EvolutionPriority sharedContext) canonicalArticulation\n [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) := by\n have same : (selectionPosition .evolvable).commitment = EvolutionPriority sharedContext :=\n funext (fun candidate => propext (priorityValueMeaning candidate))\n rw [← same]\n exact selectionGrounded .evolvable (Or.inr rfl)\n\n/- Facts of adoption remain distinct from the actual normative contents. Each\nconstructor below denotes its full represented duty, with its original task,\nconditions, reasons and scope. Domain duties enter only for the domain adopter.\nConsistency is the constraint on the resulting whole theory below; it is not\nencoded as a self-referential proposition in that theory's own definition. -/\ninductive OwnNorm\n | generation | reflection | empirical | inferential | principleValue (principle : CoreCommitment)\n | selectionValue | scope | capability | choice | ownGrounds (fact : OwnFact)\n | domain | priorityValue\n deriving DecidableEq, Repr\n\ndef normApplies (adopted : Candidate) : OwnNorm → Prop\n | .domain | .priorityValue => adopted = .evolvable\n | _ => True\n\ndef ownNormClaim (adopted : Candidate) : OwnNorm → Claim Candidate\n | .generation => fun _ => generationSpecification engineeringPolicy\n | .reflection => fun candidate => reflexivitySpecification\n (selfModel candidate).rules (selfModel candidate).self (selfModel candidate).performed\n | .empirical => fun _ => empiricalSpecification [presentBudgetRecord] (fun _ => True)\n presentBudgetClaim (fun _ => True)\n | .inferential => fun _ => inferentialSpecification capacityAssumptions capacityClaim\n | .principleValue principle => fun _ => valueSpecification (governancePosition principle)\n | .selectionValue => fun candidate => valueSpecification (selectionPosition adopted) ∧\n (selectionPosition adopted).commitment candidate\n | .scope => fun _ => scopeSpecification budgetScopeAccount\n | .capability => fun candidate => capabilitySpecification\n (engineeringProcess candidate) (engineeringCapability candidate)\n | .choice => fun candidate => choiceSpecification\n chosenRequirements (chosenImplementation candidate) chosenReasons\n | .ownGrounds fact => fun _ => inferentialSpecification\n (ownFactPremises adopted) (ownFactClaim adopted fact)\n | .domain => fun candidate => DomainSatisfied sharedContext candidate\n | .priorityValue => fun _ => Grounds012 (EvolutionPriority sharedContext) canonicalArticulation\n [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable))\n\ntheorem actualOwnNorm (chosen : Candidate)\n (ordinary : chosen = .presentSimple ∨ chosen = .evolvable)\n (norm : OwnNorm) (applicable : normApplies chosen norm) : ownNormClaim chosen norm chosen := by\n cases norm with\n | generation => exact engineeringGenerative\n | reflection => exact currentSelfApplication chosen ordinary\n | empirical => exact grounds012Singleton _ budgetEmpiricalDischarged\n | inferential => exact grounds012Singleton _ budgetInferentialDischarged\n | principleValue principle => exact governanceGrounded principle\n | selectionValue => exact ⟨selectionGrounded chosen ordinary, rfl⟩\n | scope => exact budgetScopeExplained\n | capability => exact engineeringCapabilityGrounded chosen\n | choice =>\n apply implementationReasoned\n rcases ordinary with rfl | rfl <;> change _ ≤ 12 <;> decide\n | ownGrounds fact => exact actualOwnFactGrounded chosen ordinary fact\n | domain =>\n change chosen = .evolvable at applicable\n subst chosen\n exact currentDomainSatisfied\n | priorityValue => exact priorityGrounds\n\ndef ownFactTheory (chosen : Candidate) : Theory Candidate :=\n fun claim => ∃ fact : OwnFact, claim = ownFactClaim chosen fact\n\ndef ownNormTheory (chosen : Candidate) : Theory Candidate :=\n fun claim => ∃ norm : OwnNorm, normApplies chosen norm ∧ claim = ownNormClaim chosen norm\n\n/- The consequence relation now acts on all these facts and normative contents\ntogether, including the implications of their union. -/\ndef ownTheory (chosen : Candidate) : Theory Candidate :=\n union (ownFactTheory chosen) (ownNormTheory chosen)\n\ntheorem allNormativeContentHeld (chosen : Candidate) (norm : OwnNorm)\n (applicable : normApplies chosen norm) : ownTheory chosen (ownNormClaim chosen norm) :=\n Or.inr ⟨norm, applicable, rfl⟩\n\ntheorem nonemptyOwnObjects (chosen : Candidate) :\n ownTheory chosen (ownFactClaim chosen .selected) ∧\n ownTheory chosen (ownFactClaim chosen (.coreAdoption .grounds)) ∧\n (.activity : ReviewObject) ∈ (selfModel chosen).objects ∧\n (.commitment .grounds : ReviewObject) ∈ (selfModel chosen).objects := by\n refine ⟨Or.inl ⟨.selected, rfl⟩, Or.inl ⟨.coreAdoption .grounds, rfl⟩, ?_, ?_⟩ <;>\n simp [selfModel, reviewObjects, coreCommitments]\n\ndef comparisonContext (chosen : Candidate) : CoreReader.Logic.Context Candidate OwnFact where\n assumptions := ownFactPremises chosen\n meaning := ownFactClaim chosen\n scope := valueScope\n\ndef engineeringSnapshot (chosen : Candidate) (revision : Nat) : Snapshot Candidate OwnFact :=\n ⟨ownTheory chosen, comparisonContext chosen, revision⟩\n\ntheorem currentAdmissible (chosen : Candidate)\n (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) :\n Admissible (ownTheory chosen) (comparisonContext chosen) chosen := by\n refine ⟨?_, (modelsSingleton _ _).2 rfl, ?_⟩\n · intro claim held\n rcases held with factHeld | normHeld\n · obtain ⟨fact, rfl⟩ := factHeld\n exact actualOwnFact chosen ordinary fact\n · obtain ⟨norm, applicable, rfl⟩ := normHeld\n exact actualOwnNorm chosen ordinary norm applicable\n · rcases ordinary with rfl | rfl <;> change _ ≤ 3 <;> decide\n\ntheorem currentConsistency (chosen : Candidate)\n (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) :\n consistencySpecification (engineeringSnapshot .evolvable 0)\n (engineeringSnapshot chosen 1) true := by\n exact ⟨consequenceConsistency _ _ ⟨chosen, currentAdmissible chosen ordinary⟩, fun _ => rfl⟩\n\ntheorem wholeClaimGrounded (chosen : Candidate)\n (ordinary : chosen = .presentSimple ∨ chosen = .evolvable)\n (claim : Claim Candidate) (held : ownTheory chosen claim) :\n inferentialSpecification (ownFactPremises chosen) claim := by\n apply grounds012Singleton\n refine ⟨⟨chosen, (modelsSingleton _ _).2 rfl⟩, ?_⟩\n intro candidate same\n have identity := (modelsSingleton _ _).1 same\n subst candidate\n exact (currentAdmissible chosen ordinary).1 claim held\n\n/- Keeping the same adoption marker does not conceal contradictory normative\ncontents. Both demands act on the very same candidate, question and scope. -/\ndef incompatibleNormTheory : Theory Candidate :=\n union (singleton (fun candidate => candidate = .presentSimple))\n (singleton (fun candidate => candidate ≠ .presentSimple))\n\ndef incompatibleNormContext : CoreReader.Logic.Context Candidate Unit :=\n ⟨emptyTheory, fun _ candidate => candidate = .presentSimple, fun _ => True⟩\n\ntheorem normativeContentVariation :\n coreAdopted .choice = true ∧\n ¬ Consistent incompatibleNormTheory incompatibleNormContext ∧\n normApplies .evolvable .domain ∧ ¬ normApplies .presentSimple .domain ∧\n ownTheory .evolvable (ownNormClaim .evolvable .domain) ∧\n ¬ ownTheory .presentSimple (ownNormClaim .presentSimple .domain) := by\n refine ⟨rfl, ?_, rfl, by unfold normApplies; decide, allNormativeContentHeld _ _ rfl, ?_⟩\n · apply conflictRequiresChange _ _ ()\n · intro candidate admissible\n change candidate = .presentSimple\n exact (modelsSingleton (fun c : Candidate => c = .presentSimple) candidate).1\n ((modelsUnion _ _ _).1 admissible.1).1\n · intro candidate admissible\n change candidate ≠ .presentSimple\n exact (modelsSingleton (fun c : Candidate => c ≠ .presentSimple) candidate).1\n ((modelsUnion _ _ _).1 admissible.1).2\n · intro held\n have domain := (currentAdmissible .presentSimple (Or.inl rfl)).1 _ held\n exact currentSimpleViolates domain.2.1\n\n/- Every field is an actual satisfaction or support condition. Value accounts\nand assessment completion do not replace the normative fields they explain.\nThe identity field limits this implementation to its disclosed common context. -/\nstructure Inherited (ctx : Context) (chosen : Candidate) : Prop where\n sameContext : ctx = sharedContext\n generation : generationSpecification engineeringPolicy\n consistency : consistencySpecification (engineeringSnapshot .evolvable 0)\n (engineeringSnapshot chosen 1) true\n reflection : reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self\n (selfModel chosen).performed\n ownPrincipleGrounds : ∀ principle, valueSpecification (governancePosition principle)\n choiceValueGrounds : valueSpecification (selectionPosition chosen)\n empiricalGrounds : empiricalSpecification [presentBudgetRecord] (fun _ => True)\n presentBudgetClaim (fun _ => True)\n inferentialGrounds : inferentialSpecification capacityAssumptions capacityClaim\n scopeAccount : scopeSpecification budgetScopeAccount\n capabilityGrounds : capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen)\n implementationChoice : choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons\n ownClaimGrounds : ∀ fact, inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact)\n observedHere : Compatible [presentBudgetRecord] chosen\n selectionActuallyAdopted : (selectionPosition chosen).commitment chosen\n currentOwnClaims : Models (ownTheory chosen) chosen\n fullNormativeContents : ∀ norm, normApplies chosen norm →\n ownTheory chosen (ownNormClaim chosen norm)\n wholeClaimGrounds : ∀ claim, ownTheory chosen claim →\n inferentialSpecification (ownFactPremises chosen) claim\n\ntheorem inheritedCurrent (chosen : Candidate)\n (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) :\n Inherited sharedContext chosen := by\n refine ⟨rfl, engineeringGenerative, currentConsistency chosen ordinary,\n currentSelfApplication chosen ordinary, governanceGrounded,\n selectionGrounded chosen ordinary, grounds012Singleton _ budgetEmpiricalDischarged,\n grounds012Singleton _ budgetInferentialDischarged, budgetScopeExplained,\n engineeringCapabilityGrounded chosen, ?_, actualOwnFactGrounded chosen ordinary,\n ?_, rfl, (currentAdmissible chosen ordinary).1,\n allNormativeContentHeld chosen, wholeClaimGrounded chosen ordinary⟩\n · apply implementationReasoned\n rcases ordinary with rfl | rfl <;> change _ ≤ 12 <;> decide\n · apply (budgetObservationMeaning _).2\n rcases ordinary with rfl | rfl <;> change _ ≤ 3 <;> decide\n\n/- Mutual application extracts duties for the same system, principles, claims\nand actual chosen implementation. It retains the full Inherited premise. -/\n/-- organon-map CoreReader.Engineering.inheritedMutualApplication\norganon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\ntheorem inheritedMutualApplication (ctx : Context) (chosen : Candidate)\n (inherited : Inherited ctx chosen) :\n generationSpecification engineeringPolicy ∧\n reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self\n (selfModel chosen).performed ∧\n (∀ principle, valueSpecification (governancePosition principle)) ∧\n capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen) ∧\n choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons ∧\n (∀ fact, inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact)) ∧\n (∀ norm, normApplies chosen norm → ownTheory chosen (ownNormClaim chosen norm)) ∧\n (∀ claim, ownTheory chosen claim → inferentialSpecification (ownFactPremises chosen) claim) ∧\n consistencySpecification (engineeringSnapshot .evolvable 0)\n (engineeringSnapshot chosen 1) true :=\n ⟨inherited.generation, inherited.reflection, inherited.ownPrincipleGrounds,\n inherited.capabilityGrounds, inherited.implementationChoice, inherited.ownClaimGrounds,\n inherited.fullNormativeContents, inherited.wholeClaimGrounds, inherited.consistency⟩\n\n/-- organon-map CoreReader.Engineering.inheritedMutualCases\norganon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\n-/\ntheorem inheritedMutualCases :\n Inherited sharedContext .evolvable ∧\n valueSpecification (governancePosition .grounds) ∧\n capabilitySpecification (engineeringProcess .evolvable) (engineeringCapability .evolvable) ∧\n choiceSpecification chosenRequirements (chosenImplementation .evolvable) chosenReasons ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧\n (.generationRule : ReviewObject) ∈ (selfModel .evolvable).objects ∧\n (.assessmentRule : ReviewObject) ∈ (selfModel .evolvable).objects ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .assessmentRule, .revision⟩) = .counterexample :=\n ⟨inheritedCurrent .evolvable (Or.inr rfl), governanceGrounded .grounds,\n engineeringCapabilityGrounded .evolvable,\n (inheritedCurrent .evolvable (Or.inr rfl)).implementationChoice,\n (actualSelfCriticism .evolvable).2.2.1,\n (ownRuleIdentity .evolvable .generation .revision).1,\n (ownRuleIdentity .evolvable .assessment .revision).1,\n (ownRuleContentVariation .evolvable).2.2.2.2.1⟩\n\n/- In the adopter's same context, the actual priority object and its own\nassessment method remain within the inherited criticism/generation contract. -/\n/-- organon-map CoreReader.Engineering.priorityRemainsReflexive\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\nextensions#p1 sha256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66\nsoftware-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\nsoftware-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99\n-/\ntheorem priorityRemainsReflexive (ctx : Context) (chosen : Candidate)\n (inherited : Inherited ctx chosen) (domain : DomainSatisfied ctx chosen)\n (applicable : PriorityConditions ctx) (noDeparture : ¬ JustifiedDeparture ctx .evolvable) :\n chosen = .evolvable ∧\n (.priority : ReviewObject) ∈ (selfModel chosen).objects ∧\n reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self\n (selfModel chosen).performed ∧\n (∀ principle, valueSpecification (governancePosition principle)) ∧\n Grounds012 (EvolutionPriority ctx) canonicalArticulation\n [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) ∧\n ownTheory chosen (ownNormClaim chosen .domain) ∧\n consistencySpecification (engineeringSnapshot .evolvable 0)\n (engineeringSnapshot chosen 1) true := by\n have selected := (priorityWhenApplicable ctx chosen domain.2.1 applicable noDeparture).1\n refine ⟨selected, ?_, inherited.reflection, inherited.ownPrincipleGrounds,\n ?_, allNormativeContentHeld chosen .domain selected, inherited.consistency⟩\n · subst chosen; decide\n · rw [inherited.sameContext]\n exact priorityGrounds\n\n/-- organon-map CoreReader.Engineering.priorityReflexiveCases\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\nextensions#p1 sha256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66\nsoftware-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\nsoftware-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99\n-/\ntheorem priorityReflexiveCases :\n (.priority : ReviewObject) ∈ (selfModel .evolvable).objects ∧\n objectTest .priority (.evolvable, 10) = true ∧\n (selfModel .evolvable).performed ⟨0, 1⟩ ⟨0, .priority, .revision⟩\n ((selfModel .evolvable).input ⟨0, .priority, .revision⟩)\n (.assessed .supportedWithinScope) ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧\n objectTest .evolutionMethod (.evolvable, 10) = true ∧\n objectTest .evolutionMethod (.evolvable, 5) = false ∧\n Grounds012 (EvolutionPriority sharedContext) canonicalArticulation\n [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) ∧\n Reflection.evaluate ((selfModel .evolvable).input ⟨0, .assessmentRule, .revision⟩) = .counterexample := by\n refine ⟨by decide, by decide, ?_, (actualSelfCriticism .evolvable).2.2.1,\n (actualSelfCriticism .evolvable).1, (actualSelfCriticism .evolvable).2.1,\n priorityGrounds, (ownRuleContentVariation .evolvable).2.2.2.2.1⟩\n exact ⟨⟨rfl, by decide⟩, rfl, .assessment, rfl, rfl⟩\n\n/- The witness is nonempty and satisfies the entire represented inherited and\ndomain bundles in the very same continuing activity, with active priority. -/\n/-- organon-map CoreReader.Engineering.jointWitness\norganon.charter.overview#p2 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c\norganon.charter.overview#p3 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c\norganon.charter.self-transcendence#p1 sha256 f4ca590e2ae15e3882f70c7b2bc46a8911c97cee547c8b137b5493fbf862c8c0\norganon.charter.self-transcendence.orientation#p1 sha256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf\norganon.charter.self-transcendence.non-finality#p1 sha256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8\norganon.charter.self-transcendence.limits#p1 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d\norganon.charter.self-transcendence.limits#p2 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d\norganon.charter.consistency#p1 sha256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42\norganon.charter.consistency.meaning#p1 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa\norganon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75\norganon.charter.reflexivity#p1 sha256 13293b45c2fa89068c68ae7ef3c5df38f0efadb3ef3873d78a5ba67d9691a757\norganon.charter.reflexivity.meaning#p1 sha256 8a2caede01a43d8b6c60b54c78ac089c51868e9956f316948077ccee2e45c9cc\norganon.charter.reflexivity.limits#p1 sha256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc\norganon.grounds#p1 sha256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6\norganon.grounds.assessment#p1 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d\norganon.grounds.scope#p1 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.scope#p2 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.scope#p3 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693\norganon.grounds.capabilities#p1 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0\norganon.grounds.capabilities#p2 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0\norganon.grounds.implementations#p1 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c\norganon.grounds.implementations#p2 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c\norganon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870\norganon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\nextensions#p1 sha256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66\nsoftware-engineering.purpose#p1 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.purpose#p2 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b\nsoftware-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-meaning#p1 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6\nsoftware-engineering.evolution-meaning#p2 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6\nsoftware-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\nsoftware-engineering.structural-judgment#p2 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\nsoftware-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42\nsoftware-engineering.revision#p1 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99\nsoftware-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99\n-/\ntheorem jointWitness :\n ∃ ctx : Context, ∃ chosen : Candidate,\n ctx = sharedContext ∧ chosen = .evolvable ∧\n Inherited ctx chosen ∧ DomainSatisfied ctx chosen ∧\n PriorityConditions ctx ∧ ¬ HasThreat ctx .evolvable ∧\n abstractionComplexity .presentSimple < abstractionComplexity chosen ∧\n CanChange ctx.activity chosen .successor .designRevision ∧\n CanChange ctx.activity chosen .agent .designRevision ∧\n ownTheory chosen (ownFactClaim chosen .selected) ∧\n (.commitment .grounds : ReviewObject) ∈ (selfModel chosen).objects ∧\n Admissible (ownTheory chosen) (comparisonContext chosen) chosen := by\n exact ⟨sharedContext, .evolvable, rfl, rfl,\n inheritedCurrent .evolvable (Or.inr rfl), currentDomainSatisfied,\n currentPriorityConditions, currentNoThreat.1, by decide, by decide, by decide,\n (nonemptyOwnObjects .evolvable).1, (nonemptyOwnObjects .evolvable).2.2.2,\n currentAdmissible .evolvable (Or.inr rfl)⟩\n\n/- The countermodel adopts a supported present-simplicity value and actually\nchooses that option. Every inherited duty still holds. The domain conditions\nare active; neither lifecycle nor threatened costs supplies an escape. -/\n/-- organon-map CoreReader.Engineering.inheritedDoesNotEntailPriority\norganon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\norganon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e\nextensions#p1 sha256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66\nsoftware-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\nsoftware-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04\n-/\ntheorem inheritedDoesNotEntailPriority :\n ∃ ctx : Context, ∃ chosen : Candidate,\n ctx = sharedContext ∧ chosen = .presentSimple ∧\n Inherited ctx chosen ∧ PriorityConditions ctx ∧\n Continuing ctx.activity ∧ ¬ BoundedLifecycle ctx.activity ∧\n ¬ HasThreat ctx .evolvable ∧ ¬ JustifiedDeparture ctx .evolvable ∧\n Meets ctx.required (ctx.profiles .presentSimple) ∧\n Meets ctx.required (ctx.profiles .evolvable) ∧\n credible ctx.evidence .designRevision ∧\n CanChange ctx.activity .evolvable .successor .designRevision ∧\n CanChange ctx.activity .evolvable .agent .designRevision ∧\n changeWork .evolvable .designRevision < changeWork chosen .designRevision ∧\n abstractionComplexity chosen < abstractionComplexity .evolvable ∧\n valueSpecification (selectionPosition chosen) ∧\n (selectionPosition chosen).commitment chosen ∧\n ¬ EvolutionPriority ctx chosen := by\n exact ⟨sharedContext, .presentSimple, rfl, rfl,\n inheritedCurrent .presentSimple (Or.inl rfl), currentPriorityConditions,\n by decide, by decide, currentNoThreat.1, currentNoThreat.2,\n by decide, by decide, by decide, by decide, by decide, by decide, by decide,\n selectionGrounded .presentSimple (Or.inl rfl), rfl, currentSimpleViolates⟩\n\nend CoreReader.Engineering\n```\n\n\n\n **L1** 导入 CoreReader.Engineering.Domain,使其声明及传递依赖可用;此行不新增命题。\n\n\n **L2** 导入 CoreReader.Engineering.Reflection,使其声明及传递依赖可用;此行不新增命题。\n\n\n **L3** 导入 CoreReader.Engineering.SelfApplication,使其声明及传递依赖可用;此行不新增命题。\n\n\n **L5** 开启 CoreReader.Engineering 命名空间,后续声明归入其中。\n\n\n **L7** 允许不带完整限定名引用 CoreReader.Logic CoreReader.Evidence CoreReader.Adopted 中的声明;不改变其含义。\n\n\n **L9** 注释固定此处所有解释共用的活动、需求与证据。\n\n\n **L10** 注释还固定成本限制,同时允许所选实现及陈述价值变化。\n\n\n **L11** 全部整合主张使用 sharedContext,其定义等于固定的 currentContinuing 语境。\n\n\n **L13** 对所选设计与自然数输入,maintainedOutput 提取一个可观察结果。\n\n\n **L14** 对单元素 [n] 运行 behavior 并取首项,空列表时默认 0。\n\n\n **L16** 把所选设计投影为 Core 的 Implementation 记录。\n\n\n **L17** 采用共用描述名称 order-preserving queue。\n\n\n **L18** 恰在 chosen 为 presentSimple 时标记 conventional。\n\n\n **L19** 按同一布尔相等条件标记 established。\n\n\n **L20** 实现的实际 run 函数采用 maintainedOutput。\n\n\n **L21** 其 Core 层成本为所选设计的抽象复杂度。\n\n\n **L22** 此投影的定义域允许所有自然数输入。\n\n\n **L23** 以相同 maintainedOutput 函数作为解释。\n\n\n **L24** 轨迹仅含最终输出一个元素,并非内部执行轨迹。\n\n\n **L26** 注释把 Core 选择投影限于队列的单项可观察合约。\n\n\n **L27** 注释补充当前理解预算,并在此投影之外保留单独的领域检查。\n\n\n **L28** 为此投影定义 Core 选择需求。\n\n\n **L29** 所有自然数都是允许输入。\n\n\n **L30** 期望结果为输入自身。\n\n\n **L31** 以共用语境的理解容量为预算。\n\n\n **L32** 附加价值谓词为不受限的 True。\n\n\n **L34** 可用 Core 选择理由组成有限列表。\n\n\n **L35** 列出输出与简洁性方法理由;仅属列表不会证明理由充分。\n\n\n **L37** 对每个设计与自然数 n,陈述单项输出投影的正确性。\n\n\n **L38** 实际 maintainedOutput 必须等于 n。\n\n\n **L39** 对单元素输入,该等式为定义相等,故反身性可证。\n\n\n **L41** 在预算前提下,为任意所选设计证明有理由的 Core 实现选择。\n\n\n **L42** 假设实际抽象复杂度不超出 chosenRequirements.budget。\n\n\n **L43** 结论采用实际需求、投影实现及已列理由。\n\n\n **L44** 为所有允许输入构造功能正确性,并复用传入预算证明。\n\n\n **L45** 选择输出方法理由,留下成员资格及充分性义务。\n\n\n **L46** 展开 chosenReasons 证明输出理由的成员资格。\n\n\n **L47** 证明输出理由的不受限价值条件及精确输入、输出合约。\n\n\n **L49** 注释将能力报告界定为按维护者索引的实际路径可用性。\n\n\n **L50** 注释说明 0 是路径缺失标记,不是路径存在的证据。\n\n\n **L51** capabilityOutput 为自然数输入编码的维护者报告修订路径工作量。\n\n\n **L52** 输入 0 选择原维护者。\n\n\n **L53** 输入 1 选择继任者,其余更大输入均选择智能体。\n\n\n **L54** 在 sharedContext 中判定此维护者、设计及 designRevision 的实际 CanChange。\n\n\n **L55** 路径存在时返回实际修订工作量,否则返回缺失标记 0。\n\n\n **L57** 构造报告所选设计能力输出函数的 Process。\n\n\n **L58** 其输出为 capabilityOutput,可选解释为 none。\n\n\n **L60** 为此所选设计定义 Process 上的精确功能主张。\n\n\n **L61** 对所有自然数输入,要求过程输出等于该设计的 capabilityOutput。\n\n\n **L63** 为每个所选设计的功能能力主张提供依据。\n\n\n **L64** 过程与能力规范共享同一 chosen 参数。\n\n\n **L65** 用逐点反身性履行推理性的过程合约面向,再构造单元素依据。\n\n\n **L67** actualCapabilityContrast 计算六个具体维护者、设计输出。\n\n\n **L68** presentSimple 为原维护者报告 17 单位工作量。\n\n\n **L69** 它为继任者报告路径缺失标记 0。\n\n\n **L70** 它为智能体也报告 0。\n\n\n **L71** evolvable 为原维护者报告 6 单位工作量。\n\n\n **L72** 它为继任者也报告 6。\n\n\n **L73** 它为智能体也报告 6;decide 计算全部六个等式。\n\n\n **L75** 注释介绍当前抽象复杂度的记录阈值。\n\n\n **L76** 注释把观测限于此有限模型,排除未来可维护性及价值确立。\n\n\n **L77** 在 Candidate 上构造一个记录的布尔阈值观测。\n\n\n **L78** 观测函数检查抽象复杂度 ≤ 3,记录结果为 true。\n\n\n **L80** presentBudgetClaim 恰为同一复杂度不超过 3 的谓词。\n\n\n **L82** 对每个候选项,连接与此记录相容和精确主张。\n\n\n **L83** 陈述双向等价;此记录仅约束当前复杂度。\n\n\n **L84** 分别证明等价的两个方向。\n\n\n **L85** 假设与单元素观测列表相容。\n\n\n **L86** 利用单元素成员资格,将相容性应用到实际记录。\n\n\n **L87** 把观测函数的 true 布尔结果转为复杂度命题。\n\n\n **L88** 反向假设该界限,并引入任意已列记录。\n\n\n **L89** 单元素成员资格将其确定为 presentBudgetRecord。\n\n\n **L90** 把界限转为所需的布尔值等于 true。\n\n\n **L92** 把预算观测包装为 Candidate 上的经验 Facet。\n\n\n **L93** 采用精确记录与预算主张;经验范围及不确定性谓词均为 True。\n\n\n **L95** 证明该经验面向实际得到履行。\n\n\n **L96** 以 evolvable 为相容且在范围内的见证,留下主张支持与不确定性支持义务。\n\n\n **L97** 对每个相容候选项,引入平凡的经验范围前提。\n\n\n **L98** 利用观测等价的正向证明精确预算主张。\n\n\n **L99** 剩余不确定性谓词为 True,因此每个相容候选项均平凡满足它。\n\n\n **L101** capacityClaim 是关于实际当前理解容量的命题。\n\n\n **L102** 对每个候选项要求复杂度不超过 sharedContext 的理解限制 12。\n\n\n **L104** 容量推理仅假设含 presentBudgetClaim 的单元素理论。\n\n\n **L106** 从这些假设到容量主张构造推理面向。\n\n\n **L108** 证明此推理具有模型且蕴涵其主张。\n\n\n **L109** 用 evolvable 见证复杂度不超过 3 的假设,留下蕴涵义务。\n\n\n **L110** 引入满足全部推理前提的任意候选项。\n\n\n **L111** 单元素模型等价提取 ≤ 3 界限。\n\n\n **L112** 把此界限与计算出的 3 ≤ 12 不等式组合。\n\n\n **L114** 为当前预算测量主张构造范围说明。\n\n\n **L115** 所解释主张恰为 presentBudgetClaim。\n\n\n **L116** 应用条件为不受限的 True。\n\n\n **L117** 观测范围同样为 True。\n\n\n **L118** 比较相关性意味着在 [2, 1, 2] 上实际行为相等。\n\n\n **L119** 仅当两个候选项均满足预算主张时进行比较。\n\n\n **L120** 唯一使用的方法为 measurement。\n\n\n **L121** 作用文本把观测限于当前复杂度,排除未来性能结论。\n\n\n **L122** 解释关系首先要求方法为 measurement。\n\n\n **L123** 要求精确的已存限制文本。\n\n\n **L124** 要求所解释主张及条件谓词的身份一致。\n\n\n **L126** 验证此精确说明的 scopeSpecification。\n\n\n **L127** 拆分比较范围与方法解释两个义务。\n\n\n **L128** 对被比较候选项,证明四个为 True 的条件、范围,再用它们在 [2,1,2] 上实际行为的定义相等证明相关性。\n\n\n **L129** 引入任何实际使用的方法及其使用证明。\n\n\n **L130** 计算作用字符串与空字符串不等,证明其非空。\n\n\n **L131** 复用使用相等证明,并以反身性完成文本、主张、条件身份。\n\n\n **L133** 注释引入未改变观测却加强主张的反例。\n\n\n **L134** 展示此观测不支持更严格的复杂度界限。\n\n\n **L135** evolvable 与记录的 ≤ 3 结果相容。\n\n\n **L136** 但此单元素记录不支持对全部相容世界的复杂度 ≤ 1 主张。\n\n\n **L137** 以观测等价证明相容性,留下支持失败义务。\n\n\n **L138** 为反证假设更强的支持关系成立。\n\n\n **L139** 将其应用到相容的 evolvable,得到不可能的 3 ≤ 1。\n\n\n **L140** 计算 ¬(3 ≤ 1),并用其否定导出的界限。\n\n\n **L142** 注释说明政策重视扩展,同时保留已表示形式的可修订性。\n\n\n **L143** 注释涵盖组织、方法及原则,但不声称实际修订事件发生。\n\n\n **L144** 为此工程活动实例化 Agency.Policy。\n\n\n **L145** 定义哪些目标值得追求。\n\n\n **L146** 明确采纳生成承诺时,扩展目标值得追求。\n\n\n **L147** 保持安全运行也无条件值得追求。\n\n\n **L148** 形式恰在版本等于 1 时为当前形式。\n\n\n **L149** 可修订性要求存在更大的自然数版本且生成已采纳。\n\n\n **L150** 允许任意版本不下降的转移。\n\n\n **L152** 为此具体政策证明生成规范。\n\n\n **L153** 见证已采纳的扩展目标,并为每个当前形式选择版本 + 1 作为严格更大的可修订版本。\n\n\n **L155** 注释把 OwnFact 值界定为此模型状态的数学报告。\n\n\n **L156** 注释在报告具有推理依据的同时,保留独立经验、价值任务。\n\n\n **L157** OwnFact 枚举将纳入模型理论的报告。\n\n\n **L158** 纳入选择、需求、容量、能力、预测与修订报告。\n\n\n **L159** 还纳入生成、反思报告及以原则为参数的采纳报告。\n\n\n **L160** 自动派生 DecidableEq, Repr:提供这些构造子的可判定相等与可打印表示。\n\n\n **L162** 以已采纳设计为参数,把每个 OwnFact 解释为 Candidate 上的主张。\n\n\n **L163** 选择报告要求候选项等于已采纳设计。\n\n\n **L164** 需求报告使用该候选项在 sharedContext 中的实际指标。\n\n\n **L165** 容量报告为先前定义的实际容量主张。\n\n\n **L166** 能力报告把按候选项索引的主张应用于同一候选项的过程。\n\n\n **L167** 预测报告陈述旧规模 10 一致、规模 5 不一致,不依赖候选项。\n\n\n **L168** 修订报告针对实际 revisionFor sharedContext candidate 说明。\n\n\n **L169** 政策报告陈述实际 engineeringPolicy 的 generationSpecification。\n\n\n **L170** 反思报告采用该候选项的实际反身性规范。\n\n\n **L171** 规则、自身目标及执行记录均来自同一 selfModel candidate。\n\n\n **L172** 采纳报告为同一原则的治理承诺谓词。\n\n\n **L174** 证明每项自身事实对实际所选设计成立。\n\n\n **L175** 要求普通设计,但全称量化 OwnFact。\n\n\n **L176** 在同一 chosen 候选项上求值按采纳索引的事实。\n\n\n **L177** 按事实构造子分情况。\n\n\n **L178** 选择报告是 chosen = chosen,由反身性证明。\n\n\n **L179** 对需求,枚举全部三个候选项并计算其必要指标检查。\n\n\n **L180** 对容量,限于两个普通候选项并计算复杂度 ≤ 12。\n\n\n **L181** 对能力,引入任意输入并以相同输出函数的反身性完成。\n\n\n **L182** 对预测,组合定义成立的旧等式与计算得到的新不等。\n\n\n **L183** 对修订,代入每个普通设计并判定其具体说明。\n\n\n **L184** 为政策报告复用 engineeringGenerative。\n\n\n **L185** 在普通设计前提下复用实际 currentSelfApplication。\n\n\n **L186** Core 采纳标记由定义相等为真。\n\n\n **L188** 定义关于所选设计事实的精确推理假设。\n\n\n **L189** 唯一假设为候选项等于 chosen;这是以身份为条件的推理。\n\n\n **L191** 以推理方式为每项自身事实报告提供依据。\n\n\n **L192** 保留普通设计前提及任意选取的事实。\n\n\n **L193** 以身份理论为前提,以实际事实解释为结论。\n\n\n **L194** 把单元素依据化为其推理面向的履行。\n\n\n **L195** 以 chosen 见证其自身身份前提,留下蕴涵义务。\n\n\n **L196** 引入满足该身份理论的任意候选项。\n\n\n **L197** 利用单元素模型等价提取 candidate = chosen。\n\n\n **L198** 在整个目标中以 chosen 替换 candidate。\n\n\n **L199** 对同一 chosen 设计及事实应用实际证明的自身事实定理。\n\n\n **L201** 注释把优先性、价值等价限于此固定且适用的语境。\n\n\n **L202** 注释说明两个谓词恰选择同一候选项。\n\n\n **L203** 注释通过身份把价值依据连接到实际规范内容,而非仅采纳标签。\n\n\n **L204** 对固定共用语境中的每个候选项,证明价值承诺与实际优先性选择相同。\n\n\n **L205** 左侧为明确采纳 evolvable 的选择立场之承诺。\n\n\n **L206** 右侧为 EvolutionPriority 本身,而非优先性名称标签。\n\n\n **L207** 证明此同一主张等价的两个方向。\n\n\n **L208** 假设可演化选择承诺。\n\n\n **L209** 把该承诺显化为 candidate = evolvable。\n\n\n **L210** 代入实际所选 evolvable 候选项。\n\n\n **L211** 从实际 currentDomainSatisfied 提取其优先性证明。\n\n\n **L212** 反向假设该候选项满足实际 EvolutionPriority。\n\n\n **L213** 在 sharedContext 中应用优先规则的所选候选项结论。\n\n\n **L214** 提供当前适用性及无正当偏离;这些固定语境事实不可省略。\n\n\n **L216** priorityGrounds 为 sharedContext 中的实际优先性命题提供价值依据。\n\n\n **L217** 主张为 EvolutionPriority sharedContext,使用规范表述。\n\n\n **L218** 把精确的可演化价值面向同时作为唯一所需任务与所供面向。\n\n\n **L219** 引入价值承诺谓词与实际优先性谓词的相等。\n\n\n **L220** 逐点使用命题外延性,再用函数外延性导出谓词相等。\n\n\n **L221** 把优先性主张重写为相同的价值承诺主张。\n\n\n **L222** 复用 evolvable 的 selectionGrounded;面向或受评主张的转换由该等式保证。\n\n\n **L224** 注释区分采纳事实与实际规范内容。\n\n\n **L225** 注释说明后续每个构造子保留完整已表示义务及原有任务。\n\n\n **L226** 注释保留条件、理由与范围,并把领域义务限于领域采纳者。\n\n\n **L227** 注释将一致性置于所得完整理论的外部约束位置。\n\n\n **L228** 注释避免通过断言自身一致性的自指命题来定义该理论。\n\n\n **L229** OwnNorm 将完整的已表示义务与采纳报告分开枚举。\n\n\n **L230** 纳入生成、反思、经验与推理依据及按原则索引的价值依据。\n\n\n **L231** 纳入选择价值、范围、能力、选择及按事实索引的推理依据。\n\n\n **L232** 纳入领域整包义务与实际优先性的依据,作为不同义务。\n\n\n **L233** 自动派生 DecidableEq, Repr:提供这些构造子的可判定相等与可打印表示。\n\n\n **L235** normApplies 逐规范确定依赖采纳的成员纳入条件。\n\n\n **L236** 按此谓词,仅可演化采纳者纳入领域与优先性价值义务。\n\n\n **L237** 其他每个规范均适用于所有采纳者。\n\n\n **L239** 保留 adopted 参数,把每个 OwnNorm 解释为 Candidate 上的完整命题。\n\n\n **L240** 生成规范为实际政策的完整 generationSpecification。\n\n\n **L241** 反思规范要求该候选项的实际反身性规范。\n\n\n **L242** 它采用同一候选模型的规则、自身关系与执行关系。\n\n\n **L243** 经验规范保留实际记录与原有 True 经验范围谓词。\n\n\n **L244** 它还保留精确预算主张与原有 True 不确定性谓词。\n\n\n **L245** 推理规范保留实际容量假设与容量结论。\n\n\n **L246** 每个原则价值规范要求同一治理立场的完整依据。\n\n\n **L247** 选择价值内容要求按 adopted 索引的完整价值规范。\n\n\n **L248** 它还要求同一价值承诺在该候选项上成立。\n\n\n **L249** 范围规范为精确 budgetScopeAccount 的规范。\n\n\n **L250** 能力规范保留完整能力规范。\n\n\n **L251** 过程与主张均使用同一 candidate 参数。\n\n\n **L252** 选择规范保留完整的有理由实现选择。\n\n\n **L253** 它采用实际需求、此候选项的实现及原有理由。\n\n\n **L254** 每个自身依据规范为对应事实的完整推理任务。\n\n\n **L255** 其身份前提与实际事实主张均由 adopted 索引。\n\n\n **L256** 领域规范为 sharedContext 中的实际 DomainSatisfied,在 candidate 上求值。\n\n\n **L257** 优先性价值规范为实际优先性谓词的依据,使用规范表述。\n\n\n **L258** 保留相同的所需及所供可演化价值面向。\n\n\n **L260** actualOwnNorm 证明每个适用完整规范在所选候选项上满足。\n\n\n **L261** 所选候选项仍必须为两个普通设计之一。\n\n\n **L262** 量化规范并假设实际 normApplies 条件,再得出其内容。\n\n\n **L263** 逐 OwnNorm 构造子分情况,保留其参数。\n\n\n **L264** 以实际工程政策定理履行生成义务。\n\n\n **L265** 以此普通设计的已检查自身模型定理履行反思义务。\n\n\n **L266** 在单元素依据中使用实际履行的经验面向。\n\n\n **L267** 同样使用实际履行的容量推理面向。\n\n\n **L268** 对该精确原则参数使用 governanceGrounded。\n\n\n **L269** 把实际选择依据与所选、采纳身份的反身性配对。\n\n\n **L270** 复用实际预算范围解释证明。\n\n\n **L271** 复用同一候选项的实际功能能力依据。\n\n\n **L272** 进入有理由实现选择义务。\n\n\n **L273** 应用 implementationReasoned,留下实际预算前提。\n\n\n **L274** 代入任一普通设计并计算其复杂度 ≤ 12。\n\n\n **L275** 对完全相同的所选设计及索引事实使用 actualOwnFactGrounded。\n\n\n **L276** 对领域规范,使用其采纳适用性前提。\n\n\n **L277** 把 applicable 显化为 chosen = evolvable。\n\n\n **L278** 以 evolvable 替换 chosen。\n\n\n **L279** 现在使用实际完整的当前领域满足证明。\n\n\n **L280** 固定优先性价值规范由 priorityGrounds 履行。\n\n\n **L282** ownFactTheory 恰持有已表示的自身事实主张。\n\n\n **L283** 某个 OwnFact 的解释恰等于该主张时,该主张被持有。\n\n\n **L285** ownNormTheory 持有适用的完整规范内容。\n\n\n **L286** 要求实际规范见证、其 normApplies 证明及与完整解释主张相等。\n\n\n **L288** 注释说明后果关系联合应用于事实及完整规范内容。\n\n\n **L289** 注释包括其实际并集的蕴涵,不仅分别检查两个分支。\n\n\n **L290** ownTheory 是后续模型与一致性谓词所作用的合并理论。\n\n\n **L291** 取事实报告与完整适用规范主张的并集;它并非仅含采纳标记的理论。\n\n\n **L293** 为每个所选设计及规范提供进入合并理论的方式。\n\n\n **L294** 实际适用性前提足以让该规范的精确完整主张被持有。\n\n\n **L295** 使用并集的规范分支,提供规范见证、适用性与主张身份反身性。\n\n\n **L297** 为每个所选设计展示非空持有主张与检查对象。\n\n\n **L298** 所选设计的选择报告实际属于 ownTheory。\n\n\n **L299** 依据原则的采纳报告也实际被持有。\n\n\n **L300** 活动检查对象属于 selfModel 的列表。\n\n\n **L301** 依据承诺对象属于同一列表。\n\n\n **L302** 提供两个事实分支见证,留下两个对象成员检查。\n\n\n **L303** 展开实际模型与有限承诺列表,证明这些成员资格。\n\n\n **L305** comparisonContext 是世界为 Candidate、问题为 OwnFact 的 Logic.Context。\n\n\n **L306** 其假设为精确的所选身份理论。\n\n\n **L307** 其问题含义为按 chosen 索引的事实解释。\n\n\n **L308** 其允许比较范围要求复杂度不超过 3。\n\n\n **L310** 由所选设计及显式修订编号构造 Snapshot。\n\n\n **L311** 保存完整合并理论、其比较语境及该修订编号。\n\n\n **L313** 证明所选普通设计是其合并理论的实际允许世界。\n\n\n **L314** 显式保留普通设计前提。\n\n\n **L315** 允许性包含同一 chosen 世界上的全部持有主张、比较假设及范围。\n\n\n **L316** 提供反身身份假设,留下完整理论满足及范围义务。\n\n\n **L317** 引入合并理论实际持有的任意主张。\n\n\n **L318** 把并集成员资格拆为事实与规范分支。\n\n\n **L319** 提取 OwnFact 见证并代入其精确主张解释。\n\n\n **L320** 在 chosen 上应用已检查的 actualOwnFact 定理。\n\n\n **L321** 提取 OwnNorm 见证、适用性证明及精确主张身份。\n\n\n **L322** 以同一 chosen 设计、规范及适用性证明应用 actualOwnNorm。\n\n\n **L323** 对范围,代入每个普通设计并计算复杂度 ≤ 3。\n\n\n **L325** 证明新完整快照的一致性及相对于指定旧快照的如实变化报告;不合并新旧理论。\n\n\n **L326** 新选择必须为普通设计。\n\n\n **L327** 旧快照为修订编号 0 的 evolvable。\n\n\n **L328** 当前快照为修订编号 1 的 chosen,变化被确认为 true。\n\n\n **L329** 以实际允许的 chosen 见证建立后果一致性,以反身性完成变化记录义务。\n\n\n **L331** 为合并理论中的每个主张提供依据,包括完整适用规范主张。\n\n\n **L332** 要求所选设计为普通设计。\n\n\n **L333** 量化任意 Candidate 主张,并假设其实际被 ownTheory 持有。\n\n\n **L334** 结论为该精确主张以身份为条件的推理依据。\n\n\n **L335** 把单元素依据化为推理任务。\n\n\n **L336** 以 chosen 为非空身份前提模型,留下蕴涵义务。\n\n\n **L337** 引入满足身份假设的任意候选项。\n\n\n **L338** 从单元素模型语义提取其与 chosen 相等。\n\n\n **L339** 以 chosen 替换该候选项。\n\n\n **L340** 从 currentAdmissible 投影完整理论满足,并用于精确的持有主张。\n\n\n **L342** 注释在采纳标记不变时引入不兼容内容。\n\n\n **L343** 注释指出冲突两侧使用同一候选项、问题与范围。\n\n\n **L344** 在同一 Candidate 世界上定义故意不兼容的规范理论。\n\n\n **L345** 第一个单元素理论要求候选项为 presentSimple。\n\n\n **L346** 第二个要求同一候选项不为 presentSimple。\n\n\n **L348** 使用一个 Unit 问题在共同语境中比较这些对立主张。\n\n\n **L349** 假设为空,问题含义为 candidate = presentSimple,范围为 True。\n\n\n **L351** normativeContentVariation 展示真实的采纳标记不能掩盖不兼容内容。\n\n\n **L352** 选择采纳标记仍为 true。\n\n\n **L353** 实际不兼容理论在其共同语境中仍不一致。\n\n\n **L354** 领域采纳适用于 evolvable,不适用于 presentSimple。\n\n\n **L355** 实际领域主张在可演化理论中被持有。\n\n\n **L356** 该实际领域主张不被简单设计理论持有。\n\n\n **L357** 构造采纳、适用性事实与正向成员资格,留下一致性失败及反向非成员资格。\n\n\n **L358** 把 conflictRequiresChange 应用于唯一共同 Unit 问题。\n\n\n **L359** 对任意允许候选项导出冲突的正向命题。\n\n\n **L360** 把正向问题含义显化为 candidate = presentSimple。\n\n\n **L361** 利用单元素模型等价提取正向主张。\n\n\n **L362** 从允许性的并集模型中选择第一个理论。\n\n\n **L363** 对同样的允许候选项导出反向命题。\n\n\n **L364** 把否定含义显化为 candidate ≠ presentSimple。\n\n\n **L365** 利用其单元素模型等价提取反向主张。\n\n\n **L366** 从同一并集模型中选择第二个理论。\n\n\n **L367** 为证明非成员资格,假设实际领域主张被 presentSimple 持有。\n\n\n **L368** 其已检查允许性使完整 DomainSatisfied 主张在 presentSimple 上成立。\n\n\n **L369** 从领域整包提取优先性,与 currentSimpleViolates 矛盾。\n\n\n **L371** 注释将 Inherited 字段描述为实际满足或支持条件。\n\n\n **L372** 注释否认价值说明或完成评估能替代规范字段本身。\n\n\n **L373** 注释通过身份字段明确把实现限于共同语境。\n\n\n **L374** Inherited 在显式语境与所选设计上组合已表示的继承义务;其字段是投影定理的前提。\n\n\n **L375** 把 ctx 限为精确 sharedContext;此条件强于任意语境的实现。\n\n\n **L376** 要求实际工程政策的完整 generationSpecification。\n\n\n **L377** 要求当前快照一致,并相对于旧可演化修订 0 快照如实报告变化。\n\n\n **L378** 当前快照使用此所选设计、修订 1,变化记录为 true。\n\n\n **L379** 要求按此候选项的实际规则与自身目标满足反身性。\n\n\n **L380** 执行关系来自同一候选项的 selfModel。\n\n\n **L381** 对每个 Core 原则要求实际治理立场的价值依据。\n\n\n **L382** 要求此所选设计的选择价值立场依据。\n\n\n **L383** 要求使用实际预算记录与 True 经验范围的经验任务。\n\n\n **L384** 保留其精确当前预算主张与 True 不确定性谓词;未提供量化不确定性界限。\n\n\n **L385** 要求从 capacityAssumptions 到 capacityClaim 的实际推理。\n\n\n **L386** 要求实际预算范围解释。\n\n\n **L387** 要求同一所选过程与主张的功能能力依据。\n\n\n **L388** 要求在实际需求与理由下,对此所选实现作有理由的选择。\n\n\n **L389** 对全部自身事实,要求从所选身份前提到精确事实主张的推理。\n\n\n **L390** 要求 chosen 本身与实际预算观测相容。\n\n\n **L391** 要求所选选择承诺实际在 chosen 上被采纳。\n\n\n **L392** 要求 chosen 为完整合并理论中每个持有主张的模型。\n\n\n **L393** 对每个适用规范,要求其内容实际属于理论。\n\n\n **L394** 被持有内容必须为同一规范的完整 ownNormClaim。\n\n\n **L395** 对每个实际持有主张,要求其推理依据。\n\n\n **L396** 这些依据保留显式的所选身份假设。\n\n\n **L398** 为所选设计构造 Inherited 的全部字段。\n\n\n **L399** 假设其为 presentSimple 或 evolvable。\n\n\n **L400** 所得整包恰位于 sharedContext。\n\n\n **L401** 提供语境身份、实际生成证明及完整当前一致性。\n\n\n **L402** 提供实际自应用及每个治理原则的依据。\n\n\n **L403** 提供所选选择依据及已履行的经验单元素任务。\n\n\n **L404** 提供已履行的容量推理及实际范围说明。\n\n\n **L405** 提供能力依据,留下实现选择义务,并提供全部自身事实依据。\n\n\n **L406** 留下观测相容性,提供采纳身份及实际完整理论满足。\n\n\n **L407** 提供适用规范成员资格及每个持有主张的依据。\n\n\n **L408** 对实现字段,应用实际有理由选择定理。\n\n\n **L409** 拆分普通选择并计算剩余 ≤ 12 预算条件。\n\n\n **L410** 对观测相容性,使用预算观测等价的反向。\n\n\n **L411** 拆分普通选择并计算其 ≤ 3 观测界限。\n\n\n **L413** 注释介绍对同一系统、原则及主张的相互应用。\n\n\n **L414** 注释纳入实际所选实现,并保留完整 Inherited 前提。\n\n\n **L415** 开始 CoreReader.Engineering.inheritedMutualApplication 的来源追溯元数据;后续来源标识与哈希不是 Lean 证明前提。\n\n\n **L416** 记录来源单元 organon.relationships.roles#p1 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L417** 记录来源单元 organon.relationships.roles#p2 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L418** 记录来源单元 organon.relationships.roles#p3 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L419** 结束来源追溯元数据注释;Lean 不把它解析为证明项。\n\n\n **L420** 对任意 ctx 与 chosen,inheritedMutualApplication 从 Inherited 提取同一对象义务。\n\n\n **L421** 完整继承整包是显式前提,不是定理独立推导的结论。\n\n\n **L422** 返回实际工程生成规范。\n\n\n **L423** 返回所选模型规则与自身关系上的反身性。\n\n\n **L424** 保留同一模型的执行关系。\n\n\n **L425** 对全部 Core 原则全称返回价值依据。\n\n\n **L426** 返回所选过程及其精确主张的能力依据。\n\n\n **L427** 返回实际有理由实现选择。\n\n\n **L428** 返回每项自身事实在所选身份前提下的推理依据。\n\n\n **L429** 返回每个满足适用性前提的规范之理论成员资格。\n\n\n **L430** 返回合并理论中每个实际持有主张的推理依据。\n\n\n **L431** 返回当前完整理论一致性及相对于旧可演化快照的如实变化报告。\n\n\n **L432** 其当前一侧仍为 chosen 修订 1,变化记录为 true。\n\n\n **L433** 从 inherited 投影生成、反思及治理依据以构造合取。\n\n\n **L434** 投影能力、实际实现选择及自身事实依据。\n\n\n **L435** 投影完整规范成员、全部持有主张依据及完整一致性;此处未额外证明这些前提。\n\n\n **L437** 开始 CoreReader.Engineering.inheritedMutualCases 的来源追溯元数据;后续来源标识与哈希不是 Lean 证明前提。\n\n\n **L438** 记录来源单元 organon.relationships.roles#p1 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L439** 记录来源单元 organon.relationships.roles#p2 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L440** 记录来源单元 organon.relationships.roles#p3 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L441** 结束来源追溯元数据注释;Lean 不把它解析为证明项。\n\n\n **L442** inheritedMutualCases 给出具体正向义务以及实际自批评结果。\n\n\n **L443** 完整 Inherited 整包在 sharedContext 对 evolvable 成立。\n\n\n **L444** 依据原则的治理价值规范成立。\n\n\n **L445** 实际可演化过程具有其精确功能能力依据。\n\n\n **L446** 可演化实现具有实际有理由选择支持。\n\n\n **L447** 实际批处理方法修订评估为反例。\n\n\n **L448** generationRule 对象实际属于可演化模型。\n\n\n **L449** assessmentRule 对象属于同一模型。\n\n\n **L450** 实际评估规则修订同样评估为反例。\n\n\n **L451** 使用完整 inheritedCurrent 见证及实际依据原则价值定理。\n\n\n **L452** 使用精确的可演化能力依据定理。\n\n\n **L453** 从同一继承见证提取有理由实现选择。\n\n\n **L454** 从 actualSelfCriticism 提取批处理方法反例。\n\n\n **L455** 从 ownRuleIdentity 提取生成规则对象成员资格。\n\n\n **L456** 从对应身份定理提取评估规则对象成员资格。\n\n\n **L457** 从 ownRuleContentVariation 提取当前评估规则修订反例。\n\n\n **L459** 注释把优先性对象及其评估方法置于采纳者的同一语境。\n\n\n **L460** 注释把两个对象保留在继承的批评、生成合约内。\n\n\n **L461** 开始 CoreReader.Engineering.priorityRemainsReflexive 的来源追溯元数据;后续来源标识与哈希不是 Lean 证明前提。\n\n\n **L462** 记录来源单元 organon.relationships.roles#p3 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L463** 记录来源单元 extensions#p1 及 SHA-256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L464** 记录来源单元 software-engineering.structural-judgment#p1 及 SHA-256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L465** 记录来源单元 software-engineering.revision#p2 及 SHA-256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L466** 结束来源追溯元数据注释;Lean 不把它解析为证明项。\n\n\n **L467** priorityRemainsReflexive 在显式语境、选择下把领域优先性连接到继承的自批评。\n\n\n **L468** 假设同一 ctx、chosen 的完整 Inherited 整包及实际 DomainSatisfied。\n\n\n **L469** 还假设同一语境下优先性适用且 evolvable 不存在正当偏离。\n\n\n **L470** 得出所选候选项必须为 evolvable。\n\n\n **L471** 其实际优先性对象属于自身检查列表。\n\n\n **L472** 所选自身模型仍在实际规则、目标上满足反身性。\n\n\n **L473** 在规范中保留其实际执行关系。\n\n\n **L474** 保留每个继承 Core 原则的价值依据。\n\n\n **L475** 另为实际 EvolutionPriority ctx 主张提供依据,使用规范表述。\n\n\n **L476** 其所需与所供面向为完全相同的可演化选择价值立场。\n\n\n **L477** 完整实际领域规范被 chosen 的合并理论持有。\n\n\n **L478** 保留完整继承一致性规范。\n\n\n **L479** 当前快照仍为 chosen 修订 1,变化确认值为 true。\n\n\n **L480** 从 domain 提取实际优先性,应用适用性与无偏离前提导出 chosen = evolvable。\n\n\n **L481** 构造选择身份,留下成员资格,并投影反思与 Core 价值依据。\n\n\n **L482** 留下精确优先性依据;以 selected 作为领域规范适用性,并投影一致性。\n\n\n **L483** 以 evolvable 替换 chosen,计算实际优先性对象成员资格。\n\n\n **L484** 利用 Inherited 身份字段把 ctx 重写为 sharedContext;这限定了依据结果的语境。\n\n\n **L485** 现在对完全相同的优先性谓词应用 priorityGrounds。\n\n\n **L487** 开始 CoreReader.Engineering.priorityReflexiveCases 的来源追溯元数据;后续来源标识与哈希不是 Lean 证明前提。\n\n\n **L488** 记录来源单元 organon.relationships.roles#p3 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L489** 记录来源单元 extensions#p1 及 SHA-256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L490** 记录来源单元 software-engineering.structural-judgment#p1 及 SHA-256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L491** 记录来源单元 software-engineering.revision#p2 及 SHA-256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L492** 结束来源追溯元数据注释;Lean 不把它解析为证明项。\n\n\n **L493** priorityReflexiveCases 计算实际优先性检查,并保留对不同方法对象的批评。\n\n\n **L494** 优先性对象实际列于可演化设计。\n\n\n **L495** 其有限规模 10 对象测试通过。\n\n\n **L496** 模型在评估键 (0,1) 下记录所有者 0 的优先性修订实际执行。\n\n\n **L497** 执行输入恰为同一目标构造的输入。\n\n\n **L498** 记录结果为 assessed supportedWithinScope。\n\n\n **L499** 不同的批处理方法修订仍产生反例。\n\n\n **L500** 旧批处理方法规模 10 测试成功。\n\n\n **L501** 受质疑规模 5 测试失败。\n\n\n **L502** 保留 sharedContext 中实际优先性的依据及规范表述。\n\n\n **L503** 采用相同的单元素所需、所供可演化价值面向。\n\n\n **L504** 评估规则修订的局部合约失败也被保留为反例。\n\n\n **L505** 计算优先性成员及测试成功;留下 performed,并提取批处理批评。\n\n\n **L506** 提取批处理方法的旧规模成功与受质疑规模失败。\n\n\n **L507** 提供实际优先性依据及实际规则修订反例。\n\n\n **L508** 以自身成员资格、精确输入及评估活动的键、记录身份构造 performed。\n\n\n **L510** 注释介绍满足全部已表示继承整包的非空见证。\n\n\n **L511** 注释还要求完全相同持续活动中的领域整包及适用优先性。\n\n\n **L512** 开始 CoreReader.Engineering.jointWitness 的来源追溯元数据;后续来源标识与哈希不是 Lean 证明前提。\n\n\n **L513** 记录来源单元 organon.charter.overview#p2 及 SHA-256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L514** 记录来源单元 organon.charter.overview#p3 及 SHA-256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L515** 记录来源单元 organon.charter.self-transcendence#p1 及 SHA-256 f4ca590e2ae15e3882f70c7b2bc46a8911c97cee547c8b137b5493fbf862c8c0;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L516** 记录来源单元 organon.charter.self-transcendence.orientation#p1 及 SHA-256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L517** 记录来源单元 organon.charter.self-transcendence.non-finality#p1 及 SHA-256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L518** 记录来源单元 organon.charter.self-transcendence.limits#p1 及 SHA-256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L519** 记录来源单元 organon.charter.self-transcendence.limits#p2 及 SHA-256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L520** 记录来源单元 organon.charter.consistency#p1 及 SHA-256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L521** 记录来源单元 organon.charter.consistency.meaning#p1 及 SHA-256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L522** 记录来源单元 organon.charter.consistency.meaning#p2 及 SHA-256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L523** 记录来源单元 organon.charter.consistency.limits#p1 及 SHA-256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L524** 记录来源单元 organon.charter.reflexivity#p1 及 SHA-256 13293b45c2fa89068c68ae7ef3c5df38f0efadb3ef3873d78a5ba67d9691a757;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L525** 记录来源单元 organon.charter.reflexivity.meaning#p1 及 SHA-256 8a2caede01a43d8b6c60b54c78ac089c51868e9956f316948077ccee2e45c9cc;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L526** 记录来源单元 organon.charter.reflexivity.limits#p1 及 SHA-256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L527** 记录来源单元 organon.grounds#p1 及 SHA-256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L528** 记录来源单元 organon.grounds.assessment#p1 及 SHA-256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L529** 记录来源单元 organon.grounds.assessment#p2 及 SHA-256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L530** 记录来源单元 organon.grounds.assessment#p3 及 SHA-256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L531** 记录来源单元 organon.grounds.scope#p1 及 SHA-256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L532** 记录来源单元 organon.grounds.scope#p2 及 SHA-256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L533** 记录来源单元 organon.grounds.scope#p3 及 SHA-256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L534** 记录来源单元 organon.grounds.capabilities#p1 及 SHA-256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L535** 记录来源单元 organon.grounds.capabilities#p2 及 SHA-256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L536** 记录来源单元 organon.grounds.implementations#p1 及 SHA-256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L537** 记录来源单元 organon.grounds.implementations#p2 及 SHA-256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L538** 记录来源单元 organon.grounds.implementations.limits#p1 及 SHA-256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L539** 记录来源单元 organon.relationships.roles#p1 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L540** 记录来源单元 organon.relationships.roles#p2 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L541** 记录来源单元 organon.relationships.roles#p3 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L542** 记录来源单元 extensions#p1 及 SHA-256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L543** 记录来源单元 software-engineering.purpose#p1 及 SHA-256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L544** 记录来源单元 software-engineering.purpose#p2 及 SHA-256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L545** 记录来源单元 software-engineering.purpose#p3 及 SHA-256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L546** 记录来源单元 software-engineering.evolution-priority#p1 及 SHA-256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L547** 记录来源单元 software-engineering.evolution-priority#p2 及 SHA-256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L548** 记录来源单元 software-engineering.evolution-priority#p3 及 SHA-256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L549** 记录来源单元 software-engineering.evolution-meaning#p1 及 SHA-256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L550** 记录来源单元 software-engineering.evolution-meaning#p2 及 SHA-256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L551** 记录来源单元 software-engineering.structural-judgment#p1 及 SHA-256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L552** 记录来源单元 software-engineering.structural-judgment#p2 及 SHA-256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L553** 记录来源单元 software-engineering.structural-judgment#p3 及 SHA-256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L554** 记录来源单元 software-engineering.revision#p1 及 SHA-256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L555** 记录来源单元 software-engineering.revision#p2 及 SHA-256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L556** 结束来源追溯元数据注释;Lean 不把它解析为证明项。\n\n\n **L557** jointWitness 展示一个同时满足继承与领域整包的非空有限模型。\n\n\n **L558** 存在性选择语境及 Candidate;这是存在结果,不是普遍充分性。\n\n\n **L559** 要求见证恰为 sharedContext 与 evolvable。\n\n\n **L560** 两个完整整包必须对这些相同对象成立。\n\n\n **L561** 优先性适用条件成立,且 evolvable 无已表示威胁。\n\n\n **L562** 所选设计的抽象复杂度大于 presentSimple。\n\n\n **L563** 继任者在同一活动、设计中具有实际 designRevision 路径。\n\n\n **L564** 智能体在那里也具有实际 designRevision 路径。\n\n\n **L565** 所选设计报告实际被 chosen 的理论持有。\n\n\n **L566** 依据承诺实际属于 chosen 的自身检查对象。\n\n\n **L567** Chosen 是其完整合并理论与比较语境的允许模型。\n\n\n **L568** 选择 sharedContext 与 evolvable 为见证,以反身性证明两个身份字段。\n\n\n **L569** 提供完整 inheritedCurrent 整包及 currentDomainSatisfied。\n\n\n **L570** 提供适用优先性与无威胁,再计算复杂度次序及两个维护者路径。\n\n\n **L571** 从 nonemptyOwnObjects 投影持有选择及实际依据检查对象。\n\n\n **L572** 以实际完整理论允许性证明完成。\n\n\n **L574** 注释介绍采纳有支持的当前简单性价值的反模型。\n\n\n **L575** 注释陈述实际选择及完整继承满足,并开始说明适用性限定。\n\n\n **L576** 注释排除领域条件不适用、有界生命周期及受威胁成本作为回避解释。\n\n\n **L577** 开始 CoreReader.Engineering.inheritedDoesNotEntailPriority 的来源追溯元数据;后续来源标识与哈希不是 Lean 证明前提。\n\n\n **L578** 记录来源单元 organon.relationships.roles#p1 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L579** 记录来源单元 organon.relationships.roles#p2 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L580** 记录来源单元 organon.relationships.roles#p3 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L581** 记录来源单元 extensions#p1 及 SHA-256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L582** 记录来源单元 software-engineering.evolution-priority#p1 及 SHA-256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L583** 记录来源单元 software-engineering.evolution-priority#p2 及 SHA-256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L584** 记录来源单元 software-engineering.evolution-priority#p3 及 SHA-256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04;此注释追溯受审来源对象,不是逻辑假设或对应性证明。\n\n\n **L585** 结束来源追溯元数据注释;Lean 不把它解析为证明项。\n\n\n **L586** inheritedDoesNotEntailPriority 展示有限反模型,区分继承义务与附加优先性采纳。\n\n\n **L587** 存在性选择满足以下全部合取项的语境与候选项。\n\n\n **L588** 把它们固定为 sharedContext 与 presentSimple。\n\n\n **L589** 完整继承整包成立,同时领域优先性条件适用。\n\n\n **L590** 同一活动持续且不具有有界生命周期。\n\n\n **L591** evolvable 既无威胁,也无正当偏离。\n\n\n **L592** presentSimple 满足实际必要需求。\n\n\n **L593** evolvable 也满足这些相同需求。\n\n\n **L594** 同一证据使 designRevision 可信。\n\n\n **L595** 继任者能在此活动中修订 evolvable。\n\n\n **L596** 智能体在那里也能修订 evolvable。\n\n\n **L597** evolvable 的实际设计修订工作量少于所选 presentSimple。\n\n\n **L598** 所选 presentSimple 的当前抽象复杂度小于 evolvable。\n\n\n **L599** 所选简单性价值立场具有实际价值依据。\n\n\n **L600** 同一价值立场实际承诺所选设计。\n\n\n **L601** 尽管如此,该选择的实际 EvolutionPriority 主张为假。\n\n\n **L602** 选择 sharedContext 与 presentSimple,以反身性完成身份要求。\n\n\n **L603** 提供完整继承满足及适用优先性条件。\n\n\n **L604** 计算持续性与非有界性,再使用无威胁、无偏离两个事实。\n\n\n **L605** 计算两个需求、可信修订、两个维护者路径及工作量、复杂度不等式。\n\n\n **L606** 以实际简单立场依据、反身采纳及 currentSimpleViolates 完成反模型。\n\n\n **L608** 关闭 CoreReader.Engineering 命名空间;不另行断言数学主张。\n\n\n### `leanified/CoreReader/Engineering/Reflection.lean`\n\n\n```lean\nimport CoreReader.Adopted\n\nnamespace CoreReader.Engineering.Reflection\n\nopen CoreReader.Agency CoreReader.Adopted\n\n/- A target retains the owner, the actual object and the stage being examined. -/\nstructure Target (Object : Type) where\n owner : Nat\n object : Object\n phase : Phase\n\n/- A finite assessment contract has actual tests and a scope it claims to cover.\nThe scope is an application limit, not a universal definition of assessment. -/\nstructure Contract (W : Type) where\n test : W → Bool\n tested : List W\n claimed : List W\n\n/- Inputs carry the contract belonging to the named target, so another object's\ntest result cannot silently discharge this target's inquiry. -/\nstructure Input (W Object : Type) where\n target : Target Object\n contract : Contract W\n requested : List W\n reasons : List String\n basis : Prop\n\ninductive Verdict | supportedWithinScope | counterexample | noSupportingSample\n deriving DecidableEq, Repr\n\ninductive Outcome (W : Type)\n | generated (tests scope : List W)\n | assessed (verdict : Verdict)\n deriving DecidableEq\n\n/- A successful sample does not license the wider scope: an actual failing\ninstance there changes the assessment to counterexample. -/\ndef evaluate {W Object : Type} (input : Input W Object) : Verdict :=\n if input.contract.tested.all input.contract.test then\n if input.requested.all input.contract.test then .supportedWithinScope\n else .counterexample\n else .noSupportingSample\n\n/- Generation proposes an expanded test set. Proposal generation does not prove\nthat the resulting contract passes those tests or warrants adoption. -/\ndef generate {W Object : Type} (input : Input W Object) : Outcome W :=\n .generated input.requested input.requested\n\ndef interpret {W Object : Type} (activity : Activity) (input : Input W Object)\n (outcome : Outcome W) : Prop :=\n input.reasons ≠ [] ∧ input.basis ∧ match activity with\n | .generation => outcome = generate input\n | .assessment => outcome = .assessed (evaluate input)\n\nstructure Model (W Object : Type) where\n owner : Nat\n objects : List Object\n contracts : Object → Contract W\n requested : Object → Phase → List W\n reasons : Object → Phase → List String\n basis : Object → Phase → Prop\n generationApplies : Object → Phase → Prop\n assessmentApplies : Object → Phase → Prop\n recorded : Activity → Object → Phase → Outcome W\n\ndef Model.input {W Object : Type} (m : Model W Object) (t : Target Object) : Input W Object :=\n ⟨t, m.contracts t.object, m.requested t.object t.phase, m.reasons t.object t.phase,\n m.basis t.object t.phase⟩\n\ndef Model.self {W Object : Type} (m : Model W Object) (t : Target Object) : Prop :=\n t.owner = m.owner ∧ t.object ∈ m.objects\n\ndef Model.rule {W Object : Type} (m : Model W Object) (activity : Activity) :\n ReflexiveRule (Target Object) (Input W Object) (Outcome W) where\n key := ⟨m.owner, match activity with | .generation => 0 | .assessment => 1⟩\n activity := activity\n applicable t := m.self t ∧ match activity with\n | .generation => m.generationApplies t.object t.phase\n | .assessment => m.assessmentApplies t.object t.phase\n input := m.input\n meaning := interpret activity\n\ndef Model.rules {W Object : Type} (m : Model W Object) :=\n [m.rule .generation, m.rule .assessment]\n\n/- These are the stated records. The separate follows test compares each stated\noutcome with the actual input's evaluation, rather than defining success by its name. -/\ndef Model.performed {W Object : Type} (m : Model W Object)\n (key : PrincipleKey) (t : Target Object) (input : Input W Object) (outcome : Outcome W) : Prop :=\n m.self t ∧ input = m.input t ∧\n ∃ activity, key = (m.rule activity).key ∧\n outcome = m.recorded activity t.object t.phase\n\ndef Model.follows {W Object : Type} (m : Model W Object) : Prop :=\n ∀ activity object phase, object ∈ m.objects →\n (match activity with\n | .generation => m.generationApplies object phase\n | .assessment => m.assessmentApplies object phase) →\n interpret activity (m.input ⟨m.owner, object, phase⟩) (m.recorded activity object phase)\n\n/- This generic implication retains the actual evaluation premise. Concrete\nengineering instances must discharge follows separately for their own contracts. -/\ntheorem recordedReflexivity {W Object : Type} (m : Model W Object) (checked : m.follows) :\n reflexivitySpecification m.rules m.self m.performed := by\n constructor\n · intro p hp q hq equal\n simp only [Model.rules, List.mem_cons, List.not_mem_nil, or_false] at hp hq\n rcases hp with rfl | rfl <;> rcases hq with rfl | rfl\n · rfl\n · have bad := congrArg PrincipleKey.localId equal; contradiction\n · have bad := congrArg PrincipleKey.localId equal; contradiction\n · rfl\n · intro rule hr target hs ha\n simp only [Model.rules, List.mem_cons, List.not_mem_nil, or_false] at hr\n rcases hr with rfl | rfl\n · refine ⟨m.recorded .generation target.object target.phase,\n ⟨hs, rfl, .generation, rfl, rfl⟩, ?_⟩\n have actual := checked .generation target.object target.phase hs.2 ha.2\n rcases target with ⟨owner, object, phase⟩\n have ownerEqual : owner = m.owner := hs.1\n subst owner\n exact actual\n · refine ⟨m.recorded .assessment target.object target.phase,\n ⟨hs, rfl, .assessment, rfl, rfl⟩, ?_⟩\n have actual := checked .assessment target.object target.phase hs.2 ha.2\n rcases target with ⟨owner, object, phase⟩\n have ownerEqual : owner = m.owner := hs.1\n subst owner\n exact actual\n\nend CoreReader.Engineering.Reflection\n```\n\n\n\n **L1** 导入 CoreReader.Adopted,使其声明及传递依赖可用;此行不新增命题。\n\n\n **L3** 开启 CoreReader.Engineering.Reflection 命名空间,后续声明归入其中。\n\n\n **L5** 允许不带完整限定名引用 CoreReader.Agency CoreReader.Adopted 中的声明;不改变其含义。\n\n\n **L7** 注释说明 Target 保留所有者、实际对象及受检阶段的用意;这些连接由字段编码。\n\n\n **L8** 对任意对象类型,Target 保存所有者、该类型的实际对象和生命周期阶段。\n\n\n **L9** 所有者标识是自然数;该字段不要求全局唯一。\n\n\n **L10** 此字段保留实际对象,而非仅存名称。\n\n\n **L11** 目标包含当前受检查的阶段。\n\n\n **L13** 注释介绍包含实际测试与声称范围的有限评估合约。\n\n\n **L14** 注释把此范围表示限于应用,不将其当作评估的普遍定义。\n\n\n **L15** 对任意样本类型 W,Contract 包含一个布尔测试和两个有限列表。\n\n\n **L16** 测试把每个 W 值映射为布尔结果。\n\n\n **L17** 此列表记录初始测试案例,允许为空。\n\n\n **L18** 此字段是合约声称覆盖的列表;evaluate 不读取它。\n\n\n **L20** 注释介绍与目标关联的输入;后续 Model.input 按该目标选择字段。\n\n\n **L21** 注释说明防止用另一对象测试替代本次检查的目的;原始 Input 本身不强制来源不变量。\n\n\n **L22** Input 对样本和对象类型均为多态,组合目标及其检查数据。\n\n\n **L23** 保留完整的所有者、对象、阶段目标。\n\n\n **L24** 保存模型关联到此对象的测试合约。\n\n\n **L25** 初始列表通过后,evaluate 检查此请求列表。\n\n\n **L26** 理由以字符串保存;后续检查列表非空,不通过字符串分析证明其真实性或相关性。\n\n\n **L27** 依据可为任意命题;interpret 要求其成立。\n\n\n **L29** 定义范围内支持、反例、无支持样本三个判定值。\n\n\n **L30** 自动派生 DecidableEq, Repr:提供这些构造子的可判定相等与可打印表示。\n\n\n **L32** Outcome 以样本类型 W 为参数,记录生成结果或评估结果。\n\n\n **L33** 生成结果保存两个 W 列表,分别表示测试和范围。\n\n\n **L34** 评估结果保存 Verdict,不保存样本列表。\n\n\n **L35** 在具有 [DecidableEq W] 时为 Outcome W 派生可判定相等;生成的实例保留此前提,具体 ReviewCase 模型满足它。\n\n\n **L37** 注释说明初始样本成功本身不授权更广请求列表。\n\n\n **L38** 注释指出初始成功后,实际失败的请求案例会进入反例分支。\n\n\n **L39** evaluate 隐含 W、Object 类型参数,输入一个 Input,以两次布尔全称检查计算判定。\n\n\n **L40** 先要求全部初始测试通过;空列表的 List.all 为 true。\n\n\n **L41** 初始测试与全部请求案例均通过时返回 supportedWithinScope;初始列表为空也可能如此。\n\n\n **L42** 初始测试通过而请求案例中有失败时,返回 counterexample。\n\n\n **L43** 初始案例失败时返回 noSupportingSample;名称不意味着实现检查了空列表。\n\n\n **L45** 注释把生成描述为提议测试,并开始区分提议与验证。\n\n\n **L46** 注释否认提议生成能证明测试通过或采纳有据。\n\n\n **L47** generate 隐含样本与对象类型参数,依据输入产生一个提议结果。\n\n\n **L48** 把 requested 同时复制到生成测试与范围;此处不验证任一列表。\n\n\n **L50** interpret 接收活动与输入,两个类型参数均隐含。\n\n\n **L51** 最后一个显式参数是结果;返回值是关于该结果的命题。\n\n\n **L52** 要求理由列表非空、输入依据命题成立,再按活动分支。\n\n\n **L53** 生成活动的含义是结果恰等于该输入的实际生成器输出。\n\n\n **L54** 评估活动的含义是结果恰等于 evaluate 对此输入计算的判定。\n\n\n **L56** Model 对 W、Object 参数化,提供目标成员、合约、适用性和记录结果。\n\n\n **L57** 模型具有一个自然数所有者标识。\n\n\n **L58** 仅此有限列表中的对象可满足 Model.self。\n\n\n **L59** 为每个 Object 值分配合约,包括 objects 列表以外的值。\n\n\n **L60** 请求案例依赖对象与阶段。\n\n\n **L61** 理由字符串依赖同一对象与阶段。\n\n\n **L62** 依据命题也依赖该对象与阶段。\n\n\n **L63** 命题逐对象、逐阶段确定生成适用性。\n\n\n **L64** 另一命题确定评估适用性。\n\n\n **L65** 记录结果依赖活动、对象与阶段;此处不假定其正确。\n\n\n **L67** Model.input 为任意目标构建检查输入,本身不检查所有者或成员资格。\n\n\n **L68** 保留目标本身,按其实际对象和阶段选取合约、请求案例及理由。\n\n\n **L69** 以同一对象、阶段选出的依据补全输入。\n\n\n **L71** Model.self 是目标的成员与所有权谓词。\n\n\n **L72** 同时要求所有者相等、实际对象属于列表;此处不限制阶段。\n\n\n **L74** 给定模型与活动,构造对应的反身规则。\n\n\n **L75** 规则的目标、输入、输出类型分别固定为 Target Object、Input W Object、Outcome W。\n\n\n **L76** 键由模型所有者和局部编号组成,生成用 0,评估用 1。\n\n\n **L77** 在规则中保留传入的活动。\n\n\n **L78** 适用性要求目标属于自身,且满足对应活动的适用条件。\n\n\n **L79** 生成采用此对象在此阶段的 generationApplies。\n\n\n **L80** 评估采用此对象在此阶段的 assessmentApplies。\n\n\n **L81** 实际规则输入采用模型按目标构造的 input。\n\n\n **L82** 规则含义采用该活动的实际 interpret 函数。\n\n\n **L84** 构建此模型的规则列表,两个泛型类型由推断确定。\n\n\n **L85** 规则列表仅含生成与评估两项,依次排列。\n\n\n **L87** 注释指出 performed 数据是陈述记录,另由 follows 检查。\n\n\n **L88** 注释说明要与实际输入评估比较,不能由结果名称推断成功。\n\n\n **L89** 定义属于此模型的记录执行关系。\n\n\n **L90** 关系显式接收原则键、目标、输入、结果并返回 Prop。\n\n\n **L91** 要求目标属于自身,且输入恰等于该目标实际构造的输入。\n\n\n **L92** 存在一个活动,其规则键等于传入的键。\n\n\n **L93** 结果必须恰等于该活动与同一对象、阶段的记录。\n\n\n **L95** Model.follows 表述所有适用记录均满足其实际含义。\n\n\n **L96** 全称量化活动、对象、阶段,再假设对象属于列表。\n\n\n **L97** 下一前提按活动选取适用性。\n\n\n **L98** 对生成,要求所量化对象、阶段的 generationApplies。\n\n\n **L99** 对评估,要求 assessmentApplies,再断言解释成立。\n\n\n **L100** 将记录结果与实际输入核对,目标所有者固定为 m.owner。\n\n\n **L102** 注释强调通用蕴涵保留实质评估前提。\n\n\n **L103** 注释要求具体实例为各自实际合约证明 follows。\n\n\n **L104** 对任意类型和模型,此定理假设 checked : m.follows,并不证明此前提。\n\n\n **L105** 在此前提下,证明 reflexivitySpecification 中的规则键身份与适用的自执行要求。\n\n\n **L106** 将规范拆为身份与执行两个证明义务。\n\n\n **L107** 引入列表内的两个规则,并假设其键相等。\n\n\n **L108** 将两项规则列表的成员资格展开为生成或评估两种可能。\n\n\n **L109** 替换两个成员的可能值,形成四种规则配对。\n\n\n **L110** 两个规则属于同一活动时,所需相等由反身性成立。\n\n\n **L111** 对生成与评估的配对,把键相等投影到 localId,得到 0 = 1 的矛盾。\n\n\n **L112** 对评估与生成的配对,相同投影得到 1 = 0 的矛盾。\n\n\n **L113** 两个规则属于同一活动时,所需相等由反身性成立。\n\n\n **L114** 为执行义务引入列表规则、自身目标及适用性证明。\n\n\n **L115** 将规则成员资格化为两个活动的可能值。\n\n\n **L116** 通过替换,分别处理生成与评估。\n\n\n **L117** 在生成分支,选择此目标对象、阶段的生成记录作为存在见证。\n\n\n **L118** 利用自身成员资格、精确输入与生成活动证明 performed,留下含义义务。\n\n\n **L119** 以 hs 的对象成员资格与 ha 的适用性,将 checked 用于该生成记录。\n\n\n **L120** 把目标拆为所有者、对象、阶段,显露所有者相等关系。\n\n\n **L121** 从自身目标前提提取 owner = m.owner。\n\n\n **L122** 代入模型所有者,使 checked 与目标指向相同输入。\n\n\n **L123** 先前取得的实际解释此时恰好关闭目标。\n\n\n **L124** 在评估分支,选择同一目标的评估记录作为见证。\n\n\n **L125** 以评估活动和精确输入、输出身份构造 performed。\n\n\n **L126** 将 checked 用于评估,保留此目标的成员及适用性前提。\n\n\n **L127** 把目标拆为所有者、对象、阶段,显露所有者相等关系。\n\n\n **L128** 从自身目标前提提取 owner = m.owner。\n\n\n **L129** 代入模型所有者,使 checked 与目标指向相同输入。\n\n\n **L130** 先前取得的实际解释此时恰好关闭目标。\n\n\n **L132** 关闭 CoreReader.Engineering.Reflection 命名空间;不另行断言数学主张。\n\n\n### `leanified/CoreReader/Engineering/SelfApplication.lean`\n\n\n```lean\nimport CoreReader.Engineering.Values\nimport CoreReader.Engineering.Reflection\n\nnamespace CoreReader.Engineering\n\nopen CoreReader.Adopted\n\ninductive ReviewObject | activity | commitment (principle : CoreCommitment) | priority | evolutionMethod\n | generationRule | assessmentRule\n deriving DecidableEq, Repr\n\nabbrev ReviewCase := Candidate × Nat\n\ndef generationApplies (_ : ReviewObject) (phase : CoreReader.Agency.Phase) : Prop :=\n phase ≠ .application\n\ndef assessmentApplies (_ : ReviewObject) (_ : CoreReader.Agency.Phase) : Prop := True\n\ndef ruleObject : CoreReader.Agency.Activity → ReviewObject\n | .generation => .generationRule\n | .assessment => .assessmentRule\n\n/- These inputs test the current reflection functions themselves. Size 10 has\nan actual supporting sample; size 5 removes that sample while retaining the\nrequested claim. The domain batch predictor is not used in this method test. -/\ndef ruleProbe (activity : CoreReader.Agency.Activity) (point : ReviewCase) :\n Reflection.Input ReviewCase ReviewObject where\n target := ⟨0, ruleObject activity, .revision⟩\n contract := ⟨fun _ => true, if point.2 = 10 then [point] else [], [point]⟩\n requested := [point]\n reasons := [\"retain the proposed scope and distinguish actual samples from an empty test set\"]\n basis := True\n\ndef generationRuleTest\n (method : Reflection.Input ReviewCase ReviewObject → Reflection.Outcome ReviewCase)\n (point : ReviewCase) : Bool :=\n let input := ruleProbe .generation point\n method input == .generated input.requested input.requested\n\ndef assessmentRuleTest\n (method : Reflection.Input ReviewCase ReviewObject → Reflection.Verdict)\n (point : ReviewCase) : Bool :=\n method (ruleProbe .assessment point) ==\n (if point.2 = 10 then .supportedWithinScope else .noSupportingSample)\n\n/- A candidate revision supplies the previously missing empty-sample check.\nIt is kept distinct from the current evaluator and is not silently adopted. -/\ndef sampleAwareAssessment (input : Reflection.Input ReviewCase ReviewObject) : Reflection.Verdict :=\n if input.contract.tested.isEmpty then .noSupportingSample else Reflection.evaluate input\n\n/- The method under criticism is the activity's own static batch forecast. Its\ncontract is checked at its original size and at the credible runtime change. -/\ndef objectTest (object : ReviewObject) (point : ReviewCase) : Bool :=\n match object with\n | .activity => decide (Meets currentContinuing.required (currentContinuing.profiles point.1))\n | .commitment principle => safeguardExperiment principle true point.1\n | .priority => decide (EvolutionPriority currentContinuing point.1)\n | .evolutionMethod => staticBatch 21 point.2 == liveBatch 21 point.2\n | .generationRule => generationRuleTest Reflection.generate point\n | .assessmentRule => assessmentRuleTest Reflection.evaluate point\n\ndef reviewObjects (chosen : Candidate) : List ReviewObject :=\n [.activity] ++ coreCommitments.map ReviewObject.commitment ++\n (if chosen = .evolvable then [.priority] else []) ++\n [.evolutionMethod, .generationRule, .assessmentRule]\n\ndef requestedCases (chosen : Candidate) : CoreReader.Agency.Phase → List ReviewCase\n | .formation | .application => [(chosen, 10)]\n | .revision => [(chosen, 10), (chosen, 5)]\n\ndef reviewReasons (object : ReviewObject) (phase : CoreReader.Agency.Phase) : List String :=\n let content := match object with\n | .activity => \"actual order, safety, latency and retention requirements of this activity\"\n | .commitment principle => criticismFor principle\n | .priority => \"credible design revision, successor and agent paths, necessary requirements and concrete costs\"\n | .evolutionMethod => \"the same batch forecast at its recorded size and the proposed runtime size\"\n | .generationRule => \"the actual generator must retain its input's requested tests and scope\"\n | .assessmentRule => \"the actual evaluator's acceptance depends on whether its input has supporting samples\"\n [content, match phase with\n | .formation => \"identify this object's purpose and the conditions of its initial contract\"\n | .application => \"apply that contract to the currently selected design in this continuing activity\"\n | .revision => \"examine the proposed wider input scope and retain any counterexample\"]\n\n/- The recorded verdict is independent of the evaluator: the revision of the\nbatch method is explicitly reported as a counterexample; other current checks\nare reported supported only in the scope that will be checked below. -/\ndef statedReview (chosen : Candidate) (activity : CoreReader.Agency.Activity)\n (object : ReviewObject) (phase : CoreReader.Agency.Phase) : Reflection.Outcome ReviewCase :=\n match activity with\n | .generation => .generated (requestedCases chosen phase) (requestedCases chosen phase)\n | .assessment => .assessed (match object, phase with\n | .evolutionMethod, .revision | .assessmentRule, .revision => .counterexample\n | _, _ => .supportedWithinScope)\n\n/- The basis is not a free approval flag. Each inquiry requires the facts\nrelevant to its own object; a counterexample can ground criticism rather than\nthe truth of the original method's broader claim. -/\ndef reviewBasis (chosen : Candidate) : ReviewObject → CoreReader.Agency.Phase → Prop\n | .activity, _ => ActivityScope currentContinuing.activity ∧\n Meets currentContinuing.required (currentContinuing.profiles chosen)\n | .commitment principle, _ => ReasonRelevant principle (reasonFor principle) chosen\n | .priority, _ => PriorityConditions currentContinuing ∧ ¬ HasThreat currentContinuing .evolvable\n | .evolutionMethod, .revision =>\n staticBatch 21 10 = liveBatch 21 10 ∧ staticBatch 21 5 ≠ liveBatch 21 5\n | .evolutionMethod, _ => staticBatch 21 10 = liveBatch 21 10\n | .generationRule, _ =>\n generationRuleTest Reflection.generate (chosen, 10) = true ∧\n generationRuleTest (fun _ => .generated [] []) (chosen, 10) = false\n | .assessmentRule, .revision =>\n assessmentRuleTest Reflection.evaluate (chosen, 10) = true ∧\n assessmentRuleTest Reflection.evaluate (chosen, 5) = false\n | .assessmentRule, _ => assessmentRuleTest Reflection.evaluate (chosen, 10) = true\n\ndef selfModel (chosen : Candidate) : Reflection.Model ReviewCase ReviewObject where\n owner := 0\n objects := reviewObjects chosen\n contracts object := ⟨objectTest object, [(chosen, 10)], [(chosen, 10)]⟩\n requested _ := requestedCases chosen\n reasons := reviewReasons\n basis := reviewBasis chosen\n generationApplies := generationApplies\n assessmentApplies := assessmentApplies\n recorded := statedReview chosen\n\n/- The named normative object and its finite rationale test are deliberately\ndistinct: a supported rationale experiment is not proof of universal correctness.\nThe same commitment identifier controls adoption, reasons and reflection. -/\ntheorem reviewIdentity (chosen : Candidate) (object : ReviewObject)\n (phase : CoreReader.Agency.Phase) :\n ((selfModel chosen).input ⟨0, object, phase⟩).target.object = object ∧\n ((selfModel chosen).input ⟨0, object, phase⟩).contract.test = objectTest object ∧\n ((selfModel chosen).input ⟨0, object, phase⟩).requested = requestedCases chosen phase ∧\n ((selfModel chosen).input ⟨0, object, phase⟩).reasons = reviewReasons object phase ∧\n ((selfModel chosen).input ⟨0, object, phase⟩).basis = reviewBasis chosen object phase :=\n ⟨rfl, rfl, rfl, rfl, rfl⟩\n\ntheorem currentSelfRecords (chosen : Candidate)\n (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) :\n (selfModel chosen).follows := by\n rcases ordinary with rfl | rfl\n all_goals\n intro activity object phase member applies\n cases activity <;> cases object <;> cases phase\n all_goals first\n | rename_i principle; cases principle\n | skip\n all_goals simp_all [Reflection.interpret, Reflection.Model.input,\n Reflection.evaluate, selfModel, statedReview, reviewObjects, coreCommitments,\n requestedCases, reviewReasons, criticismFor, objectTest, safeguardExperiment,\n generationApplies, assessmentApplies, generationRuleTest, assessmentRuleTest,\n ruleProbe, Reflection.generate,\n reviewBasis, ReasonRelevant, reasonFor, HasThreat, burdens, ConcreteThreat, cost,\n EvolutionPriority, PriorityConditions, JustifiedDeparture, currentContinuing,\n Continuing, ActivityScope, Meets, profile, normalRequirements, initialGrounds,\n ContinuingCapability, continuingActivity, maintainers, changePath,\n changeWork, abstractionComplexity, credible, CredibleDirection, articulateGround,\n supportGround, normalLimits, staticBatch, liveBatch, batchCount, orderedUnique,\n sortedUnique, sortValues, insertOrdered, List.eraseDups]\n all_goals decide\n\ntheorem currentSelfApplication (chosen : Candidate)\n (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) :\n reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self\n (selfModel chosen).performed :=\n Reflection.recordedReflexivity _ (currentSelfRecords chosen ordinary)\n\n/- The activity's own assessment method passes its old observation while the\nexpanded input exposes its actual failed forecast. Neither applying the method\nto itself nor generating a broader candidate makes the failed forecast true. -/\ntheorem actualSelfCriticism (chosen : Candidate) :\n objectTest .evolutionMethod (chosen, 10) = true ∧\n objectTest .evolutionMethod (chosen, 5) = false ∧\n Reflection.evaluate ((selfModel chosen).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧\n statedReview chosen .generation .evolutionMethod .revision =\n .generated [(chosen, 10), (chosen, 5)] [(chosen, 10), (chosen, 5)] ∧\n staticBatch 21 5 ≠ liveBatch 21 5 := by\n refine ⟨?_, ?_, ?_, rfl, by decide⟩\n · change (staticBatch 21 10 == liveBatch 21 10) = true\n decide\n · change (staticBatch 21 5 == liveBatch 21 5) = false\n decide\n · simp [Reflection.evaluate, Reflection.Model.input, selfModel, requestedCases,\n objectTest, staticBatch, liveBatch, batchCount]\n\n/- The objects use the very functions in the adopted rules, and the same\napplicability functions. Assessment applies in all three phases; generation\napplies to formation and revision, including formation/revision of these rules. -/\ntheorem ownRuleIdentity (chosen : Candidate) (activity : CoreReader.Agency.Activity)\n (phase : CoreReader.Agency.Phase) :\n ruleObject activity ∈ (selfModel chosen).objects ∧\n ((selfModel chosen).rule activity).meaning = Reflection.interpret activity ∧\n ((selfModel chosen).input ⟨0, ruleObject activity, phase⟩).contract.test =\n objectTest (ruleObject activity) ∧\n (selfModel chosen).generationApplies (ruleObject activity) phase =\n generationApplies (ruleObject activity) phase ∧\n (selfModel chosen).assessmentApplies (ruleObject activity) phase =\n assessmentApplies (ruleObject activity) phase := by\n refine ⟨?_, rfl, rfl, rfl, rfl⟩\n cases activity <;> simp [ruleObject, selfModel, reviewObjects]\n\n/- Changing the actual generator changes its object's result despite keeping\nthe object name. The evaluator really approves an empty initial sample set;\nits own revision review reports that bounded defect instead of a self-proof. -/\ntheorem ownRuleContentVariation (chosen : Candidate) :\n generationRuleTest Reflection.generate (chosen, 10) = true ∧\n generationRuleTest (fun _ => .generated [] []) (chosen, 10) = false ∧\n assessmentRuleTest Reflection.evaluate (chosen, 10) = true ∧\n assessmentRuleTest Reflection.evaluate (chosen, 5) = false ∧\n Reflection.evaluate ((selfModel chosen).input ⟨0, .assessmentRule, .revision⟩) = .counterexample ∧\n generationApplies .generationRule .formation ∧\n generationApplies .generationRule .revision ∧\n ¬ generationApplies .generationRule .application ∧\n (∀ phase, assessmentApplies .assessmentRule phase) := by\n simp [generationRuleTest, assessmentRuleTest, ruleProbe, Reflection.generate,\n Reflection.evaluate, Reflection.Model.input, selfModel, requestedCases,\n objectTest, generationApplies, assessmentApplies]\n\ntheorem proposedRuleRevision (chosen : Candidate) :\n assessmentRuleTest Reflection.evaluate (chosen, 5) = false ∧\n assessmentRuleTest sampleAwareAssessment (chosen, 5) = true ∧\n assessmentRuleTest sampleAwareAssessment (chosen, 10) = true ∧\n ((selfModel chosen).rule .generation).applicable ⟨0, .generationRule, .revision⟩ ∧\n ¬ (({ selfModel chosen with generationApplies := fun _ _ => False }).rule .generation).applicable\n ⟨0, .generationRule, .revision⟩ := by\n simp [assessmentRuleTest, sampleAwareAssessment, ruleProbe, Reflection.evaluate,\n Reflection.Model.rule, Reflection.Model.self, selfModel, reviewObjects,\n generationApplies]\n\nend CoreReader.Engineering\n```\n\n\n\n **L1** 导入 CoreReader.Engineering.Values,使其声明及传递依赖可用;此行不新增命题。\n\n\n **L2** 导入 CoreReader.Engineering.Reflection,使其声明及传递依赖可用;此行不新增命题。\n\n\n **L4** 开启 CoreReader.Engineering 命名空间,后续声明归入其中。\n\n\n **L6** 允许不带完整限定名引用 CoreReader.Adopted 中的声明;不改变其含义。\n\n\n **L8** ReviewObject 区分活动、带 Core 原则参数的承诺、优先性和演化方法。\n\n\n **L9** 在同一对象类型中加入实际生成规则与评估规则对象。\n\n\n **L10** 自动派生 DecidableEq, Repr:提供这些构造子的可判定相等与可打印表示。\n\n\n **L12** 检查案例是所选 Candidate 与自然数规模组成的二元组。\n\n\n **L14** 生成适用性忽略对象身份,仅依赖生命周期阶段。\n\n\n **L15** 生成恰在 application 以外适用,即形成与修订阶段。\n\n\n **L17** 评估适用性忽略两个参数,对所有对象、所有阶段均为真。\n\n\n **L19** 把每种实际活动映射为其对应的方法检查对象。\n\n\n **L20** 生成活动对应 generationRule。\n\n\n **L21** 评估活动对应 assessmentRule。\n\n\n **L23** 注释说明这些探针针对当前反思函数本身,并引入规模 10 案例。\n\n\n **L24** 注释比较规模 10 的真实初始样本与规模 5 对该样本的移除。\n\n\n **L25** 注释保留请求主张,并区分此实际规则测试与领域批处理预测器。\n\n\n **L26** 按活动和候选项、规模二元组,为实际方法构造探针。\n\n\n **L27** 探针样本类型为 ReviewCase,目标类型为 ReviewObject。\n\n\n **L28** 所有者固定为 0,阶段固定为修订,对象由活动选取。\n\n\n **L29** 内层测试恒通过;仅规模 10 提供初始样本,claimed 始终含此案例。\n\n\n **L30** 即使初始样本列表为空,仍保留此案例为请求案例。\n\n\n **L31** 提供非空理由,说明范围保留及空初始列表的区分。\n\n\n **L32** 探针依据为 True;该字段不提供额外经验论证。\n\n\n **L34** generationRuleTest 测试传入的 method 函数,允许实际替换函数。\n\n\n **L35** 方法必须把此精确反思输入类型映射到对应结果类型。\n\n\n **L36** 对给定案例,返回布尔合约结果。\n\n\n **L37** 为同一案例构造生成探针。\n\n\n **L38** 要求结果恰等于以 requested 为测试和范围的生成结果。\n\n\n **L40** assessmentRuleTest 按局部区分样本的合约检查显式传入的评估器。\n\n\n **L41** 待评估方法接收此精确输入类型并返回 Verdict。\n\n\n **L42** 每个候选项、规模案例得到布尔通过或失败结果。\n\n\n **L43** 把实际方法对评估探针的判定与下行期望判定比较。\n\n\n **L44** 规模 10 期望支持,其余规模期望 noSupportingSample;这是局部合约,不是普遍经验义务。\n\n\n **L46** 注释介绍加入缺失的空初始列表检查的修订候选。\n\n\n **L47** 注释明确把候选与当前已安装评估器分开。\n\n\n **L48** 在同一输入类型上定义独立的评估器修订候选。\n\n\n **L49** 先对空初始测试列表返回无支持样本,对非空列表再调用当前 evaluate。\n\n\n **L51** 注释将 evolutionMethod 分支介绍为对此活动自身静态批次数预测的批评。\n\n\n **L52** 注释比较原规模与可信改变后的运行规模。\n\n\n **L53** objectTest 按实际检查对象选取操作性布尔测试。\n\n\n **L54** 匹配对象构造子以选择其特定测试。\n\n\n **L55** 对活动,判定所选设计指标是否满足当前必要需求。\n\n\n **L56** 对原则承诺,在所选设计上运行对应的已启用保障实验。\n\n\n **L57** 对优先性,判定 currentContinuing 中的实际 EvolutionPriority 命题。\n\n\n **L58** 对演化方法,比较 21 项任务在此规模下的静态与实时批次数预测。\n\n\n **L59** 对生成规则,把实际 Reflection.generate 函数传入测试。\n\n\n **L60** 对评估规则,把实际 Reflection.evaluate 函数传入测试。\n\n\n **L62** 按所选设计构造有限检查对象列表。\n\n\n **L63** 纳入活动以及五个 Core 承诺,沿用其原有标识。\n\n\n **L64** 仅在选择 evolvable 时纳入优先性对象。\n\n\n **L65** 始终纳入批处理方法及两个实际规则对象。\n\n\n **L67** 请求案例依赖所选设计及生命周期阶段。\n\n\n **L68** 形成和应用阶段仅请求规模 10。\n\n\n **L69** 修订阶段将请求列表扩展为同一设计的规模 10 与 5。\n\n\n **L71** 逐对象、逐阶段构造理由字符串。\n\n\n **L72** 按实际对象构造子选择第一条理由。\n\n\n **L73** 活动理由指出其顺序、安全、延迟与保留需求。\n\n\n **L74** 原则承诺复用由同一原则索引的批评字符串。\n\n\n **L75** 优先性理由指出证据、维护者路径、需求及成本。\n\n\n **L76** 方法理由比较同一预测在记录规模与提议运行规模下的结果。\n\n\n **L77** 生成器理由要求保留请求测试与范围。\n\n\n **L78** 评估器理由陈述此处对是否存在支持样本的局部要求。\n\n\n **L79** 返回对象特定理由,再附上阶段特定理由。\n\n\n **L80** 形成阶段要求辨明对象目的与初始合约条件。\n\n\n **L81** 应用阶段指出当前所选设计与持续活动。\n\n\n **L82** 修订阶段要求检查更广输入并保留反例。\n\n\n **L84** 注释强调 statedReview 的记录独立于 evaluate 定义。\n\n\n **L85** 注释指出批处理方法修订被明确记录为反例。\n\n\n **L86** 注释把其他支持记录限于后续证明检查的有限范围。\n\n\n **L87** statedReview 独立记录给定设计及活动的结果。\n\n\n **L88** 记录同时依赖对象与阶段,类型为精确的反思结果类型。\n\n\n **L89** 区分生成记录与评估记录。\n\n\n **L90** 生成把该阶段的请求列表记录于两个输出字段。\n\n\n **L91** 评估按对象与阶段选取记录判定,不调用 evaluate。\n\n\n **L92** 批处理方法或评估规则的修订被明确记录为反例。\n\n\n **L93** 其余对象、阶段的评估均记录为 supportedWithinScope。\n\n\n **L95** 注释把 basis 介绍为对象特定事实内容,而非不受限制的批准标记。\n\n\n **L96** 注释说明反例能支持对同一对象的批评。\n\n\n **L97** 注释否认这种批评支持能建立方法原本的更广主张。\n\n\n **L98** reviewBasis 给出对象特定命题;后续为两个普通设计检查证明。\n\n\n **L99** 活动检查要求实际活动的范围条件。\n\n\n **L100** 还要求所选指标满足当前必要需求。\n\n\n **L101** 原则检查要求该同一原则理由对当前选择具有事实相关性。\n\n\n **L102** 优先性检查要求当前适用条件及 evolvable 不受威胁。\n\n\n **L103** 修订分支为批处理方法检查提供更强依据。\n\n\n **L104** 要求规模 10 成功,且规模 5 存在实际不相等。\n\n\n **L105** 其他批处理方法阶段仅要求规模 10 的相等。\n\n\n **L106** 生成器依据包含对实际函数内容的正反测试。\n\n\n **L107** 真实生成器必须在所选设计、规模 10 上通过。\n\n\n **L108** 输出为空的生成器必须在同一案例上失败。\n\n\n **L109** 评估规则修订要求两个案例的对比。\n\n\n **L110** 当前评估器必须在规模 10 上通过局部样本合约测试。\n\n\n **L111** 它必须在规模 5、初始列表为空时不满足该合约。\n\n\n **L112** 其他评估规则阶段仅要求规模 10 的正例。\n\n\n **L114** selfModel 为所选设计以这些案例、对象实例化反思模型。\n\n\n **L115** 把模型所有者设为 0。独立的 self 关系要求自身目标与之匹配;原始 Model.input 仍可接收并保留任意所有者的目标。\n\n\n **L116** 采用依赖选择的实际对象列表。\n\n\n **L117** 每个外层合约采用对应 objectTest,初始测试与声称列表均含规模 10。\n\n\n **L118** 所有对象共享所选设计的阶段特定 requestedCases。\n\n\n **L119** 采用实际的对象、阶段理由构造函数。\n\n\n **L120** 采用实质的对象、阶段依据谓词。\n\n\n **L121** 安装实际生成适用性函数。\n\n\n **L122** 安装实际评估适用性函数。\n\n\n **L123** 采用独立陈述的记录,后续由 currentSelfRecords 验证。\n\n\n **L125** 注释开始区分实际规范对象与其有限理由实验。\n\n\n **L126** 注释否认理由实验成功能证明规范普遍正确。\n\n\n **L127** 注释说明采纳、理由与反思之间预期保持同一标识的连接。\n\n\n **L128** 对每个设计与对象,reviewIdentity 确认输入各部分的身份。\n\n\n **L129** 该身份关系对所有生命周期阶段成立。\n\n\n **L130** 输入的目标对象恰为传入对象。\n\n\n **L131** 其测试恰为同一对象的 objectTest。\n\n\n **L132** 其请求列表恰为所选设计在此阶段的列表。\n\n\n **L133** 其理由恰对应同一对象及阶段。\n\n\n **L134** 其依据恰为同一设计、对象、阶段的谓词。\n\n\n **L135** 五项身份均由定义反身性成立,不是经验验证。\n\n\n **L137** currentSelfRecords 检查所选设计的记录。\n\n\n **L138** 前提把 chosen 限为 presentSimple 或 evolvable,排除 maximal。\n\n\n **L139** 结论为 follows,包含每条适用记录的实际解释要求。\n\n\n **L140** 拆开普通设计前提,分别代入两种设计。\n\n\n **L141** 将后续证明步骤应用于两个设计目标。\n\n\n **L142** 引入任意活动、对象、阶段及成员、适用性前提。\n\n\n **L143** 穷尽活动、对象、阶段的全部构造子。\n\n\n **L144** 对所有剩余目标,依序尝试下列局部策略。\n\n\n **L145** 存在承诺参数时,将其命名为 principle 并拆分五种构造子。\n\n\n **L146** 否则保留目标,不要求存在 principle 参数。\n\n\n **L147** 用实际解释和输入构造化简全部目标与假设。\n\n\n **L148** 展开评估器、模型、陈述记录及有限对象列表。\n\n\n **L149** 展开请求案例、理由、对象测试与保障实验。\n\n\n **L150** 展开两个适用性谓词与实际规则测试定义。\n\n\n **L151** 展开内层方法探针及实际生成器。\n\n\n **L152** 展开依据、相关性以及具体威胁、成本谓词。\n\n\n **L153** 展开优先性、适用性、偏离与固定当前语境。\n\n\n **L154** 展开活动范围、必要需求、指标与初始证据。\n\n\n **L155** 展开持续能力、维护者列表及实际改变路径。\n\n\n **L156** 展开工作量、复杂度以及所述方向的可信性。\n\n\n **L157** 展开证据支持、限制、批次数算术与保序输出。\n\n\n **L158** 展开有限检查所需的排序与去重辅助函数。\n\n\n **L159** 在分情况与化简后判定所有剩余封闭有限命题。\n\n\n **L161** currentSelfApplication 为所选设计导出反身性。\n\n\n **L162** 保留显式的两种普通设计前提。\n\n\n **L163** 规范采用同一 selfModel 的规则与自身目标谓词。\n\n\n **L164** 其执行关系也取自同一模型。\n\n\n **L165** 把实际证明的 currentSelfRecords 作为前提应用通用 recordedReflexivity 定理。\n\n\n **L167** 注释指出活动的批处理评估方法在旧观测上成功。\n\n\n **L168** 注释说明扩展输入揭示预测失败,并开始限定自应用的作用。\n\n\n **L169** 注释否认自应用或生成更广候选会使失败预测变真。\n\n\n **L170** actualSelfCriticism 对任意设计成立,展示批处理方法的有限失败。\n\n\n **L171** 旧规模 10 的批处理测试通过。\n\n\n **L172** 规模 5 的批处理测试失败。\n\n\n **L173** 实际修订评估器对同一方法对象报告反例。\n\n\n **L174** 指定该方法修订的独立生成记录。\n\n\n **L175** 两个生成列表均含同一设计的规模 10 与 5。\n\n\n **L176** 结论还保留底层批次数预测的不相等。\n\n\n **L177** 构造五个合取项;生成项由反身性、算术不等由可判定性完成,留下三项检查。\n\n\n **L178** 把第一证明目标显化为规模 10 的布尔相等测试。\n\n\n **L179** 计算此封闭的规模 10 相等式。\n\n\n **L180** 把下一目标显化为规模 5 的布尔测试失败。\n\n\n **L181** 计算此封闭的规模 5 失败结果。\n\n\n **L182** 为反例目标展开评估器及实际模型输入。\n\n\n **L183** 化简对象测试和批次数算术以完成反例计算。\n\n\n **L185** 注释强调检查对象与已采纳规则实际使用函数的身份一致。\n\n\n **L186** 注释保留相同适用性函数及全部阶段的评估。\n\n\n **L187** 注释把生成规则自身的形成、修订纳入生成适用阶段。\n\n\n **L188** ownRuleIdentity 将每个设计、活动连接到实际规则对象与实现。\n\n\n **L189** 连接对所有阶段陈述,无论生成是否在那里适用。\n\n\n **L190** 该活动的方法对象实际属于模型对象列表。\n\n\n **L191** 模型规则含义恰为实际 interpret activity 函数。\n\n\n **L192** 同一规则对象的输入取得其实际合约测试。\n\n\n **L193** 该测试为按此相同方法对象索引的 objectTest。\n\n\n **L194** 比较模型在此对象、阶段的生成适用性。\n\n\n **L195** 它等于声明的 generationApplies 对同一参数的值。\n\n\n **L196** 比较模型在此对象、阶段的评估适用性。\n\n\n **L197** 它等于 assessmentApplies 对这些相同参数的值。\n\n\n **L198** 四个函数、字段相等由反身性完成,仅留下实际对象成员资格。\n\n\n **L199** 拆分活动并计算实际检查对象列表中的成员资格。\n\n\n **L201** 注释说明即使对象名称不变,替换生成器内容仍会改变结果。\n\n\n **L202** 注释记录实际评估器在初始样本为空时接受;请求案例仍受检查。\n\n\n **L203** 注释把外层自身检查界定为报告这一有界局部合约缺陷,而非证明自身普遍有效。\n\n\n **L204** ownRuleContentVariation 为每个设计提供对函数内容敏感的正反案例。\n\n\n **L205** 当前生成器通过规模 10 的保留测试。\n\n\n **L206** 输出为空的生成器未通过同一测试。\n\n\n **L207** 当前评估器在有规模 10 样本时通过局部样本合约。\n\n\n **L208** 它在规模 5、初始样本列表为空时未满足该合约。\n\n\n **L209** 实际评估规则对象的外层修订评估报告反例。\n\n\n **L210** 生成适用于自身规则对象的形成。\n\n\n **L211** 它也适用于自身规则对象的修订。\n\n\n **L212** 生成不适用于该对象的应用阶段。\n\n\n **L213** 评估对自身规则对象在每个阶段均适用。\n\n\n **L214** 在各合取项中展开实际方法测试、探针与生成器。\n\n\n **L215** 展开评估器、实际输入、模型与请求案例。\n\n\n **L216** 化简对象测试及两个适用性谓词,完成有限检查。\n\n\n **L218** proposedRuleRevision 比较当前与候选评估器,并检查一次适用性变更。\n\n\n **L219** 当前评估器不满足局部空初始样本合约。\n\n\n **L220** 独立的 sampleAwareAssessment 候选通过该规模 5 合约。\n\n\n **L221** 候选也保留规模 10 的正例结果。\n\n\n **L222** 当前生成规则适用于自身生成规则对象的修订。\n\n\n **L223** 另一个将 generationApplies 改为恒假的模型更新消除了此适用性。\n\n\n **L224** 被消除的适用性恰针对所有者 0、generationRule 与修订阶段。\n\n\n **L225** 展开局部测试、候选评估器、探针与当前评估器。\n\n\n **L226** 展开实际规则、自身目标语义与模型对象成员资格。\n\n\n **L227** 化简生成适用性完成合取;此处未安装任一候选变更。\n\n\n **L229** 关闭 CoreReader.Engineering 命名空间;不另行断言数学主张。\n\n\n### `leanified/CoreReader/Engineering/Values.lean`\n\n\n```lean\nimport CoreReader.Adopted\nimport CoreReader.Engineering.Domain\n\nnamespace CoreReader.Engineering\n\nopen CoreReader.Logic CoreReader.Evidence CoreReader.Adopted\n\ninductive CoreCommitment | generation | consistency | reflexivity | grounds | choice\n deriving DecidableEq, Repr\n\ndef coreCommitments : List CoreCommitment :=\n [.generation, .consistency, .reflexivity, .grounds, .choice]\n\n/- Initial adoption is explicit. The following reasons neither infer adoption\nfrom facts nor claim that every alternative value position is untenable. -/\ndef coreAdopted (_ : CoreCommitment) : Bool := true\n\ninductive AdoptionReason\n | plannedChange (release : Nat) (direction : Change)\n | incompatibleOrders (input : List Nat)\n | ownMethodCounterexample (items size : Nat)\n | unsupportedScope (items observedSize extendedSize : Nat)\n | statusBudgetContrast (statusSelected : Candidate) (capacity : Nat)\n deriving DecidableEq, Repr\n\ndef reasonFor : CoreCommitment → AdoptionReason\n | .generation => .plannedChange 2 .designRevision\n | .consistency => .incompatibleOrders [2, 1, 2]\n | .reflexivity => .ownMethodCounterexample 21 5\n | .grounds => .unsupportedScope 21 10 5\n | .choice => .statusBudgetContrast .maximal 12\n\n/- Each factual reason has contents specific to the principle's purpose. The\ncontext is the very continuing activity and its current requirements/grounds.\nMatching a constructor alone is insufficient: the represented facts must hold. -/\nabbrev ReasonRelevant : CoreCommitment → AdoptionReason → Candidate → Prop\n | .generation, .plannedChange release direction, _ =>\n DirectionGround.plan release [direction, .migration] ∈ currentContinuing.evidence ∧\n credible currentContinuing.evidence direction ∧ Continuing currentContinuing.activity\n | .consistency, .incompatibleOrders input, _ =>\n currentContinuing.required.orderRequired = true ∧\n orderedUnique input ≠ sortedUnique input\n | .reflexivity, .ownMethodCounterexample items size, _ =>\n staticBatch items 10 = liveBatch items 10 ∧ staticBatch items size ≠ liveBatch items size\n | .grounds, .unsupportedScope items observedSize extendedSize, _ =>\n staticBatch items observedSize = liveBatch items observedSize ∧\n staticBatch items extendedSize ≠ liveBatch items extendedSize\n | .choice, .statusBudgetContrast candidate capacity, selected =>\n capacity = currentContinuing.limits.capacity .understanding ∧\n capacity < abstractionComplexity candidate ∧ abstractionComplexity selected ≤ capacity\n | _, _, _ => False\n\nabbrev valueScope (selected : Candidate) : Prop := abstractionComplexity selected ≤ 3\n\n/- A small operational experiment explains each adopted safeguard's purpose.\nThese consequences are limited to the stated experiment, not a total value score.\nThe disabled branch supplies a real contrast for this application policy. -/\ndef safeguardExperiment (principle : CoreCommitment) (enabled : Bool)\n (selected : Candidate) : Bool :=\n match principle with\n | .generation =>\n let allowed : List Change := if enabled then [.designRevision, .migration] else []\n allowed.contains .designRevision && decide (credible currentContinuing.evidence .designRevision)\n | .consistency =>\n let firstDemand := orderedUnique [2, 1, 2]\n let secondDemand := sortedUnique [2, 1, 2]\n let permitsBoth := if enabled then firstDemand == secondDemand else true\n !permitsBoth\n | .reflexivity =>\n let selfTests := if enabled then [(21, 10), (21, 5)] else [(21, 10)]\n selfTests.any (fun point => staticBatch point.1 point.2 != liveBatch point.1 point.2)\n | .grounds =>\n let licensed := if enabled then [10] else [10, 5]\n licensed.all (fun size => staticBatch 21 size == liveBatch 21 size)\n | .choice =>\n let selectedByRule := if enabled then selected else .maximal\n decide (abstractionComplexity selectedByRule ≤ currentContinuing.limits.capacity .understanding)\n\ndef criticismFor : CoreCommitment → String\n | .generation => \"Reconsider this reason if the committed change or continuing maintenance ends.\"\n | .consistency => \"Reconsider the comparison if the parties deliberately revise the observable order contract.\"\n | .reflexivity => \"This counterexample concerns the stated batch rule; it does not validate all self-assessment.\"\n | .grounds => \"A new input condition requires its own support; success at size ten does not cover size five.\"\n | .choice => \"If objectives or budgets change, compare the actual alternatives and reasons again.\"\n\ndef governancePosition (principle : CoreCommitment) : ValuePosition Candidate where\n Position := Bool\n Outcome := Bool\n adopted := true\n selected _ := coreAdopted principle\n outcome selected enabled := safeguardExperiment principle enabled selected\n objective result := result = true\n constraints selected _ := valueScope selected\n starting := singleton valueScope\n reasons := [fun selected _ => ReasonRelevant principle (reasonFor principle) selected]\n limits := valueScope\n relevantCriticism _ := True\n response _ := some (criticismFor principle)\n\ntheorem adoptionReasonRelevant (principle : CoreCommitment) (selected : Candidate)\n (scope : valueScope selected) : ReasonRelevant principle (reasonFor principle) selected := by\n cases principle\n · dsimp only [ReasonRelevant, reasonFor]; decide\n · dsimp only [ReasonRelevant, reasonFor]; decide\n · dsimp only [ReasonRelevant, reasonFor]; decide\n · dsimp only [ReasonRelevant, reasonFor]; decide\n · refine ⟨rfl, by decide, ?_⟩\n exact Nat.le_trans scope (by decide)\n\ntheorem safeguardEnabled (principle : CoreCommitment) (selected : Candidate)\n (scope : valueScope selected) : safeguardExperiment principle true selected = true := by\n cases principle\n · dsimp only [safeguardExperiment]; decide\n · dsimp only [safeguardExperiment]; decide\n · dsimp only [safeguardExperiment]; decide\n · dsimp only [safeguardExperiment]; decide\n · apply decide_eq_true\n exact Nat.le_trans scope (by change 3 ≤ 12; decide)\n\ntheorem safeguardDisabled (principle : CoreCommitment) (selected : Candidate) :\n safeguardExperiment principle false selected = false := by\n cases principle <;> simp only [safeguardExperiment, Bool.false_eq_true, ↓reduceIte] <;> decide\n\ntheorem governanceValueProcedure (principle : CoreCommitment) :\n ValueProcedure (governancePosition principle) := by\n refine ⟨by simp [governancePosition], ?_, ?_, ?_⟩\n · refine ⟨.evolvable, (modelsSingleton _ _).2 (by change 3 ≤ 3; decide),\n (by change 3 ≤ 3; decide), rfl, ?_⟩\n intro reason member\n cases List.mem_singleton.mp member\n exact adoptionReasonRelevant principle .evolvable (by change 3 ≤ 3; decide)\n · intro selected _ scope _\n exact ⟨safeguardEnabled principle selected scope, scope⟩\n · intro selected _ _\n exact ⟨criticismFor principle, rfl, by cases principle <;> decide⟩\n\ntheorem governanceGrounded (principle : CoreCommitment) :\n valueSpecification (governancePosition principle) :=\n grounds012Singleton _ (governanceValueProcedure principle)\n\n/- Factual relevance, rationale experiments and value adoption are separate.\nSwapping a reason or altering the input makes the finite rationale fail. -/\ntheorem governanceRationaleLimits :\n ¬ ReasonRelevant .consistency (reasonFor .generation) .evolvable ∧\n ¬ ReasonRelevant .reflexivity (.ownMethodCounterexample 21 10) .evolvable ∧\n ¬ ReasonRelevant .generation (.plannedChange 9 .addition) .evolvable ∧\n ¬ valueScope .maximal ∧\n (∀ principle, safeguardExperiment principle false .evolvable = false) ∧\n (∀ principle, (governancePosition principle).commitment .presentSimple) := by\n refine ⟨by change ¬ False; decide, by decide, by decide, by change ¬ (30 ≤ 3); decide,\n fun principle => safeguardDisabled principle .evolvable, fun _ => rfl⟩\n\n/- This additional value priority is a real selection between the same designs.\nBoth scopes retain all necessary domain conditions and no cost exception.\nThe present-simple stance values less abstraction now without claiming that it\nhas the better successor-maintainer capability. The other stance values that capability. -/\ndef selectionObjective (adopted : Candidate) (outcome : Nat × Nat) : Prop :=\n match adopted with\n | .presentSimple => outcome.1 ≤ 1\n | .evolvable => outcome.2 ≤ 6\n | .maximal => outcome.1 ≤ 1\n\ndef selectionPosition (adopted : Candidate) : ValuePosition Candidate where\n Position := Candidate\n Outcome := Nat × Nat\n adopted := adopted\n selected := id\n outcome _ candidate := (abstractionComplexity candidate, changeWork candidate .designRevision)\n objective := selectionObjective adopted\n constraints _ candidate := abstractionComplexity candidate ≤ currentContinuing.limits.capacity .understanding\n starting := singleton (fun candidate => candidate = adopted)\n reasons := [fun _ candidate =>\n abstractionComplexity candidate = (if adopted = .presentSimple then 1 else 3) ∧\n changeWork candidate .designRevision = (if adopted = .presentSimple then 17 else 6)]\n limits _ := Continuing currentContinuing.activity ∧\n credible currentContinuing.evidence .designRevision\n relevantCriticism _ := True\n response _ := some (if adopted = .presentSimple then\n \"The successor lacks the private-layout path; this choice does not claim evolution priority and must be reconsidered if that value is adopted.\"\n else \"The six-step design-revision path does not establish every change is cheap or every forecast is correct.\")\n\ntheorem selectionValueProcedure (adopted : Candidate)\n (ordinary : adopted = .presentSimple ∨ adopted = .evolvable) :\n ValueProcedure (selectionPosition adopted) := by\n rcases ordinary with rfl | rfl\n · refine ⟨by simp [selectionPosition], ?_, ?_, ?_⟩\n · refine ⟨.presentSimple, (modelsSingleton _ _).2 rfl, ?_, rfl, ?_⟩\n · change Continuing currentContinuing.activity ∧ credible currentContinuing.evidence .designRevision\n decide\n · intro reason member\n cases List.mem_singleton.mp member\n decide\n · intro selected _ _ allReasons\n have actual := allReasons _ (List.mem_singleton.mpr rfl)\n change abstractionComplexity .presentSimple = 1 ∧ changeWork .presentSimple .designRevision = 17 at actual\n change abstractionComplexity .presentSimple ≤ 1 ∧\n abstractionComplexity .presentSimple ≤ currentContinuing.limits.capacity .understanding\n exact ⟨by rw [actual.1]; exact Nat.le_refl _, by rw [actual.1]; decide⟩\n · intro selected _ _\n refine ⟨_, rfl, ?_⟩\n simp\n · refine ⟨by simp [selectionPosition], ?_, ?_, ?_⟩\n · refine ⟨.evolvable, (modelsSingleton _ _).2 rfl, ?_, rfl, ?_⟩\n · change Continuing currentContinuing.activity ∧ credible currentContinuing.evidence .designRevision\n decide\n · intro reason member\n cases List.mem_singleton.mp member\n decide\n · intro selected _ _ allReasons\n have actual := allReasons _ (List.mem_singleton.mpr rfl)\n change abstractionComplexity .evolvable = 3 ∧ changeWork .evolvable .designRevision = 6 at actual\n change changeWork .evolvable .designRevision ≤ 6 ∧\n abstractionComplexity .evolvable ≤ currentContinuing.limits.capacity .understanding\n exact ⟨by rw [actual.2]; exact Nat.le_refl _, by rw [actual.1]; decide⟩\n · intro selected _ _\n refine ⟨_, rfl, ?_⟩\n simp\n\ntheorem selectionGrounded (adopted : Candidate)\n (ordinary : adopted = .presentSimple ∨ adopted = .evolvable) :\n valueSpecification (selectionPosition adopted) :=\n grounds012Singleton _ (selectionValueProcedure adopted ordinary)\n\nend CoreReader.Engineering\n```\n\n\n\n **L1** 导入 CoreReader.Adopted,使其声明及传递依赖可用;此行不新增命题。\n\n\n **L2** 导入 CoreReader.Engineering.Domain,使其声明及传递依赖可用;此行不新增命题。\n\n\n **L4** 开启 CoreReader.Engineering 命名空间,后续声明归入其中。\n\n\n **L6** 允许不带完整限定名引用 CoreReader.Logic CoreReader.Evidence CoreReader.Adopted 中的声明;不改变其含义。\n\n\n **L8** 定义生成、一致性、反身性、依据与选择五个 Core 承诺标识。\n\n\n **L9** 自动派生 DecidableEq, Repr:提供这些构造子的可判定相等与可打印表示。\n\n\n **L11** coreCommitments 是全部已表示承诺标识的有限列表。\n\n\n **L12** 按显示顺序各列出五个构造子一次。\n\n\n **L14** 注释指出采纳是明确起始选择;理由不推导采纳本身。\n\n\n **L15** 注释既不从事实推导采纳,也不声称所有替代价值均不可成立。\n\n\n **L16** 每个承诺都被明确标记为已采纳;此布尔选择不是从事实前提推导的。\n\n\n **L18** AdoptionReason 是具体理由数据的类型族,本身不是证明。\n\n\n **L19** plannedChange 记录自然数版本与 Change 方向。\n\n\n **L20** incompatibleOrders 保存用于比较输出顺序的实际输入列表。\n\n\n **L21** ownMethodCounterexample 保存项目数与运行规模。\n\n\n **L22** unsupportedScope 对固定项目数区分观测规模与扩展规模。\n\n\n **L23** statusBudgetContrast 记录按地位选出的候选项与自然数容量。\n\n\n **L24** 自动派生 DecidableEq, Repr:提供这些构造子的可判定相等与可打印表示。\n\n\n **L26** 为每个 Core 承诺分配一个具体理由值。\n\n\n **L27** 生成为计划版本 2 与 designRevision。\n\n\n **L28** 一致性使用顺序敏感输入 [2, 1, 2]。\n\n\n **L29** 反身性使用 21 项与运行规模 5。\n\n\n **L30** 依据比较 21 项在规模 10 的观测与规模 5 的扩展。\n\n\n **L31** 选择将 maximal 与理解容量 12 比较。\n\n\n **L33** 注释介绍针对各原则目的的事实理由。\n\n\n **L34** 注释将理由语境固定为此持续活动及实际需求、证据。\n\n\n **L35** 注释要求实际理由内容成立,不能仅匹配构造子名称。\n\n\n **L36** ReasonRelevant 是原则、结构化理由及所选设计上的命题,检查实际理由内容。\n\n\n **L37** 对生成及计划改变理由,此分支不依赖所选设计。\n\n\n **L38** 包含该方向与迁移的精确版本计划必须出现在当前证据中。\n\n\n **L39** 该方向必须可信,且当前活动必须持续。\n\n\n **L40** 对一致性,使用不兼容顺序理由中携带的输入。\n\n\n **L41** 实际当前需求必须要求保持顺序。\n\n\n **L42** 保序去重与排序去重必须在此输入上不同。\n\n\n **L43** 对反身性,使用理由中的项目数与受质疑规模。\n\n\n **L44** 要求旧规模 10 一致,而受质疑规模不一致。\n\n\n **L45** 对依据,比较理由中的观测规模与扩展规模。\n\n\n **L46** 静态与实时预测必须在观测规模一致。\n\n\n **L47** 它们必须在提议的扩展规模不一致。\n\n\n **L48** 对选择,区分受比较的候选项与实际所选设计。\n\n\n **L49** 所述容量必须等于当前理解容量。\n\n\n **L50** 受比较候选项超出容量,而实际选择不超出容量。\n\n\n **L51** 任何不匹配的原则、理由构造子组合均返回 False。\n\n\n **L53** 价值程序披露的范围为抽象复杂度不超过 3 的设计。\n\n\n **L55** 注释介绍解释每项保障目的的小型操作实验。\n\n\n **L56** 注释将后果限于该实验,排除综合价值评分。\n\n\n **L57** 注释指出禁用分支是此应用政策内的实际对照。\n\n\n **L58** safeguardExperiment 改变指定保障的启用布尔值。\n\n\n **L59** 它还接收实际所选设计,并返回操作性布尔结果。\n\n\n **L60** 按原则选择实验;这不是综合价值度量。\n\n\n **L61** 生成分支衡量可信计划改变是否可用。\n\n\n **L62** 启用时允许 designRevision 与 migration,禁用时允许列表为空。\n\n\n **L63** 仅当 designRevision 被允许且当前可信时通过。\n\n\n **L64** 一致性分支衡量是否拒绝不兼容的同时要求。\n\n\n **L65** 以保序去重计算第一个要求。\n\n\n **L66** 以排序去重在同一输入上计算第二个要求。\n\n\n **L67** 启用检查仅在两个要求相等时同时允许;禁用则无条件同时允许。\n\n\n **L68** 拒绝同时允许时,此实验成功。\n\n\n **L69** 反身性分支对实际批次数预测进行自身测试。\n\n\n **L70** 启用时包含旧规模及受质疑规模;禁用时仅保留旧规模。\n\n\n **L71** 某个已列案例的静态与实时预测不等时通过。\n\n\n **L72** 依据分支测试获许可的输入范围。\n\n\n **L73** 启用时仅许可规模 10;禁用时把许可扩展为 10 与 5。\n\n\n **L74** 固定项目数 21,要求每个获许可规模的预测相等。\n\n\n **L75** 选择分支衡量是否符合理解容量。\n\n\n **L76** 启用时选传入设计;禁用保障时选 maximal。\n\n\n **L77** 判定规则实际选出的设计是否符合当前理解容量。\n\n\n **L79** 为每个原则分配可修订性、批评回应字符串。\n\n\n **L80** 生成回应把已承诺改变或持续维护的终止列为重新考虑条件。\n\n\n **L81** 一致性回应允许在有意修订顺序合约后重新考虑比较。\n\n\n **L82** 反身性回应把反例限于此批处理规则,不推广到全部自评估。\n\n\n **L83** 依据回应拒绝在没有各自支持时把规模 10 的成功扩展到规模 5。\n\n\n **L84** 选择回应要求在目标或预算变化时重新比较。\n\n\n **L86** 对一个原则,构造 Candidate 上的 ValuePosition,明确采纳及有界支持理由。\n\n\n **L87** 价值立场的备选项为启用、禁用布尔状态。\n\n\n **L88** 实验结果类型为 Bool。\n\n\n **L89** 明确采纳启用的价值立场。\n\n\n **L90** 对每个设计,所选立场为该原则的采纳标记。\n\n\n **L91** 结果以设计与启用立场运行同一原则的实验。\n\n\n **L92** 目标是实验成功,以 true 表示。\n\n\n **L93** 无论布尔立场如何,约束均要求设计满足 valueScope。\n\n\n **L94** 起始理论仅含 valueScope 命题。\n\n\n **L95** 唯一理由要求对同一原则、所选设计具有实际相关性。\n\n\n **L96** 应用限制同样为 valueScope。\n\n\n **L97** 所有 Candidate 值均视为相关批评;未编码更窄过滤。\n\n\n **L98** 每项批评均得到该原则的固定回应字符串。\n\n\n **L100** 为范围内的每个原则与所选设计证明理由相关性。\n\n\n **L101** 前提把所选复杂度限制到 3;结论采用其精确 reasonFor 值。\n\n\n **L102** 拆分五种原则构造子。\n\n\n **L103** 对生成,展开理由内容并计算计划成员资格、可信性与持续性。\n\n\n **L104** 对一致性,展开并计算顺序要求及不同输出。\n\n\n **L105** 对反身性,展开并计算旧规模成功与受质疑预测失败。\n\n\n **L106** 对依据,展开并计算观测相等与扩展不等。\n\n\n **L107** 对选择,证明容量身份与 maximal 超限,留下所选设计的界限。\n\n\n **L108** 把所选复杂度 ≤ 3 与 3 ≤ 12 传递组合,得到所需界限。\n\n\n **L110** 证明披露范围内每个原则的已启用实验均成功。\n\n\n **L111** 保留范围前提,并陈述实际布尔值等于 true。\n\n\n **L112** 按五个原则分情况计算各自不同的实验。\n\n\n **L113** 对生成,展开启用的改变列表并判定可信性测试。\n\n\n **L114** 对一致性,展开启用的比较并判定对不兼容要求的拒绝。\n\n\n **L115** 对反身性,展开两个测试并判定存在失败预测。\n\n\n **L116** 对依据,展开获许可规模 10 列表并判定测试成功。\n\n\n **L117** 把选择实验的布尔结果转为底层容量命题。\n\n\n **L118** 利用范围及计算得到的 3 ≤ 12 证明该容量命题。\n\n\n **L120** 禁用保障对每个原则、所选设计均失败,无需范围前提。\n\n\n **L121** 以计算出的实验值恰等于 false 陈述失败。\n\n\n **L122** 拆分原则,化简禁用分支并判定五个有限结果。\n\n\n **L124** 逐原则验证实际治理价值程序。\n\n\n **L125** 目标是同一 governancePosition 的 ValueProcedure。\n\n\n **L126** 构造非空理由,留下相容性、目标与约束、回应义务。\n\n\n **L127** 选择 evolvable 为起始理论见证,并证明其满足单元素范围理论。\n\n\n **L128** 证明其应用限制及选择身份,留下理由有效性。\n\n\n **L129** 引入属于该立场理由列表的任意理由。\n\n\n **L130** 单元素成员资格将其确定为实际相关性理由。\n\n\n **L131** 在 evolvable 的复杂度界 3 ≤ 3 上应用已证相关性定理。\n\n\n **L132** 对程序前提下的任意设计,保留其范围证明。\n\n\n **L133** 以已启用实验成功及同一范围证明满足目标和约束。\n\n\n **L134** 在回应前提下引入任意批评案例。\n\n\n **L135** 提供固定批评回应、其存储身份及由有限分情况证明的非空性。\n\n\n **L137** governanceGrounded 为每个已表示原则的价值承诺提供依据。\n\n\n **L138** 结论为精确治理立场的 valueSpecification。\n\n\n **L139** 把已验证 ValueProcedure 包装进采纳版 Core 0.1.2 的单元素依据构造。\n\n\n **L141** 注释区分事实相关性、理由实验与价值采纳。\n\n\n **L142** 注释引入通过替换理由或改变输入得到的失败案例。\n\n\n **L143** governanceRationaleLimits 展示实际失败,并区分支持与采纳。\n\n\n **L144** 生成理由因构造子不匹配而不相关于一致性。\n\n\n **L145** 规模 10 的所谓自身反例失败,因为旧预测在那里一致。\n\n\n **L146** 未支持的版本 9 新增计划不满足生成理由要求。\n\n\n **L147** maximal 位于复杂度不超过 3 的价值范围以外。\n\n\n **L148** 每个禁用保障实验在 evolvable 上均失败。\n\n\n **L149** 与此同时,每个治理承诺在 presentSimple 上也被采纳。\n\n\n **L150** 计算三个理由不相关案例及 maximal 的 30 > 3 范围失败。\n\n\n **L151** 逐原则使用 safeguardDisabled,最后的全称采纳项由身份反身性成立。\n\n\n **L153** 注释把附加价值优先性表述为在相同设计之间的实际选择。\n\n\n **L154** 注释指出共同语境的必要条件及无成本例外;下文 limits 字段显式检查持续性与可信性。\n\n\n **L155** 注释说明简单立场重视较低的当前抽象,并开始限定其能力主张。\n\n\n **L156** 注释不为简单立场声称更强继任者能力,而把该目标归于另一立场。\n\n\n **L157** selectionObjective 把所采纳设计及复杂度、工作量二元组映射到其选定目标命题。\n\n\n **L158** 目标随明确采纳的候选项改变。\n\n\n **L159** presentSimple 重视当前抽象复杂度不超过 1。\n\n\n **L160** evolvable 重视设计修订工作量不超过 6。\n\n\n **L161** maximal 分支也使用复杂度不超过 1;下文不证明 maximal 的程序成功。\n\n\n **L163** 以所采纳候选项为参数构造独立的选择 ValuePosition。\n\n\n **L164** 其备选立场为实际 Candidate 设计。\n\n\n **L165** 结果是复杂度与修订工作量组成的自然数对。\n\n\n **L166** 直接保存传入的已采纳候选项。\n\n\n **L167** 每个世界的所选立场就是自身,由恒等函数给出。\n\n\n **L168** 衡量所选立场的复杂度与实际 designRevision 工作量。\n\n\n **L169** 采用由已采纳设计索引的目标。\n\n\n **L170** 以实际理解容量约束该立场的复杂度。\n\n\n **L171** 起始理论要求世界等于已采纳设计。\n\n\n **L172** 仅有一个理由函数,忽略世界参数并检查立场。\n\n\n **L173** 采纳 presentSimple 时要求复杂度 1,否则要求复杂度 3。\n\n\n **L174** 采纳 presentSimple 时要求修订工作量 17,否则为 6。\n\n\n **L175** 程序限制要求当前活动持续。\n\n\n **L176** 还要求实际证据中 designRevision 可信。\n\n\n **L177** 每个候选项都视为相关批评。\n\n\n **L178** 每项批评均得到按是否采纳 presentSimple 选取的回应。\n\n\n **L179** 简单设计回应承认继任者缺少私有布局路径,并说明不主张演化优先性。\n\n\n **L180** 可演化回应限制六步结果的范围,不据此断言所有改变低成本或预测正确。\n\n\n **L182** 验证某个已采纳候选项的选择价值程序。\n\n\n **L183** 假设采纳的是两种普通设计之一。\n\n\n **L184** 结论为该采纳的实际 ValueProcedure。\n\n\n **L185** 拆分并代入 presentSimple 与 evolvable 两种采纳。\n\n\n **L186** 对 presentSimple,证明理由非空并留下三个实质程序义务。\n\n\n **L187** 选择 presentSimple 本身作为相容见证,以反身性完成选择身份。\n\n\n **L188** 把见证限制显化为实际持续性及可信 designRevision。\n\n\n **L189** 计算这些固定语境事实。\n\n\n **L190** 引入简单立场单元素列表中的理由。\n\n\n **L191** 把该理由替换为唯一成员。\n\n\n **L192** 计算简单设计复杂度 1 及修订工作量 17。\n\n\n **L193** 引入任意程序前提,为简单采纳保留 allReasons。\n\n\n **L194** 从 allReasons 提取实际唯一理由。\n\n\n **L195** 把理由显化为已采纳 presentSimple 的复杂度 1、工作量 17 两个具体等式。\n\n\n **L196** 把简单设计目标显化为复杂度不超过 1。\n\n\n **L197** 第二个合取项为同一设计的理解容量约束。\n\n\n **L198** 按实际复杂度等式重写,目标由 ≤ 反身性、容量由计算完成。\n\n\n **L199** 对任意相关批评进入简单设计回应义务。\n\n\n **L200** 选择已存回应及其反身等式,留下非空性。\n\n\n **L201** 化简固定回应以证明非空。\n\n\n **L202** 对 evolvable,证明理由非空并留下同样三个程序义务。\n\n\n **L203** 选择 evolvable 本身作为相容见证,并以反身性证明选择身份。\n\n\n **L204** 显化可演化见证的持续性及可信修订限制。\n\n\n **L205** 在 currentContinuing 中计算这些限制。\n\n\n **L206** 引入可演化立场单元素理由列表中的理由。\n\n\n **L207** 将其确定为唯一实际理由。\n\n\n **L208** 计算可演化设计复杂度 3 及修订工作量 6。\n\n\n **L209** 引入可演化立场的程序前提,保留 allReasons。\n\n\n **L210** 从此前提提取唯一实质理由。\n\n\n **L211** 显化已采纳可演化立场的复杂度 3 与 designRevision 工作量 6。\n\n\n **L212** 把可演化目标显化为工作量不超过 6。\n\n\n **L213** 保留对同一设计的实际理解容量约束。\n\n\n **L214** 以工作量等式完成目标,以复杂度等式完成容量检查。\n\n\n **L215** 对任意相关批评进入可演化回应义务。\n\n\n **L216** 选择已存可演化回应,留下其非空性。\n\n\n **L217** 化简回应字符串以证明非空。\n\n\n **L219** selectionGrounded 为所采纳选择包装价值依据。\n\n\n **L220** 两种普通设计的假设仍然显式保留。\n\n\n **L221** 结论恰针对 selectionPosition adopted。\n\n\n **L222** 以已证明的选择程序作为已履行的单元素价值面向。\n\n\n **L224** 关闭 CoreReader.Engineering 命名空间;不另行断言数学主张。\n\n\n### `leanified/CoreReader/Evidence.lean`\n\n\n```lean\nimport CoreReader.Logic\nimport CoreReader.Agency\n\nnamespace CoreReader.Evidence\nopen CoreReader.Logic\nopen CoreReader.Agency\n\n/- An observation records the outcome of a specified test on the represented world. -/\nstructure Record (W : Type) where\n test : W → Bool\n observed : Bool\n/- Compatible worlds reproduce the actual contents of every recorded observation. -/\ndef Compatible {W : Type} (records : List (Record W)) (w : W) : Prop :=\n ∀ r, r ∈ records → r.test w = r.observed\n/- Inferential support requires the same claim in every evidence-compatible world. -/\ndef Supports {W : Type} (records : List (Record W)) (claim : Claim W) : Prop :=\n ∀ w, Compatible records w → claim w\n/- Articulation identifies concepts, premises, reason contents and an application limit. -/\nstructure Articulation (W : Type) where\n concepts : List String\n assumptions : Theory W\n reasons : List (Claim W)\n limits : Claim W\n/- Nonempty identifiable concepts and reasons are procedural articulation requirements. -/\ndef Articulated {W : Type} (a : Articulation W) : Prop :=\n a.concepts ≠ [] ∧ a.reasons ≠ []\n/- This application model interprets an adopted option through its actual outcomes and stated goals/constraints. -/\nstructure ValuePosition (W : Type) where\n Position : Type\n Outcome : Type\n adopted : Position\n selected : W → Position\n outcome : W → Position → Outcome\n objective : Outcome → Prop\n constraints : W → Position → Prop\n starting : Theory W\n reasons : List (W → Position → Prop)\n limits : Claim W\n relevantCriticism : Claim W\n response : W → Option String\n/- The adopted position's claim is derived from the same selected option used by the outcome interpretation. -/\ndef ValuePosition.commitment {W : Type} (v : ValuePosition W) : Claim W :=\n fun w => v.selected w = v.adopted\n/- Assessed consequences concern this adopted option's actual outcome, objective and constraints. -/\ndef ValuePosition.consequence {W : Type} (v : ValuePosition W) : Claim W :=\n fun w => v.objective (v.outcome w v.adopted) ∧ v.constraints w v.adopted\n/- Articulated reasons specialize the actual option-indexed premises to the adopted option. -/\ndef ValuePosition.activeReasons {W : Type} (v : ValuePosition W) : List (Claim W) :=\n v.reasons.map (fun reason w => reason w v.adopted)\n/- A joint witness excludes inconsistent starts and impossible adoption states. -/\ndef JointAdoption {W : Type} (v : ValuePosition W) : Prop :=\n ∃ w, Models v.starting w ∧ v.limits w ∧ v.commitment w ∧\n ∀ reason, reason ∈ v.reasons → reason w v.adopted\n/- This declared option/outcome adapter checks joint reasons for an assessed consequence; it is not a necessary deductive form for all value justification. -/\ndef ValueProcedure {W : Type} (v : ValuePosition W) : Prop :=\n v.reasons ≠ [] ∧ JointAdoption v ∧\n (∀ w, Models v.starting w → v.limits w →\n (∀ reason, reason ∈ v.reasons → reason w v.adopted) → v.consequence w) ∧\n (∀ w, v.limits w → v.relevantCriticism w → ∃ answer, v.response w = some answer ∧ answer ≠ \"\")\n/- A facet carries its specific contents; several different facets can have the same conclusion. -/\ninductive Facet (W : Type) where\n | empirical (records : List (Record W)) (scope conclusion uncertainty : Claim W)\n | inferential (assumptions : Theory W) (conclusion : Claim W)\n | value (position : ValuePosition W)\n/- The claim referred to by each assessment facet is explicit. -/\ndef Facet.claim {W : Type} : Facet W → Claim W\n | .empirical _ _ p _ => p\n | .inferential _ p => p\n | .value v => v.commitment\n/- These disclosed semantic adapters implement selected nature-specific checks; passing them does not establish all real empirical or value adequacy. -/\ndef FacetDischarged {W : Type} : Facet W → Prop\n | .empirical records scope p uncertainty =>\n (∃ w, Compatible records w ∧ scope w) ∧\n Supports records (fun w => scope w → p w) ∧ Supports records uncertainty\n | .inferential assumptions p => Satisfiable assumptions ∧ Entails assumptions p\n | .value v => ValueProcedure v\n/- This model's semantic adapter identifies the actual assumptions, reason content and limit of a facet. -/\ndef FacetArticulated {W : Type} (a : Articulation W) : Facet W → Prop\n | .empirical records scope _ _ =>\n a.assumptions = singleton (Compatible records) ∧ a.reasons = [Compatible records] ∧ a.limits = scope\n | .inferential assumptions _ =>\n a.assumptions = assumptions ∧ a.reasons = [Models assumptions] ∧ a.limits = (fun _ => True)\n | .value v => a.assumptions = v.starting ∧ a.reasons = v.activeReasons ∧ a.limits = v.limits\n/- A canonical articulation exposes this adapter; the source does not mandate this particular representation of grounds. -/\ndef canonicalArticulation {W : Type} : Facet W → Articulation W\n | .empirical records scope _ _ =>\n ⟨[\"recorded test outcomes\", \"observation conditions\"], singleton (Compatible records), [Compatible records], scope⟩\n | .inferential assumptions _ =>\n ⟨[\"stated assumptions\", \"semantic consequence\"], assumptions, [Models assumptions], fun _ => True⟩\n | .value v =>\n ⟨[\"adopted position\", \"reasons and consequences\"], v.starting, v.activeReasons, v.limits⟩\n/- Canonical articulation is connected to the very facet whose grounds it identifies. -/\ntheorem canonicalFacetArticulated {W : Type} (f : Facet W) :\n FacetArticulated (canonicalArticulation f) f := by\n cases f <;> exact ⟨rfl, rfl, rfl⟩\n/- A discharged facet has nonempty canonical reason articulation, including the value procedure's reason requirement. -/\ntheorem canonicalArticulated {W : Type} (f : Facet W) (h : FacetDischarged f) :\n Articulated (canonicalArticulation f) := by\n cases f with\n | empirical records scope p uncertainty => simp [Articulated, canonicalArticulation]\n | inferential assumptions p => simp [Articulated, canonicalArticulation]\n | value v =>\n refine ⟨by simp [canonicalArticulation], ?_⟩\n simpa [canonicalArticulation, ValuePosition.activeReasons] using h.1\n/- This model of the Grounds obligation binds each actual facet to its claim and articulation. Its disclosed FacetDischarged adapters do not replace all source-level assessment responsibilities or prove real adequacy. -/\ndef Grounds {W : Type} (claim : Claim W) (articulations : Facet W → Articulation W)\n (actualApplicable : Facet W → Prop) (facets : List (Facet W)) : Prop :=\n facets ≠ [] ∧ (∀ facet, actualApplicable facet → facet ∈ facets) ∧\n ∀ facet, facet ∈ facets → facet.claim = claim ∧ Articulated (articulations facet) ∧\n FacetArticulated (articulations facet) facet ∧ FacetDischarged facet\n/- The achievement obligation requires grounds for this very claim, without making observation a universal prerequisite. -/\ndef AchievementAccountability {W : Type} (achievement : Claim W) (articulations : Facet W → Articulation W)\n (actualApplicable : Facet W → Prop) (facets : List (Facet W)) : Prop :=\n Grounds achievement articulations actualApplicable facets\n/- The concrete achievement claim refers to each transition's own before/after states. -/\ndef transitionAchievement : Claim TransitionCase :=\n fun transition => Expanded (transitionBefore transition) (transitionAfter transition)\n/- This observation inspects an actually constructed successor and its output under that transition's input condition. -/\ndef transitionPerformanceRecord : Record TransitionCase :=\n ⟨fun transition => (transitionAfter transition).constructed.any\n (fun operation => operation == .successor && decide (operation.run (transitionInput transition) = 1)), true⟩\n/- The positive report test reads its asserted operation, input and output; it does not verify their presence in the after-state. -/\ndef transitionReportRecord : Record TransitionCase :=\n ⟨fun transition =>\n let report := transitionAnnouncement transition\n report.reportedNewOperation == .successor && report.input == 0 && report.expectedOutput == 1, true⟩\n/- Only the genuine extension matches the operation/performance observation in this two-transition model. -/\ntheorem transitionPerformanceCompatible :\n ∀ transition, Compatible [transitionPerformanceRecord] transition ↔ transition = .extend := by\n intro transition\n constructor\n · intro h\n have observed := h transitionPerformanceRecord (List.mem_singleton.mpr rfl)\n cases transition\n · cases observed\n · rfl\n · intro h; cases h\n intro record hr; have hr' := List.mem_singleton.mp hr; subst record\n rfl\n/- A compatible performance observation establishes the same transition's report content and hence its represented expansion. -/\ntheorem transitionSupported : Supports [transitionPerformanceRecord] transitionAchievement := by\n intro transition compatible\n have h := (transitionPerformanceCompatible transition).1 compatible\n subst transition\n have reportTrue : (transitionAnnouncement .extend).claim := by\n simp [transitionAnnouncement, transitionAfter, transitionInput,\n Announcement.claim, GeneratingSystem.report, generatingSystem, extendedState, baseState, Operation.run]\n exact announcementClaimImpliesExpansion _ reportTrue\n/- The actual scope is the shared input-zero condition, with no probabilistic inference introduced. -/\ndef transitionFacet : Facet TransitionCase :=\n .empirical [transitionPerformanceRecord] (fun transition => transitionInput transition = 0)\n transitionAchievement (fun _ => True)\n/- The empirical assessment has a real compatible witness and supports this scoped achievement. -/\ntheorem transitionFacetDischarged : FacetDischarged transitionFacet := by\n refine ⟨⟨.extend, (transitionPerformanceCompatible _).2 rfl, rfl⟩, ?_, ?_⟩\n · intro transition compatible _; exact transitionSupported transition compatible\n · intro _ _; trivial\n/- Every applicable facet of this specified achievement has matching articulation and actual discharged evidence. -/\ntheorem transitionAccountable :\n AchievementAccountability transitionAchievement canonicalArticulation\n (fun facet => facet = transitionFacet) [transitionFacet] := by\n refine ⟨by simp, ?_, ?_⟩\n · intro facet hf; subst facet; exact List.mem_singleton.mpr rfl\n · intro facet hf; have hf' := List.mem_singleton.mp hf; subst facet\n exact ⟨rfl, canonicalArticulated _ transitionFacetDischarged,\n canonicalFacetArticulated _, transitionFacetDischarged⟩\n/- Both actual transitions issue the same positive report about their own identified state pair. -/\ntheorem transitionReportCompatible (transition : TransitionCase) :\n Compatible [transitionReportRecord] transition := by\n intro record hr; have hr' := List.mem_singleton.mp hr; subst record\n rfl\n/- Inflation is a concrete report-compatible counterworld, so the positive report alone does not support the same achievement claim. -/\ntheorem transitionReportDoesNotSupport :\n Compatible [transitionReportRecord] .inflate ∧ ¬ transitionAchievement .inflate ∧\n ¬ Supports [transitionReportRecord] transitionAchievement := by\n have noExpansion : ¬ transitionAchievement .inflate := by\n simp [transitionAchievement, transitionBefore, transitionAfter, Expanded, baseState, inflatedState]\n exact ⟨transitionReportCompatible _, noExpansion, fun h => noExpansion (h _ (transitionReportCompatible _))⟩\n/- These concrete obligations, positive evidence and negative report case all refer to the same state-pair and input semantics. -/\ndef ConcreteAchievementExample : Prop :=\n AchievementAccountability transitionAchievement canonicalArticulation\n (fun facet => facet = transitionFacet) [transitionFacet] ∧\n Compatible [transitionPerformanceRecord] .extend ∧\n Supports [transitionPerformanceRecord] transitionAchievement ∧ transitionAchievement .extend ∧\n (Compatible [transitionReportRecord] .inflate ∧ ¬ transitionAchievement .inflate ∧\n ¬ Supports [transitionReportRecord] transitionAchievement) ∧\n (∀ transition, (transitionAnnouncement transition).before = transitionBefore transition ∧\n (transitionAnnouncement transition).after = transitionAfter transition ∧\n (transitionAnnouncement transition).input = transitionInput transition ∧ transitionInput transition = 0)\n/- The concrete example jointly inhabits accountability, evidence compatibility, actual gain, and the report-only countermodel. -/\ntheorem concreteAchievementExample : ConcreteAchievementExample := by\n refine ⟨transitionAccountable, (transitionPerformanceCompatible _).2 rfl, transitionSupported,\n transitionSupported .extend ((transitionPerformanceCompatible _).2 rfl),\n transitionReportDoesNotSupport, ?_⟩\n intro transition; exact ⟨rfl,rfl,rfl,rfl⟩\n/- Semantic evidence yields truth only at a world that actually satisfies those evidence conditions. -/\ntheorem achievementNeedsSupport {W : Type} (achievement : Claim W) (records : List (Record W))\n (actual : W) (reliableHere : Compatible records actual) (support : Supports records achievement) :\n achievement actual ∧ ConcreteAchievementExample :=\n ⟨support actual reliableHere, concreteAchievementExample⟩\n/- Weakening a conclusion preserves support; this makes no claim about weakening the evidence. -/\ntheorem supportWeakening {W : Type} (records : List (Record W)) (p q : Claim W)\n (support : Supports records p) (weaker : ∀ w, p w → q w) : Supports records q :=\n fun w hw => weaker w (support w hw)\n/- Discarding the only informative observation loses support for the unchanged switch claim. -/\ntheorem evidenceWeakeningCanLoseSupport :\n Supports ([⟨id, true⟩] : List (Record Bool)) (fun w => w = true) ∧\n ¬ Supports ([] : List (Record Bool)) (fun w => w = true) := by\n refine ⟨?_, ?_⟩\n · intro w hw; exact hw ⟨id,true⟩ (by simp)\n · intro h; have bad := h false (by intro r hr; cases hr); cases bad\n/- Restricting the quantified application domain preserves a supported universal conclusion. -/\ntheorem scopeRestriction {W X : Type} (records : List (Record W)) (p : W → X → Prop)\n (wide narrow : X → Prop) (included : ∀ x, narrow x → wide x)\n (support : Supports records (fun w => ∀ x, wide x → p w x)) :\n Supports records (fun w => ∀ x, narrow x → p w x) :=\n fun w hw x hx => support w hw x (included x hx)\n/- Actual applicability, rather than an optional classifier label, determines facet responsibility. -/\ndef Duties {W : Type} (applicable : Facet W → Prop) : Prop :=\n ∀ f, applicable f → FacetDischarged f\ndef LabeledDuties {W : Type} (_labels : List String) (applicable : Facet W → Prop) : Prop :=\n Duties applicable\n/- Combining applicable facets requires both sets of substantive duties. -/\ntheorem assessmentUnion {W : Type} (a b : Facet W → Prop) :\n Duties (fun f => a f ∨ b f) ↔ Duties a ∧ Duties b := by\n constructor\n · intro h; exact ⟨fun f hf => h f (Or.inl hf), fun f hf => h f (Or.inr hf)⟩\n · rintro ⟨ha,hb⟩ f (hf|hf); exact ha f hf; exact hb f hf\n/- Omitting or changing labels does not remove an applicable duty. -/\ntheorem labelsCannotWaive {W : Type} (xs ys : List String) (a : Facet W → Prop) :\n LabeledDuties xs a ↔ LabeledDuties ys a := Iff.rfl\n/- The observed switch is the outcome itself, not a record identifier. -/\ndef switchRecord : Record Bool := ⟨id, true⟩\ntheorem switchCompatible (w : Bool) : Compatible [switchRecord] w ↔ w = true := by\n constructor\n · intro h; exact h switchRecord (by simp)\n · intro hw r hr; simp only [List.mem_singleton] at hr; cases hr; exact hw\ntheorem switchSupported : Supports [switchRecord] (fun w : Bool => w = true) :=\n fun w hw => (switchCompatible w).1 hw\n/- The candidate action has specific benefit and cost outcomes; its inactive alternative has neither. -/\ndef optionBenefit (selected : Bool) : Nat := if selected then 4 else 0\ndef optionCost (selected : Bool) : Nat := if selected then 3 else 0\n/- The report describes each option's actual cost and benefit; it does not itself assert which option ought to be selected. -/\ndef optionReport (selected : Bool) : Prop :=\n optionCost selected ≤ 3 ∧ optionBenefit selected = (if selected then 4 else 0)\n/- The on position connects its own selected option to that option's benefit/cost outcome. -/\ndef switchPosition : ValuePosition Bool where\n Position := Bool\n Outcome := Nat × Nat\n adopted := true\n selected := id\n outcome := fun _ option => (optionBenefit option, optionCost option)\n objective := fun result => result.2 < result.1\n constraints := fun _ option => optionCost option ≤ 3\n starting := singleton (fun w => w = true)\n reasons := [fun _ option => optionReport option]\n limits := fun _ => True\n relevantCriticism := fun w => w = false\n response := fun w => if w then some \"benefit exceeds cost within budget\" else some \"reconsider if the budget no longer permits this cost\"\ntheorem switchValueProcedure : ValueProcedure switchPosition := by\n refine ⟨by simp [switchPosition], ?_, ?_, ?_⟩\n · refine ⟨true, (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩\n intro reason hr\n have hr' : reason = (fun (_ : Bool) (option : Bool) => optionReport option) := List.mem_singleton.mp hr\n subst reason\n exact ⟨by decide, rfl⟩\n · intro w _ _ allReasons\n have evidence := allReasons (fun (_ : Bool) (option : Bool) => optionReport option) (List.mem_singleton.mpr rfl)\n change optionReport true at evidence\n have benefitAboveBudget : 3 < optionBenefit true := by rw [evidence.2]; decide\n exact ⟨Nat.lt_of_le_of_lt evidence.1 benefitAboveBudget, evidence.1⟩\n · intro w _ _; cases w <;> simp [switchPosition]\n/- Adopting the other option updates the adopted starting state too, so rejection cannot be blamed on an inconsistent start. -/\ndef oppositePosition : ValuePosition Bool :=\n { switchPosition with adopted := false, starting := singleton (fun w => w = false) }\n/- The alternative has a joint adoption witness but its actual zero benefit/cost fails the adopted strict-benefit objective. -/\ntheorem oppositePositionRejected : JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition := by\n have witness : JointAdoption oppositePosition := by\n refine ⟨false, (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩\n intro reason hr\n have hr' : reason = (fun (_ : Bool) (option : Bool) => optionReport option) := List.mem_singleton.mp hr\n subst reason\n exact ⟨by decide, rfl⟩\n refine ⟨witness, ?_⟩\n intro h\n have allReasons : ∀ reason, reason ∈ oppositePosition.reasons → reason false oppositePosition.adopted := by\n intro reason hr\n have hr' : reason = (fun (_ : Bool) (option : Bool) => optionReport option) := List.mem_singleton.mp hr\n subst reason\n exact ⟨by decide, rfl⟩\n have bad := h.2.2.1 false ((modelsSingleton _ _).2 rfl) trivial allReasons\n exact Nat.lt_irrefl 0 bad.1\n/- Contradictory starting assumptions and an impossible selected/adopted equality are separate inadmissible variants. -/\ndef contradictoryStartingPosition : ValuePosition Bool :=\n { switchPosition with starting := singleton (fun _ => False) }\ndef impossibleAdoptionPosition : ValuePosition Bool :=\n { switchPosition with selected := fun _ => false }\n/- The common-world witness rejects both contradiction and an impossible commitment instead of proving them vacuously. -/\ntheorem inadmissibleValuePositionsRejected :\n ¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition := by\n constructor\n · intro h; obtain ⟨w,hw,_,_,_⟩ := h.2.1\n exact (modelsSingleton _ _).1 hw\n · intro h; obtain ⟨w,_,_,hw,_⟩ := h.2.1\n cases hw\n/- Removing the reasons leaves only a position and assertion, which fails this value procedure. -/\ndef unsupportedPosition : ValuePosition Bool := { switchPosition with reasons := [] }\ndef switchEmpirical : Facet Bool :=\n .empirical [switchRecord] (fun _ => True) (fun w => w = true) (fun _ => True)\ntheorem switchEmpiricalDischarged : FacetDischarged switchEmpirical := by\n refine ⟨⟨true, (switchCompatible true).2 rfl, trivial⟩, ?_, ?_⟩\n · intro w hw _; exact switchSupported w hw\n · intro w _; trivial\n/- A mixed empirical/value position has actual empirical evidence but still lacks its value-reason duty. -/\ntheorem mixedMissingResponsibility :\n FacetDischarged switchEmpirical ∧\n ¬ LabeledDuties [] (fun f : Facet Bool => f = switchEmpirical ∨ f = .value unsupportedPosition) := by\n refine ⟨switchEmpiricalDischarged, ?_⟩\n intro h\n have bad := (h (.value unsupportedPosition) (Or.inr rfl)).1\n exact bad rfl\n/- A fully identified argument may still fail to entail the stated conclusion. -/\ndef uninformativeArgument : Articulation Bool :=\n ⟨[\"switch state\"], emptyTheory, [fun _ => True], fun _ => True⟩\ntheorem articulationNotSupport : Articulated uninformativeArgument ∧\n ¬ Entails uninformativeArgument.assumptions (fun w : Bool => w = true) := by\n exact ⟨⟨by simp [uninformativeArgument], by simp [uninformativeArgument]⟩,\n consistentIncomplete.2.1⟩\n/- Identifiable but unrelated argument fields cannot replace the actual observation grounds under the connected adapter. -/\ntheorem unrelatedArticulationRejected :\n Articulated uninformativeArgument ∧ FacetDischarged switchEmpirical ∧\n ¬ FacetArticulated uninformativeArgument switchEmpirical := by\n refine ⟨articulationNotSupport.1, switchEmpiricalDischarged, ?_⟩\n intro h\n have relation := congrFun h.1 (Compatible [switchRecord])\n have bad : False := relation.mpr rfl\n exact bad\n/- Repetition of the same unrelated temperature observation leaves the switch state undetermined. -/\ndef temperatureRecord : Record (Bool × Bool) := ⟨Prod.fst, true⟩\ntheorem temperatureCompatible (b : Bool) :\n Compatible [temperatureRecord, temperatureRecord] (true,b) := by\n intro r hr\n simp at hr\n cases hr\n rfl\n/- The world identifies a selected action and its budget; the action costs three units. -/\nabbrev BudgetWorld := Bool × Nat\n/- A real issued announcement asserts the selected action, but says nothing about affordability. -/\ndef announcement : String := \"activate\"\ndef announcementPosition : ValuePosition BudgetWorld where\n Position := Bool\n Outcome := Nat × Nat\n adopted := true\n selected := Prod.fst\n outcome := fun _ option => (optionBenefit option, optionCost option)\n objective := fun result => result.2 < result.1\n constraints := fun w option => optionCost option ≤ w.2\n starting := singleton (fun w => w.1 = true)\n reasons := [fun _ option => announcement = (if option then \"activate\" else \"disable\")]\n limits := fun _ => True\n relevantCriticism := fun w => w.2 < 3\n response := fun _ => some \"reconsider the action when its cost exceeds budget\"\n/- The zero-budget counterworld satisfies the stated starts, adoption and all announced reasons jointly. -/\ntheorem announcementHasJointAdoption : JointAdoption announcementPosition := by\n refine ⟨(true,0), (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩\n intro reason hr\n have hr' : reason = (fun (_ : BudgetWorld) (option : Bool) => announcement = (if option then \"activate\" else \"disable\")) :=\n List.mem_singleton.mp hr\n subst reason\n rfl\n/- A nonempty announcement remains true in a jointly admissible zero-budget world but cannot support the action's affordability. -/\ntheorem announcementNotBudgetReason :\n announcementPosition.reasons ≠ [] ∧ announcementPosition.commitment (true,0) ∧\n (∀ reason, reason ∈ announcementPosition.reasons → reason (true,0) announcementPosition.adopted) ∧\n ¬ announcementPosition.consequence (true,0) ∧ ¬ ValueProcedure announcementPosition := by\n refine ⟨by simp [announcementPosition], rfl, ?_, (by intro h; cases h.2), ?_⟩\n · intro reason hr\n have hr' : reason = (fun (_ : BudgetWorld) (option : Bool) => announcement = (if option then \"activate\" else \"disable\")) := List.mem_singleton.mp hr\n subst reason\n rfl\n · intro h\n have allReasons : ∀ reason, reason ∈ announcementPosition.reasons → reason (true,0) announcementPosition.adopted := by\n intro reason hr\n have hr' : reason = (fun (_ : BudgetWorld) (option : Bool) => announcement = (if option then \"activate\" else \"disable\")) := List.mem_singleton.mp hr\n subst reason\n rfl\n have bad := h.2.2.1 (true,0) ((modelsSingleton _ _).2 rfl) trivial allReasons\n cases bad.2\n/- A repeated actual selection observation contains no budget information. -/\ndef actionRecord : Record BudgetWorld := ⟨Prod.fst, true⟩\ntheorem actionCompatible (budget : Nat) : Compatible [actionRecord, actionRecord] (true,budget) := by\n intro r hr; simp at hr; cases hr; rfl\n/- Single and repeated irrelevant observations cannot establish the other outcome or the same action's budget adequacy. -/\ntheorem measurementRepeatNotSupport :\n temperatureRecord.test (true,false) = true ∧\n Compatible [temperatureRecord,temperatureRecord] (true,false) ∧\n Compatible [temperatureRecord,temperatureRecord] (true,true) ∧\n ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧\n ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧\n Compatible [actionRecord,actionRecord] (true,0) ∧\n Compatible [actionRecord,actionRecord] (true,3) ∧\n ¬ Supports [actionRecord] announcementPosition.consequence ∧\n ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧\n ¬ ValueProcedure announcementPosition := by\n refine ⟨rfl, temperatureCompatible false, temperatureCompatible true, ?_, ?_,\n actionCompatible 0, actionCompatible 3, ?_, ?_, announcementNotBudgetReason.2.2.2.2⟩\n · intro h\n have bad := h (true,false) (by intro r hr; simp only [List.mem_singleton] at hr; cases hr; rfl)\n cases bad\n · intro h; have bad := h (true,false) (temperatureCompatible false); cases bad\n · intro h\n have bad := h (true,0) (by intro r hr; simp only [List.mem_singleton] at hr; cases hr; rfl)\n cases bad.2\n · intro h; have bad := h (true,0) (actionCompatible 0); cases bad.2\n/- Missing reason records fail a procedure; independently, a present announcement fails the explicit budget-support criterion. -/\ntheorem selfAssertionNotReason :\n (unsupportedPosition.commitment true ∧ ¬ ValueProcedure unsupportedPosition) ∧\n (announcementPosition.reasons ≠ [] ∧ announcementPosition.commitment (true,0) ∧\n ¬ announcementPosition.consequence (true,0) ∧ ¬ ValueProcedure announcementPosition) ∧\n JointAdoption announcementPosition :=\n ⟨⟨rfl, fun h => h.1 rfl⟩,\n ⟨announcementNotBudgetReason.1, announcementNotBudgetReason.2.1,\n announcementNotBudgetReason.2.2.2.1, announcementNotBudgetReason.2.2.2.2⟩,\n announcementHasJointAdoption⟩\n/- The value procedure is satisfiable although the adopted starting commitment is not entailed by empty facts. -/\ntheorem valueWithoutSelfProof : ValueProcedure switchPosition ∧\n Satisfiable switchPosition.starting ∧\n ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧\n (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧\n (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition) :=\n ⟨switchValueProcedure, ⟨true, (modelsSingleton _ _).2 rfl⟩, consistentIncomplete.2.1,\n oppositePositionRejected, inadmissibleValuePositionsRejected⟩\n/- The world records the selected option and its actual benefit/cost outcomes. -/\nabbrev BenefitCostWorld := Bool × (Nat × Nat)\ndef measuredOutcome (world : BenefitCostWorld) (option : Bool) : Nat × Nat :=\n if option then world.2 else (0,0)\ndef benefitReason (world : BenefitCostWorld) (option : Bool) : Prop :=\n (measuredOutcome world option).1 = 4\ndef costReason (world : BenefitCostWorld) (option : Bool) : Prop :=\n (measuredOutcome world option).2 ≤ 3\n/- Neither recorded benefit nor recorded cost alone establishes the selected option's joint consequence. -/\ndef jointReasonPosition : ValuePosition BenefitCostWorld where\n Position := Bool\n Outcome := Nat × Nat\n adopted := true\n selected := Prod.fst\n outcome := measuredOutcome\n objective := fun result => result.2 < result.1\n constraints := fun world option => (measuredOutcome world option).2 ≤ 3\n starting := singleton (fun world => world.1 = true)\n reasons := [benefitReason, costReason]\n limits := fun _ => True\n relevantCriticism := fun world => 3 < world.2.2\n response := fun _ => some \"reassess the option when its cost exceeds the budget\"\n/- These two content constraints jointly establish the consequence in a nonempty adopted world. -/\ntheorem jointReasonProcedure : ValueProcedure jointReasonPosition := by\n refine ⟨by simp [jointReasonPosition], ?_, ?_, ?_⟩\n · refine ⟨(true,(4,3)), (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩\n intro reason hr\n change reason ∈ [benefitReason,costReason] at hr\n rcases List.mem_cons.mp hr with hr | hr\n · subst reason; rfl\n · have hr' := List.mem_singleton.mp hr\n subst reason\n change 3 ≤ 3; exact Nat.le_refl 3\n · intro world _ _ reasons\n have benefit := reasons benefitReason (by change benefitReason ∈ [benefitReason,costReason]; simp)\n have cost := reasons costReason (by change costReason ∈ [benefitReason,costReason]; simp)\n change (measuredOutcome world true).1 = 4 at benefit\n change (measuredOutcome world true).2 ≤ 3 at cost\n refine ⟨?_, cost⟩\n have bigger : 3 < (measuredOutcome world true).1 := by rw [benefit]; decide\n exact Nat.lt_of_le_of_lt cost bigger\n · intro world _ _\n exact ⟨\"reassess the option when its cost exceeds the budget\", rfl, by decide⟩\n/- Each separate reason has a concrete same-start/limit/adoption counterworld; their conjunction is sufficient. -/\ndef JointReasonsExample : Prop :=\n ValueProcedure jointReasonPosition ∧\n (Models jointReasonPosition.starting (true,(4,5)) ∧ jointReasonPosition.limits (true,(4,5)) ∧\n jointReasonPosition.commitment (true,(4,5)) ∧ benefitReason (true,(4,5)) true ∧\n ¬ jointReasonPosition.consequence (true,(4,5))) ∧\n (Models jointReasonPosition.starting (true,(0,3)) ∧ jointReasonPosition.limits (true,(0,3)) ∧\n jointReasonPosition.commitment (true,(0,3)) ∧ costReason (true,(0,3)) true ∧\n ¬ jointReasonPosition.consequence (true,(0,3)))\ntheorem jointReasonsExample : JointReasonsExample := by\n refine ⟨jointReasonProcedure,\n ⟨(modelsSingleton _ _).2 rfl, trivial, rfl, rfl, ?_⟩,\n ⟨(modelsSingleton _ _).2 rfl, trivial, rfl, Nat.le_refl 3, ?_⟩⟩\n · intro h; have bad : 5 ≤ 3 := h.2; omega\n · intro h; have bad : 3 < 0 := h.1; omega\n/- Empirical observations, semantic inference and criticism-responsive reasons coexist without a scalar score. -/\ntheorem heterogeneousReasons :\n FacetDischarged switchEmpirical ∧\n FacetDischarged (Facet.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) ∧\n FacetDischarged (Facet.value switchPosition) ∧ JointReasonsExample := by\n refine ⟨switchEmpiricalDischarged, ⟨⟨true, (modelsSingleton _ _).2 rfl⟩, ?_⟩, switchValueProcedure, jointReasonsExample⟩\n intro w hw; exact (modelsSingleton (fun x : Bool => x = true) w).1 hw\n\n/- This local observation checks the actual output on input zero. -/\ndef zeroRecord : Record (Nat → Bool) := ⟨fun f => f 0, true⟩\ndef localGenerator (seed : Nat) : Nat → Bool := fun n => n == seed\n/- All outputs being true is a stronger, explicitly quantified capability claim. -/\ndef allTrue : Claim (Nat → Bool) := fun f => ∀ n, f n = true\ntheorem zeroCompatible (f : Nat → Bool) : Compatible [zeroRecord] f ↔ f 0 = true := by\n constructor\n · intro h; exact h zeroRecord (by simp)\n · intro hf r hr; simp only [List.mem_singleton] at hr; cases hr; exact hf\n/- A generating subject owns an earlier predicate and a seed used to revise that actual predicate. -/\nstructure GeneratingProcess where\n owner : Nat\n prior : Nat → Bool\n generateSeed : Nat\n/- The revision preserves prior successes and adds the seed-selected case through the actual generator. -/\ndef GeneratingProcess.outputRevision (process : GeneratingProcess) : Nat → Bool :=\n fun input => process.prior input || localGenerator process.generateSeed input\n/- A produced revision retains its producer and exact old/new objects. -/\nstructure ProducedRevision where\n producer : Nat\n before : Nat → Bool\n after : Nat → Bool\n/- The subject itself constructs the owned before/after revision object. -/\ndef GeneratingProcess.produce (process : GeneratingProcess) : ProducedRevision :=\n ⟨process.owner, process.prior, process.outputRevision⟩\ndef sampleGeneratingProcess : GeneratingProcess := ⟨17, fun _ => false, 0⟩\n/- This same-owner revision actually changes input zero, while its produced predicate still fails at input one. -/\ndef OwnedRevisionExample : Prop :=\n sampleGeneratingProcess.produce.producer = sampleGeneratingProcess.owner ∧\n sampleGeneratingProcess.produce.before = sampleGeneratingProcess.prior ∧\n sampleGeneratingProcess.produce.after = sampleGeneratingProcess.outputRevision ∧\n sampleGeneratingProcess.produce.before 0 = false ∧ sampleGeneratingProcess.produce.after 0 = true ∧\n sampleGeneratingProcess.produce.after 1 = false ∧\n Compatible [zeroRecord] sampleGeneratingProcess.produce.after ∧\n ¬ Supports [zeroRecord] allTrue\n/- Actual producer/old/new links and the compatible failing revision witness the insufficiency of self-origin. -/\ntheorem ownedRevisionExample : OwnedRevisionExample := by\n refine ⟨rfl,rfl,rfl,rfl,rfl,rfl,(zeroCompatible _).2 rfl, ?_⟩\n intro h\n have bad := h sampleGeneratingProcess.produce.after ((zeroCompatible _).2 rfl) 1\n cases bad\n/- The generator's own sample succeeds, but its generated revision has a concrete unsupported global claim. -/\ntheorem selfOriginDoesNotSupport :\n localGenerator 0 0 = true ∧ localGenerator 0 1 = false ∧\n Compatible [zeroRecord] (localGenerator 0) ∧\n ¬ Supports [zeroRecord] allTrue ∧ OwnedRevisionExample := by\n refine ⟨rfl, rfl, (zeroCompatible _).2 rfl, ?_, ownedRevisionExample⟩\n intro h\n have bad := h (localGenerator 0) ((zeroCompatible _).2 rfl) 1\n cases bad\n/- A proper local observation allows both a universally successful and a failing extension. -/\ntheorem localNotUniversal :\n (∃ outside : Nat, outside ≠ 0) ∧\n Compatible [zeroRecord] (fun _ => true) ∧\n Compatible [zeroRecord] (localGenerator 0) ∧\n allTrue (fun _ => true) ∧ ¬ allTrue (localGenerator 0) ∧\n ¬ Supports [zeroRecord] allTrue := by\n refine ⟨⟨1, by decide⟩, (zeroCompatible _).2 rfl, (zeroCompatible _).2 rfl,\n (fun _ => rfl), ?_, selfOriginDoesNotSupport.2.2.2.1⟩\n intro h; have bad := h 1; cases bad\n/- Two implementations agree on the actual observed input and differ on a specified relevant omitted input. -/\ntheorem hiddenDifference :\n (∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧\n (fun _ : Nat => true) 1 ≠ localGenerator 0 1 := by\n refine ⟨?_, by decide⟩\n intro n hn; cases hn; rfl\n/- One observation supplies only its actual input-specific consequence, without repetition. -/\ntheorem singleObservation : [zeroRecord].length = 1 ∧\n (∃ f, Compatible [zeroRecord] f) ∧\n Supports [zeroRecord] (fun f => f 0 = true) ∧\n ¬ Supports [zeroRecord] allTrue :=\n ⟨rfl, ⟨localGenerator 0, (zeroCompatible _).2 rfl⟩,\n (fun f hf => (zeroCompatible f).1 hf), selfOriginDoesNotSupport.2.2.2.1⟩\n/- This inferential assessment derives a successor value from its explicit numeric premise without observation. -/\ndef arithmeticFacet : Facet Nat := .inferential (singleton (fun n => n = 2)) (fun n => n + 1 = 3)\ndef usesObservation {W : Type} : Facet W → Bool\n | .empirical _ _ _ _ => true\n | _ => false\n/- An actual valid inferential assessment refutes a mandatory measurement/repetition/framework chain. -/\ntheorem noUniversalChain : FacetDischarged arithmeticFacet ∧ usesObservation arithmeticFacet = false := by\n refine ⟨⟨⟨2, (modelsSingleton _ _).2 rfl⟩, ?_⟩, rfl⟩\n intro n hn\n have premise := (modelsSingleton (fun x : Nat => x = 2) n).1 hn\n change n + 1 = 3\n rw [premise]\n/- A trial has a reproducible setting, an actual outcome and a separately recorded outcome. -/\nstructure Trial where\n setting : Nat\n actualOutcome : Nat\n recordedOutcome : Nat\n/- Verifying a record, reproducing settings and retaining a conclusion are separate predicates. -/\ndef Verified (t : Trial) : Prop := t.recordedOutcome = t.actualOutcome\ndef Reproduced (a b : Trial) : Prop := a.setting = b.setting\ndef Bounded (t : Trial) : Prop := t.actualOutcome ≤ 2\n/- Same-setting possible trials can differ while preserving the chosen bound; no probability semantics is claimed. -/\ntheorem variableOutcomesStableBound :\n let a : Trial := ⟨0,1,1⟩\n let b : Trial := ⟨0,2,2⟩\n Reproduced a b ∧ a.actualOutcome ≠ b.actualOutcome ∧ Bounded a ∧ Bounded b := by\n simp [Reproduced, Bounded]\n/- Concrete records distinguish record accuracy, condition reproduction and conclusion stability. -/\ntheorem verificationReproductionStability :\n (Verified ⟨0,1,1⟩ ∧ Verified ⟨1,1,1⟩ ∧ ¬ Reproduced ⟨0,1,1⟩ ⟨1,1,1⟩) ∧\n (Reproduced ⟨0,1,1⟩ ⟨0,3,2⟩ ∧ ¬ Verified ⟨0,3,2⟩ ∧ ¬ Bounded ⟨0,3,2⟩) ∧\n (Bounded ⟨0,1,1⟩ ∧ Bounded ⟨0,2,0⟩ ∧ ¬ Verified ⟨0,2,0⟩) := by\n simp [Verified, Reproduced, Bounded]\n/- Explanation certificates are executable syntax for this same arithmetic process. -/\ninductive Program where\n | doubleInput\n | constant (value : Nat)\ndef Program.eval : Program → Nat → Nat\n | .doubleInput, n => n + n\n | .constant value, _ => value\n/- A process exposes outputs and an explanation response, whose certificate can be checked against those outputs. -/\nstructure Process where\n output : Nat → Nat\n explanation : Option Program\n/- The output-only application contract checks every relevant input. -/\ndef OutputContract (p : Process) : Prop := ∀ n, p.output n = n + n\n/- The explanation application contract requires a provided certificate faithful to this very process. -/\ndef ExplanationContract (p : Process) : Prop :=\n ∃ program, p.explanation = some program ∧ ∀ n, program.eval n = p.output n\n/- This process produces doubled values but returns no explanatory certificate. -/\ndef outputOnlyProcess : Process := ⟨fun n => n + n, none⟩\ndef explainedProcess : Process := ⟨fun n => n + n, some .doubleInput⟩\n/- Object scope fixes the very process whose contract is assessed; contract inputs themselves still range over all naturals. -/\ndef processScope (assessed : Process) : Theory Process :=\n singleton (fun candidate => candidate = assessed)\n/- This inferential facet checks an explicit contract under exact process-identity assumptions. -/\ndef processContractFacet (assessed : Process) (contract : Claim Process) : Facet Process :=\n .inferential (processScope assessed) contract\n/- The scope's compatible interpretations are exactly this assessed process, not an unrelated substitute. -/\ntheorem processScopeModels (assessed candidate : Process) :\n Models (processScope assessed) candidate ↔ candidate = assessed :=\n modelsSingleton (fun process => process = assessed) candidate\n/- A concrete contract proof supplies the facet's consequence for its scoped object. -/\ntheorem processContractDischarged (assessed : Process) (contract : Claim Process) (proof : contract assessed) :\n FacetDischarged (processContractFacet assessed contract) := by\n refine ⟨⟨assessed,(processScopeModels _ _).2 rfl⟩, ?_⟩\n intro candidate hc\n have same := (processScopeModels _ _).1 hc\n subst candidate\n exact proof\n/- Scoped capability grounds include exact claim, object-specific assumptions, canonical articulation and actual assessment. -/\ndef ProcessGrounds (assessed : Process) (contract : Claim Process) : Prop :=\n Grounds contract canonicalArticulation (fun facet => facet = processContractFacet assessed contract)\n [processContractFacet assessed contract]\ntheorem processGrounds (assessed : Process) (contract : Claim Process) (proof : contract assessed) :\n ProcessGrounds assessed contract := by\n have discharged := processContractDischarged assessed contract proof\n refine ⟨by simp, ?_, ?_⟩\n · intro facet hf; subst facet; exact List.mem_singleton.mpr rfl\n · intro facet hf; have hf' := List.mem_singleton.mp hf; subst facet\n exact ⟨rfl,canonicalArticulated _ discharged,canonicalFacetArticulated _,discharged⟩\n/- Universal output correctness here comes from the concrete program definition, not from an assumed capability label. -/\ntheorem outputCorrectByEvaluation : OutputContract outputOnlyProcess := fun _ => rfl\n/- This same process actually returns no explanation certificate. -/\ntheorem outputOnlyNoExplanation : ¬ ExplanationContract outputOnlyProcess := by\n rintro ⟨program,h,_⟩; cases h\n/- The full application contract requires outputs and an explanation of that same process. -/\ndef FullProcessContract (assessed : Process) : Prop := OutputContract assessed ∧ ExplanationContract assessed\n/- Output-only grounds have the assessed process itself as a counterworld to the stronger contract. -/\ndef OutputContractEvidence : Prop :=\n ProcessGrounds outputOnlyProcess OutputContract ∧\n Models (processScope outputOnlyProcess) outputOnlyProcess ∧\n ¬ Entails (processScope outputOnlyProcess) FullProcessContract\n/- Existing output evidence does not supply the absent explanation for the same object and scope. -/\ntheorem outputContractEvidence : OutputContractEvidence := by\n refine ⟨processGrounds _ _ outputCorrectByEvaluation, (processScopeModels _ _).2 rfl, ?_⟩\n intro stronger\n exact outputOnlyNoExplanation (stronger outputOnlyProcess ((processScopeModels _ _).2 rfl)).2\n/- Both actual application contracts have grounds and explicit object scopes; neither scope is empty. -/\ndef ScopedApplicationEvidence : Prop :=\n ProcessGrounds outputOnlyProcess OutputContract ∧\n ProcessGrounds explainedProcess FullProcessContract ∧\n (∀ candidate, Models (processScope outputOnlyProcess) candidate ↔ candidate = outputOnlyProcess) ∧\n (∀ candidate, Models (processScope explainedProcess) candidate ↔ candidate = explainedProcess) ∧\n Satisfiable (processScope outputOnlyProcess) ∧ Satisfiable (processScope explainedProcess)\n/- Concrete evaluation and a faithful double-input certificate establish the two differently scoped contracts. -/\ntheorem scopedApplicationEvidence : ScopedApplicationEvidence := by\n refine ⟨processGrounds _ _ outputCorrectByEvaluation, processGrounds _ _ ?_,\n processScopeModels _,processScopeModels _,⟨_,(processScopeModels _ _).2 rfl⟩,\n ⟨_,(processScopeModels _ _).2 rfl⟩⟩\n exact ⟨fun _ => rfl,⟨.doubleInput,rfl,fun _ => rfl⟩⟩\n/- Universal output correctness does not entail the explanation-requiring contract for the same process. -/\ntheorem outputNotExplanation : OutputContract outputOnlyProcess ∧\n ¬ ExplanationContract outputOnlyProcess ∧ OutputContractEvidence :=\n ⟨outputCorrectByEvaluation, outputOnlyNoExplanation, outputContractEvidence⟩\n/- Applications may use distinct contracts, and a faithful certificate can satisfy the stronger one. -/\ntheorem applicationContractsDiffer :\n (OutputContract outputOnlyProcess ∧ ¬ (OutputContract outputOnlyProcess ∧ ExplanationContract outputOnlyProcess)) ∧\n (OutputContract explainedProcess ∧ ExplanationContract explainedProcess) ∧\n ScopedApplicationEvidence :=\n ⟨⟨outputCorrectByEvaluation, fun h => outputOnlyNoExplanation h.2⟩,\n ⟨(fun _ => rfl), ⟨.doubleInput, rfl, fun _ => rfl⟩⟩, scopedApplicationEvidence⟩\n/- The assessor supplies a mathematical certificate; the process's own explanation response is unnecessary. -/\nstructure ExternalCertificate (p : Process) where\n assessorId : Nat\n assessedId : Nat\n distinctParticipants : assessorId ≠ assessedId\n outputCorrect : ∀ n, p.output n = n + n\n/- The external assessor 42 evaluates the specified process 7; the full output proof is constructed by evaluation. -/\ndef externalOutputCertificate : ExternalCertificate outputOnlyProcess :=\n ⟨42,7,by decide,fun _ => rfl⟩\n/- An external certificate establishes the output contract without producing an internal explanation. -/\ntheorem externalAssessment :\n (∃ certificate : ExternalCertificate outputOnlyProcess,\n certificate.assessorId = 42 ∧ certificate.assessedId = 7 ∧\n certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧\n ProcessGrounds outputOnlyProcess OutputContract ∧\n ¬ ExplanationContract outputOnlyProcess :=\n ⟨⟨externalOutputCertificate,rfl,rfl,externalOutputCertificate.distinctParticipants,\n externalOutputCertificate.outputCorrect⟩,\n processGrounds outputOnlyProcess OutputContract externalOutputCertificate.outputCorrect,\n outputOnlyNoExplanation⟩\n/- This argument records concepts and actual premises for a semantic inference, separately from executable tests. -/\ndef arithmeticArticulation : Articulation Nat := canonicalArticulation arithmeticFacet\n/- A reasoned inferential assessment needs no observation method, while applicable empirical assessment retains observations. -/\ntheorem nonExecutableAssessment :\n Grounds (fun n : Nat => n + 1 = 3) canonicalArticulation (fun f => f = arithmeticFacet) [arithmeticFacet] ∧\n usesObservation arithmeticFacet = false ∧\n FacetDischarged switchEmpirical ∧ usesObservation switchEmpirical = true := by\n refine ⟨⟨by simp, (by intro f hf; cases hf; simp), ?_⟩, rfl, switchEmpiricalDischarged, rfl⟩\n intro f hf; simp only [List.mem_singleton] at hf; cases hf\n exact ⟨rfl, canonicalArticulated _ noUniversalChain.1, canonicalFacetArticulated _, noUniversalChain.1⟩\n\nend CoreReader.Evidence\n```\n\n\n\n **L1** 导入 CoreReader.Logic,使其已检查声明可供本模块使用;这一行不提出新的哲学结论。\n\n\n **L2** 导入 CoreReader.Agency,使其已检查声明可供本模块使用;这一行不提出新的哲学结论。\n\n\n **L4** 打开命名空间 CoreReader.Evidence,使后续声明获得这一模块限定名。\n\n\n **L5** 允许不加限定使用 CoreReader.Logic 中的名称;这改变名称解析,不增加假设。\n\n\n **L6** 允许不加限定使用 CoreReader.Agency 中的名称;这改变名称解析,不增加假设。\n\n\n **L8** 说明 Record 的预定范围。对应声明涉及:记录给定世界的布尔测试及其记录结果,不包含测量出处或真实性验证。 该注释用于解释,不是证明前提。\n\n\n **L9** 声明数据接口 Record。记录给定世界的布尔测试及其记录结果,不包含测量出处或真实性验证。\n\n\n **L10** 保存读取实际被表示世界的指定布尔测试。\n\n\n **L11** 保存将与该测试比较的已观测布尔结果。\n\n\n **L12** 说明 Compatible 的预定范围。对应声明涉及:每条记录的测试结果都必须与记录值一致;空列表允许任意世界。 该注释用于解释,不是证明前提。\n\n\n **L13** 定义 Compatible。每条记录的测试结果都必须与记录值一致;空列表允许任意世界。\n\n\n **L14** 要求每条列出记录在 w 的真实测试等于该记录的观测结果。\n\n\n **L15** 说明 Supports 的预定范围。对应声明涉及:主张在所有记录兼容世界成立;这是模型内蕴涵,不是统计置信度。 该注释用于解释,不是证明前提。\n\n\n **L16** 定义 Supports。主张在所有记录兼容世界成立;这是模型内蕴涵,不是统计置信度。\n\n\n **L17** 要求同一主张在与全部记录相容的每个世界成立;没有相容世界时,该蕴含本身可能空真。\n\n\n **L18** 说明 Articulation 的预定范围。对应声明涉及:保存概念字符串、假设理论、理由列表和限度谓词。 该注释用于解释,不是证明前提。\n\n\n **L19** 声明数据接口 Articulation。保存概念字符串、假设理论、理由列表和限度谓词。\n\n\n **L20** 保存可识别概念名称;字符串本身不确立语义充分性。\n\n\n **L21** 保存作为表述假设陈述的实际理论。\n\n\n **L22** 把理由内容保存为针对同一世界类型的命题。\n\n\n **L23** 保存这些理由的真实应用限度谓词。\n\n\n **L24** 说明 Articulated 的预定范围。对应声明涉及:只要求概念与理由列表非空,不单独保证相关性或充分性。 该注释用于解释,不是证明前提。\n\n\n **L25** 定义 Articulated。只要求概念与理由列表非空,不单独保证相关性或充分性。\n\n\n **L26** 只要求概念与理由列表非空;这一程序条件弱于匹配且已履行的 Grounds。\n\n\n **L27** 说明 ValuePosition 的预定范围。对应声明涉及:表示采纳选项、实际选择、选项相关结果及理由、目标、约束、起点、范围和批评响应;这是明示应用适配模型。 该注释用于解释,不是证明前提。\n\n\n **L28** 声明数据接口 ValuePosition。表示采纳选项、实际选择、选项相关结果及理由、目标、约束、起点、范围和批评响应;这是明示应用适配模型。\n\n\n **L29** 给出该价值立场从中采纳某一项的选项类型。\n\n\n **L30** 给出用于解释各选项效果的后果类型。\n\n\n **L31** 规定被采纳的选项,与世界实际选择哪个选项分开。\n\n\n **L32** 从各世界读取实际选择的选项。\n\n\n **L33** 解释各世界中各选项的真实后果,而不保存任意支持标签。\n\n\n **L34** 把被采纳目标规定为后果上的谓词;该字段不证明其价值权威。\n\n\n **L35** 规定与目标一同检查、依赖世界和选项的约束。\n\n\n **L36** 保存起点理论;JointAdoption 将要求它与采纳及理由具有真实共同模型。\n\n\n **L37** 保存同时按世界与选项参数化的理由,因此切换采纳选项会改变受评理由。\n\n\n **L38** 规定该价值评估程序主张结论的范围。\n\n\n **L39** 识别哪些世界存在相关批评;这是明确的应用谓词。\n\n\n **L40** 保存各世界的可选文本回应;回应存在不证明批评已被充分回答。\n\n\n **L41** 说明 ValuePosition.commitment 的预定范围。对应声明涉及:承诺主张表示世界选择了所采纳选项,不再是可独立重贴的任意主张字段。 该注释用于解释,不是证明前提。\n\n\n **L42** 定义 ValuePosition.commitment。承诺主张表示世界选择了所采纳选项,不再是可独立重贴的任意主张字段。\n\n\n **L43** 通过实际选择等于同一采纳选项,导出承诺主张。\n\n\n **L44** 说明 ValuePosition.consequence 的预定范围。对应声明涉及:以目标及约束检查该采纳选项的模型结果。 该注释用于解释,不是证明前提。\n\n\n **L45** 定义 ValuePosition.consequence。以目标及约束检查该采纳选项的模型结果。\n\n\n **L46** 根据同一采纳选项的真实后果满足目标及真实约束,导出受评后果。\n\n\n **L47** 说明 ValuePosition.activeReasons 的预定范围。对应声明涉及:把每个选项相关理由实例化到采纳选项,用于根据表达。 该注释用于解释,不是证明前提。\n\n\n **L48** 定义 ValuePosition.activeReasons。把每个选项相关理由实例化到采纳选项,用于根据表达。\n\n\n **L49** 把每个按选项索引的理由特化到采纳选项,形成其实际表述的世界谓词。\n\n\n **L50** 说明 JointAdoption 的预定范围。对应声明涉及:要求存在一个世界,同时满足起点理论、范围、实际采纳及全部该选项理由。 该注释用于解释,不是证明前提。\n\n\n **L51** 定义 JointAdoption。要求存在一个世界,同时满足起点理论、范围、实际采纳及全部该选项理由。\n\n\n **L52** 要求起点假设、应用限度与实际采纳具有一个共同世界。\n\n\n **L53** 在同一见证处,要求针对该采纳选项的全部列出理由共同成立。\n\n\n **L54** 说明 ValueProcedure 的预定范围。对应声明涉及:要求非空理由、联合采纳见证、起点和范围内联合理由支持该选项后果,以及非空批评响应;不证明终极价值正确性。 该注释用于解释,不是证明前提。\n\n\n **L55** 定义 ValueProcedure。要求非空理由、联合采纳见证、起点和范围内联合理由支持该选项后果,以及非空批评响应;不证明终极价值正确性。\n\n\n **L56** 以理由非空与完整共同采纳见证开始 ValueProcedure。\n\n\n **L57** 对满足真实起点理论与限度的每个世界,施加后续条件后果要求。\n\n\n **L58** 用采纳选项的全部理由合取蕴含其真实后果;不要求单条理由充分。\n\n\n **L59** 在限度内,每项相关批评必须有指定的非空回应;这里检查回应记录,而非说服力。\n\n\n **L60** 说明 Facet 的预定范围。对应声明涉及:区分经验、推论、价值三个面向;同一主张可有多个面向。 该注释用于解释,不是证明前提。\n\n\n **L61** 声明可选构造 Facet。区分经验、推论、价值三个面向;同一主张可有多个面向。\n\n\n **L62** 经验方面保存真实测试记录,以及范围、结论与所述不确定性谓词。\n\n\n **L63** 推论方面保存真实前提理论及待从中蕴含的结论。\n\n\n **L64** 价值方面保存完整的选项与后果立场,包括起点理论、理由、限度及批评回应。\n\n\n **L65** 说明 Facet.claim 的预定范围。对应声明涉及:抽取经验或推论结论,价值面向则抽取其立场承诺。 该注释用于解释,不是证明前提。\n\n\n **L66** 定义 Facet.claim。抽取经验或推论结论,价值面向则抽取其立场承诺。\n\n\n **L67** 把经验方面自身结论 p 读为主张;记录、范围与不确定性仍为评估输入。\n\n\n **L68** 把推论方面自身结论 p 读为主张,与前提理论分开。\n\n\n **L69** 价值方面的主张是实际选择等于自身采纳选项,通过 v.commitment 导出。\n\n\n **L70** 说明 FacetDischarged 的预定范围。对应声明涉及:经验要求非空范围见证及支持,推论要求假设可满足且蕴涵结论,价值使用声明的程序接口。 该注释用于解释,不是证明前提。\n\n\n **L71** 定义 FacetDischarged。经验要求非空范围见证及支持,推论要求假设可满足且蕴涵结论,价值使用声明的程序接口。\n\n\n **L72** 进入经验履行情况,使用该方面真实记录、范围、结论 p 与不确定性谓词。\n\n\n **L73** 对经验方面,要求存在与记录相容且在范围内的世界,排除空经验域。\n\n\n **L74** 要求记录支持范围内结论及明确规定的不确定性谓词。\n\n\n **L75** 推论履行要求真实假设具有非空模型,且同一假设语义蕴含 p。\n\n\n **L76** 价值履行恰为同一立场声明的 ValueProcedure,不是终极价值充分性的证明。\n\n\n **L77** 说明 FacetArticulated 的预定范围。对应声明涉及:要求表达中的假设、理由和限度与对应面向精确对齐。 该注释用于解释,不是证明前提。\n\n\n **L78** 定义 FacetArticulated。要求表达中的假设、理由和限度与对应面向精确对齐。\n\n\n **L79** 在经验表述情况下,读取假设、理由与限度必须匹配的真实记录与范围。\n\n\n **L80** 这一经验适配器把表述假设及理由与实际记录相容性等同,并把表述限度与经验范围等同。\n\n\n **L81** 在推论情况下,以该方面真实假设理论作为表述参照。\n\n\n **L82** 这一推论适配器保留准确前提理论,将其模型条件表述为理由,并使用不受限的附加限度。\n\n\n **L83** 要求价值表述准确使用该立场的起点理论、采纳选项有效理由与限度。\n\n\n **L84** 说明 canonicalArticulation 的预定范围。对应声明涉及:按面向构造固定概念标签及与该面向对齐的假设、理由和限度。 该注释用于解释,不是证明前提。\n\n\n **L85** 定义 canonicalArticulation。按面向构造固定概念标签及与该面向对齐的假设、理由和限度。\n\n\n **L86** 从所选方面真实记录列表与范围构造经验规范表述。\n\n\n **L87** 构造命名测试结果与条件的经验表述,以实际相容性主张为前提和理由,原范围为限度。\n\n\n **L88** 从该方面真实前提理论构造推论规范表述。\n\n\n **L89** 从同一理论及其真实模型谓词构造推论表述,不增加限度。\n\n\n **L90** 使用同一完整立场 v 构造价值表述。\n\n\n **L91** 从真实起点理论、采纳选项理由与原限度构造价值表述。\n\n\n **L92** 说明 canonicalFacetArticulated 的预定范围。对应声明涉及:逐个面向用自反等式证明规范表达与原面向对齐。 该注释用于解释,不是证明前提。\n\n\n **L93** 陈述经检查的结果 canonicalFacetArticulated。逐个面向用自反等式证明规范表达与原面向对齐。\n\n\n **L94** 断言规范表述与同一方面具有语义连接;证明检查各方面构造子。\n\n\n **L95** 按三个方面构造子分类;各规范表述恰有对应分支要求的假设、理由与限度,三个等式均由自反性成立。\n\n\n **L96** 说明 canonicalArticulated 的预定范围。对应声明涉及:由已完成面向证明规范表达的概念与理由非空。 该注释用于解释,不是证明前提。\n\n\n **L97** 陈述经检查的结果 canonicalArticulated。由已完成面向证明规范表达的概念与理由非空。\n\n\n **L98** 给定该方面已履行,要求其规范概念与理由非空。\n\n\n **L99** 分别检查经验、推论与价值方面的规范表述。\n\n\n **L100** 在这一经验或推论分支中,规范概念列表和理由列表明确非空;化简验证两个表述要求。\n\n\n **L101** 在这一经验或推论分支中,规范概念列表和理由列表明确非空;化简验证两个表述要求。\n\n\n **L102** 在价值分支,前提 h 为 ValueProcedure v;其中理由非空必须确立规范有效理由非空。\n\n\n **L103** 对价值方面给出规范概念非空性,留下有效理由列表非空的义务。\n\n\n **L104** 利用通过检查的价值程序中的理由非空性;将理由特化到采纳选项保持非空。\n\n\n **L105** 说明 Grounds 的预定范围。对应声明涉及:要求非空面向清单、覆盖声明适用面、同一主张、表达对齐及各面向检查;不是现实充分性的统一判定器。 该注释用于解释,不是证明前提。\n\n\n **L106** 定义 Grounds。要求非空面向清单、覆盖声明适用面、同一主张、表达对齐及各面向检查;不是现实充分性的统一判定器。\n\n\n **L107** 独立于有限列表接收 actualApplicable,使覆盖成为明确义务,而非从列表成员关系推定。\n\n\n **L108** 要求方面列表非空,并包含每个满足 actualApplicable 的方面。\n\n\n **L109** 对每个列出方面,要求主张准确相同,并有属于该方面的非空表述。\n\n\n **L110** 还要求语义匹配真实前提、理由与限度,并通过其声明的适配器履行。\n\n\n **L111** 说明 AchievementAccountability 的预定范围。对应声明涉及:将成就主张交给同一Grounds接口,不另提供现实成就证明。 该注释用于解释,不是证明前提。\n\n\n **L112** 定义 AchievementAccountability。将成就主张交给同一Grounds接口,不另提供现实成就证明。\n\n\n **L113** 成就问责接收与 Grounds 相同的实际适用性谓词及方面列表。\n\n\n **L114** 直接以同一成就主张的 Grounds 定义问责,不增加普遍观测要求。\n\n\n **L115** 说明 transitionAchievement 的预定范围。对应声明涉及:把成就定义为同一模型变化前后状态的理解或构造扩展。 该注释用于解释,不是证明前提。\n\n\n **L116** 定义 transitionAchievement。把成就定义为同一模型变化前后状态的理解或构造扩展。\n\n\n **L117** 成就主张为所选变化自身前后状态之间的真实扩展。\n\n\n **L118** 说明 transitionPerformanceRecord 的预定范围。对应声明涉及:在两个变化模型中,测试同一后状态是否包含在该输入输出一的successor。 该注释用于解释,不是证明前提。\n\n\n **L119** 定义 transitionPerformanceRecord。在两个变化模型中,测试同一后状态是否包含在该输入输出一的successor。\n\n\n **L120** 表现测试检查该变化后状态中实际建构的操作。\n\n\n **L121** 只有后继操作存在且确实把共同变化输入变为 1 时,测试才记录 true。\n\n\n **L122** 说明 transitionReportRecord 的预定范围。对应声明涉及:仅记录报告宣称的操作、输入与输出,不直接记录成就是否实现。 该注释用于解释,不是证明前提。\n\n\n **L123** 定义 transitionReportRecord。仅记录报告宣称的操作、输入与输出,不直接记录成就是否实现。\n\n\n **L124** 开始构造一条读取实际变化公告的记录。\n\n\n **L125** 把 report 绑定到为同一变化生成的公告。\n\n\n **L126** 测试其所述后继操作、输入 0 与预期输出 1;记录积极公告,不据此确定操作存在。\n\n\n **L127** 说明 transitionPerformanceCompatible 的预定范围。对应声明涉及:穷尽膨胀与扩展两类,证明实际表现记录识别能力扩展。 该注释用于解释,不是证明前提。\n\n\n **L128** 陈述经检查的结果 transitionPerformanceCompatible。穷尽膨胀与扩展两类,证明实际表现记录识别能力扩展。\n\n\n **L129** 主张匹配真实积极表现记录当且仅当所选变化为 extend。\n\n\n **L130** 固定任意实际变化 inflate 或 extend,以证明记录相容性等价关系。\n\n\n **L131** 证明两个方向:表现相容性推出 extend,extend 则提供相容性。\n\n\n **L132** 假定该变化匹配真实积极表现记录。\n\n\n **L133** 把相容性应用于真实单元素表现记录,得到该变化的观测测试结果。\n\n\n **L134** 把实际变化分为 inflate 与 extend,两者后状态的操作内容不同。\n\n\n **L135** inflate 状态缺少后继操作,因此其表现测试不可能等于记录的 true。\n\n\n **L136** extend 情况通过自反性满足所需变化身份。\n\n\n **L137** 反方向中,代入变化等于 extend 的假设。\n\n\n **L138** 单元素记录列表的成员关系把任意记录确定为这一准确变化记录;先代入,再检查测试。\n\n\n **L139** 计算真实 extend 表现记录;其零输入后继测试等于记录的 true。\n\n\n **L140** 说明 transitionSupported 的预定范围。对应声明涉及:从表现识别、实际新增操作及报告内容,证明每个兼容变化都发生扩展。 该注释用于解释,不是证明前提。\n\n\n **L141** 陈述经检查的结果 transitionSupported。从表现识别、实际新增操作及报告内容,证明每个兼容变化都发生扩展。 后续策略块证明这一显式类型。\n\n\n **L142** 任取变化及其与真实表现记录的相容性,证明同一变化发生扩展。\n\n\n **L143** 用 transitionPerformanceCompatible 把每个与表现证据相容的变化确定为 extend。\n\n\n **L144** 用 extend 替换变化,使剩余成就主张针对其真实扩展后状态。\n\n\n **L145** 针对真实前后状态检查同一系统生成的 extend 报告:后继操作确为新增建构,并把输入 0 变为输出 1。\n\n\n **L146** 针对真实前后状态检查同一系统生成的 extend 报告:后继操作确为新增建构,并把输入 0 变为输出 1。\n\n\n **L147** 针对真实前后状态检查同一系统生成的 extend 报告:后继操作确为新增建构,并把输入 0 变为输出 1。\n\n\n **L148** 将 announcementClaimImpliesExpansion 应用于已核实报告内容,得到同一变化的 Expanded 主张。\n\n\n **L149** 说明 transitionFacet 的预定范围。对应声明涉及:把表现记录、零输入范围及精确扩展主张组成经验面向。 该注释用于解释,不是证明前提。\n\n\n **L150** 定义 transitionFacet。把表现记录、零输入范围及精确扩展主张组成经验面向。\n\n\n **L151** 从表现记录构造经验方面,并采用准确的输入 0 变化范围。\n\n\n **L152** 其结论为同一变化的成就,不确定性谓词明确为 True。\n\n\n **L153** 说明 transitionFacetDischarged 的预定范围。对应声明涉及:以扩展为非空见证,提供真实模型支持和恒真不确定性条件。 该注释用于解释,不是证明前提。\n\n\n **L154** 陈述经检查的结果 transitionFacetDischarged。以扩展为非空见证,提供真实模型支持和恒真不确定性条件。 后续策略块证明这一显式类型。\n\n\n **L155** 提供 extend 作为非空经验见证,包含相容表现证据与共同输入 0 范围;留下范围内支持及不确定性检查。\n\n\n **L156** 已证的变化支持为任意相容变化提供成就结论,因此也在所选范围内成立。\n\n\n **L157** 明确不受限的不确定性谓词为 True,因此该适配器组件直接成立;并未推得定量不确定性界限。\n\n\n **L158** 说明 transitionAccountable 的预定范围。对应声明涉及:用同一成就主张、范围、规范表达及已检查面向建立成就Grounds。 该注释用于解释,不是证明前提。\n\n\n **L159** 陈述经检查的结果 transitionAccountable。用同一成就主张、范围、规范表达及已检查面向建立成就Grounds。\n\n\n **L160** 陈述真实变化成就谓词的问责,并采用规范表述。\n\n\n **L161** 声明 transitionFacet 为唯一适用方面,并使用准确的单元素证据组合。\n\n\n **L162** 把问责拆为方面列表非空、覆盖实际适用性,以及各列出方面的匹配表述与履行。\n\n\n **L163** 适用性假设把方面确定为规定的唯一方面,因此它属于该单元素列表。\n\n\n **L164** 单元素成员关系把当前方面确定为规定方面;代入后检查其准确主张与依据。\n\n\n **L165** 组合主张相同、规范表述非空、表述与同一方面的语义连接,以及 transitionFacetDischarged。\n\n\n **L166** 组合主张相同、规范表述非空、表述与同一方面的语义连接,以及 transitionFacetDischarged。\n\n\n **L167** 说明 transitionReportCompatible 的预定范围。对应声明涉及:证明两种变化都能产生相同的宣称操作、输入和输出记录。 该注释用于解释,不是证明前提。\n\n\n **L168** 陈述经检查的结果 transitionReportCompatible。证明两种变化都能产生相同的宣称操作、输入和输出记录。\n\n\n **L169** 陈述该变化的积极报告记录与变化自身相容,也包括 inflate。\n\n\n **L170** 单元素记录列表的成员关系把任意记录确定为这一准确变化记录;先代入,再检查测试。\n\n\n **L171** 报告测试只检查真实的积极公告内容,两种变化中的公告内容计算结果相同。\n\n\n **L172** 说明 transitionReportDoesNotSupport 的预定范围。对应声明涉及:以库存膨胀变化作为符合自述却未实现成就的反模型。 该注释用于解释,不是证明前提。\n\n\n **L173** 陈述经检查的结果 transitionReportDoesNotSupport。以库存膨胀变化作为符合自述却未实现成就的反模型。\n\n\n **L174** 要求 inflate 匹配报告,却未满足同一成就谓词。\n\n\n **L175** 因此断言积极报告记录不能在全部相容变化上支持该成就。\n\n\n **L176** 展开 inflate 变化:理解和建构操作集合均未改变,因此不存在 Expanded 要求的新操作见证。\n\n\n **L177** 展开 inflate 变化:理解和建构操作集合均未改变,因此不存在 Expanded 要求的新操作见证。\n\n\n **L178** 组合 inflate 处的积极报告相容性与扩展主张为假;任何假定支持应用于此都会产生矛盾。\n\n\n **L179** 说明 ConcreteAchievementExample 的预定范围。对应声明涉及:组合同对象成就责任与获支持扩展,以及不获支持膨胀自述,并保留前后状态和输入身份。 该注释用于解释,不是证明前提。\n\n\n **L180** 定义 ConcreteAchievementExample。组合同对象成就责任与获支持扩展,以及不获支持膨胀自述,并保留前后状态和输入身份。\n\n\n **L181** 具体实例包含真实变化成就的实际问责。\n\n\n **L182** 其实际适用性谓词与列表确定同一个变化方面。\n\n\n **L183** 要求 extend 满足真实表现观测。\n\n\n **L184** 要求成就具有语义支持,且在 extend 处为真。\n\n\n **L185** 还保留与报告相容但该成就为假的 inflate 世界。\n\n\n **L186** 陈述由此得到的仅凭报告支持失败。\n\n\n **L187** 对每种变化,把报告前状态绑定到真实变化前状态。\n\n\n **L188** 把报告后状态绑定到同一变化的真实后状态。\n\n\n **L189** 把报告输入绑定到真实变化输入,并明确把该条件固定为 0。\n\n\n **L190** 说明 concreteAchievementExample 的预定范围。对应声明涉及:组合实际表现支持、自述反模型和精确状态与输入联系。 该注释用于解释,不是证明前提。\n\n\n **L191** 陈述经检查的结果 concreteAchievementExample。组合实际表现支持、自述反模型和精确状态与输入联系。 后续策略块证明这一显式类型。\n\n\n **L192** 在具体实例中组合真实成就的问责、extend 表现相容性与语义支持。\n\n\n **L193** 将同一支持应用于 extend 见证,确立该处的实际扩展。\n\n\n **L194** 纳入与报告相容的 inflate 反例,留下前后状态与输入相同的关系证明。\n\n\n **L195** 对任一变化,所有报告与状态连接及输入 0 的关系均由定义本身成立。\n\n\n **L196** 说明 achievementNeedsSupport 的预定范围。对应声明涉及:对任意实际主张应用所给兼容性与支持,并另附已检查的具体变化实例。 该注释用于解释,不是证明前提。\n\n\n **L197** 陈述经检查的结果 achievementNeedsSupport。对任意实际主张应用所给兼容性与支持,并另附已检查的具体变化实例。\n\n\n **L198** 假定所选实际世界匹配全部记录,且这些记录已经支持成就。\n\n\n **L199** 得出该实际世界中的成就为真,并附带另行构造的具体成就实例。\n\n\n **L200** 把已假定支持应用于实际证据相容世界,并将该局部真值与另行证明的具体成就实例组合。\n\n\n **L201** 说明 supportWeakening 的预定范围。对应声明涉及:同一证据支持p且p在每个世界推出q时,也支持较弱结论q。 该注释用于解释,不是证明前提。\n\n\n **L202** 陈述经检查的结果 supportWeakening。同一证据支持p且p在每个世界推出q时,也支持较弱结论q。\n\n\n **L203** 假定 p 已获支持且逐世界有 p 蕴含 q;使用相同记录得出 q 已获支持。\n\n\n **L204** 在每个相容世界 w,先用不变记录得出 p,再应用给定蕴含 weaker 得到 q。\n\n\n **L205** 说明 evidenceWeakeningCanLoseSupport 的预定范围。对应声明涉及:真布尔观察支持世界为真,删除该记录后假世界成为反例。 该注释用于解释,不是证明前提。\n\n\n **L206** 陈述经检查的结果 evidenceWeakeningCanLoseSupport。真布尔观察支持世界为真,删除该记录后假世界成为反例。\n\n\n **L207** 单一恒等观测支持布尔世界为 true。\n\n\n **L208** 删除该观测后记录为空,不能支持未改变的主张。\n\n\n **L209** 分开单条记录支持主张与删除该记录后同一主张不获支持两个目标。\n\n\n **L210** 从相容性读出有信息的恒等测试,它直接表明布尔世界为 true。\n\n\n **L211** 没有记录时 false 也相容;在该处检验假定支持,否定未改变的真世界主张。\n\n\n **L212** 说明 scopeRestriction 的预定范围。对应声明涉及:在narrow包含于wide的明确前提下,将支持结论的量词域缩窄。 该注释用于解释,不是证明前提。\n\n\n **L213** 陈述经检查的结果 scopeRestriction。在narrow包含于wide的明确前提下,将支持结论的量词域缩窄。\n\n\n **L214** 接收广域与窄域,并假定每个窄域输入均属于广域。\n\n\n **L215** 假定相同记录支持广域中每个输入上的 p。\n\n\n **L216** 得出窄域中每个输入上的支持;证据与谓词 p 都不改变。\n\n\n **L217** 对相容世界与窄域输入 x,included 将窄域成员关系转为广域成员关系,再在该处应用原广域支持。\n\n\n **L218** 说明 Duties 的预定范围。对应声明涉及:要求每个声明适用的面向完成其相应检查。 该注释用于解释,不是证明前提。\n\n\n **L219** 定义 Duties。要求每个声明适用的面向完成其相应检查。\n\n\n **L220** 要求每个实际适用方面通过其自身履行条件。\n\n\n **L221** 定义 LabeledDuties。完全忽略标签,保留由适用性决定的义务。\n\n\n **L222** 把带标签责任定义为原有适用性责任;标签不提供豁免。\n\n\n **L223** 说明 assessmentUnion 的预定范围。对应声明涉及:用析取分支证明适用面向并集的义务等价于分别履行两部分。 该注释用于解释,不是证明前提。\n\n\n **L224** 陈述经检查的结果 assessmentUnion。用析取分支证明适用面向并集的义务等价于分别履行两部分。\n\n\n **L225** 将两个适用性谓词并集的责任等同于两组责任均履行。\n\n\n **L226** 证明并集适用性谓词的责任与两个组成部分同时履行责任之间的两个方向。\n\n\n **L227** 利用对应析取嵌入,把并集责任分别限制到各适用方面谓词。\n\n\n **L228** 拆出两组责任,把实际适用性分为左右情况,并用对应责任履行同一方面。\n\n\n **L229** 说明 labelsCannotWaive 的预定范围。对应声明涉及:标签不进入义务定义,因此改变标签不改变义务。 该注释用于解释,不是证明前提。\n\n\n **L230** 陈述经检查的结果 labelsCannotWaive。标签不进入义务定义,因此改变标签不改变义务。\n\n\n **L231** 只改变标签列表不改变责任命题;该等价由自反性成立。\n\n\n **L232** 说明 switchRecord 的预定范围。对应声明涉及:记录布尔恒等测试结果为真。 该注释用于解释,不是证明前提。\n\n\n **L233** 定义 switchRecord。记录布尔恒等测试结果为真。\n\n\n **L234** 陈述经检查的结果 switchCompatible。证明与单条switch观察相容等价于布尔世界为真。 后续策略块证明这一显式类型。\n\n\n **L235** 证明与单元素开关记录相容,当且仅当真实布尔世界为 true。\n\n\n **L236** 把记录相容性应用于唯一指定测试,恢复其真实观测等式。\n\n\n **L237** 反方向中,单元素成员关系把任意列出记录确定为该测试,其等式即为给定观测前提。\n\n\n **L238** 陈述经检查的结果 switchSupported。从兼容性等价关系抽取被记录的真值结论。 给出的证明项使用所示构造见证或先前引理,而不增加公理。\n\n\n **L239** 使用 switchCompatible 的正向蕴含,从同一世界真实记录相容性提取 world=true。\n\n\n **L240** 说明 optionBenefit 的预定范围。对应声明涉及:选择true时收益为四,否则为零。 该注释用于解释,不是证明前提。\n\n\n **L241** 定义 optionBenefit。选择true时收益为四,否则为零。\n\n\n **L242** 定义 optionCost。选择true时成本为三,否则为零。\n\n\n **L243** 说明 optionReport 的预定范围。对应声明涉及:陈述与选项对应的成本和收益事实,不使用无关根据标记。 该注释用于解释,不是证明前提。\n\n\n **L244** 定义 optionReport。陈述与选项对应的成本和收益事实,不使用无关根据标记。\n\n\n **L245** 选项报告断言真实成本至多为 3,以及开启收益为 4、关闭收益为 0。\n\n\n **L246** 说明 switchPosition 的预定范围。对应声明涉及:采纳true选项,使用实际成本收益、成本小于收益目标、预算约束和范围内批评响应。 该注释用于解释,不是证明前提。\n\n\n **L247** 定义 switchPosition。采纳true选项,使用实际成本收益、成本小于收益目标、预算约束和范围内批评响应。\n\n\n **L248** 使用布尔选项表示开启与关闭。\n\n\n **L249** 以自然数对表示各后果的真实收益与成本。\n\n\n **L250** 明确采纳开启选项;采纳本身不是从算术推导的。\n\n\n **L251** 直接从布尔世界读取实际选择。\n\n\n **L252** 从同一真实选项计算收益与成本。\n\n\n **L253** 采纳真实收益严格超过真实成本这一目标。\n\n\n **L254** 按固定预算 3 检查实际选项成本。\n\n\n **L255** 假定实际布尔选择为开启;不把受评收益结论加入起点理论。\n\n\n **L256** 以按选项索引的真实成本与收益报告为唯一理由。\n\n\n **L257** 此例使用不受限世界范围;起点假设与理由内容仍约束程序。\n\n\n **L258** 把实际选择关闭的世界标记为相关批评情况。\n\n\n **L259** 给两个世界提供不同非空信息,包括在批评情况下重新考虑预算。\n\n\n **L260** 陈述经检查的结果 switchValueProcedure。提供一致采纳见证,由实际成本收益理由得到目标与约束,并检查两个布尔情形的响应。 后续策略块证明这一显式类型。\n\n\n **L261** 拆分 switchPosition 的理由非空、共同采纳见证、全部理由支持后果,以及回应批评的义务。\n\n\n **L262** 选择世界 true,满足起点选择、不受限限度与采纳选项,留下实际理由待检查。\n\n\n **L263** 任取 switchPosition 列表中的理由;下一步将在采纳的开启见证处确定其真实 optionReport 内容。\n\n\n **L264** 单元素成员关系把任意理由确定为针对该立场采纳选项的 optionReport;代入这一实际理由。\n\n\n **L265** 单元素成员关系把任意理由确定为针对该立场采纳选项的 optionReport;代入这一实际理由。\n\n\n **L266** 检查采纳的开启选项满足已记录成本界限与所述收益值。\n\n\n **L267** 对处于所述起点与限度条件的任意世界,假定全部有效理由合取。\n\n\n **L268** 从理由合取提取实际 optionReport 理由,而不是引入独立支持标签。\n\n\n **L269** 展开被采纳的选项:该证据针对开启选项。\n\n\n **L270** 利用已报告收益等式证明开启选项收益大于 3。\n\n\n **L271** 组合成本至多为 3 与收益大于 3,证明成本小于收益,并保留同一成本界限作为约束。\n\n\n **L272** 检查两个布尔世界,在需要回应批评时提供已记录的非空回应。\n\n\n **L273** 说明 oppositePosition 的预定范围。对应声明涉及:把采纳选项改为false并更新起点选择,保留同一结果模型和目标。 该注释用于解释,不是证明前提。\n\n\n **L274** 定义 oppositePosition。把采纳选项改为false并更新起点选择,保留同一结果模型和目标。\n\n\n **L275** 把采纳选项与起点选择都改为关闭,同时保留真实后果与理由解释。\n\n\n **L276** 说明 oppositePositionRejected 的预定范围。对应声明涉及:false可被联合采纳,但不满足原成本小于收益目标,故程序检查拒绝。 该注释用于解释,不是证明前提。\n\n\n **L277** 陈述经检查的结果 oppositePositionRejected。false可被联合采纳,但不满足原成本小于收益目标,故程序检查拒绝。 后续策略块证明这一显式类型。\n\n\n **L278** 在世界 false 为相反的关闭立场构造真实共同采纳见证;后续拒绝因此不依赖空域。\n\n\n **L279** 在世界 false 为相反的关闭立场构造真实共同采纳见证;后续拒绝因此不依赖空域。\n\n\n **L280** 在相反立场的 false 世界见证处任取列出理由,再检查关闭选项真实报告。\n\n\n **L281** 单元素成员关系把任意理由确定为针对该立场采纳选项的 optionReport;代入这一实际理由。\n\n\n **L282** 单元素成员关系把任意理由确定为针对该立场采纳选项的 optionReport;代入这一实际理由。\n\n\n **L283** 关闭选项自身的报告为真:零成本满足界限,零收益符合所述报告。\n\n\n **L284** 保留非空共同见证,另行否定相反价值程序的履行。\n\n\n **L285** 假定相反关闭立场满足完整 ValueProcedure,以从零收益后果导出矛盾。\n\n\n **L286** 在应用后果要求之前,先在相反立场的实际 false 世界见证处组合其全部理由。\n\n\n **L287** 任取相反立场真实理由,在其非空 false 世界反例处组合全部理由。\n\n\n **L288** 单元素成员关系把任意理由确定为针对该立场采纳选项的 optionReport;代入这一实际理由。\n\n\n **L289** 单元素成员关系把任意理由确定为针对该立场采纳选项的 optionReport;代入这一实际理由。\n\n\n **L290** 关闭选项自身的报告为真:零成本满足界限,零收益符合所述报告。\n\n\n **L291** 将假定的相反程序之联合理由后果条款,应用于同一起点与限度见证及其全部真实理由。\n\n\n **L292** 其假定目标要求关闭选项零成本严格小于零收益,与严格小于的非自反性矛盾。\n\n\n **L293** 说明 contradictoryStartingPosition 的预定范围。对应声明涉及:把起点换为恒假单项理论,使联合采纳见证不存在。 该注释用于解释,不是证明前提。\n\n\n **L294** 定义 contradictoryStartingPosition。把起点换为恒假单项理论,使联合采纳见证不存在。\n\n\n **L295** 把起点理论替换为不可能的单元素主张 False。\n\n\n **L296** 定义 impossibleAdoptionPosition。始终选择false却仍采纳true,使联合采纳不可能。\n\n\n **L297** 保留采纳的开启选项,却使所有实际选择为关闭,因此无法共同采纳。\n\n\n **L298** 说明 inadmissibleValuePositionsRejected 的预定范围。对应声明涉及:通过必需的联合见证分别拒绝不一致起点和不可能采纳。 该注释用于解释,不是证明前提。\n\n\n **L299** 陈述经检查的结果 inadmissibleValuePositionsRejected。通过必需的联合见证分别拒绝不一致起点和不可能采纳。\n\n\n **L300** 分别否定矛盾起点假设与不可能实际采纳的程序。\n\n\n **L301** 分开矛盾起点理论与不可能选择、采纳组合两个拒绝证明。\n\n\n **L302** 从假定满足程序的矛盾起点立场中提取共同采纳见证。\n\n\n **L303** 单元素起点理论在该见证处要求 False,直接否定其模型证明。\n\n\n **L304** 从假定的共同见证中提取无法实现的实际选择与采纳组合之间的相等关系。\n\n\n **L305** 所需采纳等式令不同布尔选项相等,因此该见证不存在。\n\n\n **L306** 说明 unsupportedPosition 的预定范围。对应声明涉及:复制实际价值立场但删除理由,使非空理由要求失败。 该注释用于解释,不是证明前提。\n\n\n **L307** 定义 unsupportedPosition。复制实际价值立场但删除理由,使非空理由要求失败。\n\n\n **L308** 定义 switchEmpirical。以switch观察支持世界为真,范围和不确定性谓词均为真。\n\n\n **L309** 使用真实开关观测、不受限范围与同一已开启主张;不确定性明确为 True。\n\n\n **L310** 陈述经检查的结果 switchEmpiricalDischarged。给true兼容见证、实际支持及平凡不确定性,完成经验检查。 后续策略块证明这一显式类型。\n\n\n **L311** 用 true 作为与开关记录和不受限经验范围相容的非空世界。\n\n\n **L312** 同一开关记录的语义支持,在每个相容世界证明范围内的开关主张。\n\n\n **L313** 履行明确为真的不确定性谓词,不增加经验置信度主张。\n\n\n **L314** 说明 mixedMissingResponsibility 的预定范围。对应声明涉及:经验面向通过,但同一主张的价值面缺理由,故混合义务整体失败。 该注释用于解释,不是证明前提。\n\n\n **L315** 陈述经检查的结果 mixedMissingResponsibility。经验面向通过,但同一主张的价值面缺理由,故混合义务整体失败。\n\n\n **L316** 保留真实经验开关方面的成功履行。\n\n\n **L317** 即使标签为空也否定全部混合责任,因为真实价值方面同样适用,却缺少已记录理由。\n\n\n **L318** 保留有效的经验开关方面,另行否定全部混合责任已经履行。\n\n\n **L319** 假定每个实际混合方面均已履行,包括已记录理由列表为空的价值方面。\n\n\n **L320** 从实际适用并集中选取价值方面,并提取理由列表必须非空的条件。\n\n\n **L321** 该理由列表依定义为空,因此否定的是这一已记录程序要求。\n\n\n **L322** 说明 uninformativeArgument 的预定范围。对应声明涉及:构造有概念、有恒真理由却无实质假设的表达。 该注释用于解释,不是证明前提。\n\n\n **L323** 定义 uninformativeArgument。构造有概念、有恒真理由却无实质假设的表达。\n\n\n **L324** 用空假设与 True 理由表述开关概念;这些非空文字不约束开关世界。\n\n\n **L325** 陈述经检查的结果 articulationNotSupport。表达非空不代表其空假设蕴涵世界为真。\n\n\n **L326** 无信息表述的真实假设不蕴含世界为 true。\n\n\n **L327** 把非空却无信息的概念与理由,和空理论已证的不能蕴含开关主张组合。\n\n\n **L328** 把非空却无信息的概念与理由,和空理论已证的不能蕴含开关主张组合。\n\n\n **L329** 说明 unrelatedArticulationRejected 的预定范围。对应声明涉及:虽表达非空且经验面向通过,两者的假设不匹配,不能视为同一根据表达。 该注释用于解释,不是证明前提。\n\n\n **L330** 陈述经检查的结果 unrelatedArticulationRejected。虽表达非空且经验面向通过,两者的假设不匹配,不能视为同一根据表达。\n\n\n **L331** 保留无关表述的程序存在性及开关方面的真实履行。\n\n\n **L332** 仍否定该无关表述与这一经验方面的语义匹配。\n\n\n **L333** 保留表述与有效开关证据,再单独检验这一无关表述是否真正匹配该方面。\n\n\n **L334** 假定无信息表述尽管前提理论为空,仍与 switchEmpirical 语义匹配。\n\n\n **L335** 在相容性主张自身处,计算假定的表述假设与经验相容性假设相等。\n\n\n **L336** 经验单元素理论包含该相容性主张,而无关空理论不包含;假定的相等推出 False。\n\n\n **L337** 使用所示局部证据或已证引理完成 unrelatedArticulationRejected 的这一组件;该组件属于下列固定结果:虽表达非空且经验面向通过,两者的假设不匹配,不能视为同一根据表达。\n\n\n **L338** 说明 temperatureRecord 的预定范围。对应声明涉及:只观测布尔对第一坐标,未观测第二坐标。 该注释用于解释,不是证明前提。\n\n\n **L339** 定义 temperatureRecord。只观测布尔对第一坐标,未观测第二坐标。\n\n\n **L340** 陈述经检查的结果 temperatureCompatible。复制第一坐标记录仍允许第二坐标为任意布尔值。\n\n\n **L341** 对任意输出坐标 b,重复温度记录仍与 (true,b) 相容。\n\n\n **L342** 对任意输出坐标 b,重复列表的成员关系仍选取同一温度测试;其观测的第一坐标为 true,而 b 不受约束。\n\n\n **L343** 对任意输出坐标 b,重复列表的成员关系仍选取同一温度测试;其观测的第一坐标为 true,而 b 不受约束。\n\n\n **L344** 对任意输出坐标 b,重复列表的成员关系仍选取同一温度测试;其观测的第一坐标为 true,而 b 不受约束。\n\n\n **L345** 对任意输出坐标 b,重复列表的成员关系仍选取同一温度测试;其观测的第一坐标为 true,而 b 不受约束。\n\n\n **L346** 说明 BudgetWorld 的预定范围。对应声明涉及:世界由行动布尔值和自然数预算组成。 该注释用于解释,不是证明前提。\n\n\n **L347** 引入类型缩写 BudgetWorld。世界由行动布尔值和自然数预算组成。\n\n\n **L348** 说明 announcement 的预定范围。对应声明涉及:定义固定行动宣告字符串,字符串自身不提供预算依据。 该注释用于解释,不是证明前提。\n\n\n **L349** 定义 announcement。定义固定行动宣告字符串,字符串自身不提供预算依据。\n\n\n **L350** 定义 announcementPosition。仅用行动自述作为选项理由,却要求实际成本收益及可用预算。\n\n\n **L351** 使用布尔选项表示开启与关闭。\n\n\n **L352** 以自然数对表示各后果的真实收益与成本。\n\n\n **L353** 明确采纳开启选项;采纳本身不是从算术推导的。\n\n\n **L354** 从第一坐标读取实际选择,同时让预算独立变化。\n\n\n **L355** 从同一真实选项计算收益与成本。\n\n\n **L356** 采纳真实收益严格超过真实成本这一目标。\n\n\n **L357** 比较采纳选项真实成本与该世界独立给定的预算。\n\n\n **L358** 固定选择为开启,不增加可负担性或预算假设。\n\n\n **L359** 使用真实按选项区分的公告文本作为理由;它不说明可用预算。\n\n\n **L360** 此例使用不受限世界范围;起点假设与理由内容仍约束程序。\n\n\n **L361** 把预算低于 3 认定为对该成本为 3 行动的相关批评。\n\n\n **L362** 记录成本超预算时重新考虑行动的非空信息。\n\n\n **L363** 说明 announcementHasJointAdoption 的预定范围。对应声明涉及:构造行动为真、预算零且自述理由成立的世界;后续失败不是缺少采纳见证。 该注释用于解释,不是证明前提。\n\n\n **L364** 陈述经检查的结果 announcementHasJointAdoption。构造行动为真、预算零且自述理由成立的世界;后续失败不是缺少采纳见证。 后续策略块证明这一显式类型。\n\n\n **L365** 选择已开启且预算为 0 的世界作为共同采纳见证;起点理论固定选择,却不假定可负担性。\n\n\n **L366** 在已开启且零预算的共同见证处任取公告理由。\n\n\n **L367** 根据成员关系,把实际理由确定为按选项索引的公告文本,再特化到采纳的开启选项。\n\n\n **L368** 根据成员关系,把实际理由确定为按选项索引的公告文本,再特化到采纳的开启选项。\n\n\n **L369** 根据成员关系,把实际理由确定为按选项索引的公告文本,再特化到采纳的开启选项。\n\n\n **L370** 实际公告等于开启选项的启动文本;这证明公告理由成立,不证明预算约束。\n\n\n **L371** 说明 announcementNotBudgetReason 的预定范围。对应声明涉及:预算零时,已采纳行动及非空真自述仍不能满足预算后果,故程序不成立。 该注释用于解释,不是证明前提。\n\n\n **L372** 陈述经检查的结果 announcementNotBudgetReason。预算零时,已采纳行动及非空真自述仍不能满足预算后果,故程序不成立。\n\n\n **L373** 要求公告理由非空,并在已开启且预算 0 处实际采纳。\n\n\n **L374** 在同一零预算世界,全部真实公告理由成立。\n\n\n **L375** 仍否定真实后果及整个价值程序。\n\n\n **L376** 组合非空公告理由与真实公告,否定零预算后果,留下整个程序失败的证明。\n\n\n **L377** 为预算 0 处的理由合取,任取真实公告理由列表成员。\n\n\n **L378** 根据成员关系,把实际理由确定为按选项索引的公告文本,再特化到采纳的开启选项。\n\n\n **L379** 根据成员关系,把实际理由确定为按选项索引的公告文本,再特化到采纳的开启选项。\n\n\n **L380** 实际公告等于开启选项的启动文本;这证明公告理由成立,不证明预算约束。\n\n\n **L381** 假定公告立场满足 ValueProcedure,以在预算 0 处检验其后果条款。\n\n\n **L382** 在同一已开启且预算为零的世界收集全部公告理由。\n\n\n **L383** 为该条款提供全部理由,在同一零预算世界任取公告理由。\n\n\n **L384** 根据成员关系,把实际理由确定为按选项索引的公告文本,再特化到采纳的开启选项。\n\n\n **L385** 根据成员关系,把实际理由确定为按选项索引的公告文本,再特化到采纳的开启选项。\n\n\n **L386** 实际公告等于开启选项的启动文本;这证明公告理由成立,不证明预算约束。\n\n\n **L387** 把假定程序应用于这一非空的零预算起点、限度实例及其真实公告理由。\n\n\n **L388** 所得成本约束要求成本 3 不超过预算 0,这是不可能的。\n\n\n **L389** 说明 actionRecord 的预定范围。对应声明涉及:只观测行动布尔值,不限制预算。 该注释用于解释,不是证明前提。\n\n\n **L390** 定义 actionRecord。只观测行动布尔值,不限制预算。\n\n\n **L391** 陈述经检查的结果 actionCompatible。两个重复行动记录仍与任意预算相容。 后续策略块证明这一显式类型。\n\n\n **L392** 重复列表中的每条行动记录只测试实际已开启坐标,因此任意给定预算仍相容。\n\n\n **L393** 说明 measurementRepeatNotSupport 的预定范围。对应声明涉及:用未观测坐标和预算零反例,分别拒绝单次及重复测量对无关结论和价值后果的支持。 该注释用于解释,不是证明前提。\n\n\n **L394** 陈述经检查的结果 measurementRepeatNotSupport。用未观测坐标和预算零反例,分别拒绝单次及重复测量对无关结论和价值后果的支持。\n\n\n **L395** 即使独立输出坐标为 false,真实温度测试仍返回 true。\n\n\n **L396** 在重复温度观测下保留该假输出世界。\n\n\n **L397** 在相同重复观测下也保留真输出世界。\n\n\n **L398** 单条温度记录不支持另一输出为 true。\n\n\n **L399** 重复该温度记录仍不支持另一输出为 true。\n\n\n **L400** 重复观测到启动与已开启、预算为 0 相容。\n\n\n **L401** 相同重复记录也与预算为 3 相容。\n\n\n **L402** 单条启动记录不支持该选项的真实目标与预算后果。\n\n\n **L403** 重复启动记录不能修复这一后果支持缺失。\n\n\n **L404** 基于公告的价值程序也未满足同一实际选项与约束。\n\n\n **L405** 记录观测真实值为 true,以及两个温度相容的输出选择,留下输出主张不获支持的反证。\n\n\n **L406** 保留预算 0 与预算 3 两个行动相容世界及已证的公告程序失败,留下可负担性支持主张的反证。\n\n\n **L407** 假定单次温度观测支持独立表示的第二输出为 true。\n\n\n **L408** 将假定的单记录输出支持应用于 (true,false):其温度观测为真,另一输出主张却为假。\n\n\n **L409** 将假定的单记录输出支持应用于 (true,false):其温度观测为真,另一输出主张却为假。\n\n\n **L410** 同一 (true,false) 反世界仍与重复温度记录相容,因此否定重复数据支持输出的主张。\n\n\n **L411** 假定单次行动观测支持采纳选项的收益与预算后果。\n\n\n **L412** 单次观测到启动与预算 0 相容;假定支持该处后果会迫使不可能的成本约束。\n\n\n **L413** 单次观测到启动与预算 0 相容;假定支持该处后果会迫使不可能的成本约束。\n\n\n **L414** 重复启动记录仍保留同一零预算反世界,因此仍不支持实际可负担后果。\n\n\n **L415** 说明 selfAssertionNotReason 的预定范围。对应声明涉及:组合无理由与非空但无预算依据的自断言反例,并为后者提供联合采纳见证。 该注释用于解释,不是证明前提。\n\n\n **L416** 陈述经检查的结果 selfAssertionNotReason。组合无理由与非空但无预算依据的自断言反例,并为后者提供联合采纳见证。\n\n\n **L417** 缺少理由的立场可以被实际采纳,却未通过其记录程序。\n\n\n **L418** 更强的公告实例具有非空理由,并在预算 0 处实际采纳。\n\n\n **L419** 其真实后果及程序仍失败,因为同一采纳选项超出预算。\n\n\n **L420** 保留真实共同采纳见证,排除以空起点域解释此失败。\n\n\n **L421** 按定义证明 unsupportedPosition.commitment true;若假定存在 ValueProcedure,则其理由非空要求与实际空理由列表矛盾。\n\n\n **L422** 复用 announcementNotBudgetReason 中非空真实公告理由与采纳等式。\n\n\n **L423** 还复用同一零预算后果及整个公告程序的失败。\n\n\n **L424** 保留 announcementHasJointAdoption,因此该失败不能由空或不一致起点域解释。\n\n\n **L425** 说明 valueWithoutSelfProof 的预定范围。对应声明涉及:给出有理由且一致、却不能由空假设推出的立场,并拒绝相反选项、不一致起点和不可能采纳变体。 该注释用于解释,不是证明前提。\n\n\n **L426** 陈述经检查的结果 valueWithoutSelfProof。给出有理由且一致、却不能由空假设推出的立场,并拒绝相反选项、不一致起点和不可能采纳变体。\n\n\n **L427** 要求开关立场的真实起点理论具有模型。\n\n\n **L428** 否定从空布尔理论推导其采纳承诺。\n\n\n **L429** 相反立场具有共同见证,却未通过后果评估。\n\n\n **L430** 还拒绝矛盾起点与无法采纳的变体,区分未由自身推得与不一致起点。\n\n\n **L431** 组合真实开关程序、作为起点模型的 true 世界,以及采纳主张不由 emptyTheory 蕴含。\n\n\n **L432** 加入非空相反选项的拒绝,以及矛盾起点与无法采纳两个单独变体。\n\n\n **L433** 说明 BenefitCostWorld 的预定范围。对应声明涉及:世界保存所选布尔选项及可变收益和成本。 该注释用于解释,不是证明前提。\n\n\n **L434** 引入类型缩写 BenefitCostWorld。世界保存所选布尔选项及可变收益和成本。\n\n\n **L435** 定义 measuredOutcome。true选项返回世界的收益成本对,false结果为零与零。\n\n\n **L436** 开启选项读取世界真实收益与成本对;关闭选项得到 (0,0)。\n\n\n **L437** 定义 benefitReason。要求同一选项测得收益为四。\n\n\n **L438** 收益理由要求实际选项的测得收益等于 4。\n\n\n **L439** 定义 costReason。要求该选项测得成本至多三。\n\n\n **L440** 成本理由要求同一选项的测得成本至多为 3。\n\n\n **L441** 说明 jointReasonPosition 的预定范围。对应声明涉及:用相互独立的选项收益与成本理由,共同支持采纳选项目标及预算。 该注释用于解释,不是证明前提。\n\n\n **L442** 定义 jointReasonPosition。用相互独立的选项收益与成本理由,共同支持采纳选项目标及预算。\n\n\n **L443** 使用布尔选项表示开启与关闭。\n\n\n **L444** 以自然数对表示各后果的真实收益与成本。\n\n\n **L445** 明确采纳开启选项;采纳本身不是从算术推导的。\n\n\n **L446** 从世界第一坐标读取选择,与测得收益及成本分开。\n\n\n **L447** 使用 measuredOutcome,使受评选项的真实收益与成本来自该世界。\n\n\n **L448** 采纳真实收益严格超过真实成本这一目标。\n\n\n **L449** 要求该选项测得成本至多为 3。\n\n\n **L450** 假定所选选项为开启,不假定收益或成本结论。\n\n\n **L451** 同时列出 benefitReason 与 costReason;程序将使用其合取。\n\n\n **L452** 此例使用不受限世界范围;起点假设与理由内容仍约束程序。\n\n\n **L453** 把真实测得成本大于 3 识别为相关批评。\n\n\n **L454** 记录当该选项真实成本超预算时重新评估它的非空回应。\n\n\n **L455** 说明 jointReasonProcedure 的预定范围。对应声明涉及:以收益四成本三构造联合见证,合用两个理由证明成本低于收益且不超预算。 该注释用于解释,不是证明前提。\n\n\n **L456** 陈述经检查的结果 jointReasonProcedure。以收益四成本三构造联合见证,合用两个理由证明成本低于收益且不超预算。 后续策略块证明这一显式类型。\n\n\n **L457** 拆分联合理由立场的理由非空、共同见证、基于合取的后果与批评回应。\n\n\n **L458** 用已开启、收益为 4、成本为 3 的世界作为共同的起点、限度与采纳见证。\n\n\n **L459** 在真实 (true,(4,3)) 见证处任取两条理由之一,再拆分成员关系检查各不同理由。\n\n\n **L460** 展开实际的双元素理由列表:benefitReason 与 costReason。\n\n\n **L461** 把理由成员关系分为收益理由,或剩余单元素成本理由。\n\n\n **L462** 代入收益理由,检查见证的测得收益恰为 4。\n\n\n **L463** 把剩余理由确定为 costReason 并代入。\n\n\n **L464** 把剩余理由确定为 costReason 并代入。\n\n\n **L465** 利用自然数序的自反性检查见证的成本界限 3 ≤ 3。\n\n\n **L466** 对任意被接纳世界,假定全部有效理由共同成立,而不要求任一理由单独充分。\n\n\n **L467** 在该世界与采纳选项处,从理由合取提取实际 benefitReason。\n\n\n **L468** 在同一世界与选项处,从同一合取提取 costReason。\n\n\n **L469** 展开 benefitReason:采纳的开启选项之测得收益等于 4。\n\n\n **L470** 展开 costReason:同一选项的测得成本至多为 3。\n\n\n **L471** 保留实际成本约束,只留下收益严格大于成本的目标。\n\n\n **L472** 把测得收益改写为 4,并检查它大于 3。\n\n\n **L473** 合成成本至多为 3 与 3 小于收益,使用两个理由确立成本小于收益。\n\n\n **L474** 对限度内且批评相关的世界,构造针对该选项成本过高的必需回应。\n\n\n **L475** 提供关于成本超预算时重新评估选项的明确非空回应;这登记回应,不证明其说服充分性。\n\n\n **L476** 说明 JointReasonsExample 的预定范围。对应声明涉及:表示联合理由程序通过,但任一单独理由都可在后果失败的世界成立。 该注释用于解释,不是证明前提。\n\n\n **L477** 定义 JointReasonsExample。表示联合理由程序通过,但任一单独理由都可在后果失败的世界成立。\n\n\n **L478** 要求双理由立场满足完整 ValueProcedure。\n\n\n **L479** 固定仅满足收益理由的反世界 (true,(4,5)),它满足同一起点假设与限度。\n\n\n **L480** 在该世界,实际采纳与收益理由均成立。\n\n\n **L481** 否定该处受评后果,因为真实成本过高。\n\n\n **L482** 在同一起点假设与限度下固定仅满足成本理由的反世界 (true,(0,3))。\n\n\n **L483** 在该世界,实际采纳与成本理由成立。\n\n\n **L484** 否定其受评后果,因为零收益没有超过成本 3。\n\n\n **L485** 陈述经检查的结果 jointReasonsExample。以收益四成本五及收益零成本三分别反驳单个理由充分。 后续策略块证明这一显式类型。\n\n\n **L486** 以已检查的双理由程序开始组合实例。\n\n\n **L487** 提供仅满足收益理由的反世界:收益 4、成本 5,且满足相同起点、限度与采纳条件。\n\n\n **L488** 在相同条件下提供仅满足成本理由的反世界:收益 0、成本 3。\n\n\n **L489** 仅有收益理由的世界违反成本约束 5 ≤ 3;自然数算术消去该矛盾。\n\n\n **L490** 仅有成本理由的世界不可能满足严格目标 3 < 0;算术完成该反例。\n\n\n **L491** 说明 heterogeneousReasons 的预定范围。对应声明涉及:组合经验、推论、价值实例,并加入任一理由单独不足的真实联合理由实例。 该注释用于解释,不是证明前提。\n\n\n **L492** 陈述经检查的结果 heterogeneousReasons。组合经验、推论、价值实例,并加入任一理由单独不足的真实联合理由实例。\n\n\n **L493** 纳入真实已履行的经验开关方面。\n\n\n **L494** 纳入推论方面,其可满足的真世界前提蕴含同一真世界主张。\n\n\n **L495** 在此登记定理中纳入真实开关价值程序与双理由共同支持实例。\n\n\n **L496** 组合已检查经验方面、非空推论单元素理论、价值程序及联合理由反例。\n\n\n **L497** 对推论方面,其单元素前提在任意模型中直接给出同一真世界主张。\n\n\n **L499** 说明 zeroRecord 的预定范围。对应声明涉及:只测试布尔函数在自然数零处的输出。 该注释用于解释,不是证明前提。\n\n\n **L500** 定义 zeroRecord。只测试布尔函数在自然数零处的输出。\n\n\n **L501** 定义 localGenerator。生成只在seed输入处返回真的布尔函数。\n\n\n **L502** 说明 allTrue 的预定范围。对应声明涉及:要求函数在每个自然数输入都返回真。 该注释用于解释,不是证明前提。\n\n\n **L503** 定义 allTrue。要求函数在每个自然数输入都返回真。\n\n\n **L504** 陈述经检查的结果 zeroCompatible。证明零点记录的兼容性恰好只要求f(0)=true。 后续策略块证明这一显式类型。\n\n\n **L505** 证明匹配 zeroRecord 与真实函数在输入 0 返回 true 之间的两个方向。\n\n\n **L506** 把记录相容性应用于唯一指定测试,恢复其真实观测等式。\n\n\n **L507** 反方向中,单元素成员关系把任意列出记录确定为该测试,其等式即为给定观测前提。\n\n\n **L508** 说明 GeneratingProcess 的预定范围。对应声明涉及:保存生产者身份、实际旧谓词及修订算法种子。 该注释用于解释,不是证明前提。\n\n\n **L509** 声明数据接口 GeneratingProcess。保存生产者身份、实际旧谓词及修订算法种子。\n\n\n **L510** 保存实际生成过程的所有者标识。\n\n\n **L511** 保存该过程生成修订之前的布尔值函数。\n\n\n **L512** 保存该过程真实局部生成器使用的种子输入。\n\n\n **L513** 说明 GeneratingProcess.outputRevision 的预定范围。对应声明涉及:保留旧谓词成功输入,并由实际局部生成器增加种子输入。 该注释用于解释,不是证明前提。\n\n\n **L514** 定义 GeneratingProcess.outputRevision。保留旧谓词成功输入,并由实际局部生成器增加种子输入。\n\n\n **L515** 修订函数保留每个原先为真的输出,或在实际生成种子输入处增加真值。\n\n\n **L516** 说明 ProducedRevision 的预定范围。对应声明涉及:保存生产者及精确旧新谓词对象。 该注释用于解释,不是证明前提。\n\n\n **L517** 声明数据接口 ProducedRevision。保存生产者及精确旧新谓词对象。\n\n\n **L518** 标识哪个所有者生成了这一具体修订对象。\n\n\n **L519** 保存修订的真实前函数。\n\n\n **L520** 保存修订的真实后函数。\n\n\n **L521** 说明 GeneratingProcess.produce 的预定范围。对应声明涉及:由该过程构造带自身主体及实际旧函数、输出函数的修订。 该注释用于解释,不是证明前提。\n\n\n **L522** 定义 GeneratingProcess.produce。由该过程构造带自身主体及实际旧函数、输出函数的修订。\n\n\n **L523** 直接以该过程的所有者、原函数及计算所得输出修订构造修订对象。\n\n\n **L524** 定义 sampleGeneratingProcess。以主体十七、恒假旧谓词及零种子构造实际生成过程。\n\n\n **L525** 说明 OwnedRevisionExample 的预定范围。对应声明涉及:把自身来源与精确旧新函数关联到零输入上的实际变化,而全局主张仍无支持。 该注释用于解释,不是证明前提。\n\n\n **L526** 定义 OwnedRevisionExample。把自身来源与精确旧新函数关联到零输入上的实际变化,而全局主张仍无支持。\n\n\n **L527** 把修订生成者标识绑定到真实生成过程所有者。\n\n\n **L528** 把其前函数绑定到该过程的真实原函数。\n\n\n **L529** 把其后函数绑定到该过程的真实 outputRevision。\n\n\n **L530** 要求输入 0 处实际从此前 false 变为此后 true。\n\n\n **L531** 保留修订后输入 1 处真实为 false 的输出。\n\n\n **L532** 实际生成的后函数匹配输入 0 观测。\n\n\n **L533** 该记录仍不支持所有输入为真的主张。\n\n\n **L534** 说明 ownedRevisionExample 的预定范围。对应声明涉及:计算主体和对象联系,并用自产函数在一处失败反驳全称支持。 该注释用于解释,不是证明前提。\n\n\n **L535** 陈述经检查的结果 ownedRevisionExample。计算主体和对象联系,并用自产函数在一处失败反驳全称支持。 后续策略块证明这一显式类型。\n\n\n **L536** 通过计算检查生成者身份、旧对象与输出修订关系及真实样本值;保留零输入记录相容性,留下全称支持的反证。\n\n\n **L537** 假定 zeroRecord 支持 allTrue,以该所有者实际生成的修订反驳它。\n\n\n **L538** 把假定支持应用于该所有者实际生成的后函数及输入 1;该修订在此仍返回 false。\n\n\n **L539** 消去所得 false=true 等式;实际修订构成证据相容反例。\n\n\n **L540** 说明 selfOriginDoesNotSupport 的预定范围。对应声明涉及:保留局部观察反模型,另加具有同一未获支持全局主张的真实自身旧新修订。 该注释用于解释,不是证明前提。\n\n\n **L541** 陈述经检查的结果 selfOriginDoesNotSupport。保留局部观察反模型,另加具有同一未获支持全局主张的真实自身旧新修订。\n\n\n **L542** 计算 localGenerator 0 在 0 处为 true、在 1 处为 false。\n\n\n **L543** 要求该生成函数匹配同一输入 0 记录。\n\n\n **L544** 陈述全域支持失败,并纳入具体所有者、原对象与修订关系实例。\n\n\n **L545** 计算生成函数在 0 与 1 的值,给出零输入记录相容性,并纳入自有修订关系实例。\n\n\n **L546** 假定局部零输入观测蕴含每个相容函数的全部输入均输出 true。\n\n\n **L547** 把假定全称支持实例化到 localGenerator 0,再取输入 1;零输入相容性并未约束这一失败输入。\n\n\n **L548** 消去所得 false=true 等式;实际修订构成证据相容反例。\n\n\n **L549** 说明 localNotUniversal 的预定范围。对应声明涉及:常真函数与零点真函数都符合局部记录,但只有前者全称成立,故局部记录不支持全称结论。 该注释用于解释,不是证明前提。\n\n\n **L550** 陈述经检查的结果 localNotUniversal。常真函数与零点真函数都符合局部记录,但只有前者全称成立,故局部记录不支持全称结论。\n\n\n **L551** 要求至少存在一个自然数输入处于观测单元素范围之外。\n\n\n **L552** 恒真函数匹配零输入观测。\n\n\n **L553** 局部生成器也匹配同一观测。\n\n\n **L554** 第一个函数全域为真,第二个却不是。\n\n\n **L555** 因此共同观测不支持全域为真。\n\n\n **L556** 提供观测范围以外的输入,并证明恒真函数与局部生成器都满足同一零输入观测。\n\n\n **L557** 恒真函数全域为真;保留已知支持反例,留下局部生成器全称主张的反证。\n\n\n **L558** 在输入 1 检验局部生成器的假定全域真值,而其实际结果为 false。\n\n\n **L559** 说明 hiddenDifference 的预定范围。对应声明涉及:两函数在零点范围相同,却在一处不同,说明排除范围不能否认相关差异。 该注释用于解释,不是证明前提。\n\n\n **L560** 陈述经检查的结果 hiddenDifference。两函数在零点范围相同,却在一处不同,说明排除范围不能否认相关差异。\n\n\n **L561** 只对满足 n=0 的输入陈述两个函数相等。\n\n\n **L562** 陈述它们在输入 1 处真实输出不等。\n\n\n **L563** 分开输入 0 范围内一致与输入 1 处真实输出不同两个结论。\n\n\n **L564** 根据范围前提代入 n=0;两个函数都计算为 true。\n\n\n **L565** 说明 singleObservation 的预定范围。对应声明涉及:单条记录有兼容见证并支持局部结果,但不支持全输入结论。 该注释用于解释,不是证明前提。\n\n\n **L566** 陈述经检查的结果 singleObservation。单条记录有兼容见证并支持局部结果,但不支持全输入结论。\n\n\n **L567** 要求存在与单次观测相容的真实函数,避免空证据语义。\n\n\n **L568** 该单条记录支持其真实输入 0 主张。\n\n\n **L569** 它不支持更强的全输入主张。\n\n\n **L570** 计算记录数量为一,并提供 localGenerator 0 作为真实相容见证。\n\n\n **L571** 从相容性直接提取获支持的输入 0 事实,并复用已证的 allTrue 支持失败。\n\n\n **L572** 说明 arithmeticFacet 的预定范围。对应声明涉及:以n=2为假设、n+1=3为结论构造推论面向。 该注释用于解释,不是证明前提。\n\n\n **L573** 定义 arithmeticFacet。以n=2为假设、n+1=3为结论构造推论面向。\n\n\n **L574** 定义 usesObservation。只按面向标签判断是否经验型,不判断命题是否可计算。\n\n\n **L575** 经验方面携带真实测试记录,因此将其分类为使用观测。\n\n\n **L576** 在此已表示的方法分类器中,把推论与价值方面分类为不使用观测。\n\n\n **L577** 说明 noUniversalChain 的预定范围。对应声明涉及:以二为模型证明算术推论面向成立且无需经验观察。 该注释用于解释,不是证明前提。\n\n\n **L578** 陈述经检查的结果 noUniversalChain。以二为模型证明算术推论面向成立且无需经验观察。 后续策略块证明这一显式类型。\n\n\n **L579** 提供 n=2 作为推论理论的非空见证,并指出其方面构造子不使用观测。\n\n\n **L580** 任取满足算术方面真实前提理论的自然数世界 n。\n\n\n **L581** 从真实单元素前提提取 n=2,而不是假定所需后继结论。\n\n\n **L582** 把算术结论 n+1=3 展开为剩余目标。\n\n\n **L583** 根据前提把 n 改写为 2;所需算术等式通过计算化简。\n\n\n **L584** 说明 Trial 的预定范围。对应声明涉及:分别保存设置、实际结果和记录结果三个自然数字段。 该注释用于解释,不是证明前提。\n\n\n **L585** 声明数据接口 Trial。分别保存设置、实际结果和记录结果三个自然数字段。\n\n\n **L586** 保存试次设置,与结果分开。\n\n\n **L587** 保存试次实际结果,无论记录是否准确。\n\n\n **L588** 保存独立记录的结果,以便比较准确性。\n\n\n **L589** 说明 Verified 的预定范围。对应声明涉及:记录结果等于给定实际结果即满足此验证谓词。 该注释用于解释,不是证明前提。\n\n\n **L590** 定义 Verified。记录结果等于给定实际结果即满足此验证谓词。\n\n\n **L591** 定义 Reproduced。只要求两次设置相等,不要求结果相同。\n\n\n **L592** 定义 Bounded。要求实际结果不超过固定阈值二。\n\n\n **L593** 说明 variableOutcomesStableBound 的预定范围。对应声明涉及:同设置的结果一和二不同,却都满足给定范围界限。 该注释用于解释,不是证明前提。\n\n\n **L594** 陈述经检查的结果 variableOutcomesStableBound。同设置的结果一和二不同,却都满足给定范围界限。\n\n\n **L595** 固定第一试次:设置 0,实际及记录结果均为 1。\n\n\n **L596** 固定第二试次:设置相同,实际及记录结果均为 2。\n\n\n **L597** 要求两个明确固定试次的设置相同、真实结果不同,且都满足 actualOutcome ≤ 2。\n\n\n **L598** 计算两个相同设置的试次:实际结果 1 与 2 不同,却都满足 actualOutcome ≤ 2。\n\n\n **L599** 说明 verificationReproductionStability 的预定范围。对应声明涉及:用具体数字分别区分记录准确、设置复现和结果有界。 该注释用于解释,不是证明前提。\n\n\n **L600** 陈述经检查的结果 verificationReproductionStability。用具体数字分别区分记录准确、设置复现和结果有界。\n\n\n **L601** 要求两个记录准确但设置不同的试次。\n\n\n **L602** 要求设置复现,同时第二记录不准确且实际结果超出界限。\n\n\n **L603** 要求界限保持,即使其中一个结果记录不准确。\n\n\n **L604** 分别计算各具体试次谓词,展示设置变化、记录不准确及界限失败或保持,而不混淆这些性质。\n\n\n **L605** 说明 Program 的预定范围。对应声明涉及:定义只含输入翻倍及常量的微型解释程序语法。 该注释用于解释,不是证明前提。\n\n\n **L606** 声明可选构造 Program。定义只含输入翻倍及常量的微型解释程序语法。\n\n\n **L607** 提供把实际输入加倍的解释程序语法。\n\n\n **L608** 提供常量输出解释程序语法,携带其返回自然数。\n\n\n **L609** 定义 Program.eval。执行翻倍或返回储存常量。\n\n\n **L610** 通过真实加法 n+n 计算 doubleInput 解释程序在 n 处的结果。\n\n\n **L611** 通过返回存储值计算常量程序,与输入无关。\n\n\n **L612** 说明 Process 的预定范围。对应声明涉及:保存实际输出函数和可缺失的解释程序。 该注释用于解释,不是证明前提。\n\n\n **L613** 声明数据接口 Process。保存实际输出函数和可缺失的解释程序。\n\n\n **L614** 保存同一过程在自然数输入上的真实输出函数。\n\n\n **L615** 保存过程可选的已提供解释程序,与输出函数分开。\n\n\n **L616** 说明 OutputContract 的预定范围。对应声明涉及:要求每个自然数输入的输出等于输入翻倍。 该注释用于解释,不是证明前提。\n\n\n **L617** 定义 OutputContract。要求每个自然数输入的输出等于输入翻倍。\n\n\n **L618** 说明 ExplanationContract 的预定范围。对应声明涉及:要求已附程序在所有输入上与同一过程输出相等,不断言因果理解。 该注释用于解释,不是证明前提。\n\n\n **L619** 定义 ExplanationContract。要求已附程序在所有输入上与同一过程输出相等,不断言因果理解。\n\n\n **L620** 要求实际提供程序,且其在每个自然数输入的计算等于该过程输出。\n\n\n **L621** 说明 outputOnlyProcess 的预定范围。对应声明涉及:给出正确翻倍输出,却不提供解释程序。 该注释用于解释,不是证明前提。\n\n\n **L622** 定义 outputOnlyProcess。给出正确翻倍输出,却不提供解释程序。\n\n\n **L623** 定义 explainedProcess。给同样输出并附上翻倍程序。\n\n\n **L624** 说明 processScope 的预定范围。对应声明涉及:把候选范围限定为同一被评过程,不缩窄合同的输入量词域。 该注释用于解释,不是证明前提。\n\n\n **L625** 定义 processScope。把候选范围限定为同一被评过程,不缩窄合同的输入量词域。\n\n\n **L626** 用真实等式 candidate=assessed 限制理论模型,而不是假定所需契约。\n\n\n **L627** 说明 processContractFacet 的预定范围。对应声明涉及:在精确被评过程身份假设下构造合同推论面向。 该注释用于解释,不是证明前提。\n\n\n **L628** 定义 processContractFacet。在精确被评过程身份假设下构造合同推论面向。\n\n\n **L629** 用这一准确对象身份范围与给定契约结论构造推论方面。\n\n\n **L630** 说明 processScopeModels 的预定范围。对应声明涉及:证明满足身份范围恰好等价于候选为同一被评过程。 该注释用于解释,不是证明前提。\n\n\n **L631** 陈述经检查的结果 processScopeModels。证明满足身份范围恰好等价于候选为同一被评过程。\n\n\n **L632** 陈述满足该范围恰等于成为受评过程。\n\n\n **L633** 用等于真实受评 Process 的谓词实例化 modelsSingleton,准确证明哪些候选满足 processScope。\n\n\n **L634** 说明 processContractDischarged 的预定范围。对应声明涉及:利用给定实际过程合同证明及范围身份等式,完成对应推论检查。 该注释用于解释,不是证明前提。\n\n\n **L635** 陈述经检查的结果 processContractDischarged。利用给定实际过程合同证明及范围身份等式,完成对应推论检查。\n\n\n **L636** 使用明确契约证明前提,得出同一对象契约方面的履行。\n\n\n **L637** 以受评过程自身作为其身份范围的模型,留下契约的语义蕴含。\n\n\n **L638** 任取候选及其处于真实受评过程身份范围的证明 hc。\n\n\n **L639** 从范围模型 hc 恢复候选恰为受评过程。\n\n\n **L640** 代入该过程身份,使契约目标针对实际受评对象。\n\n\n **L641** 使用明确给出的该对象契约证明前提;此一般辅助结果不会无前提地产生契约正确性。\n\n\n **L642** 说明 ProcessGrounds 的预定范围。对应声明涉及:为精确过程及合同面向要求规范Grounds,适用范围只含该面向。 该注释用于解释,不是证明前提。\n\n\n **L643** 定义 ProcessGrounds。为精确过程及合同面向要求规范Grounds,适用范围只含该面向。\n\n\n **L644** 要求给定契约具有 Grounds,使用规范表述,并将准确受评过程方面认定为适用。\n\n\n **L645** 列出的证据组合恰好包含同一过程契约方面。\n\n\n **L646** 陈述经检查的结果 processGrounds。从同一被评过程的实际合同证明构造匹配Grounds。\n\n\n **L647** 由受评过程处的明确契约证明,得出这些同一对象 ProcessGrounds。\n\n\n **L648** 把契约履行辅助结果应用于同一受评过程的明确证明。\n\n\n **L649** 拆分方面非空、准确适用性覆盖,以及各方面的主张、表述与履行义务。\n\n\n **L650** 适用性假设把方面确定为规定的唯一方面,因此它属于该单元素列表。\n\n\n **L651** 单元素成员关系把当前方面确定为规定方面;代入后检查其准确主张与依据。\n\n\n **L652** 组合相同契约主张、非空规范表述、与对象范围的语义连接及已确立履行。\n\n\n **L653** 说明 outputCorrectByEvaluation 的预定范围。对应声明涉及:从实际输出函数直接证明全输入翻倍,不假定成功标记。 该注释用于解释,不是证明前提。\n\n\n **L654** 陈述经检查的结果 outputCorrectByEvaluation。从实际输出函数直接证明全输入翻倍,不假定成功标记。 给出的证明项使用所示构造见证或先前引理,而不增加公理。\n\n\n **L655** 说明 outputOnlyNoExplanation 的预定范围。对应声明涉及:因同一过程储存none而拒绝已附解释程序的存在。 该注释用于解释,不是证明前提。\n\n\n **L656** 陈述经检查的结果 outputOnlyNoExplanation。因同一过程储存none而拒绝已附解释程序的存在。 后续策略块证明这一显式类型。\n\n\n **L657** 任何解释契约都需提供程序,令其 some 值等于该过程实际的 none 回应;不同选项构造子使之不可能。\n\n\n **L658** 说明 FullProcessContract 的预定范围。对应声明涉及:要求同一过程既输出正确,又附有输出一致的解释程序。 该注释用于解释,不是证明前提。\n\n\n **L659** 定义 FullProcessContract。要求同一过程既输出正确,又附有输出一致的解释程序。\n\n\n **L660** 说明 OutputContractEvidence 的预定范围。对应声明涉及:组合有根据输出及非空精确过程范围,以该模型反驳更强完整合同。 该注释用于解释,不是证明前提。\n\n\n **L661** 定义 OutputContractEvidence。组合有根据输出及非空精确过程范围,以该模型反驳更强完整合同。\n\n\n **L662** 要求真实只输出过程具有输出正确性依据。\n\n\n **L663** 保留该过程自身作为准确评估范围中的实例。\n\n\n **L664** 否定同一范围蕴含更强的输出与解释联合契约。\n\n\n **L665** 说明 outputContractEvidence 的预定范围。对应声明涉及:由计算建立输出Grounds,并用同一过程缺少解释反驳完整合同蕴涵。 该注释用于解释,不是证明前提。\n\n\n **L666** 陈述经检查的结果 outputContractEvidence。由计算建立输出Grounds,并用同一过程缺少解释反驳完整合同蕴涵。 后续策略块证明这一显式类型。\n\n\n **L667** 提供真实输出契约的依据及过程自身的范围见证,再在同一范围内否定更强契约。\n\n\n **L668** 假定该准确过程范围蕴含更强的输出与解释联合契约。\n\n\n **L669** 在 outputOnlyProcess 自身处实例化假定的完整契约蕴含;其解释部分与已证的解释缺失矛盾。\n\n\n **L670** 说明 ScopedApplicationEvidence 的预定范围。对应声明涉及:要求两个不同应用合同分别具有Grounds及非空精确过程范围。 该注释用于解释,不是证明前提。\n\n\n **L671** 定义 ScopedApplicationEvidence。要求两个不同应用合同分别具有Grounds及非空精确过程范围。\n\n\n **L672** 纳入 outputOnlyProcess 的输出正确性依据。\n\n\n **L673** 纳入 explainedProcess 的输出与解释联合依据。\n\n\n **L674** 对每个候选明确第一个范围准确固定为 outputOnlyProcess。\n\n\n **L675** 同样明确第二个范围准确固定为 explainedProcess。\n\n\n **L676** 要求两个真实过程身份理论均可满足。\n\n\n **L677** 说明 scopedApplicationEvidence 的预定范围。对应声明涉及:提供实际全输入输出证明,并为强合同提供翻倍解释程序。 该注释用于解释,不是证明前提。\n\n\n **L678** 陈述经检查的结果 scopedApplicationEvidence。提供实际全输入输出证明,并为强合同提供翻倍解释程序。 后续策略块证明这一显式类型。\n\n\n **L679** 通过计算构造只输出依据,并留下有解释过程的更强契约证明。\n\n\n **L680** 提供准确的过程身份范围等价关系,并用各过程自身作为其非空范围见证。\n\n\n **L681** 提供准确的过程身份范围等价关系,并用各过程自身作为其非空范围见证。\n\n\n **L682** 对 explainedProcess,通过自反性证明每个加倍输出,并提供实际给出且外延忠实的解释程序 doubleInput。\n\n\n **L683** 说明 outputNotExplanation 的预定范围。对应声明涉及:证明输出正确但无已附解释,并附同对象Grounds及反模型证据。 该注释用于解释,不是证明前提。\n\n\n **L684** 陈述经检查的结果 outputNotExplanation。证明输出正确但无已附解释,并附同对象Grounds及反模型证据。\n\n\n **L685** 保留该过程解释契约缺失及其范围内输出证据。\n\n\n **L686** 组合真实输出正确性、同一过程解释缺失及其匹配的范围内输出证据。\n\n\n **L687** 说明 applicationContractsDiffer 的预定范围。对应声明涉及:证明仅输出不足以满足强合同,解释过程满足两者;两个应用各有对应Grounds。 该注释用于解释,不是证明前提。\n\n\n **L688** 陈述经检查的结果 applicationContractsDiffer。证明仅输出不足以满足强合同,解释过程满足两者;两个应用各有对应Grounds。\n\n\n **L689** 只输出过程满足输出正确性,却未满足输出与解释联合契约。\n\n\n **L690** 有解释过程满足两个真实契约。\n\n\n **L691** 纳入两个应用契约的明确范围内依据与非空见证。\n\n\n **L692** 对 outputOnlyProcess 提供真实输出正确性,并通过提取不可能解释组件反驳任何联合契约。\n\n\n **L693** 对 explainedProcess 计算全部加倍输出,提供忠实 doubleInput 语法,并纳入两个契约匹配的范围内依据。\n\n\n **L694** 说明 ExternalCertificate 的预定范围。对应声明涉及:把输出证明绑定到精确过程及不同评估者、被评者编号;这是数学角色模型,不认证现实出处。 该注释用于解释,不是证明前提。\n\n\n **L695** 声明数据接口 ExternalCertificate。把输出证明绑定到精确过程及不同评估者、被评者编号;这是数学角色模型,不认证现实出处。\n\n\n **L696** 保存外部评估者标识。\n\n\n **L697** 保存受评参与者标识;证书类型已固定受评 Process。\n\n\n **L698** 把参与者标识不同规定为明确证书字段。\n\n\n **L699** 要求同一过程每个输入加倍输出的证明;一般证书假定该字段,具体证书则构造它。\n\n\n **L700** 说明 externalOutputCertificate 的预定范围。对应声明涉及:由实际输出计算构造评估者四十二对被评对象七的证书。 该注释用于解释,不是证明前提。\n\n\n **L701** 定义 externalOutputCertificate。由实际输出计算构造评估者四十二对被评对象七的证书。\n\n\n **L702** 构造参与者 42 与 7,计算其不等,并依真实程序自反性证明每个加倍输出。\n\n\n **L703** 说明 externalAssessment 的预定范围。对应声明涉及:由不同参与者证书提供匹配输出Grounds,而被评过程仍不返回解释。 该注释用于解释,不是证明前提。\n\n\n **L704** 陈述经检查的结果 externalAssessment。由不同参与者证书提供匹配输出Grounds,而被评过程仍不返回解释。\n\n\n **L705** 要求存在以 outputOnlyProcess 为索引的真实外部证书。\n\n\n **L706** 确定其评估者为 42、受评参与者为 7。\n\n\n **L707** 要求两者不同,且同一过程真实输出正确。\n\n\n **L708** 还保留同一输出契约匹配的 ProcessGrounds。\n\n\n **L709** 仍否定该实际过程具有内部解释契约。\n\n\n **L710** 使用真实 externalOutputCertificate,参与者固定为 42 与 7,并带有两者不同的证明。\n\n\n **L711** 从该具体证书提取全称输出正确性,其证明由真实程序构造。\n\n\n **L712** 使用同一具体输出证明,为该 outputOnlyProcess 构造匹配的 ProcessGrounds。\n\n\n **L713** 保留 outputOnlyNoExplanation,因此外部证书不声称存在内部解释。\n\n\n **L714** 说明 arithmeticArticulation 的预定范围。对应声明涉及:取得算术推论面向的规范表达。 该注释用于解释,不是证明前提。\n\n\n **L715** 定义 arithmeticArticulation。取得算术推论面向的规范表达。\n\n\n **L716** 说明 nonExecutableAssessment 的预定范围。对应声明涉及:实际算术根据检查不要求经验测试,同时保留经验面向的观察义务。 该注释用于解释,不是证明前提。\n\n\n **L717** 陈述经检查的结果 nonExecutableAssessment。实际算术根据检查不要求经验测试,同时保留经验面向的观察义务。\n\n\n **L718** 要求仅用 arithmeticFacet,为 n+1=3 提供匹配的规范 Grounds。\n\n\n **L719** 规定该推论方面不使用观测。\n\n\n **L720** 同时纳入确实使用观测且真实已履行的经验方面。\n\n\n **L721** 构造算术主张的非空且覆盖适用性的 Grounds,保留其无观测分类,并纳入有效的观测开关方面。\n\n\n **L722** 单元素成员关系把受评方面固定为 arithmeticFacet,因此检查其具体假设与结论。\n\n\n **L723** 使用同一算术方面已证的履行,配以非空规范表述及其准确语义连接。\n\n\n **L725** 关闭命名空间 CoreReader.Evidence;这不增加证明或前提。\n\n\n### `leanified/CoreReader/Integration.lean`\n\n\n```lean\nimport CoreReader.Agency\nimport CoreReader.Choice\n\nnamespace CoreReader.Integration\nopen CoreReader.Logic CoreReader.Evidence CoreReader.Agency CoreReader.Choice\n\n/- Canonical articulation preserves the actual assessment contents of each facet. -/\ntheorem canonicalGrounds {W : Type} (claim : Claim W) (facets : List (Facet W))\n (hne : facets ≠ []) (checked : ∀ f ∈ facets, f.claim = claim ∧ FacetDischarged f) :\n Grounds claim canonicalArticulation (fun f => f ∈ facets) facets := by\n exact ⟨hne, fun _ h => h, fun f hf =>\n ⟨(checked f hf).1, canonicalArticulated f (checked f hf).2,\n canonicalFacetArticulated f, (checked f hf).2⟩⟩\n\ntheorem canonicalGroundsForSingleton {W : Type} (f : Facet W) (checked : FacetDischarged f) :\n Grounds f.claim canonicalArticulation (fun g => g = f) [f] := by\n refine ⟨by simp, (by intro g hg; cases hg; simp), ?_⟩\n intro g hg\n simp only [List.mem_singleton] at hg\n subst g\n exact ⟨rfl, canonicalArticulated f checked, canonicalFacetArticulated f, checked⟩\n\n/- A mode selects whether a system applies or waives the modeled governance rule. -/\ninductive Mode | apply | waive\n deriving DecidableEq, Repr\n\n/- The four hypotheses vary algorithm and governance independently for the same assessed system. -/\nabbrev World := Candidate × Mode\n\ndef actual : World := (.identity, .apply)\n\n/- A method's form and its possible executable realizations belong to one object. -/\nstructure Method where\n form : Form\n realize : World → Implementation\n\n/- System fields identify the owner, its method, its current principle form, policy and work. -/\nstructure System where\n owner : Nat\n method : Method\n principleForm : Form\n governance : World → Mode\n requirements : Requirements\n\ndef policyFor : Mode → Policy\n | .apply => openPolicy\n | .waive => neutralPolicy\n\ndef workFor (owner : Nat) : Mode → List WorkRecord\n | .apply => completeOwnWork owner\n | .waive => []\n\ndef System.policy (s : System) (w : World) : Policy := policyFor (s.governance w)\ndef System.rules (s : System) (_w : World) : List Principle := ownRules s.owner\ndef System.work (s : System) (w : World) : List WorkRecord := workFor s.owner (s.governance w)\n\ndef actualSystem : System where\n owner := 0\n method := ⟨⟨.method, 0⟩, fun w => implementation w.1⟩\n principleForm := ⟨.principle, 0⟩\n governance := Prod.snd\n requirements := identityRequirements\n\ndef systemCapability (s : System) : Claim World :=\n fun w => ∀ n, s.requirements.inputs n → (s.method.realize w).run n = s.requirements.expected n\n\ndef systemBudget (s : System) : Claim World :=\n fun w => (s.method.realize w).cost ≤ s.requirements.budget\n\ndef systemObservation (s : System) : Record World :=\n ⟨fun w => decide ((s.method.realize w).run 0 = s.requirements.expected 0), true⟩\n\ndef systemHeld (s : System) : Theory World :=\n union (singleton (systemCapability s)) (singleton (systemBudget s))\n\ninductive Question | correctOutput | affordable\n deriving DecidableEq, Repr\n\ndef systemContext (s : System) : Context World Question :=\n ⟨singleton (Compatible [systemObservation s]),\n (fun q => match q with | .correctOutput => systemCapability s | .affordable => systemBudget s),\n fun w => (s.method.realize w).domain 0 ∧ w.2 = .apply⟩\n\nabbrev capability := systemCapability actualSystem\nabbrev observation := systemObservation actualSystem\nabbrev held := systemHeld actualSystem\nabbrev context := systemContext actualSystem\n\n/- The output observation identifies the algorithm, without identifying its independently varied governance mode. -/\ntheorem observationIdentifies (w : World) : Compatible [observation] w ↔ w.1 = .identity := by\n rcases w with ⟨candidate, mode⟩\n cases candidate <;> simp [Compatible, observation, systemObservation, actualSystem,\n implementation, identityRequirements, identityImpl, successorImpl]\n\ntheorem capabilityActual : capability actual := fun _ _ => rfl\n\ntheorem observedCapability : Supports [observation] capability := by\n intro w hw\n have hid := (observationIdentifies w).1 hw\n rcases w with ⟨candidate, mode⟩\n change candidate = .identity at hid\n subst candidate\n exact fun _ _ => rfl\n\ndef capabilityFacet : Facet World := .empirical [observation] (fun _ => True) capability (fun _ => True)\n\ntheorem capabilityFacetChecked : FacetDischarged capabilityFacet := by\n exact ⟨⟨actual, (observationIdentifies actual).2 rfl, trivial⟩,\n (fun w hw _ => observedCapability w hw), fun _ _ => trivial⟩\n\ntheorem capabilityGrounds : Grounds capability canonicalArticulation\n (fun f => f = capabilityFacet) [capabilityFacet] :=\n canonicalGroundsForSingleton capabilityFacet capabilityFacetChecked\n\ntheorem actualAdmissible : Admissible held context actual := by\n refine ⟨(modelsUnion _ _ _).2 ⟨(modelsSingleton _ _).2 capabilityActual,\n (modelsSingleton _ _).2 (by change 1 ≤ 1; decide)⟩,\n (modelsSingleton _ _).2 ((observationIdentifies actual).2 rfl), trivial, rfl⟩\n\ntheorem jointConsistent : Consistent held context :=\n consequenceConsistency held context ⟨actual, actualAdmissible⟩\n\n/- The current method/principle forms, judgments, rules and own work are read from this very system and world. -/\ndef Charter (s : System) (w : World) : Prop :=\n Generative (s.policy w) ∧ Consistent (systemHeld s) (systemContext s) ∧\n Reflexive s.owner (s.rules w) (s.work w) ∧\n (s.policy w).current s.method.form ∧ (s.policy w).current s.principleForm\n\ntheorem charterChecked : Charter actualSystem actual :=\n ⟨⟨Or.inl rfl, fun _ _ => trivial⟩, jointConsistent, completeOwnWork_reflexive 0, rfl, rfl⟩\n\n/- Revision adds a supported input-specific assertion about the same system's realized method. -/\ndef revisedHeld : Theory World := union held\n (singleton (fun w => (actualSystem.method.realize w).run 0 = actualSystem.requirements.expected 0))\n\ndef initialSnapshot : Snapshot World Question := ⟨held, context, 0⟩\ndef revisedSnapshot : Snapshot World Question := ⟨revisedHeld, context, 1⟩\n\ntheorem revisionKeepsConsistency :\n Charter actualSystem actual ∧ Consistent revisedHeld context ∧\n TruthfulReport initialSnapshot revisedSnapshot true ∧\n ¬ TruthfulReport initialSnapshot revisedSnapshot false := by\n refine ⟨charterChecked, consequenceConsistency revisedHeld context ⟨actual,\n (modelsUnion _ _ _).2 ⟨actualAdmissible.1, (modelsSingleton _ _).2 rfl⟩,\n actualAdmissible.2⟩, (fun _ => rfl), ?_⟩\n intro h\n have bad := h (Or.inr (by decide))\n cases bad\n\n/- A claim about this system's method is assessed as its owner's system claim. -/\ndef OwnCapabilityDuty (s : System) (w : World) (facets : List (Facet World)) : Prop :=\n Performed (s.work w) (.system s.owner) .assessment ∧\n Grounds (systemCapability s) canonicalArticulation (fun f => f ∈ facets) facets\n\ntheorem ownCapabilityGrounded :\n OwnCapabilityDuty actualSystem actual [capabilityFacet] ∧ capability actual := by\n refine ⟨⟨?_, ?_⟩, capabilityActual⟩\n · exact ownAssessmentPerformed 0 (.system 0) (by simp [ownSubjects])\n · exact canonicalGrounds capability [capabilityFacet] (by simp)\n (by intro f hf; simp only [List.mem_singleton] at hf; cases hf; exact ⟨rfl, capabilityFacetChecked⟩)\n\n/- This cost observation is true of both algorithms but does not discriminate their output behavior. -/\ndef costAllowanceRecord : Record World :=\n ⟨fun w => decide ((actualSystem.method.realize w).cost ≤ 2), true⟩\n\ndef unsupportedCapabilityFacet : Facet World :=\n .empirical [costAllowanceRecord] (fun _ => True) capability (fun _ => True)\n\ntheorem costCompatibleWithFailure : Compatible [costAllowanceRecord] (.successor, .apply) := by\n intro r hr\n simp only [List.mem_singleton] at hr\n subst r\n rfl\n\ntheorem costDoesNotSupportOutput : ¬ Supports [costAllowanceRecord] capability := by\n intro h\n have bad := h (.successor, .apply) costCompatibleWithFailure 0 trivial\n cases bad\n\ntheorem unsupportedGrounds : ¬ Grounds capability canonicalArticulation\n (fun f => f = unsupportedCapabilityFacet) [unsupportedCapabilityFacet] := by\n intro h\n have discharged := (h.2.2 unsupportedCapabilityFacet (by simp)).2.2.2\n exact costDoesNotSupportOutput (fun w hw => discharged.2.1 w hw trivial)\n\n/- Five separately adopted requirements govern distinct operations; the mode does not give them priority over one another. -/\ninductive Commitment | generation | consistency | reflexivity | grounds | choice\n deriving DecidableEq, Repr\n\n/- A Grounds policy governs arbitrary claims, articulations and applicable facets, rather than only one capability claim. -/\ndef groundsPermission (mode : Mode) (claim : Claim World) (a : Facet World → Articulation World)\n (applicable : Facet World → Prop) (facets : List (Facet World)) : Prop :=\n match mode with\n | .apply => Grounds claim a applicable facets\n | .waive => True\n\ndef GroundsProvision (mode : Mode) : Prop :=\n ∀ claim a applicable facets, groundsPermission mode claim a applicable facets →\n Grounds claim a applicable facets\n\ntheorem groundsProvisionMeaning (mode : Mode) : GroundsProvision mode ↔ mode = .apply := by\n cases mode with\n | apply => exact ⟨fun _ => rfl, fun _ _ _ _ _ h => h⟩\n | waive =>\n constructor\n · intro h\n exact False.elim (unsupportedGrounds (h capability canonicalArticulation\n (fun f => f = unsupportedCapabilityFacet) [unsupportedCapabilityFacet] trivial))\n · intro h; cases h\n\n/- The consistency policy checks a whole same-context theory, not isolated judgments. -/\ndef consistencyPermission (mode : Mode) (t : Theory World) (c : Context World Question) : Prop :=\n match mode with | .apply => Consistent t c | .waive => True\n\ndef conflictingHeld : Theory World := union (singleton capability) (singleton (fun w => ¬ capability w))\n\ntheorem conflictConsequences :\n Consequence conflictingHeld context .correctOutput true ∧\n Consequence conflictingHeld context .correctOutput false := by\n exact ⟨fun w hw => hw.1 capability (Or.inl rfl),\n fun w hw => hw.1 (fun w => ¬ capability w) (Or.inr rfl)⟩\n\ntheorem conflictingHeldInconsistent : ¬ Consistent conflictingHeld context :=\n conflictRequiresChange conflictingHeld context .correctOutput conflictConsequences.1 conflictConsequences.2\n\n/- The selection policy applies the actual output/budget and relevant-reason conditions to every implementation. -/\ndef choicePermission (mode : Mode) (req : Requirements) (i : Implementation) (reasons : List Reason) : Prop :=\n match mode with | .apply => JustifiedChoice req i reasons | .waive => True\n\n/- The following consequences are computed from distinct rule applications; they are not interchangeable support flags. -/\ndef proposedOperation : Mode → Operation\n | .apply => .successor\n | .waive => .copy\n\ndef selfSamples : Mode → List Nat\n | .apply => [0, 1]\n | .waive => [1]\n\nnoncomputable def conflictDecision (mode : Mode) : Bool :=\n @decide (consistencyPermission mode conflictingHeld context) (Classical.propDecidable _)\n\nnoncomputable def groundsDecision (mode : Mode) (facet : Facet World) : Bool :=\n @decide (groundsPermission mode facet.claim canonicalArticulation (fun f => f = facet) [facet])\n (Classical.propDecidable _)\n\nnoncomputable def choiceDecision (mode : Mode) (i : Implementation) (reasons : List Reason) : Bool :=\n @decide (choicePermission mode identityRequirements i reasons) (Classical.propDecidable _)\n\ntheorem decisionsApply : conflictDecision .apply = false ∧\n groundsDecision .apply unsupportedCapabilityFacet = false ∧\n groundsDecision .apply capabilityFacet = true ∧\n choiceDecision .apply cheapSuccessor [.method .simplicity] = false ∧\n choiceDecision .apply identityImpl objectiveReason = true := by\n classical\n simp only [conflictDecision, groundsDecision, choiceDecision, consistencyPermission,\n groundsPermission, choicePermission]\n exact ⟨decide_eq_false conflictingHeldInconsistent,\n decide_eq_false unsupportedGrounds, decide_eq_true capabilityGrounds,\n decide_eq_false eligibleInternalReasonNotSufficient.2, decide_eq_true identityJustified⟩\n\ntheorem decisionsWaive : conflictDecision .waive = true ∧\n groundsDecision .waive unsupportedCapabilityFacet = true ∧\n choiceDecision .waive cheapSuccessor [.method .simplicity] = true := by\n exact ⟨@decide_eq_true (consistencyPermission .waive conflictingHeld context)\n (Classical.propDecidable _) trivial,\n @decide_eq_true (groundsPermission .waive unsupportedCapabilityFacet.claim canonicalArticulation\n (fun f => f = unsupportedCapabilityFacet) [unsupportedCapabilityFacet]) (Classical.propDecidable _) trivial,\n @decide_eq_true (choicePermission .waive identityRequirements cheapSuccessor [.method .simplicity])\n (Classical.propDecidable _) trivial⟩\n\n/- Each application supplies its own outcome type, adopted objective, constraints and actual option-indexed reasons. -/\nnoncomputable def commitmentPositionFor (c : Commitment) (chosenMode : Mode) : ValuePosition World :=\n match c with\n | .generation => {\n Position := Mode, Outcome := Operation, adopted := chosenMode, selected := actualSystem.governance,\n outcome := fun _ mode => proposedOperation mode,\n objective := fun op => op.run 0 ≠ Operation.copy.run 0,\n constraints := fun _ mode => Generative (policyFor mode),\n starting := singleton (fun w => actualSystem.governance w = chosenMode),\n reasons := [fun _ mode => (proposedOperation mode).run 0 = 1 ∧ Operation.copy.run 0 = 0],\n limits := fun w => w.1 = .identity,\n relevantCriticism := fun _ => ¬ Expanded baseState inflatedState,\n response := fun _ => some \"Pursuing expansion does not guarantee it; assess the actual before and after capabilities separately\" }\n | .consistency => {\n Position := Mode, Outcome := Bool, adopted := chosenMode, selected := actualSystem.governance,\n outcome := fun _ mode => conflictDecision mode,\n objective := fun accepted => accepted = false,\n constraints := fun _ mode => consistencyPermission mode held context,\n starting := singleton (fun w => actualSystem.governance w = chosenMode),\n reasons := [fun _ _ => Consequence conflictingHeld context .correctOutput true ∧\n Consequence conflictingHeld context .correctOutput false],\n limits := fun w => w.1 = .identity,\n relevantCriticism := fun _ => ¬ Entails (emptyTheory : Theory Bool) (fun w => w = true),\n response := fun _ => some \"Consistency alone does not establish sufficient support; assess the claim with its grounds as well\" }\n | .reflexivity => {\n Position := Mode, Outcome := List Nat, adopted := chosenMode, selected := actualSystem.governance,\n outcome := fun _ mode => selfSamples mode,\n objective := fun samples => ∃ n ∈ samples, ownArithmeticPrinciple n = false,\n constraints := fun _ mode => Reflexive 0 (ownRules 0) (workFor 0 mode),\n starting := singleton (fun w => actualSystem.governance w = chosenMode),\n reasons := [fun _ _ => ownArithmeticPrinciple 0 = false ∧ ownArithmeticPrinciple 1 = true],\n limits := fun w => w.1 = .identity,\n relevantCriticism := fun _ => selfTest [1] = true ∧ ownArithmeticPrinciple 0 = false,\n response := fun _ => some \"A passing self-test does not certify the principle; retain the relevant counterexample and its scope\" }\n | .grounds => {\n Position := Mode, Outcome := Bool, adopted := chosenMode, selected := actualSystem.governance,\n outcome := fun _ mode => groundsDecision mode unsupportedCapabilityFacet,\n objective := fun accepted => accepted = false,\n constraints := fun _ mode => groundsPermission mode capability canonicalArticulation\n (fun f => f = capabilityFacet) [capabilityFacet],\n starting := singleton (fun w => actualSystem.governance w = chosenMode),\n reasons := [fun _ _ => Compatible [costAllowanceRecord] (.successor, .apply) ∧\n ¬ capability (.successor, .apply)],\n limits := fun w => w.1 = .identity,\n relevantCriticism := fun _ => OutputContract outputOnlyProcess ∧ ¬ ExplanationContract outputOnlyProcess,\n response := fun _ => some \"Grounds allows an external output assessment without requiring this process to provide an internal explanation\" }\n | .choice => {\n Position := Mode, Outcome := Bool, adopted := chosenMode, selected := actualSystem.governance,\n outcome := fun _ mode => choiceDecision mode cheapSuccessor [.method .simplicity],\n objective := fun accepted => accepted = false,\n constraints := fun _ mode => choicePermission mode identityRequirements identityImpl objectiveReason,\n starting := singleton (fun w => actualSystem.governance w = chosenMode),\n reasons := [fun _ _ => cheapSuccessor.run 0 = 1 ∧ identityRequirements.expected 0 = 0 ∧\n cheapSuccessor.cost ≤ identityRequirements.budget],\n limits := fun w => w.1 = .identity,\n relevantCriticism := fun _ => identityImpl.conventional = true ∧ identityImpl.established = true,\n response := fun _ => some \"An existing conventional method remains eligible when actual output and budget reasons justify it\" }\n\nnoncomputable def commitmentPosition (c : Commitment) : ValuePosition World := commitmentPositionFor c .apply\n\n/- The fact used as a reason has content before evaluating the adopted rule's consequence. -/\ntheorem positionReasons (c : Commitment) :\n ∀ r ∈ (commitmentPosition c).reasons, r actual (commitmentPosition c).adopted := by\n cases c <;> intro r hr <;> dsimp [commitmentPosition, commitmentPositionFor] at hr ⊢ <;>\n rcases List.mem_singleton.mp hr with rfl\n · exact ⟨rfl, rfl⟩\n · exact conflictConsequences\n · exact ⟨rfl, rfl⟩\n · refine ⟨costCompatibleWithFailure, ?_⟩\n intro h\n have bad := h 0 trivial\n cases bad\n · exact ⟨rfl, rfl, by decide⟩\n\n/- Each adopted rule has its stated consequence in this explicitly defined application; this is not ultimate value justification. -/\ntheorem positionConsequence (c : Commitment) (w : World) : (commitmentPosition c).consequence w := by\n cases c <;> dsimp [commitmentPosition, commitmentPositionFor, ValuePosition.consequence]\n · exact ⟨by decide, ⟨Or.inl rfl, fun _ _ => trivial⟩⟩\n · exact ⟨decisionsApply.1, jointConsistent⟩\n · exact ⟨⟨0, by simp [selfSamples], rfl⟩, completeOwnWork_reflexive 0⟩\n · exact ⟨decisionsApply.2.1, capabilityGrounds⟩\n · exact ⟨decisionsApply.2.2.2.1, identityJustified⟩\n\ntheorem positionProcedure (c : Commitment) : ValueProcedure (commitmentPosition c) := by\n refine ⟨?_, ?_, ?_, ?_⟩\n · cases c <;> simp [commitmentPosition, commitmentPositionFor]\n · refine ⟨actual, ?_, ?_, ?_, positionReasons c⟩\n · cases c <;> exact (modelsSingleton _ _).2 rfl\n · cases c <;> rfl\n · cases c <;> rfl\n · intro w _ _ _\n exact positionConsequence c w\n · intro w _ _\n cases c <;> exact ⟨_, rfl, by decide⟩\n\n/- Criticism is instantiated within the adopted position's actual limit rather than made vacuous. -/\ntheorem criticismWithinScope (c : Commitment) :\n (commitmentPosition c).limits actual ∧ (commitmentPosition c).relevantCriticism actual := by\n constructor\n · cases c <;> rfl\n · cases c\n · simp [commitmentPosition, commitmentPositionFor, Expanded, baseState, inflatedState]\n · exact consistentIncomplete.2.1\n · exact ⟨rfl, rfl⟩\n · exact ⟨outputNotExplanation.1, outputNotExplanation.2.1⟩\n · exact ⟨rfl, rfl⟩\n\n/- Waiving the rule changes the actual computed outcome or an explicit adopted constraint; old reasons cannot certify it unchanged. -/\ntheorem oppositeConsequenceFails (c : Commitment) (w : World) :\n ¬ (commitmentPositionFor c .waive).consequence w := by\n cases c <;> intro h\n · exact permissionNotValuation.2.2 h.2\n · have bad : conflictDecision .waive = false := h.1\n rw [decisionsWaive.1] at bad\n cases bad\n · obtain ⟨n, hn, hf⟩ := h.1\n change n ∈ [1] at hn\n have he : n = 1 := List.mem_singleton.mp hn\n subst n\n cases hf\n · have bad : groundsDecision .waive unsupportedCapabilityFacet = false := h.1\n rw [decisionsWaive.2.1] at bad\n cases bad\n · have bad : choiceDecision .waive cheapSuccessor [.method .simplicity] = false := h.1\n rw [decisionsWaive.2.2] at bad\n cases bad\n\ntheorem oppositeProcedureRejected (c : Commitment) : ¬ ValueProcedure (commitmentPositionFor c .waive) := by\n intro h\n obtain ⟨w, hs, hl, _, hr⟩ := h.2.1\n exact oppositeConsequenceFails c w (h.2.2.1 w hs hl hr)\n\n/- Each statement names adoption of a particular rule; its defined policy gives that option its meaning. -/\nnoncomputable def commitmentClaim (c : Commitment) : Claim World := (commitmentPosition c).commitment\n\nnoncomputable def commitmentFacet (c : Commitment) : Facet World := .value (commitmentPosition c)\n\ntheorem reasonsBelongToCommitments (c : Commitment) :\n Grounds (commitmentClaim c) canonicalArticulation\n (fun f => f = commitmentFacet c) [commitmentFacet c] ∧\n JointAdoption (commitmentPosition c) ∧\n (commitmentPosition c).relevantCriticism actual ∧\n ¬ ValueProcedure (commitmentPositionFor c .waive) := by\n exact ⟨canonicalGroundsForSingleton (commitmentFacet c) (positionProcedure c),\n (positionProcedure c).2.1, (criticismWithinScope c).2, oppositeProcedureRejected c⟩\n\n/- This claim concerns the Grounds rule for arbitrary claim/facet packages, not a single capability duty. -/\ntheorem groundsCommitmentIsProvision : commitmentClaim .grounds = (fun w => GroundsProvision w.2) := by\n funext w\n apply propext\n exact (groundsProvisionMeaning w.2).symm\n\ntheorem groundsSelfAssessment :\n Grounds (fun w => GroundsProvision w.2) canonicalArticulation\n (fun f => f = commitmentFacet .grounds) [commitmentFacet .grounds] ∧\n (commitmentPosition .grounds).limits actual ∧\n (commitmentPosition .grounds).relevantCriticism actual ∧\n ¬ ValueProcedure (commitmentPositionFor .grounds .waive) := by\n rw [← groundsCommitmentIsProvision]\n exact ⟨(reasonsBelongToCommitments .grounds).1,\n (criticismWithinScope .grounds).1, (criticismWithinScope .grounds).2,\n oppositeProcedureRejected .grounds⟩\n\n/- This existing principle form implements the same system's choice rule on two actual proposals.\nInput 0 names the identity proposal; input 1 names the cheap successor proposal. -/\nstructure PhilosophyMethod where\n form : Form\n mode : Mode\n\ndef currentPhilosophy (s : System) (w : World) : PhilosophyMethod :=\n ⟨s.principleForm, s.governance w⟩\n\nnoncomputable def PhilosophyMethod.review (p : PhilosophyMethod) (input : Nat) : Nat :=\n if input = 0 then\n if choiceDecision p.mode identityImpl objectiveReason then 1 else 0\n else if choiceDecision p.mode cheapSuccessor [.method .simplicity] then 1 else 0\n\nnoncomputable def PhilosophyMethod.implementation (p : PhilosophyMethod) : Implementation where\n name := \"Current philosophy's proposal review\"\n conventional := true\n established := true\n run := p.review\n cost := 1\n domain n := n = 0 ∨ n = 1\n explanation := p.review\n trace n := [n, p.review n]\n\ndef proposalRequirements : Requirements where\n inputs n := n = 0 ∨ n = 1\n expected n := if n = 0 then 1 else 0\n budget := 1\n values _ := True\n\ntheorem currentReviewCorrect : ∀ n, proposalRequirements.inputs n →\n (currentPhilosophy actualSystem actual).review n = proposalRequirements.expected n := by\n intro n hn\n rcases hn with rfl | rfl <;>\n simp [PhilosophyMethod.review, currentPhilosophy, actualSystem, actual,\n proposalRequirements, decisionsApply.2.2.2.1, decisionsApply.2.2.2.2]\n\n/- Status alone fails for this actual principle method; its demonstrated proposal decisions give a relevant reason. -/\ntheorem existingPhilosophyNotPrivileged :\n (currentPhilosophy actualSystem actual).form = actualSystem.principleForm ∧\n (currentPhilosophy actualSystem actual).mode = actualSystem.governance actual ∧\n ¬ JustifiedChoice proposalRequirements\n (currentPhilosophy actualSystem actual).implementation [.status .standing] ∧\n JustifiedChoice proposalRequirements\n (currentPhilosophy actualSystem actual).implementation [.method .output] ∧\n (currentPhilosophy actualSystem actual).review 0 = 1 ∧\n (currentPhilosophy actualSystem actual).review 1 = 0 := by\n refine ⟨rfl, rfl, statusOnlyFails _ _ _, ?_, currentReviewCorrect 0 (Or.inl rfl),\n currentReviewCorrect 1 (Or.inr rfl)⟩\n exact ⟨⟨currentReviewCorrect, by change 1 ≤ 1; decide⟩,\n .method .output, by simp, trivial, currentReviewCorrect⟩\n\n/- Applications choose their contract and requirements; the resulting claim is about this system's actual method. -/\ndef applicationClaim (s : System) (req : Requirements)\n (contract : Requirements → Implementation → Prop) : Claim World :=\n fun w => contract req (s.method.realize w)\n\ndef ApplicationDuties (s : System) (w : World) (req : Requirements)\n (contract : Requirements → Implementation → Prop)\n (articulations : Facet World → Articulation World)\n (applicable : Facet World → Prop) (facets : List (Facet World)) : Prop :=\n Reflexive s.owner (s.rules w) (s.work w) ∧\n Grounds (applicationClaim s req contract) articulations applicable facets\n\n/- These are consequences of an explicitly adopted duty, not a proof that arbitrary applications fulfill it. -/\ntheorem applicationRetainsDuties (s : System) (w : World) (req : Requirements)\n (contract : Requirements → Implementation → Prop)\n (articulations : Facet World → Articulation World)\n (applicable : Facet World → Prop) (facets : List (Facet World))\n (h : ApplicationDuties s w req contract articulations applicable facets) :\n Reflexive s.owner (s.rules w) (s.work w) ∧\n (∀ f, applicable f → f ∈ facets) ∧\n (∀ f ∈ facets, f.claim = applicationClaim s req contract ∧\n Articulated (articulations f) ∧ FacetArticulated (articulations f) f ∧ FacetDischarged f) :=\n ⟨h.1, h.2.2.1, h.2.2.2⟩\n\ndef outputContract (req : Requirements) (i : Implementation) : Prop :=\n ∀ n, req.inputs n → i.run n = req.expected n\n\ndef successorRequirements : Requirements :=\n { identityRequirements with expected := fun n => n + 1 }\n\n/- Holding the system and observation fixed while changing the actual objective changes the capability claim. -/\ndef changedObjectiveFacet : Facet World :=\n .empirical [observation] (fun _ => True)\n (applicationClaim actualSystem successorRequirements outputContract) (fun _ => True)\n\ntheorem applicationVariation :\n ApplicationDuties actualSystem actual identityRequirements outputContract\n canonicalArticulation (fun f => f = capabilityFacet) [capabilityFacet] ∧\n ¬ applicationClaim actualSystem successorRequirements outputContract actual ∧\n ¬ Grounds (applicationClaim actualSystem successorRequirements outputContract)\n canonicalArticulation (fun f => f = changedObjectiveFacet) [changedObjectiveFacet] := by\n refine ⟨⟨completeOwnWork_reflexive 0, capabilityGrounds⟩, ?_, ?_⟩\n · intro h\n have bad := h 0 trivial\n cases bad\n · intro h\n have discharged := (h.2.2 changedObjectiveFacet (by simp)).2.2.2\n have bad := discharged.2.1 actual ((observationIdentifies actual).2 rfl) trivial 0 trivial\n cases bad\n\n/- The very system satisfies the charter while its true cost evidence fails to establish its output capability. -/\ntheorem charterNotGrounds :\n Charter actualSystem actual ∧\n Compatible [costAllowanceRecord] actual ∧\n ¬ Grounds capability canonicalArticulation\n (fun f => f = unsupportedCapabilityFacet) [unsupportedCapabilityFacet] := by\n exact ⟨charterChecked, (by intro r hr; cases List.mem_singleton.mp hr; rfl), unsupportedGrounds⟩\n\n/- A single inhabited system/context carries the charter, its own actual claim and support,\ncontentful principle work, and separately reasoned governance commitments. -/\ntheorem jointWitness :\n ∃ s : System, ∃ w : World,\n Admissible (systemHeld s) (systemContext s) w ∧ Charter s w ∧\n OwnCapabilityDuty s w [capabilityFacet] ∧ systemCapability s w ∧\n JustifiedChoice s.requirements (s.method.realize w) objectiveReason ∧\n (∀ c : Commitment, Grounds (commitmentClaim c) canonicalArticulation\n (fun f => f = commitmentFacet c) [commitmentFacet c]) ∧\n s = actualSystem ∧ w = actual := by\n exact ⟨actualSystem, actual, actualAdmissible, charterChecked,\n ownCapabilityGrounded.1, capabilityActual, identityJustified,\n fun c => (reasonsBelongToCommitments c).1, rfl, rfl⟩\n\nend CoreReader.Integration\n```\n\n\n\n **L1** 导入CoreReader.Agency及其依赖。\n\n\n **L2** 导入CoreReader.Choice及其依赖。\n\n\n **L4** 打开命名空间CoreReader.Integration;文件边界不改变声明身份。\n\n\n **L5** 使列出的命名空间可通过省略前缀的名称引用。\n\n\n **L7** 说明后续定义或结果:从同一主张的已检查非空面向清单构造规范表达及Grounds;适用性按清单成员定义。\n\n\n **L8** 从同一主张的已检查非空面向清单构造规范表达及Grounds;适用性按清单成员定义。\n\n\n **L9** 假设方面列表非空,且每个方面都针对claim并已履责。\n\n\n **L10** 用各方面自身内容构造的表述建立Grounds,以列表成员关系作为适用谓词。\n\n\n **L11** 提供非空性及按成员定义直接成立的覆盖,再逐个检查列表方面。\n\n\n **L12** 对每个方面,用checked确立同一主张,并由履责得到非空表述。\n\n\n **L13** 补上该表述的确切内容对应及已给履责证明。\n\n\n **L15** 对单个已检查面向构造Grounds,适用性只限于该面向本身。\n\n\n **L16** 对单个已履责方面,使恰好该方面对其自身主张适用。\n\n\n **L17** 证明单项列表非空,且每个等于f的方面都在其中,留下逐方面内容检查。\n\n\n **L18** 取已知属于单项列表[f]的任意方面g。\n\n\n **L19** 单项成员关系把hg化为等式g=f。\n\n\n **L20** 把g替换为同一个已履责方面f。\n\n\n **L21** 用相同主张、构造表述的可表达性、确切方面内容匹配及checked履责完成Grounds字段。\n\n\n **L23** 说明后续定义或结果:区分执行模型标准与豁免标准两种模式,它们决定实际政策判断。\n\n\n **L24** 区分执行模型标准与豁免标准两种模式,它们决定实际政策判断。\n\n\n **L25** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L27** 说明后续定义或结果:世界由两个候选实现之一及两个治理模式之一组成,是封闭四世界模型。\n\n\n **L28** 世界由两个候选实现之一及两个治理模式之一组成,是封闭四世界模型。\n\n\n **L30** 指定恒等实现和执行标准模式作为实际世界。\n\n\n **L32** 说明后续定义或结果:把可修订形式身份与依赖世界的实际实现绑定。\n\n\n **L33** 把方法形式的种类与版本绑定到随世界变化的实现;仅此结构不证明该形式可修订。\n\n\n **L34** 保存该方法的形式种类与版本。\n\n\n **L35** 为每个候选与治理世界指定该同一方法的实际实现。\n\n\n **L37** 说明后续定义或结果:把主体、方法、原则形式、治理选择和应用要求绑定成系统。\n\n\n **L38** 把主体、方法、原则形式、治理选择和应用要求绑定成系统。\n\n\n **L39** 标识该系统采用其原则与工作记录的所有者。\n\n\n **L40** 保存系统的方法形式及随世界变化的实现。\n\n\n **L41** 保存系统自身原则的当前形式。\n\n\n **L42** 选择该系统在各世界采用还是豁免治理要求。\n\n\n **L43** 固定用于评估该系统实现的输入、输出、预算和价值要求。\n\n\n **L45** 执行模式使用开放政策,豁免模式使用无扩展价值的政策。\n\n\n **L46** 采用治理时选择重视扩展且允许修订的openPolicy。\n\n\n **L47** 豁免治理时选择缺少所需扩展价值取向的neutralPolicy。\n\n\n **L49** 执行模式提供内容已检查的自身工作记录,豁免模式不提供记录。\n\n\n **L50** 采用治理时,为此所有者提供完整内容性工作日志。\n\n\n **L51** 豁免治理时,同一所有者的工作日志为空。\n\n\n **L53** 按同一系统的治理选择决定政策。\n\n\n **L54** 使用属于该系统主体的登记生成及评估规则。\n\n\n **L55** 按该主体治理模式选取实际工作记录清单。\n\n\n **L57** 构造主体零、版本零方法及原则、依候选实现、依世界治理和恒等要求的实际系统。\n\n\n **L58** 给共享实际系统分配所有者0。\n\n\n **L59** 使用版本0的方法形式,由世界的候选分量选择其实例实现。\n\n\n **L60** 把该系统当前原则形式设为原则版本0。\n\n\n **L61** 从世界第二分量读取治理方式,与实现候选独立。\n\n\n **L62** 用identityRequirements评估同一方法。\n\n\n **L64** 要求该系统实际方法在自身请求输入上满足自身期望输出。\n\n\n **L65** 声称该系统实现的方法在每个必需输入上满足指定输出。\n\n\n **L67** 按该系统预算检查同一实际实现的成本。\n\n\n **L68** 声称同一实现方法的成本满足该系统自身预算。\n\n\n **L70** 记录该系统实际实现是否在零输入满足其期望输出。\n\n\n **L71** 记录测试为true:同一方法在0处的输出等于该处所需输出。\n\n\n **L73** 同时持有同一系统的能力与预算主张。\n\n\n **L74** 系统同时持有实际输出能力主张和预算主张。\n\n\n **L76** 定义上下文使用的输出正确与成本可承担两个问题。\n\n\n **L77** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L79** 以同系统观察为假设、能力及预算为含义;范围要求零在域内且采用执行模式。\n\n\n **L80** 情境假设与该系统实际0输入观察相容。\n\n\n **L81** 把correctOutput解释为该系统能力,把affordable解释为预算满足。\n\n\n **L82** 把可容许范围限于定义域包含0且采用治理的世界。\n\n\n **L84** 简写实际系统的参数化输出能力主张。\n\n\n **L85** 简写实际系统的零输入观察记录。\n\n\n **L86** 简写实际系统同时持有的能力与预算理论。\n\n\n **L87** 简写实际系统的问题、假设与范围上下文。\n\n\n **L89** 说明后续定义或结果:计算零点观察只识别恒等候选,而不限制治理模式。\n\n\n **L90** 计算零点观察只识别恒等候选,而不限制治理模式。\n\n\n **L91** 把候选算法与独立变化的治理模式分开。\n\n\n **L92** 逐一检查两个实际候选是否符合观察中的0输出测试为真。\n\n\n **L93** identity返回所需0而successor返回1,因此只有identity匹配,与治理方式无关。\n\n\n **L95** 通过约简证明实际恒等实现满足每个请求的恒等输出。\n\n\n **L97** 在封闭模型中,由候选识别和已知恒等行为得到全请求输入能力。\n\n\n **L98** 取与同一观察相容的任意世界。\n\n\n **L99** 用observationIdentifies推出该世界算法候选是identity。\n\n\n **L100** 分离世界的算法和治理分量以便替换。\n\n\n **L101** 把推出的identity等式直接改述为候选变量的等式。\n\n\n **L102** 把候选算法换成identity,保留其治理模式。\n\n\n **L103** 按定义,identity在每个输入上的运行等于所需输出,故证明此世界能力。\n\n\n **L105** 把实际观察及能力主张组成经验面向,范围不限、不确定性条件恒真。\n\n\n **L107** 提供实际兼容见证、封闭模型支持证明及平凡不确定性条件。\n\n\n **L108** 以actual作为方面无限制范围内的相容世界,避免空世界履责。\n\n\n **L109** 用observedCapability证明每个相容世界的支持;所述不确定性条件为平凡真。\n\n\n **L111** 为精确对应的能力面向构造规范Grounds。\n\n\n **L112** 只令实际输出能力方面适用,使用其自身单项证据包。\n\n\n **L113** 把单项Grounds构造应用于已经履责的能力方面。\n\n\n **L115** 证明实际恒等执行世界同时满足能力、预算、观察假设以及治理和输入域范围。\n\n\n **L116** 构造实际世界可容许见证,先证明共同持有的两项主张;能力项使用capabilityActual。\n\n\n **L117** 所持预算主张计算为实际成本1满足预算1。\n\n\n **L118** 补上与0处观察相容、0属于定义域以及actual采用apply模式。\n\n\n **L120** 从已证明的实际可接受世界推出一致性。\n\n\n **L121** 以actual及其可容许证明作为必需非空见证,应用语义后果一致性定理。\n\n\n **L123** 说明后续定义或结果:组合该系统生成政策、上下文一致性、完整内容有效反身性及当前方法和原则形式。\n\n\n **L124** 组合该系统生成政策、上下文一致性、完整内容有效反身性及当前方法和原则形式。\n\n\n **L125** Charter要求该系统实际政策具有生成取向,且共同持有判断在情境内一致。\n\n\n **L126** 它还要求该系统实际工作日志满足完整自有规则反身要求。\n\n\n **L127** 方法形式与原则形式均须在同一政策下属于当前形式。\n\n\n **L129** 组合开放政策计算结果、实际一致性和内容已验证自身工作模型。\n\n\n **L130** 组合openPolicy价值取向与可修订性、jointConsistent、完整自有日志及两个当前版本0形式。\n\n\n **L132** 说明后续定义或结果:在原持有理论中增加同系统零输入输出事实。\n\n\n **L133** 在原持有理论中增加同系统零输入输出事实。\n\n\n **L134** 增加具体断言:同一方法在输入0处满足所需输出。\n\n\n **L136** 以修订标识零保存实际理论及上下文。\n\n\n **L137** 以同一上下文和标识一保存扩充理论。\n\n\n **L139** 增加事实后保留同一章程和可接受模型,并要求如实报告修订。\n\n\n **L140** 实际系统保留Charter,增加该有支持断言后revisedHeld仍一致。\n\n\n **L141** 把已识别修订报告为true,满足单向变化报告条件。\n\n\n **L142** 把同一修订报告为false,违反该条件。\n\n\n **L143** 保留charterChecked,以actual作为具体可容许见证证明修订后一致性。\n\n\n **L144** actual满足原所持主张及新增0输入输出断言。\n\n\n **L145** 保留actual既有情境与范围证明,并验证true报告,仅余拒绝false报告。\n\n\n **L146** 假设变化后的快照能以report=false满足TruthfulReport。\n\n\n **L147** 修订编号0和1不同,因此假设的义务迫使false=true。\n\n\n **L148** 排除不可能的布尔等式,拒绝隐瞒修订。\n\n\n **L150** 说明后续定义或结果:要求该系统评估记录及其自身能力主张的匹配Grounds。\n\n\n **L151** 要求该系统评估记录及其自身能力主张的匹配Grounds。\n\n\n **L152** OwnCapabilityDuty首先要求实际评估记录针对与系统所有者一致的系统对象。\n\n\n **L153** 还要求全部所列适用方面为该系统输出能力提供同主张Grounds。\n\n\n **L155** 组合实际内容有效自身评估记录、观察支持能力Grounds及能力结论。\n\n\n **L156** 陈述实际系统自身能力义务已履行,且其声称能力实际成立。\n\n\n **L157** 直接提供capabilityActual,留下系统评估记录与对应Grounds。\n\n\n **L158** 以完整日志对系统0的评估作为自有系统工作见证。\n\n\n **L159** 从非空单项能力方面列表构造Grounds。\n\n\n **L160** 单项列表唯一方面具有确切目标主张及已证履责。\n\n\n **L162** 说明后续定义或结果:记录同系统实现成本至多二;两个候选均通过。\n\n\n **L163** 记录同系统实现成本至多二;两个候选均通过。\n\n\n **L164** 记录实现成本至多2;两个算法候选都满足这个较弱成本观察。\n\n\n **L166** 试图只凭宽松成本观察支持同一输出能力。\n\n\n **L167** 尝试仅以成本证据支持输出能力,不另加限制范围或不确定性条件。\n\n\n **L169** 计算后继执行世界符合成本观察,却不满足恒等输出。\n\n\n **L170** 取单项成本观察列表中的一条记录。\n\n\n **L171** 单项成员关系确认该记录就是costAllowanceRecord。\n\n\n **L172** 把r替换为实际成本记录。\n\n\n **L173** successor成本为2,因此记录的至多2观察计算为true。\n\n\n **L175** 把假定支持应用于兼容后继反世界及零输入,导出矛盾。\n\n\n **L176** 假设成本观察在每个相容世界都支持输出能力。\n\n\n **L177** 将假设应用于相容successor世界及输入0,得到错误等式1=0。\n\n\n **L178** 排除不可能的输出等式,反驳仅成本支持。\n\n\n **L180** 从假定Grounds抽取错误面向支持义务,并由成本反模型否定。\n\n\n **L181** 检验使该仅成本能力方面适用的单项证据包。\n\n\n **L182** 假设这个不足的单项证据包仍满足Grounds。\n\n\n **L183** 从Grounds前提提取实际仅成本能力方面的FacetDischarged。\n\n\n **L184** 其支持条款会推出仅成本Supports,与costDoesNotSupportOutput矛盾。\n\n\n **L186** 说明后续定义或结果:标识五项治理承诺,每项有分别解释的理由与结果。\n\n\n **L187** 标识五项治理承诺,每项有分别解释的理由与结果。\n\n\n **L188** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L190** 说明后续定义或结果:执行模式仅许可Grounds成立的主张包,豁免模式许可所有包。\n\n\n **L191** 执行模式仅许可Grounds成立的主张包,豁免模式许可所有包。\n\n\n **L192** 接收针对同一主张与表述的任意适用谓词和方面包。\n\n\n **L193** 按治理模式选择许可规则。\n\n\n **L194** apply模式只许可实际满足Grounds的证据包。\n\n\n **L195** waive模式不检查Grounds,许可所有证据包。\n\n\n **L197** 表达一般规范:所有获许可的主张、表达、适用面与清单组合都必须具有Grounds。\n\n\n **L198** 对任意实际主张、表述族和方面包,条款约束该模式许可的所有包。\n\n\n **L199** 每个被许可包都必须满足其自身对应Grounds义务。\n\n\n **L201** 证明执行模式履行一般规范,而具体无支持成本包反驳豁免模式。\n\n\n **L202** 分别检查apply与waive模式的一般条款。\n\n\n **L203** apply模式的许可本就是Grounds,因此返回已给证明即可满足一般条款。\n\n\n **L204** 对waive模式,需要证明无限制许可违反一般条款。\n\n\n **L205** 证明waive模式下两侧均不成立的等价关系两个方向。\n\n\n **L206** 假设该模式豁免检查时一般条款仍成立。\n\n\n **L207** 把该普遍假设应用于实际不足的能力证据包,将与unsupportedGrounds矛盾。\n\n\n **L208** 提供确切单项适用谓词和包;豁免许可为真,迫出无效Grounds结果。\n\n\n **L209** 反向蕴涵以前提waive=apply开始,这是不可能的构造器等式。\n\n\n **L211** 说明后续定义或结果:执行模式要求拟议理论和上下文一致,豁免模式无条件许可。\n\n\n **L212** 执行模式要求拟议理论和上下文一致,豁免模式无条件许可。\n\n\n **L213** apply要求整个理论在情境内一致;waive不施加该约束。\n\n\n **L215** 在同一理论中组合实际能力主张及其否定。\n\n\n **L217** 从同时持有的相反主张中抽取能力正反后果。\n\n\n **L218** 冲突的所持理论在固定情境下蕴涵输出正确的正判断。\n\n\n **L219** 同一理论和情境也蕴涵其负判断。\n\n\n **L220** 可容许世界对conflictingHeld的模型必须满足其中明确包含的能力主张。\n\n\n **L221** 同一模型也必须满足明确包含的能力否定。\n\n\n **L223** 以同条件正反后果否定一致性。\n\n\n **L224** 用同情境的两个相反后果反驳冲突所持理论的一致性。\n\n\n **L226** 说明后续定义或结果:执行治理采用单独的可行相关选择规范,豁免治理接受任意理由清单。\n\n\n **L227** 执行治理采用单独的可行相关选择规范,豁免治理接受任意理由清单。\n\n\n **L228** apply通过JustifiedChoice执行实际可行性与理由相关性要求;waive许可任意选择包。\n\n\n **L230** 说明后续定义或结果:执行模式提出后继操作,豁免模式只提出原copy操作。\n\n\n **L231** 执行模式提出后继操作,豁免模式只提出原copy操作。\n\n\n **L232** 采用生成规则时提出successor,其输出可与copy不同。\n\n\n **L233** 豁免该规则时提出未变的copy操作。\n\n\n **L235** 执行模式测试零与一,豁免模式只测试会通过的一。\n\n\n **L236** 采用反身评估时检查0和1,包括算术反例。\n\n\n **L237** 豁免时仅检查1,即算术原则通过的样本。\n\n\n **L239** 用经典命题可判定性判断具体冲突理论是否获许可;这是非计算定义,不是已部署检查器。\n\n\n **L240** 用古典命题判定把整个冲突理论许可化为布尔值;未提供可执行判定算法。\n\n\n **L242** 用经典可判定性判断该模式是否许可指定单面向主张包。\n\n\n **L243** 判定此方面自身主张及其确切单项评估包的许可。\n\n\n **L244** 为该可能不可计算的Grounds命题提供古典可判定性。\n\n\n **L246** 用经典可判定性判断恒等要求下指定实现和理由是否获许可。\n\n\n **L247** 在固定恒等要求与提供理由下,古典判定该实现的选择许可。\n\n\n **L249** 证明执行模式拒绝矛盾、无支持能力及不可行廉价后继,同时接受实际能力和恒等选择。\n\n\n **L250** 采用Grounds时拒绝仅成本能力证据包。\n\n\n **L251** 采用Grounds时接受得到适当支持的输出观察包。\n\n\n **L252** 采用选择规范时,尽管简洁性理由相关,仍因输出不可行拒绝cheapSuccessor。\n\n\n **L253** 采用选择规范时,凭实际输出理由接受identity。\n\n\n **L254** 启用这些布尔许可定义所需的古典可判定实例。\n\n\n **L255** 展开三个布尔决策及apply模式一致性谓词。\n\n\n **L256** 也展开Grounds与选择许可,显露每个布尔值判定的实际命题。\n\n\n **L257** 已证不一致性迫使conflictDecision apply为false。\n\n\n **L258** 失败的成本证据包判为false,已履责观察包判为true。\n\n\n **L259** 不可行的廉价方法判为false;可行且有理由的identity判为true。\n\n\n **L261** 计算豁免模式接受具体矛盾、无支持面向和不可行选择。\n\n\n **L262** waive模式甚至接受无支持的仅成本能力证据包。\n\n\n **L263** 它也仅凭简洁性接受cheapSuccessor,尽管输出错误。\n\n\n **L264** 从consistencyPermission开始计算豁免结果;它在此模式按定义为True。\n\n\n **L265** 用该平凡许可证明得到true的冲突决策布尔值。\n\n\n **L266** 接着判定对确切不足能力方面主张的豁免许可。\n\n\n **L267** 其单项适用谓词和包未变;豁免使许可为True、判定为true。\n\n\n **L268** 最后判定对同一廉价方法及仅简洁性理由的豁免许可。\n\n\n **L269** 该许可再次平凡为True,完成全部三个豁免决策。\n\n\n **L271** 说明后续定义或结果:为各承诺把治理模式解释为选项,分别赋予操作结果、目标、约束、实际理由及范围内批评响应。\n\n\n **L272** 为各承诺把治理模式解释为选项,分别赋予操作结果、目标、约束、实际理由及范围内批评响应。\n\n\n **L273** 为五项承诺分别选择不同的操作性价值立场适配接口。\n\n\n **L274** 构造生成承诺的价值立场。\n\n\n **L275** 其立场为治理模式、后果为操作,采纳选项与同一系统所选治理对应。\n\n\n **L276** 把模式映射为实际提出的successor或copy操作。\n\n\n **L277** 采纳的生成目标要求0处输出不同于copy的0输出。\n\n\n **L278** 还要求该模式实际政策满足采纳的Generative约束。\n\n\n **L279** 明确以同一系统选择chosenMode为起始承诺,不是推导出的普遍事实。\n\n\n **L280** 其随选项变化的理由比较拟议操作0→1与copy的0→0表现。\n\n\n **L281** 将此生成立场限于实现候选为identity的世界。\n\n\n **L282** 把实际库存膨胀却未扩展作为生成承诺的相关批评。\n\n\n **L283** 回应取向不保证进步且须另评前后能力;保存的回应是非空文本。\n\n\n **L284** 构造一致性承诺的不同价值立场。\n\n\n **L285** 以模式为立场、布尔冲突许可决策为后果,关联同一所选治理。\n\n\n **L286** 实际后果是该模式对整个冲突理论的决策。\n\n\n **L287** 要求该决策拒绝冲突理论。\n\n\n **L288** 同时要求实际所持理论与情境通过同一模式的一致性许可。\n\n\n **L289** 把同一系统采纳chosenMode陈述为此立场明确起始假设。\n\n\n **L290** 一致性理由首先包括冲突理论的输出正确正后果。\n\n\n **L291** 它还包括完全相同问题与情境下的相反后果。\n\n\n **L292** 将此一致性立场限于identity候选世界。\n\n\n **L293** 以空Bool理论不能蕴涵每个世界都为true作为实际不完整性批评。\n\n\n **L294** 回应一致性本身不确立充分支持,仍须评估主张的根据。\n\n\n **L295** 构造反身评估的价值立场。\n\n\n **L296** 以模式为立场、实际样本输入列表为后果,关联同一所选治理。\n\n\n **L297** 该模式选择样本集[0,1]或[1]。\n\n\n **L298** 要求某个实际选中样本揭示同一算术原则的假结果。\n\n\n **L299** 还要求同一模式下所有者0的规则与工作满足完整反身要求。\n\n\n **L300** 明确把同一系统采纳chosenMode作为起始承诺。\n\n\n **L301** 理由指明算术原则在0实际失败、在1成功。\n\n\n **L302** 将此反身立场限制于identity候选世界。\n\n\n **L303** 保留1处通过测试与0处实际失败这对事实作为批评。\n\n\n **L304** 回应通过自测不认证原则正确,须保留反例及其范围。\n\n\n **L305** 构造针对Grounds条款自身的价值立场。\n\n\n **L306** 以模式为立场、布尔证据包决策为后果,属于同一系统治理。\n\n\n **L307** 实际后果检验无支持的仅成本能力方面。\n\n\n **L308** 要求拒绝该无支持证据包。\n\n\n **L309** 还要求许可实际能力主张及按内容构造的表述。\n\n\n **L310** 该正约束恰使用已适当履责的单项capabilityFacet证据包。\n\n\n **L311** 把同一系统采纳chosenMode陈述为明确起始承诺。\n\n\n **L312** Grounds理由记录successor/apply世界与成本观察相容。\n\n\n **L313** 把该相容性与同一世界中声称输出能力的实际失败配对。\n\n\n **L314** 将此Grounds立场限制于identity候选世界。\n\n\n **L315** 批评指向同一过程满足输出合同却没有附带解释合同。\n\n\n **L316** 回应外部输出评估可提供Grounds,而不要求此过程解释其内部生成。\n\n\n **L317** 构造实现选择的独立价值立场。\n\n\n **L318** 以模式为立场、布尔方法许可决策为后果,关联同一治理选择。\n\n\n **L319** 受检选择是仅以简洁性为理由的廉价successor。\n\n\n **L320** 要求拒绝该错误输出选择。\n\n\n **L321** 还要求在相同要求下凭实际输出理由接受identity。\n\n\n **L322** 明确为此系统采纳chosenMode;价值起点不是从中性事实证明的。\n\n\n **L323** 选择理由比较同一输入上cheapSuccessor输出1与所需输出0。\n\n\n **L324** 还记录该方法满足预算,因此低成本不能掩盖输出失败。\n\n\n **L325** 将此选择立场限于identity候选世界。\n\n\n **L326** 把identity实际具有的惯用及既有地位,保留为对排除既有方法的相关批评。\n\n\n **L327** 回应惯用既有方法在实际输出与预算理由支持时仍可被选择。\n\n\n **L329** 把各自解释的立场具体化为采纳执行治理模式。\n\n\n **L331** 说明后续定义或结果:在同一实际世界和采纳模式下,以计算或具体反例检查每项承诺理由。\n\n\n **L332** 在同一实际世界和采纳模式下,以计算或具体反例检查每项承诺理由。\n\n\n **L333** 承诺c实际列出的每个理由,都须在actual世界对其采纳的apply选项成立。\n\n\n **L334** 分别处理五项承诺,展开各自实际理由列表,并固定其中理由r。\n\n\n **L335** 每个列表都是单项,成员前提把r确定为该承诺的具体理由。\n\n\n **L336** 生成理由计算为successor 0=1且copy 0=0。\n\n\n **L337** 一致性理由使用已证同一冲突理论的正反后果。\n\n\n **L338** 反身理由计算同一算术原则在0失败、在1成功。\n\n\n **L339** 对Grounds,提供successor世界的成本相容性,留下能力失败待证。\n\n\n **L340** 假设同一successor世界仍具有所需输出能力。\n\n\n **L341** 在必需输入0处,该假设给出successor输出1等于所需0。\n\n\n **L342** 排除不可能的1=0,证明理由中的能力失败部分。\n\n\n **L343** 选择理由计算得到输出1、所需0及廉价方法满足预算的成本。\n\n\n **L345** 说明后续定义或结果:用实际判断及遵守定理证明每个采纳模式满足自身目标与约束,不断言终极规范正确。\n\n\n **L346** 用实际判断及遵守定理证明每个采纳模式满足自身目标与约束,不断言终极规范正确。\n\n\n **L347** 将每项承诺后果展开为实际目标与随模式变化的约束。\n\n\n **L348** 生成的apply选项在0处不同于copy,且openPolicy满足价值取向与可修订性。\n\n\n **L349** 一致性的apply选项拒绝冲突理论,同时实际所持理论保持一致。\n\n\n **L350** 反身性从[0,1]选择实际反例0,并提供完整内容性自有工作反身履责。\n\n\n **L351** Grounds拒绝无支持成本包,同时正确能力证据包具有Grounds。\n\n\n **L352** 选择规范拒绝cheapSuccessor,保留有理由且可行的identity实现。\n\n\n **L354** 为每项承诺构造非空理由、联合采纳、已检查后果及非空响应;已独立证明的后果无需再用理由假设。\n\n\n **L355** 把ValueProcedure分为非空理由、联合采纳、带范围后果规则及批评回应。\n\n\n **L356** 检查每项承诺实际理由列表都包含其单项理由。\n\n\n **L357** 用同一actual世界作为JointAdoption见证,并提供positionReasons c;余下检查起始理论、限度与采纳。\n\n\n **L358** 在actual中治理为apply,因此选择采纳模式的单项起始理论成立。\n\n\n **L359** 对每项承诺,actual的identity候选满足其声明限度。\n\n\n **L360** 对每项承诺,actual所选治理等于采纳的apply选项。\n\n\n **L361** 为程序后果条款取任意世界及起始、限度、全部理由前提。\n\n\n **L362** 使用已对每个世界证明apply选项目标与约束的positionConsequence;此处不需要这些前提。\n\n\n **L363** 为回应条款,取具有适用范围内相关批评的世界。\n\n\n **L364** 每项承诺都返回其实际保存的非空回应字符串,满足回应存在要求。\n\n\n **L366** 说明后续定义或结果:为每项承诺提供实际范围内批评情形,避免这些实例的响应义务空真。\n\n\n **L367** 为每项承诺提供实际范围内批评情形,避免这些实例的响应义务空真。\n\n\n **L368** 要求actual既属于此承诺限度,且该承诺具体批评确在该处适用。\n\n\n **L369** 将实际限度检查与实际批评检查分开。\n\n\n **L370** 每个限度都要求identity,而actual候选按定义正是identity。\n\n\n **L371** 分别检查每项承诺的不同批评,不空泛假设存在批评。\n\n\n **L372** 生成批评成立,因为膨胀基线列表没有新增理解或构造操作。\n\n\n **L373** 一致性批评使用空理论不能蕴涵所选Bool主张的已证结果。\n\n\n **L374** 反身批评计算得到1处样本通过而0处失败。\n\n\n **L375** Grounds批评组合outputOnlyProcess的实际输出正确性与缺失解释合同。\n\n\n **L376** 选择批评成立,因为identity实际为惯用且既有实现。\n\n\n **L378** 说明后续定义或结果:证明豁免选项不满足各项未改变的目标或约束。\n\n\n **L379** 证明豁免选项不满足各项未改变的目标或约束。\n\n\n **L380** 陈述任意世界中每项承诺的waive选项都会违反声明目标或约束。\n\n\n **L381** 分别处理各承诺,并假设对应waive后果成立以求矛盾。\n\n\n **L382** 生成后果会要求Generative neutralPolicy,与许可不等于赋值例中已证失败矛盾。\n\n\n **L383** 一致性假设目标声称waive必须拒绝冲突理论。\n\n\n **L384** 但decisionsWaive得到接受值true,使该目标化为true=false。\n\n\n **L385** 排除一致性选项的不可能布尔等式。\n\n\n **L386** 反身性假设目标提供选中样本n,使算术原则在该处为假。\n\n\n **L387** waive模式选中样本恰为[1]。\n\n\n **L388** 属于该单项列表迫使所谓失败输入n等于1。\n\n\n **L389** 在声称失败的证明中把n替换为1。\n\n\n **L390** 该原则在1实际返回true,与声称的false结果矛盾。\n\n\n **L391** Grounds假设目标声称waive拒绝具体无支持能力包。\n\n\n **L392** decisionsWaive却说明同一包被接受,得到true=false。\n\n\n **L393** 排除不可能等式,故豁免Grounds后果失败。\n\n\n **L394** 选择的假设目标声称waive拒绝仅凭简洁性的cheapSuccessor。\n\n\n **L395** decisionsWaive证明该确切选择被接受,再次得到true=false。\n\n\n **L396** 排除该等式,完成全部五个waive后果的失败证明。\n\n\n **L398** 将假定联合采纳见证与后果失败结合,拒绝相反模式的程序。\n\n\n **L399** 假设相反的waive价值立场仍满足ValueProcedure。\n\n\n **L400** 提取其JointAdoption见证w、起始理论证明hs、限度证明hl及全部理由证明hr。\n\n\n **L401** 将假设程序的后果条款应用于同一联合见证,得到waive后果;oppositeConsequenceFails c w正反驳该后果。\n\n\n **L403** 说明后续定义或结果:抽取各立场采纳主张;都使用同一治理选择器,但分别评估结果和理由。\n\n\n **L404** 抽取各立场采纳主张;都使用同一治理选择器,但分别评估结果和理由。\n\n\n **L406** 把具体解释的承诺立场包装成价值面向。\n\n\n **L408** 为每项承诺提供Grounds、真实联合采纳、实际相关批评及同目标下相反政策的拒绝。\n\n\n **L409** 要求为承诺c的实际采纳主张提供Grounds,表述由其方面内容构造。\n\n\n **L410** 仅令commitmentFacet c适用,并只提供同一方面。\n\n\n **L411** 还要求该立场具有非空的联合可容许采纳见证。\n\n\n **L412** 要求此特定承诺的批评在actual实际成立。\n\n\n **L413** 还证明相反waive立场不满足同一价值程序要求。\n\n\n **L414** 使用该承诺已检查的positionProcedure构造单项Grounds。\n\n\n **L415** 补上其联合见证、实际批评及相反立场的已证拒绝。\n\n\n **L417** 说明后续定义或结果:证明Grounds立场采纳主张与所选治理模式的一般Grounds规范外延相同。\n\n\n **L418** 证明Grounds立场采纳主张与所选治理模式的一般Grounds规范外延相同。\n\n\n **L419** 为证明两个主张相等,固定任意世界w并比较该处命题。\n\n\n **L420** 使用命题外延性:两个命题等价即可得到相等。\n\n\n **L421** groundsProvisionMeaning说明一般条款恰在apply模式成立,与此采纳主张按反向对应。\n\n\n **L423** 把价值Grounds应用到一般Grounds规范自身,保留实际范围、批评及被拒绝豁免变体。\n\n\n **L424** 用按内容构造的表述评估量化主张与方面包的一般GroundsProvision自身。\n\n\n **L425** 适用价值方面恰为grounds承诺自身的方面。\n\n\n **L426** 要求actual满足该承诺声明限度。\n\n\n **L427** 也要求其批评在actual实际适用。\n\n\n **L428** 要求相反的豁免Grounds承诺不满足ValueProcedure。\n\n\n **L429** 把一般条款改写为外延相同的grounds采纳主张。\n\n\n **L430** 复用针对同一grounds承诺的实际Grounds证明。\n\n\n **L431** 提供分别检查过的实际限度与实际相关批评。\n\n\n **L432** 提供相反豁免Grounds立场的已证失败。\n\n\n **L434** 说明后续定义或结果:保存当前哲学原则形式及其实际治理模式。\n\n\n **L435** 说明后续定义或结果:保存当前哲学原则形式及其实际治理模式。\n\n\n **L436** 保存当前哲学原则形式及其实际治理模式。\n\n\n **L437** 保存该哲学方法实现的实际原则形式。\n\n\n **L438** 保存同一哲学方法采用还是豁免治理检查。\n\n\n **L440** 从同一系统原则形式及治理选择派生被审哲学对象。\n\n\n **L441** 以该系统自身原则形式及其在w中的治理构造哲学方法。\n\n\n **L443** 按该哲学实际治理模式,对零处恒等提案及其他处廉价不可行提案给出许可结果。\n\n\n **L444** 输入0指认identity方法提案;其余输入走廉价successor提案分支。\n\n\n **L445** 对identity,运行该哲学方法实际选择政策,接受返回1、拒绝返回0。\n\n\n **L446** 对其他输入,以同一政策评估仅凭简洁性的cheapSuccessor,同样以1/0编码接受与拒绝。\n\n\n **L448** 把实际哲学审查程序呈为实现,域为零与一,并提供对应输出及轨迹代理。\n\n\n **L449** 将实现命名为当前哲学的实际提案审查方法。\n\n\n **L450** 将该提案审查实现标记为惯用。\n\n\n **L451** 也标记同一实现为既有;后续证明检查仅此是否足以支持优先性。\n\n\n **L452** 实现实际运行恰为该哲学方法的review函数。\n\n\n **L453** 给该审查实现赋成本1。\n\n\n **L454** 仅将提案编号0和1声明为其应用定义域。\n\n\n **L455** 在实现解释字段中提供同一review函数。\n\n\n **L456** 记录由提案编号和实际审查结果组成的双条轨迹。\n\n\n **L458** 要求接受提案零、拒绝提案一,并满足预算一。\n\n\n **L459** 该应用恰测试提案编号0和1。\n\n\n **L460** 要求identity提案0被接受为1,另一受测提案被拒绝为0。\n\n\n **L461** 给予该审查方法成本预算1。\n\n\n **L462** 本例不通过要求中的values谓词增加限制。\n\n\n **L464** 从执行治理结果计算两个被要求提案的实际判断。\n\n\n **L465** 对每个必需提案,实际系统当前哲学审查须等于应用期望判定。\n\n\n **L466** 取提案n及其属于必需输入的证明hn。\n\n\n **L467** 用hn把n限定为具体identity或廉价successor提案编号。\n\n\n **L468** 展开同一当前哲学方法和实际系统,显露真实提案决策。\n\n\n **L469** 用decisionsApply将接受identity、拒绝廉价successor与所需判定匹配。\n\n\n **L471** 说明后续定义或结果:将实现绑定当前原则及治理对象,拒绝纯地位优先,并由两个实际提案判断提供正当理由。\n\n\n **L472** 将实现绑定当前原则及治理对象,拒绝纯地位优先,并由两个实际提案判断提供正当理由。\n\n\n **L473** 检查该哲学方法形式恰为实际系统当前原则形式。\n\n\n **L474** 检查其治理模式恰为同一系统在actual的模式。\n\n\n **L475** 开始陈述仅地位不足以支持选择此实际审查实现。\n\n\n **L476** 对同一哲学实现,被拒绝理由列表恰为[.status .standing]。\n\n\n **L477** 另陈述该实现在实际提案要求下具有有根据选择。\n\n\n **L478** 该正向选择使用实际输出理由,而非仅其名称或既有标记。\n\n\n **L479** 同一哲学审查实际以结果1接受identity提案0。\n\n\n **L480** 它实际以结果0拒绝廉价successor提案1。\n\n\n **L481** 提供同形式与模式、纯地位拒绝及提案0正确计算,留下正向输出理由选择待证。\n\n\n **L482** 也为必需提案1提供currentReviewCorrect,证明实际拒绝。\n\n\n **L483** 由两个提案输出正确及成本1≤预算1构造正向选择可行性。\n\n\n **L484** 以列表中的.method .output理由及currentReviewCorrect作为实际相关性见证。\n\n\n **L486** 说明后续定义或结果:将任意给定应用合同和要求用于该系统实际依世界方法。\n\n\n **L487** 将任意给定应用合同和要求用于该系统实际依世界方法。\n\n\n **L488** 接收关联Requirements与被评实现的任意应用合同。\n\n\n **L489** 在每个世界,把同一合同和要求应用于该系统实际方法实现。\n\n\n **L491** 把同系统完整反身性与精确参数化应用主张的Grounds结合。\n\n\n **L492** ApplicationDuties把选定应用合同保留为明确参数。\n\n\n **L493** 也接收为每个潜在相关方面提供的表述。\n\n\n **L494** 把实际适用谓词与提供的方面列表分开。\n\n\n **L495** 要求同一系统所有者在w的实际规则和工作满足完整反身要求。\n\n\n **L496** 要求为该系统、这些要求与此合同产生的主张提供匹配Grounds。\n\n\n **L498** 说明后续定义或结果:从明确假定的应用遵守接口抽取反身性、适用覆盖及匹配面向检查,不凭空确立遵守。\n\n\n **L499** 从明确假定的应用遵守接口抽取反身性、适用覆盖及匹配面向检查,不凭空确立遵守。\n\n\n **L500** 该定理保留任意应用合同,不固定单一能力定义。\n\n\n **L501** 保留该应用各方面的实际表述族。\n\n\n **L502** 保留该应用自身适用谓词及所提供方面列表。\n\n\n **L503** 关键前提是假设ApplicationDuties已对这些确切对象成立;定理不创造履责事实。\n\n\n **L504** 结论从假设义务保留同所有者规则与工作的完整反身要求。\n\n\n **L505** 它要求每个实际适用方面都在提供列表中,与标签无关。\n\n\n **L506** 对每个所列方面,其被评主张须等于该系统实际参数化应用主张。\n\n\n **L507** 同一方面须具有可表达且内容匹配的表述,并实际满足履责条件。\n\n\n **L508** 投影h.1为反身要求,h.2.2.1为适用方面覆盖,h.2.2.2为每个所列方面的同主张、表述与履责检查。\n\n\n **L510** 要求实现满足应用在每个请求输入上的期望输出。\n\n\n **L511** 输出合同在每个必需输入上核对该实现实际运行与所选期望输出。\n\n\n **L513** 把同一应用的期望输出由恒等改为后继,保留其他字段。\n\n\n **L514** 保留identityRequirements的输入及其他字段,但把期望输出改为n+1。\n\n\n **L516** 说明后续定义或结果:保留旧观察,把被评主张改成后继目标,以检验同对象证据是否仍足够。\n\n\n **L517** 保留旧观察,把被评主张改成后继目标,以检验同对象证据是否仍足够。\n\n\n **L518** 为无限制范围的经验方面复用旧实际观察。\n\n\n **L519** 把其被评主张改为同一系统满足successorRequirements;不确定性谓词仍平凡为真。\n\n\n **L521** 在此实例中,原恒等合同仍保有已履行义务;改后的后继合同在同一实际方法上失败,且指定保留观察包不能为它提供根据。\n\n\n **L522** 原恒等输出应用在实际系统和世界上履行ApplicationDuties。\n\n\n **L523** 该正实例使用已支持的capabilityFacet及按其自身内容构造的表述。\n\n\n **L524** 但同一实际系统不满足改变后的后继输出合同。\n\n\n **L525** 改变后的主张也不能从保留观察包取得Grounds。\n\n\n **L526** 此失败恰针对changedObjectiveFacet单项包,不针对所有可能证据包。\n\n\n **L527** 由完整自有反身要求及capabilityGrounds构造原义务,留下改变后行为与证据失败待证。\n\n\n **L528** 假设实际identity方法满足新的successor合同。\n\n\n **L529** 在必需输入0处,这会迫使实际输出0等于期望1。\n\n\n **L530** 排除不可能的0=1,反驳改变后的实际能力主张。\n\n\n **L531** 假设保留观察单项包仍为改变后的主张提供Grounds。\n\n\n **L532** 从假设Grounds包提取实际changedObjectiveFacet的履责。\n\n\n **L533** 将其支持规则应用于相容actual世界和输入0,得到同一错误输出等式0=1。\n\n\n **L534** 排除该等式,证明指定保留观察包不能为新主张提供根据。\n\n\n **L536** 说明后续定义或结果:给出实际遵守章程系统与兼容成本证据,但该指定能力面向无支持;不排除其他有效根据。\n\n\n **L537** 给出实际遵守章程系统与兼容成本证据,但该指定能力面向无支持;不排除其他有效根据。\n\n\n **L538** 同一实际系统满足全部已表示Charter条件。\n\n\n **L539** 其实际世界与真实的至多2成本观察相容。\n\n\n **L540** 然而该成本证据不能为其输出能力提供Grounds。\n\n\n **L541** 被否定的是特定unsupportedCapabilityFacet单项Grounds,不是所有可能评估包。\n\n\n **L542** 组合charterChecked、actual与成本记录的直接相容性,以及已证unsupportedGrounds反例。\n\n\n **L544** 说明后续定义或结果:构造同一系统和世界,满足实际判断、完整反身性、能力根据、可行选择及各解释承诺Grounds;这是有界模型而非哲学普遍正确性。\n\n\n **L545** 说明后续定义或结果:构造同一系统和世界,满足实际判断、完整反身性、能力根据、可行选择及各解释承诺Grounds;这是有界模型而非哲学普遍正确性。\n\n\n **L546** 构造同一系统和世界,满足实际判断、完整反身性、能力根据、可行选择及各解释承诺Grounds;这是有界模型而非哲学普遍正确性。\n\n\n **L547** 要求存在实际系统与世界对作为联合见证,使组合主张非空。\n\n\n **L548** 同一对象对必须对其共同持有主张和情境可容许,并满足Charter。\n\n\n **L549** 它还须由capabilityFacet履行自身能力义务,且拥有声称能力。\n\n\n **L550** 同一实际方法须在自身要求下凭objectiveReason得到可行的有根据选择。\n\n\n **L551** 对五项承诺中的每一项,对应实际采纳主张都须具有Grounds。\n\n\n **L552** 每项承诺使用自身确切单项价值方面及对应适用性。\n\n\n **L553** 最后确认见证就是actualSystem和actual,防止换成无关存在对象。\n\n\n **L554** 选择该确切对象对,提供实际可容许性与已检查Charter。\n\n\n **L555** 补上同一系统自身能力义务、实际能力及有根据的identity选择。\n\n\n **L556** 使用每项承诺已有Grounds证明,再按构造完成两个见证一致性等式。\n\n\n **L558** 关闭当前命名空间。\n\n\n### `leanified/CoreReader/Logic.lean`\n\n\n```lean\nnamespace CoreReader.Logic\n\n/- A claim denotes the worlds in which its content holds. -/\nabbrev Claim (W : Type) := W → Prop\n/- A theory is a collection of simultaneously held claims. -/\nabbrev Theory (W : Type) := Claim W → Prop\n/- A model satisfies every member of the whole theory. -/\ndef Models {W : Type} (t : Theory W) (w : W) : Prop := ∀ p, t p → p w\n/- Semantic entailment quantifies over all models. -/\ndef Entails {W : Type} (t : Theory W) (p : Claim W) : Prop := ∀ w, Models t w → p w\n/- Satisfiability requires an actual witness. -/\ndef Satisfiable {W : Type} (t : Theory W) : Prop := ∃ w, Models t w\n/- Assumptions, meanings and scope are distinct components; questions remain explicit. -/\nstructure Context (W Q : Type) where\n assumptions : Theory W\n meaning : Q → Claim W\n scope : Claim W\n/- Admissible worlds satisfy held claims, assumptions and scope jointly. -/\ndef Admissible {W Q : Type} (t : Theory W) (c : Context W Q) (w : W) : Prop :=\n Models t w ∧ Models c.assumptions w ∧ c.scope w\n/- A negative judgment denies the very same question under the same meaning. -/\ndef Consequence {W Q : Type} (t : Theory W) (c : Context W Q) (q : Q) (positive : Bool) : Prop :=\n ∀ w, Admissible t c w → if positive then c.meaning q w else ¬ c.meaning q w\n/- The consistency obligation prohibits both consequences at one comparison basis. -/\ndef Consistent {W Q : Type} (t : Theory W) (c : Context W Q) : Prop :=\n ∀ q, ¬ (Consequence t c q true ∧ Consequence t c q false)\n/- An inhabited joint interpretation prevents opposite semantic consequences. -/\ntheorem consequenceConsistency {W Q : Type} (t : Theory W) (c : Context W Q)\n (inhabited : ∃ w, Admissible t c w) : Consistent t c := by\n intro q h\n obtain ⟨w, hw⟩ := inhabited\n exact (h.2 w hw) (h.1 w hw)\n/- Empty and singleton theories provide concrete semantic contexts. -/\ndef emptyTheory {W : Type} : Theory W := fun _ => False\ndef singleton {W : Type} (p : Claim W) : Theory W := fun q => q = p\ndef union {W : Type} (a b : Theory W) : Theory W := fun p => a p ∨ b p\ntheorem modelsSingleton {W : Type} (p : Claim W) (w : W) : Models (singleton p) w ↔ p w := by\n constructor\n · intro h; exact h p rfl\n · intro h q hq; cases hq; exact h\ntheorem modelsUnion {W : Type} (a b : Theory W) (w : W) :\n Models (union a b) w ↔ Models a w ∧ Models b w := by\n constructor\n · intro h; exact ⟨fun p hp => h p (Or.inl hp), fun p hp => h p (Or.inr hp)⟩\n · rintro ⟨ha,hb⟩ p (hp|hp); exact ha p hp; exact hb p hp\n/- The paired world records independent truth values for two questions. -/\ndef premiseP : Claim (Bool × Bool) := fun w => w.1 = true\ndef premiseRule : Claim (Bool × Bool) := fun w => w.1 = true → w.2 = true\ndef premiseNotQ : Claim (Bool × Bool) := fun w => w.2 ≠ true\ndef jointTheory : Theory (Bool × Bool) :=\n union (singleton premiseP) (union (singleton premiseRule) (singleton premiseNotQ))\n/- Each premise has a model, but their joint implication makes the union unsatisfiable. -/\ntheorem jointConflict :\n Satisfiable (singleton premiseP) ∧ Satisfiable (singleton premiseRule) ∧\n Satisfiable (singleton premiseNotQ) ∧ ¬ Satisfiable jointTheory := by\n refine ⟨⟨(true,true), (modelsSingleton _ _).2 rfl⟩,\n ⟨(false,false), (modelsSingleton _ _).2 (by intro h; cases h)⟩,\n ⟨(false,false), (modelsSingleton _ _).2 (by intro h; cases h)⟩, ?_⟩\n rintro ⟨w, hw⟩\n have hp := hw premiseP (Or.inl rfl)\n have hr := hw premiseRule (Or.inr (Or.inl rfl))\n have hn := hw premiseNotQ (Or.inr (Or.inr rfl))\n exact hn (hr hp)\n/- A retraction replaces the old singleton, rather than retaining both at the same time. -/\ndef revisionSlice (time : Nat) : Theory Bool :=\n singleton (fun w => w = (time == 0))\n/- The initial and revised slices have models; keeping both would create a conflict. -/\ntheorem revisionCanReverse :\n Satisfiable (revisionSlice 0) ∧ Satisfiable (revisionSlice 1) ∧\n ¬ Satisfiable (union (revisionSlice 0) (revisionSlice 1)) := by\n refine ⟨⟨true, (modelsSingleton _ _).2 rfl⟩,\n ⟨false, (modelsSingleton _ _).2 rfl⟩, ?_⟩\n rintro ⟨w, hw⟩\n have hs := (modelsUnion _ _ _).1 hw\n have hp := (modelsSingleton _ _).1 hs.1\n have hn := (modelsSingleton _ _).1 hs.2\n have bad : true = false := hp.symm.trans hn\n cases bad\n/- This basic question asks whether the represented switch is on. -/\ndef onQuestion : Unit → Claim Bool := fun _ w => w = true\ndef assumptionContext (b : Bool) : Context Bool Unit :=\n ⟨singleton (fun w => w = b), onQuestion, fun _ => True⟩\ndef meaningContext (b : Bool) : Context Bool Unit :=\n ⟨singleton (fun w => w = true), (fun _ w => w = b), fun _ => True⟩\ndef scopeContext (b : Bool) : Context Bool Unit :=\n ⟨emptyTheory, onQuestion, fun w => w = b⟩\n/- Distinct assumptions, meanings and scopes each admit opposite judgments without same-context conflict. -/\ntheorem contextDifferences :\n (Consequence emptyTheory (assumptionContext true) () true ∧\n Consequence emptyTheory (assumptionContext false) () false) ∧\n (Consequence emptyTheory (meaningContext true) () true ∧\n Consequence emptyTheory (meaningContext false) () false) ∧\n (Consequence emptyTheory (scopeContext true) () true ∧\n Consequence emptyTheory (scopeContext false) () false) ∧\n (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧\n (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧\n (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w) := by\n have empty : ∀ w : Bool, Models emptyTheory w := by intro w p hp; cases hp\n refine ⟨⟨?_, ?_⟩, ⟨?_, ?_⟩, ⟨?_, ?_⟩, ?_, ?_, ?_⟩\n · intro w h; change w = true; exact (modelsSingleton (fun x : Bool => x = true) w).1 h.2.1\n · intro w h hp; have hn := (modelsSingleton _ _).1 h.2.1; cases hp.symm.trans hn\n · intro w h; change w = true; exact (modelsSingleton (fun x : Bool => x = true) w).1 h.2.1\n · intro w h hn; have hp := (modelsSingleton _ _).1 h.2.1; cases hp.symm.trans hn\n · intro w h; exact h.2.2\n · intro w h hp; cases hp.symm.trans h.2.2\n · intro b; exact ⟨b, empty b, (modelsSingleton _ _).2 rfl, trivial⟩\n · intro b; exact ⟨true, empty true, (modelsSingleton _ _).2 rfl, trivial⟩\n · intro b; exact ⟨b, empty b, empty b, rfl⟩\n/- Snapshots preserve identifiable adopted-form revisions even when semantic content agrees. -/\nstructure Snapshot (W Q : Type) where\n held : Theory W\n context : Context W Q\n revisionIdentity : Nat\n/- Semantic equivalence compares represented content, not its list ordering. -/\ndef SameContent {W Q : Type} (a b : Snapshot W Q) : Prop :=\n (∀ p, a.held p ↔ b.held p) ∧\n (∀ p, a.context.assumptions p ↔ b.context.assumptions p) ∧\n (∀ q w, a.context.meaning q w ↔ b.context.meaning q w) ∧\n (∀ w, a.context.scope w ↔ b.context.scope w)\n/- The reporting norm covers both semantic change and independently identified revisions. -/\ndef TruthfulReport {W Q : Type} (a b : Snapshot W Q) (reported : Bool) : Prop :=\n (¬ SameContent a b ∨ a.revisionIdentity ≠ b.revisionIdentity) → reported = true\n/- A real represented change and compliance entail an acknowledged change. -/\ntheorem semanticChangeMustBeReported {W Q : Type} (a b : Snapshot W Q) (reported : Bool)\n (changed : ¬ SameContent a b ∨ a.revisionIdentity ≠ b.revisionIdentity)\n (h : TruthfulReport a b reported) : reported = true := h changed\n/- Reordering a two-claim presentation preserves the held theory extension. -/\ntheorem representationOrderIrrelevant {W : Type} (p q : Claim W) :\n ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r := by\n intro r; exact or_comm\ndef contextSnapshot (c : Context Bool Unit) (revision : Nat := 0) : Snapshot Bool Unit :=\n ⟨emptyTheory, c, revision⟩\n/- Hiding each kind of contextual change violates the reporting interface; reporting alone supplies no truth guarantee. -/\ntheorem hiddenContextChangeRejected :\n ¬ TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) false ∧\n ¬ TruthfulReport (contextSnapshot (meaningContext true)) (contextSnapshot (meaningContext false)) false ∧\n ¬ TruthfulReport (contextSnapshot (scopeContext true)) (contextSnapshot (scopeContext false)) false ∧\n ¬ TruthfulReport (contextSnapshot (scopeContext true) 0) (contextSnapshot (scopeContext true) 1) false ∧\n (TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) true ∧\n ¬ Models (assumptionContext false).assumptions true) := by\n have neq : (fun w : Bool => w = true) ≠ (fun w : Bool => w = false) := by\n intro h; have k := congrFun h true; have z : true = false := k.mp rfl; cases z\n refine ⟨?_, ?_, ?_, ?_, ?_⟩\n · intro h\n have bad := h (Or.inl (by intro s; exact neq ((s.2.1 _).mp rfl)))\n cases bad\n · intro h\n have bad := h (Or.inl (by intro s; have z := (s.2.2.1 () true).mp rfl; cases z))\n cases bad\n · intro h\n have bad := h (Or.inl (by intro s; have z := (s.2.2.2 true).mp rfl; cases z))\n cases bad\n · intro h; have bad := h (Or.inr (by decide)); cases bad\n · refine ⟨fun _ => rfl, ?_⟩\n intro h; have z := (modelsSingleton _ _).1 h; cases z\n/- Two nonidentical resource objectives can share a feasible allocation. -/\ntheorem tensionWithoutContradiction :\n (∃ budget : Nat, 4 ≤ budget ∧ budget ≤ 6) ∧\n ¬ ((fun n : Nat => 4 ≤ n) = (fun n : Nat => n ≤ 6)) := by\n refine ⟨⟨5, by decide, by decide⟩, ?_⟩\n intro h; have k := congrFun h 0; have bad : 4 ≤ 0 := k.mpr (by decide); cases bad\n/- Conflicting conclusions cannot be retained under the same consistency obligation. -/\ntheorem conflictRequiresChange {W Q : Type} (t : Theory W) (c : Context W Q) (q : Q)\n (positive : Consequence t c q true) (negative : Consequence t c q false) :\n ¬ Consistent t c := fun h => h q ⟨positive,negative⟩\n/- A satisfiable theory can have a false assumption at a specified actual world. -/\ntheorem consistentFalse : Satisfiable (singleton (fun w : Bool => w = true)) ∧\n ¬ Models (singleton (fun w : Bool => w = true)) false := by\n refine ⟨⟨true, (modelsSingleton _ _).2 rfl⟩, ?_⟩\n intro h; have bad := (modelsSingleton _ _).1 h; cases bad\n/- The explicitly asked on/off question is undecided by the empty but inhabited theory. -/\ntheorem consistentIncomplete : Satisfiable (emptyTheory : Theory Bool) ∧\n ¬ Entails emptyTheory (fun w : Bool => w = true) ∧\n ¬ Entails emptyTheory (fun w : Bool => w ≠ true) := by\n have empty : ∀ w : Bool, Models emptyTheory w := by intro w p hp; cases hp\n refine ⟨⟨true, empty true⟩, ?_, ?_⟩\n · intro h; have bad := h false (empty false); cases bad\n · intro h; exact h true (empty true) rfl\n/- A claim can share a model with a theory without following in every model. -/\ntheorem compatibilityNotEntailment :\n Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧\n ¬ Entails emptyTheory (fun w : Bool => w = true) := by\n refine ⟨⟨true, (modelsUnion _ _ _).2 ⟨?_, (modelsSingleton _ _).2 rfl⟩⟩,\n consistentIncomplete.2.1⟩\n intro p hp; cases hp\n\nend CoreReader.Logic\n```\n\n\n\n **L1** 打开命名空间 CoreReader.Logic,使后续声明获得这一模块限定名。\n\n\n **L3** 说明 Claim 的预定范围。对应声明涉及:主张是从给定世界类型到命题的函数,不预设现实解释。 该注释用于解释,不是证明前提。\n\n\n **L4** 引入类型缩写 Claim。主张是从给定世界类型到命题的函数,不预设现实解释。\n\n\n **L5** 说明 Theory 的预定范围。对应声明涉及:理论用谓词选择同时持有的主张,不要求有限语法。 该注释用于解释,不是证明前提。\n\n\n **L6** 引入类型缩写 Theory。理论用谓词选择同时持有的主张,不要求有限语法。\n\n\n **L7** 说明 Models 的预定范围。对应声明涉及:世界满足理论,指理论选择的每个主张都在此世界成立。 该注释用于解释,不是证明前提。\n\n\n **L8** 定义 Models。世界满足理论,指理论选择的每个主张都在此世界成立。\n\n\n **L9** 说明 Entails 的预定范围。对应声明涉及:在所有理论模型中结论都成立;无模型时蕴涵可空真。 该注释用于解释,不是证明前提。\n\n\n **L10** 定义 Entails。在所有理论模型中结论都成立;无模型时蕴涵可空真。\n\n\n **L11** 说明 Satisfiable 的预定范围。对应声明涉及:要求存在实际世界及其满足全部理论主张的证明。 该注释用于解释,不是证明前提。\n\n\n **L12** 定义 Satisfiable。要求存在实际世界及其满足全部理论主张的证明。\n\n\n **L13** 说明 Context 的预定范围。对应声明涉及:分别保存附加假设、问题含义和适用范围。 该注释用于解释,不是证明前提。\n\n\n **L14** 声明数据接口 Context。分别保存附加假设、问题含义和适用范围。\n\n\n **L15** 保存真实的上下文假设理论,与所持理论分开。\n\n\n **L16** 把每个问题解释为针对每个世界的命题。\n\n\n **L17** 保存选择被接纳应用范围的谓词。\n\n\n **L18** 说明 Admissible 的预定范围。对应声明涉及:同一世界同时满足持有理论、上下文假设和范围。 该注释用于解释,不是证明前提。\n\n\n **L19** 定义 Admissible。同一世界同时满足持有理论、上下文假设和范围。\n\n\n **L20** 要求同一世界同时满足两个理论及上下文范围。\n\n\n **L21** 说明 Consequence 的预定范围。对应声明涉及:在同一上下文全部可接受世界中,要求指定问题的正或负结论。 该注释用于解释,不是证明前提。\n\n\n **L22** 定义 Consequence。在同一上下文全部可接受世界中,要求指定问题的正或负结论。\n\n\n **L23** 对每个可接受世界量化;符号选择该问题的含义或其否定。\n\n\n **L24** 说明 Consistent 的预定范围。对应声明涉及:禁止同一问题的正反后果并存;问题类型为空时条件空真。 该注释用于解释,不是证明前提。\n\n\n **L25** 定义 Consistent。禁止同一问题的正反后果并存;问题类型为空时条件空真。\n\n\n **L26** 对每个问题,禁止同一上下文中正反后果的合取。\n\n\n **L27** 说明 consequenceConsistency 的预定范围。对应声明涉及:用显式可接受世界同时实例化正反后果,导出矛盾,得到上下文一致性。 该注释用于解释,不是证明前提。\n\n\n **L28** 陈述经检查的结果 consequenceConsistency。用显式可接受世界同时实例化正反后果,导出矛盾,得到上下文一致性。\n\n\n **L29** 假定整个上下文具有可接受见证,得出其一致性;开始证明。\n\n\n **L30** 引入任意问题 q,以及假定的同一上下文中正反后果对 h。\n\n\n **L31** 从显式非空前提 inhabited 提取共同可接受世界 w,以及它满足整套理论、假设与范围的证明 hw。\n\n\n **L32** 在同一 w 与 hw 处应用 h 的两部分;否定后果与肯定后果矛盾。\n\n\n **L33** 说明 emptyTheory 的预定范围。对应声明涉及:不选择任何主张,故每个世界都是模型。 该注释用于解释,不是证明前提。\n\n\n **L34** 定义 emptyTheory。不选择任何主张,故每个世界都是模型。\n\n\n **L35** 定义 singleton。只选择与指定主张相等的谓词。\n\n\n **L36** 定义 union。以成员关系的析取合并两个理论。\n\n\n **L37** 陈述经检查的结果 modelsSingleton。证明满足单一主张理论等价于该主张在当前世界成立。 后续策略块证明这一显式类型。\n\n\n **L38** 将满足单一主张理论与满足该主张的等价关系拆为两个蕴含。\n\n\n **L39** 把假定的单元素理论模型 h 应用于 p;p 的成员关系由自反相等成立。\n\n\n **L40** 任取被选择的主张 q,单元素成员关系将 q 与 p 等同;代入这一等式并返回 p 已成立的前提 h。\n\n\n **L41** 陈述经检查的结果 modelsUnion。证明同一世界满足理论并集等价于同时满足两部分。\n\n\n **L42** 陈述同一世界满足理论并集,当且仅当它满足两个组成理论。\n\n\n **L43** 分别证明满足并集与同时满足两个理论之间的正反方向。\n\n\n **L44** 把成员证明嵌入左或右析取,将并集模型 h 分别限制到两个理论。\n\n\n **L45** 拆出两个组成理论的模型,将并集成员关系分为两种情况,并在同一主张与世界上使用对应模型。\n\n\n **L46** 说明 premiseP 的预定范围。对应声明涉及:要求布尔对的第一坐标为真。 该注释用于解释,不是证明前提。\n\n\n **L47** 定义 premiseP。要求布尔对的第一坐标为真。\n\n\n **L48** 定义 premiseRule。要求第一坐标为真时第二坐标也为真。\n\n\n **L49** 定义 premiseNotQ。要求第二坐标不为真。\n\n\n **L50** 定义 jointTheory。组合第一坐标事实、推论规则和第二坐标的否定。\n\n\n **L51** 通过嵌套理论并集,同时持有 P、P 蕴含 Q 的规则及非 Q。\n\n\n **L52** 说明 jointConflict 的预定范围。对应声明涉及:三个单项各自有模型,联合后以P及P→Q反驳¬Q,证明无共同模型。 该注释用于解释,不是证明前提。\n\n\n **L53** 陈述经检查的结果 jointConflict。三个单项各自有模型,联合后以P及P→Q反驳¬Q,证明无共同模型。\n\n\n **L54** 前两个结论分别为 P 与蕴含规则提供模型。\n\n\n **L55** 还要求非 Q 单独有模型,却否定整套联合理论具有模型。\n\n\n **L56** 给 P 提供模型 (true,true),用 modelsSingleton 将第一坐标相等转换为所需模型证明。\n\n\n **L57** 给蕴含前提提供模型 (false,false):其第一坐标为 false,假定它为 true 即矛盾。\n\n\n **L58** 给非 Q 提供模型 (false,false),留下联合不可满足分支待证。\n\n\n **L59** 假定存在联合模型 w 及证明 hw,以反驳其存在。\n\n\n **L60** 利用 P 在联合理论中的左侧成员关系,提取实际第一坐标事实。\n\n\n **L61** 通过规则在嵌套并集中的成员关系,提取 P 蕴含 Q。\n\n\n **L62** 在同一世界,从另一个嵌套并集分支提取非 Q。\n\n\n **L63** 将规则应用于 P 得到 Q,与已提取的非 Q 矛盾。\n\n\n **L64** 说明 revisionSlice 的预定范围。对应声明涉及:时刻零选择真世界,其他自然数时刻选择假世界。 该注释用于解释,不是证明前提。\n\n\n **L65** 定义 revisionSlice。时刻零选择真世界,其他自然数时刻选择假世界。\n\n\n **L66** 只选择一个主张:世界等于测试 time=0 所得布尔值。\n\n\n **L67** 说明 revisionCanReverse 的预定范围。对应声明涉及:给旧新切片各自的模型,并以真与假不可相等证明二者联合冲突。 该注释用于解释,不是证明前提。\n\n\n **L68** 陈述经检查的结果 revisionCanReverse。给旧新切片各自的模型,并以真与假不可相等证明二者联合冲突。\n\n\n **L69** 要求时间切片 0 与 1 各自具有模型见证。\n\n\n **L70** 否定两者同时并集的模型,而不否定各自见证。\n\n\n **L71** 给时间零的单元素理论提供 true 见证。\n\n\n **L72** 给时间一提供 false 见证,留下同时持有两个切片不可能的证明。\n\n\n **L73** 假定一个世界同时满足两个时间切片。\n\n\n **L74** 把并集模型拆为同一世界中的时间零与时间一模型。\n\n\n **L75** 从时间零单元素理论提取共同世界等于 true。\n\n\n **L76** 从时间一单元素理论提取同一世界等于 false。\n\n\n **L77** 经由同一世界合成两个等式,推出不可能的 true = false。\n\n\n **L78** 消去两个不同布尔构造子之间的不可能等式。\n\n\n **L79** 说明 onQuestion 的预定范围。对应声明涉及:唯一Unit问题询问布尔世界是否为真。 该注释用于解释,不是证明前提。\n\n\n **L80** 定义 onQuestion。唯一Unit问题询问布尔世界是否为真。\n\n\n **L81** 定义 assumptionContext。固定问题与全范围,只改变选择世界的假设。\n\n\n **L82** 通过假设选择世界 b,保留相同开启问题,并令范围允许所有世界。\n\n\n **L83** 定义 meaningContext。固定真世界假设,只改变问题的等值含义。\n\n\n **L84** 保持真世界假设,改为询问与 b 相等;范围仍不受限。\n\n\n **L85** 定义 scopeContext。固定空假设和问题,只由范围选择世界。\n\n\n **L86** 使假设为空且问题固定,仅让范围选择世界 b。\n\n\n **L87** 说明 contextDifferences 的预定范围。对应声明涉及:分别改变假设、含义、范围得到相反判断;所有展示上下文都有明确可接受世界。 该注释用于解释,不是证明前提。\n\n\n **L88** 陈述经检查的结果 contextDifferences。分别改变假设、含义、范围得到相反判断;所有展示上下文都有明确可接受世界。\n\n\n **L89** 要求在真值假设下给出肯定答案。\n\n\n **L90** 要求在假值假设下给出否定答案;两者上下文不同。\n\n\n **L91** 要求对含义为等于 true 的问题给出肯定答案。\n\n\n **L92** 当同一问题改为表示等于 false 时,要求否定答案。\n\n\n **L93** 要求在限制为 true 的范围内给出肯定答案。\n\n\n **L94** 要求在另一个限制为 false 的范围内给出否定答案。\n\n\n **L95** 对任一假设选择,要求实际可接受世界存在。\n\n\n **L96** 对任一问题含义,要求实际可接受世界存在。\n\n\n **L97** 对任一范围选择,要求实际可接受世界存在,并开始组合证明。\n\n\n **L98** 证明每个布尔世界都满足 emptyTheory,因为该理论的成员关系为 False。\n\n\n **L99** 拆分改变假设、含义和范围后的正反答案对,以及三类上下文的非空见证义务。\n\n\n **L100** 在真值假设上下文中,从单元素上下文假设读出 w = true。\n\n\n **L101** 在假值假设上下文中,假定肯定答案会与单元素假设 w = false 矛盾。\n\n\n **L102** 当问题含义为真值时,用固定的真世界假设确立肯定答案。\n\n\n **L103** 当问题含义变为假值时,假定该含义成立会与不变的真世界假设矛盾。\n\n\n **L104** 在真值范围上下文中,范围组件本身给出所需肯定答案。\n\n\n **L105** 在假值范围上下文中,肯定答案与同一世界的范围组件矛盾。\n\n\n **L106** 对任一假设 b,世界 b 满足空的所持理论、该单元素假设与不受限范围。\n\n\n **L107** 对任一问题含义 b,true 仍为见证,因为假设固定为 true 且范围不受限。\n\n\n **L108** 对任一范围选择 b,世界 b 满足两个空理论,并通过相等满足所选范围。\n\n\n **L109** 说明 Snapshot 的预定范围。对应声明涉及:保存同时持有理论、上下文和独立修订标识,不实现历史验证。 该注释用于解释,不是证明前提。\n\n\n **L110** 声明数据接口 Snapshot。保存同时持有理论、上下文和独立修订标识,不实现历史验证。\n\n\n **L111** 在快照中保存同时持有主张的理论。\n\n\n **L112** 以一个 Context 保存快照的假设、问题含义与范围。\n\n\n **L113** 保存独立的自然数修订标识,不蕴含历史验证。\n\n\n **L114** 说明 SameContent 的预定范围。对应声明涉及:比较理论成员、附加假设成员及逐问题逐世界的含义和范围。 该注释用于解释,不是证明前提。\n\n\n **L115** 定义 SameContent。比较理论成员、附加假设成员及逐问题逐世界的含义和范围。\n\n\n **L116** 要求两个快照中每个所持主张的成员关系一致。\n\n\n **L117** 要求每个上下文假设的成员关系一致。\n\n\n **L118** 要求每个问题在每个世界具有等价含义。\n\n\n **L119** 要求每个世界中的范围谓词等价。\n\n\n **L120** 说明 TruthfulReport 的预定范围。对应声明涉及:内容或修订标识变化时必须报告真;不要求报告真必然有变化,也不检测变化。 该注释用于解释,不是证明前提。\n\n\n **L121** 定义 TruthfulReport。内容或修订标识变化时必须报告真;不要求报告真必然有变化,也不检测变化。\n\n\n **L122** 将如实报告定义为:内容不同或独立修订标识不同,就给出积极标记。\n\n\n **L123** 说明 semanticChangeMustBeReported 的预定范围。对应声明涉及:把给定变化证据应用于给定报告规范,得到报告为真。 该注释用于解释,不是证明前提。\n\n\n **L124** 陈述经检查的结果 semanticChangeMustBeReported。把给定变化证据应用于给定报告规范,得到报告为真。\n\n\n **L125** 假定实际发生变更:内容不同或修订标识不同。\n\n\n **L126** 假定报告义务,并应用于前述变更前提,得到 reported=true。\n\n\n **L127** 说明 representationOrderIrrelevant 的预定范围。对应声明涉及:用析取交换律证明两个单项理论交换顺序不改变成员关系。 该注释用于解释,不是证明前提。\n\n\n **L128** 陈述经检查的结果 representationOrderIrrelevant。用析取交换律证明两个单项理论交换顺序不改变成员关系。\n\n\n **L129** 对任意主张 r,交换 p 与 q 保持其单元素理论并集中的成员关系。\n\n\n **L130** 任取候选主张 r,利用析取交换性证明重排 p 与 q 后并集成员关系不变。\n\n\n **L131** 定义 contextSnapshot。将上下文包装成空持有理论的快照,默认修订标识为零。\n\n\n **L132** 构造所持主张为空、采用给定上下文及修订标识的快照。\n\n\n **L133** 说明 hiddenContextChangeRejected 的预定范围。对应声明涉及:分别拒绝隐瞒假设、含义、范围及标识变化,并说明报告变化不保证新假设为真。 该注释用于解释,不是证明前提。\n\n\n **L134** 陈述经检查的结果 hiddenContextChangeRejected。分别拒绝隐瞒假设、含义、范围及标识变化,并说明报告变化不保证新假设为真。\n\n\n **L135** 实际上下文假设从 true 变为 false 时,拒绝 false 报告。\n\n\n **L136** 问题实际含义改变时,拒绝 false 报告。\n\n\n **L137** 实际应用范围改变时,拒绝 false 报告。\n\n\n **L138** 上下文不变但修订身份从 0 变为 1 时,拒绝 false 报告。\n\n\n **L139** 允许以 true 报告如实承认假设变化。\n\n\n **L140** 但否定这些修订后的假世界假设在实际 true 处成立。\n\n\n **L141** 准备语义不等式:选择 true 与选择 false 的谓词是不同函数。\n\n\n **L142** 在 true 处计算假定的谓词相等,它会把自反成立转换为 true = false。\n\n\n **L143** 拆出四种被拒绝的隐瞒变更,以及最后已报告但假设为假的实例。\n\n\n **L144** 假定隐瞒假设变化且报告为 false 仍满足 TruthfulReport,以反驳这一主张。\n\n\n **L145** 假定 SameContent 会使已改变的假设谓词相等;已知其不等,因此触发 TruthfulReport,迫使 false 标记为 true。\n\n\n **L146** 所需 true 报告与指定的 false 标记矛盾,因此结束这一隐瞒变更分支。\n\n\n **L147** 假定问题含义改变后仍可如实报告为未改变。\n\n\n **L148** 在唯一问题与 true 世界处,变化后的含义否定 SameContent;报告义务因而要求积极报告。\n\n\n **L149** 所需 true 报告与指定的 false 标记矛盾,因此结束这一隐瞒变更分支。\n\n\n **L150** 假定应用范围改变后仍能以 false 变更标记满足报告规则。\n\n\n **L151** 在 true 处比较两个范围以否定 SameContent,再对这一真实范围变化应用报告义务。\n\n\n **L152** 所需 true 报告与指定的 false 标记矛盾,因此结束这一隐瞒变更分支。\n\n\n **L153** 不同修订身份本身就触发报告规则;即使没有内容变化,也与 false 报告矛盾。\n\n\n **L154** 构造始终积极的如实报告,另留下修订假设真实性的反证。\n\n\n **L155** 在实际世界 true 提取修订后的假世界假设;其不可能等式表明报告变更不使假设变真。\n\n\n **L156** 说明 tensionWithoutContradiction 的预定范围。对应声明涉及:预算五同时满足不同上下界;预算零证明两约束谓词并不相同。 该注释用于解释,不是证明前提。\n\n\n **L157** 陈述经检查的结果 tensionWithoutContradiction。预算五同时满足不同上下界;预算零证明两约束谓词并不相同。\n\n\n **L158** 要求存在同时满足下界 4 与上界 6 的自然数预算。\n\n\n **L159** 还断言两个界限谓词不同,即使它们可以共同满足。\n\n\n **L160** 选择预算 5,检查两个数值界限,留下两个目标谓词不同的证明。\n\n\n **L161** 在预算 0 处,上界成立而下界不可能成立,因此两个目标谓词不相等。\n\n\n **L162** 说明 conflictRequiresChange 的预定范围。对应声明涉及:同题同条件正反后果违反一致性规范;不构造具体修复算法。 该注释用于解释,不是证明前提。\n\n\n **L163** 陈述经检查的结果 conflictRequiresChange。同题同条件正反后果违反一致性规范;不构造具体修复算法。\n\n\n **L164** 假定同一理论、上下文与问题具有两个相反后果。\n\n\n **L165** 任何 Consistent 证明都禁止给定后果对;应用这一点否定一致性,并未构造修订。\n\n\n **L166** 说明 consistentFalse 的预定范围。对应声明涉及:理论有真世界模型,却在指定假世界不成立,区分可满足与实际真。 该注释用于解释,不是证明前提。\n\n\n **L167** 陈述经检查的结果 consistentFalse。理论有真世界模型,却在指定假世界不成立,区分可满足与实际真。\n\n\n **L168** 否定实际 false 满足唯一主张为 world=true 的理论。\n\n\n **L169** 提供 true 作为单元素理论的模型,另行否定实际世界 false 满足该理论。\n\n\n **L170** 在 false 处满足单元素理论会迫使 false = true,产生不可能的布尔等式。\n\n\n **L171** 说明 consistentIncomplete 的预定范围。对应声明涉及:空理论有模型,但指定布尔问题及其否定都不被蕴涵。 该注释用于解释,不是证明前提。\n\n\n **L172** 陈述经检查的结果 consistentIncomplete。空理论有模型,但指定布尔问题及其否定都不被蕴涵。\n\n\n **L173** 具有见证的空理论不蕴含肯定的真世界答案。\n\n\n **L174** 它也不蕴含否定的真世界答案;分别证明这两个失败。\n\n\n **L175** 证明每个布尔世界都满足 emptyTheory,因为该理论的成员关系为 False。\n\n\n **L176** 提供非空的空理论模型,留下肯定与否定蕴含两个反证。\n\n\n **L177** 假定蕴含 world=true,会在空理论模型 false 处失败。\n\n\n **L178** 假定蕴含 world≠true,会在空理论模型 true 处失败。\n\n\n **L179** 说明 compatibilityNotEntailment 的预定范围。对应声明涉及:新增主张可以与原理论相容,但原理论仍不蕴涵该主张。 该注释用于解释,不是证明前提。\n\n\n **L180** 陈述经检查的结果 compatibilityNotEntailment。新增主张可以与原理论相容,但原理论仍不蕴涵该主张。\n\n\n **L181** 要求存在使 emptyTheory 与肯定单元素主张共同成立的模型。\n\n\n **L182** 仍否定 emptyTheory 本身蕴含该肯定主张。\n\n\n **L183** 用世界 true 见证空理论与肯定的单元素主张相容。\n\n\n **L184** 复用已证的空理论不能蕴含肯定主张的结果。\n\n\n **L185** 完成模型见证:没有主张能够实际属于 emptyTheory。\n\n\n **L187** 关闭命名空间 CoreReader.Logic;这不增加证明或前提。\n\n\n### `leanified/CoreReader/Reflexivity.lean`\n\n\n```lean\nimport Std\n\nnamespace CoreReader.Agency\n\ninductive Phase | formation | application | revision\n deriving DecidableEq, Repr\n\nstructure PrincipleKey where\n owner : Nat\n localId : Nat\n deriving DecidableEq, Repr\n\ninductive Subject\n | system (owner : Nat)\n | principle (owner id : Nat)\n | process (owner id : Nat) (phase : Phase)\n deriving DecidableEq, Repr\n\ndef Subject.owner : Subject → Nat\n | .system n => n\n | .principle n _ => n\n | .process n _ _ => n\n\ninductive Activity | generation | assessment\n deriving DecidableEq, Repr\n\ninductive QuestionKind | conformity | formationBasis | applicability | revisionGrounds\n deriving DecidableEq, Repr\n\ninductive SampleProgram | alwaysTrue | onlyAtZero\n deriving DecidableEq, Repr\n\ndef SampleProgram.run : SampleProgram → Nat → Bool\n | .alwaysTrue, _ => true\n | .onlyAtZero, n => n == 0\n\n/- A generated candidate specifies both the inputs it tests and the scope it proposes to license. -/\nstructure MethodDraft where\n testedInputs : List Nat\n claimedScope : List Nat\n deriving DecidableEq, Repr\n\ndef MethodDraft.accepts (draft : MethodDraft) (program : SampleProgram) : Bool :=\n draft.testedInputs.all program.run\n\n/- This finite application asks whether a proposed rule's observed inputs support its claimed input scope. -/\nstructure Inquiry where\n target : Subject\n kind : QuestionKind\n requestedScope : List Nat\n currentMethod : MethodDraft\n deriving DecidableEq, Repr\n\ninductive ReasonContent\n | purpose (inputs : List Nat)\n | declaredScope (inputs : List Nat)\n | observation (input : Nat) (output : Bool)\n | counterexample (program : SampleProgram) (input : Nat)\n deriving DecidableEq, Repr\n\ndef ReasonContent.identifier : ReasonContent → Nat\n | .purpose _ => 0\n | .declaredScope _ => 1\n | .observation _ _ => 2\n | .counterexample _ _ => 3\n\n/- Reasons have independently supplied contents, a stable local reference and the actual target they concern. -/\nstructure ReasonObject where\n reference : Nat\n target : Subject\n content : ReasonContent\n deriving DecidableEq, Repr\n\ninductive AssessmentResult | supportedWithinScope | insufficient | notApplicable | undetermined\n deriving DecidableEq, Repr\n\ninductive WorkOutcome\n | assessment (result : AssessmentResult)\n | generated (draft : MethodDraft)\n deriving DecidableEq, Repr\n\n/- A method's question, source reasons and limits are determined before looking at its activity records.\nThe meaning relation describes application of that method, not its universal adequacy. -/\nstructure Principle where\n key : PrincipleKey\n activity : Activity\n declaredMethod : MethodDraft\n applicable : Subject → Prop\n inquiry : Subject → Inquiry\n reasons : Subject → List ReasonObject\n limits : Subject → List Nat\n meaning : Inquiry → List ReasonObject → List Nat → WorkOutcome → Prop\n\nstructure WorkRecord where\n usedPrinciple : PrincipleKey\n target : Subject\n activity : Activity\n inquiry : Inquiry\n reasons : List ReasonObject\n limits : List Nat\n outcome : WorkOutcome\n deriving DecidableEq, Repr\n\ndef RegistryCoherent (rules : List Principle) : Prop :=\n ∀ p ∈ rules, ∀ q ∈ rules, p.key = q.key → p = q\n\ndef TargetResolved (rules : List Principle) : Subject → Prop\n | .system owner => ∃ p ∈ rules, p.key.owner = owner\n | .principle owner id | .process owner id _ => ∃ p ∈ rules, p.key = ⟨owner,id⟩\n\n/- The inquiry names the registered target's declared method contract, not an unrelated candidate.\nFor a system inquiry this finite model uses the registered generation contract as its assessed artifact. -/\ndef TargetContentResolved (rules : List Principle) (question : Inquiry) : Prop :=\n match question.target with\n | .system owner => ∃ p ∈ rules, p.key = ⟨owner,0⟩ ∧ question.currentMethod = p.declaredMethod\n | .principle owner id | .process owner id _ =>\n ∃ p ∈ rules, p.key = ⟨owner,id⟩ ∧ question.currentMethod = p.declaredMethod\n\ndef Performed (records : List WorkRecord) (s : Subject) (a : Activity) : Prop :=\n ∃ record ∈ records, record.target = s ∧ record.activity = a\n\n/- The old scope condition remains available without conflating scope with content completion. -/\ndef ReflexiveScope (owner : Nat) (rules : List Principle) (records : List WorkRecord) : Prop :=\n ∀ rule ∈ rules, ∀ s, s.owner = owner → rule.applicable s → Performed records s rule.activity\n\n/- A record uses a registered principle on the same resolvable target, question, reasons and limits,\nand its result must actually follow that principle's method. A negative result can satisfy this relation. -/\nstructure ValidApplication (rules : List Principle) (rule : Principle) (s : Subject)\n (record : WorkRecord) : Prop where\n registered : rule ∈ rules\n applicable : rule.applicable s\n usedIdentity : record.usedPrinciple = rule.key\n targetIdentity : record.target = s\n targetResolved : TargetResolved rules s\n activityIdentity : record.activity = rule.activity\n inquiryIdentity : record.inquiry = rule.inquiry s\n inquiryTarget : record.inquiry.target = s\n targetContent : TargetContentResolved rules record.inquiry\n reasonsIdentity : record.reasons = rule.reasons s\n reasonsNonempty : record.reasons ≠ []\n reasonTargets : ∀ reason ∈ record.reasons, reason.target = s\n limitsIdentity : record.limits = rule.limits s\n followsMeaning : rule.meaning record.inquiry record.reasons record.limits record.outcome\n\n/- The registered normative interface requires contentful application, not just activity labels. -/\ndef Reflexive (owner : Nat) (rules : List Principle) (records : List WorkRecord) : Prop :=\n RegistryCoherent rules ∧\n ∀ rule ∈ rules, ∀ s, s.owner = owner → rule.applicable s →\n ∃ record ∈ records, ValidApplication rules rule s record\n\ntheorem Reflexive.toScope {owner : Nat} {rules : List Principle} {records : List WorkRecord}\n (h : Reflexive owner rules records) : ReflexiveScope owner rules records := by\n intro rule hr s hs ha\n obtain ⟨record, hm, hv⟩ := h.2 rule hr s hs ha\n exact ⟨record, hm, hv.targetIdentity, hv.activityIdentity⟩\n\ntheorem noSelfExemption (owner : Nat) (rules : List Principle) (records : List WorkRecord)\n (h : Reflexive owner rules records) (rule : Principle) (hr : rule ∈ rules)\n (s : Subject) (hs : s.owner = owner) (ha : rule.applicable s) :\n Performed records s rule.activity := h.toScope rule hr s hs ha\n\ndef localMethod : MethodDraft := ⟨[0],[0]⟩\n\ndef inquiryFor (s : Subject) : Inquiry :=\n match s with\n | .process _ _ .formation => ⟨s, .formationBasis, [0], localMethod⟩\n | .process _ _ .application => ⟨s, .applicability, [0], localMethod⟩\n | .process _ _ .revision => ⟨s, .revisionGrounds, [0,1], localMethod⟩\n | _ => ⟨s, .conformity, [0], localMethod⟩\n\n/- These original inquiry inputs do not depend on which work records happen to be present. -/\ndef sourceReasonContents : QuestionKind → List ReasonContent\n | .formationBasis => [.purpose [0], .declaredScope [0], .observation 0 true]\n | .applicability | .conformity => [.declaredScope [0], .observation 0 true]\n | .revisionGrounds => [.purpose [0,1], .declaredScope [0], .observation 0 true,\n .counterexample .onlyAtZero 1]\n\ndef reasonsFor (s : Subject) : List ReasonObject :=\n (sourceReasonContents (inquiryFor s).kind).map fun content => ⟨content.identifier,s,content⟩\n\n/- The application-specific evaluator examines actual scope and sample/counterexample contents.\nIt is a finite inferential method, not a universal standard for empirical or value claims. -/\ndef assessInquiry (question : Inquiry) (reasons : List ReasonObject) (limits : List Nat) : AssessmentResult :=\n let contents := reasons.map ReasonObject.content\n if limits ≠ question.currentMethod.claimedScope then .undetermined else\n match question.kind with\n | .formationBasis =>\n if ReasonContent.purpose question.requestedScope ∈ contents ∧\n ReasonContent.declaredScope limits ∈ contents ∧ question.requestedScope = limits\n then .supportedWithinScope else .undetermined\n | .applicability | .conformity =>\n if question.requestedScope.all (fun n => limits.contains n) then\n if ReasonContent.declaredScope limits ∈ contents ∧\n ReasonContent.observation 0 true ∈ contents ∧ question.requestedScope = [0]\n then .supportedWithinScope else .undetermined\n else .notApplicable\n | .revisionGrounds =>\n if ReasonContent.purpose question.requestedScope ∈ contents ∧\n ReasonContent.declaredScope limits ∈ contents ∧\n ReasonContent.observation 0 true ∈ contents ∧\n contents.any (fun reason => match reason with\n | .counterexample program input => question.requestedScope.contains input &&\n question.currentMethod.accepts program &&\n !(program.run input)\n | _ => false)\n then .insufficient else .undetermined\n\ndef finiteMethodResult (activity : Activity) (question : Inquiry)\n (reasons : List ReasonObject) (limits : List Nat) : WorkOutcome :=\n match activity with\n | .generation => .generated ⟨question.currentMethod.testedInputs,question.requestedScope⟩\n | .assessment => .assessment (assessInquiry question reasons limits)\n\ndef finiteMethodMeaning (activity : Activity) (question : Inquiry)\n (reasons : List ReasonObject) (limits : List Nat) (outcome : WorkOutcome) : Prop :=\n outcome = finiteMethodResult activity question reasons limits\n\ndef ownSubjects (owner : Nat) : List Subject :=\n [.system owner, .principle owner 0, .principle owner 1,\n .process owner 0 .formation, .process owner 0 .application, .process owner 0 .revision,\n .process owner 1 .formation, .process owner 1 .application, .process owner 1 .revision]\n\n/- Applying an existing rule is not a generation event in this application. -/\ndef generationEligible : Subject → Bool\n | .process _ _ .application => false\n | _ => true\n\ndef generatingRule (owner : Nat) : Principle where\n key := ⟨owner,0⟩\n activity := .generation\n declaredMethod := localMethod\n applicable s := s ∈ ownSubjects owner ∧ generationEligible s = true\n inquiry := inquiryFor\n reasons := reasonsFor\n limits _ := [0]\n meaning := finiteMethodMeaning .generation\n\ndef assessingRule (owner : Nat) : Principle where\n key := ⟨owner,1⟩\n activity := .assessment\n declaredMethod := localMethod\n applicable s := s ∈ ownSubjects owner\n inquiry := inquiryFor\n reasons := reasonsFor\n limits _ := [0]\n meaning := finiteMethodMeaning .assessment\n\ndef ownRules (owner : Nat) : List Principle := [generatingRule owner, assessingRule owner]\n\n/- Recorded verdicts are stated separately from the evaluator, so agreement has to be proved. -/\ndef statedOutcome (activity : Activity) (s : Subject) : WorkOutcome :=\n match activity with\n | .generation => .generated ⟨(inquiryFor s).currentMethod.testedInputs,(inquiryFor s).requestedScope⟩\n | .assessment => .assessment (match (inquiryFor s).kind with\n | .revisionGrounds => .insufficient\n | _ => .supportedWithinScope)\n\ndef recordFor (rule : Principle) (s : Subject) : WorkRecord :=\n ⟨rule.key,s,rule.activity,rule.inquiry s,rule.reasons s,rule.limits s,statedOutcome rule.activity s⟩\n\ntheorem reasonsFor_nonempty (s : Subject) : reasonsFor s ≠ [] := by\n cases s with\n | system owner => simp [reasonsFor, inquiryFor, sourceReasonContents]\n | principle owner id => simp [reasonsFor, inquiryFor, sourceReasonContents]\n | process owner id phase => cases phase <;> simp [reasonsFor, inquiryFor, sourceReasonContents]\n\ntheorem reasonsFor_target (s : Subject) : ∀ reason ∈ reasonsFor s, reason.target = s := by\n intro reason h\n obtain ⟨content, _, rfl⟩ := List.mem_map.mp h\n rfl\n\ntheorem inquiryFor_target (s : Subject) : (inquiryFor s).target = s := by\n cases s with\n | system owner => rfl\n | principle owner id => rfl\n | process owner id phase => cases phase <;> rfl\n\n/- This proof includes the actual negative revision evaluation for both principle identities. -/\ntheorem ownContentEvaluates (activity : Activity) (s : Subject) :\n statedOutcome activity s = finiteMethodResult activity (inquiryFor s) (reasonsFor s) [0] := by\n cases activity with\n | generation => rfl\n | assessment =>\n cases s with\n | system owner => rfl\n | principle owner id => rfl\n | process owner id phase => cases phase <;> rfl\n\ntheorem ownRegistryCoherent (owner : Nat) : RegistryCoherent (ownRules owner) := by\n intro p hp q hq hkey\n simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hp hq\n rcases hp with rfl | rfl <;> rcases hq with rfl | rfl\n · rfl\n · have bad := congrArg PrincipleKey.localId hkey; contradiction\n · have bad := congrArg PrincipleKey.localId hkey; contradiction\n · rfl\n\ntheorem ownTargetResolved (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) :\n TargetResolved (ownRules owner) s := by\n simp only [ownSubjects, List.mem_cons, List.not_mem_nil, or_false] at hs\n rcases hs with rfl | rfl | rfl | rfl | rfl | rfl | rfl | rfl | rfl <;>\n simp [TargetResolved, ownRules, generatingRule, assessingRule]\n\ntheorem ownTargetContent (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) :\n TargetContentResolved (ownRules owner) (inquiryFor s) := by\n simp only [ownSubjects, List.mem_cons, List.not_mem_nil, or_false] at hs\n rcases hs with rfl | rfl | rfl | rfl | rfl | rfl | rfl | rfl | rfl <;>\n simp [TargetContentResolved, inquiryFor, ownRules, generatingRule, assessingRule]\n\ntheorem ownRecordValid (owner : Nat) (rule : Principle) (hr : rule ∈ ownRules owner)\n (s : Subject) (ha : rule.applicable s) :\n ValidApplication (ownRules owner) rule s (recordFor rule s) := by\n have hs : s ∈ ownSubjects owner := by\n simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr\n rcases hr with rfl | rfl\n · exact ha.1\n · exact ha\n have hq : rule.inquiry = inquiryFor := by\n simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr\n rcases hr with rfl | rfl <;> rfl\n have hg : rule.reasons = reasonsFor := by\n simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr\n rcases hr with rfl | rfl <;> rfl\n have hl : rule.limits s = [0] := by\n simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr\n rcases hr with rfl | rfl <;> rfl\n have hm : rule.meaning = finiteMethodMeaning rule.activity := by\n simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr\n rcases hr with rfl | rfl <;> rfl\n refine ⟨hr, ha, rfl, rfl, ownTargetResolved owner s hs, rfl, rfl, ?_, ?_, rfl, ?_, ?_, rfl, ?_⟩\n · change (rule.inquiry s).target = s\n rw [hq]; exact inquiryFor_target s\n · change TargetContentResolved (ownRules owner) (rule.inquiry s)\n rw [hq]; exact ownTargetContent owner s hs\n · change rule.reasons s ≠ []\n rw [hg]; exact reasonsFor_nonempty s\n · change ∀ reason ∈ rule.reasons s, reason.target = s\n rw [hg]; exact reasonsFor_target s\n · change rule.meaning (rule.inquiry s) (rule.reasons s) (rule.limits s) (statedOutcome rule.activity s)\n rw [hm, hq, hg, hl]\n exact ownContentEvaluates rule.activity s\n\ndef completeOwnWork (owner : Nat) : List WorkRecord :=\n (ownSubjects owner).flatMap fun s =>\n if generationEligible s then [recordFor (generatingRule owner) s, recordFor (assessingRule owner) s]\n else [recordFor (assessingRule owner) s]\n\ntheorem assessingRecord_member (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) :\n recordFor (assessingRule owner) s ∈ completeOwnWork owner := by\n apply List.mem_flatMap.mpr\n refine ⟨s,hs,?_⟩\n cases generationEligible s <;> simp\n\ntheorem generatingRecord_member (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner)\n (hg : generationEligible s = true) : recordFor (generatingRule owner) s ∈ completeOwnWork owner := by\n exact List.mem_flatMap.mpr ⟨s,hs,by simp [hg]⟩\n\ntheorem completeOwnWork_reflexive (owner : Nat) :\n Reflexive owner (ownRules owner) (completeOwnWork owner) := by\n refine ⟨ownRegistryCoherent owner, ?_⟩\n intro rule hr s _ ha\n refine ⟨recordFor rule s, ?_, ownRecordValid owner rule hr s ha⟩\n simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr\n rcases hr with rfl | rfl\n · exact generatingRecord_member owner s ha.1 ha.2\n · exact assessingRecord_member owner s ha\n\ntheorem ownAssessmentPerformed (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) :\n Performed (completeOwnWork owner) s .assessment :=\n ⟨recordFor (assessingRule owner) s, assessingRecord_member owner s hs, rfl, rfl⟩\n\ndef applicationRule : Principle :=\n { assessingRule 0 with key := ⟨0,0⟩, applicable := fun s => s = .process 0 0 .application }\n\ndef applicationWork : List WorkRecord := [recordFor applicationRule (.process 0 0 .application)]\n\ntheorem applicationWork_reflexive : Reflexive 0 [applicationRule] applicationWork := by\n constructor\n · intro p hp q hq _\n simp only [List.mem_singleton] at hp hq\n rw [hp,hq]\n · intro rule hr s _ ha\n simp only [List.mem_singleton] at hr\n subst rule\n change s = .process 0 0 .application at ha\n subst s\n refine ⟨recordFor applicationRule (.process 0 0 .application), by simp [applicationWork], ?_⟩\n refine ⟨by simp, rfl, rfl, rfl, ?_, rfl, rfl, rfl, ?_, rfl, ?_, ?_, rfl, ?_⟩\n · exact ⟨applicationRule, by simp, rfl⟩\n · exact ⟨applicationRule, by simp, rfl, rfl⟩\n · exact reasonsFor_nonempty _\n · exact reasonsFor_target _\n · change statedOutcome .assessment (.process 0 0 .application) = finiteMethodResult .assessment (inquiryFor (.process 0 0 .application)) (reasonsFor (.process 0 0 .application)) [0]\n exact ownContentEvaluates .assessment _\n\ntheorem applicabilityRetained (owner : Nat) (rules : List Principle) (records : List WorkRecord) :\n (Reflexive owner rules records → ReflexiveScope owner rules records) ∧\n (ReflexiveScope owner rules records ↔\n ∀ rule ∈ rules, ∀ s, s.owner = owner → (¬ rule.applicable s ∨ Performed records s rule.activity)) ∧\n (Reflexive 0 [applicationRule] applicationWork ∧\n ¬ Performed applicationWork (.system 0) .assessment) := by\n classical\n refine ⟨Reflexive.toScope, ?_, applicationWork_reflexive, ?_⟩\n · constructor\n · intro h rule hr s hs\n by_cases ha : rule.applicable s\n · exact Or.inr (h rule hr s hs ha)\n · exact Or.inl ha\n · intro h rule hr s hs ha\n exact (h rule hr s hs).resolve_left (not_not_intro ha)\n · rintro ⟨record, hm, ht, _⟩\n simp only [applicationWork, List.mem_singleton] at hm\n subst record\n cases ht\n\nend CoreReader.Agency\n```\n\n\n\n **L1** 导入Std及其依赖。\n\n\n **L3** 打开命名空间CoreReader.Agency;文件边界不改变声明身份。\n\n\n **L5** 定义形成、应用和修订三个阶段标签。\n\n\n **L6** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L8** 用所属主体和局部编号标识登记原则。\n\n\n **L9** 保存所属主体编号。\n\n\n **L10** 保存主体内部原则编号。\n\n\n **L11** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L13** 区分系统、原则及带阶段的原则过程对象。\n\n\n **L14** 用所有者编号表示系统自身。\n\n\n **L15** 用所有者及局部原则编号表示某项原则。\n\n\n **L16** 把该原则的形成、应用或修订过程表示为独立对象。\n\n\n **L17** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L19** 从各类主体对象中提取所属主体编号。\n\n\n **L20** 直接从系统对象提取所有者。\n\n\n **L21** 提取原则所有者,忽略局部编号。\n\n\n **L22** 提取过程对象所有者,不受原则编号和阶段影响。\n\n\n **L24** 区分生成工作与评估工作。\n\n\n **L25** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L27** 分别表示合规、形成根据、适用性和修订根据问题。\n\n\n **L28** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L30** 提供恒真程序及仅在零处为真的程序。\n\n\n **L31** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L33** 在自然数输入上计算两种样例程序。\n\n\n **L34** alwaysTrue样例程序接受每个自然数输入。\n\n\n **L35** onlyAtZero程序仅在输入0时返回true。\n\n\n **L37** 说明后续定义或结果:分别保存测试输入和声称范围,以表示超出测试的主张。\n\n\n **L38** 分别保存测试输入和声称范围,以表示超出测试的主张。\n\n\n **L39** 记录该方法草案实际测试程序的输入。\n\n\n **L40** 另记录该草案拟授权的输入范围。\n\n\n **L41** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L43** 程序通过列表中全部测试即被接受,未测试输入不被检查。\n\n\n **L44** 所有已测试输入返回true时接受程序;此处不检查claimedScope。\n\n\n **L46** 说明后续定义或结果:将目标对象与问题种类、请求范围和目标当前方法内容相连。\n\n\n **L47** 将目标对象与问题种类、请求范围和目标当前方法内容相连。\n\n\n **L48** 标识正在考察其方法的确切对象。\n\n\n **L49** 区分符合性、形成理由、适用性和修订理由四类问题。\n\n\n **L50** 记录此问题要求方法覆盖的输入范围。\n\n\n **L51** 附上实际待考察方法草案,包括测试输入和声称范围。\n\n\n **L52** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L54** 表示目的、声明范围、观察以及具体程序和输入反例。\n\n\n **L55** 目的理由指定方法意欲处理的输入。\n\n\n **L56** 范围理由陈述方法声明的输入限度。\n\n\n **L57** 观察理由记录具体输入和布尔输出。\n\n\n **L58** 反例理由指定待检查的实际样例程序与输入。\n\n\n **L59** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L61** 给理由构造器分配编号;编号本身不提供根据。\n\n\n **L62** 目的理由使用局部引用0;它是类别编号,不是全局唯一标识。\n\n\n **L63** 声明范围理由使用局部引用1。\n\n\n **L64** 观察理由使用局部引用2。\n\n\n **L65** 反例理由使用局部引用3。\n\n\n **L67** 说明后续定义或结果:把理由内容和引用编号绑定到其所针对对象。\n\n\n **L68** 把理由内容和引用编号绑定到其所针对对象。\n\n\n **L69** 保存该建模问题中此理由的局部引用。\n\n\n **L70** 标识该理由实际针对的对象。\n\n\n **L71** 保存理由的目的、范围、观察或反例内容。\n\n\n **L72** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L74** 允许范围内支持、不充分、不适用和未确定四种结果。\n\n\n **L75** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L77** 区分评估结果和生成的方法草案。\n\n\n **L78** 把判定包装为评估结果;负面判定仍是评估。\n\n\n **L79** 包装新生成的方法草案,不断言该草案正确。\n\n\n **L80** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L82** 说明后续定义或结果:登记规则身份、活动、方法内容、适用性、问题、理由、限度和结果语义。\n\n\n **L83** 说明后续定义或结果:登记规则身份、活动、方法内容、适用性、问题、理由、限度和结果语义。\n\n\n **L84** 登记规则身份、活动、方法内容、适用性、问题、理由、限度和结果语义。\n\n\n **L85** 为原则赋予所有者与局部编号,用于解析其记录。\n\n\n **L86** 规定该原则约束生成活动还是评估活动。\n\n\n **L87** 陈述该登记原则自身的方法草案。\n\n\n **L88** 规定该原则适用的对象。\n\n\n **L89** 为每个对象指定实际待考察问题。\n\n\n **L90** 为每个对象的问题指定所提供理由。\n\n\n **L91** 为每个对象的适用指定保留的输入限度。\n\n\n **L92** 定义结果何时遵循该原则的问题、理由与限度;仅此字段不保证方法充分。\n\n\n **L94** 记录实际应用的规则身份、目标、活动、问题、理由、限度和结果。\n\n\n **L95** 记录声称采用的确切登记原则标识。\n\n\n **L96** 记录该工作针对的对象。\n\n\n **L97** 记录此工作是生成还是评估。\n\n\n **L98** 保存该工作的具体问题记录。\n\n\n **L99** 保存该工作记录采用的具体理由。\n\n\n **L100** 保存该工作记录保留的输入限度。\n\n\n **L101** 保存记录的评估判定或生成的方法草案。\n\n\n **L102** 为前述数据类型生成可判定相等及显示实例。\n\n\n **L104** 要求相同登记键对应同一原则,排除身份歧义。\n\n\n **L105** 两项已登记原则若标识相同,就必须是同一原则,防止查找歧义。\n\n\n **L107** 要求评估目标能解析到登记主体或精确原则键。\n\n\n **L108** 登记表中存在同所有者原则时,该系统对象可解析。\n\n\n **L109** 原则和过程对象要求登记表中有确切所有者及局部编号对应项。\n\n\n **L111** 说明后续定义或结果:把问题中当前方法内容与登记目标原则的方法精确相连。\n\n\n **L112** 说明后续定义或结果:把问题中当前方法内容与登记目标原则的方法精确相连。\n\n\n **L113** 把问题中当前方法内容与登记目标原则的方法精确相连。\n\n\n **L114** 按问题实际目标的种类选择查找规则。\n\n\n **L115** 系统问题考察其所有者已登记原则0的声明方法。\n\n\n **L116** 对原则或其过程,按该目标实际所有者和编号查找。\n\n\n **L117** 要求确切标识查找成功,且问题所用方法等于登记原则的方法。\n\n\n **L119** 要求存在匹配目标和活动的实际记录;有效性另行检查。\n\n\n **L120** Performed要求存在目标和活动完全匹配的记录;它本身不检查理由内容。\n\n\n **L122** 说明后续定义或结果:保留受所属主体和适用性条件限制的记录覆盖接口。\n\n\n **L123** 保留受所属主体和适用性条件限制的记录覆盖接口。\n\n\n **L124** 对指定所有者的对象,每项适用的登记规则都须有对应活动记录。\n\n\n **L126** 说明后续定义或结果:检查登记与适用性、对象身份、目标方法内容、非空对应理由、限度及规则语义一致性。\n\n\n **L127** 说明后续定义或结果:检查登记与适用性、对象身份、目标方法内容、非空对应理由、限度及规则语义一致性。\n\n\n **L128** 检查登记与适用性、对象身份、目标方法内容、非空对应理由、限度及规则语义一致性。\n\n\n **L129** 以下证明字段确认这条特定工作记录是rule对s的有效适用。\n\n\n **L130** 要求记录采用的规则属于此登记表。\n\n\n **L131** 要求同一规则对待评对象适用。\n\n\n **L132** 核对记录所用原则标识与该规则确切标识相等。\n\n\n **L133** 检查工作记录针对的正是对象s。\n\n\n **L134** 要求记录对象能在同一规则登记表中解析。\n\n\n **L135** 检查记录活动正是该规则约束的活动。\n\n\n **L136** 检查记录问题等于该规则为s指定的问题。\n\n\n **L137** 另检查问题自身针对s,而非无关对象。\n\n\n **L138** 检查问题中的方法属于已解析的登记目标。\n\n\n **L139** 检查记录理由等于该规则为s指定的理由。\n\n\n **L140** 要求该记录至少包含一项实际理由。\n\n\n **L141** 要求每个记录理由都针对同一对象s。\n\n\n **L142** 检查记录限度等于该规则对s的限度。\n\n\n **L143** 要求记录结果满足该规则对问题、理由和限度的实际含义关系。\n\n\n **L145** 说明后续定义或结果:要求登记一致,且每条适用规则对同主体对象都有有效应用记录;仍是模型遵守条件。\n\n\n **L146** 要求登记一致,且每条适用规则对同主体对象都有有效应用记录;仍是模型遵守条件。\n\n\n **L147** Reflexive首先要求原则登记无歧义。\n\n\n **L148** 然后量化每项登记规则及其适用的自有对象。\n\n\n **L149** 对每次上述适用,都须存在通过全部ValidApplication内容检查的记录。\n\n\n **L151** 由完整反身性抽取目标和活动记录覆盖,不再保留内容有效性细节。\n\n\n **L152** 假设完整内容性Reflexive履责,推出较弱的仅范围覆盖。\n\n\n **L153** 为范围义务取已登记规则、自有对象及其适用前提。\n\n\n **L154** 用完整Reflexive履责取得实际列表记录及ValidApplication证明。\n\n\n **L155** 保留该记录的成员关系、目标一致与活动一致,证明Performed。\n\n\n **L157** 把完整反身规范应用于已登记且适用的同主体对象,得到工作记录。\n\n\n **L158** 要求完整Reflexive履责及该规则实际属于登记表。\n\n\n **L159** 还要求目标所有者匹配且该规则对其适用。\n\n\n **L160** 把导出的范围义务应用于这些前提,得到该目标的活动已经记录。\n\n\n **L162** 只测试零并声明零点范围。\n\n\n **L164** 形成询问根据,应用询问适用性,修订询问零与一范围的根据,其他对象询问合规。\n\n\n **L165** 根据对象的过程阶段选择问题,仍以同一对象为目标。\n\n\n **L166** 对形成阶段,考察覆盖输入0的方法形成根据。\n\n\n **L167** 对应用阶段,考察局部方法在输入0上的适用性。\n\n\n **L168** 对修订阶段,考察将同一局部方法范围扩至输入0和1的根据。\n\n\n **L169** 对系统或原则自身,在局部范围{0}内考察符合性。\n\n\n **L171** 说明后续定义或结果:按问题提供目的、范围、观察;修订问题另含未测试输入失败的程序反例。\n\n\n **L172** 按问题提供目的、范围、观察;修订问题另含未测试输入失败的程序反例。\n\n\n **L173** 形成理由陈述目的{0}、声明范围{0}及0处为真的观察。\n\n\n **L174** 适用性与符合性使用已声明局部范围及同一0处观察。\n\n\n **L175** 修订理由要求{0,1},同时承认原声明范围为{0}且仅有0处观察。\n\n\n **L176** 加入onlyAtZero程序在输入1处的具体修订反例。\n\n\n **L178** 把选定理由内容逐项绑定到同一问题目标。\n\n\n **L179** 将每项源理由与类别引用和同一对象s包装,保留实际内容。\n\n\n **L181** 说明后续定义或结果:按实际理由和方法范围计算结果;已通过当前测试却在请求输入失败的程序使修订主张不充分。\n\n\n **L182** 说明后续定义或结果:按实际理由和方法范围计算结果;已通过当前测试却在请求输入失败的程序使修订主张不充分。\n\n\n **L183** 按实际理由和方法范围计算结果;已通过当前测试却在请求输入失败的程序使修订主张不充分。\n\n\n **L184** 提取理由内容,以检查目的、范围、观察与反例实质。\n\n\n **L185** 提供的限度若不同于待考察方法声明范围,则返回未确定。\n\n\n **L186** 检查限度后,评估提出的具体问题种类。\n\n\n **L187** 进入形成根据的评估分支。\n\n\n **L188** 要求存在覆盖问题所请求输入的目的理由。\n\n\n **L189** 还要求明确限度声明,且请求范围等于声明范围。\n\n\n **L190** 仅上述内容检查通过时形成评估才为域内有支持,否则未确定。\n\n\n **L191** 对适用性和符合性问题采用相同局部检查。\n\n\n **L192** 首先检查每个请求输入都在所提供限度内。\n\n\n **L193** 在限度内,要求理由明确声明同一范围。\n\n\n **L194** 还要求0处为真的观察,以及请求范围恰为[0]。\n\n\n **L195** 通过这些局部检查得到域内有支持;证据不完整则未确定。\n\n\n **L196** 请求输入超出所提供限度时,判为不适用。\n\n\n **L197** 进入修订根据分支,寻找实际范围反例。\n\n\n **L198** 要求理由把修订后请求范围陈述为预期目的。\n\n\n **L199** 要求旧限度明确出现于声明范围理由中。\n\n\n **L200** 要求原先输入0上的成功观察。\n\n\n **L201** 在提供的理由内容中寻找满足以下具体检查的反例。\n\n\n **L202** 反例输入必须属于新请求范围。\n\n\n **L203** 但该反例程序必须通过当前方法的已测试输入。\n\n\n **L204** 同一程序必须在反例输入处失败。\n\n\n **L205** 其他种类理由不能自行满足该反例搜索。\n\n\n **L206** 发现测试与范围之间的反例缺口时判为不足;缺少这些内容则未确定。\n\n\n **L208** 生成保留测试输入并采用请求范围;评估执行依赖理由内容的问题检查。\n\n\n **L209** 把同一理由和限度传入按活动区分的结果函数。\n\n\n **L210** 在生成草案与评估问题之间选择。\n\n\n **L211** 生成保留方法已测试输入,却提出问题请求范围;不认证正确性。\n\n\n **L212** 评估使用此问题实际理由与限度计算assessInquiry。\n\n\n **L214** 以结果等于明示有限算法的计算值定义语义,不预设检查成功。\n\n\n **L215** 接收待检查是否遵循该活动方法的具体记录结果。\n\n\n **L216** 结果恰等于计算出的finiteMethodResult时才遵循该方法。\n\n\n **L218** 枚举所属系统、两条登记原则及各原则的三个过程阶段。\n\n\n **L219** 把系统自身及其两个原则身份纳入自有对象。\n\n\n **L220** 把原则0的形成、应用和修订分别列为对象。\n\n\n **L221** 也纳入原则1的全部三个阶段,总计九个自有对象。\n\n\n **L223** 说明后续定义或结果:此应用的生成规则排除应用阶段过程,保留其他对象。\n\n\n **L224** 此应用的生成规则排除应用阶段过程,保留其他对象。\n\n\n **L225** 在该应用模型中,把应用既有原则视为不适用生成活动。\n\n\n **L226** 其余已表示对象种类均适用生成活动。\n\n\n **L228** 登记零号生成原则,带局部方法、问题、理由及受限适用条件。\n\n\n **L229** 以此所有者的局部标识0登记生成原则。\n\n\n **L230** 令该规则约束生成工作。\n\n\n **L231** 为生成规则指定测试与范围均为[0]的局部草案。\n\n\n **L232** 生成适用性同时要求属于该所有者九个对象及符合生成资格。\n\n\n **L233** 用inquiryFor提供与对象阶段对应的实际问题。\n\n\n **L234** 用reasonsFor提供原始且与目标相连的理由内容。\n\n\n **L235** 对每个对象,生成规则均保留[0]这一限度。\n\n\n **L236** 要求生成结果符合finiteMethodResult的生成分支。\n\n\n **L238** 登记一号评估原则,按明确有限语义评估全部枚举自身对象。\n\n\n **L239** 以不同的局部标识1登记评估原则。\n\n\n **L240** 令该规则约束评估工作。\n\n\n **L241** 评估原则声明相同的局部[0]/[0]方法契约。\n\n\n **L242** 评估对该所有者全部九个对象适用。\n\n\n **L243** 给评估规则指定同一按阶段区分的问题函数。\n\n\n **L244** 为其评估指定同一原始目标相关理由。\n\n\n **L245** 保留[0]作为评估规则声明的限度。\n\n\n **L246** 要求评估结果等于评估函数的实际结果。\n\n\n **L248** 返回两个身份不同的生成和评估原则。\n\n\n **L250** 说明后续定义或结果:构造拟记录草案和范围支持或不充分结果,随后与实际算法计算核对。\n\n\n **L251** 构造拟记录草案和范围支持或不充分结果,随后与实际算法计算核对。\n\n\n **L252** 按活动选择独立陈述的记录结果。\n\n\n **L253** 记录中的生成草案保留测试输入并采用问题请求范围。\n\n\n **L254** 评估记录按问题种类选取所陈述判定,此处不调用assessInquiry。\n\n\n **L255** 修订问题记录为不足。\n\n\n **L256** 其余已表示问题记录为域内有支持。\n\n\n **L258** 用提供的规则与对象构造记录;登记成员关系与内容有效性仍需后续ValidApplication证明。\n\n\n **L259** 用此规则的标识、问题、理由和限度构造记录,但结果采用独立陈述值。\n\n\n **L261** 穷尽对象与阶段,证明每个具体问题理由非空。\n\n\n **L262** 对每种对象检查理由列表非空。\n\n\n **L263** 系统问题使用符合性理由,包含范围与观察条目。\n\n\n **L264** 原则问题同样具有非空的范围与观察列表。\n\n\n **L265** 各过程阶段分别化为实际非空的形成、应用或修订理由列表。\n\n\n **L267** 从理由列表的映射构造证明各理由都指向同一对象。\n\n\n **L268** 取已知属于此对象构造理由列表的任意理由。\n\n\n **L269** 反解map构造取得源内容,将理由替换为附有目标标识的包装。\n\n\n **L270** 该包装的目标按构造就是s,故目标等式自反成立。\n\n\n **L272** 逐构造器验证生成问题保留目标身份。\n\n\n **L273** 分别检查系统、原则和过程对象的问题目标。\n\n\n **L274** 系统问题构造时就以同一系统为目标。\n\n\n **L275** 原则问题同样保留同一原则目标。\n\n\n **L276** 每个过程阶段均以原过程对象为问题目标。\n\n\n **L278** 说明后续定义或结果:计算各对象和阶段的评估及生成,证明记录预期结果与算法一致,包含不充分结果。\n\n\n **L279** 计算各对象和阶段的评估及生成,证明记录预期结果与算法一致,包含不充分结果。\n\n\n **L280** 要求独立陈述结果等于对该对象问题、理由及[0]限度的实际计算。\n\n\n **L281** 分别检查生成草案与评估判定的结果等式。\n\n\n **L282** 两个生成定义构造完全相同的测试输入与请求范围草案。\n\n\n **L283** 对评估,现须将所陈述判定与实际评估函数核对。\n\n\n **L284** 按对象种类区分有限评估检查。\n\n\n **L285** 系统的符合性内容计算得到所陈述的域内有支持判定。\n\n\n **L286** 原则的符合性内容计算得到同一域内有支持判定。\n\n\n **L287** 形成与应用计算为有支持;修订因程序在0通过而在1失败计算为不足。\n\n\n **L289** 利用局部编号零和一不同,证明登记键无歧义。\n\n\n **L290** 取两项登记原则,并假设其标识相等。\n\n\n **L291** 把两项登记成员关系限定为实际生成规则或评估规则。\n\n\n **L292** 检查由此产生的四种具体规则配对。\n\n\n **L293** 两者都是生成规则时,原则相等直接成立。\n\n\n **L294** 生成标识0不能等于评估标识1;提取localId得到矛盾。\n\n\n **L295** 反向混合配对要求localId 1=0,也不可能。\n\n\n **L296** 两者都是评估规则时,原则相等直接成立。\n\n\n **L298** 核实九个枚举对象都能解析到实际登记主体或原则。\n\n\n **L299** 从ownSubjects选出的对象必须可在该所有者实际登记表中解析。\n\n\n **L300** 把成员前提hs展开为九个具体自有对象。\n\n\n **L301** 逐个处理九个对象,保持其原所有者和原则编号。\n\n\n **L302** 为每个目标标识找到匹配的生成或评估登记项。\n\n\n **L304** 核实每个问题的方法与登记目标的局部方法一致。\n\n\n **L305** 要求所选对象的问题考察其自身登记声明的方法。\n\n\n **L306** 再次依据实际成员前提枚举九个具体对象。\n\n\n **L307** 分别检查系统、原则和各阶段对象的目标方法对应。\n\n\n **L308** 两项登记规则都声明localMethod,恰与inquiryFor为每个枚举目标指定的方法相同。\n\n\n **L310** 综合身份、理由目标、范围、登记及实际计算,验证每个适用记录。\n\n\n **L311** 假设所选登记规则对对象s适用。\n\n\n **L312** 证明具体recordFor rule s满足每个ValidApplication字段。\n\n\n **L313** 首先从适用性推出s属于该所有者对象列表。\n\n\n **L314** 用登记成员关系将rule限定为两个自有规则之一。\n\n\n **L315** 分别处理生成与评估的适用条件。\n\n\n **L316** 生成适用性的第一个合取项就是自有对象成员关系。\n\n\n **L317** 评估适用性恰为该自有对象成员关系。\n\n\n **L318** 确立此实际规则以inquiryFor作为问题函数。\n\n\n **L319** 将登记规则成员关系化为生成或评估,以检查问题字段。\n\n\n **L320** 两个可能规则的问题字段都定义为inquiryFor。\n\n\n **L321** 确立所选规则用reasonsFor提供理由。\n\n\n **L322** 检查理由前,再次将规则限定为两个实际登记项。\n\n\n **L323** 两个登记项都恰提供reasonsFor。\n\n\n **L324** 确立该规则对s的限度恰为[0]。\n\n\n **L325** 检查所选规则限度前,先解析登记成员关系。\n\n\n **L326** 两个自有规则都保留[0]作为限度。\n\n\n **L327** 确立所选规则的含义是其自身活动对应的结果函数。\n\n\n **L328** 解析登记成员关系,以检查生成或评估的含义。\n\n\n **L329** 两种情形中,规则含义都是按其活动实例化的finiteMethodMeaning。\n\n\n **L330** 用登记与适用前提、记录一致性和已解析目标构造ValidApplication,余下检查问题、理由及计算含义。\n\n\n **L331** 余下的问题目标义务针对该规则对s的实际问题。\n\n\n **L332** 将规则问题换为inquiryFor,用其目标保持定理证明目标为s。\n\n\n **L333** 余下方法一致性义务检查该规则问题的登记目标。\n\n\n **L334** 改写为inquiryFor,使用具体自有目标的方法解析定理。\n\n\n **L335** 把记录理由非空化为该规则提供理由非空。\n\n\n **L336** 把这些理由改写为reasonsFor,应用其非空列表定理。\n\n\n **L337** 把理由目标一致性化为每项提供理由都针对s。\n\n\n **L338** 改写为reasonsFor,使用其目标保持构造定理。\n\n\n **L339** 最后义务比较独立陈述结果与该规则实际问题、理由、限度及含义。\n\n\n **L340** 代入含义、问题、理由和[0]限度这四项已证一致性。\n\n\n **L341** 用ownContentEvaluates证明记录结果等于实际方法结果。\n\n\n **L343** 为九个对象构造记录,仅在生成适用时加入生成记录。\n\n\n **L344** 通过连接分配给每个自有对象的记录,构造完整日志。\n\n\n **L345** 符合生成资格的对象同时获得生成记录和评估记录。\n\n\n **L346** 应用阶段对象仅获评估记录,与生成的明确适用限制一致。\n\n\n **L348** 证明每个对象的评估记录进入完整工作列表。\n\n\n **L349** 陈述该自有对象的评估记录属于构造出的完整日志。\n\n\n **L350** 使用flatMap成员规则:选取其分配列表包含目标记录的对象。\n\n\n **L351** 选择同一s及其给定的自有对象成员证明hs。\n\n\n **L352** 无论生成是否适用,分配列表都包含s的评估记录。\n\n\n **L354** 在明确生成适用条件下证明生成记录存在。\n\n\n **L355** 声称完整日志包含生成记录前,除自有成员关系外还要求生成资格。\n\n\n **L356** 选择s的flatMap分支;hg使该分支包含所需生成记录。\n\n\n **L358** 综合登记一致、记录存在及内容有效性,建立具体非空反身模型。\n\n\n **L359** 陈述实际双规则登记表与构造工作日志满足完整内容性反身要求。\n\n\n **L360** 提供已证登记一致性,余下逐一证明适用对象的内容性覆盖。\n\n\n **L361** 取实际登记规则和适用对象;适用性自身将提供所需自有成员关系。\n\n\n **L362** 选择recordFor rule s及已证内容有效性,仅留下它属于完整日志的义务。\n\n\n **L363** 把规则成员关系解析为生成或评估登记项。\n\n\n **L364** 按这两个实际规则情形分别证明记录成员关系。\n\n\n **L365** 对生成,ha提供自有成员关系和资格,使其记录属于完整日志。\n\n\n **L366** 对评估,ha直接提供其记录所需的自有成员关系。\n\n\n **L368** 为列表中的自身对象抽取已构造评估记录。\n\n\n **L369** 陈述同一完整工作日志中存在针对s的评估活动。\n\n\n **L370** 以s的评估记录、已证日志成员关系及确切目标活动一致性作为Performed见证。\n\n\n **L372** 把评估规则限定到一个应用阶段对象,并给出可解析键。\n\n\n **L373** 把评估规则限制为原则0的应用过程,标识为(0,0)。\n\n\n **L375** 储存该单一应用对象的完整评估记录。\n\n\n **L377** 核实单规则及其记录在受限适用范围内满足完整内容有效反身性。\n\n\n **L378** 将单项登记表一致性与唯一适用对象覆盖分开。\n\n\n **L379** 取单项登记表中任意两规则;成员关系已确定两者,因此无需使用标识相等前提。\n\n\n **L380** 单项成员关系使两规则都等于applicationRule。\n\n\n **L381** 代入这两个一致性证明两规则相等。\n\n\n **L382** 为单项应用登记表中的规则取一个适用对象。\n\n\n **L383** 用单项成员关系确认该规则是applicationRule。\n\n\n **L384** 在覆盖义务中把rule替换为确切的applicationRule。\n\n\n **L385** 展开适用性,得到s恰为所有者0的原则0应用过程。\n\n\n **L386** 把s替换为该确切过程,固定工作目标。\n\n\n **L387** 选择applicationWork唯一记录并证明成员关系,余下检查内容有效性。\n\n\n **L388** 填入直接成立的登记、适用与记录一致性字段,留下目标解析、理由及计算结果检查。\n\n\n **L389** 目标标识解析为单项登记表中的applicationRule自身。\n\n\n **L390** 同一登记规则提供问题实际考察的localMethod。\n\n\n **L391** 由reasonsFor_nonempty得应用问题理由非空。\n\n\n **L392** 每项应用理由都针对该确切应用过程对象。\n\n\n **L393** 余下含义义务是所陈述应用评估与实际有限计算结果相等。\n\n\n **L394** 用ownContentEvaluates确认应用阶段评估的该等式。\n\n\n **L396** 从完整反身性得到范围覆盖,证明条件与析取等价,并给无系统评估记录的有效受限实例。\n\n\n **L397** 第一条保留完整内容性反身要求推出范围覆盖的结论。\n\n\n **L398** 第二条把条件性范围覆盖改述为二择一义务。\n\n\n **L399** 对每个自有对象和登记规则,要么规则不适用,要么其活动已有记录。\n\n\n **L400** 具体单项应用日志在受限规则下满足完整反身要求。\n\n\n **L401** 但同一日志不含系统自身评估,因为该规则对系统自身不适用。\n\n\n **L402** 对可能不可判定的适用谓词使用古典分情形讨论。\n\n\n **L403** 提供一般范围投影和具体受限见证,留下等价关系与缺失系统记录证明。\n\n\n **L404** 证明适用性或已履行改述的两个方向。\n\n\n **L405** 假设条件性范围覆盖,固定登记规则与自有对象。\n\n\n **L406** 按该确切规则是否对该对象适用分情况。\n\n\n **L407** 适用时,覆盖义务提供已记录活动,满足右析取项。\n\n\n **L408** 不适用时,该否定适用事实满足左析取项。\n\n\n **L409** 反向证明假设该析取,并给出对自有对象的实际适用性。\n\n\n **L410** 用ha排除不适用分支,得到所需已记录活动。\n\n\n **L411** 假设存在系统评估,提取列表记录及目标一致性。\n\n\n **L412** 单项applicationWork迫使该记录就是应用过程记录。\n\n\n **L413** 把声称的系统评估记录替换为唯一过程记录。\n\n\n **L414** 其过程目标不可能等于系统目标,与假设的记录一致性矛盾。\n\n\n **L416** 关闭当前命名空间。\n\n\n### `leanified/CoreReader.lean`\n\n\n```lean\nimport CoreReader.Engineering.Integration\n```\n\n\n\n **L1** 导入 Engineering.Integration 及其传递依赖,使本工程的工程应用、继承接口、共同见证与不蕴涵证明可用;导入本身不陈述哲学定理。\n\n", + "detail_link_found": true, + "line_anchors": [] + } + ] +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-helper-caption-reuse-probe-r1.json b/SoftwareEngineering/lean/philosophy/reviews/reader-helper-caption-reuse-probe-r1.json new file mode 100644 index 0000000..99385f2 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-helper-caption-reuse-probe-r1.json @@ -0,0 +1,98 @@ +[ + { + "language": "en", + "file": "CoreReader/Logic.lean", + "source_reader_sha256": "f1a90f0aacdd9d6ba8eccc82973e770cb8317f527c4db15de42e9e41ecc2fbf5", + "nonblank_pairs": 185, + "all_code_and_caption_exact": true, + "mismatches": [] + }, + { + "language": "en", + "file": "CoreReader/Evidence.lean", + "source_reader_sha256": "f1a90f0aacdd9d6ba8eccc82973e770cb8317f527c4db15de42e9e41ecc2fbf5", + "nonblank_pairs": 721, + "all_code_and_caption_exact": true, + "mismatches": [] + }, + { + "language": "en", + "file": "CoreReader/Choice.lean", + "source_reader_sha256": "f1a90f0aacdd9d6ba8eccc82973e770cb8317f527c4db15de42e9e41ecc2fbf5", + "nonblank_pairs": 228, + "all_code_and_caption_exact": true, + "mismatches": [] + }, + { + "language": "en", + "file": "CoreReader/Agency.lean", + "source_reader_sha256": "f1a90f0aacdd9d6ba8eccc82973e770cb8317f527c4db15de42e9e41ecc2fbf5", + "nonblank_pairs": 215, + "all_code_and_caption_exact": true, + "mismatches": [] + }, + { + "language": "en", + "file": "CoreReader/Reflexivity.lean", + "source_reader_sha256": "f1a90f0aacdd9d6ba8eccc82973e770cb8317f527c4db15de42e9e41ecc2fbf5", + "nonblank_pairs": 356, + "all_code_and_caption_exact": true, + "mismatches": [] + }, + { + "language": "en", + "file": "CoreReader/Integration.lean", + "source_reader_sha256": "f1a90f0aacdd9d6ba8eccc82973e770cb8317f527c4db15de42e9e41ecc2fbf5", + "nonblank_pairs": 473, + "all_code_and_caption_exact": true, + "mismatches": [] + }, + { + "language": "zh", + "file": "CoreReader/Logic.lean", + "source_reader_sha256": "9e5c27ac66c60d74d58b75ef2cb194c48e813b3dd0cdc2c4a73acc4e9aa8dcc0", + "nonblank_pairs": 185, + "all_code_and_caption_exact": true, + "mismatches": [] + }, + { + "language": "zh", + "file": "CoreReader/Evidence.lean", + "source_reader_sha256": "9e5c27ac66c60d74d58b75ef2cb194c48e813b3dd0cdc2c4a73acc4e9aa8dcc0", + "nonblank_pairs": 721, + "all_code_and_caption_exact": true, + "mismatches": [] + }, + { + "language": "zh", + "file": "CoreReader/Choice.lean", + "source_reader_sha256": "9e5c27ac66c60d74d58b75ef2cb194c48e813b3dd0cdc2c4a73acc4e9aa8dcc0", + "nonblank_pairs": 228, + "all_code_and_caption_exact": true, + "mismatches": [] + }, + { + "language": "zh", + "file": "CoreReader/Agency.lean", + "source_reader_sha256": "9e5c27ac66c60d74d58b75ef2cb194c48e813b3dd0cdc2c4a73acc4e9aa8dcc0", + "nonblank_pairs": 215, + "all_code_and_caption_exact": true, + "mismatches": [] + }, + { + "language": "zh", + "file": "CoreReader/Reflexivity.lean", + "source_reader_sha256": "9e5c27ac66c60d74d58b75ef2cb194c48e813b3dd0cdc2c4a73acc4e9aa8dcc0", + "nonblank_pairs": 356, + "all_code_and_caption_exact": true, + "mismatches": [] + }, + { + "language": "zh", + "file": "CoreReader/Integration.lean", + "source_reader_sha256": "9e5c27ac66c60d74d58b75ef2cb194c48e813b3dd0cdc2c4a73acc4e9aa8dcc0", + "nonblank_pairs": 473, + "all_code_and_caption_exact": true, + "mismatches": [] + } +] diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-helper-reuse-probe-r1.json b/SoftwareEngineering/lean/philosophy/reviews/reader-helper-reuse-probe-r1.json new file mode 100644 index 0000000..9749ad5 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-helper-reuse-probe-r1.json @@ -0,0 +1,38 @@ +[ + { + "file": "CoreReader/Logic.lean", + "equal_nonblank_after_removing_organon_map_comments": true, + "source_sha256": "6b70be8964763b6447a2603bde665ff58106678f2e1d421bebd8c6b29ae46e04", + "copy_sha256": "0ec342691766ebd83d251dcd0da3b0ae9840aed677a714bc1b01c45d89392bc0" + }, + { + "file": "CoreReader/Evidence.lean", + "equal_nonblank_after_removing_organon_map_comments": true, + "source_sha256": "18beb2b94450fdab36229b645e2df129348f3e67306104e842e0dce6e72443e8", + "copy_sha256": "d55f33e44902cef146841cbffb65710bd7c8a3bda79d01d084edc36f019fdc96" + }, + { + "file": "CoreReader/Choice.lean", + "equal_nonblank_after_removing_organon_map_comments": true, + "source_sha256": "07cf17f73802bdd34ae00ecba317ddc0283321cce00f15a84b69df421c3fe25f", + "copy_sha256": "b28728df12ed7e73edb5569604cd2541c0ebd815ae3aaa0812e6557dece1d1ba" + }, + { + "file": "CoreReader/Agency.lean", + "equal_nonblank_after_removing_organon_map_comments": true, + "source_sha256": "b0dca4187a88a0a0f33c3dd6a11bb383907603ef514e80e9e3f09f95ce9633e2", + "copy_sha256": "2722c34645f4256f20ce31205738f2f5712ab5dd5cc6fcf9f1180d0be5aa0303" + }, + { + "file": "CoreReader/Reflexivity.lean", + "equal_nonblank_after_removing_organon_map_comments": true, + "source_sha256": "25292faa71c5585a8f50cb07d72c2f44fa12dcfb125b2b92094f9306fecb4fd0", + "copy_sha256": "48e2c74e7cbae571db1b990b9f32dd0d701f6881a8b0111d907f8861287d76fa" + }, + { + "file": "CoreReader/Integration.lean", + "equal_nonblank_after_removing_organon_map_comments": true, + "source_sha256": "6821e55e284fcc69136a77adf9375b335e9b5f567d9124ef728e562d4b9eb4e1", + "copy_sha256": "97e2939c0b6714b78a3ed78358e174619a5028ad5b0b5025c0d4422b4294921b" + } +] diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-final.json b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-final.json new file mode 100644 index 0000000..ba22139 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-final.json @@ -0,0 +1,650 @@ +{ + "role": "independent_changed_scope_public_embedding_and_lookup_recheck", + "verdict": "accepted_for_reviewed_Domain_and_T35_changed_scope", + "scope": "Exactly the accepted 14 Domain line changes in both languages, their embedding in current detailed views, and accepted T35 fields in all four views; related target/declaration/source-anchor lookup.", + "authorship_separation": "Reviewer did not author Domain or T35. Reviewer-authored Root Reflection/SelfApplication/Values/Integration prose is excluded; whole-view hashes identify bytes only and do not constitute this reviewer self-approving their other contents.", + "baseline": "SoftwareEngineering 0.2.0 / adopted Core 0.1.2", + "actual_objects": [ + { + "path": "SoftwareEngineering/PHILOSOPHY.md", + "snapshot": "private software-engineering iteration records/reader-independent-domain-final-input/PHILOSOPHY.md", + "sha256": "6c6ae78a23f2726c5c370434e808d76c206647fe7793245e88cae52c076abe34", + "bytes": 19419 + }, + { + "path": "SoftwareEngineering/lean/philosophy/run.json", + "snapshot": "private software-engineering iteration records/reader-independent-domain-final-input/lean__philosophy__run.json", + "sha256": "661ee91e1727a628c9e5933f6c6690011c575f99123b2a669ddb2b9c036a163d", + "bytes": 92244 + }, + { + "path": "SoftwareEngineering/lean/philosophy/targets.json", + "snapshot": "private software-engineering iteration records/reader-independent-domain-final-input/lean__philosophy__targets.json", + "sha256": "c0939df35dad148a0543ba92a1ac7b7d3b2eb4946f92ac4be251ec51b6481d13", + "bytes": 81994 + }, + { + "path": "private software-engineering iteration records/target-narratives-current.json", + "snapshot": "private software-engineering iteration records/reader-independent-domain-final-input/target-narratives-current.json", + "sha256": "12f534ce9489527799edebe937e5cca39dc3166afb6aec5783473334423b06d4", + "bytes": 63287 + }, + { + "path": "private software-engineering iteration records/domain-line-explanations-en.json", + "snapshot": "private software-engineering iteration records/reader-independent-domain-final-input/domain-line-explanations-en.json", + "sha256": "d1773e14c9e68a81850a9a949f11ab3722dcb3a4c2bd8c663ecf1e8102d3c471", + "bytes": 121330 + }, + { + "path": "private software-engineering iteration records/domain-line-explanations-zh.json", + "snapshot": "private software-engineering iteration records/reader-independent-domain-final-input/domain-line-explanations-zh.json", + "sha256": "24bf6725f169fad4ec28f335296c0e95c3212136e46ec3ad0974f61a32820c85", + "bytes": 101118 + }, + { + "path": "SoftwareEngineering/lean/philosophy/leanified/CoreReader/Engineering/Domain.lean", + "snapshot": "private software-engineering iteration records/reader-independent-domain-final-input/lean__philosophy__leanified__CoreReader__Engineering__Domain.lean", + "sha256": "ce5653a2950cc7443cefbfe8b9726bd4859228e831ddb7d42601e501ccbfd855", + "bytes": 54444 + }, + { + "path": "SoftwareEngineering/lean/philosophy/overview.md", + "snapshot": "private software-engineering iteration records/reader-independent-domain-final-input/lean__philosophy__overview.md", + "sha256": "c8b01525a54a9beb78086a17652ea4ded4740dad956a0a9a4f9c0ae3ee7171a2", + "bytes": 123993 + }, + { + "path": "SoftwareEngineering/lean/philosophy/details.md", + "snapshot": "private software-engineering iteration records/reader-independent-domain-final-input/lean__philosophy__details.md", + "sha256": "1b8d07cbbf3a0e7005821bc2261f89b1675d43a053802e8b779b1930e0d782af", + "bytes": 1803974 + }, + { + "path": "SoftwareEngineering/zh/lean/philosophy/overview.md", + "snapshot": "private software-engineering iteration records/reader-independent-domain-final-input/zh__lean__philosophy__overview.md", + "sha256": "31fd96fd034ab16e92d3ecc600237bf9f27fcddaff754b308e4ca14573b58a61", + "bytes": 110895 + }, + { + "path": "SoftwareEngineering/zh/lean/philosophy/details.md", + "snapshot": "private software-engineering iteration records/reader-independent-domain-final-input/zh__lean__philosophy__details.md", + "sha256": "5eba3d944c7bcef294bfed822e6c4aa8205e3e238157da5fb95365bbb57169ff", + "bytes": 1685077 + } + ], + "code_hashes": { + "CoreReader.lean": "c5574fae235419a7d6449b3ebb5d2da29d1e92a3b572c1b759438e3c470caaa9", + "CoreReader/Choice.lean": "b28728df12ed7e73edb5569604cd2541c0ebd815ae3aaa0812e6557dece1d1ba", + "CoreReader/Logic.lean": "0ec342691766ebd83d251dcd0da3b0ae9840aed677a714bc1b01c45d89392bc0", + "CoreReader/Integration.lean": "97e2939c0b6714b78a3ed78358e174619a5028ad5b0b5025c0d4422b4294921b", + "CoreReader/Agency.lean": "2722c34645f4256f20ce31205738f2f5712ab5dd5cc6fcf9f1180d0be5aa0303", + "CoreReader/Reflexivity.lean": "48e2c74e7cbae571db1b990b9f32dd0d701f6881a8b0111d907f8861287d76fa", + "CoreReader/Evidence.lean": "d55f33e44902cef146841cbffb65710bd7c8a3bda79d01d084edc36f019fdc96", + "CoreReader/Adopted.lean": "8de4d364bb3c64e29ab92e81d86cbe4c9e5af49ada3dad262d1378421fb588c2", + "CoreReader/Engineering/Reflection.lean": "c290d8472884d00bedbf945f0fc1866524e758740f40d42088c4ff9678a93fa2", + "CoreReader/Engineering/Integration.lean": "a2b88062148b3f7ebea7da02d88cb29cb04d8f1b2e9e6b97bb2420ac2c006328", + "CoreReader/Engineering/Values.lean": "ccd45bf23d2f47c41d1b2f9955d753e290687d951a0c55af41ab9a63b9a8d9cb", + "CoreReader/Engineering/SelfApplication.lean": "d69c0d369bd4fd8db4c21ce3b65abb5e9efd07ed5ab9a68d56b4db39bb9d2a21", + "CoreReader/Engineering/Domain.lean": "ce5653a2950cc7443cefbfe8b9726bd4859228e831ddb7d42601e501ccbfd855" + }, + "all_code_hashes_match_third_snapshot": true, + "source_hash_matches_prior_review": true, + "actual_targets_hash": "c0939df35dad148a0543ba92a1ac7b7d3b2eb4946f92ac4be251ec51b6481d13", + "targets_match_frozen": true, + "T35_exact_record": { + "id": "T35", + "title_en": "Revision and preserved historical evidence", + "title_zh": "修订与保留历史证据", + "conclusion_en": "Changed forecasts, maintainers, costs or objectives can justify changed judgments. A new record must retain the earlier prediction and its observed failure.", + "conclusion_zh": "预测、维护者、成本或目标变化可支持改判;新记录须保留旧预测及其观测失败。", + "premises_en": "RevisionAccount compares the revision with independently fixed observedHistory, including software identity, old prediction and actual observed result. revisionFor uses the current context and selected candidate. MaterialGroundsChanged is a disjunction of five recorded differences; it does not prove that each difference alone adequately justifies the new choice.", + "premises_zh": "RevisionAccount 将修订与独立固定的 observedHistory 比较,包括软件身份、旧预测及实际观测结果;revisionFor 使用当前语境和所选实现。 MaterialGroundsChanged 是五项记录差异的析取,不证明任一差异单独足以充分支持新选择。", + "proof_en": "The same old/new state pair changes forecast, maintenance, maintainers, migration cost and objective capacity together; the theorem lists all five differences. Tampering with both old and recordedOld cannot change the independent history. Separate retention cases use an unsupported alternative or a justified migration-cost departure.", + "proof_zh": "同一旧/新状态对同时改变预测、维护、维护者、迁移成本和目标容量;定理列出这五项差异。同步篡改 old 与 recordedOld 不能改变独立历史。另有保留案例分别使用无支持的替代方向或有根据的迁移成本让步。", + "limits_en": "The recorded history is fixed model evidence; the theorem does not authenticate arbitrary real-world logs or prove every criticism response adequate.", + "limits_zh": "记录的历史是固定模型证据;定理不鉴定任意现实日志,也不证明所有批评回应均充分。" + }, + "T35_canonical_hash": "8242e8ff1069f5fc2072eb780fecbfb2ba66faa637f6608e818b270fbc720a52", + "checks": [ + { + "language": "en", + "changed_domain_line_embeddings": [ + { + "source_line": 88, + "actual_source": " match d with", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-88", + "anchor_unique": true, + "view_anchor_line": 10829, + "view_explanation_line": 10830, + "exact_accepted_explanation": "Dispatch on the requested Change to choose its corresponding editing path; the following branches distinguish the different directions." + }, + { + "source_line": 244, + "actual_source": " objective := fun b => match b with", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-244", + "anchor_unique": true, + "view_anchor_line": 11228, + "view_explanation_line": 11229, + "exact_accepted_explanation": "Assign each Burden its objective name by matching on the burden; the following branches supply the distinct engineering objectives." + }, + { + "source_line": 298, + "actual_source": "abbrev JustifiedDeparture (ctx : Context) (c : Candidate) : Prop :=", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-298", + "anchor_unique": true, + "view_anchor_line": 11363, + "view_explanation_line": 11364, + "exact_accepted_explanation": "Define justified departure for this context and candidate through a recorded burden whose concrete cost threat must hold." + }, + { + "source_line": 299, + "actual_source": " match ctx.departure with", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-299", + "anchor_unique": true, + "view_anchor_line": 11366, + "view_explanation_line": 11367, + "exact_accepted_explanation": "Inspect this same context’s departure option to distinguish an absent explanation from a named burden." + }, + { + "source_line": 300, + "actual_source": " | none => False", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-300", + "anchor_unique": true, + "view_anchor_line": 11369, + "view_explanation_line": 11370, + "exact_accepted_explanation": "With no recorded departure burden, justification is False; absence supplies no exception." + }, + { + "source_line": 301, + "actual_source": " | some b => ConcreteThreat ctx c b", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-301", + "anchor_unique": true, + "view_anchor_line": 11372, + "view_explanation_line": 11373, + "exact_accepted_explanation": "For the recorded burden b, require ConcreteThreat for this exact context, candidate and burden." + }, + { + "source_line": 353, + "actual_source": "theorem unmetRequirementsBlockPriority :", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-353", + "anchor_unique": true, + "view_anchor_line": 11501, + "view_explanation_line": 11502, + "exact_accepted_explanation": "Check that each of the four displayed requirement failures makes PriorityConditions false. This only disables priority activation: EvolutionPriority and the later DomainSatisfied do not impose an unconditional Meets rejection." + }, + { + "source_line": 424, + "actual_source": "def insertOrdered (n : Nat) : List Nat → List Nat", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-424", + "anchor_unique": true, + "view_anchor_line": 11699, + "view_explanation_line": 11700, + "exact_accepted_explanation": "Take a natural number and an arbitrary natural-number list; the type has no sorted-input premise. sortValues uses this helper for ordered insertion into its recursively sorted tail." + }, + { + "source_line": 710, + "actual_source": "def omittedCallerCheck : EngineeringDesign :=", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-710", + "anchor_unique": true, + "view_anchor_line": 12428, + "view_explanation_line": 12429, + "exact_accepted_explanation": "Construct omittedCallerCheck as a design variant whose paths omit caller contract-runner work, for the later boundary-obligation counterexample." + }, + { + "source_line": 711, + "actual_source": " { boundaryDesign with paths := fun direction =>", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-711", + "anchor_unique": true, + "view_anchor_line": 12431, + "view_explanation_line": 12432, + "exact_accepted_explanation": "Copy boundaryDesign’s other fields unchanged and replace paths with a function that transforms the path for each requested direction." + }, + { + "source_line": 712, + "actual_source": " (boundaryDesign.paths direction).filter (fun step =>", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-712", + "anchor_unique": true, + "view_anchor_line": 12434, + "view_explanation_line": 12435, + "exact_accepted_explanation": "Filter the original boundaryDesign path for this same direction, retaining precisely the steps accepted by the following predicate." + }, + { + "source_line": 713, + "actual_source": " !(step.component == coordinatedBoundary.caller && step.tool == .contractRunner)) }", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-713", + "anchor_unique": true, + "view_anchor_line": 12437, + "view_explanation_line": 12438, + "exact_accepted_explanation": "Exclude a step exactly when it is at coordinatedBoundary.caller and uses contractRunner; keep all other steps and finish the record update." + }, + { + "source_line": 1034, + "actual_source": "abbrev DomainSatisfied (ctx : Context) (chosen : Candidate) : Prop :=", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-1034", + "anchor_unique": true, + "view_anchor_line": 13271, + "view_explanation_line": 13272, + "exact_accepted_explanation": "Combine the represented domain duties for one context and selected design. This bundle has no unconditional Meets field; priority applicability is not an overall requirement-rejection test." + }, + { + "source_line": 1035, + "actual_source": " ActivityScope ctx.activity ∧ EvolutionPriority ctx chosen ∧", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-1035", + "anchor_unique": true, + "view_anchor_line": 13274, + "view_explanation_line": 13275, + "exact_accepted_explanation": "Require ActivityScope and the conditional EvolutionPriority. If PriorityConditions is false, that implication holds vacuously; this conjunct does not reject the choice for unmet requirements, while the remaining domain duties still apply." + } + ], + "all_domain_entries_mechanically_match_accepted_component": true, + "domain_code_fence_exact": true, + "related_navigation": [ + { + "target": "T23", + "overview_to_details_resolves": true, + "domain_declaration_links": [ + { + "source_line": 159, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-159", + "actual_source": "theorem subjectLimits :" + } + ] + }, + { + "target": "T24", + "overview_to_details_resolves": true, + "domain_declaration_links": [ + { + "source_line": 321, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-321", + "actual_source": "abbrev EvolutionPriority (ctx : Context) (chosen : Candidate) : Prop :=" + }, + { + "source_line": 367, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-367", + "actual_source": "theorem priorityConditionsCases :" + } + ] + }, + { + "target": "T26", + "overview_to_details_resolves": true, + "domain_declaration_links": [ + { + "source_line": 174, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-174", + "actual_source": "abbrev CredibleDirection {Ground : Type} (grounds : List Ground)" + }, + { + "source_line": 212, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-212", + "actual_source": "theorem credibilityCases :" + } + ] + }, + { + "target": "T28", + "overview_to_details_resolves": true, + "domain_declaration_links": [ + { + "source_line": 298, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-298", + "actual_source": "abbrev JustifiedDeparture (ctx : Context) (c : Candidate) : Prop :=" + }, + { + "source_line": 410, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-410", + "actual_source": "theorem costCases :" + } + ] + }, + { + "target": "T31", + "overview_to_details_resolves": true, + "domain_declaration_links": [ + { + "source_line": 641, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-641", + "actual_source": "abbrev StructuralAccount (a : Activity) (c : Candidate) (e : StructuralEvidence) : Prop :=" + }, + { + "source_line": 733, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-733", + "actual_source": "theorem structuralCases :" + } + ] + }, + { + "target": "T35", + "overview_to_details_resolves": true, + "domain_declaration_links": [ + { + "source_line": 922, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-922", + "actual_source": "abbrev RevisionAccount (r : RevisionRecord) : Prop := RevisionAccountAgainst observedHistory r" + }, + { + "source_line": 951, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-951", + "actual_source": "theorem revisionCases :" + } + ] + } + ], + "T35_embedding": [ + { + "view": "overview", + "all_accepted_fields_embedded_exactly": { + "title": true, + "conclusion": true, + "premises": true, + "proof": true, + "limits": true + }, + "source_links_resolve": [ + "source-software-engineering-revision-p2", + "source-software-engineering-revision-p1" + ] + }, + { + "view": "details", + "all_accepted_fields_embedded_exactly": { + "title": true, + "conclusion": true, + "premises": true, + "proof": true, + "limits": true + }, + "source_links_resolve": [ + "source-software-engineering-revision-p2", + "source-software-engineering-revision-p1" + ] + } + ] + }, + { + "language": "zh", + "changed_domain_line_embeddings": [ + { + "source_line": 88, + "actual_source": " match d with", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-88", + "anchor_unique": true, + "view_anchor_line": 10829, + "view_explanation_line": 10830, + "exact_accepted_explanation": "按请求的 Change 选择对应编辑路径;后续各分支区分不同变更方向。" + }, + { + "source_line": 244, + "actual_source": " objective := fun b => match b with", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-244", + "anchor_unique": true, + "view_anchor_line": 11228, + "view_explanation_line": 11229, + "exact_accepted_explanation": "按 Burden 分派并指定对应目标名称;后续分支给出各自不同的工程目标。" + }, + { + "source_line": 298, + "actual_source": "abbrev JustifiedDeparture (ctx : Context) (c : Candidate) : Prop :=", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-298", + "anchor_unique": true, + "view_anchor_line": 11363, + "view_explanation_line": 11364, + "exact_accepted_explanation": "以记录的负担及其必须成立的具体成本威胁,定义此情境与候选的有根据让步。" + }, + { + "source_line": 299, + "actual_source": " match ctx.departure with", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-299", + "anchor_unique": true, + "view_anchor_line": 11366, + "view_explanation_line": 11367, + "exact_accepted_explanation": "检查同一情境的 departure 选项,区分未指定说明与已指定负担。" + }, + { + "source_line": 300, + "actual_source": " | none => False", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-300", + "anchor_unique": true, + "view_anchor_line": 11369, + "view_explanation_line": 11370, + "exact_accepted_explanation": "未记录让步负担时,根据条件为 False;缺省记录不提供例外。" + }, + { + "source_line": 301, + "actual_source": " | some b => ConcreteThreat ctx c b", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-301", + "anchor_unique": true, + "view_anchor_line": 11372, + "view_explanation_line": 11373, + "exact_accepted_explanation": "对记录的负担 b,要求同一情境、候选及该负担满足 ConcreteThreat。" + }, + { + "source_line": 353, + "actual_source": "theorem unmetRequirementsBlockPriority :", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-353", + "anchor_unique": true, + "view_anchor_line": 11501, + "view_explanation_line": 11502, + "exact_accepted_explanation": "检查所示四种需求失败各自使 PriorityConditions 为假。这仅阻止优先条件激活;EvolutionPriority 及后面的 DomainSatisfied 并未施加无条件的 Meets 拒绝要求。" + }, + { + "source_line": 424, + "actual_source": "def insertOrdered (n : Nat) : List Nat → List Nat", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-424", + "anchor_unique": true, + "view_anchor_line": 11699, + "view_explanation_line": 11700, + "exact_accepted_explanation": "接收一个自然数及任意自然数列表;类型不含输入已排序的前提。sortValues 调用此辅助函数,在递归排序后的尾列表中按序插入。" + }, + { + "source_line": 710, + "actual_source": "def omittedCallerCheck : EngineeringDesign :=", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-710", + "anchor_unique": true, + "view_anchor_line": 12428, + "view_explanation_line": 12429, + "exact_accepted_explanation": "构造设计变式 omittedCallerCheck,在路径中省去调用方合同执行器工作,用于后面的边界义务反例。" + }, + { + "source_line": 711, + "actual_source": " { boundaryDesign with paths := fun direction =>", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-711", + "anchor_unique": true, + "view_anchor_line": 12431, + "view_explanation_line": 12432, + "exact_accepted_explanation": "保持 boundaryDesign 的其他字段不变,将 paths 替换为按请求方向变换对应路径的函数。" + }, + { + "source_line": 712, + "actual_source": " (boundaryDesign.paths direction).filter (fun step =>", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-712", + "anchor_unique": true, + "view_anchor_line": 12434, + "view_explanation_line": 12435, + "exact_accepted_explanation": "筛选 boundaryDesign 在同一方向的原路径,只保留下述谓词接受的步骤。" + }, + { + "source_line": 713, + "actual_source": " !(step.component == coordinatedBoundary.caller && step.tool == .contractRunner)) }", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-713", + "anchor_unique": true, + "view_anchor_line": 12437, + "view_explanation_line": 12438, + "exact_accepted_explanation": "仅在步骤位于 coordinatedBoundary.caller 且使用 contractRunner 时删除它;保留其余步骤,并完成记录更新。" + }, + { + "source_line": 1034, + "actual_source": "abbrev DomainSatisfied (ctx : Context) (chosen : Candidate) : Prop :=", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-1034", + "anchor_unique": true, + "view_anchor_line": 13271, + "view_explanation_line": 13272, + "exact_accepted_explanation": "组合同一情境与所选设计的已表示领域义务。此组合没有无条件的 Meets 字段;优先适用性并不是整体需求拒绝检查。" + }, + { + "source_line": 1035, + "actual_source": " ActivityScope ctx.activity ∧ EvolutionPriority ctx chosen ∧", + "anchor": "line-code-leanified-corereader-engineering-domain-lean-1035", + "anchor_unique": true, + "view_anchor_line": 13274, + "view_explanation_line": 13275, + "exact_accepted_explanation": "要求 ActivityScope 及条件式 EvolutionPriority。若 PriorityConditions 为假,该蕴含空真;此合取项不会因需求未满足而拒绝选择,其余领域义务仍须履行。" + } + ], + "all_domain_entries_mechanically_match_accepted_component": true, + "domain_code_fence_exact": true, + "related_navigation": [ + { + "target": "T23", + "overview_to_details_resolves": true, + "domain_declaration_links": [ + { + "source_line": 159, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-159", + "actual_source": "theorem subjectLimits :" + } + ] + }, + { + "target": "T24", + "overview_to_details_resolves": true, + "domain_declaration_links": [ + { + "source_line": 321, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-321", + "actual_source": "abbrev EvolutionPriority (ctx : Context) (chosen : Candidate) : Prop :=" + }, + { + "source_line": 367, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-367", + "actual_source": "theorem priorityConditionsCases :" + } + ] + }, + { + "target": "T26", + "overview_to_details_resolves": true, + "domain_declaration_links": [ + { + "source_line": 174, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-174", + "actual_source": "abbrev CredibleDirection {Ground : Type} (grounds : List Ground)" + }, + { + "source_line": 212, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-212", + "actual_source": "theorem credibilityCases :" + } + ] + }, + { + "target": "T28", + "overview_to_details_resolves": true, + "domain_declaration_links": [ + { + "source_line": 298, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-298", + "actual_source": "abbrev JustifiedDeparture (ctx : Context) (c : Candidate) : Prop :=" + }, + { + "source_line": 410, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-410", + "actual_source": "theorem costCases :" + } + ] + }, + { + "target": "T31", + "overview_to_details_resolves": true, + "domain_declaration_links": [ + { + "source_line": 641, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-641", + "actual_source": "abbrev StructuralAccount (a : Activity) (c : Candidate) (e : StructuralEvidence) : Prop :=" + }, + { + "source_line": 733, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-733", + "actual_source": "theorem structuralCases :" + } + ] + }, + { + "target": "T35", + "overview_to_details_resolves": true, + "domain_declaration_links": [ + { + "source_line": 922, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-922", + "actual_source": "abbrev RevisionAccount (r : RevisionRecord) : Prop := RevisionAccountAgainst observedHistory r" + }, + { + "source_line": 951, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-951", + "actual_source": "theorem revisionCases :" + } + ] + } + ], + "T35_embedding": [ + { + "view": "overview", + "all_accepted_fields_embedded_exactly": { + "title": true, + "conclusion": true, + "premises": true, + "proof": true, + "limits": true + }, + "source_links_resolve": [ + "source-software-engineering-revision-p2", + "source-software-engineering-revision-p1" + ] + }, + { + "view": "details", + "all_accepted_fields_embedded_exactly": { + "title": true, + "conclusion": true, + "premises": true, + "proof": true, + "limits": true + }, + "source_links_resolve": [ + "source-software-engineering-revision-p2", + "source-software-engineering-revision-p1" + ] + } + ] + } + ], + "closed_findings": [ + "RD1", + "RD2", + "RD3", + "RD4 necessary line corrections" + ], + "optional_improvements_embedded": [ + "RD4 option/filter local explanations" + ], + "prior_records_preserved": { + "reader-independent-domain-r1.md": "2c411fb38eef7f4637c9c243930b4f30029b059893056518607e767cd851dae8", + "reader-independent-domain-r1.json": "fc60fdb13ba8f01734c78bcea55829701d2f6649a0064f9bdc58c0f9079f981d", + "reader-independent-domain-r1-granularity-clarification.json": "9d6c9b64c164a072203911b24ced32e9e32bf47a2d82a5706771934c5faa6f6a", + "reader-independent-domain-r2.md": "228a039b18206d6243e29afe3cd5e5480d930cb09d186c217284d618e61819bd", + "reader-independent-domain-r2.json": "44b4697d44a5f28ca501f868e08680dfbf7614092860e87daa28c37a1fe30f82" + }, + "reported_metadata_only": { + "manifest_hash_reported_by_initiator": "1707734f6c51b9f7cd802ba8b84ed2a4d80fb6a7617d53eac081568689fee0c1", + "actualgate_pass_reported_by_initiator": true, + "not_reused_as_this_review_evidence": "This review independently checks actual manuscript/code/source/target bytes and exact embeddings. Later public-QA metadata may change manifest identity without changing these reviewed objects." + }, + "reuse": "Reuses the preserved r1 full Domain semantics and actual probes plus r2 changed-component semantic acceptance, since code and accepted component values are unchanged. No new Lean build or full Domain semantic reread was performed for a prose embedding check.", + "limitations": [ + "Accepts only the stated changed scope, not all four manuscripts philosophically or semantically.", + "No self-review of the four Root module explanations authored by this reviewer.", + "Markdown anchor/embedding checks are actual text navigation, not screenshot/browser visual QA.", + "A later change to any relevant view/source/code/T35 bytes requires impact-based rechecking; metadata-only manifest changes do not silently change this reviewed byte object." + ] +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-final.md b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-final.md new file mode 100644 index 0000000..970f766 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-final.md @@ -0,0 +1,24 @@ +# Independent Domain final changed-scope check + +**Accepted for the reviewed Domain and T35 changed scope.** The previously accepted component corrections are now embedded exactly in the rebuilt public manuscripts, and their relevant navigation resolves. This does not approve my own Root module explanations or claim independent review of all contents of the four manuscripts. + +The 14 accepted Domain explanations (L88, L244, L298–301, L353, L424, L710–713, L1034–1035) match their current English/Chinese detailed-reader entries exactly. Each corresponding anchor occurs once and reaches the matching physical source line. The full Domain code fence equals the actual unchanged source; mechanically, all 902 rendered Domain explanations also equal the accepted component JSON, so regeneration did not disturb the 888 unchanged entries. This mechanical comparison reuses their prior independent meaning review rather than repeating it. + +T35's title, conclusion, premises, proof account and limits match the accepted component exactly in all four views. The public text now states that the same old/new pair changes five grounds together, distinguishes the disjunctive guard from substantive sufficiency, and identifies old/recordedOld tampering against fixed history. RD3 is therefore closed in the generated views, not just the intermediate component. RD1, RD2 and the necessary RD4 corrections likewise appear exactly as accepted; optional local-line improvements are also embedded. + +Actual target lookups for T23, T24, T26, T28, T31 and T35 resolve from each overview to its matching detail target, then to its Domain declaration anchors. T35 source-unit links resolve in every view. The JSON records each inspected anchor, current document line, exact explanation and actual source line. + +## Exact read objects + +- `SoftwareEngineering/lean/philosophy/overview.md`: `c8b01525a54a9beb78086a17652ea4ded4740dad956a0a9a4f9c0ae3ee7171a2` +- `SoftwareEngineering/lean/philosophy/details.md`: `1b8d07cbbf3a0e7005821bc2261f89b1675d43a053802e8b779b1930e0d782af` +- `SoftwareEngineering/zh/lean/philosophy/overview.md`: `31fd96fd034ab16e92d3ecc600237bf9f27fcddaff754b308e4ca14573b58a61` +- `SoftwareEngineering/zh/lean/philosophy/details.md`: `5eba3d944c7bcef294bfed822e6c4aa8205e3e238157da5fb95365bbb57169ff` + +Domain code: `ce5653a2950cc7443cefbfe8b9726bd4859228e831ddb7d42601e501ccbfd855`. + +Authoritative source: `6c6ae78a23f2726c5c370434e808d76c206647fe7793245e88cae52c076abe34`; selected baseline remains SoftwareEngineering 0.2.0 / adopted Core 0.1.2. Actual public targets match the frozen targets hash `c0939df35dad148a0543ba92a1ac7b7d3b2eb4946f92ac4be251ec51b6481d13`. The JSON binds the actual run, narrative file, exact T35 record, both Domain components and all current Lean file hashes. Every Lean hash matches the third snapshot; hashing other modules does not constitute semantic self-review. + +Precise read copies are under reader-independent-domain-final-input/. Earlier r1 and r2 reports remain unchanged with hashes recorded in the final JSON. The initiator supplied manifest hash `1707734f6c51b9f7cd802ba8b84ed2a4d80fb6a7617d53eac081568689fee0c1` and reported an actual gate pass. These are explicitly recorded as initiator metadata; this acceptance is grounded in independently inspected view/code/source/target bytes and navigation, not that gate report. Later public-QA/review-metadata changes may alter manifest identity without altering this read object. + +No Lean build or full Domain semantic reread was needed: the code, prior actual probes and accepted component values are unchanged. No author/source/public file was edited. This concludes the specified changed-scope embedding/navigation check, not browser visual QA, philosophical proof or independent approval of my authored Root prose. Relevant byte changes require a new impact-specific check; a metadata-only manifest update does not retroactively change what was read. diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r1-granularity-clarification.json b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r1-granularity-clarification.json new file mode 100644 index 0000000..a48b388 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r1-granularity-clarification.json @@ -0,0 +1,44 @@ +{ + "clarifies": "reader-independent-domain-r1.json RD4", + "preserves_initial_judgment": true, + "necessary_line_mapping_corrections": [ + { + "line": 88, + "actual": "match d with", + "issue": "Dispatches over every Change; current EN/ZH describes only addition/independent.", + "correction": "Explain selection of the appropriate path branch by intended change; reserve base-only semantics for L89." + }, + { + "line": 244, + "actual": "objective := fun b => match b with", + "issue": "Dispatches the objective by every Burden; current EN/ZH describes only understanding.", + "correction": "Explain burden-indexed objective string selection; reserve successor-onboarding semantics for L245." + } + ], + "optional_line_locality_improvements": [ + { + "lines": [ + 298, + 299, + 300, + 301 + ], + "reason": "Repeated whole summary does accurately include the none and some meanings; no missing proof step or false domain was found. Local declaration/match/branch explanations would improve retrieval but are not a separate blocker." + }, + { + "lines": [ + 710, + 711, + 712, + 713 + ], + "reason": "Repeated mutation summary correctly describes caller-check exclusion while retaining other work; no missing proof step was found. Distinguishing definition, record update, filter and predicate is a quality improvement, not a semantic blocker." + } + ], + "necessary_semantic_corrections_unchanged": [ + "RD1", + "RD2", + "RD3" + ], + "author_files_changed": false +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r1-probes-attempt1.log b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r1-probes-attempt1.log new file mode 100644 index 0000000..62784fa --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r1-probes-attempt1.log @@ -0,0 +1,18 @@ +exit_code=1 +insertOrdered : Nat → List Nat → List Nat +[1, 3, 0] +:5:221: error(lean.synthInstanceFailed): failed to synthesize instance of type class + Decidable + (DomainSatisfied + (withEvolvableProfile + (let __src := profile Candidate.evolvable; + { orderOutput := __src.orderOutput, unsafeOperations := 1, latency := __src.latency, + retention := __src.retention })) + Candidate.evolvable) + +Hint: Type class instance resolution failures can be inspected with the `set_option trace.Meta.synthInstance true` command. +(true, false) +(17, 18, 17) +(true, true, false, false, false) +(9, 10, true) +(false, false, false, false) diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r1-probes-attempt1.txt b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r1-probes-attempt1.txt new file mode 100644 index 0000000..873ca7a --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r1-probes-attempt1.txt @@ -0,0 +1,16 @@ +import CoreReader.Engineering.Domain +open CoreReader.Engineering +#check @insertOrdered +#eval insertOrdered 1 [3, 0] +#eval (decide (PriorityConditions (withEvolvableProfile { profile .evolvable with unsafeOperations := 1 })), decide (EvolutionPriority (withEvolvableProfile { profile .evolvable with unsafeOperations := 1 }) .evolvable), decide (DomainSatisfied (withEvolvableProfile { profile .evolvable with unsafeOperations := 1 }) .evolvable)) +#eval (decide (ContinuingCapability { continuingActivity with participants := [] } .evolvable .designRevision), decide (CanChange { continuingActivity with tools := [] } .evolvable .successor .designRevision)) +#eval (designWork privateDesign .designRevision, designWork wrappedDesign .designRevision, designWork sameWorkDesign .designRevision) +#eval (crossesBoundary boundaryDesign .coordinated coordinatedBoundary, boundaryObligationChecked boundaryDesign .coordinated coordinatedBoundary, boundaryObligationChecked omittedCallerCheck .coordinated coordinatedBoundary, crossesBoundary otherCalleeDesign .coordinated otherCalleeBoundary, boundaryObligationChecked { boundaryDesign with run := sortedUnique } .coordinated coordinatedBoundary) +#eval ((supportedDirections continuingActivity .evolvable).length, (supportedDirections continuingActivity .maximal).length, decide (HasThreat currentContinuing .maximal)) +#eval (decide (RevisionAccount rewrittenOldRecord), decide (RevisionAccount rewrittenPredictionRecord), decide (RevisionAccount rewrittenObservationRecord), decide (MaterialGroundsChanged oldState { oldState with time := 1, choice := .presentSimple })) +example : PreservesFinite orderedUnique retiredBehavior ∧ ¬ PreservesOn (fun _ => True) orderedUnique retiredBehavior := by + constructor + · decide + · intro h + have bad := h [99] trivial + contradiction diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r1-probes.log b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r1-probes.log new file mode 100644 index 0000000..744ce0b --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r1-probes.log @@ -0,0 +1,9 @@ +exit_code=0 +insertOrdered : Nat → List Nat → List Nat +[1, 3, 0] +(false, true) +(true, false) +(17, 18, 17) +(true, true, false, false, false) +(9, 10, true) +(false, false, false, false) diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r1-probes.txt b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r1-probes.txt new file mode 100644 index 0000000..b2cceb3 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r1-probes.txt @@ -0,0 +1,18 @@ +import CoreReader.Engineering.Domain +open CoreReader.Engineering +#check @insertOrdered +#eval insertOrdered 1 [3, 0] +#eval (decide (PriorityConditions (withEvolvableProfile { profile .evolvable with unsafeOperations := 1 })), decide (EvolutionPriority (withEvolvableProfile { profile .evolvable with unsafeOperations := 1 }) .evolvable)) +example : DomainSatisfied (withEvolvableProfile { profile .evolvable with unsafeOperations := 1 }) .evolvable := by + exact ⟨currentDomainSatisfied.1, (fun _ => Or.inl rfl), currentDomainSatisfied.2.2⟩ +#eval (decide (ContinuingCapability { continuingActivity with participants := [] } .evolvable .designRevision), decide (CanChange { continuingActivity with tools := [] } .evolvable .successor .designRevision)) +#eval (designWork privateDesign .designRevision, designWork wrappedDesign .designRevision, designWork sameWorkDesign .designRevision) +#eval (crossesBoundary boundaryDesign .coordinated coordinatedBoundary, boundaryObligationChecked boundaryDesign .coordinated coordinatedBoundary, boundaryObligationChecked omittedCallerCheck .coordinated coordinatedBoundary, crossesBoundary otherCalleeDesign .coordinated otherCalleeBoundary, boundaryObligationChecked { boundaryDesign with run := sortedUnique } .coordinated coordinatedBoundary) +#eval ((supportedDirections continuingActivity .evolvable).length, (supportedDirections continuingActivity .maximal).length, decide (HasThreat currentContinuing .maximal)) +#eval (decide (RevisionAccount rewrittenOldRecord), decide (RevisionAccount rewrittenPredictionRecord), decide (RevisionAccount rewrittenObservationRecord), decide (MaterialGroundsChanged oldState { oldState with time := 1, choice := .presentSimple })) +example : PreservesFinite orderedUnique retiredBehavior ∧ ¬ PreservesOn (fun _ => True) orderedUnique retiredBehavior := by + constructor + · decide + · intro h + have bad := h [99] trivial + contradiction diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r1.json b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r1.json new file mode 100644 index 0000000..721a9cd --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r1.json @@ -0,0 +1,717 @@ +{ + "reviewer_role": "independent_domain_reader_reviewer", + "authorship_separation": "Reviewer authored only Engineering Reflection/SelfApplication/Values/Integration explanations; those modules are excluded from this review. Domain line explanations and related T22–T36 target reader prose were not authored by this reviewer.", + "baseline": "SoftwareEngineering 0.2.0 / adopted Core 0.1.2", + "reviewed_byte_objects": [ + { + "path": "private software-engineering iteration records/domain-line-explanations-en.json", + "snapshot": "private software-engineering iteration records/reader-independent-domain-r1-input/domain-line-explanations-en.json", + "sha256": "c9da0d3e5f67238aad594f687a7e34ac2b45240e9b78708117849c2c8d6c427e" + }, + { + "path": "private software-engineering iteration records/domain-line-explanations-zh.json", + "snapshot": "private software-engineering iteration records/reader-independent-domain-r1-input/domain-line-explanations-zh.json", + "sha256": "19d4683c925bfb4e9d9e679653e0dfcb67ef2eb23b20226d48e329391d727cbf" + }, + { + "path": "SoftwareEngineering/lean/philosophy/leanified/CoreReader/Engineering/Domain.lean", + "snapshot": "private software-engineering iteration records/reader-independent-domain-r1-input/lean__philosophy__leanified__CoreReader__Engineering__Domain.lean", + "sha256": "ce5653a2950cc7443cefbfe8b9726bd4859228e831ddb7d42601e501ccbfd855" + }, + { + "path": "SoftwareEngineering/lean/philosophy/overview.md", + "snapshot": "private software-engineering iteration records/reader-independent-domain-r1-input/lean__philosophy__overview.md", + "sha256": "02432a947512ab709aed33c8fcd078764b96263666d0148fec5c92e111eb6f6e" + }, + { + "path": "SoftwareEngineering/lean/philosophy/details.md", + "snapshot": "private software-engineering iteration records/reader-independent-domain-r1-input/lean__philosophy__details.md", + "sha256": "5e6653bfe714707aea4dedb50d97d5e155e65c3e8279c5e88a78f07e525e0199" + }, + { + "path": "SoftwareEngineering/zh/lean/philosophy/overview.md", + "snapshot": "private software-engineering iteration records/reader-independent-domain-r1-input/zh__lean__philosophy__overview.md", + "sha256": "05f30d6cf6d8df5a1ab509cdeeb4f5b29c87df61d1ca178102645823c5a75b7f" + }, + { + "path": "SoftwareEngineering/zh/lean/philosophy/details.md", + "snapshot": "private software-engineering iteration records/reader-independent-domain-r1-input/zh__lean__philosophy__details.md", + "sha256": "830ea6830be5605c4e187086843ea0e4b56897df70a1feb0443302269baa7d80" + } + ], + "scope": "Both Domain explanation JSON files, all 902 actual nonblank Domain source lines, their rendered detailed-reader entries, and related T22–T36 overview/detail target retrieval in both languages. No source-reader review verdict was read before this initial judgment.", + "verdict": "changes_requested_for_reader_precision", + "findings": [ + { + "id": "RD1", + "priority": 2, + "status": "requires_wording_revision", + "location": { + "json_files": [ + "domain-line-explanations-en.json", + "domain-line-explanations-zh.json" + ], + "source_lines": [ + 353, + 1034, + 1035 + ] + }, + "title": "Do not turn failed priority applicability into rejection of the selected design", + "actual_text_en": "Tests that failure of any represented necessary requirement prevents activation of priority, rather than licensing an unsafe evolutionary choice.", + "actual_text_zh": "检验任一已表示必要需求失败都会阻止优先条件激活,而不是允许不安全的演化选择。", + "finding": "The positive statement about PriorityConditions is correct, but the contrast can imply that the represented overall selection is rejected. EvolutionPriority is an implication, and DomainSatisfied contains no separate unconditional Meets conjunct. For the actual evolvable profile with unsafeOperations := 1, PriorityConditions is false, EvolutionPriority is true, and DomainSatisfied is provable. The line explanations should expose that conditional limit, not imply an overall safety-rejection theorem.", + "evidence": "reader-independent-domain-r1-probes.log: (false, true); the immediately following example proves DomainSatisfied with the unsafe profile by reusing unaffected currentDomainSatisfied fields.", + "requested_change": "Replace the contrast with an explicit statement that the theorem only blocks priority activation; it does not prove rejection by EvolutionPriority or DomainSatisfied. Add that conditional limit at the DomainSatisfied entry. No source or Lean change is requested.", + "meaning_limit": "This finding concerns accuracy of the reader, not whether an unsafe design should be selected, and does not change the preserved bounded source-correspondence verdict." + }, + { + "id": "RD2", + "priority": 2, + "status": "requires_wording_revision", + "location": { + "json_files": [ + "domain-line-explanations-en.json", + "domain-line-explanations-zh.json" + ], + "source_lines": [ + 424 + ] + }, + "title": "insertOrdered has no sorted-input premise", + "actual_text_en": "Insertion receives one value and a sorted tail, supporting the comparison implementation's sorting behavior.", + "actual_text_zh": "插入函数接收一个值与有序列表,支持对比实现的排序行为。", + "finding": "The actual full type is Nat → List Nat → List Nat. There is no sortedness argument, subtype or premise. sortValues recursively supplies its sorted tail to this helper, but that caller-specific role must not be stated as the helper domain.", + "evidence": "#check @insertOrdered; #eval insertOrdered 1 [3,0] returns [1,3,0].", + "requested_change": "Say it takes a natural number and an arbitrary natural-number list; when sortValues calls it with the recursively sorted tail, it performs ordered insertion. Do not imply that the declared type enforces sorted input." + }, + { + "id": "RD3", + "priority": 2, + "status": "requires_wording_revision", + "location": { + "manuscripts": [ + "lean/philosophy/overview.md:673", + "lean/philosophy/details.md:1579", + "zh/lean/philosophy/overview.md:673", + "zh/lean/philosophy/details.md:1579" + ], + "target": "T35", + "source_lines": [ + 889, + 890, + 891, + 892, + 894, + 895, + 951, + 953, + 954, + 955, + 956, + 957 + ] + }, + "title": "The revision example changes five grounds together, not one at a time", + "actual_text_en": "The cases change one material ground at a time and retain truthful change reporting.", + "actual_text_zh": "案例分别改变实质根据,并保留如实变化报告。", + "finding": "oldState and newState differ simultaneously in forecast, maintenance, maintainers, migrationCost and objectiveCapacity. revisionCases proves all five differences for that same pair. MaterialGroundsChanged is an OR over those fields, but there are no five one-field-at-a-time revision examples in these declarations. The independent Domain L951–957 explanations correctly describe the simultaneous five-field case.", + "requested_change": "State that the concrete revision contains all five material differences simultaneously. Separately explain that MaterialGroundsChanged accepts any one listed difference, and that this necessary account condition does not prove each isolated difference substantively justifies every changed choice." + }, + { + "id": "RD4", + "priority": 3, + "status": "requires_line_local_revision", + "location": { + "json_files": [ + "domain-line-explanations-en.json", + "domain-line-explanations-zh.json" + ], + "source_lines": [ + 88, + 244, + 298, + 299, + 300, + 301, + 710, + 711, + 712, + 713 + ] + }, + "title": "Several per-line explanations repeat a block summary instead of the actual line role", + "finding": "The files cover every line, but line-local precision is uneven. L88 is the dispatch over every Change and is explained only as the addition/independent branch; L244 begins objective dispatch over every Burden and is explained only as understanding. L298–301 repeat the same whole departure summary for declaration, match, none and some branches. L710–713 repeat the same whole mutation summary rather than distinguish definition, record update, filter and exclusion predicate. These summaries are mostly true at block scope, but do not meet the requested per-nonempty-line role explanation.", + "requested_change": "Correct the two branch-dispatch descriptions and split grouped summaries at substantive lines into their actual local operations, at least the specified match/none/some and record/filter/predicate examples. Preserve concise shared context on the declaration line; do not require arbitrary word variation for comment continuation or other naturally inseparable syntax." + } + ], + "semantic_groups": [ + { + "group": "Activity, participants, tools and knowledge", + "lines": "7–166", + "result": "meaning_matches_with_line_granularity_note", + "details": "Read both languages against all actual fields and path constructors. CanChange needs nonempty path, actual participant membership and all step knowledge/tools. ContinuingCapability quantifies over listed participants, so the empty-participant vacuity is real and correctly distinguished from ActivityScope. Probes verify empty participants can satisfy ContinuingCapability while no tools blocks the successor path." + }, + { + "group": "Credibility, costs, priority and actual maximum", + "lines": "168–418", + "result": "matches_except_RD1_and_RD4", + "details": "Open Ground type, separate articulation/support and concrete plan/knowledge/history/other interpretations are disclosed. PriorityConditions retains both candidates Meets, actual continuing capability, 6<17 work and 1<3 complexity. JustifiedDeparture requires a selected burden and a concrete named objective with cost above baseline and capacity. Maximal genuinely supports ten registered directions versus evolvable nine; it exceeds the cost limit. Probe verifies (9,10,true threat). No universal maximum or universal monetary exchange is claimed." + }, + { + "group": "State changes, evolution claims, finite and universal contracts", + "lines": "420–608,822–864", + "result": "matches_except_RD2", + "details": "Read actual transform fields, separate evolutionBehavior, order/retry contracts, independent fixed party dependencies, report comparisons and treatment labels. PreservesFinite has four list samples; retry has six indices. contractPreservation returns its supplied ∀ input scoped equality, while changedObservationNotPreserved applies it to the given witness. Independent proof shows retiredBehavior passes the finite suite but fails universal True-scope preservation at [99]. No universal notification or fixed procedure is asserted." + }, + { + "group": "Structural account and actual boundary", + "lines": "610–749", + "result": "meaning_matches_with_line_granularity_note", + "details": "Read every evidence-field identity, work sum/count distinction and natural subtraction. Actual edge 2→1 belongs to actual design, both endpoints exist and differ, actual callee compiler/editor work must occur, and caller 2 must have publicContract contractRunner work plus actual finite output preservation. Removing caller check preserves crossing but fails obligation; callee 7 breaks path relation despite actual membership; changed sorted run breaks obligation with same edge/steps. Probe tuple (true,true,false,false,false) confirms these exact objects." + }, + { + "group": "Metadata insufficiency and real boundary transformations", + "lines": "751–817", + "result": "meaning_matches", + "details": "Read DesignCanChange and actual EngineeringDesign paths. introduceBoundary adds component/edge and one check to existing paths (private work17→wrapped18). relocateVerification starts from that wrapper but overrides paths using original-step map; only contractRunner component identifiers change, so sameWork remains17 and lacks privateLayout for the successor. The explanations accurately retain actual edge 8→0, nine components, changed path, same observed output, work17=17 and absent capability. Generic new-id freshness is correctly limited to concrete range8 design." + }, + { + "group": "Fixed history, changed grounds, retention and current context", + "lines": "866–1047", + "result": "line_explanations_match_except_RD1_scope_omission; target_T35_needs_RD3", + "details": "Read independent HistoricalEvidence versus report fields, OR of five material-ground differences, accurate old/current records, predicted3/actual5, all considered-directions criticism coverage, stable choice, retention criteria and revisionFor exact context fields. Account demands material change when choice changes, not sufficiency of each difference. History-tampering and time/choice-only probes all false. failedHistoryNotRewritten is a projection plus simplification for arbitrary history, not log authentication." + } + ], + "actual_probes": { + "cwd": "/var/folders/vc/1wh7h94d2317t8j271746h8h0000gn/T/organon-se-code-delta-rvdor6nj/r3-input/third-code-snapshot", + "domain_hash_matches_production_and_R3": true, + "toolchain": "Lean 4.33.1", + "input": "private software-engineering iteration records/reader-independent-domain-r1-probes.txt", + "log": "private software-engineering iteration records/reader-independent-domain-r1-probes.log", + "final_exit_code": 0, + "preserved_attempt1": "First attempt used #eval decide on DomainSatisfied and failed solely because no inferred Decidable instance was available. It was preserved as attempt1; final attempt replaces this with an explicit kernel-checked proof, not an assumed Boolean result." + }, + "retrieval": [ + { + "language": "en", + "nonempty_source_lines": 902, + "json_entries": 902, + "missing": [], + "extra": [], + "rendered_explanations_exact": true, + "source_fenced_code_exact": true, + "every_nonempty_line_anchor_exists": true, + "duplicate_domain_line_anchors": [], + "targets": [ + { + "target": "T22", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 49, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-49", + "anchor_exists": true, + "actual_source_line": "abbrev ActivityScope (a : Activity) : Prop :=" + }, + { + "source_line": 146, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-146", + "anchor_exists": true, + "actual_source_line": "theorem subjectLifecycleCases :" + } + ] + }, + { + "target": "T23", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 159, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-159", + "anchor_exists": true, + "actual_source_line": "theorem subjectLimits :" + } + ] + }, + { + "target": "T24", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 321, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-321", + "anchor_exists": true, + "actual_source_line": "abbrev EvolutionPriority (ctx : Context) (chosen : Candidate) : Prop :=" + }, + { + "source_line": 367, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-367", + "anchor_exists": true, + "actual_source_line": "theorem priorityConditionsCases :" + } + ] + }, + { + "target": "T25", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 337, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-337", + "anchor_exists": true, + "actual_source_line": "theorem priorityWhenApplicable (ctx : Context) (chosen : Candidate)" + }, + { + "source_line": 384, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-384", + "anchor_exists": true, + "actual_source_line": "theorem priorityChoices :" + } + ] + }, + { + "target": "T26", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 174, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-174", + "anchor_exists": true, + "actual_source_line": "abbrev CredibleDirection {Ground : Type} (grounds : List Ground)" + }, + { + "source_line": 212, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-212", + "anchor_exists": true, + "actual_source_line": "theorem credibilityCases :" + } + ] + }, + { + "target": "T27", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 394, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-394", + "anchor_exists": true, + "actual_source_line": "theorem credibilityLimits :" + } + ] + }, + { + "target": "T28", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 298, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-298", + "anchor_exists": true, + "actual_source_line": "abbrev JustifiedDeparture (ctx : Context) (c : Candidate) : Prop :=" + }, + { + "source_line": 410, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-410", + "anchor_exists": true, + "actual_source_line": "theorem costCases :" + } + ] + }, + { + "target": "T29", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 556, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-556", + "anchor_exists": true, + "actual_source_line": "abbrev EvolutionClaim (a : Activity) (c : Candidate) (claim : ChangeClaim) : Prop :=" + }, + { + "source_line": 569, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-569", + "anchor_exists": true, + "actual_source_line": "theorem evolutionKindsCases :" + } + ] + }, + { + "target": "T30", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 585, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-585", + "anchor_exists": true, + "actual_source_line": "theorem evolutionDimensionsLimits :" + } + ] + }, + { + "target": "T31", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 641, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-641", + "anchor_exists": true, + "actual_source_line": "abbrev StructuralAccount (a : Activity) (c : Candidate) (e : StructuralEvidence) : Prop :=" + }, + { + "source_line": 733, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-733", + "anchor_exists": true, + "actual_source_line": "theorem structuralCases :" + } + ] + }, + { + "target": "T32", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 793, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-793", + "anchor_exists": true, + "actual_source_line": "theorem structureNotCapability :" + } + ] + }, + { + "target": "T33", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 549, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-549", + "anchor_exists": true, + "actual_source_line": "abbrev ContractChangeAccount (old new : ObservableContract) (r : ContractRevision) : Prop :=" + }, + { + "source_line": 843, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-843", + "anchor_exists": true, + "actual_source_line": "theorem contractCases :" + } + ] + }, + { + "target": "T34", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 822, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-822", + "anchor_exists": true, + "actual_source_line": "theorem contractPreservation {Input Output : Type} (scope : Input → Prop)" + }, + { + "source_line": 853, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-853", + "anchor_exists": true, + "actual_source_line": "theorem contractDistinctions :" + } + ] + }, + { + "target": "T35", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 922, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-922", + "anchor_exists": true, + "actual_source_line": "abbrev RevisionAccount (r : RevisionRecord) : Prop := RevisionAccountAgainst observedHistory r" + }, + { + "source_line": 951, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-951", + "anchor_exists": true, + "actual_source_line": "theorem revisionCases :" + } + ] + }, + { + "target": "T36", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 993, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-993", + "anchor_exists": true, + "actual_source_line": "theorem revisionLimits :" + } + ] + } + ] + }, + { + "language": "zh", + "nonempty_source_lines": 902, + "json_entries": 902, + "missing": [], + "extra": [], + "rendered_explanations_exact": true, + "source_fenced_code_exact": true, + "every_nonempty_line_anchor_exists": true, + "duplicate_domain_line_anchors": [], + "targets": [ + { + "target": "T22", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 49, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-49", + "anchor_exists": true, + "actual_source_line": "abbrev ActivityScope (a : Activity) : Prop :=" + }, + { + "source_line": 146, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-146", + "anchor_exists": true, + "actual_source_line": "theorem subjectLifecycleCases :" + } + ] + }, + { + "target": "T23", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 159, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-159", + "anchor_exists": true, + "actual_source_line": "theorem subjectLimits :" + } + ] + }, + { + "target": "T24", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 321, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-321", + "anchor_exists": true, + "actual_source_line": "abbrev EvolutionPriority (ctx : Context) (chosen : Candidate) : Prop :=" + }, + { + "source_line": 367, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-367", + "anchor_exists": true, + "actual_source_line": "theorem priorityConditionsCases :" + } + ] + }, + { + "target": "T25", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 337, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-337", + "anchor_exists": true, + "actual_source_line": "theorem priorityWhenApplicable (ctx : Context) (chosen : Candidate)" + }, + { + "source_line": 384, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-384", + "anchor_exists": true, + "actual_source_line": "theorem priorityChoices :" + } + ] + }, + { + "target": "T26", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 174, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-174", + "anchor_exists": true, + "actual_source_line": "abbrev CredibleDirection {Ground : Type} (grounds : List Ground)" + }, + { + "source_line": 212, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-212", + "anchor_exists": true, + "actual_source_line": "theorem credibilityCases :" + } + ] + }, + { + "target": "T27", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 394, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-394", + "anchor_exists": true, + "actual_source_line": "theorem credibilityLimits :" + } + ] + }, + { + "target": "T28", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 298, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-298", + "anchor_exists": true, + "actual_source_line": "abbrev JustifiedDeparture (ctx : Context) (c : Candidate) : Prop :=" + }, + { + "source_line": 410, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-410", + "anchor_exists": true, + "actual_source_line": "theorem costCases :" + } + ] + }, + { + "target": "T29", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 556, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-556", + "anchor_exists": true, + "actual_source_line": "abbrev EvolutionClaim (a : Activity) (c : Candidate) (claim : ChangeClaim) : Prop :=" + }, + { + "source_line": 569, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-569", + "anchor_exists": true, + "actual_source_line": "theorem evolutionKindsCases :" + } + ] + }, + { + "target": "T30", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 585, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-585", + "anchor_exists": true, + "actual_source_line": "theorem evolutionDimensionsLimits :" + } + ] + }, + { + "target": "T31", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 641, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-641", + "anchor_exists": true, + "actual_source_line": "abbrev StructuralAccount (a : Activity) (c : Candidate) (e : StructuralEvidence) : Prop :=" + }, + { + "source_line": 733, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-733", + "anchor_exists": true, + "actual_source_line": "theorem structuralCases :" + } + ] + }, + { + "target": "T32", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 793, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-793", + "anchor_exists": true, + "actual_source_line": "theorem structureNotCapability :" + } + ] + }, + { + "target": "T33", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 549, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-549", + "anchor_exists": true, + "actual_source_line": "abbrev ContractChangeAccount (old new : ObservableContract) (r : ContractRevision) : Prop :=" + }, + { + "source_line": 843, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-843", + "anchor_exists": true, + "actual_source_line": "theorem contractCases :" + } + ] + }, + { + "target": "T34", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 822, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-822", + "anchor_exists": true, + "actual_source_line": "theorem contractPreservation {Input Output : Type} (scope : Input → Prop)" + }, + { + "source_line": 853, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-853", + "anchor_exists": true, + "actual_source_line": "theorem contractDistinctions :" + } + ] + }, + { + "target": "T35", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 922, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-922", + "anchor_exists": true, + "actual_source_line": "abbrev RevisionAccount (r : RevisionRecord) : Prop := RevisionAccountAgainst observedHistory r" + }, + { + "source_line": 951, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-951", + "anchor_exists": true, + "actual_source_line": "theorem revisionCases :" + } + ] + }, + { + "target": "T36", + "overview_link_resolves": true, + "domain_declaration_links": [ + { + "source_line": 993, + "anchor": "line-code-leanified-corereader-engineering-domain-lean-993", + "anchor_exists": true, + "actual_source_line": "theorem revisionLimits :" + } + ] + } + ] + } + ], + "reuse": "Exact Domain code hash matches the previously independently audited R3 object ce5653a2950cc7443cefbfe8b9726bd4859228e831ddb7d42601e501ccbfd855. Reused its build/declaration/axiom audit for unchanged code. The current manuscript meanings were read independently and fresh probes were run; coverage did not determine the semantic verdict.", + "limits": [ + "No independent review of reviewer-authored Root line explanations.", + "No judgment on later manuscript or source changes beyond the recorded hashes.", + "Anchor/code/JSON checks do not prove philosophical correspondence or rendered UI quality.", + "Findings request prose corrections only; no change to Lean or philosophical commitments is inferred." + ], + "artifact_hashes": { + "reader-independent-domain-r1-probes.txt": "c5bc1cb06352637044d694d9dcc49737862246576fba49ac0ecc481ea06dac21", + "reader-independent-domain-r1-probes.log": "7b1f6762c8a3a910b04b32067ba975daa3ceb4a3ea45cf29ef93e6e627194fd0", + "reader-independent-domain-r1-probes-attempt1.txt": "aca48116bb1731f3e48abf43f0e292f81c39a45ddcba5cb78245d4a199d76ddf", + "reader-independent-domain-r1-probes-attempt1.log": "74ad440eb9dce2a397b754e17193af987798b6b1fce12cd2390a581de8fc394c", + "reader-independent-domain-r1-retrieval.json": "38259c486148a5626f2e09c06614aa382544080ab338da8f85ee2cccded169c4" + } +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r1.md b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r1.md new file mode 100644 index 0000000..5c64e26 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r1.md @@ -0,0 +1,58 @@ +# Independent Domain reader review, r1 + +Verdict: **reader wording revisions required**. Most substantive Domain explanations faithfully retain the checked finite-model meaning. Four findings below concern explanatory precision; no Lean or philosophical-source change is requested. This is an independent review of Domain and related T22–T36 target prose, not self-review of the four Root modules I authored. + +The exact production Domain bytes have SHA-256 `ce5653a2950cc7443cefbfe8b9726bd4859228e831ddb7d42601e501ccbfd855`, identical to the previously checked R3 object. The input JSON hashes are EN `c9da0d3e5f67238aad594f687a7e34ac2b45240e9b78708117849c2c8d6c427e` and ZH `19d4683c925bfb4e9d9e679653e0dfcb67ef2eb23b20226d48e329391d727cbf`. Copies of these files, exact source and all four manuscripts were retained under `reader-independent-domain-r1-input/`; its hashes.json and this review JSON identify every byte object. The judgment precedes any reading of another source-reader review conclusion. + +## Required corrections + +### RD1 (P2): Do not turn failed priority applicability into rejection of the selected design + +The positive statement about PriorityConditions is correct, but the contrast can imply that the represented overall selection is rejected. EvolutionPriority is an implication, and DomainSatisfied contains no separate unconditional Meets conjunct. For the actual evolvable profile with unsafeOperations := 1, PriorityConditions is false, EvolutionPriority is true, and DomainSatisfied is provable. The line explanations should expose that conditional limit, not imply an overall safety-rejection theorem. + +Correction: Replace the contrast with an explicit statement that the theorem only blocks priority activation; it does not prove rejection by EvolutionPriority or DomainSatisfied. Add that conditional limit at the DomainSatisfied entry. No source or Lean change is requested. + +Location: `{"json_files": ["domain-line-explanations-en.json", "domain-line-explanations-zh.json"], "source_lines": [353, 1034, 1035]}`. + +### RD2 (P2): insertOrdered has no sorted-input premise + +The actual full type is Nat → List Nat → List Nat. There is no sortedness argument, subtype or premise. sortValues recursively supplies its sorted tail to this helper, but that caller-specific role must not be stated as the helper domain. + +Correction: Say it takes a natural number and an arbitrary natural-number list; when sortValues calls it with the recursively sorted tail, it performs ordered insertion. Do not imply that the declared type enforces sorted input. + +Location: `{"json_files": ["domain-line-explanations-en.json", "domain-line-explanations-zh.json"], "source_lines": [424]}`. + +### RD3 (P2): The revision example changes five grounds together, not one at a time + +oldState and newState differ simultaneously in forecast, maintenance, maintainers, migrationCost and objectiveCapacity. revisionCases proves all five differences for that same pair. MaterialGroundsChanged is an OR over those fields, but there are no five one-field-at-a-time revision examples in these declarations. The independent Domain L951–957 explanations correctly describe the simultaneous five-field case. + +Correction: State that the concrete revision contains all five material differences simultaneously. Separately explain that MaterialGroundsChanged accepts any one listed difference, and that this necessary account condition does not prove each isolated difference substantively justifies every changed choice. + +Location: `{"manuscripts": ["lean/philosophy/overview.md:673", "lean/philosophy/details.md:1579", "zh/lean/philosophy/overview.md:673", "zh/lean/philosophy/details.md:1579"], "target": "T35", "source_lines": [889, 890, 891, 892, 894, 895, 951, 953, 954, 955, 956, 957]}`. + +### RD4 (P3): Several per-line explanations repeat a block summary instead of the actual line role + +The files cover every line, but line-local precision is uneven. L88 is the dispatch over every Change and is explained only as the addition/independent branch; L244 begins objective dispatch over every Burden and is explained only as understanding. L298–301 repeat the same whole departure summary for declaration, match, none and some branches. L710–713 repeat the same whole mutation summary rather than distinguish definition, record update, filter and exclusion predicate. These summaries are mostly true at block scope, but do not meet the requested per-nonempty-line role explanation. + +Correction: Correct the two branch-dispatch descriptions and split grouped summaries at substantive lines into their actual local operations, at least the specified match/none/some and record/filter/predicate examples. Preserve concise shared context on the declaration line; do not require arbitrary word variation for comment continuation or other naturally inseparable syntax. + +Location: `{"json_files": ["domain-line-explanations-en.json", "domain-line-explanations-zh.json"], "source_lines": [88, 244, 298, 299, 300, 301, 710, 711, 712, 713]}`. + +## Meaning checks and actual evidence + +- **Activity, participants, tools and knowledge** (Domain L7–166): Read both languages against all actual fields and path constructors. CanChange needs nonempty path, actual participant membership and all step knowledge/tools. ContinuingCapability quantifies over listed participants, so the empty-participant vacuity is real and correctly distinguished from ActivityScope. Probes verify empty participants can satisfy ContinuingCapability while no tools blocks the successor path. +- **Credibility, costs, priority and actual maximum** (Domain L168–418): Open Ground type, separate articulation/support and concrete plan/knowledge/history/other interpretations are disclosed. PriorityConditions retains both candidates Meets, actual continuing capability, 6<17 work and 1<3 complexity. JustifiedDeparture requires a selected burden and a concrete named objective with cost above baseline and capacity. Maximal genuinely supports ten registered directions versus evolvable nine; it exceeds the cost limit. Probe verifies (9,10,true threat). No universal maximum or universal monetary exchange is claimed. +- **State changes, evolution claims, finite and universal contracts** (Domain L420–608,822–864): Read actual transform fields, separate evolutionBehavior, order/retry contracts, independent fixed party dependencies, report comparisons and treatment labels. PreservesFinite has four list samples; retry has six indices. contractPreservation returns its supplied ∀ input scoped equality, while changedObservationNotPreserved applies it to the given witness. Independent proof shows retiredBehavior passes the finite suite but fails universal True-scope preservation at [99]. No universal notification or fixed procedure is asserted. +- **Structural account and actual boundary** (Domain L610–749): Read every evidence-field identity, work sum/count distinction and natural subtraction. Actual edge 2→1 belongs to actual design, both endpoints exist and differ, actual callee compiler/editor work must occur, and caller 2 must have publicContract contractRunner work plus actual finite output preservation. Removing caller check preserves crossing but fails obligation; callee 7 breaks path relation despite actual membership; changed sorted run breaks obligation with same edge/steps. Probe tuple (true,true,false,false,false) confirms these exact objects. +- **Metadata insufficiency and real boundary transformations** (Domain L751–817): Read DesignCanChange and actual EngineeringDesign paths. introduceBoundary adds component/edge and one check to existing paths (private work17→wrapped18). relocateVerification starts from that wrapper but overrides paths using original-step map; only contractRunner component identifiers change, so sameWork remains17 and lacks privateLayout for the successor. The explanations accurately retain actual edge 8→0, nine components, changed path, same observed output, work17=17 and absent capability. Generic new-id freshness is correctly limited to concrete range8 design. +- **Fixed history, changed grounds, retention and current context** (Domain L866–1047): Read independent HistoricalEvidence versus report fields, OR of five material-ground differences, accurate old/current records, predicted3/actual5, all considered-directions criticism coverage, stable choice, retention criteria and revisionFor exact context fields. Account demands material change when choice changes, not sufficiency of each difference. History-tampering and time/choice-only probes all false. failedHistoryNotRewritten is a projection plus simplification for arbitrary history, not log authentication. + +Fresh stdin probes use the already built R3 copy whose Domain bytes equal the current production object. The final run exits 0. It checks the untyped sortedness assumption, unsafe-profile conditional-vacuity case, participant/tool conditions, work17/18/17, boundary mutation tuple, maximum9/10 plus cost threat, fixed-history tampering and finite-versus-universal preservation. The first failed attempt is preserved: `#eval decide DomainSatisfied` lacked an inferred Decidable instance. The successful final input instead supplies an explicit proof of that proposition. No proof failure is hidden, and no Lean input file was modified. + +The key universal proof bodies were read individually: priorityWhenApplicable applies its adopted implication and projects the same context's complexity inequality; currentSimpleViolates eliminates distinct constructors; oneDimensionDoesNotEntailEveryDimension specializes a universal strict-improvement assumption to addition; contractPreservation is identity on the supplied universal scoped equality; changedObservationNotPreserved applies that equality to its actual witness; contractRevisionObligations eliminates the preservation disjunct under explicit failure; failedHistoryNotRewritten projects the success-equality field for the same independent history. Concrete conjunction proofs retain their finite scope and were not presented as universal empirical claims. + +## Retrieval result + +Both languages cover exactly the actual 902 nonblank source lines, with zero missing/extra entries, exact rendered JSON text, one anchor per line and an exact full-source fenced block. Each overview target T22–T36 links to the matching target in its own language's details. Each language's 25 Domain declaration links points to an existing line anchor whose actual source line is recorded in `reader-independent-domain-r1-retrieval.json`. These results establish navigation and object identity, not semantic correctness. T35's semantic mismatch persists despite these passing checks. + +Source-map comments are traceability metadata. They neither become Lean assumptions nor prove source correspondence. The selected baseline remains SoftwareEngineering 0.2.0 / adopted Core 0.1.2. Previous exact-object R3 build and declaration/axiom audit are reused only for unchanged code; this report freshly reviews Domain reader meaning and does not approve later objects, authored Root prose, all philosophical interpretation, or rendered visual layout. diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r2.json b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r2.json new file mode 100644 index 0000000..9ee6840 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r2.json @@ -0,0 +1,349 @@ +{ + "role": "independent_narrow_component_recheck", + "authorship_separation": "The reviewer did not author Domain explanations or T35 narrative. This recheck does not review or approve the reviewer-authored Root four-module r2 corrections.", + "baseline": "SoftwareEngineering 0.2.0 / adopted Core 0.1.2", + "source": { + "path": "SoftwareEngineering/lean/philosophy/leanified/CoreReader/Engineering/Domain.lean", + "sha256": "ce5653a2950cc7443cefbfe8b9726bd4859228e831ddb7d42601e501ccbfd855", + "unchanged_from_r1_and_R3": true + }, + "input_hashes": [ + { + "path": "private software-engineering iteration records/domain-line-explanations-en.json", + "sha256": "d1773e14c9e68a81850a9a949f11ab3722dcb3a4c2bd8c663ecf1e8102d3c471" + }, + { + "path": "private software-engineering iteration records/domain-line-explanations-zh.json", + "sha256": "24bf6725f169fad4ec28f335296c0e95c3212136e46ec3ad0974f61a32820c85" + }, + { + "path": "private software-engineering iteration records/domain-line-author-r2-response.md", + "sha256": "e640dadea296155c29b20c3adf20eafe4adeedfdf2f5513dcb65a8a35691a51b" + }, + { + "path": "private software-engineering iteration records/domain-line-author-r2-response.json", + "sha256": "005255f21a726e8c99c72723e3c2b86a88b11619099391ed73ed26deec2a67dd" + }, + { + "path": "private software-engineering iteration records/target-narratives-current.json", + "sha256": "12f534ce9489527799edebe937e5cca39dc3166afb6aec5783473334423b06d4" + } + ], + "verdict": "accepted_changed_components_with_public_view_rebuild_pending", + "diff_and_coverage": [ + { + "language": "en", + "sha256": "d1773e14c9e68a81850a9a949f11ab3722dcb3a4c2bd8c663ecf1e8102d3c471", + "nonempty_source_lines": 902, + "entries": 902, + "unchanged_entries": 888, + "changed_lines": [ + 88, + 244, + 298, + 299, + 300, + 301, + 353, + 424, + 710, + 711, + 712, + 713, + 1034, + 1035 + ], + "missing": [], + "extra": [], + "empty": [], + "author_before_equals_independently_frozen_r1": true, + "changes": [ + { + "line": 88, + "source": " match d with", + "before": "Addition and independent change use only that two-unit base path.", + "after": "Dispatch on the requested Change to choose its corresponding editing path; the following branches distinguish the different directions." + }, + { + "line": 244, + "source": " objective := fun b => match b with", + "before": "The understanding limit concerns successor onboarding capacity.", + "after": "Assign each Burden its objective name by matching on the burden; the following branches supply the distinct engineering objectives." + }, + { + "line": 298, + "source": "abbrev JustifiedDeparture (ctx : Context) (c : Candidate) : Prop :=", + "before": "A justified departure must explicitly select a burden and establish its concrete threat; none supplies no justification.", + "after": "Define justified departure for this context and candidate through a recorded burden whose concrete cost threat must hold." + }, + { + "line": 299, + "source": " match ctx.departure with", + "before": "A justified departure must explicitly select a burden and establish its concrete threat; none supplies no justification.", + "after": "Inspect this same context’s departure option to distinguish an absent explanation from a named burden." + }, + { + "line": 300, + "source": " | none => False", + "before": "A justified departure must explicitly select a burden and establish its concrete threat; none supplies no justification.", + "after": "With no recorded departure burden, justification is False; absence supplies no exception." + }, + { + "line": 301, + "source": " | some b => ConcreteThreat ctx c b", + "before": "A justified departure must explicitly select a burden and establish its concrete threat; none supplies no justification.", + "after": "For the recorded burden b, require ConcreteThreat for this exact context, candidate and burden." + }, + { + "line": 353, + "source": "theorem unmetRequirementsBlockPriority :", + "before": "Tests that failure of any represented necessary requirement prevents activation of priority, rather than licensing an unsafe evolutionary choice.", + "after": "Check that each of the four displayed requirement failures makes PriorityConditions false. This only disables priority activation: EvolutionPriority and the later DomainSatisfied do not impose an unconditional Meets rejection." + }, + { + "line": 424, + "source": "def insertOrdered (n : Nat) : List Nat → List Nat", + "before": "Insertion receives one value and a sorted tail, supporting the comparison implementation's sorting behavior.", + "after": "Take a natural number and an arbitrary natural-number list; the type has no sorted-input premise. sortValues uses this helper for ordered insertion into its recursively sorted tail." + }, + { + "line": 710, + "source": "def omittedCallerCheck : EngineeringDesign :=", + "before": "Creates a counterexample by removing caller contract-runner steps from the actual path while retaining the design, boundary and callee-edit steps.", + "after": "Construct omittedCallerCheck as a design variant whose paths omit caller contract-runner work, for the later boundary-obligation counterexample." + }, + { + "line": 711, + "source": " { boundaryDesign with paths := fun direction =>", + "before": "Creates a counterexample by removing caller contract-runner steps from the actual path while retaining the design, boundary and callee-edit steps.", + "after": "Copy boundaryDesign’s other fields unchanged and replace paths with a function that transforms the path for each requested direction." + }, + { + "line": 712, + "source": " (boundaryDesign.paths direction).filter (fun step =>", + "before": "Creates a counterexample by removing caller contract-runner steps from the actual path while retaining the design, boundary and callee-edit steps.", + "after": "Filter the original boundaryDesign path for this same direction, retaining precisely the steps accepted by the following predicate." + }, + { + "line": 713, + "source": " !(step.component == coordinatedBoundary.caller && step.tool == .contractRunner)) }", + "before": "Creates a counterexample by removing caller contract-runner steps from the actual path while retaining the design, boundary and callee-edit steps.", + "after": "Exclude a step exactly when it is at coordinatedBoundary.caller and uses contractRunner; keep all other steps and finish the record update." + }, + { + "line": 1034, + "source": "abbrev DomainSatisfied (ctx : Context) (chosen : Candidate) : Prop :=", + "before": "Domain satisfaction combines the represented domain obligations for one context and selected design.", + "after": "Combine the represented domain duties for one context and selected design. This bundle has no unconditional Meets field; priority applicability is not an overall requirement-rejection test." + }, + { + "line": 1035, + "source": " ActivityScope ctx.activity ∧ EvolutionPriority ctx chosen ∧", + "before": "Requires valid engineering-subject scope and satisfaction of the adopted evolution priority.", + "after": "Require ActivityScope and the conditional EvolutionPriority. If PriorityConditions is false, that implication holds vacuously; this conjunct does not reject the choice for unmet requirements, while the remaining domain duties still apply." + } + ] + }, + { + "language": "zh", + "sha256": "24bf6725f169fad4ec28f335296c0e95c3212136e46ec3ad0974f61a32820c85", + "nonempty_source_lines": 902, + "entries": 902, + "unchanged_entries": 888, + "changed_lines": [ + 88, + 244, + 298, + 299, + 300, + 301, + 353, + 424, + 710, + 711, + 712, + 713, + 1034, + 1035 + ], + "missing": [], + "extra": [], + "empty": [], + "author_before_equals_independently_frozen_r1": true, + "changes": [ + { + "line": 88, + "source": " match d with", + "before": "功能增加和独立变更只使用这条两单位基础路径。", + "after": "按请求的 Change 选择对应编辑路径;后续各分支区分不同变更方向。" + }, + { + "line": 244, + "source": " objective := fun b => match b with", + "before": "理解界限对应接任者入门容量。", + "after": "按 Burden 分派并指定对应目标名称;后续分支给出各自不同的工程目标。" + }, + { + "line": 298, + "source": "abbrev JustifiedDeparture (ctx : Context) (c : Candidate) : Prop :=", + "before": "有根据的偏离必须明确选择负担并成立其具体威胁;none 不提供理由。", + "after": "以记录的负担及其必须成立的具体成本威胁,定义此情境与候选的有根据让步。" + }, + { + "line": 299, + "source": " match ctx.departure with", + "before": "有根据的偏离必须明确选择负担并成立其具体威胁;none 不提供理由。", + "after": "检查同一情境的 departure 选项,区分未指定说明与已指定负担。" + }, + { + "line": 300, + "source": " | none => False", + "before": "有根据的偏离必须明确选择负担并成立其具体威胁;none 不提供理由。", + "after": "未记录让步负担时,根据条件为 False;缺省记录不提供例外。" + }, + { + "line": 301, + "source": " | some b => ConcreteThreat ctx c b", + "before": "有根据的偏离必须明确选择负担并成立其具体威胁;none 不提供理由。", + "after": "对记录的负担 b,要求同一情境、候选及该负担满足 ConcreteThreat。" + }, + { + "line": 353, + "source": "theorem unmetRequirementsBlockPriority :", + "before": "检验任一已表示必要需求失败都会阻止优先条件激活,而不是允许不安全的演化选择。", + "after": "检查所示四种需求失败各自使 PriorityConditions 为假。这仅阻止优先条件激活;EvolutionPriority 及后面的 DomainSatisfied 并未施加无条件的 Meets 拒绝要求。" + }, + { + "line": 424, + "source": "def insertOrdered (n : Nat) : List Nat → List Nat", + "before": "插入函数接收一个值与有序列表,支持对比实现的排序行为。", + "after": "接收一个自然数及任意自然数列表;类型不含输入已排序的前提。sortValues 调用此辅助函数,在递归排序后的尾列表中按序插入。" + }, + { + "line": 710, + "source": "def omittedCallerCheck : EngineeringDesign :=", + "before": "通过从实际路径删除调用方合同执行器步骤构造反例,同时保留设计、边界与被调用方编辑步骤。", + "after": "构造设计变式 omittedCallerCheck,在路径中省去调用方合同执行器工作,用于后面的边界义务反例。" + }, + { + "line": 711, + "source": " { boundaryDesign with paths := fun direction =>", + "before": "通过从实际路径删除调用方合同执行器步骤构造反例,同时保留设计、边界与被调用方编辑步骤。", + "after": "保持 boundaryDesign 的其他字段不变,将 paths 替换为按请求方向变换对应路径的函数。" + }, + { + "line": 712, + "source": " (boundaryDesign.paths direction).filter (fun step =>", + "before": "通过从实际路径删除调用方合同执行器步骤构造反例,同时保留设计、边界与被调用方编辑步骤。", + "after": "筛选 boundaryDesign 在同一方向的原路径,只保留下述谓词接受的步骤。" + }, + { + "line": 713, + "source": " !(step.component == coordinatedBoundary.caller && step.tool == .contractRunner)) }", + "before": "通过从实际路径删除调用方合同执行器步骤构造反例,同时保留设计、边界与被调用方编辑步骤。", + "after": "仅在步骤位于 coordinatedBoundary.caller 且使用 contractRunner 时删除它;保留其余步骤,并完成记录更新。" + }, + { + "line": 1034, + "source": "abbrev DomainSatisfied (ctx : Context) (chosen : Candidate) : Prop :=", + "before": "领域满足把同一情境与所选设计的已表示领域义务组合。", + "after": "组合同一情境与所选设计的已表示领域义务。此组合没有无条件的 Meets 字段;优先适用性并不是整体需求拒绝检查。" + }, + { + "line": 1035, + "source": " ActivityScope ctx.activity ∧ EvolutionPriority ctx chosen ∧", + "before": "要求有效工程主体范围,并满足已采用演化优先。", + "after": "要求 ActivityScope 及条件式 EvolutionPriority。若 PriorityConditions 为假,该蕴含空真;此合取项不会因需求未满足而拒绝选择,其余领域义务仍须履行。" + } + ] + } + ], + "dispositions": [ + { + "finding": "RD1", + "result": "resolved_in_component", + "lines": [ + 353, + 1034, + 1035 + ], + "reason": "Both languages explicitly distinguish disabled priority activation from whole-choice rejection, disclose implication vacuity and absence of an unconditional Meets field, and retain remaining DomainSatisfied duties." + }, + { + "finding": "RD2", + "result": "resolved_in_component", + "lines": [ + 424 + ], + "reason": "Both languages state arbitrary List Nat input with no sortedness premise, while locating ordered-insertion use in sortValues recursive caller." + }, + { + "finding": "RD4 necessary", + "result": "resolved_in_component", + "lines": [ + 88, + 244 + ], + "reason": "Both dispatch explanations now range over the entire Change/Burden argument instead of describing only one branch." + }, + { + "finding": "RD4 optional locality", + "result": "improved_without_scope_expansion", + "lines": [ + 298, + 299, + 300, + 301, + 710, + 711, + 712, + 713 + ], + "reason": "The option definition/match/none/some and record/filter/exclusion lines now explain their distinct local roles without changing their predicate meaning." + }, + { + "finding": "RD3", + "result": "resolved_in_T35_component; rebuilt_public_views_pending", + "lines": [ + 889, + 890, + 891, + 892, + 894, + 895, + 951, + 953, + 954, + 955, + 956, + 957 + ], + "reason": "T35 now describes simultaneous changes to all five grounds in one old/new pair, separately describes OR semantics and non-sufficiency for substantive justification, and correctly identifies old/recordedOld tampering against independent history." + } + ], + "T35": { + "record": { + "id": "T35", + "title_en": "Revision and preserved historical evidence", + "title_zh": "修订与保留历史证据", + "conclusion_en": "Changed forecasts, maintainers, costs or objectives can justify changed judgments. A new record must retain the earlier prediction and its observed failure.", + "conclusion_zh": "预测、维护者、成本或目标变化可支持改判;新记录须保留旧预测及其观测失败。", + "premises_en": "RevisionAccount compares the revision with independently fixed observedHistory, including software identity, old prediction and actual observed result. revisionFor uses the current context and selected candidate. MaterialGroundsChanged is a disjunction of five recorded differences; it does not prove that each difference alone adequately justifies the new choice.", + "premises_zh": "RevisionAccount 将修订与独立固定的 observedHistory 比较,包括软件身份、旧预测及实际观测结果;revisionFor 使用当前语境和所选实现。 MaterialGroundsChanged 是五项记录差异的析取,不证明任一差异单独足以充分支持新选择。", + "proof_en": "The same old/new state pair changes forecast, maintenance, maintainers, migration cost and objective capacity together; the theorem lists all five differences. Tampering with both old and recordedOld cannot change the independent history. Separate retention cases use an unsupported alternative or a justified migration-cost departure.", + "proof_zh": "同一旧/新状态对同时改变预测、维护、维护者、迁移成本和目标容量;定理列出这五项差异。同步篡改 old 与 recordedOld 不能改变独立历史。另有保留案例分别使用无支持的替代方向或有根据的迁移成本让步。", + "limits_en": "The recorded history is fixed model evidence; the theorem does not authenticate arbitrary real-world logs or prove every criticism response adequate.", + "limits_zh": "记录的历史是固定模型证据;定理不鉴定任意现实日志,也不证明所有批评回应均充分。" + }, + "canonical_record_hash": "8242e8ff1069f5fc2072eb780fecbfb2ba66faa637f6608e818b270fbc720a52", + "canonicalization": "UTF-8 JSON, ensure_ascii=False, sort_keys=True, separators=(comma,colon), trailing newline", + "whole_narrative_file_hash_is_identity_only": "Only T35 content was reviewed; the whole-file hash does not imply approval of all other targets." + }, + "reuse": "The 888 unchanged entries/language are byte-equivalent values to the independently reviewed r1 JSON. Reuse its semantic findings and actual stdin probes for unchanged code; no new proof or broad test was needed for these wording-only changes. Prior missing Decidable probe attempt remains preserved in r1.", + "limits": [ + "This accepts only the 14 changed Domain entries in both languages and the exact T35 component identified here.", + "The four generated public manuscripts were not yet rebuilt for this check; no claim of final rendered/hash synchronization or link approval is made.", + "Prior r1 findings and their hashes remain preserved; this record is a new object, not an overwritten initial judgment.", + "No author files, Lean code, philosophical source or public manuscripts were edited by this recheck." + ] +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r2.md b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r2.md new file mode 100644 index 0000000..c34e449 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-domain-r2.md @@ -0,0 +1,16 @@ +# Independent Domain component recheck r2 + +**Accepted for the changed components; rebuilt public manuscripts remain pending.** This is a narrow independent recheck of prose I did not author, following my preserved r1 findings. It does not review or approve my own Root four-module corrections. + +Actual Domain source remains `ce5653a2950cc7443cefbfe8b9726bd4859228e831ddb7d42601e501ccbfd855`. The current explanation hashes are EN `d1773e14c9e68a81850a9a949f11ab3722dcb3a4c2bd8c663ecf1e8102d3c471` and ZH `24bf6725f169fad4ec28f335296c0e95c3212136e46ec3ad0974f61a32820c85`. + +I compared the complete current JSON objects against my independently frozen r1 copies, also verifying the author's before-r2 copies equal those originals. Exactly L88, L244, L298–301, L353, L424, L710–713 and L1034–1035 changed in each language: 14 entries changed, 888 unchanged. Both still cover exactly 902 nonblank source lines without missing, extra or empty entries. I read each changed English/Chinese sentence against its actual source line and dependent predicate meanings; these counts alone did not determine acceptance. + +- RD1 is resolved: the new text states the priority implication can be vacuous, DomainSatisfied lacks an unconditional Meets field, and the other domain duties still apply. It no longer claims overall rejection of the unsafe-profile choice. +- RD2 is resolved: the new text identifies arbitrary natural-number lists in insertOrdered's actual type, separating the sorted-tail use in sortValues from a nonexistent type premise. +- RD4 necessary dispatch corrections are resolved: L88 and L244 describe the complete Change/Burden dispatch. The optional option/filter locality improvements also accurately separate their actual line roles; no extra semantic condition was introduced. +- RD3 is resolved in the current T35 component: one old/new state pair changes all five material grounds together. The text separately explains the OR guard and that an individual difference is not sufficient proof of substantive justification. It now identifies tampering with old and recordedOld against fixed independent history. Both languages agree. + +The whole target-narratives-current.json hash is `12f534ce9489527799edebe937e5cca39dc3166afb6aec5783473334423b06d4`; it identifies the read file but does not approve its other targets. The exact reviewed T35 record and canonical record hash are in the JSON report. All read components and hashes are preserved under reader-independent-domain-r2-input/. + +The source and all proof inputs are unchanged, so I reuse the r1 actual probes (including the explicit unsafe DomainSatisfied proof, arbitrary-list insertion, work17/18/17, real boundary negatives and fixed-history checks) and exact-object R3 audit. No unnecessary fresh Lean build was run for wording changes. The generated four readers were not yet rebuilt, so final manuscript bytes, rendering and fresh public-link synchronization are explicitly outside this component acceptance. Initial records remain untouched. diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-independent-source-final.json b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-source-final.json new file mode 100644 index 0000000..e74a5dc --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-source-final.json @@ -0,0 +1,377 @@ +{ + "stage": "final narrow informed reader-source re-review of synchronized r2 views", + "verdict": "accepted within assigned independent reader scope; no outstanding R01-R05 or link/reuse blocker", + "manifest_observed_sha256": "1707734f6c51b9f7cd802ba8b84ed2a4d80fb6a7617d53eac081568689fee0c1", + "manifest_limit": "Observed current metadata identity only. Later metadata additions do not refresh or extend the fixed views/source/code/target objects below.", + "view_objects": [ + { + "view": "overview_en", + "path": "SoftwareEngineering/lean/philosophy/overview.md", + "sha256": "c8b01525a54a9beb78086a17652ea4ded4740dad956a0a9a4f9c0ae3ee7171a2" + }, + { + "view": "details_en", + "path": "SoftwareEngineering/lean/philosophy/details.md", + "sha256": "1b8d07cbbf3a0e7005821bc2261f89b1675d43a053802e8b779b1930e0d782af" + }, + { + "view": "overview_zh", + "path": "SoftwareEngineering/zh/lean/philosophy/overview.md", + "sha256": "31fd96fd034ab16e92d3ecc600237bf9f27fcddaff754b308e4ca14573b58a61" + }, + { + "view": "details_zh", + "path": "SoftwareEngineering/zh/lean/philosophy/details.md", + "sha256": "5eba3d944c7bcef294bfed822e6c4aa8205e3e238157da5fb95365bbb57169ff" + } + ], + "source_target_document_objects": [ + { + "path": "SoftwareEngineering/PHILOSOPHY.md", + "sha256": "6c6ae78a23f2726c5c370434e808d76c206647fe7793245e88cae52c076abe34" + }, + { + "path": "SoftwareEngineering/lean/philosophy/snapshots/PHILOSOPHY.md", + "sha256": "6c6ae78a23f2726c5c370434e808d76c206647fe7793245e88cae52c076abe34" + }, + { + "path": "SoftwareEngineering/lean/philosophy/targets.json", + "sha256": "c0939df35dad148a0543ba92a1ac7b7d3b2eb4946f92ac4be251ec51b6481d13" + }, + { + "path": "SoftwareEngineering/lean/philosophy/reviews/README.md", + "sha256": "f7bcec3e4e78c8cfa09f933ae42c0a5e4b59ee491bf521b66755a8f6c4ba8e4b" + } + ], + "code_objects": [ + { + "path": "SoftwareEngineering/lean/philosophy/leanified/CoreReader/Adopted.lean", + "sha256": "8de4d364bb3c64e29ab92e81d86cbe4c9e5af49ada3dad262d1378421fb588c2", + "manifest_match": true, + "same_reviewed_third_object": true + }, + { + "path": "SoftwareEngineering/lean/philosophy/leanified/CoreReader/Agency.lean", + "sha256": "2722c34645f4256f20ce31205738f2f5712ab5dd5cc6fcf9f1180d0be5aa0303", + "manifest_match": true, + "same_reviewed_third_object": true + }, + { + "path": "SoftwareEngineering/lean/philosophy/leanified/CoreReader/Choice.lean", + "sha256": "b28728df12ed7e73edb5569604cd2541c0ebd815ae3aaa0812e6557dece1d1ba", + "manifest_match": true, + "same_reviewed_third_object": true + }, + { + "path": "SoftwareEngineering/lean/philosophy/leanified/CoreReader/Engineering/Domain.lean", + "sha256": "ce5653a2950cc7443cefbfe8b9726bd4859228e831ddb7d42601e501ccbfd855", + "manifest_match": true, + "same_reviewed_third_object": true + }, + { + "path": "SoftwareEngineering/lean/philosophy/leanified/CoreReader/Engineering/Integration.lean", + "sha256": "a2b88062148b3f7ebea7da02d88cb29cb04d8f1b2e9e6b97bb2420ac2c006328", + "manifest_match": true, + "same_reviewed_third_object": true + }, + { + "path": "SoftwareEngineering/lean/philosophy/leanified/CoreReader/Engineering/Reflection.lean", + "sha256": "c290d8472884d00bedbf945f0fc1866524e758740f40d42088c4ff9678a93fa2", + "manifest_match": true, + "same_reviewed_third_object": true + }, + { + "path": "SoftwareEngineering/lean/philosophy/leanified/CoreReader/Engineering/SelfApplication.lean", + "sha256": "d69c0d369bd4fd8db4c21ce3b65abb5e9efd07ed5ab9a68d56b4db39bb9d2a21", + "manifest_match": true, + "same_reviewed_third_object": true + }, + { + "path": "SoftwareEngineering/lean/philosophy/leanified/CoreReader/Engineering/Values.lean", + "sha256": "ccd45bf23d2f47c41d1b2f9955d753e290687d951a0c55af41ab9a63b9a8d9cb", + "manifest_match": true, + "same_reviewed_third_object": true + }, + { + "path": "SoftwareEngineering/lean/philosophy/leanified/CoreReader/Evidence.lean", + "sha256": "d55f33e44902cef146841cbffb65710bd7c8a3bda79d01d084edc36f019fdc96", + "manifest_match": true, + "same_reviewed_third_object": true + }, + { + "path": "SoftwareEngineering/lean/philosophy/leanified/CoreReader/Integration.lean", + "sha256": "97e2939c0b6714b78a3ed78358e174619a5028ad5b0b5025c0d4422b4294921b", + "manifest_match": true, + "same_reviewed_third_object": true + }, + { + "path": "SoftwareEngineering/lean/philosophy/leanified/CoreReader/Logic.lean", + "sha256": "0ec342691766ebd83d251dcd0da3b0ae9840aed677a714bc1b01c45d89392bc0", + "manifest_match": true, + "same_reviewed_third_object": true + }, + { + "path": "SoftwareEngineering/lean/philosophy/leanified/CoreReader/Reflexivity.lean", + "sha256": "48e2c74e7cbae571db1b990b9f32dd0d701f6881a8b0111d907f8861287d76fa", + "manifest_match": true, + "same_reviewed_third_object": true + }, + { + "path": "SoftwareEngineering/lean/philosophy/leanified/CoreReader.lean", + "sha256": "c5574fae235419a7d6449b3ebb5d2da29d1e92a3b572c1b759438e3c470caaa9", + "manifest_match": true, + "same_reviewed_third_object": true + } + ], + "target_narratives_sha256": "12f534ce9489527799edebe937e5cca39dc3166afb6aec5783473334423b06d4", + "narrative_delta": [ + { + "target": "T01", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T02", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T03", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T04", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T05", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T06", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T07", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T08", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T09", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T10", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T11", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T12", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T13", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T14", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T15", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T16", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T17", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T18", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T19", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T20", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T21", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T22", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T23", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T24", + "fields_changed_from_r1": [ + "premises_en", + "premises_zh" + ], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T25", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T26", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T27", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T28", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T29", + "fields_changed_from_r1": [ + "premises_en", + "premises_zh", + "proof_en", + "proof_zh" + ], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T30", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T31", + "fields_changed_from_r1": [ + "proof_en", + "proof_zh" + ], + "fields_changed_from_accepted_r2": [ + "proof_en", + "proof_zh" + ] + }, + { + "target": "T32", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T33", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T34", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T35", + "fields_changed_from_r1": [ + "premises_en", + "premises_zh", + "proof_en", + "proof_zh" + ], + "fields_changed_from_accepted_r2": [ + "premises_en", + "premises_zh" + ] + }, + { + "target": "T36", + "fields_changed_from_r1": [ + "proof_en", + "proof_zh" + ], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T37", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T38", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T39", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + }, + { + "target": "T40", + "fields_changed_from_r1": [], + "fields_changed_from_accepted_r2": [] + } + ], + "correction_judgments": { + "T24": "Previously accepted complete conditions and participant quantification exactly present in both languages and both granularities.", + "T29": "Previously accepted separation of transformation conjunctions from EvolutionClaim is present, including the corrected proof description.", + "T35": "Previously accepted simultaneous-five-change and old/recordedOld wording is present. Added MaterialGroundsChanged OR/adequacy guard is an identified further change assigned to Domain reviewer; only scope/embedding checked here.", + "T36": "Previously accepted valid-history/criticism coverage and unchanged-choice result replaces actual-revisability overclaim in all four views.", + "Adopted692_1314": "Accepted status-only negative wording exactly rendered at both source-line anchors in both detail languages.", + "README": "The strong countermodel now supplies the explicit referent after the frozen-goals/new-code-object distinction." + }, + "assigned_elsewhere": { + "T31": "The only additional proof prose change replaces ambiguous account with boundaryObligationChecked; meaning review belongs to method reviewer.", + "Domain_line_explanations": "Authored by this reviewer; not independently approved here. Independent Domain review and its delta approval belong to the other reviewer.", + "Engineering_root_line_explanations": "Not re-opened by this narrow final check; retained separate independent reader review." + }, + "retrieval": "reader-independent-source-final-retrieval.json records actual per-view/per-target source labels, declaration-line destinations, overview-to-details links, full-code identity and exact49 source excerpts including two blank headings. These checks support navigation/identity; semantic acceptance rests on prior substantive r1/r2 reasoning plus accepted-correction embedding.", + "previous_records": [ + "reader-independent-source-review-r1.md", + "reader-independent-source-review-r1.json", + "reader-independent-source-review-r1-anchors.md", + "reader-independent-source-review-r2-components.md", + "reader-independent-source-review-r2-components.json" + ], + "exposure": "Source-first initial work preceded code; this final stage knows source, code and previous independent comparisons. It is not a new blind review. This reviewer later authored Domain line prose and excludes it from independent approval.", + "no_scope_expansion": "Source0.2.0/adoptedCore0.1.2, frozen40 targets, required cases and all reviewed Lean code are unchanged. Bounded source statuses and specified-duty/actual-fulfillment distinctions remain; no universal philosophical correctness claim is made." +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-independent-source-final.md b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-source-final.md new file mode 100644 index 0000000..a458175 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-source-final.md @@ -0,0 +1,15 @@ +# 最终读者源码窄复核 + +结论:在本审查者负责的独立读稿范围内通过。R01–R05 已接受修正均进入公开 r2 四稿,没有未关闭的对应语义或导航阻断。此结论不包含本人所作 Domain 行解释的独立批准。 + +实际 manifest 观察哈希为 `1707734f6c51b9f7cd802ba8b84ed2a4d80fb6a7617d53eac081568689fee0c1`。四稿、权威源文及快照、冻结目标、全部实际 Lean 源码与 reviews README 的精确哈希见同名 JSON。后续仅增添公开 QA 元数据时,不能将旧记录中的 manifest 哈希改写成新值;本判断直接绑定这些实际内容对象。 + +T24 的完整参与者与知识/工具条件,T29 的状态变换独立合取及契约处理,T35 同一对象对同时五项变化和 old/recordedOld,T36 的有效历史及批评方向覆盖/选择保持均精确进入两语言两粒度。Adopted 692 与 1314 的双语实际锚点均准确写为仅地位负例;其正例分支未误改。reviews README 用 The strong countermodel 明确指代,并保留“冻结目标不变,修复后的谓词和展开类型是新代码对象”的区别。 + +对全部40目标与已保存 r1、已接受 r2 组件逐字段作了实际差分。除已接受四目标修正外,新增变化仅 T31 的 boundaryObligationChecked 指代及 T35 的 MaterialGroundsChanged 析取/非充分合理性说明;这两处意义判断分别由已分配的 method reviewer 和 Domain reviewer 负责,本轮只核范围与嵌入。其余目标说明无未授权变化,Adopted 组件字节与已接受 r2 相同。全部 Lean 文件与先前第三版审查对象逐字节相同,源文与冻结目录哈希保持不变,因此复用此前源码判断而不重新展开全文评审。 + +实际逐目标查找了四稿40个目标锚点、每项来源链接与详情入口,以及详情所列声明的真实源码行目的地。所有内部链接存在且无重复锚点;两份详情的13个完整 Lean 块与对应已审源文件相同。47段实质源文与两个空结构条目均按实际摘录内容精确保留。完整逐目标目的地与检查结果见 reader-independent-source-final-retrieval.json。首次辅助探针错误地删除空结构摘录的末尾换行,产生两项假失配;保留原诊断后按字面内容核验通过,未改稿件。 + +这些定位与字节检查只支持导航、对象身份和已审修正文稿的完整转入,不凭数量或匹配证明语义。语义判断继续依赖已保存的 r1 实质问题与 r2 对应源码复核;本轮保留规范定义不等于履责、完整继承义务不等于 assessed 标记、T38同对象联合满足与T39无逃逸强反例的实际范围,以及有限证据不证明普遍哲学正确性的限制。 + +本阶段是有明确源文与代码暴露的知情复核,不是新盲译。Domain 行稿为本人作者工作,其独立判断由另一审查者完成;本记录也不重新批准分工给他人的 Root 全部行解释。 diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-independent-source-review-r1-anchors.json b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-source-review-r1-anchors.json new file mode 100644 index 0000000..f7e2aff --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-source-review-r1-anchors.json @@ -0,0 +1,34 @@ +{ + "manifest_sha256": "cd300f086c45afc1ff28a63ecce92c75ec06d94164eb0cd14d898a0f7eedcf6e", + "snapshot": "private software-engineering iteration records/before-reader-r1-revision/SoftwareEngineering", + "narrative_identity": [ + { + "view": "overview_en", + "all_40_narratives_exact": true, + "missing": [] + }, + { + "view": "details_en", + "all_40_narratives_exact": true, + "missing": [] + }, + { + "view": "overview_zh", + "all_40_narratives_exact": true, + "missing": [] + }, + { + "view": "details_zh", + "all_40_narratives_exact": true, + "missing": [] + } + ], + "anchor_probe": "reader-r1-anchor-probe.json", + "judgment": "All four view hashes match the frozen r1 manifest. All queried target/source/declaration/nonblank-line anchors resolve; no duplicate or missing internal anchor found. R01-R05 are still substantive defects in the exact generated r1 prose, despite successful structural checks. This supplements, not overwrites, reader-independent-source-review-r1.", + "own_authorship_limit": "Domain line prose was authored by this reviewer: only navigation/location was exercised on that block, not independent semantic approval.", + "limits": [ + "Not a new complete independent review of Engineering root line explanations assigned elsewhere.", + "Final corrected-view hashes and anchors require narrow delta check after regeneration.", + "No claim here that every natural-language sentence is validated by code/narrative identity checks." + ] +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-independent-source-review-r1-anchors.md b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-source-review-r1-anchors.md new file mode 100644 index 0000000..2465d31 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-source-review-r1-anchors.md @@ -0,0 +1,9 @@ +# 读者 r1 四稿实际检索补记 + +在 r1 初判保存后,对 `before-reader-r1-revision/SoftwareEngineering` 的完整固定四稿进行了实际锚点检索。该对象 manifest SHA-256 为 `cd300f086c45afc1ff28a63ecce92c75ec06d94164eb0cd14d898a0f7eedcf6e`;四稿实际字节哈希均匹配。每一稿中全部 40 项 conclusion/premises/proof/limits 与本轮已审双语原稿精确相同,因此原 R01–R05 确实进入了 r1 正式稿,结构检查通过不消除这些语义问题。 + +实测定位 T09、T24、T25、T28、T33–T36、T38、T39 的目标锚点及其 source/declaration 出链;各稿均无丢失的内部链接目标或重复锚点。英文、中文详情的 T25 均在 Markdown 1135 行,T39 均在 1740 行;沿声明链接可取得完整条件类型,继续定位 Integration 的 374–396 行可恢复完整 Inherited 字段,586–606 行可恢复强反例完整前提与具体证明。查找解释结果沿用 r1 JSON 的语义回答,不把找到标记当作回答。 + +另外实际读取中文契约保持说明确认全称范围前提与有限样例分开,读取强反例说明及 wholeClaimGrounds 字段定位,确认并未将一般 assessed 状态当作继承履责。Adopted 692 的实际中文锚点仍显示将负例误称正例,须随 R05 修正。 + +Domain 是本人所作逐行稿,本次仅在该块检索位置,未给予独立语义批准。新 Engineering 各模块全部行解释由其他审查分工处理,本补记不扩大为其全稿独立审查。正式修正后仍需针对新四稿哈希作增量检索。机器结果及全部定位记录分别保存在 reader-r1-anchor-probe.json 和 reader-independent-source-review-r1-anchors.json。 diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-independent-source-review-r1.json b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-source-review-r1.json new file mode 100644 index 0000000..9748139 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-source-review-r1.json @@ -0,0 +1,439 @@ +{ + "stage": "informed independent reader QA; initial judgment before author comparison, except disclosed T24 observation", + "overall": "reader corrections required; no reopened formal target or new Lean/source-fidelity blocker", + "reviewer_exposure": [ + "Authored original source-first review, subsequent informed code reviews and Domain line explanations.", + "Domain line explanations excluded from independent review.", + "Previously read blind-source comparison only after own saved initial code judgments.", + "Root relayed only the T24 author observation before this initial reader judgment." + ], + "objects": [ + { + "path": "private software-engineering iteration records/target-narratives-current.json", + "sha256": "df5050441153971b0da444d0c9c5518555656b88dc9042e262f31e4714ef6068" + }, + { + "path": "private software-engineering iteration records/adopted-line-explanations-en.json", + "sha256": "1a48dc20be4248b2e12245e3168ce6c11953e4eac61c8dec5c7c3ba759f5efd7" + }, + { + "path": "private software-engineering iteration records/adopted-line-explanations-zh.json", + "sha256": "e318c547184bd22f8f88f4e303bf01b8c5e0a4ea77ff91cbfa486707e1c4aade" + }, + { + "path": "private software-engineering iteration records/helper-line-explanations-en.json", + "sha256": "b7ad7f5670fb33f66b4b587e173ff85e4f3ba5c88fbeb6cb634abdba65e32377" + }, + { + "path": "private software-engineering iteration records/helper-line-explanations-zh.json", + "sha256": "315c55014f188a348b41d369b1662c3c2f4626f531cc32f6a9577746b7c536d9" + }, + { + "path": "private software-engineering iteration records/helper-line-explanation-reuse.json", + "sha256": "ffbf302affe01a6b87efab77a78f3534376c76a00fb9a93733a975bc1e623c0c" + }, + { + "path": "private software-engineering iteration records/third-code-snapshot/CoreReader/Adopted.lean", + "sha256": "8de4d364bb3c64e29ab92e81d86cbe4c9e5af49ada3dad262d1378421fb588c2" + }, + { + "path": "private software-engineering iteration records/third-code-snapshot/CoreReader/Agency.lean", + "sha256": "2722c34645f4256f20ce31205738f2f5712ab5dd5cc6fcf9f1180d0be5aa0303" + }, + { + "path": "private software-engineering iteration records/third-code-snapshot/CoreReader/Choice.lean", + "sha256": "b28728df12ed7e73edb5569604cd2541c0ebd815ae3aaa0812e6557dece1d1ba" + }, + { + "path": "private software-engineering iteration records/third-code-snapshot/CoreReader/Engineering/Domain.lean", + "sha256": "ce5653a2950cc7443cefbfe8b9726bd4859228e831ddb7d42601e501ccbfd855" + }, + { + "path": "private software-engineering iteration records/third-code-snapshot/CoreReader/Engineering/Integration.lean", + "sha256": "a2b88062148b3f7ebea7da02d88cb29cb04d8f1b2e9e6b97bb2420ac2c006328" + }, + { + "path": "private software-engineering iteration records/third-code-snapshot/CoreReader/Engineering/Reflection.lean", + "sha256": "c290d8472884d00bedbf945f0fc1866524e758740f40d42088c4ff9678a93fa2" + }, + { + "path": "private software-engineering iteration records/third-code-snapshot/CoreReader/Engineering/SelfApplication.lean", + "sha256": "d69c0d369bd4fd8db4c21ce3b65abb5e9efd07ed5ab9a68d56b4db39bb9d2a21" + }, + { + "path": "private software-engineering iteration records/third-code-snapshot/CoreReader/Engineering/Values.lean", + "sha256": "ccd45bf23d2f47c41d1b2f9955d753e290687d951a0c55af41ab9a63b9a8d9cb" + }, + { + "path": "private software-engineering iteration records/third-code-snapshot/CoreReader/Evidence.lean", + "sha256": "d55f33e44902cef146841cbffb65710bd7c8a3bda79d01d084edc36f019fdc96" + }, + { + "path": "private software-engineering iteration records/third-code-snapshot/CoreReader/Integration.lean", + "sha256": "97e2939c0b6714b78a3ed78358e174619a5028ad5b0b5025c0d4422b4294921b" + }, + { + "path": "private software-engineering iteration records/third-code-snapshot/CoreReader/Logic.lean", + "sha256": "0ec342691766ebd83d251dcd0da3b0ae9840aed677a714bc1b01c45d89392bc0" + }, + { + "path": "private software-engineering iteration records/third-code-snapshot/CoreReader/Reflexivity.lean", + "sha256": "48e2c74e7cbae571db1b990b9f32dd0d701f6881a8b0111d907f8861287d76fa" + }, + { + "path": "private software-engineering iteration records/third-code-snapshot/CoreReader.lean", + "sha256": "c5574fae235419a7d6449b3ebb5d2da29d1e92a3b572c1b759438e3c470caaa9" + }, + { + "path": "SoftwareEngineering/lean/README.md", + "sha256": "0385ac23e960787836042763d60277158e69b9cc5dedc6c1862221eedfc15764" + }, + { + "path": "SoftwareEngineering/lean/VALIDATION.md", + "sha256": "766981b9cf1dfe096974bd8909ae2dc04745af984208cde49f29d3eaafbd7b2a" + }, + { + "path": "SoftwareEngineering/lean/philosophy/SOURCE-CONTEXT.md", + "sha256": "fac570778f2dfb62470db370d63f0c039be9a9cce2a4db74ef47a059e5d6e067" + }, + { + "path": "SoftwareEngineering/lean/philosophy/reviews/README.md", + "sha256": "050f39b438bf17341a6273dc671bbf1e0a67aa2a833f8453d005ad1885637299" + }, + { + "path": "SoftwareEngineering/lean/philosophy/evidence/README.md", + "sha256": "2701fa13bf8b145c396f798856ed756fb2b36fa9bde958307cee915905e0d9c8" + }, + { + "path": "SoftwareEngineering/README.md", + "sha256": "43a53c4a84fa4e595e5a3308448c8f44570e5fbe7ad7b342af126b395d4e19a4" + }, + { + "path": "SoftwareEngineering/zh/README.md", + "sha256": "91834347037e8180d5fd978d0ac341c27ff36f45d3c82712ba66738b2aaa2703" + }, + { + "path": "SoftwareEngineering/AGENTS.md", + "sha256": "214a0287920ddcfc5ece24fbdc5f3ebf62a7d1266c8b3d8bce86489b9a925ac2" + }, + { + "path": "SoftwareEngineering/PHILOSOPHY.md", + "sha256": "6c6ae78a23f2726c5c370434e808d76c206647fe7793245e88cae52c076abe34" + } + ], + "findings": [ + { + "id": "R01", + "status": "required_reader_correction", + "targets": [ + "T24" + ], + "location": "target-narratives-current.json / T24 / premises_en,premises_zh", + "code": "CoreReader/Engineering/Domain.lean:49-54,107-113,307-313", + "finding": "Nonempty scope and a continuing-maintainer path conceal concrete conjuncts and the universal participant quantifier.", + "required": "State nonempty participants, software identity and tools, knowledge for each participant, and that every listed participant has every knowledge/tool prerequisite of the nonempty evolvable design-revision path. Retain continuing releases/maintenance, both Meets clauses, credible design revision, lower work and greater complexity.", + "exposure": "Root relayed author T24 observation before this report; independently checked actual definitions. This is not claimed as independently discovered." + }, + { + "id": "R02", + "status": "required_reader_correction", + "targets": [ + "T29" + ], + "location": "target-narratives-current.json / T29 / premises_en,premises_zh", + "code": "CoreReader/Engineering/Domain.lean:556-579", + "finding": "The prose attributes actual software transformation binding to EvolutionClaim itself. The predicate contains CanChange, contract account, contractRunner membership and preserve/revise sample behavior; transform occurs separately in the case conjunction.", + "required": "Attribute real SoftwareState transformations to evolutionKindsCases, and describe EvolutionClaim as binding direction/maintainer capability, the corresponding contract account, verification path and treatment of the stated observation. Preserve the limited observation scope." + }, + { + "id": "R03", + "status": "required_reader_correction", + "targets": [ + "T35" + ], + "location": "target-narratives-current.json / T35 / proof_en,proof_zh", + "code": "CoreReader/Engineering/Domain.lean:894-895,951-960,967-969", + "finding": "The claim that cases change one material ground at a time is false: the same old/new pair changes all five material fields. The tampering example alters old and recordedOld, not current and reported old.", + "required": "Say one before/after pair exhibits changes in forecast, maintenance, maintainers, migration cost and objective capacity; describe tampering with the stored old state and its reported copy. Do not imply one-factor isolation." + }, + { + "id": "R04", + "status": "required_reader_correction", + "targets": [ + "T36" + ], + "location": "target-narratives-current.json / T36 / proof_en,proof_zh", + "code": "CoreReader/Engineering/Domain.lean:908-916,943-945,993-1005", + "finding": "revisionLimits does not prove actual revisability of the retained design. It proves RevisionAccount stableRecord, unchanged selected candidate and RetentionJustified for the named unsupported alternative.", + "required": "Describe the valid fixed-history account, retained criticism-direction coverage and unchanged choice with the explicitly unsupported alternative. If discussing revisability from the complete reflection model, label it as a separately proved aggregate fact and cite that object, rather than treating it as a T36 case conclusion." + }, + { + "id": "R05", + "status": "required_reader_correction", + "targets": [ + "T19", + "T21" + ], + "location": "adopted-line-explanations-en.json and adopted-line-explanations-zh.json / CoreReader/Adopted.lean / 692,1314", + "code": "CoreReader/Adopted.lean:690-698,1313-1318", + "finding": "Both annotations say positive case, but these lines belong to the negated status-only choiceSpecification conjunct. The positive output-reason branch is at 695 and 1317.", + "required": "Use negative status-only branch, or neutral same implementation wording, in both languages at both occurrences." + } + ], + "targets": [ + { + "id": "T01", + "status": "accepted_bounded_narrative", + "reason": "Authority and the adopted Core 0.1.2 baseline are distinct from checker success." + }, + { + "id": "T02", + "status": "accepted_bounded_narrative", + "reason": "Generative is an adopted valuation/revisability predicate; no actual progress is inferred." + }, + { + "id": "T03", + "status": "accepted_bounded_narrative", + "reason": "Finite expansion, resource and report counterexamples retain their concrete scope." + }, + { + "id": "T04", + "status": "accepted_bounded_narrative", + "reason": "Whole-theory consistency uses the actual union and an inhabited current question/world context." + }, + { + "id": "T05", + "status": "accepted_bounded_narrative", + "reason": "Temporal/context differences and truthful-change reporting are not simultaneous consistency or universal detection." + }, + { + "id": "T06", + "status": "accepted_bounded_narrative", + "reason": "The satisfiable, false-at-actual, incomplete and compatible-but-not-entailed examples remain distinct." + }, + { + "id": "T07", + "status": "accepted_bounded_narrative", + "reason": "Self applicability and same-rule/object bindings are retained; record existence is not universal correctness." + }, + { + "id": "T08", + "status": "accepted_bounded_narrative", + "reason": "Complete Charter witness and the specified unsupported original-task package are distinguished; no universal absence of Grounds is claimed." + }, + { + "id": "T09", + "status": "accepted_bounded_narrative", + "reason": "Original AssessmentTask, NatureAppropriate, same claim and independent grounds inputs retained; no Core 0.1.3 coverage import." + }, + { + "id": "T10", + "status": "accepted_bounded_narrative", + "reason": "Compatible worlds, scope and uncertainty remain separate; observation/duplication do not automatically justify values." + }, + { + "id": "T11", + "status": "accepted_bounded_narrative", + "reason": "Inferential assumptions and claim retained; an accurate negative assessment is not successful positive support." + }, + { + "id": "T12", + "status": "accepted_bounded_narrative", + "reason": "Adopted options, joint reasons, consequences and scope form a sufficient local value adapter, not ultimate value proof." + }, + { + "id": "T13", + "status": "accepted_bounded_narrative", + "reason": "Articulation, support and qualitative comparison are not reduced to nonempty names or a universal score." + }, + { + "id": "T14", + "status": "accepted_bounded_narrative", + "reason": "Comparison scope and method roles retain actual interpretation, conditions and limits." + }, + { + "id": "T15", + "status": "accepted_bounded_narrative", + "reason": "Agreement only in the declared local scope does not erase the explicit outside difference." + }, + { + "id": "T16", + "status": "accepted_bounded_narrative", + "reason": "Same explained process; independent multiplier/input response tested at 3,1; full quantified good response and actual contract proof retained." + }, + { + "id": "T17", + "status": "accepted_bounded_narrative", + "reason": "External output certificate targets the same process and does not produce an internal explanation." + }, + { + "id": "T18", + "status": "accepted_bounded_narrative", + "reason": "Feasibility and actual valued method reason are both required; status may coexist with good reasons." + }, + { + "id": "T19", + "status": "accepted_bounded_narrative", + "reason": "The accurate-assessment independence example is explicitly weaker than full inherited-duty countermodel T39." + }, + { + "id": "T20", + "status": "accepted_bounded_narrative", + "reason": "Full Inherited premise, actual own normative contents, whole-theory support/consistency and current self-rule interpretation retained." + }, + { + "id": "T21", + "status": "accepted_bounded_narrative", + "reason": "Current philosophy implementation and its actual proposed decisions are explicit; no universal test-only assessment rule." + }, + { + "id": "T22", + "status": "accepted_bounded_narrative", + "reason": "Activity scope does not by itself give all participants all changes; finite schedules are model data." + }, + { + "id": "T23", + "status": "accepted_bounded_narrative", + "reason": "Private original-maintainer path is distinguished from all-participant continuing capability." + }, + { + "id": "T24", + "status": "correction_required", + "reason": "R01 requires complete participant/knowledge/tool quantification in the summary." + }, + { + "id": "T25", + "status": "accepted_bounded_narrative", + "reason": "EvolutionPriority, PriorityConditions and noDeparture are actual premises, used by branch elimination and equality substitution." + }, + { + "id": "T26", + "status": "accepted_bounded_narrative", + "reason": "Credibility checks actual disclosed grounds contents but not real-world predictive calibration." + }, + { + "id": "T27", + "status": "accepted_bounded_narrative", + "reason": "Conceivable, unsupported, changing and finite registered directions remain separate." + }, + { + "id": "T28", + "status": "accepted_bounded_narrative", + "reason": "ConcreteThreat compares added candidate burden with simpler cost and named objective capacity; seven separate threats are finite adapters." + }, + { + "id": "T29", + "status": "correction_required", + "reason": "R02 separates actual transformation cases from the fields of EvolutionClaim." + }, + { + "id": "T30", + "status": "accepted_bounded_narrative", + "reason": "The independent/coordinated and addition/design-revision comparisons do not imply every dimension improves." + }, + { + "id": "T31", + "status": "accepted_bounded_narrative", + "reason": "Actual boundary edge, callee edit, caller verification and finite observed equality retained; no universal checklist." + }, + { + "id": "T32", + "status": "accepted_bounded_narrative", + "reason": "Both real changed paths are retained: 17 to 18 and relocated verification 17 to 17; boundary count is not capability." + }, + { + "id": "T33", + "status": "accepted_bounded_narrative", + "reason": "Order/retry contract and independently affected parties retained; no notification duty added." + }, + { + "id": "T34", + "status": "accepted_bounded_narrative", + "reason": "Universal in-scope equality is an explicit premise; the finite suite cannot supply it automatically." + }, + { + "id": "T35", + "status": "correction_required", + "reason": "R03 corrects actual variation design and old-field tampering identity." + }, + { + "id": "T36", + "status": "correction_required", + "reason": "R04 restricts retention prose to the theorem actually proved." + }, + { + "id": "T37", + "status": "accepted_bounded_narrative", + "reason": "Full Inherited/Domain premises and same-priority actual Grounds/member/consistency retained; local sample-aware critique disclosed." + }, + { + "id": "T38", + "status": "accepted_bounded_narrative", + "reason": "One shared context satisfies complete represented inherited/domain bundles with true applicability and no cost threat." + }, + { + "id": "T39", + "status": "accepted_bounded_narrative", + "reason": "Same continuing context, full inherited fulfillment, necessary requirements, credible design revision, actual supported simple selection and no escape are retained." + }, + { + "id": "T40", + "status": "accepted_bounded_narrative", + "reason": "Declared nonformal boundaries and limited source statuses are not recast as complete proof." + } + ], + "adopted_reader": { + "nonblank_annotations_each_language": 1225, + "scope": "All English/Chinese annotations read against the fixed adopted code and prior exact-object source assessment, including provenance comments and T16 increment.", + "status": "R05 correction required; no other substantive reader mismatch identified" + }, + "helper_reader": { + "identity": "All 2178 nonblank code and caption pairs per language exactly match corresponding Core reader lines after removing organon-map comments; see reader-helper-caption-reuse-probe-r1.json.", + "new_semantic_qa": { + "Logic": "all declarations and proof steps", + "Choice": "all declarations and proof steps", + "Agency": "all declarations and proof steps", + "Reflexivity": "all declarations and proof steps", + "Integration": "all declarations and proof steps", + "Evidence": "Grounds/ValueProcedure/Facet interfaces, canonical proofs, achievement/support/scope/duty proofs at lines 1-231; actual process/capability/identity/external-certificate proofs at 606-725" + }, + "limits": "Secondary Evidence examples at 233-605 receive exact code/caption reuse identity verification rather than a fresh exhaustive line-content audit in this bounded pass. No philosophical approval is inferred from matching bytes. Engineering.Reflection is a separate new module, not one of these six helper JSON keys; its actual current semantics are checked through T20/T37 source/code narratives and prior fixed-object review.", + "status": "no substantive mismatch in freshly inspected key content; reuse disclosed" + }, + "retrieval_probes": [ + { + "query": "default priority full applicability and theorem premises", + "located": "Domain:49-54,107-113,298-343; T24/T25/T28", + "answer": "Continuing releases/maintenance; nonempty participant/software/tool scope with per-participant knowledge; both necessary requirement sets; credible design revision; every participant has path knowledge/tools; strict work advantage and current complexity cost. Priority is a separate adopted implication. With applicability and no departure, resolve the disjunction then substitute the selected candidate." + }, + { + "query": "justified departure", + "located": "Domain:298-305,328-330; T28", + "answer": "A named burden must satisfy actual ConcreteThreat, including added cost over the simpler candidate and threat to the concrete objective/capacity. Mere recorded excuse is not enough; seven burden cases are distinct finite examples." + }, + { + "query": "strong countermodel", + "located": "Integration:374-407,586-606; T39", + "answer": "Witness is sharedContext/presentSimple with every Inherited field, active PriorityConditions, continuing and not bounded lifecycle, no HasThreat or JustifiedDeparture, both Meets, credible designRevision, successor/agent evolvable paths, strict work and complexity tradeoff, actual value support and adoption; hence false EvolutionPriority. Accurate assessment alone would not suffice." + }, + { + "query": "contract and history identity", + "located": "Domain:539-563,908-928,967-1005; T29/T33-T36", + "answer": "Actual original/new contract determines affected parties and retry duties; sample treatment is explicit. Independent observedHistory fixes software, old state, prediction3 and observation5. Revising report copies cannot rewrite those objects. R02/R03/R04 correct summary overstatements." + }, + { + "query": "specification versus fulfillment", + "located": "Adopted Grounds012/specification definitions; Integration:374-407; T02/T07/T09/T20/T38; helper Evidence:25-26,51-59,71-110; Reflexivity:119-160", + "answer": "A definition states a predicate/duty; checking it compiles does not fulfill it. Full Inherited and DomainSatisfied are constructed proof bundles. Articulated and Performed are weaker than matched support/ValidApplication; negative assessment can be accurate without positive support." + } + ], + "delivery_docs": { + "status": "bounded wording/content checks passed with one precision recommendation and pending live-link execution checks", + "recommendation": "reviews/README.md says strong joint-witness and non-entailment statements remain unchanged. Prefer frozen proof goals/requirements remain unchanged, because predicates and elaborated types were substantively repaired; avoid suggesting identical historical declaration objects.", + "pending": [ + "Four generated manuscripts and target/source/code anchors not yet final at this review stage.", + "Selected kernel/manuscript-check and portable-copy execution links require actual final object checks; current drafts do not count as their execution evidence." + ], + "scope": "Five new delivery documents read fully; appended Lean entry paragraphs in three parent documents reviewed. No added philosophical obligation or upgrade from Core 0.1.2 found." + } +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-independent-source-review-r1.md b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-source-review-r1.md new file mode 100644 index 0000000..50246c8 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-source-review-r1.md @@ -0,0 +1,37 @@ +# 独立读者源码对照初判 r1 + +本轮结论:需要修正五项读稿问题;未发现需要修改冻结目标或 Lean 的新阻断。四十项双语目标说明均已读;T24、T29、T35、T36 的说明需要修正。Adopted 全部双语行解释需要修正重复出现的一处正负分支误述。正式四稿的锚点与最终执行证据尚待生成后核验。 + +## 身份与暴露 + +这是基于先前 source-first 初读及实际第三版代码审查的知情独立读者 QA,不是盲回译。我编写过 Domain 双语逐行稿,本轮不自审该稿。初稿落盘前 Root 已转告作者关于 T24 的条件量词观察;该项由实际源码独立核对,但不宣称是我的独立发现。其余作者读者 QA 结论未作为本初判输入。所有实际对象 SHA-256、逐目标判断与查找结果见同名 JSON;输入原稿保存在 reader-r1-inputs/,不覆盖作者稿。 + +## 必要修正 + +1. **R01 — T24 前提遗漏实际量词。** Domain 49–54、107–113、307–313 要求参与者、软件身份与工具非空,每位参与者有知识;持续能力是每位列出参与者拥有同一非空演化设计修订路径所需的全部知识与工具。仅写 nonempty scope / continuing-maintainer path 无法恢复这些完整条件。应展开这两项,保留持续发布维护、双方 Meets、可信设计修订、工作量优势与复杂度代价。T25 则已正确把规则、全部适用条件及无让步列为定理前提。 + +2. **R02 — T29 错把状态变换归入 EvolutionClaim 谓词。** Domain 556–563 实际连接 CanChange、对应契约账户、contractRunner 路径和指定样本的 preserve/revise 处理;SoftwareState 的 transform 在 570–575 的独立案例合取中。请分别表述,不能说该谓词自身绑定实际软件变换。保留有限观察条件。 + +3. **R03 — T35 夸大变式隔离且指错字段。** Domain 894–895 的同一前后状态同时改变 forecast、maintenance、maintainers、migrationCost、objectiveCapacity;951–957 分别列出这个同一对象对的差异,不是每次只改变一个因素。967–969 同步篡改的是 old 与 recordedOld,不是 current 与报告旧字段。双语都应按这些实际对象修正。 + +4. **R04 — T36 把稳定记录说成实际可修订性证明。** Domain 993–1005 给出有效 RevisionAccount、稳定记录选择等于旧选择和具体 unsupported alternative 的 RetentionJustified;没有证明该保留设计的实际 revisability。可改为历史账户与批评方向覆盖保持有效、选择未变、指定替代方向无获支持贡献。若要提完整集成的反思可修订性,应明确另引该结果,不能称为本案例所证。 + +5. **R05 — Adopted 行 692、1314 的双语解释把负例叫正例。** 两行都位于 `¬ choiceSpecification ... [.status .standing]` 分支;真正输出理由正例在 695、1317。请将 positive case/正例改为 status-only negative branch/仅地位负例,或使用不标正负的同实现措辞。 + +## 实际内容检查 + +Adopted 的 1225 条非空行解释在英文、中文中均已核对,包含 T16 的新机制应用:两对象共享 explainedProcess,固定翻倍回答在 multiplier=3/input=1 失败,正确回答满足任意 multiplier/input,身份范围不等于假设契约为真;实际契约证明和 same-task Grounds 才履行支持。别名、字段、全称量词、单元素模型身份定理及证明投影保持了这些区别。R05 之外未见新的实质误译。 + +六个旧 helper 的代码及双语解释复用身份已实际核验。去掉原 organon-map 注释后,每个非空源码行逐一相等,对应原 Core details 的每条解释也逐一相等,两语言各 2178 对,没有失配。记录在 reader-helper-reuse-probe-r1.json 和 reader-helper-caption-reuse-probe-r1.json。这个比对证明复用身份,不自动转移 Core 的哲学来源批准。 + +新做的 helper 内容 QA 包括 Logic、Choice、Agency、Reflexivity、Integration 的全部声明及证明步骤,Evidence 的 Grounds/ValueProcedure/Facet、canonical、achievement/support/scope/duty 部分 1–231,以及过程、能力、身份和外部证书部分 606–725。Evidence 233–605 的次级例子仅做了完整代码和解释身份复用核验,没有在本次有界检查中重新逐行作语义审查。所检查关键内容准确区分:理论模型与实际世界真;许可与赋值;范围覆盖与完整有效应用;非空表述与匹配支持;预设前提与实际构造;负面评估与未履行评估。旧 Integration 的有限四世界承诺例与新 Engineering 集成有不同对象范围,未将旧 Grounds 的所有适用面覆盖引入 Core 0.1.2。 + +## 读者检索实测 + +已用目标说明与固定源码实际找出并解释:默认优先的全部条件和三条定理前提;让步的具体成本威胁;T39 的完整 Inherited、持续且非临时生命周期、双方必要要求、可信设计修订、继任者/代理路径、真实演化优势、无成本逃逸、已支持且实际采纳的简单性选择;契约变化的独立受影响方及固定历史;规范定义与满足规范的证明区别。精确文件行号和回答见 JSON。T38/T39 没有被 adopter/assessed 标记替代。正式四稿的可点击锚点检索仍是后续检查,不在此冒报通过。 + +## 交付说明 + +新建五份交付说明全文及 README、中文 README、AGENTS 的新增 Lean 段落已检查。它们保留 SoftwareEngineering 0.2.0/Core 0.1.2、英文权威、独立 Core 运行时、有界表示、源文与代码审查、定义与履行、检查器不判断语义、历史失败不改写及精确复用限制;未发现增加子哲学义务。 + +有一处建议收紧:reviews/README.md 的 “strong joint-witness and non-entailment statements remain unchanged” 最好写成冻结证明目标/要求保持不变,避免读者以为修复前后实际谓词或展开类型字节相同。最终 kernel/manuscript-check、四稿和独立复制复跑尚未以最终对象交付;此时的路径文字与预期交付描述不算实际执行证据。本轮不批准这些尚未执行的阶段。 diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-independent-source-review-r2-components.json b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-source-review-r2-components.json new file mode 100644 index 0000000..a04590b --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-source-review-r2-components.json @@ -0,0 +1,73 @@ +{ + "stage": "narrow informed independent component re-review of reader R01-R05; not final manuscript approval", + "objects": [ + { + "path": "private software-engineering iteration records/target-narratives-current.json", + "sha256": "2a6334809fc3f23ca874f839f612906e32774c3821582c03c5bf97f521e1e584", + "matches_author_response": true + }, + { + "path": "private software-engineering iteration records/adopted-line-explanations-en.json", + "sha256": "aa4f297fb4250cf8cf1883092f74152fb6567a5b9ec4ee74dae7a8f28b1fb9b9", + "matches_author_response": true + }, + { + "path": "private software-engineering iteration records/adopted-line-explanations-zh.json", + "sha256": "69ae42b723e8fd901701c32226d7daa6adb879923ce29e8d4b58ebf58d724714", + "matches_author_response": true + }, + { + "path": "SoftwareEngineering/lean/philosophy/reviews/README.md", + "sha256": "ec3a7d6cf775d311aff2f43af085400e011727c0735ae7ef2e69b8093fcee825" + } + ], + "code_identity": [ + { + "path": "SoftwareEngineering/lean/philosophy/leanified/CoreReader/Adopted.lean", + "sha256": "8de4d364bb3c64e29ab92e81d86cbe4c9e5af49ada3dad262d1378421fb588c2", + "matches_third_code_snapshot": true + }, + { + "path": "SoftwareEngineering/lean/philosophy/leanified/CoreReader/Engineering/Domain.lean", + "sha256": "ce5653a2950cc7443cefbfe8b9726bd4859228e831ddb7d42601e501ccbfd855", + "matches_third_code_snapshot": true + } + ], + "closed_findings": [ + { + "id": "R01", + "judgment": "accepted", + "reason": "T24 now includes nonempty participants/software/tools, per-participant knowledge and all listed participants possessing the nonempty path prerequisites; all remaining priority conjuncts retained." + }, + { + "id": "R02", + "judgment": "accepted", + "reason": "T29 now separates actual SoftwareState transformations from EvolutionClaim capability, contractRunner and observation treatment; proof description identifies actual cases instead of claiming a predicate field." + }, + { + "id": "R03", + "judgment": "accepted", + "reason": "T35 correctly describes one pair with five simultaneously changed grounds, old/recordedOld tampering, and separately justified retention examples." + }, + { + "id": "R04", + "judgment": "accepted", + "reason": "T36 restricts the proved result to a valid history/criticism account, unchanged choice and the named unsupported alternative; explicitly disclaims actual design revisability in this case." + }, + { + "id": "R05", + "judgment": "accepted", + "reason": "Both English and Chinese at Adopted 692 and 1314 now identify the status-only negative branch; positive branch lines unchanged." + } + ], + "documentation": { + "frozen_goal_wording": "accepted: goals/requirements unchanged, corrected predicates and expanded types identify new review objects.", + "remaining_minor_correction": "At reviews/README.md:20 replace The latter satisfies with The strong countermodel satisfies. Inserting the preceding predicates/types sentence made latter ambiguous.", + "philosophical_scope": "No new source obligation or baseline change." + }, + "delta_scope": "Actual JSON comparison against preserved r1 shows only the specified four target narratives and two repeated Adopted line annotations changed.", + "pending": [ + "Regenerated four-view hash and anchor checks.", + "Any later Domain author revision is separate work following another reviewer’s saved independent initial report; this reviewer will not self-certify it." + ] +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-independent-source-review-r2-components.md b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-source-review-r2-components.md new file mode 100644 index 0000000..0b8ed58 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-independent-source-review-r2-components.md @@ -0,0 +1,9 @@ +# 读稿 R01–R05 组件窄复核 + +五项修正均通过对应源码的窄复核:T24 完整量词及条件已展开;T29 将真实状态变换与 EvolutionClaim 的独立条件分开,proof 也正确说明独立合取;T35 改为同一对象对五项同时变化并准确指出 old/recordedOld;T36 只陈述有效历史与批评覆盖、选择保持和指定替代方向,不再误称实际可修订性;Adopted 692/1314 双语均准确标为仅地位负例。 + +实际差分只涉及指定四项 narrative 字段与 Adopted 两处重复解释。三份实际文件哈希与作者响应一致;当前 Adopted 与 Domain 源码逐字节匹配第三版固定快照。哈希与逐项判断见同名 JSON,复核输入原样另存 reader-r2-component-inputs/。 + +reviews/README 已正确区分冻结证明目标保持不变与修复后的新代码对象。尚有一项小措辞:第20行插入 corrected predicates / expanded types 句后,The latter 的指代不清;请改为 The strong countermodel satisfies,使后续 It 也有明确先行词。此项已交 Root,不影响 R01–R05 关闭。 + +这是组件阶段复核。正式四稿尚未重建,不在此声明新四稿或最终检查通过。Domain 逐行稿是我的作者贡献;后续只会根据另一位审查者已保存的独立发现作作者修正,不独立审查自己的文字。 diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-initial-overall.json b/SoftwareEngineering/lean/philosophy/reviews/reader-initial-overall.json new file mode 100644 index 0000000..3f54ec7 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-initial-overall.json @@ -0,0 +1,154 @@ +{ + "utc": "2026-09-14T18:46:30.933348+00:00", + "independence": "Source-aware independent reader; authored none of these SE manuscripts. Initial record frozen before reading any other current reader-QA results. Has previously read R3 source/code reviews; not fresh blind backtranslation.", + "object": { + "manifest_sha256": "cd300f086c45afc1ff28a63ecce92c75ec06d94164eb0cd14d898a0f7eedcf6e", + "view_hashes": { + "lean/philosophy/overview.md": "02432a947512ab709aed33c8fcd078764b96263666d0148fec5c92e111eb6f6e", + "lean/philosophy/details.md": "5e6653bfe714707aea4dedb50d97d5e155e65c3e8279c5e88a78f07e525e0199", + "zh/lean/philosophy/overview.md": "05f30d6cf6d8df5a1ab509cdeeb4f5b29c87df61d1ca178102645823c5a75b7f", + "zh/lean/philosophy/details.md": "830ea6830be5605c4e187086843ea0e4b56897df70a1feb0443302269baa7d80" + } + }, + "full_nonblank_line_review": { + "Engineering/Reflection.lean": 113, + "Engineering/SelfApplication.lean": 203, + "Engineering/Values.lean": 201, + "Engineering/Integration.lean": 547, + "total": 1064 + }, + "coverage_method": "Read exact Lean line, published EN explanation and published ZH explanation for every nonblank root4 line, including metadata; root4-lines-code-en-zh.json preserves mapping. Read sampled full overview/detail target sections and actual links; 26 cross-granularity target lookups resolve including declaration anchors.", + "questions_file": ".local/iterations/2026-09-15-advised-lean/SE-reader-QA-questions-r1.md", + "answers": [ + { + "id": 1, + "targets": [ + "T38", + "T39" + ], + "answer": "T38 chooses sharedContext and evolvable once, then supplies Inherited and DomainSatisfied for exactly those witnesses. T39 uses the same sharedContext with presentSimple, explicit PriorityConditions, Continuing, not BoundedLifecycle, no threat/departure, both necessary requirements and actual successor/agent evolution paths. The contrast is added-value non-entailment; it does not discharge DomainSatisfied for a committed SE adopter. Inherited.sameContext explicitly limits the context. The full ownTheory includes applicable norms and facts jointly; this is not separately satisfiable adoption flags.", + "detail_lines": [ + 1705, + 1741 + ], + "status": "answered; bounded representation" + }, + { + "id": 2, + "targets": [ + "T16" + ], + "answer": "Both objects use the same explainedProcess and satisfy FullProcessContract. UnderstandingApplication012 additionally requires the represented explanation and correct response to every input/multiplier variation. The fixed-double responder fails at input3/multiplier1; the mechanism responder succeeds for the specified family. Same-object grounds are proved for the stronger object and refuted for the weaker. This is the selected application criterion, not universal psychological understanding.", + "detail_lines": [ + 751, + 789 + ], + "status": "answered; application-specific" + }, + { + "id": 3, + "targets": [ + "T31" + ], + "answer": "The coordinated path edits callee1 and runs the public-contract check at caller2. Removing the caller check leaves crossesBoundary=true but boundaryObligationChecked=false; sorting actual output also fails that latter condition. Moving callee to untouched7 removes crossing applicability. Finite preservation is an explicit component; none proves arbitrary input preservation or universal boundary costs. English account referent can be clearer (R3 below).", + "detail_lines": [ + 1389, + 1430 + ], + "status": "answered; wording clarification" + }, + { + "id": 4, + "targets": [ + "T20", + "T37" + ], + "answer": "The actual generationRule and assessmentRule are ReviewObject members with object-dependent tests, not just named flags. SelfApplication links them to the actual generator/evaluator. Generation applies only where the rule applicability predicate permits it; it is not universal over phases. The declared local empty-sample assessment contract has a retained revision counterexample. generate constructs proposed expanded samples/scope and does not prove success; evaluate checks its finite sampled/requested lists and does not establish philosophical correctness. Raw input construction accepts a supplied target, with ownership enforced by the self/performed relation (R2).", + "detail_lines": [ + 16569, + 1646 + ], + "status": "answered; ownership wording correction" + }, + { + "id": 5, + "targets": [ + "T33", + "T34", + "T35", + "T36" + ], + "answer": "contractPreservation receives forall x,scope x -> new x=old x and returns it as PreservesOn; finite order/retry tests do not supply universal equality. Cases identify affected consumers/operators and show finite preservation can miss excluded input99. RevisionAccount is an alias to RevisionAccountAgainst observedHistory; independently fixed historical prediction/results cannot be repaired by changing report fields. The 21-item old size10 agreement and size5 disagreement remain. New valid evidence can support a later appropriately scoped claim; it cannot make the old failed arithmetic true.", + "detail_lines": [ + 1489, + 1528, + 1573, + 1618 + ], + "status": "answered; historical/current distinction" + }, + { + "id": 6, + "targets": [ + "T01", + "T02", + "T20", + "T34", + "T39", + "T40" + ], + "answer": "Both overview introductions select SE0.2.0/Core0.1.2 and distinguish accepted target review, limited correspondence, incomplete source material and Lean passed. Each sampled target navigates to the matching detail anchor and declaration line anchors. T02 normative specification, T20 full-Inherited projection, T34 supplied equality, T39 finite countermodel and T01/T40 documentary boundaries retain different proof force. EN/ZH sampled sections preserve those qualifications; no successful check is presented as philosophical truth or complete proof of every source paragraph. Full public link-closure portability is reserved to V10, since this fixture excludes old generated evidence.", + "detail_lines": [ + 1, + 751, + 1528, + 1741 + ], + "status": "answered; portability separate" + } + ], + "findings": [ + { + "id": "R1", + "priority": 2, + "module": "Engineering/Reflection.lean", + "source_line": 35, + "en_detail_line": 15786, + "zh_detail_line": 15786, + "finding": "The generated Outcome equality instance is conditional on DecidableEq W; both explanations omit that typeclass premise and sound unconditional.", + "actual_evidence": "binder-lookup-probe-r2.json: @Reflection.instDecidableEqOutcome : {W : Type} → [DecidableEq W] → DecidableEq (Reflection.Outcome W)", + "requested_change": "Say that deriving provides decidable equality on Outcome W when decidable equality on W is available; retain the concrete model specialization.", + "scope": "reader prose only" + }, + { + "id": "R2", + "priority": 3, + "module": "Engineering/SelfApplication.lean", + "source_line": 115, + "en_detail_line": 16569, + "zh_detail_line": 16569, + "finding": "All its targets use owner 0 / 其所有目标使用所有者0 overstates the owner field: selfModel.input accepts a Target with any owner. Owner0 restricts self-owned targets through the separate self relation.", + "actual_evidence": "binder-lookup-probe-r2.json: #eval ((selfModel .evolvable).input ⟨99, .activity, .revision⟩).target.owner gives 99.", + "requested_change": "State that the model owner is 0; its self-owned targets must match that owner. Do not claim raw input targets are constrained by this field.", + "scope": "reader prose only" + }, + { + "id": "R3", + "priority": 3, + "module": "overview/detail T31", + "en_overview_line": 601, + "en_detail_line": 1395, + "finding": "After naming StructuralAccount, fails the account can refer to the wrong predicate. The negative calculation actually establishes boundaryObligationChecked=false; StructuralAccount takes different arguments and is not refuted by this theorem. Chinese 不能履责 does not make the same named-predicate identification.", + "actual_evidence": "structuralCases actual #check; Domain.lean:641 and 703–708; negative at 720–727.", + "requested_change": "Replace fails the account with fails the boundary-obligation check or name boundaryObligationChecked in both EN granularities.", + "scope": "precise referent clarification; no code claim" + } + ], + "verdict": "All six interpretation tasks answered from actual frozen manuscripts and code. Two local binder/ownership explanations require qualification; one English predicate referent should be tightened. No new proof or philosophy change follows. Final synchronized reader approval awaits actual prose correction and final hashes.", + "limits": [ + "Did not author or fully review the helper/Adopted/Domain per-line explanations in this QA; other reviewers handle them.", + "Initial Lean probe used two guessed theorem names and exited1; retained in binder-lookup-probe.json. Actual manuscript lookup recovered structuralCases and contractPreservation; probe-r2 exited0. No failure was hidden.", + "Reader coverage and check success do not prove philosophical correctness, exhaustive factual adequacy or universal method completeness.", + "V10 final public portable delivery and final changed-view lookup remain separate pending work." + ] +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/reader-initial-overall.md b/SoftwareEngineering/lean/philosophy/reviews/reader-initial-overall.md new file mode 100644 index 0000000..cd4d9bf --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/reader-initial-overall.md @@ -0,0 +1,44 @@ +# Independent SE reader QA, frozen r1 + +Source-aware independent reader; authored none of these SE manuscripts. Initial record frozen before reading any other current reader-QA results. Has previously read R3 source/code reviews; not fresh blind backtranslation. + +Read exact Lean line, published EN explanation and published ZH explanation for every nonblank root4 line, including metadata; root4-lines-code-en-zh.json preserves mapping. Read sampled full overview/detail target sections and actual links; 26 cross-granularity target lookups resolve including declaration anchors. + +All six interpretation tasks answered from actual frozen manuscripts and code. Two local binder/ownership explanations require qualification; one English predicate referent should be tightened. No new proof or philosophy change follows. Final synchronized reader approval awaits actual prose correction and final hashes. + +## Question 1 + +T38 chooses sharedContext and evolvable once, then supplies Inherited and DomainSatisfied for exactly those witnesses. T39 uses the same sharedContext with presentSimple, explicit PriorityConditions, Continuing, not BoundedLifecycle, no threat/departure, both necessary requirements and actual successor/agent evolution paths. The contrast is added-value non-entailment; it does not discharge DomainSatisfied for a committed SE adopter. Inherited.sameContext explicitly limits the context. The full ownTheory includes applicable norms and facts jointly; this is not separately satisfiable adoption flags. + +## Question 2 + +Both objects use the same explainedProcess and satisfy FullProcessContract. UnderstandingApplication012 additionally requires the represented explanation and correct response to every input/multiplier variation. The fixed-double responder fails at input3/multiplier1; the mechanism responder succeeds for the specified family. Same-object grounds are proved for the stronger object and refuted for the weaker. This is the selected application criterion, not universal psychological understanding. + +## Question 3 + +The coordinated path edits callee1 and runs the public-contract check at caller2. Removing the caller check leaves crossesBoundary=true but boundaryObligationChecked=false; sorting actual output also fails that latter condition. Moving callee to untouched7 removes crossing applicability. Finite preservation is an explicit component; none proves arbitrary input preservation or universal boundary costs. English account referent can be clearer (R3 below). + +## Question 4 + +The actual generationRule and assessmentRule are ReviewObject members with object-dependent tests, not just named flags. SelfApplication links them to the actual generator/evaluator. Generation applies only where the rule applicability predicate permits it; it is not universal over phases. The declared local empty-sample assessment contract has a retained revision counterexample. generate constructs proposed expanded samples/scope and does not prove success; evaluate checks its finite sampled/requested lists and does not establish philosophical correctness. Raw input construction accepts a supplied target, with ownership enforced by the self/performed relation (R2). + +## Question 5 + +contractPreservation receives forall x,scope x -> new x=old x and returns it as PreservesOn; finite order/retry tests do not supply universal equality. Cases identify affected consumers/operators and show finite preservation can miss excluded input99. RevisionAccount is an alias to RevisionAccountAgainst observedHistory; independently fixed historical prediction/results cannot be repaired by changing report fields. The 21-item old size10 agreement and size5 disagreement remain. New valid evidence can support a later appropriately scoped claim; it cannot make the old failed arithmetic true. + +## Question 6 + +Both overview introductions select SE0.2.0/Core0.1.2 and distinguish accepted target review, limited correspondence, incomplete source material and Lean passed. Each sampled target navigates to the matching detail anchor and declaration line anchors. T02 normative specification, T20 full-Inherited projection, T34 supplied equality, T39 finite countermodel and T01/T40 documentary boundaries retain different proof force. EN/ZH sampled sections preserve those qualifications; no successful check is presented as philosophical truth or complete proof of every source paragraph. Full public link-closure portability is reserved to V10, since this fixture excludes old generated evidence. + +## Necessary local wording findings + +- R1 (2): Engineering/Reflection.lean:35: The generated Outcome equality instance is conditional on DecidableEq W; both explanations omit that typeclass premise and sound unconditional. Say that deriving provides decidable equality on Outcome W when decidable equality on W is available; retain the concrete model specialization. Evidence: binder-lookup-probe-r2.json: @Reflection.instDecidableEqOutcome : {W : Type} → [DecidableEq W] → DecidableEq (Reflection.Outcome W) +- R2 (3): Engineering/SelfApplication.lean:115: All its targets use owner 0 / 其所有目标使用所有者0 overstates the owner field: selfModel.input accepts a Target with any owner. Owner0 restricts self-owned targets through the separate self relation. State that the model owner is 0; its self-owned targets must match that owner. Do not claim raw input targets are constrained by this field. Evidence: binder-lookup-probe-r2.json: #eval ((selfModel .evolvable).input ⟨99, .activity, .revision⟩).target.owner gives 99. +- R3 (3): overview/detail T31:1395: After naming StructuralAccount, fails the account can refer to the wrong predicate. The negative calculation actually establishes boundaryObligationChecked=false; StructuralAccount takes different arguments and is not refuted by this theorem. Chinese 不能履责 does not make the same named-predicate identification. Replace fails the account with fails the boundary-obligation check or name boundaryObligationChecked in both EN granularities. Evidence: structuralCases actual #check; Domain.lean:641 and 703–708; negative at 720–727. + +## Limits + +- Did not author or fully review the helper/Adopted/Domain per-line explanations in this QA; other reviewers handle them. +- Initial Lean probe used two guessed theorem names and exited1; retained in binder-lookup-probe.json. Actual manuscript lookup recovered structuralCases and contractPreservation; probe-r2 exited0. No failure was hidden. +- Reader coverage and check success do not prove philosophical correctness, exhaustive factual adequacy or universal method completeness. +- V10 final public portable delivery and final changed-view lookup remain separate pending work. diff --git a/SoftwareEngineering/lean/philosophy/reviews/semantic-cases.json b/SoftwareEngineering/lean/philosophy/reviews/semantic-cases.json new file mode 100644 index 0000000..3345e27 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/semantic-cases.json @@ -0,0 +1,2769 @@ +{ + "role": "Derived from the hash-bound R3 independent source/code review; semantic acceptance is reported by the reviewer, not produced by this export.", + "review_original_sha256": "e01cd00cbcfa4ba8c6592917ea7321eb3826bc0b365a2b1b64170a1a24a93825", + "frozen_targets_sha256": "c0939df35dad148a0543ba92a1ac7b7d3b2eb4946f92ac4be251ec51b6481d13", + "cases": [ + { + "target": "T02", + "case": "positive_valued_open_forms", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.generationCases", + "file": "CoreReader/Adopted.lean", + "line": 862, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "Generative requires valuation of expansion and revisability of every current Form, including organization, method and principle. Current examples are nonempty; the stable trace and budget-respecting stable action show that generativity does not require change in every act. This is an adopted policy predicate, not proof all systems possess it.", + "special_limits": [] + }, + { + "target": "T02", + "case": "negative_permission_only", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.permissionNotValuation", + "file": "CoreReader/Agency.lean", + "line": 37, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "Generative requires valuation of expansion and revisability of every current Form, including organization, method and principle. Current examples are nonempty; the stable trace and budget-respecting stable action show that generativity does not require change in every act. This is an adopted policy predicate, not proof all systems possess it.", + "special_limits": [] + }, + { + "target": "T02", + "case": "positive_stability", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.generationLimits", + "file": "CoreReader/Agency.lean", + "line": 194, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "Generative requires valuation of expansion and revisability of every current Form, including organization, method and principle. Current examples are nonempty; the stable trace and budget-respecting stable action show that generativity does not require change in every act. This is an adopted policy predicate, not proof all systems possess it.", + "special_limits": [] + }, + { + "target": "T02", + "case": "external_collaboration", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.collaborativeProgress", + "file": "CoreReader/Adopted.lean", + "line": 223, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "Generative requires valuation of expansion and revisability of every current Form, including organization, method and principle. Current examples are nonempty; the stable trace and budget-respecting stable action show that generativity does not require change in every act. This is an adopted policy predicate, not proof all systems possess it.", + "special_limits": [] + }, + { + "target": "T03", + "case": "permission_without_value", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.permissionNotValuation", + "file": "CoreReader/Agency.lean", + "line": 37, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions.", + "special_limits": [] + }, + { + "target": "T03", + "case": "orientation_without_progress", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.revisionWithoutProgress", + "file": "CoreReader/Agency.lean", + "line": 99, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions.", + "special_limits": [] + }, + { + "target": "T03", + "case": "count_growth_without_capability", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.generationLimits", + "file": "CoreReader/Agency.lean", + "line": 194, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions.", + "special_limits": [] + }, + { + "target": "T03", + "case": "collaborative_nonautonomous_progress", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.collaborativeProgress", + "file": "CoreReader/Adopted.lean", + "line": 223, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions.", + "special_limits": [] + }, + { + "target": "T03", + "case": "claim_without_achievement", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.inflatedAnnouncementRefuted", + "file": "CoreReader/Agency.lean", + "line": 171, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions.", + "special_limits": [] + }, + { + "target": "T03", + "case": "achievement_support_for_same_claim", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.achievementSupported012", + "file": "CoreReader/Adopted.lean", + "line": 620, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "The neutral policy permits change without valuing it; openPolicy plus stableTrace lacks progress; inflatedState adds counts without new operations. Collaborative revision depends on a collaborator; execution lacks a result when required resources are absent. The transition achievement record concerns the same before/after/operation/input, while assertion records admit the failed inflation case. All are explicit finite constructions.", + "special_limits": [] + }, + { + "target": "T04", + "case": "joint_only_contradiction", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.jointImplicationConflict012", + "file": "CoreReader/Adopted.lean", + "line": 703, + "axioms": "[]" + } + ], + "interpretation": "Consistent quantifies over joint semantic consequences of the whole held theory under one Context. Snapshot change reporting is a separate one-way Boolean obligation. The code preserves same-question/assumptions/meaning/scope and time-slice distinctions; it does not model every way a prose report could conceal change.", + "special_limits": [] + }, + { + "target": "T04", + "case": "changed_scope_not_concealed", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Logic.hiddenContextChangeRejected", + "file": "CoreReader/Logic.lean", + "line": 134, + "axioms": "[]" + } + ], + "interpretation": "Consistent quantifies over joint semantic consequences of the whole held theory under one Context. Snapshot change reporting is a separate one-way Boolean obligation. The code preserves same-question/assumptions/meaning/scope and time-slice distinctions; it does not model every way a prose report could conceal change.", + "special_limits": [] + }, + { + "target": "T04", + "case": "revision_withdraws_old", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Logic.revisionCanReverse", + "file": "CoreReader/Logic.lean", + "line": 68, + "axioms": "[]" + } + ], + "interpretation": "Consistent quantifies over joint semantic consequences of the whole held theory under one Context. Snapshot change reporting is a separate one-way Boolean obligation. The code preserves same-question/assumptions/meaning/scope and time-slice distinctions; it does not model every way a prose report could conceal change.", + "special_limits": [] + }, + { + "target": "T04", + "case": "incompatible_same_context", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.consistencyConsequences", + "file": "CoreReader/Adopted.lean", + "line": 241, + "axioms": "[]" + } + ], + "interpretation": "Consistent quantifies over joint semantic consequences of the whole held theory under one Context. Snapshot change reporting is a separate one-way Boolean obligation. The code preserves same-question/assumptions/meaning/scope and time-slice distinctions; it does not model every way a prose report could conceal change.", + "special_limits": [] + }, + { + "target": "T05", + "case": "pair_conflict", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.consistencyConsequences", + "file": "CoreReader/Adopted.lean", + "line": 241, + "axioms": "[]" + } + ], + "interpretation": "consistencyConsequences directly applies the consistency prohibition to supplied positive and negative consequences. The revisionSlice examples provide distinct satisfiable times and inconsistent union; context examples preserve an admissible witness for each context. The theorem neither proves premises nor mandates permanent historical compatibility.", + "special_limits": [] + }, + { + "target": "T05", + "case": "joint_premise_conflict", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.jointImplicationConflict012", + "file": "CoreReader/Adopted.lean", + "line": 703, + "axioms": "[]" + } + ], + "interpretation": "consistencyConsequences directly applies the consistency prohibition to supplied positive and negative consequences. The revisionSlice examples provide distinct satisfiable times and inconsistent union; context examples preserve an admissible witness for each context. The theorem neither proves premises nor mandates permanent historical compatibility.", + "special_limits": [] + }, + { + "target": "T05", + "case": "old_new_separate_times", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.sliceConsistency", + "file": "CoreReader/Adopted.lean", + "line": 247, + "axioms": "[]" + } + ], + "interpretation": "consistencyConsequences directly applies the consistency prohibition to supplied positive and negative consequences. The revisionSlice examples provide distinct satisfiable times and inconsistent union; context examples preserve an admissible witness for each context. The theorem neither proves premises nor mandates permanent historical compatibility.", + "special_limits": [] + }, + { + "target": "T05", + "case": "distinct_context_judgments", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Logic.contextDifferences", + "file": "CoreReader/Logic.lean", + "line": 88, + "axioms": "[]" + } + ], + "interpretation": "consistencyConsequences directly applies the consistency prohibition to supplied positive and negative consequences. The revisionSlice examples provide distinct satisfiable times and inconsistent union; context examples preserve an admissible witness for each context. The theorem neither proves premises nor mandates permanent historical compatibility.", + "special_limits": [] + }, + { + "target": "T05", + "case": "truthful_semantic_change_and_reordering", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Logic.hiddenContextChangeRejected", + "file": "CoreReader/Logic.lean", + "line": 134, + "axioms": "[]" + }, + { + "name": "CoreReader.Adopted.semanticOrder012", + "file": "CoreReader/Adopted.lean", + "line": 630, + "axioms": "[]" + } + ], + "interpretation": "consistencyConsequences directly applies the consistency prohibition to supplied positive and negative consequences. The revisionSlice examples provide distinct satisfiable times and inconsistent union; context examples preserve an admissible witness for each context. The theorem neither proves premises nor mandates permanent historical compatibility.", + "special_limits": [] + }, + { + "target": "T06", + "case": "different_contexts", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Logic.contextDifferences", + "file": "CoreReader/Logic.lean", + "line": 88, + "axioms": "[]" + } + ], + "interpretation": "Concrete contexts, overlapping inequalities, a consistent theory false at the selected outside world, and empty-theory countervaluations distinguish contradiction, truth, sufficiency and entailment. These support the source limits without relying on a free false support flag.", + "special_limits": [] + }, + { + "target": "T06", + "case": "tension_compatible", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.tensionConsistent012", + "file": "CoreReader/Adopted.lean", + "line": 718, + "axioms": "[]" + } + ], + "interpretation": "Concrete contexts, overlapping inequalities, a consistent theory false at the selected outside world, and empty-theory countervaluations distinguish contradiction, truth, sufficiency and entailment. These support the source limits without relying on a free false support flag.", + "special_limits": [] + }, + { + "target": "T06", + "case": "consistent_false_assumption", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.explicitlyConsistentLimits", + "file": "CoreReader/Adopted.lean", + "line": 262, + "axioms": "[]" + } + ], + "interpretation": "Concrete contexts, overlapping inequalities, a consistent theory false at the selected outside world, and empty-theory countervaluations distinguish contradiction, truth, sufficiency and entailment. These support the source limits without relying on a free false support flag.", + "special_limits": [] + }, + { + "target": "T06", + "case": "consistent_omitted_question", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.explicitlyConsistentLimits", + "file": "CoreReader/Adopted.lean", + "line": 262, + "axioms": "[]" + } + ], + "interpretation": "Concrete contexts, overlapping inequalities, a consistent theory false at the selected outside world, and empty-theory countervaluations distinguish contradiction, truth, sufficiency and entailment. These support the source limits without relying on a free false support flag.", + "special_limits": [] + }, + { + "target": "T06", + "case": "compatible_not_entailed", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Logic.compatibilityNotEntailment", + "file": "CoreReader/Logic.lean", + "line": 180, + "axioms": "[]" + } + ], + "interpretation": "Concrete contexts, overlapping inequalities, a consistent theory false at the selected outside world, and empty-theory countervaluations distinguish contradiction, truth, sufficiency and entailment. These support the source limits without relying on a free false support flag.", + "special_limits": [] + }, + { + "target": "T07", + "case": "self_applicable", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.reflexiveTargets012", + "file": "CoreReader/Adopted.lean", + "line": 605, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "The general interface/cases are reused; its engineering realization was rereviewed because selfModel now includes actual generation/evaluation rule objects and applicability. This strengthens rather than universalizes the source conditions.", + "special_limits": [] + }, + { + "target": "T07", + "case": "self_inapplicable", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.applicabilityRetained", + "file": "CoreReader/Reflexivity.lean", + "line": 396, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "The general interface/cases are reused; its engineering realization was rereviewed because selfModel now includes actual generation/evaluation rule objects and applicability. This strengthens rather than universalizes the source conditions.", + "special_limits": [] + }, + { + "target": "T07", + "case": "principle_formation", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.completeOwnWork_reflexive", + "file": "CoreReader/Reflexivity.lean", + "line": 358, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "The general interface/cases are reused; its engineering realization was rereviewed because selfModel now includes actual generation/evaluation rule objects and applicability. This strengthens rather than universalizes the source conditions.", + "special_limits": [] + }, + { + "target": "T07", + "case": "principle_application", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.reflexiveTargets012", + "file": "CoreReader/Adopted.lean", + "line": 605, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "The general interface/cases are reused; its engineering realization was rereviewed because selfModel now includes actual generation/evaluation rule objects and applicability. This strengthens rather than universalizes the source conditions.", + "special_limits": [] + }, + { + "target": "T07", + "case": "principle_revision", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.reflexiveTargets012", + "file": "CoreReader/Adopted.lean", + "line": 605, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "The general interface/cases are reused; its engineering realization was rereviewed because selfModel now includes actual generation/evaluation rule objects and applicability. This strengthens rather than universalizes the source conditions.", + "special_limits": [] + }, + { + "target": "T07", + "case": "grounds_on_grounds", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.groundsOnGrounds012", + "file": "CoreReader/Adopted.lean", + "line": 595, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "The general interface/cases are reused; its engineering realization was rereviewed because selfModel now includes actual generation/evaluation rule objects and applicability. This strengthens rather than universalizes the source conditions.", + "special_limits": [] + }, + { + "target": "T08", + "case": "self_assessed_incorrect", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Agency.selfTestDoesNotProve", + "file": "CoreReader/Agency.lean", + "line": 239, + "axioms": "[]" + } + ], + "interpretation": "A revisable principle applied only to target 1 fails required self-target 0; self tests fail elsewhere; owned revisions retain unsupported global claims. CompleteCharter012 is inhabited yet costAllowanceRecord admits an incorrect-output world, so the concrete corresponding Grounds012 claim fails. This is a bounded charter-versus-support model, not philosophical independence in all interpretations.", + "special_limits": [] + }, + { + "target": "T08", + "case": "self_generated_unsupported", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.selfOriginDoesNotSupport", + "file": "CoreReader/Evidence.lean", + "line": 541, + "axioms": "[propext]" + } + ], + "interpretation": "A revisable principle applied only to target 1 fails required self-target 0; self tests fail elsewhere; owned revisions retain unsupported global claims. CompleteCharter012 is inhabited yet costAllowanceRecord admits an incorrect-output world, so the concrete corresponding Grounds012 claim fails. This is a bounded charter-versus-support model, not philosophical independence in all interpretations.", + "special_limits": [] + }, + { + "target": "T08", + "case": "open_but_self_exempt", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.openSelfExempt012", + "file": "CoreReader/Adopted.lean", + "line": 680, + "axioms": "[propext]" + } + ], + "interpretation": "A revisable principle applied only to target 1 fails required self-target 0; self tests fail elsewhere; owned revisions retain unsupported global claims. CompleteCharter012 is inhabited yet costAllowanceRecord admits an incorrect-output world, so the concrete corresponding Grounds012 claim fails. This is a bounded charter-versus-support model, not philosophical independence in all interpretations.", + "special_limits": [] + }, + { + "target": "T08", + "case": "charter_not_general_grounds", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.charterWithoutGrounds012", + "file": "CoreReader/Adopted.lean", + "line": 499, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "A revisable principle applied only to target 1 fails required self-target 0; self tests fail elsewhere; owned revisions retain unsupported global claims. CompleteCharter012 is inhabited yet costAllowanceRecord admits an incorrect-output world, so the concrete corresponding Grounds012 claim fails. This is a bounded charter-versus-support model, not philosophical independence in all interpretations.", + "special_limits": [] + }, + { + "target": "T09", + "case": "articulable_supported", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.scopeStrength012", + "file": "CoreReader/Adopted.lean", + "line": 286, + "axioms": "[propext]" + } + ], + "interpretation": "Grounds012 formalizes successful supported grounds for one declared task using same claim/articulation/discharge and task-appropriateness. Local/global and stronger-claim countermodels preserve force and scope. It is not a complete classifier or universal procedure for deciding all possible mixed claims. Calling it the obligation to examine rather than the successful support condition would overstate the correspondence. No Core 0.1.3 all-facet obligation is introduced.", + "special_limits": [] + }, + { + "target": "T09", + "case": "articulable_unsupported", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.articulationNotSupport", + "file": "CoreReader/Evidence.lean", + "line": 325, + "axioms": "[propext]" + } + ], + "interpretation": "Grounds012 formalizes successful supported grounds for one declared task using same claim/articulation/discharge and task-appropriateness. Local/global and stronger-claim countermodels preserve force and scope. It is not a complete classifier or universal procedure for deciding all possible mixed claims. Calling it the obligation to examine rather than the successful support condition would overstate the correspondence. No Core 0.1.3 all-facet obligation is introduced.", + "special_limits": [] + }, + { + "target": "T09", + "case": "scope_overreach", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.scopeStrength012", + "file": "CoreReader/Adopted.lean", + "line": 286, + "axioms": "[propext]" + } + ], + "interpretation": "Grounds012 formalizes successful supported grounds for one declared task using same claim/articulation/discharge and task-appropriateness. Local/global and stronger-claim countermodels preserve force and scope. It is not a complete classifier or universal procedure for deciding all possible mixed claims. Calling it the obligation to examine rather than the successful support condition would overstate the correspondence. No Core 0.1.3 all-facet obligation is introduced.", + "special_limits": [] + }, + { + "target": "T09", + "case": "strength_overreach", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.scopeStrength012", + "file": "CoreReader/Adopted.lean", + "line": 286, + "axioms": "[propext]" + } + ], + "interpretation": "Grounds012 formalizes successful supported grounds for one declared task using same claim/articulation/discharge and task-appropriateness. Local/global and stronger-claim countermodels preserve force and scope. It is not a complete classifier or universal procedure for deciding all possible mixed claims. Calling it the obligation to examine rather than the successful support condition would overstate the correspondence. No Core 0.1.3 all-facet obligation is introduced.", + "special_limits": [] + }, + { + "target": "T10", + "case": "observed_relevant", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.localFacetChecked012", + "file": "CoreReader/Adopted.lean", + "line": 282, + "axioms": "[propext]" + } + ], + "interpretation": "Empirical discharge includes an in-scope compatible witness, scoped support and uncertainty support. Repetition of irrelevant first-coordinate/action observations cannot establish the second coordinate or budget value. The successful uncertainty is the exhaustive Boolean disjunction, not a quantified confidence estimate or a production measurement.", + "special_limits": [] + }, + { + "target": "T10", + "case": "repeatable_irrelevant", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.measurementRepeatNotSupport", + "file": "CoreReader/Evidence.lean", + "line": 394, + "axioms": "[propext]" + } + ], + "interpretation": "Empirical discharge includes an in-scope compatible witness, scoped support and uncertainty support. Repetition of irrelevant first-coordinate/action observations cannot establish the second coordinate or budget value. The successful uncertainty is the exhaustive Boolean disjunction, not a quantified confidence estimate or a production measurement.", + "special_limits": [] + }, + { + "target": "T10", + "case": "measured_wrong_scope", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.scopeStrength012", + "file": "CoreReader/Adopted.lean", + "line": 286, + "axioms": "[propext]" + } + ], + "interpretation": "Empirical discharge includes an in-scope compatible witness, scoped support and uncertainty support. Repetition of irrelevant first-coordinate/action observations cannot establish the second coordinate or budget value. The successful uncertainty is the exhaustive Boolean disjunction, not a quantified confidence estimate or a production measurement.", + "special_limits": [] + }, + { + "target": "T10", + "case": "uncertain_limited", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.uncertainSupported012", + "file": "CoreReader/Adopted.lean", + "line": 308, + "axioms": "[propext]" + } + ], + "interpretation": "Empirical discharge includes an in-scope compatible witness, scoped support and uncertainty support. Repetition of irrelevant first-coordinate/action observations cannot establish the second coordinate or budget value. The successful uncertainty is the exhaustive Boolean disjunction, not a quantified confidence estimate or a production measurement.", + "special_limits": [] + }, + { + "target": "T11", + "case": "valid_inference", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.inferenceChecked012", + "file": "CoreReader/Adopted.lean", + "line": 323, + "axioms": "[propext]" + } + ], + "interpretation": "The inferential wrapper requires satisfiable assumptions and actual entailment. Correct rejection of an unentailed conclusion is represented separately by InferenceExamined false and a countervaluation. Together they preserve the examination/success distinction, provided the wrapper alone is not described as the full act of assessment.", + "special_limits": [] + }, + { + "target": "T11", + "case": "compatible_unentailed", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Logic.compatibilityNotEntailment", + "file": "CoreReader/Logic.lean", + "line": 180, + "axioms": "[]" + } + ], + "interpretation": "The inferential wrapper requires satisfiable assumptions and actual entailment. Correct rejection of an unentailed conclusion is represented separately by InferenceExamined false and a countervaluation. Together they preserve the examination/success distinction, provided the wrapper alone is not described as the full act of assessment.", + "special_limits": [] + }, + { + "target": "T11", + "case": "false_inference_detected", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.inferenceChecked012", + "file": "CoreReader/Adopted.lean", + "line": 323, + "axioms": "[propext]" + } + ], + "interpretation": "The inferential wrapper requires satisfiable assumptions and actual entailment. Correct rejection of an unentailed conclusion is represented separately by InferenceExamined false and a countervaluation. Together they preserve the examination/success distinction, provided the wrapper alone is not described as the full act of assessment.", + "special_limits": [] + }, + { + "target": "T12", + "case": "reasoned_value", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.valueFulfilled012", + "file": "CoreReader/Adopted.lean", + "line": 341, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "The value construction identifies position, joint reasons, application limits, consequences and relevant criticism responses. It assumes starting claims and supplies a joint witness instead of proving every starting assumption. The universal consequence test and response nonemptiness are this application's sufficient procedure, not newly mandatory philosophical proof requirements or proof of response adequacy.", + "special_limits": [] + }, + { + "target": "T12", + "case": "unsupported_self_assertion", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.announcementNotBudgetReason", + "file": "CoreReader/Evidence.lean", + "line": 372, + "axioms": "[propext]" + } + ], + "interpretation": "The value construction identifies position, joint reasons, application limits, consequences and relevant criticism responses. It assumes starting claims and supplies a joint witness instead of proving every starting assumption. The universal consequence test and response nonemptiness are this application's sufficient procedure, not newly mandatory philosophical proof requirements or proof of response adequacy.", + "special_limits": [] + }, + { + "target": "T12", + "case": "closed_criticism", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.closedCriticism012", + "file": "CoreReader/Adopted.lean", + "line": 336, + "axioms": "[]" + } + ], + "interpretation": "The value construction identifies position, joint reasons, application limits, consequences and relevant criticism responses. It assumes starting claims and supplies a joint witness instead of proving every starting assumption. The universal consequence test and response nonemptiness are this application's sufficient procedure, not newly mandatory philosophical proof requirements or proof of response adequacy.", + "special_limits": [] + }, + { + "target": "T12", + "case": "explicit_initial_commitment", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.valueWithoutSelfProof", + "file": "CoreReader/Evidence.lean", + "line": 426, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "The value construction identifies position, joint reasons, application limits, consequences and relevant criticism responses. It assumes starting claims and supplies a joint witness instead of proving every starting assumption. The universal consequence test and response nonemptiness are this application's sufficient procedure, not newly mandatory philosophical proof requirements or proof of response adequacy.", + "special_limits": [] + }, + { + "target": "T13", + "case": "clear_false_reason", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.clearFalseReason012", + "file": "CoreReader/Adopted.lean", + "line": 637, + "axioms": "[propext]" + } + ], + "interpretation": "Clearly articulated false assumptions, repeated wrong-object observations, neutral records compatible with nonadoption, and the ordinary value example show the intended non-substitutions. Qualitative implication orders claim strength without imposing a numerical scale.", + "special_limits": [] + }, + { + "target": "T13", + "case": "repeatable_wrong_object", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.measurementRepeatNotSupport", + "file": "CoreReader/Evidence.lean", + "line": 394, + "axioms": "[propext]" + } + ], + "interpretation": "Clearly articulated false assumptions, repeated wrong-object observations, neutral records compatible with nonadoption, and the ordinary value example show the intended non-substitutions. Qualitative implication orders claim strength without imposing a numerical scale.", + "special_limits": [] + }, + { + "target": "T13", + "case": "value_not_fact", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.valueNotFact012", + "file": "CoreReader/Adopted.lean", + "line": 643, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Clearly articulated false assumptions, repeated wrong-object observations, neutral records compatible with nonadoption, and the ordinary value example show the intended non-substitutions. Qualitative implication orders claim strength without imposing a numerical scale.", + "special_limits": [] + }, + { + "target": "T13", + "case": "initial_value_without_selfproof", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.valueWithoutSelfProof", + "file": "CoreReader/Evidence.lean", + "line": 426, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Clearly articulated false assumptions, repeated wrong-object observations, neutral records compatible with nonadoption, and the ordinary value example show the intended non-substitutions. Qualitative implication orders claim strength without imposing a numerical scale.", + "special_limits": [] + }, + { + "target": "T13", + "case": "qualitative_proportionality", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.qualitativeProportionality012", + "file": "CoreReader/Adopted.lean", + "line": 348, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Clearly articulated false assumptions, repeated wrong-object observations, neutral records compatible with nonadoption, and the ordinary value example show the intended non-substitutions. Qualitative implication orders claim strength without imposing a numerical scale.", + "special_limits": [] + }, + { + "target": "T14", + "case": "local_scope_declared", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.scopeFulfilled012", + "file": "CoreReader/Adopted.lean", + "line": 379, + "axioms": "[propext]" + } + ], + "interpretation": "The local scope account binds comparison pairs, conditions, observed scope, relevance and each method explanation to the same claim. Its concrete method meanings prove local/repeated support and failure of global support. The generic explains relation remains supplied and the interface does not force every method to be used.", + "special_limits": [] + }, + { + "target": "T14", + "case": "omitted_relevant_difference", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.hiddenDifference", + "file": "CoreReader/Evidence.lean", + "line": 560, + "axioms": "[]" + } + ], + "interpretation": "The local scope account binds comparison pairs, conditions, observed scope, relevance and each method explanation to the same claim. Its concrete method meanings prove local/repeated support and failure of global support. The generic explains relation remains supplied and the interface does not force every method to be used.", + "special_limits": [] + }, + { + "target": "T14", + "case": "measurement_role", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.scopeFulfilled012", + "file": "CoreReader/Adopted.lean", + "line": 379, + "axioms": "[propext]" + } + ], + "interpretation": "The local scope account binds comparison pairs, conditions, observed scope, relevance and each method explanation to the same claim. Its concrete method meanings prove local/repeated support and failure of global support. The generic explains relation remains supplied and the interface does not force every method to be used.", + "special_limits": [] + }, + { + "target": "T14", + "case": "repetition_role", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.scopeFulfilled012", + "file": "CoreReader/Adopted.lean", + "line": 379, + "axioms": "[propext]" + } + ], + "interpretation": "The local scope account binds comparison pairs, conditions, observed scope, relevance and each method explanation to the same claim. Its concrete method meanings prove local/repeated support and failure of global support. The generic explains relation remains supplied and the interface does not force every method to be used.", + "special_limits": [] + }, + { + "target": "T14", + "case": "framework_role", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.scopeFulfilled012", + "file": "CoreReader/Adopted.lean", + "line": 379, + "axioms": "[propext]" + } + ], + "interpretation": "The local scope account binds comparison pairs, conditions, observed scope, relevance and each method explanation to the same claim. Its concrete method meanings prove local/repeated support and failure of global support. The generic explains relation remains supplied and the interface does not force every method to be used.", + "special_limits": [] + }, + { + "target": "T15", + "case": "equal_local_different_global", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.localNotUniversal", + "file": "CoreReader/Evidence.lean", + "line": 550, + "axioms": "[propext]" + } + ], + "interpretation": "Explicit functions agree only at zero and differ at one; one observation supplies local support. Trial fields separate recorded accuracy, equal settings and bounded output, and Boolean draws have equal positive weights with different outcomes. This is a finite possible-outcome model, not verification of a real stochastic process.", + "special_limits": [] + }, + { + "target": "T15", + "case": "excluded_difference", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.hiddenDifference", + "file": "CoreReader/Evidence.lean", + "line": 560, + "axioms": "[]" + } + ], + "interpretation": "Explicit functions agree only at zero and differ at one; one observation supplies local support. Trial fields separate recorded accuracy, equal settings and bounded output, and Boolean draws have equal positive weights with different outcomes. This is a finite possible-outcome model, not verification of a real stochastic process.", + "special_limits": [] + }, + { + "target": "T15", + "case": "one_observation_limited_support", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.singleObservation", + "file": "CoreReader/Evidence.lean", + "line": 566, + "axioms": "[propext]" + } + ], + "interpretation": "Explicit functions agree only at zero and differ at one; one observation supplies local support. Trial fields separate recorded accuracy, equal settings and bounded output, and Boolean draws have equal positive weights with different outcomes. This is a finite possible-outcome model, not verification of a real stochastic process.", + "special_limits": [] + }, + { + "target": "T15", + "case": "varying_random_outcomes", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.randomOutcomes012", + "file": "CoreReader/Adopted.lean", + "line": 744, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "Explicit functions agree only at zero and differ at one; one observation supplies local support. Trial fields separate recorded accuracy, equal settings and bounded output, and Boolean draws have equal positive weights with different outcomes. This is a finite possible-outcome model, not verification of a real stochastic process.", + "special_limits": [] + }, + { + "target": "T15", + "case": "qualitative_unmeasured_judgment", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.qualitativeUnmeasured012", + "file": "CoreReader/Adopted.lean", + "line": 724, + "axioms": "[propext]" + } + ], + "interpretation": "Explicit functions agree only at zero and differ at one; one observation supplies local support. Trial fields separate recorded accuracy, equal settings and bounded output, and Boolean draws have equal positive weights with different outcomes. This is a finite possible-outcome model, not verification of a real stochastic process.", + "special_limits": [] + }, + { + "target": "T16", + "case": "external_output_capability", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.capabilityFulfilled012", + "file": "CoreReader/Adopted.lean", + "line": 391, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved for the explicitly declared application capability UnderstandingApplication012: the same explained doubling process must also answer all multiplier/input variations using the actual multiplication mechanism. Identical output and ExplanationContract no longer suffice: the fixed-double answer gives 2 instead of 3 at multiplier=3,input=1, while mechanismResponder answers the declared variations and receives same-object Grounds. This is an operational understanding/variation-answer capability selected by the application, not a cognitive definition or universal standard of understanding.", + "special_limits": [] + }, + { + "target": "T16", + "case": "application_requires_understanding", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.understandingApplicationCases012", + "file": "CoreReader/Adopted.lean", + "line": 447, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved for the explicitly declared application capability UnderstandingApplication012: the same explained doubling process must also answer all multiplier/input variations using the actual multiplication mechanism. Identical output and ExplanationContract no longer suffice: the fixed-double answer gives 2 instead of 3 at multiplier=3,input=1, while mechanismResponder answers the declared variations and receives same-object Grounds. This is an operational understanding/variation-answer capability selected by the application, not a cognitive definition or universal standard of understanding.", + "special_limits": [ + "Application-defined all-multiplier variation-answer criterion; not an unrestricted cognitive claim.", + "Positive result uses the mechanism function; negative result fixes same Process and ExplanationContract but fails at (3,1)." + ] + }, + { + "target": "T16", + "case": "own_capability_assessment", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.ownCapability012", + "file": "CoreReader/Adopted.lean", + "line": 474, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved for the explicitly declared application capability UnderstandingApplication012: the same explained doubling process must also answer all multiplier/input variations using the actual multiplication mechanism. Identical output and ExplanationContract no longer suffice: the fixed-double answer gives 2 instead of 3 at multiplier=3,input=1, while mechanismResponder answers the declared variations and receives same-object Grounds. This is an operational understanding/variation-answer capability selected by the application, not a cognitive definition or universal standard of understanding.", + "special_limits": [] + }, + { + "target": "T17", + "case": "reliable_opaque_generator", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.outputNotExplanation", + "file": "CoreReader/Evidence.lean", + "line": 684, + "axioms": "[propext]" + } + ], + "interpretation": "Reliable double output with explanation = none refutes the stronger declared explanation contract; repeated item counts do not add an unavailable operation. This establishes limits on the represented output/explanation capability, not a cognitive account of human or agent understanding.", + "special_limits": [] + }, + { + "target": "T17", + "case": "high_count_no_stronger_capability", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.inventoryCases012", + "file": "CoreReader/Adopted.lean", + "line": 667, + "axioms": "[propext, Quot.sound.{u}]" + }, + { + "name": "CoreReader.Agency.generationLimits", + "file": "CoreReader/Agency.lean", + "line": 194, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "Reliable double output with explanation = none refutes the stronger declared explanation contract; repeated item counts do not add an unavailable operation. This establishes limits on the represented output/explanation capability, not a cognitive account of human or agent understanding.", + "special_limits": [] + }, + { + "target": "T17", + "case": "externally_articulated_no_introspection", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Evidence.externalAssessment", + "file": "CoreReader/Evidence.lean", + "line": 704, + "axioms": "[propext]" + } + ], + "interpretation": "Reliable double output with explanation = none refutes the stronger declared explanation contract; repeated item counts do not add an unavailable operation. This establishes limits on the represented output/explanation capability, not a cognitive account of human or agent understanding.", + "special_limits": [] + }, + { + "target": "T18", + "case": "named_only_rejected", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.allStatusOnly012", + "file": "CoreReader/Adopted.lean", + "line": 733, + "axioms": "[propext]" + } + ], + "interpretation": "JustifiedChoice combines feasibility with a valued method-content reason; status-only reasons fail by definition as the additional adopted evaluative commitment. Conventional identity remains eligible, internal explanation/applicability/simplicity/procedure reasons are admissible, and the current philosophy review is assessed by actual output reasons. No optimality or all-reasons-valid theorem is claimed.", + "special_limits": [] + }, + { + "target": "T18", + "case": "conventional_grounded_priority", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Choice.conventionWithReason", + "file": "CoreReader/Choice.lean", + "line": 108, + "axioms": "[propext]" + } + ], + "interpretation": "JustifiedChoice combines feasibility with a valued method-content reason; status-only reasons fail by definition as the additional adopted evaluative commitment. Conventional identity remains eligible, internal explanation/applicability/simplicity/procedure reasons are admissible, and the current philosophy review is assessed by actual output reasons. No optimality or all-reasons-valid theorem is claimed.", + "special_limits": [] + }, + { + "target": "T18", + "case": "method_internal_reason", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Choice.internalReasons", + "file": "CoreReader/Choice.lean", + "line": 151, + "axioms": "[]" + }, + { + "name": "CoreReader.Adopted.internalReasonDistinguishes012", + "file": "CoreReader/Adopted.lean", + "line": 657, + "axioms": "[]" + } + ], + "interpretation": "JustifiedChoice combines feasibility with a valued method-content reason; status-only reasons fail by definition as the additional adopted evaluative commitment. Conventional identity remains eligible, internal explanation/applicability/simplicity/procedure reasons are admissible, and the current philosophy review is assessed by actual output reasons. No optimality or all-reasons-valid theorem is claimed.", + "special_limits": [] + }, + { + "target": "T18", + "case": "own_philosophy_status_only", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.ownPhilosophyStatus012", + "file": "CoreReader/Adopted.lean", + "line": 690, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "JustifiedChoice combines feasibility with a valued method-content reason; status-only reasons fail by definition as the additional adopted evaluative commitment. Conventional identity remains eligible, internal explanation/applicability/simplicity/procedure reasons are admissible, and the current philosophy review is assessed by actual output reasons. No optimality or all-reasons-valid theorem is claimed.", + "special_limits": [] + }, + { + "target": "T19", + "case": "single_feasible_conventional", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Choice.singleFeasible", + "file": "CoreReader/Choice.lean", + "line": 121, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "A single feasible conventional choice, unequal outputs, equal local but different global behavior, and a distinguishing internal explanation meet the requested cases. The additional-choice example distinguishes accurate general assessment of non-entailment from the separate priority norm; this is deliberately the limited general-assessment relation in the target, not all Grounds duties.", + "special_limits": [] + }, + { + "target": "T19", + "case": "internal_reason_distinguishes", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Adopted.internalReasonDistinguishes012", + "file": "CoreReader/Adopted.lean", + "line": 657, + "axioms": "[]" + } + ], + "interpretation": "A single feasible conventional choice, unequal outputs, equal local but different global behavior, and a distinguishing internal explanation meet the requested cases. The additional-choice example distinguishes accurate general assessment of non-entailment from the separate priority norm; this is deliberately the limited general-assessment relation in the target, not all Grounds duties.", + "special_limits": [] + }, + { + "target": "T19", + "case": "unequal_open_options", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Choice.openNotEquivalent", + "file": "CoreReader/Choice.lean", + "line": 162, + "axioms": "[propext]" + } + ], + "interpretation": "A single feasible conventional choice, unequal outputs, equal local but different global behavior, and a distinguishing internal explanation meet the requested cases. The additional-choice example distinguishes accurate general assessment of non-entailment from the separate priority norm; this is deliberately the limited general-assessment relation in the target, not all Grounds duties.", + "special_limits": [] + }, + { + "target": "T19", + "case": "local_equal_global_difference", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Choice.localNotGlobal", + "file": "CoreReader/Choice.lean", + "line": 132, + "axioms": "[]" + } + ], + "interpretation": "A single feasible conventional choice, unequal outputs, equal local but different global behavior, and a distinguishing internal explanation meet the requested cases. The additional-choice example distinguishes accurate general assessment of non-entailment from the separate priority norm; this is deliberately the limited general-assessment relation in the target, not all Grounds duties.", + "special_limits": [] + }, + { + "target": "T19", + "case": "added_choice_not_from_general_assessment", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Choice.generalGroundsNotChoice", + "file": "CoreReader/Choice.lean", + "line": 257, + "axioms": "[propext]" + } + ], + "interpretation": "A single feasible conventional choice, unequal outputs, equal local but different global behavior, and a distinguishing internal explanation meet the requested cases. The additional-choice example distinguishes accurate general assessment of non-entailment from the separate priority norm; this is deliberately the limited general-assessment relation in the target, not all Grounds duties.", + "special_limits": [] + }, + { + "target": "T20", + "case": "own_grounds_articulable", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedMutualApplication", + "file": "CoreReader/Engineering/Integration.lean", + "line": 420, + "axioms": "[propext]" + }, + { + "name": "CoreReader.Engineering.governanceGrounded", + "file": "CoreReader/Engineering/Values.lean", + "line": 137, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved. The theorem now explicitly concludes the full normative-content membership, grounds for every held claim, and consistencySpecification for the same expanded ownTheory. It remains a legitimate projection of Inherited, not mutual logical derivation from fewer premises. Actual self-rule generation/assessment objects are included and checked; original empirical/inferential/value tasks remain separate.", + "special_limits": [] + }, + { + "target": "T20", + "case": "own_capability_supported", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedMutualApplication", + "file": "CoreReader/Engineering/Integration.lean", + "line": 420, + "axioms": "[propext]" + }, + { + "name": "CoreReader.Engineering.engineeringCapabilityGrounded", + "file": "CoreReader/Engineering/Integration.lean", + "line": 63, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved. The theorem now explicitly concludes the full normative-content membership, grounds for every held claim, and consistencySpecification for the same expanded ownTheory. It remains a legitimate projection of Inherited, not mutual logical derivation from fewer premises. Actual self-rule generation/assessment objects are included and checked; original empirical/inferential/value tasks remain separate.", + "special_limits": [] + }, + { + "target": "T20", + "case": "own_choice_not_status_only", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedMutualApplication", + "file": "CoreReader/Engineering/Integration.lean", + "line": 420, + "axioms": "[propext]" + }, + { + "name": "CoreReader.Engineering.implementationReasoned", + "file": "CoreReader/Engineering/Integration.lean", + "line": 41, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved. The theorem now explicitly concludes the full normative-content membership, grounds for every held claim, and consistencySpecification for the same expanded ownTheory. It remains a legitimate projection of Inherited, not mutual logical derivation from fewer premises. Actual self-rule generation/assessment objects are included and checked; original empirical/inferential/value tasks remain separate.", + "special_limits": [] + }, + { + "target": "T20", + "case": "relevant_self_application", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedMutualCases", + "file": "CoreReader/Engineering/Integration.lean", + "line": 442, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + }, + { + "name": "CoreReader.Engineering.ownRuleContentVariation", + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 204, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved. The theorem now explicitly concludes the full normative-content membership, grounds for every held claim, and consistencySpecification for the same expanded ownTheory. It remains a legitimate projection of Inherited, not mutual logical derivation from fewer premises. Actual self-rule generation/assessment objects are included and checked; original empirical/inferential/value tasks remain separate.", + "special_limits": [ + "The empty-tested-list criticism concerns the sample-aware local assessmentRuleTest contract; it is not a philosophical demand for empirical samples in every judgment." + ] + }, + { + "target": "T22", + "case": "successor_maintainer", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLifecycleCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 146, + "axioms": "[propext]" + } + ], + "interpretation": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established.", + "special_limits": [] + }, + { + "target": "T22", + "case": "agent_maintainer", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLifecycleCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 146, + "axioms": "[propext]" + } + ], + "interpretation": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established.", + "special_limits": [] + }, + { + "target": "T22", + "case": "continuing_labeled_temporary", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLifecycleCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 146, + "axioms": "[propext]" + } + ], + "interpretation": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established.", + "special_limits": [] + }, + { + "target": "T22", + "case": "genuinely_temporary", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLifecycleCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 146, + "axioms": "[propext]" + } + ], + "interpretation": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established.", + "special_limits": [] + }, + { + "target": "T22", + "case": "bounded_prototype", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLifecycleCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 146, + "axioms": "[propext]" + } + ], + "interpretation": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established.", + "special_limits": [] + }, + { + "target": "T22", + "case": "retiring_system", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLifecycleCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 146, + "axioms": "[propext]" + } + ], + "interpretation": "ActivityScope plus explicit maintainers, tools, knowledge and lifecycle fields represent the intended continuing engineering subject. Successor/agent examples are positive; temporary/prototype/retiring cases use actual bounded-run and zero-maintenance fields rather than their labels. Credibility of a real lifecycle forecast is assumed by the interpretation, not independently established.", + "special_limits": [] + }, + { + "target": "T23", + "case": "author_only_private_knowledge", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 159, + "axioms": "[propext]" + } + ], + "interpretation": "The original maintainer has privateLayout while the successor lacks it; explicit path prerequisite failure establishes the contrast. The continuing activity remains nonbounded despite its temporary label. The passive artifact returns inputs and has no propose action by its actual definition, providing one counterexample rather than a law of all artifacts.", + "special_limits": [] + }, + { + "target": "T23", + "case": "successor_missing_path", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 159, + "axioms": "[propext]" + } + ], + "interpretation": "The original maintainer has privateLayout while the successor lacks it; explicit path prerequisite failure establishes the contrast. The continuing activity remains nonbounded despite its temporary label. The passive artifact returns inputs and has no propose action by its actual definition, providing one counterexample rather than a law of all artifacts.", + "special_limits": [] + }, + { + "target": "T23", + "case": "false_temporary_label", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 159, + "axioms": "[propext]" + } + ], + "interpretation": "The original maintainer has privateLayout while the successor lacks it; explicit path prerequisite failure establishes the contrast. The continuing activity remains nonbounded despite its temporary label. The passive artifact returns inputs and has no propose action by its actual definition, providing one counterexample rather than a law of all artifacts.", + "special_limits": [] + }, + { + "target": "T23", + "case": "passive_artifact", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.subjectLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 159, + "axioms": "[propext]" + } + ], + "interpretation": "The original maintainer has privateLayout while the successor lacks it; explicit path prerequisite failure establishes the contrast. The continuing activity remains nonbounded despite its temporary label. The passive artifact returns inputs and has no propose action by its actual definition, providing one counterexample rather than a law of all artifacts.", + "special_limits": [] + }, + { + "target": "T24", + "case": "ordinary_priority", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.priorityConditionsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 367, + "axioms": "[propext]" + } + ], + "interpretation": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "special_limits": [] + }, + { + "target": "T24", + "case": "missing_behavior", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.unmetRequirementsBlockPriority", + "file": "CoreReader/Engineering/Domain.lean", + "line": 353, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "special_limits": [] + }, + { + "target": "T24", + "case": "missing_safety", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.unmetRequirementsBlockPriority", + "file": "CoreReader/Engineering/Domain.lean", + "line": 353, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "special_limits": [] + }, + { + "target": "T24", + "case": "missing_performance", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.unmetRequirementsBlockPriority", + "file": "CoreReader/Engineering/Domain.lean", + "line": 353, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "special_limits": [] + }, + { + "target": "T24", + "case": "missing_other_necessary", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.unmetRequirementsBlockPriority", + "file": "CoreReader/Engineering/Domain.lean", + "line": 353, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "special_limits": [] + }, + { + "target": "T24", + "case": "concrete_cost_override", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.priorityConditionsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 367, + "axioms": "[propext]" + } + ], + "interpretation": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "special_limits": [] + }, + { + "target": "T24", + "case": "unexplained_departure", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.priorityConditionsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 367, + "axioms": "[propext]" + } + ], + "interpretation": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "special_limits": [] + }, + { + "target": "T24", + "case": "no_extensibility_maximum", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 394, + "axioms": "[propext]" + } + ], + "interpretation": "EvolutionPriority is an explicit defeasible norm over the fixed candidate/change comparison: when lifecycle/scope, both profiles, credible revision and capability/work/complexity conditions hold, choose evolvable or identify a cost threat. Four profile failures block the antecedent; selected burdens produce qualified departures. The numerical data are local model parameters, not universal exchange rates.", + "special_limits": [] + }, + { + "target": "T25", + "case": "applicable_choose_evolution", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.priorityWhenApplicable", + "file": "CoreReader/Engineering/Domain.lean", + "line": 337, + "axioms": "[]" + }, + { + "name": "CoreReader.Engineering.priorityChoices", + "file": "CoreReader/Engineering/Domain.lean", + "line": 384, + "axioms": "[propext]" + } + ], + "interpretation": "The theorem explicitly assumes the adopted EvolutionPriority rule, applicability and no departure; it extracts the chosen evolvable value and substitutes into the supplied complexity comparison. This matches the target's normative-premise requirement. Concrete choices show simple violates the rule without a threat and can pass with the accounted threat.", + "special_limits": [] + }, + { + "target": "T25", + "case": "applicable_choose_simple_violates_domain", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.currentSimpleViolates", + "file": "CoreReader/Engineering/Domain.lean", + "line": 345, + "axioms": "[propext]" + } + ], + "interpretation": "The theorem explicitly assumes the adopted EvolutionPriority rule, applicability and no departure; it extracts the chosen evolvable value and substitutes into the supplied complexity comparison. This matches the target's normative-premise requirement. Concrete choices show simple violates the rule without a threat and can pass with the accounted threat.", + "special_limits": [] + }, + { + "target": "T25", + "case": "threat_allows_departure_with_account", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.priorityChoices", + "file": "CoreReader/Engineering/Domain.lean", + "line": 384, + "axioms": "[propext]" + } + ], + "interpretation": "The theorem explicitly assumes the adopted EvolutionPriority rule, applicability and no departure; it extracts the chosen evolvable value and substitutes into the supplied complexity comparison. This matches the target's normative-premise requirement. Concrete choices show simple violates the rule without a threat and can pass with the accounted threat.", + "special_limits": [] + }, + { + "target": "T26", + "case": "committed_plan_one_implementation", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 212, + "axioms": "[]" + }, + { + "name": "CoreReader.Engineering.credibilityLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 394, + "axioms": "[propext]" + } + ], + "interpretation": "The generic Ground interface does not restrict ground categories. Concrete plans identify a positive release and direction; knowledge/history cases contain a service/mechanism or repeated direction list, and forecast revision changes supported directions. The adapter only checks designated strings/list content, so actual relevance of a mechanism/history is a stipulated interpretation. It must not be reported as independent validation of arbitrary knowledge records.", + "special_limits": [] + }, + { + "target": "T26", + "case": "domain_knowledge", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 212, + "axioms": "[]" + } + ], + "interpretation": "The generic Ground interface does not restrict ground categories. Concrete plans identify a positive release and direction; knowledge/history cases contain a service/mechanism or repeated direction list, and forecast revision changes supported directions. The adapter only checks designated strings/list content, so actual relevance of a mechanism/history is a stipulated interpretation. It must not be reported as independent validation of arbitrary knowledge records.", + "special_limits": [] + }, + { + "target": "T26", + "case": "applicable_history", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 212, + "axioms": "[]" + } + ], + "interpretation": "The generic Ground interface does not restrict ground categories. Concrete plans identify a positive release and direction; knowledge/history cases contain a service/mechanism or repeated direction list, and forecast revision changes supported directions. The adapter only checks designated strings/list content, so actual relevance of a mechanism/history is a stipulated interpretation. It must not be reported as independent validation of arbitrary knowledge records.", + "special_limits": [] + }, + { + "target": "T26", + "case": "conceivable_only", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 212, + "axioms": "[]" + } + ], + "interpretation": "The generic Ground interface does not restrict ground categories. Concrete plans identify a positive release and direction; knowledge/history cases contain a service/mechanism or repeated direction list, and forecast revision changes supported directions. The adapter only checks designated strings/list content, so actual relevance of a mechanism/history is a stipulated interpretation. It must not be reported as independent validation of arbitrary knowledge records.", + "special_limits": [] + }, + { + "target": "T26", + "case": "revised_forecast", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 212, + "axioms": "[]" + } + ], + "interpretation": "The generic Ground interface does not restrict ground categories. Concrete plans identify a positive release and direction; knowledge/history cases contain a service/mechanism or repeated direction list, and forecast revision changes supported directions. The adapter only checks designated strings/list content, so actual relevance of a mechanism/history is a stipulated interpretation. It must not be reported as independent validation of arbitrary knowledge records.", + "special_limits": [] + }, + { + "target": "T27", + "case": "one_implementation_credible", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 394, + "axioms": "[propext]" + } + ], + "interpretation": "One implemented variant coexists with credible direction; unsupported imagined changes do not warrant the defined investment; evolvable supports nine registered directions while maximal supports ten but is not the priority. Different per-burden bounds and work comparisons demonstrate a selective example, not a mathematical impossibility of numerical tradeoffs.", + "special_limits": [] + }, + { + "target": "T27", + "case": "imagined_unwarranted", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 394, + "axioms": "[propext]" + } + ], + "interpretation": "One implemented variant coexists with credible direction; unsupported imagined changes do not warrant the defined investment; evolvable supports nine registered directions while maximal supports ten but is not the priority. Different per-burden bounds and work comparisons demonstrate a selective example, not a mathematical impossibility of numerical tradeoffs.", + "special_limits": [] + }, + { + "target": "T27", + "case": "selective_evolution", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 394, + "axioms": "[propext]" + } + ], + "interpretation": "One implemented variant coexists with credible direction; unsupported imagined changes do not warrant the defined investment; evolvable supports nine registered directions while maximal supports ten but is not the priority. Different per-burden bounds and work comparisons demonstrate a selective example, not a mathematical impossibility of numerical tradeoffs.", + "special_limits": [] + }, + { + "target": "T27", + "case": "qualitative_tradeoff", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.credibilityLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 394, + "axioms": "[propext]" + } + ], + "interpretation": "One implemented variant coexists with credible direction; unsupported imagined changes do not warrant the defined investment; evolvable supports nine registered directions while maximal supports ten but is not the priority. Different per-burden bounds and work comparisons demonstrate a selective example, not a mathematical impossibility of numerical tradeoffs.", + "special_limits": [] + }, + { + "target": "T28", + "case": "understanding_threat", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.costCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "axioms": "[propext]" + } + ], + "interpretation": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "special_limits": [] + }, + { + "target": "T28", + "case": "construction_threat", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.costCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "axioms": "[propext]" + } + ], + "interpretation": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "special_limits": [] + }, + { + "target": "T28", + "case": "diagnosis_threat", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.costCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "axioms": "[propext]" + } + ], + "interpretation": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "special_limits": [] + }, + { + "target": "T28", + "case": "verification_threat", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.costCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "axioms": "[propext]" + } + ], + "interpretation": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "special_limits": [] + }, + { + "target": "T28", + "case": "coordination_threat", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.costCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "axioms": "[propext]" + } + ], + "interpretation": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "special_limits": [] + }, + { + "target": "T28", + "case": "operation_threat", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.costCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "axioms": "[propext]" + } + ], + "interpretation": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "special_limits": [] + }, + { + "target": "T28", + "case": "migration_threat", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.costCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "axioms": "[propext]" + } + ], + "interpretation": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "special_limits": [] + }, + { + "target": "T28", + "case": "unsupported_cost_excuse", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.costCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 410, + "axioms": "[propext]" + } + ], + "interpretation": "Every named burden can trigger a departure when its candidate-specific cost exceeds a concrete objective capacity and the baseline; merely selecting a burden without a threat fails. This gives a substantive inequality reason rather than a free exception flag. Objective names and capacities remain application assumptions.", + "special_limits": [] + }, + { + "target": "T29", + "case": "addition", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "replacement", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "deletion", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "withdrawal", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "redrawing", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "migration", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "independent", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "coordinated", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "preserve_obligation", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T29", + "case": "revise_obligation", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 569, + "axioms": "[propext]" + } + ], + "interpretation": "Distinct software-state transformations and knowledge/tool paths cover additions, replacement, deletion, withdrawal, redrawing and migration; other String keeps the include-list open. EvolutionClaim binds maintainer/direction and contract treatment, and independent/coordinated paths differ. The state fields and behavior/path functions are assigned rather than derived by an actual editing interpreter.", + "special_limits": [] + }, + { + "target": "T30", + "case": "easy_add_hard_exit", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionDimensionsLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 585, + "axioms": "[propext]" + } + ], + "interpretation": "Addition can cost two while withdrawal/revision costs seventeen; coordinated work exceeds independent work; migration can remain expensive while evolution priority holds. Equal addition cost directly refutes universal strict improvement over all Change values.", + "special_limits": [] + }, + { + "target": "T30", + "case": "independent_easy_coordinated_hard", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionDimensionsLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 585, + "axioms": "[propext]" + } + ], + "interpretation": "Addition can cost two while withdrawal/revision costs seventeen; coordinated work exceeds independent work; migration can remain expensive while evolution priority holds. Equal addition cost directly refutes universal strict improvement over all Change values.", + "special_limits": [] + }, + { + "target": "T30", + "case": "some_change_expensive_permitted", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.evolutionDimensionsLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 585, + "axioms": "[propext]" + } + ], + "interpretation": "Addition can cost two while withdrawal/revision costs seventeen; coordinated work exceeds independent work; migration can remain expensive while evolution priority holds. Equal addition cost directly refutes universal strict improvement over all Change values.", + "special_limits": [] + }, + { + "target": "T31", + "case": "contract_and_work_comparison", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.structuralCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 733, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved as a finite intended-change case. actualCrossBoundaryObligation links the registered edge caller 2/callee 1 to a real callee compiler edit, a caller contractRunner/publicContract step and finite observed order preservation. Removing the caller check leaves the crossing true but rejects the obligation; changing the callee to 7 loses the crossing; replacing output with sortedUnique fails the contract. No network/runtime semantics or universal completeness of every edge is claimed.", + "special_limits": [] + }, + { + "target": "T31", + "case": "propagation_relation", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.structuralCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 733, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved as a finite intended-change case. actualCrossBoundaryObligation links the registered edge caller 2/callee 1 to a real callee compiler edit, a caller contractRunner/publicContract step and finite observed order preservation. Removing the caller check leaves the crossing true but rejects the obligation; changing the callee to 7 loses the crossing; replacing output with sortedUnique fails the contract. No network/runtime semantics or universal completeness of every edge is claimed.", + "special_limits": [] + }, + { + "target": "T31", + "case": "cross_boundary_obligation", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.actualCrossBoundaryObligation", + "file": "CoreReader/Engineering/Domain.lean", + "line": 720, + "axioms": "[]" + } + ], + "interpretation": "Resolved as a finite intended-change case. actualCrossBoundaryObligation links the registered edge caller 2/callee 1 to a real callee compiler edit, a caller contractRunner/publicContract step and finite observed order preservation. Removing the caller check leaves the crossing true but rejects the obligation; changing the callee to 7 loses the crossing; replacing output with sortedUnique fails the contract. No network/runtime semantics or universal completeness of every edge is claimed.", + "special_limits": [ + "Fixed caller/callee/contract family and finite observation domain; no universal runtime dependency semantics." + ] + }, + { + "target": "T31", + "case": "fixed_assumption", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.structuralCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 733, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved as a finite intended-change case. actualCrossBoundaryObligation links the registered edge caller 2/callee 1 to a real callee compiler edit, a caller contractRunner/publicContract step and finite observed order preservation. Removing the caller check leaves the crossing true but rejects the obligation; changing the callee to 7 loses the crossing; replacing output with sortedUnique fails the contract. No network/runtime semantics or universal completeness of every edge is claimed.", + "special_limits": [] + }, + { + "target": "T31", + "case": "withdrawal_cost", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.structuralCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 733, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved as a finite intended-change case. actualCrossBoundaryObligation links the registered edge caller 2/callee 1 to a real callee compiler edit, a caller contractRunner/publicContract step and finite observed order preservation. Removing the caller check leaves the crossing true but rejects the obligation; changing the callee to 7 loses the crossing; replacing output with sortedUnique fails the contract. No network/runtime semantics or universal completeness of every edge is claimed.", + "special_limits": [] + }, + { + "target": "T32", + "case": "same_shape_broken_order", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.structureNotCapability", + "file": "CoreReader/Engineering/Domain.lean", + "line": 793, + "axioms": "[propext]" + } + ], + "interpretation": "The frozen delta now supplies the exact new_boundary_same_work case missing from the initial code: an actual added boundary and changed path with identical units/work and remaining successor prerequisite failure. The original increased-work example is retained. These and the signature/module/named-pattern examples meet the finite negative target, without proving real-world overhead or boundary execution semantics.", + "special_limits": [] + }, + { + "target": "T32", + "case": "many_modules_shared_obligation", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.structureNotCapability", + "file": "CoreReader/Engineering/Domain.lean", + "line": 793, + "axioms": "[propext]" + } + ], + "interpretation": "The frozen delta now supplies the exact new_boundary_same_work case missing from the initial code: an actual added boundary and changed path with identical units/work and remaining successor prerequisite failure. The original increased-work example is retained. These and the signature/module/named-pattern examples meet the finite negative target, without proving real-world overhead or boundary execution semantics.", + "special_limits": [] + }, + { + "target": "T32", + "case": "named_pattern_no_change_path", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.structureNotCapability", + "file": "CoreReader/Engineering/Domain.lean", + "line": 793, + "axioms": "[propext]" + } + ], + "interpretation": "The frozen delta now supplies the exact new_boundary_same_work case missing from the initial code: an actual added boundary and changed path with identical units/work and remaining successor prerequisite failure. The original increased-work example is retained. These and the signature/module/named-pattern examples meet the finite negative target, without proving real-world overhead or boundary execution semantics.", + "special_limits": [] + }, + { + "target": "T32", + "case": "new_boundary_same_work", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.structureNotCapability", + "file": "CoreReader/Engineering/Domain.lean", + "line": 793, + "axioms": "[propext]" + } + ], + "interpretation": "The frozen delta now supplies the exact new_boundary_same_work case missing from the initial code: an actual added boundary and changed path with identical units/work and remaining successor prerequisite failure. The original increased-work example is retained. These and the signature/module/named-pattern examples meet the finite negative target, without proving real-world overhead or boundary execution semantics.", + "special_limits": [] + }, + { + "target": "T33", + "case": "preserve_identified_contract", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.contractCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 843, + "axioms": "[]" + } + ], + "interpretation": "ContractChangeAccount separates finite scoped equality from deliberate revision with changed order/retry obligations and affected-party coverage. Missing operator/incorrect old limits fail; [99] demonstrates an intentionally out-of-scope historical difference; changing procedure text remains allowed. Actual notification, completeness of parties and all-input equivalence are not modeled.", + "special_limits": [] + }, + { + "target": "T33", + "case": "deliberate_revision_with_account", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.contractCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 843, + "axioms": "[]" + } + ], + "interpretation": "ContractChangeAccount separates finite scoped equality from deliberate revision with changed order/retry obligations and affected-party coverage. Missing operator/incorrect old limits fail; [99] demonstrates an intentionally out-of-scope historical difference; changing procedure text remains allowed. Actual notification, completeness of parties and all-input equivalence are not modeled.", + "special_limits": [] + }, + { + "target": "T33", + "case": "revision_missing_parties", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.contractCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 843, + "axioms": "[]" + } + ], + "interpretation": "ContractChangeAccount separates finite scoped equality from deliberate revision with changed order/retry obligations and affected-party coverage. Missing operator/incorrect old limits fail; [99] demonstrates an intentionally out-of-scope historical difference; changing procedure text remains allowed. Actual notification, completeness of parties and all-input equivalence are not modeled.", + "special_limits": [] + }, + { + "target": "T33", + "case": "retired_historical_behavior", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.contractCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 843, + "axioms": "[]" + } + ], + "interpretation": "ContractChangeAccount separates finite scoped equality from deliberate revision with changed order/retry obligations and affected-party coverage. Missing operator/incorrect old limits fail; [99] demonstrates an intentionally out-of-scope historical difference; changing procedure text remains allowed. Actual notification, completeness of parties and all-input equivalence are not modeled.", + "special_limits": [] + }, + { + "target": "T33", + "case": "alternative_procedure", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.contractCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 843, + "axioms": "[]" + } + ], + "interpretation": "ContractChangeAccount separates finite scoped equality from deliberate revision with changed order/retry obligations and affected-party coverage. Missing operator/incorrect old limits fail; [99] demonstrates an intentionally out-of-scope historical difference; changing procedure text remains allowed. Actual notification, completeness of parties and all-input equivalence are not modeled.", + "special_limits": [] + }, + { + "target": "T34", + "case": "order_preserving_refactor", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.contractPreservation", + "file": "CoreReader/Engineering/Domain.lean", + "line": 822, + "axioms": "[]" + }, + { + "name": "CoreReader.Engineering.contractDistinctions", + "file": "CoreReader/Engineering/Domain.lean", + "line": 853, + "axioms": "[]" + } + ], + "interpretation": "contractPreservation returns the supplied universal in-scope equality proof, rather than deriving it from finite tests. changedObservationNotPreserved gives the counterexample implication; contractRevisionObligations eliminates the failed preservation branch of the assumed account. Finite order/retry cases illustrate the distinction. This is the correct conditional reading of the target, not an empirical proof from test success.", + "special_limits": [] + }, + { + "target": "T34", + "case": "sorted_order_revision", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.changedObservationNotPreserved", + "file": "CoreReader/Engineering/Domain.lean", + "line": 826, + "axioms": "[]" + }, + { + "name": "CoreReader.Engineering.contractDistinctions", + "file": "CoreReader/Engineering/Domain.lean", + "line": 853, + "axioms": "[]" + } + ], + "interpretation": "contractPreservation returns the supplied universal in-scope equality proof, rather than deriving it from finite tests. changedObservationNotPreserved gives the counterexample implication; contractRevisionObligations eliminates the failed preservation branch of the assumed account. Finite order/retry cases illustrate the distinction. This is the correct conditional reading of the target, not an empirical proof from test success.", + "special_limits": [] + }, + { + "target": "T34", + "case": "changed_failure_obligation", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.contractRevisionObligations", + "file": "CoreReader/Engineering/Domain.lean", + "line": 832, + "axioms": "[]" + }, + { + "name": "CoreReader.Engineering.contractDistinctions", + "file": "CoreReader/Engineering/Domain.lean", + "line": 853, + "axioms": "[]" + } + ], + "interpretation": "contractPreservation returns the supplied universal in-scope equality proof, rather than deriving it from finite tests. changedObservationNotPreserved gives the counterexample implication; contractRevisionObligations eliminates the failed preservation branch of the assumed account. Finite order/retry cases illustrate the distinction. This is the correct conditional reading of the target, not an empirical proof from test success.", + "special_limits": [] + }, + { + "target": "T34", + "case": "outside_scope_difference", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.contractDistinctions", + "file": "CoreReader/Engineering/Domain.lean", + "line": 853, + "axioms": "[]" + } + ], + "interpretation": "contractPreservation returns the supplied universal in-scope equality proof, rather than deriving it from finite tests. changedObservationNotPreserved gives the counterexample implication; contractRevisionObligations eliminates the failed preservation branch of the assumed account. Finite order/retry cases illustrate the distinction. This is the correct conditional reading of the target, not an empirical proof from test success.", + "special_limits": [] + }, + { + "target": "T35", + "case": "revised_change_forecast", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.revisionCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 951, + "axioms": "[propext]" + } + ], + "interpretation": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign.", + "special_limits": [] + }, + { + "target": "T35", + "case": "changed_maintainers", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.revisionCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 951, + "axioms": "[propext]" + } + ], + "interpretation": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign.", + "special_limits": [] + }, + { + "target": "T35", + "case": "changed_cost", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.revisionCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 951, + "axioms": "[propext]" + } + ], + "interpretation": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign.", + "special_limits": [] + }, + { + "target": "T35", + "case": "changed_objective", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.revisionCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 951, + "axioms": "[propext]" + } + ], + "interpretation": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign.", + "special_limits": [] + }, + { + "target": "T35", + "case": "failed_prediction_preserved", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.historicalTamperingRejected", + "file": "CoreReader/Engineering/Domain.lean", + "line": 980, + "axioms": "[]" + }, + { + "name": "CoreReader.Engineering.failedHistoryNotRewritten", + "file": "CoreReader/Engineering/Domain.lean", + "line": 924, + "axioms": "[propext]" + } + ], + "interpretation": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign.", + "special_limits": [] + }, + { + "target": "T35", + "case": "justified_retention", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.revisionCases", + "file": "CoreReader/Engineering/Domain.lean", + "line": 951, + "axioms": "[propext]" + } + ], + "interpretation": "The account binds old/new software/state/prediction/observation, increasing time, changed grounds when choice differs, and honest failure reporting. Concrete forecast, maintainer, cost and capacity changes are present. Retention is permitted by the adapter's unsupported-alternative or threat conditions. The account records necessary identity/acknowledgment conditions, not sufficient substantive justification of every possible redesign.", + "special_limits": [] + }, + { + "target": "T36", + "case": "past_failure_not_rewritten", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.historicalTamperingRejected", + "file": "CoreReader/Engineering/Domain.lean", + "line": 980, + "axioms": "[]" + }, + { + "name": "CoreReader.Engineering.failedHistoryNotRewritten", + "file": "CoreReader/Engineering/Domain.lean", + "line": 924, + "axioms": "[propext]" + } + ], + "interpretation": "Prior finite no-retroactive-success/consensus/success examples are retained. A fresh same-object probe proves revisionFor sharedContext evolvable retains the old/current design choice while selfModel evolvable satisfies reflection; this makes the open-stable example explicit without turning all stability into a duty.", + "special_limits": [] + }, + { + "target": "T36", + "case": "agreement_with_bad_case", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.revisionLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 993, + "axioms": "[propext]" + } + ], + "interpretation": "Prior finite no-retroactive-success/consensus/success examples are retained. A fresh same-object probe proves revisionFor sharedContext evolvable retains the old/current design choice while selfModel evolvable satisfies reflection; this makes the open-stable example explicit without turning all stability into a duty.", + "special_limits": [] + }, + { + "target": "T36", + "case": "local_success_global_failure", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.revisionLimits", + "file": "CoreReader/Engineering/Domain.lean", + "line": 993, + "axioms": "[propext]" + } + ], + "interpretation": "Prior finite no-retroactive-success/consensus/success examples are retained. A fresh same-object probe proves revisionFor sharedContext evolvable retains the old/current design choice while selfModel evolvable satisfies reflection; this makes the open-stable example explicit without turning all stability into a duty.", + "special_limits": [] + }, + { + "target": "T36", + "case": "open_stable_design", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.revisionContextIdentity", + "file": "CoreReader/Engineering/Domain.lean", + "line": 1020, + "axioms": "[propext]" + }, + { + "name": "CoreReader.Engineering.currentSelfApplication", + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 161, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Prior finite no-retroactive-success/consensus/success examples are retained. A fresh same-object probe proves revisionFor sharedContext evolvable retains the old/current design choice while selfModel evolvable satisfies reflection; this makes the open-stable example explicit without turning all stability into a duty.", + "special_limits": [] + }, + { + "target": "T37", + "case": "priority_self_assessment", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.priorityRemainsReflexive", + "file": "CoreReader/Engineering/Integration.lean", + "line": 467, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + }, + { + "name": "CoreReader.Engineering.priorityReflexiveCases", + "file": "CoreReader/Engineering/Integration.lean", + "line": 493, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Resolved in the same fixed shared context. priorityValueMeaning proves candidate-by-candidate equivalence between the adopted evolvable selection commitment and actual EvolutionPriority; priorityGrounds transports value support through that explicit equality while preserving the value task. The theorem now returns that exact priority claim's Grounds, domain-content membership and complete-theory consistency, in addition to reflection. The equivalence depends on current applicability/no-departure and must not be generalized to other contexts.", + "special_limits": [] + }, + { + "target": "T37", + "case": "method_self_criticism", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.actualSelfCriticism", + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 170, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + }, + { + "name": "CoreReader.Engineering.ownRuleContentVariation", + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 204, + "axioms": "[propext]" + } + ], + "interpretation": "Resolved in the same fixed shared context. priorityValueMeaning proves candidate-by-candidate equivalence between the adopted evolvable selection commitment and actual EvolutionPriority; priorityGrounds transports value support through that explicit equality while preserving the value task. The theorem now returns that exact priority claim's Grounds, domain-content membership and complete-theory consistency, in addition to reflection. The equivalence depends on current applicability/no-departure and must not be generalized to other contexts.", + "special_limits": [ + "The empty-tested-list criticism concerns the sample-aware local assessmentRuleTest contract; it is not a philosophical demand for empirical samples in every judgment." + ] + }, + { + "target": "T37", + "case": "no_selfproof_from_success", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.priorityReflexiveCases", + "file": "CoreReader/Engineering/Integration.lean", + "line": 493, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + }, + { + "name": "CoreReader.Engineering.proposedRuleRevision", + "file": "CoreReader/Engineering/SelfApplication.lean", + "line": 218, + "axioms": "[propext, Quot.sound.{u}]" + } + ], + "interpretation": "Resolved in the same fixed shared context. priorityValueMeaning proves candidate-by-candidate equivalence between the adopted evolvable selection commitment and actual EvolutionPriority; priorityGrounds transports value support through that explicit equality while preserving the value task. The theorem now returns that exact priority claim's Grounds, domain-content membership and complete-theory consistency, in addition to reflection. The equivalence depends on current applicability/no-departure and must not be generalized to other contexts.", + "special_limits": [ + "The empty-tested-list criticism concerns the sample-aware local assessmentRuleTest contract; it is not a philosophical demand for empirical samples in every judgment." + ] + }, + { + "target": "T38", + "case": "joint_all_inherited_and_domain", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.jointWitness", + "file": "CoreReader/Engineering/Integration.lean", + "line": 557, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Accepted as the requested bounded inhabitation witness after rechecking expanded Inherited and ownTheory, not merely its unchanged exterior theorem statement. The same evolvable candidate/context satisfies original necessary requirements, applicable priority/no threat, actual maintainer paths, full held fact/norm content, original support tasks and actual self-rule reflection. Source interpretation remains a revisable finite model; no empirical or philosophical universal correctness follows.", + "special_limits": [] + }, + { + "target": "T38", + "case": "same_context_identity", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.jointWitness", + "file": "CoreReader/Engineering/Integration.lean", + "line": 557, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Accepted as the requested bounded inhabitation witness after rechecking expanded Inherited and ownTheory, not merely its unchanged exterior theorem statement. The same evolvable candidate/context satisfies original necessary requirements, applicable priority/no threat, actual maintainer paths, full held fact/norm content, original support tasks and actual self-rule reflection. Source interpretation remains a revisable finite model; no empirical or philosophical universal correctness follows.", + "special_limits": [] + }, + { + "target": "T38", + "case": "nonempty_claims_and_principles", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.jointWitness", + "file": "CoreReader/Engineering/Integration.lean", + "line": 557, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + }, + { + "name": "CoreReader.Engineering.allNormativeContentHeld", + "file": "CoreReader/Engineering/Integration.lean", + "line": 293, + "axioms": "[propext]" + } + ], + "interpretation": "Accepted as the requested bounded inhabitation witness after rechecking expanded Inherited and ownTheory, not merely its unchanged exterior theorem statement. The same evolvable candidate/context satisfies original necessary requirements, applicable priority/no threat, actual maintainer paths, full held fact/norm content, original support tasks and actual self-rule reflection. Source interpretation remains a revisable finite model; no empirical or philosophical universal correctness follows.", + "special_limits": [] + }, + { + "target": "T38", + "case": "active_evolution_priority", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.jointWitness", + "file": "CoreReader/Engineering/Integration.lean", + "line": 557, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Accepted as the requested bounded inhabitation witness after rechecking expanded Inherited and ownTheory, not merely its unchanged exterior theorem statement. The same evolvable candidate/context satisfies original necessary requirements, applicable priority/no threat, actual maintainer paths, full held fact/norm content, original support tasks and actual self-rule reflection. Source interpretation remains a revisable finite model; no empirical or philosophical universal correctness follows.", + "special_limits": [] + }, + { + "target": "T38", + "case": "content_bearing_maintainer_change", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.jointWitness", + "file": "CoreReader/Engineering/Integration.lean", + "line": 557, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + }, + { + "name": "CoreReader.Engineering.actualCapabilityContrast", + "file": "CoreReader/Engineering/Integration.lean", + "line": 67, + "axioms": "[propext]" + } + ], + "interpretation": "Accepted as the requested bounded inhabitation witness after rechecking expanded Inherited and ownTheory, not merely its unchanged exterior theorem statement. The same evolvable candidate/context satisfies original necessary requirements, applicable priority/no threat, actual maintainer paths, full held fact/norm content, original support tasks and actual self-rule reflection. Source interpretation remains a revisable finite model; no empirical or philosophical universal correctness follows.", + "special_limits": [] + }, + { + "target": "T39", + "case": "all_inherited_applicable_domain_not_adopted", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedDoesNotEntailPriority", + "file": "CoreReader/Engineering/Integration.lean", + "line": 586, + "axioms": "[propext,\n Classical.choice.{u},\n Quot.sound.{u}]" + } + ], + "interpretation": "Accepted as the requested bounded non-entailment witness with every original strong branch preserved. The same continuing shared context has real encoded applicability/advantage and no lifecycle/cost escape; presentSimple adopts a separately grounded simplicity value and satisfies expanded inherited duties yet fails the extra priority. normApplies records adoption of the additional domain norm, not disappearance of its actual PriorityConditions. This distinction is central to the source's additional-value claim.", + "special_limits": [] + }, + { + "target": "T39", + "case": "no_temporary_escape", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedDoesNotEntailPriority", + "file": "CoreReader/Engineering/Integration.lean", + "line": 586, + "axioms": "[propext,\n Classical.choice.{u},\n Quot.sound.{u}]" + } + ], + "interpretation": "Accepted as the requested bounded non-entailment witness with every original strong branch preserved. The same continuing shared context has real encoded applicability/advantage and no lifecycle/cost escape; presentSimple adopts a separately grounded simplicity value and satisfies expanded inherited duties yet fails the extra priority. normApplies records adoption of the additional domain norm, not disappearance of its actual PriorityConditions. This distinction is central to the source's additional-value claim.", + "special_limits": [] + }, + { + "target": "T39", + "case": "no_cost_escape", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedDoesNotEntailPriority", + "file": "CoreReader/Engineering/Integration.lean", + "line": 586, + "axioms": "[propext,\n Classical.choice.{u},\n Quot.sound.{u}]" + } + ], + "interpretation": "Accepted as the requested bounded non-entailment witness with every original strong branch preserved. The same continuing shared context has real encoded applicability/advantage and no lifecycle/cost escape; presentSimple adopts a separately grounded simplicity value and satisfies expanded inherited duties yet fails the extra priority. normApplies records adoption of the additional domain norm, not disappearance of its actual PriorityConditions. This distinction is central to the source's additional-value claim.", + "special_limits": [] + }, + { + "target": "T39", + "case": "genuine_priority_failure", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedDoesNotEntailPriority", + "file": "CoreReader/Engineering/Integration.lean", + "line": 586, + "axioms": "[propext,\n Classical.choice.{u},\n Quot.sound.{u}]" + } + ], + "interpretation": "Accepted as the requested bounded non-entailment witness with every original strong branch preserved. The same continuing shared context has real encoded applicability/advantage and no lifecycle/cost escape; presentSimple adopts a separately grounded simplicity value and satisfies expanded inherited duties yet fails the extra priority. normApplies records adoption of the additional domain norm, not disappearance of its actual PriorityConditions. This distinction is central to the source's additional-value claim.", + "special_limits": [] + }, + { + "target": "T39", + "case": "inherited_grounds_for_other_value", + "status": "accepted-bounded", + "actual_evidence": [ + { + "name": "CoreReader.Engineering.inheritedDoesNotEntailPriority", + "file": "CoreReader/Engineering/Integration.lean", + "line": 586, + "axioms": "[propext,\n Classical.choice.{u},\n Quot.sound.{u}]" + }, + { + "name": "CoreReader.Engineering.selectionGrounded", + "file": "CoreReader/Engineering/Values.lean", + "line": 219, + "axioms": "[propext, Classical.choice.{u}, Quot.sound.{u}]" + } + ], + "interpretation": "Accepted as the requested bounded non-entailment witness with every original strong branch preserved. The same continuing shared context has real encoded applicability/advantage and no lifecycle/cost escape; presentSimple adopts a separately grounded simplicity value and satisfies expanded inherited duties yet fails the extra priority. normApplies records adoption of the additional domain norm, not disappearance of its actual PriorityConditions. This distinction is central to the source's additional-value claim.", + "special_limits": [] + } + ] +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/source-code-review-adopted-f01-f06-final.json b/SoftwareEngineering/lean/philosophy/reviews/source-code-review-adopted-f01-f06-final.json new file mode 100644 index 0000000..784b5aa --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/source-code-review-adopted-f01-f06-final.json @@ -0,0 +1,42 @@ +{ + "schema": "independent-repair-review-v1", + "reviewer": "/root/se_source_first", + "phase": "informed bounded repair review", + "candidate": "private software-engineering iteration records/Adopted-nature-candidate-04.lean", + "code_sha256": "68bb96c35553bf83d0e3a915d1cca0c72b8097670626e32046bf53af5d0bc773", + "findings": [ + { + "id": "F01", + "status": "resolved", + "scope": "explicit fixed-task sufficient content adapter; Root task identity not reviewed" + }, + { + "id": "F06", + "status": "resolved", + "scope": "same fixed empirical-task permission consequence from supplied actual counterworld reasons" + } + ], + "target_changes": [ + { + "id": "T09", + "previous": "rejected", + "status": "accepted", + "completion": "incomplete" + }, + { + "id": "T07", + "previous": "pending", + "status": "accepted", + "completion": "incomplete" + } + ], + "remaining": [ + "Root task binding", + "Root full joint witness and strong countermodel", + "Domain findings", + "final code-only independent backtranslation and type-hash/manuscript bindings" + ], + "record_sha256": "dc1952e457239f9c5a72d99b50ff043f3c243ff8914efea20e0bc49b3af441b4", + "build_log_sha256": "a2829f6b71000d5b74b17d869cf5c370482a3fd5f9e2ee72645593ddb7878a96", + "audit_log_sha256": "c450cefaa020de9b1964d6f522262543063f6bc68c414b5dda81ef33eb560317" +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/source-code-review-adopted-f01-f06-final.md b/SoftwareEngineering/lean/philosophy/reviews/source-code-review-adopted-f01-f06-final.md new file mode 100644 index 0000000..3871734 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/source-code-review-adopted-f01-f06-final.md @@ -0,0 +1,40 @@ +# Adopted F01/F06 修复:独立窄复核 + +时间:2026-09-14T17:30:52.056693+00:00。审阅者:`/root/se_source_first`。阶段:保留source-first初读和初次源码判断之后的知情修复复核。未改代码,未覆盖原记录;只审F01/F06及直接类型变化,未展开新的全文评审。 + +**F01与F06均已在当前候选披露的有限范围内解决。** T09可从rejected改为accepted(明确原task的充分适配接口);T07原先pending的grounds_on_grounds分支可接受。其他目标/Domain findings维持原状态。此结论不接受Root新task绑定、完整T38/T39、尚未完成的code-only回译或最终reader/source-fidelity证据。 + +受审对象:`Adopted-nature-candidate-04.lean`,SHA256 `68bb96c35553bf83d0e3a915d1cca0c72b8097670626e32046bf53af5d0bc773`。旧初审Adopted hash仍为 `9c7b2ea63fe176c490f007598563de58f6937f4b8dd09bcdbe5b15f39c395c3e`,不刷新旧判断。 + +## F01 — 原任务与nature适宜性 + +实际类型现在是 `Grounds012 claim articulations facets task`。每个supplied facet仍需同claim、articulation内容、discharge,并新增 `NatureAppropriate task facet`。task包含原records/scope/claim/uncertainty、原inferential assumptions,或原value position;并非仅检enum标签或自由成功Bool。 + +检查了以下实际命题及其证明内容: + +- `circularSubstitutionRejected012`:新的“假定allTrue再推出allTrue”任务本身可以有支持,但同facet不能替代既定的 `[zeroRecord]` 经验allTrue任务。反证使用 `localGenerator 0` 实际兼容原记录而在1处失败,区分原premises与新allTrue assumption,未把正确条件推论说成错误。 +- `sameEmpiricalTaskTwoMethods012`:同一个originalLocalTask既接受原经验facet,也接受从原Compatible(records)与scope构成的假设推论出input0结论。适宜性不是“原任务只能用同名种类”。 +- `uncertaintySubstitutionRejected012`:尽管推论facet对第一坐标的结论有效,同原经验task仍必须保留第二坐标uncertainty断言。`(true,false)`满足原重复温度记录而使该断言失败,因此转换评估形式不能逃掉原uncertainty责任。 +- `valueFactSubstitutionRejected012`:观察到已选择该position与其value task有理由是不同任务;实际观察facet可discharged却不能取代固定value position。 +- `inferentialContextSubstitutionRejected012`:原emptyTheory不允许被替换成新增目标结论的singleton前提。新前提下的推论正确性保留,但不是原任务的完成。 + +`grounds012Singleton`的新结论明确只适用于 `taskOfFacet f`;它没有给定任意原task的适宜性证明。该 helper 合法地创建一个任务,不能把它用作替换另一个已由源/上下文固定的任务。Root使用时必须实际保留同一原task,这仍待Root源码审查。 + +**限度**:NatureAppropriate是所选表示中足够的内容匹配,不是全部哲学适宜性的必要充分条件。等式匹配会不接受某些语义等价但表现不同的ground或推论;文件已明确披露此限度。未加入013“所有实际方面自动覆盖”义务;原任务/所选facets之外的哲学全面性仍由source inventory和最终审查负责。初始task必须与源语义对应,构造task本身不证明其真实性。 + +## F06 — Ground自我理由连接实际许可后果 + +旧 `outcome = !enabled` 已改为 `groundsExperiment012 enabled`:对固定 `groundsExperimentTask012` 及相同allTrue/zeroRecord/globalFacet实际求 `groundsPermission012` 的判定。这是classical noncomputable逻辑判定,不应称为可运行的经验试验。 + +reasons不再包含 `enabled=true`;现在给出实际反世界 `Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0)`。`groundsPosition012Checked`的后果证明从传入reasons抽出这两项,证明同一原task的Grounds不足,再推出启用policy时许可判定为false。`groundsRationaleExperiment012`还检查停用policy时同一任务许可为true,以及value outcome确实就是这两个同task实验结果。因此当前理由不是把期望开关值重命名成获益。 + +采纳true及“拒绝这个无充分支持断言”的目标仍是明确初始价值立场,不是事实必然推出的应当。规范 `GroundsProvision012 true` 对其permission gate的形式成立,与具体反例理由解释为什么在这一目标下采用gate分开。该关系足以解决F06的局部连接问题;它不证明Grounds普遍正确、所有assertion都已被实际评估或所有价值立场必须选true。 + +## 实际验证与依赖界线 + +- 已读candidate04的AssessmentTask/NatureAppropriate/Grounds012完整定义、适配helper、五组新正负变式、F06完整定义和证明,并检查修复已进入相关bundle。 +- `nature-build-04.log` SHA256 `a2829f6b71000d5b74b17d869cf5c370482a3fd5f9e2ee72645593ddb7878a96`:保存输出明确 `Build completed successfully (8 jobs)`。 +- `nature-audit.log` SHA256 `c450cefaa020de9b1964d6f522262543063f6bc68c414b5dda81ef33eb560317`:读取实际审计记录,未见error/sorryAx;所报依赖只有propext/Classical.choice/Quot.sound。未在本审阅者进程重跑Lean,未把日志检查当语义证明。 +- 所有新增type/代码hash均为新对象;旧source-code-review-partial-initial.md和targets-initial.json不改。新task参数改变相关type,最终登记须使用新type-hash和新review绑定,不允许拿旧type hash标新对象已审。 + +本阶段没有新的阻断。后续Root必须固定并使用与实际工程claim/grounds相对应的task,不能每次根据准备通过的facet重造task;且T38/T39仍需同ctx所有规范而非本helper的成功。Domain待修项及最终盲回译保持未完成。 diff --git a/SoftwareEngineering/lean/philosophy/reviews/source-code-review-domain-r2.json b/SoftwareEngineering/lean/philosophy/reviews/source-code-review-domain-r2.json new file mode 100644 index 0000000..8150f8a --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/source-code-review-domain-r2.json @@ -0,0 +1,76 @@ +{ + "schema": "independent-repair-review-v1", + "reviewer": "/root/se_source_first", + "candidate_sha256": "2949bc55e78de008c1b5bad067373e27ea1cac763db5a2404396d2ba66bbb96a", + "findings": [ + { + "id": "F02", + "status": "resolved" + }, + { + "id": "F03", + "status": "resolved" + }, + { + "id": "F04", + "status": "resolved-source-relation", + "remaining": "same-work frozen semantic-case preservation" + }, + { + "id": "F05", + "status": "resolved" + } + ], + "target_changes": [ + { + "id": "T24", + "status": "accepted", + "completion": "incomplete" + }, + { + "id": "T27", + "status": "accepted", + "completion": "incomplete" + }, + { + "id": "T29", + "status": "accepted", + "completion": "incomplete" + }, + { + "id": "T30", + "status": "accepted", + "completion": "incomplete" + }, + { + "id": "T33", + "status": "accepted", + "completion": "incomplete" + }, + { + "id": "T34", + "status": "accepted", + "completion": "incomplete" + }, + { + "id": "T35", + "status": "accepted", + "completion": "incomplete" + }, + { + "id": "T36", + "status": "accepted", + "completion": "incomplete" + }, + { + "id": "T32", + "status": "pending", + "reason": "common-object and actual-boundary defect resolved; frozen same-work case now totals17→18 and needs precise preservation judgment or supplementary equal-work instance", + "completion": "incomplete" + } + ], + "record_sha256": "53288a6b2e5bdc55a18a004c0a3c38c0a31269d97309e1f4a0b864f9cfeba28f", + "audit_sha256": "3e14447cd433375bb8408fe4e49f95907ee77d7686742e709bc7f57f43827566", + "build_log_note": "domain-build-19.log empty; exit receipt needed for final mechanical completion", + "excluded": "Root T20/T37–T39, final blind backtranslation and evidence binding" +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/source-code-review-domain-r2.md b/SoftwareEngineering/lean/philosophy/reviews/source-code-review-domain-r2.md new file mode 100644 index 0000000..4de5965 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/source-code-review-domain-r2.md @@ -0,0 +1,49 @@ +# Domain r2 — 对应初审finding的独立窄复核 + +时间:2026-09-14T17:33:57.197728+00:00。审阅者:`/root/se_source_first`。阶段:知情修复审查;未改代码、未覆盖初稿、未扩大至Root T20/T37–T39。 + +受审Domain.lean SHA256:`2949bc55e78de008c1b5bad067373e27ea1cac763db5a2404396d2ba66bbb96a`。原初审hash `bf1b5cb1c901de2d9c37dec58635f9b6af2ccd36c51b5bb158f39b182eaab941` 保留;作者r1/r2说明用于定位,以下判断来自实际定义、命题与证明内容。 + +**F02/F03/F05在披露的有限范围已解决,F04的共同对象/真实边界问题也已解决。** T32冻结 `new_boundary_same_work` 的具体实例保留另有一项待落实:当前总工作量17→18,不是原名称所指的same work。它满足源级“新增boundary不能单独证明更容易”,但不应静默把冻结的同工作量案例改成不同工作量。已将此窄差异告知root,建议保留一个实际新增边界且total work不变的变式,或在原合同确实仅把此名作为“不减轻工作”分支标识时明确记录该范围判断。其余已成立片段无需重做全文评审。 + +## F02 — 演化能力最大化与跨维比较 + +- `registeredDirections`现在有额外CSV export。maximal有真正可供successor/agent使用的migrationGuide/compiler路径;evolvable路径需要这些维护者没有的privateLayout。`transform (.other "csv export")`实际追加能力字段。不是只把abstractionComplexity命名最大。 +- `credibilityLimits`实际证明采纳evolvable满足EvolutionPriority而不满足MaximumRegisteredCapability;maximal覆盖注册十项,evolvable九项。额外CSV方向不被当前credible grounds支持。这支持有限集合内不最大化所有可能性的源分支;不声称最大化宇宙中所有想象变化。 +- `evolutionDimensionsLimits`固定同两个candidate及原maintainer,对designRevision有严格work优势而addition同为2;`oneDimensionDoesNotEntailEveryDimension`实际反驳每个Change都严格占优。原easy_add/hard_exit与贵migration分支保留。 +- 空path被CanChange/ContinuingCapability明确拒绝,未知方向不能靠空列表all获得能力。 + +T24、T27、T30可从rejected改为accepted,限于这些显式能力/成本关系。T24的旧bundle依旧只列复杂度,但补充实际能力命题已存在并由author map指出;最终case绑定必须引用实际命题,不能仍只用复杂度那一项作为证据。 + +## F03 — 合同义务和受影响方 + +`ObservableContract`独立于report,含实际order函数及maxAttempts;`retry`从这个限制计算行为。旧合同attempt3为false,新合同为true,实际行为变化替代原来孤立Nat字段不等式。 + +`partyDependencies`独立指出consumer观察order、operator观察retry;`affectedParties`从实际old/new合同差别导出相应方。`RevisionDuties`核对report覆盖这些方并绑定old/new真实maxAttempts及记录值。`contractDistinctions`拒绝只留consumer以及联动改oldFailureLimit/recordedOldFailureLimit的变式。原通知字段及必需通知程序已移除,避免额外规定source不要求的流程。 + +有限preservation、明确修订、影响方缺失、替代procedure、[99]范围外历史差别都仍有实际实例;generic contractRevisionObligations有完整old/new/account/nonpreservation前提。T33/T34改为accepted;依赖它的T29相应pending解除,保留有限direction/treatment适配限度。此接受不要求保存全部历史行为,也不要求特定测试/迁移方法。 + +## F04 — 同设计对象及实际新增边界 + +`EngineeringDesign`把metadata、run、paths、components、boundaries、batchAssumptions放在同一对象。private/documented共享metadata而successor能否走designRevision路径不同;private/sorted共享signature而order输出不同;8模块变化直接读取该设计的batch assumptions。先前无关联并列字段问题已经解决。 + +`introduceBoundary`实际新增component8、edge8→0、forwarding run和path verification step。wrappedDesign有9个components、1条boundary,work18;不再使用wrappedWork alias。该内容确实构成“增加边界不保证减少change work”的相关反例。 + +剩余仅为冻结案例精度:`new_boundary_same_work`的当前author索引也明确写17→18。不能在读者稿里继续写“总工作量相同”。若原case确切要求same total,需补相同工作量的真实新增boundary变式;原counterclaim no-improvement与修复后的已真命题不受影响。T32暂保持pending,直到该目录分支的保留被明确解决;不是重新拒绝共同对象修复。 + +## F05 — 历史事件与当前ctx身份 + +`RevisionAccountAgainst history r`现在把独立history作为参数;软件身份、old snapshot、prediction与actual数字都与该history核对。固定observedHistory中的static21/size5预测3、live实际5来自真实函数计算。 + +`failedHistoryNotRewritten`在同history失败及account满足的完整前提下推出report=false。`historicalTamperingRejected`实际拒绝联动old/recordedOld、prediction+success、actual+success及另软件身份。当前record可以改变而历史失败不能靠修改report自身被重写,这与源scope一致。 + +`revisionFor`的software来自ctx.activity.software,revisionContextIdentity也检查它与observedHistory软件及当前维护期/维护者/成本/容量/选择的连接。此前报告把固定实例的真定理和泛化历史对应前提区分;现在泛化前提在类型中明示并有实际变式。T35/T36可改为accepted,限于所披露历史输入是真实原事件的模型假设;这不是cryptographic provenance或现实历史真实性的证明。 + +## 验证和状态界线 + +- 实际读取变更的path/能力集合、合同/party/behavior定义、EngineeringDesign与boundary变换、historical绑定及所需case/theorem正文,未把作者notes当证明。 +- `domain-audit-r2.log` SHA256 `3e14447cd433375bb8408fe4e49f95907ee77d7686742e709bc7f57f43827566`;实际有命题类型及axiom输出,只见propext/Quot.sound,没有error/sorryAx。`failedHistoryNotRewritten`中的failed是合法前提名,不是失败日志。 +- `domain-build-19.log` SHA256 `e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855`,**为空文件**。这可能是成功的静默Lean命令,但空文件本身不能证明exit=0;最终交付须保存实际命令完成状态或execution receipt。此处不虚报独立重新编译成功。 +- 未重新运行Lean;Root完整集成、最终盲回译、新type-hash/源审查/四稿绑定仍未完成。所有accepted仅是本次修复对象的source-code范围判断。 + +作者修复没有授权改变源哲学、版本或冻结目标;本报告也不作这种更改。旧记录不更新hash或成功状态,后续新binding应指向本次新对象。 diff --git a/SoftwareEngineering/lean/philosophy/reviews/source-code-review-domain-same-work-final.json b/SoftwareEngineering/lean/philosophy/reviews/source-code-review-domain-same-work-final.json new file mode 100644 index 0000000..123691e --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/source-code-review-domain-same-work-final.json @@ -0,0 +1,19 @@ +{ + "schema": "independent-repair-review-v1", + "reviewer": "/root/se_source_first", + "code_sha256": "0ed052c3692d8c91a41eed60bb0cba6ca033a7c9d1163aac66b32e4291927377", + "finding": "F04", + "status": "resolved-including-frozen-same-work-case", + "target_changes": [ + { + "id": "T32", + "previous": "pending", + "status": "accepted", + "completion": "incomplete" + } + ], + "review_sha256": "c64b54d89ffed6592d5b745772835f9ff1ace23305a51dfa688289bf25c9cde2", + "receipt_sha256": "412f975863cd2f3d803673776807a0205cd5e4b5ac7d37328d69f332abab7323", + "receipt_exit_code": 0, + "scope": "new same-work actual boundary variation only; Root independent review pending" +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/source-code-review-domain-same-work-final.md b/SoftwareEngineering/lean/philosophy/reviews/source-code-review-domain-same-work-final.md new file mode 100644 index 0000000..1f64645 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/source-code-review-domain-same-work-final.md @@ -0,0 +1,11 @@ +# Domain same-work 补充实例窄复核 + +时间:2026-09-14T17:34:49.029932+00:00。审阅者:`/root/se_source_first`。本记录保留 `source-code-review-domain-r2.md` 及全部初稿,不回写其hash或状态。 + +**T32剩余pending已解决,可以在披露的有限范围内accepted。** 新Domain SHA256 `0ed052c3692d8c91a41eed60bb0cba6ca033a7c9d1163aac66b32e4291927377`;r2原对象单独保留。其余F02/F03/F05及F04共同对象判断沿用r2窄复核,未新增全文审查或预判Root。 + +实际读取 `relocateVerification`、`sameWorkDesign` 及更新后的 `structureNotCapability`。新变式确实沿 `introduceBoundary` 新增component8和edge8→0;把原有contractRunner步骤移到component8而保留其units及其他step内容。因此path不同、组件/边界确实新增、原output相同,且totalwork仍17。successor依旧缺privateLayout,实际change能力没有因新增边界获得。该新实例满足冻结 `new_boundary_same_work` 的精确同工作量内容;原17→18例仍保留为补充,而不是被改名冒充same work。 + +`integration-build-07-receipt.json` 实际记录 `lake build CoreReader`、正确项目cwd、exit_code=0、Domain及Root依赖成功构建,且receipt.domain_sha256与本次代码一致。receipt SHA256 `412f975863cd2f3d803673776807a0205cd5e4b5ac7d37328d69f332abab7323`;日志SHA256 `caa96c28e36877314eab947d5dc98f8caf032327f1fdece9b88018527e1e807d`。这为新对象提供真实构建完成证据。旧空 `domain-build-19.log` 不因此被追溯改成成功收据。 + +尚未完成最终新type-hash/axiom审计对象绑定、全代码独立code-only回译及Root完整source comparison;本次acceptance只解除旧F04剩余case精度,不等于整体完成。未改代码。 diff --git a/SoftwareEngineering/lean/philosophy/reviews/source-code-review-f07-f08.json b/SoftwareEngineering/lean/philosophy/reviews/source-code-review-f07-f08.json new file mode 100644 index 0000000..9e1bb06 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/source-code-review-f07-f08.json @@ -0,0 +1,153 @@ +{ + "schema": "independent-repair-review-v1", + "reviewer": "/root/se_source_first", + "recorded_at": "2026-09-14T18:01:11.678348+00:00", + "phase": "informed repair review; author response seen; other independent blind/source comparison not seen", + "candidate": "private software-engineering iteration records/f07-f08-candidate", + "candidate_files": { + "leanified/lakefile.toml": "05d8ba36975f87aca61e3b0ddcacc42669539f316ba9b8eef5859961e2aa6fdc", + "leanified/CoreReader/Adopted.lean": "81337c6b8d85dc02a27a20e0969e8c09e41aa85a1784c0c22c9cf4b150dd7f1e", + "leanified/CoreReader/Agency.lean": "2722c34645f4256f20ce31205738f2f5712ab5dd5cc6fcf9f1180d0be5aa0303", + "leanified/CoreReader/Choice.lean": "b28728df12ed7e73edb5569604cd2541c0ebd815ae3aaa0812e6557dece1d1ba", + "leanified/CoreReader/Engineering/Domain.lean": "9adc72e3a072d16aefb0e12a55584caa87205fc484aea488cdd80a785a8ff90b", + "leanified/CoreReader/Engineering/Integration.lean": "a2b88062148b3f7ebea7da02d88cb29cb04d8f1b2e9e6b97bb2420ac2c006328", + "leanified/CoreReader/Engineering/Reflection.lean": "c290d8472884d00bedbf945f0fc1866524e758740f40d42088c4ff9678a93fa2", + "leanified/CoreReader/Engineering/SelfApplication.lean": "d69c0d369bd4fd8db4c21ce3b65abb5e9efd07ed5ab9a68d56b4db39bb9d2a21", + "leanified/CoreReader/Engineering/Values.lean": "ccd45bf23d2f47c41d1b2f9955d753e290687d951a0c55af41ab9a63b9a8d9cb", + "leanified/CoreReader/Evidence.lean": "d55f33e44902cef146841cbffb65710bd7c8a3bda79d01d084edc36f019fdc96", + "leanified/CoreReader/Integration.lean": "97e2939c0b6714b78a3ed78358e174619a5028ad5b0b5025c0d4422b4294921b", + "leanified/CoreReader/Logic.lean": "0ec342691766ebd83d251dcd0da3b0ae9840aed677a714bc1b01c45d89392bc0", + "leanified/CoreReader/Reflexivity.lean": "48e2c74e7cbae571db1b990b9f32dd0d701f6881a8b0111d907f8861287d76fa", + "leanified/CoreReader.lean": "c5574fae235419a7d6449b3ebb5d2da29d1e92a3b572c1b759438e3c470caaa9" + }, + "read_object_hashes": { + "Integration": "a2b88062148b3f7ebea7da02d88cb29cb04d8f1b2e9e6b97bb2420ac2c006328", + "SelfApplication": "d69c0d369bd4fd8db4c21ce3b65abb5e9efd07ed5ab9a68d56b4db39bb9d2a21", + "Reflection": "c290d8472884d00bedbf945f0fc1866524e758740f40d42088c4ff9678a93fa2" + }, + "findings": [ + { + "id": "F07", + "status": "resolved-bounded", + "basis": "Actual OwnNorm content family, whole fact/norm union, member bridge and one shared admissible witness; consistency constrains that union without self-reference." + }, + { + "id": "F08", + "status": "resolved-bounded", + "basis": "Actual generation/evaluation functions are objects, with actual applicability, executed records, generator mutation and empty-initial-sample contract criticism." + } + ], + "target_changes": [ + { + "id": "T20", + "status": "accepted-bounded", + "previous": "pending-correspondence", + "resolved_findings": [ + "F07", + "F08" + ], + "completion": "incomplete", + "declarations": [ + { + "name": "CoreReader.Engineering.inheritedMutualApplication", + "type_sha256": "b60496465943a095fdd0772f4002302eb9242ece03be7a2e20ce616f0253ee4a" + }, + { + "name": "CoreReader.Engineering.inheritedMutualCases", + "type_sha256": "e3c73c4f98c7a3fe5bfadc8b2bc7a9a5231473504e047179d6299e3417f2ba4c" + } + ] + }, + { + "id": "T37", + "status": "accepted-bounded", + "previous": "pending-correspondence", + "resolved_findings": [ + "F07", + "F08" + ], + "completion": "incomplete", + "declarations": [ + { + "name": "CoreReader.Engineering.priorityRemainsReflexive", + "type_sha256": "285b4edb7397d25ccc631b194a1ff8ebb5204df450d52ec8eaf0685519b289c2" + }, + { + "name": "CoreReader.Engineering.priorityReflexiveCases", + "type_sha256": "2be55699c66ab5ba0f6310f298e19b890de4caef622e0d69676f2d6a7a3b5170" + } + ] + }, + { + "id": "T38", + "status": "accepted-bounded", + "previous": "pending-correspondence", + "resolved_findings": [ + "F07", + "F08" + ], + "completion": "incomplete", + "declarations": [ + { + "name": "CoreReader.Engineering.jointWitness", + "type_sha256": "56d1bd97b0ac6c069484812a2a975dc185a905a24ee133a780b5f23a7fdc0b59" + } + ] + }, + { + "id": "T39", + "status": "accepted-bounded", + "previous": "pending-correspondence", + "resolved_findings": [ + "F07", + "F08" + ], + "completion": "incomplete", + "declarations": [ + { + "name": "CoreReader.Engineering.inheritedDoesNotEntailPriority", + "type_sha256": "ad1b1b45257f57a53567b08bc87eb32bd6d8acf8395e9762a684c1116f270197" + } + ] + } + ], + "report_sha256": "898af33213a832832f4b6d84a8f94fd99bede9a0abae055b9e2a1af3b8ee5b1f", + "previous_full_report_sha256": "d1c38be6f8826ff29ff01ec12bb2d45f3f32e4e4b45830c7fd3250a40ab13767", + "evidence": { + "directory": "SoftwareEngineering/lean/philosophy/evidence/checks/2026-09-14T17-57-36.138Z-30664-f57092", + "files": { + "lake-build.log": "da5816c9a0767c1dbc2657dfb0528d52ef82bd1516d320d6d5d6d8d5dd988437", + "lake-build.json": "db13e62e4e665741eb1b53f915a4047cde44b220a34c5ca391036ea0030e4441", + "lean-audit.log": "872ab0c947ec133e88753dde51e0498f9b008934cd3f50baf9b474fef9f8a6e6", + "lean-audit.json": "79d9c23b7c3c51661ece41afbceb2c7416ed21cb84a6bdc1aa023c215e1e09e7", + "declaration-types.json": "ef139b207e05d1272871ee627f60636a0e9f886d2eac65aea18915e7fc33e27b", + "inputs-sha256.json": "ca316a4d6cf8bc01ec0efc4bdd91cbc0e76faea226ae227b4248cd128af18cb3" + }, + "local_files": { + "f07-f08-check.json": "a2f4ed406588dfe87840e1675ec653646a12b048f4287bc68456737bc7e43aeb", + "f07-f08-build-05-receipt.json": "1a5b64e758bb89d21f5439f1758784542b43d7e22b1b290597a1a42a2751be10", + "f07-f08-build-05.log": "aa3095899a65115b25b644ab266a5813550e301b9817f1084c87a44b55ad5f5a", + "f07-f08-author-response.md": "6850fe7b7693200544b4df76337a89ed7655871a523cccfc2a7faa59766f6da8" + }, + "observed": "build and audit actual status 0; 15 full build jobs; 59 real declaration types and only propext/Classical.choice/Quot.sound; all14 evidence inputs equal frozen candidate" + }, + "strong_statement_preservation": { + "jointWitness": "exact public statement unchanged against before-f07-f08", + "inheritedDoesNotEntailPriority": "exact public statement unchanged against before-f07-f08", + "qualification": "Inherited and ownTheory changed substantively and were independently re-read" + }, + "counterarguments_and_limits": [ + "Empty initial sample is a failure against a local sample-aware contract, not a universal source obligation that every assessment requires samples; requested tests still supply computational information.", + "Priority value/claim equivalence holds only in the fixed shared applicable no-cost-exception context.", + "Whole-claim mathematical support from fixed model identity does not replace original empirical/value/capability tasks.", + "No need to put a self-referential Consistent theory proposition inside its own definition; actual consistency constrains the exact whole theory.", + "Actual evaluator retains the exposed finite defect; sampleAwareAssessment is a distinct proposal, not silently adopted.", + "Later public Domain/Adopted changes are outside this frozen review." + ], + "production_changes": false, + "reviewer_authored_lean_probes": false, + "remaining": [ + "other independent comparison and incremental change review", + "manuscript and final delivery bindings" + ] +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/source-code-review-f07-f08.md b/SoftwareEngineering/lean/philosophy/reviews/source-code-review-f07-f08.md new file mode 100644 index 0000000..0aad5f9 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/source-code-review-f07-f08.md @@ -0,0 +1,52 @@ +# F07/F08 独立修复复核 + +审查者 `/root/se_source_first`。本记录是保存 source-first 和 full-initial 后的知情修复审查;已读作者 response,但尚未看到另一代理的盲译或源文对照意见。结论:**F07/F08 在当前有限表示中解决**。T20/T37/T38/T39 从 pending-correspondence 改为 accepted-bounded。此结论不代替后续三方比较、读者稿和最终交付检查。 + +## 对象与实际证据 + +- Integration.lean:`a2b88062148b3f7ebea7da02d88cb29cb04d8f1b2e9e6b97bb2420ac2c006328` +- SelfApplication.lean:`d69c0d369bd4fd8db4c21ce3b65abb5e9efd07ed5ab9a68d56b4db39bb9d2a21` +- Reflection.lean:`c290d8472884d00bedbf945f0fc1866524e758740f40d42088c4ff9678a93fa2` + +逐文件比较 `before-f07-f08/leanified` 与当前项目:只有这三个 Lean 文件改变。其余已审源码精确字节不变,保留既有局部接受及限度。T38 `jointWitness` 与 T39 `inheritedDoesNotEntailPriority` 的完整公开 statement(截至 `:= by`)与前稿逐字相等;它们引用的 Inherited 和 ownTheory 已补足,不能因外层 statement 未改而只复用旧组合判断。 + +实际读取 `f07-f08-build-05-receipt.json`、对应非空日志,以及 `evidence/checks/2026-09-14T17-57-36.138Z-30664-f57092` 下独立全构建和 audit 原始输出。两次实际构建及 audit 返回 0;全构建 15 jobs。59 声明有真实类型输出,已核新 T20/T37 结论及 T38/T39 完整强分支,依赖限于 propext、Classical.choice、Quot.sound,无 sorry 或项目公理。证据目录 inputs-sha256 中14项项目输入与当前对象相等。源码与每项证据 hash 绑定在同名 JSON。 + +## F07:完整内容进入同一理论 + +Integration:229–258 的 OwnNorm/ownNormClaim 不再停在 coreAdoption:逐分支展开到真实 generation、reflection、原 empirical task、capacity inference、各原则价值责任、选择价值及实际采纳、scope、capability、implementation choice、各 ownFact 的推论根据,以及领域采用者的完整 DomainSatisfied 和实际 priority 价值根据。旧 coreAdoption 仍是事实标记,但不再代替这些规范内容。 + +Integration:285–329 将事实理论与当前适用规范内容并入同一个 ownTheory。allNormativeContentHeld 提供逐项实际成员关系;currentAdmissible 对两个并集分支分别调用 actualOwnFact/actualOwnNorm,构造同一个 chosen 模型。currentConsistency 的 snapshot 持有这个并集,因此其后果关系约束的是完整内容与事实,而非每条原则单独自洽。T20 现在明确返回完整内容成员、整理论的根据和这个 consistency。 + +一致性作为约束完整理论的谓词在定义之外表示,未把 Consistent theory 自引用塞入该 theory。此选择已明确披露;它没有免除一致性,而是由 currentConsistency 直接证明其对精确同一完整理论成立。没有理由为了形式上的成员枚举要求不良自引用。 + +Integration:351–369 的实际变式保留同一采纳标记,同时把同 candidate/question/scope 的相反要求放在同一理论并证明不一致;不是只翻转“consistent”标签。另证明 evolvable 持有实际 domain 内容,而 presentSimple 不持有且不能满足该内容。该变式不是所有可能 normative encoding 的保真元定理,但结合 OwnNorm 的逐分支原谓词定义,足以回答本次缺口。 + +领域 normApplies 由 domain adoption 控制,不能与 PriorityConditions 混同:T39 的规范未采纳,但实际领域优先适用条件仍全部成立。此区分恰是用户强非蕴含目标;没有使用 temporary/cost exception 回避。 + +## F08:实际规则成为自身评估对象 + +SelfApplication:8–65 新增 generationRule/assessmentRule。其 objectTest 直接使用当前 Reflection.generate/evaluate,ruleProbe 不调用 staticBatch。ownRuleIdentity 同时连接对象成员、当前 rule.meaning=interpret、对象合同,以及实际 generation/assessment applicability。currentSelfRecords 仍对实际 interpret 检查输入理由非空、basis 与记录后果,不仅核对对象名。 + +generation 的 formation/revision 实际适用,application 不适用;assessment 三阶段适用。新增对象没有被统统豁免。ownRuleContentVariation 实际检查当前生成器保留 requested tests/scope,而替换为空输出的方法在同一探针失败。当前评估器在有初始样本时符合本地契约,在空初始样本时仍返回 supported;assessmentRule 的 revision 自评据实际失败结果返回 counterexample。这里检查的是实际正在用的评估函数,已不再用领域预测反例替代自身方法。 + +sampleAwareAssessment 是独立候选,在空/非空两种有限情况满足该样本契约;它未偷偷替换当前 evaluate。proposedRuleRevision 还让同一对象与 phase 下的实际 applicability 随候选条件改变。后一个候选将 generationApplies 设为 False,只用于实际适用性差异探针,不是当前系统的整体豁免。原当前适用性已另行证明。 + +## 反驳与保留限度 + +“空样本缺陷”是这个本地 sample-aware 期望契约下的失败,不是哲学要求所有判断都必须有观察样本。ruleProbe 的 requested 项仍由纯函数 test 检查,因此不能把它描述为“完全没有任何判断依据”。源文允许不同性质的支持,也没有通用测量链;读者稿必须保留这个范围。本限定不推翻实际方法对象绑定及自评反例。 + +priorityValueMeaning 是在固定 sharedContext、当前适用且无成本例外时,将 selectionPosition.evolvable 的 commitment 与实际 EvolutionPriority 逐 candidate 证明等价;priorityGrounds 保留该 value 原任务,并用明确等价连接同一 claim。此处依据既有实际 changeWork 与目的/限度,未声称采纳是经验事实或必然推论。T37 新增实际 priority Grounds、domain 内容成员及同一完整理论 consistency。不能把该有限等价推广到其他情境下所有优先规则。 + +wholeClaimGrounded 从固定模型身份推导整理论各项命题,是关于这个模型事实/责任完成状态的数学根据。它不取代仍在 OwnNorm 和 Inherited 中独立保留的 empirical、inferential、value、capability 原任务,没有重新引入 F01 的新假设冒充旧任务。 + +自评成功或产生 candidate revision 没有证明普遍正确;当前评估器的局部失败保留,未追溯改成成功。自反要求是适用原则的真实执行与可批评性,并不要求每次自评都宣布原方法正确。F08 得到解决也不意味着所有可能方法和适用情境均已覆盖。 + +## 目标结论 + +- T20:accepted-bounded;完整内容、同一理论一致性、原任务支持及实际自身规则对象已接通。 +- T37:accepted-bounded;实际 priority Ground、完整理论成员/一致性和领域方法及实际评估规则的批评均保留。 +- T38:accepted-bounded;同一 continuing ctx 的 evolvable 满足补足后的 Inherited 和 DomainSatisfied,接受额外复杂度且有真实 successor/agent designRevision 路径。 +- T39:accepted-bounded;同一 ctx 的实际 presentSimple 选择仍满足全部已表示继承责任,领域 PriorityConditions 成立,双方必要需求满足,credible designRevision 和实际演化优势存在,无 lifecycle/cost 逃逸,而 EvolutionPriority 实际不成立。 + +没有发现需要继续修改这三个文件才能解除 F07/F08 的阻断。此前完整初判及本次以前所有对象、失败记录与判断保持原样。本轮未改生产代码、未运行自编 Lean 探针;结论依据实际源码、已编译探针证明和真实收据,不依据作者意见或代理同意数。 diff --git a/SoftwareEngineering/lean/philosophy/reviews/source-code-review-full-initial.json b/SoftwareEngineering/lean/philosophy/reviews/source-code-review-full-initial.json new file mode 100644 index 0000000..f316d18 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/source-code-review-full-initial.json @@ -0,0 +1,3522 @@ +{ + "schema": "independent-full-source-code-review-v1", + "reviewer": "/root/se_source_first", + "recorded_at": "2026-09-14T17:49:42.008788+00:00", + "phase": "informed actual source review after preserved source-first; blind translation and its concerns not seen", + "status": "pending-correspondence", + "source_sha256": "6c6ae78a23f2726c5c370434e808d76c206647fe7793245e88cae52c076abe34", + "catalog_sha256": "c0939df35dad148a0543ba92a1ac7b7d3b2eb4946f92ac4be251ec51b6481d13", + "run_sha256": "661ee91e1727a628c9e5933f6c6690011c575f99123b2a669ddb2b9c036a163d", + "report_sha256": "d1c38be6f8826ff29ff01ec12bb2d45f3f32e4e4b45830c7fd3250a40ab13767", + "code_objects": [ + { + "path": "CoreReader/Adopted.lean", + "snapshot_sha256": "68bb96c35553bf83d0e3a915d1cca0c72b8097670626e32046bf53af5d0bc773", + "current_sha256": "81337c6b8d85dc02a27a20e0969e8c09e41aa85a1784c0c22c9cf4b150dd7f1e", + "comment_removal_exact": true + }, + { + "path": "CoreReader/Agency.lean", + "snapshot_sha256": "2722c34645f4256f20ce31205738f2f5712ab5dd5cc6fcf9f1180d0be5aa0303", + "current_sha256": "2722c34645f4256f20ce31205738f2f5712ab5dd5cc6fcf9f1180d0be5aa0303", + "comment_removal_exact": true + }, + { + "path": "CoreReader/Choice.lean", + "snapshot_sha256": "b28728df12ed7e73edb5569604cd2541c0ebd815ae3aaa0812e6557dece1d1ba", + "current_sha256": "b28728df12ed7e73edb5569604cd2541c0ebd815ae3aaa0812e6557dece1d1ba", + "comment_removal_exact": true + }, + { + "path": "CoreReader/Engineering/Domain.lean", + "snapshot_sha256": "0ed052c3692d8c91a41eed60bb0cba6ca033a7c9d1163aac66b32e4291927377", + "current_sha256": "9adc72e3a072d16aefb0e12a55584caa87205fc484aea488cdd80a785a8ff90b", + "comment_removal_exact": true + }, + { + "path": "CoreReader/Engineering/Integration.lean", + "snapshot_sha256": "0ef31c5e8f30c6f19124351d2052ff6fbec189932f2cbfe68d978f49da480715", + "current_sha256": "a93d799be16f159b1ce9624ae977d6a7831dae5ffe28ac17542f32c6755bbb88", + "comment_removal_exact": true + }, + { + "path": "CoreReader/Engineering/Reflection.lean", + "snapshot_sha256": "22e75f3aa95123c96aa66b0ec9fd9d8ce140e7b45770bb463570a026fe039ab0", + "current_sha256": "22e75f3aa95123c96aa66b0ec9fd9d8ce140e7b45770bb463570a026fe039ab0", + "comment_removal_exact": true + }, + { + "path": "CoreReader/Engineering/SelfApplication.lean", + "snapshot_sha256": "323a76292ea7496c22ab1c0bd60b52de2b79eee29bb5800d233537d30629fc0e", + "current_sha256": "323a76292ea7496c22ab1c0bd60b52de2b79eee29bb5800d233537d30629fc0e", + "comment_removal_exact": true + }, + { + "path": "CoreReader/Engineering/Values.lean", + "snapshot_sha256": "ccd45bf23d2f47c41d1b2f9955d753e290687d951a0c55af41ab9a63b9a8d9cb", + "current_sha256": "ccd45bf23d2f47c41d1b2f9955d753e290687d951a0c55af41ab9a63b9a8d9cb", + "comment_removal_exact": true + }, + { + "path": "CoreReader/Evidence.lean", + "snapshot_sha256": "d55f33e44902cef146841cbffb65710bd7c8a3bda79d01d084edc36f019fdc96", + "current_sha256": "d55f33e44902cef146841cbffb65710bd7c8a3bda79d01d084edc36f019fdc96", + "comment_removal_exact": true + }, + { + "path": "CoreReader/Integration.lean", + "snapshot_sha256": "97e2939c0b6714b78a3ed78358e174619a5028ad5b0b5025c0d4422b4294921b", + "current_sha256": "97e2939c0b6714b78a3ed78358e174619a5028ad5b0b5025c0d4422b4294921b", + "comment_removal_exact": true + }, + { + "path": "CoreReader/Logic.lean", + "snapshot_sha256": "0ec342691766ebd83d251dcd0da3b0ae9840aed677a714bc1b01c45d89392bc0", + "current_sha256": "0ec342691766ebd83d251dcd0da3b0ae9840aed677a714bc1b01c45d89392bc0", + "comment_removal_exact": true + }, + { + "path": "CoreReader/Reflexivity.lean", + "snapshot_sha256": "48e2c74e7cbae571db1b990b9f32dd0d701f6881a8b0111d907f8861287d76fa", + "current_sha256": "48e2c74e7cbae571db1b990b9f32dd0d701f6881a8b0111d907f8861287d76fa", + "comment_removal_exact": true + }, + { + "path": "CoreReader.lean", + "snapshot_sha256": "c5574fae235419a7d6449b3ebb5d2da29d1e92a3b572c1b759438e3c470caaa9", + "current_sha256": "c5574fae235419a7d6449b3ebb5d2da29d1e92a3b572c1b759438e3c470caaa9", + "comment_removal_exact": true + }, + { + "path": "lakefile.toml", + "snapshot_sha256": "05d8ba36975f87aca61e3b0ddcacc42669539f316ba9b8eef5859961e2aa6fdc", + "current_sha256": "05d8ba36975f87aca61e3b0ddcacc42669539f316ba9b8eef5859961e2aa6fdc", + "comment_removal_exact": true + }, + { + "path": "lean-toolchain", + "snapshot_sha256": "3aac669c7a910ec2389f4e4f921b605adf6ebf2d1e0c9b9cd0be4d33f3f5db71", + "current_sha256": "3aac669c7a910ec2389f4e4f921b605adf6ebf2d1e0c9b9cd0be4d33f3f5db71", + "comment_removal_exact": true + } + ], + "composition_scope": { + "inherited_specifications": [ + "T02", + "T04", + "T07", + "T09", + "T10", + "T11", + "T12", + "T14", + "T16", + "T18" + ], + "inherited_relations_and_terms": [ + "T20", + "T21" + ], + "domain_specifications": [ + "T22", + "T24", + "T26", + "T28", + "T29", + "T31", + "T33", + "T35" + ], + "domain_reflexivity": "T37", + "application": "T38 jointly satisfies every represented applicable inherited and domain obligation on one concrete context. T39 satisfies every inherited obligation with actual domain applicability and no cost exception, but declines the additional priority. Limits and permissions remain intact; not every possible cost or condition must apply in each instance." + }, + "findings": [ + { + "id": "F07", + "severity": "blocking-correspondence", + "title": "Whole held normative-content coverage lacks a faithful link", + "targets": [ + "T20", + "T37", + "T38", + "T39" + ], + "detail": "See immutable companion report. This does not assert actual Inherited or Domain fields false; missing source-to-theory preservation is the defect.", + "probes_executed": "Source unfolding only; no Lean mutation probe" + }, + { + "id": "F08", + "severity": "blocking-correspondence", + "title": "Own actual generation/assessment rules lack explicit self-assessment objects", + "targets": [ + "T20", + "T37", + "T38", + "T39" + ], + "detail": "See immutable companion report. Real staticBatch criticism is valid but does not replace scrutiny of adopted Reflection rules.", + "probes_executed": "All ReviewObject/test/Model.rule branches inspected; no Lean mutation probe" + } + ], + "formal_evidence": { + "directory": "SoftwareEngineering/lean/philosophy/evidence/checks/2026-09-14T17-35-30.437Z-29702-09a03c", + "files": { + "lake-build.log": "808d9461e64a100a7f9d98c33d99e709776f281ee0a794dbe67eac9bc8cfffbf", + "lake-build.json": "b0f40d94a96382293b4742adf9db7ad9a8134d95b7f77a346f45059c8f3634c8", + "lean-audit.log": "99418de9ec07c47d539b590244f87637f223145edbb506fd48edb44fbd515540", + "lean-audit.json": "0114e837930b09757cb6222e43935b77fab631dba37c5b41c35867ae7811500a", + "declaration-types.json": "caf75edf2c574e4aee6176b111e206f4090ea2eed689477822ec7f9b399a3402", + "execution-identity.json": "b164dbc8fd80322ded2cd75e86f891b69f7b14e3f8a7b7b18ca39442ef410c12", + "inputs-sha256.json": "b3f1f2d1211752197b21bc5ef22fb70dc915c3071e242ff01fdbe96ee6e31df8" + }, + "observed": "Actual isolated build/audit status 0; 59 actual declaration types; only propext/Classical.choice/Quot.sound; inputs match current recorded project files.", + "limitations": "Runtime identity not approval; checker semantic status not evaluated and targets incomplete; empty historical domain-build-19.log remains uncorrected." + }, + "targets": [ + { + "id": "T01", + "status": "accepted-bounded", + "sources": [ + { + "unit": "organon.preamble", + "clause": "p1" + }, + { + "unit": "organon.preamble", + "clause": "p2" + }, + { + "unit": "organon.charter.overview", + "clause": "p1" + }, + { + "unit": "organon.charter.overview", + "clause": "p2" + }, + { + "unit": "organon.charter.overview", + "clause": "p3" + }, + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "extensions", + "clause": "p1" + } + ], + "reason": "Disclosed documentary boundary or preserved source review and exact-byte repair reuse.", + "prior_judgment": null, + "findings": [], + "declarations": [], + "semantic_cases": [], + "completion_status": "incomplete" + }, + { + "id": "T02", + "status": "accepted-bounded", + "sources": [ + { + "unit": "organon.charter.overview", + "clause": "p2" + }, + { + "unit": "organon.charter.overview", + "clause": "p3" + }, + { + "unit": "organon.charter.self-transcendence", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.orientation", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.non-finality", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p2" + }, + { + "unit": "organon.relationships.terms", + "clause": "p1" + } + ], + "reason": "采用价值与可修订分离,所有FormKind含方法/原则;稳定与外部资源实例有具体操作内容。", + "prior_judgment": { + "id": "T02", + "status": "accepted", + "reason": "采用价值与可修订分离,所有FormKind含方法/原则;稳定与外部资源实例有具体操作内容。", + "findings": [], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Adopted.generationSpecification", + "actual_type_sha256": "4d07b8deec9112ff5d3e7fe744c159c254580260c78b82be6dd64347e8a9a4eb" + }, + { + "name": "CoreReader.Adopted.generationCases", + "actual_type_sha256": "430a91318477db0305b3107b81f9df39652fa27673fdc38705a86f8e158ca138" + } + ], + "semantic_cases": [ + { + "id": "positive_valued_open_forms", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "negative_permission_only", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "positive_stability", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "external_collaboration", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T03", + "status": "accepted-bounded", + "sources": [ + { + "unit": "organon.charter.self-transcendence.orientation", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.non-finality", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + } + ], + "reason": "具体构造/复制膨胀、资源依赖、announcement及同transition支持;正负分支具实际反例。", + "prior_judgment": { + "id": "T03", + "status": "accepted", + "reason": "具体构造/复制膨胀、资源依赖、announcement及同transition支持;正负分支具实际反例。", + "findings": [], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Adopted.generationLimits012", + "actual_type_sha256": "69058c75db607f675c730d92da7dd1c6ee27d75385f4ac4ff717bd9fc7e925b2" + } + ], + "semantic_cases": [ + { + "id": "permission_without_value", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "orientation_without_progress", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "count_growth_without_capability", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "collaborative_nonautonomous_progress", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "claim_without_achievement", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "achievement_support_for_same_claim", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T04", + "status": "accepted-bounded", + "sources": [ + { + "unit": "organon.charter.consistency", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "p1" + } + ], + "reason": "whole-theory语义Consequence、同context比较、真实revisionIdentity/SameContent报告约束。", + "prior_judgment": { + "id": "T04", + "status": "accepted", + "reason": "whole-theory语义Consequence、同context比较、真实revisionIdentity/SameContent报告约束。", + "findings": [], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Adopted.consistencySpecification", + "actual_type_sha256": "cf239ba7292f80875f93e960cd3417c226a8727f57f11e1ec4af4564caef076d" + }, + { + "name": "CoreReader.Adopted.consistencyCases", + "actual_type_sha256": "16a20441e5650e4992e046ae4eeb2a1867f573730aa1dc402ca70508bb1802a6" + } + ], + "semantic_cases": [ + { + "id": "joint_only_contradiction", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "changed_scope_not_concealed", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "revision_withdraws_old", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "incompatible_same_context", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T05", + "status": "accepted-bounded", + "sources": [ + { + "unit": "organon.charter.consistency", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "p1" + } + ], + "reason": "泛型反结论定理和joint conflict/时间slice/不同context/重排证明齐备;不推现实正确性。", + "prior_judgment": { + "id": "T05", + "status": "accepted", + "reason": "泛型反结论定理和joint conflict/时间slice/不同context/重排证明齐备;不推现实正确性。", + "findings": [], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Adopted.consistencyConsequences", + "actual_type_sha256": "4b3231ac25a534c2699cd8f548a59a7d8beb1cb3923456f10c95081a3b6b5be3" + }, + { + "name": "CoreReader.Adopted.consistencyCases", + "actual_type_sha256": "16a20441e5650e4992e046ae4eeb2a1867f573730aa1dc402ca70508bb1802a6" + } + ], + "semantic_cases": [ + { + "id": "pair_conflict", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "joint_premise_conflict", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "old_new_separate_times", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "distinct_context_judgments", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "truthful_semantic_change_and_reordering", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T06", + "status": "accepted-bounded", + "sources": [ + { + "unit": "organon.charter.consistency.meaning", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + } + ], + "reason": "假定真值与实际false世界、显式遗漏问题、可相容不蕴含、共享预算tension均有内容。", + "prior_judgment": { + "id": "T06", + "status": "accepted", + "reason": "假定真值与实际false世界、显式遗漏问题、可相容不蕴含、共享预算tension均有内容。", + "findings": [], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Adopted.consistencyLimits012", + "actual_type_sha256": "1bb1429eb084c222d9a84341c2d6cae05e8c83c1374bbbab8402a372099649cc" + } + ], + "semantic_cases": [ + { + "id": "different_contexts", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "tension_compatible", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "consistent_false_assumption", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "consistent_omitted_question", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "compatible_not_entailed", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T07", + "status": "accepted-bounded", + "sources": [ + { + "unit": "organon.charter.reflexivity", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + } + ], + "reason": "formation/application/revision真实method内容和适用条件有证据;grounds_on_grounds价值后果连接仍待F06。", + "prior_judgment": { + "id": "T07", + "status": "accepted", + "reason": "formation/application/revision真实method内容和适用条件有证据;grounds_on_grounds价值后果连接仍待F06。", + "findings": [ + "F06" + ], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete", + "previous": "pending", + "completion": "incomplete", + "repair_record": "source-code-review-adopted-f01-f06-final.json" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Adopted.reflexivitySpecification", + "actual_type_sha256": "d8084253926a4e9a9b2b9d6ccea7fcba129de72b8412ec4bd30c08a9bdf254bc" + }, + { + "name": "CoreReader.Adopted.reflexivityCases012", + "actual_type_sha256": "55a9d738a39137aeb7cf0ee474c532a636dc2a59451613848747030a756b29e7" + } + ], + "semantic_cases": [ + { + "id": "self_applicable", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "self_inapplicable", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "principle_formation", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "principle_application", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "principle_revision", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "grounds_on_grounds", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T08", + "status": "accepted-bounded", + "sources": [ + { + "unit": "organon.charter.reflexivity.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + }, + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "organon.grounds", + "clause": "p1" + } + ], + "reason": "自测具体错误、自生局部不足、开放而自免及完整Charter+具体不足Grounds有限countermodel可解释;后续G012变更须重查。", + "prior_judgment": { + "id": "T08", + "status": "accepted", + "reason": "自测具体错误、自生局部不足、开放而自免及完整Charter+具体不足Grounds有限countermodel可解释;后续G012变更须重查。", + "findings": [], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Adopted.reflexivityLimits012", + "actual_type_sha256": "6aaa9a96ab7f8fe3ebe04633ee7e9ae054eafa88e7e8289179d143ee96e46d05" + } + ], + "semantic_cases": [ + { + "id": "self_assessed_incorrect", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "self_generated_unsupported", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "open_but_self_exempt", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "charter_not_general_grounds", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T09", + "status": "accepted-bounded", + "sources": [ + { + "unit": "organon.grounds", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + } + ], + "reason": "F01:规范接口未固定nature-appropriate原任务,sameclaim可被新假设/类型替代。现scoped正负案例本身仍成立。", + "prior_judgment": { + "id": "T09", + "status": "accepted", + "reason": "F01:规范接口未固定nature-appropriate原任务,sameclaim可被新假设/类型替代。现scoped正负案例本身仍成立。", + "findings": [ + "F01" + ], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete", + "previous": "rejected", + "completion": "incomplete", + "repair_record": "source-code-review-adopted-f01-f06-final.json" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Adopted.Grounds012", + "actual_type_sha256": "65ead33e1cc510ec07082dde80dbec28ca36d80391c18e2ca6df7ed3e1353029" + }, + { + "name": "CoreReader.Adopted.groundsCases012", + "actual_type_sha256": "5d659ec603f559d1be5abf4df0466b2daee1633dcfbf70194c0b8ccf9640e40f" + } + ], + "semantic_cases": [ + { + "id": "articulable_supported", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "articulable_unsupported", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "scope_overreach", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "strength_overreach", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T10", + "status": "accepted-bounded", + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "p2" + } + ], + "reason": "经验有限world/record适配含非空scope、uncertainty及支持关系;温度与另一坐标/预算错配反例相关。接受显式经验任务片段。", + "prior_judgment": { + "id": "T10", + "status": "accepted", + "reason": "经验有限world/record适配含非空scope、uncertainty及支持关系;温度与另一坐标/预算错配反例相关。接受显式经验任务片段。", + "findings": [], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Adopted.empiricalSpecification", + "actual_type_sha256": "9f534ab1f51da3b82f8edf1d35b0dfab34dfe042d10c44582f04b4dce6569ef2" + }, + { + "name": "CoreReader.Adopted.empiricalCases012", + "actual_type_sha256": "fba89ddcd1cf1f745deec2bbdb86e1434e01d6fc73f99c6bf690331560f736f6" + } + ], + "semantic_cases": [ + { + "id": "observed_relevant", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "repeatable_irrelevant", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "measured_wrong_scope", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "uncertain_limited", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T11", + "status": "accepted-bounded", + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + } + ], + "reason": "由2推出3及emptyTheory同countervaluation不蕴含;检查完成与正向支持分离。", + "prior_judgment": { + "id": "T11", + "status": "accepted", + "reason": "由2推出3及emptyTheory同countervaluation不蕴含;检查完成与正向支持分离。", + "findings": [], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Adopted.inferentialSpecification", + "actual_type_sha256": "d56b013c37bfeb071f171cb3f552b8775a79eee535305a78d2d9551b86c03c16" + }, + { + "name": "CoreReader.Adopted.inferentialCases012", + "actual_type_sha256": "b37768f2ff32da55daf97b29dc027bfa78aa1a1f2456c80937dde7aa64a5c515" + } + ], + "semantic_cases": [ + { + "id": "valid_inference", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "compatible_unentailed", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "false_inference_detected", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T12", + "status": "accepted-bounded", + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + } + ], + "reason": "采用/收益/成本及批评响应为明确有限价值procedure;非空joint witness和初始commitment非空事实后果均保留。只接受披露的procedure,不作普遍价值充分性。", + "prior_judgment": { + "id": "T12", + "status": "accepted", + "reason": "采用/收益/成本及批评响应为明确有限价值procedure;非空joint witness和初始commitment非空事实后果均保留。只接受披露的procedure,不作普遍价值充分性。", + "findings": [], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Adopted.valueSpecification", + "actual_type_sha256": "1f45a163b8b2a0db44eeaeb0910e0af6168e4674ab3a3925dcfe54e3015e3ae6" + }, + { + "name": "CoreReader.Adopted.valueCases012", + "actual_type_sha256": "ce1dba18fb8bf4611fe703b21270e3b59591f6f1cf1c40f2ee03899fa26c142a" + } + ], + "semantic_cases": [ + { + "id": "reasoned_value", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "unsupported_self_assertion", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "closed_criticism", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "explicit_initial_commitment", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T13", + "status": "accepted-bounded", + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + } + ], + "reason": "清楚但假理由、无关重复观察、value非事实、自起点无需证明及定性蕴含序的片段成立。", + "prior_judgment": { + "id": "T13", + "status": "accepted", + "reason": "清楚但假理由、无关重复观察、value非事实、自起点无需证明及定性蕴含序的片段成立。", + "findings": [], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Adopted.groundsLimits012", + "actual_type_sha256": "b404dce33c3fbf86c65d3824e2fceaf5f0a1f312ce1edc1f0a9e9251af9ccad3" + } + ], + "semantic_cases": [ + { + "id": "clear_false_reason", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "repeatable_wrong_object", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "value_not_fact", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "initial_value_without_selfproof", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "qualitative_proportionality", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T14", + "status": "accepted-bounded", + "sources": [ + { + "unit": "organon.grounds.scope", + "clause": "p1" + }, + { + "unit": "organon.grounds.scope", + "clause": "p2" + }, + { + "unit": "organon.grounds.scope", + "clause": "p3" + } + ], + "reason": "scope account链接实际input0、relevance及各method用途的内容命题;非 universal method chain。", + "prior_judgment": { + "id": "T14", + "status": "accepted", + "reason": "scope account链接实际input0、relevance及各method用途的内容命题;非 universal method chain。", + "findings": [], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Adopted.scopeSpecification", + "actual_type_sha256": "01857cd86d39ca8bc2d54d15555ebed9fc9fa6a0bd40196743e5f1fbbcb966b7" + }, + { + "name": "CoreReader.Adopted.scopeCases012", + "actual_type_sha256": "e503dd4f8dacf02303b9bd7e56977a56feee218c1c677d8836c15039e83655a8" + } + ], + "semantic_cases": [ + { + "id": "local_scope_declared", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "omitted_relevant_difference", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "measurement_role", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "repetition_role", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "framework_role", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T15", + "status": "accepted-bounded", + "sources": [ + { + "unit": "organon.grounds.scope", + "clause": "p1" + }, + { + "unit": "organon.grounds.scope", + "clause": "p2" + }, + { + "unit": "organon.grounds.scope", + "clause": "p3" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "p1" + } + ], + "reason": "共享局部记录可有全局异世界;单观察支持/未重现、随机正weight变结果、无观察推论分支有实际内容。", + "prior_judgment": { + "id": "T15", + "status": "accepted", + "reason": "共享局部记录可有全局异世界;单观察支持/未重现、随机正weight变结果、无观察推论分支有实际内容。", + "findings": [], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Adopted.scopeLimits012", + "actual_type_sha256": "a286f42a08d68addaec58cb6b0b9656968db614439bd753425f3972b29d8125c" + } + ], + "semantic_cases": [ + { + "id": "equal_local_different_global", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "excluded_difference", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "one_observation_limited_support", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "varying_random_outcomes", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "qualitative_unmeasured_judgment", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T16", + "status": "accepted-bounded", + "sources": [ + { + "unit": "organon.grounds.capabilities", + "clause": "p1" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + } + ], + "reason": "实际Process输出/解释certificate约定区分,exact-object推论支持和外部评估者7/42区分;理解仅覆盖该应用解释契约。", + "prior_judgment": { + "id": "T16", + "status": "accepted", + "reason": "实际Process输出/解释certificate约定区分,exact-object推论支持和外部评估者7/42区分;理解仅覆盖该应用解释契约。", + "findings": [], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Adopted.capabilitySpecification", + "actual_type_sha256": "908a244789ebae715ab94703060109000c2369e1c4735c6cdb48a096243f3c04" + }, + { + "name": "CoreReader.Adopted.capabilityCases012", + "actual_type_sha256": "8b65b3510d304fccc5db3e8584da21c74e083b848f722afa20a46057993d6a51" + } + ], + "semantic_cases": [ + { + "id": "external_output_capability", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "application_requires_understanding", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "own_capability_assessment", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T17", + "status": "accepted-bounded", + "sources": [ + { + "unit": "organon.grounds.capabilities", + "clause": "p1" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p2" + } + ], + "reason": "同过程无解释certificate与输出正确并存;各inventoryKind复制不新增operation。", + "prior_judgment": { + "id": "T17", + "status": "accepted", + "reason": "同过程无解释certificate与输出正确并存;各inventoryKind复制不新增operation。", + "findings": [], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Adopted.capabilityLimits012", + "actual_type_sha256": "8efa4107232374dd4f308f0f4c19f39b706da292b2cb4042aba290ade3368d52" + } + ], + "semantic_cases": [ + { + "id": "reliable_opaque_generator", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "high_count_no_stronger_capability", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "externally_articulated_no_introspection", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T18", + "status": "accepted-bounded", + "sources": [ + { + "unit": "organon.grounds.implementations", + "clause": "p1" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p2" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + } + ], + "reason": "真实output/cost/explanation/domain/trace内容支持理由;status-only排除为采用规范,conventional可因output获得优先。", + "prior_judgment": { + "id": "T18", + "status": "accepted", + "reason": "真实output/cost/explanation/domain/trace内容支持理由;status-only排除为采用规范,conventional可因output获得优先。", + "findings": [], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Adopted.choiceSpecification", + "actual_type_sha256": "4b2ffafbf066633850901441a4978132cc3d84f95bef9c803f56a17866762054" + }, + { + "name": "CoreReader.Adopted.choiceCases012", + "actual_type_sha256": "36f89bc4962aa87be316945afd3147dd30111dfdca8902a41b0392a2bda28c04" + } + ], + "semantic_cases": [ + { + "id": "named_only_rejected", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "conventional_grounded_priority", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "method_internal_reason", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "own_philosophy_status_only", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T19", + "status": "accepted-bounded", + "sources": [ + { + "unit": "organon.grounds.implementations", + "clause": "p1" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p2" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "p1" + } + ], + "reason": "单可行、不同整体输出/内部解释、相同局部差全局;额外规则独立仅相对准确assessment,未冒充完整Grounds。", + "prior_judgment": { + "id": "T19", + "status": "accepted", + "reason": "单可行、不同整体输出/内部解释、相同局部差全局;额外规则独立仅相对准确assessment,未冒充完整Grounds。", + "findings": [], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Adopted.choiceLimits012", + "actual_type_sha256": "84bdf70f43a217d10ccf0d7a8179aea2b586ab845a7c8f3a2f087089c6098874" + } + ], + "semantic_cases": [ + { + "id": "single_feasible_conventional", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "internal_reason_distinguishes", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "unequal_open_options", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "local_equal_global_difference", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "added_choice_not_from_general_assessment", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T20", + "status": "pending-correspondence", + "sources": [ + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + } + ], + "reason": "Actual shared-context value, choice, capability and claim duties exist; whole held normative-content and own evaluator-object correspondence remain F07/F08.", + "prior_judgment": null, + "findings": [ + "F07", + "F08" + ], + "declarations": [ + { + "name": "CoreReader.Engineering.inheritedMutualApplication", + "actual_type_sha256": "3845e3f8d1cd47445374c4ca8f5e8c2f8a66daf6b82904ae7c84c40335e80b32" + }, + { + "name": "CoreReader.Engineering.inheritedMutualCases", + "actual_type_sha256": "d020580ca71e08adc997353d140f057bf6886f1f087307be95d6504affdf8d54" + } + ], + "semantic_cases": [ + { + "id": "own_grounds_articulable", + "status": "pending-aggregate-correspondence", + "scope": "actual Root source plus audit" + }, + { + "id": "own_capability_supported", + "status": "pending-aggregate-correspondence", + "scope": "actual Root source plus audit" + }, + { + "id": "own_choice_not_status_only", + "status": "pending-aggregate-correspondence", + "scope": "actual Root source plus audit" + }, + { + "id": "relevant_self_application", + "status": "pending-aggregate-correspondence", + "scope": "actual Root source plus audit" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T21", + "status": "accepted-bounded", + "sources": [ + { + "unit": "organon.relationships.terms", + "clause": "p1" + } + ], + "reason": "Disclosed documentary boundary or preserved source review and exact-byte repair reuse.", + "prior_judgment": null, + "findings": [], + "declarations": [], + "semantic_cases": [], + "completion_status": "incomplete" + }, + { + "id": "T22", + "status": "accepted-bounded", + "sources": [ + { + "unit": "software-engineering.purpose", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p2" + }, + { + "unit": "software-engineering.purpose", + "clause": "p3" + } + ], + "reason": "维护者路径所需知识工具有内容,继续/短命仅采用披露的有限日程判据;不声称通用生命周期定义。", + "prior_judgment": { + "id": "T22", + "status": "accepted", + "reason": "维护者路径所需知识工具有内容,继续/短命仅采用披露的有限日程判据;不声称通用生命周期定义。", + "findings": [], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Engineering.ActivityScope", + "actual_type_sha256": "fdfa84c29643bd37a72d614541ecf59b4b7efdf606ac4b7480cb02fe3e4c8382" + }, + { + "name": "CoreReader.Engineering.subjectLifecycleCases", + "actual_type_sha256": "a2d126370b7fef5af4645ef64d85b169467518bfb8f76269b41f47f82e0bd02b" + } + ], + "semantic_cases": [ + { + "id": "successor_maintainer", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "agent_maintainer", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "continuing_labeled_temporary", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "genuinely_temporary", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "bounded_prototype", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "retiring_system", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T23", + "status": "accepted-bounded", + "sources": [ + { + "unit": "software-engineering.purpose", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p2" + }, + { + "unit": "software-engineering.purpose", + "clause": "p3" + } + ], + "reason": "同一privateLayout路径原作者可用而successor不可用;label不决定实际日程,passive action语言界限明确。", + "prior_judgment": { + "id": "T23", + "status": "accepted", + "reason": "同一privateLayout路径原作者可用而successor不可用;label不决定实际日程,passive action语言界限明确。", + "findings": [], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Engineering.subjectLimits", + "actual_type_sha256": "4d0b23030599912d1ad72613e9956d5dd179d987aa64f0a694f74e85847b2a2b" + } + ], + "semantic_cases": [ + { + "id": "author_only_private_knowledge", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "successor_missing_path", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "false_temporary_label", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "passive_artifact", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T24", + "status": "accepted-bounded", + "sources": [ + { + "unit": "software-engineering.purpose", + "clause": "p3" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "reason": "适用、必要requirements失败及cost例外真案例保留;no_extensibility_maximum冻结分支未由complexity最大值满足,F02。", + "prior_judgment": { + "id": "T24", + "status": "accepted", + "reason": "适用、必要requirements失败及cost例外真案例保留;no_extensibility_maximum冻结分支未由complexity最大值满足,F02。", + "findings": [ + "F02" + ], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete", + "completion": "incomplete", + "repair_record": "source-code-review-domain-r2.json" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Engineering.EvolutionPriority", + "actual_type_sha256": "8609cb39944d272540e985febb940328bc4a85a6e22fe06e652f4c95bd043ddb" + }, + { + "name": "CoreReader.Engineering.priorityConditionsCases", + "actual_type_sha256": "3206e3bed26ebff1742e044beabbfcca534354e4895936cd6496b4af5a5485e9" + } + ], + "semantic_cases": [ + { + "id": "ordinary_priority", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "missing_behavior", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "missing_safety", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "missing_performance", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "missing_other_necessary", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "concrete_cost_override", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "unexplained_departure", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "no_extensibility_maximum", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T25", + "status": "accepted-bounded", + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "reason": "泛型rule+实际conditions+无departure推出所选evolvable;三个samectx选择例具真实关系,未从Core推出priority。", + "prior_judgment": { + "id": "T25", + "status": "accepted", + "reason": "泛型rule+实际conditions+无departure推出所选evolvable;三个samectx选择例具真实关系,未从Core推出priority。", + "findings": [], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Engineering.priorityWhenApplicable", + "actual_type_sha256": "6b1efb7cab71c9b837ce57e666f331112f6416f18a59675e8119416b3d7a39a6" + }, + { + "name": "CoreReader.Engineering.priorityChoices", + "actual_type_sha256": "d4cbb2cea4f863c0a900531a90fd4e36cd04ad50df57b340871001d6fb01b349" + } + ], + "semantic_cases": [ + { + "id": "applicable_choose_evolution", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "applicable_choose_simple_violates_domain", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "threat_allows_departure_with_account", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T26", + "status": "accepted-bounded", + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "reason": "在给定grounds任务/可信解释的有限plan/history/knowledge适配下,单实现/想象无对应支持/修订forecast可读。非全部现实可信性判据。", + "prior_judgment": { + "id": "T26", + "status": "accepted", + "reason": "在给定grounds任务/可信解释的有限plan/history/knowledge适配下,单实现/想象无对应支持/修订forecast可读。非全部现实可信性判据。", + "findings": [], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Engineering.CredibleDirection", + "actual_type_sha256": "1906e98dd6d042fc973fb93506c24accc024a7643adaddd05e071030c8b5682b" + }, + { + "name": "CoreReader.Engineering.credibilityCases", + "actual_type_sha256": "b5d172388be7bcd1bdbeea1f07436b61458bd02c0e714dc83b7d7565adefa6c9" + } + ], + "semantic_cases": [ + { + "id": "committed_plan_one_implementation", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "domain_knowledge", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "applicable_history", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "conceivable_only", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "revised_forecast", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T27", + "status": "accepted-bounded", + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "reason": "可信单实现及无支持想象例成立;不最大化演化能力/保留所有可能性的相应能力关系缺失,F02。", + "prior_judgment": { + "id": "T27", + "status": "accepted", + "reason": "可信单实现及无支持想象例成立;不最大化演化能力/保留所有可能性的相应能力关系缺失,F02。", + "findings": [ + "F02" + ], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete", + "completion": "incomplete", + "repair_record": "source-code-review-domain-r2.json" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Engineering.credibilityLimits", + "actual_type_sha256": "76415ebe0bbc33c3827da7db33b1e89e3f676b7cf0f4f39df5401beeda5f40c4" + } + ], + "semantic_cases": [ + { + "id": "one_implementation_credible", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "imagined_unwarranted", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "selective_evolution", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "qualitative_tradeoff", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T28", + "status": "accepted-bounded", + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "reason": "七维cost与各自容量/命名objective及departure指定连接;无实际threat借口拒绝。仅该有限cost模型。", + "prior_judgment": { + "id": "T28", + "status": "accepted", + "reason": "七维cost与各自容量/命名objective及departure指定连接;无实际threat借口拒绝。仅该有限cost模型。", + "findings": [], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Engineering.JustifiedDeparture", + "actual_type_sha256": "f6c50ef1eaca65b4a3886bcbc5ccb11393e89a2d7baf8f6980b6a58f9d0719a4" + }, + { + "name": "CoreReader.Engineering.costCases", + "actual_type_sha256": "0159f38d1da3fe90524ce5a5d2e2b1d3a4fc5a14c6a76a6fbc07a158d16edd90" + } + ], + "semantic_cases": [ + { + "id": "understanding_threat", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "construction_threat", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "diagnosis_threat", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "verification_threat", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "coordination_threat", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "operation_threat", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "migration_threat", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "unsupported_cost_excuse", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T29", + "status": "accepted-bounded", + "sources": [ + { + "unit": "software-engineering.evolution-meaning", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p2" + } + ], + "reason": "六类state字段变化、path可行及independent/coordinated差别有内容;obligation treatment依赖待修ContractChangeAccount,F03。", + "prior_judgment": { + "id": "T29", + "status": "accepted", + "reason": "六类state字段变化、path可行及independent/coordinated差别有内容;obligation treatment依赖待修ContractChangeAccount,F03。", + "findings": [], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete", + "completion": "incomplete", + "repair_record": "source-code-review-domain-r2.json" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Engineering.EvolutionClaim", + "actual_type_sha256": "9c0c528a387fd26adf8c44acbd1e97da3c991c6544f40f31c0a8c3adb2ccd2f7" + }, + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "actual_type_sha256": "ccab4c5ed0bb676cef2d8435b8252630c0bc2f32d0ce9023156532deb6b77a1e" + } + ], + "semantic_cases": [ + { + "id": "addition", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "replacement", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "deletion", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "withdrawal", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "redrawing", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "migration", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "independent", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "coordinated", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "preserve_obligation", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "revise_obligation", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T30", + "status": "accepted-bounded", + "sources": [ + { + "unit": "software-engineering.evolution-meaning", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p2" + } + ], + "reason": "easy_add/hard_exit和贵migration有限例成立;一设计一维优势不表示全维优势的跨设计比较未实现,F02。", + "prior_judgment": { + "id": "T30", + "status": "accepted", + "reason": "easy_add/hard_exit和贵migration有限例成立;一设计一维优势不表示全维优势的跨设计比较未实现,F02。", + "findings": [ + "F02" + ], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete", + "completion": "incomplete", + "repair_record": "source-code-review-domain-r2.json" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Engineering.evolutionDimensionsLimits", + "actual_type_sha256": "ba2af856a831323eaa2344e83084a08689b7a287f6a8542edcef6fb0c2e57af7" + } + ], + "semantic_cases": [ + { + "id": "easy_add_hard_exit", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "independent_easy_coordinated_hard", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "some_change_expensive_permitted", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T31", + "status": "accepted-bounded", + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p2" + } + ], + "reason": "actual path派生propagation/work、前后finite合同观察、fixed/live反例和withdrawal代价;work单位为显式假定。", + "prior_judgment": { + "id": "T31", + "status": "accepted", + "reason": "actual path派生propagation/work、前后finite合同观察、fixed/live反例和withdrawal代价;work单位为显式假定。", + "findings": [], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Engineering.StructuralAccount", + "actual_type_sha256": "45df6c2c2383df05162c2a265ba6daf5debbdf46847dc9de1801f881eb00db1e" + }, + { + "name": "CoreReader.Engineering.structuralCases", + "actual_type_sha256": "93ac47c7e7132943abd11f6a6e9ce897c2b641d89e753d83bcd29509e80f572e" + } + ], + "semantic_cases": [ + { + "id": "contract_and_work_comparison", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "propagation_relation", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "cross_boundary_obligation", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "fixed_assumption", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "withdrawal_cost", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T32", + "status": "accepted-bounded", + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p2" + } + ], + "reason": "common-object and actual-boundary defect resolved; frozen same-work case now totals17→18 and needs precise preservation judgment or supplementary equal-work instance", + "prior_judgment": { + "id": "T32", + "status": "accepted", + "reason": "common-object and actual-boundary defect resolved; frozen same-work case now totals17→18 and needs precise preservation judgment or supplementary equal-work instance", + "findings": [ + "F04" + ], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete", + "completion": "incomplete", + "repair_record": "source-code-review-domain-same-work-final.json", + "previous": "pending" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Engineering.structureNotCapability", + "actual_type_sha256": "2c09939db7dbc6561ff01284d1187a4272120050885c7743d2227d2a6e133ea9" + } + ], + "semantic_cases": [ + { + "id": "same_shape_broken_order", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "many_modules_shared_obligation", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "named_pattern_no_change_path", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "new_boundary_same_work", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T33", + "status": "accepted-bounded", + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "p3" + } + ], + "reason": "有限preservation/revision及outside-scope例真;实际changed obligations/affected parties匹配不足,F03。", + "prior_judgment": { + "id": "T33", + "status": "accepted", + "reason": "有限preservation/revision及outside-scope例真;实际changed obligations/affected parties匹配不足,F03。", + "findings": [ + "F03" + ], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete", + "completion": "incomplete", + "repair_record": "source-code-review-domain-r2.json" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Engineering.ContractChangeAccount", + "actual_type_sha256": "c58d92d3f41481a1b24941446085e8161c5dcb32cc266487f9734c2c03c8d3fe" + }, + { + "name": "CoreReader.Engineering.contractCases", + "actual_type_sha256": "d577c98b03b1349b8acdc20e24a2d1141ea92e5ce49ab73e3518385e0981adeb" + } + ], + "semantic_cases": [ + { + "id": "preserve_identified_contract", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "deliberate_revision_with_account", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "revision_missing_parties", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "retired_historical_behavior", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "alternative_procedure", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T34", + "status": "accepted-bounded", + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "p3" + } + ], + "reason": "泛型all-observations-preserve及变观察反证均真;changed_failure_obligation只是独立字段3≠5,F03。", + "prior_judgment": { + "id": "T34", + "status": "accepted", + "reason": "泛型all-observations-preserve及变观察反证均真;changed_failure_obligation只是独立字段3≠5,F03。", + "findings": [ + "F03" + ], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete", + "completion": "incomplete", + "repair_record": "source-code-review-domain-r2.json" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Engineering.contractPreservation", + "actual_type_sha256": "d9078e49c446deddda26e669891464c695136710e6b34620ca8ee4f08bdafbed" + }, + { + "name": "CoreReader.Engineering.contractDistinctions", + "actual_type_sha256": "bc0f83a82833ba24fc73f01ff24ac513e5ce42fec36a8195c70d516365a07a28" + } + ], + "semantic_cases": [ + { + "id": "order_preserving_refactor", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "sorted_order_revision", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "changed_failure_obligation", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "outside_scope_difference", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T35", + "status": "accepted-bounded", + "sources": [ + { + "unit": "software-engineering.revision", + "clause": "p2" + }, + { + "unit": "software-engineering.revision", + "clause": "p1" + } + ], + "reason": "当前ctx identity和记录内部变化例已实现;固定历史事件/本次任务绑定与泛化scope待F05。", + "prior_judgment": { + "id": "T35", + "status": "accepted", + "reason": "当前ctx identity和记录内部变化例已实现;固定历史事件/本次任务绑定与泛化scope待F05。", + "findings": [ + "F05" + ], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete", + "completion": "incomplete", + "repair_record": "source-code-review-domain-r2.json" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Engineering.RevisionAccount", + "actual_type_sha256": "865a4c6c542f07f6b0ce44a67e98175239ef389738b16bc6071ccebffae61c8b" + }, + { + "name": "CoreReader.Engineering.revisionCases", + "actual_type_sha256": "8e2008450f4c7a80eca24630a18e6c77bf570055daee2c75c2577987c06ff629" + } + ], + "semantic_cases": [ + { + "id": "revised_change_forecast", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "changed_maintainers", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "changed_cost", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "changed_objective", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "failed_prediction_preserved", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "justified_retention", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T36", + "status": "accepted-bounded", + "sources": [ + { + "unit": "software-engineering.revision", + "clause": "p2" + }, + { + "unit": "software-engineering.revision", + "clause": "p1" + } + ], + "reason": "固定revisionRecord改report拒绝、agree但3≠5和局部成功反例成立;通用historical correspondence及stable record同任务限度待F05。", + "prior_judgment": { + "id": "T36", + "status": "accepted", + "reason": "固定revisionRecord改report拒绝、agree但3≠5和局部成功反例成立;通用historical correspondence及stable record同任务限度待F05。", + "findings": [ + "F05" + ], + "acceptance_scope": "仅本次已读源及其披露的数学/有限应用片段;未完成最终blind backtranslation和完整Root集成审查", + "completion_status": "incomplete", + "completion": "incomplete", + "repair_record": "source-code-review-domain-r2.json" + }, + "findings": [], + "declarations": [ + { + "name": "CoreReader.Engineering.revisionLimits", + "actual_type_sha256": "071a3e5cddf46166eacbd56285cdb4abb9f11a94e50e8bf00f8bc100f01026d0" + } + ], + "semantic_cases": [ + { + "id": "past_failure_not_rewritten", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "agreement_with_bad_case", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "local_success_global_failure", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + }, + { + "id": "open_stable_design", + "status": "accepted-bounded-reused", + "scope": "preserved independent source review and repairs; comment-only identity verified" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T37", + "status": "pending-correspondence", + "sources": [ + { + "unit": "organon.relationships.roles", + "clause": "p3" + }, + { + "unit": "extensions", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.revision", + "clause": "p2" + } + ], + "reason": "Actual priority object and static/live criticism are valid locally; full consistency and own adopted evaluator objects remain F07/F08.", + "prior_judgment": null, + "findings": [ + "F07", + "F08" + ], + "declarations": [ + { + "name": "CoreReader.Engineering.priorityRemainsReflexive", + "actual_type_sha256": "7348e0b4e8905385dad854787ce1959aff10ba9165df95a08a4fb9e4bfec7aed" + }, + { + "name": "CoreReader.Engineering.priorityReflexiveCases", + "actual_type_sha256": "9bf307a3e762002cbd34684f2e7b5cb8f043447ba38346f6ac04df2d54c50df7" + } + ], + "semantic_cases": [ + { + "id": "priority_self_assessment", + "status": "pending-aggregate-correspondence", + "scope": "actual Root source plus audit" + }, + { + "id": "method_self_criticism", + "status": "pending-aggregate-correspondence", + "scope": "actual Root source plus audit" + }, + { + "id": "no_selfproof_from_success", + "status": "pending-aggregate-correspondence", + "scope": "actual Root source plus audit" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T38", + "status": "pending-correspondence", + "sources": [ + { + "unit": "organon.charter.overview", + "clause": "p2" + }, + { + "unit": "organon.charter.overview", + "clause": "p3" + }, + { + "unit": "organon.charter.self-transcendence", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.orientation", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.non-finality", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity.limits", + "clause": "p1" + }, + { + "unit": "organon.grounds", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + }, + { + "unit": "organon.grounds.scope", + "clause": "p1" + }, + { + "unit": "organon.grounds.scope", + "clause": "p2" + }, + { + "unit": "organon.grounds.scope", + "clause": "p3" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p1" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p2" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p1" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p2" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + }, + { + "unit": "extensions", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p2" + }, + { + "unit": "software-engineering.purpose", + "clause": "p3" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p2" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p2" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p3" + }, + { + "unit": "software-engineering.revision", + "clause": "p1" + }, + { + "unit": "software-engineering.revision", + "clause": "p2" + } + ], + "reason": "Actual shared evolvable context, complete present interfaces, requirements, extra complexity and maintainer paths proved; complete source-meaning correspondence remains F07/F08.", + "prior_judgment": null, + "findings": [ + "F07", + "F08" + ], + "declarations": [ + { + "name": "CoreReader.Engineering.jointWitness", + "actual_type_sha256": "56d1bd97b0ac6c069484812a2a975dc185a905a24ee133a780b5f23a7fdc0b59" + } + ], + "semantic_cases": [ + { + "id": "joint_all_inherited_and_domain", + "status": "pending-aggregate-correspondence", + "scope": "actual Root source plus audit" + }, + { + "id": "same_context_identity", + "status": "pending-aggregate-correspondence", + "scope": "actual Root source plus audit" + }, + { + "id": "nonempty_claims_and_principles", + "status": "pending-aggregate-correspondence", + "scope": "actual Root source plus audit" + }, + { + "id": "active_evolution_priority", + "status": "pending-aggregate-correspondence", + "scope": "actual Root source plus audit" + }, + { + "id": "content_bearing_maintainer_change", + "status": "pending-aggregate-correspondence", + "scope": "actual Root source plus audit" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T39", + "status": "pending-correspondence", + "sources": [ + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + }, + { + "unit": "extensions", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "reason": "Actual shared continuing simple choice, both requirements, credible design change, no cost/lifecycle escape, grounded alternative value all proved; complete inherited correspondence remains F07/F08.", + "prior_judgment": null, + "findings": [ + "F07", + "F08" + ], + "declarations": [ + { + "name": "CoreReader.Engineering.inheritedDoesNotEntailPriority", + "actual_type_sha256": "ad1b1b45257f57a53567b08bc87eb32bd6d8acf8395e9762a684c1116f270197" + } + ], + "semantic_cases": [ + { + "id": "all_inherited_applicable_domain_not_adopted", + "status": "pending-aggregate-correspondence", + "scope": "actual Root source plus audit" + }, + { + "id": "no_temporary_escape", + "status": "pending-aggregate-correspondence", + "scope": "actual Root source plus audit" + }, + { + "id": "no_cost_escape", + "status": "pending-aggregate-correspondence", + "scope": "actual Root source plus audit" + }, + { + "id": "genuine_priority_failure", + "status": "pending-aggregate-correspondence", + "scope": "actual Root source plus audit" + }, + { + "id": "inherited_grounds_for_other_value", + "status": "pending-aggregate-correspondence", + "scope": "actual Root source plus audit" + } + ], + "completion_status": "incomplete" + }, + { + "id": "T40", + "status": "accepted-bounded", + "sources": [ + { + "unit": "organon.preamble", + "clause": "p1" + }, + { + "unit": "organon.preamble", + "clause": "p2" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p2" + }, + { + "unit": "organon.grounds", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + }, + { + "unit": "organon.grounds.scope", + "clause": "p2" + }, + { + "unit": "organon.grounds.scope", + "clause": "p3" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p1" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p2" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p1" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + }, + { + "unit": "extensions", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p2" + }, + { + "unit": "software-engineering.purpose", + "clause": "p3" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p2" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p2" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p3" + }, + { + "unit": "software-engineering.revision", + "clause": "p1" + }, + { + "unit": "software-engineering.revision", + "clause": "p2" + } + ], + "reason": "Disclosed documentary boundary or preserved source review and exact-byte repair reuse.", + "prior_judgment": null, + "findings": [], + "declarations": [], + "semantic_cases": [], + "completion_status": "incomplete" + } + ], + "source_clauses": [ + { + "unit": "organon.preamble", + "clause": "p1", + "unit_sha256": "d612a2a8da20a4c70114c0767d79aa88269b48bcee97fc43328ae722ea890706", + "targets": [ + "T01", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "not-blocked-by-current-findings" + }, + { + "unit": "organon.preamble", + "clause": "p2", + "unit_sha256": "d612a2a8da20a4c70114c0767d79aa88269b48bcee97fc43328ae722ea890706", + "targets": [ + "T01", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "not-blocked-by-current-findings" + }, + { + "unit": "organon.charter.overview", + "clause": "p1", + "unit_sha256": "75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c", + "targets": [ + "T01" + ], + "local_status": "accepted-bounded", + "composition_status": "not-blocked-by-current-findings" + }, + { + "unit": "organon.charter.overview", + "clause": "p2", + "unit_sha256": "75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c", + "targets": [ + "T01", + "T02", + "T38" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.charter.overview", + "clause": "p3", + "unit_sha256": "75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c", + "targets": [ + "T01", + "T02", + "T38" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.charter.self-transcendence", + "clause": "p1", + "unit_sha256": "f4ca590e2ae15e3882f70c7b2bc46a8911c97cee547c8b137b5493fbf862c8c0", + "targets": [ + "T02", + "T38" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.charter.self-transcendence.orientation", + "clause": "p1", + "unit_sha256": "7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf", + "targets": [ + "T02", + "T03", + "T38" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.charter.self-transcendence.non-finality", + "clause": "p1", + "unit_sha256": "4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8", + "targets": [ + "T02", + "T03", + "T38" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p1", + "unit_sha256": "6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d", + "targets": [ + "T03", + "T38" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p2", + "unit_sha256": "6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d", + "targets": [ + "T02", + "T03", + "T38", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.charter.consistency", + "clause": "p1", + "unit_sha256": "c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42", + "targets": [ + "T04", + "T05", + "T38" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p1", + "unit_sha256": "81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa", + "targets": [ + "T04", + "T05", + "T38" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p2", + "unit_sha256": "81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa", + "targets": [ + "T04", + "T05", + "T06", + "T38" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "p1", + "unit_sha256": "4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75", + "targets": [ + "T04", + "T05", + "T06", + "T38" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.charter.reflexivity", + "clause": "p1", + "unit_sha256": "13293b45c2fa89068c68ae7ef3c5df38f0efadb3ef3873d78a5ba67d9691a757", + "targets": [ + "T07", + "T38" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.charter.reflexivity.meaning", + "clause": "p1", + "unit_sha256": "8a2caede01a43d8b6c60b54c78ac089c51868e9956f316948077ccee2e45c9cc", + "targets": [ + "T07", + "T38" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.charter.reflexivity.limits", + "clause": "p1", + "unit_sha256": "ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc", + "targets": [ + "T07", + "T08", + "T38" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.grounds", + "clause": "p1", + "unit_sha256": "4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6", + "targets": [ + "T08", + "T09", + "T38", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p1", + "unit_sha256": "ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d", + "targets": [ + "T09", + "T13", + "T38", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p2", + "unit_sha256": "ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d", + "targets": [ + "T09", + "T10", + "T11", + "T12", + "T13", + "T38", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3", + "unit_sha256": "ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d", + "targets": [ + "T09", + "T12", + "T13", + "T38", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.grounds.scope", + "clause": "p1", + "unit_sha256": "4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693", + "targets": [ + "T14", + "T15", + "T38" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.grounds.scope", + "clause": "p2", + "unit_sha256": "4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693", + "targets": [ + "T14", + "T15", + "T38", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.grounds.scope", + "clause": "p3", + "unit_sha256": "4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693", + "targets": [ + "T14", + "T15", + "T38", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p1", + "unit_sha256": "7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0", + "targets": [ + "T16", + "T17", + "T38", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p2", + "unit_sha256": "7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0", + "targets": [ + "T16", + "T17", + "T38", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p1", + "unit_sha256": "bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c", + "targets": [ + "T18", + "T19", + "T38", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p2", + "unit_sha256": "bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c", + "targets": [ + "T18", + "T19", + "T38", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "p1", + "unit_sha256": "db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870", + "targets": [ + "T15", + "T18", + "T19", + "T38" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.relationships.roles", + "clause": "p1", + "unit_sha256": "24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e", + "targets": [ + "T01", + "T08", + "T20", + "T38", + "T39", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2", + "unit_sha256": "24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e", + "targets": [ + "T03", + "T06", + "T11", + "T16", + "T20", + "T38", + "T39", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3", + "unit_sha256": "24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e", + "targets": [ + "T07", + "T08", + "T16", + "T18", + "T20", + "T37", + "T38", + "T39", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "organon.relationships.terms", + "clause": "p1", + "unit_sha256": "61cb7ce4f2920f1aa6771502b87a66536ae0504acccfebd9dd23bcc62756eddf", + "targets": [ + "T02", + "T21" + ], + "local_status": "accepted-bounded", + "composition_status": "not-blocked-by-current-findings" + }, + { + "unit": "extensions", + "clause": "p1", + "unit_sha256": "ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66", + "targets": [ + "T01", + "T37", + "T38", + "T39", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "software-engineering.purpose", + "clause": "p1", + "unit_sha256": "946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b", + "targets": [ + "T22", + "T23", + "T38", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "software-engineering.purpose", + "clause": "p2", + "unit_sha256": "946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b", + "targets": [ + "T22", + "T23", + "T38", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "software-engineering.purpose", + "clause": "p3", + "unit_sha256": "946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b", + "targets": [ + "T22", + "T23", + "T24", + "T38", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p1", + "unit_sha256": "c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04", + "targets": [ + "T24", + "T25", + "T38", + "T39", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2", + "unit_sha256": "c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04", + "targets": [ + "T24", + "T25", + "T26", + "T27", + "T38", + "T39", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3", + "unit_sha256": "c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04", + "targets": [ + "T24", + "T25", + "T26", + "T27", + "T28", + "T38", + "T39", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p1", + "unit_sha256": "c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6", + "targets": [ + "T29", + "T30", + "T38", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p2", + "unit_sha256": "c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6", + "targets": [ + "T29", + "T30", + "T38", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p1", + "unit_sha256": "8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42", + "targets": [ + "T31", + "T32", + "T37", + "T38", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p2", + "unit_sha256": "8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42", + "targets": [ + "T31", + "T32", + "T38", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p3", + "unit_sha256": "8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42", + "targets": [ + "T33", + "T34", + "T38", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "software-engineering.revision", + "clause": "p1", + "unit_sha256": "5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99", + "targets": [ + "T35", + "T36", + "T38", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + }, + { + "unit": "software-engineering.revision", + "clause": "p2", + "unit_sha256": "5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99", + "targets": [ + "T35", + "T36", + "T37", + "T38", + "T40" + ], + "local_status": "accepted-bounded", + "composition_status": "pending-F07-F08" + } + ], + "prior_review_hashes": { + "source-first-initial.md": "0975c0e97c220a9558cbb56c264c7253c70175cedf6cd771b860ec5764a13ab5", + "source-code-review-partial-initial.md": "bf7a6bd136720295e79c495e3980ecbe05a595a66d4aed9af4521390e87cd86a", + "source-code-review-adopted-f01-f06-final.md": "dc1952e457239f9c5a72d99b50ff043f3c243ff8914efea20e0bc49b3af441b4", + "source-code-review-domain-r2.md": "53288a6b2e5bdc55a18a004c0a3c38c0a31269d97309e1f4a0b864f9cfeba28f", + "source-code-review-domain-same-work-final.md": "c64b54d89ffed6592d5b745772835f9ff1ace23305a51dfa688289bf25c9cde2" + }, + "remaining": [ + "F07/F08 new-object review", + "fresh blind-code comparison", + "bilingual reader and type binding review" + ], + "production_changes": false +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/source-code-review-full-initial.md b/SoftwareEngineering/lean/philosophy/reviews/source-code-review-full-initial.md new file mode 100644 index 0000000..5957115 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/source-code-review-full-initial.md @@ -0,0 +1,47 @@ +# 完整源码对照初判 + +审查者:`/root/se_source_first`。阶段:保存独立 source-first 后的知情源码对照;尚未接触新鲜 code-only 盲译或其具体 concerns。当前完整组合暂不接受,T20/T37/T38/T39 有以下两项对应阻断。不是 Lean 类型错误,也没有证明源文或强目标不可满足。 + +## F07:完整已持规范与 whole held theory 的对应缺口 + +`Integration.lean:148–204` 的 `ownTheory` 仅枚举 `OwnFact`。generation/reflection 已有实际 specification 命题,但 `coreAdoption` 的解释是 `governancePosition.commitment`,最终为恒真采纳标记。完整 empirical/inferential/value/scope/capability/implementationChoice,以及 adopter 的 DomainSatisfied/priority 等实际规范字段,没有各自对应的 held norm 内容或完整内容理论到此 theory 的保真关系。`currentConsistency` 只证明这个枚举理论。 + +`Integration.lean:240` 的 Inherited 各字段有真实满足证明,绝非只有标记。本 finding 不断言那些字段为假,也不声称遗漏规范与此有限模型冲突:固定 candidate 甚至可以支持许多未显式枚举的真命题。阻断是源码注释所称“every represented current fact and adopted commitment”的完整内容对应没有展示;采用事实不能自动取代所采用规范的内容。 + +修复边界:显式连接全部被表示且当前适用的已持规范内容、条件与判断到受一致性约束的理论,或提供完整内容理论与当前理论的保真关系。保留真实规范满足字段和 T39 简单选择;无需新增 Core 0.1.3 的全方面 Grounds 义务。 + +实际检查:逐一展开 OwnFact/ownFactClaim/ownTheory;coreAdoption 归约为 true,generation/reflection 的规范已经单列。建议后续探针(本轮未执行 Lean 探针):相同采纳标签下内容要求不相容的规范应进入同一内容理论并触发冲突;适用范围变化应改变被持有内容,不能仅靠 marker 名称确认。 + +## F08:系统自己的 generation/assessment 规则缺少明确自评对象 + +`Reflection.lean:70–96` 实际采用的两条规则是 `Model.rule generation/assessment`,其 meaning 为 `interpret activity`。`SelfApplication.lean:8–24` 的 ReviewObject 列表只有 activity、五种 commitment、priority、evolutionMethod;后者实际内容是 staticBatch/liveBatch 预测。commitment 的 test 是 safeguardExperiment,basis 为对应 ReasonRelevant,是具体理由与后果试验。没有一个对象的实际内容/输入明确绑定当前 generation/assessment rule 的 meaning、适用条件及评估方法。 + +Model.follows 正确检查这些规则用于已有对象列表,但列表未包括这两个实际规则。reviewIdentity 绑定了枚举对象与其理由试验,不能单独证明对象就是当前使用的评估规则。源码已把这些规则用作系统自己的 generation/assessment;其 formation/revision 的适用性需要明确处理,不能以 staticBatch 的反例替代。这不是要求所有原则无条件自应用或无限回归。 + +领域方法在 21/10 正确、21/5 失败,是有效批评;priority 对象也确实测试实际 EvolutionPriority,绝非 assessed flag。F08 不否定这些局部案例。修复边界是让所采用规则的实际内容和条件在自身 formation/application/revision 的对象关系中可追踪,并提供相关适用性和实际执行/批评证据。不适用须由具体条件说明,不能将新增自规则对象全部设为不适用。 + +实际检查:核对全部 ReviewObject 构造子、objectTest 分支及 Model.rule meaning。建议后续探针(未执行):改变实际评估规则或适用范围而保持枚举名/理由文本不变,对应对象内容和输入应随之改变;用实际方法的一项有限批评核对对象,不能只重放领域预测反例。 + +## 已成立的具体内容 + +Inherited 真实包含 generation、consistency、reflection、own principle values、choice value、empirical/inferential/scope/capability/implementation choice 与 own claims。共同 ctx 绑定 sharedContext,不能任意替换。Root 经验任务保留实际 present-budget record;推论保留真实 capacity assumptions;value/capability 分别履责。OwnFact 的固定模型身份推论没有替换原经验任务,未重现 F01 的新循环假设替代旧任务问题。 + +Values 的理由与具体原则内容相关:计划/designRevision、相反顺序合同、static/live 的 21/5 反例、测量范围 10/5、实际 complexity/work 与预算。safeguard enabled/disabled 改变实际许可变更、冲突许可、自测集合、许可范围或选择实现,后果不是自由获益 Bool。初始采纳仍为承诺,事实不被声称必然推出采纳。部分 consequence 证明不再消费已固定且真实的 reason premise,本身不构成 F06 复发。 + +T38 实际选 evolvable,T39 实际选 presentSimple;两者处在共同 continuing 情境,双方满足必要需求,具有 credible designRevision,evolvable 的 successor/agent 有真实变更路径。T39 明确排除 bounded lifecycle、cost threat 和 justified departure,简单选择的价值承诺有实际复杂度理由。T38 接受额外复杂度并有较少的真实变更工作量。不得通过削弱这些分支解决 F07/F08。 + +engineeringCapability 是明确的输出/报告契约,不等于所有维护者均能修改;更强 successor/agent 断言由独立 CanChange 实际路径证明。Grounds012 保留有限的显式原任务/内容适配,而非声称覆盖所有 claim nature,也未增加 Core013 全方面义务。 + +## 对象复用和形式证据 + +`encoding-v2-before-mappings` 全部 15 个文件与当前对象逐项比较:当前仅删除新增 `/-- organon-map ... -/` 注释后,与快照字节相等。Adopted 快照 hash 为 `68bb96c35553bf83d0e3a915d1cca0c72b8097670626e32046bf53af5d0bc773`;Domain 为 `0ed052c3692d8c91a41eed60bb0cba6ca033a7c9d1163aac66b32e4291927377`。据此披露地复用此前修复判断,不改签旧批准 hash。 + +实际读取 `evidence/checks/2026-09-14T17-35-30.437Z-29702-09a03c` 的 lake-build、lean-audit 原始日志/收据及 ConstantInfo 类型。完整隔离构建和实际 audit status 0;59 声明有完整类型及公理输出,限于 propext、Classical.choice、Quot.sound,没有 sorry 或项目公理。inputs-sha256 的 14 项项目输入与当前对象逐项相等。运行身份是执行记录,不是工具批准;checker semantic_status 未评估且 proof_targets incomplete。旧空 domain-build-19.log 没有被回写为 PASS。 + +## 逐目标与源段判断 + +同名 JSON 记录全部 40 目标、47 parser 源段、175 semantic cases 和59声明真实 type hash。T01/T21/T40 的非形式边界接受;T02–T19/T22–T36 在此前初审、修复及本次精确字节复用范围内接受。T04/T07 的一般接口与案例接受不等于 Root 的完整组合已经对应。T20/T37/T38/T39 为 pending-correspondence,理由是 F07/F08,而不是其真实有限分支未证明。 + +T37 的 priority 自评和 staticBatch 方法批评局部有效,但整体 inherited consistency 与系统自身采用规则的对象覆盖仍待修复。T38/T39 的强实际分支已经有效,完整源义组合仍不能仅凭 Inherited/DomainSatisfied 名称宣布覆盖。 + +全部旧记录保持原样。本轮未改生产代码,没有 Lean 探针编译;独立代码盲译、四本读者稿及最终绑定未审,不能据本记录宣布最终交付完成。 diff --git a/SoftwareEngineering/lean/philosophy/reviews/source-code-review-r3.json b/SoftwareEngineering/lean/philosophy/reviews/source-code-review-r3.json new file mode 100644 index 0000000..ccdd436 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/source-code-review-r3.json @@ -0,0 +1,87 @@ +{ + "schema": "independent-r3-review-v1", + "reviewer": "/root/se_source_first", + "recorded_at": "2026-09-14T18:05:52.464100+00:00", + "candidate": "private software-engineering iteration records/third-code-snapshot", + "files": { + "lean-toolchain": "3aac669c7a910ec2389f4e4f921b605adf6ebf2d1e0c9b9cd0be4d33f3f5db71", + "CoreReader.lean": "c5574fae235419a7d6449b3ebb5d2da29d1e92a3b572c1b759438e3c470caaa9", + "lake-manifest.json": "bbc61a9c84a4f346e142fd849100a94729248bbcc8a736fa594318fc21b48345", + "lakefile.toml": "05d8ba36975f87aca61e3b0ddcacc42669539f316ba9b8eef5859961e2aa6fdc", + "CoreReader/Choice.lean": "b28728df12ed7e73edb5569604cd2541c0ebd815ae3aaa0812e6557dece1d1ba", + "CoreReader/Logic.lean": "0ec342691766ebd83d251dcd0da3b0ae9840aed677a714bc1b01c45d89392bc0", + "CoreReader/Integration.lean": "97e2939c0b6714b78a3ed78358e174619a5028ad5b0b5025c0d4422b4294921b", + "CoreReader/Agency.lean": "2722c34645f4256f20ce31205738f2f5712ab5dd5cc6fcf9f1180d0be5aa0303", + "CoreReader/Reflexivity.lean": "48e2c74e7cbae571db1b990b9f32dd0d701f6881a8b0111d907f8861287d76fa", + "CoreReader/Evidence.lean": "d55f33e44902cef146841cbffb65710bd7c8a3bda79d01d084edc36f019fdc96", + "CoreReader/Adopted.lean": "8de4d364bb3c64e29ab92e81d86cbe4c9e5af49ada3dad262d1378421fb588c2", + "CoreReader/Engineering/Reflection.lean": "c290d8472884d00bedbf945f0fc1866524e758740f40d42088c4ff9678a93fa2", + "CoreReader/Engineering/Integration.lean": "a2b88062148b3f7ebea7da02d88cb29cb04d8f1b2e9e6b97bb2420ac2c006328", + "CoreReader/Engineering/Values.lean": "ccd45bf23d2f47c41d1b2f9955d753e290687d951a0c55af41ab9a63b9a8d9cb", + "CoreReader/Engineering/Domain.olean": "c6ccc73e0d0e8e3da0d9bc078b3e9e3d916ec1ce99e0c9723cafaf39b5c27525", + "CoreReader/Engineering/SelfApplication.lean": "d69c0d369bd4fd8db4c21ce3b65abb5e9efd07ed5ab9a68d56b4db39bb9d2a21", + "CoreReader/Engineering/Domain.lean": "ce5653a2950cc7443cefbfe8b9726bd4859228e831ddb7d42601e501ccbfd855" + }, + "report_sha256": "c3d06769eba25fec696936c87a560228ce04d675757adc8887a36357ff9939aa", + "comparison_phase": "other independent source comparison read only after own F07/F08 judgment preserved", + "other_review_hashes": { + "source-comparison-initial.md": "41231e41278a6389f72db28cf2b75322cfdecaa0c8a831051aa7b10b7b30b2e9", + "source-comparison-initial.json": "458c5302b44cfcaa799fd1d9cebf34df392aebdf7fa57c74e2cd5b8c2fa96244" + }, + "target_changes": [ + { + "id": "T16", + "status": "accepted-bounded", + "basis": "Same explained process, distinct multiplier-change answer; actual 3/1 counterexample and same application/task Grounds." + }, + { + "id": "T31", + "status": "accepted-bounded", + "basis": "Actual caller/callee relation and intended callee edit, caller knowledge/check obligation, actual scoped order equality; omission/other-callee/sorted-run counterexamples." + } + ], + "root_reuse": { + "files": [ + "Integration.lean", + "SelfApplication.lean", + "Reflection.lean" + ], + "exact_bytes_equal_f07_f08_candidate": true, + "review_sha256": "898af33213a832832f4b6d84a8f94fd99bede9a0abae055b9e2a1af3b8ee5b1f" + }, + "composition_targets": { + "T20": "accepted-bounded, completion pending readers and other final review", + "T37": "accepted-bounded, completion pending readers and other final review", + "T38": "accepted-bounded, completion pending readers and other final review", + "T39": "accepted-bounded, completion pending readers and other final review" + }, + "declarations": { + "CoreReader.Adopted.capabilityCases012": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.capabilitySpecification [])\n (Lean.Expr.const `CoreReader.Evidence.explainedProcess []))\n (Lean.Expr.const `CoreReader.Evidence.FullProcessContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Exists [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))\n (Lean.Expr.lam\n `certificate\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate.assessorId [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExternalCertificate.assessedId [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.bvar 0))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))\n (Lean.BinderInfo.default))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.ExplanationContract [])\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess [])))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.OwnCapability012 [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 7)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 7)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 7)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 7)))))\n (Lean.Expr.const `CoreReader.Evidence.outputOnlyProcess []))\n (Lean.Expr.const `CoreReader.Evidence.OutputContract [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `CoreReader.Evidence.Process []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012.process [])\n (Lean.Expr.const `CoreReader.Adopted.explainedWithoutVariation012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012.process [])\n (Lean.Expr.const `CoreReader.Adopted.mechanismResponder012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.FullProcessContract [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012.process [])\n (Lean.Expr.const `CoreReader.Adopted.explainedWithoutVariation012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.UnderstandingApplication012 [])\n (Lean.Expr.const `CoreReader.Adopted.explainedWithoutVariation012 []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.UnderstandingApplication012 [])\n (Lean.Expr.const `CoreReader.Adopted.mechanismResponder012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 []))\n (Lean.Expr.const `CoreReader.Adopted.UnderstandingApplication012 []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.understandingFacet012 [])\n (Lean.Expr.const `CoreReader.Adopted.mechanismResponder012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.understandingTask012 [])\n (Lean.Expr.const `CoreReader.Adopted.mechanismResponder012 []))))\n (Lean.Expr.app\n (Lean.Expr.const `Not [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.Grounds012 [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 []))\n (Lean.Expr.const `CoreReader.Adopted.UnderstandingApplication012 []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.canonicalArticulation [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.cons [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.understandingFacet012 [])\n (Lean.Expr.const `CoreReader.Adopted.explainedWithoutVariation012 [])))\n (Lean.Expr.app\n (Lean.Expr.const `List.nil [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Evidence.Facet [])\n (Lean.Expr.const `CoreReader.Adopted.MechanismApplication012 [])))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Adopted.understandingTask012 [])\n (Lean.Expr.const `CoreReader.Adopted.explainedWithoutVariation012 []))))))))))", + "sha256": "71d33f0d4ef4ccd7b59de8cf61f1e8aa0edae58f02813c4f4f3d79754d592d03" + }, + "CoreReader.Engineering.structuralCases": { + "type": "Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.StructuralAccount [])\n (Lean.Expr.const `CoreReader.Engineering.continuingActivity []))\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.structuralEvidence [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.propagation [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 3)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 3))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `List.length [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.propagation [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `List.any [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.EditStep []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changePath [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated [])))\n (Lean.Expr.lam\n `s\n (Lean.Expr.const `CoreReader.Engineering.EditStep [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Bool.and [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `BEq.beq [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.const `instDecidableEqNat [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.component [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 2)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 2))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `BEq.beq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `instBEqOfDecidableEq [Lean.Level.zero])\n (Lean.Expr.const `CoreReader.Engineering.Knowledge []))\n (Lean.Expr.const `CoreReader.Engineering.instDecidableEqKnowledge [])))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EditStep.requires [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `CoreReader.Engineering.Knowledge.publicContract [])))\n (Lean.BinderInfo.default))))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.PreservesFinite [])\n (Lean.Expr.const `CoreReader.Engineering.orderedUnique []))\n (Lean.Expr.const `CoreReader.Engineering.orderedRefactor [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.app\n (Lean.Expr.const `List [Lean.Level.zero])\n (Lean.Expr.app (Lean.Expr.const `List [Lean.Level.zero]) (Lean.Expr.const `Nat []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.StructuralEvidence.observedBefore [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.structuralEvidence [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision []))))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.StructuralEvidence.observedAfter [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.structuralEvidence [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.evolvable []))\n (Lean.Expr.const `CoreReader.Engineering.Change.designRevision [])))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)]) (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.staticBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 10))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 10)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 10)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Ne [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.staticBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app\n (Lean.Expr.const `instOfNatNat [])\n (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.liveBatch [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 21)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 21)))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 5)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 5)))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Nat []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.changeWork [])\n (Lean.Expr.const `CoreReader.Engineering.Candidate.presentSimple []))\n (Lean.Expr.const `CoreReader.Engineering.Change.withdrawal [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app (Lean.Expr.const `OfNat.ofNat [Lean.Level.zero]) (Lean.Expr.const `Nat []))\n (Lean.Expr.lit (Lean.Literal.natVal 17)))\n (Lean.Expr.app (Lean.Expr.const `instOfNatNat []) (Lean.Expr.lit (Lean.Literal.natVal 17))))))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.crossesBoundary [])\n (Lean.Expr.const `CoreReader.Engineering.boundaryDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.coordinatedBoundary [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.boundaryObligationChecked [])\n (Lean.Expr.const `CoreReader.Engineering.boundaryDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.coordinatedBoundary [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.crossesBoundary [])\n (Lean.Expr.const `CoreReader.Engineering.omittedCallerCheck []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.coordinatedBoundary [])))\n (Lean.Expr.const `Bool.true [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.boundaryObligationChecked [])\n (Lean.Expr.const `CoreReader.Engineering.omittedCallerCheck []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.coordinatedBoundary [])))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `And [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.crossesBoundary [])\n (Lean.Expr.const `CoreReader.Engineering.otherCalleeDesign []))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.otherCalleeBoundary [])))\n (Lean.Expr.const `Bool.false [])))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `Eq [Lean.Level.succ (Lean.Level.zero)])\n (Lean.Expr.const `Bool []))\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.boundaryObligationChecked [])\n (Lean.Expr.letE\n (Lean.Name.mkNum (Lean.Name.mkStr (Lean.Name.mkStr (Lean.Name.mkNum `__src.«_@».CoreReader.Engineering.Domain 1550649743) \"_hygCtx\") \"_hyg\") 194)\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign [])\n (Lean.Expr.const `CoreReader.Engineering.boundaryDesign [])\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.mk [])\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Engineering.EngineeringDesign.metadata\n [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.const `CoreReader.Engineering.sortedUnique []))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.paths [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Engineering.EngineeringDesign.components\n [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const `CoreReader.Engineering.EngineeringDesign.boundaries [])\n (Lean.Expr.bvar 0)))\n (Lean.Expr.app\n (Lean.Expr.const\n `CoreReader.Engineering.EngineeringDesign.batchAssumptions\n [])\n (Lean.Expr.bvar 0)))\n true))\n (Lean.Expr.const `CoreReader.Engineering.Change.coordinated []))\n (Lean.Expr.const `CoreReader.Engineering.coordinatedBoundary [])))\n (Lean.Expr.const `Bool.false [])))))))))))))))", + "sha256": "4fdfb378096465bfe330f655d5cc248745bbfdcb505407595d9d23254428de9e" + } + }, + "evidence": { + "directory": "SoftwareEngineering/lean/philosophy/evidence/checks/2026-09-14T18-03-09.923Z-30953-387a51", + "files": { + "lake-build.json": "8dda59eea4c29bb0cbcf3dcba65838bb2c2162a75c1c2c58637b0a14564b6f80", + "lake-build.log": "d5b6777292f0fd671708ba437137595e17fe37df155f8526ae8392844267714c", + "lean-audit.json": "11eb8fc26bd0a3c693ae22115587819d2926d133d0345c423af57dc081de4a1d", + "lean-audit.log": "ccafad4d73a2997ffbb0c01fbefc57e3e8e405857da8d3c3a4e63b71e76e4466", + "inputs-sha256.json": "c031bd4f9bd3fe325f85ce43172611e616d647c8572595b75dac5e2ac9866216", + "declaration-types.json": "1a709e7455ab9fa93640b440b80d72b1f3b6fb34c76e87252f1d658d47690db4" + }, + "build_status": 0, + "audit_status": 0 + }, + "limits": [ + "Operational mechanism prediction is application-selected understanding, not psychological understanding.", + "Cross-boundary obligation is a specified application rule and finite scoped contract check, not arbitrary edge causal inference.", + "No production edits; no reviewer-created Lean probes.", + "Upcoming Domain line explanations are authored material requiring separate independent review." + ] +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/source-code-review-r3.md b/SoftwareEngineering/lean/philosophy/reviews/source-code-review-r3.md new file mode 100644 index 0000000..54c004c --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/source-code-review-r3.md @@ -0,0 +1,39 @@ +# 第三版增量独立复核与三方比较 + +审查者 `/root/se_source_first`。固定对象为 `third-code-snapshot`;相对于已接受的 `f07-f08-candidate`,新增语义只在 Domain 和 Adopted。三个 Root 文件与 F07/F08 候选精确字节相等,故复用已保存的相应判断。本轮是在本人的 F07/F08 判定落盘之后才读取另一代理的 `blind-source-initial-preserved/source-comparison-initial.md/json`,不将本轮称为盲审。 + +结论:**T31 和 T16 两项增量在披露的应用范围内接受,没有新增阻断。** 旧初稿不改写;原第三方意见针对其精确历史对象仍成立。 + +## T31:真实 boundary 与跨界义务 + +Domain hash:`ce5653a2950cc7443cefbfe8b9726bd4859228e831ddb7d42601e501ccbfd855`。 + +`coordinatedBoundary` 是真实 caller 2、callee 1 边;`boundaryDesign` 的边集合确实包含该边。`crossesBoundary` 检查边归属、两个端点存在且不同,以及 intended direction 的实际路径包含 callee 的 editor/compiler 步骤。`boundaryObligationChecked` 在此基础上要求 caller 的 contractRunner/publicContract 步骤,并核对实际 design.run 在声明的有限合同输入上保持 orderedUnique。 + +`actualCrossBoundaryObligation` 与正式 T31 `structuralCases` 都保留六项实际内容:正确边发生穿越并履行义务;删除 caller 检查时穿越仍成立而义务失败;将 callee 改到没有相应编辑步骤的 7 时穿越失败;保留名字、边和工作步骤但把实际行为改成 sortedUnique 时合同义务失败。因而不是只观察一条 EditStep 有 publicContract 标签,也没有把 contract 字符串当作合同正确性。 + +这解决了另一代理指出、而我此前局部接受中未充分区分的 T31 冻结 case 对应缺口。我的此前接受不应被解释成旧对象已经具有这一新增关系;新对象另行补足。此模型将“callee 被编辑时 caller 需检查顺序合同”作为明确应用规则,不是从任意边存在推出真实工程义务。合同观察是有限输入集;接口没有成为运行时调用图解释器,亦未证明所有软件边的传播规律。 + +## T16:解释与应用所选理解能力分离 + +Adopted hash:`8de4d364bb3c64e29ab92e81d86cbe4c9e5af49ada3dad262d1378421fb588c2`。 + +`MechanismApplication012` 将原 process 与针对 multiplier/input 变化的 answer 分开。`UnderstandingApplication012` 同时要求原 FullProcessContract、原过程对 multiplier=2 的输出,以及对任意 multiplier/input 的机制预测。两个对象拥有完全相同 explainedProcess,但固定返回 doubleInput 的对象在 multiplier=3,input=1 给出 2 而非 3,故不能满足这个更强应用契约。mechanismResponder 的答复函数确实是乘法机制;证明对任意输入展开,而非由有限成功样本推出全称。 + +对应 Grounds 的 task 与 facet 都绑定同一应用对象、身份 scope 及同一个更强 claim。正例先证明该契约并给出非空身份模型;负例从支持义务取出同一个错误对象的契约,利用 3/1 反例否定。没有以另一个对象或新循环前提替换原任务。 + +另一代理对旧 explanation-only 案例的异议成立。新增案例将“理解”明确为应用选定的机制变化预测能力,超出仅储存与输出等价的解释程序;它不是心理理解、内在意识或所有方法理解的哲学统一定义。源文允许应用指定能力,该范围与限制必须在读者稿保留。 + +## T20/T37/T38/T39 的三方处置 + +另一代理原意见指出 T20 结论缺 consistency,T37 缺同一 priority 的 Grounds 与 consistency。我在独立 F07/F08 报告中另指出完整内容理论与自身规则对象问题。现冻结第三版保留已单独审过的修复:T20 显式给出完整内容成员、整理论根据与一致性;T37 用固定情境内明确 commitment/priority 等价连接真实 value task,并包含领域内容成员与一致性。自规则对象直接检验当前 generate/evaluate 的真实内容和适用性。 + +两份独立历史意见不是彼此投票作证;当前接受依据新增源码与实际类型。T38/T39 强分支没有削弱;T38 整体源义组合不再受此次 T16/T31 及既有 F07/F08 缺口阻断。T39 的真实简单选择、所有继承责任、领域适用、无 lifecycle/cost 逃逸保留。 + +## 实际形式证据及后续范围 + +`third-check.json` 指向 `evidence/checks/2026-09-14T18-03-09.923Z-30953-387a51`。实际全构建及 audit 返回 0;已读取新增 capabilityCases012/structuralCases 的完整打印类型,不仅使用摘要。59 声明类型及公理审计保留;公理仅 propext、Classical.choice、Quot.sound。证据中的14项项目输入与 third-code-snapshot 精确相等。当前源码 hash、证据 hash 和相关真实 type hash 见同名 JSON。 + +范围仍是规范接口、条件定理和声明的有限模型/应用。成功支持与正确执行一次否定评估不同,有限 value procedure 不是要求所有初始价值证明自身全部前提;这些第三方限定与我的既有限度相容并应进入稿件。最终稿与第三方修复复核尚不由本记录代替。 + +下一步的 Domain 逐行 EN/ZH JSON 由我撰写,因此我是那份读稿的作者;覆盖核查仅验证其完整性,不自称对自己读稿完成独立审查。 diff --git a/SoftwareEngineering/lean/philosophy/reviews/source-initial-targets.json b/SoftwareEngineering/lean/philosophy/reviews/source-initial-targets.json new file mode 100644 index 0000000..2441326 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/source-initial-targets.json @@ -0,0 +1,3056 @@ +{ + "schema_version": "source-first-recommendations-1", + "status": "independent initial recommendations; not frozen author catalog", + "author": "independent agent /root/se_source_first", + "recorded_at": "2026-09-14T16:44:03.740255+00:00", + "source_path": "SoftwareEngineering/PHILOSOPHY.md", + "source_sha256": "6c6ae78a23f2726c5c370434e808d76c206647fe7793245e88cae52c076abe34", + "selected_baseline": { + "path": "SoftwareEngineering/PHILOSOPHY.md", + "sha256": "6c6ae78a23f2726c5c370434e808d76c206647fe7793245e88cae52c076abe34", + "philosophy_version": "0.2.0", + "core_version": "0.1.2", + "derived_from_hash": "cb23f8a44d6b877ff9b5385961ff8e5fa788f8021ae267cdc8e305870ec20ca7" + }, + "exposure": { + "author_candidate_seen": false, + "existing_lean_models_seen": false, + "prior_review_files_seen": false, + "qualification": "Read required Core .local/ACTIVE.md index; it exposed prior completion/count summaries but no model, target statements or review rationale. Read Core 0.1.3 as method authority, not selected child baseline. Parent task and accepted user contract explicitly disclose required joint witness/nonentailment objective; these are task objectives, not author verdict." + }, + "inputs": [ + { + "path": "OrganonCore/AGENTS.md", + "sha256": "474f186904f74199628a782e12f1649cc1bc707d433d578915bf06027e9ef381" + }, + { + "path": "local command-wrapper instructions", + "sha256": "49c368c302c6f63d089f4c1085b242fc50fe22ce5bc34dada6478083000e7c6f" + }, + { + "path": "SoftwareEngineering/AGENTS.md", + "sha256": "8063634e1326c1b2bf3e7b752e494e752e32244addc59e6056b58ebd266dbdaf" + }, + { + "path": "OrganonCore/PHILOSOPHY.md", + "sha256": "1a0bebd61e35d46a3ba2e882305ce60f423e37a343ecdfd0b6f314e437aade59" + }, + { + "path": "SoftwareEngineering/PHILOSOPHY.md", + "sha256": "6c6ae78a23f2726c5c370434e808d76c206647fe7793245e88cae52c076abe34" + }, + { + "path": "SoftwareEngineering/docs/rationale.md", + "sha256": "b3bc8493b2b9af0995825c5358d7b5ef87bc43c1ada257a5811bc2e674250b92" + }, + { + "path": "SoftwareEngineering/docs/cases.md", + "sha256": "29451cdf0ea68416ab88f143cf8a7363200aa56c1625cd69dcbbac8212d15d31" + }, + { + "path": "OrganonCore/skills/organon-core-leanify-prove/SKILL.md", + "sha256": "8ede8444368c68f4c368e931318849f33df10226bc1382a5edac7f47eb682794" + }, + { + "path": "OrganonCore/skills/references/iteration.md", + "sha256": "5ac3460cbad126ff2fe88a411a2cf65374eefeb7f711836a15ac572d82fa2106" + }, + { + "path": "OrganonCore/skills/references/philosophy-resolution.md", + "sha256": "9b3b4822c8876608f2d401ec85dd1c9902fdf6dee6a67ec5c1f42010823be204" + }, + { + "path": "OrganonCore/skills/organon-core-leanify-prove/references/proof-targets.md", + "sha256": "84f4b5f586cf83f4bc9973d770c9a34c17513beaac3dbb87378d9aef10ce3d4f" + }, + { + "path": "OrganonCore/.local/ACTIVE.md", + "sha256": "1891d464c330785aa6946875922e5208f997ea41a1da92e24d21a66e4270f753" + }, + { + "path": "private software-engineering iteration records/ACCEPTED-PLAN.md", + "sha256": "19296f58880fece1f814d2faff2351ce3cfe92e949a794112206e1f46296b604" + } + ], + "partition_note": "Independent local paragraph/table-row partition, exact source lines and direct-body bytes included. Source not edited. Before freeze remap cNN IDs to repository parser/run clauses; line spans and hashes are authority for this initial inventory. Whitespace retained in direct_body; headers/IDs separated by source structure.", + "units": [ + { + "id": "organon.preamble", + "direct_body_start": 12, + "direct_body_end": 16, + "direct_body_sha256": "d612a2a8da20a4c70114c0767d79aa88269b48bcee97fc43328ae722ea890706", + "direct_body": "\nThis is a statement of Software Engineering Organon’s adopted philosophy. It expresses commitments, not factual assertions about every system or a proof of universal correctness.\n\nThe quoted provisions, their meanings, and their conditions of application form the core. The charter and Grounds constrain one another; their grouping establishes neither a deductive hierarchy nor an order of priority. [Rationale](docs/rationale.md) supplies arguments and cases without adding obligations to this core. Skills are revisable applications under the repository’s stated objectives and constraints, not part of the philosophical commitments themselves.\n\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 13, + "line_end": 13, + "text": "This is a statement of Software Engineering Organon’s adopted philosophy. It expresses commitments, not factual assertions about every system or a proof of universal correctness.\n", + "structural_only": false, + "target_ids": [ + "T01", + "T40" + ] + }, + { + "id": "c02", + "line_start": 15, + "line_end": 15, + "text": "The quoted provisions, their meanings, and their conditions of application form the core. The charter and Grounds constrain one another; their grouping establishes neither a deductive hierarchy nor an order of priority. [Rationale](docs/rationale.md) supplies arguments and cases without adding obligations to this core. Skills are revisable applications under the repository’s stated objectives and constraints, not part of the philosophical commitments themselves.\n", + "structural_only": false, + "target_ids": [ + "T01", + "T40" + ] + } + ] + }, + { + "id": "organon.charter", + "direct_body_start": 19, + "direct_body_end": 19, + "direct_body_sha256": "01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b", + "direct_body": "\n", + "structural_only": true, + "clauses": [] + }, + { + "id": "organon.charter.overview", + "direct_body_start": 22, + "direct_body_end": 28, + "direct_body_sha256": "75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c", + "direct_body": "\n**Self-Transcendence · Internal Consistency · Reflexivity**\n\n> A system is intrinsically oriented toward expanding what it can understand and construct. It brings itself and its principles within the scope of generation and assessment, with internal consistency constraining this process.\n\nThe overview connects three distinct requirements: self-transcendence establishes a generative orientation and refuses to treat existing forms as final, internal consistency constrains judgments held simultaneously, and reflexivity brings the system and its principles within the scope of their own generation and assessment. The provisions below specify the conditions for each.\n\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 23, + "line_end": 23, + "text": "**Self-Transcendence · Internal Consistency · Reflexivity**\n", + "structural_only": true, + "target_ids": [ + "T01" + ] + }, + { + "id": "c02", + "line_start": 25, + "line_end": 25, + "text": "> A system is intrinsically oriented toward expanding what it can understand and construct. It brings itself and its principles within the scope of generation and assessment, with internal consistency constraining this process.\n", + "structural_only": false, + "target_ids": [ + "T01", + "T02", + "T38" + ] + }, + { + "id": "c03", + "line_start": 27, + "line_end": 27, + "text": "The overview connects three distinct requirements: self-transcendence establishes a generative orientation and refuses to treat existing forms as final, internal consistency constrains judgments held simultaneously, and reflexivity brings the system and its principles within the scope of their own generation and assessment. The provisions below specify the conditions for each.\n", + "structural_only": false, + "target_ids": [ + "T01", + "T02", + "T38" + ] + } + ] + }, + { + "id": "organon.charter.self-transcendence", + "direct_body_start": 31, + "direct_body_end": 33, + "direct_body_sha256": "f4ca590e2ae15e3882f70c7b2bc46a8911c97cee547c8b137b5493fbf862c8c0", + "direct_body": "\n> A system is intrinsically oriented toward expanding what it can understand and construct. It does not regard any existing form as the endpoint of generation.\n\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 32, + "line_end": 32, + "text": "> A system is intrinsically oriented toward expanding what it can understand and construct. It does not regard any existing form as the endpoint of generation.\n", + "structural_only": false, + "target_ids": [ + "T02", + "T38" + ] + } + ] + }, + { + "id": "organon.charter.self-transcendence.orientation", + "direct_body_start": 36, + "direct_body_end": 38, + "direct_body_sha256": "7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf", + "direct_body": "\nA commitment to keeping generative possibilities open is distinct from valuing their expansion. A system has an intrinsic orientation when it regards that expansion as worth pursuing. Merely permitting change does not fully express this orientation.\n\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 37, + "line_end": 37, + "text": "A commitment to keeping generative possibilities open is distinct from valuing their expansion. A system has an intrinsic orientation when it regards that expansion as worth pursuing. Merely permitting change does not fully express this orientation.\n", + "structural_only": false, + "target_ids": [ + "T02", + "T03", + "T38" + ] + } + ] + }, + { + "id": "organon.charter.self-transcendence.non-finality", + "direct_body_start": 41, + "direct_body_end": 43, + "direct_body_sha256": "4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8", + "direct_body": "\nRefusing to regard an existing form as an endpoint keeps it open to being surpassed. “Existing form” includes a system’s current organization, methods, and principles, not only its appearance or artifacts. These remain within the scope of possible change; their revisability does not guarantee actual progress.\n\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 42, + "line_end": 42, + "text": "Refusing to regard an existing form as an endpoint keeps it open to being surpassed. “Existing form” includes a system’s current organization, methods, and principles, not only its appearance or artifacts. These remain within the scope of possible change; their revisability does not guarantee actual progress.\n", + "structural_only": false, + "target_ids": [ + "T02", + "T03", + "T38" + ] + } + ] + }, + { + "id": "organon.charter.self-transcendence.limits", + "direct_body_start": 46, + "direct_body_end": 53, + "direct_body_sha256": "6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d", + "direct_body": "\nWhether progress has actually occurred remains a separate judgment. Having the orientation does not guarantee progress. Progress cannot be established merely by an increase in the number of artifacts, levels of abstraction, or terms.\n\n- “Intrinsic orientation” expresses Organon’s philosophical commitment; it does not assert that all systems in fact develop autonomously.\n- Self-transcendence does not imply independence from external experience, knowledge, or collaboration, nor does it guarantee autonomous execution or self-improvement.\n- Refusing to regard an existing form as an endpoint does not require every action to produce change. Justified stability can coexist with a generative orientation.\n- Whether transcendence expands what can be understood and constructed requires discernible grounds; a system’s own claim of generation does not establish actual achievement.\n\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 47, + "line_end": 47, + "text": "Whether progress has actually occurred remains a separate judgment. Having the orientation does not guarantee progress. Progress cannot be established merely by an increase in the number of artifacts, levels of abstraction, or terms.\n", + "structural_only": false, + "target_ids": [ + "T03", + "T38" + ] + }, + { + "id": "c02", + "line_start": 49, + "line_end": 52, + "text": "- “Intrinsic orientation” expresses Organon’s philosophical commitment; it does not assert that all systems in fact develop autonomously.\n- Self-transcendence does not imply independence from external experience, knowledge, or collaboration, nor does it guarantee autonomous execution or self-improvement.\n- Refusing to regard an existing form as an endpoint does not require every action to produce change. Justified stability can coexist with a generative orientation.\n- Whether transcendence expands what can be understood and constructed requires discernible grounds; a system’s own claim of generation does not establish actual achievement.\n", + "structural_only": false, + "target_ids": [ + "T02", + "T03", + "T38", + "T40" + ] + } + ] + }, + { + "id": "organon.charter.consistency", + "direct_body_start": 56, + "direct_body_end": 58, + "direct_body_sha256": "c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42", + "direct_body": "\n> The principles and judgments a system holds simultaneously, together with their implications, must not yield contradictory judgments on the same question under the same assumptions, meanings of terms, and scope of application.\n\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 57, + "line_end": 57, + "text": "> The principles and judgments a system holds simultaneously, together with their implications, must not yield contradictory judgments on the same question under the same assumptions, meanings of terms, and scope of application.\n", + "structural_only": false, + "target_ids": [ + "T04", + "T05", + "T38" + ] + } + ] + }, + { + "id": "organon.charter.consistency.meaning", + "direct_body_start": 61, + "direct_body_end": 65, + "direct_body_sha256": "81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa", + "direct_body": "\n“Held simultaneously” specifies which principles, judgments, and implications must hold together. Revision may withdraw an earlier judgment; old and new principles need not remain compatible forever. When a change has occurred, that change cannot be represented as though it had not occurred.\n\n“The same assumptions, meanings of terms, and scope of application” specifies the basis for comparing judgments. Divergent judgments under different conditions do not automatically constitute contradictions. Nor can unacknowledged changes in assumptions, meanings, or scope be used to conceal an existing contradiction.\n\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 62, + "line_end": 62, + "text": "“Held simultaneously” specifies which principles, judgments, and implications must hold together. Revision may withdraw an earlier judgment; old and new principles need not remain compatible forever. When a change has occurred, that change cannot be represented as though it had not occurred.\n", + "structural_only": false, + "target_ids": [ + "T04", + "T05", + "T38" + ] + }, + { + "id": "c02", + "line_start": 64, + "line_end": 64, + "text": "“The same assumptions, meanings of terms, and scope of application” specifies the basis for comparing judgments. Divergent judgments under different conditions do not automatically constitute contradictions. Nor can unacknowledged changes in assumptions, meanings, or scope be used to conceal an existing contradiction.\n", + "structural_only": false, + "target_ids": [ + "T04", + "T05", + "T06", + "T38" + ] + } + ] + }, + { + "id": "organon.charter.consistency.limits", + "direct_body_start": 68, + "direct_body_end": 71, + "direct_body_sha256": "4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75", + "direct_body": "\n- Tension between different assessments or values does not directly constitute a contradiction. Revision or qualification is needed when they require incompatible conclusions under the same conditions.\n- Internal consistency is not correctness or sufficiency. A set of principles may be internally consistent while relying on false assumptions or neglecting important questions.\n\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 69, + "line_end": 70, + "text": "- Tension between different assessments or values does not directly constitute a contradiction. Revision or qualification is needed when they require incompatible conclusions under the same conditions.\n- Internal consistency is not correctness or sufficiency. A set of principles may be internally consistent while relying on false assumptions or neglecting important questions.\n", + "structural_only": false, + "target_ids": [ + "T04", + "T05", + "T06", + "T38" + ] + } + ] + }, + { + "id": "organon.charter.reflexivity", + "direct_body_start": 74, + "direct_body_end": 76, + "direct_body_sha256": "13293b45c2fa89068c68ae7ef3c5df38f0efadb3ef3873d78a5ba67d9691a757", + "direct_body": "\n> A system’s principles of generation and assessment also apply to the system itself and to the formation, application, and revision of those principles.\n\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 75, + "line_end": 75, + "text": "> A system’s principles of generation and assessment also apply to the system itself and to the formation, application, and revision of those principles.\n", + "structural_only": false, + "target_ids": [ + "T07", + "T38" + ] + } + ] + }, + { + "id": "organon.charter.reflexivity.meaning", + "direct_body_start": 79, + "direct_body_end": 81, + "direct_body_sha256": "8a2caede01a43d8b6c60b54c78ac089c51868e9956f316948077ccee2e45c9cc", + "direct_body": "\nReflexivity encompasses both the system itself and its principles. Assessment concerns not only whether the system conforms to its principles, but also how those principles are formed, where they apply, and why they may need revision. The formation and revision of principles thus also become objects of generation and assessment.\n\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 80, + "line_end": 80, + "text": "Reflexivity encompasses both the system itself and its principles. Assessment concerns not only whether the system conforms to its principles, but also how those principles are formed, where they apply, and why they may need revision. The formation and revision of principles thus also become objects of generation and assessment.\n", + "structural_only": false, + "target_ids": [ + "T07", + "T38" + ] + } + ] + }, + { + "id": "organon.charter.reflexivity.limits", + "direct_body_start": 84, + "direct_body_end": 88, + "direct_body_sha256": "ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc", + "direct_body": "\n- Applying principles equally retains their conditions of application. When the relevant conditions hold, being the system itself is not a basis for exemption. Nor does the requirement of reflexivity establish that every principle can be applied to itself without examining its applicability.\n- Self-application does not constitute self-proof. Subjecting a principle to its own assessment does not thereby establish its correctness.\n- That a revision is produced by the system itself does not give it sufficient grounds.\n\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 85, + "line_end": 87, + "text": "- Applying principles equally retains their conditions of application. When the relevant conditions hold, being the system itself is not a basis for exemption. Nor does the requirement of reflexivity establish that every principle can be applied to itself without examining its applicability.\n- Self-application does not constitute self-proof. Subjecting a principle to its own assessment does not thereby establish its correctness.\n- That a revision is produced by the system itself does not give it sufficient grounds.\n", + "structural_only": false, + "target_ids": [ + "T07", + "T08", + "T38" + ] + } + ] + }, + { + "id": "organon.grounds", + "direct_body_start": 91, + "direct_body_end": 93, + "direct_body_sha256": "4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6", + "direct_body": "\n> The grounds of principles and judgments must be articulable and subject to assessment appropriate to the nature of the claim. The strength and scope of a claim must be proportionate to the support provided by its grounds.\n\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 92, + "line_end": 92, + "text": "> The grounds of principles and judgments must be articulable and subject to assessment appropriate to the nature of the claim. The strength and scope of a claim must be proportionate to the support provided by its grounds.\n", + "structural_only": false, + "target_ids": [ + "T09", + "T38", + "T40" + ] + } + ] + }, + { + "id": "organon.grounds.assessment", + "direct_body_start": 96, + "direct_body_end": 106, + "direct_body_sha256": "ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d", + "direct_body": "\nArticulation and assessment have distinct responsibilities. Articulability requires that concepts, assumptions, reasons, and limits can be identified. Assessment requires examining whether those grounds support the corresponding claim. Clearly expressed grounds are not thereby sufficiently established.\n\n| Type of claim | Responsibility of assessment | What cannot substitute for that responsibility |\n| --- | --- | --- |\n| Empirical claim | Examine observations, evidence, and performance, together with the conditions, scope, and uncertainty of their support for the claim. | Treating measurability or repeatability itself as proof of relevance, correctness, or value. |\n| Inferential claim | Examine whether the conclusion is supported by the stated assumptions and inferential relations. | Treating the absence of conflict between a conclusion and its assumptions as sufficient to establish that the conclusion follows from them. |\n| Value commitment | State the position taken, its reasons, limits of application, and consequences, and remain open to relevant criticism. | Presenting a commitment as an empirical fact or a necessary inference, or substituting self-assertion for reasons. |\n\nInitial value commitments may be stated explicitly as commitments; they need not prove all their own starting assumptions. The strength and scope of a claim do not require conversion to a common numerical scale. Different types of claims specify their support and limits in accordance with their nature.\n\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 97, + "line_end": 97, + "text": "Articulation and assessment have distinct responsibilities. Articulability requires that concepts, assumptions, reasons, and limits can be identified. Assessment requires examining whether those grounds support the corresponding claim. Clearly expressed grounds are not thereby sufficiently established.\n", + "structural_only": false, + "target_ids": [ + "T09", + "T13", + "T38", + "T40" + ] + }, + { + "id": "c02", + "line_start": 99, + "line_end": 99, + "text": "| Type of claim | Responsibility of assessment | What cannot substitute for that responsibility |\n", + "structural_only": true, + "target_ids": [ + "T09", + "T13", + "T38", + "T40" + ] + }, + { + "id": "c03", + "line_start": 100, + "line_end": 100, + "text": "| --- | --- | --- |\n", + "structural_only": true, + "target_ids": [ + "T09", + "T13", + "T38", + "T40" + ] + }, + { + "id": "c04", + "line_start": 101, + "line_end": 101, + "text": "| Empirical claim | Examine observations, evidence, and performance, together with the conditions, scope, and uncertainty of their support for the claim. | Treating measurability or repeatability itself as proof of relevance, correctness, or value. |\n", + "structural_only": false, + "target_ids": [ + "T09", + "T10", + "T13", + "T38", + "T40" + ] + }, + { + "id": "c05", + "line_start": 102, + "line_end": 102, + "text": "| Inferential claim | Examine whether the conclusion is supported by the stated assumptions and inferential relations. | Treating the absence of conflict between a conclusion and its assumptions as sufficient to establish that the conclusion follows from them. |\n", + "structural_only": false, + "target_ids": [ + "T09", + "T11", + "T13", + "T38", + "T40" + ] + }, + { + "id": "c06", + "line_start": 103, + "line_end": 103, + "text": "| Value commitment | State the position taken, its reasons, limits of application, and consequences, and remain open to relevant criticism. | Presenting a commitment as an empirical fact or a necessary inference, or substituting self-assertion for reasons. |\n", + "structural_only": false, + "target_ids": [ + "T09", + "T12", + "T13", + "T38", + "T40" + ] + }, + { + "id": "c07", + "line_start": 105, + "line_end": 105, + "text": "Initial value commitments may be stated explicitly as commitments; they need not prove all their own starting assumptions. The strength and scope of a claim do not require conversion to a common numerical scale. Different types of claims specify their support and limits in accordance with their nature.\n", + "structural_only": false, + "target_ids": [ + "T09", + "T12", + "T13", + "T38", + "T40" + ] + } + ] + }, + { + "id": "organon.grounds.scope", + "direct_body_start": 109, + "direct_body_end": 115, + "direct_body_sha256": "4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693", + "direct_body": "\nPerformance is discerned within particular relations, conditions, and scopes of observation. A boundary helps specify what a comparison concerns, but local examples do not automatically support unconditional universal conclusions. A judgment cannot establish that relevant differences do not exist merely because its chosen scope omits them.\n\nMeasurement can make some differences comparable. Repeated assessment can help examine the stability of corresponding conclusions. Their roles, and the role of any assessment framework, must be explained relative to the claim and its context. Measurement, repeatability, and an assessment framework do not form a universally necessary chain on which all judgments must depend.\n\nAn observation that has not been reproduced may still offer limited support, and random outcomes need not be identical on every occasion. The verifiability of observations, reproducibility of conditions, and stability of conclusions must be distinguished.\n\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 110, + "line_end": 110, + "text": "Performance is discerned within particular relations, conditions, and scopes of observation. A boundary helps specify what a comparison concerns, but local examples do not automatically support unconditional universal conclusions. A judgment cannot establish that relevant differences do not exist merely because its chosen scope omits them.\n", + "structural_only": false, + "target_ids": [ + "T14", + "T15", + "T38" + ] + }, + { + "id": "c02", + "line_start": 112, + "line_end": 112, + "text": "Measurement can make some differences comparable. Repeated assessment can help examine the stability of corresponding conclusions. Their roles, and the role of any assessment framework, must be explained relative to the claim and its context. Measurement, repeatability, and an assessment framework do not form a universally necessary chain on which all judgments must depend.\n", + "structural_only": false, + "target_ids": [ + "T14", + "T15", + "T38", + "T40" + ] + }, + { + "id": "c03", + "line_start": 114, + "line_end": 114, + "text": "An observation that has not been reproduced may still offer limited support, and random outcomes need not be identical on every occasion. The verifiability of observations, reproducibility of conditions, and stability of conclusions must be distinguished.\n", + "structural_only": false, + "target_ids": [ + "T14", + "T15", + "T38", + "T40" + ] + } + ] + }, + { + "id": "organon.grounds.capabilities", + "direct_body_start": 118, + "direct_body_end": 122, + "direct_body_sha256": "7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0", + "direct_body": "\nCapability claims are subject to Grounds: the capability claimed, its conditions, and the support for it must be identifiable. The core does not prescribe uniform definitions of method mastery, method generation, or capability levels. Applications specify the capabilities they assess and may require understanding, explanation, or performance under relevant variations.\n\nGrounds for a capability claim may be supplied by an external assessor. Their articulability does not by itself require the assessed system to understand or explain its internal generation process. Evidence of reliable output must be assessed against the capability actually claimed; it does not automatically establish understanding of that process. Nor can the number of method documents, terms, tools, or artifacts alone establish a capability beyond what that evidence supports.\n\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 119, + "line_end": 119, + "text": "Capability claims are subject to Grounds: the capability claimed, its conditions, and the support for it must be identifiable. The core does not prescribe uniform definitions of method mastery, method generation, or capability levels. Applications specify the capabilities they assess and may require understanding, explanation, or performance under relevant variations.\n", + "structural_only": false, + "target_ids": [ + "T16", + "T17", + "T38", + "T40" + ] + }, + { + "id": "c02", + "line_start": 121, + "line_end": 121, + "text": "Grounds for a capability claim may be supplied by an external assessor. Their articulability does not by itself require the assessed system to understand or explain its internal generation process. Evidence of reliable output must be assessed against the capability actually claimed; it does not automatically establish understanding of that process. Nor can the number of method documents, terms, tools, or artifacts alone establish a capability beyond what that evidence supports.\n", + "structural_only": false, + "target_ids": [ + "T16", + "T17", + "T38", + "T40" + ] + } + ] + }, + { + "id": "organon.grounds.implementations", + "direct_body_start": 125, + "direct_body_end": 129, + "direct_body_sha256": "bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c", + "direct_body": "\n> The choice of an implementation must be supported by reasons connected to the objectives and values pursued and to the relevant constraints. Its name, conventional use, or established status alone does not provide sufficient grounds for giving it priority.\n\nThis choice provision adds an additional evaluative commitment: name, conventional use, or established status alone is insufficient to establish priority. Grouping it under Grounds does not mean that it follows from the general requirement to assess reasons, or merely from the discernibility of performance. Conventions and existing arrangements may have practical significance, but that significance must be connected to the objectives and values pursued and to the relevant constraints.\n\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 126, + "line_end": 126, + "text": "> The choice of an implementation must be supported by reasons connected to the objectives and values pursued and to the relevant constraints. Its name, conventional use, or established status alone does not provide sufficient grounds for giving it priority.\n", + "structural_only": false, + "target_ids": [ + "T18", + "T19", + "T38", + "T40" + ] + }, + { + "id": "c02", + "line_start": 128, + "line_end": 128, + "text": "This choice provision adds an additional evaluative commitment: name, conventional use, or established status alone is insufficient to establish priority. Grouping it under Grounds does not mean that it follows from the general requirement to assess reasons, or merely from the discernibility of performance. Conventions and existing arrangements may have practical significance, but that significance must be connected to the objectives and values pursued and to the relevant constraints.\n", + "structural_only": false, + "target_ids": [ + "T18", + "T19", + "T38", + "T40" + ] + } + ] + }, + { + "id": "organon.grounds.implementations.limits", + "direct_body_start": 132, + "direct_body_end": 137, + "direct_body_sha256": "db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870", + "direct_body": "\n- Openness does not make all implementations equivalent, nor does it guarantee multiple feasible implementations for the same objective.\n- A method’s explanatory power, limits of application, simplicity, and explicit process requirements may all provide grounded reasons for assessment. They cannot be excluded merely because they concern methods internal to the implementation.\n- Identical local performance does not establish overall equivalence. Relations, conditions, and the scope of comparison are constrained by the provisions of Grounds.\n- Openness does not reject an implementation merely because it already exists or is conventionally used. Relevant reasons may still give it priority.\n\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 133, + "line_end": 136, + "text": "- Openness does not make all implementations equivalent, nor does it guarantee multiple feasible implementations for the same objective.\n- A method’s explanatory power, limits of application, simplicity, and explicit process requirements may all provide grounded reasons for assessment. They cannot be excluded merely because they concern methods internal to the implementation.\n- Identical local performance does not establish overall equivalence. Relations, conditions, and the scope of comparison are constrained by the provisions of Grounds.\n- Openness does not reject an implementation merely because it already exists or is conventionally used. Relevant reasons may still give it priority.\n", + "structural_only": false, + "target_ids": [ + "T15", + "T18", + "T19", + "T38" + ] + } + ] + }, + { + "id": "organon.relationships", + "direct_body_start": 140, + "direct_body_end": 140, + "direct_body_sha256": "01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b", + "direct_body": "\n", + "structural_only": true, + "clauses": [] + }, + { + "id": "organon.relationships.roles", + "direct_body_start": 143, + "direct_body_end": 149, + "direct_body_sha256": "24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e", + "direct_body": "\nThe charter states the generative orientation, the consistency constraint, and reflexive application. Grounds specifies support requirements for judgments and includes an additional commitment concerning implementation choices. Both parts belong to the core and constrain one another. Their placement neither makes Grounds a deduction from the charter nor gives the charter priority over it. Each commitment needs its own reasons.\n\nInternal Consistency concerns whether simultaneously held judgments can hold together; Grounds concerns whether and how far a claim is supported. A conclusion may fail to conflict with its assumptions without being supported by them. Self-Transcendence specifies a generative orientation and non-finality; neither establishes actual capability. Applications may supply objectives, values, and capability definitions; claims made under those objectives, values, and definitions remain subject to the relevant core provisions.\n\nSelf-Transcendence does not substitute for Reflexivity: keeping existing forms open to being surpassed differs from applying relevant principles to the system and to their own formation, application, and revision. Reflexivity extends these requirements to the system and to the formation, application, and revision of its principles. The grounds and limits of the Grounds provisions must themselves be articulable. The system’s own capability claims remain subject to assessment, and this philosophy’s existing form cannot gain priority merely from its established status. Such mutual application provides no self-proof and does not remove conditions of application.\n\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 144, + "line_end": 144, + "text": "The charter states the generative orientation, the consistency constraint, and reflexive application. Grounds specifies support requirements for judgments and includes an additional commitment concerning implementation choices. Both parts belong to the core and constrain one another. Their placement neither makes Grounds a deduction from the charter nor gives the charter priority over it. Each commitment needs its own reasons.\n", + "structural_only": false, + "target_ids": [ + "T01", + "T20", + "T38", + "T39", + "T40" + ] + }, + { + "id": "c02", + "line_start": 146, + "line_end": 146, + "text": "Internal Consistency concerns whether simultaneously held judgments can hold together; Grounds concerns whether and how far a claim is supported. A conclusion may fail to conflict with its assumptions without being supported by them. Self-Transcendence specifies a generative orientation and non-finality; neither establishes actual capability. Applications may supply objectives, values, and capability definitions; claims made under those objectives, values, and definitions remain subject to the relevant core provisions.\n", + "structural_only": false, + "target_ids": [ + "T03", + "T06", + "T11", + "T16", + "T20", + "T38", + "T39", + "T40" + ] + }, + { + "id": "c03", + "line_start": 148, + "line_end": 148, + "text": "Self-Transcendence does not substitute for Reflexivity: keeping existing forms open to being surpassed differs from applying relevant principles to the system and to their own formation, application, and revision. Reflexivity extends these requirements to the system and to the formation, application, and revision of its principles. The grounds and limits of the Grounds provisions must themselves be articulable. The system’s own capability claims remain subject to assessment, and this philosophy’s existing form cannot gain priority merely from its established status. Such mutual application provides no self-proof and does not remove conditions of application.\n", + "structural_only": false, + "target_ids": [ + "T07", + "T08", + "T16", + "T18", + "T20", + "T37", + "T38", + "T39", + "T40" + ] + } + ] + }, + { + "id": "organon.relationships.terms", + "direct_body_start": 152, + "direct_body_end": 157, + "direct_body_sha256": "61cb7ce4f2920f1aa6771502b87a66536ae0504acccfebd9dd23bcc62756eddf", + "direct_body": "\n| Term | Meaning in this philosophy |\n| --- | --- |\n| Existing form | The system’s current organization, methods, and principles, not only its appearance or artifacts. |\n| Assessment | Examination of reasons, applicability, and observed performance; not limited to executable tests. |\n\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 153, + "line_end": 153, + "text": "| Term | Meaning in this philosophy |\n", + "structural_only": true, + "target_ids": [ + "T21" + ] + }, + { + "id": "c02", + "line_start": 154, + "line_end": 154, + "text": "| --- | --- |\n", + "structural_only": true, + "target_ids": [ + "T21" + ] + }, + { + "id": "c03", + "line_start": 155, + "line_end": 155, + "text": "| Existing form | The system’s current organization, methods, and principles, not only its appearance or artifacts. |\n", + "structural_only": false, + "target_ids": [ + "T02", + "T21" + ] + }, + { + "id": "c04", + "line_start": 156, + "line_end": 156, + "text": "| Assessment | Examination of reasons, applicability, and observed performance; not limited to executable tests. |\n", + "structural_only": false, + "target_ids": [ + "T21" + ] + } + ] + }, + { + "id": "extensions", + "direct_body_start": 160, + "direct_body_end": 162, + "direct_body_sha256": "ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66", + "direct_body": "\nThis chapter adds a software engineering commitment and specifies its meaning and limits. It does not claim that this commitment follows from the Charter or Grounds. Those provisions remain adopted and constrain its application.\n\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 161, + "line_end": 161, + "text": "This chapter adds a software engineering commitment and specifies its meaning and limits. It does not claim that this commitment follows from the Charter or Grounds. Those provisions remain adopted and constrain its application.\n", + "structural_only": false, + "target_ids": [ + "T01", + "T37", + "T38", + "T39", + "T40" + ] + } + ] + }, + { + "id": "software-engineering.purpose", + "direct_body_start": 165, + "direct_body_end": 171, + "direct_body_sha256": "946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b", + "direct_body": "\nSoftware engineering concerns the construction, operation, understanding, and revision of software within its relevant human and technical conditions. This philosophy guides decisions by people and agents; it does not attribute an intrinsic orientation to every software artifact.\n\nThe evolution capability considered here belongs to the continuing engineering activity: maintainers, including successor maintainers and agents, working with software, tools, and available knowledge. Code that its original author can modify is not on that ground alone shown to support that continuing activity.\n\nApply the following priority according to the software's credible lifecycle and maintenance expectations. A genuinely temporary script, bounded prototype, or retiring system may have little reason to support further evolution. Calling a continuing system temporary does not establish that condition.\n\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 166, + "line_end": 166, + "text": "Software engineering concerns the construction, operation, understanding, and revision of software within its relevant human and technical conditions. This philosophy guides decisions by people and agents; it does not attribute an intrinsic orientation to every software artifact.\n", + "structural_only": false, + "target_ids": [ + "T22", + "T23", + "T38", + "T40" + ] + }, + { + "id": "c02", + "line_start": 168, + "line_end": 168, + "text": "The evolution capability considered here belongs to the continuing engineering activity: maintainers, including successor maintainers and agents, working with software, tools, and available knowledge. Code that its original author can modify is not on that ground alone shown to support that continuing activity.\n", + "structural_only": false, + "target_ids": [ + "T22", + "T23", + "T38", + "T40" + ] + }, + { + "id": "c03", + "line_start": 170, + "line_end": 170, + "text": "Apply the following priority according to the software's credible lifecycle and maintenance expectations. A genuinely temporary script, bounded prototype, or retiring system may have little reason to support further evolution. Calling a continuing system temporary does not establish that condition.\n", + "structural_only": false, + "target_ids": [ + "T22", + "T23", + "T24", + "T38", + "T40" + ] + } + ] + }, + { + "id": "software-engineering.evolution-priority", + "direct_body_start": 174, + "direct_body_end": 180, + "direct_body_sha256": "c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04", + "direct_body": "\n> When relevant behavioral, safety, performance, and other necessary requirements are satisfied, give priority to continuing maintainers' ability to make credible future changes, including changes to the design itself, over present abstraction simplicity. Accept additional present abstraction complexity for that purpose, while allowing this preference to yield when the added costs threaten concrete engineering objectives.\n\nCredible directions of change have articulable grounds, such as a committed plan, relevant domain knowledge, or an applicable history of change. They need not already have multiple implementations. Their credibility remains open to revision; a conceivable change alone does not establish that it warrants accommodation now.\n\nThis is a default priority, not an obligation to maximize extensibility or retain every possibility. Costs include relevant burdens of understanding, construction, diagnosis, verification, coordination, operation, and eventual migration. A departure from the priority identifies the objective threatened and why the costs matter. No universal numerical exchange rate between these considerations is prescribed.\n\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 175, + "line_end": 175, + "text": "> When relevant behavioral, safety, performance, and other necessary requirements are satisfied, give priority to continuing maintainers' ability to make credible future changes, including changes to the design itself, over present abstraction simplicity. Accept additional present abstraction complexity for that purpose, while allowing this preference to yield when the added costs threaten concrete engineering objectives.\n", + "structural_only": false, + "target_ids": [ + "T24", + "T25", + "T38", + "T39", + "T40" + ] + }, + { + "id": "c02", + "line_start": 177, + "line_end": 177, + "text": "Credible directions of change have articulable grounds, such as a committed plan, relevant domain knowledge, or an applicable history of change. They need not already have multiple implementations. Their credibility remains open to revision; a conceivable change alone does not establish that it warrants accommodation now.\n", + "structural_only": false, + "target_ids": [ + "T24", + "T25", + "T26", + "T27", + "T38", + "T39", + "T40" + ] + }, + { + "id": "c03", + "line_start": 179, + "line_end": 179, + "text": "This is a default priority, not an obligation to maximize extensibility or retain every possibility. Costs include relevant burdens of understanding, construction, diagnosis, verification, coordination, operation, and eventual migration. A departure from the priority identifies the objective threatened and why the costs matter. No universal numerical exchange rate between these considerations is prescribed.\n", + "structural_only": false, + "target_ids": [ + "T24", + "T25", + "T26", + "T27", + "T28", + "T38", + "T39", + "T40" + ] + } + ] + }, + { + "id": "software-engineering.evolution-meaning", + "direct_body_start": 183, + "direct_body_end": 187, + "direct_body_sha256": "c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6", + "direct_body": "\nEvolution includes adding capabilities, replacing implementations, deleting mechanisms, withdrawing abstractions, redrawing boundaries, and migrating away from an existing technology or model. Making additions within a fixed scheme does not establish equal ability to revise or leave that scheme. Not every such change can or should be made inexpensive.\n\nAn evolution claim identifies the relevant changes and the maintainers' conditions. Independent changes, coordinated changes, preservation of existing obligations, and deliberate revision of those obligations can require different structures. A design's advantage on one dimension does not establish an advantage on every dimension.\n\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 184, + "line_end": 184, + "text": "Evolution includes adding capabilities, replacing implementations, deleting mechanisms, withdrawing abstractions, redrawing boundaries, and migrating away from an existing technology or model. Making additions within a fixed scheme does not establish equal ability to revise or leave that scheme. Not every such change can or should be made inexpensive.\n", + "structural_only": false, + "target_ids": [ + "T29", + "T30", + "T38", + "T40" + ] + }, + { + "id": "c02", + "line_start": 186, + "line_end": 186, + "text": "An evolution claim identifies the relevant changes and the maintainers' conditions. Independent changes, coordinated changes, preservation of existing obligations, and deliberate revision of those obligations can require different structures. A design's advantage on one dimension does not establish an advantage on every dimension.\n", + "structural_only": false, + "target_ids": [ + "T29", + "T30", + "T38", + "T40" + ] + } + ] + }, + { + "id": "software-engineering.structural-judgment", + "direct_body_start": 190, + "direct_body_end": 196, + "direct_body_sha256": "8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42", + "direct_body": "\nApply the preceding commitment to engineering consequences as a whole, including the relations among components, their observable contracts, and the work needed to understand and verify a change. An interface's shape, the number of modules or extension points, or the use of a named principle is not sufficient evidence of the claimed capability.\n\nThe relevant comparison may examine how a change propagates, which knowledge and obligations cross a boundary, which assumptions become fixed, and what a later withdrawal would require. A proposed boundary needs support for the changes it is meant to accommodate; introducing it does not by itself show that those changes became easier.\n\nDistinguish a transformation that preserves an identified observable contract from one that deliberately revises that contract. The latter needs a corresponding account of changed obligations and affected parties. This distinction does not require preserving every historical behavior or using a particular testing or migration procedure.\n\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 191, + "line_end": 191, + "text": "Apply the preceding commitment to engineering consequences as a whole, including the relations among components, their observable contracts, and the work needed to understand and verify a change. An interface's shape, the number of modules or extension points, or the use of a named principle is not sufficient evidence of the claimed capability.\n", + "structural_only": false, + "target_ids": [ + "T31", + "T32", + "T37", + "T38", + "T40" + ] + }, + { + "id": "c02", + "line_start": 193, + "line_end": 193, + "text": "The relevant comparison may examine how a change propagates, which knowledge and obligations cross a boundary, which assumptions become fixed, and what a later withdrawal would require. A proposed boundary needs support for the changes it is meant to accommodate; introducing it does not by itself show that those changes became easier.\n", + "structural_only": false, + "target_ids": [ + "T31", + "T32", + "T38", + "T40" + ] + }, + { + "id": "c03", + "line_start": 195, + "line_end": 195, + "text": "Distinguish a transformation that preserves an identified observable contract from one that deliberately revises that contract. The latter needs a corresponding account of changed obligations and affected parties. This distinction does not require preserving every historical behavior or using a particular testing or migration procedure.\n", + "structural_only": false, + "target_ids": [ + "T33", + "T34", + "T38", + "T40" + ] + } + ] + }, + { + "id": "software-engineering.revision", + "direct_body_start": 199, + "direct_body_end": 202, + "direct_body_sha256": "5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99", + "direct_body": "\nChanged evidence about likely changes, maintenance conditions, costs, or objectives may justify revising a design or this priority's application. A revised judgment acknowledges material changes in its grounds; it does not make a failed prediction successful retrospectively.\n\nRetaining a design can be justified when the relevant alternatives have no supported contribution or impose costs that defeat the objective. Reflexivity also keeps this engineering commitment and the methods used to assess evolution within the scope of criticism and revision. Continued change, agreement, or successful examples do not establish its universal correctness.\n", + "structural_only": false, + "clauses": [ + { + "id": "c01", + "line_start": 200, + "line_end": 200, + "text": "Changed evidence about likely changes, maintenance conditions, costs, or objectives may justify revising a design or this priority's application. A revised judgment acknowledges material changes in its grounds; it does not make a failed prediction successful retrospectively.\n", + "structural_only": false, + "target_ids": [ + "T38", + "T40" + ] + }, + { + "id": "c02", + "line_start": 202, + "line_end": 202, + "text": "Retaining a design can be justified when the relevant alternatives have no supported contribution or impose costs that defeat the objective. Reflexivity also keeps this engineering commitment and the methods used to assess evolution within the scope of criticism and revision. Continued change, agreement, or successful examples do not establish its universal correctness.\n", + "structural_only": false, + "target_ids": [ + "T35", + "T36", + "T38", + "T40" + ] + } + ] + } + ], + "targets": [ + { + "id": "T01", + "kind": "boundary", + "source_line_spans": [ + [ + 13, + 15 + ], + [ + 23, + 27 + ], + [ + 144, + 144 + ], + [ + 161, + 161 + ] + ], + "statement": "Authority and roles: adopted commitments, no universal factual assertion or correctness proof; meanings and limits constrain quotation; charter and Grounds mutually constrain without hierarchy; rationale/skills add no philosophical duties; domain preference is additional.", + "premises": [ + "Distinguish document role from deductive claims. No assumed metatheorem about all possible formalizations." + ], + "required_cases": [], + "acceptance": "Trace every role sentence; do not turn absence of asserted deduction into a claimed impossibility theorem without a separately justified model.", + "recommended_declaration_kind": null, + "sources": [ + { + "unit": "organon.preamble", + "clause": "c01" + }, + { + "unit": "organon.preamble", + "clause": "c02" + }, + { + "unit": "organon.charter.overview", + "clause": "c01" + }, + { + "unit": "organon.charter.overview", + "clause": "c02" + }, + { + "unit": "organon.charter.overview", + "clause": "c03" + }, + { + "unit": "organon.relationships.roles", + "clause": "c01" + }, + { + "unit": "extensions", + "clause": "c01" + } + ] + }, + { + "id": "T02", + "kind": "specification", + "source_line_spans": [ + [ + 25, + 27 + ], + [ + 32, + 32 + ], + [ + 37, + 37 + ], + [ + 42, + 42 + ], + [ + 49, + 52 + ], + [ + 155, + 155 + ] + ], + "statement": "Self-transcendence requires valuing expansion of understanding and construction and keeping all existing organization, methods and principles open to being surpassed; justified stable acts remain permitted.", + "premises": [ + "System/activity subject", + "current forms quantified without omitting principles", + "orientation is normative commitment, not empirical universality." + ], + "required_cases": [ + "positive_valued_open_forms", + "negative_permission_only", + "positive_stability", + "external_collaboration" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "definition", + "sources": [ + { + "unit": "organon.charter.overview", + "clause": "c02" + }, + { + "unit": "organon.charter.overview", + "clause": "c03" + }, + { + "unit": "organon.charter.self-transcendence", + "clause": "c01" + }, + { + "unit": "organon.charter.self-transcendence.orientation", + "clause": "c01" + }, + { + "unit": "organon.charter.self-transcendence.non-finality", + "clause": "c01" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "c02" + }, + { + "unit": "organon.relationships.terms", + "clause": "c03" + } + ] + }, + { + "id": "T03", + "kind": "nonentailment", + "source_line_spans": [ + [ + 37, + 37 + ], + [ + 42, + 42 + ], + [ + 47, + 52 + ], + [ + 146, + 146 + ] + ], + "statement": "Permission to change does not entail valuing expansion; valuing/open forms do not entail achieved progress, actual capability, independence, autonomous execution or self-improvement; output/term/abstraction counts or self-claims alone do not establish achievement.", + "premises": [ + "Keep valuing, revisability, progress, support and autonomous properties distinct", + "ground actual achievement in a declared criterion independent of mere count/claim." + ], + "required_cases": [ + "permission_without_value", + "orientation_without_progress", + "count_growth_without_capability", + "collaborative_nonautonomous_progress", + "claim_without_achievement" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "theorem-or-case", + "sources": [ + { + "unit": "organon.charter.self-transcendence.orientation", + "clause": "c01" + }, + { + "unit": "organon.charter.self-transcendence.non-finality", + "clause": "c01" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "c01" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "c02" + }, + { + "unit": "organon.relationships.roles", + "clause": "c02" + } + ] + }, + { + "id": "T04", + "kind": "specification", + "source_line_spans": [ + [ + 57, + 57 + ], + [ + 62, + 70 + ] + ], + "statement": "All simultaneously held principles/judgments and their joint implications must avoid opposite conclusions on same question, assumptions, term meanings and scope; incompatible same-condition demands need revision/qualification; recorded change cannot be concealed.", + "premises": [ + "Consequence over whole held set", + "explicit context equality", + "no per-principle-only substitute", + "distinguish held-at-time from historical union", + "change-report condition separate from consistency." + ], + "required_cases": [ + "joint_only_contradiction", + "changed_scope_not_concealed", + "revision_withdraws_old", + "incompatible_same_context" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "definition", + "sources": [ + { + "unit": "organon.charter.consistency", + "clause": "c01" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "c01" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "c02" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "c01" + } + ] + }, + { + "id": "T05", + "kind": "theorem", + "source_line_spans": [ + [ + 57, + 57 + ], + [ + 62, + 69 + ] + ], + "statement": "Given faithful context identity and whole-set consequence, an opposite pair under the same context violates consistency; removing a prior judgment may eliminate the conflict without requiring permanent historical compatibility.", + "premises": [ + "A consequence relation, positive/negative conclusions for same question, active-set membership, context equality", + "explicit withdrawal semantics", + "no explosion assumption needed." + ], + "required_cases": [ + "pair_conflict", + "joint_premise_conflict", + "old_new_separate_times", + "distinct_context_judgments" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "theorem", + "sources": [ + { + "unit": "organon.charter.consistency", + "clause": "c01" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "c01" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "c02" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "c01" + } + ] + }, + { + "id": "T06", + "kind": "nonentailment", + "source_line_spans": [ + [ + 64, + 70 + ], + [ + 146, + 146 + ] + ], + "statement": "Different-condition disagreement and value tension alone do not entail contradiction; consistency does not entail true assumptions, adequacy or support for a compatible conclusion.", + "premises": [ + "Concrete shared interpretation of truth/support and consequence", + "relevant omitted question represented", + "unsupported conclusion must demonstrably fail entailment, not merely have a false support flag." + ], + "required_cases": [ + "different_contexts", + "tension_compatible", + "consistent_false_assumption", + "consistent_omitted_question", + "compatible_not_entailed" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "theorem-or-case", + "sources": [ + { + "unit": "organon.charter.consistency.meaning", + "clause": "c02" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "c01" + }, + { + "unit": "organon.relationships.roles", + "clause": "c02" + } + ] + }, + { + "id": "T07", + "kind": "specification", + "source_line_spans": [ + [ + 75, + 87 + ], + [ + 148, + 148 + ] + ], + "statement": "Generation and assessment apply to system and principle formation/application/revision under their actual applicability conditions; self-status is no exemption; applicability is not universalized; Grounds grounds/limits and own capability claims are included.", + "premises": [ + "Explicit target kinds for system, formation, application, revision", + "principle applicability and duties", + "nonempty applicable self-target and inapplicable pair", + "no endless-recursion requirement." + ], + "required_cases": [ + "self_applicable", + "self_inapplicable", + "principle_formation", + "principle_application", + "principle_revision", + "grounds_on_grounds" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "definition", + "sources": [ + { + "unit": "organon.charter.reflexivity", + "clause": "c01" + }, + { + "unit": "organon.charter.reflexivity.meaning", + "clause": "c01" + }, + { + "unit": "organon.charter.reflexivity.limits", + "clause": "c01" + }, + { + "unit": "organon.relationships.roles", + "clause": "c03" + } + ] + }, + { + "id": "T08", + "kind": "nonentailment", + "source_line_spans": [ + [ + 85, + 87 + ], + [ + 148, + 148 + ] + ], + "statement": "Self-application or self-produced revision does not establish correctness or sufficient grounds; openness of forms does not by itself meet reflexivity.", + "premises": [ + "Assessment events/duties not truth", + "generation provenance not support", + "concrete countercase with a revisable but self-exempt assessment rule." + ], + "required_cases": [ + "self_assessed_incorrect", + "self_generated_unsupported", + "open_but_self_exempt" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "theorem-or-case", + "sources": [ + { + "unit": "organon.charter.reflexivity.limits", + "clause": "c01" + }, + { + "unit": "organon.relationships.roles", + "clause": "c03" + } + ] + }, + { + "id": "T09", + "kind": "specification", + "source_line_spans": [ + [ + 92, + 105 + ] + ], + "statement": "Grounds requires articulable concepts/assumptions/reasons/limits, assessment appropriate to claim nature, and strength/scope proportionate to supplied support. Articulation and assessment are distinct responsibilities.", + "premises": [ + "Grounds tied to corresponding claim and context", + "explicit support relation, force and scope", + "no universal numeric scale or complete mutually exclusive taxonomy", + "Core 0.1.2 only." + ], + "required_cases": [ + "articulable_supported", + "articulable_unsupported", + "scope_overreach", + "strength_overreach" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "definition", + "sources": [ + { + "unit": "organon.grounds", + "clause": "c01" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c01" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c02" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c03" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c04" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c05" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c06" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c07" + } + ] + }, + { + "id": "T10", + "kind": "specification", + "source_line_spans": [ + [ + 101, + 101 + ] + ], + "statement": "Empirical assessment examines observations, evidence and performance and their support conditions, scope and uncertainty; measurability/repeatability is no replacement for relevance, correctness or value assessment.", + "premises": [ + "Actual empirical content and relevant relation from observations to claim", + "measurement/repetition is evidence property, not automatic support", + "finite adapter remains limited." + ], + "required_cases": [ + "observed_relevant", + "repeatable_irrelevant", + "measured_wrong_scope", + "uncertain_limited" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "definition", + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "c04" + } + ] + }, + { + "id": "T11", + "kind": "specification", + "source_line_spans": [ + [ + 102, + 102 + ], + [ + 146, + 146 + ] + ], + "statement": "Inferential assessment examines whether conclusion follows/supports under stated assumptions and inferential relations; mere nonconflict cannot replace this examination.", + "premises": [ + "A concrete inference semantics and countervaluation when lack of entailment is claimed", + "distinguish task of examination from successful conclusion." + ], + "required_cases": [ + "valid_inference", + "compatible_unentailed", + "false_inference_detected" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "definition", + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "c05" + }, + { + "unit": "organon.relationships.roles", + "clause": "c02" + } + ] + }, + { + "id": "T12", + "kind": "specification", + "source_line_spans": [ + [ + 103, + 105 + ] + ], + "statement": "Value commitments identify position, reasons, applicability limits and consequences and stay open to relevant criticism; neither empirical/necessary-inference presentation nor self-assertion substitutes. Initial commitments need not prove all starting assumptions.", + "premises": [ + "Stated value stance distinct from factual claims", + "reason interface without recursive proof demand", + "relevant criticism condition", + "qualitative support comparisons allowed." + ], + "required_cases": [ + "reasoned_value", + "unsupported_self_assertion", + "closed_criticism", + "explicit_initial_commitment" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "definition", + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "c06" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c07" + } + ] + }, + { + "id": "T13", + "kind": "nonentailment", + "source_line_spans": [ + [ + 97, + 105 + ] + ], + "statement": "Articulability alone does not establish grounds; measurable/repeatable observations alone establish neither relevance, correctness nor value; a stated value commitment need not be empirical fact or necessary consequence, nor prove all its starting assumptions.", + "premises": [ + "Concrete inadequacy criterion for each countercase", + "avoid defining insufficient support as missing record only", + "empirical/inferential/value readings not made exhaustive or exclusive." + ], + "required_cases": [ + "clear_false_reason", + "repeatable_wrong_object", + "value_not_fact", + "initial_value_without_selfproof", + "qualitative_proportionality" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "theorem-or-case", + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "c01" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c02" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c03" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c04" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c05" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c06" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c07" + } + ] + }, + { + "id": "T14", + "kind": "specification", + "source_line_spans": [ + [ + 110, + 114 + ] + ], + "statement": "Performance/comparison judgments state relevant relations, conditions and observation scope; scope omission cannot establish absence of relevant differences; roles of measurement, repetition and framework are explained relative to claim/context.", + "premises": [ + "Local and broader scopes and relevance relation distinct", + "explanation of actually used method does not require all three methods universally." + ], + "required_cases": [ + "local_scope_declared", + "omitted_relevant_difference", + "measurement_role", + "repetition_role", + "framework_role" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "definition", + "sources": [ + { + "unit": "organon.grounds.scope", + "clause": "c01" + }, + { + "unit": "organon.grounds.scope", + "clause": "c02" + }, + { + "unit": "organon.grounds.scope", + "clause": "c03" + } + ] + }, + { + "id": "T15", + "kind": "nonentailment", + "source_line_spans": [ + [ + 110, + 114 + ], + [ + 135, + 135 + ] + ], + "statement": "Local equal performance does not entail global equivalence/unconditional universality; omitting a difference does not establish its nonexistence. Limited unreproduced support and variable random outcomes are possible without a universal measurement→repeatability→framework chain.", + "premises": [ + "Explicit nonempty local and broader domains, shared observations and relation", + "verifiability, reproducible conditions and stable conclusions modeled separately", + "unreproduced is not necessarily irreproducible." + ], + "required_cases": [ + "equal_local_different_global", + "excluded_difference", + "one_observation_limited_support", + "varying_random_outcomes", + "qualitative_unmeasured_judgment" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "theorem-or-case", + "sources": [ + { + "unit": "organon.grounds.scope", + "clause": "c01" + }, + { + "unit": "organon.grounds.scope", + "clause": "c02" + }, + { + "unit": "organon.grounds.scope", + "clause": "c03" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "c01" + } + ] + }, + { + "id": "T16", + "kind": "specification", + "source_line_spans": [ + [ + 119, + 121 + ], + [ + 146, + 148 + ] + ], + "statement": "Capability claim identifies capability, conditions and support under Grounds; applications choose relevant capability definitions and may require understanding/explanation/variation. External assessors may provide grounds; own-system claims receive same relevant duties.", + "premises": [ + "Claim-indexed capability, externally supplied support and actual scope", + "no universal capability levels or introspective requirement." + ], + "required_cases": [ + "external_output_capability", + "application_requires_understanding", + "own_capability_assessment" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "definition", + "sources": [ + { + "unit": "organon.grounds.capabilities", + "clause": "c01" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "c02" + }, + { + "unit": "organon.relationships.roles", + "clause": "c02" + }, + { + "unit": "organon.relationships.roles", + "clause": "c03" + } + ] + }, + { + "id": "T17", + "kind": "nonentailment", + "source_line_spans": [ + [ + 119, + 121 + ] + ], + "statement": "Reliable output or artifact/document/tool/term count alone does not establish internal-process understanding or stronger capability; articulable external grounds do not imply that assessed system understands/explains generation.", + "premises": [ + "Concrete task success and independent understanding criterion", + "external reasons not silently attributed to internal subject", + "scope escalation displayed." + ], + "required_cases": [ + "reliable_opaque_generator", + "high_count_no_stronger_capability", + "externally_articulated_no_introspection" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "theorem-or-case", + "sources": [ + { + "unit": "organon.grounds.capabilities", + "clause": "c01" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "c02" + } + ] + }, + { + "id": "T18", + "kind": "specification", + "source_line_spans": [ + [ + 126, + 128 + ], + [ + 134, + 136 + ], + [ + 148, + 148 + ] + ], + "statement": "Implementation priority needs reasons connected to objectives, values and relevant constraints; name/convention/status alone insufficient. Internal method explanation, applicability limits, simplicity/process requirements may count; conventional options may win on relevant grounds, including this philosophy's existing form.", + "premises": [ + "Reason relevance to particular choice", + "provenance alone distinct from practical familiarity/support", + "no rule that internal reasons are always decisive." + ], + "required_cases": [ + "named_only_rejected", + "conventional_grounded_priority", + "method_internal_reason", + "own_philosophy_status_only" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "definition", + "sources": [ + { + "unit": "organon.grounds.implementations", + "clause": "c01" + }, + { + "unit": "organon.grounds.implementations", + "clause": "c02" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "c01" + }, + { + "unit": "organon.relationships.roles", + "clause": "c03" + } + ] + }, + { + "id": "T19", + "kind": "nonentailment", + "source_line_spans": [ + [ + 126, + 136 + ] + ], + "statement": "Openness neither makes alternatives equivalent nor ensures multiple feasible implementations, excludes conventional choices or excludes internal-method reasons. Local performance equality does not settle whole choice.", + "premises": [ + "Concrete feasible option set and grounded comparison", + "at least one positive witness with a single feasible conventional option", + "distinct global consequences." + ], + "required_cases": [ + "single_feasible_conventional", + "internal_reason_distinguishes", + "unequal_open_options", + "local_equal_global_difference" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "theorem-or-case", + "sources": [ + { + "unit": "organon.grounds.implementations", + "clause": "c01" + }, + { + "unit": "organon.grounds.implementations", + "clause": "c02" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "c01" + } + ] + }, + { + "id": "T20", + "kind": "theorem", + "source_line_spans": [ + [ + 144, + 148 + ] + ], + "statement": "Under jointly satisfied inherited commitments and actual applicability, own principles/assessment methods/grounds/capability judgments inherit their corresponding generation, consistency and support duties without self-proof or removal of conditions.", + "premises": [ + "Same subject/context, shared principle/object identifiers, applicability", + "reflexivity interface connected to concrete Grounds/choice/capability obligations", + "no isolated conjunction of unrelated models." + ], + "required_cases": [ + "own_grounds_articulable", + "own_capability_supported", + "own_choice_not_status_only", + "relevant_self_application" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "theorem", + "sources": [ + { + "unit": "organon.relationships.roles", + "clause": "c01" + }, + { + "unit": "organon.relationships.roles", + "clause": "c02" + }, + { + "unit": "organon.relationships.roles", + "clause": "c03" + } + ] + }, + { + "id": "T21", + "kind": "boundary", + "source_line_spans": [ + [ + 153, + 156 + ] + ], + "statement": "Existing form includes organization/methods/principles. Assessment is examination of reasons, applicability and observed performance and is not limited to executable testing.", + "premises": [ + "Definitions constrain every related model, including review subjects", + "no claim every assessment executes every listed operation when inapplicable." + ], + "required_cases": [], + "acceptance": "Review formal object taxonomy and assessment relation for excluded source meanings; record any finite-enumeration limits.", + "recommended_declaration_kind": null, + "sources": [ + { + "unit": "organon.relationships.terms", + "clause": "c01" + }, + { + "unit": "organon.relationships.terms", + "clause": "c02" + }, + { + "unit": "organon.relationships.terms", + "clause": "c03" + }, + { + "unit": "organon.relationships.terms", + "clause": "c04" + } + ] + }, + { + "id": "T22", + "kind": "specification", + "source_line_spans": [ + [ + 166, + 170 + ] + ], + "statement": "Domain subject is continuing engineering activity by current/successor human or agent maintainers with software/tools/knowledge across credible lifecycle; priority applicability reflects actual lifecycle/maintenance expectations, not labels or artifact intrinsic orientation.", + "premises": [ + "Subject/maintainer roles, credible lifecycle grounds, activity versus artifact", + "temporary/prototype/retiring contexts considered conditionally, not blanket exemption by name." + ], + "required_cases": [ + "successor_maintainer", + "agent_maintainer", + "continuing_labeled_temporary", + "genuinely_temporary", + "bounded_prototype", + "retiring_system" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "definition", + "sources": [ + { + "unit": "software-engineering.purpose", + "clause": "c01" + }, + { + "unit": "software-engineering.purpose", + "clause": "c02" + }, + { + "unit": "software-engineering.purpose", + "clause": "c03" + } + ] + }, + { + "id": "T23", + "kind": "nonentailment", + "source_line_spans": [ + [ + 166, + 170 + ] + ], + "statement": "Original-author editability does not establish continuing-maintainer evolution capability; calling a continuing system temporary does not establish genuinely bounded lifecycle; adopted human/agent orientation does not entail every artifact has it.", + "premises": [ + "Concrete edit/understand/verify paths scoped by maintainer knowledge", + "lifecycle evidence distinct from label", + "actual continuing example." + ], + "required_cases": [ + "author_only_private_knowledge", + "successor_missing_path", + "false_temporary_label", + "passive_artifact" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "theorem-or-case", + "sources": [ + { + "unit": "software-engineering.purpose", + "clause": "c01" + }, + { + "unit": "software-engineering.purpose", + "clause": "c02" + }, + { + "unit": "software-engineering.purpose", + "clause": "c03" + } + ] + }, + { + "id": "T24", + "kind": "specification", + "source_line_spans": [ + [ + 170, + 179 + ] + ], + "statement": "When credible lifecycle/maintenance scope and relevant behavioral, safety, performance and other necessary requirements hold, favor continuing-maintainer credible future change capability including design revision over present abstraction simplicity; accept purpose-linked added complexity; allow yielding only when added costs threaten concrete objectives, with objective/cost account.", + "premises": [ + "Explicit options, same engineering context, feasible requirements, supported credible change set, comparative evolution advantage, simplicity/complexity tradeoff, threat and departure explanation", + "no unconditional maximization or numeric exchange rate." + ], + "required_cases": [ + "ordinary_priority", + "missing_behavior", + "missing_safety", + "missing_performance", + "missing_other_necessary", + "concrete_cost_override", + "unexplained_departure", + "no_extensibility_maximum" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "definition", + "sources": [ + { + "unit": "software-engineering.purpose", + "clause": "c03" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "c01" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "c02" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "c03" + } + ] + }, + { + "id": "T25", + "kind": "theorem", + "source_line_spans": [ + [ + 175, + 179 + ] + ], + "statement": "For a context meeting all priority conditions, with a credible evolution advantage over a simpler feasible option and no concrete cost threat, domain satisfaction requires the evolution-favoring choice/priority and acceptance of its relevant additional complexity.", + "premises": [ + "Every T24 premise explicit, adopted domain rule as normative premise", + "preference compliance separate from act of assessment and universal goodness. Do not infer adoption from Core alone." + ], + "required_cases": [ + "applicable_choose_evolution", + "applicable_choose_simple_violates_domain", + "threat_allows_departure_with_account" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "theorem", + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "c01" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "c02" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "c03" + } + ] + }, + { + "id": "T26", + "kind": "specification", + "source_line_spans": [ + [ + 177, + 179 + ] + ], + "statement": "Credible change direction has articulable grounds (examples are plan/domain knowledge/history, not an exhaustive required list), remains revisable, and needs no existing multiple implementations. Conceivability alone cannot justify present accommodation.", + "premises": [ + "Grounds for direction and present investment separately", + "applicability of history/knowledge", + "no Boolean label replacing content of supporting plan." + ], + "required_cases": [ + "committed_plan_one_implementation", + "domain_knowledge", + "applicable_history", + "conceivable_only", + "revised_forecast" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "definition", + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "c02" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "c03" + } + ] + }, + { + "id": "T27", + "kind": "nonentailment", + "source_line_spans": [ + [ + 177, + 179 + ] + ], + "statement": "Conceivable change alone does not entail warranted accommodation; credible change does not entail multiple existing implementations, maximal extensibility, retention of every possibility or universal numerical exchange rate.", + "premises": [ + "Nonempty supported direction and explicit alternative irrelevant direction", + "finite priority/qualitative comparison", + "credibility independent of current multiplicity." + ], + "required_cases": [ + "one_implementation_credible", + "imagined_unwarranted", + "selective_evolution", + "qualitative_tradeoff" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "theorem-or-case", + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "c02" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "c03" + } + ] + }, + { + "id": "T28", + "kind": "specification", + "source_line_spans": [ + [ + 179, + 179 + ] + ], + "statement": "Cost/departure account admits understanding, construction, diagnosis, verification, coordination, operation and eventual migration burdens and identifies threatened objective and causal significance of added cost.", + "premises": [ + "Do not require every burden be material in every case", + "costs attached to candidate/context and concrete objective, not free exception flag." + ], + "required_cases": [ + "understanding_threat", + "construction_threat", + "diagnosis_threat", + "verification_threat", + "coordination_threat", + "operation_threat", + "migration_threat", + "unsupported_cost_excuse" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "definition", + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "c03" + } + ] + }, + { + "id": "T29", + "kind": "specification", + "source_line_spans": [ + [ + 184, + 186 + ] + ], + "statement": "Evolution includes capability addition, implementation replacement, mechanism deletion, abstraction withdrawal, boundary redrawing and technology/model migration; claims identify relevant changes and maintainer conditions; independent/coordinated changes and preserved/revised obligations may require different structures.", + "premises": [ + "Nonexhaustive source include-list", + "identified capability relation indexed by change, context and maintainer", + "obligation semantics tracked." + ], + "required_cases": [ + "addition", + "replacement", + "deletion", + "withdrawal", + "redrawing", + "migration", + "independent", + "coordinated", + "preserve_obligation", + "revise_obligation" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "definition", + "sources": [ + { + "unit": "software-engineering.evolution-meaning", + "clause": "c01" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "c02" + } + ] + }, + { + "id": "T30", + "kind": "nonentailment", + "source_line_spans": [ + [ + 184, + 186 + ] + ], + "statement": "Cheap/effective additions within fixed scheme do not entail equal ability to revise/leave it; advantage on one dimension does not entail every dimension; no duty to make every change inexpensive.", + "premises": [ + "Concrete change-work or enabled-path relation producing add/exit contrast and independent/coordinated contrast", + "no arbitrary unsupported capability flags." + ], + "required_cases": [ + "easy_add_hard_exit", + "independent_easy_coordinated_hard", + "some_change_expensive_permitted" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "theorem-or-case", + "sources": [ + { + "unit": "software-engineering.evolution-meaning", + "clause": "c01" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "c02" + } + ] + }, + { + "id": "T31", + "kind": "specification", + "source_line_spans": [ + [ + 191, + 193 + ] + ], + "statement": "Structural choice applies to whole relevant engineering consequences: component relations, observable contracts, understanding and verification work; boundary capability needs support for intended changes; propagation/cross-boundary knowledge and obligations/fixed assumptions/withdrawal are possible comparison inquiries.", + "premises": [ + "Whole relevant scope rather than every imaginable consequence", + "may-examine inquiries are not compulsory universal checklist", + "intended change and boundary support relation explicit." + ], + "required_cases": [ + "contract_and_work_comparison", + "propagation_relation", + "cross_boundary_obligation", + "fixed_assumption", + "withdrawal_cost" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "definition", + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "c01" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "c02" + } + ] + }, + { + "id": "T32", + "kind": "nonentailment", + "source_line_spans": [ + [ + 191, + 193 + ] + ], + "statement": "Interface shape, module/extension-point count, named principle or boundary introduction alone cannot establish claimed evolution capability or easier intended change.", + "premises": [ + "Executable or finite semantic consequence model links shape to behavior and work to change", + "demonstrate missing capability by contract/propagation/work failure rather than named false flag." + ], + "required_cases": [ + "same_shape_broken_order", + "many_modules_shared_obligation", + "named_pattern_no_change_path", + "new_boundary_same_work" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "theorem-or-case", + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "c01" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "c02" + } + ] + }, + { + "id": "T33", + "kind": "specification", + "source_line_spans": [ + [ + 195, + 195 + ] + ], + "statement": "Distinguish preserving an identified observable contract from deliberately revising it; deliberate revision accounts for changed obligations and affected parties; no requirement to preserve every historical behavior or use particular tests/migration procedure.", + "premises": [ + "Identified contract and observations, deliberate revision intent, obligations/affected parties mapping", + "preservation scope explicit", + "changes outside scope not silently violations." + ], + "required_cases": [ + "preserve_identified_contract", + "deliberate_revision_with_account", + "revision_missing_parties", + "retired_historical_behavior", + "alternative_procedure" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "definition", + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "c03" + } + ] + }, + { + "id": "T34", + "kind": "theorem", + "source_line_spans": [ + [ + 195, + 195 + ] + ], + "statement": "Given equality of all identified contract observations in scope, a transformation preserves that identified contract; deliberate changed in-scope observations cannot be claimed preservation of that same contract and require revised-obligation/party account under domain satisfaction.", + "premises": [ + "Contract semantics and scope, total behavior on registered domain, at least one explicit distinguishing observation for revision, domain rule", + "finite examples reported finite." + ], + "required_cases": [ + "order_preserving_refactor", + "sorted_order_revision", + "changed_failure_obligation", + "outside_scope_difference" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "theorem", + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "c03" + } + ] + }, + { + "id": "T35", + "kind": "specification", + "source_line_spans": [ + [ + 201, + 203 + ] + ], + "statement": "Changed evidence about expected changes, maintenance conditions, costs/objectives can justify revised design/priority application; revised judgment acknowledges material grounds changes and cannot retroactively relabel failed prediction success. Retention may be justified by alternatives lacking contribution or defeating objectives.", + "premises": [ + "Separate old/new evidence/time, prediction outcome and judgment, permission versus compulsory redesign", + "applicable alternatives and objective explicit." + ], + "required_cases": [ + "revised_change_forecast", + "changed_maintainers", + "changed_cost", + "changed_objective", + "failed_prediction_preserved", + "justified_retention" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "definition", + "sources": [ + { + "unit": "software-engineering.revision", + "clause": "c02" + } + ] + }, + { + "id": "T36", + "kind": "nonentailment", + "source_line_spans": [ + [ + 201, + 203 + ] + ], + "statement": "Revised judgment cannot make past failed prediction true; continued change, agreement and successful examples do not establish universal correctness; justified retention is compatible with domain/reflexive revision openness.", + "premises": [ + "Time-indexed prediction semantics invariant under report revision", + "finite successes with explicit broader failure", + "activity is open to criticism while choosing stability now." + ], + "required_cases": [ + "past_failure_not_rewritten", + "agreement_with_bad_case", + "local_success_global_failure", + "open_stable_design" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "theorem-or-case", + "sources": [ + { + "unit": "software-engineering.revision", + "clause": "c02" + } + ] + }, + { + "id": "T37", + "kind": "theorem", + "source_line_spans": [ + [ + 161, + 161 + ], + [ + 191, + 191 + ], + [ + 203, + 203 + ], + [ + 148, + 148 + ] + ], + "statement": "With inherited and domain satisfaction in a shared applicable context, the priority and evolution-assessment methods remain objects of grounds, consistency and reflexive criticism/revision; domain success cannot exempt its rule.", + "premises": [ + "Same domain-rule object assessed via inherited predicates", + "explicit relevant applicability", + "user adoption choice distinguished from metalevel correctness." + ], + "required_cases": [ + "priority_self_assessment", + "method_self_criticism", + "no_selfproof_from_success" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "theorem", + "sources": [ + { + "unit": "organon.relationships.roles", + "clause": "c03" + }, + { + "unit": "extensions", + "clause": "c01" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "c01" + } + ] + }, + { + "id": "T38", + "kind": "satisfiability", + "source_line_spans": [ + [ + 25, + 27 + ], + [ + 32, + 52 + ], + [ + 57, + 87 + ], + [ + 92, + 148 + ], + [ + 161, + 203 + ] + ], + "statement": "USER ADDITIONAL STRONG OBJECTIVE: one content-bearing nonempty system/context jointly satisfies every represented inherited and domain commitment, with a continuing lifecycle, actual applicable priority and evolution chosen despite additional present abstraction complexity.", + "premises": [ + "Common context/subjects/claims/reasons/alternatives", + "shared nontrivial consequence relation", + "actual empirical/inferential/value duties relevant and fulfilled where represented", + "successor+agent maintenance pathways, credible design-change direction, satisfied necessary requirements, no defeating cost threat. Whole Inherited and Domain interfaces used, not subset." + ], + "required_cases": [ + "joint_all_inherited_and_domain", + "same_context_identity", + "nonempty_claims_and_principles", + "active_evolution_priority", + "content_bearing_maintainer_change" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "theorem-or-case", + "sources": [ + { + "unit": "organon.charter.overview", + "clause": "c02" + }, + { + "unit": "organon.charter.overview", + "clause": "c03" + }, + { + "unit": "organon.charter.self-transcendence", + "clause": "c01" + }, + { + "unit": "organon.charter.self-transcendence.orientation", + "clause": "c01" + }, + { + "unit": "organon.charter.self-transcendence.non-finality", + "clause": "c01" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "c01" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "c02" + }, + { + "unit": "organon.charter.consistency", + "clause": "c01" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "c01" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "c02" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "c01" + }, + { + "unit": "organon.charter.reflexivity", + "clause": "c01" + }, + { + "unit": "organon.charter.reflexivity.meaning", + "clause": "c01" + }, + { + "unit": "organon.charter.reflexivity.limits", + "clause": "c01" + }, + { + "unit": "organon.grounds", + "clause": "c01" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c01" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c02" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c03" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c04" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c05" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c06" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c07" + }, + { + "unit": "organon.grounds.scope", + "clause": "c01" + }, + { + "unit": "organon.grounds.scope", + "clause": "c02" + }, + { + "unit": "organon.grounds.scope", + "clause": "c03" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "c01" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "c02" + }, + { + "unit": "organon.grounds.implementations", + "clause": "c01" + }, + { + "unit": "organon.grounds.implementations", + "clause": "c02" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "c01" + }, + { + "unit": "organon.relationships.roles", + "clause": "c01" + }, + { + "unit": "organon.relationships.roles", + "clause": "c02" + }, + { + "unit": "organon.relationships.roles", + "clause": "c03" + }, + { + "unit": "extensions", + "clause": "c01" + }, + { + "unit": "software-engineering.purpose", + "clause": "c01" + }, + { + "unit": "software-engineering.purpose", + "clause": "c02" + }, + { + "unit": "software-engineering.purpose", + "clause": "c03" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "c01" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "c02" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "c03" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "c01" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "c02" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "c01" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "c02" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "c03" + }, + { + "unit": "software-engineering.revision", + "clause": "c01" + }, + { + "unit": "software-engineering.revision", + "clause": "c02" + } + ] + }, + { + "id": "T39", + "kind": "nonentailment", + "source_line_spans": [ + [ + 161, + 161 + ], + [ + 175, + 179 + ], + [ + 144, + 148 + ] + ], + "statement": "USER ADDITIONAL STRONG OBJECTIVE: a countermodel satisfies all represented inherited commitments while genuine domain-priority applicability holds and domain evolution priority is not adopted; proves non-entailment in the disclosed representation.", + "premises": [ + "Same common context as all inherited duties", + "continuing lifecycle (not temporary), supported credible evolution advantage including design revision, requirements satisfied, no concrete defeating cost threat, present-simplicity preference actually selected/adopted, grounded alternative value reasons consistent with Core, assessment not substituted for adoption." + ], + "required_cases": [ + "all_inherited_applicable_domain_not_adopted", + "no_temporary_escape", + "no_cost_escape", + "genuine_priority_failure", + "inherited_grounds_for_other_value" + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment.", + "recommended_declaration_kind": "theorem-or-case", + "sources": [ + { + "unit": "organon.relationships.roles", + "clause": "c01" + }, + { + "unit": "organon.relationships.roles", + "clause": "c02" + }, + { + "unit": "organon.relationships.roles", + "clause": "c03" + }, + { + "unit": "extensions", + "clause": "c01" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "c01" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "c02" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "c03" + } + ] + }, + { + "id": "T40", + "kind": "boundary", + "source_line_spans": [ + [ + 13, + 15 + ], + [ + 49, + 52 + ], + [ + 92, + 105 + ], + [ + 112, + 121 + ], + [ + 126, + 128 + ], + [ + 144, + 148 + ], + [ + 161, + 179 + ], + [ + 184, + 203 + ] + ], + "statement": "Formal specification/conditional proofs and finite witnesses do not establish empirical adequacy of lifecycle forecasts, support relevance, future maintainability, value superiority or universal philosophical correctness; representation choices remain disclosed and revisable.", + "premises": [ + "Every conditional result carries full mathematical premises", + "finite cases and source correspondence judgments are separate", + "difficult agreed theorem cannot be reclassified boundary to claim completion." + ], + "required_cases": [], + "acceptance": "Review manuscript distinction of normative expression, fulfillment witness, mathematical entailment, empirical support and adoption; retain unresolved material readings and every unfinished target.", + "recommended_declaration_kind": null, + "sources": [ + { + "unit": "organon.preamble", + "clause": "c01" + }, + { + "unit": "organon.preamble", + "clause": "c02" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "c02" + }, + { + "unit": "organon.grounds", + "clause": "c01" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c01" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c02" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c03" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c04" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c05" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c06" + }, + { + "unit": "organon.grounds.assessment", + "clause": "c07" + }, + { + "unit": "organon.grounds.scope", + "clause": "c02" + }, + { + "unit": "organon.grounds.scope", + "clause": "c03" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "c01" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "c02" + }, + { + "unit": "organon.grounds.implementations", + "clause": "c01" + }, + { + "unit": "organon.grounds.implementations", + "clause": "c02" + }, + { + "unit": "organon.relationships.roles", + "clause": "c01" + }, + { + "unit": "organon.relationships.roles", + "clause": "c02" + }, + { + "unit": "organon.relationships.roles", + "clause": "c03" + }, + { + "unit": "extensions", + "clause": "c01" + }, + { + "unit": "software-engineering.purpose", + "clause": "c01" + }, + { + "unit": "software-engineering.purpose", + "clause": "c02" + }, + { + "unit": "software-engineering.purpose", + "clause": "c03" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "c01" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "c02" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "c03" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "c01" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "c02" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "c01" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "c02" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "c03" + }, + { + "unit": "software-engineering.revision", + "clause": "c01" + }, + { + "unit": "software-engineering.revision", + "clause": "c02" + } + ] + } + ], + "coverage": { + "units": 28, + "clauses": 54, + "targets": 40, + "uncovered_substantive_clauses": [] + } +} diff --git a/SoftwareEngineering/lean/philosophy/reviews/source-initial.md b/SoftwareEngineering/lean/philosophy/reviews/source-initial.md new file mode 100644 index 0000000..c4f646f --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/source-initial.md @@ -0,0 +1,40 @@ +# 独立 source-first 初稿 — SoftwareEngineering 全文 + +记录时间:2026-09-14T16:44:03.740255+00:00。审阅者:`/root/se_source_first`。本记录在查看作者目标目录、候选 Lean 或既有 Core Lean 模型/旧评审文件之前形成。这里只写本记录和 `source-first-targets.json`,未编码、未修改源文本、未执行源示例。 + +## 对象、基准与实际暴露 + +选择基准与被形式化源均为 `SoftwareEngineering/PHILOSOPHY.md`,SoftwareEngineering 0.2.0 / Core 0.1.2;SHA256 `6c6ae78a23f2726c5c370434e808d76c206647fe7793245e88cae52c076abe34`。`derived_from` 是源的继承元数据,其 Core hash 不能替代本次实际源 hash。Core 当前 0.1.3 只约束审阅方法及 Core 维护。父任务保留调用者为本次用户任务,真实相对引用目录为 `SoftwareEngineering`。 + +已完整读主源,包括表格、含义、限度及关系。已读 rationale 和 cases 作为解释背景,没有访问其中外部链接,未主张重新核实其文献摘要或既有运行结果。按根规则读取 `.local/ACTIVE.md` 时,索引暴露了过去 Core 完成数和状态摘要;没有打开其链接、旧代码、旧目标目录或评审原文。这一有限暴露如实保留,不能声称完全未见任何历史状态。已见父任务和 `ACCEPTED-PLAN.md` 中的用户强证明目标;未见作者形式化方案、候选目录或预期正确结论。各实际输入路径与 SHA256 在 JSON 的 `inputs`。 + +## 完整性与分类方法 + +JSON 保留 28 个 direct-body 单元、54 个本地段落/表格行分片和 40 个建议目标,保留所有 direct-body 原文字节(含空白),每片带精确行区间与目标映射。纯标题结构和表头/分隔行有独立标记;术语表两行是约束语义,不能当纯格式丢弃。没有未追踪的实质分片。本地 `cNN` 仅供初稿定位,作者须对齐仓库 parser/run 的真实 clause ID 后冻结;这不是现成的 `targets.json`。 + +目录按完整语义与分支组织,重复条款共享目标。T01–T21 覆盖继承承诺及关系,T22–T37 覆盖领域主体、优先、演化、结构、修订,T38–T39 是用户明确额外的强关系证明,T40 固定非形式边界。每项在 JSON 给 statement、完整前提族、证据种类、正反案例和完成判据。specification 是义务表达,不是履行证明;theorem 是采用规则和公开前提下的推论;有限实例是所声明表示的满足性或非蕴含证据,不是现实经验或价值正确性。 + +## 编码前须保留的区别 + +1. **旧 Core 0.1.2 不得偷增。** 子哲学 §2.1 止于 articulation/support 区别,没有当前 Core 0.1.3 的 “more than one applicable aspect” 和 “Omitting a classification” 两句。可以为诚实对应而不强迫互斥/穷尽分类,可以在应用中表达混合内容,但不能把“全部实际 aspect 无遗漏分类义务”作为子哲学明文新增公理。任何强化须标为额外表示/应用假设,不能说继承而来。不要直接复制当前 Core 满足接口再声称是旧基准。 +2. **支持不是完成评估。** Assessment 要检查对应 grounds 是否支持 claim;完成检查不保证被检查主张受支持。反例应有可解释的支持失败(反赋值、遗漏相关观测、维度超范围、可见契约违例),不能用 `supported := false` 或“无记录”冒充不足依据。 +3. **一致性是联合后果。** 全体同时持有判断的 consequence relation 须能检测由组合前提才推出的冲突;单个原则分别无冲突不足。条件、词义、问题、范围相同才构成要求中的冲突。修订可撤回,不能把历史并集作当前义务,也不能靠静默换 scope 消失冲突。 +4. **领域主体是 continuing activity。** 维护者包括接任者与 agent,软件本身不是自动拥有 intrinsic orientation 的主体。作者能编辑与继任者有可理解/修改/验证路径是不同主张。credibility 应有 plan/knowledge/history 等内容,但这些例示不穷尽全部合法依据。 +5. **适用与例外。** §4.2 以必要 requirements 满足为条件,并承接可信 lifecycle/maintenance。priority 是可让步的默认价值承诺;威胁具体目标的 added costs 才能在模型里形成相应例外,须有目标与成本关联说明。不要把每种 cost 都变成每案必需,也不要把 “may have little reason” 变成所有 temporary 类型绝对豁免。 +6. **优先与行动的读法。** “give priority / Accept additional complexity” 至少是理由/偏好与接受负担的规范,不能仅表示“评估已执行”;建模为实际选择需公开 candidate 比较、可行性、可信演化优势与相关成本的条件。若证明只覆盖二选一严格优势场景,报告为该场景的表示,而非任意真实决策的完备理论。 +7. **evolution 不只是 add。** addition/replacement/deletion/withdrawal/redrawing/migration 六类,以及 independent/coordinated、preserve/revise obligations 的不同维度均要追踪。它们是 “includes / can require”,不应变成穷尽本体或要求每案实现全部变化且均廉价。 +8. **整体后果与可选考察。** contract、component relation、understanding/verification work 不可被接口形状取代。propagation/knowledge/obligation/fixed assumptions/withdrawal 的 “may examine” 不能升级成每次必做 scorecard。 +9. **契约修订和历史真实。** preserved identified observable contract 与 deliberately revised contract 区别明确;后者需要 changed obligations/affected parties 说明,但不要求保存一切历史行为或特定测试/迁移法。新证据可改变新判断,不能使旧预测倒转成功。 +10. **规范角色不冒充不可能性。** 原文 “does not claim ... follows” 明确不提出推导与层级,不单靠该措辞就证明任何逻辑表示下都不蕴含。用户明确要求的强非蕴含目标另列 T39;其数学范围和适配前提要逐项审查。 + +## 强关系目标的独立建议 + +**T38 联合满足见证。** 采用一个真实含内容的有限工程场景:继续维护的软件,接任维护者和 agent 有明确可用工具/知识,已满足行为、安全、性能及其他必要约束;一项有计划依据的设计修订在候选 A 中可实现且可验证,在更简单候选 B 中负担更高;A 的现有抽象更复杂但不威胁具体目标。系统重视扩展、保持方法/原则可修订、联合判断一致,对相关 empirical/inferential/value 主张给出限定依据,允许原则和评估法自适用且保持适用条件;据此采用 A。证明必须是同一个 ctx 同时满足整个 represented inherited interface 和整个 domain interface,不能分别给互不相关实例。至少一个相关 principle/self-target、非空 claim、有效推论、实质演化比较应真实活跃,避免全空/default-True。 + +**T39 强反例。** 保留 continuing lifecycle、可信设计演化优势、全部必要 requirements 满足且无具体成本威胁;不允许 temporary、成本例外或“做过评估”借口。一个价值选择者认可演化值得追求并保持一切现有形式开放,也满足 inherited Grounds、选择理由与自省义务,但在当前可行 tradeoff 中以另一公开且限定的价值理由采用现有抽象简单候选 B,未采纳领域默认优先。其理由不能只有名称/传统/地位,也不能谎报 A 不可行或构成 objective threat。这里说明 Core 的 intrinsic orientation 不等同于每个决策都把未来演化放在 present simplicity 之前;持有不同优先次序仍须自行说明理由与一致性。若模型把 self-transcendence 直接定义为领域 priority,则反例被定义排除,属于偷增基准。该目标若无法形成忠实反例,必须保留失败/未解,而非换弱条件。 + +这两个目标来自用户额外证明契约;源 §4 开头与 rationale 的附加价值说明提供解释背景。联合满足证明不建立采纳充分理由,强反例不反驳领域承诺价值,也不证明其现实错误。 + +## 当前自检与交接 + +已以脚本检查所有 substantive direct-body 分片都有目标映射;JSON 可解析并记录源/基准实际 hash。没有运行 Lean 或源码案例,没有用文件检查宣称语义正确。此初稿是在作者比较前独立产生,后续发现应另追加 dated comparison,而不覆盖本次原判断。目标可以在不丢义务/分支的前提下重新归组;任何实质范围或读法差异应保留并由主任务按用户契约处理。 diff --git a/SoftwareEngineering/lean/philosophy/reviews/source-migration-2026-09-15.md b/SoftwareEngineering/lean/philosophy/reviews/source-migration-2026-09-15.md new file mode 100644 index 0000000..1012d9f --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/source-migration-2026-09-15.md @@ -0,0 +1,19 @@ +# Independent source migration review — advised 0.2.1 + +Reviewer: root agent, distinct from content_migration builder. This is a comparison review after the independently recorded initial assessment; it is not a blind review of new philosophical commitments. + +## Exact object + +Current English source SHA-256: `adc8cce5ac55a5e3795f8806748603eb69d5695fa37bbe263bee20ac6c14a1a6`. Original source, code, target declarations and readers were preserved under the release baseline. The reviewer directly compared both English sources and rationale text, target JSON, English/Chinese philosophy and four reader views; code files and declaration lists were checked for byte/value identity. + +## Findings and scope + +The English philosophical change consists only of the user-approved version metadata and the rationale URL in organon.preamble p2. Rationale text is unchanged. The p2 distinctions between authoritative provisions, mutually constraining charter/Grounds, non-normative rationale and revisable skills remain identical. Other philosophical provisions are unchanged. The Chinese source preserves the same changed references and metadata without changing force or scope. + +The current target bodies and all Lean code/declarations remain unchanged. T01 retains its documentary/authority boundary; changing a link or version does not create a new mathematical claim, prove authority, or establish real-world fulfillment. Previous interpretation judgments may be reused for their exact unchanged code, assumptions and source clauses, with this review documenting the new whole-source binding. Preserve limited, incomplete, nonformal and not-applicable results. This review supplies no upgrade of target/source status. + +The four readers retain the same exact source excerpt with its new URL and existing status. For the domain readers, describe the checkpoint as remaining Core0.1.2, without suggesting that tool runtime version selects the adopted baseline. Domain derived_from and the source lock remain historical provenance. + +## Decision + +The path-only source migration is accepted within this stated comparison scope, conditional on actual refreshed binding/current manuscript checks and documented historical replay. Preserve original review files as historical judgments; append this review as a distinct current migration object. Mechanical gates and this limited review do not establish universal philosophical correctness. diff --git a/SoftwareEngineering/lean/philosophy/reviews/target-freeze-review.md b/SoftwareEngineering/lean/philosophy/reviews/target-freeze-review.md new file mode 100644 index 0000000..eb6c551 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/reviews/target-freeze-review.md @@ -0,0 +1,28 @@ +# 冻结前最终窄复核 + +时间:2026-09-14T16:56:15.877540+00:00。独立源文审阅者:`/root/se_source_first`。 + +**通过,可以冻结当前目录。** 本判断仅接受证明合同的范围、分支和已修正来源映射,不是Lean实现、案例真实性、source fidelity或最终证明完成的验收。仍未查看候选Lean、旧Core模型或旧评审文件,也未参与编码。独立初稿及前次阻断判断保持不变。 + +当前 `targets-draft.json` SHA256:`c0939df35dad148a0543ba92a1ac7b7d3b2eb4946f92ac4be251ec51b6481d13`。 + +## 阻断项逐项结论 + +- R1:T35/T36现在都引用 `software-engineering.revision:p1` 与 `p2`;T37已有该单元p2;T08新增 `organon.relationships.roles:p1` 和 `organon.grounds:p1`。重新检查真实source和source hash,定位修正满足前次要求。我的初稿尾段off-by-one原因仍由前次记录保留,不回写旧文件。 +- R2:T08 statement明确“所披露表示中的一个非空共同context满足完整represented Charter而具体claim不满足general Grounds”;premises把Charter连到T02/T04/T07及适用条件,把Grounds连到T09的articulation、对应assessment、proportionality,并要求实质claim/grounds/scope/strength失败,排除空域、缺record、自由False标签及假定Grounds。有限模型与所有可能表示下绝对独立已明确区分。满足此次新增目标的可冻结精度。 +- 新增 `composition_scope` 精确列明继承规范T02/T04/T07/T09/T10/T11/T12/T14/T16/T18、关系/术语T20/T21、领域规范T22/T24/T26/T28/T29/T31/T33/T35、领域反思T37。T38同ctx联合满足和T39全部继承成立且领域实际适用/无成本例外/实际拒绝优先均保留;适用条件及许可不被升级成每案所有条件都成立。 + +## 再检查的保持项 + +40目标ID和kind保留;全部原始premises及原semantic_cases保留,新增项未替代旧项。源仍为SoftwareEngineering0.2.0 / Core0.1.2,SHA256 `6c6ae78a23f2726c5c370434e808d76c206647fe7793245e88cae52c076abe34`。新增组合范围没有导入Core0.1.3的mixed-aspect/omitted-classification新增义务。声明名是binding,不证明175个semantic_cases存在;实际代码须逐一审查内容、语义适配、完整类型及依赖。 + +T08的有限模型说明宜在读者稿中表述为“在该表示中显示不蕴含;原文不提供基于排布的推导”,不能倒称有限实例证明了文档排布的普遍元理论。此为现有scope的表达约束,不是阻断或新增证明目标。T19的general assessment有限读法也不能替代T39完整继承满足。 + +## 实际输入与检查 + +- `targets-draft-before-r2.json` SHA256 `e5969a63f0b7552b81b9870343bcbb6d9ae6736fdd565e72075eb10639ddbc16`。它已包含R1修正,本次与其差异仅为T08 statement/premises/sources和composition_scope。 +- `target-freeze-independent-comparison.md` SHA256 `64b6e4e12a073822f122fddecd9014d30413864e6842713e33ecfba0f9ad1391`。 +- 实际检查:读取上述draft差异;断言R1全部源引用存在;逐40项比较独立初稿的kind、原premises、原案例集合无丢失;确认当前实际源hash一致;独立审读R2新增语义。 +- 未执行Lean或源示例,未给任何实现对象fidelity接受判断。 + +后续冻结应采用上述新hash对应字节并保留本审查绑定。若数学前提、target scope或案例语义后来实质变化,应保存新版本并复核,不能以名称不变维持旧验收。 diff --git a/SoftwareEngineering/lean/philosophy/run.json b/SoftwareEngineering/lean/philosophy/run.json new file mode 100644 index 0000000..e0e6c73 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/run.json @@ -0,0 +1,2252 @@ +{ + "schema_version": 1, + "source": { + "kind": "organon", + "path": "../../PHILOSOPHY.md", + "snapshot": "snapshots/PHILOSOPHY.md", + "sha256": "adc8cce5ac55a5e3795f8806748603eb69d5695fa37bbe263bee20ac6c14a1a6", + "metadata": { + "format_version": "0.1.0", + "philosophy_version": "0.2.1", + "core_version": "0.1.2", + "derived_from": { + "source_id": "https://github.com/shendeguize/OrganonCore", + "philosophy_version": "0.1.2", + "content_hash": "cb23f8a44d6b877ff9b5385961ff8e5fa788f8021ae267cdc8e305870ec20ca7" + } + } + }, + "baseline": { + "path": "../../PHILOSOPHY.md", + "sha256": "adc8cce5ac55a5e3795f8806748603eb69d5695fa37bbe263bee20ac6c14a1a6" + }, + "project": { + "path": "leanified", + "root_module": "CoreReader" + }, + "preregistration": { + "path": "PREREGISTERED.md", + "sha256": "f39cb0e07ace7d0ea330d90f8102f06f8f623d976ad8e0f3e6df729772bfbfcc" + }, + "proof_targets": { + "path": "targets.json", + "sha256": "19184f5f301fb5a2f156d09a1d5b4fee5f9e8e9bbc96fdc5fbbc9ccb426287bb" + }, + "units": [ + { + "id": "organon.preamble", + "hash": "9080c157865a0a07b88739a413018368e380c1f9525b3b6a74c332b94e8f25dc", + "status": "nonformal", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "This is a statement of Software Engineering Organon’s adopted philosophy. It expresses commitments, not factual assertions about every system or a proof of universal correctness.", + "declarations": [], + "status": "nonformal", + "reason": "Documentary context or a disclosed nonformal boundary; no theorem of universal correctness is assigned." + }, + { + "id": "p2", + "claim": "The quoted provisions, their meanings, and their conditions of application form the core. The charter and Grounds constrain one another; their grouping establishes neither a deductive hierarchy nor an order of priority. [Rationale](rationale/README.md) supplies arguments and cases without adding obligations to this core. Skills are revisable applications under the repository’s stated objectives and constraints, not part of the philosophical commitments themselves.", + "declarations": [], + "status": "nonformal", + "reason": "Documentary context or a disclosed nonformal boundary; no theorem of universal correctness is assigned." + } + ] + }, + { + "id": "organon.charter", + "hash": "01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b", + "status": "structural", + "reason": "Heading without substantive direct-body content.", + "clauses": [] + }, + { + "id": "organon.charter.overview", + "hash": "75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c", + "status": "partial", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "**Self-Transcendence · Internal Consistency · Reflexivity**", + "declarations": [], + "status": "nonformal", + "reason": "Documentary context or a disclosed nonformal boundary; no theorem of universal correctness is assigned." + }, + { + "id": "p2", + "claim": "> A system is intrinsically oriented toward expanding what it can understand and construct. It brings itself and its principles within the scope of generation and assessment, with internal consistency constraining this process.", + "declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases", + "CoreReader.Engineering.jointWitness" + ] + }, + { + "id": "p3", + "claim": "The overview connects three distinct requirements: self-transcendence establishes a generative orientation and refuses to treat existing forms as final, internal consistency constrains judgments held simultaneously, and reflexivity brings the system and its principles within the scope of their own generation and assessment. The provisions below specify the conditions for each.", + "declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases", + "CoreReader.Engineering.jointWitness" + ] + } + ] + }, + { + "id": "organon.charter.self-transcendence", + "hash": "f4ca590e2ae15e3882f70c7b2bc46a8911c97cee547c8b137b5493fbf862c8c0", + "status": "partial", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "> A system is intrinsically oriented toward expanding what it can understand and construct. It does not regard any existing form as the endpoint of generation.", + "declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases", + "CoreReader.Engineering.jointWitness" + ] + } + ] + }, + { + "id": "organon.charter.self-transcendence.orientation", + "hash": "7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf", + "status": "partial", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "A commitment to keeping generative possibilities open is distinct from valuing their expansion. A system has an intrinsic orientation when it regards that expansion as worth pursuing. Merely permitting change does not fully express this orientation.", + "declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases", + "CoreReader.Adopted.generationLimits012", + "CoreReader.Engineering.jointWitness" + ] + } + ] + }, + { + "id": "organon.charter.self-transcendence.non-finality", + "hash": "4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8", + "status": "partial", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "Refusing to regard an existing form as an endpoint keeps it open to being surpassed. “Existing form” includes a system’s current organization, methods, and principles, not only its appearance or artifacts. These remain within the scope of possible change; their revisability does not guarantee actual progress.", + "declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases", + "CoreReader.Adopted.generationLimits012", + "CoreReader.Engineering.jointWitness" + ] + } + ] + }, + { + "id": "organon.charter.self-transcendence.limits", + "hash": "6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d", + "status": "partial", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "Whether progress has actually occurred remains a separate judgment. Having the orientation does not guarantee progress. Progress cannot be established merely by an increase in the number of artifacts, levels of abstraction, or terms.", + "declarations": [ + "CoreReader.Adopted.generationLimits012", + "CoreReader.Engineering.jointWitness" + ] + }, + { + "id": "p2", + "claim": "- “Intrinsic orientation” expresses Organon’s philosophical commitment; it does not assert that all systems in fact develop autonomously.\n- Self-transcendence does not imply independence from external experience, knowledge, or collaboration, nor does it guarantee autonomous execution or self-improvement.\n- Refusing to regard an existing form as an endpoint does not require every action to produce change. Justified stability can coexist with a generative orientation.\n- Whether transcendence expands what can be understood and constructed requires discernible grounds; a system’s own claim of generation does not establish actual achievement.", + "declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases", + "CoreReader.Adopted.generationLimits012", + "CoreReader.Engineering.jointWitness" + ] + } + ] + }, + { + "id": "organon.charter.consistency", + "hash": "c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42", + "status": "partial", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "> The principles and judgments a system holds simultaneously, together with their implications, must not yield contradictory judgments on the same question under the same assumptions, meanings of terms, and scope of application.", + "declarations": [ + "CoreReader.Adopted.consistencySpecification", + "CoreReader.Adopted.consistencyCases", + "CoreReader.Adopted.consistencyConsequences", + "CoreReader.Engineering.jointWitness" + ] + } + ] + }, + { + "id": "organon.charter.consistency.meaning", + "hash": "81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa", + "status": "partial", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "“Held simultaneously” specifies which principles, judgments, and implications must hold together. Revision may withdraw an earlier judgment; old and new principles need not remain compatible forever. When a change has occurred, that change cannot be represented as though it had not occurred.", + "declarations": [ + "CoreReader.Adopted.consistencySpecification", + "CoreReader.Adopted.consistencyCases", + "CoreReader.Adopted.consistencyConsequences", + "CoreReader.Engineering.jointWitness" + ] + }, + { + "id": "p2", + "claim": "“The same assumptions, meanings of terms, and scope of application” specifies the basis for comparing judgments. Divergent judgments under different conditions do not automatically constitute contradictions. Nor can unacknowledged changes in assumptions, meanings, or scope be used to conceal an existing contradiction.", + "declarations": [ + "CoreReader.Adopted.consistencySpecification", + "CoreReader.Adopted.consistencyCases", + "CoreReader.Adopted.consistencyConsequences", + "CoreReader.Adopted.consistencyLimits012", + "CoreReader.Engineering.jointWitness" + ] + } + ] + }, + { + "id": "organon.charter.consistency.limits", + "hash": "4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75", + "status": "partial", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "- Tension between different assessments or values does not directly constitute a contradiction. Revision or qualification is needed when they require incompatible conclusions under the same conditions.\n- Internal consistency is not correctness or sufficiency. A set of principles may be internally consistent while relying on false assumptions or neglecting important questions.", + "declarations": [ + "CoreReader.Adopted.consistencySpecification", + "CoreReader.Adopted.consistencyCases", + "CoreReader.Adopted.consistencyConsequences", + "CoreReader.Adopted.consistencyLimits012", + "CoreReader.Engineering.jointWitness" + ] + } + ] + }, + { + "id": "organon.charter.reflexivity", + "hash": "13293b45c2fa89068c68ae7ef3c5df38f0efadb3ef3873d78a5ba67d9691a757", + "status": "partial", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "> A system’s principles of generation and assessment also apply to the system itself and to the formation, application, and revision of those principles.", + "declarations": [ + "CoreReader.Adopted.reflexivitySpecification", + "CoreReader.Adopted.reflexivityCases012", + "CoreReader.Engineering.jointWitness" + ] + } + ] + }, + { + "id": "organon.charter.reflexivity.meaning", + "hash": "8a2caede01a43d8b6c60b54c78ac089c51868e9956f316948077ccee2e45c9cc", + "status": "partial", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "Reflexivity encompasses both the system itself and its principles. Assessment concerns not only whether the system conforms to its principles, but also how those principles are formed, where they apply, and why they may need revision. The formation and revision of principles thus also become objects of generation and assessment.", + "declarations": [ + "CoreReader.Adopted.reflexivitySpecification", + "CoreReader.Adopted.reflexivityCases012", + "CoreReader.Engineering.jointWitness" + ] + } + ] + }, + { + "id": "organon.charter.reflexivity.limits", + "hash": "ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc", + "status": "partial", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "- Applying principles equally retains their conditions of application. When the relevant conditions hold, being the system itself is not a basis for exemption. Nor does the requirement of reflexivity establish that every principle can be applied to itself without examining its applicability.\n- Self-application does not constitute self-proof. Subjecting a principle to its own assessment does not thereby establish its correctness.\n- That a revision is produced by the system itself does not give it sufficient grounds.", + "declarations": [ + "CoreReader.Adopted.reflexivitySpecification", + "CoreReader.Adopted.reflexivityCases012", + "CoreReader.Adopted.reflexivityLimits012", + "CoreReader.Engineering.jointWitness" + ] + } + ] + }, + { + "id": "organon.grounds", + "hash": "4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6", + "status": "partial", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "> The grounds of principles and judgments must be articulable and subject to assessment appropriate to the nature of the claim. The strength and scope of a claim must be proportionate to the support provided by its grounds.", + "declarations": [ + "CoreReader.Adopted.reflexivityLimits012", + "CoreReader.Adopted.Grounds012", + "CoreReader.Adopted.groundsCases012", + "CoreReader.Engineering.jointWitness" + ] + } + ] + }, + { + "id": "organon.grounds.assessment", + "hash": "ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d", + "status": "partial", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "Articulation and assessment have distinct responsibilities. Articulability requires that concepts, assumptions, reasons, and limits can be identified. Assessment requires examining whether those grounds support the corresponding claim. Clearly expressed grounds are not thereby sufficiently established.", + "declarations": [ + "CoreReader.Adopted.Grounds012", + "CoreReader.Adopted.groundsCases012", + "CoreReader.Adopted.groundsLimits012", + "CoreReader.Engineering.jointWitness" + ] + }, + { + "id": "p2", + "claim": "| Type of claim | Responsibility of assessment | What cannot substitute for that responsibility |\n| --- | --- | --- |\n| Empirical claim | Examine observations, evidence, and performance, together with the conditions, scope, and uncertainty of their support for the claim. | Treating measurability or repeatability itself as proof of relevance, correctness, or value. |\n| Inferential claim | Examine whether the conclusion is supported by the stated assumptions and inferential relations. | Treating the absence of conflict between a conclusion and its assumptions as sufficient to establish that the conclusion follows from them. |\n| Value commitment | State the position taken, its reasons, limits of application, and consequences, and remain open to relevant criticism. | Presenting a commitment as an empirical fact or a necessary inference, or substituting self-assertion for reasons. |", + "declarations": [ + "CoreReader.Adopted.Grounds012", + "CoreReader.Adopted.groundsCases012", + "CoreReader.Adopted.empiricalSpecification", + "CoreReader.Adopted.empiricalCases012", + "CoreReader.Adopted.inferentialSpecification", + "CoreReader.Adopted.inferentialCases012", + "CoreReader.Adopted.valueSpecification", + "CoreReader.Adopted.valueCases012", + "CoreReader.Adopted.groundsLimits012", + "CoreReader.Engineering.jointWitness" + ] + }, + { + "id": "p3", + "claim": "Initial value commitments may be stated explicitly as commitments; they need not prove all their own starting assumptions. The strength and scope of a claim do not require conversion to a common numerical scale. Different types of claims specify their support and limits in accordance with their nature.", + "declarations": [ + "CoreReader.Adopted.Grounds012", + "CoreReader.Adopted.groundsCases012", + "CoreReader.Adopted.valueSpecification", + "CoreReader.Adopted.valueCases012", + "CoreReader.Adopted.groundsLimits012", + "CoreReader.Engineering.jointWitness" + ] + } + ] + }, + { + "id": "organon.grounds.scope", + "hash": "4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693", + "status": "partial", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "Performance is discerned within particular relations, conditions, and scopes of observation. A boundary helps specify what a comparison concerns, but local examples do not automatically support unconditional universal conclusions. A judgment cannot establish that relevant differences do not exist merely because its chosen scope omits them.", + "declarations": [ + "CoreReader.Adopted.scopeSpecification", + "CoreReader.Adopted.scopeCases012", + "CoreReader.Adopted.scopeLimits012", + "CoreReader.Engineering.jointWitness" + ] + }, + { + "id": "p2", + "claim": "Measurement can make some differences comparable. Repeated assessment can help examine the stability of corresponding conclusions. Their roles, and the role of any assessment framework, must be explained relative to the claim and its context. Measurement, repeatability, and an assessment framework do not form a universally necessary chain on which all judgments must depend.", + "declarations": [ + "CoreReader.Adopted.scopeSpecification", + "CoreReader.Adopted.scopeCases012", + "CoreReader.Adopted.scopeLimits012", + "CoreReader.Engineering.jointWitness" + ] + }, + { + "id": "p3", + "claim": "An observation that has not been reproduced may still offer limited support, and random outcomes need not be identical on every occasion. The verifiability of observations, reproducibility of conditions, and stability of conclusions must be distinguished.", + "declarations": [ + "CoreReader.Adopted.scopeSpecification", + "CoreReader.Adopted.scopeCases012", + "CoreReader.Adopted.scopeLimits012", + "CoreReader.Engineering.jointWitness" + ] + } + ] + }, + { + "id": "organon.grounds.capabilities", + "hash": "7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0", + "status": "partial", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "Capability claims are subject to Grounds: the capability claimed, its conditions, and the support for it must be identifiable. The core does not prescribe uniform definitions of method mastery, method generation, or capability levels. Applications specify the capabilities they assess and may require understanding, explanation, or performance under relevant variations.", + "declarations": [ + "CoreReader.Adopted.capabilitySpecification", + "CoreReader.Adopted.capabilityCases012", + "CoreReader.Adopted.capabilityLimits012", + "CoreReader.Engineering.jointWitness" + ] + }, + { + "id": "p2", + "claim": "Grounds for a capability claim may be supplied by an external assessor. Their articulability does not by itself require the assessed system to understand or explain its internal generation process. Evidence of reliable output must be assessed against the capability actually claimed; it does not automatically establish understanding of that process. Nor can the number of method documents, terms, tools, or artifacts alone establish a capability beyond what that evidence supports.", + "declarations": [ + "CoreReader.Adopted.capabilitySpecification", + "CoreReader.Adopted.capabilityCases012", + "CoreReader.Adopted.capabilityLimits012", + "CoreReader.Engineering.jointWitness" + ] + } + ] + }, + { + "id": "organon.grounds.implementations", + "hash": "bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c", + "status": "partial", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "> The choice of an implementation must be supported by reasons connected to the objectives and values pursued and to the relevant constraints. Its name, conventional use, or established status alone does not provide sufficient grounds for giving it priority.", + "declarations": [ + "CoreReader.Adopted.choiceSpecification", + "CoreReader.Adopted.choiceCases012", + "CoreReader.Adopted.choiceLimits012", + "CoreReader.Engineering.jointWitness" + ] + }, + { + "id": "p2", + "claim": "This choice provision adds an additional evaluative commitment: name, conventional use, or established status alone is insufficient to establish priority. Grouping it under Grounds does not mean that it follows from the general requirement to assess reasons, or merely from the discernibility of performance. Conventions and existing arrangements may have practical significance, but that significance must be connected to the objectives and values pursued and to the relevant constraints.", + "declarations": [ + "CoreReader.Adopted.choiceSpecification", + "CoreReader.Adopted.choiceCases012", + "CoreReader.Adopted.choiceLimits012", + "CoreReader.Engineering.jointWitness" + ] + } + ] + }, + { + "id": "organon.grounds.implementations.limits", + "hash": "db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870", + "status": "partial", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "- Openness does not make all implementations equivalent, nor does it guarantee multiple feasible implementations for the same objective.\n- A method’s explanatory power, limits of application, simplicity, and explicit process requirements may all provide grounded reasons for assessment. They cannot be excluded merely because they concern methods internal to the implementation.\n- Identical local performance does not establish overall equivalence. Relations, conditions, and the scope of comparison are constrained by the provisions of Grounds.\n- Openness does not reject an implementation merely because it already exists or is conventionally used. Relevant reasons may still give it priority.", + "declarations": [ + "CoreReader.Adopted.scopeLimits012", + "CoreReader.Adopted.choiceSpecification", + "CoreReader.Adopted.choiceCases012", + "CoreReader.Adopted.choiceLimits012", + "CoreReader.Engineering.jointWitness" + ] + } + ] + }, + { + "id": "organon.relationships", + "hash": "01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b", + "status": "structural", + "reason": "Heading without substantive direct-body content.", + "clauses": [] + }, + { + "id": "organon.relationships.roles", + "hash": "24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e", + "status": "partial", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "The charter states the generative orientation, the consistency constraint, and reflexive application. Grounds specifies support requirements for judgments and includes an additional commitment concerning implementation choices. Both parts belong to the core and constrain one another. Their placement neither makes Grounds a deduction from the charter nor gives the charter priority over it. Each commitment needs its own reasons.", + "declarations": [ + "CoreReader.Adopted.reflexivityLimits012", + "CoreReader.Engineering.inheritedMutualApplication", + "CoreReader.Engineering.inheritedMutualCases", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ] + }, + { + "id": "p2", + "claim": "Internal Consistency concerns whether simultaneously held judgments can hold together; Grounds concerns whether and how far a claim is supported. A conclusion may fail to conflict with its assumptions without being supported by them. Self-Transcendence specifies a generative orientation and non-finality; neither establishes actual capability. Applications may supply objectives, values, and capability definitions; claims made under those objectives, values, and definitions remain subject to the relevant core provisions.", + "declarations": [ + "CoreReader.Adopted.generationLimits012", + "CoreReader.Adopted.consistencyLimits012", + "CoreReader.Adopted.inferentialSpecification", + "CoreReader.Adopted.inferentialCases012", + "CoreReader.Adopted.capabilitySpecification", + "CoreReader.Adopted.capabilityCases012", + "CoreReader.Engineering.inheritedMutualApplication", + "CoreReader.Engineering.inheritedMutualCases", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ] + }, + { + "id": "p3", + "claim": "Self-Transcendence does not substitute for Reflexivity: keeping existing forms open to being surpassed differs from applying relevant principles to the system and to their own formation, application, and revision. Reflexivity extends these requirements to the system and to the formation, application, and revision of its principles. The grounds and limits of the Grounds provisions must themselves be articulable. The system’s own capability claims remain subject to assessment, and this philosophy’s existing form cannot gain priority merely from its established status. Such mutual application provides no self-proof and does not remove conditions of application.", + "declarations": [ + "CoreReader.Adopted.reflexivitySpecification", + "CoreReader.Adopted.reflexivityCases012", + "CoreReader.Adopted.reflexivityLimits012", + "CoreReader.Adopted.capabilitySpecification", + "CoreReader.Adopted.capabilityCases012", + "CoreReader.Adopted.choiceSpecification", + "CoreReader.Adopted.choiceCases012", + "CoreReader.Engineering.inheritedMutualApplication", + "CoreReader.Engineering.inheritedMutualCases", + "CoreReader.Engineering.priorityRemainsReflexive", + "CoreReader.Engineering.priorityReflexiveCases", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ] + } + ] + }, + { + "id": "organon.relationships.terms", + "hash": "61cb7ce4f2920f1aa6771502b87a66536ae0504acccfebd9dd23bcc62756eddf", + "status": "partial", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "| Term | Meaning in this philosophy |\n| --- | --- |\n| Existing form | The system’s current organization, methods, and principles, not only its appearance or artifacts. |\n| Assessment | Examination of reasons, applicability, and observed performance; not limited to executable tests. |", + "declarations": [ + "CoreReader.Adopted.generationSpecification", + "CoreReader.Adopted.generationCases" + ] + } + ] + }, + { + "id": "extensions", + "hash": "ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66", + "status": "partial", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "This chapter adds a software engineering commitment and specifies its meaning and limits. It does not claim that this commitment follows from the Charter or Grounds. Those provisions remain adopted and constrain its application.", + "declarations": [ + "CoreReader.Engineering.priorityRemainsReflexive", + "CoreReader.Engineering.priorityReflexiveCases", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ] + } + ] + }, + { + "id": "software-engineering.purpose", + "hash": "946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b", + "status": "partial", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "Software engineering concerns the construction, operation, understanding, and revision of software within its relevant human and technical conditions. This philosophy guides decisions by people and agents; it does not attribute an intrinsic orientation to every software artifact.", + "declarations": [ + "CoreReader.Engineering.ActivityScope", + "CoreReader.Engineering.subjectLifecycleCases", + "CoreReader.Engineering.subjectLimits", + "CoreReader.Engineering.jointWitness" + ] + }, + { + "id": "p2", + "claim": "The evolution capability considered here belongs to the continuing engineering activity: maintainers, including successor maintainers and agents, working with software, tools, and available knowledge. Code that its original author can modify is not on that ground alone shown to support that continuing activity.", + "declarations": [ + "CoreReader.Engineering.ActivityScope", + "CoreReader.Engineering.subjectLifecycleCases", + "CoreReader.Engineering.subjectLimits", + "CoreReader.Engineering.jointWitness" + ] + }, + { + "id": "p3", + "claim": "Apply the following priority according to the software's credible lifecycle and maintenance expectations. A genuinely temporary script, bounded prototype, or retiring system may have little reason to support further evolution. Calling a continuing system temporary does not establish that condition.", + "declarations": [ + "CoreReader.Engineering.ActivityScope", + "CoreReader.Engineering.subjectLifecycleCases", + "CoreReader.Engineering.subjectLimits", + "CoreReader.Engineering.EvolutionPriority", + "CoreReader.Engineering.priorityConditionsCases", + "CoreReader.Engineering.jointWitness" + ] + } + ] + }, + { + "id": "software-engineering.evolution-priority", + "hash": "c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04", + "status": "partial", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "> When relevant behavioral, safety, performance, and other necessary requirements are satisfied, give priority to continuing maintainers' ability to make credible future changes, including changes to the design itself, over present abstraction simplicity. Accept additional present abstraction complexity for that purpose, while allowing this preference to yield when the added costs threaten concrete engineering objectives.", + "declarations": [ + "CoreReader.Engineering.EvolutionPriority", + "CoreReader.Engineering.priorityConditionsCases", + "CoreReader.Engineering.priorityWhenApplicable", + "CoreReader.Engineering.priorityChoices", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ] + }, + { + "id": "p2", + "claim": "Credible directions of change have articulable grounds, such as a committed plan, relevant domain knowledge, or an applicable history of change. They need not already have multiple implementations. Their credibility remains open to revision; a conceivable change alone does not establish that it warrants accommodation now.", + "declarations": [ + "CoreReader.Engineering.EvolutionPriority", + "CoreReader.Engineering.priorityConditionsCases", + "CoreReader.Engineering.priorityWhenApplicable", + "CoreReader.Engineering.priorityChoices", + "CoreReader.Engineering.CredibleDirection", + "CoreReader.Engineering.credibilityCases", + "CoreReader.Engineering.credibilityLimits", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ] + }, + { + "id": "p3", + "claim": "This is a default priority, not an obligation to maximize extensibility or retain every possibility. Costs include relevant burdens of understanding, construction, diagnosis, verification, coordination, operation, and eventual migration. A departure from the priority identifies the objective threatened and why the costs matter. No universal numerical exchange rate between these considerations is prescribed.", + "declarations": [ + "CoreReader.Engineering.EvolutionPriority", + "CoreReader.Engineering.priorityConditionsCases", + "CoreReader.Engineering.priorityWhenApplicable", + "CoreReader.Engineering.priorityChoices", + "CoreReader.Engineering.CredibleDirection", + "CoreReader.Engineering.credibilityCases", + "CoreReader.Engineering.credibilityLimits", + "CoreReader.Engineering.JustifiedDeparture", + "CoreReader.Engineering.costCases", + "CoreReader.Engineering.jointWitness", + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ] + } + ] + }, + { + "id": "software-engineering.evolution-meaning", + "hash": "c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6", + "status": "partial", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "Evolution includes adding capabilities, replacing implementations, deleting mechanisms, withdrawing abstractions, redrawing boundaries, and migrating away from an existing technology or model. Making additions within a fixed scheme does not establish equal ability to revise or leave that scheme. Not every such change can or should be made inexpensive.", + "declarations": [ + "CoreReader.Engineering.EvolutionClaim", + "CoreReader.Engineering.evolutionKindsCases", + "CoreReader.Engineering.evolutionDimensionsLimits", + "CoreReader.Engineering.jointWitness" + ] + }, + { + "id": "p2", + "claim": "An evolution claim identifies the relevant changes and the maintainers' conditions. Independent changes, coordinated changes, preservation of existing obligations, and deliberate revision of those obligations can require different structures. A design's advantage on one dimension does not establish an advantage on every dimension.", + "declarations": [ + "CoreReader.Engineering.EvolutionClaim", + "CoreReader.Engineering.evolutionKindsCases", + "CoreReader.Engineering.evolutionDimensionsLimits", + "CoreReader.Engineering.jointWitness" + ] + } + ] + }, + { + "id": "software-engineering.structural-judgment", + "hash": "8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42", + "status": "partial", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "Apply the preceding commitment to engineering consequences as a whole, including the relations among components, their observable contracts, and the work needed to understand and verify a change. An interface's shape, the number of modules or extension points, or the use of a named principle is not sufficient evidence of the claimed capability.", + "declarations": [ + "CoreReader.Engineering.StructuralAccount", + "CoreReader.Engineering.structuralCases", + "CoreReader.Engineering.structureNotCapability", + "CoreReader.Engineering.priorityRemainsReflexive", + "CoreReader.Engineering.priorityReflexiveCases", + "CoreReader.Engineering.jointWitness" + ] + }, + { + "id": "p2", + "claim": "The relevant comparison may examine how a change propagates, which knowledge and obligations cross a boundary, which assumptions become fixed, and what a later withdrawal would require. A proposed boundary needs support for the changes it is meant to accommodate; introducing it does not by itself show that those changes became easier.", + "declarations": [ + "CoreReader.Engineering.StructuralAccount", + "CoreReader.Engineering.structuralCases", + "CoreReader.Engineering.structureNotCapability", + "CoreReader.Engineering.jointWitness" + ] + }, + { + "id": "p3", + "claim": "Distinguish a transformation that preserves an identified observable contract from one that deliberately revises that contract. The latter needs a corresponding account of changed obligations and affected parties. This distinction does not require preserving every historical behavior or using a particular testing or migration procedure.", + "declarations": [ + "CoreReader.Engineering.ContractChangeAccount", + "CoreReader.Engineering.contractCases", + "CoreReader.Engineering.contractPreservation", + "CoreReader.Engineering.contractDistinctions", + "CoreReader.Engineering.jointWitness" + ] + } + ] + }, + { + "id": "software-engineering.revision", + "hash": "5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99", + "status": "partial", + "reason": "Normative expressions and bounded mathematical claims remain distinct from actual-world adequacy and philosophical adoption.", + "clauses": [ + { + "id": "p1", + "claim": "Changed evidence about likely changes, maintenance conditions, costs, or objectives may justify revising a design or this priority's application. A revised judgment acknowledges material changes in its grounds; it does not make a failed prediction successful retrospectively.", + "declarations": [ + "CoreReader.Engineering.RevisionAccount", + "CoreReader.Engineering.revisionCases", + "CoreReader.Engineering.revisionLimits", + "CoreReader.Engineering.jointWitness" + ] + }, + { + "id": "p2", + "claim": "Retaining a design can be justified when the relevant alternatives have no supported contribution or impose costs that defeat the objective. Reflexivity also keeps this engineering commitment and the methods used to assess evolution within the scope of criticism and revision. Continued change, agreement, or successful examples do not establish its universal correctness.", + "declarations": [ + "CoreReader.Engineering.RevisionAccount", + "CoreReader.Engineering.revisionCases", + "CoreReader.Engineering.revisionLimits", + "CoreReader.Engineering.priorityRemainsReflexive", + "CoreReader.Engineering.priorityReflexiveCases", + "CoreReader.Engineering.jointWitness" + ] + } + ] + } + ], + "declarations": [ + { + "name": "CoreReader.Adopted.generationSpecification", + "kind": "definition", + "sources": [ + { + "unit": "organon.charter.overview", + "clause": "p2" + }, + { + "unit": "organon.charter.overview", + "clause": "p3" + }, + { + "unit": "organon.charter.self-transcendence", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.orientation", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.non-finality", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p2" + }, + { + "unit": "organon.relationships.terms", + "clause": "p1" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.generationCases", + "kind": "case", + "sources": [ + { + "unit": "organon.charter.overview", + "clause": "p2" + }, + { + "unit": "organon.charter.overview", + "clause": "p3" + }, + { + "unit": "organon.charter.self-transcendence", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.orientation", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.non-finality", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p2" + }, + { + "unit": "organon.relationships.terms", + "clause": "p1" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.generationLimits012", + "kind": "case", + "sources": [ + { + "unit": "organon.charter.self-transcendence.orientation", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.non-finality", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.consistencySpecification", + "kind": "definition", + "sources": [ + { + "unit": "organon.charter.consistency", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "p1" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.consistencyCases", + "kind": "case", + "sources": [ + { + "unit": "organon.charter.consistency", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "p1" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.consistencyConsequences", + "kind": "theorem", + "sources": [ + { + "unit": "organon.charter.consistency", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "p1" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.consistencyLimits012", + "kind": "case", + "sources": [ + { + "unit": "organon.charter.consistency.meaning", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.reflexivitySpecification", + "kind": "definition", + "sources": [ + { + "unit": "organon.charter.reflexivity", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.reflexivityCases012", + "kind": "case", + "sources": [ + { + "unit": "organon.charter.reflexivity", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.reflexivityLimits012", + "kind": "case", + "sources": [ + { + "unit": "organon.charter.reflexivity.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + }, + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "organon.grounds", + "clause": "p1" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.Grounds012", + "kind": "definition", + "sources": [ + { + "unit": "organon.grounds", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.groundsCases012", + "kind": "case", + "sources": [ + { + "unit": "organon.grounds", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.empiricalSpecification", + "kind": "definition", + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "p2" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.empiricalCases012", + "kind": "case", + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "p2" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.inferentialSpecification", + "kind": "definition", + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.inferentialCases012", + "kind": "case", + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.valueSpecification", + "kind": "definition", + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.valueCases012", + "kind": "case", + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.groundsLimits012", + "kind": "case", + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.scopeSpecification", + "kind": "definition", + "sources": [ + { + "unit": "organon.grounds.scope", + "clause": "p1" + }, + { + "unit": "organon.grounds.scope", + "clause": "p2" + }, + { + "unit": "organon.grounds.scope", + "clause": "p3" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.scopeCases012", + "kind": "case", + "sources": [ + { + "unit": "organon.grounds.scope", + "clause": "p1" + }, + { + "unit": "organon.grounds.scope", + "clause": "p2" + }, + { + "unit": "organon.grounds.scope", + "clause": "p3" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.scopeLimits012", + "kind": "case", + "sources": [ + { + "unit": "organon.grounds.scope", + "clause": "p1" + }, + { + "unit": "organon.grounds.scope", + "clause": "p2" + }, + { + "unit": "organon.grounds.scope", + "clause": "p3" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "p1" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.capabilitySpecification", + "kind": "definition", + "sources": [ + { + "unit": "organon.grounds.capabilities", + "clause": "p1" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.capabilityCases012", + "kind": "case", + "sources": [ + { + "unit": "organon.grounds.capabilities", + "clause": "p1" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.capabilityLimits012", + "kind": "case", + "sources": [ + { + "unit": "organon.grounds.capabilities", + "clause": "p1" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p2" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.choiceSpecification", + "kind": "definition", + "sources": [ + { + "unit": "organon.grounds.implementations", + "clause": "p1" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p2" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.choiceCases012", + "kind": "case", + "sources": [ + { + "unit": "organon.grounds.implementations", + "clause": "p1" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p2" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Adopted.choiceLimits012", + "kind": "case", + "sources": [ + { + "unit": "organon.grounds.implementations", + "clause": "p1" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p2" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "p1" + } + ], + "file": "CoreReader/Adopted.lean" + }, + { + "name": "CoreReader.Engineering.inheritedMutualApplication", + "kind": "theorem", + "sources": [ + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + } + ], + "file": "CoreReader/Engineering/Integration.lean" + }, + { + "name": "CoreReader.Engineering.inheritedMutualCases", + "kind": "case", + "sources": [ + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + } + ], + "file": "CoreReader/Engineering/Integration.lean" + }, + { + "name": "CoreReader.Engineering.ActivityScope", + "kind": "definition", + "sources": [ + { + "unit": "software-engineering.purpose", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p2" + }, + { + "unit": "software-engineering.purpose", + "clause": "p3" + } + ], + "file": "CoreReader/Engineering/Domain.lean" + }, + { + "name": "CoreReader.Engineering.subjectLifecycleCases", + "kind": "case", + "sources": [ + { + "unit": "software-engineering.purpose", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p2" + }, + { + "unit": "software-engineering.purpose", + "clause": "p3" + } + ], + "file": "CoreReader/Engineering/Domain.lean" + }, + { + "name": "CoreReader.Engineering.subjectLimits", + "kind": "case", + "sources": [ + { + "unit": "software-engineering.purpose", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p2" + }, + { + "unit": "software-engineering.purpose", + "clause": "p3" + } + ], + "file": "CoreReader/Engineering/Domain.lean" + }, + { + "name": "CoreReader.Engineering.EvolutionPriority", + "kind": "definition", + "sources": [ + { + "unit": "software-engineering.purpose", + "clause": "p3" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "file": "CoreReader/Engineering/Domain.lean" + }, + { + "name": "CoreReader.Engineering.priorityConditionsCases", + "kind": "case", + "sources": [ + { + "unit": "software-engineering.purpose", + "clause": "p3" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "file": "CoreReader/Engineering/Domain.lean" + }, + { + "name": "CoreReader.Engineering.priorityWhenApplicable", + "kind": "theorem", + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "file": "CoreReader/Engineering/Domain.lean" + }, + { + "name": "CoreReader.Engineering.priorityChoices", + "kind": "case", + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "file": "CoreReader/Engineering/Domain.lean" + }, + { + "name": "CoreReader.Engineering.CredibleDirection", + "kind": "definition", + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "file": "CoreReader/Engineering/Domain.lean" + }, + { + "name": "CoreReader.Engineering.credibilityCases", + "kind": "case", + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "file": "CoreReader/Engineering/Domain.lean" + }, + { + "name": "CoreReader.Engineering.credibilityLimits", + "kind": "case", + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "file": "CoreReader/Engineering/Domain.lean" + }, + { + "name": "CoreReader.Engineering.JustifiedDeparture", + "kind": "definition", + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "file": "CoreReader/Engineering/Domain.lean" + }, + { + "name": "CoreReader.Engineering.costCases", + "kind": "case", + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "file": "CoreReader/Engineering/Domain.lean" + }, + { + "name": "CoreReader.Engineering.EvolutionClaim", + "kind": "definition", + "sources": [ + { + "unit": "software-engineering.evolution-meaning", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p2" + } + ], + "file": "CoreReader/Engineering/Domain.lean" + }, + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "kind": "case", + "sources": [ + { + "unit": "software-engineering.evolution-meaning", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p2" + } + ], + "file": "CoreReader/Engineering/Domain.lean" + }, + { + "name": "CoreReader.Engineering.evolutionDimensionsLimits", + "kind": "case", + "sources": [ + { + "unit": "software-engineering.evolution-meaning", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p2" + } + ], + "file": "CoreReader/Engineering/Domain.lean" + }, + { + "name": "CoreReader.Engineering.StructuralAccount", + "kind": "definition", + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p2" + } + ], + "file": "CoreReader/Engineering/Domain.lean" + }, + { + "name": "CoreReader.Engineering.structuralCases", + "kind": "case", + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p2" + } + ], + "file": "CoreReader/Engineering/Domain.lean" + }, + { + "name": "CoreReader.Engineering.structureNotCapability", + "kind": "case", + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p2" + } + ], + "file": "CoreReader/Engineering/Domain.lean" + }, + { + "name": "CoreReader.Engineering.ContractChangeAccount", + "kind": "definition", + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "p3" + } + ], + "file": "CoreReader/Engineering/Domain.lean" + }, + { + "name": "CoreReader.Engineering.contractCases", + "kind": "case", + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "p3" + } + ], + "file": "CoreReader/Engineering/Domain.lean" + }, + { + "name": "CoreReader.Engineering.contractPreservation", + "kind": "theorem", + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "p3" + } + ], + "file": "CoreReader/Engineering/Domain.lean" + }, + { + "name": "CoreReader.Engineering.contractDistinctions", + "kind": "case", + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "p3" + } + ], + "file": "CoreReader/Engineering/Domain.lean" + }, + { + "name": "CoreReader.Engineering.RevisionAccount", + "kind": "definition", + "sources": [ + { + "unit": "software-engineering.revision", + "clause": "p2" + }, + { + "unit": "software-engineering.revision", + "clause": "p1" + } + ], + "file": "CoreReader/Engineering/Domain.lean" + }, + { + "name": "CoreReader.Engineering.revisionCases", + "kind": "case", + "sources": [ + { + "unit": "software-engineering.revision", + "clause": "p2" + }, + { + "unit": "software-engineering.revision", + "clause": "p1" + } + ], + "file": "CoreReader/Engineering/Domain.lean" + }, + { + "name": "CoreReader.Engineering.revisionLimits", + "kind": "case", + "sources": [ + { + "unit": "software-engineering.revision", + "clause": "p2" + }, + { + "unit": "software-engineering.revision", + "clause": "p1" + } + ], + "file": "CoreReader/Engineering/Domain.lean" + }, + { + "name": "CoreReader.Engineering.priorityRemainsReflexive", + "kind": "theorem", + "sources": [ + { + "unit": "organon.relationships.roles", + "clause": "p3" + }, + { + "unit": "extensions", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.revision", + "clause": "p2" + } + ], + "file": "CoreReader/Engineering/Integration.lean" + }, + { + "name": "CoreReader.Engineering.priorityReflexiveCases", + "kind": "case", + "sources": [ + { + "unit": "organon.relationships.roles", + "clause": "p3" + }, + { + "unit": "extensions", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.revision", + "clause": "p2" + } + ], + "file": "CoreReader/Engineering/Integration.lean" + }, + { + "name": "CoreReader.Engineering.jointWitness", + "kind": "case", + "sources": [ + { + "unit": "organon.charter.overview", + "clause": "p2" + }, + { + "unit": "organon.charter.overview", + "clause": "p3" + }, + { + "unit": "organon.charter.self-transcendence", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.orientation", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.non-finality", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity.limits", + "clause": "p1" + }, + { + "unit": "organon.grounds", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + }, + { + "unit": "organon.grounds.scope", + "clause": "p1" + }, + { + "unit": "organon.grounds.scope", + "clause": "p2" + }, + { + "unit": "organon.grounds.scope", + "clause": "p3" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p1" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p2" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p1" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p2" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + }, + { + "unit": "extensions", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p2" + }, + { + "unit": "software-engineering.purpose", + "clause": "p3" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p2" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p2" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p3" + }, + { + "unit": "software-engineering.revision", + "clause": "p1" + }, + { + "unit": "software-engineering.revision", + "clause": "p2" + } + ], + "file": "CoreReader/Engineering/Integration.lean" + }, + { + "name": "CoreReader.Engineering.inheritedDoesNotEntailPriority", + "kind": "case", + "sources": [ + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + }, + { + "unit": "extensions", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "file": "CoreReader/Engineering/Integration.lean" + } + ], + "cases": [ + { + "id": "CoreReader-Adopted-generationCases", + "declaration": "CoreReader.Adopted.generationCases", + "kind": "registered_model_case", + "expectation": "Self-transcendence requires valuing expansion of understanding and construction and keeping all existing organization, methods and principles open to being surpassed; justified stable acts remain permitted." + }, + { + "id": "CoreReader-Adopted-generationLimits012", + "declaration": "CoreReader.Adopted.generationLimits012", + "kind": "registered_model_case", + "expectation": "Permission to change does not entail valuing expansion; valuing/open forms do not entail achieved progress, actual capability, independence, autonomous execution or self-improvement; output/term/abstraction counts or self-claims alone do not establish achievement." + }, + { + "id": "CoreReader-Adopted-consistencyCases", + "declaration": "CoreReader.Adopted.consistencyCases", + "kind": "registered_model_case", + "expectation": "All simultaneously held principles/judgments and their joint implications must avoid opposite conclusions on same question, assumptions, term meanings and scope; incompatible same-condition demands need revision/qualification; recorded change cannot be concealed. Given faithful context identity and whole-set consequence, an opposite pair under the same context violates consistency; removing a prior judgment may eliminate the conflict without requiring permanent historical compatibility." + }, + { + "id": "CoreReader-Adopted-consistencyLimits012", + "declaration": "CoreReader.Adopted.consistencyLimits012", + "kind": "registered_model_case", + "expectation": "Different-condition disagreement and value tension alone do not entail contradiction; consistency does not entail true assumptions, adequacy or support for a compatible conclusion." + }, + { + "id": "CoreReader-Adopted-reflexivityCases012", + "declaration": "CoreReader.Adopted.reflexivityCases012", + "kind": "registered_model_case", + "expectation": "Generation and assessment apply to system and principle formation/application/revision under their actual applicability conditions; self-status is no exemption; applicability is not universalized; Grounds grounds/limits and own capability claims are included." + }, + { + "id": "CoreReader-Adopted-reflexivityLimits012", + "declaration": "CoreReader.Adopted.reflexivityLimits012", + "kind": "registered_model_case", + "expectation": "Self-application or self-produced revision does not establish correctness or sufficient grounds; openness of forms does not by itself meet reflexivity. In the declared representation, one nonempty common context satisfies the complete represented Charter requirements but fails the represented general Grounds requirement for a concrete identified claim. This bounded example shows that chapter placement supplies no deductive support; it does not assert independence in every possible representation." + }, + { + "id": "CoreReader-Adopted-groundsCases012", + "declaration": "CoreReader.Adopted.groundsCases012", + "kind": "registered_model_case", + "expectation": "Grounds requires articulable concepts/assumptions/reasons/limits, assessment appropriate to claim nature, and strength/scope proportionate to supplied support. Articulation and assessment are distinct responsibilities." + }, + { + "id": "CoreReader-Adopted-empiricalCases012", + "declaration": "CoreReader.Adopted.empiricalCases012", + "kind": "registered_model_case", + "expectation": "Empirical assessment examines observations, evidence and performance and their support conditions, scope and uncertainty; measurability/repeatability is no replacement for relevance, correctness or value assessment." + }, + { + "id": "CoreReader-Adopted-inferentialCases012", + "declaration": "CoreReader.Adopted.inferentialCases012", + "kind": "registered_model_case", + "expectation": "Inferential assessment examines whether conclusion follows/supports under stated assumptions and inferential relations; mere nonconflict cannot replace this examination." + }, + { + "id": "CoreReader-Adopted-valueCases012", + "declaration": "CoreReader.Adopted.valueCases012", + "kind": "registered_model_case", + "expectation": "Value commitments identify position, reasons, applicability limits and consequences and stay open to relevant criticism; neither empirical/necessary-inference presentation nor self-assertion substitutes. Initial commitments need not prove all starting assumptions." + }, + { + "id": "CoreReader-Adopted-groundsLimits012", + "declaration": "CoreReader.Adopted.groundsLimits012", + "kind": "registered_model_case", + "expectation": "Articulability alone does not establish grounds; measurable/repeatable observations alone establish neither relevance, correctness nor value; a stated value commitment need not be empirical fact or necessary consequence, nor prove all its starting assumptions." + }, + { + "id": "CoreReader-Adopted-scopeCases012", + "declaration": "CoreReader.Adopted.scopeCases012", + "kind": "registered_model_case", + "expectation": "Performance/comparison judgments state relevant relations, conditions and observation scope; scope omission cannot establish absence of relevant differences; roles of measurement, repetition and framework are explained relative to claim/context." + }, + { + "id": "CoreReader-Adopted-scopeLimits012", + "declaration": "CoreReader.Adopted.scopeLimits012", + "kind": "registered_model_case", + "expectation": "Local equal performance does not entail global equivalence/unconditional universality; omitting a difference does not establish its nonexistence. Limited unreproduced support and variable random outcomes are possible without a universal measurement→repeatability→framework chain." + }, + { + "id": "CoreReader-Adopted-capabilityCases012", + "declaration": "CoreReader.Adopted.capabilityCases012", + "kind": "registered_model_case", + "expectation": "Capability claim identifies capability, conditions and support under Grounds; applications choose relevant capability definitions and may require understanding/explanation/variation. External assessors may provide grounds; own-system claims receive same relevant duties." + }, + { + "id": "CoreReader-Adopted-capabilityLimits012", + "declaration": "CoreReader.Adopted.capabilityLimits012", + "kind": "registered_model_case", + "expectation": "Reliable output or artifact/document/tool/term count alone does not establish internal-process understanding or stronger capability; articulable external grounds do not imply that assessed system understands/explains generation." + }, + { + "id": "CoreReader-Adopted-choiceCases012", + "declaration": "CoreReader.Adopted.choiceCases012", + "kind": "registered_model_case", + "expectation": "Implementation priority needs reasons connected to objectives, values and relevant constraints; name/convention/status alone insufficient. Internal method explanation, applicability limits, simplicity/process requirements may count; conventional options may win on relevant grounds, including this philosophy's existing form." + }, + { + "id": "CoreReader-Adopted-choiceLimits012", + "declaration": "CoreReader.Adopted.choiceLimits012", + "kind": "registered_model_case", + "expectation": "Openness neither makes alternatives equivalent nor ensures multiple feasible implementations, excludes conventional choices or excludes internal-method reasons. Local performance equality does not settle whole choice. The added choice priority rule is not inferred from the represented general requirement to assess reasons; this inherited limited assessment relation is distinct from the stronger domain nonentailment in T39." + }, + { + "id": "CoreReader-Engineering-inheritedMutualCases", + "declaration": "CoreReader.Engineering.inheritedMutualCases", + "kind": "registered_model_case", + "expectation": "Under jointly satisfied inherited commitments and actual applicability, own principles/assessment methods/grounds/capability judgments inherit their corresponding generation, consistency and support duties without self-proof or removal of conditions." + }, + { + "id": "CoreReader-Engineering-subjectLifecycleCases", + "declaration": "CoreReader.Engineering.subjectLifecycleCases", + "kind": "registered_model_case", + "expectation": "Domain subject is continuing engineering activity by current/successor human or agent maintainers with software/tools/knowledge across credible lifecycle; priority applicability reflects actual lifecycle/maintenance expectations, not labels or artifact intrinsic orientation." + }, + { + "id": "CoreReader-Engineering-subjectLimits", + "declaration": "CoreReader.Engineering.subjectLimits", + "kind": "registered_model_case", + "expectation": "Original-author editability does not establish continuing-maintainer evolution capability; calling a continuing system temporary does not establish genuinely bounded lifecycle; adopted human/agent orientation does not entail every artifact has it." + }, + { + "id": "CoreReader-Engineering-priorityConditionsCases", + "declaration": "CoreReader.Engineering.priorityConditionsCases", + "kind": "registered_model_case", + "expectation": "When credible lifecycle/maintenance scope and relevant behavioral, safety, performance and other necessary requirements hold, favor continuing-maintainer credible future change capability including design revision over present abstraction simplicity; accept purpose-linked added complexity; allow yielding only when added costs threaten concrete objectives, with objective/cost account." + }, + { + "id": "CoreReader-Engineering-priorityChoices", + "declaration": "CoreReader.Engineering.priorityChoices", + "kind": "registered_model_case", + "expectation": "For a context meeting all priority conditions, with a credible evolution advantage over a simpler feasible option and no concrete cost threat, domain satisfaction requires the evolution-favoring choice/priority and acceptance of its relevant additional complexity." + }, + { + "id": "CoreReader-Engineering-credibilityCases", + "declaration": "CoreReader.Engineering.credibilityCases", + "kind": "registered_model_case", + "expectation": "Credible change direction has articulable grounds (examples are plan/domain knowledge/history, not an exhaustive required list), remains revisable, and needs no existing multiple implementations. Conceivability alone cannot justify present accommodation." + }, + { + "id": "CoreReader-Engineering-credibilityLimits", + "declaration": "CoreReader.Engineering.credibilityLimits", + "kind": "registered_model_case", + "expectation": "Conceivable change alone does not entail warranted accommodation; credible change does not entail multiple existing implementations, maximal extensibility, retention of every possibility or universal numerical exchange rate." + }, + { + "id": "CoreReader-Engineering-costCases", + "declaration": "CoreReader.Engineering.costCases", + "kind": "registered_model_case", + "expectation": "Cost/departure account admits understanding, construction, diagnosis, verification, coordination, operation and eventual migration burdens and identifies threatened objective and causal significance of added cost." + }, + { + "id": "CoreReader-Engineering-evolutionKindsCases", + "declaration": "CoreReader.Engineering.evolutionKindsCases", + "kind": "registered_model_case", + "expectation": "Evolution includes capability addition, implementation replacement, mechanism deletion, abstraction withdrawal, boundary redrawing and technology/model migration; claims identify relevant changes and maintainer conditions; independent/coordinated changes and preserved/revised obligations may require different structures." + }, + { + "id": "CoreReader-Engineering-evolutionDimensionsLimits", + "declaration": "CoreReader.Engineering.evolutionDimensionsLimits", + "kind": "registered_model_case", + "expectation": "Cheap/effective additions within fixed scheme do not entail equal ability to revise/leave it; advantage on one dimension does not entail every dimension; no duty to make every change inexpensive." + }, + { + "id": "CoreReader-Engineering-structuralCases", + "declaration": "CoreReader.Engineering.structuralCases", + "kind": "registered_model_case", + "expectation": "Structural choice applies to whole relevant engineering consequences: component relations, observable contracts, understanding and verification work; boundary capability needs support for intended changes; propagation/cross-boundary knowledge and obligations/fixed assumptions/withdrawal are possible comparison inquiries." + }, + { + "id": "CoreReader-Engineering-structureNotCapability", + "declaration": "CoreReader.Engineering.structureNotCapability", + "kind": "registered_model_case", + "expectation": "Interface shape, module/extension-point count, named principle or boundary introduction alone cannot establish claimed evolution capability or easier intended change." + }, + { + "id": "CoreReader-Engineering-contractCases", + "declaration": "CoreReader.Engineering.contractCases", + "kind": "registered_model_case", + "expectation": "Distinguish preserving an identified observable contract from deliberately revising it; deliberate revision accounts for changed obligations and affected parties; no requirement to preserve every historical behavior or use particular tests/migration procedure." + }, + { + "id": "CoreReader-Engineering-contractDistinctions", + "declaration": "CoreReader.Engineering.contractDistinctions", + "kind": "registered_model_case", + "expectation": "Given equality of all identified contract observations in scope, a transformation preserves that identified contract; deliberate changed in-scope observations cannot be claimed preservation of that same contract and require revised-obligation/party account under domain satisfaction." + }, + { + "id": "CoreReader-Engineering-revisionCases", + "declaration": "CoreReader.Engineering.revisionCases", + "kind": "registered_model_case", + "expectation": "Changed evidence about expected changes, maintenance conditions, costs/objectives can justify revised design/priority application; revised judgment acknowledges material grounds changes and cannot retroactively relabel failed prediction success. Retention may be justified by alternatives lacking contribution or defeating objectives." + }, + { + "id": "CoreReader-Engineering-revisionLimits", + "declaration": "CoreReader.Engineering.revisionLimits", + "kind": "registered_model_case", + "expectation": "Revised judgment cannot make past failed prediction true; continued change, agreement and successful examples do not establish universal correctness; justified retention is compatible with domain/reflexive revision openness." + }, + { + "id": "CoreReader-Engineering-priorityReflexiveCases", + "declaration": "CoreReader.Engineering.priorityReflexiveCases", + "kind": "registered_model_case", + "expectation": "With inherited and domain satisfaction in a shared applicable context, the priority and evolution-assessment methods remain objects of grounds, consistency and reflexive criticism/revision; domain success cannot exempt its rule." + }, + { + "id": "CoreReader-Engineering-jointWitness", + "declaration": "CoreReader.Engineering.jointWitness", + "kind": "registered_model_case", + "expectation": "USER ADDITIONAL STRONG OBJECTIVE: one content-bearing nonempty system/context jointly satisfies every represented inherited and domain commitment, with a continuing lifecycle, actual applicable priority and evolution chosen despite additional present abstraction complexity." + }, + { + "id": "CoreReader-Engineering-inheritedDoesNotEntailPriority", + "declaration": "CoreReader.Engineering.inheritedDoesNotEntailPriority", + "kind": "registered_model_case", + "expectation": "USER ADDITIONAL STRONG OBJECTIVE: a countermodel satisfies all represented inherited commitments while genuine domain-priority applicability holds and domain evolution priority is not adopted; proves non-entailment in the disclosed representation." + } + ] +} diff --git a/SoftwareEngineering/lean/philosophy/snapshots/PHILOSOPHY.md b/SoftwareEngineering/lean/philosophy/snapshots/PHILOSOPHY.md new file mode 100644 index 0000000..dc76a0f --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/snapshots/PHILOSOPHY.md @@ -0,0 +1,202 @@ +--- +format_version: 0.1.0 +philosophy_version: 0.2.1 +core_version: 0.1.2 +derived_from: + source_id: "https://github.com/shendeguize/OrganonCore" + philosophy_version: "0.1.2" + content_hash: "cb23f8a44d6b877ff9b5385961ff8e5fa788f8021ae267cdc8e305870ec20ca7" +--- +# Software Engineering Organon: Charter and Grounds + + +This is a statement of Software Engineering Organon’s adopted philosophy. It expresses commitments, not factual assertions about every system or a proof of universal correctness. + +The quoted provisions, their meanings, and their conditions of application form the core. The charter and Grounds constrain one another; their grouping establishes neither a deductive hierarchy nor an order of priority. [Rationale](rationale/README.md) supplies arguments and cases without adding obligations to this core. Skills are revisable applications under the repository’s stated objectives and constraints, not part of the philosophical commitments themselves. + +## 1. Charter + + +### 1.1 Overview + + +**Self-Transcendence · Internal Consistency · Reflexivity** + +> A system is intrinsically oriented toward expanding what it can understand and construct. It brings itself and its principles within the scope of generation and assessment, with internal consistency constraining this process. + +The overview connects three distinct requirements: self-transcendence establishes a generative orientation and refuses to treat existing forms as final, internal consistency constrains judgments held simultaneously, and reflexivity brings the system and its principles within the scope of their own generation and assessment. The provisions below specify the conditions for each. + +### 1.2 Self-Transcendence + + +> A system is intrinsically oriented toward expanding what it can understand and construct. It does not regard any existing form as the endpoint of generation. + +#### 1.2.1 Generative Orientation + + +A commitment to keeping generative possibilities open is distinct from valuing their expansion. A system has an intrinsic orientation when it regards that expansion as worth pursuing. Merely permitting change does not fully express this orientation. + +#### 1.2.2 Non-finality + + +Refusing to regard an existing form as an endpoint keeps it open to being surpassed. “Existing form” includes a system’s current organization, methods, and principles, not only its appearance or artifacts. These remain within the scope of possible change; their revisability does not guarantee actual progress. + +#### 1.2.3 Grounds for Achievement and Limits + + +Whether progress has actually occurred remains a separate judgment. Having the orientation does not guarantee progress. Progress cannot be established merely by an increase in the number of artifacts, levels of abstraction, or terms. + +- “Intrinsic orientation” expresses Organon’s philosophical commitment; it does not assert that all systems in fact develop autonomously. +- Self-transcendence does not imply independence from external experience, knowledge, or collaboration, nor does it guarantee autonomous execution or self-improvement. +- Refusing to regard an existing form as an endpoint does not require every action to produce change. Justified stability can coexist with a generative orientation. +- Whether transcendence expands what can be understood and constructed requires discernible grounds; a system’s own claim of generation does not establish actual achievement. + +### 1.3 Internal Consistency + + +> The principles and judgments a system holds simultaneously, together with their implications, must not yield contradictory judgments on the same question under the same assumptions, meanings of terms, and scope of application. + +#### 1.3.1 Meaning + + +“Held simultaneously” specifies which principles, judgments, and implications must hold together. Revision may withdraw an earlier judgment; old and new principles need not remain compatible forever. When a change has occurred, that change cannot be represented as though it had not occurred. + +“The same assumptions, meanings of terms, and scope of application” specifies the basis for comparing judgments. Divergent judgments under different conditions do not automatically constitute contradictions. Nor can unacknowledged changes in assumptions, meanings, or scope be used to conceal an existing contradiction. + +#### 1.3.2 Conditions and Limits + + +- Tension between different assessments or values does not directly constitute a contradiction. Revision or qualification is needed when they require incompatible conclusions under the same conditions. +- Internal consistency is not correctness or sufficiency. A set of principles may be internally consistent while relying on false assumptions or neglecting important questions. + +### 1.4 Reflexivity + + +> A system’s principles of generation and assessment also apply to the system itself and to the formation, application, and revision of those principles. + +#### 1.4.1 Meaning + + +Reflexivity encompasses both the system itself and its principles. Assessment concerns not only whether the system conforms to its principles, but also how those principles are formed, where they apply, and why they may need revision. The formation and revision of principles thus also become objects of generation and assessment. + +#### 1.4.2 Conditions and Limits + + +- Applying principles equally retains their conditions of application. When the relevant conditions hold, being the system itself is not a basis for exemption. Nor does the requirement of reflexivity establish that every principle can be applied to itself without examining its applicability. +- Self-application does not constitute self-proof. Subjecting a principle to its own assessment does not thereby establish its correctness. +- That a revision is produced by the system itself does not give it sufficient grounds. + +## 2. Grounds + + +> The grounds of principles and judgments must be articulable and subject to assessment appropriate to the nature of the claim. The strength and scope of a claim must be proportionate to the support provided by its grounds. + +### 2.1 Articulation and Responsibilities of Assessment + + +Articulation and assessment have distinct responsibilities. Articulability requires that concepts, assumptions, reasons, and limits can be identified. Assessment requires examining whether those grounds support the corresponding claim. Clearly expressed grounds are not thereby sufficiently established. + +| Type of claim | Responsibility of assessment | What cannot substitute for that responsibility | +| --- | --- | --- | +| Empirical claim | Examine observations, evidence, and performance, together with the conditions, scope, and uncertainty of their support for the claim. | Treating measurability or repeatability itself as proof of relevance, correctness, or value. | +| Inferential claim | Examine whether the conclusion is supported by the stated assumptions and inferential relations. | Treating the absence of conflict between a conclusion and its assumptions as sufficient to establish that the conclusion follows from them. | +| Value commitment | State the position taken, its reasons, limits of application, and consequences, and remain open to relevant criticism. | Presenting a commitment as an empirical fact or a necessary inference, or substituting self-assertion for reasons. | + +Initial value commitments may be stated explicitly as commitments; they need not prove all their own starting assumptions. The strength and scope of a claim do not require conversion to a common numerical scale. Different types of claims specify their support and limits in accordance with their nature. + +### 2.2 Relations, Scope, and the Limits of Measurement + + +Performance is discerned within particular relations, conditions, and scopes of observation. A boundary helps specify what a comparison concerns, but local examples do not automatically support unconditional universal conclusions. A judgment cannot establish that relevant differences do not exist merely because its chosen scope omits them. + +Measurement can make some differences comparable. Repeated assessment can help examine the stability of corresponding conclusions. Their roles, and the role of any assessment framework, must be explained relative to the claim and its context. Measurement, repeatability, and an assessment framework do not form a universally necessary chain on which all judgments must depend. + +An observation that has not been reproduced may still offer limited support, and random outcomes need not be identical on every occasion. The verifiability of observations, reproducibility of conditions, and stability of conclusions must be distinguished. + +### 2.3 Capability Claims + + +Capability claims are subject to Grounds: the capability claimed, its conditions, and the support for it must be identifiable. The core does not prescribe uniform definitions of method mastery, method generation, or capability levels. Applications specify the capabilities they assess and may require understanding, explanation, or performance under relevant variations. + +Grounds for a capability claim may be supplied by an external assessor. Their articulability does not by itself require the assessed system to understand or explain its internal generation process. Evidence of reliable output must be assessed against the capability actually claimed; it does not automatically establish understanding of that process. Nor can the number of method documents, terms, tools, or artifacts alone establish a capability beyond what that evidence supports. + +### 2.4 Implementation Choices: Openness to Alternatives + + +> The choice of an implementation must be supported by reasons connected to the objectives and values pursued and to the relevant constraints. Its name, conventional use, or established status alone does not provide sufficient grounds for giving it priority. + +This choice provision adds an additional evaluative commitment: name, conventional use, or established status alone is insufficient to establish priority. Grouping it under Grounds does not mean that it follows from the general requirement to assess reasons, or merely from the discernibility of performance. Conventions and existing arrangements may have practical significance, but that significance must be connected to the objectives and values pursued and to the relevant constraints. + +#### 2.4.1 Conditions and Limits + + +- Openness does not make all implementations equivalent, nor does it guarantee multiple feasible implementations for the same objective. +- A method’s explanatory power, limits of application, simplicity, and explicit process requirements may all provide grounded reasons for assessment. They cannot be excluded merely because they concern methods internal to the implementation. +- Identical local performance does not establish overall equivalence. Relations, conditions, and the scope of comparison are constrained by the provisions of Grounds. +- Openness does not reject an implementation merely because it already exists or is conventionally used. Relevant reasons may still give it priority. + +## 3. Relationships and Necessary Terms + + +### 3.1 Roles and Mutual Constraints + + +The charter states the generative orientation, the consistency constraint, and reflexive application. Grounds specifies support requirements for judgments and includes an additional commitment concerning implementation choices. Both parts belong to the core and constrain one another. Their placement neither makes Grounds a deduction from the charter nor gives the charter priority over it. Each commitment needs its own reasons. + +Internal Consistency concerns whether simultaneously held judgments can hold together; Grounds concerns whether and how far a claim is supported. A conclusion may fail to conflict with its assumptions without being supported by them. Self-Transcendence specifies a generative orientation and non-finality; neither establishes actual capability. Applications may supply objectives, values, and capability definitions; claims made under those objectives, values, and definitions remain subject to the relevant core provisions. + +Self-Transcendence does not substitute for Reflexivity: keeping existing forms open to being surpassed differs from applying relevant principles to the system and to their own formation, application, and revision. Reflexivity extends these requirements to the system and to the formation, application, and revision of its principles. The grounds and limits of the Grounds provisions must themselves be articulable. The system’s own capability claims remain subject to assessment, and this philosophy’s existing form cannot gain priority merely from its established status. Such mutual application provides no self-proof and does not remove conditions of application. + +### 3.2 Necessary Terms + + +| Term | Meaning in this philosophy | +| --- | --- | +| Existing form | The system’s current organization, methods, and principles, not only its appearance or artifacts. | +| Assessment | Examination of reasons, applicability, and observed performance; not limited to executable tests. | + +## 4. Software Engineering + + +This chapter adds a software engineering commitment and specifies its meaning and limits. It does not claim that this commitment follows from the Charter or Grounds. Those provisions remain adopted and constrain its application. + +### 4.1 Purpose, Subjects, and Lifecycle + + +Software engineering concerns the construction, operation, understanding, and revision of software within its relevant human and technical conditions. This philosophy guides decisions by people and agents; it does not attribute an intrinsic orientation to every software artifact. + +The evolution capability considered here belongs to the continuing engineering activity: maintainers, including successor maintainers and agents, working with software, tools, and available knowledge. Code that its original author can modify is not on that ground alone shown to support that continuing activity. + +Apply the following priority according to the software's credible lifecycle and maintenance expectations. A genuinely temporary script, bounded prototype, or retiring system may have little reason to support further evolution. Calling a continuing system temporary does not establish that condition. + +### 4.2 Priority for Credible Evolution + + +> When relevant behavioral, safety, performance, and other necessary requirements are satisfied, give priority to continuing maintainers' ability to make credible future changes, including changes to the design itself, over present abstraction simplicity. Accept additional present abstraction complexity for that purpose, while allowing this preference to yield when the added costs threaten concrete engineering objectives. + +Credible directions of change have articulable grounds, such as a committed plan, relevant domain knowledge, or an applicable history of change. They need not already have multiple implementations. Their credibility remains open to revision; a conceivable change alone does not establish that it warrants accommodation now. + +This is a default priority, not an obligation to maximize extensibility or retain every possibility. Costs include relevant burdens of understanding, construction, diagnosis, verification, coordination, operation, and eventual migration. A departure from the priority identifies the objective threatened and why the costs matter. No universal numerical exchange rate between these considerations is prescribed. + +### 4.3 Meaning of Evolution + + +Evolution includes adding capabilities, replacing implementations, deleting mechanisms, withdrawing abstractions, redrawing boundaries, and migrating away from an existing technology or model. Making additions within a fixed scheme does not establish equal ability to revise or leave that scheme. Not every such change can or should be made inexpensive. + +An evolution claim identifies the relevant changes and the maintainers' conditions. Independent changes, coordinated changes, preservation of existing obligations, and deliberate revision of those obligations can require different structures. A design's advantage on one dimension does not establish an advantage on every dimension. + +### 4.4 Structural Judgments and Their Support + + +Apply the preceding commitment to engineering consequences as a whole, including the relations among components, their observable contracts, and the work needed to understand and verify a change. An interface's shape, the number of modules or extension points, or the use of a named principle is not sufficient evidence of the claimed capability. + +The relevant comparison may examine how a change propagates, which knowledge and obligations cross a boundary, which assumptions become fixed, and what a later withdrawal would require. A proposed boundary needs support for the changes it is meant to accommodate; introducing it does not by itself show that those changes became easier. + +Distinguish a transformation that preserves an identified observable contract from one that deliberately revises that contract. The latter needs a corresponding account of changed obligations and affected parties. This distinction does not require preserving every historical behavior or using a particular testing or migration procedure. + +### 4.5 Revision and Justified Stability + + +Changed evidence about likely changes, maintenance conditions, costs, or objectives may justify revising a design or this priority's application. A revised judgment acknowledges material changes in its grounds; it does not make a failed prediction successful retrospectively. + +Retaining a design can be justified when the relevant alternatives have no supported contribution or impose costs that defeat the objective. Reflexivity also keeps this engineering commitment and the methods used to assess evolution within the scope of criticism and revision. Continued change, agreement, or successful examples do not establish its universal correctness. diff --git a/SoftwareEngineering/lean/philosophy/targets.json b/SoftwareEngineering/lean/philosophy/targets.json new file mode 100644 index 0000000..4d38813 --- /dev/null +++ b/SoftwareEngineering/lean/philosophy/targets.json @@ -0,0 +1,1991 @@ +{ + "schema_version": 1, + "source_sha256": "adc8cce5ac55a5e3795f8806748603eb69d5695fa37bbe263bee20ac6c14a1a6", + "targets": [ + { + "id": "T01", + "kind": "boundary", + "sources": [ + { + "unit": "organon.preamble", + "clause": "p1" + }, + { + "unit": "organon.preamble", + "clause": "p2" + }, + { + "unit": "organon.charter.overview", + "clause": "p1" + }, + { + "unit": "organon.charter.overview", + "clause": "p2" + }, + { + "unit": "organon.charter.overview", + "clause": "p3" + }, + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "extensions", + "clause": "p1" + } + ], + "statement": "Authority and roles: adopted commitments, no universal factual assertion or correctness proof; meanings and limits constrain quotation; charter and Grounds mutually constrain without hierarchy; rationale/skills add no philosophical duties; domain preference is additional.", + "premises": [ + "Distinguish document role from deductive claims. No assumed metatheorem about all possible formalizations." + ], + "acceptance": "Trace every role sentence; do not turn absence of asserted deduction into a claimed impossibility theorem without a separately justified model. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [], + "required_cases": [], + "semantic_cases": [] + }, + { + "id": "T02", + "kind": "specification", + "sources": [ + { + "unit": "organon.charter.overview", + "clause": "p2" + }, + { + "unit": "organon.charter.overview", + "clause": "p3" + }, + { + "unit": "organon.charter.self-transcendence", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.orientation", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.non-finality", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p2" + }, + { + "unit": "organon.relationships.terms", + "clause": "p1" + } + ], + "statement": "Self-transcendence requires valuing expansion of understanding and construction and keeping all existing organization, methods and principles open to being surpassed; justified stable acts remain permitted.", + "premises": [ + "System/activity subject", + "current forms quantified without omitting principles", + "orientation is normative commitment, not empirical universality." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Adopted.generationSpecification", + "kind": "definition" + }, + { + "name": "CoreReader.Adopted.generationCases", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Adopted.generationCases" + ], + "semantic_cases": [ + "positive_valued_open_forms", + "negative_permission_only", + "positive_stability", + "external_collaboration" + ] + }, + { + "id": "T03", + "kind": "nonentailment", + "sources": [ + { + "unit": "organon.charter.self-transcendence.orientation", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.non-finality", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + } + ], + "statement": "Permission to change does not entail valuing expansion; valuing/open forms do not entail achieved progress, actual capability, independence, autonomous execution or self-improvement; output/term/abstraction counts or self-claims alone do not establish achievement.", + "premises": [ + "Keep valuing, revisability, progress, support and autonomous properties distinct", + "ground actual achievement in a declared criterion independent of mere count/claim." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Adopted.generationLimits012", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Adopted.generationLimits012" + ], + "semantic_cases": [ + "permission_without_value", + "orientation_without_progress", + "count_growth_without_capability", + "collaborative_nonautonomous_progress", + "claim_without_achievement", + "achievement_support_for_same_claim" + ] + }, + { + "id": "T04", + "kind": "specification", + "sources": [ + { + "unit": "organon.charter.consistency", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "p1" + } + ], + "statement": "All simultaneously held principles/judgments and their joint implications must avoid opposite conclusions on same question, assumptions, term meanings and scope; incompatible same-condition demands need revision/qualification; recorded change cannot be concealed.", + "premises": [ + "Consequence over whole held set", + "explicit context equality", + "no per-principle-only substitute", + "distinguish held-at-time from historical union", + "change-report condition separate from consistency." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Adopted.consistencySpecification", + "kind": "definition" + }, + { + "name": "CoreReader.Adopted.consistencyCases", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Adopted.consistencyCases" + ], + "semantic_cases": [ + "joint_only_contradiction", + "changed_scope_not_concealed", + "revision_withdraws_old", + "incompatible_same_context" + ] + }, + { + "id": "T05", + "kind": "theorem", + "sources": [ + { + "unit": "organon.charter.consistency", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "p1" + } + ], + "statement": "Given faithful context identity and whole-set consequence, an opposite pair under the same context violates consistency; removing a prior judgment may eliminate the conflict without requiring permanent historical compatibility.", + "premises": [ + "A consequence relation, positive/negative conclusions for same question, active-set membership, context equality", + "explicit withdrawal semantics", + "no explosion assumption needed." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Adopted.consistencyConsequences", + "kind": "theorem" + }, + { + "name": "CoreReader.Adopted.consistencyCases", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Adopted.consistencyCases" + ], + "semantic_cases": [ + "pair_conflict", + "joint_premise_conflict", + "old_new_separate_times", + "distinct_context_judgments", + "truthful_semantic_change_and_reordering" + ] + }, + { + "id": "T06", + "kind": "nonentailment", + "sources": [ + { + "unit": "organon.charter.consistency.meaning", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + } + ], + "statement": "Different-condition disagreement and value tension alone do not entail contradiction; consistency does not entail true assumptions, adequacy or support for a compatible conclusion.", + "premises": [ + "Concrete shared interpretation of truth/support and consequence", + "relevant omitted question represented", + "unsupported conclusion must demonstrably fail entailment, not merely have a false support flag." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Adopted.consistencyLimits012", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Adopted.consistencyLimits012" + ], + "semantic_cases": [ + "different_contexts", + "tension_compatible", + "consistent_false_assumption", + "consistent_omitted_question", + "compatible_not_entailed" + ] + }, + { + "id": "T07", + "kind": "specification", + "sources": [ + { + "unit": "organon.charter.reflexivity", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + } + ], + "statement": "Generation and assessment apply to system and principle formation/application/revision under their actual applicability conditions; self-status is no exemption; applicability is not universalized; Grounds grounds/limits and own capability claims are included.", + "premises": [ + "Explicit target kinds for system, formation, application, revision", + "principle applicability and duties", + "nonempty applicable self-target and inapplicable pair", + "no endless-recursion requirement." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Adopted.reflexivitySpecification", + "kind": "definition" + }, + { + "name": "CoreReader.Adopted.reflexivityCases012", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Adopted.reflexivityCases012" + ], + "semantic_cases": [ + "self_applicable", + "self_inapplicable", + "principle_formation", + "principle_application", + "principle_revision", + "grounds_on_grounds" + ] + }, + { + "id": "T08", + "kind": "nonentailment", + "sources": [ + { + "unit": "organon.charter.reflexivity.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + }, + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "organon.grounds", + "clause": "p1" + } + ], + "statement": "Self-application or self-produced revision does not establish correctness or sufficient grounds; openness of forms does not by itself meet reflexivity. In the declared representation, one nonempty common context satisfies the complete represented Charter requirements but fails the represented general Grounds requirement for a concrete identified claim. This bounded example shows that chapter placement supplies no deductive support; it does not assert independence in every possible representation.", + "premises": [ + "Assessment events/duties not truth", + "generation provenance not support", + "concrete countercase with a revisable but self-exempt assessment rule.", + "Complete represented Charter includes the specifications in T02, T04 and T07 with their applicability conditions.", + "General Grounds includes the T09 articulation, corresponding assessment and proportionality requirements. Failure must concern a concrete identified claim, grounds, scope and strength, with a substantive failed support relation, not an empty domain, missing record or freely assigned false label. Grounds is not assumed." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Adopted.reflexivityLimits012", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Adopted.reflexivityLimits012" + ], + "semantic_cases": [ + "self_assessed_incorrect", + "self_generated_unsupported", + "open_but_self_exempt", + "charter_not_general_grounds" + ] + }, + { + "id": "T09", + "kind": "specification", + "sources": [ + { + "unit": "organon.grounds", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + } + ], + "statement": "Grounds requires articulable concepts/assumptions/reasons/limits, assessment appropriate to claim nature, and strength/scope proportionate to supplied support. Articulation and assessment are distinct responsibilities.", + "premises": [ + "Grounds tied to corresponding claim and context", + "explicit support relation, force and scope", + "no universal numeric scale or complete mutually exclusive taxonomy", + "Core 0.1.2 only." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Adopted.Grounds012", + "kind": "definition" + }, + { + "name": "CoreReader.Adopted.groundsCases012", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Adopted.groundsCases012" + ], + "semantic_cases": [ + "articulable_supported", + "articulable_unsupported", + "scope_overreach", + "strength_overreach" + ] + }, + { + "id": "T10", + "kind": "specification", + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "p2" + } + ], + "statement": "Empirical assessment examines observations, evidence and performance and their support conditions, scope and uncertainty; measurability/repeatability is no replacement for relevance, correctness or value assessment.", + "premises": [ + "Actual empirical content and relevant relation from observations to claim", + "measurement/repetition is evidence property, not automatic support", + "finite adapter remains limited." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Adopted.empiricalSpecification", + "kind": "definition" + }, + { + "name": "CoreReader.Adopted.empiricalCases012", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Adopted.empiricalCases012" + ], + "semantic_cases": [ + "observed_relevant", + "repeatable_irrelevant", + "measured_wrong_scope", + "uncertain_limited" + ] + }, + { + "id": "T11", + "kind": "specification", + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + } + ], + "statement": "Inferential assessment examines whether conclusion follows/supports under stated assumptions and inferential relations; mere nonconflict cannot replace this examination.", + "premises": [ + "A concrete inference semantics and countervaluation when lack of entailment is claimed", + "distinguish task of examination from successful conclusion." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Adopted.inferentialSpecification", + "kind": "definition" + }, + { + "name": "CoreReader.Adopted.inferentialCases012", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Adopted.inferentialCases012" + ], + "semantic_cases": [ + "valid_inference", + "compatible_unentailed", + "false_inference_detected" + ] + }, + { + "id": "T12", + "kind": "specification", + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + } + ], + "statement": "Value commitments identify position, reasons, applicability limits and consequences and stay open to relevant criticism; neither empirical/necessary-inference presentation nor self-assertion substitutes. Initial commitments need not prove all starting assumptions.", + "premises": [ + "Stated value stance distinct from factual claims", + "reason interface without recursive proof demand", + "relevant criticism condition", + "qualitative support comparisons allowed." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Adopted.valueSpecification", + "kind": "definition" + }, + { + "name": "CoreReader.Adopted.valueCases012", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Adopted.valueCases012" + ], + "semantic_cases": [ + "reasoned_value", + "unsupported_self_assertion", + "closed_criticism", + "explicit_initial_commitment" + ] + }, + { + "id": "T13", + "kind": "nonentailment", + "sources": [ + { + "unit": "organon.grounds.assessment", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + } + ], + "statement": "Articulability alone does not establish grounds; measurable/repeatable observations alone establish neither relevance, correctness nor value; a stated value commitment need not be empirical fact or necessary consequence, nor prove all its starting assumptions.", + "premises": [ + "Concrete inadequacy criterion for each countercase", + "avoid defining insufficient support as missing record only", + "empirical/inferential/value readings not made exhaustive or exclusive." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Adopted.groundsLimits012", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Adopted.groundsLimits012" + ], + "semantic_cases": [ + "clear_false_reason", + "repeatable_wrong_object", + "value_not_fact", + "initial_value_without_selfproof", + "qualitative_proportionality" + ] + }, + { + "id": "T14", + "kind": "specification", + "sources": [ + { + "unit": "organon.grounds.scope", + "clause": "p1" + }, + { + "unit": "organon.grounds.scope", + "clause": "p2" + }, + { + "unit": "organon.grounds.scope", + "clause": "p3" + } + ], + "statement": "Performance/comparison judgments state relevant relations, conditions and observation scope; scope omission cannot establish absence of relevant differences; roles of measurement, repetition and framework are explained relative to claim/context.", + "premises": [ + "Local and broader scopes and relevance relation distinct", + "explanation of actually used method does not require all three methods universally." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Adopted.scopeSpecification", + "kind": "definition" + }, + { + "name": "CoreReader.Adopted.scopeCases012", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Adopted.scopeCases012" + ], + "semantic_cases": [ + "local_scope_declared", + "omitted_relevant_difference", + "measurement_role", + "repetition_role", + "framework_role" + ] + }, + { + "id": "T15", + "kind": "nonentailment", + "sources": [ + { + "unit": "organon.grounds.scope", + "clause": "p1" + }, + { + "unit": "organon.grounds.scope", + "clause": "p2" + }, + { + "unit": "organon.grounds.scope", + "clause": "p3" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "p1" + } + ], + "statement": "Local equal performance does not entail global equivalence/unconditional universality; omitting a difference does not establish its nonexistence. Limited unreproduced support and variable random outcomes are possible without a universal measurement→repeatability→framework chain.", + "premises": [ + "Explicit nonempty local and broader domains, shared observations and relation", + "verifiability, reproducible conditions and stable conclusions modeled separately", + "unreproduced is not necessarily irreproducible." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Adopted.scopeLimits012", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Adopted.scopeLimits012" + ], + "semantic_cases": [ + "equal_local_different_global", + "excluded_difference", + "one_observation_limited_support", + "varying_random_outcomes", + "qualitative_unmeasured_judgment" + ] + }, + { + "id": "T16", + "kind": "specification", + "sources": [ + { + "unit": "organon.grounds.capabilities", + "clause": "p1" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + } + ], + "statement": "Capability claim identifies capability, conditions and support under Grounds; applications choose relevant capability definitions and may require understanding/explanation/variation. External assessors may provide grounds; own-system claims receive same relevant duties.", + "premises": [ + "Claim-indexed capability, externally supplied support and actual scope", + "no universal capability levels or introspective requirement." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Adopted.capabilitySpecification", + "kind": "definition" + }, + { + "name": "CoreReader.Adopted.capabilityCases012", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Adopted.capabilityCases012" + ], + "semantic_cases": [ + "external_output_capability", + "application_requires_understanding", + "own_capability_assessment" + ] + }, + { + "id": "T17", + "kind": "nonentailment", + "sources": [ + { + "unit": "organon.grounds.capabilities", + "clause": "p1" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p2" + } + ], + "statement": "Reliable output or artifact/document/tool/term count alone does not establish internal-process understanding or stronger capability; articulable external grounds do not imply that assessed system understands/explains generation.", + "premises": [ + "Concrete task success and independent understanding criterion", + "external reasons not silently attributed to internal subject", + "scope escalation displayed." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Adopted.capabilityLimits012", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Adopted.capabilityLimits012" + ], + "semantic_cases": [ + "reliable_opaque_generator", + "high_count_no_stronger_capability", + "externally_articulated_no_introspection" + ] + }, + { + "id": "T18", + "kind": "specification", + "sources": [ + { + "unit": "organon.grounds.implementations", + "clause": "p1" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p2" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + } + ], + "statement": "Implementation priority needs reasons connected to objectives, values and relevant constraints; name/convention/status alone insufficient. Internal method explanation, applicability limits, simplicity/process requirements may count; conventional options may win on relevant grounds, including this philosophy's existing form.", + "premises": [ + "Reason relevance to particular choice", + "provenance alone distinct from practical familiarity/support", + "no rule that internal reasons are always decisive." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Adopted.choiceSpecification", + "kind": "definition" + }, + { + "name": "CoreReader.Adopted.choiceCases012", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Adopted.choiceCases012" + ], + "semantic_cases": [ + "named_only_rejected", + "conventional_grounded_priority", + "method_internal_reason", + "own_philosophy_status_only" + ] + }, + { + "id": "T19", + "kind": "nonentailment", + "sources": [ + { + "unit": "organon.grounds.implementations", + "clause": "p1" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p2" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "p1" + } + ], + "statement": "Openness neither makes alternatives equivalent nor ensures multiple feasible implementations, excludes conventional choices or excludes internal-method reasons. Local performance equality does not settle whole choice. The added choice priority rule is not inferred from the represented general requirement to assess reasons; this inherited limited assessment relation is distinct from the stronger domain nonentailment in T39.", + "premises": [ + "Concrete feasible option set and grounded comparison", + "at least one positive witness with a single feasible conventional option", + "distinct global consequences." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Adopted.choiceLimits012", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Adopted.choiceLimits012" + ], + "semantic_cases": [ + "single_feasible_conventional", + "internal_reason_distinguishes", + "unequal_open_options", + "local_equal_global_difference", + "added_choice_not_from_general_assessment" + ] + }, + { + "id": "T20", + "kind": "theorem", + "sources": [ + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + } + ], + "statement": "Under jointly satisfied inherited commitments and actual applicability, own principles/assessment methods/grounds/capability judgments inherit their corresponding generation, consistency and support duties without self-proof or removal of conditions.", + "premises": [ + "Same subject/context, shared principle/object identifiers, applicability", + "reflexivity interface connected to concrete Grounds/choice/capability obligations", + "no isolated conjunction of unrelated models." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Engineering.inheritedMutualApplication", + "kind": "theorem" + }, + { + "name": "CoreReader.Engineering.inheritedMutualCases", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Engineering.inheritedMutualCases" + ], + "semantic_cases": [ + "own_grounds_articulable", + "own_capability_supported", + "own_choice_not_status_only", + "relevant_self_application" + ] + }, + { + "id": "T21", + "kind": "boundary", + "sources": [ + { + "unit": "organon.relationships.terms", + "clause": "p1" + } + ], + "statement": "Existing form includes organization/methods/principles. Assessment is examination of reasons, applicability and observed performance and is not limited to executable testing.", + "premises": [ + "Definitions constrain every related model, including review subjects", + "no claim every assessment executes every listed operation when inapplicable." + ], + "acceptance": "Review formal object taxonomy and assessment relation for excluded source meanings; record any finite-enumeration limits. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [], + "required_cases": [], + "semantic_cases": [] + }, + { + "id": "T22", + "kind": "specification", + "sources": [ + { + "unit": "software-engineering.purpose", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p2" + }, + { + "unit": "software-engineering.purpose", + "clause": "p3" + } + ], + "statement": "Domain subject is continuing engineering activity by current/successor human or agent maintainers with software/tools/knowledge across credible lifecycle; priority applicability reflects actual lifecycle/maintenance expectations, not labels or artifact intrinsic orientation.", + "premises": [ + "Subject/maintainer roles, credible lifecycle grounds, activity versus artifact", + "temporary/prototype/retiring contexts considered conditionally, not blanket exemption by name." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Engineering.ActivityScope", + "kind": "definition" + }, + { + "name": "CoreReader.Engineering.subjectLifecycleCases", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Engineering.subjectLifecycleCases" + ], + "semantic_cases": [ + "successor_maintainer", + "agent_maintainer", + "continuing_labeled_temporary", + "genuinely_temporary", + "bounded_prototype", + "retiring_system" + ] + }, + { + "id": "T23", + "kind": "nonentailment", + "sources": [ + { + "unit": "software-engineering.purpose", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p2" + }, + { + "unit": "software-engineering.purpose", + "clause": "p3" + } + ], + "statement": "Original-author editability does not establish continuing-maintainer evolution capability; calling a continuing system temporary does not establish genuinely bounded lifecycle; adopted human/agent orientation does not entail every artifact has it.", + "premises": [ + "Concrete edit/understand/verify paths scoped by maintainer knowledge", + "lifecycle evidence distinct from label", + "actual continuing example." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Engineering.subjectLimits", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Engineering.subjectLimits" + ], + "semantic_cases": [ + "author_only_private_knowledge", + "successor_missing_path", + "false_temporary_label", + "passive_artifact" + ] + }, + { + "id": "T24", + "kind": "specification", + "sources": [ + { + "unit": "software-engineering.purpose", + "clause": "p3" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "statement": "When credible lifecycle/maintenance scope and relevant behavioral, safety, performance and other necessary requirements hold, favor continuing-maintainer credible future change capability including design revision over present abstraction simplicity; accept purpose-linked added complexity; allow yielding only when added costs threaten concrete objectives, with objective/cost account.", + "premises": [ + "Explicit options, same engineering context, feasible requirements, supported credible change set, comparative evolution advantage, simplicity/complexity tradeoff, threat and departure explanation", + "no unconditional maximization or numeric exchange rate." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Engineering.EvolutionPriority", + "kind": "definition" + }, + { + "name": "CoreReader.Engineering.priorityConditionsCases", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Engineering.priorityConditionsCases" + ], + "semantic_cases": [ + "ordinary_priority", + "missing_behavior", + "missing_safety", + "missing_performance", + "missing_other_necessary", + "concrete_cost_override", + "unexplained_departure", + "no_extensibility_maximum" + ] + }, + { + "id": "T25", + "kind": "theorem", + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "statement": "For a context meeting all priority conditions, with a credible evolution advantage over a simpler feasible option and no concrete cost threat, domain satisfaction requires the evolution-favoring choice/priority and acceptance of its relevant additional complexity.", + "premises": [ + "Every T24 premise explicit, adopted domain rule as normative premise", + "preference compliance separate from act of assessment and universal goodness. Do not infer adoption from Core alone." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Engineering.priorityWhenApplicable", + "kind": "theorem" + }, + { + "name": "CoreReader.Engineering.priorityChoices", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Engineering.priorityChoices" + ], + "semantic_cases": [ + "applicable_choose_evolution", + "applicable_choose_simple_violates_domain", + "threat_allows_departure_with_account" + ] + }, + { + "id": "T26", + "kind": "specification", + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "statement": "Credible change direction has articulable grounds (examples are plan/domain knowledge/history, not an exhaustive required list), remains revisable, and needs no existing multiple implementations. Conceivability alone cannot justify present accommodation.", + "premises": [ + "Grounds for direction and present investment separately", + "applicability of history/knowledge", + "no Boolean label replacing content of supporting plan." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Engineering.CredibleDirection", + "kind": "definition" + }, + { + "name": "CoreReader.Engineering.credibilityCases", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Engineering.credibilityCases" + ], + "semantic_cases": [ + "committed_plan_one_implementation", + "domain_knowledge", + "applicable_history", + "conceivable_only", + "revised_forecast" + ] + }, + { + "id": "T27", + "kind": "nonentailment", + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "statement": "Conceivable change alone does not entail warranted accommodation; credible change does not entail multiple existing implementations, maximal extensibility, retention of every possibility or universal numerical exchange rate.", + "premises": [ + "Nonempty supported direction and explicit alternative irrelevant direction", + "finite priority/qualitative comparison", + "credibility independent of current multiplicity." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Engineering.credibilityLimits", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Engineering.credibilityLimits" + ], + "semantic_cases": [ + "one_implementation_credible", + "imagined_unwarranted", + "selective_evolution", + "qualitative_tradeoff" + ] + }, + { + "id": "T28", + "kind": "specification", + "sources": [ + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "statement": "Cost/departure account admits understanding, construction, diagnosis, verification, coordination, operation and eventual migration burdens and identifies threatened objective and causal significance of added cost.", + "premises": [ + "Do not require every burden be material in every case", + "costs attached to candidate/context and concrete objective, not free exception flag." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Engineering.JustifiedDeparture", + "kind": "definition" + }, + { + "name": "CoreReader.Engineering.costCases", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Engineering.costCases" + ], + "semantic_cases": [ + "understanding_threat", + "construction_threat", + "diagnosis_threat", + "verification_threat", + "coordination_threat", + "operation_threat", + "migration_threat", + "unsupported_cost_excuse" + ] + }, + { + "id": "T29", + "kind": "specification", + "sources": [ + { + "unit": "software-engineering.evolution-meaning", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p2" + } + ], + "statement": "Evolution includes capability addition, implementation replacement, mechanism deletion, abstraction withdrawal, boundary redrawing and technology/model migration; claims identify relevant changes and maintainer conditions; independent/coordinated changes and preserved/revised obligations may require different structures.", + "premises": [ + "Nonexhaustive source include-list", + "identified capability relation indexed by change, context and maintainer", + "obligation semantics tracked." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Engineering.EvolutionClaim", + "kind": "definition" + }, + { + "name": "CoreReader.Engineering.evolutionKindsCases", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Engineering.evolutionKindsCases" + ], + "semantic_cases": [ + "addition", + "replacement", + "deletion", + "withdrawal", + "redrawing", + "migration", + "independent", + "coordinated", + "preserve_obligation", + "revise_obligation" + ] + }, + { + "id": "T30", + "kind": "nonentailment", + "sources": [ + { + "unit": "software-engineering.evolution-meaning", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p2" + } + ], + "statement": "Cheap/effective additions within fixed scheme do not entail equal ability to revise/leave it; advantage on one dimension does not entail every dimension; no duty to make every change inexpensive.", + "premises": [ + "Concrete change-work or enabled-path relation producing add/exit contrast and independent/coordinated contrast", + "no arbitrary unsupported capability flags." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Engineering.evolutionDimensionsLimits", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Engineering.evolutionDimensionsLimits" + ], + "semantic_cases": [ + "easy_add_hard_exit", + "independent_easy_coordinated_hard", + "some_change_expensive_permitted" + ] + }, + { + "id": "T31", + "kind": "specification", + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p2" + } + ], + "statement": "Structural choice applies to whole relevant engineering consequences: component relations, observable contracts, understanding and verification work; boundary capability needs support for intended changes; propagation/cross-boundary knowledge and obligations/fixed assumptions/withdrawal are possible comparison inquiries.", + "premises": [ + "Whole relevant scope rather than every imaginable consequence", + "may-examine inquiries are not compulsory universal checklist", + "intended change and boundary support relation explicit." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Engineering.StructuralAccount", + "kind": "definition" + }, + { + "name": "CoreReader.Engineering.structuralCases", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Engineering.structuralCases" + ], + "semantic_cases": [ + "contract_and_work_comparison", + "propagation_relation", + "cross_boundary_obligation", + "fixed_assumption", + "withdrawal_cost" + ] + }, + { + "id": "T32", + "kind": "nonentailment", + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p2" + } + ], + "statement": "Interface shape, module/extension-point count, named principle or boundary introduction alone cannot establish claimed evolution capability or easier intended change.", + "premises": [ + "Executable or finite semantic consequence model links shape to behavior and work to change", + "demonstrate missing capability by contract/propagation/work failure rather than named false flag." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Engineering.structureNotCapability", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Engineering.structureNotCapability" + ], + "semantic_cases": [ + "same_shape_broken_order", + "many_modules_shared_obligation", + "named_pattern_no_change_path", + "new_boundary_same_work" + ] + }, + { + "id": "T33", + "kind": "specification", + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "p3" + } + ], + "statement": "Distinguish preserving an identified observable contract from deliberately revising it; deliberate revision accounts for changed obligations and affected parties; no requirement to preserve every historical behavior or use particular tests/migration procedure.", + "premises": [ + "Identified contract and observations, deliberate revision intent, obligations/affected parties mapping", + "preservation scope explicit", + "changes outside scope not silently violations." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Engineering.ContractChangeAccount", + "kind": "definition" + }, + { + "name": "CoreReader.Engineering.contractCases", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Engineering.contractCases" + ], + "semantic_cases": [ + "preserve_identified_contract", + "deliberate_revision_with_account", + "revision_missing_parties", + "retired_historical_behavior", + "alternative_procedure" + ] + }, + { + "id": "T34", + "kind": "theorem", + "sources": [ + { + "unit": "software-engineering.structural-judgment", + "clause": "p3" + } + ], + "statement": "Given equality of all identified contract observations in scope, a transformation preserves that identified contract; deliberate changed in-scope observations cannot be claimed preservation of that same contract and require revised-obligation/party account under domain satisfaction.", + "premises": [ + "Contract semantics and scope, total behavior on registered domain, at least one explicit distinguishing observation for revision, domain rule", + "finite examples reported finite." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Engineering.contractPreservation", + "kind": "theorem" + }, + { + "name": "CoreReader.Engineering.contractDistinctions", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Engineering.contractDistinctions" + ], + "semantic_cases": [ + "order_preserving_refactor", + "sorted_order_revision", + "changed_failure_obligation", + "outside_scope_difference" + ] + }, + { + "id": "T35", + "kind": "specification", + "sources": [ + { + "unit": "software-engineering.revision", + "clause": "p2" + }, + { + "unit": "software-engineering.revision", + "clause": "p1" + } + ], + "statement": "Changed evidence about expected changes, maintenance conditions, costs/objectives can justify revised design/priority application; revised judgment acknowledges material grounds changes and cannot retroactively relabel failed prediction success. Retention may be justified by alternatives lacking contribution or defeating objectives.", + "premises": [ + "Separate old/new evidence/time, prediction outcome and judgment, permission versus compulsory redesign", + "applicable alternatives and objective explicit." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Engineering.RevisionAccount", + "kind": "definition" + }, + { + "name": "CoreReader.Engineering.revisionCases", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Engineering.revisionCases" + ], + "semantic_cases": [ + "revised_change_forecast", + "changed_maintainers", + "changed_cost", + "changed_objective", + "failed_prediction_preserved", + "justified_retention" + ] + }, + { + "id": "T36", + "kind": "nonentailment", + "sources": [ + { + "unit": "software-engineering.revision", + "clause": "p2" + }, + { + "unit": "software-engineering.revision", + "clause": "p1" + } + ], + "statement": "Revised judgment cannot make past failed prediction true; continued change, agreement and successful examples do not establish universal correctness; justified retention is compatible with domain/reflexive revision openness.", + "premises": [ + "Time-indexed prediction semantics invariant under report revision", + "finite successes with explicit broader failure", + "activity is open to criticism while choosing stability now." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Engineering.revisionLimits", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Engineering.revisionLimits" + ], + "semantic_cases": [ + "past_failure_not_rewritten", + "agreement_with_bad_case", + "local_success_global_failure", + "open_stable_design" + ] + }, + { + "id": "T37", + "kind": "theorem", + "sources": [ + { + "unit": "organon.relationships.roles", + "clause": "p3" + }, + { + "unit": "extensions", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.revision", + "clause": "p2" + } + ], + "statement": "With inherited and domain satisfaction in a shared applicable context, the priority and evolution-assessment methods remain objects of grounds, consistency and reflexive criticism/revision; domain success cannot exempt its rule.", + "premises": [ + "Same domain-rule object assessed via inherited predicates", + "explicit relevant applicability", + "user adoption choice distinguished from metalevel correctness." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Engineering.priorityRemainsReflexive", + "kind": "theorem" + }, + { + "name": "CoreReader.Engineering.priorityReflexiveCases", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Engineering.priorityReflexiveCases" + ], + "semantic_cases": [ + "priority_self_assessment", + "method_self_criticism", + "no_selfproof_from_success" + ] + }, + { + "id": "T38", + "kind": "satisfiability", + "sources": [ + { + "unit": "organon.charter.overview", + "clause": "p2" + }, + { + "unit": "organon.charter.overview", + "clause": "p3" + }, + { + "unit": "organon.charter.self-transcendence", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.orientation", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.non-finality", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p1" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.consistency.meaning", + "clause": "p2" + }, + { + "unit": "organon.charter.consistency.limits", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity.meaning", + "clause": "p1" + }, + { + "unit": "organon.charter.reflexivity.limits", + "clause": "p1" + }, + { + "unit": "organon.grounds", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + }, + { + "unit": "organon.grounds.scope", + "clause": "p1" + }, + { + "unit": "organon.grounds.scope", + "clause": "p2" + }, + { + "unit": "organon.grounds.scope", + "clause": "p3" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p1" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p2" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p1" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p2" + }, + { + "unit": "organon.grounds.implementations.limits", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + }, + { + "unit": "extensions", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p2" + }, + { + "unit": "software-engineering.purpose", + "clause": "p3" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p2" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p2" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p3" + }, + { + "unit": "software-engineering.revision", + "clause": "p1" + }, + { + "unit": "software-engineering.revision", + "clause": "p2" + } + ], + "statement": "USER ADDITIONAL STRONG OBJECTIVE: one content-bearing nonempty system/context jointly satisfies every represented inherited and domain commitment, with a continuing lifecycle, actual applicable priority and evolution chosen despite additional present abstraction complexity.", + "premises": [ + "Common context/subjects/claims/reasons/alternatives", + "shared nontrivial consequence relation", + "actual empirical/inferential/value duties relevant and fulfilled where represented", + "successor+agent maintenance pathways, credible design-change direction, satisfied necessary requirements, no defeating cost threat. Whole Inherited and Domain interfaces used, not subset." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Engineering.jointWitness", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Engineering.jointWitness" + ], + "semantic_cases": [ + "joint_all_inherited_and_domain", + "same_context_identity", + "nonempty_claims_and_principles", + "active_evolution_priority", + "content_bearing_maintainer_change" + ] + }, + { + "id": "T39", + "kind": "nonentailment", + "sources": [ + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + }, + { + "unit": "extensions", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + } + ], + "statement": "USER ADDITIONAL STRONG OBJECTIVE: a countermodel satisfies all represented inherited commitments while genuine domain-priority applicability holds and domain evolution priority is not adopted; proves non-entailment in the disclosed representation.", + "premises": [ + "Same common context as all inherited duties", + "continuing lifecycle (not temporary), supported credible evolution advantage including design revision, requirements satisfied, no concrete defeating cost threat, present-simplicity preference actually selected/adopted, grounded alternative value reasons consistent with Core, assessment not substituted for adoption." + ], + "acceptance": "Preserve every stated branch and premise; inspect actual Lean types/dependencies; provide all named positive/negative cases with semantic relevance; independent source fidelity acceptance required. A specification alone proves no fulfillment. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [ + { + "name": "CoreReader.Engineering.inheritedDoesNotEntailPriority", + "kind": "case" + } + ], + "required_cases": [ + "CoreReader.Engineering.inheritedDoesNotEntailPriority" + ], + "semantic_cases": [ + "all_inherited_applicable_domain_not_adopted", + "no_temporary_escape", + "no_cost_escape", + "genuine_priority_failure", + "inherited_grounds_for_other_value" + ] + }, + { + "id": "T40", + "kind": "boundary", + "sources": [ + { + "unit": "organon.preamble", + "clause": "p1" + }, + { + "unit": "organon.preamble", + "clause": "p2" + }, + { + "unit": "organon.charter.self-transcendence.limits", + "clause": "p2" + }, + { + "unit": "organon.grounds", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p1" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p2" + }, + { + "unit": "organon.grounds.assessment", + "clause": "p3" + }, + { + "unit": "organon.grounds.scope", + "clause": "p2" + }, + { + "unit": "organon.grounds.scope", + "clause": "p3" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p1" + }, + { + "unit": "organon.grounds.capabilities", + "clause": "p2" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p1" + }, + { + "unit": "organon.grounds.implementations", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p1" + }, + { + "unit": "organon.relationships.roles", + "clause": "p2" + }, + { + "unit": "organon.relationships.roles", + "clause": "p3" + }, + { + "unit": "extensions", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p1" + }, + { + "unit": "software-engineering.purpose", + "clause": "p2" + }, + { + "unit": "software-engineering.purpose", + "clause": "p3" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p2" + }, + { + "unit": "software-engineering.evolution-priority", + "clause": "p3" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p1" + }, + { + "unit": "software-engineering.evolution-meaning", + "clause": "p2" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p1" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p2" + }, + { + "unit": "software-engineering.structural-judgment", + "clause": "p3" + }, + { + "unit": "software-engineering.revision", + "clause": "p1" + }, + { + "unit": "software-engineering.revision", + "clause": "p2" + } + ], + "statement": "Formal specification/conditional proofs and finite witnesses do not establish empirical adequacy of lifecycle forecasts, support relevance, future maintainability, value superiority or universal philosophical correctness; representation choices remain disclosed and revisable.", + "premises": [ + "Every conditional result carries full mathematical premises", + "finite cases and source correspondence judgments are separate", + "difficult agreed theorem cannot be reclassified boundary to claim completion." + ], + "acceptance": "Review manuscript distinction of normative expression, fulfillment witness, mathematical entailment, empirical support and adoption; retain unresolved material readings and every unfinished target. All semantic_cases below remain required even when one checked declaration proves several together. Preserve the source-first case meanings; any actual scope change requires a separately recorded user decision.", + "required_declarations": [], + "required_cases": [], + "semantic_cases": [] + } + ], + "composition_scope": { + "inherited_specifications": [ + "T02", + "T04", + "T07", + "T09", + "T10", + "T11", + "T12", + "T14", + "T16", + "T18" + ], + "inherited_relations_and_terms": [ + "T20", + "T21" + ], + "domain_specifications": [ + "T22", + "T24", + "T26", + "T28", + "T29", + "T31", + "T33", + "T35" + ], + "domain_reflexivity": "T37", + "application": "T38 jointly satisfies every represented applicable inherited and domain obligation on one concrete context. T39 satisfies every inherited obligation with actual domain applicability and no cost exception, but declines the additional priority. Limits and permissions remain intact; not every possible cost or condition must apply in each instance." + } +} diff --git a/SoftwareEngineering/rationale/README.md b/SoftwareEngineering/rationale/README.md new file mode 100644 index 0000000..507cb24 --- /dev/null +++ b/SoftwareEngineering/rationale/README.md @@ -0,0 +1,90 @@ +# Software Engineering: Reasons and Limits + +This non-normative rationale explains the [Software Engineering philosophy](../PHILOSOPHY.md). It neither establishes adoption nor adds obligations to that text. Its starting point is Organon Core 0.1.2; its additional value position concerns software maintained by people and agents across a stated lifecycle. Within that scope, the user favors continued evolution toward credible changes, while accepting concessions when its cost threatens concrete objectives. Credibility concerns identifiable reasons to expect a direction of change, rather than every imaginable extension. + +The argument below distinguishes that value choice from Core's constraints and from engineering literature. Source summaries report limited contributions. Interpretations connecting them to this philosophy are the author's arguments, not conclusions attributed to those sources. Constructed counterexamples are identified accordingly. + +## What Core Contributes, and What It Leaves Open + +**Self-Transcendence** challenges the finality of an architecture, toolchain, or design vocabulary. In software, that gives a reason to retain the possibility of learning a better decomposition. An additional premise is needed to prefer investing in that possibility over completing a bounded product: future constructive capacity must matter within the product's lifecycle. Core itself allows justified stability. A constructed counterexample is a disposable converter whose validated output completes its purpose; replacing its straightforward implementation with an extension framework need not expand anything the maintainers value. + +**Internal Consistency** helps distinguish incompatible commitments from ordinary trade-offs. A system cannot coherently promise a particular freshness guarantee while accepting stale results under precisely that guarantee. Applying this constraint needs explicit meanings of freshness, acknowledgment, and relevant execution conditions. It does not choose those meanings or establish their adequacy. As a constructed counterexample, two components may consistently implement the same erroneous unit conversion. Consistency exposes conflicts within a position; it does not supply the missing domain truth. + +**Reflexivity** brings architecture rules and agent instructions into the same field of criticism as application code. A rule intended to reduce coordination can itself become a source of coordination overhead. The additional engineering premise is that such overhead matters to the maintainers' objectives. A constructed counterexample is a review rule that demands another review of every review without an identifiable remaining question. Reflexivity makes that rule assessable; it neither proves the review effective nor entails this endless procedure or any particular independent-review arrangement. + +**Grounds: articulation and assessment** separates a convincing explanation from sufficient support. A claim about throughput calls for evidence about the relevant workload; a claim that an interface isolates change calls for an argument about dependencies and change scenarios; a preference for future flexibility calls for reasons and acknowledged consequences. The engineering application supplies those workloads and scenarios. A constructed counterexample is a perfectly documented abstraction whose supposed future customers never materialize. Its rationale was articulable, but its forecast may have been poor. + +**Grounds: scope and measurement** prevents a local success from settling a broader architectural comparison. Equal outputs on unchanged inputs leave concurrency, updates, failure handling, and maintenance effort unexamined. Additional premises determine which of those differences matter here. The limit also applies to negative judgments: an isolated incident may justify investigating a failure without establishing a population-wide defect. A constructed counterexample is rejecting a useful failure report solely because it has not yet been reproduced. Neither numerical scores nor repeatability alone resolves relevance. + +**Capability claims** need a declared object of assessment. An agent may reliably perform a transformation in a constrained repository without understanding every reason for the architecture. Core permits external evidence for the former claim; it does not universally require introspective explanation. Requiring an understandable handover is an additional application choice, justified here by continuing maintenance. A constructed counterexample is an opaque but reliable generator supporting a maintainable product through stable interfaces and inspectable outputs. Its opacity alone does not establish incapacity, although a stronger understanding claim remains unsupported. + +**Openness to Alternative Implementations** blocks priority based solely on a pattern's reputation. The contribution is substantive: neither SOLID, functional programming, nor metaprogramming establishes its own suitability. Engineering adds the objectives and constraints that make comparison possible. A constructed counterexample to indiscriminate novelty is replacing a familiar, supported platform with an unfamiliar alternative that offers identical relevant behavior but makes handover harder. Familiarity can supply a practical reason; calling an implementation conventional does not refute it. + +These commitments constrain one another without prescribing a hierarchy of software values. Their conjunction does not entail that evolution takes priority over present abstraction simplicity once relevant necessary requirements are met. This philosophy adds that defeasible preference because its intended maintainers expect continued responsibility for changing software. Conversely, compatibility with Core would not by itself justify adopting the preference. Its merit depends on the lifecycle, the credibility of expected changes, and what maintaining those possibilities costs. + +## Engineering Arguments and Their Boundaries + +Parnas compares decompositions that distribute processing steps with decompositions that hide design decisions. His argument supports examining which knowledge crosses a module boundary. It does not equate good structure with a particular runtime arrangement: he explicitly discusses the call overhead of a mechanical implementation and alternatives that preserve the decomposition while assembling efficient code. This is an original condition, not a later exception invented to protect modularity. [Parnas, “On the Criteria To Be Used in Decomposing Systems into Modules,” pp. 1056–1058](https://cse.sc.edu/~mgv/csce330f14/ParnasCriteria.pdf). + +For **SRP**, Martin's later explanation locates responsibility in the business function requesting change and connects cohesion with common reasons for change. This supports investigating why code changes together, rather than counting methods. Constructed counterexample: separating validation, calculation, and explanation solely because they are different verbs can scatter a single business-rule revision across independently maintained components. That example is this rationale's objection to a mechanical interpretation, not Martin's empirical finding. [Martin, “The Single Responsibility Principle,” 2014](https://blog.cleancoder.com/uncle-bob/2014/05/08/SingleReponsibilityPrinciple.html). + +For **OCP**, Martin explicitly limits closure to selected changes. His original drawing example accommodates new shapes without making the drawing loop immune to a new ordering requirement. The useful question is therefore which change an extension mechanism protects and which it leaves exposed. A promise of universal extensibility overstates this source; modifying an existing boundary can be a reasoned response to a different change direction. [Martin, “The Open-Closed Principle,” p. 6](https://objectmentor.com/resources/articles/ocp.pdf). + +For **LSP**, Liskov and Wing make subtype judgments depend on specifications and preservation of observable properties, including invariants and history properties. Their window example shows why allowing additional movements can violate a property relied on by existing clients. Matching signatures or leaving inherited methods untouched is insufficient. Applying similar reasoning to protocols or generic parameters is a proposed transfer of the idea; their paper does not establish every such application. [Liskov and Wing, “A Behavioral Notion of Subtyping,” §§5.2–5.3](https://www.cs.cmu.edu/~wing/publications/LiskovWing94.pdf). + +For **ISP**, Martin examines clients forced to depend on interfaces they do not use. Separating those dependencies need not split the stateful object: the timed-door example implements distinct client interfaces over shared data. The original case therefore challenges the inference that interface separation always calls for object separation. Whether a proposed division reduces consequential coupling remains a question about the actual clients. [Martin, “The Interface Segregation Principle,” pp. 4–6](https://objectmentor.com/resources/articles/isp.pdf). + +For **DIP**, the concern is the relationship between higher-level policy, abstractions, and implementation details. Martin includes C standard I/O as an example, so the mechanism is not confined to inheritance frameworks. Constructed counterexample: an interface that reproduces a vendor's schema and exceptions can retain dependence on those details despite dependency injection. The architectural claim then needs more than an interface declaration. [Martin, “The Dependency Inversion Principle,” pp. 5–6](https://objectmentor.com/resources/articles/dip.pdf). + +Martin's broader account supplies important qualifications across these principles: static templates can realize OCP; ISP does not require a distinct interface for every client class; stable concrete dependencies can be reasonable. His warning that a character-encoding change can undermine the last judgment preserves its conditions. These qualifications support contextual use rather than a compulsory inventory of abstract classes. [Martin, “Design Principles and Design Patterns,” pp. 7, 14–16](https://objectmentor.com/resources/articles/Principles_and_Patterns.pdf). + +**Refactoring** has a behavioral boundary. Fowler defines it in terms of internal restructuring that makes software easier to understand and cheaper to modify while preserving observable behavior. That supports distinguishing structural preparation from a feature change; the definition alone does not determine a project's observations. Constructed counterexample: a rewrite preserves returned values but changes externally relied-on failure behavior. Calling it refactoring cannot settle whether that behavior was within the preservation claim. [Fowler, “Definition of Refactoring”](https://martinfowler.com/bliki/DefinitionOfRefactoring.html). + +**Functional composition** offers another route to decomposition. Hughes shows how higher-order functions and lazy evaluation separate reusable computation patterns and separate generation from selection. His argument does not make the absence of assignment a sufficient quality measure. An original qualification concerns side effects whose timing becomes dependent on distant consumption. The relevant benefit is a useful compositional boundary, not adherence to a vocabulary or a blanket ban on state. [Hughes, “Why Functional Programming Matters,” §§1–4](https://www.cs.kent.ac.uk/people/staff/dat/miranda/whyfp90.pdf). + +**Generic programming** likewise needs common semantics, not merely matching syntax. Dehnert and Stepanov argue from operational laws and complexity expectations. Their iterator discussion explains why providing random-access-shaped operations over a different complexity model can mislead algorithm selection. This supports examining the assumptions hidden in reusable algorithms; it does not justify requiring every identity-bearing or resource-owning object to model a regular value. [Dehnert and Stepanov, “Fundamentals of Generic Programming,” pp. 3–5, 10–11](https://www.stepanovpapers.com/DeSt98.pdf). + +**Template metaprogramming and partial evaluation** explain how information available earlier can specialize later computation. Veldhuizen relates template instantiation to offline partial evaluation while distinguishing parameterized reuse, compile-time computation, and generation. His recursive-instantiation example also exposes termination limits. The connection can explain a benefit; it cannot establish that specialization is free or that every parameter deserves static binding. [Veldhuizen, “C++ Templates as Partial Evaluation”](https://arxiv.org/abs/cs/9810010). + +Expression templates offer a concrete case: Veldhuizen demonstrates avoiding temporary vectors and combining evaluation, under particular benchmark conditions. Those results do not establish a universal advantage for expression templates. [Veldhuizen, “Expression Templates”](https://www.cs.rpi.edu/~musser/design/blitz/exprtmpl.html). Iglberger and colleagues subsequently show limitations in matrix, sparse, and compound operations, motivating different evaluation strategies and optimized kernels. Their experiments are a counterexample to unconditional performance claims, not evidence about every current library version. [Iglberger et al., “Expression Templates Revisited,” §§5–8](https://arxiv.org/abs/1104.1729). + +This rationale draws a further engineering inference: moving work from execution to compilation changes where cost and restrictions appear. A useful comparison might include build latency, generated-code size, diagnostics, deployment combinations, runtime dispatch, and the expertise required to modify the mechanism. Constructed counterexample: a finite configuration known at release may suit specialization, while customer-loaded behavior may suit runtime selection. Neither arrangement wins solely because it moves decisions earlier or later. + +## Composition and Inheritance + +The LSP argument above concerns behavioral subtyping. It does not by itself choose between inheriting implementation and composing collaborators for reuse. The following comparison is this rationale's engineering argument. Inheritance can provide a useful shared implementation when the subtype contract and supported variation points are stable. Composition can let maintainers replace a collaborator without claiming that the containing object is a subtype of it. Neither mechanism alone establishes independent change: a delegating wrapper that exposes its collaborator's exceptions and lifetime requirements may preserve the same consequential dependencies. + +A constructed example is a service with an evolving retry policy. A policy collaborator can permit replacement without editing an unrelated storage hierarchy. But if retries, transactions and acknowledgment jointly determine observable behavior, separating their classes does not make their changes independent. An inherited framework with explicit, stable hooks may remain easier for its actual maintainers to understand and verify than a network of forwarding objects. Compare the contracts, permitted overrides, ownership and propagation of the credible change. Revisit the choice when those conditions change; do not prefer composition or inheritance solely by slogan. + + +## A Reasoned Design Judgment + +The preceding arguments suggest a contextual line of inquiry, not a mandatory scorecard. A design proposal can begin with a concrete change and explain what would have to be understood, modified, verified, and handed over under the present structure. Comparing a proposed boundary with retaining the current arrangement can then reveal whether it localizes a real decision or simply relocates complexity. One credible change may justify a boundary; numerous hypothetical changes may justify none. + +The important inference concerns total consequences for the relevant maintainers. Fewer edited files can conceal a harder central abstraction. Additional modules can make distinct responsibilities independently intelligible. A specialized implementation can simplify its users' work while concentrating difficult machinery in a place with adequate expertise. These possibilities defeat fixed preferences about paradigm, layer count, or abstraction density. They do not make alternatives indistinguishable: the stated task and constraints can still favor one decisively. + +Verification could combine behavior-preserving comparisons, exercises of the relevant change, examination of dependencies, and a maintainer's explanation of how the design works. These are suggested evidential approaches whose burden depends on the claim. Passing a narrow test supports its narrow result; a clear argument about future change remains conditional on its premises. Uncertainty can favor postponement, a small seam, or direct implementation rather than a general framework. + +## Withdrawal, Migration, and Continuing Responsibility + +Evolution can include removing an abstraction. Under this proposal, its continued presence has no entitlement based on creation cost or architectural prestige. A constructed example is a policy framework whose supposedly independent variations have converged into one stable rule. Inlining that rule may improve comprehensibility and release maintainers from coordinating obsolete extension points. The relevant comparison includes what would become harder to change as well as what becomes simpler now. + +Migration introduces a different question from the desirability of the destination. A simpler representation can be a poor immediate choice if reaching it loses required data, breaks dependent consumers, or exceeds an operational budget. Reversal may require restoring data and coordination state, not merely reverting code. As an application suggestion, staged replacement can expose these consequences while the old behavior remains available; retaining both versions also has costs and cannot be presumed preferable indefinitely. + +Handover provides a concrete challenge to claims of maintainability. Future people and agents inherit interfaces, assumptions, failure modes, and tools, rather than the author's private understanding. This rationale therefore treats reconstructible reasons and usable modification paths as valuable. It does not infer that every contributor must explain every internal mechanism. Maintainers can reasonably rely on constrained generators, specialist ownership, and stable components when those arrangements remain credible over the chosen lifecycle. + +There are strong reasons to reject or override evolution priority in particular circumstances. A short-lived artifact may have no valuable future extension. A verified boundary may be expensive to reopen. Runtime constraints, deployment size, interoperability, or scarce maintenance expertise may make a flexible design threaten the product's purpose. Predictions can also privilege imagined future users over people bearing present costs. These are substantive objections to weigh, not failures to appreciate architecture. + +The principal trade-off is how much present complexity to accept for credible future capability. The preference gives that capability weight without proving its value in every case. Remaining gaps include how a project establishes its lifecycle, whose maintenance burden counts, and what evidence makes a forecast credible enough to guide an expensive choice. This rationale offers reasons for examining those questions; it neither supplies universal thresholds nor certifies adoption. + +## Clause Map + +This map makes the proposal's reasons and revision conditions inspectable. It explains the five domain units without adding obligations to them. + +| Unit | Problem, premises and support | Alternatives, counterexample and revision grounds | +| --- | --- | --- | +| 4.1 Purpose, subjects and lifecycle | An author's ability to edit can conceal a successor's inability to maintain. Continuing responsibility makes tools, knowledge and handover relevant to the capability claimed. | An individual prototype or disposable artifact may need only bounded completion. Changed actual maintenance responsibility or retirement expectations can warrant reconsidering the scope; a label alone does not establish that change. | +| 4.2 Priority for credible evolution | Optimizing present abstraction simplicity can impose avoidable later costs when a change direction has identifiable grounds. The user values that future capability and accepts some present complexity for it. | Present simplicity, postponement and a small seam remain alternatives. A forecast that never materializes, or flexibility that threatens a concrete objective, can defeat a particular investment. This value preference remains criticizable even when the forecast is accurate. | +| 4.3 Meaning of evolution | Extension within one scheme can coexist with an expensive exit. Continued maintenance includes withdrawal, deletion and migration when those changes matter. | A deliberately fixed scope can be adequate for a bounded product. Cheap extension does not prove cheap replacement; different relevant obligations or change directions can warrant reconsidering the judgment. No design must make all changes cheap. | +| 4.4 Structural judgments | Interface shape and pattern names omit behavior, dependencies and verification work. Whole engineering consequences connect a design choice to the capability claimed. | Direct code, abstraction, static specialization and runtime selection can each be supported under different constraints. A signature-compatible replacement that breaks required ordering is a counterexample to shape-based assurance. Changed contracts require a corresponding new judgment. | +| 4.5 Revision and stability | Failed forecasts and sunk investment can preserve mechanisms after their rationale has weakened. Core's non-finality and Grounds support revisiting that rationale while permitting justified retention. | Retaining a design can be justified when alternatives lack a supported contribution or defeat the objective. A costly rewrite with no relevant benefit rebuts compulsory change. Materially changed grounds can warrant another decision without rewriting what supported the earlier one. | diff --git a/SoftwareEngineering/rationale/architecture-case.md b/SoftwareEngineering/rationale/architecture-case.md new file mode 100644 index 0000000..cd2e469 --- /dev/null +++ b/SoftwareEngineering/rationale/architecture-case.md @@ -0,0 +1,77 @@ +# Actual repository case: AgentOrganon responsibilities + +This account examines the AgentOrganon worktree read on 2026-09-12. Its fixed +philosophical baseline was Core 0.1.2; the software engineering priorities were +additional review premises. The proposed domain philosophy was not substituted +for that baseline. This is source-based structural reasoning, separate from the +[constructed executable cases](../docs/cases.md) and the repeated skill study. It reports +neither a completed restructuring nor measured maintenance gains. + +## The decision and the observed boundaries + +The question is whether fewer entrypoints or more shared machinery would help +continuing human and agent maintainers preserve, change and retire this system. +The relevant change directions include downstream philosophical revision, +different operation callers, and handoff between maintainers. A proposed new +host or format remains conditional; this case invents no demand for either. + +Repository paths below are relative to the AgentOrganon checkout: + +- `skills/organon-assess`, `skills/organon-principled-review` and + `skills/organon-absorb` select + the caller's philosophy through `scripts/resolve.js`, then pass its path and + real reference directory into the relevant Core method. The shared resolver + already exists in `scripts/lib/operations.js`; repeated instructions are not + three implementations of the same algorithm. +- Core assess owns the current philosophical relationship judgment. Core + principled-review returns structural findings under identified standards. + Core absorb examines reasons for adoption and coordinates its authorized + workflow. A structural preference does not itself establish philosophical + conflict, and compatibility does not itself warrant adoption. +- `skills/organon-wording-review` delegates wording review without first + selecting a philosophy. A shared preflight that always demanded one would + lose this existing behavior. +- `skills/organon-philosophy` coordinates deterministic document management + with philosophical review. `scripts/lib/sections.js` parses stable units; + `scripts/lib/lock.js` defines and validates source checkpoints and declined-state + records; `scripts/lib/operations.js` compares and binds inputs; + `scripts/lib/io.js` handles protected paths and recoverable paired + writes. These checks cannot certify the meaning or authorization of adoption. + +These boundaries separate questions and failure conditions. They do not prove +that the present files or number of entrypoints are necessary. A format change +would still cross parsing, checkpoints, operations and their shared contract; +layering does not make that migration independent or free. + +## Alternatives under the same objectives + +| Alternative | Reason to consider it | Cost, condition and present judgment | +| --- | --- | --- | +| Retain the allocation | Current relationship, structural analysis, adoption and file operations can change under distinct responsibilities. | Repeated instructions and context handoffs remain maintenance costs. Retention is justified provisionally, without declaring the layout final. | +| Share routing material | A common account of the existing resolver could reduce inconsistent instructions when selection rules change. | Another resolver would duplicate existing machinery; a semantic router also needs task selection rules. Preserve wording-only behavior and explicit-path failure. Fewer paragraphs alone do not establish a benefit. | +| Partially combine assess and full review | A common working context could reduce rediscovery where a broad assessment needs structural analysis. | Preserve narrow assessment and the difference between a method finding and a philosophical conflict. Both distinctions could survive a single file; a file boundary is not their proof. No observed duplication rate establishes a gain here. | +| Pass workspace context directly to Core | A caller that already selects its philosophy can use Core's existing explicit-path contract. | Moving automatic workspace discovery into Core changes its defaults and dependencies. A textual host contract and an executable dependency have different costs; neither is required merely to remove a wrapper. | +| Make handoff material more explicit | A successor could more readily recover the baseline, object, grounds, candidate, authority and next responsible action. | Existing six-part records already cover much of this. Added material can become stale or repeat authoritative sources. Start from a demonstrated omission or a concrete prospective change with clear grounds, rather than requiring a new bundle for every task. | + +The provisional recommendation is to retain the main responsibilities while +examining concrete handoff failures or prospective changes with clear grounds +before selecting a structural revision. For example, an actual lost baseline could support a narrower handoff +correction; a shorter transcript alone would not. Conversely, a combined method +that preserves the relevant distinctions with less successor effort would count +against retaining the current organization. Neither result is assumed here. + +## What this case supports + +Stable unit identities, source checkpoints, remembered declines and recovery +state create present complexity for concrete future operations: moving or +removing text, reconsidering an upstream proposal, and recovering from an interrupted +write. That is a reason to examine what a simplification preserves before +removing these mechanisms. It is not evidence that all existing complexity pays +for itself. + +The source locations above and the checkout's `rtk proxy node --test` suite make +the mechanical claims inspectable. The tests cover their declared file behavior; +they do not compare successor effort, agent judgment or philosophical efficacy. +Independent assessment and the repeated skill study are recorded separately. +This source-based account does not establish their outcomes. New failures can +justify a revision, with its changed grounds identified. diff --git a/SoftwareEngineering/zh/PHILOSOPHY.md b/SoftwareEngineering/zh/PHILOSOPHY.md new file mode 100644 index 0000000..437c7ca --- /dev/null +++ b/SoftwareEngineering/zh/PHILOSOPHY.md @@ -0,0 +1,202 @@ +--- +format_version: 0.1.0 +philosophy_version: 0.2.1 +core_version: 0.1.2 +derived_from: + source_id: "https://github.com/shendeguize/OrganonCore" + philosophy_version: "0.1.2" + content_hash: "cb23f8a44d6b877ff9b5385961ff8e5fa788f8021ae267cdc8e305870ec20ca7" +--- +# 软件工程 Organon:总纲与根据 + + +本文是软件工程 Organon 已采用哲学声明的中文对应译本,表达其承诺,不断言所有体系事实上具有这些属性,也不证明这些承诺普遍正确。[英文权威文本](../PHILOSOPHY.md) 与本文章节对应;含义发生分歧时以英文为准。 + +引用正文、含义及适用条件共同构成核心。总纲与根据相互约束;这种分组既不确立推导层级,也不确立优先次序。[配套论证](rationale/README.md) 提供论证与情境,不向核心增加义务。Skill 是在本仓库已说明的目标与约束下形成的可修订应用,不属于哲学承诺本身。 + +## 1. 总纲 + + +### 1.1 总述 + + +**自超越 · 自洽 · 反身** + +> 体系以拓展自身所能理解和所能构成的可能性为内在取向,将自身及其原则纳入生成与检验,并以自洽约束这一过程。 + +总述连接三个不同的要求:自超越确立生成取向,并拒绝将既有构成视为终点,自洽约束同时持有的判断,反身将体系及其原则纳入它们自身的生成与检验范围。各项条件由下列分述明确。 + +### 1.2 自超越 + + +> 体系以拓展自身所能理解和所能构成的可能性为内在取向,不将任何既有构成视为生成的终点。 + +#### 1.2.1 生成取向 + + +对生成可能保持开放的承诺,与珍视这种可能的拓展有所区别。体系将这种拓展视为值得追求时,就具有内在取向。仅仅允许变化不足以表达这一取向。 + +#### 1.2.2 非终局性 + + +不将既有构成认定为终点,使其保持可被超越的开放性。“既有构成”包括体系当前的组织方式、方法和原则,不仅指外观或已有产物。这些都处于可能改变的范围内;可修订性不保证实际取得进展。 + +#### 1.2.3 成效根据与边界 + + +是否实际取得进展,仍需另行判断。具有这一取向不保证取得进展。不能仅凭产物数量、抽象层数或术语数量的增加认定取得了进展。 + +- “内在取向”表达 Organon 的哲学承诺,不声称所有体系事实上都会自主发展。 +- 自超越不意味着体系无需外部经验、知识或协作,也不保证能够自主执行或自行改善。 +- 不将既有构成视为终点,不要求每次行动都产生改变。有根据的稳定与保留生成取向可以相容。 +- 超越是否拓展了可理解、可构成的可能,须有可辨识的根据;对生成的自我宣称不足以证明实际成效。 + +### 1.3 自洽 + + +> 在相同前提、概念含义与适用范围内,体系同时持有的原则和判断及其推论,不得对同一问题给出相互矛盾的判断。 + +#### 1.3.1 含义 + + +“同时持有”限定了需要共同成立的原则、判断及其推论。修订可以撤回旧判断,不要求新旧原则永远相容;发生了变化,就不能将该变化表述为从未发生。 + +“相同前提、概念含义与适用范围”限定判断之间的比较。不同条件下的判断分歧不自动构成矛盾;暗中改变前提、词义或范围,也不能用于掩盖原有矛盾。 + +#### 1.3.2 适用边界 + + +- 不同评价或价值之间存在张力,并不直接构成矛盾;当它们在相同条件下要求互不相容的结论时,需要修正或限定。 +- 自洽不等于正确或充分。一套原则可以内部一致,却依赖错误前提,或者遗漏重要问题。 + +### 1.4 反身 + + +> 体系的生成与检验原则,同样约束体系自身,以及这些原则的形成、适用与修订。 + +#### 1.4.1 含义 + + +反身覆盖体系自身与原则本身两个对象。不仅检验体系是否符合原则,也检验原则如何形成、适用于何处,以及为何可能需要修订。原则的形成和修订因此也成为生成与检验的对象。 + +#### 1.4.2 适用边界 + + +- “同样约束”保留适用条件。相关条件成立时,不能仅因对象是自身就获得豁免;也不能仅因要求反身,就声称所有原则都可以不加辨析地用于自身。 +- 自我适用不构成自我证明。原则接受自身的检验,不等于原则因此正确。 +- 一个修订由体系自身产生,不等于它因此具有充分根据。 + +## 2. 根据 + + +> 原则与判断的根据应可说明,并接受与主张性质相称的检验。主张的强度与适用范围,应与其根据所能提供的支持相称。 + +### 2.1 说明与检验责任 + + +说明与检验承担不同责任。可说明性要求能够辨明概念、前提、理由及限度;检验要求审查这些根据能否支持相应主张。根据表达清楚,不等于根据已经充分成立。 + +| 主张类型 | 检验责任 | 不能替代该责任的做法 | +| --- | --- | --- | +| 经验主张 | 审查观测、证据与表现,以及它们支持主张的条件、范围和不确定性。 | 将可度量或可重复本身当作相关性、正确性或价值的证明。 | +| 推论主张 | 审查结论是否由所说明的前提和推理关系得到支持。 | 仅因结论与前提没有冲突,就认定结论已经由前提推出。 | +| 价值承诺 | 说明所采取的立场、理由、适用限度及后果,并接受相应质疑。 | 将承诺冒充经验事实或必然推论,或以自我宣称替代理由。 | + +起始价值承诺可以明确作为承诺提出,不要求通过自身证明全部起始前提。主张的强度与适用范围不要求统一换算成数值;不同类型的主张按其性质说明支持与限度。 + +### 2.2 关系、范围与度量的限度 + + +表现总在特定关系、条件和观察范围中被辨识。边界有助于说明比较涉及什么,但局部样例不能自动支持无条件的普遍结论;判断不能因选定的范围遗漏相关差异,就宣称这些差异不存在。 + +度量可以使某些差异可比较;重复评价可以帮助检查相应结论的稳定性。两者及任何检验框架的作用,都须相对于主张和情境说明。度量、可重复性与检验框架不组成所有判断都必须依赖的普遍必然链。 + +未复现的观察仍可能提供有限支持;随机结果不必逐次相同。需要区分观察的可核查性、条件的可复现性及结论的稳定性。 + +### 2.3 能力主张 + + +能力主张接受根据的约束:须能辨明所声称的能力、其条件及支持。核心不统一规定方法掌握、方法生成或能力等级的定义。具体应用明确其所评价的能力,可以要求理解、解释或在相关变化中的表现。 + +能力主张的根据可以由外部评价者提供。根据可说明,并不因此要求被评价体系理解或解释其内部生成过程。可靠产出的证据须依实际声称的能力接受检验,不自动确立对生成过程的理解。方法文档、术语、工具或产物的数量,也不能单独确立超出该证据所能支持的能力。 + +### 2.4 实现选择:对替代实现的开放 + + +> 实现方式的取舍,应有与所追求目标、价值及相关约束相联系的理由。名称、惯例或既有地位本身,不构成优先采用某种实现的充分根据。 + +本选择条款增加一项额外的评价承诺:名称、惯例或既有地位本身不足以确立优先性。将其归入根据,不表示它可以从检验理由的一般要求推出,也不表示它可以仅从表现的可辨识性推出。惯例和已有安排可以具有实际意义,但需要说明这种意义与所追求目标、价值及约束的关系。 + +#### 2.4.1 适用边界 + + +- 开放不意味着所有实现等价,也不保证同一目标必然存在多种可行实现。 +- 方法的解释力、适用边界、简约性及明确的过程要求,都可以成为有根据的评价理由;不能仅因它们涉及实现内部的方法就排除它们。 +- 局部表现相同不足以证明整体等价。关系、条件和比较范围受“根据”各条款约束。 +- 开放不是仅因一种实现已经存在或被惯常采用就否定它;该实现仍可凭相关理由获得优先。 + +## 3. 关系与必要术语 + + +### 3.1 分工与相互约束 + + +总纲表达生成取向、一致性约束与反身适用;根据规定判断所需支持的要求,并包含关于实现选择的额外承诺。两部分都属于核心,且相互约束。这种安排既不使根据成为总纲的推论,也不使总纲优先于根据。每项承诺都需要自己的理由。 + +自洽关注同时持有的判断能否共同成立,根据关注主张是否得到支持,以及得到多大程度的支持。与前提不冲突的结论,仍可能没有被前提支持。自超越规定生成取向与非终局性,两者都不确立实际能力。具体应用可以提供目标、价值及能力定义;在这些目标、价值及定义下提出的主张,仍接受相关核心条款的约束。 + +自超越不替代反身:使既有构成保持可被超越的开放性,与将相关原则用于体系及这些原则自身的形成、适用和修订有所区别。反身将这些要求延伸至体系自身,以及体系原则的形成、适用和修订。“根据”各条款自身的根据与限度须可说明;体系自身的能力主张仍须接受检验;本哲学的既有构成也不能仅凭既有地位获得优先。这种相互适用没有提供自我证明,也不取消适用条件。 + +### 3.2 必要术语 + + +| 中文 | 英文 | 本文中的含义 | +| --- | --- | --- | +| 既有构成 | existing form | 体系当前的组织方式、方法和原则,不仅指外观或已有产物。 | +| 检验 | assessment | 包括对理由、适用性及观察到的表现的审查,不限于可执行的测试。 | + +## 4. 软件工程 + + +本章增加一项软件工程承诺,并说明其含义与限度。本章不声称这一承诺由总纲或根据推出。总纲与根据的条款仍被采纳,并约束这项承诺的适用。 + +### 4.1 目的、主体与生命周期 + + +软件工程涉及在相关的人与技术条件下构建、运行、理解和修订软件。本哲学指导人与 agent 的决策,不将内在取向赋予每一个软件产物。 + +这里考察的演进能力属于持续的工程活动:维护者,包括后续维护者和 agent,结合软件、工具及可用知识开展工作。代码能被原作者修改,不能仅凭这一点就认定它支持这种持续活动。 + +根据软件有可信根据的生命周期与维护预期,适用下列优先原则。确实临时使用的脚本、有明确边界的原型或即将退役的系统,可能没有多少理由支持进一步演进。把一个持续使用的系统称为临时系统,不足以确立这一条件。 + +### 4.2 优先支持有可信根据的演进 + + +> 在相关行为、安全、性能及其他必要要求得到满足时,相比当下的抽象简洁性,优先考虑持续维护者实施有可信根据的未来变更的能力,包括对设计本身的变更。为此接受当下增加的抽象复杂度,同时允许在新增成本威胁具体工程目标时让这一偏好退让。 + +有可信根据的变更方向具有可说明的根据,例如已承诺的计划、相关领域知识或适用的变更历史。它们不必已经存在多个实现。其可信程度仍可修订;一种变更仅仅可以设想,并不足以确立现在就应为它提供支持。 + +这是一项默认优先原则,不是将可扩展性最大化或保留每一种可能性的义务。成本包括理解、构建、诊断、验证、协调、运行及最终迁移所涉及的负担。偏离这一优先原则时,需指出受到威胁的目标,并说明这些成本为何重要。这里不规定这些考量之间通用的数值换算率。 + +### 4.3 演进的含义 + + +演进包括增加能力、替换实现、删除机制、撤除抽象、重划边界,以及迁离既有技术或模型。在固定方案内增加内容,不足以确立同等的修订或脱离该方案的能力。不是每一种此类变更都能够或应当变得低成本。 + +演进主张需指出相关变更和维护者所处的条件。独立变更、协同变更、保留既有义务,以及有意修订这些义务,可能需要不同结构。设计在一个维度上的优势,不足以确立它在所有维度上都具有优势。 + +### 4.4 结构判断及其支持 + + +用前述承诺评价整体工程后果,包括组件之间的关系、其可观察契约,以及理解和验证变更所需的工作。接口的形式、模块或扩展点的数量,或对某项具名原则的使用,都不足以证明所声称的能力。 + +相关比较可以考察变更如何传播,哪些知识和义务跨越边界,哪些前提被固定,以及日后撤除需要什么。拟议边界需要针对其意图支持的变更提供根据;引入边界本身,不足以表明这些变更已变得更容易。 + +区分保持某一已明确的可观察契约的变换,与有意修订该契约的变换。后者需要相应说明改变了哪些义务、影响了哪些相关方。这一区分不要求保留每一种历史行为,也不要求使用特定测试或迁移程序。 + +### 4.5 修订与有根据的稳定 + + +关于可能的变更、维护条件、成本或目标的证据发生变化,可以成为修订设计或调整这一优先原则适用方式的理由。修订后的判断需承认其根据的实质变化,不能据此追溯地将失败的预测改称成功。 + +当相关替代方案没有得到支持的贡献,或其成本使目标无法实现时,保留设计可以有根据。反身也使这项工程承诺以及用于检验演进的方法保持在批评和修订的范围内。持续变化、共识或成功案例,都不足以确立其普遍正确性。 diff --git a/SoftwareEngineering/zh/README.md b/SoftwareEngineering/zh/README.md new file mode 100644 index 0000000..3dad3d8 --- /dev/null +++ b/SoftwareEngineering/zh/README.md @@ -0,0 +1,35 @@ +# Software Engineering Organon + +本目录包含已采用的软件工程 Organon、配套论证及案例。受管理的哲学保留已审议的 Core 0.1.2 来源。格式检查通过本身不构成哲学采用授权。 + +[哲学正文](PHILOSOPHY.md)保留 Core 承诺,并增加有可信根据的软件演进应当优先这一可让步的附加立场。[配套论证](rationale/README.md)考察理由、来源、替代方案及反对意见。[构造案例](docs/cases.md)提供可执行示例;[AgentOrganon 架构案例](rationale/architecture-case.md)另行考察真实仓库职责。本中文文本对应[英文权威文本](../README.md)。 + +哲学版本为 **0.2.0**:增加领域承诺,同时保持已有 Core 承诺的含义、强度与适用范围。`core_version` 保持 **0.1.2**,标识已完整审议的 Core 工作树文本;`format_version` 保持 **0.1.0**。该版本记录已采用的整体;后续改变其含义或适用范围,需要具体决定。 + +领域优先级是一项附加价值承诺,不是自超越的推论。其主体是持续的人类与 agent 维护活动,范围遵循有可信根据的生命周期条件,并同时包括撤除、迁移与扩展。它不自动优先任何技术范式。 + +## 阅读与使用 + +先阅读哲学的承诺与限度,再通过论证考察根据,通过案例查看有边界的可执行示例。论证与案例不增加哲学义务。4.2 优先级以相关必要要求、有可信根据的变更方向和实际生命周期预期为条件;模式名称不能决定设计选择。 + +操作选用本 Organon 作为已采用基线时,应显式传入本目录对应英文 `PHILOSOPHY.md`,并在委托时保持其真实目录。审查拟议替换时,保持调用方选定的已采用基线,将提案单独作为审查对象传入。集合根目录不能代替领域选择。拟议替换在获得具体采用决定前,仍是审查对象。assess 判断与选定哲学的关系,principled-review 进行结构分析,absorb 审议拟议哲学采用,wording-review 只审查措辞。哲学管理负责文档与 lock 操作。 + +以 AgentOrganon checkout 为当前目录,可以检查受管理的目标: + +```sh +rtk proxy node scripts/check.js AdvisedOrganons/SoftwareEngineering/PHILOSOPHY.md +``` + +此命令检查受管理的英文哲学及其 lock,不确立哲学正确性,也不授予采用权限。对独立候选作来源检查,应向 `scripts/check.js --source` 传入候选的实际路径。相邻 lock 属于受管理的英文文档;译文遵循英文元数据和 ID,不具有独立采用状态。 + +从包含 `examples/` 的领域目录运行隔离示例: + +```sh +rtk proxy node examples/run.mjs +``` + +这需要[案例](docs/cases.md)所述的 Node.js 与 C++20 编译器。运行器检查已声明的示例行为与预期反例;它不验证哲学,也不确立生产维护收益。生成文件与执行证据留在被忽略的 `examples/.local/` 中。 + +## Lean 实现与对照稿 + +[Lean 交付说明](../lean/README.md)提供维护中的 Lean 工程、冻结目标、来源审查、选定证据,以及[中文速览](lean/philosophy/overview.md)与[逐行详解](lean/philosophy/details.md)和对应英文稿。采用基准仍保留本 Organon 的 Core 0.1.2。检查显式使用独立 OrganonCore 运行环境,子哲学不复制维护检查器。 diff --git a/SoftwareEngineering/zh/docs/cases.md b/SoftwareEngineering/zh/docs/cases.md new file mode 100644 index 0000000..2520b88 --- /dev/null +++ b/SoftwareEngineering/zh/docs/cases.md @@ -0,0 +1,49 @@ +# 构造的软件工程案例 + +这些原创、独立隔离的示例在已声明要求下比较具体实现选择。它们不是对生产仓库的观察,不是对哲学的独立检验,也不是哲学正确的证据。每个示例都明确指出其契约和已知反例。它们不使用正式独立案例集或留出材料。另行记录的 [AgentOrganon 架构案例](../rationale/architecture-case.md)考察真实仓库职责,并说明其来源与限度。 + +示例需要 Node.js 和 C++20 编译器,不需要第三方包。组合运行器默认使用 `/usr/bin/clang++`;可以通过 `CXX` 选择其他编译器,其约束诊断须包含 `constraints not satisfied`。从同时包含 `examples/` 与 `docs/` 的目录运行: + +```sh +rtk proxy node examples/run.mjs +``` + +运行器将精确的参数向量、工具版本、stdout、stderr、退出状态和终止信号记录在 `examples/.local/verification.log`。生成的二进制文件和日志留在 `examples/.local/` 下,由 `examples/.gitignore` 覆盖。每次运行都会替换该日志;如需比较不同运行,应在重跑前另行保留。命令结果不符合预期时,运行器会失败。预期的编译拒绝只有在编译器非零退出且报告约束未满足时才算成功。同一探针的有效实例必须先编译并运行。 + +## 1. JavaScript:重构前后的可观察契约 + +**目标与约束。** 调用方需要去除重复字符串,并保持首次出现的顺序。接受的输入域为普通稠密字符串数组,包括冻结数组;相等性采用精确比较,不做大小写折叠或 Unicode 规范化。结果是一个由调用方拥有的新数组,输入不变。无效输入抛出 `TypeError`,不规定消息文本。代理、访问器、对内建对象的恶意修改及资源耗尽不在本示例范围内。 + +**变体。** `stableUniqueLoop` 使用迭代和局部 `Set`;`stableUniqueReduce` 使用归约和数组操作。两者提供相同的已声明行为。`sortedUnique` 刻意保留 `string[] -> string[]` 的表面形式,却对输出排序。其已知反例为 `['b', 'a', 'b']`:要求的结果是 `['b', 'a']`,错误的替代实现返回 `['a', 'b']`。 + +**检查与观察。** 共享测试套件检查空输入、重复项、顺序、精确字符串差异、冻结输入、结果所有权,以及包括稀疏数组在内的无效输入。两个正确实现都通过。单独的负例测试确认,错误结果满足表面形式,而同一个相等性断言会拒绝它。测试会捕获这次预期拒绝:测试套件通过,表示发现了反例,不表示错误的替代实现满足契约。 + +维护的源码是 [stable-unique.mjs](../../examples/js/stable-unique.mjs);预先声明的示例和检查在 [contract.test.mjs](../../examples/js/contract.test.mjs) 中。从包含 `examples/` 的目录单独重跑本案例: + +```sh +rtk proxy node --test examples/js/contract.test.mjs +``` + +**限度与维护决定。** 通过这些有限示例,可以支持有边界的重构主张;它不证明所有 JavaScript 交互下的等价性。输入验证被刻意共享,因此共有缺陷可能逃过两个实现之间的比较。预期结果和拒绝检查提供了额外证据,但仍不完整。 + +归约变体反复搜索和复制不断增长的累加器;这一源码层面的观察,构成了选择它之前检查相关负载成本的理由。这里未测量延迟、内存或吞吐量优势。当这些成本威胁具体服务目标时,行为一致本身不足以成为采用它的理由。人类或 agent 维护者可以保留循环实现、撤回拟议替换,或在选定实现后移除冗余变体。永久保留两者不是验收条件。作出这项决定时,保持可观察契约及其回归检查。 + +## 2. C++20:静态配置、泛型形式与运行时变更 + +**目标与约束。** 批次计数器接受 `[0, 1,000,000]` 范围内的记录数和 `[1, 1024]` 范围内的容量,返回记录数除以容量后向上取整的值。不满的最后一批计为一批。无效运行时参数抛出 `std::invalid_argument`;不规定消息文本。另有一项要求:容量可以在同一进程内变化,无需重新编译。这些要求被明确区分:固定的部署配置与运行中的变更,不应被暗中视为可以互换。 + +**变体。** `StaticBatches` 使用 C++20 `requires` 子句约束配置。`RuntimeBatches` 在构造和更新时验证容量。两者均在运行时验证记录数。`BatchPolicy` concept 要求存在可对 const 对象调用且返回 `int` 的表达式;`count_batches` 通过这一泛型接口接受任一策略。`DropsPartialBatch` 满足 concept,却刻意将 `9 / 8` 截断为 `1`,违反结果应为 `2` 的要求。 + +**检查与观察。** 可执行程序检查空记录、恰好整批、不满整批及输入域边界的记录数;有效静态容量的边界;两个变体的无效记录数;无效运行时配置;以及更新行为。将运行时容量从 `8` 改为 `4`,会使 `9` 条记录的结果从 `2` 变为 `3`。被拒绝的更新保持此前的有效容量。静态特化的结果仍为 `2`。concept 接受刻意构造的错误策略,而明确的语义检查观察到了其已知违规。 + +运行器还以容量 `8` 编译同一个配置探针,然后检查编译器是否拒绝 `0` 和 `1025`。这里的编译拒绝确立了这些无效静态配置被排除。它不确立每个被接受的策略都满足语义契约:反例可以编译。检查和实现位于 [case.cpp](../../examples/cpp/case.cpp)、[batches.hpp](../../examples/cpp/batches.hpp) 和 [config-probe.cpp](../../examples/cpp/config-probe.cpp)。使用上面的组合运行器,可以复现正例执行与预期的编译负例。 + +**限度与维护决定。** `requires` 表达式和成功编译检查的是一组明确的语言约束。它们不证明语义可替换性,也不消除动态输入验证。仅有固定特化无法满足运行中变更的要求。在已编译的特化之间进行选择,会增加运行时选择机制以及一组受支持的配置;它不是零成本地提供运行中变更。本案例既不测量优化收益,也不测量分派成本,更不按名称排列范式优劣。 + +对于容量确实固定的部署,在其真实目标下,两种实现都仍是候选。对于运行中变更的要求,运行时变体满足这里演示的变更行为。如果仍要求运行中变更,且尚未确立可接受的替代方案,那么从运行时配置迁往固定特化的迁移应当停止或撤回。只有其具体义务已经退役或转移后,移除运行时路径才有可辩护的理由。这是示意性的决策边界,不是已完成生产迁移的报告,也不是执行此类迁移的授权。 + +## 本地执行记录与支持范围 + +2026-09-12,组合运行器完成了全部 9 条命令:读取工具版本、5 项通过的 JavaScript 测试、C++ 编译与执行、有效配置探针的编译与执行,以及 2 项预期的静态约束拒绝。原始版本信息和诊断输出保存在 `examples/.local/verification.log`。 + +这些案例展示了已声明要求与实现选择的具体后果。它们不确立函数式、命令式、泛型、编译期或运行时技术的普遍优势。它们也不展示生产规模的可扩展性、迁移安全性或任何哲学采用流程的质量。契约、示例、预期反例与重跑命令,为未来的人类及 agent 维护者提供可检查的起点,使其能在已声明目的变化时修订或移除这些示例。 diff --git a/SoftwareEngineering/zh/lean/philosophy/details.md b/SoftwareEngineering/zh/lean/philosophy/details.md new file mode 100644 index 0000000..4149f7b --- /dev/null +++ b/SoftwareEngineering/zh/lean/philosophy/details.md @@ -0,0 +1,24858 @@ +# 软件工程哲学与 Lean:逐行详解 + +本文按 40 个冻结目标组织。目标接受、Lean 检查及来源保真是不同判断;规范定义不证明义务已履行,有限模型也不证明现实中的普遍正确性。47 个来源段落与两个空标题在追溯附录完整保留。 + +采用基准为 SoftwareEngineering 0.2.1(继承 Core 0.1.2);当前 Core 工具仅提供检查运行环境。 + +`accepted` 表示相应目标在已说明范围内获接受;`limited` 表示来源段落只有受限的形式对应;`incomplete` 保留未构成该段完整证明的部分。Lean 的 `passed` 仅报告已登记声明的检查;规范接口的通过不等于义务履行。 + +[另一粒度](overview.md) · [冻结目标](../../../lean/philosophy/targets.json) · [审查与暴露说明](../../../lean/philosophy/reviews/README.md) · [实际声明类型](../../../lean/philosophy/evidence/declaration-types.json) + +| 目标 | 主张 | 种类 | 目标审查 | +| --- | --- | --- | --- | +| [T01](#t01) | 权威与采用基准 | boundary | accepted | +| [T02](#t02) | 重视扩展与形式可修订 | specification | accepted | +| [T03](#t03) | 取向不等于成就 | nonentailment | accepted | +| [T04](#t04) | 整个已持理论的一致性 | specification | accepted | +| [T05](#t05) | 冲突与显式修订 | theorem | accepted | +| [T06](#t06) | 一致性、真与支持有别 | nonentailment | accepted | +| [T07](#t07) | 保留条件的自我适用 | specification | accepted | +| [T08](#t08) | 自我适用不产生自我证明 | nonentailment | accepted | +| [T09](#t09) | 原评估任务的根据 | specification | accepted | +| [T10](#t10) | 经验支持与不确定性 | specification | accepted | +| [T11](#t11) | 推论与否定性检查 | specification | accepted | +| [T12](#t12) | 价值位置及理由 | specification | accepted | +| [T13](#t13) | 表达与支持比例的限度 | nonentailment | accepted | +| [T14](#t14) | 关系、比较范围与方法角色 | specification | accepted | +| [T15](#t15) | 局部证据不会抹去差异 | nonentailment | accepted | +| [T16](#t16) | 应用特定的能力与理解 | specification | accepted | +| [T17](#t17) | 输出证据不蕴涵内省 | nonentailment | accepted | +| [T18](#t18) | 有根据的实现选择 | specification | accepted | +| [T19](#t19) | 开放性与附加选择承诺 | nonentailment | accepted | +| [T20](#t20) | 同一工程系统内的相互适用 | theorem | accepted | +| [T21](#t21) | 现存形式与评估 | boundary | accepted | +| [T22](#t22) | 持续工程活动 | specification | accepted | +| [T23](#t23) | 私人可修改性与共同能力 | nonentailment | accepted | +| [T24](#t24) | 演化优先的条件 | specification | accepted | +| [T25](#t25) | 优先适用时的条件定理 | theorem | accepted | +| [T26](#t26) | 有根据的可信变化方向 | specification | accepted | +| [T27](#t27) | 可信性不等于无限预留 | nonentailment | accepted | +| [T28](#t28) | 具体成本与有根据的让步 | specification | accepted | +| [T29](#t29) | 演化种类与义务变化 | specification | accepted | +| [T30](#t30) | 一项演化优势不是所有优势 | nonentailment | accepted | +| [T31](#t31) | 结构后果与跨边界义务 | specification | accepted | +| [T32](#t32) | 结构名称不能证明能力 | nonentailment | accepted | +| [T33](#t33) | 契约保持与刻意修订 | specification | accepted | +| [T34](#t34) | 契约保持定理 | theorem | accepted | +| [T35](#t35) | 修订与保留历史证据 | specification | accepted | +| [T36](#t36) | 修订不能改写失败 | nonentailment | accepted | +| [T37](#t37) | 优先原则仍接受自身评估 | theorem | accepted | +| [T38](#t38) | 全部已表示义务的共同见证 | satisfiability | accepted | +| [T39](#t39) | 继承义务不强制附加优先 | nonentailment | accepted | +| [T40](#t40) | 形式证据不能建立什么 | boundary | accepted | + + +## T01 · 权威与采用基准 + +SoftwareEngineering 0.2.1 采用继承的 Core 0.1.2 文本及附加工程优先承诺;本稿不推进已采纳的 Core 0.1.2 检查点。 + +**前提与表示:** 完整条款、含义及适用限度是权威文本。rationale 与案例辅助解释;当前 Core 检查器是独立运行依赖。 + +**证明或检查:** 冻结并追溯源字节、元数据及段落原文;文献权威不分配 Lean 定理。 + +**限度:** 章节顺序和检查通过均不建立演绎层级、普遍哲学正确性或所有系统的采用事实。 + +**状态:** accepted (boundary). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.preamble#p1](#source-organon-preamble-p1), [organon.preamble#p2](#source-organon-preamble-p2), [organon.charter.overview#p1](#source-organon-charter-overview-p1), [organon.charter.overview#p2](#source-organon-charter-overview-p2), [organon.charter.overview#p3](#source-organon-charter-overview-p3), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [extensions#p1](#source-extensions-p1) + +此边界目标没有 Lean 声明。 + + + +## T02 · 重视扩展与形式可修订 + +generationSpecification 要求重视扩展,并使当前组织、方法和原则形式保持可修订;有理由的稳定行动可与此取向共存。 + +**前提与表示:** Policy 提供价值位置、当前形式及可修订关系。具体政策有实际当前形式,并非以空清单履责。 + +**证明或检查:** 正例构造价值取向及可修订性;中性政策虽允许版本变化却不重视扩展。稳定与协作案例检查实际状态变换和资源。 + +**限度:** 此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.charter.overview#p2](#source-organon-charter-overview-p2), [organon.charter.overview#p3](#source-organon-charter-overview-p3), [organon.charter.self-transcendence#p1](#source-organon-charter-self-transcendence-p1), [organon.charter.self-transcendence.orientation#p1](#source-organon-charter-self-transcendence-orientation-p1), [organon.charter.self-transcendence.non-finality#p1](#source-organon-charter-self-transcendence-non-finality-p1), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.relationships.terms#p1](#source-organon-relationships-terms-p1) + +### `CoreReader.Adopted.generationSpecification` + +[leanified/CoreReader/Adopted.lean:80](#line-code-leanified-corereader-adopted-lean-80) · definition + +核心依赖: none. + +```lean +def generationSpecification (policy : Policy) : Prop := Generative policy +``` + +### `CoreReader.Adopted.generationCases` + +[leanified/CoreReader/Adopted.lean:862](#line-code-leanified-corereader-adopted-lean-862) · case + +核心依赖: `propext`, `Quot.sound`. + +```lean +theorem generationCases : + (Generative openPolicy ∧ + (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧ + (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1)))) ∧ + (neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy) ∧ + (Generative generatingSystem.policy ∧ + generatingSystem.policy.permitsVersion 0 0 ∧ + ¬ Expanded generatingSystem.current inflatedState ∧ + generatingSystem.current.inventory.length < inflatedState.inventory.length ∧ + generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧ + generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧ + generatingSystem.execute availableResources = some 6 ∧ + generatingSystem.execute { availableResources with experience := none } = none ∧ +``` + + + +## T03 · 取向不等于成就 + +许可、价值取向、可修订性及清单增长本身不建立能力扩展或实际执行。 + +**前提与表示:** 状态包含实际可用操作;删除资源会改变执行结果。成就证据固定同一变换、操作、输入及输出主张。 + +**证明或检查:** 膨胀状态增加数量却没有 successor 操作。协作案例依赖相应资源才获得该操作。性能记录支持指定成就,而自我宣布记录容许反例世界。 + +**限度:** 这些是具体不蕴涵结果及有限支持案例,不是学习或自主执行的经验预测。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.charter.self-transcendence.orientation#p1](#source-organon-charter-self-transcendence-orientation-p1), [organon.charter.self-transcendence.non-finality#p1](#source-organon-charter-self-transcendence-non-finality-p1), [organon.charter.self-transcendence.limits#p1](#source-organon-charter-self-transcendence-limits-p1), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2) + +### `CoreReader.Adopted.generationLimits012` + +[leanified/CoreReader/Adopted.lean:904](#line-code-leanified-corereader-adopted-lean-904) · case + +核心依赖: `propext`, `Quot.sound`. + +```lean +theorem generationLimits012 : + (neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy) ∧ + (Generative openPolicy ∧ + (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧ + (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1)))) ∧ + (Generative generatingSystem.policy ∧ + generatingSystem.policy.permitsVersion 0 0 ∧ + ¬ Expanded generatingSystem.current inflatedState ∧ + generatingSystem.current.inventory.length < inflatedState.inventory.length ∧ + generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧ + generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧ + generatingSystem.execute availableResources = some 6 ∧ + generatingSystem.execute { availableResources with experience := none } = none ∧ +``` + + + +## T04 · 整个已持理论的一致性 + +一致性约束同一假设、含义和范围下所有已持主张的联合后果;如实报告修订是另一项条件。 + +**前提与表示:** Theory 选取命题值主张;Context 固定假设、问题含义和范围。正反后果量化同一组可容许世界。 + +**证明或检查:** 案例展示只有合并才产生的冲突、真实语境变化、分别一致的时间切片及如实的布尔变化记录。 + +**限度:** 一般接口在空问题域中可能空泛成立;工程实例使用非空问题族和实际可容许选项。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.charter.consistency#p1](#source-organon-charter-consistency-p1), [organon.charter.consistency.meaning#p1](#source-organon-charter-consistency-meaning-p1), [organon.charter.consistency.meaning#p2](#source-organon-charter-consistency-meaning-p2), [organon.charter.consistency.limits#p1](#source-organon-charter-consistency-limits-p1) + +### `CoreReader.Adopted.consistencySpecification` + +[leanified/CoreReader/Adopted.lean:90](#line-code-leanified-corereader-adopted-lean-90) · definition + +核心依赖: none. + +```lean +def consistencySpecification {W Q : Type} (before after : Snapshot W Q) + (reported : Bool) : Prop := +``` + +### `CoreReader.Adopted.consistencyCases` + +[leanified/CoreReader/Adopted.lean:952](#line-code-leanified-corereader-adopted-lean-952) · case + +核心依赖: none. + +```lean +theorem consistencyCases : + (Satisfiable (singleton premiseP) ∧ Satisfiable (singleton premiseRule) ∧ + Satisfiable (singleton premiseNotQ) ∧ ¬ Satisfiable jointTheory) ∧ + ((Consequence emptyTheory (assumptionContext true) () true ∧ + Consequence emptyTheory (assumptionContext false) () false) ∧ + (Consequence emptyTheory (meaningContext true) () true ∧ + Consequence emptyTheory (meaningContext false) () false) ∧ + (Consequence emptyTheory (scopeContext true) () true ∧ + Consequence emptyTheory (scopeContext false) () false) ∧ + (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w)) ∧ + (¬ TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (meaningContext true)) (contextSnapshot (meaningContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (scopeContext true)) (contextSnapshot (scopeContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (scopeContext true) 0) (contextSnapshot (scopeContext true) 1) false ∧ + (TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) true ∧ + ¬ Models (assumptionContext false).assumptions true)) ∧ + (Satisfiable (revisionSlice 0) ∧ Satisfiable (revisionSlice 1) ∧ + ¬ Satisfiable (union (revisionSlice 0) (revisionSlice 1))) ∧ + ((∀ time, Consistent (revisionSlice time) broadBoolContext) ∧ + ¬ Consistent (union (revisionSlice 0) (revisionSlice 1)) broadBoolContext) ∧ + (∀ p q : Claim Bool, + ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r) ∧ + (Consequence jointTheory jointContext012 () true ∧ + Consequence jointTheory jointContext012 () false ∧ + ¬ Consistent jointTheory jointContext012) := +``` + + + +## T05 · 冲突与显式修订 + +同一问题上的相反后果违反一致性;撤回旧判断后,各修订时间切片可以分别一致。 + +**前提与表示:** 条件定理接收两项带正反号的后果及共同语境,并不证明这两项前提。 + +**证明或检查:** consistencyConsequences 应用 conflictRequiresChange。切片案例为各时点构造模型,并为合并推导冲突;交换并集次序不改变选中的主张。 + +**限度:** 结果不要求与已撤回主张永久相容,也未识别所有可能掩盖修订的文字遗漏。 + +**状态:** accepted (theorem). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.charter.consistency#p1](#source-organon-charter-consistency-p1), [organon.charter.consistency.meaning#p1](#source-organon-charter-consistency-meaning-p1), [organon.charter.consistency.meaning#p2](#source-organon-charter-consistency-meaning-p2), [organon.charter.consistency.limits#p1](#source-organon-charter-consistency-limits-p1) + +### `CoreReader.Adopted.consistencyConsequences` + +[leanified/CoreReader/Adopted.lean:241](#line-code-leanified-corereader-adopted-lean-241) · theorem + +核心依赖: none. + +```lean +theorem consistencyConsequences {W Q : Type} (t : Theory W) (c : Context W Q) (q : Q) + (positive : Consequence t c q true) (negative : Consequence t c q false) : + ¬ Consistent t c := conflictRequiresChange t c q positive negative +``` + +### `CoreReader.Adopted.consistencyCases` + +[leanified/CoreReader/Adopted.lean:952](#line-code-leanified-corereader-adopted-lean-952) · case + +核心依赖: none. + +```lean +theorem consistencyCases : + (Satisfiable (singleton premiseP) ∧ Satisfiable (singleton premiseRule) ∧ + Satisfiable (singleton premiseNotQ) ∧ ¬ Satisfiable jointTheory) ∧ + ((Consequence emptyTheory (assumptionContext true) () true ∧ + Consequence emptyTheory (assumptionContext false) () false) ∧ + (Consequence emptyTheory (meaningContext true) () true ∧ + Consequence emptyTheory (meaningContext false) () false) ∧ + (Consequence emptyTheory (scopeContext true) () true ∧ + Consequence emptyTheory (scopeContext false) () false) ∧ + (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w)) ∧ + (¬ TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (meaningContext true)) (contextSnapshot (meaningContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (scopeContext true)) (contextSnapshot (scopeContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (scopeContext true) 0) (contextSnapshot (scopeContext true) 1) false ∧ + (TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) true ∧ + ¬ Models (assumptionContext false).assumptions true)) ∧ + (Satisfiable (revisionSlice 0) ∧ Satisfiable (revisionSlice 1) ∧ + ¬ Satisfiable (union (revisionSlice 0) (revisionSlice 1))) ∧ + ((∀ time, Consistent (revisionSlice time) broadBoolContext) ∧ + ¬ Consistent (union (revisionSlice 0) (revisionSlice 1)) broadBoolContext) ∧ + (∀ p q : Claim Bool, + ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r) ∧ + (Consequence jointTheory jointContext012 () true ∧ + Consequence jointTheory jointContext012 () false ∧ + ¬ Consistent jointTheory jointContext012) := +``` + + + +## T06 · 一致性、真与支持有别 + +不同条件与可相容的价值张力不必冲突;一致的集合仍可在某世界为假,或不能推出某结论。 + +**前提与表示:** 案例使用明确的布尔世界、作用域和同时成立的不等式,而非自由指定的正确标记。 + +**证明或检查:** 见证证明一致性;另一个反例赋值使主张为假或反驳所声称的蕴涵。改变假设或范围会显式改变比较对象。 + +**限度:** 一致性不是充分的经验或价值支持;反例只涉及已披露的数学表示。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.charter.consistency.meaning#p2](#source-organon-charter-consistency-meaning-p2), [organon.charter.consistency.limits#p1](#source-organon-charter-consistency-limits-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2) + +### `CoreReader.Adopted.consistencyLimits012` + +[leanified/CoreReader/Adopted.lean:987](#line-code-leanified-corereader-adopted-lean-987) · case + +核心依赖: none. + +```lean +theorem consistencyLimits012 : + ((Consequence emptyTheory (assumptionContext true) () true ∧ + Consequence emptyTheory (assumptionContext false) () false) ∧ + (Consequence emptyTheory (meaningContext true) () true ∧ + Consequence emptyTheory (meaningContext false) () false) ∧ + (Consequence emptyTheory (scopeContext true) () true ∧ + Consequence emptyTheory (scopeContext false) () false) ∧ + (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w)) ∧ + ((∃ budget : Nat, 4 ≤ budget ∧ budget ≤ 6) ∧ + ¬ ((fun n : Nat => 4 ≤ n) = (fun n : Nat => n ≤ 6))) ∧ + (Consistent (singleton (fun w : Bool => w = true)) broadBoolContext ∧ + ¬ Models (singleton (fun w : Bool => w = true)) false ∧ + Consistent (emptyTheory : Theory Bool) broadBoolContext ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧ + (Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧ + (Consistent (union (singleton (fun n : Nat => 4 ≤ n)) (singleton (fun n => n ≤ 6))) tensionContext012) := +``` + + + +## T07 · 保留条件的自我适用 + +相关生成和评估规则适用于系统,以及原则的形成、应用和修订;对象是自身不能成为豁免理由。 + +**前提与表示:** 每条规则具有所属者与键、适用条件、实际输入和结果含义;相同键须对应同一规则。 + +**证明或检查:** 具体记录履行适用的自身目标。仅适用于特定应用的规则提供明确的不适用系统案例。Grounds 对自身的评估使用真实的越界反例和价值理由。 + +**限度:** 一般输入谓词仍需解释;非空具体对象及实际记录建立模型内义务履行,不建立普遍自我证明。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.charter.reflexivity#p1](#source-organon-charter-reflexivity-p1), [organon.charter.reflexivity.meaning#p1](#source-organon-charter-reflexivity-meaning-p1), [organon.charter.reflexivity.limits#p1](#source-organon-charter-reflexivity-limits-p1), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3) + +### `CoreReader.Adopted.reflexivitySpecification` + +[leanified/CoreReader/Adopted.lean:110](#line-code-leanified-corereader-adopted-lean-110) · definition + +核心依赖: none. + +```lean +def reflexivitySpecification {T I O : Type} (rules : List (ReflexiveRule T I O)) + (isSelf : T → Prop) (performed : PrincipleKey → T → I → O → Prop) : Prop := +``` + +### `CoreReader.Adopted.reflexivityCases012` + +[leanified/CoreReader/Adopted.lean:1015](#line-code-leanified-corereader-adopted-lean-1015) · case + +核心依赖: `propext`, `Classical.choice`, `Quot.sound`. + +```lean +theorem reflexivityCases012 : + (reflexivitySpecification ((ownRules 0).map legacyRule) (fun s => s.owner = 0) + (legacyPerformed (ownRules 0) (completeOwnWork 0)) ∧ + (∀ phase, Performed (completeOwnWork 0) (.process 0 0 phase) .assessment) ∧ + Performed (completeOwnWork 0) (.system 0) .assessment ∧ + reflexivitySpecification ([applicationRule].map legacyRule) (fun s => s.owner = 0) + (legacyPerformed [applicationRule] applicationWork) ∧ + ¬ Performed applicationWork (.system 0) .assessment) ∧ + (Grounds012 (fun enabled => GroundsProvision012 enabled) canonicalArticulation [.value groundsPosition012] (.value groundsPosition012) ∧ + groundsPosition012.limits true ∧ groundsPosition012.relevantCriticism true) ∧ + (Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0) ∧ + groundsExperiment012 true = false ∧ groundsExperiment012 false = true ∧ + groundsPosition012.outcome true true = groundsExperiment012 true ∧ + groundsPosition012.outcome true false = groundsExperiment012 false) := +``` + + + +## T08 · 自我适用不产生自我证明 + +自我评估或生成的方案仍可能缺乏支持。在一个共同有限语境中,已表示的完整 Charter 成立,而具体的一般 Grounds 任务不成立。 + +**前提与表示:** CompleteCharter012 包含同一系统的价值取向、可修订性、整体一致性、如实报告及实际适用的自我工作。 + +**证明或检查:** charterWithoutGrounds012 构造该 Charter 见证。预算观察允许一个不具所声称输出能力的世界,因此不能履行指定能力方面的支持责任。 + +**限度:** 此有限反模型不证明所有可能编码中的独立性;保持形式开放也不能替代实际自反工作。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.charter.reflexivity.limits#p1](#source-organon-charter-reflexivity-limits-p1), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.grounds#p1](#source-organon-grounds-p1) + +### `CoreReader.Adopted.reflexivityLimits012` + +[leanified/CoreReader/Adopted.lean:1038](#line-code-leanified-corereader-adopted-lean-1038) · case + +核心依赖: `propext`, `Quot.sound`. + +```lean +theorem reflexivityLimits012 : + (selfTest [1] = true ∧ ownArithmeticPrinciple 0 = false ∧ + ¬ (∀ n, ownArithmeticPrinciple n = true)) ∧ + (localGenerator 0 0 = true ∧ localGenerator 0 1 = false ∧ + Compatible [zeroRecord] (localGenerator 0) ∧ + ¬ Supports [zeroRecord] allTrue ∧ OwnedRevisionExample) ∧ + (Generative openPolicy ∧ ¬ Reflexive 0 (ownRules 0) []) ∧ + (CompleteCharter012 CoreReader.Integration.actualSystem CoreReader.Integration.actual ∧ + Admissible CoreReader.Integration.held CoreReader.Integration.context CoreReader.Integration.actual ∧ + Compatible [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.actual ∧ + Articulated (canonicalArticulation CoreReader.Integration.unsupportedCapabilityFacet) ∧ + ¬ Supports [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.capability ∧ + ¬ Grounds012 CoreReader.Integration.capability canonicalArticulation + [CoreReader.Integration.unsupportedCapabilityFacet] + (taskOfFacet CoreReader.Integration.unsupportedCapabilityFacet)) ∧ + (generationSpecification openPolicy ∧ openPolicy.revisable ⟨.principle,0⟩ ∧ + selfExemptPerformed012 ⟨0,1⟩ 1 1 true ∧ + selfExemptRule012.applicable 0 ∧ + ¬ reflexivitySpecification [selfExemptRule012] (fun target => target = 0) selfExemptPerformed012) := +``` + + + +## T09 · 原评估任务的根据 + +Grounds012 要求非空的评估方面集合,能表达其根据、履行支持责任,并适合原主张任务;清楚表达本身不够。 + +**前提与表示:** AssessmentTask 固定原观察、范围、主张与不确定性,或原推论前提、实际价值位置;NatureAppropriate 比较内容,不只检查分类标签。 + +**证明或检查:** 输入零的证据支持该输入,但容许输入一失败的反例世界。用假设结论的新前提替换原经验任务会被拒绝;合法推论适配保留原观察、范围前提及不确定性。 + +**限度:** 这是已声明任务的充分有限适配,不是穷尽分类,也未导入 Core 0.1.3 的全方面覆盖。声明新任务不授权替换已固定任务。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.grounds#p1](#source-organon-grounds-p1), [organon.grounds.assessment#p1](#source-organon-grounds-assessment-p1), [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3) + +### `CoreReader.Adopted.Grounds012` + +[leanified/CoreReader/Adopted.lean:54](#line-code-leanified-corereader-adopted-lean-54) · definition + +核心依赖: `propext`. + +```lean +def Grounds012 {W : Type} (claim : Claim W) + (articulations : Facet W → Articulation W) (facets : List (Facet W)) + (task : AssessmentTask W) : Prop := +``` + +### `CoreReader.Adopted.groundsCases012` + +[leanified/CoreReader/Adopted.lean:1066](#line-code-leanified-corereader-adopted-lean-1066) · case + +核心依赖: `propext`. + +```lean +theorem groundsCases012 : + (Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧ + Articulated (canonicalArticulation globalFacet012) ∧ + ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧ + ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012)) ∧ + (Articulated uninformativeArgument ∧ + ¬ Entails uninformativeArgument.assumptions (fun w : Bool => w = true)) ∧ + (Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] (taskOfFacet circularGlobalFacet012) ∧ + ¬ NatureAppropriate originalGlobalTask012 circularGlobalFacet012 ∧ + ¬ Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] originalGlobalTask012) := +``` + + + +## T10 · 经验支持与不确定性 + +经验适配检查相容观察、非空适用范围、对指定主张及其不确定性的支持。 + +**前提与表示:** 记录是数学观察函数及记录值;它们与现实测量的对应需要外部解释。 + +**证明或检查:** 相关的输入零记录支持局部主张。重复无关观察不能支持另一对象;不确定性案例的两个相容世界保留不同的未观察结果。 + +**限度:** 重复性或可测性本身不建立相关性、正确性或价值;未观察结果不同不必违背有限支持。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2) + +### `CoreReader.Adopted.empiricalSpecification` + +[leanified/CoreReader/Adopted.lean:152](#line-code-leanified-corereader-adopted-lean-152) · definition + +核心依赖: `propext`. + +```lean +def empiricalSpecification {W : Type} (records : List (Record W)) + (scope claim uncertainty : Claim W) : Prop := +``` + +### `CoreReader.Adopted.empiricalCases012` + +[leanified/CoreReader/Adopted.lean:1082](#line-code-leanified-corereader-adopted-lean-1082) · case + +核心依赖: `propext`. + +```lean +theorem empiricalCases012 : + (Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧ + Articulated (canonicalArticulation globalFacet012) ∧ + ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧ + ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012)) ∧ + (temperatureRecord.test (true,false) = true ∧ + Compatible [temperatureRecord,temperatureRecord] (true,false) ∧ + Compatible [temperatureRecord,temperatureRecord] (true,true) ∧ + ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + Compatible [actionRecord,actionRecord] (true,0) ∧ + Compatible [actionRecord,actionRecord] (true,3) ∧ + ¬ Supports [actionRecord] announcementPosition.consequence ∧ + ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧ + ¬ ValueProcedure announcementPosition) ∧ + (empiricalSpecification [temperatureRecord, temperatureRecord] (fun _ => True) + (fun w => w.1 = true) (fun w => w.2 = true ∨ w.2 = false) ∧ + Compatible [temperatureRecord, temperatureRecord] (true,true) ∧ + Compatible [temperatureRecord, temperatureRecord] (true,false)) ∧ + (Grounds012 (fun f => f 0 = true) canonicalArticulation [localFacet012] originalLocalTask012 ∧ + Grounds012 (fun f => f 0 = true) canonicalArticulation [observedInferenceFacet012] originalLocalTask012) ∧ + (FacetDischarged uncertaintyBypassFacet012 ∧ + ¬ NatureAppropriate originalUncertaintyTask012 uncertaintyBypassFacet012 ∧ + ¬ Grounds012 (fun w : Bool × Bool => w.1 = true) canonicalArticulation + [uncertaintyBypassFacet012] originalUncertaintyTask012) := +``` + + + +## T11 · 推论与否定性检查 + +推论支持要求从可满足的已述假设得到蕴涵;正确完成的检查也可以拒绝结论。 + +**前提与表示:** Entails 量化所给理论的所有模型;InferenceExamined 记录接受与实际蕴涵是否相符。 + +**证明或检查:** 算术案例从 n = 2 推得 n + 1 = 3。布尔反例世界满足同一空理论却使结论为假,从而验证否定性检查。 + +**限度:** 缺少支持不等于评估做错;与假设相容弱于从假设得到蕴涵。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2) + +### `CoreReader.Adopted.inferentialSpecification` + +[leanified/CoreReader/Adopted.lean:161](#line-code-leanified-corereader-adopted-lean-161) · definition + +核心依赖: `propext`. + +```lean +def inferentialSpecification {W : Type} (assumptions : Theory W) (claim : Claim W) : Prop := +``` + +### `CoreReader.Adopted.inferentialCases012` + +[leanified/CoreReader/Adopted.lean:1114](#line-code-leanified-corereader-adopted-lean-1114) · case + +核心依赖: `propext`. + +```lean +theorem inferentialCases012 : + (inferentialSpecification (singleton (fun n : Nat => n = 2)) (fun n => n + 1 = 3) ∧ + InferenceExamined (emptyTheory : Theory Bool) (fun w => w = true) false ∧ + Models (emptyTheory : Theory Bool) false ∧ ¬ ((fun w : Bool => w = true) false)) ∧ + (Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧ + (FacetDischarged (Facet.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) ∧ + ¬ Grounds012 (fun w : Bool => w = true) canonicalArticulation + [.inferential (singleton (fun w => w = true)) (fun w => w = true)] + (.inferential emptyTheory (fun w => w = true))) := +``` + + + +## T12 · 价值位置及理由 + +价值位置陈述采纳、理由、限度、后果及对相关批评的回应;初始采纳不是单由观察推出的。 + +**前提与表示:** ValueProcedure 使用所给目标与约束、采纳与理由共同成立的见证、条件性适切性,以及批评适用时的回应。 + +**证明或检查:** 开关案例具有实际预算与收益后果。去掉相关回应会使程序不成立;中性观察不迫使采纳。 + +**限度:** 应用给出充分的价值评估构造,不是证明所有初始假设的普遍要求,也不证明某价值普遍最优。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3) + +### `CoreReader.Adopted.valueSpecification` + +[leanified/CoreReader/Adopted.lean:168](#line-code-leanified-corereader-adopted-lean-168) · definition + +核心依赖: `propext`. + +```lean +def valueSpecification {W : Type} (position : ValuePosition W) : Prop := +``` + +### `CoreReader.Adopted.valueCases012` + +[leanified/CoreReader/Adopted.lean:1131](#line-code-leanified-corereader-adopted-lean-1131) · case + +核心依赖: `propext`, `Classical.choice`, `Quot.sound`. + +```lean +theorem valueCases012 : + (valueSpecification switchPosition) ∧ + (announcementPosition.reasons ≠ [] ∧ announcementPosition.commitment (true,0) ∧ + (∀ reason, reason ∈ announcementPosition.reasons → reason (true,0) announcementPosition.adopted) ∧ + ¬ announcementPosition.consequence (true,0) ∧ ¬ ValueProcedure announcementPosition) ∧ + (¬ ValueProcedure closedPosition012) ∧ + (ValueProcedure switchPosition ∧ + Satisfiable switchPosition.starting ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧ + (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧ + (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition)) ∧ + (FacetDischarged selectedFactFacet012 ∧ valueSpecification switchPosition ∧ + ¬ Grounds012 switchPosition.commitment canonicalArticulation [selectedFactFacet012] (.value switchPosition)) := +``` + + + +## T13 · 表达与支持比例的限度 + +清楚的理由可能为假或无关;可以用定性蕴涵比较主张强度,无须共同数值尺度。 + +**前提与表示:** 案例固定实际反例世界、中性记录及明确的初始价值假设。 + +**证明或检查:** 反例世界否定表达清楚的事实论证。allTrue 蕴涵输入零为真,反向蕴涵在输入一失败。中性证据和空理论都不能推出价值承诺。 + +**限度:** 这些区分不要求把价值、经验证据和推论化为同一分数。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.grounds.assessment#p1](#source-organon-grounds-assessment-p1), [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3) + +### `CoreReader.Adopted.groundsLimits012` + +[leanified/CoreReader/Adopted.lean:1152](#line-code-leanified-corereader-adopted-lean-1152) · case + +核心依赖: `propext`, `Classical.choice`, `Quot.sound`. + +```lean +theorem groundsLimits012 : + (Articulated clearFalseArgument012 ∧ ¬ Models clearFalseArgument012.assumptions false) ∧ + (temperatureRecord.test (true,false) = true ∧ + Compatible [temperatureRecord,temperatureRecord] (true,false) ∧ + Compatible [temperatureRecord,temperatureRecord] (true,true) ∧ + ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + Compatible [actionRecord,actionRecord] (true,0) ∧ + Compatible [actionRecord,actionRecord] (true,3) ∧ + ¬ Supports [actionRecord] announcementPosition.consequence ∧ + ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧ + ¬ ValueProcedure announcementPosition) ∧ + (valueSpecification switchPosition ∧ + Compatible [valueNeutralRecord012] false ∧ + ¬ Supports [valueNeutralRecord012] switchPosition.commitment ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment) ∧ + (ValueProcedure switchPosition ∧ + Satisfiable switchPosition.starting ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧ + (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧ + (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition)) ∧ + (ClaimNoStronger (fun f : Nat → Bool => f 0 = true) allTrue ∧ + ¬ ClaimNoStronger allTrue (fun f : Nat → Bool => f 0 = true) ∧ + valueSpecification switchPosition) := +``` + + + +## T14 · 关系、比较范围与方法角色 + +被比较对象须处于已述条件和观察范围,并满足所述相关关系;每项实际使用的方法需要与主张相关的角色说明。 + +**前提与表示:** ScopeAccount 提供比较、相关关系及 explains 谓词;具体记录另将主张、条件、角色文本与支持事实精确连接。 + +**证明或检查:** 局部记录将两个输入都限制为零。测量与重复支持该局部输出;框架角色明确保留不能普遍外推的结论。 + +**限度:** 角色字符串非空本身不是充分解释;未使用的方法也不会因此成为必需。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.grounds.scope#p1](#source-organon-grounds-scope-p1), [organon.grounds.scope#p2](#source-organon-grounds-scope-p2), [organon.grounds.scope#p3](#source-organon-grounds-scope-p3) + +### `CoreReader.Adopted.scopeSpecification` + +[leanified/CoreReader/Adopted.lean:191](#line-code-leanified-corereader-adopted-lean-191) · definition + +核心依赖: none. + +```lean +def scopeSpecification {W : Type} (account : ScopeAccount W) : Prop := +``` + +### `CoreReader.Adopted.scopeCases012` + +[leanified/CoreReader/Adopted.lean:1184](#line-code-leanified-corereader-adopted-lean-1184) · case + +核心依赖: `propext`. + +```lean +theorem scopeCases012 : + (scopeSpecification localScopeAccount012) ∧ + ((∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧ + (fun _ : Nat => true) 1 ≠ localGenerator 0 1) := +``` + + + +## T15 · 局部证据不会抹去差异 + +局部行为相同可与别处的相关差异共存;有限观察可以支持有限主张,无须普遍的方法链。 + +**前提与表示:** 主张及观察范围保持明确。随机输出案例区分事件观察、条件可复现与有限结论的稳定性。 + +**证明或检查:** 具体函数在零处相同,在一处不同;单次观察只支持其局部主张。数学推论和价值程序展示不强制使用观察链的情形。 + +**限度:** 把某输入排除出比较,不是该处不存在相关差异的证据。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.grounds.scope#p1](#source-organon-grounds-scope-p1), [organon.grounds.scope#p2](#source-organon-grounds-scope-p2), [organon.grounds.scope#p3](#source-organon-grounds-scope-p3), [organon.grounds.implementations.limits#p1](#source-organon-grounds-implementations-limits-p1) + +### `CoreReader.Adopted.scopeLimits012` + +[leanified/CoreReader/Adopted.lean:1197](#line-code-leanified-corereader-adopted-lean-1197) · case + +核心依赖: `propext`, `Quot.sound`. + +```lean +theorem scopeLimits012 : + ((∃ outside : Nat, outside ≠ 0) ∧ + Compatible [zeroRecord] (fun _ => true) ∧ + Compatible [zeroRecord] (localGenerator 0) ∧ + allTrue (fun _ => true) ∧ ¬ allTrue (localGenerator 0) ∧ + ¬ Supports [zeroRecord] allTrue) ∧ + ((∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧ + (fun _ : Nat => true) 1 ≠ localGenerator 0 1) ∧ + ([zeroRecord].length = 1 ∧ + (∃ f, Compatible [zeroRecord] f) ∧ + Supports [zeroRecord] (fun f => f 0 = true) ∧ + ¬ Supports [zeroRecord] allTrue) ∧ + (let a : Trial := ⟨0,1,1⟩ +``` + + + +## T16 · 应用特定的能力与理解 + +能力主张保留实际对象、契约及根据;应用可以要求超出可靠输出或输出等价解释的能力。 + +**前提与表示:** 输出契约覆盖所有自然数输入。另一个机制应用将操作性理解定义为解释同一过程,并正确回答所有输入与乘数变式;这是该应用选择的判准。 + +**证明或检查:** ExternalCertificate 在无内省要求下检查输出。两个机制对象具有同一个 explainedProcess;固定翻倍回答者在 (3,1) 失败,机制回答者则证明更强契约及同对象 Grounds012;失败对象也不能获得该根据。 + +**限度:** 这不是心理理解的普遍定义。精确身份是范围前提;履行支持责任的是实际契约证明,而非身份本身。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3) + +### `CoreReader.Adopted.capabilitySpecification` + +[leanified/CoreReader/Adopted.lean:205](#line-code-leanified-corereader-adopted-lean-205) · definition + +核心依赖: `propext`. + +```lean +def capabilitySpecification (assessed : Process) (contract : Claim Process) : Prop := +``` + +### `CoreReader.Adopted.capabilityCases012` + +[leanified/CoreReader/Adopted.lean:1232](#line-code-leanified-corereader-adopted-lean-1232) · case + +核心依赖: `propext`. + +```lean +theorem capabilityCases012 : + (capabilitySpecification outputOnlyProcess OutputContract ∧ + capabilitySpecification explainedProcess FullProcessContract ∧ + (∃ certificate : ExternalCertificate outputOnlyProcess, + certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧ + ¬ ExplanationContract outputOnlyProcess) ∧ + (OwnCapability012 7 7 outputOnlyProcess OutputContract) ∧ + (explainedWithoutVariation012.process = mechanismResponder012.process ∧ + FullProcessContract explainedWithoutVariation012.process ∧ + ¬ UnderstandingApplication012 explainedWithoutVariation012 ∧ + UnderstandingApplication012 mechanismResponder012 ∧ + Grounds012 UnderstandingApplication012 canonicalArticulation + [understandingFacet012 mechanismResponder012] (understandingTask012 mechanismResponder012) ∧ + ¬ Grounds012 UnderstandingApplication012 canonicalArticulation + [understandingFacet012 explainedWithoutVariation012] (understandingTask012 explainedWithoutVariation012)) := +``` + + + +## T17 · 输出证据不蕴涵内省 + +可靠输出、外部表达及清单增长,不自动建立过程解释或更强能力。 + +**前提与表示:** 不透明过程实际不返回解释证书,但其输出证明仍覆盖所有自然数输入。 + +**证明或检查:** 证明将输出正确与没有解释并置。重复各类 copy 产物不会提供 successor 操作;资源和膨胀状态案例保留此区别。 + +**限度:** 外部评估者可以支持所选输出主张,而不建立被评系统如何理解自身生成过程。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2) + +### `CoreReader.Adopted.capabilityLimits012` + +[leanified/CoreReader/Adopted.lean:1254](#line-code-leanified-corereader-adopted-lean-1254) · case + +核心依赖: `propext`, `Quot.sound`. + +```lean +theorem capabilityLimits012 : + (capabilitySpecification outputOnlyProcess OutputContract ∧ + capabilitySpecification explainedProcess FullProcessContract ∧ + (∃ certificate : ExternalCertificate outputOnlyProcess, + certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧ + ¬ ExplanationContract outputOnlyProcess) ∧ + (∀ kind : InventoryKind, + Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .copy ∧ + ¬ Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .successor) ∧ + (Generative generatingSystem.policy ∧ + generatingSystem.policy.permitsVersion 0 0 ∧ + ¬ Expanded generatingSystem.current inflatedState ∧ + generatingSystem.current.inventory.length < inflatedState.inventory.length ∧ + generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧ + generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧ + generatingSystem.execute availableResources = some 6 ∧ + generatingSystem.execute { availableResources with experience := none } = none ∧ +``` + + + +## T18 · 有根据的实现选择 + +实现优先需要与目标和约束相连的理由。惯例可有实践意义,但地位本身不够。 + +**前提与表示:** JustifiedChoice 包含实际需求满足及至少一项相关方法理由。解释、适用性、简单性和过程都可在所选需求下相关。 + +**证明或检查:** 惯用的恒等实现满足契约和预算。廉价 successor 虽成本较低却不满足指定输出;仅凭地位的选择不满足理由条件。 + +**限度:** 这些是应用理由,不是普遍成本函数,也不要求惯用实现必须落选。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.grounds.implementations#p1](#source-organon-grounds-implementations-p1), [organon.grounds.implementations#p2](#source-organon-grounds-implementations-p2), [organon.grounds.implementations.limits#p1](#source-organon-grounds-implementations-limits-p1), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3) + +### `CoreReader.Adopted.choiceSpecification` + +[leanified/CoreReader/Adopted.lean:215](#line-code-leanified-corereader-adopted-lean-215) · definition + +核心依赖: none. + +```lean +def choiceSpecification (requirements : Requirements) (implementation : Implementation) + (reasons : List Reason) : Prop := JustifiedChoice requirements implementation reasons +``` + +### `CoreReader.Adopted.choiceCases012` + +[leanified/CoreReader/Adopted.lean:1295](#line-code-leanified-corereader-adopted-lean-1295) · case + +核心依赖: `propext`, `Classical.choice`, `Quot.sound`. + +```lean +theorem choiceCases012 : + (identityImpl.conventional = true ∧ identityImpl.established = true ∧ + JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output]) ∧ + (Relevant identityRequirements identityImpl (.method .explanation) ∧ + Relevant identityRequirements identityImpl (.method .applicability) ∧ + Relevant identityRequirements identityImpl (.method .simplicity) ∧ + Relevant identityRequirements identityImpl (.method .procedure) ∧ + (Relevant identityRequirements cheapSuccessor (.method .simplicity) ∧ + ¬ JustifiedChoice identityRequirements cheapSuccessor [.method .simplicity])) ∧ + (Articulated priorityArticulation ∧ AssessmentAccurate false ∧ + (∀ selected, Models statusFacts selected) ∧ + priorityClaim .identity ∧ ¬ priorityClaim .successor ∧ + ¬ Entails statusFacts priorityClaim ∧ + ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧ + ((∀ n, identityImpl.run n = wrongExplanation012.run n) ∧ + Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧ + Relevant identityRequirements identityImpl (.method .explanation) ∧ + ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation)) ∧ + (¬ choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation + [.status .standing] ∧ + choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation + [.method .output]) ∧ + (∀ kind : StatusKind, + ¬ choiceSpecification identityRequirements identityImpl [.status kind]) := +``` + + + +## T19 · 开放性与附加选择承诺 + +开放性允许选项不同,也可与只有一个可行惯用选项共存。附加选择规则不能仅由完成一般评估得到。 + +**前提与表示:** 有限的一般评估模型与 T39 的更强工程不蕴涵,是不同对象和结果。 + +**证明或检查:** 具体需求范围区分局部相同的选项。一般评估案例保留所述评估,但仅凭地位的优先缺乏相关理由。 + +**限度:** 没有结果断言所有实现等价、保证多个可行实现,或从章节位置推出选择承诺。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.grounds.implementations#p1](#source-organon-grounds-implementations-p1), [organon.grounds.implementations#p2](#source-organon-grounds-implementations-p2), [organon.grounds.implementations.limits#p1](#source-organon-grounds-implementations-limits-p1) + +### `CoreReader.Adopted.choiceLimits012` + +[leanified/CoreReader/Adopted.lean:1329](#line-code-leanified-corereader-adopted-lean-1329) · case + +核心依赖: `propext`, `Classical.choice`, `Quot.sound`. + +```lean +theorem choiceLimits012 : + ((∀ candidate, Feasible identityRequirements (implementation candidate) ↔ candidate = .identity) ∧ + JustifiedChoice identityRequirements identityImpl objectiveReason) ∧ + (identityImpl.conventional = true ∧ identityImpl.established = true ∧ + JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output]) ∧ + ((∀ n, identityImpl.run n = wrongExplanation012.run n) ∧ + Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧ + Relevant identityRequirements identityImpl (.method .explanation) ∧ + ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation)) ∧ + (JustifiedChoice identityRequirements identityImpl objectiveReason ∧ + identityImpl.run 0 ≠ successorImpl.run 0) ∧ + ((∀ x, x = 0 → identityImpl.run x = changedOutsideZero.run x) ∧ + identityImpl.run 1 ≠ changedOutsideZero.run 1) ∧ + ((Articulated priorityArticulation ∧ AssessmentAccurate false ∧ + (∀ selected, Models statusFacts selected) ∧ + priorityClaim .identity ∧ ¬ priorityClaim .successor ∧ + ¬ Entails statusFacts priorityClaim ∧ + ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧ + PolicyIndependenceExample) := +``` + + + +## T20 · 同一工程系统内的相互适用 + +继承义务适用于本系统的原则、方法、价值位置、能力报告和实现选择;实际规范内容进入其整体一致性理论。 + +**前提与表示:** Inherited 固定 sharedContext,并包含已履行的生成、自反、原经验/推论/价值任务、范围、能力和选择。ownTheory 合并实际事实与各项适用 OwnNorm 内容;一致性约束该完整并集。 + +**证明或检查:** inheritedMutualApplication 提取实际字段及完整内容/支持关系;inheritedCurrent 另行构造它们。两条实际自反规则均成为自身对象,评估器的修订检查报告其局部空样本缺陷。 + +**限度:** 字段提取不从单一原则推出所有义务。采纳标记是独立事实,不能替代规范内容。要求样本的批评属于应用判准,不是对观察的普遍要求。 + +**状态:** accepted (theorem). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3) + +### `CoreReader.Engineering.inheritedMutualApplication` + +[leanified/CoreReader/Engineering/Integration.lean:420](#line-code-leanified-corereader-engineering-integration-lean-420) · theorem + +核心依赖: `propext`. + +```lean +theorem inheritedMutualApplication (ctx : Context) (chosen : Candidate) + (inherited : Inherited ctx chosen) : + generationSpecification engineeringPolicy ∧ + reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self + (selfModel chosen).performed ∧ + (∀ principle, valueSpecification (governancePosition principle)) ∧ + capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen) ∧ + choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons ∧ + (∀ fact, inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact)) ∧ + (∀ norm, normApplies chosen norm → ownTheory chosen (ownNormClaim chosen norm)) ∧ + (∀ claim, ownTheory chosen claim → inferentialSpecification (ownFactPremises chosen) claim) ∧ + consistencySpecification (engineeringSnapshot .evolvable 0) + (engineeringSnapshot chosen 1) true := +``` + +### `CoreReader.Engineering.inheritedMutualCases` + +[leanified/CoreReader/Engineering/Integration.lean:442](#line-code-leanified-corereader-engineering-integration-lean-442) · case + +核心依赖: `propext`, `Classical.choice`, `Quot.sound`. + +```lean +theorem inheritedMutualCases : + Inherited sharedContext .evolvable ∧ + valueSpecification (governancePosition .grounds) ∧ + capabilitySpecification (engineeringProcess .evolvable) (engineeringCapability .evolvable) ∧ + choiceSpecification chosenRequirements (chosenImplementation .evolvable) chosenReasons ∧ + Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧ + (.generationRule : ReviewObject) ∈ (selfModel .evolvable).objects ∧ + (.assessmentRule : ReviewObject) ∈ (selfModel .evolvable).objects ∧ + Reflection.evaluate ((selfModel .evolvable).input ⟨0, .assessmentRule, .revision⟩) = .counterexample := +``` + + + +## T21 · 现存形式与评估 + +现存形式包含组织、方法和原则;评估包括检查理由及适用性,不限于可执行测试。 + +**前提与表示:** 这些术语约束全文及其他目标的解释。 + +**证明或检查:** 来源追溯保留术语原文。形式类别及推论/价值案例说明其用法,不为词表另造定理。 + +**限度:** 此处使用的有限测试机制没有把所有评估重新定义为测试。 + +**状态:** accepted (boundary). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.relationships.terms#p1](#source-organon-relationships-terms-p1) + +此边界目标没有 Lean 声明。 + + + +## T22 · 持续工程活动 + +主体是由维护者、软件、工具和可用知识在实际生命周期中构成的活动;“临时”标签不能建立有限生命周期。 + +**前提与表示:** ActivityScope 要求非空参与者、软件和工具,以及参与者可用的知识;Continuing 和 BoundedLifecycle 检查发布、维护和限定运行次数。 + +**证明或检查:** 持续案例虽带临时标签,却有三次发布和六个维护周期。另设临时、原型和退役活动,具有真正限定的执行且没有后续维护安排。 + +**限度:** 这些数量是有限模型数据,不是项目工期估算。处于范围内本身不证明每位参与者都能完成每种变化。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.purpose#p1](#source-software-engineering-purpose-p1), [software-engineering.purpose#p2](#source-software-engineering-purpose-p2), [software-engineering.purpose#p3](#source-software-engineering-purpose-p3) + +### `CoreReader.Engineering.ActivityScope` + +[leanified/CoreReader/Engineering/Domain.lean:49](#line-code-leanified-corereader-engineering-domain-lean-49) · definition + +核心依赖: none. + +```lean +abbrev ActivityScope (a : Activity) : Prop := +``` + +### `CoreReader.Engineering.subjectLifecycleCases` + +[leanified/CoreReader/Engineering/Domain.lean:146](#line-code-leanified-corereader-engineering-domain-lean-146) · case + +核心依赖: `propext`. + +```lean +theorem subjectLifecycleCases : + ActivityScope continuingActivity ∧ + CanChange continuingActivity .evolvable .successor .designRevision ∧ + CanChange continuingActivity .evolvable .agent .designRevision ∧ + continuingActivity.label = "temporary" ∧ Continuing continuingActivity ∧ + ¬ BoundedLifecycle continuingActivity ∧ BoundedLifecycle temporaryActivity ∧ + BoundedLifecycle prototypeActivity ∧ BoundedLifecycle retiringActivity := by decide +``` + + + +## T23 · 私人可修改性与共同能力 + +原作者能够修改,不建立继任者或代理的能力;被动产物本身也不承接活动的意图。 + +**前提与表示:** CanChange 检查非空实际编辑/验证路径、参与者身份、工具及每一步所需知识。 + +**证明或检查:** 简单设计需要 privateLayout;原作者具备,继任者和代理没有。文档化路径使用后两者可用的公共知识和工具。产物执行与维护者提案仍是不同活动。 + +**限度:** 结果涉及已表示路径;缺少某条文档化路径,不是所有维护方式均不可能的普遍定理。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.purpose#p1](#source-software-engineering-purpose-p1), [software-engineering.purpose#p2](#source-software-engineering-purpose-p2), [software-engineering.purpose#p3](#source-software-engineering-purpose-p3) + +### `CoreReader.Engineering.subjectLimits` + +[leanified/CoreReader/Engineering/Domain.lean:159](#line-code-leanified-corereader-engineering-domain-lean-159) · case + +核心依赖: `propext`. + +```lean +theorem subjectLimits : + CanChange continuingActivity .presentSimple .original .designRevision ∧ + ¬ CanChange continuingActivity .presentSimple .successor .designRevision ∧ + ¬ ContinuingCapability continuingActivity .presentSimple .designRevision ∧ + continuingActivity.label = "temporary" ∧ ¬ BoundedLifecycle continuingActivity ∧ + orientation .agent ≠ [] ∧ passiveArtifact [2, 1] = [2, 1] ∧ + EngineeringAction.propose .designRevision ∈ maintainerActions .agent ∧ + EngineeringAction.propose .designRevision ∉ artifactActions [2, 1] := by decide +``` + + + +## T24 · 演化优先的条件 + +EvolutionPriority 是有条件的采用偏好:全部 PriorityConditions 成立时,选择 evolvable,或给出有根据的让步。 + +**前提与表示:** 条件要求持续发布与维护;参与者、软件身份及工具非空;每位参与者均有可用知识;两选项均满足行为/安全/延迟/保留要求;设计修订具有可信根据;evolvable 的修订路径非空,且每位列出参与者都具有路径所需的全部知识与工具。该路径的工作量须低于简单选项,而演化选项的当前复杂度更高。 + +**证明或检查:** 每种必要要求失败都会阻断适用性。普通语境的工作量为 6 对 17,复杂度为 3 对 1。具体成本威胁可支持让步,无说明的借口不能。最大候选增加真实 CSV 路径,却超出预算。 + +**限度:** 这里表达并例示默认价值优先,不从 Core 演绎该优先,也不要求最大扩展性。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.purpose#p3](#source-software-engineering-purpose-p3), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3) + +### `CoreReader.Engineering.EvolutionPriority` + +[leanified/CoreReader/Engineering/Domain.lean:321](#line-code-leanified-corereader-engineering-domain-lean-321) · definition + +核心依赖: none. + +```lean +abbrev EvolutionPriority (ctx : Context) (chosen : Candidate) : Prop := +``` + +### `CoreReader.Engineering.priorityConditionsCases` + +[leanified/CoreReader/Engineering/Domain.lean:367](#line-code-leanified-corereader-engineering-domain-lean-367) · case + +核心依赖: `propext`. + +```lean +theorem priorityConditionsCases : + EvolutionPriority currentContinuing .evolvable ∧ + ¬ Meets normalRequirements { profile .evolvable with orderOutput := [1, 2] } ∧ +``` + + + +## T25 · 优先适用时的条件定理 + +给定已采用的优先规则、全部适用条件且无有根据的让步,必须选择 evolvable,并接受其较高当前复杂度。 + +**前提与表示:** priorityWhenApplicable 接收 EvolutionPriority、PriorityConditions 及不存在 JustifiedDeparture;这些是定理前提。 + +**证明或检查:** 将规则应用于给定条件,排除让步分支,再提取严格复杂度比较。具体案例检查演化选择、违反规则的简单选择及受威胁支持的让步。 + +**限度:** 定理不从事实证明价值规则,也不建立所有看似复杂的设计均具有相关优势。 + +**状态:** accepted (theorem). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3) + +### `CoreReader.Engineering.priorityWhenApplicable` + +[leanified/CoreReader/Engineering/Domain.lean:337](#line-code-leanified-corereader-engineering-domain-lean-337) · theorem + +核心依赖: none. + +```lean +theorem priorityWhenApplicable (ctx : Context) (chosen : Candidate) + (rule : EvolutionPriority ctx chosen) (applicable : PriorityConditions ctx) + (noDeparture : ¬ JustifiedDeparture ctx .evolvable) : + chosen = .evolvable ∧ + abstractionComplexity .presentSimple < abstractionComplexity chosen := by +``` + +### `CoreReader.Engineering.priorityChoices` + +[leanified/CoreReader/Engineering/Domain.lean:384](#line-code-leanified-corereader-engineering-domain-lean-384) · case + +核心依赖: `propext`. + +```lean +theorem priorityChoices : + EvolutionPriority currentContinuing .evolvable ∧ + ¬ EvolutionPriority currentContinuing .presentSimple ∧ + EvolutionPriority (threatened .verification) .presentSimple := by +``` + + + +## T26 · 有根据的可信变化方向 + +可信方向具有可表达的支持根据;无须已经存在多个实现,而单纯想象不足。 + +**前提与表示:** 适配检查计划、领域知识和历史内容,并提供可扩展的其他证据形式;这些是应用构造子,不是穷尽的哲学清单。 + +**证明或检查:** 登记计划指定第 2 次发布及设计修订。知识与历史案例检查具体相关性。仅有想象的条目失败;证据变化可以产生不同预测。 + +**限度:** 证明检查模型中给定的证据内容,不建立任意现实计划的可信性或预测校准程度。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3) + +### `CoreReader.Engineering.CredibleDirection` + +[leanified/CoreReader/Engineering/Domain.lean:174](#line-code-leanified-corereader-engineering-domain-lean-174) · definition + +核心依赖: none. + +```lean +abbrev CredibleDirection {Ground : Type} (grounds : List Ground) + (articulated : Ground → Bool) (supports : Ground → Change → Bool) + (d : Change) : Prop := +``` + +### `CoreReader.Engineering.credibilityCases` + +[leanified/CoreReader/Engineering/Domain.lean:212](#line-code-leanified-corereader-engineering-domain-lean-212) · case + +核心依赖: none. + +```lean +theorem credibilityCases : + credible initialGrounds .designRevision ∧ + credible [.knowledge "queue" [.designRevision] "tenant-config-reload"] .designRevision ∧ + credible [.history "queue" [.migration, .migration]] .migration ∧ + ¬ credible [] (.other "quantum backend") ∧ + credible forecastGrounds .deletion ∧ ¬ credible forecastGrounds .designRevision := by decide +``` + + + +## T27 · 可信性不等于无限预留 + +可信变化可支持选择性的预留,无须当前已有多个实现或最大化扩展;可想象性本身不提供这种支持。 + +**前提与表示:** 案例保留一个现有实现、某个有支持的具体方向及明确成本维度。 + +**证明或检查:** 可信计划案例在只有一个实现时仍成立。想象证据不满足支持条件。实际选择性设计及分开的成本坐标,不要求保留每种可能性或共同兑换率。 + +**限度:** 有限方向清单不证明所有未来变化可预测,也不证明遗漏可能性全都无关。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3) + +### `CoreReader.Engineering.credibilityLimits` + +[leanified/CoreReader/Engineering/Domain.lean:394](#line-code-leanified-corereader-engineering-domain-lean-394) · case + +核心依赖: `propext`. + +```lean +theorem credibilityLimits : + credible initialGrounds .designRevision ∧ implementedVariants.length = 1 ∧ + ¬ WarrantedAccommodation [] (.other "quantum backend") 0 5 ∧ + ¬ credible initialGrounds (.other "quantum backend") ∧ + EvolutionPriority currentContinuing .evolvable ∧ + abstractionComplexity .evolvable < abstractionComplexity .maximal ∧ + cost .evolvable .construction < cost .evolvable .migration ∧ + ¬ MaximumRegisteredCapability continuingActivity .evolvable ∧ + MaximumRegisteredCapability continuingActivity .maximal ∧ + (supportedDirections continuingActivity .evolvable).length = 9 ∧ + (supportedDirections continuingActivity .maximal).length = 10 ∧ + ¬ credible initialGrounds (.other "csv export") := by decide +``` + + + +## T28 · 具体成本与有根据的让步 + +让步须指出额外成本威胁哪个具体目标。模型允许七种不同负担,不将它们汇总为普遍分数。 + +**前提与表示:** ConcreteThreat 连接实际候选成本、较简单选项的比较成本及指定负担的容量;JustifiedDeparture 将记录的负担和目标连接到该威胁。 + +**证明或检查:** 分别降低理解、构建、诊断、验证、协调、运行及迁移的相关容量形成案例。任意记录的借口若没有真实容量威胁就不能成立。 + +**限度:** 有限成本是模型中的工作与预算数据。源文不要求每类成本都适用,也不提供普遍数值取舍。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3) + +### `CoreReader.Engineering.JustifiedDeparture` + +[leanified/CoreReader/Engineering/Domain.lean:298](#line-code-leanified-corereader-engineering-domain-lean-298) · definition + +核心依赖: none. + +```lean +abbrev JustifiedDeparture (ctx : Context) (c : Candidate) : Prop := +``` + +### `CoreReader.Engineering.costCases` + +[leanified/CoreReader/Engineering/Domain.lean:410](#line-code-leanified-corereader-engineering-domain-lean-410) · case + +核心依赖: `propext`. + +```lean +theorem costCases : + JustifiedDeparture (threatened .understanding) .evolvable ∧ + JustifiedDeparture (threatened .construction) .evolvable ∧ + JustifiedDeparture (threatened .diagnosis) .evolvable ∧ + JustifiedDeparture (threatened .verification) .evolvable ∧ + JustifiedDeparture (threatened .coordination) .evolvable ∧ + JustifiedDeparture (threatened .operation) .evolvable ∧ + JustifiedDeparture (threatened .migration) .evolvable ∧ + ¬ JustifiedDeparture { currentContinuing with departure := some .migration } .evolvable := by decide +``` + + + +## T29 · 演化种类与义务变化 + +演化包含添加、替换、删除、撤销抽象、重画边界和迁移;独立与协调变化具有不同路径及契约处理。 + +**前提与表示:** EvolutionClaim 将指定请求及维护者能力连接到相应契约说明、实际 contractRunner 步骤和指定观察的保持/修订处理。SoftwareState 变换是 evolutionKindsCases 的独立合取项,不是此谓词的字段。 + +**证明或检查:** 案例以独立合取项计算添加、替换、删除、撤销、边界及迁移状态变化;还检查继任者路径、替换请求的保持、重画边界的显式契约修订及独立/协调工作的差异。修订说明针对改变的可观察行为;状态变换合取项另行检查。 + +**限度:** 枚举构造子例示源文维度,并允许其他方向;它们不声称涵盖所有演化,也不声称每种变化廉价。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.evolution-meaning#p1](#source-software-engineering-evolution-meaning-p1), [software-engineering.evolution-meaning#p2](#source-software-engineering-evolution-meaning-p2) + +### `CoreReader.Engineering.EvolutionClaim` + +[leanified/CoreReader/Engineering/Domain.lean:556](#line-code-leanified-corereader-engineering-domain-lean-556) · definition + +核心依赖: none. + +```lean +abbrev EvolutionClaim (a : Activity) (c : Candidate) (claim : ChangeClaim) : Prop := +``` + +### `CoreReader.Engineering.evolutionKindsCases` + +[leanified/CoreReader/Engineering/Domain.lean:569](#line-code-leanified-corereader-engineering-domain-lean-569) · case + +核心依赖: `propext`. + +```lean +theorem evolutionKindsCases : + (transform .addition originalSoftware).capabilities = ["deduplicate", "tenant batching"] ∧ + (transform .replacement originalSoftware).implementation = 1 ∧ + (transform .deletion originalSoftware).mechanisms = ["queue"] ∧ + (transform .withdrawal originalSoftware).abstractions = [] ∧ + (transform .redrawing originalSoftware).boundary = 1 ∧ + (transform .migration originalSoftware).technology = "portable store" ∧ + changes.all (fun d => decide (CanChange continuingActivity .evolvable .successor d)) = true ∧ + EvolutionClaim continuingActivity .evolvable ⟨.replacement, .successor, .preserve⟩ ∧ + EvolutionClaim continuingActivity .evolvable ⟨.redrawing, .agent, .revise⟩ ∧ + changeWork .evolvable .independent < changeWork .evolvable .coordinated := by decide +``` + + + +## T30 · 一项演化优势不是所有优势 + +方案内易于添加,不蕴涵易于退出;设计修订有优势,也不蕴涵每个维度都有严格优势。 + +**前提与表示:** 工作量由同一设计、同一变化种类的实际编辑/验证路径计算。 + +**证明或检查:** 简单设计具有短添加路径和 17 单位撤销路径。可演化设计把修订从 17 降到 6,但两者添加均为 2;协调变化工作量可以高于独立变化。 + +**限度:** 这些反例排除无根据的跨维度推断,不新增所有变化都须廉价的义务。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.evolution-meaning#p1](#source-software-engineering-evolution-meaning-p1), [software-engineering.evolution-meaning#p2](#source-software-engineering-evolution-meaning-p2) + +### `CoreReader.Engineering.evolutionDimensionsLimits` + +[leanified/CoreReader/Engineering/Domain.lean:585](#line-code-leanified-corereader-engineering-domain-lean-585) · case + +核心依赖: `propext`. + +```lean +theorem evolutionDimensionsLimits : + changeWork .presentSimple .addition = 2 ∧ + changeWork .presentSimple .withdrawal = 17 ∧ + changeWork .evolvable .independent < changeWork .evolvable .coordinated ∧ + EvolutionPriority currentContinuing .evolvable ∧ + 9 < changeWork .evolvable .migration ∧ + CanChange continuingActivity .presentSimple .original .addition ∧ + CanChange continuingActivity .evolvable .original .addition ∧ + CanChange continuingActivity .presentSimple .original .designRevision ∧ + CanChange continuingActivity .evolvable .original .designRevision ∧ + changeWork .evolvable .designRevision < changeWork .presentSimple .designRevision ∧ + changeWork .evolvable .addition = changeWork .presentSimple .addition ∧ + (transform (.other "csv export") originalSoftware).capabilities = ["deduplicate", "csv export"] ∧ + CanChange continuingActivity .maximal .successor (.other "csv export") ∧ + ¬ CanChange continuingActivity .evolvable .successor (.other "csv export") := by +``` + + + +## T31 · 结构后果与跨边界义务 + +结构评估将预期变化连接到传播、实际可观察契约、知识及验证工作;边界标签本身不能建立跨边界义务已获处理。 + +**前提与表示:** StructuralAccount 将记录的受影响组件、观察及工作绑定到实际路径。边界案例具有调用方 2、被调用方 1 及明确的保序义务。 + +**证明或检查:** 协调变化修改被调用方 1,并在调用方 2 检查契约。删除调用方检查仍发生跨界,却不满足 boundaryObligationChecked;把被调用方改为未触及的 7 会改变适用性;排序输出则不满足同一可观察契约。 + +**限度:** 这些是相关的有限检查,不是普遍强制清单,也不是现实中所有边界成本的估算。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2) + +### `CoreReader.Engineering.StructuralAccount` + +[leanified/CoreReader/Engineering/Domain.lean:641](#line-code-leanified-corereader-engineering-domain-lean-641) · definition + +核心依赖: none. + +```lean +abbrev StructuralAccount (a : Activity) (c : Candidate) (e : StructuralEvidence) : Prop := +``` + +### `CoreReader.Engineering.structuralCases` + +[leanified/CoreReader/Engineering/Domain.lean:733](#line-code-leanified-corereader-engineering-domain-lean-733) · case + +核心依赖: `propext`. + +```lean +theorem structuralCases : + StructuralAccount continuingActivity .evolvable (structuralEvidence .evolvable .designRevision) ∧ + (propagation .presentSimple .designRevision).length = 3 ∧ + (propagation .evolvable .designRevision).length = 2 ∧ + (changePath .evolvable .coordinated).any (fun s => s.component == 2 && s.requires == .publicContract) = true ∧ + PreservesFinite orderedUnique orderedRefactor ∧ + (structuralEvidence .evolvable .designRevision).observedBefore ≠ + (structuralEvidence .evolvable .designRevision).observedAfter ∧ + staticBatch 21 10 = liveBatch 21 10 ∧ staticBatch 21 5 ≠ liveBatch 21 5 ∧ + changeWork .presentSimple .withdrawal = 17 ∧ + (crossesBoundary boundaryDesign .coordinated coordinatedBoundary = true ∧ + boundaryObligationChecked boundaryDesign .coordinated coordinatedBoundary = true ∧ + crossesBoundary omittedCallerCheck .coordinated coordinatedBoundary = true ∧ + boundaryObligationChecked omittedCallerCheck .coordinated coordinatedBoundary = false ∧ + crossesBoundary otherCalleeDesign .coordinated otherCalleeBoundary = false ∧ + boundaryObligationChecked { boundaryDesign with run := sortedUnique } +``` + + + +## T32 · 结构名称不能证明能力 + +相同签名、模块数量或原则名称可以掩盖不同行为或变更能力;引入真实边界不必降低变化工作量。 + +**前提与表示:** EngineeringDesign 包含实际行为、组件路径、边界及固定批处理假设;元数据单独保留。 + +**证明或检查:** 相同签名产生保序与排序两种输出。八个模块都需要调整批量。私人路径和文档化路径元数据相同,继任者能力却不同。新增边界迁移已有验证步骤,工作量仍为 17,且仍缺私人知识;另一个追加检查版本为 18。 + +**限度:** 等工作量案例通过实际路径变换保留步骤单位;这些单位是披露的模型度量,不是观测工程耗时。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2) + +### `CoreReader.Engineering.structureNotCapability` + +[leanified/CoreReader/Engineering/Domain.lean:793](#line-code-leanified-corereader-engineering-domain-lean-793) · case + +核心依赖: `propext`. + +```lean +theorem structureNotCapability : + (privateDesign.metadata.signature = sortedDesign.metadata.signature ∧ + privateDesign.run [2, 1, 2] = [2, 1] ∧ sortedDesign.run [2, 1, 2] ≠ [2, 1]) ∧ + (privateDesign.metadata.modules = privateDesign.components.length ∧ + privateDesign.batchAssumptions.length = 8 ∧ + (designModulesNeedingRevision privateDesign 5).length = 8) ∧ + (privateDesign.metadata.principle = "dependency inversion" ∧ + privateDesign.metadata = documentedDesign.metadata ∧ + ¬ DesignCanChange continuingActivity privateDesign .successor .designRevision ∧ + DesignCanChange continuingActivity documentedDesign .successor .designRevision) ∧ + (privateDesign.boundaries.length = 0 ∧ wrappedDesign.boundaries.length = 1 ∧ + wrappedDesign.components.length = 9 ∧ + wrappedDesign.boundaries = [⟨8, 0, "List Nat → List Nat"⟩] ∧ + wrappedDesign.run [2, 1, 2] = privateDesign.run [2, 1, 2] ∧ + designWork privateDesign .designRevision = 17 ∧ + designWork wrappedDesign .designRevision = 18 ∧ + ¬ designWork wrappedDesign .designRevision < designWork privateDesign .designRevision) ∧ + (sameWorkDesign.boundaries = [⟨8, 0, "List Nat → List Nat"⟩] ∧ + sameWorkDesign.components.length = 9 ∧ + sameWorkDesign.paths .designRevision ≠ privateDesign.paths .designRevision ∧ + sameWorkDesign.run [2, 1, 2] = privateDesign.run [2, 1, 2] ∧ + designWork sameWorkDesign .designRevision = designWork privateDesign .designRevision ∧ + designWork sameWorkDesign .designRevision = 17 ∧ + ¬ DesignCanChange continuingActivity sameWorkDesign .successor .designRevision) := by +``` + + + +## T33 · 契约保持与刻意修订 + +指定契约可以保持,也可以刻意修订。修订说明识别变化义务及受影响方,不能把行为变化悄然改称保持。 + +**前提与表示:** ObservableContract 包含顺序行为和重试限制。实际依赖决定哪些消费者/运行人员受到影响,报告不能自行将他们排除。 + +**证明或检查:** 保序重构通过。排序及重试限制变化需要修订说明。遗漏实际受影响的运行人员会失败;有限测试外退出的行为展示局部保持的限度。 + +**限度:** 模型不要求保留所有历史行为、使用特定测试程序,也未新增普遍通知义务。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3) + +### `CoreReader.Engineering.ContractChangeAccount` + +[leanified/CoreReader/Engineering/Domain.lean:549](#line-code-leanified-corereader-engineering-domain-lean-549) · definition + +核心依赖: none. + +```lean +abbrev ContractChangeAccount (old new : ObservableContract) (r : ContractRevision) : Prop := +``` + +### `CoreReader.Engineering.contractCases` + +[leanified/CoreReader/Engineering/Domain.lean:843](#line-code-leanified-corereader-engineering-domain-lean-843) · case + +核心依赖: none. + +```lean +theorem contractCases : + ContractChangeAccount originalContract refactoredContract normalRevision ∧ + ContractChangeAccount originalContract revisedContract normalRevision ∧ + ¬ ContractChangeAccount originalContract revisedContract { normalRevision with affected := [] } ∧ +``` + + + +## T34 · 契约保持定理 + +若所有指定范围内的观察相等,则指定契约保持;范围内观察改变会反驳同一契约的保持。 + +**前提与表示:** contractPreservation 接收范围内普遍相等的前提。有限顺序/重试案例是独立检查,不自动提供该普遍前提。 + +**证明或检查:** 定理将所给相等关系作为 PreservesOn 返回;changedObservationNotPreserved 将其应用到不同结果的输入。案例计算顺序变化、重试 3、受影响方及被排除输入 [99] 的差异。 + +**限度:** 有限测试集通过不是普遍相等证明;保持判断始终保留指定范围。 + +**状态:** accepted (theorem). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3) + +### `CoreReader.Engineering.contractPreservation` + +[leanified/CoreReader/Engineering/Domain.lean:822](#line-code-leanified-corereader-engineering-domain-lean-822) · theorem + +核心依赖: none. + +```lean +theorem contractPreservation {Input Output : Type} (scope : Input → Prop) + (old new : Input → Output) (observations : ∀ x, scope x → new x = old x) : + PreservesOn scope old new := observations +``` + +### `CoreReader.Engineering.contractDistinctions` + +[leanified/CoreReader/Engineering/Domain.lean:853](#line-code-leanified-corereader-engineering-domain-lean-853) · case + +核心依赖: none. + +```lean +theorem contractDistinctions : + PreservesFinite orderedUnique orderedRefactor ∧ + ¬ PreservesFinite orderedUnique sortedUnique ∧ + retry originalContract 3 = false ∧ retry revisedContract 3 = true ∧ + ¬ PreservesContractFinite originalContract revisedContract ∧ + affectedParties originalContract revisedContract = ["queue consumer", "queue operator"] ∧ + ¬ ContractChangeAccount originalContract revisedContract + { normalRevision with affected := ["queue consumer"] } ∧ +``` + + + +## T35 · 修订与保留历史证据 + +预测、维护者、成本或目标变化可支持改判;新记录须保留旧预测及其观测失败。 + +**前提与表示:** RevisionAccount 将修订与独立固定的 observedHistory 比较,包括软件身份、旧预测及实际观测结果;revisionFor 使用当前语境和所选实现。 MaterialGroundsChanged 是五项记录差异的析取,不证明任一差异单独足以充分支持新选择。 + +**证明或检查:** 同一旧/新状态对同时改变预测、维护、维护者、迁移成本和目标容量;定理列出这五项差异。同步篡改 old 与 recordedOld 不能改变独立历史。另有保留案例分别使用无支持的替代方向或有根据的迁移成本让步。 + +**限度:** 记录的历史是固定模型证据;定理不鉴定任意现实日志,也不证明所有批评回应均充分。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.revision#p2](#source-software-engineering-revision-p2), [software-engineering.revision#p1](#source-software-engineering-revision-p1) + +### `CoreReader.Engineering.RevisionAccount` + +[leanified/CoreReader/Engineering/Domain.lean:922](#line-code-leanified-corereader-engineering-domain-lean-922) · definition + +核心依赖: none. + +```lean +abbrev RevisionAccount (r : RevisionRecord) : Prop := RevisionAccountAgainst observedHistory r +``` + +### `CoreReader.Engineering.revisionCases` + +[leanified/CoreReader/Engineering/Domain.lean:951](#line-code-leanified-corereader-engineering-domain-lean-951) · case + +核心依赖: `propext`. + +```lean +theorem revisionCases : + RevisionAccount revisionRecord ∧ + revisionRecord.old.forecast ≠ revisionRecord.current.forecast ∧ + revisionRecord.old.maintenance ≠ revisionRecord.current.maintenance ∧ + revisionRecord.old.maintainers ≠ revisionRecord.current.maintainers ∧ + revisionRecord.old.migrationCost ≠ revisionRecord.current.migrationCost ∧ + revisionRecord.old.objectiveCapacity ≠ revisionRecord.current.objectiveCapacity ∧ + revisionRecord.predictedBatchCount ≠ revisionRecord.actualBatchCount ∧ + RetentionJustified currentContinuing [.other "quantum backend"] ∧ + RetentionJustified (threatened .migration) [.migration] := by decide +``` + + + +## T36 · 修订不能改写失败 + +新判断不能使旧失败预测变真。一致赞同和局部成功不建立普遍正确性;有理由的稳定仍然可能。 + +**前提与表示:** 旧静态预测及变化后的实际批处理结果独立于修订报告保持固定。 + +**证明或检查:** 21 项案例在批量 10 时相同,在批量 5 时不同;重贴标签不能修复该算术事实。稳定记录保留有效历史说明及批评方向覆盖,同时保持选择不变;指定无支持替代方向满足有界的保留判准。本案例不证明设计的实际可修订性。 + +**限度:** 结果允许有界的保留判断,不给予对后续根据或批评的永久豁免。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.revision#p2](#source-software-engineering-revision-p2), [software-engineering.revision#p1](#source-software-engineering-revision-p1) + +### `CoreReader.Engineering.revisionLimits` + +[leanified/CoreReader/Engineering/Domain.lean:993](#line-code-leanified-corereader-engineering-domain-lean-993) · case + +核心依赖: `propext`. + +```lean +theorem revisionLimits : + RevisionAccount revisionRecord ∧ + ¬ RevisionAccount { revisionRecord with reportedPredictionSucceeded := true } ∧ +``` + + + +## T37 · 优先原则仍接受自身评估 + +对同一采用者及适用语境,优先原则和实际评估方法仍受 Grounds、整体理论一致性及自反审查约束。 + +**前提与表示:** 定理保留完整 Inherited、DomainSatisfied、PriorityConditions 和无有根据让步的前提。它识别实际优先对象,并以 sharedContext 内的含义等价连接演化价值承诺与 EvolutionPriority。 + +**证明或检查:** 排除让步分支,保留自反责任,并给出 priorityGrounds 及领域内容在完整一致理论中的成员关系。自身预测和评估器修订案例保留实际反例。 + +**限度:** 成功自评既不证明优先原则普遍正确,也不建立普遍样本要求。空样本批评适用于声明的局部评估契约。 + +**状态:** accepted (theorem). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.revision#p2](#source-software-engineering-revision-p2) + +### `CoreReader.Engineering.priorityRemainsReflexive` + +[leanified/CoreReader/Engineering/Integration.lean:467](#line-code-leanified-corereader-engineering-integration-lean-467) · theorem + +核心依赖: `propext`, `Classical.choice`, `Quot.sound`. + +```lean +theorem priorityRemainsReflexive (ctx : Context) (chosen : Candidate) + (inherited : Inherited ctx chosen) (domain : DomainSatisfied ctx chosen) + (applicable : PriorityConditions ctx) (noDeparture : ¬ JustifiedDeparture ctx .evolvable) : + chosen = .evolvable ∧ + (.priority : ReviewObject) ∈ (selfModel chosen).objects ∧ + reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self + (selfModel chosen).performed ∧ + (∀ principle, valueSpecification (governancePosition principle)) ∧ + Grounds012 (EvolutionPriority ctx) canonicalArticulation + [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) ∧ + ownTheory chosen (ownNormClaim chosen .domain) ∧ + consistencySpecification (engineeringSnapshot .evolvable 0) + (engineeringSnapshot chosen 1) true := by +``` + +### `CoreReader.Engineering.priorityReflexiveCases` + +[leanified/CoreReader/Engineering/Integration.lean:493](#line-code-leanified-corereader-engineering-integration-lean-493) · case + +核心依赖: `propext`, `Classical.choice`, `Quot.sound`. + +```lean +theorem priorityReflexiveCases : + (.priority : ReviewObject) ∈ (selfModel .evolvable).objects ∧ + objectTest .priority (.evolvable, 10) = true ∧ + (selfModel .evolvable).performed ⟨0, 1⟩ ⟨0, .priority, .revision⟩ + ((selfModel .evolvable).input ⟨0, .priority, .revision⟩) + (.assessed .supportedWithinScope) ∧ + Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧ + objectTest .evolutionMethod (.evolvable, 10) = true ∧ + objectTest .evolutionMethod (.evolvable, 5) = false ∧ + Grounds012 (EvolutionPriority sharedContext) canonicalArticulation + [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) ∧ + Reflection.evaluate ((selfModel .evolvable).input ⟨0, .assessmentRule, .revision⟩) = .counterexample := by +``` + + + +## T38 · 全部已表示义务的共同见证 + +一个非空持续语境及其 evolvable 选择,同时满足已表示的完整继承和领域义务;优先确实适用,并接受额外当前复杂度。 + +**前提与表示:** 见证固定 sharedContext、各原评估任务及价值、完整事实/规范理论、继任者和代理路径、满足的需求、可信设计修订及无具体成本威胁。 + +**证明或检查:** inheritedCurrent 为 evolvable 构造每项继承字段;currentDomainSatisfied 提供领域义务。具体数值检查复杂度 3 对 1、工作量 6 对 17、非空自身对象及同一选项的可容许性。 + +**限度:** 这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +**状态:** accepted (satisfiability). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.charter.overview#p2](#source-organon-charter-overview-p2), [organon.charter.overview#p3](#source-organon-charter-overview-p3), [organon.charter.self-transcendence#p1](#source-organon-charter-self-transcendence-p1), [organon.charter.self-transcendence.orientation#p1](#source-organon-charter-self-transcendence-orientation-p1), [organon.charter.self-transcendence.non-finality#p1](#source-organon-charter-self-transcendence-non-finality-p1), [organon.charter.self-transcendence.limits#p1](#source-organon-charter-self-transcendence-limits-p1), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.charter.consistency#p1](#source-organon-charter-consistency-p1), [organon.charter.consistency.meaning#p1](#source-organon-charter-consistency-meaning-p1), [organon.charter.consistency.meaning#p2](#source-organon-charter-consistency-meaning-p2), [organon.charter.consistency.limits#p1](#source-organon-charter-consistency-limits-p1), [organon.charter.reflexivity#p1](#source-organon-charter-reflexivity-p1), [organon.charter.reflexivity.meaning#p1](#source-organon-charter-reflexivity-meaning-p1), [organon.charter.reflexivity.limits#p1](#source-organon-charter-reflexivity-limits-p1), [organon.grounds#p1](#source-organon-grounds-p1), [organon.grounds.assessment#p1](#source-organon-grounds-assessment-p1), [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3), [organon.grounds.scope#p1](#source-organon-grounds-scope-p1), [organon.grounds.scope#p2](#source-organon-grounds-scope-p2), [organon.grounds.scope#p3](#source-organon-grounds-scope-p3), [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2), [organon.grounds.implementations#p1](#source-organon-grounds-implementations-p1), [organon.grounds.implementations#p2](#source-organon-grounds-implementations-p2), [organon.grounds.implementations.limits#p1](#source-organon-grounds-implementations-limits-p1), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.purpose#p1](#source-software-engineering-purpose-p1), [software-engineering.purpose#p2](#source-software-engineering-purpose-p2), [software-engineering.purpose#p3](#source-software-engineering-purpose-p3), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3), [software-engineering.evolution-meaning#p1](#source-software-engineering-evolution-meaning-p1), [software-engineering.evolution-meaning#p2](#source-software-engineering-evolution-meaning-p2), [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2), [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3), [software-engineering.revision#p1](#source-software-engineering-revision-p1), [software-engineering.revision#p2](#source-software-engineering-revision-p2) + +### `CoreReader.Engineering.jointWitness` + +[leanified/CoreReader/Engineering/Integration.lean:557](#line-code-leanified-corereader-engineering-integration-lean-557) · case + +核心依赖: `propext`, `Classical.choice`, `Quot.sound`. + +```lean +theorem jointWitness : + ∃ ctx : Context, ∃ chosen : Candidate, + ctx = sharedContext ∧ chosen = .evolvable ∧ + Inherited ctx chosen ∧ DomainSatisfied ctx chosen ∧ + PriorityConditions ctx ∧ ¬ HasThreat ctx .evolvable ∧ + abstractionComplexity .presentSimple < abstractionComplexity chosen ∧ + CanChange ctx.activity chosen .successor .designRevision ∧ + CanChange ctx.activity chosen .agent .designRevision ∧ + ownTheory chosen (ownFactClaim chosen .selected) ∧ + (.commitment .grounds : ReviewObject) ∈ (selfModel chosen).objects ∧ + Admissible (ownTheory chosen) (comparisonContext chosen) chosen := by +``` + + + +## T39 · 继承义务不强制附加优先 + +在同一优先适用的持续语境内,presentSimple 选择满足每项已表示继承义务,却不采纳附加演化优先。 + +**前提与表示:** 两选项均满足必要要求;演化优势、可信设计修订、继任者/代理路径及复杂度取舍在模型内真实成立。没有临时生命周期或成本让步逃逸。 + +**证明或检查:** inheritedCurrent 为 presentSimple 构造完整继承义务。其实际采纳的简单性价值具有成本/工作理由及批评限度。领域规则要求 evolvable 或让步,而两者均被排除,因此 EvolutionPriority 为假。 + +**限度:** 反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3) + +### `CoreReader.Engineering.inheritedDoesNotEntailPriority` + +[leanified/CoreReader/Engineering/Integration.lean:586](#line-code-leanified-corereader-engineering-integration-lean-586) · case + +核心依赖: `propext`, `Classical.choice`, `Quot.sound`. + +```lean +theorem inheritedDoesNotEntailPriority : + ∃ ctx : Context, ∃ chosen : Candidate, + ctx = sharedContext ∧ chosen = .presentSimple ∧ + Inherited ctx chosen ∧ PriorityConditions ctx ∧ + Continuing ctx.activity ∧ ¬ BoundedLifecycle ctx.activity ∧ + ¬ HasThreat ctx .evolvable ∧ ¬ JustifiedDeparture ctx .evolvable ∧ + Meets ctx.required (ctx.profiles .presentSimple) ∧ + Meets ctx.required (ctx.profiles .evolvable) ∧ + credible ctx.evidence .designRevision ∧ + CanChange ctx.activity .evolvable .successor .designRevision ∧ + CanChange ctx.activity .evolvable .agent .designRevision ∧ + changeWork .evolvable .designRevision < changeWork chosen .designRevision ∧ + abstractionComplexity chosen < abstractionComplexity .evolvable ∧ + valueSpecification (selectionPosition chosen) ∧ + (selectionPosition chosen).commitment chosen ∧ + ¬ EvolutionPriority ctx chosen := by +``` + + + +## T40 · 形式证据不能建立什么 + +受检规范、条件证明及具体见证,仍与经验适切性、充分现实根据及哲学采纳有别。 + +**前提与表示:** 来源对应是单独记录的有界判断。成本、计划、历史、操作性理解及有限契约保留已披露的应用解释。 + +**证明或检查:** 本稿绑定实际源文、代码、类型和依赖对象,以及独立初稿与后续修复。先前失败或不完整对象不会被改称成功的历史执行。 + +**限度:** 构建成功、来源追溯、代理一致和自我适用不证明哲学正确性;没有为取得完成状态而删除冻结可证明目标或将其改为边界。 + +**状态:** accepted (boundary). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.preamble#p1](#source-organon-preamble-p1), [organon.preamble#p2](#source-organon-preamble-p2), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.grounds#p1](#source-organon-grounds-p1), [organon.grounds.assessment#p1](#source-organon-grounds-assessment-p1), [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3), [organon.grounds.scope#p2](#source-organon-grounds-scope-p2), [organon.grounds.scope#p3](#source-organon-grounds-scope-p3), [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2), [organon.grounds.implementations#p1](#source-organon-grounds-implementations-p1), [organon.grounds.implementations#p2](#source-organon-grounds-implementations-p2), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.purpose#p1](#source-software-engineering-purpose-p1), [software-engineering.purpose#p2](#source-software-engineering-purpose-p2), [software-engineering.purpose#p3](#source-software-engineering-purpose-p3), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3), [software-engineering.evolution-meaning#p1](#source-software-engineering-evolution-meaning-p1), [software-engineering.evolution-meaning#p2](#source-software-engineering-evolution-meaning-p2), [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2), [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3), [software-engineering.revision#p1](#source-software-engineering-revision-p1), [software-engineering.revision#p2](#source-software-engineering-revision-p2) + +此边界目标没有 Lean 声明。 + + +## 来源追溯附录 + + + + +### `organon.preamble#p1` + +```text +This is a statement of Software Engineering Organon’s adopted philosophy. It expresses commitments, not factual assertions about every system or a proof of universal correctness. +``` + +状态: **not_applicable**; Lean: not_checked; 来源保真: not_applicable. + +此段保留文献权威、解释角色或已说明边界,不分配形式证明。 + +相关目标: [T01](#t01), [T40](#t40). + + + + + + +### `organon.preamble#p2` + +```text +The quoted provisions, their meanings, and their conditions of application form the core. The charter and Grounds constrain one another; their grouping establishes neither a deductive hierarchy nor an order of priority. [Rationale](rationale/README.md) supplies arguments and cases without adding obligations to this core. Skills are revisable applications under the repository’s stated objectives and constraints, not part of the philosophical commitments themselves. +``` + +状态: **not_applicable**; Lean: not_checked; 来源保真: not_applicable. + +此段保留文献权威、解释角色或已说明边界,不分配形式证明。 + +相关目标: [T01](#t01), [T40](#t40). + + + + + + +### `organon.charter` + +```text + + +``` + +状态: **not_applicable**; Lean: not_checked; 来源保真: not_applicable. + +空标题只保留结构,不分配定理。 + + + + + + +### `organon.charter.overview#p1` + +```text +**Self-Transcendence · Internal Consistency · Reflexivity** +``` + +状态: **not_applicable**; Lean: not_checked; 来源保真: not_applicable. + +此段保留文献权威、解释角色或已说明边界,不分配形式证明。 + +相关目标: [T01](#t01). + + + + + + +### `organon.charter.overview#p2` + +```text +> A system is intrinsically oriented toward expanding what it can understand and construct. It brings itself and its principles within the scope of generation and assessment, with internal consistency constraining this process. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T02、T38 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T01](#t01), [T02](#t02), [T38](#t38). + + + + + + +### `organon.charter.overview#p3` + +```text +The overview connects three distinct requirements: self-transcendence establishes a generative orientation and refuses to treat existing forms as final, internal consistency constrains judgments held simultaneously, and reflexivity brings the system and its principles within the scope of their own generation and assessment. The provisions below specify the conditions for each. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T02、T38 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T01](#t01), [T02](#t02), [T38](#t38). + + + + + + +### `organon.charter.self-transcendence#p1` + +```text +> A system is intrinsically oriented toward expanding what it can understand and construct. It does not regard any existing form as the endpoint of generation. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T02、T38 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T02](#t02), [T38](#t38). + + + + + + +### `organon.charter.self-transcendence.orientation#p1` + +```text +A commitment to keeping generative possibilities open is distinct from valuing their expansion. A system has an intrinsic orientation when it regards that expansion as worth pursuing. Merely permitting change does not fully express this orientation. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T02、T03、T38 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。这些是具体不蕴涵结果及有限支持案例,不是学习或自主执行的经验预测。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T02](#t02), [T03](#t03), [T38](#t38). + + + + + + +### `organon.charter.self-transcendence.non-finality#p1` + +```text +Refusing to regard an existing form as an endpoint keeps it open to being surpassed. “Existing form” includes a system’s current organization, methods, and principles, not only its appearance or artifacts. These remain within the scope of possible change; their revisability does not guarantee actual progress. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T02、T03、T38 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。这些是具体不蕴涵结果及有限支持案例,不是学习或自主执行的经验预测。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T02](#t02), [T03](#t03), [T38](#t38). + + + + + + +### `organon.charter.self-transcendence.limits#p1` + +```text +Whether progress has actually occurred remains a separate judgment. Having the orientation does not guarantee progress. Progress cannot be established merely by an increase in the number of artifacts, levels of abstraction, or terms. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T03、T38 作受限对应。这些是具体不蕴涵结果及有限支持案例,不是学习或自主执行的经验预测。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T03](#t03), [T38](#t38). + + + + + + +### `organon.charter.self-transcendence.limits#p2` + +```text +- “Intrinsic orientation” expresses Organon’s philosophical commitment; it does not assert that all systems in fact develop autonomously. +- Self-transcendence does not imply independence from external experience, knowledge, or collaboration, nor does it guarantee autonomous execution or self-improvement. +- Refusing to regard an existing form as an endpoint does not require every action to produce change. Justified stability can coexist with a generative orientation. +- Whether transcendence expands what can be understood and constructed requires discernible grounds; a system’s own claim of generation does not establish actual achievement. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T02、T03、T38 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。这些是具体不蕴涵结果及有限支持案例,不是学习或自主执行的经验预测。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T02](#t02), [T03](#t03), [T38](#t38), [T40](#t40). + + + + + + +### `organon.charter.consistency#p1` + +```text +> The principles and judgments a system holds simultaneously, together with their implications, must not yield contradictory judgments on the same question under the same assumptions, meanings of terms, and scope of application. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T04、T05、T38 作受限对应。一般接口在空问题域中可能空泛成立;工程实例使用非空问题族和实际可容许选项。结果不要求与已撤回主张永久相容,也未识别所有可能掩盖修订的文字遗漏。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T04](#t04), [T05](#t05), [T38](#t38). + + + + + + +### `organon.charter.consistency.meaning#p1` + +```text +“Held simultaneously” specifies which principles, judgments, and implications must hold together. Revision may withdraw an earlier judgment; old and new principles need not remain compatible forever. When a change has occurred, that change cannot be represented as though it had not occurred. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T04、T05、T38 作受限对应。一般接口在空问题域中可能空泛成立;工程实例使用非空问题族和实际可容许选项。结果不要求与已撤回主张永久相容,也未识别所有可能掩盖修订的文字遗漏。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T04](#t04), [T05](#t05), [T38](#t38). + + + + + + +### `organon.charter.consistency.meaning#p2` + +```text +“The same assumptions, meanings of terms, and scope of application” specifies the basis for comparing judgments. Divergent judgments under different conditions do not automatically constitute contradictions. Nor can unacknowledged changes in assumptions, meanings, or scope be used to conceal an existing contradiction. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T04、T05、T06、T38 作受限对应。一般接口在空问题域中可能空泛成立;工程实例使用非空问题族和实际可容许选项。结果不要求与已撤回主张永久相容,也未识别所有可能掩盖修订的文字遗漏。一致性不是充分的经验或价值支持;反例只涉及已披露的数学表示。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T04](#t04), [T05](#t05), [T06](#t06), [T38](#t38). + + + + + + +### `organon.charter.consistency.limits#p1` + +```text +- Tension between different assessments or values does not directly constitute a contradiction. Revision or qualification is needed when they require incompatible conclusions under the same conditions. +- Internal consistency is not correctness or sufficiency. A set of principles may be internally consistent while relying on false assumptions or neglecting important questions. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T04、T05、T06、T38 作受限对应。一般接口在空问题域中可能空泛成立;工程实例使用非空问题族和实际可容许选项。结果不要求与已撤回主张永久相容,也未识别所有可能掩盖修订的文字遗漏。一致性不是充分的经验或价值支持;反例只涉及已披露的数学表示。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T04](#t04), [T05](#t05), [T06](#t06), [T38](#t38). + + + + + + +### `organon.charter.reflexivity#p1` + +```text +> A system’s principles of generation and assessment also apply to the system itself and to the formation, application, and revision of those principles. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T07、T38 作受限对应。一般输入谓词仍需解释;非空具体对象及实际记录建立模型内义务履行,不建立普遍自我证明。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T07](#t07), [T38](#t38). + + + + + + +### `organon.charter.reflexivity.meaning#p1` + +```text +Reflexivity encompasses both the system itself and its principles. Assessment concerns not only whether the system conforms to its principles, but also how those principles are formed, where they apply, and why they may need revision. The formation and revision of principles thus also become objects of generation and assessment. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T07、T38 作受限对应。一般输入谓词仍需解释;非空具体对象及实际记录建立模型内义务履行,不建立普遍自我证明。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T07](#t07), [T38](#t38). + + + + + + +### `organon.charter.reflexivity.limits#p1` + +```text +- Applying principles equally retains their conditions of application. When the relevant conditions hold, being the system itself is not a basis for exemption. Nor does the requirement of reflexivity establish that every principle can be applied to itself without examining its applicability. +- Self-application does not constitute self-proof. Subjecting a principle to its own assessment does not thereby establish its correctness. +- That a revision is produced by the system itself does not give it sufficient grounds. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T07、T08、T38 作受限对应。一般输入谓词仍需解释;非空具体对象及实际记录建立模型内义务履行,不建立普遍自我证明。此有限反模型不证明所有可能编码中的独立性;保持形式开放也不能替代实际自反工作。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T07](#t07), [T08](#t08), [T38](#t38). + + + + + + +### `organon.grounds#p1` + +```text +> The grounds of principles and judgments must be articulable and subject to assessment appropriate to the nature of the claim. The strength and scope of a claim must be proportionate to the support provided by its grounds. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T08、T09、T38 作受限对应。此有限反模型不证明所有可能编码中的独立性;保持形式开放也不能替代实际自反工作。这是已声明任务的充分有限适配,不是穷尽分类,也未导入 Core 0.1.3 的全方面覆盖。声明新任务不授权替换已固定任务。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T08](#t08), [T09](#t09), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.assessment#p1` + +```text +Articulation and assessment have distinct responsibilities. Articulability requires that concepts, assumptions, reasons, and limits can be identified. Assessment requires examining whether those grounds support the corresponding claim. Clearly expressed grounds are not thereby sufficiently established. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T09、T13、T38 作受限对应。这是已声明任务的充分有限适配,不是穷尽分类,也未导入 Core 0.1.3 的全方面覆盖。声明新任务不授权替换已固定任务。这些区分不要求把价值、经验证据和推论化为同一分数。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T09](#t09), [T13](#t13), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.assessment#p2` + +```text +| Type of claim | Responsibility of assessment | What cannot substitute for that responsibility | +| --- | --- | --- | +| Empirical claim | Examine observations, evidence, and performance, together with the conditions, scope, and uncertainty of their support for the claim. | Treating measurability or repeatability itself as proof of relevance, correctness, or value. | +| Inferential claim | Examine whether the conclusion is supported by the stated assumptions and inferential relations. | Treating the absence of conflict between a conclusion and its assumptions as sufficient to establish that the conclusion follows from them. | +| Value commitment | State the position taken, its reasons, limits of application, and consequences, and remain open to relevant criticism. | Presenting a commitment as an empirical fact or a necessary inference, or substituting self-assertion for reasons. | +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T09、T10、T11、T12、T13、T38 作受限对应。这是已声明任务的充分有限适配,不是穷尽分类,也未导入 Core 0.1.3 的全方面覆盖。声明新任务不授权替换已固定任务。重复性或可测性本身不建立相关性、正确性或价值;未观察结果不同不必违背有限支持。缺少支持不等于评估做错;与假设相容弱于从假设得到蕴涵。应用给出充分的价值评估构造,不是证明所有初始假设的普遍要求,也不证明某价值普遍最优。这些区分不要求把价值、经验证据和推论化为同一分数。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T09](#t09), [T10](#t10), [T11](#t11), [T12](#t12), [T13](#t13), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.assessment#p3` + +```text +Initial value commitments may be stated explicitly as commitments; they need not prove all their own starting assumptions. The strength and scope of a claim do not require conversion to a common numerical scale. Different types of claims specify their support and limits in accordance with their nature. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T09、T12、T13、T38 作受限对应。这是已声明任务的充分有限适配,不是穷尽分类,也未导入 Core 0.1.3 的全方面覆盖。声明新任务不授权替换已固定任务。应用给出充分的价值评估构造,不是证明所有初始假设的普遍要求,也不证明某价值普遍最优。这些区分不要求把价值、经验证据和推论化为同一分数。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T09](#t09), [T12](#t12), [T13](#t13), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.scope#p1` + +```text +Performance is discerned within particular relations, conditions, and scopes of observation. A boundary helps specify what a comparison concerns, but local examples do not automatically support unconditional universal conclusions. A judgment cannot establish that relevant differences do not exist merely because its chosen scope omits them. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T14、T15、T38 作受限对应。角色字符串非空本身不是充分解释;未使用的方法也不会因此成为必需。把某输入排除出比较,不是该处不存在相关差异的证据。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T14](#t14), [T15](#t15), [T38](#t38). + + + + + + +### `organon.grounds.scope#p2` + +```text +Measurement can make some differences comparable. Repeated assessment can help examine the stability of corresponding conclusions. Their roles, and the role of any assessment framework, must be explained relative to the claim and its context. Measurement, repeatability, and an assessment framework do not form a universally necessary chain on which all judgments must depend. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T14、T15、T38 作受限对应。角色字符串非空本身不是充分解释;未使用的方法也不会因此成为必需。把某输入排除出比较,不是该处不存在相关差异的证据。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T14](#t14), [T15](#t15), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.scope#p3` + +```text +An observation that has not been reproduced may still offer limited support, and random outcomes need not be identical on every occasion. The verifiability of observations, reproducibility of conditions, and stability of conclusions must be distinguished. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T14、T15、T38 作受限对应。角色字符串非空本身不是充分解释;未使用的方法也不会因此成为必需。把某输入排除出比较,不是该处不存在相关差异的证据。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T14](#t14), [T15](#t15), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.capabilities#p1` + +```text +Capability claims are subject to Grounds: the capability claimed, its conditions, and the support for it must be identifiable. The core does not prescribe uniform definitions of method mastery, method generation, or capability levels. Applications specify the capabilities they assess and may require understanding, explanation, or performance under relevant variations. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T16、T17、T38 作受限对应。这不是心理理解的普遍定义。精确身份是范围前提;履行支持责任的是实际契约证明,而非身份本身。外部评估者可以支持所选输出主张,而不建立被评系统如何理解自身生成过程。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T16](#t16), [T17](#t17), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.capabilities#p2` + +```text +Grounds for a capability claim may be supplied by an external assessor. Their articulability does not by itself require the assessed system to understand or explain its internal generation process. Evidence of reliable output must be assessed against the capability actually claimed; it does not automatically establish understanding of that process. Nor can the number of method documents, terms, tools, or artifacts alone establish a capability beyond what that evidence supports. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T16、T17、T38 作受限对应。这不是心理理解的普遍定义。精确身份是范围前提;履行支持责任的是实际契约证明,而非身份本身。外部评估者可以支持所选输出主张,而不建立被评系统如何理解自身生成过程。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T16](#t16), [T17](#t17), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.implementations#p1` + +```text +> The choice of an implementation must be supported by reasons connected to the objectives and values pursued and to the relevant constraints. Its name, conventional use, or established status alone does not provide sufficient grounds for giving it priority. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T18、T19、T38 作受限对应。这些是应用理由,不是普遍成本函数,也不要求惯用实现必须落选。没有结果断言所有实现等价、保证多个可行实现,或从章节位置推出选择承诺。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T18](#t18), [T19](#t19), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.implementations#p2` + +```text +This choice provision adds an additional evaluative commitment: name, conventional use, or established status alone is insufficient to establish priority. Grouping it under Grounds does not mean that it follows from the general requirement to assess reasons, or merely from the discernibility of performance. Conventions and existing arrangements may have practical significance, but that significance must be connected to the objectives and values pursued and to the relevant constraints. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T18、T19、T38 作受限对应。这些是应用理由,不是普遍成本函数,也不要求惯用实现必须落选。没有结果断言所有实现等价、保证多个可行实现,或从章节位置推出选择承诺。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T18](#t18), [T19](#t19), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.implementations.limits#p1` + +```text +- Openness does not make all implementations equivalent, nor does it guarantee multiple feasible implementations for the same objective. +- A method’s explanatory power, limits of application, simplicity, and explicit process requirements may all provide grounded reasons for assessment. They cannot be excluded merely because they concern methods internal to the implementation. +- Identical local performance does not establish overall equivalence. Relations, conditions, and the scope of comparison are constrained by the provisions of Grounds. +- Openness does not reject an implementation merely because it already exists or is conventionally used. Relevant reasons may still give it priority. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T15、T18、T19、T38 作受限对应。把某输入排除出比较,不是该处不存在相关差异的证据。这些是应用理由,不是普遍成本函数,也不要求惯用实现必须落选。没有结果断言所有实现等价、保证多个可行实现,或从章节位置推出选择承诺。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T15](#t15), [T18](#t18), [T19](#t19), [T38](#t38). + + + + + + +### `organon.relationships` + +```text + + +``` + +状态: **not_applicable**; Lean: not_checked; 来源保真: not_applicable. + +空标题只保留结构,不分配定理。 + + + + + + +### `organon.relationships.roles#p1` + +```text +The charter states the generative orientation, the consistency constraint, and reflexive application. Grounds specifies support requirements for judgments and includes an additional commitment concerning implementation choices. Both parts belong to the core and constrain one another. Their placement neither makes Grounds a deduction from the charter nor gives the charter priority over it. Each commitment needs its own reasons. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T08、T20、T38、T39 作受限对应。此有限反模型不证明所有可能编码中的独立性;保持形式开放也不能替代实际自反工作。字段提取不从单一原则推出所有义务。采纳标记是独立事实,不能替代规范内容。要求样本的批评属于应用判准,不是对观察的普遍要求。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。 + +相关目标: [T01](#t01), [T08](#t08), [T20](#t20), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `organon.relationships.roles#p2` + +```text +Internal Consistency concerns whether simultaneously held judgments can hold together; Grounds concerns whether and how far a claim is supported. A conclusion may fail to conflict with its assumptions without being supported by them. Self-Transcendence specifies a generative orientation and non-finality; neither establishes actual capability. Applications may supply objectives, values, and capability definitions; claims made under those objectives, values, and definitions remain subject to the relevant core provisions. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T03、T06、T11、T16、T20、T38、T39 作受限对应。这些是具体不蕴涵结果及有限支持案例,不是学习或自主执行的经验预测。一致性不是充分的经验或价值支持;反例只涉及已披露的数学表示。缺少支持不等于评估做错;与假设相容弱于从假设得到蕴涵。这不是心理理解的普遍定义。精确身份是范围前提;履行支持责任的是实际契约证明,而非身份本身。字段提取不从单一原则推出所有义务。采纳标记是独立事实,不能替代规范内容。要求样本的批评属于应用判准,不是对观察的普遍要求。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。 + +相关目标: [T03](#t03), [T06](#t06), [T11](#t11), [T16](#t16), [T20](#t20), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `organon.relationships.roles#p3` + +```text +Self-Transcendence does not substitute for Reflexivity: keeping existing forms open to being surpassed differs from applying relevant principles to the system and to their own formation, application, and revision. Reflexivity extends these requirements to the system and to the formation, application, and revision of its principles. The grounds and limits of the Grounds provisions must themselves be articulable. The system’s own capability claims remain subject to assessment, and this philosophy’s existing form cannot gain priority merely from its established status. Such mutual application provides no self-proof and does not remove conditions of application. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T07、T08、T16、T18、T20、T37、T38、T39 作受限对应。一般输入谓词仍需解释;非空具体对象及实际记录建立模型内义务履行,不建立普遍自我证明。此有限反模型不证明所有可能编码中的独立性;保持形式开放也不能替代实际自反工作。这不是心理理解的普遍定义。精确身份是范围前提;履行支持责任的是实际契约证明,而非身份本身。这些是应用理由,不是普遍成本函数,也不要求惯用实现必须落选。字段提取不从单一原则推出所有义务。采纳标记是独立事实,不能替代规范内容。要求样本的批评属于应用判准,不是对观察的普遍要求。成功自评既不证明优先原则普遍正确,也不建立普遍样本要求。空样本批评适用于声明的局部评估契约。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。 + +相关目标: [T07](#t07), [T08](#t08), [T16](#t16), [T18](#t18), [T20](#t20), [T37](#t37), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `organon.relationships.terms#p1` + +```text +| Term | Meaning in this philosophy | +| --- | --- | +| Existing form | The system’s current organization, methods, and principles, not only its appearance or artifacts. | +| Assessment | Examination of reasons, applicability, and observed performance; not limited to executable tests. | +``` + +状态: **incomplete**; Lean: passed; 来源保真: partial. + +来源与 T02 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。 + +相关目标: [T02](#t02), [T21](#t21). + + + + + + +### `extensions#p1` + +```text +This chapter adds a software engineering commitment and specifies its meaning and limits. It does not claim that this commitment follows from the Charter or Grounds. Those provisions remain adopted and constrain its application. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T37、T38、T39 作受限对应。成功自评既不证明优先原则普遍正确,也不建立普遍样本要求。空样本批评适用于声明的局部评估契约。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。 + +相关目标: [T01](#t01), [T37](#t37), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `software-engineering.purpose#p1` + +```text +Software engineering concerns the construction, operation, understanding, and revision of software within its relevant human and technical conditions. This philosophy guides decisions by people and agents; it does not attribute an intrinsic orientation to every software artifact. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T22、T23、T38 作受限对应。这些数量是有限模型数据,不是项目工期估算。处于范围内本身不证明每位参与者都能完成每种变化。结果涉及已表示路径;缺少某条文档化路径,不是所有维护方式均不可能的普遍定理。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T22](#t22), [T23](#t23), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.purpose#p2` + +```text +The evolution capability considered here belongs to the continuing engineering activity: maintainers, including successor maintainers and agents, working with software, tools, and available knowledge. Code that its original author can modify is not on that ground alone shown to support that continuing activity. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T22、T23、T38 作受限对应。这些数量是有限模型数据,不是项目工期估算。处于范围内本身不证明每位参与者都能完成每种变化。结果涉及已表示路径;缺少某条文档化路径,不是所有维护方式均不可能的普遍定理。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T22](#t22), [T23](#t23), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.purpose#p3` + +```text +Apply the following priority according to the software's credible lifecycle and maintenance expectations. A genuinely temporary script, bounded prototype, or retiring system may have little reason to support further evolution. Calling a continuing system temporary does not establish that condition. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T22、T23、T24、T38 作受限对应。这些数量是有限模型数据,不是项目工期估算。处于范围内本身不证明每位参与者都能完成每种变化。结果涉及已表示路径;缺少某条文档化路径,不是所有维护方式均不可能的普遍定理。这里表达并例示默认价值优先,不从 Core 演绎该优先,也不要求最大扩展性。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T22](#t22), [T23](#t23), [T24](#t24), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.evolution-priority#p1` + +```text +> When relevant behavioral, safety, performance, and other necessary requirements are satisfied, give priority to continuing maintainers' ability to make credible future changes, including changes to the design itself, over present abstraction simplicity. Accept additional present abstraction complexity for that purpose, while allowing this preference to yield when the added costs threaten concrete engineering objectives. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T24、T25、T38、T39 作受限对应。这里表达并例示默认价值优先,不从 Core 演绎该优先,也不要求最大扩展性。定理不从事实证明价值规则,也不建立所有看似复杂的设计均具有相关优势。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。 + +相关目标: [T24](#t24), [T25](#t25), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `software-engineering.evolution-priority#p2` + +```text +Credible directions of change have articulable grounds, such as a committed plan, relevant domain knowledge, or an applicable history of change. They need not already have multiple implementations. Their credibility remains open to revision; a conceivable change alone does not establish that it warrants accommodation now. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T24、T25、T26、T27、T38、T39 作受限对应。这里表达并例示默认价值优先,不从 Core 演绎该优先,也不要求最大扩展性。定理不从事实证明价值规则,也不建立所有看似复杂的设计均具有相关优势。证明检查模型中给定的证据内容,不建立任意现实计划的可信性或预测校准程度。有限方向清单不证明所有未来变化可预测,也不证明遗漏可能性全都无关。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。 + +相关目标: [T24](#t24), [T25](#t25), [T26](#t26), [T27](#t27), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `software-engineering.evolution-priority#p3` + +```text +This is a default priority, not an obligation to maximize extensibility or retain every possibility. Costs include relevant burdens of understanding, construction, diagnosis, verification, coordination, operation, and eventual migration. A departure from the priority identifies the objective threatened and why the costs matter. No universal numerical exchange rate between these considerations is prescribed. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T24、T25、T26、T27、T28、T38、T39 作受限对应。这里表达并例示默认价值优先,不从 Core 演绎该优先,也不要求最大扩展性。定理不从事实证明价值规则,也不建立所有看似复杂的设计均具有相关优势。证明检查模型中给定的证据内容,不建立任意现实计划的可信性或预测校准程度。有限方向清单不证明所有未来变化可预测,也不证明遗漏可能性全都无关。有限成本是模型中的工作与预算数据。源文不要求每类成本都适用,也不提供普遍数值取舍。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。 + +相关目标: [T24](#t24), [T25](#t25), [T26](#t26), [T27](#t27), [T28](#t28), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `software-engineering.evolution-meaning#p1` + +```text +Evolution includes adding capabilities, replacing implementations, deleting mechanisms, withdrawing abstractions, redrawing boundaries, and migrating away from an existing technology or model. Making additions within a fixed scheme does not establish equal ability to revise or leave that scheme. Not every such change can or should be made inexpensive. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T29、T30、T38 作受限对应。枚举构造子例示源文维度,并允许其他方向;它们不声称涵盖所有演化,也不声称每种变化廉价。这些反例排除无根据的跨维度推断,不新增所有变化都须廉价的义务。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T29](#t29), [T30](#t30), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.evolution-meaning#p2` + +```text +An evolution claim identifies the relevant changes and the maintainers' conditions. Independent changes, coordinated changes, preservation of existing obligations, and deliberate revision of those obligations can require different structures. A design's advantage on one dimension does not establish an advantage on every dimension. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T29、T30、T38 作受限对应。枚举构造子例示源文维度,并允许其他方向;它们不声称涵盖所有演化,也不声称每种变化廉价。这些反例排除无根据的跨维度推断,不新增所有变化都须廉价的义务。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T29](#t29), [T30](#t30), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.structural-judgment#p1` + +```text +Apply the preceding commitment to engineering consequences as a whole, including the relations among components, their observable contracts, and the work needed to understand and verify a change. An interface's shape, the number of modules or extension points, or the use of a named principle is not sufficient evidence of the claimed capability. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T31、T32、T37、T38 作受限对应。这些是相关的有限检查,不是普遍强制清单,也不是现实中所有边界成本的估算。等工作量案例通过实际路径变换保留步骤单位;这些单位是披露的模型度量,不是观测工程耗时。成功自评既不证明优先原则普遍正确,也不建立普遍样本要求。空样本批评适用于声明的局部评估契约。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T31](#t31), [T32](#t32), [T37](#t37), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.structural-judgment#p2` + +```text +The relevant comparison may examine how a change propagates, which knowledge and obligations cross a boundary, which assumptions become fixed, and what a later withdrawal would require. A proposed boundary needs support for the changes it is meant to accommodate; introducing it does not by itself show that those changes became easier. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T31、T32、T38 作受限对应。这些是相关的有限检查,不是普遍强制清单,也不是现实中所有边界成本的估算。等工作量案例通过实际路径变换保留步骤单位;这些单位是披露的模型度量,不是观测工程耗时。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T31](#t31), [T32](#t32), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.structural-judgment#p3` + +```text +Distinguish a transformation that preserves an identified observable contract from one that deliberately revises that contract. The latter needs a corresponding account of changed obligations and affected parties. This distinction does not require preserving every historical behavior or using a particular testing or migration procedure. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T33、T34、T38 作受限对应。模型不要求保留所有历史行为、使用特定测试程序,也未新增普遍通知义务。有限测试集通过不是普遍相等证明;保持判断始终保留指定范围。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T33](#t33), [T34](#t34), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.revision#p1` + +```text +Changed evidence about likely changes, maintenance conditions, costs, or objectives may justify revising a design or this priority's application. A revised judgment acknowledges material changes in its grounds; it does not make a failed prediction successful retrospectively. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T35、T36、T38 作受限对应。记录的历史是固定模型证据;定理不鉴定任意现实日志,也不证明所有批评回应均充分。结果允许有界的保留判断,不给予对后续根据或批评的永久豁免。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T35](#t35), [T36](#t36), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.revision#p2` + +```text +Retaining a design can be justified when the relevant alternatives have no supported contribution or impose costs that defeat the objective. Reflexivity also keeps this engineering commitment and the methods used to assess evolution within the scope of criticism and revision. Continued change, agreement, or successful examples do not establish its universal correctness. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T35、T36、T37、T38 作受限对应。记录的历史是固定模型证据;定理不鉴定任意现实日志,也不证明所有批评回应均充分。结果允许有界的保留判断,不给予对后续根据或批评的永久豁免。成功自评既不证明优先原则普遍正确,也不建立普遍样本要求。空样本批评适用于声明的局部评估契约。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T35](#t35), [T36](#t36), [T37](#t37), [T38](#t38), [T40](#t40). + + + +## 完整代码与逐行解释 + +每份文件保持经检查的完整内容。下列逐行解释为修订后的知情解释;初次盲稿及被拒绝的旧判定另行保留。 + + +### `leanified/CoreReader/Adopted.lean` + + +```lean +import CoreReader.Integration + +namespace CoreReader.Adopted +open CoreReader.Logic CoreReader.Agency CoreReader.Evidence CoreReader.Choice + +/- These are three explicit mathematical assessment tasks, not an exhaustive or +exclusive taxonomy of claim natures. A task fixes the original claim and support +context before any candidate assessment is proposed. Its identity must be retained +when comparing alternative assessments; taskOfFacet declares a new task and does +not authorize replacing a previously identified task. -/ +inductive AssessmentTask (W : Type) where + | empirical (records : List (Record W)) (scope claim uncertainty : Claim W) + | inferential (assumptions : Theory W) (claim : Claim W) + | value (position : ValuePosition W) + +def taskOfFacet {W : Type} : Facet W → AssessmentTask W + | .empirical records scope claim uncertainty => .empirical records scope claim uncertainty + | .inferential assumptions claim => .inferential assumptions claim + | .value position => .value position + +/- This is a content-based sufficient adapter for the declared task, not a +philosophical rule requiring one unique assessment form. The empirical task may +also be assessed inferentially from exactly its observation/scope premises; its +original uncertainty obligation is still checked. In particular, adding the +conclusion as a new premise cannot replace the original empirical grounds. +The finite adapter need not accept every semantically equivalent presentation. -/ +def NatureAppropriate {W : Type} : AssessmentTask W → Facet W → Prop + | .empirical records scope claim uncertainty, .empirical actualRecords actualScope conclusion actualUncertainty => + actualRecords = records ∧ actualScope = scope ∧ conclusion = claim ∧ actualUncertainty = uncertainty + | .empirical records scope claim uncertainty, .inferential assumptions conclusion => + assumptions = singleton (fun w => Compatible records w ∧ scope w) ∧ + conclusion = claim ∧ Supports records uncertainty + | .inferential assumptions claim, .inferential actualAssumptions conclusion => + actualAssumptions = assumptions ∧ conclusion = claim + | .value position, .value actualPosition => actualPosition = position + | _, _ => False + +theorem taskOfFacetAppropriate {W : Type} (f : Facet W) : NatureAppropriate (taskOfFacet f) f := by + cases f with + | empirical _ _ _ _ => exact ⟨rfl, rfl, rfl, rfl⟩ + | inferential _ _ => exact ⟨rfl, rfl⟩ + | value _ => rfl + +/- Core 0.1.2 requires appropriateness to the original claim task. Supplied facets +are an explicit assessment scope, without importing Core 0.1.3's all-applicable +coverage requirement. No claim-kind label or freely assigned success flag proves +appropriateness: NatureAppropriate compares the actual task and facet contents. -/ +/-- organon-map CoreReader.Adopted.Grounds012 +organon.grounds#p1 sha256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6 +organon.grounds.assessment#p1 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +-/ +def Grounds012 {W : Type} (claim : Claim W) + (articulations : Facet W → Articulation W) (facets : List (Facet W)) + (task : AssessmentTask W) : Prop := + facets ≠ [] ∧ ∀ facet ∈ facets, + facet.claim = claim ∧ Articulated (articulations facet) ∧ + FacetArticulated (articulations facet) facet ∧ FacetDischarged facet ∧ + NatureAppropriate task facet + +/- This helper proves the newly declared taskOfFacet f only. It supplies no +appropriateness proof for another, previously fixed task with the same claim. -/ +theorem grounds012Singleton {W : Type} (f : Facet W) (h : FacetDischarged f) : + Grounds012 f.claim canonicalArticulation [f] (taskOfFacet f) := by + refine ⟨by simp, ?_⟩ + intro facet hf + cases List.mem_singleton.mp hf + exact ⟨rfl, canonicalArticulated f h, canonicalFacetArticulated f, h, taskOfFacetAppropriate f⟩ + +/-- organon-map CoreReader.Adopted.generationSpecification +organon.charter.overview#p2 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c +organon.charter.overview#p3 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c +organon.charter.self-transcendence#p1 sha256 f4ca590e2ae15e3882f70c7b2bc46a8911c97cee547c8b137b5493fbf862c8c0 +organon.charter.self-transcendence.orientation#p1 sha256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf +organon.charter.self-transcendence.non-finality#p1 sha256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8 +organon.charter.self-transcendence.limits#p2 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d +organon.relationships.terms#p1 sha256 61cb7ce4f2920f1aa6771502b87a66536ae0504acccfebd9dd23bcc62756eddf +-/ +def generationSpecification (policy : Policy) : Prop := Generative policy + +/- All consequences use the whole currently held set. Historical reporting is +separate and does not require simultaneous compatibility with withdrawn claims. -/ +/-- organon-map CoreReader.Adopted.consistencySpecification +organon.charter.consistency#p1 sha256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42 +organon.charter.consistency.meaning#p1 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75 +-/ +def consistencySpecification {W Q : Type} (before after : Snapshot W Q) + (reported : Bool) : Prop := + Consistent after.held after.context ∧ TruthfulReport before after reported + +/- A method's actual input and interpretation are parameters, permitting domain +methods as well as the small arithmetic adapter. Key coherence prevents records +for another method from silently satisfying the duty. -/ +structure ReflexiveRule (T I O : Type) where + key : PrincipleKey + activity : Activity + applicable : T → Prop + input : T → I + meaning : I → O → Prop + +/-- organon-map CoreReader.Adopted.reflexivitySpecification +organon.charter.reflexivity#p1 sha256 13293b45c2fa89068c68ae7ef3c5df38f0efadb3ef3873d78a5ba67d9691a757 +organon.charter.reflexivity.meaning#p1 sha256 8a2caede01a43d8b6c60b54c78ac089c51868e9956f316948077ccee2e45c9cc +organon.charter.reflexivity.limits#p1 sha256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +def reflexivitySpecification {T I O : Type} (rules : List (ReflexiveRule T I O)) + (isSelf : T → Prop) (performed : PrincipleKey → T → I → O → Prop) : Prop := + (∀ p ∈ rules, ∀ q ∈ rules, p.key = q.key → p = q) ∧ + ∀ rule ∈ rules, ∀ target, isSelf target → rule.applicable target → + ∃ outcome, performed rule.key target (rule.input target) outcome ∧ + rule.meaning (rule.input target) outcome + +def legacyRule (p : Principle) : ReflexiveRule Subject Inquiry WorkOutcome := + ⟨p.key, p.activity, p.applicable, p.inquiry, + fun inquiry outcome => p.meaning inquiry (p.reasons inquiry.target) (p.limits inquiry.target) outcome⟩ + +def legacyPerformed (rules : List Principle) (records : List WorkRecord) + (key : PrincipleKey) (target : Subject) (input : Inquiry) (outcome : WorkOutcome) : Prop := + ∃ p ∈ rules, ∃ record ∈ records, + p.key = key ∧ ValidApplication rules p target record ∧ + record.inquiry = input ∧ record.outcome = outcome + +theorem legacyReflexivity (owner : Nat) (rules : List Principle) (records : List WorkRecord) + (h : Reflexive owner rules records) : + reflexivitySpecification (rules.map legacyRule) (fun s => s.owner = owner) + (legacyPerformed rules records) := by + constructor + · intro p hp q hq he + obtain ⟨a, ha, rfl⟩ := List.mem_map.mp hp + obtain ⟨b, hb, rfl⟩ := List.mem_map.mp hq + exact congrArg legacyRule (h.1 a ha b hb he) + · intro rule hr target ht happ + obtain ⟨p, hp, rfl⟩ := List.mem_map.mp hr + obtain ⟨record, hm, hv⟩ := h.2 p hp target ht happ + refine ⟨record.outcome, ⟨p, hp, record, hm, rfl, hv, hv.inquiryIdentity, rfl⟩, ?_⟩ + change p.meaning (p.inquiry target) (p.reasons (p.inquiry target).target) + (p.limits (p.inquiry target).target) record.outcome + have ti : (p.inquiry target).target = target := hv.inquiryIdentity ▸ hv.inquiryTarget + rw [ti] + rw [← hv.inquiryIdentity, ← hv.reasonsIdentity, ← hv.limitsIdentity] + exact hv.followsMeaning + +/- These are fulfillment interfaces for the named mathematical adapters, not +universal empirical adequacy claims or definitions of all possible claim kinds. -/ +/-- organon-map CoreReader.Adopted.empiricalSpecification +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +-/ +def empiricalSpecification {W : Type} (records : List (Record W)) + (scope claim uncertainty : Claim W) : Prop := + Grounds012 claim canonicalArticulation [.empirical records scope claim uncertainty] + (.empirical records scope claim uncertainty) + +/-- organon-map CoreReader.Adopted.inferentialSpecification +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +def inferentialSpecification {W : Type} (assumptions : Theory W) (claim : Claim W) : Prop := + Grounds012 claim canonicalArticulation [.inferential assumptions claim] (.inferential assumptions claim) + +/-- organon-map CoreReader.Adopted.valueSpecification +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +-/ +def valueSpecification {W : Type} (position : ValuePosition W) : Prop := + Grounds012 position.commitment canonicalArticulation [.value position] (.value position) + +/- Scope and roles are explicitly identified relative to a claim. An actually +used method needs an explanation; unused methods are not required. The input +relation can encode contextual relevance without a universal numeric scale. -/ +inductive AssessmentMethod | measurement | repetition | framework + deriving DecidableEq +structure ScopeAccount (W : Type) where + claim : Claim W + conditions : Claim W + observationScope : Claim W + relevant : W → W → Prop + compared : W → W → Prop + used : AssessmentMethod → Prop + role : AssessmentMethod → String + explains : AssessmentMethod → String → Claim W → Claim W → Prop + +/-- organon-map CoreReader.Adopted.scopeSpecification +organon.grounds.scope#p1 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.scope#p2 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.scope#p3 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +-/ +def scopeSpecification {W : Type} (account : ScopeAccount W) : Prop := + (∀ a b, account.compared a b → account.conditions a ∧ account.conditions b ∧ + account.observationScope a ∧ account.observationScope b ∧ account.relevant a b) ∧ + ∀ method, account.used method → account.role method ≠ "" ∧ + account.explains method (account.role method) account.claim account.conditions + +/- A capability is selected by the application as an exact object-scoped +contract; whether explanation is part of it remains an application choice. -/ +/-- organon-map CoreReader.Adopted.capabilitySpecification +organon.grounds.capabilities#p1 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0 +organon.grounds.capabilities#p2 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0 +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +def capabilitySpecification (assessed : Process) (contract : Claim Process) : Prop := + Grounds012 contract canonicalArticulation [processContractFacet assessed contract] + (.inferential (processScope assessed) contract) + +/-- organon-map CoreReader.Adopted.choiceSpecification +organon.grounds.implementations#p1 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c +organon.grounds.implementations#p2 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c +organon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870 +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +def choiceSpecification (requirements : Requirements) (implementation : Implementation) + (reasons : List Reason) : Prop := JustifiedChoice requirements implementation reasons + +/- A collaborator supplies the successor operation. Removing that resource +leaves the initial state; progress is tested on actual added operation content. -/ +def collaborativeRevision (resources : ExternalResources) : State := + if resources.collaborator.isSome then extendedState else baseState + +theorem collaborativeProgress : + generationSpecification openPolicy ∧ + Expanded baseState (collaborativeRevision availableResources) ∧ + ¬ Expanded baseState (collaborativeRevision { availableResources with collaborator := none }) ∧ + assistedExecution ⟨none, none, none⟩ = none := by + refine ⟨⟨Or.inl rfl, fun _ _ => trivial⟩, ?_, ?_, rfl⟩ + · exact Or.inr ⟨.successor, by simp [collaborativeRevision, availableResources, extendedState], + by simp [baseState]⟩ + · simp [collaborativeRevision, Expanded, baseState] + +/- A truth-preserving current slice need not retain an earlier incompatible +slice. Context changes and presentation order have separate semantics. -/ +/-- organon-map CoreReader.Adopted.consistencyConsequences +organon.charter.consistency#p1 sha256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42 +organon.charter.consistency.meaning#p1 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75 +-/ +theorem consistencyConsequences {W Q : Type} (t : Theory W) (c : Context W Q) (q : Q) + (positive : Consequence t c q true) (negative : Consequence t c q false) : + ¬ Consistent t c := conflictRequiresChange t c q positive negative + +def broadBoolContext : Context Bool Unit := ⟨emptyTheory, onQuestion, fun _ => True⟩ + +theorem sliceConsistency : + (∀ time, Consistent (revisionSlice time) broadBoolContext) ∧ + ¬ Consistent (union (revisionSlice 0) (revisionSlice 1)) broadBoolContext := by + constructor + · intro time + apply consequenceConsistency + exact ⟨time == 0, (modelsSingleton _ _).2 rfl, (by intro p hp; cases hp), trivial⟩ + · apply conflictRequiresChange _ _ () + · intro w h + change w = true + exact (modelsSingleton (fun w : Bool => w = true) w).1 ((modelsUnion _ _ _).1 h.1).1 + · intro w h ht + have hn := (modelsSingleton _ _).1 ((modelsUnion _ _ _).1 h.1).2 + cases ht.symm.trans hn + +theorem explicitlyConsistentLimits : + Consistent (singleton (fun w : Bool => w = true)) broadBoolContext ∧ + ¬ Models (singleton (fun w : Bool => w = true)) false ∧ + Consistent (emptyTheory : Theory Bool) broadBoolContext ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true) := by + refine ⟨?_, consistentFalse.2, ?_, consistentIncomplete.2.1⟩ + · exact consequenceConsistency _ _ ⟨true, (modelsSingleton _ _).2 rfl, + (by intro p hp; cases hp), trivial⟩ + · exact consequenceConsistency _ _ ⟨true, (by intro p hp; cases hp), + (by intro p hp; cases hp), trivial⟩ + +/- One observed input supports the local claim. The identical records cannot +support all inputs, nor the stronger claim that both Boolean outputs are true. -/ +def localFacet012 : Facet (Nat → Bool) := + .empirical [zeroRecord] (fun _ => True) (fun f => f 0 = true) (fun _ => True) +def globalFacet012 : Facet (Nat → Bool) := + .empirical [zeroRecord] (fun _ => True) allTrue (fun _ => True) +def strongFacet012 : Facet (Nat → Bool) := + .empirical [zeroRecord] (fun _ => True) (fun f => f 0 = true ∧ f 1 = true) (fun _ => True) + +theorem localFacetChecked012 : FacetDischarged localFacet012 := + ⟨⟨localGenerator 0, (zeroCompatible _).2 rfl, trivial⟩, + (fun f hf _ => (zeroCompatible f).1 hf), fun _ _ => trivial⟩ + +theorem scopeStrength012 : + Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧ + Articulated (canonicalArticulation globalFacet012) ∧ + ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧ + ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012) := by + refine ⟨grounds012Singleton _ localFacetChecked012, ⟨by simp [canonicalArticulation, globalFacet012], + by simp [canonicalArticulation, globalFacet012]⟩, ?_, ?_⟩ + · intro h + have checked := (h.2 globalFacet012 (by simp)).2.2.2.1 + have bad := checked.2.1 (localGenerator 0) ((zeroCompatible _).2 rfl) trivial 1 + cases bad + · intro h + have checked := (h.2 strongFacet012 (by simp)).2.2.2.1 + have bad := (checked.2.1 (localGenerator 0) ((zeroCompatible _).2 rfl) trivial).2 + cases bad + +/- A bounded outcome statement can leave another observable entirely unknown. +This represents uncertainty by a range of compatible worlds, not a probability. -/ +def uncertainFacet012 : Facet (Bool × Bool) := + .empirical [temperatureRecord, temperatureRecord] (fun _ => True) + (fun w => w.1 = true) (fun w => w.2 = true ∨ w.2 = false) + +theorem uncertainSupported012 : + empiricalSpecification [temperatureRecord, temperatureRecord] (fun _ => True) + (fun w => w.1 = true) (fun w => w.2 = true ∨ w.2 = false) ∧ + Compatible [temperatureRecord, temperatureRecord] (true,true) ∧ + Compatible [temperatureRecord, temperatureRecord] (true,false) := by + refine ⟨grounds012Singleton uncertainFacet012 ?_, temperatureCompatible true, temperatureCompatible false⟩ + refine ⟨⟨(true,false), temperatureCompatible false, trivial⟩, ?_, ?_⟩ + · intro w hw _; exact hw temperatureRecord (by simp) + · intro w _; cases w.2 <;> simp + +/- Correctly completed negative examination is distinct from a supported +conclusion. The countervaluation satisfies the same premises. -/ +def InferenceExamined {W : Type} (premises : Theory W) (conclusion : Claim W) + (accepted : Bool) : Prop := accepted = true ↔ Entails premises conclusion + +theorem inferenceChecked012 : + inferentialSpecification (singleton (fun n : Nat => n = 2)) (fun n => n + 1 = 3) ∧ + InferenceExamined (emptyTheory : Theory Bool) (fun w => w = true) false ∧ + Models (emptyTheory : Theory Bool) false ∧ ¬ ((fun w : Bool => w = true) false) := by + refine ⟨grounds012Singleton arithmeticFacet noUniversalChain.1, ?_, (by intro p hp; cases hp), by decide⟩ + constructor + · intro h; cases h + · intro h; exact False.elim (consistentIncomplete.2.1 h) + +/- Closing a response to an actually relevant criticism fails the value +procedure even when its budget/benefit reasons and joint adoption are unchanged. -/ +def closedPosition012 : ValuePosition Bool := { switchPosition with response := fun _ => none } + +theorem closedCriticism012 : ¬ ValueProcedure closedPosition012 := by + intro h + obtain ⟨answer, ha, _⟩ := h.2.2.2 false trivial rfl + cases ha + +theorem valueFulfilled012 : valueSpecification switchPosition := + grounds012Singleton _ switchValueProcedure + +/- Qualitative entailment orders claims by implication, without conversion of +value and empirical/inferential reasons to a common numeric scale. -/ +def ClaimNoStronger {W : Type} (weaker stronger : Claim W) : Prop := ∀ w, stronger w → weaker w + +theorem qualitativeProportionality012 : + ClaimNoStronger (fun f : Nat → Bool => f 0 = true) allTrue ∧ + ¬ ClaimNoStronger allTrue (fun f : Nat → Bool => f 0 = true) ∧ + valueSpecification switchPosition := by + refine ⟨fun _ h => h 0, ?_, valueFulfilled012⟩ + intro h + have bad := h (localGenerator 0) rfl 1 + cases bad + +def scopeRole012 : AssessmentMethod → String + | .measurement => "identify the output at the observed input zero" + | .repetition => "check the same local conclusion against repeated input-zero observations" + | .framework => "compare only the declared input; keep broader claims separate" + +def scopeRoleContent012 : AssessmentMethod → Prop + | .measurement => Supports [zeroRecord] (fun f => f 0 = true) + | .repetition => Supports [zeroRecord, zeroRecord] (fun f => f 0 = true) + | .framework => ¬ Supports [zeroRecord] allTrue + +def localScopeAccount012 : ScopeAccount Nat where + claim n := (localGenerator 0) n = true + conditions _ := True + observationScope n := n = 0 + relevant a b := a = b + compared a b := a = 0 ∧ b = 0 + used _ := True + role := scopeRole012 + explains method text claim conditions := + text = scopeRole012 method ∧ claim = (fun n => localGenerator 0 n = true) ∧ + conditions = (fun _ => True) ∧ scopeRoleContent012 method + +theorem scopeFulfilled012 : scopeSpecification localScopeAccount012 := by + constructor + · intro a b h + exact ⟨trivial, trivial, h.1, h.2, h.1.trans h.2.symm⟩ + · intro method _ + refine ⟨?_, rfl, rfl, rfl, ?_⟩ + · cases method <;> decide + · cases method with + | measurement => exact singleObservation.2.2.1 + | repetition => intro f hf; exact hf zeroRecord (by simp) + | framework => exact singleObservation.2.2.2 + +theorem capabilityFulfilled012 : + capabilitySpecification outputOnlyProcess OutputContract ∧ + capabilitySpecification explainedProcess FullProcessContract ∧ + (∃ certificate : ExternalCertificate outputOnlyProcess, + certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧ + ¬ ExplanationContract outputOnlyProcess := by + refine ⟨grounds012Singleton _ (processContractDischarged _ _ outputCorrectByEvaluation), + grounds012Singleton _ (processContractDischarged _ _ ?_), + ⟨externalOutputCertificate, externalOutputCertificate.distinctParticipants, + externalOutputCertificate.outputCorrect⟩, outputOnlyNoExplanation⟩ + exact ⟨fun _ => rfl, .doubleInput, rfl, fun _ => rfl⟩ + +/- This application asks the assessed object to predict a multiplier mechanism +at changed inputs and multiplier values. This is one operational understanding +criterion selected by an application, not a definition of psychological understanding. +The original output and explanation alone do not answer the additional questions. -/ +structure MechanismApplication012 where + process : Process + answer : Nat → Nat → Nat + +def mechanism012 (multiplier input : Nat) : Nat := multiplier * input + +def UnderstandingApplication012 (assessed : MechanismApplication012) : Prop := + FullProcessContract assessed.process ∧ + (∀ input, assessed.process.output input = mechanism012 2 input) ∧ + ∀ multiplier input, assessed.answer multiplier input = mechanism012 multiplier input + +def explainedWithoutVariation012 : MechanismApplication012 := + ⟨explainedProcess, fun _ input => input + input⟩ + +def mechanismResponder012 : MechanismApplication012 := + ⟨explainedProcess, mechanism012⟩ + +/- The assessment task is fixed by this very application object and the stronger +contract. Identity is a scope premise; the positive case still proves the contract. -/ +def understandingScope012 (assessed : MechanismApplication012) : Theory MechanismApplication012 := + singleton (fun candidate => candidate = assessed) + +def understandingTask012 (assessed : MechanismApplication012) : AssessmentTask MechanismApplication012 := + .inferential (understandingScope012 assessed) UnderstandingApplication012 + +def understandingFacet012 (assessed : MechanismApplication012) : Facet MechanismApplication012 := + .inferential (understandingScope012 assessed) UnderstandingApplication012 + +theorem mechanismResponderUnderstands012 : UnderstandingApplication012 mechanismResponder012 := by + refine ⟨⟨(fun _ => rfl), .doubleInput, rfl, (fun _ => rfl)⟩, ?_, fun _ _ => rfl⟩ + intro input + simp [mechanismResponder012, explainedProcess, mechanism012, Nat.two_mul] + +theorem explainedWithoutVariationFails012 : + ¬ UnderstandingApplication012 explainedWithoutVariation012 := by + intro h + have wrong := h.2.2 3 1 + change 2 = 3 at wrong + cases wrong + +theorem understandingApplicationCases012 : + explainedWithoutVariation012.process = mechanismResponder012.process ∧ + FullProcessContract explainedWithoutVariation012.process ∧ + ¬ UnderstandingApplication012 explainedWithoutVariation012 ∧ + UnderstandingApplication012 mechanismResponder012 ∧ + Grounds012 UnderstandingApplication012 canonicalArticulation + [understandingFacet012 mechanismResponder012] (understandingTask012 mechanismResponder012) ∧ + ¬ Grounds012 UnderstandingApplication012 canonicalArticulation + [understandingFacet012 explainedWithoutVariation012] (understandingTask012 explainedWithoutVariation012) := by + refine ⟨rfl, ⟨(fun _ => rfl), .doubleInput, rfl, (fun _ => rfl)⟩, + explainedWithoutVariationFails012, mechanismResponderUnderstands012, ?_, ?_⟩ + · apply grounds012Singleton + refine ⟨⟨mechanismResponder012, (modelsSingleton _ _).2 rfl⟩, ?_⟩ + intro candidate hc + have same := (modelsSingleton _ _).1 hc + subst candidate + exact mechanismResponderUnderstands012 + · intro h + have discharged := (h.2 (understandingFacet012 explainedWithoutVariation012) (by simp)).2.2.2.1 + exact explainedWithoutVariationFails012 + (discharged.2 explainedWithoutVariation012 ((modelsSingleton _ _).2 rfl)) + +/- The same exact application contract receives Grounds when its owner asserts +it; external certificates change who supplies reasons, not the asserted object. -/ +def OwnCapability012 (owner claimant : Nat) (process : Process) (contract : Claim Process) : Prop := + owner = claimant ∧ capabilitySpecification process contract + +theorem ownCapability012 : OwnCapability012 7 7 outputOnlyProcess OutputContract := + ⟨rfl, capabilityFulfilled012.1⟩ + +/- A complete represented Charter includes generation, whole-set consistency, +truthful revision reporting and applicable contentful self-work on the same +system. The world type is the finite Candidate × Mode type. -/ +def CompleteCharter012 (system : CoreReader.Integration.System) + (world : CoreReader.Integration.World) : Prop := + generationSpecification (system.policy world) ∧ + consistencySpecification + ⟨CoreReader.Integration.systemHeld system, CoreReader.Integration.systemContext system, 0⟩ + ⟨CoreReader.Integration.systemHeld system, CoreReader.Integration.systemContext system, 0⟩ false ∧ + reflexivitySpecification ((system.rules world).map legacyRule) (fun s => s.owner = system.owner) + (legacyPerformed (system.rules world) (system.work world)) ∧ + (system.policy world).current system.method.form ∧ + (system.policy world).current system.principleForm + +theorem completeCharter012 : CompleteCharter012 CoreReader.Integration.actualSystem CoreReader.Integration.actual := by + refine ⟨CoreReader.Integration.charterChecked.1, + ⟨CoreReader.Integration.jointConsistent, ?_⟩, + legacyReflexivity 0 _ _ (completeOwnWork_reflexive 0), rfl, rfl⟩ + rintro (h | h) + · exact False.elim (h ⟨fun _ => Iff.rfl, fun _ => Iff.rfl, fun _ _ => Iff.rfl, fun _ => Iff.rfl⟩) + · exact False.elim (h rfl) + +theorem charterWithoutGrounds012 : + CompleteCharter012 CoreReader.Integration.actualSystem CoreReader.Integration.actual ∧ + Admissible CoreReader.Integration.held CoreReader.Integration.context CoreReader.Integration.actual ∧ + Compatible [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.actual ∧ + Articulated (canonicalArticulation CoreReader.Integration.unsupportedCapabilityFacet) ∧ + ¬ Supports [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.capability ∧ + ¬ Grounds012 CoreReader.Integration.capability canonicalArticulation + [CoreReader.Integration.unsupportedCapabilityFacet] + (taskOfFacet CoreReader.Integration.unsupportedCapabilityFacet) := by + refine ⟨completeCharter012, CoreReader.Integration.actualAdmissible, + (by intro r hr; cases List.mem_singleton.mp hr; rfl), + ⟨by simp [canonicalArticulation, CoreReader.Integration.unsupportedCapabilityFacet], + by simp [canonicalArticulation, CoreReader.Integration.unsupportedCapabilityFacet]⟩, + CoreReader.Integration.costDoesNotSupportOutput, ?_⟩ + intro h + have checked := (h.2 CoreReader.Integration.unsupportedCapabilityFacet (by simp)).2.2.2.1 + exact CoreReader.Integration.costDoesNotSupportOutput (fun w hw => checked.2.1 w hw trivial) + +/- Permission to assert is evaluated on the same claim, articulation and facets. +The countercase derives inadequacy from the actual unobserved output. -/ +def groundsPermission012 {W : Type} (enabled : Bool) (claim : Claim W) + (a : Facet W → Articulation W) (facets : List (Facet W)) (task : AssessmentTask W) : Prop := + if enabled then Grounds012 claim a facets task else True + +def GroundsProvision012 (enabled : Bool) : Prop := + ∀ (claim : Claim (Nat → Bool)) a facets task, + groundsPermission012 enabled claim a facets task → Grounds012 claim a facets task + +theorem groundsProvision012Meaning (enabled : Bool) : GroundsProvision012 enabled ↔ enabled = true := by + cases enabled with + | true => exact ⟨fun _ => rfl, fun _ _ _ _ _ h => h⟩ + | false => + constructor + · intro h + exact False.elim (scopeStrength012.2.2.1 (h globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) trivial)) + · intro h; cases h + +/- The value rationale concerns this fixed empirical assertion task. The +same task, observed grounds and concrete counterworld are retained when the +permission policy is enabled or disabled. -/ +def groundsExperimentTask012 : AssessmentTask (Nat → Bool) := + .empirical [zeroRecord] (fun _ => True) allTrue (fun _ => True) + +noncomputable def groundsExperiment012 (enabled : Bool) : Bool := + @decide (groundsPermission012 enabled allTrue canonicalArticulation [globalFacet012] + groundsExperimentTask012) (Classical.propDecidable _) + +noncomputable def groundsPosition012 : ValuePosition Bool where + Position := Bool + Outcome := Bool + adopted := true + selected := id + outcome _ enabled := groundsExperiment012 enabled + objective accepted := accepted = false + constraints _ enabled := GroundsProvision012 enabled + starting := singleton (fun enabled => enabled = true) + reasons := [fun _ _ => Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0)] + limits _ := True + relevantCriticism _ := ¬ Supports [zeroRecord] allTrue + response _ := some "retain local support and reject the unsupported universal conclusion" + +theorem groundsPosition012Checked : ValueProcedure groundsPosition012 := by + refine ⟨by simp [groundsPosition012], ?_, ?_, ?_⟩ + · refine ⟨true, (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩ + intro reason hr + cases List.mem_singleton.mp hr + refine ⟨(zeroCompatible _).2 rfl, ?_⟩ + intro h; have bad := h 1; cases bad + · intro w _ _ reasons + have counterworld := reasons _ (List.mem_singleton.mpr rfl) + change Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0) at counterworld + have unsupported : ¬ Grounds012 allTrue canonicalArticulation [globalFacet012] groundsExperimentTask012 := by + intro h + have discharged := (h.2 globalFacet012 (by simp)).2.2.2.1 + exact counterworld.2 (discharged.2.1 (localGenerator 0) counterworld.1 trivial) + refine ⟨?_, (groundsProvision012Meaning true).2 rfl⟩ + exact @decide_eq_false (groundsPermission012 true allTrue canonicalArticulation [globalFacet012] + groundsExperimentTask012) (Classical.propDecidable _) unsupported + · intro w _ _; exact ⟨_, rfl, by decide⟩ + +theorem groundsRationaleExperiment012 : + Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0) ∧ + groundsExperiment012 true = false ∧ groundsExperiment012 false = true ∧ + groundsPosition012.outcome true true = groundsExperiment012 true ∧ + groundsPosition012.outcome true false = groundsExperiment012 false := by + refine ⟨(zeroCompatible _).2 rfl, ?_, ?_, ?_, rfl, rfl⟩ + · intro h; have bad := h 1; cases bad + · have actualReasons : ∀ reason ∈ groundsPosition012.reasons, reason true groundsPosition012.adopted := by + intro reason member + cases List.mem_singleton.mp member + refine ⟨(zeroCompatible _).2 rfl, ?_⟩ + intro h; have bad := h 1; cases bad + exact (groundsPosition012Checked.2.2.1 true ((modelsSingleton _ _).2 rfl) trivial actualReasons).1 + · exact @decide_eq_true (groundsPermission012 false allTrue canonicalArticulation [globalFacet012] + groundsExperimentTask012) (Classical.propDecidable _) trivial + +theorem groundsOnGrounds012 : + Grounds012 (fun enabled => GroundsProvision012 enabled) canonicalArticulation [.value groundsPosition012] (.value groundsPosition012) ∧ + groundsPosition012.limits true ∧ groundsPosition012.relevantCriticism true := by + have same : (Facet.value groundsPosition012).claim = (fun enabled => GroundsProvision012 enabled) := by + funext enabled + exact propext (groundsProvision012Meaning enabled).symm + refine ⟨?_, trivial, singleObservation.2.2.2⟩ + rw [← same] + exact grounds012Singleton _ groundsPosition012Checked + +theorem reflexiveTargets012 : + reflexivitySpecification ((ownRules 0).map legacyRule) (fun s => s.owner = 0) + (legacyPerformed (ownRules 0) (completeOwnWork 0)) ∧ + (∀ phase, Performed (completeOwnWork 0) (.process 0 0 phase) .assessment) ∧ + Performed (completeOwnWork 0) (.system 0) .assessment ∧ + reflexivitySpecification ([applicationRule].map legacyRule) (fun s => s.owner = 0) + (legacyPerformed [applicationRule] applicationWork) ∧ + ¬ Performed applicationWork (.system 0) .assessment := by + refine ⟨legacyReflexivity 0 _ _ (completeOwnWork_reflexive 0), ?_, + ownAssessmentPerformed 0 (.system 0) (by simp [ownSubjects]), + legacyReflexivity 0 _ _ applicationWork_reflexive, (applicabilityRetained 0 [] []).2.2.2⟩ + intro phase + apply ownAssessmentPerformed + cases phase <;> simp [ownSubjects] + +theorem achievementSupported012 : + Grounds012 transitionAchievement canonicalArticulation [transitionFacet] (taskOfFacet transitionFacet) ∧ + Compatible [transitionPerformanceRecord] .extend ∧ + transitionAchievement .extend ∧ ¬ transitionAchievement .inflate ∧ + ¬ Supports [transitionReportRecord] transitionAchievement := by + refine ⟨grounds012Singleton _ transitionFacetDischarged, ?_, ?_, ?_, transitionReportDoesNotSupport.2.2⟩ + · exact (transitionPerformanceCompatible .extend).mpr rfl + · simp [transitionAchievement, transitionBefore, transitionAfter, Expanded, baseState, extendedState] + · simp [transitionAchievement, transitionBefore, transitionAfter, Expanded, baseState, inflatedState] + +theorem semanticOrder012 : ∀ p q : Claim Bool, + ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r := + representationOrderIrrelevant + +def clearFalseArgument012 : Articulation Bool := + ⟨["the actual switch is on"], singleton (fun w => w = true), [fun w => w = true], fun _ => True⟩ + +theorem clearFalseReason012 : + Articulated clearFalseArgument012 ∧ ¬ Models clearFalseArgument012.assumptions false := + ⟨⟨by simp [clearFalseArgument012], by simp [clearFalseArgument012]⟩, consistentFalse.2⟩ + +def valueNeutralRecord012 : Record Bool := ⟨fun _ => true, true⟩ + +theorem valueNotFact012 : + valueSpecification switchPosition ∧ + Compatible [valueNeutralRecord012] false ∧ + ¬ Supports [valueNeutralRecord012] switchPosition.commitment ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment := by + have compatible : Compatible [valueNeutralRecord012] false := by + intro r hr; cases List.mem_singleton.mp hr; rfl + refine ⟨valueFulfilled012, compatible, ?_, valueWithoutSelfProof.2.2.1⟩ + intro h + have bad := h false compatible + cases bad + +def wrongExplanation012 : Implementation := { identityImpl with explanation := fun n => n + 1 } + +theorem internalReasonDistinguishes012 : + (∀ n, identityImpl.run n = wrongExplanation012.run n) ∧ + Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧ + Relevant identityRequirements identityImpl (.method .explanation) ∧ + ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation) := by + refine ⟨fun _ => rfl, identityFeasible, identityFeasible, internalReasons.1, ?_⟩ + intro h + have bad := h.2 0 trivial + cases bad + +theorem inventoryCases012 : ∀ kind : InventoryKind, + Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .copy ∧ + ¬ Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .successor := by + intro kind + simp [Available] + + +def selfExemptRule012 : ReflexiveRule Nat Nat Bool := + ⟨⟨0,1⟩, .assessment, fun _ => True, id, + fun input output => output = ownArithmeticPrinciple input⟩ +def selfExemptPerformed012 (key : PrincipleKey) (target input : Nat) (output : Bool) : Prop := + key = ⟨0,1⟩ ∧ target = 1 ∧ input = target ∧ output = ownArithmeticPrinciple input + +theorem openSelfExempt012 : + generationSpecification openPolicy ∧ openPolicy.revisable ⟨.principle,0⟩ ∧ + selfExemptPerformed012 ⟨0,1⟩ 1 1 true ∧ + selfExemptRule012.applicable 0 ∧ + ¬ reflexivitySpecification [selfExemptRule012] (fun target => target = 0) selfExemptPerformed012 := by + refine ⟨⟨Or.inl rfl, fun _ _ => trivial⟩, trivial, ⟨rfl,rfl,rfl,by decide⟩, trivial, ?_⟩ + intro h + obtain ⟨outcome, performed, _⟩ := h.2 selfExemptRule012 (by simp) 0 rfl trivial + cases performed.2.1 + +theorem ownPhilosophyStatus012 : + ¬ choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation + [.status .standing] ∧ + choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation + [.method .output] := + ⟨CoreReader.Integration.existingPhilosophyNotPrivileged.2.2.1, + CoreReader.Integration.existingPhilosophyNotPrivileged.2.2.2.1⟩ + +def jointContext012 : Context (Bool × Bool) Unit := + ⟨emptyTheory, fun _ w => w.2 = true, fun _ => True⟩ + +theorem jointImplicationConflict012 : + Consequence jointTheory jointContext012 () true ∧ + Consequence jointTheory jointContext012 () false ∧ + ¬ Consistent jointTheory jointContext012 := by + have positive : Consequence jointTheory jointContext012 () true := by + intro w hw + exact (hw.1 premiseRule (Or.inr (Or.inl rfl))) (hw.1 premiseP (Or.inl rfl)) + have negative : Consequence jointTheory jointContext012 () false := by + intro w hw + exact hw.1 premiseNotQ (Or.inr (Or.inr rfl)) + exact ⟨positive, negative, conflictRequiresChange _ _ () positive negative⟩ + +def tensionContext012 : Context Nat Unit := + ⟨emptyTheory, fun _ n => n ≤ 6, fun _ => True⟩ + +theorem tensionConsistent012 : + Consistent (union (singleton (fun n : Nat => 4 ≤ n)) (singleton (fun n => n ≤ 6))) tensionContext012 := by + apply consequenceConsistency + exact ⟨5, (modelsUnion _ _ _).2 ⟨(modelsSingleton _ _).2 (by decide), + (modelsSingleton _ _).2 (by decide)⟩, (by intro p hp; cases hp), trivial⟩ + +theorem qualitativeUnmeasured012 : + inferentialSpecification (singleton (fun on : Bool => on = true)) (fun on => on ≠ false) ∧ + usesObservation (Facet.inferential (singleton (fun on : Bool => on = true)) (fun on => on ≠ false)) = false := by + refine ⟨grounds012Singleton _ ⟨⟨true, (modelsSingleton _ _).2 rfl⟩, ?_⟩, rfl⟩ + intro on hon hf + have ht := (modelsSingleton (fun on : Bool => on = true) on).1 hon + cases ht.symm.trans hf + + +theorem allStatusOnly012 : ∀ kind : StatusKind, + ¬ choiceSpecification identityRequirements identityImpl [.status kind] := + statusOnlyFails identityRequirements identityImpl + +/- A finite two-draw experiment assigns positive equal weights to both possible +outcomes. It models possibility and a stable conclusion, not empirical claims +about any physical random-number source. -/ +def drawWeight012 (_draw : Bool) : Nat := 1 +def randomTrial012 (draw : Bool) : Trial := + ⟨0, if draw then 1 else 2, if draw then 1 else 2⟩ + +theorem randomOutcomes012 : + drawWeight012 true > 0 ∧ drawWeight012 false > 0 ∧ + drawWeight012 true = drawWeight012 false ∧ + Reproduced (randomTrial012 true) (randomTrial012 false) ∧ + (randomTrial012 true).actualOutcome ≠ (randomTrial012 false).actualOutcome ∧ + (∀ draw, Verified (randomTrial012 draw) ∧ Bounded (randomTrial012 draw)) := by + refine ⟨by decide, by decide, rfl, rfl, by decide, ?_⟩ + intro draw + cases draw <;> simp [Verified, Bounded, randomTrial012] + + +/- Original tasks are fixed independently of the candidate substitutions below. -/ +def originalGlobalTask012 : AssessmentTask (Nat → Bool) := + .empirical [zeroRecord] (fun _ => True) allTrue (fun _ => True) +def originalLocalTask012 : AssessmentTask (Nat → Bool) := + .empirical [zeroRecord] (fun _ => True) (fun f => f 0 = true) (fun _ => True) + +def circularGlobalFacet012 : Facet (Nat → Bool) := .inferential (singleton allTrue) allTrue + +theorem circularGlobalConditional012 : FacetDischarged circularGlobalFacet012 := by + refine ⟨⟨fun _ => true, (modelsSingleton _ _).2 (fun _ => rfl)⟩, ?_⟩ + intro f hf + exact (modelsSingleton _ _).1 hf + +theorem circularSubstitutionRejected012 : + Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] (taskOfFacet circularGlobalFacet012) ∧ + ¬ NatureAppropriate originalGlobalTask012 circularGlobalFacet012 ∧ + ¬ Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] originalGlobalTask012 := by + have inappropriate : ¬ NatureAppropriate originalGlobalTask012 circularGlobalFacet012 := by + intro h + have equalPremises := h.1 + have originalMember : singleton (fun f => Compatible [zeroRecord] f ∧ True) allTrue := equalPremises ▸ (show singleton allTrue allTrue from rfl) + have equalClaims : allTrue = (fun f => Compatible [zeroRecord] f ∧ True) := originalMember + have claimedAll := (congrFun equalClaims (localGenerator 0)).mpr ⟨(zeroCompatible _).2 rfl, trivial⟩ + have bad := claimedAll 1 + cases bad + refine ⟨grounds012Singleton _ circularGlobalConditional012, inappropriate, ?_⟩ + intro h + exact inappropriate (h.2 circularGlobalFacet012 (by simp)).2.2.2.2 + +def observedPremises012 : Theory (Nat → Bool) := singleton (fun f => Compatible [zeroRecord] f ∧ True) +def observedInferenceFacet012 : Facet (Nat → Bool) := + .inferential observedPremises012 (fun f => f 0 = true) + +theorem observedInferenceChecked012 : FacetDischarged observedInferenceFacet012 := by + refine ⟨⟨localGenerator 0, (modelsSingleton _ _).2 ⟨(zeroCompatible _).2 rfl, trivial⟩⟩, ?_⟩ + intro f hf + exact (zeroCompatible _).1 ((modelsSingleton _ _).1 hf).1 + +theorem sameEmpiricalTaskTwoMethods012 : + Grounds012 (fun f => f 0 = true) canonicalArticulation [localFacet012] originalLocalTask012 ∧ + Grounds012 (fun f => f 0 = true) canonicalArticulation [observedInferenceFacet012] originalLocalTask012 := by + refine ⟨grounds012Singleton _ localFacetChecked012, ?_⟩ + refine ⟨by simp, ?_⟩ + intro f hf + cases List.mem_singleton.mp hf + exact ⟨rfl, canonicalArticulated _ observedInferenceChecked012, + canonicalFacetArticulated _, observedInferenceChecked012, rfl, rfl, fun _ _ => trivial⟩ + +/- The second coordinate remains unobserved. Switching assessment form cannot +remove that uncertainty responsibility from the original empirical task. -/ +def originalUncertaintyTask012 : AssessmentTask (Bool × Bool) := + .empirical [temperatureRecord, temperatureRecord] (fun _ => True) + (fun w => w.1 = true) (fun w => w.2 = true) +def uncertaintyBypassFacet012 : Facet (Bool × Bool) := + .inferential (singleton (fun w => Compatible [temperatureRecord, temperatureRecord] w ∧ True)) + (fun w => w.1 = true) + +theorem uncertaintyBypassChecked012 : FacetDischarged uncertaintyBypassFacet012 := by + refine ⟨⟨(true,false), (modelsSingleton _ _).2 ⟨temperatureCompatible false, trivial⟩⟩, ?_⟩ + intro w hw + exact ((modelsSingleton _ _).1 hw).1 temperatureRecord (by simp) + +theorem uncertaintySubstitutionRejected012 : + FacetDischarged uncertaintyBypassFacet012 ∧ + ¬ NatureAppropriate originalUncertaintyTask012 uncertaintyBypassFacet012 ∧ + ¬ Grounds012 (fun w : Bool × Bool => w.1 = true) canonicalArticulation + [uncertaintyBypassFacet012] originalUncertaintyTask012 := by + have inappropriate : ¬ NatureAppropriate originalUncertaintyTask012 uncertaintyBypassFacet012 := by + intro h + have bad := h.2.2 (true,false) (temperatureCompatible false) + cases bad + exact ⟨uncertaintyBypassChecked012, inappropriate, + fun h => inappropriate (h.2 uncertaintyBypassFacet012 (by simp)).2.2.2.2⟩ + +def selectedFactFacet012 : Facet Bool := + .empirical [switchRecord] (fun _ => True) switchPosition.commitment (fun _ => True) + +theorem valueFactSubstitutionRejected012 : + FacetDischarged selectedFactFacet012 ∧ valueSpecification switchPosition ∧ + ¬ Grounds012 switchPosition.commitment canonicalArticulation [selectedFactFacet012] (.value switchPosition) := by + refine ⟨switchEmpiricalDischarged, valueFulfilled012, ?_⟩ + intro h + exact (h.2 selectedFactFacet012 (by simp)).2.2.2.2 + +theorem inferentialContextSubstitutionRejected012 : + FacetDischarged (Facet.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) ∧ + ¬ Grounds012 (fun w : Bool => w = true) canonicalArticulation + [.inferential (singleton (fun w => w = true)) (fun w => w = true)] + (.inferential emptyTheory (fun w => w = true)) := by + refine ⟨⟨⟨true, (modelsSingleton _ _).2 rfl⟩, fun w hw => (modelsSingleton (fun w : Bool => w = true) w).1 hw⟩, ?_⟩ + intro h + have appropriate := (h.2 (.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) (by simp)).2.2.2.2 + have same : singleton (fun w : Bool => w = true) = emptyTheory := appropriate.1 + have bad : emptyTheory (fun w : Bool => w = true) := same ▸ (show singleton (fun w : Bool => w = true) (fun w => w = true) from rfl) + exact bad + + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.generationCases +organon.charter.overview#p2 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c +organon.charter.overview#p3 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c +organon.charter.self-transcendence#p1 sha256 f4ca590e2ae15e3882f70c7b2bc46a8911c97cee547c8b137b5493fbf862c8c0 +organon.charter.self-transcendence.orientation#p1 sha256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf +organon.charter.self-transcendence.non-finality#p1 sha256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8 +organon.charter.self-transcendence.limits#p2 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d +organon.relationships.terms#p1 sha256 61cb7ce4f2920f1aa6771502b87a66536ae0504acccfebd9dd23bcc62756eddf +-/ +theorem generationCases : + (Generative openPolicy ∧ + (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧ + (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1)))) ∧ + (neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy) ∧ + (Generative generatingSystem.policy ∧ + generatingSystem.policy.permitsVersion 0 0 ∧ + ¬ Expanded generatingSystem.current inflatedState ∧ + generatingSystem.current.inventory.length < inflatedState.inventory.length ∧ + generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧ + generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧ + generatingSystem.execute availableResources = some 6 ∧ + generatingSystem.execute { availableResources with experience := none } = none ∧ + generatingSystem.execute { availableResources with knowledge := none } = none ∧ + generatingSystem.execute { availableResources with collaborator := none } = none ∧ + generatingSystem.execute ⟨none, none, none⟩ = none ∧ + ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧ + generatingSystem.stableAction = generatingSystem.current ∧ + generatingSystem.requirementsMet generatingSystem.stableAction ∧ + generatingSystem.withinBudget generatingSystem.stableAction ∧ + ¬ generatingSystem.withinBudget inflatedState ∧ + StableReason generatingSystem.current inflatedState ∧ + (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧ + inflatedAnnouncement.owner = generatingSystem.owner ∧ + inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧ + inflatedAnnouncement.reportedNewOperation = .successor ∧ + inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧ + ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after)) ∧ + (generationSpecification openPolicy ∧ + Expanded baseState (collaborativeRevision availableResources) ∧ + ¬ Expanded baseState (collaborativeRevision { availableResources with collaborator := none }) ∧ + assistedExecution ⟨none, none, none⟩ = none) := + ⟨revisionWithoutProgress, permissionNotValuation, generationLimits, collaborativeProgress⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.generationLimits012 +organon.charter.self-transcendence.orientation#p1 sha256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf +organon.charter.self-transcendence.non-finality#p1 sha256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8 +organon.charter.self-transcendence.limits#p1 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d +organon.charter.self-transcendence.limits#p2 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +theorem generationLimits012 : + (neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy) ∧ + (Generative openPolicy ∧ + (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧ + (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1)))) ∧ + (Generative generatingSystem.policy ∧ + generatingSystem.policy.permitsVersion 0 0 ∧ + ¬ Expanded generatingSystem.current inflatedState ∧ + generatingSystem.current.inventory.length < inflatedState.inventory.length ∧ + generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧ + generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧ + generatingSystem.execute availableResources = some 6 ∧ + generatingSystem.execute { availableResources with experience := none } = none ∧ + generatingSystem.execute { availableResources with knowledge := none } = none ∧ + generatingSystem.execute { availableResources with collaborator := none } = none ∧ + generatingSystem.execute ⟨none, none, none⟩ = none ∧ + ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧ + generatingSystem.stableAction = generatingSystem.current ∧ + generatingSystem.requirementsMet generatingSystem.stableAction ∧ + generatingSystem.withinBudget generatingSystem.stableAction ∧ + ¬ generatingSystem.withinBudget inflatedState ∧ + StableReason generatingSystem.current inflatedState ∧ + (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧ + inflatedAnnouncement.owner = generatingSystem.owner ∧ + inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧ + inflatedAnnouncement.reportedNewOperation = .successor ∧ + inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧ + ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after)) ∧ + (generationSpecification openPolicy ∧ + Expanded baseState (collaborativeRevision availableResources) ∧ + ¬ Expanded baseState (collaborativeRevision { availableResources with collaborator := none }) ∧ + assistedExecution ⟨none, none, none⟩ = none) ∧ + (Grounds012 transitionAchievement canonicalArticulation [transitionFacet] (taskOfFacet transitionFacet) ∧ + Compatible [transitionPerformanceRecord] .extend ∧ + transitionAchievement .extend ∧ ¬ transitionAchievement .inflate ∧ + ¬ Supports [transitionReportRecord] transitionAchievement) ∧ + (∀ kind : InventoryKind, + Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .copy ∧ + ¬ Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .successor) := + ⟨permissionNotValuation, revisionWithoutProgress, generationLimits, collaborativeProgress, achievementSupported012, inventoryCases012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.consistencyCases +organon.charter.consistency#p1 sha256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42 +organon.charter.consistency.meaning#p1 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75 +-/ +theorem consistencyCases : + (Satisfiable (singleton premiseP) ∧ Satisfiable (singleton premiseRule) ∧ + Satisfiable (singleton premiseNotQ) ∧ ¬ Satisfiable jointTheory) ∧ + ((Consequence emptyTheory (assumptionContext true) () true ∧ + Consequence emptyTheory (assumptionContext false) () false) ∧ + (Consequence emptyTheory (meaningContext true) () true ∧ + Consequence emptyTheory (meaningContext false) () false) ∧ + (Consequence emptyTheory (scopeContext true) () true ∧ + Consequence emptyTheory (scopeContext false) () false) ∧ + (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w)) ∧ + (¬ TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (meaningContext true)) (contextSnapshot (meaningContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (scopeContext true)) (contextSnapshot (scopeContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (scopeContext true) 0) (contextSnapshot (scopeContext true) 1) false ∧ + (TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) true ∧ + ¬ Models (assumptionContext false).assumptions true)) ∧ + (Satisfiable (revisionSlice 0) ∧ Satisfiable (revisionSlice 1) ∧ + ¬ Satisfiable (union (revisionSlice 0) (revisionSlice 1))) ∧ + ((∀ time, Consistent (revisionSlice time) broadBoolContext) ∧ + ¬ Consistent (union (revisionSlice 0) (revisionSlice 1)) broadBoolContext) ∧ + (∀ p q : Claim Bool, + ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r) ∧ + (Consequence jointTheory jointContext012 () true ∧ + Consequence jointTheory jointContext012 () false ∧ + ¬ Consistent jointTheory jointContext012) := + ⟨jointConflict, contextDifferences, hiddenContextChangeRejected, revisionCanReverse, sliceConsistency, semanticOrder012, jointImplicationConflict012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.consistencyLimits012 +organon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75 +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +theorem consistencyLimits012 : + ((Consequence emptyTheory (assumptionContext true) () true ∧ + Consequence emptyTheory (assumptionContext false) () false) ∧ + (Consequence emptyTheory (meaningContext true) () true ∧ + Consequence emptyTheory (meaningContext false) () false) ∧ + (Consequence emptyTheory (scopeContext true) () true ∧ + Consequence emptyTheory (scopeContext false) () false) ∧ + (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w)) ∧ + ((∃ budget : Nat, 4 ≤ budget ∧ budget ≤ 6) ∧ + ¬ ((fun n : Nat => 4 ≤ n) = (fun n : Nat => n ≤ 6))) ∧ + (Consistent (singleton (fun w : Bool => w = true)) broadBoolContext ∧ + ¬ Models (singleton (fun w : Bool => w = true)) false ∧ + Consistent (emptyTheory : Theory Bool) broadBoolContext ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧ + (Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧ + (Consistent (union (singleton (fun n : Nat => 4 ≤ n)) (singleton (fun n => n ≤ 6))) tensionContext012) := + ⟨contextDifferences, tensionWithoutContradiction, explicitlyConsistentLimits, compatibilityNotEntailment, tensionConsistent012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.reflexivityCases012 +organon.charter.reflexivity#p1 sha256 13293b45c2fa89068c68ae7ef3c5df38f0efadb3ef3873d78a5ba67d9691a757 +organon.charter.reflexivity.meaning#p1 sha256 8a2caede01a43d8b6c60b54c78ac089c51868e9956f316948077ccee2e45c9cc +organon.charter.reflexivity.limits#p1 sha256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +theorem reflexivityCases012 : + (reflexivitySpecification ((ownRules 0).map legacyRule) (fun s => s.owner = 0) + (legacyPerformed (ownRules 0) (completeOwnWork 0)) ∧ + (∀ phase, Performed (completeOwnWork 0) (.process 0 0 phase) .assessment) ∧ + Performed (completeOwnWork 0) (.system 0) .assessment ∧ + reflexivitySpecification ([applicationRule].map legacyRule) (fun s => s.owner = 0) + (legacyPerformed [applicationRule] applicationWork) ∧ + ¬ Performed applicationWork (.system 0) .assessment) ∧ + (Grounds012 (fun enabled => GroundsProvision012 enabled) canonicalArticulation [.value groundsPosition012] (.value groundsPosition012) ∧ + groundsPosition012.limits true ∧ groundsPosition012.relevantCriticism true) ∧ + (Compatible [zeroRecord] (localGenerator 0) ∧ ¬ allTrue (localGenerator 0) ∧ + groundsExperiment012 true = false ∧ groundsExperiment012 false = true ∧ + groundsPosition012.outcome true true = groundsExperiment012 true ∧ + groundsPosition012.outcome true false = groundsExperiment012 false) := + ⟨reflexiveTargets012, groundsOnGrounds012, groundsRationaleExperiment012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.reflexivityLimits012 +organon.charter.reflexivity.limits#p1 sha256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.grounds#p1 sha256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6 +-/ +theorem reflexivityLimits012 : + (selfTest [1] = true ∧ ownArithmeticPrinciple 0 = false ∧ + ¬ (∀ n, ownArithmeticPrinciple n = true)) ∧ + (localGenerator 0 0 = true ∧ localGenerator 0 1 = false ∧ + Compatible [zeroRecord] (localGenerator 0) ∧ + ¬ Supports [zeroRecord] allTrue ∧ OwnedRevisionExample) ∧ + (Generative openPolicy ∧ ¬ Reflexive 0 (ownRules 0) []) ∧ + (CompleteCharter012 CoreReader.Integration.actualSystem CoreReader.Integration.actual ∧ + Admissible CoreReader.Integration.held CoreReader.Integration.context CoreReader.Integration.actual ∧ + Compatible [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.actual ∧ + Articulated (canonicalArticulation CoreReader.Integration.unsupportedCapabilityFacet) ∧ + ¬ Supports [CoreReader.Integration.costAllowanceRecord] CoreReader.Integration.capability ∧ + ¬ Grounds012 CoreReader.Integration.capability canonicalArticulation + [CoreReader.Integration.unsupportedCapabilityFacet] + (taskOfFacet CoreReader.Integration.unsupportedCapabilityFacet)) ∧ + (generationSpecification openPolicy ∧ openPolicy.revisable ⟨.principle,0⟩ ∧ + selfExemptPerformed012 ⟨0,1⟩ 1 1 true ∧ + selfExemptRule012.applicable 0 ∧ + ¬ reflexivitySpecification [selfExemptRule012] (fun target => target = 0) selfExemptPerformed012) := + ⟨selfTestDoesNotProve, selfOriginDoesNotSupport, generationNotReflexivity, charterWithoutGrounds012, openSelfExempt012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.groundsCases012 +organon.grounds#p1 sha256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6 +organon.grounds.assessment#p1 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +-/ +theorem groundsCases012 : + (Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧ + Articulated (canonicalArticulation globalFacet012) ∧ + ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧ + ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012)) ∧ + (Articulated uninformativeArgument ∧ + ¬ Entails uninformativeArgument.assumptions (fun w : Bool => w = true)) ∧ + (Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] (taskOfFacet circularGlobalFacet012) ∧ + ¬ NatureAppropriate originalGlobalTask012 circularGlobalFacet012 ∧ + ¬ Grounds012 allTrue canonicalArticulation [circularGlobalFacet012] originalGlobalTask012) := + ⟨scopeStrength012, articulationNotSupport, circularSubstitutionRejected012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.empiricalCases012 +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +-/ +theorem empiricalCases012 : + (Grounds012 localFacet012.claim canonicalArticulation [localFacet012] (taskOfFacet localFacet012) ∧ + Articulated (canonicalArticulation globalFacet012) ∧ + ¬ Grounds012 globalFacet012.claim canonicalArticulation [globalFacet012] (taskOfFacet globalFacet012) ∧ + ¬ Grounds012 strongFacet012.claim canonicalArticulation [strongFacet012] (taskOfFacet strongFacet012)) ∧ + (temperatureRecord.test (true,false) = true ∧ + Compatible [temperatureRecord,temperatureRecord] (true,false) ∧ + Compatible [temperatureRecord,temperatureRecord] (true,true) ∧ + ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + Compatible [actionRecord,actionRecord] (true,0) ∧ + Compatible [actionRecord,actionRecord] (true,3) ∧ + ¬ Supports [actionRecord] announcementPosition.consequence ∧ + ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧ + ¬ ValueProcedure announcementPosition) ∧ + (empiricalSpecification [temperatureRecord, temperatureRecord] (fun _ => True) + (fun w => w.1 = true) (fun w => w.2 = true ∨ w.2 = false) ∧ + Compatible [temperatureRecord, temperatureRecord] (true,true) ∧ + Compatible [temperatureRecord, temperatureRecord] (true,false)) ∧ + (Grounds012 (fun f => f 0 = true) canonicalArticulation [localFacet012] originalLocalTask012 ∧ + Grounds012 (fun f => f 0 = true) canonicalArticulation [observedInferenceFacet012] originalLocalTask012) ∧ + (FacetDischarged uncertaintyBypassFacet012 ∧ + ¬ NatureAppropriate originalUncertaintyTask012 uncertaintyBypassFacet012 ∧ + ¬ Grounds012 (fun w : Bool × Bool => w.1 = true) canonicalArticulation + [uncertaintyBypassFacet012] originalUncertaintyTask012) := + ⟨scopeStrength012, measurementRepeatNotSupport, uncertainSupported012, sameEmpiricalTaskTwoMethods012, uncertaintySubstitutionRejected012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.inferentialCases012 +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +theorem inferentialCases012 : + (inferentialSpecification (singleton (fun n : Nat => n = 2)) (fun n => n + 1 = 3) ∧ + InferenceExamined (emptyTheory : Theory Bool) (fun w => w = true) false ∧ + Models (emptyTheory : Theory Bool) false ∧ ¬ ((fun w : Bool => w = true) false)) ∧ + (Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true)) ∧ + (FacetDischarged (Facet.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) ∧ + ¬ Grounds012 (fun w : Bool => w = true) canonicalArticulation + [.inferential (singleton (fun w => w = true)) (fun w => w = true)] + (.inferential emptyTheory (fun w => w = true))) := + ⟨inferenceChecked012, compatibilityNotEntailment, inferentialContextSubstitutionRejected012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.valueCases012 +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +-/ +theorem valueCases012 : + (valueSpecification switchPosition) ∧ + (announcementPosition.reasons ≠ [] ∧ announcementPosition.commitment (true,0) ∧ + (∀ reason, reason ∈ announcementPosition.reasons → reason (true,0) announcementPosition.adopted) ∧ + ¬ announcementPosition.consequence (true,0) ∧ ¬ ValueProcedure announcementPosition) ∧ + (¬ ValueProcedure closedPosition012) ∧ + (ValueProcedure switchPosition ∧ + Satisfiable switchPosition.starting ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧ + (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧ + (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition)) ∧ + (FacetDischarged selectedFactFacet012 ∧ valueSpecification switchPosition ∧ + ¬ Grounds012 switchPosition.commitment canonicalArticulation [selectedFactFacet012] (.value switchPosition)) := + ⟨valueFulfilled012, announcementNotBudgetReason, closedCriticism012, valueWithoutSelfProof, valueFactSubstitutionRejected012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.groundsLimits012 +organon.grounds.assessment#p1 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +-/ +theorem groundsLimits012 : + (Articulated clearFalseArgument012 ∧ ¬ Models clearFalseArgument012.assumptions false) ∧ + (temperatureRecord.test (true,false) = true ∧ + Compatible [temperatureRecord,temperatureRecord] (true,false) ∧ + Compatible [temperatureRecord,temperatureRecord] (true,true) ∧ + ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + Compatible [actionRecord,actionRecord] (true,0) ∧ + Compatible [actionRecord,actionRecord] (true,3) ∧ + ¬ Supports [actionRecord] announcementPosition.consequence ∧ + ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧ + ¬ ValueProcedure announcementPosition) ∧ + (valueSpecification switchPosition ∧ + Compatible [valueNeutralRecord012] false ∧ + ¬ Supports [valueNeutralRecord012] switchPosition.commitment ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment) ∧ + (ValueProcedure switchPosition ∧ + Satisfiable switchPosition.starting ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧ + (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧ + (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition)) ∧ + (ClaimNoStronger (fun f : Nat → Bool => f 0 = true) allTrue ∧ + ¬ ClaimNoStronger allTrue (fun f : Nat → Bool => f 0 = true) ∧ + valueSpecification switchPosition) := + ⟨clearFalseReason012, measurementRepeatNotSupport, valueNotFact012, valueWithoutSelfProof, qualitativeProportionality012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.scopeCases012 +organon.grounds.scope#p1 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.scope#p2 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.scope#p3 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +-/ +theorem scopeCases012 : + (scopeSpecification localScopeAccount012) ∧ + ((∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧ + (fun _ : Nat => true) 1 ≠ localGenerator 0 1) := + ⟨scopeFulfilled012, hiddenDifference⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.scopeLimits012 +organon.grounds.scope#p1 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.scope#p2 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.scope#p3 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870 +-/ +theorem scopeLimits012 : + ((∃ outside : Nat, outside ≠ 0) ∧ + Compatible [zeroRecord] (fun _ => true) ∧ + Compatible [zeroRecord] (localGenerator 0) ∧ + allTrue (fun _ => true) ∧ ¬ allTrue (localGenerator 0) ∧ + ¬ Supports [zeroRecord] allTrue) ∧ + ((∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧ + (fun _ : Nat => true) 1 ≠ localGenerator 0 1) ∧ + ([zeroRecord].length = 1 ∧ + (∃ f, Compatible [zeroRecord] f) ∧ + Supports [zeroRecord] (fun f => f 0 = true) ∧ + ¬ Supports [zeroRecord] allTrue) ∧ + (let a : Trial := ⟨0,1,1⟩ + let b : Trial := ⟨0,2,2⟩ + Reproduced a b ∧ a.actualOutcome ≠ b.actualOutcome ∧ Bounded a ∧ Bounded b) ∧ + ((Verified ⟨0,1,1⟩ ∧ Verified ⟨1,1,1⟩ ∧ ¬ Reproduced ⟨0,1,1⟩ ⟨1,1,1⟩) ∧ + (Reproduced ⟨0,1,1⟩ ⟨0,3,2⟩ ∧ ¬ Verified ⟨0,3,2⟩ ∧ ¬ Bounded ⟨0,3,2⟩) ∧ + (Bounded ⟨0,1,1⟩ ∧ Bounded ⟨0,2,0⟩ ∧ ¬ Verified ⟨0,2,0⟩)) ∧ + (FacetDischarged arithmeticFacet ∧ usesObservation arithmeticFacet = false) ∧ + (inferentialSpecification (singleton (fun on : Bool => on = true)) (fun on => on ≠ false) ∧ + usesObservation (Facet.inferential (singleton (fun on : Bool => on = true)) (fun on => on ≠ false)) = false) ∧ + (drawWeight012 true > 0 ∧ drawWeight012 false > 0 ∧ + drawWeight012 true = drawWeight012 false ∧ + Reproduced (randomTrial012 true) (randomTrial012 false) ∧ + (randomTrial012 true).actualOutcome ≠ (randomTrial012 false).actualOutcome ∧ + (∀ draw, Verified (randomTrial012 draw) ∧ Bounded (randomTrial012 draw))) := + ⟨localNotUniversal, hiddenDifference, singleObservation, variableOutcomesStableBound, verificationReproductionStability, noUniversalChain, qualitativeUnmeasured012, randomOutcomes012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.capabilityCases012 +organon.grounds.capabilities#p1 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0 +organon.grounds.capabilities#p2 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0 +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +theorem capabilityCases012 : + (capabilitySpecification outputOnlyProcess OutputContract ∧ + capabilitySpecification explainedProcess FullProcessContract ∧ + (∃ certificate : ExternalCertificate outputOnlyProcess, + certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧ + ¬ ExplanationContract outputOnlyProcess) ∧ + (OwnCapability012 7 7 outputOnlyProcess OutputContract) ∧ + (explainedWithoutVariation012.process = mechanismResponder012.process ∧ + FullProcessContract explainedWithoutVariation012.process ∧ + ¬ UnderstandingApplication012 explainedWithoutVariation012 ∧ + UnderstandingApplication012 mechanismResponder012 ∧ + Grounds012 UnderstandingApplication012 canonicalArticulation + [understandingFacet012 mechanismResponder012] (understandingTask012 mechanismResponder012) ∧ + ¬ Grounds012 UnderstandingApplication012 canonicalArticulation + [understandingFacet012 explainedWithoutVariation012] (understandingTask012 explainedWithoutVariation012)) := + ⟨capabilityFulfilled012, ownCapability012, understandingApplicationCases012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.capabilityLimits012 +organon.grounds.capabilities#p1 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0 +organon.grounds.capabilities#p2 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0 +-/ +theorem capabilityLimits012 : + (capabilitySpecification outputOnlyProcess OutputContract ∧ + capabilitySpecification explainedProcess FullProcessContract ∧ + (∃ certificate : ExternalCertificate outputOnlyProcess, + certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧ + ¬ ExplanationContract outputOnlyProcess) ∧ + (∀ kind : InventoryKind, + Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .copy ∧ + ¬ Available [⟨kind, .copy⟩, ⟨kind, .copy⟩] .successor) ∧ + (Generative generatingSystem.policy ∧ + generatingSystem.policy.permitsVersion 0 0 ∧ + ¬ Expanded generatingSystem.current inflatedState ∧ + generatingSystem.current.inventory.length < inflatedState.inventory.length ∧ + generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧ + generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧ + generatingSystem.execute availableResources = some 6 ∧ + generatingSystem.execute { availableResources with experience := none } = none ∧ + generatingSystem.execute { availableResources with knowledge := none } = none ∧ + generatingSystem.execute { availableResources with collaborator := none } = none ∧ + generatingSystem.execute ⟨none, none, none⟩ = none ∧ + ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧ + generatingSystem.stableAction = generatingSystem.current ∧ + generatingSystem.requirementsMet generatingSystem.stableAction ∧ + generatingSystem.withinBudget generatingSystem.stableAction ∧ + ¬ generatingSystem.withinBudget inflatedState ∧ + StableReason generatingSystem.current inflatedState ∧ + (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧ + inflatedAnnouncement.owner = generatingSystem.owner ∧ + inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧ + inflatedAnnouncement.reportedNewOperation = .successor ∧ + inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧ + ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after)) := + ⟨capabilityFulfilled012, inventoryCases012, generationLimits⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.choiceCases012 +organon.grounds.implementations#p1 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c +organon.grounds.implementations#p2 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c +organon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870 +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +theorem choiceCases012 : + (identityImpl.conventional = true ∧ identityImpl.established = true ∧ + JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output]) ∧ + (Relevant identityRequirements identityImpl (.method .explanation) ∧ + Relevant identityRequirements identityImpl (.method .applicability) ∧ + Relevant identityRequirements identityImpl (.method .simplicity) ∧ + Relevant identityRequirements identityImpl (.method .procedure) ∧ + (Relevant identityRequirements cheapSuccessor (.method .simplicity) ∧ + ¬ JustifiedChoice identityRequirements cheapSuccessor [.method .simplicity])) ∧ + (Articulated priorityArticulation ∧ AssessmentAccurate false ∧ + (∀ selected, Models statusFacts selected) ∧ + priorityClaim .identity ∧ ¬ priorityClaim .successor ∧ + ¬ Entails statusFacts priorityClaim ∧ + ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧ + ((∀ n, identityImpl.run n = wrongExplanation012.run n) ∧ + Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧ + Relevant identityRequirements identityImpl (.method .explanation) ∧ + ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation)) ∧ + (¬ choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation + [.status .standing] ∧ + choiceSpecification CoreReader.Integration.proposalRequirements + (CoreReader.Integration.currentPhilosophy CoreReader.Integration.actualSystem CoreReader.Integration.actual).implementation + [.method .output]) ∧ + (∀ kind : StatusKind, + ¬ choiceSpecification identityRequirements identityImpl [.status kind]) := + ⟨conventionWithReason, internalReasons, statusAssessmentNonEntailment, internalReasonDistinguishes012, ownPhilosophyStatus012, allStatusOnly012⟩ + +/- The bundle preserves the full checked propositions of its named component cases. -/ +/-- organon-map CoreReader.Adopted.choiceLimits012 +organon.grounds.implementations#p1 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c +organon.grounds.implementations#p2 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c +organon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870 +-/ +theorem choiceLimits012 : + ((∀ candidate, Feasible identityRequirements (implementation candidate) ↔ candidate = .identity) ∧ + JustifiedChoice identityRequirements identityImpl objectiveReason) ∧ + (identityImpl.conventional = true ∧ identityImpl.established = true ∧ + JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output]) ∧ + ((∀ n, identityImpl.run n = wrongExplanation012.run n) ∧ + Feasible identityRequirements identityImpl ∧ Feasible identityRequirements wrongExplanation012 ∧ + Relevant identityRequirements identityImpl (.method .explanation) ∧ + ¬ Relevant identityRequirements wrongExplanation012 (.method .explanation)) ∧ + (JustifiedChoice identityRequirements identityImpl objectiveReason ∧ + identityImpl.run 0 ≠ successorImpl.run 0) ∧ + ((∀ x, x = 0 → identityImpl.run x = changedOutsideZero.run x) ∧ + identityImpl.run 1 ≠ changedOutsideZero.run 1) ∧ + ((Articulated priorityArticulation ∧ AssessmentAccurate false ∧ + (∀ selected, Models statusFacts selected) ∧ + priorityClaim .identity ∧ ¬ priorityClaim .successor ∧ + ¬ Entails statusFacts priorityClaim ∧ + ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧ + PolicyIndependenceExample) := + ⟨singleFeasible, conventionWithReason, internalReasonDistinguishes012, openNotEquivalent, localNotGlobal, generalGroundsNotChoice⟩ + +end CoreReader.Adopted +``` + + + + **L1** 通过 Integration 导入已检查的 Logic、Evidence、Choice 和 Agency 示例。 + + + **L3** 把后续声明置于 CoreReader.Adopted 命名空间。 + + + **L4** 允许省略四个辅助命名空间的前缀。 + + + **L6** 注释把表示范围限定为三种明确的数学任务形式。 + + + **L7** 这些形式不是穷尽或排他的分类;必须固定原主张及其支持。 + + + **L8** 支持上下文在提出候选评估之前固定。 + + + **L9** 替代评估必须保持任务身份;taskOfFacet 则声明一个新任务。 + + + **L10** 声明新任务不等于有权替换既有任务。 + + + **L11** 在任意世界类型 W 上定义任务数据;构造数据不证明任务履行。 + + + **L12** 经验任务保存原记录、范围、主张和不确定性谓词。 + + + **L13** 推论任务保存原假设及结论。 + + + **L14** 价值任务保存完整立场,包括理由、限制及后果。 + + + **L16** 把一个评估方面转换为它自身声明的新评估任务。 + + + **L17** 把经验方面的全部字段复制到新声明的任务。 + + + **L18** 复制推论的假设及结论,不增添支持。 + + + **L19** 在新任务中保留完整价值立场。 + + + **L21** 说明针对已声明任务、基于内容的充分适配。 + + + **L22** 这一有限适配不构成哲学上必须采用唯一评估形式的要求。 + + + **L23** 经验任务可使用严格基于原观察及范围前提的推论。 + + + **L24** 改变评估形式仍须保留原不确定性责任。 + + + **L25** 假定所需结论不能替代原经验依据。 + + + **L26** 有限适配不保证接受每一种等价表述。 + + + **L27** 把适宜性定义为独立固定的任务与候选评估方面之间的关系。 + + + **L28** 比较原经验任务与候选经验评估。 + + + **L29** 要求记录、范围、结论及不确定性内容逐项相等。 + + + **L30** 处理为同一个原经验任务提出的推论评估。 + + + **L31** 要求其假设恰为与原记录相容并满足原范围。 + + + **L32** 保留原结论,并要求原记录支持原不确定性谓词。 + + + **L33** 比较原推论任务与候选推论评估。 + + + **L34** 要求假设及结论相同,不允许新增把结论当假设的前提。 + + + **L35** 价值任务要求整个立场相等,而不只是所选选项相同。 + + + **L36** 在这一已披露的有限适配中拒绝其他任务与方面的组合。 + + + **L38** 证明方面符合由它自身新声明的任务;不涉及另一原任务。 + + + **L39** 按三个方面构造器分情况证明。 + + + **L40** 经验分支给出四项内容的自反相等。 + + + **L41** 推论分支给出假设及结论的自反相等。 + + + **L42** 价值分支使用完整立场的自反相等。 + + + **L44** 说明所采用 Core 0.1.2 下的任务需要适宜的评估。 + + + **L45** 给定方面列表是明确表示的评估范围。 + + + **L46** 不引入 Core 0.1.3 全部适用方面覆盖规则或自证有效的种类标签。 + + + **L47** 适宜性取决于任务及方面的实际内容。 + + + **L48** 开始 CoreReader.Adopted.Grounds012 的来源追溯元数据;映射不是证明前提。 + + + **L49** 记录来源条款 organon.grounds#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L50** 记录来源条款 organon.grounds.assessment#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L51** 记录来源条款 organon.grounds.assessment#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L52** 记录来源条款 organon.grounds.assessment#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L53** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L54** 针对 W 上的明确主张定义 Grounds012。 + + + **L55** 以实际陈述函数和候选方面列表为参数。 + + + **L56** 另把独立固定的原任务列为显式参数。 + + + **L57** 要求列表非空,并检查列表中的每个方面。 + + + **L58** 把每个方面绑定到同一主张,并要求其陈述可识别。 + + + **L59** 要求陈述匹配该方面的内容,并要求完成所表示的评估。 + + + **L60** 还要求适宜于原任务;仅结论相同并不足够。 + + + **L62** 该辅助结果只涉及新声明的 taskOfFacet f。 + + + **L63** 它不能证明评估适宜于另一个结论相同的既有任务。 + + + **L64** 假定给定方面 f 已完成评估;辅助结果并不证明这一前提。 + + + **L65** 推出典范陈述及该方面自身新声明任务下的 Grounds。 + + + **L66** 证明单元素列表非空,留下对列表方面的全称责任。 + + + **L67** 引入任意列出方面及其成员证明。 + + + **L68** 单元素成员关系把该方面等同于 f。 + + + **L69** 组合主张身份、典范陈述、已假定的完成证明 h 及任务内容身份。 + + + **L71** 开始 CoreReader.Adopted.generationSpecification 的来源追溯元数据;映射不是证明前提。 + + + **L72** 记录来源条款 organon.charter.overview#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L73** 记录来源条款 organon.charter.overview#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L74** 记录来源条款 organon.charter.self-transcendence#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L75** 记录来源条款 organon.charter.self-transcendence.orientation#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L76** 记录来源条款 organon.charter.self-transcendence.non-finality#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L77** 记录来源条款 organon.charter.self-transcendence.limits#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L78** 记录来源条款 organon.relationships.terms#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L79** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L80** 生成责任的满足意味着重视扩展并使每个当前形式保持可修订。 + + + **L82** 一致性注释涉及整套当前持有主张的共同后果。 + + + **L83** 报告历史变化与同时保留已撤回主张是不同要求。 + + + **L84** 开始 CoreReader.Adopted.consistencySpecification 的来源追溯元数据;映射不是证明前提。 + + + **L85** 记录来源条款 organon.charter.consistency#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L86** 记录来源条款 organon.charter.consistency.meaning#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L87** 记录来源条款 organon.charter.consistency.meaning#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L88** 记录来源条款 organon.charter.consistency.limits#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L89** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L90** 针对世界及问题上的前后快照定义一致性和报告责任。 + + + **L91** 布尔报告记录是否承认发生变化。 + + + **L92** 要求当前整套理论一致,并要求前后变化报告真实。 + + + **L94** 反身规则注释允许领域专属的输入及解释类型。 + + + **L95** 规则键必须一致地标识同一个方法。 + + + **L96** 另一方法的工作不能暗中履行本规则的责任。 + + + **L97** 封装针对目标 T、输入 I 和结果 O 的反身规则。 + + + **L98** 保存规则的所有者及局部原则身份。 + + + **L99** 保存规则涉及生成还是评估。 + + + **L100** 保存规则对各目标适用的条件。 + + + **L101** 指定每个目标对应的实际输入。 + + + **L102** 指定每个输入下哪些结果符合方法含义。 + + + **L104** 开始 CoreReader.Adopted.reflexivitySpecification 的来源追溯元数据;映射不是证明前提。 + + + **L105** 记录来源条款 organon.charter.reflexivity#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L106** 记录来源条款 organon.charter.reflexivity.meaning#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L107** 记录来源条款 organon.charter.reflexivity.limits#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L108** 记录来源条款 organon.relationships.roles#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L109** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L110** 在给定通用反身规则列表上定义责任。 + + + **L111** 提供自身目标判定,以及由键、目标、输入、结果索引的实际执行关系。 + + + **L112** 登记规则中的相同键必须标识相同完整规则。 + + + **L113** 对每条规则及自身目标保留该规则的实际适用条件。 + + + **L114** 要求有在恰好该目标及规定输入上实际执行的结果。 + + + **L115** 要求同一结果满足该规则的含义关系。 + + + **L117** 把已有具体原则适配为通用反身接口。 + + + **L118** 保留其键、活动、适用条件和询问函数。 + + + **L119** 使用该询问实际目标对应的理由及限制判断其含义。 + + + **L121** 在现有规则及记录上定义具体工作关系。 + + + **L122** 标识所要求的精确键、目标、询问及结果。 + + + **L123** 要求给定列表中确有登记原则及实际记录。 + + + **L124** 要求键匹配,并满足有内容的 ValidApplication 谓词。 + + + **L125** 把记录的询问及结果绑定到所要求的对象。 + + + **L127** 陈述从现有具体反身性到通用接口的条件桥接。 + + + **L128** 假定具体 Reflexive 满足证明 h;接口本身并不建立它。 + + + **L129** 结论映射全部原规则,并保留该所有者的自身目标谓词。 + + + **L130** 通过 legacyPerformed 使用原实际记录,并开始证明。 + + + **L131** 把登记一致性与逐目标工作责任分开证明。 + + + **L132** 取两个映射后的规则、各自成员证明和键相等前提。 + + + **L133** 从映射后的成员关系取回第一个原规则 a。 + + + **L134** 同样取回第二个原规则 b。 + + + **L135** 用原登记一致性等同 a 与 b,再映射该等式。 + + + **L136** 引入列出的规则、其自身目标及实际适用证明。 + + + **L137** 取回映射规则对应的原原则。 + + + **L138** 应用已假定的具体反身性 h,取得该目标上的有效执行记录。 + + + **L139** 选择该记录的结果,保留键、成员关系及询问身份。 + + + **L140** 展开为原原则针对自身询问及目标专属理由的含义责任。 + + + **L141** 保留同一目标的限制及本记录结果。 + + + **L142** 推出询问内嵌目标就是实际评估的目标。 + + + **L143** 用该身份等式重写内嵌目标。 + + + **L144** 把询问、理由及限制重写为精确记录字段。 + + + **L145** 使用记录已有的 followsMeaning 证明完成桥接。 + + + **L147** 规范注释把履行限定于所列数学适配。 + + + **L148** 它不主张普遍经验充分性或完整分类。 + + + **L149** 开始 CoreReader.Adopted.empiricalSpecification 的来源追溯元数据;映射不是证明前提。 + + + **L150** 记录来源条款 organon.grounds.assessment#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L151** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L152** 使用明确的原观察定义经验责任。 + + + **L153** 把范围、所断言主张及不确定性谓词保留为不同输入。 + + + **L154** 要求给定经验候选方面满足典范 Grounds。 + + + **L155** 把原任务固定到这些相同记录、范围、主张及不确定性。 + + + **L157** 开始 CoreReader.Adopted.inferentialSpecification 的来源追溯元数据;映射不是证明前提。 + + + **L158** 记录来源条款 organon.grounds.assessment#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L159** 记录来源条款 organon.relationships.roles#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L160** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L161** 相对于明确原假设及主张定义推论责任满足。 + + + **L162** 要求该推论方面履行具有相同原假设的任务。 + + + **L164** 开始 CoreReader.Adopted.valueSpecification 的来源追溯元数据;映射不是证明前提。 + + + **L165** 记录来源条款 organon.grounds.assessment#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L166** 记录来源条款 organon.grounds.assessment#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L167** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L168** 为给定完整价值立场定义满足条件。 + + + **L169** 要求其承诺在恰好该价值立场任务下满足 Grounds。 + + + **L171** 说明比较范围及方法用途涉及特定主张。 + + + **L172** 只有实际使用的方法才承担所表示的用途解释责任。 + + + **L173** 相关性关系不要求普遍数值尺度。 + + + **L174** 引入三种所表示的方法类别:测量、重复和框架。 + + + **L175** 为这一有限方法类型生成可判定相等。 + + + **L176** 封装 W 上针对主张的比较及方法用途说明。 + + + **L177** 保存被评估的主张。 + + + **L178** 独立于观察范围保存相关条件。 + + + **L179** 保存哪些世界或输入位于观察范围内。 + + + **L180** 保存比较对象之间的上下文相关性。 + + + **L181** 保存实际比较哪些对象对。 + + + **L182** 保存实际使用哪些评估方法。 + + + **L183** 为每种方法指定用途说明文字。 + + + **L184** 保存把方法及其用途文字关联到主张和条件的语义关系。 + + + **L186** 开始 CoreReader.Adopted.scopeSpecification 的来源追溯元数据;映射不是证明前提。 + + + **L187** 记录来源条款 organon.grounds.scope#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L188** 记录来源条款 organon.grounds.scope#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L189** 记录来源条款 organon.grounds.scope#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L190** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L191** 为给定比较说明定义范围责任满足。 + + + **L192** 每对实际比较对象的两侧都必须满足说明中的条件。 + + + **L193** 两侧还须位于范围内,并满足已陈述的相关性关系。 + + + **L194** 每种实际使用的方法都需要非空用途说明。 + + + **L195** 该精确用途须相对于本主张及条件解释此方法。 + + + **L197** 能力由应用选择的、针对一个精确过程的契约表示。 + + + **L198** 是否要求解释证书仍由应用决定。 + + + **L199** 开始 CoreReader.Adopted.capabilitySpecification 的来源追溯元数据;映射不是证明前提。 + + + **L200** 记录来源条款 organon.grounds.capabilities#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L201** 记录来源条款 organon.grounds.capabilities#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L202** 记录来源条款 organon.relationships.roles#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L203** 记录来源条款 organon.relationships.roles#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L204** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L205** 针对被评估过程及选定契约定义能力责任。 + + + **L206** 要求精确过程契约方面满足 Grounds。 + + + **L207** 原推论任务固定过程身份假设及该契约。 + + + **L209** 开始 CoreReader.Adopted.choiceSpecification 的来源追溯元数据;映射不是证明前提。 + + + **L210** 记录来源条款 organon.grounds.implementations#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L211** 记录来源条款 organon.grounds.implementations#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L212** 记录来源条款 organon.grounds.implementations.limits#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L213** 记录来源条款 organon.relationships.roles#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L214** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L215** 为实际要求及实现定义选择责任满足。 + + + **L216** 理由必须满足辅助定义中的可行性及相关内容条件。 + + + **L218** 注释把协作者标识为新增操作的来源。 + + + **L219** 没有该资源时,转换保留初始操作内容。 + + + **L220** 定义依赖协作的状态修订。 + + + **L221** 存在协作者时返回 extendedState,否则返回 baseState。 + + + **L223** 证明实际协作扩展可以与无援助执行失败并存。 + + + **L224** 开放策略满足所表示的生成承诺。 + + + **L225** 可用协作者带来新构造或新理解的操作。 + + + **L226** 移除同一协作者后,不再发生所表示的扩展。 + + + **L227** 没有经验、知识及协作者时,辅助执行不返回结果。 + + + **L228** 给出策略证明及按求值成立的无援助失败,留下两个转换主张。 + + + **L229** 选择 successor 作为扩展状态中新构造的操作。 + + + **L230** 验证基础状态中原先没有 successor。 + + + **L231** 展开无协作者分支,证明内容未变不构成扩展。 + + + **L233** 注释把当前一致性与旧的不相容判断分开。 + + + **L234** 语义上下文变化与呈现顺序有不同作用。 + + + **L235** 开始 CoreReader.Adopted.consistencyConsequences 的来源追溯元数据;映射不是证明前提。 + + + **L236** 记录来源条款 organon.charter.consistency#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L237** 记录来源条款 organon.charter.consistency.meaning#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L238** 记录来源条款 organon.charter.consistency.meaning#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L239** 记录来源条款 organon.charter.consistency.limits#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L240** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L241** 针对一套理论、一个上下文及一个问题陈述条件性不一致定理。 + + + **L242** 假定同一问题在同一上下文中的正反后果均成立。 + + + **L243** 这两个前提直接违反 Consistent;不推出事实正确性。 + + + **L245** 使用布尔世界、开关问题、无附加假设及无限制范围。 + + + **L247** 证明每个修订时间片一致,但新旧时间片并集不一致。 + + + **L248** 对每个当前时间片量化一致性。 + + + **L249** 拒绝同时保留相反的零时刻与一时刻时间片。 + + + **L250** 分别证明单时间片一致性及并集不一致性。 + + + **L251** 在正例分支固定任意时刻。 + + + **L252** 用一个实际可接受世界建立一致性。 + + + **L253** 选择布尔值 time==0;它满足时间片、空假设及无限制范围。 + + + **L254** 把并集不一致归约为开关问题的相反后果。 + + + **L255** 为肯定后果取任意可接受世界。 + + + **L256** 把所需肯定含义展开为 w=true。 + + + **L257** 从并集模型的零时刻部分读取 w=true。 + + + **L258** 为否定后果,额外假定该世界为开。 + + + **L259** 从同一并集模型的一时刻部分读取 w=false。 + + + **L260** 组合等式,导出 true=false 的矛盾。 + + + **L262** 证明含假假设或未决问题的明确一致示例。 + + + **L263** 单一开状态理论在宽上下文中一致。 + + + **L264** 否定实际 false 满足唯一主张为 world=true 的理论。 + + + **L265** 空持有理论在该上下文中也一致。 + + + **L266** 具有见证的空理论不蕴含肯定的真世界答案。 + + + **L267** 复用已检查的假世界及不蕴含结果,留下两个一致性见证。 + + + **L268** 为开状态理论选择 true 世界作为模型。 + + + **L269** 其附加假设为空且范围不受限。 + + + **L270** 为空理论仍选择 true;无需检查持有前提。 + + + **L271** 空上下文假设及无限制范围补全可接受性。 + + + **L273** 注释区分输入零上的支持与更强断言。 + + + **L274** 全输入为真及额外输入一合取项都不由该记录推出。 + + + **L275** 定义只断言输入零输出为真的经验方面。 + + + **L276** 使用 zeroRecord、无限制世界范围、局部主张及平凡不确定性。 + + + **L277** 用相同记录定义更强的全输入经验断言。 + + + **L278** 主张为 allTrue;范围及不确定性并不添加证据。 + + + **L279** 定义加强为两个输出的经验断言。 + + + **L280** 要求从未变的输入零记录推出 f0=true 及 f1=true。 + + + **L282** 证明局部经验方面在所表示范围内完成评估。 + + + **L283** 给出 localGenerator0 作为范围内与证据相容的实际世界。 + + + **L284** 相容性给出观察到的零输入输出;不确定性谓词为 True。 + + + **L286** 组合局部支持、全局范围越界失败及更强主张内容失败。 + + + **L287** 局部主张履行其明确声明的局部任务。 + + + **L288** 全局候选仍具有清楚可识别的陈述。 + + + **L289** 尽管陈述清楚,全输入任务仍不满足 Grounds。 + + + **L290** 两个输出任务在相同记录下也失败。 + + + **L291** 复用已检查的局部支持,并开始验证全局陈述字段。 + + + **L292** 证明其理由可识别,留下两个实质失败待证。 + + + **L293** 为反驳而假定全局 Grounds 成立。 + + + **L294** 从该假设提取全局方面必须满足的完成条件。 + + + **L295** 把其假定支持应用到 localGenerator0 的输入一处,而该处输出为假。 + + + **L296** 消去由此产生的不可能布尔等式。 + + + **L297** 为反证假定更强双输出主张满足 Grounds。 + + + **L298** 提取该候选的经验评估完成责任。 + + + **L299** 其第二个合取项错误要求 localGenerator0 在输入一输出真。 + + + **L300** 与实际假输出矛盾。 + + + **L302** 注释允许一个结果被观察确定,而另一可观察量仍未知。 + + + **L303** 此处不确定性表示为可能世界集合,而非概率分布。 + + + **L304** 在布尔对上定义具有不确定性的经验方面。 + + + **L305** 使用重复的第一坐标观察,不进一步限制世界。 + + + **L306** 断言第一坐标为真,同时允许第二坐标取任一值。 + + + **L308** 证明这一有限经验断言及仍存在的两种可能性。 + + + **L309** 经验任务使用相同的重复温度记录。 + + + **L310** 主张只固定第一坐标;不确定性明确允许第二坐标变化。 + + + **L311** 真/真世界与重复记录相符。 + + + **L312** 真/假世界同样与它们相符。 + + + **L313** 使用典范单方面 Grounds,并给出两个相容世界。 + + + **L314** 选择真/假为非空经验见证,并拆分支持责任。 + + + **L315** 通过记录成员关系读取实际第一坐标观察。 + + + **L316** 穷尽第二坐标的两个值,以证明所陈述的不确定性范围。 + + + **L318** 注释把准确的否定评估与受支持的肯定断言区分开。 + + + **L319** 反赋值必须满足相同原前提。 + + + **L320** 针对明确前提及结论定义评估报告。 + + + **L321** 报告恰在原前提蕴含结论时接受;这是准确性定义,不是肯定结果。 + + + **L323** 同时证明有效算术推论和准确的否定布尔评估。 + + + **L324** 从陈述的假设 n=2,限定推论建立 n+1=3。 + + + **L325** 空布尔理论对于开状态主张准确地得到否定报告。 + + + **L326** false 世界满足相同空前提,却使结论为假。 + + + **L327** 使用已检查的算术完成证明及具体反世界,留下报告准确性。 + + + **L328** 证明报告与蕴含等价关系的两个方向。 + + + **L329** 否定报告等于 true 不可能成立。 + + + **L330** 假定蕴含与已检查的空理论反赋值矛盾。 + + + **L332** 注释把相关批评标识为实际责任。 + + + **L333** 预算理由及采用未变并不能免除回应责任。 + + + **L334** 保留 switchPosition 的其他内容,只把所有回应改为 none。 + + + **L336** 证明没有回应的立场不满足所表示的价值评估过程。 + + + **L337** 为反证而假定该价值评估过程成立。 + + + **L338** 把其回应责任应用到实际相关的 false 世界批评。 + + + **L339** 所要求的 some 回答与定义中的 none 回应矛盾。 + + + **L341** 陈述固定 switch 价值立场任务的履行。 + + + **L342** 在典范单方面辅助证明中使用已检查的 switch 价值过程。 + + + **L344** 注释通过逻辑蕴含比较主张强度。 + + + **L345** 不要求把价值理由与其他理由统一换算为数值。 + + + **L346** 把较弱定义为:在较强主张成立的每个世界中都成立。 + + + **L348** 证明非对称蕴含次序,同时保留有理由的价值任务。 + + + **L349** 每个输入都为真蕴含输入零为真。 + + + **L350** 输入零为真不蕴含每个输入都为真。 + + + **L351** switch 价值任务仍独立得到履行。 + + + **L352** 把全称真特化到零并复用价值履行,留下逆向关系待反驳。 + + + **L353** 假定更强的全输入主张由局部主张推出。 + + + **L354** 把该假设应用于 localGenerator0,并检查输入一。 + + + **L355** 输入一的假输出与假定蕴含矛盾。 + + + **L357** 为每种所表示的评估方法指定具体说明文字。 + + + **L358** 测量识别被观察输入零的输出。 + + + **L359** 重复评估用重复的零输入记录检查同一局部结论。 + + + **L360** 框架把已声明输入与更广的未受支持主张分开。 + + + **L362** 为每种已述方法用途给出描述其实际贡献的命题。 + + + **L363** 测量的贡献是支持观察到的零输入输出。 + + + **L364** 重复的贡献是由重复记录支持该同一输出。 + + + **L365** 框架记录局部观察并不支持 allTrue。 + + + **L367** 在自然数输入上实例化完整局部范围说明。 + + + **L368** 该说明涉及 localGenerator0 是否在该输入成功。 + + + **L369** 不施加附加输入条件。 + + + **L370** 只有输入零属于观察范围。 + + + **L371** 所表示的相关性关系要求输入相等。 + + + **L372** 只有两个输入都等于零时才实际比较。 + + + **L373** 此具体示例使用三种所表示的方法。 + + + **L374** 使用前面指定的方法用途文字。 + + + **L375** 定义何种说明构成本说明下的有效解释。 + + + **L376** 要求精确的用途文字及精确的局部生成器主张。 + + + **L377** 还要求实际条件及该方法的实质贡献。 + + + **L379** 证明所实例化范围说明履行其陈述责任。 + + + **L380** 把对象对比较有效性与已用方法解释分开证明。 + + + **L381** 取说明认定被比较的任意对象对。 + + + **L382** 使用两者均为零的身份建立条件、范围及相同输入相关性。 + + + **L383** 固定本说明使用的任意方法。 + + + **L384** 给出精确用途、主张、条件身份,留下文字非空及语义贡献。 + + + **L385** 检查三段用途文字均非空。 + + + **L386** 按方法种类拆分实质贡献。 + + + **L387** 复用单次观察已证明的局部支持。 + + + **L388** 从重复记录相容性中读取零输入记录。 + + + **L389** 复用同一观察无法支持 allTrue 的证明。 + + + **L391** 证明两种不同过程契约的履行,以及无内部解释时的外部证书。 + + + **L392** 仅输出过程具有其输出契约的 Grounds。 + + + **L393** 有解释的过程具有更强输出加解释契约的 Grounds。 + + + **L394** 为恰好该仅输出过程给出外部证书。 + + + **L395** 其评估者与被评估者身份不同,且其输出契约成立。 + + + **L396** 然而该过程仍不提供解释契约。 + + + **L397** 用求值得出的输出正确性完成精确过程范围内的推论。 + + + **L398** 把有解释过程的 Grounds 归约为证明其更强契约。 + + + **L399** 选择实际外部证书及其已证参与者区别。 + + + **L400** 使用证书输出证明及已建立的内部解释缺失。 + + + **L401** 通过求值证明所有输出,并提供忠实的 doubleInput 证书。 + + + **L403** 该应用要求此被评对象预测乘法机制的行为。 + + + **L404** 问题同时改变输入和乘数,构成一个操作性的理解任务。 + + + **L405** 该判准属于此应用,不定义一般心理意义上的理解。 + + + **L406** 原始输出及其忠实解释本身不能提供额外问题的答案。 + + + **L407** 定义一个应用对象,包含其过程和对机制变式的回答。 + + + **L408** process 字段包含对象的原始输出函数和解释回应。 + + + **L409** answer 函数接收乘数和输入,返回对象预测的自然数输出。 + + + **L411** 将机制的预测结果定义为乘数与输入之积。 + + + **L413** 为一个被评对象定义此应用中较强的理解契约。 + + + **L414** 要求同一对象的原始过程同时满足输出正确性和忠实解释。 + + + **L415** 要求每个原始输出都符合乘数为二时的乘法机制。 + + + **L416** 要求对每个自然数乘数和输入都正确回答机制问题,包括改变后的取值。 + + + **L418** 定义一个有忠实解释、但回答忽略乘数变化的对象。 + + + **L419** 使用 explainedProcess,同时无论所问乘数如何都回答输入的两倍。 + + + **L421** 定义使用乘法规则回答机制变式问题的对象。 + + + **L422** 保留同一 explainedProcess,并以 mechanism012 作为实际回答函数。 + + + **L424** 根据此应用对象及其较强契约固定评估任务。 + + + **L425** 对象身份限制范围;它并不假设正例证明必须确立的契约。 + + + **L426** 为指定应用对象定义推论范围。 + + + **L427** 其唯一范围前提为候选对象等于被评对象。 + + + **L429** 为指定对象定义原始理解评估任务。 + + + **L430** 该任务使用精确的对象身份假设和较强的理解主张。 + + + **L432** 为该同一指定对象定义候选推论评估方面。 + + + **L433** 该方面保留原任务的精确身份假设和理解主张。 + + + **L435** 证明机制回答对象实际满足所选理解契约。 + + + **L436** 通过化简构造原输出、解释及全部变式回答的正确性,留下原乘数下的一致性待证。 + + + **L437** 为剩余的原机制一致性义务取任意输入。 + + + **L438** 展开具体定义,利用输入乘二等于输入与自身之和。 + + + **L440** 陈述忽略乘数变式的对象所对应的失败定理。 + + + **L441** 结论否定该具体对象满足较强理解契约。 + + + **L442** 暂时假设较强契约成立,以导出矛盾。 + + + **L443** 将契约要求的变式正确性实例化为乘数三、输入一。 + + + **L444** 计算对象回答和机制结果,将所假设的等式化为二等于三。 + + + **L445** 排除这两个不同自然数之间不可能成立的等式。 + + + **L447** 汇总具体理解正反例及其对象范围内的 Grounds 结果。 + + + **L448** 两个应用对象包含完全相同的原始过程,因此其输出和解释相同。 + + + **L449** 变式回答错误的对象仍满足原始输出与解释契约。 + + + **L450** 该对象未能满足较强的应用理解任务。 + + + **L451** 机制回答对象满足该较强任务。 + + + **L452** 断言精确的较强理解主张具有使用规范表述的 Grounds。 + + + **L453** 正例方面和固定的原始任务都指向机制回答对象。 + + + **L454** 在反例对象的情形中否定同一较强理解主张的 Grounds。 + + + **L455** 反例评估保留该对象自身固定的任务及身份范围,随后开始汇总证明。 + + + **L456** 直接从共同的具体过程构造过程相同和原始契约忠实成立的证据。 + + + **L457** 使用已证明的两个理解任务的失败与成功,留下其 Grounds 主张待证。 + + + **L458** 将单方面 Grounds 辅助定理用于正例方面;这里其声明的任务恰为固定的理解任务。 + + + **L459** 以回答对象自身作为身份假设的模型,再留下语义后果待证。 + + + **L460** 取满足固定身份假设的任意候选对象。 + + + **L461** 从单一范围假设的模型中提取候选对象与被评回答对象相等。 + + + **L462** 利用已证明的身份等式,将候选对象替换为该回答对象本身。 + + + **L463** 提供已确立的具体较强契约,而非在范围中假设该契约。 + + + **L464** 暂时假设反例对象具有 Grounds,以导出矛盾。 + + + **L465** 从所假设的 Grounds 中提取实际反例对象的单一方面已获履行。 + + + **L466** 应用已证明的此对象较强理解任务的失败结论。 + + + **L467** 将所假设的蕴涵应用于同一对象的身份模型会证明已被否定的契约,从而产生矛盾。 + + + **L469** 自我断言仍保留相同精确应用契约。 + + + **L470** 更换理由提供者不改变被断言的对象。 + + + **L471** 为所有者、断言者、过程及契约定义自身能力责任。 + + + **L472** 要求所有者与断言者身份相同,并满足通常的限定能力责任。 + + + **L474** 证明所有者 7 可凭这些 Grounds 断言自身仅输出契约。 + + + **L475** 组合身份相等及已检查的输出能力。 + + + **L477** 完整的所表示 Charter 包含生成及整套理论一致性。 + + + **L478** 它还包含真实报告及适用的有内容自身工作。 + + + **L479** 这些责任共享一个系统,世界类型是有限 Candidate×Mode。 + + + **L480** 为给定集成系统定义完整的所表示 Charter。 + + + **L481** 在一个共同有限世界中评估其责任。 + + + **L482** 要求该系统自身在此世界的策略具有生成取向。 + + + **L483** 还要求配对的一致性及报告规范。 + + + **L484** 使用系统整套持有理论及上下文作为前快照。 + + + **L485** 使用相同后快照及否定变化报告;并未隐瞒变化。 + + + **L486** 把通用反身性规范应用于同一系统的映射规则及所有者。 + + + **L487** 在执行关系中使用该系统的实际规则及工作记录。 + + + **L488** 要求其方法形式属于当前形式。 + + + **L489** 还要求其原则形式属于当前形式。 + + + **L491** 证明具体集成系统满足该完整的所表示 Charter。 + + + **L492** 复用具体系统已检查的生成策略。 + + + **L493** 复用其共同一致性,留下真实的未变报告。 + + + **L494** 桥接实际完成的自身工作,并验证两个当前形式身份。 + + + **L495** 把任何被假定的变化分为语义变化或修订身份变化。 + + + **L496** 相同快照的持有理论、假设、含义及范围相等,与语义变化假设矛盾。 + + + **L497** 相同修订标识与另一变化情形矛盾。 + + + **L499** 证明完整 Charter 履行不蕴含这一具体未获支持的 Grounds 任务。 + + + **L500** 恰好该具体系统及世界履行所有所表示 Charter 组成要求。 + + + **L501** 它也为持有理论及上下文提供实际可接受世界。 + + + **L502** 具体成本额度记录在该世界为真。 + + + **L503** 候选能力方面具有可识别的典范陈述。 + + + **L504** 该真实成本记录不能支持实际输出能力。 + + + **L505** 因此相同能力在这些候选依据下不满足 Grounds。 + + + **L506** 候选列表包含已标识的未受支持能力方面。 + + + **L507** 其原任务保留该方面的经验主张及支持上下文。 + + + **L508** 复用完整 Charter 证明及共同可接受世界。 + + + **L509** 针对该实际世界直接检查单一成本记录。 + + + **L510** 展开该方面的典范陈述以验证其概念。 + + + **L511** 还验证其非空可识别理由。 + + + **L512** 复用实质成本与输出反模型,留下完整 Grounds 拒绝待证。 + + + **L513** 为反证假定该任务满足 Grounds。 + + + **L514** 提取恰好该能力方面所需的经验评估完成条件。 + + + **L515** 它会在同一范围内推出已被反驳的成本到输出支持关系。 + + + **L517** 许可必须涉及同一主张、陈述及方面。 + + + **L518** 不足来自观察范围外的实际失败。 + + + **L519** 定义带有明确启用标志及主张的许可策略。 + + + **L520** 在策略输入中保留实际陈述、候选方面及原任务。 + + + **L521** 启用时许可要求 Grounds;禁用时允许所有内容包。 + + + **L523** 定义许可策略是否落实所表示的 Grounds 责任。 + + + **L524** 量化此世界类型中所有主张、陈述、候选列表及原任务。 + + + **L525** 要求每个被许可内容包都对同一原任务满足 Grounds。 + + + **L527** 证明这种落实策略性质恰在启用模式成立。 + + + **L528** 考虑启用标志的两个值。 + + + **L529** 启用时许可就是 Grounds,因此该蕴含返回其前提。 + + + **L530** 处理允许未受支持内容包的禁用模式。 + + + **L531** 在该模式下分别证明所提等价的两个方向。 + + + **L532** 假定禁用许可仍落实全部 Grounds 责任。 + + + **L533** 把它应用于具体未受支持的全局任务,与 scopeStrength012 矛盾。 + + + **L534** 反向前提 false=true 不可能成立。 + + + **L536** 价值理由涉及一个固定经验断言任务。 + + + **L537** 其记录及实际反世界在不同模式中保持相同。 + + + **L538** 启用与禁用模式之间只改变许可策略。 + + + **L539** 声明许可策略比较使用的原经验任务。 + + + **L540** 它以输入零记录断言 allTrue,世界范围无限制,不确定性为平凡条件。 + + + **L542** 定义实际任务许可的不可计算逻辑判定,而非运行时实验。 + + + **L543** 询问是否许可该精确 allTrue 主张及全局候选。 + + + **L544** 保留固定原任务,并使用经典命题可判定性。 + + + **L546** 定义关于该实际任务许可策略的价值立场。 + + + **L547** 备选项是启用或禁用策略。 + + + **L548** 后果是布尔许可判定。 + + + **L549** 明确采用启用选项;不宣称从事实推出这种采用。 + + + **L550** 所表示世界本身标识所选选项。 + + + **L551** 为该选项判断固定任务的实际许可。 + + + **L552** 陈述的目标是拒绝未受支持的断言。 + + + **L553** 还要求所选策略落实所表示的 Grounds 条款。 + + + **L554** 起始假设明确记录采用启用模式。 + + + **L555** 理由是与记录相容却使 allTrue 为假的具体程序,而非 enabled=true。 + + + **L556** 所表示价值立场的世界范围无限制。 + + + **L557** allTrue 实际缺少支持构成相关批评。 + + + **L558** 提供非空回应,保留局部支持并拒绝越界。 + + + **L560** 为这一具体许可理由证明有限价值评估过程。 + + + **L561** 验证理由非空,并拆分共同采用、后果及批评回应。 + + + **L562** 选择启用世界,满足其起点、范围及所采用选择。 + + + **L563** 取该立场理由列表的任意成员。 + + + **L564** 把它等同于唯一具体反世界理由。 + + + **L565** 给出记录相容性,留下全局主张的假性。 + + + **L566** 程序在输入一输出假,从而反驳 allTrue。 + + + **L567** 在后果分支中假定当前世界的所给理由事实。 + + + **L568** 从传入理由提取实际反世界事实。 + + + **L569** 展开其两个内容:记录相容性及 allTrue 失败。 + + + **L570** 推出同一固定原全局任务不具有 Grounds。 + + + **L571** 为反证假定该精确 Grounds 内容包成立。 + + + **L572** 提取 globalFacet012 的经验评估完成条件。 + + + **L573** 用传入反世界的相容性,与其传入的全局假性矛盾。 + + + **L574** 把实际拒绝与启用模式落实一般条款分开证明。 + + + **L575** 把推出的无许可转换为假的逻辑判定。 + + + **L576** 该判定仍涉及同一原任务;经典可判定性不增加经验测试。 + + + **L577** 对范围内任意相关批评给出固定非空回应。 + + + **L579** 证明有限许可策略比较保留实际反例内容。 + + + **L580** 同一程序与观察记录匹配,并使全局主张失败。 + + + **L581** 启用许可拒绝该任务;禁用许可接受它。 + + + **L582** 价值立场的启用后果就是实际启用许可判定。 + + + **L583** 其禁用后果同样是实际禁用许可判定。 + + + **L584** 给出相容性及后果身份,留下假性与两个判定。 + + + **L585** 通过输入一处的实际失败反驳 allTrue。 + + + **L586** 在启用世界明确构造每个所需理由。 + + + **L587** 取一个理由及其成员证明。 + + + **L588** 把它等同于实际唯一反世界理由。 + + + **L589** 给出其与观察记录的相容性。 + + + **L590** 在输入一给出其使 allTrue 失败的实际反例。 + + + **L591** 把这些实际理由传给已检查价值过程,提取拒绝后果。 + + + **L592** 禁用模式下,许可命题为 True。 + + + **L593** 把未变任务的平凡许可转换为真判定。 + + + **L595** 对所表示 Grounds 条款自身,证明基于价值的限定 Grounds 评估。 + + + **L596** 被评估主张是落实 Grounds,任务是精确的 groundsPosition012 价值任务。 + + + **L597** 采用世界在范围内,并具有实际支持限制批评。 + + + **L598** 把立场所采用选择的主张关联到落实条款的命题。 + + + **L599** 在任意启用标志处比较这两个主张函数。 + + + **L600** 通过命题外延性使用已证明的落实与启用选择等价。 + + + **L601** 给出范围及实际批评,留下该条款的 Grounds。 + + + **L602** 用已建立的精确函数身份重写主张。 + + + **L603** 把单方面 Grounds 辅助证明应用于实际检查的价值过程。 + + + **L605** 证明具体适用自身目标的覆盖,而不把适用性普遍化。 + + + **L606** 完整登记的自身规则满足通用反身性接口。 + + + **L607** 其实际完成的工作提供执行实例。 + + + **L608** 形成、应用及修订阶段均有评估记录。 + + + **L609** 还存在实际系统自身评估。 + + + **L610** 较窄的仅应用规则也独立满足通用反身性。 + + + **L611** 其实际 applicationWork 是执行工作的来源。 + + + **L612** 该较窄规则无需产生不适用的系统评估。 + + + **L613** 桥接完整自身工作反身性,留下阶段全称量化。 + + + **L614** 利用具体系统目标成员关系取得其评估记录。 + + + **L615** 桥接仅应用示例,并保留已证明不存在的系统工作。 + + + **L616** 固定任意形成、应用或修订阶段。 + + + **L617** 把所需记录归约为已有 ownAssessmentPerformed 定理。 + + + **L618** 检查目标列表包含三个阶段各自的过程。 + + + **L620** 证明精确实际转换的成就支持,并拒绝仅凭报告建立支持。 + + + **L621** 转换的性能方面履行其声明的精确成就任务。 + + + **L622** 扩展转换与实际性能记录匹配。 + + + **L623** 扩展增添能力;清单膨胀则不会。 + + + **L624** 仅有报告不足以支持同一转换成就主张。 + + + **L625** 复用已检查的转换方面及报告反例,留下实际转换事实。 + + + **L626** 使用性能相容性与 extend 转换之间的等价关系。 + + + **L627** 展开实际前后状态,验证扩展中的新操作。 + + + **L628** 展开膨胀,验证已理解和已构造操作均未增加。 + + + **L630** 陈述任意两个布尔世界主张的次序无关性。 + + + **L631** 任意成员属于该单主张并集,当且仅当属于次序颠倒的并集。 + + + **L632** 应用一般呈现顺序定理。 + + + **L634** 定义关于开关的清楚陈述但可能为假的论证。 + + + **L635** 其概念、唯一开状态假设、开状态理由及无限制范围均明确。 + + + **L637** 证明陈述清楚不使该论证在实际关状态世界中为真。 + + + **L638** 其字段可识别,但 false 世界不满足其假设。 + + + **L639** 检查陈述非空,并复用具体假假设结果。 + + + **L641** 定义测试恒返 true、并不揭示选择的记录。 + + + **L643** 证明有理由的价值承诺不必由中性记录事实推出。 + + + **L644** switch 价值任务具有自身已履行的理由及责任。 + + + **L645** 相反选择 false 与中性记录相容。 + + + **L646** 因此这些记录不建立对 switch 承诺的采用。 + + + **L647** 空事实理论也不蕴含这种采用。 + + + **L648** 构造中性记录的实际 false 选择反世界。 + + + **L649** 单一恒真测试经求值与记录结果相符。 + + + **L650** 复用价值履行及无需自证结果,留下观察支持失败。 + + + **L651** 假定中性记录支持该采用主张。 + + + **L652** 把它应用于相容的相反选择世界。 + + + **L653** 所断言真选择与实际假选择矛盾。 + + + **L655** 保留 identity 实现的行为及成本,只把解释改为 successor。 + + + **L657** 证明内部解释忠实性区分其他方面可行且输出相同的实现。 + + + **L658** 两个实现在每个输入返回相同实际输出。 + + + **L659** 两者满足相同输出及预算可行性要求。 + + + **L660** identity 实现的解释是相关且忠实的理由。 + + + **L661** 更改后的解释不满足同一相关性与内容检查。 + + + **L662** 给出相同输出、两项可行性证明及有效解释理由。 + + + **L663** 假定更改后的解释是相关忠实理由。 + + + **L664** 把其要求的解释与输出相等特化到输入零。 + + + **L665** successor 的输出一与 identity 的输出零矛盾。 + + + **L667** 对所有清单类别量化复制示例。 + + + **L668** 两个 copy 条目的复制仍提供 copy 操作。 + + + **L669** 它们并不提供不同的 successor 操作。 + + + **L670** 固定任意文档、术语、工具或产物类别。 + + + **L671** 展开实际条目成员关系,检查操作内容。 + + + **L674** 定义适用于每个自然数目标的评估规则。 + + + **L675** 赋予其键 (0,1)、普遍适用性,以及作为输入的目标自身。 + + + **L676** 其结果必须等于 ownArithmeticPrinciple 在该输入的实际求值。 + + + **L677** 为这一故意豁免自身的规则定义实际工作关系。 + + + **L678** 工作只对目标一存在,键与输入匹配,结果为算术求值。 + + + **L680** 证明开放可修订及对另一目标的真实工作并不满足自身应用。 + + + **L681** 策略重视扩展,并保持原则形式可修订。 + + + **L682** 对目标一的实际评估返回 true。 + + + **L683** 但同一规则也适用于自身目标零。 + + + **L684** 它因适用自身目标未获得工作而不满足反身性。 + + + **L685** 给出实际策略、可修订性及另一目标工作,留下自身责任失败。 + + + **L686** 假定这一豁免自身的关系满足反身性。 + + + **L687** 取得它在适用自身目标零处假定执行的结果。 + + + **L688** Performed 要求目标零等于一,产生矛盾。 + + + **L690** 证明系统当前哲学方法没有仅凭地位获得优先的特权。 + + + **L691** 在实际提案审查要求下陈述仅地位理由的拒绝。 + + + **L692** 此仅凭地位的负例分支使用精确相同的当前哲学实现。 + + + **L693** 被拒绝的理由列表只有既有地位。 + + + **L694** 陈述相同提案审查要求下与之对照的有根据选择。 + + + **L695** 正例使用精确相同的当前哲学实现。 + + + **L696** 其实际输出表现提供正例理由。 + + + **L697** 复用实际当前方法已检查的仅地位理由拒绝。 + + + **L698** 复用其独立检查的基于输出理由的支持。 + + + **L700** 在两个布尔坐标上定义一个共同上下文。 + + + **L701** 不用附加假设;问题是在无限制范围中第二坐标是否为真。 + + + **L703** 从共同持有前提推出问题的两个符号,并证明不一致。 + + + **L704** 共同理论蕴含肯定的第二坐标问题。 + + + **L705** 它还在相同上下文蕴含同一问题的否定。 + + + **L706** 因此它违反已定义的一致性条件。 + + + **L707** 先从实际组合前提推导肯定后果。 + + + **L708** 为整套共同理论取任意可接受世界。 + + + **L709** 从同一持有集合提取 P→Q 和 P,并把前者应用于后者。 + + + **L710** 再从同一理论推导否定后果。 + + + **L711** 使用同一整套理论可接受性条件。 + + + **L712** 经其精确嵌套并集成员关系读取持有前提 ¬Q。 + + + **L713** 组合两个符号并应用一般矛盾判据;不使用爆炸规则。 + + + **L715** 为同时存在的价值张力定义数值预算上下文。 + + + **L716** 问题是 n≤6,无附加假设且范围无限制。 + + + **L718** 证明两个不同预算要求共同一致。 + + + **L719** 整个持有集合同时要求 4≤n 及 n≤6。 + + + **L720** 通过明确可接受分配建立一致性。 + + + **L721** 选择五,满足并集中的第一个预算要求。 + + + **L722** 还满足第二要求、空假设及无限制范围。 + + + **L724** 证明不使用观察方法的定性推论。 + + + **L725** 在明确前提 on=true 下推出 on≠false。 + + + **L726** 该实际推论方面表明它不使用观察。 + + + **L727** 给出 true 世界前提模型,留下所需推论。 + + + **L728** 取满足前提的布尔值,并假定它等于 false。 + + + **L729** 从单前提理论读取它与 true 相等。 + + + **L730** 这两个等式会把 true 等同于 false。 + + + **L733** 对每种所表示地位类别量化仅凭地位的拒绝。 + + + **L734** 名称、惯例或既有地位单独都不能支持选择 identity 实现。 + + + **L735** 把辅助全类别地位定理应用于这些精确要求及实现。 + + + **L737** 注释说明两个有限可能抽取结果都赋有正的相等权重。 + + + **L738** 模型涉及可能变化的结果及稳定界限。 + + + **L739** 它不对物理随机源作经验断言。 + + + **L740** 给每个布尔抽取值赋予权重一。 + + + **L741** 为每个抽取值定义实际结果及记录结果。 + + + **L742** 两种抽取均使用设置零;true 得一、false 得二,且记录准确。 + + + **L744** 证明有限抽取变化时不失去条件复现性或共同界限。 + + + **L745** 两个可能抽取的权重均为正。 + + + **L746** 两种权重相等。 + + + **L747** 两个试验复现相同设置。 + + + **L748** 其实际结果仍然不同。 + + + **L749** 对每个抽取,记录准确且实际结果至多为二。 + + + **L750** 求值验证正权重、相等、设置及不同结果,留下全称记录准确性及界限。 + + + **L751** 固定任意抽取值。 + + + **L752** 展开实际记录及界限,检查两个抽取值。 + + + **L755** 原评估任务在候选替代之前独立声明。 + + + **L756** 定义固定原全输入经验任务。 + + + **L757** 其唯一观察是 zeroRecord;主张为 allTrue。 + + + **L758** 定义另一个原局部经验任务。 + + + **L759** 使用相同记录时,它只断言 f0=true。 + + + **L761** 定义循环但数学有效的条件推论:假定 allTrue 再推出 allTrue。 + + + **L763** 证明该单独陈述的条件推论可满足且有效。 + + + **L764** 恒真函数满足其 allTrue 假设。 + + + **L765** 取满足该单一假设的任意函数。 + + + **L766** 返回前提模型中已经给定的 allTrue 事实。 + + + **L768** 区分新条件任务的有效履行与对原经验任务的无效替代。 + + + **L769** 循环方面具有其自身明确新条件任务的 Grounds。 + + + **L770** 它并不适宜于先前固定的全局经验任务。 + + + **L771** 因此它不能仅因结论相同就履行该原任务。 + + + **L772** 首先证明候选违反原任务适宜性。 + + + **L773** 为反证假定适宜性成立。 + + + **L774** 提取其要求的原前提理论与候选前提理论相等。 + + + **L775** 该等式会使 allTrue 成为观察及范围单主张理论的成员。 + + + **L776** 单一成员关系继而把 allTrue 本身等同于仅记录相容及范围。 + + + **L777** 把错误身份应用于真正匹配原记录的 localGenerator0。 + + + **L778** 该身份错误地给出输入一的真输出。 + + + **L779** 与实际假输出矛盾。 + + + **L780** 保留有效的独立条件任务及已证不适宜性。 + + + **L781** 假定候选仍履行原任务 Grounds。 + + + **L782** 提取其所需适宜性,与前述反例矛盾。 + + + **L784** 把推论前提固定为恰好原零输入记录相容性及范围。 + + + **L785** 定义使用这些未变原前提的候选推论。 + + + **L786** 只推出实际零输入观察。 + + + **L788** 证明这一基于观察的推论可满足且有效。 + + + **L789** 使用 localGenerator0 作为原记录及范围前提的模型。 + + + **L790** 取满足这些精确前提的任意函数。 + + + **L791** 提取相容性,进而得到观察到的零输入输出。 + + + **L793** 证明两种评估形式可履行同一未变经验任务。 + + + **L794** 原经验方面履行固定局部任务。 + + + **L795** 合法的基于观察推论履行恰好同一任务。 + + + **L796** 复用原经验证明,留下替代推论适配。 + + + **L797** 证明替代候选列表非空,并检查其唯一成员。 + + + **L798** 取该列表中的任意候选。 + + + **L799** 把它等同于基于观察的推论方面。 + + + **L800** 为已检查推论给出精确结论及典范陈述。 + + + **L801** 保留原前提、结论及原平凡不确定性支持。 + + + **L803** 这些记录并未观察第二坐标。 + + + **L804** 改用推论不能抹去原不确定性责任。 + + + **L805** 定义要求不确定性支持超出记录所能提供的原任务。 + + + **L806** 使用重复第一坐标记录及无限制范围。 + + + **L807** 断言第一坐标为真,同时还要求不确定性确认未观察的第二坐标为真。 + + + **L808** 定义一个推论候选,其自身完成条件不包含这一额外不确定性责任。 + + + **L809** 其前提保留原记录相容性及范围。 + + + **L810** 其结论只断言第一坐标。 + + + **L812** 证明该候选的条件推论本身有效。 + + + **L813** 真/假世界满足该推论的精确前提。 + + + **L814** 取这些前提的任意模型。 + + + **L815** 读取记录的第一坐标结果,建立局部结论。 + + + **L817** 证明这一有效推论不能绕过原不确定性责任。 + + + **L818** 保留有效候选自身的完成证明。 + + + **L819** 拒绝其对于完整原不确定性任务的适宜性。 + + + **L820** 拒绝该原第一坐标断言及其未变陈述的 Grounds。 + + + **L821** 候选仍须接受完整原不确定性任务的检查。 + + + **L822** 首先建立实质不适宜性。 + + + **L823** 假定原不确定性责任得到保留及履行。 + + + **L824** 把它要求的第二坐标支持应用于与记录相容的真/假世界。 + + + **L825** 假的第二坐标与该假定支持矛盾。 + + + **L826** 组合有效条件推论及其对原任务的不适宜性。 + + + **L827** 任何所声称 Grounds 都会提供恰好被反驳的适宜性。 + + + **L829** 定义关于实际上选择了哪个价值选项的经验观察。 + + + **L830** switch 记录支持选择事实,不确定性为平凡条件。 + + + **L832** 把受支持的选择事实与原价值理由任务的履行区分开。 + + + **L833** 经验选择方面完成评估,有理由的价值立场也独立履行其任务。 + + + **L834** 单独经验事实仍不能履行固定价值立场任务。 + + + **L835** 复用经验及价值证明,留下对替代的拒绝。 + + + **L836** 假定经验事实履行了该原价值任务。 + + + **L837** 所要求的价值任务与经验方面组合在有限适配中为 False。 + + + **L839** 证明改变原推论假设也使任务替代无效。 + + + **L840** 从 on=true 推出其自身的条件推论本身有效。 + + + **L841** 在推论上下文被替代时拒绝原开状态主张的 Grounds。 + + + **L842** 候选把结论自身假定为前提。 + + + **L843** 固定原任务采用的则是空假设理论。 + + + **L844** 为有效条件推论给出 true 世界模型并返回其前提,留下替代失败。 + + + **L845** 假定改变前提的候选满足原任务 Grounds。 + + + **L846** 从单元素列表提取精确候选的适宜性。 + + + **L847** 它会把非空的开状态单假设理论等同于空理论。 + + + **L848** 传递单元素成员关系,得到空理论中的成员关系。 + + + **L849** 这种成员关系按定义为 False,从而完成矛盾证明。 + + + **L852** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。 + + + **L853** 开始 CoreReader.Adopted.generationCases 的来源追溯元数据;映射不是证明前提。 + + + **L854** 记录来源条款 organon.charter.overview#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L855** 记录来源条款 organon.charter.overview#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L856** 记录来源条款 organon.charter.self-transcendence#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L857** 记录来源条款 organon.charter.self-transcendence.orientation#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L858** 记录来源条款 organon.charter.self-transcendence.non-finality#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L859** 记录来源条款 organon.charter.self-transcendence.limits#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L860** 记录来源条款 organon.relationships.terms#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L861** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L862** 汇总已检查的生成价值取向、仅许可失败、有理由稳定及真实协作案例。 + + + **L863** 明确开放的策略满足 Generative。 + + + **L864** 另明确每类形式的版本0均可修订。 + + + **L865** 常值轨迹中任意相邻状态都没有新增理解或构造操作。 + + + **L866** 陈述neutralPolicy允许0→1且两版本不同,但缺少价值取向使Generative失败。 + + + **L867** 具体生成系统自身的策略满足 Generative。 + + + **L868** 其政策允许保持版本0,因此生成取向不要求每次行动都改变版本。 + + + **L869** 膨胀该系统库存不会扩展其已表示能力。 + + + **L870** 膨胀状态的库存条目严格多于该系统当前状态。 + + + **L871** 抽象层级数也严格增加,却没有能力扩展。 + + + **L872** 在能力内容保持不变时,词汇条目数严格增加。 + + + **L873** 资源为1、2、3时,该系统执行实际返回some 6。 + + + **L874** 从同一资源包移除经验,使该系统执行失败。 + + + **L875** 单独移除知识,同样使其执行返回none。 + + + **L876** 单独移除协作者输入,也使执行失败。 + + + **L877** 三种外部输入均缺失时,同一执行接口返回none。 + + + **L878** 系统稳定动作不产生已表示能力扩展。 + + + **L879** 该稳定动作恰为保持系统当前状态。 + + + **L880** 保持当前状态可保留工作负载必需的copy操作。 + + + **L881** 保留的单条状态满足该系统1条的应用预算。 + + + **L882** 复制后库存有2条,超过同一系统的1条预算。 + + + **L883** 稳定具有所述理由:构造内容未变,但只有当前状态满足预算。 + + + **L884** 确认该报告由此系统针对inflatedState、successor、输入0和输出1构造。 + + + **L885** 报告所有者等于该生成系统的所有者。 + + + **L886** 报告以该系统当前状态为基线,以inflatedState为结果。 + + + **L887** 确认声称新增操作是successor。 + + + **L888** 确认公告中的测试输入是0、预期输出是1。 + + + **L889** 陈述公告实质主张失败,且公告自身的状态对没有扩展。 + + + **L890** 开放策略满足所表示的生成承诺。 + + + **L891** 可用协作者带来新构造或新理解的操作。 + + + **L892** 移除同一协作者后,不再发生所表示的扩展。 + + + **L893** 没有经验、知识及协作者时,辅助执行不返回结果。 + + + **L894** 把四个实际组成证明组装为完整陈述的合取;名字本身不是证据。 + + + **L896** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。 + + + **L897** 开始 CoreReader.Adopted.generationLimits012 的来源追溯元数据;映射不是证明前提。 + + + **L898** 记录来源条款 organon.charter.self-transcendence.orientation#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L899** 记录来源条款 organon.charter.self-transcendence.non-finality#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L900** 记录来源条款 organon.charter.self-transcendence.limits#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L901** 记录来源条款 organon.charter.self-transcendence.limits#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L902** 记录来源条款 organon.relationships.roles#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L903** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L904** 汇总生成相关不蕴含:许可不等于价值取向,开放不等于成就,内容比数量更有判别力。 + + + **L905** 陈述neutralPolicy允许0→1且两版本不同,但缺少价值取向使Generative失败。 + + + **L906** 开放策略本身履行价值取向及可修订条件。 + + + **L907** 另明确每类形式的版本0均可修订。 + + + **L908** 常值轨迹中任意相邻状态都没有新增理解或构造操作。 + + + **L909** 在后续无进展示例中,该系统仍具有生成取向。 + + + **L910** 其政策允许保持版本0,因此生成取向不要求每次行动都改变版本。 + + + **L911** 膨胀该系统库存不会扩展其已表示能力。 + + + **L912** 膨胀状态的库存条目严格多于该系统当前状态。 + + + **L913** 抽象层级数也严格增加,却没有能力扩展。 + + + **L914** 在能力内容保持不变时,词汇条目数严格增加。 + + + **L915** 资源为1、2、3时,该系统执行实际返回some 6。 + + + **L916** 从同一资源包移除经验,使该系统执行失败。 + + + **L917** 单独移除知识,同样使其执行返回none。 + + + **L918** 单独移除协作者输入,也使执行失败。 + + + **L919** 三种外部输入均缺失时,同一执行接口返回none。 + + + **L920** 系统稳定动作不产生已表示能力扩展。 + + + **L921** 该稳定动作恰为保持系统当前状态。 + + + **L922** 保持当前状态可保留工作负载必需的copy操作。 + + + **L923** 保留的单条状态满足该系统1条的应用预算。 + + + **L924** 复制后库存有2条,超过同一系统的1条预算。 + + + **L925** 稳定具有所述理由:构造内容未变,但只有当前状态满足预算。 + + + **L926** 确认该报告由此系统针对inflatedState、successor、输入0和输出1构造。 + + + **L927** 报告所有者等于该生成系统的所有者。 + + + **L928** 报告以该系统当前状态为基线,以inflatedState为结果。 + + + **L929** 确认声称新增操作是successor。 + + + **L930** 确认公告中的测试输入是0、预期输出是1。 + + + **L931** 陈述公告实质主张失败,且公告自身的状态对没有扩展。 + + + **L932** 开放策略满足所表示的生成承诺。 + + + **L933** 可用协作者带来新构造或新理解的操作。 + + + **L934** 移除同一协作者后,不再发生所表示的扩展。 + + + **L935** 没有经验、知识及协作者时,辅助执行不返回结果。 + + + **L936** 转换的性能方面履行其声明的精确成就任务。 + + + **L937** 要求 extend 满足真实表现观测。 + + + **L938** 扩展增添能力;清单膨胀则不会。 + + + **L939** 因此断言积极报告记录不能在全部相容变化上支持该成就。 + + + **L940** 对每种所表示条目类别量化清单内容结果。 + + + **L941** 两个 copy 条目的复制仍提供 copy 操作。 + + + **L942** 它们并不提供不同的 successor 操作。 + + + **L943** 组合六项证明,包括实际协作进展、同转换支持及全部类别复制限制。 + + + **L945** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。 + + + **L946** 开始 CoreReader.Adopted.consistencyCases 的来源追溯元数据;映射不是证明前提。 + + + **L947** 记录来源条款 organon.charter.consistency#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L948** 记录来源条款 organon.charter.consistency.meaning#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L949** 记录来源条款 organon.charter.consistency.meaning#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L950** 记录来源条款 organon.charter.consistency.limits#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L951** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L952** 汇总整套集合冲突、上下文区别、真实报告、撤回及呈现顺序案例。 + + + **L953** 前两个结论分别为 P 与蕴含规则提供模型。 + + + **L954** 还要求非 Q 单独有模型,却否定整套联合理论具有模型。 + + + **L955** 要求在真值假设下给出肯定答案。 + + + **L956** 要求在假值假设下给出否定答案;两者上下文不同。 + + + **L957** 要求对含义为等于 true 的问题给出肯定答案。 + + + **L958** 当同一问题改为表示等于 false 时,要求否定答案。 + + + **L959** 要求在限制为 true 的范围内给出肯定答案。 + + + **L960** 要求在另一个限制为 false 的范围内给出否定答案。 + + + **L961** 对任一假设选择,要求实际可接受世界存在。 + + + **L962** 对任一问题含义,要求实际可接受世界存在。 + + + **L963** 无论选择哪种范围,结论都包含实际可接受世界。 + + + **L964** 实际上下文假设从 true 变为 false 时,拒绝 false 报告。 + + + **L965** 问题实际含义改变时,拒绝 false 报告。 + + + **L966** 实际应用范围改变时,拒绝 false 报告。 + + + **L967** 上下文不变但修订身份从 0 变为 1 时,拒绝 false 报告。 + + + **L968** 允许以 true 报告如实承认假设变化。 + + + **L969** 但否定这些修订后的假世界假设在实际 true 处成立。 + + + **L970** 要求时间切片 0 与 1 各自具有模型见证。 + + + **L971** 否定两者同时并集的模型,而不否定各自见证。 + + + **L972** 对每个当前时间片量化一致性。 + + + **L973** 拒绝同时保留相反的零时刻与一时刻时间片。 + + + **L974** 次序主张适用于任意布尔世界主张 p 与 q。 + + + **L975** 任意成员属于该单主张并集,当且仅当属于次序颠倒的并集。 + + + **L976** 共同理论蕴含肯定的第二坐标问题。 + + + **L977** 它还在相同上下文蕴含同一问题的否定。 + + + **L978** 因此它违反已定义的一致性条件。 + + + **L979** 组合七个已检查部分,保留共同推论冲突及分时一致性。 + + + **L981** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。 + + + **L982** 开始 CoreReader.Adopted.consistencyLimits012 的来源追溯元数据;映射不是证明前提。 + + + **L983** 记录来源条款 organon.charter.consistency.meaning#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L984** 记录来源条款 organon.charter.consistency.limits#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L985** 记录来源条款 organon.relationships.roles#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L986** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L987** 汇总一致性限制,包含实际上下文模型、预算张力、假假设及不蕴含。 + + + **L988** 要求在真值假设下给出肯定答案。 + + + **L989** 要求在假值假设下给出否定答案;两者上下文不同。 + + + **L990** 要求对含义为等于 true 的问题给出肯定答案。 + + + **L991** 当同一问题改为表示等于 false 时,要求否定答案。 + + + **L992** 要求在限制为 true 的范围内给出肯定答案。 + + + **L993** 要求在另一个限制为 false 的范围内给出否定答案。 + + + **L994** 对任一假设选择,要求实际可接受世界存在。 + + + **L995** 对任一问题含义,要求实际可接受世界存在。 + + + **L996** 无论选择哪种范围,结论都包含实际可接受世界。 + + + **L997** 要求存在同时满足下界 4 与上界 6 的自然数预算。 + + + **L998** 还断言两个界限谓词不同,即使它们可以共同满足。 + + + **L999** 单一开状态理论在宽上下文中一致。 + + + **L1000** 否定实际 false 满足唯一主张为 world=true 的理论。 + + + **L1001** 空持有理论在该上下文中也一致。 + + + **L1002** 具有见证的空理论不蕴含肯定的真世界答案。 + + + **L1003** 要求存在使 emptyTheory 与肯定单元素主张共同成立的模型。 + + + **L1004** 具有见证的空理论不蕴含肯定的真世界答案。 + + + **L1005** 整个持有集合同时要求 4≤n 及 n≤6。 + + + **L1006** 使用五个组成证明;最后一项为两个要求提供实际共享的一致分配。 + + + **L1008** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。 + + + **L1009** 开始 CoreReader.Adopted.reflexivityCases012 的来源追溯元数据;映射不是证明前提。 + + + **L1010** 记录来源条款 organon.charter.reflexivity#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1011** 记录来源条款 organon.charter.reflexivity.meaning#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1012** 记录来源条款 organon.charter.reflexivity.limits#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1013** 记录来源条款 organon.relationships.roles#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1014** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L1015** 汇总适用自身目标工作、Grounds 自身评估及其实际许可后果。 + + + **L1016** 完整登记的自身规则满足通用反身性接口。 + + + **L1017** 其实际完成的工作提供执行实例。 + + + **L1018** 形成、应用及修订阶段均有评估记录。 + + + **L1019** 还存在实际系统自身评估。 + + + **L1020** 较窄的仅应用规则也独立满足通用反身性。 + + + **L1021** 其实际 applicationWork 是执行工作的来源。 + + + **L1022** 但同一日志不含系统自身评估,因为该规则对系统自身不适用。 + + + **L1023** 被评估主张是落实 Grounds,任务是精确的 groundsPosition012 价值任务。 + + + **L1024** 采用世界在范围内,并具有实际支持限制批评。 + + + **L1025** 同一程序与观察记录匹配,并使全局主张失败。 + + + **L1026** 启用许可拒绝该任务;禁用许可接受它。 + + + **L1027** 价值立场的启用后果就是实际启用许可判定。 + + + **L1028** 其禁用后果同样是实际禁用许可判定。 + + + **L1029** 组合实际记录、已检查价值过程及同任务启用与禁用许可比较。 + + + **L1031** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。 + + + **L1032** 开始 CoreReader.Adopted.reflexivityLimits012 的来源追溯元数据;映射不是证明前提。 + + + **L1033** 记录来源条款 organon.charter.reflexivity.limits#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1034** 记录来源条款 organon.relationships.roles#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1035** 记录来源条款 organon.relationships.roles#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1036** 记录来源条款 organon.grounds#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1037** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L1038** 汇总自证、自生支持及豁免自身的开放之具体失败,并包含完整 Charter 与选定 Grounds 的分离。 + + + **L1039** 同一算术原则在样本1上通过,却在0上为假。 + + + **L1040** 因此该原则并非对所有自然数输入都返回true。 + + + **L1041** 计算 localGenerator 0 在 0 处为 true、在 1 处为 false。 + + + **L1042** 要求该生成函数匹配同一输入 0 记录。 + + + **L1043** 陈述全域支持失败,并纳入具体所有者、原对象与修订关系实例。 + + + **L1044** 将openPolicy的生成取向与空工作日志下的自有反身履责失败组合。 + + + **L1045** 恰好该具体系统及世界履行所有所表示 Charter 组成要求。 + + + **L1046** 它也为持有理论及上下文提供实际可接受世界。 + + + **L1047** 具体成本额度记录在该世界为真。 + + + **L1048** 候选能力方面具有可识别的典范陈述。 + + + **L1049** 该真实成本记录不能支持实际输出能力。 + + + **L1050** 因此相同能力在这些候选依据下不满足 Grounds。 + + + **L1051** 候选列表包含已标识的未受支持能力方面。 + + + **L1052** 其原任务保留该方面的经验主张及支持上下文。 + + + **L1053** 策略重视扩展,并保持原则形式可修订。 + + + **L1054** 对目标一的实际评估返回 true。 + + + **L1055** 但同一规则也适用于自身目标零。 + + + **L1056** 它因适用自身目标未获得工作而不满足反身性。 + + + **L1057** 使用五个具体组成证明,不从自我应用推断正确性。 + + + **L1059** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。 + + + **L1060** 开始 CoreReader.Adopted.groundsCases012 的来源追溯元数据;映射不是证明前提。 + + + **L1061** 记录来源条款 organon.grounds#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1062** 记录来源条款 organon.grounds.assessment#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1063** 记录来源条款 organon.grounds.assessment#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1064** 记录来源条款 organon.grounds.assessment#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1065** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L1066** 汇总同任务 Grounds 示例及被拒绝的循环假设替代。 + + + **L1067** 局部主张履行其明确声明的局部任务。 + + + **L1068** 全局候选仍具有清楚可识别的陈述。 + + + **L1069** 尽管陈述清楚,全输入任务仍不满足 Grounds。 + + + **L1070** 两个输出任务在相同记录下也失败。 + + + **L1071** 没有信息增益的论证仍具有可识别概念及理由。 + + + **L1072** 无信息表述的真实假设不蕴含世界为 true。 + + + **L1073** 循环方面具有其自身明确新条件任务的 Grounds。 + + + **L1074** 它并不适宜于先前固定的全局经验任务。 + + + **L1075** 因此它不能仅因结论相同就履行该原任务。 + + + **L1076** 组合范围与强度反模型、无支持的可陈述性,以及保持原任务后的替代拒绝。 + + + **L1078** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。 + + + **L1079** 开始 CoreReader.Adopted.empiricalCases012 的来源追溯元数据;映射不是证明前提。 + + + **L1080** 记录来源条款 organon.grounds.assessment#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1081** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L1082** 在保留原任务的前提下汇总经验相关性、范围、不确定性及替代评估案例。 + + + **L1083** 局部主张履行其明确声明的局部任务。 + + + **L1084** 全局候选仍具有清楚可识别的陈述。 + + + **L1085** 尽管陈述清楚,全输入任务仍不满足 Grounds。 + + + **L1086** 两个输出任务在相同记录下也失败。 + + + **L1087** 即使独立输出坐标为 false,真实温度测试仍返回 true。 + + + **L1088** 在重复温度观测下保留该假输出世界。 + + + **L1089** 在相同重复观测下也保留真输出世界。 + + + **L1090** 单条温度记录不支持另一输出为 true。 + + + **L1091** 重复该温度记录仍不支持另一输出为 true。 + + + **L1092** 重复观测到启动与已开启、预算为 0 相容。 + + + **L1093** 相同重复记录也与预算为 3 相容。 + + + **L1094** 单条启动记录不支持该选项的真实目标与预算后果。 + + + **L1095** 重复启动记录不能修复这一后果支持缺失。 + + + **L1096** 基于公告的价值程序也未满足同一实际选项与约束。 + + + **L1097** 经验任务使用相同的重复温度记录。 + + + **L1098** 主张只固定第一坐标;不确定性明确允许第二坐标变化。 + + + **L1099** 真/真世界与重复记录相符。 + + + **L1100** 真/假世界同样与它们相符。 + + + **L1101** 原经验方面履行固定局部任务。 + + + **L1102** 合法的基于观察推论履行恰好同一任务。 + + + **L1103** 保留有效候选自身的完成证明。 + + + **L1104** 拒绝其对于完整原不确定性任务的适宜性。 + + + **L1105** 拒绝该原第一坐标断言及其未变陈述的 Grounds。 + + + **L1106** 候选仍须接受完整原不确定性任务的检查。 + + + **L1107** 使用五个组成证明,包括合法经验转推论评估及被拒绝的不确定性绕过。 + + + **L1109** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。 + + + **L1110** 开始 CoreReader.Adopted.inferentialCases012 的来源追溯元数据;映射不是证明前提。 + + + **L1111** 记录来源条款 organon.grounds.assessment#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1112** 记录来源条款 organon.relationships.roles#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1113** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L1114** 汇总有效推论、相容但不蕴含的结论及被拒绝的原前提变更。 + + + **L1115** 从陈述的假设 n=2,限定推论建立 n+1=3。 + + + **L1116** 空布尔理论对于开状态主张准确地得到否定报告。 + + + **L1117** false 世界满足相同空前提,却使结论为假。 + + + **L1118** 要求存在使 emptyTheory 与肯定单元素主张共同成立的模型。 + + + **L1119** 具有见证的空理论不蕴含肯定的真世界答案。 + + + **L1120** 纳入推论方面,其可满足的真世界前提蕴含同一真世界主张。 + + + **L1121** 在推论上下文被替代时拒绝原开状态主张的 Grounds。 + + + **L1122** 候选把结论自身假定为前提。 + + + **L1123** 固定原任务采用的则是空假设理论。 + + + **L1124** 组合算术及否定报告证明、实际反赋值及原上下文替代拒绝。 + + + **L1126** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。 + + + **L1127** 开始 CoreReader.Adopted.valueCases012 的来源追溯元数据;映射不是证明前提。 + + + **L1128** 记录来源条款 organon.grounds.assessment#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1129** 记录来源条款 organon.grounds.assessment#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1130** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L1131** 汇总有理由价值采用、不足的自我宣布、实际批评、初始承诺及事实与价值的区别。 + + + **L1132** switch 价值任务具有自身已履行的理由及责任。 + + + **L1133** 要求公告理由非空,并在已开启且预算 0 处实际采纳。 + + + **L1134** 在同一零预算世界,全部真实公告理由成立。 + + + **L1135** 仍否定真实后果及整个价值程序。 + + + **L1136** 关闭所有批评回应使 closedPosition012 不满足价值过程。 + + + **L1137** 原 switch 立场确实满足所表示价值过程。 + + + **L1138** 其明确采用的起始假设具有实际模型。 + + + **L1139** 否定从空布尔理论推导其采纳承诺。 + + + **L1140** 相反立场具有共同见证,却未通过后果评估。 + + + **L1141** 分别否定矛盾起点假设与不可能实际采纳的程序。 + + + **L1142** 经验选择方面完成评估,有理由的价值立场也独立履行其任务。 + + + **L1143** 单独经验事实仍不能履行固定价值立场任务。 + + + **L1144** 组装五个价值证明,保留假设、限制及实际负例。 + + + **L1146** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。 + + + **L1147** 开始 CoreReader.Adopted.groundsLimits012 的来源追溯元数据;映射不是证明前提。 + + + **L1148** 记录来源条款 organon.grounds.assessment#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1149** 记录来源条款 organon.grounds.assessment#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1150** 记录来源条款 organon.grounds.assessment#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1151** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L1152** 汇总清楚理由、重复无关事实、自证要求及数值通约性的限制。 + + + **L1153** 其字段可识别,但 false 世界不满足其假设。 + + + **L1154** 即使独立输出坐标为 false,真实温度测试仍返回 true。 + + + **L1155** 在重复温度观测下保留该假输出世界。 + + + **L1156** 在相同重复观测下也保留真输出世界。 + + + **L1157** 单条温度记录不支持另一输出为 true。 + + + **L1158** 重复该温度记录仍不支持另一输出为 true。 + + + **L1159** 重复观测到启动与已开启、预算为 0 相容。 + + + **L1160** 相同重复记录也与预算为 3 相容。 + + + **L1161** 单条启动记录不支持该选项的真实目标与预算后果。 + + + **L1162** 重复启动记录不能修复这一后果支持缺失。 + + + **L1163** 基于公告的价值程序也未满足同一实际选项与约束。 + + + **L1164** switch 价值任务具有自身已履行的理由及责任。 + + + **L1165** 相反选择 false 与中性记录相容。 + + + **L1166** 因此这些记录不建立对 switch 承诺的采用。 + + + **L1167** 否定从空布尔理论推导其采纳承诺。 + + + **L1168** 有限 switch 价值过程在其陈述解释下得到履行。 + + + **L1169** 采用的起始理论可满足,但不声称它由空事实推出。 + + + **L1170** 否定从空布尔理论推导其采纳承诺。 + + + **L1171** 相反立场具有共同见证,却未通过后果评估。 + + + **L1172** 分别否定矛盾起点假设与不可能实际采纳的程序。 + + + **L1173** 每个输入都为真蕴含输入零为真。 + + + **L1174** 输入零为真不蕴含每个输入都为真。 + + + **L1175** switch 价值任务具有自身已履行的理由及责任。 + + + **L1176** 组合具体假理由及错误对象反例,以及价值和定性强度结果。 + + + **L1178** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。 + + + **L1179** 开始 CoreReader.Adopted.scopeCases012 的来源追溯元数据;映射不是证明前提。 + + + **L1180** 记录来源条款 organon.grounds.scope#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1181** 记录来源条款 organon.grounds.scope#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1182** 记录来源条款 organon.grounds.scope#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1183** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L1184** 汇总已履行局部范围说明及实际被遗漏差异。 + + + **L1185** 已定义局部说明满足所有所表示比较及方法用途责任。 + + + **L1186** 只对满足 n=0 的输入陈述两个函数相等。 + + + **L1187** 陈述它们在输入 1 处真实输出不等。 + + + **L1188** 使用实际范围说明证明及输入一差异见证。 + + + **L1190** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。 + + + **L1191** 开始 CoreReader.Adopted.scopeLimits012 的来源追溯元数据;映射不是证明前提。 + + + **L1192** 记录来源条款 organon.grounds.scope#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1193** 记录来源条款 organon.grounds.scope#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1194** 记录来源条款 organon.grounds.scope#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1195** 记录来源条款 organon.grounds.implementations.limits#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1196** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L1197** 汇总有限局部支持、更广差异、试验区别及非观察评估。 + + + **L1198** 确实存在位于被观察零输入之外的自然数输入。 + + + **L1199** 恒真函数匹配零输入观测。 + + + **L1200** 要求该生成函数匹配同一输入 0 记录。 + + + **L1201** 第一个函数全域为真,第二个却不是。 + + + **L1202** 原零输入记录并不支持全输入为真。 + + + **L1203** 只对满足 n=0 的输入陈述两个函数相等。 + + + **L1204** 陈述它们在输入 1 处真实输出不等。 + + + **L1205** 证据列表恰好包含一次观察。 + + + **L1206** 该单次观察具有实际相容函数,因此支持示例非空。 + + + **L1207** 该单条记录支持其真实输入 0 主张。 + + + **L1208** 其有限支持仍不能建立 allTrue。 + + + **L1209** 定义试验 a:设置零,实际结果一且记录准确。 + + + **L1210** 定义相同设置下的试验 b:实际结果二且记录准确。 + + + **L1211** 要求两个明确固定试次的设置相同、真实结果不同,且都满足 actualOutcome ≤ 2。 + + + **L1212** 要求两个记录准确但设置不同的试次。 + + + **L1213** 要求设置复现,同时第二记录不准确且实际结果超出界限。 + + + **L1214** 要求界限保持,即使其中一个结果记录不准确。 + + + **L1215** 算术方面完成评估,尽管其方法不使用观察。 + + + **L1216** 在明确前提 on=true 下推出 on≠false。 + + + **L1217** 该实际推论方面表明它不使用观察。 + + + **L1218** 两个可能抽取的权重均为正。 + + + **L1219** 两种权重相等。 + + + **L1220** 两个试验复现相同设置。 + + + **L1221** 其实际结果仍然不同。 + + + **L1222** 对每个抽取,记录准确且实际结果至多为二。 + + + **L1223** 组合八项证明;不把有限带权抽取和逻辑判定宣称为经验普遍保证。 + + + **L1225** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。 + + + **L1226** 开始 CoreReader.Adopted.capabilityCases012 的来源追溯元数据;映射不是证明前提。 + + + **L1227** 记录来源条款 organon.grounds.capabilities#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1228** 记录来源条款 organon.grounds.capabilities#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1229** 记录来源条款 organon.relationships.roles#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1230** 记录来源条款 organon.relationships.roles#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1231** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L1232** 汇总精确对象的输出及解释契约,并对所有者自身主张保留相同责任。 + + + **L1233** 仅输出过程具有其输出契约的 Grounds。 + + + **L1234** 有解释的过程具有更强输出加解释契约的 Grounds。 + + + **L1235** 要求存在以 outputOnlyProcess 为索引的真实外部证书。 + + + **L1236** 要求两者不同,且同一过程真实输出正确。 + + + **L1237** 仍否定该实际过程具有内部解释契约。 + + + **L1238** 保留现有自身能力情形,并合取新增的理解情形。 + + + **L1239** 两个应用对象包含完全相同的原始过程,因此其输出和解释相同。 + + + **L1240** 变式回答错误的对象仍满足原始输出与解释契约。 + + + **L1241** 该对象未能满足较强的应用理解任务。 + + + **L1242** 机制回答对象满足该较强任务。 + + + **L1243** 断言精确的较强理解主张具有使用规范表述的 Grounds。 + + + **L1244** 正例方面和固定的原始任务都指向机制回答对象。 + + + **L1245** 在反例对象的情形中否定同一较强理解主张的 Grounds。 + + + **L1246** 反例评估保留该对象自身固定的任务及身份范围,并结束新增理解情形的陈述。 + + + **L1247** 由保留的能力、自身能力证明和新增理解情形证明构造汇总结果。 + + + **L1249** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。 + + + **L1250** 开始 CoreReader.Adopted.capabilityLimits012 的来源追溯元数据;映射不是证明前提。 + + + **L1251** 记录来源条款 organon.grounds.capabilities#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1252** 记录来源条款 organon.grounds.capabilities#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1253** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L1254** 汇总没有解释的可靠输出,以及更强能力主张的清单与资源限制。 + + + **L1255** 仅输出过程具有其输出契约的 Grounds。 + + + **L1256** 有解释的过程具有更强输出加解释契约的 Grounds。 + + + **L1257** 要求存在以 outputOnlyProcess 为索引的真实外部证书。 + + + **L1258** 要求两者不同,且同一过程真实输出正确。 + + + **L1259** 仍否定该实际过程具有内部解释契约。 + + + **L1260** 复制主张适用于每种所表示清单类型。 + + + **L1261** 两个 copy 条目的复制仍提供 copy 操作。 + + + **L1262** 它们并不提供不同的 successor 操作。 + + + **L1263** 相同具体生成系统具有生成策略。 + + + **L1264** 其政策允许保持版本0,因此生成取向不要求每次行动都改变版本。 + + + **L1265** 膨胀该系统库存不会扩展其已表示能力。 + + + **L1266** 膨胀状态的库存条目严格多于该系统当前状态。 + + + **L1267** 抽象层级数也严格增加,却没有能力扩展。 + + + **L1268** 在能力内容保持不变时,词汇条目数严格增加。 + + + **L1269** 资源为1、2、3时,该系统执行实际返回some 6。 + + + **L1270** 从同一资源包移除经验,使该系统执行失败。 + + + **L1271** 单独移除知识,同样使其执行返回none。 + + + **L1272** 单独移除协作者输入,也使执行失败。 + + + **L1273** 三种外部输入均缺失时,同一执行接口返回none。 + + + **L1274** 系统稳定动作不产生已表示能力扩展。 + + + **L1275** 该稳定动作恰为保持系统当前状态。 + + + **L1276** 保持当前状态可保留工作负载必需的copy操作。 + + + **L1277** 保留的单条状态满足该系统1条的应用预算。 + + + **L1278** 复制后库存有2条,超过同一系统的1条预算。 + + + **L1279** 稳定具有所述理由:构造内容未变,但只有当前状态满足预算。 + + + **L1280** 确认该报告由此系统针对inflatedState、successor、输入0和输出1构造。 + + + **L1281** 报告所有者等于该生成系统的所有者。 + + + **L1282** 报告以该系统当前状态为基线,以inflatedState为结果。 + + + **L1283** 确认声称新增操作是successor。 + + + **L1284** 确认公告中的测试输入是0、预期输出是1。 + + + **L1285** 陈述公告实质主张失败,且公告自身的状态对没有扩展。 + + + **L1286** 组合限定能力证明、全类别内容检查及实际生成与资源限制。 + + + **L1288** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。 + + + **L1289** 开始 CoreReader.Adopted.choiceCases012 的来源追溯元数据;映射不是证明前提。 + + + **L1290** 记录来源条款 organon.grounds.implementations#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1291** 记录来源条款 organon.grounds.implementations#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1292** 记录来源条款 organon.grounds.implementations.limits#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1293** 记录来源条款 organon.relationships.roles#p3 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1294** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L1295** 汇总有依据惯常选择、内部方法理由及仅地位理由拒绝,并包含当前哲学。 + + + **L1296** 保留恒等实现两个真实地位事实均为 true。 + + + **L1297** 主张使用惯常与真实输出理由组成的列表可获得有理由选择;相关性来自输出理由。 + + + **L1298** 要求同一真实恒等实现具有忠实解释理由。 + + + **L1299** 要求其真实适用性覆盖必需输入。 + + + **L1300** 要求其真实成本满足所重视的简单性与预算条件。 + + + **L1301** 要求其真实轨迹内容满足所重视的过程条件。 + + + **L1302** 要求 cheapSuccessor 的成本理由在所选要求下真实相关。 + + + **L1303** 仍否定它仅凭该理由获得有理由选择,因为可行性还包括输出正确。 + + + **L1304** 要求同一地位优先权评估具有程序表述与正确否定报告。 + + + **L1305** 保留所有候选解释为相同真实地位事实的模型。 + + + **L1306** 优先权谓词在 identity 处成立,在 successor 处失败。 + + + **L1307** 真实名称、惯例及地位事实不蕴含该特定优先主张。 + + + **L1308** 还拒绝只以既有地位作为真实理由选择恒等实现。 + + + **L1309** 两个实现在每个输入返回相同实际输出。 + + + **L1310** 两者满足相同输出及预算可行性要求。 + + + **L1311** 要求同一真实恒等实现具有忠实解释理由。 + + + **L1312** 更改后的解释不满足同一相关性与内容检查。 + + + **L1313** 在实际提案审查要求下陈述仅地位理由的拒绝。 + + + **L1314** 此仅凭地位的负例分支使用精确相同的当前哲学实现。 + + + **L1315** 被拒绝的理由列表只有既有地位。 + + + **L1316** 陈述相同提案审查要求下与之对照的有根据选择。 + + + **L1317** 正例使用精确相同的当前哲学实现。 + + + **L1318** 其实际输出表现提供正例理由。 + + + **L1319** 对名称、惯常使用及既有地位量化仅凭地位的不足。 + + + **L1320** 名称、惯例或既有地位单独都不能支持选择 identity 实现。 + + + **L1321** 组合六项选择证明,保留实际内容比较并拒绝当前哲学的特权。 + + + **L1323** 说明该汇总保留各组成命题的完整内容;后面的具名证明建立它们的合取。 + + + **L1324** 开始 CoreReader.Adopted.choiceLimits012 的来源追溯元数据;映射不是证明前提。 + + + **L1325** 记录来源条款 organon.grounds.implementations#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1326** 记录来源条款 organon.grounds.implementations#p2 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1327** 记录来源条款 organon.grounds.implementations.limits#p1 及所示 SHA-256 身份;这是文档关联,不是语义验证。 + + + **L1328** 结束前面的来源映射注释,不添加逻辑条件。 + + + **L1329** 汇总开放性限制:唯一可行惯常选项、不同内部理由、更广差异及有限评估策略独立性。 + + + **L1330** 在明确的双值候选类型中,要求可行性恰对应 identity。 + + + **L1331** 还保留恒等实现真实的输出理由选择依据。 + + + **L1332** 保留恒等实现两个真实地位事实均为 true。 + + + **L1333** 主张使用惯常与真实输出理由组成的列表可获得有理由选择;相关性来自输出理由。 + + + **L1334** 两个实现在每个输入返回相同实际输出。 + + + **L1335** 两者满足相同输出及预算可行性要求。 + + + **L1336** 要求同一真实恒等实现具有忠实解释理由。 + + + **L1337** 更改后的解释不满足同一相关性与内容检查。 + + + **L1338** 还保留恒等实现真实的输出理由选择依据。 + + + **L1339** 还要求恒等与后继实现在输入 0 产生不同真实输出。 + + + **L1340** 只在输入 0 范围下比较真实输出。 + + + **L1341** 另行要求输入 1 处真实输出不同。 + + + **L1342** 要求同一地位优先权评估具有程序表述与正确否定报告。 + + + **L1343** 保留所有候选解释为相同真实地位事实的模型。 + + + **L1344** 优先权谓词在 identity 处成立,在 successor 处失败。 + + + **L1345** 仅地位前提仍不蕴含优先主张。 + + + **L1346** 还拒绝只以既有地位作为真实理由选择恒等实现。 + + + **L1347** 两个策略共享同一准确评估,但实际优先理由不同;这不是对完整 Grounds 的独立性。 + + + **L1348** 使用六个已检查部分;generalGroundsNotChoice 只证明已披露的一般评估与选择策略分离。 + + + **L1350** 结束 CoreReader.Adopted;后续声明不再位于此命名空间。 + + +### `leanified/CoreReader/Agency.lean` + + +```lean +import CoreReader.Reflexivity + +namespace CoreReader.Agency + +inductive FormKind | organization | method | principle | appearance | artifact + deriving DecidableEq, Repr + +structure Form where + kind : FormKind + version : Nat + deriving DecidableEq, Repr + +inductive Aim | expandUnderstandingAndConstruction | preserveSafeOperation + deriving DecidableEq, Repr + +/- A policy records an adopted valuation, current forms, and permission. It does not assert that valuation is correct or enacted. -/ +structure Policy where + worthPursuing : Aim → Prop + current : Form → Prop + revisable : Form → Prop + permitsVersion : Nat → Nat → Prop + +/- The normative specification keeps valuation and revisability separate from realized transitions. -/ +def Generative (p : Policy) : Prop := + p.worthPursuing .expandUnderstandingAndConstruction ∧ + ∀ f, p.current f → p.revisable f + +def openPolicy : Policy where + worthPursuing a := a = .expandUnderstandingAndConstruction ∨ a = .preserveSafeOperation + current f := f.version = 0 + revisable _ := True + permitsVersion _ _ := True + +def neutralPolicy : Policy := { openPolicy with worthPursuing := fun _ => False } + +/- Permitting a real version change does not supply an adopted value position. -/ +theorem permissionNotValuation : + neutralPolicy.permitsVersion 0 1 ∧ (0 : Nat) ≠ 1 ∧ ¬ Generative neutralPolicy := by + simp [neutralPolicy, openPolicy, Generative] + +/- This is an explicit consequence of the adopted specification, not evidence of actual revision. -/ +theorem revisabilityCovers (p : Policy) (h : Generative p) (k : FormKind) (v : Nat) + (hc : p.current ⟨k, v⟩) : p.revisable ⟨k, v⟩ := h.2 _ hc + +inductive Operation | copy | successor + deriving DecidableEq, Repr + +def Operation.run : Operation → Nat → Nat + | .copy, n => n + | .successor, n => n + 1 + +inductive InventoryKind | document | term | tool | artifact + deriving DecidableEq, Repr + +structure Item where + kind : InventoryKind + content : Operation + deriving DecidableEq, Repr + +/- Available represented operations are the contents present, not their number of occurrences. -/ +def Available (xs : List Item) (op : Operation) : Prop := + ∃ item ∈ xs, item.content = op + +/- Duplicating any inventory category preserves exactly the represented operation content. -/ +theorem inventoryNotCapability (kind : InventoryKind) (ops : List Operation) (op : Operation) : + Available ((ops.map fun x => Item.mk kind x) ++ (ops.map fun x => Item.mk kind x)) op ↔ + Available (ops.map fun x => Item.mk kind x) op := by + simp only [Available, List.mem_append] + constructor + · rintro ⟨x, hx | hx, hop⟩ <;> exact ⟨x, hx, hop⟩ + · rintro ⟨x, hx, hop⟩ + exact ⟨x, Or.inl hx, hop⟩ + +structure State where + understood : List Operation + constructed : List Operation + inventory : List Item + abstractionLayers : List Operation + vocabulary : List Operation + deriving DecidableEq, Repr + +/- A gain must identify an operation newly understood or constructed; this is a disclosed finite capability representation. -/ +def Expanded (before after : State) : Prop := + (∃ op, op ∈ after.understood ∧ op ∉ before.understood) ∨ + (∃ op, op ∈ after.constructed ∧ op ∉ before.constructed) + +def baseState : State := + ⟨[.copy], [.copy], [⟨.artifact, .copy⟩], [.copy], [.copy]⟩ + +def inflatedState : State := + { baseState with + inventory := baseState.inventory ++ baseState.inventory + abstractionLayers := [.copy, .copy] + vocabulary := [.copy, .copy] } + +def stableTrace (_time : Nat) : State := baseState + +/- A revisable policy can govern an unchanged trace; no improvement is hidden in revisability. -/ +theorem revisionWithoutProgress : + Generative openPolicy ∧ + (∀ k : FormKind, openPolicy.revisable ⟨k, 0⟩) ∧ + (∀ t, ¬ Expanded (stableTrace t) (stableTrace (t + 1))) := by + simp [Generative, openPolicy, stableTrace, Expanded] + +structure ExternalResources where + experience : Option Nat + knowledge : Option Nat + collaborator : Option Nat + deriving DecidableEq, Repr + +/- This interpreter actually needs all three external inputs to produce the modeled result. -/ +def assistedExecution (r : ExternalResources) : Option Nat := do + let e ← r.experience + let k ← r.knowledge + let c ← r.collaborator + pure (Operation.copy.run (e + k + c)) + +def availableResources : ExternalResources := ⟨some 1, some 2, some 3⟩ + +/- Stability has a concrete stated reason in this workload: preserve its operation while staying within the one-item budget. -/ +def StableReason (before proposed : State) : Prop := + before.constructed = proposed.constructed ∧ + before.inventory.length ≤ 1 ∧ ¬ proposed.inventory.length ≤ 1 + +/- The policy, current capabilities, execution interface and workload constraints belong to one generating system. -/ +structure GeneratingSystem where + owner : Nat + policy : Policy + current : State + execute : ExternalResources → Option Nat + applicationBudget : Nat + requiredOperations : List Operation +/- The modeled system uses the assisted interpreter under a one-item budget and a copy-operation requirement. -/ +def generatingSystem : GeneratingSystem where + owner := 0 + policy := openPolicy + current := baseState + execute := assistedExecution + applicationBudget := 1 + requiredOperations := [.copy] +/- A stable action retains this system's own current state. -/ +def GeneratingSystem.stableAction (system : GeneratingSystem) : State := system.current +def GeneratingSystem.requirementsMet (system : GeneratingSystem) (state : State) : Prop := + ∀ operation, operation ∈ system.requiredOperations → operation ∈ state.constructed +def GeneratingSystem.withinBudget (system : GeneratingSystem) (state : State) : Prop := + state.inventory.length ≤ system.applicationBudget +/- An expansion report identifies the actual before/after states and the operation/performance it asserts was added. -/ +structure Announcement where + owner : Nat + before : State + after : State + reportedNewOperation : Operation + input : Nat + expectedOutput : Nat + deriving DecidableEq, Repr +/- Reports are generated by this system and identify its actual current state as their baseline. -/ +def GeneratingSystem.report (system : GeneratingSystem) (after : State) + (operation : Operation) (input expectedOutput : Nat) : Announcement := + ⟨system.owner, system.current, after, operation, input, expectedOutput⟩ +/- Report content is interpreted against those very states and the named operation's actual behavior. -/ +def Announcement.claim (report : Announcement) : Prop := + report.reportedNewOperation ∈ report.after.constructed ∧ + report.reportedNewOperation ∉ report.before.constructed ∧ + report.reportedNewOperation.run report.input = report.expectedOutput +/- A true report of this form entails a represented construction expansion. -/ +theorem announcementClaimImpliesExpansion (report : Announcement) (h : report.claim) : + Expanded report.before report.after := Or.inr ⟨report.reportedNewOperation, h.1, h.2.1⟩ +/- This concrete self-report asserts a successor operation for the actual inventory-only inflation. -/ +def inflatedAnnouncement : Announcement := generatingSystem.report inflatedState .successor 0 1 +/- The report asserts a real successor result but its named operation is absent from its own after-state. -/ +theorem inflatedAnnouncementRefuted : + inflatedAnnouncement.before = baseState ∧ inflatedAnnouncement.after = inflatedState ∧ + inflatedAnnouncement.reportedNewOperation = .successor ∧ + inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧ + ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after := by + simp [inflatedAnnouncement, GeneratingSystem.report, generatingSystem, Announcement.claim, Expanded, baseState, inflatedState] + +/- These transitions share one initial state; only extension adds an actual new operation. -/ +inductive TransitionCase | inflate | extend + deriving DecidableEq, Repr + +def extendedState : State := + { baseState with understood := [.copy, .successor], constructed := [.copy, .successor] } +def transitionBefore (_transition : TransitionCase) : State := baseState +def transitionAfter : TransitionCase → State + | .inflate => inflatedState + | .extend => extendedState +/- Both alternatives are assessed under the same concrete input condition. -/ +def transitionInput (_transition : TransitionCase) : Nat := 0 +def transitionAnnouncement (transition : TransitionCase) : Announcement := + generatingSystem.report (transitionAfter transition) .successor (transitionInput transition) 1 + +/- Eleven boundary branches share a content-bearing trace and executable dependency model. They do not assert a universal law of human capability. -/ +theorem generationLimits : + Generative generatingSystem.policy ∧ + generatingSystem.policy.permitsVersion 0 0 ∧ + ¬ Expanded generatingSystem.current inflatedState ∧ + generatingSystem.current.inventory.length < inflatedState.inventory.length ∧ + generatingSystem.current.abstractionLayers.length < inflatedState.abstractionLayers.length ∧ + generatingSystem.current.vocabulary.length < inflatedState.vocabulary.length ∧ + generatingSystem.execute availableResources = some 6 ∧ + generatingSystem.execute { availableResources with experience := none } = none ∧ + generatingSystem.execute { availableResources with knowledge := none } = none ∧ + generatingSystem.execute { availableResources with collaborator := none } = none ∧ + generatingSystem.execute ⟨none, none, none⟩ = none ∧ + ¬ Expanded generatingSystem.current generatingSystem.stableAction ∧ + generatingSystem.stableAction = generatingSystem.current ∧ + generatingSystem.requirementsMet generatingSystem.stableAction ∧ + generatingSystem.withinBudget generatingSystem.stableAction ∧ + ¬ generatingSystem.withinBudget inflatedState ∧ + StableReason generatingSystem.current inflatedState ∧ + (inflatedAnnouncement = generatingSystem.report inflatedState .successor 0 1 ∧ + inflatedAnnouncement.owner = generatingSystem.owner ∧ + inflatedAnnouncement.before = generatingSystem.current ∧ inflatedAnnouncement.after = inflatedState ∧ + inflatedAnnouncement.reportedNewOperation = .successor ∧ + inflatedAnnouncement.input = 0 ∧ inflatedAnnouncement.expectedOutput = 1 ∧ + ¬ inflatedAnnouncement.claim ∧ ¬ Expanded inflatedAnnouncement.before inflatedAnnouncement.after) := by + simp [generatingSystem, GeneratingSystem.stableAction, GeneratingSystem.requirementsMet, + GeneratingSystem.withinBudget, GeneratingSystem.report, Generative, openPolicy, Expanded, + baseState, inflatedState, assistedExecution, availableResources, Operation.run, + StableReason, inflatedAnnouncement, Announcement.claim] + +/- The empty work log omits an actually applicable system assessment despite an open generative policy. -/ +theorem generationNotReflexivity : + Generative openPolicy ∧ ¬ Reflexive 0 (ownRules 0) [] := by + constructor + · simp [Generative, openPolicy] + · intro h + have bad := noSelfExemption 0 (ownRules 0) [] h (assessingRule 0) (by simp [ownRules]) + (.system 0) rfl (by simp [assessingRule, ownSubjects]) + simp [Performed] at bad + +/- The same proposed arithmetic principle is used in the self-test and in the universal correctness claim. -/ +def ownArithmeticPrinciple (n : Nat) : Bool := decide (n + 1 = 2 * n) + +def selfTest (samples : List Nat) : Bool := samples.all ownArithmeticPrinciple + +/- A genuine evaluation on the selected sample succeeds, while the same principle fails at zero. -/ +theorem selfTestDoesNotProve : + selfTest [1] = true ∧ ownArithmeticPrinciple 0 = false ∧ + ¬ (∀ n, ownArithmeticPrinciple n = true) := by + constructor + · decide + constructor + · decide + · intro h + have bad := h 0 + contradiction + +end CoreReader.Agency +``` + + + + **L1** 导入CoreReader.Reflexivity及其依赖。 + + + **L3** 打开命名空间CoreReader.Agency;文件边界不改变声明身份。 + + + **L5** 定义组织、方法、原则、外观和产物五类形式标签。 + + + **L6** 为前述数据类型生成可判定相等及显示实例。 + + + **L8** 形式由种类标签和自然数版本构成,不包含内容或转换规则。 + + + **L9** 保存该形式属于组织、方法、原则、外观还是产物。 + + + **L10** 保存自然数形式版本,不证明变化已经发生。 + + + **L11** 为前述数据类型生成可判定相等及显示实例。 + + + **L13** 定义扩展理解与构造、保持安全运行两个目标标签;数据类型自身不为任一目标赋值。 + + + **L14** 为前述数据类型生成可判定相等及显示实例。 + + + **L16** 说明后续定义或结果:分别保存目标价值、当前形式、可修订形式和版本许可四个谓词。 + + + **L17** 分别保存目标价值、当前形式、可修订形式和版本许可四个谓词。 + + + **L18** 规定此政策把两个已表示目标中的哪些视为值得追求。 + + + **L19** 规定此政策当前持有的形式种类与版本对。 + + + **L20** 规定此政策保留哪些形式种类与版本对的可修订性。 + + + **L21** 独立于实际执行规定版本间许可。 + + + **L23** 说明后续定义或结果:要求视扩展为值得追求,且全部当前形式可修订;不承诺执行或进步。 + + + **L24** 要求视扩展为值得追求,且全部当前形式可修订;不承诺执行或进步。 + + + **L25** 要求该政策把理解与构造的扩展视为值得追求。 + + + **L26** 要求该政策当前持有的每个形式仍可修订。 + + + **L28** 重视两个目标,以版本零为当前形式,并允许所有修订和版本对。 + + + **L29** openPolicy同时重视扩展与保持安全运行。 + + + **L30** 把版本恰为0的形式视为当前形式,不限种类。 + + + **L31** 允许修订所有形式,包括当前未持有的形式。 + + + **L32** 允许任意两个版本号间的变更,但不执行变更。 + + + **L34** 保留开放政策许可,但把所有目标价值设为假。 + + + **L36** 说明后续定义或结果:实际允许不同版本零到一,同时缺少扩展价值取向,证明许可不充分。 + + + **L37** 实际允许不同版本零到一,同时缺少扩展价值取向,证明许可不充分。 + + + **L38** 陈述neutralPolicy允许0→1且两版本不同,但缺少价值取向使Generative失败。 + + + **L39** 展开两个政策:许可为真,0≠1可计算为真,所需价值取向为假。 + + + **L41** 说明后续定义或结果:将已假定的生成规范实例化到指定当前种类与版本,不执行修订。 + + + **L42** 将已假定的生成规范实例化到指定当前种类与版本,不执行修订。 + + + **L43** 将h中的可修订条款应用于hc确认是当前形式的同一种类与版本。 + + + **L45** 只定义自然数恒等和后继两种操作。 + + + **L46** 为前述数据类型生成可判定相等及显示实例。 + + + **L48** 按构造器计算恒等或加一输出。 + + + **L49** 执行copy直接返回原输入。 + + + **L50** 执行successor返回输入加1。 + + + **L52** 定义文档、术语、工具、产物四个库存标签。 + + + **L53** 为前述数据类型生成可判定相等及显示实例。 + + + **L55** 库存项保存种类标签及两种操作之一。 + + + **L56** 把库存条目分类为文档、术语、工具或产物。 + + + **L57** 记录条目表示的操作,与其类别分开。 + + + **L58** 为前述数据类型生成可判定相等及显示实例。 + + + **L60** 说明后续定义或结果:存在库存成员携带指定操作即为可用;重复次数不影响此条件。 + + + **L61** 存在库存成员携带指定操作即为可用;重复次数不影响此条件。 + + + **L62** 只有存在包含该操作的列表条目,该操作才可用。 + + + **L64** 说明后续定义或结果:通过双向复用同一成员见证,证明复制任一种类库存不会新增可用操作。 + + + **L65** 通过双向复用同一成员见证,证明复制任一种类库存不会新增可用操作。 + + + **L66** 检查把ops按固定类别包装并复制列表后的操作可用性。 + + + **L67** 将其与同一列表未复制时的可用性比较。 + + + **L68** 展开可用性,把复制列表成员关系化为属于任一副本。 + + + **L69** 分别证明复制既不增加也不减少已表示的操作。 + + + **L70** 任一副本中的条目都可作为原列表中同一操作的见证。 + + + **L71** 反向证明取原条目x、成员证明hx及内容匹配证明hop。 + + + **L72** 把同一条目放在第一副本中,保持操作匹配。 + + + **L74** 用五个列表分别表示理解、构造、库存、抽象层级和词汇。 + + + **L75** 列出该状态中表示为已理解的操作。 + + + **L76** 列出该状态中表示为已构造的操作。 + + + **L77** 保存库存条目;条目重复数量与能力成员关系不同。 + + + **L78** 保存抽象层级条目,不把数量等同理解能力。 + + + **L79** 保存词汇条目,不把数量等同构造能力。 + + + **L80** 为前述数据类型生成可判定相等及显示实例。 + + + **L82** 说明后续定义或结果:理解或构造列表新增至少一个先前没有的操作;不要求其他能力都保留。 + + + **L83** 理解或构造列表新增至少一个先前没有的操作;不要求其他能力都保留。 + + + **L84** 扩展可由变化后已理解、变化前未理解的操作见证。 + + + **L85** 另一种扩展见证是新增的已构造操作。 + + + **L87** 构造只含copy操作、一个copy产物的初始状态。 + + + **L88** 基线理解并构造copy,且各有一个copy产物、层级和词汇条目。 + + + **L90** 只复制库存、层级和词汇,理解与构造列表保持原样。 + + + **L91** 以baseState为起点,保留下面未覆盖的字段。 + + + **L92** 复制单条库存,但保持已理解和已构造操作不变。 + + + **L93** 将一个抽象层级条目改为两个copy条目。 + + + **L94** 同样把词汇列表加倍,不引入新操作。 + + + **L96** 每个时刻都返回同一初始状态。 + + + **L98** 说明后续定义或结果:生成规范和全面可修订性与常值、无扩展轨迹相容。 + + + **L99** 生成规范和全面可修订性与常值、无扩展轨迹相容。 + + + **L100** 陈述openPolicy满足所采纳的价值取向与可修订规范。 + + + **L101** 另明确每类形式的版本0均可修订。 + + + **L102** 常值轨迹中任意相邻状态都没有新增理解或构造操作。 + + + **L103** 把政策条款化为真,把每项扩展化为未变列表中不可能的新增成员。 + + + **L105** 保存经验、知识和协作者三个可缺失自然数槽。 + + + **L106** 可选外部经验值;none会使辅助执行在首次读取时失败。 + + + **L107** 继经验输入后必须取得的可选知识值。 + + + **L108** 产生结果前必须取得的可选协作者值。 + + + **L109** 为前述数据类型生成可判定相等及显示实例。 + + + **L111** 说明后续定义或结果:依次读取三个Option槽;全部存在时返回总和,任一缺失时返回none。 + + + **L112** 依次读取三个Option槽;全部存在时返回总和,任一缺失时返回none。 + + + **L113** 将经验读入e,若资源缺失则立即返回none。 + + + **L114** 将知识读入k,缺失则终止同一个Option计算。 + + + **L115** 将协作者值读入c,同样传递缺失结果。 + + + **L116** 通过copy操作返回e+k+c之和,并包装为some。 + + + **L118** 提供一、二、三三个实际资源值。 + + + **L120** 说明后续定义或结果:要求构造列表相同、原库存至多一项而拟议库存超限。 + + + **L121** 要求构造列表相同、原库存至多一项而拟议库存超限。 + + + **L122** 保留旧状态的理由之一是两状态具有完全相同的已构造操作。 + + + **L123** 旧库存必须满足单条限制,而拟议库存超过该限制。 + + + **L125** 说明后续定义或结果:把同一主体的政策、当前状态、资源执行函数、预算和所需操作绑定成系统。 + + + **L126** 把同一主体的政策、当前状态、资源执行函数、预算和所需操作绑定成系统。 + + + **L127** 标识该生成系统的所有者。 + + + **L128** 把价值取向与可修订政策附于同一系统。 + + + **L129** 保存系统当前的能力与库存表示状态。 + + + **L130** 保存该系统实际消耗资源的执行函数。 + + + **L131** 规定评估稳定状态和拟议状态的库存数量预算。 + + + **L132** 规定工作负载要求保持已构造的操作。 + + + **L133** 说明后续定义或结果:主体零采用开放政策、初始状态、三资源执行、预算一和copy要求。 + + + **L134** 主体零采用开放政策、初始状态、三资源执行、预算一和copy要求。 + + + **L135** 给具体生成系统分配所有者编号0。 + + + **L136** 在同一具体系统中采用openPolicy。 + + + **L137** 将其当前能力和库存设为baseState。 + + + **L138** 以需要三种资源的辅助解释器作为该系统执行接口。 + + + **L139** 把该工作负载的库存预算定为恰好1条。 + + + **L140** 要求具体工作负载保留copy操作。 + + + **L141** 说明后续定义或结果:以该系统当前状态作为保持稳定的动作结果。 + + + **L142** 以该系统当前状态作为保持稳定的动作结果。 + + + **L143** 检查同一系统要求的每个操作都在被评状态构造列表中。 + + + **L144** 对该系统和待评状态,所有必需操作都必须属于状态的已构造列表。 + + + **L145** 按该系统明示预算检查被评状态库存长度。 + + + **L146** 用同一系统声明的应用预算检查该状态的库存数量。 + + + **L147** 说明后续定义或结果:保存报告主体、精确前后状态、声称新增操作、输入和期望输出。 + + + **L148** 保存报告主体、精确前后状态、声称新增操作、输入和期望输出。 + + + **L149** 记录该扩展公告的所有者。 + + + **L150** 保存公告指定的确切基线状态。 + + + **L151** 保存公告指定的确切结果状态。 + + + **L152** 指定声称新增构造的操作。 + + + **L153** 固定公告声称该操作表现所用的输入。 + + + **L154** 保存该操作在指定输入上的声称输出。 + + + **L155** 为前述数据类型生成可判定相等及显示实例。 + + + **L156** 说明后续定义或结果:用本系统主体和当前状态构造对应拟议状态及操作合同的报告。 + + + **L157** 用本系统主体和当前状态构造对应拟议状态及操作合同的报告。 + + + **L158** 接收该报告声称新增的操作及具体输入输出对。 + + + **L159** 以系统所有者和当前基线构造报告,并填入给定后状态与主张数据。 + + + **L160** 说明后续定义或结果:要求声称操作在后状态中新出现,并在指定输入产生期望输出。 + + + **L161** 要求声称操作在后状态中新出现,并在指定输入产生期望输出。 + + + **L162** 报告所称新增操作必须实际属于公告的后状态。 + + + **L163** 同一操作必须不属于公告基线的已构造列表。 + + + **L164** 该操作在报告输入上的实际运行必须等于声称输出。 + + + **L165** 说明后续定义或结果:从已成立报告中抽取新构造操作,作为扩展的存在见证。 + + + **L166** 从已成立报告中抽取新构造操作,作为扩展的存在见证。 + + + **L167** 用主张中的后状态成员关系与前状态缺失关系构造Expanded的构造分支。 + + + **L168** 说明后续定义或结果:系统对仅库存膨胀的状态报告零输入上的新增successor。 + + + **L169** 系统对仅库存膨胀的状态报告零输入上的新增successor。 + + + **L170** 说明后续定义或结果:核实报告对象后计算其新增操作主张及实际扩展均不成立。 + + + **L171** 核实报告对象后计算其新增操作主张及实际扩展均不成立。 + + + **L172** 确认具体公告所指正是baseState与inflatedState。 + + + **L173** 确认声称新增操作是successor。 + + + **L174** 确认公告中的测试输入是0、预期输出是1。 + + + **L175** 陈述公告实质主张失败,且公告自身的状态对没有扩展。 + + + **L176** 计算报告字段和未变能力列表;即使successor的0→1表现正确,后状态仍没有该操作。 + + + **L178** 说明后续定义或结果:成就模型仅含库存膨胀与实际操作扩展两个候选变化。 + + + **L179** 成就模型仅含库存膨胀与实际操作扩展两个候选变化。 + + + **L180** 为前述数据类型生成可判定相等及显示实例。 + + + **L182** 在初始状态的理解和构造列表中添加successor。 + + + **L183** 在理解与构造列表中同时加入successor,保留基线其他字段。 + + + **L184** 两种模型变化使用同一个初始状态基线。 + + + **L185** 按变化类别选择库存膨胀或能力扩展后状态。 + + + **L186** inflate转移以仅膨胀库存的状态结束。 + + + **L187** extend转移以新增理解和构造successor的状态结束。 + + + **L188** 说明后续定义或结果:两种变化都明确使用零作为测试输入。 + + + **L189** 两种变化都明确使用零作为测试输入。 + + + **L190** 对同一系统及指定后状态报告successor在零处输出一。 + + + **L191** 两种转移都在共同输入0上公告successor,但各自指定实际后状态。 + + + **L193** 说明后续定义或结果:在绑定系统上核实数量不增能力、外援依赖、有根据稳定动作和同对象虚假成就报告等全部分支。 + + + **L194** 在绑定系统上核实数量不增能力、外援依赖、有根据稳定动作和同对象虚假成就报告等全部分支。 + + + **L195** 具体系统仍满足所采纳的生成政策。 + + + **L196** 其政策允许保持版本0,因此生成取向不要求每次行动都改变版本。 + + + **L197** 膨胀该系统库存不会扩展其已表示能力。 + + + **L198** 膨胀状态的库存条目严格多于该系统当前状态。 + + + **L199** 抽象层级数也严格增加,却没有能力扩展。 + + + **L200** 在能力内容保持不变时,词汇条目数严格增加。 + + + **L201** 资源为1、2、3时,该系统执行实际返回some 6。 + + + **L202** 从同一资源包移除经验,使该系统执行失败。 + + + **L203** 单独移除知识,同样使其执行返回none。 + + + **L204** 单独移除协作者输入,也使执行失败。 + + + **L205** 三种外部输入均缺失时,同一执行接口返回none。 + + + **L206** 系统稳定动作不产生已表示能力扩展。 + + + **L207** 该稳定动作恰为保持系统当前状态。 + + + **L208** 保持当前状态可保留工作负载必需的copy操作。 + + + **L209** 保留的单条状态满足该系统1条的应用预算。 + + + **L210** 复制后库存有2条,超过同一系统的1条预算。 + + + **L211** 稳定具有所述理由:构造内容未变,但只有当前状态满足预算。 + + + **L212** 确认该报告由此系统针对inflatedState、successor、输入0和输出1构造。 + + + **L213** 报告所有者等于该生成系统的所有者。 + + + **L214** 报告以该系统当前状态为基线,以inflatedState为结果。 + + + **L215** 此实际报告称为新增的操作是successor。 + + + **L216** 报告声称的表现仍是具体的0→1。 + + + **L217** 尽管存在该报告,其主张仍为假,其自身前后状态也没有能力扩展。 + + + **L218** 展开具体系统、保持动作和必需操作检查,开始计算generationLimits各条款。 + + + **L219** 再展开单条预算、报告构造器和政策及扩展谓词,使主张化为具体数据。 + + + **L220** 用实际基线及膨胀列表和三资源解释器,判定数量、成员关系和执行结果。 + + + **L221** 最后展开稳定理由与自有公告主张,通过计算完成全部合取分支。 + + + **L223** 说明后续定义或结果:开放政策满足生成规范,但空记录无法履行非空自身规则的评估要求。 + + + **L224** 开放政策满足生成规范,但空记录无法履行非空自身规则的评估要求。 + + + **L225** 将openPolicy的生成取向与空工作日志下的自有反身履责失败组合。 + + + **L226** 分别证明生成取向,并反驳空日志的Reflexive主张。 + + + **L227** 计算openPolicy的扩展价值取向与无条件可修订性。 + + + **L228** 反证假设空日志满足自有反身契约。 + + + **L229** 对已登记assessingRule应用无自我豁免定理,从假设的空日志履责迫出已执行评估。 + + + **L230** 选取所有者匹配的系统自身,并证明该评估对它适用。 + + + **L231** 展开Performed后得到空工作列表中不可能存在的成员。 + + + **L233** 说明后续定义或结果:计算自然数等式n+1=2*n是否成立。 + + + **L234** 计算自然数等式n+1=2*n是否成立。 + + + **L236** 逐个检验给定样本上的算术谓词,不检查样本外输入。 + + + **L238** 说明后续定义或结果:样本一通过而零失败,反驳从有限自测得到全称正确性。 + + + **L239** 样本一通过而零失败,反驳从有限自测得到全称正确性。 + + + **L240** 同一算术原则在样本1上通过,却在0上为假。 + + + **L241** 因此该原则并非对所有自然数输入都返回true。 + + + **L242** 将通过样本的计算与两项失败主张分开。 + + + **L243** 计算单样本:1+1等于2×1,故selfTest [1]为true。 + + + **L244** 把0处的具体失败与普遍成功的反驳分开。 + + + **L245** 计算0+1≠2×0,使ownArithmeticPrinciple 0为false。 + + + **L246** 假设同一原则对每个输入都成功。 + + + **L247** 把该普遍假设实例化到输入0。 + + + **L248** 与0处计算所得false矛盾,反驳普遍正确性。 + + + **L250** 关闭当前命名空间。 + + +### `leanified/CoreReader/Choice.lean` + + +```lean +import CoreReader.Evidence + +namespace CoreReader.Choice +open CoreReader.Logic CoreReader.Evidence + +inductive StatusKind | name | convention | standing + deriving DecidableEq, Repr + +inductive MethodReason | output | explanation | applicability | simplicity | procedure + deriving DecidableEq, Repr + +inductive Reason | status (kind : StatusKind) | method (kind : MethodReason) + deriving DecidableEq, Repr + +/- An implementation has observable behavior, a stated domain, an explanation formula and an execution trace. -/ +structure Implementation where + name : String + conventional : Bool + established : Bool + run : Nat → Nat + cost : Nat + domain : Nat → Prop + explanation : Nat → Nat + trace : Nat → List Nat + +/- An application selects relevant objectives and constraints; no universal ranking or score is prescribed. -/ +structure Requirements where + inputs : Nat → Prop + expected : Nat → Nat + budget : Nat + values : MethodReason → Prop + +/- These are explicit, content-based interpretations of possible method reasons in this application. -/ +def MethodContent (req : Requirements) (i : Implementation) : MethodReason → Prop + | .output => ∀ x, req.inputs x → i.run x = req.expected x + | .explanation => ∀ x, req.inputs x → i.explanation x = i.run x + | .applicability => ∀ x, req.inputs x → i.domain x + | .simplicity => i.cost ≤ req.budget + | .procedure => ∀ x, req.inputs x → (i.trace x).getLast? = some (i.run x) + +/- The extra choice commitment requires both selected relevance and actual reason content; pure status supplies neither. -/ +def Relevant (req : Requirements) (i : Implementation) : Reason → Prop + | .status _ => False + | .method kind => req.values kind ∧ MethodContent req i kind + +def Feasible (req : Requirements) (i : Implementation) : Prop := + (∀ x, req.inputs x → i.run x = req.expected x) ∧ i.cost ≤ req.budget + +/- In this application, a relevant reason is eligible only after its stated output and budget requirements hold. -/ +def JustifiedChoice (req : Requirements) (i : Implementation) (reasons : List Reason) : Prop := + Feasible req i ∧ ∃ reason ∈ reasons, Relevant req i reason + +/- This proves the structural effect of the adopted choice commitment for each of its three status-only cases. -/ +theorem statusOnlyFails (req : Requirements) (i : Implementation) (k : StatusKind) : + ¬ JustifiedChoice req i [.status k] := by + rintro ⟨_, reason, hr, hv⟩ + simp only [List.mem_singleton] at hr + subst reason + exact hv + +def identityImpl : Implementation where + name := "Existing identity implementation" + conventional := true + established := true + run n := n + cost := 1 + domain _ := True + explanation n := n + trace n := [n] + +def successorImpl : Implementation where + name := "Successor implementation" + conventional := false + established := false + run n := n + 1 + cost := 2 + domain _ := True + explanation n := n + 1 + trace n := [n, n + 1] + +def changedOutsideZero : Implementation := + { identityImpl with + name := "Changed outside zero" + conventional := false + established := false + run := fun n => if n = 0 then 0 else n + 1 + explanation := fun n => if n = 0 then 0 else n + 1 + trace := fun n => [if n = 0 then 0 else n + 1] } + +def identityRequirements : Requirements where + inputs _ := True + expected n := n + budget := 1 + values _ := True + +def objectiveReason : List Reason := [.method .output] + +theorem identityOutputReason : Relevant identityRequirements identityImpl (.method .output) := by + exact ⟨trivial, fun _ _ => rfl⟩ + +theorem identityFeasible : Feasible identityRequirements identityImpl := + ⟨fun _ _ => rfl, by decide⟩ + +theorem identityJustified : JustifiedChoice identityRequirements identityImpl objectiveReason := + ⟨identityFeasible, .method .output, by simp [objectiveReason], identityOutputReason⟩ + +/- A conventional existing implementation can be selected for an actual requirement, not for status alone. -/ +theorem conventionWithReason : + identityImpl.conventional = true ∧ identityImpl.established = true ∧ + JustifiedChoice identityRequirements identityImpl [.status .convention, .method .output] := by + exact ⟨rfl, rfl, identityFeasible, .method .output, by simp, identityOutputReason⟩ + +inductive Candidate | identity | successor + deriving DecidableEq, Repr + +def implementation : Candidate → Implementation + | .identity => identityImpl + | .successor => successorImpl + +/- Feasibility is decided by the same stated behavior and resource requirement for either candidate. -/ +theorem singleFeasible : + (∀ candidate, Feasible identityRequirements (implementation candidate) ↔ candidate = .identity) ∧ + JustifiedChoice identityRequirements identityImpl objectiveReason := by + constructor + · intro candidate + cases candidate + · simp [Feasible, identityRequirements, implementation, identityImpl] + · simp [Feasible, identityRequirements, implementation, successorImpl] + · exact identityJustified + +/- The same observed input can conceal a relevant difference at another input. -/ +theorem localNotGlobal : + (∀ x, x = 0 → identityImpl.run x = changedOutsideZero.run x) ∧ + identityImpl.run 1 ≠ changedOutsideZero.run 1 := by + constructor + · intro x hx; subst x; rfl + · decide + +/- This candidate is cheap enough but misses the required identity output. -/ +def cheapSuccessor : Implementation := { successorImpl with cost := 1 } + +theorem eligibleInternalReasonNotSufficient : + Relevant identityRequirements cheapSuccessor (.method .simplicity) ∧ + ¬ JustifiedChoice identityRequirements cheapSuccessor [.method .simplicity] := by + refine ⟨⟨trivial, by change 1 ≤ 1; decide⟩, ?_⟩ + intro h + have bad := h.1.1 0 trivial + cases bad + +/- Each of the four internal-method reasons is eligible because of its actual selected requirement and content. -/ +theorem internalReasons : + Relevant identityRequirements identityImpl (.method .explanation) ∧ + Relevant identityRequirements identityImpl (.method .applicability) ∧ + Relevant identityRequirements identityImpl (.method .simplicity) ∧ + Relevant identityRequirements identityImpl (.method .procedure) ∧ + (Relevant identityRequirements cheapSuccessor (.method .simplicity) ∧ + ¬ JustifiedChoice identityRequirements cheapSuccessor [.method .simplicity]) := by + exact ⟨⟨trivial, fun _ _ => rfl⟩, ⟨trivial, fun _ _ => trivial⟩, + ⟨trivial, by change 1 ≤ 1; decide⟩, ⟨trivial, fun _ _ => rfl⟩, eligibleInternalReasonNotSufficient⟩ + +/- Openness about reasons does not make two actual behaviors identical or reject the existing implementation. -/ +theorem openNotEquivalent : + JustifiedChoice identityRequirements identityImpl objectiveReason ∧ + identityImpl.run 0 ≠ successorImpl.run 0 := by + exact ⟨identityJustified, by decide⟩ + +/- A priority interpretation chooses one of the same two actual implementations. -/ +def priorityClaim : Claim Candidate := fun selected => selected = .identity + +def statusFacts : Theory Candidate := union + (singleton (fun _ => identityImpl.conventional = true)) + (singleton (fun _ => identityImpl.established = true)) + +/- Both interpretations have exactly the same true conventional and established status facts. -/ +theorem statusFactsModel (selected : Candidate) : Models statusFacts selected := by + exact (modelsUnion _ _ _).2 ⟨(modelsSingleton _ _).2 rfl, (modelsSingleton _ _).2 rfl⟩ + +def priorityArticulation : Articulation Candidate := + ⟨["priority", "conventional use", "established status"], statusFacts, + [fun _ => identityImpl.conventional = true, fun _ => identityImpl.established = true], + fun _ => True⟩ + +/- This procedure reports whether the actual status premises entail that very priority claim over its stated two-candidate scope. -/ +def AssessmentAccurate (report : Bool) : Prop := + report = true ↔ Entails statusFacts priorityClaim + +theorem statusDoesNotEntailPriority : ¬ Entails statusFacts priorityClaim := by + intro h + have bad := h .successor (statusFactsModel .successor) + cases bad + +theorem statusAssessmentNonEntailment : + Articulated priorityArticulation ∧ AssessmentAccurate false ∧ + (∀ selected, Models statusFacts selected) ∧ + priorityClaim .identity ∧ ¬ priorityClaim .successor ∧ + ¬ Entails statusFacts priorityClaim ∧ + ¬ JustifiedChoice identityRequirements identityImpl [.status .standing] := by + refine ⟨⟨by simp [priorityArticulation], by simp [priorityArticulation]⟩, + ⟨(by intro h; cases h), (fun h => False.elim (statusDoesNotEntailPriority h))⟩, + statusFactsModel, rfl, (by intro h; cases h), statusDoesNotEntailPriority, + statusOnlyFails _ _ _⟩ + +/- An assessment identifies the exact premises and priority question whose entailment it reports. -/ +structure PriorityAssessment where + premises : Theory Candidate + question : Claim Candidate + report : Bool +/- Accuracy concerns the actual reported entailment question, independently of a later choice policy. -/ +def PriorityAssessment.accurate (assessment : PriorityAssessment) : Prop := + assessment.report = true ↔ Entails assessment.premises assessment.question +/- Both policies receive this same correctly negative status-only priority audit. -/ +def statusPriorityAudit : PriorityAssessment := ⟨statusFacts, priorityClaim, false⟩ +/- Priority reasons are a policy component independent of the assessment's report and objects. -/ +structure ChoicePolicy where + selected : Candidate + priorityReasons : List Reason + assessment : PriorityAssessment +/- This is completion of the specified assessment procedure only, not full compliance with philosophical Grounds. -/ +def GeneralAssessmentFulfilled (policy : ChoicePolicy) : Prop := + Articulated priorityArticulation ∧ policy.assessment = statusPriorityAudit ∧ policy.assessment.accurate +/- The additional choice norm separately tests the reasons actually used to prioritize the selected implementation. -/ +def AdditionalChoiceNorm (policy : ChoicePolicy) : Prop := + JustifiedChoice identityRequirements (implementation policy.selected) policy.priorityReasons +/- This policy retains status alone as its priority reason despite receiving the correctly negative status audit. -/ +def statusPriorityPolicy : ChoicePolicy := ⟨.identity, [.status .standing], statusPriorityAudit⟩ +/- This policy selects the same implementation using its actual relevant output reason after the same audit. -/ +def outputPriorityPolicy : ChoicePolicy := ⟨.identity, objectiveReason, statusPriorityAudit⟩ +/- The shared negative result is mathematically accurate for its actual status premises and question. -/ +theorem statusPriorityAuditAccurate : statusPriorityAudit.accurate := by + constructor + · intro h; cases h + · intro h; exact False.elim (statusDoesNotEntailPriority h) +/- These independently variable policies share facts, selected implementation and completed audit, but differ on the extra choice norm. -/ +def PolicyIndependenceExample : Prop := + statusPriorityPolicy.selected = outputPriorityPolicy.selected ∧ + statusPriorityPolicy.assessment = outputPriorityPolicy.assessment ∧ + statusPriorityPolicy.assessment.premises = statusFacts ∧ + statusPriorityPolicy.assessment.question = priorityClaim ∧ + statusPriorityPolicy.assessment.report = false ∧ + (∀ selected, Models statusPriorityPolicy.assessment.premises selected) ∧ + statusPriorityPolicy.priorityReasons ≠ outputPriorityPolicy.priorityReasons ∧ + GeneralAssessmentFulfilled statusPriorityPolicy ∧ GeneralAssessmentFulfilled outputPriorityPolicy ∧ + ¬ AdditionalChoiceNorm statusPriorityPolicy ∧ AdditionalChoiceNorm outputPriorityPolicy +/- Changing the actual priority reasons changes choice compliance while the accurate audit remains identical. -/ +theorem policyIndependenceExample : PolicyIndependenceExample := by + have articulated : Articulated priorityArticulation := + ⟨by simp [priorityArticulation], by simp [priorityArticulation]⟩ + refine ⟨rfl,rfl,rfl,rfl,rfl,statusFactsModel,?_, + ⟨articulated,rfl,statusPriorityAuditAccurate⟩, + ⟨articulated,rfl,statusPriorityAuditAccurate⟩,?_,?_⟩ + · decide + · exact statusOnlyFails identityRequirements identityImpl .standing + · exact identityJustified + +/- A correctly articulated, completed negative assessment does not enforce the additional selection rule. +This is only independence from represented assessment procedures: keeping this unsupported priority would fail general support proportionality too. -/ +theorem generalGroundsNotChoice : + (Articulated priorityArticulation ∧ AssessmentAccurate false ∧ + (∀ selected, Models statusFacts selected) ∧ + priorityClaim .identity ∧ ¬ priorityClaim .successor ∧ + ¬ Entails statusFacts priorityClaim ∧ + ¬ JustifiedChoice identityRequirements identityImpl [.status .standing]) ∧ + PolicyIndependenceExample := + ⟨statusAssessmentNonEntailment, policyIndependenceExample⟩ + +end CoreReader.Choice +``` + + + + **L1** 导入 CoreReader.Evidence,使其已检查声明可供本模块使用;这一行不提出新的哲学结论。 + + + **L3** 打开命名空间 CoreReader.Choice,使后续声明获得这一模块限定名。 + + + **L4** 允许不加限定使用 CoreReader.Logic CoreReader.Evidence 中的名称;这改变名称解析,不增加假设。 + + + **L6** 声明可选构造 StatusKind。定义名称、惯用性和既有地位三类身份理由标签。 + + + **L7** 为这些有限构造子派生可判定相等与可打印表示;它们是计算便利,不是选择判据。 + + + **L9** 声明可选构造 MethodReason。定义输出、解释、适用性、简洁性和流程五类方法理由。 + + + **L10** 为这些有限构造子派生可判定相等与可打印表示;它们是计算便利,不是选择判据。 + + + **L12** 声明可选构造 Reason。将身份理由与方法理由区分为不同构造器。 + + + **L13** 为这些有限构造子派生可判定相等与可打印表示;它们是计算便利,不是选择判据。 + + + **L15** 说明 Implementation 的预定范围。对应声明涉及:分别保存名称和状态标记、输出、成本、域、解释函数与轨迹。 该注释用于解释,不是证明前提。 + + + **L16** 声明数据接口 Implementation。分别保存名称和状态标记、输出、成本、域、解释函数与轨迹。 + + + **L17** 保存实现的描述性名称,不赋予优先权。 + + + **L18** 以布尔地位事实记录实现是否惯常。 + + + **L19** 记录实现是否已经确立,与真实行为独立。 + + + **L20** 保存真实自然数输入与输出函数。 + + + **L21** 保存将按应用预算检查的成本。 + + + **L22** 以输入上的谓词保存实现所述适用域。 + + + **L23** 保存将与真实运行结果比较的解释输出内容。 + + + **L24** 保存按输入索引的执行轨迹,其最后元素可与真实输出比较。 + + + **L26** 说明 Requirements 的预定范围。对应声明涉及:保存输入域、期望输出、预算及重视的方法理由类别。 该注释用于解释,不是证明前提。 + + + **L27** 声明数据接口 Requirements。保存输入域、期望输出、预算及重视的方法理由类别。 + + + **L28** 规定应用实际要求哪些输入。 + + + **L29** 规定各输入的预期输出。 + + + **L30** 规定应用预算约束。 + + + **L31** 规定该应用重视哪些方法理由类别;这一选择是被采纳的输入。 + + + **L33** 说明 MethodContent 的预定范围。对应声明涉及:按方法类别检查实际输出、解释等同、域覆盖、成本或轨迹末项合同。 该注释用于解释,不是证明前提。 + + + **L34** 定义 MethodContent。按方法类别检查实际输出、解释等同、域覆盖、成本或轨迹末项合同。 + + + **L35** 输出理由要求该实现真实输出在每个必需输入上等于应用预期输出。 + + + **L36** 解释理由要求解释输出在每个必需输入上匹配同一实现真实运行。 + + + **L37** 适用性理由要求每个应用必需输入属于该实现的适用域。 + + + **L38** 简单性理由为所选应用真实的成本不超预算条件。 + + + **L39** 过程理由要求真实轨迹末元素在每个必需输入上等于该实现真实输出。 + + + **L41** 说明 Relevant 的预定范围。对应声明涉及:身份理由被已采纳规范排除;方法理由必须被重视并满足其对应合同。 该注释用于解释,不是证明前提。 + + + **L42** 定义 Relevant。身份理由被已采纳规范排除;方法理由必须被重视并满足其对应合同。 + + + **L43** 在这一被采纳选择规范下,地位理由被定义为不相关,不依赖其地位子类。 + + + **L44** 方法理由必须同时属于这些要求所重视的类别,并满足该类别真实 MethodContent。 + + + **L46** 定义 Feasible。同时要求指定输入上的输出正确及成本不超预算。 + + + **L47** 可行性要求每个必需输入的真实输出正确,且真实成本不超过应用预算。 + + + **L49** 说明 JustifiedChoice 的预定范围。对应声明涉及:同时要求输出和预算可行,以及至少一个列出的、被重视且内容成立的方法理由。 该注释用于解释,不是证明前提。 + + + **L50** 定义 JustifiedChoice。同时要求输出和预算可行,以及至少一个列出的、被重视且内容成立的方法理由。 + + + **L51** 要求可行性及至少一个实际列出的相关理由;仅有相关理由不确立可行性。 + + + **L53** 说明 statusOnlyFails 的预定范围。对应声明涉及:纯身份理由的相关性定义为假,故任何实现都不能仅凭它获得规范内正当选择。 该注释用于解释,不是证明前提。 + + + **L54** 陈述经检查的结果 statusOnlyFails。纯身份理由的相关性定义为假,故任何实现都不能仅凭它获得规范内正当选择。 + + + **L55** 对给定任意要求与实现,否定唯一列出理由为地位时的有理由选择。 + + + **L56** 拆解假定的仅凭地位的有理由选择,提取所列理由及相关性证明;仅有可行性不能提供缺失的相关性。 + + + **L57** 化简单元素成员关系,说明提取的理由恰为给定地位理由。 + + + **L58** 把确定的地位理由代入假定的相关性证明。 + + + **L59** 地位理由的相关性被定义为 False,因此提取出的 hv 已是矛盾。 + + + **L61** 定义 identityImpl。构造既有惯用恒等实现:成本一、全域、对应解释和单项轨迹。 + + + **L62** 命名具体既有恒等实现,不用名称证明质量。 + + + **L63** 把恒等实现的惯常与既有地位标记为 true;这些事实仍与真实方法理由不同。 + + + **L64** 把恒等实现的惯常与既有地位标记为 true;这些事实仍与真实方法理由不同。 + + + **L65** 把真实恒等输出定义为未改变的输入 n。 + + + **L66** 把恒等实现真实成本设为 1。 + + + **L67** 使恒等实现适用域包含全部自然数输入。 + + + **L68** 提供等于输入的解释结果,与恒等实现真实输出匹配。 + + + **L69** 以单元素输入作为真实轨迹,其最后元素等于恒等输出。 + + + **L71** 定义 successorImpl。构造后继实现:成本二、全域、对应解释及两项轨迹。 + + + **L72** 命名替代的后继实现。 + + + **L73** 在该例中把后继实现标记为既非惯常也非既有;这一地位本身不决定可行性。 + + + **L74** 在该例中把后继实现标记为既非惯常也非既有;这一地位本身不决定可行性。 + + + **L75** 把后继实现真实输出定义为 n+1。 + + + **L76** 把其原始成本设为 2,高于恒等应用预算 1。 + + + **L77** 使后继实现适用域也包含每个自然数输入。 + + + **L78** 提供其解释结果 n+1,忠实于自身真实输出。 + + + **L79** 在轨迹中记录输入及之后的真实后继输出。 + + + **L81** 定义 changedOutsideZero。复制恒等实现但令非零输入改为后继,零点仍相同。 + + + **L82** 从 identityImpl 的字段出发,明确覆盖后续组件。 + + + **L83** 按其在零输入以外的变化命名修改后实现。 + + + **L84** 把修改后实现的惯常与既有标记改为 false。 + + + **L85** 把修改后实现的惯常与既有标记改为 false。 + + + **L86** 在输入 0 保持输出 0,其余输入均返回 n+1。 + + + **L87** 使其解释遵循相同真实分段输出函数。 + + + **L88** 以相同分段结果作为单元素轨迹,完成实现覆盖。 + + + **L90** 定义 identityRequirements。要求所有自然数输入保持恒等,预算一,重视全部方法理由。 + + + **L91** 恒等应用要求全部自然数输入。 + + + **L92** 把期望输出设为未改变的输入。 + + + **L93** 为应用采纳预算 1。 + + + **L94** 接纳全部已表示的方法理由类别,仍须检查其真实内容。 + + + **L96** 定义 objectiveReason。理由清单只包含输出合同这一方法类别。 + + + **L98** 陈述经检查的结果 identityOutputReason。恒等实现直接满足所要求全输入恒等输出且该理由被重视。 后续策略块证明这一显式类型。 + + + **L99** 这些要求接纳输出理由;identityImpl 在每个允许输入的真实输出与预期输出由自反性相等。 + + + **L101** 陈述经检查的结果 identityFeasible。证明全输入恒等输出及成本一满足预算一。 给出的证明项使用所示构造见证或先前引理,而不增加公理。 + + + **L102** 对恒等实现,每个必需输出均由自反性正确;计算成本 1 不超过预算 1。 + + + **L104** 陈述经检查的结果 identityJustified。以恒等输出和可行性为基础构造实际选择理由见证。 给出的证明项使用所示构造见证或先前引理,而不增加公理。 + + + **L105** 组合恒等实现可行性与真实输出理由,证明它属于 objectiveReason,并提供基于内容的相关性。 + + + **L107** 说明 conventionWithReason 的预定范围。对应声明涉及:既有惯用标记与有效输出理由并存;真正证据来自方法理由而非标记。 该注释用于解释,不是证明前提。 + + + **L108** 陈述经检查的结果 conventionWithReason。既有惯用标记与有效输出理由并存;真正证据来自方法理由而非标记。 + + + **L109** 保留恒等实现两个真实地位事实均为 true。 + + + **L110** 主张使用惯常与真实输出理由组成的列表可获得有理由选择;相关性来自输出理由。 + + + **L111** 计算惯常与既有地位事实,保留实际可行性,并选取列表中的输出理由及其另行证明的相关性。 + + + **L113** 声明可选构造 Candidate。候选域严格只有identity与successor,不含所有实现。 + + + **L114** 为这些有限构造子派生可判定相等与可打印表示;它们是计算便利,不是选择判据。 + + + **L116** 定义 implementation。将两个候选标签映射到其具体函数实现。 + + + **L117** 把恒等候选解释为真实 identityImpl 对象。 + + + **L118** 把后继候选解释为真实 successorImpl 对象。 + + + **L120** 说明 singleFeasible 的预定范围。对应声明涉及:穷尽两个候选,证明恒等是预算一及恒等目标下唯一可行者,并有实际选择理由。 该注释用于解释,不是证明前提。 + + + **L121** 陈述经检查的结果 singleFeasible。穷尽两个候选,证明恒等是预算一及恒等目标下唯一可行者,并有实际选择理由。 + + + **L122** 在明确的双值候选类型中,要求可行性恰对应 identity。 + + + **L123** 还保留恒等实现真实的输出理由选择依据。 + + + **L124** 分开准确的可行候选刻画与恒等选择已有的理由证明。 + + + **L125** 固定明确恒等、后继类型中的任意候选,再检查其可行性等价关系。 + + + **L126** 穷尽实际双候选类型:identity 或 successor;不涉及未列出的实现。 + + + **L127** 对 identity 展开真实输出与成本;恒等输出和预算条件均满足。 + + + **L128** 对 successor 展开同一要求;该候选不能满足恒等输出,其原始成本也超预算。 + + + **L129** 复用 identityJustified 完成具体候选的有理由选择义务。 + + + **L131** 说明 localNotGlobal 的预定范围。对应声明涉及:两个实现零点相同、一处不同,不能由局部表现推全域等价。 该注释用于解释,不是证明前提。 + + + **L132** 陈述经检查的结果 localNotGlobal。两个实现零点相同、一处不同,不能由局部表现推全域等价。 + + + **L133** 只在输入 0 范围下比较真实输出。 + + + **L134** 另行要求输入 1 处真实输出不同。 + + + **L135** 分开输入 0 范围内相等与输入 1 处真实不等两个目标。 + + + **L136** 代入局部范围假设 x=0;两个实现输出依定义相等。 + + + **L137** 计算输入 1 处的实际输出,验证所述不等关系。 + + + **L139** 说明 cheapSuccessor 的预定范围。对应声明涉及:把后继成本降为一,但仍不满足恒等输出目标。 该注释用于解释,不是证明前提。 + + + **L140** 定义 cheapSuccessor。把后继成本降为一,但仍不满足恒等输出目标。 + + + **L142** 陈述经检查的结果 eligibleInternalReasonNotSufficient。廉价后继有相关简洁性理由,却因输出不可行仍不能获得正当选择。 + + + **L143** 要求 cheapSuccessor 的成本理由在所选要求下真实相关。 + + + **L144** 仍否定它仅凭该理由获得有理由选择,因为可行性还包括输出正确。 + + + **L145** 证明便宜后继实现具有被接纳的成本理由,成本 1 不超过预算 1,再单独否定有理由选择。 + + + **L146** 假定 cheapSuccessor 凭成本理由获得有理由选择,以提取并反驳其必需输出可行性。 + + + **L147** 假定有理由选择包含输出可行性;将其应用于输入 0,而后继实现返回 1,不是预期 0。 + + + **L148** 消去所得不可能输出等式;相关成本理由没有修复错误输出。 + + + **L150** 说明 internalReasons 的预定范围。对应声明涉及:给恒等实现四类有效内部理由,并以廉价后继反驳相关理由自动充分。 该注释用于解释,不是证明前提。 + + + **L151** 陈述经检查的结果 internalReasons。给恒等实现四类有效内部理由,并以廉价后继反驳相关理由自动充分。 + + + **L152** 要求同一真实恒等实现具有忠实解释理由。 + + + **L153** 要求其真实适用性覆盖必需输入。 + + + **L154** 要求其真实成本满足所重视的简单性与预算条件。 + + + **L155** 要求其真实轨迹内容满足所重视的过程条件。 + + + **L156** 纳入另一个便宜后继实例,其中成本理由合格。 + + + **L157** 该便宜候选仍未满足有理由选择;组合定理从此开始证明。 + + + **L158** 给 identity 提供被接纳且真实忠实的解释与适用性理由,并在每个必需输入检查内容。 + + + **L159** 提供真实预算与轨迹理由,再纳入便宜却错误的实例,说明相关性本身不充分。 + + + **L161** 说明 openNotEquivalent 的预定范围。对应声明涉及:已有正当选择实例,但恒等与后继在零处仍不同。 该注释用于解释,不是证明前提。 + + + **L162** 陈述经检查的结果 openNotEquivalent。已有正当选择实例,但恒等与后继在零处仍不同。 + + + **L163** 基于真实输出理由,保留既有恒等实现的有理由选择。 + + + **L164** 还要求恒等与后继实现在输入 0 产生不同真实输出。 + + + **L165** 保留已有恒等选择理由,并计算 identity 与 successor 在 0 处不同的真实输出。 + + + **L167** 说明 priorityClaim 的预定范围。对应声明涉及:要求被选候选为identity。 该注释用于解释,不是证明前提。 + + + **L168** 定义 priorityClaim。要求被选候选为identity。 + + + **L170** 定义 statusFacts。理论只包含固定identity的惯用和既有状态事实,与当前选择无关。 + + + **L171** 第一地位前提记录恒等实现真实惯常地位,不依赖候选解释。 + + + **L172** 第二地位前提记录同一实现真实既有地位。 + + + **L174** 说明 statusFactsModel 的预定范围。对应声明涉及:两个候选都满足这些固定元数据事实。 该注释用于解释,不是证明前提。 + + + **L175** 陈述经检查的结果 statusFactsModel。两个候选都满足这些固定元数据事实。 后续策略块证明这一显式类型。 + + + **L176** 两个地位谓词都针对同一真实恒等实现,且独立于选择哪种候选解释而为真;组合其单元素模型。 + + + **L178** 定义 priorityArticulation。把身份事实、对应理由及全范围保存成非空表达。 + + + **L179** 以 statusFacts 为前提理论,表述优先权与真实地位概念。 + + + **L180** 把相同真实惯常与既有事实列为所表述理由。 + + + **L181** 对该地位优先权表述使用不受限候选范围。 + + + **L183** 说明 AssessmentAccurate 的预定范围。对应声明涉及:报告为真恰好对应身份事实蕴涵优先选择的语义结论。 该注释用于解释,不是证明前提。 + + + **L184** 定义 AssessmentAccurate。报告为真恰好对应身份事实蕴涵优先选择的语义结论。 + + + **L185** 以 report=true 与这些地位事实语义蕴含该准确优先权问题之间的等价,定义报告准确性。 + + + **L187** 陈述经检查的结果 statusDoesNotEntailPriority。以successor为身份事实的反模型,拒绝推出必须选择identity。 后续策略块证明这一显式类型。 + + + **L188** 假定真实地位事实在全部候选解释中蕴含恒等优先权。 + + + **L189** 将假定的地位到优先权蕴含应用于 successor;它满足全部相同真实地位事实,却不是 identity。 + + + **L190** 不同候选构造子否定在 successor 处推出的优先权等式。 + + + **L192** 陈述经检查的结果 statusAssessmentNonEntailment。保留原事实反模型:身份事实可表达且被准确评估,但不蕴涵恒等优先。 + + + **L193** 要求同一地位优先权评估具有程序表述与正确否定报告。 + + + **L194** 保留所有候选解释为相同真实地位事实的模型。 + + + **L195** 优先权谓词在 identity 处成立,在 successor 处失败。 + + + **L196** 否定仅由地位事实蕴含该优先权谓词。 + + + **L197** 还拒绝只以既有地位作为真实理由选择恒等实现。 + + + **L198** 检查 priorityArticulation 具有非空概念与真实地位理由。 + + + **L199** 证明 false 报告准确:它不可能等于 true;任意蕴含假设又与真实 successor 反模型矛盾。 + + + **L200** 保留两个候选对相同事实的模型、identity 而非 successor 的优先权,以及已证的蕴含失败。 + + + **L201** 对唯一理由为既有地位的明确恒等选择,复用一般的仅凭地位失败定理。 + + + **L203** 说明 PriorityAssessment 的预定范围。对应声明涉及:独立于选择政策保存实际假设、问题及布尔评估报告。 该注释用于解释,不是证明前提。 + + + **L204** 声明数据接口 PriorityAssessment。独立于选择政策保存实际假设、问题及布尔评估报告。 + + + **L205** 保存该评估实际审查的前提理论。 + + + **L206** 保存待评估其蕴含的准确优先权主张。 + + + **L207** 保存报告的布尔答案,与事实及问题分开。 + + + **L208** 说明 PriorityAssessment.accurate 的预定范围。对应声明涉及:要求报告精确对应同一假设和问题的语义蕴涵结果。 该注释用于解释,不是证明前提。 + + + **L209** 定义 PriorityAssessment.accurate。要求报告精确对应同一假设和问题的语义蕴涵结果。 + + + **L210** 要求该评估真实报告与其自身前提到自身问题的蕴含准确一致。 + + + **L211** 说明 statusPriorityAudit 的预定范围。对应声明涉及:为固定身份事实与优先问题记录不蕴涵报告。 该注释用于解释,不是证明前提。 + + + **L212** 定义 statusPriorityAudit。为固定身份事实与优先问题记录不蕴涵报告。 + + + **L213** 说明 ChoicePolicy 的预定范围。对应声明涉及:把所选候选、优先理由和独立储存的评估分开。 该注释用于解释,不是证明前提。 + + + **L214** 声明数据接口 ChoicePolicy。把所选候选、优先理由和独立储存的评估分开。 + + + **L215** 保存该政策实际选择的候选。 + + + **L216** 独立于评估记录保存该政策真实优先权理由。 + + + **L217** 保存政策完成其程序的实际评估。 + + + **L218** 说明 GeneralAssessmentFulfilled 的预定范围。对应声明涉及:要求实际表达非空并保留准确身份审查,不加入额外选择标准。 该注释用于解释,不是证明前提。 + + + **L219** 定义 GeneralAssessmentFulfilled。要求实际表达非空并保留准确身份审查,不加入额外选择标准。 + + + **L220** 要求非空表述、恰为共享 statusPriorityAudit 及其准确性;这是特定程序履行,不是完整哲学 Grounds。 + + + **L221** 说明 AdditionalChoiceNorm 的预定范围。对应声明涉及:把单独的可行性及相关性规范应用到政策所选实现和理由。 该注释用于解释,不是证明前提。 + + + **L222** 定义 AdditionalChoiceNorm。把单独的可行性及相关性规范应用到政策所选实现和理由。 + + + **L223** 把 JustifiedChoice 单独应用于政策实际所选实现及真实理由列表。 + + + **L224** 说明 statusPriorityPolicy 的预定范围。对应声明涉及:政策只凭既有地位选择恒等,同时保留准确的不蕴涵评估。 该注释用于解释,不是证明前提。 + + + **L225** 定义 statusPriorityPolicy。政策只凭既有地位选择恒等,同时保留准确的不蕴涵评估。 + + + **L226** 说明 outputPriorityPolicy 的预定范围。对应声明涉及:保留同一选择和评估,把理由改为实际输出理由。 该注释用于解释,不是证明前提。 + + + **L227** 定义 outputPriorityPolicy。保留同一选择和评估,把理由改为实际输出理由。 + + + **L228** 说明 statusPriorityAuditAccurate 的预定范围。对应声明涉及:利用后继反模型证明所记不蕴涵报告准确。 该注释用于解释,不是证明前提。 + + + **L229** 陈述经检查的结果 statusPriorityAuditAccurate。利用后继反模型证明所记不蕴涵报告准确。 后续策略块证明这一显式类型。 + + + **L230** 把否定审查的准确性拆为与蕴含等价的两个方向。 + + + **L231** 审查的实际 false 报告不可能等于 true,因此该方向的前提不可能成立。 + + + **L232** 任何所断言的蕴含都与 statusDoesNotEntailPriority 矛盾,从而确立 false 报告准确性的反方向。 + + + **L233** 说明 PolicyIndependenceExample 的预定范围。对应声明涉及:要求同选择同审查而理由不同的两政策,均履行所表示评估责任,只有输出理由政策满足额外规范。 该注释用于解释,不是证明前提。 + + + **L234** 定义 PolicyIndependenceExample。要求同选择同审查而理由不同的两政策,均履行所表示评估责任,只有输出理由政策满足额外规范。 + + + **L235** 固定两个政策所选候选相同。 + + + **L236** 固定两个政策采用同一实际评估。 + + + **L237** 把该评估前提绑定到真实共享 statusFacts。 + + + **L238** 把其问题绑定到同一 priorityClaim。 + + + **L239** 把共同报告固定为 false,不允许政策变化改变审查答案。 + + + **L240** 为每个候选解释保留相同评估前提的模型。 + + + **L241** 尽管候选与审查相同,仍要求实际优先权理由列表不同。 + + + **L242** 要求两个政策准确完成同一指定评估程序。 + + + **L243** 要求额外选择规范下结果相反:地位失败、输出通过。 + + + **L244** 说明 policyIndependenceExample 的预定范围。对应声明涉及:构造两个独立政策对象,结合真实审查准确性、身份理由拒绝和输出理由成立。 该注释用于解释,不是证明前提。 + + + **L245** 陈述经检查的结果 policyIndependenceExample。构造两个独立政策对象,结合真实审查准确性、身份理由拒绝和输出理由成立。 后续策略块证明这一显式类型。 + + + **L246** 为两个政策构造同一个关于真实地位优先权问题的非空表述。 + + + **L247** 为两个政策构造同一个关于真实地位优先权问题的非空表述。 + + + **L248** 固定相同所选候选、审查、前提、问题与 false 报告;保留真实事实模型,留下理由列表差异。 + + + **L249** 证明仅凭地位的政策完成了这一确切、具有表述且报告在数学上准确的审查。 + + + **L250** 给输出政策提供同样已履行的审查,留下两个分别的额外选择规范结果。 + + + **L251** 计算仅凭地位与基于输出的优先权理由列表不同,尽管所选候选与审查相同。 + + + **L252** 把 statusOnlyFails 应用于实际地位政策的优先权理由,证明其未满足 AdditionalChoiceNorm。 + + + **L253** 对输出政策实际相关的输出理由使用 identityJustified,证明其满足 AdditionalChoiceNorm。 + + + **L255** 说明 generalGroundsNotChoice 的预定范围。对应声明涉及:将事实非蕴涵与独立政策层反例组合,表明所表示一般评估责任不推出额外选择规范。 该注释用于解释,不是证明前提。 + + + **L256** 说明 generalGroundsNotChoice 的预定范围。对应声明涉及:将事实非蕴涵与独立政策层反例组合,表明所表示一般评估责任不推出额外选择规范。 该注释用于解释,不是证明前提。 + + + **L257** 陈述经检查的结果 generalGroundsNotChoice。将事实非蕴涵与独立政策层反例组合,表明所表示一般评估责任不推出额外选择规范。 + + + **L258** 将原有具有表述且准确否定的地位评估保留为登记结果的一部分。 + + + **L259** 保留每个候选都满足的相同真实地位前提。 + + + **L260** 保留 identity 优先权为真、successor 优先权为假。 + + + **L261** 保留已展示的地位到优先权非蕴含。 + + + **L262** 保留仅凭地位的选择失败,再与更强的政策独立变化实例结合。 + + + **L263** 通过 PolicyIndependenceExample 纳入真实政策变化,而不停留于地位非蕴含。 + + + **L264** 把保留的地位非蕴含证明与 policyIndependenceExample 组合,使登记定理包含真实独立的优先权理由变化。 + + + **L266** 关闭命名空间 CoreReader.Choice;这不增加证明或前提。 + + +### `leanified/CoreReader/Engineering/Domain.lean` + + +```lean +import Std + +namespace CoreReader.Engineering + +/- This is a bounded engineering application model. Work units count explicit +operations; they are not a universal exchange rate or empirical forecast. -/ +inductive Maintainer where + | original | successor | agent + deriving DecidableEq, Repr +inductive Tool where + | editor | compiler | contractRunner | migrationRunner + deriving DecidableEq, Repr +inductive Knowledge where + | privateLayout | publicContract | changeGuide | migrationGuide + deriving DecidableEq, Repr +inductive Change where + | addition | replacement | deletion | withdrawal | redrawing | migration + | independent | coordinated | designRevision | other (name : String) + deriving DecidableEq, Repr +inductive Candidate where + | presentSimple | evolvable | maximal + deriving DecidableEq, Repr +inductive Burden where + | understanding | construction | diagnosis | verification | coordination + | operation | migration + deriving DecidableEq, Repr + +def maintainers : List Maintainer := [.original, .successor, .agent] +def changes : List Change := [.addition, .replacement, .deletion, .withdrawal, + .redrawing, .migration, .independent, .coordinated, .designRevision] +def burdens : List Burden := [.understanding, .construction, .diagnosis, + .verification, .coordination, .operation, .migration] + +structure Activity where + participants : List Maintainer + software : String + tools : List Tool + available : Maintainer → List Knowledge + scheduledReleases : Nat + scheduledMaintenance : Nat + boundedRuns : Option Nat + label : String + +/-- organon-map CoreReader.Engineering.ActivityScope +software-engineering.purpose#p1 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.purpose#p2 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +-/ +abbrev ActivityScope (a : Activity) : Prop := + a.participants ≠ [] ∧ a.software ≠ "" ∧ a.tools ≠ [] ∧ + a.participants.all (fun m => !(a.available m).isEmpty) = true + +abbrev Continuing (a : Activity) : Prop := + 0 < a.scheduledReleases ∧ 0 < a.scheduledMaintenance + +abbrev BoundedLifecycle (a : Activity) : Prop := + a.boundedRuns.isSome = true ∧ a.scheduledReleases = 0 ∧ + a.scheduledMaintenance = 0 + +def continuingActivity : Activity := { + participants := maintainers, software := "order-preserving queue", + tools := [.editor, .compiler, .contractRunner, .migrationRunner], + available := fun m => match m with + | .original => [.privateLayout, .publicContract, .changeGuide, .migrationGuide] + | _ => [.publicContract, .changeGuide, .migrationGuide], + scheduledReleases := 3, scheduledMaintenance := 6, + boundedRuns := none, label := "temporary" } + +def temporaryActivity : Activity := { continuingActivity with + scheduledReleases := 0, scheduledMaintenance := 0, boundedRuns := some 1, + label := "one-shot import" } +def prototypeActivity : Activity := { temporaryActivity with + boundedRuns := some 4, label := "bounded prototype" } +def retiringActivity : Activity := { temporaryActivity with + boundedRuns := some 2, label := "retiring service" } + +structure EditStep where + component : Nat + requires : Knowledge + tool : Tool + units : Nat + deriving DecidableEq, Repr + +def changePath (c : Candidate) (d : Change) : List EditStep := + let guide := if c = .presentSimple then Knowledge.privateLayout else .changeGuide + let base : List EditStep := [⟨0, guide, .editor, 1⟩, + ⟨0, .publicContract, .contractRunner, 1⟩] + match d with + | .addition | .independent => base + | .replacement | .deletion => base ++ [⟨1, guide, .compiler, 1⟩] + | .coordinated => base ++ [⟨1, guide, .compiler, 3⟩, ⟨2, .publicContract, .contractRunner, 3⟩] + | .migration => base ++ [⟨1, .migrationGuide, .migrationRunner, 8⟩] + | .withdrawal | .redrawing | .designRevision => + if c = .presentSimple then base ++ + [⟨1, guide, .editor, 5⟩, ⟨2, guide, .compiler, 5⟩, + ⟨2, .publicContract, .contractRunner, 5⟩] + else base ++ [⟨1, guide, .editor, 2⟩, ⟨1, .publicContract, .contractRunner, 2⟩] + | .other name => + if name = "csv export" then + if c = .maximal then base ++ [⟨3, .migrationGuide, .compiler, 2⟩] + else base ++ [⟨3, .privateLayout, .compiler, 20⟩] + else [] + +def changeWork (c : Candidate) (d : Change) : Nat := + ((changePath c d).map EditStep.units).sum + +abbrev CanChange (a : Activity) (c : Candidate) (m : Maintainer) (d : Change) : Prop := + (changePath c d) ≠ [] ∧ m ∈ a.participants ∧ (changePath c d).all + (fun step => (a.available m).contains step.requires && a.tools.contains step.tool) = true + +abbrev ContinuingCapability (a : Activity) (c : Candidate) (d : Change) : Prop := + (changePath c d) ≠ [] ∧ a.participants.all (fun m => (changePath c d).all + (fun step => (a.available m).contains step.requires && a.tools.contains step.tool)) = true + +/- Maximal is maximal only on this explicitly registered finite set. The +extra CSV direction has an actual documented compilation path and later state +transformation; unsupported names do not gain a capability from an empty path. -/ +def registeredDirections : List Change := changes ++ [.other "csv export"] +def supportedDirections (a : Activity) (c : Candidate) : List Change := + registeredDirections.filter (fun d => decide (ContinuingCapability a c d)) +abbrev MaximumRegisteredCapability (a : Activity) (c : Candidate) : Prop := + registeredDirections.all (fun d => decide (ContinuingCapability a c d)) = true + +/- A software value here is a passive function: no intention is stored in it. +An engineering intention is an agent's selected set of changes. -/ +def passiveArtifact (xs : List Nat) : List Nat := xs + +def orientation : Maintainer → List Change := fun _ => [.designRevision, .migration] + +inductive EngineeringAction where + | propose (direction : Change) + | execute (result : List Nat) + deriving DecidableEq, Repr + +def maintainerActions (m : Maintainer) : List EngineeringAction := + (orientation m).map EngineeringAction.propose + +def artifactActions (input : List Nat) : List EngineeringAction := + [.execute (passiveArtifact input)] + +/-- organon-map CoreReader.Engineering.subjectLifecycleCases +software-engineering.purpose#p1 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.purpose#p2 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +-/ +theorem subjectLifecycleCases : + ActivityScope continuingActivity ∧ + CanChange continuingActivity .evolvable .successor .designRevision ∧ + CanChange continuingActivity .evolvable .agent .designRevision ∧ + continuingActivity.label = "temporary" ∧ Continuing continuingActivity ∧ + ¬ BoundedLifecycle continuingActivity ∧ BoundedLifecycle temporaryActivity ∧ + BoundedLifecycle prototypeActivity ∧ BoundedLifecycle retiringActivity := by decide + +/-- organon-map CoreReader.Engineering.subjectLimits +software-engineering.purpose#p1 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.purpose#p2 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +-/ +theorem subjectLimits : + CanChange continuingActivity .presentSimple .original .designRevision ∧ + ¬ CanChange continuingActivity .presentSimple .successor .designRevision ∧ + ¬ ContinuingCapability continuingActivity .presentSimple .designRevision ∧ + continuingActivity.label = "temporary" ∧ ¬ BoundedLifecycle continuingActivity ∧ + orientation .agent ≠ [] ∧ passiveArtifact [2, 1] = [2, 1] ∧ + EngineeringAction.propose .designRevision ∈ maintainerActions .agent ∧ + EngineeringAction.propose .designRevision ∉ artifactActions [2, 1] := by decide + +/- Ground is intentionally parameterized: the examples below do not exhaust +possible sources of credibility. The supplied support relation needs review. -/ +/-- organon-map CoreReader.Engineering.CredibleDirection +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +abbrev CredibleDirection {Ground : Type} (grounds : List Ground) + (articulated : Ground → Bool) (supports : Ground → Change → Bool) + (d : Change) : Prop := + grounds.any (fun g => articulated g && supports g d) = true + +inductive DirectionGround where + | plan (release : Nat) (committed : List Change) + | knowledge (service : String) (affected : List Change) (mechanism : String) + | history (service : String) (observed : List Change) + | other (account : String) (supported : List Change) + deriving DecidableEq, Repr + +def articulateGround : DirectionGround → Bool + | .plan release ds => release > 0 && !ds.isEmpty + | .knowledge service ds mechanism => service != "" && !ds.isEmpty && mechanism != "" + | .history service ds => service != "" && !ds.isEmpty + | .other account ds => account != "" && !ds.isEmpty + +def supportGround : DirectionGround → Change → Bool + | .plan release ds, d => release > 0 && ds.contains d + | .knowledge service ds mechanism, d => + service == "queue" && mechanism == "tenant-config-reload" && ds.contains d + | .history service ds, d => service == "queue" && (ds.filter (· == d)).length >= 2 + | .other account ds, d => account == "reviewed customer migration requirement" && ds.contains d + +abbrev initialGrounds : List DirectionGround := [.plan 2 [.designRevision, .migration]] +def forecastGrounds : List DirectionGround := [.plan 3 [.deletion]] +abbrev credible (gs : List DirectionGround) (d : Change) : Prop := + CredibleDirection gs articulateGround supportGround d + +abbrev WarrantedAccommodation (gs : List DirectionGround) (d : Change) + (objectiveGain investment : Nat) : Prop := + credible gs d ∧ 0 < objectiveGain ∧ investment ≤ objectiveGain + +/-- organon-map CoreReader.Engineering.credibilityCases +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +theorem credibilityCases : + credible initialGrounds .designRevision ∧ + credible [.knowledge "queue" [.designRevision] "tenant-config-reload"] .designRevision ∧ + credible [.history "queue" [.migration, .migration]] .migration ∧ + ¬ credible [] (.other "quantum backend") ∧ + credible forecastGrounds .deletion ∧ ¬ credible forecastGrounds .designRevision := by decide + +def abstractionComplexity : Candidate → Nat + | .presentSimple => 1 | .evolvable => 3 | .maximal => 30 + +def implementedVariants : List Candidate := [.presentSimple] + +/- No scalar conversion across burden dimensions is used by the priority rule. -/ +structure CostVector where + amount : Burden → Nat +structure CostLimits where + capacity : Burden → Nat + objective : Burden → String + +def cost : Candidate → Burden → Nat + | .presentSimple, _ => 1 + | .evolvable, .understanding => 3 + | .evolvable, .construction => 4 + | .evolvable, .diagnosis => 2 + | .evolvable, .verification => 4 + | .evolvable, .coordination => 2 + | .evolvable, .operation => 2 + | .evolvable, .migration => 8 + | .maximal, _ => 40 + +def normalLimits : CostLimits := { + capacity := fun _ => 12, + objective := fun b => match b with + | .understanding => "successor onboarding capacity" + | .construction => "release construction capacity" + | .diagnosis => "incident diagnosis window" + | .verification => "release verification capacity" + | .coordination => "available team coordination" + | .operation => "runtime resource budget" + | .migration => "retirement migration capacity" } + +structure Requirements where + orderRequired : Bool + maxUnsafeOperations : Nat + maxLatency : Nat + minRetention : Nat + +def normalRequirements : Requirements := ⟨true, 0, 10, 30⟩ +def behavior : Candidate → List Nat → List Nat := fun _ xs => xs.eraseDups + +/- Candidate profiles are observations in this bounded scenario. Modified +profiles below test all four independent necessary-requirement gates. -/ +structure CandidateProfile where + orderOutput : List Nat + unsafeOperations : Nat + latency : Nat + retention : Nat + +def profile (c : Candidate) : CandidateProfile := ⟨behavior c [2, 1, 2], 0, 5, 30⟩ +abbrev Meets (r : Requirements) (p : CandidateProfile) : Prop := + (r.orderRequired = true → p.orderOutput = [2, 1]) ∧ + p.unsafeOperations ≤ r.maxUnsafeOperations ∧ p.latency ≤ r.maxLatency ∧ + r.minRetention ≤ p.retention + +structure Context where + activity : Activity + required : Requirements + evidence : List DirectionGround + limits : CostLimits + departure : Option Burden + profiles : Candidate → CandidateProfile := profile + +def currentContinuing : Context := { + activity := continuingActivity, required := normalRequirements, + evidence := initialGrounds, limits := normalLimits, departure := none } + +abbrev ConcreteThreat (ctx : Context) (c : Candidate) (b : Burden) : Prop := + cost .presentSimple b < cost c b ∧ ctx.limits.capacity b < cost c b ∧ + ctx.limits.objective b ≠ "" + +abbrev HasThreat (ctx : Context) (c : Candidate) : Prop := + burdens.any (fun b => decide (ConcreteThreat ctx c b)) = true + +/-- organon-map CoreReader.Engineering.JustifiedDeparture +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +abbrev JustifiedDeparture (ctx : Context) (c : Candidate) : Prop := + match ctx.departure with + | none => False + | some b => ConcreteThreat ctx c b + +instance (ctx : Context) (c : Candidate) : Decidable (JustifiedDeparture ctx c) := by + unfold JustifiedDeparture + split <;> infer_instance + +abbrev PriorityConditions (ctx : Context) : Prop := + Continuing ctx.activity ∧ ActivityScope ctx.activity ∧ + Meets ctx.required (ctx.profiles .presentSimple) ∧ Meets ctx.required (ctx.profiles .evolvable) ∧ + credible ctx.evidence .designRevision ∧ + ContinuingCapability ctx.activity .evolvable .designRevision ∧ + changeWork .evolvable .designRevision < changeWork .presentSimple .designRevision ∧ + abstractionComplexity .presentSimple < abstractionComplexity .evolvable + +/-- organon-map CoreReader.Engineering.EvolutionPriority +software-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +abbrev EvolutionPriority (ctx : Context) (chosen : Candidate) : Prop := + PriorityConditions ctx → chosen = .evolvable ∨ JustifiedDeparture ctx .evolvable + +theorem currentPriorityConditions : PriorityConditions currentContinuing := by decide +theorem currentNoThreat : ¬ HasThreat currentContinuing .evolvable ∧ + ¬ JustifiedDeparture currentContinuing .evolvable := by decide + +def threatened (b : Burden) : Context := { currentContinuing with + limits := { normalLimits with capacity := fun x => if x = b then 1 else 12 }, + departure := some b } + +/-- organon-map CoreReader.Engineering.priorityWhenApplicable +software-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +theorem priorityWhenApplicable (ctx : Context) (chosen : Candidate) + (rule : EvolutionPriority ctx chosen) (applicable : PriorityConditions ctx) + (noDeparture : ¬ JustifiedDeparture ctx .evolvable) : + chosen = .evolvable ∧ + abstractionComplexity .presentSimple < abstractionComplexity chosen := by + have hc := (rule applicable).resolve_right noDeparture + exact ⟨hc, hc ▸ applicable.2.2.2.2.2.2.2⟩ + +theorem currentSimpleViolates : ¬ EvolutionPriority currentContinuing .presentSimple := by + intro h + have bad := (h currentPriorityConditions).resolve_right currentNoThreat.2 + cases bad + +def withEvolvableProfile (p : CandidateProfile) : Context := { currentContinuing with + profiles := fun c => if c = .evolvable then p else profile c } + +theorem unmetRequirementsBlockPriority : + ¬ PriorityConditions (withEvolvableProfile { profile .evolvable with orderOutput := [1, 2] }) ∧ + ¬ PriorityConditions (withEvolvableProfile { profile .evolvable with unsafeOperations := 1 }) ∧ + ¬ PriorityConditions (withEvolvableProfile { profile .evolvable with latency := 11 }) ∧ + ¬ PriorityConditions (withEvolvableProfile { profile .evolvable with retention := 29 }) := by + simp [PriorityConditions, withEvolvableProfile, currentContinuing, Meets, + normalRequirements] + +/-- organon-map CoreReader.Engineering.priorityConditionsCases +software-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +theorem priorityConditionsCases : + EvolutionPriority currentContinuing .evolvable ∧ + ¬ Meets normalRequirements { profile .evolvable with orderOutput := [1, 2] } ∧ + ¬ Meets normalRequirements { profile .evolvable with unsafeOperations := 1 } ∧ + ¬ Meets normalRequirements { profile .evolvable with latency := 11 } ∧ + ¬ Meets normalRequirements { profile .evolvable with retention := 29 } ∧ + EvolutionPriority (threatened .verification) .presentSimple ∧ + ¬ JustifiedDeparture { threatened .verification with departure := none } .evolvable ∧ + abstractionComplexity .evolvable < abstractionComplexity .maximal := by + refine ⟨by decide, by decide, by decide, by decide, by decide, by decide, ?_, by decide⟩ + simp [JustifiedDeparture] + +/-- organon-map CoreReader.Engineering.priorityChoices +software-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +theorem priorityChoices : + EvolutionPriority currentContinuing .evolvable ∧ + ¬ EvolutionPriority currentContinuing .presentSimple ∧ + EvolutionPriority (threatened .verification) .presentSimple := by + exact ⟨by decide, currentSimpleViolates, by decide⟩ + +/-- organon-map CoreReader.Engineering.credibilityLimits +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +theorem credibilityLimits : + credible initialGrounds .designRevision ∧ implementedVariants.length = 1 ∧ + ¬ WarrantedAccommodation [] (.other "quantum backend") 0 5 ∧ + ¬ credible initialGrounds (.other "quantum backend") ∧ + EvolutionPriority currentContinuing .evolvable ∧ + abstractionComplexity .evolvable < abstractionComplexity .maximal ∧ + cost .evolvable .construction < cost .evolvable .migration ∧ + ¬ MaximumRegisteredCapability continuingActivity .evolvable ∧ + MaximumRegisteredCapability continuingActivity .maximal ∧ + (supportedDirections continuingActivity .evolvable).length = 9 ∧ + (supportedDirections continuingActivity .maximal).length = 10 ∧ + ¬ credible initialGrounds (.other "csv export") := by decide + +/-- organon-map CoreReader.Engineering.costCases +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +theorem costCases : + JustifiedDeparture (threatened .understanding) .evolvable ∧ + JustifiedDeparture (threatened .construction) .evolvable ∧ + JustifiedDeparture (threatened .diagnosis) .evolvable ∧ + JustifiedDeparture (threatened .verification) .evolvable ∧ + JustifiedDeparture (threatened .coordination) .evolvable ∧ + JustifiedDeparture (threatened .operation) .evolvable ∧ + JustifiedDeparture (threatened .migration) .evolvable ∧ + ¬ JustifiedDeparture { currentContinuing with departure := some .migration } .evolvable := by decide + +/- Total functions model an identified order-preserving de-duplication API. +The test corpus is explicitly finite; universal preservation is separate. -/ +def orderedUnique (xs : List Nat) : List Nat := xs.eraseDups +def orderedRefactor (xs : List Nat) : List Nat := xs.eraseDups ++ [] +def insertOrdered (n : Nat) : List Nat → List Nat + | [] => [n] + | x :: xs => if n ≤ x then n :: x :: xs else x :: insertOrdered n xs + +def sortValues : List Nat → List Nat + | [] => [] + | x :: xs => insertOrdered x (sortValues xs) + +def sortedUnique (xs : List Nat) : List Nat := (sortValues xs).eraseDups + +structure SoftwareState where + capabilities : List String + implementation : Nat + mechanisms : List String + abstractions : List String + boundary : Nat + technology : String + batchSize : Nat + deriving DecidableEq, Repr + +def originalSoftware : SoftwareState := + ⟨["deduplicate"], 0, ["queue", "legacy cache"], ["fixed batch"], 0, "legacy store", 10⟩ + +def transform (d : Change) (s : SoftwareState) : SoftwareState := match d with + | .addition => { s with capabilities := s.capabilities ++ ["tenant batching"] } + | .replacement => { s with implementation := s.implementation + 1 } + | .deletion => { s with mechanisms := s.mechanisms.filter (· != "legacy cache") } + | .withdrawal => { s with abstractions := s.abstractions.filter (· != "fixed batch") } + | .redrawing => { s with boundary := s.boundary + 1 } + | .migration => { s with technology := "portable store" } + | .independent => { s with batchSize := 5 } + | .coordinated => { s with batchSize := 5, boundary := s.boundary + 1 } + | .designRevision => { s with batchSize := 5, abstractions := ["live configuration"], boundary := s.boundary + 1 } + | .other name => + if name = "csv export" then { s with capabilities := s.capabilities ++ ["csv export"] } + else s + +def evolutionBehavior (d : Change) : List Nat → List Nat := + if d = .redrawing ∨ d = .designRevision then sortedUnique else orderedUnique + +/- Changes include an open other constructor. Work, maintainer knowledge and +obligation treatment are separate dimensions, not one extensibility score. -/ +inductive ObligationTreatment where + | preserve | revise + deriving DecidableEq, Repr +structure ChangeClaim where + direction : Change + byMaintainer : Maintainer + treatment : ObligationTreatment + +abbrev contractInputs : List (List Nat) := [[], [2, 1, 2], [1, 3, 1], [4, 4]] +def PreservesOn {Input Output : Type} (scope : Input → Prop) + (old new : Input → Output) : Prop := ∀ x, scope x → new x = old x + +abbrev PreservesFinite (old new : List Nat → List Nat) : Prop := + contractInputs.all (fun xs => new xs == old xs) = true + +/- The actual contracts and observer dependencies are inputs independent of +any revision report. Reports cannot redefine the affected population or the +old/new retry behavior merely by changing their own fields. -/ +structure ObservableContract where + order : List Nat → List Nat + maxAttempts : Nat + +def retry (contract : ObservableContract) (attempts : Nat) : Bool := + attempts < contract.maxAttempts + +def orderContract (order : List Nat → List Nat) : ObservableContract := ⟨order, 3⟩ +def originalContract : ObservableContract := orderContract orderedUnique +def refactoredContract : ObservableContract := orderContract orderedRefactor +def revisedContract : ObservableContract := ⟨sortedUnique, 5⟩ +def evolutionContract (d : Change) : ObservableContract := + ⟨evolutionBehavior d, if d = .redrawing ∨ d = .designRevision then 5 else 3⟩ + +def failureInputs : List Nat := [0, 1, 2, 3, 4, 5] +abbrev PreservesContractFinite (old new : ObservableContract) : Prop := + PreservesFinite old.order new.order ∧ + failureInputs.all (fun attempts => retry new attempts == retry old attempts) = true + +inductive ContractAspect where + | order | retry + deriving DecidableEq, Repr +structure PartyDependency where + party : String + observes : ContractAspect + deriving DecidableEq, Repr + +def partyDependencies : List PartyDependency := + [⟨"queue consumer", .order⟩, ⟨"queue operator", .retry⟩] + +def aspectChanged (old new : ObservableContract) : ContractAspect → Bool + | .order => contractInputs.any (fun xs => new.order xs != old.order xs) + | .retry => failureInputs.any (fun attempts => retry new attempts != retry old attempts) + +def affectedParties (old new : ObservableContract) : List String := + (partyDependencies.filter (fun dependency => aspectChanged old new dependency.observes)).map + PartyDependency.party + +structure ContractRevision where + deliberate : Bool + revisedOrder : List Nat + affected : List String + oldFailureLimit : Nat + newFailureLimit : Nat + recordedOldFailureLimit : Nat + recordedNewFailureLimit : Nat + procedure : String + +def normalRevision : ContractRevision := { + deliberate := true, revisedOrder := [1, 2], + affected := ["queue consumer", "queue operator"], + oldFailureLimit := 3, newFailureLimit := 5, + recordedOldFailureLimit := 3, recordedNewFailureLimit := 5, + procedure := "contract review" } + +abbrev RevisionDuties (old new : ObservableContract) (r : ContractRevision) : Prop := + r.deliberate = true ∧ r.revisedOrder = new.order [2, 1, 2] ∧ + (affectedParties old new).all (fun p => r.affected.contains p) = true ∧ + r.oldFailureLimit = old.maxAttempts ∧ r.newFailureLimit = new.maxAttempts ∧ + r.recordedOldFailureLimit = old.maxAttempts ∧ + r.recordedNewFailureLimit = new.maxAttempts + +/-- organon-map CoreReader.Engineering.ContractChangeAccount +software-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +-/ +abbrev ContractChangeAccount (old new : ObservableContract) (r : ContractRevision) : Prop := + PreservesContractFinite old new ∨ RevisionDuties old new r + +/-- organon-map CoreReader.Engineering.EvolutionClaim +software-engineering.evolution-meaning#p1 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6 +software-engineering.evolution-meaning#p2 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6 +-/ +abbrev EvolutionClaim (a : Activity) (c : Candidate) (claim : ChangeClaim) : Prop := + CanChange a c claim.byMaintainer claim.direction ∧ + ContractChangeAccount originalContract (evolutionContract claim.direction) normalRevision ∧ + (changePath c claim.direction).any (fun step => step.tool == .contractRunner) = true ∧ + ((claim.treatment = .preserve ∧ + evolutionBehavior claim.direction [2, 1, 2] = orderedUnique [2, 1, 2]) ∨ + (claim.treatment = .revise ∧ + evolutionBehavior claim.direction [2, 1, 2] ≠ orderedUnique [2, 1, 2])) + +/-- organon-map CoreReader.Engineering.evolutionKindsCases +software-engineering.evolution-meaning#p1 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6 +software-engineering.evolution-meaning#p2 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6 +-/ +theorem evolutionKindsCases : + (transform .addition originalSoftware).capabilities = ["deduplicate", "tenant batching"] ∧ + (transform .replacement originalSoftware).implementation = 1 ∧ + (transform .deletion originalSoftware).mechanisms = ["queue"] ∧ + (transform .withdrawal originalSoftware).abstractions = [] ∧ + (transform .redrawing originalSoftware).boundary = 1 ∧ + (transform .migration originalSoftware).technology = "portable store" ∧ + changes.all (fun d => decide (CanChange continuingActivity .evolvable .successor d)) = true ∧ + EvolutionClaim continuingActivity .evolvable ⟨.replacement, .successor, .preserve⟩ ∧ + EvolutionClaim continuingActivity .evolvable ⟨.redrawing, .agent, .revise⟩ ∧ + changeWork .evolvable .independent < changeWork .evolvable .coordinated := by decide + +/-- organon-map CoreReader.Engineering.evolutionDimensionsLimits +software-engineering.evolution-meaning#p1 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6 +software-engineering.evolution-meaning#p2 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6 +-/ +theorem evolutionDimensionsLimits : + changeWork .presentSimple .addition = 2 ∧ + changeWork .presentSimple .withdrawal = 17 ∧ + changeWork .evolvable .independent < changeWork .evolvable .coordinated ∧ + EvolutionPriority currentContinuing .evolvable ∧ + 9 < changeWork .evolvable .migration ∧ + CanChange continuingActivity .presentSimple .original .addition ∧ + CanChange continuingActivity .evolvable .original .addition ∧ + CanChange continuingActivity .presentSimple .original .designRevision ∧ + CanChange continuingActivity .evolvable .original .designRevision ∧ + changeWork .evolvable .designRevision < changeWork .presentSimple .designRevision ∧ + changeWork .evolvable .addition = changeWork .presentSimple .addition ∧ + (transform (.other "csv export") originalSoftware).capabilities = ["deduplicate", "csv export"] ∧ + CanChange continuingActivity .maximal .successor (.other "csv export") ∧ + ¬ CanChange continuingActivity .evolvable .successor (.other "csv export") := by + exact ⟨by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide, by decide⟩ + +theorem oneDimensionDoesNotEntailEveryDimension : + changeWork .evolvable .designRevision < changeWork .presentSimple .designRevision ∧ + ¬ (∀ d : Change, changeWork .evolvable d < changeWork .presentSimple d) := by + refine ⟨by decide, ?_⟩ + intro allDirections + exact (by decide : ¬ changeWork .evolvable .addition < changeWork .presentSimple .addition) + (allDirections .addition) + +def propagation (c : Candidate) (d : Change) : List Nat := + ((changePath c d).map EditStep.component).eraseDups + +def batchCount (items size : Nat) : Nat := (items + size - 1) / size +def staticBatch (items _runtimeSize : Nat) : Nat := batchCount items 10 +def liveBatch (items runtimeSize : Nat) : Nat := batchCount items runtimeSize + +structure StructuralEvidence where + intended : Change + participants : List Maintainer + touched : List Nat + contractObservations : List (List Nat) + observedBefore : List (List Nat) + observedAfter : List (List Nat) + understandingWork : Nat + verificationWork : Nat + boundaryGain : Nat + +def structuralEvidence (c : Candidate) (d : Change) : StructuralEvidence := { + intended := d, participants := maintainers, touched := propagation c d, + contractObservations := contractInputs, + observedBefore := contractInputs.map orderedUnique, + observedAfter := contractInputs.map (evolutionBehavior d), + understandingWork := changeWork c d, + verificationWork := ((changePath c d).filter (fun step => step.tool == .contractRunner)).length, + boundaryGain := changeWork .presentSimple d - changeWork c d } + +/-- organon-map CoreReader.Engineering.StructuralAccount +software-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +software-engineering.structural-judgment#p2 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +-/ +abbrev StructuralAccount (a : Activity) (c : Candidate) (e : StructuralEvidence) : Prop := + e.participants = a.participants ∧ e.touched = propagation c e.intended ∧ + e.contractObservations = contractInputs ∧ + e.observedBefore = contractInputs.map orderedUnique ∧ + e.observedAfter = contractInputs.map (evolutionBehavior e.intended) ∧ + e.understandingWork = changeWork c e.intended ∧ + e.verificationWork = ((changePath c e.intended).filter + (fun step => step.tool == .contractRunner)).length ∧ + e.boundaryGain = changeWork .presentSimple e.intended - changeWork c e.intended + +structure InterfaceView where + signature : String + modules : Nat + extensionPoints : Nat + principle : String + deriving DecidableEq, Repr + +def sameShape : InterfaceView := ⟨"List Nat → List Nat", 8, 12, "dependency inversion"⟩ +def moduleAssumptions : List (Nat × Nat) := + (List.range 8).map (fun component => (component, 10)) + +def modulesNeedingRevision (newSize : Nat) : List Nat := + (moduleAssumptions.filter (fun p => p.2 != newSize)).map Prod.fst + +structure Boundary where + caller : Nat + callee : Nat + contract : String + deriving DecidableEq, Repr + +structure EngineeringDesign where + metadata : InterfaceView + run : List Nat → List Nat + paths : Change → List EditStep + components : List Nat + boundaries : List Boundary + batchAssumptions : List (Nat × Nat) + +def privateDesign : EngineeringDesign := { + metadata := sameShape, run := orderedUnique, paths := changePath .presentSimple, + components := List.range 8, boundaries := [], batchAssumptions := moduleAssumptions } + +def documentedDesign : EngineeringDesign := { + privateDesign with paths := changePath .evolvable } + +def sortedDesign : EngineeringDesign := { documentedDesign with run := sortedUnique } + +/- This application has a caller at component 2 and a callee at component 1. +Editing the callee crosses that actual edge. The caller must recheck the +observable order contract in this finite case; the contract name alone is not +evidence that either the verification work or the observable equality holds. -/ +def coordinatedBoundary : Boundary := ⟨2, 1, "order-preserving queue"⟩ + +def boundaryDesign : EngineeringDesign := + { documentedDesign with boundaries := [coordinatedBoundary] } + +def crossesBoundary (design : EngineeringDesign) (direction : Change) (edge : Boundary) : Bool := + design.boundaries.contains edge && design.components.contains edge.caller && + design.components.contains edge.callee && edge.caller != edge.callee && + (design.paths direction).any (fun step => step.component == edge.callee && + (step.tool == .editor || step.tool == .compiler)) + +def boundaryObligationChecked (design : EngineeringDesign) (direction : Change) + (edge : Boundary) : Bool := + crossesBoundary design direction edge && + (design.paths direction).any (fun step => step.component == edge.caller && + step.tool == .contractRunner && step.requires == .publicContract) && + decide (PreservesFinite orderedUnique design.run) + +def omittedCallerCheck : EngineeringDesign := + { boundaryDesign with paths := fun direction => + (boundaryDesign.paths direction).filter (fun step => + !(step.component == coordinatedBoundary.caller && step.tool == .contractRunner)) } + +def otherCalleeBoundary : Boundary := { coordinatedBoundary with callee := 7 } + +def otherCalleeDesign : EngineeringDesign := + { boundaryDesign with boundaries := [otherCalleeBoundary] } + +theorem actualCrossBoundaryObligation : + crossesBoundary boundaryDesign .coordinated coordinatedBoundary = true ∧ + boundaryObligationChecked boundaryDesign .coordinated coordinatedBoundary = true ∧ + crossesBoundary omittedCallerCheck .coordinated coordinatedBoundary = true ∧ + boundaryObligationChecked omittedCallerCheck .coordinated coordinatedBoundary = false ∧ + crossesBoundary otherCalleeDesign .coordinated otherCalleeBoundary = false ∧ + boundaryObligationChecked { boundaryDesign with run := sortedUnique } + .coordinated coordinatedBoundary = false := by decide + +/-- organon-map CoreReader.Engineering.structuralCases +software-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +software-engineering.structural-judgment#p2 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +-/ +theorem structuralCases : + StructuralAccount continuingActivity .evolvable (structuralEvidence .evolvable .designRevision) ∧ + (propagation .presentSimple .designRevision).length = 3 ∧ + (propagation .evolvable .designRevision).length = 2 ∧ + (changePath .evolvable .coordinated).any (fun s => s.component == 2 && s.requires == .publicContract) = true ∧ + PreservesFinite orderedUnique orderedRefactor ∧ + (structuralEvidence .evolvable .designRevision).observedBefore ≠ + (structuralEvidence .evolvable .designRevision).observedAfter ∧ + staticBatch 21 10 = liveBatch 21 10 ∧ staticBatch 21 5 ≠ liveBatch 21 5 ∧ + changeWork .presentSimple .withdrawal = 17 ∧ + (crossesBoundary boundaryDesign .coordinated coordinatedBoundary = true ∧ + boundaryObligationChecked boundaryDesign .coordinated coordinatedBoundary = true ∧ + crossesBoundary omittedCallerCheck .coordinated coordinatedBoundary = true ∧ + boundaryObligationChecked omittedCallerCheck .coordinated coordinatedBoundary = false ∧ + crossesBoundary otherCalleeDesign .coordinated otherCalleeBoundary = false ∧ + boundaryObligationChecked { boundaryDesign with run := sortedUnique } + .coordinated coordinatedBoundary = false) := by decide + +abbrev DesignCanChange (a : Activity) (design : EngineeringDesign) + (m : Maintainer) (d : Change) : Prop := + design.paths d ≠ [] ∧ m ∈ a.participants ∧ + (design.paths d).all (fun step => + (a.available m).contains step.requires && a.tools.contains step.tool) = true + +def designWork (design : EngineeringDesign) (d : Change) : Nat := + ((design.paths d).map EditStep.units).sum + +def designModulesNeedingRevision (design : EngineeringDesign) (newSize : Nat) : List Nat := + (design.batchAssumptions.filter (fun p => p.2 != newSize)).map Prod.fst + +/- In this finite model, a facade adds an actual component, forwarding edge +and contract verification step. It preserves observable order but does not +remove the original edit/compilation work or supply private maintainer knowledge. -/ +def introduceBoundary (design : EngineeringDesign) : EngineeringDesign := { + metadata := { design.metadata with modules := design.metadata.modules + 1, extensionPoints := design.metadata.extensionPoints + 1 }, + run := fun xs => design.run (xs ++ []), + paths := fun d => if (design.paths d).isEmpty then [] else + design.paths d ++ [⟨design.components.length, .publicContract, .contractRunner, 1⟩], + components := design.components ++ [design.components.length], + boundaries := design.boundaries ++ + [⟨design.components.length, 0, design.metadata.signature⟩], + batchAssumptions := design.batchAssumptions } + +def wrappedDesign : EngineeringDesign := introduceBoundary privateDesign + +/- This second facade relocates the existing contract-verification work to +the new component. It changes the actual boundary and step locations without +reducing the work or making the private edit knowledge public. -/ +def relocateVerification (design : EngineeringDesign) : EngineeringDesign := { + introduceBoundary design with + paths := fun d => (design.paths d).map (fun step => + if step.tool = .contractRunner then { step with component := design.components.length } + else step) } + +def sameWorkDesign : EngineeringDesign := relocateVerification privateDesign + +/-- organon-map CoreReader.Engineering.structureNotCapability +software-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +software-engineering.structural-judgment#p2 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +-/ +theorem structureNotCapability : + (privateDesign.metadata.signature = sortedDesign.metadata.signature ∧ + privateDesign.run [2, 1, 2] = [2, 1] ∧ sortedDesign.run [2, 1, 2] ≠ [2, 1]) ∧ + (privateDesign.metadata.modules = privateDesign.components.length ∧ + privateDesign.batchAssumptions.length = 8 ∧ + (designModulesNeedingRevision privateDesign 5).length = 8) ∧ + (privateDesign.metadata.principle = "dependency inversion" ∧ + privateDesign.metadata = documentedDesign.metadata ∧ + ¬ DesignCanChange continuingActivity privateDesign .successor .designRevision ∧ + DesignCanChange continuingActivity documentedDesign .successor .designRevision) ∧ + (privateDesign.boundaries.length = 0 ∧ wrappedDesign.boundaries.length = 1 ∧ + wrappedDesign.components.length = 9 ∧ + wrappedDesign.boundaries = [⟨8, 0, "List Nat → List Nat"⟩] ∧ + wrappedDesign.run [2, 1, 2] = privateDesign.run [2, 1, 2] ∧ + designWork privateDesign .designRevision = 17 ∧ + designWork wrappedDesign .designRevision = 18 ∧ + ¬ designWork wrappedDesign .designRevision < designWork privateDesign .designRevision) ∧ + (sameWorkDesign.boundaries = [⟨8, 0, "List Nat → List Nat"⟩] ∧ + sameWorkDesign.components.length = 9 ∧ + sameWorkDesign.paths .designRevision ≠ privateDesign.paths .designRevision ∧ + sameWorkDesign.run [2, 1, 2] = privateDesign.run [2, 1, 2] ∧ + designWork sameWorkDesign .designRevision = designWork privateDesign .designRevision ∧ + designWork sameWorkDesign .designRevision = 17 ∧ + ¬ DesignCanChange continuingActivity sameWorkDesign .successor .designRevision) := by + exact ⟨by decide, by decide, by decide, by decide, by decide⟩ + +/-- organon-map CoreReader.Engineering.contractPreservation +software-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +-/ +theorem contractPreservation {Input Output : Type} (scope : Input → Prop) + (old new : Input → Output) (observations : ∀ x, scope x → new x = old x) : + PreservesOn scope old new := observations + +theorem changedObservationNotPreserved {Input Output : Type} (scope : Input → Prop) + (old new : Input → Output) (x : Input) (inside : scope x) + (different : new x ≠ old x) : ¬ PreservesOn scope old new := by + intro h + exact different (h x inside) + +theorem contractRevisionObligations (old new : ObservableContract) + (r : ContractRevision) (account : ContractChangeAccount old new r) + (changed : ¬ PreservesContractFinite old new) : + RevisionDuties old new r := account.resolve_left changed + +def retiredBehavior (xs : List Nat) : List Nat := + if xs = [99] then [] else orderedUnique xs + +/-- organon-map CoreReader.Engineering.contractCases +software-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +-/ +theorem contractCases : + ContractChangeAccount originalContract refactoredContract normalRevision ∧ + ContractChangeAccount originalContract revisedContract normalRevision ∧ + ¬ ContractChangeAccount originalContract revisedContract { normalRevision with affected := [] } ∧ + PreservesFinite orderedUnique retiredBehavior ∧ retiredBehavior [99] ≠ orderedUnique [99] ∧ + ContractChangeAccount originalContract revisedContract { normalRevision with procedure := "paired audit" } := by decide + +/-- organon-map CoreReader.Engineering.contractDistinctions +software-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +-/ +theorem contractDistinctions : + PreservesFinite orderedUnique orderedRefactor ∧ + ¬ PreservesFinite orderedUnique sortedUnique ∧ + retry originalContract 3 = false ∧ retry revisedContract 3 = true ∧ + ¬ PreservesContractFinite originalContract revisedContract ∧ + affectedParties originalContract revisedContract = ["queue consumer", "queue operator"] ∧ + ¬ ContractChangeAccount originalContract revisedContract + { normalRevision with affected := ["queue consumer"] } ∧ + ¬ ContractChangeAccount originalContract revisedContract + { normalRevision with oldFailureLimit := 5, recordedOldFailureLimit := 5 } ∧ + ContractChangeAccount originalContract revisedContract normalRevision ∧ + PreservesFinite orderedUnique retiredBehavior ∧ retiredBehavior [99] ≠ orderedUnique [99] := by decide + +/- Revision records time-indexed evidence rather than changing a past event. +Judgment is choice under current evidence; forecast truth is a separate value. -/ +structure RevisionState where + time : Nat + forecast : List Change + maintenance : Nat + maintainers : List Maintainer + migrationCost : Nat + objectiveCapacity : Nat + choice : Candidate + deriving DecidableEq, Repr +structure RevisionRecord where + software : String + old : RevisionState + current : RevisionState + recordedOld : RevisionState + recordedCurrent : RevisionState + predictedBatchCount : Nat + actualBatchCount : Nat + reportedPredictionSucceeded : Bool + consideredChanges : List Change + criticizedDirections : List Change + +abbrev MaterialGroundsChanged (old current : RevisionState) : Prop := + old.forecast ≠ current.forecast ∨ old.maintenance ≠ current.maintenance ∨ + old.maintainers ≠ current.maintainers ∨ + old.migrationCost ≠ current.migrationCost ∨ old.objectiveCapacity ≠ current.objectiveCapacity + +def oldState : RevisionState := ⟨0, [.designRevision], 6, [.original], 8, 12, .evolvable⟩ +def newState : RevisionState := ⟨1, [.deletion], 2, [.successor, .agent], 14, 10, .presentSimple⟩ + +structure HistoricalEvidence where + software : String + state : RevisionState + predictedBatchCount : Nat + actualBatchCount : Nat + +/- Independent event content: the recorded predictor used a fixed batch size +of ten; the actual event had runtime size five and twenty-one queue items. -/ +def observedHistory : HistoricalEvidence := + ⟨"order-preserving queue", oldState, staticBatch 21 5, liveBatch 21 5⟩ + +abbrev RevisionAccountAgainst (history : HistoricalEvidence) (r : RevisionRecord) : Prop := + r.software = history.software ∧ + r.old = history.state ∧ r.recordedOld = history.state ∧ + r.predictedBatchCount = history.predictedBatchCount ∧ + r.actualBatchCount = history.actualBatchCount ∧ + r.old.time < r.current.time ∧ r.recordedCurrent = r.current ∧ + (r.old.choice ≠ r.current.choice → MaterialGroundsChanged r.old r.current) ∧ + r.reportedPredictionSucceeded = decide (history.predictedBatchCount = history.actualBatchCount) ∧ + r.consideredChanges.all (fun d => r.criticizedDirections.contains d) = true + +/-- organon-map CoreReader.Engineering.RevisionAccount +software-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +software-engineering.revision#p1 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +-/ +abbrev RevisionAccount (r : RevisionRecord) : Prop := RevisionAccountAgainst observedHistory r + +theorem failedHistoryNotRewritten (history : HistoricalEvidence) (r : RevisionRecord) + (account : RevisionAccountAgainst history r) + (failed : history.predictedBatchCount ≠ history.actualBatchCount) : + r.reportedPredictionSucceeded = false := by + simpa [failed] using account.2.2.2.2.2.2.2.2.1 + +def revisionRecord : RevisionRecord := { + software := "order-preserving queue", + old := oldState, current := newState, recordedOld := oldState, recordedCurrent := newState, + predictedBatchCount := staticBatch 21 5, actualBatchCount := liveBatch 21 5, + reportedPredictionSucceeded := false, + consideredChanges := changes, criticizedDirections := changes } + +abbrev SupportedAlternative (gs : List DirectionGround) (d : Change) : Prop := credible gs d + +abbrev RetentionJustified (ctx : Context) (alternatives : List Change) : Prop := + alternatives.all (fun d => !decide (SupportedAlternative ctx.evidence d)) = true ∨ + JustifiedDeparture ctx .evolvable + +def stableRecord : RevisionRecord := { revisionRecord with + current := { newState with choice := .evolvable }, + recordedCurrent := { newState with choice := .evolvable } } + +/-- organon-map CoreReader.Engineering.revisionCases +software-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +software-engineering.revision#p1 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +-/ +theorem revisionCases : + RevisionAccount revisionRecord ∧ + revisionRecord.old.forecast ≠ revisionRecord.current.forecast ∧ + revisionRecord.old.maintenance ≠ revisionRecord.current.maintenance ∧ + revisionRecord.old.maintainers ≠ revisionRecord.current.maintainers ∧ + revisionRecord.old.migrationCost ≠ revisionRecord.current.migrationCost ∧ + revisionRecord.old.objectiveCapacity ≠ revisionRecord.current.objectiveCapacity ∧ + revisionRecord.predictedBatchCount ≠ revisionRecord.actualBatchCount ∧ + RetentionJustified currentContinuing [.other "quantum backend"] ∧ + RetentionJustified (threatened .migration) [.migration] := by decide + +def observations : List (Nat × Nat) := [(21, 10), (30, 10), (40, 10)] +def revisionsMade : List Nat := [1, 2, 3] +def agreedBatch (reviewers : List Maintainer) (items size : Nat) : List Nat := + reviewers.map (fun _ => staticBatch items size) + +def rewrittenOldRecord : RevisionRecord := { revisionRecord with + old := { oldState with forecast := [.deletion] }, + recordedOld := { oldState with forecast := [.deletion] } } + +def rewrittenPredictionRecord : RevisionRecord := { revisionRecord with + predictedBatchCount := 5, reportedPredictionSucceeded := true } + +def rewrittenObservationRecord : RevisionRecord := { revisionRecord with + actualBatchCount := 3, reportedPredictionSucceeded := true } + +def unrelatedSoftwareRecord : RevisionRecord := { + revisionRecord with software := "unrelated batch processor" } + +theorem historicalTamperingRejected : + RevisionAccount revisionRecord ∧ + ¬ RevisionAccount rewrittenOldRecord ∧ + ¬ RevisionAccount rewrittenPredictionRecord ∧ + ¬ RevisionAccount rewrittenObservationRecord ∧ + observedHistory.predictedBatchCount = 3 ∧ observedHistory.actualBatchCount = 5 ∧ + ¬ RevisionAccount unrelatedSoftwareRecord := by + exact ⟨by decide, by decide, by decide, by decide, by decide, by decide, by decide⟩ + +/-- organon-map CoreReader.Engineering.revisionLimits +software-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +software-engineering.revision#p1 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +-/ +theorem revisionLimits : + RevisionAccount revisionRecord ∧ + ¬ RevisionAccount { revisionRecord with reportedPredictionSucceeded := true } ∧ + revisionsMade.length = 3 ∧ + agreedBatch maintainers 21 5 = [3, 3, 3] ∧ liveBatch 21 5 = 5 ∧ + observations.all (fun p => staticBatch p.1 p.2 == liveBatch p.1 p.2) = true ∧ + staticBatch 21 5 ≠ liveBatch 21 5 ∧ + RevisionAccount stableRecord ∧ stableRecord.current.choice = stableRecord.old.choice ∧ + RetentionJustified currentContinuing [.other "quantum backend"] := by + refine ⟨by decide, ?_, by decide, by decide, by decide, by decide, + by decide, by decide, by decide, by decide⟩ + dsimp [RevisionAccount, RevisionAccountAgainst, observedHistory, MaterialGroundsChanged, revisionRecord, oldState, newState] + decide + +def groundedChanges : DirectionGround → List Change + | .plan _ ds | .knowledge _ ds _ | .history _ ds | .other _ ds => ds + +def currentRevisionState (ctx : Context) (chosen : Candidate) : RevisionState := { + time := 1, forecast := ctx.evidence.flatMap groundedChanges, + maintenance := ctx.activity.scheduledMaintenance, maintainers := ctx.activity.participants, + migrationCost := cost chosen .migration, + objectiveCapacity := ctx.limits.capacity .migration, + choice := chosen } + +def revisionFor (ctx : Context) (chosen : Candidate) : RevisionRecord := { + stableRecord with software := ctx.activity.software, current := currentRevisionState ctx chosen, recordedCurrent := currentRevisionState ctx chosen } + +theorem revisionContextIdentity : + (revisionFor currentContinuing .evolvable).software = currentContinuing.activity.software ∧ + (revisionFor currentContinuing .evolvable).software = observedHistory.software ∧ (revisionFor currentContinuing .evolvable).current.maintenance = + currentContinuing.activity.scheduledMaintenance ∧ + (revisionFor currentContinuing .evolvable).current.maintainers = currentContinuing.activity.participants ∧ + (revisionFor currentContinuing .evolvable).current.migrationCost = cost .evolvable .migration ∧ + (revisionFor currentContinuing .evolvable).current.objectiveCapacity = + currentContinuing.limits.capacity .migration ∧ + (revisionFor currentContinuing .evolvable).current.choice = .evolvable ∧ + RevisionAccount (revisionFor currentContinuing .evolvable) := by decide + +/- Whole domain satisfaction keeps actual subject, credibility, account and +revision duties. The same context is passed to priority and every domain duty. +Application account choices below are finite records, not universal claims. -/ +abbrev DomainSatisfied (ctx : Context) (chosen : Candidate) : Prop := + ActivityScope ctx.activity ∧ EvolutionPriority ctx chosen ∧ + credible ctx.evidence .designRevision ∧ + (ctx.departure ≠ none → JustifiedDeparture ctx .evolvable) ∧ + EvolutionClaim ctx.activity chosen ⟨.designRevision, .successor, .revise⟩ ∧ + StructuralAccount ctx.activity chosen (structuralEvidence chosen .designRevision) ∧ + ContractChangeAccount (orderContract (behavior chosen)) (evolutionContract .designRevision) normalRevision ∧ + RevisionAccount (revisionFor ctx chosen) + +theorem currentDomainSatisfied : DomainSatisfied currentContinuing .evolvable := by + refine ⟨by decide, by decide, by decide, ?_, by decide, by decide, by decide, by decide⟩ + simp [currentContinuing] + +end CoreReader.Engineering +``` + + + + **L1** 加载 Lean 标准库,供本模型使用列表、算术、字符串及可判定的有限检查。 + + + **L3** 把应用词汇和结论放入 CoreReader.Engineering 命名空间,与继承的 Core 接口区分。 + + + **L5** 工作量数字计数有限场景中明确设定的编辑操作;它们不是各类负担的通用换算率,也不是未来工程表现的实测预测。 + + + **L6** 工作量数字计数有限场景中明确设定的编辑操作;它们不是各类负担的通用换算率,也不是未来工程表现的实测预测。 + + + **L7** 三种维护者角色区分原作者、接任者和代理,因此原作者可修改并不等于持续维护能力。 + + + **L8** 三种维护者角色区分原作者、接任者和代理,因此原作者可修改并不等于持续维护能力。 + + + **L9** 自动为 Maintainer 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。 + + + **L10** 工具区分编辑、编译、合同检查和迁移;变更路径所需工具必须实际可用。 + + + **L11** 工具区分编辑、编译、合同检查和迁移;变更路径所需工具必须实际可用。 + + + **L12** 自动为 Tool 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。 + + + **L13** 知识区分私有实现布局、公共合同以及变更和迁移指南;这些前提用来区分维护者能力。 + + + **L14** 知识区分私有实现布局、公共合同以及变更和迁移指南;这些前提用来区分维护者能力。 + + + **L15** 自动为 Knowledge 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。 + + + **L16** 变更词汇包含六种主要演化操作、独立和协同工作、设计修订及开放的命名扩展;九项示例列表并不穷尽该类型。 + + + **L17** 变更词汇包含六种主要演化操作、独立和协同工作、设计修订及开放的命名扩展;九项示例列表并不穷尽该类型。 + + + **L18** 变更词汇包含六种主要演化操作、独立和协同工作、设计修订及开放的命名扩展;九项示例列表并不穷尽该类型。 + + + **L19** 自动为 Change 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。 + + + **L20** 三种候选设计分别用于比较当下简单性、可信演化支持和更多已登记扩展能力;优劣由后续行为与工作量数据说明。 + + + **L21** 三种候选设计分别用于比较当下简单性、可信演化支持和更多已登记扩展能力;优劣由后续行为与工作量数据说明。 + + + **L22** 自动为 Candidate 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。 + + + **L23** 七种不同负担覆盖理解、构建、诊断、验证、协调、运行和迁移;模型不要求把它们加总。 + + + **L24** 七种不同负担覆盖理解、构建、诊断、验证、协调、运行和迁移;模型不要求把它们加总。 + + + **L25** 七种不同负担覆盖理解、构建、诊断、验证、协调、运行和迁移;模型不要求把它们加总。 + + + **L26** 自动为 Burden 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。 + + + **L28** 具体活动包含三类维护者,使接任者与代理能力断言具有实际对象。 + + + **L29** 为有限案例登记九种常规变更;其他命名变更仍可另行表示。 + + + **L30** 为有限案例登记九种常规变更;其他命名变更仍可另行表示。 + + + **L31** 列出全部已表示成本维度,使威胁检查能逐维度进行。 + + + **L32** 列出全部已表示成本维度,使威胁检查能逐维度进行。 + + + **L34** 工程活动把能力断言相关的人员或代理、软件、工具、知识与生命周期预期放在同一对象中。 + + + **L35** 记录参与该活动的维护者;个人变更能力随后要求属于此名单。 + + + **L36** 标识所维护的软件;后续修订报告也据此绑定实际任务。 + + + **L37** 记录可用工具,而不假定所有所需工具都存在。 + + + **L38** 按维护者分别指定可用知识,允许原作者掌握接任者不知道的私有细节。 + + + **L39** 以计划发布次数作为持续开发预期的一项具体指标。 + + + **L40** 独立于发布次数记录计划维护量。 + + + **L41** 可选的有限运行界限表示真正有界的用途;仅无界限并非持续活动的定义。 + + + **L42** 把描述标签与生命周期事实分开,以便检验误称为 temporary 的情况。 + + + **L44** 开始来源映射注释,把 CoreReader.Engineering.ActivityScope 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。 + + + **L45** 为 CoreReader.Engineering.ActivityScope 记录源文引用 software-engineering.purpose/p1,该直接正文的 SHA256 为 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b。这是可追踪绑定,不是新增前提或语义证明。 + + + **L46** 为 CoreReader.Engineering.ActivityScope 记录源文引用 software-engineering.purpose/p2,该直接正文的 SHA256 为 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b。这是可追踪绑定,不是新增前提或语义证明。 + + + **L47** 为 CoreReader.Engineering.ActivityScope 记录源文引用 software-engineering.purpose/p3,该直接正文的 SHA256 为 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b。这是可追踪绑定,不是新增前提或语义证明。 + + + **L48** 结束 CoreReader.Engineering.ActivityScope 的源文映射注释;其后恢复可执行声明。 + + + **L49** 活动范围是工程主体的具体适用条件,不是赋予代码的内在意图。 + + + **L50** 要求实际参与者、非空软件标识和可用工具。 + + + **L51** 每名已列维护者都须有某些知识;这尚不表明知识足以支持所有变更。 + + + **L53** 本模型把计划发布和维护均为正作为持续活动条件;活动名称无关。 + + + **L54** 本模型把计划发布和维护均为正作为持续活动条件;活动名称无关。 + + + **L56** 有界生命周期要求声明有限运行上限,且没有计划发布或维护;仅 temporary 标签不能满足它。 + + + **L57** 有界生命周期要求声明有限运行上限,且没有计划发布或维护;仅 temporary 标签不能满足它。 + + + **L58** 有界生命周期要求声明有限运行上限,且没有计划发布或维护;仅 temporary 标签不能满足它。 + + + **L60** 持续队列活动包含全部维护者和四种工具;软件标识为保持顺序的队列。 + + + **L61** 持续队列活动包含全部维护者和四种工具;软件标识为保持顺序的队列。 + + + **L62** 持续队列活动包含全部维护者和四种工具;软件标识为保持顺序的队列。 + + + **L63** 只有原维护者拥有 privateLayout;接任者与代理拥有公共合同和指南,形成真实的前提差异。 + + + **L64** 只有原维护者拥有 privateLayout;接任者与代理拥有公共合同和指南,形成真实的前提差异。 + + + **L65** 只有原维护者拥有 privateLayout;接任者与代理拥有公共合同和指南,形成真实的前提差异。 + + + **L66** 活动计划三次发布、六个维护单位,两项持续生命周期指标均为正。 + + + **L67** 虽然标签写 temporary,却没有有限运行界限;后续案例拒绝以此标签证明生命周期有界。 + + + **L69** 一次性变式清除计划发布和维护,并设单次运行界限,构成真正有界的示例。 + + + **L70** 一次性变式清除计划发布和维护,并设单次运行界限,构成真正有界的示例。 + + + **L71** 一次性变式清除计划发布和维护,并设单次运行界限,构成真正有界的示例。 + + + **L72** 原型保留零维护的有界配置,但允许运行四次。 + + + **L73** 原型保留零维护的有界配置,但允许运行四次。 + + + **L74** 退役服务使用相同有界配置,并设两次剩余运行。 + + + **L75** 退役服务使用相同有界配置,并设两次剩余运行。 + + + **L77** 每个编辑步骤记录工作位置、所需知识与工具,以及设定的工作单位。 + + + **L78** 标识该工作步骤涉及的组件。 + + + **L79** 给出执行维护者必须具备的知识前提。 + + + **L80** 给出该步骤所需工具。 + + + **L81** 为这个明确操作指定自然数成本;后续总量对这些单位求和。 + + + **L82** 自动为 EditStep 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。 + + + **L84** 按候选设计和预期变更构造明确工作路径,而非根据设计标签赋予能力。 + + + **L85** presentSimple 需要私有布局知识;其他设计使用接任者具备的变更指南。 + + + **L86** 每条常规路径先在组件 0 编辑,再检查公共合同,两步各耗一个单位。 + + + **L87** 每条常规路径先在组件 0 编辑,再检查公共合同,两步各耗一个单位。 + + + **L88** 按请求的 Change 选择对应编辑路径;后续各分支区分不同变更方向。 + + + **L89** 功能增加和独立变更只使用这条两单位基础路径。 + + + **L90** 替换和删除增加组件 1 的一单位编译步骤,并使用设计所选指南。 + + + **L91** 协同变更新增组件 1 的编译和组件 2 的公共合同验证,各耗三个单位。 + + + **L92** 迁移增加一个需要迁移指南的八单位迁移执行步骤。 + + + **L93** 撤回、边界重划和设计修订按所选设计分支;简单方案与演化方案在此使用不同工作路径。 + + + **L94** 撤回、边界重划和设计修订按所选设计分支;简单方案与演化方案在此使用不同工作路径。 + + + **L95** 简单设计增加依赖私有指南的编辑、编译以及公共合同检查,三步各五单位,总工作量为十七。 + + + **L96** 简单设计增加依赖私有指南的编辑、编译以及公共合同检查,三步各五单位,总工作量为十七。 + + + **L97** 其他设计改为在组件 1 增加两单位编辑和两单位公共合同检查,加基础步骤共六单位。 + + + **L98** 开放的其他变更构造子目前只对 csv export 设置具体特殊路径。 + + + **L99** 开放的其他变更构造子目前只对 csv export 设置具体特殊路径。 + + + **L100** maximal 通过组件 3 上依赖迁移指南的编译支持 CSV 导出,新增两单位工作。 + + + **L101** 其他设计的 CSV 导出需要 privateLayout 和额外二十单位编译工作,因此接任者不具备该路径前提。 + + + **L102** 未识别名称没有路径;非空路径要求防止空列表造成空洞的能力成功。 + + + **L104** 总工作量是实际路径各步骤设定单位之和,不是模块或扩展点数量。 + + + **L105** 总工作量是实际路径各步骤设定单位之和,不是模块或扩展点数量。 + + + **L107** 个人变更能力同时索引实际活动、设计、维护者和预期变更。 + + + **L108** 能力要求非空路径、维护者参与,以及全部步骤的知识和工具前提;任一前提失败都会阻断断言。 + + + **L109** 能力要求非空路径、维护者参与,以及全部步骤的知识和工具前提;任一前提失败都会阻断断言。 + + + **L111** 持续能力要求非空路径,且每名已列维护者均具备执行路径所需知识和工具;活动范围另行要求参与者非空。 + + + **L112** 持续能力要求非空路径,且每名已列维护者均具备执行路径所需知识和工具;活动范围另行要求参与者非空。 + + + **L113** 持续能力要求非空路径,且每名已列维护者均具备执行路径所需知识和工具;活动范围另行要求参与者非空。 + + + **L115** 最大能力仅相对于已登记的有限方向集合;CSV 具有具体工作和状态内容,未支持名称不能因空路径而获得能力。 + + + **L116** 最大能力仅相对于已登记的有限方向集合;CSV 具有具体工作和状态内容,未支持名称不能因空路径而获得能力。 + + + **L117** 最大能力仅相对于已登记的有限方向集合;CSV 具有具体工作和状态内容,未支持名称不能因空路径而获得能力。 + + + **L118** 在九种常规变更之外加入 CSV 导出,得到十个登记方向。 + + + **L119** 仅保留所选设计中每名持续维护者均可执行的登记方向。 + + + **L120** 仅保留所选设计中每名持续维护者均可执行的登记方向。 + + + **L121** 候选方案支持固定列表中的全部方向时具备最大登记能力;这不是对所有可想象变更的最大性。 + + + **L122** 候选方案支持固定列表中的全部方向时具备最大登记能力;这不是对所有可想象变更的最大性。 + + + **L124** 被动软件函数与维护者选择的意图分开;示例不把生成取向归于每个工件。 + + + **L125** 被动软件函数与维护者选择的意图分开;示例不把生成取向归于每个工件。 + + + **L126** 工件原样返回输入,不提出变更建议。 + + + **L128** 每名已表示维护者都选择设计修订与迁移,这是活动明确选择的意图。 + + + **L130** 行动区分提出变更建议与执行软件获得输出列表。 + + + **L131** 行动区分提出变更建议与执行软件获得输出列表。 + + + **L132** 行动区分提出变更建议与执行软件获得输出列表。 + + + **L133** 自动为 EngineeringAction 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。 + + + **L135** 维护者意图转为针对各已选方向的实际 propose 行动。 + + + **L136** 维护者意图转为针对各已选方向的实际 propose 行动。 + + + **L138** 工件唯一行动是执行被动函数;行动列表不含提议构造子。 + + + **L139** 工件唯一行动是执行被动函数;行动列表不含提议构造子。 + + + **L141** 开始来源映射注释,把 CoreReader.Engineering.subjectLifecycleCases 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。 + + + **L142** 为 CoreReader.Engineering.subjectLifecycleCases 记录源文引用 software-engineering.purpose/p1,该直接正文的 SHA256 为 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b。这是可追踪绑定,不是新增前提或语义证明。 + + + **L143** 为 CoreReader.Engineering.subjectLifecycleCases 记录源文引用 software-engineering.purpose/p2,该直接正文的 SHA256 为 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b。这是可追踪绑定,不是新增前提或语义证明。 + + + **L144** 为 CoreReader.Engineering.subjectLifecycleCases 记录源文引用 software-engineering.purpose/p3,该直接正文的 SHA256 为 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b。这是可追踪绑定,不是新增前提或语义证明。 + + + **L145** 结束 CoreReader.Engineering.subjectLifecycleCases 的源文映射注释;其后恢复可执行声明。 + + + **L146** 汇集共享队列活动的具体范围、维护者能力和生命周期正例。 + + + **L147** 持续活动满足工程主体的非空范围条件。 + + + **L148** 接任者具备演化方案设计修订所需工具与公共知识。 + + + **L149** 代理也具备同一设计修订的前提。 + + + **L150** 具体活动即使带有 temporary 标签,仍然属于持续活动。 + + + **L151** 持续活动并非有界;一次性、原型和退役变式则满足各自明确的有限生命周期条件。 + + + **L152** 持续活动并非有界;一次性、原型和退役变式则满足各自明确的有限生命周期条件。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。 + + + **L154** 开始来源映射注释,把 CoreReader.Engineering.subjectLimits 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。 + + + **L155** 为 CoreReader.Engineering.subjectLimits 记录源文引用 software-engineering.purpose/p1,该直接正文的 SHA256 为 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b。这是可追踪绑定,不是新增前提或语义证明。 + + + **L156** 为 CoreReader.Engineering.subjectLimits 记录源文引用 software-engineering.purpose/p2,该直接正文的 SHA256 为 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b。这是可追踪绑定,不是新增前提或语义证明。 + + + **L157** 为 CoreReader.Engineering.subjectLimits 记录源文引用 software-engineering.purpose/p3,该直接正文的 SHA256 为 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b。这是可追踪绑定,不是新增前提或语义证明。 + + + **L158** 结束 CoreReader.Engineering.subjectLimits 的源文映射注释;其后恢复可执行声明。 + + + **L159** 汇集反例,说明不能从较弱事实推断持续能力或软件意图。 + + + **L160** 原维护者拥有私有布局知识,因此可以修订简单设计。 + + + **L161** 接任者缺少私有知识前提,无法执行同一简单设计修订。 + + + **L162** 因此,简单设计并不支持所有持续维护者执行该修订。 + + + **L163** temporary 标签与实际有界生命周期条件不成立同时存在。 + + + **L164** 代理意图非空,而被动工件仍仅返回 [2,1]。 + + + **L165** 设计修订建议出现在代理行动中,却不在工件执行行动中。 + + + **L166** 设计修订建议出现在代理行动中,却不在工件执行行动中。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。 + + + **L168** 可信性以可表述性检查和支持关系为参数;后续示例不验证所有可能提供的关系。 + + + **L169** 可信性以可表述性检查和支持关系为参数;后续示例不验证所有可能提供的关系。 + + + **L170** 开始来源映射注释,把 CoreReader.Engineering.CredibleDirection 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。 + + + **L171** 为 CoreReader.Engineering.CredibleDirection 记录源文引用 software-engineering.evolution-priority/p2,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。 + + + **L172** 为 CoreReader.Engineering.CredibleDirection 记录源文引用 software-engineering.evolution-priority/p3,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。 + + + **L173** 结束 CoreReader.Engineering.CredibleDirection 的源文映射注释;其后恢复可执行声明。 + + + **L174** 允许任意根据类型,保留可信性来源的开放性。 + + + **L175** 应用分别提供根据是否可表述、是否支持预期方向的检查。 + + + **L176** 某方向可信当且仅当至少一项已列根据通过针对该方向的两项检查。 + + + **L177** 某方向可信当且仅当至少一项已列根据通过针对该方向的两项检查。 + + + **L179** 具体示例采用这些根据记录,但不把构造子视为穷尽的哲学分类。 + + + **L180** 计划记录发布编号与承诺变更。 + + + **L181** 领域知识记录相关服务、受影响变更及机制说明。 + + + **L182** 历史记录服务及观察到的变更方向。 + + + **L183** other 构造子保留其他可表述说明及其支持变更的空间。 + + + **L184** 自动为 DirectionGround 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。 + + + **L186** 检查具体根据记录是否具有本应用要求的标识内容。 + + + **L187** 计划须给出正发布编号及至少一个承诺方向。 + + + **L188** 知识须标识服务、若干受影响方向及非空机制说明。 + + + **L189** 历史需要命名服务及某些观察。 + + + **L190** 其他根据需要非空说明及方向列表。 + + + **L192** 按有限应用的具体记录解释支持,而非从字符串推導任意真实世界相关性。 + + + **L193** 正发布编号的计划仅支持其明确包含的方向。 + + + **L194** 指定队列知识在机制为 tenant-config-reload 时支持所列方向;该机制名称属于应用解释。 + + + **L195** 指定队列知识在机制为 tenant-config-reload 时支持所列方向;该机制名称属于应用解释。 + + + **L196** 队列历史中某方向至少出现两次时支持它;这是应用选择的有限支持规则。 + + + **L197** 特定已评审客户迁移说明仅支持其列出的方向。 + + + **L199** 初始根据承诺在发布 2 进行设计修订和迁移。 + + + **L200** 修订后的预测改为承诺发布 3 进行删除。 + + + **L201** 把通用可信性专化为 DirectionGround,采用上述具体可表述性和支持解释。 + + + **L202** 把通用可信性专化为 DirectionGround,采用上述具体可表述性和支持解释。 + + + **L204** 所选预先支持检查要求方向可信、目标收益为正且投入不大于收益;这是局部充分准则,不是通用数值换算规则。 + + + **L205** 所选预先支持检查要求方向可信、目标收益为正且投入不大于收益;这是局部充分准则,不是通用数值换算规则。 + + + **L206** 所选预先支持检查要求方向可信、目标收益为正且投入不大于收益;这是局部充分准则,不是通用数值换算规则。 + + + **L208** 开始来源映射注释,把 CoreReader.Engineering.credibilityCases 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。 + + + **L209** 为 CoreReader.Engineering.credibilityCases 记录源文引用 software-engineering.evolution-priority/p2,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。 + + + **L210** 为 CoreReader.Engineering.credibilityCases 记录源文引用 software-engineering.evolution-priority/p3,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。 + + + **L211** 结束 CoreReader.Engineering.credibilityCases 的源文映射注释;其后恢复可执行声明。 + + + **L212** 组合计划、知识和历史支持正例,以及无根据想象和预测修订的对照。 + + + **L213** 实际发布 2 计划支持设计修订。 + + + **L214** 指定队列机制为设计修订提供所声明的知识支持。 + + + **L215** 两次已记录队列迁移满足具体历史支持准则。 + + + **L216** 空根据列表不支持想象中的量子后端。 + + + **L217** 改变后的预测支持删除,并不再支持设计修订。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。 + + + **L219** 给简单、演化和最大方案分别设定当下抽象复杂度 1、3、30;这些是场景参数。 + + + **L220** 给简单、演化和最大方案分别设定当下抽象复杂度 1、3、30;这些是场景参数。 + + + **L222** 目前仅实现简单方案,以展示可信性不要求多个现存实现。 + + + **L224** 优先规则把每类负担与各自容量比较,而非换算成单个评分。 + + + **L225** 成本向量可按负担分别指定自然数量;这一辅助结构不强制汇总。 + + + **L226** 成本向量可按负担分别指定自然数量;这一辅助结构不强制汇总。 + + + **L227** 成本界限为每类负担配对容量与明确目标,使威胁断言针对具体事项。 + + + **L228** 成本界限为每类负担配对容量与明确目标,使威胁断言针对具体事项。 + + + **L229** 成本界限为每类负担配对容量与明确目标,使威胁断言针对具体事项。 + + + **L231** 本场景中,简单基准的各类负担都耗一个单位。 + + + **L232** 本场景中,简单基准的各类负担都耗一个单位。 + + + **L233** 演化方案的理解成本为三单位。 + + + **L234** 演化方案的构建成本为四单位。 + + + **L235** 演化方案的诊断成本为两单位。 + + + **L236** 演化方案的验证成本为四单位。 + + + **L237** 演化方案的协调成本为两单位。 + + + **L238** 演化方案的运行成本为两单位。 + + + **L239** 演化方案迁移成本为八单位,展示并非所有负担都必须低廉。 + + + **L240** 最大方案在每个已表示负担上都耗四十单位。 + + + **L242** 常规情境中每类负担容量均为十二,足以承受演化方案的设定成本。 + + + **L243** 常规情境中每类负担容量均为十二,足以承受演化方案的设定成本。 + + + **L244** 按 Burden 分派并指定对应目标名称;后续分支给出各自不同的工程目标。 + + + **L245** 理解界限对应接任者入门容量。 + + + **L246** 构建容量关联发布准备。 + + + **L247** 诊断容量对应事件诊断时间窗口。 + + + **L248** 验证容量对应发布检查。 + + + **L249** 协调容量对应可用团队协作能力。 + + + **L250** 运行容量对应运行时资源预算。 + + + **L251** 迁移容量对应最终退役迁移。 + + + **L253** 必要需求与演化价值偏好分开。 + + + **L254** 表示是否要求指定的输出顺序合同。 + + + **L255** 限定允许的不安全操作数量。 + + + **L256** 限定观察到的延迟。 + + + **L257** 设定最低保留量要求。 + + + **L259** 常规需求要求保持顺序、无不安全操作、延迟不超过十且保留量至少三十。 + + + **L260** 三个候选行为都按给定顺序删除重复列表值;这一局部相等不等于其维护路径或成本相等。 + + + **L262** 表现记录是本场景设定的观察;后续变式分别违反四个需求门槛。 + + + **L263** 表现记录是本场景设定的观察;后续变式分别违反四个需求门槛。 + + + **L264** 表现记录包含与这些需求相关的四项行为、安全和性能量。 + + + **L265** 保存指定顺序测试观察到的输出。 + + + **L266** 保存该表现记录中的不安全操作数量。 + + + **L267** 保存该表现记录的延迟观察值。 + + + **L268** 保存该表现记录的保留量观察值。 + + + **L270** 各原始表现记录观察 [2,1,2] 去重结果、零不安全操作、延迟五和保留量三十。 + + + **L271** 满足需求时,若要求保持顺序就须得到 [2,1];需求关闭时不强加顺序约束。 + + + **L272** 满足需求时,若要求保持顺序就须得到 [2,1];需求关闭时不强加顺序约束。 + + + **L273** 安全计数和延迟不得超过上限,保留量须达到下限。 + + + **L274** 安全计数和延迟不得超过上限,保留量须达到下限。 + + + **L276** 情境绑定领域规范使用的活动、需求、证据、成本和所选偏离说明。 + + + **L277** 承载实际工程活动及维护者条件。 + + + **L278** 承载相关必要需求。 + + + **L279** 承载未来方向可信性的根据。 + + + **L280** 承载逐类负担的目标容量。 + + + **L281** 可选地标识用于说明偏离演化优先的负担。 + + + **L282** 提供候选表现观察,默认使用常规记录,也允许明确测试变式。 + + + **L284** 共享常规情境使用持续队列、常规需求、发布 2 根据和容量十二的界限,且未提出偏离理由。 + + + **L285** 共享常规情境使用持续队列、常规需求、发布 2 根据和容量十二的界限,且未提出偏离理由。 + + + **L286** 共享常规情境使用持续队列、常规需求、发布 2 根据和容量十二的界限,且未提出偏离理由。 + + + **L288** 具体威胁要求新增成本同时超过简单基准和命名目标容量;只命名负担而无这些不等式不够。 + + + **L289** 具体威胁要求新增成本同时超过简单基准和命名目标容量;只命名负担而无这些不等式不够。 + + + **L290** 具体威胁要求新增成本同时超过简单基准和命名目标容量;只命名负担而无这些不等式不够。 + + + **L292** 七个已表示负担维度中有一项满足具体威胁条件,就存在威胁。 + + + **L293** 七个已表示负担维度中有一项满足具体威胁条件,就存在威胁。 + + + **L295** 开始来源映射注释,把 CoreReader.Engineering.JustifiedDeparture 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。 + + + **L296** 为 CoreReader.Engineering.JustifiedDeparture 记录源文引用 software-engineering.evolution-priority/p3,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。 + + + **L297** 结束 CoreReader.Engineering.JustifiedDeparture 的源文映射注释;其后恢复可执行声明。 + + + **L298** 以记录的负担及其必须成立的具体成本威胁,定义此情境与候选的有根据让步。 + + + **L299** 检查同一情境的 departure 选项,区分未指定说明与已指定负担。 + + + **L300** 未记录让步负担时,根据条件为 False;缺省记录不提供例外。 + + + **L301** 对记录的负担 b,要求同一情境、候选及该负担满足 ConcreteThreat。 + + + **L303** 为偏离命题提供判定过程,使有限案例可通过计算检查。 + + + **L304** 展开 JustifiedDeparture 中对可选负担的分支。 + + + **L305** 区分 none 与某负担,由 Lean 获取 False 或具体算术、字符串条件的可判定性。 + + + **L307** 优先适用性是生命周期、可行性、可信性和实际能力比较条件的合取。 + + + **L308** 要求活动持续且具有有效工程主体范围。 + + + **L309** 简单和演化两个方案都必须满足同一情境的必要需求。 + + + **L310** 情境须包含设计修订的可信根据,而不只是想象中的功能增加。 + + + **L311** 每名持续维护者都须能用演化方案执行该设计修订。 + + + **L312** 演化方案实际设计修订路径的工作量须小于简单方案。 + + + **L313** 演化方案须承担更多当下抽象复杂度,使目标取舍具有实际内容。 + + + **L315** 开始来源映射注释,把 CoreReader.Engineering.EvolutionPriority 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。 + + + **L316** 为 CoreReader.Engineering.EvolutionPriority 记录源文引用 software-engineering.purpose/p3,该直接正文的 SHA256 为 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b。这是可追踪绑定,不是新增前提或语义证明。 + + + **L317** 为 CoreReader.Engineering.EvolutionPriority 记录源文引用 software-engineering.evolution-priority/p1,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。 + + + **L318** 为 CoreReader.Engineering.EvolutionPriority 记录源文引用 software-engineering.evolution-priority/p2,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。 + + + **L319** 为 CoreReader.Engineering.EvolutionPriority 记录源文引用 software-engineering.evolution-priority/p3,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。 + + + **L320** 结束 CoreReader.Engineering.EvolutionPriority 的源文映射注释;其后恢复可执行声明。 + + + **L321** 这是采用的可让位优先规范:全部适用条件成立时,应选择演化方案,除非其新增成本具有明确的合理偏离说明;规范并非仅由那些事实推导。 + + + **L322** 这是采用的可让位优先规范:全部适用条件成立时,应选择演化方案,除非其新增成本具有明确的合理偏离说明;规范并非仅由那些事实推导。 + + + **L324** 通过计算证明共享常规情境满足全部优先适用条件。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。 + + + **L325** 通过计算证明常规演化成本不威胁任何已表示目标,也不存在有根据的偏离。 + + + **L326** 通过计算证明常规演化成本不威胁任何已表示目标,也不存在有根据的偏离。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。 + + + **L328** 威胁变式只把选中负担容量降到一,并将该负担记录为偏离理由;其他容量仍为十二。 + + + **L329** 威胁变式只把选中负担容量降到一,并将该负担记录为偏离理由;其他容量仍为十二。 + + + **L330** 威胁变式只把选中负担容量降到一,并将该负担记录为偏离理由;其他容量仍为十二。 + + + **L332** 开始来源映射注释,把 CoreReader.Engineering.priorityWhenApplicable 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。 + + + **L333** 为 CoreReader.Engineering.priorityWhenApplicable 记录源文引用 software-engineering.evolution-priority/p1,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。 + + + **L334** 为 CoreReader.Engineering.priorityWhenApplicable 记录源文引用 software-engineering.evolution-priority/p2,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。 + + + **L335** 为 CoreReader.Engineering.priorityWhenApplicable 记录源文引用 software-engineering.evolution-priority/p3,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。 + + + **L336** 结束 CoreReader.Engineering.priorityWhenApplicable 的源文映射注释;其后恢复可执行声明。 + + + **L337** 条件结论适用于此应用词汇中的任意情境和所选候选。 + + + **L338** 同时假定采用优先规则及其实际适用性;定理没有凭自身证明这两个前提。 + + + **L339** 还假定不存在有根据的成本偏离。 + + + **L340** 在这些前提下,必须选择演化方案,并承担所声明的额外抽象复杂度。 + + + **L341** 在这些前提下,必须选择演化方案,并承担所声明的额外抽象复杂度。 + + + **L342** 把已采用的蕴含应用于实际条件,再用 noDeparture 排除偏离分支。 + + + **L343** 把所得选择相等与适用前提中的最后一项复杂度不等式组合,并代入实际所选候选。 + + + **L345** 证明在常规适用且无威胁情境中选择简单方案违反已采用的演化优先。 + + + **L346** 暂时假定简单选择满足规则,以导出矛盾。 + + + **L347** 实际适用性激活规则,无偏离条件迫使不可能的 simple=evolvable 相等。 + + + **L348** 排除不同候选构造子的相等,完成否定结论。 + + + **L350** 仅替换演化方案的观察记录,保留其他候选记录和情境,以隔离必要需求变式。 + + + **L351** 仅替换演化方案的观察记录,保留其他候选记录和情境,以隔离必要需求变式。 + + + **L353** 检查所示四种需求失败各自使 PriorityConditions 为假。这仅阻止优先条件激活;EvolutionPriority 及后面的 DomainSatisfied 并未施加无条件的 Meets 拒绝要求。 + + + **L354** 把观察顺序从 [2,1] 改为 [1,2] 会使优先适用条件不成立。 + + + **L355** 一次不安全操作超过允许的零,从而使适用条件不成立。 + + + **L356** 延迟十一超过界限十,从而使适用条件不成立。 + + + **L357** 保留量二十九低于三十,从而使适用条件不成立。 + + + **L358** 化简适用条件、修改后的表现记录及需求谓词;每个分支归结为明确失败的相等或数值界限。 + + + **L359** 化简适用条件、修改后的表现记录及需求谓词;每个分支归结为明确失败的相等或数值界限。 + + + **L361** 开始来源映射注释,把 CoreReader.Engineering.priorityConditionsCases 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。 + + + **L362** 为 CoreReader.Engineering.priorityConditionsCases 记录源文引用 software-engineering.purpose/p3,该直接正文的 SHA256 为 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b。这是可追踪绑定,不是新增前提或语义证明。 + + + **L363** 为 CoreReader.Engineering.priorityConditionsCases 记录源文引用 software-engineering.evolution-priority/p1,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。 + + + **L364** 为 CoreReader.Engineering.priorityConditionsCases 记录源文引用 software-engineering.evolution-priority/p2,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。 + + + **L365** 为 CoreReader.Engineering.priorityConditionsCases 记录源文引用 software-engineering.evolution-priority/p3,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。 + + + **L366** 结束 CoreReader.Engineering.priorityConditionsCases 的源文映射注释;其后恢复可执行声明。 + + + **L367** 组合常规优先、四种需求失败、有说明的成本例外以及未选最大复杂度方案的案例。 + + + **L368** 在常规情境选择演化方案满足已采用的优先规范。 + + + **L369** 重排后的输出不满足常规顺序需求。 + + + **L370** 一次不安全操作不满足安全需求。 + + + **L371** 延迟十一不满足性能界限。 + + + **L372** 保留量二十九不满足最低保留需求。 + + + **L373** 验证容量受到具体威胁时,规则可通过偏离分支容许简单选择。 + + + **L374** 即使保留成本威胁数据,去掉偏离说明后也不存在已说明的合理偏离。 + + + **L375** 优先的演化设计复杂度为三,低于最大方案的三十;优先规范不要求最大化复杂度。 + + + **L376** 用有限判定构造合取,只留下缺少偏离说明的分支待化简。 + + + **L377** 偏离说明缺失时 JustifiedDeparture 化为 False,从而证明该否定分支。 + + + **L379** 开始来源映射注释,把 CoreReader.Engineering.priorityChoices 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。 + + + **L380** 为 CoreReader.Engineering.priorityChoices 记录源文引用 software-engineering.evolution-priority/p1,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。 + + + **L381** 为 CoreReader.Engineering.priorityChoices 记录源文引用 software-engineering.evolution-priority/p2,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。 + + + **L382** 为 CoreReader.Engineering.priorityChoices 记录源文引用 software-engineering.evolution-priority/p3,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。 + + + **L383** 结束 CoreReader.Engineering.priorityChoices 的源文映射注释;其后恢复可执行声明。 + + + **L384** 同时呈现实际常规演化选择、常规简单选择被拒及威胁情境容许简单选择。 + + + **L385** 常规演化选择符合已采用规则。 + + + **L386** 常规简单选择不符合相同规则。 + + + **L387** 验证受威胁的情境提供选择简单方案的合理例外。 + + + **L388** 把计算出的正例与此前证明的无威胁简单选择矛盾组合。 + + + **L390** 开始来源映射注释,把 CoreReader.Engineering.credibilityLimits 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。 + + + **L391** 为 CoreReader.Engineering.credibilityLimits 记录源文引用 software-engineering.evolution-priority/p2,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。 + + + **L392** 为 CoreReader.Engineering.credibilityLimits 记录源文引用 software-engineering.evolution-priority/p3,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。 + + + **L393** 结束 CoreReader.Engineering.credibilityLimits 的源文映射注释;其后恢复可执行声明。 + + + **L394** 区分可信计划变更、现存实现数量、想象中的可能性与最大登记能力。 + + + **L395** 设计修订计划可信,同时仅有一个候选实现。 + + + **L396** 无根据、零收益的想象量子后端不能支持五单位投入。 + + + **L397** 初始计划不支持想象中的量子后端方向。 + + + **L398** 常规演化选择仍满足领域优先规范。 + + + **L399** 优先设计的当下复杂度低于最大方案。 + + + **L400** 演化方案内部构建与迁移成本不同,保留负担区别而非单一通用费率。 + + + **L401** 演化方案不能让所有持续维护者支持每个登记方向。 + + + **L402** 最大方案确实支持明确登记的有限集合中的所有方向。 + + + **L403** 演化方案支持九个登记方向。 + + + **L404** 最大方案支持十个,使额外扩展能力具有实质内容而非仅是名称。 + + + **L405** 当前计划不支持 CSV 导出,因此技术上可实现本身不构成当前可信根据。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。 + + + **L407** 开始来源映射注释,把 CoreReader.Engineering.costCases 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。 + + + **L408** 为 CoreReader.Engineering.costCases 记录源文引用 software-engineering.evolution-priority/p3,该直接正文的 SHA256 为 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04。这是可追踪绑定,不是新增前提或语义证明。 + + + **L409** 结束 CoreReader.Engineering.costCases 的源文映射注释;其后恢复可执行声明。 + + + **L410** 逐一检查七类负担都可成为偏离优先规范的具体理由。 + + + **L411** 把理解容量降为一,使演化方案的理解成本成为合理偏离理由。 + + + **L412** 类似的构建容量威胁支持合理偏离。 + + + **L413** 类似的诊断容量威胁支持合理偏离。 + + + **L414** 类似的验证容量威胁支持合理偏离。 + + + **L415** 类似的协调容量威胁支持合理偏离。 + + + **L416** 类似的运行容量威胁支持合理偏离。 + + + **L417** 类似的迁移容量威胁支持合理偏离。 + + + **L418** 在常规容量十二的情境中仅命名迁移,不会产生真实威胁或合理例外。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。 + + + **L420** 以下全函数表示指定去重接口;有限语料上的相等与全称合同保持分开。 + + + **L421** 以下全函数表示指定去重接口;有限语料上的相等与全称合同保持分开。 + + + **L422** 使用标准库保持顺序的列表操作删除重复值。 + + + **L423** 重构执行相同去重并附加空列表,保持输出不变。 + + + **L424** 接收一个自然数及任意自然数列表;类型不含输入已排序的前提。sortValues 调用此辅助函数,在递归排序后的尾列表中按序插入。 + + + **L425** 向空列表插入得到单元素列表。 + + + **L426** 把值放在首个不小于它的头元素之前;否则保留头元素并递归插入尾部。 + + + **L428** 排序递归使用插入操作;它改变顺序,而非仅做去重。 + + + **L429** 空列表排序后仍为空。 + + + **L430** 先排序尾部,再把原头元素插入已排序结果。 + + + **L432** 替代实现先排序再去重,因此可能违反原顺序合同。 + + + **L434** 软件状态字段让不同演化类别改变已表示设计的不同方面。 + + + **L435** 列出软件已表示的能力。 + + + **L436** 标识使用的实现版本。 + + + **L437** 列出可以增删的具体机制。 + + + **L438** 列出可以保留或撤回的抽象。 + + + **L439** 记录边界修订编号,与能力和实现编号区分。 + + + **L440** 标识可迁出的存储技术或模型。 + + + **L441** 记录配置的批次大小。 + + + **L442** 自动为 SoftwareState 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。 + + + **L444** 初始软件支持去重,使用实现 0、队列与旧缓存、固定批次抽象、边界编号 0、旧存储及批次大小十。 + + + **L445** 初始软件支持去重,使用实现 0、队列与旧缓存、固定批次抽象、边界编号 0、旧存储及批次大小十。 + + + **L447** 每个变更方向修改软件状态中实际选定的字段;这是设定的状态模型,而非可执行源码编辑器。 + + + **L448** 增加操作保留已有能力并添加租户批处理。 + + + **L449** 替换操作递增实现标识。 + + + **L450** 删除操作移除旧缓存,保留其他机制。 + + + **L451** 撤回操作移除固定批次抽象。 + + + **L452** 重划操作递增边界修订编号。 + + + **L453** 迁移操作把旧技术换为可移植存储。 + + + **L454** 独立变更只把批次大小更新为五。 + + + **L455** 协同变更同时更新批次大小和边界编号。 + + + **L456** 设计修订把批次设为五、将抽象替换为实时配置,并重划边界。 + + + **L457** 命名 CSV 方向增加实际 CSV 能力;未识别的其他方向保持状态不变。 + + + **L458** 命名 CSV 方向增加实际 CSV 能力;未识别的其他方向保持状态不变。 + + + **L459** 命名 CSV 方向增加实际 CSV 能力;未识别的其他方向保持状态不变。 + + + **L461** 本应用中,重划和设计修订有意采用 sortedUnique 行为;其他变更保留 orderedUnique 行为。 + + + **L462** 本应用中,重划和设计修订有意采用 sortedUnique 行为;其他变更保留 orderedUnique 行为。 + + + **L464** 开放变更类别、工作需求、维护者知识与义务处理方式彼此独立,不折合成单个可扩展性分数。 + + + **L465** 开放变更类别、工作需求、维护者知识与义务处理方式彼此独立,不折合成单个可扩展性分数。 + + + **L466** 变更断言明确说明其保持义务还是有意修订义务。 + + + **L467** 变更断言明确说明其保持义务还是有意修订义务。 + + + **L468** 变更断言明确说明其保持义务还是有意修订义务。 自动为 ObligationTreatment 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。 + + + **L469** 在同一断言中组合预期方向、执行维护者和声明的义务处理方式。 + + + **L470** 标识所断言能力针对的变更。 + + + **L471** 标识其条件必须支持该变更的维护者。 + + + **L472** 说明同一指定义务是保持还是有意修订。 + + + **L474** 有限顺序语料恰为四个列表:空、[2,1,2]、[1,3,1] 和 [4,4];后续有限保持断言仅限这些输入。 + + + **L475** 全称范围保持要求新旧函数对每个满足所给范围谓词的输入都相等。 + + + **L476** 全称范围保持要求新旧函数对每个满足所给范围谓词的输入都相等。 + + + **L478** 有限保持仅用布尔相等检查声明语料;它不推出前述覆盖所有范围输入的性质。 + + + **L479** 有限保持仅用布尔相等检查声明语料;它不推出前述覆盖所有范围输入的性质。 + + + **L481** 合同与观察者依赖独立于报告提供,防止修改报告就重定义实际新旧行为或受影响人群。 + + + **L482** 合同与观察者依赖独立于报告提供,防止修改报告就重定义实际新旧行为或受影响人群。 + + + **L483** 合同与观察者依赖独立于报告提供,防止修改报告就重定义实际新旧行为或受影响人群。 + + + **L484** 可观察合同组合顺序行为和重试界限。 + + + **L485** 顺序函数是实际可观察行为,而非仅合同名称。 + + + **L486** 重试阈值属于实际合同。 + + + **L488** 尝试编号低于 maxAttempts 时才允许重试,使阈值变化具有可观察后果。 + + + **L489** 尝试编号低于 maxAttempts 时才允许重试,使阈值变化具有可观察后果。 + + + **L491** 常规顺序合同把所给函数与阈值三配对。 + + + **L492** 原合同使用保持顺序的去重及阈值三。 + + + **L493** 重构合同仅换成外延相同的重构函数,保留阈值三。 + + + **L494** 有意修订采用排序去重和阈值五,改变两项已表示合同方面。 + + + **L495** 方向对应合同采用实际演化行为,仅在重划或设计修订时提高重试阈值。 + + + **L496** 方向对应合同采用实际演化行为,仅在重划或设计修订时提高重试阈值。 + + + **L498** 有限重试语料包含零至五的尝试编号。 + + + **L499** 有限完整合同保持同时要求 contractInputs 上顺序相等及 failureInputs 上重试相等。 + + + **L500** 有限完整合同保持同时要求 contractInputs 上顺序相等及 failureInputs 上重试相等。 + + + **L501** 有限完整合同保持同时要求 contractInputs 上顺序相等及 failureInputs 上重试相等。 + + + **L503** 顺序与重试是不同可观察合同方面,允许不同参与方分别依赖。 + + + **L504** 顺序与重试是不同可观察合同方面,允许不同参与方分别依赖。 + + + **L505** 顺序与重试是不同可观察合同方面,允许不同参与方分别依赖。 自动为 ContractAspect 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。 + + + **L506** 依赖记录把命名参与方与其观察的合同方面连接。 + + + **L507** 标识义务可能受影响的参与方。 + + + **L508** 标识该参与方依赖的具体可观察方面。 + + + **L509** 自动为 PartyDependency 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。 + + + **L511** 队列消费者依赖顺序,队列运维者依赖重试行为;这些依赖在修订报告之外固定。 + + + **L512** 队列消费者依赖顺序,队列运维者依赖重试行为;这些依赖在修订报告之外固定。 + + + **L514** 按每项方面的有限观察,从实际新旧合同检测变化。 + + + **L515** 任一声明顺序输入产生不同输出时,顺序方面发生变化。 + + + **L516** 任一声明尝试编号产生不同许可结果时,重试方面发生变化。 + + + **L518** 受影响参与方列表从其观察方面确实变化的固定依赖计算,而非取自报告自己的声称。 + + + **L519** 受影响参与方列表从其观察方面确实变化的固定依赖计算,而非取自报告自己的声称。 + + + **L520** 受影响参与方列表从其观察方面确实变化的固定依赖计算,而非取自报告自己的声称。 + + + **L522** 修订说明记录意图、变化后观察、参与方、实际界限声称、已记录界限及程序说明。 + + + **L523** 表明合同改变是有意的。 + + + **L524** 记录指定样本上的修订后顺序输出。 + + + **L525** 列出报告承认的参与方;后续责任把它与实际受影响参与方比较。 + + + **L526** 给出报告声称的原重试阈值。 + + + **L527** 给出报告声称的新重试阈值。 + + + **L528** 保留报告中原阈值的历史记录。 + + + **L529** 保留记录的新阈值。 + + + **L530** 命名所选程序;哲学说明不规定某一种特定程序。 + + + **L532** 常规修订是有意的,并记录新的排序结果 [1,2]。 + + + **L533** 常规修订是有意的,并记录新的排序结果 [1,2]。 + + + **L534** 承认两项实际方面变化影响到消费者与运维者。 + + + **L535** 给出实际重试界限从三变为五。 + + + **L536** 保留记录同样写明之前三、之后五,而非改写原界限。 + + + **L537** 把合同评审用作一种可选程序,而不将该名称设为有效性条件。 + + + **L539** 修订责任针对独立提供的新旧合同及具体报告进行评估。 + + + **L540** 要求有意修订,并准确报告 [2,1,2] 上的新输出。 + + + **L541** 每个实际受影响参与方都须出现在报告中;允许额外列人,也未规定通知义务。 + + + **L542** 报告声称的两个失败界限须等于独立提供的实际阈值。 + + + **L543** 记录的旧界限仍须匹配原合同。 + + + **L544** 记录的新界限须匹配新合同。 + + + **L546** 开始来源映射注释,把 CoreReader.Engineering.ContractChangeAccount 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。 + + + **L547** 为 CoreReader.Engineering.ContractChangeAccount 记录源文引用 software-engineering.structural-judgment/p3,该直接正文的 SHA256 为 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42。这是可追踪绑定,不是新增前提或语义证明。 + + + **L548** 结束 CoreReader.Engineering.ContractChangeAccount 的源文映射注释;其后恢复可执行声明。 + + + **L549** 合同变更说明要么保持全部声明的有限观察,要么履行有意修订责任;二者是不同分支。 + + + **L550** 合同变更说明要么保持全部声明的有限观察,要么履行有意修订责任;二者是不同分支。 + + + **L552** 开始来源映射注释,把 CoreReader.Engineering.EvolutionClaim 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。 + + + **L553** 为 CoreReader.Engineering.EvolutionClaim 记录源文引用 software-engineering.evolution-meaning/p1,该直接正文的 SHA256 为 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6。这是可追踪绑定,不是新增前提或语义证明。 + + + **L554** 为 CoreReader.Engineering.EvolutionClaim 记录源文引用 software-engineering.evolution-meaning/p2,该直接正文的 SHA256 为 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6。这是可追踪绑定,不是新增前提或语义证明。 + + + **L555** 结束 CoreReader.Engineering.EvolutionClaim 的源文映射注释;其后恢复可执行声明。 + + + **L556** 能力断言针对具体维护者和方向,并明确义务处理方式。 + + + **L557** 命名维护者必须实际能够执行预期方向的路径。 + + + **L558** 同一方向的实际新旧合同变更须具备有效保持或修订说明。 + + + **L559** 该方向路径须含合同执行器步骤,使断言关联已表示的验证工作。 + + + **L560** 保持型断言要求指定样本维持原有顺序输出。 + + + **L561** 保持型断言要求指定样本维持原有顺序输出。 + + + **L562** 修订型断言则要求该样本输出实际不同;处理标签不能悄然颠倒观察关系。 + + + **L563** 修订型断言则要求该样本输出实际不同;处理标签不能悄然颠倒观察关系。 + + + **L565** 开始来源映射注释,把 CoreReader.Engineering.evolutionKindsCases 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。 + + + **L566** 为 CoreReader.Engineering.evolutionKindsCases 记录源文引用 software-engineering.evolution-meaning/p1,该直接正文的 SHA256 为 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6。这是可追踪绑定,不是新增前提或语义证明。 + + + **L567** 为 CoreReader.Engineering.evolutionKindsCases 记录源文引用 software-engineering.evolution-meaning/p2,该直接正文的 SHA256 为 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6。这是可追踪绑定,不是新增前提或语义证明。 + + + **L568** 结束 CoreReader.Engineering.evolutionKindsCases 的源文映射注释;其后恢复可执行声明。 + + + **L569** 汇集实际状态变化、接任者能力及保持与修订两类断言示例。 + + + **L570** 增加操作保留去重并添加租户批处理。 + + + **L571** 替换操作把实现编号从零改为一。 + + + **L572** 删除操作移除旧缓存,留下队列机制。 + + + **L573** 撤回操作移除唯一固定批次抽象,抽象列表变空。 + + + **L574** 重划操作把边界编号从零改为一。 + + + **L575** 迁移操作把存储技术改为 portable store。 + + + **L576** 接任者具备所给工具和指南,可执行九条常规演化变更路径。 + + + **L577** 接任者的替换构成有效保持型 EvolutionClaim。 + + + **L578** 代理的边界重划构成有效有意修订型 EvolutionClaim。 + + + **L579** 独立工作耗二单位、协同工作耗八单位,因此二者无需具有相同工作量。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。 + + + **L581** 开始来源映射注释,把 CoreReader.Engineering.evolutionDimensionsLimits 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。 + + + **L582** 为 CoreReader.Engineering.evolutionDimensionsLimits 记录源文引用 software-engineering.evolution-meaning/p1,该直接正文的 SHA256 为 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6。这是可追踪绑定,不是新增前提或语义证明。 + + + **L583** 为 CoreReader.Engineering.evolutionDimensionsLimits 记录源文引用 software-engineering.evolution-meaning/p2,该直接正文的 SHA256 为 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6。这是可追踪绑定,不是新增前提或语义证明。 + + + **L584** 结束 CoreReader.Engineering.evolutionDimensionsLimits 的源文映射注释;其后恢复可执行声明。 + + + **L585** 展示不同演化维度具有不同成本与能力,包括实际最大方案与演化方案的对照。 + + + **L586** 简单设计增加操作耗两单位。 + + + **L587** 撤回其固定结构耗十七单位,明显多于增加。 + + + **L588** 演化方案独立变更工作量少于协同变更。 + + + **L589** 这些不均等成本可与满足演化优先并存。 + + + **L590** 演化迁移耗十单位,虽满足优先规范仍超过九。 + + + **L591** 原维护者可以在简单设计中增加功能。 + + + **L592** 原维护者也可以在演化设计中增加功能。 + + + **L593** 原维护者的私有知识允许其修订简单设计。 + + + **L594** 原维护者也能执行演化方案设计修订。 + + + **L595** 对于同一设计修订方向,演化方案耗六单位,简单方案耗十七单位。 + + + **L596** 两个设计增加操作都耗两单位;设计修订优势不是所有维度上的严格优势。 + + + **L597** CSV 导出实际修改能力列表,在去重之外加入 CSV。 + + + **L598** 接任者具备最大方案 CSV 路径所需指南和工具。 + + + **L599** 接任者缺少演化方案 CSV 路径需要的 privateLayout,尽管该方案还有其他优势。 + + + **L600** 用 Lean 判定过程对明确有限路径、状态和算术逐项构造合取;没有进行经验推广。 + + + **L602** 给出反例,否定从单一方向优势推出所有方向严格改善。 + + + **L603** 保留设计修订上的真实严格改善。 + + + **L604** 否定演化方案对每种 Change 都严格减少工作,包括增加和其他命名方向。 + + + **L605** 计算修订正不等式,并留下全称否定用反例证明。 + + + **L606** 假定每个方向都严格改善,以导出矛盾。 + + + **L607** 把假设专化到增加方向;两边工作量均为二,所声称严格不等式为假。 + + + **L608** 把假设专化到增加方向;两边工作量均为二,所声称严格不等式为假。 + + + **L610** 变更传播是实际路径触及组件编号的去重列表,保留与预期变更的关系。 + + + **L611** 变更传播是实际路径触及组件编号的去重列表,保留与预期变更的关系。 + + + **L613** 计算自然数批次数表达式 (items+size−1)/size,预期用于正批次大小;Lean 的减法和除法在该预期域外仍是全定义运算。 + + + **L614** 静态预测器有意忽略 runtimeSize,始终按大小十计算。 + + + **L615** 实时预测器使用所给运行时批次大小,使固定假设可被检验。 + + + **L617** 结构证据记录把预期变更与参与者、传播、观察及工作说明连接。 + + + **L618** 标识这份证据应支持的变更。 + + + **L619** 标识证据说明中的相关维护者。 + + + **L620** 记录变更触及的组件。 + + + **L621** 记录观察合同所用的确切输入语料。 + + + **L622** 记录变更前在该语料上的输出。 + + + **L623** 记录变更后在相同语料上的输出。 + + + **L624** 存储所表示的理解工作量;此处用总路径工作实例化。 + + + **L625** 存储验证工作量,下面用合同执行器步骤数实例化,而非这些步骤的单位之和。 + + + **L626** 存储针对该预期变更相对简单设计的工作收益声称。 + + + **L628** 从候选路径与同一预期方向构造具体证据记录。 + + + **L629** 绑定方向、全部维护者以及实际去重传播列表。 + + + **L630** 恰使用声明的有限合同语料。 + + + **L631** 使用 orderedUnique 计算旧观察。 + + + **L632** 使用该方向实际 evolutionBehavior 计算新观察。 + + + **L633** 理解工作字段等于预期路径的总设定工作量。 + + + **L634** 验证量计数同一路径中的实际 contractRunner 步骤。 + + + **L635** 工作收益是简单工作减所选工作,使用自然数减法;结果截断于零,不记录负收益。 + + + **L637** 开始来源映射注释,把 CoreReader.Engineering.StructuralAccount 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。 + + + **L638** 为 CoreReader.Engineering.StructuralAccount 记录源文引用 software-engineering.structural-judgment/p1,该直接正文的 SHA256 为 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42。这是可追踪绑定,不是新增前提或语义证明。 + + + **L639** 为 CoreReader.Engineering.StructuralAccount 记录源文引用 software-engineering.structural-judgment/p2,该直接正文的 SHA256 为 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42。这是可追踪绑定,不是新增前提或语义证明。 + + + **L640** 结束 CoreReader.Engineering.StructuralAccount 的源文映射注释;其后恢复可执行声明。 + + + **L641** 有效结构说明须匹配实际活动、候选和预期变更;仅填入记录字段不够。 + + + **L642** 记录参与者须等于活动参与者,触及组件须等于所断言方向的实际传播。 + + + **L643** 说明须准确标识指定有限观察输入。 + + + **L644** 其变更前结果须是这些输入上的原有顺序行为。 + + + **L645** 其变更后结果须来自同一预期方向的行为。 + + + **L646** 声称的理解工作量须匹配所选路径总工作。 + + + **L647** 验证字段须匹配实际合同执行器步骤数量;检查的是具体工作关系,而非自由评估标记。 + + + **L648** 验证字段须匹配实际合同执行器步骤数量;检查的是具体工作关系,而非自由评估标记。 + + + **L649** 声称收益须等于同一预期变更实际简单工作减所选工作的差。 + + + **L651** 可见接口元数据与可执行行为和编辑路径分开,用于后续不足性反例。 + + + **L652** 存储可见函数签名文本。 + + + **L653** 存储声称模块数,后续与实际组件列表比较。 + + + **L654** 存储可见扩展点数量。 + + + **L655** 存储命名设计原则;名称本身不会证明能力。 + + + **L656** 自动为 InterfaceView 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。 + + + **L658** 多个设计共享 List Nat→List Nat 签名、八个模块、十二个扩展点和依赖倒置标签。 + + + **L659** 编号零至七的八个组件都假定批次大小十。 + + + **L660** 编号零至七的八个组件都假定批次大小十。 + + + **L662** 改变批次大小时,选出存储假设与新大小不同的组件;新大小五时八个都需修订。 + + + **L663** 改变批次大小时,选出存储假设与新大小不同的组件;新大小五时八个都需修订。 + + + **L665** 边界携带实际端点编号和合同标签,使检查能区分具体关系。 + + + **L666** 标识边的调用方端点。 + + + **L667** 标识边的被调用方端点。 + + + **L668** 存储边的合同标签;后续检查还要求工作与实际输出相等,因此该字符串不是充分证据。 + + + **L669** 自动为 Boundary 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。 + + + **L671** 完整已表示设计把元数据与实际函数、路径、组件、边界和假设组合。 + + + **L672** 把可见元数据与实质设计字段并列保存。 + + + **L673** 承载合同比较所用的实际行为。 + + + **L674** 按预期变更分别提供具体编辑步骤。 + + + **L675** 列出实际组件编号,以便检查端点存在性。 + + + **L676** 列出设计实际表示的边。 + + + **L677** 把组件与其固定批次大小假设关联。 + + + **L679** 私有设计具有共享元数据、顺序行为和简单设计路径;它有八个组件、无显式边及八项固定批次假设。 + + + **L680** 私有设计具有共享元数据、顺序行为和简单设计路径;它有八个组件、无显式边及八项固定批次假设。 + + + **L681** 私有设计具有共享元数据、顺序行为和简单设计路径;它有八个组件、无显式边及八项固定批次假设。 + + + **L683** 文档化设计只把工作路径改为演化方案依赖指南的路径;元数据与可观察行为保持相同。 + + + **L684** 文档化设计只把工作路径改为演化方案依赖指南的路径;元数据与可观察行为保持相同。 + + + **L686** 排序变式改变实际行为,却保留文档化设计的元数据与路径,以构成同签名合同反例。 + + + **L688** 此有限应用把编辑被调用方 1 视为穿越实际 2→1 边,并要求调用方检查顺序;边标签或合同名称都不能证明验证已发生或输出已保持。 + + + **L689** 此有限应用把编辑被调用方 1 视为穿越实际 2→1 边,并要求调用方检查顺序;边标签或合同名称都不能证明验证已发生或输出已保持。 + + + **L690** 此有限应用把编辑被调用方 1 视为穿越实际 2→1 边,并要求调用方检查顺序;边标签或合同名称都不能证明验证已发生或输出已保持。 + + + **L691** 此有限应用把编辑被调用方 1 视为穿越实际 2→1 边,并要求调用方检查顺序;边标签或合同名称都不能证明验证已发生或输出已保持。 + + + **L692** 实例化从调用方 2 到被调用方 1 的具体边,并使用队列顺序合同标签。 + + + **L694** 把该实际边加入 documentedDesign 的边界列表,使后续检查针对确实包含该边的设计。 + + + **L695** 把该实际边加入 documentedDesign 的边界列表,使后续检查针对确实包含该边的设计。 + + + **L697** 针对一个实际设计、一个预期方向及一条边检查跨界。 + + + **L698** 边须属于设计,调用方须是实际组件。 + + + **L699** 被调用方也须存在,且调用方与被调用方须为不同组件。 + + + **L700** 预期路径须实际编辑或编译被调用方组件;无关边不能证明经过此边界的传播。 + + + **L701** 预期路径须实际编辑或编译被调用方组件;无关边不能证明经过此边界的传播。 + + + **L703** 边界义务检查索引同一设计、预期变更和边,因此无关边界的结果不能替代。 + + + **L704** 边界义务检查索引同一设计、预期变更和边,因此无关边界的结果不能替代。 + + + **L705** 先要求实际跨界关系,再把调用方检查视为跨界义务。 + + + **L706** 同一变更路径须含调用方组件上的 contractRunner 步骤,且需要 publicContract 知识。 + + + **L707** 同一变更路径须含调用方组件上的 contractRunner 步骤,且需要 publicContract 知识。 + + + **L708** 实际设计行为须在声明有限顺序语料上保持 orderedUnique;仅有检查步骤标签而无输出相等仍失败。 + + + **L710** 构造设计变式 omittedCallerCheck,在路径中省去调用方合同执行器工作,用于后面的边界义务反例。 + + + **L711** 保持 boundaryDesign 的其他字段不变,将 paths 替换为按请求方向变换对应路径的函数。 + + + **L712** 筛选 boundaryDesign 在同一方向的原路径,只保留下述谓词接受的步骤。 + + + **L713** 仅在步骤位于 coordinatedBoundary.caller 且使用 contractRunner 时删除它;保留其余步骤,并完成记录更新。 + + + **L715** 把被调用端点移到组件 7,保留调用方和合同标签。 + + + **L717** 替代设计实际包含改变后的边,因此跨界否定检查针对端点与路径不匹配,而非仅边缺失。 + + + **L718** 替代设计实际包含改变后的边,因此跨界否定检查针对端点与路径不匹配,而非仅边缺失。 + + + **L720** 检查实际边、预期工作、调用方义务与可观察行为之间的正反关系。 + + + **L721** boundaryDesign 的协同工作经过其实际 2→1 边。 + + + **L722** 该工作包含要求的调用方检查,并保持有限顺序合同。 + + + **L723** 删除调用方检查并未删除被调用方编辑,因此仍然发生跨界。 + + + **L724** 但移除调用方检查后,跨界义务未履行。 + + + **L725** 指向被调用方 7 的边未被穿越,因为协同路径不编辑或编译该端点。 + + + **L726** 只把 run 换为 sortedUnique 就违反顺序义务,即使边与检查步骤不变;通过计算证明这组有限合取。 + + + **L727** 只把 run 换为 sortedUnique 就违反顺序义务,即使边与检查步骤不变;通过计算证明这组有限合取。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。 + + + **L729** 开始来源映射注释,把 CoreReader.Engineering.structuralCases 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。 + + + **L730** 为 CoreReader.Engineering.structuralCases 记录源文引用 software-engineering.structural-judgment/p1,该直接正文的 SHA256 为 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42。这是可追踪绑定,不是新增前提或语义证明。 + + + **L731** 为 CoreReader.Engineering.structuralCases 记录源文引用 software-engineering.structural-judgment/p2,该直接正文的 SHA256 为 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42。这是可追踪绑定,不是新增前提或语义证明。 + + + **L732** 结束 CoreReader.Engineering.structuralCases 的源文映射注释;其后恢复可执行声明。 + + + **L733** 登记的结构案例组合包含实际传播、合同观察、工作以及新增显式跨界检查。 + + + **L734** 演化方案设计修订证据匹配实际持续活动和预期路径。 + + + **L735** 简单设计修订触及三个不同组件。 + + + **L736** 演化设计修订触及两个不同组件。 + + + **L737** 协同工作包含需要公共合同知识的组件 2 步骤;后续新增案例还把它绑定到真实边。 + + + **L738** 重构在声明有限合同语料上保持顺序行为。 + + + **L739** 有意设计修订的实际前后观察列表不同;没有把该改变误称为保持。 + + + **L740** 有意设计修订的实际前后观察列表不同;没有把该改变误称为保持。 + + + **L741** 对于二十一个元素,静态批次假设在运行时大小十时正确,在大小五时失败。 + + + **L742** 撤回简单设计结构耗十七单位,保留最终退出成本。 + + + **L743** 协同路径穿越实际调用方 2/被调用方 1 边界。 + + + **L744** 该边界的公共合同验证及有限顺序义务得到履行。 + + + **L745** 省略调用方验证后,被调用方编辑仍穿越边界。 + + + **L746** 省略调用方验证使义务检查失败。 + + + **L747** 被调用方为组件 7 的边不匹配该编辑路径,未被穿越。 + + + **L748** 相同边和步骤若配上 sortedUnique 行为,就不满足实际有限顺序保持;decide 检查整个具体结构组合的各项。 + + + **L749** 相同边和步骤若配上 sortedUnique 行为,就不满足实际有限顺序保持;decide 检查整个具体结构组合的各项。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。 + + + **L751** 把个人能力从候选标签推广到具有自身路径的实际 EngineeringDesign。 + + + **L752** 把个人能力从候选标签推广到具有自身路径的实际 EngineeringDesign。 + + + **L753** 要求实际设计路径非空,且维护者参与活动。 + + + **L754** 每个实际路径步骤都须能用该维护者的知识及活动工具执行。 + + + **L755** 每个实际路径步骤都须能用该维护者的知识及活动工具执行。 + + + **L757** 从该设计对象实际路径单位计算工作,使路径变式可明确改变或保持总量。 + + + **L758** 从该设计对象实际路径单位计算工作,使路径变式可明确改变或保持总量。 + + + **L760** 找出自身已记录批次假设与拟用运行时大小不同的组件。 + + + **L761** 找出自身已记录批次假设与拟用运行时大小不同的组件。 + + + **L763** 第一种外观包装增加组件、转发边和验证步骤,同时保持输出;它既不提供缺失的私有知识,也不消除原编辑工作。 + + + **L764** 第一种外观包装增加组件、转发边和验证步骤,同时保持输出;它既不提供缺失的私有知识,也不消除原编辑工作。 + + + **L765** 第一种外观包装增加组件、转发边和验证步骤,同时保持输出;它既不提供缺失的私有知识,也不消除原编辑工作。 + + + **L766** 在完整设计上构造第一种明确的引入边界变换。 + + + **L767** 可见模块数和扩展点数均增加一。 + + + **L768** 包装先给输入附加空列表,再调用原行为,从而保持结果。 + + + **L769** 原路径缺失时仍保持缺失;仅包装不能为未知变更创造支持。 + + + **L770** 已有路径在新组件编号处增加一个公共合同验证单位。 + + + **L771** 以原组件列表长度作为新组件编号加入;对于具体零至七初始设计,该编号是新的。 + + + **L772** 加入从该新组件到组件 0 的转发边,并携带原签名标签。 + + + **L773** 加入从该新组件到组件 0 的转发边,并携带原签名标签。 + + + **L774** 保留全部固定批次假设,因此包装没有解除这些假设造成的关联。 + + + **L776** 把第一种包装变换用于私有设计,构造实际工作量增加反例。 + + + **L778** 第二种包装把已有验证移到新组件,而不增加工作;真实边界与路径变化仍未提供私有知识或降低总工作量。 + + + **L779** 第二种包装把已有验证移到新组件,而不增加工作;真实边界与路径变化仍未提供私有知识或降低总工作量。 + + + **L780** 第二种包装把已有验证移到新组件,而不增加工作;真实边界与路径变化仍未提供私有知识或降低总工作量。 + + + **L781** 从相同引入边界设计开始,保留新组件、边及等价行为。 + + + **L782** 从相同引入边界设计开始,保留新组件、边及等价行为。 + + + **L783** 从原设计步骤重建工作路径,取消第一种包装额外附加的验证步骤。 + + + **L784** 把每个原 contractRunner 步骤移到新组件,同时保留其知识、工具和单位。 + + + **L785** 保留每个非验证步骤,完成不改变工作单位的迁移。 + + + **L787** 具体同工作量设计是私有设计经验证迁移后的结果。 + + + **L789** 开始来源映射注释,把 CoreReader.Engineering.structureNotCapability 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。 + + + **L790** 为 CoreReader.Engineering.structureNotCapability 记录源文引用 software-engineering.structural-judgment/p1,该直接正文的 SHA256 为 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42。这是可追踪绑定,不是新增前提或语义证明。 + + + **L791** 为 CoreReader.Engineering.structureNotCapability 记录源文引用 software-engineering.structural-judgment/p2,该直接正文的 SHA256 为 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42。这是可追踪绑定,不是新增前提或语义证明。 + + + **L792** 结束 CoreReader.Engineering.structureNotCapability 的源文映射注释;其后恢复可执行声明。 + + + **L793** 汇集反例,说明签名、模块数、原则名称及新边界本身不证明所声称能力或更少工作。 + + + **L794** 私有设计与排序设计签名相同,却在 [2,1,2] 上产生不同顺序结果;相同接口形状不构成合同等价。 + + + **L795** 私有设计与排序设计签名相同,却在 [2,1,2] 上产生不同顺序结果;相同接口形状不构成合同等价。 + + + **L796** 私有设计声明的八个模块等于实际组件列表长度。 + + + **L797** 它有八项实际记录的批次假设,而非仅模块数量标签。 + + + **L798** 运行时批次大小改为五时,八个组件都需修订假设。 + + + **L799** 私有设计带有依赖倒置原则名称。 + + + **L800** 私有设计与文档化设计共享全部可见元数据。 + + + **L801** 尽管有该标签,接任者仍无法修订私有设计,因为路径需要私有布局知识。 + + + **L802** 接任者可以通过真正不同、依赖指南的路径修订文档化设计。 + + + **L803** 第一种包装把实际边界数从零改为一。 + + + **L804** 它也把实际组件数从八增至九。 + + + **L805** 新增实际边恰为组件 8→0,并带原列表函数签名。 + + + **L806** 第一种包装保留 [2,1,2] 上的原观察输出。 + + + **L807** 原私有设计的设计修订需要十七单位。 + + + **L808** 第一种包装增加验证步骤后需要十八单位。 + + + **L809** 因此,此实际引入边界未减少预期设计修订工作。 + + + **L810** 迁移变式同样具有具体边 8→0。 + + + **L811** 迁移变式有九个实际组件。 + + + **L812** 其设计修订路径因验证组件编号迁移而不同于原路径。 + + + **L813** 迁移保留原观察顺序结果。 + + + **L814** 其总设定工作量与原路径总量完全相等。 + + + **L815** 该未改变总量为十七单位。 + + + **L816** 迁移后接任者仍缺少所需私有知识,因此新边界不构成持续能力。 + + + **L817** 对实际记录、函数和算术使用判定过程,证明五组具体反例。 + + + **L819** 开始来源映射注释,把 CoreReader.Engineering.contractPreservation 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。 + + + **L820** 为 CoreReader.Engineering.contractPreservation 记录源文引用 software-engineering.structural-judgment/p3,该直接正文的 SHA256 为 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42。这是可追踪绑定,不是新增前提或语义证明。 + + + **L821** 结束 CoreReader.Engineering.contractPreservation 的源文映射注释;其后恢复可执行声明。 + + + **L822** 一般保持定理对输入输出类型多态,并保留明确提供的范围。 + + + **L823** 其前提已经提供范围内每个输入的新旧行为相等。 + + + **L824** 把同一全称范围相等作为 PreservesOn 返回;没有从有限测试推出全称保持。 + + + **L826** 声明范围内一个实际不同观察足以否定范围保持。 + + + **L827** 固定新旧函数、一个输入及该输入属于范围的证明。 + + + **L828** 假定该处实际输出不同,推出不可能保持。 + + + **L829** 暂时假定范围保持。 + + + **L830** 把保持性质应用到范围内反例,与已知输出差异矛盾。 + + + **L832** 修订义务定理比较同一组实际新旧可观察合同。 + + + **L833** 要求报告已满足保持或修订二选一说明。 + + + **L834** 还假定实际有限合同保持失败。 + + + **L835** 排除保持分支,剩下报告的修订责任;并非仅从行为改变就生成说明。 + + + **L837** 退役行为仅改变不在声明有限语料中的输入 [99],在其他输入保留 orderedUnique。 + + + **L838** 退役行为仅改变不在声明有限语料中的输入 [99],在其他输入保留 orderedUnique。 + + + **L840** 开始来源映射注释,把 CoreReader.Engineering.contractCases 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。 + + + **L841** 为 CoreReader.Engineering.contractCases 记录源文引用 software-engineering.structural-judgment/p3,该直接正文的 SHA256 为 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42。这是可追踪绑定,不是新增前提或语义证明。 + + + **L842** 结束 CoreReader.Engineering.contractCases 的源文映射注释;其后恢复可执行声明。 + + + **L843** 组合保持、有意修订、遗漏参与方被拒及程序灵活性案例。 + + + **L844** 重构合同通过有限保持获得有效说明。 + + + **L845** 顺序与重试均改变的合同通过实际修订责任获得有效说明。 + + + **L846** 空的已承认参与方列表无法说明实际消费者和运维者变化。 + + + **L847** 退役行为保持每个声明有限输入,却在 [99] 不同,展示范围限度。 + + + **L848** 把程序名称改为 paired audit 仍保留有效说明;没有强制某种特定程序。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。 + + + **L850** 开始来源映射注释,把 CoreReader.Engineering.contractDistinctions 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。 + + + **L851** 为 CoreReader.Engineering.contractDistinctions 记录源文引用 software-engineering.structural-judgment/p3,该直接正文的 SHA256 为 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42。这是可追踪绑定,不是新增前提或语义证明。 + + + **L852** 结束 CoreReader.Engineering.contractDistinctions 的源文映射注释;其后恢复可执行声明。 + + + **L853** 区分实际顺序保持、重试改变、参与方影响与准确历史合同报告。 + + + **L854** 附加空列表的重构保持有限顺序合同。 + + + **L855** 先排序再去重不保持同一顺序合同。 + + + **L856** 尝试编号三时,原阈值禁止重试,新阈值允许重试,使失败策略变化具体可见。 + + + **L857** 因此顺序与重试组合合同并未保持。 + + + **L858** 固定依赖映射在此例恰好识别消费者与运维者受影响。 + + + **L859** 仅承认消费者会遗漏受重试改变影响的运维者,因此修订说明失败。 + + + **L860** 仅承认消费者会遗漏受重试改变影响的运维者,因此修订说明失败。 + + + **L861** 把两个报告旧界限字段都改为五仍失败,因为独立实际原合同阈值为三。 + + + **L862** 把两个报告旧界限字段都改为五仍失败,因为独立实际原合同阈值为三。 + + + **L863** 未篡改的 normalRevision 正确说明有意变更。 + + + **L864** 有限保持仍容许 [99] 处有意的范围外差异;它不是所有输入等价。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。 + + + **L866** 修订关注带时间索引证据下的当前选择,不改变已经观察到的预测真值。 + + + **L867** 修订关注带时间索引证据下的当前选择,不改变已经观察到的预测真值。 + + + **L868** 修订状态记录某时刻的证据、维护条件、成本、目标与所选设计。 + + + **L869** 用自然数时间编号排列状态。 + + + **L870** 记录预期未来变更方向。 + + + **L871** 记录预期维护量。 + + + **L872** 记录预期由谁维护软件。 + + + **L873** 记录相关迁移成本。 + + + **L874** 记录目标相对该成本的容量。 + + + **L875** 记录在这些条件下所选设计。 + + + **L876** 自动为 RevisionState 提供相等判定和可打印表示;这些支持具体案例计算,不是关于该类型的哲学断言。 + + + **L877** 修订记录保留实际和已报告状态,以及可单独检查的预测结果和批评覆盖。 + + + **L878** 把报告绑定到命名软件任务。 + + + **L879** 承载报告所声称的旧状态。 + + + **L880** 承载当前状态。 + + + **L881** 保留报告记录的旧状态,以与独立历史比较。 + + + **L882** 保留其记录的当前状态。 + + + **L883** 给出此前预测的批次数。 + + + **L884** 给出实际观察批次数。 + + + **L885** 记录报告是否宣称预测成功;后续检查把该布尔值绑定到实际历史相等关系。 + + + **L886** 列出此次修订考虑的变更方向。 + + + **L887** 列出保留在声明批评范围内的方向。 + + + **L889** 实质变化针对具体根据,而非仅更晚时间戳或重新标记的选择。 + + + **L890** 预期方向或维护量变化属于根据改变。 + + + **L891** 维护者改变也改变相关条件。 + + + **L892** 迁移成本或目标容量改变构成另一种实质根据差异。 + + + **L894** 时间零的旧状态预期设计修订、六单位维护、原维护者、成本八/容量十二,并选择演化方案。 + + + **L895** 时间一的新状态预期删除、两单位维护、接任者和代理维护、成本十四/容量十,并选择简单方案。 + + + **L897** HistoricalEvidence 是独立于可改报告的输入,固定任务、旧状态及过去预测与观察。 + + + **L898** 标识历史事件涉及的软件。 + + + **L899** 保留实际历史修订状态。 + + + **L900** 独立于新报告保留历史预测。 + + + **L901** 独立于报告保留历史观察结果。 + + + **L903** 记录事件使用固定为十的预测器,而实际对二十一个元素使用运行时大小五;不匹配作为事件内容保留。 + + + **L904** 记录事件使用固定为十的预测器,而实际对二十一个元素使用运行时大小五;不匹配作为事件内容保留。 + + + **L905** 把队列历史固定为 oldState,并用两个实际函数得到预测三、实际五。 + + + **L906** 把队列历史固定为 oldState,并用两个实际函数得到预测三、实际五。 + + + **L908** 对独立提供的历史对象检查报告,而非仅让报告字段相互比较。 + + + **L909** 报告软件身份须匹配历史任务。 + + + **L910** 报告的旧状态声称与所记录旧状态都须等于独立历史状态。 + + + **L911** 报告须保留实际历史预测数。 + + + **L912** 它须保留实际历史观察数。 + + + **L913** 时间须推进,当前状态记录须准确反映当前状态。 + + + **L914** 设计选择改变要求实质根据改变;仅该条件不证明每种此类重新设计都实质合理。 + + + **L915** 报告成功标记须等于实际历史预测与观察是否相等的判定,防止事后重标记。 + + + **L916** 每个已考虑方向须留在所列批评范围;这种有限覆盖不是自反正确性的普遍证明。 + + + **L918** 开始来源映射注释,把 CoreReader.Engineering.RevisionAccount 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。 + + + **L919** 为 CoreReader.Engineering.RevisionAccount 记录源文引用 software-engineering.revision/p2,该直接正文的 SHA256 为 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99。这是可追踪绑定,不是新增前提或语义证明。 + + + **L920** 为 CoreReader.Engineering.RevisionAccount 记录源文引用 software-engineering.revision/p1,该直接正文的 SHA256 为 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99。这是可追踪绑定,不是新增前提或语义证明。 + + + **L921** 结束 CoreReader.Engineering.RevisionAccount 的源文映射注释;其后恢复可执行声明。 + + + **L922** 把通用历史绑定说明专化为固定的已观察队列历史。 + + + **L924** 禁止改写结果适用于任意所给历史和报告,不仅针对队列数字。 + + + **L925** 假定报告针对同一历史对象满足完整说明。 + + + **L926** 假定实际历史预测与观察不同。 + + + **L927** 推出准确报告必须标记预测未成功。 + + + **L928** 取出说明中的成功标记相等关系,再用历史失败前提化简,得到 false。 + + + **L930** 构造常规修订报告,准确记录新旧状态并保留失败预测。 + + + **L931** 使用与 observedHistory 相同的保持顺序队列身份。 + + + **L932** 实际和已记录状态分别与 oldState、newState 相同。 + + + **L933** 使用二十一个元素、运行时大小五时实际 static/live 批次数。 + + + **L934** 如实标记该预测未成功。 + + + **L935** 考虑全部九个常规方向,并把九个都保留在批评范围内。 + + + **L937** 在此保留设计适配器中,有支持的替代方案就是按情境根据解释可信的方向。 + + + **L939** 保留设计可由声明的缺少贡献或具体成本条件支持;这是应用准则。 + + + **L940** 一个分支要求所有列出的替代方向都缺少情境中的可信支持。 + + + **L941** 另一分支通过明确合理的演化成本偏离容许保留设计。 + + + **L943** 稳定变式在实际与记录的当前状态中都继续选择演化方案,同时保留变化证据、如实失败预测及批评覆盖。 + + + **L944** 稳定变式在实际与记录的当前状态中都继续选择演化方案,同时保留变化证据、如实失败预测及批评覆盖。 + + + **L945** 稳定变式在实际与记录的当前状态中都继续选择演化方案,同时保留变化证据、如实失败预测及批评覆盖。 + + + **L947** 开始来源映射注释,把 CoreReader.Engineering.revisionCases 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。 + + + **L948** 为 CoreReader.Engineering.revisionCases 记录源文引用 software-engineering.revision/p2,该直接正文的 SHA256 为 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99。这是可追踪绑定,不是新增前提或语义证明。 + + + **L949** 为 CoreReader.Engineering.revisionCases 记录源文引用 software-engineering.revision/p1,该直接正文的 SHA256 为 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99。这是可追踪绑定,不是新增前提或语义证明。 + + + **L950** 结束 CoreReader.Engineering.revisionCases 的源文映射注释;其后恢复可执行声明。 + + + **L951** 展示有效修订,包含五项实质根据差异、保留的预测失败及两种保留设计理由。 + + + **L952** 常规报告满足针对固定独立历史的说明。 + + + **L953** 其预测从设计修订改为删除。 + + + **L954** 其维护量从六改为二。 + + + **L955** 其维护者集合从原作者改为接任者与代理。 + + + **L956** 其迁移成本从八改为十四。 + + + **L957** 其目标容量从十二改为十。 + + + **L958** 预测三仍不同于实际五;修订决定不改变此次失败。 + + + **L959** 缺少可信根据的量子后端替代方向构成无支持替代方案的保留案例。 + + + **L960** 真实迁移容量威胁构成基于成本的保留案例。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。 + + + **L962** 成功观察集仅使用运行时大小十,元素数分别为二十一、三十和四十。 + + + **L963** 记录三个修订编号;仅数量不会证明正确。 + + + **L964** 每名评审者都报告同一静态预测结果,表示意见一致,却不增加独立支持或改变实际预测器。 + + + **L965** 每名评审者都报告同一静态预测结果,表示意见一致,却不增加独立支持或改变实际预测器。 + + + **L967** 第一种篡改变式同时改变声称与记录的旧预测,以检验报告字段彼此一致仍不能覆盖独立历史。 + + + **L968** 第一种篡改变式同时改变声称与记录的旧预测,以检验报告字段彼此一致仍不能覆盖独立历史。 + + + **L969** 第一种篡改变式同时改变声称与记录的旧预测,以检验报告字段彼此一致仍不能覆盖独立历史。 + + + **L971** 第二种变式把预测数改为五并宣称成功,试图改写旧预测以匹配观察。 + + + **L972** 第二种变式把预测数改为五并宣称成功,试图改写旧预测以匹配观察。 + + + **L974** 第三种变式把观察数改为三并宣称预测成功,试图改写实际事件。 + + + **L975** 第三种变式把观察数改为三并宣称预测成功,试图改写实际事件。 + + + **L977** 身份变式保留数字数据却把报告分配给无关软件,以检验任务绑定。 + + + **L978** 身份变式保留数字数据却把报告分配给无关软件,以检验任务绑定。 + + + **L980** 展示固定历史证据如何拒绝报告字段联动篡改及软件身份替换。 + + + **L981** 未修改报告保持有效。 + + + **L982** 同时修改两个旧状态字段无法满足独立固定历史。 + + + **L983** 改写预测数与成功标记被拒绝。 + + + **L984** 改写观察数与成功标记也被拒绝。 + + + **L985** 所有这些变式中,独立历史始终保留预测三与观察五。 + + + **L986** 无关软件的报告不满足任务身份要求。 + + + **L987** 不修改历史对象,通过计算证明七项具体有效性、失败和历史数字结论。 + + + **L989** 开始来源映射注释,把 CoreReader.Engineering.revisionLimits 关联到下列源文段落;注释不改变 Lean 含义,也不证明对应关系。 + + + **L990** 为 CoreReader.Engineering.revisionLimits 记录源文引用 software-engineering.revision/p2,该直接正文的 SHA256 为 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99。这是可追踪绑定,不是新增前提或语义证明。 + + + **L991** 为 CoreReader.Engineering.revisionLimits 记录源文引用 software-engineering.revision/p1,该直接正文的 SHA256 为 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99。这是可追踪绑定,不是新增前提或语义证明。 + + + **L992** 结束 CoreReader.Engineering.revisionLimits 的源文映射注释;其后恢复可执行声明。 + + + **L993** 组合事后成功重标记、修订次数、意见一致、重复局部成功及合理稳定的限度。 + + + **L994** 常规历史说明有效。 + + + **L995** 仅把 reportedPredictionSucceeded 改为 true 就使说明无效。 + + + **L996** 明确列表中出现三次修订,但数量不提供正确性定理。 + + + **L997** 三名维护者都同意静态结果三,但实时结果为五;一致意见不消除反例。 + + + **L998** 每个已列大小十观察中,静态和实时预测器均一致。 + + + **L999** 这些重复成功与运行时大小五处的失败并存。 + + + **L1000** 稳定报告保持历史有效并延续原设计选择,表明修订开放性不强迫每次行动都改变设计。 + + + **L1001** 无支持的量子后端替代方向仍允许保留当前设计。 + + + **L1002** 用有限判定构造合取,只留下虚报成功说明待明确展开。 + + + **L1003** 用有限判定构造合取,只留下虚报成功说明待明确展开。 + + + **L1004** 展开固定历史、实际报告和实质变化谓词,使虚假成功声称显露为具体三与五不等。 + + + **L1005** 通过计算检查剩余可判定矛盾。 + + + **L1007** 不论根据构造子为何,都提取记录列出的方向;该提取仅记录预测内容,本身不证明可信性。 + + + **L1008** 不论根据构造子为何,都提取记录列出的方向;该提取仅记录预测内容,本身不证明可信性。 + + + **L1010** 从实际情境与所选设计构造当前修订状态,而非使用无关联报告占位值。 + + + **L1011** 设时间为一,并把实际情境证据所列方向串接为预测。 + + + **L1012** 从同一活动复制维护量和参与维护者。 + + + **L1013** 使用所选设计实际设定的迁移成本。 + + + **L1014** 使用同一情境的迁移目标容量。 + + + **L1015** 记录实际所选候选。 + + + **L1017** 报告保留 stableRecord 的历史数据,但把软件、实际当前状态和记录当前状态绑定到此情境与所选候选。 + + + **L1018** 报告保留 stableRecord 的历史数据,但把软件、实际当前状态和记录当前状态绑定到此情境与所选候选。 + + + **L1020** 检查实例化修订报告确实属于共享工程情境,并满足固定历史说明。 + + + **L1021** 其软件标识等于活动实际标识。 + + + **L1022** 同一标识匹配历史证据,且当前维护量等于活动计划。 + + + **L1023** 同一标识匹配历史证据,且当前维护量等于活动计划。 + + + **L1024** 当前维护者等于实际参与者列表。 + + + **L1025** 当前迁移成本等于演化方案设定成本。 + + + **L1026** 当前目标容量等于共享情境迁移容量。 + + + **L1027** 当前目标容量等于共享情境迁移容量。 + + + **L1028** 记录的当前选择实际为演化方案。 + + + **L1029** 完整绑定报告满足 RevisionAccount;这些具体检查由实际字段计算判定。 行末 by decide 通过执行判定过程证明所写具体命题;它不推广到所示对象与范围之外。 + + + **L1031** 完整领域组合在同一情境保留实际主体、可信性、说明和修订责任;所选有限应用记录不声称普遍工程充分性。 + + + **L1032** 完整领域组合在同一情境保留实际主体、可信性、说明和修订责任;所选有限应用记录不声称普遍工程充分性。 + + + **L1033** 完整领域组合在同一情境保留实际主体、可信性、说明和修订责任;所选有限应用记录不声称普遍工程充分性。 + + + **L1034** 组合同一情境与所选设计的已表示领域义务。此组合没有无条件的 Meets 字段;优先适用性并不是整体需求拒绝检查。 + + + **L1035** 要求 ActivityScope 及条件式 EvolutionPriority。若 PriorityConditions 为假,该蕴含空真;此合取项不会因需求未满足而拒绝选择,其余领域义务仍须履行。 + + + **L1036** 要求设计修订方向具备实际可信根据。 + + + **L1037** 若记录了偏离,就须是合理具体成本偏离;没有偏离记录不会额外创造例外。 + + + **L1038** 要求接任者具有实际设计修订能力,并明确采用修订义务方式。 + + + **L1039** 要求结构说明匹配同一活动、所选候选和设计修订证据。 + + + **L1040** 要求保持或修订说明比较所选设计顺序合同与实际设计修订合同。 + + + **L1041** 要求同一情境与候选的修订报告满足固定独立历史说明。 + + + **L1043** 为共享持续演化示例构造实际完整领域满足。 + + + **L1044** 计算具体主体、优先、可信性、变更、结构、合同和历史义务,留下条件偏离检查。 + + + **L1045** 常规情境记录 departure=none,因此要求已记录偏离具有理由的蕴含空真;优先规范本身仍实际适用,且没有成本逃逸。 + + + **L1047** 结束工程命名空间;以上声明仍可通过 CoreReader.Engineering 访问。 + + +### `leanified/CoreReader/Engineering/Integration.lean` + + +```lean +import CoreReader.Engineering.Domain +import CoreReader.Engineering.Reflection +import CoreReader.Engineering.SelfApplication + +namespace CoreReader.Engineering + +open CoreReader.Logic CoreReader.Evidence CoreReader.Adopted + +/- All interpretations below share this activity, requirements, evidence and +cost limits. Only the selected implementation and its stated value priority vary. -/ +abbrev sharedContext : Context := currentContinuing + +def maintainedOutput (chosen : Candidate) (n : Nat) : Nat := + (behavior chosen [n]).headD 0 + +def chosenImplementation (chosen : Candidate) : CoreReader.Choice.Implementation where + name := "order-preserving queue" + conventional := chosen == .presentSimple + established := chosen == .presentSimple + run := maintainedOutput chosen + cost := abstractionComplexity chosen + domain _ := True + explanation := maintainedOutput chosen + trace n := [maintainedOutput chosen n] + +/- This Core choice projection checks the queue's one-item observable contract +and present understanding budget. Domain retains its additional required checks. -/ +def chosenRequirements : CoreReader.Choice.Requirements where + inputs _ := True + expected n := n + budget := sharedContext.limits.capacity .understanding + values _ := True + +def chosenReasons : List CoreReader.Choice.Reason := + [.method .output, .method .simplicity] + +theorem maintainedOutputCorrect (chosen : Candidate) (n : Nat) : + maintainedOutput chosen n = n := by + rfl + +theorem implementationReasoned (chosen : Candidate) + (budget : abstractionComplexity chosen ≤ chosenRequirements.budget) : + choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons := by + refine ⟨⟨fun n _ => maintainedOutputCorrect chosen n, budget⟩, + .method .output, ?_, ?_⟩ + · simp [chosenReasons] + · exact ⟨trivial, fun n _ => maintainedOutputCorrect chosen n⟩ + +/- This reported capability concerns actual paths for each maintainer. Zero +records the unavailable path, not an assertion that an unsupported path exists. -/ +def capabilityOutput (chosen : Candidate) (input : Nat) : Nat := + let maintainer := if input = 0 then Maintainer.original + else if input = 1 then Maintainer.successor else Maintainer.agent + if decide (CanChange sharedContext.activity chosen maintainer .designRevision) + then changeWork chosen .designRevision else 0 + +def engineeringProcess (chosen : Candidate) : Process := + ⟨capabilityOutput chosen, none⟩ + +def engineeringCapability (chosen : Candidate) : Claim Process := + fun process => ∀ input, process.output input = capabilityOutput chosen input + +theorem engineeringCapabilityGrounded (chosen : Candidate) : + capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen) := by + exact grounds012Singleton _ (processContractDischarged _ _ (fun _ => rfl)) + +theorem actualCapabilityContrast : + (engineeringProcess .presentSimple).output 0 = 17 ∧ + (engineeringProcess .presentSimple).output 1 = 0 ∧ + (engineeringProcess .presentSimple).output 2 = 0 ∧ + (engineeringProcess .evolvable).output 0 = 6 ∧ + (engineeringProcess .evolvable).output 1 = 6 ∧ + (engineeringProcess .evolvable).output 2 = 6 := by decide + +/- A recorded threshold test measures present abstraction complexity in this +finite model. It does not observe future maintainability or establish a value. -/ +def presentBudgetRecord : Record Candidate := + ⟨fun candidate => decide (abstractionComplexity candidate ≤ 3), true⟩ + +abbrev presentBudgetClaim : Claim Candidate := fun candidate => abstractionComplexity candidate ≤ 3 + +theorem budgetObservationMeaning (candidate : Candidate) : + Compatible [presentBudgetRecord] candidate ↔ presentBudgetClaim candidate := by + constructor + · intro observed + have result := observed presentBudgetRecord (List.mem_singleton.mpr rfl) + exact of_decide_eq_true result + · intro enough record member + cases List.mem_singleton.mp member + exact decide_eq_true enough + +def budgetEmpiricalFacet : Facet Candidate := + .empirical [presentBudgetRecord] (fun _ => True) presentBudgetClaim (fun _ => True) + +theorem budgetEmpiricalDischarged : FacetDischarged budgetEmpiricalFacet := by + refine ⟨⟨.evolvable, (budgetObservationMeaning _).2 (by decide), trivial⟩, ?_, ?_⟩ + · intro candidate observed _ + exact (budgetObservationMeaning candidate).1 observed + · intro _ _; trivial + +def capacityClaim : Claim Candidate := + fun candidate => abstractionComplexity candidate ≤ sharedContext.limits.capacity .understanding + +def capacityAssumptions : Theory Candidate := singleton presentBudgetClaim + +def budgetInferentialFacet : Facet Candidate := .inferential capacityAssumptions capacityClaim + +theorem budgetInferentialDischarged : FacetDischarged budgetInferentialFacet := by + refine ⟨⟨.evolvable, (modelsSingleton _ _).2 (by decide)⟩, ?_⟩ + intro candidate premises + have small := (modelsSingleton _ _).1 premises + exact Nat.le_trans small (by decide) + +def budgetScopeAccount : ScopeAccount Candidate where + claim := presentBudgetClaim + conditions := fun _ => True + observationScope := fun _ => True + relevant := fun a b => behavior a [2, 1, 2] = behavior b [2, 1, 2] + compared := fun a b => presentBudgetClaim a ∧ presentBudgetClaim b + used method := method = .measurement + role _ := "threshold observation of present complexity; no future-performance conclusion" + explains method text claim conditions := method = .measurement ∧ + text = "threshold observation of present complexity; no future-performance conclusion" ∧ + claim = presentBudgetClaim ∧ conditions = (fun _ => True) + +theorem budgetScopeExplained : scopeSpecification budgetScopeAccount := by + constructor + · intro a b _; exact ⟨trivial, trivial, trivial, trivial, rfl⟩ + · intro method hm + exact ⟨by change "threshold observation of present complexity; no future-performance conclusion" ≠ ""; decide, + hm, rfl, rfl, rfl⟩ + +/- The unchanged observation cannot justify a stronger complexity bound. -/ +theorem budgetObservationLimit : + Compatible [presentBudgetRecord] .evolvable ∧ + ¬ Supports [presentBudgetRecord] (fun candidate => abstractionComplexity candidate ≤ 1) := by + refine ⟨(budgetObservationMeaning _).2 (by decide), ?_⟩ + intro support + have impossible := support .evolvable ((budgetObservationMeaning _).2 (by decide)) + exact (by decide : ¬ (3 ≤ 1)) impossible + +/- The policy values expansion while keeping every represented organization, +method and principle form revisable. It does not assert that a revision occurs. -/ +def engineeringPolicy : CoreReader.Agency.Policy where + worthPursuing aim := + (aim = .expandUnderstandingAndConstruction ∧ coreAdopted .generation = true) ∨ + aim = .preserveSafeOperation + current form := form.version = 1 + revisable form := ∃ next, form.version < next ∧ coreAdopted .generation = true + permitsVersion old next := old ≤ next + +theorem engineeringGenerative : generationSpecification engineeringPolicy := by + exact ⟨Or.inl ⟨rfl, rfl⟩, fun form _ => ⟨form.version + 1, Nat.lt_succ_self _, rfl⟩⟩ + +/- Own facts are mathematical reports about this model and its recorded state. +Their inferential tasks do not replace the separate empirical or value tasks. -/ +inductive OwnFact + | selected | requirements | capacity | capability | forecast | revision + | generativePolicy | reflection | coreAdoption (principle : CoreCommitment) + deriving DecidableEq, Repr + +abbrev ownFactClaim (adopted : Candidate) : OwnFact → Claim Candidate + | .selected => fun candidate => candidate = adopted + | .requirements => fun candidate => Meets sharedContext.required (sharedContext.profiles candidate) + | .capacity => capacityClaim + | .capability => fun candidate => engineeringCapability candidate (engineeringProcess candidate) + | .forecast => fun _ => staticBatch 21 10 = liveBatch 21 10 ∧ staticBatch 21 5 ≠ liveBatch 21 5 + | .revision => fun candidate => RevisionAccount (revisionFor sharedContext candidate) + | .generativePolicy => fun _ => generationSpecification engineeringPolicy + | .reflection => fun candidate => reflexivitySpecification + (selfModel candidate).rules (selfModel candidate).self (selfModel candidate).performed + | .coreAdoption principle => (governancePosition principle).commitment + +theorem actualOwnFact (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) (fact : OwnFact) : + ownFactClaim chosen fact chosen := by + cases fact with + | selected => rfl + | requirements => cases chosen <;> decide + | capacity => rcases ordinary with rfl | rfl <;> change _ ≤ 12 <;> decide + | capability => intro _; rfl + | forecast => exact ⟨rfl, by decide⟩ + | revision => rcases ordinary with rfl | rfl <;> decide + | generativePolicy => exact engineeringGenerative + | reflection => exact currentSelfApplication chosen ordinary + | coreAdoption _ => rfl + +def ownFactPremises (chosen : Candidate) : Theory Candidate := + singleton (fun candidate => candidate = chosen) + +theorem actualOwnFactGrounded (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) (fact : OwnFact) : + inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact) := by + apply grounds012Singleton + refine ⟨⟨chosen, (modelsSingleton _ _).2 rfl⟩, ?_⟩ + intro candidate same + have identity := (modelsSingleton _ _).1 same + subst candidate + exact actualOwnFact chosen ordinary fact + +/- In this fixed applicable context, the actual priority rule and the adopted +evolution value select exactly the same candidate. This identity connects its +value grounds to the normative rule, not merely to an adoption label. -/ +theorem priorityValueMeaning (candidate : Candidate) : + (selectionPosition .evolvable).commitment candidate ↔ + EvolutionPriority sharedContext candidate := by + constructor + · intro selected + change candidate = .evolvable at selected + subst candidate + exact currentDomainSatisfied.2.1 + · intro priority + exact (priorityWhenApplicable sharedContext candidate priority + currentPriorityConditions currentNoThreat.2).1 + +theorem priorityGrounds : + Grounds012 (EvolutionPriority sharedContext) canonicalArticulation + [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) := by + have same : (selectionPosition .evolvable).commitment = EvolutionPriority sharedContext := + funext (fun candidate => propext (priorityValueMeaning candidate)) + rw [← same] + exact selectionGrounded .evolvable (Or.inr rfl) + +/- Facts of adoption remain distinct from the actual normative contents. Each +constructor below denotes its full represented duty, with its original task, +conditions, reasons and scope. Domain duties enter only for the domain adopter. +Consistency is the constraint on the resulting whole theory below; it is not +encoded as a self-referential proposition in that theory's own definition. -/ +inductive OwnNorm + | generation | reflection | empirical | inferential | principleValue (principle : CoreCommitment) + | selectionValue | scope | capability | choice | ownGrounds (fact : OwnFact) + | domain | priorityValue + deriving DecidableEq, Repr + +def normApplies (adopted : Candidate) : OwnNorm → Prop + | .domain | .priorityValue => adopted = .evolvable + | _ => True + +def ownNormClaim (adopted : Candidate) : OwnNorm → Claim Candidate + | .generation => fun _ => generationSpecification engineeringPolicy + | .reflection => fun candidate => reflexivitySpecification + (selfModel candidate).rules (selfModel candidate).self (selfModel candidate).performed + | .empirical => fun _ => empiricalSpecification [presentBudgetRecord] (fun _ => True) + presentBudgetClaim (fun _ => True) + | .inferential => fun _ => inferentialSpecification capacityAssumptions capacityClaim + | .principleValue principle => fun _ => valueSpecification (governancePosition principle) + | .selectionValue => fun candidate => valueSpecification (selectionPosition adopted) ∧ + (selectionPosition adopted).commitment candidate + | .scope => fun _ => scopeSpecification budgetScopeAccount + | .capability => fun candidate => capabilitySpecification + (engineeringProcess candidate) (engineeringCapability candidate) + | .choice => fun candidate => choiceSpecification + chosenRequirements (chosenImplementation candidate) chosenReasons + | .ownGrounds fact => fun _ => inferentialSpecification + (ownFactPremises adopted) (ownFactClaim adopted fact) + | .domain => fun candidate => DomainSatisfied sharedContext candidate + | .priorityValue => fun _ => Grounds012 (EvolutionPriority sharedContext) canonicalArticulation + [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) + +theorem actualOwnNorm (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) + (norm : OwnNorm) (applicable : normApplies chosen norm) : ownNormClaim chosen norm chosen := by + cases norm with + | generation => exact engineeringGenerative + | reflection => exact currentSelfApplication chosen ordinary + | empirical => exact grounds012Singleton _ budgetEmpiricalDischarged + | inferential => exact grounds012Singleton _ budgetInferentialDischarged + | principleValue principle => exact governanceGrounded principle + | selectionValue => exact ⟨selectionGrounded chosen ordinary, rfl⟩ + | scope => exact budgetScopeExplained + | capability => exact engineeringCapabilityGrounded chosen + | choice => + apply implementationReasoned + rcases ordinary with rfl | rfl <;> change _ ≤ 12 <;> decide + | ownGrounds fact => exact actualOwnFactGrounded chosen ordinary fact + | domain => + change chosen = .evolvable at applicable + subst chosen + exact currentDomainSatisfied + | priorityValue => exact priorityGrounds + +def ownFactTheory (chosen : Candidate) : Theory Candidate := + fun claim => ∃ fact : OwnFact, claim = ownFactClaim chosen fact + +def ownNormTheory (chosen : Candidate) : Theory Candidate := + fun claim => ∃ norm : OwnNorm, normApplies chosen norm ∧ claim = ownNormClaim chosen norm + +/- The consequence relation now acts on all these facts and normative contents +together, including the implications of their union. -/ +def ownTheory (chosen : Candidate) : Theory Candidate := + union (ownFactTheory chosen) (ownNormTheory chosen) + +theorem allNormativeContentHeld (chosen : Candidate) (norm : OwnNorm) + (applicable : normApplies chosen norm) : ownTheory chosen (ownNormClaim chosen norm) := + Or.inr ⟨norm, applicable, rfl⟩ + +theorem nonemptyOwnObjects (chosen : Candidate) : + ownTheory chosen (ownFactClaim chosen .selected) ∧ + ownTheory chosen (ownFactClaim chosen (.coreAdoption .grounds)) ∧ + (.activity : ReviewObject) ∈ (selfModel chosen).objects ∧ + (.commitment .grounds : ReviewObject) ∈ (selfModel chosen).objects := by + refine ⟨Or.inl ⟨.selected, rfl⟩, Or.inl ⟨.coreAdoption .grounds, rfl⟩, ?_, ?_⟩ <;> + simp [selfModel, reviewObjects, coreCommitments] + +def comparisonContext (chosen : Candidate) : CoreReader.Logic.Context Candidate OwnFact where + assumptions := ownFactPremises chosen + meaning := ownFactClaim chosen + scope := valueScope + +def engineeringSnapshot (chosen : Candidate) (revision : Nat) : Snapshot Candidate OwnFact := + ⟨ownTheory chosen, comparisonContext chosen, revision⟩ + +theorem currentAdmissible (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) : + Admissible (ownTheory chosen) (comparisonContext chosen) chosen := by + refine ⟨?_, (modelsSingleton _ _).2 rfl, ?_⟩ + · intro claim held + rcases held with factHeld | normHeld + · obtain ⟨fact, rfl⟩ := factHeld + exact actualOwnFact chosen ordinary fact + · obtain ⟨norm, applicable, rfl⟩ := normHeld + exact actualOwnNorm chosen ordinary norm applicable + · rcases ordinary with rfl | rfl <;> change _ ≤ 3 <;> decide + +theorem currentConsistency (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) : + consistencySpecification (engineeringSnapshot .evolvable 0) + (engineeringSnapshot chosen 1) true := by + exact ⟨consequenceConsistency _ _ ⟨chosen, currentAdmissible chosen ordinary⟩, fun _ => rfl⟩ + +theorem wholeClaimGrounded (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) + (claim : Claim Candidate) (held : ownTheory chosen claim) : + inferentialSpecification (ownFactPremises chosen) claim := by + apply grounds012Singleton + refine ⟨⟨chosen, (modelsSingleton _ _).2 rfl⟩, ?_⟩ + intro candidate same + have identity := (modelsSingleton _ _).1 same + subst candidate + exact (currentAdmissible chosen ordinary).1 claim held + +/- Keeping the same adoption marker does not conceal contradictory normative +contents. Both demands act on the very same candidate, question and scope. -/ +def incompatibleNormTheory : Theory Candidate := + union (singleton (fun candidate => candidate = .presentSimple)) + (singleton (fun candidate => candidate ≠ .presentSimple)) + +def incompatibleNormContext : CoreReader.Logic.Context Candidate Unit := + ⟨emptyTheory, fun _ candidate => candidate = .presentSimple, fun _ => True⟩ + +theorem normativeContentVariation : + coreAdopted .choice = true ∧ + ¬ Consistent incompatibleNormTheory incompatibleNormContext ∧ + normApplies .evolvable .domain ∧ ¬ normApplies .presentSimple .domain ∧ + ownTheory .evolvable (ownNormClaim .evolvable .domain) ∧ + ¬ ownTheory .presentSimple (ownNormClaim .presentSimple .domain) := by + refine ⟨rfl, ?_, rfl, by unfold normApplies; decide, allNormativeContentHeld _ _ rfl, ?_⟩ + · apply conflictRequiresChange _ _ () + · intro candidate admissible + change candidate = .presentSimple + exact (modelsSingleton (fun c : Candidate => c = .presentSimple) candidate).1 + ((modelsUnion _ _ _).1 admissible.1).1 + · intro candidate admissible + change candidate ≠ .presentSimple + exact (modelsSingleton (fun c : Candidate => c ≠ .presentSimple) candidate).1 + ((modelsUnion _ _ _).1 admissible.1).2 + · intro held + have domain := (currentAdmissible .presentSimple (Or.inl rfl)).1 _ held + exact currentSimpleViolates domain.2.1 + +/- Every field is an actual satisfaction or support condition. Value accounts +and assessment completion do not replace the normative fields they explain. +The identity field limits this implementation to its disclosed common context. -/ +structure Inherited (ctx : Context) (chosen : Candidate) : Prop where + sameContext : ctx = sharedContext + generation : generationSpecification engineeringPolicy + consistency : consistencySpecification (engineeringSnapshot .evolvable 0) + (engineeringSnapshot chosen 1) true + reflection : reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self + (selfModel chosen).performed + ownPrincipleGrounds : ∀ principle, valueSpecification (governancePosition principle) + choiceValueGrounds : valueSpecification (selectionPosition chosen) + empiricalGrounds : empiricalSpecification [presentBudgetRecord] (fun _ => True) + presentBudgetClaim (fun _ => True) + inferentialGrounds : inferentialSpecification capacityAssumptions capacityClaim + scopeAccount : scopeSpecification budgetScopeAccount + capabilityGrounds : capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen) + implementationChoice : choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons + ownClaimGrounds : ∀ fact, inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact) + observedHere : Compatible [presentBudgetRecord] chosen + selectionActuallyAdopted : (selectionPosition chosen).commitment chosen + currentOwnClaims : Models (ownTheory chosen) chosen + fullNormativeContents : ∀ norm, normApplies chosen norm → + ownTheory chosen (ownNormClaim chosen norm) + wholeClaimGrounds : ∀ claim, ownTheory chosen claim → + inferentialSpecification (ownFactPremises chosen) claim + +theorem inheritedCurrent (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) : + Inherited sharedContext chosen := by + refine ⟨rfl, engineeringGenerative, currentConsistency chosen ordinary, + currentSelfApplication chosen ordinary, governanceGrounded, + selectionGrounded chosen ordinary, grounds012Singleton _ budgetEmpiricalDischarged, + grounds012Singleton _ budgetInferentialDischarged, budgetScopeExplained, + engineeringCapabilityGrounded chosen, ?_, actualOwnFactGrounded chosen ordinary, + ?_, rfl, (currentAdmissible chosen ordinary).1, + allNormativeContentHeld chosen, wholeClaimGrounded chosen ordinary⟩ + · apply implementationReasoned + rcases ordinary with rfl | rfl <;> change _ ≤ 12 <;> decide + · apply (budgetObservationMeaning _).2 + rcases ordinary with rfl | rfl <;> change _ ≤ 3 <;> decide + +/- Mutual application extracts duties for the same system, principles, claims +and actual chosen implementation. It retains the full Inherited premise. -/ +/-- organon-map CoreReader.Engineering.inheritedMutualApplication +organon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +theorem inheritedMutualApplication (ctx : Context) (chosen : Candidate) + (inherited : Inherited ctx chosen) : + generationSpecification engineeringPolicy ∧ + reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self + (selfModel chosen).performed ∧ + (∀ principle, valueSpecification (governancePosition principle)) ∧ + capabilitySpecification (engineeringProcess chosen) (engineeringCapability chosen) ∧ + choiceSpecification chosenRequirements (chosenImplementation chosen) chosenReasons ∧ + (∀ fact, inferentialSpecification (ownFactPremises chosen) (ownFactClaim chosen fact)) ∧ + (∀ norm, normApplies chosen norm → ownTheory chosen (ownNormClaim chosen norm)) ∧ + (∀ claim, ownTheory chosen claim → inferentialSpecification (ownFactPremises chosen) claim) ∧ + consistencySpecification (engineeringSnapshot .evolvable 0) + (engineeringSnapshot chosen 1) true := + ⟨inherited.generation, inherited.reflection, inherited.ownPrincipleGrounds, + inherited.capabilityGrounds, inherited.implementationChoice, inherited.ownClaimGrounds, + inherited.fullNormativeContents, inherited.wholeClaimGrounds, inherited.consistency⟩ + +/-- organon-map CoreReader.Engineering.inheritedMutualCases +organon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +-/ +theorem inheritedMutualCases : + Inherited sharedContext .evolvable ∧ + valueSpecification (governancePosition .grounds) ∧ + capabilitySpecification (engineeringProcess .evolvable) (engineeringCapability .evolvable) ∧ + choiceSpecification chosenRequirements (chosenImplementation .evolvable) chosenReasons ∧ + Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧ + (.generationRule : ReviewObject) ∈ (selfModel .evolvable).objects ∧ + (.assessmentRule : ReviewObject) ∈ (selfModel .evolvable).objects ∧ + Reflection.evaluate ((selfModel .evolvable).input ⟨0, .assessmentRule, .revision⟩) = .counterexample := + ⟨inheritedCurrent .evolvable (Or.inr rfl), governanceGrounded .grounds, + engineeringCapabilityGrounded .evolvable, + (inheritedCurrent .evolvable (Or.inr rfl)).implementationChoice, + (actualSelfCriticism .evolvable).2.2.1, + (ownRuleIdentity .evolvable .generation .revision).1, + (ownRuleIdentity .evolvable .assessment .revision).1, + (ownRuleContentVariation .evolvable).2.2.2.2.1⟩ + +/- In the adopter's same context, the actual priority object and its own +assessment method remain within the inherited criticism/generation contract. -/ +/-- organon-map CoreReader.Engineering.priorityRemainsReflexive +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +extensions#p1 sha256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66 +software-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +software-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +-/ +theorem priorityRemainsReflexive (ctx : Context) (chosen : Candidate) + (inherited : Inherited ctx chosen) (domain : DomainSatisfied ctx chosen) + (applicable : PriorityConditions ctx) (noDeparture : ¬ JustifiedDeparture ctx .evolvable) : + chosen = .evolvable ∧ + (.priority : ReviewObject) ∈ (selfModel chosen).objects ∧ + reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self + (selfModel chosen).performed ∧ + (∀ principle, valueSpecification (governancePosition principle)) ∧ + Grounds012 (EvolutionPriority ctx) canonicalArticulation + [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) ∧ + ownTheory chosen (ownNormClaim chosen .domain) ∧ + consistencySpecification (engineeringSnapshot .evolvable 0) + (engineeringSnapshot chosen 1) true := by + have selected := (priorityWhenApplicable ctx chosen domain.2.1 applicable noDeparture).1 + refine ⟨selected, ?_, inherited.reflection, inherited.ownPrincipleGrounds, + ?_, allNormativeContentHeld chosen .domain selected, inherited.consistency⟩ + · subst chosen; decide + · rw [inherited.sameContext] + exact priorityGrounds + +/-- organon-map CoreReader.Engineering.priorityReflexiveCases +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +extensions#p1 sha256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66 +software-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +software-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +-/ +theorem priorityReflexiveCases : + (.priority : ReviewObject) ∈ (selfModel .evolvable).objects ∧ + objectTest .priority (.evolvable, 10) = true ∧ + (selfModel .evolvable).performed ⟨0, 1⟩ ⟨0, .priority, .revision⟩ + ((selfModel .evolvable).input ⟨0, .priority, .revision⟩) + (.assessed .supportedWithinScope) ∧ + Reflection.evaluate ((selfModel .evolvable).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧ + objectTest .evolutionMethod (.evolvable, 10) = true ∧ + objectTest .evolutionMethod (.evolvable, 5) = false ∧ + Grounds012 (EvolutionPriority sharedContext) canonicalArticulation + [.value (selectionPosition .evolvable)] (.value (selectionPosition .evolvable)) ∧ + Reflection.evaluate ((selfModel .evolvable).input ⟨0, .assessmentRule, .revision⟩) = .counterexample := by + refine ⟨by decide, by decide, ?_, (actualSelfCriticism .evolvable).2.2.1, + (actualSelfCriticism .evolvable).1, (actualSelfCriticism .evolvable).2.1, + priorityGrounds, (ownRuleContentVariation .evolvable).2.2.2.2.1⟩ + exact ⟨⟨rfl, by decide⟩, rfl, .assessment, rfl, rfl⟩ + +/- The witness is nonempty and satisfies the entire represented inherited and +domain bundles in the very same continuing activity, with active priority. -/ +/-- organon-map CoreReader.Engineering.jointWitness +organon.charter.overview#p2 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c +organon.charter.overview#p3 sha256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c +organon.charter.self-transcendence#p1 sha256 f4ca590e2ae15e3882f70c7b2bc46a8911c97cee547c8b137b5493fbf862c8c0 +organon.charter.self-transcendence.orientation#p1 sha256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf +organon.charter.self-transcendence.non-finality#p1 sha256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8 +organon.charter.self-transcendence.limits#p1 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d +organon.charter.self-transcendence.limits#p2 sha256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d +organon.charter.consistency#p1 sha256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42 +organon.charter.consistency.meaning#p1 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.meaning#p2 sha256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa +organon.charter.consistency.limits#p1 sha256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75 +organon.charter.reflexivity#p1 sha256 13293b45c2fa89068c68ae7ef3c5df38f0efadb3ef3873d78a5ba67d9691a757 +organon.charter.reflexivity.meaning#p1 sha256 8a2caede01a43d8b6c60b54c78ac089c51868e9956f316948077ccee2e45c9cc +organon.charter.reflexivity.limits#p1 sha256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc +organon.grounds#p1 sha256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6 +organon.grounds.assessment#p1 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p2 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.assessment#p3 sha256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d +organon.grounds.scope#p1 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.scope#p2 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.scope#p3 sha256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693 +organon.grounds.capabilities#p1 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0 +organon.grounds.capabilities#p2 sha256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0 +organon.grounds.implementations#p1 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c +organon.grounds.implementations#p2 sha256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c +organon.grounds.implementations.limits#p1 sha256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870 +organon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +extensions#p1 sha256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66 +software-engineering.purpose#p1 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.purpose#p2 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.purpose#p3 sha256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b +software-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-meaning#p1 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6 +software-engineering.evolution-meaning#p2 sha256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6 +software-engineering.structural-judgment#p1 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +software-engineering.structural-judgment#p2 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +software-engineering.structural-judgment#p3 sha256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42 +software-engineering.revision#p1 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +software-engineering.revision#p2 sha256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99 +-/ +theorem jointWitness : + ∃ ctx : Context, ∃ chosen : Candidate, + ctx = sharedContext ∧ chosen = .evolvable ∧ + Inherited ctx chosen ∧ DomainSatisfied ctx chosen ∧ + PriorityConditions ctx ∧ ¬ HasThreat ctx .evolvable ∧ + abstractionComplexity .presentSimple < abstractionComplexity chosen ∧ + CanChange ctx.activity chosen .successor .designRevision ∧ + CanChange ctx.activity chosen .agent .designRevision ∧ + ownTheory chosen (ownFactClaim chosen .selected) ∧ + (.commitment .grounds : ReviewObject) ∈ (selfModel chosen).objects ∧ + Admissible (ownTheory chosen) (comparisonContext chosen) chosen := by + exact ⟨sharedContext, .evolvable, rfl, rfl, + inheritedCurrent .evolvable (Or.inr rfl), currentDomainSatisfied, + currentPriorityConditions, currentNoThreat.1, by decide, by decide, by decide, + (nonemptyOwnObjects .evolvable).1, (nonemptyOwnObjects .evolvable).2.2.2, + currentAdmissible .evolvable (Or.inr rfl)⟩ + +/- The countermodel adopts a supported present-simplicity value and actually +chooses that option. Every inherited duty still holds. The domain conditions +are active; neither lifecycle nor threatened costs supplies an escape. -/ +/-- organon-map CoreReader.Engineering.inheritedDoesNotEntailPriority +organon.relationships.roles#p1 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p2 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +organon.relationships.roles#p3 sha256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e +extensions#p1 sha256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66 +software-engineering.evolution-priority#p1 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p2 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +software-engineering.evolution-priority#p3 sha256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04 +-/ +theorem inheritedDoesNotEntailPriority : + ∃ ctx : Context, ∃ chosen : Candidate, + ctx = sharedContext ∧ chosen = .presentSimple ∧ + Inherited ctx chosen ∧ PriorityConditions ctx ∧ + Continuing ctx.activity ∧ ¬ BoundedLifecycle ctx.activity ∧ + ¬ HasThreat ctx .evolvable ∧ ¬ JustifiedDeparture ctx .evolvable ∧ + Meets ctx.required (ctx.profiles .presentSimple) ∧ + Meets ctx.required (ctx.profiles .evolvable) ∧ + credible ctx.evidence .designRevision ∧ + CanChange ctx.activity .evolvable .successor .designRevision ∧ + CanChange ctx.activity .evolvable .agent .designRevision ∧ + changeWork .evolvable .designRevision < changeWork chosen .designRevision ∧ + abstractionComplexity chosen < abstractionComplexity .evolvable ∧ + valueSpecification (selectionPosition chosen) ∧ + (selectionPosition chosen).commitment chosen ∧ + ¬ EvolutionPriority ctx chosen := by + exact ⟨sharedContext, .presentSimple, rfl, rfl, + inheritedCurrent .presentSimple (Or.inl rfl), currentPriorityConditions, + by decide, by decide, currentNoThreat.1, currentNoThreat.2, + by decide, by decide, by decide, by decide, by decide, by decide, by decide, + selectionGrounded .presentSimple (Or.inl rfl), rfl, currentSimpleViolates⟩ + +end CoreReader.Engineering +``` + + + + **L1** 导入 CoreReader.Engineering.Domain,使其声明及传递依赖可用;此行不新增命题。 + + + **L2** 导入 CoreReader.Engineering.Reflection,使其声明及传递依赖可用;此行不新增命题。 + + + **L3** 导入 CoreReader.Engineering.SelfApplication,使其声明及传递依赖可用;此行不新增命题。 + + + **L5** 开启 CoreReader.Engineering 命名空间,后续声明归入其中。 + + + **L7** 允许不带完整限定名引用 CoreReader.Logic CoreReader.Evidence CoreReader.Adopted 中的声明;不改变其含义。 + + + **L9** 注释固定此处所有解释共用的活动、需求与证据。 + + + **L10** 注释还固定成本限制,同时允许所选实现及陈述价值变化。 + + + **L11** 全部整合主张使用 sharedContext,其定义等于固定的 currentContinuing 语境。 + + + **L13** 对所选设计与自然数输入,maintainedOutput 提取一个可观察结果。 + + + **L14** 对单元素 [n] 运行 behavior 并取首项,空列表时默认 0。 + + + **L16** 把所选设计投影为 Core 的 Implementation 记录。 + + + **L17** 采用共用描述名称 order-preserving queue。 + + + **L18** 恰在 chosen 为 presentSimple 时标记 conventional。 + + + **L19** 按同一布尔相等条件标记 established。 + + + **L20** 实现的实际 run 函数采用 maintainedOutput。 + + + **L21** 其 Core 层成本为所选设计的抽象复杂度。 + + + **L22** 此投影的定义域允许所有自然数输入。 + + + **L23** 以相同 maintainedOutput 函数作为解释。 + + + **L24** 轨迹仅含最终输出一个元素,并非内部执行轨迹。 + + + **L26** 注释把 Core 选择投影限于队列的单项可观察合约。 + + + **L27** 注释补充当前理解预算,并在此投影之外保留单独的领域检查。 + + + **L28** 为此投影定义 Core 选择需求。 + + + **L29** 所有自然数都是允许输入。 + + + **L30** 期望结果为输入自身。 + + + **L31** 以共用语境的理解容量为预算。 + + + **L32** 附加价值谓词为不受限的 True。 + + + **L34** 可用 Core 选择理由组成有限列表。 + + + **L35** 列出输出与简洁性方法理由;仅属列表不会证明理由充分。 + + + **L37** 对每个设计与自然数 n,陈述单项输出投影的正确性。 + + + **L38** 实际 maintainedOutput 必须等于 n。 + + + **L39** 对单元素输入,该等式为定义相等,故反身性可证。 + + + **L41** 在预算前提下,为任意所选设计证明有理由的 Core 实现选择。 + + + **L42** 假设实际抽象复杂度不超出 chosenRequirements.budget。 + + + **L43** 结论采用实际需求、投影实现及已列理由。 + + + **L44** 为所有允许输入构造功能正确性,并复用传入预算证明。 + + + **L45** 选择输出方法理由,留下成员资格及充分性义务。 + + + **L46** 展开 chosenReasons 证明输出理由的成员资格。 + + + **L47** 证明输出理由的不受限价值条件及精确输入、输出合约。 + + + **L49** 注释将能力报告界定为按维护者索引的实际路径可用性。 + + + **L50** 注释说明 0 是路径缺失标记,不是路径存在的证据。 + + + **L51** capabilityOutput 为自然数输入编码的维护者报告修订路径工作量。 + + + **L52** 输入 0 选择原维护者。 + + + **L53** 输入 1 选择继任者,其余更大输入均选择智能体。 + + + **L54** 在 sharedContext 中判定此维护者、设计及 designRevision 的实际 CanChange。 + + + **L55** 路径存在时返回实际修订工作量,否则返回缺失标记 0。 + + + **L57** 构造报告所选设计能力输出函数的 Process。 + + + **L58** 其输出为 capabilityOutput,可选解释为 none。 + + + **L60** 为此所选设计定义 Process 上的精确功能主张。 + + + **L61** 对所有自然数输入,要求过程输出等于该设计的 capabilityOutput。 + + + **L63** 为每个所选设计的功能能力主张提供依据。 + + + **L64** 过程与能力规范共享同一 chosen 参数。 + + + **L65** 用逐点反身性履行推理性的过程合约面向,再构造单元素依据。 + + + **L67** actualCapabilityContrast 计算六个具体维护者、设计输出。 + + + **L68** presentSimple 为原维护者报告 17 单位工作量。 + + + **L69** 它为继任者报告路径缺失标记 0。 + + + **L70** 它为智能体也报告 0。 + + + **L71** evolvable 为原维护者报告 6 单位工作量。 + + + **L72** 它为继任者也报告 6。 + + + **L73** 它为智能体也报告 6;decide 计算全部六个等式。 + + + **L75** 注释介绍当前抽象复杂度的记录阈值。 + + + **L76** 注释把观测限于此有限模型,排除未来可维护性及价值确立。 + + + **L77** 在 Candidate 上构造一个记录的布尔阈值观测。 + + + **L78** 观测函数检查抽象复杂度 ≤ 3,记录结果为 true。 + + + **L80** presentBudgetClaim 恰为同一复杂度不超过 3 的谓词。 + + + **L82** 对每个候选项,连接与此记录相容和精确主张。 + + + **L83** 陈述双向等价;此记录仅约束当前复杂度。 + + + **L84** 分别证明等价的两个方向。 + + + **L85** 假设与单元素观测列表相容。 + + + **L86** 利用单元素成员资格,将相容性应用到实际记录。 + + + **L87** 把观测函数的 true 布尔结果转为复杂度命题。 + + + **L88** 反向假设该界限,并引入任意已列记录。 + + + **L89** 单元素成员资格将其确定为 presentBudgetRecord。 + + + **L90** 把界限转为所需的布尔值等于 true。 + + + **L92** 把预算观测包装为 Candidate 上的经验 Facet。 + + + **L93** 采用精确记录与预算主张;经验范围及不确定性谓词均为 True。 + + + **L95** 证明该经验面向实际得到履行。 + + + **L96** 以 evolvable 为相容且在范围内的见证,留下主张支持与不确定性支持义务。 + + + **L97** 对每个相容候选项,引入平凡的经验范围前提。 + + + **L98** 利用观测等价的正向证明精确预算主张。 + + + **L99** 剩余不确定性谓词为 True,因此每个相容候选项均平凡满足它。 + + + **L101** capacityClaim 是关于实际当前理解容量的命题。 + + + **L102** 对每个候选项要求复杂度不超过 sharedContext 的理解限制 12。 + + + **L104** 容量推理仅假设含 presentBudgetClaim 的单元素理论。 + + + **L106** 从这些假设到容量主张构造推理面向。 + + + **L108** 证明此推理具有模型且蕴涵其主张。 + + + **L109** 用 evolvable 见证复杂度不超过 3 的假设,留下蕴涵义务。 + + + **L110** 引入满足全部推理前提的任意候选项。 + + + **L111** 单元素模型等价提取 ≤ 3 界限。 + + + **L112** 把此界限与计算出的 3 ≤ 12 不等式组合。 + + + **L114** 为当前预算测量主张构造范围说明。 + + + **L115** 所解释主张恰为 presentBudgetClaim。 + + + **L116** 应用条件为不受限的 True。 + + + **L117** 观测范围同样为 True。 + + + **L118** 比较相关性意味着在 [2, 1, 2] 上实际行为相等。 + + + **L119** 仅当两个候选项均满足预算主张时进行比较。 + + + **L120** 唯一使用的方法为 measurement。 + + + **L121** 作用文本把观测限于当前复杂度,排除未来性能结论。 + + + **L122** 解释关系首先要求方法为 measurement。 + + + **L123** 要求精确的已存限制文本。 + + + **L124** 要求所解释主张及条件谓词的身份一致。 + + + **L126** 验证此精确说明的 scopeSpecification。 + + + **L127** 拆分比较范围与方法解释两个义务。 + + + **L128** 对被比较候选项,证明四个为 True 的条件、范围,再用它们在 [2,1,2] 上实际行为的定义相等证明相关性。 + + + **L129** 引入任何实际使用的方法及其使用证明。 + + + **L130** 计算作用字符串与空字符串不等,证明其非空。 + + + **L131** 复用使用相等证明,并以反身性完成文本、主张、条件身份。 + + + **L133** 注释引入未改变观测却加强主张的反例。 + + + **L134** 展示此观测不支持更严格的复杂度界限。 + + + **L135** evolvable 与记录的 ≤ 3 结果相容。 + + + **L136** 但此单元素记录不支持对全部相容世界的复杂度 ≤ 1 主张。 + + + **L137** 以观测等价证明相容性,留下支持失败义务。 + + + **L138** 为反证假设更强的支持关系成立。 + + + **L139** 将其应用到相容的 evolvable,得到不可能的 3 ≤ 1。 + + + **L140** 计算 ¬(3 ≤ 1),并用其否定导出的界限。 + + + **L142** 注释说明政策重视扩展,同时保留已表示形式的可修订性。 + + + **L143** 注释涵盖组织、方法及原则,但不声称实际修订事件发生。 + + + **L144** 为此工程活动实例化 Agency.Policy。 + + + **L145** 定义哪些目标值得追求。 + + + **L146** 明确采纳生成承诺时,扩展目标值得追求。 + + + **L147** 保持安全运行也无条件值得追求。 + + + **L148** 形式恰在版本等于 1 时为当前形式。 + + + **L149** 可修订性要求存在更大的自然数版本且生成已采纳。 + + + **L150** 允许任意版本不下降的转移。 + + + **L152** 为此具体政策证明生成规范。 + + + **L153** 见证已采纳的扩展目标,并为每个当前形式选择版本 + 1 作为严格更大的可修订版本。 + + + **L155** 注释把 OwnFact 值界定为此模型状态的数学报告。 + + + **L156** 注释在报告具有推理依据的同时,保留独立经验、价值任务。 + + + **L157** OwnFact 枚举将纳入模型理论的报告。 + + + **L158** 纳入选择、需求、容量、能力、预测与修订报告。 + + + **L159** 还纳入生成、反思报告及以原则为参数的采纳报告。 + + + **L160** 自动派生 DecidableEq, Repr:提供这些构造子的可判定相等与可打印表示。 + + + **L162** 以已采纳设计为参数,把每个 OwnFact 解释为 Candidate 上的主张。 + + + **L163** 选择报告要求候选项等于已采纳设计。 + + + **L164** 需求报告使用该候选项在 sharedContext 中的实际指标。 + + + **L165** 容量报告为先前定义的实际容量主张。 + + + **L166** 能力报告把按候选项索引的主张应用于同一候选项的过程。 + + + **L167** 预测报告陈述旧规模 10 一致、规模 5 不一致,不依赖候选项。 + + + **L168** 修订报告针对实际 revisionFor sharedContext candidate 说明。 + + + **L169** 政策报告陈述实际 engineeringPolicy 的 generationSpecification。 + + + **L170** 反思报告采用该候选项的实际反身性规范。 + + + **L171** 规则、自身目标及执行记录均来自同一 selfModel candidate。 + + + **L172** 采纳报告为同一原则的治理承诺谓词。 + + + **L174** 证明每项自身事实对实际所选设计成立。 + + + **L175** 要求普通设计,但全称量化 OwnFact。 + + + **L176** 在同一 chosen 候选项上求值按采纳索引的事实。 + + + **L177** 按事实构造子分情况。 + + + **L178** 选择报告是 chosen = chosen,由反身性证明。 + + + **L179** 对需求,枚举全部三个候选项并计算其必要指标检查。 + + + **L180** 对容量,限于两个普通候选项并计算复杂度 ≤ 12。 + + + **L181** 对能力,引入任意输入并以相同输出函数的反身性完成。 + + + **L182** 对预测,组合定义成立的旧等式与计算得到的新不等。 + + + **L183** 对修订,代入每个普通设计并判定其具体说明。 + + + **L184** 为政策报告复用 engineeringGenerative。 + + + **L185** 在普通设计前提下复用实际 currentSelfApplication。 + + + **L186** Core 采纳标记由定义相等为真。 + + + **L188** 定义关于所选设计事实的精确推理假设。 + + + **L189** 唯一假设为候选项等于 chosen;这是以身份为条件的推理。 + + + **L191** 以推理方式为每项自身事实报告提供依据。 + + + **L192** 保留普通设计前提及任意选取的事实。 + + + **L193** 以身份理论为前提,以实际事实解释为结论。 + + + **L194** 把单元素依据化为其推理面向的履行。 + + + **L195** 以 chosen 见证其自身身份前提,留下蕴涵义务。 + + + **L196** 引入满足该身份理论的任意候选项。 + + + **L197** 利用单元素模型等价提取 candidate = chosen。 + + + **L198** 在整个目标中以 chosen 替换 candidate。 + + + **L199** 对同一 chosen 设计及事实应用实际证明的自身事实定理。 + + + **L201** 注释把优先性、价值等价限于此固定且适用的语境。 + + + **L202** 注释说明两个谓词恰选择同一候选项。 + + + **L203** 注释通过身份把价值依据连接到实际规范内容,而非仅采纳标签。 + + + **L204** 对固定共用语境中的每个候选项,证明价值承诺与实际优先性选择相同。 + + + **L205** 左侧为明确采纳 evolvable 的选择立场之承诺。 + + + **L206** 右侧为 EvolutionPriority 本身,而非优先性名称标签。 + + + **L207** 证明此同一主张等价的两个方向。 + + + **L208** 假设可演化选择承诺。 + + + **L209** 把该承诺显化为 candidate = evolvable。 + + + **L210** 代入实际所选 evolvable 候选项。 + + + **L211** 从实际 currentDomainSatisfied 提取其优先性证明。 + + + **L212** 反向假设该候选项满足实际 EvolutionPriority。 + + + **L213** 在 sharedContext 中应用优先规则的所选候选项结论。 + + + **L214** 提供当前适用性及无正当偏离;这些固定语境事实不可省略。 + + + **L216** priorityGrounds 为 sharedContext 中的实际优先性命题提供价值依据。 + + + **L217** 主张为 EvolutionPriority sharedContext,使用规范表述。 + + + **L218** 把精确的可演化价值面向同时作为唯一所需任务与所供面向。 + + + **L219** 引入价值承诺谓词与实际优先性谓词的相等。 + + + **L220** 逐点使用命题外延性,再用函数外延性导出谓词相等。 + + + **L221** 把优先性主张重写为相同的价值承诺主张。 + + + **L222** 复用 evolvable 的 selectionGrounded;面向或受评主张的转换由该等式保证。 + + + **L224** 注释区分采纳事实与实际规范内容。 + + + **L225** 注释说明后续每个构造子保留完整已表示义务及原有任务。 + + + **L226** 注释保留条件、理由与范围,并把领域义务限于领域采纳者。 + + + **L227** 注释将一致性置于所得完整理论的外部约束位置。 + + + **L228** 注释避免通过断言自身一致性的自指命题来定义该理论。 + + + **L229** OwnNorm 将完整的已表示义务与采纳报告分开枚举。 + + + **L230** 纳入生成、反思、经验与推理依据及按原则索引的价值依据。 + + + **L231** 纳入选择价值、范围、能力、选择及按事实索引的推理依据。 + + + **L232** 纳入领域整包义务与实际优先性的依据,作为不同义务。 + + + **L233** 自动派生 DecidableEq, Repr:提供这些构造子的可判定相等与可打印表示。 + + + **L235** normApplies 逐规范确定依赖采纳的成员纳入条件。 + + + **L236** 按此谓词,仅可演化采纳者纳入领域与优先性价值义务。 + + + **L237** 其他每个规范均适用于所有采纳者。 + + + **L239** 保留 adopted 参数,把每个 OwnNorm 解释为 Candidate 上的完整命题。 + + + **L240** 生成规范为实际政策的完整 generationSpecification。 + + + **L241** 反思规范要求该候选项的实际反身性规范。 + + + **L242** 它采用同一候选模型的规则、自身关系与执行关系。 + + + **L243** 经验规范保留实际记录与原有 True 经验范围谓词。 + + + **L244** 它还保留精确预算主张与原有 True 不确定性谓词。 + + + **L245** 推理规范保留实际容量假设与容量结论。 + + + **L246** 每个原则价值规范要求同一治理立场的完整依据。 + + + **L247** 选择价值内容要求按 adopted 索引的完整价值规范。 + + + **L248** 它还要求同一价值承诺在该候选项上成立。 + + + **L249** 范围规范为精确 budgetScopeAccount 的规范。 + + + **L250** 能力规范保留完整能力规范。 + + + **L251** 过程与主张均使用同一 candidate 参数。 + + + **L252** 选择规范保留完整的有理由实现选择。 + + + **L253** 它采用实际需求、此候选项的实现及原有理由。 + + + **L254** 每个自身依据规范为对应事实的完整推理任务。 + + + **L255** 其身份前提与实际事实主张均由 adopted 索引。 + + + **L256** 领域规范为 sharedContext 中的实际 DomainSatisfied,在 candidate 上求值。 + + + **L257** 优先性价值规范为实际优先性谓词的依据,使用规范表述。 + + + **L258** 保留相同的所需及所供可演化价值面向。 + + + **L260** actualOwnNorm 证明每个适用完整规范在所选候选项上满足。 + + + **L261** 所选候选项仍必须为两个普通设计之一。 + + + **L262** 量化规范并假设实际 normApplies 条件,再得出其内容。 + + + **L263** 逐 OwnNorm 构造子分情况,保留其参数。 + + + **L264** 以实际工程政策定理履行生成义务。 + + + **L265** 以此普通设计的已检查自身模型定理履行反思义务。 + + + **L266** 在单元素依据中使用实际履行的经验面向。 + + + **L267** 同样使用实际履行的容量推理面向。 + + + **L268** 对该精确原则参数使用 governanceGrounded。 + + + **L269** 把实际选择依据与所选、采纳身份的反身性配对。 + + + **L270** 复用实际预算范围解释证明。 + + + **L271** 复用同一候选项的实际功能能力依据。 + + + **L272** 进入有理由实现选择义务。 + + + **L273** 应用 implementationReasoned,留下实际预算前提。 + + + **L274** 代入任一普通设计并计算其复杂度 ≤ 12。 + + + **L275** 对完全相同的所选设计及索引事实使用 actualOwnFactGrounded。 + + + **L276** 对领域规范,使用其采纳适用性前提。 + + + **L277** 把 applicable 显化为 chosen = evolvable。 + + + **L278** 以 evolvable 替换 chosen。 + + + **L279** 现在使用实际完整的当前领域满足证明。 + + + **L280** 固定优先性价值规范由 priorityGrounds 履行。 + + + **L282** ownFactTheory 恰持有已表示的自身事实主张。 + + + **L283** 某个 OwnFact 的解释恰等于该主张时,该主张被持有。 + + + **L285** ownNormTheory 持有适用的完整规范内容。 + + + **L286** 要求实际规范见证、其 normApplies 证明及与完整解释主张相等。 + + + **L288** 注释说明后果关系联合应用于事实及完整规范内容。 + + + **L289** 注释包括其实际并集的蕴涵,不仅分别检查两个分支。 + + + **L290** ownTheory 是后续模型与一致性谓词所作用的合并理论。 + + + **L291** 取事实报告与完整适用规范主张的并集;它并非仅含采纳标记的理论。 + + + **L293** 为每个所选设计及规范提供进入合并理论的方式。 + + + **L294** 实际适用性前提足以让该规范的精确完整主张被持有。 + + + **L295** 使用并集的规范分支,提供规范见证、适用性与主张身份反身性。 + + + **L297** 为每个所选设计展示非空持有主张与检查对象。 + + + **L298** 所选设计的选择报告实际属于 ownTheory。 + + + **L299** 依据原则的采纳报告也实际被持有。 + + + **L300** 活动检查对象属于 selfModel 的列表。 + + + **L301** 依据承诺对象属于同一列表。 + + + **L302** 提供两个事实分支见证,留下两个对象成员检查。 + + + **L303** 展开实际模型与有限承诺列表,证明这些成员资格。 + + + **L305** comparisonContext 是世界为 Candidate、问题为 OwnFact 的 Logic.Context。 + + + **L306** 其假设为精确的所选身份理论。 + + + **L307** 其问题含义为按 chosen 索引的事实解释。 + + + **L308** 其允许比较范围要求复杂度不超过 3。 + + + **L310** 由所选设计及显式修订编号构造 Snapshot。 + + + **L311** 保存完整合并理论、其比较语境及该修订编号。 + + + **L313** 证明所选普通设计是其合并理论的实际允许世界。 + + + **L314** 显式保留普通设计前提。 + + + **L315** 允许性包含同一 chosen 世界上的全部持有主张、比较假设及范围。 + + + **L316** 提供反身身份假设,留下完整理论满足及范围义务。 + + + **L317** 引入合并理论实际持有的任意主张。 + + + **L318** 把并集成员资格拆为事实与规范分支。 + + + **L319** 提取 OwnFact 见证并代入其精确主张解释。 + + + **L320** 在 chosen 上应用已检查的 actualOwnFact 定理。 + + + **L321** 提取 OwnNorm 见证、适用性证明及精确主张身份。 + + + **L322** 以同一 chosen 设计、规范及适用性证明应用 actualOwnNorm。 + + + **L323** 对范围,代入每个普通设计并计算复杂度 ≤ 3。 + + + **L325** 证明新完整快照的一致性及相对于指定旧快照的如实变化报告;不合并新旧理论。 + + + **L326** 新选择必须为普通设计。 + + + **L327** 旧快照为修订编号 0 的 evolvable。 + + + **L328** 当前快照为修订编号 1 的 chosen,变化被确认为 true。 + + + **L329** 以实际允许的 chosen 见证建立后果一致性,以反身性完成变化记录义务。 + + + **L331** 为合并理论中的每个主张提供依据,包括完整适用规范主张。 + + + **L332** 要求所选设计为普通设计。 + + + **L333** 量化任意 Candidate 主张,并假设其实际被 ownTheory 持有。 + + + **L334** 结论为该精确主张以身份为条件的推理依据。 + + + **L335** 把单元素依据化为推理任务。 + + + **L336** 以 chosen 为非空身份前提模型,留下蕴涵义务。 + + + **L337** 引入满足身份假设的任意候选项。 + + + **L338** 从单元素模型语义提取其与 chosen 相等。 + + + **L339** 以 chosen 替换该候选项。 + + + **L340** 从 currentAdmissible 投影完整理论满足,并用于精确的持有主张。 + + + **L342** 注释在采纳标记不变时引入不兼容内容。 + + + **L343** 注释指出冲突两侧使用同一候选项、问题与范围。 + + + **L344** 在同一 Candidate 世界上定义故意不兼容的规范理论。 + + + **L345** 第一个单元素理论要求候选项为 presentSimple。 + + + **L346** 第二个要求同一候选项不为 presentSimple。 + + + **L348** 使用一个 Unit 问题在共同语境中比较这些对立主张。 + + + **L349** 假设为空,问题含义为 candidate = presentSimple,范围为 True。 + + + **L351** normativeContentVariation 展示真实的采纳标记不能掩盖不兼容内容。 + + + **L352** 选择采纳标记仍为 true。 + + + **L353** 实际不兼容理论在其共同语境中仍不一致。 + + + **L354** 领域采纳适用于 evolvable,不适用于 presentSimple。 + + + **L355** 实际领域主张在可演化理论中被持有。 + + + **L356** 该实际领域主张不被简单设计理论持有。 + + + **L357** 构造采纳、适用性事实与正向成员资格,留下一致性失败及反向非成员资格。 + + + **L358** 把 conflictRequiresChange 应用于唯一共同 Unit 问题。 + + + **L359** 对任意允许候选项导出冲突的正向命题。 + + + **L360** 把正向问题含义显化为 candidate = presentSimple。 + + + **L361** 利用单元素模型等价提取正向主张。 + + + **L362** 从允许性的并集模型中选择第一个理论。 + + + **L363** 对同样的允许候选项导出反向命题。 + + + **L364** 把否定含义显化为 candidate ≠ presentSimple。 + + + **L365** 利用其单元素模型等价提取反向主张。 + + + **L366** 从同一并集模型中选择第二个理论。 + + + **L367** 为证明非成员资格,假设实际领域主张被 presentSimple 持有。 + + + **L368** 其已检查允许性使完整 DomainSatisfied 主张在 presentSimple 上成立。 + + + **L369** 从领域整包提取优先性,与 currentSimpleViolates 矛盾。 + + + **L371** 注释将 Inherited 字段描述为实际满足或支持条件。 + + + **L372** 注释否认价值说明或完成评估能替代规范字段本身。 + + + **L373** 注释通过身份字段明确把实现限于共同语境。 + + + **L374** Inherited 在显式语境与所选设计上组合已表示的继承义务;其字段是投影定理的前提。 + + + **L375** 把 ctx 限为精确 sharedContext;此条件强于任意语境的实现。 + + + **L376** 要求实际工程政策的完整 generationSpecification。 + + + **L377** 要求当前快照一致,并相对于旧可演化修订 0 快照如实报告变化。 + + + **L378** 当前快照使用此所选设计、修订 1,变化记录为 true。 + + + **L379** 要求按此候选项的实际规则与自身目标满足反身性。 + + + **L380** 执行关系来自同一候选项的 selfModel。 + + + **L381** 对每个 Core 原则要求实际治理立场的价值依据。 + + + **L382** 要求此所选设计的选择价值立场依据。 + + + **L383** 要求使用实际预算记录与 True 经验范围的经验任务。 + + + **L384** 保留其精确当前预算主张与 True 不确定性谓词;未提供量化不确定性界限。 + + + **L385** 要求从 capacityAssumptions 到 capacityClaim 的实际推理。 + + + **L386** 要求实际预算范围解释。 + + + **L387** 要求同一所选过程与主张的功能能力依据。 + + + **L388** 要求在实际需求与理由下,对此所选实现作有理由的选择。 + + + **L389** 对全部自身事实,要求从所选身份前提到精确事实主张的推理。 + + + **L390** 要求 chosen 本身与实际预算观测相容。 + + + **L391** 要求所选选择承诺实际在 chosen 上被采纳。 + + + **L392** 要求 chosen 为完整合并理论中每个持有主张的模型。 + + + **L393** 对每个适用规范,要求其内容实际属于理论。 + + + **L394** 被持有内容必须为同一规范的完整 ownNormClaim。 + + + **L395** 对每个实际持有主张,要求其推理依据。 + + + **L396** 这些依据保留显式的所选身份假设。 + + + **L398** 为所选设计构造 Inherited 的全部字段。 + + + **L399** 假设其为 presentSimple 或 evolvable。 + + + **L400** 所得整包恰位于 sharedContext。 + + + **L401** 提供语境身份、实际生成证明及完整当前一致性。 + + + **L402** 提供实际自应用及每个治理原则的依据。 + + + **L403** 提供所选选择依据及已履行的经验单元素任务。 + + + **L404** 提供已履行的容量推理及实际范围说明。 + + + **L405** 提供能力依据,留下实现选择义务,并提供全部自身事实依据。 + + + **L406** 留下观测相容性,提供采纳身份及实际完整理论满足。 + + + **L407** 提供适用规范成员资格及每个持有主张的依据。 + + + **L408** 对实现字段,应用实际有理由选择定理。 + + + **L409** 拆分普通选择并计算剩余 ≤ 12 预算条件。 + + + **L410** 对观测相容性,使用预算观测等价的反向。 + + + **L411** 拆分普通选择并计算其 ≤ 3 观测界限。 + + + **L413** 注释介绍对同一系统、原则及主张的相互应用。 + + + **L414** 注释纳入实际所选实现,并保留完整 Inherited 前提。 + + + **L415** 开始 CoreReader.Engineering.inheritedMutualApplication 的来源追溯元数据;后续来源标识与哈希不是 Lean 证明前提。 + + + **L416** 记录来源单元 organon.relationships.roles#p1 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L417** 记录来源单元 organon.relationships.roles#p2 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L418** 记录来源单元 organon.relationships.roles#p3 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L419** 结束来源追溯元数据注释;Lean 不把它解析为证明项。 + + + **L420** 对任意 ctx 与 chosen,inheritedMutualApplication 从 Inherited 提取同一对象义务。 + + + **L421** 完整继承整包是显式前提,不是定理独立推导的结论。 + + + **L422** 返回实际工程生成规范。 + + + **L423** 返回所选模型规则与自身关系上的反身性。 + + + **L424** 保留同一模型的执行关系。 + + + **L425** 对全部 Core 原则全称返回价值依据。 + + + **L426** 返回所选过程及其精确主张的能力依据。 + + + **L427** 返回实际有理由实现选择。 + + + **L428** 返回每项自身事实在所选身份前提下的推理依据。 + + + **L429** 返回每个满足适用性前提的规范之理论成员资格。 + + + **L430** 返回合并理论中每个实际持有主张的推理依据。 + + + **L431** 返回当前完整理论一致性及相对于旧可演化快照的如实变化报告。 + + + **L432** 其当前一侧仍为 chosen 修订 1,变化记录为 true。 + + + **L433** 从 inherited 投影生成、反思及治理依据以构造合取。 + + + **L434** 投影能力、实际实现选择及自身事实依据。 + + + **L435** 投影完整规范成员、全部持有主张依据及完整一致性;此处未额外证明这些前提。 + + + **L437** 开始 CoreReader.Engineering.inheritedMutualCases 的来源追溯元数据;后续来源标识与哈希不是 Lean 证明前提。 + + + **L438** 记录来源单元 organon.relationships.roles#p1 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L439** 记录来源单元 organon.relationships.roles#p2 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L440** 记录来源单元 organon.relationships.roles#p3 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L441** 结束来源追溯元数据注释;Lean 不把它解析为证明项。 + + + **L442** inheritedMutualCases 给出具体正向义务以及实际自批评结果。 + + + **L443** 完整 Inherited 整包在 sharedContext 对 evolvable 成立。 + + + **L444** 依据原则的治理价值规范成立。 + + + **L445** 实际可演化过程具有其精确功能能力依据。 + + + **L446** 可演化实现具有实际有理由选择支持。 + + + **L447** 实际批处理方法修订评估为反例。 + + + **L448** generationRule 对象实际属于可演化模型。 + + + **L449** assessmentRule 对象属于同一模型。 + + + **L450** 实际评估规则修订同样评估为反例。 + + + **L451** 使用完整 inheritedCurrent 见证及实际依据原则价值定理。 + + + **L452** 使用精确的可演化能力依据定理。 + + + **L453** 从同一继承见证提取有理由实现选择。 + + + **L454** 从 actualSelfCriticism 提取批处理方法反例。 + + + **L455** 从 ownRuleIdentity 提取生成规则对象成员资格。 + + + **L456** 从对应身份定理提取评估规则对象成员资格。 + + + **L457** 从 ownRuleContentVariation 提取当前评估规则修订反例。 + + + **L459** 注释把优先性对象及其评估方法置于采纳者的同一语境。 + + + **L460** 注释把两个对象保留在继承的批评、生成合约内。 + + + **L461** 开始 CoreReader.Engineering.priorityRemainsReflexive 的来源追溯元数据;后续来源标识与哈希不是 Lean 证明前提。 + + + **L462** 记录来源单元 organon.relationships.roles#p3 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L463** 记录来源单元 extensions#p1 及 SHA-256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L464** 记录来源单元 software-engineering.structural-judgment#p1 及 SHA-256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L465** 记录来源单元 software-engineering.revision#p2 及 SHA-256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L466** 结束来源追溯元数据注释;Lean 不把它解析为证明项。 + + + **L467** priorityRemainsReflexive 在显式语境、选择下把领域优先性连接到继承的自批评。 + + + **L468** 假设同一 ctx、chosen 的完整 Inherited 整包及实际 DomainSatisfied。 + + + **L469** 还假设同一语境下优先性适用且 evolvable 不存在正当偏离。 + + + **L470** 得出所选候选项必须为 evolvable。 + + + **L471** 其实际优先性对象属于自身检查列表。 + + + **L472** 所选自身模型仍在实际规则、目标上满足反身性。 + + + **L473** 在规范中保留其实际执行关系。 + + + **L474** 保留每个继承 Core 原则的价值依据。 + + + **L475** 另为实际 EvolutionPriority ctx 主张提供依据,使用规范表述。 + + + **L476** 其所需与所供面向为完全相同的可演化选择价值立场。 + + + **L477** 完整实际领域规范被 chosen 的合并理论持有。 + + + **L478** 保留完整继承一致性规范。 + + + **L479** 当前快照仍为 chosen 修订 1,变化确认值为 true。 + + + **L480** 从 domain 提取实际优先性,应用适用性与无偏离前提导出 chosen = evolvable。 + + + **L481** 构造选择身份,留下成员资格,并投影反思与 Core 价值依据。 + + + **L482** 留下精确优先性依据;以 selected 作为领域规范适用性,并投影一致性。 + + + **L483** 以 evolvable 替换 chosen,计算实际优先性对象成员资格。 + + + **L484** 利用 Inherited 身份字段把 ctx 重写为 sharedContext;这限定了依据结果的语境。 + + + **L485** 现在对完全相同的优先性谓词应用 priorityGrounds。 + + + **L487** 开始 CoreReader.Engineering.priorityReflexiveCases 的来源追溯元数据;后续来源标识与哈希不是 Lean 证明前提。 + + + **L488** 记录来源单元 organon.relationships.roles#p3 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L489** 记录来源单元 extensions#p1 及 SHA-256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L490** 记录来源单元 software-engineering.structural-judgment#p1 及 SHA-256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L491** 记录来源单元 software-engineering.revision#p2 及 SHA-256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L492** 结束来源追溯元数据注释;Lean 不把它解析为证明项。 + + + **L493** priorityReflexiveCases 计算实际优先性检查,并保留对不同方法对象的批评。 + + + **L494** 优先性对象实际列于可演化设计。 + + + **L495** 其有限规模 10 对象测试通过。 + + + **L496** 模型在评估键 (0,1) 下记录所有者 0 的优先性修订实际执行。 + + + **L497** 执行输入恰为同一目标构造的输入。 + + + **L498** 记录结果为 assessed supportedWithinScope。 + + + **L499** 不同的批处理方法修订仍产生反例。 + + + **L500** 旧批处理方法规模 10 测试成功。 + + + **L501** 受质疑规模 5 测试失败。 + + + **L502** 保留 sharedContext 中实际优先性的依据及规范表述。 + + + **L503** 采用相同的单元素所需、所供可演化价值面向。 + + + **L504** 评估规则修订的局部合约失败也被保留为反例。 + + + **L505** 计算优先性成员及测试成功;留下 performed,并提取批处理批评。 + + + **L506** 提取批处理方法的旧规模成功与受质疑规模失败。 + + + **L507** 提供实际优先性依据及实际规则修订反例。 + + + **L508** 以自身成员资格、精确输入及评估活动的键、记录身份构造 performed。 + + + **L510** 注释介绍满足全部已表示继承整包的非空见证。 + + + **L511** 注释还要求完全相同持续活动中的领域整包及适用优先性。 + + + **L512** 开始 CoreReader.Engineering.jointWitness 的来源追溯元数据;后续来源标识与哈希不是 Lean 证明前提。 + + + **L513** 记录来源单元 organon.charter.overview#p2 及 SHA-256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L514** 记录来源单元 organon.charter.overview#p3 及 SHA-256 75d7d941d3c07ea748c4a9261d36a75fbd5664ff9c817c4034a9a36a3a12664c;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L515** 记录来源单元 organon.charter.self-transcendence#p1 及 SHA-256 f4ca590e2ae15e3882f70c7b2bc46a8911c97cee547c8b137b5493fbf862c8c0;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L516** 记录来源单元 organon.charter.self-transcendence.orientation#p1 及 SHA-256 7f9b85c0816b3d69e417cf3cbe17b7b59931388f84d799ce6730c998037358bf;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L517** 记录来源单元 organon.charter.self-transcendence.non-finality#p1 及 SHA-256 4ae4497523e79e0606ab3849c47b6ea16f8888a952e063e6966eb36b750f3df8;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L518** 记录来源单元 organon.charter.self-transcendence.limits#p1 及 SHA-256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L519** 记录来源单元 organon.charter.self-transcendence.limits#p2 及 SHA-256 6dade83f0b7fcc004bdb37b6726c15b31b06a377de4e86d506c9d2e67847029d;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L520** 记录来源单元 organon.charter.consistency#p1 及 SHA-256 c6960c590c096d33250599cf418e3c6a1dc26bfc7d7800c82b8efde656950f42;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L521** 记录来源单元 organon.charter.consistency.meaning#p1 及 SHA-256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L522** 记录来源单元 organon.charter.consistency.meaning#p2 及 SHA-256 81c09e38a3349499f95401d1c08f6069666c13547a43bc4e4395330743055faa;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L523** 记录来源单元 organon.charter.consistency.limits#p1 及 SHA-256 4fa1c29bf95ad6ef04c6d27671a832c0af8ba31b9c0d8018a8d09c4f33c38e75;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L524** 记录来源单元 organon.charter.reflexivity#p1 及 SHA-256 13293b45c2fa89068c68ae7ef3c5df38f0efadb3ef3873d78a5ba67d9691a757;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L525** 记录来源单元 organon.charter.reflexivity.meaning#p1 及 SHA-256 8a2caede01a43d8b6c60b54c78ac089c51868e9956f316948077ccee2e45c9cc;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L526** 记录来源单元 organon.charter.reflexivity.limits#p1 及 SHA-256 ac0baae0d86e69f84c1ca4dee837de2759e2d29c295ffc257d988962158d4bbc;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L527** 记录来源单元 organon.grounds#p1 及 SHA-256 4ee74dc8617388ee75d63b507176ecb73b8527758b648f7c588d3ae7f3445ec6;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L528** 记录来源单元 organon.grounds.assessment#p1 及 SHA-256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L529** 记录来源单元 organon.grounds.assessment#p2 及 SHA-256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L530** 记录来源单元 organon.grounds.assessment#p3 及 SHA-256 ac2f84ce07036731964e26221e6d3ef83c9b647ebe249862eb2bc115856e6e4d;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L531** 记录来源单元 organon.grounds.scope#p1 及 SHA-256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L532** 记录来源单元 organon.grounds.scope#p2 及 SHA-256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L533** 记录来源单元 organon.grounds.scope#p3 及 SHA-256 4a0e93c7834e4ef62f129ee4621cf7bf1c93b64d86f9f145d1592adcf9fb6693;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L534** 记录来源单元 organon.grounds.capabilities#p1 及 SHA-256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L535** 记录来源单元 organon.grounds.capabilities#p2 及 SHA-256 7249f6f2ef327baaa72349cae53b9245f23a34436356dd05f3c6005cab35e8f0;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L536** 记录来源单元 organon.grounds.implementations#p1 及 SHA-256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L537** 记录来源单元 organon.grounds.implementations#p2 及 SHA-256 bb2a822a304d4a20f513218f356ddbeeca8ee139e3ed802213591e9ff6c5095c;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L538** 记录来源单元 organon.grounds.implementations.limits#p1 及 SHA-256 db9b5f1803baab0e1b05a3a9e068948667412afa7d692e1da3869ca54be4b870;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L539** 记录来源单元 organon.relationships.roles#p1 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L540** 记录来源单元 organon.relationships.roles#p2 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L541** 记录来源单元 organon.relationships.roles#p3 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L542** 记录来源单元 extensions#p1 及 SHA-256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L543** 记录来源单元 software-engineering.purpose#p1 及 SHA-256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L544** 记录来源单元 software-engineering.purpose#p2 及 SHA-256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L545** 记录来源单元 software-engineering.purpose#p3 及 SHA-256 946a96680b1a00867f58e7921588e5a56e79b336ba3d322b8aef1122cc75a60b;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L546** 记录来源单元 software-engineering.evolution-priority#p1 及 SHA-256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L547** 记录来源单元 software-engineering.evolution-priority#p2 及 SHA-256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L548** 记录来源单元 software-engineering.evolution-priority#p3 及 SHA-256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L549** 记录来源单元 software-engineering.evolution-meaning#p1 及 SHA-256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L550** 记录来源单元 software-engineering.evolution-meaning#p2 及 SHA-256 c3fa878716f4370ebd1d352d2c135255695cfec6e1d33900a184cb46acb80bf6;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L551** 记录来源单元 software-engineering.structural-judgment#p1 及 SHA-256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L552** 记录来源单元 software-engineering.structural-judgment#p2 及 SHA-256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L553** 记录来源单元 software-engineering.structural-judgment#p3 及 SHA-256 8014457feae3410a7220426dbbe4293f7b5d1d2aa152f4085ccd1f03d5983a42;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L554** 记录来源单元 software-engineering.revision#p1 及 SHA-256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L555** 记录来源单元 software-engineering.revision#p2 及 SHA-256 5d31bed0197ea7e7028eb7a85e56059516421c6c27613cc5479e0b98c5111d99;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L556** 结束来源追溯元数据注释;Lean 不把它解析为证明项。 + + + **L557** jointWitness 展示一个同时满足继承与领域整包的非空有限模型。 + + + **L558** 存在性选择语境及 Candidate;这是存在结果,不是普遍充分性。 + + + **L559** 要求见证恰为 sharedContext 与 evolvable。 + + + **L560** 两个完整整包必须对这些相同对象成立。 + + + **L561** 优先性适用条件成立,且 evolvable 无已表示威胁。 + + + **L562** 所选设计的抽象复杂度大于 presentSimple。 + + + **L563** 继任者在同一活动、设计中具有实际 designRevision 路径。 + + + **L564** 智能体在那里也具有实际 designRevision 路径。 + + + **L565** 所选设计报告实际被 chosen 的理论持有。 + + + **L566** 依据承诺实际属于 chosen 的自身检查对象。 + + + **L567** Chosen 是其完整合并理论与比较语境的允许模型。 + + + **L568** 选择 sharedContext 与 evolvable 为见证,以反身性证明两个身份字段。 + + + **L569** 提供完整 inheritedCurrent 整包及 currentDomainSatisfied。 + + + **L570** 提供适用优先性与无威胁,再计算复杂度次序及两个维护者路径。 + + + **L571** 从 nonemptyOwnObjects 投影持有选择及实际依据检查对象。 + + + **L572** 以实际完整理论允许性证明完成。 + + + **L574** 注释介绍采纳有支持的当前简单性价值的反模型。 + + + **L575** 注释陈述实际选择及完整继承满足,并开始说明适用性限定。 + + + **L576** 注释排除领域条件不适用、有界生命周期及受威胁成本作为回避解释。 + + + **L577** 开始 CoreReader.Engineering.inheritedDoesNotEntailPriority 的来源追溯元数据;后续来源标识与哈希不是 Lean 证明前提。 + + + **L578** 记录来源单元 organon.relationships.roles#p1 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L579** 记录来源单元 organon.relationships.roles#p2 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L580** 记录来源单元 organon.relationships.roles#p3 及 SHA-256 24b533c77fe93d0570da65ee361893f2c445842f48ee6f315f99f8abc06a0e5e;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L581** 记录来源单元 extensions#p1 及 SHA-256 ec87a2f17b2f88addcadea0108add11ad3d4239daf56db466ba0ddbe7cc92b66;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L582** 记录来源单元 software-engineering.evolution-priority#p1 及 SHA-256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L583** 记录来源单元 software-engineering.evolution-priority#p2 及 SHA-256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L584** 记录来源单元 software-engineering.evolution-priority#p3 及 SHA-256 c2237515e869b2f88269cf19e3c97ef80c3c87342d1a03cd911cac03fe5a3a04;此注释追溯受审来源对象,不是逻辑假设或对应性证明。 + + + **L585** 结束来源追溯元数据注释;Lean 不把它解析为证明项。 + + + **L586** inheritedDoesNotEntailPriority 展示有限反模型,区分继承义务与附加优先性采纳。 + + + **L587** 存在性选择满足以下全部合取项的语境与候选项。 + + + **L588** 把它们固定为 sharedContext 与 presentSimple。 + + + **L589** 完整继承整包成立,同时领域优先性条件适用。 + + + **L590** 同一活动持续且不具有有界生命周期。 + + + **L591** evolvable 既无威胁,也无正当偏离。 + + + **L592** presentSimple 满足实际必要需求。 + + + **L593** evolvable 也满足这些相同需求。 + + + **L594** 同一证据使 designRevision 可信。 + + + **L595** 继任者能在此活动中修订 evolvable。 + + + **L596** 智能体在那里也能修订 evolvable。 + + + **L597** evolvable 的实际设计修订工作量少于所选 presentSimple。 + + + **L598** 所选 presentSimple 的当前抽象复杂度小于 evolvable。 + + + **L599** 所选简单性价值立场具有实际价值依据。 + + + **L600** 同一价值立场实际承诺所选设计。 + + + **L601** 尽管如此,该选择的实际 EvolutionPriority 主张为假。 + + + **L602** 选择 sharedContext 与 presentSimple,以反身性完成身份要求。 + + + **L603** 提供完整继承满足及适用优先性条件。 + + + **L604** 计算持续性与非有界性,再使用无威胁、无偏离两个事实。 + + + **L605** 计算两个需求、可信修订、两个维护者路径及工作量、复杂度不等式。 + + + **L606** 以实际简单立场依据、反身采纳及 currentSimpleViolates 完成反模型。 + + + **L608** 关闭 CoreReader.Engineering 命名空间;不另行断言数学主张。 + + +### `leanified/CoreReader/Engineering/Reflection.lean` + + +```lean +import CoreReader.Adopted + +namespace CoreReader.Engineering.Reflection + +open CoreReader.Agency CoreReader.Adopted + +/- A target retains the owner, the actual object and the stage being examined. -/ +structure Target (Object : Type) where + owner : Nat + object : Object + phase : Phase + +/- A finite assessment contract has actual tests and a scope it claims to cover. +The scope is an application limit, not a universal definition of assessment. -/ +structure Contract (W : Type) where + test : W → Bool + tested : List W + claimed : List W + +/- Inputs carry the contract belonging to the named target, so another object's +test result cannot silently discharge this target's inquiry. -/ +structure Input (W Object : Type) where + target : Target Object + contract : Contract W + requested : List W + reasons : List String + basis : Prop + +inductive Verdict | supportedWithinScope | counterexample | noSupportingSample + deriving DecidableEq, Repr + +inductive Outcome (W : Type) + | generated (tests scope : List W) + | assessed (verdict : Verdict) + deriving DecidableEq + +/- A successful sample does not license the wider scope: an actual failing +instance there changes the assessment to counterexample. -/ +def evaluate {W Object : Type} (input : Input W Object) : Verdict := + if input.contract.tested.all input.contract.test then + if input.requested.all input.contract.test then .supportedWithinScope + else .counterexample + else .noSupportingSample + +/- Generation proposes an expanded test set. Proposal generation does not prove +that the resulting contract passes those tests or warrants adoption. -/ +def generate {W Object : Type} (input : Input W Object) : Outcome W := + .generated input.requested input.requested + +def interpret {W Object : Type} (activity : Activity) (input : Input W Object) + (outcome : Outcome W) : Prop := + input.reasons ≠ [] ∧ input.basis ∧ match activity with + | .generation => outcome = generate input + | .assessment => outcome = .assessed (evaluate input) + +structure Model (W Object : Type) where + owner : Nat + objects : List Object + contracts : Object → Contract W + requested : Object → Phase → List W + reasons : Object → Phase → List String + basis : Object → Phase → Prop + generationApplies : Object → Phase → Prop + assessmentApplies : Object → Phase → Prop + recorded : Activity → Object → Phase → Outcome W + +def Model.input {W Object : Type} (m : Model W Object) (t : Target Object) : Input W Object := + ⟨t, m.contracts t.object, m.requested t.object t.phase, m.reasons t.object t.phase, + m.basis t.object t.phase⟩ + +def Model.self {W Object : Type} (m : Model W Object) (t : Target Object) : Prop := + t.owner = m.owner ∧ t.object ∈ m.objects + +def Model.rule {W Object : Type} (m : Model W Object) (activity : Activity) : + ReflexiveRule (Target Object) (Input W Object) (Outcome W) where + key := ⟨m.owner, match activity with | .generation => 0 | .assessment => 1⟩ + activity := activity + applicable t := m.self t ∧ match activity with + | .generation => m.generationApplies t.object t.phase + | .assessment => m.assessmentApplies t.object t.phase + input := m.input + meaning := interpret activity + +def Model.rules {W Object : Type} (m : Model W Object) := + [m.rule .generation, m.rule .assessment] + +/- These are the stated records. The separate follows test compares each stated +outcome with the actual input's evaluation, rather than defining success by its name. -/ +def Model.performed {W Object : Type} (m : Model W Object) + (key : PrincipleKey) (t : Target Object) (input : Input W Object) (outcome : Outcome W) : Prop := + m.self t ∧ input = m.input t ∧ + ∃ activity, key = (m.rule activity).key ∧ + outcome = m.recorded activity t.object t.phase + +def Model.follows {W Object : Type} (m : Model W Object) : Prop := + ∀ activity object phase, object ∈ m.objects → + (match activity with + | .generation => m.generationApplies object phase + | .assessment => m.assessmentApplies object phase) → + interpret activity (m.input ⟨m.owner, object, phase⟩) (m.recorded activity object phase) + +/- This generic implication retains the actual evaluation premise. Concrete +engineering instances must discharge follows separately for their own contracts. -/ +theorem recordedReflexivity {W Object : Type} (m : Model W Object) (checked : m.follows) : + reflexivitySpecification m.rules m.self m.performed := by + constructor + · intro p hp q hq equal + simp only [Model.rules, List.mem_cons, List.not_mem_nil, or_false] at hp hq + rcases hp with rfl | rfl <;> rcases hq with rfl | rfl + · rfl + · have bad := congrArg PrincipleKey.localId equal; contradiction + · have bad := congrArg PrincipleKey.localId equal; contradiction + · rfl + · intro rule hr target hs ha + simp only [Model.rules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl + · refine ⟨m.recorded .generation target.object target.phase, + ⟨hs, rfl, .generation, rfl, rfl⟩, ?_⟩ + have actual := checked .generation target.object target.phase hs.2 ha.2 + rcases target with ⟨owner, object, phase⟩ + have ownerEqual : owner = m.owner := hs.1 + subst owner + exact actual + · refine ⟨m.recorded .assessment target.object target.phase, + ⟨hs, rfl, .assessment, rfl, rfl⟩, ?_⟩ + have actual := checked .assessment target.object target.phase hs.2 ha.2 + rcases target with ⟨owner, object, phase⟩ + have ownerEqual : owner = m.owner := hs.1 + subst owner + exact actual + +end CoreReader.Engineering.Reflection +``` + + + + **L1** 导入 CoreReader.Adopted,使其声明及传递依赖可用;此行不新增命题。 + + + **L3** 开启 CoreReader.Engineering.Reflection 命名空间,后续声明归入其中。 + + + **L5** 允许不带完整限定名引用 CoreReader.Agency CoreReader.Adopted 中的声明;不改变其含义。 + + + **L7** 注释说明 Target 保留所有者、实际对象及受检阶段的用意;这些连接由字段编码。 + + + **L8** 对任意对象类型,Target 保存所有者、该类型的实际对象和生命周期阶段。 + + + **L9** 所有者标识是自然数;该字段不要求全局唯一。 + + + **L10** 此字段保留实际对象,而非仅存名称。 + + + **L11** 目标包含当前受检查的阶段。 + + + **L13** 注释介绍包含实际测试与声称范围的有限评估合约。 + + + **L14** 注释把此范围表示限于应用,不将其当作评估的普遍定义。 + + + **L15** 对任意样本类型 W,Contract 包含一个布尔测试和两个有限列表。 + + + **L16** 测试把每个 W 值映射为布尔结果。 + + + **L17** 此列表记录初始测试案例,允许为空。 + + + **L18** 此字段是合约声称覆盖的列表;evaluate 不读取它。 + + + **L20** 注释介绍与目标关联的输入;后续 Model.input 按该目标选择字段。 + + + **L21** 注释说明防止用另一对象测试替代本次检查的目的;原始 Input 本身不强制来源不变量。 + + + **L22** Input 对样本和对象类型均为多态,组合目标及其检查数据。 + + + **L23** 保留完整的所有者、对象、阶段目标。 + + + **L24** 保存模型关联到此对象的测试合约。 + + + **L25** 初始列表通过后,evaluate 检查此请求列表。 + + + **L26** 理由以字符串保存;后续检查列表非空,不通过字符串分析证明其真实性或相关性。 + + + **L27** 依据可为任意命题;interpret 要求其成立。 + + + **L29** 定义范围内支持、反例、无支持样本三个判定值。 + + + **L30** 自动派生 DecidableEq, Repr:提供这些构造子的可判定相等与可打印表示。 + + + **L32** Outcome 以样本类型 W 为参数,记录生成结果或评估结果。 + + + **L33** 生成结果保存两个 W 列表,分别表示测试和范围。 + + + **L34** 评估结果保存 Verdict,不保存样本列表。 + + + **L35** 在具有 [DecidableEq W] 时为 Outcome W 派生可判定相等;生成的实例保留此前提,具体 ReviewCase 模型满足它。 + + + **L37** 注释说明初始样本成功本身不授权更广请求列表。 + + + **L38** 注释指出初始成功后,实际失败的请求案例会进入反例分支。 + + + **L39** evaluate 隐含 W、Object 类型参数,输入一个 Input,以两次布尔全称检查计算判定。 + + + **L40** 先要求全部初始测试通过;空列表的 List.all 为 true。 + + + **L41** 初始测试与全部请求案例均通过时返回 supportedWithinScope;初始列表为空也可能如此。 + + + **L42** 初始测试通过而请求案例中有失败时,返回 counterexample。 + + + **L43** 初始案例失败时返回 noSupportingSample;名称不意味着实现检查了空列表。 + + + **L45** 注释把生成描述为提议测试,并开始区分提议与验证。 + + + **L46** 注释否认提议生成能证明测试通过或采纳有据。 + + + **L47** generate 隐含样本与对象类型参数,依据输入产生一个提议结果。 + + + **L48** 把 requested 同时复制到生成测试与范围;此处不验证任一列表。 + + + **L50** interpret 接收活动与输入,两个类型参数均隐含。 + + + **L51** 最后一个显式参数是结果;返回值是关于该结果的命题。 + + + **L52** 要求理由列表非空、输入依据命题成立,再按活动分支。 + + + **L53** 生成活动的含义是结果恰等于该输入的实际生成器输出。 + + + **L54** 评估活动的含义是结果恰等于 evaluate 对此输入计算的判定。 + + + **L56** Model 对 W、Object 参数化,提供目标成员、合约、适用性和记录结果。 + + + **L57** 模型具有一个自然数所有者标识。 + + + **L58** 仅此有限列表中的对象可满足 Model.self。 + + + **L59** 为每个 Object 值分配合约,包括 objects 列表以外的值。 + + + **L60** 请求案例依赖对象与阶段。 + + + **L61** 理由字符串依赖同一对象与阶段。 + + + **L62** 依据命题也依赖该对象与阶段。 + + + **L63** 命题逐对象、逐阶段确定生成适用性。 + + + **L64** 另一命题确定评估适用性。 + + + **L65** 记录结果依赖活动、对象与阶段;此处不假定其正确。 + + + **L67** Model.input 为任意目标构建检查输入,本身不检查所有者或成员资格。 + + + **L68** 保留目标本身,按其实际对象和阶段选取合约、请求案例及理由。 + + + **L69** 以同一对象、阶段选出的依据补全输入。 + + + **L71** Model.self 是目标的成员与所有权谓词。 + + + **L72** 同时要求所有者相等、实际对象属于列表;此处不限制阶段。 + + + **L74** 给定模型与活动,构造对应的反身规则。 + + + **L75** 规则的目标、输入、输出类型分别固定为 Target Object、Input W Object、Outcome W。 + + + **L76** 键由模型所有者和局部编号组成,生成用 0,评估用 1。 + + + **L77** 在规则中保留传入的活动。 + + + **L78** 适用性要求目标属于自身,且满足对应活动的适用条件。 + + + **L79** 生成采用此对象在此阶段的 generationApplies。 + + + **L80** 评估采用此对象在此阶段的 assessmentApplies。 + + + **L81** 实际规则输入采用模型按目标构造的 input。 + + + **L82** 规则含义采用该活动的实际 interpret 函数。 + + + **L84** 构建此模型的规则列表,两个泛型类型由推断确定。 + + + **L85** 规则列表仅含生成与评估两项,依次排列。 + + + **L87** 注释指出 performed 数据是陈述记录,另由 follows 检查。 + + + **L88** 注释说明要与实际输入评估比较,不能由结果名称推断成功。 + + + **L89** 定义属于此模型的记录执行关系。 + + + **L90** 关系显式接收原则键、目标、输入、结果并返回 Prop。 + + + **L91** 要求目标属于自身,且输入恰等于该目标实际构造的输入。 + + + **L92** 存在一个活动,其规则键等于传入的键。 + + + **L93** 结果必须恰等于该活动与同一对象、阶段的记录。 + + + **L95** Model.follows 表述所有适用记录均满足其实际含义。 + + + **L96** 全称量化活动、对象、阶段,再假设对象属于列表。 + + + **L97** 下一前提按活动选取适用性。 + + + **L98** 对生成,要求所量化对象、阶段的 generationApplies。 + + + **L99** 对评估,要求 assessmentApplies,再断言解释成立。 + + + **L100** 将记录结果与实际输入核对,目标所有者固定为 m.owner。 + + + **L102** 注释强调通用蕴涵保留实质评估前提。 + + + **L103** 注释要求具体实例为各自实际合约证明 follows。 + + + **L104** 对任意类型和模型,此定理假设 checked : m.follows,并不证明此前提。 + + + **L105** 在此前提下,证明 reflexivitySpecification 中的规则键身份与适用的自执行要求。 + + + **L106** 将规范拆为身份与执行两个证明义务。 + + + **L107** 引入列表内的两个规则,并假设其键相等。 + + + **L108** 将两项规则列表的成员资格展开为生成或评估两种可能。 + + + **L109** 替换两个成员的可能值,形成四种规则配对。 + + + **L110** 两个规则属于同一活动时,所需相等由反身性成立。 + + + **L111** 对生成与评估的配对,把键相等投影到 localId,得到 0 = 1 的矛盾。 + + + **L112** 对评估与生成的配对,相同投影得到 1 = 0 的矛盾。 + + + **L113** 两个规则属于同一活动时,所需相等由反身性成立。 + + + **L114** 为执行义务引入列表规则、自身目标及适用性证明。 + + + **L115** 将规则成员资格化为两个活动的可能值。 + + + **L116** 通过替换,分别处理生成与评估。 + + + **L117** 在生成分支,选择此目标对象、阶段的生成记录作为存在见证。 + + + **L118** 利用自身成员资格、精确输入与生成活动证明 performed,留下含义义务。 + + + **L119** 以 hs 的对象成员资格与 ha 的适用性,将 checked 用于该生成记录。 + + + **L120** 把目标拆为所有者、对象、阶段,显露所有者相等关系。 + + + **L121** 从自身目标前提提取 owner = m.owner。 + + + **L122** 代入模型所有者,使 checked 与目标指向相同输入。 + + + **L123** 先前取得的实际解释此时恰好关闭目标。 + + + **L124** 在评估分支,选择同一目标的评估记录作为见证。 + + + **L125** 以评估活动和精确输入、输出身份构造 performed。 + + + **L126** 将 checked 用于评估,保留此目标的成员及适用性前提。 + + + **L127** 把目标拆为所有者、对象、阶段,显露所有者相等关系。 + + + **L128** 从自身目标前提提取 owner = m.owner。 + + + **L129** 代入模型所有者,使 checked 与目标指向相同输入。 + + + **L130** 先前取得的实际解释此时恰好关闭目标。 + + + **L132** 关闭 CoreReader.Engineering.Reflection 命名空间;不另行断言数学主张。 + + +### `leanified/CoreReader/Engineering/SelfApplication.lean` + + +```lean +import CoreReader.Engineering.Values +import CoreReader.Engineering.Reflection + +namespace CoreReader.Engineering + +open CoreReader.Adopted + +inductive ReviewObject | activity | commitment (principle : CoreCommitment) | priority | evolutionMethod + | generationRule | assessmentRule + deriving DecidableEq, Repr + +abbrev ReviewCase := Candidate × Nat + +def generationApplies (_ : ReviewObject) (phase : CoreReader.Agency.Phase) : Prop := + phase ≠ .application + +def assessmentApplies (_ : ReviewObject) (_ : CoreReader.Agency.Phase) : Prop := True + +def ruleObject : CoreReader.Agency.Activity → ReviewObject + | .generation => .generationRule + | .assessment => .assessmentRule + +/- These inputs test the current reflection functions themselves. Size 10 has +an actual supporting sample; size 5 removes that sample while retaining the +requested claim. The domain batch predictor is not used in this method test. -/ +def ruleProbe (activity : CoreReader.Agency.Activity) (point : ReviewCase) : + Reflection.Input ReviewCase ReviewObject where + target := ⟨0, ruleObject activity, .revision⟩ + contract := ⟨fun _ => true, if point.2 = 10 then [point] else [], [point]⟩ + requested := [point] + reasons := ["retain the proposed scope and distinguish actual samples from an empty test set"] + basis := True + +def generationRuleTest + (method : Reflection.Input ReviewCase ReviewObject → Reflection.Outcome ReviewCase) + (point : ReviewCase) : Bool := + let input := ruleProbe .generation point + method input == .generated input.requested input.requested + +def assessmentRuleTest + (method : Reflection.Input ReviewCase ReviewObject → Reflection.Verdict) + (point : ReviewCase) : Bool := + method (ruleProbe .assessment point) == + (if point.2 = 10 then .supportedWithinScope else .noSupportingSample) + +/- A candidate revision supplies the previously missing empty-sample check. +It is kept distinct from the current evaluator and is not silently adopted. -/ +def sampleAwareAssessment (input : Reflection.Input ReviewCase ReviewObject) : Reflection.Verdict := + if input.contract.tested.isEmpty then .noSupportingSample else Reflection.evaluate input + +/- The method under criticism is the activity's own static batch forecast. Its +contract is checked at its original size and at the credible runtime change. -/ +def objectTest (object : ReviewObject) (point : ReviewCase) : Bool := + match object with + | .activity => decide (Meets currentContinuing.required (currentContinuing.profiles point.1)) + | .commitment principle => safeguardExperiment principle true point.1 + | .priority => decide (EvolutionPriority currentContinuing point.1) + | .evolutionMethod => staticBatch 21 point.2 == liveBatch 21 point.2 + | .generationRule => generationRuleTest Reflection.generate point + | .assessmentRule => assessmentRuleTest Reflection.evaluate point + +def reviewObjects (chosen : Candidate) : List ReviewObject := + [.activity] ++ coreCommitments.map ReviewObject.commitment ++ + (if chosen = .evolvable then [.priority] else []) ++ + [.evolutionMethod, .generationRule, .assessmentRule] + +def requestedCases (chosen : Candidate) : CoreReader.Agency.Phase → List ReviewCase + | .formation | .application => [(chosen, 10)] + | .revision => [(chosen, 10), (chosen, 5)] + +def reviewReasons (object : ReviewObject) (phase : CoreReader.Agency.Phase) : List String := + let content := match object with + | .activity => "actual order, safety, latency and retention requirements of this activity" + | .commitment principle => criticismFor principle + | .priority => "credible design revision, successor and agent paths, necessary requirements and concrete costs" + | .evolutionMethod => "the same batch forecast at its recorded size and the proposed runtime size" + | .generationRule => "the actual generator must retain its input's requested tests and scope" + | .assessmentRule => "the actual evaluator's acceptance depends on whether its input has supporting samples" + [content, match phase with + | .formation => "identify this object's purpose and the conditions of its initial contract" + | .application => "apply that contract to the currently selected design in this continuing activity" + | .revision => "examine the proposed wider input scope and retain any counterexample"] + +/- The recorded verdict is independent of the evaluator: the revision of the +batch method is explicitly reported as a counterexample; other current checks +are reported supported only in the scope that will be checked below. -/ +def statedReview (chosen : Candidate) (activity : CoreReader.Agency.Activity) + (object : ReviewObject) (phase : CoreReader.Agency.Phase) : Reflection.Outcome ReviewCase := + match activity with + | .generation => .generated (requestedCases chosen phase) (requestedCases chosen phase) + | .assessment => .assessed (match object, phase with + | .evolutionMethod, .revision | .assessmentRule, .revision => .counterexample + | _, _ => .supportedWithinScope) + +/- The basis is not a free approval flag. Each inquiry requires the facts +relevant to its own object; a counterexample can ground criticism rather than +the truth of the original method's broader claim. -/ +def reviewBasis (chosen : Candidate) : ReviewObject → CoreReader.Agency.Phase → Prop + | .activity, _ => ActivityScope currentContinuing.activity ∧ + Meets currentContinuing.required (currentContinuing.profiles chosen) + | .commitment principle, _ => ReasonRelevant principle (reasonFor principle) chosen + | .priority, _ => PriorityConditions currentContinuing ∧ ¬ HasThreat currentContinuing .evolvable + | .evolutionMethod, .revision => + staticBatch 21 10 = liveBatch 21 10 ∧ staticBatch 21 5 ≠ liveBatch 21 5 + | .evolutionMethod, _ => staticBatch 21 10 = liveBatch 21 10 + | .generationRule, _ => + generationRuleTest Reflection.generate (chosen, 10) = true ∧ + generationRuleTest (fun _ => .generated [] []) (chosen, 10) = false + | .assessmentRule, .revision => + assessmentRuleTest Reflection.evaluate (chosen, 10) = true ∧ + assessmentRuleTest Reflection.evaluate (chosen, 5) = false + | .assessmentRule, _ => assessmentRuleTest Reflection.evaluate (chosen, 10) = true + +def selfModel (chosen : Candidate) : Reflection.Model ReviewCase ReviewObject where + owner := 0 + objects := reviewObjects chosen + contracts object := ⟨objectTest object, [(chosen, 10)], [(chosen, 10)]⟩ + requested _ := requestedCases chosen + reasons := reviewReasons + basis := reviewBasis chosen + generationApplies := generationApplies + assessmentApplies := assessmentApplies + recorded := statedReview chosen + +/- The named normative object and its finite rationale test are deliberately +distinct: a supported rationale experiment is not proof of universal correctness. +The same commitment identifier controls adoption, reasons and reflection. -/ +theorem reviewIdentity (chosen : Candidate) (object : ReviewObject) + (phase : CoreReader.Agency.Phase) : + ((selfModel chosen).input ⟨0, object, phase⟩).target.object = object ∧ + ((selfModel chosen).input ⟨0, object, phase⟩).contract.test = objectTest object ∧ + ((selfModel chosen).input ⟨0, object, phase⟩).requested = requestedCases chosen phase ∧ + ((selfModel chosen).input ⟨0, object, phase⟩).reasons = reviewReasons object phase ∧ + ((selfModel chosen).input ⟨0, object, phase⟩).basis = reviewBasis chosen object phase := + ⟨rfl, rfl, rfl, rfl, rfl⟩ + +theorem currentSelfRecords (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) : + (selfModel chosen).follows := by + rcases ordinary with rfl | rfl + all_goals + intro activity object phase member applies + cases activity <;> cases object <;> cases phase + all_goals first + | rename_i principle; cases principle + | skip + all_goals simp_all [Reflection.interpret, Reflection.Model.input, + Reflection.evaluate, selfModel, statedReview, reviewObjects, coreCommitments, + requestedCases, reviewReasons, criticismFor, objectTest, safeguardExperiment, + generationApplies, assessmentApplies, generationRuleTest, assessmentRuleTest, + ruleProbe, Reflection.generate, + reviewBasis, ReasonRelevant, reasonFor, HasThreat, burdens, ConcreteThreat, cost, + EvolutionPriority, PriorityConditions, JustifiedDeparture, currentContinuing, + Continuing, ActivityScope, Meets, profile, normalRequirements, initialGrounds, + ContinuingCapability, continuingActivity, maintainers, changePath, + changeWork, abstractionComplexity, credible, CredibleDirection, articulateGround, + supportGround, normalLimits, staticBatch, liveBatch, batchCount, orderedUnique, + sortedUnique, sortValues, insertOrdered, List.eraseDups] + all_goals decide + +theorem currentSelfApplication (chosen : Candidate) + (ordinary : chosen = .presentSimple ∨ chosen = .evolvable) : + reflexivitySpecification (selfModel chosen).rules (selfModel chosen).self + (selfModel chosen).performed := + Reflection.recordedReflexivity _ (currentSelfRecords chosen ordinary) + +/- The activity's own assessment method passes its old observation while the +expanded input exposes its actual failed forecast. Neither applying the method +to itself nor generating a broader candidate makes the failed forecast true. -/ +theorem actualSelfCriticism (chosen : Candidate) : + objectTest .evolutionMethod (chosen, 10) = true ∧ + objectTest .evolutionMethod (chosen, 5) = false ∧ + Reflection.evaluate ((selfModel chosen).input ⟨0, .evolutionMethod, .revision⟩) = .counterexample ∧ + statedReview chosen .generation .evolutionMethod .revision = + .generated [(chosen, 10), (chosen, 5)] [(chosen, 10), (chosen, 5)] ∧ + staticBatch 21 5 ≠ liveBatch 21 5 := by + refine ⟨?_, ?_, ?_, rfl, by decide⟩ + · change (staticBatch 21 10 == liveBatch 21 10) = true + decide + · change (staticBatch 21 5 == liveBatch 21 5) = false + decide + · simp [Reflection.evaluate, Reflection.Model.input, selfModel, requestedCases, + objectTest, staticBatch, liveBatch, batchCount] + +/- The objects use the very functions in the adopted rules, and the same +applicability functions. Assessment applies in all three phases; generation +applies to formation and revision, including formation/revision of these rules. -/ +theorem ownRuleIdentity (chosen : Candidate) (activity : CoreReader.Agency.Activity) + (phase : CoreReader.Agency.Phase) : + ruleObject activity ∈ (selfModel chosen).objects ∧ + ((selfModel chosen).rule activity).meaning = Reflection.interpret activity ∧ + ((selfModel chosen).input ⟨0, ruleObject activity, phase⟩).contract.test = + objectTest (ruleObject activity) ∧ + (selfModel chosen).generationApplies (ruleObject activity) phase = + generationApplies (ruleObject activity) phase ∧ + (selfModel chosen).assessmentApplies (ruleObject activity) phase = + assessmentApplies (ruleObject activity) phase := by + refine ⟨?_, rfl, rfl, rfl, rfl⟩ + cases activity <;> simp [ruleObject, selfModel, reviewObjects] + +/- Changing the actual generator changes its object's result despite keeping +the object name. The evaluator really approves an empty initial sample set; +its own revision review reports that bounded defect instead of a self-proof. -/ +theorem ownRuleContentVariation (chosen : Candidate) : + generationRuleTest Reflection.generate (chosen, 10) = true ∧ + generationRuleTest (fun _ => .generated [] []) (chosen, 10) = false ∧ + assessmentRuleTest Reflection.evaluate (chosen, 10) = true ∧ + assessmentRuleTest Reflection.evaluate (chosen, 5) = false ∧ + Reflection.evaluate ((selfModel chosen).input ⟨0, .assessmentRule, .revision⟩) = .counterexample ∧ + generationApplies .generationRule .formation ∧ + generationApplies .generationRule .revision ∧ + ¬ generationApplies .generationRule .application ∧ + (∀ phase, assessmentApplies .assessmentRule phase) := by + simp [generationRuleTest, assessmentRuleTest, ruleProbe, Reflection.generate, + Reflection.evaluate, Reflection.Model.input, selfModel, requestedCases, + objectTest, generationApplies, assessmentApplies] + +theorem proposedRuleRevision (chosen : Candidate) : + assessmentRuleTest Reflection.evaluate (chosen, 5) = false ∧ + assessmentRuleTest sampleAwareAssessment (chosen, 5) = true ∧ + assessmentRuleTest sampleAwareAssessment (chosen, 10) = true ∧ + ((selfModel chosen).rule .generation).applicable ⟨0, .generationRule, .revision⟩ ∧ + ¬ (({ selfModel chosen with generationApplies := fun _ _ => False }).rule .generation).applicable + ⟨0, .generationRule, .revision⟩ := by + simp [assessmentRuleTest, sampleAwareAssessment, ruleProbe, Reflection.evaluate, + Reflection.Model.rule, Reflection.Model.self, selfModel, reviewObjects, + generationApplies] + +end CoreReader.Engineering +``` + + + + **L1** 导入 CoreReader.Engineering.Values,使其声明及传递依赖可用;此行不新增命题。 + + + **L2** 导入 CoreReader.Engineering.Reflection,使其声明及传递依赖可用;此行不新增命题。 + + + **L4** 开启 CoreReader.Engineering 命名空间,后续声明归入其中。 + + + **L6** 允许不带完整限定名引用 CoreReader.Adopted 中的声明;不改变其含义。 + + + **L8** ReviewObject 区分活动、带 Core 原则参数的承诺、优先性和演化方法。 + + + **L9** 在同一对象类型中加入实际生成规则与评估规则对象。 + + + **L10** 自动派生 DecidableEq, Repr:提供这些构造子的可判定相等与可打印表示。 + + + **L12** 检查案例是所选 Candidate 与自然数规模组成的二元组。 + + + **L14** 生成适用性忽略对象身份,仅依赖生命周期阶段。 + + + **L15** 生成恰在 application 以外适用,即形成与修订阶段。 + + + **L17** 评估适用性忽略两个参数,对所有对象、所有阶段均为真。 + + + **L19** 把每种实际活动映射为其对应的方法检查对象。 + + + **L20** 生成活动对应 generationRule。 + + + **L21** 评估活动对应 assessmentRule。 + + + **L23** 注释说明这些探针针对当前反思函数本身,并引入规模 10 案例。 + + + **L24** 注释比较规模 10 的真实初始样本与规模 5 对该样本的移除。 + + + **L25** 注释保留请求主张,并区分此实际规则测试与领域批处理预测器。 + + + **L26** 按活动和候选项、规模二元组,为实际方法构造探针。 + + + **L27** 探针样本类型为 ReviewCase,目标类型为 ReviewObject。 + + + **L28** 所有者固定为 0,阶段固定为修订,对象由活动选取。 + + + **L29** 内层测试恒通过;仅规模 10 提供初始样本,claimed 始终含此案例。 + + + **L30** 即使初始样本列表为空,仍保留此案例为请求案例。 + + + **L31** 提供非空理由,说明范围保留及空初始列表的区分。 + + + **L32** 探针依据为 True;该字段不提供额外经验论证。 + + + **L34** generationRuleTest 测试传入的 method 函数,允许实际替换函数。 + + + **L35** 方法必须把此精确反思输入类型映射到对应结果类型。 + + + **L36** 对给定案例,返回布尔合约结果。 + + + **L37** 为同一案例构造生成探针。 + + + **L38** 要求结果恰等于以 requested 为测试和范围的生成结果。 + + + **L40** assessmentRuleTest 按局部区分样本的合约检查显式传入的评估器。 + + + **L41** 待评估方法接收此精确输入类型并返回 Verdict。 + + + **L42** 每个候选项、规模案例得到布尔通过或失败结果。 + + + **L43** 把实际方法对评估探针的判定与下行期望判定比较。 + + + **L44** 规模 10 期望支持,其余规模期望 noSupportingSample;这是局部合约,不是普遍经验义务。 + + + **L46** 注释介绍加入缺失的空初始列表检查的修订候选。 + + + **L47** 注释明确把候选与当前已安装评估器分开。 + + + **L48** 在同一输入类型上定义独立的评估器修订候选。 + + + **L49** 先对空初始测试列表返回无支持样本,对非空列表再调用当前 evaluate。 + + + **L51** 注释将 evolutionMethod 分支介绍为对此活动自身静态批次数预测的批评。 + + + **L52** 注释比较原规模与可信改变后的运行规模。 + + + **L53** objectTest 按实际检查对象选取操作性布尔测试。 + + + **L54** 匹配对象构造子以选择其特定测试。 + + + **L55** 对活动,判定所选设计指标是否满足当前必要需求。 + + + **L56** 对原则承诺,在所选设计上运行对应的已启用保障实验。 + + + **L57** 对优先性,判定 currentContinuing 中的实际 EvolutionPriority 命题。 + + + **L58** 对演化方法,比较 21 项任务在此规模下的静态与实时批次数预测。 + + + **L59** 对生成规则,把实际 Reflection.generate 函数传入测试。 + + + **L60** 对评估规则,把实际 Reflection.evaluate 函数传入测试。 + + + **L62** 按所选设计构造有限检查对象列表。 + + + **L63** 纳入活动以及五个 Core 承诺,沿用其原有标识。 + + + **L64** 仅在选择 evolvable 时纳入优先性对象。 + + + **L65** 始终纳入批处理方法及两个实际规则对象。 + + + **L67** 请求案例依赖所选设计及生命周期阶段。 + + + **L68** 形成和应用阶段仅请求规模 10。 + + + **L69** 修订阶段将请求列表扩展为同一设计的规模 10 与 5。 + + + **L71** 逐对象、逐阶段构造理由字符串。 + + + **L72** 按实际对象构造子选择第一条理由。 + + + **L73** 活动理由指出其顺序、安全、延迟与保留需求。 + + + **L74** 原则承诺复用由同一原则索引的批评字符串。 + + + **L75** 优先性理由指出证据、维护者路径、需求及成本。 + + + **L76** 方法理由比较同一预测在记录规模与提议运行规模下的结果。 + + + **L77** 生成器理由要求保留请求测试与范围。 + + + **L78** 评估器理由陈述此处对是否存在支持样本的局部要求。 + + + **L79** 返回对象特定理由,再附上阶段特定理由。 + + + **L80** 形成阶段要求辨明对象目的与初始合约条件。 + + + **L81** 应用阶段指出当前所选设计与持续活动。 + + + **L82** 修订阶段要求检查更广输入并保留反例。 + + + **L84** 注释强调 statedReview 的记录独立于 evaluate 定义。 + + + **L85** 注释指出批处理方法修订被明确记录为反例。 + + + **L86** 注释把其他支持记录限于后续证明检查的有限范围。 + + + **L87** statedReview 独立记录给定设计及活动的结果。 + + + **L88** 记录同时依赖对象与阶段,类型为精确的反思结果类型。 + + + **L89** 区分生成记录与评估记录。 + + + **L90** 生成把该阶段的请求列表记录于两个输出字段。 + + + **L91** 评估按对象与阶段选取记录判定,不调用 evaluate。 + + + **L92** 批处理方法或评估规则的修订被明确记录为反例。 + + + **L93** 其余对象、阶段的评估均记录为 supportedWithinScope。 + + + **L95** 注释把 basis 介绍为对象特定事实内容,而非不受限制的批准标记。 + + + **L96** 注释说明反例能支持对同一对象的批评。 + + + **L97** 注释否认这种批评支持能建立方法原本的更广主张。 + + + **L98** reviewBasis 给出对象特定命题;后续为两个普通设计检查证明。 + + + **L99** 活动检查要求实际活动的范围条件。 + + + **L100** 还要求所选指标满足当前必要需求。 + + + **L101** 原则检查要求该同一原则理由对当前选择具有事实相关性。 + + + **L102** 优先性检查要求当前适用条件及 evolvable 不受威胁。 + + + **L103** 修订分支为批处理方法检查提供更强依据。 + + + **L104** 要求规模 10 成功,且规模 5 存在实际不相等。 + + + **L105** 其他批处理方法阶段仅要求规模 10 的相等。 + + + **L106** 生成器依据包含对实际函数内容的正反测试。 + + + **L107** 真实生成器必须在所选设计、规模 10 上通过。 + + + **L108** 输出为空的生成器必须在同一案例上失败。 + + + **L109** 评估规则修订要求两个案例的对比。 + + + **L110** 当前评估器必须在规模 10 上通过局部样本合约测试。 + + + **L111** 它必须在规模 5、初始列表为空时不满足该合约。 + + + **L112** 其他评估规则阶段仅要求规模 10 的正例。 + + + **L114** selfModel 为所选设计以这些案例、对象实例化反思模型。 + + + **L115** 把模型所有者设为 0。独立的 self 关系要求自身目标与之匹配;原始 Model.input 仍可接收并保留任意所有者的目标。 + + + **L116** 采用依赖选择的实际对象列表。 + + + **L117** 每个外层合约采用对应 objectTest,初始测试与声称列表均含规模 10。 + + + **L118** 所有对象共享所选设计的阶段特定 requestedCases。 + + + **L119** 采用实际的对象、阶段理由构造函数。 + + + **L120** 采用实质的对象、阶段依据谓词。 + + + **L121** 安装实际生成适用性函数。 + + + **L122** 安装实际评估适用性函数。 + + + **L123** 采用独立陈述的记录,后续由 currentSelfRecords 验证。 + + + **L125** 注释开始区分实际规范对象与其有限理由实验。 + + + **L126** 注释否认理由实验成功能证明规范普遍正确。 + + + **L127** 注释说明采纳、理由与反思之间预期保持同一标识的连接。 + + + **L128** 对每个设计与对象,reviewIdentity 确认输入各部分的身份。 + + + **L129** 该身份关系对所有生命周期阶段成立。 + + + **L130** 输入的目标对象恰为传入对象。 + + + **L131** 其测试恰为同一对象的 objectTest。 + + + **L132** 其请求列表恰为所选设计在此阶段的列表。 + + + **L133** 其理由恰对应同一对象及阶段。 + + + **L134** 其依据恰为同一设计、对象、阶段的谓词。 + + + **L135** 五项身份均由定义反身性成立,不是经验验证。 + + + **L137** currentSelfRecords 检查所选设计的记录。 + + + **L138** 前提把 chosen 限为 presentSimple 或 evolvable,排除 maximal。 + + + **L139** 结论为 follows,包含每条适用记录的实际解释要求。 + + + **L140** 拆开普通设计前提,分别代入两种设计。 + + + **L141** 将后续证明步骤应用于两个设计目标。 + + + **L142** 引入任意活动、对象、阶段及成员、适用性前提。 + + + **L143** 穷尽活动、对象、阶段的全部构造子。 + + + **L144** 对所有剩余目标,依序尝试下列局部策略。 + + + **L145** 存在承诺参数时,将其命名为 principle 并拆分五种构造子。 + + + **L146** 否则保留目标,不要求存在 principle 参数。 + + + **L147** 用实际解释和输入构造化简全部目标与假设。 + + + **L148** 展开评估器、模型、陈述记录及有限对象列表。 + + + **L149** 展开请求案例、理由、对象测试与保障实验。 + + + **L150** 展开两个适用性谓词与实际规则测试定义。 + + + **L151** 展开内层方法探针及实际生成器。 + + + **L152** 展开依据、相关性以及具体威胁、成本谓词。 + + + **L153** 展开优先性、适用性、偏离与固定当前语境。 + + + **L154** 展开活动范围、必要需求、指标与初始证据。 + + + **L155** 展开持续能力、维护者列表及实际改变路径。 + + + **L156** 展开工作量、复杂度以及所述方向的可信性。 + + + **L157** 展开证据支持、限制、批次数算术与保序输出。 + + + **L158** 展开有限检查所需的排序与去重辅助函数。 + + + **L159** 在分情况与化简后判定所有剩余封闭有限命题。 + + + **L161** currentSelfApplication 为所选设计导出反身性。 + + + **L162** 保留显式的两种普通设计前提。 + + + **L163** 规范采用同一 selfModel 的规则与自身目标谓词。 + + + **L164** 其执行关系也取自同一模型。 + + + **L165** 把实际证明的 currentSelfRecords 作为前提应用通用 recordedReflexivity 定理。 + + + **L167** 注释指出活动的批处理评估方法在旧观测上成功。 + + + **L168** 注释说明扩展输入揭示预测失败,并开始限定自应用的作用。 + + + **L169** 注释否认自应用或生成更广候选会使失败预测变真。 + + + **L170** actualSelfCriticism 对任意设计成立,展示批处理方法的有限失败。 + + + **L171** 旧规模 10 的批处理测试通过。 + + + **L172** 规模 5 的批处理测试失败。 + + + **L173** 实际修订评估器对同一方法对象报告反例。 + + + **L174** 指定该方法修订的独立生成记录。 + + + **L175** 两个生成列表均含同一设计的规模 10 与 5。 + + + **L176** 结论还保留底层批次数预测的不相等。 + + + **L177** 构造五个合取项;生成项由反身性、算术不等由可判定性完成,留下三项检查。 + + + **L178** 把第一证明目标显化为规模 10 的布尔相等测试。 + + + **L179** 计算此封闭的规模 10 相等式。 + + + **L180** 把下一目标显化为规模 5 的布尔测试失败。 + + + **L181** 计算此封闭的规模 5 失败结果。 + + + **L182** 为反例目标展开评估器及实际模型输入。 + + + **L183** 化简对象测试和批次数算术以完成反例计算。 + + + **L185** 注释强调检查对象与已采纳规则实际使用函数的身份一致。 + + + **L186** 注释保留相同适用性函数及全部阶段的评估。 + + + **L187** 注释把生成规则自身的形成、修订纳入生成适用阶段。 + + + **L188** ownRuleIdentity 将每个设计、活动连接到实际规则对象与实现。 + + + **L189** 连接对所有阶段陈述,无论生成是否在那里适用。 + + + **L190** 该活动的方法对象实际属于模型对象列表。 + + + **L191** 模型规则含义恰为实际 interpret activity 函数。 + + + **L192** 同一规则对象的输入取得其实际合约测试。 + + + **L193** 该测试为按此相同方法对象索引的 objectTest。 + + + **L194** 比较模型在此对象、阶段的生成适用性。 + + + **L195** 它等于声明的 generationApplies 对同一参数的值。 + + + **L196** 比较模型在此对象、阶段的评估适用性。 + + + **L197** 它等于 assessmentApplies 对这些相同参数的值。 + + + **L198** 四个函数、字段相等由反身性完成,仅留下实际对象成员资格。 + + + **L199** 拆分活动并计算实际检查对象列表中的成员资格。 + + + **L201** 注释说明即使对象名称不变,替换生成器内容仍会改变结果。 + + + **L202** 注释记录实际评估器在初始样本为空时接受;请求案例仍受检查。 + + + **L203** 注释把外层自身检查界定为报告这一有界局部合约缺陷,而非证明自身普遍有效。 + + + **L204** ownRuleContentVariation 为每个设计提供对函数内容敏感的正反案例。 + + + **L205** 当前生成器通过规模 10 的保留测试。 + + + **L206** 输出为空的生成器未通过同一测试。 + + + **L207** 当前评估器在有规模 10 样本时通过局部样本合约。 + + + **L208** 它在规模 5、初始样本列表为空时未满足该合约。 + + + **L209** 实际评估规则对象的外层修订评估报告反例。 + + + **L210** 生成适用于自身规则对象的形成。 + + + **L211** 它也适用于自身规则对象的修订。 + + + **L212** 生成不适用于该对象的应用阶段。 + + + **L213** 评估对自身规则对象在每个阶段均适用。 + + + **L214** 在各合取项中展开实际方法测试、探针与生成器。 + + + **L215** 展开评估器、实际输入、模型与请求案例。 + + + **L216** 化简对象测试及两个适用性谓词,完成有限检查。 + + + **L218** proposedRuleRevision 比较当前与候选评估器,并检查一次适用性变更。 + + + **L219** 当前评估器不满足局部空初始样本合约。 + + + **L220** 独立的 sampleAwareAssessment 候选通过该规模 5 合约。 + + + **L221** 候选也保留规模 10 的正例结果。 + + + **L222** 当前生成规则适用于自身生成规则对象的修订。 + + + **L223** 另一个将 generationApplies 改为恒假的模型更新消除了此适用性。 + + + **L224** 被消除的适用性恰针对所有者 0、generationRule 与修订阶段。 + + + **L225** 展开局部测试、候选评估器、探针与当前评估器。 + + + **L226** 展开实际规则、自身目标语义与模型对象成员资格。 + + + **L227** 化简生成适用性完成合取;此处未安装任一候选变更。 + + + **L229** 关闭 CoreReader.Engineering 命名空间;不另行断言数学主张。 + + +### `leanified/CoreReader/Engineering/Values.lean` + + +```lean +import CoreReader.Adopted +import CoreReader.Engineering.Domain + +namespace CoreReader.Engineering + +open CoreReader.Logic CoreReader.Evidence CoreReader.Adopted + +inductive CoreCommitment | generation | consistency | reflexivity | grounds | choice + deriving DecidableEq, Repr + +def coreCommitments : List CoreCommitment := + [.generation, .consistency, .reflexivity, .grounds, .choice] + +/- Initial adoption is explicit. The following reasons neither infer adoption +from facts nor claim that every alternative value position is untenable. -/ +def coreAdopted (_ : CoreCommitment) : Bool := true + +inductive AdoptionReason + | plannedChange (release : Nat) (direction : Change) + | incompatibleOrders (input : List Nat) + | ownMethodCounterexample (items size : Nat) + | unsupportedScope (items observedSize extendedSize : Nat) + | statusBudgetContrast (statusSelected : Candidate) (capacity : Nat) + deriving DecidableEq, Repr + +def reasonFor : CoreCommitment → AdoptionReason + | .generation => .plannedChange 2 .designRevision + | .consistency => .incompatibleOrders [2, 1, 2] + | .reflexivity => .ownMethodCounterexample 21 5 + | .grounds => .unsupportedScope 21 10 5 + | .choice => .statusBudgetContrast .maximal 12 + +/- Each factual reason has contents specific to the principle's purpose. The +context is the very continuing activity and its current requirements/grounds. +Matching a constructor alone is insufficient: the represented facts must hold. -/ +abbrev ReasonRelevant : CoreCommitment → AdoptionReason → Candidate → Prop + | .generation, .plannedChange release direction, _ => + DirectionGround.plan release [direction, .migration] ∈ currentContinuing.evidence ∧ + credible currentContinuing.evidence direction ∧ Continuing currentContinuing.activity + | .consistency, .incompatibleOrders input, _ => + currentContinuing.required.orderRequired = true ∧ + orderedUnique input ≠ sortedUnique input + | .reflexivity, .ownMethodCounterexample items size, _ => + staticBatch items 10 = liveBatch items 10 ∧ staticBatch items size ≠ liveBatch items size + | .grounds, .unsupportedScope items observedSize extendedSize, _ => + staticBatch items observedSize = liveBatch items observedSize ∧ + staticBatch items extendedSize ≠ liveBatch items extendedSize + | .choice, .statusBudgetContrast candidate capacity, selected => + capacity = currentContinuing.limits.capacity .understanding ∧ + capacity < abstractionComplexity candidate ∧ abstractionComplexity selected ≤ capacity + | _, _, _ => False + +abbrev valueScope (selected : Candidate) : Prop := abstractionComplexity selected ≤ 3 + +/- A small operational experiment explains each adopted safeguard's purpose. +These consequences are limited to the stated experiment, not a total value score. +The disabled branch supplies a real contrast for this application policy. -/ +def safeguardExperiment (principle : CoreCommitment) (enabled : Bool) + (selected : Candidate) : Bool := + match principle with + | .generation => + let allowed : List Change := if enabled then [.designRevision, .migration] else [] + allowed.contains .designRevision && decide (credible currentContinuing.evidence .designRevision) + | .consistency => + let firstDemand := orderedUnique [2, 1, 2] + let secondDemand := sortedUnique [2, 1, 2] + let permitsBoth := if enabled then firstDemand == secondDemand else true + !permitsBoth + | .reflexivity => + let selfTests := if enabled then [(21, 10), (21, 5)] else [(21, 10)] + selfTests.any (fun point => staticBatch point.1 point.2 != liveBatch point.1 point.2) + | .grounds => + let licensed := if enabled then [10] else [10, 5] + licensed.all (fun size => staticBatch 21 size == liveBatch 21 size) + | .choice => + let selectedByRule := if enabled then selected else .maximal + decide (abstractionComplexity selectedByRule ≤ currentContinuing.limits.capacity .understanding) + +def criticismFor : CoreCommitment → String + | .generation => "Reconsider this reason if the committed change or continuing maintenance ends." + | .consistency => "Reconsider the comparison if the parties deliberately revise the observable order contract." + | .reflexivity => "This counterexample concerns the stated batch rule; it does not validate all self-assessment." + | .grounds => "A new input condition requires its own support; success at size ten does not cover size five." + | .choice => "If objectives or budgets change, compare the actual alternatives and reasons again." + +def governancePosition (principle : CoreCommitment) : ValuePosition Candidate where + Position := Bool + Outcome := Bool + adopted := true + selected _ := coreAdopted principle + outcome selected enabled := safeguardExperiment principle enabled selected + objective result := result = true + constraints selected _ := valueScope selected + starting := singleton valueScope + reasons := [fun selected _ => ReasonRelevant principle (reasonFor principle) selected] + limits := valueScope + relevantCriticism _ := True + response _ := some (criticismFor principle) + +theorem adoptionReasonRelevant (principle : CoreCommitment) (selected : Candidate) + (scope : valueScope selected) : ReasonRelevant principle (reasonFor principle) selected := by + cases principle + · dsimp only [ReasonRelevant, reasonFor]; decide + · dsimp only [ReasonRelevant, reasonFor]; decide + · dsimp only [ReasonRelevant, reasonFor]; decide + · dsimp only [ReasonRelevant, reasonFor]; decide + · refine ⟨rfl, by decide, ?_⟩ + exact Nat.le_trans scope (by decide) + +theorem safeguardEnabled (principle : CoreCommitment) (selected : Candidate) + (scope : valueScope selected) : safeguardExperiment principle true selected = true := by + cases principle + · dsimp only [safeguardExperiment]; decide + · dsimp only [safeguardExperiment]; decide + · dsimp only [safeguardExperiment]; decide + · dsimp only [safeguardExperiment]; decide + · apply decide_eq_true + exact Nat.le_trans scope (by change 3 ≤ 12; decide) + +theorem safeguardDisabled (principle : CoreCommitment) (selected : Candidate) : + safeguardExperiment principle false selected = false := by + cases principle <;> simp only [safeguardExperiment, Bool.false_eq_true, ↓reduceIte] <;> decide + +theorem governanceValueProcedure (principle : CoreCommitment) : + ValueProcedure (governancePosition principle) := by + refine ⟨by simp [governancePosition], ?_, ?_, ?_⟩ + · refine ⟨.evolvable, (modelsSingleton _ _).2 (by change 3 ≤ 3; decide), + (by change 3 ≤ 3; decide), rfl, ?_⟩ + intro reason member + cases List.mem_singleton.mp member + exact adoptionReasonRelevant principle .evolvable (by change 3 ≤ 3; decide) + · intro selected _ scope _ + exact ⟨safeguardEnabled principle selected scope, scope⟩ + · intro selected _ _ + exact ⟨criticismFor principle, rfl, by cases principle <;> decide⟩ + +theorem governanceGrounded (principle : CoreCommitment) : + valueSpecification (governancePosition principle) := + grounds012Singleton _ (governanceValueProcedure principle) + +/- Factual relevance, rationale experiments and value adoption are separate. +Swapping a reason or altering the input makes the finite rationale fail. -/ +theorem governanceRationaleLimits : + ¬ ReasonRelevant .consistency (reasonFor .generation) .evolvable ∧ + ¬ ReasonRelevant .reflexivity (.ownMethodCounterexample 21 10) .evolvable ∧ + ¬ ReasonRelevant .generation (.plannedChange 9 .addition) .evolvable ∧ + ¬ valueScope .maximal ∧ + (∀ principle, safeguardExperiment principle false .evolvable = false) ∧ + (∀ principle, (governancePosition principle).commitment .presentSimple) := by + refine ⟨by change ¬ False; decide, by decide, by decide, by change ¬ (30 ≤ 3); decide, + fun principle => safeguardDisabled principle .evolvable, fun _ => rfl⟩ + +/- This additional value priority is a real selection between the same designs. +Both scopes retain all necessary domain conditions and no cost exception. +The present-simple stance values less abstraction now without claiming that it +has the better successor-maintainer capability. The other stance values that capability. -/ +def selectionObjective (adopted : Candidate) (outcome : Nat × Nat) : Prop := + match adopted with + | .presentSimple => outcome.1 ≤ 1 + | .evolvable => outcome.2 ≤ 6 + | .maximal => outcome.1 ≤ 1 + +def selectionPosition (adopted : Candidate) : ValuePosition Candidate where + Position := Candidate + Outcome := Nat × Nat + adopted := adopted + selected := id + outcome _ candidate := (abstractionComplexity candidate, changeWork candidate .designRevision) + objective := selectionObjective adopted + constraints _ candidate := abstractionComplexity candidate ≤ currentContinuing.limits.capacity .understanding + starting := singleton (fun candidate => candidate = adopted) + reasons := [fun _ candidate => + abstractionComplexity candidate = (if adopted = .presentSimple then 1 else 3) ∧ + changeWork candidate .designRevision = (if adopted = .presentSimple then 17 else 6)] + limits _ := Continuing currentContinuing.activity ∧ + credible currentContinuing.evidence .designRevision + relevantCriticism _ := True + response _ := some (if adopted = .presentSimple then + "The successor lacks the private-layout path; this choice does not claim evolution priority and must be reconsidered if that value is adopted." + else "The six-step design-revision path does not establish every change is cheap or every forecast is correct.") + +theorem selectionValueProcedure (adopted : Candidate) + (ordinary : adopted = .presentSimple ∨ adopted = .evolvable) : + ValueProcedure (selectionPosition adopted) := by + rcases ordinary with rfl | rfl + · refine ⟨by simp [selectionPosition], ?_, ?_, ?_⟩ + · refine ⟨.presentSimple, (modelsSingleton _ _).2 rfl, ?_, rfl, ?_⟩ + · change Continuing currentContinuing.activity ∧ credible currentContinuing.evidence .designRevision + decide + · intro reason member + cases List.mem_singleton.mp member + decide + · intro selected _ _ allReasons + have actual := allReasons _ (List.mem_singleton.mpr rfl) + change abstractionComplexity .presentSimple = 1 ∧ changeWork .presentSimple .designRevision = 17 at actual + change abstractionComplexity .presentSimple ≤ 1 ∧ + abstractionComplexity .presentSimple ≤ currentContinuing.limits.capacity .understanding + exact ⟨by rw [actual.1]; exact Nat.le_refl _, by rw [actual.1]; decide⟩ + · intro selected _ _ + refine ⟨_, rfl, ?_⟩ + simp + · refine ⟨by simp [selectionPosition], ?_, ?_, ?_⟩ + · refine ⟨.evolvable, (modelsSingleton _ _).2 rfl, ?_, rfl, ?_⟩ + · change Continuing currentContinuing.activity ∧ credible currentContinuing.evidence .designRevision + decide + · intro reason member + cases List.mem_singleton.mp member + decide + · intro selected _ _ allReasons + have actual := allReasons _ (List.mem_singleton.mpr rfl) + change abstractionComplexity .evolvable = 3 ∧ changeWork .evolvable .designRevision = 6 at actual + change changeWork .evolvable .designRevision ≤ 6 ∧ + abstractionComplexity .evolvable ≤ currentContinuing.limits.capacity .understanding + exact ⟨by rw [actual.2]; exact Nat.le_refl _, by rw [actual.1]; decide⟩ + · intro selected _ _ + refine ⟨_, rfl, ?_⟩ + simp + +theorem selectionGrounded (adopted : Candidate) + (ordinary : adopted = .presentSimple ∨ adopted = .evolvable) : + valueSpecification (selectionPosition adopted) := + grounds012Singleton _ (selectionValueProcedure adopted ordinary) + +end CoreReader.Engineering +``` + + + + **L1** 导入 CoreReader.Adopted,使其声明及传递依赖可用;此行不新增命题。 + + + **L2** 导入 CoreReader.Engineering.Domain,使其声明及传递依赖可用;此行不新增命题。 + + + **L4** 开启 CoreReader.Engineering 命名空间,后续声明归入其中。 + + + **L6** 允许不带完整限定名引用 CoreReader.Logic CoreReader.Evidence CoreReader.Adopted 中的声明;不改变其含义。 + + + **L8** 定义生成、一致性、反身性、依据与选择五个 Core 承诺标识。 + + + **L9** 自动派生 DecidableEq, Repr:提供这些构造子的可判定相等与可打印表示。 + + + **L11** coreCommitments 是全部已表示承诺标识的有限列表。 + + + **L12** 按显示顺序各列出五个构造子一次。 + + + **L14** 注释指出采纳是明确起始选择;理由不推导采纳本身。 + + + **L15** 注释既不从事实推导采纳,也不声称所有替代价值均不可成立。 + + + **L16** 每个承诺都被明确标记为已采纳;此布尔选择不是从事实前提推导的。 + + + **L18** AdoptionReason 是具体理由数据的类型族,本身不是证明。 + + + **L19** plannedChange 记录自然数版本与 Change 方向。 + + + **L20** incompatibleOrders 保存用于比较输出顺序的实际输入列表。 + + + **L21** ownMethodCounterexample 保存项目数与运行规模。 + + + **L22** unsupportedScope 对固定项目数区分观测规模与扩展规模。 + + + **L23** statusBudgetContrast 记录按地位选出的候选项与自然数容量。 + + + **L24** 自动派生 DecidableEq, Repr:提供这些构造子的可判定相等与可打印表示。 + + + **L26** 为每个 Core 承诺分配一个具体理由值。 + + + **L27** 生成为计划版本 2 与 designRevision。 + + + **L28** 一致性使用顺序敏感输入 [2, 1, 2]。 + + + **L29** 反身性使用 21 项与运行规模 5。 + + + **L30** 依据比较 21 项在规模 10 的观测与规模 5 的扩展。 + + + **L31** 选择将 maximal 与理解容量 12 比较。 + + + **L33** 注释介绍针对各原则目的的事实理由。 + + + **L34** 注释将理由语境固定为此持续活动及实际需求、证据。 + + + **L35** 注释要求实际理由内容成立,不能仅匹配构造子名称。 + + + **L36** ReasonRelevant 是原则、结构化理由及所选设计上的命题,检查实际理由内容。 + + + **L37** 对生成及计划改变理由,此分支不依赖所选设计。 + + + **L38** 包含该方向与迁移的精确版本计划必须出现在当前证据中。 + + + **L39** 该方向必须可信,且当前活动必须持续。 + + + **L40** 对一致性,使用不兼容顺序理由中携带的输入。 + + + **L41** 实际当前需求必须要求保持顺序。 + + + **L42** 保序去重与排序去重必须在此输入上不同。 + + + **L43** 对反身性,使用理由中的项目数与受质疑规模。 + + + **L44** 要求旧规模 10 一致,而受质疑规模不一致。 + + + **L45** 对依据,比较理由中的观测规模与扩展规模。 + + + **L46** 静态与实时预测必须在观测规模一致。 + + + **L47** 它们必须在提议的扩展规模不一致。 + + + **L48** 对选择,区分受比较的候选项与实际所选设计。 + + + **L49** 所述容量必须等于当前理解容量。 + + + **L50** 受比较候选项超出容量,而实际选择不超出容量。 + + + **L51** 任何不匹配的原则、理由构造子组合均返回 False。 + + + **L53** 价值程序披露的范围为抽象复杂度不超过 3 的设计。 + + + **L55** 注释介绍解释每项保障目的的小型操作实验。 + + + **L56** 注释将后果限于该实验,排除综合价值评分。 + + + **L57** 注释指出禁用分支是此应用政策内的实际对照。 + + + **L58** safeguardExperiment 改变指定保障的启用布尔值。 + + + **L59** 它还接收实际所选设计,并返回操作性布尔结果。 + + + **L60** 按原则选择实验;这不是综合价值度量。 + + + **L61** 生成分支衡量可信计划改变是否可用。 + + + **L62** 启用时允许 designRevision 与 migration,禁用时允许列表为空。 + + + **L63** 仅当 designRevision 被允许且当前可信时通过。 + + + **L64** 一致性分支衡量是否拒绝不兼容的同时要求。 + + + **L65** 以保序去重计算第一个要求。 + + + **L66** 以排序去重在同一输入上计算第二个要求。 + + + **L67** 启用检查仅在两个要求相等时同时允许;禁用则无条件同时允许。 + + + **L68** 拒绝同时允许时,此实验成功。 + + + **L69** 反身性分支对实际批次数预测进行自身测试。 + + + **L70** 启用时包含旧规模及受质疑规模;禁用时仅保留旧规模。 + + + **L71** 某个已列案例的静态与实时预测不等时通过。 + + + **L72** 依据分支测试获许可的输入范围。 + + + **L73** 启用时仅许可规模 10;禁用时把许可扩展为 10 与 5。 + + + **L74** 固定项目数 21,要求每个获许可规模的预测相等。 + + + **L75** 选择分支衡量是否符合理解容量。 + + + **L76** 启用时选传入设计;禁用保障时选 maximal。 + + + **L77** 判定规则实际选出的设计是否符合当前理解容量。 + + + **L79** 为每个原则分配可修订性、批评回应字符串。 + + + **L80** 生成回应把已承诺改变或持续维护的终止列为重新考虑条件。 + + + **L81** 一致性回应允许在有意修订顺序合约后重新考虑比较。 + + + **L82** 反身性回应把反例限于此批处理规则,不推广到全部自评估。 + + + **L83** 依据回应拒绝在没有各自支持时把规模 10 的成功扩展到规模 5。 + + + **L84** 选择回应要求在目标或预算变化时重新比较。 + + + **L86** 对一个原则,构造 Candidate 上的 ValuePosition,明确采纳及有界支持理由。 + + + **L87** 价值立场的备选项为启用、禁用布尔状态。 + + + **L88** 实验结果类型为 Bool。 + + + **L89** 明确采纳启用的价值立场。 + + + **L90** 对每个设计,所选立场为该原则的采纳标记。 + + + **L91** 结果以设计与启用立场运行同一原则的实验。 + + + **L92** 目标是实验成功,以 true 表示。 + + + **L93** 无论布尔立场如何,约束均要求设计满足 valueScope。 + + + **L94** 起始理论仅含 valueScope 命题。 + + + **L95** 唯一理由要求对同一原则、所选设计具有实际相关性。 + + + **L96** 应用限制同样为 valueScope。 + + + **L97** 所有 Candidate 值均视为相关批评;未编码更窄过滤。 + + + **L98** 每项批评均得到该原则的固定回应字符串。 + + + **L100** 为范围内的每个原则与所选设计证明理由相关性。 + + + **L101** 前提把所选复杂度限制到 3;结论采用其精确 reasonFor 值。 + + + **L102** 拆分五种原则构造子。 + + + **L103** 对生成,展开理由内容并计算计划成员资格、可信性与持续性。 + + + **L104** 对一致性,展开并计算顺序要求及不同输出。 + + + **L105** 对反身性,展开并计算旧规模成功与受质疑预测失败。 + + + **L106** 对依据,展开并计算观测相等与扩展不等。 + + + **L107** 对选择,证明容量身份与 maximal 超限,留下所选设计的界限。 + + + **L108** 把所选复杂度 ≤ 3 与 3 ≤ 12 传递组合,得到所需界限。 + + + **L110** 证明披露范围内每个原则的已启用实验均成功。 + + + **L111** 保留范围前提,并陈述实际布尔值等于 true。 + + + **L112** 按五个原则分情况计算各自不同的实验。 + + + **L113** 对生成,展开启用的改变列表并判定可信性测试。 + + + **L114** 对一致性,展开启用的比较并判定对不兼容要求的拒绝。 + + + **L115** 对反身性,展开两个测试并判定存在失败预测。 + + + **L116** 对依据,展开获许可规模 10 列表并判定测试成功。 + + + **L117** 把选择实验的布尔结果转为底层容量命题。 + + + **L118** 利用范围及计算得到的 3 ≤ 12 证明该容量命题。 + + + **L120** 禁用保障对每个原则、所选设计均失败,无需范围前提。 + + + **L121** 以计算出的实验值恰等于 false 陈述失败。 + + + **L122** 拆分原则,化简禁用分支并判定五个有限结果。 + + + **L124** 逐原则验证实际治理价值程序。 + + + **L125** 目标是同一 governancePosition 的 ValueProcedure。 + + + **L126** 构造非空理由,留下相容性、目标与约束、回应义务。 + + + **L127** 选择 evolvable 为起始理论见证,并证明其满足单元素范围理论。 + + + **L128** 证明其应用限制及选择身份,留下理由有效性。 + + + **L129** 引入属于该立场理由列表的任意理由。 + + + **L130** 单元素成员资格将其确定为实际相关性理由。 + + + **L131** 在 evolvable 的复杂度界 3 ≤ 3 上应用已证相关性定理。 + + + **L132** 对程序前提下的任意设计,保留其范围证明。 + + + **L133** 以已启用实验成功及同一范围证明满足目标和约束。 + + + **L134** 在回应前提下引入任意批评案例。 + + + **L135** 提供固定批评回应、其存储身份及由有限分情况证明的非空性。 + + + **L137** governanceGrounded 为每个已表示原则的价值承诺提供依据。 + + + **L138** 结论为精确治理立场的 valueSpecification。 + + + **L139** 把已验证 ValueProcedure 包装进采纳版 Core 0.1.2 的单元素依据构造。 + + + **L141** 注释区分事实相关性、理由实验与价值采纳。 + + + **L142** 注释引入通过替换理由或改变输入得到的失败案例。 + + + **L143** governanceRationaleLimits 展示实际失败,并区分支持与采纳。 + + + **L144** 生成理由因构造子不匹配而不相关于一致性。 + + + **L145** 规模 10 的所谓自身反例失败,因为旧预测在那里一致。 + + + **L146** 未支持的版本 9 新增计划不满足生成理由要求。 + + + **L147** maximal 位于复杂度不超过 3 的价值范围以外。 + + + **L148** 每个禁用保障实验在 evolvable 上均失败。 + + + **L149** 与此同时,每个治理承诺在 presentSimple 上也被采纳。 + + + **L150** 计算三个理由不相关案例及 maximal 的 30 > 3 范围失败。 + + + **L151** 逐原则使用 safeguardDisabled,最后的全称采纳项由身份反身性成立。 + + + **L153** 注释把附加价值优先性表述为在相同设计之间的实际选择。 + + + **L154** 注释指出共同语境的必要条件及无成本例外;下文 limits 字段显式检查持续性与可信性。 + + + **L155** 注释说明简单立场重视较低的当前抽象,并开始限定其能力主张。 + + + **L156** 注释不为简单立场声称更强继任者能力,而把该目标归于另一立场。 + + + **L157** selectionObjective 把所采纳设计及复杂度、工作量二元组映射到其选定目标命题。 + + + **L158** 目标随明确采纳的候选项改变。 + + + **L159** presentSimple 重视当前抽象复杂度不超过 1。 + + + **L160** evolvable 重视设计修订工作量不超过 6。 + + + **L161** maximal 分支也使用复杂度不超过 1;下文不证明 maximal 的程序成功。 + + + **L163** 以所采纳候选项为参数构造独立的选择 ValuePosition。 + + + **L164** 其备选立场为实际 Candidate 设计。 + + + **L165** 结果是复杂度与修订工作量组成的自然数对。 + + + **L166** 直接保存传入的已采纳候选项。 + + + **L167** 每个世界的所选立场就是自身,由恒等函数给出。 + + + **L168** 衡量所选立场的复杂度与实际 designRevision 工作量。 + + + **L169** 采用由已采纳设计索引的目标。 + + + **L170** 以实际理解容量约束该立场的复杂度。 + + + **L171** 起始理论要求世界等于已采纳设计。 + + + **L172** 仅有一个理由函数,忽略世界参数并检查立场。 + + + **L173** 采纳 presentSimple 时要求复杂度 1,否则要求复杂度 3。 + + + **L174** 采纳 presentSimple 时要求修订工作量 17,否则为 6。 + + + **L175** 程序限制要求当前活动持续。 + + + **L176** 还要求实际证据中 designRevision 可信。 + + + **L177** 每个候选项都视为相关批评。 + + + **L178** 每项批评均得到按是否采纳 presentSimple 选取的回应。 + + + **L179** 简单设计回应承认继任者缺少私有布局路径,并说明不主张演化优先性。 + + + **L180** 可演化回应限制六步结果的范围,不据此断言所有改变低成本或预测正确。 + + + **L182** 验证某个已采纳候选项的选择价值程序。 + + + **L183** 假设采纳的是两种普通设计之一。 + + + **L184** 结论为该采纳的实际 ValueProcedure。 + + + **L185** 拆分并代入 presentSimple 与 evolvable 两种采纳。 + + + **L186** 对 presentSimple,证明理由非空并留下三个实质程序义务。 + + + **L187** 选择 presentSimple 本身作为相容见证,以反身性完成选择身份。 + + + **L188** 把见证限制显化为实际持续性及可信 designRevision。 + + + **L189** 计算这些固定语境事实。 + + + **L190** 引入简单立场单元素列表中的理由。 + + + **L191** 把该理由替换为唯一成员。 + + + **L192** 计算简单设计复杂度 1 及修订工作量 17。 + + + **L193** 引入任意程序前提,为简单采纳保留 allReasons。 + + + **L194** 从 allReasons 提取实际唯一理由。 + + + **L195** 把理由显化为已采纳 presentSimple 的复杂度 1、工作量 17 两个具体等式。 + + + **L196** 把简单设计目标显化为复杂度不超过 1。 + + + **L197** 第二个合取项为同一设计的理解容量约束。 + + + **L198** 按实际复杂度等式重写,目标由 ≤ 反身性、容量由计算完成。 + + + **L199** 对任意相关批评进入简单设计回应义务。 + + + **L200** 选择已存回应及其反身等式,留下非空性。 + + + **L201** 化简固定回应以证明非空。 + + + **L202** 对 evolvable,证明理由非空并留下同样三个程序义务。 + + + **L203** 选择 evolvable 本身作为相容见证,并以反身性证明选择身份。 + + + **L204** 显化可演化见证的持续性及可信修订限制。 + + + **L205** 在 currentContinuing 中计算这些限制。 + + + **L206** 引入可演化立场单元素理由列表中的理由。 + + + **L207** 将其确定为唯一实际理由。 + + + **L208** 计算可演化设计复杂度 3 及修订工作量 6。 + + + **L209** 引入可演化立场的程序前提,保留 allReasons。 + + + **L210** 从此前提提取唯一实质理由。 + + + **L211** 显化已采纳可演化立场的复杂度 3 与 designRevision 工作量 6。 + + + **L212** 把可演化目标显化为工作量不超过 6。 + + + **L213** 保留对同一设计的实际理解容量约束。 + + + **L214** 以工作量等式完成目标,以复杂度等式完成容量检查。 + + + **L215** 对任意相关批评进入可演化回应义务。 + + + **L216** 选择已存可演化回应,留下其非空性。 + + + **L217** 化简回应字符串以证明非空。 + + + **L219** selectionGrounded 为所采纳选择包装价值依据。 + + + **L220** 两种普通设计的假设仍然显式保留。 + + + **L221** 结论恰针对 selectionPosition adopted。 + + + **L222** 以已证明的选择程序作为已履行的单元素价值面向。 + + + **L224** 关闭 CoreReader.Engineering 命名空间;不另行断言数学主张。 + + +### `leanified/CoreReader/Evidence.lean` + + +```lean +import CoreReader.Logic +import CoreReader.Agency + +namespace CoreReader.Evidence +open CoreReader.Logic +open CoreReader.Agency + +/- An observation records the outcome of a specified test on the represented world. -/ +structure Record (W : Type) where + test : W → Bool + observed : Bool +/- Compatible worlds reproduce the actual contents of every recorded observation. -/ +def Compatible {W : Type} (records : List (Record W)) (w : W) : Prop := + ∀ r, r ∈ records → r.test w = r.observed +/- Inferential support requires the same claim in every evidence-compatible world. -/ +def Supports {W : Type} (records : List (Record W)) (claim : Claim W) : Prop := + ∀ w, Compatible records w → claim w +/- Articulation identifies concepts, premises, reason contents and an application limit. -/ +structure Articulation (W : Type) where + concepts : List String + assumptions : Theory W + reasons : List (Claim W) + limits : Claim W +/- Nonempty identifiable concepts and reasons are procedural articulation requirements. -/ +def Articulated {W : Type} (a : Articulation W) : Prop := + a.concepts ≠ [] ∧ a.reasons ≠ [] +/- This application model interprets an adopted option through its actual outcomes and stated goals/constraints. -/ +structure ValuePosition (W : Type) where + Position : Type + Outcome : Type + adopted : Position + selected : W → Position + outcome : W → Position → Outcome + objective : Outcome → Prop + constraints : W → Position → Prop + starting : Theory W + reasons : List (W → Position → Prop) + limits : Claim W + relevantCriticism : Claim W + response : W → Option String +/- The adopted position's claim is derived from the same selected option used by the outcome interpretation. -/ +def ValuePosition.commitment {W : Type} (v : ValuePosition W) : Claim W := + fun w => v.selected w = v.adopted +/- Assessed consequences concern this adopted option's actual outcome, objective and constraints. -/ +def ValuePosition.consequence {W : Type} (v : ValuePosition W) : Claim W := + fun w => v.objective (v.outcome w v.adopted) ∧ v.constraints w v.adopted +/- Articulated reasons specialize the actual option-indexed premises to the adopted option. -/ +def ValuePosition.activeReasons {W : Type} (v : ValuePosition W) : List (Claim W) := + v.reasons.map (fun reason w => reason w v.adopted) +/- A joint witness excludes inconsistent starts and impossible adoption states. -/ +def JointAdoption {W : Type} (v : ValuePosition W) : Prop := + ∃ w, Models v.starting w ∧ v.limits w ∧ v.commitment w ∧ + ∀ reason, reason ∈ v.reasons → reason w v.adopted +/- This declared option/outcome adapter checks joint reasons for an assessed consequence; it is not a necessary deductive form for all value justification. -/ +def ValueProcedure {W : Type} (v : ValuePosition W) : Prop := + v.reasons ≠ [] ∧ JointAdoption v ∧ + (∀ w, Models v.starting w → v.limits w → + (∀ reason, reason ∈ v.reasons → reason w v.adopted) → v.consequence w) ∧ + (∀ w, v.limits w → v.relevantCriticism w → ∃ answer, v.response w = some answer ∧ answer ≠ "") +/- A facet carries its specific contents; several different facets can have the same conclusion. -/ +inductive Facet (W : Type) where + | empirical (records : List (Record W)) (scope conclusion uncertainty : Claim W) + | inferential (assumptions : Theory W) (conclusion : Claim W) + | value (position : ValuePosition W) +/- The claim referred to by each assessment facet is explicit. -/ +def Facet.claim {W : Type} : Facet W → Claim W + | .empirical _ _ p _ => p + | .inferential _ p => p + | .value v => v.commitment +/- These disclosed semantic adapters implement selected nature-specific checks; passing them does not establish all real empirical or value adequacy. -/ +def FacetDischarged {W : Type} : Facet W → Prop + | .empirical records scope p uncertainty => + (∃ w, Compatible records w ∧ scope w) ∧ + Supports records (fun w => scope w → p w) ∧ Supports records uncertainty + | .inferential assumptions p => Satisfiable assumptions ∧ Entails assumptions p + | .value v => ValueProcedure v +/- This model's semantic adapter identifies the actual assumptions, reason content and limit of a facet. -/ +def FacetArticulated {W : Type} (a : Articulation W) : Facet W → Prop + | .empirical records scope _ _ => + a.assumptions = singleton (Compatible records) ∧ a.reasons = [Compatible records] ∧ a.limits = scope + | .inferential assumptions _ => + a.assumptions = assumptions ∧ a.reasons = [Models assumptions] ∧ a.limits = (fun _ => True) + | .value v => a.assumptions = v.starting ∧ a.reasons = v.activeReasons ∧ a.limits = v.limits +/- A canonical articulation exposes this adapter; the source does not mandate this particular representation of grounds. -/ +def canonicalArticulation {W : Type} : Facet W → Articulation W + | .empirical records scope _ _ => + ⟨["recorded test outcomes", "observation conditions"], singleton (Compatible records), [Compatible records], scope⟩ + | .inferential assumptions _ => + ⟨["stated assumptions", "semantic consequence"], assumptions, [Models assumptions], fun _ => True⟩ + | .value v => + ⟨["adopted position", "reasons and consequences"], v.starting, v.activeReasons, v.limits⟩ +/- Canonical articulation is connected to the very facet whose grounds it identifies. -/ +theorem canonicalFacetArticulated {W : Type} (f : Facet W) : + FacetArticulated (canonicalArticulation f) f := by + cases f <;> exact ⟨rfl, rfl, rfl⟩ +/- A discharged facet has nonempty canonical reason articulation, including the value procedure's reason requirement. -/ +theorem canonicalArticulated {W : Type} (f : Facet W) (h : FacetDischarged f) : + Articulated (canonicalArticulation f) := by + cases f with + | empirical records scope p uncertainty => simp [Articulated, canonicalArticulation] + | inferential assumptions p => simp [Articulated, canonicalArticulation] + | value v => + refine ⟨by simp [canonicalArticulation], ?_⟩ + simpa [canonicalArticulation, ValuePosition.activeReasons] using h.1 +/- This model of the Grounds obligation binds each actual facet to its claim and articulation. Its disclosed FacetDischarged adapters do not replace all source-level assessment responsibilities or prove real adequacy. -/ +def Grounds {W : Type} (claim : Claim W) (articulations : Facet W → Articulation W) + (actualApplicable : Facet W → Prop) (facets : List (Facet W)) : Prop := + facets ≠ [] ∧ (∀ facet, actualApplicable facet → facet ∈ facets) ∧ + ∀ facet, facet ∈ facets → facet.claim = claim ∧ Articulated (articulations facet) ∧ + FacetArticulated (articulations facet) facet ∧ FacetDischarged facet +/- The achievement obligation requires grounds for this very claim, without making observation a universal prerequisite. -/ +def AchievementAccountability {W : Type} (achievement : Claim W) (articulations : Facet W → Articulation W) + (actualApplicable : Facet W → Prop) (facets : List (Facet W)) : Prop := + Grounds achievement articulations actualApplicable facets +/- The concrete achievement claim refers to each transition's own before/after states. -/ +def transitionAchievement : Claim TransitionCase := + fun transition => Expanded (transitionBefore transition) (transitionAfter transition) +/- This observation inspects an actually constructed successor and its output under that transition's input condition. -/ +def transitionPerformanceRecord : Record TransitionCase := + ⟨fun transition => (transitionAfter transition).constructed.any + (fun operation => operation == .successor && decide (operation.run (transitionInput transition) = 1)), true⟩ +/- The positive report test reads its asserted operation, input and output; it does not verify their presence in the after-state. -/ +def transitionReportRecord : Record TransitionCase := + ⟨fun transition => + let report := transitionAnnouncement transition + report.reportedNewOperation == .successor && report.input == 0 && report.expectedOutput == 1, true⟩ +/- Only the genuine extension matches the operation/performance observation in this two-transition model. -/ +theorem transitionPerformanceCompatible : + ∀ transition, Compatible [transitionPerformanceRecord] transition ↔ transition = .extend := by + intro transition + constructor + · intro h + have observed := h transitionPerformanceRecord (List.mem_singleton.mpr rfl) + cases transition + · cases observed + · rfl + · intro h; cases h + intro record hr; have hr' := List.mem_singleton.mp hr; subst record + rfl +/- A compatible performance observation establishes the same transition's report content and hence its represented expansion. -/ +theorem transitionSupported : Supports [transitionPerformanceRecord] transitionAchievement := by + intro transition compatible + have h := (transitionPerformanceCompatible transition).1 compatible + subst transition + have reportTrue : (transitionAnnouncement .extend).claim := by + simp [transitionAnnouncement, transitionAfter, transitionInput, + Announcement.claim, GeneratingSystem.report, generatingSystem, extendedState, baseState, Operation.run] + exact announcementClaimImpliesExpansion _ reportTrue +/- The actual scope is the shared input-zero condition, with no probabilistic inference introduced. -/ +def transitionFacet : Facet TransitionCase := + .empirical [transitionPerformanceRecord] (fun transition => transitionInput transition = 0) + transitionAchievement (fun _ => True) +/- The empirical assessment has a real compatible witness and supports this scoped achievement. -/ +theorem transitionFacetDischarged : FacetDischarged transitionFacet := by + refine ⟨⟨.extend, (transitionPerformanceCompatible _).2 rfl, rfl⟩, ?_, ?_⟩ + · intro transition compatible _; exact transitionSupported transition compatible + · intro _ _; trivial +/- Every applicable facet of this specified achievement has matching articulation and actual discharged evidence. -/ +theorem transitionAccountable : + AchievementAccountability transitionAchievement canonicalArticulation + (fun facet => facet = transitionFacet) [transitionFacet] := by + refine ⟨by simp, ?_, ?_⟩ + · intro facet hf; subst facet; exact List.mem_singleton.mpr rfl + · intro facet hf; have hf' := List.mem_singleton.mp hf; subst facet + exact ⟨rfl, canonicalArticulated _ transitionFacetDischarged, + canonicalFacetArticulated _, transitionFacetDischarged⟩ +/- Both actual transitions issue the same positive report about their own identified state pair. -/ +theorem transitionReportCompatible (transition : TransitionCase) : + Compatible [transitionReportRecord] transition := by + intro record hr; have hr' := List.mem_singleton.mp hr; subst record + rfl +/- Inflation is a concrete report-compatible counterworld, so the positive report alone does not support the same achievement claim. -/ +theorem transitionReportDoesNotSupport : + Compatible [transitionReportRecord] .inflate ∧ ¬ transitionAchievement .inflate ∧ + ¬ Supports [transitionReportRecord] transitionAchievement := by + have noExpansion : ¬ transitionAchievement .inflate := by + simp [transitionAchievement, transitionBefore, transitionAfter, Expanded, baseState, inflatedState] + exact ⟨transitionReportCompatible _, noExpansion, fun h => noExpansion (h _ (transitionReportCompatible _))⟩ +/- These concrete obligations, positive evidence and negative report case all refer to the same state-pair and input semantics. -/ +def ConcreteAchievementExample : Prop := + AchievementAccountability transitionAchievement canonicalArticulation + (fun facet => facet = transitionFacet) [transitionFacet] ∧ + Compatible [transitionPerformanceRecord] .extend ∧ + Supports [transitionPerformanceRecord] transitionAchievement ∧ transitionAchievement .extend ∧ + (Compatible [transitionReportRecord] .inflate ∧ ¬ transitionAchievement .inflate ∧ + ¬ Supports [transitionReportRecord] transitionAchievement) ∧ + (∀ transition, (transitionAnnouncement transition).before = transitionBefore transition ∧ + (transitionAnnouncement transition).after = transitionAfter transition ∧ + (transitionAnnouncement transition).input = transitionInput transition ∧ transitionInput transition = 0) +/- The concrete example jointly inhabits accountability, evidence compatibility, actual gain, and the report-only countermodel. -/ +theorem concreteAchievementExample : ConcreteAchievementExample := by + refine ⟨transitionAccountable, (transitionPerformanceCompatible _).2 rfl, transitionSupported, + transitionSupported .extend ((transitionPerformanceCompatible _).2 rfl), + transitionReportDoesNotSupport, ?_⟩ + intro transition; exact ⟨rfl,rfl,rfl,rfl⟩ +/- Semantic evidence yields truth only at a world that actually satisfies those evidence conditions. -/ +theorem achievementNeedsSupport {W : Type} (achievement : Claim W) (records : List (Record W)) + (actual : W) (reliableHere : Compatible records actual) (support : Supports records achievement) : + achievement actual ∧ ConcreteAchievementExample := + ⟨support actual reliableHere, concreteAchievementExample⟩ +/- Weakening a conclusion preserves support; this makes no claim about weakening the evidence. -/ +theorem supportWeakening {W : Type} (records : List (Record W)) (p q : Claim W) + (support : Supports records p) (weaker : ∀ w, p w → q w) : Supports records q := + fun w hw => weaker w (support w hw) +/- Discarding the only informative observation loses support for the unchanged switch claim. -/ +theorem evidenceWeakeningCanLoseSupport : + Supports ([⟨id, true⟩] : List (Record Bool)) (fun w => w = true) ∧ + ¬ Supports ([] : List (Record Bool)) (fun w => w = true) := by + refine ⟨?_, ?_⟩ + · intro w hw; exact hw ⟨id,true⟩ (by simp) + · intro h; have bad := h false (by intro r hr; cases hr); cases bad +/- Restricting the quantified application domain preserves a supported universal conclusion. -/ +theorem scopeRestriction {W X : Type} (records : List (Record W)) (p : W → X → Prop) + (wide narrow : X → Prop) (included : ∀ x, narrow x → wide x) + (support : Supports records (fun w => ∀ x, wide x → p w x)) : + Supports records (fun w => ∀ x, narrow x → p w x) := + fun w hw x hx => support w hw x (included x hx) +/- Actual applicability, rather than an optional classifier label, determines facet responsibility. -/ +def Duties {W : Type} (applicable : Facet W → Prop) : Prop := + ∀ f, applicable f → FacetDischarged f +def LabeledDuties {W : Type} (_labels : List String) (applicable : Facet W → Prop) : Prop := + Duties applicable +/- Combining applicable facets requires both sets of substantive duties. -/ +theorem assessmentUnion {W : Type} (a b : Facet W → Prop) : + Duties (fun f => a f ∨ b f) ↔ Duties a ∧ Duties b := by + constructor + · intro h; exact ⟨fun f hf => h f (Or.inl hf), fun f hf => h f (Or.inr hf)⟩ + · rintro ⟨ha,hb⟩ f (hf|hf); exact ha f hf; exact hb f hf +/- Omitting or changing labels does not remove an applicable duty. -/ +theorem labelsCannotWaive {W : Type} (xs ys : List String) (a : Facet W → Prop) : + LabeledDuties xs a ↔ LabeledDuties ys a := Iff.rfl +/- The observed switch is the outcome itself, not a record identifier. -/ +def switchRecord : Record Bool := ⟨id, true⟩ +theorem switchCompatible (w : Bool) : Compatible [switchRecord] w ↔ w = true := by + constructor + · intro h; exact h switchRecord (by simp) + · intro hw r hr; simp only [List.mem_singleton] at hr; cases hr; exact hw +theorem switchSupported : Supports [switchRecord] (fun w : Bool => w = true) := + fun w hw => (switchCompatible w).1 hw +/- The candidate action has specific benefit and cost outcomes; its inactive alternative has neither. -/ +def optionBenefit (selected : Bool) : Nat := if selected then 4 else 0 +def optionCost (selected : Bool) : Nat := if selected then 3 else 0 +/- The report describes each option's actual cost and benefit; it does not itself assert which option ought to be selected. -/ +def optionReport (selected : Bool) : Prop := + optionCost selected ≤ 3 ∧ optionBenefit selected = (if selected then 4 else 0) +/- The on position connects its own selected option to that option's benefit/cost outcome. -/ +def switchPosition : ValuePosition Bool where + Position := Bool + Outcome := Nat × Nat + adopted := true + selected := id + outcome := fun _ option => (optionBenefit option, optionCost option) + objective := fun result => result.2 < result.1 + constraints := fun _ option => optionCost option ≤ 3 + starting := singleton (fun w => w = true) + reasons := [fun _ option => optionReport option] + limits := fun _ => True + relevantCriticism := fun w => w = false + response := fun w => if w then some "benefit exceeds cost within budget" else some "reconsider if the budget no longer permits this cost" +theorem switchValueProcedure : ValueProcedure switchPosition := by + refine ⟨by simp [switchPosition], ?_, ?_, ?_⟩ + · refine ⟨true, (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩ + intro reason hr + have hr' : reason = (fun (_ : Bool) (option : Bool) => optionReport option) := List.mem_singleton.mp hr + subst reason + exact ⟨by decide, rfl⟩ + · intro w _ _ allReasons + have evidence := allReasons (fun (_ : Bool) (option : Bool) => optionReport option) (List.mem_singleton.mpr rfl) + change optionReport true at evidence + have benefitAboveBudget : 3 < optionBenefit true := by rw [evidence.2]; decide + exact ⟨Nat.lt_of_le_of_lt evidence.1 benefitAboveBudget, evidence.1⟩ + · intro w _ _; cases w <;> simp [switchPosition] +/- Adopting the other option updates the adopted starting state too, so rejection cannot be blamed on an inconsistent start. -/ +def oppositePosition : ValuePosition Bool := + { switchPosition with adopted := false, starting := singleton (fun w => w = false) } +/- The alternative has a joint adoption witness but its actual zero benefit/cost fails the adopted strict-benefit objective. -/ +theorem oppositePositionRejected : JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition := by + have witness : JointAdoption oppositePosition := by + refine ⟨false, (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩ + intro reason hr + have hr' : reason = (fun (_ : Bool) (option : Bool) => optionReport option) := List.mem_singleton.mp hr + subst reason + exact ⟨by decide, rfl⟩ + refine ⟨witness, ?_⟩ + intro h + have allReasons : ∀ reason, reason ∈ oppositePosition.reasons → reason false oppositePosition.adopted := by + intro reason hr + have hr' : reason = (fun (_ : Bool) (option : Bool) => optionReport option) := List.mem_singleton.mp hr + subst reason + exact ⟨by decide, rfl⟩ + have bad := h.2.2.1 false ((modelsSingleton _ _).2 rfl) trivial allReasons + exact Nat.lt_irrefl 0 bad.1 +/- Contradictory starting assumptions and an impossible selected/adopted equality are separate inadmissible variants. -/ +def contradictoryStartingPosition : ValuePosition Bool := + { switchPosition with starting := singleton (fun _ => False) } +def impossibleAdoptionPosition : ValuePosition Bool := + { switchPosition with selected := fun _ => false } +/- The common-world witness rejects both contradiction and an impossible commitment instead of proving them vacuously. -/ +theorem inadmissibleValuePositionsRejected : + ¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition := by + constructor + · intro h; obtain ⟨w,hw,_,_,_⟩ := h.2.1 + exact (modelsSingleton _ _).1 hw + · intro h; obtain ⟨w,_,_,hw,_⟩ := h.2.1 + cases hw +/- Removing the reasons leaves only a position and assertion, which fails this value procedure. -/ +def unsupportedPosition : ValuePosition Bool := { switchPosition with reasons := [] } +def switchEmpirical : Facet Bool := + .empirical [switchRecord] (fun _ => True) (fun w => w = true) (fun _ => True) +theorem switchEmpiricalDischarged : FacetDischarged switchEmpirical := by + refine ⟨⟨true, (switchCompatible true).2 rfl, trivial⟩, ?_, ?_⟩ + · intro w hw _; exact switchSupported w hw + · intro w _; trivial +/- A mixed empirical/value position has actual empirical evidence but still lacks its value-reason duty. -/ +theorem mixedMissingResponsibility : + FacetDischarged switchEmpirical ∧ + ¬ LabeledDuties [] (fun f : Facet Bool => f = switchEmpirical ∨ f = .value unsupportedPosition) := by + refine ⟨switchEmpiricalDischarged, ?_⟩ + intro h + have bad := (h (.value unsupportedPosition) (Or.inr rfl)).1 + exact bad rfl +/- A fully identified argument may still fail to entail the stated conclusion. -/ +def uninformativeArgument : Articulation Bool := + ⟨["switch state"], emptyTheory, [fun _ => True], fun _ => True⟩ +theorem articulationNotSupport : Articulated uninformativeArgument ∧ + ¬ Entails uninformativeArgument.assumptions (fun w : Bool => w = true) := by + exact ⟨⟨by simp [uninformativeArgument], by simp [uninformativeArgument]⟩, + consistentIncomplete.2.1⟩ +/- Identifiable but unrelated argument fields cannot replace the actual observation grounds under the connected adapter. -/ +theorem unrelatedArticulationRejected : + Articulated uninformativeArgument ∧ FacetDischarged switchEmpirical ∧ + ¬ FacetArticulated uninformativeArgument switchEmpirical := by + refine ⟨articulationNotSupport.1, switchEmpiricalDischarged, ?_⟩ + intro h + have relation := congrFun h.1 (Compatible [switchRecord]) + have bad : False := relation.mpr rfl + exact bad +/- Repetition of the same unrelated temperature observation leaves the switch state undetermined. -/ +def temperatureRecord : Record (Bool × Bool) := ⟨Prod.fst, true⟩ +theorem temperatureCompatible (b : Bool) : + Compatible [temperatureRecord, temperatureRecord] (true,b) := by + intro r hr + simp at hr + cases hr + rfl +/- The world identifies a selected action and its budget; the action costs three units. -/ +abbrev BudgetWorld := Bool × Nat +/- A real issued announcement asserts the selected action, but says nothing about affordability. -/ +def announcement : String := "activate" +def announcementPosition : ValuePosition BudgetWorld where + Position := Bool + Outcome := Nat × Nat + adopted := true + selected := Prod.fst + outcome := fun _ option => (optionBenefit option, optionCost option) + objective := fun result => result.2 < result.1 + constraints := fun w option => optionCost option ≤ w.2 + starting := singleton (fun w => w.1 = true) + reasons := [fun _ option => announcement = (if option then "activate" else "disable")] + limits := fun _ => True + relevantCriticism := fun w => w.2 < 3 + response := fun _ => some "reconsider the action when its cost exceeds budget" +/- The zero-budget counterworld satisfies the stated starts, adoption and all announced reasons jointly. -/ +theorem announcementHasJointAdoption : JointAdoption announcementPosition := by + refine ⟨(true,0), (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩ + intro reason hr + have hr' : reason = (fun (_ : BudgetWorld) (option : Bool) => announcement = (if option then "activate" else "disable")) := + List.mem_singleton.mp hr + subst reason + rfl +/- A nonempty announcement remains true in a jointly admissible zero-budget world but cannot support the action's affordability. -/ +theorem announcementNotBudgetReason : + announcementPosition.reasons ≠ [] ∧ announcementPosition.commitment (true,0) ∧ + (∀ reason, reason ∈ announcementPosition.reasons → reason (true,0) announcementPosition.adopted) ∧ + ¬ announcementPosition.consequence (true,0) ∧ ¬ ValueProcedure announcementPosition := by + refine ⟨by simp [announcementPosition], rfl, ?_, (by intro h; cases h.2), ?_⟩ + · intro reason hr + have hr' : reason = (fun (_ : BudgetWorld) (option : Bool) => announcement = (if option then "activate" else "disable")) := List.mem_singleton.mp hr + subst reason + rfl + · intro h + have allReasons : ∀ reason, reason ∈ announcementPosition.reasons → reason (true,0) announcementPosition.adopted := by + intro reason hr + have hr' : reason = (fun (_ : BudgetWorld) (option : Bool) => announcement = (if option then "activate" else "disable")) := List.mem_singleton.mp hr + subst reason + rfl + have bad := h.2.2.1 (true,0) ((modelsSingleton _ _).2 rfl) trivial allReasons + cases bad.2 +/- A repeated actual selection observation contains no budget information. -/ +def actionRecord : Record BudgetWorld := ⟨Prod.fst, true⟩ +theorem actionCompatible (budget : Nat) : Compatible [actionRecord, actionRecord] (true,budget) := by + intro r hr; simp at hr; cases hr; rfl +/- Single and repeated irrelevant observations cannot establish the other outcome or the same action's budget adequacy. -/ +theorem measurementRepeatNotSupport : + temperatureRecord.test (true,false) = true ∧ + Compatible [temperatureRecord,temperatureRecord] (true,false) ∧ + Compatible [temperatureRecord,temperatureRecord] (true,true) ∧ + ¬ Supports [temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + ¬ Supports [temperatureRecord,temperatureRecord] (fun w : Bool × Bool => w.2 = true) ∧ + Compatible [actionRecord,actionRecord] (true,0) ∧ + Compatible [actionRecord,actionRecord] (true,3) ∧ + ¬ Supports [actionRecord] announcementPosition.consequence ∧ + ¬ Supports [actionRecord,actionRecord] announcementPosition.consequence ∧ + ¬ ValueProcedure announcementPosition := by + refine ⟨rfl, temperatureCompatible false, temperatureCompatible true, ?_, ?_, + actionCompatible 0, actionCompatible 3, ?_, ?_, announcementNotBudgetReason.2.2.2.2⟩ + · intro h + have bad := h (true,false) (by intro r hr; simp only [List.mem_singleton] at hr; cases hr; rfl) + cases bad + · intro h; have bad := h (true,false) (temperatureCompatible false); cases bad + · intro h + have bad := h (true,0) (by intro r hr; simp only [List.mem_singleton] at hr; cases hr; rfl) + cases bad.2 + · intro h; have bad := h (true,0) (actionCompatible 0); cases bad.2 +/- Missing reason records fail a procedure; independently, a present announcement fails the explicit budget-support criterion. -/ +theorem selfAssertionNotReason : + (unsupportedPosition.commitment true ∧ ¬ ValueProcedure unsupportedPosition) ∧ + (announcementPosition.reasons ≠ [] ∧ announcementPosition.commitment (true,0) ∧ + ¬ announcementPosition.consequence (true,0) ∧ ¬ ValueProcedure announcementPosition) ∧ + JointAdoption announcementPosition := + ⟨⟨rfl, fun h => h.1 rfl⟩, + ⟨announcementNotBudgetReason.1, announcementNotBudgetReason.2.1, + announcementNotBudgetReason.2.2.2.1, announcementNotBudgetReason.2.2.2.2⟩, + announcementHasJointAdoption⟩ +/- The value procedure is satisfiable although the adopted starting commitment is not entailed by empty facts. -/ +theorem valueWithoutSelfProof : ValueProcedure switchPosition ∧ + Satisfiable switchPosition.starting ∧ + ¬ Entails (emptyTheory : Theory Bool) switchPosition.commitment ∧ + (JointAdoption oppositePosition ∧ ¬ ValueProcedure oppositePosition) ∧ + (¬ ValueProcedure contradictoryStartingPosition ∧ ¬ ValueProcedure impossibleAdoptionPosition) := + ⟨switchValueProcedure, ⟨true, (modelsSingleton _ _).2 rfl⟩, consistentIncomplete.2.1, + oppositePositionRejected, inadmissibleValuePositionsRejected⟩ +/- The world records the selected option and its actual benefit/cost outcomes. -/ +abbrev BenefitCostWorld := Bool × (Nat × Nat) +def measuredOutcome (world : BenefitCostWorld) (option : Bool) : Nat × Nat := + if option then world.2 else (0,0) +def benefitReason (world : BenefitCostWorld) (option : Bool) : Prop := + (measuredOutcome world option).1 = 4 +def costReason (world : BenefitCostWorld) (option : Bool) : Prop := + (measuredOutcome world option).2 ≤ 3 +/- Neither recorded benefit nor recorded cost alone establishes the selected option's joint consequence. -/ +def jointReasonPosition : ValuePosition BenefitCostWorld where + Position := Bool + Outcome := Nat × Nat + adopted := true + selected := Prod.fst + outcome := measuredOutcome + objective := fun result => result.2 < result.1 + constraints := fun world option => (measuredOutcome world option).2 ≤ 3 + starting := singleton (fun world => world.1 = true) + reasons := [benefitReason, costReason] + limits := fun _ => True + relevantCriticism := fun world => 3 < world.2.2 + response := fun _ => some "reassess the option when its cost exceeds the budget" +/- These two content constraints jointly establish the consequence in a nonempty adopted world. -/ +theorem jointReasonProcedure : ValueProcedure jointReasonPosition := by + refine ⟨by simp [jointReasonPosition], ?_, ?_, ?_⟩ + · refine ⟨(true,(4,3)), (modelsSingleton _ _).2 rfl, trivial, rfl, ?_⟩ + intro reason hr + change reason ∈ [benefitReason,costReason] at hr + rcases List.mem_cons.mp hr with hr | hr + · subst reason; rfl + · have hr' := List.mem_singleton.mp hr + subst reason + change 3 ≤ 3; exact Nat.le_refl 3 + · intro world _ _ reasons + have benefit := reasons benefitReason (by change benefitReason ∈ [benefitReason,costReason]; simp) + have cost := reasons costReason (by change costReason ∈ [benefitReason,costReason]; simp) + change (measuredOutcome world true).1 = 4 at benefit + change (measuredOutcome world true).2 ≤ 3 at cost + refine ⟨?_, cost⟩ + have bigger : 3 < (measuredOutcome world true).1 := by rw [benefit]; decide + exact Nat.lt_of_le_of_lt cost bigger + · intro world _ _ + exact ⟨"reassess the option when its cost exceeds the budget", rfl, by decide⟩ +/- Each separate reason has a concrete same-start/limit/adoption counterworld; their conjunction is sufficient. -/ +def JointReasonsExample : Prop := + ValueProcedure jointReasonPosition ∧ + (Models jointReasonPosition.starting (true,(4,5)) ∧ jointReasonPosition.limits (true,(4,5)) ∧ + jointReasonPosition.commitment (true,(4,5)) ∧ benefitReason (true,(4,5)) true ∧ + ¬ jointReasonPosition.consequence (true,(4,5))) ∧ + (Models jointReasonPosition.starting (true,(0,3)) ∧ jointReasonPosition.limits (true,(0,3)) ∧ + jointReasonPosition.commitment (true,(0,3)) ∧ costReason (true,(0,3)) true ∧ + ¬ jointReasonPosition.consequence (true,(0,3))) +theorem jointReasonsExample : JointReasonsExample := by + refine ⟨jointReasonProcedure, + ⟨(modelsSingleton _ _).2 rfl, trivial, rfl, rfl, ?_⟩, + ⟨(modelsSingleton _ _).2 rfl, trivial, rfl, Nat.le_refl 3, ?_⟩⟩ + · intro h; have bad : 5 ≤ 3 := h.2; omega + · intro h; have bad : 3 < 0 := h.1; omega +/- Empirical observations, semantic inference and criticism-responsive reasons coexist without a scalar score. -/ +theorem heterogeneousReasons : + FacetDischarged switchEmpirical ∧ + FacetDischarged (Facet.inferential (singleton (fun w : Bool => w = true)) (fun w => w = true)) ∧ + FacetDischarged (Facet.value switchPosition) ∧ JointReasonsExample := by + refine ⟨switchEmpiricalDischarged, ⟨⟨true, (modelsSingleton _ _).2 rfl⟩, ?_⟩, switchValueProcedure, jointReasonsExample⟩ + intro w hw; exact (modelsSingleton (fun x : Bool => x = true) w).1 hw + +/- This local observation checks the actual output on input zero. -/ +def zeroRecord : Record (Nat → Bool) := ⟨fun f => f 0, true⟩ +def localGenerator (seed : Nat) : Nat → Bool := fun n => n == seed +/- All outputs being true is a stronger, explicitly quantified capability claim. -/ +def allTrue : Claim (Nat → Bool) := fun f => ∀ n, f n = true +theorem zeroCompatible (f : Nat → Bool) : Compatible [zeroRecord] f ↔ f 0 = true := by + constructor + · intro h; exact h zeroRecord (by simp) + · intro hf r hr; simp only [List.mem_singleton] at hr; cases hr; exact hf +/- A generating subject owns an earlier predicate and a seed used to revise that actual predicate. -/ +structure GeneratingProcess where + owner : Nat + prior : Nat → Bool + generateSeed : Nat +/- The revision preserves prior successes and adds the seed-selected case through the actual generator. -/ +def GeneratingProcess.outputRevision (process : GeneratingProcess) : Nat → Bool := + fun input => process.prior input || localGenerator process.generateSeed input +/- A produced revision retains its producer and exact old/new objects. -/ +structure ProducedRevision where + producer : Nat + before : Nat → Bool + after : Nat → Bool +/- The subject itself constructs the owned before/after revision object. -/ +def GeneratingProcess.produce (process : GeneratingProcess) : ProducedRevision := + ⟨process.owner, process.prior, process.outputRevision⟩ +def sampleGeneratingProcess : GeneratingProcess := ⟨17, fun _ => false, 0⟩ +/- This same-owner revision actually changes input zero, while its produced predicate still fails at input one. -/ +def OwnedRevisionExample : Prop := + sampleGeneratingProcess.produce.producer = sampleGeneratingProcess.owner ∧ + sampleGeneratingProcess.produce.before = sampleGeneratingProcess.prior ∧ + sampleGeneratingProcess.produce.after = sampleGeneratingProcess.outputRevision ∧ + sampleGeneratingProcess.produce.before 0 = false ∧ sampleGeneratingProcess.produce.after 0 = true ∧ + sampleGeneratingProcess.produce.after 1 = false ∧ + Compatible [zeroRecord] sampleGeneratingProcess.produce.after ∧ + ¬ Supports [zeroRecord] allTrue +/- Actual producer/old/new links and the compatible failing revision witness the insufficiency of self-origin. -/ +theorem ownedRevisionExample : OwnedRevisionExample := by + refine ⟨rfl,rfl,rfl,rfl,rfl,rfl,(zeroCompatible _).2 rfl, ?_⟩ + intro h + have bad := h sampleGeneratingProcess.produce.after ((zeroCompatible _).2 rfl) 1 + cases bad +/- The generator's own sample succeeds, but its generated revision has a concrete unsupported global claim. -/ +theorem selfOriginDoesNotSupport : + localGenerator 0 0 = true ∧ localGenerator 0 1 = false ∧ + Compatible [zeroRecord] (localGenerator 0) ∧ + ¬ Supports [zeroRecord] allTrue ∧ OwnedRevisionExample := by + refine ⟨rfl, rfl, (zeroCompatible _).2 rfl, ?_, ownedRevisionExample⟩ + intro h + have bad := h (localGenerator 0) ((zeroCompatible _).2 rfl) 1 + cases bad +/- A proper local observation allows both a universally successful and a failing extension. -/ +theorem localNotUniversal : + (∃ outside : Nat, outside ≠ 0) ∧ + Compatible [zeroRecord] (fun _ => true) ∧ + Compatible [zeroRecord] (localGenerator 0) ∧ + allTrue (fun _ => true) ∧ ¬ allTrue (localGenerator 0) ∧ + ¬ Supports [zeroRecord] allTrue := by + refine ⟨⟨1, by decide⟩, (zeroCompatible _).2 rfl, (zeroCompatible _).2 rfl, + (fun _ => rfl), ?_, selfOriginDoesNotSupport.2.2.2.1⟩ + intro h; have bad := h 1; cases bad +/- Two implementations agree on the actual observed input and differ on a specified relevant omitted input. -/ +theorem hiddenDifference : + (∀ n : Nat, n = 0 → (fun _ : Nat => true) n = localGenerator 0 n) ∧ + (fun _ : Nat => true) 1 ≠ localGenerator 0 1 := by + refine ⟨?_, by decide⟩ + intro n hn; cases hn; rfl +/- One observation supplies only its actual input-specific consequence, without repetition. -/ +theorem singleObservation : [zeroRecord].length = 1 ∧ + (∃ f, Compatible [zeroRecord] f) ∧ + Supports [zeroRecord] (fun f => f 0 = true) ∧ + ¬ Supports [zeroRecord] allTrue := + ⟨rfl, ⟨localGenerator 0, (zeroCompatible _).2 rfl⟩, + (fun f hf => (zeroCompatible f).1 hf), selfOriginDoesNotSupport.2.2.2.1⟩ +/- This inferential assessment derives a successor value from its explicit numeric premise without observation. -/ +def arithmeticFacet : Facet Nat := .inferential (singleton (fun n => n = 2)) (fun n => n + 1 = 3) +def usesObservation {W : Type} : Facet W → Bool + | .empirical _ _ _ _ => true + | _ => false +/- An actual valid inferential assessment refutes a mandatory measurement/repetition/framework chain. -/ +theorem noUniversalChain : FacetDischarged arithmeticFacet ∧ usesObservation arithmeticFacet = false := by + refine ⟨⟨⟨2, (modelsSingleton _ _).2 rfl⟩, ?_⟩, rfl⟩ + intro n hn + have premise := (modelsSingleton (fun x : Nat => x = 2) n).1 hn + change n + 1 = 3 + rw [premise] +/- A trial has a reproducible setting, an actual outcome and a separately recorded outcome. -/ +structure Trial where + setting : Nat + actualOutcome : Nat + recordedOutcome : Nat +/- Verifying a record, reproducing settings and retaining a conclusion are separate predicates. -/ +def Verified (t : Trial) : Prop := t.recordedOutcome = t.actualOutcome +def Reproduced (a b : Trial) : Prop := a.setting = b.setting +def Bounded (t : Trial) : Prop := t.actualOutcome ≤ 2 +/- Same-setting possible trials can differ while preserving the chosen bound; no probability semantics is claimed. -/ +theorem variableOutcomesStableBound : + let a : Trial := ⟨0,1,1⟩ + let b : Trial := ⟨0,2,2⟩ + Reproduced a b ∧ a.actualOutcome ≠ b.actualOutcome ∧ Bounded a ∧ Bounded b := by + simp [Reproduced, Bounded] +/- Concrete records distinguish record accuracy, condition reproduction and conclusion stability. -/ +theorem verificationReproductionStability : + (Verified ⟨0,1,1⟩ ∧ Verified ⟨1,1,1⟩ ∧ ¬ Reproduced ⟨0,1,1⟩ ⟨1,1,1⟩) ∧ + (Reproduced ⟨0,1,1⟩ ⟨0,3,2⟩ ∧ ¬ Verified ⟨0,3,2⟩ ∧ ¬ Bounded ⟨0,3,2⟩) ∧ + (Bounded ⟨0,1,1⟩ ∧ Bounded ⟨0,2,0⟩ ∧ ¬ Verified ⟨0,2,0⟩) := by + simp [Verified, Reproduced, Bounded] +/- Explanation certificates are executable syntax for this same arithmetic process. -/ +inductive Program where + | doubleInput + | constant (value : Nat) +def Program.eval : Program → Nat → Nat + | .doubleInput, n => n + n + | .constant value, _ => value +/- A process exposes outputs and an explanation response, whose certificate can be checked against those outputs. -/ +structure Process where + output : Nat → Nat + explanation : Option Program +/- The output-only application contract checks every relevant input. -/ +def OutputContract (p : Process) : Prop := ∀ n, p.output n = n + n +/- The explanation application contract requires a provided certificate faithful to this very process. -/ +def ExplanationContract (p : Process) : Prop := + ∃ program, p.explanation = some program ∧ ∀ n, program.eval n = p.output n +/- This process produces doubled values but returns no explanatory certificate. -/ +def outputOnlyProcess : Process := ⟨fun n => n + n, none⟩ +def explainedProcess : Process := ⟨fun n => n + n, some .doubleInput⟩ +/- Object scope fixes the very process whose contract is assessed; contract inputs themselves still range over all naturals. -/ +def processScope (assessed : Process) : Theory Process := + singleton (fun candidate => candidate = assessed) +/- This inferential facet checks an explicit contract under exact process-identity assumptions. -/ +def processContractFacet (assessed : Process) (contract : Claim Process) : Facet Process := + .inferential (processScope assessed) contract +/- The scope's compatible interpretations are exactly this assessed process, not an unrelated substitute. -/ +theorem processScopeModels (assessed candidate : Process) : + Models (processScope assessed) candidate ↔ candidate = assessed := + modelsSingleton (fun process => process = assessed) candidate +/- A concrete contract proof supplies the facet's consequence for its scoped object. -/ +theorem processContractDischarged (assessed : Process) (contract : Claim Process) (proof : contract assessed) : + FacetDischarged (processContractFacet assessed contract) := by + refine ⟨⟨assessed,(processScopeModels _ _).2 rfl⟩, ?_⟩ + intro candidate hc + have same := (processScopeModels _ _).1 hc + subst candidate + exact proof +/- Scoped capability grounds include exact claim, object-specific assumptions, canonical articulation and actual assessment. -/ +def ProcessGrounds (assessed : Process) (contract : Claim Process) : Prop := + Grounds contract canonicalArticulation (fun facet => facet = processContractFacet assessed contract) + [processContractFacet assessed contract] +theorem processGrounds (assessed : Process) (contract : Claim Process) (proof : contract assessed) : + ProcessGrounds assessed contract := by + have discharged := processContractDischarged assessed contract proof + refine ⟨by simp, ?_, ?_⟩ + · intro facet hf; subst facet; exact List.mem_singleton.mpr rfl + · intro facet hf; have hf' := List.mem_singleton.mp hf; subst facet + exact ⟨rfl,canonicalArticulated _ discharged,canonicalFacetArticulated _,discharged⟩ +/- Universal output correctness here comes from the concrete program definition, not from an assumed capability label. -/ +theorem outputCorrectByEvaluation : OutputContract outputOnlyProcess := fun _ => rfl +/- This same process actually returns no explanation certificate. -/ +theorem outputOnlyNoExplanation : ¬ ExplanationContract outputOnlyProcess := by + rintro ⟨program,h,_⟩; cases h +/- The full application contract requires outputs and an explanation of that same process. -/ +def FullProcessContract (assessed : Process) : Prop := OutputContract assessed ∧ ExplanationContract assessed +/- Output-only grounds have the assessed process itself as a counterworld to the stronger contract. -/ +def OutputContractEvidence : Prop := + ProcessGrounds outputOnlyProcess OutputContract ∧ + Models (processScope outputOnlyProcess) outputOnlyProcess ∧ + ¬ Entails (processScope outputOnlyProcess) FullProcessContract +/- Existing output evidence does not supply the absent explanation for the same object and scope. -/ +theorem outputContractEvidence : OutputContractEvidence := by + refine ⟨processGrounds _ _ outputCorrectByEvaluation, (processScopeModels _ _).2 rfl, ?_⟩ + intro stronger + exact outputOnlyNoExplanation (stronger outputOnlyProcess ((processScopeModels _ _).2 rfl)).2 +/- Both actual application contracts have grounds and explicit object scopes; neither scope is empty. -/ +def ScopedApplicationEvidence : Prop := + ProcessGrounds outputOnlyProcess OutputContract ∧ + ProcessGrounds explainedProcess FullProcessContract ∧ + (∀ candidate, Models (processScope outputOnlyProcess) candidate ↔ candidate = outputOnlyProcess) ∧ + (∀ candidate, Models (processScope explainedProcess) candidate ↔ candidate = explainedProcess) ∧ + Satisfiable (processScope outputOnlyProcess) ∧ Satisfiable (processScope explainedProcess) +/- Concrete evaluation and a faithful double-input certificate establish the two differently scoped contracts. -/ +theorem scopedApplicationEvidence : ScopedApplicationEvidence := by + refine ⟨processGrounds _ _ outputCorrectByEvaluation, processGrounds _ _ ?_, + processScopeModels _,processScopeModels _,⟨_,(processScopeModels _ _).2 rfl⟩, + ⟨_,(processScopeModels _ _).2 rfl⟩⟩ + exact ⟨fun _ => rfl,⟨.doubleInput,rfl,fun _ => rfl⟩⟩ +/- Universal output correctness does not entail the explanation-requiring contract for the same process. -/ +theorem outputNotExplanation : OutputContract outputOnlyProcess ∧ + ¬ ExplanationContract outputOnlyProcess ∧ OutputContractEvidence := + ⟨outputCorrectByEvaluation, outputOnlyNoExplanation, outputContractEvidence⟩ +/- Applications may use distinct contracts, and a faithful certificate can satisfy the stronger one. -/ +theorem applicationContractsDiffer : + (OutputContract outputOnlyProcess ∧ ¬ (OutputContract outputOnlyProcess ∧ ExplanationContract outputOnlyProcess)) ∧ + (OutputContract explainedProcess ∧ ExplanationContract explainedProcess) ∧ + ScopedApplicationEvidence := + ⟨⟨outputCorrectByEvaluation, fun h => outputOnlyNoExplanation h.2⟩, + ⟨(fun _ => rfl), ⟨.doubleInput, rfl, fun _ => rfl⟩⟩, scopedApplicationEvidence⟩ +/- The assessor supplies a mathematical certificate; the process's own explanation response is unnecessary. -/ +structure ExternalCertificate (p : Process) where + assessorId : Nat + assessedId : Nat + distinctParticipants : assessorId ≠ assessedId + outputCorrect : ∀ n, p.output n = n + n +/- The external assessor 42 evaluates the specified process 7; the full output proof is constructed by evaluation. -/ +def externalOutputCertificate : ExternalCertificate outputOnlyProcess := + ⟨42,7,by decide,fun _ => rfl⟩ +/- An external certificate establishes the output contract without producing an internal explanation. -/ +theorem externalAssessment : + (∃ certificate : ExternalCertificate outputOnlyProcess, + certificate.assessorId = 42 ∧ certificate.assessedId = 7 ∧ + certificate.assessorId ≠ certificate.assessedId ∧ OutputContract outputOnlyProcess) ∧ + ProcessGrounds outputOnlyProcess OutputContract ∧ + ¬ ExplanationContract outputOnlyProcess := + ⟨⟨externalOutputCertificate,rfl,rfl,externalOutputCertificate.distinctParticipants, + externalOutputCertificate.outputCorrect⟩, + processGrounds outputOnlyProcess OutputContract externalOutputCertificate.outputCorrect, + outputOnlyNoExplanation⟩ +/- This argument records concepts and actual premises for a semantic inference, separately from executable tests. -/ +def arithmeticArticulation : Articulation Nat := canonicalArticulation arithmeticFacet +/- A reasoned inferential assessment needs no observation method, while applicable empirical assessment retains observations. -/ +theorem nonExecutableAssessment : + Grounds (fun n : Nat => n + 1 = 3) canonicalArticulation (fun f => f = arithmeticFacet) [arithmeticFacet] ∧ + usesObservation arithmeticFacet = false ∧ + FacetDischarged switchEmpirical ∧ usesObservation switchEmpirical = true := by + refine ⟨⟨by simp, (by intro f hf; cases hf; simp), ?_⟩, rfl, switchEmpiricalDischarged, rfl⟩ + intro f hf; simp only [List.mem_singleton] at hf; cases hf + exact ⟨rfl, canonicalArticulated _ noUniversalChain.1, canonicalFacetArticulated _, noUniversalChain.1⟩ + +end CoreReader.Evidence +``` + + + + **L1** 导入 CoreReader.Logic,使其已检查声明可供本模块使用;这一行不提出新的哲学结论。 + + + **L2** 导入 CoreReader.Agency,使其已检查声明可供本模块使用;这一行不提出新的哲学结论。 + + + **L4** 打开命名空间 CoreReader.Evidence,使后续声明获得这一模块限定名。 + + + **L5** 允许不加限定使用 CoreReader.Logic 中的名称;这改变名称解析,不增加假设。 + + + **L6** 允许不加限定使用 CoreReader.Agency 中的名称;这改变名称解析,不增加假设。 + + + **L8** 说明 Record 的预定范围。对应声明涉及:记录给定世界的布尔测试及其记录结果,不包含测量出处或真实性验证。 该注释用于解释,不是证明前提。 + + + **L9** 声明数据接口 Record。记录给定世界的布尔测试及其记录结果,不包含测量出处或真实性验证。 + + + **L10** 保存读取实际被表示世界的指定布尔测试。 + + + **L11** 保存将与该测试比较的已观测布尔结果。 + + + **L12** 说明 Compatible 的预定范围。对应声明涉及:每条记录的测试结果都必须与记录值一致;空列表允许任意世界。 该注释用于解释,不是证明前提。 + + + **L13** 定义 Compatible。每条记录的测试结果都必须与记录值一致;空列表允许任意世界。 + + + **L14** 要求每条列出记录在 w 的真实测试等于该记录的观测结果。 + + + **L15** 说明 Supports 的预定范围。对应声明涉及:主张在所有记录兼容世界成立;这是模型内蕴涵,不是统计置信度。 该注释用于解释,不是证明前提。 + + + **L16** 定义 Supports。主张在所有记录兼容世界成立;这是模型内蕴涵,不是统计置信度。 + + + **L17** 要求同一主张在与全部记录相容的每个世界成立;没有相容世界时,该蕴含本身可能空真。 + + + **L18** 说明 Articulation 的预定范围。对应声明涉及:保存概念字符串、假设理论、理由列表和限度谓词。 该注释用于解释,不是证明前提。 + + + **L19** 声明数据接口 Articulation。保存概念字符串、假设理论、理由列表和限度谓词。 + + + **L20** 保存可识别概念名称;字符串本身不确立语义充分性。 + + + **L21** 保存作为表述假设陈述的实际理论。 + + + **L22** 把理由内容保存为针对同一世界类型的命题。 + + + **L23** 保存这些理由的真实应用限度谓词。 + + + **L24** 说明 Articulated 的预定范围。对应声明涉及:只要求概念与理由列表非空,不单独保证相关性或充分性。 该注释用于解释,不是证明前提。 + + + **L25** 定义 Articulated。只要求概念与理由列表非空,不单独保证相关性或充分性。 + + + **L26** 只要求概念与理由列表非空;这一程序条件弱于匹配且已履行的 Grounds。 + + + **L27** 说明 ValuePosition 的预定范围。对应声明涉及:表示采纳选项、实际选择、选项相关结果及理由、目标、约束、起点、范围和批评响应;这是明示应用适配模型。 该注释用于解释,不是证明前提。 + + + **L28** 声明数据接口 ValuePosition。表示采纳选项、实际选择、选项相关结果及理由、目标、约束、起点、范围和批评响应;这是明示应用适配模型。 + + + **L29** 给出该价值立场从中采纳某一项的选项类型。 + + + **L30** 给出用于解释各选项效果的后果类型。 + + + **L31** 规定被采纳的选项,与世界实际选择哪个选项分开。 + + + **L32** 从各世界读取实际选择的选项。 + + + **L33** 解释各世界中各选项的真实后果,而不保存任意支持标签。 + + + **L34** 把被采纳目标规定为后果上的谓词;该字段不证明其价值权威。 + + + **L35** 规定与目标一同检查、依赖世界和选项的约束。 + + + **L36** 保存起点理论;JointAdoption 将要求它与采纳及理由具有真实共同模型。 + + + **L37** 保存同时按世界与选项参数化的理由,因此切换采纳选项会改变受评理由。 + + + **L38** 规定该价值评估程序主张结论的范围。 + + + **L39** 识别哪些世界存在相关批评;这是明确的应用谓词。 + + + **L40** 保存各世界的可选文本回应;回应存在不证明批评已被充分回答。 + + + **L41** 说明 ValuePosition.commitment 的预定范围。对应声明涉及:承诺主张表示世界选择了所采纳选项,不再是可独立重贴的任意主张字段。 该注释用于解释,不是证明前提。 + + + **L42** 定义 ValuePosition.commitment。承诺主张表示世界选择了所采纳选项,不再是可独立重贴的任意主张字段。 + + + **L43** 通过实际选择等于同一采纳选项,导出承诺主张。 + + + **L44** 说明 ValuePosition.consequence 的预定范围。对应声明涉及:以目标及约束检查该采纳选项的模型结果。 该注释用于解释,不是证明前提。 + + + **L45** 定义 ValuePosition.consequence。以目标及约束检查该采纳选项的模型结果。 + + + **L46** 根据同一采纳选项的真实后果满足目标及真实约束,导出受评后果。 + + + **L47** 说明 ValuePosition.activeReasons 的预定范围。对应声明涉及:把每个选项相关理由实例化到采纳选项,用于根据表达。 该注释用于解释,不是证明前提。 + + + **L48** 定义 ValuePosition.activeReasons。把每个选项相关理由实例化到采纳选项,用于根据表达。 + + + **L49** 把每个按选项索引的理由特化到采纳选项,形成其实际表述的世界谓词。 + + + **L50** 说明 JointAdoption 的预定范围。对应声明涉及:要求存在一个世界,同时满足起点理论、范围、实际采纳及全部该选项理由。 该注释用于解释,不是证明前提。 + + + **L51** 定义 JointAdoption。要求存在一个世界,同时满足起点理论、范围、实际采纳及全部该选项理由。 + + + **L52** 要求起点假设、应用限度与实际采纳具有一个共同世界。 + + + **L53** 在同一见证处,要求针对该采纳选项的全部列出理由共同成立。 + + + **L54** 说明 ValueProcedure 的预定范围。对应声明涉及:要求非空理由、联合采纳见证、起点和范围内联合理由支持该选项后果,以及非空批评响应;不证明终极价值正确性。 该注释用于解释,不是证明前提。 + + + **L55** 定义 ValueProcedure。要求非空理由、联合采纳见证、起点和范围内联合理由支持该选项后果,以及非空批评响应;不证明终极价值正确性。 + + + **L56** 以理由非空与完整共同采纳见证开始 ValueProcedure。 + + + **L57** 对满足真实起点理论与限度的每个世界,施加后续条件后果要求。 + + + **L58** 用采纳选项的全部理由合取蕴含其真实后果;不要求单条理由充分。 + + + **L59** 在限度内,每项相关批评必须有指定的非空回应;这里检查回应记录,而非说服力。 + + + **L60** 说明 Facet 的预定范围。对应声明涉及:区分经验、推论、价值三个面向;同一主张可有多个面向。 该注释用于解释,不是证明前提。 + + + **L61** 声明可选构造 Facet。区分经验、推论、价值三个面向;同一主张可有多个面向。 + + + **L62** 经验方面保存真实测试记录,以及范围、结论与所述不确定性谓词。 + + + **L63** 推论方面保存真实前提理论及待从中蕴含的结论。 + + + **L64** 价值方面保存完整的选项与后果立场,包括起点理论、理由、限度及批评回应。 + + + **L65** 说明 Facet.claim 的预定范围。对应声明涉及:抽取经验或推论结论,价值面向则抽取其立场承诺。 该注释用于解释,不是证明前提。 + + + **L66** 定义 Facet.claim。抽取经验或推论结论,价值面向则抽取其立场承诺。 + + + **L67** 把经验方面自身结论 p 读为主张;记录、范围与不确定性仍为评估输入。 + + + **L68** 把推论方面自身结论 p 读为主张,与前提理论分开。 + + + **L69** 价值方面的主张是实际选择等于自身采纳选项,通过 v.commitment 导出。 + + + **L70** 说明 FacetDischarged 的预定范围。对应声明涉及:经验要求非空范围见证及支持,推论要求假设可满足且蕴涵结论,价值使用声明的程序接口。 该注释用于解释,不是证明前提。 + + + **L71** 定义 FacetDischarged。经验要求非空范围见证及支持,推论要求假设可满足且蕴涵结论,价值使用声明的程序接口。 + + + **L72** 进入经验履行情况,使用该方面真实记录、范围、结论 p 与不确定性谓词。 + + + **L73** 对经验方面,要求存在与记录相容且在范围内的世界,排除空经验域。 + + + **L74** 要求记录支持范围内结论及明确规定的不确定性谓词。 + + + **L75** 推论履行要求真实假设具有非空模型,且同一假设语义蕴含 p。 + + + **L76** 价值履行恰为同一立场声明的 ValueProcedure,不是终极价值充分性的证明。 + + + **L77** 说明 FacetArticulated 的预定范围。对应声明涉及:要求表达中的假设、理由和限度与对应面向精确对齐。 该注释用于解释,不是证明前提。 + + + **L78** 定义 FacetArticulated。要求表达中的假设、理由和限度与对应面向精确对齐。 + + + **L79** 在经验表述情况下,读取假设、理由与限度必须匹配的真实记录与范围。 + + + **L80** 这一经验适配器把表述假设及理由与实际记录相容性等同,并把表述限度与经验范围等同。 + + + **L81** 在推论情况下,以该方面真实假设理论作为表述参照。 + + + **L82** 这一推论适配器保留准确前提理论,将其模型条件表述为理由,并使用不受限的附加限度。 + + + **L83** 要求价值表述准确使用该立场的起点理论、采纳选项有效理由与限度。 + + + **L84** 说明 canonicalArticulation 的预定范围。对应声明涉及:按面向构造固定概念标签及与该面向对齐的假设、理由和限度。 该注释用于解释,不是证明前提。 + + + **L85** 定义 canonicalArticulation。按面向构造固定概念标签及与该面向对齐的假设、理由和限度。 + + + **L86** 从所选方面真实记录列表与范围构造经验规范表述。 + + + **L87** 构造命名测试结果与条件的经验表述,以实际相容性主张为前提和理由,原范围为限度。 + + + **L88** 从该方面真实前提理论构造推论规范表述。 + + + **L89** 从同一理论及其真实模型谓词构造推论表述,不增加限度。 + + + **L90** 使用同一完整立场 v 构造价值表述。 + + + **L91** 从真实起点理论、采纳选项理由与原限度构造价值表述。 + + + **L92** 说明 canonicalFacetArticulated 的预定范围。对应声明涉及:逐个面向用自反等式证明规范表达与原面向对齐。 该注释用于解释,不是证明前提。 + + + **L93** 陈述经检查的结果 canonicalFacetArticulated。逐个面向用自反等式证明规范表达与原面向对齐。 + + + **L94** 断言规范表述与同一方面具有语义连接;证明检查各方面构造子。 + + + **L95** 按三个方面构造子分类;各规范表述恰有对应分支要求的假设、理由与限度,三个等式均由自反性成立。 + + + **L96** 说明 canonicalArticulated 的预定范围。对应声明涉及:由已完成面向证明规范表达的概念与理由非空。 该注释用于解释,不是证明前提。 + + + **L97** 陈述经检查的结果 canonicalArticulated。由已完成面向证明规范表达的概念与理由非空。 + + + **L98** 给定该方面已履行,要求其规范概念与理由非空。 + + + **L99** 分别检查经验、推论与价值方面的规范表述。 + + + **L100** 在这一经验或推论分支中,规范概念列表和理由列表明确非空;化简验证两个表述要求。 + + + **L101** 在这一经验或推论分支中,规范概念列表和理由列表明确非空;化简验证两个表述要求。 + + + **L102** 在价值分支,前提 h 为 ValueProcedure v;其中理由非空必须确立规范有效理由非空。 + + + **L103** 对价值方面给出规范概念非空性,留下有效理由列表非空的义务。 + + + **L104** 利用通过检查的价值程序中的理由非空性;将理由特化到采纳选项保持非空。 + + + **L105** 说明 Grounds 的预定范围。对应声明涉及:要求非空面向清单、覆盖声明适用面、同一主张、表达对齐及各面向检查;不是现实充分性的统一判定器。 该注释用于解释,不是证明前提。 + + + **L106** 定义 Grounds。要求非空面向清单、覆盖声明适用面、同一主张、表达对齐及各面向检查;不是现实充分性的统一判定器。 + + + **L107** 独立于有限列表接收 actualApplicable,使覆盖成为明确义务,而非从列表成员关系推定。 + + + **L108** 要求方面列表非空,并包含每个满足 actualApplicable 的方面。 + + + **L109** 对每个列出方面,要求主张准确相同,并有属于该方面的非空表述。 + + + **L110** 还要求语义匹配真实前提、理由与限度,并通过其声明的适配器履行。 + + + **L111** 说明 AchievementAccountability 的预定范围。对应声明涉及:将成就主张交给同一Grounds接口,不另提供现实成就证明。 该注释用于解释,不是证明前提。 + + + **L112** 定义 AchievementAccountability。将成就主张交给同一Grounds接口,不另提供现实成就证明。 + + + **L113** 成就问责接收与 Grounds 相同的实际适用性谓词及方面列表。 + + + **L114** 直接以同一成就主张的 Grounds 定义问责,不增加普遍观测要求。 + + + **L115** 说明 transitionAchievement 的预定范围。对应声明涉及:把成就定义为同一模型变化前后状态的理解或构造扩展。 该注释用于解释,不是证明前提。 + + + **L116** 定义 transitionAchievement。把成就定义为同一模型变化前后状态的理解或构造扩展。 + + + **L117** 成就主张为所选变化自身前后状态之间的真实扩展。 + + + **L118** 说明 transitionPerformanceRecord 的预定范围。对应声明涉及:在两个变化模型中,测试同一后状态是否包含在该输入输出一的successor。 该注释用于解释,不是证明前提。 + + + **L119** 定义 transitionPerformanceRecord。在两个变化模型中,测试同一后状态是否包含在该输入输出一的successor。 + + + **L120** 表现测试检查该变化后状态中实际建构的操作。 + + + **L121** 只有后继操作存在且确实把共同变化输入变为 1 时,测试才记录 true。 + + + **L122** 说明 transitionReportRecord 的预定范围。对应声明涉及:仅记录报告宣称的操作、输入与输出,不直接记录成就是否实现。 该注释用于解释,不是证明前提。 + + + **L123** 定义 transitionReportRecord。仅记录报告宣称的操作、输入与输出,不直接记录成就是否实现。 + + + **L124** 开始构造一条读取实际变化公告的记录。 + + + **L125** 把 report 绑定到为同一变化生成的公告。 + + + **L126** 测试其所述后继操作、输入 0 与预期输出 1;记录积极公告,不据此确定操作存在。 + + + **L127** 说明 transitionPerformanceCompatible 的预定范围。对应声明涉及:穷尽膨胀与扩展两类,证明实际表现记录识别能力扩展。 该注释用于解释,不是证明前提。 + + + **L128** 陈述经检查的结果 transitionPerformanceCompatible。穷尽膨胀与扩展两类,证明实际表现记录识别能力扩展。 + + + **L129** 主张匹配真实积极表现记录当且仅当所选变化为 extend。 + + + **L130** 固定任意实际变化 inflate 或 extend,以证明记录相容性等价关系。 + + + **L131** 证明两个方向:表现相容性推出 extend,extend 则提供相容性。 + + + **L132** 假定该变化匹配真实积极表现记录。 + + + **L133** 把相容性应用于真实单元素表现记录,得到该变化的观测测试结果。 + + + **L134** 把实际变化分为 inflate 与 extend,两者后状态的操作内容不同。 + + + **L135** inflate 状态缺少后继操作,因此其表现测试不可能等于记录的 true。 + + + **L136** extend 情况通过自反性满足所需变化身份。 + + + **L137** 反方向中,代入变化等于 extend 的假设。 + + + **L138** 单元素记录列表的成员关系把任意记录确定为这一准确变化记录;先代入,再检查测试。 + + + **L139** 计算真实 extend 表现记录;其零输入后继测试等于记录的 true。 + + + **L140** 说明 transitionSupported 的预定范围。对应声明涉及:从表现识别、实际新增操作及报告内容,证明每个兼容变化都发生扩展。 该注释用于解释,不是证明前提。 + + + **L141** 陈述经检查的结果 transitionSupported。从表现识别、实际新增操作及报告内容,证明每个兼容变化都发生扩展。 后续策略块证明这一显式类型。 + + + **L142** 任取变化及其与真实表现记录的相容性,证明同一变化发生扩展。 + + + **L143** 用 transitionPerformanceCompatible 把每个与表现证据相容的变化确定为 extend。 + + + **L144** 用 extend 替换变化,使剩余成就主张针对其真实扩展后状态。 + + + **L145** 针对真实前后状态检查同一系统生成的 extend 报告:后继操作确为新增建构,并把输入 0 变为输出 1。 + + + **L146** 针对真实前后状态检查同一系统生成的 extend 报告:后继操作确为新增建构,并把输入 0 变为输出 1。 + + + **L147** 针对真实前后状态检查同一系统生成的 extend 报告:后继操作确为新增建构,并把输入 0 变为输出 1。 + + + **L148** 将 announcementClaimImpliesExpansion 应用于已核实报告内容,得到同一变化的 Expanded 主张。 + + + **L149** 说明 transitionFacet 的预定范围。对应声明涉及:把表现记录、零输入范围及精确扩展主张组成经验面向。 该注释用于解释,不是证明前提。 + + + **L150** 定义 transitionFacet。把表现记录、零输入范围及精确扩展主张组成经验面向。 + + + **L151** 从表现记录构造经验方面,并采用准确的输入 0 变化范围。 + + + **L152** 其结论为同一变化的成就,不确定性谓词明确为 True。 + + + **L153** 说明 transitionFacetDischarged 的预定范围。对应声明涉及:以扩展为非空见证,提供真实模型支持和恒真不确定性条件。 该注释用于解释,不是证明前提。 + + + **L154** 陈述经检查的结果 transitionFacetDischarged。以扩展为非空见证,提供真实模型支持和恒真不确定性条件。 后续策略块证明这一显式类型。 + + + **L155** 提供 extend 作为非空经验见证,包含相容表现证据与共同输入 0 范围;留下范围内支持及不确定性检查。 + + + **L156** 已证的变化支持为任意相容变化提供成就结论,因此也在所选范围内成立。 + + + **L157** 明确不受限的不确定性谓词为 True,因此该适配器组件直接成立;并未推得定量不确定性界限。 + + + **L158** 说明 transitionAccountable 的预定范围。对应声明涉及:用同一成就主张、范围、规范表达及已检查面向建立成就Grounds。 该注释用于解释,不是证明前提。 + + + **L159** 陈述经检查的结果 transitionAccountable。用同一成就主张、范围、规范表达及已检查面向建立成就Grounds。 + + + **L160** 陈述真实变化成就谓词的问责,并采用规范表述。 + + + **L161** 声明 transitionFacet 为唯一适用方面,并使用准确的单元素证据组合。 + + + **L162** 把问责拆为方面列表非空、覆盖实际适用性,以及各列出方面的匹配表述与履行。 + + + **L163** 适用性假设把方面确定为规定的唯一方面,因此它属于该单元素列表。 + + + **L164** 单元素成员关系把当前方面确定为规定方面;代入后检查其准确主张与依据。 + + + **L165** 组合主张相同、规范表述非空、表述与同一方面的语义连接,以及 transitionFacetDischarged。 + + + **L166** 组合主张相同、规范表述非空、表述与同一方面的语义连接,以及 transitionFacetDischarged。 + + + **L167** 说明 transitionReportCompatible 的预定范围。对应声明涉及:证明两种变化都能产生相同的宣称操作、输入和输出记录。 该注释用于解释,不是证明前提。 + + + **L168** 陈述经检查的结果 transitionReportCompatible。证明两种变化都能产生相同的宣称操作、输入和输出记录。 + + + **L169** 陈述该变化的积极报告记录与变化自身相容,也包括 inflate。 + + + **L170** 单元素记录列表的成员关系把任意记录确定为这一准确变化记录;先代入,再检查测试。 + + + **L171** 报告测试只检查真实的积极公告内容,两种变化中的公告内容计算结果相同。 + + + **L172** 说明 transitionReportDoesNotSupport 的预定范围。对应声明涉及:以库存膨胀变化作为符合自述却未实现成就的反模型。 该注释用于解释,不是证明前提。 + + + **L173** 陈述经检查的结果 transitionReportDoesNotSupport。以库存膨胀变化作为符合自述却未实现成就的反模型。 + + + **L174** 要求 inflate 匹配报告,却未满足同一成就谓词。 + + + **L175** 因此断言积极报告记录不能在全部相容变化上支持该成就。 + + + **L176** 展开 inflate 变化:理解和建构操作集合均未改变,因此不存在 Expanded 要求的新操作见证。 + + + **L177** 展开 inflate 变化:理解和建构操作集合均未改变,因此不存在 Expanded 要求的新操作见证。 + + + **L178** 组合 inflate 处的积极报告相容性与扩展主张为假;任何假定支持应用于此都会产生矛盾。 + + + **L179** 说明 ConcreteAchievementExample 的预定范围。对应声明涉及:组合同对象成就责任与获支持扩展,以及不获支持膨胀自述,并保留前后状态和输入身份。 该注释用于解释,不是证明前提。 + + + **L180** 定义 ConcreteAchievementExample。组合同对象成就责任与获支持扩展,以及不获支持膨胀自述,并保留前后状态和输入身份。 + + + **L181** 具体实例包含真实变化成就的实际问责。 + + + **L182** 其实际适用性谓词与列表确定同一个变化方面。 + + + **L183** 要求 extend 满足真实表现观测。 + + + **L184** 要求成就具有语义支持,且在 extend 处为真。 + + + **L185** 还保留与报告相容但该成就为假的 inflate 世界。 + + + **L186** 陈述由此得到的仅凭报告支持失败。 + + + **L187** 对每种变化,把报告前状态绑定到真实变化前状态。 + + + **L188** 把报告后状态绑定到同一变化的真实后状态。 + + + **L189** 把报告输入绑定到真实变化输入,并明确把该条件固定为 0。 + + + **L190** 说明 concreteAchievementExample 的预定范围。对应声明涉及:组合实际表现支持、自述反模型和精确状态与输入联系。 该注释用于解释,不是证明前提。 + + + **L191** 陈述经检查的结果 concreteAchievementExample。组合实际表现支持、自述反模型和精确状态与输入联系。 后续策略块证明这一显式类型。 + + + **L192** 在具体实例中组合真实成就的问责、extend 表现相容性与语义支持。 + + + **L193** 将同一支持应用于 extend 见证,确立该处的实际扩展。 + + + **L194** 纳入与报告相容的 inflate 反例,留下前后状态与输入相同的关系证明。 + + + **L195** 对任一变化,所有报告与状态连接及输入 0 的关系均由定义本身成立。 + + + **L196** 说明 achievementNeedsSupport 的预定范围。对应声明涉及:对任意实际主张应用所给兼容性与支持,并另附已检查的具体变化实例。 该注释用于解释,不是证明前提。 + + + **L197** 陈述经检查的结果 achievementNeedsSupport。对任意实际主张应用所给兼容性与支持,并另附已检查的具体变化实例。 + + + **L198** 假定所选实际世界匹配全部记录,且这些记录已经支持成就。 + + + **L199** 得出该实际世界中的成就为真,并附带另行构造的具体成就实例。 + + + **L200** 把已假定支持应用于实际证据相容世界,并将该局部真值与另行证明的具体成就实例组合。 + + + **L201** 说明 supportWeakening 的预定范围。对应声明涉及:同一证据支持p且p在每个世界推出q时,也支持较弱结论q。 该注释用于解释,不是证明前提。 + + + **L202** 陈述经检查的结果 supportWeakening。同一证据支持p且p在每个世界推出q时,也支持较弱结论q。 + + + **L203** 假定 p 已获支持且逐世界有 p 蕴含 q;使用相同记录得出 q 已获支持。 + + + **L204** 在每个相容世界 w,先用不变记录得出 p,再应用给定蕴含 weaker 得到 q。 + + + **L205** 说明 evidenceWeakeningCanLoseSupport 的预定范围。对应声明涉及:真布尔观察支持世界为真,删除该记录后假世界成为反例。 该注释用于解释,不是证明前提。 + + + **L206** 陈述经检查的结果 evidenceWeakeningCanLoseSupport。真布尔观察支持世界为真,删除该记录后假世界成为反例。 + + + **L207** 单一恒等观测支持布尔世界为 true。 + + + **L208** 删除该观测后记录为空,不能支持未改变的主张。 + + + **L209** 分开单条记录支持主张与删除该记录后同一主张不获支持两个目标。 + + + **L210** 从相容性读出有信息的恒等测试,它直接表明布尔世界为 true。 + + + **L211** 没有记录时 false 也相容;在该处检验假定支持,否定未改变的真世界主张。 + + + **L212** 说明 scopeRestriction 的预定范围。对应声明涉及:在narrow包含于wide的明确前提下,将支持结论的量词域缩窄。 该注释用于解释,不是证明前提。 + + + **L213** 陈述经检查的结果 scopeRestriction。在narrow包含于wide的明确前提下,将支持结论的量词域缩窄。 + + + **L214** 接收广域与窄域,并假定每个窄域输入均属于广域。 + + + **L215** 假定相同记录支持广域中每个输入上的 p。 + + + **L216** 得出窄域中每个输入上的支持;证据与谓词 p 都不改变。 + + + **L217** 对相容世界与窄域输入 x,included 将窄域成员关系转为广域成员关系,再在该处应用原广域支持。 + + + **L218** 说明 Duties 的预定范围。对应声明涉及:要求每个声明适用的面向完成其相应检查。 该注释用于解释,不是证明前提。 + + + **L219** 定义 Duties。要求每个声明适用的面向完成其相应检查。 + + + **L220** 要求每个实际适用方面通过其自身履行条件。 + + + **L221** 定义 LabeledDuties。完全忽略标签,保留由适用性决定的义务。 + + + **L222** 把带标签责任定义为原有适用性责任;标签不提供豁免。 + + + **L223** 说明 assessmentUnion 的预定范围。对应声明涉及:用析取分支证明适用面向并集的义务等价于分别履行两部分。 该注释用于解释,不是证明前提。 + + + **L224** 陈述经检查的结果 assessmentUnion。用析取分支证明适用面向并集的义务等价于分别履行两部分。 + + + **L225** 将两个适用性谓词并集的责任等同于两组责任均履行。 + + + **L226** 证明并集适用性谓词的责任与两个组成部分同时履行责任之间的两个方向。 + + + **L227** 利用对应析取嵌入,把并集责任分别限制到各适用方面谓词。 + + + **L228** 拆出两组责任,把实际适用性分为左右情况,并用对应责任履行同一方面。 + + + **L229** 说明 labelsCannotWaive 的预定范围。对应声明涉及:标签不进入义务定义,因此改变标签不改变义务。 该注释用于解释,不是证明前提。 + + + **L230** 陈述经检查的结果 labelsCannotWaive。标签不进入义务定义,因此改变标签不改变义务。 + + + **L231** 只改变标签列表不改变责任命题;该等价由自反性成立。 + + + **L232** 说明 switchRecord 的预定范围。对应声明涉及:记录布尔恒等测试结果为真。 该注释用于解释,不是证明前提。 + + + **L233** 定义 switchRecord。记录布尔恒等测试结果为真。 + + + **L234** 陈述经检查的结果 switchCompatible。证明与单条switch观察相容等价于布尔世界为真。 后续策略块证明这一显式类型。 + + + **L235** 证明与单元素开关记录相容,当且仅当真实布尔世界为 true。 + + + **L236** 把记录相容性应用于唯一指定测试,恢复其真实观测等式。 + + + **L237** 反方向中,单元素成员关系把任意列出记录确定为该测试,其等式即为给定观测前提。 + + + **L238** 陈述经检查的结果 switchSupported。从兼容性等价关系抽取被记录的真值结论。 给出的证明项使用所示构造见证或先前引理,而不增加公理。 + + + **L239** 使用 switchCompatible 的正向蕴含,从同一世界真实记录相容性提取 world=true。 + + + **L240** 说明 optionBenefit 的预定范围。对应声明涉及:选择true时收益为四,否则为零。 该注释用于解释,不是证明前提。 + + + **L241** 定义 optionBenefit。选择true时收益为四,否则为零。 + + + **L242** 定义 optionCost。选择true时成本为三,否则为零。 + + + **L243** 说明 optionReport 的预定范围。对应声明涉及:陈述与选项对应的成本和收益事实,不使用无关根据标记。 该注释用于解释,不是证明前提。 + + + **L244** 定义 optionReport。陈述与选项对应的成本和收益事实,不使用无关根据标记。 + + + **L245** 选项报告断言真实成本至多为 3,以及开启收益为 4、关闭收益为 0。 + + + **L246** 说明 switchPosition 的预定范围。对应声明涉及:采纳true选项,使用实际成本收益、成本小于收益目标、预算约束和范围内批评响应。 该注释用于解释,不是证明前提。 + + + **L247** 定义 switchPosition。采纳true选项,使用实际成本收益、成本小于收益目标、预算约束和范围内批评响应。 + + + **L248** 使用布尔选项表示开启与关闭。 + + + **L249** 以自然数对表示各后果的真实收益与成本。 + + + **L250** 明确采纳开启选项;采纳本身不是从算术推导的。 + + + **L251** 直接从布尔世界读取实际选择。 + + + **L252** 从同一真实选项计算收益与成本。 + + + **L253** 采纳真实收益严格超过真实成本这一目标。 + + + **L254** 按固定预算 3 检查实际选项成本。 + + + **L255** 假定实际布尔选择为开启;不把受评收益结论加入起点理论。 + + + **L256** 以按选项索引的真实成本与收益报告为唯一理由。 + + + **L257** 此例使用不受限世界范围;起点假设与理由内容仍约束程序。 + + + **L258** 把实际选择关闭的世界标记为相关批评情况。 + + + **L259** 给两个世界提供不同非空信息,包括在批评情况下重新考虑预算。 + + + **L260** 陈述经检查的结果 switchValueProcedure。提供一致采纳见证,由实际成本收益理由得到目标与约束,并检查两个布尔情形的响应。 后续策略块证明这一显式类型。 + + + **L261** 拆分 switchPosition 的理由非空、共同采纳见证、全部理由支持后果,以及回应批评的义务。 + + + **L262** 选择世界 true,满足起点选择、不受限限度与采纳选项,留下实际理由待检查。 + + + **L263** 任取 switchPosition 列表中的理由;下一步将在采纳的开启见证处确定其真实 optionReport 内容。 + + + **L264** 单元素成员关系把任意理由确定为针对该立场采纳选项的 optionReport;代入这一实际理由。 + + + **L265** 单元素成员关系把任意理由确定为针对该立场采纳选项的 optionReport;代入这一实际理由。 + + + **L266** 检查采纳的开启选项满足已记录成本界限与所述收益值。 + + + **L267** 对处于所述起点与限度条件的任意世界,假定全部有效理由合取。 + + + **L268** 从理由合取提取实际 optionReport 理由,而不是引入独立支持标签。 + + + **L269** 展开被采纳的选项:该证据针对开启选项。 + + + **L270** 利用已报告收益等式证明开启选项收益大于 3。 + + + **L271** 组合成本至多为 3 与收益大于 3,证明成本小于收益,并保留同一成本界限作为约束。 + + + **L272** 检查两个布尔世界,在需要回应批评时提供已记录的非空回应。 + + + **L273** 说明 oppositePosition 的预定范围。对应声明涉及:把采纳选项改为false并更新起点选择,保留同一结果模型和目标。 该注释用于解释,不是证明前提。 + + + **L274** 定义 oppositePosition。把采纳选项改为false并更新起点选择,保留同一结果模型和目标。 + + + **L275** 把采纳选项与起点选择都改为关闭,同时保留真实后果与理由解释。 + + + **L276** 说明 oppositePositionRejected 的预定范围。对应声明涉及:false可被联合采纳,但不满足原成本小于收益目标,故程序检查拒绝。 该注释用于解释,不是证明前提。 + + + **L277** 陈述经检查的结果 oppositePositionRejected。false可被联合采纳,但不满足原成本小于收益目标,故程序检查拒绝。 后续策略块证明这一显式类型。 + + + **L278** 在世界 false 为相反的关闭立场构造真实共同采纳见证;后续拒绝因此不依赖空域。 + + + **L279** 在世界 false 为相反的关闭立场构造真实共同采纳见证;后续拒绝因此不依赖空域。 + + + **L280** 在相反立场的 false 世界见证处任取列出理由,再检查关闭选项真实报告。 + + + **L281** 单元素成员关系把任意理由确定为针对该立场采纳选项的 optionReport;代入这一实际理由。 + + + **L282** 单元素成员关系把任意理由确定为针对该立场采纳选项的 optionReport;代入这一实际理由。 + + + **L283** 关闭选项自身的报告为真:零成本满足界限,零收益符合所述报告。 + + + **L284** 保留非空共同见证,另行否定相反价值程序的履行。 + + + **L285** 假定相反关闭立场满足完整 ValueProcedure,以从零收益后果导出矛盾。 + + + **L286** 在应用后果要求之前,先在相反立场的实际 false 世界见证处组合其全部理由。 + + + **L287** 任取相反立场真实理由,在其非空 false 世界反例处组合全部理由。 + + + **L288** 单元素成员关系把任意理由确定为针对该立场采纳选项的 optionReport;代入这一实际理由。 + + + **L289** 单元素成员关系把任意理由确定为针对该立场采纳选项的 optionReport;代入这一实际理由。 + + + **L290** 关闭选项自身的报告为真:零成本满足界限,零收益符合所述报告。 + + + **L291** 将假定的相反程序之联合理由后果条款,应用于同一起点与限度见证及其全部真实理由。 + + + **L292** 其假定目标要求关闭选项零成本严格小于零收益,与严格小于的非自反性矛盾。 + + + **L293** 说明 contradictoryStartingPosition 的预定范围。对应声明涉及:把起点换为恒假单项理论,使联合采纳见证不存在。 该注释用于解释,不是证明前提。 + + + **L294** 定义 contradictoryStartingPosition。把起点换为恒假单项理论,使联合采纳见证不存在。 + + + **L295** 把起点理论替换为不可能的单元素主张 False。 + + + **L296** 定义 impossibleAdoptionPosition。始终选择false却仍采纳true,使联合采纳不可能。 + + + **L297** 保留采纳的开启选项,却使所有实际选择为关闭,因此无法共同采纳。 + + + **L298** 说明 inadmissibleValuePositionsRejected 的预定范围。对应声明涉及:通过必需的联合见证分别拒绝不一致起点和不可能采纳。 该注释用于解释,不是证明前提。 + + + **L299** 陈述经检查的结果 inadmissibleValuePositionsRejected。通过必需的联合见证分别拒绝不一致起点和不可能采纳。 + + + **L300** 分别否定矛盾起点假设与不可能实际采纳的程序。 + + + **L301** 分开矛盾起点理论与不可能选择、采纳组合两个拒绝证明。 + + + **L302** 从假定满足程序的矛盾起点立场中提取共同采纳见证。 + + + **L303** 单元素起点理论在该见证处要求 False,直接否定其模型证明。 + + + **L304** 从假定的共同见证中提取无法实现的实际选择与采纳组合之间的相等关系。 + + + **L305** 所需采纳等式令不同布尔选项相等,因此该见证不存在。 + + + **L306** 说明 unsupportedPosition 的预定范围。对应声明涉及:复制实际价值立场但删除理由,使非空理由要求失败。 该注释用于解释,不是证明前提。 + + + **L307** 定义 unsupportedPosition。复制实际价值立场但删除理由,使非空理由要求失败。 + + + **L308** 定义 switchEmpirical。以switch观察支持世界为真,范围和不确定性谓词均为真。 + + + **L309** 使用真实开关观测、不受限范围与同一已开启主张;不确定性明确为 True。 + + + **L310** 陈述经检查的结果 switchEmpiricalDischarged。给true兼容见证、实际支持及平凡不确定性,完成经验检查。 后续策略块证明这一显式类型。 + + + **L311** 用 true 作为与开关记录和不受限经验范围相容的非空世界。 + + + **L312** 同一开关记录的语义支持,在每个相容世界证明范围内的开关主张。 + + + **L313** 履行明确为真的不确定性谓词,不增加经验置信度主张。 + + + **L314** 说明 mixedMissingResponsibility 的预定范围。对应声明涉及:经验面向通过,但同一主张的价值面缺理由,故混合义务整体失败。 该注释用于解释,不是证明前提。 + + + **L315** 陈述经检查的结果 mixedMissingResponsibility。经验面向通过,但同一主张的价值面缺理由,故混合义务整体失败。 + + + **L316** 保留真实经验开关方面的成功履行。 + + + **L317** 即使标签为空也否定全部混合责任,因为真实价值方面同样适用,却缺少已记录理由。 + + + **L318** 保留有效的经验开关方面,另行否定全部混合责任已经履行。 + + + **L319** 假定每个实际混合方面均已履行,包括已记录理由列表为空的价值方面。 + + + **L320** 从实际适用并集中选取价值方面,并提取理由列表必须非空的条件。 + + + **L321** 该理由列表依定义为空,因此否定的是这一已记录程序要求。 + + + **L322** 说明 uninformativeArgument 的预定范围。对应声明涉及:构造有概念、有恒真理由却无实质假设的表达。 该注释用于解释,不是证明前提。 + + + **L323** 定义 uninformativeArgument。构造有概念、有恒真理由却无实质假设的表达。 + + + **L324** 用空假设与 True 理由表述开关概念;这些非空文字不约束开关世界。 + + + **L325** 陈述经检查的结果 articulationNotSupport。表达非空不代表其空假设蕴涵世界为真。 + + + **L326** 无信息表述的真实假设不蕴含世界为 true。 + + + **L327** 把非空却无信息的概念与理由,和空理论已证的不能蕴含开关主张组合。 + + + **L328** 把非空却无信息的概念与理由,和空理论已证的不能蕴含开关主张组合。 + + + **L329** 说明 unrelatedArticulationRejected 的预定范围。对应声明涉及:虽表达非空且经验面向通过,两者的假设不匹配,不能视为同一根据表达。 该注释用于解释,不是证明前提。 + + + **L330** 陈述经检查的结果 unrelatedArticulationRejected。虽表达非空且经验面向通过,两者的假设不匹配,不能视为同一根据表达。 + + + **L331** 保留无关表述的程序存在性及开关方面的真实履行。 + + + **L332** 仍否定该无关表述与这一经验方面的语义匹配。 + + + **L333** 保留表述与有效开关证据,再单独检验这一无关表述是否真正匹配该方面。 + + + **L334** 假定无信息表述尽管前提理论为空,仍与 switchEmpirical 语义匹配。 + + + **L335** 在相容性主张自身处,计算假定的表述假设与经验相容性假设相等。 + + + **L336** 经验单元素理论包含该相容性主张,而无关空理论不包含;假定的相等推出 False。 + + + **L337** 使用所示局部证据或已证引理完成 unrelatedArticulationRejected 的这一组件;该组件属于下列固定结果:虽表达非空且经验面向通过,两者的假设不匹配,不能视为同一根据表达。 + + + **L338** 说明 temperatureRecord 的预定范围。对应声明涉及:只观测布尔对第一坐标,未观测第二坐标。 该注释用于解释,不是证明前提。 + + + **L339** 定义 temperatureRecord。只观测布尔对第一坐标,未观测第二坐标。 + + + **L340** 陈述经检查的结果 temperatureCompatible。复制第一坐标记录仍允许第二坐标为任意布尔值。 + + + **L341** 对任意输出坐标 b,重复温度记录仍与 (true,b) 相容。 + + + **L342** 对任意输出坐标 b,重复列表的成员关系仍选取同一温度测试;其观测的第一坐标为 true,而 b 不受约束。 + + + **L343** 对任意输出坐标 b,重复列表的成员关系仍选取同一温度测试;其观测的第一坐标为 true,而 b 不受约束。 + + + **L344** 对任意输出坐标 b,重复列表的成员关系仍选取同一温度测试;其观测的第一坐标为 true,而 b 不受约束。 + + + **L345** 对任意输出坐标 b,重复列表的成员关系仍选取同一温度测试;其观测的第一坐标为 true,而 b 不受约束。 + + + **L346** 说明 BudgetWorld 的预定范围。对应声明涉及:世界由行动布尔值和自然数预算组成。 该注释用于解释,不是证明前提。 + + + **L347** 引入类型缩写 BudgetWorld。世界由行动布尔值和自然数预算组成。 + + + **L348** 说明 announcement 的预定范围。对应声明涉及:定义固定行动宣告字符串,字符串自身不提供预算依据。 该注释用于解释,不是证明前提。 + + + **L349** 定义 announcement。定义固定行动宣告字符串,字符串自身不提供预算依据。 + + + **L350** 定义 announcementPosition。仅用行动自述作为选项理由,却要求实际成本收益及可用预算。 + + + **L351** 使用布尔选项表示开启与关闭。 + + + **L352** 以自然数对表示各后果的真实收益与成本。 + + + **L353** 明确采纳开启选项;采纳本身不是从算术推导的。 + + + **L354** 从第一坐标读取实际选择,同时让预算独立变化。 + + + **L355** 从同一真实选项计算收益与成本。 + + + **L356** 采纳真实收益严格超过真实成本这一目标。 + + + **L357** 比较采纳选项真实成本与该世界独立给定的预算。 + + + **L358** 固定选择为开启,不增加可负担性或预算假设。 + + + **L359** 使用真实按选项区分的公告文本作为理由;它不说明可用预算。 + + + **L360** 此例使用不受限世界范围;起点假设与理由内容仍约束程序。 + + + **L361** 把预算低于 3 认定为对该成本为 3 行动的相关批评。 + + + **L362** 记录成本超预算时重新考虑行动的非空信息。 + + + **L363** 说明 announcementHasJointAdoption 的预定范围。对应声明涉及:构造行动为真、预算零且自述理由成立的世界;后续失败不是缺少采纳见证。 该注释用于解释,不是证明前提。 + + + **L364** 陈述经检查的结果 announcementHasJointAdoption。构造行动为真、预算零且自述理由成立的世界;后续失败不是缺少采纳见证。 后续策略块证明这一显式类型。 + + + **L365** 选择已开启且预算为 0 的世界作为共同采纳见证;起点理论固定选择,却不假定可负担性。 + + + **L366** 在已开启且零预算的共同见证处任取公告理由。 + + + **L367** 根据成员关系,把实际理由确定为按选项索引的公告文本,再特化到采纳的开启选项。 + + + **L368** 根据成员关系,把实际理由确定为按选项索引的公告文本,再特化到采纳的开启选项。 + + + **L369** 根据成员关系,把实际理由确定为按选项索引的公告文本,再特化到采纳的开启选项。 + + + **L370** 实际公告等于开启选项的启动文本;这证明公告理由成立,不证明预算约束。 + + + **L371** 说明 announcementNotBudgetReason 的预定范围。对应声明涉及:预算零时,已采纳行动及非空真自述仍不能满足预算后果,故程序不成立。 该注释用于解释,不是证明前提。 + + + **L372** 陈述经检查的结果 announcementNotBudgetReason。预算零时,已采纳行动及非空真自述仍不能满足预算后果,故程序不成立。 + + + **L373** 要求公告理由非空,并在已开启且预算 0 处实际采纳。 + + + **L374** 在同一零预算世界,全部真实公告理由成立。 + + + **L375** 仍否定真实后果及整个价值程序。 + + + **L376** 组合非空公告理由与真实公告,否定零预算后果,留下整个程序失败的证明。 + + + **L377** 为预算 0 处的理由合取,任取真实公告理由列表成员。 + + + **L378** 根据成员关系,把实际理由确定为按选项索引的公告文本,再特化到采纳的开启选项。 + + + **L379** 根据成员关系,把实际理由确定为按选项索引的公告文本,再特化到采纳的开启选项。 + + + **L380** 实际公告等于开启选项的启动文本;这证明公告理由成立,不证明预算约束。 + + + **L381** 假定公告立场满足 ValueProcedure,以在预算 0 处检验其后果条款。 + + + **L382** 在同一已开启且预算为零的世界收集全部公告理由。 + + + **L383** 为该条款提供全部理由,在同一零预算世界任取公告理由。 + + + **L384** 根据成员关系,把实际理由确定为按选项索引的公告文本,再特化到采纳的开启选项。 + + + **L385** 根据成员关系,把实际理由确定为按选项索引的公告文本,再特化到采纳的开启选项。 + + + **L386** 实际公告等于开启选项的启动文本;这证明公告理由成立,不证明预算约束。 + + + **L387** 把假定程序应用于这一非空的零预算起点、限度实例及其真实公告理由。 + + + **L388** 所得成本约束要求成本 3 不超过预算 0,这是不可能的。 + + + **L389** 说明 actionRecord 的预定范围。对应声明涉及:只观测行动布尔值,不限制预算。 该注释用于解释,不是证明前提。 + + + **L390** 定义 actionRecord。只观测行动布尔值,不限制预算。 + + + **L391** 陈述经检查的结果 actionCompatible。两个重复行动记录仍与任意预算相容。 后续策略块证明这一显式类型。 + + + **L392** 重复列表中的每条行动记录只测试实际已开启坐标,因此任意给定预算仍相容。 + + + **L393** 说明 measurementRepeatNotSupport 的预定范围。对应声明涉及:用未观测坐标和预算零反例,分别拒绝单次及重复测量对无关结论和价值后果的支持。 该注释用于解释,不是证明前提。 + + + **L394** 陈述经检查的结果 measurementRepeatNotSupport。用未观测坐标和预算零反例,分别拒绝单次及重复测量对无关结论和价值后果的支持。 + + + **L395** 即使独立输出坐标为 false,真实温度测试仍返回 true。 + + + **L396** 在重复温度观测下保留该假输出世界。 + + + **L397** 在相同重复观测下也保留真输出世界。 + + + **L398** 单条温度记录不支持另一输出为 true。 + + + **L399** 重复该温度记录仍不支持另一输出为 true。 + + + **L400** 重复观测到启动与已开启、预算为 0 相容。 + + + **L401** 相同重复记录也与预算为 3 相容。 + + + **L402** 单条启动记录不支持该选项的真实目标与预算后果。 + + + **L403** 重复启动记录不能修复这一后果支持缺失。 + + + **L404** 基于公告的价值程序也未满足同一实际选项与约束。 + + + **L405** 记录观测真实值为 true,以及两个温度相容的输出选择,留下输出主张不获支持的反证。 + + + **L406** 保留预算 0 与预算 3 两个行动相容世界及已证的公告程序失败,留下可负担性支持主张的反证。 + + + **L407** 假定单次温度观测支持独立表示的第二输出为 true。 + + + **L408** 将假定的单记录输出支持应用于 (true,false):其温度观测为真,另一输出主张却为假。 + + + **L409** 将假定的单记录输出支持应用于 (true,false):其温度观测为真,另一输出主张却为假。 + + + **L410** 同一 (true,false) 反世界仍与重复温度记录相容,因此否定重复数据支持输出的主张。 + + + **L411** 假定单次行动观测支持采纳选项的收益与预算后果。 + + + **L412** 单次观测到启动与预算 0 相容;假定支持该处后果会迫使不可能的成本约束。 + + + **L413** 单次观测到启动与预算 0 相容;假定支持该处后果会迫使不可能的成本约束。 + + + **L414** 重复启动记录仍保留同一零预算反世界,因此仍不支持实际可负担后果。 + + + **L415** 说明 selfAssertionNotReason 的预定范围。对应声明涉及:组合无理由与非空但无预算依据的自断言反例,并为后者提供联合采纳见证。 该注释用于解释,不是证明前提。 + + + **L416** 陈述经检查的结果 selfAssertionNotReason。组合无理由与非空但无预算依据的自断言反例,并为后者提供联合采纳见证。 + + + **L417** 缺少理由的立场可以被实际采纳,却未通过其记录程序。 + + + **L418** 更强的公告实例具有非空理由,并在预算 0 处实际采纳。 + + + **L419** 其真实后果及程序仍失败,因为同一采纳选项超出预算。 + + + **L420** 保留真实共同采纳见证,排除以空起点域解释此失败。 + + + **L421** 按定义证明 unsupportedPosition.commitment true;若假定存在 ValueProcedure,则其理由非空要求与实际空理由列表矛盾。 + + + **L422** 复用 announcementNotBudgetReason 中非空真实公告理由与采纳等式。 + + + **L423** 还复用同一零预算后果及整个公告程序的失败。 + + + **L424** 保留 announcementHasJointAdoption,因此该失败不能由空或不一致起点域解释。 + + + **L425** 说明 valueWithoutSelfProof 的预定范围。对应声明涉及:给出有理由且一致、却不能由空假设推出的立场,并拒绝相反选项、不一致起点和不可能采纳变体。 该注释用于解释,不是证明前提。 + + + **L426** 陈述经检查的结果 valueWithoutSelfProof。给出有理由且一致、却不能由空假设推出的立场,并拒绝相反选项、不一致起点和不可能采纳变体。 + + + **L427** 要求开关立场的真实起点理论具有模型。 + + + **L428** 否定从空布尔理论推导其采纳承诺。 + + + **L429** 相反立场具有共同见证,却未通过后果评估。 + + + **L430** 还拒绝矛盾起点与无法采纳的变体,区分未由自身推得与不一致起点。 + + + **L431** 组合真实开关程序、作为起点模型的 true 世界,以及采纳主张不由 emptyTheory 蕴含。 + + + **L432** 加入非空相反选项的拒绝,以及矛盾起点与无法采纳两个单独变体。 + + + **L433** 说明 BenefitCostWorld 的预定范围。对应声明涉及:世界保存所选布尔选项及可变收益和成本。 该注释用于解释,不是证明前提。 + + + **L434** 引入类型缩写 BenefitCostWorld。世界保存所选布尔选项及可变收益和成本。 + + + **L435** 定义 measuredOutcome。true选项返回世界的收益成本对,false结果为零与零。 + + + **L436** 开启选项读取世界真实收益与成本对;关闭选项得到 (0,0)。 + + + **L437** 定义 benefitReason。要求同一选项测得收益为四。 + + + **L438** 收益理由要求实际选项的测得收益等于 4。 + + + **L439** 定义 costReason。要求该选项测得成本至多三。 + + + **L440** 成本理由要求同一选项的测得成本至多为 3。 + + + **L441** 说明 jointReasonPosition 的预定范围。对应声明涉及:用相互独立的选项收益与成本理由,共同支持采纳选项目标及预算。 该注释用于解释,不是证明前提。 + + + **L442** 定义 jointReasonPosition。用相互独立的选项收益与成本理由,共同支持采纳选项目标及预算。 + + + **L443** 使用布尔选项表示开启与关闭。 + + + **L444** 以自然数对表示各后果的真实收益与成本。 + + + **L445** 明确采纳开启选项;采纳本身不是从算术推导的。 + + + **L446** 从世界第一坐标读取选择,与测得收益及成本分开。 + + + **L447** 使用 measuredOutcome,使受评选项的真实收益与成本来自该世界。 + + + **L448** 采纳真实收益严格超过真实成本这一目标。 + + + **L449** 要求该选项测得成本至多为 3。 + + + **L450** 假定所选选项为开启,不假定收益或成本结论。 + + + **L451** 同时列出 benefitReason 与 costReason;程序将使用其合取。 + + + **L452** 此例使用不受限世界范围;起点假设与理由内容仍约束程序。 + + + **L453** 把真实测得成本大于 3 识别为相关批评。 + + + **L454** 记录当该选项真实成本超预算时重新评估它的非空回应。 + + + **L455** 说明 jointReasonProcedure 的预定范围。对应声明涉及:以收益四成本三构造联合见证,合用两个理由证明成本低于收益且不超预算。 该注释用于解释,不是证明前提。 + + + **L456** 陈述经检查的结果 jointReasonProcedure。以收益四成本三构造联合见证,合用两个理由证明成本低于收益且不超预算。 后续策略块证明这一显式类型。 + + + **L457** 拆分联合理由立场的理由非空、共同见证、基于合取的后果与批评回应。 + + + **L458** 用已开启、收益为 4、成本为 3 的世界作为共同的起点、限度与采纳见证。 + + + **L459** 在真实 (true,(4,3)) 见证处任取两条理由之一,再拆分成员关系检查各不同理由。 + + + **L460** 展开实际的双元素理由列表:benefitReason 与 costReason。 + + + **L461** 把理由成员关系分为收益理由,或剩余单元素成本理由。 + + + **L462** 代入收益理由,检查见证的测得收益恰为 4。 + + + **L463** 把剩余理由确定为 costReason 并代入。 + + + **L464** 把剩余理由确定为 costReason 并代入。 + + + **L465** 利用自然数序的自反性检查见证的成本界限 3 ≤ 3。 + + + **L466** 对任意被接纳世界,假定全部有效理由共同成立,而不要求任一理由单独充分。 + + + **L467** 在该世界与采纳选项处,从理由合取提取实际 benefitReason。 + + + **L468** 在同一世界与选项处,从同一合取提取 costReason。 + + + **L469** 展开 benefitReason:采纳的开启选项之测得收益等于 4。 + + + **L470** 展开 costReason:同一选项的测得成本至多为 3。 + + + **L471** 保留实际成本约束,只留下收益严格大于成本的目标。 + + + **L472** 把测得收益改写为 4,并检查它大于 3。 + + + **L473** 合成成本至多为 3 与 3 小于收益,使用两个理由确立成本小于收益。 + + + **L474** 对限度内且批评相关的世界,构造针对该选项成本过高的必需回应。 + + + **L475** 提供关于成本超预算时重新评估选项的明确非空回应;这登记回应,不证明其说服充分性。 + + + **L476** 说明 JointReasonsExample 的预定范围。对应声明涉及:表示联合理由程序通过,但任一单独理由都可在后果失败的世界成立。 该注释用于解释,不是证明前提。 + + + **L477** 定义 JointReasonsExample。表示联合理由程序通过,但任一单独理由都可在后果失败的世界成立。 + + + **L478** 要求双理由立场满足完整 ValueProcedure。 + + + **L479** 固定仅满足收益理由的反世界 (true,(4,5)),它满足同一起点假设与限度。 + + + **L480** 在该世界,实际采纳与收益理由均成立。 + + + **L481** 否定该处受评后果,因为真实成本过高。 + + + **L482** 在同一起点假设与限度下固定仅满足成本理由的反世界 (true,(0,3))。 + + + **L483** 在该世界,实际采纳与成本理由成立。 + + + **L484** 否定其受评后果,因为零收益没有超过成本 3。 + + + **L485** 陈述经检查的结果 jointReasonsExample。以收益四成本五及收益零成本三分别反驳单个理由充分。 后续策略块证明这一显式类型。 + + + **L486** 以已检查的双理由程序开始组合实例。 + + + **L487** 提供仅满足收益理由的反世界:收益 4、成本 5,且满足相同起点、限度与采纳条件。 + + + **L488** 在相同条件下提供仅满足成本理由的反世界:收益 0、成本 3。 + + + **L489** 仅有收益理由的世界违反成本约束 5 ≤ 3;自然数算术消去该矛盾。 + + + **L490** 仅有成本理由的世界不可能满足严格目标 3 < 0;算术完成该反例。 + + + **L491** 说明 heterogeneousReasons 的预定范围。对应声明涉及:组合经验、推论、价值实例,并加入任一理由单独不足的真实联合理由实例。 该注释用于解释,不是证明前提。 + + + **L492** 陈述经检查的结果 heterogeneousReasons。组合经验、推论、价值实例,并加入任一理由单独不足的真实联合理由实例。 + + + **L493** 纳入真实已履行的经验开关方面。 + + + **L494** 纳入推论方面,其可满足的真世界前提蕴含同一真世界主张。 + + + **L495** 在此登记定理中纳入真实开关价值程序与双理由共同支持实例。 + + + **L496** 组合已检查经验方面、非空推论单元素理论、价值程序及联合理由反例。 + + + **L497** 对推论方面,其单元素前提在任意模型中直接给出同一真世界主张。 + + + **L499** 说明 zeroRecord 的预定范围。对应声明涉及:只测试布尔函数在自然数零处的输出。 该注释用于解释,不是证明前提。 + + + **L500** 定义 zeroRecord。只测试布尔函数在自然数零处的输出。 + + + **L501** 定义 localGenerator。生成只在seed输入处返回真的布尔函数。 + + + **L502** 说明 allTrue 的预定范围。对应声明涉及:要求函数在每个自然数输入都返回真。 该注释用于解释,不是证明前提。 + + + **L503** 定义 allTrue。要求函数在每个自然数输入都返回真。 + + + **L504** 陈述经检查的结果 zeroCompatible。证明零点记录的兼容性恰好只要求f(0)=true。 后续策略块证明这一显式类型。 + + + **L505** 证明匹配 zeroRecord 与真实函数在输入 0 返回 true 之间的两个方向。 + + + **L506** 把记录相容性应用于唯一指定测试,恢复其真实观测等式。 + + + **L507** 反方向中,单元素成员关系把任意列出记录确定为该测试,其等式即为给定观测前提。 + + + **L508** 说明 GeneratingProcess 的预定范围。对应声明涉及:保存生产者身份、实际旧谓词及修订算法种子。 该注释用于解释,不是证明前提。 + + + **L509** 声明数据接口 GeneratingProcess。保存生产者身份、实际旧谓词及修订算法种子。 + + + **L510** 保存实际生成过程的所有者标识。 + + + **L511** 保存该过程生成修订之前的布尔值函数。 + + + **L512** 保存该过程真实局部生成器使用的种子输入。 + + + **L513** 说明 GeneratingProcess.outputRevision 的预定范围。对应声明涉及:保留旧谓词成功输入,并由实际局部生成器增加种子输入。 该注释用于解释,不是证明前提。 + + + **L514** 定义 GeneratingProcess.outputRevision。保留旧谓词成功输入,并由实际局部生成器增加种子输入。 + + + **L515** 修订函数保留每个原先为真的输出,或在实际生成种子输入处增加真值。 + + + **L516** 说明 ProducedRevision 的预定范围。对应声明涉及:保存生产者及精确旧新谓词对象。 该注释用于解释,不是证明前提。 + + + **L517** 声明数据接口 ProducedRevision。保存生产者及精确旧新谓词对象。 + + + **L518** 标识哪个所有者生成了这一具体修订对象。 + + + **L519** 保存修订的真实前函数。 + + + **L520** 保存修订的真实后函数。 + + + **L521** 说明 GeneratingProcess.produce 的预定范围。对应声明涉及:由该过程构造带自身主体及实际旧函数、输出函数的修订。 该注释用于解释,不是证明前提。 + + + **L522** 定义 GeneratingProcess.produce。由该过程构造带自身主体及实际旧函数、输出函数的修订。 + + + **L523** 直接以该过程的所有者、原函数及计算所得输出修订构造修订对象。 + + + **L524** 定义 sampleGeneratingProcess。以主体十七、恒假旧谓词及零种子构造实际生成过程。 + + + **L525** 说明 OwnedRevisionExample 的预定范围。对应声明涉及:把自身来源与精确旧新函数关联到零输入上的实际变化,而全局主张仍无支持。 该注释用于解释,不是证明前提。 + + + **L526** 定义 OwnedRevisionExample。把自身来源与精确旧新函数关联到零输入上的实际变化,而全局主张仍无支持。 + + + **L527** 把修订生成者标识绑定到真实生成过程所有者。 + + + **L528** 把其前函数绑定到该过程的真实原函数。 + + + **L529** 把其后函数绑定到该过程的真实 outputRevision。 + + + **L530** 要求输入 0 处实际从此前 false 变为此后 true。 + + + **L531** 保留修订后输入 1 处真实为 false 的输出。 + + + **L532** 实际生成的后函数匹配输入 0 观测。 + + + **L533** 该记录仍不支持所有输入为真的主张。 + + + **L534** 说明 ownedRevisionExample 的预定范围。对应声明涉及:计算主体和对象联系,并用自产函数在一处失败反驳全称支持。 该注释用于解释,不是证明前提。 + + + **L535** 陈述经检查的结果 ownedRevisionExample。计算主体和对象联系,并用自产函数在一处失败反驳全称支持。 后续策略块证明这一显式类型。 + + + **L536** 通过计算检查生成者身份、旧对象与输出修订关系及真实样本值;保留零输入记录相容性,留下全称支持的反证。 + + + **L537** 假定 zeroRecord 支持 allTrue,以该所有者实际生成的修订反驳它。 + + + **L538** 把假定支持应用于该所有者实际生成的后函数及输入 1;该修订在此仍返回 false。 + + + **L539** 消去所得 false=true 等式;实际修订构成证据相容反例。 + + + **L540** 说明 selfOriginDoesNotSupport 的预定范围。对应声明涉及:保留局部观察反模型,另加具有同一未获支持全局主张的真实自身旧新修订。 该注释用于解释,不是证明前提。 + + + **L541** 陈述经检查的结果 selfOriginDoesNotSupport。保留局部观察反模型,另加具有同一未获支持全局主张的真实自身旧新修订。 + + + **L542** 计算 localGenerator 0 在 0 处为 true、在 1 处为 false。 + + + **L543** 要求该生成函数匹配同一输入 0 记录。 + + + **L544** 陈述全域支持失败,并纳入具体所有者、原对象与修订关系实例。 + + + **L545** 计算生成函数在 0 与 1 的值,给出零输入记录相容性,并纳入自有修订关系实例。 + + + **L546** 假定局部零输入观测蕴含每个相容函数的全部输入均输出 true。 + + + **L547** 把假定全称支持实例化到 localGenerator 0,再取输入 1;零输入相容性并未约束这一失败输入。 + + + **L548** 消去所得 false=true 等式;实际修订构成证据相容反例。 + + + **L549** 说明 localNotUniversal 的预定范围。对应声明涉及:常真函数与零点真函数都符合局部记录,但只有前者全称成立,故局部记录不支持全称结论。 该注释用于解释,不是证明前提。 + + + **L550** 陈述经检查的结果 localNotUniversal。常真函数与零点真函数都符合局部记录,但只有前者全称成立,故局部记录不支持全称结论。 + + + **L551** 要求至少存在一个自然数输入处于观测单元素范围之外。 + + + **L552** 恒真函数匹配零输入观测。 + + + **L553** 局部生成器也匹配同一观测。 + + + **L554** 第一个函数全域为真,第二个却不是。 + + + **L555** 因此共同观测不支持全域为真。 + + + **L556** 提供观测范围以外的输入,并证明恒真函数与局部生成器都满足同一零输入观测。 + + + **L557** 恒真函数全域为真;保留已知支持反例,留下局部生成器全称主张的反证。 + + + **L558** 在输入 1 检验局部生成器的假定全域真值,而其实际结果为 false。 + + + **L559** 说明 hiddenDifference 的预定范围。对应声明涉及:两函数在零点范围相同,却在一处不同,说明排除范围不能否认相关差异。 该注释用于解释,不是证明前提。 + + + **L560** 陈述经检查的结果 hiddenDifference。两函数在零点范围相同,却在一处不同,说明排除范围不能否认相关差异。 + + + **L561** 只对满足 n=0 的输入陈述两个函数相等。 + + + **L562** 陈述它们在输入 1 处真实输出不等。 + + + **L563** 分开输入 0 范围内一致与输入 1 处真实输出不同两个结论。 + + + **L564** 根据范围前提代入 n=0;两个函数都计算为 true。 + + + **L565** 说明 singleObservation 的预定范围。对应声明涉及:单条记录有兼容见证并支持局部结果,但不支持全输入结论。 该注释用于解释,不是证明前提。 + + + **L566** 陈述经检查的结果 singleObservation。单条记录有兼容见证并支持局部结果,但不支持全输入结论。 + + + **L567** 要求存在与单次观测相容的真实函数,避免空证据语义。 + + + **L568** 该单条记录支持其真实输入 0 主张。 + + + **L569** 它不支持更强的全输入主张。 + + + **L570** 计算记录数量为一,并提供 localGenerator 0 作为真实相容见证。 + + + **L571** 从相容性直接提取获支持的输入 0 事实,并复用已证的 allTrue 支持失败。 + + + **L572** 说明 arithmeticFacet 的预定范围。对应声明涉及:以n=2为假设、n+1=3为结论构造推论面向。 该注释用于解释,不是证明前提。 + + + **L573** 定义 arithmeticFacet。以n=2为假设、n+1=3为结论构造推论面向。 + + + **L574** 定义 usesObservation。只按面向标签判断是否经验型,不判断命题是否可计算。 + + + **L575** 经验方面携带真实测试记录,因此将其分类为使用观测。 + + + **L576** 在此已表示的方法分类器中,把推论与价值方面分类为不使用观测。 + + + **L577** 说明 noUniversalChain 的预定范围。对应声明涉及:以二为模型证明算术推论面向成立且无需经验观察。 该注释用于解释,不是证明前提。 + + + **L578** 陈述经检查的结果 noUniversalChain。以二为模型证明算术推论面向成立且无需经验观察。 后续策略块证明这一显式类型。 + + + **L579** 提供 n=2 作为推论理论的非空见证,并指出其方面构造子不使用观测。 + + + **L580** 任取满足算术方面真实前提理论的自然数世界 n。 + + + **L581** 从真实单元素前提提取 n=2,而不是假定所需后继结论。 + + + **L582** 把算术结论 n+1=3 展开为剩余目标。 + + + **L583** 根据前提把 n 改写为 2;所需算术等式通过计算化简。 + + + **L584** 说明 Trial 的预定范围。对应声明涉及:分别保存设置、实际结果和记录结果三个自然数字段。 该注释用于解释,不是证明前提。 + + + **L585** 声明数据接口 Trial。分别保存设置、实际结果和记录结果三个自然数字段。 + + + **L586** 保存试次设置,与结果分开。 + + + **L587** 保存试次实际结果,无论记录是否准确。 + + + **L588** 保存独立记录的结果,以便比较准确性。 + + + **L589** 说明 Verified 的预定范围。对应声明涉及:记录结果等于给定实际结果即满足此验证谓词。 该注释用于解释,不是证明前提。 + + + **L590** 定义 Verified。记录结果等于给定实际结果即满足此验证谓词。 + + + **L591** 定义 Reproduced。只要求两次设置相等,不要求结果相同。 + + + **L592** 定义 Bounded。要求实际结果不超过固定阈值二。 + + + **L593** 说明 variableOutcomesStableBound 的预定范围。对应声明涉及:同设置的结果一和二不同,却都满足给定范围界限。 该注释用于解释,不是证明前提。 + + + **L594** 陈述经检查的结果 variableOutcomesStableBound。同设置的结果一和二不同,却都满足给定范围界限。 + + + **L595** 固定第一试次:设置 0,实际及记录结果均为 1。 + + + **L596** 固定第二试次:设置相同,实际及记录结果均为 2。 + + + **L597** 要求两个明确固定试次的设置相同、真实结果不同,且都满足 actualOutcome ≤ 2。 + + + **L598** 计算两个相同设置的试次:实际结果 1 与 2 不同,却都满足 actualOutcome ≤ 2。 + + + **L599** 说明 verificationReproductionStability 的预定范围。对应声明涉及:用具体数字分别区分记录准确、设置复现和结果有界。 该注释用于解释,不是证明前提。 + + + **L600** 陈述经检查的结果 verificationReproductionStability。用具体数字分别区分记录准确、设置复现和结果有界。 + + + **L601** 要求两个记录准确但设置不同的试次。 + + + **L602** 要求设置复现,同时第二记录不准确且实际结果超出界限。 + + + **L603** 要求界限保持,即使其中一个结果记录不准确。 + + + **L604** 分别计算各具体试次谓词,展示设置变化、记录不准确及界限失败或保持,而不混淆这些性质。 + + + **L605** 说明 Program 的预定范围。对应声明涉及:定义只含输入翻倍及常量的微型解释程序语法。 该注释用于解释,不是证明前提。 + + + **L606** 声明可选构造 Program。定义只含输入翻倍及常量的微型解释程序语法。 + + + **L607** 提供把实际输入加倍的解释程序语法。 + + + **L608** 提供常量输出解释程序语法,携带其返回自然数。 + + + **L609** 定义 Program.eval。执行翻倍或返回储存常量。 + + + **L610** 通过真实加法 n+n 计算 doubleInput 解释程序在 n 处的结果。 + + + **L611** 通过返回存储值计算常量程序,与输入无关。 + + + **L612** 说明 Process 的预定范围。对应声明涉及:保存实际输出函数和可缺失的解释程序。 该注释用于解释,不是证明前提。 + + + **L613** 声明数据接口 Process。保存实际输出函数和可缺失的解释程序。 + + + **L614** 保存同一过程在自然数输入上的真实输出函数。 + + + **L615** 保存过程可选的已提供解释程序,与输出函数分开。 + + + **L616** 说明 OutputContract 的预定范围。对应声明涉及:要求每个自然数输入的输出等于输入翻倍。 该注释用于解释,不是证明前提。 + + + **L617** 定义 OutputContract。要求每个自然数输入的输出等于输入翻倍。 + + + **L618** 说明 ExplanationContract 的预定范围。对应声明涉及:要求已附程序在所有输入上与同一过程输出相等,不断言因果理解。 该注释用于解释,不是证明前提。 + + + **L619** 定义 ExplanationContract。要求已附程序在所有输入上与同一过程输出相等,不断言因果理解。 + + + **L620** 要求实际提供程序,且其在每个自然数输入的计算等于该过程输出。 + + + **L621** 说明 outputOnlyProcess 的预定范围。对应声明涉及:给出正确翻倍输出,却不提供解释程序。 该注释用于解释,不是证明前提。 + + + **L622** 定义 outputOnlyProcess。给出正确翻倍输出,却不提供解释程序。 + + + **L623** 定义 explainedProcess。给同样输出并附上翻倍程序。 + + + **L624** 说明 processScope 的预定范围。对应声明涉及:把候选范围限定为同一被评过程,不缩窄合同的输入量词域。 该注释用于解释,不是证明前提。 + + + **L625** 定义 processScope。把候选范围限定为同一被评过程,不缩窄合同的输入量词域。 + + + **L626** 用真实等式 candidate=assessed 限制理论模型,而不是假定所需契约。 + + + **L627** 说明 processContractFacet 的预定范围。对应声明涉及:在精确被评过程身份假设下构造合同推论面向。 该注释用于解释,不是证明前提。 + + + **L628** 定义 processContractFacet。在精确被评过程身份假设下构造合同推论面向。 + + + **L629** 用这一准确对象身份范围与给定契约结论构造推论方面。 + + + **L630** 说明 processScopeModels 的预定范围。对应声明涉及:证明满足身份范围恰好等价于候选为同一被评过程。 该注释用于解释,不是证明前提。 + + + **L631** 陈述经检查的结果 processScopeModels。证明满足身份范围恰好等价于候选为同一被评过程。 + + + **L632** 陈述满足该范围恰等于成为受评过程。 + + + **L633** 用等于真实受评 Process 的谓词实例化 modelsSingleton,准确证明哪些候选满足 processScope。 + + + **L634** 说明 processContractDischarged 的预定范围。对应声明涉及:利用给定实际过程合同证明及范围身份等式,完成对应推论检查。 该注释用于解释,不是证明前提。 + + + **L635** 陈述经检查的结果 processContractDischarged。利用给定实际过程合同证明及范围身份等式,完成对应推论检查。 + + + **L636** 使用明确契约证明前提,得出同一对象契约方面的履行。 + + + **L637** 以受评过程自身作为其身份范围的模型,留下契约的语义蕴含。 + + + **L638** 任取候选及其处于真实受评过程身份范围的证明 hc。 + + + **L639** 从范围模型 hc 恢复候选恰为受评过程。 + + + **L640** 代入该过程身份,使契约目标针对实际受评对象。 + + + **L641** 使用明确给出的该对象契约证明前提;此一般辅助结果不会无前提地产生契约正确性。 + + + **L642** 说明 ProcessGrounds 的预定范围。对应声明涉及:为精确过程及合同面向要求规范Grounds,适用范围只含该面向。 该注释用于解释,不是证明前提。 + + + **L643** 定义 ProcessGrounds。为精确过程及合同面向要求规范Grounds,适用范围只含该面向。 + + + **L644** 要求给定契约具有 Grounds,使用规范表述,并将准确受评过程方面认定为适用。 + + + **L645** 列出的证据组合恰好包含同一过程契约方面。 + + + **L646** 陈述经检查的结果 processGrounds。从同一被评过程的实际合同证明构造匹配Grounds。 + + + **L647** 由受评过程处的明确契约证明,得出这些同一对象 ProcessGrounds。 + + + **L648** 把契约履行辅助结果应用于同一受评过程的明确证明。 + + + **L649** 拆分方面非空、准确适用性覆盖,以及各方面的主张、表述与履行义务。 + + + **L650** 适用性假设把方面确定为规定的唯一方面,因此它属于该单元素列表。 + + + **L651** 单元素成员关系把当前方面确定为规定方面;代入后检查其准确主张与依据。 + + + **L652** 组合相同契约主张、非空规范表述、与对象范围的语义连接及已确立履行。 + + + **L653** 说明 outputCorrectByEvaluation 的预定范围。对应声明涉及:从实际输出函数直接证明全输入翻倍,不假定成功标记。 该注释用于解释,不是证明前提。 + + + **L654** 陈述经检查的结果 outputCorrectByEvaluation。从实际输出函数直接证明全输入翻倍,不假定成功标记。 给出的证明项使用所示构造见证或先前引理,而不增加公理。 + + + **L655** 说明 outputOnlyNoExplanation 的预定范围。对应声明涉及:因同一过程储存none而拒绝已附解释程序的存在。 该注释用于解释,不是证明前提。 + + + **L656** 陈述经检查的结果 outputOnlyNoExplanation。因同一过程储存none而拒绝已附解释程序的存在。 后续策略块证明这一显式类型。 + + + **L657** 任何解释契约都需提供程序,令其 some 值等于该过程实际的 none 回应;不同选项构造子使之不可能。 + + + **L658** 说明 FullProcessContract 的预定范围。对应声明涉及:要求同一过程既输出正确,又附有输出一致的解释程序。 该注释用于解释,不是证明前提。 + + + **L659** 定义 FullProcessContract。要求同一过程既输出正确,又附有输出一致的解释程序。 + + + **L660** 说明 OutputContractEvidence 的预定范围。对应声明涉及:组合有根据输出及非空精确过程范围,以该模型反驳更强完整合同。 该注释用于解释,不是证明前提。 + + + **L661** 定义 OutputContractEvidence。组合有根据输出及非空精确过程范围,以该模型反驳更强完整合同。 + + + **L662** 要求真实只输出过程具有输出正确性依据。 + + + **L663** 保留该过程自身作为准确评估范围中的实例。 + + + **L664** 否定同一范围蕴含更强的输出与解释联合契约。 + + + **L665** 说明 outputContractEvidence 的预定范围。对应声明涉及:由计算建立输出Grounds,并用同一过程缺少解释反驳完整合同蕴涵。 该注释用于解释,不是证明前提。 + + + **L666** 陈述经检查的结果 outputContractEvidence。由计算建立输出Grounds,并用同一过程缺少解释反驳完整合同蕴涵。 后续策略块证明这一显式类型。 + + + **L667** 提供真实输出契约的依据及过程自身的范围见证,再在同一范围内否定更强契约。 + + + **L668** 假定该准确过程范围蕴含更强的输出与解释联合契约。 + + + **L669** 在 outputOnlyProcess 自身处实例化假定的完整契约蕴含;其解释部分与已证的解释缺失矛盾。 + + + **L670** 说明 ScopedApplicationEvidence 的预定范围。对应声明涉及:要求两个不同应用合同分别具有Grounds及非空精确过程范围。 该注释用于解释,不是证明前提。 + + + **L671** 定义 ScopedApplicationEvidence。要求两个不同应用合同分别具有Grounds及非空精确过程范围。 + + + **L672** 纳入 outputOnlyProcess 的输出正确性依据。 + + + **L673** 纳入 explainedProcess 的输出与解释联合依据。 + + + **L674** 对每个候选明确第一个范围准确固定为 outputOnlyProcess。 + + + **L675** 同样明确第二个范围准确固定为 explainedProcess。 + + + **L676** 要求两个真实过程身份理论均可满足。 + + + **L677** 说明 scopedApplicationEvidence 的预定范围。对应声明涉及:提供实际全输入输出证明,并为强合同提供翻倍解释程序。 该注释用于解释,不是证明前提。 + + + **L678** 陈述经检查的结果 scopedApplicationEvidence。提供实际全输入输出证明,并为强合同提供翻倍解释程序。 后续策略块证明这一显式类型。 + + + **L679** 通过计算构造只输出依据,并留下有解释过程的更强契约证明。 + + + **L680** 提供准确的过程身份范围等价关系,并用各过程自身作为其非空范围见证。 + + + **L681** 提供准确的过程身份范围等价关系,并用各过程自身作为其非空范围见证。 + + + **L682** 对 explainedProcess,通过自反性证明每个加倍输出,并提供实际给出且外延忠实的解释程序 doubleInput。 + + + **L683** 说明 outputNotExplanation 的预定范围。对应声明涉及:证明输出正确但无已附解释,并附同对象Grounds及反模型证据。 该注释用于解释,不是证明前提。 + + + **L684** 陈述经检查的结果 outputNotExplanation。证明输出正确但无已附解释,并附同对象Grounds及反模型证据。 + + + **L685** 保留该过程解释契约缺失及其范围内输出证据。 + + + **L686** 组合真实输出正确性、同一过程解释缺失及其匹配的范围内输出证据。 + + + **L687** 说明 applicationContractsDiffer 的预定范围。对应声明涉及:证明仅输出不足以满足强合同,解释过程满足两者;两个应用各有对应Grounds。 该注释用于解释,不是证明前提。 + + + **L688** 陈述经检查的结果 applicationContractsDiffer。证明仅输出不足以满足强合同,解释过程满足两者;两个应用各有对应Grounds。 + + + **L689** 只输出过程满足输出正确性,却未满足输出与解释联合契约。 + + + **L690** 有解释过程满足两个真实契约。 + + + **L691** 纳入两个应用契约的明确范围内依据与非空见证。 + + + **L692** 对 outputOnlyProcess 提供真实输出正确性,并通过提取不可能解释组件反驳任何联合契约。 + + + **L693** 对 explainedProcess 计算全部加倍输出,提供忠实 doubleInput 语法,并纳入两个契约匹配的范围内依据。 + + + **L694** 说明 ExternalCertificate 的预定范围。对应声明涉及:把输出证明绑定到精确过程及不同评估者、被评者编号;这是数学角色模型,不认证现实出处。 该注释用于解释,不是证明前提。 + + + **L695** 声明数据接口 ExternalCertificate。把输出证明绑定到精确过程及不同评估者、被评者编号;这是数学角色模型,不认证现实出处。 + + + **L696** 保存外部评估者标识。 + + + **L697** 保存受评参与者标识;证书类型已固定受评 Process。 + + + **L698** 把参与者标识不同规定为明确证书字段。 + + + **L699** 要求同一过程每个输入加倍输出的证明;一般证书假定该字段,具体证书则构造它。 + + + **L700** 说明 externalOutputCertificate 的预定范围。对应声明涉及:由实际输出计算构造评估者四十二对被评对象七的证书。 该注释用于解释,不是证明前提。 + + + **L701** 定义 externalOutputCertificate。由实际输出计算构造评估者四十二对被评对象七的证书。 + + + **L702** 构造参与者 42 与 7,计算其不等,并依真实程序自反性证明每个加倍输出。 + + + **L703** 说明 externalAssessment 的预定范围。对应声明涉及:由不同参与者证书提供匹配输出Grounds,而被评过程仍不返回解释。 该注释用于解释,不是证明前提。 + + + **L704** 陈述经检查的结果 externalAssessment。由不同参与者证书提供匹配输出Grounds,而被评过程仍不返回解释。 + + + **L705** 要求存在以 outputOnlyProcess 为索引的真实外部证书。 + + + **L706** 确定其评估者为 42、受评参与者为 7。 + + + **L707** 要求两者不同,且同一过程真实输出正确。 + + + **L708** 还保留同一输出契约匹配的 ProcessGrounds。 + + + **L709** 仍否定该实际过程具有内部解释契约。 + + + **L710** 使用真实 externalOutputCertificate,参与者固定为 42 与 7,并带有两者不同的证明。 + + + **L711** 从该具体证书提取全称输出正确性,其证明由真实程序构造。 + + + **L712** 使用同一具体输出证明,为该 outputOnlyProcess 构造匹配的 ProcessGrounds。 + + + **L713** 保留 outputOnlyNoExplanation,因此外部证书不声称存在内部解释。 + + + **L714** 说明 arithmeticArticulation 的预定范围。对应声明涉及:取得算术推论面向的规范表达。 该注释用于解释,不是证明前提。 + + + **L715** 定义 arithmeticArticulation。取得算术推论面向的规范表达。 + + + **L716** 说明 nonExecutableAssessment 的预定范围。对应声明涉及:实际算术根据检查不要求经验测试,同时保留经验面向的观察义务。 该注释用于解释,不是证明前提。 + + + **L717** 陈述经检查的结果 nonExecutableAssessment。实际算术根据检查不要求经验测试,同时保留经验面向的观察义务。 + + + **L718** 要求仅用 arithmeticFacet,为 n+1=3 提供匹配的规范 Grounds。 + + + **L719** 规定该推论方面不使用观测。 + + + **L720** 同时纳入确实使用观测且真实已履行的经验方面。 + + + **L721** 构造算术主张的非空且覆盖适用性的 Grounds,保留其无观测分类,并纳入有效的观测开关方面。 + + + **L722** 单元素成员关系把受评方面固定为 arithmeticFacet,因此检查其具体假设与结论。 + + + **L723** 使用同一算术方面已证的履行,配以非空规范表述及其准确语义连接。 + + + **L725** 关闭命名空间 CoreReader.Evidence;这不增加证明或前提。 + + +### `leanified/CoreReader/Integration.lean` + + +```lean +import CoreReader.Agency +import CoreReader.Choice + +namespace CoreReader.Integration +open CoreReader.Logic CoreReader.Evidence CoreReader.Agency CoreReader.Choice + +/- Canonical articulation preserves the actual assessment contents of each facet. -/ +theorem canonicalGrounds {W : Type} (claim : Claim W) (facets : List (Facet W)) + (hne : facets ≠ []) (checked : ∀ f ∈ facets, f.claim = claim ∧ FacetDischarged f) : + Grounds claim canonicalArticulation (fun f => f ∈ facets) facets := by + exact ⟨hne, fun _ h => h, fun f hf => + ⟨(checked f hf).1, canonicalArticulated f (checked f hf).2, + canonicalFacetArticulated f, (checked f hf).2⟩⟩ + +theorem canonicalGroundsForSingleton {W : Type} (f : Facet W) (checked : FacetDischarged f) : + Grounds f.claim canonicalArticulation (fun g => g = f) [f] := by + refine ⟨by simp, (by intro g hg; cases hg; simp), ?_⟩ + intro g hg + simp only [List.mem_singleton] at hg + subst g + exact ⟨rfl, canonicalArticulated f checked, canonicalFacetArticulated f, checked⟩ + +/- A mode selects whether a system applies or waives the modeled governance rule. -/ +inductive Mode | apply | waive + deriving DecidableEq, Repr + +/- The four hypotheses vary algorithm and governance independently for the same assessed system. -/ +abbrev World := Candidate × Mode + +def actual : World := (.identity, .apply) + +/- A method's form and its possible executable realizations belong to one object. -/ +structure Method where + form : Form + realize : World → Implementation + +/- System fields identify the owner, its method, its current principle form, policy and work. -/ +structure System where + owner : Nat + method : Method + principleForm : Form + governance : World → Mode + requirements : Requirements + +def policyFor : Mode → Policy + | .apply => openPolicy + | .waive => neutralPolicy + +def workFor (owner : Nat) : Mode → List WorkRecord + | .apply => completeOwnWork owner + | .waive => [] + +def System.policy (s : System) (w : World) : Policy := policyFor (s.governance w) +def System.rules (s : System) (_w : World) : List Principle := ownRules s.owner +def System.work (s : System) (w : World) : List WorkRecord := workFor s.owner (s.governance w) + +def actualSystem : System where + owner := 0 + method := ⟨⟨.method, 0⟩, fun w => implementation w.1⟩ + principleForm := ⟨.principle, 0⟩ + governance := Prod.snd + requirements := identityRequirements + +def systemCapability (s : System) : Claim World := + fun w => ∀ n, s.requirements.inputs n → (s.method.realize w).run n = s.requirements.expected n + +def systemBudget (s : System) : Claim World := + fun w => (s.method.realize w).cost ≤ s.requirements.budget + +def systemObservation (s : System) : Record World := + ⟨fun w => decide ((s.method.realize w).run 0 = s.requirements.expected 0), true⟩ + +def systemHeld (s : System) : Theory World := + union (singleton (systemCapability s)) (singleton (systemBudget s)) + +inductive Question | correctOutput | affordable + deriving DecidableEq, Repr + +def systemContext (s : System) : Context World Question := + ⟨singleton (Compatible [systemObservation s]), + (fun q => match q with | .correctOutput => systemCapability s | .affordable => systemBudget s), + fun w => (s.method.realize w).domain 0 ∧ w.2 = .apply⟩ + +abbrev capability := systemCapability actualSystem +abbrev observation := systemObservation actualSystem +abbrev held := systemHeld actualSystem +abbrev context := systemContext actualSystem + +/- The output observation identifies the algorithm, without identifying its independently varied governance mode. -/ +theorem observationIdentifies (w : World) : Compatible [observation] w ↔ w.1 = .identity := by + rcases w with ⟨candidate, mode⟩ + cases candidate <;> simp [Compatible, observation, systemObservation, actualSystem, + implementation, identityRequirements, identityImpl, successorImpl] + +theorem capabilityActual : capability actual := fun _ _ => rfl + +theorem observedCapability : Supports [observation] capability := by + intro w hw + have hid := (observationIdentifies w).1 hw + rcases w with ⟨candidate, mode⟩ + change candidate = .identity at hid + subst candidate + exact fun _ _ => rfl + +def capabilityFacet : Facet World := .empirical [observation] (fun _ => True) capability (fun _ => True) + +theorem capabilityFacetChecked : FacetDischarged capabilityFacet := by + exact ⟨⟨actual, (observationIdentifies actual).2 rfl, trivial⟩, + (fun w hw _ => observedCapability w hw), fun _ _ => trivial⟩ + +theorem capabilityGrounds : Grounds capability canonicalArticulation + (fun f => f = capabilityFacet) [capabilityFacet] := + canonicalGroundsForSingleton capabilityFacet capabilityFacetChecked + +theorem actualAdmissible : Admissible held context actual := by + refine ⟨(modelsUnion _ _ _).2 ⟨(modelsSingleton _ _).2 capabilityActual, + (modelsSingleton _ _).2 (by change 1 ≤ 1; decide)⟩, + (modelsSingleton _ _).2 ((observationIdentifies actual).2 rfl), trivial, rfl⟩ + +theorem jointConsistent : Consistent held context := + consequenceConsistency held context ⟨actual, actualAdmissible⟩ + +/- The current method/principle forms, judgments, rules and own work are read from this very system and world. -/ +def Charter (s : System) (w : World) : Prop := + Generative (s.policy w) ∧ Consistent (systemHeld s) (systemContext s) ∧ + Reflexive s.owner (s.rules w) (s.work w) ∧ + (s.policy w).current s.method.form ∧ (s.policy w).current s.principleForm + +theorem charterChecked : Charter actualSystem actual := + ⟨⟨Or.inl rfl, fun _ _ => trivial⟩, jointConsistent, completeOwnWork_reflexive 0, rfl, rfl⟩ + +/- Revision adds a supported input-specific assertion about the same system's realized method. -/ +def revisedHeld : Theory World := union held + (singleton (fun w => (actualSystem.method.realize w).run 0 = actualSystem.requirements.expected 0)) + +def initialSnapshot : Snapshot World Question := ⟨held, context, 0⟩ +def revisedSnapshot : Snapshot World Question := ⟨revisedHeld, context, 1⟩ + +theorem revisionKeepsConsistency : + Charter actualSystem actual ∧ Consistent revisedHeld context ∧ + TruthfulReport initialSnapshot revisedSnapshot true ∧ + ¬ TruthfulReport initialSnapshot revisedSnapshot false := by + refine ⟨charterChecked, consequenceConsistency revisedHeld context ⟨actual, + (modelsUnion _ _ _).2 ⟨actualAdmissible.1, (modelsSingleton _ _).2 rfl⟩, + actualAdmissible.2⟩, (fun _ => rfl), ?_⟩ + intro h + have bad := h (Or.inr (by decide)) + cases bad + +/- A claim about this system's method is assessed as its owner's system claim. -/ +def OwnCapabilityDuty (s : System) (w : World) (facets : List (Facet World)) : Prop := + Performed (s.work w) (.system s.owner) .assessment ∧ + Grounds (systemCapability s) canonicalArticulation (fun f => f ∈ facets) facets + +theorem ownCapabilityGrounded : + OwnCapabilityDuty actualSystem actual [capabilityFacet] ∧ capability actual := by + refine ⟨⟨?_, ?_⟩, capabilityActual⟩ + · exact ownAssessmentPerformed 0 (.system 0) (by simp [ownSubjects]) + · exact canonicalGrounds capability [capabilityFacet] (by simp) + (by intro f hf; simp only [List.mem_singleton] at hf; cases hf; exact ⟨rfl, capabilityFacetChecked⟩) + +/- This cost observation is true of both algorithms but does not discriminate their output behavior. -/ +def costAllowanceRecord : Record World := + ⟨fun w => decide ((actualSystem.method.realize w).cost ≤ 2), true⟩ + +def unsupportedCapabilityFacet : Facet World := + .empirical [costAllowanceRecord] (fun _ => True) capability (fun _ => True) + +theorem costCompatibleWithFailure : Compatible [costAllowanceRecord] (.successor, .apply) := by + intro r hr + simp only [List.mem_singleton] at hr + subst r + rfl + +theorem costDoesNotSupportOutput : ¬ Supports [costAllowanceRecord] capability := by + intro h + have bad := h (.successor, .apply) costCompatibleWithFailure 0 trivial + cases bad + +theorem unsupportedGrounds : ¬ Grounds capability canonicalArticulation + (fun f => f = unsupportedCapabilityFacet) [unsupportedCapabilityFacet] := by + intro h + have discharged := (h.2.2 unsupportedCapabilityFacet (by simp)).2.2.2 + exact costDoesNotSupportOutput (fun w hw => discharged.2.1 w hw trivial) + +/- Five separately adopted requirements govern distinct operations; the mode does not give them priority over one another. -/ +inductive Commitment | generation | consistency | reflexivity | grounds | choice + deriving DecidableEq, Repr + +/- A Grounds policy governs arbitrary claims, articulations and applicable facets, rather than only one capability claim. -/ +def groundsPermission (mode : Mode) (claim : Claim World) (a : Facet World → Articulation World) + (applicable : Facet World → Prop) (facets : List (Facet World)) : Prop := + match mode with + | .apply => Grounds claim a applicable facets + | .waive => True + +def GroundsProvision (mode : Mode) : Prop := + ∀ claim a applicable facets, groundsPermission mode claim a applicable facets → + Grounds claim a applicable facets + +theorem groundsProvisionMeaning (mode : Mode) : GroundsProvision mode ↔ mode = .apply := by + cases mode with + | apply => exact ⟨fun _ => rfl, fun _ _ _ _ _ h => h⟩ + | waive => + constructor + · intro h + exact False.elim (unsupportedGrounds (h capability canonicalArticulation + (fun f => f = unsupportedCapabilityFacet) [unsupportedCapabilityFacet] trivial)) + · intro h; cases h + +/- The consistency policy checks a whole same-context theory, not isolated judgments. -/ +def consistencyPermission (mode : Mode) (t : Theory World) (c : Context World Question) : Prop := + match mode with | .apply => Consistent t c | .waive => True + +def conflictingHeld : Theory World := union (singleton capability) (singleton (fun w => ¬ capability w)) + +theorem conflictConsequences : + Consequence conflictingHeld context .correctOutput true ∧ + Consequence conflictingHeld context .correctOutput false := by + exact ⟨fun w hw => hw.1 capability (Or.inl rfl), + fun w hw => hw.1 (fun w => ¬ capability w) (Or.inr rfl)⟩ + +theorem conflictingHeldInconsistent : ¬ Consistent conflictingHeld context := + conflictRequiresChange conflictingHeld context .correctOutput conflictConsequences.1 conflictConsequences.2 + +/- The selection policy applies the actual output/budget and relevant-reason conditions to every implementation. -/ +def choicePermission (mode : Mode) (req : Requirements) (i : Implementation) (reasons : List Reason) : Prop := + match mode with | .apply => JustifiedChoice req i reasons | .waive => True + +/- The following consequences are computed from distinct rule applications; they are not interchangeable support flags. -/ +def proposedOperation : Mode → Operation + | .apply => .successor + | .waive => .copy + +def selfSamples : Mode → List Nat + | .apply => [0, 1] + | .waive => [1] + +noncomputable def conflictDecision (mode : Mode) : Bool := + @decide (consistencyPermission mode conflictingHeld context) (Classical.propDecidable _) + +noncomputable def groundsDecision (mode : Mode) (facet : Facet World) : Bool := + @decide (groundsPermission mode facet.claim canonicalArticulation (fun f => f = facet) [facet]) + (Classical.propDecidable _) + +noncomputable def choiceDecision (mode : Mode) (i : Implementation) (reasons : List Reason) : Bool := + @decide (choicePermission mode identityRequirements i reasons) (Classical.propDecidable _) + +theorem decisionsApply : conflictDecision .apply = false ∧ + groundsDecision .apply unsupportedCapabilityFacet = false ∧ + groundsDecision .apply capabilityFacet = true ∧ + choiceDecision .apply cheapSuccessor [.method .simplicity] = false ∧ + choiceDecision .apply identityImpl objectiveReason = true := by + classical + simp only [conflictDecision, groundsDecision, choiceDecision, consistencyPermission, + groundsPermission, choicePermission] + exact ⟨decide_eq_false conflictingHeldInconsistent, + decide_eq_false unsupportedGrounds, decide_eq_true capabilityGrounds, + decide_eq_false eligibleInternalReasonNotSufficient.2, decide_eq_true identityJustified⟩ + +theorem decisionsWaive : conflictDecision .waive = true ∧ + groundsDecision .waive unsupportedCapabilityFacet = true ∧ + choiceDecision .waive cheapSuccessor [.method .simplicity] = true := by + exact ⟨@decide_eq_true (consistencyPermission .waive conflictingHeld context) + (Classical.propDecidable _) trivial, + @decide_eq_true (groundsPermission .waive unsupportedCapabilityFacet.claim canonicalArticulation + (fun f => f = unsupportedCapabilityFacet) [unsupportedCapabilityFacet]) (Classical.propDecidable _) trivial, + @decide_eq_true (choicePermission .waive identityRequirements cheapSuccessor [.method .simplicity]) + (Classical.propDecidable _) trivial⟩ + +/- Each application supplies its own outcome type, adopted objective, constraints and actual option-indexed reasons. -/ +noncomputable def commitmentPositionFor (c : Commitment) (chosenMode : Mode) : ValuePosition World := + match c with + | .generation => { + Position := Mode, Outcome := Operation, adopted := chosenMode, selected := actualSystem.governance, + outcome := fun _ mode => proposedOperation mode, + objective := fun op => op.run 0 ≠ Operation.copy.run 0, + constraints := fun _ mode => Generative (policyFor mode), + starting := singleton (fun w => actualSystem.governance w = chosenMode), + reasons := [fun _ mode => (proposedOperation mode).run 0 = 1 ∧ Operation.copy.run 0 = 0], + limits := fun w => w.1 = .identity, + relevantCriticism := fun _ => ¬ Expanded baseState inflatedState, + response := fun _ => some "Pursuing expansion does not guarantee it; assess the actual before and after capabilities separately" } + | .consistency => { + Position := Mode, Outcome := Bool, adopted := chosenMode, selected := actualSystem.governance, + outcome := fun _ mode => conflictDecision mode, + objective := fun accepted => accepted = false, + constraints := fun _ mode => consistencyPermission mode held context, + starting := singleton (fun w => actualSystem.governance w = chosenMode), + reasons := [fun _ _ => Consequence conflictingHeld context .correctOutput true ∧ + Consequence conflictingHeld context .correctOutput false], + limits := fun w => w.1 = .identity, + relevantCriticism := fun _ => ¬ Entails (emptyTheory : Theory Bool) (fun w => w = true), + response := fun _ => some "Consistency alone does not establish sufficient support; assess the claim with its grounds as well" } + | .reflexivity => { + Position := Mode, Outcome := List Nat, adopted := chosenMode, selected := actualSystem.governance, + outcome := fun _ mode => selfSamples mode, + objective := fun samples => ∃ n ∈ samples, ownArithmeticPrinciple n = false, + constraints := fun _ mode => Reflexive 0 (ownRules 0) (workFor 0 mode), + starting := singleton (fun w => actualSystem.governance w = chosenMode), + reasons := [fun _ _ => ownArithmeticPrinciple 0 = false ∧ ownArithmeticPrinciple 1 = true], + limits := fun w => w.1 = .identity, + relevantCriticism := fun _ => selfTest [1] = true ∧ ownArithmeticPrinciple 0 = false, + response := fun _ => some "A passing self-test does not certify the principle; retain the relevant counterexample and its scope" } + | .grounds => { + Position := Mode, Outcome := Bool, adopted := chosenMode, selected := actualSystem.governance, + outcome := fun _ mode => groundsDecision mode unsupportedCapabilityFacet, + objective := fun accepted => accepted = false, + constraints := fun _ mode => groundsPermission mode capability canonicalArticulation + (fun f => f = capabilityFacet) [capabilityFacet], + starting := singleton (fun w => actualSystem.governance w = chosenMode), + reasons := [fun _ _ => Compatible [costAllowanceRecord] (.successor, .apply) ∧ + ¬ capability (.successor, .apply)], + limits := fun w => w.1 = .identity, + relevantCriticism := fun _ => OutputContract outputOnlyProcess ∧ ¬ ExplanationContract outputOnlyProcess, + response := fun _ => some "Grounds allows an external output assessment without requiring this process to provide an internal explanation" } + | .choice => { + Position := Mode, Outcome := Bool, adopted := chosenMode, selected := actualSystem.governance, + outcome := fun _ mode => choiceDecision mode cheapSuccessor [.method .simplicity], + objective := fun accepted => accepted = false, + constraints := fun _ mode => choicePermission mode identityRequirements identityImpl objectiveReason, + starting := singleton (fun w => actualSystem.governance w = chosenMode), + reasons := [fun _ _ => cheapSuccessor.run 0 = 1 ∧ identityRequirements.expected 0 = 0 ∧ + cheapSuccessor.cost ≤ identityRequirements.budget], + limits := fun w => w.1 = .identity, + relevantCriticism := fun _ => identityImpl.conventional = true ∧ identityImpl.established = true, + response := fun _ => some "An existing conventional method remains eligible when actual output and budget reasons justify it" } + +noncomputable def commitmentPosition (c : Commitment) : ValuePosition World := commitmentPositionFor c .apply + +/- The fact used as a reason has content before evaluating the adopted rule's consequence. -/ +theorem positionReasons (c : Commitment) : + ∀ r ∈ (commitmentPosition c).reasons, r actual (commitmentPosition c).adopted := by + cases c <;> intro r hr <;> dsimp [commitmentPosition, commitmentPositionFor] at hr ⊢ <;> + rcases List.mem_singleton.mp hr with rfl + · exact ⟨rfl, rfl⟩ + · exact conflictConsequences + · exact ⟨rfl, rfl⟩ + · refine ⟨costCompatibleWithFailure, ?_⟩ + intro h + have bad := h 0 trivial + cases bad + · exact ⟨rfl, rfl, by decide⟩ + +/- Each adopted rule has its stated consequence in this explicitly defined application; this is not ultimate value justification. -/ +theorem positionConsequence (c : Commitment) (w : World) : (commitmentPosition c).consequence w := by + cases c <;> dsimp [commitmentPosition, commitmentPositionFor, ValuePosition.consequence] + · exact ⟨by decide, ⟨Or.inl rfl, fun _ _ => trivial⟩⟩ + · exact ⟨decisionsApply.1, jointConsistent⟩ + · exact ⟨⟨0, by simp [selfSamples], rfl⟩, completeOwnWork_reflexive 0⟩ + · exact ⟨decisionsApply.2.1, capabilityGrounds⟩ + · exact ⟨decisionsApply.2.2.2.1, identityJustified⟩ + +theorem positionProcedure (c : Commitment) : ValueProcedure (commitmentPosition c) := by + refine ⟨?_, ?_, ?_, ?_⟩ + · cases c <;> simp [commitmentPosition, commitmentPositionFor] + · refine ⟨actual, ?_, ?_, ?_, positionReasons c⟩ + · cases c <;> exact (modelsSingleton _ _).2 rfl + · cases c <;> rfl + · cases c <;> rfl + · intro w _ _ _ + exact positionConsequence c w + · intro w _ _ + cases c <;> exact ⟨_, rfl, by decide⟩ + +/- Criticism is instantiated within the adopted position's actual limit rather than made vacuous. -/ +theorem criticismWithinScope (c : Commitment) : + (commitmentPosition c).limits actual ∧ (commitmentPosition c).relevantCriticism actual := by + constructor + · cases c <;> rfl + · cases c + · simp [commitmentPosition, commitmentPositionFor, Expanded, baseState, inflatedState] + · exact consistentIncomplete.2.1 + · exact ⟨rfl, rfl⟩ + · exact ⟨outputNotExplanation.1, outputNotExplanation.2.1⟩ + · exact ⟨rfl, rfl⟩ + +/- Waiving the rule changes the actual computed outcome or an explicit adopted constraint; old reasons cannot certify it unchanged. -/ +theorem oppositeConsequenceFails (c : Commitment) (w : World) : + ¬ (commitmentPositionFor c .waive).consequence w := by + cases c <;> intro h + · exact permissionNotValuation.2.2 h.2 + · have bad : conflictDecision .waive = false := h.1 + rw [decisionsWaive.1] at bad + cases bad + · obtain ⟨n, hn, hf⟩ := h.1 + change n ∈ [1] at hn + have he : n = 1 := List.mem_singleton.mp hn + subst n + cases hf + · have bad : groundsDecision .waive unsupportedCapabilityFacet = false := h.1 + rw [decisionsWaive.2.1] at bad + cases bad + · have bad : choiceDecision .waive cheapSuccessor [.method .simplicity] = false := h.1 + rw [decisionsWaive.2.2] at bad + cases bad + +theorem oppositeProcedureRejected (c : Commitment) : ¬ ValueProcedure (commitmentPositionFor c .waive) := by + intro h + obtain ⟨w, hs, hl, _, hr⟩ := h.2.1 + exact oppositeConsequenceFails c w (h.2.2.1 w hs hl hr) + +/- Each statement names adoption of a particular rule; its defined policy gives that option its meaning. -/ +noncomputable def commitmentClaim (c : Commitment) : Claim World := (commitmentPosition c).commitment + +noncomputable def commitmentFacet (c : Commitment) : Facet World := .value (commitmentPosition c) + +theorem reasonsBelongToCommitments (c : Commitment) : + Grounds (commitmentClaim c) canonicalArticulation + (fun f => f = commitmentFacet c) [commitmentFacet c] ∧ + JointAdoption (commitmentPosition c) ∧ + (commitmentPosition c).relevantCriticism actual ∧ + ¬ ValueProcedure (commitmentPositionFor c .waive) := by + exact ⟨canonicalGroundsForSingleton (commitmentFacet c) (positionProcedure c), + (positionProcedure c).2.1, (criticismWithinScope c).2, oppositeProcedureRejected c⟩ + +/- This claim concerns the Grounds rule for arbitrary claim/facet packages, not a single capability duty. -/ +theorem groundsCommitmentIsProvision : commitmentClaim .grounds = (fun w => GroundsProvision w.2) := by + funext w + apply propext + exact (groundsProvisionMeaning w.2).symm + +theorem groundsSelfAssessment : + Grounds (fun w => GroundsProvision w.2) canonicalArticulation + (fun f => f = commitmentFacet .grounds) [commitmentFacet .grounds] ∧ + (commitmentPosition .grounds).limits actual ∧ + (commitmentPosition .grounds).relevantCriticism actual ∧ + ¬ ValueProcedure (commitmentPositionFor .grounds .waive) := by + rw [← groundsCommitmentIsProvision] + exact ⟨(reasonsBelongToCommitments .grounds).1, + (criticismWithinScope .grounds).1, (criticismWithinScope .grounds).2, + oppositeProcedureRejected .grounds⟩ + +/- This existing principle form implements the same system's choice rule on two actual proposals. +Input 0 names the identity proposal; input 1 names the cheap successor proposal. -/ +structure PhilosophyMethod where + form : Form + mode : Mode + +def currentPhilosophy (s : System) (w : World) : PhilosophyMethod := + ⟨s.principleForm, s.governance w⟩ + +noncomputable def PhilosophyMethod.review (p : PhilosophyMethod) (input : Nat) : Nat := + if input = 0 then + if choiceDecision p.mode identityImpl objectiveReason then 1 else 0 + else if choiceDecision p.mode cheapSuccessor [.method .simplicity] then 1 else 0 + +noncomputable def PhilosophyMethod.implementation (p : PhilosophyMethod) : Implementation where + name := "Current philosophy's proposal review" + conventional := true + established := true + run := p.review + cost := 1 + domain n := n = 0 ∨ n = 1 + explanation := p.review + trace n := [n, p.review n] + +def proposalRequirements : Requirements where + inputs n := n = 0 ∨ n = 1 + expected n := if n = 0 then 1 else 0 + budget := 1 + values _ := True + +theorem currentReviewCorrect : ∀ n, proposalRequirements.inputs n → + (currentPhilosophy actualSystem actual).review n = proposalRequirements.expected n := by + intro n hn + rcases hn with rfl | rfl <;> + simp [PhilosophyMethod.review, currentPhilosophy, actualSystem, actual, + proposalRequirements, decisionsApply.2.2.2.1, decisionsApply.2.2.2.2] + +/- Status alone fails for this actual principle method; its demonstrated proposal decisions give a relevant reason. -/ +theorem existingPhilosophyNotPrivileged : + (currentPhilosophy actualSystem actual).form = actualSystem.principleForm ∧ + (currentPhilosophy actualSystem actual).mode = actualSystem.governance actual ∧ + ¬ JustifiedChoice proposalRequirements + (currentPhilosophy actualSystem actual).implementation [.status .standing] ∧ + JustifiedChoice proposalRequirements + (currentPhilosophy actualSystem actual).implementation [.method .output] ∧ + (currentPhilosophy actualSystem actual).review 0 = 1 ∧ + (currentPhilosophy actualSystem actual).review 1 = 0 := by + refine ⟨rfl, rfl, statusOnlyFails _ _ _, ?_, currentReviewCorrect 0 (Or.inl rfl), + currentReviewCorrect 1 (Or.inr rfl)⟩ + exact ⟨⟨currentReviewCorrect, by change 1 ≤ 1; decide⟩, + .method .output, by simp, trivial, currentReviewCorrect⟩ + +/- Applications choose their contract and requirements; the resulting claim is about this system's actual method. -/ +def applicationClaim (s : System) (req : Requirements) + (contract : Requirements → Implementation → Prop) : Claim World := + fun w => contract req (s.method.realize w) + +def ApplicationDuties (s : System) (w : World) (req : Requirements) + (contract : Requirements → Implementation → Prop) + (articulations : Facet World → Articulation World) + (applicable : Facet World → Prop) (facets : List (Facet World)) : Prop := + Reflexive s.owner (s.rules w) (s.work w) ∧ + Grounds (applicationClaim s req contract) articulations applicable facets + +/- These are consequences of an explicitly adopted duty, not a proof that arbitrary applications fulfill it. -/ +theorem applicationRetainsDuties (s : System) (w : World) (req : Requirements) + (contract : Requirements → Implementation → Prop) + (articulations : Facet World → Articulation World) + (applicable : Facet World → Prop) (facets : List (Facet World)) + (h : ApplicationDuties s w req contract articulations applicable facets) : + Reflexive s.owner (s.rules w) (s.work w) ∧ + (∀ f, applicable f → f ∈ facets) ∧ + (∀ f ∈ facets, f.claim = applicationClaim s req contract ∧ + Articulated (articulations f) ∧ FacetArticulated (articulations f) f ∧ FacetDischarged f) := + ⟨h.1, h.2.2.1, h.2.2.2⟩ + +def outputContract (req : Requirements) (i : Implementation) : Prop := + ∀ n, req.inputs n → i.run n = req.expected n + +def successorRequirements : Requirements := + { identityRequirements with expected := fun n => n + 1 } + +/- Holding the system and observation fixed while changing the actual objective changes the capability claim. -/ +def changedObjectiveFacet : Facet World := + .empirical [observation] (fun _ => True) + (applicationClaim actualSystem successorRequirements outputContract) (fun _ => True) + +theorem applicationVariation : + ApplicationDuties actualSystem actual identityRequirements outputContract + canonicalArticulation (fun f => f = capabilityFacet) [capabilityFacet] ∧ + ¬ applicationClaim actualSystem successorRequirements outputContract actual ∧ + ¬ Grounds (applicationClaim actualSystem successorRequirements outputContract) + canonicalArticulation (fun f => f = changedObjectiveFacet) [changedObjectiveFacet] := by + refine ⟨⟨completeOwnWork_reflexive 0, capabilityGrounds⟩, ?_, ?_⟩ + · intro h + have bad := h 0 trivial + cases bad + · intro h + have discharged := (h.2.2 changedObjectiveFacet (by simp)).2.2.2 + have bad := discharged.2.1 actual ((observationIdentifies actual).2 rfl) trivial 0 trivial + cases bad + +/- The very system satisfies the charter while its true cost evidence fails to establish its output capability. -/ +theorem charterNotGrounds : + Charter actualSystem actual ∧ + Compatible [costAllowanceRecord] actual ∧ + ¬ Grounds capability canonicalArticulation + (fun f => f = unsupportedCapabilityFacet) [unsupportedCapabilityFacet] := by + exact ⟨charterChecked, (by intro r hr; cases List.mem_singleton.mp hr; rfl), unsupportedGrounds⟩ + +/- A single inhabited system/context carries the charter, its own actual claim and support, +contentful principle work, and separately reasoned governance commitments. -/ +theorem jointWitness : + ∃ s : System, ∃ w : World, + Admissible (systemHeld s) (systemContext s) w ∧ Charter s w ∧ + OwnCapabilityDuty s w [capabilityFacet] ∧ systemCapability s w ∧ + JustifiedChoice s.requirements (s.method.realize w) objectiveReason ∧ + (∀ c : Commitment, Grounds (commitmentClaim c) canonicalArticulation + (fun f => f = commitmentFacet c) [commitmentFacet c]) ∧ + s = actualSystem ∧ w = actual := by + exact ⟨actualSystem, actual, actualAdmissible, charterChecked, + ownCapabilityGrounded.1, capabilityActual, identityJustified, + fun c => (reasonsBelongToCommitments c).1, rfl, rfl⟩ + +end CoreReader.Integration +``` + + + + **L1** 导入CoreReader.Agency及其依赖。 + + + **L2** 导入CoreReader.Choice及其依赖。 + + + **L4** 打开命名空间CoreReader.Integration;文件边界不改变声明身份。 + + + **L5** 使列出的命名空间可通过省略前缀的名称引用。 + + + **L7** 说明后续定义或结果:从同一主张的已检查非空面向清单构造规范表达及Grounds;适用性按清单成员定义。 + + + **L8** 从同一主张的已检查非空面向清单构造规范表达及Grounds;适用性按清单成员定义。 + + + **L9** 假设方面列表非空,且每个方面都针对claim并已履责。 + + + **L10** 用各方面自身内容构造的表述建立Grounds,以列表成员关系作为适用谓词。 + + + **L11** 提供非空性及按成员定义直接成立的覆盖,再逐个检查列表方面。 + + + **L12** 对每个方面,用checked确立同一主张,并由履责得到非空表述。 + + + **L13** 补上该表述的确切内容对应及已给履责证明。 + + + **L15** 对单个已检查面向构造Grounds,适用性只限于该面向本身。 + + + **L16** 对单个已履责方面,使恰好该方面对其自身主张适用。 + + + **L17** 证明单项列表非空,且每个等于f的方面都在其中,留下逐方面内容检查。 + + + **L18** 取已知属于单项列表[f]的任意方面g。 + + + **L19** 单项成员关系把hg化为等式g=f。 + + + **L20** 把g替换为同一个已履责方面f。 + + + **L21** 用相同主张、构造表述的可表达性、确切方面内容匹配及checked履责完成Grounds字段。 + + + **L23** 说明后续定义或结果:区分执行模型标准与豁免标准两种模式,它们决定实际政策判断。 + + + **L24** 区分执行模型标准与豁免标准两种模式,它们决定实际政策判断。 + + + **L25** 为前述数据类型生成可判定相等及显示实例。 + + + **L27** 说明后续定义或结果:世界由两个候选实现之一及两个治理模式之一组成,是封闭四世界模型。 + + + **L28** 世界由两个候选实现之一及两个治理模式之一组成,是封闭四世界模型。 + + + **L30** 指定恒等实现和执行标准模式作为实际世界。 + + + **L32** 说明后续定义或结果:把可修订形式身份与依赖世界的实际实现绑定。 + + + **L33** 把方法形式的种类与版本绑定到随世界变化的实现;仅此结构不证明该形式可修订。 + + + **L34** 保存该方法的形式种类与版本。 + + + **L35** 为每个候选与治理世界指定该同一方法的实际实现。 + + + **L37** 说明后续定义或结果:把主体、方法、原则形式、治理选择和应用要求绑定成系统。 + + + **L38** 把主体、方法、原则形式、治理选择和应用要求绑定成系统。 + + + **L39** 标识该系统采用其原则与工作记录的所有者。 + + + **L40** 保存系统的方法形式及随世界变化的实现。 + + + **L41** 保存系统自身原则的当前形式。 + + + **L42** 选择该系统在各世界采用还是豁免治理要求。 + + + **L43** 固定用于评估该系统实现的输入、输出、预算和价值要求。 + + + **L45** 执行模式使用开放政策,豁免模式使用无扩展价值的政策。 + + + **L46** 采用治理时选择重视扩展且允许修订的openPolicy。 + + + **L47** 豁免治理时选择缺少所需扩展价值取向的neutralPolicy。 + + + **L49** 执行模式提供内容已检查的自身工作记录,豁免模式不提供记录。 + + + **L50** 采用治理时,为此所有者提供完整内容性工作日志。 + + + **L51** 豁免治理时,同一所有者的工作日志为空。 + + + **L53** 按同一系统的治理选择决定政策。 + + + **L54** 使用属于该系统主体的登记生成及评估规则。 + + + **L55** 按该主体治理模式选取实际工作记录清单。 + + + **L57** 构造主体零、版本零方法及原则、依候选实现、依世界治理和恒等要求的实际系统。 + + + **L58** 给共享实际系统分配所有者0。 + + + **L59** 使用版本0的方法形式,由世界的候选分量选择其实例实现。 + + + **L60** 把该系统当前原则形式设为原则版本0。 + + + **L61** 从世界第二分量读取治理方式,与实现候选独立。 + + + **L62** 用identityRequirements评估同一方法。 + + + **L64** 要求该系统实际方法在自身请求输入上满足自身期望输出。 + + + **L65** 声称该系统实现的方法在每个必需输入上满足指定输出。 + + + **L67** 按该系统预算检查同一实际实现的成本。 + + + **L68** 声称同一实现方法的成本满足该系统自身预算。 + + + **L70** 记录该系统实际实现是否在零输入满足其期望输出。 + + + **L71** 记录测试为true:同一方法在0处的输出等于该处所需输出。 + + + **L73** 同时持有同一系统的能力与预算主张。 + + + **L74** 系统同时持有实际输出能力主张和预算主张。 + + + **L76** 定义上下文使用的输出正确与成本可承担两个问题。 + + + **L77** 为前述数据类型生成可判定相等及显示实例。 + + + **L79** 以同系统观察为假设、能力及预算为含义;范围要求零在域内且采用执行模式。 + + + **L80** 情境假设与该系统实际0输入观察相容。 + + + **L81** 把correctOutput解释为该系统能力,把affordable解释为预算满足。 + + + **L82** 把可容许范围限于定义域包含0且采用治理的世界。 + + + **L84** 简写实际系统的参数化输出能力主张。 + + + **L85** 简写实际系统的零输入观察记录。 + + + **L86** 简写实际系统同时持有的能力与预算理论。 + + + **L87** 简写实际系统的问题、假设与范围上下文。 + + + **L89** 说明后续定义或结果:计算零点观察只识别恒等候选,而不限制治理模式。 + + + **L90** 计算零点观察只识别恒等候选,而不限制治理模式。 + + + **L91** 把候选算法与独立变化的治理模式分开。 + + + **L92** 逐一检查两个实际候选是否符合观察中的0输出测试为真。 + + + **L93** identity返回所需0而successor返回1,因此只有identity匹配,与治理方式无关。 + + + **L95** 通过约简证明实际恒等实现满足每个请求的恒等输出。 + + + **L97** 在封闭模型中,由候选识别和已知恒等行为得到全请求输入能力。 + + + **L98** 取与同一观察相容的任意世界。 + + + **L99** 用observationIdentifies推出该世界算法候选是identity。 + + + **L100** 分离世界的算法和治理分量以便替换。 + + + **L101** 把推出的identity等式直接改述为候选变量的等式。 + + + **L102** 把候选算法换成identity,保留其治理模式。 + + + **L103** 按定义,identity在每个输入上的运行等于所需输出,故证明此世界能力。 + + + **L105** 把实际观察及能力主张组成经验面向,范围不限、不确定性条件恒真。 + + + **L107** 提供实际兼容见证、封闭模型支持证明及平凡不确定性条件。 + + + **L108** 以actual作为方面无限制范围内的相容世界,避免空世界履责。 + + + **L109** 用observedCapability证明每个相容世界的支持;所述不确定性条件为平凡真。 + + + **L111** 为精确对应的能力面向构造规范Grounds。 + + + **L112** 只令实际输出能力方面适用,使用其自身单项证据包。 + + + **L113** 把单项Grounds构造应用于已经履责的能力方面。 + + + **L115** 证明实际恒等执行世界同时满足能力、预算、观察假设以及治理和输入域范围。 + + + **L116** 构造实际世界可容许见证,先证明共同持有的两项主张;能力项使用capabilityActual。 + + + **L117** 所持预算主张计算为实际成本1满足预算1。 + + + **L118** 补上与0处观察相容、0属于定义域以及actual采用apply模式。 + + + **L120** 从已证明的实际可接受世界推出一致性。 + + + **L121** 以actual及其可容许证明作为必需非空见证,应用语义后果一致性定理。 + + + **L123** 说明后续定义或结果:组合该系统生成政策、上下文一致性、完整内容有效反身性及当前方法和原则形式。 + + + **L124** 组合该系统生成政策、上下文一致性、完整内容有效反身性及当前方法和原则形式。 + + + **L125** Charter要求该系统实际政策具有生成取向,且共同持有判断在情境内一致。 + + + **L126** 它还要求该系统实际工作日志满足完整自有规则反身要求。 + + + **L127** 方法形式与原则形式均须在同一政策下属于当前形式。 + + + **L129** 组合开放政策计算结果、实际一致性和内容已验证自身工作模型。 + + + **L130** 组合openPolicy价值取向与可修订性、jointConsistent、完整自有日志及两个当前版本0形式。 + + + **L132** 说明后续定义或结果:在原持有理论中增加同系统零输入输出事实。 + + + **L133** 在原持有理论中增加同系统零输入输出事实。 + + + **L134** 增加具体断言:同一方法在输入0处满足所需输出。 + + + **L136** 以修订标识零保存实际理论及上下文。 + + + **L137** 以同一上下文和标识一保存扩充理论。 + + + **L139** 增加事实后保留同一章程和可接受模型,并要求如实报告修订。 + + + **L140** 实际系统保留Charter,增加该有支持断言后revisedHeld仍一致。 + + + **L141** 把已识别修订报告为true,满足单向变化报告条件。 + + + **L142** 把同一修订报告为false,违反该条件。 + + + **L143** 保留charterChecked,以actual作为具体可容许见证证明修订后一致性。 + + + **L144** actual满足原所持主张及新增0输入输出断言。 + + + **L145** 保留actual既有情境与范围证明,并验证true报告,仅余拒绝false报告。 + + + **L146** 假设变化后的快照能以report=false满足TruthfulReport。 + + + **L147** 修订编号0和1不同,因此假设的义务迫使false=true。 + + + **L148** 排除不可能的布尔等式,拒绝隐瞒修订。 + + + **L150** 说明后续定义或结果:要求该系统评估记录及其自身能力主张的匹配Grounds。 + + + **L151** 要求该系统评估记录及其自身能力主张的匹配Grounds。 + + + **L152** OwnCapabilityDuty首先要求实际评估记录针对与系统所有者一致的系统对象。 + + + **L153** 还要求全部所列适用方面为该系统输出能力提供同主张Grounds。 + + + **L155** 组合实际内容有效自身评估记录、观察支持能力Grounds及能力结论。 + + + **L156** 陈述实际系统自身能力义务已履行,且其声称能力实际成立。 + + + **L157** 直接提供capabilityActual,留下系统评估记录与对应Grounds。 + + + **L158** 以完整日志对系统0的评估作为自有系统工作见证。 + + + **L159** 从非空单项能力方面列表构造Grounds。 + + + **L160** 单项列表唯一方面具有确切目标主张及已证履责。 + + + **L162** 说明后续定义或结果:记录同系统实现成本至多二;两个候选均通过。 + + + **L163** 记录同系统实现成本至多二;两个候选均通过。 + + + **L164** 记录实现成本至多2;两个算法候选都满足这个较弱成本观察。 + + + **L166** 试图只凭宽松成本观察支持同一输出能力。 + + + **L167** 尝试仅以成本证据支持输出能力,不另加限制范围或不确定性条件。 + + + **L169** 计算后继执行世界符合成本观察,却不满足恒等输出。 + + + **L170** 取单项成本观察列表中的一条记录。 + + + **L171** 单项成员关系确认该记录就是costAllowanceRecord。 + + + **L172** 把r替换为实际成本记录。 + + + **L173** successor成本为2,因此记录的至多2观察计算为true。 + + + **L175** 把假定支持应用于兼容后继反世界及零输入,导出矛盾。 + + + **L176** 假设成本观察在每个相容世界都支持输出能力。 + + + **L177** 将假设应用于相容successor世界及输入0,得到错误等式1=0。 + + + **L178** 排除不可能的输出等式,反驳仅成本支持。 + + + **L180** 从假定Grounds抽取错误面向支持义务,并由成本反模型否定。 + + + **L181** 检验使该仅成本能力方面适用的单项证据包。 + + + **L182** 假设这个不足的单项证据包仍满足Grounds。 + + + **L183** 从Grounds前提提取实际仅成本能力方面的FacetDischarged。 + + + **L184** 其支持条款会推出仅成本Supports,与costDoesNotSupportOutput矛盾。 + + + **L186** 说明后续定义或结果:标识五项治理承诺,每项有分别解释的理由与结果。 + + + **L187** 标识五项治理承诺,每项有分别解释的理由与结果。 + + + **L188** 为前述数据类型生成可判定相等及显示实例。 + + + **L190** 说明后续定义或结果:执行模式仅许可Grounds成立的主张包,豁免模式许可所有包。 + + + **L191** 执行模式仅许可Grounds成立的主张包,豁免模式许可所有包。 + + + **L192** 接收针对同一主张与表述的任意适用谓词和方面包。 + + + **L193** 按治理模式选择许可规则。 + + + **L194** apply模式只许可实际满足Grounds的证据包。 + + + **L195** waive模式不检查Grounds,许可所有证据包。 + + + **L197** 表达一般规范:所有获许可的主张、表达、适用面与清单组合都必须具有Grounds。 + + + **L198** 对任意实际主张、表述族和方面包,条款约束该模式许可的所有包。 + + + **L199** 每个被许可包都必须满足其自身对应Grounds义务。 + + + **L201** 证明执行模式履行一般规范,而具体无支持成本包反驳豁免模式。 + + + **L202** 分别检查apply与waive模式的一般条款。 + + + **L203** apply模式的许可本就是Grounds,因此返回已给证明即可满足一般条款。 + + + **L204** 对waive模式,需要证明无限制许可违反一般条款。 + + + **L205** 证明waive模式下两侧均不成立的等价关系两个方向。 + + + **L206** 假设该模式豁免检查时一般条款仍成立。 + + + **L207** 把该普遍假设应用于实际不足的能力证据包,将与unsupportedGrounds矛盾。 + + + **L208** 提供确切单项适用谓词和包;豁免许可为真,迫出无效Grounds结果。 + + + **L209** 反向蕴涵以前提waive=apply开始,这是不可能的构造器等式。 + + + **L211** 说明后续定义或结果:执行模式要求拟议理论和上下文一致,豁免模式无条件许可。 + + + **L212** 执行模式要求拟议理论和上下文一致,豁免模式无条件许可。 + + + **L213** apply要求整个理论在情境内一致;waive不施加该约束。 + + + **L215** 在同一理论中组合实际能力主张及其否定。 + + + **L217** 从同时持有的相反主张中抽取能力正反后果。 + + + **L218** 冲突的所持理论在固定情境下蕴涵输出正确的正判断。 + + + **L219** 同一理论和情境也蕴涵其负判断。 + + + **L220** 可容许世界对conflictingHeld的模型必须满足其中明确包含的能力主张。 + + + **L221** 同一模型也必须满足明确包含的能力否定。 + + + **L223** 以同条件正反后果否定一致性。 + + + **L224** 用同情境的两个相反后果反驳冲突所持理论的一致性。 + + + **L226** 说明后续定义或结果:执行治理采用单独的可行相关选择规范,豁免治理接受任意理由清单。 + + + **L227** 执行治理采用单独的可行相关选择规范,豁免治理接受任意理由清单。 + + + **L228** apply通过JustifiedChoice执行实际可行性与理由相关性要求;waive许可任意选择包。 + + + **L230** 说明后续定义或结果:执行模式提出后继操作,豁免模式只提出原copy操作。 + + + **L231** 执行模式提出后继操作,豁免模式只提出原copy操作。 + + + **L232** 采用生成规则时提出successor,其输出可与copy不同。 + + + **L233** 豁免该规则时提出未变的copy操作。 + + + **L235** 执行模式测试零与一,豁免模式只测试会通过的一。 + + + **L236** 采用反身评估时检查0和1,包括算术反例。 + + + **L237** 豁免时仅检查1,即算术原则通过的样本。 + + + **L239** 用经典命题可判定性判断具体冲突理论是否获许可;这是非计算定义,不是已部署检查器。 + + + **L240** 用古典命题判定把整个冲突理论许可化为布尔值;未提供可执行判定算法。 + + + **L242** 用经典可判定性判断该模式是否许可指定单面向主张包。 + + + **L243** 判定此方面自身主张及其确切单项评估包的许可。 + + + **L244** 为该可能不可计算的Grounds命题提供古典可判定性。 + + + **L246** 用经典可判定性判断恒等要求下指定实现和理由是否获许可。 + + + **L247** 在固定恒等要求与提供理由下,古典判定该实现的选择许可。 + + + **L249** 证明执行模式拒绝矛盾、无支持能力及不可行廉价后继,同时接受实际能力和恒等选择。 + + + **L250** 采用Grounds时拒绝仅成本能力证据包。 + + + **L251** 采用Grounds时接受得到适当支持的输出观察包。 + + + **L252** 采用选择规范时,尽管简洁性理由相关,仍因输出不可行拒绝cheapSuccessor。 + + + **L253** 采用选择规范时,凭实际输出理由接受identity。 + + + **L254** 启用这些布尔许可定义所需的古典可判定实例。 + + + **L255** 展开三个布尔决策及apply模式一致性谓词。 + + + **L256** 也展开Grounds与选择许可,显露每个布尔值判定的实际命题。 + + + **L257** 已证不一致性迫使conflictDecision apply为false。 + + + **L258** 失败的成本证据包判为false,已履责观察包判为true。 + + + **L259** 不可行的廉价方法判为false;可行且有理由的identity判为true。 + + + **L261** 计算豁免模式接受具体矛盾、无支持面向和不可行选择。 + + + **L262** waive模式甚至接受无支持的仅成本能力证据包。 + + + **L263** 它也仅凭简洁性接受cheapSuccessor,尽管输出错误。 + + + **L264** 从consistencyPermission开始计算豁免结果;它在此模式按定义为True。 + + + **L265** 用该平凡许可证明得到true的冲突决策布尔值。 + + + **L266** 接着判定对确切不足能力方面主张的豁免许可。 + + + **L267** 其单项适用谓词和包未变;豁免使许可为True、判定为true。 + + + **L268** 最后判定对同一廉价方法及仅简洁性理由的豁免许可。 + + + **L269** 该许可再次平凡为True,完成全部三个豁免决策。 + + + **L271** 说明后续定义或结果:为各承诺把治理模式解释为选项,分别赋予操作结果、目标、约束、实际理由及范围内批评响应。 + + + **L272** 为各承诺把治理模式解释为选项,分别赋予操作结果、目标、约束、实际理由及范围内批评响应。 + + + **L273** 为五项承诺分别选择不同的操作性价值立场适配接口。 + + + **L274** 构造生成承诺的价值立场。 + + + **L275** 其立场为治理模式、后果为操作,采纳选项与同一系统所选治理对应。 + + + **L276** 把模式映射为实际提出的successor或copy操作。 + + + **L277** 采纳的生成目标要求0处输出不同于copy的0输出。 + + + **L278** 还要求该模式实际政策满足采纳的Generative约束。 + + + **L279** 明确以同一系统选择chosenMode为起始承诺,不是推导出的普遍事实。 + + + **L280** 其随选项变化的理由比较拟议操作0→1与copy的0→0表现。 + + + **L281** 将此生成立场限于实现候选为identity的世界。 + + + **L282** 把实际库存膨胀却未扩展作为生成承诺的相关批评。 + + + **L283** 回应取向不保证进步且须另评前后能力;保存的回应是非空文本。 + + + **L284** 构造一致性承诺的不同价值立场。 + + + **L285** 以模式为立场、布尔冲突许可决策为后果,关联同一所选治理。 + + + **L286** 实际后果是该模式对整个冲突理论的决策。 + + + **L287** 要求该决策拒绝冲突理论。 + + + **L288** 同时要求实际所持理论与情境通过同一模式的一致性许可。 + + + **L289** 把同一系统采纳chosenMode陈述为此立场明确起始假设。 + + + **L290** 一致性理由首先包括冲突理论的输出正确正后果。 + + + **L291** 它还包括完全相同问题与情境下的相反后果。 + + + **L292** 将此一致性立场限于identity候选世界。 + + + **L293** 以空Bool理论不能蕴涵每个世界都为true作为实际不完整性批评。 + + + **L294** 回应一致性本身不确立充分支持,仍须评估主张的根据。 + + + **L295** 构造反身评估的价值立场。 + + + **L296** 以模式为立场、实际样本输入列表为后果,关联同一所选治理。 + + + **L297** 该模式选择样本集[0,1]或[1]。 + + + **L298** 要求某个实际选中样本揭示同一算术原则的假结果。 + + + **L299** 还要求同一模式下所有者0的规则与工作满足完整反身要求。 + + + **L300** 明确把同一系统采纳chosenMode作为起始承诺。 + + + **L301** 理由指明算术原则在0实际失败、在1成功。 + + + **L302** 将此反身立场限制于identity候选世界。 + + + **L303** 保留1处通过测试与0处实际失败这对事实作为批评。 + + + **L304** 回应通过自测不认证原则正确,须保留反例及其范围。 + + + **L305** 构造针对Grounds条款自身的价值立场。 + + + **L306** 以模式为立场、布尔证据包决策为后果,属于同一系统治理。 + + + **L307** 实际后果检验无支持的仅成本能力方面。 + + + **L308** 要求拒绝该无支持证据包。 + + + **L309** 还要求许可实际能力主张及按内容构造的表述。 + + + **L310** 该正约束恰使用已适当履责的单项capabilityFacet证据包。 + + + **L311** 把同一系统采纳chosenMode陈述为明确起始承诺。 + + + **L312** Grounds理由记录successor/apply世界与成本观察相容。 + + + **L313** 把该相容性与同一世界中声称输出能力的实际失败配对。 + + + **L314** 将此Grounds立场限制于identity候选世界。 + + + **L315** 批评指向同一过程满足输出合同却没有附带解释合同。 + + + **L316** 回应外部输出评估可提供Grounds,而不要求此过程解释其内部生成。 + + + **L317** 构造实现选择的独立价值立场。 + + + **L318** 以模式为立场、布尔方法许可决策为后果,关联同一治理选择。 + + + **L319** 受检选择是仅以简洁性为理由的廉价successor。 + + + **L320** 要求拒绝该错误输出选择。 + + + **L321** 还要求在相同要求下凭实际输出理由接受identity。 + + + **L322** 明确为此系统采纳chosenMode;价值起点不是从中性事实证明的。 + + + **L323** 选择理由比较同一输入上cheapSuccessor输出1与所需输出0。 + + + **L324** 还记录该方法满足预算,因此低成本不能掩盖输出失败。 + + + **L325** 将此选择立场限于identity候选世界。 + + + **L326** 把identity实际具有的惯用及既有地位,保留为对排除既有方法的相关批评。 + + + **L327** 回应惯用既有方法在实际输出与预算理由支持时仍可被选择。 + + + **L329** 把各自解释的立场具体化为采纳执行治理模式。 + + + **L331** 说明后续定义或结果:在同一实际世界和采纳模式下,以计算或具体反例检查每项承诺理由。 + + + **L332** 在同一实际世界和采纳模式下,以计算或具体反例检查每项承诺理由。 + + + **L333** 承诺c实际列出的每个理由,都须在actual世界对其采纳的apply选项成立。 + + + **L334** 分别处理五项承诺,展开各自实际理由列表,并固定其中理由r。 + + + **L335** 每个列表都是单项,成员前提把r确定为该承诺的具体理由。 + + + **L336** 生成理由计算为successor 0=1且copy 0=0。 + + + **L337** 一致性理由使用已证同一冲突理论的正反后果。 + + + **L338** 反身理由计算同一算术原则在0失败、在1成功。 + + + **L339** 对Grounds,提供successor世界的成本相容性,留下能力失败待证。 + + + **L340** 假设同一successor世界仍具有所需输出能力。 + + + **L341** 在必需输入0处,该假设给出successor输出1等于所需0。 + + + **L342** 排除不可能的1=0,证明理由中的能力失败部分。 + + + **L343** 选择理由计算得到输出1、所需0及廉价方法满足预算的成本。 + + + **L345** 说明后续定义或结果:用实际判断及遵守定理证明每个采纳模式满足自身目标与约束,不断言终极规范正确。 + + + **L346** 用实际判断及遵守定理证明每个采纳模式满足自身目标与约束,不断言终极规范正确。 + + + **L347** 将每项承诺后果展开为实际目标与随模式变化的约束。 + + + **L348** 生成的apply选项在0处不同于copy,且openPolicy满足价值取向与可修订性。 + + + **L349** 一致性的apply选项拒绝冲突理论,同时实际所持理论保持一致。 + + + **L350** 反身性从[0,1]选择实际反例0,并提供完整内容性自有工作反身履责。 + + + **L351** Grounds拒绝无支持成本包,同时正确能力证据包具有Grounds。 + + + **L352** 选择规范拒绝cheapSuccessor,保留有理由且可行的identity实现。 + + + **L354** 为每项承诺构造非空理由、联合采纳、已检查后果及非空响应;已独立证明的后果无需再用理由假设。 + + + **L355** 把ValueProcedure分为非空理由、联合采纳、带范围后果规则及批评回应。 + + + **L356** 检查每项承诺实际理由列表都包含其单项理由。 + + + **L357** 用同一actual世界作为JointAdoption见证,并提供positionReasons c;余下检查起始理论、限度与采纳。 + + + **L358** 在actual中治理为apply,因此选择采纳模式的单项起始理论成立。 + + + **L359** 对每项承诺,actual的identity候选满足其声明限度。 + + + **L360** 对每项承诺,actual所选治理等于采纳的apply选项。 + + + **L361** 为程序后果条款取任意世界及起始、限度、全部理由前提。 + + + **L362** 使用已对每个世界证明apply选项目标与约束的positionConsequence;此处不需要这些前提。 + + + **L363** 为回应条款,取具有适用范围内相关批评的世界。 + + + **L364** 每项承诺都返回其实际保存的非空回应字符串,满足回应存在要求。 + + + **L366** 说明后续定义或结果:为每项承诺提供实际范围内批评情形,避免这些实例的响应义务空真。 + + + **L367** 为每项承诺提供实际范围内批评情形,避免这些实例的响应义务空真。 + + + **L368** 要求actual既属于此承诺限度,且该承诺具体批评确在该处适用。 + + + **L369** 将实际限度检查与实际批评检查分开。 + + + **L370** 每个限度都要求identity,而actual候选按定义正是identity。 + + + **L371** 分别检查每项承诺的不同批评,不空泛假设存在批评。 + + + **L372** 生成批评成立,因为膨胀基线列表没有新增理解或构造操作。 + + + **L373** 一致性批评使用空理论不能蕴涵所选Bool主张的已证结果。 + + + **L374** 反身批评计算得到1处样本通过而0处失败。 + + + **L375** Grounds批评组合outputOnlyProcess的实际输出正确性与缺失解释合同。 + + + **L376** 选择批评成立,因为identity实际为惯用且既有实现。 + + + **L378** 说明后续定义或结果:证明豁免选项不满足各项未改变的目标或约束。 + + + **L379** 证明豁免选项不满足各项未改变的目标或约束。 + + + **L380** 陈述任意世界中每项承诺的waive选项都会违反声明目标或约束。 + + + **L381** 分别处理各承诺,并假设对应waive后果成立以求矛盾。 + + + **L382** 生成后果会要求Generative neutralPolicy,与许可不等于赋值例中已证失败矛盾。 + + + **L383** 一致性假设目标声称waive必须拒绝冲突理论。 + + + **L384** 但decisionsWaive得到接受值true,使该目标化为true=false。 + + + **L385** 排除一致性选项的不可能布尔等式。 + + + **L386** 反身性假设目标提供选中样本n,使算术原则在该处为假。 + + + **L387** waive模式选中样本恰为[1]。 + + + **L388** 属于该单项列表迫使所谓失败输入n等于1。 + + + **L389** 在声称失败的证明中把n替换为1。 + + + **L390** 该原则在1实际返回true,与声称的false结果矛盾。 + + + **L391** Grounds假设目标声称waive拒绝具体无支持能力包。 + + + **L392** decisionsWaive却说明同一包被接受,得到true=false。 + + + **L393** 排除不可能等式,故豁免Grounds后果失败。 + + + **L394** 选择的假设目标声称waive拒绝仅凭简洁性的cheapSuccessor。 + + + **L395** decisionsWaive证明该确切选择被接受,再次得到true=false。 + + + **L396** 排除该等式,完成全部五个waive后果的失败证明。 + + + **L398** 将假定联合采纳见证与后果失败结合,拒绝相反模式的程序。 + + + **L399** 假设相反的waive价值立场仍满足ValueProcedure。 + + + **L400** 提取其JointAdoption见证w、起始理论证明hs、限度证明hl及全部理由证明hr。 + + + **L401** 将假设程序的后果条款应用于同一联合见证,得到waive后果;oppositeConsequenceFails c w正反驳该后果。 + + + **L403** 说明后续定义或结果:抽取各立场采纳主张;都使用同一治理选择器,但分别评估结果和理由。 + + + **L404** 抽取各立场采纳主张;都使用同一治理选择器,但分别评估结果和理由。 + + + **L406** 把具体解释的承诺立场包装成价值面向。 + + + **L408** 为每项承诺提供Grounds、真实联合采纳、实际相关批评及同目标下相反政策的拒绝。 + + + **L409** 要求为承诺c的实际采纳主张提供Grounds,表述由其方面内容构造。 + + + **L410** 仅令commitmentFacet c适用,并只提供同一方面。 + + + **L411** 还要求该立场具有非空的联合可容许采纳见证。 + + + **L412** 要求此特定承诺的批评在actual实际成立。 + + + **L413** 还证明相反waive立场不满足同一价值程序要求。 + + + **L414** 使用该承诺已检查的positionProcedure构造单项Grounds。 + + + **L415** 补上其联合见证、实际批评及相反立场的已证拒绝。 + + + **L417** 说明后续定义或结果:证明Grounds立场采纳主张与所选治理模式的一般Grounds规范外延相同。 + + + **L418** 证明Grounds立场采纳主张与所选治理模式的一般Grounds规范外延相同。 + + + **L419** 为证明两个主张相等,固定任意世界w并比较该处命题。 + + + **L420** 使用命题外延性:两个命题等价即可得到相等。 + + + **L421** groundsProvisionMeaning说明一般条款恰在apply模式成立,与此采纳主张按反向对应。 + + + **L423** 把价值Grounds应用到一般Grounds规范自身,保留实际范围、批评及被拒绝豁免变体。 + + + **L424** 用按内容构造的表述评估量化主张与方面包的一般GroundsProvision自身。 + + + **L425** 适用价值方面恰为grounds承诺自身的方面。 + + + **L426** 要求actual满足该承诺声明限度。 + + + **L427** 也要求其批评在actual实际适用。 + + + **L428** 要求相反的豁免Grounds承诺不满足ValueProcedure。 + + + **L429** 把一般条款改写为外延相同的grounds采纳主张。 + + + **L430** 复用针对同一grounds承诺的实际Grounds证明。 + + + **L431** 提供分别检查过的实际限度与实际相关批评。 + + + **L432** 提供相反豁免Grounds立场的已证失败。 + + + **L434** 说明后续定义或结果:保存当前哲学原则形式及其实际治理模式。 + + + **L435** 说明后续定义或结果:保存当前哲学原则形式及其实际治理模式。 + + + **L436** 保存当前哲学原则形式及其实际治理模式。 + + + **L437** 保存该哲学方法实现的实际原则形式。 + + + **L438** 保存同一哲学方法采用还是豁免治理检查。 + + + **L440** 从同一系统原则形式及治理选择派生被审哲学对象。 + + + **L441** 以该系统自身原则形式及其在w中的治理构造哲学方法。 + + + **L443** 按该哲学实际治理模式,对零处恒等提案及其他处廉价不可行提案给出许可结果。 + + + **L444** 输入0指认identity方法提案;其余输入走廉价successor提案分支。 + + + **L445** 对identity,运行该哲学方法实际选择政策,接受返回1、拒绝返回0。 + + + **L446** 对其他输入,以同一政策评估仅凭简洁性的cheapSuccessor,同样以1/0编码接受与拒绝。 + + + **L448** 把实际哲学审查程序呈为实现,域为零与一,并提供对应输出及轨迹代理。 + + + **L449** 将实现命名为当前哲学的实际提案审查方法。 + + + **L450** 将该提案审查实现标记为惯用。 + + + **L451** 也标记同一实现为既有;后续证明检查仅此是否足以支持优先性。 + + + **L452** 实现实际运行恰为该哲学方法的review函数。 + + + **L453** 给该审查实现赋成本1。 + + + **L454** 仅将提案编号0和1声明为其应用定义域。 + + + **L455** 在实现解释字段中提供同一review函数。 + + + **L456** 记录由提案编号和实际审查结果组成的双条轨迹。 + + + **L458** 要求接受提案零、拒绝提案一,并满足预算一。 + + + **L459** 该应用恰测试提案编号0和1。 + + + **L460** 要求identity提案0被接受为1,另一受测提案被拒绝为0。 + + + **L461** 给予该审查方法成本预算1。 + + + **L462** 本例不通过要求中的values谓词增加限制。 + + + **L464** 从执行治理结果计算两个被要求提案的实际判断。 + + + **L465** 对每个必需提案,实际系统当前哲学审查须等于应用期望判定。 + + + **L466** 取提案n及其属于必需输入的证明hn。 + + + **L467** 用hn把n限定为具体identity或廉价successor提案编号。 + + + **L468** 展开同一当前哲学方法和实际系统,显露真实提案决策。 + + + **L469** 用decisionsApply将接受identity、拒绝廉价successor与所需判定匹配。 + + + **L471** 说明后续定义或结果:将实现绑定当前原则及治理对象,拒绝纯地位优先,并由两个实际提案判断提供正当理由。 + + + **L472** 将实现绑定当前原则及治理对象,拒绝纯地位优先,并由两个实际提案判断提供正当理由。 + + + **L473** 检查该哲学方法形式恰为实际系统当前原则形式。 + + + **L474** 检查其治理模式恰为同一系统在actual的模式。 + + + **L475** 开始陈述仅地位不足以支持选择此实际审查实现。 + + + **L476** 对同一哲学实现,被拒绝理由列表恰为[.status .standing]。 + + + **L477** 另陈述该实现在实际提案要求下具有有根据选择。 + + + **L478** 该正向选择使用实际输出理由,而非仅其名称或既有标记。 + + + **L479** 同一哲学审查实际以结果1接受identity提案0。 + + + **L480** 它实际以结果0拒绝廉价successor提案1。 + + + **L481** 提供同形式与模式、纯地位拒绝及提案0正确计算,留下正向输出理由选择待证。 + + + **L482** 也为必需提案1提供currentReviewCorrect,证明实际拒绝。 + + + **L483** 由两个提案输出正确及成本1≤预算1构造正向选择可行性。 + + + **L484** 以列表中的.method .output理由及currentReviewCorrect作为实际相关性见证。 + + + **L486** 说明后续定义或结果:将任意给定应用合同和要求用于该系统实际依世界方法。 + + + **L487** 将任意给定应用合同和要求用于该系统实际依世界方法。 + + + **L488** 接收关联Requirements与被评实现的任意应用合同。 + + + **L489** 在每个世界,把同一合同和要求应用于该系统实际方法实现。 + + + **L491** 把同系统完整反身性与精确参数化应用主张的Grounds结合。 + + + **L492** ApplicationDuties把选定应用合同保留为明确参数。 + + + **L493** 也接收为每个潜在相关方面提供的表述。 + + + **L494** 把实际适用谓词与提供的方面列表分开。 + + + **L495** 要求同一系统所有者在w的实际规则和工作满足完整反身要求。 + + + **L496** 要求为该系统、这些要求与此合同产生的主张提供匹配Grounds。 + + + **L498** 说明后续定义或结果:从明确假定的应用遵守接口抽取反身性、适用覆盖及匹配面向检查,不凭空确立遵守。 + + + **L499** 从明确假定的应用遵守接口抽取反身性、适用覆盖及匹配面向检查,不凭空确立遵守。 + + + **L500** 该定理保留任意应用合同,不固定单一能力定义。 + + + **L501** 保留该应用各方面的实际表述族。 + + + **L502** 保留该应用自身适用谓词及所提供方面列表。 + + + **L503** 关键前提是假设ApplicationDuties已对这些确切对象成立;定理不创造履责事实。 + + + **L504** 结论从假设义务保留同所有者规则与工作的完整反身要求。 + + + **L505** 它要求每个实际适用方面都在提供列表中,与标签无关。 + + + **L506** 对每个所列方面,其被评主张须等于该系统实际参数化应用主张。 + + + **L507** 同一方面须具有可表达且内容匹配的表述,并实际满足履责条件。 + + + **L508** 投影h.1为反身要求,h.2.2.1为适用方面覆盖,h.2.2.2为每个所列方面的同主张、表述与履责检查。 + + + **L510** 要求实现满足应用在每个请求输入上的期望输出。 + + + **L511** 输出合同在每个必需输入上核对该实现实际运行与所选期望输出。 + + + **L513** 把同一应用的期望输出由恒等改为后继,保留其他字段。 + + + **L514** 保留identityRequirements的输入及其他字段,但把期望输出改为n+1。 + + + **L516** 说明后续定义或结果:保留旧观察,把被评主张改成后继目标,以检验同对象证据是否仍足够。 + + + **L517** 保留旧观察,把被评主张改成后继目标,以检验同对象证据是否仍足够。 + + + **L518** 为无限制范围的经验方面复用旧实际观察。 + + + **L519** 把其被评主张改为同一系统满足successorRequirements;不确定性谓词仍平凡为真。 + + + **L521** 在此实例中,原恒等合同仍保有已履行义务;改后的后继合同在同一实际方法上失败,且指定保留观察包不能为它提供根据。 + + + **L522** 原恒等输出应用在实际系统和世界上履行ApplicationDuties。 + + + **L523** 该正实例使用已支持的capabilityFacet及按其自身内容构造的表述。 + + + **L524** 但同一实际系统不满足改变后的后继输出合同。 + + + **L525** 改变后的主张也不能从保留观察包取得Grounds。 + + + **L526** 此失败恰针对changedObjectiveFacet单项包,不针对所有可能证据包。 + + + **L527** 由完整自有反身要求及capabilityGrounds构造原义务,留下改变后行为与证据失败待证。 + + + **L528** 假设实际identity方法满足新的successor合同。 + + + **L529** 在必需输入0处,这会迫使实际输出0等于期望1。 + + + **L530** 排除不可能的0=1,反驳改变后的实际能力主张。 + + + **L531** 假设保留观察单项包仍为改变后的主张提供Grounds。 + + + **L532** 从假设Grounds包提取实际changedObjectiveFacet的履责。 + + + **L533** 将其支持规则应用于相容actual世界和输入0,得到同一错误输出等式0=1。 + + + **L534** 排除该等式,证明指定保留观察包不能为新主张提供根据。 + + + **L536** 说明后续定义或结果:给出实际遵守章程系统与兼容成本证据,但该指定能力面向无支持;不排除其他有效根据。 + + + **L537** 给出实际遵守章程系统与兼容成本证据,但该指定能力面向无支持;不排除其他有效根据。 + + + **L538** 同一实际系统满足全部已表示Charter条件。 + + + **L539** 其实际世界与真实的至多2成本观察相容。 + + + **L540** 然而该成本证据不能为其输出能力提供Grounds。 + + + **L541** 被否定的是特定unsupportedCapabilityFacet单项Grounds,不是所有可能评估包。 + + + **L542** 组合charterChecked、actual与成本记录的直接相容性,以及已证unsupportedGrounds反例。 + + + **L544** 说明后续定义或结果:构造同一系统和世界,满足实际判断、完整反身性、能力根据、可行选择及各解释承诺Grounds;这是有界模型而非哲学普遍正确性。 + + + **L545** 说明后续定义或结果:构造同一系统和世界,满足实际判断、完整反身性、能力根据、可行选择及各解释承诺Grounds;这是有界模型而非哲学普遍正确性。 + + + **L546** 构造同一系统和世界,满足实际判断、完整反身性、能力根据、可行选择及各解释承诺Grounds;这是有界模型而非哲学普遍正确性。 + + + **L547** 要求存在实际系统与世界对作为联合见证,使组合主张非空。 + + + **L548** 同一对象对必须对其共同持有主张和情境可容许,并满足Charter。 + + + **L549** 它还须由capabilityFacet履行自身能力义务,且拥有声称能力。 + + + **L550** 同一实际方法须在自身要求下凭objectiveReason得到可行的有根据选择。 + + + **L551** 对五项承诺中的每一项,对应实际采纳主张都须具有Grounds。 + + + **L552** 每项承诺使用自身确切单项价值方面及对应适用性。 + + + **L553** 最后确认见证就是actualSystem和actual,防止换成无关存在对象。 + + + **L554** 选择该确切对象对,提供实际可容许性与已检查Charter。 + + + **L555** 补上同一系统自身能力义务、实际能力及有根据的identity选择。 + + + **L556** 使用每项承诺已有Grounds证明,再按构造完成两个见证一致性等式。 + + + **L558** 关闭当前命名空间。 + + +### `leanified/CoreReader/Logic.lean` + + +```lean +namespace CoreReader.Logic + +/- A claim denotes the worlds in which its content holds. -/ +abbrev Claim (W : Type) := W → Prop +/- A theory is a collection of simultaneously held claims. -/ +abbrev Theory (W : Type) := Claim W → Prop +/- A model satisfies every member of the whole theory. -/ +def Models {W : Type} (t : Theory W) (w : W) : Prop := ∀ p, t p → p w +/- Semantic entailment quantifies over all models. -/ +def Entails {W : Type} (t : Theory W) (p : Claim W) : Prop := ∀ w, Models t w → p w +/- Satisfiability requires an actual witness. -/ +def Satisfiable {W : Type} (t : Theory W) : Prop := ∃ w, Models t w +/- Assumptions, meanings and scope are distinct components; questions remain explicit. -/ +structure Context (W Q : Type) where + assumptions : Theory W + meaning : Q → Claim W + scope : Claim W +/- Admissible worlds satisfy held claims, assumptions and scope jointly. -/ +def Admissible {W Q : Type} (t : Theory W) (c : Context W Q) (w : W) : Prop := + Models t w ∧ Models c.assumptions w ∧ c.scope w +/- A negative judgment denies the very same question under the same meaning. -/ +def Consequence {W Q : Type} (t : Theory W) (c : Context W Q) (q : Q) (positive : Bool) : Prop := + ∀ w, Admissible t c w → if positive then c.meaning q w else ¬ c.meaning q w +/- The consistency obligation prohibits both consequences at one comparison basis. -/ +def Consistent {W Q : Type} (t : Theory W) (c : Context W Q) : Prop := + ∀ q, ¬ (Consequence t c q true ∧ Consequence t c q false) +/- An inhabited joint interpretation prevents opposite semantic consequences. -/ +theorem consequenceConsistency {W Q : Type} (t : Theory W) (c : Context W Q) + (inhabited : ∃ w, Admissible t c w) : Consistent t c := by + intro q h + obtain ⟨w, hw⟩ := inhabited + exact (h.2 w hw) (h.1 w hw) +/- Empty and singleton theories provide concrete semantic contexts. -/ +def emptyTheory {W : Type} : Theory W := fun _ => False +def singleton {W : Type} (p : Claim W) : Theory W := fun q => q = p +def union {W : Type} (a b : Theory W) : Theory W := fun p => a p ∨ b p +theorem modelsSingleton {W : Type} (p : Claim W) (w : W) : Models (singleton p) w ↔ p w := by + constructor + · intro h; exact h p rfl + · intro h q hq; cases hq; exact h +theorem modelsUnion {W : Type} (a b : Theory W) (w : W) : + Models (union a b) w ↔ Models a w ∧ Models b w := by + constructor + · intro h; exact ⟨fun p hp => h p (Or.inl hp), fun p hp => h p (Or.inr hp)⟩ + · rintro ⟨ha,hb⟩ p (hp|hp); exact ha p hp; exact hb p hp +/- The paired world records independent truth values for two questions. -/ +def premiseP : Claim (Bool × Bool) := fun w => w.1 = true +def premiseRule : Claim (Bool × Bool) := fun w => w.1 = true → w.2 = true +def premiseNotQ : Claim (Bool × Bool) := fun w => w.2 ≠ true +def jointTheory : Theory (Bool × Bool) := + union (singleton premiseP) (union (singleton premiseRule) (singleton premiseNotQ)) +/- Each premise has a model, but their joint implication makes the union unsatisfiable. -/ +theorem jointConflict : + Satisfiable (singleton premiseP) ∧ Satisfiable (singleton premiseRule) ∧ + Satisfiable (singleton premiseNotQ) ∧ ¬ Satisfiable jointTheory := by + refine ⟨⟨(true,true), (modelsSingleton _ _).2 rfl⟩, + ⟨(false,false), (modelsSingleton _ _).2 (by intro h; cases h)⟩, + ⟨(false,false), (modelsSingleton _ _).2 (by intro h; cases h)⟩, ?_⟩ + rintro ⟨w, hw⟩ + have hp := hw premiseP (Or.inl rfl) + have hr := hw premiseRule (Or.inr (Or.inl rfl)) + have hn := hw premiseNotQ (Or.inr (Or.inr rfl)) + exact hn (hr hp) +/- A retraction replaces the old singleton, rather than retaining both at the same time. -/ +def revisionSlice (time : Nat) : Theory Bool := + singleton (fun w => w = (time == 0)) +/- The initial and revised slices have models; keeping both would create a conflict. -/ +theorem revisionCanReverse : + Satisfiable (revisionSlice 0) ∧ Satisfiable (revisionSlice 1) ∧ + ¬ Satisfiable (union (revisionSlice 0) (revisionSlice 1)) := by + refine ⟨⟨true, (modelsSingleton _ _).2 rfl⟩, + ⟨false, (modelsSingleton _ _).2 rfl⟩, ?_⟩ + rintro ⟨w, hw⟩ + have hs := (modelsUnion _ _ _).1 hw + have hp := (modelsSingleton _ _).1 hs.1 + have hn := (modelsSingleton _ _).1 hs.2 + have bad : true = false := hp.symm.trans hn + cases bad +/- This basic question asks whether the represented switch is on. -/ +def onQuestion : Unit → Claim Bool := fun _ w => w = true +def assumptionContext (b : Bool) : Context Bool Unit := + ⟨singleton (fun w => w = b), onQuestion, fun _ => True⟩ +def meaningContext (b : Bool) : Context Bool Unit := + ⟨singleton (fun w => w = true), (fun _ w => w = b), fun _ => True⟩ +def scopeContext (b : Bool) : Context Bool Unit := + ⟨emptyTheory, onQuestion, fun w => w = b⟩ +/- Distinct assumptions, meanings and scopes each admit opposite judgments without same-context conflict. -/ +theorem contextDifferences : + (Consequence emptyTheory (assumptionContext true) () true ∧ + Consequence emptyTheory (assumptionContext false) () false) ∧ + (Consequence emptyTheory (meaningContext true) () true ∧ + Consequence emptyTheory (meaningContext false) () false) ∧ + (Consequence emptyTheory (scopeContext true) () true ∧ + Consequence emptyTheory (scopeContext false) () false) ∧ + (∀ b, ∃ w, Admissible emptyTheory (assumptionContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (meaningContext b) w) ∧ + (∀ b, ∃ w, Admissible emptyTheory (scopeContext b) w) := by + have empty : ∀ w : Bool, Models emptyTheory w := by intro w p hp; cases hp + refine ⟨⟨?_, ?_⟩, ⟨?_, ?_⟩, ⟨?_, ?_⟩, ?_, ?_, ?_⟩ + · intro w h; change w = true; exact (modelsSingleton (fun x : Bool => x = true) w).1 h.2.1 + · intro w h hp; have hn := (modelsSingleton _ _).1 h.2.1; cases hp.symm.trans hn + · intro w h; change w = true; exact (modelsSingleton (fun x : Bool => x = true) w).1 h.2.1 + · intro w h hn; have hp := (modelsSingleton _ _).1 h.2.1; cases hp.symm.trans hn + · intro w h; exact h.2.2 + · intro w h hp; cases hp.symm.trans h.2.2 + · intro b; exact ⟨b, empty b, (modelsSingleton _ _).2 rfl, trivial⟩ + · intro b; exact ⟨true, empty true, (modelsSingleton _ _).2 rfl, trivial⟩ + · intro b; exact ⟨b, empty b, empty b, rfl⟩ +/- Snapshots preserve identifiable adopted-form revisions even when semantic content agrees. -/ +structure Snapshot (W Q : Type) where + held : Theory W + context : Context W Q + revisionIdentity : Nat +/- Semantic equivalence compares represented content, not its list ordering. -/ +def SameContent {W Q : Type} (a b : Snapshot W Q) : Prop := + (∀ p, a.held p ↔ b.held p) ∧ + (∀ p, a.context.assumptions p ↔ b.context.assumptions p) ∧ + (∀ q w, a.context.meaning q w ↔ b.context.meaning q w) ∧ + (∀ w, a.context.scope w ↔ b.context.scope w) +/- The reporting norm covers both semantic change and independently identified revisions. -/ +def TruthfulReport {W Q : Type} (a b : Snapshot W Q) (reported : Bool) : Prop := + (¬ SameContent a b ∨ a.revisionIdentity ≠ b.revisionIdentity) → reported = true +/- A real represented change and compliance entail an acknowledged change. -/ +theorem semanticChangeMustBeReported {W Q : Type} (a b : Snapshot W Q) (reported : Bool) + (changed : ¬ SameContent a b ∨ a.revisionIdentity ≠ b.revisionIdentity) + (h : TruthfulReport a b reported) : reported = true := h changed +/- Reordering a two-claim presentation preserves the held theory extension. -/ +theorem representationOrderIrrelevant {W : Type} (p q : Claim W) : + ∀ r, union (singleton p) (singleton q) r ↔ union (singleton q) (singleton p) r := by + intro r; exact or_comm +def contextSnapshot (c : Context Bool Unit) (revision : Nat := 0) : Snapshot Bool Unit := + ⟨emptyTheory, c, revision⟩ +/- Hiding each kind of contextual change violates the reporting interface; reporting alone supplies no truth guarantee. -/ +theorem hiddenContextChangeRejected : + ¬ TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (meaningContext true)) (contextSnapshot (meaningContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (scopeContext true)) (contextSnapshot (scopeContext false)) false ∧ + ¬ TruthfulReport (contextSnapshot (scopeContext true) 0) (contextSnapshot (scopeContext true) 1) false ∧ + (TruthfulReport (contextSnapshot (assumptionContext true)) (contextSnapshot (assumptionContext false)) true ∧ + ¬ Models (assumptionContext false).assumptions true) := by + have neq : (fun w : Bool => w = true) ≠ (fun w : Bool => w = false) := by + intro h; have k := congrFun h true; have z : true = false := k.mp rfl; cases z + refine ⟨?_, ?_, ?_, ?_, ?_⟩ + · intro h + have bad := h (Or.inl (by intro s; exact neq ((s.2.1 _).mp rfl))) + cases bad + · intro h + have bad := h (Or.inl (by intro s; have z := (s.2.2.1 () true).mp rfl; cases z)) + cases bad + · intro h + have bad := h (Or.inl (by intro s; have z := (s.2.2.2 true).mp rfl; cases z)) + cases bad + · intro h; have bad := h (Or.inr (by decide)); cases bad + · refine ⟨fun _ => rfl, ?_⟩ + intro h; have z := (modelsSingleton _ _).1 h; cases z +/- Two nonidentical resource objectives can share a feasible allocation. -/ +theorem tensionWithoutContradiction : + (∃ budget : Nat, 4 ≤ budget ∧ budget ≤ 6) ∧ + ¬ ((fun n : Nat => 4 ≤ n) = (fun n : Nat => n ≤ 6)) := by + refine ⟨⟨5, by decide, by decide⟩, ?_⟩ + intro h; have k := congrFun h 0; have bad : 4 ≤ 0 := k.mpr (by decide); cases bad +/- Conflicting conclusions cannot be retained under the same consistency obligation. -/ +theorem conflictRequiresChange {W Q : Type} (t : Theory W) (c : Context W Q) (q : Q) + (positive : Consequence t c q true) (negative : Consequence t c q false) : + ¬ Consistent t c := fun h => h q ⟨positive,negative⟩ +/- A satisfiable theory can have a false assumption at a specified actual world. -/ +theorem consistentFalse : Satisfiable (singleton (fun w : Bool => w = true)) ∧ + ¬ Models (singleton (fun w : Bool => w = true)) false := by + refine ⟨⟨true, (modelsSingleton _ _).2 rfl⟩, ?_⟩ + intro h; have bad := (modelsSingleton _ _).1 h; cases bad +/- The explicitly asked on/off question is undecided by the empty but inhabited theory. -/ +theorem consistentIncomplete : Satisfiable (emptyTheory : Theory Bool) ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true) ∧ + ¬ Entails emptyTheory (fun w : Bool => w ≠ true) := by + have empty : ∀ w : Bool, Models emptyTheory w := by intro w p hp; cases hp + refine ⟨⟨true, empty true⟩, ?_, ?_⟩ + · intro h; have bad := h false (empty false); cases bad + · intro h; exact h true (empty true) rfl +/- A claim can share a model with a theory without following in every model. -/ +theorem compatibilityNotEntailment : + Satisfiable (union emptyTheory (singleton (fun w : Bool => w = true))) ∧ + ¬ Entails emptyTheory (fun w : Bool => w = true) := by + refine ⟨⟨true, (modelsUnion _ _ _).2 ⟨?_, (modelsSingleton _ _).2 rfl⟩⟩, + consistentIncomplete.2.1⟩ + intro p hp; cases hp + +end CoreReader.Logic +``` + + + + **L1** 打开命名空间 CoreReader.Logic,使后续声明获得这一模块限定名。 + + + **L3** 说明 Claim 的预定范围。对应声明涉及:主张是从给定世界类型到命题的函数,不预设现实解释。 该注释用于解释,不是证明前提。 + + + **L4** 引入类型缩写 Claim。主张是从给定世界类型到命题的函数,不预设现实解释。 + + + **L5** 说明 Theory 的预定范围。对应声明涉及:理论用谓词选择同时持有的主张,不要求有限语法。 该注释用于解释,不是证明前提。 + + + **L6** 引入类型缩写 Theory。理论用谓词选择同时持有的主张,不要求有限语法。 + + + **L7** 说明 Models 的预定范围。对应声明涉及:世界满足理论,指理论选择的每个主张都在此世界成立。 该注释用于解释,不是证明前提。 + + + **L8** 定义 Models。世界满足理论,指理论选择的每个主张都在此世界成立。 + + + **L9** 说明 Entails 的预定范围。对应声明涉及:在所有理论模型中结论都成立;无模型时蕴涵可空真。 该注释用于解释,不是证明前提。 + + + **L10** 定义 Entails。在所有理论模型中结论都成立;无模型时蕴涵可空真。 + + + **L11** 说明 Satisfiable 的预定范围。对应声明涉及:要求存在实际世界及其满足全部理论主张的证明。 该注释用于解释,不是证明前提。 + + + **L12** 定义 Satisfiable。要求存在实际世界及其满足全部理论主张的证明。 + + + **L13** 说明 Context 的预定范围。对应声明涉及:分别保存附加假设、问题含义和适用范围。 该注释用于解释,不是证明前提。 + + + **L14** 声明数据接口 Context。分别保存附加假设、问题含义和适用范围。 + + + **L15** 保存真实的上下文假设理论,与所持理论分开。 + + + **L16** 把每个问题解释为针对每个世界的命题。 + + + **L17** 保存选择被接纳应用范围的谓词。 + + + **L18** 说明 Admissible 的预定范围。对应声明涉及:同一世界同时满足持有理论、上下文假设和范围。 该注释用于解释,不是证明前提。 + + + **L19** 定义 Admissible。同一世界同时满足持有理论、上下文假设和范围。 + + + **L20** 要求同一世界同时满足两个理论及上下文范围。 + + + **L21** 说明 Consequence 的预定范围。对应声明涉及:在同一上下文全部可接受世界中,要求指定问题的正或负结论。 该注释用于解释,不是证明前提。 + + + **L22** 定义 Consequence。在同一上下文全部可接受世界中,要求指定问题的正或负结论。 + + + **L23** 对每个可接受世界量化;符号选择该问题的含义或其否定。 + + + **L24** 说明 Consistent 的预定范围。对应声明涉及:禁止同一问题的正反后果并存;问题类型为空时条件空真。 该注释用于解释,不是证明前提。 + + + **L25** 定义 Consistent。禁止同一问题的正反后果并存;问题类型为空时条件空真。 + + + **L26** 对每个问题,禁止同一上下文中正反后果的合取。 + + + **L27** 说明 consequenceConsistency 的预定范围。对应声明涉及:用显式可接受世界同时实例化正反后果,导出矛盾,得到上下文一致性。 该注释用于解释,不是证明前提。 + + + **L28** 陈述经检查的结果 consequenceConsistency。用显式可接受世界同时实例化正反后果,导出矛盾,得到上下文一致性。 + + + **L29** 假定整个上下文具有可接受见证,得出其一致性;开始证明。 + + + **L30** 引入任意问题 q,以及假定的同一上下文中正反后果对 h。 + + + **L31** 从显式非空前提 inhabited 提取共同可接受世界 w,以及它满足整套理论、假设与范围的证明 hw。 + + + **L32** 在同一 w 与 hw 处应用 h 的两部分;否定后果与肯定后果矛盾。 + + + **L33** 说明 emptyTheory 的预定范围。对应声明涉及:不选择任何主张,故每个世界都是模型。 该注释用于解释,不是证明前提。 + + + **L34** 定义 emptyTheory。不选择任何主张,故每个世界都是模型。 + + + **L35** 定义 singleton。只选择与指定主张相等的谓词。 + + + **L36** 定义 union。以成员关系的析取合并两个理论。 + + + **L37** 陈述经检查的结果 modelsSingleton。证明满足单一主张理论等价于该主张在当前世界成立。 后续策略块证明这一显式类型。 + + + **L38** 将满足单一主张理论与满足该主张的等价关系拆为两个蕴含。 + + + **L39** 把假定的单元素理论模型 h 应用于 p;p 的成员关系由自反相等成立。 + + + **L40** 任取被选择的主张 q,单元素成员关系将 q 与 p 等同;代入这一等式并返回 p 已成立的前提 h。 + + + **L41** 陈述经检查的结果 modelsUnion。证明同一世界满足理论并集等价于同时满足两部分。 + + + **L42** 陈述同一世界满足理论并集,当且仅当它满足两个组成理论。 + + + **L43** 分别证明满足并集与同时满足两个理论之间的正反方向。 + + + **L44** 把成员证明嵌入左或右析取,将并集模型 h 分别限制到两个理论。 + + + **L45** 拆出两个组成理论的模型,将并集成员关系分为两种情况,并在同一主张与世界上使用对应模型。 + + + **L46** 说明 premiseP 的预定范围。对应声明涉及:要求布尔对的第一坐标为真。 该注释用于解释,不是证明前提。 + + + **L47** 定义 premiseP。要求布尔对的第一坐标为真。 + + + **L48** 定义 premiseRule。要求第一坐标为真时第二坐标也为真。 + + + **L49** 定义 premiseNotQ。要求第二坐标不为真。 + + + **L50** 定义 jointTheory。组合第一坐标事实、推论规则和第二坐标的否定。 + + + **L51** 通过嵌套理论并集,同时持有 P、P 蕴含 Q 的规则及非 Q。 + + + **L52** 说明 jointConflict 的预定范围。对应声明涉及:三个单项各自有模型,联合后以P及P→Q反驳¬Q,证明无共同模型。 该注释用于解释,不是证明前提。 + + + **L53** 陈述经检查的结果 jointConflict。三个单项各自有模型,联合后以P及P→Q反驳¬Q,证明无共同模型。 + + + **L54** 前两个结论分别为 P 与蕴含规则提供模型。 + + + **L55** 还要求非 Q 单独有模型,却否定整套联合理论具有模型。 + + + **L56** 给 P 提供模型 (true,true),用 modelsSingleton 将第一坐标相等转换为所需模型证明。 + + + **L57** 给蕴含前提提供模型 (false,false):其第一坐标为 false,假定它为 true 即矛盾。 + + + **L58** 给非 Q 提供模型 (false,false),留下联合不可满足分支待证。 + + + **L59** 假定存在联合模型 w 及证明 hw,以反驳其存在。 + + + **L60** 利用 P 在联合理论中的左侧成员关系,提取实际第一坐标事实。 + + + **L61** 通过规则在嵌套并集中的成员关系,提取 P 蕴含 Q。 + + + **L62** 在同一世界,从另一个嵌套并集分支提取非 Q。 + + + **L63** 将规则应用于 P 得到 Q,与已提取的非 Q 矛盾。 + + + **L64** 说明 revisionSlice 的预定范围。对应声明涉及:时刻零选择真世界,其他自然数时刻选择假世界。 该注释用于解释,不是证明前提。 + + + **L65** 定义 revisionSlice。时刻零选择真世界,其他自然数时刻选择假世界。 + + + **L66** 只选择一个主张:世界等于测试 time=0 所得布尔值。 + + + **L67** 说明 revisionCanReverse 的预定范围。对应声明涉及:给旧新切片各自的模型,并以真与假不可相等证明二者联合冲突。 该注释用于解释,不是证明前提。 + + + **L68** 陈述经检查的结果 revisionCanReverse。给旧新切片各自的模型,并以真与假不可相等证明二者联合冲突。 + + + **L69** 要求时间切片 0 与 1 各自具有模型见证。 + + + **L70** 否定两者同时并集的模型,而不否定各自见证。 + + + **L71** 给时间零的单元素理论提供 true 见证。 + + + **L72** 给时间一提供 false 见证,留下同时持有两个切片不可能的证明。 + + + **L73** 假定一个世界同时满足两个时间切片。 + + + **L74** 把并集模型拆为同一世界中的时间零与时间一模型。 + + + **L75** 从时间零单元素理论提取共同世界等于 true。 + + + **L76** 从时间一单元素理论提取同一世界等于 false。 + + + **L77** 经由同一世界合成两个等式,推出不可能的 true = false。 + + + **L78** 消去两个不同布尔构造子之间的不可能等式。 + + + **L79** 说明 onQuestion 的预定范围。对应声明涉及:唯一Unit问题询问布尔世界是否为真。 该注释用于解释,不是证明前提。 + + + **L80** 定义 onQuestion。唯一Unit问题询问布尔世界是否为真。 + + + **L81** 定义 assumptionContext。固定问题与全范围,只改变选择世界的假设。 + + + **L82** 通过假设选择世界 b,保留相同开启问题,并令范围允许所有世界。 + + + **L83** 定义 meaningContext。固定真世界假设,只改变问题的等值含义。 + + + **L84** 保持真世界假设,改为询问与 b 相等;范围仍不受限。 + + + **L85** 定义 scopeContext。固定空假设和问题,只由范围选择世界。 + + + **L86** 使假设为空且问题固定,仅让范围选择世界 b。 + + + **L87** 说明 contextDifferences 的预定范围。对应声明涉及:分别改变假设、含义、范围得到相反判断;所有展示上下文都有明确可接受世界。 该注释用于解释,不是证明前提。 + + + **L88** 陈述经检查的结果 contextDifferences。分别改变假设、含义、范围得到相反判断;所有展示上下文都有明确可接受世界。 + + + **L89** 要求在真值假设下给出肯定答案。 + + + **L90** 要求在假值假设下给出否定答案;两者上下文不同。 + + + **L91** 要求对含义为等于 true 的问题给出肯定答案。 + + + **L92** 当同一问题改为表示等于 false 时,要求否定答案。 + + + **L93** 要求在限制为 true 的范围内给出肯定答案。 + + + **L94** 要求在另一个限制为 false 的范围内给出否定答案。 + + + **L95** 对任一假设选择,要求实际可接受世界存在。 + + + **L96** 对任一问题含义,要求实际可接受世界存在。 + + + **L97** 对任一范围选择,要求实际可接受世界存在,并开始组合证明。 + + + **L98** 证明每个布尔世界都满足 emptyTheory,因为该理论的成员关系为 False。 + + + **L99** 拆分改变假设、含义和范围后的正反答案对,以及三类上下文的非空见证义务。 + + + **L100** 在真值假设上下文中,从单元素上下文假设读出 w = true。 + + + **L101** 在假值假设上下文中,假定肯定答案会与单元素假设 w = false 矛盾。 + + + **L102** 当问题含义为真值时,用固定的真世界假设确立肯定答案。 + + + **L103** 当问题含义变为假值时,假定该含义成立会与不变的真世界假设矛盾。 + + + **L104** 在真值范围上下文中,范围组件本身给出所需肯定答案。 + + + **L105** 在假值范围上下文中,肯定答案与同一世界的范围组件矛盾。 + + + **L106** 对任一假设 b,世界 b 满足空的所持理论、该单元素假设与不受限范围。 + + + **L107** 对任一问题含义 b,true 仍为见证,因为假设固定为 true 且范围不受限。 + + + **L108** 对任一范围选择 b,世界 b 满足两个空理论,并通过相等满足所选范围。 + + + **L109** 说明 Snapshot 的预定范围。对应声明涉及:保存同时持有理论、上下文和独立修订标识,不实现历史验证。 该注释用于解释,不是证明前提。 + + + **L110** 声明数据接口 Snapshot。保存同时持有理论、上下文和独立修订标识,不实现历史验证。 + + + **L111** 在快照中保存同时持有主张的理论。 + + + **L112** 以一个 Context 保存快照的假设、问题含义与范围。 + + + **L113** 保存独立的自然数修订标识,不蕴含历史验证。 + + + **L114** 说明 SameContent 的预定范围。对应声明涉及:比较理论成员、附加假设成员及逐问题逐世界的含义和范围。 该注释用于解释,不是证明前提。 + + + **L115** 定义 SameContent。比较理论成员、附加假设成员及逐问题逐世界的含义和范围。 + + + **L116** 要求两个快照中每个所持主张的成员关系一致。 + + + **L117** 要求每个上下文假设的成员关系一致。 + + + **L118** 要求每个问题在每个世界具有等价含义。 + + + **L119** 要求每个世界中的范围谓词等价。 + + + **L120** 说明 TruthfulReport 的预定范围。对应声明涉及:内容或修订标识变化时必须报告真;不要求报告真必然有变化,也不检测变化。 该注释用于解释,不是证明前提。 + + + **L121** 定义 TruthfulReport。内容或修订标识变化时必须报告真;不要求报告真必然有变化,也不检测变化。 + + + **L122** 将如实报告定义为:内容不同或独立修订标识不同,就给出积极标记。 + + + **L123** 说明 semanticChangeMustBeReported 的预定范围。对应声明涉及:把给定变化证据应用于给定报告规范,得到报告为真。 该注释用于解释,不是证明前提。 + + + **L124** 陈述经检查的结果 semanticChangeMustBeReported。把给定变化证据应用于给定报告规范,得到报告为真。 + + + **L125** 假定实际发生变更:内容不同或修订标识不同。 + + + **L126** 假定报告义务,并应用于前述变更前提,得到 reported=true。 + + + **L127** 说明 representationOrderIrrelevant 的预定范围。对应声明涉及:用析取交换律证明两个单项理论交换顺序不改变成员关系。 该注释用于解释,不是证明前提。 + + + **L128** 陈述经检查的结果 representationOrderIrrelevant。用析取交换律证明两个单项理论交换顺序不改变成员关系。 + + + **L129** 对任意主张 r,交换 p 与 q 保持其单元素理论并集中的成员关系。 + + + **L130** 任取候选主张 r,利用析取交换性证明重排 p 与 q 后并集成员关系不变。 + + + **L131** 定义 contextSnapshot。将上下文包装成空持有理论的快照,默认修订标识为零。 + + + **L132** 构造所持主张为空、采用给定上下文及修订标识的快照。 + + + **L133** 说明 hiddenContextChangeRejected 的预定范围。对应声明涉及:分别拒绝隐瞒假设、含义、范围及标识变化,并说明报告变化不保证新假设为真。 该注释用于解释,不是证明前提。 + + + **L134** 陈述经检查的结果 hiddenContextChangeRejected。分别拒绝隐瞒假设、含义、范围及标识变化,并说明报告变化不保证新假设为真。 + + + **L135** 实际上下文假设从 true 变为 false 时,拒绝 false 报告。 + + + **L136** 问题实际含义改变时,拒绝 false 报告。 + + + **L137** 实际应用范围改变时,拒绝 false 报告。 + + + **L138** 上下文不变但修订身份从 0 变为 1 时,拒绝 false 报告。 + + + **L139** 允许以 true 报告如实承认假设变化。 + + + **L140** 但否定这些修订后的假世界假设在实际 true 处成立。 + + + **L141** 准备语义不等式:选择 true 与选择 false 的谓词是不同函数。 + + + **L142** 在 true 处计算假定的谓词相等,它会把自反成立转换为 true = false。 + + + **L143** 拆出四种被拒绝的隐瞒变更,以及最后已报告但假设为假的实例。 + + + **L144** 假定隐瞒假设变化且报告为 false 仍满足 TruthfulReport,以反驳这一主张。 + + + **L145** 假定 SameContent 会使已改变的假设谓词相等;已知其不等,因此触发 TruthfulReport,迫使 false 标记为 true。 + + + **L146** 所需 true 报告与指定的 false 标记矛盾,因此结束这一隐瞒变更分支。 + + + **L147** 假定问题含义改变后仍可如实报告为未改变。 + + + **L148** 在唯一问题与 true 世界处,变化后的含义否定 SameContent;报告义务因而要求积极报告。 + + + **L149** 所需 true 报告与指定的 false 标记矛盾,因此结束这一隐瞒变更分支。 + + + **L150** 假定应用范围改变后仍能以 false 变更标记满足报告规则。 + + + **L151** 在 true 处比较两个范围以否定 SameContent,再对这一真实范围变化应用报告义务。 + + + **L152** 所需 true 报告与指定的 false 标记矛盾,因此结束这一隐瞒变更分支。 + + + **L153** 不同修订身份本身就触发报告规则;即使没有内容变化,也与 false 报告矛盾。 + + + **L154** 构造始终积极的如实报告,另留下修订假设真实性的反证。 + + + **L155** 在实际世界 true 提取修订后的假世界假设;其不可能等式表明报告变更不使假设变真。 + + + **L156** 说明 tensionWithoutContradiction 的预定范围。对应声明涉及:预算五同时满足不同上下界;预算零证明两约束谓词并不相同。 该注释用于解释,不是证明前提。 + + + **L157** 陈述经检查的结果 tensionWithoutContradiction。预算五同时满足不同上下界;预算零证明两约束谓词并不相同。 + + + **L158** 要求存在同时满足下界 4 与上界 6 的自然数预算。 + + + **L159** 还断言两个界限谓词不同,即使它们可以共同满足。 + + + **L160** 选择预算 5,检查两个数值界限,留下两个目标谓词不同的证明。 + + + **L161** 在预算 0 处,上界成立而下界不可能成立,因此两个目标谓词不相等。 + + + **L162** 说明 conflictRequiresChange 的预定范围。对应声明涉及:同题同条件正反后果违反一致性规范;不构造具体修复算法。 该注释用于解释,不是证明前提。 + + + **L163** 陈述经检查的结果 conflictRequiresChange。同题同条件正反后果违反一致性规范;不构造具体修复算法。 + + + **L164** 假定同一理论、上下文与问题具有两个相反后果。 + + + **L165** 任何 Consistent 证明都禁止给定后果对;应用这一点否定一致性,并未构造修订。 + + + **L166** 说明 consistentFalse 的预定范围。对应声明涉及:理论有真世界模型,却在指定假世界不成立,区分可满足与实际真。 该注释用于解释,不是证明前提。 + + + **L167** 陈述经检查的结果 consistentFalse。理论有真世界模型,却在指定假世界不成立,区分可满足与实际真。 + + + **L168** 否定实际 false 满足唯一主张为 world=true 的理论。 + + + **L169** 提供 true 作为单元素理论的模型,另行否定实际世界 false 满足该理论。 + + + **L170** 在 false 处满足单元素理论会迫使 false = true,产生不可能的布尔等式。 + + + **L171** 说明 consistentIncomplete 的预定范围。对应声明涉及:空理论有模型,但指定布尔问题及其否定都不被蕴涵。 该注释用于解释,不是证明前提。 + + + **L172** 陈述经检查的结果 consistentIncomplete。空理论有模型,但指定布尔问题及其否定都不被蕴涵。 + + + **L173** 具有见证的空理论不蕴含肯定的真世界答案。 + + + **L174** 它也不蕴含否定的真世界答案;分别证明这两个失败。 + + + **L175** 证明每个布尔世界都满足 emptyTheory,因为该理论的成员关系为 False。 + + + **L176** 提供非空的空理论模型,留下肯定与否定蕴含两个反证。 + + + **L177** 假定蕴含 world=true,会在空理论模型 false 处失败。 + + + **L178** 假定蕴含 world≠true,会在空理论模型 true 处失败。 + + + **L179** 说明 compatibilityNotEntailment 的预定范围。对应声明涉及:新增主张可以与原理论相容,但原理论仍不蕴涵该主张。 该注释用于解释,不是证明前提。 + + + **L180** 陈述经检查的结果 compatibilityNotEntailment。新增主张可以与原理论相容,但原理论仍不蕴涵该主张。 + + + **L181** 要求存在使 emptyTheory 与肯定单元素主张共同成立的模型。 + + + **L182** 仍否定 emptyTheory 本身蕴含该肯定主张。 + + + **L183** 用世界 true 见证空理论与肯定的单元素主张相容。 + + + **L184** 复用已证的空理论不能蕴含肯定主张的结果。 + + + **L185** 完成模型见证:没有主张能够实际属于 emptyTheory。 + + + **L187** 关闭命名空间 CoreReader.Logic;这不增加证明或前提。 + + +### `leanified/CoreReader/Reflexivity.lean` + + +```lean +import Std + +namespace CoreReader.Agency + +inductive Phase | formation | application | revision + deriving DecidableEq, Repr + +structure PrincipleKey where + owner : Nat + localId : Nat + deriving DecidableEq, Repr + +inductive Subject + | system (owner : Nat) + | principle (owner id : Nat) + | process (owner id : Nat) (phase : Phase) + deriving DecidableEq, Repr + +def Subject.owner : Subject → Nat + | .system n => n + | .principle n _ => n + | .process n _ _ => n + +inductive Activity | generation | assessment + deriving DecidableEq, Repr + +inductive QuestionKind | conformity | formationBasis | applicability | revisionGrounds + deriving DecidableEq, Repr + +inductive SampleProgram | alwaysTrue | onlyAtZero + deriving DecidableEq, Repr + +def SampleProgram.run : SampleProgram → Nat → Bool + | .alwaysTrue, _ => true + | .onlyAtZero, n => n == 0 + +/- A generated candidate specifies both the inputs it tests and the scope it proposes to license. -/ +structure MethodDraft where + testedInputs : List Nat + claimedScope : List Nat + deriving DecidableEq, Repr + +def MethodDraft.accepts (draft : MethodDraft) (program : SampleProgram) : Bool := + draft.testedInputs.all program.run + +/- This finite application asks whether a proposed rule's observed inputs support its claimed input scope. -/ +structure Inquiry where + target : Subject + kind : QuestionKind + requestedScope : List Nat + currentMethod : MethodDraft + deriving DecidableEq, Repr + +inductive ReasonContent + | purpose (inputs : List Nat) + | declaredScope (inputs : List Nat) + | observation (input : Nat) (output : Bool) + | counterexample (program : SampleProgram) (input : Nat) + deriving DecidableEq, Repr + +def ReasonContent.identifier : ReasonContent → Nat + | .purpose _ => 0 + | .declaredScope _ => 1 + | .observation _ _ => 2 + | .counterexample _ _ => 3 + +/- Reasons have independently supplied contents, a stable local reference and the actual target they concern. -/ +structure ReasonObject where + reference : Nat + target : Subject + content : ReasonContent + deriving DecidableEq, Repr + +inductive AssessmentResult | supportedWithinScope | insufficient | notApplicable | undetermined + deriving DecidableEq, Repr + +inductive WorkOutcome + | assessment (result : AssessmentResult) + | generated (draft : MethodDraft) + deriving DecidableEq, Repr + +/- A method's question, source reasons and limits are determined before looking at its activity records. +The meaning relation describes application of that method, not its universal adequacy. -/ +structure Principle where + key : PrincipleKey + activity : Activity + declaredMethod : MethodDraft + applicable : Subject → Prop + inquiry : Subject → Inquiry + reasons : Subject → List ReasonObject + limits : Subject → List Nat + meaning : Inquiry → List ReasonObject → List Nat → WorkOutcome → Prop + +structure WorkRecord where + usedPrinciple : PrincipleKey + target : Subject + activity : Activity + inquiry : Inquiry + reasons : List ReasonObject + limits : List Nat + outcome : WorkOutcome + deriving DecidableEq, Repr + +def RegistryCoherent (rules : List Principle) : Prop := + ∀ p ∈ rules, ∀ q ∈ rules, p.key = q.key → p = q + +def TargetResolved (rules : List Principle) : Subject → Prop + | .system owner => ∃ p ∈ rules, p.key.owner = owner + | .principle owner id | .process owner id _ => ∃ p ∈ rules, p.key = ⟨owner,id⟩ + +/- The inquiry names the registered target's declared method contract, not an unrelated candidate. +For a system inquiry this finite model uses the registered generation contract as its assessed artifact. -/ +def TargetContentResolved (rules : List Principle) (question : Inquiry) : Prop := + match question.target with + | .system owner => ∃ p ∈ rules, p.key = ⟨owner,0⟩ ∧ question.currentMethod = p.declaredMethod + | .principle owner id | .process owner id _ => + ∃ p ∈ rules, p.key = ⟨owner,id⟩ ∧ question.currentMethod = p.declaredMethod + +def Performed (records : List WorkRecord) (s : Subject) (a : Activity) : Prop := + ∃ record ∈ records, record.target = s ∧ record.activity = a + +/- The old scope condition remains available without conflating scope with content completion. -/ +def ReflexiveScope (owner : Nat) (rules : List Principle) (records : List WorkRecord) : Prop := + ∀ rule ∈ rules, ∀ s, s.owner = owner → rule.applicable s → Performed records s rule.activity + +/- A record uses a registered principle on the same resolvable target, question, reasons and limits, +and its result must actually follow that principle's method. A negative result can satisfy this relation. -/ +structure ValidApplication (rules : List Principle) (rule : Principle) (s : Subject) + (record : WorkRecord) : Prop where + registered : rule ∈ rules + applicable : rule.applicable s + usedIdentity : record.usedPrinciple = rule.key + targetIdentity : record.target = s + targetResolved : TargetResolved rules s + activityIdentity : record.activity = rule.activity + inquiryIdentity : record.inquiry = rule.inquiry s + inquiryTarget : record.inquiry.target = s + targetContent : TargetContentResolved rules record.inquiry + reasonsIdentity : record.reasons = rule.reasons s + reasonsNonempty : record.reasons ≠ [] + reasonTargets : ∀ reason ∈ record.reasons, reason.target = s + limitsIdentity : record.limits = rule.limits s + followsMeaning : rule.meaning record.inquiry record.reasons record.limits record.outcome + +/- The registered normative interface requires contentful application, not just activity labels. -/ +def Reflexive (owner : Nat) (rules : List Principle) (records : List WorkRecord) : Prop := + RegistryCoherent rules ∧ + ∀ rule ∈ rules, ∀ s, s.owner = owner → rule.applicable s → + ∃ record ∈ records, ValidApplication rules rule s record + +theorem Reflexive.toScope {owner : Nat} {rules : List Principle} {records : List WorkRecord} + (h : Reflexive owner rules records) : ReflexiveScope owner rules records := by + intro rule hr s hs ha + obtain ⟨record, hm, hv⟩ := h.2 rule hr s hs ha + exact ⟨record, hm, hv.targetIdentity, hv.activityIdentity⟩ + +theorem noSelfExemption (owner : Nat) (rules : List Principle) (records : List WorkRecord) + (h : Reflexive owner rules records) (rule : Principle) (hr : rule ∈ rules) + (s : Subject) (hs : s.owner = owner) (ha : rule.applicable s) : + Performed records s rule.activity := h.toScope rule hr s hs ha + +def localMethod : MethodDraft := ⟨[0],[0]⟩ + +def inquiryFor (s : Subject) : Inquiry := + match s with + | .process _ _ .formation => ⟨s, .formationBasis, [0], localMethod⟩ + | .process _ _ .application => ⟨s, .applicability, [0], localMethod⟩ + | .process _ _ .revision => ⟨s, .revisionGrounds, [0,1], localMethod⟩ + | _ => ⟨s, .conformity, [0], localMethod⟩ + +/- These original inquiry inputs do not depend on which work records happen to be present. -/ +def sourceReasonContents : QuestionKind → List ReasonContent + | .formationBasis => [.purpose [0], .declaredScope [0], .observation 0 true] + | .applicability | .conformity => [.declaredScope [0], .observation 0 true] + | .revisionGrounds => [.purpose [0,1], .declaredScope [0], .observation 0 true, + .counterexample .onlyAtZero 1] + +def reasonsFor (s : Subject) : List ReasonObject := + (sourceReasonContents (inquiryFor s).kind).map fun content => ⟨content.identifier,s,content⟩ + +/- The application-specific evaluator examines actual scope and sample/counterexample contents. +It is a finite inferential method, not a universal standard for empirical or value claims. -/ +def assessInquiry (question : Inquiry) (reasons : List ReasonObject) (limits : List Nat) : AssessmentResult := + let contents := reasons.map ReasonObject.content + if limits ≠ question.currentMethod.claimedScope then .undetermined else + match question.kind with + | .formationBasis => + if ReasonContent.purpose question.requestedScope ∈ contents ∧ + ReasonContent.declaredScope limits ∈ contents ∧ question.requestedScope = limits + then .supportedWithinScope else .undetermined + | .applicability | .conformity => + if question.requestedScope.all (fun n => limits.contains n) then + if ReasonContent.declaredScope limits ∈ contents ∧ + ReasonContent.observation 0 true ∈ contents ∧ question.requestedScope = [0] + then .supportedWithinScope else .undetermined + else .notApplicable + | .revisionGrounds => + if ReasonContent.purpose question.requestedScope ∈ contents ∧ + ReasonContent.declaredScope limits ∈ contents ∧ + ReasonContent.observation 0 true ∈ contents ∧ + contents.any (fun reason => match reason with + | .counterexample program input => question.requestedScope.contains input && + question.currentMethod.accepts program && + !(program.run input) + | _ => false) + then .insufficient else .undetermined + +def finiteMethodResult (activity : Activity) (question : Inquiry) + (reasons : List ReasonObject) (limits : List Nat) : WorkOutcome := + match activity with + | .generation => .generated ⟨question.currentMethod.testedInputs,question.requestedScope⟩ + | .assessment => .assessment (assessInquiry question reasons limits) + +def finiteMethodMeaning (activity : Activity) (question : Inquiry) + (reasons : List ReasonObject) (limits : List Nat) (outcome : WorkOutcome) : Prop := + outcome = finiteMethodResult activity question reasons limits + +def ownSubjects (owner : Nat) : List Subject := + [.system owner, .principle owner 0, .principle owner 1, + .process owner 0 .formation, .process owner 0 .application, .process owner 0 .revision, + .process owner 1 .formation, .process owner 1 .application, .process owner 1 .revision] + +/- Applying an existing rule is not a generation event in this application. -/ +def generationEligible : Subject → Bool + | .process _ _ .application => false + | _ => true + +def generatingRule (owner : Nat) : Principle where + key := ⟨owner,0⟩ + activity := .generation + declaredMethod := localMethod + applicable s := s ∈ ownSubjects owner ∧ generationEligible s = true + inquiry := inquiryFor + reasons := reasonsFor + limits _ := [0] + meaning := finiteMethodMeaning .generation + +def assessingRule (owner : Nat) : Principle where + key := ⟨owner,1⟩ + activity := .assessment + declaredMethod := localMethod + applicable s := s ∈ ownSubjects owner + inquiry := inquiryFor + reasons := reasonsFor + limits _ := [0] + meaning := finiteMethodMeaning .assessment + +def ownRules (owner : Nat) : List Principle := [generatingRule owner, assessingRule owner] + +/- Recorded verdicts are stated separately from the evaluator, so agreement has to be proved. -/ +def statedOutcome (activity : Activity) (s : Subject) : WorkOutcome := + match activity with + | .generation => .generated ⟨(inquiryFor s).currentMethod.testedInputs,(inquiryFor s).requestedScope⟩ + | .assessment => .assessment (match (inquiryFor s).kind with + | .revisionGrounds => .insufficient + | _ => .supportedWithinScope) + +def recordFor (rule : Principle) (s : Subject) : WorkRecord := + ⟨rule.key,s,rule.activity,rule.inquiry s,rule.reasons s,rule.limits s,statedOutcome rule.activity s⟩ + +theorem reasonsFor_nonempty (s : Subject) : reasonsFor s ≠ [] := by + cases s with + | system owner => simp [reasonsFor, inquiryFor, sourceReasonContents] + | principle owner id => simp [reasonsFor, inquiryFor, sourceReasonContents] + | process owner id phase => cases phase <;> simp [reasonsFor, inquiryFor, sourceReasonContents] + +theorem reasonsFor_target (s : Subject) : ∀ reason ∈ reasonsFor s, reason.target = s := by + intro reason h + obtain ⟨content, _, rfl⟩ := List.mem_map.mp h + rfl + +theorem inquiryFor_target (s : Subject) : (inquiryFor s).target = s := by + cases s with + | system owner => rfl + | principle owner id => rfl + | process owner id phase => cases phase <;> rfl + +/- This proof includes the actual negative revision evaluation for both principle identities. -/ +theorem ownContentEvaluates (activity : Activity) (s : Subject) : + statedOutcome activity s = finiteMethodResult activity (inquiryFor s) (reasonsFor s) [0] := by + cases activity with + | generation => rfl + | assessment => + cases s with + | system owner => rfl + | principle owner id => rfl + | process owner id phase => cases phase <;> rfl + +theorem ownRegistryCoherent (owner : Nat) : RegistryCoherent (ownRules owner) := by + intro p hp q hq hkey + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hp hq + rcases hp with rfl | rfl <;> rcases hq with rfl | rfl + · rfl + · have bad := congrArg PrincipleKey.localId hkey; contradiction + · have bad := congrArg PrincipleKey.localId hkey; contradiction + · rfl + +theorem ownTargetResolved (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) : + TargetResolved (ownRules owner) s := by + simp only [ownSubjects, List.mem_cons, List.not_mem_nil, or_false] at hs + rcases hs with rfl | rfl | rfl | rfl | rfl | rfl | rfl | rfl | rfl <;> + simp [TargetResolved, ownRules, generatingRule, assessingRule] + +theorem ownTargetContent (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) : + TargetContentResolved (ownRules owner) (inquiryFor s) := by + simp only [ownSubjects, List.mem_cons, List.not_mem_nil, or_false] at hs + rcases hs with rfl | rfl | rfl | rfl | rfl | rfl | rfl | rfl | rfl <;> + simp [TargetContentResolved, inquiryFor, ownRules, generatingRule, assessingRule] + +theorem ownRecordValid (owner : Nat) (rule : Principle) (hr : rule ∈ ownRules owner) + (s : Subject) (ha : rule.applicable s) : + ValidApplication (ownRules owner) rule s (recordFor rule s) := by + have hs : s ∈ ownSubjects owner := by + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl + · exact ha.1 + · exact ha + have hq : rule.inquiry = inquiryFor := by + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl <;> rfl + have hg : rule.reasons = reasonsFor := by + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl <;> rfl + have hl : rule.limits s = [0] := by + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl <;> rfl + have hm : rule.meaning = finiteMethodMeaning rule.activity := by + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl <;> rfl + refine ⟨hr, ha, rfl, rfl, ownTargetResolved owner s hs, rfl, rfl, ?_, ?_, rfl, ?_, ?_, rfl, ?_⟩ + · change (rule.inquiry s).target = s + rw [hq]; exact inquiryFor_target s + · change TargetContentResolved (ownRules owner) (rule.inquiry s) + rw [hq]; exact ownTargetContent owner s hs + · change rule.reasons s ≠ [] + rw [hg]; exact reasonsFor_nonempty s + · change ∀ reason ∈ rule.reasons s, reason.target = s + rw [hg]; exact reasonsFor_target s + · change rule.meaning (rule.inquiry s) (rule.reasons s) (rule.limits s) (statedOutcome rule.activity s) + rw [hm, hq, hg, hl] + exact ownContentEvaluates rule.activity s + +def completeOwnWork (owner : Nat) : List WorkRecord := + (ownSubjects owner).flatMap fun s => + if generationEligible s then [recordFor (generatingRule owner) s, recordFor (assessingRule owner) s] + else [recordFor (assessingRule owner) s] + +theorem assessingRecord_member (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) : + recordFor (assessingRule owner) s ∈ completeOwnWork owner := by + apply List.mem_flatMap.mpr + refine ⟨s,hs,?_⟩ + cases generationEligible s <;> simp + +theorem generatingRecord_member (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) + (hg : generationEligible s = true) : recordFor (generatingRule owner) s ∈ completeOwnWork owner := by + exact List.mem_flatMap.mpr ⟨s,hs,by simp [hg]⟩ + +theorem completeOwnWork_reflexive (owner : Nat) : + Reflexive owner (ownRules owner) (completeOwnWork owner) := by + refine ⟨ownRegistryCoherent owner, ?_⟩ + intro rule hr s _ ha + refine ⟨recordFor rule s, ?_, ownRecordValid owner rule hr s ha⟩ + simp only [ownRules, List.mem_cons, List.not_mem_nil, or_false] at hr + rcases hr with rfl | rfl + · exact generatingRecord_member owner s ha.1 ha.2 + · exact assessingRecord_member owner s ha + +theorem ownAssessmentPerformed (owner : Nat) (s : Subject) (hs : s ∈ ownSubjects owner) : + Performed (completeOwnWork owner) s .assessment := + ⟨recordFor (assessingRule owner) s, assessingRecord_member owner s hs, rfl, rfl⟩ + +def applicationRule : Principle := + { assessingRule 0 with key := ⟨0,0⟩, applicable := fun s => s = .process 0 0 .application } + +def applicationWork : List WorkRecord := [recordFor applicationRule (.process 0 0 .application)] + +theorem applicationWork_reflexive : Reflexive 0 [applicationRule] applicationWork := by + constructor + · intro p hp q hq _ + simp only [List.mem_singleton] at hp hq + rw [hp,hq] + · intro rule hr s _ ha + simp only [List.mem_singleton] at hr + subst rule + change s = .process 0 0 .application at ha + subst s + refine ⟨recordFor applicationRule (.process 0 0 .application), by simp [applicationWork], ?_⟩ + refine ⟨by simp, rfl, rfl, rfl, ?_, rfl, rfl, rfl, ?_, rfl, ?_, ?_, rfl, ?_⟩ + · exact ⟨applicationRule, by simp, rfl⟩ + · exact ⟨applicationRule, by simp, rfl, rfl⟩ + · exact reasonsFor_nonempty _ + · exact reasonsFor_target _ + · change statedOutcome .assessment (.process 0 0 .application) = finiteMethodResult .assessment (inquiryFor (.process 0 0 .application)) (reasonsFor (.process 0 0 .application)) [0] + exact ownContentEvaluates .assessment _ + +theorem applicabilityRetained (owner : Nat) (rules : List Principle) (records : List WorkRecord) : + (Reflexive owner rules records → ReflexiveScope owner rules records) ∧ + (ReflexiveScope owner rules records ↔ + ∀ rule ∈ rules, ∀ s, s.owner = owner → (¬ rule.applicable s ∨ Performed records s rule.activity)) ∧ + (Reflexive 0 [applicationRule] applicationWork ∧ + ¬ Performed applicationWork (.system 0) .assessment) := by + classical + refine ⟨Reflexive.toScope, ?_, applicationWork_reflexive, ?_⟩ + · constructor + · intro h rule hr s hs + by_cases ha : rule.applicable s + · exact Or.inr (h rule hr s hs ha) + · exact Or.inl ha + · intro h rule hr s hs ha + exact (h rule hr s hs).resolve_left (not_not_intro ha) + · rintro ⟨record, hm, ht, _⟩ + simp only [applicationWork, List.mem_singleton] at hm + subst record + cases ht + +end CoreReader.Agency +``` + + + + **L1** 导入Std及其依赖。 + + + **L3** 打开命名空间CoreReader.Agency;文件边界不改变声明身份。 + + + **L5** 定义形成、应用和修订三个阶段标签。 + + + **L6** 为前述数据类型生成可判定相等及显示实例。 + + + **L8** 用所属主体和局部编号标识登记原则。 + + + **L9** 保存所属主体编号。 + + + **L10** 保存主体内部原则编号。 + + + **L11** 为前述数据类型生成可判定相等及显示实例。 + + + **L13** 区分系统、原则及带阶段的原则过程对象。 + + + **L14** 用所有者编号表示系统自身。 + + + **L15** 用所有者及局部原则编号表示某项原则。 + + + **L16** 把该原则的形成、应用或修订过程表示为独立对象。 + + + **L17** 为前述数据类型生成可判定相等及显示实例。 + + + **L19** 从各类主体对象中提取所属主体编号。 + + + **L20** 直接从系统对象提取所有者。 + + + **L21** 提取原则所有者,忽略局部编号。 + + + **L22** 提取过程对象所有者,不受原则编号和阶段影响。 + + + **L24** 区分生成工作与评估工作。 + + + **L25** 为前述数据类型生成可判定相等及显示实例。 + + + **L27** 分别表示合规、形成根据、适用性和修订根据问题。 + + + **L28** 为前述数据类型生成可判定相等及显示实例。 + + + **L30** 提供恒真程序及仅在零处为真的程序。 + + + **L31** 为前述数据类型生成可判定相等及显示实例。 + + + **L33** 在自然数输入上计算两种样例程序。 + + + **L34** alwaysTrue样例程序接受每个自然数输入。 + + + **L35** onlyAtZero程序仅在输入0时返回true。 + + + **L37** 说明后续定义或结果:分别保存测试输入和声称范围,以表示超出测试的主张。 + + + **L38** 分别保存测试输入和声称范围,以表示超出测试的主张。 + + + **L39** 记录该方法草案实际测试程序的输入。 + + + **L40** 另记录该草案拟授权的输入范围。 + + + **L41** 为前述数据类型生成可判定相等及显示实例。 + + + **L43** 程序通过列表中全部测试即被接受,未测试输入不被检查。 + + + **L44** 所有已测试输入返回true时接受程序;此处不检查claimedScope。 + + + **L46** 说明后续定义或结果:将目标对象与问题种类、请求范围和目标当前方法内容相连。 + + + **L47** 将目标对象与问题种类、请求范围和目标当前方法内容相连。 + + + **L48** 标识正在考察其方法的确切对象。 + + + **L49** 区分符合性、形成理由、适用性和修订理由四类问题。 + + + **L50** 记录此问题要求方法覆盖的输入范围。 + + + **L51** 附上实际待考察方法草案,包括测试输入和声称范围。 + + + **L52** 为前述数据类型生成可判定相等及显示实例。 + + + **L54** 表示目的、声明范围、观察以及具体程序和输入反例。 + + + **L55** 目的理由指定方法意欲处理的输入。 + + + **L56** 范围理由陈述方法声明的输入限度。 + + + **L57** 观察理由记录具体输入和布尔输出。 + + + **L58** 反例理由指定待检查的实际样例程序与输入。 + + + **L59** 为前述数据类型生成可判定相等及显示实例。 + + + **L61** 给理由构造器分配编号;编号本身不提供根据。 + + + **L62** 目的理由使用局部引用0;它是类别编号,不是全局唯一标识。 + + + **L63** 声明范围理由使用局部引用1。 + + + **L64** 观察理由使用局部引用2。 + + + **L65** 反例理由使用局部引用3。 + + + **L67** 说明后续定义或结果:把理由内容和引用编号绑定到其所针对对象。 + + + **L68** 把理由内容和引用编号绑定到其所针对对象。 + + + **L69** 保存该建模问题中此理由的局部引用。 + + + **L70** 标识该理由实际针对的对象。 + + + **L71** 保存理由的目的、范围、观察或反例内容。 + + + **L72** 为前述数据类型生成可判定相等及显示实例。 + + + **L74** 允许范围内支持、不充分、不适用和未确定四种结果。 + + + **L75** 为前述数据类型生成可判定相等及显示实例。 + + + **L77** 区分评估结果和生成的方法草案。 + + + **L78** 把判定包装为评估结果;负面判定仍是评估。 + + + **L79** 包装新生成的方法草案,不断言该草案正确。 + + + **L80** 为前述数据类型生成可判定相等及显示实例。 + + + **L82** 说明后续定义或结果:登记规则身份、活动、方法内容、适用性、问题、理由、限度和结果语义。 + + + **L83** 说明后续定义或结果:登记规则身份、活动、方法内容、适用性、问题、理由、限度和结果语义。 + + + **L84** 登记规则身份、活动、方法内容、适用性、问题、理由、限度和结果语义。 + + + **L85** 为原则赋予所有者与局部编号,用于解析其记录。 + + + **L86** 规定该原则约束生成活动还是评估活动。 + + + **L87** 陈述该登记原则自身的方法草案。 + + + **L88** 规定该原则适用的对象。 + + + **L89** 为每个对象指定实际待考察问题。 + + + **L90** 为每个对象的问题指定所提供理由。 + + + **L91** 为每个对象的适用指定保留的输入限度。 + + + **L92** 定义结果何时遵循该原则的问题、理由与限度;仅此字段不保证方法充分。 + + + **L94** 记录实际应用的规则身份、目标、活动、问题、理由、限度和结果。 + + + **L95** 记录声称采用的确切登记原则标识。 + + + **L96** 记录该工作针对的对象。 + + + **L97** 记录此工作是生成还是评估。 + + + **L98** 保存该工作的具体问题记录。 + + + **L99** 保存该工作记录采用的具体理由。 + + + **L100** 保存该工作记录保留的输入限度。 + + + **L101** 保存记录的评估判定或生成的方法草案。 + + + **L102** 为前述数据类型生成可判定相等及显示实例。 + + + **L104** 要求相同登记键对应同一原则,排除身份歧义。 + + + **L105** 两项已登记原则若标识相同,就必须是同一原则,防止查找歧义。 + + + **L107** 要求评估目标能解析到登记主体或精确原则键。 + + + **L108** 登记表中存在同所有者原则时,该系统对象可解析。 + + + **L109** 原则和过程对象要求登记表中有确切所有者及局部编号对应项。 + + + **L111** 说明后续定义或结果:把问题中当前方法内容与登记目标原则的方法精确相连。 + + + **L112** 说明后续定义或结果:把问题中当前方法内容与登记目标原则的方法精确相连。 + + + **L113** 把问题中当前方法内容与登记目标原则的方法精确相连。 + + + **L114** 按问题实际目标的种类选择查找规则。 + + + **L115** 系统问题考察其所有者已登记原则0的声明方法。 + + + **L116** 对原则或其过程,按该目标实际所有者和编号查找。 + + + **L117** 要求确切标识查找成功,且问题所用方法等于登记原则的方法。 + + + **L119** 要求存在匹配目标和活动的实际记录;有效性另行检查。 + + + **L120** Performed要求存在目标和活动完全匹配的记录;它本身不检查理由内容。 + + + **L122** 说明后续定义或结果:保留受所属主体和适用性条件限制的记录覆盖接口。 + + + **L123** 保留受所属主体和适用性条件限制的记录覆盖接口。 + + + **L124** 对指定所有者的对象,每项适用的登记规则都须有对应活动记录。 + + + **L126** 说明后续定义或结果:检查登记与适用性、对象身份、目标方法内容、非空对应理由、限度及规则语义一致性。 + + + **L127** 说明后续定义或结果:检查登记与适用性、对象身份、目标方法内容、非空对应理由、限度及规则语义一致性。 + + + **L128** 检查登记与适用性、对象身份、目标方法内容、非空对应理由、限度及规则语义一致性。 + + + **L129** 以下证明字段确认这条特定工作记录是rule对s的有效适用。 + + + **L130** 要求记录采用的规则属于此登记表。 + + + **L131** 要求同一规则对待评对象适用。 + + + **L132** 核对记录所用原则标识与该规则确切标识相等。 + + + **L133** 检查工作记录针对的正是对象s。 + + + **L134** 要求记录对象能在同一规则登记表中解析。 + + + **L135** 检查记录活动正是该规则约束的活动。 + + + **L136** 检查记录问题等于该规则为s指定的问题。 + + + **L137** 另检查问题自身针对s,而非无关对象。 + + + **L138** 检查问题中的方法属于已解析的登记目标。 + + + **L139** 检查记录理由等于该规则为s指定的理由。 + + + **L140** 要求该记录至少包含一项实际理由。 + + + **L141** 要求每个记录理由都针对同一对象s。 + + + **L142** 检查记录限度等于该规则对s的限度。 + + + **L143** 要求记录结果满足该规则对问题、理由和限度的实际含义关系。 + + + **L145** 说明后续定义或结果:要求登记一致,且每条适用规则对同主体对象都有有效应用记录;仍是模型遵守条件。 + + + **L146** 要求登记一致,且每条适用规则对同主体对象都有有效应用记录;仍是模型遵守条件。 + + + **L147** Reflexive首先要求原则登记无歧义。 + + + **L148** 然后量化每项登记规则及其适用的自有对象。 + + + **L149** 对每次上述适用,都须存在通过全部ValidApplication内容检查的记录。 + + + **L151** 由完整反身性抽取目标和活动记录覆盖,不再保留内容有效性细节。 + + + **L152** 假设完整内容性Reflexive履责,推出较弱的仅范围覆盖。 + + + **L153** 为范围义务取已登记规则、自有对象及其适用前提。 + + + **L154** 用完整Reflexive履责取得实际列表记录及ValidApplication证明。 + + + **L155** 保留该记录的成员关系、目标一致与活动一致,证明Performed。 + + + **L157** 把完整反身规范应用于已登记且适用的同主体对象,得到工作记录。 + + + **L158** 要求完整Reflexive履责及该规则实际属于登记表。 + + + **L159** 还要求目标所有者匹配且该规则对其适用。 + + + **L160** 把导出的范围义务应用于这些前提,得到该目标的活动已经记录。 + + + **L162** 只测试零并声明零点范围。 + + + **L164** 形成询问根据,应用询问适用性,修订询问零与一范围的根据,其他对象询问合规。 + + + **L165** 根据对象的过程阶段选择问题,仍以同一对象为目标。 + + + **L166** 对形成阶段,考察覆盖输入0的方法形成根据。 + + + **L167** 对应用阶段,考察局部方法在输入0上的适用性。 + + + **L168** 对修订阶段,考察将同一局部方法范围扩至输入0和1的根据。 + + + **L169** 对系统或原则自身,在局部范围{0}内考察符合性。 + + + **L171** 说明后续定义或结果:按问题提供目的、范围、观察;修订问题另含未测试输入失败的程序反例。 + + + **L172** 按问题提供目的、范围、观察;修订问题另含未测试输入失败的程序反例。 + + + **L173** 形成理由陈述目的{0}、声明范围{0}及0处为真的观察。 + + + **L174** 适用性与符合性使用已声明局部范围及同一0处观察。 + + + **L175** 修订理由要求{0,1},同时承认原声明范围为{0}且仅有0处观察。 + + + **L176** 加入onlyAtZero程序在输入1处的具体修订反例。 + + + **L178** 把选定理由内容逐项绑定到同一问题目标。 + + + **L179** 将每项源理由与类别引用和同一对象s包装,保留实际内容。 + + + **L181** 说明后续定义或结果:按实际理由和方法范围计算结果;已通过当前测试却在请求输入失败的程序使修订主张不充分。 + + + **L182** 说明后续定义或结果:按实际理由和方法范围计算结果;已通过当前测试却在请求输入失败的程序使修订主张不充分。 + + + **L183** 按实际理由和方法范围计算结果;已通过当前测试却在请求输入失败的程序使修订主张不充分。 + + + **L184** 提取理由内容,以检查目的、范围、观察与反例实质。 + + + **L185** 提供的限度若不同于待考察方法声明范围,则返回未确定。 + + + **L186** 检查限度后,评估提出的具体问题种类。 + + + **L187** 进入形成根据的评估分支。 + + + **L188** 要求存在覆盖问题所请求输入的目的理由。 + + + **L189** 还要求明确限度声明,且请求范围等于声明范围。 + + + **L190** 仅上述内容检查通过时形成评估才为域内有支持,否则未确定。 + + + **L191** 对适用性和符合性问题采用相同局部检查。 + + + **L192** 首先检查每个请求输入都在所提供限度内。 + + + **L193** 在限度内,要求理由明确声明同一范围。 + + + **L194** 还要求0处为真的观察,以及请求范围恰为[0]。 + + + **L195** 通过这些局部检查得到域内有支持;证据不完整则未确定。 + + + **L196** 请求输入超出所提供限度时,判为不适用。 + + + **L197** 进入修订根据分支,寻找实际范围反例。 + + + **L198** 要求理由把修订后请求范围陈述为预期目的。 + + + **L199** 要求旧限度明确出现于声明范围理由中。 + + + **L200** 要求原先输入0上的成功观察。 + + + **L201** 在提供的理由内容中寻找满足以下具体检查的反例。 + + + **L202** 反例输入必须属于新请求范围。 + + + **L203** 但该反例程序必须通过当前方法的已测试输入。 + + + **L204** 同一程序必须在反例输入处失败。 + + + **L205** 其他种类理由不能自行满足该反例搜索。 + + + **L206** 发现测试与范围之间的反例缺口时判为不足;缺少这些内容则未确定。 + + + **L208** 生成保留测试输入并采用请求范围;评估执行依赖理由内容的问题检查。 + + + **L209** 把同一理由和限度传入按活动区分的结果函数。 + + + **L210** 在生成草案与评估问题之间选择。 + + + **L211** 生成保留方法已测试输入,却提出问题请求范围;不认证正确性。 + + + **L212** 评估使用此问题实际理由与限度计算assessInquiry。 + + + **L214** 以结果等于明示有限算法的计算值定义语义,不预设检查成功。 + + + **L215** 接收待检查是否遵循该活动方法的具体记录结果。 + + + **L216** 结果恰等于计算出的finiteMethodResult时才遵循该方法。 + + + **L218** 枚举所属系统、两条登记原则及各原则的三个过程阶段。 + + + **L219** 把系统自身及其两个原则身份纳入自有对象。 + + + **L220** 把原则0的形成、应用和修订分别列为对象。 + + + **L221** 也纳入原则1的全部三个阶段,总计九个自有对象。 + + + **L223** 说明后续定义或结果:此应用的生成规则排除应用阶段过程,保留其他对象。 + + + **L224** 此应用的生成规则排除应用阶段过程,保留其他对象。 + + + **L225** 在该应用模型中,把应用既有原则视为不适用生成活动。 + + + **L226** 其余已表示对象种类均适用生成活动。 + + + **L228** 登记零号生成原则,带局部方法、问题、理由及受限适用条件。 + + + **L229** 以此所有者的局部标识0登记生成原则。 + + + **L230** 令该规则约束生成工作。 + + + **L231** 为生成规则指定测试与范围均为[0]的局部草案。 + + + **L232** 生成适用性同时要求属于该所有者九个对象及符合生成资格。 + + + **L233** 用inquiryFor提供与对象阶段对应的实际问题。 + + + **L234** 用reasonsFor提供原始且与目标相连的理由内容。 + + + **L235** 对每个对象,生成规则均保留[0]这一限度。 + + + **L236** 要求生成结果符合finiteMethodResult的生成分支。 + + + **L238** 登记一号评估原则,按明确有限语义评估全部枚举自身对象。 + + + **L239** 以不同的局部标识1登记评估原则。 + + + **L240** 令该规则约束评估工作。 + + + **L241** 评估原则声明相同的局部[0]/[0]方法契约。 + + + **L242** 评估对该所有者全部九个对象适用。 + + + **L243** 给评估规则指定同一按阶段区分的问题函数。 + + + **L244** 为其评估指定同一原始目标相关理由。 + + + **L245** 保留[0]作为评估规则声明的限度。 + + + **L246** 要求评估结果等于评估函数的实际结果。 + + + **L248** 返回两个身份不同的生成和评估原则。 + + + **L250** 说明后续定义或结果:构造拟记录草案和范围支持或不充分结果,随后与实际算法计算核对。 + + + **L251** 构造拟记录草案和范围支持或不充分结果,随后与实际算法计算核对。 + + + **L252** 按活动选择独立陈述的记录结果。 + + + **L253** 记录中的生成草案保留测试输入并采用问题请求范围。 + + + **L254** 评估记录按问题种类选取所陈述判定,此处不调用assessInquiry。 + + + **L255** 修订问题记录为不足。 + + + **L256** 其余已表示问题记录为域内有支持。 + + + **L258** 用提供的规则与对象构造记录;登记成员关系与内容有效性仍需后续ValidApplication证明。 + + + **L259** 用此规则的标识、问题、理由和限度构造记录,但结果采用独立陈述值。 + + + **L261** 穷尽对象与阶段,证明每个具体问题理由非空。 + + + **L262** 对每种对象检查理由列表非空。 + + + **L263** 系统问题使用符合性理由,包含范围与观察条目。 + + + **L264** 原则问题同样具有非空的范围与观察列表。 + + + **L265** 各过程阶段分别化为实际非空的形成、应用或修订理由列表。 + + + **L267** 从理由列表的映射构造证明各理由都指向同一对象。 + + + **L268** 取已知属于此对象构造理由列表的任意理由。 + + + **L269** 反解map构造取得源内容,将理由替换为附有目标标识的包装。 + + + **L270** 该包装的目标按构造就是s,故目标等式自反成立。 + + + **L272** 逐构造器验证生成问题保留目标身份。 + + + **L273** 分别检查系统、原则和过程对象的问题目标。 + + + **L274** 系统问题构造时就以同一系统为目标。 + + + **L275** 原则问题同样保留同一原则目标。 + + + **L276** 每个过程阶段均以原过程对象为问题目标。 + + + **L278** 说明后续定义或结果:计算各对象和阶段的评估及生成,证明记录预期结果与算法一致,包含不充分结果。 + + + **L279** 计算各对象和阶段的评估及生成,证明记录预期结果与算法一致,包含不充分结果。 + + + **L280** 要求独立陈述结果等于对该对象问题、理由及[0]限度的实际计算。 + + + **L281** 分别检查生成草案与评估判定的结果等式。 + + + **L282** 两个生成定义构造完全相同的测试输入与请求范围草案。 + + + **L283** 对评估,现须将所陈述判定与实际评估函数核对。 + + + **L284** 按对象种类区分有限评估检查。 + + + **L285** 系统的符合性内容计算得到所陈述的域内有支持判定。 + + + **L286** 原则的符合性内容计算得到同一域内有支持判定。 + + + **L287** 形成与应用计算为有支持;修订因程序在0通过而在1失败计算为不足。 + + + **L289** 利用局部编号零和一不同,证明登记键无歧义。 + + + **L290** 取两项登记原则,并假设其标识相等。 + + + **L291** 把两项登记成员关系限定为实际生成规则或评估规则。 + + + **L292** 检查由此产生的四种具体规则配对。 + + + **L293** 两者都是生成规则时,原则相等直接成立。 + + + **L294** 生成标识0不能等于评估标识1;提取localId得到矛盾。 + + + **L295** 反向混合配对要求localId 1=0,也不可能。 + + + **L296** 两者都是评估规则时,原则相等直接成立。 + + + **L298** 核实九个枚举对象都能解析到实际登记主体或原则。 + + + **L299** 从ownSubjects选出的对象必须可在该所有者实际登记表中解析。 + + + **L300** 把成员前提hs展开为九个具体自有对象。 + + + **L301** 逐个处理九个对象,保持其原所有者和原则编号。 + + + **L302** 为每个目标标识找到匹配的生成或评估登记项。 + + + **L304** 核实每个问题的方法与登记目标的局部方法一致。 + + + **L305** 要求所选对象的问题考察其自身登记声明的方法。 + + + **L306** 再次依据实际成员前提枚举九个具体对象。 + + + **L307** 分别检查系统、原则和各阶段对象的目标方法对应。 + + + **L308** 两项登记规则都声明localMethod,恰与inquiryFor为每个枚举目标指定的方法相同。 + + + **L310** 综合身份、理由目标、范围、登记及实际计算,验证每个适用记录。 + + + **L311** 假设所选登记规则对对象s适用。 + + + **L312** 证明具体recordFor rule s满足每个ValidApplication字段。 + + + **L313** 首先从适用性推出s属于该所有者对象列表。 + + + **L314** 用登记成员关系将rule限定为两个自有规则之一。 + + + **L315** 分别处理生成与评估的适用条件。 + + + **L316** 生成适用性的第一个合取项就是自有对象成员关系。 + + + **L317** 评估适用性恰为该自有对象成员关系。 + + + **L318** 确立此实际规则以inquiryFor作为问题函数。 + + + **L319** 将登记规则成员关系化为生成或评估,以检查问题字段。 + + + **L320** 两个可能规则的问题字段都定义为inquiryFor。 + + + **L321** 确立所选规则用reasonsFor提供理由。 + + + **L322** 检查理由前,再次将规则限定为两个实际登记项。 + + + **L323** 两个登记项都恰提供reasonsFor。 + + + **L324** 确立该规则对s的限度恰为[0]。 + + + **L325** 检查所选规则限度前,先解析登记成员关系。 + + + **L326** 两个自有规则都保留[0]作为限度。 + + + **L327** 确立所选规则的含义是其自身活动对应的结果函数。 + + + **L328** 解析登记成员关系,以检查生成或评估的含义。 + + + **L329** 两种情形中,规则含义都是按其活动实例化的finiteMethodMeaning。 + + + **L330** 用登记与适用前提、记录一致性和已解析目标构造ValidApplication,余下检查问题、理由及计算含义。 + + + **L331** 余下的问题目标义务针对该规则对s的实际问题。 + + + **L332** 将规则问题换为inquiryFor,用其目标保持定理证明目标为s。 + + + **L333** 余下方法一致性义务检查该规则问题的登记目标。 + + + **L334** 改写为inquiryFor,使用具体自有目标的方法解析定理。 + + + **L335** 把记录理由非空化为该规则提供理由非空。 + + + **L336** 把这些理由改写为reasonsFor,应用其非空列表定理。 + + + **L337** 把理由目标一致性化为每项提供理由都针对s。 + + + **L338** 改写为reasonsFor,使用其目标保持构造定理。 + + + **L339** 最后义务比较独立陈述结果与该规则实际问题、理由、限度及含义。 + + + **L340** 代入含义、问题、理由和[0]限度这四项已证一致性。 + + + **L341** 用ownContentEvaluates证明记录结果等于实际方法结果。 + + + **L343** 为九个对象构造记录,仅在生成适用时加入生成记录。 + + + **L344** 通过连接分配给每个自有对象的记录,构造完整日志。 + + + **L345** 符合生成资格的对象同时获得生成记录和评估记录。 + + + **L346** 应用阶段对象仅获评估记录,与生成的明确适用限制一致。 + + + **L348** 证明每个对象的评估记录进入完整工作列表。 + + + **L349** 陈述该自有对象的评估记录属于构造出的完整日志。 + + + **L350** 使用flatMap成员规则:选取其分配列表包含目标记录的对象。 + + + **L351** 选择同一s及其给定的自有对象成员证明hs。 + + + **L352** 无论生成是否适用,分配列表都包含s的评估记录。 + + + **L354** 在明确生成适用条件下证明生成记录存在。 + + + **L355** 声称完整日志包含生成记录前,除自有成员关系外还要求生成资格。 + + + **L356** 选择s的flatMap分支;hg使该分支包含所需生成记录。 + + + **L358** 综合登记一致、记录存在及内容有效性,建立具体非空反身模型。 + + + **L359** 陈述实际双规则登记表与构造工作日志满足完整内容性反身要求。 + + + **L360** 提供已证登记一致性,余下逐一证明适用对象的内容性覆盖。 + + + **L361** 取实际登记规则和适用对象;适用性自身将提供所需自有成员关系。 + + + **L362** 选择recordFor rule s及已证内容有效性,仅留下它属于完整日志的义务。 + + + **L363** 把规则成员关系解析为生成或评估登记项。 + + + **L364** 按这两个实际规则情形分别证明记录成员关系。 + + + **L365** 对生成,ha提供自有成员关系和资格,使其记录属于完整日志。 + + + **L366** 对评估,ha直接提供其记录所需的自有成员关系。 + + + **L368** 为列表中的自身对象抽取已构造评估记录。 + + + **L369** 陈述同一完整工作日志中存在针对s的评估活动。 + + + **L370** 以s的评估记录、已证日志成员关系及确切目标活动一致性作为Performed见证。 + + + **L372** 把评估规则限定到一个应用阶段对象,并给出可解析键。 + + + **L373** 把评估规则限制为原则0的应用过程,标识为(0,0)。 + + + **L375** 储存该单一应用对象的完整评估记录。 + + + **L377** 核实单规则及其记录在受限适用范围内满足完整内容有效反身性。 + + + **L378** 将单项登记表一致性与唯一适用对象覆盖分开。 + + + **L379** 取单项登记表中任意两规则;成员关系已确定两者,因此无需使用标识相等前提。 + + + **L380** 单项成员关系使两规则都等于applicationRule。 + + + **L381** 代入这两个一致性证明两规则相等。 + + + **L382** 为单项应用登记表中的规则取一个适用对象。 + + + **L383** 用单项成员关系确认该规则是applicationRule。 + + + **L384** 在覆盖义务中把rule替换为确切的applicationRule。 + + + **L385** 展开适用性,得到s恰为所有者0的原则0应用过程。 + + + **L386** 把s替换为该确切过程,固定工作目标。 + + + **L387** 选择applicationWork唯一记录并证明成员关系,余下检查内容有效性。 + + + **L388** 填入直接成立的登记、适用与记录一致性字段,留下目标解析、理由及计算结果检查。 + + + **L389** 目标标识解析为单项登记表中的applicationRule自身。 + + + **L390** 同一登记规则提供问题实际考察的localMethod。 + + + **L391** 由reasonsFor_nonempty得应用问题理由非空。 + + + **L392** 每项应用理由都针对该确切应用过程对象。 + + + **L393** 余下含义义务是所陈述应用评估与实际有限计算结果相等。 + + + **L394** 用ownContentEvaluates确认应用阶段评估的该等式。 + + + **L396** 从完整反身性得到范围覆盖,证明条件与析取等价,并给无系统评估记录的有效受限实例。 + + + **L397** 第一条保留完整内容性反身要求推出范围覆盖的结论。 + + + **L398** 第二条把条件性范围覆盖改述为二择一义务。 + + + **L399** 对每个自有对象和登记规则,要么规则不适用,要么其活动已有记录。 + + + **L400** 具体单项应用日志在受限规则下满足完整反身要求。 + + + **L401** 但同一日志不含系统自身评估,因为该规则对系统自身不适用。 + + + **L402** 对可能不可判定的适用谓词使用古典分情形讨论。 + + + **L403** 提供一般范围投影和具体受限见证,留下等价关系与缺失系统记录证明。 + + + **L404** 证明适用性或已履行改述的两个方向。 + + + **L405** 假设条件性范围覆盖,固定登记规则与自有对象。 + + + **L406** 按该确切规则是否对该对象适用分情况。 + + + **L407** 适用时,覆盖义务提供已记录活动,满足右析取项。 + + + **L408** 不适用时,该否定适用事实满足左析取项。 + + + **L409** 反向证明假设该析取,并给出对自有对象的实际适用性。 + + + **L410** 用ha排除不适用分支,得到所需已记录活动。 + + + **L411** 假设存在系统评估,提取列表记录及目标一致性。 + + + **L412** 单项applicationWork迫使该记录就是应用过程记录。 + + + **L413** 把声称的系统评估记录替换为唯一过程记录。 + + + **L414** 其过程目标不可能等于系统目标,与假设的记录一致性矛盾。 + + + **L416** 关闭当前命名空间。 + + +### `leanified/CoreReader.lean` + + +```lean +import CoreReader.Engineering.Integration +``` + + + + **L1** 导入 Engineering.Integration 及其传递依赖,使本工程的工程应用、继承接口、共同见证与不蕴涵证明可用;导入本身不陈述哲学定理。 + diff --git a/SoftwareEngineering/zh/lean/philosophy/overview.md b/SoftwareEngineering/zh/lean/philosophy/overview.md new file mode 100644 index 0000000..8ebec52 --- /dev/null +++ b/SoftwareEngineering/zh/lean/philosophy/overview.md @@ -0,0 +1,1622 @@ +# 软件工程哲学与 Lean:主张速览 + +本文按 40 个冻结目标组织。目标接受、Lean 检查及来源保真是不同判断;规范定义不证明义务已履行,有限模型也不证明现实中的普遍正确性。47 个来源段落与两个空标题在追溯附录完整保留。 + +采用基准为 SoftwareEngineering 0.2.1(继承 Core 0.1.2);当前 Core 工具仅提供检查运行环境。 + +`accepted` 表示相应目标在已说明范围内获接受;`limited` 表示来源段落只有受限的形式对应;`incomplete` 保留未构成该段完整证明的部分。Lean 的 `passed` 仅报告已登记声明的检查;规范接口的通过不等于义务履行。 + +[另一粒度](details.md) · [冻结目标](../../../lean/philosophy/targets.json) · [审查与暴露说明](../../../lean/philosophy/reviews/README.md) · [实际声明类型](../../../lean/philosophy/evidence/declaration-types.json) + +| 目标 | 主张 | 种类 | 目标审查 | +| --- | --- | --- | --- | +| [T01](#t01) | 权威与采用基准 | boundary | accepted | +| [T02](#t02) | 重视扩展与形式可修订 | specification | accepted | +| [T03](#t03) | 取向不等于成就 | nonentailment | accepted | +| [T04](#t04) | 整个已持理论的一致性 | specification | accepted | +| [T05](#t05) | 冲突与显式修订 | theorem | accepted | +| [T06](#t06) | 一致性、真与支持有别 | nonentailment | accepted | +| [T07](#t07) | 保留条件的自我适用 | specification | accepted | +| [T08](#t08) | 自我适用不产生自我证明 | nonentailment | accepted | +| [T09](#t09) | 原评估任务的根据 | specification | accepted | +| [T10](#t10) | 经验支持与不确定性 | specification | accepted | +| [T11](#t11) | 推论与否定性检查 | specification | accepted | +| [T12](#t12) | 价值位置及理由 | specification | accepted | +| [T13](#t13) | 表达与支持比例的限度 | nonentailment | accepted | +| [T14](#t14) | 关系、比较范围与方法角色 | specification | accepted | +| [T15](#t15) | 局部证据不会抹去差异 | nonentailment | accepted | +| [T16](#t16) | 应用特定的能力与理解 | specification | accepted | +| [T17](#t17) | 输出证据不蕴涵内省 | nonentailment | accepted | +| [T18](#t18) | 有根据的实现选择 | specification | accepted | +| [T19](#t19) | 开放性与附加选择承诺 | nonentailment | accepted | +| [T20](#t20) | 同一工程系统内的相互适用 | theorem | accepted | +| [T21](#t21) | 现存形式与评估 | boundary | accepted | +| [T22](#t22) | 持续工程活动 | specification | accepted | +| [T23](#t23) | 私人可修改性与共同能力 | nonentailment | accepted | +| [T24](#t24) | 演化优先的条件 | specification | accepted | +| [T25](#t25) | 优先适用时的条件定理 | theorem | accepted | +| [T26](#t26) | 有根据的可信变化方向 | specification | accepted | +| [T27](#t27) | 可信性不等于无限预留 | nonentailment | accepted | +| [T28](#t28) | 具体成本与有根据的让步 | specification | accepted | +| [T29](#t29) | 演化种类与义务变化 | specification | accepted | +| [T30](#t30) | 一项演化优势不是所有优势 | nonentailment | accepted | +| [T31](#t31) | 结构后果与跨边界义务 | specification | accepted | +| [T32](#t32) | 结构名称不能证明能力 | nonentailment | accepted | +| [T33](#t33) | 契约保持与刻意修订 | specification | accepted | +| [T34](#t34) | 契约保持定理 | theorem | accepted | +| [T35](#t35) | 修订与保留历史证据 | specification | accepted | +| [T36](#t36) | 修订不能改写失败 | nonentailment | accepted | +| [T37](#t37) | 优先原则仍接受自身评估 | theorem | accepted | +| [T38](#t38) | 全部已表示义务的共同见证 | satisfiability | accepted | +| [T39](#t39) | 继承义务不强制附加优先 | nonentailment | accepted | +| [T40](#t40) | 形式证据不能建立什么 | boundary | accepted | + + +## T01 · 权威与采用基准 + +SoftwareEngineering 0.2.1 采用继承的 Core 0.1.2 文本及附加工程优先承诺;本稿不推进已采纳的 Core 0.1.2 检查点。 + +**前提与表示:** 完整条款、含义及适用限度是权威文本。rationale 与案例辅助解释;当前 Core 检查器是独立运行依赖。 + +**证明或检查:** 冻结并追溯源字节、元数据及段落原文;文献权威不分配 Lean 定理。 + +**限度:** 章节顺序和检查通过均不建立演绎层级、普遍哲学正确性或所有系统的采用事实。 + +**状态:** accepted (boundary). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.preamble#p1](#source-organon-preamble-p1), [organon.preamble#p2](#source-organon-preamble-p2), [organon.charter.overview#p1](#source-organon-charter-overview-p1), [organon.charter.overview#p2](#source-organon-charter-overview-p2), [organon.charter.overview#p3](#source-organon-charter-overview-p3), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [extensions#p1](#source-extensions-p1) + +[声明、证明与逐行解释](details.md#t01) + + + +## T02 · 重视扩展与形式可修订 + +generationSpecification 要求重视扩展,并使当前组织、方法和原则形式保持可修订;有理由的稳定行动可与此取向共存。 + +**前提与表示:** Policy 提供价值位置、当前形式及可修订关系。具体政策有实际当前形式,并非以空清单履责。 + +**证明或检查:** 正例构造价值取向及可修订性;中性政策虽允许版本变化却不重视扩展。稳定与协作案例检查实际状态变换和资源。 + +**限度:** 此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.charter.overview#p2](#source-organon-charter-overview-p2), [organon.charter.overview#p3](#source-organon-charter-overview-p3), [organon.charter.self-transcendence#p1](#source-organon-charter-self-transcendence-p1), [organon.charter.self-transcendence.orientation#p1](#source-organon-charter-self-transcendence-orientation-p1), [organon.charter.self-transcendence.non-finality#p1](#source-organon-charter-self-transcendence-non-finality-p1), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.relationships.terms#p1](#source-organon-relationships-terms-p1) + +[声明、证明与逐行解释](details.md#t02) + + + +## T03 · 取向不等于成就 + +许可、价值取向、可修订性及清单增长本身不建立能力扩展或实际执行。 + +**前提与表示:** 状态包含实际可用操作;删除资源会改变执行结果。成就证据固定同一变换、操作、输入及输出主张。 + +**证明或检查:** 膨胀状态增加数量却没有 successor 操作。协作案例依赖相应资源才获得该操作。性能记录支持指定成就,而自我宣布记录容许反例世界。 + +**限度:** 这些是具体不蕴涵结果及有限支持案例,不是学习或自主执行的经验预测。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.charter.self-transcendence.orientation#p1](#source-organon-charter-self-transcendence-orientation-p1), [organon.charter.self-transcendence.non-finality#p1](#source-organon-charter-self-transcendence-non-finality-p1), [organon.charter.self-transcendence.limits#p1](#source-organon-charter-self-transcendence-limits-p1), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2) + +[声明、证明与逐行解释](details.md#t03) + + + +## T04 · 整个已持理论的一致性 + +一致性约束同一假设、含义和范围下所有已持主张的联合后果;如实报告修订是另一项条件。 + +**前提与表示:** Theory 选取命题值主张;Context 固定假设、问题含义和范围。正反后果量化同一组可容许世界。 + +**证明或检查:** 案例展示只有合并才产生的冲突、真实语境变化、分别一致的时间切片及如实的布尔变化记录。 + +**限度:** 一般接口在空问题域中可能空泛成立;工程实例使用非空问题族和实际可容许选项。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.charter.consistency#p1](#source-organon-charter-consistency-p1), [organon.charter.consistency.meaning#p1](#source-organon-charter-consistency-meaning-p1), [organon.charter.consistency.meaning#p2](#source-organon-charter-consistency-meaning-p2), [organon.charter.consistency.limits#p1](#source-organon-charter-consistency-limits-p1) + +[声明、证明与逐行解释](details.md#t04) + + + +## T05 · 冲突与显式修订 + +同一问题上的相反后果违反一致性;撤回旧判断后,各修订时间切片可以分别一致。 + +**前提与表示:** 条件定理接收两项带正反号的后果及共同语境,并不证明这两项前提。 + +**证明或检查:** consistencyConsequences 应用 conflictRequiresChange。切片案例为各时点构造模型,并为合并推导冲突;交换并集次序不改变选中的主张。 + +**限度:** 结果不要求与已撤回主张永久相容,也未识别所有可能掩盖修订的文字遗漏。 + +**状态:** accepted (theorem). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.charter.consistency#p1](#source-organon-charter-consistency-p1), [organon.charter.consistency.meaning#p1](#source-organon-charter-consistency-meaning-p1), [organon.charter.consistency.meaning#p2](#source-organon-charter-consistency-meaning-p2), [organon.charter.consistency.limits#p1](#source-organon-charter-consistency-limits-p1) + +[声明、证明与逐行解释](details.md#t05) + + + +## T06 · 一致性、真与支持有别 + +不同条件与可相容的价值张力不必冲突;一致的集合仍可在某世界为假,或不能推出某结论。 + +**前提与表示:** 案例使用明确的布尔世界、作用域和同时成立的不等式,而非自由指定的正确标记。 + +**证明或检查:** 见证证明一致性;另一个反例赋值使主张为假或反驳所声称的蕴涵。改变假设或范围会显式改变比较对象。 + +**限度:** 一致性不是充分的经验或价值支持;反例只涉及已披露的数学表示。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.charter.consistency.meaning#p2](#source-organon-charter-consistency-meaning-p2), [organon.charter.consistency.limits#p1](#source-organon-charter-consistency-limits-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2) + +[声明、证明与逐行解释](details.md#t06) + + + +## T07 · 保留条件的自我适用 + +相关生成和评估规则适用于系统,以及原则的形成、应用和修订;对象是自身不能成为豁免理由。 + +**前提与表示:** 每条规则具有所属者与键、适用条件、实际输入和结果含义;相同键须对应同一规则。 + +**证明或检查:** 具体记录履行适用的自身目标。仅适用于特定应用的规则提供明确的不适用系统案例。Grounds 对自身的评估使用真实的越界反例和价值理由。 + +**限度:** 一般输入谓词仍需解释;非空具体对象及实际记录建立模型内义务履行,不建立普遍自我证明。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.charter.reflexivity#p1](#source-organon-charter-reflexivity-p1), [organon.charter.reflexivity.meaning#p1](#source-organon-charter-reflexivity-meaning-p1), [organon.charter.reflexivity.limits#p1](#source-organon-charter-reflexivity-limits-p1), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3) + +[声明、证明与逐行解释](details.md#t07) + + + +## T08 · 自我适用不产生自我证明 + +自我评估或生成的方案仍可能缺乏支持。在一个共同有限语境中,已表示的完整 Charter 成立,而具体的一般 Grounds 任务不成立。 + +**前提与表示:** CompleteCharter012 包含同一系统的价值取向、可修订性、整体一致性、如实报告及实际适用的自我工作。 + +**证明或检查:** charterWithoutGrounds012 构造该 Charter 见证。预算观察允许一个不具所声称输出能力的世界,因此不能履行指定能力方面的支持责任。 + +**限度:** 此有限反模型不证明所有可能编码中的独立性;保持形式开放也不能替代实际自反工作。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.charter.reflexivity.limits#p1](#source-organon-charter-reflexivity-limits-p1), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.grounds#p1](#source-organon-grounds-p1) + +[声明、证明与逐行解释](details.md#t08) + + + +## T09 · 原评估任务的根据 + +Grounds012 要求非空的评估方面集合,能表达其根据、履行支持责任,并适合原主张任务;清楚表达本身不够。 + +**前提与表示:** AssessmentTask 固定原观察、范围、主张与不确定性,或原推论前提、实际价值位置;NatureAppropriate 比较内容,不只检查分类标签。 + +**证明或检查:** 输入零的证据支持该输入,但容许输入一失败的反例世界。用假设结论的新前提替换原经验任务会被拒绝;合法推论适配保留原观察、范围前提及不确定性。 + +**限度:** 这是已声明任务的充分有限适配,不是穷尽分类,也未导入 Core 0.1.3 的全方面覆盖。声明新任务不授权替换已固定任务。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.grounds#p1](#source-organon-grounds-p1), [organon.grounds.assessment#p1](#source-organon-grounds-assessment-p1), [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3) + +[声明、证明与逐行解释](details.md#t09) + + + +## T10 · 经验支持与不确定性 + +经验适配检查相容观察、非空适用范围、对指定主张及其不确定性的支持。 + +**前提与表示:** 记录是数学观察函数及记录值;它们与现实测量的对应需要外部解释。 + +**证明或检查:** 相关的输入零记录支持局部主张。重复无关观察不能支持另一对象;不确定性案例的两个相容世界保留不同的未观察结果。 + +**限度:** 重复性或可测性本身不建立相关性、正确性或价值;未观察结果不同不必违背有限支持。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2) + +[声明、证明与逐行解释](details.md#t10) + + + +## T11 · 推论与否定性检查 + +推论支持要求从可满足的已述假设得到蕴涵;正确完成的检查也可以拒绝结论。 + +**前提与表示:** Entails 量化所给理论的所有模型;InferenceExamined 记录接受与实际蕴涵是否相符。 + +**证明或检查:** 算术案例从 n = 2 推得 n + 1 = 3。布尔反例世界满足同一空理论却使结论为假,从而验证否定性检查。 + +**限度:** 缺少支持不等于评估做错;与假设相容弱于从假设得到蕴涵。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2) + +[声明、证明与逐行解释](details.md#t11) + + + +## T12 · 价值位置及理由 + +价值位置陈述采纳、理由、限度、后果及对相关批评的回应;初始采纳不是单由观察推出的。 + +**前提与表示:** ValueProcedure 使用所给目标与约束、采纳与理由共同成立的见证、条件性适切性,以及批评适用时的回应。 + +**证明或检查:** 开关案例具有实际预算与收益后果。去掉相关回应会使程序不成立;中性观察不迫使采纳。 + +**限度:** 应用给出充分的价值评估构造,不是证明所有初始假设的普遍要求,也不证明某价值普遍最优。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3) + +[声明、证明与逐行解释](details.md#t12) + + + +## T13 · 表达与支持比例的限度 + +清楚的理由可能为假或无关;可以用定性蕴涵比较主张强度,无须共同数值尺度。 + +**前提与表示:** 案例固定实际反例世界、中性记录及明确的初始价值假设。 + +**证明或检查:** 反例世界否定表达清楚的事实论证。allTrue 蕴涵输入零为真,反向蕴涵在输入一失败。中性证据和空理论都不能推出价值承诺。 + +**限度:** 这些区分不要求把价值、经验证据和推论化为同一分数。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.grounds.assessment#p1](#source-organon-grounds-assessment-p1), [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3) + +[声明、证明与逐行解释](details.md#t13) + + + +## T14 · 关系、比较范围与方法角色 + +被比较对象须处于已述条件和观察范围,并满足所述相关关系;每项实际使用的方法需要与主张相关的角色说明。 + +**前提与表示:** ScopeAccount 提供比较、相关关系及 explains 谓词;具体记录另将主张、条件、角色文本与支持事实精确连接。 + +**证明或检查:** 局部记录将两个输入都限制为零。测量与重复支持该局部输出;框架角色明确保留不能普遍外推的结论。 + +**限度:** 角色字符串非空本身不是充分解释;未使用的方法也不会因此成为必需。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.grounds.scope#p1](#source-organon-grounds-scope-p1), [organon.grounds.scope#p2](#source-organon-grounds-scope-p2), [organon.grounds.scope#p3](#source-organon-grounds-scope-p3) + +[声明、证明与逐行解释](details.md#t14) + + + +## T15 · 局部证据不会抹去差异 + +局部行为相同可与别处的相关差异共存;有限观察可以支持有限主张,无须普遍的方法链。 + +**前提与表示:** 主张及观察范围保持明确。随机输出案例区分事件观察、条件可复现与有限结论的稳定性。 + +**证明或检查:** 具体函数在零处相同,在一处不同;单次观察只支持其局部主张。数学推论和价值程序展示不强制使用观察链的情形。 + +**限度:** 把某输入排除出比较,不是该处不存在相关差异的证据。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.grounds.scope#p1](#source-organon-grounds-scope-p1), [organon.grounds.scope#p2](#source-organon-grounds-scope-p2), [organon.grounds.scope#p3](#source-organon-grounds-scope-p3), [organon.grounds.implementations.limits#p1](#source-organon-grounds-implementations-limits-p1) + +[声明、证明与逐行解释](details.md#t15) + + + +## T16 · 应用特定的能力与理解 + +能力主张保留实际对象、契约及根据;应用可以要求超出可靠输出或输出等价解释的能力。 + +**前提与表示:** 输出契约覆盖所有自然数输入。另一个机制应用将操作性理解定义为解释同一过程,并正确回答所有输入与乘数变式;这是该应用选择的判准。 + +**证明或检查:** ExternalCertificate 在无内省要求下检查输出。两个机制对象具有同一个 explainedProcess;固定翻倍回答者在 (3,1) 失败,机制回答者则证明更强契约及同对象 Grounds012;失败对象也不能获得该根据。 + +**限度:** 这不是心理理解的普遍定义。精确身份是范围前提;履行支持责任的是实际契约证明,而非身份本身。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3) + +[声明、证明与逐行解释](details.md#t16) + + + +## T17 · 输出证据不蕴涵内省 + +可靠输出、外部表达及清单增长,不自动建立过程解释或更强能力。 + +**前提与表示:** 不透明过程实际不返回解释证书,但其输出证明仍覆盖所有自然数输入。 + +**证明或检查:** 证明将输出正确与没有解释并置。重复各类 copy 产物不会提供 successor 操作;资源和膨胀状态案例保留此区别。 + +**限度:** 外部评估者可以支持所选输出主张,而不建立被评系统如何理解自身生成过程。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2) + +[声明、证明与逐行解释](details.md#t17) + + + +## T18 · 有根据的实现选择 + +实现优先需要与目标和约束相连的理由。惯例可有实践意义,但地位本身不够。 + +**前提与表示:** JustifiedChoice 包含实际需求满足及至少一项相关方法理由。解释、适用性、简单性和过程都可在所选需求下相关。 + +**证明或检查:** 惯用的恒等实现满足契约和预算。廉价 successor 虽成本较低却不满足指定输出;仅凭地位的选择不满足理由条件。 + +**限度:** 这些是应用理由,不是普遍成本函数,也不要求惯用实现必须落选。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.grounds.implementations#p1](#source-organon-grounds-implementations-p1), [organon.grounds.implementations#p2](#source-organon-grounds-implementations-p2), [organon.grounds.implementations.limits#p1](#source-organon-grounds-implementations-limits-p1), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3) + +[声明、证明与逐行解释](details.md#t18) + + + +## T19 · 开放性与附加选择承诺 + +开放性允许选项不同,也可与只有一个可行惯用选项共存。附加选择规则不能仅由完成一般评估得到。 + +**前提与表示:** 有限的一般评估模型与 T39 的更强工程不蕴涵,是不同对象和结果。 + +**证明或检查:** 具体需求范围区分局部相同的选项。一般评估案例保留所述评估,但仅凭地位的优先缺乏相关理由。 + +**限度:** 没有结果断言所有实现等价、保证多个可行实现,或从章节位置推出选择承诺。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.grounds.implementations#p1](#source-organon-grounds-implementations-p1), [organon.grounds.implementations#p2](#source-organon-grounds-implementations-p2), [organon.grounds.implementations.limits#p1](#source-organon-grounds-implementations-limits-p1) + +[声明、证明与逐行解释](details.md#t19) + + + +## T20 · 同一工程系统内的相互适用 + +继承义务适用于本系统的原则、方法、价值位置、能力报告和实现选择;实际规范内容进入其整体一致性理论。 + +**前提与表示:** Inherited 固定 sharedContext,并包含已履行的生成、自反、原经验/推论/价值任务、范围、能力和选择。ownTheory 合并实际事实与各项适用 OwnNorm 内容;一致性约束该完整并集。 + +**证明或检查:** inheritedMutualApplication 提取实际字段及完整内容/支持关系;inheritedCurrent 另行构造它们。两条实际自反规则均成为自身对象,评估器的修订检查报告其局部空样本缺陷。 + +**限度:** 字段提取不从单一原则推出所有义务。采纳标记是独立事实,不能替代规范内容。要求样本的批评属于应用判准,不是对观察的普遍要求。 + +**状态:** accepted (theorem). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3) + +[声明、证明与逐行解释](details.md#t20) + + + +## T21 · 现存形式与评估 + +现存形式包含组织、方法和原则;评估包括检查理由及适用性,不限于可执行测试。 + +**前提与表示:** 这些术语约束全文及其他目标的解释。 + +**证明或检查:** 来源追溯保留术语原文。形式类别及推论/价值案例说明其用法,不为词表另造定理。 + +**限度:** 此处使用的有限测试机制没有把所有评估重新定义为测试。 + +**状态:** accepted (boundary). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.relationships.terms#p1](#source-organon-relationships-terms-p1) + +[声明、证明与逐行解释](details.md#t21) + + + +## T22 · 持续工程活动 + +主体是由维护者、软件、工具和可用知识在实际生命周期中构成的活动;“临时”标签不能建立有限生命周期。 + +**前提与表示:** ActivityScope 要求非空参与者、软件和工具,以及参与者可用的知识;Continuing 和 BoundedLifecycle 检查发布、维护和限定运行次数。 + +**证明或检查:** 持续案例虽带临时标签,却有三次发布和六个维护周期。另设临时、原型和退役活动,具有真正限定的执行且没有后续维护安排。 + +**限度:** 这些数量是有限模型数据,不是项目工期估算。处于范围内本身不证明每位参与者都能完成每种变化。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.purpose#p1](#source-software-engineering-purpose-p1), [software-engineering.purpose#p2](#source-software-engineering-purpose-p2), [software-engineering.purpose#p3](#source-software-engineering-purpose-p3) + +[声明、证明与逐行解释](details.md#t22) + + + +## T23 · 私人可修改性与共同能力 + +原作者能够修改,不建立继任者或代理的能力;被动产物本身也不承接活动的意图。 + +**前提与表示:** CanChange 检查非空实际编辑/验证路径、参与者身份、工具及每一步所需知识。 + +**证明或检查:** 简单设计需要 privateLayout;原作者具备,继任者和代理没有。文档化路径使用后两者可用的公共知识和工具。产物执行与维护者提案仍是不同活动。 + +**限度:** 结果涉及已表示路径;缺少某条文档化路径,不是所有维护方式均不可能的普遍定理。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.purpose#p1](#source-software-engineering-purpose-p1), [software-engineering.purpose#p2](#source-software-engineering-purpose-p2), [software-engineering.purpose#p3](#source-software-engineering-purpose-p3) + +[声明、证明与逐行解释](details.md#t23) + + + +## T24 · 演化优先的条件 + +EvolutionPriority 是有条件的采用偏好:全部 PriorityConditions 成立时,选择 evolvable,或给出有根据的让步。 + +**前提与表示:** 条件要求持续发布与维护;参与者、软件身份及工具非空;每位参与者均有可用知识;两选项均满足行为/安全/延迟/保留要求;设计修订具有可信根据;evolvable 的修订路径非空,且每位列出参与者都具有路径所需的全部知识与工具。该路径的工作量须低于简单选项,而演化选项的当前复杂度更高。 + +**证明或检查:** 每种必要要求失败都会阻断适用性。普通语境的工作量为 6 对 17,复杂度为 3 对 1。具体成本威胁可支持让步,无说明的借口不能。最大候选增加真实 CSV 路径,却超出预算。 + +**限度:** 这里表达并例示默认价值优先,不从 Core 演绎该优先,也不要求最大扩展性。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.purpose#p3](#source-software-engineering-purpose-p3), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3) + +[声明、证明与逐行解释](details.md#t24) + + + +## T25 · 优先适用时的条件定理 + +给定已采用的优先规则、全部适用条件且无有根据的让步,必须选择 evolvable,并接受其较高当前复杂度。 + +**前提与表示:** priorityWhenApplicable 接收 EvolutionPriority、PriorityConditions 及不存在 JustifiedDeparture;这些是定理前提。 + +**证明或检查:** 将规则应用于给定条件,排除让步分支,再提取严格复杂度比较。具体案例检查演化选择、违反规则的简单选择及受威胁支持的让步。 + +**限度:** 定理不从事实证明价值规则,也不建立所有看似复杂的设计均具有相关优势。 + +**状态:** accepted (theorem). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3) + +[声明、证明与逐行解释](details.md#t25) + + + +## T26 · 有根据的可信变化方向 + +可信方向具有可表达的支持根据;无须已经存在多个实现,而单纯想象不足。 + +**前提与表示:** 适配检查计划、领域知识和历史内容,并提供可扩展的其他证据形式;这些是应用构造子,不是穷尽的哲学清单。 + +**证明或检查:** 登记计划指定第 2 次发布及设计修订。知识与历史案例检查具体相关性。仅有想象的条目失败;证据变化可以产生不同预测。 + +**限度:** 证明检查模型中给定的证据内容,不建立任意现实计划的可信性或预测校准程度。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3) + +[声明、证明与逐行解释](details.md#t26) + + + +## T27 · 可信性不等于无限预留 + +可信变化可支持选择性的预留,无须当前已有多个实现或最大化扩展;可想象性本身不提供这种支持。 + +**前提与表示:** 案例保留一个现有实现、某个有支持的具体方向及明确成本维度。 + +**证明或检查:** 可信计划案例在只有一个实现时仍成立。想象证据不满足支持条件。实际选择性设计及分开的成本坐标,不要求保留每种可能性或共同兑换率。 + +**限度:** 有限方向清单不证明所有未来变化可预测,也不证明遗漏可能性全都无关。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3) + +[声明、证明与逐行解释](details.md#t27) + + + +## T28 · 具体成本与有根据的让步 + +让步须指出额外成本威胁哪个具体目标。模型允许七种不同负担,不将它们汇总为普遍分数。 + +**前提与表示:** ConcreteThreat 连接实际候选成本、较简单选项的比较成本及指定负担的容量;JustifiedDeparture 将记录的负担和目标连接到该威胁。 + +**证明或检查:** 分别降低理解、构建、诊断、验证、协调、运行及迁移的相关容量形成案例。任意记录的借口若没有真实容量威胁就不能成立。 + +**限度:** 有限成本是模型中的工作与预算数据。源文不要求每类成本都适用,也不提供普遍数值取舍。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3) + +[声明、证明与逐行解释](details.md#t28) + + + +## T29 · 演化种类与义务变化 + +演化包含添加、替换、删除、撤销抽象、重画边界和迁移;独立与协调变化具有不同路径及契约处理。 + +**前提与表示:** EvolutionClaim 将指定请求及维护者能力连接到相应契约说明、实际 contractRunner 步骤和指定观察的保持/修订处理。SoftwareState 变换是 evolutionKindsCases 的独立合取项,不是此谓词的字段。 + +**证明或检查:** 案例以独立合取项计算添加、替换、删除、撤销、边界及迁移状态变化;还检查继任者路径、替换请求的保持、重画边界的显式契约修订及独立/协调工作的差异。修订说明针对改变的可观察行为;状态变换合取项另行检查。 + +**限度:** 枚举构造子例示源文维度,并允许其他方向;它们不声称涵盖所有演化,也不声称每种变化廉价。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.evolution-meaning#p1](#source-software-engineering-evolution-meaning-p1), [software-engineering.evolution-meaning#p2](#source-software-engineering-evolution-meaning-p2) + +[声明、证明与逐行解释](details.md#t29) + + + +## T30 · 一项演化优势不是所有优势 + +方案内易于添加,不蕴涵易于退出;设计修订有优势,也不蕴涵每个维度都有严格优势。 + +**前提与表示:** 工作量由同一设计、同一变化种类的实际编辑/验证路径计算。 + +**证明或检查:** 简单设计具有短添加路径和 17 单位撤销路径。可演化设计把修订从 17 降到 6,但两者添加均为 2;协调变化工作量可以高于独立变化。 + +**限度:** 这些反例排除无根据的跨维度推断,不新增所有变化都须廉价的义务。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.evolution-meaning#p1](#source-software-engineering-evolution-meaning-p1), [software-engineering.evolution-meaning#p2](#source-software-engineering-evolution-meaning-p2) + +[声明、证明与逐行解释](details.md#t30) + + + +## T31 · 结构后果与跨边界义务 + +结构评估将预期变化连接到传播、实际可观察契约、知识及验证工作;边界标签本身不能建立跨边界义务已获处理。 + +**前提与表示:** StructuralAccount 将记录的受影响组件、观察及工作绑定到实际路径。边界案例具有调用方 2、被调用方 1 及明确的保序义务。 + +**证明或检查:** 协调变化修改被调用方 1,并在调用方 2 检查契约。删除调用方检查仍发生跨界,却不满足 boundaryObligationChecked;把被调用方改为未触及的 7 会改变适用性;排序输出则不满足同一可观察契约。 + +**限度:** 这些是相关的有限检查,不是普遍强制清单,也不是现实中所有边界成本的估算。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2) + +[声明、证明与逐行解释](details.md#t31) + + + +## T32 · 结构名称不能证明能力 + +相同签名、模块数量或原则名称可以掩盖不同行为或变更能力;引入真实边界不必降低变化工作量。 + +**前提与表示:** EngineeringDesign 包含实际行为、组件路径、边界及固定批处理假设;元数据单独保留。 + +**证明或检查:** 相同签名产生保序与排序两种输出。八个模块都需要调整批量。私人路径和文档化路径元数据相同,继任者能力却不同。新增边界迁移已有验证步骤,工作量仍为 17,且仍缺私人知识;另一个追加检查版本为 18。 + +**限度:** 等工作量案例通过实际路径变换保留步骤单位;这些单位是披露的模型度量,不是观测工程耗时。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2) + +[声明、证明与逐行解释](details.md#t32) + + + +## T33 · 契约保持与刻意修订 + +指定契约可以保持,也可以刻意修订。修订说明识别变化义务及受影响方,不能把行为变化悄然改称保持。 + +**前提与表示:** ObservableContract 包含顺序行为和重试限制。实际依赖决定哪些消费者/运行人员受到影响,报告不能自行将他们排除。 + +**证明或检查:** 保序重构通过。排序及重试限制变化需要修订说明。遗漏实际受影响的运行人员会失败;有限测试外退出的行为展示局部保持的限度。 + +**限度:** 模型不要求保留所有历史行为、使用特定测试程序,也未新增普遍通知义务。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3) + +[声明、证明与逐行解释](details.md#t33) + + + +## T34 · 契约保持定理 + +若所有指定范围内的观察相等,则指定契约保持;范围内观察改变会反驳同一契约的保持。 + +**前提与表示:** contractPreservation 接收范围内普遍相等的前提。有限顺序/重试案例是独立检查,不自动提供该普遍前提。 + +**证明或检查:** 定理将所给相等关系作为 PreservesOn 返回;changedObservationNotPreserved 将其应用到不同结果的输入。案例计算顺序变化、重试 3、受影响方及被排除输入 [99] 的差异。 + +**限度:** 有限测试集通过不是普遍相等证明;保持判断始终保留指定范围。 + +**状态:** accepted (theorem). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3) + +[声明、证明与逐行解释](details.md#t34) + + + +## T35 · 修订与保留历史证据 + +预测、维护者、成本或目标变化可支持改判;新记录须保留旧预测及其观测失败。 + +**前提与表示:** RevisionAccount 将修订与独立固定的 observedHistory 比较,包括软件身份、旧预测及实际观测结果;revisionFor 使用当前语境和所选实现。 MaterialGroundsChanged 是五项记录差异的析取,不证明任一差异单独足以充分支持新选择。 + +**证明或检查:** 同一旧/新状态对同时改变预测、维护、维护者、迁移成本和目标容量;定理列出这五项差异。同步篡改 old 与 recordedOld 不能改变独立历史。另有保留案例分别使用无支持的替代方向或有根据的迁移成本让步。 + +**限度:** 记录的历史是固定模型证据;定理不鉴定任意现实日志,也不证明所有批评回应均充分。 + +**状态:** accepted (specification). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.revision#p2](#source-software-engineering-revision-p2), [software-engineering.revision#p1](#source-software-engineering-revision-p1) + +[声明、证明与逐行解释](details.md#t35) + + + +## T36 · 修订不能改写失败 + +新判断不能使旧失败预测变真。一致赞同和局部成功不建立普遍正确性;有理由的稳定仍然可能。 + +**前提与表示:** 旧静态预测及变化后的实际批处理结果独立于修订报告保持固定。 + +**证明或检查:** 21 项案例在批量 10 时相同,在批量 5 时不同;重贴标签不能修复该算术事实。稳定记录保留有效历史说明及批评方向覆盖,同时保持选择不变;指定无支持替代方向满足有界的保留判准。本案例不证明设计的实际可修订性。 + +**限度:** 结果允许有界的保留判断,不给予对后续根据或批评的永久豁免。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [software-engineering.revision#p2](#source-software-engineering-revision-p2), [software-engineering.revision#p1](#source-software-engineering-revision-p1) + +[声明、证明与逐行解释](details.md#t36) + + + +## T37 · 优先原则仍接受自身评估 + +对同一采用者及适用语境,优先原则和实际评估方法仍受 Grounds、整体理论一致性及自反审查约束。 + +**前提与表示:** 定理保留完整 Inherited、DomainSatisfied、PriorityConditions 和无有根据让步的前提。它识别实际优先对象,并以 sharedContext 内的含义等价连接演化价值承诺与 EvolutionPriority。 + +**证明或检查:** 排除让步分支,保留自反责任,并给出 priorityGrounds 及领域内容在完整一致理论中的成员关系。自身预测和评估器修订案例保留实际反例。 + +**限度:** 成功自评既不证明优先原则普遍正确,也不建立普遍样本要求。空样本批评适用于声明的局部评估契约。 + +**状态:** accepted (theorem). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.revision#p2](#source-software-engineering-revision-p2) + +[声明、证明与逐行解释](details.md#t37) + + + +## T38 · 全部已表示义务的共同见证 + +一个非空持续语境及其 evolvable 选择,同时满足已表示的完整继承和领域义务;优先确实适用,并接受额外当前复杂度。 + +**前提与表示:** 见证固定 sharedContext、各原评估任务及价值、完整事实/规范理论、继任者和代理路径、满足的需求、可信设计修订及无具体成本威胁。 + +**证明或检查:** inheritedCurrent 为 evolvable 构造每项继承字段;currentDomainSatisfied 提供领域义务。具体数值检查复杂度 3 对 1、工作量 6 对 17、非空自身对象及同一选项的可容许性。 + +**限度:** 这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +**状态:** accepted (satisfiability). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.charter.overview#p2](#source-organon-charter-overview-p2), [organon.charter.overview#p3](#source-organon-charter-overview-p3), [organon.charter.self-transcendence#p1](#source-organon-charter-self-transcendence-p1), [organon.charter.self-transcendence.orientation#p1](#source-organon-charter-self-transcendence-orientation-p1), [organon.charter.self-transcendence.non-finality#p1](#source-organon-charter-self-transcendence-non-finality-p1), [organon.charter.self-transcendence.limits#p1](#source-organon-charter-self-transcendence-limits-p1), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.charter.consistency#p1](#source-organon-charter-consistency-p1), [organon.charter.consistency.meaning#p1](#source-organon-charter-consistency-meaning-p1), [organon.charter.consistency.meaning#p2](#source-organon-charter-consistency-meaning-p2), [organon.charter.consistency.limits#p1](#source-organon-charter-consistency-limits-p1), [organon.charter.reflexivity#p1](#source-organon-charter-reflexivity-p1), [organon.charter.reflexivity.meaning#p1](#source-organon-charter-reflexivity-meaning-p1), [organon.charter.reflexivity.limits#p1](#source-organon-charter-reflexivity-limits-p1), [organon.grounds#p1](#source-organon-grounds-p1), [organon.grounds.assessment#p1](#source-organon-grounds-assessment-p1), [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3), [organon.grounds.scope#p1](#source-organon-grounds-scope-p1), [organon.grounds.scope#p2](#source-organon-grounds-scope-p2), [organon.grounds.scope#p3](#source-organon-grounds-scope-p3), [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2), [organon.grounds.implementations#p1](#source-organon-grounds-implementations-p1), [organon.grounds.implementations#p2](#source-organon-grounds-implementations-p2), [organon.grounds.implementations.limits#p1](#source-organon-grounds-implementations-limits-p1), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.purpose#p1](#source-software-engineering-purpose-p1), [software-engineering.purpose#p2](#source-software-engineering-purpose-p2), [software-engineering.purpose#p3](#source-software-engineering-purpose-p3), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3), [software-engineering.evolution-meaning#p1](#source-software-engineering-evolution-meaning-p1), [software-engineering.evolution-meaning#p2](#source-software-engineering-evolution-meaning-p2), [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2), [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3), [software-engineering.revision#p1](#source-software-engineering-revision-p1), [software-engineering.revision#p2](#source-software-engineering-revision-p2) + +[声明、证明与逐行解释](details.md#t38) + + + +## T39 · 继承义务不强制附加优先 + +在同一优先适用的持续语境内,presentSimple 选择满足每项已表示继承义务,却不采纳附加演化优先。 + +**前提与表示:** 两选项均满足必要要求;演化优势、可信设计修订、继任者/代理路径及复杂度取舍在模型内真实成立。没有临时生命周期或成本让步逃逸。 + +**证明或检查:** inheritedCurrent 为 presentSimple 构造完整继承义务。其实际采纳的简单性价值具有成本/工作理由及批评限度。领域规则要求 evolvable 或让步,而两者均被排除,因此 EvolutionPriority 为假。 + +**限度:** 反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。 + +**状态:** accepted (nonentailment). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3) + +[声明、证明与逐行解释](details.md#t39) + + + +## T40 · 形式证据不能建立什么 + +受检规范、条件证明及具体见证,仍与经验适切性、充分现实根据及哲学采纳有别。 + +**前提与表示:** 来源对应是单独记录的有界判断。成本、计划、历史、操作性理解及有限契约保留已披露的应用解释。 + +**证明或检查:** 本稿绑定实际源文、代码、类型和依赖对象,以及独立初稿与后续修复。先前失败或不完整对象不会被改称成功的历史执行。 + +**限度:** 构建成功、来源追溯、代理一致和自我适用不证明哲学正确性;没有为取得完成状态而删除冻结可证明目标或将其改为边界。 + +**状态:** accepted (boundary). 这是该冻结目标的审查结果,不提升为整段来源的完整证明。 + +**来源:** [organon.preamble#p1](#source-organon-preamble-p1), [organon.preamble#p2](#source-organon-preamble-p2), [organon.charter.self-transcendence.limits#p2](#source-organon-charter-self-transcendence-limits-p2), [organon.grounds#p1](#source-organon-grounds-p1), [organon.grounds.assessment#p1](#source-organon-grounds-assessment-p1), [organon.grounds.assessment#p2](#source-organon-grounds-assessment-p2), [organon.grounds.assessment#p3](#source-organon-grounds-assessment-p3), [organon.grounds.scope#p2](#source-organon-grounds-scope-p2), [organon.grounds.scope#p3](#source-organon-grounds-scope-p3), [organon.grounds.capabilities#p1](#source-organon-grounds-capabilities-p1), [organon.grounds.capabilities#p2](#source-organon-grounds-capabilities-p2), [organon.grounds.implementations#p1](#source-organon-grounds-implementations-p1), [organon.grounds.implementations#p2](#source-organon-grounds-implementations-p2), [organon.relationships.roles#p1](#source-organon-relationships-roles-p1), [organon.relationships.roles#p2](#source-organon-relationships-roles-p2), [organon.relationships.roles#p3](#source-organon-relationships-roles-p3), [extensions#p1](#source-extensions-p1), [software-engineering.purpose#p1](#source-software-engineering-purpose-p1), [software-engineering.purpose#p2](#source-software-engineering-purpose-p2), [software-engineering.purpose#p3](#source-software-engineering-purpose-p3), [software-engineering.evolution-priority#p1](#source-software-engineering-evolution-priority-p1), [software-engineering.evolution-priority#p2](#source-software-engineering-evolution-priority-p2), [software-engineering.evolution-priority#p3](#source-software-engineering-evolution-priority-p3), [software-engineering.evolution-meaning#p1](#source-software-engineering-evolution-meaning-p1), [software-engineering.evolution-meaning#p2](#source-software-engineering-evolution-meaning-p2), [software-engineering.structural-judgment#p1](#source-software-engineering-structural-judgment-p1), [software-engineering.structural-judgment#p2](#source-software-engineering-structural-judgment-p2), [software-engineering.structural-judgment#p3](#source-software-engineering-structural-judgment-p3), [software-engineering.revision#p1](#source-software-engineering-revision-p1), [software-engineering.revision#p2](#source-software-engineering-revision-p2) + +[声明、证明与逐行解释](details.md#t40) + + +## 来源追溯附录 + + + + +### `organon.preamble#p1` + +```text +This is a statement of Software Engineering Organon’s adopted philosophy. It expresses commitments, not factual assertions about every system or a proof of universal correctness. +``` + +状态: **not_applicable**; Lean: not_checked; 来源保真: not_applicable. + +此段保留文献权威、解释角色或已说明边界,不分配形式证明。 + +相关目标: [T01](#t01), [T40](#t40). + + + + + + +### `organon.preamble#p2` + +```text +The quoted provisions, their meanings, and their conditions of application form the core. The charter and Grounds constrain one another; their grouping establishes neither a deductive hierarchy nor an order of priority. [Rationale](rationale/README.md) supplies arguments and cases without adding obligations to this core. Skills are revisable applications under the repository’s stated objectives and constraints, not part of the philosophical commitments themselves. +``` + +状态: **not_applicable**; Lean: not_checked; 来源保真: not_applicable. + +此段保留文献权威、解释角色或已说明边界,不分配形式证明。 + +相关目标: [T01](#t01), [T40](#t40). + + + + + + +### `organon.charter` + +```text + + +``` + +状态: **not_applicable**; Lean: not_checked; 来源保真: not_applicable. + +空标题只保留结构,不分配定理。 + + + + + + +### `organon.charter.overview#p1` + +```text +**Self-Transcendence · Internal Consistency · Reflexivity** +``` + +状态: **not_applicable**; Lean: not_checked; 来源保真: not_applicable. + +此段保留文献权威、解释角色或已说明边界,不分配形式证明。 + +相关目标: [T01](#t01). + + + + + + +### `organon.charter.overview#p2` + +```text +> A system is intrinsically oriented toward expanding what it can understand and construct. It brings itself and its principles within the scope of generation and assessment, with internal consistency constraining this process. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T02、T38 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T01](#t01), [T02](#t02), [T38](#t38). + + + + + + +### `organon.charter.overview#p3` + +```text +The overview connects three distinct requirements: self-transcendence establishes a generative orientation and refuses to treat existing forms as final, internal consistency constrains judgments held simultaneously, and reflexivity brings the system and its principles within the scope of their own generation and assessment. The provisions below specify the conditions for each. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T02、T38 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T01](#t01), [T02](#t02), [T38](#t38). + + + + + + +### `organon.charter.self-transcendence#p1` + +```text +> A system is intrinsically oriented toward expanding what it can understand and construct. It does not regard any existing form as the endpoint of generation. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T02、T38 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T02](#t02), [T38](#t38). + + + + + + +### `organon.charter.self-transcendence.orientation#p1` + +```text +A commitment to keeping generative possibilities open is distinct from valuing their expansion. A system has an intrinsic orientation when it regards that expansion as worth pursuing. Merely permitting change does not fully express this orientation. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T02、T03、T38 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。这些是具体不蕴涵结果及有限支持案例,不是学习或自主执行的经验预测。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T02](#t02), [T03](#t03), [T38](#t38). + + + + + + +### `organon.charter.self-transcendence.non-finality#p1` + +```text +Refusing to regard an existing form as an endpoint keeps it open to being surpassed. “Existing form” includes a system’s current organization, methods, and principles, not only its appearance or artifacts. These remain within the scope of possible change; their revisability does not guarantee actual progress. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T02、T03、T38 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。这些是具体不蕴涵结果及有限支持案例,不是学习或自主执行的经验预测。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T02](#t02), [T03](#t03), [T38](#t38). + + + + + + +### `organon.charter.self-transcendence.limits#p1` + +```text +Whether progress has actually occurred remains a separate judgment. Having the orientation does not guarantee progress. Progress cannot be established merely by an increase in the number of artifacts, levels of abstraction, or terms. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T03、T38 作受限对应。这些是具体不蕴涵结果及有限支持案例,不是学习或自主执行的经验预测。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T03](#t03), [T38](#t38). + + + + + + +### `organon.charter.self-transcendence.limits#p2` + +```text +- “Intrinsic orientation” expresses Organon’s philosophical commitment; it does not assert that all systems in fact develop autonomously. +- Self-transcendence does not imply independence from external experience, knowledge, or collaboration, nor does it guarantee autonomous execution or self-improvement. +- Refusing to regard an existing form as an endpoint does not require every action to produce change. Justified stability can coexist with a generative orientation. +- Whether transcendence expands what can be understood and constructed requires discernible grounds; a system’s own claim of generation does not establish actual achievement. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T02、T03、T38 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。这些是具体不蕴涵结果及有限支持案例,不是学习或自主执行的经验预测。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T02](#t02), [T03](#t03), [T38](#t38), [T40](#t40). + + + + + + +### `organon.charter.consistency#p1` + +```text +> The principles and judgments a system holds simultaneously, together with their implications, must not yield contradictory judgments on the same question under the same assumptions, meanings of terms, and scope of application. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T04、T05、T38 作受限对应。一般接口在空问题域中可能空泛成立;工程实例使用非空问题族和实际可容许选项。结果不要求与已撤回主张永久相容,也未识别所有可能掩盖修订的文字遗漏。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T04](#t04), [T05](#t05), [T38](#t38). + + + + + + +### `organon.charter.consistency.meaning#p1` + +```text +“Held simultaneously” specifies which principles, judgments, and implications must hold together. Revision may withdraw an earlier judgment; old and new principles need not remain compatible forever. When a change has occurred, that change cannot be represented as though it had not occurred. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T04、T05、T38 作受限对应。一般接口在空问题域中可能空泛成立;工程实例使用非空问题族和实际可容许选项。结果不要求与已撤回主张永久相容,也未识别所有可能掩盖修订的文字遗漏。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T04](#t04), [T05](#t05), [T38](#t38). + + + + + + +### `organon.charter.consistency.meaning#p2` + +```text +“The same assumptions, meanings of terms, and scope of application” specifies the basis for comparing judgments. Divergent judgments under different conditions do not automatically constitute contradictions. Nor can unacknowledged changes in assumptions, meanings, or scope be used to conceal an existing contradiction. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T04、T05、T06、T38 作受限对应。一般接口在空问题域中可能空泛成立;工程实例使用非空问题族和实际可容许选项。结果不要求与已撤回主张永久相容,也未识别所有可能掩盖修订的文字遗漏。一致性不是充分的经验或价值支持;反例只涉及已披露的数学表示。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T04](#t04), [T05](#t05), [T06](#t06), [T38](#t38). + + + + + + +### `organon.charter.consistency.limits#p1` + +```text +- Tension between different assessments or values does not directly constitute a contradiction. Revision or qualification is needed when they require incompatible conclusions under the same conditions. +- Internal consistency is not correctness or sufficiency. A set of principles may be internally consistent while relying on false assumptions or neglecting important questions. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T04、T05、T06、T38 作受限对应。一般接口在空问题域中可能空泛成立;工程实例使用非空问题族和实际可容许选项。结果不要求与已撤回主张永久相容,也未识别所有可能掩盖修订的文字遗漏。一致性不是充分的经验或价值支持;反例只涉及已披露的数学表示。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T04](#t04), [T05](#t05), [T06](#t06), [T38](#t38). + + + + + + +### `organon.charter.reflexivity#p1` + +```text +> A system’s principles of generation and assessment also apply to the system itself and to the formation, application, and revision of those principles. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T07、T38 作受限对应。一般输入谓词仍需解释;非空具体对象及实际记录建立模型内义务履行,不建立普遍自我证明。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T07](#t07), [T38](#t38). + + + + + + +### `organon.charter.reflexivity.meaning#p1` + +```text +Reflexivity encompasses both the system itself and its principles. Assessment concerns not only whether the system conforms to its principles, but also how those principles are formed, where they apply, and why they may need revision. The formation and revision of principles thus also become objects of generation and assessment. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T07、T38 作受限对应。一般输入谓词仍需解释;非空具体对象及实际记录建立模型内义务履行,不建立普遍自我证明。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T07](#t07), [T38](#t38). + + + + + + +### `organon.charter.reflexivity.limits#p1` + +```text +- Applying principles equally retains their conditions of application. When the relevant conditions hold, being the system itself is not a basis for exemption. Nor does the requirement of reflexivity establish that every principle can be applied to itself without examining its applicability. +- Self-application does not constitute self-proof. Subjecting a principle to its own assessment does not thereby establish its correctness. +- That a revision is produced by the system itself does not give it sufficient grounds. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T07、T08、T38 作受限对应。一般输入谓词仍需解释;非空具体对象及实际记录建立模型内义务履行,不建立普遍自我证明。此有限反模型不证明所有可能编码中的独立性;保持形式开放也不能替代实际自反工作。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T07](#t07), [T08](#t08), [T38](#t38). + + + + + + +### `organon.grounds#p1` + +```text +> The grounds of principles and judgments must be articulable and subject to assessment appropriate to the nature of the claim. The strength and scope of a claim must be proportionate to the support provided by its grounds. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T08、T09、T38 作受限对应。此有限反模型不证明所有可能编码中的独立性;保持形式开放也不能替代实际自反工作。这是已声明任务的充分有限适配,不是穷尽分类,也未导入 Core 0.1.3 的全方面覆盖。声明新任务不授权替换已固定任务。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T08](#t08), [T09](#t09), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.assessment#p1` + +```text +Articulation and assessment have distinct responsibilities. Articulability requires that concepts, assumptions, reasons, and limits can be identified. Assessment requires examining whether those grounds support the corresponding claim. Clearly expressed grounds are not thereby sufficiently established. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T09、T13、T38 作受限对应。这是已声明任务的充分有限适配,不是穷尽分类,也未导入 Core 0.1.3 的全方面覆盖。声明新任务不授权替换已固定任务。这些区分不要求把价值、经验证据和推论化为同一分数。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T09](#t09), [T13](#t13), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.assessment#p2` + +```text +| Type of claim | Responsibility of assessment | What cannot substitute for that responsibility | +| --- | --- | --- | +| Empirical claim | Examine observations, evidence, and performance, together with the conditions, scope, and uncertainty of their support for the claim. | Treating measurability or repeatability itself as proof of relevance, correctness, or value. | +| Inferential claim | Examine whether the conclusion is supported by the stated assumptions and inferential relations. | Treating the absence of conflict between a conclusion and its assumptions as sufficient to establish that the conclusion follows from them. | +| Value commitment | State the position taken, its reasons, limits of application, and consequences, and remain open to relevant criticism. | Presenting a commitment as an empirical fact or a necessary inference, or substituting self-assertion for reasons. | +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T09、T10、T11、T12、T13、T38 作受限对应。这是已声明任务的充分有限适配,不是穷尽分类,也未导入 Core 0.1.3 的全方面覆盖。声明新任务不授权替换已固定任务。重复性或可测性本身不建立相关性、正确性或价值;未观察结果不同不必违背有限支持。缺少支持不等于评估做错;与假设相容弱于从假设得到蕴涵。应用给出充分的价值评估构造,不是证明所有初始假设的普遍要求,也不证明某价值普遍最优。这些区分不要求把价值、经验证据和推论化为同一分数。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T09](#t09), [T10](#t10), [T11](#t11), [T12](#t12), [T13](#t13), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.assessment#p3` + +```text +Initial value commitments may be stated explicitly as commitments; they need not prove all their own starting assumptions. The strength and scope of a claim do not require conversion to a common numerical scale. Different types of claims specify their support and limits in accordance with their nature. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T09、T12、T13、T38 作受限对应。这是已声明任务的充分有限适配,不是穷尽分类,也未导入 Core 0.1.3 的全方面覆盖。声明新任务不授权替换已固定任务。应用给出充分的价值评估构造,不是证明所有初始假设的普遍要求,也不证明某价值普遍最优。这些区分不要求把价值、经验证据和推论化为同一分数。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T09](#t09), [T12](#t12), [T13](#t13), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.scope#p1` + +```text +Performance is discerned within particular relations, conditions, and scopes of observation. A boundary helps specify what a comparison concerns, but local examples do not automatically support unconditional universal conclusions. A judgment cannot establish that relevant differences do not exist merely because its chosen scope omits them. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T14、T15、T38 作受限对应。角色字符串非空本身不是充分解释;未使用的方法也不会因此成为必需。把某输入排除出比较,不是该处不存在相关差异的证据。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T14](#t14), [T15](#t15), [T38](#t38). + + + + + + +### `organon.grounds.scope#p2` + +```text +Measurement can make some differences comparable. Repeated assessment can help examine the stability of corresponding conclusions. Their roles, and the role of any assessment framework, must be explained relative to the claim and its context. Measurement, repeatability, and an assessment framework do not form a universally necessary chain on which all judgments must depend. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T14、T15、T38 作受限对应。角色字符串非空本身不是充分解释;未使用的方法也不会因此成为必需。把某输入排除出比较,不是该处不存在相关差异的证据。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T14](#t14), [T15](#t15), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.scope#p3` + +```text +An observation that has not been reproduced may still offer limited support, and random outcomes need not be identical on every occasion. The verifiability of observations, reproducibility of conditions, and stability of conclusions must be distinguished. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T14、T15、T38 作受限对应。角色字符串非空本身不是充分解释;未使用的方法也不会因此成为必需。把某输入排除出比较,不是该处不存在相关差异的证据。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T14](#t14), [T15](#t15), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.capabilities#p1` + +```text +Capability claims are subject to Grounds: the capability claimed, its conditions, and the support for it must be identifiable. The core does not prescribe uniform definitions of method mastery, method generation, or capability levels. Applications specify the capabilities they assess and may require understanding, explanation, or performance under relevant variations. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T16、T17、T38 作受限对应。这不是心理理解的普遍定义。精确身份是范围前提;履行支持责任的是实际契约证明,而非身份本身。外部评估者可以支持所选输出主张,而不建立被评系统如何理解自身生成过程。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T16](#t16), [T17](#t17), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.capabilities#p2` + +```text +Grounds for a capability claim may be supplied by an external assessor. Their articulability does not by itself require the assessed system to understand or explain its internal generation process. Evidence of reliable output must be assessed against the capability actually claimed; it does not automatically establish understanding of that process. Nor can the number of method documents, terms, tools, or artifacts alone establish a capability beyond what that evidence supports. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T16、T17、T38 作受限对应。这不是心理理解的普遍定义。精确身份是范围前提;履行支持责任的是实际契约证明,而非身份本身。外部评估者可以支持所选输出主张,而不建立被评系统如何理解自身生成过程。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T16](#t16), [T17](#t17), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.implementations#p1` + +```text +> The choice of an implementation must be supported by reasons connected to the objectives and values pursued and to the relevant constraints. Its name, conventional use, or established status alone does not provide sufficient grounds for giving it priority. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T18、T19、T38 作受限对应。这些是应用理由,不是普遍成本函数,也不要求惯用实现必须落选。没有结果断言所有实现等价、保证多个可行实现,或从章节位置推出选择承诺。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T18](#t18), [T19](#t19), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.implementations#p2` + +```text +This choice provision adds an additional evaluative commitment: name, conventional use, or established status alone is insufficient to establish priority. Grouping it under Grounds does not mean that it follows from the general requirement to assess reasons, or merely from the discernibility of performance. Conventions and existing arrangements may have practical significance, but that significance must be connected to the objectives and values pursued and to the relevant constraints. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T18、T19、T38 作受限对应。这些是应用理由,不是普遍成本函数,也不要求惯用实现必须落选。没有结果断言所有实现等价、保证多个可行实现,或从章节位置推出选择承诺。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T18](#t18), [T19](#t19), [T38](#t38), [T40](#t40). + + + + + + +### `organon.grounds.implementations.limits#p1` + +```text +- Openness does not make all implementations equivalent, nor does it guarantee multiple feasible implementations for the same objective. +- A method’s explanatory power, limits of application, simplicity, and explicit process requirements may all provide grounded reasons for assessment. They cannot be excluded merely because they concern methods internal to the implementation. +- Identical local performance does not establish overall equivalence. Relations, conditions, and the scope of comparison are constrained by the provisions of Grounds. +- Openness does not reject an implementation merely because it already exists or is conventionally used. Relevant reasons may still give it priority. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T15、T18、T19、T38 作受限对应。把某输入排除出比较,不是该处不存在相关差异的证据。这些是应用理由,不是普遍成本函数,也不要求惯用实现必须落选。没有结果断言所有实现等价、保证多个可行实现,或从章节位置推出选择承诺。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T15](#t15), [T18](#t18), [T19](#t19), [T38](#t38). + + + + + + +### `organon.relationships` + +```text + + +``` + +状态: **not_applicable**; Lean: not_checked; 来源保真: not_applicable. + +空标题只保留结构,不分配定理。 + + + + + + +### `organon.relationships.roles#p1` + +```text +The charter states the generative orientation, the consistency constraint, and reflexive application. Grounds specifies support requirements for judgments and includes an additional commitment concerning implementation choices. Both parts belong to the core and constrain one another. Their placement neither makes Grounds a deduction from the charter nor gives the charter priority over it. Each commitment needs its own reasons. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T08、T20、T38、T39 作受限对应。此有限反模型不证明所有可能编码中的独立性;保持形式开放也不能替代实际自反工作。字段提取不从单一原则推出所有义务。采纳标记是独立事实,不能替代规范内容。要求样本的批评属于应用判准,不是对观察的普遍要求。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。 + +相关目标: [T01](#t01), [T08](#t08), [T20](#t20), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `organon.relationships.roles#p2` + +```text +Internal Consistency concerns whether simultaneously held judgments can hold together; Grounds concerns whether and how far a claim is supported. A conclusion may fail to conflict with its assumptions without being supported by them. Self-Transcendence specifies a generative orientation and non-finality; neither establishes actual capability. Applications may supply objectives, values, and capability definitions; claims made under those objectives, values, and definitions remain subject to the relevant core provisions. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T03、T06、T11、T16、T20、T38、T39 作受限对应。这些是具体不蕴涵结果及有限支持案例,不是学习或自主执行的经验预测。一致性不是充分的经验或价值支持;反例只涉及已披露的数学表示。缺少支持不等于评估做错;与假设相容弱于从假设得到蕴涵。这不是心理理解的普遍定义。精确身份是范围前提;履行支持责任的是实际契约证明,而非身份本身。字段提取不从单一原则推出所有义务。采纳标记是独立事实,不能替代规范内容。要求样本的批评属于应用判准,不是对观察的普遍要求。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。 + +相关目标: [T03](#t03), [T06](#t06), [T11](#t11), [T16](#t16), [T20](#t20), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `organon.relationships.roles#p3` + +```text +Self-Transcendence does not substitute for Reflexivity: keeping existing forms open to being surpassed differs from applying relevant principles to the system and to their own formation, application, and revision. Reflexivity extends these requirements to the system and to the formation, application, and revision of its principles. The grounds and limits of the Grounds provisions must themselves be articulable. The system’s own capability claims remain subject to assessment, and this philosophy’s existing form cannot gain priority merely from its established status. Such mutual application provides no self-proof and does not remove conditions of application. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T07、T08、T16、T18、T20、T37、T38、T39 作受限对应。一般输入谓词仍需解释;非空具体对象及实际记录建立模型内义务履行,不建立普遍自我证明。此有限反模型不证明所有可能编码中的独立性;保持形式开放也不能替代实际自反工作。这不是心理理解的普遍定义。精确身份是范围前提;履行支持责任的是实际契约证明,而非身份本身。这些是应用理由,不是普遍成本函数,也不要求惯用实现必须落选。字段提取不从单一原则推出所有义务。采纳标记是独立事实,不能替代规范内容。要求样本的批评属于应用判准,不是对观察的普遍要求。成功自评既不证明优先原则普遍正确,也不建立普遍样本要求。空样本批评适用于声明的局部评估契约。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。 + +相关目标: [T07](#t07), [T08](#t08), [T16](#t16), [T18](#t18), [T20](#t20), [T37](#t37), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `organon.relationships.terms#p1` + +```text +| Term | Meaning in this philosophy | +| --- | --- | +| Existing form | The system’s current organization, methods, and principles, not only its appearance or artifacts. | +| Assessment | Examination of reasons, applicability, and observed performance; not limited to executable tests. | +``` + +状态: **incomplete**; Lean: passed; 来源保真: partial. + +来源与 T02 作受限对应。此定义表达采用的义务,不会导致变化,也不证明所有系统都能自主改进。 + +相关目标: [T02](#t02), [T21](#t21). + + + + + + +### `extensions#p1` + +```text +This chapter adds a software engineering commitment and specifies its meaning and limits. It does not claim that this commitment follows from the Charter or Grounds. Those provisions remain adopted and constrain its application. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T37、T38、T39 作受限对应。成功自评既不证明优先原则普遍正确,也不建立普遍样本要求。空样本批评适用于声明的局部评估契约。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。 + +相关目标: [T01](#t01), [T37](#t37), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `software-engineering.purpose#p1` + +```text +Software engineering concerns the construction, operation, understanding, and revision of software within its relevant human and technical conditions. This philosophy guides decisions by people and agents; it does not attribute an intrinsic orientation to every software artifact. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T22、T23、T38 作受限对应。这些数量是有限模型数据,不是项目工期估算。处于范围内本身不证明每位参与者都能完成每种变化。结果涉及已表示路径;缺少某条文档化路径,不是所有维护方式均不可能的普遍定理。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T22](#t22), [T23](#t23), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.purpose#p2` + +```text +The evolution capability considered here belongs to the continuing engineering activity: maintainers, including successor maintainers and agents, working with software, tools, and available knowledge. Code that its original author can modify is not on that ground alone shown to support that continuing activity. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T22、T23、T38 作受限对应。这些数量是有限模型数据,不是项目工期估算。处于范围内本身不证明每位参与者都能完成每种变化。结果涉及已表示路径;缺少某条文档化路径,不是所有维护方式均不可能的普遍定理。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T22](#t22), [T23](#t23), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.purpose#p3` + +```text +Apply the following priority according to the software's credible lifecycle and maintenance expectations. A genuinely temporary script, bounded prototype, or retiring system may have little reason to support further evolution. Calling a continuing system temporary does not establish that condition. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T22、T23、T24、T38 作受限对应。这些数量是有限模型数据,不是项目工期估算。处于范围内本身不证明每位参与者都能完成每种变化。结果涉及已表示路径;缺少某条文档化路径,不是所有维护方式均不可能的普遍定理。这里表达并例示默认价值优先,不从 Core 演绎该优先,也不要求最大扩展性。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T22](#t22), [T23](#t23), [T24](#t24), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.evolution-priority#p1` + +```text +> When relevant behavioral, safety, performance, and other necessary requirements are satisfied, give priority to continuing maintainers' ability to make credible future changes, including changes to the design itself, over present abstraction simplicity. Accept additional present abstraction complexity for that purpose, while allowing this preference to yield when the added costs threaten concrete engineering objectives. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T24、T25、T38、T39 作受限对应。这里表达并例示默认价值优先,不从 Core 演绎该优先,也不要求最大扩展性。定理不从事实证明价值规则,也不建立所有看似复杂的设计均具有相关优势。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。 + +相关目标: [T24](#t24), [T25](#t25), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `software-engineering.evolution-priority#p2` + +```text +Credible directions of change have articulable grounds, such as a committed plan, relevant domain knowledge, or an applicable history of change. They need not already have multiple implementations. Their credibility remains open to revision; a conceivable change alone does not establish that it warrants accommodation now. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T24、T25、T26、T27、T38、T39 作受限对应。这里表达并例示默认价值优先,不从 Core 演绎该优先,也不要求最大扩展性。定理不从事实证明价值规则,也不建立所有看似复杂的设计均具有相关优势。证明检查模型中给定的证据内容,不建立任意现实计划的可信性或预测校准程度。有限方向清单不证明所有未来变化可预测,也不证明遗漏可能性全都无关。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。 + +相关目标: [T24](#t24), [T25](#t25), [T26](#t26), [T27](#t27), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `software-engineering.evolution-priority#p3` + +```text +This is a default priority, not an obligation to maximize extensibility or retain every possibility. Costs include relevant burdens of understanding, construction, diagnosis, verification, coordination, operation, and eventual migration. A departure from the priority identifies the objective threatened and why the costs matter. No universal numerical exchange rate between these considerations is prescribed. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T24、T25、T26、T27、T28、T38、T39 作受限对应。这里表达并例示默认价值优先,不从 Core 演绎该优先,也不要求最大扩展性。定理不从事实证明价值规则,也不建立所有看似复杂的设计均具有相关优势。证明检查模型中给定的证据内容,不建立任意现实计划的可信性或预测校准程度。有限方向清单不证明所有未来变化可预测,也不证明遗漏可能性全都无关。有限成本是模型中的工作与预算数据。源文不要求每类成本都适用,也不提供普遍数值取舍。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。反模型允许 Core 所容许的不同附加价值排序。它建立有限不蕴涵,不建立领域优先无根据,也不声称简单设计更利于未来维护。 + +相关目标: [T24](#t24), [T25](#t25), [T26](#t26), [T27](#t27), [T28](#t28), [T38](#t38), [T39](#t39), [T40](#t40). + + + + + + +### `software-engineering.evolution-meaning#p1` + +```text +Evolution includes adding capabilities, replacing implementations, deleting mechanisms, withdrawing abstractions, redrawing boundaries, and migrating away from an existing technology or model. Making additions within a fixed scheme does not establish equal ability to revise or leave that scheme. Not every such change can or should be made inexpensive. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T29、T30、T38 作受限对应。枚举构造子例示源文维度,并允许其他方向;它们不声称涵盖所有演化,也不声称每种变化廉价。这些反例排除无根据的跨维度推断,不新增所有变化都须廉价的义务。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T29](#t29), [T30](#t30), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.evolution-meaning#p2` + +```text +An evolution claim identifies the relevant changes and the maintainers' conditions. Independent changes, coordinated changes, preservation of existing obligations, and deliberate revision of those obligations can require different structures. A design's advantage on one dimension does not establish an advantage on every dimension. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T29、T30、T38 作受限对应。枚举构造子例示源文维度,并允许其他方向;它们不声称涵盖所有演化,也不声称每种变化廉价。这些反例排除无根据的跨维度推断,不新增所有变化都须廉价的义务。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T29](#t29), [T30](#t30), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.structural-judgment#p1` + +```text +Apply the preceding commitment to engineering consequences as a whole, including the relations among components, their observable contracts, and the work needed to understand and verify a change. An interface's shape, the number of modules or extension points, or the use of a named principle is not sufficient evidence of the claimed capability. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T31、T32、T37、T38 作受限对应。这些是相关的有限检查,不是普遍强制清单,也不是现实中所有边界成本的估算。等工作量案例通过实际路径变换保留步骤单位;这些单位是披露的模型度量,不是观测工程耗时。成功自评既不证明优先原则普遍正确,也不建立普遍样本要求。空样本批评适用于声明的局部评估契约。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T31](#t31), [T32](#t32), [T37](#t37), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.structural-judgment#p2` + +```text +The relevant comparison may examine how a change propagates, which knowledge and obligations cross a boundary, which assumptions become fixed, and what a later withdrawal would require. A proposed boundary needs support for the changes it is meant to accommodate; introducing it does not by itself show that those changes became easier. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T31、T32、T38 作受限对应。这些是相关的有限检查,不是普遍强制清单,也不是现实中所有边界成本的估算。等工作量案例通过实际路径变换保留步骤单位;这些单位是披露的模型度量,不是观测工程耗时。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T31](#t31), [T32](#t32), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.structural-judgment#p3` + +```text +Distinguish a transformation that preserves an identified observable contract from one that deliberately revises that contract. The latter needs a corresponding account of changed obligations and affected parties. This distinction does not require preserving every historical behavior or using a particular testing or migration procedure. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T33、T34、T38 作受限对应。模型不要求保留所有历史行为、使用特定测试程序,也未新增普遍通知义务。有限测试集通过不是普遍相等证明;保持判断始终保留指定范围。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T33](#t33), [T34](#t34), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.revision#p1` + +```text +Changed evidence about likely changes, maintenance conditions, costs, or objectives may justify revising a design or this priority's application. A revised judgment acknowledges material changes in its grounds; it does not make a failed prediction successful retrospectively. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T35、T36、T38 作受限对应。记录的历史是固定模型证据;定理不鉴定任意现实日志,也不证明所有批评回应均充分。结果允许有界的保留判断,不给予对后续根据或批评的永久豁免。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T35](#t35), [T36](#t36), [T38](#t38), [T40](#t40). + + + + + + +### `software-engineering.revision#p2` + +```text +Retaining a design can be justified when the relevant alternatives have no supported contribution or impose costs that defeat the objective. Reflexivity also keeps this engineering commitment and the methods used to assess evolution within the scope of criticism and revision. Continued change, agreement, or successful examples do not establish its universal correctness. +``` + +状态: **limited**; Lean: passed; 来源保真: partial. + +来源与 T35、T36、T37、T38 作受限对应。记录的历史是固定模型证据;定理不鉴定任意现实日志,也不证明所有批评回应均充分。结果允许有界的保留判断,不给予对后续根据或批评的永久豁免。成功自评既不证明优先原则普遍正确,也不建立普遍样本要求。空样本批评适用于声明的局部评估契约。这是经审查表示的可满足性;它既不证明现实工程结果,也不将哲学价值采纳化约为定理。 + +相关目标: [T35](#t35), [T36](#t36), [T37](#t37), [T38](#t38), [T40](#t40). + + + diff --git a/SoftwareEngineering/zh/rationale/README.md b/SoftwareEngineering/zh/rationale/README.md new file mode 100644 index 0000000..2f27482 --- /dev/null +++ b/SoftwareEngineering/zh/rationale/README.md @@ -0,0 +1,90 @@ +# 软件工程:理由与限度 + +这份非规范性论证解释[软件工程哲学](../PHILOSOPHY.md)。它既不确立采用,也不向该文本增加义务。其起点是 Organon Core 0.1.2;新增的价值立场面向由人与 agent 在已说明的生命周期内维护的软件。在这一范围内,用户偏好朝有可信根据的变更方向持续演进,同时接受在其成本威胁具体目标时作出让步。可信程度关乎预期某一变更方向的可辨识理由,而非所有可想象的扩展。 + +以下论证区分这一价值选择、Core 的约束与工程文献。来源摘要只陈述各来源的有限贡献。将这些贡献与本哲学联系起来的解释,是作者的论证,不是归于这些来源的结论。构造的反例均作相应标明。 + +## Core 的贡献与留下的开放问题 + +**自超越**质疑架构、工具链或设计词汇的终局性。在软件中,这为保留学习更好分解方式的可能性提供了理由。若要优先投资于这种可能,而非完成一个有明确边界的产品,还需要额外前提:未来的构建能力必须在产品生命周期内具有重要性。Core 本身允许有根据的稳定。一个构造的反例是一次性转换器,其经验证的输出已经完成了目的;用扩展框架替换其直接实现,并不必然拓展任何维护者珍视的东西。 + +**自洽**有助于区分不相容的承诺与普通权衡。体系不能一面承诺某种数据新鲜度保证,一面又在完全相同的保证下接受过时结果,并仍称自身自洽。适用这一约束,需要明确新鲜度、确认以及相关执行条件的含义。它不选择这些含义,也不确立这些含义是否充分。作为构造的反例,两个组件可能一致地实施同一种错误的单位换算。自洽揭示立场内部的冲突,不提供缺失的领域真相。 + +**反身**将架构规则和 agent 指令与应用代码一同纳入批评范围。意在减少协调的规则,本身可能成为协调开销的来源。额外的工程前提是:这类开销与维护者的目标有关。一个构造的反例是某项审查规则,在没有可辨识的剩余问题时,仍要求每次审查都再接受一次审查。反身使这一规则可以接受检验;它既不证明审查有效,也不蕴含这种无止境程序或任何特定的独立审查安排。 + +**根据:说明与检验**区分有说服力的解释与充分支持。关于吞吐量的主张需要相关负载的证据;关于接口隔离变更的主张需要针对依赖和变更情境的论证;对未来灵活性的偏好需要理由,并承认其后果。工程应用提供这些负载和情境。一个构造的反例是文档完备的抽象,其设想的未来客户却从未出现。它的理由可以说明,但其预测可能并不可靠。 + +**根据:范围与度量**防止用局部成功决定更广泛的架构比较。在未改变的输入上得到相同输出,仍未考察并发、更新、故障处理和维护工作量。哪些差异在这里重要,由额外前提决定。这一限度也适用于负面判断:孤立事件可以成为调查故障的理由,却不足以确立整个总体存在缺陷。一个构造的反例是仅因某份有用的故障报告尚未复现,就拒绝它。数值评分与可重复性都不能单独解决相关性问题。 + +**能力主张**需要明确检验对象。agent 可以在受约束的仓库中可靠地完成某种变换,而不理解架构的每一项理由。Core 允许用外部证据支持前一种主张,并不普遍要求内省式解释。要求交接内容可被理解,是一项额外的应用选择,这里以持续维护为其理由。一个构造的反例是不透明但可靠的生成器,它通过稳定接口和可检查输出支持可维护的产品。仅凭其不透明,不能确立它缺乏能力;不过,更强的理解能力主张仍未得到支持。 + +**对替代实现的开放**排除仅凭模式的声誉给予优先的做法。这项贡献具有实质内容:SOLID、函数式编程与元编程,都不能自行确立自身的适用性。工程补充了使比较成为可能的目标和约束。针对不加辨别地追逐新颖性的一个构造反例是:用一种陌生的替代方案取代熟悉且有支持的平台,相关行为相同,交接却更困难。熟悉程度可以提供实际理由;称一种实现符合惯例,并不能反驳它。 + +这些承诺相互约束,但不规定软件价值的层级。将它们结合起来,并不能推出在相关必要要求得到满足后,演进应优先于当下抽象的简单性。本哲学增加这一可让步的偏好,是因为其目标维护者预期会持续负责不断变化的软件。反过来,与 Core 兼容本身也不足以成为采用该偏好的理由。它的价值取决于生命周期、预期变更的可信程度,以及保留这些可能性所需的成本。 + +## 工程论证及其边界 + +Parnas 比较了分配处理步骤的分解方式与隐藏设计决策的分解方式。他的论证支持考察哪些知识跨越模块边界。它没有将良好结构等同于某一种运行时安排:他明确讨论了机械照搬的实现所带来的调用开销,以及在保持分解方式的同时组装高效代码的替代方案。这是原文已有的条件,不是后来为保护模块化而添加的例外。[Parnas, “On the Criteria To Be Used in Decomposing Systems into Modules,” pp. 1056–1058](https://cse.sc.edu/~mgv/csce330f14/ParnasCriteria.pdf)。 + +关于 **SRP**,Martin 后来的解释将职责定位于提出变更要求的业务职能,并将内聚与共同的变更理由联系起来。这支持调查代码为何一同变化,而非计算方法数量。构造的反例:仅因验证、计算和解释是不同动词,就将它们分开,可能把同一项业务规则修订分散到独立维护的组件中。这是本论证对机械解释的反例,不是 Martin 的经验发现。[Martin, “The Single Responsibility Principle,” 2014](https://blog.cleancoder.com/uncle-bob/2014/05/08/SingleReponsibilityPrinciple.html)。 + +关于 **OCP**,Martin 明确将封闭性限定于选定的变更。他原文中的绘图示例能够容纳新形状,却不能让绘图循环免受新排序要求的影响。因此,有用的问题是扩展机制保护了哪种变更,又将哪种变更暴露在外。承诺普遍的可扩展性超出了该来源的主张;面对不同的变更方向,修改既有边界可以是有理由的响应。[Martin, “The Open-Closed Principle,” p. 6](https://objectmentor.com/resources/articles/ocp.pdf)。 + +关于 **LSP**,Liskov 和 Wing 将子类型判断建立在规格以及对可观察性质的保持之上,包括不变量和历史性质。他们的窗口示例说明,为何允许额外的移动可能违反既有客户端所依赖的性质。签名匹配或不改动继承方法都不足以成立。将类似推理用于协议或泛型参数,是对这一思想的拟议迁用;他们的论文不确立每一种此类应用。[Liskov and Wing, “A Behavioral Notion of Subtyping,” §§5.2–5.3](https://www.cs.cmu.edu/~wing/publications/LiskovWing94.pdf)。 + +关于 **ISP**,Martin 考察了被迫依赖其不使用接口的客户端。分离这些依赖,不必拆开有状态对象:定时门示例在共享数据之上实现不同的客户端接口。因此,原始案例质疑了“接口分离总是要求对象分离”这一推论。拟议的划分是否减少了产生实际后果的耦合,仍需针对真实客户端判断。[Martin, “The Interface Segregation Principle,” pp. 4–6](https://objectmentor.com/resources/articles/isp.pdf)。 + +关于 **DIP**,关注点是高层策略、抽象和实现细节之间的关系。Martin 的例子包括 C 标准 I/O,因此这一机制不限于继承框架。构造的反例:某个接口照搬供应商的数据模式和异常,即便采用依赖注入,也可能保留对这些细节的依赖。因此,架构主张需要接口声明之外的支持。[Martin, “The Dependency Inversion Principle,” pp. 5–6](https://objectmentor.com/resources/articles/dip.pdf)。 + +Martin 更广泛的论述为这些原则提供了重要限定:静态模板可以实现 OCP;ISP 不要求每个客户端类都有独立接口;依赖稳定的具体实现可以是合理的。他提醒字符编码变更可能推翻最后一项判断,保留了该判断的条件。这些限定支持依情境应用原则,而非强制罗列一套抽象类。[Martin, “Design Principles and Design Patterns,” pp. 7, 14–16](https://objectmentor.com/resources/articles/Principles_and_Patterns.pdf)。 + +**重构**有行为边界。Fowler 将其定义为在保持可观察行为的同时,使软件更易理解、修改成本更低的内部结构调整。这支持区分结构准备与功能变更;仅凭这一定义,无法确定项目中的观察范围。构造的反例:某次重写保持返回值,却改变了外部所依赖的失败行为。称其为重构,不能决定该行为是否在保持主张的范围内。[Fowler, “Definition of Refactoring”](https://martinfowler.com/bliki/DefinitionOfRefactoring.html)。 + +**函数式组合**提供另一条分解路径。Hughes 展示了高阶函数和惰性求值如何分离可复用的计算模式,以及如何将生成与选择分离。他的论证没有将不使用赋值视为充分的质量尺度。原文的一项限定涉及副作用:其发生时机可能依赖相隔很远的消费位置。相关收益是有用的组合边界,不是遵循某套词汇或全面禁止状态。[Hughes, “Why Functional Programming Matters,” §§1–4](https://www.cs.kent.ac.uk/people/staff/dat/miranda/whyfp90.pdf)。 + +**泛型编程**同样需要共同语义,不能只有语法匹配。Dehnert 和 Stepanov 从操作定律与复杂度预期出发论证。他们对迭代器的讨论解释了,为何在不同复杂度模型上提供形似随机访问的操作,会误导算法选择。这支持考察可复用算法中隐藏的前提;它不支持要求每个具有身份或拥有资源的对象都建模为规则值(regular value)。[Dehnert and Stepanov, “Fundamentals of Generic Programming,” pp. 3–5, 10–11](https://www.stepanovpapers.com/DeSt98.pdf)。 + +**模板元编程与部分求值**说明,如何利用较早可用的信息,对较后的计算进行特化。Veldhuizen 将模板实例化与离线部分求值联系起来,同时区分参数化复用、编译期计算和生成。他的递归实例化示例也暴露了终止性方面的限度。这一联系可以解释某种收益;它不能确立特化没有成本,也不能确立每个参数都值得静态绑定。[Veldhuizen, “C++ Templates as Partial Evaluation”](https://arxiv.org/abs/cs/9810010)。 + +表达式模板提供了一个具体案例:Veldhuizen 在特定基准条件下展示了避免临时向量和合并求值。这些结果不能确立表达式模板具有普遍优势。[Veldhuizen, “Expression Templates”](https://www.cs.rpi.edu/~musser/design/blitz/exprtmpl.html)。Iglberger 及其同事随后展示了矩阵、稀疏和复合运算中的局限,从而提出采用不同求值策略和优化计算内核的理由。他们的实验是针对无条件性能主张的反例,不是有关每个当前库版本的证据。[Iglberger et al., “Expression Templates Revisited,” §§5–8](https://arxiv.org/abs/1104.1729)。 + +本论证进一步作出工程推论:将工作从执行期移到编译期,会改变成本与限制出现的位置。有用的比较可以包括构建延迟、生成代码的体积、诊断、部署组合、运行时分派,以及修改该机制所需的专长。构造的反例:发布时已知的有限配置可能适合特化,而客户加载的行为可能适合运行时选择。任何一种安排都不能仅因把决策前移或后移就胜出。 + +## 组合与继承 + +前述 LSP 论证关乎行为子类型,本身不决定为复用而继承实现或组合协作者之间的选择。以下比较是本配套文档的工程论证。当子类型契约与受支持的变化点稳定时,继承可以提供有用的共享实现。组合可以让维护者替换协作者,而不声称包含它的对象是它的子类型。任何一种机制都不能单独确立独立变更:如果委托包装层暴露协作者的异常与生命周期要求,就可能保留同样具有实际后果的依赖。 + +一个构造的例子是重试策略不断变化的服务。策略协作者可以允许替换,而无需编辑无关的存储继承层级。但如果重试、事务和确认共同决定可观察行为,拆分类并不会使其变更独立。对于实际维护者,具有明确且稳定钩子的继承框架,仍可能比一组相互转发的对象更易理解和验证。比较契约、允许的覆盖、所有权及有可信根据的变更如何传播。当这些条件改变时重新审视选择;不能只凭口号优先采用组合或继承。 + + +## 有理由的设计判断 + +前述论证提出一条依情境展开的考察路径,不是一套强制评分表。设计提案可以从一项具体变更开始,说明在当前结构下需要理解、修改、验证和交接什么。将拟议边界与保留当前安排作比较,随后可以揭示它是在使真实决策局部化,还是仅仅搬移复杂度。一项有可信根据的变更可能足以支持一条边界;大量假设性变更也可能一条都不能支持。 + +重要的推论关乎相关维护者承担的整体后果。修改文件更少,可能掩盖更难理解的核心抽象。增加模块,可能使不同职责能够被独立理解。特化实现可以简化使用者的工作,同时将复杂机制集中在具有足够专长的地方。这些可能性否定了对范式、层数或抽象密度的固定偏好。它们不使替代方案无法区分:已说明的任务和约束仍可明确支持其中一种。 + +验证可以结合保持行为的比较、相关变更的实际演练、依赖审查,以及维护者对设计工作方式的解释。这些是建议的取证方式,其负担取决于主张。通过范围有限的测试,只支持相应有限结果;对未来变更的清晰论证,仍以其前提为条件。不确定性可以成为推迟、小范围预留改动接口或直接实现的理由,而非采用通用框架。 + +## 撤除、迁移与持续责任 + +演进可以包括移除抽象。在本提案下,抽象不能凭创建成本或架构声望获得继续存在的资格。一个构造的例子是策略框架,其中原以为相互独立的变化已经收敛为一条稳定规则。内联这一规则,可以改善可理解性,使维护者不再需要协调过时的扩展点。相关比较既包括当下变得更简单的方面,也包括日后会变得更难修改的方面。 + +迁移提出了一个不同于“目标状态是否值得追求”的问题。更简单的表示,如果在迁往它的过程中丢失所需数据、破坏依赖它的使用方,或超出运行预算,就可能不是当下的好选择。逆转可能需要恢复数据和协调状态,而非仅仅回退代码。作为应用建议,分阶段替换可以在旧行为仍然可用时揭示这些后果;同时保留两个版本也有成本,不能预设它会永远更优。 + +交接对可维护性主张提出了具体挑战。未来的人与 agent 接手的是接口、前提、故障模式和工具,而非作者私有的理解。因此,本论证珍视可重新还原的理由与可用的修改路径。它不推断每一位贡献者都必须解释每一种内部机制。当受约束的生成器、专人负责和稳定组件等安排在选定生命周期内仍有可信根据时,维护者可以合理依赖它们。 + +在特定情境中,有充分理由拒绝演进优先原则或使其退让。短命产物可能没有有价值的未来扩展。重新打开已验证的边界可能成本很高。运行时约束、部署体积、互操作性或维护专长稀缺,可能使灵活设计威胁产品目的。预测也可能让想象中的未来用户优先于承担当下成本的人。这些是需要权衡的实质反对理由,不是未能理解架构价值的表现。 + +主要权衡是:为有可信根据的未来能力接受多少当下复杂度。这一偏好赋予这种能力一定分量,却没有证明它在每一种情形中都有价值。未解决的问题包括项目如何确立其生命周期、哪些人的维护负担应被计入,以及什么证据能让预测足够可信,从而指导昂贵的选择。本论证为考察这些问题提供理由;它既不给出通用阈值,也不证明已获采用。 + +## 条款对照 + +这份对照使提案的理由与修订条件可以检查。它解释五个领域单元,不向它们增加义务。 + +| 单元 | 问题、前提与支持 | 替代方案、反例与修订理由 | +| --- | --- | --- | +| 4.1 目的、主体与生命周期 | 作者能够编辑,可能掩盖接手者无法维护。持续责任使工具、知识与交接同所声称的能力相关。 | 个人原型或一次性产物可能只需完成有限目的。实际维护责任或退役预期改变,可以成为重新审视范围的理由;仅凭标签不能确立这种变化。 | +| 4.2 有可信根据的演进优先 | 当某一变更方向有可辨识根据时,优化当下抽象的简单性,可能带来本可避免的后续成本。用户珍视这种未来能力,并愿为之承担一定当下复杂度。 | 当下简单性、推迟与小范围预留改动接口仍是替代方案。预测未实现,或灵活性威胁具体目标,都可能使某次投资失去理由。即便预测准确,这项价值偏好仍可受批评。 | +| 4.3 演进的含义 | 在同一方案内扩展,可以与高昂的退出成本并存。当撤除、删除与迁移具有相关性时,持续维护也包括这些变更。 | 刻意固定的范围可能足以服务有明确边界的产品。扩展便宜不证明替换便宜;相关义务或变更方向不同,可以成为重新审视判断的理由。不存在让所有变更都便宜的要求。 | +| 4.4 结构判断 | 接口形式与模式名称遗漏了行为、依赖及验证工作。整体工程后果将设计选择与所声称的能力联系起来。 | 直接代码、抽象、静态特化与运行时选择,均可能在不同约束下得到支持。签名兼容却破坏所需顺序的替换,是对仅凭形式提供保证的反例。契约改变需要相应的新判断。 | +| 4.5 修订与稳定 | 失败预测与沉没投入可能在理由减弱后仍维持机制。Core 的非终局性与根据支持重新审视理由,同时允许有根据的保留。 | 替代方案缺乏有支持的贡献,或妨碍目标达成时,保留设计可以有根据。没有相关收益的昂贵重写反驳了强制变更。根据的实质变化可以支持另一决定,而无需改写先前决定所依据的理由。 | diff --git a/SoftwareEngineering/zh/rationale/architecture-case.md b/SoftwareEngineering/zh/rationale/architecture-case.md new file mode 100644 index 0000000..99fb5db --- /dev/null +++ b/SoftwareEngineering/zh/rationale/architecture-case.md @@ -0,0 +1,34 @@ +# 真实仓库案例:AgentOrganon 的职责 + +本记录考察 2026-09-12 读取的 AgentOrganon 工作树。固定哲学基线为 Core 0.1.2;软件工程取向是额外审查前提。拟议的领域哲学没有替代该基线。这是基于源码的结构论证,与[构造的可执行案例](../docs/cases.md)及多次重复的 skill 专项分开。它既不报告已完成的结构重组,也不报告测得的维护收益。 + +## 决策问题与观察到的边界 + +问题是:减少入口或增加共享机制,是否有助于持续维护的人和 agent 保持、改变及退役这个系统。相关变化方向包括下游哲学修订、不同操作调用方,以及维护者之间的交接。新的宿主或格式仍是有条件的设想;本案例不虚构对它们的需求。 + +以下仓库路径均相对于 AgentOrganon checkout: + +- `skills/organon-assess`、`skills/organon-principled-review` 和 `skills/organon-absorb` 通过 `scripts/resolve.js` 选择调用方的哲学,再将其路径和真实引用目录传入相应的 Core 方法。共享解析器已经存在于 `scripts/lib/operations.js`;重复说明不是同一算法的三份实现。 +- Core assess 负责当前哲学关系的判断。Core principled-review 在明确的标准下返回结构性发现。Core absorb 考察采用理由并协调其获授权的工作流。结构偏好本身不确立哲学冲突,兼容本身也不足以支持采用。 +- `skills/organon-wording-review` 委派措辞审查时不先选择哲学。如果共享前置步骤一律要求哲学,就会丢失这项既有行为。 +- `skills/organon-philosophy` 协调确定性文档管理与哲学审查。`scripts/lib/sections.js` 解析稳定文本单位;`scripts/lib/lock.js` 定义并校验来源检查点与拒绝记录;`scripts/lib/operations.js` 比较并绑定输入;`scripts/lib/io.js` 处理受保护路径和可恢复的成对写入。这些检查不能认证采用的含义或授权。 + +这些边界区分问题和失败条件。它们不证明当前文件划分或入口数量必不可少。格式变更仍会跨越解析、检查点、操作及其共享契约;分层不使这种迁移相互独立或无需成本。 + +## 相同目标下的替代方案 + +| 替代方案 | 值得考虑的理由 | 成本、条件与当前判断 | +| --- | --- | --- | +| 保留当前分工 | 当前关系、结构分析、采用和文件操作可以在不同职责下变化。 | 重复说明与上下文交接仍有维护成本。暂时保留有理由,但不将当前布局视为终局。 | +| 共享路由说明 | 对现有解析器的共同说明,可能减少选择规则改变时出现的不一致指引。 | 另一个解析器会重复既有机制;语义路由还需要任务选择规则。须保持措辞审查独立性和显式路径失败行为。段落更少本身不确立收益。 | +| 部分合并 assess 与完整审查 | 当宽范围评估需要结构分析时,共享工作上下文可能减少重新查找。 | 须保持窄范围评估,以及方法发现与哲学冲突的区别。单个文件也可以保持这两项区分;文件边界不是其证明。这里没有观察到的重复率足以确立收益。 | +| 直接向 Core 传递工作区上下文 | 已经选定哲学的调用方可以使用 Core 现有的显式路径契约。 | 将自动工作区发现移入 Core 会改变其默认行为与依赖。文本形式的宿主契约与可执行依赖具有不同成本;仅为移除一个 wrapper,并不必然需要其中任何一种。 | +| 更明确的交接材料 | 继任者可能更容易恢复基线、对象、依据、候选、权限及下一项行动的责任。 | 现有六部分记录已经覆盖其中不少内容。新增材料可能过期或重复权威来源。应从已证实的遗漏或有明确依据的具体预期变化出发,而不是要求每项任务都新增一个资料包。 | + +暂时建议保留主要职责,在选定结构修订前考察具体交接失败或有明确依据的预期变化。例如,实际丢失基线可以支持更窄的交接修正;仅有更短的会话记录不足以支持它。反过来,如果合并后的方法保持相关区分,又减少继任者的负担,就会削弱保留当前组织方式的理由。这里不预设任何一种结果。 + +## 本案例的支持范围 + +稳定单位身份、来源检查点、拒绝记忆及恢复状态,为具体的未来操作增加了当前复杂度:移动或移除文本、重新考虑上游提案,以及从中断写入中恢复。这构成了在移除这些机制前检查简化保留哪些能力的理由。它不证明所有既有复杂度都值得承担。 + +上述源码位置及 checkout 的 `rtk proxy node --test` 套件,使机械性主张可供检查。测试覆盖其声明的文件行为;它们不比较继任者负担、agent 判断或哲学效力。独立评估和多次重复的 skill 专项另有记录。这份基于源码的记录不确立那些工作的结果。新的失败可以支持修订,但须指出依据发生了哪些变化。 diff --git a/assets/banner.svg b/assets/banner.svg new file mode 100644 index 0000000..9a64d04 --- /dev/null +++ b/assets/banner.svg @@ -0,0 +1 @@ +AdvisedOrganons — OrganonGround agent judgments and improvements. Philosophy, methods and grounds.PHILOSOPHY · METHODS · GROUNDSAdvisedOrganonsGround agent judgments and improvements.ORGANON / 1.0.0-rc.1 diff --git a/docs/getting-started.md b/docs/getting-started.md new file mode 100644 index 0000000..592f72f --- /dev/null +++ b/docs/getting-started.md @@ -0,0 +1,47 @@ +# Quick start + +Use Node.js 22 or later and your chosen agent tool. These commands target the published candidate package; before publication, use the local candidate archive route below. + +## 1. Install the methods + +```sh +npx --yes @shendeguize/agent-organon@1.0.0-rc.1 install --product advised --agent codex --scope project --project /path/to/workspace --version 1.0.0-rc.1 --domain SoftwareEngineering +``` + +Replace `/path/to/workspace` with your project path. Choose `codex`, `claude`, `cursor`, `copilot`, `gemini` or `opencode` for `--agent`. Start with project installation; use `--scope global` for global installation. Installing methods does not adopt a philosophy. + +## 2. Check installation and discovery + +```sh +npx --yes @shendeguize/agent-organon@1.0.0-rc.1 check --product advised --agent codex --scope project --project /path/to/workspace +``` + +Open the agent in that project and confirm the method appears in its skill list or can be loaded explicitly. File checks establish installation integrity; actual tool support is recorded in the candidate’s validation matrix. Resolve reported project/global naming conflicts before continuing. + +## 3. Select a philosophy explicitly + +```sh +npx --yes @shendeguize/agent-organon@1.0.0-rc.1 init --product advised --agent codex --scope project --project /path/to/workspace --domain SoftwareEngineering --philosophy SoftwareEngineering +``` + +Read the preview, confirm the destination and philosophical text, then repeat the command with `--apply --plan-sha256 ` using the exact `planSha256` value in that preview. A changed philosophy or instruction file requires a new preview and decision. An existing philosophy must not be silently replaced; the collection root does not select a domain. Method installation and project adoption are managed separately. + +## 4. Complete a read-only assessment + +Give the agent the actual material you want assessed and ask: + +> Use `organon-software-engineering` with this project’s explicitly selected `PHILOSOPHY.md` as the adopted baseline. Assess the material’s grounds, applicability and possible conflicts. Return a read-only report; do not edit files or adopt a proposal. + +Check that the report identifies its baseline, reasons and limits. An assessment does not authorize philosophical revision; missing independent review must remain explicitly incomplete. + +## Offline archives and lifecycle commands + +Download and extract the archive from the corresponding GitHub Release. Every product includes `installer/organon.mjs`, which Node can run directly; only the AgentOrganon npm package registers the `organon` command. + +```sh +node /path/to/extracted/package/installer/organon.mjs install --product advised --agent codex --scope project --project /path/to/workspace --from /path/to/shendeguize-advised-organons-1.0.0-rc.1.tgz --domain SoftwareEngineering +``` + +The same entrypoint provides `update`, `rollback` and `uninstall`. Check integrity before updating; user modifications or existing-file conflicts stop an update. Uninstall retains user modifications and the adopted project philosophy. + +[Understand the concepts and boundaries](https://shendeguize.github.io/AdvisedOrganons/understand) · [GitHub Releases](https://github.com/shendeguize/AdvisedOrganons/releases) diff --git a/docs/understanding.md b/docs/understanding.md new file mode 100644 index 0000000..a7cc7f7 --- /dev/null +++ b/docs/understanding.md @@ -0,0 +1,36 @@ +# Understand Organon + +## Start with three distinct objects + +**Philosophy** states adopted commitments, their meanings and conditions of application. **Skills** apply methods to tasks and remain revisable. **Tools** check and transform files; they do not decide philosophical correctness or reasons for adoption. + +## How an assessment starts + +Identify the actual input and adopted philosophy, then state the question to assess. Examine reasons, conditions and scope; distinguish contradiction from insufficient support. When considering a revision, keep the preceding baseline identifiable. Compatibility does not warrant adoption, and conflict does not by itself defeat reasons for revision. + +## When change is needed + +An ordinary assessment can end with a report. Absorption examines reasons for philosophical revision and implements it after explicit authorization. Wording review concerns expression; file management checks structure and identity. These methods have different responsibilities and do not replace one another’s judgments. + +## A map of the reading material + +- [Philosophy](https://shendeguize.github.io/AdvisedOrganons/philosophy): commitments, meanings and limits. +- [Rationale](https://shendeguize.github.io/AdvisedOrganons/rationale): arguments, alternatives and objections; no additional philosophical obligations. +- [Lean reader](https://shendeguize.github.io/AdvisedOrganons/lean): begin with claims, premises and boundaries, then inspect declarations and line explanations. +- Maintenance protocols: review, validation and release procedures for maintainers, in the repository’s `maintenance/` directory. + +## What Lean can establish + +Lean checks formal conclusions under given definitions and assumptions. Target `accepted`, kernel `passed` and source fidelity are different judgments; `limited`, `incomplete` and `not_applicable` retain their recorded meanings. Defining a duty does not show its fulfillment; a finite model does not establish universal real-world correctness. Readers unfamiliar with Lean can start with the claim overview and consult the paired code and explanation pages one line at a time. + +## Installation and adoption are separate + +Project installation supplies method entrypoints for that project; global installation supplies user-level entrypoints. Neither adopts a philosophy automatically. A project selects its baseline through explicit initialization; updating, rolling back or uninstalling methods does not automatically change that decision. A domain collection requires an explicit domain choice. + +## Choose a method + +| Discovered entrypoint | Purpose | +| --- | --- | +| `organon-software-engineering` | Route assessment under a selected philosophy; also support wording-only review. | + +Before assessment, explicitly select the domain and adopted philosophy path, then use this domain entrypoint to reach the bundled workspace and Core review methods. The package includes the required implementations but does not separately register the four Core method names as discoverable skills. Installing the domain entrypoint does not adopt its philosophy; a wording-only request does not require a philosophy selection. diff --git a/maintenance/pages-and-stars.md b/maintenance/pages-and-stars.md new file mode 100644 index 0000000..d3a10e1 --- /dev/null +++ b/maintenance/pages-and-stars.md @@ -0,0 +1,27 @@ +# Pages and observed GitHub stars + +This repository publishes its site from the independent `site-data` branch. `main` CI produces development artifacts. It does not deploy them. + +## Publish a released site + +After all three products have passed the complete release gates and are publicly available on npm and GitHub, dispatch **Verified release Pages** (`pages.yml`) from reviewed `main` or `release/1.0.0`. Supply the exact product version and canonical SHA-256 digest of the published `release-manifest.json`. + +The workflow downloads the coordinator's public bundle, checks its complete evidence closure, and verifies all three npm and GitHub distributions against the manifest. It checks out the site's exact source commit and the manifest's Core theme commit, installs locked site-build dependencies in a temporary runner directory, and builds and checks the bilingual site. The workspace gitlinks and the domain's Core tooling pin must agree with the release manifest. + +Only after those checks does it replace `site-data/public/`, preserving observed star history. `recommended-release.json` binds the release manifest, source and Core commits, verification time, and every immutable published file hash. Older versions and different content with the same version cannot replace the recommendation. The workflow uploads that directory and deploys it through the `github-pages` environment. + +Core and AdvisedOrganons load the operational workspace tools from the exact commit in `release/tooling.json` (`workspace.repository` and `workspace.commit`). AdvisedOrganons also records `core`. These are reviewed full commit pins. The actual website theme always comes from the release manifest's Core source. + +## Daily observation + +**Observed stars** (`stars.yml`) runs daily at 02:17 UTC and can also be dispatched manually. It reads the real GitHub total and appends at most one observation per UTC date to `site-data/stars.json`. Zero, decreases, observation timestamps, and missing dates are retained. A failed API response or invalid count changes no published state. + +Before any release, sampling stores `stars.json` and `stars.svg` but does not create or deploy a website. After a release, it verifies the saved manifest, recommendation and HTML hashes, updates only `public/assets/stars.json` and `public/assets/stars.svg`, and redeploys the existing released HTML. It does not rebuild from `main` or claim a new all-channel check. README's stable chart address is `https://shendeguize.github.io/AdvisedOrganons/assets/stars.svg`; it becomes available after the first site release. + +Both workflows share one concurrency group. They push only `refs/heads/site-data`, without force; a competing remote update causes failure. They need Actions enabled, a Pages site configured to use GitHub Actions, and the repository token's scoped `contents: write` permission for the data branch. Only the deployment job receives `pages: write` and `id-token: write`. Protected integration and release branches are not data storage. + +## Verify and recover + +Rerun `node --test tests/release-site-data.test.mjs tests/release.test.mjs` in the pinned AgentOrganon tooling checkout. These are local fixture tests; a passing result does not claim a remote deployment occurred. + +If sampling fails, inspect the run and retry after resolving the API or stored-state issue. History is not synthesized. If deployment fails after a successful branch update, rerun the workflow: the saved release identity remains available. A failed publication gate must be resolved in the release process before retrying Pages. Review any unexpected stored-file or checksum change rather than replacing its hash to silence the check. diff --git a/package.json b/package.json new file mode 100644 index 0000000..d61a80d --- /dev/null +++ b/package.json @@ -0,0 +1,25 @@ +{ + "private": true, + "type": "module", + "engines": { + "node": ">=22" + }, + "name": "@shendeguize/advised-organons", + "version": "1.0.0-rc.1", + "description": "Explicitly selected domain philosophies for agent workspaces", + "license": "MIT", + "repository": { + "type": "git", + "url": "https://github.com/shendeguize/AdvisedOrganons.git" + }, + "scripts": { + "test": "node scripts/test.mjs", + "build:site": "node scripts/site.mjs build", + "check:site": "node scripts/site.mjs check", + "check:content": "node scripts/release.mjs content", + "build:package": "node scripts/release.mjs package-build", + "check:package": "node scripts/release.mjs package-check", + "check:github": "node scripts/release.mjs github", + "check:release": "node scripts/release.mjs manifest" + } +} diff --git a/release/tooling.json b/release/tooling.json new file mode 100644 index 0000000..63022d3 --- /dev/null +++ b/release/tooling.json @@ -0,0 +1,11 @@ +{ + "schema_version": 1, + "workspace": { + "repository": "shendeguize/AgentOrganon", + "commit": "52a824c1d5c4f92da8d984c8ce976754bc514a64" + }, + "core": { + "repository": "shendeguize/OrganonCore", + "commit": "77c1ef086cc2eb55d192059e97658abc5ca7f95f" + } +} diff --git a/scripts/release.mjs b/scripts/release.mjs new file mode 100644 index 0000000..52d79cf --- /dev/null +++ b/scripts/release.mjs @@ -0,0 +1,14 @@ +import fs from 'node:fs'; +import path from 'node:path'; +import { spawnSync } from 'node:child_process'; +import { fileURLToPath } from 'node:url'; +const root=path.resolve(path.dirname(fileURLToPath(import.meta.url)), '..'); +const workspace=process.env.ORGANON_WORKSPACE_ROOT || path.resolve(root,'..'); +const commands={content:['scripts/release/content.mjs','--repo',root], 'package-build':['scripts/package/build.mjs','--product','advised'], 'package-check':['scripts/package/check.mjs'], github:['scripts/release/governance.mjs','check','--repository','shendeguize/AdvisedOrganons'], manifest:['scripts/release/manifest.mjs','check']}; +const command=commands[process.argv[2]]; +if(!command) throw new Error('Unknown release gate'); +const script=path.join(workspace,command[0]); +if(!fs.existsSync(script)) throw new Error('Release coordination requires the fixed three-repository workspace; set ORGANON_WORKSPACE_ROOT'); +const result=spawnSync(process.execPath,[script,...command.slice(1),...process.argv.slice(3)],{stdio:'inherit',cwd:workspace}); +if(result.error) throw result.error; +process.exitCode=result.status??1; diff --git a/scripts/site.mjs b/scripts/site.mjs new file mode 100644 index 0000000..23273a2 --- /dev/null +++ b/scripts/site.mjs @@ -0,0 +1,13 @@ +import fs from 'node:fs'; +import path from 'node:path'; +import { spawnSync } from 'node:child_process'; +import { fileURLToPath } from 'node:url'; +const root=path.resolve(path.dirname(fileURLToPath(import.meta.url)), '..'); +const core=process.env.ORGANON_CORE_ROOT || path.resolve(root,'../OrganonCore'); +const mode=process.argv[2]; +if (!['build','check'].includes(mode)) throw new Error('Expected build or check'); +const script=path.join(core,'tools/site',`${mode}.mjs`); +if (!fs.existsSync(script)) throw new Error('Missing fixed Core tooling; set ORGANON_CORE_ROOT'); +const result=spawnSync(process.execPath,[script,'--repo',root,...process.argv.slice(3)],{stdio:'inherit'}); +if(result.error) throw result.error; +process.exitCode=result.status??1; diff --git a/scripts/test.mjs b/scripts/test.mjs new file mode 100644 index 0000000..043dd46 --- /dev/null +++ b/scripts/test.mjs @@ -0,0 +1,12 @@ +import fs from 'node:fs'; +import path from 'node:path'; +import { spawnSync } from 'node:child_process'; +import { fileURLToPath } from 'node:url'; + +const root = path.resolve(path.dirname(fileURLToPath(import.meta.url)), '..'); +const directory = path.join(root, 'tests'); +const files = fs.existsSync(directory) ? fs.readdirSync(directory).filter(name => /\.test\.(?:mjs|js)$/.test(name)).sort().map(name => path.join(directory, name)) : []; +if (!files.length) throw new Error('No owned tests found'); +const result = spawnSync(process.execPath, ['--test', '--test-concurrency=2', ...process.argv.slice(2), ...files], { stdio: 'inherit', cwd: root }); +if (result.error) throw result.error; +process.exitCode = result.status ?? 1; diff --git a/site/index.md b/site/index.md new file mode 100644 index 0000000..c41bf54 --- /dev/null +++ b/site/index.md @@ -0,0 +1,37 @@ +--- +layout: home +hero: + name: "AdvisedOrganons" + text: "Ground agent judgments and improvements." + tagline: "Domain philosophies with explicit boundaries · Make commitments explicit. Examine grounds. Revise for reasons." + actions: + - theme: brand + text: "Quick start" + link: /quick-start + - theme: alt + text: "Read the philosophy" + link: /philosophy +features: + - title: "Make the baseline explicit" + details: "Distinguish adopted commitments, a proposed change and the method’s own constraints." + - title: "Examine reasons and limits" + details: "Connect a claim to its assumptions, grounds and scope of application." + - title: "Revise for stated reasons" + details: "Examine reasons for change; retain an explicit human decision on philosophical adoption." +--- + +## Why philosophy as a design foundation + +Agents make judgments and propose changes. A philosophy makes their underlying commitments readable, open to criticism and revisable. Organon supplies philosophical text and review methods that ask for reasons and limits. It does not guarantee correct judgments or treat a count of methods as evidence of capability. + +The current domain is **SoftwareEngineering**. Philosophy **0.2.1** adds a defeasible priority for credible software evolution and retains the considered Core **0.1.2** checkpoint. That priority is an additional commitment, not a deduction from the Core. Selecting this domain remains explicit. + +## Three repositories, distinct responsibilities + +| Repository | Responsibility | +| --- | --- | +| [AgentOrganon](https://shendeguize.github.io/AgentOrganon/) | Workspace skills and management of adopted philosophy copies. | +| [OrganonCore](https://shendeguize.github.io/OrganonCore/) | The core philosophy, review methods and bounded Lean evidence. | +| [AdvisedOrganons](https://shendeguize.github.io/AdvisedOrganons/) | A collection of domain philosophies; select a domain explicitly. | + +Installation packages supply non-Lean capabilities; the website retains the philosophy and Lean reader views. diff --git a/site/public/assets/stars.json b/site/public/assets/stars.json new file mode 100644 index 0000000..0b0a4a7 --- /dev/null +++ b/site/public/assets/stars.json @@ -0,0 +1,10 @@ +{ + "schema_version": 1, + "repository": "shendeguize/AdvisedOrganons", + "observations": [ + { + "observed_at": "2026-09-15T04:41:11.086Z", + "total": 0 + } + ] +} diff --git a/site/public/assets/stars.svg b/site/public/assets/stars.svg new file mode 100644 index 0000000..2d4efe3 --- /dev/null +++ b/site/public/assets/stars.svg @@ -0,0 +1 @@ +shendeguize/AdvisedOrganons — observed GitHub starsDaily observed totals, including decreases. Missing dates are gaps. Last observed 2026-09-15T04:41:11.086Z: 0.GitHub stars · 0shendeguize/AdvisedOrganonsObserved since 2026-09-15 · Updated 2026-09-15T04:41:11.086ZDaily total / 每日总数 · gaps indicate missing observations / 缺样保留断点2026-09-15T04:41:11.086Z: 0 diff --git a/site/site.json b/site/site.json new file mode 100644 index 0000000..e5eec14 --- /dev/null +++ b/site/site.json @@ -0,0 +1,7 @@ +{ + "repository": "AdvisedOrganons", + "product": "advised", + "version": "1.0.0-rc.1", + "themeVersion": "1.0.0-rc.1", + "philosophyRoot": "SoftwareEngineering" +} diff --git a/site/zh/index.md b/site/zh/index.md new file mode 100644 index 0000000..152f838 --- /dev/null +++ b/site/zh/index.md @@ -0,0 +1,37 @@ +--- +layout: home +hero: + name: "AdvisedOrganons" + text: "让 agent 的判断与改进有依据。" + tagline: "具有明确边界的领域哲学 · 明确承诺,审查根据,有理由地修订。" + actions: + - theme: brand + text: "快速开始" + link: /zh/quick-start + - theme: alt + text: "阅读哲学" + link: /zh/philosophy +features: + - title: "明确判断基准" + details: "区分已采纳的承诺、待审查的提议与方法自身的约束。" + - title: "审查理由与限度" + details: "将主张与前提、根据及适用范围联系起来。" + - title: "有理由地修订" + details: "审查改变的理由;哲学采纳保留明确的人类决定。" +--- + +## 为什么采用哲学设计 + +Agent 会进行判断,也会提出改变。哲学让这些判断所依据的承诺可读、可质疑、可修订。Organon 提供哲学文本与审查方法,要求说明理由和边界;它不保证每次判断正确,也不把方法数量当作能力证明。 + +当前领域为 **SoftwareEngineering**。哲学 **0.2.1** 增加允许有根据地退让的软件演进优先承诺,保留已考虑的 Core **0.1.2** 检查点。该优先性是额外承诺,不是从 Core 推导出的结论;使用时仍需显式选择领域。 + +## 三个仓库,各有职责 + +| 仓库 | 职责 | +| --- | --- | +| [AgentOrganon](https://shendeguize.github.io/AgentOrganon/zh/) | 工作区技能与已采纳哲学副本的管理。 | +| [OrganonCore](https://shendeguize.github.io/OrganonCore/zh/) | 核心哲学、审查方法,以及有边界的 Lean 证据。 | +| [AdvisedOrganons](https://shendeguize.github.io/AdvisedOrganons/zh/) | 领域哲学集合;使用时显式选择领域。 | + +安装包只提供非 Lean 能力;网站保留完整哲学及 Lean 读者视图。 diff --git a/skills/organon-software-engineering/SKILL.md b/skills/organon-software-engineering/SKILL.md new file mode 100644 index 0000000..91e2321 --- /dev/null +++ b/skills/organon-software-engineering/SKILL.md @@ -0,0 +1,12 @@ +--- +name: organon-software-engineering +description: Route a software engineering assessment under an explicitly selected adopted philosophy to the Organon review methods. Installation does not adopt a domain philosophy. +--- + +# Software Engineering Organon + +Ask the caller to identify the adopted philosophy path if it has not already been selected. Keep the caller's workspace separate from this installed collection. Do not select the bundled SoftwareEngineering text merely because this skill is installed or because the task concerns software engineering. + +Read the selected philosophy, including its meanings and limits. Locate AgentOrganon from the installed runtime directory stated in this skill's discovery copy, or from an explicitly supplied AgentOrganon checkout. If that runtime is unavailable, report the missing dependency. Pass the selected philosophy's exact path and real reference directory to the runtime's `skills/organon-assess/SKILL.md`. That method retains the caller's baseline through Core delegation. For a request limited to wording, use the runtime's `skills/organon-wording-review/SKILL.md` without acquiring a philosophical adoption requirement. + +The [bundled SoftwareEngineering philosophy](../../SoftwareEngineering/PHILOSOPHY.md) is available for an explicit selection. Installing, updating or removing this package does not adopt, revise or withdraw a project's philosophy. A philosophical revision requires the separate review and authorization workflow of the selected method. diff --git a/tests/philosophy.test.mjs b/tests/philosophy.test.mjs new file mode 100644 index 0000000..e68f14b --- /dev/null +++ b/tests/philosophy.test.mjs @@ -0,0 +1,15 @@ +import test from 'node:test'; +import assert from 'node:assert/strict'; +import fs from 'node:fs'; +import path from 'node:path'; +import { fileURLToPath } from 'node:url'; + +const root = path.resolve(path.dirname(fileURLToPath(import.meta.url)), '..'); +test('the path-only release retains the domain adoption checkpoint and bilingual unit identity', () => { + const en = fs.readFileSync(path.join(root, 'SoftwareEngineering/PHILOSOPHY.md'), 'utf8'); + const zh = fs.readFileSync(path.join(root, 'SoftwareEngineering/zh/PHILOSOPHY.md'), 'utf8'); + for (const text of [en,zh]) { assert.match(text, /^philosophy_version: 0\.2\.1$/m); assert.match(text, /^core_version: 0\.1\.2$/m); assert.match(text, /\]\(rationale\/README\.md\)/); } + const ids = text => [...text.matchAll(//g)].map(match => match[1]); + assert.deepEqual(ids(en), ids(zh)); + assert(!fs.existsSync(path.join(root, 'SoftwareEngineering/docs/rationale.md'))); +}); diff --git a/zh/README.md b/zh/README.md new file mode 100644 index 0000000..02baef6 --- /dev/null +++ b/zh/README.md @@ -0,0 +1,57 @@ +![AdvisedOrganons](../assets/banner.svg) + +[English](../README.md) · [简体中文](README.md) · [Website](https://shendeguize.github.io/AdvisedOrganons/zh/) · [Releases](https://github.com/shendeguize/AdvisedOrganons/releases) + +# AdvisedOrganons + +具有明确边界的领域哲学。 + +## Design Aim · 设计目标 + +让 agent 的判断与改进有依据。Organon 让承诺、理由和适用边界可读、可审查、可修订。它提供哲学和方法,不保证判断正确或自动改进;哲学采纳保留明确的人类决定。 + +当前领域为 **SoftwareEngineering**。哲学 **0.2.1** 增加允许有根据地退让的软件演进优先承诺,保留已考虑的 Core **0.1.2** 检查点。该优先性是额外承诺,不是从 Core 推导出的结论;使用时仍需显式选择领域。 + +## 开始使用 + +```sh +npx --yes @shendeguize/agent-organon@1.0.0-rc.1 install --product advised --agent codex --scope project --project /path/to/workspace --version 1.0.0-rc.1 --domain SoftwareEngineering +``` + +候选发行版 **1.0.0-rc.1** 等待审核。公开包可用后执行上述命令;发行前使用本地候选包。需要 Node.js 22+。支持项目或全局安装;六种 agent 适配的真实验证状态见发行矩阵。 + +[完整快速开始:安装 → 检查 → 选择哲学 → 只读评估](https://shendeguize.github.io/AdvisedOrganons/zh/quick-start) + +## 阅读与仓库结构 + +| 入口 | 内容 | +| --- | --- | +| [AgentOrganon](https://github.com/shendeguize/AgentOrganon) | 工作区技能及已采纳副本的管理。 | +| [OrganonCore](https://github.com/shendeguize/OrganonCore) | 核心哲学、审查方法与 Lean 证据。 | +| [AdvisedOrganons](https://github.com/shendeguize/AdvisedOrganons) | 领域哲学集合;明确选择领域后使用。 | +| [Docs](https://shendeguize.github.io/AdvisedOrganons/zh/understand) | 帮助读者理解概念、操作及能力边界。 | +| [Philosophy](https://shendeguize.github.io/AdvisedOrganons/zh/philosophy) | 已采纳承诺及其含义与条件。 | +| [Lean](https://shendeguize.github.io/AdvisedOrganons/zh/lean) | 主张速览及代码与解释的左右对照。 | + +发布包仅包含哲学、非 Lean skills 及运行所需文件。网站、教程、Lean 工程与证据仍在源码中维护。Rationale 独立于人读 docs,不增加哲学义务;维护协议位于 maintenance。 + + +## 选择方法 + +| 可发现入口 | 用途 | +| --- | --- | +| `organon-software-engineering` | 对已选哲学的评估进行路由;也支持仅限措辞的审查。 | + +评估前先明确选择要采用的领域及其哲学路径,再通过这个领域入口调用包内的工作区与 Core 审查方法。该包包含所需实现,但不会把四个 Core 方法名分别注册为可发现技能。安装领域入口本身不采纳领域哲学;仅审查措辞的请求不需要哲学选择。 + +## 星标历史 + +![当前仓库真实星标总数历史](https://shendeguize.github.io/AdvisedOrganons/assets/stars.svg) + +从启用日起每日记录真实总数。零值、取消星标和缺失采样如实保留;图中注明更新时间。 + +## 参与维护 + +维护前阅读仓库的 agent 指导与维护协议。机械检查、独立审查和人类采纳决定具有不同职责。 + +MIT · [License](../LICENSE) diff --git a/zh/docs/getting-started.md b/zh/docs/getting-started.md new file mode 100644 index 0000000..ea3700d --- /dev/null +++ b/zh/docs/getting-started.md @@ -0,0 +1,47 @@ +# 快速开始 + +需要 Node.js 22 或更高版本,以及你选择的 agent 工具。下列命令针对已公开的候选发行包;发布前先使用发行候选包的本地文件方式。 + +## 1. 安装方法 + +```sh +npx --yes @shendeguize/agent-organon@1.0.0-rc.1 install --product advised --agent codex --scope project --project /path/to/workspace --version 1.0.0-rc.1 --domain SoftwareEngineering +``` + +将 `/path/to/workspace` 换成你的项目路径。`--agent` 可选择 `codex`、`claude`、`cursor`、`copilot`、`gemini` 或 `opencode`。首次使用推荐项目安装;全局安装选择 `--scope global`。安装能力不等于已采纳哲学。 + +## 2. 检查安装与发现 + +```sh +npx --yes @shendeguize/agent-organon@1.0.0-rc.1 check --product advised --agent codex --scope project --project /path/to/workspace +``` + +在该项目中打开 agent,确认其技能列表或显式加载入口能够找到相关方法。文件检查通过只说明安装完整性;工具真实调用的支持状态以候选发行的验证矩阵为准。遇到项目与全局重名安装时,先按照检查结果解决冲突。 + +## 3. 显式选择哲学 + +```sh +npx --yes @shendeguize/agent-organon@1.0.0-rc.1 init --product advised --agent codex --scope project --project /path/to/workspace --domain SoftwareEngineering --philosophy SoftwareEngineering +``` + +阅读预览,确认目标与哲学文本后,再在相同命令上增加 `--apply --plan-sha256 `,使用该预览返回的准确 `planSha256` 值。哲学或指令文件发生变化后,必须重新预览并决定。已有哲学不得被静默替换;集合根不代表已选择领域。方法安装和项目哲学采纳分别管理。 + +## 4. 完成一次只读评估 + +向 agent 提交实际需要评估的材料,并要求: + +> 使用 `organon-software-engineering` ,以本项目显式选择的 `PHILOSOPHY.md` 为已采纳基准,评估这份材料的根据、适用范围和潜在冲突。给出只读报告,不修改文件,也不采纳提议。 + +检查报告是否明确指出基准、理由和限度。评估结论不自动授权哲学修订;独立复核缺失时,应保留未完成状态。 + +## 离线包与后续管理 + +从对应 GitHub Release 下载包并解压。每个产品包内的 `installer/organon.mjs` 都可以直接由 Node 运行;只有 AgentOrganon 的 npm 包注册 `organon` 命令。 + +```sh +node /path/to/extracted/package/installer/organon.mjs install --product advised --agent codex --scope project --project /path/to/workspace --from /path/to/shendeguize-advised-organons-1.0.0-rc.1.tgz --domain SoftwareEngineering +``` + +相同入口提供 `update`、`rollback` 和 `uninstall`。更新前检查完整性;用户修改或已有文件冲突会停止更新。卸载保留用户修改和已采纳的项目哲学。 + +[理解概念与边界](https://shendeguize.github.io/AdvisedOrganons/zh/understand) · [GitHub Releases](https://github.com/shendeguize/AdvisedOrganons/releases) diff --git a/zh/docs/understanding.md b/zh/docs/understanding.md new file mode 100644 index 0000000..3565e2a --- /dev/null +++ b/zh/docs/understanding.md @@ -0,0 +1,36 @@ +# 理解 Organon + +## 先区分三个对象 + +**哲学**说明已采纳的承诺、含义和适用条件。**Skill**把方法用于具体任务,可随经验修订。**工具**检查和变换文件,不能替人判断哲学是否正确或是否值得采纳。 + +## 一次评估怎样开始 + +先确定实际输入与已采纳的哲学,再说明要评估的问题。审查理由、条件及范围,区分冲突与支持不足。提议修订时,原基准保持可辨认;兼容不自动支持采纳,冲突也不自动否定修订理由。 + +## 何时需要改变 + +普通评估可以只给出报告。吸收流程用于检查哲学修订的理由,并在明确授权后实施。措辞审查仅处理表达;文件管理检查结构和身份。方法之间有不同职责,不能互相代替判断。 + +## 阅读材料的地图 + +- [哲学](https://shendeguize.github.io/AdvisedOrganons/zh/philosophy):承诺、含义与限度。 +- [Rationale](https://shendeguize.github.io/AdvisedOrganons/zh/rationale):论证、替代方案和反对意见,不增加哲学义务。 +- [Lean 对照](https://shendeguize.github.io/AdvisedOrganons/zh/lean):从主张、前提和边界读起,再展开声明与逐行解释。 +- 维护协议:面向维护者的审查、验证与发布过程,位于仓库的 `maintenance/`。 + +## Lean 能说明什么 + +Lean 检查给定定义和假设下的形式结论。目标 `accepted`、内核 `passed`、来源保真状态是不同判断;`limited`、`incomplete`、`not_applicable` 等状态保留其原有含义。定义义务不证明义务已履行,有限模型不证明现实中的普遍正确性。不懂 Lean 的读者可以先读主张速览,再在左右对照页逐行查看解释。 + +## 安装与采纳分别管理 + +项目安装只提供该项目的方法入口;全局安装提供用户范围入口。两种安装都不自动采纳哲学。项目通过显式初始化选择基准;更新、回退或卸载方法不会自动改变这个决定。领域集合必须明确选择领域。 + +## 选择方法 + +| 可发现入口 | 用途 | +| --- | --- | +| `organon-software-engineering` | 对已选哲学的评估进行路由;也支持仅限措辞的审查。 | + +评估前先明确选择要采用的领域及其哲学路径,再通过这个领域入口调用包内的工作区与 Core 审查方法。该包包含所需实现,但不会把四个 Core 方法名分别注册为可发现技能。安装领域入口本身不采纳领域哲学;仅审查措辞的请求不需要哲学选择。 diff --git a/zh/maintenance/pages-and-stars.md b/zh/maintenance/pages-and-stars.md new file mode 100644 index 0000000..d81d705 --- /dev/null +++ b/zh/maintenance/pages-and-stars.md @@ -0,0 +1,27 @@ +# Pages 与 GitHub 星标实测 + +本仓库从独立的 `site-data` 分支发布站点。`main` CI 生成开发产物,不部署这些产物。 + +## 发布已发行站点 + +三个产品完成全部发行门禁并在 npm 与 GitHub 公开后,从经过审查的 `main` 或 `release/1.0.0` 手动运行 **Verified release Pages**(`pages.yml`)。提供精确产品版本及公开 `release-manifest.json` 的规范化 SHA-256 摘要。 + +工作流下载总入口仓库的公开发行包,检查完整证据闭包,再核对三个产品的 npm 与 GitHub 分发。它检出本站的精确源码 commit 和清单中的 Core 主题 commit,在临时 runner 目录安装锁定的站点构建依赖,构建并检查双语站点。工作区 gitlink 和领域仓库的 Core 工具固定版本必须与清单一致。 + +检查全部通过后才替换 `site-data/public/`,并保留已观察的星标历史。`recommended-release.json` 绑定发行清单、源码和 Core commit、验证时间及每个不可变公开文件的 hash。旧版本或同版本不同内容不能覆盖推荐版本。工作流上传该目录,通过 `github-pages` 环境部署。 + +Core 与 AdvisedOrganons 从 `release/tooling.json` 的 `workspace.repository`、`workspace.commit` 加载操作工具;AdvisedOrganons 还记录 `core`。这些字段必须是经过审查的完整 commit。实际网站主题始终取自发行清单的 Core 来源。 + +## 每日实测 + +**Observed stars**(`stars.yml`)每日 02:17 UTC 运行,也可手动触发。它读取 GitHub 的真实总数,每个 UTC 日期最多向 `site-data/stars.json` 添加一次观察。零值、下降、观察时间和缺样均保留。API 失败或计数无效时,不改变公开状态。 + +首次发行前,只保存 `stars.json` 和 `stars.svg`,不创建或部署网站。发行后,先检查已保存的清单、推荐记录和 HTML hash,仅更新 `public/assets/stars.json` 与 `public/assets/stars.svg`,再部署已有发行 HTML。它不从 `main` 重建,也不宣称重新完成全部渠道验证。README 的稳定曲线地址是 `https://shendeguize.github.io/AdvisedOrganons/assets/stars.svg`,首次站点发行后可用。 + +两个工作流共享并发组,只向 `refs/heads/site-data` 执行非强制推送;远端竞争更新会导致失败。需要启用 Actions,将 Pages 配置为使用 GitHub Actions,并给予仓库 token 写数据分支所需的 `contents: write`。只有部署 job 获得 `pages: write` 和 `id-token: write`。受保护的集成与发行分支不承载采样数据。 + +## 验证与恢复 + +在固定版本的 AgentOrganon 工具检出目录运行 `node --test tests/release-site-data.test.mjs tests/release.test.mjs`。这是本地夹具测试,通过不代表执行过远端部署。 + +采样失败时,检查运行记录,解决 API 或保存状态的问题后重试,不补造历史。分支更新成功而部署失败时,可以重跑工作流,已保存的发行身份仍然存在。发行门禁失败必须先在发行流程解决,再重试 Pages。出现异常文件或 checksum 变化时,应审查变化,不得仅替换 hash 来消除报错。